protection_fault: lf_advlock

1 view
Skip to first unread message

syzbot

unread,
Jan 27, 2022, 6:06:21 AM1/27/22
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: ff683e69af4a Allow rsync:// URI as file in -f mode. This m..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=136adfd0700000
kernel config: https://syzkaller.appspot.com/x/.config?x=bf87b6915a88cd0d
dashboard link: https://syzkaller.appspot.com/bug?extid=a2649c1d77e9d2463f33

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a2649c...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
the kernel did not panic
ddb{1}> trace
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f ls_ref sys/kern/vfs_lockf.c:140 [inline]
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f sys/kern/vfs_lockf.c:281
VOP_ADVLOCK(fffffd807179bdc0,fffffd8008747ba0,2,ffff800024652bb0,40) at VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
closef(fffffd80665ead10,ffff80002e39ed28) at closef+0xe5
fdfree(ffff80002e39ed28) at fdfree+0xf4 sys/kern/kern_descrip.c:1195
exit1(ffff80002e39ed28,0,0,1) at exit1+0x37d sys/kern/kern_exit.c:202
sys_exit(ffff80002e39ed28,ffff800024652d20,ffff800024652d80) at sys_exit+0x16 sys/kern/kern_exit.c:95
syscall(ffff800024652df0) at syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff800024652df0) at syscall+0x489 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe3d50, count: -8
ddb{1}> show registers
rdi 0
rsi 0
rbp 0xffff800024652b00
rbx 0xdead4110dead4110
rdx 0
rcx 0x9
rax 0xffff80002e39ed28
r8 0
r9 0x1
r10 0x2d9ba996a8f1923c
r11 0xc20bdee8ecf5fa4e
r12 0x2
r13 0xffffffffffffffff
r14 0xffff800000bdece0
r15 0
rip 0xffffffff8216bfff lf_advlock+0x21f
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff800024652a70
ss 0x10
lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{1}> show proc
PROC (syz-executor.0) pid=324379 stat=onproc
flags process=1018<EXITING,SUGID,SINGLEEXIT> proc=2000<WEXIT>
pri=32, usrpri=80, nice=20
forw=0xffffffffffffffff, list=0xffff80002e39e008,0xffff80002e39fa58
process=0xffff8000ffff14e0 user=0xffff80002464d000, vmspace=0xfffffd806c61d010
estcpu=36, cpticks=2, pctcpu=0.0
user=0, sys=1, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
54317 282050 17198 32767 2 0x10 syz-executor.2
54317 169258 17198 32767 2 0x4000010 syz-executor.2
60494 373146 57774 32767 2 0x10 syz-executor.7
60494 337216 57774 32767 3 0x4000090 fsleep syz-executor.7
92937 114879 37969 32767 7 0x10 syz-executor.5
92937 503233 37969 32767 3 0x4000090 lockf syz-executor.5
29820 305709 82596 32767 2 0x10 syz-executor.3
38735 358107 31485 32767 2 0x10 syz-executor.1
38735 512646 31485 32767 3 0x4000090 fsleep syz-executor.1
66432 331679 89176 32767 2 0x10 syz-executor.6
66432 345949 89176 32767 3 0x4000090 lockf syz-executor.6
66432 206815 89176 32767 3 0x4000090 lockf syz-executor.6
17198 304413 45352 32767 3 0x90 nanoslp syz-executor.2
45352 508946 10287 0 3 0x82 wait syz-executor.2
57774 438178 25881 32767 2 0x10 syz-executor.7
25881 312164 10287 0 3 0x82 wait syz-executor.7
