From nobody@FreeBSD.org  Wed Oct 29 03:47:52 2008
Return-Path: <nobody@FreeBSD.org>
Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34])
	by hub.freebsd.org (Postfix) with ESMTP id DDE5F106568D
	for <freebsd-gnats-submit@FreeBSD.org>; Wed, 29 Oct 2008 03:47:52 +0000 (UTC)
	(envelope-from nobody@FreeBSD.org)
Received: from www.freebsd.org (www.freebsd.org [IPv6:2001:4f8:fff6::21])
	by mx1.freebsd.org (Postfix) with ESMTP id C6F418FC0C
	for <freebsd-gnats-submit@FreeBSD.org>; Wed, 29 Oct 2008 03:47:52 +0000 (UTC)
	(envelope-from nobody@FreeBSD.org)
Received: from www.freebsd.org (localhost [127.0.0.1])
	by www.freebsd.org (8.14.3/8.14.3) with ESMTP id m9T3lqA5009824
	for <freebsd-gnats-submit@FreeBSD.org>; Wed, 29 Oct 2008 03:47:52 GMT
	(envelope-from nobody@www.freebsd.org)
Received: (from nobody@localhost)
	by www.freebsd.org (8.14.3/8.14.3/Submit) id m9T3lqEC009823;
	Wed, 29 Oct 2008 03:47:52 GMT
	(envelope-from nobody)
Message-Id: <200810290347.m9T3lqEC009823@www.freebsd.org>
Date: Wed, 29 Oct 2008 03:47:52 GMT
From: Kirk Strauser <kirk@strauser.com>
To: freebsd-gnats-submit@FreeBSD.org
Subject: Accessing SCSI tape drive randomly crashes my amd64 system
X-Send-Pr-Version: www-3.1
X-GNATS-Notify:

>Number:         128452
>Category:       kern
>Synopsis:       [sa] [panic] Accessing SCSI tape drive randomly crashes my amd64 system
>Confidential:   no
>Severity:       serious
>Priority:       low
>Responsible:    freebsd-scsi
>State:          closed
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Wed Oct 29 03:50:01 UTC 2008
>Closed-Date:    Tue May 07 14:25:43 UTC 2013
>Last-Modified:  Tue May 07 14:25:43 UTC 2013
>Originator:     Kirk Strauser
>Release:        7-STABLE from 2008-09-18
>Organization:
>Environment:
FreeBSD kanga.honeypot.net 7.1-PRERELEASE FreeBSD 7.1-PRERELEASE #2: Thu Sep 18 19:17:10 CDT 2008     root@kanga.honeypot.net:/usr/obj/usr/src/sys/KANGA  amd64

>Description:
Accessing my tape drive randomly causes my FreeBSD 7-STABLE/amd64 system
to crash.  This has been going on for at least a couple of months, but I
finally got a kernel dump to play with.  I typically see this when running
a backup with Amanda, and as soon as the first filesystem dump starts to
flush to tape, the system reboots.


My kernel is very slightly changed from GENERIC, with PMAP_SHPGPERPROC
increased for PostgreSQL and the re(4) driver disabled (because it only
works when compiled as a module; different issue).

$ cat KANGA
include		GENERIC
ident		KANGA
option		PMAP_SHPGPERPROC=400
nodevice	re


The only compiler option in /etc/make.conf is "CPUTYPE?=core2".  In
short, this is very nearly a generic system.


My dmesg:

Copyright (c) 1992-2008 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
	The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 7.1-PRERELEASE #2: Thu Sep 18 19:17:10 CDT 2008
    root@kanga.honeypot.net:/usr/obj/usr/src/sys/KANGA
module_register: module cpu/ichss already exists!
Module cpu/ichss failed to register: 17
module_register: module cpu/powernow already exists!
Module cpu/powernow failed to register: 17
module_register: module cpu/est already exists!
Module cpu/est failed to register: 17
module_register: module cpu/p4tcc already exists!
Module cpu/p4tcc failed to register: 17
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) Core(TM)2 Duo CPU     E8400  @ 3.00GHz (3002.68-MHz K8-class CPU)
  Origin = "GenuineIntel"  Id = 0x10676  Stepping = 6
  Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
  Features2=0x8e3fd<SSE3,RSVD2,MON,DS_CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,<b19>>
  AMD Features=0x20100800<SYSCALL,NX,LM>
  AMD Features2=0x1<LAHF>
  Cores per package: 2
usable memory = 6428176384 (6130 MB)
avail memory  = 6203736064 (5916 MB)
ACPI APIC Table: <GBT    GBTUACPI>
FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
 cpu0 (BSP): APIC ID:  0
 cpu1 (AP): APIC ID:  1
ioapic0: Changing APIC ID to 2
ioapic0 <Version 2.0> irqs 0-23 on motherboard
kbd1 at kbdmux0
ath_hal: 0.9.20.3 (AR5210, AR5211, AR5212, RF5111, RF5112, RF2413, RF5413)
acpi0: <GBT GBTUACPI> on motherboard
acpi0: [ITHREAD]
acpi0: Power Button (fixed)
acpi0: reservation of 0, a0000 (3) failed
acpi0: reservation of 100000, cfde0000 (3) failed
Timecounter "ACPI-fast" frequency 3579545 Hz quality 1000
acpi_timer0: <24-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0
acpi_hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
Timecounter "HPET" frequency 14318180 Hz quality 900
acpi_button0: <Power Button> on acpi0
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
pcib1: <PCI-PCI bridge> irq 16 at device 1.0 on pci0
pci1: <PCI bus> on pcib1
vgapci0: <VGA-compatible display> port 0x8000-0x80ff mem 0xd0000000-0xdfffffff,0xe5000000-0xe500ffff irq 16 at device 0.0 on pci1
pci1: <multimedia> at device 0.1 (no driver attached)
pcib2: <PCI-PCI bridge> irq 16 at device 6.0 on pci0
pci2: <PCI bus> on pcib2
uhci0: <UHCI (generic) USB controller> port 0xd500-0xd51f irq 16 at device 26.0 on pci0
uhci0: [GIANT-LOCKED]
uhci0: [ITHREAD]
usb0: <UHCI (generic) USB controller> on uhci0
usb0: USB revision 1.0
uhub0: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb0
uhub0: 2 ports with 2 removable, self powered
uhci1: <UHCI (generic) USB controller> port 0xd000-0xd01f irq 21 at device 26.1 on pci0
uhci1: [GIANT-LOCKED]
uhci1: [ITHREAD]
usb1: <UHCI (generic) USB controller> on uhci1
usb1: USB revision 1.0
uhub1: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb1
uhub1: 2 ports with 2 removable, self powered
uhci2: <UHCI (generic) USB controller> port 0xd100-0xd11f irq 18 at device 26.2 on pci0
uhci2: [GIANT-LOCKED]
uhci2: [ITHREAD]
usb2: <UHCI (generic) USB controller> on uhci2
usb2: USB revision 1.0
uhub2: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb2
uhub2: 2 ports with 2 removable, self powered
ehci0: <EHCI (generic) USB 2.0 controller> mem 0xea305000-0xea3053ff irq 18 at device 26.7 on pci0
ehci0: [GIANT-LOCKED]
ehci0: [ITHREAD]
usb3: EHCI version 1.0
usb3: companion controllers, 2 ports each: usb0 usb1 usb2
usb3: <EHCI (generic) USB 2.0 controller> on ehci0
usb3: USB revision 2.0
uhub3: <Intel EHCI root hub, class 9/0, rev 2.00/1.00, addr 1> on usb3
uhub3: 6 ports with 6 removable, self powered
umass0: <Verbatim STORE N GO, class 0/0, rev 2.00/1.10, addr 2> on uhub3
pci0: <multimedia> at device 27.0 (no driver attached)
pcib3: <ACPI PCI-PCI bridge> irq 16 at device 28.0 on pci0
pci3: <ACPI PCI bus> on pcib3
pcib4: <ACPI PCI-PCI bridge> irq 19 at device 28.3 on pci0
pci4: <ACPI PCI bus> on pcib4
atapci0: <JMicron JMB363 SATA300 controller> port 0x9000-0x9007,0x9100-0x9103,0x9200-0x9207,0x9300-0x9303,0x9400-0x940f mem 0xea000000-0xea001fff irq 19 at device 0.0 on pci4
atapci0: [ITHREAD]
atapci0: AHCI called from vendor specific driver
atapci0: AHCI Version 01.00 controller with 2 ports detected
ata2: <ATA channel 0> on atapci0
ata2: [ITHREAD]
ata3: <ATA channel 1> on atapci0
ata3: [ITHREAD]
ata4: <ATA channel 2> on atapci0
ata4: [ITHREAD]
pcib5: <ACPI PCI-PCI bridge> irq 16 at device 28.4 on pci0
pci5: <ACPI PCI bus> on pcib5
re0: <RealTek 8168/8168B/8168C/8168CP/8111B/8111C/8111CP PCIe Gigabit Ethernet> port 0xa000-0xa0ff mem 0xea210000-0xea210fff,0xea200000-0xea20ffff irq 16 at device 0.0 on pci5
re0: Chip rev. 0x3c000000
re0: MAC rev. 0x00400000
miibus0: <MII bus> on re0
rgephy0: <RTL8169S/8110S/8211B media interface> PHY 1 on miibus0
rgephy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseT, 1000baseT-FDX, auto
re0: Ethernet address: 00:1f:d0:22:b8:a8
re0: [FILTER]
pcib6: <ACPI PCI-PCI bridge> irq 17 at device 28.5 on pci0
pci6: <ACPI PCI bus> on pcib6
re1: <RealTek 8168/8168B/8168C/8168CP/8111B/8111C/8111CP PCIe Gigabit Ethernet> port 0xb000-0xb0ff mem 0xea110000-0xea110fff,0xea100000-0xea10ffff irq 17 at device 0.0 on pci6
re1: Chip rev. 0x3c000000
re1: MAC rev. 0x00400000
miibus1: <MII bus> on re1
rgephy1: <RTL8169S/8110S/8211B media interface> PHY 1 on miibus1
rgephy1:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseT, 1000baseT-FDX, auto
re1: Ethernet address: 00:1f:d0:22:b8:b8
re1: [FILTER]
uhci3: <UHCI (generic) USB controller> port 0xd200-0xd21f irq 23 at device 29.0 on pci0
uhci3: [GIANT-LOCKED]
uhci3: [ITHREAD]
usb4: <UHCI (generic) USB controller> on uhci3
usb4: USB revision 1.0
uhub4: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb4
uhub4: 2 ports with 2 removable, self powered
uhci4: <UHCI (generic) USB controller> port 0xd300-0xd31f irq 19 at device 29.1 on pci0
uhci4: [GIANT-LOCKED]
uhci4: [ITHREAD]
usb5: <UHCI (generic) USB controller> on uhci4
usb5: USB revision 1.0
uhub5: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb5
uhub5: 2 ports with 2 removable, self powered
uhci5: <UHCI (generic) USB controller> port 0xd400-0xd41f irq 18 at device 29.2 on pci0
uhci5: [GIANT-LOCKED]
uhci5: [ITHREAD]
usb6: <UHCI (generic) USB controller> on uhci5
usb6: USB revision 1.0
uhub6: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb6
uhub6: 2 ports with 2 removable, self powered
ehci1: <EHCI (generic) USB 2.0 controller> mem 0xea304000-0xea3043ff irq 23 at device 29.7 on pci0
ehci1: [GIANT-LOCKED]
ehci1: [ITHREAD]
usb7: EHCI version 1.0
usb7: companion controllers, 2 ports each: usb4 usb5 usb6
usb7: <EHCI (generic) USB 2.0 controller> on ehci1
usb7: USB revision 2.0
uhub7: <Intel EHCI root hub, class 9/0, rev 2.00/1.00, addr 1> on usb7
uhub7: 6 ports with 6 removable, self powered
pcib7: <ACPI PCI-PCI bridge> at device 30.0 on pci0
pci7: <ACPI PCI bus> on pcib7
sym0: <875> port 0xc000-0xc0ff mem 0xe9004000-0xe90040ff,0xe9006000-0xe9006fff irq 20 at device 0.0 on pci7
sym0: Tekram NVRAM, ID 15, Fast-20, SE, parity checking
sym0: [ITHREAD]
fwohci0: <Texas Instruments TSB43AB23> mem 0xe9005000-0xe90057ff,0xe9000000-0xe9003fff irq 18 at device 6.0 on pci7
fwohci0: [FILTER]
fwohci0: OHCI version 1.10 (ROM=0)
fwohci0: No. of Isochronous channels is 4.
fwohci0: EUI64 00:2b:78:a9:00:00:1f:d0
fwohci0: Phy 1394a available S400, 3 ports.
fwohci0: Link S400, max_rec 2048 bytes.
firewire0: <IEEE1394(FireWire) bus> on fwohci0
dcons_crom0: <dcons configuration ROM> on firewire0
dcons_crom0: bus_addr 0x113c000
fwe0: <Ethernet over FireWire> on firewire0
if_fwe0: Fake Ethernet address: 02:2b:78:00:1f:d0
fwe0: Ethernet address: 02:2b:78:00:1f:d0
fwip0: <IP over FireWire> on firewire0
fwip0: Firewire address: 00:2b:78:a9:00:00:1f:d0 @ 0xfffe00000000, S400, maxrec 2048
sbp0: <SBP-2/SCSI over FireWire> on firewire0
fwohci0: Initiate bus reset
fwohci0: BUS reset
fwohci0: node_id=0xc800ffc0, gen=1, CYCLEMASTER mode
isab0: <PCI-ISA bridge> at device 31.0 on pci0
isa0: <ISA bus> on isab0
atapci1: <Intel ICH9 SATA300 controller> port 0xd600-0xd607,0xd700-0xd703,0xd800-0xd807,0xd900-0xd903,0xda00-0xda0f,0xdb00-0xdb0f irq 19 at device 31.2 on pci0
atapci1: [ITHREAD]
ata5: <ATA channel 0> on atapci1
ata5: [ITHREAD]
ata6: <ATA channel 1> on atapci1
ata6: [ITHREAD]
pci0: <serial bus, SMBus> at device 31.3 (no driver attached)
atapci2: <Intel ICH9 SATA300 controller> port 0xdd00-0xdd07,0xde00-0xde03,0xdf00-0xdf07,0xe000-0xe003,0xe100-0xe10f,0xe200-0xe20f irq 19 at device 31.5 on pci0
atapci2: [ITHREAD]
ata7: <ATA channel 0> on atapci2
ata7: [ITHREAD]
ata8: <ATA channel 1> on atapci2
ata8: [ITHREAD]
sio0: configured irq 4 not in bitmap of probed irqs 0
sio0: port may not be enabled
sio0: configured irq 4 not in bitmap of probed irqs 0
sio0: port may not be enabled
sio0: <16550A-compatible COM port> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
sio0: type 16550A
sio0: [FILTER]
ppc0: <Parallel port> port 0x378-0x37f irq 7 on acpi0
ppc0: Generic chipset (NIBBLE-only) in COMPATIBLE mode
ppbus0: <Parallel port bus> on ppc0
ppbus0: [ITHREAD]
plip0: <PLIP network interface> on ppbus0
plip0: WARNING: using obsoleted IFF_NEEDSGIANT flag
lpt0: <Printer> on ppbus0
lpt0: Interrupt-driven port
ppi0: <Parallel I/O> on ppbus0
ppc0: [GIANT-LOCKED]
ppc0: [ITHREAD]
atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
kbd0 at atkbd0
atkbd0: [GIANT-LOCKED]
atkbd0: [ITHREAD]
psm0: <PS/2 Mouse> irq 12 on atkbdc0
psm0: [GIANT-LOCKED]
psm0: [ITHREAD]
psm0: model IntelliMouse, device ID 3
cpu0: <ACPI CPU> on acpi0
coretemp0: <CPU On-Die Thermal Sensors> on cpu0
est0: <Enhanced SpeedStep Frequency Control> on cpu0
est: CPU supports Enhanced Speedstep, but is not recognized.
est: cpu_vendor GenuineIntel, msr 61a092006000920
device_attach: est0 attach returned 6
p4tcc0: <CPU Frequency Thermal Control> on cpu0
cpu1: <ACPI CPU> on acpi0
coretemp1: <CPU On-Die Thermal Sensors> on cpu1
est1: <Enhanced SpeedStep Frequency Control> on cpu1
est: CPU supports Enhanced Speedstep, but is not recognized.
est: cpu_vendor GenuineIntel, msr 61a092006000920
device_attach: est1 attach returned 6
p4tcc1: <CPU Frequency Thermal Control> on cpu1
sc0: <System console> at flags 0x100 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
sio1: configured irq 3 not in bitmap of probed irqs 0
sio1: port may not be enabled
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
Timecounters tick every 1.000 msec
firewire0: 1 nodes, maxhop <= 0, cable IRM = 0 (me)
firewire0: bus manager 0 (me)
acd0: DVDROM <IDE DVD-ROM 16X/VER 2.40> at ata4-master UDMA33
ad10: 715403MB <Hitachi HDS721075KLA330 GK8OA70M> at ata5-master SATA300
sa0 at sym0 bus 0 target 3 lun 0
sa0: <SEAGATE DAT    9SP40-000 912L> Removable Sequential Access SCSI-3 device 
sa0: 20.000MB/s transfers (10.000MHz, offset 16, 16bit)
SMP: AP CPU #1 Launched!
da0 at umass-sim0 bus 0 target 0 lun 0
da0: <Verbatim STORE N GO 5.00> Removable Direct Access SCSI-0 device 
da0: 40.000MB/s transfers
da0: 3822MB (7827456 512 byte sectors: 255H 63S/T 487C)
GEOM_LABEL: Label for provider da0s1 is msdosfs/STORE N GO.
Trying to mount root from ufs:/dev/ad10s1a
WARNING: / was not properly dismounted
/: mount pending error: blocks 7856 files 10
GEOM_LABEL: Label msdosfs/STORE N GO removed.
GEOM_LABEL: Label for provider da0s1 is msdosfs/STORE N GO.



A backtrace of the kernel dump:

$ kgdb /boot/kernel/kernel /var/crash/vmcore.5
GNU gdb 6.1.1 [FreeBSD]
Copyright 2004 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "amd64-marcel-freebsd"...

Unread portion of the kernel message buffer:


Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address	= 0x258
fault code		= supervisor read data, page not present
instruction pointer	= 0x8:0xffffffff8047ca7a
stack pointer	        = 0x10:0xffffffffaef6cac0
frame pointer	        = 0x10:0xffffff0004105a50
code segment		= base 0x0, limit 0xfffff, type 0x1b
			= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags	= interrupt enabled, resume, IOPL = 0
current process		= 50 (syncer)
trap number		= 12
panic: page fault
cpuid = 0
Uptime: 4h8m27s
Physical memory: 6130 MB
Dumping 590 MB: 575 559 543 527 511 495 479 463 447 431 415 399 383 367 351 335 319 303 287 271 255 239 223 207 191 175 159 143 127 111 95 79 63 47 31 15

Reading symbols from /boot/kernel/if_re.ko...Reading symbols from /boot/kernel/if_re.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/if_re.ko
Reading symbols from /boot/kernel/coretemp.ko...Reading symbols from /boot/kernel/coretemp.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/coretemp.ko
Reading symbols from /boot/kernel/cpufreq.ko...Reading symbols from /boot/kernel/cpufreq.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/cpufreq.ko
Reading symbols from /boot/kernel/pflog.ko...Reading symbols from /boot/kernel/pflog.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/pflog.ko
Reading symbols from /boot/kernel/pf.ko...Reading symbols from /boot/kernel/pf.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/pf.ko
Reading symbols from /boot/kernel/linux.ko...Reading symbols from /boot/kernel/linux.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/linux.ko
Reading symbols from /boot/kernel/nullfs.ko...Reading symbols from /boot/kernel/nullfs.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/nullfs.ko
Reading symbols from /boot/kernel/fdescfs.ko...Reading symbols from /boot/kernel/fdescfs.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/fdescfs.ko
Reading symbols from /boot/kernel/accf_http.ko...Reading symbols from /boot/kernel/accf_http.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/accf_http.ko
Reading symbols from /boot/kernel/green_saver.ko...Reading symbols from /boot/kernel/green_saver.ko.symbols...done.
done.
Loaded symbols for /boot/kernel/green_saver.ko
#0  doadump () at pcpu.h:195
195	pcpu.h: No such file or directory.
	in pcpu.h
(kgdb) list *0xffffffff8047ca7a
0xffffffff8047ca7a is in _mtx_lock_sleep (/usr/src/sys/kern/kern_mutex.c:341).
336			 */
337			v = m->mtx_lock;
338			if (v != MTX_UNOWNED) {
339				owner = (struct thread *)(v & ~MTX_FLAGMASK);
340	#ifdef ADAPTIVE_GIANT
341				if (TD_IS_RUNNING(owner)) {
342	#else
343				if (m != &Giant && TD_IS_RUNNING(owner)) {
344	#endif
345					if (LOCK_LOG_TEST(&m->lock_object, 0))
(kgdb) backtrace
#0  doadump () at pcpu.h:195
#1  0x0000000000000004 in ?? ()
#2  0xffffffff80487e41 in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:418
#3  0xffffffff80488272 in panic (fmt=0x104 <Address 0x104 out of bounds>)
    at /usr/src/sys/kern/kern_shutdown.c:572
#4  0xffffffff8073fd6a in trap_fatal (frame=0xffffff0004105a50, eva=Variable "eva" is not available.
)
    at /usr/src/sys/amd64/amd64/trap.c:764
#5  0xffffffff80740111 in trap_pfault (frame=0xffffffffaef6ca10, usermode=0)
    at /usr/src/sys/amd64/amd64/trap.c:680
#6  0xffffffff807409cf in trap (frame=0xffffffffaef6ca10) at /usr/src/sys/amd64/amd64/trap.c:449
#7  0xffffffff8072742e in calltrap () at /usr/src/sys/amd64/amd64/exception.S:209
#8  0xffffffff8047ca7a in _mtx_lock_sleep (m=0xffffff00a02504d8, tid=18446742974266104400, opts=Variable "opts" is not available.
)
    at /usr/src/sys/kern/kern_mutex.c:339
#9  0xffffffff80500342 in vfs_msync (mp=0xffffff000410ea68, flags=2)
    at /usr/src/sys/kern/vfs_subr.c:2979
#10 0xffffffff8050059b in sync_fsync (ap=Variable "ap" is not available.
) at /usr/src/sys/kern/vfs_subr.c:3216
#11 0xffffffff80500d1c in sched_sync () at vnode_if.h:538
#12 0xffffffff8046863d in fork_exit (callout=0xffffffff80500707 <sched_sync>, arg=0x0, 
    frame=0xffffffffaef6cc80) at /usr/src/sys/kern/kern_fork.c:804
#13 0xffffffff807277fe in fork_trampoline () at /usr/src/sys/amd64/amd64/exception.S:455
#14 0x0000000000000000 in ?? ()
#15 0x0000000000000000 in ?? ()
#16 0x0000000000000001 in ?? ()
#17 0x0000000000000000 in ?? ()
#18 0x0000000000000000 in ?? ()
#19 0x0000000000000000 in ?? ()
#20 0x0000000000000000 in ?? ()
#21 0x0000000000000000 in ?? ()
#22 0x0000000000000000 in ?? ()
#23 0x0000000000000000 in ?? ()
#24 0x0000000000000000 in ?? ()
#25 0x0000000000000000 in ?? ()
#26 0x0000000000000000 in ?? ()
#27 0x0000000000000000 in ?? ()
#28 0x0000000000000000 in ?? ()
#29 0x0000000000000000 in ?? ()
#30 0x0000000000000000 in ?? ()
#31 0x0000000000000000 in ?? ()
#32 0x0000000000000000 in ?? ()
#33 0x0000000000000000 in ?? ()
#34 0x0000000000000000 in ?? ()
#35 0x0000000000000000 in ?? ()
#36 0x0000000000000000 in ?? ()
#37 0x0000000000000000 in ?? ()
#38 0x0000000000d0d000 in ?? ()
#39 0xffffffff80a67e80 in tdg_maxid ()
#40 0xffffffff80a74680 in tdq_cpu ()
#41 0xffffffff80a74680 in tdq_cpu ()
#42 0xffffff0004105a50 in ?? ()
#43 0xffffff0004105d80 in ?? ()
#44 0xffffffffaef6c268 in ?? ()
#45 0x0000000000000000 in ?? ()
#46 0xffffffff804a7090 in sched_switch (td=0xffffffff80500707, newtd=0x800571450, flags=Variable "flags" is not available.
)
    at /usr/src/sys/kern/sched_ule.c:1938
#47 0x0000000000000000 in ?? ()
#48 0x0000000000000000 in ?? ()
#49 0x0000000000000000 in ?? ()
#50 0x0000000000000000 in ?? ()
#51 0x0000000000000000 in ?? ()
#52 0x0000000000000000 in ?? ()
#53 0x0000000000000000 in ?? ()
#54 0x0000000000000000 in ?? ()
#55 0x0000000000000000 in ?? ()
#56 0x0000000000000000 in ?? ()
#57 0x0000000000000000 in ?? ()
#58 0x0000000000000000 in ?? ()
#59 0x0000000000000000 in ?? ()
#60 0x0000000000000000 in ?? ()
#61 0x0000000000000000 in ?? ()
#62 0x0000000000000000 in ?? ()
#63 0x0000000000000000 in ?? ()
#64 0x0000000000000000 in ?? ()
#65 0x0000000000000000 in ?? ()
#66 0x0000000000000000 in ?? ()
#67 0x0000000000000000 in ?? ()
#68 0x0000000000000000 in ?? ()
#69 0x0000000000000000 in ?? ()
#70 0x0000000000000000 in ?? ()
#71 0x0000000000000000 in ?? ()
#72 0x0000000000000000 in ?? ()
#73 0x0000000000000000 in ?? ()
#74 0x0000000000000000 in ?? ()
#75 0x0000000000000000 in ?? ()
#76 0x0000000000000000 in ?? ()
#77 0x0000000000000000 in ?? ()
#78 0x0000000000000000 in ?? ()
#79 0x0000000000000000 in ?? ()
#80 0x0000000000000000 in ?? ()
#81 0x0000000000000000 in ?? ()
#82 0x0000000000000000 in ?? ()
#83 0x0000000000000000 in ?? ()
#84 0x0000000000000000 in ?? ()
#85 0x0000000000000000 in ?? ()
#86 0x0000000000000000 in ?? ()
#87 0x0000000000000000 in ?? ()
#88 0x0000000000000000 in ?? ()
#89 0x0000000000000000 in ?? ()
#90 0x0000000000000000 in ?? ()
#91 0x0000000000000000 in ?? ()
#92 0x0000000000000000 in ?? ()
#93 0x0000000000000000 in ?? ()
#94 0x0000000000000000 in ?? ()
#95 0x0000000000000000 in ?? ()
#96 0x0000000000000000 in ?? ()
#97 0x0000000000000000 in ?? ()
#98 0x0000000000000000 in ?? ()
#99 0x0000000000000000 in ?? ()
#100 0x0000000000000000 in ?? ()
#101 0x0000000000000000 in ?? ()
#102 0x0000000000000000 in ?? ()
#103 0x0000000000000000 in ?? ()
#104 0x0000000000000000 in ?? ()
#105 0x0000000000000000 in ?? ()
#106 0x0000000000000000 in ?? ()
#107 0x0000000000000000 in ?? ()
#108 0x0000000000000000 in ?? ()
#109 0x0000000000000000 in ?? ()
#110 0x0000000000000000 in ?? ()
#111 0x0000000000000000 in ?? ()
#112 0x0000000000000000 in ?? ()
#113 0x0000000000000000 in ?? ()
#114 0x0000000000000000 in ?? ()
Cannot access memory at address 0xffffffffaef6d000
(kgdb) quit

>How-To-Repeat:
Attempt to write data to sa0.  This only results in a reboot perhaps
20% of the time, and I haven't found conditions that make it 100%.
>Fix:


>Release-Note:
>Audit-Trail:
Responsible-Changed-From-To: freebsd-bugs->freebsd-scsi 
Responsible-Changed-By: linimon 
Responsible-Changed-When: Wed Oct 29 16:04:29 UTC 2008 
Responsible-Changed-Why:  
Over to maintainer(s). 

http://www.freebsd.org/cgi/query-pr.cgi?pr=128452 

From: Kirk Strauser <kirk@strauser.com>
To: bug-followup@FreeBSD.org,
 kirk@strauser.com
Cc:  
Subject: Re: kern/128452: [sa] [panic] Accessing SCSI tape drive randomly crashes my amd64 system
Date: Wed, 29 Oct 2008 16:44:50 -0500

 --Apple-Mail-39-48870811
 Content-Type: text/plain;
 	charset=US-ASCII;
 	format=flowed;
 	delsp=yes
 Content-Transfer-Encoding: 7bit
 
 And another crash, this time while running "sudo dd if=/dev/zero of=/ 
 dev/sa0 bs=1m count=100":
 
 
 (kgdb) bt
 #0  doadump () at pcpu.h:195
 #1  0x0000000000000004 in ?? ()
 #2  0xffffffff80487e41 in boot (howto=260) at /usr/src/sys/kern/ 
 kern_shutdown.c:418
 #3  0xffffffff80488272 in panic (fmt=0x104 <Address 0x104 out of  
 bounds>)
      at /usr/src/sys/kern/kern_shutdown.c:572
 #4  0xffffffff8067c354 in ufs_dirbad (ip=Variable "ip" is not available.
 ) at /usr/src/sys/ufs/ufs/ufs_lookup.c:607
 #5  0xffffffff8067d51d in ufs_lookup (ap=0xffffffffb16e47a0)
      at /usr/src/sys/ufs/ufs/ufs_lookup.c:297
 #6  0xffffffff804ef854 in vfs_cache_lookup (ap=Variable "ap" is not  
 available.
 ) at vnode_if.h:83
 #7  0xffffffff8077fb2f in VOP_LOOKUP_APV (vop=0xffffffff80a00000,  
 a=0xffffffffb16e4860)
      at vnode_if.c:99
 #8  0xffffffff804f59ac in lookup (ndp=0xffffffffb16e4970) at  
 vnode_if.h:57
 #9  0xffffffff804f6884 in namei (ndp=0xffffffffb16e4970) at /usr/src/ 
 sys/kern/vfs_lookup.c:219
 #10 0xffffffff8050323c in kern_stat (td=0xffffff006bc0f370,
      path=0x5a7c08 <Address 0x5a7c08 out of bounds>, pathseg=Variable  
 "pathseg" is not available.
 )
      at /usr/src/sys/kern/vfs_syscalls.c:2113
 #11 0xffffffff8050347c in stat (td=Variable "td" is not available.
 ) at /usr/src/sys/kern/vfs_syscalls.c:2097
 #12 0xffffffff8074037c in syscall (frame=0xffffffffb16e4c80) at /usr/ 
 src/sys/amd64/amd64/trap.c:907
 #13 0xffffffff8072763b in Xfast_syscall () at /usr/src/sys/amd64/amd64/ 
 exception.S:330
 #14 0x0000000800bdd57c in ?? ()
 Previous frame inner to this frame (corrupt stack?)
 
 
 
 
 --Apple-Mail-39-48870811
 Content-Type: text/html;
 	charset=US-ASCII
 Content-Transfer-Encoding: quoted-printable
 
 <html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =
 -webkit-line-break: after-white-space; "><div>And another crash, this =
 time while running "sudo dd if=3D/dev/zero of=3D/dev/sa0 bs=3D1m =
 count=3D100":</div><div><br></div><div><br></div><div>(kgdb) =
 bt</div><div>#0 &nbsp;doadump () at pcpu.h:195</div><div>#1 =
 &nbsp;0x0000000000000004 in ?? ()</div><div>#2 &nbsp;0xffffffff80487e41 =
 in boot (howto=3D260) at =
 /usr/src/sys/kern/kern_shutdown.c:418</div><div>#3 =
 &nbsp;0xffffffff80488272 in panic (fmt=3D0x104 &lt;Address 0x104 out of =
 bounds>)</div><div>&nbsp;&nbsp; &nbsp;at =
 /usr/src/sys/kern/kern_shutdown.c:572</div><div>#4 =
 &nbsp;0xffffffff8067c354 in ufs_dirbad (ip=3DVariable "ip" is not =
 available.</div><div>) at =
 /usr/src/sys/ufs/ufs/ufs_lookup.c:607</div><div>#5 =
 &nbsp;0xffffffff8067d51d in ufs_lookup =
 (ap=3D0xffffffffb16e47a0)</div><div>&nbsp;&nbsp; &nbsp;at =
 /usr/src/sys/ufs/ufs/ufs_lookup.c:297</div><div>#6 =
 &nbsp;0xffffffff804ef854 in vfs_cache_lookup (ap=3DVariable "ap" is not =
 available.</div><div>) at vnode_if.h:83</div><div>#7 =
 &nbsp;0xffffffff8077fb2f in VOP_LOOKUP_APV (vop=3D0xffffffff80a00000, =
 a=3D0xffffffffb16e4860)</div><div>&nbsp;&nbsp; &nbsp;at =
 vnode_if.c:99</div><div>#8 &nbsp;0xffffffff804f59ac in lookup =
 (ndp=3D0xffffffffb16e4970) at vnode_if.h:57</div><div>#9 =
 &nbsp;0xffffffff804f6884 in namei (ndp=3D0xffffffffb16e4970) at =
 /usr/src/sys/kern/vfs_lookup.c:219</div><div>#10 0xffffffff8050323c in =
 kern_stat (td=3D0xffffff006bc0f370,&nbsp;</div><div>&nbsp;&nbsp; =
 &nbsp;path=3D0x5a7c08 &lt;Address 0x5a7c08 out of bounds>, =
 pathseg=3DVariable "pathseg" is not =
 available.</div><div>)</div><div>&nbsp;&nbsp; &nbsp;at =
 /usr/src/sys/kern/vfs_syscalls.c:2113</div><div>#11 0xffffffff8050347c =
 in stat (td=3DVariable "td" is not available.</div><div>) at =
 /usr/src/sys/kern/vfs_syscalls.c:2097</div><div>#12 0xffffffff8074037c =
 in syscall (frame=3D0xffffffffb16e4c80) at =
 /usr/src/sys/amd64/amd64/trap.c:907</div><div>#13 0xffffffff8072763b in =
 Xfast_syscall () at =
 /usr/src/sys/amd64/amd64/exception.S:330</div><div>#14 =
 0x0000000800bdd57c in ?? ()</div><div>Previous frame inner to this frame =
 (corrupt stack?)</div><div><br></div><div =
 apple-content-edited=3D"true"><span class=3D"Apple-style-span" =
 style=3D"border-collapse: separate; border-spacing: 0px 0px; color: =
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
 normal; font-variant: normal; font-weight: normal; letter-spacing: =
 normal; line-height: normal; text-align: auto; =
 -khtml-text-decorations-in-effect: none; text-indent: 0px; =
 -apple-text-size-adjust: auto; text-transform: none; orphans: 2; =
 white-space: normal; widows: 2; word-spacing: 0px; "><div =
 style=3D"word-wrap: break-word; -khtml-nbsp-mode: space; =
 -khtml-line-break: after-white-space; "><span class=3D"Apple-style-span" =
 style=3D"border-collapse: separate; border-spacing: 0px 0px; color: =
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
 normal; font-variant: normal; font-weight: normal; letter-spacing: =
 normal; line-height: normal; text-align: auto; =
 -khtml-text-decorations-in-effect: none; text-indent: 0px; =
 -apple-text-size-adjust: auto; text-transform: none; orphans: 2; =
 white-space: normal; widows: 2; word-spacing: 0px; "><br =
 class=3D"Apple-interchange-newline"></span></div></span> =
 </div><br></body></html>=
 
 --Apple-Mail-39-48870811--

From: Kirk Strauser <KIRK@STRAUSER.COM>
To: bug-followup@FreeBSD.org,
 kirk@strauser.com
Cc:  
Subject: Re: kern/128452: [sa] [panic] Accessing SCSI tape drive randomly crashes my amd64 system
Date: Sat, 1 Nov 2008 21:16:51 -0500

 And other kernel panic dump.  Daily crashes while making backups are  
 pretty standard now.
 
 This problem started when the machine was an Athlon 1.4GHz.  Since  
 then, I have replaced literally every component but the tape drive  
 itself, including an identical model Tekram DC-390F SCSI card (I  
 bought two a while back and swapped cards between servers for testing).
 
 Is there any additional information I could provide to help out?
 
 
 (kgdb) list *0xffffffff80739535
 0xffffffff80739535 is in pmap_clear_modify (atomic.h:143).
 138	atomic.h: No such file or directory.
 	in atomic.h
 (kgdb) bt
 #0  doadump () at pcpu.h:195
 #1  0x0000000000000004 in ?? ()
 #2  0xffffffff80488641 in boot (howto=260) at /usr/src/sys/kern/ 
 kern_shutdown.c:418
 #3  0xffffffff80488a7c in panic (fmt=0x104 <Address 0x104 out of  
 bounds>)
      at /usr/src/sys/kern/kern_shutdown.c:574
 #4  0xffffffff8074081a in trap_fatal (frame=0xffffff0001101a50,  
 eva=Variable "eva" is not available.
 )
      at /usr/src/sys/amd64/amd64/trap.c:764
 #5  0xffffffff807412d8 in trap (frame=0xffffffffac26ca40) at /usr/src/ 
 sys/amd64/amd64/trap.c:565
 #6  0xffffffff80727ece in calltrap () at /usr/src/sys/amd64/amd64/ 
 exception.S:209
 #7  0xffffffff80739535 in pmap_clear_modify (m=0xffffff00c4f74e20) at  
 atomic.h:143
 #8  0xffffffff8069ca79 in vm_page_set_validclean  
 (m=0xffffff00c4f74e20, base=0, size=4096)
      at /usr/src/sys/vm/vm_page.c:1813
 #9  0xffffffff804eda0f in bufdone_finish (bp=0xffffffff9a26e6a0)
      at /usr/src/sys/kern/vfs_bio.c:3272
 #10 0xffffffff804edcec in bufdone (bp=0xffffffff9a26e6a0) at /usr/src/ 
 sys/kern/vfs_bio.c:3173
 #11 0xffffffff804f0375 in cluster_callback (bp=0xffffffff99fbe720)
      at /usr/src/sys/kern/vfs_cluster.c:542
 #12 0xffffffff804edcc5 in bufdone (bp=0xffffffff99fbe720) at /usr/src/ 
 sys/kern/vfs_bio.c:3167
 #13 0xffffffff8043c2c2 in g_io_schedule_up (tp=Variable "tp" is not  
 available.
 ) at /usr/src/sys/geom/geom_io.c:587
 #14 0xffffffff8043c566 in g_up_procbody () at /usr/src/sys/geom/ 
 geom_kern.c:95
 #15 0xffffffff80468d5d in fork_exit (callout=0xffffffff8043c514  
 <g_up_procbody>, arg=0x0,
      frame=0xffffffffac26cc80) at /usr/src/sys/kern/kern_fork.c:804
 #16 0xffffffff8072829e in fork_trampoline () at /usr/src/sys/amd64/ 
 amd64/exception.S:455
 #17 0x0000000000000000 in ?? ()
 #18 0x0000000000000000 in ?? ()
 #19 0x0000000000000001 in ?? ()
 #20 0x0000000000000000 in ?? ()
 #21 0x0000000000000000 in ?? ()
 #22 0x0000000000000000 in ?? ()
 #23 0x0000000000000000 in ?? ()
 #24 0x0000000000000000 in ?? ()
 #25 0x0000000000000000 in ?? ()
 #26 0x0000000000000000 in ?? ()
 #27 0x0000000000000000 in ?? ()
 #28 0x0000000000000000 in ?? ()
 #29 0x0000000000000000 in ?? ()
 #30 0x0000000000000000 in ?? ()
 #31 0x0000000000000000 in ?? ()
 #32 0x0000000000000000 in ?? ()
 ---Type <return> to continue, or q <return> to quit---
 #33 0x0000000000000000 in ?? ()
 #34 0x0000000000000000 in ?? ()
 #35 0x0000000000000000 in ?? ()
 #36 0x0000000000000000 in ?? ()
 #37 0x0000000000000000 in ?? ()
 #38 0x0000000000000000 in ?? ()
 #39 0x0000000000000000 in ?? ()
 #40 0x0000000000000000 in ?? ()
 #41 0x0000000000d0e000 in ?? ()
 #42 0xffffffff80a69180 in tdg_maxid ()
 #43 0xffffffff80a75980 in tdq_cpu ()
 #44 0xffffffff80a75980 in tdq_cpu ()
 #45 0xffffff0001101a50 in ?? ()
 #46 0xffffff0001101d80 in ?? ()
 #47 0xffffffffac26c0c8 in ?? ()
 #48 0x0000000000000000 in ?? ()
 #49 0xffffffff804a78ee in sched_switch (td=0xffffffff8043c514,  
 newtd=0x800530450, flags=Variable "flags" is not available.
 )
      at /usr/src/sys/kern/sched_ule.c:1938
 #50 0x0000000000000000 in ?? ()
 #51 0x0000000000000000 in ?? ()
 #52 0x0000000000000000 in ?? ()
 #53 0x0000000000000000 in ?? ()
 #54 0x0000000000000000 in ?? ()
 #55 0x0000000000000000 in ?? ()
 #56 0x0000000000000000 in ?? ()
 #57 0x0000000000000000 in ?? ()
 #58 0x0000000000000000 in ?? ()
 #59 0x0000000000000000 in ?? ()
 #60 0x0000000000000000 in ?? ()
 #61 0x0000000000000000 in ?? ()
 #62 0x0000000000000000 in ?? ()
 #63 0x0000000000000000 in ?? ()
 #64 0x0000000000000000 in ?? ()
 #65 0x0000000000000000 in ?? ()
 #66 0x0000000000000000 in ?? ()
 #67 0x0000000000000000 in ?? ()
 #68 0x0000000000000000 in ?? ()
 #69 0x0000000000000000 in ?? ()
 #70 0x0000000000000000 in ?? ()
 ---Type <return> to continue, or q <return> to quit---
 #71 0x0000000000000000 in ?? ()
 #72 0x0000000000000000 in ?? ()
 #73 0x0000000000000000 in ?? ()
 #74 0x0000000000000000 in ?? ()
 #75 0x0000000000000000 in ?? ()
 #76 0x0000000000000000 in ?? ()
 #77 0x0000000000000000 in ?? ()
 #78 0x0000000000000000 in ?? ()
 #79 0x0000000000000000 in ?? ()
 #80 0x0000000000000000 in ?? ()
 #81 0x0000000000000000 in ?? ()
 #82 0x0000000000000000 in ?? ()
 #83 0x0000000000000000 in ?? ()
 #84 0x0000000000000000 in ?? ()
 #85 0x0000000000000000 in ?? ()
 #86 0x0000000000000000 in ?? ()
 #87 0x0000000000000000 in ?? ()
 #88 0x0000000000000000 in ?? ()
 #89 0x0000000000000000 in ?? ()
 #90 0x0000000000000000 in ?? ()
 #91 0x0000000000000000 in ?? ()
 #92 0x0000000000000000 in ?? ()
 #93 0x0000000000000000 in ?? ()
 #94 0x0000000000000000 in ?? ()
 #95 0x0000000000000000 in ?? ()
 #96 0x0000000000000000 in ?? ()
 #97 0x0000000000000000 in ?? ()
 #98 0x0000000000000000 in ?? ()
 #99 0x0000000000000000 in ?? ()
 #100 0x0000000000000000 in ?? ()
 #101 0x0000000000000000 in ?? ()
 #102 0x0000000000000000 in ?? ()
 #103 0x0000000000000000 in ?? ()
 #104 0x0000000000000000 in ?? ()
 #105 0x0000000000000000 in ?? ()
 #106 0x0000000000000000 in ?? ()
 #107 0x0000000000000000 in ?? ()
 #108 0x0000000000000000 in ?? ()
 #109 0x0000000000000000 in ?? ()
 ---Type <return> to continue, or q <return> to quit---
 #110 0x0000000000000000 in ?? ()
 #111 0x0000000000000000 in ?? ()
 #112 0x0000000000000000 in ?? ()
 #113 0x0000000000000000 in ?? ()
 #114 0x0000000000000000 in ?? ()
 #115 0x0000000000000000 in ?? ()
 #116 0x0000000000000000 in ?? ()
 #117 0x0000000000000000 in ?? ()
 Cannot access memory at address 0xffffffffac26d000
 

From: Kirk Strauser <kirk@strauser.com>
To: bug-followup@FreeBSD.org,
 kirk@strauser.com
Cc:  
Subject: Re: kern/128452: [sa] [panic] Accessing SCSI tape drive randomly crashes my amd64 system
Date: Sun, 9 Nov 2008 11:16:30 -0600

 I got another panic this morning when starting an Amanda "flush" from  
 disk to tape.  I had recompiled the kernel with SCHED_4BSD instead of  
 SCHED_ULE for testing.  Also, I've run memtest on this system for 8+  
 hours straight with no RAM errors.
 
 # kgdb /boot/kernel/kernel /var/crash/vmcore.10
 GNU gdb 6.1.1 [FreeBSD]
 Copyright 2004 Free Software Foundation, Inc.
 GDB is free software, covered by the GNU General Public License, and  
 you are
 welcome to change it and/or distribute copies of it under certain  
 conditions.
 Type "show copying" to see the conditions.
 There is absolutely no warranty for GDB.  Type "show warranty" for  
 details.
 This GDB was configured as "amd64-marcel-freebsd"...
 
 Unread portion of the kernel message buffer:
 
 
 Fatal trap 12: page fault while in kernel mode
 cpuid = 0; apic id = 00
 fault virtual address	= 0x258
 fault code		= supervisor read data, page not present
 instruction pointer	= 0x8:0xffffffff8047d41a
 stack pointer	        = 0x10:0xffffffffaef6cac0
 frame pointer	        = 0x10:0xffffff000443aa50
 code segment		= base 0x0, limit 0xfffff, type 0x1b
 			= DPL 0, pres 1, long 1, def32 0, gran 1
 processor eflags	= interrupt enabled, resume, IOPL = 0
 current process		= 50 (syncer)
 trap number		= 12
 panic: page fault
 cpuid = 0
 Uptime: 2d16h27m41s
 Physical memory: 6130 MB
 Dumping 675 MB: 660 644 628 612 596 580 564 548 532 516 500 484 468  
 452 436 420 404 388 372 356 340 324 308 292 276 260 244 228 212 196  
 180 164 148 132 116 100 84 68 52 36 20 4
 
 Reading symbols from /boot/kernel/if_re.ko...Reading symbols from / 
 boot/kernel/if_re.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/if_re.ko
 Reading symbols from /boot/kernel/coretemp.ko...Reading symbols from / 
 boot/kernel/coretemp.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/coretemp.ko
 Reading symbols from /boot/kernel/cpufreq.ko...Reading symbols from / 
 boot/kernel/cpufreq.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/cpufreq.ko
 Reading symbols from /boot/kernel/pflog.ko...Reading symbols from / 
 boot/kernel/pflog.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/pflog.ko
 Reading symbols from /boot/kernel/pf.ko...Reading symbols from /boot/ 
 kernel/pf.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/pf.ko
 Reading symbols from /boot/kernel/linux.ko...Reading symbols from / 
 boot/kernel/linux.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/linux.ko
 Reading symbols from /boot/kernel/nullfs.ko...Reading symbols from / 
 boot/kernel/nullfs.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/nullfs.ko
 Reading symbols from /boot/kernel/fdescfs.ko...Reading symbols from / 
 boot/kernel/fdescfs.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/fdescfs.ko
 Reading symbols from /boot/kernel/accf_http.ko...Reading symbols from / 
 boot/kernel/accf_http.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/accf_http.ko
 Reading symbols from /boot/kernel/green_saver.ko...Reading symbols  
 from /boot/kernel/green_saver.ko.symbols...done.
 done.
 Loaded symbols for /boot/kernel/green_saver.ko
 #0  doadump () at pcpu.h:195
 195	pcpu.h: No such file or directory.
 	in pcpu.h
 (kgdb) list *0xffffffff8047d41a
 0xffffffff8047d41a is in _mtx_lock_sleep (/usr/src/sys/kern/ 
 kern_mutex.c:341).
 336			 */
 337			v = m->mtx_lock;
 338			if (v != MTX_UNOWNED) {
 339				owner = (struct thread *)(v & ~MTX_FLAGMASK);
 340	#ifdef ADAPTIVE_GIANT
 341				if (TD_IS_RUNNING(owner)) {
 342	#else
 343				if (m != &Giant && TD_IS_RUNNING(owner)) {
 344	#endif
 345					if (LOCK_LOG_TEST(&m->lock_object, 0))
 (kgdb) backtrace
 #0  doadump () at pcpu.h:195
 #1  0x0000000000000004 in ?? ()
 #2  0xffffffff80488821 in boot (howto=260) at /usr/src/sys/kern/ 
 kern_shutdown.c:418
 #3  0xffffffff80488c5c in panic (fmt=0x104 <Address 0x104 out of  
 bounds>) at /usr/src/sys/kern/kern_shutdown.c:574
 #4  0xffffffff8073f1aa in trap_fatal (frame=0xffffff000443aa50,  
 eva=Variable "eva" is not available.
 ) at /usr/src/sys/amd64/amd64/trap.c:764
 #5  0xffffffff8073f551 in trap_pfault (frame=0xffffffffaef6ca10,  
 usermode=0) at /usr/src/sys/amd64/amd64/trap.c:680
 #6  0xffffffff8073fe0f in trap (frame=0xffffffffaef6ca10) at /usr/src/ 
 sys/amd64/amd64/trap.c:449
 #7  0xffffffff8072685e in calltrap () at /usr/src/sys/amd64/amd64/ 
 exception.S:209
 #8  0xffffffff8047d41a in _mtx_lock_sleep (m=0xffffff003c1b74d8,  
 tid=18446742974269467216, opts=Variable "opts" is not available.
 ) at /usr/src/sys/kern/kern_mutex.c:339
 #9  0xffffffff804ff4e2 in vfs_msync (mp=0xffffff000445aa68, flags=2)  
 at /usr/src/sys/kern/vfs_subr.c:2976
 #10 0xffffffff804ff73b in sync_fsync (ap=Variable "ap" is not available.
 ) at /usr/src/sys/kern/vfs_subr.c:3225
 #11 0xffffffff804ffebc in sched_sync () at vnode_if.h:538
 #12 0xffffffff80468efd in fork_exit (callout=0xffffffff804ff8a7  
 <sched_sync>, arg=0x0, frame=0xffffffffaef6cc80)
      at /usr/src/sys/kern/kern_fork.c:804
 #13 0xffffffff80726c2e in fork_trampoline () at /usr/src/sys/amd64/ 
 amd64/exception.S:455
 #14 0x0000000000000000 in ?? ()
 #15 0x0000000000000000 in ?? ()
 #16 0x0000000000000001 in ?? ()
 #17 0x0000000000000000 in ?? ()
 #18 0x0000000000000000 in ?? ()
 #19 0x0000000000000000 in ?? ()
 #20 0x0000000000000000 in ?? ()
 #21 0x0000000000000000 in ?? ()
 #22 0x0000000000000000 in ?? ()
 #23 0x0000000000000000 in ?? ()
 #24 0x0000000000000000 in ?? ()
 #25 0x0000000000000000 in ?? ()
 #26 0x0000000000000000 in ?? ()
 #27 0x0000000000000000 in ?? ()
 #28 0x0000000000000000 in ?? ()
 #29 0x0000000000000000 in ?? ()
 #30 0x0000000000000000 in ?? ()
 #31 0x0000000000000000 in ?? ()
 #32 0x0000000000000000 in ?? ()
 #33 0x0000000000000000 in ?? ()
 #34 0x0000000000000000 in ?? ()
 #35 0x0000000000000000 in ?? ()
 #36 0x0000000000000000 in ?? ()
 #37 0x0000000000000000 in ?? ()
 #38 0x0000000000d04000 in ?? ()
 #39 0x0000000000000002 in ?? ()
 #40 0x0000000000000000 in ?? ()
 #41 0xffffff00044428f0 in ?? ()
 #42 0xffffff00044afa50 in ?? ()
 #43 0xffffff000443aa50 in ?? ()
 #44 0xffffffffaef6ca28 in ?? ()
 #45 0xffffff000443aa50 in ?? ()
 #46 0xffffffff804a7246 in sched_switch (td=0x0,  
 newtd=0xffffffff804ff8a7, flags=1) at /usr/src/sys/kern/sched_4bsd.c:910
 #47 0x0000000000000000 in ?? ()
 #48 0x0000000000000000 in ?? ()
 #49 0x0000000000000000 in ?? ()
 #50 0x0000000000000000 in ?? ()
 #51 0x0000000000000000 in ?? ()
 #52 0x0000000000000000 in ?? ()
 #53 0x0000000000000000 in ?? ()
 #54 0x0000000000000000 in ?? ()
 #55 0x0000000000000000 in ?? ()
 #56 0x0000000000000000 in ?? ()
 #57 0x0000000000000000 in ?? ()
 #58 0x0000000000000000 in ?? ()
 #59 0x0000000000000000 in ?? ()
 #60 0x0000000000000000 in ?? ()
 #61 0x0000000000000000 in ?? ()
 #62 0x0000000000000000 in ?? ()
 #63 0x0000000000000000 in ?? ()
 #64 0x0000000000000000 in ?? ()
 #65 0x0000000000000000 in ?? ()
 #66 0x0000000000000000 in ?? ()
 #67 0x0000000000000000 in ?? ()
 #68 0x0000000000000000 in ?? ()
 #69 0x0000000000000000 in ?? ()
 #70 0x0000000000000000 in ?? ()
 #71 0x0000000000000000 in ?? ()
 #72 0x0000000000000000 in ?? ()
 #73 0x0000000000000000 in ?? ()
 #74 0x0000000000000000 in ?? ()
 #75 0x0000000000000000 in ?? ()
 #76 0x0000000000000000 in ?? ()
 #77 0x0000000000000000 in ?? ()
 #78 0x0000000000000000 in ?? ()
 #79 0x0000000000000000 in ?? ()
 #80 0x0000000000000000 in ?? ()
 #81 0x0000000000000000 in ?? ()
 #82 0x0000000000000000 in ?? ()
 #83 0x0000000000000000 in ?? ()
 #84 0x0000000000000000 in ?? ()
 #85 0x0000000000000000 in ?? ()
 #86 0x0000000000000000 in ?? ()
 #87 0x0000000000000000 in ?? ()
 #88 0x0000000000000000 in ?? ()
 #89 0x0000000000000000 in ?? ()
 #90 0x0000000000000000 in ?? ()
 #91 0x0000000000000000 in ?? ()
 #92 0x0000000000000000 in ?? ()
 #93 0x0000000000000000 in ?? ()
 #94 0x0000000000000000 in ?? ()
 #95 0x0000000000000000 in ?? ()
 #96 0x0000000000000000 in ?? ()
 #97 0x0000000000000000 in ?? ()
 #98 0x0000000000000000 in ?? ()
 #99 0x0000000000000000 in ?? ()
 #100 0x0000000000000000 in ?? ()
 #101 0x0000000000000000 in ?? ()
 #102 0x0000000000000000 in ?? ()
 #103 0x0000000000000000 in ?? ()
 #104 0x0000000000000000 in ?? ()
 #105 0x0000000000000000 in ?? ()
 #106 0x0000000000000000 in ?? ()
 #107 0x0000000000000000 in ?? ()
 #108 0x0000000000000000 in ?? ()
 #109 0x0000000000000000 in ?? ()
 #110 0x0000000000000000 in ?? ()
 #111 0x0000000000000000 in ?? ()
 #112 0x0000000000000000 in ?? ()
 #113 0x0000000000000000 in ?? ()
 #114 0x0000000000000000 in ?? ()
 #115 0x0000000000000000 in ?? ()
 #116 0x0000000000000000 in ?? ()
 #117 0x0000000000000000 in ?? ()
 #118 0x0000000000000000 in ?? ()
 Cannot access memory at address 0xffffffffaef6d000
 (kgdb) quit
 

From: Kirk Strauser <kirk@daycos.com>
To: bug-followup@freebsd.org,
 kirk@strauser.com
Cc:  
Subject: Re: kern/128452: [sa] [panic] Accessing SCSI tape drive randomly crashes my amd64 system
Date: Mon, 17 Nov 2008 09:32:58 -0600

 I don't wish to pester, but is anyone actually looking at these?  If so, 
 should I continue submitting dumps, or do you already have what you need?  Is 
 there anything else I can provide?
 

From: Kirk Strauser <kirk@daycos.com>
To: bug-followup@freebsd.org,
 kirk@strauser.com
Cc:  
Subject: Re: kern/128452: [sa] [panic] Accessing SCSI tape drive randomly crashes my amd64 system
Date: Wed, 19 Nov 2008 09:33:33 -0600

 You can close this bug.  I replaced the card with an Adaptec 29160 and it's 
 been working perfectly ever since.  In all fairness, though, the old cards 
 (Tekram DC390F) should be removed from the list of supported hardware since 
 they are no longer functional under FreeBSD 7.
State-Changed-From-To: open->closed 
State-Changed-By: sbruno 
State-Changed-When: Tue May 7 14:24:58 UTC 2013 
State-Changed-Why:  
Requestor worked around issue by replacing his Tekram card with an Adaptect 29160. 

Too bad we never spent the time to look into this 5 years ago. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=128452 
>Unformatted:
