[Bug 252700] page fault in zfsctl_snapdir_lookup

From: <bugzilla-noreply_at_freebsd.org>
Date: Thu, 27 Jul 2023 11:18:37 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=252700

geoffroy desvernay <dgeo@centrale-marseille.fr> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |dgeo@centrale-marseille.fr

--- Comment #14 from geoffroy desvernay <dgeo@centrale-marseille.fr> ---
I do experience pseudo random crashes with find(8), may this be related ?

Unread portion of the kernel message buffer:
panic: page fault
cpuid = 4
time = 1690247328
KDB: stack backtrace:
#0 0xffffffff80c53d95 at kdb_backtrace+0x65
#1 0xffffffff80c06711 at vpanic+0x151
#2 0xffffffff80c065b3 at panic+0x43
#3 0xffffffff810b1fa7 at trap_fatal+0x387
#4 0xffffffff810b1fff at trap_pfault+0x4f
#5 0xffffffff81088e48 at calltrap+0x8
#6 0xffffffff80ce4d96 at vgonel+0x186
#7 0xffffffff80ce5451 at vgone+0x31
#8 0xffffffff80cd3df9 at vfs_hash_insert+0x279
#9 0xffffffff82176e59 at sfs_vgetx+0x149
#10 0xffffffff82177a44 at zfsctl_snapdir_lookup+0x1e4
#11 0xffffffff80cd60ac at lookup+0x45c
#12 0xffffffff80cd52cd at namei+0x24d
#13 0xffffffff80cf2c16 at kern_statat+0xf6
#14 0xffffffff80cf331f at sys_fstatat+0x2f
#15 0xffffffff810b289c at amd64_syscall+0x10c
#16 0xffffffff8108975b at fast_syscall_common+0xf8
Uptime: 18h19m29s

__curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
55              __asm("movq %%gs:%P1,%0" : "=r" (td) : "n" (offsetof(struct
pcpu,
(kgdb) bt
#0  __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
#1  doadump (textdump=<optimized out>) at /usr/src/sys/kern/kern_shutdown.c:396
#2  0xffffffff80c062da in kern_reboot (howto=260) at
/usr/src/sys/kern/kern_shutdown.c:484
#3  0xffffffff80c0677e in vpanic (fmt=<optimized out>,
ap=ap@entry=0xfffffe01a84643d0)
    at /usr/src/sys/kern/kern_shutdown.c:923
#4  0xffffffff80c065b3 in panic (fmt=<unavailable>) at
/usr/src/sys/kern/kern_shutdown.c:847
#5  0xffffffff810b1fa7 in trap_fatal (frame=0xfffffe01a84644c0, eva=0) at
/usr/src/sys/amd64/amd64/trap.c:942
#6  0xffffffff810b1fff in trap_pfault (frame=0xfffffe01a84644c0,
usermode=false, signo=<optimized out>, 
    ucode=<optimized out>) at /usr/src/sys/amd64/amd64/trap.c:761
#7  <signal handler called>
#8  0x0000000000000000 in ?? ()
#9  0xffffffff811813fc in VOP_CLOSE_APV (vop=0xffffffff8242aad0
<zfsctl_ops_snapshot>, a=a@entry=0xfffffe01a84645b0)
    at vnode_if.c:498
#10 0xffffffff80ce4d96 in VOP_CLOSE (vp=0xfffff805ce07c3d0, fflag=4, cred=0x0,
td=0xfffffe01a3ecaac0) at ./vnode_if.h:249
#11 vgonel (vp=vp@entry=0xfffff805ce07c3d0) at
/usr/src/sys/kern/vfs_subr.c:4092
#12 0xffffffff80ce5451 in vgone (vp=vp@entry=0xfffff805ce07c3d0) at
/usr/src/sys/kern/vfs_subr.c:3967
#13 0xffffffff80cd3df9 in vfs_hash_insert (vp=0xfffff805ce07c3d0, hash=7373,
hash@entry=2823179312, 
    flags=flags@entry=2097152, td=td@entry=0xfffffe01a3ecaac0,
vpp=vpp@entry=0xfffffe01a8464c30, fn=<optimized out>, 
    arg=0xfffff808188efd80) at /usr/src/sys/kern/vfs_hash.c:181
#14 0xffffffff82176e59 in sfs_vnode_insert (vp=0xfffffe01a84645b0,
flags=2097152, id=<optimized out>, 
    parent_id=<optimized out>, vpp=<optimized out>) at
/usr/src/sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ctldir.c:152
#15 sfs_vgetx (mp=0xfffffe01637fab00, flags=flags@entry=2097152,
parent_id=parent_id@entry=2, id=<optimized out>, 
    tag=<optimized out>, vops=0xffffffff8242aad0 <zfsctl_ops_snapshot>, 
    setup=0xffffffff82178180 <zfsctl_snapshot_vnode_setup>,
arg=0xfffffe01a8464820, vpp=0xfffffe01a8464c30)
    at /usr/src/sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ctldir.c:200
#16 0xffffffff82177a44 in zfsctl_snapdir_lookup (ap=<optimized out>)
    at /usr/src/sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ctldir.c:954
#17 0xffffffff80cd60ac in VOP_LOOKUP (dvp=0xfffff805e17b67a0,
vpp=0xfffffe01a8464c30, cnp=0xfffffe01a8464c58)
    at ./vnode_if.h:65
#18 lookup (ndp=ndp@entry=0xfffffe01a8464bd8) at
/usr/src/sys/kern/vfs_lookup.c:1086
#19 0xffffffff80cd52cd in namei (ndp=ndp@entry=0xfffffe01a8464bd8) at
/usr/src/sys/kern/vfs_lookup.c:616
#20 0xffffffff80cf2c16 in kern_statat (td=0xfffffe01a3ecaac0, flag=<optimized
out>, fd=-100, path=0x0, 
    pathseg=(unknown: 0xa3ecafd0), pathseg@entry=UIO_USERSPACE,
sbp=0xfffffe01a8465000, sbp@entry=0xfffffe01a8464d18, 
    hook=0x0) at /usr/src/sys/kern/vfs_syscalls.c:2438
#21 0xffffffff80cf331f in sys_fstatat (td=0xfffffe01a84645b0,
uap=0xfffffe01a3ecaea8)
    at /usr/src/sys/kern/vfs_syscalls.c:2415
#22 0xffffffff810b289c in syscallenter (td=0xfffffe01a3ecaac0) at
/usr/src/sys/amd64/amd64/../../kern/subr_syscall.c:190
#23 amd64_syscall (td=0xfffffe01a3ecaac0, traced=0) at
/usr/src/sys/amd64/amd64/trap.c:1183
#24 <signal handler called>
#25 0x0000107a36849cba in ?? ()
Backtrace stopped: Cannot access memory at address 0x107a342835e8

-- 
You are receiving this mail because:
You are the assignee for the bug.