panic: acquiring blockable sleep lock with spinlock or critical section held (kernel_lock) &kernel_lock (2)

1 view
Skip to first unread message

syzbot

unread,
Sep 11, 2019, 12:20:08 PM9/11/19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 067ee7eb Add window_marked_flag, GitHub issue 1887.
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11ad9901600000
kernel config: https://syzkaller.appspot.com/x/.config?x=26ca0a9c07f16a3a
dashboard link: https://syzkaller.appspot.com/bug?extid=c8905496cd61610f77e2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12ba59a5600000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+c89054...@syzkaller.appspotmail.com

login: panic: acquiring blockable sleep lock with spinlock or critical
section held (kernel_lock) &kernel_lock
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*142615 10979 0 0x14000 0x200 1 systqmp
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:207
witness_checkorder(ffffffff82666ce0,9,0) at witness_checkorder+0x10e0
sys/kern/subr_witness.c:820
__mp_lock(ffffffff82666ad8) at __mp_lock+0xa1 read_rflags
machine/cpufunc.h:195 [inline]
__mp_lock(ffffffff82666ad8) at __mp_lock+0xa1 intr_disable
machine/cpufunc.h:216 [inline]
__mp_lock(ffffffff82666ad8) at __mp_lock+0xa1 sys/kern/kern_lock.c:142
pageflttrap() at pageflttrap+0x6f sys/arch/amd64/amd64/trap.c:162
kerntrap(ffff800020a313d0) at kerntrap+0xec sys/arch/amd64/amd64/trap.c:287
alltraps_kern_meltdown(6,fffffd806f5c8000,ac63141c,0,fffffd806f4c5938,ffffffff8263e270)
at
alltraps_kern_meltdown+0x7b
pool_do_put(ffffffff8263e270,fffffd806f5c7a00) at pool_do_put+0x12e
sys/kern/subr_pool.c:844
pool_cache_gc(ffffffff8263e270) at pool_cache_gc+0x144 pool_cache_list_put
sys/kern/subr_pool.c:1981 [inline]
pool_cache_gc(ffffffff8263e270) at pool_cache_gc+0x144
sys/kern/subr_pool.c:2033
pool_gc_pages(0) at pool_gc_pages+0x6c sys/kern/subr_pool.c:1567
taskq_thread(ffffffff824de130) at taskq_thread+0x9c sys/kern/kern_task.c:368
end trace frame: 0x0, count: 4
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
acquiring blockable sleep lock with spinlock or critical section held
(kernel_lock) &kernel_lock
ddb{1}> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:207
witness_checkorder(ffffffff82666ce0,9,0) at witness_checkorder+0x10e0
sys/kern/subr_witness.c:820
__mp_lock(ffffffff82666ad8) at __mp_lock+0xa1 read_rflags
machine/cpufunc.h:195 [inline]
__mp_lock(ffffffff82666ad8) at __mp_lock+0xa1 intr_disable
machine/cpufunc.h:216 [inline]
__mp_lock(ffffffff82666ad8) at __mp_lock+0xa1 sys/kern/kern_lock.c:142
pageflttrap() at pageflttrap+0x6f sys/arch/amd64/amd64/trap.c:162
kerntrap(ffff800020a313d0) at kerntrap+0xec sys/arch/amd64/amd64/trap.c:287
alltraps_kern_meltdown(6,fffffd806f5c8000,ac63141c,0,fffffd806f4c5938,ffffffff8263e270)
at
alltraps_kern_meltdown+0x7b
pool_do_put(ffffffff8263e270,fffffd806f5c7a00) at pool_do_put+0x12e
sys/kern/subr_pool.c:844
pool_cache_gc(ffffffff8263e270) at pool_cache_gc+0x144 pool_cache_list_put
sys/kern/subr_pool.c:1981 [inline]
pool_cache_gc(ffffffff8263e270) at pool_cache_gc+0x144
sys/kern/subr_pool.c:2033
pool_gc_pages(0) at pool_gc_pages+0x6c sys/kern/subr_pool.c:1567
taskq_thread(ffffffff824de130) at taskq_thread+0x9c sys/kern/kern_task.c:368
end trace frame: 0x0, count: -11
ddb{1}> show registers
rdi 0
rsi 0x1
rbp 0xffff800020a31140
rbx 0xffff800020a311f0
rdx 0x8b
rcx 0x2
rax 0x1
r8 0xffffffff812fd86f kprintf+0x16f
r9 0x1
r10 0xf65ce6a7bd71b0c
r11 0x578b830cffb2f8f0
r12 0x3000000008
r13 0xffff800020a31150
r14 0x100
r15 0x1
rip 0xffffffff81c098c8 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff800020a31130
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb{1}> show proc
PROC (systqmp) pid=142615 stat=onproc
flags process=14000<NOZOMBIE,SYSTEM> proc=200<SYSTEM>
pri=32, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff800020a10c58,0xffff800020a10500
process=0xffff800020a12380 user=0xffff800020a2c000,
vmspace=0xffffffff826421b0
estcpu=0, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
1089 272654 49844 0 3 0x82 nanosleep syz-executor.0
49844 39113 98147 0 3 0x82 thrsleep syz-execprog
49844 478343 98147 0 3 0x4000082 nanosleep syz-execprog
49844 257410 98147 0 3 0x4000082 thrsleep syz-execprog
49844 345352 98147 0 3 0x4000082 thrsleep syz-execprog
49844 376628 98147 0 3 0x4000082 thrsleep syz-execprog
49844 173202 98147 0 3 0x4000082 thrsleep syz-execprog
49844 199121 98147 0 3 0x4000082 thrsleep syz-execprog
49844 163844 98147 0 3 0x4000082 nanosleep syz-execprog
49844 238051 98147 0 3 0x4000082 kqread syz-execprog
98147 245421 35080 0 3 0x10008a pause ksh
35080 160632 15880 0 3 0x92 select sshd
81409 405001 1 0 3 0x100083 ttyin getty
15880 207987 1 0 3 0x80 select sshd
68273 171370 49078 74 3 0x100092 bpf pflogd
49078 68348 1 0 3 0x80 netio pflogd
44913 356947 79313 73 3 0x100090 kqread syslogd
79313 400907 1 0 3 0x100082 netio syslogd
10896 272256 1 77 3 0x100090 poll dhclient
23885 165816 1 0 3 0x80 poll dhclient
27897 87087 0 0 3 0x14200 pgzero zerothread
34256 472383 0 0 3 0x14200 aiodoned aiodoned
62011 167479 0 0 3 0x14200 syncer update
89629 174027 0 0 3 0x14200 cleaner cleaner
2423 238870 0 0 3 0x14200 reaper reaper
38843 133200 0 0 3 0x14200 pgdaemon pagedaemon
20040 131069 0 0 3 0x14200 bored crynlk
46450 175143 0 0 3 0x14200 bored crypto
17694 332015 0 0 3 0x40014200 acpi0 acpi0
61442 79053 0 0 3 0x40014200 idle1
99285 197711 0 0 3 0x14200 bored softnet
*10979 142615 0 0 7 0x14200 systqmp
7465 423677 0 0 3 0x14200 bored systq
82291 175721 0 0 3 0x40014200 bored softclock
40917 6494 0 0 7 0x40014200 idle0
93718 233945 0 0 3 0x14200 bored smr
1 326258 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
CPU 1:
exclusive mutex mbufpl r = 0 (0xffffffff8263e280)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1163
#1 mtx_enter_try+0x102
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 pool_cache_gc+0x12d pl_enter sys/kern/subr_pool.c:104 [inline]
#3 pool_cache_gc+0x12d pool_cache_list_put sys/kern/subr_pool.c:1976
[inline]
#3 pool_cache_gc+0x12d sys/kern/subr_pool.c:2033
#4 pool_gc_pages+0x6c sys/kern/subr_pool.c:1567
#5 taskq_thread+0x9c sys/kern/kern_task.c:368
#6 proc_trampoline+0x1c
Process 10979 (systqmp) thread 0xffff800020a10768 (142615)
shared rwlock pools r = 0 (0xffffffff824b5540)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1163
#1 pool_gc_pages+0x21 sys/kern/subr_pool.c:1563
#2 taskq_thread+0x9c sys/kern/kern_task.c:368
#3 proc_trampoline+0x1c
shared rwlock systqmp r = 0 (0xffffffff824de190)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1163
#1 taskq_thread+0x8f sys/kern/kern_task.c:367
#2 proc_trampoline+0x1c
exclusive mutex mbufpl r = 0 (0xffffffff8263e280)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1163
#1 mtx_enter_try+0x102
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 pool_cache_gc+0x12d pl_enter sys/kern/subr_pool.c:104 [inline]
#3 pool_cache_gc+0x12d pool_cache_list_put sys/kern/subr_pool.c:1976
[inline]
#3 pool_cache_gc+0x12d sys/kern/subr_pool.c:2033
#4 pool_gc_pages+0x6c sys/kern/subr_pool.c:1567
#5 taskq_thread+0x9c sys/kern/kern_task.c:368
#6 proc_trampoline+0x1c
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9457 6385K 6385K 78643K 10544 0 0
pcb 13 8K 8K 78643K 13 0 0
rtable 77 2K 2K 78643K 165 0 0
ifaddr 32 9K 9K 78643K 450 0 0
counters 39 33K 33K 78643K 39 0 0
ioctlops 0 0K 4K 78643K 1468 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1181 74K 74K 78643K 1186 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 1K 78643K 2 0 0
VM map 2 1K 1K 78643K 2 0 0
sem 2 0K 0K 78643K 2 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1808 196K 290K 78643K 12765 0 0
file desc 2 4K 12K 78643K 435 0 0
proc 59 63K 83K 78643K 384 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
in_multi 22 1K 1K 78643K 22 0 0
ether_multi 1 0K 0K 78643K 1 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 18 79K 79K 78643K 18 0 0
exec 0 0K 1K 78643K 199 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 71 12K 12K 78643K 1374 0 0
UVM aobj 2 2K 2K 78643K 2 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
NDP 5 0K 0K 78643K 7 0 0
temp 48 3538K 3602K 78643K 4170 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 4 0 1 1 0 1 1 0
8 0
plcache 128 20 0 0 1 0 1 1 0
8 0
rtpcb 80 17 0 15 1 0 1 1 0
8 0
rtentry 112 34 0 4 1 0 1 1 0
8 0
unpcb 120 29 0 19 1 0 1 1 0
8 0
syncache 264 5 0 5 2 2 0 1 0
8 0
tcpcb 544 8 0 5 1 0 1 1 0
8 0
inpcb 280 451 0 445 1 0 1 1 0
8 0
nd6 48 2 0 0 1 0 1 1 0
8 0
pfosfp 40 846 0 423 5 0 5 5 0
8 0
pfosfpen 112 1428 0 714 21 0 21 21 0
8 0
pfstitem 24 10 0 6 2 1 1 1 0
8 0
pfstkey 112 10 0 6 2 1 1 1 0
8 0
pfstate 328 10 0 6 2 1 1 1 0
8 0
pfrule 1360 21 0 16 2 1 1 2 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 168 0 2 11 0 11 11 0
8 0
art_table 32 169 0 2 2 0 2 2 0
8 0
art_node 16 33 0 6 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 1839 0 437 46 0 46 46 0
8 0
ffsino 272 1839 0 437 94 0 94 94 0
8 0
nchpl 144 2495 0 884 60 0 60 60 0
8 0
uvmvnodes 72 1849 0 0 34 0 34 34 0
8 0
vnodes 208 1849 0 0 98 0 98 98 0
8 0
namei 1024 5810 0 5810 3 2 1 1 0
8 1
percpumem 16 30 0 0 1 0 1 1 0
8 0
scxspl 192 6765 0 6765 23 22 1 7 0
8 1
plimitpl 152 15 0 8 1 0 1 1 0
8 0
sigapl 432 643 0 630 2 0 2 2 0
8 0
knotepl 112 39 0 28 1 0 1 1 0
8 0
kqueuepl 104 2 0 0 1 0 1 1 0
8 0
pipepl 112 154 0 141 3 2 1 1 0
8 0
fdescpl 488 644 0 630 3 0 3 3 0
8 0
filepl 152 1955 0 1897 3 0 3 3 0
8 0
lockfpl 104 5 0 4 1 0 1 1 0
8 0
lockfspl 48 3 0 2 1 0 1 1 0
8 0
sessionpl 112 19 0 9 1 0 1 1 0
8 0
pgrppl 48 19 0 9 1 0 1 1 0
8 0
ucredpl 96 52 0 43 1 0 1 1 0
8 0
zombiepl 144 630 0 629 3 2 1 1 0
8 0
processpl 896 659 0 629 4 0 4 4 0
8 0
procpl 632 667 0 629 4 0 4 4 0
8 0
sockpl 384 497 0 479 2 0 2 2 0
8 0
mcl4k 4096 2 0 0 1 0 1 1 0
8 0
mcl2k 2048 72 0 0 9 0 9 9 0
8 0
mtagpl 80 1 0 0 1 0 1 1 0
8 0
mbufpl 256 127 0 0 6 0 6 6 0
8 0
mbufpl: pool(0xffffffff8263e270:mbufpl): free list modified: page
0xfffffd806f5c7000; item ordinal 4; addr 0xfffffd806f5c7e00 (p
0xfffffd806f4c5000); offset 0x0=0x0
mbufpl: pool(0xffffffff8263e270:mbufpl): page inconsistency: page
0xfffffd806f5c7000; item ordinal 5; addr 0xac63141c
bufpl 256 6303 0 1315 312 0 312 312 0
8 0
anonpl 16 32865 0 30799 16 4 12 13 0
124 3
amapchunkpl 152 1212 0 1147 5 0 5 5 0
158 2
amappl16 192 1839 0 1781 4 0 4 4 0
8 1
amappl14 176 35 0 30 3 2 1 1 0
8 0
amappl13 168 1 0 1 1 0 1 1 0
8 1
amappl12 160 9 0 6 2 1 1 1 0
8 0
amappl11 152 51 0 36 1 0 1 1 0
8 0
amappl10 144 17 0 13 1 0 1 1 0
8 0
amappl9 136 880 0 873 1 0 1 1 0
8 0
amappl8 128 546 0 536 1 0 1 1 0
8 0
amappl7 120 33 0 30 1 0 1 1 0
8 0
amappl6 112 74 0 66 1 0 1 1 0
8 0
amappl5 104 126 0 112 1 0 1 1 0
8 0
amappl4 96 916 0 887 1 0 1 1 0
8 0
amappl3 88 116 0 110 1 0 1 1 0
8 0
amappl2 80 1768 0 1708 5 2 3 3 0
8 1
amappl1 72 18651 0 18235 26 9 17 20 0
8 7
amappl 80 895 0 867 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 1 0 0 1 0 1 1 0
8 0
uaddrrnd 24 644 0 630 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 644 0 630 1 0 1 1 0
8 0
vmmpekpl 168 7255 0 7231 2 0 2 2 0
8 0
vmmpepl 168 50010 0 49059 95 16 79 80 0 357
37
vmsppl 368 643 0 630 2 0 2 2 0
8 0
pdppl 4096 1295 0 1260 6 0 6 6 0
8 1
pvpl 32 155378 0 150937 124 10 114 115 0 265
78
pmappl 232 643 0 630 1 0 1 1 0
8 0
extentpl 40 41 0 26 1 0 1 1 0
8 0
phpool 112 453 0 5 13 0 13 13 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Sep 1, 2021, 12:12:16 AM9/1/21
to syzkaller-o...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 444296aeff58 Honour netinet6 when generating symlinks to t..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13d12291300000
kernel config: https://syzkaller.appspot.com/x/.config?x=bf87b6915a88cd0d
dashboard link: https://syzkaller.appspot.com/bug?extid=c8905496cd61610f77e2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1247a125300000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12b8dfd5300000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c89054...@syzkaller.appspotmail.com

login: panic: acquiring blockable sleep lock with spinlock or critical section held (kernel_lock) &kernel_lock
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
409905 85272 0 0 0 1 syz-executor1189
* 11849 85272 0 0 0x4000000 0 syz-executor1189
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:440
panic(ffffffff82464b8f) at panic+0x177 sys/kern/subr_prf.c:202
witness_checkorder(ffffffff82838c20,9,0) at witness_checkorder+0x11eb sys/kern/subr_witness.c:833
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 read_rflags machine/cpufunc.h:195 [inline]
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 intr_disable machine/cpufunc.h:216 [inline]
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 sys/kern/kern_lock.c:142
intr_handler(ffff800021302d20,ffff80000006a400) at intr_handler+0x5e sys/arch/amd64/amd64/intr.c:532
Xintr_ioapic_edge17_untramp() at Xintr_ioapic_edge17_untramp+0x18f
Xspllower() at Xspllower+0x19
mtx_enter_try(ffffffff829e4270) at mtx_enter_try+0x100
mtx_enter(ffffffff829e4270) at mtx_enter+0x4b sys/kern/kern_lock.c:266
pool_get(ffffffff829e4270,9) at pool_get+0xbf sys/kern/subr_pool.c:581
uvmspace_alloc(0,200000,1,0) at uvmspace_alloc+0x3d sys/uvm/uvm_map.c:3478
vm_impl_init_vmx(ffff8000213e1888,ffff8000ffff6fd0) at vm_impl_init_vmx+0x71 sys/arch/amd64/amd64/vmm.c:1584
vm_create(ffff800000b22800,ffff8000ffff6fd0) at vm_create+0x19b vm_impl_init sys/arch/amd64/amd64/vmm.c:1690 [inline]
vm_create(ffff800000b22800,ffff8000ffff6fd0) at vm_create+0x19b sys/arch/amd64/amd64/vmm.c:1510
vmmioctl(a00,c5005601,ffff800000b22800,1,ffff8000ffff6fd0) at vmmioctl+0x1f2
end trace frame: 0xffff8000213031b0, count: 0
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb{0}>
ddb{0}> set $lines = 0
ddb{0}> set $maxwidth = 0
ddb{0}> show panic
*cpu0: acquiring blockable sleep lock with spinlock or critical section held (kernel_lock) &kernel_lock
ddb{0}> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:440
panic(ffffffff82464b8f) at panic+0x177 sys/kern/subr_prf.c:202
witness_checkorder(ffffffff82838c20,9,0) at witness_checkorder+0x11eb sys/kern/subr_witness.c:833
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 read_rflags machine/cpufunc.h:195 [inline]
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 intr_disable machine/cpufunc.h:216 [inline]
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 sys/kern/kern_lock.c:142
intr_handler(ffff800021302d20,ffff80000006a400) at intr_handler+0x5e sys/arch/amd64/amd64/intr.c:532
Xintr_ioapic_edge17_untramp() at Xintr_ioapic_edge17_untramp+0x18f
Xspllower() at Xspllower+0x19
mtx_enter_try(ffffffff829e4270) at mtx_enter_try+0x100
mtx_enter(ffffffff829e4270) at mtx_enter+0x4b sys/kern/kern_lock.c:266
pool_get(ffffffff829e4270,9) at pool_get+0xbf sys/kern/subr_pool.c:581
uvmspace_alloc(0,200000,1,0) at uvmspace_alloc+0x3d sys/uvm/uvm_map.c:3478
vm_impl_init_vmx(ffff8000213e1888,ffff8000ffff6fd0) at vm_impl_init_vmx+0x71 sys/arch/amd64/amd64/vmm.c:1584
vm_create(ffff800000b22800,ffff8000ffff6fd0) at vm_create+0x19b vm_impl_init sys/arch/amd64/amd64/vmm.c:1690 [inline]
vm_create(ffff800000b22800,ffff8000ffff6fd0) at vm_create+0x19b sys/arch/amd64/amd64/vmm.c:1510
vmmioctl(a00,c5005601,ffff800000b22800,1,ffff8000ffff6fd0) at vmmioctl+0x1f2
VOP_IOCTL(fffffd807058b210,c5005601,ffff800000b22800,1,fffffd807f7d89c0,ffff8000ffff6fd0) at VOP_IOCTL+0x9a sys/kern/vfs_vops.c:295
vn_ioctl(fffffd806e3d33a0,c5005601,ffff800000b22800,ffff8000ffff6fd0) at vn_ioctl+0xba sys/kern/vfs_vnops.c:531
sys_ioctl(ffff8000ffff6fd0,ffff8000213033e8,ffff800021303430) at sys_ioctl+0x4a2
syscall(ffff8000213034b0) at syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff8000213034b0) at syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x69c30412be0, count: -19
ddb{0}> show registers
rdi 0
rsi 0x1
rbp 0xffff800021302b10
rbx 0xffffffff8280abff cpu_info_full_primary+0x2bff
rdx 0x8b
rcx 0x2
rax 0x68
r8 0xffffffff81a0be34 kprintf+0x144
r9 0x1
r10 0x85d98e5a9beaed72
r11 0x75dae88b1d1dc84d
r12 0xffffffff8280aa00 cpu_info_full_primary+0x2a00
r13 0
r14 0
r15 0x1
rip 0xffffffff81e3e908 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff800021302b00
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb{0}> show proc
PROC (syz-executor1189) pid=11849 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=17, usrpri=66, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff62b0,0xffffffff82913618
process=0xffff80002120a9f0 user=0xffff8000212fe000, vmspace=0xfffffd806b428e80
estcpu=36, cpticks=1, pctcpu=0.0
user=0, sys=0, intr=1
ddb{0}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
85272 409905 98073 0 7 0 syz-executor1189
*85272 11849 98073 0 7 0x4000000 syz-executor1189
98073 509691 17932 0 3 0x80 nanoslp syz-executor1189
6590 77678 17932 0 3 0 biowait syz-executor1189
17932 330554 84730 0 3 0x82 nanoslp syz-executor1189
84730 104856 17470 0 3 0x10008a sigsusp ksh
17470 403772 95321 0 3 0x9a select sshd
14774 70811 1 0 3 0x100083 ttyin getty
95321 457380 1 0 3 0x88 select sshd
76341 210687 60992 74 3 0x100092 bpf pflogd
60992 437587 1 0 3 0x80 netio pflogd
57930 71267 75163 73 3 0x100090 kqread syslogd
75163 251624 1 0 3 0x100082 netio syslogd
81458 348823 1 0 3 0x100080 kqread resolvd
43085 163033 70478 77 3 0x100092 kqread dhcpleased
61391 143226 70478 77 3 0x100092 kqread dhcpleased
70478 473062 1 0 3 0x80 kqread dhcpleased
1955 385938 0 0 3 0x14200 bored smr
25977 165474 0 0 3 0x14200 pgzero zerothread
69991 94236 0 0 3 0x14200 aiodoned aiodoned
8260 403557 0 0 3 0x14200 syncer update
7605 308690 0 0 3 0x14200 cleaner cleaner
69222 153132 0 0 3 0x14200 reaper reaper
91637 243970 0 0 3 0x14200 pgdaemon pagedaemon
98867 449183 0 0 3 0x14200 bored crynlk
18770 248580 0 0 3 0x14200 bored crypto
22744 2389 0 0 3 0x14200 bored viomb
24390 382376 0 0 3 0x40014200 acpi0 acpi0
83379 196495 0 0 3 0x40014200 idle1
12924 467848 0 0 3 0x14200 bored softnet
88076 489141 0 0 3 0x14200 bored systqmp
39537 186333 0 0 3 0x14200 bored systq
48979 115832 0 0 3 0x40014200 bored softclock
73739 41697 0 0 3 0x40014200 idle0
1 337710 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{0}> show all locks
CPU 0:
exclusive mutex vmsppl r = 0 (0xffffffff829e4280)
#0 witness_lock+0x4b0 stacktrace_save sys/sys/stacktrace.h:36 [inline]
#0 witness_lock+0x4b0 sys/kern/subr_witness.c:1182
#1 mtx_enter_try+0x100
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 pool_get+0xbf sys/kern/subr_pool.c:581
#4 uvmspace_alloc+0x3d sys/uvm/uvm_map.c:3478
#5 vm_impl_init_vmx+0x71 sys/arch/amd64/amd64/vmm.c:1584
#6 vm_create+0x19b vm_impl_init sys/arch/amd64/amd64/vmm.c:1690 [inline]
#6 vm_create+0x19b sys/arch/amd64/amd64/vmm.c:1510
#7 vmmioctl+0x1f2
#8 VOP_IOCTL+0x9a sys/kern/vfs_vops.c:295
#9 vn_ioctl+0xba sys/kern/vfs_vnops.c:531
#10 sys_ioctl+0x4a2
#11 syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
#11 syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
#12 Xsyscall+0x128
Process 85272 (syz-executor1189) thread 0xffff8000ffff6fd0 (11849)
exclusive rwlock vmlistlock r = 0 (0xffff800000655c78)
#0 witness_lock+0x4b0 stacktrace_save sys/sys/stacktrace.h:36 [inline]
#0 witness_lock+0x4b0 sys/kern/subr_witness.c:1182
#1 vm_create+0x12e vm_impl_init sys/arch/amd64/amd64/vmm.c:1688 [inline]
#1 vm_create+0x12e sys/arch/amd64/amd64/vmm.c:1510
#2 vmmioctl+0x1f2
#3 VOP_IOCTL+0x9a sys/kern/vfs_vops.c:295
#4 vn_ioctl+0xba sys/kern/vfs_vnops.c:531
#5 sys_ioctl+0x4a2
#6 syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
#6 syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
#7 Xsyscall+0x128
exclusive mutex vmsppl r = 0 (0xffffffff829e4280)
#0 witness_lock+0x4b0 stacktrace_save sys/sys/stacktrace.h:36 [inline]
#0 witness_lock+0x4b0 sys/kern/subr_witness.c:1182
#1 mtx_enter_try+0x100
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 pool_get+0xbf sys/kern/subr_pool.c:581
#4 uvmspace_alloc+0x3d sys/uvm/uvm_map.c:3478
#5 vm_impl_init_vmx+0x71 sys/arch/amd64/amd64/vmm.c:1584
#6 vm_create+0x19b vm_impl_init sys/arch/amd64/amd64/vmm.c:1690 [inline]
#6 vm_create+0x19b sys/arch/amd64/amd64/vmm.c:1510
#7 vmmioctl+0x1f2
#8 VOP_IOCTL+0x9a sys/kern/vfs_vops.c:295
#9 vn_ioctl+0xba sys/kern/vfs_vnops.c:531
#10 sys_ioctl+0x4a2
#11 syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
#11 syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
#12 Xsyscall+0x128
Process 6590 (syz-executor1189) thread 0xffff80002121e540 (77678)
exclusive rrwlock inode r = 0 (0xfffffd806d8f0f78)
#0 witness_lock+0x4b0 stacktrace_save sys/sys/stacktrace.h:36 [inline]
#0 witness_lock+0x4b0 sys/kern/subr_witness.c:1182
#1 rw_enter+0x3e2 sys/kern/kern_rwlock.c:310
#2 rrw_enter+0x8b sys/kern/kern_rwlock.c:461
#3 VOP_LOCK+0x87 sys/kern/vfs_vops.c:614
#4 vn_lock+0x84 sys/kern/vfs_vnops.c:579
#5 vget+0x1eb sys/kern/vfs_subr.c:676
#6 ufs_ihashget+0x121 sys/ufs/ufs/ufs_ihash.c:119
#7 ffs_vget+0x7c sys/ufs/ffs/ffs_vfsops.c:1321
#8 ufs_lookup+0x145f sys/ufs/ufs/ufs_lookup.c:487
#9 VOP_LOOKUP+0x5b sys/kern/vfs_vops.c:88
#10 vfs_lookup+0x737 sys/kern/vfs_lookup.c:561
#11 namei+0x55a sys/kern/vfs_lookup.c:245
#12 dounlinkat+0x99 sys/kern/vfs_syscalls.c:1854
#13 syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
#13 syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
#14 Xsyscall+0x128
exclusive rrwlock inode r = 0 (0xfffffd807028b708)
#0 witness_lock+0x4b0 stacktrace_save sys/sys/stacktrace.h:36 [inline]
#0 witness_lock+0x4b0 sys/kern/subr_witness.c:1182
#1 rw_enter+0x3e2 sys/kern/kern_rwlock.c:310
#2 rrw_enter+0x8b sys/kern/kern_rwlock.c:461
#3 VOP_LOCK+0x87 sys/kern/vfs_vops.c:614
#4 vn_lock+0x84 sys/kern/vfs_vnops.c:579
#5 vfs_lookup+0xdd sys/kern/vfs_lookup.c:413
#6 namei+0x55a sys/kern/vfs_lookup.c:245
#7 dounlinkat+0x99 sys/kern/vfs_syscalls.c:1854
#8 syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
#8 syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
#9 Xsyscall+0x128
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10111 6416K 6417K 78643K 11201 0
pcb 13 8K 8K 78643K 13 0
rtable 62 2K 2K 78643K 112 0
ifaddr 29 8K 8K 78643K 30 0
counters 40 33K 33K 78643K 40 0
ioctlops 1 2K 4K 78643K 2124 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 6 0
vnodes 1183 74K 75K 78643K 1188 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 1K 78643K 2 0
VM map 2 1K 1K 78643K 2 0
sem 2 0K 0K 78643K 2 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12598 0
file desc 1 0K 0K 78643K 1 0
proc 67 87K 87K 78643K 278 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
in_multi 11 0K 0K 78643K 11 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 19 95K 95K 78643K 19 0
exec 0 0K 2K 78643K 348 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 1392 10469K 10469K 78643K 10144 0
UVM aobj 3 2K 2K 78643K 3 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
NDP 4 0K 0K 78643K 4 0
temp 23 4193K 4257K 78643K 3252 0
kqueue 9 12K 12K 78643K 9 0
SYN cache 2 16K 16K 78643K 2 0
ddb{0}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 22 0 0 1 0 1 1 0 8 0
rtpcb 120 17 0 14 1 0 1 1 0 8 0
rtentry 112 23 0 1 1 0 1 1 0 8 0
unpcb 120 35 0 20 1 0 1 1 0 8 0
syncache 296 5 0 5 2 2 0 1 0 8 0
tcpcb 736 8 0 5 1 0 1 1 0 8 0
arp 120 2 0 0 1 0 1 1 0 8 0
inpcb 304 32 0 26 1 0 1 1 0 8 0
pfosfp 40 1428 0 1005 5 0 5 5 0 8 0
pfosfpen 112 1428 0 714 21 0 21 21 0 8 0
pfstitem 24 9 0 2 1 0 1 1 0 8 0
pfstkey 112 9 0 2 1 0 1 1 0 8 0
pfstate 320 9 0 2 1 0 1 1 0 8 0
pfrule 1360 21 0 16 2 1 1 2 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 96 0 0 6 0 6 6 0 8 0
art_table 32 97 0 0 1 0 1 1 0 8 0
art_node 16 22 0 2 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 2705 0 1310 88 0 88 88 0 8 0
ffsino 272 2705 0 1310 94 0 94 94 0 8 0
nchpl 144 4169 0 2616 58 0 58 58 0 8 0
uvmvnodes 72 2715 0 0 50 0 50 50 0 8 0
vnodes 224 2715 0 0 160 0 160 160 0 8 0
namei 1024 9308 0 9308 2 1 1 1 0 8 1
percpumem 16 32 0 0 1 0 1 1 0 8 0
vcpupl 2048 644 0 0 81 0 81 81 0 8 0
vmpool 560 645 0 0 47 0 47 47 0 8 0
scxspl 216 9507 0 9506 11 10 1 8 0 8 0
plimitpl 152 16 0 9 1 0 1 1 0 8 0
sigapl 424 902 0 868 5 0 5 5 0 8 0
futexpl 56 761 0 761 1 0 1 1 0 8 1
knotepl 112 23 0 0 1 0 1 1 0 8 0
kqueuepl 216 5 0 0 1 0 1 1 0 8 0
pipepl 336 69 0 66 2 1 1 1 0 8 0
fdescpl 496 886 0 868 3 0 3 3 0 8 0
filepl 152 3018 0 2958 3 0 3 3 0 8 0
lockfpl 104 6 0 4 1 0 1 1 0 8 0
lockfspl 48 4 0 2 1 0 1 1 0 8 0
sessionpl 144 18 0 9 1 0 1 1 0 8 0
pgrppl 48 18 0 9 1 0 1 1 0 8 0
ucredpl 96 69 0 57 1 0 1 1 0 8 0
zombiepl 144 868 0 868 2 1 1 1 0 8 1
processpl 1072 902 0 868 3 0 3 3 0 8 0
procpl 672 1561 0 1526 4 0 4 4 0 8 0
sockpl 480 84 0 60 5 1 4 4 0 8 0
mcl8k 8192 4 0 0 1 0 1 1 0 8 0
mcl4k 4096 1 0 0 1 0 1 1 0 8 0
mcl2k 2048 78 0 0 9 0 9 9 0 8 0
mtagpl 96 3 0 0 1 0 1 1 0 8 0
mbufpl 256 128 0 0 8 0 8 8 0 8 0
bufpl 280 2671 0 91 185 0 185 185 0 8 0
anonpl 24 149103 0 145747 25 4 21 21 0 186 0
amapchunkpl 152 18985 0 18796 10 1 9 9 0 158 1
amappl16 200 742 0 92 35 0 35 35 0 8 0
amappl13 176 18 0 17 2 1 1 1 0 8 0
amappl12 168 15 0 15 1 1 0 1 0 8 0
amappl11 160 58 0 44 1 0 1 1 0 8 0
amappl10 152 42 0 37 1 0 1 1 0 8 0
amappl9 144 228 0 226 1 0 1 1 0 8 0
amappl8 136 331 0 328 2 1 1 1 0 8 0
amappl7 128 52 0 45 1 0 1 1 0 8 0
amappl6 120 88 0 83 1 0 1 1 0 8 0
amappl5 112 209 0 193 1 0 1 1 0 8 0
amappl4 104 1169 0 1146 1 0 1 1 0 8 0
amappl3 96 690 0 686 1 0 1 1 0 8 0
amappl2 88 420 0 375 3 1 2 2 0 8 0
amappl1 80 15917 0 15519 11 2 9 9 0 8 0
amappl 88 9248 0 8519 18 1 17 17 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 64 2 0 0 1 0 1 1 0 8 0
uaddrrnd 24 1530 0 868 4 0 4 4 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 1530 0 868 4 0 4 4 0 8 0
vmmpekpl 168 7585 0 7564 2 0 2 2 0 8 1
vmmpepl 168 66257 0 64001 103 4 99 99 0 357 0
vmsppl 368 1529 0 868 61 0 61 61 0 8 0
rwobjpl 56 17119 0 15252 29 2 27 27 0 8 0
pdppl 4096 3068 0 2380 711 22 689 689 0 8 1
pvpl 32 291840 0 287073 45 4 41 41 0 265 2
pmappl 224 1529 0 868 39 0 39 39 0 8 0
extentpl 40 58 0 40 1 0 1 1 0 8 0
phpool 112 1074 0 27 30 0 30 30 0 8 0
ddb{0}> machine ddbcpu 0
Invalid cpu 0
ddb{0}> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:440
panic(ffffffff82464b8f) at panic+0x177 sys/kern/subr_prf.c:202
witness_checkorder(ffffffff82838c20,9,0) at witness_checkorder+0x11eb sys/kern/subr_witness.c:833
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 read_rflags machine/cpufunc.h:195 [inline]
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 intr_disable machine/cpufunc.h:216 [inline]
__mp_lock(ffffffff82838a18) at __mp_lock+0xa1 sys/kern/kern_lock.c:142
intr_handler(ffff800021302d20,ffff80000006a400) at intr_handler+0x5e sys/arch/amd64/amd64/intr.c:532
Xintr_ioapic_edge17_untramp() at Xintr_ioapic_edge17_untramp+0x18f
Xspllower() at Xspllower+0x19
mtx_enter_try(ffffffff829e4270) at mtx_enter_try+0x100
mtx_enter(ffffffff829e4270) at mtx_enter+0x4b sys/kern/kern_lock.c:266
pool_get(ffffffff829e4270,9) at pool_get+0xbf sys/kern/subr_pool.c:581
uvmspace_alloc(0,200000,1,0) at uvmspace_alloc+0x3d sys/uvm/uvm_map.c:3478
vm_impl_init_vmx(ffff8000213e1888,ffff8000ffff6fd0) at vm_impl_init_vmx+0x71 sys/arch/amd64/amd64/vmm.c:1584
vm_create(ffff800000b22800,ffff8000ffff6fd0) at vm_create+0x19b vm_impl_init sys/arch/amd64/amd64/vmm.c:1690 [inline]
vm_create(ffff800000b22800,ffff8000ffff6fd0) at vm_create+0x19b sys/arch/amd64/amd64/vmm.c:1510
vmmioctl(a00,c5005601,ffff800000b22800,1,ffff8000ffff6fd0) at vmmioctl+0x1f2
VOP_IOCTL(fffffd807058b210,c5005601,ffff800000b22800,1,fffffd807f7d89c0,ffff8000ffff6fd0) at VOP_IOCTL+0x9a sys/kern/vfs_vops.c:295
vn_ioctl(fffffd806e3d33a0,c5005601,ffff800000b22800,ffff8000ffff6fd0) at vn_ioctl+0xba sys/kern/vfs_vnops.c:531
sys_ioctl(ffff8000ffff6fd0,ffff8000213033e8,ffff800021303430) at sys_ioctl+0x4a2
syscall(ffff8000213034b0) at syscall+0x5a9 mi_syscall sys/sys/syscall_mi.h:102 [inline]
syscall(ffff8000213034b0) at syscall+0x5a9 sys/arch/amd64/amd64/trap.c:587
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x69c30412be0, count: -19
ddb{0}> machine ddbcpu 1
Stopped at x86_ipi_db+0x1a: addq $0x8,%rsp
x86_ipi_db(ffff800020d38ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
end of kernel
end trace frame: 0x7f7ffffbb7f0, count: 12
ddb{1}> trace
x86_ipi_db(ffff800020d38ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
end of kernel
end trace frame: 0x7f7ffffbb7f0, count: -3
ddb{1}>

Reply all
Reply to author
Forward
0 new messages