Mbuf double-free guilty party detection patch

Mike Silbersack silby at silby.com
Sun Jun 26 06:21:06 GMT 2005


On Sun, 26 Jun 2005, Andrey Chernov wrote:

> On Sat, Jun 25, 2005 at 05:13:18PM -0500, Mike Silbersack wrote:
>> Here's a fixed version of the patch that should return the correct
>
> I got lots of:
>
> Jun 26 05:22:44 pobrecita kernel: This memory last freed by: c04d7a88
> Jun 26 05:22:44 pobrecita kernel: Memory modified after free 0xc2458900(256) val=0 @ 0xc2458930
>
> with "@ 0xc2458930" part changed and "last freed" addresses are:
> c04d7a88, c04dbe9d, c04dc490, c04dffff, c04e02bc
>
> kgdb /sys/i386/compile/POBRECITA/kernel.debug /dev/mem
> (kgdb) x 0xc04d7a88
> 0xc04d7a88 <m_freem+24>:        0xf475c085
> (kgdb) x 0xc04dffff
> 0xc04dffff <sbcompress+431>:    0x66ebc389
> (kgdb) x 0xc04dc490
> 0xc04dc490 <soreceive+2640>:    0x8908558b
> (kgdb) x 0xc04e02bc
> 0xc04e02bc <sbdrop_locked+236>: 0xdb85c189
> (kgdb) x 0xc04dbe9d
> 0xc04dbe9d <soreceive+1117>:    0x8908558b
>
> Is it helps?

Yes and no.  Your results tell me that it's probably not a simple use 
after free, but rather something smashing all over memory for some reason. 
I'm going to have to port Bosko's memguard to uma to really figure this 
out.

*sigh*

Mike "Silby" Silbersack


More information about the freebsd-current mailing list