assert "rn != NULL" failed in pipex.c

5 views
Skip to first unread message

syzbot

unread,
May 10, 2025, 12:51:23 PM5/10/25
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 5fc296287174 powerpc: Use MI soft interrupt code
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17e91670580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=a27b0c7b00d6f1aa08f3

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/1a139290c6a9/disk-5fc29628.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/d6049fd99494/bsd-5fc29628.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/13df162ffb59/kernel-5fc29628.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a27b0c...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "rn != NULL" failed: file "/syzkaller/managers/main/kernel/sys/net/pipex.c", line 504
Starting stack trace...
panic(ffffffff8342bd5e) at panic+0x1ba sys/kern/subr_prf.c:229
__assert(ffffffff833d59dd,ffffffff833660e4,1f8,ffffffff8338c28f) at __assert+0x29 sys/kern/subr_prf.c:-1
pipex_unlink_session_locked(ffff80002a869130) at pipex_unlink_session_locked+0x413 sys/net/pipex.c:504
pipex_destroy_all_sessions(ffff80000145b800) at pipex_destroy_all_sessions+0xd9 pipex_rele_session sys/net/pipex.c:-1 [inline]
pipex_destroy_all_sessions(ffff80000145b800) at pipex_destroy_all_sessions+0xd9 sys/net/pipex.c:156
pppacclose(637e,41,2000,ffff80003c97d4b0) at p
ppacclose+0x16f
spec_close(ffff80003c951900) at spec_close+0x412 sys/kern/spec_vnops.c:-1
VOP_CLOSE(fffffd806a2df360,41,fffffd807f7d72d8,ffff80003c97d4b0) at VOP_CLOSE+0x12a sys/kern/vfs_vops.c:156
vn_closefile(fffffd8061770810,ffff80003c97d4b0) at vn_closefile+0x11d vn_close sys/kern/vfs_vnops.c:292 [inline]
vn_closefile(fffffd8061770810,ffff80003c97d4b0) at vn_closefile+0x11d sys/kern/vfs_vnops.c:615
fdrop(fffffd8061770810,ffff80003c97d4b0) at fdrop+0x126 sys/kern/kern_descrip.c:1267
closef(fffffd8061770810,ffff80003c97d4b0) at closef+0x18d sys/kern/kern_descrip.c:1251
syscall(ffff80003c951b60) at syscall+0x97e mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c951b60) at syscall+0x97e sys/arch/amd64/amd64/trap.c:579
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xaf1df077340, count: 245
End of stack trace.
syncing disks...set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Mar 10, 2026, 9:34:15 PM (21 hours ago) Mar 10
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages