NetBSD-Syzbot archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: MSan: Uninitialized Memory in uiomove



Hello,

syzbot tried to test the proposed patch but the build/boot failed:

| / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | +3159712/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ +1034592| / - \ | /  [1510368- \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ +976997| / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | ]=0x6a5feb0
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | Loading /var/db/entropy-file  
[   1.0000000] cpu_rng: rdrand/rdseed
[   1.0000000] entropy: ready
[   1.0000000] entropy: entering seed from bootloader with 256 bits of entropy
[   1.0000000] ksyms: checking .text
[   1.0000000] ksyms: checking .rodata.hotpatch
[   1.0000000] ksyms: checking .rodata
[   1.0000000] ksyms: checking link_set_x86_hotpatch_descriptors
[   1.0000000] ksyms: checking link_set_sdt_providers_set
[   1.0000000] ksyms: checking link_set_sdt_probes_set
[   1.0000000] ksyms: checking link_set_sdt_argtypes_set
[   1.0000000] ksyms: checking link_set_modules
[   1.0000000] ksyms: checking link_set_sysctl_funcs
[   1.0000000] ksyms: checking link_set_acpi_device_calls
[   1.0000000] ksyms: checking link_set_evcnts
[   1.0000000] ksyms: checking link_set_linux_module_param_info
[   1.0000000] ksyms: checking link_set_linux_module_param_desc
[   1.0000000] ksyms: checking link_set_domains
[   1.0000000] ksyms: checking link_set_ieee80211_funcs
[   1.0000000] ksyms: checking link_set_ah_chips
[   1.0000000] ksyms: checking link_set_ah_rfs
[   1.0000000] ksyms: checking link_set_dkwedge_methods
[   1.0000000] ksyms: checking link_set_prop_linkpools
[   1.0000000] ksyms: checking .data
[   1.0000000] ksyms: checking .data.cacheline_aligned
[   1.0000000] ksyms: checking .data.read_mostly
[   1.0000000] ksyms: checking .bss
[   1.0000000] ksyms: checking .note.netbsd.ident
[   1.0000000] ksyms: checking .note.Xen
[   1.0000000] ksyms: checking .ident
[   1.0000000] ksyms: checking .comment
[   1.0000000] ksyms: checking .gnu_debuglink
[   1.0000000] ksyms: checking .symtab
[   1.0000000] ksyms: checking .strtab
[   1.0000000] ksyms: checking .shstrtab
[   1.0000000] Loaded initial symtab at 0xffffffff86a00a68, strtab at 0xffffffff86b71648, # entries 62932
[   1.0000000] Copyright (c) 1996, 1997, 1998, 1999, 2000, 2001, 2002, 2003, 2004, 2005,
[   1.0000000]     2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017,
[   1.0000000]     2018, 2019, 2020, 2021, 2022
[   1.0000000]     The NetBSD Foundation, Inc.  All rights reserved.
[   1.0000000] Copyright (c) 1982, 1986, 1989, 1991, 1993
[   1.0000000]     The Regents of the University of California.  All rights reserved.

[   1.0000000] NetBSD 9.99.98 (GENERIC_SYZKALLER) #0: Mon Jul  4 16:03:54 UTC 2022
[   1.0000000] 	root@ci2:/syzkaller/jobs/netbsd/kernel/sys/arch/amd64/compile/obj/GENERIC_SYZKALLER
[   1.0000000] total memory = 8191 MB
[   1.0000000] avail memory = 4044 MB
[   1.0000030] mainbus0 (root)
[   1.0000030] ACPI: RSDP 0x00000000000F2740 000014 (v00 Google)
[   1.0000030] ACPI: RSDT 0x00000000BFFFFF90 000038 (v01 Google GOOGRSDT 00000001 GOOG 00000001)
[   1.0000030] ACPI: FACP 0x00000000BFFFF330 0000F4 (v02 Google GOOGFACP 00000001 GOOG 00000001)
[   1.0000030] ACPI: DSDT 0x00000000BFFFD8C0 001A64 (v01 Google GOOGDSDT 00000001 GOOG 00000001)
[   1.0000030] ACPI: FACS 0x00000000BFFFD880 000040
[   1.0000030] ACPI: SRAT 0x00000000BFFFFE60 0000C8 (v03 Google GOOGSRAT 00000001 GOOG 00000001)
[   1.0000030] ACPI: APIC 0x00000000BFFFFDB0 000076 (v05 Google GOOGAPIC 00000001 GOOG 00000001)
[   1.0000030] ACPI: SSDT 0x00000000BFFFF430 000980 (v01 Google GOOGSSDT 00000001 GOOG 00000001)
[   1.0000030] ACPI: WAET 0x00000000BFFFFE30 000028 (v01 Google GOOGWAET 00000001 GOOG 00000001)
[   1.0000030] ACPI: 2 ACPI AML tables successfully acquired and loaded
[   1.0000030] ioapic0 at mainbus0 apid 0
[   1.0000030] cpu0 at mainbus0 apid 0
[   1.0000030] cpu0: Intel(R) Xeon(R) CPU @ 2.20GHz, id 0x406f0
[   1.0000030] cpu0: node 0, package 0, core 0, smt 0
[   1.0000030] cpu1 at mainbus0 apid 1
[   1.0000030] cpu1: Intel(R) Xeon(R) CPU @ 2.20GHz, id 0x406f0
[   1.0000030] cpu1: node 0, package 0, core 0, smt 1
[   1.0000030] acpi0 at mainbus0: Intel ACPICA 20211217
[   1.0000030] acpi0: fixed power button present
[   1.0000030] acpi0: fixed sleep button present
[   1.0061940] pckbc1 at acpi0 (KBD, PNP0303) (kbd port): io 0x60,0x64 irq 1
[   1.0061940] pckbc2 at acpi0 (MOU, PNP0F13) (aux port): irq 12
[   1.0061940] com0 at acpi0 (COM1, PNP0501-1): io 0x3f8-0x3ff irq 4
[   1.0061940] com: ns16550a, 16-byte FIFO
[   1.0061940] com0: console
[   1.0061940] com1 at acpi0 (COM2, PNP0501-2): io 0x2f8-0x2ff irq 3
[   1.0061940] com1: ns16550a, 16-byte FIFO
[   1.0061940] com2 at acpi0 (COM3, PNP0501-3): io 0x3e8-0x3ef irq 6
[   1.0061940] com2: ns16550a, 16-byte FIFO
[   1.0061940] com3 at acpi0 (COM4, PNP0501-4): io 0x2e8-0x2ef irq 7
[   1.0061940] com3: ns16550a, 16-byte FIFO
[   1.0061940] PEVT (QEMU0001) at acpi0 not configured
[   1.0061940] ACPI: Enabled 16 GPEs in block 00 to 0F
[   1.0061940] pckbd0 at pckbc1 (kbd slot)
[   1.0061940] pckbc1: using irq 1 for kbd slot
[   1.0061940] wskbd0 at pckbd0 mux 1
[   1.0061940] pms0 at pckbc1 (aux slot)
[   1.0061940] pckbc1: using irq 12 for aux slot
[   1.0061940] wsmouse0 at pms0 mux 0
[   1.0061940] pci0 at mainbus0 bus 0: configuration mode 1
[   1.0061940] pchb0 at pci0 dev 0 function 0: Intel 82441FX (PMC) PCI and Memory Controller (rev. 0x02)
[   1.0061940] pcib0 at pci0 dev 1 function 0: Intel 82371AB (PIIX4) PCI-ISA Bridge (rev. 0x03)
[   1.0061940] piixpm0 at pci0 dev 1 function 3: Intel 82371AB (PIIX4) Power Management Controller (rev. 0x03)
[   1.0061940] piixpm0: SMBus disabled
[   1.0061940] virtio0 at pci0 dev 3 function 0
[   1.0061940] virtio0: SCSI device (rev. 0x00)
[   1.0061940] vioscsi0 at virtio0: features: 0
[   1.0061940] vioscsi0: cmd_per_lun 256 qsize 8192 seg_max 64 max_target 253 max_lun 1
[   1.0061940] virtio0: config interrupting at msix0 vec 0
[   1.0061940] virtio0: queues interrupting at msix0 vec 1
[   1.0061940] scsibus0 at vioscsi0: 254 targets, 2 luns per target
[   1.0061940] virtio1 at pci0 dev 4 function 0
[   1.0061940] virtio1: network device (rev. 0x00)
[   1.0061940] vioif0 at virtio1: features: 0x20030020<EVENT_IDX,CTRL_VQ,STATUS,MAC>
[   1.0061940] vioif0: Ethernet address 42:01:0a:80:00:98
[   1.0061940] virtio1: config interrupting at msix1 vec 0
[   1.0061940] virtio1: queues interrupting at msix1 vec 1
[   1.0061940] genfb0 at pci0 dev 5 function 0: vendor 1ae0 product a002 (rev. 0x01)
[   1.0061940] virtio2 at pci0 dev 6 function 0
[   1.0061940] virtio2: memory balloon device (rev. 0x00)
[   1.0061940] viomb0 at virtio2: features: 0x1<MUST_TELL_HOST>
[   1.0061940] virtio2: interrupting at ioapic0 pin 10
[   1.0061940] virtio3 at pci0 dev 7 function 0
[   1.0061940] virtio3: entropy device (rev. 0x00)
[   1.0061940] viornd0 at virtio3: features: 0
[   1.0061940] virtio3: interrupting at ioapic0 pin 11
[   1.0061940] isa0 at pcib0
[   1.0061940] attimer0 at isa0 port 0x40-0x43
[   1.0061940] pcppi0 at isa0 port 0x61
[   1.0061940] spkr0 at pcppi0: PC Speaker
[   1.0061940] wsbell at spkr0 not configured
[   1.0061940] midi0 at pcppi0: PC speaker
[   1.0061940] sysbeep0 at pcppi0
[   1.0061940] attimer0: attached to pcppi0
[   1.0061940] acpicpu0 at cpu0: ACPI CPU
[   1.0061940] acpicpu1 at cpu1: ACPI CPU
[   1.8657991] cpu0 has 2 core siblings: cpu1 cpu0
[   1.8657991] cpu0 has 2 pkg siblings: cpu1 cpu0
[   1.8773360] cpu0 has 1 1st siblings: cpu0
[   1.8773360] cpu0 first in package: cpu0
[   1.8861910] cpu1 has 2 core siblings: cpu0 cpu1
[   1.8861910] cpu1 has 2 pkg siblings: cpu0 cpu1
[   1.8861910] cpu1 has 1 1st siblings: cpu0
[   1.8985379] cpu1 first in package: cpu0
[   2.0633039] sd0 at scsibus0 target 1 lun 0: <Google, PersistentDisk, 1> disk fixed
[   2.0733235] sd0: fabricating a geometry
[   2.0733235] sd0: 2048 MB, 2048 cyl, 64 head, 32 sec, 512 bytes/sect x 4194304 sectors
[   2.0861913] sd0: fabricating a geometry
[   2.1333010] dk0 at sd0: "49b813d1-8009-4c4f-b3e1-2cc288366ecc", 2097085 blocks at 64, type: ffs
[   2.1511581] dk1 at sd0: "2a5f9479-33b7-499d-8cc4-f8d9ae0937b7", 2097119 blocks at 2097152, type: swap
[   2.1609583] sd0: async, 8-bit transfers, tagged queueing
[   2.7632953] usb0 at vhci0: USB revision 2.0
[   2.7933584] uhub0 at usb0: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   3.3132991] usb1 at vhci1: USB revision 2.0
[   3.3433339] uhub1 at usb1: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   3.8733058] usb2 at vhci2: USB revision 2.0
[   3.8933469] uhub2 at usb2: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   4.4132953] usb3 at vhci3: USB revision 2.0
[   4.4333479] uhub3 at usb3: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   4.9632941] usb4 at vhci4: USB revision 2.0
[   4.9833434] uhub4 at usb4: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   5.5032994] usb5 at vhci5: USB revision 2.0
[   5.5333316] uhub5 at usb5: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   6.0633000] usb6 at vhci6: USB revision 2.0
[   6.0833583] uhub6 at usb6: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   6.6032874] usb7 at vhci7: USB revision 2.0
[   6.6333317] uhub7 at usb7: NetBSD (0x0000) VHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 1
[   6.7732826] boot device: sd0
[   6.7732826] root on dk0 dumps on dk1
[   6.7833127] dump_misc_init: max_paddr = 0x240000000
[   6.7952901] mountroot: trying lfs...
[   6.8036204] mountroot: trying ffs...
[   6.8233213] root file system type: ffs
[   6.8332830] kern.module.path=/stand/amd64/9.99.98/modules
[   6.8332830] clock: unknown CMOS layout
[   6.8833491] init: copying out path `/sbin/init' 11
Mon Jul  4 16:07[   7.7633331] panic: kernel diagnostic assertion "error" failed: file "/syzkaller/jobs/netbsd/kernel/sys/kern/tty.c", line 2281 
:44 UTC 2022
[   7.7799243] cpu0: Begin traceback...
[   7.7832739] vpanic() at netbsd:vpanic+0xc9d
[   7.8132774] kern_assert() at netbsd:kern_assert+0x228
[   7.8332779] ttwrite() at netbsd:ttwrite+0x28f9
[   7.8632806] comwrite() at netbsd:comwrite+0x208
[   7.8932835] cdev_write() at netbsd:cdev_write+0x2e0
[   7.9132782] cnwrite() at netbsd:cnwrite+0x1bf
[   7.9432799] cdev_write() at netbsd:cdev_write+0x2e0
[   7.9632774] spec_write() at netbsd:spec_write+0x561
[   7.9932819] VOP_WRITE() at netbsd:VOP_WRITE+0x39b
[   8.0232792] vn_write() at netbsd:vn_write+0x709
[   8.0532781] dofilewrite() at netbsd:dofilewrite+0x360
[   8.0732792] sys_write() at netbsd:sys_write+0x259
[   8.1032777] syscall() at netbsd:syscall+0x60c
[   8.1132733] --- syscall (number 4) ---
[   8.1232790] netbsd:syscall+0x60c:
[   8.1232790] cpu0: End traceback...
[   8.1232790] fatal breakpoint trap in supervisor mode
[   8.1232790] trap type 1 code 0 rip 0xffffffff802228ad cs 0x8 rflags 0x282 cr2 0x761eaf81e496 ilevel 0 rsp 0xffffe180877f43d0
[   8.1232790] curlwp 0xffffe1801229a680 pid 202.202 lowest kstack 0xffffe180877ed2c0
Stopped in pid 202.202 (sh) at  netbsd:breakpoint+0x5:  leave
breakpoint() at netbsd:breakpoint+0x5
vpanic() at netbsd:vpanic+0xc9d
kern_assert() at netbsd:kern_assert+0x228
ttwrite() at netbsd:ttwrite+0x28f9
comwrite() at netbsd:comwrite+0x208
cdev_write() at netbsd:cdev_write+0x2e0
cnwrite() at netbsd:cnwrite+0x1bf
cdev_write() at netbsd:cdev_write+0x2e0
spec_write() at netbsd:spec_write+0x561
VOP_WRITE() at netbsd:VOP_WRITE+0x39b
vn_write() at netbsd:vn_write+0x709
dofilewrite() at netbsd:dofilewrite+0x360
sys_write() at netbsd:sys_write+0x259
syscall() at netbsd:syscall+0x60c
--- syscall (number 4) ---
netbsd:syscall+0x60c:
ds          a918
es          40f3
fs          43c0
gs          0
rdi         5
rsi         0
--db_more--

syzkaller build log:
go env (err=<nil>)
GO111MODULE="auto"
GOARCH="amd64"
GOBIN=""
GOCACHE="/syzkaller/.cache/go-build"
GOENV="/syzkaller/.config/go/env"
GOEXE=""
GOEXPERIMENT=""
GOFLAGS=""
GOHOSTARCH="amd64"
GOHOSTOS="linux"
GOINSECURE=""
GOMODCACHE="/syzkaller/jobs/netbsd/gopath/pkg/mod"
GONOPROXY=""
GONOSUMDB=""
GOOS="linux"
GOPATH="/syzkaller/jobs/netbsd/gopath"
GOPRIVATE=""
GOPROXY="https://proxy.golang.org,direct";
GOROOT="/usr/local/go"
GOSUMDB="sum.golang.org"
GOTMPDIR=""
GOTOOLDIR="/usr/local/go/pkg/tool/linux_amd64"
GOVCS=""
GOVERSION="go1.17"
GCCGO="gccgo"
AR="ar"
CC="gcc"
CXX="g++"
CGO_ENABLED="1"
GOMOD="/syzkaller/jobs/netbsd/gopath/src/github.com/google/syzkaller/go.mod"
CGO_CFLAGS="-g -O2"
CGO_CPPFLAGS=""
CGO_CXXFLAGS="-g -O2"
CGO_FFLAGS="-g -O2"
CGO_LDFLAGS="-g -O2"
PKG_CONFIG="pkg-config"
GOGCCFLAGS="-fPIC -m64 -pthread -fmessage-length=0 -fdebug-prefix-map=/tmp/go-build2755801767=/tmp/go-build -gno-record-gcc-switches"

git status (err=<nil>)
HEAD detached at a7dab6385
nothing to commit, working tree clean


go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
bin/syz-sysgen
touch .descriptions
GOOS=netbsd GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=a7dab6385c1d95547a88e22577fb56fbcd5c37eb -X 'github.com/google/syzkaller/prog.gitRevisionDate=20220205-085958'" "-tags=syz_target syz_os_netbsd syz_arch_amd64 " -o ./bin/netbsd_amd64/syz-fuzzer github.com/google/syzkaller/syz-fuzzer
GOOS=netbsd GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=a7dab6385c1d95547a88e22577fb56fbcd5c37eb -X 'github.com/google/syzkaller/prog.gitRevisionDate=20220205-085958'" "-tags=syz_target syz_os_netbsd syz_arch_amd64 " -o ./bin/netbsd_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
GOOS=netbsd GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=a7dab6385c1d95547a88e22577fb56fbcd5c37eb -X 'github.com/google/syzkaller/prog.gitRevisionDate=20220205-085958'" "-tags=syz_target syz_os_netbsd syz_arch_amd64 " -o ./bin/netbsd_amd64/syz-stress github.com/google/syzkaller/tools/syz-stress
mkdir -p ./bin/netbsd_amd64
/syzkaller/shared/netbsd/tools/bin/x86_64--netbsd-g++ -o ./bin/netbsd_amd64/syz-executor executor/executor.cc \
	-m64 --sysroot /syzkaller/shared/netbsd/dest/ -O2 -pthread -Wall -Werror -Wparentheses -Wframe-larger-than=16384 -fpermissive -w -DGOOS_netbsd=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"a7dab6385c1d95547a88e22577fb56fbcd5c37eb\"


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=12b27810080000


Tested on:

commit:         330a6f8f lint: do not treat message IDs as arithmetic ..
git tree:       https://github.com/NetBSD/src trunk
kernel config:  https://syzkaller.appspot.com/x/.config?x=739e57438eb9ed9e
dashboard link: https://syzkaller.appspot.com/bug?extid=b992757b1efc6ef0de63
compiler:       Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~~exp1~20220126212112.63
patch:          https://syzkaller.appspot.com/x/patch.diff?x=1533cf04080000

-- 
You received this message because you are subscribed to the Google Groups "syzkaller-netbsd-bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-netbsd-bugs+unsubscribe%googlegroups.com@localhost.
To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-netbsd-bugs/0000000000002d522b05e2fd0ef9%40google.com.


Home | Main Index | Thread Index | Old Index