pool: free list modified: art_heap4

0 views
Skip to first unread message

syzbot

unread,
Nov 26, 2019, 2:27:08 AM11/26/19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 943f8c8c simplify histogram code and cut off at < limit, a..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1020976ae00000
kernel config: https://syzkaller.appspot.com/x/.config?x=d0fe83f82fe104d4
dashboard link: https://syzkaller.appspot.com/bug?extid=e61a74552e65a7ae9143

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+e61a74...@syzkaller.appspotmail.com

panic: pool_do_get: art_heap4 free list modified: page 0xfffffd8029d95000;
item addr 0xfffffd8029d95000; offset 0x0=0x0 != 0x33773c11720e314c
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*125614 47675 0 0x2 0 0 ifconfig
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:207
pool_do_get(ffffffff8259a378,a,ffff800017931978) at pool_do_get+0x42a
sys/kern/subr_pool.c:746
pool_get(ffffffff8259a378,a) at pool_get+0xb5 sys/kern/subr_pool.c:581
art_table_get(ffff800000075a00,fffffd802dcbd968,1f) at art_table_get+0x12e
sys/net/art.c:722
art_insert(ffff800000075a00,fffffd8036d6bbe0,ffff800000a66fe8,80) at
art_insert+0x155 sys/net/art.c:387
rtable_insert(0,ffff800000a66fe0,0,ffff800000a66140,1,fffffd802a5ef698) at
rtable_insert+0x2b4 sys/net/rtable.c:554
rtrequest(1,ffff800017931c98,1,ffff800017931d68,0) at rtrequest+0x8be
sys/net/route.c:941
rt_ifa_add(ffff800000a95a00,240404,ffff800000a95a40,0) at rt_ifa_add+0x290
sys/net/route.c:1133
rt_ifa_addlocal(ffff800000a95a00) at rt_ifa_addlocal+0x149
sys/net/route.c:1242
in6_update_ifa(ffff800000a91800,ffff800017932020,0) at
in6_update_ifa+0x13bb sys/netinet6/in6.c:723
in6_ifattach_linklocal(ffff800000a91800,0) at in6_ifattach_linklocal+0x2a2
sys/netinet6/in6_ifattach.c:281
in6_ifattach(ffff800000a91800) at in6_ifattach+0x17e
sys/netinet6/in6_ifattach.c:400
ifnewlladdr(ffff800000a91800) at ifnewlladdr+0x119 sys/net/if.c:3127
end trace frame: 0xffff800017932260, count: 0
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
pool_do_get: art_heap4 free list modified: page 0xfffffd8029d95000; item
addr 0xfffffd8029d95000; offset 0x0=0x0 != 0x33773c11720e314c
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:207
pool_do_get(ffffffff8259a378,a,ffff800017931978) at pool_do_get+0x42a
sys/kern/subr_pool.c:746
pool_get(ffffffff8259a378,a) at pool_get+0xb5 sys/kern/subr_pool.c:581
art_table_get(ffff800000075a00,fffffd802dcbd968,1f) at art_table_get+0x12e
sys/net/art.c:722
art_insert(ffff800000075a00,fffffd8036d6bbe0,ffff800000a66fe8,80) at
art_insert+0x155 sys/net/art.c:387
rtable_insert(0,ffff800000a66fe0,0,ffff800000a66140,1,fffffd802a5ef698) at
rtable_insert+0x2b4 sys/net/rtable.c:554
