protection_fault: sblock

0 views
Skip to first unread message

syzbot

unread,
Dec 31, 2021, 6:44:20 PM12/31/21
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 86dca86fec42 Interrups -> Interrupts
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12609557b00000
kernel config: https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link: https://syzkaller.appspot.com/bug?extid=602f1c467b574ffb3d9d

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+602f1c...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at sblock+0x4a: movq 0x8(%rax),%rax
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
the kernel did not panic
ddb> trace
sblock(fffffd806e51cc50,fffffd806e51cce8,1) at sblock+0x4a soassertlocked sys/kern/uipc_socket2.c:323 [inline]
sblock(fffffd806e51cc50,fffffd806e51cce8,1) at sblock+0x4a sys/kern/uipc_socket2.c:378
soreceive(fffffd806e51cc50,0,ffff8000263d4f58,0,0,ffff8000263d4e6c,6a7a0c8b28be7b28) at soreceive+0x203 sys/kern/uipc_socket.c:776
fifo_read(ffff8000263d4ec0) at fifo_read+0xcb sys/miscfs/fifofs/fifo_vnops.c:260
VOP_READ(fffffd8066467708,ffff8000263d4f58,64,fffffd807f7d81e0) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_rdwr(0,fffffd8066467708,ffff800008945500,1002,0,1,5ae5a4c15e0efa7e,ffff8000006b3000,fffffd8069892c88,0) at vn_rdwr+0x105
vndstrategy(fffffd8069892c88) at vndstrategy+0x3b3 sys/dev/vnd.c:342
physio(ffffffff81b097c0,2902,8000,ffffffff81193e20,ffff8000263d53c8) at physio+0x289 sys/kern/kern_physio.c:163
spec_read(ffff8000263d5220) at spec_read+0xec sys/kern/spec_vnops.c:222
VOP_READ(fffffd807a081ca8,ffff8000263d53c8,0,fffffd807f7d8660) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_read(fffffd8068340d38,ffff8000263d53c8,0) at vn_read+0x121 sys/kern/vfs_vnops.c:375
dofilereadv(ffff800027f6c548,4,ffff8000263d53c8,0,ffff8000263d54c0) at dofilereadv+0x19e sys/kern/sys_generic.c:252
sys_read(ffff800027f6c548,ffff8000263d5468,ffff8000263d54c0) at sys_read+0x83 sys/kern/sys_generic.c:172
syscall(ffff8000263d5530) at syscall+0x44e sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xaabf4e89480, count: -14
ddb> show registers
rdi 0
rsi 0x40
rbp 0xffff8000263d4d40
rbx 0x1
rdx 0xffff800000ce9cc0
rcx 0x119a __ALIGN_SIZE+0x19a
rax 0x6fba8db5b3ddddda
r8 0x400
r9 0
r10 0xaef8d28f441e82cb
r11 0x1d46df0da8e7f73f
r12 0
r13 0x1
r14 0xfffffd806e51cd38
r15 0xfffffd806e51cc50
rip 0xffffffff8213f77a sblock+0x4a
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff8000263d4ce0
ss 0x10
sblock+0x4a: movq 0x8(%rax),%rax
ddb> show proc
PROC (syz-executor.2) pid=137399 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=24, usrpri=78, nice=20
forw=0xffffffffffffffff, list=0xffff800027f6c7e8,0xffff800027f6cd38
process=0xffff8000230cefc0 user=0xffff8000263d0000, vmspace=0xfffffd80665c3330
estcpu=36, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
99122 510436 35213 0 2 0 syz-executor.3
99122 482583 35213 0 2 0x4000000 syz-executor.3
1125 498362 45683 0 2 0 syz-executor.2
* 1125 137399 45683 0 7 0x4000000 syz-executor.2
83186 442786 3300 0 2 0 syz-executor.1
83186 326516 3300 0 3 0x4000080 fsleep syz-executor.1
3300 268677 61237 0 3 0x82 nanoslp syz-executor.1
35213 439838 61237 0 3 0x82 nanoslp syz-executor.3
45683 474600 61237 0 3 0x82 nanoslp syz-executor.2
27166 428916 61237 0 2 0x2 syz-executor.0
4019 494204 0 0 3 0x14200 acct acct
59367 439367 0 0 3 0x14280 nfsidl nfsio
68995 395138 0 0 3 0x14280 nfsidl nfsio
4244 177197 0 0 3 0x14280 nfsidl nfsio
69183 261758 0 0 3 0x14280 nfsidl nfsio
69883 378584 0 0 3 0x14280 nfsidl nfsio
50261 468750 0 0 3 0x14280 nfsidl nfsio
25681 144605 0 0 3 0x14280 nfsidl nfsio
17726 246364 0 0 3 0x14280 nfsidl nfsio
43239 360843 0 0 3 0x14280 nfsidl nfsio
60167 439585 0 0 3 0x14280 nfsidl nfsio
40354 313274 0 0 3 0x14280 nfsidl nfsio
59936 457172 0 0 3 0x14280 nfsidl nfsio
40943 385513 0 0 3 0x14280 nfsidl nfsio
63253 186345 0 0 3 0x14280 nfsidl nfsio
6411 63510 0 0 3 0x14280 nfsidl nfsio
57150 173184 0 0 3 0x14280 nfsidl nfsio
30334 308690 0 0 3 0x14280 nfsidl nfsio
81659 271832 0 0 3 0x14280 nfsidl nfsio
39824 42192 0 0 3 0x14280 nfsidl nfsio
34825 21894 0 0 3 0x14280 nfsidl nfsio
65029 480573 0 0 3 0x14200 bored sosplice
61237 44101 68228 0 3 0x82 thrsleep syz-fuzzer
61237 346869 68228 0 3 0x4000082 nanoslp syz-fuzzer
61237 298310 68228 0 3 0x4000082 thrsleep syz-fuzzer
61237 521645 68228 0 3 0x4000082 thrsleep syz-fuzzer
61237 266911 68228 0 3 0x4000082 thrsleep syz-fuzzer
61237 439982 68228 0 3 0x4000082 thrsleep syz-fuzzer
61237 357609 68228 0 3 0x4000082 kqread syz-fuzzer
68228 10952 15405 0 3 0x10008a sigsusp ksh
15405 329660 66891 0 3 0x9a poll sshd
89056 254525 1 0 3 0x100083 ttyin getty
66891 154663 1 0 3 0x88 poll sshd
94858 375286 14660 73 3 0x100090 kqread syslogd
14660 366435 1 0 3 0x100082 netio syslogd
5210 351532 1 0 3 0x100080 kqread resolvd
86887 484764 26629 77 3 0x100092 kqread dhcpleased
75071 415897 26629 77 3 0x100092 kqread dhcpleased
26629 403255 1 0 3 0x80 kqread dhcpleased
82556 480658 0 0 3 0x14200 bored smr
30683 334721 0 0 2 0x14200 zerothread
14283 224347 0 0 3 0x14200 aiodoned aiodoned
38371 426198 0 0 3 0x14200 syncer update
50572 246527 0 0 3 0x14200 cleaner cleaner
56860 188778 0 0 3 0x14200 reaper reaper
21472 390396 0 0 3 0x14200 pgdaemon pagedaemon
34060 513059 0 0 3 0x14200 bored viomb
29317 515643 0 0 3 0x40014200 acpi0 acpi0
39444 72942 0 0 3 0x14200 bored softnet
1305 338702 0 0 3 0x14200 bored systqmp
17907 192849 0 0 3 0x14200 bored systq
41364 436154 0 0 3 0x40014200 bored softclock
88587 476847 0 0 3 0x40014200 idle0
1 64600 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10186 6428K 8123K 78643K 47955 0
pcb 13 20K 23K 78643K 2951 0
rtable 223 32K 34K 78643K 18593 0
ifaddr 96 29K 30K 78643K 2876 0
sysctl 3 1K 1K 78643K 3 0
counters 24 17K 17K 78643K 416 0
ioctlops 0 0K 4K 78643K 2894 0
iov 0 0K 17K 78643K 1813 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1479 93K 93K 78643K 14254 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 9K 78643K 189 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 0K 78643K 2212 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12598 0
file desc 9 29K 45K 78643K 18563 0
sigio 0 0K 0K 78643K 323 0
proc 75 56K 71K 78643K 4178 0
subproc 52 3K 3K 78643K 1596 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 646 0
in_multi 52 3K 3K 78643K 1848 0
ether_multi 1 0K 0K 78643K 223 0
mrt 1 0K 0K 78643K 56 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 241 1076K 1076K 78643K 241 0
exec 0 0K 2K 78643K 5832 0
pfkey data 0 0K 0K 78643K 5 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 386 569K 583K 78643K 217111 0
UVM aobj 131 9K 9K 78643K 155 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 729 0
NDP 9 0K 1K 78643K 658 0
temp 118 4231K 4675K 78643K 212820 0
kqueue 11 16K 23K 78643K 1452 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 13910 0 13907 90 87 3 5 0 8 2
rtentry 112 1543 0 1485 3 1 2 2 0 8 0
unpcb 136 11033 0 11020 113 110 3 8 0 8 2
syncache 296 92 0 92 19 19 0 1 0 8 0
tcpqe 32 18 0 18 8 8 0 1 0 8 0
tcpcb 736 7132 0 7128 233 232 1 14 0 8 0
arp 88 256 0 246 1 0 1 1 0 8 0
ipq 40 47 0 47 14 14 0 1 0 8 0
ipqe 40 1373 0 1373 14 14 0 1 0 8 0
inpcb 304 16202 0 16195 254 253 1 12 0 8 0
rttmr 72 12 0 12 4 4 0 1 0 8 0
ip6q 72 21 0 21 2 2 0 1 0 8 0
ip6af 40 41 0 41 2 2 0 1 0 8 0
nd6 48 386 0 374 1 0 1 1 0 8 0
pkpcb 40 110 0 110 5 5 0 1 0 8 0
kcovpl 48 122 0 118 1 0 1 1 0 8 0
ppxss 1152 154 0 153 3 2 1 1 0 8 0
pfstscr 40 28 0 28 6 6 0 1 0 8 0
pffrent 40 1 0 1 1 1 0 1 0 8 0
pfosfp 40 5 0 4 1 0 1 1 0 8 0
pfosfpen 112 5 0 4 1 0 1 1 0 8 0
pfrktable 1344 1624 0 1585 13 9 4 4 0 8 0
pftag 88 104 0 93 4 3 1 1 0 8 0
pfqueue 264 2 0 0 1 0 1 1 0 8 0
pfstitem 24 13 0 13 3 3 0 1 0 8 0
pfstkey 112 55 0 55 7 7 0 1 0 8 0
pfstate 320 31 0 31 7 7 0 1 0 8 0
pfrule 1360 1651 0 1255 39 5 34 34 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 6450 0 6205 69 53 16 18 0 8 0
art_table 32 6451 0 6205 7 4 3 3 0 8 0
art_node 16 1542 0 1493 1 0 1 1 0 8 0
sysvmsgpl 40 2 0 2 1 1 0 1 0 8 0
semupl 112 3 0 3 1 1 0 1 0 8 0
semapl 112 2210 0 2200 1 0 1 1 0 8 0
shmpl 112 152 0 24 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 26019 0 24572 91 0 91 91 0 8 0
ffsino 240 26019 0 24572 86 0 86 86 0 8 0
nchpl 144 49704 0 48116 61 0 61 61 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 224 5926 0 0 349 0 349 349 0 8 0
namei 1024 181545 0 181545 7 6 1 1 0 8 1
vcpupl 1984 202 0 0 26 0 26 26 0 8 0
vmpool 528 214 0 12 15 1 14 14 0 8 0
pfiaddrpl 120 902 0 703 9 2 7 7 0 8 0
scsiplug 72 8 0 8 2 2 0 1 0 8 0
scxspl 216 149080 0 149080 43 42 1 8 0 8 1
plimitpl 152 2490 0 2480 1 0 1 1 0 8 0
sigapl 424 18446 0 18391 8 1 7 7 0 8 0
futexpl 64 177429 0 177428 5 4 1 1 0 8 0
knotepl 112 16513 0 16463 6 4 2 4 0 8 0
kqueuepl 184 4098 0 4091 49 48 1 7 0 8 0
pipepl 304 3160 0 3144 83 81 2 7 0 8 0
fdescpl 432 18410 0 18390 3 0 3 3 0 8 0
filepl 120 135758 0 135608 198 191 7 13 0 8 2
lockfpl 104 4855 0 4852 14 13 1 2 0 8 0
lockfspl 48 1438 0 1435 1 0 1 1 0 8 0
sessionpl 144 137 0 125 1 0 1 1 0 8 0
pgrppl 48 207 0 195 1 0 1 1 0 8 0
ucredpl 96 16649 0 16639 1 0 1 1 0 8 0
zombiepl 144 18391 0 18391 6 5 1 1 0 8 1
processpl 1000 18446 0 18391 16 8 8 8 0 8 0
procpl 672 44178 0 44114 50 43 7 7 0 8 1
sosppl 168 125 0 125 20 20 0 1 0 8 0
sockpl 448 41337 0 41314 658 647 11 31 0 8 8
mcl64k 65536 558 0 558 52 52 0 1 0 8 0
mcl16k 16384 142 0 142 33 33 0 1 0 8 0
mcl12k 12288 547 0 547 41 41 0 1 0 8 0
mcl9k 9216 262 0 262 40 40 0 1 0 8 0
mcl8k 8192 1238 0 1238 37 36 1 1 0 8 1
mcl4k 4096 1880 0 1880 36 35 1 1 0 8 1
mcl2k2 2112 140 0 140 45 45 0 1 0 8 0
mcl2k 2048 111934 0 111888 29 22 7 11 0 8 0
mtagpl 96 5135 0 5034 50 46 4 15 0 8 0
mbufpl 256 445191 0 444795 4112 4076 36 457 0 8 7
bufpl 288 42505 0 36087 459 0 459 459 0 8 0
anonpl 24 5036992 0 5017978 359 235 124 144 0 188 0
amapchunkpl 152 579757 0 579105 153 126 27 40 0 158 0
amappl16 200 51738 0 50913 226 179 47 57 0 8 0
amappl15 192 3036 0 3036 9 9 0 1 0 8 0
amappl14 184 3278 0 3276 1 0 1 1 0 8 0
amappl13 176 2044 0 2043 1 0 1 1 0 8 0
amappl12 168 3903 0 3896 1 0 1 1 0 8 0
amappl11 160 1985 0 1974 1 0 1 1 0 8 0
amappl10 152 2457 0 2448 1 0 1 1 0 8 0
amappl9 144 2170 0 2167 1 0 1 1 0 8 0
amappl8 136 3785 0 3702 3 0 3 3 0 8 0
amappl7 128 1942 0 1930 1 0 1 1 0 8 0
amappl6 120 2617 0 2598 1 0 1 1 0 8 0
amappl5 112 14141 0 14122 1 0 1 1 0 8 0
amappl4 104 8584 0 8562 1 0 1 1 0 8 0
amappl3 96 6045 0 6028 1 0 1 1 0 8 0
amappl2 88 4523 0 4480 2 0 2 2 0 8 0
amappl1 80 323065 0 322602 18 7 11 12 0 8 0
amappl 88 214756 0 214536 7 1 6 6 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 154 0 24 3 0 3 3 0 8 0
uaddrrnd 24 18624 0 18402 2 0 2 2 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 18624 0 18402 2 0 2 2 0 8 0
vmmpekpl 168 111944 0 111887 3 0 3 3 0 8 0
vmmpepl 168 1717781 0 1715088 604 476 128 158 0 357 0
vmsppl 272 18623 0 18402 18 3 15 15 0 8 0
rwobjpl 24 389113 0 381373 59 11 48 49 0 8 0
pdppl 4096 37254 0 37006 354 104 250 250 0 8 2
pvpl 32 8449262 0 8427926 541 355 186 240 0 265 0
pmappl 216 18623 0 18402 15 2 13 13 0 8 0
extentpl 40 57 0 38 1 0 1 1 0 8 0
phpool 112 6320 0 5306 75 39 36 38 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
sblock(fffffd806e51cc50,fffffd806e51cce8,1) at sblock+0x4a soassertlocked sys/kern/uipc_socket2.c:323 [inline]
sblock(fffffd806e51cc50,fffffd806e51cce8,1) at sblock+0x4a sys/kern/uipc_socket2.c:378
soreceive(fffffd806e51cc50,0,ffff8000263d4f58,0,0,ffff8000263d4e6c,6a7a0c8b28be7b28) at soreceive+0x203 sys/kern/uipc_socket.c:776
fifo_read(ffff8000263d4ec0) at fifo_read+0xcb sys/miscfs/fifofs/fifo_vnops.c:260
VOP_READ(fffffd8066467708,ffff8000263d4f58,64,fffffd807f7d81e0) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_rdwr(0,fffffd8066467708,ffff800008945500,1002,0,1,5ae5a4c15e0efa7e,ffff8000006b3000,fffffd8069892c88,0) at vn_rdwr+0x105
vndstrategy(fffffd8069892c88) at vndstrategy+0x3b3 sys/dev/vnd.c:342
physio(ffffffff81b097c0,2902,8000,ffffffff81193e20,ffff8000263d53c8) at physio+0x289 sys/kern/kern_physio.c:163
spec_read(ffff8000263d5220) at spec_read+0xec sys/kern/spec_vnops.c:222
VOP_READ(fffffd807a081ca8,ffff8000263d53c8,0,fffffd807f7d8660) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_read(fffffd8068340d38,ffff8000263d53c8,0) at vn_read+0x121 sys/kern/vfs_vnops.c:375
dofilereadv(ffff800027f6c548,4,ffff8000263d53c8,0,ffff8000263d54c0) at dofilereadv+0x19e sys/kern/sys_generic.c:252
sys_read(ffff800027f6c548,ffff8000263d5468,ffff8000263d54c0) at sys_read+0x83 sys/kern/sys_generic.c:172
syscall(ffff8000263d5530) at syscall+0x44e sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xaabf4e89480, count: -14
ddb> machine ddbcpu 1
No such command
ddb> trace
sblock(fffffd806e51cc50,fffffd806e51cce8,1) at sblock+0x4a soassertlocked sys/kern/uipc_socket2.c:323 [inline]
sblock(fffffd806e51cc50,fffffd806e51cce8,1) at sblock+0x4a sys/kern/uipc_socket2.c:378
soreceive(fffffd806e51cc50,0,ffff8000263d4f58,0,0,ffff8000263d4e6c,6a7a0c8b28be7b28) at soreceive+0x203 sys/kern/uipc_socket.c:776
fifo_read(ffff8000263d4ec0) at fifo_read+0xcb sys/miscfs/fifofs/fifo_vnops.c:260
VOP_READ(fffffd8066467708,ffff8000263d4f58,64,fffffd807f7d81e0) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_rdwr(0,fffffd8066467708,ffff800008945500,1002,0,1,5ae5a4c15e0efa7e,ffff8000006b3000,fffffd8069892c88,0) at vn_rdwr+0x105
vndstrategy(fffffd8069892c88) at vndstrategy+0x3b3 sys/dev/vnd.c:342
physio(ffffffff81b097c0,2902,8000,ffffffff81193e20,ffff8000263d53c8) at physio+0x289 sys/kern/kern_physio.c:163
spec_read(ffff8000263d5220) at spec_read+0xec sys/kern/spec_vnops.c:222
VOP_READ(fffffd807a081ca8,ffff8000263d53c8,0,fffffd807f7d8660) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_read(fffffd8068340d38,ffff8000263d53c8,0) at vn_read+0x121 sys/kern/vfs_vnops.c:375
dofilereadv(ffff800027f6c548,4,ffff8000263d53c8,0,ffff8000263d54c0) at dofilereadv+0x19e sys/kern/sys_generic.c:252
sys_read(ffff800027f6c548,ffff8000263d5468,ffff8000263d54c0) at sys_read+0x83 sys/kern/sys_generic.c:172
syscall(ffff8000263d5530) at syscall+0x44e sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xaabf4e89480, count: -14


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 1, 2022, 1:55:17 AM1/1/22
to syzkaller-o...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 86dca86fec42 Interrups -> Interrupts
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12a2f957b00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1680fc07b00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+602f1c...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at sblock+0x4a: movq 0x8(%rax),%rax
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
the kernel did not panic
ddb> trace
sblock(fffffd806e52b710,fffffd806e52b7a8,1) at sblock+0x4a soassertlocked sys/kern/uipc_socket2.c:323 [inline]
sblock(fffffd806e52b710,fffffd806e52b7a8,1) at sblock+0x4a sys/kern/uipc_socket2.c:378
soreceive(fffffd806e52b710,0,ffff80002172d878,0,0,ffff80002172d78c,d50d58f415e1f532) at soreceive+0x203 sys/kern/uipc_socket.c:776
fifo_read(ffff80002172d7e0) at fifo_read+0xcb sys/miscfs/fifofs/fifo_vnops.c:260
VOP_READ(fffffd806ad14478,ffff80002172d878,64,fffffd807f7d8780) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_rdwr(0,fffffd806ad14478,ffff800008943500,1002,0,1,b29ce688c93c242c,ffff8000006b3000,fffffd80708ea5e0,0) at vn_rdwr+0x105
vndstrategy(fffffd80708ea5e0) at vndstrategy+0x3b3 sys/dev/vnd.c:342
physio(ffffffff81b097c0,2902,8000,ffffffff81193e20,ffff80002172dce8) at physio+0x289 sys/kern/kern_physio.c:163
spec_read(ffff80002172db40) at spec_read+0xec sys/kern/spec_vnops.c:222
VOP_READ(fffffd806ed62bc8,ffff80002172dce8,0,fffffd807f7d88a0) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_read(fffffd806d018e28,ffff80002172dce8,0) at vn_read+0x121 sys/kern/vfs_vnops.c:375
dofilereadv(ffff80002165dce0,4,ffff80002172dce8,0,ffff80002172dde0) at dofilereadv+0x19e sys/kern/sys_generic.c:252
sys_read(ffff80002165dce0,ffff80002172dd88,ffff80002172dde0) at sys_read+0x83 sys/kern/sys_generic.c:172
syscall(ffff80002172de50) at syscall+0x44e sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x246e8578f70, count: -14
ddb> show registers
rdi 0
rsi 0x40
rbp 0xffff80002172d660
rbx 0x1
rdx 0x1
rcx 0xffff80002165dce4
rax 0x40afdfe4b41281f8
r8 0x400
r9 0
r10 0xeb767bfafa06e58c
r11 0x78b64149214d8c1a
r12 0
r13 0x1
r14 0xfffffd806e52b7f8
r15 0xfffffd806e52b710
rip 0xffffffff8213f77a sblock+0x4a
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80002172d600
ss 0x10
sblock+0x4a: movq 0x8(%rax),%rax
ddb> show proc
PROC (syz-executor.2) pid=339973 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=24, usrpri=86, nice=20
forw=0xffffffffffffffff, list=0xffff80002165da40,0xffff80002165ca90
process=0xffff80002166ebd8 user=0xffff800021728000, vmspace=0xfffffd806af59560
estcpu=36, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
3220 10113 9167 0 2 0 syz-executor.0
75198 236080 30024 0 2 0 syz-executor.3
75198 292750 30024 0 2 0x4000000 syz-executor.3
31333 512444 51194 0 2 0 syz-executor.1
31333 349823 51194 0 2 0x4000000 syz-executor.1
15527 311584 38643 0 2 0 syz-executor.2
*15527 339973 38643 0 7 0x4000000 syz-executor.2
15527 73347 38643 0 3 0x4000080 fsleep syz-executor.2
30024 428016 77017 0 2 0x482 syz-executor.3
38643 208369 77017 0 2 0x482 syz-executor.2
51194 132667 77017 0 2 0x482 syz-executor.1
9167 292169 77017 0 2 0x482 syz-executor.0
77017 356402 2404 0 3 0x82 kqread syz-execprog
77017 27397 2404 0 2 0x4000482 syz-execprog
77017 359130 2404 0 3 0x4000082 thrsleep syz-execprog
77017 304134 2404 0 3 0x4000082 thrsleep syz-execprog
77017 1812 2404 0 3 0x4000082 thrsleep syz-execprog
77017 305282 2404 0 3 0x4000082 thrsleep syz-execprog
2404 517055 75247 0 3 0x10008a sigsusp ksh
75247 27671 23046 0 3 0x9a poll sshd
95443 468751 1 0 3 0x100083 ttyin getty
23046 455818 1 0 3 0x88 poll sshd
24646 242902 34592 73 2 0x100010 syslogd
34592 396542 1 0 3 0x100082 netio syslogd
56175 332448 1 0 3 0x100080 kqread resolvd
31908 232566 34650 77 3 0x100092 kqread dhcpleased
66713 511616 34650 77 3 0x100092 kqread dhcpleased
34650 57041 1 0 3 0x80 kqread dhcpleased
65100 49579 0 0 3 0x14200 bored smr
64221 39312 0 0 2 0x14200 zerothread
65383 103619 0 0 3 0x14200 aiodoned aiodoned
30028 284373 0 0 3 0x14200 syncer update
42180 100238 0 0 3 0x14200 cleaner cleaner
67375 332711 0 0 3 0x14200 reaper reaper
92243 365898 0 0 3 0x14200 pgdaemon pagedaemon
49363 386136 0 0 3 0x14200 bored viomb
12411 488430 0 0 3 0x40014200 acpi0 acpi0
39600 297311 0 0 3 0x14200 bored softnet
34478 563 0 0 3 0x14200 bored systqmp
91400 358779 0 0 3 0x14200 bored systq
72614 449475 0 0 3 0x40014200 bored softclock
91773 62802 0 0 3 0x40014200 idle0
1 277340 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10138 6390K 6412K 78643K 11879 0
pcb 13 8K 8K 78643K 13 0
rtable 150 4K 4K 78643K 234 0
ifaddr 53 12K 12K 78643K 53 0
counters 23 16K 16K 78643K 23 0
ioctlops 0 0K 2K 78643K 29 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1178 74K 74K 78643K 3620 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 1K 78643K 2 0
VM map 2 0K 0K 78643K 2 0
sem 2 0K 0K 78643K 2 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12598 0
file desc 10 33K 49K 78643K 2506 0
proc 55 54K 71K 78643K 337 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
in_multi 55 3K 3K 78643K 55 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 25 122K 122K 78643K 25 0
exec 0 0K 2K 78643K 427 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 180 38K 39K 78643K 38560 0
UVM aobj 3 2K 2K 78643K 3 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
NDP 7 0K 1K 78643K 15 0
temp 36 4178K 4243K 78643K 9486 0
kqueue 10 14K 14K 78643K 10 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 28 0 25 1 0 1 1 0 8 0
rtentry 112 67 0 1 2 0 2 2 0 8 0
unpcb 136 4905 0 4892 1 0 1 1 0 8 0
syncache 296 5 0 5 2 2 0 1 0 8 0
tcpcb 736 7 0 4 1 0 1 1 0 8 0
arp 88 10 0 0 1 0 1 1 0 8 0
inpcb 304 38 0 32 1 0 1 1 0 8 0
nd6 48 12 0 0 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 277 0 0 18 0 18 18 0 8 0
art_table 32 278 0 0 3 0 3 3 0 8 0
art_node 16 66 0 6 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 8740 0 7333 89 0 89 89 0 8 0
ffsino 240 8740 0 7333 84 0 84 84 0 8 0
nchpl 144 11405 0 9791 61 0 61 61 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 224 5926 0 0 349 0 349 349 0 8 0
namei 1024 32117 0 32117 2 1 1 1 0 8 1
scxspl 216 26976 0 26976 33 32 1 8 0 8 1
plimitpl 152 19 0 9 1 0 1 1 0 8 0
sigapl 424 2728 0 2694 5 1 4 5 0 8 0
futexpl 64 31751 0 31750 1 0 1 1 0 8 0
knotepl 112 204 0 156 2 0 2 2 0 8 0
kqueuepl 184 6 0 0 1 0 1 1 0 8 0
pipepl 304 89 0 73 3 1 2 2 0 8 0
fdescpl 432 2715 0 2694 3 0 3 3 0 8 0
filepl 120 13337 0 13243 4 0 4 4 0 8 0
lockfpl 104 6 0 4 1 0 1 1 0 8 0
lockfspl 48 4 0 2 1 0 1 1 0 8 0
sessionpl 144 21 0 9 1 0 1 1 0 8 0
pgrppl 48 21 0 9 1 0 1 1 0 8 0
ucredpl 96 719 0 709 1 0 1 1 0 8 0
zombiepl 144 2694 0 2694 2 1 1 1 0 8 1
processpl 1000 2728 0 2694 5 0 5 5 0 8 0
procpl 672 10539 0 10496 5 0 5 5 0 8 1
sockpl 448 4971 0 4949 4 0 4 4 0 8 1
mcl8k 8192 9 0 9 2 2 0 1 0 8 0
mcl4k 4096 5 0 5 2 2 0 1 0 8 0
mcl2k 2048 5404 0 5368 7 2 5 6 0 8 0
mtagpl 96 4 0 4 1 1 0 1 0 8 0
mbufpl 256 90470 0 90259 18 0 18 18 0 8 0
bufpl 288 7951 0 1534 459 0 459 459 0 8 0
anonpl 24 834758 0 829575 45 8 37 38 0 188 0
amapchunkpl 152 93785 0 93385 21 2 19 20 0 158 1
amappl16 200 5094 0 5002 5 0 5 5 0 8 0
amappl15 192 647 0 644 1 0 1 1 0 8 0
amappl14 184 10 0 5 1 0 1 1 0 8 0
amappl13 176 40 0 39 2 1 1 1 0 8 0
amappl12 168 625 0 621 2 1 1 1 0 8 0
amappl11 160 668 0 656 1 0 1 1 0 8 0
amappl10 152 45 0 39 1 0 1 1 0 8 0
amappl9 144 429 0 425 1 0 1 1 0 8 0
amappl8 136 915 0 896 2 1 1 1 0 8 0
amappl7 128 658 0 651 1 0 1 1 0 8 0
amappl6 120 145 0 132 1 0 1 1 0 8 0
amappl5 112 2030 0 2016 1 0 1 1 0 8 0
amappl4 104 1191 0 1172 1 0 1 1 0 8 0
amappl3 96 752 0 735 1 0 1 1 0 8 0
amappl2 88 959 0 918 2 0 2 2 0 8 0
amappl1 80 59079 0 58613 15 4 11 12 0 8 0
amappl 88 38256 0 38114 4 0 4 4 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 2 0 0 1 0 1 1 0 8 0
uaddrrnd 24 2715 0 2694 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 2715 0 2694 1 0 1 1 0 8 0
vmmpekpl 168 28443 0 28423 2 0 2 2 0 8 0
vmmpepl 168 233630 0 232211 72 6 66 66 0 357 3
vmsppl 272 2714 0 2694 3 1 2 2 0 8 0
rwobjpl 24 76947 0 70224 41 0 41 41 0 8 0
pdppl 4096 5436 0 5388 80 32 48 56 0 8 0
pvpl 32 1324753 0 1316324 157 81 76 137 0 265 0
pmappl 216 2714 0 2694 2 0 2 2 0 8 0
extentpl 40 57 0 38 1 0 1 1 0 8 0
phpool 112 776 0 42 21 0 21 21 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
sblock(fffffd806e52b710,fffffd806e52b7a8,1) at sblock+0x4a soassertlocked sys/kern/uipc_socket2.c:323 [inline]
sblock(fffffd806e52b710,fffffd806e52b7a8,1) at sblock+0x4a sys/kern/uipc_socket2.c:378
soreceive(fffffd806e52b710,0,ffff80002172d878,0,0,ffff80002172d78c,d50d58f415e1f532) at soreceive+0x203 sys/kern/uipc_socket.c:776
fifo_read(ffff80002172d7e0) at fifo_read+0xcb sys/miscfs/fifofs/fifo_vnops.c:260
VOP_READ(fffffd806ad14478,ffff80002172d878,64,fffffd807f7d8780) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_rdwr(0,fffffd806ad14478,ffff800008943500,1002,0,1,b29ce688c93c242c,ffff8000006b3000,fffffd80708ea5e0,0) at vn_rdwr+0x105
vndstrategy(fffffd80708ea5e0) at vndstrategy+0x3b3 sys/dev/vnd.c:342
physio(ffffffff81b097c0,2902,8000,ffffffff81193e20,ffff80002172dce8) at physio+0x289 sys/kern/kern_physio.c:163
spec_read(ffff80002172db40) at spec_read+0xec sys/kern/spec_vnops.c:222
VOP_READ(fffffd806ed62bc8,ffff80002172dce8,0,fffffd807f7d88a0) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_read(fffffd806d018e28,ffff80002172dce8,0) at vn_read+0x121 sys/kern/vfs_vnops.c:375
dofilereadv(ffff80002165dce0,4,ffff80002172dce8,0,ffff80002172dde0) at dofilereadv+0x19e sys/kern/sys_generic.c:252
sys_read(ffff80002165dce0,ffff80002172dd88,ffff80002172dde0) at sys_read+0x83 sys/kern/sys_generic.c:172
syscall(ffff80002172de50) at syscall+0x44e sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x246e8578f70, count: -14
ddb> machine ddbcpu 1
No such command
ddb> trace
sblock(fffffd806e52b710,fffffd806e52b7a8,1) at sblock+0x4a soassertlocked sys/kern/uipc_socket2.c:323 [inline]
sblock(fffffd806e52b710,fffffd806e52b7a8,1) at sblock+0x4a sys/kern/uipc_socket2.c:378
soreceive(fffffd806e52b710,0,ffff80002172d878,0,0,ffff80002172d78c,d50d58f415e1f532) at soreceive+0x203 sys/kern/uipc_socket.c:776
fifo_read(ffff80002172d7e0) at fifo_read+0xcb sys/miscfs/fifofs/fifo_vnops.c:260
VOP_READ(fffffd806ad14478,ffff80002172d878,64,fffffd807f7d8780) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_rdwr(0,fffffd806ad14478,ffff800008943500,1002,0,1,b29ce688c93c242c,ffff8000006b3000,fffffd80708ea5e0,0) at vn_rdwr+0x105
vndstrategy(fffffd80708ea5e0) at vndstrategy+0x3b3 sys/dev/vnd.c:342
physio(ffffffff81b097c0,2902,8000,ffffffff81193e20,ffff80002172dce8) at physio+0x289 sys/kern/kern_physio.c:163
spec_read(ffff80002172db40) at spec_read+0xec sys/kern/spec_vnops.c:222
VOP_READ(fffffd806ed62bc8,ffff80002172dce8,0,fffffd807f7d88a0) at VOP_READ+0xbf sys/kern/vfs_vops.c:227
vn_read(fffffd806d018e28,ffff80002172dce8,0) at vn_read+0x121 sys/kern/vfs_vnops.c:375
dofilereadv(ffff80002165dce0,4,ffff80002172dce8,0,ffff80002172dde0) at dofilereadv+0x19e sys/kern/sys_generic.c:252
sys_read(ffff80002165dce0,ffff80002172dd88,ffff80002172dde0) at sys_read+0x83 sys/kern/sys_generic.c:172
syscall(ffff80002172de50) at syscall+0x44e sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x246e8578f70, count: -14

Reply all
Reply to author
Forward
0 new messages