FreeBSD Bugzilla – Attachment 152865 Details for
Bug 197535
[re] [panic] if_re (Realtek 8168) causes memory write after free and kernel panic
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
Dmesg and kernel panic on CURRENT
log11-1.1 (text/plain), 17.25 KB, created by
luca.pizzamiglio
on 2015-02-11 11:07:15 UTC
(
hide
)
Description:
Dmesg and kernel panic on CURRENT
Filename:
MIME Type:
Creator:
luca.pizzamiglio
Created:
2015-02-11 11:07:15 UTC
Size:
17.25 KB
patch
obsolete
>ifconfig re0 192 .168.205.177 netmask 255.255.255.0 ># Memory modified after free 0xfffff800036bf000(2048) val=ffffffff @ 0xfffff800036bf000 >Memory modified after free 0xfffff800036b5000(2048) val=ffffffff @ 0xfffff800036b5000 >Memory modified after free 0xfffff800036aa000(2048) val=ffffffff @ 0xfffff800036aa000 >Memory modified after free 0xfffff800036a0000(2048) val=ffffffff @ 0xfffff800036a0000 >Memory modified after free 0xfffff80003696000(2048) val=ffffffff @ 0xfffff80003696000 >Memory modified after free 0xfffff8000368c000(2048) val=ffffffff @ 0xfffff8000368c000 >Memory modified after free 0xfffff80003681000(2048) val=ffffffff @ 0xfffff80003681000 >Memory modified after free 0xfffff80003677000(2048) val=ffffffff @ 0xfffff80003677000 >Memory modified after free 0xfffff8000366d000(2048) val=ffffffff @ 0xfffff8000366d000 >Memory modified after free 0xfffff80003662000(2048) val=ffffffff @ 0xfffff80003662000 >Memory modified after free 0xfffff80003658000(2048) val=ffffffff @ 0xfffff80003658000 >Memory modified after free 0xfffff8000364e000(2048) val=ffffffff @ 0xfffff8000364e000 > ># dmesg >Copyright (c) 1992-2015 The FreeBSD Project. >Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 > The Regents of the University of California. All rights reserved. >FreeBSD is a registered trademark of The FreeBSD Foundation. >FreeBSD 11.0-CURRENT #0 r278031: Sun Feb 1 18:24:33 UTC 2015 > root@releng2.nyi.freebsd.org:/usr/obj/usr/src/sys/GENERIC amd64 >FreeBSD clang version 3.5.1 (tags/RELEASE_351/final 225668) 20150115 >WARNING: WITNESS option enabled, expect reduced performance. >VT: running with driver "efifb". >CPU: Intel(R) Atom(TM) CPU E3825 @ 1.33GHz (1333.37-MHz K8-class CPU) > Origin="GenuineIntel" Id=0x30673 Family=0x6 Model=0x37 Stepping=3 > Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE> > Features2=0x43d8e3bf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,SSE4.1,SSE4.2,MOVBE,POPCNT,TSCDLT,AESNI,RDRAND> > AMD Features=0x28100800<SYSCALL,NX,RDTSCP,LM> > AMD Features2=0x101<LAHF,Prefetch> > Structured Extended Features=0x2282<TSCADJ,SMEP,ERMS> > VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID > TSC: P-state invariant, performance statistics >real memory = 2063597568 (1968 MB) >avail memory = 1947123712 (1856 MB) >Event timer "LAPIC" quality 600 >ACPI APIC Table: <INTEL EDK2 > >FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs >FreeBSD/SMP: 1 package(s) x 2 core(s) > cpu0 (BSP): APIC ID: 0 > cpu1 (AP): APIC ID: 4 >ioapic0: Changing APIC ID to 2 >ioapic0 <Version 2.0> irqs 0-86 on motherboard >random: entropy device infrastructure driver >random: selecting highest priority adaptor <Dummy> >kbd0 at kbdmux0 >netmap: loaded module >random: SOFT: yarrow init() >random: selecting highest priority adaptor <Yarrow> >module_register_init: MOD_LOAD (vesa, 0xffffffff80dd85a0, 0) error 19 >random: live provider: "Intel Secure Key RNG" >acpi0: <INTEL EDK2> on motherboard >acpi0: Power Button (fixed) >unknown: I/O range not supported >cpu0: <ACPI CPU> on acpi0 >cpu0: invalid _CST package >cpu1: <ACPI CPU> on acpi0 >atrtc0: <AT realtime clock> port 0x70-0x77 on acpi0 >atrtc0: Warning: Couldn't map I/O. >Event timer "RTC" frequency 32768 Hz quality 0 >hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff irq 8 on acpi0 >Timecounter "HPET" frequency 14318180 Hz quality 950 >Event timer "HPET" frequency 14318180 Hz quality 450 >Event timer "HPET1" frequency 14318180 Hz quality 440 >Event timer "HPET2" frequency 14318180 Hz quality 440 >attimer0: <AT timer> port 0x40-0x43,0x50-0x53 irq 0 on acpi0 >Timecounter "i8254" frequency 1193182 Hz quality 0 >Event timer "i8254" frequency 1193182 Hz quality 100 >Timecounter "ACPI-safe" frequency 3579545 Hz quality 850 >acpi_timer0: <24-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0 >pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0 >pcib0: Length mismatch for 3 range: 108fffff vs 10900000 >pci0: <ACPI PCI bus> on pcib0 >vgapci0: <VGA-compatible display> port 0x2050-0x2057 mem 0x90000000-0x903fffff,0x80000000-0x8fffffff at device 2.0 on pci0 >vgapci0: Boot video device >xhci0: <Intel Intel BayTrail USB 3.0 controller> mem 0x90800000-0x9080ffff at device 20.0 on pci0 >xhci0: 32 bytes context size, 64-bit DMA >xhci0: Port routing mask set to 0xffffffff >usbus0 on xhci0 >pci0: <encrypt/decrypt> at device 26.0 (no driver attached) >hdac0: <Intel BayTrail HDA Controller> mem 0x90810000-0x90813fff at device 27.0 on pci0 >pcib1: <ACPI PCI-PCI bridge> at device 28.0 on pci0 >pci1: <ACPI PCI bus> on pcib1 >pcib2: <ACPI PCI-PCI bridge> at device 28.2 on pci0 >pci2: <ACPI PCI bus> on pcib2 >re0: <RealTek 8168/8111 B/C/CP/D/DP/E/F/G PCIe Gigabit Ethernet> port 0x1000-0x10ff mem 0x90500000-0x90500fff,0x90400000-0x90403fff at device 0.0 on pci2 >re0: Using 1 MSI-X message >re0: turning off MSI enable bit. >re0: ASPM disabled >re0: Chip rev. 0x4c000000 >re0: MAC rev. 0x00000000 >miibus0: <MII bus> on re0 >rgephy0: <RTL8251 1000BASE-T media interface> PHY 1 on miibus0 >rgephy0: none, 10baseT, 10baseT-FDX, 10baseT-FDX-flow, 100baseTX, 100baseTX-FDX, 100baseTX-FDX-flow, 1000baseT-FDX, 1000baseT-FDX-master, 1000baseT-FDX-flow, 1000baseT-FDX-flow-master, auto, auto-flow >re0: Using defaults for TSO: 65518/35/2048 >re0: Ethernet address: 00:13:20:fe:31:db >001.000045 [2718] netmap_attach success for re0 tx 1/256 rx 1/256 queues/slots >pcib3: <ACPI PCI-PCI bridge> at device 28.3 on pci0 >pci3: <ACPI PCI bus> on pcib3 >isab0: <PCI-ISA bridge> at device 31.0 on pci0 >isa0: <ISA bus> on isab0 >acpi_button0: <Power Button> on acpi0 >acpi_button1: <Sleep Button> on acpi0 >acpi_tz0: <Thermal Zone> on acpi0 >uart0: <16550 or compatible> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0 >uart0: console (115200,n,8,1) >ppc0: cannot reserve I/O port range >est0: <Enhanced SpeedStep Frequency Control> on cpu0 >est1: <Enhanced SpeedStep Frequency Control> on cpu1 >Timecounters tick every 1.000 msec >hdacc0: <Intel (0x2882) HDA CODEC> at cad 2 on hdac0 >hdaa0: <Intel (0x2882) Audio Function Group> at nid 1 on hdacc0 >pcm0: <Intel (0x2882) (HDMI/DP 8ch)> at nid 4 on hdaa0 >pcm1: <Intel (0x2882) (HDMI/DP 8ch)> at nid 5 on hdaa0 >usbus0: 5.0Gbps Super Speed USB v3.0 >uma_zalloc_arg: zone "64" with the following non-sleepable locks held: >exclusive sleep mutex vtdev (vtdev) r = 0 (0xffffffff814c7660) locked @ /usr/src/sys/dev/vt/vt_core.c:2545 >KDB: stack backtrace: >db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xffffffff81bf7a40 >witness_warn() at witness_warn+0x4ae/frame 0xffffffff81bf7b10 >uma_zalloc_arg() at uma_zalloc_arg+0x3b/frame 0xffffffff81bf7b80 >malloc() at malloc+0x192/frame 0xffffffff81bf7bd0 >eventhandler_register() at eventhandler_register+0x34/frame 0xffffffff81bf7c10 >vt_upgrade() at vt_upgrade+0x43e/frame 0xffffffff81bf7c90 >mi_startup() at mi_startup+0x118/frame 0xffffffff81bf7cb0 >btext() at btext+0x2c >uma_zalloc_arg: zone "128" with the following non-sleepable locks held: >exclusive sleep mutex vtdev (vtdev) r = 0 (0xffffffff814c7660) locked @ /usr/src/sys/dev/vt/vt_core.c:2545 >KDB: stack backtrace: >db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xffffffff81bf7a40 >witness_warn() at witness_warn+0x4ae/frame 0xffffffff81bf7b10 >uma_zalloc_arg() at uma_zalloc_arg+0x3b/frame 0xffffffff81bf7b80 >malloc() at malloc+0x192/frame 0xffffffff81bf7bd0 >eventhandler_register() at eventhandler_register+0x104/frame 0xffffffff81bf7c10 >vt_upgrade() at vt_upgrade+0x43e/frame 0xffffffff81bf7c90 >mi_startup() at mi_startup+0x118/frame 0xffffffff81bf7cb0 >btext() at btext+0x2c >uma_zalloc_arg: zone "64" with the following non-sleepable locks held: >exclusive sleep mutex vtdev (vtdev) r = 0 (0xffffffff814c7660) locked @ /usr/src/sys/dev/vt/vt_core.c:2545 >KDB: stack backtrace: >db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xffffffff81bf7a40 >witness_warn() at witness_warn+0x4ae/frame 0xffffffff81bf7b10 >uma_zalloc_arg() at uma_zalloc_arg+0x3b/frame 0xffffffff81bf7b80 >malloc() at malloc+0x192/frame 0xffffffff81bf7bd0 >eventhandler_register() at eventhandler_register+0x34/frame 0xffffffff81bf7c10 >vt_upgrade() at vt_upgrade+0x45c/frame 0xffffffff81bf7c90 >mi_startup() at mi_startup+0x118/frame 0xffffffff81bf7cb0 >btext() at btext+0x2c >random: unblocking device. >SMP: AP CPU #1 Launched! >Timecounter "TSC" frequency 1333366220 Hz quality 1000 >WARNING: WITNESS option enabled, expect reduced performance. >Root mount waiting for: usbus0 >ugen0.1: <0x8086> at usbus0 >uhub0: <0x8086 XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus0 >uhub0: 7 ports with 7 removable, self powered >Root mount waiting for: usbus0 >ugen0.2: <vendor 0x046a> at usbus0 >ukbd0: <vendor 0x046a product 0x0021, class 0/0, rev 2.00/0.20, addr 1> on usbus0 >kbd1 at ukbd0 >Root mount waiting for: usbus0 >ugen0.3: <vendor 0x13fe> at usbus0 >umass0: <vendor 0x13fe USB DISK 2.0, class 0/0, rev 2.00/1.00, addr 2> on usbus0 >umass0: SCSI over Bulk-Only; quirks = 0x0100 >umass0:0:0: Attached to scbus0 >Trying to mount root from ufs:/dev/ufs/FreeBSD_Install [ro,noatime]... >da0 at umass-sim0 bus 0 scbus0 target 0 lun 0 >mountroot: waiting for device /dev/ufs/FreeBSD_Install ... >da0: < USB DISK 2.0 PMAP> Removable Direct Access SCSI-6 device >da0: Serial Number 070744256B05D247 >da0: 40.000MB/s transfers >da0: 3824MB (7831552 512 byte sectors: 255H 63S/T 487C) >da0: quirks=0x3<NO_SYNC_CACHE,NO_6_BYTE> >GEOM: da0: the secondary GPT header is not in the last LBA. >GEOM: diskid/DISK-070744256B05D247: the secondary GPT header is not in the last LBA. >GEOM: diskid/DISK-070744256B05D247: the secondary GPT header is not in the last LBA. >GEOM: diskid/DISK-070744256B05D247: the secondary GPT header is not in the last LBA. >uhid0: <vendor 0x046a product 0x0021, class 0/0, rev 2.00/0.20, addr 1> on usbus0 >re0: link state changed to DOWN >re0: link state changed to UP >Memory modified after free 0xfffff800036bf000(2048) val=ffffffff @ 0xfffff800036bf000 >Memory modified after free 0xfffff800036b5000(2048) val=ffffffff @ 0xfffff800036b5000 >Memory modified after free 0xfffff800036aa000(2048) val=ffffffff @ 0xfffff800036aa000 >Memory modified after free 0xfffff800036a0000(2048) val=ffffffff @ 0xfffff800036a0000 >Memory modified after free 0xfffff80003696000(2048) val=ffffffff @ 0xfffff80003696000 >Memory modified after free 0xfffff8000368c000(2048) val=ffffffff @ 0xfffff8000368c000 >Memory modified after free 0xfffff80003681000(2048) val=ffffffff @ 0xfffff80003681000 >Memory modified after free 0xfffff80003677000(2048) val=ffffffff @ 0xfffff80003677000 >Memory modified after free 0xfffff8000366d000(2048) val=ffffffff @ 0xfffff8000366d000 >Memory modified after free 0xfffff80003662000(2048) val=ffffffff @ 0xfffff80003662000 >Memory modified after free 0xfffff80003658000(2048) val=ffffffff @ 0xfffff80003658000 >Memory modified after free 0xfffff8000364e000(2048) val=ffffffff @ 0xfffff8000364e000 ># ping 192.168.205.30 >capability mode sandbox enabled >PING 192.168.205.30 (192.168.205.30): 56 data bytes >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >ping: sendto: Host is down >kernel trap 12 with interrupts disabled > > >Fatal trap 12: page fault while in kernel mode >cpuid = 0; apic id = 00 >fault virtual address = 0xfffffe008f488d28 >fault code = supervisor read data, page not present >instruction pointer = 0x20:0xffffffff80d46a3d >stack pointer = 0x28:0xfffffe0075be59d0 >frame pointer = 0x28:0xfffffe0075be5a40 >code segment = base 0x0, limit 0xfffff, type 0x1b > = DPL 0, pres 1, long 1, def32 0, gran 1 >processor eflags = resume, IOPL = 0 >current process = 11 (idle: cpu0) >[ thread pid 11 tid 100003 ] >Stopped at ctx_switch_xsave+0x22: movq 0x68(%r8),%rcx >db> bt >Tracing pid 11 tid 100003 td 0xfffff8000286a000 >ctx_switch_xsave() at ctx_switch_xsave+0x22/frame 0xfffffe0075be5a40 >mi_switch() at mi_switch+0x179/frame 0xfffffe0075be5a80 >critical_exit() at critical_exit+0x8b/frame 0xfffffe0075be5aa0 >sched_idletd() at sched_idletd+0x4e0/frame 0xfffffe0075be5bb0 >fork_exit() at fork_exit+0x84/frame 0xfffffe0075be5bf0 >fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0075be5bf0 >--- trap 0, rip = 0, rsp = 0xfffffe0075be5cb0, rbp = 0 --- >No such command >db> show reg >cs 0x20 >ds 0x3b >es 0x3b003b >fs 0x8f488d28001b0013 >gs 0xfe008f488d28001b >ss 0x28 >rax 0xffffffff8097462d sched_switch+0x4cd >rcx 0xfffff80002adc910 >rdx 0xffffffff81642c00 tdq_cpu >rbx 0x384e0 >rsp 0xfffffe0075be59d0 >rbp 0xfffffe0075be5a40 >rsi 0xfffff80002adc4a0 >rdi 0xfffff8000286a000 >r8 0xfffffe008f488cc0 >r9 0x2710 >r10 0xffffffff81642c00 tdq_cpu >r11 0 >r12 0xffffffff81642c18 tdq_cpu+0x18 >r13 0 >--More---- >r14 0xfffff80002adc4a0 >r15 0xfffff8000286a000 >rip 0xffffffff80d46a3d ctx_switch_xsave+0x22 >rflags 0x10007 >ctx_switch_xsave+0x22: movq 0x68(%r8),%rcx >db> >panic >panic: from debugger >cpuid = 0 >KDB: stack backtrace: >db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xfffffe0075be5320 >vpanic() at vpanic+0x189/frame 0xfffffe0075be53a0 >panic() at panic+0x43/frame 0xfffffe0075be5400 >db_panic() at db_panic+0x17/frame 0xfffffe0075be5410 >db_command() at db_command+0x27c/frame 0xfffffe0075be54d0 >db_command_loop() at db_command_loop+0x64/frame 0xfffffe0075be54e0 >db_trap() at db_trap+0xe0/frame 0xfffffe0075be5570 >kdb_trap() at kdb_trap+0x18e/frame 0xfffffe0075be5600 >trap_fatal() at trap_fatal+0x339/frame 0xfffffe0075be5660 >trap_pfault() at trap_pfault+0x241/frame 0xfffffe0075be5700 >trap() at trap+0x4b2/frame 0xfffffe0075be5910 >calltrap() at calltrap+0x8/frame 0xfffffe0075be5910 >--- trap 0xc, rip = 0xffffffff80d46a3d, rsp = 0xfffffe0075be59d0, rbp = 0xfffffe0075be5a40 --- >ctx_switch_xsave() at ctx_switch_xsave+0x22/frame 0xfffffe0075be5a40 >mi_switch() at mi_switch+0x179/frame 0xfffffe0075be5a80 >critical_exit() at critical_exit+0x8b/frame 0xfffffe0075be5aa0 >sched_idletd() at sched_idletd+0x4e0/frame 0xfffffe0075be5bb0 >fork_exit() at fork_exit+0x84/frame 0xfffffe0075be5bf0 >fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0075be5bf0 >--- trap 0, rip = 0, rsp = 0xfffffe0075be5cb0, rbp = 0 --- >Uptime: 3m51s >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 197535
: 152865 |
152866
|
152990
|
153780