uvm_fault: sbdrop

0 views
Skip to first unread message

syzbot

unread,
Dec 6, 2019, 1:28:09 AM12/6/19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: ce2d2588 Document IP6_SOIIKEY_LEN
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13a4e59ce00000
kernel config: https://syzkaller.appspot.com/x/.config?x=d0fe83f82fe104d4
dashboard link: https://syzkaller.appspot.com/bug?extid=37e5882854377187f93e

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+37e588...@syzkaller.appspotmail.com

uvm_fault(0xffffffff8250c1f8, 0xfffffd0000000018, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at sbdrop+0x1f9: movl 0x18(%r15),%r13d
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
kernel page fault
uvm_fault(0xffffffff8250c1f8, 0xfffffd0000000018, 0, 1) -> e
sbdrop(ffff800016b59fd8,ffff800016b5a060,a42) at sbdrop+0x1f9
sys/kern/uipc_socket2.c:963
end trace frame: 0xffff800016b59f80, count: 0
ddb> trace
sbdrop(ffff800016b59fd8,ffff800016b5a060,a42) at sbdrop+0x1f9
sys/kern/uipc_socket2.c:963
sbflush(ffff800016b59fd8,ffff800016b5a060) at sbflush+0x93
sys/kern/uipc_socket2.c:932
sbrelease(ffff800016b59fd8,ffff800016b5a060) at sbrelease+0x2e
sys/kern/uipc_socket2.c:526
sorflush(fffffd8036fb2780) at sorflush+0x13d sys/kern/uipc_socket.c:1105
sofree(fffffd8036fb2780,42) at sofree+0x147 sys/kern/uipc_socket.c:241
soclose(fffffd8036fb2780,0) at soclose+0x268 sys/kern/uipc_socket.c:313
soo_close(fffffd803d81b018,ffff800016b48c70) at soo_close+0x40
fdrop(fffffd803d81b018,ffff800016b48c70) at fdrop+0xc2
sys/kern/kern_descrip.c:1273
closef(fffffd803d81b018,ffff800016b48c70) at closef+0x118
sys/kern/kern_descrip.c:1257
fdfree(ffff800016b48c70) at fdfree+0x100 sys/kern/kern_descrip.c:1189
exit1(ffff800016b48c70,0,1) at exit1+0x32f sys/kern/kern_exit.c:196
sys_exit(ffff800016b48c70,ffff800016b5a420,ffff800016b5a470) at
sys_exit+0x17 sys/kern/kern_exit.c:94
syscall(ffff800016b5a4f0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffe13f0, count: -14
ddb> show registers
rdi 0
rsi 0x44e
rbp 0xffff800016b59f30
rbx 0xfffffd802dd71f00
rdx 0xffff800016b59d70
rcx 0x1000 __ALIGN_SIZE
rax 0
r8 0
r9 0x3
r10 0x97b679b590a06895
r11 0x955c2635907be625
r12 0x44e
r13 0xc00
r14 0xffff800016b5a060
r15 0xfffffd0000000000
rip 0xffffffff817214b9 sbdrop+0x1f9
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff800016b59ed0
ss 0x10
sbdrop+0x1f9: movl 0x18(%r15),%r13d
ddb> show proc
PROC (syz-executor.1) pid=108332 stat=onproc
flags process=1008<EXITING,SINGLEEXIT> proc=2000<WEXIT>
pri=32, usrpri=73, nice=20
forw=0xffffffffffffffff, list=0xffff800016b48780,0xffff800016b482a0
process=0xffff8000ffff7450 user=0xffff800016b55000,
vmspace=0xfffffd803f011ee0
estcpu=23, cpticks=2, pctcpu=0.11
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
37583 97080 22293 0 2 0 syz-executor.0
37583 85815 22293 0 3 0x4000080 fsleep syz-executor.0
37583 40148 22293 0 3 0x4000080 fsleep syz-executor.0
31633 371971 0 0 3 0x14200 bored sosplice
76798 444396 78431 0 3 0x82 nanosleep syz-executor.1
22293 295721 78431 0 3 0x82 nanosleep syz-executor.0
78431 442528 58657 0 3 0x82 thrsleep syz-fuzzer
78431 175538 58657 0 3 0x4000082 thrsleep syz-fuzzer
78431 444489 58657 0 3 0x4000082 thrsleep syz-fuzzer
78431 511512 58657 0 3 0x4000082 thrsleep syz-fuzzer
78431 419785 58657 0 3 0x4000082 thrsleep syz-fuzzer
78431 15623 58657 0 3 0x4000082 thrsleep syz-fuzzer
78431 107443 58657 0 3 0x4000082 thrsleep syz-fuzzer
78431 249444 58657 0 3 0x4000082 kqread syz-fuzzer
58657 473787 60836 0 3 0x10008a pause ksh
60836 200900 70260 0 3 0x92 select sshd
61292 221397 1 0 3 0x100083 ttyin getty
70260 3405 1 0 3 0x80 select sshd
96902 91770 47778 73 3 0x100090 kqread syslogd
47778 173880 1 0 3 0x100082 netio syslogd
97335 463416 1 77 3 0x100090 poll dhclient
73440 439967 1 0 3 0x80 poll dhclient
20707 97694 0 0 2 0x14200 zerothread
73577 159735 0 0 3 0x14200 aiodoned aiodoned
6009 165674 0 0 3 0x14200 syncer update
36333 428551 0 0 3 0x14200 cleaner cleaner
5491 517096 0 0 3 0x14200 reaper reaper
17716 227066 0 0 3 0x14200 pgdaemon pagedaemon
69115 189053 0 0 3 0x14200 bored crynlk
13695 169183 0 0 3 0x14200 bored crypto
75141 219714 0 0 3 0x40014200 acpi0 acpi0
26102 511205 0 0 3 0x14200 bored softnet
522 95097 0 0 3 0x14200 bored systqmp
1343 234112 0 0 3 0x14200 bored systq
22331 219356 0 0 3 0x40014200 bored softclock
24384 417646 0 0 3 0x40014200 idle0
82081 522816 0 0 3 0x14200 bored smr
1 192916 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9507 6661K 7494K 78643K 11902 0
pcb 13 8K 8K 78643K 66 0
rtable 101 5K 5K 78643K 280 0
ifaddr 64 13K 13K 78643K 85 0
counters 19 16K 16K 78643K 19 0
ioctlops 0 0K 2K 78643K 27 0
iov 0 0K 16K 78643K 34 0
mount 1 1K 1K 78643K 1 0
vnodes 1226 77K 77K 78643K 1529 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 4 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 0K 78643K 57 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 6 17K 25K 78643K 219 0
sigio 0 0K 0K 78643K 7 0
proc 48 38K 63K 78643K 383 0
subproc 32 2K 2K 78643K 34 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 26 0
in_multi 48 2K 2K 78643K 67 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 48 212K 212K 78643K 48 0
exec 0 0K 1K 78643K 195 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 117 22K 27K 78643K 1443 0
UVM aobj 11 2K 3K 78643K 13 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 42 0
NDP 10 0K 0K 78643K 19 0
temp 126 3014K 3653K 78643K 15251 0
kqueue 0 0K 0K 78643K 2 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 8 0 3 1 0 1 1 0
8 0
rtpcb 80 43 0 36 1 0 1 1 0
8 0
rtentry 112 61 0 22 2 0 2 2 0
8 0
unpcb 120 178 0 167 1 0 1 1 0
8 0
syncache 264 5 0 5 2 2 0 1 0
8 0
tcpqe 32 93 0 93 2 2 0 1 0
8 0
tcpcb 544 76 0 72 1 0 1 1 0
8 0
ipq 40 3 0 3 1 0 1 1 0
8 1
ipqe 40 135 0 135 1 0 1 1 0
8 1
inpcb 280 431 0 424 2 0 2 2 0
8 1
nd6 48 7 0 4 1 0 1 1 0
8 0
pkpcb 40 2 0 2 1 0 1 1 0
8 1
ppxss 1128 1 0 1 1 1 0 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 351 0 129 16 0 16 16 0
8 1
art_table 32 352 0 129 3 0 3 3 0
8 0
art_node 16 60 0 24 1 0 1 1 0
8 0
sysvmsgpl 40 28 0 20 1 0 1 1 0
8 0
semupl 112 3 0 3 1 1 0 1 0
8 0
semapl 112 55 0 45 1 0 1 1 0
8 0
shmpl 112 11 0 2 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 1703 0 305 46 0 46 46 0
8 0
ffsino 240 1703 0 305 83 0 83 83 0
8 0
nchpl 144 2200 0 588 60 0 60 60 0
8 0
uvmvnodes 72 2022 0 0 37 0 37 37 0
8 0
vnodes 208 2022 0 0 107 0 107 107 0
8 0
namei 1024 6008 0 6008 1 0 1 1 0
8 1
scxspl 192 6195 0 6195 8 7 1 7 0
8 1
plimitpl 152 32 0 25 1 0 1 1 0
8 0
sigapl 432 390 0 376 2 0 2 2 0
8 0
futexpl 56 6592 0 6590 1 0 1 1 0
8 0
knotepl 112 109 0 90 1 0 1 1 0
8 0
kqueuepl 104 151 0 138 1 0 1 1 0
8 0
pipepl 128 240 0 221 1 0 1 1 0
8 0
fdescpl 424 391 0 376 2 0 2 2 0
8 0
filepl 120 3007 0 2882 4 0 4 4 0
8 0
lockfpl 104 77 0 73 1 0 1 1 0
8 0
lockfspl 48 28 0 26 1 0 1 1 0
8 0
sessionpl 112 17 0 7 1 0 1 1 0
8 0
pgrppl 48 19 0 9 1 0 1 1 0
8 0
ucredpl 96 241 0 234 1 0 1 1 0
8 0
zombiepl 144 377 0 376 1 0 1 1 0
8 0
processpl 864 406 0 376 4 0 4 4 0
8 0
procpl 632 721 0 682 4 0 4 4 0
8 0
sosppl 128 8 0 8 1 0 1 1 0
8 1
sockpl 384 656 0 630 4 0 4 4 0
8 1
mcl64k 65536 29 0 29 1 0 1 1 0
8 1
mcl16k 16384 5 0 5 1 0 1 1 0
8 1
mcl12k 12288 11 0 11 1 0 1 1 0
8 1
mcl9k 9216 4 0 4 1 0 1 1 0
8 1
mcl8k 8192 11 0 10 1 0 1 1 0
8 0
mcl4k 4096 34 0 34 1 0 1 1 0
8 1
mcl2k 2048 68385 0 68338 17 10 7 14 0
8 0
mtagpl 80 23 0 4 2 1 1 1 0
8 0
mbufpl 256 110312 0 110076 22 5 17 19 0
8 0
bufpl 280 6594 0 1712 349 0 349 349 0
8 0
anonpl 16 61416 0 40897 90 7 83 87 0
62 0
amapchunkpl 152 2041 0 1879 15 4 11 11 0
158 4
amappl16 192 2335 0 1194 58 0 58 58 0
8 0
amappl15 184 145 0 138 1 0 1 1 0
8 0
amappl14 176 26 0 23 1 0 1 1 0
8 0
amappl12 160 102 0 100 2 1 1 1 0
8 0
amappl11 152 45 0 34 1 0 1 1 0
8 0
amappl10 144 16 0 14 1 0 1 1 0
8 0
amappl9 136 559 0 555 1 0 1 1 0
8 0
amappl8 128 121 0 91 1 0 1 1 0
8 0
amappl7 120 99 0 86 1 0 1 1 0
8 0
amappl6 112 54 0 47 1 0 1 1 0
8 0
amappl5 104 235 0 224 1 0 1 1 0
8 0
amappl4 96 606 0 577 1 0 1 1 0
8 0
amappl3 88 131 0 123 1 0 1 1 0
8 0
amappl2 80 2390 0 2310 3 1 2 3 0
8 0
amappl1 72 16813 0 16358 25 16 9 20 0
8 0
amappl 80 963 0 913 2 0 2 2 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 12 0 2 1 0 1 1 0
8 0
uaddrrnd 24 391 0 376 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 391 0 376 1 0 1 1 0
8 0
vmmpekpl 168 6761 0 6734 2 0 2 2 0
8 0
vmmpepl 168 55178 0 52794 139 19 120 135 0 357
16
vmsppl 272 390 0 376 2 1 1 2 0
8 0
pdppl 4096 788 0 752 6 1 5 6 0
8 0
pvpl 32 186926 0 162804 204 7 197 204 0
265 2
pmappl 200 390 0 376 1 0 1 1 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 158 0 19 4 0 4 4 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 10, 2020, 12:05:12 PM10/10/20
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages