Re: Kernel panic in ieee80211_chan2mode <- SIOCS80211 ioctl

From: Marcin Cieslak <saper_at_saper.info>
Date: Wed, 09 Sep 2026 09:04:21 UTC
On Tue, 8 Sep 2026, Bjoern A. Zeeb wrote:

> On Tue, 8 Sep 2026, Marcin Cieslak wrote:
>
>> This is amd64 current as of 067ae9850f05a27239c28ae5819e4016e997cff2
>>=20
>> brcmfmac0@pci0:2:0:0:=09class=3D0x028000 rev=3D0x05 hdr=3D0x00 vendor=3D=
0x14e4=20
>> device=3D0x43a3 subvendor=3D0x106b subdevice=3D0x0159
>>=20
>>=20
>> (running the vibe coded driver as of=20
>> 9adbe774d3be91827d628fbd811daf63512acb6d)
>
> Generally I'd not support this but ask to report it to the vibe coding=20
> repo...
>
> Here's some ideas though.
>
>> #20 0xffffffff80e525f2 in ieee80211_setup_rates (ni=3D0x33443836,
>>    ni@entry=3D0xfffffe00fa139000, rates=3D<optimized out>,
>
> Can you print ni details here on frame 20 and frame 19?
>

#20 0xffffffff80e525f2 in ieee80211_setup_rates (ni=3D0x33443836, ni@entry=
=3D0xfffffe00fa139000, rates=3D<optimized out>, xrates=3Dxrates@entry=3D0xf=
ffffe00f8af19e7 "3", flags=3D-2048, flags@entry=3D1) at /usr/src/sys/net802=
11/ieee80211_input.c:450
450=09=09return ieee80211_fix_rate(ni, rs, flags);
Cannot access memory at address 0x33443836

#19 0xffffffff80e7014f in ieee80211_fix_rate (ni=3D0xfffffe00fa139000, nrs=
=3D0xfffffe00fa1392a5, flags=3D1) at /usr/src/sys/net80211/ieee80211_proto.=
c:650
650=09=09ucastrate =3D vap->iv_txparms[ieee80211_chan2mode(ni->ni_chan)].uc=
astrate;
$3 =3D {ni_vap =3D 0xfffff80025bdd000, ni_ic =3D 0xfffffe00f9409448, ni_tab=
le =3D 0xfffffe00f940fa58, ni_list =3D {tqe_next =3D 0x0, tqe_prev =3D 0xff=
fffe00f9cbc018}, ni_hash =3D {le_next =3D 0x0, le_prev =3D 0xfffffe00f940fb=
38}, ni_refcnt =3D 1, ni_flags =3D 131072, ni_associd =3D 0, ni_vlan =3D 0,=
 ni_txpower =3D 100, ni_authmode =3D 1 '\001', ni_ath_flags =3D 0 '\000', n=
i_ath_defkeyix =3D 32767, ni_txparms =3D 0xfffff80025bdd72c, ni_jointime =
=3D 0, ni_challenge =3D 0x0, ni_ies =3D {wpa_ie =3D 0x0, rsn_ie =3D 0x0, wm=
e_ie =3D 0xfffff800016d49a6 "\335\030", ath_ie =3D 0x0, htcap_ie =3D 0x0, h=
tinfo_ie =3D 0x0, tdma_ie =3D 0x0, meshid_ie =3D 0x0, vhtcap_ie =3D 0x0, vh=
topmode_ie =3D 0x0, vhtpwrenv_ie =3D 0x0, apchanrep_ie =3D 0x0, bssload_ie =
=3D 0x0, spare =3D {0x0, 0x0, 0x0, 0x0}, data =3D 0xfffff800016d4980 "", le=
n =3D 126}, ni_txseqs =3D {0 <repeats 17 times>}, ni_rxseqs =3D {0 <repeats=
 17 times>}, ni_rxfragstamp =3D 0, ni_rxfrag =3D {0x0, 0x0, 0x0}, ni_ucastk=
ey =3D {wk_keylen =3D 0 '\000', wk_pad =3D 0 '\000', wk_pad1 =3D "\000", wk=
_flags =3D 3, wk_keyix =3D 65535, wk_rxkeyix =3D 65535, wk_key =3D '\000' <=
repeats 31 times>, wk_keyrsc =3D {0 <repeats 17 times>}, wk_keytsc =3D 0, w=
k_cipher =3D 0xffffffff817dada0 <ieee80211_cipher_none>, wk_private =3D 0xf=
ffff80025bdd000, wk_macaddr =3D "\000\000\000\000\000"}, ni_avgrssi =3D 640=
0, ni_noise =3D -95 '\241', ni_mimo_rssi_ctl =3D {0, 0, 0, 0}, ni_mimo_rssi=
_ext =3D {0, 0, 0, 0}, ni_mimo_noise_ctl =3D "\000\000\000", ni_mimo_noise_=
ext =3D "\000\000\000", ni_mimo_chains =3D 0 '\000', ni_macaddr =3D "\324\0=
01=CD", <incomplete sequence \323>, ni_bssid =3D "\324\001=CD", <incomplete=
 sequence \323>, ni_tstamp =3D {data =3D "\000\000\000\000\000\000\000", ts=
f =3D 0}, ni_intval =3D 100, ni_capinfo =3D 1057, ni_esslen =3D 10 '\n', ni=
_essid =3D "lower-deck", '\000' <repeats 21 times>, ni_rates =3D {rs_nrates=
 =3D 15 '\017', rs_rates =3D "\000\020\000\000\025f1\006\000\000D401C"}, ni=
_chan =3D 0x33443836, ni_fhdwell =3D 0, ni_fhindex =3D 0 '\000', ni_erp =3D=
 13892, ni_timoff =3D 17464, ni_dtim_period =3D 51 '3', ni_dtim_count =3D 0=
 '\000', ni_meshidlen =3D 0 '\000', ni_meshid =3D '\000' <repeats 16 times>=
, "d\000!\004\000\000\000\000@\232@\371\000\376\377\377", ni_mlstate =3D IE=
EE80211_NODE_MESH_IDLE, ni_mllid =3D 0, ni_mlpid =3D 12800, ni_mltimer =3D =
{c_links =3D {le =3D {le_next =3D 0x0, le_prev =3D 0x0}, sle =3D {sle_next =
=3D 0x0}, tqe =3D {tqe_next =3D 0x0, tqe_prev =3D 0x0}}, c_time =3D 0, c_pr=
ecision =3D 0, c_arg =3D 0x0, c_func =3D 0x0, c_lock =3D 0x0, c_flags =3D 0=
, c_iflags =3D 0, c_cpu =3D 0}, ni_mlrcnt =3D 0 '\000', ni_mltval =3D 0 '\0=
00', ni_mlhtimer =3D {c_links =3D {le =3D {le_next =3D 0x0, le_prev =3D 0x0=
}, sle =3D {sle_next =3D 0x0}, tqe =3D {tqe_next =3D 0x0, tqe_prev =3D 0x0}=
}, c_time =3D 0, c_precision =3D 0, c_arg =3D 0x0, c_func =3D 0x0, c_lock =
=3D 0x0, c_flags =3D 0, c_iflags =3D 0, c_cpu =3D 0}, ni_mlhcnt =3D 0 '\000=
', ni_htcap =3D 0, ni_htparam =3D 0 '\000', ni_htctlchan =3D 0 '\000', ni_h=
t2ndchan =3D 0 '\000', ni_htopmode =3D 0 '\000', ni_htstbc =3D 0 '\000', ni=
_chw =3D NET80211_STA_RX_BW_20, ni_htrates =3D {rs_nrates =3D 0 '\000', rs_=
rates =3D '\000' <repeats 25 times>, "Hm\001\000\370\377\377~\000\000\000\0=
00\000\000\000\017\b", '\000' <repeats 34 times>}, ni_tx_ampdu =3D {{txa_ni=
 =3D 0x0, txa_flags =3D 0, txa_tid =3D 0 '\000', txa_token =3D 0 '\000', tx=
a_lastsample =3D 0, txa_pkts =3D 0, txa_avgpps =3D 0, txa_qbytes =3D 0, txa=
_qframes =3D 0, txa_start =3D 0, txa_seqpending =3D 0, txa_wnd =3D 0, txa_a=
ttempts =3D 0 '\000', txa_nextrequest =3D 0, txa_timer =3D {c_links =3D {le=
 =3D {le_next =3D 0x0, le_prev =3D 0x0}, sle =3D {sle_next =3D 0x0}, tqe =
=3D {tqe_next =3D 0x0, tqe_prev =3D 0x0}}, c_time =3D 0, c_precision =3D 0,=
 c_arg =3D 0x0, c_func =3D 0x0, c_lock =3D 0x0, c_flags =3D 0, c_iflags =3D=
 0, c_cpu =3D 0}, txa_private =3D 0x0, txa_pad =3D {0, 0, 0, 0}} <repeats 1=
6 times>}, ni_rx_ampdu =3D {{rxa_flags =3D 0, rxa_qbytes =3D 0, rxa_qframes=
 =3D 0, rxa_seqstart =3D 0, rxa_start =3D 0, rxa_wnd =3D 0, rxa_age =3D 0, =
rxa_nframes =3D 0, rxa_mq =3D {{mq_head =3D {stqh_first =3D 0x0, stqh_last =
=3D 0x0}, mq_len =3D 0, mq_maxlen =3D 0} <repeats 64 times>}, rxa_private =
=3D 0x0, rxa_pad =3D {0, 0, 0}} <repeats 16 times>}, ni_vhtcap =3D 0, ni_vh=
t_basicmcs =3D 0, ni_vht_tx_map =3D 0, ni_vht_mcsinfo =3D {rx_mcs_map =3D 0=
, rx_highest =3D 0, tx_mcs_map =3D 0, tx_highest =3D 0}, ni_vht_chan1 =3D 0=
 '\000', ni_vht_chan2 =3D 0 '\000', ni_vht_chanwidth =3D 0 '\000', ni_vht_p=
ad1 =3D 0 '\000', ni_vht_spare =3D {0, 0, 0, 0, 0, 0, 0, 0}, ni_tx_superg =
=3D {0x0 <repeats 16 times>}, ni_inact =3D 2, ni_inact_reload =3D 2, ni_txr=
ate =3D {type =3D IEEE80211_NODE_TXRATE_UNDEFINED, nss =3D 0 '\000', mcs =
=3D 0 '\000', dot11rate =3D 0 '\000'}, ni_psq =3D {psq_lock =3D {lock_objec=
t =3D {lo_name =3D 0xffffffff813463a8 "unknown", lo_flags =3D 16973824, lo_=
data =3D 0, lo_witness =3D 0x0}, mtx_lock =3D 0}, psq_len =3D 0, psq_maxlen=
 =3D 50, psq_drops =3D 0, psq_head =3D {{head =3D 0x0, tail =3D 0x0, len =
=3D 0}, {head =3D 0x0, tail =3D 0x0, len =3D 0}}}, ni_stats =3D {ns_rx_data=
 =3D 0, ns_rx_mgmt =3D 0, ns_rx_ctrl =3D 0, ns_rx_ucast =3D 0, ns_rx_mcast =
=3D 0, ns_rx_bytes =3D 0, ns_rx_beacons =3D 0, ns_rx_proberesp =3D 0, ns_rx=
_dup =3D 0, ns_rx_noprivacy =3D 0, ns_rx_wepfail =3D 0, ns_rx_demicfail =3D=
 0, ns_rx_decap =3D 0, ns_rx_defrag =3D 0, ns_rx_disassoc =3D 0, ns_rx_deau=
th =3D 0, ns_rx_action =3D 0, ns_rx_decryptcrc =3D 0, ns_rx_unauth =3D 0, n=
s_rx_unencrypted =3D 0, ns_rx_drop =3D 0, ns_tx_data =3D 0, ns_tx_mgmt =3D =
0, ns_tx_ctrl =3D 0, ns_tx_ucast =3D 0, ns_tx_mcast =3D 0, ns_tx_bytes =3D =
0, ns_tx_probereq =3D 0, ns_tx_novlantag =3D 0, ns_tx_vlanmismatch =3D 0, n=
s_ps_discard =3D 0, ns_tx_assoc =3D 0, ns_tx_assoc_fail =3D 0, ns_tx_auth =
=3D 0, ns_tx_auth_fail =3D 0, ns_tx_deauth =3D 0, ns_tx_deauth_code =3D 0, =
ns_tx_disassoc =3D 0, ns_tx_disassoc_code =3D 0, ns_rx_amsdu_more =3D 0, ns=
_rx_amsdu_more_end =3D 0, ns_spare =3D {0, 0, 0, 0, 0, 0}}, ni_wdsvap =3D 0=
x0, ni_rctls =3D 0x0, ni_quiet_ie_set =3D 0, ni_quiet_ie =3D {quiet_ie =3D =
0 '\000', len =3D 0 '\000', tbttcount =3D 0 '\000', period =3D 0 '\000', du=
ration =3D 0, offset =3D 0}, ni_uapsd =3D 0 '\000', ni_drv_data =3D 0x0, ni=
_spare =3D {0, 0, 0}}

>> #22 0xffffffff80e576dc in setmlme_assoc_sta (vap=3D0xfffff80025bdd000,
>>     mac=3D0xfffffe00f8af1962 "\324\001_h\323lower-deck",
>>     ssid_len=3D<optimized out>, ssid=3D<optimized out>)
>>     at /usr/src/sys/net80211/ieee80211_ioctl.c:1693
>> ...
>>             se_intval =3D 100, se_capinfo =3D 1057, se_chan =3D=20
>> 0xfffffe00f9409a40,
>> ...
>
> Can you also print se_chan details here?
>
>
> My guess is that it is memory corruption with an overflowing rate set
> not caught properly but it also looks like the stack is corrupt.

What I noticed that in the frame #20

ni@entry is reported to be 0xfffffe00fa139000 but "ni" is already
corrupted.

It could mean that ieee80211_setup_rates overwrote the stack.

> If you can reproduce this you could try (on a debug kernel):
> wlandebug -i wlan0 +11n +xrates
> and see what may get logged right before panic.
> Beware there is no kernel message buffer in the dump so the information

There is one, I have reported this to this very list, seems to be sme libkv=
m trouble to find symbols.

Full msgbuf as ASCII attached

$1 =3D {msg_ptr =3D 0xfffff8046efe8000 "C InternalLength 00     130\n   rsc=
alc-0832 RsGetListLength       : Type 86, AmlLength 0C InternalLength 00   =
  148\n   rscalc-0832 RsGetListLength       : Type 86, AmlLength 0C Interna=
lLength 00     16"..., msg_magic =3D 405602, msg_size =3D 98232, msg_wseq =
=3D 159349, msg_rseq =3D 157500, msg_cksum =3D 7823747, msg_seqmod =3D 1571=
712, msg_lastpri =3D -1, msg_flags =3D 2, msg_lock =3D {lock_object =3D {lo=
_name =3D 0xffffffff813d0a1e "msgbuf", lo_flags =3D 196608, lo_data =3D 0, =
lo_witness =3D 0x0}, mtx_lock =3D 0}}

First entry in the buffer:

<6>wlan0: Ethernet address: 78:4f:43:60:6c:4a
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2457/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 5200/0x00010140
wlan0: sta_add: demoting HT->legacy 5200/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5500/0x00010140
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 5220/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5500/0x00010140
wlan0: sta_add: demoting HT->legacy 2412/0x00010480
wlan0: sta_add: demoting HT->legacy 2412/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2457/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 5220/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5300/0x00010140
wlan0: sta_add: demoting HT->legacy 5300/0x00010140
wlan0: sta_add: demoting HT->legacy 5500/0x00010140
wlan0: sta_add: demoting HT->legacy 2412/0x00010480
wlan0: sta_add: demoting HT->legacy 2437/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 2457/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 5200/0x00010140
wlan0: sta_add: demoting HT->legacy 5220/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5500/0x00010140
wlan0: sta_add: demoting HT->legacy 5540/0x00010140
wlan0: sta_add: demoting HT->legacy 2412/0x00010480
wlan0: sta_add: demoting HT->legacy 2437/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 2457/0x00010480
wlan0: sta_add: demoting HT->legacy 2462/0x00010480
wlan0: sta_add: demoting HT->legacy 5200/0x00010140
wlan0: sta_add: demoting HT->legacy 5220/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5500/0x00010140

Second entry in the buffer:

<6>wlan0: Ethernet address: 78:4f:43:60:6c:4a
wlan0: sta_add: demoting HT->legacy 2412/0x00010480
wlan0: sta_add: demoting HT->legacy 2447/0x00010480
wlan0: sta_add: demoting HT->legacy 5200/0x00010140
wlan0: sta_add: demoting HT->legacy 5220/0x00010140
wlan0: sta_add: demoting HT->legacy 5260/0x00010140
wlan0: sta_add: demoting HT->legacy 5500/0x00010140
wlan0: sta_add: demoting HT->legacy 5540/0x00010140