From nobody Sat Jun 11 21:17:37 2022 X-Original-To: net@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 57BD0847803 for ; Sat, 11 Jun 2022 21:17:39 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4LL9dv1GX1z3DM4 for ; Sat, 11 Jun 2022 21:17:39 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 0C3391466F for ; Sat, 11 Jun 2022 21:17:39 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 25BLHc35046921 for ; Sat, 11 Jun 2022 21:17:38 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 25BLHcGp046920 for net@FreeBSD.org; Sat, 11 Jun 2022 21:17:38 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: net@FreeBSD.org Subject: [Bug 264257] [tcp] Panic: Fatal trap 12: page fault while in kernel mode (if_io_tqg_4) - m_copydata ... at /usr/src/sys/kern/uipc_mbuf.c:659 Date: Sat, 11 Jun 2022 21:17:37 +0000 X-Bugzilla-Reason: AssignedTo CC X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 13.1-RELEASE X-Bugzilla-Keywords: crash, needs-qa X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: chris@cretaforce.gr X-Bugzilla-Status: Open X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: net@FreeBSD.org X-Bugzilla-Flags: maintainer-feedback? maintainer-feedback? maintainer-feedback- maintainer-feedback? mfc-stable13? X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Networking and TCP/IP with FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-net List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-net@freebsd.org MIME-Version: 1.0 ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1654982259; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UyZRNkjtvcZzqDJr6Z83Wh+xmnFUG673lBTuHUGjBZQ=; b=aL/90u9ECCJXA6Z8PE2EvmvM0cNlgFbhCTC8iVP6REq12cKqLcHdfNECMJ+fwK/a3yxbVJ wBWBYahIMPNLabt9bRV7DRqfgtf/A3Q3JrftxCOx6YycN0dV98bMIGpBHwZAfaiVhGUPpy 2tJoNGZG6PqQ6RMlYfebqbkPOonk57Naw/VjS6oiVhmR260WjcY1tQpmdZpIKPhQVxlAhd I2yJi/zCd37rwuETrYY91EWY37U7hrq9yqEj3f5OriYvFfAhMVlWe47NCvwqctIWq1msAD w1cxJfOP5FVmb8vyJiDyDza661cWdcQK2j7gOVEbQuCbjJw1O3yX25hlB3OWJw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1654982259; a=rsa-sha256; cv=none; b=gW1IvwsWjBKJ6CZCh0VG2W8N6nzQnom6X0/CdX0u9uOevP5+NPc7xRBBRwcqNKDSmyrO7F 19aAy5RzNywFv30Pj+L6pPfKFiFRq/4+rtGtjsGRTpyETKRz9QDrcxvGhMFVW0xehZtIw7 FDzLSVZ4XTBbhU8dyDrKUFI16N9lrISK8gRODuAF/YoxuUvYV958NywH3f5Di9zZA4lBMN cYmElQeRB+lJnX2Q0zqsbGwAPTgGjpFDtFFza2Hht8nc9CkHxmDgAP/pkHvJ6dTmlncp2U sNe8MDV4op8hpKtaS+qesWeBogbCdNQT/SMZxuoSEYoE6iVVmp0fBRSw/oetSA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D264257 --- Comment #36 from Christos Chatzaras --- Today I had a kernel panic in a server. Is it possible the same bug? Fatal trap 12: page fault while in kernel mode cpuid =3D 7; apic id =3D 07 fault virtual address =3D 0x18 fault code =3D supervisor read data, page not present instruction pointer =3D 0x20:0xffffffff80cae31d stack pointer =3D 0x28:0xfffffe00e00445f0 frame pointer =3D 0x28:0xfffffe00e0044660 code segment =3D base 0x0, limit 0xfffff, type 0x1b =3D DPL 0, pres 1, long 1, def32 0, gran 1 processor eflags =3D interrupt enabled, resume, IOPL =3D 0 current process =3D 0 (if_io_tqg_7) trap number =3D 12 panic: page fault cpuid =3D 7 time =3D 1654981222 KDB: stack backtrace: #0 0xffffffff80c69465 at kdb_backtrace+0x65 #1 0xffffffff80c1bb1f at vpanic+0x17f #2 0xffffffff80c1b993 at panic+0x43 #3 0xffffffff810afdf5 at trap_fatal+0x385 #4 0xffffffff810afe4f at trap_pfault+0x4f #5 0xffffffff81087528 at calltrap+0x8 #6 0xffffffff80de07c9 at tcp_output+0x1339 #7 0xffffffff80dd7eed at tcp_do_segment+0x2cfd #8 0xffffffff80dd44b1 at tcp_input_with_port+0xb61 #9 0xffffffff80dd515b at tcp_input+0xb #10 0xffffffff80dc691f at ip_input+0x11f #11 0xffffffff80d53089 at netisr_dispatch_src+0xb9 #12 0xffffffff80d36ea8 at ether_demux+0x138 #13 0xffffffff80d38235 at ether_nh_input+0x355 #14 0xffffffff80d53089 at netisr_dispatch_src+0xb9 #15 0xffffffff80d372d9 at ether_input+0x69 #16 0xffffffff80ddd9f4 at tcp_lro_flush+0x2f4 #17 0xffffffff80dddd3b at tcp_lro_flush_all+0x1bb Uptime: 20d1h1m33s Dumping 2502 out of 32501 MB:..1%..11%..21%..31%..41%..51%..61%..71%..81%..