assert "amap->am_buckets[bucket] == NULL" failed in uvm_amap.c

0 views
Skip to first unread message

syzbot

unread,
Nov 10, 2025, 3:32:28 AM (2 days ago) Nov 10
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 129ed0dedc2e regen
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=144dd17c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=1a93028cb5abf442ac8e

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d517ce5ca6ff/disk-129ed0de.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/51a74c020655/bsd-129ed0de.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/4ecf1f322f29/kernel-129ed0de.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1a9302...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "amap->am_buckets[bucket] == NULL" failed: file "/syzkaller/managers/main/kernel/sys/uvm/uvm_amap.c", line 138
Starting stack trace...
panic(ffffffff8335e2f9) at panic+0x1ba sys/kern/subr_prf.c:229
__assert(ffffffff8339eb18,ffffffff83338361,8a,ffffffff833c064b) at __assert+0x29 sys/kern/subr_prf.c:-1
amap_chunk_get(fffffd8066b4c000,17,1,2) at amap_chunk_get+0x2fd
amap_add(fffffd806bd19cf8,17000,fffffd806c416318,0) at amap_add+0xb1 sys/uvm/uvm_amap.c:-1
uvm_fault_lower(ffff80003c964fa0,ffff80003c964fd8,ffff80003c964f20) at uvm_fault_lower+0x639 sys/uvm/uvm_fault.c:1484
uvm_fault(fffffd806c1efe78,f9b1aa59000,0,2) at uvm_fault+0x241 sys/uvm/uvm_fault.c:-1
upageflttrap(ffff80003c965140,f9b1aa595a0) at upageflttrap+0xa0 sys/arch/amd64/amd64/trap.c:192
usertrap(ffff80003c965140) at usertrap+0x413 sys/arch/amd64/amd64/trap.c:622
recall_trap() at recall_trap+0x8
end of kernel
end trace frame: 0x78ae4d840540, count: 248
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages