syzbot found the following issue on:
HEAD commit: 2610791609b5 sndiod: In the CTL_SW case, the third ctl_new..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=134d52c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=3fddeb49ebd3bae6a730
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/df7cabe729ab/disk-26107916.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/73cfaba04525/bsd-26107916.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ef4b7f508cad/kernel-26107916.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3fddeb...@syzkaller.appspotmail.com
� ҬJ6 uvm_fault(0xfffffa806cf165d0, 0x98, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at dovutimens+0x368: movl 0x98(%rax),%r12d
--db_more-- TID PID UID PRFLAGS PFLAGS CPU COMMAND
--db_more-- *283988 41538 0 0 0x4000000 0K syz-executor
--db_more-- dovutimens(ffff800031b8aa98,fffffa805fbc8c08,ffff80003c3e4f80) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
--db_more-- sys_futimes(ffff800031b8aa98,ffff80003c3e50d0,ffff80003c3e5020) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
--db_more-- syscall(ffff80003c3e50d0) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
--db_more-- syscall(ffff80003c3e50d0) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xeeb81b89850, count: 11
--db_more-- https://www.openbsd.org/ddb.html describes the minimum info required in bug
--db_more-- reports. Insufficient info makes it difficult to find and fix bugs.
ddb{0}> ines = 0
No such command
ddb{0}> set $maxwidth = 0
ddb{0}> show panic
*cpu0: uvm_fault(0xfffffa806cf165d0, 0x98, 0, 1) -> e
ddb{0}> show kasan
No such command
ddb{0}> trace
dovutimens(ffff800031b8aa98,fffffa805fbc8c08,ffff80003c3e4f80) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
sys_futimes(ffff800031b8aa98,ffff80003c3e50d0,ffff80003c3e5020) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff80003c3e50d0) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3e50d0) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
--db_more-- Xsyscall() at Xsyscall+0x128
--db_more-- end of kernel
--db_more-- end trace frame: 0xeeb81b89850, count: -4
ddb{0}> w registers
Symbol not found
ddb{0}> show proc
PROC (syz-executor) tid=283988 pid=41538 tcnt=2 stat=onproc
flags process=0 proc=4000000<THREAD>
runpri=32, usrpri=50, slppri=32, nice=20
--db_more-- wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
--db_more-- forw=0xffffffffffffffff, list=0xffff800031b8b260,0xffffffff83a94258
--db_more-- process=0xffff80003c400028 user=0xffff80003c3e0000, vmspace=0xfffffa806cf165d0
--db_more-- estcpu=36, cpticks=1, pctcpu=0.0, user=0, sys=1, intr=0
ddb{0}> how all locks
No such command
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11072 12232K 12275K 166960K 12649 0
pcb 19 14K 16K 166960K 256 0
--db_more-- rtable 228 9K 11K 166960K 1106 0
--db_more-- pf 34 17K 37K 166960K 419 0
--db_more-- ifaddr 35 6K 7K 166960K 93 0
--db_more-- ifgroup 47 2K 2K 166960K 135 0
--db_more-- sysctl 3 1K 9K 166960K 13 0
counters 66 36K 37K 166960K 122 0
ioctlops 0 0K 4K 166960K 1973 0
iov 0 0K 16K 166960K 50 0
--db_more-- mount 1 1K 1K 166960K 1 0
--db_more-- log 0 0K 0K 166960K 4 0
--db_more-- vnodes 1385 87K 87K 166960K 2196 0
--db_more-- UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 5K 166960K 11 0
VM map 2 1K 1K 166960K 2 0
--db_more-- sem 12 0K 0K 166960K 34 0
--db_more-- dirhash 12 2K 2K 166960K 12 0
--db_more-- ACPI 1734 201K 291K 166960K 11964 0
--db_more-- file desc 16 57K 97K 166960K 896 0
--db_more-- sigio 0 0K 0K 166960K 8 0
--db_more-- proc 72 115K 180K 166960K 812 0
--db_more-- subproc 72 4K 4K 166960K 135 0
--db_more-- NFS srvsock 1 0K 0K 166960K 1 0
--db_more-- ddb{0}> hine ddbcpu 0
No such command
ddb{0}> trace
dovutimens(ffff800031b8aa98,fffffa805fbc8c08,ffff80003c3e4f80) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
sys_futimes(ffff800031b8aa98,ffff80003c3e50d0,ffff80003c3e5020) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff80003c3e50d0) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3e50d0) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
--db_more-- Xsyscall() at Xsyscall+0x128
--db_more-- end of kernel
--db_more-- ddb{0}> hine ddbcpu 1
No such command
ddb{0}> trace
dovutimens(ffff800031b8aa98,fffffa805fbc8c08,ffff80003c3e4f80) at dovutimens+0x368 sys/kern/vfs_syscalls.c:2691
sys_futimes(ffff800031b8aa98,ffff80003c3e50d0,ffff80003c3e5020) at sys_futimes+0x208 sys/kern/vfs_syscalls.c:2733
syscall(ffff80003c3e50d0) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3e50d0) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup