uvm_fault: kcov_remote_enter (2)

0 views
Skip to first unread message

syzbot

unread,
Mar 28, 2024, 2:02:24 AMMar 28
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 2ee472d028ec Support having bcmpcie(4) as both PCIe bus an..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1092e1e9180000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=3662f77b0d675dc35988

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/3251cdf9a375/disk-2ee472d0.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/45f17e008029/bsd-2ee472d0.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c7513241ff7c/kernel-2ee472d0.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3662f7...@syzkaller.appspotmail.com

uvm_fault(0xffffffff82d44868, 0xffff80002a186000, 0, 2) -> e
kernel: page fault trap, code=2
Stopped at kcov_remote_enter+0x122: movq $0,0(%rcx)
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*210125 59625 0 0 0 0 syz-executor.5
kcov_remote_enter(0,ffff8000ffff8c98) at kcov_remote_enter+0x122 sys/dev/kcov.c:675
timeout_run(ffff80002a604e18) at timeout_run+0x84 sys/kern/kern_timeout.c:664
softclock_process_tick_timeout(ffff80002a604e18,0) at softclock_process_tick_timeout+0x19b sys/kern/kern_timeout.c:723
softclock(0) at softclock+0x139 sys/kern/kern_timeout.c:755
softintr_dispatch(0) at softintr_dispatch+0xc1 sys/arch/amd64/amd64/softintr.c:90
Xsoftclock() at Xsoftclock+0x27
end of kernel
end trace frame: 0x7d935ff27130, count: 9
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
*cpu0: uvm_fault(0xffffffff82d44868, 0xffff80002a186000, 0, 2) -> e
ddb> trace
kcov_remote_enter(0,ffff8000ffff8c98) at kcov_remote_enter+0x122 sys/dev/kcov.c:675
timeout_run(ffff80002a604e18) at timeout_run+0x84 sys/kern/kern_timeout.c:664
softclock_process_tick_timeout(ffff80002a604e18,0) at softclock_process_tick_timeout+0x19b sys/kern/kern_timeout.c:723
softclock(0) at softclock+0x139 sys/kern/kern_timeout.c:755
softintr_dispatch(0) at softintr_dispatch+0xc1 sys/arch/amd64/amd64/softintr.c:90
Xsoftclock() at Xsoftclock+0x27
end of kernel
end trace frame: 0x7d935ff27130, count: -6
ddb> show registers
rdi 0xffffffff
rsi 0xffff8000006a8a00
rbp 0xffff800035dd31c0
rbx 0x7ffee249
rdx 0xffff80002a699ab0
rcx 0xffff80002a186000
rax 0xfffffd8067462f00
r8 0
r9 0
r10 0x8282837393eeebee
r11 0xcd6060dcf30139a1
r12 0xffff80002a604d58
r13 0xffffffff82ca5ff0 cpu_info_full_primary+0x1ff0
r14 0xffff8000ffff8c98
r15 0
rip 0xffffffff815d1242 kcov_remote_enter+0x122
cs 0x8
rflags 0x10297 __ALIGN_SIZE+0xf297
rsp 0xffff800035dd31a0
ss 0
kcov_remote_enter+0x122: movq $0,0(%rcx)
ddb> show proc
PROC (syz-executor.5) tid=210125 pid=59625 tcnt=2 stat=onproc
flags process=0 proc=0
runpri=67, usrpri=67, slppri=17, nice=20
wchan=0x0, wmesg=, ps_single=0x0
forw=0xffffffffffffffff, list=0xffff80002a6d1298,0xffff80002a6982d8
process=0xffff800035e0b688 user=0xffff800035dce000, vmspace=0xfffffd807e2992e0
estcpu=36, cpticks=2, pctcpu=0.0, user=1, sys=0, intr=1
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
70960 166129 30398 0 2 0 syz-executor.2
*59625 210125 10138 0 7 0 syz-executor.5
59625 390303 10138 0 2 0x4000000 syz-executor.5
89232 437032 83113 0 2 0 syz-executor.4
89232 271303 83113 0 2 0x4000000 syz-executor.4
61620 395061 55068 0 2 0 syz-executor.6
61620 67425 55068 0 3 0x4000080 fsleep syz-executor.6
84805 378181 82571 0 2 0 syz-executor.7
84805 377493 82571 0 2 0x4000000 syz-executor.7
91214 235156 30346 0 2 0 syz-executor.1
91214 478733 30346 0 3 0x4000080 fsleep syz-executor.1
14917 385166 79153 0 2 0 syz-executor.0
14917 218070 79153 0 3 0x4000080 kqread syz-executor.0
30398 158235 63609 0 2 0x2 syz-executor.2
55068 520268 63609 0 3 0x82 nanoslp syz-executor.6
69481 219635 63609 0 2 0x2 syz-executor.3
83113 90092 63609 0 3 0x82 nanoslp syz-executor.4
81123 411909 0 0 3 0x14200 bored sosplice
82571 67066 63609 0 2 0x482 syz-executor.7
10138 14726 63609 0 3 0x82 nanoslp syz-executor.5
79153 85336 63609 0 3 0x82 nanoslp syz-executor.0
30346 316058 63609 0 3 0x82 nanoslp syz-executor.1
63609 164506 19374 0 3 0x1a000082 wait syz-fuzzer
63609 379878 19374 0 3 0x1e000082 nanoslp syz-fuzzer
63609 454701 19374 0 3 0x1e000082 thrsleep syz-fuzzer
63609 43369 19374 0 3 0x1e000082 wait syz-fuzzer
63609 192666 19374 0 3 0x1e000082 wait syz-fuzzer
63609 117732 19374 0 3 0x1e000082 wait syz-fuzzer
63609 477447 19374 0 3 0x1e000082 wait syz-fuzzer
63609 335426 19374 0 3 0x1e000082 thrsleep syz-fuzzer
63609 224706 19374 0 3 0x1e000082 wait syz-fuzzer
63609 134993 19374 0 3 0x1e000082 thrsleep syz-fuzzer
63609 393708 19374 0 3 0x1e000082 wait syz-fuzzer
63609 239799 19374 0 3 0x1e000082 kqread syz-fuzzer
63609 245939 19374 0 3 0x1e000082 wait syz-fuzzer
63609 75077 19374 0 3 0x1e000082 thrsleep syz-fuzzer
19374 504889 31567 0 3 0x810008a sigsusp ksh
31567 456384 60680 0 3 0x1800009a kqread sshd
68066 275431 1 0 3 0x18100083 ttyin getty
60680 461749 1 0 3 0x18000088 kqread sshd
95504 179788 29667 73 3 0x19100090 kqread syslogd
29667 195001 1 0 3 0x18100082 netio syslogd
2168 45209 1 0 3 0x18100080 kqread resolvd
40220 512261 85398 77 3 0x18100092 kqread dhcpleased
41120 396288 85398 77 3 0x18100092 kqread dhcpleased
85398 501761 1 0 3 0x18000080 kqread dhcpleased
21741 362558 0 0 3 0x14200 bored smr
34755 340255 0 0 2 0x14200 zerothread
2874 510190 0 0 3 0x14200 aiodoned aiodoned
89910 304180 0 0 3 0x14200 syncer update
95403 116053 0 0 3 0x14200 cleaner cleaner
75404 265948 0 0 3 0x14200 reaper reaper
27294 58987 0 0 3 0x14200 pgdaemon pagedaemon
54213 300043 0 0 3 0x14200 bored viomb
71731 74239 0 0 3 0x40014200 acpi0 acpi0
86185 65376 0 0 3 0x14200 bored softnet3
94654 317418 0 0 3 0x14200 bored softnet2
14039 67736 0 0 3 0x14200 bored softnet1
32397 230364 0 0 3 0x14200 bored softnet0
96369 151788 0 0 3 0x14200 bored systqmp
36681 508795 0 0 3 0x14200 bored systq
48670 321756 0 0 3 0x40014200 tmoslp softclock
99495 314421 0 0 3 0x40014200 idle0
1 157772 0 0 3 0x8000082 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10218 6550K 6929K 166960K 16833 0
pcb 15 12K 13K 166960K 118 0
rtable 210 6K 6K 166960K 1009 0
pf 29 8K 9K 166960K 94 0
ifaddr 40 11K 11K 166960K 110 0
ifgroup 50 2K 2K 166960K 149 0
counters 30 17K 17K 166960K 61 0
ioctlops 0 0K 2K 166960K 113 0
iov 0 0K 20K 166960K 387 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1661 104K 105K 166960K 3406 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 9K 166960K 32 0
VM map 2 1K 1K 166960K 2 0
sem 12 0K 0K 166960K 535 0
dirhash 12 2K 2K 166960K 27 0
ACPI 1697 195K 286K 166960K 12548 0
file desc 17 61K 73K 166960K 2772 0
sigio 0 0K 0K 166960K 51 0
proc 58 59K 75K 166960K 774 0
subproc 104 6K 6K 166960K 208 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 104 0
in_multi 88 6K 7K 166960K 232 0
ether_multi 1 0K 0K 166960K 1 0
mrt 1 0K 0K 166960K 4 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 91 413K 413K 166960K 91 0
exec 0 0K 1K 166960K 699 0
pfkey data 0 0K 0K 166960K 5 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 354 214K 214K 166960K 27290 0
UVM aobj 131 4K 4K 166960K 131 0
pinsyscall 22 44K 100K 166960K 1448 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 0K 166960K 88 0
NDP 11 0K 1K 166960K 77 0
temp 75 6806K 6888K 166960K 16335 0
kqueue 14 22K 28K 166960K 244 0
SYN cache 2 16K 16K 166960K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 96 0 93 1 0 1 1 0 8 0
rtentry 112 330 0 232 4 1 3 4 0 8 0
unpcb 144 1674 0 1661 6 0 6 6 0 8 5
syncache 336 19 0 19 2 1 1 1 0 8 1
tcpqe 32 645 0 645 2 1 1 1 0 8 1
tcpcb 808 865 0 860 14 6 8 8 0 8 7
arp 88 48 0 32 1 0 1 1 0 8 0
ipq 40 2 0 2 1 0 1 1 0 8 1
ipqe 40 6 0 6 1 0 1 1 0 8 1
inpcb 360 2021 0 2010 14 5 9 9 0 8 7
nd6 104 51 0 30 1 0 1 1 0 8 0
pkpcb 40 21 0 21 1 0 1 1 0 8 1
kcovpl 48 16 0 8 1 0 1 1 0 8 0
ppxss 1072 14 0 14 2 1 1 1 0 8 1
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 1002 0 585 31 4 27 29 0 8 0
art_table 32 1003 0 585 4 0 4 4 0 8 0
art_node 16 262 0 173 1 0 1 1 0 8 0
sysvmsgpl 40 52 0 12 1 0 1 1 0 8 0
semapl 112 532 0 522 1 0 1 1 0 8 0
shmpl 112 128 0 0 4 0 4 4 0 8 0
dirhash 1024 27 0 10 3 0 3 3 0 8 0
dino2pl 256 5591 0 4070 96 0 96 96 0 8 0
ffsino 240 5591 0 4070 90 0 90 90 0 8 0
nchpl 144 9799 0 8073 66 0 66 66 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 32639 0 32639 4 2 2 2 0 8 2
vcpupl 2048 21 0 0 3 0 3 3 0 8 0
vmpool 664 30 0 9 2 0 2 2 0 8 0
kstatmem 264 84 0 62 2 0 2 2 0 8 0
scxspl 216 30037 0 30037 11 7 4 8 1 8 4
plimitpl 152 206 0 191 1 0 1 1 0 8 0
sigapl 424 3052 0 3007 6 0 6 6 0 8 0
futexpl 64 25686 0 25684 1 0 1 1 0 8 0
knotepl 120 29326 0 29029 16 4 12 16 0 8 3
kqueuepl 184 525 0 515 4 0 4 4 0 8 3
pipepl 288 648 0 619 10 0 10 10 0 8 7
fdescpl 432 3034 0 3006 4 0 4 4 0 8 0
filepl 120 19017 0 18773 19 4 15 15 0 8 5
lockfpl 104 847 0 844 2 0 2 2 0 8 1
lockfspl 48 232 0 229 1 0 1 1 0 8 0
sessionpl 144 31 0 15 1 0 1 1 0 8 0
pgrppl 48 115 0 99 1 0 1 1 0 8 0
ucredpl 104 3113 0 3102 1 0 1 1 0 8 0
zombiepl 144 3007 0 3007 1 0 1 1 0 8 1
processpl 1072 3052 0 3007 4 0 4 4 0 8 0
