HEAD crashed at ioctl() / in_control()

From: Alexander Motin <mav_at_FreeBSD.org>
Date: Fri, 21 Mar 2008 00:08:16 +0200
Hi.

While doing active user connect/disconnect mpd stress testing my system 
with HEAD of first days of march crashed with such symptoms:

#11 0xc0a4421b in calltrap () at /usr/src/sys/i386/i386/exception.s:146
#12 0xc083b36d in in_control (so=0xc33bca9c, cmd=2149607705, 
data=0xc45a7aa0 "ng408", ifp=0xc458e000, td=dwarf2_read_address: 
Corrupted DWARF expression.
) at /usr/src/sys/netinet/in.c:494
#13 0xc07ffe83 in ifioctl (so=0xc33bca9c, cmd=2149607705, 
data=0xc45a7aa0 "ng408", td=0xc33ba220) at /usr/src/sys/net/if.c:1888
#14 0xc07a9e24 in soo_ioctl (fp=0xc2fab444, cmd=2149607705, 
data=0xc45a7aa0, active_cred=0xc2cf5500, td=0xc33ba220) at 
/usr/src/sys/kern/sys_socket.c:200
#15 0xc07a40a8 in kern_ioctl (td=0xc33ba220, fd=3, com=2149607705, 
data=0xc45a7aa0 "ng408") at file.h:254
#16 0xc07a4214 in ioctl (td=0xc33ba220, uap=0xd62cdcfc) at 
/usr/src/sys/kern/sys_generic.c:677
#17 0xc0a5dfb3 in syscall (frame=0xd62cdd38) at 
/usr/src/sys/i386/i386/trap.c:1034
#18 0xc0a44280 in Xint0x80_syscall () at 
/usr/src/sys/i386/i386/exception.s:203
#19 0x00000033 in ?? ()
(kgdb) frame 12
#12 0xc083b36d in in_control (so=0xc33bca9c, cmd=2149607705, 
data=0xc45a7aa0 "ng408", ifp=0xc458e000, td=dwarf2_read_address: 
Corrupted DWARF expression.
) at /usr/src/sys/netinet/in.c:494
494             TAILQ_REMOVE(&ifp->if_addrhead, &ia->ia_ifa, ifa_link);
(kgdb) l
489             /*
490              * Protect from ipintr() traversing address list while 
we're modifying
491              * it.
492              */
493             s = splnet();
494             TAILQ_REMOVE(&ifp->if_addrhead, &ia->ia_ifa, ifa_link);
495             TAILQ_REMOVE(&in_ifaddrhead, ia, ia_link);
496             if (ia->ia_addr.sin_family == AF_INET) {
497                     LIST_REMOVE(ia, ia_hash);
498                     /*
(kgdb) p ifp->if_addrhead
$1 = {tqh_first = 0xdeadc0de, tqh_last = 0xdeadc0de}
(kgdb) p ifp
$2 = (struct ifnet *) 0xc458e000

This test assumes active, possibly concurrent interface 
creation/destruction and address adding/deleting.

-- 
Alexander Motin
Received on Thu Mar 20 2008 - 22:08:23 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:39:29 UTC