pool: free list modified: namei

0 views
Skip to first unread message

syzbot

unread,
Nov 11, 2025, 7:19:30 AM (yesterday) Nov 11
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 05de582f27ae remove the old pkg-config. It's not coming ba..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10360692580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=dc7f50d35da7a58ab7a2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d1e6b66b34a9/disk-05de582f.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/3ce386832372/bsd-05de582f.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/019389f22111/kernel-05de582f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dc7f50...@syzkaller.appspotmail.com

panic: pool_do_get: namei free list modified: page 0xffff800030510000; item addr 0xffff800030510400; offset 0x0=0x0 != 0x2ea8c3f17d2a27ee
Starting stack trace...
panic(ffffffff83396a2d) at panic+0x1ba sys/kern/subr_prf.c:229
pool_do_get(ffffffff83882980,1,ffff80003050afe8) at pool_do_get+0x574 sys/kern/subr_pool.c:743
pool_get(ffffffff83882980,1) at pool_get+0x11a sys/kern/subr_pool.c:-1
namei(ffff80003050b0f8) at namei+0xdf sys/kern/vfs_lookup.c:145
dorenameat(ffff80002a7e47f8,ffffff9c,2000000007c0,ffffff9c,200000001040) at dorenameat+0x144 sys/kern/vfs_syscalls.c:3004
syscall(ffff80003050b390) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003050b390) at syscall+0x962 sys/arch/amd64/amd64/trap.c:765
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x799ec652de0, count: 250
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages