pool: free list modified: pdppl (5)

0 views
Skip to first unread message

syzbot

unread,
5:29 PM (1 hour ago) 5:29 PM
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f4c39256adbf Allow cd(4)/vioscsi(4) in confidential VM mode
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=153b6612580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=e5295f4c534d9833a54b

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0b7262b6c741/disk-f4c39256.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/bdf694febfac/bsd-f4c39256.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/cc5c8f405a4d/kernel-f4c39256.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e5295f...@syzkaller.appspotmail.com

panic: pool_do_get: pdppl free list modified: page 0xfffffd8066c2f000; item addr 0xfffffd8066c2f000; offset 0x0=0xb62453c14d9b8e88 != 0xb62453c14d9b8eca
Starting stack trace...
panic(ffffffff833acdc7) at panic+0x1ba sys/kern/subr_prf.c:229
pool_do_get(ffffffff8394b438,1,ffff80003c939578) at pool_do_get+0x574 sys/kern/subr_pool.c:743
pool_get(ffffffff8394b438,1) at pool_get+0x11a sys/kern/subr_pool.c:-1
pmap_create() at pmap_create+0x18c sys/arch/amd64/amd64/pmap.c:1391
uvmspace_fork(ffff8000ffffba98) at uvmspace_fork+0x7f uvmspace_init sys/uvm/uvm_map.c:-1 [inline]
uvmspace_fork(ffff8000ffffba98) at uvmspace_fork+0x7f uvmspace_alloc sys/uvm/uvm_map.c:3247 [inline]
uvmspace_fork(ffff8000ffffba98) at uvmspace_fork+0x7f sys/uvm/uvm_map.c:3732
process_new(ffff80002a854d30,ffff8000ffffba98,1) at process_new+0x558 sys/kern/kern_fork.c:281
fork1(ffff80002a7bca78,1,ffffffff81305ee0,0,ffff80003c9397f0,0) at fork1+0x3f2 sys/kern/kern_fork.c:-1
syscall(ffff80003c9398a0) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c9398a0) at syscall+0x962 sys/arch/amd64/amd64/trap.c:765
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7a2944857d10, count: 248
End of stack trace.
syncing disks...















---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages