panic: vm_page_unhold: hold count < 0!!!

8 views
Skip to first unread message

syzbot

unread,
Mar 17, 2019, 9:10:05 PM3/17/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 8b17fbc2 Change date of Canberra Day, now on second Monday..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=14b9becf200000
dashboard link: https://syzkaller.appspot.com/bug?extid=7a0cbdf5168eb06073df

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+7a0cbd...@syzkaller.appspotmail.com

panic: vm_page_unhold: hold count < 0!!!
cpuid = 0
time = 77
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212ca6d0
vpanic() at vpanic+0x1e0/frame 0xfffffe00212ca730
panic() at panic+0x43/frame 0xfffffe00212ca790
vm_page_unhold_pages() at vm_page_unhold_pages+0x1e3/frame
0xfffffe00212ca7e0
pipe_write() at pipe_write+0x16d8/frame 0xfffffe00212ca8b0
dofilewrite() at dofilewrite+0xfd/frame 0xfffffe00212ca910
kern_writev() at kern_writev+0x66/frame 0xfffffe00212ca950
sys_writev() at sys_writev+0x50/frame 0xfffffe00212ca980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212caab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212caab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffbbf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 5608 tid 100210 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 17, 2019, 9:50:04 PM3/17/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 8b17fbc2 Change date of Canberra Day, now on second Monday..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=102cc9d7200000
dashboard link: https://syzkaller.appspot.com/bug?extid=7a0cbdf5168eb06073df
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13f86dfb200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+7a0cbd...@syzkaller.appspotmail.com

login: panic: vm_page_unhold: hold count < 0!!!
cpuid = 1
time = 1552873535
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212726d0
vpanic() at vpanic+0x1e0/frame 0xfffffe0021272730
panic() at panic+0x43/frame 0xfffffe0021272790
vm_page_unhold_pages() at vm_page_unhold_pages+0x1e3/frame
0xfffffe00212727e0
pipe_write() at pipe_write+0x16d8/frame 0xfffffe00212728b0
dofilewrite() at dofilewrite+0xfd/frame 0xfffffe0021272910
kern_writev() at kern_writev+0x66/frame 0xfffffe0021272950
sys_writev() at sys_writev+0x50/frame 0xfffffe0021272980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021272ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021272ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffdcf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 904 tid 100338 ]

Mark Johnston

unread,
Jul 2, 2019, 10:54:22 AM7/2/19
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: Fatal trap 12: page fault in vm_page_unhold_pages
Reply all
Reply to author
Forward
0 new messages