uvm_fault: _bpf_mtap

2 views
Skip to first unread message

syzbot

unread,
Nov 29, 2018, 4:45:04 PM11/29/18
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 25236b556a2d sync
git tree: https://github.com/openbsd/src.git master
console output: https://syzkaller.appspot.com/x/log.txt?x=167fec25400000
dashboard link: https://syzkaller.appspot.com/bug?extid=34cebddd84b99fe1f3b6
compiler:

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+34cebd...@syzkaller.appspotmail.com

uvm_fault(0xffffffff81eb72b0, 0x6000118, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at _bpf_mtap+0x68: movl 0x18(%rbx),%r13d


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

Greg Steuck

unread,
Dec 4, 2018, 12:27:58 AM12/4/18
to syzbot+34cebd...@syzkaller.appspotmail.com, syzkaller-o...@googlegroups.com
There's another hit with better diagnostics now.

Looks like the mbuf chain is broken: 
1260 for (m0 = m; m0 != NULL; m0 = m0->m_next)
1261 pktlen += m0->m_len;

/syzkaller/managers/main/kernel/sys/net/bpf.c:1260
    29a0:       e8 00 00 00 00          callq  29a5 <_bpf_mtap+0x65>
                        29a1: R_X86_64_PC32     __sanitizer_cov_trace_pc+0xfffffffffffffffc
    29a5:       4c 89 e8                mov    %r13,%rax
    29a8:       44 8b 6b 18             mov    0x18(%rbx),%r13d     # rbx=0x6000100    __kernel_end_phys+0x4000100
    29ac:       49 01 c5                add    %rax,%r13
/syzkaller/managers/main/kernel/sys/net/bpf.c:1260
    29af:       48 8b 1b                mov    (%rbx),%rbx
    29b2:       48 85 db                test   %rbx,%rbx
    29b5:       75 e9                   jne    29a0 <_bpf_mtap+0x60>



--
You received this message because you are subscribed to the Google Groups "syzkaller-openbsd-bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-openbsd...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-openbsd-bugs/00000000000062e63f057bd498da%40google.com.
For more options, visit https://groups.google.com/d/optout.


--
nest.cx is Gmail hosted, use PGP for anything private. Key: http://goo.gl/6dMsr
Fingerprint: 5E2B 2D0E 1E03 2046 BEC3  4D50 0B15 42BD 8DF5 A1B0

syzbot

unread,
Jun 19, 2019, 7:03:04 PM6/19/19
to gr...@nest.cx, syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages