assert "bp->b_bufsize > NUM" failed in vfs_bio.c

0 views
Skip to first unread message

syzbot

unread,
Mar 22, 2026, 9:40:35 AM (20 hours ago) Mar 22
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 67e6794a9e1c SIGWINCH is now part of POSIX.1-2024
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=148781d6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=cce4207ff9ffca94548e

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7202381a5fbe/disk-67e6794a.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/02f8f7d727f9/bsd-67e6794a.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/514167d759a3/kernel-67e6794a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+cce420...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "bp->b_bufsize > 0" failed: file "/syzkaller/managers/main/kernel/sys/kern/vfs_bio.c", line 865
Starting stack trace...
panic(ffffffff834125e3) at panic+0x1ba sys/kern/subr_prf.c:229
__assert(ffffffff83452871,ffffffff8345a1a4,361,ffffffff833b7047) at __assert+0x29 sys/kern/subr_prf.c:-1
brelse(fffffd806b538260) at brelse+0x4ea
bwrite(fffffd806b538260) at bwrite+0x2ef sys/kern/vfs_bio.c:760
ufs_dirremove(fffffd806ab5ea50,fffffd806f6bf100,800c,0) at ufs_dirremove+0x28d sys/ufs/ufs/ufs_lookup.c:919

ufs_remove(ffff80002a8b8f40) at ufs_remove+0x1a7 sys/ufs/ufs/ufs_vnops.c:594
VOP_REMOVE(fffffd806ab5ea50,fffffd806807c980,ffff80002a8b9018) at VOP_REMOVE+0x172 sys/kern/vfs_vops.c:331
dounlinkat(ffff80002a746d00,ffffff9c,7b56dc785890,0) at dounlinkat+0x1c4 sys/kern/vfs_syscalls.c:1923
syscall(ffff80002a8b9180) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80002a8b9180) at syscall+0x962 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7b56dc785d40, count: 247
End of stack trace.
syncing disks...set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages