what's an evil packet ?

Harald Koenig (koenig@tat.physik.uni-tuebingen.de)
Tue, 8 Jul 1997 20:31:44 +0200


Hi,

for the last 4 days we're getting the following message

RPC: rpc_send sending evil packet:
c84adc5e 01000000 00000000 00000000 00000000 00000000 00000000 01000000

exactly every minute for just one dual-PPro200 box running Linux 2.0.30-SMP.
when this happens, the NFS traffic to one SGI IRIX 5.3 box ("ceres") is dead,
while networking (ping, telnet etc.) to ceres is still OK and NFS to other
SGI boxes doesn't have a problem.

what's this "evil packet", who is sending it to whom,
and what do these numbers tell you ?

here is a small snip from syslogs where NFS only was dead for a few minutes,
usually this lasts *much* longer (*many* hours or until reboot).

Jul 8 12:19:32 alamak kernel: NFS server ceres not responding, still trying.
Jul 8 12:19:36 alamak kernel: RPC: rpc_send sending evil packet:
Jul 8 12:19:36 alamak kernel: c84adc5e 01000000 00000000 00000000 00000000 00000000 00000000 01000000
Jul 8 12:20:36 alamak kernel: RPC: rpc_doio sending evil packet:
Jul 8 12:20:36 alamak kernel: c84adc5e 01000000 00000000 00000000 00000000 00000000 00000000 01000000
Jul 8 12:20:36 alamak kernel: RPC: rpc_send sending evil packet:
Jul 8 12:20:36 alamak kernel: c84adc5e 01000000 00000000 00000000 00000000 00000000 00000000 01000000
Jul 8 12:21:36 alamak kernel: RPC: rpc_send sending evil packet:
Jul 8 12:21:36 alamak kernel: c84adc5e 01000000 00000000 00000000 00000000 00000000 00000000 01000000
Jul 8 12:22:36 alamak kernel: RPC: rpc_send sending evil packet:
Jul 8 12:22:36 alamak kernel: c84adc5e 01000000 00000000 00000000 00000000 00000000 00000000 01000000
Jul 8 12:23:27 alamak kernel: NFS server ceres OK.

any idea or hint ? we're running 2.0.30-SMP on this PC for a long time now
with no problems until July 4th where this started.

another dual-PPro200 box with identical setup doesn't show these messages
or problem, neither do some single-PProswith 2.0.30, all in the same subnet
connected to the same hub...

Harald

--
All SCSI disks will from now on                     ___       _____
be required to send an email notice                0--,|    /OOOOOOO\
24 hours prior to complete hardware failure!      <_/  /  /OOOOOOOOOOO\
                                                    \  \/OOOOOOOOOOOOOOO\
                                                      \ OOOOOOOOOOOOOOOOO|//
Harald Koenig,                                         \/\/\/\/\/\/\/\/\/
Inst.f.Theoret.Astrophysik                              //  /     \\  \
koenig@tat.physik.uni-tuebingen.de                     ^^^^^       ^^^^^