uvm_fault: ifiq_enqueue_qlim

2 views
Skip to first unread message

syzbot

unread,
Jul 28, 2026, 4:25:29 PMJul 28
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e63b2cdac76f remove unneeded includes
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17f7249e580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=ee424ec1e507e1e118b3

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/90965ad17d81/disk-e63b2cda.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/6e3a33748f4d/bsd-e63b2cda.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/64fc945b330c/kernel-e63b2cda.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ee424e...@syzkaller.appspotmail.com

uvm_fault(0xffffffff83abb7c8, 0x0, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at ifiq_enqueue_qlim+0x39: movq 0(%r15),%rax
TID PID UID PRFLAGS PFLAGS CPU COMMAND
* 72033 64592 0 0x14000 0x200 0 softnet0
ifiq_enqueue_qlim(0,fffffc006f9ac000,2000) at ifiq_enqueue_qlim+0x39 sys/net/ifq.c:800
if_output_local(ffff800000c48000,fffffc006f9ac000,18) at if_output_local+0xae sys/net/if.c:1011
if_output_tso(ffff800000c48000,ffff80002a70ba58,ffff80002a70b990,fffffc006fd7ecc0,8000) at if_output_tso+0x200 sys/net/if.c:-1
ip6_output(fffffc006f9ac000,0,0,0,0,0) at ip6_output+0x1e68 sys/netinet6/ip6_output.c:664
ip6_send_dispatch(ffffffff83ad72f8) at ip6_send_dispatch+0xb4 sys/netinet6/ip6_input.c:1563
taskq_thread(ffff80000002c000) at taskq_thread+0xe4 sys/kern/kern_task.c:446
end trace frame: 0x0, count: 9
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
*cpu0: uvm_fault(0xffffffff83abb7c8, 0x0, 0, 1) -> e
ddb> show kasan
No such command
ddb> trace
ifiq_enqueue_qlim(0,fffffc006f9ac000,2000) at ifiq_enqueue_qlim+0x39 sys/net/ifq.c:800
if_output_local(ffff800000c48000,fffffc006f9ac000,18) at if_output_local+0xae sys/net/if.c:1011
if_output_tso(ffff800000c48000,ffff80002a70ba58,ffff80002a70b990,fffffc006fd7ecc0,8000) at if_output_tso+0x200 sys/net/if.c:-1
ip6_output(fffffc006f9ac000,0,0,0,0,0) at ip6_output+0x1e68 sys/netinet6/ip6_output.c:664
ip6_send_dispatch(ffffffff83ad72f8) at ip6_send_dispatch+0xb4 sys/netinet6/ip6_input.c:1563
taskq_thread(ffff80000002c000) at taskq_thread+0xe4 sys/kern/kern_task.c:446
end trace frame: 0x0, count: -6
ddb> show registers
rdi 0
rsi 0xfffffc006f9ac000
rbp 0xffff80002a70b880
rbx 0x18
rdx 0
rcx 0xffff80000002e4b0
rax 0xffff80002a6ec530
r8 0x600fa00 __kernel_phys_end+0x240fa00
r9 0x8000 __ALIGN_SIZE+0x7000
r10 0x273722e9a4685552
r11 0xf102d48d420e8069
r12 0x2000 __ALIGN_SIZE+0x1000
r13 0
r14 0xfffffc006f9ac000
r15 0
rip 0xffffffff83322e29 ifiq_enqueue_qlim+0x39
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80002a70b830
ss 0x10
ifiq_enqueue_qlim+0x39: movq 0(%r15),%rax
ddb> show proc
PROC (softnet0) tid=72033 pid=64592 tcnt=1 stat=onproc
flags process=14000<NOZOMBIE,SYSTEM> proc=200<SYSTEM>
runpri=32, usrpri=50, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
forw=0xffffffffffffffff, list=0xffff80002a6eca60,0xffff80002a6ec2a8
process=0xffff800045ffd200 user=0xffff80002a706000, vmspace=0xffffffff83abb7c8
estcpu=0, cpticks=3, pctcpu=0.0, user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S PRLAGS PFLAGS WAIT COMMAND
99424 492067 85426 0 2 0 0 syz-executor
99424 421198 85426 0 2 0 0x4000000 syz-executor
67055 279199 91136 0 2 0 0 syz-executor
67055 52103 91136 0 3 0 0x4000080 fsleep syz-executor
55186 24486 84001 -1 2 0x10 0 syz-executor
55186 409831 84001 -1 3 0x10 0x4000080 fsleep syz-executor
24035 50905 74946 0 2 0 0 syz-executor
24035 362590 74946 0 3 0 0x4000080 fsleep syz-executor
35854 79191 0 0 3 0x14000 0x200 acct acct
43261 67016 0 0 3 0x14000 0x280 nfsidl nfsio
81117 277640 0 0 3 0x14000 0x280 nfsidl nfsio
59588 189923 0 0 3 0x14000 0x280 nfsidl nfsio
2502 433949 0 0 3 0x14000 0x280 nfsidl nfsio
68921 75017 0 0 3 0x14000 0x280 nfsidl nfsio
98332 469844 0 0 3 0x14000 0x280 nfsidl nfsio
32745 403699 0 0 3 0x14000 0x280 nfsidl nfsio
39331 251190 0 0 3 0x14000 0x280 nfsidl nfsio
68527 368963 0 0 3 0x14000 0x280 nfsidl nfsio
30435 373607 0 0 3 0x14000 0x280 nfsidl nfsio
94367 509353 0 0 3 0x14000 0x280 nfsidl nfsio
26352 288336 0 0 3 0x14000 0x280 nfsidl nfsio
41254 440093 0 0 3 0x14000 0x280 nfsidl nfsio
71247 436657 0 0 3 0x14000 0x280 nfsidl nfsio
59075 423193 0 0 3 0x14000 0x280 nfsidl nfsio
30212 326903 0 0 3 0x14000 0x280 nfsidl nfsio
54748 384375 0 0 3 0x14000 0x280 nfsidl nfsio
90754 272325 0 0 3 0x14000 0x280 nfsidl nfsio
32433 83639 0 0 3 0x14000 0x280 nfsidl nfsio
53338 176964 0 0 3 0x14000 0x280 nfsidl nfsio
91866 46722 17276 0 3 0x2 0x80 piperd syz-executor
93037 220528 17276 0 3 0x2 0x80 piperd syz-executor
85426 521724 17276 0 3 0x2 0x80 nanoslp syz-executor
32741 286899 17276 0 2 0x2 0 syz-executor
91136 994 17276 0 3 0x2 0x80 nanoslp syz-executor
84001 319081 17276 0 3 0x2 0x80 nanoslp syz-executor
74946 442372 17276 0 3 0x2 0x80 nanoslp syz-executor
17276 174173 8418 0 2 0x10000002 0 syz-executor
8418 131483 19312 0 3 0x100002 0x88 sigsusp ksh
19312 217044 91502 0 3 0x10 0x88 kqread sshd-session
91502 368239 49931 0 3 0x12 0x80 kqread sshd-session
20629 403096 1 0 3 0x100003 0x80 ttyin getty
49931 113731 1 0 3 0 0x88 kqread sshd
75027 473874 77210 73 3 0x1100010 0x80 kqread syslogd
77210 232673 1 0 3 0x100002 0x80 sbwait syslogd
38089 399016 1 0 3 0x100000 0x80 kqread resolvd
841 206563 95711 77 3 0x100012 0x80 kqread dhcpleased
41708 236681 95711 77 3 0x100012 0x80 kqread dhcpleased
95711 265865 1 0 3 0 0x80 kqread dhcpleased
59516 182810 0 0 3 0x14000 0x200 bored smr
61200 245323 0 0 2 0x14000 0x200 zerothread
12874 247781 0 0 3 0x14000 0x200 aiodoned aiodoned
63030 273324 0 0 3 0x14000 0x200 syncer update
97695 137709 0 0 3 0x14000 0x200 cleaner cleaner
96234 514947 0 0 3 0x14000 0x200 reaper reaper
26994 67683 0 0 3 0x14000 0x200 pgdaemon pagedaemon
67637 10317 0 0 3 0x14000 0x200 bored viomb
75637 367809 0 0 3 0x14000 0x40000200 acpi0 acpi0
*64592 72033 0 0 7 0x14000 0x200 softnet0
39056 418994 0 0 3 0x14000 0x200 bored systqmp
85882 83325 0 0 3 0x14000 0x200 bored systq
6485 247795 0 0 3 0x14000 0x40000200 tmoslp softclock
70326 155323 0 0 3 0x14000 0x40000200 idle0
1 398338 0 0 3 0x2 0x80 wait init
0 0 -1 0 3 0x10000 0x200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11028 12103K 12299K 166960K 12221 0
pcb 17 12K 12K 166960K 49 0
rtable 227 7K 8K 166960K 381 0
pf 29 12K 13K 166960K 36 0
ifaddr 38 6K 7K 166960K 46 0
ifgroup 46 2K 2K 166960K 56 0
sysctl 1 1K 9K 166960K 5 0
counters 32 17K 17K 166960K 36 0
ioctlops 0 0K 4K 166960K 142 0
iov 0 0K 8K 166960K 4 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1305 82K 82K 166960K 1593 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 5K 166960K 7 0
VM map 2 1K 1K 166960K 2 0
sem 8 0K 0K 166960K 11 0
dirhash 12 2K 2K 166960K 15 0
ACPI 1734 201K 291K 166960K 11964 0
file desc 13 45K 89K 166960K 311 0
sigio 0 0K 0K 166960K 3 0
proc 63 67K 83K 166960K 507 0
subproc 63 3K 5K 166960K 225 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 12 0
in_multi 88 6K 7K 166960K 104 0
ether_multi 1 0K 0K 166960K 3 0
mrt 0 0K 0K 166960K 20 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 61 281K 281K 166960K 61 0
exec 0 0K 1K 166960K 426 0
fusefs mount 1 32K 32K 166960K 1 0
pfkey data 0 0K 0K 166960K 1 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 183 141K 164K 166960K 4072 0
UVM aobj 9 2K 2K 166960K 11 0
pinsyscall 34 68K 92K 166960K 1411 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 2 0K 0K 166960K 10 0
NDP 10 0K 1K 166960K 29 0
temp 30 9106K 9112K 166960K 4224 0
kqueue 13 20K 26K 166960K 57 0
SYN cache 2 16K 16K 166960K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 44 0 41 1 0 1 1 0 8 0
rtentry 136 115 0 14 4 0 4 4 0 8 0
unpcb 144 114 0 97 1 0 1 1 0 8 0
syncache 336 5 0 5 1 0 1 1 0 8 1
tcpcb 736 31 0 27 1 0 1 1 0 8 0
arp 96 18 0 2 1 0 1 1 0 8 0
inpcb 328 140 0 132 2 0 2 2 0 8 1
nd6 112 26 0 4 1 0 1 1 0 8 0
pkpcb 40 2 0 2 1 0 1 1 0 8 1
kcovpl 48 25 0 18 1 0 1 1 0 8 0
ppxss 1072 2 0 2 1 0 1 1 0 8 1
pfstscr 40 4 0 4 1 0 1 1 0 8 1
pfstkey 128 2 0 2 1 0 1 1 0 8 1
pfstate 384 2 0 2 1 0 1 1 0 8 1
pfrule 1360 1 0 1 1 0 1 1 0 8 1
rttmr 136 1 0 1 1 0 1 1 0 8 1
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 458 0 46 29 0 29 29 0 8 2
art_table 40 459 0 46 5 0 5 5 0 8 0
art_node 32 115 0 23 1 0 1 1 0 8 0
semupl 112 1 0 1 1 0 1 1 0 8 1
semapl 72 9 0 3 1 0 1 1 0 8 0
shmpl 112 8 0 2 1 0 1 1 0 8 0
dirhash 1024 19 0 2 3 0 3 3 0 8 0
dino2pl 256 1799 0 323 93 0 93 93 0 8 0
ffsino 256 1799 0 323 93 0 93 93 0 8 0
nchpl 144 2181 0 478 64 0 64 64 0 8 0
vnodes 216 2079 0 0 116 0 116 116 0 8 0
namei 1024 6628 0 6627 2 0 2 2 0 8 1
kstatmem 264 27 0 6 2 0 2 2 0 8 0
scxspl 216 9344 0 9344 4 0 4 4 1 8 4
plimitpl 152 58 0 41 1 0 1 1 0 8 0
sigapl 424 593 0 533 7 0 7 7 0 8 0
knotepl 120 5485 0 5438 2 0 2 2 0 8 0
kqueuepl 184 61 0 52 1 0 1 1 0 8 0
pipepl 304 248 0 221 3 0 3 3 0 8 0
fdescpl 448 559 0 534 5 0 5 5 0 8 2
filepl 120 2512 0 2317 8 0 8 8 0 8 0
lockfpl 104 52 0 50 1 0 1 1 0 8 0
lockfspl 48 26 0 24 1 0 1 1 0 8 0
sessionpl 144 50 0 42 1 0 1 1 0 8 0
pgrppl 48 75 0 59 1 0 1 1 0 8 0
ucredpl 104 240 0 228 1 0 1 1 0 8 0
zombiepl 144 534 0 533 1 0 1 1 0 8 0
processpl 1152 593 0 533 5 0 5 5 0 8 0
procpl 664 778 0 714 6 0 6 6 0 8 0
sockpl 552 304 0 276 3 0 3 3 0 8 1
mcl64k 65536 6 0 6 1 0 1 1 0 8 1
mcl8k 8192 6 0 6 1 0 1 1 0 8 1
mcl4k 4096 2669 0 2610 14 0 14 14 0 8 6
mcl2k 2048 228 0 227 2 0 2 2 0 8 1
mextrefs 64 102 0 101 1 0 1 1 0 8 0
mtagpl 96 9 0 8 1 0 1 1 0 8 0
mbufpl 256 5711 0 5528 25 5 20 25 0 8 8
bufpl 272 3592 0 102 233 0 233 233 0 8 0
anonpl 24 97451 0 94648 41 0 41 41 0 187 16
amapchunkpl 152 11874 0 11530 23 0 23 23 0 158 9
amappl16 200 1606 0 1584 14 5 9 14 0 8 7
amappl15 192 2 0 2 1 0 1 1 0 8 1
amappl14 184 409 0 408 1 0 1 1 0 8 0
amappl13 176 139 0 129 1 0 1 1 0 8 0
amappl12 168 808 0 783 2 0 2 2 0 8 0
amappl11 160 74 0 74 1 0 1 1 0 8 1
amappl10 152 58 0 48 1 0 1 1 0 8 0
amappl9 144 273 0 273 1 0 1 1 0 8 1
amappl8 136 90 0 89 1 0 1 1 0 8 0
amappl7 128 173 0 162 1 0 1 1 0 8 0
amappl6 120 156 0 154 1 0 1 1 0 8 0
amappl5 112 93 0 86 1 0 1 1 0 8 0
amappl4 104 272 0 257 1 0 1 1 0 8 0
amappl3 96 2296 0 2217 3 0 3 3 0 8 1
amappl2 88 519 0 465 2 0 2 2 0 8 0
amappl1 80 10747 0 10220 13 0 13 13 0 8 1
amappl 88 3338 0 3218 4 0 4 4 0 92 0
uvmvnodes 80 100 0 0 3 0 3 3 0 8 0
dma4096 4096 1 0 1 1 0 1 1 0 8 1
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 0 1 1 0 8 1
dma128 128 253 0 253 1 0 1 1 0 8 1
dma64 64 6 0 6 1 0 1 1 0 8 1
dma32 32 7 0 7 1 0 1 1 0 8 1
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 10 0 2 1 0 1 1 0 8 0
uaddrrnd 24 559 0 534 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 559 0 534 1 0 1 1 0 8 0
vmmpekpl 168 6823 0 6785 3 0 3 3 0 8 0
vmmpepl 168 44665 0 43108 82 0 82 82 0 357 8
vmsppl 368 558 0 534 4 0 4 4 0 8 1
rwobjpl 40 15435 0 14555 12 0 12 12 0 8 1
pdppl 4096 1124 0 1068 96 38 58 78 0 8 2
pvpl 32 250183 0 242636 89 0 89 89 0 265 14
pmappl 216 558 0 534 2 0 2 2 0 8 0
extentpl 40 46 0 28 1 0 1 1 0 8 0
phpool 112 608 0 43 17 0 17 17 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
ifiq_enqueue_qlim(0,fffffc006f9ac000,2000) at ifiq_enqueue_qlim+0x39 sys/net/ifq.c:800
if_output_local(ffff800000c48000,fffffc006f9ac000,18) at if_output_local+0xae sys/net/if.c:1011
if_output_tso(ffff800000c48000,ffff80002a70ba58,ffff80002a70b990,fffffc006fd7ecc0,8000) at if_output_tso+0x200 sys/net/if.c:-1
ip6_output(fffffc006f9ac000,0,0,0,0,0) at ip6_output+0x1e68 sys/netinet6/ip6_output.c:664
ip6_send_dispatch(ffffffff83ad72f8) at ip6_send_dispatch+0xb4 sys/netinet6/ip6_input.c:1563
taskq_thread(ffff80000002c000) at taskq_thread+0xe4 sys/kern/kern_task.c:446
end trace frame: 0x0, count: -6
ddb> machine ddbcpu 1
No such command
ddb> trace
ifiq_enqueue_qlim(0,fffffc006f9ac000,2000) at ifiq_enqueue_qlim+0x39 sys/net/ifq.c:800
if_output_local(ffff800000c48000,fffffc006f9ac000,18) at if_output_local+0xae sys/net/if.c:1011
if_output_tso(ffff800000c48000,ffff80002a70ba58,ffff80002a70b990,fffffc006fd7ecc0,8000) at if_output_tso+0x200 sys/net/if.c:-1
ip6_output(fffffc006f9ac000,0,0,0,0,0) at ip6_output+0x1e68 sys/netinet6/ip6_output.c:664
ip6_send_dispatch(ffffffff83ad72f8) at ip6_send_dispatch+0xb4 sys/netinet6/ip6_input.c:1563
taskq_thread(ffff80000002c000) at taskq_thread+0xe4 sys/kern/kern_task.c:446
end trace frame: 0x0, count: -6


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages