From owner-freebsd-hackers@FreeBSD.ORG Fri Dec 18 17:29:41 2009 Return-Path: Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id C55FC106566B for ; Fri, 18 Dec 2009 17:29:41 +0000 (UTC) (envelope-from rwatson@freebsd.org) Received: from cyrus.watson.org (cyrus.watson.org [65.122.17.42]) by mx1.freebsd.org (Postfix) with ESMTP id 9DCEE8FC15 for ; Fri, 18 Dec 2009 17:29:41 +0000 (UTC) Received: from [192.168.2.102] (host86-146-40-97.range86-146.btcentralplus.com [86.146.40.97]) by cyrus.watson.org (Postfix) with ESMTPSA id C0DE446B03; Fri, 18 Dec 2009 12:29:40 -0500 (EST) Mime-Version: 1.0 (Apple Message framework v1077) Content-Type: text/plain; charset=us-ascii From: "Robert N. M. Watson" In-Reply-To: <237c27100912171025l3525da40m4abb526dd31ef067@mail.gmail.com> Date: Fri, 18 Dec 2009 17:29:38 +0000 Content-Transfer-Encoding: quoted-printable Message-Id: <9BE780E7-4114-43DF-BA5E-3517F2E28D21@freebsd.org> References: <237c27100912151140o1b227bb1pdaa65f5aee13ab5b@mail.gmail.com> <237c27100912171025l3525da40m4abb526dd31ef067@mail.gmail.com> To: Linda Messerschmidt X-Mailer: Apple Mail (2.1077) Cc: freebsd-hackers@freebsd.org Subject: Re: 8.0-RELEASE-p1 Panic "panic: sbdrop" X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 18 Dec 2009 17:29:41 -0000 On 17 Dec 2009, at 18:25, Linda Messerschmidt wrote: > On Wed, Dec 16, 2009 at 6:52 AM, Robert Watson = wrote: >> Could you tell us a bit more about the network configuration -- = especially, >> are you using any tunneling software (such as ipsec), netgraph, or = other >> less commonly used network features? Are you using accept filters? >=20 > Let's see, we are using a couple of simple PF rdr rules in conjunction > with squid and yes, we are using accf_http with it as well. Other > than that, nothing uncommon. >=20 > The ethernet is Intel onboard, em0 and em1. Web traffic comes in on > em0, gets redirected to squid, and origin server requests go out on > e1. It crashed under relatively light traffic, about 3000 requests > per minute. Is this something you might be able to reproduce on a non-production = system? Might you be able to test on 8.0 whether, without accf_http, the = problem goes away? (I'm not sure it makes life easier for you, but -- you should be able to = use an 8.0 kernel with a 7.x userspace, making the cost of rolling = forward/back to test things a bit easier perhaps) Thanks, Robert=