Fatal trap 9: general protection fault while in kernel mode cpuid = 0; lapic id = 0 instruction pointer = 0x8:0xffffffff8072a759 stack pointer = 0x10:0xfffff8008d1f8700 frame pointer = 0x10:0xfffff8008d1f8740 code segment = base 0x0, limit 0xfffff, type 0x1b = DPL 0, pres 1, long 1, def32 0, gran 1 processor eflags = interrupt enabled, resume, IOPL = 0 current process = Idle current thread = pri 12 kernel: type 9 trap, code=0 CPU0 stopping CPUs: 0x0000003e stopped Stopped at bpf_mtap+0x79: movl 0x68(%rbx),%eax db> --- Trigger chain (root-only): 1. sysctl net.filters_default_to_accept=1 2. kldload ipfw3 ; kldload ipfw3_basic 3. sysctl net.inet.ip.fw3.verbose=1 4. kldload df748_wire_log.ko # harness: ip_fw3_log_ptr = ip_fw3_log # (upstream never assigns this ptr => dead code by default) 5. ipfw3 add 1000 deny log 12 icmp from 127.0.0.1 to 127.0.0.1 # log N's N is uint16_t, NO bounds check (LOG_IF_MAX=10) 6. ping -c1 -t1 127.0.0.1 -> check_deny (ip_fw3.c:258) -> ip_fw3_log_ptr(m, eh, 12) (ip_fw3.c:264) -> ip_fw3_log (ip_fw3_log.c:114) -> the_if = log_if_table[12] (ip_fw3_log.c:121, OOB) -> the_if->if_bpf deref at offset 16 returns 0xc000200200000100 (non-canonical) -> bpf_mtap_hdr(...,0xc000200200000100,...) -> bpf_mtap deref -> trap 9 (panic) Root cause: missing `if (id >= LOG_IF_MAX) return;` at top of ip_fw3_log(). Reachability: rule install requires SYSCAP_NONET_RAW (raw IP socket) => ROOT-ONLY. Path liveness: ip_fw3_log_ptr is initialised NULL (ip_fw3.c:134) and NEVER assigned anywhere in sys/ -> the buggy function is dead code on a default kernel; harness module wires the pointer to prove the primitive.