Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 24 Apr 2015 16:01:51 -0700
From:      David Wolfskill <david@catwhisker.org>
To:        stable@freebsd.org
Cc:        wireless@freebsd.org
Subject:   stable/10 panic; _ieee80211_crypto_delkey() likely involved
Message-ID:  <20150424230151.GQ37361@albert.catwhisker.org>

next in thread | raw e-mail | index | archive | help

--HAv5+T9jbwMPl6Kw
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

I was reading some recent commits to stable/10 after just having issued
"service netif restart iwn0" in an effort to get wlan0 to re-associate,
and my laptop panicked:

Fri Apr 24 15:28:37 PDT 2015

FreeBSD localhost 10.1-STABLE FreeBSD 10.1-STABLE #46  r281921M/281927:1001=
512: Fri Apr 24 04:24:32 PDT 2015     root@g1-254.catwhisker.org:/common/S1=
/obj/usr/src/sys/CANARY  i386

panic: page fault
=2E..
Unread portion of the kernel message buffer:

Fatal trap 12: page fault while in kernel mode
cpuid =3D 5; apic id =3D 05
fault virtual address   =3D 0x18
fault code              =3D supervisor read, page not present
instruction pointer     =3D 0x20:0xc0bceff2
stack pointer           =3D 0x28:0xc650f754
frame pointer           =3D 0x28:0xc650f7a4
code segment            =3D base 0x0, limit 0xfffff, type 0x1b
                        =3D DPL 0, pres 1, def32 1, gran 1
processor eflags        =3D interrupt enabled, resume, IOPL =3D 0
current process         =3D 3493 (wpa_supplicant)
trap number             =3D 12
panic: page fault
cpuid =3D 5
KDB: stack backtrace:
#0 0xc0b1fd52 at kdb_backtrace+0x52
#1 0xc0ae13cf at panic+0x11f
#2 0xc0f65804 at trap_fatal+0x324
#3 0xc0f65b65 at trap_pfault+0x355
#4 0xc0f65224 at trap+0x674
#5 0xc0f5059c at calltrap+0x6
#6 0xc0bceede at ieee80211_crypto_delkey+0x1e
#7 0xc0be43a6 at ieee80211_ioctl_delkey+0x76
#8 0xc0be3115 at ieee80211_ioctl_set80211+0x585
#9 0xc0c0d8b1 at in_control+0x221
#10 0xc0bac060 at ifioctl+0x1460
#11 0xc0b40848 at soo_ioctl+0x2e8
#12 0xc0b38768 at kern_ioctl+0x258
#13 0xc0b3846c at sys_ioctl+0xec
#14 0xc0f662c6 at syscall+0x4a6
#15 0xc0f50631 at Xint0x80_syscall+0x21
Uptime: 7h2m17s
Physical memory: 3270 MB
=2E..
#0  doadump (textdump=3D-824728192) at pcpu.h:233
233     pcpu.h: No such file or directory.
        in pcpu.h
(kgdb) #0  doadump (textdump=3D-824728192) at pcpu.h:233
#1  0xc0ae103d in kern_reboot (howto=3D260)
    at /usr/src/sys/kern/kern_shutdown.c:452
#2  0xc0ae140d in panic (fmt=3D<value optimized out>)
    at /usr/src/sys/kern/kern_shutdown.c:759
#3  0xc0f65804 in trap_fatal (frame=3D<value optimized out>,=20
    eva=3D<value optimized out>) at /usr/src/sys/i386/i386/trap.c:1023
#4  0xc0f65b65 in trap_pfault (frame=3D0x0, usermode=3D<value optimized out=
>,=20
    eva=3D0) at /usr/src/sys/i386/i386/trap.c:835
#5  0xc0f65224 in trap (frame=3D0xc650f714) at /usr/src/sys/i386/i386/trap.=
c:532
#6  0xc0f5059c in calltrap () at /usr/src/sys/i386/i386/exception.s:170
#7  0xc0bceff2 in _ieee80211_crypto_delkey ()
    at /usr/src/sys/net80211/ieee80211_crypto.c:105
#8  0xc0bceede in ieee80211_crypto_delkey (vap=3D0xd46a0000, key=3D0xd46a06=
70)
    at /usr/src/sys/net80211/ieee80211_crypto.c:461
#9  0xc0be43a6 in ieee80211_ioctl_delkey (vap=3D0xd46a0000,=20
    ireq=3D<value optimized out>)
    at /usr/src/sys/net80211/ieee80211_ioctl.c:1252
#10 0xc0be3115 in ieee80211_ioctl_set80211 ()
    at /usr/src/sys/net80211/ieee80211_ioctl.c:2814
#11 0xc0c0d8b1 in in_control (so=3D<value optimized out>, cmd=3DCannot acce=
ss memory at address 0xfffffffb
)
    at /usr/src/sys/netinet/in.c:308
#12 0xc0bac060 in ifioctl (so=3D0xd46a0000, cmd=3D2149345770,=20
    data=3D<value optimized out>, td=3D<value optimized out>)
    at /usr/src/sys/net/if.c:2751
#13 0xc0b40848 in soo_ioctl (fp=3D0xd00fd348, cmd=3D<value optimized out>,=
=20
    data=3D0xc650fa40, active_cred=3D0xd000de80, td=3D0xd46a0000)
    at /usr/src/sys/kern/sys_socket.c:212
#14 0xc0b38768 in kern_ioctl (td=3D<value optimized out>,=20
    fd=3D<value optimized out>, com=3D<value optimized out>) at file.h:320
#15 0xc0b3846c in sys_ioctl (uap=3D<value optimized out>)
    at /usr/src/sys/kern/sys_generic.c:718
#16 0xc0f662c6 in syscall (frame=3D<value optimized out>) at subr_syscall.c=
:134
#17 0xc0f50631 in Xint0x80_syscall ()
    at /usr/src/sys/i386/i386/exception.s:270
#18 0x00000033 in ?? ()
Previous frame inner to this frame (corrupt stack?)
Current language:  auto; currently minimal
(kgdb)=20
=2E...

I have the crash dump & text dumps available, and can put the latter
up on my Web server for a bit if that would be useful.

Peace,
david
--=20
David H. Wolfskill				david@catwhisker.org
Those who murder in the name of God or prophet are blasphemous cowards.

See http://www.catwhisker.org/~david/publickey.gpg for my public key.

--HAv5+T9jbwMPl6Kw
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQJ8BAEBCgBmBQJVOstfXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ4RThEMDY4QTIxMjc1MDZFRDIzODYzRTc4
QTY3RjlDOERFRjQxOTNCAAoJEIpn+cje9Bk7t/gP+gJY5HKysFfTIaIPSv9yFDpP
ouRV0hcGn9uPTjtHaGqQGrI0gf+pX5JRydy8WVJ+MIIWb77ZyHTJkwnyEGScqDTZ
SL+escgptzxiABv/tRYzbuRu3gXQLXxrKAZpPgZCyNw7kWuCU3vpY+r9SnB2EokT
uq74JFo25biZlecTwzAyJQpST0+Xp78A7sQnWULulY3m3tq27mHtKAhQKWJg1Llp
iku9cLSLMW0IKIxUoyaRBRpDRUNRAskSl1qtFzlMGEOEvcAkXdCa3TMz03wabH4T
t0gvFW9B7lPUr0kprGDOohStIaXhF9H76z+0dF/ZG7G9b76GXIDnkykso+ArE6TB
UB+FryL32HHOigRG5285NG2YOhHE1lFPUEUVKZXa6E0jH1w829mjgL5AsccTC/zc
jO2t3F8WXV1uA31j2+okfiCG/tletUecTl+mmliMIaxJuDPvkA4C+LxNzf1SS/eo
e0NVjfwS++VUYexcQCBhLsAdDPqdodgMc8SW0JFgxWfGbl22OLIJgQnJVKrR8dIe
BY2JNTeIPQ3SAA57PkCaGG5Wa22OaLVLw54r2VQwBKcCogeXl3ch0OxkJo3uzu0/
FWC8ytZkw3U/nETlViB8BrclYcjAHLk1eIdqkZqov2Tq0xiHrAt8+CEwhTyLafzx
vsZfRZYA9v9wQ7s0IHS1
=aiiu
-----END PGP SIGNATURE-----

--HAv5+T9jbwMPl6Kw--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20150424230151.GQ37361>