Bug 230008 - [panic] [fdescfs] Page fault in vn_finished_write+0x13
Summary: [panic] [fdescfs] Page fault in vn_finished_write+0x13
Status: New
Alias: None
Product: Base System
Classification: Unclassified
Component: kern (show other bugs)
Version: CURRENT
Hardware: Any Any
: --- Affects Only Me
Assignee: freebsd-bugs mailing list
URL:
Keywords: panic
Depends on:
Blocks:
 
Reported: 2018-07-24 09:51 UTC by Peter Holm
Modified: 2018-08-09 17:02 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peter Holm freebsd_committer 2018-07-24 09:51:26 UTC
20180724 11:01:27 all (5/573): fdescfs.sh

Fatal trap 12: page fault while in kernel mode
cpuid = 2; apic id = 02
fault virtual address	= 0x70
fault code		= supervisor read data, page not present
instruction pointer	= 0x20:0xffffffff80c82943
stack pointer	        = 0x28:0xfffffe002e0f97b0
frame pointer	        = 0x28:0xfffffe002e0f97c0
code segment		= base rx0, limit 0xfffff, type 0x1b
			= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags	= interrupt enabled, resume, IOPL = 0
current process		= 76129 (ls)
[ thread pid 76129 tid 100138 ]
Stopped at      vn_finished_write+0x13: cmpq    $0,ll+0x4f(%rax)
db>

Details @ https://people.freebsd.org/~pho/stress/log/fdescfs-3.txt
Comment 1 Mark Johnston freebsd_committer 2018-08-09 17:02:16 UTC
Looks like this occurred because mp->mnt_op == NULL (though it's non-null in the kernel core).  MNTK_REFEXPIRE|MNTK_UNMOUNTF is set on the mount, so it seems this was a race with a free of the mountpoint.