Hello,
syzbot found the following issue on:
HEAD commit: 87dc1fa97379 Ensure known_hosts file exists when setting up.
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=147c9b72580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link:
https://syzkaller.appspot.com/bug?extid=5c4d0d721f4b850a14d6
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/9369fd0bc960/disk-87dc1fa9.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/0cbc7fb421cc/bsd-87dc1fa9.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/4fc4aa5cd9da/kernel-87dc1fa9.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+5c4d0d...@syzkaller.appspotmail.com
uvm_fault(0xfffffd806ccee180, 0x70, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at dovutimens+0x368: movl 0x70(%rax),%r12d
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*122099 82007 0 0 0x4000000 0 syz-executor
dovutimens(ffff80003c90bca8,fffffd806d107538,ffff80003c909c40) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2771
sys_futimens(ffff80003c90bca8,ffff80003c909d80,ffff80003c909cd0) at sys_futimens+0xb3 sys/kern/vfs_syscalls.c:2847
syscall(ffff80003c909d80) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c909d80) at syscall+0x962 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6332ae52db0, count: 11
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
*cpu0: uvm_fault(0xfffffd806ccee180, 0x70, 0, 1) -> e
ddb> trace
dovutimens(ffff80003c90bca8,fffffd806d107538,ffff80003c909c40) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2771
sys_futimens(ffff80003c90bca8,ffff80003c909d80,ffff80003c909cd0) at sys_futimens+0xb3 sys/kern/vfs_syscalls.c:2847
syscall(ffff80003c909d80) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c909d80) at syscall+0x962 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6332ae52db0, count: -4
ddb> show registers
rdi 0xffff8000314c8000
rsi 0x40
rbp 0xffff80003c909c30
rbx 0
rdx 0xffff8000314c8000
rcx 0x3f
rax 0
r8 0x7f7fffffc000
r9 0
r10 0x3f07618725bc027
r11 0xbf5ab5df750a0e00
r12 0xffff80003c909c40
r13 0
r14 0xfffffd806d107538
r15 0xffff80003c90bca8
rip 0xffffffff82960a18 dovutimens+0x368
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80003c909b30
ss 0x10
dovutimens+0x368: movl 0x70(%rax),%r12d
ddb> show proc
PROC (syz-executor) tid=122099 pid=82007 tcnt=2 stat=onproc
flags process=0 proc=4000000<THREAD>
runpri=32, usrpri=50, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
forw=0xffffffffffffffff, list=0xffff80003c90a550,0xffff80003c90b4f0
process=0xffff8000ffff8018 user=0xffff80003c904000, vmspace=0xfffffd806ccee180
estcpu=0, cpticks=1, pctcpu=0.0, user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
61111 44015 31815 0 2 0 syz-executor
61111 256018 31815 0 3 0x4000080 fsleep syz-executor
95213 425967 30204 0 2 0 syz-executor
95213 15101 30204 0 3 0x4000080 fsleep syz-executor
57079 482310 52534 0 2 0 syz-executor
57079 224678 52534 0 3 0x4000080 fsleep syz-executor
82007 110660 82550 0 2 0 syz-executor
*82007 122099 82550 0 7 0x4000000 syz-executor
10744 435411 92767 0 2 0 syz-executor
10744 166543 92767 0 3 0x4000080 fifor syz-executor
85097 266097 6009 0 2 0 syz-executor
85097 97891 6009 0 3 0x4000080 bpf syz-executor
85097 307330 6009 0 3 0x4000080 fsleep syz-executor
94298 271636 7755 0 2 0x40 syz-executor
52534 135949 36297 0 3 0x82 nanoslp syz-executor
92767 148264 36297 0 2 0xc82 syz-executor
6009 98319 36297 0 2 0xc82 syz-executor
31815 507703 36297 0 3 0x82 nanoslp syz-executor
82550 270777 36297 0 2 0xc82 syz-executor
30204 319790 36297 0 3 0x82 nanoslp syz-executor
82565 426892 36297 0 2 0x2 syz-executor
7755 514176 36297 0 3 0x82 ppwait syz-executor
36297 93736 85817 0 3 0x82 kqread syz-executor
85817 397008 95879 0 3 0x10008a sigsusp ksh
95879 156322 87554 0 3 0x98 kqread sshd-session
87554 417196 98948 0 3 0x92 kqread sshd-session
52976 381873 1 0 3 0x100083 ttyin getty
98948 288896 1 0 3 0x88 kqread sshd
60399 492473 51547 73 3 0x1100090 kqread syslogd
51547 385721 1 0 3 0x100082 sbwait syslogd
87121 109925 1 0 3 0x100080 kqread resolvd
65984 323701 89118 77 3 0x100092 kqread dhcpleased
52067 204852 89118 77 3 0x100092 kqread dhcpleased
89118 394663 1 0 3 0x80 kqread dhcpleased
278 162289 0 0 3 0x14200 bored smr
62829 239215 0 0 2 0x14200 zerothread
12868 122238 0 0 3 0x14200 aiodoned aiodoned
76339 215282 0 0 3 0x14200 syncer update
26063 111724 0 0 3 0x14200 cleaner cleaner
1586 476691 0 0 3 0x14200 reaper reaper
16339 11829 0 0 3 0x14200 pgdaemon pagedaemon
70717 165840 0 0 3 0x14200 bored viomb
31099 209071 0 0 3 0x40014200 acpi0 acpi0
65059 72218 0 0 3 0x14200 bored softnet0
46072 28114 0 0 3 0x14200 bored systqmp
35572 414937 0 0 3 0x14200 bored systq
46949 466037 0 0 3 0x40014200 tmoslp softclock
56071 36248 0 0 3 0x40014200 idle0
1 78804 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11047 12233K 12385K 166960K 12349 0
pcb 19 12K 12K 166960K 22 0
rtable 235 6K 6K 166960K 359 0
pf 31 13K 13K 166960K 33 0
ifaddr 41 7K 7K 166960K 44 0
ifgroup 50 2K 2K 166960K 52 0
sysctl 1 1K 9K 166960K 5 0
counters 33 17K 17K 166960K 34 0
ioctlops 0 0K 4K 166960K 35 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1327 83K 83K 166960K 1417 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 1K 166960K 2 0
VM map 2 1K 1K 166960K 2 0
sem 3 0K 0K 166960K 3 0
dirhash 12 2K 2K 166960K 12 0
ACPI 1692 195K 286K 166960K 12470 0
file desc 17 61K 93K 166960K 174 0
proc 58 59K 91K 166960K 490 0
subproc 72 4K 4K 166960K 72 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 4 0
in_multi 89 6K 6K 166960K 89 0
ether_multi 1 0K 0K 166960K 1 0
mrt 0 0K 0K 166960K 1 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 61 281K 281K 166960K 61 0
exec 0 0K 1K 166960K 360 0
fusefs mount 1 32K 32K 166960K 1 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 209 150K 158K 166960K 3237 0
UVM aobj 4 2K 2K 166960K 4 0
pinsyscall 38 76K 94K 166960K 1246 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
NDP 11 0K 1K 166960K 26 0
temp 36 9062K 9126K 166960K 3989 0
kqueue 13 20K 24K 166960K 28 0
SYN cache 2 16K 16K 166960K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 38 0 35 1 0 1 1 0 8 0
rtentry 136 108 0 2 4 0 4 4 0 8 0
unpcb 144 55 0 38 1 0 1 1 0 8 0
syncache 336 4 0 4 1 0 1 1 0 8 1
tcpcb 736 22 0 18 1 0 1 1 0 8 0
arp 96 19 0 0 1 0 1 1 0 8 0
inpcb 328 81 0 72 1 0 1 1 0 8 0
nd6 112 21 0 0 1 0 1 1 0 8 0
pkpcb 40 1 0 1 1 0 1 1 0 8 1
kcovpl 48 8 0 0 1 0 1 1 0 8 0
ppxss 1072 1 0 1 1 0 1 1 0 8 1
pfstitem 24 2 0 0 1 0 1 1 0 8 0
pfstkey 128 2 0 0 1 0 1 1 0 8 0
pfstate 384 1 0 0 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 416 0 0 26 0 26 26 0 8 0
art_table 40 417 0 0 5 0 5 5 0 8 0
art_node 32 107 0 11 1 0 1 1 0 8 0
sysvmsgpl 40 1 0 0 1 0 1 1 0 8 0
semapl 112 1 0 0 1 0 1 1 0 8 0
shmpl 112 1 0 0 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 1610 0 153 92 0 92 92 0 8 0
ffsino 256 1610 0 153 92 0 92 92 0 8 0
nchpl 144 1861 0 176 63 0 63 63 0 8 0
vnodes 216 1747 0 0 98 0 98 98 0 8 0
namei 1024 5431 0 5431 2 0 2 2 0 8 2
kstatmem 264 24 0 2 2 0 2 2 0 8 0
scxspl 216 6007 0 6007 2 0 2 2 1 8 2
plimitpl 152 34 0 18 1 0 1 1 0 8 0
sigapl 424 464 0 422 6 0 6 6 0 8 1
knotepl 120 3765 0 3718 2 0 2 2 0 8 0
kqueuepl 184 30 0 21 1 0 1 1 0 8 0
pipepl 304 119 0 92 3 0 3 3 0 8 0
fdescpl 448 451 0 422 5 0 5 5 0 8 1
filepl 120 1621 0 1410 8 0 8 8 0 8 1
lockfpl 104 10 0 8 1 0 1 1 0 8 0
lockfspl 48 6 0 4 1 0 1 1 0 8 0
sessionpl 144 21 0 13 1 0 1 1 0 8 0
pgrppl 48 29 0 13 1 0 1 1 0 8 0
ucredpl 104 109 0 98 1 0 1 1 0 8 0
zombiepl 144 422 0 422 1 0 1 1 0 8 1
processpl 1152 464 0 422 4 0 4 4 0 8 0
procpl 664 518 0 469 5 0 5 5 0 8 0
sockpl 552 177 0 148 3 0 3 3 0 8 0
mcl64k 65536 3 0 3 1 0 1 1 0 8 1
mcl16k 16384 1 0 1 1 0 1 1 0 8 1
mcl8k 8192 8 0 8 1 0 1 1 0 8 1
mcl4k 4096 2517 0 2464 13 0 13 13 0 8 6
mcl2k 2048 151 0 150 3 0 3 3 0 8 2
mtagpl 96 4 0 4 1 0 1 1 0 8 1
mbufpl 256 4407 0 4267 13 0 13 13 0 8 0
bufpl 280 2265 0 102 155 0 155 155 0 8 0
anonpl 24 100318 0 97324 23 0 23 23 0 187 3
amapchunkpl 152 9178 0 8748 19 0 19 19 0 158 2
amappl16 200 1876 0 1857 5 0 5 5 0 8 3
amappl15 192 5 0 5 1 0 1 1 0 8 1
amappl14 184 404 0 403 1 0 1 1 0 8 0
amappl13 176 157 0 147 1 0 1 1 0 8 0
amappl12 168 687 0 660 2 0 2 2 0 8 0
amappl11 160 22 0 22 1 0 1 1 0 8 1
amappl10 152 57 0 47 1 0 1 1 0 8 0
amappl9 144 262 0 262 1 0 1 1 0 8 1
amappl8 136 92 0 91 1 0 1 1 0 8 0
amappl7 128 141 0 130 1 0 1 1 0 8 0
amappl6 120 149 0 148 1 0 1 1 0 8 0
amappl5 112 103 0 96 1 0 1 1 0 8 0
amappl4 104 249 0 235 1 0 1 1 0 8 0
amappl3 96 1619 0 1520 3 0 3 3 0 8 0
amappl2 88 495 0 443 2 0 2 2 0 8 0
amappl1 80 9059 0 8513 13 0 13 13 0 8 1
amappl 88 2563 0 2418 4 0 4 4 0 92 0
uvmvnodes 80 95 0 0 2 0 2 2 0 8 0
dma4096 4096 1 0 1 1 0 1 1 0 8 1
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 0 1 1 0 8 1
dma128 128 253 0 253 1 0 1 1 0 8 1
dma64 64 6 0 6 1 0 1 1 0 8 1
dma32 32 7 0 7 1 0 1 1 0 8 1
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 3 0 0 1 0 1 1 0 8 0
uaddrrnd 24 451 0 422 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 451 0 422 1 0 1 1 0 8 0
vmmpekpl 168 5244 0 5214 2 0 2 2 0 8 0
vmmpepl 168 36696 0 34967 80 0 80 80 0 357 3
vmsppl 368 450 0 422 4 0 4 4 0 8 1
rwobjpl 40 13558 0 12648 11 0 11 11 0 8 0
pdppl 4096 908 0 844 94 26 68 80 0 8 4
pvpl 32 226876 0 218538 79 0 79 79 0 265 8
pmappl 216 450 0 422 3 0 3 3 0 8 0
extentpl 40 45 0 27 1 0 1 1 0 8 0
phpool 112 356 0 26 10 0 10 10 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
dovutimens(ffff80003c90bca8,fffffd806d107538,ffff80003c909c40) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2771
sys_futimens(ffff80003c90bca8,ffff80003c909d80,ffff80003c909cd0) at sys_futimens+0xb3 sys/kern/vfs_syscalls.c:2847
syscall(ffff80003c909d80) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c909d80) at syscall+0x962 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6332ae52db0, count: -4
ddb> machine ddbcpu 1
No such command
ddb> trace
dovutimens(ffff80003c90bca8,fffffd806d107538,ffff80003c909c40) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2771
sys_futimens(ffff80003c90bca8,ffff80003c909d80,ffff80003c909cd0) at sys_futimens+0xb3 sys/kern/vfs_syscalls.c:2847
syscall(ffff80003c909d80) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c909d80) at syscall+0x962 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6332ae52db0, count: -4
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup