From nobody Wed Aug 5 14:06:25 2026 X-Original-To: net@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hFXJg4lkMz6nL28 for ; Wed, 05 Aug 2026 14:06:27 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hFXJf6kjJz3lbn for ; Wed, 05 Aug 2026 14:06:26 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1785938786; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vYMrqydal3oRYYYo/YpIe5OFL4J5B7e9lnE86XLkazI=; b=K5RTfN6j98QjAJaeDBK4GJFFqYGJUa6R08D/rt4O1KFJiaC1Rewo8e88CiOz6+COOzc750 Gmha9fBdq2hHY0OZEVQllypPrY5RUCegFRu99vXfaU4Rf0ccR3q4pJhEoIhH1VkY0rR1G/ uWEi15ryV+Zhm3wKijCnhoNdhYSFCj57WTRFrVDdGlLACgGbqyFuZ+SvR4/P+0HJ84avN4 fWC2E5M1Th9rzPauvar2CyaPy544RFc1ysjil+njhhgScgGIK40QC0ur3wC16576WwtSWt zKI9OEXU+VKXQA7t/NJjUq6HH4WTu1HVz79Y2ohE1BHHUISKB2mCPar8u0mqow== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1785938786; a=rsa-sha256; cv=none; b=XJJ96Vj4O0OElBlbmw3UP2DnX9TSIdRw+8R7DD2RqUEfT/Yy4uysY2xwuYTGOqIgWfrBpV SRPtXLExAbEQeF4gU9ICLEEq6Tt/7GTeBJHUL9ozF1V9RdKrR7lMGryevMALKBKhk9n72/ z3ZJpL810qUE8p7ClQcLmPJaMQFRGjTkvW9+v6fjiYUowXhwnK1c+KY2oOyeY4YpnkM+K6 5Qq5qT2YUg4weoYzG937M3X/5rcbwR9J62kO7Bzo6jOt1MJeyYpy/7vTrN1E74u1wh9ngu JoAkQ7KzV0KIx263kxDqRTPXuOUvE348aFQz/9CRVdUyWe4a5rGj2eeb0Yh7Ug== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1785938786; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vYMrqydal3oRYYYo/YpIe5OFL4J5B7e9lnE86XLkazI=; b=EqMu/+ejoREA5m3EVRxoSdNbbXwYdtqb5JrlWcQTZYh0kNoRLLj1BdZY60EOqF9QeWRhzZ CnG5i9SWRM9jHXs7AY9uymf+fGo6MTcnJiKpZ+Q74j10TNYqAVgsaKa7ENsD5INrmHC1NF Xx1ahmbpdegOTal2L3l/WktF4IRTHUd4zxIL/X0U/YGSPTHMdS4HzzdMpSP2VXRuWA7tgc 5UZ4y8L78/hj84O3C6sxv0FPg2zoMJXAgVdZxhQQEIYM+tdUauYBNVYqi5x9tqeilOdqxR Xt3o2/SnL/QbWo8cWB1AFVEAs2tWIGKisu8Ixqmqmc9DaPr0cdhlObKhmN4fhQ== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4hFXJf4xhqzdWM for ; Wed, 05 Aug 2026 14:06:26 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 675E6QIb046746 for ; Wed, 5 Aug 2026 14:06:26 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 675E6Qqk046745 for net@FreeBSD.org; Wed, 5 Aug 2026 14:06:26 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: net@FreeBSD.org Subject: [Bug 288904] [tcp] page fault in tcp_default_output Date: Wed, 05 Aug 2026 14:06:25 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 14.3-RELEASE X-Bugzilla-Keywords: crash, regression X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: firk@cantconnect.ru X-Bugzilla-Status: Closed X-Bugzilla-Resolution: FIXED X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: net@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Networking and TCP/IP with FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-net List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-net@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D288904 --- Comment #25 from firk@cantconnect.ru --- (In reply to Gleb Smirnoff from comment #11) Looks like it is PR 276761 (tcp_close() vs tcp_discardcb() timers desync). = And yes, it was not MFCed to 14.x. The commit bffebc336f4ece4d18774c1ab8f555802cebf961 is related because it fixes a race introduced by PR 276761 fix, but it is not a direct source of these panics. I made a small patch which is expected to fix the problem in 14.x branch. D= id not tested it much for now. I don't think it is a good idea to keep supported 14.4 release in unusable state. --- sys/netinet/tcp_subr.c.orig 2026-08-01 23:05:43.997108869 +0300 +++ sys/netinet/tcp_subr.c 2026-08-05 11:51:31.431921701 +0300 @@ -2598,6 +2598,16 @@ tcp_fastopen_decrement_counter(tp->t_tfo_pending); tp->t_tfo_pending =3D NULL; } + + /* + * tcp_timer_stop() may drop INP_WLOCK internally + * this may lead to racy two-thread closing in rare cases + * so just reset tp->t_timers + * tcp_timer_enter() is aware of this + */ + for (tt_which i =3D 0; i < TT_N; i++) + tp->t_timers[i] =3D SBT_MAX; + if (tp->t_fb->tfb_tcp_timer_stop_all !=3D NULL) tp->t_fb->tfb_tcp_timer_stop_all(tp); in_pcbdrop(inp); --- sys/netinet/tcp_timer.c.orig 2026-08-01 23:05:44.001110870 +0300 +++ sys/netinet/tcp_timer.c 2026-08-05 12:17:39.251384522 +0300 @@ -874,6 +874,11 @@ curthread->td_pflags |=3D TDP_INTCPCALLOUT; which =3D tcp_timer_next(tp, NULL); + if (which =3D=3D TT_N) { /* see tcp_close() comment about stoping t= imers */ + INP_WUNLOCK(inp); + curthread->td_pflags &=3D ~TDP_INTCPCALLOUT; + return; + } MPASS(which < TT_N); tp->t_timers[which] =3D SBT_MAX; tp->t_precisions[which] =3D 0; @@ -909,6 +914,10 @@ #endif INP_WLOCK_ASSERT(inp); + if (tp->t_state =3D=3D TCPS_CLOSED) { +/* printf("tcp_timer_activate(%p,%d,%u) for TCPS_CLOSED connection, ignoring\n", tp, (int)which, delta);*/ + return; + } if (delta > 0) { what =3D TT_STARTING; The commented printf() will often print this warnings for TT_REXMT (0) if enabled, but I don't think these silently skipped timer activations will ha= rm (they seems fixed in 15.x in some other place). --=20 You are receiving this mail because: You are the assignee for the bug.=