[Bug 257195] [tcp] Panic when RACK enabled: tcp_hptsi at /usr/src/sys/netinet/tcp_hpts.c:1662

From: <bugzilla-noreply_at_freebsd.org>
Date: Sun, 18 Jul 2021 04:07:43 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=257195

--- Comment #14 from iron.udjin@gmail.com ---
(In reply to iron.udjin from comment #12)

OS: stable/13-n246050-07ef7a034965

On another server I catched one more panic. But it has a little bit different
trace:

Fatal trap 12: page fault while in kernel mode
cpuid = 39; apic id = 33
fault virtual address   = 0x18
fault code              = supervisor read data, page not present
instruction pointer     = 0x20:0xffffffff80fc1c20
stack pointer           = 0x0:0xfffffe0321555e90
frame pointer           = 0x0:0xfffffe0321555ed0
code segment            = base 0x0, limit 0xfffff, type 0x1b
                        = DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags        = interrupt enabled, resume, IOPL = 0
current process         = 11 (swi1: hpts)
trap number             = 12
panic: page fault
cpuid = 39
time = 1624174594
KDB: stack backtrace:
#0 0xffffffff805f37a5 at kdb_backtrace+0x65
#1 0xffffffff805a9931 at vpanic+0x181
#2 0xffffffff805a97a3 at panic+0x43
#3 0xffffffff80852617 at trap_fatal+0x387
#4 0xffffffff8085266f at trap_pfault+0x4f
#5 0xffffffff80851ce3 at trap+0x253
#6 0xffffffff8082ac18 at calltrap+0x8
#7 0xffffffff80fb183c at rack_log_output+0xec
#8 0xffffffff80fa9a33 at rack_output+0x6ca3
#9 0xffffffff80718835 at tcp_hpts_thread+0x725
#10 0xffffffff8056cfed at ithread_loop+0x24d
#11 0xffffffff80569ebd at fork_exit+0x7d
#12 0xffffffff8082bc9e at fork_trampoline+0xe
Uptime: 9h40m48s
Dumping 21243 out of 196233
MB:..1%..11%..21%..31%..41%..51%..61%..71%..81%..91%

__curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
55              __asm("movq %%gs:%P1,%0" : "=r" (td) : "n" (offsetof(struct
pcpu,
(kgdb) #0  __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
#1  doadump (textdump=<optimized out>)
    at /usr/src/sys/kern/kern_shutdown.c:399
#2  0xffffffff805a9525 in kern_reboot (howto=260)
    at /usr/src/sys/kern/kern_shutdown.c:486
#3  0xffffffff805a99a0 in vpanic (fmt=<optimized out>, ap=<optimized out>)
    at /usr/src/sys/kern/kern_shutdown.c:919
#4  0xffffffff805a97a3 in panic (fmt=<unavailable>)
    at /usr/src/sys/kern/kern_shutdown.c:843
#5  0xffffffff80852617 in trap_fatal (frame=0xfffffe0321555dd0, eva=24)
    at /usr/src/sys/amd64/amd64/trap.c:943
#6  0xffffffff8085266f in trap_pfault (frame=frame@entry=0xfffffe0321555dd0, 
    usermode=false, signo=<optimized out>, signo@entry=0x0, 
    ucode=<optimized out>, ucode@entry=0x0)
    at /usr/src/sys/amd64/amd64/trap.c:760
#7  0xffffffff80851ce3 in trap (frame=0xfffffe0321555dd0)
    at /usr/src/sys/amd64/amd64/trap.c:438
#8  <signal handler called>
#9  rack_setup_offset_for_rsm (src_rsm=0xfffff814ec3da230, 
    rsm=0xfffff81f552bebd0)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:6024
    at /usr/src/sys/kern/kern_shutdown.c:919
#4  0xffffffff805a97a3 in panic (fmt=<unavailable>)
    at /usr/src/sys/kern/kern_shutdown.c:843
#5  0xffffffff80852617 in trap_fatal (frame=0xfffffe0321555dd0, eva=24)
    at /usr/src/sys/amd64/amd64/trap.c:943
#6  0xffffffff8085266f in trap_pfault (frame=frame@entry=0xfffffe0321555dd0, 
    usermode=false, signo=<optimized out>, signo@entry=0x0, 
    ucode=<optimized out>, ucode@entry=0x0)
    at /usr/src/sys/amd64/amd64/trap.c:760
#7  0xffffffff80851ce3 in trap (frame=0xfffffe0321555dd0)
    at /usr/src/sys/amd64/amd64/trap.c:438
#8  <signal handler called>
#9  rack_setup_offset_for_rsm (src_rsm=0xfffff814ec3da230, 
    rsm=0xfffff81f552bebd0)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:6024
#10 rack_clone_rsm (rack=<optimized out>, nrsm=0xfffff81f552bebd0, 
    rsm=0xfffff814ec3da230, start=3444253360)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:6076
#11 rack_update_entry (tp=tp@entry=0xfffffe07d12dc870, 
    rack=0xfffffe07c8e3cd00, rsm=0xfffff814ec3da230, ts=34848115395, 
    lenp=lenp@entry=0xfffffe0321555f14, add_flag=<optimized out>)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:7169
#12 0xffffffff80fb183c in rack_log_output (tp=tp@entry=0xfffffe07d12dc870, 
    to=<optimized out>, len=len@entry=253, seq_out=3444253107, 
    th_flags=<optimized out>, th_flags@entry=16 '\020', err=err@entry=0, 
    cts=34848115395, hintrsm=0x0, add_flag=16384, s_mb=0xfffff80df0cd4800, 
    s_moff=1)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:7384
#13 0xffffffff80fa9a33 in rack_fast_rsm_output (tp=<optimized out>, 
    rack=<optimized out>, rsm=<optimized out>, ts_val=<optimized out>, 
    cts=488377027, ms_cts=34848115, tv=0xfffffe0321556018, 
    len=<optimized out>)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:15404
#14 rack_output (tp=<optimized out>)
    at /usr/src/sys/modules/tcp/rack/../../../netinet/tcp_stacks/rack.c:16417
#15 0xffffffff80718835 in tcp_hptsi (hpts=0xfffff8184d9f3700)
    at /usr/src/sys/netinet/tcp_hpts.c:1613
#16 tcp_hpts_thread (ctx=0xfffff8184d9f3700)
    at /usr/src/sys/netinet/tcp_hpts.c:1832
#17 0xffffffff8056cfed in intr_event_execute_handlers (p=<optimized out>, 
    ie=0xfffff8184d9d0c00) at /usr/src/sys/kern/kern_intr.c:1168
#18 ithread_execute_handlers (p=<optimized out>, ie=0xfffff8184d9d0c00)
    at /usr/src/sys/kern/kern_intr.c:1181
#19 ithread_loop (arg=arg@entry=0xfffff8184d9e3640)
    at /usr/src/sys/kern/kern_intr.c:1269
#20 0xffffffff80569ebd in fork_exit (
    callout=0xffffffff8056cda0 <ithread_loop>, arg=0xfffff8184d9e3640, 
    frame=0xfffffe0321556480) at /usr/src/sys/kern/kern_fork.c:1083
#21 <signal handler called>
(kgdb)

There is also VIMAGE enabled.

-- 
You are receiving this mail because:
You are the assignee for the bug.