From nobody@FreeBSD.org  Wed Dec  4 02:25:35 2013
Return-Path: <nobody@FreeBSD.org>
Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1])
	(using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by hub.freebsd.org (Postfix) with ESMTPS id B78C6E7D
	for <freebsd-gnats-submit@FreeBSD.org>; Wed,  4 Dec 2013 02:25:35 +0000 (UTC)
Received: from oldred.freebsd.org (oldred.freebsd.org [8.8.178.121])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by mx1.freebsd.org (Postfix) with ESMTPS id 8B9741734
	for <freebsd-gnats-submit@FreeBSD.org>; Wed,  4 Dec 2013 02:25:35 +0000 (UTC)
Received: from oldred.freebsd.org ([127.0.1.6])
	by oldred.freebsd.org (8.14.5/8.14.7) with ESMTP id rB42PYi0082111
	for <freebsd-gnats-submit@FreeBSD.org>; Wed, 4 Dec 2013 02:25:34 GMT
	(envelope-from nobody@oldred.freebsd.org)
Received: (from nobody@localhost)
	by oldred.freebsd.org (8.14.5/8.14.5/Submit) id rB42PYkg082104;
	Wed, 4 Dec 2013 02:25:34 GMT
	(envelope-from nobody)
Message-Id: <201312040225.rB42PYkg082104@oldred.freebsd.org>
Date: Wed, 4 Dec 2013 02:25:34 GMT
From: Alex Wilkinson <alex.wilkinson@cba.com.au>
To: freebsd-gnats-submit@FreeBSD.org
Subject: pfioctl causing kernel panics in 10-BETA{3,4}
X-Send-Pr-Version: www-3.1
X-GNATS-Notify:

>Number:         184485
>Category:       kern
>Synopsis:       [pf] pfioctl causing kernel panics in 10-BETA{3,4}
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    glebius
>State:          feedback
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Wed Dec 04 02:30:01 UTC 2013
>Closed-Date:    
>Last-Modified:  Wed Dec 18 05:20:00 UTC 2013
>Originator:     Alex Wilkinson
>Release:        10.0-BETA4
>Organization:
>Environment:
FreeBSD hostname 10.0-BETA4 FreeBSD 10.0-BETA4 #0 r258860: Tue Dec  3 13:46:27 EST 2013     root@hostname:/usr/obj/usr/src/sys/MYCONFIG  amd64
>Description:
Every morning I arrive at at the ddb> prompt with a kernel panic. I have no clue what the trigger is. BT is:


(kgdb) bt
#0  doadump (textdump=1) at pcpu.h:219
#1  0xffffffff808c0005 in kern_reboot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:447
#2  0xffffffff808c03e4 in panic (fmt=<value optimized out>) at /usr/src/sys/kern/kern_shutdown.c:754
#3  0xffffffff80346077 in db_panic (addr=<value optimized out>, have_addr=<value optimized out>, count=<value optimized out>, modif=<value optimized out>) at /usr/src/sys/ddb/db_command.c:482
#4  0xffffffff80345c8d in db_command (cmd_table=<value optimized out>) at /usr/src/sys/ddb/db_command.c:449
#5  0xffffffff80345a04 in db_command_loop () at /usr/src/sys/ddb/db_command.c:502
#6  0xffffffff80348370 in db_trap (type=<value optimized out>, code=0) at /usr/src/sys/ddb/db_main.c:231
#7  0xffffffff808f9563 in kdb_trap (type=12, code=0, tf=<value optimized out>) at /usr/src/sys/kern/subr_kdb.c:656
#8  0xffffffff80cf0612 in trap_fatal (frame=0xfffffe085bdeba60, eva=<value optimized out>) at /usr/src/sys/amd64/amd64/trap.c:877
#9  0xffffffff80cf0929 in trap_pfault (frame=0xfffffe085bdeba60, usermode=0) at /usr/src/sys/amd64/amd64/trap.c:699
#10 0xffffffff80cf00b6 in trap (frame=0xfffffe085bdeba60) at /usr/src/sys/amd64/amd64/trap.c:463
#11 0xffffffff80cd6e52 in calltrap () at /usr/src/sys/amd64/amd64/exception.S:232
#12 0xffffffff80aca5e3 in pfioctl (dev=0x2, cmd=<value optimized out>, addr=0xfffff803ec438000 "", flags=<value optimized out>, td=<value optimized out>) at /usr/src/sys/netpfil/pf/pf_ioctl.c:1289
#13 0xffffffff807b9d5f in devfs_ioctl_f (fp=0xfffff80014d474b0, com=3417850886, data=0xfffff803ec438000, cred=<value optimized out>, td=0xfffff80014e50920) at /usr/src/sys/fs/devfs/devfs_vnops.c:757
#14 0xffffffff80910a1e in kern_ioctl (td=0xfffff80014e50920, fd=<value optimized out>, com=2) at file.h:319
#15 0xffffffff8091079f in sys_ioctl (td=0xfffff80014e50920, uap=0xfffffe085bdeca40) at /usr/src/sys/kern/sys_generic.c:702
#16 0xffffffff80cf0f47 in amd64_syscall (td=0xfffff80014e50920, traced=0) at subr_syscall.c:134
#17 0xffffffff80cd713b in Xfast_syscall () at /usr/src/sys/amd64/amd64/exception.S:391
#18 0x0000000800dbac2a in ?? ()
Previous frame inner to this frame (corrupt stack?)
Current language:  auto; currently minimal


>How-To-Repeat:
who knows ...
>Fix:
no clue ...

>Release-Note:
>Audit-Trail:
Responsible-Changed-From-To: freebsd-amd64->freebsd-pf 
Responsible-Changed-By: linimon 
Responsible-Changed-When: Mon Dec 9 00:01:37 UTC 2013 
Responsible-Changed-Why:  
reclassify. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=184485 
State-Changed-From-To: open->feedback 
State-Changed-By: glebius 
State-Changed-When: Wed Dec 18 05:01:09 UTC 2013 
State-Changed-Why:  
Submitter asked for feedback. 


Responsible-Changed-From-To: freebsd-pf->glebius 
Responsible-Changed-By: glebius 
Responsible-Changed-When: Wed Dec 18 05:01:09 UTC 2013 
Responsible-Changed-Why:  
I'm going to fix that. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=184485 

From: Gleb Smirnoff <glebius@glebius.int.ru>
To: Alex Wilkinson <alex.wilkinson@cba.com.au>
Cc: freebsd-gnats-submit@FreeBSD.org
Subject: Re: kern/184485
Date: Wed, 18 Dec 2013 09:15:44 +0400

   Alex,
 
   can you please obtain and share crashdump for the panic?
 
 -- 
 Totus tuus, Glebius.
>Unformatted:
