uvm_fault: rtrequest (3)

2 views
Skip to first unread message

syzbot

unread,
Oct 31, 2024, 7:48:33 AM10/31/24
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3c6d599c37f2 For AMD SEV automatically load psp(4) firmwar..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17605540580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=9cf51859d432181f1086

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/61032314a438/disk-3c6d599c.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/34206e16e76e/bsd-3c6d599c.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/19f8384961e1/kernel-3c6d599c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9cf518...@syzkaller.appspotmail.com

uvm_fault(0xfffffd806c214978, 0xdb, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at rtrequest+0x7c7: movzbl 0xdb(%r13),%eax
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*115065 21672 0 0 0x4000000 0 syz-executor
rtrequest(1,ffff80002d9dafc8,38,ffff80002d9daf40,0) at rtrequest+0x7c7 sys/net/route.c:1008
rtm_output(ffff8000013deb00,ffff80002d9db070,ffff80002d9dafc8,38,0) at rtm_output+0x855 sys/net/rtsock.c:973
route_output(fffffd806e8f1000,fffffd806d1ff408) at route_output+0x9ac sys/net/rtsock.c:878
route_send(fffffd806d1ff408,fffffd806e8f1000,0,0) at route_send+0xd7 sys/net/rtsock.c:342
sosend(fffffd806d1ff408,0,ffff80002d9db228,0,0,0) at sosend+0xa40
sendit(ffff80002a4c22a0,4,ffff80002d9db320,0,ffff80002d9db3d0) at sendit+0x721 sys/kern/uipc_syscalls.c:786
sys_sendto(ffff80002a4c22a0,ffff80002d9db480,ffff80002d9db3d0) at sys_sendto+0x8d sys/kern/uipc_syscalls.c:564
syscall(ffff80002d9db480) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x1fd794071e0, count: 6
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
*cpu0: uvm_fault(0xfffffd806c214978, 0xdb, 0, 1) -> e
ddb> trace
rtrequest(1,ffff80002d9dafc8,38,ffff80002d9daf40,0) at rtrequest+0x7c7 sys/net/route.c:1008
rtm_output(ffff8000013deb00,ffff80002d9db070,ffff80002d9dafc8,38,0) at rtm_output+0x855 sys/net/rtsock.c:973
route_output(fffffd806e8f1000,fffffd806d1ff408) at route_output+0x9ac sys/net/rtsock.c:878
route_send(fffffd806d1ff408,fffffd806e8f1000,0,0) at route_send+0xd7 sys/net/rtsock.c:342
sosend(fffffd806d1ff408,0,ffff80002d9db228,0,0,0) at sosend+0xa40
sendit(ffff80002a4c22a0,4,ffff80002d9db320,0,ffff80002d9db3d0) at sendit+0x721 sys/kern/uipc_syscalls.c:786
sys_sendto(ffff80002a4c22a0,ffff80002d9db480,ffff80002d9db3d0) at sys_sendto+0x8d sys/kern/uipc_syscalls.c:564
syscall(ffff80002d9db480) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x1fd794071e0, count: -9
ddb> show registers
rdi 0
rsi 0
rbp 0xffff80002d9daf10
rbx 0xffff8000013eac70
rdx 0xffff800001256e00
rcx 0x244
rax 0
r8 0x70
r9 0
r10 0x8ffe0b6b42ee2261
r11 0xabe7269feddb2c76
r12 0xfffffd80705c65b0
r13 0
r14 0x1
r15 0x33
rip 0xffffffff81181597 rtrequest+0x7c7
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80002d9dae20
ss 0x10
rtrequest+0x7c7: movzbl 0xdb(%r13),%eax
ddb> show proc
PROC (syz-executor) tid=115065 pid=21672 tcnt=2 stat=onproc
flags process=0 proc=4000000<THREAD>
runpri=32, usrpri=86, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
forw=0xffffffffffffffff, list=0xffff80002a4c2f48,0xffffffff8351d800
process=0xffff8000329f6ae8 user=0xffff80002d9d6000, vmspace=0xfffffd806c214978
estcpu=36, cpticks=19, pctcpu=0.0, user=0, sys=19, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
21672 259986 53703 0 2 0 syz-executor
*21672 115065 53703 0 7 0x4000000 syz-executor
8504 56789 9729 0 2 0 syz-executor
8504 387808 9729 0 3 0x4000080 fsleep syz-executor
24426 82475 92459 0 2 0 syz-executor
24426 489342 92459 0 3 0x4000080 bell syz-executor
15868 374959 30903 60929 2 0x10 syz-executor
15868 7474 30903 60929 3 0x4000090 fsleep syz-executor
15868 456828 30903 60929 3 0x4000090 fsleep syz-executor
64295 19899 9750 0 2 0x2 syz-executor
92459 521796 9750 0 2 0x482 syz-executor
90256 187258 0 0 3 0x14280 nfsidl nfsio
68978 392478 0 0 3 0x14280 nfsidl nfsio
848 252826 0 0 3 0x14280 nfsidl nfsio
43467 121942 0 0 3 0x14280 nfsidl nfsio
25791 423035 0 0 3 0x14280 nfsidl nfsio
15605 102233 0 0 3 0x14280 nfsidl nfsio
24959 412305 0 0 3 0x14280 nfsidl nfsio
35481 336808 0 0 3 0x14280 nfsidl nfsio
69172 198213 0 0 3 0x14280 nfsidl nfsio
80093 334440 0 0 3 0x14280 nfsidl nfsio
22792 67420 0 0 3 0x14280 nfsidl nfsio
74739 324721 0 0 3 0x14280 nfsidl nfsio
31623 377550 0 0 3 0x14280 nfsidl nfsio
90455 394227 0 0 3 0x14280 nfsidl nfsio
93110 496705 0 0 3 0x14280 nfsidl nfsio
66832 510459 0 0 3 0x14280 nfsidl nfsio
24244 340882 0 0 3 0x14280 nfsidl nfsio
43719 449596 0 0 3 0x14280 nfsidl nfsio
34165 201035 0 0 3 0x14280 nfsidl nfsio
7068 509465 0 0 3 0x14280 nfsidl nfsio
30903 282755 9750 0 2 0x482 syz-executor
53703 461593 9750 0 2 0x482 syz-executor
27259 516854 1 0 2 0x100083 getty
98314 409107 0 0 3 0x14200 bored sosplice
93798 92604 9750 0 2 0x482 syz-executor
61630 419202 9750 0 3 0x82 wait syz-executor
9729 23733 9750 0 2 0x482 syz-executor
53347 502034 9750 0 2 0x482 syz-executor
9750 513214 30664 0 3 0x82 kqread syz-executor
30664 204888 2726 0 3 0x10008a sigsusp ksh
2726 391113 95365 0 3 0x98 kqread sshd-session
95365 518285 61392 0 3 0x92 kqread sshd-session
61392 439174 1 0 3 0x88 kqread sshd
22328 288832 596 73 3 0x1100090 kqread syslogd
596 176943 1 0 3 0x100082 sbwait syslogd
56381 195537 1 0 3 0x100080 kqread resolvd
81437 44651 11267 77 3 0x100092 kqread dhcpleased
79535 522314 11267 77 3 0x100092 kqread dhcpleased
11267 22131 1 0 3 0x80 kqread dhcpleased
85846 323211 0 0 2 0x14200 smr
8813 61898 0 0 2 0x14200 zerothread
42319 150870 0 0 3 0x14200 aiodoned aiodoned
16807 337089 0 0 3 0x14200 syncer update
53346 502729 0 0 3 0x14200 cleaner cleaner
3899 41347 0 0 3 0x14200 reaper reaper
33312 112291 0 0 3 0x14200 pgdaemon pagedaemon
8046 292191 0 0 3 0x14200 bored viomb
71839 479233 0 0 3 0x40014200 acpi0 acpi0
50939 290774 0 0 3 0x14200 bored softnet3
81475 255824 0 0 3 0x14200 bored softnet2
63939 435541 0 0 3 0x14200 bored softnet1
85158 205857 0 0 2 0x14200 softnet0
75073 230914 0 0 3 0x14200 bored systqmp
9624 308255 0 0 3 0x14200 bored systq
31237 229753 0 0 2 0x40014200 softclock
22839 325549 0 0 3 0x40014200 idle0
1 308221 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10226 11133K 11555K 166960K 16084 0
pcb 17 18K 19K 166960K 542 0
rtable 180 15K 15K 166960K 1104 0
pf 39 14K 269K 166960K 145 0
ifaddr 37 6K 7K 166960K 107 0
ifgroup 56 2K 2K 166960K 169 0
sysctl 2 0K 0K 166960K 12 0
counters 33 17K 17K 166960K 63 0
ioctlops 0 0K 4K 166960K 344 0
iov 0 0K 20K 166960K 339 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1497 94K 95K 166960K 4384 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 9K 166960K 58 0
VM map 2 1K 1K 166960K 2 0
sem 24 21K 21K 166960K 119 0
dirhash 12 2K 2K 166960K 42 0
ACPI 1690 195K 286K 166960K 12468 0
file desc 17 61K 97K 166960K 2588 0
sigio 0 0K 0K 166960K 239 0
proc 60 59K 124K 166960K 876 0
subproc 104 6K 6K 166960K 173 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 513 0
in_multi 67 5K 7K 166960K 246 0
ether_multi 1 0K 0K 166960K 19 0
mrt 1 0K 0K 166960K 9 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 265 1182K 1182K 166960K 265 0
exec 0 0K 1K 166960K 913 0
pfkey data 0 0K 0K 166960K 3 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 228 72K 89K 166960K 25200 0
UVM aobj 131 7K 7K 166960K 141 0
pinsyscall 38 76K 96K 166960K 3782 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 0K 166960K 197 0
NDP 14 0K 2K 166960K 79 0
temp 78 6816K 6938K 166960K 71181 0
kqueue 14 22K 32K 166960K 467 0
SYN cache 2 2352K 2360K 166960K 3 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 379 0 374 3 1 2 3 0 8 1
rtentry 112 331 0 255 4 0 4 4 0 8 0
unpcb 144 3005 0 2987 21 14 7 8 0 8 6
syncache 336 10 0 10 3 3 0 1 0 8 0
tcpqe 32 1 0 1 1 1 0 1 0 8 0
tcpcb 808 1219 0 1215 19 17 2 11 0 8 1
arp 88 40 0 27 1 0 1 1 0 8 0
ipq 40 9 0 8 2 1 1 1 0 8 0
ipqe 40 105 0 104 2 1 1 1 0 8 0
inpcb 336 3867 0 3860 35 31 4 18 0 8 3
nd6 104 52 0 36 1 0 1 1 0 8 0
pkpcb 40 55 0 55 3 2 1 1 0 8 1
kcovpl 48 13 0 5 1 0 1 1 0 8 0
ppxss 1072 14 0 11 2 1 1 1 0 8 0
pfrktable 1344 3 0 1 1 0 1 1 0 8 0
pfanchor 1288 1 0 0 1 0 1 1 0 8 0
pftag 88 2 0 0 1 0 1 1 0 8 0
pfrule 1344 73 0 71 2 1 1 1 0 8 0
art_heap8 4096 5 0 0 5 0 5 5 0 8 0
art_heap4 256 884 0 543 33 9 24 29 0 8 0
art_table 32 889 0 543 4 0 4 4 0 8 0
art_node 16 220 0 156 1 0 1 1 0 8 0
sysvmsgpl 40 13 0 6 1 0 1 1 0 8 0
semapl 112 109 0 87 1 0 1 1 0 8 0
shmpl 112 138 0 10 4 0 4 4 0 8 0
dirhash 1024 37 0 20 3 0 3 3 0 8 0
dino2pl 256 6332 0 4835 95 0 95 95 0 8 0
ffsino 240 6332 0 4835 89 0 89 89 0 8 0
nchpl 144 10235 0 9705 63 40 23 63 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 37882 0 37881 4 3 1 2 0 8 0
pfiaddrpl 120 2 0 0 1 0 1 1 0 8 0
kstatmem 264 88 0 60 2 0 2 2 0 8 0
scsiplug 72 12 0 12 3 3 0 1 0 8 0
scxspl 216 27904 0 27904 11 10 1 8 1 8 1
plimitpl 152 894 0 878 1 0 1 1 0 8 0
sigapl 424 2896 0 2830 9 1 8 8 0 8 0
futexpl 64 38317 0 38314 1 0 1 1 0 8 0
knotepl 120 112184 0 112135 67 54 13 23 0 8 8
kqueuepl 184 1006 0 996 7 6 1 4 0 8 0
pipepl 288 589 0 562 14 11 3 7 0 8 0
fdescpl 432 2851 0 2822 5 1 4 5 0 8 0
filepl 120 23699 0 23451 36 20 16 17 0 8 6
lockfpl 104 1303 0 1301 2 1 1 2 0 8 0
lockfspl 48 486 0 484 1 0 1 1 0 8 0
sessionpl 144 34 0 26 1 0 1 1 0 8 0
pgrppl 48 210 0 194 1 0 1 1 0 8 0
ucredpl 104 4388 0 4374 1 0 1 1 0 8 0
zombiepl 144 2843 0 2840 2 1 1 1 0 8 0
processpl 1096 2896 0 2830 5 0 5 5 0 8 0
procpl 648 6451 0 6380 8 1 7 8 0 8 0
sosppl 168 23 0 23 3 2 1 1 0 8 1
sockpl 504 7521 0 7491 126 114 12 35 0 8 8
mcl64k 65536 76 0 76 4 3 1 1 0 8 1
mcl16k 16384 4 0 4 1 1 0 1 0 8 0
mcl9k 9216 1 0 1 1 1 0 1 0 8 0
mcl8k 8192 77 0 77 4 3 1 1 0 8 1
mcl4k 4096 5873 0 5816 21 12 9 18 0 8 1
mcl2k2 2112 3 0 0 1 0 1 1 0 8 0
mcl2k 2048 3009 0 3007 9 7 2 4 0 8 1
mtagpl 96 164 0 76 3 0 3 3 0 8 0
mbufpl 256 36256 0 36021 194 169 25 132 0 8 8
bufpl 280 8164 0 1917 447 0 447 447 0 8 0
anonpl 24 438302 0 434702 137 65 72 72 0 187 43
amapchunkpl 152 86709 0 86203 61 33 28 37 0 158 3
amappl16 200 10851 0 10818 88 76 12 28 0 8 8
amappl15 192 13 0 13 1 1 0 1 0 8 0
amappl14 184 139 0 129 1 0 1 1 0 8 0
amappl13 176 11 0 10 1 0 1 1 0 8 0
amappl12 168 3560 0 3531 3 1 2 3 0 8 0
amappl11 160 49 0 39 1 0 1 1 0 8 0
amappl10 152 9 0 9 1 1 0 1 0 8 0
amappl9 144 123 0 123 1 1 0 1 0 8 0
amappl8 136 26 0 24 1 0 1 1 0 8 0
amappl7 128 148 0 138 1 0 1 1 0 8 0
amappl6 120 213 0 211 1 0 1 1 0 8 0
amappl5 112 158 0 149 1 0 1 1 0 8 0
amappl4 104 402 0 387 1 0 1 1 0 8 0
amappl3 96 15344 0 15248 3 0 3 3 0 8 0
amappl2 88 3224 0 3144 3 0 3 3 0 8 0
amappl1 80 16771 0 16256 16 4 12 14 0 8 0
amappl 88 24451 0 24279 5 0 5 5 0 92 0
dma65536 65536 1 0 1 1 1 0 1 0 8 0
dma32768 32768 1 0 1 1 1 0 1 0 8 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 2 0 1 1 0 1 1 0 8 0
dma256 256 8 0 8 3 3 0 1 0 8 0
dma128 128 256 0 256 3 3 0 1 0 8 0
dma64 64 7 0 7 2 2 0 1 0 8 0
dma32 32 8 0 8 2 2 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 140 0 10 3 0 3 3 0 8 0
uaddrrnd 24 2851 0 2822 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 2851 0 2822 1 0 1 1 0 8 0
vmmpekpl 168 22564 0 22518 3 0 3 3 0 8 0
vmmpepl 168 178145 0 176394 136 35 101 101 0 357 19
vmsppl 344 2850 0 2822 4 1 3 4 0 8 0
rwobjpl 24 53416 0 46500 45 0 45 45 0 8 0
pdppl 4096 5708 0 5644 162 96 66 82 0 8 2
pvpl 32 1187540 0 1178076 223 104 119 122 0 265 30
pmappl 216 2850 0 2822 3 0 3 3 0 8 0
extentpl 40 55 0 38 1 0 1 1 0 8 0
phpool 112 828 0 485 13 0 13 13 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
rtrequest(1,ffff80002d9dafc8,38,ffff80002d9daf40,0) at rtrequest+0x7c7 sys/net/route.c:1008
rtm_output(ffff8000013deb00,ffff80002d9db070,ffff80002d9dafc8,38,0) at rtm_output+0x855 sys/net/rtsock.c:973
route_output(fffffd806e8f1000,fffffd806d1ff408) at route_output+0x9ac sys/net/rtsock.c:878
route_send(fffffd806d1ff408,fffffd806e8f1000,0,0) at route_send+0xd7 sys/net/rtsock.c:342
sosend(fffffd806d1ff408,0,ffff80002d9db228,0,0,0) at sosend+0xa40
sendit(ffff80002a4c22a0,4,ffff80002d9db320,0,ffff80002d9db3d0) at sendit+0x721 sys/kern/uipc_syscalls.c:786
sys_sendto(ffff80002a4c22a0,ffff80002d9db480,ffff80002d9db3d0) at sys_sendto+0x8d sys/kern/uipc_syscalls.c:564
syscall(ffff80002d9db480) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x1fd794071e0, count: -9
ddb> machine ddbcpu 1
No such command
ddb> trace
rtrequest(1,ffff80002d9dafc8,38,ffff80002d9daf40,0) at rtrequest+0x7c7 sys/net/route.c:1008
rtm_output(ffff8000013deb00,ffff80002d9db070,ffff80002d9dafc8,38,0) at rtm_output+0x855 sys/net/rtsock.c:973
route_output(fffffd806e8f1000,fffffd806d1ff408) at route_output+0x9ac sys/net/rtsock.c:878
route_send(fffffd806d1ff408,fffffd806e8f1000,0,0) at route_send+0xd7 sys/net/rtsock.c:342
sosend(fffffd806d1ff408,0,ffff80002d9db228,0,0,0) at sosend+0xa40
sendit(ffff80002a4c22a0,4,ffff80002d9db320,0,ffff80002d9db3d0) at sendit+0x721 sys/kern/uipc_syscalls.c:786
sys_sendto(ffff80002a4c22a0,ffff80002d9db480,ffff80002d9db3d0) at sys_sendto+0x8d sys/kern/uipc_syscalls.c:564
syscall(ffff80002d9db480) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x1fd794071e0, count: -9


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Feb 11, 2025, 3:48:19 PM2/11/25
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages