Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 23 May 2012 22:10:04 GMT
From:      Joerg Pulz <Joerg.Pulz@frm2.tum.de>
To:        freebsd-pf@FreeBSD.org
Subject:   Re: kern/168190: [pf] panic when using pf and route-to (maybe: bad fragment handling?)
Message-ID:  <201205232210.q4NMA4PF058452@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help
The following reply was made to PR kern/168190; it has been noted by GNATS.

From: Joerg Pulz <Joerg.Pulz@frm2.tum.de>
To: Daniel Hartmeier <daniel@benzedrine.cx>
Cc: FreeBSD-gnats-submit@freebsd.org, freebsd-pf@freebsd.org
Subject: Re: kern/168190: [pf] panic when using pf and route-to (maybe: bad
 fragment handling?)
Date: Thu, 24 May 2012 00:06:54 +0200 (CEST)

   This message is in MIME format.  The first part should be readable text,
   while the remaining parts are likely unreadable without MIME-aware tools.
 
 --3469798045-489758976-1337810639=:24195
 Content-Type: TEXT/PLAIN; CHARSET=ISO-8859-15; format=flowed
 Content-Transfer-Encoding: 8BIT
 Content-ID: <alpine.BSF.2.00.1205240006221.24271@unqrf.nqzva.sez2>
 
 -----BEGIN PGP SIGNED MESSAGE-----
 Hash: SHA1
 
 Content-ID: <alpine.BSF.2.00.1205240006220.24271@unqrf.nqzva.sez2>
 
 On Wed, 23 May 2012, Daniel Hartmeier wrote:
 
 > On Wed, May 23, 2012 at 07:50:04PM +0000, Joerg Pulz wrote:
 >
 >>  Let me know if you need more output.
 >
 > Oh, we can identify the pfil hook by printing *pfh, pfh->pfil_func and
 > comparing the address to that of pf_check_out, fr_check_wrapper, and the
 > one for ipfw, right?
 
 Danniel,
 
 here is what i could get out.
 I was unable to print *pfh and pfh->pfil_func, but i printed the other 
 two and *ph, maybe this helps.
 
 Joerg
 
 #### kgdb.out_assert2
 
 GNU gdb 6.1.1 [FreeBSD]
 Copyright 2004 Free Software Foundation, Inc.
 GDB is free software, covered by the GNU General Public License, and you are
 welcome to change it and/or distribute copies of it under certain conditions.
 Type "show copying" to see the conditions.
 There is absolutely no warranty for GDB.  Type "show warranty" for details.
 This GDB was configured as "amd64-marcel-freebsd"...
 
 Unread portion of the kernel message buffer:
 panic: ASSERT_HOST_BYTE_ORDER
 cpuid = 1
 KDB: stack backtrace:
 db_trace_self_wrapper() at db_trace_self_wrapper+0x2a
 kdb_backtrace() at kdb_backtrace+0x37
 panic() at panic+0x182
 pfil_run_hooks() at pfil_run_hooks+0x159
 ip_output() at ip_output+0x6de
 ip_forward() at ip_forward+0x19e
 ip_input() at ip_input+0x670
 swi_net() at swi_net+0x15a
 intr_event_execute_handlers() at intr_event_execute_handlers+0x66
 ithread_loop() at ithread_loop+0xaf
 fork_exit() at fork_exit+0x12a
 fork_trampoline() at fork_trampoline+0xe
 - --- trap 0, rip = 0, rsp = 0xffffff8000241d00, rbp = 0 ---
 KDB: enter: panic
 Dumping 585 out of 4077 MB:..3%..11%..22%..31%..41%..52%..61%..72%..82%..91%
 
 Reading symbols from /boot/kernel/geom_mirror.ko...Reading symbols from /boot/kernel/geom_mirror.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/geom_mirror.ko
 Reading symbols from /boot/kernel/ipmi.ko...Reading symbols from /boot/kernel/ipmi.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/ipmi.ko
 #0  doadump (textdump=0) at pcpu.h:224
 224		__asm("movq %%gs:0,%0" : "=r" (td));
 (kgdb) up 10
 #10 0xffffffff8074b325 in pfil_run_hooks (ph=0xfffffe000581f880,
      mp=0xffffff8000241978, ifp=0xfffffe0003002000, dir=2, inp=0x0)
      at /usr/src/sys/net/pfil.c:89
 89				ASSERT_HOST_BYTE_ORDER(m);
 (kgdb) list
 84				ASSERT_HOST_BYTE_ORDER(m);
 85				rv = (*pfh->pfil_func)(pfh->pfil_arg, &m, ifp, dir,
 86				    inp);
 87				if (rv != 0 || m == NULL)
 88					break;
 89				ASSERT_HOST_BYTE_ORDER(m);
 90			}
 91		}
 92		PFIL_RUNLOCK(ph, &rmpt);
 93		*mp = m;
 (kgdb) p *pfh
 (kgdb) p pfh->pfil_func
 (kgdb) p pf_check_out
 $1 = {int (void *, struct mbuf **, struct ifnet *, int, struct inpcb
       *)} 0xffffffff8032d17a <pf_check_out>
 (kgdb) p fr_check_wrapper
 $2 = {int (void *, struct mbuf **, struct ifnet *,
      int)} 0xffffffff802fae2d <fr_check_wrapper>
 (kgdb) p *ph
 $3 = {ph_in = {tqh_first = 0xfffffe0003007b40, tqh_last = 0xfffffe000581fb00},
    ph_out = {tqh_first = 0xffffffff80779733, tqh_last = 0x0},
    ph_type = 92404512, ph_nhooks = -512, ph_lock = {lock_object = {
        lo_name = 0xfffffe0003007ae0 " ø\201\005", lo_flags = 2155321139,
        lo_data = 4294967295, lo_witness = 0x0}, rm_writecpus = {__bits = {
          -2198926812672}}, rm_activeReaders = {lh_first = 0xfffffe0005bf9b00},
      _rm_lock = {_rm_lock_mtx = {lock_object = {
            lo_name = 0x1 <Address 0x1 out of bounds>, lo_flags = 0,
            lo_data = 0, lo_witness = 0xfffffe000589f800},
          mtx_lock = 18446741874779218176}, _rm_lock_sx = {lock_object = {
            lo_name = 0x1 <Address 0x1 out of bounds>, lo_flags = 0,
            lo_data = 0, lo_witness = 0xfffffe000589f800},
          sx_lock = 18446741874779218176}}}, ph_un = {phu_val = 0,
      phu_ptr = 0x0}, ph_list = {le_next = 0x0, le_prev = 0xfffffe000581f800}}
 (kgdb)
 
 #### kgdb.out_assert2
 
 - -- 
 The beginning is the most important part of the work.
  				-Plato
 -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v2.0.18 (FreeBSD)
 
 iD8DBQFPvV+BSPOsGF+KA+MRAudvAJ4kQQl4isOAkmVCvzcj1ipGEagbwACgkhhO
 Ib9Dfbm6bUJcUHS6yBcbrQU=
 =FnJL
 -----END PGP SIGNATURE-----
 --3469798045-489758976-1337810639=:24195--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201205232210.q4NMA4PF058452>