2.9.0 beta leads to kernel panic on boot
-
I have a Fujitsu Futro S940 with an Intel Pentium J5005. I ran 2.8.1 without issue, but the 2.9.0 beta leads to a kernel panic during boot:
---<<BOOT>>--- Copyright (c) 1992-2026 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD is a registered trademark of The FreeBSD Foundation. FreeBSD 16.0-CURRENT #0 RELENG_2_9_0-n256132-d8e3138ecf52: Thu Aug 6 18:16:43 UTC 2026 root@pfsense-build-release-amd64-1.eng.atx.netgate.com:/var/jenkins/workspace/pfSense-CE-snapshots-2_9_0-main/ obj/amd64/h1bjZuKg/var/jenkins/workspace/pfSense-CE-snapshots-2_9_0-main/sources/FreeBSD-src-RELENG_2_9_0/amd64.am d64/sys/pfSense amd64 FreeBSD clang version 21.1.8 (https://github.com/llvm/llvm-project.git llvmorg-21.1.8-0-g2078da43e25a) VT(vga): resolution 640x480 sysctl_register_oid: can't re-use a leaf (vfs.zfs.metaslab.condense_pct)! CPU: Intel(R) Pentium(R) Silver J5005 CPU @ 1.50GHz (1497.60-MHz K8-class CPU) Origin="GenuineIntel" Id=0x706a1 Family=0x6 Model=0x7a Stepping=1 Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX ,FXSR,SSE,SSE2,SS,HTT,TM,PBE> Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC ,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND> AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM> AMD Features2=0x101<LAHF,Prefetch> Structured Extended Features=0x2294e287<FSGSBASE,TSCADJ,SGX,SMEP,ERMS,NFPUSG,MPX,PQE,RDSEED,SMAP,CLFLUSHOPT,PROC TRACE,SHA> Structured Extended Features2=0x40400004<UMIP,RDPID,SGXLC> Structured Extended Features3=0xac000400<MD_CLEAR,IBPB,STIBP,ARCH_CAP,SSBD> XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES> IA32_ARCH_CAPS=0x14000c6a<IBRS_ALL,SKIP_L1DFL_VME,MDS_NO> VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr TSC: P-state invariant, performance statistics real memory = 4294967296 (4096 MB) avail memory = 3865894912 (3686 MB) Event timer "LAPIC" quality 600 ACPI APIC Table: <INTEL GLK-SOC > WARNING: L1 data cache covers fewer APIC IDs than a core (0 < 1) FreeBSD/SMP: Multiprocessor System Detected: 4 CPUs FreeBSD/SMP: 1 package(s) x 4 core(s) random: registering fast source Intel Secure Key Seed random: fast provider: "Intel Secure Key Seed" random: unblocking device. ioapic0 <Version 2.0> irqs 0-119 Launching APs: 3 2 1 TCP_ratelimit: Is now initialized ipw_bss: You need to read the LICENSE file in /usr/share/doc/legal/intel_ipw.LICENSE. ipw_bss: If you agree with the license, set legal.intel_ipw.license_ack=1 in /boot/loader.conf. module_register_init: MOD_LOAD (ipw_bss_fw, 0xffffffff807a5130, 0) error 1 ipw_ibss: You need to read the LICENSE file in /usr/share/doc/legal/intel_ipw.LICENSE. ipw_ibss: If you agree with the license, set legal.intel_ipw.license_ack=1 in /boot/loader.conf. module_register_init: MOD_LOAD (ipw_ibss_fw, 0xffffffff807a51e0, 0) error 1 ipw_monitor: You need to read the LICENSE file in /usr/share/doc/legal/intel_ipw.LICENSE. ipw_monitor: If you agree with the license, set legal.intel_ipw.license_ack=1 in /boot/loader.conf. module_register_init: MOD_LOAD (ipw_monitor_fw, 0xffffffff807a5290, 0) error 1 iwi_bss: You need to read the LICENSE file in /usr/share/doc/legal/intel_iwi.LICENSE. iwi_bss: If you agree with the license, set legal.intel_iwi.license_ack=1 in /boot/loader.conf. module_register_init: MOD_LOAD (iwi_bss_fw, 0xffffffff807c4d50, 0) error 1 iwi_ibss: You need to read the LICENSE file in /usr/share/doc/legal/intel_iwi.LICENSE. iwi_ibss: If you agree with the license, set legal.intel_iwi.license_ack=1 in /boot/loader.conf. module_register_init: MOD_LOAD (iwi_ibss_fw, 0xffffffff807c4e00, 0) error 1 iwi_monitor: You need to read the LICENSE file in /usr/share/doc/legal/intel_iwi.LICENSE. iwi_monitor: If you agree with the license, set legal.intel_iwi.license_ack=1 in /boot/loader.conf. module_register_init: MOD_LOAD (iwi_monitor_fw, 0xffffffff807c4eb0, 0) error 1 random: entropy device external interface wlan: mac acl policy registered kbd1 at kbdmux0 efirtc0: <EFI Realtime Clock> efirtc0: registered as a time-of-day clock, resolution 1.000000s netgate0: <unknown hardware> netgate0: version: 0.2 smbios0: <System Management BIOS> at iomem 0x7b20b000-0x7b20b017 smbios0: Entry point: v3 (64-bit), Version: 3.1 acpi0: <FUJ D3543-A1> acpi0: Power Button (fixed) unknown: I/O range not supported cpu0: <ACPI CPU> on acpi0 attimer0: <AT timer> port 0x40-0x43,0x50-0x53 irq 0 on acpi0 Timecounter "i8254" frequency 1193182 Hz quality 0 Event timer "i8254" frequency 1193182 Hz quality 100 atrtc0: <AT realtime clock> port 0x70-0x77 on acpi0 atrtc0: Warning: Couldn't map I/O. atrtc0: registered as a time-of-day clock, resolution 1.000000s Event timer "RTC" frequency 32768 Hz quality 0 hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff irq 8 on acpi0 Timecounter "HPET" frequency 19200000 Hz quality 950 Event timer "HPET" frequency 19200000 Hz quality 550 Event timer "HPET1" frequency 19200000 Hz quality 440 Event timer "HPET2" frequency 19200000 Hz quality 440 Event timer "HPET3" frequency 19200000 Hz quality 440 Event timer "HPET4" frequency 19200000 Hz quality 440 Timecounter "ACPI-fast" frequency 3579545 Hz quality 900 acpi_timer0: <32-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0 pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0 pcib0: Length mismatch for 3 range: 1 vs 1000000010000 pci0: <ACPI PCI bus> on pcib0 pcib0: no PRT entry for 0.0.INTA vgapci0: <VGA-compatible display> port 0xf000-0xf03f mem 0xa0000000-0xa0ffffff,0x90000000-0x9fffffff at device 2.0 on pci0 vgapci0: Boot video device pci0: <simple comms> at device 15.0 (no driver attached) ahci0: <Intel Gemini Lake AHCI SATA controller> port 0xf090-0xf097,0xf080-0xf083,0xf060-0xf07f mem 0xa1410000-0xa1 411fff,0xa142a000-0xa142a0ff,0xa1429000-0xa14297ff at device 18.0 on pci0 ahci0: AHCI v1.31 with 2 6Gbps ports, Port Multiplier supported ahcich0: <AHCI channel> at channel 0 on ahci0 ahcich1: <AHCI channel> at channel 1 on ahci0 pcib1: <ACPI PCI-PCI bridge> at device 19.0 on pci0 pci1: <ACPI PCI bus> on pcib1 ix0: <Intel(R) X520 82599 (Dual SFP+)> port 0xe020-0xe03f mem 0xa1100000-0xa11fffff,0xa1304000-0xa1307fff at devic e 0.0 on pci1 ix0: Using 2048 TX descriptors and 2048 RX descriptors ix0: Using 4 RX queues 4 TX queues ix0: Using MSI-X interrupts with 5 vectors ix0: allocated for 4 queues ix0: allocated for 4 rx queues ix0: Ethernet address: a0:36:9f:da:1c:44 ix0: PCI Express Bus: Speed 5.0GT/s Width x1 ix0: Option ROM V1-b3534-p0 eTrack 0x8000095d ix0: netmap queues/slots: TX 4/2048, RX 4/2048 ix1: <Intel(R) X520 82599 (Dual SFP+)> port 0xe000-0xe01f mem 0xa1000000-0xa10fffff,0xa1300000-0xa1303fff at devic e 0.1 on pci1 ix1: Using 2048 TX descriptors and 2048 RX descriptors ix1: Using 4 RX queues 4 TX queues ix1: Using MSI-X interrupts with 5 vectors ix1: allocated for 4 queues ix1: allocated for 4 rx queues ix1: Ethernet address: a0:36:9f:da:1c:46 ix1: PCI Express Bus: Speed 5.0GT/s Width x1 ix1: Option ROM V1-b3534-p0 eTrack 0x8000095d ix1: netmap queues/slots: TX 4/2048, RX 4/2048 pcib2: <ACPI PCI-PCI bridge> at device 19.2 on pci0 pci2: <ACPI PCI bus> on pcib2 pcib3: <ACPI PCI-PCI bridge> at device 19.3 on pci0 pci3: <ACPI PCI bus> on pcib3 pcib4: <ACPI PCI-PCI bridge> at device 20.0 on pci0 pci4: <ACPI PCI bus> on pcib4 pcib5: <ACPI PCI-PCI bridge> at device 20.1 on pci0 pci5: <ACPI PCI bus> on pcib5 xhci0: <Intel Gemini Lake USB 3.0 controller> mem 0xa1400000-0xa140ffff irq 17 at device 21.0 on pci0 xhci0: 32 bytes context size, 64-bit DMA xhci0: xECP capabilities <PROTO,PROTO,VEND(c0),LEGACY,VEND(c6),VEND(c7),VEND(c2),DEBUG,VEND(c3),VEND(c4),VEND(c5), VEND(c8),VEND(c9),VEND(cb)> usbus0 on xhci0 usbus0: 5.0Gbps Super Speed USB v3.0 isab0: <PCI-ISA bridge> at device 31.0 on pci0 isa0: <ISA bus> on isab0 acpi_button0: <Power Button> on acpi0 acpi_spmc0: <System Power Management Controller> on acpi0 Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) Firmware Warning (ACPI): Possibly buggy BIOS with ACPI_TYPE_INTEGER for function enumeration (20260408/ACPI-3143) acpi_spmc0: DSMs supported: <Intel,Microsoft,AMD> acpi_spmc0: DSM Intel, revision 0: Supported functions: 0x7e<DEVICE_CONSTRAINTS,CRASH_DUMP_DEVICE,DISPLAY_OFF,DISP LAY_ON,LPI_ENTRY,LPI_EXIT> acpi_spmc0: DSM Microsoft, revision 0: Supported functions: 0 acpi_spmc0: DSM AMD, revision 0: Supported functions: 0 Fatal trap 12: page fault while in kernel mode cpuid = 0; apic id = 00 fault virtual address = 0x20 fault code = supervisor read data, page not present instruction pointer = 0x20:0xffffffff8051d28d stack pointer = 0x28:0xffffffff83dddc00 frame pointer = 0x28:0xffffffff83dddd00 processor eflags = interrupt enabled, resume, IOPL = 0 current thread = 0/100000 (kernel/kernel) rdi: fffff8000180d720 rsi: 0000000000000000 rdx: 0000000000000004 rcx: 0000000000000004 r8: 0000000000000040 r9: fffffe0008635d00 rax: 0000000000000000 rbx: 0000000000000008 rbp: ffffffff83dddd00 r10: 0000000000000000 r11: 000000005f42535f r12: 0000000000000000 r13: ffffffff816b8138 r14: 0000000000000028 r15: fffff8000180d558 panic: page fault cpuid = 0 time = 1 KDB: enter: panic [ thread pid 0 tid 100000 ] Stopped at kdb_enter+0x33: movq $0,0x20cb242(%rip) db>Some wrangling with Claude leads me to this commit: https://cgit.freebsd.org/src/commit/?id=c5daa5a4c32c which specifically states that the driver hasn't been tested on Intel hardware.
-
I'm not aware of anyone hitting that before, it might be something in your hardware/BIOS/firmware. Might be worth checking for a firmware update for the motherboard.
You might be able to disable that power management in the BIOS, too.
If all else fails, it may be possible to disable that driver with something like
hint.acpi_spmc.0.disabled=1in/boot/loader.conf.local -
The BIOS is running the latest version. I can only set the CPU C-state (which has no effect), not disable any kind of advanced power saving.
I did a stack-trace guided by Claude, this is what it came up with:
Faulting instruction: db> x/i 0xffffffff8051d28d acpi_spmc_attach+0x7ad: cmpq $0,0x20(%rax) Analysis: The faulting instruction is a NULL check on a field at offset 0x20 of a struct pointed to by %rax, where %rax is itself NULL. So a pointer returned earlier in attach was used without being checked. Offset 0x20 is beyond sizeof(ACPI_OBJECT) on amd64, so %rax is not a package element; it points at a larger struct. Suggested fix: Whatever pointer is obtained immediately before acpi_spmc_attach+0x7ad needs a NULL check with a graceful skip, rather than aborting attach or faulting. A device listed in the platform constraint table having no attached driver should be a normal, expected condition. -
Disabling it with a device hint would confirm that's issue.
You can also add that one time at the loader prompt to allow it to boot:
set hint.acpi_spmc.0.disabled=1 boot -
@stephenw10 Setting that hint at the loader prompt indeed allows pfSense to boot as normal.
-
Cool. You can then add the line to loader.conf.local.
Do you have a full crash report from the panic?
You can upload it here if so: https://nc.netgate.com/nextcloud/s/LMdq7DK5mABciqC
-
@stephenw10 Sure I could set that as a permanent hint, but is that really the solution? The FreeBSD commit I link to specifically states that it wasn't tested on Intel hardware. An untested commit leading to a kernel panic if the BIOS returns unexpected values requires a real fix imho, not a band-aid.
What kind of report do you need besides the bootlog from the first post?
-
Normally in the case of a kernel panic a crash report is created and should be shown as an alert on the dashboard. The crash report includes a full backtrace from the panicking process.
-
@stephenw10 Boot halts on the db> prompt. I then reboot, and add the hint at the loader prompt to succesfully boot into pfSense. There's no alert on the dashboard after this, and also nothing in /var/crash.
I did pull this from the db> prompt:
db> bt Tracing pid 0 tid 100000 td 0xffffffff8275ab20 kdb_enter() at kdb_enter+0x33/frame 0xffffffff83ddda70 panic() at panic+0x43/frame 0xffffffff83dddad0 trap_pfault() at trap_pfault+0x3a8/frame 0xffffffff83dddb30 calltrap() at calltrap+0x8/frame 0xffffffff83dddb30 --- trap 0xc, rip = 0xffffffff8051d28d, rsp = 0xffffffff83dddc00, rbp = 0xffffffff83dddd00 --- acpi_spmc_attach() at acpi_spmc_attach+0x7ad/frame 0xffffffff83dddd00 device_attach() at device_attach+0x448/frame 0xffffffff83dddd50 bus_attach_children() at bus_attach_children+0x2d/frame 0xffffffff83dddd70 acpi_probe_children() at acpi_probe_children+0x7a/frame 0xffffffff83dddde0 acpi_attach() at acpi_attach+0xa93/frame 0xffffffff83ddde60 device_attach() at device_attach+0x448/frame 0xffffffff83dddeb0 bus_attach_children() at bus_attach_children+0x2d/frame 0xffffffff83ddded0 nexus_acpi_attach() at nexus_acpi_attach+0x65/frame 0xffffffff83dddef0 device_attach() at device_attach+0x448/frame 0xffffffff83dddf40 bus_generic_new_pass() at bus_generic_new_pass+0x109/frame 0xffffffff83dddf70 root_bus_configure() at root_bus_configure+0x26/frame 0xffffffff83dddf90 configure() at configure+0x9/frame 0xffffffff83dddfa0 mi_startup() at mi_startup+0x1e3/frame 0xffffffff83dddff0 db> x/i 0xffffffff8051d28d acpi_spmc_attach+0x7ad: cmpq $0,0x20(%rax) -
Ah, nice.
Cool I'll run this up to some devs for next steps.
-
Can we see the ASL from the bios on that device?
acpidump -dt | gzip -c9 > my_computer.asl.gz -
@stephenw10 I've uploaded the file using the Nextcloud link from your earlier post.
For what it's worth, I've asked Claude (Opus 5 High) to analyze the file in relation to the kernel panic, but the forum keeps identifying it as spam. So here it is on Pastebin: https://pastebin.com/RkfRKQwA
@stephenw10 As a suggestion, also a patch crafted by Claude: https://pastebin.com/Cnh6H7Ga
-
J jimp referenced this topic
-
@TampertK said in 2.9.0 beta leads to kernel panic on boot:
I have a Fujitsu Futro S940 with an Intel Pentium J5005.
Just a question: Is someone with a Intel Celeron J3455 that hits this problem? (I have a Lab machine with this processor)
Thanks,
FireOdo -
This appears to be a bios issue rather than tied to a specific CPU.
-
@stephenw10 said in 2.9.0 beta leads to kernel panic on boot:
This appears to be a bios issue rather than tied to a specific CPU.
OK, thanks - I added that line to loader.conf.local as a precaution ... because it runs CE (2.8.1 now) and there is no BE backup.
(its a rel. cheap enclosure from China - no way to find any BIOS updates, if needed)Regards
-
You can create a backup BE in CE as long as it's running ZFS. But it won't automatically role back to it if boot fails.
-
@stephenw10 said in 2.9.0 beta leads to kernel panic on boot:
You can create a backup BE in CE as long as it's running ZFS. But it won't automatically role back to it if boot fails.
You're right, but without automatic rollback its not really useful (in this situation) ... IMHO
-
Yeah really the full ZFS upgrade process from the Plus is needed to get the full advantage.
-
@stephenw10 said in 2.9.0 beta leads to kernel panic on boot:
Yeah really the full ZFS upgrade process from the Plus is needed to get the full advantage.
I updated to 2.9.0 on this machine and it went (as far as I see for now) smooth. The loader.conf.local entry is necessary - see following post!
-
@stephenw10 said in 2.9.0 beta leads to kernel panic on boot:
Disabling it with a device hint would confirm that's issue.
You can also add that one time at the loader prompt to allow it to boot:
set hint.acpi_spmc.0.disabled=1 bootI was too optimist - removing that line from loader.conf.local gets me to the problem in this thread.
But at the loader prompt with
set hint.acpi_spmc.0.disabled=1 bootI get the machine up ...
Strange that in the dmesg the "acpi_spmc" doesn't show up ...
Privacy Policy · Cookie Policy