Hello,
syzbot found the following issue on:
HEAD commit: 2610791609b5 sndiod: In the CTL_SW case, the third ctl_new..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=17867132580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link:
https://syzkaller.appspot.com/bug?extid=e9f225d9edbd542f75ea
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/df7cabe729ab/disk-26107916.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/73cfaba04525/bsd-26107916.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/ef4b7f508cad/kernel-26107916.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+e9f225...@syzkaller.appspotmail.com
uvm_fault(0xffffef006cee7b88, 0x98, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at dovutimens+0x368: movl 0x98(%rax),%r12d
--db_more-- TID PID UID PRFLAGS PFLAGS CPU COMMAND
--db_more-- 215644 41979 0 0 0 0 syz-executor
--db_more-- *401571 8828 0 0 0x4000000 1K syz-executor
--db_more-- dovutimens(ffff80003c3b8a80,ffffef006014ea20,ffff800039f979e0) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
--db_more-- sys_futimes(ffff80003c3b8a80,ffff800039f97b30,ffff800039f97a80) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff800039f97b30) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff800039f97b30) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
--db_more-- end trace frame: 0x3f3bd61d660, count: 11
--db_more--
https://www.openbsd.org/ddb.html describes the minimum info required in bug
--db_more-- reports. Insufficient info makes it difficult to find and fix bugs.
ddb{1}> nes = 0
No such command
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
*cpu1: uvm_fault(0xffffef006cee7b88, 0x98, 0, 1) -> e
ddb{1}> show kasan
No such command
ddb{1}> trace
dovutimens(ffff80003c3b8a80,ffffef006014ea20,ffff800039f979e0) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
sys_futimes(ffff80003c3b8a80,ffff800039f97b30,ffff800039f97a80) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff800039f97b30) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff800039f97b30) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
--db_more-- Xsyscall() at Xsyscall+0x128
--db_more-- end of kernel
--db_more-- end trace frame: 0x3f3bd61d660, count: -4
ddb{1}> w registers
Symbol not found
ddb{1}> show proc
PROC (syz-executor) tid=401571 pid=8828 tcnt=2 stat=onproc
flags process=0 proc=4000000<THREAD>
runpri=32, usrpri=50, slppri=32, nice=20
--db_more-- wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
--db_more-- forw=0xffffffffffffffff, list=0xffff80003c3b9778,0xffff80003c3b9cb8
--db_more-- process=0xffff80002a37d358 user=0xffff800039f92000, vmspace=0xffffef006cee7b88
--db_more-- estcpu=36, cpticks=1, pctcpu=0.0, user=0, sys=1, intr=0
ddb{1}> how all locks
No such command
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11078 12162K 12286K 166960K 12324 0
pcb 17 12K 12K 166960K 47 0
--db_more-- rtable 204 16K 18K 166960K 394 0
--db_more-- pf 41 19K 22K 166960K 78 0
--db_more-- ifaddr 37 6K 7K 166960K 51 0
--db_more-- ifgroup 59 2K 2K 166960K 73 0
--db_more-- sysctl 3 1K 9K 166960K 8 0
counters 72 37K 38K 166960K 84 0
ioctlops 0 0K 4K 166960K 1548 0
iov 0 0K 16K 166960K 6 0
--db_more-- mount 1 1K 1K 166960K 1 0
--db_more-- log 0 0K 0K 166960K 4 0
--db_more-- vnodes 1357 85K 86K 166960K 1622 0
--db_more-- UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 1K 166960K 2 0
VM map 2 1K 1K 166960K 2 0
--db_more-- sem 8 0K 0K 166960K 15 0
--db_more-- dirhash 12 2K 2K 166960K 12 0
--db_more-- ACPI 1734 201K 291K 166960K 11964 0
--db_more-- file desc 18 65K 89K 166960K 275 0
--db_more-- sigio 0 0K 0K 166960K 4 0
--db_more-- proc 72 115K 164K 166960K 560 0
--db_more-- subproc 72 4K 4K 166960K 72 0
--db_more-- NFS srvsock 1 0K 0K 166960K 1 0
--db_more-- ddb{1}> hine ddbcpu 0
No such command
ddb{1}> trace
dovutimens(ffff80003c3b8a80,ffffef006014ea20,ffff800039f979e0) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
sys_futimes(ffff80003c3b8a80,ffff800039f97b30,ffff800039f97a80) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff800039f97b30) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff800039f97b30) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
--db_more-- Xsyscall() at Xsyscall+0x128
--db_more-- end of kernel
--db_more-- ddb{1}> hine ddbcpu 1
No such command
ddb{1}> trace
dovutimens(ffff80003c3b8a80,ffffef006014ea20,ffff800039f979e0) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
sys_futimes(ffff80003c3b8a80,ffff800039f97b30,ffff800039f97a80) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff800039f97b30) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff800039f97b30) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup