panic: ffs_blkfree: bad size (3)

0 views
Skip to first unread message

syzbot

unread,
Jan 12, 2024, 3:56:19 PMJan 12
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 2d01bf8aac77 Send UDP packets in parallel.
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10c510ede80000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=2bec2c8fe3717c60542a

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/6b2809da21d3/disk-2d01bf8a.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/857a7163ae12/bsd-2d01bf8a.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/92968269d01c/kernel-2d01bf8a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2bec2c...@syzkaller.appspotmail.com

panic: ffs_blkfree: bad size
Stopped at db_enter+0x1c: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*517432 3391 0 0 0x4000000 0K syz-executor.3
328276 15788 0 0x14000 0x200 1 reaper
db_enter() at db_enter+0x1c sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff827ef3ea) at panic+0x17b sys/kern/subr_prf.c:198
ffs_blkfree(fffffd8066fa2de0,3,4000) at ffs_blkfree+0xa42 sys/ufs/ffs/ffs_alloc.c:1296
ffs_indirtrunc(fffffd8066fa2de0,fffffffffffffff4,e3b20,ffffffffffffffff,0,ffff8000374c2458) at ffs_indirtrunc+0x65d sys/ufs/ffs/ffs_inode.c:543
ffs_truncate(fffffd8066fa2de0,0,0,ffffffffffffffff) at ffs_truncate+0xfa5 sys/ufs/ffs/ffs_inode.c:335
ufs_inactive(ffff8000374c2618) at ufs_inactive+0x152 sys/ufs/ufs/ufs_inode.c:84
VOP_INACTIVE(fffffd8067a49c00,ffff80002a1c9ab0) at VOP_INACTIVE+0xc5 sys/kern/vfs_vops.c:489
vrele(fffffd8067a49c00) at vrele+0xd3 sys/kern/vfs_subr.c:827
ktrsettrace(ffffffff82d936c0,80001419,fffffd80659a12d0,fffffd807f7d6680) at ktrsettrace+0xb7 sys/kern/kern_ktrace.c:122
ktrops(ffff80002a1c9ab0,ffffffff82d936c0,0,80001419,fffffd80659a12d0,fffffd807f7d6680) at ktrops+0x1a8 sys/kern/kern_ktrace.c:564
doktrace(fffffd80659a12d0,0,1419,0,ffff80002a1c9ab0) at doktrace+0xeb sys/kern/kern_ktrace.c:510
sys_ktrace(ffff80002a1c9ab0,ffff8000374c29b0,ffff8000374c2a00) at sys_ktrace+0xd6 sys/kern/kern_ktrace.c:549
syscall(ffff8000374c2a60) at syscall+0x42c sys/arch/amd64/amd64/trap.c:591
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xd280d686bd0, count: 1
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb{0}>
ddb{0}> set $lines = 0
ddb{0}> set $maxwidth = 0
ddb{0}> show panic
*cpu0: ffs_blkfree: bad size
ddb{0}> trace
db_enter() at db_enter+0x1c sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff827ef3ea) at panic+0x17b sys/kern/subr_prf.c:198
ffs_blkfree(fffffd8066fa2de0,3,4000) at ffs_blkfree+0xa42 sys/ufs/ffs/ffs_alloc.c:1296
ffs_indirtrunc(fffffd8066fa2de0,fffffffffffffff4,e3b20,ffffffffffffffff,0,ffff8000374c2458) at ffs_indirtrunc+0x65d sys/ufs/ffs/ffs_inode.c:543
ffs_truncate(fffffd8066fa2de0,0,0,ffffffffffffffff) at ffs_truncate+0xfa5 sys/ufs/ffs/ffs_inode.c:335
ufs_inactive(ffff8000374c2618) at ufs_inactive+0x152 sys/ufs/ufs/ufs_inode.c:84
VOP_INACTIVE(fffffd8067a49c00,ffff80002a1c9ab0) at VOP_INACTIVE+0xc5 sys/kern/vfs_vops.c:489
vrele(fffffd8067a49c00) at vrele+0xd3 sys/kern/vfs_subr.c:827
ktrsettrace(ffffffff82d936c0,80001419,fffffd80659a12d0,fffffd807f7d6680) at ktrsettrace+0xb7 sys/kern/kern_ktrace.c:122
ktrops(ffff80002a1c9ab0,ffffffff82d936c0,0,80001419,fffffd80659a12d0,fffffd807f7d6680) at ktrops+0x1a8 sys/kern/kern_ktrace.c:564
doktrace(fffffd80659a12d0,0,1419,0,ffff80002a1c9ab0) at doktrace+0xeb sys/kern/kern_ktrace.c:510
sys_ktrace(ffff80002a1c9ab0,ffff8000374c29b0,ffff8000374c2a00) at sys_ktrace+0xd6 sys/kern/kern_ktrace.c:549
syscall(ffff8000374c2a60) at syscall+0x42c sys/arch/amd64/amd64/trap.c:591
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xd280d686bd0, count: -14
ddb{0}> show registers
rdi 0
rsi 0x1
rbp 0xffff8000374c2140
rbx 0xffffffff82b97ba7 cpu_info_full_primary+0x2ba7
rdx 0xffff800000d50500
rcx 0xffff80002a1c9ab0
rax 0xffffffff82b96ff0 cpu_info_full_primary+0x1ff0
r8 0x101010101010101
r9 0x8080808080808080
r10 0x4465bd3107c8e327
r11 0x94e0c474aa355b00
r12 0xffffffff82b979a8 cpu_info_full_primary+0x29a8
r13 0
r14 0
r15 0x1
rip 0xffffffff81d4536c db_enter+0x1c
cs 0x8
rflags 0x246
rsp 0xffff8000374c2130
ss 0
db_enter+0x1c: addq $0x8,%rsp
ddb{0}> show proc
PROC (syz-executor.3) tid=517432 pid=3391 tcnt=2 stat=onproc
flags process=0 proc=4000000<THREAD>
runpri=17, usrpri=80, slppri=17, nice=20
wchan=0x0, wmesg=, ps_single=0x0
forw=0xffffffffffffffff, list=0xffff80002a24f7f8,0xffff80002a1c5ac8
process=0xffff8000ffff1938 user=0xffff8000374bd000, vmspace=0xfffffd8065dea940
estcpu=36, cpticks=1, pctcpu=0.0, user=0, sys=1, intr=0
ddb{0}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
91724 185885 71414 0 2 0 syz-executor.7
91724 216027 71414 0 3 0x4000080 fsleep syz-executor.7
91724 112806 71414 0 2 0x4000000 syz-executor.7
3391 393132 69271 0 2 0 syz-executor.3
* 3391 517432 69271 0 7 0x4000000 syz-executor.3
40697 442658 29420 0 2 0 syz-executor.6
40697 180618 29420 0 3 0x4000080 fsleep syz-executor.6
40697 192341 29420 0 3 0x4000080 fsleep syz-executor.6
43379 406261 58130 0 2 0 syz-executor.2
43379 522236 58130 0 2 0x4000000 syz-executor.2
43379 277043 58130 0 2 0x4000000 syz-executor.2
97149 359669 55473 0 2 0 syz-executor.5
97149 356653 55473 0 3 0x4000080 fsleep syz-executor.5
97149 5246 55473 0 3 0x4000080 netio syz-executor.5
83890 374954 0 0 3 0x14280 nfsidl nfsio
35750 46816 0 0 3 0x14280 nfsidl nfsio
59320 288379 0 0 3 0x14280 nfsidl nfsio
93882 42592 0 0 3 0x14280 nfsidl nfsio
64298 283874 0 0 3 0x14280 nfsidl nfsio
84565 62567 0 0 3 0x14280 nfsidl nfsio
1636 303021 0 0 3 0x14280 nfsidl nfsio
17095 26088 0 0 3 0x14280 nfsidl nfsio
1361 10837 0 0 3 0x14280 nfsidl nfsio
