Re: ng_socket refcount bug?

Kristof Provost <[email protected]> Sat, 27 Jun 2026 09:04:55 +0200
Newsgroups gmane.os.freebsd.devel.net
Message-ID <[email protected]>
On 27 Jun 2026, at 1:37, Gleb Smirnoff wrote:
> On Fri, Jun 19, 2026 at 04:15:29PM -0400, Kristof Provost wrote:
> K> I pretty consistently see a panic running if_pppoe tests.
> K> These tests use `/usr/libexec/pppoed -l pppoe-pap epair0b` (or 
> similar) to
> K> be a PPPoE server in one vnet (so that I can test if_pppoe in 
> another
> K> vnet).
> K>
> K> Unfortunately I can’t share the if_pppoe module required to run 
> them.
> K>
> K> They reliably panic like this:
> K>
> K> 	panic: ng node  won't die
> K> 	cpuid = 39
> K> 	time = 1781899222
> K> 	KDB: stack backtrace:
> K> 	db_trace_self_wrapper() at db_trace_self_wrapper+0x36/frame
> K> 0xfffffe004ac1cb40
> K> 	vpanic() at vpanic+0x149/frame 0xfffffe004ac1cc70
> K> 	panic() at panic+0x43/frame 0xfffffe004ac1ccd0
> K> 	vnet_netgraph_uninit() at vnet_netgraph_uninit+0x171/frame
> K> 0xfffffe004ac1cd00
> K> 	vnet_destroy() at vnet_destroy+0x154/frame 0xfffffe004ac1cd30
> K> 	prison_deref() at prison_deref+0xb15/frame 0xfffffe004ac1cdb0
> K> 	sys_jail_remove() at sys_jail_remove+0x1a7/frame 
> 0xfffffe004ac1cdf0
> K> 	amd64_syscall() at amd64_syscall+0x179/frame 0xfffffe004ac1cf30
> K> 	fast_syscall_common() at fast_syscall_common+0xf8/frame 
> 0xfffffe004ac1cf30
> K> 	--- syscall (508, FreeBSD ELF64, jail_remove), rip = 
> 0xfe32964660a, rsp =
> K> 0xfe324ddabb8, rbp = 0xfe324ddac40 ---
> K> 	KDB: enter: panic
> K> 	[ thread pid 17271 tid 102985 ]
> K> 	Stopped at      kdb_enter+0x33: movq    $0,0x15abeb2(%rip)
>
> Fix pushed in 4d3cbeb7b407.
>
Sweet, thanks!

—
Kristof