= 91% __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55 warning: Source file is more recent than executable. 55 __asm("movq %%gs:%P1,%0" : "=3Dr" (td) : "n" (offsetof(stru= ct pcpu, (kgdb) #0 __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55 #1 doadump (textdump=3D) at /usr/src/sys/kern/kern_shutdown.c:399 #2 0xffffffff80c1b71c in kern_reboot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c:487 #3 0xffffffff80c1bb8e in vpanic (fmt=3D0xffffffff811b4fb9 "%s",=20 ap=3D) at /usr/src/sys/kern/kern_shutdown.c:920 #4 0xffffffff80c1b993 in panic (fmt=3D) at /usr/src/sys/kern/kern_shutdown.c:844 #5 0xffffffff810afdf5 in trap_fatal (frame=3D0xfffffe00e0044530, eva=3D24) at /usr/src/sys/amd64/amd64/trap.c:944 #6 0xffffffff810afe4f in trap_pfault (frame=3D0xfffffe00e0044530,=20 usermode=3Dfalse, signo=3D, ucode=3D) at /usr/src/sys/amd64/amd64/trap.c:763 #7 #8 m_copydata (m=3D0x0, m@entry=3D0xfffff80405398400, off=3D0, len=3D1,=20 cp=3D) at /usr/src/sys/kern/uipc_mbuf.c:659 #9 0xffffffff80de07c9 in tcp_output (tp=3D) at /usr/src/sys/netinet/tcp_output.c:1081 #10 0xffffffff80dd7eed in tcp_do_segment (m=3D,=20 th=3D, so=3D, tp=3D0xfffffe013f603000,=20 drop_hdrlen=3D40, tlen=3D, iptos=3D0 '\000') at /usr/src/sys/netinet/tcp_input.c:2637 #11 0xffffffff80dd44b1 in tcp_input_with_port (mp=3D,=20 offp=3D, proto=3D, port=3Dport@entry=3D0) at /usr/src/sys/netinet/tcp_input.c:1400 #12 0xffffffff80dd515b in tcp_input (mp=3D0xfffff80405398400, offp=3D0x0, p= roto=3D1) at /usr/src/sys/netinet/tcp_input.c:1496 #13 0xffffffff80dc691f in ip_input (m=3D0x0) at /usr/src/sys/netinet/ip_input.c:839 #14 0xffffffff80d53089 in netisr_dispatch_src (proto=3D1,=20 source=3Dsource@entry=3D0, m=3D0xfffff8002f330900) at /usr/src/sys/net/netisr.c:1143 #15 0xffffffff80d5345f in netisr_dispatch (proto=3D87655424, m=3D0x1) at /usr/src/sys/net/netisr.c:1234 #16 0xffffffff80d36ea8 in ether_demux (ifp=3Difp@entry=3D0xfffff80004454000= ,=20 m=3D0x0) at /usr/src/sys/net/if_ethersubr.c:921 #17 0xffffffff80d38235 in ether_input_internal (ifp=3D0xfffff80004454000, m= =3D0x0) at /usr/src/sys/net/if_ethersubr.c:707 #18 ether_nh_input (m=3D) at /usr/src/sys/net/if_ethersubr.c= :737 #19 0xffffffff80d53089 in netisr_dispatch_src (proto=3Dproto@entry=3D5,=20 source=3Dsource@entry=3D0, m=3Dm@entry=3D0xfffff8002f330900) at /usr/src/sys/net/netisr.c:1143 #20 0xffffffff80d5345f in netisr_dispatch (proto=3D87655424, proto@entry=3D= 5,=20 m=3D0x1, m@entry=3D0xfffff8002f330900) at /usr/src/sys/net/netisr.c:1234 #21 0xffffffff80d372d9 in ether_input (ifp=3D,=20 m=3D0xfffff8002f330900) at /usr/src/sys/net/if_ethersubr.c:828 #22 0xffffffff80ddd9f4 in tcp_lro_flush (lc=3Dlc@entry=3D0xfffff80003cf5830= ,=20 le=3D0xfffffe0103f3f690) at /usr/src/sys/netinet/tcp_lro.c:1375 #23 0xffffffff80dddd3b in tcp_lro_rx_done (lc=3D0xfffff80003cf5830) at /usr/src/sys/netinet/tcp_lro.c:566 #24 tcp_lro_flush_all (lc=3Dlc@entry=3D0xfffff80003cf5830) at /usr/src/sys/netinet/tcp_lro.c:1532 #25 0xffffffff80d4f503 in iflib_rxeof (rxq=3D,=20 rxq@entry=3D0xfffff80003cf5800, budget=3D) at /usr/src/sys/net/iflib.c:3058 #26 0xffffffff80d49b22 in _task_fn_rx (context=3D0xfffff80003cf5800) at /usr/src/sys/net/iflib.c:3990 #27 0xffffffff80c67e9d in gtaskqueue_run_locked ( queue=3Dqueue@entry=3D0xfffff80003ac2000) at /usr/src/sys/kern/subr_gtaskqueue.c:371 #28 0xffffffff80c67b12 in gtaskqueue_thread_loop (arg=3D,=20 arg@entry=3D0xfffffe00387fb0b0) at /usr/src/sys/kern/subr_gtaskqueue.c:= 547 #29 0xffffffff80bd8a5e in fork_exit ( callout=3D0xffffffff80c67a50 ,=20 arg=3D0xfffffe00387fb0b0, frame=3D0xfffffe00e0044f40) at /usr/src/sys/kern/kern_fork.c:1093 #30 #31 mi_startup () at /usr/src/sys/kern/init_main.c:322 Backtrace stopped: Cannot access memory at address 0x1d (kgdb) --=20 You are receiving this mail because: You are the assignee for the bug. You are on the CC list for the bug.=