Hello,
syzbot found the following crash on:
HEAD commit: 094736f0 Provide separate accounting for user-wired pages.
git tree: freebsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=130e9100a00000
dashboard link:
https://syzkaller.appspot.com/bug?extid=1d2cc393bd6c88a548be
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+1d2cc3...@syzkaller.appspotmail.com
panic: vm_object_vndeallocate: bad object reference count
cpuid = 0
time = 1557770838
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212776f0
vpanic() at vpanic+0x1e0/frame 0xfffffe0021277750
panic() at panic+0x43/frame 0xfffffe00212777b0
vm_object_collapse() at vm_object_collapse/frame 0xfffffe0021277810
vn_mmap() at vn_mmap+0x2e3/frame 0xfffffe0021277890
kern_mmap() at kern_mmap+0x8a8/frame 0xfffffe0021277950
sys_mmap() at sys_mmap+0x38/frame 0xfffffe0021277980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021277ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021277ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x41309a, rsp =
0x7fffdfffdf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 1114 tid 100457 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.