Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 12 Feb 2007 14:48:23 +0500
From:      =?koi8-r?B?68/Sy8/Eyc7P1yD3zMHEyc3J0iD3zMHEydPMwdfP18ne?= <korkodinov@ertelecom.ru>
To:        <freebsd-net@freebsd.org>
Subject:   FW: i386/108963: kernel panic on swi:net
Message-ID:  <838DB0534DD36F4EAF4793C7EC83DDFF21EC94@er-mail.hq>

next in thread | raw e-mail | index | archive | help
Dear mailinglist members,

=20

Maybe somebody can look at this PR?

http://www.freebsd.org/cgi/query-pr.cgi?pr=3D108963&cat=3D

As I see we have NULL pointer in m_copydata.

Why it happened?

=20

Are there any suggestions that could assist in solving this problem?

=20

P.S. I have similar problem when using ipnat with ftp_proxy on 6.1R and =
6.2R

Thanks,

Vladimir

=9A

=20

-----Original Message-----
From: owner-freebsd-i386@freebsd.org =
[mailto:owner-freebsd-i386@freebsd.org] On Behalf Of Denis
Sent: Friday, February 09, 2007 3:47 PM
To: freebsd-gnats-submit@FreeBSD.org
Subject: i386/108963: kernel panic on swi:net

=20

=20

>Number:=9A=9A=9A=9A=9A=9A=9A=9A 108963

>Category:=9A=9A=9A=9A=9A=9A i386

>Synopsis:=9A=9A=9A=9A=9A=9A kernel panic on swi:net

>Confidential:=9A=9A no

>Severity:=9A=9A=9A=9A=9A=9A serious

>Priority:=9A=9A=9A=9A=9A=9A high

>Responsible:=9A=9A=9A freebsd-i386

>State:=9A=9A=9A=9A=9A=9A=9A=9A=9A open

>Quarter:=9A=9A=9A=9A=9A=9A=9A=20

>Keywords:=9A=9A=9A=9A=9A=9A=20

>Date-Required:

>Class:=9A=9A=9A=9A=9A=9A=9A=9A=9A sw-bug

>Submitter-Id:=9A=9A current-users

>Arrival-Date:=9A=9A Fri Feb 09 10:50:10 GMT 2007

>Closed-Date:

>Last-Modified:

>Originator:=9A=9A=9A=9A Denis

>Release:=9A=9A=9A=9A=9A=9A=9A 6.2-PRERELEASE CVSUpped from 6.1 RELEASE =
on Feb 6

>Organization:

ISP MainStream

>Environment:

FreeBSD main.nikopol.net 6.2-PRERELEASE FreeBSD 6.2-PRERELEASE #29: Wed =
Feb=9A 7 10:55:22 EET 2007=9A=9A=9A=9A =
den@main.nikopol.net:/usr/src/sys/i386/compile/MS=9A i386

>Description:

Server is using MPD authorization, ipnat address translation; serves =
proxy, sendmail, popa3d, BIND and MySQL daemons.

Problem begin to appear in 6.1-RELEASE with same error and after CVSup =
to 6.2-PRERELEASE on Feb, 6 problem doesn't solved.

=20

Server is running on single core AMD Athlon 3500+, have two Intel =
Gigabit NIC's (em) and one Intel 100Mbit NIC (fxp).

=20

=20

Below I paste core debug information.

=20

=20

Fatal trap 12: page fault while in kernel mode

fault virtual address=9A=9A =3D 0xc

fault code=9A=9A=9A=9A=9A=9A=9A=9A =9A=9A=9A=9A=9A=3D supervisor read, =
page not present

instruction pointer=9A=9A=9A=9A =3D 0x20:0xc055b4cc

stack pointer=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A =3D 0x28:0xe4faaa20

frame pointer=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A =3D 0x28:0xe4faaa2c

code segment=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A =3D base 0x0, limit =
0xfffff, type 0x1b

=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A =
=3D DPL 0, pres 1, def32 1, gran 1

processor eflags=9A=9A=9A=9A=9A=9A=9A =3D interrupt enabled, resume, =
IOPL =3D 0

current process=9A=9A=9A=9A=9A=9A=9A=9A =3D 13 (swi1: net)

trap number=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A =3D 12

panic: page fault

Uptime: 9h24m41s

Dumping 2046 MB (2 chunks)

=9A chunk 0: 1MB (159 pages) ... ok

=9A chunk 1: 2046MB (523760 pages) 2030 2014 1998 1982 1966 1950 1934 =
1918 1902 1886 1870 1854 1838 1822 1

806 1790 1774 1758 1742 1726 1710 1694 1678 1662 1646 1630 1614 1598 =
1582 1566 1550 1534 1518 1502 1486

1470 1454 1438 1422 1406 1390 1374 1358 1342 1326 1310 1294 1278 1262 =
1246 1230 1214 1198 1182 1166 1150

=9A1134 1118 1102 1086 1070 1054 1038 1022 1006 990 974 958 942 926 910 =
894 878 862 846 830 814 798 782 76

6 750 734 718 702 686 670 654 638 622 606 590 574 558 542 526 510 494 =
478 462 446 430 414 398 382 366 35

0 334 318 302 286 270 254 238 222 206 190 174 158 142 126 110 94 78 62 =
46 30 14

=20

#0=9A doadump () at pcpu.h:165

165=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A=9A __asm __volatile("movl =
%%fs:0,%0" : "=3Dr" (td));

(kgdb) list *0xc055b4cc

0xc055b4cc is in m_copydata (libkern.h:56).

51=9A=9A=9A=9A=9A static __inline int imax(int a, int b) { return (a > b =
? a : b); }

52=9A=9A=9A=9A=9A static __inline int imin(int a, int b) { return (a < b =
? a : b); }

53=9A=9A=9A=9A=9A static __inline long lmax(long a, long b) { return (a =
> b ? a : b); }

54=9A=9A=9A=9A=9A static __inline long lmin(long a, long b) { return (a =
< b ? a : b); }

55=9A=9A=9A=9A=9A static __inline u_int max(u_int a, u_int b) { return =
(a > b ? a : b); }

56=9A=9A=9A=9A=9A static __inline u_int min(u_int a, u_int b) { return =
(a < b ? a : b); }

57=9A=9A=9A=9A=9A static __inline quad_t qmax(quad_t a, quad_t b) { =
return (a > b ? a : b); }

58=9A=9A=9A=9A=9A static __inline quad_t qmin(quad_t a, quad_t b) { =
return (a < b ? a : b); }

59=9A=9A=9A=9A=9A static __inline u_long ulmax(u_long a, u_long b) { =
return (a > b ? a : b); }

60=9A=9A=9A=9A=9A static __inline u_long ulmin(u_long a, u_long b) { =
return (a < b ? a : b); }

(kgdb) bt

#0=9A doadump () at pcpu.h:165

#1=9A 0xc0529c56 in boot (howto=3D260) at =
../../../kern/kern_shutdown.c:409

#2=9A 0xc0529f1c in panic (fmt=3D0xc06824a6 "%s") at =
../../../kern/kern_shutdown.c:565

#3=9A 0xc065bd26 in trap_fatal (frame=3D0xe4faa9e0, eva=3D12) at =
../../../i386/i386/trap.c:837

#4=9A 0xc065ba57 in trap_pfault (frame=3D0xe4faa9e0, usermode=3D0, =
eva=3D12) at ../../../i386/i386/trap.c:745

#5=9A 0xc065b671 in trap (frame=3D

=9A=9A=9A=9A=9A {tf_fs =3D 8, tf_es =3D 40, tf_ds =3D 40, tf_edi =3D 1, =
tf_esi =3D 0, tf_ebp =3D -453334484, tf_isp =3D -4533345

16, tf_ebx =3D -891044160, tf_edx =3D 0, tf_ecx =3D -891044192, tf_eax =
=3D 120, tf_trapno =3D 12, tf_err =3D 0, tf_e

ip =3D -1068124980, tf_cs =3D 32, tf_eflags =3D 590338, tf_esp =3D =
-891044160, tf_ss =3D -891044147})

=9A=9A=9A at ../../../i386/i386/trap.c:435

#6=9A 0xc064a5ea in calltrap () at ../../../i386/i386/exception.s:139

#7=9A 0xc055b4cc in m_copydata (m=3D0x0, off=3D0, len=3D1,

=9A=9A=9A cp=3D0xcae3becd "complete.\r\n227 Entering Passive Mode =
(212,119,184,110,138,178).\r\n200 PORT command

=9Asuccessful\r\n221 Goodbye.\r&#1047;\003") at =
../../../kern/uipc_mbuf.c:543

#8=9A 0xc044cd32 in ippr_ftp_process (fin=3D0xe4faab6c, =
nat=3D0xc744ac00, ftp=3D0xcae3be00, rv=3D1)

=9A=9A=9A at ip_ftp_pxy.c:1192

#9=9A 0xc044d076 in ippr_ftp_in (fin=3D0xe4faab6c, aps=3D0x78, =
nat=3D0xc744ac00) at ip_ftp_pxy.c:1358

#10 0xc045180d in appr_check (fin=3D0xe4faab6c, nat=3D0xc744ac00)

=9A=9A=9A at ../../../contrib/ipfilter/netinet/ip_proxy.c:540

#11 0xc044a559 in fr_natin (fin=3D0xe4faab6c, nat=3D0xc744ac00, =
natadd=3D1, nflags=3D1)

=9A=9A=9A at ../../../contrib/ipfilter/netinet/ip_nat.c:4105

#12 0xc044a42e in fr_checknatin (fin=3D0xe4faab6c, passp=3D0xe4faab68)

=9A=9A=9A at ../../../contrib/ipfilter/netinet/ip_nat.c:4040

#13 0xc043e705 in fr_check (ip=3D0xc7300030, hlen=3D20, ifp=3D0x78, =
out=3D0, mp=3D0xe4faac54)

=9A=9A=9A at ../../../contrib/ipfilter/netinet/fil.c:2466

#14 0xc0442af2 in fr_check_wrapper (arg=3D0x0, mp=3D0x0, =
ifp=3D0xc64a9800, dir=3D1)

=9A=9A=9A at ../../../contrib/ipfilter/netinet/ip_fil_freebsd.c:171

#15 0xc059b4b3 in pfil_run_hooks (ph=3D0xc07003e0, mp=3D0xe4faaca8, =
ifp=3D0xc64a9800, dir=3D1, inp=3D0x0)

=9A=9A=9A at ../../../net/pfil.c:139

#16 0xc05c4bdf in ip_input (m=3D0xc95a7300) at =
../../../netinet/ip_input.c:468

#17 0xc059a053 in netisr_processqueue (ni=3D0xc06ff398) at =
../../../net/netisr.c:236

#18 0xc059a24e in swi_net (dummy=3D0x0) at ../../../net/netisr.c:349

#19 0xc0515c05 in ithread_execute_handlers (p=3D0xc6384648, =
ie=3D0xc63ea100)

=9A=9A=9A at ../../../kern/kern_intr.c:682

#20 0xc0515d10 in ithread_loop (arg=3D0xc636e6f0) at =
../../../kern/kern_intr.c:765

#21 0xc0514bb4 in fork_exit (callout=3D0xc0515cbc <ithread_loop>, =
arg=3D0xc636e6f0, frame=3D0xe4faad38)

=9A=9A=9A at ../../../kern/kern_fork.c:821

#22 0xc064a64c in fork_trampoline () at =
../../../i386/i386/exception.s:208

>How-To-Repeat:

Problem appear in random, so I have no clue what exactly results panic.

>Fix:

=20

>Release-Note:

>Audit-Trail:

>Unformatted:

_______________________________________________

freebsd-i386@freebsd.org mailing list

http://lists.freebsd.org/mailman/listinfo/freebsd-i386

To unsubscribe, send any mail to "freebsd-i386-unsubscribe@freebsd.org"




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?838DB0534DD36F4EAF4793C7EC83DDFF21EC94>