panic: uvm_fault: fault on non-pageable map (ADDR, ADDR)

3 views
Skip to first unread message

syzbot

unread,
Sep 15, 2019, 11:37:08 PM9/15/19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 4ab68d81 With the recent fixes to SCSI version detection w..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=14d2cace600000
kernel config: https://syzkaller.appspot.com/x/.config?x=d0fe83f82fe104d4
dashboard link: https://syzkaller.appspot.com/bug?extid=e4d924e1c128b88f9558

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+e4d924...@syzkaller.appspotmail.com

a ��]� � {6�?8 �QB��`�`7��.b�\L�] :*���. �[Ծ�e�J��� � �*h���]��P|0͞ 6wm |
ŽF���FD� ��ct��A% �u a ��]� � {6�?8 �QB��`�`7��.b�\L�] :*���. �[Ծ�e�J��� � �*h���]��P|
0͞ 6wm |ŽF���FD� ��ct��A% �u panic: uvm_fault: fault on non-pageable map
(0xffffffff82550fa0, 0xffff800000a90000)
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*168116 96523 0 0 0x4000000 0 syz-executor.1
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:207
uvm_fault(ffffffff825510a0,ffff800000a90000,1,4) at uvm_fault+0x2148
uvmfault_amapcopy sys/uvm/uvm_fault.c:463 [inline]
uvm_fault(ffffffff825510a0,ffff800000a90000,1,4) at uvm_fault+0x2148
sys/uvm/uvm_fault.c:559
pageflttrap() at pageflttrap+0x239 sys/arch/amd64/amd64/trap.c:199
kerntrap(ffff80001777d0b0) at kerntrap+0xdb sys/arch/amd64/amd64/trap.c:287
alltraps_kern_meltdown(6,ffff800017b45000,fffffd802edcc698,11,ffff80000005bfc0,ffff80001777d318)
at
alltraps_kern_meltdown+0x7b
ffff800000a90800(b,ffff80001777d278,83,ffff80001777d318,0,b) at
0xffff800000a90800
rt_match(fffffd803c0495f8,0,1,0) at rt_match+0xbe rt_clone
sys/net/route.c:266 [inline]
rt_match(fffffd803c0495f8,0,1,0) at rt_match+0xbe sys/net/route.c:242
in_pcbselsrc(ffff80001777d3f0,fffffd8036f2b620,fffffd803c049578) at
in_pcbselsrc+0x219 sys/netinet/in_pcb.c:934
in_pcbconnect(fffffd803c049578,fffffd8036f2b600) at in_pcbconnect+0x107
sys/netinet/in_pcb.c:492
udp_usrreq(fffffd802caa3c10,4,0,fffffd8036f2b600,0,ffff8000ffff2508) at
udp_usrreq+0x560
sys_connect(ffff8000ffff2508,ffff80001777d578,ffff80001777d5c0) at
sys_connect+0x3df sys/kern/uipc_syscalls.c:388
syscall(ffff80001777d640) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall(6,0,fffffffffffffed2,0,3,d567358f010) at Xsyscall+0x128
end of kernel
end trace frame: 0xd58c14ed8e0, count: 1
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
uvm_fault: fault on non-pageable map (0xffffffff82550fa0,
0xffff800000a90000)
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic() at panic+0x15c sys/kern/subr_prf.c:207
uvm_fault(ffffffff825510a0,ffff800000a90000,1,4) at uvm_fault+0x2148
uvmfault_amapcopy sys/uvm/uvm_fault.c:463 [inline]
uvm_fault(ffffffff825510a0,ffff800000a90000,1,4) at uvm_fault+0x2148
sys/uvm/uvm_fault.c:559
pageflttrap() at pageflttrap+0x239 sys/arch/amd64/amd64/trap.c:199
kerntrap(ffff80001777d0b0) at kerntrap+0xdb sys/arch/amd64/amd64/trap.c:287
alltraps_kern_meltdown(6,ffff800017b45000,fffffd802edcc698,11,ffff80000005bfc0,ffff80001777d318)
at
alltraps_kern_meltdown+0x7b
ffff800000a90800(b,ffff80001777d278,83,ffff80001777d318,0,b) at
0xffff800000a90800
rt_match(fffffd803c0495f8,0,1,0) at rt_match+0xbe rt_clone
sys/net/route.c:266 [inline]
rt_match(fffffd803c0495f8,0,1,0) at rt_match+0xbe sys/net/route.c:242
in_pcbselsrc(ffff80001777d3f0,fffffd8036f2b620,fffffd803c049578) at
in_pcbselsrc+0x219 sys/netinet/in_pcb.c:934
in_pcbconnect(fffffd803c049578,fffffd8036f2b600) at in_pcbconnect+0x107
sys/netinet/in_pcb.c:492
udp_usrreq(fffffd802caa3c10,4,0,fffffd8036f2b600,0,ffff8000ffff2508) at
udp_usrreq+0x560
sys_connect(ffff8000ffff2508,ffff80001777d578,ffff80001777d5c0) at
sys_connect+0x3df sys/kern/uipc_syscalls.c:388
syscall(ffff80001777d640) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall(6,0,fffffffffffffed2,0,3,d567358f010) at Xsyscall+0x128
end of kernel
end trace frame: 0xd58c14ed8e0, count: -14
ddb> show registers
rdi 0xffffffff81ff91f7 db_enter+0x17
rsi 0x2f9c __ALIGN_SIZE+0x1f9c
rbp 0xffff80001777cce0
rbx 0xffff80001777cd90
rdx 0x2f9d __ALIGN_SIZE+0x1f9d
rcx 0xffff800017b45000
rax 0xffff800017b45000
r8 0xffff80001777cca0
r9 0x1
r10 0xffff800000aa9940
r11 0x96b317386df08257
r12 0x3000000008
r13 0xffff80001777ccf0
r14 0x100
r15 0x1
rip 0xffffffff81ff91f8 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff80001777ccd0
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor.1) pid=168116 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=81, usrpri=81, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff3160,0xffffffff8255a180
process=0xffff8000148950f8 user=0xffff800017778000,
vmspace=0xfffffd803f013000
estcpu=36, cpticks=1, pctcpu=0.0
user=0, sys=1, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
96523 401272 23606 0 2 0 syz-executor.1
*96523 168116 23606 0 7 0x4000000 syz-executor.1
64243 324292 52542 0 3 0x82 nanosleep syz-executor.0
32381 196894 1 0 3 0x100083 ttyin getty
23606 372192 52542 0 3 0x82 nanosleep syz-executor.1
37784 199418 0 0 3 0x14200 acct acct
83909 312058 0 0 3 0x14200 bored sosplice
52542 410293 17233 0 3 0x82 thrsleep syz-fuzzer
52542 333545 17233 0 3 0x4000082 thrsleep syz-fuzzer
52542 72481 17233 0 3 0x4000082 thrsleep syz-fuzzer
52542 235616 17233 0 3 0x4000082 thrsleep syz-fuzzer
52542 335440 17233 0 3 0x4000082 thrsleep syz-fuzzer
52542 352665 17233 0 3 0x4000082 kqread syz-fuzzer
52542 244094 17233 0 3 0x4000082 thrsleep syz-fuzzer
17233 177641 61904 0 3 0x10008a pause ksh
61904 348983 90916 0 3 0x92 select sshd
90916 465496 1 0 3 0x80 select sshd
16798 150593 61434 73 3 0x100090 kqread syslogd
61434 385521 1 0 3 0x100082 netio syslogd
40583 419019 1 77 3 0x100090 poll dhclient
51283 105779 1 0 3 0x80 poll dhclient
47278 518906 0 0 2 0x14200 zerothread
84292 506289 0 0 3 0x14200 aiodoned aiodoned
79280 404504 0 0 3 0x14200 syncer update
78035 138944 0 0 3 0x14200 cleaner cleaner
65220 355501 0 0 3 0x14200 reaper reaper
19561 160562 0 0 3 0x14200 pgdaemon pagedaemon
7774 121324 0 0 3 0x14200 bored crynlk
7665 50490 0 0 3 0x14200 bored crypto
77889 230472 0 0 3 0x40014200 acpi0 acpi0
4552 404739 0 0 3 0x14200 bored softnet
48587 183035 0 0 3 0x14200 bored systqmp
8465 427209 0 0 3 0x14200 bored systq
95004 484426 0 0 3 0x40014200 bored softclock
32771 52644 0 0 3 0x40014200 idle0
87558 488365 0 0 3 0x14200 bored smr
1 453937 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9534 6366K 7129K 78643K 17975 0 0
pcb 13 8K 8K 78643K 285 0 0
rtable 124 8K 8K 78643K 758 0 0
ifaddr 70 16K 16K 78643K 263 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 132 0 0
iov 0 0K 20K 78643K 208 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1218 77K 77K 78643K 3633 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 5K 78643K 50 0 0
VM map 2 0K 0K 78643K 4 0 0
sem 12 0K 0K 78643K 339 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1793 195K 288K 78643K 12645 0 0
file desc 5 13K 25K 78643K 2416 0 0
sigio 0 0K 0K 78643K 34 0 0
proc 49 38K 63K 78643K 689 0 0
subproc 32 2K 2K 78643K 119 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
ip_moptions 0 0K 0K 78643K 250 0 0
in_multi 35 2K 2K 78643K 153 0 0
ether_multi 1 0K 0K 78643K 6 0 0
mrt 0 0K 0K 78643K 12 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 90 397K 397K 78643K 90 0 0
exec 0 0K 1K 78643K 424 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 102 21K 30K 78643K 6530 0 0
UVM aobj 103 3K 3K 78643K 124 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
ip6_options 0 0K 0K 78643K 264 0 0
NDP 15 0K 0K 78643K 77 0 0
temp 191 3536K 3606K 78643K 69975 0 0
kqueue 0 0K 0K 78643K 8 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 14 0 7 1 0 1 1 0
8 0
rtpcb 80 164 0 162 1 0 1 1 0
8 0
rtentry 112 101 0 53 2 0 2 2 0
8 0
unpcb 120 856 0 845 1 0 1 1 0
8 0
syncache 264 5 0 5 2 2 0 1 0
8 0
tcpqe 32 5097 0 5097 1 1 0 1 0
8 0
tcpcb 544 505 0 501 1 0 1 1 0
8 0
inpcb 280 1501 0 1493 1 0 1 1 0
8 0
rttmr 72 3 0 3 3 3 0 1 0
8 0
nd6 48 13 0 9 1 0 1 1 0
8 0
pkpcb 40 4 0 4 1 1 0 1 0
8 0
ppxss 1128 25 0 25 9 8 1 1 0
8 1
art_heap8 4096 4 0 2 2 0 2 2 0
8 0
art_heap4 256 529 0 280 20 4 16 17 0
8 0
art_table 32 533 0 282 4 1 3 3 0
8 0
art_node 16 97 0 54 1 0 1 1 0
8 0
sysvmsgpl 40 27 0 16 1 0 1 1 0
8 0
semapl 112 335 0 325 1 0 1 1 0
8 0
shmpl 112 122 0 21 3 0 3 3 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 5704 0 4290 46 0 46 46 0
8 0
ffsino 240 5704 0 4290 84 0 84 84 0
8 0
nchpl 144 9742 0 8130 60 0 60 60 0
8 0
uvmvnodes 72 5926 0 0 108 0 108 108 0
8 0
vnodes 208 5926 0 0 312 0 312 312 0
8 0
namei 1024 32287 0 32287 3 2 1 1 0
8 1
vmpool 520 2 0 2 1 1 0 1 0
8 0
scsiplug 64 8 0 8 4 3 1 1 0
8 1
scxspl 192 30630 0 30630 18 16 2 7 0
8 2
plimitpl 152 192 0 184 1 0 1 1 0
8 0
sigapl 432 2573 0 2560 2 0 2 2 0
8 0
futexpl 56 51837 0 51837 1 0 1 1 0
8 1
knotepl 112 482 0 463 2 1 1 2 0
8 0
kqueuepl 104 519 0 517 1 0 1 1 0
8 0
pipepl 112 1214 0 1195 5 3 2 2 0
8 1
fdescpl 424 2574 0 2560 2 0 2 2 0
8 0
filepl 120 19270 0 19171 10 5 5 5 0
8 2
lockfpl 104 7339 0 7338 2 1 1 2 0
8 0
lockfspl 48 1177 0 1176 1 0 1 1 0
8 0
sessionpl 112 23 0 13 1 0 1 1 0
8 0
pgrppl 48 34 0 24 1 0 1 1 0
8 0
ucredpl 96 2602 0 2593 1 0 1 1 0
8 0
zombiepl 144 2560 0 2559 3 2 1 1 0
8 0
processpl 864 2590 0 2559 4 0 4 4 0
8 0
procpl 632 5597 0 5559 4 0 4 4 0
8 0
sosppl 128 17 0 17 6 5 1 1 0
8 1
sockpl 384 2558 0 2537 6 3 3 4 0
8 0
mcl64k 65536 44 0 44 11 10 1 1 0
8 1
mcl16k 16384 13 0 13 8 7 1 1 0
8 1
mcl12k 12288 44 0 44 5 4 1 1 0
8 1
mcl9k 9216 25 0 25 8 8 0 1 0
8 0
mcl8k 8192 58 0 58 4 3 1 1 0
8 1
mcl4k 4096 152 0 152 4 3 1 1 0
8 1
mcl2k2 2112 17 0 17 7 6 1 1 0
8 1
mcl2k 2048 57018 0 56975 19 12 7 13 0
8 1
mtagpl 80 151 0 94 3 1 2 2 0
8 0
mbufpl 256 104631 0 104418 22 7 15 16 0
8 0
bufpl 256 14968 0 9372 350 0 350 350 0
8 0
anonpl 16 217885 0 206059 125 63 62 76 0
62 1
amapchunkpl 152 11018 0 10887 29 22 7 11 0
158 1
amappl16 192 12297 0 11485 76 33 43 53 0
8 2
amappl15 184 193 0 192 2 1 1 1 0
8 0
amappl14 176 1706 0 1699 2 1 1 1 0
8 0
amappl13 168 1 0 1 1 1 0 1 0
8 0
amappl12 160 7 0 6 1 0 1 1 0
8 0
amappl11 152 83 0 72 1 0 1 1 0
8 0
amappl10 144 8 0 7 2 1 1 1 0
8 0
amappl9 136 638 0 632 1 0 1 1 0
8 0
amappl8 128 213 0 186 1 0 1 1 0
8 0
amappl7 120 65 0 59 1 0 1 1 0
8 0
amappl6 112 113 0 103 1 0 1 1 0
8 0
amappl5 104 190 0 179 1 0 1 1 0
8 0
amappl4 96 1958 0 1932 1 0 1 1 0
8 0
amappl3 88 1898 0 1891 1 0 1 1 0
8 0
amappl2 80 19648 0 19583 4 2 2 3 0
8 0
amappl1 72 54643 0 54236 26 16 10 20 0
8 0
amappl 80 5896 0 5854 2 0 2 2 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 123 0 21 2 0 2 2 0
8 0
uaddrrnd 24 2576 0 2560 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 2576 0 2560 1 0 1 1 0
8 0
vmmpekpl 168 17794 0 17765 2 0 2 2 0
8 0
vmmpepl 168 300692 0 298833 218 106 112 112 0 357
26
vmsppl 272 2573 0 2560 2 1 1 2 0
8 0
pdppl 4096 5158 0 5124 6 1 5 6 0
8 0
pvpl 32 617807 0 602934 273 110 163 190 0 265
17
pmappl 200 2575 0 2562 1 0 1 1 0
8 0
extentpl 40 41 0 26 1 0 1 1 0
8 0
phpool 112 541 0 52 15 1 14 14 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Anton Lindqvist

unread,
Sep 16, 2019, 3:22:04 AM9/16/19
to syzbot, syzkaller-o...@googlegroups.com
#syz dup: panic: attempt to execute user address 0x0 in supervisor mode
Reply all
Reply to author
Forward
0 new messages