Hello,
syzbot found the following issue on:
HEAD commit: 97ee8abe534f Unbreak previous.
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=14847682580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link:
https://syzkaller.appspot.com/bug?extid=f62974b57730ca5b1f0d
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/8299542ddda4/disk-97ee8abe.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/6e71d76af37b/bsd-97ee8abe.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/d1f72584b382/kernel-97ee8abe.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+f62974...@syzkaller.appspotmail.com
panic: kernel diagnostic assertion "(LIST_NEXT(inp, inp_lhash) == NULL) || (LIST_NEXT(inp, inp_lhash) == _Q_INVALID)" failed: file "/syzkaller/managers/main/kernel/sys/netinet/in_pcb.c", line 671
Starting stack trace...
panic(ffffffff8342de09) at panic+0x1ba sys/kern/subr_prf.c:229
__assert(ffffffff833de45c,ffffffff833c8dfd,29f,ffffffff8330f9c4) at __assert+0x29 sys/kern/subr_prf.c:-1
in_pcbunref(fffffd8079f9c3d8) at in_pcbunref+0x1d9 sys/netinet/in_pcb.c:672
tcp_input_solocked(ffff80002a74b190,ffff80002a74b19c,0,2,ffff80002a74b188) at tcp_input_solocked+0xfd sys/netinet/tcp_input.c:2229
tcp_input_mlist(ffffffff839cae60,2) at tcp_input_mlist+0x93 sys/netinet/tcp_input.c:-1
if_input_process(ffff800000b11800,ffff80002a74b268,0) at if_input_process+0x229 sys/net/if.c:1015
ifiq_process(ffff800000b11c18) at ifiq_process+0xcd sys/net/ifq.c:874
taskq_thread(ffff80000002c000) at taskq_thread+0xd4 sys/kern/kern_task.c:446
end trace frame: 0x0, count: 249
End of stack trace.
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup