[Bug 260393] Page Fault tcp_output/tcp_input

From: <bugzilla-noreply_at_freebsd.org>
Date: Wed, 22 Dec 2021 13:55:41 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=260393

--- Comment #45 from Dobri Dobrev <ddobrev85@gmail.com> ---
(In reply to Hans Petter Selasky from comment #44)

(kgdb) where
#0  __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
#1  doadump (textdump=<optimized out>) at /usr/src/sys/kern/kern_shutdown.c:399
#2  0xffffffff80c12f6c in kern_reboot (howto=260) at
/usr/src/sys/kern/kern_shutdown.c:487
#3  0xffffffff80c133de in vpanic (fmt=0xffffffff81191bdd "%s", ap=<optimized
out>) at /usr/src/sys/kern/kern_shutdown.c:920
#4  0xffffffff80c131e3 in panic (fmt=<unavailable>) at
/usr/src/sys/kern/kern_shutdown.c:844
#5  0xffffffff810991b5 in trap_fatal (frame=0xfffffe00d3bfd5b0, eva=24) at
/usr/src/sys/amd64/amd64/trap.c:944
#6  0xffffffff8109920f in trap_pfault (frame=0xfffffe00d3bfd5b0,
usermode=false, signo=<optimized out>, ucode=<optimized out>) at
/usr/src/sys/amd64/amd64/trap.c:763
#7  <signal handler called>
#8  m_copydata (m=0x0, m@entry=0xfffff8010ee80d00, off=0, len=1, cp=<optimized
out>) at /usr/src/sys/kern/uipc_mbuf.c:657
#9  0xffffffff80dd5fa9 in tcp_output (tp=<optimized out>) at
/usr/src/sys/netinet/tcp_output.c:1081
#10 0xffffffff80dcd382 in tcp_do_segment (m=<optimized out>, th=<optimized
out>, so=<optimized out>, tp=0xfffffe0251638870, drop_hdrlen=40,
tlen=<optimized out>, iptos=0 '\000') at /usr/src/sys/netinet/tcp_input.c:2822
#11 0xffffffff80dc9d41 in tcp_input_with_port (mp=<optimized out>,
offp=<optimized out>, proto=<optimized out>, port=port@entry=0) at
/usr/src/sys/netinet/tcp_input.c:1400
#12 0xffffffff80dca9eb in tcp_input (mp=0xfffff8010ee80d00, offp=0x0, proto=1)
at /usr/src/sys/netinet/tcp_input.c:1496
#13 0xffffffff80dbc1bf in ip_input (m=0x0) at
/usr/src/sys/netinet/ip_input.c:834
#14 0xffffffff80d491a9 in netisr_dispatch_src (proto=1, source=source@entry=0,
m=0xfffff8015b58d700) at /usr/src/sys/net/netisr.c:1143
#15 0xffffffff80d4957f in netisr_dispatch (proto=250088704, m=0x1) at
/usr/src/sys/net/netisr.c:1234
#16 0xffffffff80d2d128 in ether_demux (ifp=ifp@entry=0xfffff80105343000, m=0x0)
at /usr/src/sys/net/if_ethersubr.c:921
#17 0xffffffff80d2e4b5 in ether_input_internal (ifp=0xfffff80105343000, m=0x0)
at /usr/src/sys/net/if_ethersubr.c:707
#18 ether_nh_input (m=<optimized out>) at /usr/src/sys/net/if_ethersubr.c:737
#19 0xffffffff80d491a9 in netisr_dispatch_src (proto=proto@entry=5,
source=source@entry=0, m=m@entry=0xfffff8015b58d700) at
/usr/src/sys/net/netisr.c:1143
#20 0xffffffff80d4957f in netisr_dispatch (proto=250088704, proto@entry=5,
m=0x1, m@entry=0xfffff8015b58d700) at /usr/src/sys/net/netisr.c:1234
#21 0xffffffff80d2d559 in ether_input (ifp=<optimized out>,
m=0xfffff8015b58d700) at /usr/src/sys/net/if_ethersubr.c:828
#22 0xffffffff80d45617 in iflib_rxeof (rxq=<optimized out>,
rxq@entry=0xfffffe00d68b6340, budget=<optimized out>) at
/usr/src/sys/net/iflib.c:3046
#23 0xffffffff80d3fc62 in _task_fn_rx (context=0xfffffe00d68b6340) at
/usr/src/sys/net/iflib.c:3989
#24 0xffffffff80c5f80d in gtaskqueue_run_locked
(queue=queue@entry=0xfffff80103920b00) at
/usr/src/sys/kern/subr_gtaskqueue.c:371
#25 0xffffffff80c5f482 in gtaskqueue_thread_loop (arg=<optimized out>,
arg@entry=0xfffffe00d6bd1020) at /usr/src/sys/kern/subr_gtaskqueue.c:547
#26 0xffffffff80bd053e in fork_exit (callout=0xffffffff80c5f3c0
<gtaskqueue_thread_loop>, arg=0xfffffe00d6bd1020, frame=0xfffffe00d3bfdf40) at
/usr/src/sys/kern/kern_fork.c:1092
#27 <signal handler called>
#28 mi_startup () at /usr/src/sys/kern/init_main.c:322
Backtrace stopped: Cannot access memory at address 0xb
(kgdb) frame 8
#8  m_copydata (m=0x0, m@entry=0xfffff8010ee80d00, off=0, len=1, cp=<optimized
out>) at /usr/src/sys/kern/uipc_mbuf.c:657
warning: Source file is more recent than executable.
657                     count = min(m->m_len - off, len);
(kgdb) print /x *tp->t_inpcb
No symbol "tp" in current context.
(kgdb) print /x tp->t_inpcb
No symbol "tp" in current context.
(kgdb) 


There doesn't appear to be "tp" in frame 8 ...

-- 
You are receiving this mail because:
You are the assignee for the bug.