kernel panic: Kmalloc failed! Handle me!

2 views
Skip to first unread message

syzbot

unread,
Nov 1, 2019, 3:40:09 PM11/1/19
to aka...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 7a1e025a vmm: reimplement the x86 instruction decoder
git tree: akaros
console output: https://syzkaller.appspot.com/x/log.txt?x=1163f95ce00000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b018fab5edd31b3
dashboard link: https://syzkaller.appspot.com/bug?extid=2e05ebd8cc0e2eb2204c

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2e05eb...@syzkaller.appspotmail.com

kernel panic at kern/src/kmalloc.c:79, from core 0: Kmalloc failed! Handle
me!
Stack Backtrace on Core 0:
#01 [<0xffffffffc200a7fc>] in backtrace at src/kdebug.c:235
#02 [<0xffffffffc2009f95>] in _panic at src/init.c:275
#03 [<0xffffffffc200ad84>] in kmalloc at src/kmalloc.c:79
#04 [<0xffffffffc200adaf>] in kzmalloc at src/kmalloc.c:91
#05 [<0xffffffffc207f6b4>] in mntralloc at drivers/dev/mnt.c:1110
#06 [<0xffffffffc207f7e3>] in mntflushalloc at drivers/dev/mnt.c:1058
#07 [<0xffffffffc207fc80>] in mountio at drivers/dev/mnt.c:854
#08 [<0xffffffffc207fd75>] in mountrpc at drivers/dev/mnt.c:783
#09 [<0xffffffffc20808a8>] in mntopencreate at drivers/dev/mnt.c:568
#10 [<0xffffffffc2080a08>] in mntopen at drivers/dev/mnt.c:585
#11 [<0xffffffffc20341c0>] in __namec_from at src/ns/chan.c:1236
#12 [<0xffffffffc20349b3>] in namec at src/ns/chan.c:1530
#13 [<0xffffffffc2041b4d>] in sysopenat at src/ns/sysfile.c:585
#14 [<0xffffffffc2058fbe>] in sys_openat at src/syscall.c:1824
#15 [<0xffffffffc2059f29>] in syscall at src/syscall.c:2580
#16 [<0xffffffffc205aad8>] in run_local_syscall at src/syscall.c:2617
#17 [<0xffffffffc205b019>] in prep_syscalls at src/syscall.c:2637
#18 [<0xffffffffc20b6282>] in sysenter_callwrapper at arch/x86/trap.c:926
kernel panic at kern/src/atomic.c:100, from core 3: assertion failed:
spin_locked(lock)
Stack Backtrace on Core 3:
#01 [<0xffffffffc200a7fc>] in backtrace at src/kdebug.c:235
#02 [<0xffffffffc2009f95>] in _panic at src/init.c:275
#03 [<0xffffffffc2003d9d>] in spin_unlock at src/atomic.c:100
#04 [< [inline] >] in spin_unlock_irqsave at include/atomic.h:303
#04 [< [inline] >] in alloc_from_arena at src/arena.c:712
#04 [<0xffffffffc20024cd>] in arena_alloc at src/arena.c:842
#05 [< [inline] >] in kmem_cache_grow at src/slab.c:821
#05 [<0xffffffffc2053c8f>] in __kmem_alloc_from_slab at src/slab.c:608
#06 [<0xffffffffc20545ba>] in kmem_cache_alloc at src/slab.c:696
#07 [<0xffffffffc2053668>] in kmem_cache_free at src/slab.c:790
#08 [<0xffffffffc205bcbd>] in process_routine_kmsg at src/trap.c:231
#09 [<0xffffffffc205565e>] in __smp_idle at src/smp.c:78


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 31, 2019, 5:44:11 AM12/31/19
to aka...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 76e8476b kconfig: use pkg-config for ncurses detection
git tree: akaros
console output: https://syzkaller.appspot.com/x/log.txt?x=13fbb63ee00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15c4d971e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12b2b98ee00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2e05eb...@syzkaller.appspotmail.com

kernel panic at kern/src/kmalloc.c:67, from core 0: Kmalloc failed! Handle
me!
Stack Backtrace on Core 0:
#01 [<0xffffffffc200a7fc>] in backtrace at src/kdebug.c:235
#02 [<0xffffffffc2009f95>] in _panic at src/init.c:275
#03 [<0xffffffffc200ad9e>] in kmalloc at src/kmalloc.c:67
#04 [<0xffffffffc2030e98>] in block_alloc at src/ns/allocb.c:63
#05 [<0xffffffffc206364b>] in igbereplenish at drivers/net/etherigbe.c:1043
#06 [<0xffffffffc2064e09>] in igberproc at drivers/net/etherigbe.c:1194
#07 [<0xffffffffc200b724>] in __ktask_wrapper at src/kthread.c:292
#08 [<0xffffffffc205bced>] in process_routine_kmsg at src/trap.c:241
#09 [<0xffffffffc205567e>] in __smp_idle at src/smp.c:78

Reply all
Reply to author
Forward
0 new messages