Some additional filesystem fuzzing by Bob Prohaska has turned up ways to circumvent the existing filesystem checks. They can both crash the kernel and cause fsck_ffs(8) to segment fault when trying to fix them.
These changes should resolve those problems without rejecting any valid filesystems.