88431 216728 0 0 3 0x14280 nfsidl nfsio
78606 395909 0 0 3 0x14280 nfsidl nfsio
28307 256414 0 0 3 0x14280 nfsidl nfsio
61752 227028 0 0 3 0x14280 nfsidl nfsio
58365 261810 0 0 3 0x14280 nfsidl nfsio
80415 478633 0 0 3 0x14280 nfsidl nfsio
91934 149791 0 0 3 0x14280 nfsidl nfsio
71788 320975 0 0 3 0x14280 nfsidl nfsio
99866 338699 0 0 3 0x14280 nfsidl nfsio
88480 100983 0 0 3 0x14280 nfsidl nfsio
63884 284880 0 0 3 0x14280 nfsidl nfsio
41194 468493 1 0 3 0x100083 ttyin getty
29420 457181 95470 0 3 0x82 nanoslp syz-executor.6
55473 195077 95470 0 3 0x82 nanoslp syz-executor.5
98464 229305 95470 0 2 0x2 syz-executor.1
69271 67189 95470 0 3 0x82 nanoslp syz-executor.3
71414 310493 95470 0 2 0x2 syz-executor.7
64655 21377 95470 0 2 0x482 syz-executor.4
58130 396173 95470 0 2 0x482 syz-executor.2
73558 250817 95470 0 2 0x482 syz-executor.0
17280 5604 0 0 3 0x14200 acct acct
20175 43946 0 0 3 0x14200 bored sosplice
95470 99007 33871 0 3 0x2000082 thrsleep syz-fuzzer
95470 150643 33871 0 2 0x6000482 syz-fuzzer
95470 503980 33871 0 3 0x6000082 wait syz-fuzzer
95470 122049 33871 0 3 0x6000082 wait syz-fuzzer
95470 156772 33871 0 3 0x6000082 thrsleep syz-fuzzer
95470 418854 33871 0 3 0x6000082 wait syz-fuzzer
95470 192916 33871 0 3 0x6000082 wait syz-fuzzer
95470 158703 33871 0 3 0x6000082 wait syz-fuzzer
95470 165426 33871 0 3 0x6000082 thrsleep syz-fuzzer
95470 403927 33871 0 3 0x6000082 wait syz-fuzzer
95470 370498 33871 0 3 0x6000082 thrsleep syz-fuzzer
95470 200970 33871 0 3 0x6000082 thrsleep syz-fuzzer
95470 262328 33871 0 3 0x6000082 wait syz-fuzzer
95470 20166 33871 0 3 0x6000082 kqread syz-fuzzer
95470 251245 33871 0 3 0x6000082 wait syz-fuzzer
95470 344870 33871 0 3 0x6000082 thrsleep syz-fuzzer
33871 67621 20196 0 3 0x10008a sigsusp ksh
20196 136958 90943 0 3 0x9a kqread sshd
90943 97488 1 0 3 0x88 kqread sshd
76916 201754 9681 74 3 0x1100092 bpf pflogd
9681 331201 1 0 3 0x80 netio pflogd
88246 178898 59170 73 3 0x1100090 kqread syslogd
59170 392623 1 0 3 0x100082 netio syslogd
33218 61524 1 0 3 0x100080 kqread resolvd
60588 512510 63749 77 3 0x100092 kqread dhcpleased
63914 125713 63749 77 3 0x100092 kqread dhcpleased
63749 493349 1 0 3 0x80 kqread dhcpleased
20366 468111 0 0 3 0x14200 bored smr
38255 309712 0 0 2 0x14200 zerothread
33632 515912 0 0 3 0x14200 aiodoned aiodoned
74643 179676 0 0 3 0x14200 syncer update
55073 64337 0 0 3 0x14200 cleaner cleaner
15788 328276 0 0 7 0x14200 reaper
12849 159064 0 0 3 0x14200 pgdaemon pagedaemon
96624 216734 0 0 3 0x14200 bored viomb
57730 522968 0 0 3 0x40014200 acpi0 acpi0
7671 187370 0 0 3 0x40014200 idle1
9642 219509 0 0 3 0x14200 bored softnet3
44521 47546 0 0 3 0x14200 bored softnet2
81550 474385 0 0 3 0x14200 bored softnet1
36188 457284 0 0 3 0x14200 bored softnet0
7719 208158 0 0 3 0x14200 bored systqmp
7760 289277 0 0 3 0x14200 bored systq
46616 523414 0 0 3 0x14200 tmoslp softclockmp
34832 206526 0 0 2 0x40014200 softclock
8393 291848 0 0 3 0x40014200 idle0
1 178687 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{0}> show all locks
Process 3391 (syz-executor.3) thread 0xffff80002a1c9ab0 (517432)
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10216 6503K 7202K 166960K 18996 0
pcb 15 18K 20K 166960K 423 0
rtable 252 15K 15K 166960K 911 0
pf 34 9K 10K 166960K 142 0
ifaddr 47 16K 16K 166960K 128 0
ifgroup 59 2K 2K 166960K 214 0
sysctl 4 1K 1K 166960K 8 0
counters 66 36K 36K 166960K 148 0
ioctlops 0 0K 4K 166960K 1685 0
iov 1 2K 24K 166960K 769 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1441 90K 91K 166960K 5630 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 9K 166960K 45 0
VM map 2 1K 1K 166960K 2 0
sem 12 1K 1K 166960K 13 0
dirhash 12 2K 2K 166960K 36 0
ACPI 1697 195K 286K 166960K 12548 0
file desc 15 53K 97K 166960K 6093 0
sigio 0 0K 0K 166960K 948 0
proc 73 91K 140K 166960K 1129 0
subproc 104 6K 6K 166960K 255 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 539 0
in_multi 100 7K 7K 166960K 243 0
ether_multi 1 0K 0K 166960K 5 0
mrt 1 0K 0K 166960K 5 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 97 440K 440K 166960K 97 0
exec 0 0K 1K 166960K 985 0
tdb 3 0K 0K 166960K 3 0
pagedep 1 8K 8K 166960K 1 0
inodedep 1 32K 32K 166960K 1 0
newblk 1 0K 0K 166960K 1 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 397 92K 105K 166960K 63343 0
UVM aobj 131 4K 4K 166960K 136 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 1K 166960K 1975 0
NDP 13 0K 1K 166960K 92 0
temp 74 5932K 6064K 166960K 28585 0
kqueue 12 18K 26K 166960K 396 0
SYN cache 2 16K 16K 166960K 2 0
ddb{0}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 24 0 0 1 0 1 1 0 8 0
rtpcb 120 327 0 324 6 5 1 3 0 8 0
rtentry 112 257 0 141 4 0 4 4 0 8 0
unpcb 144 4559 0 4542 66 65 1 6 0 8 0
syncache 312 62 0 62 11 11 0 1 0 8 0
sackhl 24 3 0 3 1 1 0 1 0 8 0
tcpqe 32 200 0 200 9 9 0 1 0 8 0
tcpcb 808 5801 0 5786 105 98 7 15 0 8 3
arp 120 49 0 28 1 0 1 1 0 8 0
inpcb 368 8304 0 8285 110 104 6 14 0 8 3
nd6 136 63 0 36 1 0 1 1 0 8 0
pkpcb 40 4 0 4 2 2 0 1 0 8 0
kcovpl 48 19 0 11 1 0 1 1 0 8 0
ppxss 1256 12 0 12 5 5 0 1 0 8 0
pffrag 232 3 0 3 1 1 0 1 0 482 0
pffrnode 88 3 0 3 1 1 0 1 0 8 0
pffrent 40 11 0 11 2 2 0 1 0 8 0
pfosfp 40 1428 0 1005 5 0 5 5 0 8 0
pfosfpen 112 1428 0 714 21 0 21 21 0 8 0
pfstitem 24 174 0 158 1 0 1 1 0 8 0
pfstkey 128 174 0 158 2 0 2 2 0 8 0
pfstate 376 174 0 158 5 2 3 4 0 8 0
pfrule 1344 21 0 16 2 1 1 2 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 986 0 514 40 10 30 30 0 8 0
art_table 32 987 0 514 4 0 4 4 0 8 0
art_node 16 254 0 149 1 0 1 1 0 8 0
sysvmsgpl 40 12 0 8 1 0 1 1 0 8 0
semupl 112 3 0 3 1 1 0 1 0 8 0
semapl 112 10 0 0 1 0 1 1 0 8 0
shmpl 112 133 0 5 4 0 4 4 0 8 0
dirhash 1024 33 0 16 3 0 3 3 0 8 0
dino2pl 256 10638 0 9170 93 0 93 93 0 8 0
ffsino 272 10638 0 9170 99 0 99 99 0 8 0
nchpl 144 19333 0 17673 64 0 64 64 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 72329 0 72329 6 5 1 2 0 8 1
percpumem 16 88 0 41 1 0 1 1 0 8 0
vcpupl 2048 13 0 1 2 0 2 2 0 8 0
vmpool 696 15 0 3 2 0 2 2 0 8 0
kstatmem 264 108 0 82 2 0 2 2 0 8 0
scxspl 216 56784 0 56784 21 20 1 8 1 8 1
plimitpl 152 910 0 894 1 0 1 1 0 8 0
sigapl 424 6599 0 6529 16 7 9 9 0 8 0
futexpl 64 54576 0 54572 1 0 1 1 0 8 0
knotepl 120 846 0 0 20 2 18 18 0 8 0
kqueuepl 216 982 0 974 16 15 1 7 0 8 0
pipepl 320 3412 0 3384 79 76 3 13 0 8 0
fdescpl 496 6379 0 6351 10 6 4 5 0 8 0
filepl 152 54813 0 54532 97 79 18 22 0 8 6
lockfpl 104 2101 0 2098 6 5 1 2 0 8 0
lockfspl 48 710 0 707 1 0 1 1 0 8 0
sessionpl 144 36 0 19 1 0 1 1 0 8 0
pgrppl 48 259 0 242 1 0 1 1 0 8 0
ucredpl 104 9899 0 9883 1 0 1 1 0 8 0
zombiepl 144 6531 0 6529 1 0 1 1 0 8 0
processpl 1072 6599 0 6529 5 0 5 5 0 8 0
procpl 680 17871 0 17774 12 3 9 10 0 8 0
srpgc 96 21 0 21 8 8 0 1 0 8 0
sosppl 168 54 0 54 6 5 1 1 0 8 1
sockpl 488 13205 0 13166 294 284 10 33 0 8 4
mcl64k 65536 19 0 0 3 1 2 3 0 8 0
mcl16k 16384 17 0 0 3 0 3 3 0 8 0
mcl12k 12288 17 0 0 2 0 2 2 0 8 0
mcl9k 9216 12 0 0 1 0 1 1 0 8 0
mcl8k 8192 18 0 0 3 0 3 3 0 8 0
mcl4k 4096 33 0 0 3 0 3 3 0 8 0
mcl2k2 2112 7 0 0 1 0 1 1 0 8 0
mcl2k 2048 323 0 0 38 6 32 38 0 8 0
mtagpl 96 214 0 0 5 0 5 5 0 8 0
mbufpl 256 1308 0 0 69 0 69 69 0 8 0
bufpl 288 14270 0 7946 453 1 452 453 0 8 0
anonpl 24 834356 0 815474 197 82 115 136 0 186 0
amapchunkpl 152 199842 0 198909 67 27 40 46 0 158 0
amappl16 200 22126 0 21470 122 87 35 47 0 8 0
amappl15 192 26 0 24 1 0 1 1 0 8 0
amappl14 184 214 0 199 2 1 1 2 0 8 0
amappl13 176 46 0 45 1 0 1 1 0 8 0
amappl12 168 7223 0 7195 4 2 2 3 0 8 0
amappl11 160 57 0 43 1 0 1 1 0 8 0
amappl10 152 50 0 37 1 0 1 1 0 8 0
amappl9 144 346 0 346 1 0 1 1 0 8 1
amappl8 136 407 0 310 5 1 4 4 0 8 0
amappl7 128 227 0 198 2 0 2 2 0 8 0
amappl6 120 479 0 469 1 0 1 1 0 8 0
amappl5 112 203 0 192 1 0 1 1 0 8 0
amappl4 104 573 0 543 2 1 1 2 0 8 0
amappl3 96 38863 0 38778 3 0 3 3 0 8 0
amappl2 88 7206 0 7127 3 1 2 3 0 8 0
amappl1 80 31948 0 31388 23 9 14 23 0 8 0
amappl 88 62483 0 62239 9 2 7 7 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 135 0 5 3 0 3 3 0 8 0
uaddrrnd 24 6394 0 6354 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 6394 0 6354 1 0 1 1 0 8 0
vmmpekpl 168 61161 0 61095 4 0 4 4 0 8 0
vmmpepl 168 402866 0 400247 237 117 120 136 0 357 0
vmsppl 464 6393 0 6353 7 1 6 6 0 8 0
rwobjpl 56 114095 0 106240 117 5 112 112 0 8 0
pdppl 4096 12796 0 12718 397 315 82 86 0 8 4
pvpl 32 45422 0 0 367 0 367 367 0 265 0
pmappl 248 6393 0 6353 4 1 3 3 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 1459 0 561 27 0 27 27 0 8 0
ddb{0}> machine ddbcpu 0
Invalid cpu 0
ddb{0}> trace
db_enter() at db_enter+0x1c sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff827ef3ea) at panic+0x17b sys/kern/subr_prf.c:198
ffs_blkfree(fffffd8066fa2de0,3,4000) at ffs_blkfree+0xa42 sys/ufs/ffs/ffs_alloc.c:1296
ffs_indirtrunc(fffffd8066fa2de0,fffffffffffffff4,e3b20,ffffffffffffffff,0,ffff8000374c2458) at ffs_indirtrunc+0x65d sys/ufs/ffs/ffs_inode.c:543
ffs_truncate(fffffd8066fa2de0,0,0,ffffffffffffffff) at ffs_truncate+0xfa5 sys/ufs/ffs/ffs_inode.c:335
ufs_inactive(ffff8000374c2618) at ufs_inactive+0x152 sys/ufs/ufs/ufs_inode.c:84
VOP_INACTIVE(fffffd8067a49c00,ffff80002a1c9ab0) at VOP_INACTIVE+0xc5 sys/kern/vfs_vops.c:489
vrele(fffffd8067a49c00) at vrele+0xd3 sys/kern/vfs_subr.c:827
ktrsettrace(ffffffff82d936c0,80001419,fffffd80659a12d0,fffffd807f7d6680) at ktrsettrace+0xb7 sys/kern/kern_ktrace.c:122
ktrops(ffff80002a1c9ab0,ffffffff82d936c0,0,80001419,fffffd80659a12d0,fffffd807f7d6680) at ktrops+0x1a8 sys/kern/kern_ktrace.c:564
doktrace(fffffd80659a12d0,0,1419,0,ffff80002a1c9ab0) at doktrace+0xeb sys/kern/kern_ktrace.c:510
sys_ktrace(ffff80002a1c9ab0,ffff8000374c29b0,ffff8000374c2a00) at sys_ktrace+0xd6 sys/kern/kern_ktrace.c:549
syscall(ffff8000374c2a60) at syscall+0x42c sys/arch/amd64/amd64/trap.c:591
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xd280d686bd0, count: -14
ddb{0}> machine ddbcpu 1
Stopped at x86_ipi_db+0x1e: addq $0x8,%rsp
x86_ipi_db(ffff800029d2bff0) at x86_ipi_db+0x1e sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__mp_lock(ffffffff82ca58a8) at __mp_lock+0x122 __mp_lock_spin sys/kern/kern_lock.c:116 [inline]
__mp_lock(ffffffff82ca58a8) at __mp_lock+0x122 sys/kern/kern_lock.c:147
uvm_unmap_detach(ffff80002a1922c0,1) at uvm_unmap_detach+0x113 sys/uvm/uvm_map.c:1382
uvm_map_teardown(fffffd806efba748) at uvm_map_teardown+0x2f5 sys/uvm/uvm_map.c:2585
uvmspace_free(fffffd806efba748) at uvmspace_free+0xa6 sys/uvm/uvm_map.c:3503
reaper(ffff80002a1867f0) at reaper+0x19a sys/kern/kern_exit.c:458
end trace frame: 0x0, count: 7
ddb{1}> trace
x86_ipi_db(ffff800029d2bff0) at x86_ipi_db+0x1e sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__mp_lock(ffffffff82ca58a8) at __mp_lock+0x122 __mp_lock_spin sys/kern/kern_lock.c:116 [inline]
__mp_lock(ffffffff82ca58a8) at __mp_lock+0x122 sys/kern/kern_lock.c:147
uvm_unmap_detach(ffff80002a1922c0,1) at uvm_unmap_detach+0x113 sys/uvm/uvm_map.c:1382
uvm_map_teardown(fffffd806efba748) at uvm_map_teardown+0x2f5 sys/uvm/uvm_map.c:2585
uvmspace_free(fffffd806efba748) at uvmspace_free+0xa6 sys/uvm/uvm_map.c:3503
reaper(ffff80002a1867f0) at reaper+0x19a sys/kern/kern_exit.c:458
end trace frame: 0x0, count: -8


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Apr 11, 2024, 4:56:18 PMApr 11
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages