panic: pmap_remove_ptes: unmanaged page marked PG_PVLIST: va ADDR, opte 0x7fff

0 views
Skip to first unread message

syzbot

unread,
Mar 14, 2026, 1:28:28 AM (yesterday) Mar 14
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fd49698d88e5 Add support for RK3576 clocks and resets. A c..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=16d703c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=bf6251e1e8d383881ce5

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/c159f2fe1cb1/disk-fd49698d.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/d321f1e712d8/bsd-fd49698d.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/0df89642a17a/kernel-fd49698d.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+bf6251...@syzkaller.appspotmail.com

panic: pmap_remove_ptes: unmanaged page marked PG_PVLIST: va 0x110c235000, opte 0x7fff
Starting stack trace...
panic(ffffffff8349a006) at panic+0x1ba sys/kern/subr_prf.c:229
pmap_remove_pte(fffffd806b4865f8,fffffd800719e300,7f8008861180,110c230000,110c400000,0) at pmap_remove_pte
pmap_do_remove(fffffd806b4865f8,110c230000,110e230000,0) at pmap_do_remove+0x53a sys/arch/amd64/amd64/pmap.c:1920
uvm_unmap_kill_entry_withlock(fffffd806ccd8e70,fffffd806ccc9070,0) at uvm_unmap_kill_entry_withlock+0x269 sys/uvm/uvm_map.c:1869
uvm_map_teardown(fffffd806ccd8e70) at uvm_map_teardown+0x117 uvm_map_addr_RBT_LEFT sys/uvm/uvm_map.h:-1 [inline]
uvm_map_teardown(fffffd806ccd8e70) at uvm_map_teardown+0x117 sys/uvm/uvm_map.c:2497
exit1(ffff80002a79c7e0,0,0,1) at exit1+0x6e6 sys/kern/kern_exit.c:259
sys_exit(ffff80002a79c7e0,ffff80003c9ab2f0,ffff80003c9ab240) at sys_exit+0x1a sys/kern/kern_exit.c:-1
syscall(ffff80003c9ab2f0) at syscall+0x962 mi_syscall sys/sys/syscall_mi.h:-1 [inline]
syscall(ffff80003c9ab2f0) at syscall+0x962 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x718eed1b5990, count: 248
End of stack trace.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages