kern/111098: 7.0 Current unexpectedly hangs

Dao-hui Chen dhchen at dhchen.com
Sun Apr 1 16:00:11 UTC 2007


>Number:         111098
>Category:       kern
>Synopsis:       7.0 Current unexpectedly hangs
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    freebsd-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Sun Apr 01 16:00:10 GMT 2007
>Closed-Date:
>Last-Modified:
>Originator:     Dao-hui Chen
>Release:        
>Organization:
>Environment:
FreeBSD equinox.dhchen.com 7.0-CURRENT FreeBSD 7.0-CURRENT #10: Sat Mar 31 14:55:29 CST 2007     root at equinox.dhchen.com:/usr/obj/usr/src/sys/EQUINOX  i386

>Description:
Recently I installed and run mldonkey-current. After running mldonkey kernel becomes very unstable. Systems panics unexpectedly. First I thought it's about the kernel I used(about one month ago), so I updated to newest kernel, but the problem still there. It panics at network stack, so maybe it's not the donkey's problem.


kernel stack (bt full) at panic:

#0  doadump () at pcpu.h:172
No locals.
#1  0xc0531c0c in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:409
        first_buf_printf = 1
#2  0xc0531f7d in panic (fmt=0xc06d0bc0 "%s") at /usr/src/sys/kern/kern_shutdown.c:563
        td = (struct thread *) 0xc29931b0
        bootopt = 256
        newpanic = 1
        ap = 0xc29931b0 ""
        buf = "page fault", '\0' <repeats 245 times>
#3  0xc06ac232 in trap_fatal (frame=0xd487c8cc, eva=12) at /usr/src/sys/i386/i386/trap.c:868
        code = 0
        type = 12
        ss = 40
        esp = 0
        softseg = {ssd_base = 0, ssd_limit = 1048575, ssd_type = 27, ssd_dpl = 0, ssd_p = 1,
  ssd_xx = 8, ssd_xx1 = 0, ssd_def32 = 1, ssd_gran = 1}
        msg = 0x0
#4  0xc06abec5 in trap_pfault (frame=0xd487c8cc, usermode=0, eva=12)
    at /usr/src/sys/i386/i386/trap.c:777
        va = 0
        vm = (struct vmspace *) 0x0
        map = 0x1
        rv = 1
        ftype = 1 '\001'
        td = (struct thread *) 0xc29931b0
        p = (struct proc *) 0xc2992900
#5  0xc06aba3c in trap (frame=0xd487c8cc) at /usr/src/sys/i386/i386/trap.c:462
        td = (struct thread *) 0xc29931b0
        p = (struct proc *) 0xc2992900
        i = 0
        ucode = 0
        type = 12
        code = 0
        addr = -1026758624
        eva = 12
        ksi = {ksi_link = {tqe_next = 0xc2a2bcc4, tqe_prev = 0xd487c8e0}, ksi_info = {
    si_signo = -1023981568, si_errno = -729298312, si_code = -729298436, si_pid = -1069226950,
    si_uid = 3265444096, si_status = -729298720, si_addr = 0x1, si_value = {sival_int = 0,
      sival_ptr = 0x0}, _reason = {_fault = {_trapno = 0}, _timer = {_timerid = 0,
        _overrun = 127}, _mesgq = {_mqd = 0}, _poll = {_band = 0}, __spare__ = {__spare1__ = 0,
        __spare2__ = {127, 0, -1029855672, 1, 389150722, 54, -1027982768}}}},
  ksi_flags = -1021236156, ksi_sigq = 0xd487c914}
#6  0xc069970b in calltrap () at /usr/src/sys/i386/i386/exception.s:139
No locals.
#7  0xc057e492 in sbsndptr (sb=0xc31f5e5c, off=3191, len=1188, moff=0x0)
    at /usr/src/sys/kern/uipc_sockbuf.c:936
        m = (struct mbuf *) 0x0
        ret = (struct mbuf *) 0xc2ba9300
#8  0xc05ea96d in tcp_output (tp=0xc31ebae0) at /usr/src/sys/netinet/tcp_output.c:796
        mb = (struct mbuf *) 0xc77
        moff = 0
        so = (struct socket *) 0xc31f5d98
        len = 4380
        recwin = 65700
        sendwin = 4380
        off = 0
        flags = 16
        error = 0
        m = (struct mbuf *) 0xc2bf2400
        ip = (struct ip *) 0x0
        th = (struct tcphdr *) 0x111c
        opt = "\000H&#40408;&#37485;\036&#40672;020\000\000\000&#22505;\207&#22539;\230W&#39184;000@\004&#32311;000H&#40408;\000\000\000\000\000\000\000\000&#22145;\207?
        ipoptlen = 0
        optlen = 0
        hdrlen = 40
        idle = 1
        sendalot = 0
        sack_rxmit = 0
        sack_bytes_rxmt = 0
        p = (struct sackhole *) 0x0
        tso = 1
        to = {to_flags = 0, to_tsval = 3270985728, to_tsecr = 256, to_mss = 0, to_wscale = 0 '\0',
  to_nsacks = 0 '\0', to_sacks = 0xc05799c7 "\203&#23360;f[]&#40672;215v",
  to_signature = 0xc1055e00 "]&#24159;&#39184;210n\005&#32311;200n\005?}
        ip6 = (struct ip6_hdr *) 0x0
        isipv6 = 0
#9  0xc05e8d44 in tcp_do_segment (m=0xc2f74800, th=0xc2fa8824, so=0xc31f5d98, tp=0xc31ebae0,
    drop_hdrlen=40, tlen=0) at /usr/src/sys/netinet/tcp_input.c:2537
        thflags = 16
        acked = 0
        ourfinisacked = 0
        needoutput = 1
        rstreason = 1188
        todrop = 0
        win = 3191
        tiwin = 17520
        to = {to_flags = 0, to_tsval = 3271198736, to_tsecr = 3565669016, to_mss = 51944,
  to_wscale = 135 '\207', to_nsacks = 212 '?,
  to_sacks = 0xc05c72ce "\211&#37189;213]&#28725;213u&#40011;213}&#57686;211&#39199;&#40672;215v", to_signature = 0xc29ce000 ""}
#10 0xc05e6fc7 in tcp_input (m=0xc2f74800, off0=20) at /usr/src/sys/netinet/tcp_input.c:1004
        th = (struct tcphdr *) 0xc2fa8824
        ip = (struct ip *) 0xc2fa8810
        ipov = (struct ipovly *) 0xc32ad5e8
        inp = (struct inpcb *) 0xc32ad5e8
        tp = (struct tcpcb *) 0xc31ebae0
        so = (struct socket *) 0xc31f5d98
        optp = (u_char *) 0x0
        optlen = 0
        len = 40
        tlen = 0
        off = 40
        drop_hdrlen = 40
        thflags = 16
        rstreason = 1188
        ip6 = (struct ip6_hdr *) 0x0
        isipv6 = 0
        ip6buf = '\0' <repeats 16 times>, "H&#27771;207&#23093;&#39184;\&#39184;030&#37401;&#39184;000\000\000\000\000\000\000\000\001\000\000\000\000\000\000\000\000H"
        to = {to_flags = 0, to_tsval = 0, to_tsecr = 1, to_mss = 51996, to_wscale = 135 '\207',
  to_nsacks = 212 '?, to_sacks = 0xc045eb70 "\211&#36513;205&#40860;\032\203;",
  to_signature = 0x1 <Address 0x1 out of bounds>}
#11 0xc05de28d in ip_input (m=0xc2f74800) at /usr/src/sys/netinet/ip_input.c:662
        ip = (struct ip *) 0xc2fa8810
        ia = (struct in_ifaddr *) 0xc2b33200
        ifa = (struct ifaddr *) 0xc77
        checkif = 0
        hlen = 20
        sum = 1188
        dchg = 0
        odst = {s_addr = 1286374108}
#12 0xc05cbd7d in netisr_dispatch (num=2, m=0xc77) at /usr/src/sys/net/netisr.c:278
        ni = (struct netisr *) 0x4a4
#13 0xc05c7d3f in ether_demux (ifp=0xc29aac00, m=0xc2f74800) at /usr/src/sys/net/if_ethersubr.c:829
        eh = (struct ether_header *) 0x4a4
        isr = 3191
        ether_type = 2048
#14 0xc05c7b56 in ether_input (ifp=0xc29aac00, m=0xc2f74800) at /usr/src/sys/net/if_ethersubr.c:687
        eh = (struct ether_header *) 0xc2fa8802
        etype = 2048
#15 0xc04b2108 in msk_rxeof (sc_if=0xc29bf000, status=4, len=60)
    at /usr/src/sys/dev/msk/if_msk.c:3062
        m = (struct mbuf *) 0xc2f74800
        ifp = (struct ifnet *) 0xc29aac00
        cons = 0
        rxlen = 3191
#16 0xc04b2da3 in msk_handle_events (sc=0xc29be900) at /usr/src/sys/dev/msk/if_msk.c:3440
        sc_if = (struct msk_if_softc *) 0xc29bf000
        rxput = {0, 0}
        sd = (struct msk_stat_desc *) 0x4a4
        control = 3191
        status = 3932416
        cons = 991
        idx = 992
        len = 60
        port = 0
        rxprog = 0
#17 0xc04b3328 in msk_int_task (arg=0xc29be900, pending=1) at /usr/src/sys/dev/msk/if_msk.c:3553
        sc = (struct msk_softc *) 0xc29be900
        sc_if0 = (struct msk_if_softc *) 0xc29bf000
        sc_if1 = (struct msk_if_softc *) 0x0
        ifp0 = (struct ifnet *) 0xc29aac00
        ifp1 = (struct ifnet *) 0x0
        status = 1073741824
        domore = -1030147664
#18 0xc056141d in taskqueue_run (queue=0xc29a0d00) at /usr/src/sys/kern/subr_taskqueue.c:255
        task = (struct task *) 0xc29be9a0
        owned = 1
        pending = 1
#19 0xc05619b8 in taskqueue_thread_loop (arg=0x4a4) at /usr/src/sys/kern/subr_taskqueue.c:374
        tq = (struct taskqueue *) 0xc29a0d00
#20 0xc0517890 in fork_exit (callout=0xc0561920 <taskqueue_thread_loop>, arg=0x4a4, frame=0x4a4)
    at /usr/src/sys/kern/kern_fork.c:814
        p = (struct proc *) 0xc2992900
        td = (struct thread *) 0xc77
#21 0xc0699780 in fork_trampoline () at /usr/src/sys/i386/i386/exception.s:205
No locals.


boot dmesg:

Copyright (c) 1992-2007 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
        The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 7.0-CURRENT #10: Sat Mar 31 14:55:29 CST 2007
    root at equinox.dhchen.com:/usr/obj/usr/src/sys/EQUINOX
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) Celeron(R) M processor         1.40GHz (1399.85-MHz 686-class CPU)
  Origin = "GenuineIntel"  Id = 0x6d8  Stepping = 8
  Features=0xafe9fbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,TM,PBE>
  AMD Features=0x100000<NX>
real memory  = 527302656 (502 MB)
avail memory = 506490880 (483 MB)
ACPI: RSDP @ 0x0xf9190/0x0014 (v  0 IntelR)
ACPI: RSDT @ 0x0x1f6e3040/0x0030 (v  1 IntelR AWRDACPI 0x42302E31 AWRD 0x00000000)
ACPI: FACP @ 0x0x1f6e30c0/0x0074 (v  1 IntelR AWRDACPI 0x42302E31 AWRD 0x00000000)
ACPI: DSDT @ 0x0x1f6e3180/0x41EA (v  1 INTELR AWRDACPI 0x00001000 MSFT 0x0100000E)
ACPI: FACS @ 0x0x1f6e0000/0x0040
ACPI: MCFG @ 0x0x1f6e7480/0x003C (v  1 IntelR AWRDACPI 0x42302E31 AWRD 0x00000000)
ACPI: APIC @ 0x0x1f6e73c0/0x005A (v  1 IntelR AWRDACPI 0x42302E31 AWRD 0x00000000)
acpi0: <IntelR AWRDACPI> on motherboard
acpi0: [ITHREAD]
acpi0: Power Button (fixed)
acpi0: reservation of 0, a0000 (3) failed
acpi0: reservation of 100000, 1f5e0000 (3) failed
Timecounter "ACPI-safe" frequency 3579545 Hz quality 1000
acpi_timer0: <24-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0
cpu0: <ACPI CPU> on acpi0
p4tcc0: <CPU Frequency Thermal Control> on cpu0
acpi_button0: <Power Button> on acpi0
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
vgapci0: <VGA-compatible display> port 0xe400-0xe407 mem 0xd0300000-0xd037ffff,0xc0000000-0xcfffffff,0xd0380000-0xd03bffff irq 10 at device 2.0 on pci0
agp0: <Intel 82915GM (915GM GMCH) SVGA controller> on vgapci0
agp0: detected 7932k stolen memory
agp0: aperture size is 256M
pci0: <multimedia> at device 27.0 (no driver attached)
pcib1: <ACPI PCI-PCI bridge> irq 10 at device 28.0 on pci0
pci1: <ACPI PCI bus> on pcib1
mskc0: <Marvell Yukon 88E8053 Gigabit Ethernet> port 0xb000-0xb0ff mem 0xd0020000-0xd0023fff irq 10 at device 0.0 on pci1
msk0: <Marvell Technology Group Ltd. Yukon EC Id 0xb6 Rev 0x01> on mskc0
msk0: Ethernet address: 00:13:d3:50:f5:b9
miibus0: <MII bus> on msk0
e1000phy0: <Marvell 88E1111 Gigabit PHY> PHY 0 on miibus0
e1000phy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseTX-FDX, auto
mskc0: [FILTER]
pcib2: <ACPI PCI-PCI bridge> irq 12 at device 28.1 on pci0
pci2: <ACPI PCI bus> on pcib2
mskc1: <Marvell Yukon 88E8053 Gigabit Ethernet> port 0xc000-0xc0ff mem 0xd0120000-0xd0123fff irq 12 at device 0.0 on pci2
msk1: <Marvell Technology Group Ltd. Yukon EC Id 0xb6 Rev 0x01> on mskc1
msk1: Ethernet address: 00:13:d3:50:f5:b8
miibus1: <MII bus> on msk1
e1000phy1: <Marvell 88E1111 Gigabit PHY> PHY 0 on miibus1
e1000phy1:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseTX-FDX, auto
mskc1: [FILTER]
uhci0: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-A> port 0xe000-0xe01f irq 9 at device 29.0 on pci0
uhci0: [GIANT-LOCKED]
uhci0: [ITHREAD]
usb0: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-A> on uhci0
usb0: USB revision 1.0
uhub0: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb0
uhub0: 2 ports with 2 removable, self powered
uhci1: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-B> port 0xe100-0xe11f irq 11 at device 29.1 on pci0
uhci1: [GIANT-LOCKED]
uhci1: [ITHREAD]
usb1: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-B> on uhci1
usb1: USB revision 1.0
uhub1: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb1
uhub1: 2 ports with 2 removable, self powered
uhci2: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-C> port 0xe200-0xe21f irq 11 at device 29.2 on pci0
uhci2: [GIANT-LOCKED]
uhci2: [ITHREAD]
usb2: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-C> on uhci2
usb2: USB revision 1.0
uhub2: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb2
uhub2: 2 ports with 2 removable, self powered
uhci3: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-D> port 0xe300-0xe31f irq 10 at device 29.3 on pci0
uhci3: [GIANT-LOCKED]
uhci3: [ITHREAD]
usb3: <Intel 82801FB/FR/FW/FRW (ICH6) USB controller USB-D> on uhci3
usb3: USB revision 1.0
uhub3: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb3
uhub3: 2 ports with 2 removable, self powered
ehci0: <Intel 82801FB (ICH6) USB 2.0 controller> mem 0xd03c4000-0xd03c43ff irq 9 at device 29.7 on pci0
ehci0: [GIANT-LOCKED]
ehci0: [ITHREAD]
usb4: EHCI version 1.0
usb4: companion controllers, 2 ports each: usb0 usb1 usb2 usb3
usb4: <Intel 82801FB (ICH6) USB 2.0 controller> on ehci0
usb4: USB revision 2.0
uhub4: <Intel EHCI root hub, class 9/0, rev 2.00/1.00, addr 1> on usb4
uhub4: 8 ports with 8 removable, self powered
pcib3: <ACPI PCI-PCI bridge> at device 30.0 on pci0
pci3: <ACPI PCI bus> on pcib3
pci3: <serial bus, FireWire> at device 9.0 (no driver attached)
isab0: <PCI-ISA bridge> at device 31.0 on pci0
isa0: <ISA bus> on isab0
atapci0: <Intel ICH6 UDMA100 controller> port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xf000-0xf00f at device 31.1 on pci0
ata0: <ATA channel 0> on atapci0
ata0: [ITHREAD]
ata1: <ATA channel 1> on atapci0
ata1: [ITHREAD]
atapci1: <Intel ICH6 SATA150 controller> port 0xe500-0xe507,0xe600-0xe603,0xe700-0xe707,0xe800-0xe803,0xe900-0xe90f irq 11 at device 31.2 on pci0
atapci1: [ITHREAD]
ata2: <ATA channel 0> on atapci1
ata2: [ITHREAD]
ata3: <ATA channel 1> on atapci1
ata3: [ITHREAD]
ichsmb0: <SMBus controller> port 0x500-0x51f irq 11 at device 31.3 on pci0
ichsmb0: [GIANT-LOCKED]
ichsmb0: [ITHREAD]
smbus0: <System Management Bus> on ichsmb0
smb0: <SMBus generic I/O> on smbus0
acpi_tz0: <Thermal Zone> on acpi0
sio0: <16550A-compatible COM port> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
sio0: type 16550A
sio0: [FILTER]
sio1: <16550A-compatible COM port> port 0x2f8-0x2ff irq 3 on acpi0
sio1: type 16550A
sio1: [FILTER]
orm0: <ISA Option ROM> at iomem 0xc0000-0xce7ff pnpid ORM0000 on isa0
atkbdc0: <Keyboard controller (i8042)> at port 0x60,0x64 on isa0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
atkbd0: [GIANT-LOCKED]
atkbd0: [ITHREAD]
sc0: <System console> at flags 0x100 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
Timecounter "TSC" frequency 1399849927 Hz quality 800
Timecounters tick every 1.000 msec
ad0: 117800MB <HDS722512VLAT80 V33OA6MA> at ata0-master UDMA100
ad4: 238475MB <HDT722525DLA380 V44OA96A> at ata2-master SATA150
Trying to mount root from ufs:/dev/ad4s1a
WARNING: / was not properly dismounted
msk0: link state changed to UP
msk1: link state changed to UP

>How-To-Repeat:

>Fix:

>Release-Note:
>Audit-Trail:
>Unformatted:


More information about the freebsd-bugs mailing list