[Bug 290039] core under load 15.0-ALPHA4-ish

From: <bugzilla-noreply_at_freebsd.org>
Date: Mon, 06 Oct 2025 11:03:19 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=290039

            Bug ID: 290039
           Summary: core under load 15.0-ALPHA4-ish
           Product: Base System
           Version: 15.0-STABLE
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: kern
          Assignee: bugs@FreeBSD.org
          Reporter: dave@daveg.ca

Created attachment 264344
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=264344&action=edit
system core file description.

Multiple core dumps on poudriere.  Core file available if required.

__curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:57
57              __asm("movq %%gs:%c1,%0" : "=r" (td)
(kgdb) #0  __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:57
        td = <optimized out>
#1  doadump (textdump=<optimized out>) at /usr/src/sys/kern/kern_shutdown.c:399
        error = 0
        coredump = <optimized out>
#2  0xffffffff80b732a9 in kern_reboot (howto=260)
    at /usr/src/sys/kern/kern_shutdown.c:519
        once = 0
#3  0xffffffff80b737b7 in vpanic (fmt=0xffffffff811d2f80 "%s",
    ap=ap@entry=0xfffffe01e22f0520) at /usr/src/sys/kern/kern_shutdown.c:974
        buf = "page fault", '\000' <repeats 245 times>
        __pc = 0x0
        __pc = 0x0
        __pc = 0x0
        other_cpus = {__bits = {61439, 0 <repeats 15 times>}}
        td = 0xfffff80103bad780
        bootopt = <unavailable>
        newpanic = <optimized out>
#4  0xffffffff80b735e3 in panic (fmt=<unavailable>)
    at /usr/src/sys/kern/kern_shutdown.c:887
        ap = {{gp_offset = 16, fp_offset = 48,
            overflow_arg_area = 0xfffffe01e22f0550,
            reg_save_area = 0xfffffe01e22f04f0}}
#5  0xffffffff8107bf69 in trap_fatal (frame=<optimized out>,
    eva=<optimized out>) at /usr/src/sys/amd64/amd64/trap.c:969
        type = <optimized out>
        handled = <optimized out>
#6  0xffffffff8107bf69 in trap_pfault (frame=0xfffffe01e22f05a0,
    usermode=false, signo=<optimized out>, ucode=<optimized out>)
        __pc = 0x0
        __pc = 0x0
        __pc = 0x0
        td = <optimized out>
        p = <optimized out>
        eva = <optimized out>
        map = <optimized out>
        ftype = <optimized out>
        rv = <optimized out>
#7  <signal handler called>
No locals.
#8  syncache_drop (sc=0x0, sch=sch@entry=0xfffffe01f8339530)
    at /usr/src/sys/netinet/tcp_syncache.c:420
No locals.
#9  0xffffffff80d6b855 in syncache_insert (sc=sc@entry=0xfffff804d361dd10,
    sch=0xfffffe01f8339530) at /usr/src/sys/netinet/tcp_syncache.c:383
        sc2 = 0x0
#10 0xffffffff80d6acb1 in syncache_add (inc=inc@entry=0xfffffe01e22f08b0,
    to=to@entry=0xfffffe01e22f0850, th=th@entry=0xfffff8032f9c9482,
    inp=inp@entry=0xfffff803312a0540, so=0xfffff8027d85b000,
    m=m@entry=0xfffff8032f9c9400, tod=0x0, todctx=0x0, iptos=0 '\000', port=0)
    at /usr/src/sys/netinet/tcp_syncache.c:1763
        sch = 0xfffffe01f8339530
        maclabel = 0x0
        scs = {sc_hash = {tqe_next = 0x0, tqe_prev = 0x7a724001}, sc_inc = {
            inc_flags = 64 '@', inc_len = 7 '\a', inc_fibnum = 57903,
            inc_ie = {ie_fport = 65025, ie_lport = 65535, ie_dependfaddr = {
                id46_addr = {ia46_pad32 = {2161349369, 4294967295,
                    4294967295}, ia46_addr4 = {s_addr = 4294965249}},
                id6_addr = {__u6_addr = {
                    __u6_addr8 =
"\371\222Ӏ\377\377\377\377\377\377\377\377\001\370\377\377", __u6_addr16 =
{37625, 32979, 65535, 65535, 65535, 65535, 63489,
                      65535}, __u6_addr32 = {2161349369, 4294967295,
                      4294967295, 4294965249}}}}, ie_dependladdr = {
                id46_addr = {ia46_pad32 = {3568101248, 854501411, 0},
                  ia46_addr4 = {s_addr = 0}}, id6_addr = {__u6_addr = {
                    __u6_addr8 =
"\200\347\254\324#\250\3562\000\000\000\000\000\000\000", __u6_addr16 = {59264,
54444, 43043, 13038, 0, 0, 0, 0},
                    __u6_addr32 = {3568101248, 854501411, 0, 0}}}},
              ie6_zoneid = 22}}, sc_rxttime = 873750594, sc_rxmits = 0,
          sc_port = 0, sc_tsreflect = 0, sc_tsoff = 0, sc_flowlabel = 0,
          sc_irs = 3, sc_iss = 873750594, sc_ipopts = 0x3,
          sc_peer_mss = 51624, sc_wnd = 24048, sc_ip_ttl = 1 '\001',
          sc_ip_tos = 254 '\376', sc_requested_s_scale = 15 '\017',
          sc_requested_r_scale = 15 '\017', sc_flags = 255,
          sc_challenge_ack_cnt = 0, sc_challenge_ack_end = 4294967295,
          sc_tod = 0xfffff80103bad780, sc_todctx = 0xfffff803312a0540,
          sc_label = 0x2, sc_cred = 0xfffffe01e22f07a0,
          sc_tfo_cookie = 0xffffffff80d3c34f <in_pcblookup_hash+127>,
          sc_pspare = 0xfffffe01e22f07b0, sc_spare = {2159219129, 4294967295}}
        tfo_response_cookie = 18446735287623739636
        rv = 0x0
        sc = 0xfffff804d361dd10
        ipopts = 0x0
        autoflowlabel = 0
        tfo_pending = 0x0
        tfo_cookie_valid = 0
        tfo_response_cookie_valid = <optimized out>
        tp = 0xfffff803312a0540
        ip_ttl = 64
        ip_tos = <optimized out>
        win = <optimized out>
        ltflags = 0
        s = <optimized out>
        locked = <optimized out>
#11 0xffffffff80d4fa18 in tcp_input_with_port (mp=<optimized out>,
    offp=<optimized out>, proto=<optimized out>, port=port@entry=0)
    at /usr/src/sys/netinet/tcp_input.c:1348
        inc = {inc_flags = 0 '\000', inc_len = 0 '\000', inc_fibnum = 0,
          inc_ie = {ie_fport = 46367, ie_lport = 47873, ie_dependfaddr = {
              id46_addr = {ia46_pad32 = {0, 0, 0}, ia46_addr4 = {
                  s_addr = 854501411}}, id6_addr = {__u6_addr = {
                  __u6_addr8 = '\000' <repeats 12 times>, "#\250", <incomplete
sequence \356\062>, __u6_addr16 = {0, 0, 0, 0, 0, 0, 43043, 13038},
                  __u6_addr32 = {0, 0, 0, 854501411}}}}, ie_dependladdr = {
              id46_addr = {ia46_pad32 = {0, 0, 0}, ia46_addr4 = {
                  s_addr = 873750594}}, id6_addr = {__u6_addr = {
                  __u6_addr8 = '\000' <repeats 12 times>, "B`\0244",
                  __u6_addr16 = {0, 0, 0, 0, 0, 0, 24642, 13332},
                  __u6_addr32 = {0, 0, 0, 873750594}}}}, ie6_zoneid = 0}}
        so = 0xfffff8027d85b000
        to = {to_flags = 23, to_tsval = 786907833, to_tsecr = 0,
          to_sacks = 0xfffff8032289f80e "E",
          to_signature = 0xfffff8032289f80e "E", to_tfo_cookie = 0x0,
          to_mss = 1200, to_wscale = 7 '\a', to_nsacks = 107 'k',
          to_tfo_len = 3 '\003', to_spare = 1638199296}
        m = 0xfffff8032f9c9400
        th = 0xfffff8032f9c9482
        ip = 0xfffff8032f9c946e
        inp = 0xfffff803312a0540
        tp = 0xfffff803312a0540
        optp = 0xfffff8032f9c9496 "\002\004\004\260\004\002\b\n.\347B\271"
        optlen = 20
        tlen = <optimized out>
        fwd_tag = 0x0
        ip6 = 0x0
        s = 0x0
        closed_port = false
        off0 = <optimized out>
        iptos = 0 '\000'
        off = <optimized out>
        len = <optimized out>
        ipttl = <optimized out>
        thflags = <optimized out>
        drop_hdrlen = 60
        lookupflag = 3
        isipv6 = <optimized out>
#12 0xffffffff80d5009b in tcp_input (mp=0x0, offp=0xfffffe01f8339530, proto=0)
    at /usr/src/sys/netinet/tcp_input.c:1493
No locals.
#13 0xffffffff80d3fa39 in ip_input (m=0x0)
    at /usr/src/sys/netinet/ip_input.c:861
        hlen = 20
        ip = 0xfffff8032f9c946e
        ia = <optimized out>
        dchg = <optimized out>
        ifp = <optimized out>
        ip_len = <optimized out>
        sum = <optimized out>
        odst = <optimized out>
        strong_es = <optimized out>
        ifa = <optimized out>
#14 0xffffffff80cc040f in netisr_dispatch_src (proto=proto@entry=1,
    source=18446741883145393456, source@entry=0, m=0x0)
    at /usr/src/sys/net/netisr.c:1151
        __pc = 0x0
        __pc = 0x0
        __pc = 0x0
        cpuid = 0
        npp = 0xffffffff81c02438 <netisr_proto+56>
        dispatch_policy = <optimized out>
        nwsp = <optimized out>
        npwp = <optimized out>
        error = <optimized out>
        dosignal = <optimized out>
        out_unlock = <optimized out>
#15 0xffffffff80cc07ef in netisr_dispatch (proto=0, proto@entry=1, m=0x0)
    at /usr/src/sys/net/netisr.c:1242
No locals.
#16 0xffffffff80ca4269 in ether_demux (ifp=ifp@entry=0xfffff8024b0ff000,
    m=0xfffff8032f9c9400) at /usr/src/sys/net/if_ethersubr.c:938
        i = <optimized out>
        eh = <optimized out>
        ether_type = <optimized out>
        isr = 1
#17 0xffffffff80ca55c9 in ether_input_internal (ifp=0xfffff8024b0ff000,
    m=0xfffff8032f9c9400) at /usr/src/sys/net/if_ethersubr.c:702
        eh = 0xfffff8032f9c9460
        saved_vnet = 0xfffff801014e3100
        etype = <optimized out>
        evl = <optimized out>
#18 ether_nh_input (m=<optimized out>) at /usr/src/sys/net/if_ethersubr.c:732
No locals.
#19 0xffffffff80cc040f in netisr_dispatch_src (proto=proto@entry=5,
    source=18446741883145393456, source@entry=0, m=0x0)
    at /usr/src/sys/net/netisr.c:1151
        __pc = 0x0
        __pc = 0x0
        __pc = 0x0
        cpuid = 0
        npp = 0xffffffff81c02518 <netisr_proto+280>
        dispatch_policy = <optimized out>
        nwsp = <optimized out>
        npwp = <optimized out>
        error = <optimized out>
        dosignal = <optimized out>
        out_unlock = <optimized out>
#20 0xffffffff80cc07ef in netisr_dispatch (proto=0, proto@entry=5, m=0x0)
    at /usr/src/sys/net/netisr.c:1242
No locals.
#21 0xffffffff80ca45d6 in ether_input (ifp=<optimized out>,
    m=0xfffffe01f8339530) at /usr/src/sys/net/if_ethersubr.c:843
        et = {et_link = {tqe_next = 0xfffffe01e22f0b40, tqe_prev = 0x0},
          et_td = 0xfffffe01e22f0b70, et_section = {bucket = 2160778628},
          et_old_priority = 255 '\377'}
        saved_vnet = 0xfffff801014e3100
        mn = 0x0
        needs_epoch = <optimized out>
#22 0xffffffff80ca41ae in ether_demux (ifp=ifp@entry=0xfffff80105eb2000,
    m=0xfffff8032f9c9400) at /usr/src/sys/net/if_ethersubr.c:889
        i = <optimized out>
        eh = <optimized out>
        ether_type = <optimized out>
        isr = <optimized out>
#23 0xffffffff80ca55c9 in ether_input_internal (ifp=0xfffff80105eb2000,
    m=0xfffff8032f9c9400) at /usr/src/sys/net/if_ethersubr.c:702
        eh = 0xfffff8032f9c9460
        saved_vnet = 0xfffff801014e3100
        etype = <optimized out>
        evl = <optimized out>
#24 ether_nh_input (m=<optimized out>) at /usr/src/sys/net/if_ethersubr.c:732
No locals.
#25 0xffffffff80cc040f in netisr_dispatch_src (proto=proto@entry=5,
    source=18446741883145393456, source@entry=0, m=0x0)
    at /usr/src/sys/net/netisr.c:1151
        __pc = 0x0
        __pc = 0x0
        __pc = 0x0
        cpuid = 4294966785
        npp = 0xffffffff81c02518 <netisr_proto+280>
        dispatch_policy = <optimized out>
        nwsp = <optimized out>
        npwp = <optimized out>
        error = <optimized out>
        dosignal = <optimized out>
        out_unlock = <optimized out>
#26 0xffffffff80cc07ef in netisr_dispatch (proto=0, proto@entry=5, m=0x0)
    at /usr/src/sys/net/netisr.c:1242
No locals.
#27 0xffffffff80ca45d6 in ether_input (ifp=<optimized out>,
    m=0xfffffe01f8339530) at /usr/src/sys/net/if_ethersubr.c:843
        et = {et_link = {tqe_next = 0xfffffe01e22f0ca0,
            tqe_prev = 0xffffffff80b84e4c <binuptime+76>},
          et_td = 0xfffff801014e3100, et_section = {bucket = 3843841328},
          et_old_priority = 1 '\001'}
        saved_vnet = 0xfffff801014e3100
        mn = 0x0
        needs_epoch = <optimized out>
#28 0xffffffff80d58bbc in tcp_lro_flush_all (lc=lc@entry=0xfffffe01e51c5d30)
    at /usr/src/sys/netinet/tcp_lro.c:1252
        mb = 0xfffff8032f9c9400
        __pc = 0x0
        __pc = 0x0
        saved_vnet = 0x0
        seq = 13820913490958745600
        x = 0
        nseq = <optimized out>
#29 0xffffffff80cbca08 in iflib_rxeof (rxq=rxq@entry=0xfffffe01e51c5d00,
    budget=<optimized out>) at /usr/src/sys/net/iflib.c:3029
        ri = <optimized out>
        ctx = 0xfffff80105e8f000
        sctx = 0xffffffff81838140 <ixgbe_sctx_init>
        scctx = 0xfffff80105e8f0a8
        retval = <optimized out>
        ifp = 0xfffff80105eb2000
        mt = 0x0
        mh = 0x0
        rx_bytes = 74
        rx_pkts = 1
        cidxp = 0xfffff8010603fa00
        avail = 0
        saved_vnet = 0x0
        budget_left = 15
        err = <optimized out>
        m = <optimized out>
        i = <optimized out>
        fl = <optimized out>
        lro_enabled = <optimized out>
#30 0xffffffff80cb75d2 in _task_fn_rx (context=0xfffffe01e51c5d00)
    at /usr/src/sys/net/iflib.c:4080
        __pc = 0x0
        work = 0
        rxq = 0xfffffe01e51c5d00
        ctx = 0xfffff80105e8f000
        nmirq = <optimized out>
        more = <optimized out>
        budget = 38192
#31 0xffffffff80bbecde in gtaskqueue_run_locked (
    queue=queue@entry=0xfffff801017bb600)
    at /usr/src/sys/kern/subr_gtaskqueue.c:368
        et = {et_link = {tqe_next = 0x0, tqe_prev = 0xfffffe00b335dad8},
          et_td = 0xfffff80103bad780, et_section = {bucket = 1},
          et_old_priority = 2 '\002'}
        tb = {tb_running = 0xfffffe01e51c5db0, tb_seq = 1826916, tb_link = {
            le_next = 0x0, le_prev = 0xfffff801017bb610}}
        in_net_epoch = true
        gtask = <optimized out>
#32 0xffffffff80bbe982 in gtaskqueue_thread_loop (
    arg=arg@entry=0xfffffe01e2c63128)
    at /usr/src/sys/kern/subr_gtaskqueue.c:544
        tqp = <optimized out>
        tq = 0xfffff801017bb600
#33 0xffffffff80b298eb in fork_exit (
    callout=0xffffffff80bbe8c0 <gtaskqueue_thread_loop>,
    arg=0xfffffe01e2c63128, frame=0xfffffe01e22f0f40)
    at /usr/src/sys/kern/kern_fork.c:1153
        __pc = 0x0
        __pc = 0x0
        td = 0xfffff80103bad780
        p = 0xffffffff81b81cd8 <proc0>
        dtd = <optimized out>
#34 <signal handler called>
No locals.
#35 0x491243f0455243f4 in ?? ()
No symbol table info available.
Backtrace stopped: Cannot access memory at address 0xee25d8bce265d8b8

-- 
You are receiving this mail because:
You are the assignee for the bug.