Subject: Panic: amap_wipeout: corrupt amap
To: NetBSD current-users <current-users@NetBSD.org>
From: Bjoern Labitzke <bcsl@gmx.de>
List: current-users
Date: 03/23/2003 20:51:59
Hi...

For a few weeks I get a reproducable panic on shutdown. If nobody
knows how to fix this at once, I will send-pr it.

System: Pentium-II, 128 MB RAM
        NetBSD-current (updated frequently; the problems started after
        one rebuild (sorry, do not know the date) and persists even
        after several updates of the kernel)
        XFree 4.3.0

The scenario: shutdown the machine. As soon as /etc/rc.d/xfs stop is
run, the machine hangs with a panic: amap_wipeout: corrupt amap. This
is 100% reproducable. (At least the panic at shutdown is reproducable
and at least once after running /etc/rc.d/xfs stop manually.)

Here is a backtrace:

(gdb) backtrace
#0  0x1 in ?? ()
#1  0xc0278132 in cpu_reboot (howto=260, bootstr=0x0)
    at /usr/src/sys/arch/i386/i386/machdep.c:863
#2  0xc01df67d in db_reboot_cmd () at /usr/src/sys/ddb/db_command.c:670
#3  0xc01df358 in db_command (last_cmdp=0xc037a86c, cmd_table=0xc0327a20)
    at /usr/src/sys/ddb/db_command.c:456
#4  0xc01def57 in db_command_loop () at /usr/src/sys/ddb/db_command.c:247
#5  0xc01e2a48 in db_trap (type=1, code=0) at /usr/src/sys/ddb/db_trap.c:97
#6  0xc0275c5d in kdb_trap (type=1, code=0, regs=0xd7b01e1c)
    at /usr/src/sys/arch/i386/i386/db_interface.c:224
#7  0xc027fc0b in trap (frame={tf_gs = 16, tf_fs = 48, tf_es = -676331504,
      tf_ds = 16, tf_edi = -1070388758, tf_esi = 256, tf_ebp = -676323748,
      tf_ebx = -676323704, tf_edx = 0, tf_ecx = 271, tf_eax = 6538,
      tf_trapno = 1, tf_err = 0, tf_eip = -1071162052, tf_cs = 8,
      tf_eflags = 514, tf_esp = -676323716, tf_ss = -1071573508,
      tf_vm86_es = 1, tf_vm86_ds = -673128404, tf_vm86_fs = 1169,
      tf_vm86_gs = -1071259779}) at /usr/src/sys/arch/i386/i386/trap.c:285
#8  0xc010610e in calltrap ()
#9  0xc02115fc in panic (fmt=0xc03329ea "amap_wipeout: corrupt amap")
    at /usr/src/sys/kern/subr_prf.c:230
#10 0xc025d847 in amap_wipeout (amap=0xd7e0e02c)
    at /usr/src/sys/uvm/uvm_amap.c:668
#11 0xc025cecf in amap_unref (amap=0xd7e0e02c, offset=0, len=1169, all=0)
    at /usr/src/sys/uvm/uvm_amap_i.h:257
#12 0xc0264d2b in uvm_unmap_detach (first_entry=0xd7b0dbc0, flags=0)
    at /usr/src/sys/uvm/uvm_map.c:328
#13 0xc0266ae2 in uvmspace_free (vm=0xd7adc240)
    at /usr/src/sys/uvm/uvm_map.c:3168
#14 0xc0261ac4 in uvm_proc_exit (p=0xd7b06684)
    at /usr/src/sys/uvm/uvm_glue.c:353
#15 0xc01f91f9 in reaper (arg=0xd7adf400) at /usr/src/sys/kern/kern_exit.c:592


A crash dump, the kernel and the corresponding symbol file exist. A PR
will follow tomorrow...

Bye,
Bjoern

-- 
Bjoern Labitzke  <bcsl@gmx.de>
   Use GPG! (Don't you use envelopes for your letters?)