15833 276897 86009 32767 3 0x90 nanoslp syz-executor.0
86009 2553 10287 0 3 0x82 wait syz-executor.0
89176 188335 58197 32767 3 0x90 nanoslp syz-executor.6
58197 235313 10287 0 3 0x82 wait syz-executor.6
8045 55584 2754 32767 3 0x90 nanoslp syz-executor.4
2754 345230 10287 0 3 0x82 wait syz-executor.4
31485 220759 73529 32767 3 0x90 nanoslp syz-executor.1
73529 21688 10287 0 3 0x82 wait syz-executor.1
37969 16220 72320 32767 3 0x90 nanoslp syz-executor.5
72320 288891 10287 0 3 0x82 wait syz-executor.5
82596 6372 80973 32767 3 0x90 nanoslp syz-executor.3
80973 256369 10287 0 3 0x82 wait syz-executor.3
32115 424009 0 0 3 0x14200 bored sosplice
10287 326371 7163 0 3 0x82 thrsleep syz-fuzzer
10287 114075 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 11827 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 467056 7163 0 3 0x4000082 kqread syz-fuzzer
10287 183748 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 317815 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 480045 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 115485 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 371855 7163 0 3 0x4000082 thrsleep syz-fuzzer
10287 429443 7163 0 3 0x4000082 thrsleep syz-fuzzer
7163 199419 42661 0 3 0x10008a sigsusp ksh
42661 350522 55659 0 3 0x9a poll sshd
609 119495 1 0 3 0x100083 ttyin getty
55659 346402 1 0 3 0x88 poll sshd
66003 130851 95167 73 3 0x100090 kqread syslogd
95167 193206 1 0 3 0x100082 netio syslogd
71615 193688 1 0 3 0x100080 kqread resolvd
49367 49791 81832 77 3 0x100092 kqread dhcpleased
87002 72744 81832 77 3 0x100092 kqread dhcpleased
81832 196865 1 0 3 0x80 kqread dhcpleased
9555 235528 0 0 3 0x14200 bored smr
42040 240761 0 0 2 0x14200 zerothread
52617 44689 0 0 3 0x14200 aiodoned aiodoned
37352 413517 0 0 3 0x14200 syncer update
10352 379027 0 0 3 0x14200 cleaner cleaner
81073 418075 0 0 3 0x14200 reaper reaper
49951 282999 0 0 3 0x14200 pgdaemon pagedaemon
5394 340844 0 0 3 0x14200 bored viomb
30208 157357 0 0 3 0x40014200 acpi0 acpi0
9452 79562 0 0 3 0x40014200 idle1
65965 2710 0 0 3 0x14200 bored softnet
19148 355283 0 0 3 0x14200 bored systqmp
59042 230877 0 0 3 0x14200 bored systq
64233 280871 0 0 3 0x40014200 bored softclock
8581 19270 0 0 3 0x40014200 idle0
1 465123 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10202 6411K 6418K 78643K 11411 0
pcb 13 12K 14K 78643K 17 0
rtable 250 7K 7K 78643K 2813 0
ifaddr 81 17K 17K 78643K 357 0
sysctl 3 1K 5K 78643K 8 0
counters 56 35K 35K 78643K 134 0
ioctlops 0 0K 2K 78643K 356 0
iov 0 0K 44K 78643K 3298 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 5 0
vnodes 1271 79K 79K 78643K 13570 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 9K 78643K 287 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 7798 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12598 0
file desc 25 93K 121K 78643K 26138 0
sigio 0 0K 0K 78643K 265 0
proc 56 74K 99K 78643K 3011 0
subproc 104 6K 6K 78643K 611 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 2464 0
in_multi 99 6K 7K 78643K 889 0
ether_multi 1 0K 0K 78643K 118 0
mrt 2 0K 0K 78643K 4 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 259 1155K 1155K 78643K 259 0
exec 0 0K 2K 78643K 4285 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 540 103K 119K 78643K 351851 0
UVM aobj 131 8K 8K 78643K 131 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 640 0
NDP 11 0K 2K 78643K 144 0
temp 125 4699K 4827K 78643K 67982 0
kqueue 12 18K 26K 78643K 1682 0
SYN cache 2 16K 16K 78643K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 22 0 0 1 0 1 1 0 8 0
rtpcb 120 2233 0 2230 30 29 1 5 0 8 0
rtentry 112 595 0 479 4 0 4 4 0 8 0
unpcb 136 22528 0 22515 224 221 3 9 0 8 2
syncache 296 245 0 245 51 51 0 1 0 8 0
tcpqe 32 121 0 121 26 26 0 1 0 8 0
tcpcb 736 10412 0 10408 375 371 4 15 0 8 3
arp 120 98 0 80 1 0 1 1 0 8 0
ipq 40 99 0 99 19 19 0 1 0 8 0
ipqe 40 985 0 985 19 19 0 1 0 8 0
inpcb 304 25703 0 25696 431 425 6 16 0 8 5
rttmr 72 4 0 3 1 0 1 1 0 8 0
ip6q 72 35 0 35 11 11 0 1 0 8 0
ip6af 40 73 0 73 11 11 0 1 0 8 0
nd6 48 193 0 164 1 0 1 1 0 8 0
kcovpl 48 47 0 39 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 2492 0 1971 47 14 33 35 0 8 0
art_table 32 2493 0 1971 6 1 5 5 0 8 0
art_node 16 594 0 488 1 0 1 1 0 8 0
semapl 112 7796 0 7786 1 0 1 1 0 8 0
shmpl 112 128 0 0 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 42563 0 41121 91 0 91 91 0 8 0
ffsino 272 42563 0 41121 97 0 97 97 0 8 0
nchpl 144 75854 0 74229 62 0 62 62 0 8 0
uvmvnodes 80 6634 0 0 136 0 136 136 0 8 0
vnodes 224 6634 0 0 391 0 391 391 0 8 0
namei 1024 280738 0 280738 11 10 1 2 0 8 1
percpumem 16 79 0 39 1 0 1 1 0 8 0
scxspl 216 219625 0 219625 92 91 1 8 0 8 1
plimitpl 152 5739 0 5716 20 19 1 2 0 8 0
sigapl 424 26337 0 26286 7 1 6 7 0 8 0
futexpl 64 233548 0 233546 11 10 1 1 0 8 0
knotepl 112 575 0 0 6 1 5 5 0 8 0
kqueuepl 216 10007 0 9990 208 206 2 8 0 8 1
pipepl 336 4291 0 4263 122 116 6 13 0 8 3
fdescpl 496 26322 0 26286 7 2 5 6 0 8 0
filepl 152 204591 0 204348 405 393 12 20 0 8 1
lockfpl 104 34915 0 34908 4 3 1 2 0 8 0
lockfspl 48 5133 0 5129 1 0 1 1 0 8 0
sessionpl 144 62 0 46 1 0 1 1 0 8 0
pgrppl 48 190 0 174 1 0 1 1 0 8 0
ucredpl 96 65617 0 65599 1 0 1 1 0 8 0
zombiepl 144 26287 0 26285 2 1 1 1 0 8 0
processpl 1064 26337 0 26285 5 1 4 4 0 8 0
procpl 672 88058 0 87991 59 52 7 9 0 8 0
sosppl 168 467 0 467 56 55 1 1 0 8 1
sockpl 480 51083 0 51060 1283 1272 11 34 0 8 8
mcl64k 65536 73 0 0 4 1 3 3 0 8 0
mcl16k 16384 73 0 0 7 4 3 3 0 8 0
mcl12k 12288 41 0 0 2 0 2 2 0 8 0
mcl9k 9216 41 0 0 2 0 2 2 0 8 0
mcl8k 8192 65 0 0 6 3 3 3 0 8 0
mcl4k 4096 42 0 0 4 1 3 3 0 8 0
mcl2k2 2112 25 0 0 2 0 2 2 0 8 0
mcl2k 2048 456 0 0 19 5 14 19 0 8 0
mtagpl 96 2 0 0 1 0 1 1 0 8 0
mbufpl 256 10247 0 0 545 1 544 544 0 8 0
bufpl 288 45379 0 38744 475 0 475 475 0 8 0
anonpl 24 8054645 0 8039404 509 386 123 126 0 186 12
amapchunkpl 152 908992 0 908153 350 313 37 49 0 158 1
amappl16 200 79373 0 78867 435 399 36 40 0 8 8
amappl15 192 12122 0 12114 1 0 1 1 0 8 0
amappl14 184 2028 0 2021 1 0 1 1 0 8 0
amappl13 176 5368 0 5361 1 0 1 1 0 8 0
amappl12 168 78 0 70 1 0 1 1 0 8 0
amappl11 160 1298 0 1284 1 0 1 1 0 8 0
amappl10 152 4435 0 4413 1 0 1 1 0 8 0
amappl9 144 2016 0 2014 1 0 1 1 0 8 0
amappl8 136 4356 0 4102 9 0 9 9 0 8 0
amappl7 128 1714 0 1702 1 0 1 1 0 8 0
amappl6 120 1919 0 1889 3 1 2 2 0 8 0
amappl5 112 23786 0 23756 1 0 1 1 0 8 0
amappl4 104 6271 0 6237 2 0 2 2 0 8 0
amappl3 96 6976 0 6960 1 0 1 1 0 8 0
amappl2 88 7500 0 7443 3 1 2 3 0 8 0
amappl1 80 490059 0 489420 29 14 15 18 0 8 0
amappl 88 349512 0 349213 13 5 8 8 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 130 0 0 3 0 3 3 0 8 0
uaddrrnd 24 26322 0 26286 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 26322 0 26286 1 0 1 1 0 8 0
vmmpekpl 168 225196 0 225129 4 0 4 4 0 8 0
vmmpepl 168 2466226 0 2463136 519 367 152 156 0 357 11
vmsppl 368 26321 0 26286 4 0 4 4 0 8 0
rwobjpl 56 626884 0 618443 156 32 124 124 0 8 4
pdppl 4096 52651 0 52572 926 845 81 93 0 8 2
pvpl 32 13340767 0 13319647 936 723 213 247 0 265 16
pmappl 248 26321 0 26286 4 1 3 3 0 8 0
extentpl 40 57 0 38 1 0 1 1 0 8 0
phpool 112 2740 0 1373 40 0 40 40 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x1a: addq $0x8,%rsp
ddb{0}> trace
x86_ipi_db(ffffffff829a6ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
__mp_lock(ffffffff82ae1148) at __mp_lock+0x122 __mp_lock_spin sys/kern/kern_lock.c:116 [inline]
__mp_lock(ffffffff82ae1148) at __mp_lock+0x122 sys/kern/kern_lock.c:147
softintr_dispatch(0) at softintr_dispatch+0x4e sys/arch/amd64/amd64/softintr.c:88
Xsoftclock() at Xsoftclock+0x1f
end of kernel
end trace frame: 0x7f7ffffbddd0, count: -6
ddb{0}> machine ddbcpu 1
Stopped at lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{1}> trace
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f ls_ref sys/kern/vfs_lockf.c:140 [inline]
lf_advlock(ffff800000bdece0,0,fffffd8008747ba0,2,ffff800024652bb0,40) at lf_advlock+0x21f sys/kern/vfs_lockf.c:281
VOP_ADVLOCK(fffffd807179bdc0,fffffd8008747ba0,2,ffff800024652bb0,40) at VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
closef(fffffd80665ead10,ffff80002e39ed28) at closef+0xe5
fdfree(ffff80002e39ed28) at fdfree+0xf4 sys/kern/kern_descrip.c:1195
exit1(ffff80002e39ed28,0,0,1) at exit1+0x37d sys/kern/kern_exit.c:202
sys_exit(ffff80002e39ed28,ffff800024652d20,ffff800024652d80) at sys_exit+0x16 sys/kern/kern_exit.c:95
syscall(ffff800024652df0) at syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff800024652df0) at syscall+0x489 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe3d50, count: -8


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 12, 2022, 7:32:19 PM3/12/22
to syzkaller-o...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 447db83cf4f0 Revert holding a read lock on the map while c..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=121485b5700000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1676717e700000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17320ade700000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a2649c...@syzkaller.appspotmail.com

login: kernel: protection fault trap, code=0
Stopped at lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{0}>
ddb{0}> set $lines = 0
ddb{0}> set $maxwidth = 0
ddb{0}> show panic
the kernel did not panic
ddb{0}> trace
lf_advlock(ffff800000bcf0e0,0,fffffd806d5bf1f0,2,ffff8000212044c0,40) at lf_advlock+0x21f ls_ref sys/kern/vfs_lockf.c:140 [inline]
lf_advlock(ffff800000bcf0e0,0,fffffd806d5bf1f0,2,ffff8000212044c0,40) at lf_advlock+0x21f sys/kern/vfs_lockf.c:281
VOP_ADVLOCK(fffffd806caccb68,fffffd806d5bf1f0,2,ffff8000212044c0,40) at VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
closef(fffffd8075a19988,ffff800021192000) at closef+0xe5
syscall(ffff8000212045f0) at syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff8000212045f0) at syscall+0x489 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe8490, count: -5
ddb{0}> show registers
rdi 0
rsi 0
rbp 0xffff800021204410
rbx 0xdeaf4152deaf4152
rdx 0x6
rcx 0x5
rax 0
r8 0xffff8000212044c0
r9 0x40
r10 0
r11 0xe3fde0640d4885cd
r12 0x2
r13 0xffffffffffffffff
r14 0xffff800000bcf0e0
r15 0
rip 0xffffffff81744def lf_advlock+0x21f
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff800021204380
ss 0x10
lf_advlock+0x21f: addl $0x1,0x28(%rbx)
ddb{0}> show proc
PROC (syz-executor3824244753) pid=32750 stat=onproc
flags process=0 proc=0
pri=50, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff800021192540,0xffff800021193cf0
process=0xffff8000211f7620 user=0xffff8000211ff000, vmspace=0xfffffd8070acdb90
estcpu=36, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb{0}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
18628 35920 99008 0 3 0 lockflk syz-executor3824244753
81509 29344 89458 0 3 0 lockflk syz-executor3824244753
99232 196077 84468 0 3 0 lockflk syz-executor3824244753
*26172 32750 56548 0 7 0 syz-executor3824244753
5151 186564 48998 0 3 0x80 nanoslp syz-executor3824244753
82521 512317 48998 0 3 0x80 nanoslp syz-executor3824244753
37342 391057 48998 0 3 0x80 nanoslp syz-executor3824244753
85199 52638 48998 0 3 0x80 nanoslp syz-executor3824244753
56548 90145 48998 0 3 0x80 nanoslp syz-executor3824244753
84468 10416 48998 0 3 0x80 nanoslp syz-executor3824244753
99008 497388 48998 0 3 0x80 nanoslp syz-executor3824244753
89458 298492 48998 0 3 0x80 nanoslp syz-executor3824244753
48998 215837 96802 0 3 0x82 nanoslp syz-executor3824244753
96802 349695 92859 0 3 0x10008a sigsusp ksh
92859 446585 2168 0 3 0x9a kqread sshd
96558 428914 1 0 3 0x100083 ttyin getty
2168 465351 1 0 3 0x88 kqread sshd
21763 521931 36152 74 3 0x1100092 bpf pflogd
36152 121026 1 0 3 0x80 netio pflogd
16251 374712 84715 73 3 0x1100090 kqread syslogd
84715 6513 1 0 3 0x100082 netio syslogd
29116 345551 1 0 3 0x100080 kqread resolvd
91223 64900 2224 77 3 0x100092 kqread dhcpleased
14449 20130 2224 77 3 0x100092 kqread dhcpleased
2224 341632 1 0 3 0x80 kqread dhcpleased
1541 109059 0 0 3 0x14200 bored smr
73141 508431 0 0 3 0x14200 pgzero zerothread
19358 228342 0 0 3 0x14200 aiodoned aiodoned
56414 387776 0 0 3 0x14200 syncer update
45416 331533 0 0 3 0x14200 cleaner cleaner
65310 121593 0 0 3 0x14200 reaper reaper
98804 2362 0 0 3 0x14200 pgdaemon pagedaemon
75534 166076 0 0 3 0x14200 bored viomb
12650 218557 0 0 3 0x40014200 acpi0 acpi0
21840 445146 0 0 7 0x40014200 idle1
87651 438606 0 0 3 0x14200 bored softnet
29279 489971 0 0 3 0x14200 bored systqmp
15528 467937 0 0 3 0x14200 bored systq
14096 377589 0 0 3 0x40014200 bored softclock
57035 292852 0 0 3 0x40014200 idle0
1 511746 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{0}> show all locks
Process 26172 (syz-executor3824244753) thread 0xffff800021192000 (32750)
exclusive rwlock lockflk r = 0 (0xffffffff8291bb40)
#0 witness_lock+0x44d
#1 lf_advlock+0x189 sys/kern/vfs_lockf.c:263
#2 VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
#3 closef+0xe5
#4 syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
#4 syscall+0x489 sys/arch/amd64/amd64/trap.c:585
#5 Xsyscall+0x128
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10161 6456K 6478K 78643K 180684 0
pcb 13 8K 8K 78643K 13 0
rtable 62 2K 2K 78643K 112 0
ifaddr 29 8K 8K 78643K 32 0
counters 40 33K 33K 78643K 40 0
ioctlops 0 0K 4K 78643K 1479 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 5 0
vnodes 1171 73K 73K 78643K 254399 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 1K 78643K 2 0
VM map 2 1K 1K 78643K 2 0
sem 2 0K 0K 78643K 2 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 4 6K 17K 78643K 508309 0
proc 67 87K 87K 78643K 282 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
in_multi 11 0K 0K 78643K 11 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 97 440K 440K 78643K 97 0
exec 0 0K 2K 78643K 432 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 95 5K 5K 78643K 171698 0
UVM aobj 3 2K 2K 78643K 3 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
NDP 4 0K 0K 78643K 4 0
temp 24 4690K 4753K 78643K 172778 0
kqueue 11 16K 18K 78643K 24 0
SYN cache 2 16K 16K 78643K 2 0
ddb{0}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 22 0 0 1 0 1 1 0 8 0
rtpcb 120 17 0 14 1 0 1 1 0 8 0
rtentry 112 23 0 1 1 0 1 1 0 8 0
unpcb 136 35 0 20 1 0 1 1 0 8 0
syncache 296 5 0 5 2 2 0 1 0 8 0
tcpcb 736 8 0 5 1 0 1 1 0 8 0
arp 120 2 0 0 1 0 1 1 0 8 0
inpcb 304 32 0 26 1 0 1 1 0 8 0
pfosfp 40 1428 0 1005 5 0 5 5 0 8 0
pfosfpen 112 1428 0 714 21 0 21 21 0 8 0
pfstitem 24 8 0 7 2 1 1 1 0 8 0
pfstkey 112 8 0 7 2 1 1 1 0 8 0
pfstate 320 8 0 7 2 1 1 1 0 8 0
pfrule 1360 21 0 16 2 1 1 2 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 97 0 0 7 0 7 7 0 8 0
art_table 32 98 0 0 1 0 1 1 0 8 0
art_node 16 22 0 2 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 85210 0 83826 87 0 87 87 0 8 0
ffsino 272 85210 0 83826 93 0 93 93 0 8 0
nchpl 144 85385 0 83835 58 0 58 58 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 224 5926 0 0 349 0 349 349 0 8 0
namei 1024 2376511 0 2376511 2 1 1 1 0 8 1
percpumem 16 32 0 0 1 0 1 1 0 8 0
scxspl 216 4234 0 4234 76 75 1 8 0 8 1
plimitpl 152 16 0 9 1 0 1 1 0 8 0
sigapl 424 169765 0 169720 6 0 6 6 0 8 0
knotepl 120 56 0 0 2 0 2 2 0 8 0
kqueuepl 216 20 0 13 1 0 1 1 0 8 0
pipepl 336 86 0 83 2 1 1 1 0 8 0
fdescpl 496 169751 0 169724 4 0 4 4 0 8 0
filepl 152 1864929 0 1864859 4 0 4 4 0 8 1
lockfpl 104 318975 0 318973 1 0 1 1 0 8 0
lockfspl 48 161044 0 161042 1 0 1 1 0 8 0
sessionpl 144 18 0 9 1 0 1 1 0 8 0
pgrppl 48 18 0 9 1 0 1 1 0 8 0
ucredpl 96 1524986 0 1524974 1 0 1 1 0 8 0
zombiepl 144 169724 0 169720 2 1 1 1 0 8 0
processpl 1064 169765 0 169720 4 0 4 4 0 8 0
procpl 672 169765 0 169720 4 0 4 4 0 8 0
sockpl 480 84 0 60 5 1 4 4 0 8 0
mcl8k 8192 3 0 0 1 0 1 1 0 8 0
mcl4k 4096 3 0 0 1 0 1 1 0 8 0
mcl2k 2048 68 0 0 9 1 8 8 0 8 0
mtagpl 96 3 0 0 1 0 1 1 0 8 0
mbufpl 256 134 0 0 7 0 7 7 0 8 0
bufpl 288 2014 0 93 138 0 138 138 0 8 0
anonpl 24 1058003 0 1055650 17 2 15 17 0 186 0
amapchunkpl 152 173428 0 173272 8 1 7 8 0 158 0
amappl16 200 169465 0 169462 2 1 1 1 0 8 0
amappl15 192 67 0 64 1 0 1 1 0 8 0
amappl14 184 2 0 1 1 0 1 1 0 8 0
amappl13 176 35 0 34 2 1 1 1 0 8 0
amappl12 168 9 0 9 2 2 0 1 0 8 0
amappl11 160 48 0 34 1 0 1 1 0 8 0
amappl10 152 4 0 2 1 0 1 1 0 8 0
amappl9 144 450 0 448 1 0 1 1 0 8 0
amappl8 136 370 0 367 1 0 1 1 0 8 0
amappl7 128 65 0 62 1 0 1 1 0 8 0
amappl6 120 115 0 102 1 0 1 1 0 8 0
amappl5 112 169628 0 169607 1 0 1 1 0 8 0
amappl4 104 641 0 620 1 0 1 1 0 8 0
amappl3 96 121 0 112 1 0 1 1 0 8 0
amappl2 88 370 0 332 1 0 1 1 0 8 0
amappl1 80 686594 0 686196 10 1 9 10 0 8 0
amappl 88 171417 0 171340 2 0 2 2 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 2 0 0 1 0 1 1 0 8 0
uaddrrnd 24 169751 0 169724 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 169751 0 169724 1 0 1 1 0 8 0
vmmpekpl 168 387547 0 387530 1 0 1 1 0 8 0
vmmpepl 168 2737693 0 2736666 89 44 45 48 0 357 0
vmsppl 368 169750 0 169724 3 0 3 3 0 8 0
rwobjpl 56 183523 0 177035 92 0 92 92 0 8 0
pdppl 4096 339509 0 339448 199 138 61 69 0 8 0
pvpl 32 4718211 0 4713850 43 6 37 43 0 265 0
pmappl 248 169750 0 169724 2 0 2 2 0 8 0
extentpl 40 58 0 38 1 0 1 1 0 8 0
phpool 112 559 0 144 13 0 13 13 0 8 0
ddb{0}> machine ddbcpu 0
Invalid cpu 0
ddb{0}> trace
lf_advlock(ffff800000bcf0e0,0,fffffd806d5bf1f0,2,ffff8000212044c0,40) at lf_advlock+0x21f ls_ref sys/kern/vfs_lockf.c:140 [inline]
lf_advlock(ffff800000bcf0e0,0,fffffd806d5bf1f0,2,ffff8000212044c0,40) at lf_advlock+0x21f sys/kern/vfs_lockf.c:281
VOP_ADVLOCK(fffffd806caccb68,fffffd806d5bf1f0,2,ffff8000212044c0,40) at VOP_ADVLOCK+0x71 sys/kern/vfs_vops.c:628
closef(fffffd8075a19988,ffff800021192000) at closef+0xe5
syscall(ffff8000212045f0) at syscall+0x489 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff8000212045f0) at syscall+0x489 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe8490, count: -5
ddb{0}> machine ddbcpu 1
Stopped at x86_ipi_db+0x1a: addq $0x8,%rsp
ddb{1}> trace
x86_ipi_db(ffff800020ce8ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
acpicpu_idle() at acpicpu_idle+0x312 sys/dev/acpi/acpicpu.c:1206
sched_idle(ffff800020ce8ff0) at sched_idle+0x417 sys/kern/kern_sched.c:178
end trace frame: 0x0, count: -5

Reply all
Reply to author
Forward
0 new messages