DF-0825 / run.log
Copyright (c) 2003-2026 The DragonFly Project.
Copyright (c) 1992-2003 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026
root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC
acpi_hpet: frequency 100000000
Using cputimer HPET for TSC calibration
Timer latency (in TSC ticks): 39318 min=33180 max=75260
TSC clock: 3600007090 Hz, NOT invariant
CPU: QEMU Virtual CPU version 2.5+ (3600.01-MHz K8-class CPU)
Origin="GenuineIntel" Id=0x60fb1 Family=0xf Model=0x6b Stepping=1
Features=0x1783fbfd<FPU,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,FXSR,SSE,SSE2,HTT>
Features2=0x80202001<SSE3,CX16,x2APIC,VMM>
AMD Features=0x20100800<SYSCALL,NX,LM>
AMD Features2=0x1<LAHF>
MONITOR/MWAIT Features=0x2<INTBRK>
VMM/Hypervisor: Origin="KVMKVMKVM"
real memory = 4293381120 (4094 MB)
avail memory = 4088926208 (3899 MB)
LAPIC: enter X2APIC mode
madt_lapic_probe: lapic_count=6 x2apic_count=0
ACPI CPUS = 6
lapic: divisor index 0, frequency 500003800 Hz
CPU Topology: cores_per_chip: 6; threads_per_core: 1; chips_per_package: 1;
srat_probe: can't locate SRAT
SMI Frequency (worst case): 21276 Hz (47 us)
Initialize MI interrupts for 6 cpus
TSC is not invariant, no further tests will be performed
Spectre: support=( none ) req=ffff operating=( none )
MDS: support=( none ) req=ffff operating=( none )
machdep.meltdown_mitigation enabled to protect against (mostly Intel) meltdown bug
system call performance will be impacted
interrupt uses mplock: swi_taskq
wdog: In-kernel automatic watchdog reset enabled
md0: Malloc disk
evdev device loaded.
kbd1 at kbdmux0
ACPI: RSDP 0x00000000000F59A0 000014 (v00 BOCHS )
ACPI: RSDT 0x00000000BFFE1CAC 000034 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: FACP 0x00000000BFFE1B38 000074 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: DSDT 0x00000000BFFE0040 001AF8 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: FACS 0x00000000BFFE0000 000040
ACPI: APIC 0x00000000BFFE1BAC 0000A0 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: HPET 0x00000000BFFE1C4C 000038 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: WAET 0x00000000BFFE1C84 000028 (v01 BOCHS BXPC 00000001 BXPC 00000001)
sc0: <System console> on motherboard
sc0: VGA <16 virtual consoles, flags=0x100>
acpi0: <BOCHS BXPC> on motherboard
ACPI: 1 ACPI AML tables successfully acquired and loaded
ACPI FADT: SCI testing interrupt mode ...
ACPI FADT: SCI select level/high
acpi0: Power Button (fixed)
acpi_hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
acpi_timer0 on acpi0
isab0: <ACPI Generic ISA bridge> on acpi0
isa0: <ISA bus> on isab0
cpu0: <ACPI CPU> on acpi0
cpu_cst0: <ACPI CPU C-State> on cpu0
cpu1: <ACPI CPU> on acpi0
cpu_cst1: <ACPI CPU C-State> on cpu1
cpu2: <ACPI CPU> on acpi0
cpu_cst2: <ACPI CPU C-State> on cpu2
cpu3: <ACPI CPU> on acpi0
cpu_cst3: <ACPI CPU C-State> on cpu3
cpu4: <ACPI CPU> on acpi0
cpu_cst4: <ACPI CPU C-State> on cpu4
cpu5: <ACPI CPU> on acpi0
cpu_cst5: <ACPI CPU C-State> on cpu5
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
isab1: <PCI-ISA bridge> at device 1.0 on pci0
isa1: <ISA bus> on isab1
atapci0: <Intel PIIX3 WDMA2 controller> port 0xc0a0-0xc0af,0x376,0x170-0x177,0x3f6,0x1f0-0x1f7 at device 1.1 on pci0
ata0: <ATA channel 0> on atapci0
interrupt uses mplock: ata0
ata1: <ATA channel 1> on atapci0
interrupt uses mplock: ata1
acd0: DVDROM <QEMU DVD-ROM/2.5+> at ata1-master WDMA2
pci0: <bridge> (vendor 0x8086, dev 0x7113) at device 1.3 irq 9
vgapci0: <VGA-compatible display> mem 0xfebd0000-0xfebd0fff,0xfd000000-0xfdffffff at device 2.0 on pci0
vgapci0: Boot video device
virtio_pci0: <VirtIO PCI Network adapter> port 0xc080-0xc09f mem 0xfe000000-0xfe003fff,0xfebd1000-0xfebd1fff irq 11 at device 3.0 on pci0
vtnet0: <VirtIO Networking Adapter> on virtio_pci0
virtio_pci0: host features: 0x79bf8064 <EventIdx,RingIndirect,AnyLayout,NotifyOnEmpty,SetMacAddress,GuestAnnounce,RxModeExtra,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,TxAllGSO,MacAddress,DynOffload>
virtio_pci0: negotiated features: 0x198f8020 <RingIndirect,AnyLayout,NotifyOnEmpty,SetMacAddress,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,MacAddress>
virtio_pci0: using 3 MSI-X vectors
vtnet0: MAC address: 52:54:00:12:34:56
virtio_pci1: <VirtIO PCI Block adapter> port 0xc000-0xc07f mem 0xfe004000-0xfe007fff,0xfebd2000-0xfebd2fff irq 11 at device 4.0 on pci0
vtblk0: <VirtIO Block Adapter> on virtio_pci1
virtio_pci1: host features: 0x79007e54 <EventIdx,RingIndirect,AnyLayout,NotifyOnEmpty,WriteZeroes,Discard,MultiQueue,ConfigWCE,Topology,FlushCommand,BlockSize,DiskGeometry,MaxNumSegs>
virtio_pci1: negotiated features: 0x10001a54 <RingIndirect,MultiQueue,ConfigWCE,FlushCommand,BlockSize,DiskGeometry,MaxNumSegs>
virtio_pci1: using 6 MSI-X vectors
vtblk0: Virtio: ncylinders at legacy maximum (16383), recalculating to 62415
vtblk0: Block size: 512
vtblk0: 30720MB (62914560 512 byte sectors: 16H 63S/T 16383C)
atkbdc0: <Keyboard controller (i8042)> port 0x64,0x60 irq 1 on acpi0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
kbd0 at atkbd0
psm0: <PS/2 Mouse> irq 12 on atkbdc0
interrupt uses mplock: psm0
psm0: model IntelliMouse Explorer, device ID 4
sio0: <16550A-compatible COM port> port 0x3f8-0x3ff irq 4 on acpi0
sio0: type 16550A, console
ACPI: Enabled 2 GPEs in block 00 to 0F
rdrand0: No RdRand support.
orm0: <ISA Option ROM> at iomem 0xe8000-0xeffff on isa1
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa1
sio2: can't drain, serial port might not exist, disabling
hpt27xx: no controller detected.
CAM: Configuring 2 busses
CAM: finished configuring all busses
cd0 at ata1 bus 0 target 0 lun 0
cd0: <QEMU QEMU DVD-ROM 2.5+> Removable CD-ROM SCSI-0 device
cd0: 16.000MB/s transfers
cd0: Attempt to query device size failed: NOT READY, Medium not present
Mounting root from hammer2:vbd0s1d
hammer2_mount: root devstr="vbd0s1d"
hammer2_mount: device="vbd0s1d" label="ROOT" rdonly=1
hammer2_ondisk: "/dev/vbd0s1d" zone=3 id=0 offset=0x0000000000000000 size=0x000000063f000000
hammer2_mount: hmp=0xfffff8008fae0000 pmp=0xfffff80090280000
DMA space used: 13580k, remaining available: 131072k
Mounting devfs
hammer2_mount: "vbd0s1d": no recovery needed
hammer2: enable read/write
swap low/high-water marks set to 41940/62910
KLDLOAD_RC=0
---dmesg after load---
DF-0825: harness start
DF-0825: calling nfs_getnickauth(nmp, cred uid=1001, ...)
DF-0825: nickname planted = 0xdeadbeef
DF-0825: RPCAKN_NICKNAME = 1, txdr = 0x01000000
DF-0825: nfs_getnickauth returned error=0
DF-0825: auth_str = 0xfffff8008d680c84, auth_len = 8
DF-0825: auth_str[0..3] = 0xdeadbeef
DF-0825: auth_str[4..7] = 0x00000000 (<= OOB heap if bug present)
DF-0825: expected[0..3] = 0x00000001 (RPCAKN_NICKNAME)
DF-0825: expected[4..7] = 0xdeadbeef (nickname)
DF-0825: raw bytes at auth_str: deadbeef 00000000 00000000 00000000
DF-0825: *** BUG CONFIRMED ***
DF-0825: auth_str[0] = nickname 0xdeadbeef, NOT RPCAKN_NICKNAME
DF-0825: => auth_str points 4 bytes past allocation base
DF-0825: => auth_str[4..7] = 0x00000000 is OOB heap read
DF-0825: => caller kfree(auth_str) frees non-base ptr => slab corruption
DF-0825: now calling kfree(auth_str) to demonstrate slab corruption...
DF-0825: kfree returned (no panic => INVARIANTS may be off or slab was lucky)
DF-0825: harness done
---kldstat---
4 1 0xffffffff82600000 1000 df0825_harness.ko (/usr/src/sys/test/df0825_harness/df0825_harness.ko)
325 df0825_harness