From owner-freebsd-net@freebsd.org Sat Nov 5 17:05:26 2016 Return-Path: Delivered-To: freebsd-net@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 5B5EBAF76FF for ; Sat, 5 Nov 2016 17:05:26 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 41A7713C for ; Sat, 5 Nov 2016 17:05:26 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id uA5H5PnF085285 for ; Sat, 5 Nov 2016 17:05:26 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-net@FreeBSD.org Subject: [Bug 213257] Crash in IGB driver with ALTQ Date: Sat, 05 Nov 2016 17:05:25 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 10.3-STABLE X-Bugzilla-Keywords: IntelNetworking X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: john@saltant.com X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-net@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: cc Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 05 Nov 2016 17:05:26 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D213257 John W. O'Brien changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |john@saltant.com --- Comment #8 from John W. O'Brien --- I believe I have been experiencing this too. Didn't happen at r301164. Does happen as of r306933. Here are examples of two recent traces from 10.3-STABLE r308209 with ALTQ enabled. #0 doadump (textdump=3D) at pcpu.h:219 #1 0xffffffff809939b2 in kern_reboot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c:486 #2 0xffffffff80993d95 in vpanic (fmt=3D, ap=3D) at /usr/src/sys/kern/kern_shutdown.c:889 #3 0xffffffff80993c23 in panic (fmt=3D0x0) at /usr/src/sys/kern/kern_shutdown.c:818 #4 0xffffffff80a10cb3 in sbcut_internal (sb=3D, len=3D) at /usr/src/sys/kern/uipc_sockbuf.c:886 #5 0xffffffff80b52a71 in tcp_do_segment (m=3D, th=3D, so=3D, tp=3D, drop_hdrlen=3D, tlen= =3D0, iptos=3D, ti_locked=3D) at /usr/src/sys/netinet/tcp_input.c:2838 #6 0xffffffff80b50897 in tcp_input (m=3D, off0=3D) at /usr/src/sys/netinet/tcp_input.c:1414 #7 0xffffffff80adee4b in ip_input (m=3D0xfffff800460cf400) at /usr/src/sys/netinet/ip_input.c:733 #8 0xffffffff80a761b2 in netisr_dispatch_src (proto=3D, source=3D, m=3D0x0) at /usr/src/sys/net/netisr.c:9= 76 #9 0xffffffff80a6c036 in ether_demux (ifp=3D, m=3D0xfffff800460cf400) at /usr/src/sys/net/if_ethersubr.c:851 #10 0xffffffff80a6ccde in ether_nh_input (m=3D) at /usr/src/sys/net/if_ethersubr.c:646 #11 0xffffffff80a761b2 in netisr_dispatch_src (proto=3D, source=3D, m=3D0x0) at /usr/src/sys/net/netisr.c:9= 76 #12 0xffffffff805101b9 in igb_rxeof (count=3D98) at /usr/src/sys/dev/e1000/if_igb.c:4790 #13 0xffffffff80510803 in igb_msix_que (arg=3D0xfffff8000996f400) at /usr/src/sys/dev/e1000/if_igb.c:1597 #14 0xffffffff8095f30b in intr_event_execute_handlers ( p=3D, ie=3D0xfffff80009979d00) at /usr/src/sys/kern/kern_intr.c:1264 #15 0xffffffff8095f756 in ithread_loop (arg=3D0xfffff800099982a0) at /usr/src/sys/kern/kern_intr.c:1277 #16 0xffffffff8095ce3a in fork_exit ( callout=3D0xffffffff8095f6c0 , arg=3D0xfffff800099982a0, frame=3D0xfffffe0000340ac0) at /usr/src/sys/kern/kern_fork.c:1030 #17 0xffffffff80ddda3e in fork_trampoline () at /usr/src/sys/amd64/amd64/exception.S:613 #18 0x0000000000000000 in ?? () #0 doadump (textdump=3D) at pcpu.h:219 #1 0xffffffff809939b2 in kern_reboot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c:486 #2 0xffffffff80993d95 in vpanic (fmt=3D, ap=3D) at /usr/src/sys/kern/kern_shutdown.c:889 #3 0xffffffff80993c23 in panic (fmt=3D0x0) at /usr/src/sys/kern/kern_shutdown.c:818 #4 0xffffffff80df7b7b in trap_fatal (frame=3D, eva=3D) at /usr/src/sys/amd64/amd64/trap.c:858 #5 0xffffffff80df77ef in trap (frame=3D) at /usr/src/sys/amd64/amd64/trap.c:203 #6 0xffffffff80ddd4fc in calltrap () at /usr/src/sys/amd64/amd64/exception.S:238 #7 0xffffffff80a0cfcf in m_tag_delete_chain (m=3D0xfffff80059071600, t=3D) at /usr/src/sys/kern/uipc_mbuf2.c:353 #8 0xffffffff80c6c07e in uma_zfree_arg (zone=3D0xfffff800073fe000, item=3D0xfffff80059071600, udata=3D0x0) at /usr/src/sys/vm/uma_core.c:2= 693 #9 0xffffffff80a08cd3 in m_freem (mb=3D) at uma.h:364 #10 0xffffffff80a6c047 in ether_demux (ifp=3D, m=3D0xfffff80059071600) at /usr/src/sys/net/if_ethersubr.c:871 #11 0xffffffff80a6ccde in ether_nh_input (m=3D) at /usr/src/sys/net/if_ethersubr.c:646 #12 0xffffffff80a761b2 in netisr_dispatch_src (proto=3D, source=3D, m=3D0x206c6562616c2e65) at /usr/src/sys/net/netisr.c:976 #13 0xffffffff805101b9 in igb_rxeof (count=3D98) at /usr/src/sys/dev/e1000/if_igb.c:4790 #14 0xffffffff80510803 in igb_msix_que (arg=3D0xfffff8000996f670) at /usr/src/sys/dev/e1000/if_igb.c:1597 #15 0xffffffff8095f30b in intr_event_execute_handlers ( p=3D, ie=3D0xfffff80009979700) at /usr/src/sys/kern/kern_intr.c:1264 #16 0xffffffff8095f756 in ithread_loop (arg=3D0xfffff800099981e0) at /usr/src/sys/kern/kern_intr.c:1277 #17 0xffffffff8095ce3a in fork_exit ( callout=3D0xffffffff8095f6c0 , arg=3D0xfffff800099981e0, frame=3D0xfffffe000037cac0) at /usr/src/sys/kern/kern_fork.c:1030 #18 0xffffffff80ddda3e in fork_trampoline () at /usr/src/sys/amd64/amd64/exception.S:613 #19 0x0000000000000000 in ?? () Let me know how else I can help isolate the issue. --=20 You are receiving this mail because: You are the assignee for the bug.=