Hello,
syzbot found the following crash on:
HEAD commit: 8864b422 Switch bpf to use pgsigio(9) and sigio_init(9) in..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=175d9615e00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link:
https://syzkaller.appspot.com/bug?extid=80754707234fc344c628
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+807547...@syzkaller.appspotmail.com
panic: unhandled af 152
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
* 41027 98377 0 0 0x4000000 0 syz-executor.1
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff821b8616) at panic+0x15c sys/kern/subr_prf.c:207
unhandled_af(98) at unhandled_af+0x16
pf_addrcpy(ffff80001d405ea8,ffff80001d4061a0,98) at pf_addrcpy+0x99
sys/net/pf.c:409
pfioctl(4900,c0504417,ffff80001d4061a0,1,ffff8000ffff33d8) at
pfioctl+0x43c0 sys/net/pf_ioctl.c:1827
VOP_IOCTL(fffffd805d5ba340,c0504417,ffff80001d4061a0,1,fffffd806c3be840,ffff8000ffff33d8)
at
VOP_IOCTL+0x88 sys/kern/vfs_vops.c:291
vn_ioctl(fffffd80636e62e0,c0504417,ffff80001d4061a0,ffff8000ffff33d8) at
vn_ioctl+0xb7 sys/kern/vfs_vnops.c:533
sys_ioctl(ffff8000ffff33d8,ffff80001d4062b8,ffff80001d406300) at
sys_ioctl+0x5b9
syscall(ffff80001d406380) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xa77f961b3f0, count: 5
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
unhandled af 152
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff821b8616) at panic+0x15c sys/kern/subr_prf.c:207
unhandled_af(98) at unhandled_af+0x16
pf_addrcpy(ffff80001d405ea8,ffff80001d4061a0,98) at pf_addrcpy+0x99
sys/net/pf.c:409
pfioctl(4900,c0504417,ffff80001d4061a0,1,ffff8000ffff33d8) at
pfioctl+0x43c0 sys/net/pf_ioctl.c:1827
VOP_IOCTL(fffffd805d5ba340,c0504417,ffff80001d4061a0,1,fffffd806c3be840,ffff8000ffff33d8)
at
VOP_IOCTL+0x88 sys/kern/vfs_vops.c:291
vn_ioctl(fffffd80636e62e0,c0504417,ffff80001d4061a0,ffff8000ffff33d8) at
vn_ioctl+0xb7 sys/kern/vfs_vnops.c:533
sys_ioctl(ffff8000ffff33d8,ffff80001d4062b8,ffff80001d406300) at
sys_ioctl+0x5b9
syscall(ffff80001d406380) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xa77f961b3f0, count: -10
ddb> show registers
rdi 0xffffffff81f91017 db_enter+0x17
rsi 0xb92
rbp 0xffff80001d405d60
rbx 0xffff80001d405e10
rdx 0xb93
rcx 0xffff80001f639000
rax 0xffff80001f639000
r8 0xffff80001d405d20
r9 0x1
r10 0xffff8000009edf40
r11 0xef4dac1713b2cd4a
r12 0x3000000008
r13 0xffff80001d405d70
r14 0x100
r15 0x1
rip 0xffffffff81f91018 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff80001d405d50
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor.1) pid=41027 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=82, usrpri=82, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff3b40,0xffff8000ffff3170
process=0xffff8000ffff6a48 user=0xffff80001d401000,
vmspace=0xfffffd8053388560
estcpu=36, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
98377 337770 39224 0 2 0 syz-executor.1
*98377 41027 39224 0 7 0x4000000 syz-executor.1
98377 41820 39224 0 3 0x4000080 fsleep syz-executor.1
78084 416440 99463 0 2 0x2 syz-executor.0
61772 190339 0 0 3 0x14200 acct acct
1682 110003 0 0 3 0x14200 bored sosplice
39224 124166 99463 0 3 0x82 nanosleep syz-executor.1
99463 64587 8780 0 3 0x82 thrsleep syz-fuzzer
99463 84374 8780 0 3 0x4000082 nanosleep syz-fuzzer
99463 459620 8780 0 3 0x4000082 thrsleep syz-fuzzer
99463 197157 8780 0 3 0x4000082 thrsleep syz-fuzzer
99463 167325 8780 0 3 0x4000082 thrsleep syz-fuzzer
99463 139377 8780 0 3 0x4000082 thrsleep syz-fuzzer
99463 49100 8780 0 3 0x4000082 thrsleep syz-fuzzer
99463 2668 8780 0 3 0x4000082 kqread syz-fuzzer
8780 483001 52009 0 3 0x10008a pause ksh
52009 142718 51481 0 3 0x92 select sshd
83534 505736 1 0 3 0x100083 ttyin getty
51481 47603 1 0 3 0x80 select sshd
39871 263840 73911 73 3 0x100090 kqread syslogd
73911 25437 1 0 3 0x100082 netio syslogd
9154 435282 1 77 3 0x100090 poll dhclient
7269 401620 1 0 3 0x80 poll dhclient
70949 521477 0 0 2 0x14200 zerothread
73620 435180 0 0 3 0x14200 aiodoned aiodoned
57483 242465 0 0 3 0x14200 syncer update
31312 186048 0 0 3 0x14200 cleaner cleaner
443 398032 0 0 3 0x14200 reaper reaper
33147 66309 0 0 3 0x14200 pgdaemon pagedaemon
68495 169710 0 0 3 0x14200 bored crynlk
44012 271908 0 0 3 0x14200 bored crypto
63111 189817 0 0 3 0x40014200 acpi0 acpi0
72556 422971 0 0 3 0x14200 bored softnet
7828 208864 0 0 3 0x14200 bored systqmp
96117 292552 0 0 3 0x14200 bored systq
91001 53239 0 0 3 0x40014200 bored softclock
58792 522044 0 0 3 0x40014200 idle0
63580 487335 0 0 3 0x14200 bored smr
1 471583 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9453 6332K 6978K 78643K 14784 0
pcb 13 8K 9K 78643K 1244 0
rtable 112 4K 4K 78643K 378 0
ifaddr 43 11K 12K 78643K 266 0
counters 19 16K 16K 78643K 19 0
ioctlops 0 0K 4K 78643K 1707 0
iov 0 0K 16K 78643K 162 0
mount 1 1K 1K 78643K 1 0
vnodes 1218 77K 77K 78643K 5543 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 57 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 0K 78643K 144 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 5 13K 25K 78643K 25211 0
sigio 0 0K 0K 78643K 101 0
proc 66 39K 63K 78643K 633 0
subproc 32 2K 2K 78643K 51 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 195 0
in_multi 33 2K 2K 78643K 88 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 49 228K 228K 78643K 49 0
exec 0 0K 1K 78643K 233 0
pfkey data 0 0K 0K 78643K 6 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 133 23K 23K 78643K 55576 0
UVM aobj 130 4K 4K 78643K 148 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 170 0
NDP 5 0K 0K 78643K 12 0
temp 105 3020K 3090K 78643K 307570 0
kqueue 0 0K 0K 78643K 107 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 8 0 2 1 0 1 1 0
8 0
rtpcb 80 29 0 27 1 0 1 1 0
8 0
rtentry 112 55 0 11 2 0 2 2 0
8 0
unpcb 120 57952 0 57944 26 24 2 3 0
8 1
syncache 264 4 0 4 1 1 0 1 0
8 0
sackhl 24 4 0 4 3 3 0 1 0
8 0
tcpcb 544 980 0 976 1 0 1 1 0
8 0
inpcb 280 10131 0 10124 14 12 2 2 0
8 1
nd6 48 6 0 2 1 0 1 1 0
8 0
pkpcb 40 570 0 570 3 3 0 1 0
8 0
pfrktable 1344 71 0 69 2 1 1 1 0
8 0
pftag 88 13 0 13 1 1 0 1 0
8 0
pfrule 1360 306 0 90 18 0 18 18 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 256 0 43 14 0 14 14 0
8 0
art_table 32 257 0 43 2 0 2 2 0
8 0
art_node 16 54 0 14 1 0 1 1 0
8 0
semupl 112 203 0 203 18 17 1 1 0
8 1
semapl 112 142 0 132 1 0 1 1 0
8 0
shmpl 112 146 0 18 4 0 4 4 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 33442 0 32009 47 0 47 47 0
8 0
ffsino 240 33442 0 32009 85 0 85 85 0
8 0
nchpl 144 65669 0 64004 63 0 63 63 0
8 0
uvmvnodes 72 5926 0 0 108 0 108 108 0
8 0
vnodes 208 5926 0 0 312 0 312 312 0
8 0
namei 1024 170277 0 170276 1 0 1 1 0
8 0
vcpupl 1984 2 0 1 1 0 1 1 0
8 0
vmpool 528 2 0 1 1 0 1 1 0
8 0
pfiaddrpl 120 24 0 15 1 0 1 1 0
8 0
scxspl 192 171809 0 171809 1 0 1 1 0
8 1
plimitpl 152 2540 0 2533 1 0 1 1 0
8 0
sigapl 432 25379 0 25366 2 0 2 2 0
8 0
futexpl 56 244016 0 244015 1 0 1 1 0
8 0
knotepl 112 531 0 512 1 0 1 1 0
8 0
kqueuepl 104 8618 0 8614 1 0 1 1 0
8 0
pipepl 112 2186 0 2167 1 0 1 1 0
8 0
fdescpl 424 25380 0 25366 2 0 2 2 0
8 0
filepl 120 148395 0 148283 39 34 5 6 0
8 1
lockfpl 104 2138 0 2137 1 0 1 1 0
8 0
lockfspl 48 939 0 938 1 0 1 1 0
8 0
sessionpl 112 18 0 8 1 0 1 1 0
8 0
pgrppl 48 3563 0 3553 1 0 1 1 0
8 0
ucredpl 96 14936 0 14925 1 0 1 1 0
8 0
zombiepl 144 25423 0 25423 1 0 1 1 0
8 1
processpl 872 25453 0 25423 4 0 4 4 0
8 0
procpl 632 52671 0 52632 4 0 4 4 0
8 0
sockpl 384 69205 0 69188 98 92 6 10 0
8 4
mcl64k 65536 142 0 142 21 21 0 1 0
8 0
mcl16k 16384 120 0 120 20 19 1 1 0
8 1
mcl12k 12288 435 0 435 28 28 0 1 0
8 0
mcl9k 9216 83 0 83 19 18 1 1 0
8 1
mcl8k 8192 567 0 567 29 28 1 1 0
8 1
mcl4k 4096 1270 0 1270 33 32 1 1 0
8 1
mcl2k2 2112 77 0 77 29 28 1 1 0
8 1
mcl2k 2048 50290 0 50250 18 12 6 11 0
8 0
mtagpl 80 2 0 2 1 1 0 1 0
8 0
mbufpl 256 206917 0 206835 17 7 10 11 0
8 2
bufpl 280 34894 0 28710 442 0 442 442 0
8 0
anonpl 16 1438531 0 1433729 35 14 21 34 0
107 0
amapchunkpl 152 80936 0 80848 10 5 5 6 0
158 1
amappl16 192 100963 0 100733 22 10 12 22 0
8 0
amappl15 184 60 0 56 1 0 1 1 0
8 0
amappl14 176 31 0 29 1 0 1 1 0
8 0
amappl13 168 8 0 7 1 0 1 1 0
8 0
amappl12 160 5 0 5 1 1 0 1 0
8 0
amappl11 152 102 0 89 1 0 1 1 0
8 0
amappl10 144 12603 0 12599 1 0 1 1 0
8 0
amappl9 136 13102 0 13097 1 0 1 1 0
8 0
amappl8 128 12833 0 12777 2 0 2 2 0
8 0
amappl7 120 12693 0 12677 1 0 1 1 0
8 0
amappl6 112 99 0 93 1 0 1 1 0
8 0
amappl5 104 287 0 277 1 0 1 1 0
8 0
amappl4 96 25664 0 25637 1 0 1 1 0
8 0
amappl3 88 661 0 654 1 0 1 1 0
8 0
amappl2 80 202492 0 202421 3 1 2 3 0
8 0
amappl1 72 419096 0 418663 26 16 10 20 0
8 0
amappl 80 52930 0 52895 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 147 0 18 3 0 3 3 0
8 0
uaddrrnd 24 25382 0 25367 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 25382 0 25367 1 0 1 1 0
8 0
vmmpekpl 168 111850 0 111828 2 0 2 2 0
8 0
vmmpepl 168 2829389 0 2828021 126 61 65 79 0
357 3
vmsppl 272 25381 0 25367 3 1 2 2 0
8 0
pdppl 4096 50770 0 50735 6 1 5 6 0
8 0
pvpl 32 4146859 0 4139505 241 178 63 115 0
265 1
pmappl 200 25381 0 25367 1 0 1 1 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 272 0 123 5 0 5 5 0
8 0
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.