Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 30 Jan 2001 11:20:34 +0100 (CET)
From:      Harti Brandt <brandt@fokus.gmd.de>
To:        Julian Elischer <julian@elischer.org>
Cc:        julian@freebsd.org, freebsd-net@freebsd.org, archie@freebsd.org
Subject:   Re: netgraph: problem in ng_base
Message-ID:  <Pine.BSF.4.21.0101301113380.390-100000@beagle.fokus.gmd.de>
In-Reply-To: <3A768232.282B28E6@elischer.org>

next in thread | previous in thread | raw e-mail | index | archive | help

Hi,

Just a bit more information: I just tried to run my PDP-11 simulator
while having loaded ng_ether from the previous tests. The simulator uses
the if_tap interface to emulate an ethernet interface to the PDP. Suddenly
the system crashed while doing an ifconfig. The crash occured in
ng_ether_output, because the node pointer in the interface structure was
NULL. It checked the sources of if_tap and ng_ether, but could not find,
how this was caused. So I tried to repeat the crash, but no luck. The
trace from the crashdump shows:

Script started on Tue Jan 30 11:16:48 2001
GNU gdb 4.18
Copyright 1998 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you ar=
e
welcome to change it and/or distribute copies of it under certain condition=
s.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "i386-unknown-freebsd"...
(no debugging symbols found)...
IdlePTD 3457024
initial pcb at 2a8f40
panicstr: from debugger
panic messages:
---
Fatal trap 12: page fault while in kernel mode
fault virtual address=09=3D 0x84
fault code=09=09=3D supervisor read, page not present
instruction pointer=09=3D 0x8:0xc311a66a
stack pointer=09        =3D 0x10:0xd7ac5d00
frame pointer=09        =3D 0x10:0xd7ac5d0c
code segment=09=09=3D base 0x0, limit 0xfffff, type 0x1b
=09=09=09=3D DPL 0, pres 1, def32 1, gran 1
processor eflags=09=3D interrupt enabled, resume, IOPL =3D 0
current process=09=09=3D 12341 (ifconfig)
panic: from debugger
panic: from debugger
Uptime: 17h16m42s

dumping to dev da0s1b, offset 1048736
dump 511 510 509 508 507 506 505 504 503 502 501 500 499 498 497 496 495 49=
4 493 492 491 490 489 488 487 486 485 484 483 482 481 480 479 478 477 476 4=
75 474 473 472 471 470 469 468 467 466 465 464 463 462 461 460 459 458 457 =
456 455 454 453 452 451 450 449 448 447 446 445 444 443 442 441 440 439 438=
 437 436 435 434 433 432 431 430 429 428 427 426 425 424 423 422 421 420 41=
9 418 417 416 415 414 413 412 411 410 409 408 407 406 405 404 403 402 401 4=
00 399 398 397 396 395 394 393 392 391 390 389 388 387 386 385 384 383 382 =
381 380 379 378 377 376 375 374 373 372 371 370 369 368 367 366 365 364 363=
 362 361 360 359 358 357 356 355 354 353 352 351 350 349 348 347 346 345 34=
4 343 342 341 340 339 338 337 336 335 334 333 332 331 330 329 328 327 326 3=
25 324 323 322 321 320 319 318 317 316 315 314 313 312 311 310 309 308 307 =
306 305 304 303 302 301 300 299 298 297 296 295 294 293 292 291 290 289 288=
 287 286 285 284 283 282 281 280 279 278 277 276 275 274 273 272 271 270 26=
9 268 267 266 265 264 263 262 261 260 259 258 257 256 255 254 253 252 251 2=
50 249 248 247 246 245 244 243 242 241 240 239 238 237 236 235 234 233 232 =
231 230 229 228 227 226 225 224 223 222 221 220 219 218 217 216 215 214 213=
 212 211 210 209 208 207 206 205 204 203 202 201 200 199 198 197 196 195 19=
4 193 192 191 190 189 188 187 186 185 184 183 182 181 180 179 178 177 176 1=
75 174 173 172 171 170 169 168 167 166 165 164 163 162 161 160 159 158 157 =
156 155 154 153 152 151 150 149 148 147 146 145 144 143 142 141 140 139 138=
 137 136 135 134 133 132 131 130 129 128 127 126 125 124 123 122 121 120 11=
9 118 117 116 115 114 113 112 111 110 109 108 107 106 105 104 103 102 101 1=
00 99 98 97 96 95 94 93 92 91 90 89 88 87 86 85 84 83 82 81 80 79 78 77 76 =
75 74 73 72 71 70 69 68 67 66 65 64 63 62 61 60 59 58 57 56 55 54 53 52 51 =
50 49 48 47 46 45 44 43 42 41 40 39 38 37 36 35 34 33 32 31 30 29 28 27 26 =
25 24 23 22 21 20 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0=20
---
#0  0xc0182102 in dumpsys ()
(kgdb) bt
#0  0xc0182102 in dumpsys ()
#1  0xc0181eef in boot ()
#2  0xc01822b9 in panic ()
#3  0xc012e455 in db_panic ()
#4  0xc012e3f5 in db_command ()
#5  0xc012e4ba in db_command_loop ()
#6  0xc0130687 in db_trap ()
#7  0xc020fca6 in kdb_trap ()
#8  0xc021bd08 in trap_fatal ()
#9  0xc021ba7d in trap_pfault ()
#10 0xc021b64b in trap ()
#11 0xc311a66a in ?? ()
#12 0xc01c57d8 in ether_output ()
#13 0xc01ca61b in arprequest ()
#14 0xc01cafff in arp_ifinit ()
#15 0xc01c5c8d in ether_ioctl ()
#16 0xc310eb1c in ?? ()
#17 0xc01cc3dd in in_ifinit ()
#18 0xc01cbf1d in in_control ()
#19 0xc01c4753 in ifioctl ()
#20 0xc0197c72 in soo_ioctl ()
#21 0xc0195082 in ioctl ()
#22 0xc021c14c in syscall2 ()
#23 0xc0210613 in Xint0x80_syscall ()
---Type <return> to continue, or q <return> to quit---
#24 0x80486dd in ?? ()
#25 0x8048135 in ?? ()
(kgdb)=20
Script done on Tue Jan 30 11:16:53 2001

Frame #11 was ng_ether_output in ddb.

But while trying to repeat the crash I suddenly discovered the following
in /var/log/messages:

Jan 30 11:05:56 beagle /boot/kernel/kernel: Accessing freed node node: ID [=
3]: type 'ether', 0 hooks, flags 0x9, 0 refs, :
Jan 30 11:05:56 beagle /boot/kernel/kernel: Last active @ /usr/src/sys/modu=
les/netgraph/netgraph/../../../netgraph/ng_base.c, line 2436
Jan 30 11:05:56 beagle /boot/kernel/kernel: problem discovered at file /usr=
/src/sys/modules/netgraph/ether/../../../netgraph/ng_ether.c, line 341
Jan 30 11:05:56 beagle /boot/kernel/kernel: Accessing freed node node: ID [=
3]: type 'ether', 0 hooks, flags 0x9, 0 refs, :
Jan 30 11:05:56 beagle /boot/kernel/kernel: Last active @ /usr/src/sys/modu=
les/netgraph/ether/../../../netgraph/ng_ether.c, line 341
Jan 30 11:05:56 beagle /boot/kernel/kernel: problem discovered at file /usr=
/src/sys/modules/netgraph/ether/../../../netgraph/ng_ether.c, line 344
Jan 30 11:05:56 beagle /boot/kernel/kernel: Accessing freed node node: ID [=
3]: type 'ether', 0 hooks, flags 0x9, 0 refs, :
Jan 30 11:05:56 beagle /boot/kernel/kernel: Last active @ /usr/src/sys/modu=
les/netgraph/ether/../../../netgraph/ng_ether.c, line 344
Jan 30 11:05:56 beagle /boot/kernel/kernel: problem discovered at file /usr=
/src/sys/modules/netgraph/ether/../../../netgraph/ng_ether.c, line 345

That looks exactly like my problem, so I assume it is not the sscop code.

harti



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-net" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0101301113380.390-100000>