pool: cpu free list modified: mbufpl (4)

0 views
Skip to first unread message

syzbot

unread,
Apr 15, 2024, 4:42:21 PMApr 15
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7019ae976ad9 Run raw IP input in parallel.
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=16614367180000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=daecb1649911bafa9776

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/493fc62c8c8e/disk-7019ae97.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/2247efe5d319/bsd-7019ae97.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/cb27b5845795/kernel-7019ae97.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+daecb1...@syzkaller.appspotmail.com

panic: pool_cache_item_magic_check: mbufpl cpu free list modified: item addr 0xfffffd8066255200+16 0x0!=0x9d08f969c9bdb95d
Stopped at db_enter+0x1c: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
* 11477 5205 0 0x1a000002 0x4000000 1 syz-fuzzer
122505 94007 0 0x14000 0x200 0 softnet0
db_enter() at db_enter+0x1c sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff8284c656) at panic+0x17b sys/kern/subr_prf.c:198
pool_cache_get(ffffffff82e2e178) at pool_cache_get+0x302
pool_get(ffffffff82e2e178,1) at pool_get+0x96 sys/kern/subr_pool.c:573
m_gethdr(1,1) at m_gethdr+0x67 sys/kern/uipc_mbuf.c:276
m_getuio(ffff80002a209fa0,0,43af,ffff80002a20a0f8) at m_getuio+0xa4 sys/kern/uipc_socket.c:706
sosend(ffff800010fd4fa0,0,ffff80002a20a0f8,0,0,80) at sosend+0x524 sys/kern/uipc_socket.c:660
dofilewritev(ffff80002a1aece8,6,ffff80002a20a0f8,0,ffff80002a20a1b0) at dofilewritev+0x1a9 sys/kern/sys_generic.c:375
sys_write(ffff80002a1aece8,ffff80002a20a260,ffff80002a20a1b0) at sys_write+0x87 sys/kern/sys_generic.c:295
syscall(ffff80002a20a260) at syscall+0x8cf mi_syscall sys/sys/syscall_mi.h:180 [inline]
syscall(ffff80002a20a260) at syscall+0x8cf sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x2bfdb9590, count: 4
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages