panic: l diagnostic assertion "!topdown || hint <= orig_hint" failed: file "/syzkaller/managers/ci2-netbsd-kmsan/kernel/


syzbot found the following issue on:

HEAD commit:    94e40a0fa623 s/collissions/collisions/
git tree:       netbsd
console output:
kernel config:
dashboard link:
compiler:       Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~~exp1~20220126212112.63

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:

[ 331.5kerne902754] panic: l diagnostic assertion "!topdown || hint <= orig_hint" failed: file "/syzkaller/managers/ci2-netbsd-kmsan/kernel/sys/uvm/uvm_map.c", line 1801 map=0xffffac801360a700 hint=0xffffffffff012000 orig_hint=0x20ffe000 length=0x20ffe000 uobj=0x0 uoffset=0xffffffffffffffff align=0 flags=0x80010 entry=0xffffac801370a980 (uvm_map_findspace line 1998)
[ 331.6203227] WARNING: defaulted mmap() share type to MAP_PRIVATE (pid 3981 command syz-executor.1)
[ 331.6203227] cpu1: Begin traceback...
[ 331.7502557] vpanic() at netbsd:vpanic+0xc9d
[ 331.8402457] WARNING: defaulted mmap() share type to MAP_PRIVATE (pid 6212 command syz-executor.0)
[ 331.8702440] kern_assert() at netbsd:kern_assert+0x228
[ 331.9902462] uvm_map_findspace() at netbsd:uvm_map_findspace+0x4c8b uvm_findspace_invariants sys/uvm/uvm_map.c:1795 [inline]
[ 331.9902462] uvm_map_findspace() at netbsd:uvm_map_findspace+0x4c8b sys/uvm/uvm_map.c:1998
[ 332.1202541] uvm_map_prepare() at netbsd:uvm_map_prepare+0xf5e sys/uvm/uvm_map.c:1181
[ 332.2502599] uvm_map() at netbsd:uvm_map+0x5f6 sys/uvm/uvm_map.c:1089
[ 332.3902412] uvm_mmap() at netbsd:uvm_mmap+0xd2d sys/uvm/uvm_mmap.c:949
[ 332.5202459] sys_mmap() at netbsd:sys_mmap+0x16e1 sys/uvm/uvm_mmap.c:425
[ 332.6502490] compat_43_sys_mmap() at netbsd:compat_43_sys_mmap+0x331 sys/compat/common/vm_43.c:150
[ 332.7802537] sys___syscall() at netbsd:sys___syscall+0x2c6 sys/kern/sys_syscall.c:90
[ 332.9302533] syscall() at netbsd:syscall+0x60c sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 332.9302533] syscall() at netbsd:syscall+0x60c sys/arch/x86/x86/syscall.c:138
[ 332.9702480] --- syscall (number 71 via SYS_syscall) ---
[ 333.0102565] netbsd:syscall+0x60c:
[ 333.0202509] cpu1: End traceback...
[ 333.0302581] fatal breakpoint trap in supervisor mode
[ 333.0402487] trap type 1 code 0 rip 0xffffffff802228ad cs 0x8 rflags 0x282 cr2 0x7de5fc401000 ilevel 0 rsp 0xffffac80899b7240
[ 333.0702506] curlwp 0xffffac801370c680 pid 3981.3987 lowest kstack 0xffffac80899b02c0

This report is generated by a bot. It may contain errors.
See for more information about syzbot.
syzbot engineers can be reached at

syzbot will keep track of this issue. See: for how to communicate with syzbot.

