Hello,
syzbot found the following issue on:
HEAD commit: 2194060d1c40 Switch the default TLS cipher set from "compa..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=11fa77d2580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link:
https://syzkaller.appspot.com/bug?extid=4330a351fe243674944a
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/09ad6399b7ca/disk-2194060d.raw.xz
bsd.gdb:
https://storage.googleapis.com/syzbot-assets/c810ba7d2e98/bsd-2194060d.gdb.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/2283483eee0c/kernel-2194060d.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+4330a3...@syzkaller.appspotmail.com
panic: kernel diagnostic assertion "pr->ps_threadcnt == 0" failed: file "/syzkaller/managers/setuid/kernel/sys/kern/kern_exit.c", line 888
Stopped at db_enter+0x25: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
154668 67546 32767 0x10 0x4000000 0 syz-executor
*282865 64953 0 0x14000 0x200 1K reaper
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834bd8f7) at panic+0x1e5 sys/kern/subr_prf.c:198
__assert(ffffffff834f80a8,ffffffff8349ae1e,378,ffffffff8351a308) at __assert+0x29 sys/kern/subr_prf.c:-1
process_zap(ffff80003c3cd360) at process_zap+0x31d sys/kern/kern_exit.c:889
reaper(ffff800045ffd9f8) at reaper+0x2b0 sys/kern/kern_exit.c:525
end trace frame: 0x0, count: 10
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
*cpu1: kernel diagnostic assertion "pr->ps_threadcnt == 0" failed: file "/syzkaller/managers/setuid/kernel/sys/kern/kern_exit.c", line 888
ddb{1}> trace
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834bd8f7) at panic+0x1e5 sys/kern/subr_prf.c:198
__assert(ffffffff834f80a8,ffffffff8349ae1e,378,ffffffff8351a308) at __assert+0x29 sys/kern/subr_prf.c:-1
process_zap(ffff80003c3cd360) at process_zap+0x31d sys/kern/kern_exit.c:889
reaper(ffff800045ffd9f8) at reaper+0x2b0 sys/kern/kern_exit.c:525
end trace frame: 0x0, count: -5
ddb{1}> show registers
rdi 0
rsi 0x1
rbp 0xffff80002a1f4bf0
rbx 0xffff80002999ee07
rdx 0
rcx 0xffff800045ffd9f8
rax 0xffff80002999dff0
r8 0x101010101010101
r9 0x8080808080808080
r10 0x21c96ebad97ab0a
r11 0x599c42ca39920c5a
r12 0xffff80002999ec08
r13 0
r14 0
r15 0x1
rip 0xffffffff81d8c1b5 db_enter+0x25
cs 0x8
rflags 0x246
rsp 0xffff80002a1f4be0
ss 0x10
db_enter+0x25: addq $0x8,%rsp
ddb{1}> show proc
PROC (reaper) tid=282865 pid=64953 tcnt=1 stat=onproc
flags process=14000<NOZOMBIE,SYSTEM> proc=200<SYSTEM>
runpri=32, usrpri=50, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0x0 scnt=0 ecnt=0
forw=0xffffffffffffffff, list=0xffff800045fffc88,0xffff800045ffd770
process=0xffff800045ffb9c0 user=0xffff80002a1ef000, vmspace=0xffffffff839e6928
estcpu=0, cpticks=10, pctcpu=0.2, user=0, sys=0, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
80365 451320 89196 0 2 0 syz-executor
13859 169566 70255 32767 2 0x10 syz-executor
13859 5995 70255 32767 3 0x4000090 fsleep syz-executor
15171 81804 26138 32767 2 0x10 syz-executor
15171 281681 26138 32767 3 0x4000090 fsleep syz-executor
67546 394985 49253 32767 2 0x10 syz-executor
67546 154668 49253 32767 7 0x4000010 syz-executor
22317 63689 89196 0 2 0x10000002 syz-executor
4749 67102 7074 32767 2 0x10 syz-executor
4749 475101 7074 32767 2 0x4000010 syz-executor
4749 437514 7074 32767 2 0x4000010 syz-executor
4749 338157 7074 32767 3 0x4000090 fsleep syz-executor
11719 180927 51914 32767 2 0x10 syz-executor
11719 103043 51914 32767 3 0x4000090 lockf syz-executor
11719 118698 51914 32767 3 0x4000090 fsleep syz-executor
7074 133885 36929 32767 3 0x90 nanoslp syz-executor
26138 233623 72828 32767 3 0x90 nanoslp syz-executor
51914 465053 91563 32767 3 0x90 nanoslp syz-executor
49253 283851 95588 32767 3 0x90 nanoslp syz-executor
70255 102314 43606 32767 3 0x90 nanoslp syz-executor
51898 443143 41641 32767 3 0x10 biowait syz-executor
72828 332741 89196 0 3 0x82 wait syz-executor
41641 395397 89196 0 3 0x82 wait syz-executor
43606 150892 89196 0 3 0x82 wait syz-executor
36929 462005 89196 0 3 0x82 wait syz-executor
91563 477901 89196 0 3 0x82 wait syz-executor
95588 518085 89196 0 3 0x82 wait syz-executor
89196 468121 92050 0 2 0x2 syz-executor
92050 494054 59919 0 3 0x10008a sigsusp ksh
59919 510040 74499 0 3 0x98 kqread sshd-session
74499 283078 86042 0 3 0x92 kqread sshd-session
72316 35622 1 0 3 0x100083 ttyin getty
86042 310523 1 0 3 0x88 kqread sshd
520 237723 57673 73 3 0x1100090 kqread syslogd
57673 524105 1 0 3 0x100082 sbwait syslogd
29797 455168 1 0 3 0x100080 kqread resolvd
76225 221186 98585 77 3 0x100092 kqread dhcpleased
58755 420992 98585 77 3 0x100092 kqread dhcpleased
98585 516533 1 0 3 0x80 kqread dhcpleased
8344 82194 0 0 3 0x14200 bored smr
20876 319282 0 0 2 0x14200 zerothread
46263 411133 0 0 3 0x14200 aiodoned aiodoned
92530 75950 0 0 3 0x14200 syncer update
45858 361925 0 0 3 0x14200 cleaner cleaner
*64953 282865 0 0 7 0x14200 reaper
6816 508561 0 0 3 0x14200 pgdaemon pagedaemon
29814 362884 0 0 3 0x14200 bored viomb
65271 58826 0 0 3 0x40014200 acpi0 acpi0
46554 184237 0 0 3 0x40014200 idle1
96792 287028 0 0 3 0x14200 bored softnet1
27085 64080 0 0 3 0x14200 bored softnet0
7084 391558 0 0 3 0x14200 bored systqmp
4032 510896 0 0 3 0x14200 bored systq
78256 60852 0 0 3 0x14200 tmoslp softclockmp
72613 273030 0 0 3 0x40014200 tmoslp softclock
78549 457409 0 0 3 0x40014200 idle0
1 449104 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
Process 67546 (syz-executor) thread 0xffff80003c400a88 (154668)
exclusive rwlock fdlock r = 0 (0xffff80003c3e26a8)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 sys_closefrom+0x1ed sys/kern/kern_descrip.c:1468
#3 syscall+0xbd4 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#3 syscall+0xbd4 sys/arch/amd64/amd64/trap.c:783
#4 Xsyscall+0x128
Process 51898 (syz-executor) thread 0xffff800045feefa8 (443143)
exclusive rrwlock inode r = 0 (0xfffff6806b6198e0)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:621
#3 VOP_LOCK+0xbd sys/kern/vfs_vops.c:527
#4 ufs_ihashins+0x4f ufs_ihash sys/ufs/ufs/ufs_ihash.c:-1 [inline]
#4 ufs_ihashins+0x4f sys/ufs/ufs/ufs_ihash.c:159
#5 ffs_vget+0x187 sys/ufs/ffs/ffs_vfsops.c:1232
#6 ffs_inode_alloc+0x279 sys/ufs/ffs/ffs_alloc.c:393
#7 ufs_mkdir+0xfc sys/ufs/ufs/ufs_vnops.c:1112
#8 VOP_MKDIR+0x101 sys/kern/vfs_vops.c:394
#9 domkdirat+0x179 sys/kern/vfs_syscalls.c:3062
#10 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#10 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#11 Xsyscall+0x128
exclusive rrwlock inode r = 0 (0xfffff6806d3159f0)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 rw_do_enter_write+0x419 sys/kern/kern_rwlock.c:320
#2 rrw_enter+0xc6 sys/kern/kern_rwlock.c:621
#3 VOP_LOCK+0xbd sys/kern/vfs_vops.c:527
#4 vn_lock+0xa4 sys/kern/vfs_vnops.c:576
#5 vfs_lookup+0x12b sys/kern/vfs_lookup.c:431
#6 namei+0x7c5 sys/kern/vfs_lookup.c:250
#7 domkdirat+0x8b sys/kern/vfs_syscalls.c:3047
#8 syscall+0xb17 mi_syscall sys/sys/syscall_mi.h:176 [inline]
#8 syscall+0xb17 sys/arch/amd64/amd64/trap.c:783
#9 Xsyscall+0x128
Process 64953 (reaper) thread 0xffff800045ffd9f8 (282865)
exclusive kernel_lock &kernel_lock r = 0 (0xffffffff83af7200)
#0 witness_lock+0x5f1 stacktrace_save sys/sys/stacktrace.h:37 [inline]
#0 witness_lock+0x5f1 sys/kern/subr_witness.c:1160
#1 __mp_acquire_count+0x58 sys/kern/kern_lock.c:-1
#2 sleep_finish+0x2d8 sys/kern/kern_synch.c:369
#3 rw_do_enter_write+0x1dc sys/kern/kern_rwlock.c:298
#4 knote_processexit+0x2b sys/kern/kern_event.c:2235
#5 reaper+0x26d sys/kern/kern_exit.c:515
#6 proc_trampoline+0x10
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 11045 12014K 12034K 166960K 12142 0
pcb 17 12K 12K 166960K 17 0
rtable 197 5K 7K 166960K 354 0
pf 27 16K 16K 166960K 31 0
ifaddr 34 6K 7K 166960K 44 0
ifgroup 42 1K 2K 166960K 50 0
sysctl 1 1K 9K 166960K 5 0
counters 66 36K 37K 166960K 70 0
ioctlops 0 0K 4K 166960K 33 0
iov 0 0K 12K 166960K 10 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1288 81K 81K 166960K 1428 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 5K 166960K 3 0
VM map 2 1K 1K 166960K 2 0
sem 5 0K 0K 166960K 5 0
dirhash 12 2K 2K 166960K 12 0
ACPI 1692 195K 286K 166960K 12470 0
file desc 21 74K 125K 166960K 233 0
proc 58 99K 147K 166960K 503 0
subproc 63 3K 4K 166960K 144 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
ip_moptions 2 0K 0K 166960K 3 0
in_multi 77 5K 7K 166960K 99 0
ether_multi 1 0K 0K 166960K 1 0
mrt 0 0K 0K 166960K 6 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 67 307K 307K 166960K 67 0
exec 0 0K 1K 166960K 371 0
fusefs mount 1 32K 32K 166960K 1 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 222 151K 177K 166960K 3456 0
UVM aobj 5 2K 2K 166960K 5 0
pinsyscall 42 84K 112K 166960K 1316 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
ip6_options 0 0K 0K 166960K 3 0
NDP 9 0K 2K 166960K 27 0
temp 32 9118K 9134K 166960K 3976 0
kqueue 20 29K 29K 166960K 42 0
SYN cache 2 16K 16K 166960K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 26 0 0 1 0 1 1 0 8 0
rtpcb 120 41 0 37 1 0 1 1 0 8 0
rtentry 176 113 0 23 6 0 6 6 0 8 0
unpcb 144 75 0 60 1 0 1 1 0 8 0
syncache 336 5 0 5 1 0 1 1 0 8 1
tcpqe 32 2 0 2 1 0 1 1 0 8 1
tcpcb 736 67 0 61 1 0 1 1 0 8 0
arp 136 19 0 4 1 0 1 1 0 8 0
ipq 40 1 0 0 1 0 1 1 0 8 0
ipqe 40 1 0 0 1 0 1 1 0 8 0
inpcb 328 138 0 125 2 0 2 2 0 8 0
nd6 152 25 0 6 1 0 1 1 0 8 0
kcovpl 48 16 0 9 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 468 0 88 30 0 30 30 0 8 4
art_table 40 469 0 88 5 0 5 5 0 8 0
art_node 32 113 0 31 1 0 1 1 0 8 0
sysvmsgpl 40 1 0 0 1 0 1 1 0 8 0
semapl 72 3 0 0 1 0 1 1 0 8 0
shmpl 112 2 0 0 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 1650 0 175 93 0 93 93 0 8 0
ffsino 296 1650 0 175 114 0 114 114 0 8 0
nchpl 144 1931 0 234 64 0 64 64 0 8 0
vnodes 216 1803 0 0 101 0 101 101 0 8 0
namei 1024 6025 0 6024 1 0 1 1 0 8 0
percpumem 16 50 0 2 1 0 1 1 0 8 0
kstatmem 264 25 0 4 2 0 2 2 0 8 0
scxspl 216 6441 0 6440 4 2 2 3 1 8 1
plimitpl 152 129 0 107 2 0 2 2 0 8 0
sigapl 424 509 0 459 7 0 7 7 0 8 0
knotepl 120 291 0 0 9 0 9 9 0 8 0
kqueuepl 224 70 0 25 3 0 3 3 0 8 0
pipepl 344 153 0 123 3 0 3 3 0 8 0
fdescpl 528 493 0 460 4 0 4 4 0 8 0
filepl 160 2083 0 1844 11 0 11 11 0 8 0
lockfpl 104 26 0 22 1 0 1 1 0 8 0
lockfspl 48 12 0 9 1 0 1 1 0 8 0
sessionpl 144 36 0 21 1 0 1 1 0 8 0
pgrppl 48 52 0 30 1 0 1 1 0 8 0
ucredpl 104 194 0 177 1 0 1 1 0 8 0
zombiepl 144 460 0 459 1 0 1 1 0 8 0
processpl 1232 509 0 459 5 0 5 5 0 8 0
procpl 664 607 0 549 7 0 7 7 0 8 0
sockpl 752 254 0 222 5 0 5 5 0 8 1
mcl64k 65536 1 0 0 1 0 1 1 0 8 0
mcl8k 8192 2 0 0 1 0 1 1 0 8 0
mcl4k 4096 123 0 0 16 0 16 16 0 8 0
mcl2k 2048 24 0 0 3 0 3 3 0 8 0
mtagpl 96 2 0 0 1 0 1 1 0 8 0
mbufpl 256 208 0 0 13 0 13 13 0 8 0
bufpl 272 2311 0 102 148 0 148 148 0 8 0
anonpl 32 7394 0 0 60 0 60 60 0 247 0
amapchunkpl 152 9918 0 9443 30 0 30 30 0 158 8
amappl16 200 2057 0 2039 14 4 10 14 0 8 8
amappl15 192 3 0 3 1 1 0 1 0 8 0
amappl14 184 409 0 408 1 0 1 1 0 8 0
amappl13 176 119 0 109 1 0 1 1 0 8 0
amappl12 168 726 0 694 2 0 2 2 0 8 0
amappl11 160 4 0 4 1 1 0 1 0 8 0
amappl10 152 57 0 47 1 0 1 1 0 8 0
amappl9 144 271 0 271 1 1 0 1 0 8 0
amappl8 136 89 0 88 1 0 1 1 0 8 0
amappl7 128 143 0 130 1 0 1 1 0 8 0
amappl6 120 156 0 155 1 0 1 1 0 8 0
amappl5 112 91 0 84 1 0 1 1 0 8 0
amappl4 104 261 0 247 1 0 1 1 0 8 0
amappl3 96 1795 0 1685 5 1 4 4 0 8 0
amappl2 88 519 0 467 2 0 2 2 0 8 0
amappl1 80 10842 0 10284 15 0 15 15 0 8 1
amappl 88 2761 0 2601 5 0 5 5 0 92 0
uvmvnodes 80 101 0 0 3 0 3 3 0 8 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 4 0 0 1 0 1 1 0 8 0
uaddrrnd 24 494 0 461 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 494 0 461 1 0 1 1 0 8 0
vmmpekpl 168 6223 0 6176 3 0 3 3 0 8 0
vmmpepl 168 41193 0 39313 102 0 102 102 0 357 11
vmsppl 488 493 0 461 7 1 6 6 0 8 0
rwobjpl 80 15430 0 14521 26 0 26 26 0 8 3
pdppl 4096 995 0 922 107 24 83 97 0 8 10
pvpl 32 13660 0 0 111 0 111 111 0 265 0
pmappl 256 493 0 461 4 1 3 3 0 8 0
extentpl 40 45 0 27 1 0 1 1 0 8 0
phpool 112 426 0 27 12 0 12 12 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x27: addq $0x8,%rsp
x86_ipi_db(ffffffff8399fff0) at x86_ipi_db+0x27 sys/arch/amd64/amd64/db_interface.c:394
x86_ipi_handler() at x86_ipi_handler+0xd9 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__mp_lock(ffffffff83af6a00) at __mp_lock+0x192 __mp_lock_spin sys/kern/kern_lock.c:142 [inline]
__mp_lock(ffffffff83af6a00) at __mp_lock+0x192 sys/kern/kern_lock.c:173
intr_handler(ffff80002a354b30,ffff8000002a3480) at intr_handler+0xe9 sys/arch/amd64/amd64/intr.c:560
Xintr_ioapic_edge23_untramp() at Xintr_ioapic_edge23_untramp+0x18f
rw_exit_write(ffff80003c3e2690) at rw_exit_write+0x10a rw_exited sys/kern/kern_rwlock.c:508 [inline]
rw_exit_write(ffff80003c3e2690) at rw_exit_write+0x10a sys/kern/kern_rwlock.c:161
fdrelease(ffff80003c400a88,ae) at fdrelease+0x165 sys/kern/kern_descrip.c:763
sys_closefrom(ffff80003c400a88,ffff80002a354dc0,ffff80002a354d10) at sys_closefrom+0x13c sys/kern/kern_descrip.c:1471
syscall(ffff80002a354dc0) at syscall+0xbd4 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80002a354dc0) at syscall+0xbd4 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6b85c8db990, count: 4
ddb{0}> trace
x86_ipi_db(ffffffff8399fff0) at x86_ipi_db+0x27 sys/arch/amd64/amd64/db_interface.c:394
x86_ipi_handler() at x86_ipi_handler+0xd9 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
__mp_lock(ffffffff83af6a00) at __mp_lock+0x192 __mp_lock_spin sys/kern/kern_lock.c:142 [inline]
__mp_lock(ffffffff83af6a00) at __mp_lock+0x192 sys/kern/kern_lock.c:173
intr_handler(ffff80002a354b30,ffff8000002a3480) at intr_handler+0xe9 sys/arch/amd64/amd64/intr.c:560
Xintr_ioapic_edge23_untramp() at Xintr_ioapic_edge23_untramp+0x18f
rw_exit_write(ffff80003c3e2690) at rw_exit_write+0x10a rw_exited sys/kern/kern_rwlock.c:508 [inline]
rw_exit_write(ffff80003c3e2690) at rw_exit_write+0x10a sys/kern/kern_rwlock.c:161
fdrelease(ffff80003c400a88,ae) at fdrelease+0x165 sys/kern/kern_descrip.c:763
sys_closefrom(ffff80003c400a88,ffff80002a354dc0,ffff80002a354d10) at sys_closefrom+0x13c sys/kern/kern_descrip.c:1471
syscall(ffff80002a354dc0) at syscall+0xbd4 mi_syscall sys/sys/syscall_mi.h:176 [inline]
syscall(ffff80002a354dc0) at syscall+0xbd4 sys/arch/amd64/amd64/trap.c:783
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x6b85c8db990, count: -11
ddb{0}> machine ddbcpu 1
Stopped at db_enter+0x25: addq $0x8,%rsp
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834bd8f7) at panic+0x1e5 sys/kern/subr_prf.c:198
__assert(ffffffff834f80a8,ffffffff8349ae1e,378,ffffffff8351a308) at __assert+0x29 sys/kern/subr_prf.c:-1
process_zap(ffff80003c3cd360) at process_zap+0x31d sys/kern/kern_exit.c:889
reaper(ffff800045ffd9f8) at reaper+0x2b0 sys/kern/kern_exit.c:525
end trace frame: 0x0, count: 10
ddb{1}> trace
db_enter() at db_enter+0x25 sys/arch/amd64/amd64/db_interface.c:438
panic(ffffffff834bd8f7) at panic+0x1e5 sys/kern/subr_prf.c:198
__assert(ffffffff834f80a8,ffffffff8349ae1e,378,ffffffff8351a308) at __assert+0x29 sys/kern/subr_prf.c:-1
process_zap(ffff80003c3cd360) at process_zap+0x31d sys/kern/kern_exit.c:889
reaper(ffff800045ffd9f8) at reaper+0x2b0 sys/kern/kern_exit.c:525
end trace frame: 0x0, count: -5
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup