panic: inconsistent bufpage counts

0 views
Skip to first unread message

syzbot

unread,
May 16, 2024, 7:38:29 AMMay 16
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: b20edd337af0 Recent OpenSBI versions implement shutdown an..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11625a3f180000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=965cbc60a594b79f2ccd

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d10d5e73f943/disk-b20edd33.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/83ce40a92db6/bsd-b20edd33.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b689f1d30e65/kernel-b20edd33.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+965cbc...@syzkaller.appspotmail.com

panic: inconsistent bufpage counts
Starting stack trace...
panic(ffffffff828eeb65) at panic+0x16f sys/kern/subr_prf.c:229
bufcache_release(fffffd807e271148) at bufcache_release+0x405 sys/kern/vfs_bio.c:1757
brelse(fffffd807e271148) at brelse+0x131 sys/kern/vfs_bio.c:927
ffs_read(ffff80002a257ac0) at ffs_read+0x35a sys/ufs/ffs/ffs_vnops.c:216
VOP_READ(fffffd806bf15e98,ffff80002a257b58,0,fffffd807f7d3680) at VOP_READ+0xc3 sys/kern/vfs_vops.c:227
uvn_io(fffffd806d3221b0,ffff80002a257c68,1,202,0) at uvn_io+0x3c6
uvn_get(fffffd806d3221b0,3d8000,ffff80002a257d28,ffff80002a257cf8,0,3,42d5b10c182beafe,0) at uvn_get+0x1e9 sys/uvm/uvm_vnode.c:1110
uvm_fault_lower(ffff80002a257e90,ffff80002a257ec8,ffff80002a257e10,2) at uvm_fault_lower+0x368 sys/uvm/uvm_fault.c:1284
uvm_fault(fffffd8064ae2c20,1b2edf8000,2,3) at uvm_fault+0x255 sys/uvm/uvm_fault.c:637
uvm_fault_wire(fffffd8064ae2c20,1b2ea60000,1b2ee20000,3) at uvm_fault_wire+0x63 sys/uvm/uvm_fault.c:1602
uvm_map_pageable_wire(fffffd8064ae2c20,fffffd806d598740,0,267,ffffffff811a6be0,0) at uvm_map_pageable_wire+0x2dd sys/uvm/uvm_map.c:2159
sys_mlockall(ffff80002f71f4a8,ffff80002a2581a0,ffff80002a2580f0) at sys_mlockall+0x61 sys/uvm/uvm_mmap.c:899
syscall(ffff80002a2581a0) at syscall+0x854 mi_syscall sys/sys/syscall_mi.h:180 [inline]
syscall(ffff80002a2581a0) at syscall+0x854 sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6677e22dc0, count: 243
End of stack trace.
panic: inconsistent bufpage counts
Starting stack trace...
panic(ffffffff828eeb65) at panic+0x16f sys/kern/subr_prf.c:229
bufcache_release(fffffd805735f690) at bufcache_release+0x405 sys/kern/vfs_bio.c:1757
brelse(fffffd805735f690) at brelse+0x131 sys/kern/vfs_bio.c:927
sd_buf_done(fffffd8076bdd6e8) at sd_buf_done+0x1fd sys/scsi/sd.c:772
scsi_done(fffffd8076bdd6e8) at scsi_done+0x2e sys/scsi/scsi_base.c:1496
vioscsi_vq_done(ffff8000000a3268) at vioscsi_vq_done+0xb1 sys/dev/pv/vioscsi.c:350
intr_handler(ffff80002a245db0,ffff80000006bc00) at intr_handler+0x93 sys/arch/amd64/amd64/intr.c:543
Xintr_ioapic_edge23_untramp() at Xintr_ioapic_edge23_untramp+0x18f
Xspllower() at Xspllower+0x1d
timeout_run(ffff80002a20e0c8) at timeout_run+0xd0 sys/kern/kern_timeout.c:666
softclock_process_tick_timeout(ffff80002a20e0c8,0) at softclock_process_tick_timeout+0x19d sys/kern/kern_timeout.c:723
softclock(0) at softclock+0x139 sys/kern/kern_timeout.c:755
softintr_dispatch(0) at softintr_dispatch+0xcd sys/arch/amd64/amd64/softintr.c:90
Xsoftclock() at Xsoftclock+0x27
end of kernel
end trace frame: 0x7f30086a3e10, count: 243
End of stack trace.

dump to dev 4,1 not possible
rebooting...
SeaBIOS (version 1.8.2-google)
Total RAM Size = 0x0000000080000000 = 2048 MiB
CPUs found: 2 Max CPUs supported: 2
SeaBIOS (version 1.8.2-google)
Machine UUID 2c48b237-609e-0a7d-d6ca-08d70f46a694
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0 removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f27f0: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Sending Seabios boot VM event.
Booting from Hard Disk 0...
>> OpenBSD/amd64 BOOT 3.65
boot> set $maxwidth = 0
set: syntax error
boot> show panic
boot: illegal argument panic
boot> trace
boot> show registers
boot> show proc
boot> ps
boot> show all locks
boot> show malloc
boot> show all pools
boot> machine ddbcpu 0
machine: syntax error
boot> trace
boot> machine ddbcpu 1
machine: syntax error
boot> trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages