From owner-freebsd-bugs@freebsd.org Fri Apr 2 22:12:17 2021 Return-Path: Delivered-To: freebsd-bugs@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 8E0265B472E for ; Fri, 2 Apr 2021 22:12:17 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mailman.nyi.freebsd.org (mailman.nyi.freebsd.org [IPv6:2610:1c1:1:606c::50:13]) by mx1.freebsd.org (Postfix) with ESMTP id 4FBvRj3Dqtz4V9D for ; Fri, 2 Apr 2021 22:12:17 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: by mailman.nyi.freebsd.org (Postfix) id 6E0DC5B472D; Fri, 2 Apr 2021 22:12:17 +0000 (UTC) Delivered-To: bugs@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 6CA935B472C for ; Fri, 2 Apr 2021 22:12:17 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4FBvRj2K9Lz4Tyb for ; Fri, 2 Apr 2021 22:12:17 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 41708274D5 for ; Fri, 2 Apr 2021 22:12:17 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 132MCHer044645 for ; Fri, 2 Apr 2021 22:12:17 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 132MCH7t044644 for bugs@FreeBSD.org; Fri, 2 Apr 2021 22:12:17 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: bugs@FreeBSD.org Subject: [Bug 254725] 13.0-RC4 crash tcp_lro Date: Fri, 02 Apr 2021 22:12:17 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 13.0-STABLE X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: rscheff@freebsd.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: bugs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 02 Apr 2021 22:12:17 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D254725 --- Comment #10 from Richard Scheffenegger --- received the core and kernel.debug symbols. The panic is likely a off-by-one related to the FIN bit, but not with the rescue retransmission, but rather PRR. The TCP state indicates, that only the last data byte, and the final FIN bit are unacknowledged.=20 frame 11: (kgdb) p *tp->sackhint.nexthole $48 =3D {start =3D 935342315, end =3D 935342316, rxmit =3D 935342315, scbli= nk =3D {tqe_next =3D 0x0, tqe_prev =3D 0xfffffe013eac0618}} (kgdb) p tp->snd_max $49 =3D 935342317 (kgdb) p tp->snd_una $50 =3D 935342315 (kgdb) p/x tp->t_flags $6 =3D 0x603003f4 =3D=3D=3D=3D> TF_SENTFIN is set. Now, the FIN bit occupys the last Seq# (..317). The SACK hole should therefore be a valid 1 byte hole, which hasn't been retransmitted... The incoming SACK appears to be SACKing the FIN bit? (kgdb) p/x *(struct sackblk *)to.to_sacks $53 =3D {start =3D 0xec30c037, end =3D 0xed30c037} (kgdb) p 0x37c030ec $54 =3D 935342316 (kgdb) p 0x37c030ed $55 =3D 935342317 --=20 You are receiving this mail because: You are the assignee for the bug.=