procpl 680 6861 0 6797 8 1 7 7 0 8 1
sosppl 168 37 0 37 1 0 1 1 0 8 1
sockpl 488 3815 0 3791 53 41 12 22 0 8 9
mcl64k 65536 144 0 144 2 1 1 1 0 8 1
mcl16k 16384 63 0 63 2 1 1 1 0 8 1
mcl12k 12288 108 0 108 2 1 1 1 0 8 1
mcl9k 9216 63 0 63 2 1 1 1 0 8 1
mcl8k 8192 273 0 273 2 1 1 1 0 8 1
mcl4k 4096 295 0 295 2 1 1 1 0 8 1
mcl2k2 2112 13 0 13 2 1 1 1 0 8 1
mcl2k 2048 74870 0 74702 61 31 30 33 0 8 8
mtagpl 96 757 0 324 16 0 16 16 0 8 4
mbufpl 256 141589 0 140971 102 48 54 95 0 8 7
bufpl 280 10081 0 3745 453 0 453 453 0 8 0
anonpl 24 422187 0 408524 115 4 111 111 0 188 22
amapchunkpl 152 97478 0 96627 49 1 48 48 0 158 12
amappl16 200 10225 0 9792 39 8 31 36 0 8 7
amappl15 192 39 0 38 1 0 1 1 0 8 0
amappl14 184 172 0 162 2 1 1 2 0 8 0
amappl13 176 12 0 12 1 1 0 1 0 8 0
amappl12 168 3770 0 3742 2 0 2 2 0 8 0
amappl11 160 51 0 41 1 0 1 1 0 8 0
amappl10 152 48 0 40 1 0 1 1 0 8 0
amappl9 144 194 0 193 1 0 1 1 0 8 0
amappl8 136 191 0 139 2 0 2 2 0 8 0
amappl7 128 66 0 52 1 0 1 1 0 8 0
amappl6 120 447 0 428 2 1 1 2 0 8 0
amappl5 112 260 0 247 1 0 1 1 0 8 0
amappl4 104 601 0 567 2 1 1 2 0 8 0
amappl3 96 17623 0 17542 3 0 3 3 0 8 0
amappl2 88 3600 0 3528 4 1 3 4 0 8 0
amappl1 80 19317 0 18836 21 10 11 21 0 8 0
amappl 88 26595 0 26373 6 0 6 6 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 130 0 0 3 0 3 3 0 8 0
uaddrrnd 24 3064 0 3015 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 3064 0 3015 1 0 1 1 0 8 0
vmmpekpl 168 24385 0 24320 4 0 4 4 0 8 0
vmmpepl 168 200059 0 197828 152 26 126 126 0 357 23
vmsppl 352 3063 0 3015 5 0 5 5 0 8 0
rwobjpl 24 59175 0 51708 46 0 46 46 0 8 0
pdppl 4096 6134 0 6051 233 148 85 87 0 8 2
pvpl 32 1057541 0 1038383 398 203 195 362 0 265 33
pmappl 216 3063 0 3015 3 0 3 3 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 669 0 247 13 0 13 13 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
kcov_remote_enter(0,ffff8000ffff8c98) at kcov_remote_enter+0x122 sys/dev/kcov.c:675
timeout_run(ffff80002a604e18) at timeout_run+0x84 sys/kern/kern_timeout.c:664
softclock_process_tick_timeout(ffff80002a604e18,0) at softclock_process_tick_timeout+0x19b sys/kern/kern_timeout.c:723
softclock(0) at softclock+0x139 sys/kern/kern_timeout.c:755
softintr_dispatch(0) at softintr_dispatch+0xc1 sys/arch/amd64/amd64/softintr.c:90
Xsoftclock() at Xsoftclock+0x27
end of kernel
end trace frame: 0x7d935ff27130, count: -6
ddb> machine ddbcpu 1
No such command
ddb> trace
kcov_remote_enter(0,ffff8000ffff8c98) at kcov_remote_enter+0x122 sys/dev/kcov.c:675
timeout_run(ffff80002a604e18) at timeout_run+0x84 sys/kern/kern_timeout.c:664
softclock_process_tick_timeout(ffff80002a604e18,0) at softclock_process_tick_timeout+0x19b sys/kern/kern_timeout.c:723
softclock(0) at softclock+0x139 sys/kern/kern_timeout.c:755
softintr_dispatch(0) at softintr_dispatch+0xc1 sys/arch/amd64/amd64/softintr.c:90
Xsoftclock() at Xsoftclock+0x27
end of kernel
end trace frame: 0x7d935ff27130, count: -6


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages