Hello,
syzbot found the following issue on:
HEAD commit: b0e7aced8b61 Simplify EC_get_builtin_curves().
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=139a7c5f980000
kernel config:
https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link:
https://syzkaller.appspot.com/bug?extid=400caf9c1c9f9b2d97c4
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/0a6fe75c7bb2/disk-b0e7aced.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/ebe2772bacfb/bsd-b0e7aced.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/02713b07760a/kernel-b0e7aced.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+400caf...@syzkaller.appspotmail.com
panic: kernel diagnostic assertion "ps->ps_uvncount == 0" faile
d: file "/syzkaller/managers/main/kernel/sys/kern/kern_unveil.c
", line 188
Starting stack trace...
panic(ffffffff830b03bc) at panic+0x1ba sys/kern/subr_prf.c:229
__assert(ffffffff8306a3b3,ffffffff8303eaf8,bc,ffffffff82ff1bac) at __assert+0x29
unveil_destroy(ffff80002a465570) at unveil_destroy+0x1dd sys/kern/kern_unveil.c:188
exit1(ffff80002a4f11f8,b,0,1) at exit1+0x60f sys/kern/kern_exit.c:233
sys_exit(ffff80002a4f11f8,ffff8000374676c0,ffff800037467610) at sys_exit+0x1a
syscall(ffff8000374676c0) at syscall+0x97e sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7b480b318670, count: 250
End of stack trace.
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup