panic: vm_object_vndeallocate: bad object reference count

2 views
Skip to first unread message

syzbot

unread,
May 13, 2019, 2:08:07 PM5/13/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 094736f0 Provide separate accounting for user-wired pages.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=130e9100a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=1d2cc393bd6c88a548be

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+1d2cc3...@syzkaller.appspotmail.com

panic: vm_object_vndeallocate: bad object reference count
cpuid = 0
time = 1557770838
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212776f0
vpanic() at vpanic+0x1e0/frame 0xfffffe0021277750
panic() at panic+0x43/frame 0xfffffe00212777b0
vm_object_collapse() at vm_object_collapse/frame 0xfffffe0021277810
vn_mmap() at vn_mmap+0x2e3/frame 0xfffffe0021277890
kern_mmap() at kern_mmap+0x8a8/frame 0xfffffe0021277950
sys_mmap() at sys_mmap+0x38/frame 0xfffffe0021277980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021277ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021277ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x41309a, rsp =
0x7fffdfffdf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 1114 tid 100457 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 13, 2019, 3:13:07 PM5/13/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 094736f0 Provide separate accounting for user-wired pages.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=141edee8a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=1d2cc393bd6c88a548be
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17f8f33ca00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=125d6daca00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+1d2cc3...@syzkaller.appspotmail.com

panic: vm_object_vndeallocate: bad object reference count
cpuid = 1
time = 1557774561
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020d936f0
vpanic() at vpanic+0x1e0/frame 0xfffffe0020d93750
panic() at panic+0x43/frame 0xfffffe0020d937b0
vm_object_collapse() at vm_object_collapse/frame 0xfffffe0020d93810
vn_mmap() at vn_mmap+0x2e3/frame 0xfffffe0020d93890
kern_mmap() at kern_mmap+0x8a8/frame 0xfffffe0020d93950
sys_mmap() at sys_mmap+0x38/frame 0xfffffe0020d93980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020d93ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020d93ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x41c31a, rsp =
0x7fffffffead8, rbp = 0x7fffffffeb40 ---
KDB: enter: panic
[ thread pid 759 tid 100072 ]
Reply all
Reply to author
Forward
0 new messages