uvm_fault: mtx_enter (2)

0 views
Skip to first unread message

syzbot

unread,
1:52 AM (20 hours ago) 1:52 AM
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3b8d610e537f correct test for non-NULL; ok ratchov@
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=168f5949580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=7f40bdbe49b65a32f7c8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e61ff1630a1c/disk-3b8d610e.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/69a7e2100836/bsd-3b8d610e.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/6821d3f95ab5/kernel-3b8d610e.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7f40bd...@syzkaller.appspotmail.com

uvm_fault(0xfffff1006d17b5d0, 0x17e9, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at mtx_enter+0x6e: movq 0(%r14),%r15
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*416340 46842 0 0 0x4000000 0 syz-executor
mtx_enter(17e9) at mtx_enter+0x6e sys/kern/kern_lock.c:549
disk_unbusy(17b9,4000,65560,0) at disk_unbusy+0x4e sys/kern/subr_disk.c:1254
sd_buf_done(fffff10061087b20) at sd_buf_done+0x2ab sys/scsi/sd.c:768
vioscsi_vq_done(ffff8000000a3618) at vioscsi_vq_done+0xe1 sys/dev/pv/vioscsi.c:-1
intr_handler(ffff80002a851220,ffff8000002a2400) at intr_handler+0xcb sys/arch/amd64/amd64/intr.c:-1
Xintr_ioapic_edge23_untramp() at Xintr_ioapic_edge23_untramp+0x18f
Xspllower() at Xspllower+0x1d
softintr_dispatch(0) at softintr_dispatch+0xe3 sys/kern/kern_softintr.c:-1
dosoftint(0) at dosoftint+0x48 sys/arch/amd64/amd64/intr.c:862
Xsoftclock() at Xsoftclock+0x27
malloc(1,7f,9) at malloc+0xb94 sys/kern/kern_malloc.c:352
sysctl_sysvipc(ffff80002a8517b8,1,200000000100,ffff80002a8517e8) at sysctl_sysvipc+0x461 sys/kern/kern_sysctl.c:2766
kern_sysctl(ffff80002a8517b4,2,200000000100,ffff80002a8517e8,0,27,1e1364000e3d942e) at kern_sysctl+0x139 sys/kern/kern_sysctl.c:736
sys_sysctl(ffff80003c8fb248,ffff80002a851910,ffff80002a851860) at sys_sysctl+0x3e5 sys/kern/kern_sysctl.c:-1
end trace frame: 0xffff80002a851900, count: 0
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages