panic: Bad tailq NEXT(ADDR->tqh_last) != NULL

7 views
Skip to first unread message

syzbot

unread,
May 8, 2019, 9:57:08 PM5/8/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: db5d04b9 Avoid literal @generated tag in file-generating s..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13ab02e8a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=6fc50d56a0497637a4d9

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6fc50d...@syzkaller.appspotmail.com

Feb 18 13:56:40 ci-freebsd-main-6 kernpanic: Bad tailq
NEXT(0xffffffff828d6938->tqh_last) != NULL
cpuid = 0
time = 4197400
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0028a4f480
vpanic() at vpanic+0x1e0/frame 0xfffffe0028a4f4e0
panic() at panic+0x43/frame 0xfffffe0028a4f540
authunix_create() at authunix_create+0x801/frame 0xfffffe0028a4f800
sys_nlm_syscall() at sys_nlm_syscall+0xed/frame 0xfffffe0028a4f980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0028a4fab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0028a4fab0
--- syscall (154, FreeBSD ELF64, sys_nlm_syscall), rip = 0x20000009, rsp =
0x7fffdfffdeb8, rbp = 0x98 ---
KDB: enter: panic
[ thread pid 1963 tid 100540 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 25, 2019, 4:50:06 AM10/25/19
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages