panic: wakeup: p_stat is NUM (4)

1 view
Skip to first unread message

syzbot

unread,
Mar 17, 2024, 9:02:18 PMMar 17
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 1eb3d403c0b9 Annotate RSA-PSS SHA parameter encoding as wr..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10eeee31180000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=b111765c6b8b0192d64d

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d98fc0d3e081/disk-1eb3d403.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/8c6bb4d95ce9/bsd-1eb3d403.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/aca86263a813/kernel-1eb3d403.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b11176...@syzkaller.appspotmail.com

panic: wakeup: p_stat is 0
Stopped at db_enter+0x1c: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq kernel: double fault trap, code=0
Stopped at splraise+0x19: pushq %r14
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
uvm_fault(0xfffffd80698ecb10, 0x6759602cf0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at db_show_all_procs+0x210: movq 0x20(%r13),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
SeaBIOS (version 1.8.2-google)
Total RAM Size = 0x0000000080000000 = 2048 MiB
CPUs found: 2 Max CPUs supported: 2
SeaBIOS (version 1.8.2-google)
Machine UUID 1498d526-897b-4d0e-28be-a262cd523d51
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0 removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f27f0: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Sending Seabios boot VM event.
Booting from Hard Disk 0...
>> OpenBSD/amd64 BOOT 3.65
boot> set $maxwidth = 0
set: syntax error
boot> show panic
boot: illegal argument panic
boot> trace
boot> show registers
boot> show proc
boot> ps
boot> show all locks
boot> show malloc
boot> show all pools
boot> machine ddbcpu 0
machine: syntax error
boot> trace
boot> machine ddbcpu 1
machine: syntax error
boot> trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages