panic: ffs_valloc: dup alloc (4)

2 views
Skip to first unread message

syzbot

unread,
Oct 5, 2025, 5:35:31 AM (10 days ago) Oct 5
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 28c2bc42cf18 rpki-client: improve error message for duplic..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1452585b980000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=731fb4df80c6af50c42b

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/47b3526f5182/disk-28c2bc42.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/9bf4a101948e/bsd-28c2bc42.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/356307f0fd08/kernel-28c2bc42.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+731fb4...@syzkaller.appspotmail.com

panic: ffs_valloc: dup alloc
Starting stack trace...
panic(ffffffff83332f62) at panic+0x1ba sys/kern/subr_prf.c:229
ffs_inode_alloc(fffffd806bdfa600,41ed,fffffd8007bfb618,ffff80002a8459f8) at ffs_inode_alloc+0x94e
ufs_mkdir(ffff80002a845a60) at ufs_mkdir+0xfc sys/ufs/ufs/ufs_vnops.c:1112
VOP_MKDIR(fffffd806c4e9618,ffff80002a845bc0,ffff80002a845bf0,ffff80002a845af0) at VOP_MKDIR+0x101 sys/kern/vfs_vops.c:394
domkdirat(ffff80002a7c3a00,ffffff9c,7a035f53ef70,1ff) at domkdirat+0x179 sys/kern/vfs_syscalls.c:3113
syscall(ffff80002a845d60) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80002a845d60) at syscall+0x962 sys/arch/amd64/amd64/trap.c:748
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7a035f53f010load: 4.14 not a, controlling ter minal
pckbd_encable: command eroror
pckbd_enabule: command erronr
pckbd_enablet: command error:
pckbd_enable: command error
2pckbd_enable: co5mmand error
pc0kbd_enable: comm
and error
pckbd_enable: commanEd error
pckbd_nenable: command derror
pckbd_en able: command eroror
load: 5.83f not a controlli ng terminal
WAsRNING: thread `ntfsio' (438070) eaxits with statusc -1
WARNING: tkhread `nfsio' (2 1918) exits witht status -1
WARrNING: thread `nfasio' (215630) excits with status e-1
WARNING: th.read `nfsio' (42
0603) exits with status -1
WARNING: thread `nfssio' (342322) exyits with status n-1
WARNING: thcread `nfsio' (46i6211) exits withn status -1
WARgNING: thread `nf sio' (328469) exdits with status i-1
WARNING: thsread `nfsio' (50k2987) exits withs status -1
WAR.NING: thread `nf.sio' (121768) ex.its with status -1
WARNING: thread `nfsio' (103763) exits with status -1
WARNING: thread `nfsio' (200046) exits with status -1
WARNING: thread `nfsio' (273392) exits with status -1
WARNING: thread `nfsio' (37083) exits with status -1
WARNING: thread `nfsio' (237890) exits with status -1
WARNING: thread `nfsio' (335868) exits with status -1
WARNING: thread `nfsio' (165862) exits with status -1
WARNING: thread `nfsio' (340081) exits with status -1
WARNING: thread `nfsio' (205032) exits with status -1
WARNING: thread `nfsio' (437910) exits with status -1
WARNING: thread `nfsio' (419357) exits with status -1
mode = 040755, inum = 103994, fs = /

set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages