Hello,
syzbot found the following issue on:
HEAD commit: ff683e69af4a Allow rsync:// URI as file in -f mode. This m..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=136adfd0700000
kernel config:
https://syzkaller.appspot.com/x/.config?x=bf87b6915a88cd0d
dashboard link:
https://syzkaller.appspot.com/bug?extid=a2649c1d77e9d2463f33
Unfortunately, I don't have any reproducer for this issue yet.
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+a2649c...@syzkaller.appspotmail.com
kernel: protection fault trap, code=0
Stopped at lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
the kernel did not panic
ddb{1}> trace
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f ls_ref sys/kern/vfs_lockf.c:140 [inline]
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f sys/kern/vfs_lockf.c:281
VOP_ADVLOCK(fffffd807179bdc0,fffffd8008747ba0,2,ffff800024652bb0,40) at VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
closef(fffffd80665ead10,ffff80002e39ed28) at closef+0xe5
fdfree(ffff80002e39ed28) at fdfree+0xf4 sys/kern/kern_descrip.c:1195
exit1(ffff80002e39ed28,0,0,1) at exit1+0x37d sys/kern/kern_exit.c:202
sys_exit(ffff80002e39ed28,ffff800024652d20,ffff800024652d80) at sys_exit+0x16 sys/kern/kern_exit.c:95
syscall(ffff800024652df0) at syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff800024652df0) at syscall+0x489 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe3d50, count: -8
ddb{1}> show registers
rdi 0
rsi 0
rbp 0xffff800024652b00
rbx 0xdead4110dead4110
rdx 0
rcx 0x9
rax 0xffff80002e39ed28
r8 0
r9 0x1
r10 0x2d9ba996a8f1923c
r11 0xc20bdee8ecf5fa4e
r12 0x2
r13 0xffffffffffffffff
r14 0xffff800000bdece0
r15 0
rip 0xffffffff8216bfff lf_advlock+0x21f
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff800024652a70
ss 0x10
lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{1}> show proc
PROC (syz-executor.0) pid=324379 stat=onproc
flags process=1018<EXITING,SUGID,SINGLEEXIT> proc=2000<WEXIT>
pri=32, usrpri=80, nice=20
forw=0xffffffffffffffff, list=0xffff80002e39e008,0xffff80002e39fa58
process=0xffff8000ffff14e0 user=0xffff80002464d000, vmspace=0xfffffd806c61d010
estcpu=36, cpticks=2, pctcpu=0.0
user=0, sys=1, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
54317 282050 17198 32767 2 0x10 syz-executor.2
54317 169258 17198 32767 2 0x4000010 syz-executor.2
60494 373146 57774 32767 2 0x10 syz-executor.7
60494 337216 57774 32767 3 0x4000090 fsleep syz-executor.7
92937 114879 37969 32767 7 0x10 syz-executor.5
92937 503233 37969 32767 3 0x4000090 lockf syz-executor.5
29820 305709 82596 32767 2 0x10 syz-executor.3
38735 358107 31485 32767 2 0x10 syz-executor.1
38735 512646 31485 32767 3 0x4000090 fsleep syz-executor.1
66432 331679 89176 32767 2 0x10 syz-executor.6
66432 345949 89176 32767 3 0x4000090 lockf syz-executor.6
66432 206815 89176 32767 3 0x4000090 lockf syz-executor.6
17198 304413 45352 32767 3 0x90 nanoslp syz-executor.2
45352 508946 10287 0 3 0x82 wait syz-executor.2
57774 438178 25881 32767 2 0x10 syz-executor.7
25881 312164 10287 0 3 0x82 wait syz-executor.7
15833 276897 86009 32767 3 0x90 nanoslp syz-executor.0
86009 2553 10287 0 3 0x82 wait syz-executor.0
89176 188335 58197 32767 3 0x90 nanoslp syz-executor.6
58197 235313 10287 0 3 0x82 wait syz-executor.6
8045 55584 2754 32767 3 0x90 nanoslp syz-executor.4
2754 345230 10287 0 3 0x82 wait syz-executor.4
31485 220759 73529 32767 3 0x90 nanoslp syz-executor.1
73529 21688 10287 0 3 0x82 wait syz-executor.1
37969 16220 72320 32767 3 0x90 nanoslp syz-executor.5
72320 288891 10287 0 3 0x82 wait syz-executor.5
82596 6372 80973 32767 3 0x90 nanoslp syz-executor.3
80973 256369 10287 0 3 0x82 wait syz-executor.3
32115 424009 0 0 3 0x14200 bored sosplice
10287 326371 7163 0 3 0x82 thrsleep syz-fuzzer
10287 114075 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 11827 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 467056 7163 0 3 0x4000082 kqread syz-fuzzer
10287 183748 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 317815 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 480045 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 115485 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 371855 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 429443 7163 0 3 0x4000082 thrsleep syz-fuzzer
7163 199419 42661 0 3 0x10008a sigsusp ksh
42661 350522 55659 0 3 0x9a poll sshd
609 119495 1 0 3 0x100083 ttyin getty
55659 346402 1 0 3 0x88 poll sshd
66003 130851 95167 73 3 0x100090 kqread syslogd
95167 193206 1 0 3 0x100082 netio syslogd
71615 193688 1 0 3 0x100080 kqread resolvd
49367 49791 81832 77 3 0x100092 kqread dhcpleased
87002 72744 81832 77 3 0x100092 kqread dhcpleased
81832 196865 1 0 3 0x80 kqread dhcpleased
9555 235528 0 0 3 0x14200 bored smr
42040 240761 0 0 2 0x14200 zerothread
52617 44689 0 0 3 0x14200 aiodoned aiodoned
37352 413517 0 0 3 0x14200 syncer update
10352 379027 0 0 3 0x14200 cleaner cleaner
81073 418075 0 0 3 0x14200 reaper reaper
49951 282999 0 0 3 0x14200 pgdaemon pagedaemon
5394 340844 0 0 3 0x14200 bored viomb
30208 157357 0 0 3 0x40014200 acpi0 acpi0
9452 79562 0 0 3 0x40014200 idle1
65965 2710 0 0 3 0x14200 bored softnet
19148 355283 0 0 3 0x14200 bored systqmp
59042 230877 0 0 3 0x14200 bored systq
64233 280871 0 0 3 0x40014200 bored softclock
8581 19270 0 0 3 0x40014200 idle0
1 465123 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10202 6411K 6418K 78643K 11411 0
pcb 13 12K 14K 78643K 17 0
rtable 250 7K 7K 78643K 2813 0
ifaddr 81 17K 17K 78643K 357 0
sysctl 3 1K 5K 78643K 8 0
counters 56 35K 35K 78643K 134 0
ioctlops 0 0K 2K 78643K 356 0
iov 0 0K 44K 78643K 3298 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 5 0
vnodes 1271 79K 79K 78643K 13570 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 9K 78643K 287 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 7798 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12598 0
file desc 25 93K 121K 78643K 26138 0
sigio 0 0K 0K 78643K 265 0
proc 56 74K 99K 78643K 3011 0
subproc 104 6K 6K 78643K 611 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 2464 0
in_multi 99 6K 7K 78643K 889 0
ether_multi 1 0K 0K 78643K 118 0
mrt 2 0K 0K 78643K 4 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 259 1155K 1155K 78643K 259 0
exec 0 0K 2K 78643K 4285 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 540 103K 119K 78643K 351851 0
UVM aobj 131 8K 8K 78643K 131 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 640 0
NDP 11 0K 2K 78643K 144 0
temp 125 4699K 4827K 78643K 67982 0
kqueue 12 18K 26K 78643K 1682 0
SYN cache 2 16K 16K 78643K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 22 0 0 1 0 1 1 0 8 0
rtpcb 120 2233 0 2230 30 29 1 5 0 8 0
rtentry 112 595 0 479 4 0 4 4 0 8 0
unpcb 136 22528 0 22515 224 221 3 9 0 8 2
syncache 296 245 0 245 51 51 0 1 0 8 0
tcpqe 32 121 0 121 26 26 0 1 0 8 0
tcpcb 736 10412 0 10408 375 371 4 15 0 8 3
arp 120 98 0 80 1 0 1 1 0 8 0
ipq 40 99 0 99 19 19 0 1 0 8 0
ipqe 40 985 0 985 19 19 0 1 0 8 0
inpcb 304 25703 0 25696 431 425 6 16 0 8 5
rttmr 72 4 0 3 1 0 1 1 0 8 0
ip6q 72 35 0 35 11 11 0 1 0 8 0
ip6af 40 73 0 73 11 11 0 1 0 8 0
nd6 48 193 0 164 1 0 1 1 0 8 0
kcovpl 48 47 0 39 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 2492 0 1971 47 14 33 35 0 8 0
art_table 32 2493 0 1971 6 1 5 5 0 8 0
art_node 16 594 0 488 1 0 1 1 0 8 0
semapl 112 7796 0 7786 1 0 1 1 0 8 0
shmpl 112 128 0 0 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 42563 0 41121 91 0 91 91 0 8 0
ffsino 272 42563 0 41121 97 0 97 97 0 8 0
nchpl 144 75854 0 74229 62 0 62 62 0 8 0
uvmvnodes 80 6634 0 0 136 0 136 136 0 8 0
vnodes 224 6634 0 0 391 0 391 391 0 8 0
namei 1024 280738 0 280738 11 10 1 2 0 8 1
percpumem 16 79 0 39 1 0 1 1 0 8 0
scxspl 216 219625 0 219625 92 91 1 8 0 8 1
plimitpl 152 5739 0 5716 20 19 1 2 0 8 0
sigapl 424 26337 0 26286 7 1 6 7 0 8 0
futexpl 64 233548 0 233546 11 10 1 1 0 8 0
knotepl 112 575 0 0 6 1 5 5 0 8 0
kqueuepl 216 10007 0 9990 208 206 2 8 0 8 1
pipepl 336 4291 0 4263 122 116 6 13 0 8 3
fdescpl 496 26322 0 26286 7 2 5 6 0 8 0
filepl 152 204591 0 204348 405 393 12 20 0 8 1
lockfpl 104 34915 0 34908 4 3 1 2 0 8 0
lockfspl 48 5133 0 5129 1 0 1 1 0 8 0
sessionpl 144 62 0 46 1 0 1 1 0 8 0
pgrppl 48 190 0 174 1 0 1 1 0 8 0
ucredpl 96 65617 0 65599 1 0 1 1 0 8 0
zombiepl 144 26287 0 26285 2 1 1 1 0 8 0
processpl 1064 26337 0 26285 5 1 4 4 0 8 0
procpl 672 88058 0 87991 59 52 7 9 0 8 0
sosppl 168 467 0 467 56 55 1 1 0 8 1
sockpl 480 51083 0 51060 1283 1272 11 34 0 8 8
mcl64k 65536 73 0 0 4 1 3 3 0 8 0
mcl16k 16384 73 0 0 7 4 3 3 0 8 0
mcl12k 12288 41 0 0 2 0 2 2 0 8 0
mcl9k 9216 41 0 0 2 0 2 2 0 8 0
mcl8k 8192 65 0 0 6 3 3 3 0 8 0
mcl4k 4096 42 0 0 4 1 3 3 0 8 0
mcl2k2 2112 25 0 0 2 0 2 2 0 8 0
mcl2k 2048 456 0 0 19 5 14 19 0 8 0
mtagpl 96 2 0 0 1 0 1 1 0 8 0
mbufpl 256 10247 0 0 545 1 544 544 0 8 0
bufpl 288 45379 0 38744 475 0 475 475 0 8 0
anonpl 24 8054645 0 8039404 509 386 123 126 0 186 12
amapchunkpl 152 908992 0 908153 350 313 37 49 0 158 1
amappl16 200 79373 0 78867 435 399 36 40 0 8 8
amappl15 192 12122 0 12114 1 0 1 1 0 8 0
amappl14 184 2028 0 2021 1 0 1 1 0 8 0
amappl13 176 5368 0 5361 1 0 1 1 0 8 0
amappl12 168 78 0 70 1 0 1 1 0 8 0
amappl11 160 1298 0 1284 1 0 1 1 0 8 0
amappl10 152 4435 0 4413 1 0 1 1 0 8 0
amappl9 144 2016 0 2014 1 0 1 1 0 8 0
amappl8 136 4356 0 4102 9 0 9 9 0 8 0
amappl7 128 1714 0 1702 1 0 1 1 0 8 0
amappl6 120 1919 0 1889 3 1 2 2 0 8 0
amappl5 112 23786 0 23756 1 0 1 1 0 8 0
amappl4 104 6271 0 6237 2 0 2 2 0 8 0
amappl3 96 6976 0 6960 1 0 1 1 0 8 0
amappl2 88 7500 0 7443 3 1 2 3 0 8 0
amappl1 80 490059 0 489420 29 14 15 18 0 8 0
amappl 88 349512 0 349213 13 5 8 8 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 130 0 0 3 0 3 3 0 8 0
uaddrrnd 24 26322 0 26286 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 26322 0 26286 1 0 1 1 0 8 0
vmmpekpl 168 225196 0 225129 4 0 4 4 0 8 0
vmmpepl 168 2466226 0 2463136 519 367 152 156 0 357 11
vmsppl 368 26321 0 26286 4 0 4 4 0 8 0
rwobjpl 56 626884 0 618443 156 32 124 124 0 8 4
pdppl 4096 52651 0 52572 926 845 81 93 0 8 2
pvpl 32 13340767 0 13319647 936 723 213 247 0 265 16
pmappl 248 26321 0 26286 4 1 3 3 0 8 0
extentpl 40 57 0 38 1 0 1 1 0 8 0
phpool 112 2740 0 1373 40 0 40 40 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x1a: addq $0x8,%rsp
ddb{0}> trace
x86_ipi_db(ffffffff829a6ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
__mp_lock(ffffffff82ae1148) at __mp_lock+0x122 __mp_lock_spin sys/kern/kern_lock.c:116 [inline]
__mp_lock(ffffffff82ae1148) at __mp_lock+0x122 sys/kern/kern_lock.c:147
softintr_dispatch(0) at softintr_dispatch+0x4e sys/arch/amd64/amd64/softintr.c:88
Xsoftclock() at Xsoftclock+0x1f
end of kernel
end trace frame: 0x7f7ffffbddd0, count: -6
ddb{0}> machine ddbcpu 1
Stopped at lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{1}> trace
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f ls_ref sys/kern/vfs_lockf.c:140 [inline]
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f sys/kern/vfs_lockf.c:281
VOP_ADVLOCK(fffffd807179bdc0,fffffd8008747ba0,2,ffff800024652bb0,40) at VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
closef(fffffd80665ead10,ffff80002e39ed28) at closef+0xe5
fdfree(ffff80002e39ed28) at fdfree+0xf4 sys/kern/kern_descrip.c:1195
exit1(ffff80002e39ed28,0,0,1) at exit1+0x37d sys/kern/kern_exit.c:202
sys_exit(ffff80002e39ed28,ffff800024652d20,ffff800024652d80) at sys_exit+0x16 sys/kern/kern_exit.c:95
syscall(ffff800024652df0) at syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff800024652df0) at syscall+0x489 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe3d50, count: -8
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.