Re: ipf 4.1.32RC4 crashes Solaris9

Darren Reed <[email protected]>
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <29127_1239269023_49DDBE9F_29127_1045_1_49DDBE04.7050908@reed.wattle.id.au>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Joseph Tam wrote:
|
| I spoke too soon when I reported this being stable for Solaris8/9.
| It still crashes my Sol9 loaded DNS server.  The symptoms are the same:
| it is stable just as long as you don't filter by UDP ports, but as soon
| as you add UDP port filter rules, it will crash after a while.
|
| I ran ACT on the core dump, and I've included the relevant portion of the
| output.  Trap 0x31 is some sort of data access MMU miss in fr_derefrule().
| What could cause that?

A bad pointer... something similar has been seen on FreeBSD, so it is 
kind of comforting to see this...
See:
http://sourceforge.net/tracker/?func=detail&aid=2706212&group_id=169098&atid=849053

| unix: setjmp ()
| unix: panicsys+0x44 (0x105d2c0,0x2a1003704c8,0x1,0x1,0x8,0x8)
| unix: vpanic ()
| unix: panic+0x1c (0x105d2c0,0x31,0x2a100370720,0x30000c59b2c,0x0)
| unix: die+0xa4 (0x31,0x2a100370720,0x30000c59b2c,0x0)
| unix: trap+0x8e4 (0x2a100370720)
| unix: priv_rtt
| ipf: fr_derefrule+0xe8 
(0x30000c59b2c,0x2a100370a5e,0x30,0x89522416,0xffffffffffffffe8,0x30)
| SUNW,UltraSPARC-III+: bcopy ()
| ce: ce_wput+0x264 (0x30001e21818,0x30001f4eb40)
| unix: putnext+0x21c (0x300011112f0,0x30001f4eb40)
| pfil: pfilmodwput+0x40 (0x300011112f0,0x30001f4eb40)
| unix: putnext+0x21c (0x30001111060,0x30001f4eb40)
| ip: ip_wput_frag+0xb30 
(0x30009475048?,0x30001f4eb40?,0x30009475098,0x0,0x4000)
| ip: ip_wput_ire_fragmentit ()
| ip: ip_wput_ire+0x16ac 
(0x30003290438,0x30003c44b80,0x30009475048,0x300025e5540,0x0)
| ip: ip_wput_pktoptions+0x56c (0x30003290438,0x30003c44b80,0x14fa230)
| ip: ip_wput+0x78 (0x30003290438,0x30003c44b80)
| unix: putnext+0x21c (0x300032901a8,0x30003c44b80)
| udp: udp_wput+0x6bc (0x300032901a8,0x3000413f280)
| unix: putnext+0x21c (0x300032906c8,0x3000413f280)
| genunix: strput+0x270 
(0x3000328b348,0x3000413f280,0x2a100371a00,0x2a100371698,0x0,0x0)
| genunix: kstrputmsg+0x36c 
(0x30001f0ce50,0x30003d16000,0x2a100371a00,0x7c,0x0,0x4)
| sockfs: sosend_dgram+0x25c 
(0x30001f0ce50,0x30009357c90,0x10,0x2a100371a00,0x8)
| sockfs: sosendmsg+0x3f4 (0x30001f0ce50,0x2a1003719d0,0x2a100371a00)
| sockfs: sendit+0x15c (0x3,0x2a1003719d0,0x2a100371a00,0x8)
| sockfs: sendto+0x78 (0x3,0x69ed8,0x7c,0x0,0xffbffcb0,0x10)
| sockfs: sendto32+0x3c (0x3,0x69ed8,0x7c,0x0,0xffbffcb0,0x10)
| unix: syscall_trap32+0xa8 (0x3,0x69ed8,0x7c,0x0,0xffbffcb0,0x10)
| ..
| 20fc07a     panic[cpu1]/thread=30003367340: 20fc07a     BAD TRAP: 
type=31 rp=2a100370720 addr=30000c59b2c mmu_fsr=0
| 20fc07a 20fc07a     dnscache: 20fc07a     trap type = 0x31
| 20fc07a     addr=0x30000c59b2c
| 20fc07a     pid=363, pc=0x118b8a8, sp=0x2a10036ffc1, tstate=0x80001600,
|         context=0x8a4

If you can go into /var/crash/machine and run "adb -k *.#", what
does the output of "0x118b8a8/i" say?

Darren

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
 
iEYEARECAAYFAkndvgQACgkQP7JIXtvLbFW1sgCfQqJ/BMqi6Q2ApnsfLqsSoV4H
Z0oAoOMZT0PyY9U08tq7nvNBdhawAinb
=zsFI
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.