panic: vtnet_txq_offload_ctx: mbuf ADDR start NUM offset NUM proto -NUM (3)

2 views
Skip to first unread message

syzbot

unread,
Aug 18, 2025, 7:06:32 AMAug 18
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: c04fe26aa2f7 nfsport.h: minor comments cleanup
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=11605234580000
dashboard link: https://syzkaller.appspot.com/bug?extid=efd3ced31f79f931972d

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+efd3ce...@syzkaller.appspotmail.com

panic: vtnet_txq_offload_ctx: mbuf 0xfffffe006d10a900 start 14 offset 14 proto -1
cpuid = 1
time = 1755515137
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0056e96930
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe0056e96a90
vpanic() at vpanic+0x257/frame 0xfffffe0056e96c50
panic() at panic+0xb5/frame 0xfffffe0056e96d10
vtnet_txq_encap() at vtnet_txq_encap+0xa9a/frame 0xfffffe0056e96e90
vtnet_txq_mq_start_locked() at vtnet_txq_mq_start_locked+0x28a/frame 0xfffffe0056e96fa0
vtnet_txq_mq_start() at vtnet_txq_mq_start+0xd7/frame 0xfffffe0056e96fd0
ether_output_frame() at ether_output_frame+0x30c/frame 0xfffffe0056e97090
ether_output() at ether_output+0x114b/frame 0xfffffe0056e97200
ip_output_send() at ip_output_send+0x2a2/frame 0xfffffe0056e97270
ip_output() at ip_output+0x2e32/frame 0xfffffe0056e974d0
udp_send() at udp_send+0x1a32/frame 0xfffffe0056e976d0
udp6_send() at udp6_send+0x813/frame 0xfffffe0056e979c0
sosend_dgram() at sosend_dgram+0x62a/frame 0xfffffe0056e97a30
sousrsend() at sousrsend+0x112/frame 0xfffffe0056e97ac0
dofilewrite() at dofilewrite+0x133/frame 0xfffffe0056e97b30
kern_writev() at kern_writev+0xd4/frame 0xfffffe0056e97bf0
sys_write() at sys_write+0x230/frame 0xfffffe0056e97d10
amd64_syscall() at amd64_syscall+0x4e2/frame 0xfffffe0056e97f30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe0056e97f30
--- syscall (198, FreeBSD ELF64, __syscall), rip = 0x3a1bba, rsp = 0x823a08f08, rbp = 0x823a08f80 ---
KDB: enter: panic
[ thread pid 958 tid 100303 ]
Stopped at kdb_enter+0x6e: movq $0,0x25b6f77(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe006ea00000
rdx 0x7ffff
rbx 0xffffffff827e1820 .str.27
rsp 0xfffffe0056e96a70
rbp 0xfffffe0056e96a90
rsi 0x80001
rdi 0xffffffff816260e9 printf+0x149
r8 0
r9 0xffffffff
r10 0
r11 0x2
r12 0xfffffe0054144780
r13 0xfffffffffffffffd
r14 0xffffffff827e1820 .str.27
r15 0
rip 0xffffffff8160fc1e kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x25b6f77(%rip)
db> show proc
Process 958 (syz-executor) at 0xfffffe0054133000:
state: NORMAL
uid: -1 gids: 0, 5
parent: pid 764 at 0xfffffe00540d6558
ABI: FreeBSD ELF64
flag: 0x10000180 flag2: 0
arguments: ./syz-executor exec
reaper: 0xfffffe0007809010 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00540c9248
(map 0xfffffe00540c9248)
(map.pmap 0xfffffe00540c92e8)
(pmap 0xfffffe00540c9358)
threads: 2
100264 RunQ syz-executor
100303 Run CPU 1 syz-executor
db> ps
pid ppid pgrp uid state wmesg wchan cmd
963 0 0 0 DL mdwait 0xfffffe0058632000 [md0]
962 763 763 0 R (threaded) syz-executor
100260 RunQ syz-executor
100305 S uwait 0xfffffe0059acdb00 syz-executor
961 766 766 0 R (threaded) syz-executor
100282 RunQ syz-executor
100306 S uwait 0xfffffe006df3b900 syz-executor
960 957 765 0 S uwait 0xfffffe006df3bc00 syz-executor
959 957 765 0 S uwait 0xfffffe006df3ba00 syz-executor
958 764 764 -1 R (threaded) syz-executor
100264 RunQ syz-executor
100303 Run CPU 1 syz-executor
957 765 765 0 R (threaded) syz-executor
100137 RunQ syz-executor
100301 RunQ syz-executor
100302 S uwait 0xfffffe006df3b800 syz-executor
955 1 765 0 S uwait 0xfffffe006df3bb00 syz-executor
947 1 766 0 S uwait 0xfffffe0059b1d400 syz-executor
944 1 765 0 S uwait 0xfffffe006df39a80 syz-executor
934 1 764 0 S uwait 0xfffffe006df3b300 syz-executor
933 0 0 0 DL (threaded) [KTLS]
100259 D - 0xfffffe0053ef6300 [thr_0]
100270 D - 0xfffffe0053ef6380 [thr_1]
100271 D - 0xffffffff83cb9628 [reclaim_0]
920 1 765 0 S uwait 0xfffffe0059b1db80 syz-executor
912 1 764 0 S uwait 0xfffffe006df3b100 syz-executor
904 1 763 0 S uwait 0xfffffe006df39200 syz-executor
882 0 0 0 DL (threaded) [so_splice]
100140 D - 0xfffffe0058587680 [thr_0]
100173 D - 0xfffffe00585876c0 [thr_1]
881 1 766 0 S uwait 0xfffffe0059b20a80 syz-executor
879 1 879 0 Ss select 0xfffffe0059b1d2c0 rtsol
878 1 878 0 Ss select 0xfffffe0059b1d040 rtsol
877 1 877 0 Ss select 0xfffffe0059acde40 rtsol
873 780 423 0 S kqread 0xfffffe00593d9e00 rtsol
822 1 764 0 S uwait 0xfffffe0059b1d780 syz-executor
820 1 765 0 S uwait 0xfffffe0059b1d680 syz-executor
814 0 0 0 DL aiordy 0xfffffe00540e1570 [aiod4]
813 0 0 0 DL aiordy 0xfffffe005410f568 [aiod3]
812 1 765 0 S umtxn 0xfffffe0059aa0a00 syz-executor
811 0 0 0 DL aiordy 0xfffffe005410fac0 [aiod2]
809 0 0 0 DL aiordy 0xfffffe005410f010 [aiod1]
780 770 423 0 S wait 0xfffffe00540df008 sh
770 423 423 0 S wait 0xfffffe00540a7010 sh
766 762 766 0 S nanslp 0xffffffff83ba7c41 syz-executor
765 762 765 0 S nanslp 0xffffffff83ba7c41 syz-executor
764 762 764 0 S nanslp 0xffffffff83ba7c41 syz-executor
763 762 763 0 S nanslp 0xffffffff83ba7c41 syz-executor
762 760 760 0 S select 0xfffffe006df39a40 syz-executor
760 758 760 0 Ss sigsusp 0xfffffe0054003b68 csh
758 681 758 0 Ss select 0xfffffe00584e62c0 sshd
747 1 747 0 Ss+ ttyin 0xfffffe00077fd8b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00585bdcb0 getty
