Hello,
syzbot found the following issue on:
HEAD commit: 925b83c94733 Add keys and menu items for copy mode line nu..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=1389b346580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link:
https://syzkaller.appspot.com/bug?extid=eefbaca0eb56be2757c2
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/5e5d38f78d8c/disk-925b83c9.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/5f32e163f80a/bsd-925b83c9.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/6e08f00af9b3/kernel-925b83c9.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+eefbac...@syzkaller.appspotmail.com
login: panic: free: non-malloced addr 0x6a558e3c type ip_moptions
Stopped at db_enter+0x25: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834337b8) at panic+0x1cf sys/kern/subr_prf.c:198
free(6a558e3c,35,0) at free+0x6b7 sys/kern/kern_malloc.c:426
ip_freemoptions(ffff800000c57b00) at ip_freemoptions+0xea sys/netinet/ip_output.c:1744
in_pcbdetach(fffffa806fbdbce8) at in_pcbdetach+0xec sys/netinet/in_pcb.c:605
tcp_close(ffff8000015bb700) at tcp_close+0x194 tcpstat_inc sys/netinet/tcp_var.h:-1 [inline]
tcp_close(ffff8000015bb700) at tcp_close+0x194 sys/netinet/tcp_subr.c:530
tcp_detach(ffff8000016413b0) at tcp_detach+0x8f sys/netinet/tcp_usrreq.c:-1
soclose(ffff8000016413b0,0) at soclose+0xad pru_detach sys/sys/protosw.h:281 [inline]
soclose(ffff8000016413b0,0) at soclose+0xad sys/kern/uipc_socket.c:403
soo_close(fffffa8070e234b0,ffff80003c8e2a80) at soo_close+0x56 sys/kern/sys_socket.c:-1
fdrop(fffffa8070e234b0,ffff80003c8e2a80) at fdrop+0x121 sys/kern/kern_descrip.c:1281
closef(fffffa8070e234b0,ffff80003c8e2a80) at closef+0x190 sys/kern/kern_descrip.c:1265
fdfree(ffff80003c8e2a80) at fdfree+0x115 sys/kern/kern_descrip.c:1196
exit1(ffff80003c8e2a80,0,0,1) at exit1+0x595 sys/kern/kern_exit.c:215
sys_exit(ffff80003c8e2a80,ffff8000348c3080,ffff8000348c2fd0) at sys_exit+0x1a sys/kern/kern_exit.c:-1
end trace frame: 0xffff8000348c3070, count: 0
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb>
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup