Hello,
syzbot found the following crash on:
HEAD commit: df989dde Fix line numbers - commands are added after the l..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=132cb04ca00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=60e2b7157576c8d7
dashboard link:
https://syzkaller.appspot.com/bug?extid=927e93a362f3ae33dd9c
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+927e93...@syzkaller.appspotmail.com
uvm_fault(0xfffffd803f013d68, 0x100000008, 0, 2) -> e
kernel: page fault trap, code=0
Stopped at arp_rtrequest+0x15f: movq %rcx,0x8(%r15)
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
kernel page fault
uvm_fault(0xfffffd803f013d68, 0x100000008, 0, 2) -> e
arp_rtrequest() at arp_rtrequest+0x15f sys/netinet/if_ether.c:201
end trace frame: 0xffff8000149adff0, count: 0
ddb> trace
arp_rtrequest() at arp_rtrequest+0x15f sys/netinet/if_ether.c:201
rtm_output(ffff8000009e7200,ffff8000149ae0a8,ffff8000149ae000,40,0) at
rtm_output+0xbf4 sys/net/rtsock.c:1040
route_output(fffffd8036b1bb00,fffffd8038ec2a80,0,0) at route_output+0x7d7
sys/net/rtsock.c:814
route_usrreq(fffffd8038ec2a80,9,fffffd8036b1bb00,0,0,ffff8000ffff8e18) at
route_usrreq+0x363 sys/net/rtsock.c:271
sosend(fffffd8038ec2a80,0,ffff8000149ae2a0,0,0,80) at sosend+0x660
sys/kern/uipc_socket.c:513
sendit(ffff8000ffff8e18,3,ffff8000149ae380,0,ffff8000149ae490) at
sendit+0x53c sys/kern/uipc_syscalls.c:662
sys_sendto(ffff8000ffff8e18,ffff8000149ae428,ffff8000149ae490) at
sys_sendto+0x80 sys/kern/uipc_syscalls.c:527
syscall(ffff8000149ae500) at syscall+0x511
Xsyscall(6,0,ffffffffffffffd8,0,6,33fcb204010) at Xsyscall+0x128
end of kernel
end trace frame: 0x3420517bf60, count: -9
ddb> show registers
rdi 0xffffffff81d28db7 arp_rtrequest+0x157
rsi 0x194
rbp 0xffff8000149adf50
rbx 0xffff80000005bea0
rdx 0x195
rcx 0xdeaf4152deaf4152
rax 0xffff80000005bea8
r8 0x40
r9 0x5
r10 0xffff800000994b80
r11 0xf26f4d82e91f5047
r12 0xffff800000172290
r13 0x2
r14 0xfffffd802fc5c4d8
r15 0x100000000
rip 0xffffffff81d28dbf arp_rtrequest+0x15f
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff8000149aded0
ss 0x10
arp_rtrequest+0x15f: movq %rcx,0x8(%r15)
ddb> show proc
PROC (syz-executor.1) pid=388573 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=86, usrpri=86, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff8710,0xffffffff82296ba0
process=0xffff8000ffff66a0 user=0xffff8000149a9000,
vmspace=0xfffffd803f013d68
estcpu=36, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
3906 106073 13035 0 2 0 syz-executor.1
* 3906 388573 13035 0 7 0x4000000 syz-executor.1
12359 372097 79845 0 2 0x2 syz-executor.0
62875 238105 1 0 3 0x100083 ttyin getty
81951 207673 0 0 3 0x14200 bored sosplice
13035 272899 79845 0 3 0x82 nanosleep syz-executor.1
79845 74386 96347 0 3 0x82 thrsleep syz-fuzzer
79845 130935 96347 0 2 0x4000482 syz-fuzzer
79845 387134 96347 0 3 0x4000082 thrsleep syz-fuzzer
79845 457227 96347 0 3 0x4000082 thrsleep syz-fuzzer
79845 81104 96347 0 3 0x4000082 kqread syz-fuzzer
79845 333543 96347 0 3 0x4000082 thrsleep syz-fuzzer
79845 157955 96347 0 3 0x4000082 thrsleep syz-fuzzer
79845 484705 96347 0 3 0x4000082 thrsleep syz-fuzzer
96347 262282 71619 0 3 0x10008a pause ksh
71619 368070 24922 0 3 0x92 select sshd
24922 495474 1 0 3 0x80 select sshd
75188 174483 14525 73 2 0x100090 syslogd
14525 4235 1 0 3 0x100082 netio syslogd
57259 131095 1 77 3 0x100090 poll dhclient
85036 501701 1 0 3 0x80 poll dhclient
14293 118114 0 0 2 0x14200 zerothread
19259 336301 0 0 3 0x14200 aiodoned aiodoned
59898 316910 0 0 3 0x14200 syncer update
77564 261048 0 0 3 0x14200 cleaner cleaner
11297 461761 0 0 3 0x14200 reaper reaper
22821 80193 0 0 3 0x14200 pgdaemon pagedaemon
33280 287641 0 0 3 0x14200 bored crynlk
13100 370942 0 0 3 0x14200 bored crypto
96194 443697 0 0 3 0x40014200 acpi0 acpi0
58045 328927 0 0 3 0x14200 bored softnet
10272 452273 0 0 3 0x14200 bored systqmp
72215 19320 0 0 3 0x14200 bored systq
22182 324441 0 0 3 0x40014200 bored softclock
67233 162735 0 0 3 0x40014200 idle0
82388 277610 0 0 3 0x14200 bored smr
1 373690 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9523 6356K 7276K 78643K 22803 0 0
pcb 24 9K 11K 78643K 3678 0 0
rtable 131 5K 5K 78643K 5257 0 0
ifaddr 59 24K 32K 78643K 2533 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 236 0 0
iov 0 0K 32K 78643K 593 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1194 75K 76K 78643K 7289 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 5K 78643K 61 0 0
VM map 2 0K 0K 78643K 2 0 0
sem 12 0K 1K 78643K 614 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1793 195K 288K 78643K 12537 0 0
file desc 5 13K 25K 78643K 9029 0 0
sigio 0 0K 0K 78643K 98 0 0
proc 42 30K 54K 78643K 941 0 0
subproc 32 2K 2K 78643K 85 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
ip_moptions 0 0K 0K 78643K 442 0 0
in_multi 33 2K 2K 78643K 162 0 0
ether_multi 1 0K 0K 78643K 15 0 0
mrt 0 0K 0K 78643K 13 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 108 477K 477K 78643K 108 0 0
exec 0 0K 1K 78643K 599 0 0
pfkey data 0 0K 4K 78643K 6 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 84 20K 29K 78643K 20656 0 0
UVM aobj 130 4K 4K 78643K 131 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
ip6_options 0 0K 1K 78643K 214 0 0
NDP 12 0K 0K 78643K 641 0 0
temp 182 2715K 2843K 78643K 30869 0 0
kqueue 0 0K 0K 78643K 32 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 12 0 6 1 0 1 1 0
8 0
inpcbpl 280 3133 0 3126 1 0 1 1 0
8 0
plimitpl 152 137 0 130 1 0 1 1 0
8 0
rtentry 112 126 0 77 2 0 2 2 0
8 0
syncache 264 4 0 4 1 1 0 1 0
8 0
tcpcb 544 1825 0 1821 1 0 1 1 0
8 0
nd6 48 15 0 9 1 0 1 1 0
8 0
swfcl 56 1 0 0 1 0 1 1 0
8 0
ppxss 1128 605 0 605 17 16 1 1 0
8 1
art_heap8 4096 2 0 0 2 0 2 2 0
8 0
art_heap4 256 350 0 144 13 0 13 13 0
8 0
art_table 32 352 0 144 2 0 2 2 0
8 0
art_node 16 83 0 41 1 0 1 1 0
8 0
sysvmsgpl 40 6 0 2 1 0 1 1 0
8 0
semapl 112 612 0 602 1 0 1 1 0
8 0
shmpl 112 129 0 1 4 0 4 4 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 16291 0 14825 48 0 48 48 0
8 0
ffsino 240 16291 0 14825 88 1 87 87 0
8 0
nchpl 144 28023 0 26417 61 0 61 61 0
8 0
uvmvnodes 72 5926 0 0 108 0 108 108 0
8 0
vnodes 200 5926 0 0 312 0 312 312 0
8 0
namei 1024 79643 0 79643 2 1 1 1 0
8 1
scsiplug 64 10 0 10 6 6 0 1 0
8 0
scxspl 192 79581 0 79581 18 17 1 7 0
8 1
sigapl 432 9192 0 9179 2 0 2 2 0
8 0
futexpl 56 116325 0 116325 1 0 1 1 0
8 1
knotepl 112 881 0 862 1 0 1 1 0
8 0
kqueuepl 104 1107 0 1105 1 0 1 1 0
8 0
pipepl 112 3746 0 3727 10 9 1 2 0
8 0
fdescpl 424 9193 0 9179 2 0 2 2 0
8 0
filepl 120 42546 0 42451 6 2 4 5 0
8 1
lockfpl 104 2351 0 2351 4 3 1 1 0
8 1
lockfspl 48 760 0 760 4 3 1 1 0
8 1
sessionpl 112 21 0 11 1 0 1 1 0
8 0
pgrppl 48 89 0 79 1 0 1 1 0
8 0
ucredpl 96 9059 0 9052 1 0 1 1 0
8 0
zombiepl 144 9179 0 9179 2 1 1 1 0
8 1
processpl 840 9208 0 9179 4 0 4 4 0
8 0
procpl 600 19703 0 19666 5 1 4 4 0
8 1
sosppl 128 77 0 77 18 17 1 1 0
8 1
sockpl 384 6895 0 6877 12 9 3 4 0
8 1
mcl64k 65536 1153 0 1153 90 90 0 33 0
8 0
mcl16k 16384 32 0 32 14 14 0 1 0
8 0
mcl12k 12288 80 0 80 26 25 1 1 0
8 1
mcl9k 9216 83 0 83 23 22 1 1 0
8 1
mcl8k 8192 69 0 69 24 23 1 1 0
8 1
mcl4k 4096 227 0 227 16 16 0 1 0
8 0
mcl2k2 2112 31 0 31 14 14 0 1 0
8 0
mcl2k 2048 61100 0 61054 21 14 7 11 0
8 0
mtagpl 80 6 0 6 3 3 0 1 0
8 0
mbufpl 256 153386 0 153236 54 43 11 22 0
8 0
bufpl 256 20470 0 15922 285 0 285 285 0
8 0
anonpl 16 625582 0 616991 193 155 38 67 0
62 2
amapchunkpl 152 32859 0 32778 34 29 5 11 0
158 0
amappl16 192 42052 0 41595 157 133 24 47 0
8 0
amappl15 184 16 0 15 1 0 1 1 0
8 0
amappl14 176 69 0 68 2 1 1 1 0
8 0
amappl13 168 19 0 18 1 0 1 1 0
8 0
amappl12 160 4545 0 4540 1 0 1 1 0
8 0
amappl11 152 58 0 44 1 0 1 1 0
8 0
amappl10 144 1737 0 1734 2 1 1 1 0
8 0
amappl9 136 3320 0 3315 1 0 1 1 0
8 0
amappl8 128 2898 0 2881 1 0 1 1 0
8 0
amappl7 120 1705 0 1699 1 0 1 1 0
8 0
amappl6 112 53 0 46 1 0 1 1 0
8 0
amappl5 104 4747 0 4735 1 0 1 1 0
8 0
amappl4 96 9369 0 9348 1 0 1 1 0
8 0
amappl3 88 342 0 332 1 0 1 1 0
8 0
amappl2 80 73588 0 73521 4 2 2 3 0
8 0
amappl1 72 160264 0 159864 24 15 9 19 0
8 0
amappl 80 19990 0 19958 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 130 0 1 3 0 3 3 0
8 0
uaddrrnd 24 9193 0 9179 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 9193 0 9179 1 0 1 1 0
8 0
vmmpekpl 168 55383 0 55358 2 0 2 2 0
8 0
vmmpepl 168 892339 0 890923 197 130 67 87 0
357 4
vmsppl 264 9192 0 9179 3 2 1 2 0
8 0
pdppl 4096 18392 0 18358 6 1 5 6 0
8 0
pvpl 32 1780920 0 1769254 409 299 110 164 0 265
13
pmappl 200 9192 0 9179 1 0 1 1 0
8 0
extentpl 40 41 0 26 1 0 1 1 0
8 0
phpool 112 621 0 205 16 3 13 14 0
8 0
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.