pool: free list modified: rttmr

1 view
Skip to first unread message

syzbot

unread,
Mar 21, 2024, 8:05:34 PMMar 21
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 173c810f1a3f Write padding character into the right positi..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13b95ac9180000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=0160e931eeddc4d24fcd

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e98fccebbed7/disk-173c810f.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/57a52faca30e/bsd-173c810f.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d240cccea302/kernel-173c810f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0160e9...@syzkaller.appspotmail.com

panic: pool_p_free: rttmr free list modified: page 0xfffffd8058574000; item addr 0xfffffd8058574ee0; offset 0x10=0x82d5d040
Starting stack trace...
panic(ffffffff828ce771) at panic+0x16f sys/kern/subr_prf.c:229
pool_p_free(ffffffff82d6fcc8,fffffd8058574f90) at pool_p_free+0x20f sys/kern/subr_pool.c:984
pool_gc_pages(0) at pool_gc_pages+0x255 sys/kern/subr_pool.c:1583
taskq_thread(ffffffff82cd7a90) at taskq_thread+0xe5 sys/kern/kern_task.c:450
end trace frame: 0x0, count: 253
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages