Fatal trap 12: page fault in __mtx_assert

3 views
Skip to first unread message

syzbot

unread,
Mar 23, 2019, 4:31:05 AM3/23/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 0d79d351 pf tests: Fix accidental duplication of content
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1078bd93200000
dashboard link: https://syzkaller.appspot.com/bug?extid=179a1ad49f3c4c215fa2

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+179a1a...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0x80
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff8103c6f9
stack pointer = 0x28:0xfffffe002131c5e0
frame pointer = 0x28:0xfffffe002131c610
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 3521 (syz-executor.2)
trap number = 12
panic: page fault
cpuid = 0
time = 196
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe002131c240
vpanic() at vpanic+0x1e0/frame 0xfffffe002131c2a0
panic() at panic+0x43/frame 0xfffffe002131c300
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe002131c380
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe002131c3f0
trap() at trap+0x44d/frame 0xfffffe002131c510
calltrap() at calltrap+0x8/frame 0xfffffe002131c510
--- trap 0xc, rip = 0xffffffff8103c6f9, rsp = 0xfffffe002131c5e0, rbp =
0xfffffe002131c610 ---
__mtx_assert() at __mtx_assert+0xb9/frame 0xfffffe002131c610
tcp_log_set_id() at tcp_log_set_id+0x819/frame 0xfffffe002131c680
tcp_default_ctloutput() at tcp_default_ctloutput+0x13a4/frame
0xfffffe002131c7d0
tcp_ctloutput() at tcp_ctloutput+0x30f/frame 0xfffffe002131c850
sosetopt() at sosetopt+0x101/frame 0xfffffe002131c8d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe002131c950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe002131c980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe002131cab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe002131cab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e7a, rsp =
0x7fffdffdcf38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 3521 tid 100602 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 23, 2019, 4:48:06 AM3/23/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 0d79d351 pf tests: Fix accidental duplication of content
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1020f1df200000
dashboard link: https://syzkaller.appspot.com/bug?extid=179a1ad49f3c4c215fa2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1003dbef200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+179a1a...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x80
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff8103c6f9
stack pointer = 0x28:0xfffffe002126d5e0
frame pointer = 0x28:0xfffffe002126d610
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 772 (syz-executor.0)
trap number = 12
panic: page fault
cpuid = 1
time = 1553330658
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe002126d240
vpanic() at vpanic+0x1e0/frame 0xfffffe002126d2a0
panic() at panic+0x43/frame 0xfffffe002126d300
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe002126d380
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe002126d3f0
trap() at trap+0x44d/frame 0xfffffe002126d510
calltrap() at calltrap+0x8/frame 0xfffffe002126d510
--- trap 0xc, rip = 0xffffffff8103c6f9, rsp = 0xfffffe002126d5e0, rbp =
0xfffffe002126d610 ---
__mtx_assert() at __mtx_assert+0xb9/frame 0xfffffe002126d610
tcp_log_set_id() at tcp_log_set_id+0x819/frame 0xfffffe002126d680
tcp_default_ctloutput() at tcp_default_ctloutput+0x13a4/frame
0xfffffe002126d7d0
tcp_ctloutput() at tcp_ctloutput+0x30f/frame 0xfffffe002126d850
sosetopt() at sosetopt+0x101/frame 0xfffffe002126d8d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe002126d950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe002126d980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe002126dab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe002126dab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e7a, rsp =
0x7fffdffdcf38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 772 tid 100118 ]
Reply all
Reply to author
Forward
0 new messages