rtrequest(1,ffff800017931c98,1,ffff800017931d68,0) at rtrequest+0x8be
sys/net/route.c:941
rt_ifa_add(ffff800000a95a00,240404,ffff800000a95a40,0) at rt_ifa_add+0x290
sys/net/route.c:1133
rt_ifa_addlocal(ffff800000a95a00) at rt_ifa_addlocal+0x149
sys/net/route.c:1242
in6_update_ifa(ffff800000a91800,ffff800017932020,0) at
in6_update_ifa+0x13bb sys/netinet6/in6.c:723
in6_ifattach_linklocal(ffff800000a91800,0) at in6_ifattach_linklocal+0x2a2
sys/netinet6/in6_ifattach.c:281
in6_ifattach(ffff800000a91800) at in6_ifattach+0x17e
sys/netinet6/in6_ifattach.c:400
ifnewlladdr(ffff800000a91800) at ifnewlladdr+0x119 sys/net/if.c:3127
ifioctl(fffffd8036ff9c00,8020691f,ffff800017932270,ffff8000ffff3b40) at
ifioctl+0x1b2e sys/net/if.c:2205
sys_ioctl(ffff8000ffff3b40,ffff800017932380,ffff8000179323d0) at
sys_ioctl+0x5b9
syscall(ffff800017932450) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffdec80, count: -18
ddb> show registers
rdi 0
rsi 0x1
rbp 0xffff8000179317e0
rbx 0xffff800017931890
rdx 0x2
rcx 0
rax 0
r8 0xffff8000179317a0
r9 0x1
r10 0
r11 0x8ab2fb2a4f47c626
r12 0x3000000008
r13 0xffff8000179317f0
r14 0x100
r15 0x1
rip 0xffffffff8127dee8 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff8000179317d0
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (ifconfig) pid=125614 stat=onproc
flags process=2<EXEC> proc=0
pri=50, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff2290,0xffffffff825b1098
process=0xffff8000ffff6d90 user=0xffff80001792d000,
vmspace=0xfffffd803f011330
estcpu=0, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
*47675 125614 97292 0 7 0x2 ifconfig
97292 214280 52032 0 2 0x100002 sh
52032 411867 59352 0 3 0x82 wait syz-executor.1
11715 466725 0 0 3 0x14200 bored sosplice
49708 3265 59352 0 3 0x82 piperd syz-executor.0
59352 202055 81359 0 3 0x82 thrsleep syz-fuzzer
59352 116241 81359 0 3 0x4000082 thrsleep syz-fuzzer
59352 202370 81359 0 3 0x4000082 thrsleep syz-fuzzer
59352 224146 81359 0 3 0x4000082 thrsleep syz-fuzzer
59352 230478 81359 0 3 0x4000082 kqread syz-fuzzer
59352 101325 81359 0 3 0x4000082 thrsleep syz-fuzzer
59352 35146 81359 0 3 0x4000082 thrsleep syz-fuzzer
59352 363538 81359 0 3 0x4000082 thrsleep syz-fuzzer
59352 52478 81359 0 3 0x4000082 thrsleep syz-fuzzer
81359 64032 89385 0 3 0x10008a pause ksh
89385 231842 85563 0 3 0x92 select sshd
26120 102918 1 0 3 0x100083 ttyin getty
85563 257398 1 0 3 0x80 select sshd
54845 429292 2405 73 3 0x100090 kqread syslogd
2405 12385 1 0 3 0x100082 netio syslogd
83311 153983 1 77 3 0x100090 poll dhclient
99579 184996 1 0 3 0x80 poll dhclient
25579 30605 0 0 2 0x14200 zerothread
56586 184809 0 0 3 0x14200 aiodoned aiodoned
91043 374972 0 0 3 0x14200 syncer update
