pool: free list modified: aobjpl (2)

0 views
Skip to first unread message

syzbot

unread,
Mar 9, 2025, 10:51:22 PM3/9/25
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7475d27301c2 drm/amdgpu: disable BAR resize on Dell G5 SE
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11434664580000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=94b1873ca417b622b1eb

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/2429291e0bb9/disk-7475d273.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/614ece07ce3c/bsd-7475d273.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/8f8bef0b3bbe/kernel-7475d273.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+94b187...@syzkaller.appspotmail.com

panic: pool_do_get: aobjpl free list modified: page 0xfffffd806f811000; item addr 0xfffffd806f811f30; offset 0x1c=0xdeafbeae
Starting stack trace...
panic(ffffffff833ae28d) at panic+0x1d0 sys/kern/subr_prf.c:229
pool_do_get(ffffffff839122c8,1,ffff8000330ac018) at pool_do_get+0x5da
pool_get(ffffffff839122c8,1) at pool_get+0x149
uao_create(2000,0) at uao_create+0xaa sys/uvm/uvm_aobj.c:697
shmget_allocate_segment(ffff80002a354020,ffff8000330ac2d0,0,ffff8000330ac220) at shmget_allocate_segment+0x42d sys/kern/sysv_shm.c:444
sys_shmget(ffff80002a354020,ffff8000330ac2d0,ffff8000330ac220) at sys_shmget+0x1b2 sys/kern/sysv_shm.c:482
syscall(ffff8000330ac2d0) at syscall+0xb08 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff8000330ac2d0) at syscall+0xb08 sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x27dc689c050, count: 249
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jun 7, 2025, 10:51:23 PM6/7/25
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages