Hello,
syzbot found the following issue on:
HEAD commit: ae8b598acb72 rpki-client: validate octets in a printable s..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=167bf212580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link:
https://syzkaller.appspot.com/bug?extid=264af07a1b4136a89b80
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/140ad2837e4e/disk-ae8b598a.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/de2047374e44/bsd-ae8b598a.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/2b21ef5e245c/kernel-ae8b598a.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+264af0...@syzkaller.appspotmail.com
panic: pmap_remove_ptes: unmanaged page marked PG_PVLIST: va 0x719fba66b000, opte 0x900007fff
Starting stack trace...
panic(ffffffff8342d871) at panic+0x1d0 sys/kern/subr_prf.c:229
pmap_remove_pte(fffffd806ec7c000,fffffd80088960f8,7fb8cfdd32a0,719fba654000,719fba752000,0) at pmap_remove_pte
pmap_do_remove(fffffd806ec7c000,719fba654000,719fba752000,0) at pmap_do_remove+0x589 sys/arch/amd64/amd64/pmap.c:1920
uvm_unmap_kill_entry_withlock(fffffd800b063b70,fffffd8070ffec08,0) at uvm_unmap_kill_entry_withlock+0x269 sys/uvm/uvm_map.c:1863
uvm_map_teardown(fffffd800b063b70) at uvm_map_teardown+0x117 uvm_map_addr_RBT_LEFT sys/uvm/uvm_map.h:-1 [inline]
uvm_map_teardown(fffffd800b063b70) at uvm_map_teardown+0x117 sys/uvm/uvm_map.c:2486
exit1(ffff8000fffeefa8,0,0,1) at exit1+0x6fc sys/kern/kern_exit.c:260
sys_exit(ffff8000fffeefa8,ffff80002a3be780,ffff80002a3be6d0) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80002a3be780) at syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80002a3be780) at syscall+0xb17 sys/arch/amd64/amd64/trap.c:765
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x719fba752ff0, count: 248
End of stack trace.
syncing disks...
set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup