protection_fault: witness_checkorder (5)

5 views
Skip to first unread message

syzbot

unread,
Feb 6, 2025, 7:35:27 AM2/6/25
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 4a7e1005694f Update awk to the Jan 14, 2025 version. * Fi..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15c633df980000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=a61fbe87bc805c481c49

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/54842087657a/disk-4a7e1005.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/d9deae68dfb5/bsd-4a7e1005.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/0bb1f2a46380/kernel-4a7e1005.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a61fbe...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at witness_checkorder+0xa9: movl 0x18(%r14),%r15d
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
the kernel did not panic
ddb{1}> trace
witness_checkorder(dead4110dead4230,9,0) at witness_checkorder+0xa9 sys/kern/subr_witness.c:775
mtx_enter(dead4110dead4220) at mtx_enter+0x47 sys/kern/kern_lock.c:238
prsignal(dead4110dead4110,14) at prsignal+0x36 sys/kern/kern_sig.c:908
reaper(ffff8000ffffc008) at reaper+0x32c sys/kern/kern_exit.c:489
end trace frame: 0x0, count: -4
ddb{1}> show registers
rdi 0
rsi 0
rbp 0xffff80002a3c2120
rbx 0
rdx 0
rcx 0xffff8000ffffc008
rax 0xffff800029b5bff0
r8 0x2
r9 0x1
r10 0x115d6fec596b2f02
r11 0xbc33793f188dcf63
r12 0
r13 0x1
r14 0xdead4110dead4230
r15 0x3
rip 0xffffffff81229069 witness_checkorder+0xa9
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80002a3c2070
ss 0x10
witness_checkorder+0xa9: movl 0x18(%r14),%r15d
ddb{1}> show proc
PROC (reaper) tid=433582 pid=43714 tcnt=1 stat=onproc
flags process=14000<NOZOMBIE,SYSTEM> proc=200<SYSTEM>
runpri=32, usrpri=51, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
forw=0xffffffffffffffff, list=0xffff8000ffffccb0,0xffff8000ffffc2a0
process=0xffff80002a3c5488 user=0xffff80002a3bd000, vmspace=0xffffffff83672678
estcpu=1, cpticks=3, pctcpu=0.45, user=0, sys=132, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
99250 166380 2569 32767 2 0x10 syz-executor
99250 412185 2569 32767 2 0x4000010 syz-executor
48412 408133 75586 32767 7 0x10 syz-executor
48412 296263 75586 32767 3 0x4000090 ttyout syz-executor
48412 67383 75586 32767 3 0x4000090 fsleep syz-executor
48412 461053 75586 32767 3 0x4000090 fsleep syz-executor
27717 44563 40029 32767 2 0x10 syz-executor
27717 39679 40029 32767 3 0x4000090 fsleep syz-executor
66923 208059 0 0 3 0x14200 bored sosplice
85982 60078 96466 32767 2 0x10 syz-executor
30519 211437 20271 32767 3 0x90 piperd syz-executor
44011 411924 44053 32767 3 0x90 piperd syz-executor
5236 400643 16534 32767 3 0x10 biowait syz-executor
40029 237317 42951 32767 3 0x90 nanoslp syz-executor
75586 502965 93288 32767 3 0x90 nanoslp syz-executor
2569 220186 63964 32767 3 0x90 nanoslp syz-executor
44053 186931 70858 0 3 0x82 wait syz-executor
20271 78183 70858 0 3 0x82 wait syz-executor
16534 228625 70858 0 3 0x82 wait syz-executor
93288 461789 70858 0 3 0x82 wait syz-executor
96466 271986 70858 0 3 0x82 wait syz-executor
63964 456195 70858 0 3 0x82 wait syz-executor
42951 137822 70858 0 3 0x82 wait syz-executor
70858 248151 68676 0 3 0x82 nanoslp syz-executor
68676 33485 42049 0 3 0x10008a sigsusp ksh
42049 287979 88156 0 3 0x98 kqread sshd-session
88156 480723 1858 0 3 0x92 kqread sshd-session
37113 28238 1 0 3 0x100083 ttyin getty
1858 175192 1 0 3 0x88 kqread sshd
34162 123262 94227 73 3 0x1100090 kqread syslogd
94227 108181 1 0 3 0x100082 sbwait syslogd
61150 143021 1 0 3 0x100080 kqread resolvd
16849 311419 37093 77 3 0x100092 kqread dhcpleased
86236 275598 37093 77 3 0x100092 kqread dhcpleased
37093 387847 1 0 3 0x80 kqread dhcpleased
70561 310564 0 0 3 0x14200 bored smr
87902 183685 0 0 2 0x14200 zerothread
92670 322061 0 0 3 0x14200 aiodoned aiodoned
71606 83642 0 0 3 0x14200 syncer update
41238 114427 0 0 3 0x14200 cleaner cleaner
*43714 433582 0 0 7 0x14200 reaper
81039 479213 0 0 3 0x14200 pgdaemon pagedaemon
73214 428552 0 0 3 0x14200 bored viomb
52108 329115 0 0 3 0x40014200 acpi0 acpi0
64665 109706 0 0 3 0x40014200 idle1
31854 479753 0 0 3 0x14200 bored softnet3
6888 188884 0 0 3 0x14200 bored softnet2
42213 290455 0 0 3 0x14200 bored softnet1
82185 292547 0 0 3 0x14200 bored softnet0
99568 343655 0 0 3 0x14200 bored systqmp
91653 90230 0 0 3 0x14200 bored systq
12530 181185 0 0 3 0x14200 tmoslp softclockmp
86354 261264 0 0 3 0x40014200 tmoslp softclock
27909 502048 0 0 3 0x40014200 idle0
1 260714 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
Process 48412 (syz-executor) thread 0xffff8000ffff62a8 (408133)
exclusive rwlock uobjlk r = 0 (0xfffffd806cf73058)
#0 witness_lock+0x5bb stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5bb sys/kern/subr_witness.c:1155
#1 rw_do_enter_write+0x3ea sys/kern/kern_rwlock.c:316
#2 uvm_fault+0x1e9 sys/uvm/uvm_fault.c:690
#3 upageflttrap+0xa9 sys/arch/amd64/amd64/trap.c:188
#4 usertrap+0x2d8 sys/arch/amd64/amd64/trap.c:436
#5 recall_trap+0x8
shared rwlock vmmaplk r = 0 (0xfffffd806c233bd8)
#0 witness_lock+0x5bb stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5bb sys/kern/subr_witness.c:1155
#1 rw_do_enter_read+0x3af sys/kern/kern_rwlock.c:405
#2 uvmfault_lookup+0x122 sys/uvm/uvm_fault.c:1864
#3 uvm_fault_check+0x4b sys/uvm/uvm_fault.c:732
#4 uvm_fault+0x106 sys/uvm/uvm_fault.c:668
#5 upageflttrap+0xa9 sys/arch/amd64/amd64/trap.c:188
#6 usertrap+0x2d8 sys/arch/amd64/amd64/trap.c:436
#7 recall_trap+0x8
Process 5236 (syz-executor) thread 0xffff8000ffff9458 (400643)
exclusive rrwlock inode r = 0 (0xfffffd806c0ab618)
#0 witness_lock+0x5bb stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5bb sys/kern/subr_witness.c:1155
#1 rw_do_enter_write+0x3ea sys/kern/kern_rwlock.c:316
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:616
#3 VOP_LOCK+0xa6 sys/kern/vfs_vops.c:524
#4 vn_lock+0xa4 sys/kern/vfs_vnops.c:570
#5 vget+0x2bd sys/kern/vfs_subr.c:694
#6 ufs_ihashget+0x185 sys/ufs/ufs/ufs_ihash.c:98
#7 ffs_vget+0x8c sys/ufs/ffs/ffs_vfsops.c:1201
#8 ufs_lookup+0x19f8 sys/ufs/ufs/ufs_lookup.c:478
#9 VOP_LOOKUP+0x6e sys/kern/vfs_vops.c:85
#10 vfs_lookup+0x8fa sys/kern/vfs_lookup.c:566
#11 namei+0x7aa sys/kern/vfs_lookup.c:250
#12 dounlinkat+0xc1 sys/kern/vfs_syscalls.c:1851
#13 syscall+0xb08 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#13 syscall+0xb08 sys/arch/amd64/amd64/trap.c:577
#14 Xsyscall+0x128
exclusive rrwlock inode r = 0 (0xfffffd806c32e878)
#0 witness_lock+0x5bb stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5bb sys/kern/subr_witness.c:1155
#1 rw_do_enter_write+0x3ea sys/kern/kern_rwlock.c:316
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:616
#3 VOP_LOCK+0xa6 sys/kern/vfs_vops.c:524
#4 vn_lock+0xa4 sys/kern/vfs_vnops.c:570
#5 vfs_lookup+0x109 sys/kern/vfs_lookup.c:418
#6 namei+0x7aa sys/kern/vfs_lookup.c:250
#7 dounlinkat+0xc1 sys/kern/vfs_syscalls.c:1851
#8 syscall+0xb08 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#8 syscall+0xb08 sys/arch/amd64/amd64/trap.c:577
#9 Xsyscall+0x128
Process 43714 (reaper) thread 0xffff8000ffffc008 (433582)
exclusive kernel_lock &kernel_lock r = 0 (0xffffffff835f89c8)
#0 witness_lock+0x5bb stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5bb sys/kern/subr_witness.c:1155
#1 __mp_acquire_count+0x58
#2 mi_switch+0x4b7 sys/kern/sched_bsd.c:441
#3 sleep_finish+0x24f sys/kern/kern_synch.c:414
#4 rw_do_enter_write+0x1de sys/kern/kern_rwlock.c:292
#5 knote_processexit+0x2b sys/kern/kern_event.c:2063
#6 reaper+0x2ad sys/kern/kern_exit.c:486
#7 proc_trampoline+0x10
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10183 10952K 10966K 166960K 11265 0
pcb 17 12K 12K 166960K 17 0
rtable 218 6K 6K 166960K 372 0
pf 29 16K 16K 166960K 31 0
ifaddr 38 6K 7K 166960K 44 0
ifgroup 46 2K 2K 166960K 50 0
sysctl 3 1K 1K 166960K 4 0
counters 62 36K 36K 166960K 64 0
ioctlops 0 0K 2K 166960K 34 0
iov 0 0K 16K 166960K 88 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1332 84K 84K 166960K 1605 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 5K 166960K 7 0
VM map 2 1K 1K 166960K 2 0
sem 12 0K 0K 166960K 24 0
dirhash 12 2K 2K 166960K 18 0
ACPI 1690 195K 286K 166960K 12468 0
file desc 19 69K 125K 166960K 475 0
sigio 0 0K 0K 166960K 2 0
proc 58 79K 115K 166960K 491 0
subproc 63 3K 4K 166960K 252 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 46 0
in_multi 88 6K 7K 166960K 112 0
ether_multi 1 0K 0K 166960K 5 0
mrt 1 0K 0K 166960K 1 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 61 281K 281K 166960K 61 0
exec 0 0K 1K 166960K 399 0
fusefs mount 1 32K 32K 166960K 1 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 193 64K 82K 166960K 5431 0
UVM aobj 17 4K 4K 166960K 18 0
pinsyscall 40 80K 112K 166960K 1522 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 0K 166960K 21 0
NDP 10 0K 2K 166960K 27 0
temp 36 6891K 6957K 166960K 5081 0
kqueue 13 20K 26K 166960K 80 0
SYN cache 2 16K 16K 166960K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 24 0 0 1 0 1 1 0 8 0
rtpcb 120 59 0 56 1 0 1 1 0 8 0
rtentry 112 115 0 13 4 0 4 4 0 8 0
unpcb 144 280 0 265 4 1 3 3 0 8 2
syncache 336 6 0 6 1 1 0 1 0 8 0
tcpqe 32 1 0 1 1 1 0 1 0 8 0
tcpcb 808 142 0 137 4 3 1 4 0 8 0
arp 120 18 0 2 1 0 1 1 0 8 0
ipq 40 4 0 0 1 0 1 1 0 8 0
ipqe 40 9 0 4 1 0 1 1 0 8 0
inpcb 376 536 0 528 11 8 3 11 0 8 2
nd6 136 28 0 4 1 0 1 1 0 8 0
kcovpl 48 28 0 21 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 463 0 49 29 1 28 29 0 8 0
art_table 32 464 0 49 4 0 4 4 0 8 0
art_node 16 114 0 21 1 0 1 1 0 8 0
sysvmsgpl 40 2 0 1 1 0 1 1 0 8 0
semupl 112 1 0 1 1 1 0 1 0 8 0
semapl 112 22 0 12 1 0 1 1 0 8 0
shmpl 112 15 0 1 1 0 1 1 0 8 0
dirhash 1024 21 0 4 3 0 3 3 0 8 0
dino2pl 256 1983 0 460 96 0 96 96 0 8 0
ffsino 280 1983 0 460 109 0 109 109 0 8 0
nchpl 144 2514 0 819 63 0 63 63 0 8 0
uvmvnodes 80 2244 0 0 46 0 46 46 0 8 0
vnodes 216 2244 0 0 125 0 125 125 0 8 0
namei 1024 7809 0 7809 2 1 1 2 0 8 1
percpumem 16 46 0 1 1 0 1 1 0 8 0
kstatmem 264 22 0 2 2 0 2 2 0 8 0
scxspl 216 7502 0 7501 9 8 1 8 1 8 0
plimitpl 152 112 0 89 3 1 2 2 0 8 1
sigapl 424 721 0 670 8 1 7 8 0 8 0
futexpl 64 3351 0 3348 1 0 1 1 0 8 0
knotepl 120 321 0 0 10 0 10 10 0 8 0
kqueuepl 216 89 0 80 1 0 1 1 0 8 0
pipepl 328 186 0 158 3 0 3 3 0 8 0
fdescpl 504 702 0 671 7 2 5 6 0 8 0
filepl 152 3513 0 3314 15 3 12 12 0 8 4
lockfpl 104 60 0 57 1 0 1 1 0 8 0
lockfspl 48 29 0 26 1 0 1 1 0 8 0
sessionpl 144 44 0 29 1 0 1 1 0 8 0
pgrppl 48 75 0 53 1 0 1 1 0 8 0
ucredpl 104 567 0 549 1 0 1 1 0 8 0
zombiepl 144 671 0 670 1 0 1 1 0 8 0
processpl 1168 721 0 670 5 0 5 5 0 8 0
procpl 648 1144 0 1088 6 0 6 6 0 8 0
sosppl 168 2 0 2 2 1 1 1 0 8 1
sockpl 688 882 0 856 17 7 10 12 0 8 7
mcl64k 65536 4 0 0 1 0 1 1 0 8 0
mcl16k 16384 3 0 0 1 0 1 1 0 8 0
mcl12k 12288 1 0 0 1 0 1 1 0 8 0
mcl8k 8192 3 0 0 1 0 1 1 0 8 0
mcl4k 4096 120 0 0 15 0 15 15 0 8 0
mcl2k 2048 18 0 0 3 0 3 3 0 8 0
mtagpl 96 1 0 0 1 0 1 1 0 8 0
mbufpl 256 221 0 0 14 0 14 14 0 8 0
bufpl 280 2585 0 123 176 0 176 176 0 8 0
anonpl 24 138217 0 135321 55 8 47 55 0 185 20
amapchunkpl 152 17284 0 16872 28 5 23 27 0 158 2
amappl16 200 2675 0 2654 16 14 2 14 0 8 0
amappl15 192 4 0 4 1 1 0 1 0 8 0
amappl14 184 165 0 155 1 0 1 1 0 8 0
amappl13 176 39 0 39 1 1 0 1 0 8 0
amappl12 168 1317 0 1286 2 0 2 2 0 8 0
amappl11 160 45 0 35 1 0 1 1 0 8 0
amappl10 152 8 0 8 1 1 0 1 0 8 0
amappl9 144 254 0 253 1 0 1 1 0 8 0
amappl8 136 25 0 23 1 0 1 1 0 8 0
amappl7 128 114 0 104 1 0 1 1 0 8 0
amappl6 120 178 0 175 1 0 1 1 0 8 0
amappl5 112 137 0 130 1 0 1 1 0 8 0
amappl4 104 291 0 277 1 0 1 1 0 8 0
amappl3 96 3084 0 2986 4 0 4 4 0 8 0
amappl2 88 650 0 595 2 0 2 2 0 8 0
amappl1 80 9243 0 8714 14 0 14 14 0 8 0
amappl 88 5026 0 4880 5 0 5 5 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 17 0 1 1 0 1 1 0 8 0
uaddrrnd 24 702 0 671 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 702 0 671 1 0 1 1 0 8 0
vmmpekpl 168 7517 0 7478 3 0 3 3 0 8 0
vmmpepl 168 49838 0 48123 94 7 87 92 0 357 2
vmsppl 456 701 0 671 7 2 5 6 0 8 0
rwobjpl 64 18848 0 15803 50 0 50 50 0 8 0
pdppl 4096 1411 0 1342 131 50 81 97 0 8 12
pvpl 32 15924 0 0 129 0 129 129 0 265 0
pmappl 248 701 0 671 4 1 3 3 0 8 0
extentpl 40 55 0 38 1 0 1 1 0 8 0
phpool 112 317 0 60 8 0 8 8 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x27: addq $0x8,%rsp
ddb{0}> trace
x86_ipi_db(ffffffff8353bff0) at x86_ipi_db+0x27 sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xd9 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__mp_lock(ffffffff835f87c0) at __mp_lock+0x192 __mp_lock_spin sys/kern/kern_lock.c:113 [inline]
__mp_lock(ffffffff835f87c0) at __mp_lock+0x192 sys/kern/kern_lock.c:144
intr_handler(ffff80003a1aa430,ffff800000079f00) at intr_handler+0xe1 sys/arch/amd64/amd64/intr.c:553
Xintr_ioapic_edge23_untramp() at Xintr_ioapic_edge23_untramp+0x18f
__sanitizer_cov_trace_pc() at __sanitizer_cov_trace_pc+0x33 kd_curproc sys/dev/kcov.c:585 [inline]
__sanitizer_cov_trace_pc() at __sanitizer_cov_trace_pc+0x33 sys/dev/kcov.c:153
__mp_lock(ffffffff835f87c0) at __mp_lock+0x1a3 __mp_lock_spin sys/kern/kern_lock.c:113 [inline]
__mp_lock(ffffffff835f87c0) at __mp_lock+0x1a3 sys/kern/kern_lock.c:144
uvm_fault(fffffd806c233ad8,ad7b5eb000,0,1) at uvm_fault+0x1ee sys/uvm/uvm_fault.c:691
upageflttrap(ffff80003a1aa7d0,ad7b5eb000) at upageflttrap+0xa9 sys/arch/amd64/amd64/trap.c:188
usertrap(ffff80003a1aa7d0) at usertrap+0x2d8 sys/arch/amd64/amd64/trap.c:436
recall_trap() at recall_trap+0x8
end of kernel
end trace frame: 0x73ca70b6a020, count: -12
ddb{0}> machine ddbcpu 1
Stopped at witness_checkorder+0xa9: movl 0x18(%r14),%r15d
ddb{1}> trace
witness_checkorder(dead4110dead4230,9,0) at witness_checkorder+0xa9 sys/kern/subr_witness.c:775
mtx_enter(dead4110dead4220) at mtx_enter+0x47 sys/kern/kern_lock.c:238
prsignal(dead4110dead4110,14) at prsignal+0x36 sys/kern/kern_sig.c:908
reaper(ffff8000ffffc008) at reaper+0x32c sys/kern/kern_exit.c:489
end trace frame: 0x0, count: -4


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages