Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 21 Feb 2003 16:02:07 -0300
From:      "Daniel C. Sobral" <dcs@tcoip.com.br>
To:        rwatson@freebsd.org, current@freebsd.org
Subject:   Witness This
Message-ID:  <3E5677AF.9060005@tcoip.com.br>

next in thread | raw e-mail | index | archive | help

Ok, a couple of witness complains, first about the sound driver, I 
think, and the second something macish. Then a backtrace for a mac_mls 
panic. All this for your weekend entertainment. :-)

First, witness cmi:

backtrace(c032e7d9,c25af500,c25a98d4,c046236e,c04623ec) at backtrace+0x17

witness_lock(c25af500,8,c04623ec,1b8,c) at witness_lock+0x660
_mtx_lock_flags(c25af500,0,c04623ec,1b8,80000095) at _mtx_lock_flags+0xb1
chn_intr(c25a9880,c,10000,208,c25af7c0) at chn_intr+0x2f
cmi_intr(c25a9800,0,c0329618,217,c25ae9ec) at cmi_intr+0xa6
ithread_loop(c25a9000,cd2ced48,c032948d,366,55ff44fd) at ithread_loop+0x182
fork_exit(c01cd420,c25a9000,cd2ced48) at fork_exit+0xc4
fork_trampoline() at fork_trampoline+0x1a
--- trap 0x1, eip = 0, esp = 0xcd2ced7c, ebp = 0 ---

Now, witness biba:

backtrace(c032e7d9,c0831110,c03395bc,c03395bc,c0339453) at backtrace+0x17
witness_lock(c0831110,8,c0339453,145,d1d726dc) at witness_lock+0x660
_mtx_lock_flags(c0831110,0,c0339453,145,d1d72704) at _mtx_lock_flags+0xb1
_vm_map_lock(c08310b0,c0339453,145,d1d72708,c038a058) at _vm_map_lock+0x36
kmem_malloc(c08310b0,1000,5,d1d72770,c02bda1d) at kmem_malloc+0x65
page_alloc(c083c240,1000,d1d72763,5,c0389e00) at page_alloc+0x27
slab_zalloc(c083c240,5,c033ae28,667,c083cda4) at slab_zalloc+0xfd
uma_zone_slab(c083c240,5,c033ae28,667,0) at uma_zone_slab+0xd8
uma_zalloc_internal(c083c240,0,5,6e7,0) at uma_zalloc_internal+0x55
uma_zfree_arg(c083cd80,c2bc0900,c2bc0fc8,116,80) at uma_zfree_arg+0x2c9
free(c2bc0900,c0364b80,d1d72838,c027620d,c2bc0900) at free+0xde
biba_free(c2bc0900,c0364e60,d1d72858,c01d6baf,c2c1621c) at biba_free+0x1d
mac_biba_destroy_label(c2c1621c,0,c032a35b,3eb,0) at 
mac_biba_destroy_label+0x1d

mac_destroy_vnode_label(c2c1621c,d1d728bc,c0240373,c2c1611c,0) at 
mac_destroy_vn
ode_label+0x7f
mac_destroy_vnode(c2c1611c,0,c03329d0,3bd,15d) at mac_destroy_vnode+0x16
getnewvnode(c0334a68,c25f9800,c2607700,d1d7290c,6) at getnewvnode+0x393
ffs_vget(c25f9800,19273,2,d1d72984,d1d72988) at ffs_vget+0x9b
ufs_lookup(d1d72ab8,d1d72af4,c0236d7c,d1d72ab8,d1d72c38) at ufs_lookup+0xdfb
ufs_vnoperate(d1d72ab8,d1d72c38,d1d72c4c,c01f3b04,c26095a0) at 
ufs_vnoperate+0x1
8
vfs_cache_lookup(d1d72b68,d1d72b94,c023b6d9,d1d72b68,c2c40e6c) at 
vfs_cache_look
up+0x2fc
ufs_vnoperate(d1d72b68,c2c40e6c,d1d72c4c,0,c26095a0) at ufs_vnoperate+0x18
lookup(d1d72c24,0,c0332347,a4,c26095a0) at lookup+0x329
namei(d1d72c24,0,d1d72c24,c0390440,0) at namei+0x24e
lstat(c26095a0,d1d72d10,c033e8c9,407,2) at lstat+0x52
syscall(806002f,806002f,bfbf002f,8072b00,8072b48) at syscall+0x28e
Xint0x80_syscall() at Xint0x80_syscall+0x1d
--- syscall (190), eip = 0x280b8ea3, esp = 0xbfbffb0c, ebp = 0xbfbffba8 ---

Finally, trace this:

#0  doadump () at /usr/src/sys/kern/kern_shutdown.c:239
No locals.
#1  0xc0128945 in db_fncall (dummy1=0, dummy2=0, dummy3=1999,
     dummy4=0xcd2a7750 "\200'7À\bÚ6Àlw*Í\r")
     at /usr/src/sys/ddb/db_command.c:546
	fn_addr = -1071732400
	args = {0 <repeats 11 times>}
	nargs = 11
	retval = 0
	func = (fcn_10args_t *) 0xc01ea950 <doadump>
	t = 0
#2  0xc01286c2 in db_command (last_cmdp=0xc0346ae0, cmd_table=0x0,
     aux_cmd_tablep=0xc0341084, aux_cmd_tablep_end=0xc0341088)
     at /usr/src/sys/ddb/db_command.c:346
	cmd = (struct command *) 0xc0346a70
	t = 0
	modif = "\200'7À\bÚ6Àlw*Í\r\0\0\0`\006<À\r\0\0\0\001\0\0\0\214w*ͦU-Ààì:
À\aK\0 
à\006<À\200Ë:À\200'7Àx\0\0\0\200'7À\bÚ6À°w*Íá£\022ÀGò1ÀТ\022À\0\0\0\0\02
0\0\0\0\bÚ6À\200'7ÀN\234\022À\200'7À`\0377Àx\0\0\0\003\0\0"
	addr = 0
	count = 1999
	have_addr = 0
	result = 0
#3  0xc01287d6 in db_command_loop () at /usr/src/sys/ddb/db_command.c:470
No locals.
#4  0xc012b56a in db_trap (type=3, code=0) at /usr/src/sys/ddb/db_trap.c:72
	bkpt = 0
#5  0xc02dec22 in kdb_trap (type=3, code=0, regs=0xcd2a78a4)
     at /usr/src/sys/i386/i386/db_interface.c:166
	ddb_mode = 1
#6  0xc02f060f in trap (frame=
       {tf_fs = 24, tf_es = -1070006256, tf_ds = -852885488, tf_edi = 
-1058227632
, tf_esi = 256, tf_ebp = -852854544, tf_isp = -852854576, tf_ebx = 0, 
tf_edx = 0
, tf_ecx = 1920, tf_eax = 18, tf_trapno = 3, tf_err = 0, tf_eip = 
-1070731580, t
f_cs = 8, tf_eflags = 646, tf_esp = -1070350146, tf_ss = -1070421591})
     at /usr/src/sys/i386/i386/trap.c:603
	td = (struct thread *) 0xc0ecba50
	p = (struct proc *) 0xc0eca9ec
	sticks = 0
	i = 0
	ucode = 0
	type = 3
	code = 0
	eva = 0
#7  0xc02e0578 in calltrap () at {standard input}:96
No locals.
#8  0xc01eb0bb in panic (fmt=0x0) at /usr/src/sys/kern/kern_shutdown.c:528
	td = (struct thread *) 0xc0ecba50
	bootopt = 256
	newpanic = 1
	buf = "mac_mls_single_in_range: a not single", '\0' <repeats 218 times>
#9  0xc0277274 in mac_mls_single_in_range (single=0x0, range=0xc2605e80)
     at /usr/src/sys/security/mac_mls/mac_mls.c:225
No locals.
#10 0xc0278cb6 in mac_mls_check_ifnet_transmit (ifnet=0xc25ebc00,
     ifnetlabel=0x0, m=0xc0eda000, mbuflabel=0x0)
     at /usr/src/sys/security/mac_mls/mac_mls.c:1462
	p = (struct mac_mls *) 0x0
	i = (struct mac_mls *) 0x0
#11 0xc01dad7a in mac_check_ifnet_transmit (ifnet=0xc25ebc00, 
mbuf=0xc0eda000)
     at /usr/src/sys/kern/kern_mac.c:2269
	mpc = (struct mac_policy_conf *) 0xc2605e80
	error = 0
#12 0xc02527d8 in ether_output (ifp=0xc25ebc00, m=0xc0eda000, 
dst=0xc26cc410,
     rt0=0xc2b16100) at /usr/src/sys/net/if_ethersubr.c:157
	type = 0
	error = -1058168748
	hdrcmplt = 0
	esrc = "\0\0\0\0\024"
	edst = "T íÀÌy"
	rt = (struct rtentry *) 0xc0eda000
	eh = (struct ether_header *) 0xc0eda054
	loop_copy = 0
	ac = (struct arpcom *) 0xc25ebc00
#13 0xc0262785 in ip_output (m0=0xc0eda000, opt=0xc0eda054, ro=0xc289ba08,
     flags=0, imo=0x0, inp=0xc289b9cc) at 
/usr/src/sys/netinet/ip_output.c:1015
	ip = (struct ip *) 0xc0eda054
	mhip = (struct ip *) 0xcd2a7a58
	ifp = (struct ifnet *) 0xc25ebc00
	m = (struct mbuf *) 0xc2b16100
	hlen = 20
	len = -1071770192
	off = -1070052704
	error = 0
	dst = (struct sockaddr_in *) 0xc26cc410
	ia = (struct in_ifaddr *) 0xc2608e00
	isbroadcast = 0
	sw_csum = 1
	pkt_dst = {s_addr = 843641662}
	args = {m = 0xcd2a7a7c, oif = 0xc01d181b, next_hop = 0x0, rule = 0x0,
   eh = 0x0, ro = 0x2cf, dst = 0xc0eda000, flags = 2, f_id = {dst_ip = 1,
     src_ip = 3442113188, dst_port = 20111, src_port = 49184, proto = 0 
'\0',
     flags = 160 ' '}, divert_rule = 0, retval = 2}
	src_was_INADDR_ANY = 0
#14 0xc026a68c in tcp_twrespond (tw=0xc2cd3000, flags=16)
     at /usr/src/sys/netinet/tcp_subr.c:1776
	inp = (struct inpcb *) 0xc289b9cc
	th = (struct tcphdr *) 0xc0eda068
	m = (struct mbuf *) 0xc0eda000
	ip = (struct ip *) 0xc0eda054
	optp = (u_int8_t *) 0x0
	optlen = 12
	error = 0
#15 0xc026a42d in tcp_twstart (tp=0xc280d700)
     at /usr/src/sys/netinet/tcp_subr.c:1663
	tm = (struct tcptw_mem *) 0x0
	tw = (struct tcptw *) 0xc2cd3000
	inp = (struct inpcb *) 0xc289b9cc
	tw_time = 60000
	acknow = 1
	so = (struct socket *) 0xc280d700
#16 0xc026706e in tcp_input (m=0xc0eda000, off0=20)
     at /usr/src/sys/netinet/tcp_input.c:2189
	th = (struct tcphdr *) 0xc1357034
	ip = (struct ip *) 0xc1357020
	ipov = (struct ipovly *) 0x1
	inp = (struct inpcb *) 0xc289b9cc
	optp = (u_char *) 0xc1357048 "\001\001\b\n\017-\2235"
	optlen = 12
	len = -1031153932
	tlen = 0
	off = -1031153932
	drop_hdrlen = 52
	tp = (struct tcpcb *) 0xc289d6f4
	thflags = 1
	so = (struct socket *) 0xc280d700
	todrop = -1031153932
	acked = -1031153932
	ourfinisacked = -1031153932
	needoutput = 0
	tiwin = 57920
	to = {to_flags = 1, to_tsval = 254645045, to_tsecr = 379134,
   to_cc = 0, to_ccecho = 0, to_mss = 0, to_requested_s_scale = 0 '\0',
   to_pad = 0 '\0'}
	taop = (struct rmxp_tao *) 0xc289d6f4
	tao_noncached = {tao_cc = 3442113524, tao_ccsent = 5,
   tao_mssopt = 45568}
	headlocked = 0
	next_hop = (struct sockaddr_in *) 0x0
	rstreason = -1031153932
#17 0xc0260a14 in ip_input (m=0xc0eda000)
     at /usr/src/sys/netinet/ip_input.c:934
	ip = (struct ip *) 0xc1357020
	fp = (struct ipq *) 0xc2608e00
	ia = (struct in_ifaddr *) 0xc2608e00
	ifa = (struct ifaddr *) 0x0
	i = 0
	hlen = 20
	checkif = 1
	sum = 0
	pkt_dst = {s_addr = 100794378}
	divert_info = 0
	args = {m = 0xc03aca38, oif = 0x0, next_hop = 0x0, rule = 0x0,
   eh = 0x0, ro = 0xcd2a7cb8, dst = 0xc0360fb4, flags = 949, f_id = {
     dst_ip = 3224580591, src_ip = 3442113704, dst_port = 5552,
     src_port = 49182, proto = 180 '´', flags = 15 '\017'}, divert_rule = 0,
   retval = 3224542840}
#18 0xc0260ac1 in ipintr () at /usr/src/sys/netinet/ip_input.c:952
	m = (struct mbuf *) 0xc0eda000
#19 0xc0254964 in swi_net (dummy=0x0) at /usr/src/sys/net/netisr.c:97
	pollmore = 0
	bits = 4
	i = 2
#20 0xc01c9be2 in ithread_loop (arg=0xc0ec8f00)
     at /usr/src/sys/kern/kern_intr.c:536
	ithd = (struct ithd *) 0xc0ec8f00
	ih = (struct intrhand *) 0xc0ec04c0
	td = (struct thread *) 0xc0ecba50
	p = (struct proc *) 0xc0eca9ec
#21 0xc01c8cb4 in fork_exit (callout=0xc0ec04c0, arg=0x0, frame=0x0)
     at /usr/src/sys/kern/kern_fork.c:871
	td = (struct thread *) 0x0
	p = (struct proc *) 0xc0ec8f00



-- 
Daniel C. Sobral
Gerência de Operações
Divisão de Comunicação de Dados
Coordenação de Segurança
TCO
Fones: 55-61-313-7654/Cel: 55-61-9618-0904
E-mail:	Daniel.Capo@tco.net.br
	Daniel.Sobral@tcoip.com.br
	dcs@tcoip.com.br



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3E5677AF.9060005>