[Bug 260393] Page Fault tcp_output/tcp_input

From: <bugzilla-noreply_at_freebsd.org>
Date: Sat, 16 Apr 2022 16:44:03 +0000

--- Comment #92 from Dobri Dobrev <ddobrev85_at_gmail.com> ---
(In reply to Michael Tuexen from comment #91)

I hadn't had a chance to update to the latest stable/13.

Just got a crash after 112 days uptime on stable/13-n248590-b7da472979a

Here's what kgdb shows:

Reading symbols from /boot/kernel/kernel...
Reading symbols from /usr/lib/debug//boot/kernel/kernel.debug...

Unread portion of the kernel message buffer:
[9705874] panic: page fault
[9705874] cpuid = 5
[9705874] time = 1650110040
[9705874] KDB: stack backtrace:
[9705874] #0 0xffffffff80c60dd5 at kdb_backtrace+0x65
[9705874] #1 0xffffffff80c1336f at vpanic+0x17f
[9705874] #2 0xffffffff80c131e3 at panic+0x43
[9705874] #3 0xffffffff810991b5 at trap_fatal+0x385
[9705874] #4 0xffffffff8109920f at trap_pfault+0x4f
[9705874] #5 0xffffffff810705e8 at calltrap+0x8
[9705874] #6 0xffffffff80dd5fa9 at tcp_output+0x1339
[9705874] #7 0xffffffff80dcd382 at tcp_do_segment+0x2902
[9705874] #8 0xffffffff80dc9d41 at tcp_input_with_port+0xb61
[9705874] #9 0xffffffff80dca9eb at tcp_input+0xb
[9705874] #10 0xffffffff80dbc1bf at ip_input+0x11f
[9705874] #11 0xffffffff80d491a9 at netisr_dispatch_src+0xb9
[9705874] #12 0xffffffff80d2d128 at ether_demux+0x138
[9705874] #13 0xffffffff80d2e4b5 at ether_nh_input+0x355
[9705874] #14 0xffffffff80d491a9 at netisr_dispatch_src+0xb9
[9705874] #15 0xffffffff80d2d559 at ether_input+0x69
[9705874] #16 0xffffffff80d45617 at iflib_rxeof+0xc27
[9705874] #17 0xffffffff80d3fc62 at _task_fn_rx+0x72
[9705874] Uptime: 112d8h4m34s
[9705874] Dumping 11660 out of 65425

__curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
55      __asm("movq %%gs:%P1,%0" : "=r" (td) : "n" (offsetof(struct pcpu,
(kgdb) where
#0  __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55
#1  doadump (textdump=<optimized out>) at /usr/src/sys/kern/kern_shutdown.c:399
#2  0xffffffff80c12f6c in kern_reboot (howto=260) at
#3  0xffffffff80c133de in vpanic (fmt=0xffffffff81191bdd "%s", ap=<optimized
out>) at /usr/src/sys/kern/kern_shutdown.c:920
#4  0xffffffff80c131e3 in panic (fmt=<unavailable>) at
#5  0xffffffff810991b5 in trap_fatal (frame=0xfffffe0069f535b0, eva=24) at
#6  0xffffffff8109920f in trap_pfault (frame=0xfffffe0069f535b0,
usermode=false, signo=<optimized out>, ucode=<optimized out>) at
#7  <signal handler called>
#8  m_copydata (m=0x0, m_at_entry=0xfffff801e9cc5b00, off=0, len=1, cp=<optimized
out>) at /usr/src/sys/kern/uipc_mbuf.c:657
#9  0xffffffff80dd5fa9 in tcp_output (tp=<optimized out>) at
#10 0xffffffff80dcd382 in tcp_do_segment (m=<optimized out>, th=<optimized
out>, so=<optimized out>, tp=0xfffffe01a0d0b870, drop_hdrlen=52,
tlen=<optimized out>, 
    iptos=0 '\000') at /usr/src/sys/netinet/tcp_input.c:2822
#11 0xffffffff80dc9d41 in tcp_input_with_port (mp=<optimized out>,
offp=<optimized out>, proto=<optimized out>, port=port_at_entry=0) at
#12 0xffffffff80dca9eb in tcp_input (mp=0xfffff801e9cc5b00, offp=0x0, proto=1)
at /usr/src/sys/netinet/tcp_input.c:1496
#13 0xffffffff80dbc1bf in ip_input (m=0x0) at
#14 0xffffffff80d491a9 in netisr_dispatch_src (proto=1, source=source_at_entry=0,
m=0xfffff8002c41c400) at /usr/src/sys/net/netisr.c:1143
#15 0xffffffff80d4957f in netisr_dispatch (proto=3922483968, m=0x1) at
#16 0xffffffff80d2d128 in ether_demux (ifp=ifp_at_entry=0xfffff80001ed8000, m=0x0)
at /usr/src/sys/net/if_ethersubr.c:921
#17 0xffffffff80d2e4b5 in ether_input_internal (ifp=0xfffff80001ed8000, m=0x0)
at /usr/src/sys/net/if_ethersubr.c:707
#18 ether_nh_input (m=<optimized out>) at /usr/src/sys/net/if_ethersubr.c:737
#19 0xffffffff80d491a9 in netisr_dispatch_src (proto=proto_at_entry=5,
source=source_at_entry=0, m=m_at_entry=0xfffff8002c41c400) at
#20 0xffffffff80d4957f in netisr_dispatch (proto=3922483968, proto_at_entry=5,
m=0x1, m_at_entry=0xfffff8002c41c400) at /usr/src/sys/net/netisr.c:1234
#21 0xffffffff80d2d559 in ether_input (ifp=<optimized out>,
m=0xfffff8002c41c400) at /usr/src/sys/net/if_ethersubr.c:828
#22 0xffffffff80d45617 in iflib_rxeof (rxq=<optimized out>,
rxq_at_entry=0xfffffe0114b00040, budget=<optimized out>) at
#23 0xffffffff80d3fc62 in _task_fn_rx (context=0xfffffe0114b00040) at
#24 0xffffffff80c5f80d in gtaskqueue_run_locked
(queue=queue_at_entry=0xfffff80001d68800) at
#25 0xffffffff80c5f482 in gtaskqueue_thread_loop (arg=<optimized out>,
arg_at_entry=0xfffffe0114a7b080) at /usr/src/sys/kern/subr_gtaskqueue.c:547
#26 0xffffffff80bd053e in fork_exit (callout=0xffffffff80c5f3c0
<gtaskqueue_thread_loop>, arg=0xfffffe0114a7b080, frame=0xfffffe0069f53f40)
    at /usr/src/sys/kern/kern_fork.c:1092
#27 <signal handler called>
#28 mi_startup () at /usr/src/sys/kern/init_main.c:322
Backtrace stopped: Cannot access memory at address 0x17

Let me know if I should update to latest stable/13, or if you'd want to examine
the crashdump the same way we did before - you tell me what you need, I do it
and provide it here.


You are receiving this mail because:
You are the assignee for the bug.
Received on Sat Apr 16 2022 - 16:44:03 UTC

Original text of this message