745 1 745 0 Ss+ ttyin 0xfffffe00077fbcb0 getty
744 1 744 0 Ss+ ttyin 0xfffffe00077fc0b0 getty
743 1 743 0 Ss+ ttyin 0xfffffe00077fc4b0 getty
742 1 742 0 Ss+ ttyin 0xfffffe00077fc8b0 getty
741 1 741 0 Ss+ ttyin 0xfffffe00585be0b0 getty
740 1 740 0 Ss+ ttyin 0xfffffe00585be4b0 getty
739 1 739 0 Ss+ ttyin 0xfffffe00585be8b0 getty
737 1 17 0 S+ piperd 0xfffffe00596a9140 logger
736 735 17 0 S+ nanslp 0xffffffff83ba7c40 sleep
735 1 17 0 S+ wait 0xfffffe00540de558 sh
685 1 685 0 Ss nanslp 0xffffffff83ba7c41 cron
681 1 681 0 Ss select 0xfffffe0059b1e3c0 sshd
494 1 494 0 Ss select 0xfffffe0059a076c0 syslogd
423 1 423 0 Ss wait 0xfffffe00540d8010 devd
422 1 422 65 Ss select 0xfffffe00584e6240 dhclient
337 1 337 0 Ss select 0xfffffe0059b20d40 dhclient
334 1 334 0 Ss select 0xfffffe0059a07640 dhclient
16 0 0 0 DL syncer 0xffffffff83cc5820 [syncer]
15 0 0 0 DL vlruwt 0xfffffe000780a018 [vnlru]
14 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83cc3d60 [bufdaemon]
100080 D - 0xffffffff83001ec0 [bufspacedaemon-0]
100094 D sdflush 0xfffffe0053fe08e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83d0ec80 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83cf4d48 [dom0]
100081 D launds 0xffffffff83cf4d54 [laundry: dom0]
100082 D umarcl 0xffffffff81df2890 [uma]
7 0 0 0 DL - 0xffffffff839205d8 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff843b5c30 [pf purge]
5 0 0 0 DL waiting 0xffffffff8485c700 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100045 D - 0xffffffff838ea340 [doneq0]
100046 D - 0xffffffff838ea2c0 [async]
100075 D - 0xffffffff838ea140 [scanner]
3 0 0 0 DL (threaded) [crypto]
100042 D crypto_ 0xffffffff83cf0640 [crypto]
100043 D crypto_ 0xfffffe0007a95c30 [crypto returns 0]
100044 D crypto_ 0xfffffe0007a95c80 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100037 D - 0xffffffff83b50640 [g_event]
100038 D - 0xffffffff83b50660 [g_up]
100039 D - 0xffffffff83b50680 [g_down]
2 0 0 0 RL (threaded) [clock]
100031 I [clock (0)]
100032 Run CPU 0 [clock (1)]
12 0 0 0 WL (threaded) [intr]
100013 I [swi6: task queue]
100014 I [swi6: Giant taskq]
100016 I [swi5: fast taskq]
100033 I [swi1: netisr 0]
100034 I [swi1: hpts]
100035 I [swi1: hpts]
100047 I [irq24: virtio_pci0]
100048 I [irq25: virtio_pci0]
100049 I [irq26: virtio_pci0]
100050 I [irq27: virtio_pci0]
100051 I [irq28: virtio_pci1]
100052 I [irq29: virtio_pci1]
100053 I [irq30: virtio_pci1]
100054 I [irq31: virtio_pci1]
100055 I [irq32: virtio_pci1]
100060 I [irq10: virtio_pci2]
100062 I [irq1: atkbd0]
100063 I [irq12: psm0]
100064 I [swi0: uart uart++]
100068 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0007809010 [init]
10 0 0 0 DL audit_w 0xffffffff83cf10e0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D parked 0xffffffff84c43ff0 [swapper]
100005 D - 0xfffffe0007a98b00 [softirq_0]
100006 D - 0xfffffe0007a98900 [softirq_1]
100007 D - 0xfffffe0007a98700 [if_io_tqg_0]
100008 D - 0xfffffe0007a98500 [if_io_tqg_1]
100009 D - 0xfffffe0007a98300 [if_config_tqg_0]
100010 D - 0xfffffe00083f9700 [kqueue_ctx taskq]
100011 D - 0xfffffe00083f9600 [jail_remove taskq]
100012 D - 0xfffffe00083f9500 [bus taskq]
100015 D - 0xfffffe00083f9000 [thread taskq]
100017 D - 0xfffffe00083f8c00 [aiod_kick taskq]
100018 D - 0xfffffe00083f8b00 [deferred_unmount ta]
100019 D - 0xfffffe00083f8a00 [inm_free taskq]
100020 D - 0xfffffe00083f8900 [in6m_free taskq]
100021 D - 0xfffffe00083f8800 [linuxkpi_irq_wq]
100022 D - 0xfffffe00083f8700 [linuxkpi_short_wq_0]
100023 D - 0xfffffe00083f8700 [linuxkpi_short_wq_1]
100024 D - 0xfffffe00083f8700 [linuxkpi_short_wq_2]
100025 D - 0xfffffe00083f8700 [linuxkpi_short_wq_3]
100026 D - 0xfffffe00083f8600 [linuxkpi_long_wq_0]
100027 D - 0xfffffe00083f8600 [linuxkpi_long_wq_1]
100028 D - 0xfffffe00083f8600 [linuxkpi_long_wq_2]
100029 D - 0xfffffe00083f8600 [linuxkpi_long_wq_3]
100036 D - 0xfffffe00083f8100 [firmware taskq]
100040 D - 0xfffffe00083f7e00 [crypto_0]
100041 D - 0xfffffe00083f7e00 [crypto_1]
100056 D - 0xfffffe00083f7700 [vtnet0 rxq 0]
100057 D - 0xfffffe00083f7600 [vtnet0 txq 0]
100058 D - 0xfffffe00083f7500 [vtnet0 rxq 1]
100059 D - 0xfffffe00083f7400 [vtnet0 txq 1]
100061 D vtbslp 0xfffffe0057d76f00 [virtio_balloon]
100065 D - 0xffffffff827e5f00 [deadlkres]
100069 D - 0xfffffe00593db000 [acpi_task_0]
100070 D - 0xfffffe00593db000 [acpi_task_1]
100071 D - 0xfffffe00593db000 [acpi_task_2]
100073 D - 0xfffffe00083fb100 [mca taskq]
100074 D - 0xfffffe00083f7d00 [CAM taskq]
100076 D - 0xfffffe00593dae00 [ipsec_offload]
db> show all locks
Process 958 (syz-executor) thread 0xfffffe0054144780 (100303)
exclusive sleep mutex vtnet0-tx1 (vtnet0-tx1) r = 0 (0xfffffe0007773700) locked @ /syzkaller/managers/main/kernel/sys/dev/virtio/network/if_vtnet.c:2777
exclusive rw udpinp (udpinp) r = 0 (0xfffffe006def73a0) locked @ /syzkaller/managers/main/kernel/sys/netinet/udp_usrreq.c:1162
Process 957 (syz-executor) thread 0xfffffe005413b780 (100301)
exclusive rw vmobject (vmobject) r = 0 (0xfffffe005410a000) locked @ /syzkaller/managers/main/kernel/sys/vm/vm_fault.c:358
shared sx vm map (user) (vm map (user)) r = 0 (0xfffffe00541124f0) locked @ /syzkaller/managers/main/kernel/sys/vm/vm_map.c:4998
db> show malloc
Type InUse MemUse Requests
pf_hash 6 12804K 6
linker 419 5517K 575
tcp_hpts 7 4801K 7
devbuf 4187 4323K 4213
sysctloid 35455 2089K 35530
vtbuf 24 1968K 46
kobj 331 1324K 504
newblk 14 1028K 1015
vfscache 3 1025K 3
pcb 35 678K 170
inodedep 18 519K 321
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
filedesc 42 329K 251
subproc 162 326K 1061
vnet_data 2 224K 2
acpitask 1 224K 1
KTRACE 100 200K 100
acpica 1674 184K 54444
vmem 5 144K 6
tidhash 3 141K 3
pagedep 12 131K 139
tfo_ccache 1 128K 1
IP reass 1 128K 1
DEVFS1 107 107K 124
sem 4 106K 4
gtaskqueue 18 98K 18
bus 1000 82K 5086
mtx_pool 3 74K 3
syncache 1 68K 1
NFSD srvcache 3 68K 3
module 525 66K 525
ddb_capture 1 64K 1
kdtrace 227 44K 1271
umtx 336 42K 336
shm 2 34K 5
hostcache 1 32K 1
DEVFS3 125 32K 135
msg 4 30K 4
kbdmux 6 28K 6
BPF 17 27K 21
temp 32 21K 1905
DEVFS_RULE 56 20K 56
routetbl 132 19K 407
ifaddr 66 19K 68
ufs_mount 4 17K 5
proc 3 17K 3
LRO 16 17K 16
filemon 2 16K 6
tty 16 16K 16
ithread 90 15K 90
bus-sc 34 15K 1657
eventhandler 163 14K 163
lltable 43 14K 43
ifnet 7 13K 7
ether_multi 152 13K 176
kenv 95 12K 95
GEOM 54 12K 457
cred 28 11K 201
CAM queue 5 11K 1528
rman 82 10K 437
kqueue 84 10K 1061
rpc 8 9K 8
in6_multi 65 9K 66
bmsafemap 2 9K 232
plimit 22 9K 317
devstat 4 9K 4
UART 12 9K 12
ksem 1 8K 2
shmfd 1 8K 5
iov 2 8K 13610
pfs_vncache 1 8K 1
audit_evclass 240 8K 304
taskqueue 69 8K 81
sglist 6 7K 6
CAM DEV 3 6K 510
pfs_nodes 22 6K 22
ufs_dirhash 24 5K 27
pf_ifnet 12 5K 21
pwddesc 73 5K 1001
UMA 271 5K 271
vt 11 5K 11
pf_table 2 4K 3
memdesc 1 4K 1
MCA 32 4K 32
md_disk 1 4K 2
evdev 4 4K 4
acpisem 28 4K 28
selfd 49 4K 303117
proc-args 99 3K 1997
DEVFSP 47 3K 64
session 23 3K 34
terminal 11 3K 11
uidinfo 5 3K 11
acpidev 20 3K 20
hhook 8 3K 10
clone 9 3K 9
kcovinfo 36 3K 36
netlink 2 3K 72
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
ip6ndp 12 2K 14
CC Mem 14 2K 73
Unitno 28 2K 56
lockf 16 2K 47
sctp_ifa 13 2K 14
CAM XPT 22 2K 543
sctp_atcl 4 2K 50
in_multi 6 2K 11
tun 4 2K 4
select 12 2K 50
toponodes 6 2K 6
ipsecpolicy 2 2K 2
msi 9 2K 9
softdep 1 1K 1
dirrem 4 1K 195
diradd 8 1K 213
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 40
NFSD session 1 1K 1
inpcbpolicy 31 1K 301
newdirblk 7 1K 110
mkdir 7 1K 220
CAM periph 4 1K 271
ipsec 3 1K 3
sctp_ifn 6 1K 14
mld 6 1K 6
igmp 6 1K 6
pfil 6 1K 6
osd 19 1K 90
isadev 6 1K 6
mount 16 1K 331
pci_link 10 1K 10
crypto 4 1K 11
encap_export_host 12 1K 12
freework 3 1K 196
freeblks 2 1K 132
indirdep 2 1K 97
procdesc 4 1K 10
cdev 2 1K 2
lkpikmalloc 8 1K 9
counter_rate 13 1K 13
chacha20random 1 1K 1
biobuf 1 1K 1
sctp_timw 1 1K 1
freefile 2 1K 162
ip_msource 4 1K 12
vnodes 1 1K 2
ktls 1 1K 12
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 5
prison 6 1K 6
sctp_atky 4 1K 52
cryptodev 2 1K 57
pf_rule 1 1K 1
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
aio 4 1K 5
eventfd 1 1K 5
pmchooks 1 1K 1
filedesc_to_leader 2 1K 7
CAM path 4 1K 1034
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 3445
filecaps 4 1K 79
sctp_vrf 1 1K 1
sctp_athm 4 1K 51
ip6_msource 1 1K 2
vnet 1 1K 1
accf 1 1K 1
pmc 1 1K 1
entropy 2 1K 33
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
ext2_mount 0 0K 0
ext2_node 0 0K 0
ext2_extents 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
mqdata 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 77
sctp_iter 0 0K 12
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 12
sctp_aadr 0 0K 0
sctp_stro 0 0K 1
sctp_stri 0 0K 2
sctp_map 0 0K 2
tcp_pcm_rack 0 0K 1
tcp_do_rack 0 0K 0
tcp_fsb_rack 0 0K 2
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
ixl 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
fpukern_ctx 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
NMI handlers 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
amdiommu_dom 0 0K 0
amdiommu_ctx 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
aesni_data 0 0K 0
xenbus 0 0K 0
vm_fictitious 0 0K 0
UMAHash 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 138
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 20
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 16
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
ktls_ocf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
simple_attr 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpimhi 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 10
ip6_moptions 0 0K 2
in6_mfilter 0 0K 4
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
ip_moptions 0 0K 8
in_mfilter 0 0K 21
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 21
fadvise 0 0K 0
VN POLL 0 0K 8
statfs 0 0K 229
namei_tracker 0 0K 2
inotify 0 0K 69
export_host 0 0K 0
cl_savebuf 0 0K 25
lio 0 0K 2
acl 0 0K 0
mbuf_tag 0 0K 0
pts 0 0K 0
timerfd 0 0K 0
ioctlops 0 0K 112
Witness 0 0K 0
stack 0 0K 0
sbuf 0 0K 312
firmware 0 0K 0
compressor 0 0K 0
SWAP 0 0K 0
sysctltmp 0 0K 635
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 71
rctl 0 0K 0
cache 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 2
pwd 0 0K 0
tty console 0 0K 0
boottrace 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 78
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
tmpfs extattr 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
pvscsi 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
ufshci 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 1
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
SIIS driver 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
mpi3mrbuf 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
md_sectors 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
ciss_data 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
AHCI driver 0 0K 0
agp 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
acpicmbat 0 0K 0
aacraidcam 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
scsi_pass 0 0K 0
scsi_da 0 0K 70
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
nvme_da 0 0K 0
CAM CCB 0 0K 523
CAM ccb queue 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8321 1077 12953 0 254 38494208 0
mbuf 256 8650 1012 17199 0 254 2473472 0
BUF TRIE 152 244 11560 1026 0 62 1794208 0
malloc-4096 4096 417 3 1492 0 2 1720320 0
malloc-384 384 4215 45 4230 0 30 1635840 0
malloc-128 128 12506 235 12969 0 126 1630848 0
tcp_log 416 1826 1990 6643 0 254 1587456 0
UMA Slabs 0 112 11047 35 11047 0 126 1241184 0
RADIX NODE 152 7864 87 31826 0 62 1208552 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
vmem btag 56 16640 31 16640 0 254 933576 0
malloc-65536 65536 14 0 17 0 1 917504 0
FFS inode 1168 536 24 701 0 8 654080 0
sctp_asoc 2256 0 255 1 0 254 575280 0
socket 1024 59 449 1575 0 254 520192 0
lkpicurr 168 2 3094 2 0 62 520128 0
pbuf 2624 0 182 0 0 2 477568 0
malloc-64 64 3948 3171 307084 0 254 455616 0
VM OBJECT 248 1305 135 14964 0 62 357120 0
malloc-16384 16384 20 1 313 0 1 344064 0
malloc-2048 2048 9 151 517 0 8 327680 0
256 Bucket 2048 148 12 1103 0 8 327680 0
THREAD 1860 153 15 306 0 8 312480 0
sctp_ep 1152 4 255 48 0 254 298368 0
malloc-2048 2048 107 37 174 0 8 294912 0
VNODE 440 574 92 741 0 30 293040 0
malloc-32768 32768 1 7 67 0 1 262144 0
malloc-16 16 14629 371 14837 0 254 240000 0
DEVCTL 1024 24 196 149 0 0 225280 0
malloc-65536 65536 2 1 3 0 1 196608 0
sctp_raddr 736 0 264 1 0 254 194304 0
MAP ENTRY 96 1713 303 47987 0 126 193536 0
UMA Zones 768 243 1 243 0 16 187392 0
malloc-32 32 5374 296 6434 0 254 181440 0
malloc-128 128 1143 252 25590 0 126 178560 0
lkpimm 56 1 3095 1 0 254 173376 0
unpcb 320 22 494 1195 0 254 165120 0
FFS2 dinode 256 536 94 701 0 62 161280 0
malloc-256 256 78 552 1241 0 62 161280 0
FPU_save_area 832 155 25 388 0 16 149760 0
malloc-1024 1024 121 23 147 0 16 147456 0
S VFS Cache 104 1025 262 1225 0 126 133848 0
malloc-65536 65536 0 2 63 0 1 131072 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 110 0 1 131072 0
malloc-32768 32768 4 0 4 0 1 131072 0
mbuf_packet 256 3 505 262 0 254 130048 0
PROC 1368 72 16 963 0 8 120384 0
ksiginfo 112 69 975 112 0 126 116928 0
pf anchors 1664 1 69 1 0 64 116480 0
malloc-32768 32768 2 1 122 0 1 98304 0
malloc-16384 16384 6 0 7 0 1 98304 0
malloc-8192 8192 7 4 13 0 1 90112 0
malloc-4096 4096 19 3 35 0 2 90112 0
filedesc0 1072 73 11 1001 0 8 90048 0
UMA Kegs 384 229 4 229 0 30 89472 0
syncache 168 1 527 7 0 254 88704 0
128 Bucket 1024 47 36 254 0 16 84992 0
malloc-64 64 512 559 1562 0 254 68544 0
malloc-128 128 339 188 426 0 126 67456 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-32768 32768 1 1 13 0 1 65536 0
malloc-8192 8192 7 1 41 0 1 65536 0
malloc-8192 8192 7 1 9 0 1 65536 0
64 Bucket 512 87 41 1825 0 30 65536 0
malloc-256 256 156 99 612 0 62 65280 0
malloc-256 256 185 70 404 0 62 65280 0
g_bio 408 0 150 7311 0 30 61200 0
malloc-384 384 109 41 110 0 30 57600 0
malloc-64 64 466 353 683 0 254 52416 0
malloc-128 128 161 242 625 0 126 51584 0
malloc-256 256 118 77 760 0 62 49920 0
malloc-256 256 71 124 303 0 62 49920 0
malloc-256 256 42 153 538 0 62 49920 0
32 Bucket 256 75 120 502 0 62 49920 0
DIRHASH 1024 34 14 36 0 16 49152 0
NAMEI 1024 0 48 14290 0 16 49152 0
malloc-2048 2048 16 8 33 0 8 49152 0
malloc-2048 2048 6 18 71 0 8 49152 0
malloc-2048 2048 1 23 574 0 8 49152 0
malloc-1024 1024 5 43 1517 0 16 49152 0
pcpu-64 64 502 266 502 0 254 49152 0
malloc-384 384 46 74 525 0 30 46080 0
malloc-384 384 45 75 390 0 30 46080 0
tcp_inpcb 1304 14 19 73 0 8 43032 0
vnpbuf 2624 0 16 5 0 16 41984 0
malloc-4096 4096 5 5 562 0 2 40960 0
pcpu-8 8 4779 341 4977 0 254 40960 0
VMSPACE 584 50 20 941 0 16 40880 0
pipe 736 21 34 335 0 16 40480 0
sctp_chunk 152 0 260 1 0 254 39520 0
udp_inpcb 408 10 80 177 0 30 36720 0
hostcache 64 2 565 2 0 254 36288 0
malloc-64 64 16 551 88 0 254 36288 0
malloc-64 64 324 243 13578 0 254 36288 0
malloc-64 64 329 238 2846 0 254 36288 0
malloc-64 64 8 559 63 0 254 36288 0
malloc-64 64 137 430 1292 0 254 36288 0
malloc-128 128 26 253 108 0 126 35712 0
malloc-128 128 68 211 3316 0 126 35712 0
malloc-128 128 155 124 928 0 126 35712 0
malloc-128 128 32 247 453 0 126 35712 0
routing nhops 256 26 109 33 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-256 256 21 114 823 0 62 34560 0
malloc-256 256 4 131 329 0 62 34560 0
ripcb 376 7 83 45 0 30 33840 0
malloc-16384 16384 1 1 2 0 1 32768 0
malloc-4096 4096 5 3 8 0 2 32768 0
malloc-2048 2048 10 6 22 0 8 32768 0
malloc-2048 2048 2 14 201 0 8 32768 0
malloc-1024 1024 2 30 46 0 16 32768 0
malloc-1024 1024 6 26 21 0 16 32768 0
malloc-1024 1024 3 29 171 0 16 32768 0
malloc-1024 1024 18 14 22 0 16 32768 0
malloc-1024 1024 18 14 20 0 16 32768 0
malloc-1024 1024 1 31 6 0 16 32768 0
malloc-512 512 10 54 121 0 30 32768 0
malloc-512 512 8 56 17 0 30 32768 0
malloc-512 512 3 61 43 0 30 32768 0
malloc-512 512 2 62 40 0 30 32768 0
malloc-512 512 2 62 51 0 30 32768 0
malloc-512 512 6 58 28 0 30 32768 0
ttyinq 160 135 65 300 0 62 32000 0
Files 80 225 175 7727 0 126 32000 0
PGRP 120 27 237 38 0 126 31680 0
clpbuf 2624 0 12 70 0 4 31488 0
sctp_laddr 48 1 587 14 0 254 28224 0
rl_entry 48 4 584 8 0 254 28224 0
16 Bucket 144 65 131 310 0 62 28224 0
4 Bucket 48 7 581 10 0 254 28224 0
AIO 208 2 131 27 0 62 27664 0
da_ccb 544 0 49 1947 0 16 26656 0
udplite_inpcb 408 0 63 6 0 30 25704 0
TURNSTILE 136 169 20 169 0 62 25704 0
cpuset 200 42 86 54 0 62 25600 0
malloc-8192 8192 1 2 82 0 1 24576 0
ertt_txseginfo 40 0 606 502 0 254 24240 0
PWD 40 28 578 173 0 254 24240 0
rtentry 168 29 115 33 0 62 24192 0
8 Bucket 80 71 229 365 0 126 24000 0
malloc-384 384 7 53 7 0 30 23040 0
malloc-384 384 2 58 2 0 30 23040 0
malloc-384 384 0 60 343 0 30 23040 0
malloc-384 384 2 58 28 0 30 23040 0
Mountpoints 2816 2 6 4 0 4 22528 0
SLEEPQUEUE 88 169 87 169 0 126 22528 0
ertt 72 14 266 73 0 126 20160 0
malloc-32 32 258 372 420 0 254 20160 0
malloc-32 32 128 502 252 0 254 20160 0
malloc-32 32 134 496 664 0 254 20160 0
malloc-32 32 85 545 1198 0 254 20160 0
malloc-32 32 96 534 138 0 254 20160 0
malloc-32 32 73 557 334 0 254 20160 0
malloc-32 32 38 592 2710 0 254 20160 0
2 Bucket 32 65 565 386 0 254 20160 0
KNOTE 160 6 119 54 0 62 20000 0
tcp_rack_map 128 0 155 3 0 126 19840 0
cryptop 280 0 70 4 0 30 19600 0
AIOCB 552 1 34 66 0 16 19320 0
ktls_session 256 0 75 1 0 62 19200 0
vmem 1856 2 7 2 0 8 16704 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-8192 8192 0 2 21 0 1 16384 0
malloc-4096 4096 1 3 11 0 2 16384 0
malloc-4096 4096 2 2 3 0 2 16384 0
malloc-4096 4096 2 2 272 0 2 16384 0
malloc-2048 2048 4 4 4 0 8 16384 0
malloc-512 512 1 31 9 0 30 16384 0
SMR CPU 32 8 503 8 0 254 16352 0
tcp_bbr_pcb 896 0 18 1 0 16 16128 0
malloc-16 16 328 672 1810 0 254 16000 0
kenv 258 17 43 1065 0 30 15480 0
tcp_rack_pcb 1088 0 14 1 0 8 15232 0
mqnode 416 3 33 3 0 30 14976 0
domainset 40 1 314 42 0 254 12600 0
SMR SHARED 24 8 503 8 0 254 12264 0
malloc-16 16 15 735 33 0 254 12000 0
malloc-16 16 61 689 324 0 254 12000 0
malloc-16 16 70 680 429 0 254 12000 0
malloc-16 16 185 565 3024 0 254 12000 0
malloc-16 16 9 741 11 0 254 12000 0
malloc-16 16 15 735 24812 0 254 12000 0
itimer 352 0 33 8 0 30 11616 0
splice 184 0 63 2 0 62 11592 0
L VFS Cache 320 0 36 16 0 30 11520 0
AIOLIO 272 0 42 2 0 30 11424 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 3 0 2 8192 0
pcpu-16 16 8 504 8 0 254 8192 0
vtnet_tx_hdr 24 1 333 1793 0 254 8016 0
UMA Slabs 1 176 9 13 9 0 62 3872 0
KMAP ENTRY 96 18 21 22 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 152 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf fragment node 72 0 0 0 0 126 0 0
pf frags 232 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf Ethernet anchors 1240 0 0 0 0 64 0 0
pf UDP mappings 104 0 0 0 0 126 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 384 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 18, 2025, 8:29:30 AMAug 18
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: c04fe26aa2f7 nfsport.h: minor comments cleanup
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=12486442580000
dashboard link: https://syzkaller.appspot.com/bug?extid=efd3ced31f79f931972d
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11adbba2580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16486442580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+efd3ce...@syzkaller.appspotmail.com

panic: vtnet_txq_offload_ctx: mbuf 0xfffffe006c600500 start 14 offset 14 proto -1
cpuid = 1
time = 1755520100
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0056c35930
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe0056c35a90
vpanic() at vpanic+0x257/frame 0xfffffe0056c35c50
panic() at panic+0xb5/frame 0xfffffe0056c35d10
vtnet_txq_encap() at vtnet_txq_encap+0xa9a/frame 0xfffffe0056c35e90
vtnet_txq_mq_start_locked() at vtnet_txq_mq_start_locked+0x28a/frame 0xfffffe0056c35fa0
vtnet_txq_mq_start() at vtnet_txq_mq_start+0xd7/frame 0xfffffe0056c35fd0
ether_output_frame() at ether_output_frame+0x30c/frame 0xfffffe0056c36090
ether_output() at ether_output+0x114b/frame 0xfffffe0056c36200
ip_output_send() at ip_output_send+0x2a2/frame 0xfffffe0056c36270
ip_output() at ip_output+0x2e32/frame 0xfffffe0056c364d0
udp_send() at udp_send+0x1a32/frame 0xfffffe0056c366d0
udp6_send() at udp6_send+0x813/frame 0xfffffe0056c369c0
sosend_dgram() at sosend_dgram+0x62a/frame 0xfffffe0056c36a30
sousrsend() at sousrsend+0x112/frame 0xfffffe0056c36ac0
dofilewrite() at dofilewrite+0x133/frame 0xfffffe0056c36b30
kern_writev() at kern_writev+0xd4/frame 0xfffffe0056c36bf0
sys_write() at sys_write+0x230/frame 0xfffffe0056c36d10
amd64_syscall() at amd64_syscall+0x4e2/frame 0xfffffe0056c36f30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe0056c36f30
--- syscall (198, FreeBSD ELF64, __syscall), rip = 0x3a1bba, rsp = 0x820d034e8, rbp = 0x820d03560 ---
KDB: enter: panic
[ thread pid 835 tid 100106 ]
Stopped at kdb_enter+0x6e: movq $0,0x25b6f77(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe0002bf1850
rdx 0xdffff7c000000000
rbx 0xffffffff827e1820 .str.27
rsp 0xfffffe0056c35a70
rbp 0xfffffe0056c35a90
rsi 0
rdi 0xffffffff830004e8 panicstr
r8 0
r9 0xffffffff
r10 0
r11 0x2
r12 0xfffffe00540c0000
r13 0xfffffffffffffffd
r14 0xffffffff827e1820 .str.27
r15 0
rip 0xffffffff8160fc1e kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x25b6f77(%rip)
db> show proc
Process 835 (syz-executor) at 0xfffffe00540a9560:
state: NORMAL
uid: 0 gids: 0, 5
parent: pid 828 at 0xfffffe00540d2008
ABI: FreeBSD ELF64
flag: 0x10000000 flag2: 0
arguments: ./syz-executor exec
reaper: 0xfffffe0007809010 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe0054109248
(map 0xfffffe0054109248)
(map.pmap 0xfffffe00541092e8)
(pmap 0xfffffe0054109358)
threads: 1
100106 Run CPU 1 syz-executor
db> ps
pid ppid pgrp uid state wmesg wchan cmd
835 828 828 0 R CPU 1 syz-executor
828 773 828 0 S nanslp 0xffffffff83ba7c40 syz-executor
819 1 819 0 Ss select 0xfffffe006def9540 dhclient
815 805 423 0 S nanslp 0xffffffff83ba7c41 dhclient
805 423 423 0 S wait 0xfffffe0054104558 sh
773 772 770 0 S select 0xfffffe00596cb240 syz-executor
772 770 770 0 S (threaded) syz-execprog
100107 S kqread 0xfffffe00593da900 syz-execprog
100111 S uwait 0xfffffe00596cb580 syz-execprog
100112 S uwait 0xfffffe00596cb680 syz-execprog
100113 S uwait 0xfffffe00596cb780 syz-execprog
100114 S uwait 0xfffffe00596cd880 syz-execprog
100115 S uwait 0xfffffe00596cb880 syz-execprog
100116 S uwait 0xfffffe00596cd980 syz-execprog
100117 S uwait 0xfffffe00596cda80 syz-execprog
770 768 770 0 Ss sigsusp 0xfffffe0054104b60 csh
768 681 768 0 Ss select 0xfffffe00596cb340 sshd
747 1 747 0 Ss+ ttyin 0xfffffe00077fd8b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00585bccb0 getty
745 1 745 0 Ss+ ttyin 0xfffffe00585bd0b0 getty
744 1 744 0 Ss+ ttyin 0xfffffe00585bd4b0 getty
743 1 743 0 Ss+ ttyin 0xfffffe00585bd8b0 getty
742 1 742 0 Ss+ ttyin 0xfffffe00585bdcb0 getty
741 1 741 0 Ss+ ttyin 0xfffffe00585be0b0 getty
740 1 740 0 Ss+ ttyin 0xfffffe00585be4b0 getty
739 1 739 0 Ss+ ttyin 0xfffffe00585be8b0 getty
737 1 17 0 S+ piperd 0xfffffe006b44db80 logger
736 735 17 0 S+ nanslp 0xffffffff83ba7c40 sleep
735 1 17 0 S+ wait 0xfffffe00540d2560 sh
685 1 685 0 Ss nanslp 0xffffffff83ba7c41 cron
681 1 681 0 Ss select 0xfffffe006defa540 sshd
494 1 494 0 Ss select 0xfffffe00596cc840 syslogd
423 1 423 0 Ss wait 0xfffffe00540aa568 devd
422 1 422 65 Ss select 0xfffffe006defa5c0 dhclient
337 1 337 0 Ss select 0xfffffe00596cbf40 dhclient
334 1 334 0 Ss select 0xfffffe00596cc8c0 dhclient
16 0 0 0 DL syncer 0xffffffff83cc5820 [syncer]
15 0 0 0 DL vlruwt 0xfffffe000780a018 [vnlru]
14 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83cc3d60 [bufdaemon]
100082 D - 0xffffffff83001ec0 [bufspacedaemon-0]
100094 D sdflush 0xfffffe006b520ce8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83d0ec80 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83cf4d48 [dom0]
100080 D launds 0xffffffff83cf4d54 [laundry: dom0]
100081 D umarcl 0xffffffff81df2890 [uma]
7 0 0 0 DL - 0xffffffff839205d8 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff8457cc30 [pf purge]
5 0 0 0 DL waiting 0xffffffff84884700 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100045 D - 0xffffffff838ea340 [doneq0]
100046 D - 0xffffffff838ea2c0 [async]
100075 D - 0xffffffff838ea140 [scanner]
3 0 0 0 DL (threaded) [crypto]
100042 D crypto_ 0xffffffff83cf0640 [crypto]
100043 D crypto_ 0xfffffe0007a95c30 [crypto returns 0]
100044 D crypto_ 0xfffffe0007a95c80 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100037 D - 0xffffffff83b50640 [g_event]
100038 D - 0xffffffff83b50660 [g_up]
100039 D - 0xffffffff83b50680 [g_down]
2 0 0 0 WL (threaded) [clock]
100031 I [clock (0)]
100032 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100013 I [swi6: task queue]
100014 I [swi6: Giant taskq]
100016 I [swi5: fast taskq]
100033 Run CPU 0 [swi1: netisr 0]
100065 D - 0xffffffff827e5f01 [deadlkres]
100069 D - 0xfffffe00593db000 [acpi_task_0]
100070 D - 0xfffffe00593db000 [acpi_task_1]
100071 D - 0xfffffe00593db000 [acpi_task_2]
100073 D - 0xfffffe00083fb100 [mca taskq]
100074 D - 0xfffffe00083f7d00 [CAM taskq]
100076 D - 0xfffffe00593dae00 [ipsec_offload]
db> show all locks
Process 835 (syz-executor) thread 0xfffffe00540c0000 (100106)
exclusive sleep mutex vtnet0-tx1 (vtnet0-tx1) r = 0 (0xfffffe0007778700) locked @ /syzkaller/managers/main/kernel/sys/dev/virtio/network/if_vtnet.c:2777
exclusive rw udpinp (udpinp) r = 0 (0xfffffe006b732e20) locked @ /syzkaller/managers/main/kernel/sys/netinet/udp_usrreq.c:1162
db> show malloc
Type InUse MemUse Requests
pf_hash 6 12804K 6
linker 377 5100K 487
tcp_hpts 7 4801K 7
devbuf 4187 4323K 4212
sysctloid 35125 2069K 35200
vtbuf 24 1968K 46
newblk 1886 1496K 1936
kobj 331 1324K 495
vfscache 3 1025K 3
pcb 23 669K 46
inodedep 87 545K 110
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
vnet_data 2 224K 2
acpitask 1 224K 1
subproc 112 206K 903
KTRACE 100 200K 100
acpica 1674 184K 54444
vmem 5 144K 7
tidhash 3 141K 3
pagedep 44 139K 53
tfo_ccache 1 128K 1
IP reass 1 128K 1
sem 4 106K 4
DEVFS1 103 103K 117
gtaskqueue 18 98K 18
bus 1000 82K 5086
mtx_pool 3 74K 3
syncache 1 68K 1
NFSD srvcache 3 68K 3
module 523 66K 523
ddb_capture 1 64K 1
filedesc 5 37K 87
umtx 272 34K 272
kdtrace 167 34K 972
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 122 31K 133
msg 4 30K 4
kbdmux 6 28K 6
temp 19 21K 1785
DEVFS_RULE 56 20K 56
BPF 11 18K 12
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 90 15K 90
bus-sc 34 15K 1657
eventhandler 163 14K 163
ifaddr 39 13K 50
kenv 95 12K 95
routetbl 79 12K 309
GEOM 49 11K 431
CAM queue 5 11K 1528
rman 82 10K 437
rpc 8 9K 8
cred 23 9K 277
bmsafemap 3 9K 77
devstat 4 9K 4
UART 12 9K 12
ksem 1 8K 1
mkdir 64 8K 86
shmfd 1 8K 1
pfs_vncache 1 8K 1
audit_evclass 240 8K 304
plimit 20 8K 438
taskqueue 69 8K 69
diradd 56 7K 74
ifnet 4 7K 5
sglist 6 7K 6
LRO 6 7K 8
CAM DEV 3 6K 510
lltable 19 6K 27
kqueue 48 6K 841
dirrem 22 6K 35
pfs_nodes 22 6K 22
ether_multi 68 6K 106
ufs_dirhash 24 5K 24
UMA 268 5K 268
in6_multi 35 5K 45
newdirblk 34 5K 43
vt 11 5K 11
pf_ifnet 9 4K 16
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
acpisem 28 4K 28
pwddesc 45 3K 836
proc-args 73 3K 1881
terminal 11 3K 11
session 21 3K 46
acpidev 20 3K 20
hhook 8 3K 10
clone 9 3K 9
uidinfo 3 3K 9
netlink 2 3K 60
selfd 33 3K 28912
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
lockf 18 2K 25
Unitno 28 2K 50
CAM XPT 22 2K 543
toponodes 6 2K 6
ipsecpolicy 2 2K 2
select 10 2K 34
msi 9 2K 9
softdep 1 1K 1
indirdep 4 1K 4
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 8
NFSD session 1 1K 1
ip6ndp 6 1K 9
sctp_ifa 7 1K 10
CAM periph 4 1K 271
ipsec 3 1K 3
CC Mem 6 1K 13
in_multi 3 1K 6
nhops 6 1K 6
pfil 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
freefile 5 1K 14
crypto 4 1K 4
encap_export_host 12 1K 12
osd 11 1K 30
cdev 2 1K 2
lkpikmalloc 8 1K 9
inpcbpolicy 14 1K 166
counter_rate 13 1K 13
sctp_ifn 3 1K 10
mld 3 1K 4
igmp 3 1K 4
tun 1 1K 2
chacha20random 1 1K 1
biobuf 1 1K 1
DEVFSP 5 1K 41
vnodes 1 1K 1
procdesc 2 1K 8
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
cryptodev 2 1K 49
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
pmchooks 1 1K 1
CAM path 4 1K 1034
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 3356
filecaps 4 1K 70
sctp_vrf 1 1K 1
vnet 1 1K 1
pmc 1 1K 1
entropy 2 1K 54
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
freework 1 1K 31
p1003.1b 1 1K 1
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 9
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 0
sctp_atky 0 0K 0
sctp_atcl 0 0K 0
sctp_a_it 0 0K 9
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
mqdata 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
filemon 0 0K 0
tcp_pcm_rack 0 0K 0
tcp_do_rack 0 0K 0
tcp_fsb_rack 0 0K 0
savedino 0 0K 15
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 2
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freeblks 0 0K 30
freefrag 0 0K 32
ipsec-misc 0 0K 2
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 19
fadvise 0 0K 0
VN POLL 0 0K 0
statfs 0 0K 196
namei_tracker 0 0K 0
inotify 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 31
aio 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
accf 0 0K 0
pts 0 0K 0
timerfd 0 0K 0
iov 0 0K 15192
ioctlops 0 0K 92
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
sbuf 0 0K 288
firmware 0 0K 0
compressor 0 0K 0
SWAP 0 0K 0
sysctltmp 0 0K 669
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
cache 0 0K 0
kcovinfo 0 0K 30
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
boottrace 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
tcp_log_dev 0 0K 0
md_disk 0 0K 0
mbuf_jumbo_page 4096 8320 1078 24616 0 254 38494208 0
mbuf 256 8586 1076 32584 0 254 2473472 0
tcp_log 416 611 4474 9034 0 254 2115360 0
BUF TRIE 152 293 11511 1027 0 62 1794208 0
malloc-384 384 4206 24 4219 0 30 1624320 0
malloc-128 128 12384 109 12462 0 126 1599104 0
malloc-4096 4096 388 2 1354 0 2 1597440 0
UMA Slabs 0 112 10910 28 10910 0 126 1225056 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
malloc-65536 65536 13 1 16 0 1 917504 0
vmem btag 56 16278 105 16278 0 254 917448 0
RADIX NODE 152 4430 739 27728 0 62 785688 0
FFS inode 1168 550 10 564 0 8 654080 0
socket 1024 26 482 1364 0 254 520192 0
lkpicurr 168 2 3094 2 0 62 520128 0
malloc-256 256 1945 50 2158 0 62 510720 0
pbuf 2624 0 194 0 0 2 509056 0
256 Bucket 2048 128 8 948 0 8 278528 0
VM OBJECT 248 1039 81 13674 0 62 277760 0
VNODE 440 583 47 600 0 30 277200 0
malloc-64 64 3895 200 32786 0 254 262080 0
THREAD 1860 121 15 135 0 8 252960 0
malloc-2048 2048 7 113 514 0 8 245760 0
malloc-16 16 14478 272 14546 0 254 236000 0
malloc-2048 2048 104 8 125 0 8 229376 0
DEVCTL 1024 14 206 141 0 0 225280 0
UMA Zones 768 240 4 240 0 16 187392 0
malloc-32 32 5334 336 6393 0 254 181440 0
malloc-128 128 1135 260 25529 0 126 178560 0
lkpimm 56 1 3095 1 0 254 173376 0
unpcb 320 11 505 1177 0 254 165120 0
FFS2 dinode 256 550 80 564 0 62 161280 0
S VFS Cache 104 1019 268 1064 0 126 133848 0
MAP ENTRY 96 1049 337 42626 0 126 133056 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 52 0 1 131072 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 110 0 1 131072 0
malloc-32768 32768 4 0 4 0 1 131072 0
malloc-1024 1024 114 14 133 0 16 131072 0
mbuf_packet 256 0 508 161 0 254 130048 0
FPU_save_area 832 123 21 12628 0 16 119808 0
ksiginfo 112 38 1006 12507 0 126 116928 0
malloc-32768 32768 2 1 122 0 1 98304 0
malloc-16384 16384 2 4 233 0 1 98304 0
PROC 1368 44 22 835 0 8 90288 0
UMA Kegs 384 227 6 227 0 30 89472 0
128 Bucket 1024 47 36 342 0 16 84992 0
malloc-64 64 512 559 1554 0 254 68544 0
malloc-128 128 338 189 414 0 126 67456 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-32768 32768 0 2 11 0 1 65536 0
malloc-16384 16384 4 0 5 0 1 65536 0
malloc-8192 8192 7 1 33 0 1 65536 0
64 Bucket 512 73 55 2263 0 30 65536 0
g_bio 408 0 150 5055 0 30 61200 0
filedesc0 1072 45 11 836 0 8 60032 0
malloc-384 384 110 40 388 0 30 57600 0
malloc-4096 4096 13 1 18 0 2 57344 0
malloc-64 64 466 353 671 0 254 52416 0
malloc-128 128 159 244 642 0 126 51584 0
malloc-256 256 147 48 475 0 62 49920 0
malloc-256 256 101 94 495 0 62 49920 0
malloc-256 256 69 126 202 0 62 49920 0
malloc-256 256 149 46 212 0 62 49920 0
32 Bucket 256 57 138 553 0 62 49920 0
DIRHASH 1024 34 14 34 0 16 49152 0
NAMEI 1024 0 48 12926 0 16 49152 0
malloc-8192 8192 6 0 7 0 1 49152 0
malloc-8192 8192 5 1 7 0 1 49152 0
malloc-2048 2048 10 14 27 0 8 49152 0
malloc-2048 2048 1 23 574 0 8 49152 0
malloc-1024 1024 5 43 1490 0 16 49152 0
malloc-384 384 75 45 80 0 30 46080 0
syncache 168 0 264 6 0 254 44352 0
clpbuf 2624 0 16 72 0 4 41984 0
VMSPACE 584 29 41 821 0 16 40880 0
pcpu-8 8 4447 161 4653 0 254 36864 0
udp_inpcb 408 7 83 149 0 30 36720 0
malloc-64 64 241 326 15186 0 254 36288 0
malloc-64 64 240 327 2426 0 254 36288 0
malloc-64 64 7 560 53 0 254 36288 0
malloc-64 64 97 470 1138 0 254 36288 0
malloc-128 128 26 253 83 0 126 35712 0
malloc-128 128 50 229 3308 0 126 35712 0
malloc-128 128 113 166 833 0 126 35712 0
malloc-128 128 106 173 228 0 126 35712 0
routing nhops 256 14 121 25 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-256 256 48 87 752 0 62 34560 0
malloc-256 256 37 98 129 0 62 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-4096 4096 5 3 7 0 2 32768 0
malloc-4096 4096 4 4 558 0 2 32768 0
malloc-2048 2048 5 11 18 0 8 32768 0
malloc-2048 2048 5 11 44 0 8 32768 0
malloc-1024 1024 2 30 42 0 16 32768 0
malloc-1024 1024 6 26 21 0 16 32768 0
malloc-1024 1024 3 29 170 0 16 32768 0
malloc-1024 1024 18 14 22 0 16 32768 0
malloc-1024 1024 18 14 18 0 16 32768 0
malloc-1024 1024 1 31 6 0 16 32768 0
malloc-512 512 10 54 120 0 30 32768 0
malloc-512 512 5 59 10 0 30 32768 0
malloc-512 512 1 63 16 0 30 32768 0
malloc-512 512 2 62 8 0 30 32768 0
malloc-512 512 2 62 49 0 30 32768 0
malloc-512 512 1 63 17 0 30 32768 0
pcpu-64 64 499 13 499 0 254 32768 0
ertt_txseginfo 40 1 807 633 0 254 32320 0
ttyinq 160 135 65 300 0 62 32000 0
PGRP 120 22 242 62 0 126 31680 0
sctp_laddr 48 0 588 10 0 254 28224 0
16 Bucket 144 49 147 335 0 62 28224 0
4 Bucket 48 8 580 14 0 254 28224 0
da_ccb 544 0 49 1494 0 16 26656 0
TURNSTILE 136 137 52 137 0 62 25704 0
cpuset 200 7 121 7 0 62 25600 0
malloc-8192 8192 1 2 82 0 1 24576 0
malloc-4096 4096 1 5 233 0 2 24576 0
pipe 736 10 23 338 0 16 24288 0
PWD 40 13 593 130 0 254 24240 0
rtentry 168 17 127 25 0 62 24192 0
Files 80 97 203 7041 0 126 24000 0
8 Bucket 80 54 246 569 0 126 24000 0
tcp_inpcb 1304 6 12 13 0 8 23472 0
malloc-384 384 7 53 7 0 30 23040 0
malloc-384 384 2 58 2 0 30 23040 0
malloc-384 384 0 60 343 0 30 23040 0
malloc-384 384 30 30 453 0 30 23040 0
malloc-384 384 2 58 24 0 30 23040 0
ripcb 376 1 59 4 0 30 22560 0
Mountpoints 2816 2 6 2 0 4 22528 0
SLEEPQUEUE 88 137 119 137 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
ertt 72 6 274 13 0 126 20160 0
malloc-64 64 11 304 75 0 254 20160 0
malloc-32 32 254 376 410 0 254 20160 0
malloc-32 32 122 508 163 0 254 20160 0
malloc-32 32 104 526 629 0 254 20160 0
malloc-32 32 50 580 983 0 254 20160 0
malloc-32 32 51 579 76 0 254 20160 0
malloc-32 32 63 567 241 0 254 20160 0
malloc-32 32 38 592 2710 0 254 20160 0
2 Bucket 32 54 576 318 0 254 20160 0
KNOTE 160 6 119 140 0 62 20000 0
malloc-256 256 4 71 326 0 62 19200 0
vmem 1856 2 7 2 0 8 16704 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-8192 8192 0 2 19 0 1 16384 0
malloc-4096 4096 1 3 9 0 2 16384 0
malloc-4096 4096 2 2 3 0 2 16384 0
malloc-2048 2048 4 4 4 0 8 16384 0
malloc-2048 2048 2 6 195 0 8 16384 0
malloc-512 512 1 31 2 0 30 16384 0
SMR CPU 32 8 503 8 0 254 16352 0
kenv 258 17 43 1066 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
SMR SHARED 24 8 503 8 0 254 12264 0
malloc-16 16 10 740 29 0 254 12000 0
malloc-16 16 57 693 220 0 254 12000 0
malloc-16 16 55 695 266 0 254 12000 0
malloc-16 16 185 565 3024 0 254 12000 0
malloc-16 16 9 741 9 0 254 12000 0
malloc-16 16 297 453 1626 0 254 12000 0
malloc-16 16 15 735 24812 0 254 12000 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
pcpu-16 16 8 504 8 0 254 8192 0
vtnet_tx_hdr 24 1 333 6371 0 254 8016 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 152 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf fragment node 72 0 0 0 0 126 0 0
pf frags 232 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf Ethernet anchors 1240 0 0 0 0 64 0 0
pf anchors 1664 0 0 0 0 64 0 0
pf UDP mappings 104 0 0 0 0 126 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 384 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_bbr_pcb 896 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tcp_rack_pcb 1088 0 0 0 0 8 0 0
tcp_rack_map 128 0 0 0 0 126 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2256 0 0 0 0 254 0 0
sctp_ep 1152 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcpreass 48 0 0 0 0 254 0 0
udplite_inpcb 408 0 0 0 0 30 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIO 208 0 0 0 0 62 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
TMPFS node 240 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 152 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 112 0 0 0 0 126 0 0
skbuff 1808 0 0 0 0 8 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 16 0 0
nfspbuf 2624 0 0 0 0 4 0 0
swwbuf 2624 0 0 0 0 2 0 0
swrbuf 2624 0 0 0 0 4 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 152 0 0 0 0 62 0 0
rl_entry 48 0 0 0 0 254 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
m

---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages