From owner-freebsd-fs@freebsd.org Sun Aug 19 09:42:28 2018 Return-Path: Delivered-To: freebsd-fs@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 657F51088128 for ; Sun, 19 Aug 2018 09:42:28 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id E1CD78F043 for ; Sun, 19 Aug 2018 09:42:27 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: by mailman.ysv.freebsd.org (Postfix) id A6A1E1088124; Sun, 19 Aug 2018 09:42:27 +0000 (UTC) Delivered-To: fs@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 84B201088123 for ; Sun, 19 Aug 2018 09:42:27 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.ysv.freebsd.org (mxrelay.ysv.freebsd.org [IPv6:2001:1900:2254:206a::19:3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mxrelay.ysv.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 10C7D8F03A for ; Sun, 19 Aug 2018 09:42:27 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mxrelay.ysv.freebsd.org (Postfix) with ESMTPS id 69A59158BF for ; Sun, 19 Aug 2018 09:42:26 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id w7J9gQnP021347 for ; Sun, 19 Aug 2018 09:42:26 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id w7J9gQGv021346 for fs@FreeBSD.org; Sun, 19 Aug 2018 09:42:26 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: fs@FreeBSD.org Subject: [Bug 227784] zfs: Fatal trap 9: general protection fault while in kernel mode on shutdown Date: Sun, 19 Aug 2018 09:42:25 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: panic X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: wulf@freebsd.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: fs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: cc Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-fs@freebsd.org X-Mailman-Version: 2.1.27 Precedence: list List-Id: Filesystems List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 19 Aug 2018 09:42:28 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D227784 Vladimir Kondratyev changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |wulf@freebsd.org --- Comment #10 from Vladimir Kondratyev --- (In reply to Andriy Gapon from comment #6) > Do you still have the crash dump? > If so, could you please provide full output of 'p *dd' ? I still observe the panic everyday, so I have a crash dump: (kgdb) frame 10 #10 0xffffffff8035f6dc in dsl_dir_evict_async (dbu=3D0xfffff80006b67400) at /usr/src/sys/cddl/contrib/opensolaris/uts/common/fs/zfs/dsl_dir.c:158 158 spa_async_close(dd->dd_pool->dp_spa, dd); (kgdb) p *dd $7 =3D {dd_dbu =3D {dbu_tqent =3D {tqent_task =3D {ta_link =3D { stqe_next =3D 0xfffff8000689b400}, ta_pending =3D 0, ta_priority = =3D 0,=20 ta_func =3D 0xffffffff802f5410 ,=20 ta_context =3D 0xfffff80006b67400},=20 tqent_func =3D 0xffffffff8035f4e0 ,=20 tqent_arg =3D 0xfffff80006b67400}, dbu_evict_func_sync =3D 0x0,=20 dbu_evict_func_async =3D 0xffffffff8035f4e0 ,=20 dbu_clear_on_evict_dbufp =3D 0xfffff80006b67458}, dd_object =3D 12,=20 dd_pool =3D 0xfffff800066f5800, dd_dbuf =3D 0x0, dd_dirty_link =3D {tn_ne= xt =3D { 0x0, 0x0, 0x0, 0x0}, tn_member =3D "\000\000\000"},=20 dd_parent =3D 0xfffff80006b66c00, dd_lock =3D {lock_object =3D { lo_name =3D 0xffffffff80999c14 "dd->dd_lock", lo_flags =3D 577830912,= =20 lo_data =3D 0, lo_witness =3D 0x0}, sx_lock =3D 1}, dd_props =3D { list_size =3D 56, list_offset =3D 0, list_head =3D { list_next =3D 0xfffff80006b674c0, list_prev =3D 0xfffff80006b674c0}},= =20 dd_snap_cmtime =3D {tv_sec =3D 1534644915, tv_nsec =3D 715064905},=20 dd_origin_txg =3D 0, dd_tempreserved =3D {0, 0, 0, 0}, dd_space_towrite = =3D {0, 0,=20 0, 0}, dd_myname =3D "$ORIGIN", '\000' } (kgdb) printf "%X\n", *(int *)dd->dd_pool DEADC0DE It looks like memory referenced by dd->dd_pool is already freed when spa_async_close() is called. --=20 You are receiving this mail because: You are the assignee for the bug.=