From root@imul.math.uni.lodz.pl  Mon Apr  3 22:39:23 2006
Return-Path: <root@imul.math.uni.lodz.pl>
Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125])
	by hub.freebsd.org (Postfix) with ESMTP id 5925F16A41F
	for <FreeBSD-gnats-submit@freebsd.org>; Mon,  3 Apr 2006 22:39:23 +0000 (UTC)
	(envelope-from root@imul.math.uni.lodz.pl)
Received: from imul.math.uni.lodz.pl (imul.math.uni.lodz.pl [212.191.65.2])
	by mx1.FreeBSD.org (Postfix) with ESMTP id BD32143D6A
	for <FreeBSD-gnats-submit@freebsd.org>; Mon,  3 Apr 2006 22:39:22 +0000 (GMT)
	(envelope-from root@imul.math.uni.lodz.pl)
Received: by imul.math.uni.lodz.pl (Postfix, from userid 0)
	id 1933E37583D; Tue,  4 Apr 2006 00:38:33 +0200 (CEST)
Message-Id: <20060403223833.1933E37583D@imul.math.uni.lodz.pl>
Date: Tue,  4 Apr 2006 00:38:33 +0200 (CEST)
From: Marcin Gryszkalis <mg@fork.pl>
Reply-To: Marcin Gryszkalis <mg@fork.pl>
To: FreeBSD-gnats-submit@freebsd.org
Cc: mg@math.ui.lodz.pl
Subject: panic in sys/kern/tty_subr.c putc()	
X-Send-Pr-Version: 3.113
X-GNATS-Notify: joe518psu@yahoo.com

>Number:         95288
>Category:       kern
>Synopsis:       [pppd] [tty] [panic] if_ppp panic in sys/kern/tty_subr.c putc()
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    freebsd-net
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Mon Apr 03 22:40:13 GMT 2006
>Closed-Date:    
>Last-Modified:  Wed Mar 19 10:42:37 UTC 2008
>Originator:     Marcin Gryszkalis
>Release:        FreeBSD 6.1-PRERELEASE i386
>Organization:
>Environment:
System: FreeBSD imul.math.uni.lodz.pl 6.1-PRERELEASE FreeBSD 6.1-PRERELEASE #9: Fri Mar 24 09:41:54 CET 2006 root@imul.math.uni.lodz.pl:/usr/obj/usr/src/sys/imul i386


	
>Description:

	I got panic during ppp connection, the backtrace is:

#0  doadump () at pcpu.h:165
#1  0xc04ff027 in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:402
#2  0xc04ff369 in panic (fmt=0xc06b308b "%s") at /usr/src/sys/kern/kern_shutdown.c:558
#3  0xc06899bc in trap_fatal (frame=0xd43bda80, eva=0) at /usr/src/sys/i386/i386/trap.c:836
#4  0xc0689692 in trap_pfault (frame=0xd43bda80, usermode=0, eva=6) at /usr/src/sys/i386/i386/trap.c:744
#5  0xc068924f in trap (frame=
      {tf_fs = -1017249784, tf_es = 40, tf_ds = 4915240, tf_edi = 209, tf_esi = -1019750344, tf_ebp = -734274864, tf_isp = -734274900, tf_ebx = 0, tf_edx = 2, tf_ecx = 5, tf_eax = -33, tf_trapno = 12, tf_err = 2, tf_eip = -1068239194, tf_cs = 32, tf_eflags = 590343, tf_esp = 0, tf_ss = -734274812}) at /usr/src/sys/i386/i386/trap.c:434
#6  0xc067622a in calltrap () at /usr/src/sys/i386/i386/exception.s:139
#7  0xc053f6a6 in putc (chr=209, clistp=0xc337d838) at /usr/src/sys/kern/tty_subr.c:416
#8  0xc05924cd in pppasyncstart (sc=0xc39c7400) at /usr/src/sys/net/ppp_tty.c:649
#9  0xc058c64d in pppoutput (ifp=0xc33d2800, m0=0xc35b4a00, dst=0xd43bdb88, rtp=0xc3563528) at /usr/src/sys/net/if_ppp.c:961
#10 0xc05b0907 in ip_output (m=0xc35b4a00, opt=0xc33d2800, ro=0xd43bdb84, flags=1, imo=0x0, inp=0x0) at /usr/src/sys/netinet/ip_output.c:777
#11 0xc05afc00 in ip_forward (m=0xc35b4a00, srcrt=0) at /usr/src/sys/netinet/ip_input.c:1907
#12 0xc05ae32c in ip_input (m=0xc35b4a00) at /usr/src/sys/netinet/ip_input.c:689
#13 0xc05917c9 in netisr_processqueue (ni=0xc0717ad8) at /usr/src/sys/net/netisr.c:236
#14 0xc0591a2f in swi_net (dummy=0x0) at /usr/src/sys/net/netisr.c:349
#15 0xc04e4918 in ithread_execute_handlers (p=0xc32a7830, ie=0xc32e5280) at /usr/src/sys/kern/kern_intr.c:673
#16 0xc04e4a86 in ithread_loop (arg=0xc3291720) at /usr/src/sys/kern/kern_intr.c:756
#17 0xc04e346f in fork_exit (callout=0xc04e4a10 <ithread_loop>, arg=0xffffffdf, frame=0xffffffdf) at /usr/src/sys/kern/kern_fork.c:805
#18 0xc067628c in fork_trampoline () at /usr/src/sys/i386/i386/exception.s:208

	The problem seems to be here:

(kgdb) frame 7
#7  0xc053f6a6 in putc (chr=209, clistp=0xc337d838) at /usr/src/sys/kern/tty_subr.c:416
416                     clrbit(cblockp->c_quote, clistp->c_cl - (char *)cblockp->c_info);

(kgdb) p cblockp
$1 = (struct cblock *) 0x0


	Additional info

(kgdb) p chr
$2 = 209

(kgdb) p *clistp
$6 = {c_cc = 41, c_cbcount = 0, c_cbmax = 19, c_cbreserved = 19, c_cf = 0x0, c_cl = 0x29 <Address 0x29 out of bounds>}

(kgdb) frame 8
#8  0xc05924cd in pppasyncstart (sc=0xc39c7400) at /usr/src/sys/net/ppp_tty.c:649
649                         if (putc(*q, &tp->t_outq)) {

(kgdb) p *tp
$10 = {t_rawq = {c_cc = 0, c_cbcount = 0, c_cbmax = 0, c_cbreserved = 0, c_cf = 0x0, c_cl = 0x0}, t_rawcc = 6812, t_canq = {c_cc = 0, c_cbcount = 0, c_cbmax = 1,
    c_cbreserved = 1, c_cf = 0x0, c_cl = 0x0}, t_cancc = 14, t_outq = {c_cc = 41, c_cbcount = 0, c_cbmax = 19, c_cbreserved = 19, c_cf = 0x0,
    c_cl = 0x29 <Address 0x29 out of bounds>}, t_outcc = 2394, t_line = 5, t_dev = 0xc3897500, t_mdev = 0xc3922100, t_devunit = 2, t_state = 131112, t_flags = 0,
  t_timeout = 300000, t_pgrp = 0xc5935600, t_session = 0xc3a33880, t_sigio = 0x0, t_rsel = {si_thrlist = {tqe_next = 0x0, tqe_prev = 0xc51e2330}, si_thread = 0xc51e2300,
    si_note = {kl_list = {slh_first = 0x0}, kl_lock = 0xc04dc960 <knlist_mtx_lock>, kl_unlock = 0xc04dc9c0 <knlist_mtx_unlock>, kl_locked = 0xc04dca20 <knlist_mtx_locked>,
      kl_lockarg = 0xc337d9ec}, si_flags = 0}, t_wsel = {si_thrlist = {tqe_next = 0x0, tqe_prev = 0x0}, si_thread = 0x0, si_note = {kl_list = {slh_first = 0x0},
      kl_lock = 0xc04dc960 <knlist_mtx_lock>, kl_unlock = 0xc04dc9c0 <knlist_mtx_unlock>, kl_locked = 0xc04dca20 <knlist_mtx_locked>, kl_lockarg = 0xc337d9ec}, si_flags = 0},
  t_termios = {c_iflag = 5, c_oflag = 0, c_cflag = 215808, c_lflag = 0, c_cc = "\004\000\177\027\025\022\b\003\034\032\031\021\023\026\017\001\000\024", c_ispeed = 57600,
    c_ospeed = 57600}, t_init_in = {c_iflag = 11010, c_oflag = 3, c_cflag = 19200, c_lflag = 1408,
    c_cc = "\004\177\027\025\022\b\003\034\032\031\021\023\026\017\001\000\024", c_ispeed = 9600, c_ospeed = 9600}, t_init_out = {c_iflag = 11010, c_oflag = 3,
    c_cflag = 19200, c_lflag = 1408, c_cc = "\004\177\027\025\022\b\003\034\032\031\021\023\026\017\001\000\024", c_ispeed = 9600, c_ospeed = 9600}, t_lock_in = {c_iflag = 0,
    c_oflag = 0, c_cflag = 0, c_lflag = 0, c_cc = '\0' <repeats 19 times>, c_ispeed = 0, c_ospeed = 0}, t_lock_out = {c_iflag = 0, c_oflag = 0, c_cflag = 0, c_lflag = 0,
    c_cc = '\0' <repeats 19 times>, c_ispeed = 0, c_ospeed = 0}, t_winsize = {ws_row = 0, ws_col = 0, ws_xpixel = 0, ws_ypixel = 0}, t_sc = 0xc37e0800, t_lsc = 0xc39c7400,
  t_column = 39, t_rocount = 0, t_rocol = 0, t_ififosize = 512, t_ihiwat = 7680, t_ilowat = 6720, t_ispeedwat = 0, t_ohiwat = 2052, t_olowat = 256, t_ospeedwat = 0, t_gen = 29,
  t_list = {tqe_next = 0xc3392400, tqe_prev = 0xc33b5ddc}, t_actout = 1, t_wopeners = 0, t_mtx = {mtx_object = {lo_class = 0xc06edda4, lo_name = 0xc06bf0b1 "tty",
      lo_type = 0xc06bf0b1 "tty", lo_flags = 196608, lo_list = {tqe_next = 0x0, tqe_prev = 0x0}, lo_witness = 0x0}, mtx_lock = 4, mtx_recurse = 0}, t_refcnt = 3,
  t_hotchar = 126, t_dtr_wait = 3000, t_do_timestamp = 0, t_timestamp = {tv_sec = 0, tv_usec = 0}, t_pps = 0x0, t_oproc = 0xc048f070 <ucomstart>, t_stop = 0xc048f360 <ucomstop>,
  t_param = 0xc048eed0 <ucomparam>, t_modem = 0xc048ebf0 <ucommodem>, t_break = 0xc048ecd0 <ucombreak>, t_ioctl = 0xc048eb60 <ucomioctl>, t_open = 0xc048e8a0 <ucomopen>,
  t_purge = 0, t_close = 0xc048eae0 <ucomclose>, t_cioctl = 0}

	
>How-To-Repeat:
	Happened just once (~100 ppp connections established so far on this box), bug may be related to USB-serial driver (as you can see above this modem is connected via ucom).

>Fix:

	


>Release-Note:
>Audit-Trail:

From: Kris Kennaway <kris@obsecurity.org>
To: Marcin Gryszkalis <mg@fork.pl>
Cc: FreeBSD-gnats-submit@FreeBSD.org, mg@math.ui.lodz.pl
Subject: Re: kern/95288: panic in sys/kern/tty_subr.c putc()
Date: Mon, 3 Apr 2006 18:45:41 -0400

 --+HP7ph2BbKc20aGI
 Content-Type: text/plain; charset=us-ascii
 Content-Disposition: inline
 
 On Tue, Apr 04, 2006 at 12:38:33AM +0200, Marcin Gryszkalis wrote:
 
 > 	I got panic during ppp connection, the backtrace is:
 
 kernel ppp is known to be broken and is unlikely to be fixed any time
 soon, please use ppp(8) instead.
 
 Kris
 --+HP7ph2BbKc20aGI
 Content-Type: application/pgp-signature
 Content-Disposition: inline
 
 -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v1.4.2.2 (FreeBSD)
 
 iD8DBQFEMaWVWry0BWjoQKURAkJRAJ9DRYLXobH4XSxXF0jfFs3IqqEEbwCfVWFc
 En2cSj5jTRAMfkQCC8oggDg=
 =MnKN
 -----END PGP SIGNATURE-----
 
 --+HP7ph2BbKc20aGI--

From: Robert Watson <rwatson@FreeBSD.org>
To: Marcin Gryszkalis <mg@fork.pl>
Cc: FreeBSD-gnats-submit@FreeBSD.org, mg@math.ui.lodz.pl,
	freebsd-bugs@FreeBSD.org
Subject: Re: kern/95288: panic in sys/kern/tty_subr.c putc()	
Date: Wed, 5 Apr 2006 16:20:21 +0100 (BST)

   This message is in MIME format.  The first part should be readable text,
   while the remaining parts are likely unreadable without MIME-aware tools.
 
 --0-666368381-1144250421=:82516
 Content-Type: TEXT/PLAIN; charset=ISO-8859-1; format=flowed
 Content-Transfer-Encoding: QUOTED-PRINTABLE
 
 
 
 On Tue, 4 Apr 2006, Marcin Gryszkalis wrote:
 
 > =09I got panic during ppp connection, the backtrace is:
 
 You want to update to a slightly more recent RELENG_6 to catch the followin=
 g=20
 change, which may help:
 
    revision 1.105.2.3
    date: 2006/04/02 11:10:38;  author: rwatson;  state: Exp;  lines: +1 -1
    Merge if_ppp.c:1.113 from HEAD to RELENG_6:
 
      Add IFF_NEEDSGIANT to kernel PPP support.  I have no idea why this was=
 n't
      here, but it should have been.
 
    Approved by:    re (hrs)
 
 It looks like your RELENG_6 snapshot is about a week before this change wen=
 t=20
 in.
 
 Robert N M Watson
 
 >
 > #0  doadump () at pcpu.h:165
 > #1  0xc04ff027 in boot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c=
 :402
 > #2  0xc04ff369 in panic (fmt=3D0xc06b308b "%s") at /usr/src/sys/kern/kern=
 _shutdown.c:558
 > #3  0xc06899bc in trap_fatal (frame=3D0xd43bda80, eva=3D0) at /usr/src/sy=
 s/i386/i386/trap.c:836
 > #4  0xc0689692 in trap_pfault (frame=3D0xd43bda80, usermode=3D0, eva=3D6)=
  at /usr/src/sys/i386/i386/trap.c:744
 > #5  0xc068924f in trap (frame=3D
 >      {tf_fs =3D -1017249784, tf_es =3D 40, tf_ds =3D 4915240, tf_edi =3D =
 209, tf_esi =3D -1019750344, tf_ebp =3D -734274864, tf_isp =3D -734274900, =
 tf_ebx =3D 0, tf_edx =3D 2, tf_ecx =3D 5, tf_eax =3D -33, tf_trapno =3D 12,=
  tf_err =3D 2, tf_eip =3D -1068239194, tf_cs =3D 32, tf_eflags =3D 590343, =
 tf_esp =3D 0, tf_ss =3D -734274812}) at /usr/src/sys/i386/i386/trap.c:434
 > #6  0xc067622a in calltrap () at /usr/src/sys/i386/i386/exception.s:139
 > #7  0xc053f6a6 in putc (chr=3D209, clistp=3D0xc337d838) at /usr/src/sys/k=
 ern/tty_subr.c:416
 > #8  0xc05924cd in pppasyncstart (sc=3D0xc39c7400) at /usr/src/sys/net/ppp=
 _tty.c:649
 > #9  0xc058c64d in pppoutput (ifp=3D0xc33d2800, m0=3D0xc35b4a00, dst=3D0xd=
 43bdb88, rtp=3D0xc3563528) at /usr/src/sys/net/if_ppp.c:961
 > #10 0xc05b0907 in ip_output (m=3D0xc35b4a00, opt=3D0xc33d2800, ro=3D0xd43=
 bdb84, flags=3D1, imo=3D0x0, inp=3D0x0) at /usr/src/sys/netinet/ip_output.c=
 :777
 > #11 0xc05afc00 in ip_forward (m=3D0xc35b4a00, srcrt=3D0) at /usr/src/sys/=
 netinet/ip_input.c:1907
 > #12 0xc05ae32c in ip_input (m=3D0xc35b4a00) at /usr/src/sys/netinet/ip_in=
 put.c:689
 > #13 0xc05917c9 in netisr_processqueue (ni=3D0xc0717ad8) at /usr/src/sys/n=
 et/netisr.c:236
 > #14 0xc0591a2f in swi_net (dummy=3D0x0) at /usr/src/sys/net/netisr.c:349
 > #15 0xc04e4918 in ithread_execute_handlers (p=3D0xc32a7830, ie=3D0xc32e52=
 80) at /usr/src/sys/kern/kern_intr.c:673
