kernel: protection fault trap, code=NUM (5)

1 view
Skip to first unread message

syzbot

unread,
Aug 28, 2022, 3:11:33 AM8/28/22
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 293c01dc0e68 Remove unused mutex.
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=106869db080000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=bf39e70d1ce19c1c751b

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+bf39e7...@syzkaller.appspotmail.com

exclusive kernel: protection fault trap, code=0
Faulted in DDB; continuing...
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10200 6410K 6419K 78643K 11303 0
pcb 13 10K 12K 78643K 15 0
rtable 240 6K 7K 78643K 534 0
ifaddr 82 16K 16K 78643K 112 0
sysctl 2 0K 2K 78643K 5 0
counters 56 35K 35K 78643K 64 0
ioctlops 0 0K 2K 78643K 157 0
iov 0 0K 20K 78643K 866 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1271 79K 79K 78643K 2333 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 9K 78643K 61 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 794 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 22 81K 125K 78643K 4277 0
sigio 0 0K 0K 78643K 101 0
proc 56 78K 103K 78643K 765 0
subproc 104 6K 6K 78643K 156 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 482 0
in_multi 99 6K 7K 78643K 179 0
ether_multi 1 0K 0K 78643K 5 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 181 811K 811K 78643K 181 0
exec 0 0K 2K 78643K 1146 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 8 62K 62K 78643K 8 0
UVM amap 278 83K 96K 78643K 27041 0
UVM aobj 131 8K 8K 78643K 144 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 130 0
NDP 11 0K 2K 78643K 39 0
temp 124 4726K 4792K 78643K 13548 0
kqueue 12 18K 28K 78643K 589 0
SYN cache 2 16K 16K 78643K 2 0
ddb{0}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 22 0 0 1 0 1 1 0 8 0
rtpcb 120 207 0 204 2 1 1 2 0 8 0
rtentry 112 159 0 46 4 0 4 4 0 8 0
unpcb 144 4149 0 4134 31 26 5 10 0 8 4
syncache 296 50 0 50 11 10 1 1 0 8 1
tcpqe 32 80 0 80 9 8 1 1 0 8 1
tcpcb 768 2860 0 2837 61 53 8 14 0 8 5
arp 120 27 0 8 1 0 1 1 0 8 0
ipq 40 2 0 1 2 1 1 1 0 8 0
ipqe 40 7 0 6 2 1 1 1 0 8 0
inpcb 368 4602 0 4587 61 58 3 14 0 8 1
nd6 48 39 0 13 1 0 1 1 0 8 0
kcovpl 48 12 0 4 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 656 0 189 30 0 30 30 0 8 0
art_table 32 657 0 189 4 0 4 4 0 8 0
art_node 16 158 0 55 1 0 1 1 0 8 0
sysvmsgpl 40 22 0 14 1 0 1 1 0 8 0
semupl 112 6 0 6 1 1 0 1 0 8 0
semapl 112 792 0 782 1 0 1 1 0 8 0
shmpl 112 141 0 13 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 7311 0 5876 91 0 91 91 0 8 0
ffsino 272 7311 0 5876 97 0 97 97 0 8 0
nchpl 144 13085 0 11449 63 0 63 63 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 42418 0 42418 4 3 1 2 0 8 1
percpumem 16 44 0 4 1 0 1 1 0 8 0
kstatmem 264 30 0 8 2 0 2 2 0 8 0
scxspl 216 44254 0 44254 17 16 1 6 0 8 1
plimitpl 152 936 0 914 4 3 1 2 0 8 0
sigapl 424 4554 0 4502 7 0 7 7 0 8 0
futexpl 64 37375 0 37375 5 4 1 1 0 8 1
knotepl 120 457 0 0 10 0 10 10 0 8 0
kqueuepl 216 3986 0 3978 43 34 9 12 0 8 8
pipepl 320 1478 0 1450 31 21 10 13 0 8 7
fdescpl 496 4536 0 4503 7 2 5 6 0 8 0
filepl 152 34329 0 34090 67 50 17 20 0 8 7
lockfpl 104 702 0 700 1 0 1 1 0 8 0
lockfspl 48 188 0 186 1 0 1 1 0 8 0
sessionpl 144 27 0 11 1 0 1 1 0 8 0
pgrppl 48 43 0 27 1 0 1 1 0 8 0
ucredpl 104 5437 0 5419 1 0 1 1 0 8 0
zombiepl 144 4503 0 4502 1 0 1 1 0 8 0
processpl 1064 4554 0 4502 5 1 4 5 0 8 0
procpl 672 12799 0 12729 13 5 8 9 0 8 1
sosppl 168 68 0 68 6 6 0 1 0 8 0
sockpl 488 9079 0 9050 159 147 12 34 0 8 8
mcl64k 65536 25 0 0 3 0 3 3 0 8 0
mcl16k 16384 18 0 0 3 0 3 3 0 8 0
mcl12k 12288 17 0 0 2 0 2 2 0 8 0
mcl9k 9216 14 0 0 1 0 1 1 0 8 0
mcl8k 8192 26 0 0 4 1 3 3 0 8 0
mcl4k 4096 25 0 0 4 0 4 4 0 8 0
mcl2k2 2112 3 0 0 1 0 1 1 0 8 0
mcl2k 2048 345 0 0 43 1 42 43 0 8 2
mtagpl 96 4 0 0 1 0 1 1 0 8 0
mbufpl 256 474 0 0 24 0 24 24 0 8 0
bufpl 288 10920 0 4590 453 0 453 453 0 8 0
anonpl 24 896657 0 884407 149 52 97 110 0 186 3
amapchunkpl 152 79138 0 78547 79 42 37 40 0 158 10
amappl16 200 12655 0 12270 73 41 32 37 0 8 8
amappl15 192 1393 0 1384 1 0 1 1 0 8 0
amappl14 184 1304 0 1294 1 0 1 1 0 8 0
amappl13 176 352 0 350 1 0 1 1 0 8 0
amappl12 168 197 0 194 1 0 1 1 0 8 0
amappl11 160 422 0 406 1 0 1 1 0 8 0
amappl10 152 511 0 507 1 0 1 1 0 8 0
amappl9 144 1050 0 1044 1 0 1 1 0 8 0
amappl8 136 770 0 675 4 0 4 4 0 8 0
amappl7 128 174 0 152 1 0 1 1 0 8 0
amappl6 120 800 0 779 2 1 1 2 0 8 0
amappl5 112 3920 0 3897 1 0 1 1 0 8 0
amappl4 104 1907 0 1871 3 1 2 3 0 8 0
amappl3 96 13850 0 13801 2 0 2 2 0 8 0
amappl2 88 873 0 840 2 1 1 2 0 8 0
amappl1 80 114930 0 114267 20 3 17 19 0 8 1
amappl 88 26340 0 26183 6 1 5 5 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 143 0 13 3 0 3 3 0 8 0
uaddrrnd 24 4536 0 4503 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 4536 0 4503 1 0 1 1 0 8 0
vmmpekpl 168 41976 0 41918 4 0 4 4 0 8 0
vmmpepl 168 444876 0 442348 171 36 135 140 0 357 10
vmsppl 368 4535 0 4503 4 0 4 4 0 8 0
rwobjpl 56 116764 0 109362 111 2 109 109 0 8 2
pdppl 4096 9079 0 9006 207 126 81 95 0 8 8
pvpl 32 1836889 0 1819615 344 152 192 242 0 265 30
pmappl 248 4535 0 4503 4 1 3 3 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 1035 0 191 25 0 25 25 0 8 0
ddb{0}> machine ddbcpu 0
Invalid cpu 0
ddb{0}> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff8257b2ef) at panic+0x177 sys/kern/subr_prf.c:198
tcp_output(ffff800000c59248) at tcp_output+0x2cd2 sys/netinet/tcp_output.c:727
tcp_send(fffffd8067c499a0,fffffd806d5a8100,0,fffffd80723e9800) at tcp_send+0xc4 sys/netinet/tcp_usrreq.c:953
sosend(fffffd8067c499a0,0,ffff80002e4d3590,0,fffffd80723e9800,0) at sosend+0x62a pru_send sys/sys/protosw.h:331 [inline]
sosend(fffffd8067c499a0,0,ffff80002e4d3590,0,fffffd80723e9800,0) at sosend+0x62a sys/kern/uipc_socket.c:646
sendit(ffff800029606d30,8,ffff80002e4d3710,0,ffff80002e4d3800) at sendit+0x65d sys/kern/uipc_syscalls.c:694
sys_sendmsg(ffff800029606d30,ffff80002e4d37b8,ffff80002e4d3800) at sys_sendmsg+0x198 sys/kern/uipc_syscalls.c:601
syscall(ffff80002e4d3880) at syscall+0x4c3 mi_syscall sys/sys/syscall_mi.h:101 [inline]
syscall(ffff80002e4d3880) at syscall+0x4c3 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xc21bc41d30, count: -9
ddb{0}> machine ddbcpu 1
Stopped at x86_ipi_db+0x1a: addq $0x8,%rsp
x86_ipi_db(ffff800020dd8ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
alltraps_kern_meltdown() at alltraps_kern_meltdown+0x68
savectx() at savectx+0xae
end of kernel
end trace frame: 0x7f7ffffeaf20, count: 10
ddb{1}> trace
x86_ipi_db(ffff800020dd8ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
alltraps_kern_meltdown() at alltraps_kern_meltdown+0x68
savectx() at savectx+0xae
end of kernel
end trace frame: 0x7f7ffffeaf20, count: -5


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Greg Steuck

unread,
Aug 29, 2022, 11:02:29 AM8/29/22
to syzbot, syzkaller-o...@googlegroups.com
#syz dup: panic: tcp_output

--
You received this message because you are subscribed to the Google Groups "syzkaller-openbsd-bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-openbsd...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-openbsd-bugs/0000000000005e44d005e747db1d%40google.com.


--
nest.cx is Gmail hosted, use PGP: https://pgp.key-server.io/0x0B1542BD8DF5A1B0
Fingerprint: 5E2B 2D0E 1E03 2046 BEC3  4D50 0B15 42BD 8DF5 A1B0
Reply all
Reply to author
Forward
0 new messages