panic: vm_page_free_prep: freeing mapped page ADDR

2 views
Skip to first unread message

syzbot

unread,
May 14, 2019, 12:28:05 AM5/14/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 094736f0 Provide separate accounting for user-wired pages.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1268b794a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=2036eb0649eef498351f

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2036eb...@syzkaller.appspotmail.com

panic: vm_page_free_prep: freeing mapped page 0xfffff8007f235000
cpuid = 1
time = 1557808054
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001faef270
vpanic() at vpanic+0x1e0/frame 0xfffffe001faef2d0
panic() at panic+0x43/frame 0xfffffe001faef330
vm_page_free_prep() at vm_page_free_prep+0x341/frame 0xfffffe001faef360
vm_page_free_toq() at vm_page_free_toq+0x1b/frame 0xfffffe001faef390
vm_object_page_remove() at vm_object_page_remove+0x375/frame
0xfffffe001faef3f0
vnode_pager_setsize() at vnode_pager_setsize+0x107/frame 0xfffffe001faef440
vtruncbuf() at vtruncbuf+0x50a/frame 0xfffffe001faef4a0
ffs_truncate() at ffs_truncate+0x16b5/frame 0xfffffe001faef690
ufs_setattr() at ufs_setattr+0x918/frame 0xfffffe001faef730
VOP_SETATTR_APV() at VOP_SETATTR_APV+0xc2/frame 0xfffffe001faef760
kern_truncate() at kern_truncate+0x289/frame 0xfffffe001faef980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001faefab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001faefab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x41309a, rsp =
0x7fffdfffdf38, rbp = 0x2 ---
KDB: enter: panic
[ thread pid 1178 tid 100565 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Mark Johnston

unread,
May 14, 2019, 10:22:07 AM5/14/19
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: vm_object_vndeallocate: bad object reference count
Reply all
Reply to author
Forward
0 new messages