assert "cpipe->pipe_buffer.cnt == 0" failed in sys_pipe.c

5 views
Skip to first unread message

syzbot

unread,
Jul 9, 2019, 10:27:07 AM7/9/19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: c05fa0b5 The system calls getgroups(2) and setgroups(2) pa..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13d5f3c3a00000
kernel config: https://syzkaller.appspot.com/x/.config?x=60e2b7157576c8d7
dashboard link: https://syzkaller.appspot.com/bug?extid=b559fa9d3292c3cb0343

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b559fa...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "cpipe->pipe_buffer.cnt == 0" failed:
file "/syzkaller/managers/main/kernel/sys/kern/sys_pipe.c", line 223
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*321386 46521 0 0 0x4000000 0 syz-executor.1
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:212
__assert(ffffffff81f8ad79,ffffffff81f99791,df,ffffffff81f2c9d6) at
__assert+0x2e sys/kern/subr_prf.c:159
pipespace(fffffd8036450628,10000) at pipespace+0x16f sys/kern/sys_pipe.c:219
pipe_write(fffffd8035f36c40,ffff800017a087a8,0) at pipe_write+0x952
sys/kern/sys_pipe.c:472
dofilewritev(ffff8000ffff38c8,4,ffff800017a087a8,0,ffff800017a088b0) at
dofilewritev+0x1ac sys/kern/sys_generic.c:364
sys_write(ffff8000ffff38c8,ffff800017a08848,ffff800017a088b0) at
sys_write+0x83 sys/kern/sys_generic.c:284
syscall(ffff800017a08910) at syscall+0x508
Xsyscall(6,0,c,0,3,449435551b0) at Xsyscall+0x128
end of kernel
end trace frame: 0x44c25765b90, count: 6
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
kernel diagnostic assertion "cpipe->pipe_buffer.cnt == 0" failed:
file "/syzkaller/managers/main/kernel/sys/kern/sys_pipe.c", line 223
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:212
__assert(ffffffff81f8ad79,ffffffff81f99791,df,ffffffff81f2c9d6) at
__assert+0x2e sys/kern/subr_prf.c:159
pipespace(fffffd8036450628,10000) at pipespace+0x16f sys/kern/sys_pipe.c:219
pipe_write(fffffd8035f36c40,ffff800017a087a8,0) at pipe_write+0x952
sys/kern/sys_pipe.c:472
dofilewritev(ffff8000ffff38c8,4,ffff800017a087a8,0,ffff800017a088b0) at
dofilewritev+0x1ac sys/kern/sys_generic.c:364
sys_write(ffff8000ffff38c8,ffff800017a08848,ffff800017a088b0) at
sys_write+0x83 sys/kern/sys_generic.c:284
syscall(ffff800017a08910) at syscall+0x508
Xsyscall(6,0,c,0,3,449435551b0) at Xsyscall+0x128
end of kernel
end trace frame: 0x44c25765b90, count: -9
ddb> show registers
rdi 0xffffffff81c87f67 db_enter+0x17
rsi 0x3d1a __ALIGN_SIZE+0x2d1a
rbp 0xffff800017a08520
rbx 0xffff800017a085d0
rdx 0x3d1b __ALIGN_SIZE+0x2d1b
rcx 0xffff800016ded000
rax 0xffff800016ded000
r8 0xffff800017a084e0
r9 0x1
r10 0xffff800000997f80
r11 0xfd18cd0874d08145
r12 0x3000000008
r13 0xffff800017a08530
r14 0x100
r15 0x1
rip 0xffffffff81c87f68 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff800017a08510
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor.1) pid=321386 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=16, usrpri=81, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff3b40,0xffff8000ffff3170
process=0xffff8000ffff6d90 user=0xffff800017a03000,
vmspace=0xfffffd803f013110
estcpu=31, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
9056 109734 16454 0 2 0 syz-executor.0
9056 308703 16454 0 3 0x4000080 kqread syz-executor.0
46521 265240 48238 0 2 0 syz-executor.1
46521 373024 48238 0 2 0x4000000 syz-executor.1
46521 37230 48238 0 2 0x4000000 syz-executor.1
*46521 321386 48238 0 7 0x4000000 syz-executor.1
47579 185211 0 0 3 0x14200 bored sosplice
48238 461056 60544 0 3 0x82 nanosleep syz-executor.1
16454 351175 60544 0 3 0x82 nanosleep syz-executor.0
60544 105611 11508 0 3 0x82 kqread syz-fuzzer
60544 39875 11508 0 3 0x4000082 thrsleep syz-fuzzer
60544 383306 11508 0 3 0x4000082 thrsleep syz-fuzzer
60544 398179 11508 0 3 0x4000082 thrsleep syz-fuzzer
60544 121080 11508 0 3 0x4000082 thrsleep syz-fuzzer
60544 487764 11508 0 3 0x4000082 thrsleep syz-fuzzer
60544 516199 11508 0 3 0x4000082 thrsleep syz-fuzzer
11508 149330 5108 0 3 0x10008a pause ksh
5108 193597 10050 0 3 0x92 select sshd
39007 338760 1 0 3 0x100083 ttyin getty
10050 62743 1 0 3 0x80 select sshd
37976 307909 90044 73 3 0x100090 kqread syslogd
90044 216665 1 0 3 0x100082 netio syslogd
68225 487720 1 77 3 0x100090 poll dhclient
60682 330584 1 0 3 0x80 poll dhclient
70048 450380 0 0 2 0x14200 zerothread
93370 217747 0 0 3 0x14200 aiodoned aiodoned
58933 267609 0 0 3 0x14200 syncer update
68561 501575 0 0 3 0x14200 cleaner cleaner
78771 237447 0 0 3 0x14200 reaper reaper
86685 331720 0 0 3 0x14200 pgdaemon pagedaemon
40101 143548 0 0 3 0x14200 bored crynlk
5266 447670 0 0 3 0x14200 bored crypto
94135 326089 0 0 3 0x40014200 acpi0 acpi0
36074 497697 0 0 3 0x14200 bored softnet
38080 351590 0 0 3 0x14200 bored systqmp
29807 300129 0 0 3 0x14200 bored systq
28372 382823 0 0 3 0x40014200 bored softclock
49920 129996 0 0 3 0x40014200 idle0
16796 41435 0 0 3 0x14200 bored smr
1 470138 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9495 6338K 6974K 78643K 13452 0 0
pcb 23 9K 11K 78643K 478 0 0
rtable 111 4K 4K 78643K 428 0 0
ifaddr 56 13K 14K 78643K 158 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 75 0 0
iov 0 0K 32K 78643K 126 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1215 76K 77K 78643K 2443 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 5K 78643K 6 0 0
VM map 2 0K 0K 78643K 2 0 0
sem 12 0K 0K 78643K 223 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1793 195K 288K 78643K 12645 0 0
file desc 6 17K 25K 78643K 1599 0 0
sigio 0 0K 0K 78643K 35 0 0
proc 41 30K 54K 78643K 414 0 0
subproc 32 2K 2K 78643K 34 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
ip_moptions 0 0K 0K 78643K 134 0 0
in_multi 33 2K 2K 78643K 125 0 0
ether_multi 1 0K 0K 78643K 27 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 60 265K 265K 78643K 60 0 0
exec 0 0K 1K 78643K 258 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 93 21K 38K 78643K 4431 0 0
UVM aobj 20 2K 2K 78643K 20 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
ip6_options 0 0K 0K 78643K 88 0 0
NDP 11 0K 0K 78643K 47 0 0
temp 123 2713K 2781K 78643K 7353 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 6 0 0 1 0 1 1 0
8 0
inpcbpl 280 452 0 445 1 0 1 1 0
8 0
rtentry 112 45 0 1 2 0 2 2 0
8 0
syncache 264 4 0 4 1 1 0 1 0
8 0
tcpqe 32 32 0 32 4 4 0 1 0
8 0
tcpcb 544 205 0 201 1 0 1 1 0
8 0
nd6 48 6 0 0 1 0 1 1 0
8 0
ppxss 1128 27 0 26 1 0 1 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 188 0 0 12 0 12 12 0
8 0
art_table 32 189 0 0 2 0 2 2 0
8 0
art_node 16 44 0 4 1 0 1 1 0
8 0
semapl 112 221 0 211 1 0 1 1 0
8 0
shmpl 112 18 0 0 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 4155 0 2728 48 1 47 47 0
8 0
ffsino 240 4155 0 2728 85 0 85 85 0
8 0
nchpl 144 6227 0 4584 61 0 61 61 0
8 0
uvmvnodes 72 4788 0 0 88 0 88 88 0
8 0
vnodes 200 4788 0 0 252 0 252 252 0
8 0
namei 1024 16543 0 16543 4 3 1 1 0
8 1
scxspl 192 16876 0 16876 11 10 1 6 0
8 1
plimitpl 152 78 0 71 1 0 1 1 0
8 0
sigapl 432 1770 0 1756 2 0 2 2 0
8 0
futexpl 56 13241 0 13241 6 5 1 1 0
8 1
knotepl 112 241 0 222 1 0 1 1 0
8 0
kqueuepl 104 224 0 220 1 0 1 1 0
8 0
pipepl 112 514 0 493 3 2 1 2 0
8 0
fdescpl 424 1771 0 1756 2 0 2 2 0
8 0
filepl 120 7218 0 7116 5 1 4 5 0
8 0
lockfpl 104 221 0 220 5 4 1 1 0
8 0
lockfspl 48 68 0 67 5 4 1 1 0
8 0
sessionpl 112 17 0 7 1 0 1 1 0
8 0
pgrppl 48 41 0 31 1 0 1 1 0
8 0
ucredpl 96 2014 0 2007 1 0 1 1 0
8 0
zombiepl 144 1756 0 1756 6 5 1 1 0
8 1
processpl 864 1786 0 1756 4 0 4 4 0
8 0
procpl 632 3665 0 3625 4 0 4 4 0
8 0
sosppl 128 48 0 48 2 2 0 1 0
8 0
sockpl 384 872 0 855 7 4 3 4 0
8 1
mcl64k 65536 98 0 98 5 4 1 1 0
8 1
mcl9k 9216 30 0 30 4 3 1 1 0
8 1
mcl8k 8192 21 0 21 2 2 0 1 0
8 0
mcl4k 4096 113 0 113 4 3 1 1 0
8 1
mcl2k2 2112 21 0 21 2 2 0 1 0
8 0
mcl2k 2048 16135 0 16102 16 10 6 8 0
8 1
mtagpl 80 4 0 4 2 2 0 1 0
8 0
mbufpl 256 45329 0 45287 12 7 5 8 0
8 0
bufpl 256 8072 0 3506 286 0 286 286 0
8 0
anonpl 16 222590 0 218692 88 67 21 46 0
62 0
amapchunkpl 152 7285 0 7201 16 12 4 11 0
158 0
amappl16 192 11690 0 11518 71 61 10 31 0
8 0
amappl15 184 750 0 748 1 0 1 1 0
8 0
amappl14 176 798 0 790 1 0 1 1 0
8 0
amappl13 168 7 0 7 1 1 0 1 0
8 0
amappl12 160 9 0 5 1 0 1 1 0
8 0
amappl11 152 874 0 860 1 0 1 1 0
8 0
amappl10 144 60 0 58 2 1 1 1 0
8 0
amappl9 136 241 0 238 1 0 1 1 0
8 0
amappl8 128 126 0 111 1 0 1 1 0
8 0
amappl7 120 29 0 25 1 0 1 1 0
8 0
amappl6 112 868 0 860 1 0 1 1 0
8 0
amappl5 104 776 0 766 1 0 1 1 0
8 0
amappl4 96 1253 0 1227 2 1 1 2 0
8 0
amappl3 88 1665 0 1651 1 0 1 1 0
8 0
amappl2 80 13364 0 13289 4 2 2 3 0
8 0
amappl1 72 37855 0 37428 26 17 9 19 0
8 0
amappl 80 3926 0 3891 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 19 0 0 1 0 1 1 0
8 0
uaddrrnd 24 1771 0 1756 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 1771 0 1756 1 0 1 1 0
8 0
vmmpekpl 168 14510 0 14487 2 0 2 2 0
8 0
vmmpepl 168 210581 0 209254 143 84 59 77 0
357 1
vmsppl 272 1770 0 1756 2 1 1 2 0
8 0
pdppl 4096 3548 0 3512 6 1 5 6 0
8 0
pvpl 32 561263 0 554310 194 115 79 120 0 265
20
pmappl 200 1770 0 1756 1 0 1 1 0
8 0
extentpl 40 41 0 26 1 0 1 1 0
8 0
phpool 112 441 0 33 12 0 12 12 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jul 9, 2019, 11:00:07 AM7/9/19
to syzkaller-o...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: c05fa0b5 The system calls getgroups(2) and setgroups(2) pa..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=146ff2f3a00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12410487a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1694cfc7a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b559fa...@syzkaller.appspotmail.com

login: panic: kernel diagnostic assertion "cpipe->pipe_buffer.cnt == 0"
failed: file "/syzkaller/managers/main/kernel/sys/kern/sys_pipe.c", line 223
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*260067 45648 0 0x2 0x4000000 0 syz-executor4393
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:212
__assert(ffffffff81f8ad79,ffffffff81f99791,df,ffffffff81f2c9d6) at
__assert+0x2e sys/kern/subr_prf.c:159
pipespace(fffffd803b498628,10000) at pipespace+0x16f sys/kern/sys_pipe.c:219
pipe_write(fffffd803616a878,ffff800014990778,0) at pipe_write+0x952
sys/kern/sys_pipe.c:472
dofilewritev(ffff8000ffff5648,7,ffff800014990778,0,ffff800014990880) at
dofilewritev+0x1ac sys/kern/sys_generic.c:364
sys_write(ffff8000ffff5648,ffff800014990818,ffff800014990880) at
sys_write+0x83 sys/kern/sys_generic.c:284
syscall(ffff8000149908e0) at syscall+0x508
Xsyscall(6,0,5e39bfb0138,0,5e39bfb0118,5e39bfb0110) at Xsyscall+0x128
end of kernel
end trace frame: 0x5e61fb4ec30, count: 6
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
kernel diagnostic assertion "cpipe->pipe_buffer.cnt == 0" failed:
file "/syzkaller/managers/main/kernel/sys/kern/sys_pipe.c", line 223
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:212
__assert(ffffffff81f8ad79,ffffffff81f99791,df,ffffffff81f2c9d6) at
__assert+0x2e sys/kern/subr_prf.c:159
pipespace(fffffd803b498628,10000) at pipespace+0x16f sys/kern/sys_pipe.c:219
pipe_write(fffffd803616a878,ffff800014990778,0) at pipe_write+0x952
sys/kern/sys_pipe.c:472
dofilewritev(ffff8000ffff5648,7,ffff800014990778,0,ffff800014990880) at
dofilewritev+0x1ac sys/kern/sys_generic.c:364
sys_write(ffff8000ffff5648,ffff800014990818,ffff800014990880) at
sys_write+0x83 sys/kern/sys_generic.c:284
syscall(ffff8000149908e0) at syscall+0x508
Xsyscall(6,0,5e39bfb0138,0,5e39bfb0118,5e39bfb0110) at Xsyscall+0x128
end of kernel
end trace frame: 0x5e61fb4ec30, count: -9
ddb> show registers
rdi 0
rsi 0x1
rbp 0xffff8000149904f0
rbx 0xffff8000149905a0
rdx 0x2
rcx 0x1
rax 0x1
r8 0xffff8000149904b0
r9 0x1
r10 0x9ddac5ae6114b634
r11 0xd55d3bf75e7a45ac
r12 0x3000000008
r13 0xffff800014990500
r14 0x100
r15 0x1
rip 0xffffffff81c87f68 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff8000149904e0
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor4393) pid=260067 stat=onproc
flags process=2<EXEC> proc=4000000<THREAD>
pri=16, usrpri=51, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff4500,0xffff8000ffff58d0
process=0xffff800014942018 user=0xffff80001498b000,
vmspace=0xfffffd803f013110
estcpu=1, cpticks=2, pctcpu=0.0
user=0, sys=2, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
45648 253492 71971 0 2 0x482 syz-executor4393
45648 115731 71971 0 2 0x4000002 syz-executor4393
45648 38703 71971 0 3 0x4000082 pipewr syz-executor4393
*45648 260067 71971 0 7 0x4000002 syz-executor4393
45648 103528 71971 0 3 0x4000082 fsleep syz-executor4393
45648 75861 71971 0 3 0x4000082 fsleep syz-executor4393
45648 392146 71971 0 3 0x4000082 fsleep syz-executor4393
45648 455744 71971 0 2 0x4000002 syz-executor4393
71971 234144 99194 0 3 0x10008a pause ksh
99194 515210 34369 0 3 0x92 select sshd
12737 522352 1 0 3 0x100083 ttyin getty
34369 510706 1 0 3 0x80 select sshd
16110 153239 77536 73 3 0x100090 kqread syslogd
77536 136398 1 0 3 0x100082 netio syslogd
44596 435276 1 77 3 0x100090 poll dhclient
10734 482124 1 0 3 0x80 poll dhclient
82322 236152 0 0 3 0x14200 pgzero zerothread
64891 67611 0 0 3 0x14200 aiodoned aiodoned
44407 386341 0 0 3 0x14200 syncer update
89078 343488 0 0 3 0x14200 cleaner cleaner
49214 340878 0 0 3 0x14200 reaper reaper
77519 439946 0 0 3 0x14200 pgdaemon pagedaemon
42863 345769 0 0 3 0x14200 bored crynlk
91543 86990 0 0 3 0x14200 bored crypto
25176 50148 0 0 3 0x40014200 acpi0 acpi0
198 190801 0 0 3 0x14200 bored softnet
57872 57968 0 0 3 0x14200 bored systqmp
26068 116655 0 0 3 0x14200 bored systq
94205 30204 0 0 3 0x40014200 bored softclock
79993 270526 0 0 3 0x40014200 idle0
81989 92445 0 0 3 0x14200 bored smr
1 176016 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9428 6307K 6308K 78643K 10521 0 0
pcb 23 9K 9K 78643K 55 0 0
rtable 61 1K 2K 78643K 116 0 0
ifaddr 21 7K 7K 78643K 21 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 13 0 0
iov 0 0K 12K 78643K 2 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1180 74K 74K 78643K 1185 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 1K 78643K 2 0 0
VM map 2 0K 0K 78643K 2 0 0
sem 2 0K 0K 78643K 2 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1793 195K 288K 78643K 12645 0 0
file desc 1 0K 0K 78643K 1 0 0
proc 40 30K 38K 78643K 257 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
in_multi 11 0K 0K 78643K 11 0 0
ether_multi 1 0K 0K 78643K 1 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 18 79K 79K 78643K 18 0 0
exec 0 0K 1K 78643K 152 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 65 11K 11K 78643K 713 0 0
UVM aobj 2 2K 2K 78643K 2 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
NDP 3 0K 0K 78643K 3 0 0
temp 30 2707K 2771K 78643K 1715 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 2 0 0 1 0 1 1 0
8 0
inpcbpl 280 22 0 16 1 0 1 1 0
8 0
rtentry 112 23 0 1 1 0 1 1 0
8 0
syncache 264 5 0 5 1 0 1 1 0
8 1
tcpcb 544 8 0 5 1 0 1 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 96 0 0 6 0 6 6 0
8 0
art_table 32 97 0 0 1 0 1 1 0
8 0
art_node 16 22 0 2 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 1392 0 16 45 0 45 45 0
8 0
ffsino 240 1392 0 16 81 0 81 81 0
8 0
nchpl 144 1567 0 31 57 0 57 57 0
8 0
uvmvnodes 72 1401 0 0 26 0 26 26 0
8 0
vnodes 200 1401 0 0 74 0 74 74 0
8 0
namei 1024 3367 0 3367 2 1 1 1 0
8 1
scxspl 192 2634 0 2634 8 2 6 6 0
8 6
plimitpl 152 14 0 8 1 0 1 1 0
8 0
sigapl 432 176 0 166 2 0 2 2 0
8 0
futexpl 56 16 0 13 1 0 1 1 0
8 0
knotepl 112 5 0 0 1 0 1 1 0
8 0
kqueuepl 104 1 0 0 1 0 1 1 0
8 0
pipepl 112 122 0 111 2 1 1 1 0
8 0
fdescpl 424 177 0 166 2 0 2 2 0
8 0
filepl 120 845 0 796 2 0 2 2 0
8 0
lockfpl 104 8 0 6 2 1 1 1 0
8 0
lockfspl 48 4 0 3 2 1 1 1 0
8 0
sessionpl 112 18 0 9 1 0 1 1 0
8 0
pgrppl 48 18 0 9 1 0 1 1 0
8 0
ucredpl 96 47 0 40 1 0 1 1 0
8 0
zombiepl 144 166 0 166 2 1 1 1 0
8 1
processpl 864 191 0 166 4 0 4 4 0
8 0
procpl 632 198 0 166 3 0 3 3 0
8 0
sockpl 384 64 0 48 2 0 2 2 0
8 0
mcl4k 4096 10 0 10 1 0 1 1 0
8 1
mcl2k 2048 6106 0 6069 8 1 7 8 0
8 2
mtagpl 80 2 0 2 1 1 0 1 0
8 0
mbufpl 256 10399 0 10354 8 3 5 6 0
8 1
bufpl 256 2208 0 262 122 0 122 122 0
8 0
anonpl 16 18242 0 16762 8 2 6 7 0
62 0
amapchunkpl 152 490 0 441 2 0 2 2 0
158 0
amappl16 192 93 0 70 2 0 2 2 0
8 0
amappl14 176 36 0 32 1 0 1 1 0
8 0
amappl12 160 8 0 8 1 0 1 1 0
8 1
amappl11 152 41 0 30 1 0 1 1 0
8 0
amappl10 144 46 0 45 1 0 1 1 0
8 0
amappl9 136 376 0 374 1 0 1 1 0
8 0
amappl8 128 88 0 83 1 0 1 1 0
8 0
amappl7 120 13 0 12 1 0 1 1 0
8 0
amappl6 112 40 0 36 1 0 1 1 0
8 0
amappl5 104 167 0 158 1 0 1 1 0
8 0
amappl4 96 399 0 375 1 0 1 1 0
8 0
amappl3 88 148 0 137 1 0 1 1 0
8 0
amappl2 80 724 0 668 3 1 2 2 0
8 0
amappl1 72 12179 0 11741 16 6 10 16 0
8 0
amappl 80 371 0 345 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 1 0 0 1 0 1 1 0
8 0
uaddrrnd 24 177 0 166 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 177 0 166 1 0 1 1 0
8 0
vmmpekpl 168 5340 0 5326 1 0 1 1 0
8 0
vmmpepl 168 25952 0 25088 50 12 38 48 0
357 0
vmsppl 272 176 0 166 1 0 1 1 0
8 0
pdppl 4096 360 0 332 5 0 5 5 0
8 0
pvpl 32 71901 0 68781 30 4 26 26 0
265 0
pmappl 200 176 0 166 1 0 1 1 0
8 0
extentpl 40 41 0 26 1 0 1 1 0
8 0
phpool 112 241 0 7 7 0 7 7 0
8 0
ddb>

syzbot

unread,
Jul 11, 2019, 1:32:35 PM7/11/19
to Anton Lindqvist, an...@basename.se, syzkaller-o...@googlegroups.com
> #syz test: https://github.com/mptre/openbsd-src pipe

This bug is already marked as fixed. No point in testing.

Reply all
Reply to author
Forward
0 new messages