7594 72413 0 0 3 0x14200 cleaner cleaner
10334 454210 0 0 3 0x14200 reaper reaper
63602 495284 0 0 3 0x14200 pgdaemon pagedaemon
28546 480977 0 0 3 0x14200 bored crynlk
12852 36624 0 0 3 0x14200 bored crypto
80100 42246 0 0 3 0x40014200 acpi0 acpi0
68876 155419 0 0 2 0x14200 softnet
31299 471157 0 0 2 0x14200 systqmp
97753 461310 0 0 3 0x14200 bored systq
19404 53149 0 0 3 0x40014200 bored softclock
48022 44054 0 0 3 0x40014200 idle0
14901 269463 0 0 3 0x14200 bored smr
1 56775 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9502 6351K 7060K 78643K 11026 0 0
pcb 13 8K 9K 78643K 271 0 0
rtable 88 3K 3K 78643K 258 0 0
ifaddr 71 13K 14K 78643K 99 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 19 0 0
iov 0 0K 16K 78643K 31 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1228 77K 77K 78643K 1374 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 5K 78643K 7 0 0
VM map 2 0K 0K 78643K 2 0 0
sem 12 0K 1K 78643K 65 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1794 195K 288K 78643K 12646 0 0
file desc 6 17K 25K 78643K 174 0 0
sigio 0 0K 0K 78643K 8 0 0
proc 55 46K 54K 78643K 423 0 0
subproc 32 2K 2K 78643K 51 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
ip_moptions 0 0K 0K 78643K 16 0 0
in_multi 37 1K 2K 78643K 62 0 0
ether_multi 1 0K 0K 78643K 1 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 48 212K 212K 78643K 48 0 0
exec 0 0K 1K 78643K 204 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 102 21K 22K 78643K 1225 0 0
UVM aobj 18 2K 2K 78643K 20 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
ip6_options 0 0K 0K 78643K 30 0 0
NDP 12 0K 0K 78643K 20 0 0
temp 112 3529K 3593K 78643K 4879 0 0
kqueue 0 0K 0K 78643K 2 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 6 0 2 1 0 1 1 0
8 0
rtpcb 80 27 0 25 1 0 1 1 0
8 0
rtentry 112 55 0 21 2 0 2 2 0
8 0
unpcb 120 83 0 75 1 0 1 1 0
8 0
syncache 264 4 0 4 1 1 0 1 0
8 0
tcpqe 32 73 0 73 1 1 0 1 0
8 0
tcpcb 544 54 0 50 1 0 1 1 0
8 0
ipq 40 2 0 2 1 1 0 1 0
8 0
ipqe 40 4 0 4 1 1 0 1 0
8 0
inpcb 280 396 0 388 2 0 2 2 0
8 1
nd6 48 6 0 5 1 0 1 1 0
8 0
ppxss 1128 1 0 1 1 0 1 1 0
8 1
art_heap8 4096 2 0 0 2 0 2 2 0
8 0
art_heap4 256 282 0 82 15 0 15 15 0
8 2
art_heap4: pool(0xffffffff8259a378:art_heap4): free list modified: page
0xfffffd8029d95000; item ordinal 0; addr 0xfffffd8029d95000 (p
0xfffffd802d9f8000); offset 0x0=0x0
pool(art_heap4): free list modified: page 0xfffffd8029d95000; item ordinal
0; addr 0xfffffd8029d95000 (p 0xfffffd802d9f8000); offset 0x0=0x0
art_heap4: pool(0xffffffff8259a378:art_heap4): page inconsistency: page
0xfffffd8029d95000; item ordinal 1; addr 0xdab58c89ea77e143
art_table 32 285 0 82 2 0 2 2 0
8 0
art_node 16 54 0 18 1 0 1 1 0
8 0
sysvmsgpl 40 38 0 21 1 0 1 1 0
8 0
semupl 112 3 0 3 1 1 0 1 0
8 0
semapl 112 63 0 53 1 0 1 1 0
8 0
shmpl 112 18 0 2 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 1626 0 225 46 0 46 46 0
8 0
ffsino 240 1626 0 225 83 0 83 83 0
8 0
nchpl 144 2087 0 494 60 0 60 60 0
8 0
uvmvnodes 72 1792 0 0 33 0 33 33 0
8 0
vnodes 208 1792 0 0 95 0 95 95 0
8 0
namei 1024 5402 0 5402 1 0 1 1 0
8 1
scxspl 192 5614 0 5614 8 1 7 7 0
8 7
plimitpl 152 21 0 14 1 0 1 1 0
8 0
sigapl 432 341 0 327 2 0 2 2 0
8 0
futexpl 56 4206 0 4206 1 0 1 1 0
8 1
knotepl 112 84 0 63 1 0 1 1 0
8 0
kqueuepl 104 38 0 36 1 0 1 1 0
8 0
pipepl 128 218 0 199 2 1 1 2 0
8 0
fdescpl 424 342 0 327 2 0 2 2 0
8 0
filepl 120 2238 0 2142 4 0 4 4 0
8 1
lockfpl 104 52 0 51 1 0 1 1 0
8 0
lockfspl 48 18 0 17 1 0 1 1 0
8 0
sessionpl 112 18 0 8 1 0 1 1 0
8 0
pgrppl 48 22 0 12 1 0 1 1 0
8 0
ucredpl 96 168 0 161 1 0 1 1 0
8 0
zombiepl 144 327 0 327 1 0 1 1 0
8 1
processpl 864 357 0 327 4 0 4 4 0
8 0
procpl 632 541 0 503 4 0 4 4 0
8 0
sosppl 128 3 0 3 1 0 1 1 0
8 1
sockpl 384 514 0 496 4 0 4 4 0
8 2
mcl64k 65536 23 0 23 1 0 1 1 0
8 1
mcl16k 16384 2 0 2 1 0 1 1 0
8 1
mcl12k 12288 4 0 4 1 0 1 1 0
8 1
mcl9k 9216 3 0 3 1 0 1 1 0
8 1
mcl8k 8192 6 0 6 1 0 1 1 0
8 1
mcl4k 4096 17 0 17 2 1 1 1 0
8 1
mcl2k2 2112 1 0 1 1 0 1 1 0
8 1
mcl2k 2048 70000 0 69952 16 5 11 14 0
8 4
mtagpl 80 12 0 4 2 1 1 1 0
8 0
mbufpl 256 111790 0 111662 13 1 12 12 0
8 0
bufpl 256 6334 0 1518 302 0 302 302 0
8 0
anonpl 16 47851 0 32637 81 2 79 79 0
62 0
amapchunkpl 152 1587 0 1438 9 0 9 9 0
158 2
amappl16 192 1775 0 700 55 0 55 55 0
8 0
amappl15 184 1 0 1 1 1 0 1 0
8 0
amappl14 176 116 0 108 1 0 1 1 0
8 0
amappl13 168 66 0 66 1 0 1 1 0
8 1
amappl12 160 8 0 6 1 0 1 1 0
8 0
amappl11 152 49 0 37 1 0 1 1 0
8 0
amappl10 144 11 0 10 1 0 1 1 0
8 0
amappl9 136 563 0 559 1 0 1 1 0
8 0
amappl8 128 153 0 127 1 0 1 1 0
8 0
amappl7 120 36 0 31 1 0 1 1 0
8 0
amappl6 112 56 0 44 1 0 1 1 0
8 0
amappl5 104 148 0 134 1 0 1 1 0
8 0
amappl4 96 553 0 527 1 0 1 1 0
8 0
amappl3 88 113 0 107 1 0 1 1 0
8 0
amappl2 80 1978 0 1920 3 1 2 3 0
8 0
amappl1 72 15542 0 15107 26 17 9 20 0
8 0
amappl 80 767 0 724 2 0 2 2 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 19 0 2 1 0 1 1 0
8 0
uaddrrnd 24 342 0 327 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 342 0 327 1 0 1 1 0
8 0
vmmpekpl 168 6655 0 6631 2 0 2 2 0
8 0
vmmpepl 168 48991 0 46896 144 7 137 137 0 357
43
vmsppl 272 341 0 327 2 1 1 2 0
8 0
pdppl 4096 690 0 654 6 1 5 6 0
8 0
pvpl 32 156171 0 137871 188 0 188 188 0
265 5
pmappl 200 341 0 327 1 0 1 1 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 451 0 11 13 0 13 13 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 19, 2020, 7:43:10 AM3/19/20
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages