protection_fault: __llvm_retpoline_r11 (2)

1 view
Skip to first unread message

syzbot

unread,
Apr 2, 2023, 7:05:43 AM4/2/23
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 1e5b016c5082 sync for __syscall removal
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17e50f85c80000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=7da8c7a624cd71d33356

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/452af0b271ef/disk-1e5b016c.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/5145fa4f4c7c/bsd-1e5b016c.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/992507fc6105/kernel-1e5b016c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7da8c7...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at __llvm_retpoline_r11+0x14: ret
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
the kernel did not panic
ddb> trace
__llvm_retpoline_r11() at __llvm_retpoline_r11+0x14
softclock_thread(ffff8000fffff050) at softclock_thread+0xf4 sys/kern/kern_timeout.c:765
end trace frame: 0x0, count: -2
ddb> show registers
rdi 0xdead4110dead4110
rsi 0
rbp 0xffff8000216048b0
rbx 0
rdx 0
rcx 0xffffffff82c10a80 timeout_proc
rax 0x9
r8 0
r9 0
r10 0x78bca212a8660b19
r11 0xdead4110dead4110
r12 0xdead4110dead4110
r13 0xffffffff82b9dff0 cpu_info_full_primary+0x1ff0
r14 0xffff8000ffffcbd0
r15 0xdead4110dead4110
rip 0xffffffff81008ac4 __llvm_retpoline_r11+0x14
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff800021604870
ss 0x10
__llvm_retpoline_r11+0x14: ret
ddb> show proc
PROC (softclock) pid=321783 stat=onproc
flags process=14000<NOZOMBIE,SYSTEM> proc=40000200<SYSTEM,CPUPEG>
pri=0, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff8000fffff308,0xffff8000ffffeda8
process=0xffff8000ffffcbd0 user=0xffff8000215ff000, vmspace=0xffffffff82c0a9b0
estcpu=0, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
64390 20742 39113 0 2 0x3000 syz-executor.5
91196 102046 68068 0 2 0 syz-executor.6
91196 306102 68068 0 3 0x4000080 fsleep syz-executor.6
63185 227029 67842 0 2 0x480 syz-executor.3
63185 333479 67842 0 3 0x4000080 fsleep syz-executor.3
35327 428769 41284 0 2 0x480 syz-executor.7
35327 412547 41284 0 3 0x4000080 netio syz-executor.7
35327 275215 41284 0 3 0x4000080 fsleep syz-executor.7
67842 459845 64413 0 2 0x482 syz-executor.3
36157 276306 64413 0 3 0x82 piperd syz-executor.2
22694 291730 64413 0 2 0x482 syz-executor.4
39113 269427 64413 0 2 0x482 syz-executor.5
41284 494157 64413 0 2 0x482 syz-executor.7
68068 241214 64413 0 2 0x482 syz-executor.6
70201 25641 0 0 3 0x14280 nfsidl nfsio
76747 274927 0 0 3 0x14280 nfsidl nfsio
9462 440555 0 0 3 0x14280 nfsidl nfsio
39687 299857 0 0 3 0x14280 nfsidl nfsio
72515 317086 0 0 3 0x14280 nfsidl nfsio
41418 347622 0 0 3 0x14280 nfsidl nfsio
3155 154119 0 0 3 0x14280 nfsidl nfsio
76706 302907 0 0 3 0x14280 nfsidl nfsio
51843 417771 0 0 3 0x14280 nfsidl nfsio
6427 230886 0 0 3 0x14280 nfsidl nfsio
47323 206165 0 0 3 0x14280 nfsidl nfsio
9262 131662 0 0 3 0x14280 nfsidl nfsio
2607 77086 0 0 3 0x14280 nfsidl nfsio
39440 304886 0 0 3 0x14280 nfsidl nfsio
15774 403277 0 0 3 0x14280 nfsidl nfsio
31649 126716 0 0 3 0x14280 nfsidl nfsio
54334 200281 0 0 3 0x14280 nfsidl nfsio
35266 449632 0 0 3 0x14280 nfsidl nfsio
7657 507842 0 0 3 0x14280 nfsidl nfsio
51016 484367 0 0 3 0x14280 nfsidl nfsio
40885 7422 64413 0 2 0x482 syz-executor.0
37980 278305 64413 0 2 0x482 syz-executor.1
56476 48807 0 0 3 0x14200 acct acct
84504 238910 1 0 3 0x100083 ttyin getty
29201 72371 0 0 3 0x14200 bored sosplice
64413 437498 51572 0 3 0x82 wait syz-fuzzer
64413 273418 51572 0 3 0x4000082 thrsleep syz-fuzzer
64413 355654 51572 0 3 0x4000082 wait syz-fuzzer
64413 90712 51572 0 3 0x4000082 thrsleep syz-fuzzer
64413 302775 51572 0 3 0x4000082 wait syz-fuzzer
64413 25304 51572 0 3 0x4000082 wait syz-fuzzer
64413 474020 51572 0 3 0x4000082 wait syz-fuzzer
64413 436049 51572 0 3 0x4000082 thrsleep syz-fuzzer
64413 74063 51572 0 3 0x4000082 wait syz-fuzzer
64413 345227 51572 0 3 0x4000082 kqread syz-fuzzer
64413 258744 51572 0 3 0x4000082 thrsleep syz-fuzzer
64413 467441 51572 0 3 0x4000082 wait syz-fuzzer
64413 382615 51572 0 3 0x4000082 wait syz-fuzzer
64413 460316 51572 0 3 0x4000082 thrsleep syz-fuzzer
51572 283997 14775 0 3 0x10008a sigsusp ksh
14775 285229 5986 0 3 0x9a kqread sshd
5986 522617 1 0 3 0x88 kqread sshd
56095 126531 35867 73 3 0x1100090 kqread syslogd
35867 315298 1 0 3 0x100082 netio syslogd
43473 191259 1 0 3 0x100080 kqread resolvd
2205 408874 0 0 2 0x14200 smr
23206 495446 0 0 2 0x14200 zerothread
29292 13343 0 0 3 0x14200 aiodoned aiodoned
64322 87494 0 0 3 0x14200 syncer update
98505 407712 0 0 3 0x14200 cleaner cleaner
79804 305118 0 0 3 0x14200 reaper reaper
69727 45453 0 0 3 0x14200 pgdaemon pagedaemon
82870 431036 0 0 3 0x14200 bored viomb
76247 217621 0 0 3 0x40014200 acpi0 acpi0
93513 341557 0 0 3 0x14200 bored softnet
43827 502345 0 0 3 0x14200 bored softnet
25988 342717 0 0 3 0x14200 bored softnet
22157 198884 0 0 3 0x14200 bored softnet
56267 461658 0 0 3 0x14200 bored systqmp
88052 156438 0 0 3 0x14200 bored systq
*42881 321783 0 0 7 0x40014200 softclock
10989 157286 0 0 3 0x40014200 idle0
1 137433 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10218 6425K 7210K 78643K 13435 0
pcb 13 20K 24K 78643K 1072 0
rtable 245 17K 17K 78643K 1844 0
ifaddr 94 26K 27K 78643K 725 0
sysctl 2 0K 2K 78643K 9 0
counters 30 17K 17K 78643K 278 0
ioctlops 0 0K 4K 78643K 873 0
iov 0 0K 32K 78643K 1109 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1556 97K 98K 78643K 5886 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 9K 78643K 80 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 1092 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 15 53K 73K 78643K 6685 0
sigio 0 0K 0K 78643K 163 0
proc 56 43K 83K 78643K 1571 0
subproc 104 6K 6K 78643K 498 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 573 0
in_multi 100 6K 7K 78643K 656 0
ether_multi 1 0K 0K 78643K 89 0
mrt 1 0K 0K 78643K 41 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 217 970K 970K 78643K 217 0
exec 0 0K 1K 78643K 1973 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 8 62K 64K 78643K 10 0
UVM amap 286 84K 99K 78643K 44158 0
UVM aobj 131 6K 6K 78643K 137 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 336 0
NDP 14 0K 1K 78643K 236 0
temp 135 5770K 71434K 78643K 95459 0
kqueue 6 10K 24K 78643K 541 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 506 0 505 5 4 1 2 0 8 0
rtentry 112 604 0 497 5 1 4 4 0 8 0
unpcb 144 7419 0 7283 59 53 6 8 0 8 0
syncache 296 53 0 53 9 9 0 1 0 8 0
sackhl 24 1 0 1 1 1 0 1 0 8 0
tcpqe 32 114 0 114 4 4 0 1 0 8 0
tcpcb 776 9538 0 9532 124 115 9 21 0 8 8
arp 88 90 0 70 1 0 1 1 0 8 0
ipq 40 7 0 6 4 3 1 1 0 8 0
ipqe 40 19 0 15 4 3 1 1 0 8 0
inpcb 336 14126 0 14121 122 111 11 20 0 8 10
nd6 48 122 0 98 1 0 1 1 0 8 0
pkpcb 40 4 0 4 1 1 0 1 0 8 0
kcovpl 48 38 0 30 1 0 1 1 0 8 0
ppxss 1160 163 0 161 10 9 1 1 0 8 0
pppxif 1360 99 0 99 7 7 0 1 0 8 0
pfstscr 40 73 0 0 1 0 1 1 0 8 0
pfanchor 1280 258 0 8 21 0 21 21 0 8 0
pfstitem 24 79 0 66 1 0 1 1 0 8 0
pfstkey 128 119 0 115 1 0 1 1 0 8 0
pfstate 352 113 0 40 7 0 7 7 0 8 0
rttmr 136 16 0 16 6 5 1 1 0 8 1
pool(rttmr): free list modified: page 0xfffffd8069956000; item ordinal 0; addr 0xfffffd8069956e80 (p 0xfffffd8069956000); offset 0x10=0xffffffff
art_heap8 4096 8 0 7 6 5 1 3 0 8 0
art_heap4 256 2536 0 2068 46 16 30 30 0 8 0
art_table 32 2544 0 2075 4 0 4 4 0 8 0
art_node 16 599 0 505 1 0 1 1 0 8 0
sysvmsgpl 40 2 0 2 1 1 0 1 0 8 0
semapl 112 1090 0 1080 1 0 1 1 0 8 0
shmpl 112 134 0 6 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 11268 0 9818 91 0 91 91 0 8 0
ffsino 240 11268 0 9818 86 0 86 86 0 8 0
nchpl 144 20703 0 19065 63 0 63 63 0 8 0
rtmask 32 1 0 1 1 1 0 1 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 78007 0 78007 3 2 1 3 0 8 1
vmpool 664 20 0 20 6 6 0 1 0 8 0
kstatmem 264 310 0 282 4 1 3 3 0 8 1
scxspl 216 54059 0 54059 17 16 1 8 0 8 1
plimitpl 152 1058 0 1044 1 0 1 1 0 8 0
sigapl 424 6944 0 6881 8 0 8 8 0 8 0
futexpl 64 78645 0 78642 1 0 1 1 0 8 0
knotepl 120 120617 0 120552 39 35 4 15 0 8 0
kqueuepl 184 1657 0 1652 22 21 1 7 0 8 0
pipepl 288 2397 0 2369 41 38 3 9 0 8 0
fdescpl 432 6904 0 6881 4 0 4 4 0 8 0
filepl 120 64240 0 63893 77 63 14 17 0 8 3
lockfpl 104 1353 0 1352 2 1 1 2 0 8 0
lockfspl 48 553 0 552 1 0 1 1 0 8 0
sessionpl 144 54 0 39 1 0 1 1 0 8 0
pgrppl 48 295 0 280 1 0 1 1 0 8 0
ucredpl 104 10072 0 10064 1 0 1 1 0 8 0
zombiepl 144 6885 0 6881 2 1 1 1 0 8 0
processpl 1008 6944 0 6881 10 1 9 9 0 8 0
procpl 696 16794 0 16714 13 4 9 9 0 8 0
sosppl 168 94 0 94 8 8 0 1 0 8 0
sockpl 456 22071 0 21929 430 410 20 35 0 8 2
mcl64k 65536 301 0 299 8 7 1 1 0 8 0
mcl16k 16384 124 0 124 14 14 0 1 0 8 0
mcl12k 12288 229 0 229 11 11 0 1 0 8 0
mcl9k 9216 99 0 98 11 10 1 1 0 8 0
mcl8k 8192 399 0 394 7 6 1 1 0 8 0
mcl4k 4096 802 0 798 4 3 1 1 0 8 0
mcl2k2 2112 37 0 37 13 13 0 1 0 8 0
mcl2k 2048 92373 0 92321 40 32 8 31 0 8 0
mtagpl 96 166 0 166 5 5 0 4 0 8 0
mbufpl 256 232128 0 231938 1078 1064 14 507 0 8 0
bufpl 288 14468 0 8071 458 0 458 458 0 8 0
anonpl 24 1328790 0 1311659 167 51 116 139 0 188 0
amapchunkpl 152 126494 0 125802 82 49 33 42 0 158 0
amappl16 200 11771 0 11169 67 31 36 45 0 8 0
amappl15 192 11 0 10 1 0 1 1 0 8 0
amappl14 184 270 0 260 2 1 1 2 0 8 0
amappl13 176 14 0 14 3 3 0 1 0 8 0
amappl12 168 761 0 760 1 0 1 1 0 8 0
amappl11 160 51 0 46 1 0 1 1 0 8 0
amappl10 152 67 0 57 1 0 1 1 0 8 0
amappl9 144 988 0 988 6 6 0 1 0 8 0
amappl8 136 339 0 258 3 0 3 3 0 8 0
amappl7 128 222 0 201 2 0 2 2 0 8 0
amappl6 120 332 0 318 2 1 1 2 0 8 0
amappl5 112 350 0 347 1 0 1 1 0 8 0
amappl4 104 943 0 914 2 1 1 2 0 8 0
amappl3 96 19114 0 19071 2 0 2 2 0 8 0
amappl2 88 7743 0 7689 3 0 3 3 0 8 0
amappl1 80 155744 0 155152 27 13 14 26 0 8 0
amappl 88 43201 0 43033 5 0 5 5 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 136 0 6 3 0 3 3 0 8 0
uaddrrnd 24 6924 0 6901 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 6924 0 6901 1 0 1 1 0 8 0
vmmpekpl 168 56584 0 56520 4 0 4 4 0 8 0
vmmpepl 168 637073 0 634657 263 144 119 145 0 357 2
vmsppl 344 6923 0 6901 3 0 3 3 0 8 0
rwobjpl 24 166932 0 159323 47 0 47 47 0 8 0
pdppl 4096 13854 0 13802 416 358 58 68 0 8 6
pvpl 32 2643759 0 2621790 354 165 189 333 0 265 0
pmappl 216 6923 0 6901 2 0 2 2 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 2433 0 1665 37 12 25 37 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
__llvm_retpoline_r11() at __llvm_retpoline_r11+0x14
softclock_thread(ffff8000fffff050) at softclock_thread+0xf4 sys/kern/kern_timeout.c:765
end trace frame: 0x0, count: -2
ddb> machine ddbcpu 1
No such command
ddb> trace
__llvm_retpoline_r11() at __llvm_retpoline_r11+0x14
softclock_thread(ffff8000fffff050) at softclock_thread+0xf4 sys/kern/kern_timeout.c:765
end trace frame: 0x0, count: -2


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jul 1, 2023, 7:06:43 AM7/1/23
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages