GENERIC RELENG_6 from Nov 7 19:57 UTC, vmcore.115

GDB: no debug ports present
KDB: debugger backends: ddb
KDB: current backend: ddb
Copyright (c) 1992-2006 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
        The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 6.2-PRERELEASE #0: Tue Nov  7 21:39:14 CET 2006
    pho@crashbox.osted.lan:/usr/src/sys/i386/compile/PHO
WARNING: WITNESS option enabled, expect reduced performance.
ACPI APIC Table: <A M I  OEMAPIC >
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) XEON(TM) CPU 1.80GHz (1799.80-MHz 686-class CPU)
  Origin = "GenuineIntel"  Id = 0xf24  Stepping = 4
  Features=0x3febfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM>
  Logical CPUs per core: 2
real memory  = 1073676288 (1023 MB)
avail memory = 1032548352 (984 MB)
:
Trying to mount root from ufs:/dev/ad0s1a
WARNING: / was not properly dismounted
fxp0: link state changed to UP
panic: mutex nfsd_mtx not owned at ../../../nfsserver/nfs_srvsock.c:147
cpuid = 1
KDB: enter: panic
[thread pid 697 tid 100042 ]
Stopped at      kdb_enter+0x2b: nop
db> where
Tracing pid 697 tid 100042 td 0xc54a7480
kdb_enter(c08f6e73) at kdb_enter+0x2b
panic(c08f6357,c08faafc,c090afe2,93,0,...) at panic+0x14b
_mtx_assert(c0a3d3a0,1,c090afe2,93,c07cf708,...) at _mtx_assert+0x67
nfs_rephead(0,c5cc8500,48,e5a499bc,e5a499c0,...) at nfs_rephead+0x25
nfsrv_symlink(c5cc8500,c570b980,c54a7480,e5a49c98) at nfsrv_symlink+0x3b7
nfssvc_nfsd(c54a7480) at nfssvc_nfsd+0x3ed
nfssvc(c54a7480,e5a49d04) at nfssvc+0x18c
syscall(3b,3b,3b,1,0,...) at syscall+0x22f
Xint0x80_syscall() at Xint0x80_syscall+0x1f
--- syscall (155, FreeBSD ELF32, nfssvc), eip = 0x280c61b7, esp = 0xbfbfeb1c, ebp = 0xbfbfeb38 ---
db> show alllocks
Process 697 (nfsd) thread 0xc54a7480 (100042)
exclusive sleep mutex Giant r = 0 (0xc09e20e0) locked @ nfsserver/nfs_serv.c:2833
db> show allpcpu
Current CPU: 1

cpuid        = 0
curthread    = 0xc52f8a80: pid 13 "idle: cpu0"
curpcb       = 0xe3d7cd90
fpcurthread  = none
idlethread   = 0xc52f8a80: pid 13 "idle: cpu0"
APIC ID      = 0
currentldt   = 0x50
spin locks held:

cpuid        = 1
curthread    = 0xc54a7480: pid 697 "nfsd"
curpcb       = 0xe5a49d90
fpcurthread  = none
idlethread   = 0xc52f8900: pid 12 "idle: cpu1"
APIC ID      = 1
currentldt   = 0x50
spin locks held:

cpuid        = 2
curthread    = 0xc52f8d80: pid 15 "swi4: clock sio"
curpcb       = 0xe3d82d90
fpcurthread  = none
idlethread   = 0xc52f8780: pid 11 "idle: cpu2"
APIC ID      = 6
currentldt   = 0x50
spin locks held:

cpuid        = 3
curthread    = 0xc52f8600: pid 10 "idle: cpu3"
curpcb       = 0xe3d73d90
fpcurthread  = none
idlethread   = 0xc52f8600: pid 10 "idle: cpu3"
APIC ID      = 7
currentldt   = 0x50
spin locks held:

db> set $lines 0
db> ps
  pid  ppid  pgrp   uid   state   wmesg     wchan    cmd
  953     0     0     0  SL      -        0xc0a380a0 [nfsiod 0]
  950   949   948  1001  S+      nfsreq   0xc5b95480 syscall
  949   948   948  1001  S+      wait     0xc57b8c90 syscall
  948   907   948  1001  S+      nanslp   0xc09e29cc syscall
  907   899   907  1001  S+      wait     0xc56f4648 bash
  906     1   906     0  Ss+     ttyin    0xc54c8c10 getty
  905     1   905     0  Ss+     ttyin    0xc54cb010 getty
  904     1   904     0  Ss+     ttyin    0xc54ca010 getty
  903     1   903     0  Ss+     ttyin    0xc54c9410 getty
  902     1   902     0  Ss+     ttyin    0xc54c9810 getty
  901     1   901     0  Ss+     ttyin    0xc54c2010 getty
  900     1   900     0  Ss+     ttyin    0xc54cb410 getty
  899     1   899     0  Ss+     wait     0xc56e9a78 login
  885     1   885     0  Ss      select   0xc0a2fd24 inetd
  861     1   861     0  Ss      select   0xc0a2fd24 moused
  845     1   845     0  Ss      nanslp   0xc09e29cc watchdogd
  796     1   796     0  Ss      nanslp   0xc09e29cc cron
  790     1   790    25  Ss      pause    0xc56f4aac sendmail
  786     1   786     0  Ss      select   0xc0a2fd24 sendmail
  780     1   780     0  Ss      select   0xc0a2fd24 sshd
  760     1   760     0  Ss      select   0xc0a2fd24 ntpd
  729     1   729     0  Ss      select   0xc0a2fd24 usbd
  700   696   696     0  S       -        0xc5817400 nfsd
  699   696   696     0  S       -        0xc5710800 nfsd
  698   696   696     0  S       -        0xc5817600 nfsd
  697   696   696     0  R       CPU 1               nfsd
  696     1   696     0  Ss      select   0xc0a2fd24 nfsd
  694     1   694     0  Ss      select   0xc0a2fd24 mountd
  641     1   641     0  Ss      select   0xc0a2fd24 rpcbind
  621     1   621     0  Ss      select   0xc0a2fd24 syslogd
  553     1   553     0  Ss      select   0xc0a2fd24 devd
   42     0     0     0  SL      -        0xe57fed04 [schedcpu]
   41     0     0     0  SL      sdflush  0xc0a3d734 [softdepflush]
   40     0     0     0  SL      vlruwt   0xc5613c90 [vnlru]
   39     0     0     0  SL      syncer   0xc09e2740 [syncer]
   38     0     0     0  SL      psleep   0xc0a3028c [bufdaemon]
   37     0     0     0  SL      pgzero   0xc0a3e6a4 [pagezero]
   36     0     0     0  SL      psleep   0xc0a3e1f4 [vmdaemon]
   35     0     0     0  SL      psleep   0xc0a3e1b0 [pagedaemon]
   34     0     0     0  WL                          [irq7: ppc0]
   33     0     0     0  SL      -        0xc5406e3c [fdc0]
   32     0     0     0  WL                          [swi0: sio]
   31     0     0     0  WL                          [irq12: psm0]
   30     0     0     0  WL                          [irq1: atkbd0]
   29     0     0     0  WL                          [irq15: ata1]
   28     0     0     0  WL                          [irq14: ata0]
   27     0     0     0  WL                          [irq17: fxp0]
   26     0     0     0  SL      usbtsk   0xc09df604 [usbtask]
   25     0     0     0  SL      usbevt   0xc540c210 [usb0]
   24     0     0     0  WL                          [irq16: uhci0]
   23     0     0     0  WL                          [irq48: em0]
   22     0     0     0  WL                          [irq9: acpi0]
    9     0     0     0  SL      -        0xc5409900 [thread taskq]
   21     0     0     0  WL                          [swi6: Giant taskq]
   20     0     0     0  WL                          [swi6: task queue]
    8     0     0     0  SL      -        0xc5348200 [acpi_task_2]
    7     0     0     0  SL      -        0xc5348200 [acpi_task_1]
    6     0     0     0  SL      -        0xc5348200 [acpi_task_0]
    5     0     0     0  SL      -        0xc5348280 [kqueue taskq]
   19     0     0     0  WL                          [swi2: cambio]
   18     0     0     0  WL                          [swi5: +]
   17     0     0     0  SL      -        0xc09dd320 [yarrow]
    4     0     0     0  SL      -        0xc09dfe88 [g_down]
