"Memory modified after free" - by whom?
Adrian Chadd
adrian at freebsd.org
Mon Dec 10 23:21:46 UTC 2012
On 10 December 2012 15:18, <mdf at freebsd.org> wrote:
> On Mon, Dec 10, 2012 at 3:10 PM, Adrian Chadd <adrian at freebsd.org> wrote:
>> 9216 sounds like a jumbo frame mbuf. So the NIC is writing to an mbuf
>> after it's finalised/freed.
>>
>> I have a similar bug showing up on ath(4) RX. :(
>
> Compile with DEBUG_MEMGUARD in the kernel configuration, and then set
> vm.memguard.desc to the name of the UMA zone used for the 9216 byte
> allocations, mbuf_jumbo_9k. This should cause a panic when the memory
> is touched after free.
Right, but I think its a _hardware_ access after the buffer has been freed..
Adrian
More information about the freebsd-net
mailing list