From nobody Wed May 27 01:34:39 2026 X-Original-To: current@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gQBxk2YBQz6f565 for ; Wed, 27 May 2026 01:34:50 +0000 (UTC) (envelope-from bzeeb-lists@lists.zabbadoz.net) Received: from mx-01.divo.sbone.de (mx-01.divo.sbone.de [IPv6:2003:a:140a:2200:6:594:fffe:19]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature ECDSA (prime256v1) client-digest SHA256) (Client CN "mx-01.divo.sbone.de", Issuer "E7" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gQBxj0604z3Wrv for ; Wed, 27 May 2026 01:34:48 +0000 (UTC) (envelope-from bzeeb-lists@lists.zabbadoz.net) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=zabbadoz.net header.s=20240622 header.b=fgwXdSVF; dmarc=pass (policy=none) header.from=zabbadoz.net; spf=pass (mx1.freebsd.org: domain of bzeeb-lists@lists.zabbadoz.net designates 2003:a:140a:2200:6:594:fffe:19 as permitted sender) smtp.mailfrom=bzeeb-lists@lists.zabbadoz.net Received: from mail.sbone.de (mail.sbone.de [IPv6:fde9:577b:c1a9:4902:0:7404:2:1025]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx-01.divo.sbone.de (Postfix) with ESMTPS id 17CA7A64805 for ; Wed, 27 May 2026 01:34:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=zabbadoz.net; s=20240622; t=1779845656; bh=sDvAJGpMk4XcVglW2AKd61BsfA5o5qR7TAaoO1CuVlg=; h=Date:From:To:Subject:In-Reply-To:References; b=fgwXdSVFUmup5Xgb5D/qZ//RCesRNvD6szss9AEU1nDKCj1VERTdOvh7SzdbkZQDd VPBmv2mIzAeYZ+7pIP4xg/ireO2OJbml3oAo/0v2YNwRUjZ32H6o/O/yDtygFVtov9 Cl6wg2/Mu51Y0spXrhag3jBEn5QgieSI+TqLIwIIcYcLAFCqEotkkcAzt/+UWiLLpa NTUWFNE5Y4sC4g+LZSnOIm3bSjZ0Su34KPTaHUudUmn1NjCtKgnvlKuZqhotYM8SMi R5O54CBMcGFerXWsjvDFULH6DoCWoJXYjRi9lJjg+40GyRts38FnJNqvCjYMB4ok8L Val6G/UqfOmYoNsJmQ7MiTnFNwtvVlCQ9ElvTeXZfAB4dQ2ghdyD5UEGFdmRnl+o2U 81GOzIy4+3vOEGy6U52uevntqV+2USmMP9ToAxqaZy1/6KtGqEtVTncvNN8s/sDCRp ZfCtU2VVr996pNllizD9Wlt/5GFbnTLyq8exa9maazRVVITyxNCavAe8e+FsO3JEQV Cv+shXZyHs9/Unqj8Z+C2tR/GdzwG3cvxXAMcqL9PhhooNVbfqfYM4pF2K4NaROsPX 3yJcgZRrOmtpQMkb2pCVzLXgz0RIsniB8/1S4fGatylCxwrOGLF9KLykBwVxL65+3U QGjiM7WOOMXyaA8rZ4t3aoA8= Received: from content-filter.t4-02.sbone.de (content-filter.t4-02.sbone.de [IPv6:fde9:577b:c1a9:4902:0:7404:2:2742]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail.sbone.de (Postfix) with ESMTPS id E0D2E2D029E9 for ; Wed, 27 May 2026 01:34:40 +0000 (UTC) X-Virus-Scanned: amavisd-new at sbone.de Received: from mail.sbone.de ([IPv6:fde9:577b:c1a9:4902:0:7404:2:1025]) by content-filter.t4-02.sbone.de (content-filter.t4-02.sbone.de [IPv6:fde9:577b:c1a9:4902:0:7404:2:2742]) (amavisd-new, port 10024) with ESMTP id oq4Tilx3mBIw for ; Wed, 27 May 2026 01:34:39 +0000 (UTC) Received: from nv.t4-02.sbone.de (nv.t4-02.sbone.de [IPv6:fde9:577b:c1a9:4902:0:7404:2:22]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail.sbone.de (Postfix) with ESMTPSA id 9A8862D029D8 for ; Wed, 27 May 2026 01:34:39 +0000 (UTC) Date: Wed, 27 May 2026 01:34:39 +0000 (UTC) From: "Bjoern A. Zeeb" To: current@freebsd.org Subject: Re: Fatal trap 12: .. cpu_idle_acpi .. callout_process In-Reply-To: Message-ID: References: X-OpenPGP-Key-Id: 0x14003F198FEFA3E77207EE8D2B58B8F83CCF1842 List-Id: Discussions about the use of FreeBSD-current List-Archive: https://lists.freebsd.org/archives/freebsd-current List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-current@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII; format=flowed X-Spamd-Result: default: False [-4.00 / 15.00]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-1.00)[-0.999]; DMARC_POLICY_ALLOW(-0.50)[zabbadoz.net,none]; R_DKIM_ALLOW(-0.20)[zabbadoz.net:s=20240622]; R_SPF_ALLOW(-0.20)[+ip6:2003:a:140a:2200:6:594:fffe:19]; MIME_GOOD(-0.10)[text/plain]; MISSING_XM_UA(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:3320, ipnet:2003::/19, country:DE]; RCVD_COUNT_THREE(0.00)[4]; ARC_NA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; MLMMJ_DEST(0.00)[current@freebsd.org]; TO_DN_NONE(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[current@freebsd.org]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_TLS_LAST(0.00)[]; DKIM_TRACE(0.00)[zabbadoz.net:+] X-Spamd-Bar: --- X-Rspamd-Queue-Id: 4gQBxj0604z3Wrv On Tue, 26 May 2026, Bjoern A. Zeeb wrote: > Hi, > > I got some LinuxKPI problems sorted and can finally shutdown a system w/o > a driver panicing but now I see on a recent main (pxe booted in bhyve); > this seems reproducible and typing reset I get the next panic and the next > and the next and ... until bhyve stops after scrolling for a few seconds. > > Anyone seen this or any ideas? I'll try to build a plain main kernel > otherwise > to check that it's not anything else... I have already found the next LinuxKPI bug. If I just boot a kernel and do a shutdown -r I do not run into it so unless it rings a bell for someone else as well, please ignore this for now. > Syncing disks, vnodes remaining... 0 done > All buffers synced. > Uptime: 46s > kernel trap 12 with interrupts disabled > > > Fatal trap 12: page fault while in kernel mode > cpuid = 0; apic id = 00 > fault virtual address = 0xfffffe00a58a0630 > fault code = supervisor read data, page not present > instruction pointer = 0x20:0xffffffff80c0ebe8 > stack pointer = 0x28:0xfffffe008bc49bb0 > frame pointer = 0x28:0xfffffe008bc49c20 > code segment = base 0x0, limit 0xfffff, type 0x1b > = DPL 0, pres 1, long 1, def32 0, gran 1 > processor eflags = resume, IOPL = 0 > current process = 11 (idle: cpu0) > rdi: 0000000000002f2c rsi: 0000000000008000 rdx: 0000000000002e2d > rcx: 0000000000002e2c r8: fffffe00a58a0630 r9: 000000007fff2744 > rax: fffffe000ef4e000 rbx: 0000000000002e2c rbp: fffffe008bc49c20 > r10: 00000000000003e7 r11: 000000000000044c r12: 0000002f2d000000 > r13: 0000002f2d000000 r14: 0000002e2dd1597a r15: ffffffff82b28300 > trap number = 12 > panic: page fault > cpuid = 0 > time = 1779819492 > KDB: stack backtrace: > db_trace_self_wrapper() at db_trace_self_wrapper+0x36/frame > 0xfffffe008bc498e0 > vpanic() at vpanic+0x149/frame 0xfffffe008bc49a10 > panic() at panic+0x43/frame 0xfffffe008bc49a70 > trap_pfault() at trap_pfault+0x449/frame 0xfffffe008bc49ae0 > calltrap() at calltrap+0x8/frame 0xfffffe008bc49ae0 > --- trap 0xc, rip = 0xffffffff80c0ebe8, rsp = 0xfffffe008bc49bb0, rbp = > 0xfffffe008bc49c20 --- > callout_process() at callout_process+0x138/frame 0xfffffe008bc49c20 > handleevents() at handleevents+0x19a/frame 0xfffffe008bc49c60 > timercb() at timercb+0x19e/frame 0xfffffe008bc49cc0 > lapic_handle_timer() at lapic_handle_timer+0xa4/frame 0xfffffe008bc49cf0 > Xtimerint() at Xtimerint+0xb1/frame 0xfffffe008bc49cf0 > --- interrupt, rip = 0xffffffff810b1104, rsp = 0xfffffe008bc49dc0, rbp = > 0xfffffe008bc49dd0 --- > cpu_idle_acpi() at cpu_idle_acpi+0x54/frame 0xfffffe008bc49dd0 > cpu_idle() at cpu_idle+0xa6/frame 0xfffffe008bc49df0 > sched_ule_idletd() at sched_ule_idletd+0x524/frame 0xfffffe008bc49ef0 > fork_exit() at fork_exit+0x82/frame 0xfffffe008bc49f30 > fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe008bc49f30 > --- trap 0, rip = 0, rsp = 0, rbp = 0 --- > KDB: enter: panic > [ thread pid 11 tid 100003 ] > Stopped at kdb_enter+0x33: movq $0,0x15be0c2(%rip) > db> reset > panic: mtx_lock_spin: recursed on non-recursive mutex callout @ > /usr/src/sys/kern/kern_timeout.c:576 > > cpuid = 0 > time = 1779819492 > KDB: stack backtrace: > db_trace_self_wrapper() at db_trace_self_wrapper+0x36/frame > 0xfffffe008bc49160 > vpanic() at vpanic+0x149/frame 0xfffffe008bc49290 > panic() at panic+0x43/frame 0xfffffe008bc492f0 > __mtx_lock_spin_flags() at __mtx_lock_spin_flags+0x11b/frame > 0xfffffe008bc49330 > _callout_stop_safe() at _callout_stop_safe+0x106/frame 0xfffffe008bc493a0 > shutdown_resettodr() at shutdown_resettodr+0x15/frame 0xfffffe008bc493b0 > kern_reboot() at kern_reboot+0x2a3/frame 0xfffffe008bc493f0 > db_reset() at db_reset+0x108/frame 0xfffffe008bc49420 > db_command() at db_command+0x3aa/frame 0xfffffe008bc494e0 > db_command_loop() at db_command_loop+0x4d/frame 0xfffffe008bc494f0 > db_trap() at db_trap+0x100/frame 0xfffffe008bc49590 > kdb_trap() at kdb_trap+0x25f/frame 0xfffffe008bc496e0 > trap() at trap+0x888/frame 0xfffffe008bc49810 > calltrap() at calltrap+0x8/frame 0xfffffe008bc49810 > --- trap 0x3, rip = 0xffffffff80c44f43, rsp = 0xfffffe008bc498e8, rbp = > 0xfffffe008bc49a10 --- > kdb_enter() at kdb_enter+0x33/frame 0xfffffe008bc49a10 > panic() at panic+0x43/frame 0xfffffe008bc49a70 > trap_pfault() at trap_pfault+0x449/frame 0xfffffe008bc49ae0 > calltrap() at calltrap+0x8/frame 0xfffffe008bc49ae0 > --- trap 0xc, rip = 0xffffffff80c0ebe8, rsp = 0xfffffe008bc49bb0, rbp = > 0xfffffe008bc49c20 --- > callout_process() at callout_process+0x138/frame 0xfffffe008bc49c20 > handleevents() at handleevents+0x19a/frame 0xfffffe008bc49c60 > timercb() at timercb+0x19e/frame 0xfffffe008bc49cc0 > lapic_handle_timer() at lapic_handle_timer+0xa4/frame 0xfffffe008bc49cf0 > Xtimerint() at Xtimerint+0xb1/frame 0xfffffe008bc49cf0 > --- interrupt, rip = 0xffffffff810b1104, rsp = 0xfffffe008bc49dc0, rbp = > 0xfffffe008bc49dd0 --- > cpu_idle_acpi() at cpu_idle_acpi+0x54/frame 0xfffffe008bc49dd0 > cpu_idle() at cpu_idle+0xa6/frame 0xfffffe008bc49df0 > sched_ule_idletd() at sched_ule_idletd+0x524/frame 0xfffffe008bc49ef0 > fork_exit() at fork_exit+0x82/frame 0xfffffe008bc49f30 > fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe008bc49f30 > --- trap 0, rip = 0, rsp = 0, rbp = 0 --- > panic: mtx_lock_spin: recursed on non-recursive mutex callout @ > /usr/src/sys/kern/kern_timeout.c:576 > > cpuid = 0 > time = 1779819492 > .. > .. > .. > > > -- Bjoern A. Zeeb r15:7