Hello,
syzbot found the following crash on:
HEAD commit: df989dde Fix line numbers - commands are added after the l..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=150e49bca00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=7f659e47e42d9641
dashboard link:
https://syzkaller.appspot.com/bug?extid=bdc489ecb509995a21ed
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+bdc489...@syzkaller.appspotmail.com
login: uvm_fault(0xfffffd807f00c708, 0x110, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at mrt6_ioctl+0xa2: movl 0x110(%r12),%r15d
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
kernel page fault
uvm_fault(0xfffffd807f00c708, 0x110, 0, 1) -> e
mrt6_ioctl(fffffd806f691480,c028756b,ffff800025015870) at mrt6_ioctl+0xa2
get_mif6_cnt sys/netinet6/ip6_mroute.c:306 [inline]
mrt6_ioctl(fffffd806f691480,c028756b,ffff800025015870) at mrt6_ioctl+0xa2
sys/netinet6/ip6_mroute.c:256
end trace frame: 0xffff800025015970, count: 0
ddb{1}> trace
mrt6_ioctl(fffffd806f691480,c028756b,ffff800025015870) at mrt6_ioctl+0xa2
get_mif6_cnt sys/netinet6/ip6_mroute.c:306 [inline]
mrt6_ioctl(fffffd806f691480,c028756b,ffff800025015870) at mrt6_ioctl+0xa2
sys/netinet6/ip6_mroute.c:256
sys_ioctl(ffff800020b38720,ffff800025015998,ffff800025015a00) at
sys_ioctl+0x5b8
syscall(ffff800025015a70) at syscall+0x552 mi_syscall
sys/sys/syscall_mi.h:99 [inline]
syscall(ffff800025015a70) at syscall+0x552 sys/arch/amd64/amd64/trap.c:574
Xsyscall(6,0,ffffffffffffff62,0,3,19117eee010) at Xsyscall+0x128
end of kernel
end trace frame: 0x193961109f0, count: -4
ddb{1}> show registers
rdi 0xffffffff810ae2c9 spllower+0x79
rsi 0xf1
rbp 0xffff800025015860
rbx 0xffff80000066e000
rdx 0xf2
rcx 0xffff800022dde000
rax 0xd
r8 0xffffffff81937b14 mrt6_ioctl+0x44
r9 0x7
r10 0xc050756a
r11 0x3841d13d6ec03992
r12 0
r13 0x28
r14 0xffff800025015870
r15 0xc028756b
rip 0xffffffff81937b72 mrt6_ioctl+0xa2
cs 0x8
rflags 0x10286 __ALIGN_SIZE+0xf286
rsp 0xffff800025015800
ss 0x10
mrt6_ioctl+0xa2: movl 0x110(%r12),%r15d
ddb{1}> show proc
PROC (syz-executor.0) pid=378865 stat=onproc
flags process=10<SUGID> proc=4000000<THREAD>
pri=70, usrpri=70, nice=20
forw=0xffffffffffffffff, list=0xffff800020b39530,0xffffffff82374f30
process=0xffff800020b3ad30 user=0xffff800025010000,
vmspace=0xfffffd807f00c708
estcpu=36, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
44751 128013 92345 32767 7 0x10 syz-executor.0
*44751 378865 92345 32767 7 0x4000010 syz-executor.0
92345 15313 35636 32767 3 0x90 nanosleep syz-executor.0
35636 178297 59853 0 3 0x82 wait syz-executor.0
87164 108766 10471 32767 3 0x90 nanosleep syz-executor.1
10471 472154 59853 0 3 0x82 wait syz-executor.1
19740 197191 0 0 3 0x14200 bored sosplice
59853 82058 53383 0 3 0x82 thrsleep syz-fuzzer
59853 267446 53383 0 3 0x4000082 nanosleep syz-fuzzer
59853 68691 53383 0 3 0x4000082 thrsleep syz-fuzzer
59853 458644 53383 0 3 0x4000082 kqread syz-fuzzer
59853 287523 53383 0 3 0x4000082 thrsleep syz-fuzzer
59853 260543 53383 0 3 0x4000082 thrsleep syz-fuzzer
59853 510606 53383 0 3 0x4000082 thrsleep syz-fuzzer
59853 152154 53383 0 3 0x4000082 thrsleep syz-fuzzer
59853 442624 53383 0 3 0x4000082 thrsleep syz-fuzzer
59853 273348 53383 0 3 0x4000082 nanosleep syz-fuzzer
53383 101573 1772 0 3 0x10008a pause ksh
1772 87717 99023 0 3 0x92 select sshd
50635 272821 1 0 3 0x100083 ttyin getty
99023 234861 1 0 3 0x80 select sshd
43926 190775 10617 73 2 0x100090 syslogd
10617 258638 1 0 3 0x100082 netio syslogd
39757 365508 1 77 3 0x100090 poll dhclient
41825 20998 1 0 3 0x80 poll dhclient
3050 159660 0 0 3 0x14200 pgzero zerothread
74391 347891 0 0 3 0x14200 aiodoned aiodoned
46974 114636 0 0 3 0x14200 syncer update
53080 386907 0 0 3 0x14200 cleaner cleaner
26295 411093 0 0 3 0x14200 reaper reaper
97191 166662 0 0 3 0x14200 pgdaemon pagedaemon
8398 480464 0 0 3 0x14200 bored crynlk
67573 188886 0 0 3 0x14200 bored crypto
47793 429029 0 0 3 0x40014200 acpi0 acpi0
47697 470226 0 0 3 0x40014200 idle1
55386 282199 0 0 3 0x14200 bored softnet
34298 367079 0 0 3 0x14200 bored systqmp
49958 180629 0 0 3 0x14200 bored systq
29471 284972 0 0 3 0x40014200 bored softclock
38066 155454 0 0 3 0x40014200 idle0
7617 217519 0 0 3 0x14200 bored smr
1 317336 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
Process 44751 (syz-executor.0) thread 0xffff800020b38720 (378865)
shared rwlock netlock r = 0 (0xffffffff821d55b8)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1161
#1 mrt6_ioctl+0x91 mrt6_iflookupbymif sys/netinet6/ip6_mroute.c:1182
[inline]
#1 mrt6_ioctl+0x91 get_mif6_cnt sys/netinet6/ip6_mroute.c:306 [inline]
#1 mrt6_ioctl+0x91 sys/netinet6/ip6_mroute.c:256
#2 sys_ioctl+0x5b8
#3 syscall+0x552 mi_syscall sys/sys/syscall_mi.h:99 [inline]
#3 syscall+0x552 sys/arch/amd64/amd64/trap.c:574
#4 Xsyscall+0x128
exclusive kernel_lock &kernel_lock r = 1 (0xffffffff82373c68)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1161
#1 syscall+0x43a mi_syscall sys/sys/syscall_mi.h:91 [inline]
#1 syscall+0x43a sys/arch/amd64/amd64/trap.c:574
#2 Xsyscall+0x128
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9459 6321K 6321K 78643K 10596 0 0
pcb 23 9K 10K 78643K 268 0 0
rtable 105 3K 3K 78643K 635 0 0
ifaddr 36 10K 10K 78643K 99 0 0
counters 39 33K 33K 78643K 39 0 0
ioctlops 0 0K 2K 78643K 38 0 0
iov 0 0K 16K 78643K 38 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1208 76K 76K 78643K 1470 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 5K 78643K 10 0 0
VM map 2 1K 1K 78643K 2 0 0
sem 12 0K 0K 78643K 32 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1808 196K 290K 78643K 12628 0 0
file desc 7 21K 33K 78643K 630 0 0
sigio 0 0K 0K 78643K 14 0 0
proc 41 38K 70K 78643K 742 0 0
subproc 34 2K 2K 78643K 204 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
ip_moptions 0 0K 0K 78643K 40 0 0
in_multi 33 2K 2K 78643K 149 0 0
ether_multi 1 0K 0K 78643K 2 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 54 238K 238K 78643K 54 0 0
exec 0 0K 1K 78643K 340 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 81 20K 30K 78643K 2701 0 0
UVM aobj 26 2K 2K 78643K 30 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
ip6_options 0 0K 0K 78643K 33 0 0
NDP 5 0K 0K 78643K 39 0 0
temp 98 2724K 2790K 78643K 5429 0 0
kqueue 0 0K 0K 78643K 13 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 26 0 20 1 0 1 1 0
8 0
inpcbpl 280 273 0 266 1 0 1 1 0
8 0
plimitpl 152 57 0 48 1 0 1 1 0
8 0
plcache 128 20 0 0 1 0 1 1 0
8 0
rtentry 112 155 0 111 2 0 2 2 0
8 0
syncache 264 4 0 4 1 1 0 1 0
8 0
tcpqe 32 4 0 4 1 1 0 1 0
8 0
tcpcb 544 105 0 100 1 0 1 1 0
8 0
nd6 48 36 0 30 1 0 1 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 636 0 448 12 0 12 12 0
8 0
art_table 32 637 0 448 2 0 2 2 0
8 0
art_node 16 154 0 114 1 0 1 1 0
8 0
sysvmsgpl 40 9 0 2 1 0 1 1 0
8 0
semapl 112 30 0 20 1 0 1 1 0
8 0
shmpl 112 28 0 4 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 2039 0 613 48 1 47 47 0
8 0
ffsino 272 2039 0 613 96 0 96 96 0
8 0
nchpl 144 2957 0 1338 61 0 61 61 0
8 0
uvmvnodes 72 2252 0 0 41 0 41 41 0
8 0
vnodes 200 2252 0 0 119 0 119 119 0
8 0
namei 1024 8877 0 8877 2 1 1 1 0
8 1
percpumem 16 30 0 0 1 0 1 1 0
8 0
scxspl 192 7471 0 7471 8 7 1 6 0
8 1
sigapl 432 771 0 756 3 1 2 3 0
8 0
futexpl 56 4231 0 4231 1 0 1 1 0
8 1
knotepl 112 353 0 334 1 0 1 1 0
8 0
kqueuepl 104 98 0 96 1 0 1 1 0
8 0
pipepl 112 446 0 427 3 2 1 2 0
8 0
fdescpl 488 772 0 756 3 0 3 3 0
8 0
filepl 152 3830 0 3733 6 1 5 5 0
8 1
lockfpl 104 117 0 117 2 1 1 1 0
8 1
lockfspl 48 39 0 39 2 1 1 1 0
8 1
sessionpl 112 27 0 17 1 0 1 1 0
8 0
pgrppl 48 31 0 21 1 0 1 1 0
8 0
ucredpl 96 859 0 850 1 0 1 1 0
8 0
zombiepl 144 756 0 755 2 1 1 1 0
8 0
processpl 840 788 0 755 4 0 4 4 0
8 0
procpl 600 1625 0 1582 5 1 4 5 0
8 0
srpgc 64 60 0 60 1 0 1 1 0
8 1
sosppl 128 4 0 4 2 2 0 1 0
8 0
sockpl 384 538 0 520 3 0 3 3 0
8 1
mcl64k 65536 3 0 0 1 0 1 1 0
8 0
mcl12k 12288 6 0 0 1 0 1 1 0
8 0
mcl9k 9216 3 0 0 1 0 1 1 0
8 0
mcl8k 8192 2 0 0 1 0 1 1 0
8 0
mcl4k 4096 4 0 0 1 0 1 1 0
8 0
mcl2k 2048 135 0 0 16 0 16 16 0
8 0
mtagpl 80 1 0 0 1 0 1 1 0
8 0
mbufpl 256 198 0 0 12 0 12 12 0
8 0
bufpl 256 6247 0 1160 318 0 318 318 0
8 0
anonpl 16 69820 0 64247 36 5 31 31 0
125 7
amapchunkpl 152 5134 0 5051 16 7 9 11 0
158 5
amappl16 192 2055 0 1765 19 2 17 17 0
8 2
amappl15 184 259 0 255 1 0 1 1 0
8 0
amappl14 176 293 0 285 2 1 1 1 0
8 0
amappl13 168 8 0 8 1 1 0 1 0
8 0
amappl12 160 84 0 83 1 0 1 1 0
8 0
amappl11 152 79 0 64 1 0 1 1 0
8 0
amappl10 144 149 0 146 1 0 1 1 0
8 0
amappl9 136 765 0 762 1 0 1 1 0
8 0
amappl8 128 324 0 307 1 0 1 1 0
8 0
amappl7 120 145 0 138 1 0 1 1 0
8 0
amappl6 112 70 0 61 1 0 1 1 0
8 0
amappl5 104 243 0 233 1 0 1 1 0
8 0
amappl4 96 651 0 625 1 0 1 1 0
8 0
amappl3 88 537 0 523 1 0 1 1 0
8 0
amappl2 80 4416 0 4346 4 2 2 3 0
8 0
amappl1 72 27223 0 26786 24 15 9 19 0
8 0
amappl 80 2000 0 1966 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 29 0 4 1 0 1 1 0
8 0
uaddrrnd 24 772 0 756 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 772 0 756 1 0 1 1 0
8 0
vmmpekpl 168 9666 0 9640 2 0 2 2 0
8 0
vmmpepl 168 89939 0 88571 95 28 67 74 0
357 7
vmsppl 360 771 0 756 2 0 2 2 0
8 0
pdppl 4096 1552 0 1512 6 0 6 6 0
8 0
pvpl 32 239407 0 230650 127 34 93 102 0 265
16
pmappl 232 771 0 756 2 1 1 2 0
8 0
extentpl 40 41 0 26 1 0 1 1 0
8 0
phpool 112 472 0 3 14 0 14 14 0
8 0
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.