From owner-freebsd-bugs@freebsd.org Tue Sep 10 14:13:01 2019 Return-Path: Delivered-To: freebsd-bugs@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 343DAD782E for ; Tue, 10 Sep 2019 14:13:01 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mailman.nyi.freebsd.org (mailman.nyi.freebsd.org [IPv6:2610:1c1:1:606c::50:13]) by mx1.freebsd.org (Postfix) with ESMTP id 46SRnn0cdxz4TwF for ; Tue, 10 Sep 2019 14:13:01 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: by mailman.nyi.freebsd.org (Postfix) id 14E4BD782D; Tue, 10 Sep 2019 14:13:01 +0000 (UTC) Delivered-To: bugs@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 14ABED782C for ; Tue, 10 Sep 2019 14:13:01 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 46SRnm6rh0z4TwD for ; Tue, 10 Sep 2019 14:13:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id CFD7F274DC for ; Tue, 10 Sep 2019 14:13:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id x8AED0TD070580 for ; Tue, 10 Sep 2019 14:13:00 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id x8AED0G0070579 for bugs@FreeBSD.org; Tue, 10 Sep 2019 14:13:00 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: bugs@FreeBSD.org Subject: [Bug 240471] panic: rcv_start < rcv_end Date: Tue, 10 Sep 2019 14:13:00 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: new X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: ler@FreeBSD.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: bugs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_id short_desc product version rep_platform op_sys bug_status bug_severity priority component assigned_to reporter Message-ID: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 10 Sep 2019 14:13:01 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D240471 Bug ID: 240471 Summary: panic: rcv_start < rcv_end Product: Base System Version: CURRENT Hardware: Any OS: Any Status: New Severity: Affects Only Me Priority: --- Component: kern Assignee: bugs@FreeBSD.org Reporter: ler@FreeBSD.org I've seen this panic for a while randomly. I have cores. this latest one is on r352025 Unread portion of the kernel message buffer: panic: rcv_start < rcv_end cpuid =3D 0 time =3D 1568101636 KDB: stack backtrace: db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xfffffe01f7ccb= 380 vpanic() at vpanic+0x19d/frame 0xfffffe01f7ccb3d0 panic() at panic+0x43/frame 0xfffffe01f7ccb430 tcp_update_dsack_list() at tcp_update_dsack_list+0x489/frame 0xfffffe01f7cc= b4b0 tcp_do_segment() at tcp_do_segment+0x1fbd/frame 0xfffffe01f7ccb590 tcp_input() at tcp_input+0xde8/frame 0xfffffe01f7ccb6e0 ip_input() at ip_input+0x11d/frame 0xfffffe01f7ccb780 netisr_dispatch_src() at netisr_dispatch_src+0x89/frame 0xfffffe01f7ccb7f0 ether_demux() at ether_demux+0x13b/frame 0xfffffe01f7ccb820 ng_ether_rcv_upper() at ng_ether_rcv_upper+0x95/frame 0xfffffe01f7ccb840 ng_apply_item() at ng_apply_item+0x100/frame 0xfffffe01f7ccb8c0 ng_snd_item() at ng_snd_item+0x2ad/frame 0xfffffe01f7ccb900 ng_apply_item() at ng_apply_item+0x100/frame 0xfffffe01f7ccb980 ng_snd_item() at ng_snd_item+0x2ad/frame 0xfffffe01f7ccb9c0 ng_ether_input() at ng_ether_input+0x4c/frame 0xfffffe01f7ccb9f0 ether_nh_input() at ether_nh_input+0x2cd/frame 0xfffffe01f7ccba40 netisr_dispatch_src() at netisr_dispatch_src+0x89/frame 0xfffffe01f7ccbab0 ether_input() at ether_input+0x48/frame 0xfffffe01f7ccbad0 bce_intr() at bce_intr+0x697/frame 0xfffffe01f7ccbb50 ithread_loop() at ithread_loop+0x187/frame 0xfffffe01f7ccbbb0 fork_exit() at fork_exit+0x84/frame 0xfffffe01f7ccbbf0 fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe01f7ccbbf0 --- trap 0, rip =3D 0, rsp =3D 0, rbp =3D 0 --- Uptime: 2d7h30m34s Dumping 26161 out of 131027 MB:..1%..11%..21%..31%..41%..51%..61%..71%..81%..91% __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55 55 __asm("movq %%gs:%P1,%0" : "=3Dr" (td) : "n" (offsetof(stru= ct pcpu, (kgdb) #0 __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:55 #1 doadump (textdump=3D1) at /usr/src/sys/kern/kern_shutdown.c:392 #2 0xffffffff804bd160 in kern_reboot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c:479 #3 0xffffffff804bd5d9 in vpanic (fmt=3D, ap=3D) at /usr/src/sys/kern/kern_shutdown.c:908 #4 0xffffffff804bd313 in panic (fmt=3D) at /usr/src/sys/kern/kern_shutdown.c:835 #5 0xffffffff80676049 in tcp_update_dsack_list (tp=3D0xfffff81092c91760, rcv_start=3D1781970437, rcv_end=3D1781970437) at /usr/src/sys/netinet/tcp_sack.c:166 #6 0xffffffff8066b01d in tcp_do_segment (m=3D0xfffff806144cfa00, th=3D, so=3D0xfffff8018caf2a98, tp=3D0xfffff81092c91760, drop_hdrlen=3D40, tlen=3D, iptos=3D0 '\000') at /usr/src/sys/netinet/tcp_input.c:3076 #7 0xffffffff80668378 in tcp_input (mp=3D, offp=3D, proto=3D) at /usr/src/sys/netinet/tcp_input.c:1373 #8 0xffffffff805f2c6d in ip_input (m=3D0x0) at /usr/src/sys/netinet/ip_input.c:829 #9 0xffffffff805ce9c9 in netisr_dispatch_src (proto=3D1, source=3D, m=3D) at /usr/src/sys/net/netisr= .c:1123 #10 0xffffffff805c3bfb in ether_demux (ifp=3D0xfffff80129859000, m=3D) at /usr/src/sys/net/if_ethersubr.c:913 #11 0xffffffff827f4045 in ng_ether_rcv_upper (hook=3D, item=3D) at /usr/src/sys/netgraph/ng_ether.c:741 #12 0xffffffff827e1750 in ng_apply_item (node=3D0xfffff8012ee3e500, item=3D0xfffff805ab929b00, rw=3D0) at /usr/src/sys/netgraph/ng_base.c:2= 403 #13 0xffffffff827e144d in ng_snd_item (item=3D0xfffff805ab929b00, flags=3D0) at /usr/src/sys/netgraph/ng_base.c:2320 #14 0xffffffff827e1750 in ng_apply_item (node=3D0xfffff8012ee3e000, item=3D0xfffff805ab929b00, rw=3D0) at /usr/src/sys/netgraph/ng_base.c:2= 403 #15 0xffffffff827e144d in ng_snd_item (item=3D0xfffff805ab929b00, flags=3D0) at /usr/src/sys/netgraph/ng_base.c:2320 #16 0xffffffff827f3cbc in ng_ether_input (ifp=3D, mp=3D0xfffffe01f7ccba18) at /usr/src/sys/netgraph/ng_ether.c:255 #17 0xffffffff805c4e4d in ether_input_internal (ifp=3D0xfffff80129859000, m=3D0xfffff806144cfa00) at /usr/src/sys/net/if_ethersubr.c:654 #18 ether_nh_input (m=3D) at /usr/src/sys/net/if_ethersubr.c= :735 #19 0xffffffff805ce9c9 in netisr_dispatch_src (proto=3D5, source=3D, m=3D) at /usr/src/sys/net/netisr= .c:1123 #20 0xffffffff805c4038 in ether_input (ifp=3D0xfffff80129859000, m=3D0x0) at /usr/src/sys/net/if_ethersubr.c:823 #21 0xffffffff8262f877 in bce_rx_intr (sc=3D) at /usr/src/sys/dev/bce/if_bce.c:6848 #22 bce_intr (xsc=3D0xfffffe0200820000) at /usr/src/sys/dev/bce/if_bce.c:80= 17 #23 0xffffffff80485ba7 in intr_event_execute_handlers (p=3D, ie=3D) at /usr/src/sys/kern/kern_intr.c:1148 #24 ithread_execute_handlers (p=3D, ie=3D) at /usr/src/sys/kern/kern_intr.c:1161 #25 ithread_loop (arg=3D) at /usr/src/sys/kern/kern_intr.c:1= 241 #26 0xffffffff80482704 in fork_exit ( callout=3D0xffffffff80485a20 , arg=3D0xfffff80105945820, frame=3D0xfffffe01f7ccbc00) at /usr/src/sys/kern/kern_fork.c:1046 #27 (kgdb) --=20 You are receiving this mail because: You are the assignee for the bug.=