assert "to_ticks >= NUM" failed in kern_timeout.c

3 views
Skip to first unread message

syzbot

unread,
Jul 29, 2024, 6:52:18 AM7/29/24
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: dd24756f1f82 The dash must not come first in the getopt(3)..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15b541c9980000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=f650785d4f2b3fe28284

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/31c455be5d32/disk-dd24756f.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/1f6540fa1697/bsd-dd24756f.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a0fe55b20aec/kernel-dd24756f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+f65078...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "to_ticks >= 0" failed: file "/syzkaller/managers/multicore/kernel/sys/kern/kern_timeout.c", line 300
Starting stack trace...
panic(ffffffff830d9281) at panic+0x1d0 sys/kern/subr_prf.c:229
__assert(ffffffff8308d65a,ffffffff8306ecf6,12c,ffffffff82fd87e1) at __assert+0x29
timeout_add(ffff80000121dd28,ffffff43) at timeout_add+0x2f7 sys/kern/kern_timeout.c:300
bpf_catchpacket(ffff80000121dc00,fffffd807ddad400,ef,ffffffff,ffff8000371b1040) at bpf_catchpacket+0x4bf sys/net/bpf.c:1646
_bpf_mtap(ffff80000124f700,fffffd807ddad400,fffffd807ddad400,1) at _bpf_mtap+0x321 sys/net/bpf.c:1416
if_vinput(ffff8000011c4000,fffffd807ddad400) at if_vinput+0xa7 sys/net/if.c:1026
tun_dev_write(5d00,ffff8000371b13d8,ffff800031f4e000,2) at tun_dev_write+0x301 sys/net/if_tun.c:914
spec_write(ffff8000371b1230) at spec_write+0x120 sys/kern/spec_vnops.c:302
VOP_WRITE(fffffd805b606e80,ffff8000371b13d8,11,fffffd807f7d3680) at VOP_WRITE+0x102 sys/kern/vfs_vops.c:245
vn_write(fffffd80681e61e0,ffff8000371b13d8,0) at vn_write+0x1d1 sys/kern/vfs_vnops.c:408
dofilewritev(ffff8000fffed700,c8,ffff8000371b13d8,0,ffff8000371b1490) at dofilewritev+0x23c sys/kern/sys_generic.c:375
sys_write(ffff8000fffed700,ffff8000371b1540,ffff8000371b1490) at sys_write+0xa2 sys/kern/sys_generic.c:295
syscall(ffff8000371b1540) at syscall+0xbb6 mi_syscall sys/sys/syscall_mi.h:179 [inline]
syscall(ffff8000371b1540) at syscall+0xbb6 sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7cb4f6472b0, count: 243
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages