panic: ffs_blkfree_cg: freeing free block (2)

10 views
Skip to first unread message

syzbot

unread,
Apr 30, 2019, 8:16:05 AM4/30/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 8d42a256 powerpc64: Fix switch panic from cpu_throw()
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1340637ca00000
dashboard link: https://syzkaller.appspot.com/bug?extid=cc052223614c27bb3f53

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+cc0522...@syzkaller.appspotmail.com

panic: ffs_blkfree_cg: freeing free block
cpuid = 0
time = 35
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe002d0cbfe0
vpanic() at vpanic+0x1e0/frame 0xfffffe002d0cc040
panic() at panic+0x43/frame 0xfffffe002d0cc0a0
ffs_blkfree_cg() at ffs_blkfree_cg+0x6e9/frame 0xfffffe002d0cc160
ffs_blkfree() at ffs_blkfree+0x15e/frame 0xfffffe002d0cc1e0
ffs_indirtrunc() at ffs_indirtrunc+0x724/frame 0xfffffe002d0cc2e0
ffs_indirtrunc() at ffs_indirtrunc+0x68e/frame 0xfffffe002d0cc3c0
ffs_indirtrunc() at ffs_indirtrunc+0x68e/frame 0xfffffe002d0cc4a0
ffs_truncate() at ffs_truncate+0x17c3/frame 0xfffffe002d0cc690
ufs_setattr() at ufs_setattr+0x918/frame 0xfffffe002d0cc730
VOP_SETATTR_APV() at VOP_SETATTR_APV+0xc2/frame 0xfffffe002d0cc760
kern_truncate() at kern_truncate+0x289/frame 0xfffffe002d0cc980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe002d0ccab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe002d0ccab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412fda, rsp =
0x7fffdfffdf38, rbp = 0x2 ---
KDB: enter: panic
[ thread pid 8000 tid 102259 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Mark Johnston

unread,
Jul 29, 2019, 3:06:05 PM7/29/19
to syzbot, syzkaller-f...@googlegroups.com
#syz fix: Lock the vnode before calling ufs_bmap_seekdata().

I have no proof that this commit fixes the bug, but it is a possibility,
and we have no reproducer.
Reply all
Reply to author
Forward
0 new messages