panic: free: unaligned addr ADDR, size NUM, type ip_moptions, mask NUM

0 views
Skip to first unread message

syzbot

unread,
Aug 6, 2026, 6:46:38 PM (11 days ago) Aug 6
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 07df0a216fc9 remove some include statements linux dropped
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11d83e49580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=5f02f0f5f414e5607049

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/9dc4656ce59d/disk-07df0a21.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/4ec49fa41acd/bsd-07df0a21.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/90b2fd56dd38/kernel-07df0a21.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5f02f0...@syzkaller.appspotmail.com

panic: free: unaligned addr 0xffff80000161000b, size 8192, type ip_moptions, mask 4095
Stopped at db_enter+0x25: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
239363 36817 0 0x14000 0x200 1 reaper
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834aea04) at panic+0x1e5 sys/kern/subr_prf.c:198
free(ffff80000161000b,35,0) at free+0x6e8 sys/kern/kern_malloc.c:390
ip_freemoptions(ffff800000c439d0) at ip_freemoptions+0xea sys/netinet/ip_output.c:1744
in_pcbdetach(ffffef006fed3a40) at in_pcbdetach+0xec sys/netinet/in_pcb.c:605
udp_detach(ffff800001639ac8) at udp_detach+0x5a sys/netinet/udp_usrreq.c:1158
soclose(ffff800001639ac8,0) at soclose+0xb0 pru_detach sys/sys/protosw.h:281 [inline]
soclose(ffff800001639ac8,0) at soclose+0xb0 sys/kern/uipc_socket.c:403
soo_close(ffffef006d0e80d8,ffff80003c400d20) at soo_close+0x56 sys/kern/sys_socket.c:-1
fdrop(ffffef006d0e80d8,ffff80003c400d20) at fdrop+0x121 sys/kern/kern_descrip.c:1281
closef(ffffef006d0e80d8,ffff80003c400d20) at closef+0x192 sys/kern/kern_descrip.c:1265
fdfree(ffff80003c400d20) at fdfree+0x116 sys/kern/kern_descrip.c:1196
exit1(ffff80003c400d20,0,0,1) at exit1+0x595 sys/kern/kern_exit.c:215
sys_exit(ffff80003c400d20,ffff80003c3e1030,ffff80003c3e0f80) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c3e1030) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3e1030) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
end trace frame: 0xffff80003c3e10b0, count: 0
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb{0}>
ddb{0}> set $lines = 0
ddb{0}> set $maxwidth = 0
ddb{0}> show panic
*cpu0: free: unaligned addr 0xffff80000161000b, size 8192, type ip_moptions, mask 4095
ddb{0}> show kasan
No such command
ddb{0}> trace
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834aea04) at panic+0x1e5 sys/kern/subr_prf.c:198
free(ffff80000161000b,35,0) at free+0x6e8 sys/kern/kern_malloc.c:390
ip_freemoptions(ffff800000c439d0) at ip_freemoptions+0xea sys/netinet/ip_output.c:1744
in_pcbdetach(ffffef006fed3a40) at in_pcbdetach+0xec sys/netinet/in_pcb.c:605
udp_detach(ffff800001639ac8) at udp_detach+0x5a sys/netinet/udp_usrreq.c:1158
soclose(ffff800001639ac8,0) at soclose+0xb0 pru_detach sys/sys/protosw.h:281 [inline]
soclose(ffff800001639ac8,0) at soclose+0xb0 sys/kern/uipc_socket.c:403
soo_close(ffffef006d0e80d8,ffff80003c400d20) at soo_close+0x56 sys/kern/sys_socket.c:-1
fdrop(ffffef006d0e80d8,ffff80003c400d20) at fdrop+0x121 sys/kern/kern_descrip.c:1281
closef(ffffef006d0e80d8,ffff80003c400d20) at closef+0x192 sys/kern/kern_descrip.c:1265
fdfree(ffff80003c400d20) at fdfree+0x116 sys/kern/kern_descrip.c:1196
exit1(ffff80003c400d20,0,0,1) at exit1+0x595 sys/kern/kern_exit.c:215
sys_exit(ffff80003c400d20,ffff80003c3e1030,ffff80003c3e0f80) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c3e1030) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3e1030) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x73e3770b3380, count: -15
ddb{0}> show registers
rdi 0
rsi 0x1
rbp 0xffff80003c3e0b20
rbx 0xffffffff83916e07 cpu_info_full_primary+0x2e07
rdx 0
rcx 0xffff80003c400d20
rax 0xffffffff83915ff0 cpu_info_full_primary+0x1ff0
r8 0x101010101010101
r9 0x8080808080808080
r10 0x195fda01b3864347
r11 0xe23606005b932509
r12 0xffffffff83916c08 cpu_info_full_primary+0x2c08
r13 0
r14 0
r15 0x1
rip 0xffffffff814ae3c5 db_enter+0x25
cs 0x8
rflags 0x246
rsp 0xffff80003c3e0b10
ss 0x10
db_enter+0x25: addq $0x8,%rsp
ddb{0}> show proc
PROC (syz-executor) tid=66314 pid=94671 tcnt=0 stat=onproc
flags process=1018<EXITING,SUGID,SINGLEEXIT> proc=2000<WEXIT>
runpri=32, usrpri=78, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0xffff80003c400d20 scnt=-1 ecnt=1
forw=0xffffffffffffffff, list=0xffff80003c4014e8,0xffffffff83a188f8
process=0xffff800045feb508 user=0xffff80003c3dc000, vmspace=0xffffef000f95b7d0
estcpu=28, cpticks=7, pctcpu=0.0, user=0, sys=1, intr=0
ddb{0}> ps
PID TID PPID UID S PRLAGS PFLAGS WAIT COMMAND
9193 19059 32318 0 3 0x100002 0x80 sbwait arp
32318 449238 1652 0 3 0x100002 0x88 sigsusp sh
3653 57346 75177 32767 3 0x10 0x80 nanoslp syz-executor
67405 346261 46010 32767 3 0x10 0x80 piperd syz-executor
35255 221926 38377 32767 3 0x10 0x80 nanoslp syz-executor
937 83781 59815 32767 3 0x10 0x80 piperd syz-executor
44133 217862 16361 32767 3 0x10 0x80 piperd syz-executor
1652 431452 55667 0 3 0 0x80 wait syz-executor
69513 12287 87855 32767 3 0x10 0x80 piperd syz-executor
38377 359278 64362 0 3 0x2 0x80 wait syz-executor
59815 262063 64362 0 3 0x2 0x80 wait syz-executor
16361 489712 64362 0 3 0x2 0x80 wait syz-executor
55667 262596 64362 0 3 0x2 0x80 wait syz-executor
46010 251885 64362 0 3 0x2 0x80 wait syz-executor
75177 82311 64362 0 3 0x2 0x80 wait syz-executor
87855 430080 64362 0 3 0x2 0x80 wait syz-executor
64362 311915 617 0 3 0x2 0x80 nanoslp syz-executor
617 445666 49761 0 3 0x100002 0x88 sigsusp ksh
49761 343611 50355 0 3 0x10 0x88 kqread sshd-session
50355 365185 64030 0 3 0x12 0x80 kqread sshd-session
59305 308892 1 0 3 0x100003 0x80 ttyin getty
64030 395699 1 0 3 0 0x88 kqread sshd
23360 361597 176 73 3 0x1100010 0x80 kqread syslogd
176 124301 1 0 3 0x100002 0x80 sbwait syslogd
33634 35211 1 0 3 0x100000 0x80 kqread resolvd
40106 430950 5439 77 3 0x100012 0x80 kqread dhcpleased
19247 366765 5439 77 3 0x100012 0x80 kqread dhcpleased
5439 221648 1 0 3 0 0x80 kqread dhcpleased
82826 434556 0 0 3 0x14000 0x200 bored smr
52770 285321 0 0 3 0x14000 0x200 pgzero zerothread
88913 258652 0 0 3 0x14000 0x200 aiodoned aiodoned
3011 44351 0 0 3 0x14000 0x200 syncer update
63774 215300 0 0 3 0x14000 0x200 cleaner cleaner
36817 239363 0 0 7 0x14000 0x200 reaper
97479 438941 0 0 3 0x14000 0x200 pgdaemon pagedaemon
2566 404649 0 0 3 0x14000 0x200 bored viomb
29175 65507 0 0 3 0x14000 0x40000200 acpi0 acpi0
43001 45335 0 0 3 0x14000 0x40000200 idle1
97232 99573 0 0 3 0x14000 0x200 bored softnet1
54903 58425 0 0 3 0x14000 0x200 bored softnet0
17451 366496 0 0 3 0x14000 0x200 bored systqmp
95612 467984 0 0 3 0x14000 0x200 bored systq
57344 319522 0 0 3 0x14000 0x200 tmoslp softclockmp
92672 16486 0 0 3 0x14000 0x40000200 tmoslp softclock
57866 353593 0 0 3 0x14000 0x40000200 idle0
1 494588 0 0 3 0x2 0x80 wait init
0 0 -1 0 3 0x10000 0x200 scheduler swapper
ddb{0}> show all locks
CPU 0:
exclusive mutex /syzkaller/managers/setuid/kernel/sys/kern/kern_malloc.c:96 r = 0 (0xffffffff83994138)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 mtx_enter+0x4b4 sys/kern/kern_lock.c:487
#2 free+0x9f sys/kern/kern_malloc.c:393
#3 ip_freemoptions+0xea sys/netinet/ip_output.c:1744
#4 in_pcbdetach+0xec sys/netinet/in_pcb.c:605
#5 udp_detach+0x5a sys/netinet/udp_usrreq.c:1158
#6 soclose+0xb0 pru_detach sys/sys/protosw.h:281 [inline]
#6 soclose+0xb0 sys/kern/uipc_socket.c:403
#7 soo_close+0x56 sys/kern/sys_socket.c:-1
#8 fdrop+0x121 sys/kern/kern_descrip.c:1281
#9 closef+0x192 sys/kern/kern_descrip.c:1265
#10 fdfree+0x116 sys/kern/kern_descrip.c:1196
#11 exit1+0x595 sys/kern/kern_exit.c:215
#12 sys_exit+0x1a sys/kern/kern_exit.c:-1
#13 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#13 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#14 Xsyscall+0x128
Process 36817 (reaper) thread 0xffff800045ffd230 (239363)
exclusive rwlock kmmaplk r = 0 (0xffffffff83a4de88)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 vm_map_lock_ln+0x12e sys/uvm/uvm_map.c:5170
#3 uvm_unmap+0x7d sys/uvm/uvm_map.c:1798
#4 km_free+0x85 sys/uvm/uvm_km.c:714
#5 uvm_uarea_free+0x4f sys/uvm/uvm_glue.c:304
#6 reaper+0x1ca sys/kern/kern_exit.c:495
#7 proc_trampoline+0x10
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11047 12016K 12034K 166960K 12141 0
pcb 17 12K 12K 166960K 17 0
rtable 199 5K 6K 166960K 339 0
pf 29 16K 16K 166960K 31 0
ifaddr 36 6K 7K 166960K 42 0
ifgroup 46 2K 2K 166960K 50 0
sysctl 3 1K 9K 166960K 8 0
counters 68 36K 37K 166960K 70 0
ioctlops 0 0K 4K 166960K 35 0
iov 0 0K 16K 166960K 11 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1288 81K 81K 166960K 1595 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 5K 166960K 11 0
VM map 2 1K 1K 166960K 2 0
sem 12 0K 1K 166960K 52 0
dirhash 12 2K 2K 166960K 15 0
ACPI 1734 201K 291K 166960K 11964 0
file desc 20 73K 125K 166960K 417 0
sigio 0 0K 0K 166960K 2 0
proc 58 99K 147K 166960K 523 0
subproc 63 3K 4K 166960K 243 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 2 0K 0K 166960K 48 0
in_multi 78 5K 6K 166960K 103 0
ether_multi 1 0K 0K 166960K 6 0
mrt 1 0K 0K 166960K 14 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 61 281K 281K 166960K 61 0
exec 0 0K 1K 166960K 420 0
fusefs mount 1 32K 32K 166960K 1 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 211 161K 187K 166960K 5235 0
UVM aobj 17 2K 2K 166960K 19 0
pinsyscall 42 84K 112K 166960K 1538 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 0K 166960K 8 0
NDP 10 0K 1K 166960K 25 0
temp 68 9127K 9147K 166960K 4665 0
kqueue 13 20K 27K 166960K 85 0
SYN cache 2 16K 16K 166960K 2 0
ddb{0}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 28 0 0 1 0 1 1 0 8 0
rtpcb 120 114 0 110 3 2 1 3 0 8 0
rtentry 176 103 0 12 5 0 5 5 0 8 0
unpcb 144 179 0 164 1 0 1 1 0 8 0
syncache 336 9 0 9 1 0 1 1 0 8 1
tcpqe 32 1 0 1 1 1 0 1 0 8 0
tcpcb 736 79 0 73 1 0 1 1 0 8 0
arp 136 17 0 2 1 0 1 1 0 8 0
inpcb 328 267 0 257 4 0 4 4 0 8 3
ip6q 72 1 0 1 1 1 0 1 0 8 0
ip6af 40 2 0 2 1 1 0 1 0 8 0
nd6 152 21 0 3 1 0 1 1 0 8 0
kcovpl 48 27 0 20 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 411 0 44 26 2 24 26 0 8 0
art_table 40 412 0 44 5 0 5 5 0 8 0
art_node 32 103 0 20 1 0 1 1 0 8 0
sysvmsgpl 40 3 0 2 1 0 1 1 0 8 0
semupl 112 1 0 1 1 1 0 1 0 8 0
semapl 72 49 0 39 1 0 1 1 0 8 0
shmpl 112 16 0 2 1 0 1 1 0 8 0
dirhash 1024 19 0 2 3 0 3 3 0 8 0
dino2pl 256 1931 0 446 93 0 93 93 0 8 0
ffsino 296 1931 0 446 115 0 115 115 0 8 0
nchpl 144 2430 0 722 64 0 64 64 0 8 0
vnodes 216 2183 0 0 122 0 122 122 0 8 0
namei 1024 7730 0 7730 1 0 1 1 0 8 1
percpumem 16 51 0 1 1 0 1 1 0 8 0
kstatmem 264 25 0 2 2 0 2 2 0 8 0
scxspl 216 8364 0 8364 11 3 8 8 1 8 8
plimitpl 152 95 0 73 2 1 1 2 0 8 0
sigapl 424 683 0 635 7 0 7 7 0 8 0
knotepl 120 289 0 0 9 0 9 9 0 8 0
kqueuepl 224 91 0 82 1 0 1 1 0 8 0
pipepl 344 204 0 177 3 0 3 3 0 8 0
fdescpl 528 667 0 635 4 0 4 4 0 8 0
filepl 160 3202 0 3003 12 1 11 12 0 8 1
lockfpl 104 60 0 58 1 0 1 1 0 8 0
lockfspl 48 27 0 25 1 0 1 1 0 8 0
sessionpl 144 53 0 38 1 0 1 1 0 8 0
pgrppl 48 146 0 124 1 0 1 1 0 8 0
ucredpl 104 512 0 495 1 0 1 1 0 8 0
zombiepl 144 637 0 635 1 0 1 1 0 8 0
processpl 1232 683 0 635 5 0 5 5 0 8 0
procpl 664 1034 0 986 6 0 6 6 0 8 0
sockpl 752 564 0 535 12 5 7 10 0 8 3
mcl64k 65536 5 0 0 1 0 1 1 0 8 0
mcl16k 16384 1 0 0 1 0 1 1 0 8 0
mcl8k 8192 3 0 0 1 0 1 1 0 8 0
mcl4k 4096 121 0 0 16 0 16 16 0 8 0
mcl2k2 2112 1 0 0 1 0 1 1 0 8 0
mcl2k 2048 27 0 0 4 0 4 4 0 8 0
mextrefs 64 26 0 0 1 0 1 1 0 8 0
mtagpl 96 3 0 0 1 0 1 1 0 8 0
mbufpl 256 1203 0 0 75 0 75 75 0 8 0
bufpl 272 2800 0 104 180 0 180 180 0 8 0
anonpl 32 7714 0 0 63 0 63 63 0 247 0
amapchunkpl 152 15813 0 15399 32 5 27 32 0 158 6
amappl16 200 1578 0 1562 4 2 2 4 0 8 0
amappl15 192 34 0 34 1 1 0 1 0 8 0
amappl14 184 406 0 404 1 0 1 1 0 8 0
amappl13 176 124 0 113 1 0 1 1 0 8 0
amappl12 168 903 0 873 2 0 2 2 0 8 0
amappl11 160 6 0 5 1 0 1 1 0 8 0
amappl10 152 58 0 48 1 0 1 1 0 8 0
amappl9 144 276 0 275 1 0 1 1 0 8 0
amappl8 136 95 0 94 1 0 1 1 0 8 0
amappl7 128 144 0 132 1 0 1 1 0 8 0
amappl6 120 143 0 141 1 0 1 1 0 8 0
amappl5 112 101 0 94 1 0 1 1 0 8 0
amappl4 104 273 0 257 1 0 1 1 0 8 0
amappl3 96 2603 0 2522 4 1 3 3 0 8 0
amappl2 88 832 0 759 2 0 2 2 0 8 0
amappl1 80 12465 0 11896 16 2 14 16 0 8 0
amappl 88 4462 0 4319 5 0 5 5 0 92 0
uvmvnodes 80 104 0 0 3 0 3 3 0 8 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 18 0 2 1 0 1 1 0 8 0
uaddrrnd 24 667 0 635 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 667 0 635 1 0 1 1 0 8 0
vmmpekpl 168 7981 0 7942 3 0 3 3 0 8 0
vmmpepl 168 52315 0 50527 103 6 97 103 0 357 8
vmsppl 488 666 0 635 7 1 6 6 0 8 0
rwobjpl 80 17643 0 16701 24 2 22 24 0 8 0
pdppl 4096 1341 0 1270 119 36 83 97 0 8 12
pvpl 32 15615 0 0 126 0 126 126 0 265 0
pmappl 256 666 0 635 4 1 3 3 0 8 0
extentpl 40 46 0 28 1 0 1 1 0 8 0
phpool 112 530 0 41 14 0 14 14 0 8 0
ddb{0}> machine ddbcpu 0
Invalid cpu 0
ddb{0}> trace
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834aea04) at panic+0x1e5 sys/kern/subr_prf.c:198
free(ffff80000161000b,35,0) at free+0x6e8 sys/kern/kern_malloc.c:390
ip_freemoptions(ffff800000c439d0) at ip_freemoptions+0xea sys/netinet/ip_output.c:1744
in_pcbdetach(ffffef006fed3a40) at in_pcbdetach+0xec sys/netinet/in_pcb.c:605
udp_detach(ffff800001639ac8) at udp_detach+0x5a sys/netinet/udp_usrreq.c:1158
soclose(ffff800001639ac8,0) at soclose+0xb0 pru_detach sys/sys/protosw.h:281 [inline]
soclose(ffff800001639ac8,0) at soclose+0xb0 sys/kern/uipc_socket.c:403
soo_close(ffffef006d0e80d8,ffff80003c400d20) at soo_close+0x56 sys/kern/sys_socket.c:-1
fdrop(ffffef006d0e80d8,ffff80003c400d20) at fdrop+0x121 sys/kern/kern_descrip.c:1281
closef(ffffef006d0e80d8,ffff80003c400d20) at closef+0x192 sys/kern/kern_descrip.c:1265
fdfree(ffff80003c400d20) at fdfree+0x116 sys/kern/kern_descrip.c:1196
exit1(ffff80003c400d20,0,0,1) at exit1+0x595 sys/kern/kern_exit.c:215
sys_exit(ffff80003c400d20,ffff80003c3e1030,ffff80003c3e0f80) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c3e1030) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c3e1030) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x73e3770b3380, count: -15
ddb{0}> machine ddbcpu 1
Stopped at x86_ipi_db+0x27: addq $0x8,%rsp
x86_ipi_db(ffff80002999dff0) at x86_ipi_db+0x27 sys/arch/amd64/amd64/db_interface.c:394
x86_ipi_handler() at x86_ipi_handler+0xd9 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__sanitizer_cov_trace_const_cmp4(0,0) at __sanitizer_cov_trace_const_cmp4+0x35 kd_curproc sys/dev/kcov.c:585 [inline]
__sanitizer_cov_trace_const_cmp4(0,0) at __sanitizer_cov_trace_const_cmp4+0x35 sys/dev/kcov.c:230
mtx_enter(ffffffff839af4d0) at mtx_enter+0x5a sys/kern/kern_lock.c:-1
msleep_nsec(ffffffff839af508,ffffffff839af4d0,4,ffffffff834d5a2d,ffffffffffffffff) at msleep_nsec+0x2d3 sys/kern/kern_synch.c:209
reaper(ffff800045ffd230) at reaper+0x15b sys/kern/kern_exit.c:479
end trace frame: 0x0, count: 8
ddb{1}> trace
x86_ipi_db(ffff80002999dff0) at x86_ipi_db+0x27 sys/arch/amd64/amd64/db_interface.c:394
x86_ipi_handler() at x86_ipi_handler+0xd9 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__sanitizer_cov_trace_const_cmp4(0,0) at __sanitizer_cov_trace_const_cmp4+0x35 kd_curproc sys/dev/kcov.c:585 [inline]
__sanitizer_cov_trace_const_cmp4(0,0) at __sanitizer_cov_trace_const_cmp4+0x35 sys/dev/kcov.c:230
mtx_enter(ffffffff839af4d0) at mtx_enter+0x5a sys/kern/kern_lock.c:-1
msleep_nsec(ffffffff839af508,ffffffff839af4d0,4,ffffffff834d5a2d,ffffffffffffffff) at msleep_nsec+0x2d3 sys/kern/kern_synch.c:209
reaper(ffff800045ffd230) at reaper+0x15b sys/kern/kern_exit.c:479
end trace frame: 0x0, count: -7


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages