panic: bad arg kind: <nil> (3)

0 views
Skip to first unread message

syzbot

unread,
Jan 8, 2020, 6:50:10 PM1/8/20
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 81aacb2f Skip fdplock when freeing a file descriptor table..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=122b85c6e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link: https://syzkaller.appspot.com/bug?extid=673e4ce7c40c0a5e6f39

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+673e4c...@syzkaller.appspotmail.com

panic: bad arg kind: <nil>

goroutine 24 [running]:
github.com/google/syzkaller/prog.clone(0x0, 0x0, 0xc00056f770,
0xc002234450, 0xc002221940)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/clone.go:79 +0x954
github.com/google/syzkaller/prog.(*Prog).Clone(0xc000119c80, 0x8f4571)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/clone.go:24 +0x279
github.com/google/syzkaller/prog.resourceCentric(0xcb4120, 0xc001f465a0,
0xc0020a1340, 0x8f1501, 0xc00056f9f0, 0x448dce, 0xc001dff030)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/rand.go:817 +0xbf
github.com/google/syzkaller/prog.(*ResourceType).generate(0xcb4120,
0xc0020a1340, 0xc001f465a0, 0x40, 0x879220, 0xc0020a12e0, 0xc000040380,
0x40)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/rand.go:650 +0x920
github.com/google/syzkaller/prog.(*randGen).generateArgImpl(0xc0020a1340,
0xc001f465a0, 0x9ae620, 0xcb4120, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/rand.go:643 +0x506
github.com/google/syzkaller/prog.(*randGen).generateArg(...)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/rand.go:592
github.com/google/syzkaller/prog.(*randGen).generateArgs(0xc0020a1340,
0xc001f465a0, 0xca6bc0, 0x4, 0x4, 0xc00056fd40, 0x4eeea3, 0xc001954000,
0x4ad6cb3222d8bacb, 0xc00056fd68, ...)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/rand.go:580 +0x107
github.com/google/syzkaller/prog.(*randGen).generateParticularCall(0xc0020a1340,
0xc001f465a0,
0xceae80, 0x6, 0xc001f465a0, 0xc002086740)
/syzkaller/gopath/src/github.com/google/syzkaller/prog/rand.go:524 +0xc6


OpenBSD/amd64 (ci-openbsd-main-7.c.syzkaller.internal) (tty00)

login: kernel: protection fault trap, code=0
Stopped at in_delmulti+0x8d: movl 0xc(%r14),%r15d
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
the kernel did not panic
ddb> trace
in_delmulti(ffbffffffeffffff) at in_delmulti+0x8d sys/netinet/in.c:914
in_purgeaddr(ffff800000a02800) at in_purgeaddr+0x156 sys/netinet/in.c:760
in_ifdetach(ffff8000009ef800) at in_ifdetach+0x74 sys/netinet/in.c:969
if_detach(ffff8000009ef800) at if_detach+0x140 sys/net/if.c:1151
tun_clone_destroy(ffff8000009ef800) at tun_clone_destroy+0x14c
sys/net/if_tun.c:320
spec_close(ffff80001d41fde0) at spec_close+0x311 sys/kern/spec_vnops.c:555
VOP_CLOSE(fffffd8062aead00,7,fffffd806c3bea80,ffff8000ffff84f8) at
VOP_CLOSE+0xc0 sys/kern/vfs_vops.c:175
vn_closefile(fffffd8055e7cd30,ffff8000ffff84f8) at vn_closefile+0xd3
vn_close sys/kern/vfs_vnops.c:298 [inline]
vn_closefile(fffffd8055e7cd30,ffff8000ffff84f8) at vn_closefile+0xd3
sys/kern/vfs_vnops.c:610
fdrop(fffffd8055e7cd30,ffff8000ffff84f8) at fdrop+0xc2
sys/kern/kern_descrip.c:1271
closef(fffffd8055e7cd30,ffff8000ffff84f8) at closef+0x118
sys/kern/kern_descrip.c:1255
fdfree(ffff8000ffff84f8) at fdfree+0x100 sys/kern/kern_descrip.c:1187
exit1(ffff8000ffff84f8,0,d,1) at exit1+0x334 sys/kern/kern_exit.c:196
postsig(ffff8000ffff84f8,d) at postsig+0x4a8 sigexit
sys/kern/kern_sig.c:1476 [inline]
postsig(ffff8000ffff84f8,d) at postsig+0x4a8 sys/kern/kern_sig.c:1408
userret(ffff8000ffff84f8) at userret+0x159 sys/kern/kern_sig.c:1866
syscall(ffff80001d420260) at syscall+0x42e mi_syscall_return
sys/sys/syscall_mi.h:115 [inline]
syscall(ffff80001d420260) at syscall+0x42e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe0930, count: -16
ddb> show registers
rdi 0x2
rsi 0
rbp 0xffff80001d41fc10
rbx 0
rdx 0x3
rcx 0x1
rax 0
r8 0xffff800000a02800
r9 0x5
r10 0x9e016ccf8c01eb00
r11 0x5e38eaf7db06ea70
r12 0
r13 0x3
r14 0xffbffffffeffffff
r15 0x1
rip 0xffffffff813d2b9d in_delmulti+0x8d
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80001d41fbb0
ss 0x10
in_delmulti+0x8d: movl 0xc(%r14),%r15d
ddb> show proc
PROC (syz-executor.0) pid=141434 stat=onproc
flags process=a<EXEC,EXITING> proc=2000<WEXIT>
pri=50, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff4778,0xffff8000ffff2028
process=0xffff80001d39a6d8 user=0xffff80001d41b000,
vmspace=0xfffffd806bc09330
estcpu=36, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
33763 373137 0 0 3 0x14200 bored sosplice
6178 241276 79507 0 2 0x12 sshd
82204 99662 1 0 3 0x100083 ttyin getty
79507 140841 1 0 3 0x80 select sshd
61135 186862 16383 73 3 0x100090 kqread syslogd
16383 368105 1 0 3 0x100082 netio syslogd
99650 509910 1 77 2 0x100010 dhclient
58367 466636 1 0 3 0x80 poll dhclient
62495 342978 0 0 2 0x14200 zerothread
44669 47619 0 0 3 0x14200 aiodoned aiodoned
30368 492557 0 0 3 0x14200 syncer update
41028 60738 0 0 3 0x14200 cleaner cleaner
32394 382006 0 0 3 0x14200 reaper reaper
91211 317903 0 0 3 0x14200 pgdaemon pagedaemon
61638 412181 0 0 3 0x14200 bored crynlk
72662 436929 0 0 3 0x14200 bored crypto
29727 305248 0 0 3 0x40014200 acpi0 acpi0
93184 397995 0 0 2 0x14200 softnet
14755 149697 0 0 2 0x14200 systqmp
94658 341486 0 0 3 0x14200 bored systq
17721 383093 0 0 2 0x40014200 softclock
52438 65815 0 0 3 0x40014200 idle0
36747 494652 0 0 3 0x14200 bored smr
1 462199 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9480 6335K 7040K 78643K 10972 0
pcb 13 8K 8K 78643K 29 0
rtable 80 3K 4K 78643K 231 0
ifaddr 56 11K 13K 78643K 88 0
counters 19 16K 16K 78643K 19 0
ioctlops 0 0K 2K 78643K 19 0
iov 0 0K 16K 78643K 27 0
mount 1 1K 1K 78643K 1 0
vnodes 1221 77K 77K 78643K 1328 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 4 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 0K 78643K 43 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 2 4K 25K 78643K 147 0
proc 49 38K 63K 78643K 372 0
subproc 7 0K 2K 78643K 34 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 1K 78643K 33 0
in_multi 34 1K 2K 78643K 51 0
ether_multi 1 0K 0K 78643K 2 0
mrt 0 0K 0K 78643K 2 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 43 201K 201K 78643K 43 0
exec 0 0K 1K 78643K 185 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 61 10K 21K 78643K 1189 0
UVM aobj 20 2K 2K 78643K 20 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 8 0
NDP 9 0K 0K 78643K 17 0
temp 78 2999K 3076K 78643K 8346 0
kqueue 2 2K 18K 78643K 42 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 6 0 4 1 0 1 1 0
8 0
rtpcb 80 19 0 17 1 0 1 1 0
8 0
rtentry 112 46 0 16 2 0 2 2 0
8 0
unpcb 120 75 0 67 1 0 1 1 0
8 0
syncache 264 4 0 4 1 1 0 1 0
8 0
tcpqe 32 58 0 58 1 1 0 1 0
8 0
tcpcb 544 56 0 52 1 0 1 1 0
8 0
inpcb 280 297 0 291 2 1 1 2 0
8 0
rttmr 72 1 0 1 1 1 0 1 0
8 0
nd6 48 4 0 2 1 0 1 1 0
8 0
pkpcb 40 2 0 2 1 1 0 1 0
8 0
ppxss 1128 3 0 3 2 1 1 1 0
8 1
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 213 0 43 14 0 14 14 0
8 1
art_table 32 214 0 43 2 0 2 2 0
8 0
art_node 16 45 0 14 1 0 1 1 0
8 0
sysvmsgpl 40 26 0 19 1 0 1 1 0
8 0
semupl 112 1 0 1 1 1 0 1 0
8 0
semapl 112 41 0 31 1 0 1 1 0
8 0
shmpl 112 18 0 0 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 1609 0 210 46 0 46 46 0
8 0
ffsino 240 1609 0 210 83 0 83 83 0
8 0
nchpl 144 2020 0 412 60 0 60 60 0
8 0
uvmvnodes 72 1736 0 0 32 0 32 32 0
8 0
vnodes 208 1736 0 0 92 0 92 92 0
8 0
namei 1024 5161 0 5161 1 0 1 1 0
8 1
scxspl 192 5532 0 5532 1 0 1 1 0
8 1
plimitpl 152 22 0 16 1 0 1 1 0
8 0
sigapl 432 318 0 309 2 0 2 2 0
8 0
futexpl 56 3433 0 3433 1 0 1 1 0
8 1
knotepl 112 104 0 99 1 0 1 1 0
8 0
kqueuepl 104 58 0 57 1 0 1 1 0
8 0
pipepl 112 210 0 204 1 0 1 1 0
8 0
fdescpl 432 319 0 309 2 0 2 2 0
8 0
filepl 120 2016 0 1966 4 0 4 4 0
8 1
lockfpl 104 36 0 35 1 0 1 1 0
8 0
lockfspl 48 17 0 16 1 0 1 1 0
8 0
sessionpl 112 17 0 8 1 0 1 1 0
8 0
pgrppl 48 19 0 10 1 0 1 1 0
8 0
ucredpl 96 149 0 142 1 0 1 1 0
8 0
zombiepl 144 310 0 308 1 0 1 1 0
8 0
processpl 864 334 0 308 4 0 4 4 0
8 0
procpl 632 498 0 472 4 0 4 4 0
8 0
sockpl 384 398 0 382 5 2 3 4 0
8 1
mcl64k 65536 11 0 11 2 1 1 1 0
8 1
mcl16k 16384 1 0 1 1 1 0 1 0
8 0
mcl12k 12288 2 0 2 1 1 0 1 0
8 0
mcl9k 9216 2 0 2 1 1 0 1 0
8 0
mcl8k 8192 8 0 8 2 1 1 1 0
8 1
mcl4k 4096 28 0 28 3 2 1 1 0
8 1
mcl2k 2048 60817 0 60773 15 9 6 13 0
8 0
mtagpl 80 9 0 4 2 1 1 1 0
8 0
mbufpl 256 97094 0 96994 12 3 9 9 0
8 1
bufpl 280 6370 0 1326 361 0 361 361 0
8 0
anonpl 16 46704 0 45567 74 1 73 73 0 107
59
amapchunkpl 152 1331 0 1296 7 1 6 7 0
158 3
amappl16 192 1602 0 1595 50 0 50 50 0 8
47
amappl15 184 50 0 46 1 0 1 1 0
8 0
amappl14 176 91 0 91 1 0 1 1 0
8 1
amappl13 168 9 0 8 1 0 1 1 0
8 0
amappl12 160 6 0 6 1 1 0 1 0
8 0
amappl11 152 47 0 36 1 0 1 1 0
8 0
amappl10 144 13 0 13 1 0 1 1 0
8 1
amappl9 136 593 0 590 1 0 1 1 0
8 0
amappl8 128 156 0 152 1 0 1 1 0
8 0
amappl7 120 92 0 84 1 0 1 1 0
8 0
amappl6 112 54 0 51 1 0 1 1 0
8 0
amappl5 104 170 0 162 1 0 1 1 0
8 0
amappl4 96 538 0 511 1 0 1 1 0
8 0
amappl3 88 181 0 173 1 0 1 1 0
8 0
amappl2 80 1754 0 1701 3 1 2 3 0
8 0
amappl1 72 15401 0 15040 25 15 10 20 0
8 0
amappl 80 724 0 705 2 1 1 2 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 19 0 0 1 0 1 1 0
8 0
uaddrrnd 24 319 0 309 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 319 0 309 1 0 1 1 0
8 0
vmmpekpl 168 6266 0 6247 2 0 2 2 0
8 0
vmmpepl 168 45622 0 44835 105 13 92 101 0 357
46
vmsppl 272 318 0 309 2 1 1 2 0
8 0
pdppl 4096 644 0 618 6 1 5 6 0
8 0
pvpl 32 152255 0 149536 179 0 179 179 0 265
144
pmappl 200 318 0 309 1 0 1 1 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 148 0 21 4 0 4 4 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Anton Lindqvist

unread,
Jan 9, 2020, 3:12:21 AM1/9/20
to syzbot, syzkaller-o...@googlegroups.com
#syz invalid
Reply all
Reply to author
Forward
0 new messages