    3     0     0     0  SL      -        0xc09dfe84 [g_up]
    2     0     0     0  SL      -        0xc09dfe7c [g_event]
   16     0     0     0  WL                          [swi3: vm]
   15     0     0     0  RL      CPU 2               [swi4: clock sio]
   14     0     0     0  WL                          [swi1: net]
   13     0     0     0  RL      CPU 0               [idle: cpu0]
   12     0     0     0  RL                          [idle: cpu1]
   11     0     0     0  RL                          [idle: cpu2]
   10     0     0     0  RL      CPU 3               [idle: cpu3]
    1     0     1     0  SLs     wait     0xc52fc000 [init]
    0     0     0     0  WLs                         [swapper]
db> call doadump
Dumping 1023 MB (2 chunks)
  chunk 0: 1MB (159 pages) ... ok
  chunk 1: 1023MB (261872 pages) 1007 991 975 959 943 927 911 895 879 863 847 831 815 799 783 767 751 735 719 703 687 671 655 639 623 607 591 575 559 543 527 511 495 479 463 447 431 415 399 383 367 351 335 319 303 287 271 255 239 223 207 191 175 159 143 127 111 95 79 63 47 31 15 ... ok

Dump complete
= 0xf
db> call print_uptime
Uptime: 3m40s
= 0x4
db> reset
cpu_reset: Restarting BSP
cpu_reset_proxy: Stopped CPU 1

(kgdb) bt full
#0  doadump () at pcpu.h:165
No locals.
#1  0xc0473b03 in db_fncall (dummy1=0xc0a5c3a0, dummy2=0x0, dummy3=0xc085d07b,
    dummy4=0xe5a49778 "么227文迣\205餐220\227文\224\227文\220\a") at ../../../ddb/db_command.c:492
        fn_addr = 0xc06761b4
        args = {0x0, 0x208345d5, 0x7, 0xc0a3ee80, 0x0, 0xc5348a80, 0xc5377600, 0xe5a49760, 0x2, 0xc092d940}
        nargs = 0x0
        retval = 0xc0a3eda0
        t = 0x0
#2  0xc0473908 in db_command (last_cmdp=0xc09c6ec4, cmd_table=0x0, aux_cmd_tablep=0xc0924704, aux_cmd_tablep_end=0xc0924720)
    at ../../../ddb/db_command.c:350
        cmd = (struct command *) 0xc092dae0
        t = 0x0
        modif = "么227文迣\205餐220\227文\224\227文\220\a\000\000么227文\002\aW餐000\000\000\000\200\2124疊 疇餐r\000\000\000| 疇餐r\000\000\000\001\000\000\000胐227文\027苒205檗\227文0苒205餐000v7儻Ⅷx\000\000\000儡\234餐000\000\000\000礒227文訑G斂o\217嚐 VG餐000\000\000\000儡\234錡NG"
        addr = 0xc0a5c3a0
        count = 0xc085d07b
        have_addr = 0x0
        result = 0x0
#3  0xc04739d0 in db_command_loop () at ../../../ddb/db_command.c:458
No locals.
#4  0xc0475605 in db_trap (type=0x3, code=0x0) at ../../../ddb/db_main.c:229
        jb = {{_jb = {0xe5a49830, 0xe5a4981c, 0xe5a49864, 0x1, 0x0, 0xc047559e, 0x0, 0xd, 0x1, 0x0, 0xe5a4986c, 0xc06956d0}}}
        prev_jb = (void *) 0x0
        bkpt = 0x0
#5  0xc068f0fc in kdb_trap (type=0x3, code=0x0, tf=0xe5a498bc) at ../../../kern/subr_kdb.c:473
        did_stop_cpus = 0x1
        handled = 0xe5a498bc
#6  0xc087a0f0 in trap (frame=
      {tf_fs = 0xe5a40008, tf_es = 0xc0690028, tf_ds = 0xc08f0028, tf_edi = 0xc08f6357, tf_esi = 0x1, tf_ebp = 0xe5a498fc, tf_isp = 0xe5a498e8, tf_ebx = 0xe5a49928, tf_edx = 0x0, tf_ecx = 0xc1833000, tf_eax = 0x12, tf_trapno = 0x3, tf_err = 0x0, tf_eip = 0xc068ee63, tf_cs = 0x20, tf_eflags = 0x286, tf_esp = 0xe5a4991c, tf_ss = 0xc0676a27}) at ../../../i386/i386/trap.c:594
        td = (struct thread *) 0xc54a7480
        p = (struct proc *) 0xc5613000
        sticks = 0xc54a7480
        i = 0x0
        ucode = 0x0
        type = 0x3
        code = 0x0
        eva = 0x0
#7  0xc086649a in calltrap () at ../../../i386/i386/exception.s:139
No locals.
#8  0xc068ee63 in kdb_enter (msg=0x12 <Address 0x12 out of bounds>) at cpufunc.h:60
No locals.
#9  0xc0676a27 in panic (fmt=0xc08f6357 "mutex %s not owned at %s:%d") at ../../../kern/kern_shutdown.c:559
        td = (struct thread *) 0xc54a7480
        bootopt = 0x100
        newpanic = 0x1
        ap = 0xe5a49928 "歿217濩珮220餐223"
        buf = "mutex nfsd_mtx not owned at ../../../nfsserver/nfs_srvsock.c:147", '\0' <repeats 191 times>
#10 0xc066ed6f in _mtx_assert (m=0xc0a3d3a0, what=0xc1833000, file=0xc090afe2 "../../../nfsserver/nfs_srvsock.c", line=0x93)
    at ../../../kern/kern_mutex.c:768
No locals.
#11 0xc076ca11 in nfs_rephead (siz=0x0, nd=0xc5cc8500, err=0x48, mbp=0x12, bposp=0x12) at ../../../nfsserver/nfs_srvsock.c:147
        tl = (u_int32_t *) 0x0
        mreq = (struct mbuf *) 0x0
        bpos = 0xc185b3c0 " 許205總廄205磺_\227默\214\221擱+\217"
        mb = (struct mbuf *) 0xc07cf708
#12 0xc076708f in nfsrv_symlink (nfsd=0xc5cc8500, slp=0xc570b980, td=0xc54a7480, mrq=0xe5a49c98) at ../../../nfsserver/nfs_serv.c:2844
        t1 = 0x12
        mrep = (struct mbuf *) 0x0
        md = (struct mbuf *) 0xc5882700
        nam = (struct sockaddr *) 0xc569ab30
        dpos = 0xc5882764 "瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤"...
        cred = (struct ucred *) 0xc5c4cc00
        va = {va_type = VNON, va_mode = 0x1ff, va_nlink = 0xffff, va_uid = 0xffffffff, va_gid = 0xffffffff, va_fsid = 0xffffffff,
  va_fileid = 0xffffffff, va_size = 0xffffffffffffffff, va_blocksize = 0xffffffff, va_atime = {tv_sec = 0xffffffff,
    tv_nsec = 0xffffffff}, va_mtime = {tv_sec = 0xffffffff, tv_nsec = 0xffffffff}, va_ctime = {tv_sec = 0xffffffff,
    tv_nsec = 0xffffffff}, va_birthtime = {tv_sec = 0xffffffff, tv_nsec = 0xffffffff}, va_gen = 0xffffffff, va_flags = 0xffffffff,
  va_rdev = 0xffffffff, va_bytes = 0xffffffffffffffff, va_filerev = 0x0, va_vaflags = 0x0, va_spare = 0x0}
        dirfor = {va_type = VDIR, va_mode = 0x1f8, va_nlink = 0x2, va_uid = 0x3e9, va_gid = 0x0, va_fsid = 0x57, va_fileid = 0x13,
  va_size = 0x200, va_blocksize = 0x4000, va_atime = {tv_sec = 0x4551ff07, tv_nsec = 0x0}, va_mtime = {tv_sec = 0x4551ff07,
    tv_nsec = 0x0}, va_ctime = {tv_sec = 0x4551ff07, tv_nsec = 0x0}, va_birthtime = {tv_sec = 0x4551ff07, tv_nsec = 0x0},
  va_gen = 0x73e4acba, va_flags = 0x0, va_rdev = 0xc27, va_bytes = 0x800, va_filerev = 0xd7289bdc8f, va_vaflags = 0x0,
  va_spare = 0xc08fabe5}
        diraft = {va_type = 3852770072, va_mode = 0xe981, va_nlink = 0xc066, va_uid = 0xc0a2fc88, va_gid = 0xe5a49b44,
  va_fsid = 0xc069aab8, va_fileid = 0xc54a7480, va_size = 0xc54a7480, va_blocksize = 0xc54a74f8, va_atime = {tv_sec = 0xe5a49b4c,
    tv_nsec = 0xc06880f3}, va_mtime = {tv_sec = 0xc09e20a0, tv_nsec = 0x2}, va_ctime = {tv_sec = 0xc08f866c, tv_nsec = 0x267},
  va_birthtime = {tv_sec = 0xc54a7480, tv_nsec = 0xe5a49b58}, va_gen = 0x246, va_flags = 0xc09e9580, va_rdev = 0xe5a49b64,
  va_bytes = 0xc0a2fc88c066e981, va_filerev = 0xc069aab8e5a49b90, va_vaflags = 0xc09e9580, va_spare = 0x0}
        nd = {ni_dirp = 0xc54a7480 "", ni_segflg = UIO_SYSSPACE, ni_startdir = 0xc5cf22b8, ni_rootdir = 0xc06995b0,
  ni_topdir = 0xc0911dc6, ni_vp = 0x0, ni_dvp = 0xc5cf22b8, ni_pathlen = 0x1, ni_next = 0xc57e2008 "", ni_loopcnt = 0xc54a74f8,
  ni_cnd = {cn_nameiop = 0x1, cn_flags = 0xc0dc08, cn_thread = 0xc54a7480, cn_cred = 0xc5c4cc00, cn_lkflags = 0x2,
    cn_pnbuf = 0xc57e2000 "濊キ", cn_nameptr = 0xc57e2000 "濊キ", cn_namelen = 0x8, cn_consume = 0x0}}
        bpos = 0xc54a7480 ""
        pathcp = 0x0
        io = {uio_iov = 0xc1874968, uio_iovcnt = 0x9, uio_offset = 0xc06880f3e5a49ac0, uio_resid = 0xc09e20a0, uio_segflg = UIO_NOCOPY,
  uio_rw = 3230631532, uio_td = 0x267}
        iv = {iov_base = 0xc54a7480, iov_len = 0xc5613000}
        error = 0x48
        len = 0x8
        len2 = 0x0
        dirfor_ret = 0x0
        diraft_ret = 0x1
        v3 = 0x8
        mb = (struct mbuf *) 0xc56130a8
        mreq = (struct mbuf *) 0x12
        dirp = (struct vnode *) 0xc5cf22b8
        nfh = {fh_generic = {fh_fsid = {val = {0x434f6181, 0xa1e353a3}}, fh_fid = {fid_len = 0xc, fid_reserved = 0x0,
      fid_data = "\023\000\000\000漪酲\000\000\000\000\000\000\000"}},
  fh_bytes = "\201aOCΠ耤\f\000\000\000\023\000\000\000漪酲\000\000\000\000\000\000\000\000l\206\217髻\002\000\000\200tJ闢\232文F\002\000\000|  \236餐\\232文\201嶨餐200tJ瓚徑髏t\000\000\000\200\232文酀200h嚐  \236餐002\000\000\000\200tJ髏200\225\236餐200tJ髏234\232文酀200h嚐  \236餐002\000\000\000l\206\217餐200tJ髏200tJ"}
        mp = (struct mount *) 0xc5788000
#13 0xc076ff49 in nfssvc_nfsd (td=0x12) at ../../../nfsserver/nfs_syscalls.c:474
        siz = 0x74
        slp = (struct nfssvc_sock *) 0xc570b980
        nfsd = (struct nfsd *) 0xc5817800
        nd = (struct nfsrv_descript *) 0xc5cc8500
        m = (struct mbuf *) 0xc5d08d00
        mreq = (struct mbuf *) 0xc5d08d00
        error = 0x0
        cacherep = 0x2
        sotype = 0x2
        writes_todo = 0x0
        procrastinate = 0x0
        cur_usec = Unhandled dwarf expression opcode 0x93
(kgdb) proc 950
(kgdb) bt full
#0  0xc06873e7 in sched_switch (td=0xc5616900, newtd=0xc52f8a80, flags=0x1) at ../../../kern/sched_4bsd.c:973
        kg = (struct ksegrp *) 0x0
        p = (struct proc *) 0xc57b8000
#1  0xc067c8c8 in mi_switch (flags=0x1, newtd=0x0) at ../../../kern/kern_synch.c:420
        new_switchtime = {sec = 0xdc, frac = 0xb8c4f6c273aac7a8}
        td = (struct thread *) 0xc5616900
        p = (struct proc *) 0xc57b8000
        __func__ = "mi_switch"
#2  0xc0694b65 in sleepq_switch (wchan=0x0) at ../../../kern/subr_sleepqueue.c:450
        sc = (struct sleepqueue_chain *) 0xc09e7900
        td = (struct thread *) 0xc5616900
#3  0xc0694cae in sleepq_wait (wchan=0xc5b95480) at ../../../kern/subr_sleepqueue.c:530
No locals.
#4  0xc067c2f5 in msleep (ident=0xc5b95480, mtx=0xc0a379e0, priority=0x53, wmesg=0xc090a749 "nfsreq", timo=0x0)
    at ../../../kern/kern_synch.c:211
        _giantcnt = 0x1
        Giant__wf = 0xc090a6e1 "nfsclient/nfs_socket.c"
        Giant__wl = 0x484
        td = (struct thread *) 0xc5616900
        p = (struct proc *) 0x1
        catch = 0x0
        rval = 0x0
        flags = 0x0
        mtx__wf = 0xc090a6e1 "nfsclient/nfs_socket.c"
        mtx__wl = 0x2a6
#5  0xc07538c0 in nfs_reply (rep=0xc5b95480) at ../../../nfsclient/nfs_socket.c:682
        so = (struct socket *) 0x0
        m = (struct mbuf *) 0x0
        error = 0x0
        sotype = 0x2
        slpflag = 0x0
#6  0xc0754371 in nfs_request (vp=0xc5d00984, mrest=0xc5882400, procnum=0xa, td=0xc5616900, cred=0xc5b99c80, mrp=0xe5aabb5c,
    mdp=0xe5aabb60, dposp=0xe5aabb64) at ../../../nfsclient/nfs_socket.c:1131
        mrep = (struct mbuf *) 0xc5b99c80
        m2 = (struct mbuf *) 0x0
        rep = (struct nfsreq *) 0xc5b95480
        tl = (u_int32_t *) 0x0
        i = 0x0
        nmp = (struct nfsmount *) 0xc5c0a000
        m = (struct mbuf *) 0xc55f1d00
        md = (struct mbuf *) 0x29d
        mheadend = (struct mbuf *) 0xc55f1d00
        waituntil = 0xc5b99c80
        dpos = 0x0
        error = 0x0
        mrest_len = 0x0
        auth_len = 0x0
        now = {tv_sec = 0xdc, tv_usec = 0xaff3d}
        xidp = (u_int32_t *) 0xc55f1dbc
        __func__ = "nfs_request"
#7  0xc075bd69 in nfs_symlink (ap=0xe5aabbb8) at ../../../nfsclient/nfs_vnops.c:1720
        oldset = {__bits = {0x0, 0x0, 0x0, 0x0}}
        dvp = (struct vnode *) 0xc5d00984
        vap = (struct vattr *) 0xe5aabc48
        cnp = (struct componentname *) 0xe5aabc20
        sp = (struct nfsv2_sattr *) 0xe5aabb70
        bpos = 0xc5882464 "瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤瓿冤"...
        dpos = 0xc0986200 "濬\227"
        slen = 0xe5aabb70
        error = 0xe5aabc48
        wccflag = 0x0
        gotvp = 0xc5d00984
        mreq = (struct mbuf *) 0xc5882400
        mrep = (struct mbuf *) 0xe5aabb80
        md = (struct mbuf *) 0xc06ce80b
        mb = (struct mbuf *) 0xc5882400
        newvp = (struct vnode *) 0x0
        v3 = 0x200
#8  0xc088cb3b in VOP_SYMLINK_APV (vop=0xc0986200, a=0xe5aabbb8) at vnode_if.c:1370
        rc = 0xc0986200
#9  0xc06d2167 in kern_symlink (td=0xc5616900, path=0xc5d00984 "\002", link=0x2804feb7 <Address 0x2804feb7 out of bounds>,
    segflg=UIO_USERSPACE) at vnode_if.h:711
        mp = (struct mount *) 0xc5c08b90
        vattr = {va_type = VNON, va_mode = 0x1ff, va_nlink = 0xffff, va_uid = 0xffffffff, va_gid = 0xffffffff, va_fsid = 0xffffffff,
  va_fileid = 0xffffffff, va_size = 0xffffffffffffffff, va_blocksize = 0xffffffff, va_atime = {tv_sec = 0xffffffff,
    tv_nsec = 0xffffffff}, va_mtime = {tv_sec = 0xffffffff, tv_nsec = 0xffffffff}, va_ctime = {tv_sec = 0xffffffff,
    tv_nsec = 0xffffffff}, va_birthtime = {tv_sec = 0xffffffff, tv_nsec = 0xffffffff}, va_gen = 0xffffffff, va_flags = 0xffffffff,
  va_rdev = 0xffffffff, va_bytes = 0xffffffffffffffff, va_filerev = 0x0, va_vaflags = 0x0, va_spare = 0x0}
        syspath = 0xc5782000 ""
        error = 0xc5d00984
        nd = {ni_dirp = 0x2804feb7 <Address 0x2804feb7 out of bounds>, ni_segflg = UIO_USERSPACE, ni_startdir = 0x0,
  ni_rootdir = 0xc566215c, ni_topdir = 0x0, ni_vp = 0x0, ni_dvp = 0xc5d00984, ni_pathlen = 0x1, ni_next = 0xc572dc08 "",
  ni_loopcnt = 0x0, ni_cnd = {cn_nameiop = 0x1, cn_flags = 0x700cc08, cn_thread = 0xc5616900, cn_cred = 0xc5b99c80, cn_lkflags = 0x2,
    cn_pnbuf = 0xc572dc00 "濊キ", cn_nameptr = 0xc572dc00 "濊キ", cn_namelen = 0x8, cn_consume = 0x0}}
        vfslocked = 0x1
#10 0xc06d1e31 in symlink (td=0xc5616900, uap=0x0) at ../../../kern/vfs_syscalls.c:1514
No locals.
#11 0xc087a8df in syscall (frame=
      {tf_fs = 0x2805003b, tf_es = 0xbfbf003b, tf_ds = 0xbfbf003b, tf_edi = 0x280509c8, tf_esi = 0xbfbfec50, tf_ebp = 0xbfbfeaf8, tf_isp = 0xe5aabd64, tf_ebx = 0x8, tf_edx = 0x0, tf_ecx = 0x8049150, tf_eax = 0x39, tf_trapno = 0x0, tf_err = 0x2, tf_eip = 0x280ab845, tf_cs = 0x33, tf_eflags = 0x297, tf_esp = 0xbfbfeab0, tf_ss = 0x3b}) at ../../../i386/i386/trap.c:983
        params = 0xbfbfeab4 <Address 0xbfbfeab4 out of bounds>
        callp = (struct sysent *) 0xc09717ec
        td = (struct thread *) 0xc5616900
        p = (struct proc *) 0xc57b8000
        orig_tf_eflags = 0x297
        sticks = 0x2a9
        error = 0x0
        narg = 0x2
        args = {0xbf0421f5, 0x2804feb7, 0xc09e20a0, 0x2, 0xc08f866c, 0x267, 0xc0a5d16c, 0xe5aabd2c}
        code = 0x39
#12 0xc08664ef in Xint0x80_syscall () at ../../../i386/i386/exception.s:200
No locals.