 > #16 0xc04e4a86 in ithread_loop (arg=3D0xc3291720) at /usr/src/sys/kern/ke=
 rn_intr.c:756
 > #17 0xc04e346f in fork_exit (callout=3D0xc04e4a10 <ithread_loop>, arg=3D0=
 xffffffdf, frame=3D0xffffffdf) at /usr/src/sys/kern/kern_fork.c:805
 > #18 0xc067628c in fork_trampoline () at /usr/src/sys/i386/i386/exception.=
 s:208
 >
 > =09The problem seems to be here:
 >
 > (kgdb) frame 7
 > #7  0xc053f6a6 in putc (chr=3D209, clistp=3D0xc337d838) at /usr/src/sys/k=
 ern/tty_subr.c:416
 > 416                     clrbit(cblockp->c_quote, clistp->c_cl - (char *)c=
 blockp->c_info);
 >
 > (kgdb) p cblockp
 > $1 =3D (struct cblock *) 0x0
 >
 >
 > =09Additional info
 >
 > (kgdb) p chr
 > $2 =3D 209
 >
 > (kgdb) p *clistp
 > $6 =3D {c_cc =3D 41, c_cbcount =3D 0, c_cbmax =3D 19, c_cbreserved =3D 19=
 , c_cf =3D 0x0, c_cl =3D 0x29 <Address 0x29 out of bounds>}
 >
 > (kgdb) frame 8
 > #8  0xc05924cd in pppasyncstart (sc=3D0xc39c7400) at /usr/src/sys/net/ppp=
 _tty.c:649
 > 649                         if (putc(*q, &tp->t_outq)) {
 >
 > (kgdb) p *tp
 > $10 =3D {t_rawq =3D {c_cc =3D 0, c_cbcount =3D 0, c_cbmax =3D 0, c_cbrese=
 rved =3D 0, c_cf =3D 0x0, c_cl =3D 0x0}, t_rawcc =3D 6812, t_canq =3D {c_cc=
  =3D 0, c_cbcount =3D 0, c_cbmax =3D 1,
 >    c_cbreserved =3D 1, c_cf =3D 0x0, c_cl =3D 0x0}, t_cancc =3D 14, t_out=
 q =3D {c_cc =3D 41, c_cbcount =3D 0, c_cbmax =3D 19, c_cbreserved =3D 19, c=
 _cf =3D 0x0,
 >    c_cl =3D 0x29 <Address 0x29 out of bounds>}, t_outcc =3D 2394, t_line =
 =3D 5, t_dev =3D 0xc3897500, t_mdev =3D 0xc3922100, t_devunit =3D 2, t_stat=
 e =3D 131112, t_flags =3D 0,
 >  t_timeout =3D 300000, t_pgrp =3D 0xc5935600, t_session =3D 0xc3a33880, t=
 _sigio =3D 0x0, t_rsel =3D {si_thrlist =3D {tqe_next =3D 0x0, tqe_prev =3D =
 0xc51e2330}, si_thread =3D 0xc51e2300,
 >    si_note =3D {kl_list =3D {slh_first =3D 0x0}, kl_lock =3D 0xc04dc960 <=
 knlist_mtx_lock>, kl_unlock =3D 0xc04dc9c0 <knlist_mtx_unlock>, kl_locked =
 =3D 0xc04dca20 <knlist_mtx_locked>,
 >      kl_lockarg =3D 0xc337d9ec}, si_flags =3D 0}, t_wsel =3D {si_thrlist =
 =3D {tqe_next =3D 0x0, tqe_prev =3D 0x0}, si_thread =3D 0x0, si_note =3D {k=
 l_list =3D {slh_first =3D 0x0},
 >      kl_lock =3D 0xc04dc960 <knlist_mtx_lock>, kl_unlock =3D 0xc04dc9c0 <=
 knlist_mtx_unlock>, kl_locked =3D 0xc04dca20 <knlist_mtx_locked>, kl_lockar=
 g =3D 0xc337d9ec}, si_flags =3D 0},
 >  t_termios =3D {c_iflag =3D 5, c_oflag =3D 0, c_cflag =3D 215808, c_lflag=
  =3D 0, c_cc =3D "\004\000=FF\177\027\025\022\b\003\034\032\031\021\023\026=
 \017\001\000\024=FF", c_ispeed =3D 57600,
 >    c_ospeed =3D 57600}, t_init_in =3D {c_iflag =3D 11010, c_oflag =3D 3, =
 c_cflag =3D 19200, c_lflag =3D 1408,
 >    c_cc =3D "\004=FF=FF\177\027\025\022\b\003\034\032\031\021\023\026\017=
 \001\000\024=FF", c_ispeed =3D 9600, c_ospeed =3D 9600}, t_init_out =3D {c_=
 iflag =3D 11010, c_oflag =3D 3,
 >    c_cflag =3D 19200, c_lflag =3D 1408, c_cc =3D "\004=FF=FF\177\027\025\=
 022\b\003\034\032\031\021\023\026\017\001\000\024=FF", c_ispeed =3D 9600, c=
 _ospeed =3D 9600}, t_lock_in =3D {c_iflag =3D 0,
 >    c_oflag =3D 0, c_cflag =3D 0, c_lflag =3D 0, c_cc =3D '\0' <repeats 19=
  times>, c_ispeed =3D 0, c_ospeed =3D 0}, t_lock_out =3D {c_iflag =3D 0, c_=
 oflag =3D 0, c_cflag =3D 0, c_lflag =3D 0,
 >    c_cc =3D '\0' <repeats 19 times>, c_ispeed =3D 0, c_ospeed =3D 0}, t_w=
 insize =3D {ws_row =3D 0, ws_col =3D 0, ws_xpixel =3D 0, ws_ypixel =3D 0}, =
 t_sc =3D 0xc37e0800, t_lsc =3D 0xc39c7400,
 >  t_column =3D 39, t_rocount =3D 0, t_rocol =3D 0, t_ififosize =3D 512, t_=
 ihiwat =3D 7680, t_ilowat =3D 6720, t_ispeedwat =3D 0, t_ohiwat =3D 2052, t=
 _olowat =3D 256, t_ospeedwat =3D 0, t_gen =3D 29,
 >  t_list =3D {tqe_next =3D 0xc3392400, tqe_prev =3D 0xc33b5ddc}, t_actout =
 =3D 1, t_wopeners =3D 0, t_mtx =3D {mtx_object =3D {lo_class =3D 0xc06edda4=
 , lo_name =3D 0xc06bf0b1 "tty",
 >      lo_type =3D 0xc06bf0b1 "tty", lo_flags =3D 196608, lo_list =3D {tqe_=
 next =3D 0x0, tqe_prev =3D 0x0}, lo_witness =3D 0x0}, mtx_lock =3D 4, mtx_r=
 ecurse =3D 0}, t_refcnt =3D 3,
 >  t_hotchar =3D 126, t_dtr_wait =3D 3000, t_do_timestamp =3D 0, t_timestam=
 p =3D {tv_sec =3D 0, tv_usec =3D 0}, t_pps =3D 0x0, t_oproc =3D 0xc048f070 =
 <ucomstart>, t_stop =3D 0xc048f360 <ucomstop>,
 >  t_param =3D 0xc048eed0 <ucomparam>, t_modem =3D 0xc048ebf0 <ucommodem>, =
 t_break =3D 0xc048ecd0 <ucombreak>, t_ioctl =3D 0xc048eb60 <ucomioctl>, t_o=
 pen =3D 0xc048e8a0 <ucomopen>,
 >  t_purge =3D 0, t_close =3D 0xc048eae0 <ucomclose>, t_cioctl =3D 0}
 >
 >
 >> How-To-Repeat:
 > =09Happened just once (~100 ppp connections established so far on this bo=
 x), bug may be related to USB-serial driver (as you can see above this mode=
 m is connected via ucom).
 >
 >> Fix:
 >
 >
 >
 >
 >> Release-Note:
 >> Audit-Trail:
 >> Unformatted:
 > _______________________________________________
 > freebsd-bugs@freebsd.org mailing list
 > http://lists.freebsd.org/mailman/listinfo/freebsd-bugs
 > To unsubscribe, send any mail to "freebsd-bugs-unsubscribe@freebsd.org"
 >
 --0-666368381-1144250421=:82516--
Responsible-Changed-From-To: freebsd-bugs->freebsd-net 
Responsible-Changed-By: gavin 
Responsible-Changed-When: Wed Mar 19 10:22:10 UTC 2008 
Responsible-Changed-Why:  
Over to -net, this looks to me like it may be an issue with in-kernel PPP. 
Note that the issue still exists with 7.0-RELEASE, see PR i386/121853. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=95288 
>Unformatted:
