kernel: page fault trap, code=NUM (2)

0 views
Skip to first unread message

syzbot

unread,
May 5, 2023, 7:48:51 AM5/5/23
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e253a7cc21de symbols.awk: Remove cfb dance
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17a48b04280000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=fff03b887db0f5f0c2d1

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0653cd8cd1af/disk-e253a7cc.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/5952fb033bfc/bsd-e253a7cc.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c3ac6e183439/kernel-e253a7cc.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+fff03b...@syzkaller.appspotmail.com

PROC (kernel: page fault trap, code=0
Faulted in DDB; continuing...
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10174 6412K 6668K 78643K 11759 0
pcb 13 16K 18K 78643K 390 0
rtable 159 14K 15K 78643K 1316 0
ifaddr 61 18K 21K 78643K 269 0
sysctl 2 0K 0K 78643K 2 0
counters 25 17K 17K 78643K 155 0
ioctlops 0 0K 2K 78643K 188 0
iov 0 0K 12K 78643K 167 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1472 92K 92K 78643K 3231 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 17 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 363 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 14 49K 69K 78643K 1888 0
sigio 0 0K 0K 78643K 41 0
proc 52 42K 75K 78643K 645 0
subproc 104 6K 6K 78643K 156 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 373 0
in_multi 57 3K 6K 78643K 192 0
ether_multi 1 0K 0K 78643K 16 0
mrt 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 163 731K 731K 78643K 163 0
exec 0 0K 1K 78643K 785 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 8 62K 64K 78643K 10 0
UVM amap 289 83K 85K 78643K 19776 0
UVM aobj 131 4K 4K 78643K 143 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 113 0
NDP 12 0K 2K 78643K 87 0
temp 120 5850K 6878K 78643K 40106 0
kqueue 6 10K 24K 78643K 180 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 1696 0 1695 12 10 2 5 0 8 1
rtentry 112 173 0 107 4 0 4 4 0 8 0
unpcb 144 3547 0 3541 23 17 6 10 0 8 5
syncache 296 15 0 15 4 3 1 1 0 8 1
tcpqe 32 149 0 149 3 2 1 1 0 8 1
tcpcb 776 943 0 939 34 26 8 14 0 8 7
arp 88 26 0 14 1 0 1 1 0 8 0
ipq 40 2 0 1 1 0 1 1 0 8 0
ipqe 40 7 0 6 1 0 1 1 0 8 0
inpcb 336 2450 0 2446 35 26 9 18 0 8 8
nd6 104 36 0 21 1 0 1 1 0 8 0
pkpcb 40 9 0 9 1 1 0 1 0 8 0
kcovpl 48 12 0 4 1 0 1 1 0 8 0
mppekey 1024 4 0 4 1 1 0 1 0 8 0
ppxss 1160 99 0 99 4 3 1 1 0 8 1
ppxss: pool(0xffffffff82cf14e0:ppxss): page inconsistency: page 0x0; at page head addr 0xffff800023153f90 (p 0xffff800023150000)
pppxif 1360 11 0 11 2 2 0 1 0 8 0
pfstscr 40 3 0 2 1 0 1 1 0 8 0
pfanchor 1288 887 46 375 43 0 43 43 0 8 0
pfqueue 264 3 0 3 1 1 0 1 0 8 0
pfstitem 24 2 0 0 1 0 1 1 0 8 0
pfstkey 128 6 0 4 1 0 1 1 0 8 0
pfstate 352 3 0 2 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 781 0 522 29 9 20 29 0 8 0
art_table 32 782 0 522 4 0 4 4 0 8 0
art_node 16 170 0 114 1 0 1 1 0 8 0
sysvmsgpl 40 53 0 13 1 0 1 1 0 8 0
semapl 112 361 0 351 1 0 1 1 0 8 0
shmpl 112 140 0 12 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dirhash: pool(0xffffffff82cc5f00:dirhash): free list modified: page 0xffff80002167f000; item ordinal 0; addr 0xffff800021680000 (p 0xfffffd806fd82000); offset 0x0=0x0
pool(dirhash): free list modified: page 0xffff80002167f000; item ordinal 0; addr 0xffff800021680000 (p 0xfffffd806fd82000); offset 0x0=0x0
dirhash: pool(0xffffffff82cc5f00:dirhash): page inconsistency: page 0xffff80002167f000; item ordinal 1; addr 0xd9e9e64c8617f81e
dino2pl 256 4372 0 2938 91 0 91 91 0 8 0
ffsino 240 4372 0 2938 85 0 85 85 0 8 0
nchpl 144 7175 0 6686 63 41 22 63 0 8 0
rtmask 32 2 0 2 1 0 1 1 0 8 1
uvmvnodes 80 5688 0 0 117 0 117 117 0 8 0
vnodes 216 5688 0 0 316 0 316 316 0 8 0
namei 1024 26322 0 26322 3 2 1 3 0 8 1
namei: pool(0xffffffff82c0fad0:namei): free list modified: page 0xffff8000216cb000; item ordinal 0; addr 0xffff8000216cb000 (p 0xfffffd806ac30000); offset 0x0=0x0
pool(namei): free list modified: page 0xffff8000216cb000; item ordinal 0; addr 0xffff8000216cb000 (p 0xfffffd806ac30000); offset 0x0=0x0
namei: pool(0xffffffff82c0fad0:namei): page inconsistency: page 0xffff8000216cb000; item ordinal 1; addr 0x58580e3f81eea9a6
kstatmem 264 126 0 106 2 0 2 2 0 8 0
scxspl 216 19969 0 19969 11 10 1 8 0 8 1
plimitpl 152 284 0 270 1 0 1 1 0 8 0
sigapl 424 2198 0 2138 8 0 8 8 0 8 0
futexpl 64 21630 0 21630 1 0 1 1 0 8 1
knotepl 120 23380 0 23316 20 16 4 11 0 8 0
kqueuepl 184 409 0 404 5 4 1 4 0 8 0
pipepl 288 626 0 598 9 4 5 5 0 8 2
fdescpl 432 2160 0 2138 4 1 3 4 0 8 0
filepl 120 20781 0 20565 34 21 13 21 0 8 5
lockfpl 104 494 0 493 2 1 1 2 0 8 0
lockfspl 48 117 0 116 1 0 1 1 0 8 0
sessionpl 144 27 0 12 1 0 1 1 0 8 0
pgrppl 48 110 0 95 1 0 1 1 0 8 0
ucredpl 104 3081 0 3073 1 0 1 1 0 8 0
zombiepl 144 2138 0 2138 1 0 1 1 0 8 1
processpl 1008 2198 0 2138 11 2 9 9 0 8 1
processpl: pool(0xffffffff82c11b78:processpl): page inconsistency: page 0x0; at page head addr 0xffff8000216eff90 (p 0xffff8000216ee000)
processpl: pool(0xffffffff82c11b78:processpl): page inconsistency: page 0x0; at page head addr 0xffff8000299f1f90 (p 0xffff8000299f0000)
procpl 696 5105 0 5029 13 3 10 10 0 8 1
procpl: pool(0xffffffff82c119d0:procpl): page inconsistency: page 0x0; at page head addr 0xffff800024b8bf90 (p 0xffff800024b8a000)
procpl: pool(0xffffffff82c119d0:procpl): page inconsistency: page 0x0; at page head addr 0xffff8000216f1f90 (p 0xffff8000216f0000)
procpl: pool(0xffffffff82c119d0:procpl): page inconsistency: page 0x0; at page head addr 0xffff800023133f90 (p 0xffff800023132000)
sosppl 168 12 0 12 2 2 0 1 0 8 0
sockpl 456 7703 0 7692 156 144 12 42 0 8 10
mcl64k 65536 111 0 111 3 2 1 1 0 8 1
mcl16k 16384 45 0 45 4 3 1 1 0 8 1
mcl12k 12288 66 0 66 1 0 1 1 0 8 1
mcl9k 9216 22 0 22 2 2 0 1 0 8 0
mcl8k 8192 141 0 141 2 1 1 1 0 8 1
mcl4k 4096 249 0 249 1 0 1 1 0 8 1
mcl2k2 2112 11 0 11 5 4 1 1 0 8 1
mcl2k 2048 78244 0 78203 34 27 7 31 0 8 0
mtagpl 96 15 0 15 2 1 1 1 0 8 1
mbufpl 256 172702 0 172600 1102 1082 20 574 0 8 8
bufpl 288 7081 0 696 457 0 457 457 0 8 0
anonpl 24 375090 0 363084 108 8 100 103 0 188 0
amapchunkpl 152 64445 0 63676 47 10 37 45 0 158 1
amappl16 200 9322 0 8836 36 9 27 30 0 8 0
amappl15 192 24 0 22 1 0 1 1 0 8 0
amappl14 184 167 0 157 2 1 1 2 0 8 0
amappl13 176 18 0 18 1 1 0 1 0 8 0
amappl12 168 2840 0 2818 2 0 2 2 0 8 0
amappl11 160 53 0 49 1 0 1 1 0 8 0
amappl10 152 30 0 21 2 1 1 1 0 8 0
amappl9 144 183 0 182 2 1 1 2 0 8 0
amappl8 136 207 0 147 3 0 3 3 0 8 0
amappl7 128 73 0 59 1 0 1 1 0 8 0
amappl6 120 292 0 277 2 1 1 2 0 8 0
amappl5 112 183 0 180 1 0 1 1 0 8 0
amappl4 104 640 0 610 2 1 1 2 0 8 0
amappl3 96 12681 0 12622 3 0 3 3 0 8 0
amappl2 88 2441 0 2398 4 2 2 3 0 8 0
amappl1 80 16511 0 16109 22 12 10 22 0 8 0
amappl 88 19200 0 19011 6 0 6 6 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 142 0 12 3 0 3 3 0 8 0
uaddrrnd 24 2160 0 2138 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 2160 0 2138 1 0 1 1 0 8 0
vmmpekpl 168 22161 0 22116 3 0 3 3 0 8 0
vmmpepl 168 150783 0 148857 146 35 111 130 0 357 14
vmsppl 360 2159 0 2138 3 0 3 3 0 8 1
rwobjpl 24 48999 0 41874 44 0 44 44 0 8 1
pdppl 4096 4326 0 4276 190 138 52 66 0 8 2
pvpl 32 848571 0 832269 334 70 264 334 0 265 94
pmappl 216 2159 0 2138 2 0 2 2 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 2055 0 1299 37 5 32 37 0 8 6
ddb> machine ddbcpu 0
No such command
ddb> trace
end trace frame: 0x0, count: -1
ddb> machine ddbcpu 1
No such command
ddb> trace
end trace frame: 0x0, count: -1


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 3, 2023, 7:48:37 AM8/3/23
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages