assert "pg->wire_count == NUM" failed in uvm_page.c

0 views
Skip to first unread message

syzbot

unread,
6:17 AM (5 hours ago) 6:17 AM
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d11ef3f2eb06 replace SRPs with SMRs for carp iface list ha..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=157ff51a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=53685bdd9a03f0636a7a

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e11453ed41dd/disk-d11ef3f2.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/d3f073d280aa/bsd-d11ef3f2.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f7556f151ff5/kernel-d11ef3f2.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+53685b...@syzkaller.appspotmail.com

panic: kernel diagnostic assertion "pg->wire_count == 0" failed: file "/syzkaller/managers/main/kernel/sys/uvm/uvm_page.c", line 1326
Starting stack trace...
panic(ffffffff83377972) at panic+0x1ba sys/kern/subr_prf.c:229
__assert(ffffffff833b9c23,ffffffff833a659f,52e,ffffffff833d7055) at __assert+0x29 sys/kern/subr_prf.c:-1
uvm_pagedequeue(fffffd8007188400) at uvm_pagedequeue+0x2cd sys/uvm/uvm_page.c:1324
uvn_flush(fffffd80691d0d80,0,0,19) at uvn_flush+0xb8f sys/uvm/uvm_vnode.c:818
uvn_detach(fffffd80691d0d80) at uvn_detach+0xb8 sys/uvm/uvm_vnode.c:344
uvm_unmap_detach(ffff80003c989110,0) at uvm_unmap_detach+0x15e sys/uvm/uvm_map.c:1364
uvm_map_teardown(fffffd806cb83740) at uvm_map_teardown+0x357 sys/uvm/uvm_map.c:2525
exit1(ffff80002a7bd4e0,0,0,1) at exit1+0x6e6 sys/kern/kern_exit.c:259
sys_exit(ffff80002a7bd4e0,ffff80003c9892d0,ffff80003c989220) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c9892d0) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c9892d0) at syscall+0x962 sys/arch/amd64/amd64/trap.c:775
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x74206d5d2b10, count: 246
End of stack trace.

syncing disks...set $lines = 0
set $maxwidth = 0
show panic
trace
show registers
show proc
ps
show all locks
show malloc
show all pools
machine ddbcpu 0
trace
machine ddbcpu 1
trace


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages