[Fuzz] qemu-system-i386 virtio-mouse: Assertion in address_space_lduw_le_cached failed
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
QEMU |
Expired
|
Undecided
|
Unassigned |
Bug Description
--[ Reproducer
cat << EOF | ./build/
-device virtio-mouse -display none -qtest stdio
outl 0xcf8 0x80000820
outl 0xcfc 0xe0004000
outl 0xcf8 0x80000804
outb 0xcfc 0x02
write 0xe000400c 0x4 0x003fe62e
write 0xe0004016 0x1 0x01
write 0xe0004024 0x1 0x01
write 0xe000401c 0x1 0x01
write 0xe0007007 0x1 0x00
write 0xe0004018 0x1 0x41
write 0xe0007007 0x1 0x00
EOF
--[ Output
[I 1611805425.711054] OPENED
[R +0.040080] outl 0xcf8 0x80000820
OK
[S +0.040117] OK
[R +0.040136] outl 0xcfc 0xe0004000
OK
[S +0.040155] OK
[R +0.040165] outl 0xcf8 0x80000804
OK
[S +0.040172] OK
[R +0.040184] outb 0xcfc 0x02
OK
[S +0.040683] OK
[R +0.040702] write 0xe000400c 0x4 0x003fe62e
OK
[S +0.040735] OK
[R +0.040743] write 0xe0004016 0x1 0x01
OK
[S +0.040748] OK
[R +0.040755] write 0xe0004024 0x1 0x01
OK
[S +0.040760] OK
[R +0.040767] write 0xe000401c 0x1 0x01
OK
[S +0.040785] OK
[R +0.040792] write 0xe0007007 0x1 0x00
OK
[S +0.040810] OK
[R +0.040817] write 0xe0004018 0x1 0x41
OK
[S +0.040822] OK
[R +0.040839] write 0xe0007007 0x1 0x00
qemu-system-i386: /home/ubuntu/
-- [ Original ASAN report
qemu-fuzz-i386: /home/ubuntu/
==3406167== ERROR: libFuzzer: deadly signal
#0 0x5644e4ae0f21 in __sanitizer_
#1 0x5644e4a29fe8 in fuzzer:
#2 0x5644e4a10023 in fuzzer:
#3 0x7f77e2a4b3bf (/lib/x86_
#4 0x7f77e285c18a in raise (/lib/x86_
#5 0x7f77e283b858 in abort (/lib/x86_
#6 0x7f77e283b728 (/lib/x86_
#7 0x7f77e284cf35 in __assert_fail (/lib/x86_
#8 0x5644e60051b2 in address_
#9 0x5644e60051b2 in lduw_le_phys_cached /home/ubuntu/
#10 0x5644e60051b2 in virtio_
#11 0x5644e5ff476d in vring_avail_ring /home/ubuntu/
#12 0x5644e5ff476d in vring_get_
#13 0x5644e5ff476d in virtio_
#14 0x5644e5ff476d in virtio_
#15 0x5644e5ff5556 in virtio_notify /home/ubuntu/
#16 0x5644e5571d2a in virtio_
#17 0x5644e5ff20ec in virtio_queue_notify /home/ubuntu/
#18 0x5644e60908fb in memory_
#19 0x5644e6090363 in access_
#20 0x5644e608fbc0 in memory_
#21 0x5644e5b97bc6 in flatview_
#22 0x5644e5b8d328 in flatview_write /home/ubuntu/
#23 0x5644e5b8d328 in address_space_write /home/ubuntu/
#24 0x5644e6018906 in qtest_process_
#25 0x5644e60159df in qtest_process_inbuf /home/ubuntu/
#26 0x5644e6015735 in qtest_server_
#27 0x5644e667cf68 in qtest_sendf /home/ubuntu/
#28 0x5644e667e54e in qtest_write /home/ubuntu/
#29 0x5644e667e54e in qtest_writeq /home/ubuntu/
#30 0x5644e4b1037e in __wrap_qtest_writeq /home/ubuntu/
#31 0x5644e4b1c33d in op_write /home/ubuntu/
#32 0x5644e4b1a259 in generic_fuzz /home/ubuntu/
#33 0x5644e4b0b333 in LLVMFuzzerTestO
#34 0x5644e4a11581 in fuzzer:
#35 0x5644e49fcc92 in fuzzer:
#36 0x5644e4a02cfe in fuzzer:
#37 0x5644e4a2a7c2 in main (/home/
#38 0x7f77e283d0b2 in __libc_start_main (/lib/x86_
#39 0x5644e49d739d in _start (/home/
This is an automated cleanup. This bug report has been moved to QEMU's
new bug tracker on gitlab.com and thus gets marked as 'expired' now.
Please continue with the discussion here:
https:/ /gitlab. com/qemu- project/ qemu/-/ issues/ 302