[Bug 197351] [ip6] panic when lagg(4) removes IPv6 addresses from member interface

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Thu Feb 5 15:53:17 UTC 2015


            Bug ID: 197351
           Summary: [ip6] panic when lagg(4) removes IPv6 addresses from
                    member interface
           Product: Base System
           Version: 11.0-CURRENT
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: kern
          Assignee: freebsd-bugs at FreeBSD.org
          Reporter: ae at FreeBSD.org

Created attachment 152588
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=152588&action=edit

When lagg(4) removes IPv6 addresses from member interface system panics if IPv6
address had `autoconf` flag.

How to reproduce:
# ifconfig em0 inet6 fc00::1/64 autconf
# ifconfig lagg0 create laggproto loadbalance laggport em0 laggport re0 up

Fatal trap 9: general protection fault while in kernel mode
cpuid = 3; apic id = 06
instruction pointer    = 0x20:0xffffffff80b651a0
stack pointer            = 0x28:0xfffffe06606c9540
frame pointer            = 0x28:0xfffffe06606c9580
code segment        = base 0x0, limit 0xfffff, type 0x1b
            = DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags    = interrupt enabled, resume, IOPL = 0
current process        = 895 (ifconfig)

(kgdb) bt
#0  doadump (textdump=Unhandled dwarf expression opcode 0x93
) at pcpu.h:219
#1  0xffffffff80358216 in db_fncall (dummy1=<value optimized out>,
dummy2=<value optimized out>, dummy3=<value optimized out>, dummy4=<value
optimized out>)
    at /home/devel/freebsd/base/head/sys/ddb/db_command.c:568
#2  0xffffffff80357efc in db_command (cmd_table=0x0) at
#3  0xffffffff80357c64 in db_command_loop () at
#4  0xffffffff8035a7a0 in db_trap (type=<value optimized out>, code=Unhandled
dwarf expression opcode 0x93
) at /home/devel/freebsd/base/head/sys/ddb/db_main.c:251
#5  0xffffffff80993efe in kdb_trap (type=Unhandled dwarf expression opcode 0x93
) at /home/devel/freebsd/base/head/sys/kern/subr_kdb.c:654
#6  0xffffffff80db4ef9 in trap_fatal (frame=0xfffffe06606c9490, eva=<value
optimized out>) at /home/devel/freebsd/base/head/sys/amd64/amd64/trap.c:856
#7  0xffffffff80db4bae in trap (frame=<value optimized out>) at
#8  0xffffffff80d93eb2 in calltrap () at
#9  0xffffffff80b651a0 in find_pfxlist_reachable_router (pr=<value optimized
out>) at /home/devel/freebsd/base/head/sys/netinet6/nd6_rtr.c:1301
#10 0xffffffff80b639b6 in pfxlist_onlink_check () at
#11 0xffffffff80b64ceb in prelist_remove (pr=<value optimized out>) at
#12 0xffffffff80b5bfe5 in nd6_purge (ifp=0xfffff800069b7000) at
#13 0xffffffff80b44b93 in in6_ifdetach (ifp=0xfffff800069b7000) at
#14 0xffffffff8221cd1f in lagg_ioctl (ifp=<value optimized out>, cmd=<value
optimized out>, data=<value optimized out>)
#15 0xffffffff80a2c957 in ifioctl (so=0xfffff80006d2cf00, cmd=2152229261,
data=0xfffffe06606c98f0 "lagg0", td=0xfffff80025c104a0)
    at /home/devel/freebsd/base/head/sys/net/if.c:2739
#16 0xffffffff809b5d00 in kern_ioctl (td=0xfffff80025c104a0, fd=<value
optimized out>, com=120, data=<value optimized out>) at file.h:318
#17 0xffffffff809b5993 in sys_ioctl (td=0xfffff80025c104a0,
uap=0xfffffe06606c9a40) at
#18 0xffffffff80db575f in amd64_syscall (td=0xfffff80025c104a0, traced=0) at
#19 0xffffffff80d9419b in Xfast_syscall () at
#20 0x00000008011e1c6a in ?? ()

You are receiving this mail because:
You are the assignee for the bug.

More information about the freebsd-bugs mailing list