syzbot found the following issue on:
HEAD commit: 1eab3ea7ad62 Clean-up BUILDINFO from /home/_sysupgrade lik..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10694f64580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=640f5b53834a8559e680
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/5732daa5f887/disk-1eab3ea7.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/c52dd82b8cba/bsd-1eab3ea7.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/733e7fcb6521/kernel-1eab3ea7.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+640f5b...@syzkaller.appspotmail.com
./file0 /dev/bpf ./file0 ouse ./file0 tap7 � � � D .� �� panic: pool_do_get: shmpl free list modified: page 0xfffffd80680dc000; item addr 0xfffffd80680dcb60; offset 0x40=0x806
Starting stack trace...
panic(ffffffff830ce4ad) at panic+0x1d0 sys/kern/subr_prf.c:229
pool_do_get(ffffffff8367dfd0,1,ffff80003c5dca18) at pool_do_get+0x5da
pool_get(ffffffff8367dfd0,1) at pool_get+0x149
shmget_allocate_segment(ffff80003657c538,ffff80003c5dcc70,1,ffff80003c5dcbc0) at shmget_allocate_segment+0x1a7
sys_shmget(ffff80003657c538,ffff80003c5dcc70,ffff80003c5dcbc0) at sys_shmget+0x1b2 sys/kern/sysv_shm.c:482
syscall(ffff80003c5dcc70) at syscall+0xb08 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80003c5dcc70) at syscall+0xb08 sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xf17392c3170, count: 250
End of stack trace.
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup