protection_fault: pool_do_put (3)

0 views
Skip to first unread message

syzbot

unread,
Aug 10, 2026, 3:07:34 AM (8 days ago) Aug 10
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fab829404855 ttys(5): a few editorial cleanups
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=144c2149580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=eee70244aa305dc183a8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/821d99f61d6e/disk-fab82940.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/b8fdb713ac9a/bsd-fab82940.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f0c47598ab11/kernel-fab82940.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+eee702...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at pool_do_put+0x17c: movq 0x8(%r13),%r13
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
the kernel did not panic
ddb{1}> show kasan
No such command
ddb{1}> trace
pool_do_put(ffffffff83ad09b0,ffff800010fdbab0) at pool_do_put+0x17c sys/kern/subr_pool.c:847
pool_put(ffffffff83ad09b0,ffff800010fdbab0) at pool_put+0xba sys/kern/subr_pool.c:805
soclose(ffff800010fdbab0,0) at soclose+0x752 sys/kern/uipc_socket.c:499
soo_close(fffff3806d7d63e8,ffff800045feea78) at soo_close+0x56 sys/kern/sys_socket.c:-1
fdrop(fffff3806d7d63e8,ffff800045feea78) at fdrop+0x121 sys/kern/kern_descrip.c:1281
closef(fffff3806d7d63e8,ffff800045feea78) at closef+0x192 sys/kern/kern_descrip.c:1265
fdfree(ffff800045feea78) at fdfree+0x116 sys/kern/kern_descrip.c:1196
exit1(ffff800045feea78,0,0,1) at exit1+0x595 sys/kern/kern_exit.c:215
sys_exit(ffff800045feea78,ffff80003c3d6980,ffff80003c3d68d0) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c3d6980) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3d6980) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x76e1462c78c0, count: -11
ddb{1}> show registers
rdi 0x14bf78613cfea959
rsi 0xeb40f8612c0307a9
rbp 0xffff80003c3d6600
rbx 0x14bf78613cfea959
rdx 0
rcx 0xffff800045feea78
rax 0xffff80002999dff0
r8 0xffffffffffffffff
r9 0x1
r10 0x65a84a34c46527d
r11 0x7dd1d19464b18a0c
r12 0xffff800010fdbab0
r13 0x14bf78613cfea959
r14 0xffffffff83ad09b0 socket_pool
r15 0xffff800010fdbf90
rip 0xffffffff830f8e0c pool_do_put+0x17c
cs 0x8
rflags 0x10207 __ALIGN_SIZE+0xf207
rsp 0xffff80003c3d6550
ss 0x10
pool_do_put+0x17c: movq 0x8(%r13),%r13
ddb{1}> show proc
PROC (syz-executor) tid=67428 pid=55947 tcnt=0 stat=onproc
flags process=1018<EXITING,SUGID,SINGLEEXIT> proc=2000<WEXIT>
runpri=32, usrpri=86, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0xffff800045feea78 scnt=-1 ecnt=1
forw=0xffffffffffffffff, list=0xffff800045fe42c0,0xffff800045fef780
process=0xffff800045fe1360 user=0xffff80003c3d1000, vmspace=0xfffff380694ad030
estcpu=36, cpticks=5, pctcpu=0.0, user=0, sys=0, intr=0
ddb{1}> ps
PID TID PPID UID S PRLAGS PFLAGS WAIT COMMAND
79785 398159 82270 32767 3 0x10 0x80 nanoslp syz-executor
79785 292603 82270 32767 3 0x10 0x4000080 fsleep syz-executor
79785 114488 82270 32767 3 0x10 0x4000080 fsleep syz-executor
79785 473313 82270 32767 3 0x10 0x4000080 fsleep syz-executor
48296 201141 28643 0 3 0x2 0 getblk syz-executor
83212 43966 47746 32767 3 0x10 0 biowait syz-executor
47746 477883 28643 0 3 0x2 0x80 wait syz-executor
5364 423590 57035 32767 3 0x10 0x80 nanoslp syz-executor
5364 46436 57035 32767 3 0x10 0x4000080 piperd syz-executor
5364 261101 57035 32767 3 0x10 0x4000080 fsleep syz-executor
71693 271863 70971 0 3 0x100002 0x80 sbwait arp
70971 185283 75258 0 3 0x100002 0x88 sigsusp sh
58575 209860 32954 0 3 0x100002 0x80 sbwait arp
32954 201360 54624 0 3 0x100002 0x88 sigsusp sh
48904 492278 16169 32767 3 0x10 0x80 nanoslp syz-executor
57035 98920 13150 32767 3 0x10 0x80 nanoslp syz-executor
83926 65497 19444 0 3 0x100002 0x80 sbwait arp
19444 380903 16777 0 3 0x100002 0x88 sigsusp sh
75258 46688 73503 0 3 0 0x80 wait syz-executor
54624 519484 55738 0 3 0 0x80 wait syz-executor
82270 51342 48120 32767 3 0x10 0x80 nanoslp syz-executor
16777 106688 61798 0 3 0 0x80 wait syz-executor
13150 157360 28643 0 3 0x2 0x80 wait syz-executor
16169 479566 28643 0 3 0x2 0x80 wait syz-executor
73503 328944 28643 0 3 0x2 0x80 wait syz-executor
55738 449926 28643 0 3 0x2 0x80 wait syz-executor
48120 249509 28643 0 3 0x2 0x80 wait syz-executor
61798 92256 28643 0 3 0x2 0x80 wait syz-executor
28643 117639 42397 0 3 0x2 0x80 kqread syz-executor
42397 300845 59049 0 3 0x100002 0x88 sigsusp ksh
59049 377071 87169 0 3 0x10 0x88 kqread sshd-session
87169 325480 36383 0 3 0x12 0x80 kqread sshd-session
59525 194637 1 0 3 0x100003 0x80 ttyin getty
36383 495772 1 0 3 0 0x88 kqread sshd
16875 50347 60321 73 3 0x1100010 0x80 kqread syslogd
60321 326892 1 0 3 0x100002 0x80 sbwait syslogd
72895 15346 1 0 3 0x100000 0x80 kqread resolvd
31827 456512 82698 77 3 0x100012 0x80 kqread dhcpleased
51708 332466 82698 77 3 0x100012 0x80 kqread dhcpleased
82698 359241 1 0 3 0 0x80 kqread dhcpleased
51433 352487 0 0 3 0x14000 0x200 bored smr
94502 20289 0 0 7 0x14000 0x200 zerothread
23229 265897 0 0 3 0x14000 0x200 aiodoned aiodoned
80603 5556 0 0 3 0x14000 0x200 syncer update
61679 334630 0 0 3 0x14000 0x200 cleaner cleaner
7367 311564 0 0 3 0x14000 0x200 reaper reaper
94933 243311 0 0 3 0x14000 0x200 pgdaemon pagedaemon
45151 491452 0 0 3 0x14000 0x200 bored viomb
26808 383727 0 0 3 0x14000 0x40000200 acpi0 acpi0
98402 28100 0 0 3 0x14000 0x40000200 idle1
46536 386418 0 0 3 0x14000 0x200 bored softnet1
98459 399578 0 0 3 0x14000 0x200 bored softnet0
57352 490503 0 0 3 0x14000 0x200 bored systqmp
73992 3407 0 0 3 0x14000 0x200 bored systq
73039 216378 0 0 3 0x14000 0x200 tmoslp softclockmp
7308 348972 0 0 3 0x14000 0x40000200 tmoslp softclock
15363 302247 0 0 3 0x14000 0x40000200 idle0
1 446283 0 0 3 0x2 0x80 wait init
0 0 -1 0 3 0x10000 0x200 scheduler swapper
ddb{1}> show all locks
CPU 1:
exclusive mutex sockpl r = 0 (0xffffffff83ad09c8)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 mtx_enter+0x4b4 sys/kern/kern_lock.c:487
#2 pool_put+0xa6 sys/kern/subr_pool.c:803
#3 soclose+0x752 sys/kern/uipc_socket.c:499
#4 soo_close+0x56 sys/kern/sys_socket.c:-1
#5 fdrop+0x121 sys/kern/kern_descrip.c:1281
#6 closef+0x192 sys/kern/kern_descrip.c:1265
#7 fdfree+0x116 sys/kern/kern_descrip.c:1196
#8 exit1+0x595 sys/kern/kern_exit.c:215
#9 sys_exit+0x1a sys/kern/kern_exit.c:-1
#10 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#10 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#11 Xsyscall+0x128
Process 48296 (syz-executor) thread 0xffff800045fef770 (201141)
exclusive rrwlock inode r = 0 (0xfffff3806a7891e8)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:621
#3 VOP_LOCK+0xbd sys/kern/vfs_vops.c:527
#4 ufs_ihashins+0x4f ufs_ihash sys/ufs/ufs/ufs_ihash.c:-1 [inline]
#4 ufs_ihashins+0x4f sys/ufs/ufs/ufs_ihash.c:150
#5 ffs_vget+0x187 sys/ufs/ffs/ffs_vfsops.c:1232
#6 ffs_inode_alloc+0x279 sys/ufs/ffs/ffs_alloc.c:393
#7 ufs_mkdir+0xfc sys/ufs/ufs/ufs_vnops.c:1112
#8 VOP_MKDIR+0x101 sys/kern/vfs_vops.c:394
#9 domkdirat+0x179 sys/kern/vfs_syscalls.c:3063
#10 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#10 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#11 Xsyscall+0x128
exclusive rrwlock inode r = 0 (0xfffff3806ff836a0)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:621
#3 VOP_LOCK+0xbd sys/kern/vfs_vops.c:527
#4 vn_lock+0xa4 sys/kern/vfs_vnops.c:576
#5 vfs_lookup+0x12b sys/kern/vfs_lookup.c:431
#6 namei+0x7c5 sys/kern/vfs_lookup.c:250
#7 domkdirat+0x8b sys/kern/vfs_syscalls.c:3048
#8 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#8 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#9 Xsyscall+0x128
Process 83212 (syz-executor) thread 0xffff800045fe42c0 (43966)
exclusive rrwlock inode r = 0 (0xfffff3806d6afb20)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:621
#3 VOP_LOCK+0xbd sys/kern/vfs_vops.c:527
#4 vn_lock+0xa4 sys/kern/vfs_vnops.c:576
#5 vget+0x2a2 sys/kern/vfs_subr.c:692
#6 ufs_ihashget+0x185 sys/ufs/ufs/ufs_ihash.c:98
#7 ffs_vget+0x8c sys/ufs/ffs/ffs_vfsops.c:1203
#8 ufs_lookup+0x1a36 sys/ufs/ufs/ufs_lookup.c:478
#9 VOP_LOOKUP+0x6e sys/kern/vfs_vops.c:85
#10 vfs_lookup+0x963 sys/kern/vfs_lookup.c:580
#11 namei+0x7c5 sys/kern/vfs_lookup.c:250
#12 dounlinkat+0xc1 sys/kern/vfs_syscalls.c:1807
#13 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#13 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#14 Xsyscall+0x128
exclusive rrwlock inode r = 0 (0xfffff3806a789310)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:621
#3 VOP_LOCK+0xbd sys/kern/vfs_vops.c:527
#4 vn_lock+0xa4 sys/kern/vfs_vnops.c:576
#5 vfs_lookup+0x12b sys/kern/vfs_lookup.c:431
#6 namei+0x7c5 sys/kern/vfs_lookup.c:250
#7 dounlinkat+0xc1 sys/kern/vfs_syscalls.c:1807
#8 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#8 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#9 Xsyscall+0x128
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11046 12016K 12034K 166960K 12143 0
pcb 17 14K 16K 166960K 19 0
rtable 167 4K 5K 166960K 328 0
pf 29 16K 16K 166960K 33 0
ifaddr 32 5K 6K 166960K 42 0
ifgroup 46 2K 2K 166960K 54 0
sysctl 3 1K 9K 166960K 8 0
counters 68 36K 37K 166960K 72 0
ioctlops 0 0K 4K 166960K 33 0
iov 0 0K 8K 166960K 5 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1287 81K 81K 166960K 1461 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 5K 166960K 7 0
VM map 2 1K 1K 166960K 2 0
sem 9 0K 1K 166960K 11 0
dirhash 12 2K 2K 166960K 15 0
ACPI 1734 201K 291K 166960K 11964 0
file desc 26 94K 129K 166960K 266 0
sigio 0 0K 0K 166960K 2 0
proc 61 115K 147K 166960K 540 0
subproc 63 3K 4K 166960K 108 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 0 0K 0K 166960K 19 0
in_multi 58 3K 4K 166960K 82 0
ether_multi 1 0K 0K 166960K 2 0
mrt 0 0K 0K 166960K 3 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 55 254K 254K 166960K 55 0
exec 0 0K 1K 166960K 393 0
fusefs mount 1 32K 32K 166960K 1 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 238 149K 184K 166960K 4122 0
UVM aobj 107 3K 3K 166960K 109 0
pinsyscall 50 100K 122K 166960K 1397 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 0K 166960K 9 0
NDP 12 0K 1K 166960K 24 0
temp 31 9114K 9130K 166960K 4091 0
kqueue 13 20K 31K 166960K 60 0
SYN cache 2 16K 16K 166960K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 28 0 0 1 0 1 1 0 8 0
rtpcb 120 43 0 36 1 0 1 1 0 8 0
rtentry 176 101 0 26 5 0 5 5 0 8 1
unpcb 144 203 0 188 3 0 3 3 0 8 2
syncache 336 7 0 7 1 0 1 1 0 8 1
tcpcb 736 54 0 49 1 0 1 1 0 8 0
arp 136 17 0 4 1 0 1 1 0 8 0
ipq 40 1 0 0 1 0 1 1 0 8 0
ipqe 40 2 0 1 1 0 1 1 0 8 0
inpcb 328 373 0 365 13 4 9 13 0 8 8
nd6 152 21 0 9 1 0 1 1 0 8 0
kcovpl 48 12 0 5 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 410 0 125 23 0 23 23 0 8 0
art_table 40 411 0 125 4 0 4 4 0 8 0
art_node 32 101 0 32 1 0 1 1 0 8 0
sysvmsgpl 40 1 0 1 1 0 1 1 0 8 1
semupl 112 1 0 1 1 0 1 1 0 8 1
semapl 72 7 0 0 1 0 1 1 0 8 0
shmpl 112 106 0 2 3 0 3 3 0 8 0
dirhash 1024 19 0 2 3 0 3 3 0 8 0
dino2pl 256 1793 0 327 92 0 92 92 0 8 0
ffsino 296 1793 0 327 113 0 113 113 0 8 0
nchpl 144 2143 0 447 63 0 63 63 0 8 0
vnodes 216 1910 0 0 107 0 107 107 0 8 0
namei 1024 6623 0 6622 1 0 1 1 0 8 0
percpumem 16 52 0 2 1 0 1 1 0 8 0
kstatmem 264 27 0 4 2 0 2 2 0 8 0
scxspl 216 7464 0 7463 4 3 1 3 1 8 0
plimitpl 152 65 0 42 2 0 2 2 0 8 0
sigapl 424 563 0 509 7 0 7 7 0 8 0
knotepl 120 313 0 0 10 0 10 10 0 8 0
kqueuepl 224 130 0 121 3 0 3 3 0 8 2
pipepl 344 148 0 120 3 0 3 3 0 8 0
fdescpl 528 547 0 509 4 0 4 4 0 8 0
filepl 160 2665 0 2462 17 0 17 17 0 8 7
lockfpl 104 32 0 29 1 0 1 1 0 8 0
lockfspl 48 15 0 12 1 0 1 1 0 8 0
sessionpl 144 32 0 17 1 0 1 1 0 8 0
pgrppl 48 47 0 24 1 0 1 1 0 8 0
ucredpl 104 422 0 407 1 0 1 1 0 8 0
zombiepl 144 510 0 509 1 0 1 1 0 8 0
processpl 1232 563 0 509 5 0 5 5 0 8 0
procpl 664 764 0 705 7 0 7 7 0 8 1
sosppl 176 2 0 2 1 0 1 1 0 8 1
sockpl 752 619 0 588 17 5 12 17 0 8 8
sockpl: pool(0xffffffff83ad09b0:sockpl): page inconsistency: page 0x0; at page head addr 0xffff800010fd9f90 (p 0xffff800010fd8000)
sockpl: pool(0xffffffff83ad09b0:sockpl): free list modified: page 0xffff800010fda000; item ordinal 1; addr 0xffff800010fda040 (p 0xffff800010fda000); offset 0x0=0x10000005d
pool(sockpl): free list modified: page 0xffff800010fda000; item ordinal 1; addr 0xffff800010fda040 (p 0xffff800010fda000); offset 0x0=0x3000
sockpl: pool(0xffffffff83ad09b0:sockpl): page inconsistency: page 0xffff800010fda000; item ordinal 2; addr 0x14bf78613cfea959
mcl64k 65536 2 0 0 1 0 1 1 0 8 0
mcl8k 8192 3 0 0 1 0 1 1 0 8 0
mcl4k 4096 112 0 0 14 0 14 14 0 8 0
mcl2k 2048 33 0 0 5 0 5 5 0 8 0
mextrefs 64 29 0 0 1 0 1 1 0 8 0
mtagpl 96 3 0 0 1 0 1 1 0 8 0
mbufpl 256 405 0 0 26 0 26 26 0 8 0
bufpl 272 2719 0 102 175 0 175 175 0 8 0
anonpl 32 6064 0 0 49 0 49 49 0 247 0
amapchunkpl 152 12298 0 11818 28 0 28 28 0 158 5
amappl16 200 2147 0 2132 5 2 3 5 0 8 1
amappl15 192 11 0 11 2 2 0 1 0 8 0
amappl14 184 413 0 409 1 0 1 1 0 8 0
amappl13 176 120 0 107 1 0 1 1 0 8 0
amappl12 168 786 0 753 2 0 2 2 0 8 0
amappl11 160 6 0 6 1 1 0 1 0 8 0
amappl10 152 59 0 49 1 0 1 1 0 8 0
amappl9 144 270 0 270 1 1 0 1 0 8 0
amappl8 136 99 0 98 1 0 1 1 0 8 0
amappl7 128 147 0 133 1 0 1 1 0 8 0
amappl6 120 149 0 144 1 0 1 1 0 8 0
amappl5 112 99 0 92 1 0 1 1 0 8 0
amappl4 104 273 0 253 1 0 1 1 0 8 0
amappl3 96 2035 0 1937 4 1 3 3 0 8 0
amappl2 88 693 0 615 3 0 3 3 0 8 0
amappl1 80 11674 0 11041 17 0 17 17 0 8 1
amappl 88 3384 0 3222 6 1 5 5 0 92 0
uvmvnodes 80 99 0 0 3 0 3 3 0 8 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 108 0 2 2 0 2 2 0 8 0
uaddrrnd 24 547 0 509 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 547 0 509 1 0 1 1 0 8 0
vmmpekpl 168 6748 0 6703 3 0 3 3 0 8 0
vmmpepl 168 45563 0 43539 109 0 109 109 0 357 11
vmsppl 488 546 0 509 7 1 6 6 0 8 0
rwobjpl 80 16791 0 15642 29 0 29 29 0 8 1
pdppl 4096 1101 0 1018 113 20 93 99 0 8 10
pvpl 32 14681 0 0 119 0 119 119 0 265 0
pmappl 256 546 0 509 4 1 3 3 0 8 0
extentpl 40 46 0 28 1 0 1 1 0 8 0
phpool 112 464 0 23 13 0 13 13 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x27: addq $0x8,%rsp
ddb{0}> trace
x86_ipi_db(ffffffff839d2ff0) at x86_ipi_db+0x27 sys/arch/amd64/amd64/db_interface.c:394
x86_ipi_handler() at x86_ipi_handler+0xd9 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__mp_lock(ffffffff83a10100) at __mp_lock+0x192 __mp_lock_spin sys/kern/kern_lock.c:142 [inline]
__mp_lock(ffffffff83a10100) at __mp_lock+0x192 sys/kern/kern_lock.c:173
intr_handler(ffff80002a20c320,ffff8000002a2900) at intr_handler+0xe9 sys/arch/amd64/amd64/intr.c:560
Xintr_ioapic_edge23_untramp() at Xintr_ioapic_edge23_untramp+0x18f
pagezero() at pagezero+0x33
end trace frame: 0x0, count: -7
ddb{0}> machine ddbcpu 1
Stopped at pool_do_put+0x17c: movq 0x8(%r13),%r13
ddb{1}> trace
pool_do_put(ffffffff83ad09b0,ffff800010fdbab0) at pool_do_put+0x17c sys/kern/subr_pool.c:847
pool_put(ffffffff83ad09b0,ffff800010fdbab0) at pool_put+0xba sys/kern/subr_pool.c:805
soclose(ffff800010fdbab0,0) at soclose+0x752 sys/kern/uipc_socket.c:499
soo_close(fffff3806d7d63e8,ffff800045feea78) at soo_close+0x56 sys/kern/sys_socket.c:-1
fdrop(fffff3806d7d63e8,ffff800045feea78) at fdrop+0x121 sys/kern/kern_descrip.c:1281
closef(fffff3806d7d63e8,ffff800045feea78) at closef+0x192 sys/kern/kern_descrip.c:1265
fdfree(ffff800045feea78) at fdfree+0x116 sys/kern/kern_descrip.c:1196
exit1(ffff800045feea78,0,0,1) at exit1+0x595 sys/kern/kern_exit.c:215
sys_exit(ffff800045feea78,ffff80003c3d6980,ffff80003c3d68d0) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c3d6980) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3d6980) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x76e1462c78c0, count: -11


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages