assert "pg->wire_count == NUM" failed in vfs_biomem.c (5)

0 views
Skip to first unread message

syzbot

unread,
Aug 24, 2025, 8:54:38 AMAug 24
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 9279bdd4d788 vi: fix 'p' command with a count
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10eacef0580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=02c43b319fa4aa5cf773

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/027a2dc4593c/disk-9279bdd4.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/c95f85ce5072/bsd-9279bdd4.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/857267ea7bbd/kernel-9279bdd4.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+02c43b...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "pg->wire_count == 1" failed: file "/syzkaller/managers/multicore/kernel/sys/kern/vfs_biomem.c", line 310
Starting stack trace...
panic(ffffffff83373b29) at panic+0x1d0 sys/kern/subr_prf.c:229
__assert(ffffffff833aef10,ffffffff83311b78,136,ffffffff832f4b34) at __assert+0x29 sys/kern/subr_prf.c:-1
buf_free_pages(fffffd805e90e158) at buf_free_pages+0x23d sys/kern/vfs_biomem.c:299
buf_dealloc_mem(fffffd805e90e158) at buf_dealloc_mem+0x14e sys/kern/vfs_biomem.c:179
buf_put(fffffd805e90e158) at buf_put+0x1d9 sys/kern/vfs_bio.c:123

brelse(fffffd805e90e158) at brelse+0x397 sys/kern/vfs_bio.c:932
vinvalbuf(fffffd8061a99450,2,ffffffffffffffff,ffff80002a36cd48,0,ffffffffffffffff) at vinvalbuf+0x539 sys/kern/vfs_subr.c:2004
ffs_truncate(fffffd806d09e880,0,0,ffffffffffffffff) at ffs_truncate+0xf4a sys/ufs/ffs/ffs_inode.c:-1
ufs_inactive(ffff80003c482fd0) at ufs_inactive+0x202 sys/ufs/ufs/ufs_inode.c:84
VOP_INACTIVE(fffffd8061a99450,ffff80002a36cd48) at VOP_INACTIVE+0x104 sys/kern/vfs_vops.c:498
vrele(fffffd8061a99450) at vrele+0x129 sys/kern/vfs_subr.c:844
ktrwriteraw(ffff80002a36cd48,fffffd8061a99450,fffffd80097fb548,ffff80003c483170,ffff80003c483150) at ktrwriteraw+0x35d ktrcleartrace sys/kern/kern_ktrace.c:86 [inline]
ktrwriteraw(ffff80002a36cd48,fffffd8061a99450,fffffd80097fb548,ffff80003c483170,ffff80003c483150) at ktrwriteraw+0x35d sys/kern/kern_ktrace.c:710
ktrsysret(ffff80002a36cd48,35,0,ffff80003c483240) at ktrsysret+0x192 ktrwrite2 sys/kern/kern_ktrace.c:-1 [inline]
ktrsysret(ffff80002a36cd48,35,0,ffff80003c483240) at ktrsysret+0x192 sys/kern/kern_ktrace.c:209
syscall(ffff80003c4832f0) at syscall+0xa50 mi_syscall_return sys/sys/syscall_mi.h:204 [inline]
syscall(ffff80003c4832f0) at syscall+0xa50 sys/arch/amd64/amd64/trap.c:769
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x719647470820, count: 242
End of stack trace.
syncing disks...set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages