From owner-freebsd-bugs@FreeBSD.ORG Fri Apr 27 14:30:06 2007 Return-Path: X-Original-To: freebsd-bugs@hub.freebsd.org Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 4770E16A401 for ; Fri, 27 Apr 2007 14:30:06 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [69.147.83.40]) by mx1.freebsd.org (Postfix) with ESMTP id 2867713C4AE for ; Fri, 27 Apr 2007 14:30:06 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id l3REU6rk046729 for ; Fri, 27 Apr 2007 14:30:06 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id l3REU6ko046728; Fri, 27 Apr 2007 14:30:06 GMT (envelope-from gnats) Resent-Date: Fri, 27 Apr 2007 14:30:06 GMT Resent-Message-Id: <200704271430.l3REU6ko046728@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, John Pineau Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 2650D16A408 for ; Fri, 27 Apr 2007 14:29:35 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [69.147.83.33]) by mx1.freebsd.org (Postfix) with ESMTP id 0D6B513C480 for ; Fri, 27 Apr 2007 14:29:35 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.13.1/8.13.1) with ESMTP id l3RETYtu018909 for ; Fri, 27 Apr 2007 14:29:35 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.13.1/8.13.1/Submit) id l3REOWYh008845; Fri, 27 Apr 2007 14:24:32 GMT (envelope-from nobody) Message-Id: <200704271424.l3REOWYh008845@www.freebsd.org> Date: Fri, 27 Apr 2007 14:24:32 GMT From: John Pineau To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.0 Cc: Subject: kern/112182: Kernel Panic on HP DL320-G5 Running 62-STABLE X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 27 Apr 2007 14:30:06 -0000 >Number: 112182 >Category: kern >Synopsis: Kernel Panic on HP DL320-G5 Running 62-STABLE >Confidential: no >Severity: critical >Priority: high >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Fri Apr 27 14:30:05 GMT 2007 >Closed-Date: >Last-Modified: >Originator: John Pineau >Release: 62-STABLE >Organization: LinearLogic >Environment: FreeBSD mailproxy1.linearlogic.com 6.2-RELEASE FreeBSD 6.2-RELEASE #0: Fri Jan 12 08:43:30 UTC 2007 root@portnoy.cse.buffalo.edu:/usr/obj/usr/src/sys/SMP amd64 (Minimum working kernel) >Description: Attached is debug output using 6.2-STABLE. I'm not a programmer, but it looks like its happening in the bge driver (to me at least). Hardware is an HP DL320-G5. This has been reproduced in 6.2-STABLE using both GENERIC and SMP, AMD64 and i386. 6.2-RELEASE has no issue on any architecture. Any assistance would be appreciated. >How-To-Repeat: Compile 62-STABLE from 62-RELEASE on DL320-G5. i386 and AMD64 tested, SMP and GENERIC >Fix: Patch attached with submission follows: Script started on Thu Apr 26 12:05:38 2007 mailproxy1# ls bounds kernel.debug.0 typescript info.0 minfree vmcore.0 mailproxy1# lslskgdb kernel.debug.0 vmcore.0 kgdb: kvm_nlist(_stopped_cpus): kgdb: kvm_nlist(_stoppcbs): [GDB will not be able to debug user-mode threads: /usr/lib/libthread_db.so: Undefined symbol "ps_pglobal_lookup"] GNU gdb 6.1.1 [FreeBSD] Copyright 2004 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "amd64-marcel-freebsd". Unread portion of the kernel message buffer: <5>bge0: link state changed to UP <2>NMI ISA a0, EISA ff <2>RAM parity error, likely hardware failure. Fatal trap 19: non-maskable interrupt trap while in kernel mode instruction pointer = 0x8:0xffffffff802614c3 stack pointer = 0x10:0xffffffffb40f8930 frame pointer = 0x10:0xffffffff86a95000 code segment = base 0x0, limit 0xfffff, type 0x1b = DPL 0, pres 1, long 1, def32 0, gran 1 processor eflags = interrupt enabled, IOPL = 0 current process = 473 (devd) trap number = 19 panic: non-maskable interrupt trap Uptime: 4s Dumping 2046 MB (2 chunks) chunk 0: 1MB (159 pages) ... ok chunk 1: 2046MB (523624 pages) 2030 2014 1998 1982 1966 1950 1934 1918 1902 1886 1870 1854 1838 1822 1806 1790 1774 1758 1742 1726 1710 1694 1678 1662 1646 1630 1614 1598 1582 1566 1550 1534 1518 1502 1486 1470 1454 1438 1422 1406 1390 1374 1358 1342 1326 1310 1294 1278 1262 1246 1230 1214 1198 1182 1166 1150 1134 1118 1102 1086 1070 1054 1038 1022 1006 990 974 958 942 926 910 894 878 862 846 830 814 798 782 766 750 734 718 702 686 670 654 638 622 606 590 574 558 542 526 510 494 478 462 446 430 414 398 382 366 350 334 318 302 286 270 254 238 222 206 190 174 158 142 126 110 94 78 62 46 30 14 #0 doadump () at pcpu.h:172 172 pcpu.h: No such file or directory. in pcpu.h (kgdb) where #0 doadump () at pcpu.h:172 #1 0x0000000000000004 in ?? () #2 0xffffffff80412b33 in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:409 #3 0xffffffff80413136 in panic (fmt=0xffffff0061cc5be0 "X\223è`") at /usr/src/sys/kern/kern_shutdown.c:565 #4 0xffffffff806314b1 in trap_fatal (frame=0xffffff0061cc5be0, eva=18446742975823778648) at /usr/src/sys/amd64/amd64/trap.c:668 #5 0xffffffff806319a2 in trap (frame= {tf_rdi = -1095250280448, tf_rsi = 1, tf_rdx = 25, tf_rcx = 4026531840, tf_r8 = 0, tf_r9 = 26, tf_rax = 0, tf_rbx = 4294967295, tf_rbp = -2035724288, tf_r10 = 1, tf_r11 = -2144988016, tf_r12 = 25, tf_r13 = 1, tf_r14 = 0, tf_r15 = -1097858598496, tf_trapno = 19, tf_addr = 0, tf_flags = -1097858211840, tf_err = 0, tf_rip = -2144987965, tf_cs = 8, tf_rflags = 514, tf_rsp = -1274050240, tf_ss = 16}) at /usr/src/sys/amd64/amd64/trap.c:470 #6 0xffffffff8061c968 in nmi_calltrap () at /usr/src/sys/amd64/amd64/exception.S:366 #7 0xffffff00fdff0000 in ?? () #8 0x0000000000000001 in ?? () #9 0x0000000000000019 in ?? () #10 0x00000000f0000000 in ?? () #11 0x0000000000000000 in ?? () #12 0x000000000000001a in ?? () ---Type to continue, or q to quit---   #13 0x0000000000000000 in ?? () #14 0x00000000ffffffff in ?? () #15 0xffffffff86a95000 in ?? () #16 0x0000000000000001 in ?? () #17 0xffffffff80261490 in bge_read_eeprom () at /usr/src/sys/dev/bge/if_bge.c:542 #18 0x0000000000000019 in ?? () #19 0x0000000000000001 in ?? () #20 0x0000000000000000 in ?? () #21 0xffffff00628739a0 in ?? () #22 0x0000000000000013 in ?? () #23 0x0000000000000000 in ?? () #24 0xffffff00628d2000 in ?? () #25 0x0000000000000000 in ?? () #26 0xffffffff802614c3 in bge_miibus_readreg (dev=0x0, phy=0, reg=25) at bus.h:241 #27 0x0000000000000010 in ?? () #28 0xffffff007b857200 in ?? () #29 0xffffff0000dd1500 in ?? () #30 0xffffff007b874e00 in ?? () #31 0xffffffff802e7655 in brgphy_service (sc=0xffffffffb40f8940, mii=0xffffff007b857200, cmd=3) at miibus_if.h:25 #32 0xffffffff802ecf3e in mii_pollstat (mii=0xffffff007b857200) ---Type to continue, or q to quit--- at /usr/src/sys/dev/mii/mii.c:389 #33 0xffffffff8026445c in bge_ifmedia_sts (ifp=0x0, ifmr=0xffffff005fec0840) at /usr/src/sys/dev/bge/if_bge.c:3750 #34 0xffffffff8049c43e in ifmedia_ioctl (ifp=0x0, ifr=0xffffff005fec0840, ifm=0xffffff007b857200, cmd=0) at /usr/src/sys/net/if_media.c:281 #35 0xffffffff8026692d in bge_ioctl (ifp=0xffffff0000001800, command=3224398136, data=0xffffff005fec0840 "bge0") at /usr/src/sys/dev/bge/if_bge.c:3823 #36 0xffffffff804963d7 in ifhwioctl (cmd=3224398136, ifp=0xffffff0000001800, data=0xffffff005fec0840 "bge0", td=0x0) at /usr/src/sys/net/if.c:1502 #37 0xffffffff80496dfc in ifioctl (so=0xffffff00628739a0, cmd=3224398136, data=0xffffff005fec0840 "bge0", td=0xffffff0061cc5be0) at /usr/src/sys/net/if.c:1559 #38 0xffffffff80443686 in soo_ioctl (fp=0x0, cmd=3224398136, data=0xffffff005fec0840, active_cred=0x0, td=0xffffff0061cc5be0) at /usr/src/sys/kern/sys_socket.c:214 #39 0xffffffff8043ca0b in ioctl (td=0xffffff0061cc5be0, uap=0xffffffffb40f8bc0) at file.h:265 #40 0xffffffff80632311 in syscall (frame= {tf_rdi = 5, tf_rsi = 3224398136, tf_rdx = 140737488349312, tf_rcx = 140737488349328, tf_r8 = -1098981901144, tf_r9 = 140737488349272, tf_rax = 54, tf_rbx = 140737488349312, tf_rbp = 5, tf_r10 = 0, tf_r11 = 0, tf_r12 = 0, tf_r13 = 5681856, tf_r14 = 140737488349376, tf_r15 = 140737488349360, tf_trapno = 12, tf_add---Type to continue, or q to quit--- r = 5681180, tf_flags = 12, tf_err = 2, tf_rip = 4400972, tf_cs = 43, tf_rflags = 582, tf_rsp = 140737488349272, tf_ss = 35}) at /usr/src/sys/amd64/amd64/trap.c:803 #41 0xffffffff8061c818 in Xfast_syscall () at /usr/src/sys/amd64/amd64/exception.S:270 #42 0x000000000043274c in ?? () Previous frame inner to this frame (corrupt stack?) (kgdb) cat     q mailproxy1# cauname -a FreeBSD mailproxy1.linearlogic.com 6.2-RELEASE FreeBSD 6.2-RELEASE #0: Fri Jan 12 08:43:30 UTC 2007 root@portnoy.cse.buffalo.edu:/usr/obj/usr/src/sys/SMP amd64 mailproxy1# cat /etcvar/log/debug.log dmedmsesg Copyright (c) 1992-2007 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD is a registered trademark of The FreeBSD Foundation. FreeBSD 6.2-RELEASE #0: Fri Jan 12 08:43:30 UTC 2007 root@portnoy.cse.buffalo.edu:/usr/obj/usr/src/sys/SMP ACPI APIC Table: Timecounter "i8254" frequency 1193182 Hz quality 0 CPU: Intel(R) Xeon(R) CPU 3040 @ 1.86GHz (1866.75-MHz K8-class CPU) Origin = "GenuineIntel" Id = 0x6f2 Stepping = 2 Features=0xbfebfbff Features2=0xe3bd,CX16,,> AMD Features=0x20000800 AMD Features2=0x1 Cores per package: 2 real memory = 2145812480 (2046 MB) avail memory = 2060406784 (1964 MB) FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs cpu0 (BSP): APIC ID: 0 cpu1 (AP): APIC ID: 1 ioapic0 irqs 0-23 on motherboard kbd1 at kbdmux0 ath_hal: 0.9.17.2 (AR5210, AR5211, AR5212, RF5111, RF5112, RF2413, RF5413) acpi0: on motherboard acpi0: Power Button (fixed) Timecounter "ACPI-fast" frequency 3579545 Hz quality 1000 acpi_timer0: <24-bit timer at 3.579545MHz> port 0x908-0x90b on acpi0 cpu0: on acpi0 acpi_perf0: on cpu0 cpu1: on acpi0 pcib0: on acpi0 pci0: on pcib0 pcib1: at device 1.0 on pci0 pci10: on pcib1 pcib2: at device 28.0 on pci0 pci2: on pcib2 pcib3: at device 0.0 on pci2 pci3: on pcib3 bge0: mem 0xfdff0000-0xfdffffff,0xfdfe0000-0xfdfeffff irq 16 at device 4.0 on pci3 miibus0: on bge0 brgphy0: on miibus0 brgphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseTX, 1000baseTX-FDX, auto bge0: Ethernet address: 00:1b:78:06:1c:ba bge1: mem 0xfdfd0000-0xfdfdffff,0xfdfc0000-0xfdfcffff irq 17 at device 4.1 on pci3 miibus1: on bge1 brgphy1: on miibus1 brgphy1: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseTX, 1000baseTX-FDX, auto bge1: Ethernet address: 00:1b:78:06:1c:bb pcib4: at device 8.0 on pci3 pci4: on pcib4 pcib5: at device 28.4 on pci0 pci7: on pcib5 pcib6: at device 28.5 on pci0 uhci0: port 0x1000-0x101f irq 21 at device 29.0 on pci0 uhci0: [GIANT-LOCKED] usb0: on uhci0 usb0: USB revision 1.0 uhub0: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub0: 2 ports with 2 removable, self powered uhci1: port 0x1020-0x103f irq 21 at device 29.1 on pci0 uhci1: [GIANT-LOCKED] usb1: on uhci1 usb1: USB revision 1.0 uhub1: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub1: 2 ports with 2 removable, self powered uhci2: port 0x1040-0x105f irq 21 at device 29.2 on pci0 uhci2: [GIANT-LOCKED] usb2: on uhci2 usb2: USB revision 1.0 uhub2: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub2: 2 ports with 2 removable, self powered uhci3: port 0x1060-0x107f irq 21 at device 29.3 on pci0 uhci3: [GIANT-LOCKED] usb3: on uhci3 usb3: USB revision 1.0 uhub3: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub3: 2 ports with 2 removable, self powered ehci0: mem 0xfdcf0000-0xfdcf03ff irq 21 at device 29.7 on pci0 ehci0: [GIANT-LOCKED] usb4: waiting for BIOS to give up control usb4: EHCI version 1.0 usb4: companion controllers, 2 ports each: usb0 usb1 usb2 usb3 usb4: on ehci0 usb4: USB revision 2.0 uhub4: Intel EHCI root hub, class 9/0, rev 2.00/1.00, addr 1 uhub4: 8 ports with 8 removable, self powered pcib7: at device 30.0 on pci0 pci1: on pcib7 pci1: at device 3.0 (no driver attached) pci1: at device 4.0 (no driver attached) pci1: at device 4.2 (no driver attached) uhci4: port 0x3800-0x381f irq 23 at device 4.4 on pci1 uhci4: [GIANT-LOCKED] usb5: on uhci4 usb5: USB revision 1.0 uhub5: (0x103c) UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub5: 2 ports with 2 removable, self powered pci1: at device 4.6 (no driver attached) isab0: at device 31.0 on pci0 isa0: on isab0 atapci0: port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0x500-0x50f at device 31.1 on pci0 ata0: on atapci0 ata1: on atapci0 atapci1: port 0x1080-0x1087,0x1088-0x108b,0x1090-0x1097,0x1098-0x109b,0x10a0-0x10af mem 0xfdce0000-0xfdce03ff irq 20 at device 31.2 on pci0 ata2: on atapci1 ata3: on atapci1 acpi_tz0: on acpi0 atkbdc0: port 0x60,0x64 irq 1 on acpi0 atkbd0: irq 1 on atkbdc0 kbd0 at atkbd0 atkbd0: [GIANT-LOCKED] psm0: irq 12 on atkbdc0 psm0: [GIANT-LOCKED] psm0: model IntelliMouse Explorer, device ID 4 orm0: at iomem 0xc0000-0xcafff,0xe6000-0xe7fff on isa0 ppc0: cannot reserve I/O port range sc0: at flags 0x100 on isa0 sc0: VGA <16 virtual consoles, flags=0x300> sio0: configured irq 4 not in bitmap of probed irqs 0 sio0: port may not be enabled sio0 at port 0x3f8-0x3ff irq 4 flags 0x10 on isa0 sio0: type 8250 or not responding sio1: configured irq 3 not in bitmap of probed irqs 0 sio1: port may not be enabled vga0: at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0 ukbd0: HP Virtual Keyboard, rev 1.10/0.02, addr 2, iclass 3/1 kbd2 at ukbd0 ums0: HP Virtual Keyboard, rev 1.10/0.02, addr 2, iclass 3/1 ums0: 3 buttons. uhub6: HP Virtual Hub, class 9/0, rev 1.10/0.01, addr 3 uhub6: 7 ports with 7 removable, self powered Timecounters tick every 1.000 msec acd0: CDROM at ata0-master UDMA33 ad4: 152627MB at ata2-master SATA150 ad6: 152627MB at ata3-master SATA150 SMP: AP CPU #1 Launched! Trying to mount root from ufs:/dev/ad4s1a bge0: link state changed to UP mailproxy1# scr^Dexit Script done on Thu Apr 26 12:07:58 2007 >Release-Note: >Audit-Trail: >Unformatted: