panic: pmap_remove_pte: unmanaged page marked PG_PVLIST: va ADDR, opte ADDR (2)

0 views
Skip to first unread message

syzbot

unread,
Dec 4, 2025, 4:48:32 PM (2 days ago) Dec 4
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 2f3d0dde3672 rpki-client: zap extra blank line in ip.c
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=16613cc2580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=e4e195056fcc1a1184aa

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/4a0a7b37019a/disk-2f3d0dde.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/7e37bffb3669/bsd-2f3d0dde.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/475ef01e08b7/kernel-2f3d0dde.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e4e195...@syzkaller.appspotmail.com

panic: pmap_remove_pte: unmanaged page marked PG_PVLIST: va 0x3ba0e260000, opte 0x70003efff
Starting stack trace...
panic(ffffffff83437438) at panic+0x1d0 sys/kern/subr_prf.c:229
pmap_remove_pte(fffffd806c937000,fffffd800889c178,7f81dd071300,3ba0e260000,0,ffff800036007d10) at pmap_remove_pte+0x374
pmap_do_remove(fffffd806c937000,3ba0e260000,3ba0e261000,0) at pmap_do_remove+0xa3b sys/arch/amd64/amd64/pmap.c:1852
uvm_unmap_kill_entry_withlock(fffffd806caf2b88,fffffd8078a582b0,0) at uvm_unmap_kill_entry_withlock+0x269 sys/uvm/uvm_map.c:1863
uvm_map_teardown(fffffd806caf2b88) at uvm_map_teardown+0x117 uvm_map_addr_RBT_LEFT sys/uvm/uvm_map.h:-1 [inline]
uvm_map_teardown(fffffd806caf2b88) at uvm_map_teardown+0x117 sys/uvm/uvm_map.c:2486
exit1(ffff80002a270548,0,4,1) at exit1+0x6fc sys/kern/kern_exit.c:260
sigexit(ffff80002a270548,4) at sigexit+0x116
trapsignal(ffff80002a270548,b,6,1,f) at trapsignal+0x860 sys/kern/kern_sig.c:872
upageflttrap(ffff800036008140,f) at upageflttrap+0x266 sys/arch/amd64/amd64/trap.c:218
usertrap(ffff800036008140) at usertrap+0x42f sys/arch/amd64/amd64/trap.c:632
recall_trap() at recall_trap+0x8
end of kernel
end trace frame: 0x77926979b010, count: 246
End of stack trace.
syncing disks...
set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages