GENERIC HEAD from Jan 27 19:01 UTC, vmcore.38
(sys/dev/ata is from Jan 18 in order to dump)

GDB: no debug ports present
KDB: debugger backends: ddb
KDB: current backend: ddb
Copyright (c) 1992-2006 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
        The Regents of the University of California. All rights reserved.
FreeBSD 7.0-CURRENT #10: Fri Jan 27 20:46:51 CET 2006
    pho@crashbox.osted.lan:/usr/src/sys/i386/compile/PHO
WARNING: WITNESS option enabled, expect reduced performance.
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) XEON(TM) CPU 1.80GHz (1799.81-MHz 686-class CPU)
  Origin = "GenuineIntel"  Id = 0xf24  Stepping = 4
  Features=0x3febfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM>
  Logical CPUs per core: 2
real memory  = 1073676288 (1023 MB)
avail memory = 1040891904 (992 MB)
:
Trying to mount root from ufs:/dev/ad0s1a
fxp0: link state changed to UP
VNASSERT failed
0xc534e3f0: tag devfs, type VCHR
    usecount 0, writecount 0, refcount 0 mountedhere 0xc50b6500
    flags (VI_DOOMED)
    #0 0xc064a108 at lockmgr+0x50c
#1 0xc06a5e35 at vop_stdlock+0x21
#2 0xc0829c1b at VOP_LOCK_APV+0x87
#3 0xc06b9f54 at vn_lock+0xac
#4 0xc06b92c6 at vn_close+0x5e
#5 0xc06ba096 at vn_closefile+0xce
#6 0xc060b027 at devfs_close_f+0xf
#7 0xc0638e2c at fdrop_locked+0x88
#8 0xc0638d9c at fdrop+0x24
#9 0xc063788b at closef+0x36b
#10 0xc063510e at close+0x1be
#11 0xc08184b6 at syscall+0x27e
#12 0xc08041ef at Xint0x80_syscall+0x1f

panic: No vop_inactive(0xc534e3f0, 0xe764f74c)
cpuid = 1
KDB: enter: panic
[thread pid 666 tid 100097 ]
Stopped at      kdb_enter+0x2b: nop
db> where
Tracing pid 666 tid 100097 td 0xc4ee4820
kdb_enter(c088515f) at kdb_enter+0x2b
panic(c08aedac,c534e3f0,e764f74c,c534e3f0,c088daac) at panic+0x14b
VOP_INACTIVE_APV(0,e764f74c) at VOP_INACTIVE_APV+0x73
vinactive(c534e3f0,c4ee4820) at vinactive+0x75
vgonel(c534e3f0,c534e4b8,0,c088e84e,93b) at vgonel+0xf1
vgone(c534e3f0,0,e764f804,c06098c1,c4e48c80) at vgone+0x26
devfs_delete(c4e48c80,c5351600,c0885916,15b,c4e48c80) at devfs_delete+0x3c
devfs_populate_loop(c4e48c80,0) at devfs_populate_loop+0x101
devfs_populate(c4e48c80,c0951150,2,c4eb5005,0) at devfs_populate+0x32
devfs_lookupx(e764f968,c4e48c90,c087d5d6,23f,c090c240) at devfs_lookupx+0x39b
devfs_lookup(e764f968,c4e4c000,0,e764f984,c06a7d96) at devfs_lookup+0x2d
VOP_LOOKUP_APV(c090c240,e764f968) at VOP_LOOKUP_APV+0x87
lookup(e764fb70,fa,0,c4ee4820,c4ee4820) at lookup+0x3f2
namei(e764fb70,c4ee4820,e764fa14,c4ee4820,c0951150) at namei+0x37e
vn_open_cred(e764fb70,e764fc70,0,c4fef500,4) at vn_open_cred+0x277
vn_open(e764fb70,e764fc70,0,4,c088e84e) at vn_open+0x1e
kern_open(c4ee4820,bfbfe340,0,3,0) at kern_open+0xb6
open(c4ee4820,e764fd04,c4ee4820,0,2) at open+0x1a
syscall(3b,3b,3b,2,3) at syscall+0x27e
Xint0x80_syscall() at Xint0x80_syscall+0x1f
--- syscall (5, FreeBSD ELF32, open), eip = 0x28142fff, esp = 0xbfbfe30c, ebp = 0xbfbfe368 ---
db> show allpcpu
Current CPU: 1

cpuid        = 0
curthread    = 0xc4af09c0: pid 3 "g_up"
curpcb       = 0xe3685d90
fpcurthread  = none
idlethread   = 0xc4aef9c0: pid 13 "idle: cpu0"
APIC ID      = 0
currentldt   = 0x50
spin locks held:

cpuid        = 1
curthread    = 0xc4ee4820: pid 666 "pty"
curpcb       = 0xe764fd90
fpcurthread  = none
idlethread   = 0xc4aef820: pid 12 "idle: cpu1"
APIC ID      = 1
currentldt   = 0x50
spin locks held:

cpuid        = 2
curthread    = 0xc4aef680: pid 11 "idle: cpu2"
curpcb       = 0xe3664d90
fpcurthread  = none
idlethread   = 0xc4aef680: pid 11 "idle: cpu2"
APIC ID      = 6
currentldt   = 0x50
spin locks held:

cpuid        = 3
curthread    = 0xc4aef4e0: pid 10 "idle: cpu3"
curpcb       = 0xe3661d90
fpcurthread  = none
idlethread   = 0xc4aef4e0: pid 10 "idle: cpu3"
APIC ID      = 7
currentldt   = 0x50
spin locks held:

db> show alllocks
Process 666 (pty) thread 0xc4ee4820 (100097)
exclusive sx devfsmount r = 0 (0xc4e48c90) locked @ fs/devfs/devfs_vnops.c:575
Process 3 (g_up) thread 0xc4af09c0 (100015)
exclusive sleep mutex ATA state lock r = 0 (0xc4be60e8) locked @ dev/ata/ata-queue.c:183
exclusive sleep mutex ATA queue lock r = 0 (0xc4be6104) locked @ dev/ata/ata-queue.c:166
db> where 3
Tracing pid 3 tid 100015 td 0xc4af09c0
cpustop_handler(e3685b98,c0817731,0,f424,0) at cpustop_handler+0x31
ipi_nmi_handler(0,f424,0,0,c4ae50a0) at ipi_nmi_handler+0x28
trap(c4be0008,e3680028,c4af0028,60,c4ca2400) at trap+0x3d
calltrap() at calltrap+0x5
--- trap 0x13, eip = 0xc07f0370, esp = 0xe3685be0, ebp = 0xe3685bf0 ---
siointr1(c4ca2400,c09bf90c,0,c08a62c4,56e) at siointr1+0x230
siointr(c4ca2400) at siointr+0x21
intr_execute_handlers(c4ae50a0,e3685c4c,4,e3685cb0,c0804553) at intr_execute_handlers+0xe1
lapic_handle_intr(39) at lapic_handle_intr+0x30
Xapic_isr1() at Xapic_isr1+0x33
--- interrupt, eip = 0xc06a1a22, esp = 0xe3685c8c, ebp = 0xe3685cb0 ---
bufdone_finish(d8b7c9bc) at bufdone_finish+0x66
bufdone(d8b7c9bc) at bufdone+0xaa
g_vfs_done(c5003e70) at g_vfs_done+0x8a
biodone(c5003e70) at biodone+0x58
g_io_schedule_up(c4af09c0) at g_io_schedule_up+0xcb
g_up_procbody(0,e3685d38,0,c06201e8,0) at g_up_procbody+0x5a
fork_exit(c06201e8,0,e3685d38) at fork_exit+0xa4
fork_trampoline() at fork_trampoline+0x8
--- trap 0x1, eip = 0, esp = 0xe3685d6c, ebp = 0 ---
db> ps
  pid   proc     uid  ppid  pgrp  flag   stat  wmesg    wchan  cmd
  671 c5030ac8 1001   664   658 0000002 [SLPQ devfs 0xc4e4c058][SLP] pty
  670 c4edd678 1001   664   658 0000002 [SLPQ devfs 0xc4e4c058][SLP] pty
  669 c4edd8a0 1001   664   658 0000002 [SLPQ devfs 0xc4e4c058][SLP] pty
  668 c4ec9678 1001   664   658 0000002 [SLPQ devfs 0xc4e4c058][SLP] pty
  667 c4fe2cf0 1001   664   658 0000002 [SLPQ devfs 0xc4e4c058][SLP] pty
  666 c4ee2cf0 1001   664   658 0000002 [CPU 1] pty
  665 c4fe5ac8 1001   664   658 0000002 [SLPQ devfs 0xc4e4c058][SLP] pty
  664 c4fe2450 1001   663   658 0000002 [SLPQ wait 0xc4fe2450][SLP] pty
  663 c4edd228 1001   662   658 0004002 [SLPQ nanslp 0xc09519e4][SLP] pty
  662 c4e99678 1001   661   658 0000002 [SLPQ wait 0xc4e99678][SLP] run
  661 c4fe2228 1001   660   658 0000002 [SLPQ wait 0xc4fe2228][SLP] run
  660 c4e2acf0 1001   658   658 0004002 [SLPQ nanslp 0xc09519e4][SLP] run
  658 c4fe58a0 1001   654   658 0004002 [SLPQ wait 0xc4fe58a0][SLP] sh
  654 c4e2a678 1001   653   654 0004002 [SLPQ wait 0xc4e2a678][SLP] bash
  653 c4fe2000    0   652   653 0004102 [SLPQ wait 0xc4fe2000][SLP] su
  652 c4ee2678    0     1   652 0004002 [SLPQ wait 0xc4ee2678][SLP] sh
   45 c4e28228    0     0     0 0000204 [SLPQ - 0xe50e7d04][SLP] schedcpu
   44 c4e28450    0     0     0 0000204 [SLPQ - 0xc09a566c][SLP] nfsiod 3
   43 c4e28678    0     0     0 0000204 [SLPQ - 0xc09a5668][SLP] nfsiod 2
   42 c4e288a0    0     0     0 0000204 [SLPQ - 0xc09a5664][SLP] nfsiod 1
   41 c4e28ac8    0     0     0 0000204 [SLPQ - 0xc09a5660][SLP] nfsiod 0
   40 c4e28cf0    0     0     0 0000204 [SLPQ syncer 0xc0951730][SLP] syncer
   39 c4e2a000    0     0     0 0000204 [SLPQ vlruwt 0xc4e2a000][SLP] vnlru
   38 c4bf1cf0    0     0     0 0000204 [SLPQ snaprdb 0xc4e3e420][SLP] bufdaemon
   37 c4c99000    0     0     0 000020c [SLPQ pgzero 0xc09b3590][SLP] pagezero
   36 c4c99228    0     0     0 0000204 [SLPQ psleep 0xc09ab4bc][SLP] vmdaemon
   35 c4c99450    0     0     0 0000204 [SLPQ psleep 0xc09ab47c][SLP] pagedaemon
   34 c4c99678    0     0     0 0000204 [IWAIT] irq7: ppc0
   33 c4c998a0    0     0     0 0000204 [SLPQ - 0xc4c9f03c][SLP] fdc0
   32 c4c99ac8    0     0     0 0000204 [IWAIT] swi0: sio
   31 c4c99cf0    0     0     0 0000204 [IWAIT] irq12: psm0
   30 c4c9d000    0     0     0 0000204 [IWAIT] irq1: atkbd0
   29 c4c9d228    0     0     0 0000204 [IWAIT] irq15: ata1
   28 c4c9d450    0     0     0 0000204 [IWAIT] irq14: ata0
   27 c4b46678    0     0     0 0000204 [IWAIT] irq17: fxp0
   26 c4b468a0    0     0     0 0000204 [SLPQ usbtsk 0xc094ef24][SLP] usbtask
   25 c4b46ac8    0     0     0 0000204 [SLPQ usbevt 0xc4c29210][SLP] usb0
   24 c4b46cf0    0     0     0 0000204 [IWAIT] irq16: uhci0
   23 c4bf1000    0     0     0 0000204 [SLPQ - 0xc4c20480][SLP] em0 taskq
   22 c4bf1228    0     0     0 0000204 [IWAIT] irq9: acpi0
   21 c4bf1450    0     0     0 0000204 [IWAIT] swi6: Giant taskq
   20 c4bf1678    0     0     0 0000204 [IWAIT] swi6: task queue
    9 c4bf18a0    0     0     0 0000204 [SLPQ - 0xc4b45600][SLP] acpi_task_2
    8 c4bf1ac8    0     0     0 0000204 [SLPQ - 0xc4b45600][SLP] acpi_task_1
    7 c4af3228    0     0     0 0000204 [SLPQ - 0xc4b45600][SLP] acpi_task_0
    6 c4af3450    0     0     0 0000204 [SLPQ - 0xc4b45680][SLP] kqueue taskq
   19 c4af3678    0     0     0 0000204 [IWAIT] swi2: cambio
   18 c4af38a0    0     0     0 0000204 [IWAIT] swi5: +
    5 c4af3ac8    0     0     0 0000204 [SLPQ - 0xc4b45980][SLP] thread taskq
   17 c4af3cf0    0     0     0 0000204 [SLPQ - 0xc094cb80][SLP] yarrow
    4 c4b46000    0     0     0 0000204 [SLPQ - 0xc094f69c][SLP] g_down
    3 c4b46228    0     0     0 0000204 [CPU 0] g_up
    2 c4b46450    0     0     0 0000204 [SLPQ - 0xc094f690][SLP] g_event
   16 c4aee000    0     0     0 0000204 [IWAIT] swi3: vm
   15 c4aee228    0     0     0 000020c [IWAIT] swi4: clock sio
   14 c4aee450    0     0     0 0000204 [IWAIT] swi1: net
   13 c4aee678    0     0     0 000020c [Can run] idle: cpu0
   12 c4aee8a0    0     0     0 000020c [Can run] idle: cpu1
   11 c4aeeac8    0     0     0 000020c [CPU 2] idle: cpu2
   10 c4aeecf0    0     0     0 000020c [CPU 3] idle: cpu3
    1 c4af3000    0     0     1 0004200 [SLPQ wait 0xc4af3000][SLP] init
    0 c094f7a0    0     0     0 0000200 [IWAIT] swapper
db> call doadump
Dumping 1023 MB (2 chunks)
  chunk 0: 1MB (159 pages) ... ok
  chunk 1: 1023MB (261872 pages) 1007 991 975 959 943 927 911 895 879 863 847 831 815 799 783 767 751 735 719 703 687 671 655 639 623 607 591 575 559 543 527 511 495 479 463 447 431 415 399 383 367 351 335 319 303 287 271 255 239 223 207 191 175 159 143 127 111 95 79 63 47 31 15 ... ok

Dump complete
= 0xf
db> reset
cpu_reset: Restarting BSP
cpu_reset_proxy: Stopped CPU 1
GDB: no debug ports present

(kgdb) bt
#0  doadump () at pcpu.h:166
#1  0xc046b0c7 in db_fncall (dummy1=0xc09d0ae0, dummy2=0x0, dummy3=0xc07facef, dummy4=0xe764f524 "Pd4\220\177<d@d\220\a")
    at ../../../ddb/db_command.c:489
#2  0xc046aecc in db_command (last_cmdp=0xc0938724, cmd_table=0x0, aux_cmd_tablep=0xc08b1d74, aux_cmd_tablep_end=0xc08b1d90)
    at ../../../ddb/db_command.c:404
#3  0xc046af94 in db_command_loop () at ../../../ddb/db_command.c:455
#4  0xc046cbad in db_trap (type=0x3, code=0x0) at ../../../ddb/db_main.c:228
#5  0xc066f9cc in kdb_trap (type=0x3, code=0x0, tf=0xe764f6bc) at ../../../kern/subr_kdb.c:485
#6  0xc0817c4c in trap (frame=
      {tf_fs = 0xe7640008, tf_es = 0xc0670028, tf_ds = 0xc0880028, tf_edi = 0xc08aedac, tf_esi = 0x1, tf_ebp = 0xe764f6fc, tf_isp = 0xe764f6e8, tf_ebx = 0xe764f728, tf_edx = 0x0, tf_ecx = 0xc1033000, tf_eax = 0x12, tf_trapno = 0x3, tf_err = 0x0, tf_eip = 0xc066f6d3, tf_cs = 0x20, tf_eflags = 0x286, tf_esp = 0xe764f71c, tf_ss = 0xc065549b}) at ../../../i386/i386/trap.c:614
#7  0xc080419a in calltrap () at ../../../i386/i386/exception.s:137
#8  0xc066f6d3 in kdb_enter (msg=0x12 <Address 0x12 out of bounds>) at cpufunc.h:60
#9  0xc065549b in panic (fmt=0xc08aedac "No vop_inactive(%p, %p)") at ../../../kern/kern_shutdown.c:549
#10 0xc0829abf in VOP_INACTIVE_APV (vop=0x12, a=0xe764f74c) at vnode_if.c:1503
#11 0xc06aec29 in vinactive (vp=0xc534e3f0, td=0x12) at vnode_if.h:795
#12 0xc06af2f9 in vgonel (vp=0xc534e3f0) at ../../../kern/vfs_subr.c:2419
#13 0xc06af1ee in vgone (vp=0xc534e3f0) at ../../../kern/vfs_subr.c:2364
#14 0xc0609650 in devfs_delete (dm=0xc4e48c80, de=0xc5351600) at ../../../fs/devfs/devfs_devs.c:243
#15 0xc06098c1 in devfs_populate_loop (dm=0xc4e48c80, cleanup=0x0) at ../../../fs/devfs/devfs_devs.c:350
#16 0xc0609b72 in devfs_populate (dm=0xc4e48c80) at ../../../fs/devfs/devfs_devs.c:446
#17 0xc060b853 in devfs_lookupx (ap=0x12) at ../../../fs/devfs/devfs_vnops.c:512
#18 0xc060b995 in devfs_lookup (ap=0xe764f968) at ../../../fs/devfs/devfs_vnops.c:576
#19 0xc082884b in VOP_LOOKUP_APV (vop=0xc090c240, a=0xe764f968) at vnode_if.c:97
#20 0xc06a7d96 in lookup (ndp=0xe764fb70) at vnode_if.h:56
#21 0xc06a7742 in namei (ndp=0xe764fb70) at ../../../kern/vfs_lookup.c:203
#22 0xc06b9023 in vn_open_cred (ndp=0xe764fb70, flagp=0xe764fc70, cmode=0x0, cred=0xc4fef500, fdidx=0x4) at ../../../kern/vfs_vnops.c:182
#23 0xc06b8daa in vn_open (ndp=0x0, flagp=0xe764fc70, cmode=0x0, fdidx=0x4) at ../../../kern/vfs_vnops.c:91
#24 0xc06b2296 in kern_open (td=0xc4ee4820, path=0x12 <Address 0x12 out of bounds>, pathseg=18, flags=0x3, mode=0x0)
    at ../../../kern/vfs_syscalls.c:977
#25 0xc06b21aa in open (td=0xc4ee4820, uap=0xe764fd04) at ../../../kern/vfs_syscalls.c:943
#26 0xc08184b6 in syscall (frame=
      {tf_fs = 0x3b, tf_es = 0x3b, tf_ds = 0x3b, tf_edi = 0x2, tf_esi = 0x3, tf_ebp = 0xbfbfe368, tf_isp = 0xe764fd64, tf_ebx = 0x28090b40, tf_edx = 0xffffffff, tf_ecx = 0x1, tf_eax = 0x5, tf_trapno = 0xc, tf_err = 0x2, tf_eip = 0x28142fff, tf_cs = 0x33, tf_eflags = 0x282, tf_esp = 0xbfbfe30c, tf_ss = 0x3b}) at ../../../i386/i386/trap.c:1008
#27 0xc08041ef in Xint0x80_syscall () at ../../../i386/i386/exception.s:190
(kgdb) f 12
#12 0xc06af2f9 in vgonel (vp=0xc534e3f0) at ../../../kern/vfs_subr.c:2419
2419                            vinactive(vp, td);
(kgdb) p *vp
$1 = {v_type = VCHR, v_tag = 0xc087d2d2 "devfs", v_op = 0x0, v_data = 0x0, v_mount = 0xc4e47c00, v_nmntvnodes = {tqe_next = 0xc5297a80,
    tqe_prev = 0xc4f89164}, v_un = {vu_mount = 0xc50b6500, vu_socket = 0xc50b6500, vu_cdev = 0xc50b6500, vu_fifoinfo = 0xc50b6500},
  v_hashlist = {le_next = 0x0, le_prev = 0x0}, v_hash = 0x0, v_cache_src = {lh_first = 0x0}, v_cache_dst = {tqh_first = 0x0,
    tqh_last = 0xc534e420}, v_dd = 0x0, v_cstart = 0x0, v_lasta = 0x0, v_lastw = 0x0, v_clen = 0x0, v_lock = {lk_interlock = 0xc0950b38,
    lk_flags = 0x80, lk_sharecount = 0x0, lk_waitcount = 0x0, lk_exclusivecount = 0x0, lk_prio = 0x50, lk_wmesg = 0xc087d2d2 "devfs",
    lk_timo = 0x33, lk_lockholder = 0xffffffff, lk_newlock = 0x0, lk_stack = {depth = 0xd, pcs = {0xc064a108, 0xc06a5e35, 0xc0829c1b,
        0xc06b9f54, 0xc06b92c6, 0xc06ba096, 0xc060b027, 0xc0638e2c, 0xc0638d9c, 0xc063788b, 0xc063510e, 0xc08184b6, 0xc08041ef, 0x0, 0x0,
        0x0, 0x0, 0x0}}}, v_interlock = {mtx_object = {lo_name = 0xc0888d4e "vnode interlock", lo_type = 0xc0888d4e "vnode interlock",
      lo_flags = 0x1020000, lo_witness_data = {lod_list = {stqe_next = 0xc0960bb0}, lod_witness = 0xc0960bb0}}, mtx_lock = 0x4,
    mtx_recurse = 0x0}, v_vnlock = 0xc534e448, v_holdcnt = 0x0, v_usecount = 0x0, v_iflag = 0x880, v_vflag = 0x2, v_writecount = 0x0,
  v_freelist = {tqe_next = 0xc5297a80, tqe_prev = 0xc52270f8}, v_bufobj = {bo_mtx = 0xc534e4b8, bo_clean = {bv_hd = {tqh_first = 0x0,
        tqh_last = 0xc534e4f4}, bv_root = 0x0, bv_cnt = 0x0}, bo_dirty = {bv_hd = {tqh_first = 0x0, tqh_last = 0xc534e504}, bv_root = 0x0,
      bv_cnt = 0x0}, bo_numoutput = 0x0, bo_flag = 0x0, bo_ops = 0xc091af44, bo_bsize = 0x200, bo_object = 0x0, bo_synclist = {
      le_next = 0x0, le_prev = 0x0}, bo_private = 0xc534e3f0, __bo_vnode = 0xc534e3f0}, v_pollinfo = 0x0, v_label = 0x0}