mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	Johan Hovold <jhovold@gmail.com>, Felipe Balbi <balbi@ti.com>
Subject: [01/73] usb: musb: omap2430: fix kernel panic on reboot
Date: Fri, 04 Mar 2011 16:55:06 -0800	[thread overview]
Message-ID: <20110305005634.714960046@clark.kroah.org> (raw)
In-Reply-To: <20110305005720.GA16162@kroah.com>

2.6.37-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Johan Hovold <jhovold@gmail.com>

commit b193b412e62b134adf69af286c7e7f8e99259350 upstream.

Cancel idle timer in musb_platform_exit.

The idle timer could trigger after clock had been disabled leading to
kernel panic when MUSB_DEVCTL is accessed in musb_do_idle on 2.6.37.

The fault below is no longer triggered on 2.6.38-rc4 (clock is disabled
later, and only if compiled as a module, and the offending memory access
has moved) but the timer should be cancelled nonetheless.

Rebooting... musb_hdrc musb_hdrc: remove, state 4
usb usb1: USB disconnect, address 1
musb_hdrc musb_hdrc: USB bus 1 deregistered
Unhandled fault: external abort on non-linefetch (0x1028) at 0xfa0ab060
Internal error: : 1028 [#1] PREEMPT
last sysfs file: /sys/kernel/uevent_seqnum
Modules linked in:
CPU: 0    Not tainted  (2.6.37+ #6)
PC is at musb_do_idle+0x24/0x138
LR is at musb_do_idle+0x18/0x138
pc : [<c02377d8>]    lr : [<c02377cc>]    psr: 80000193
sp : cf2bdd80  ip : cf2bdd80  fp : c048a20c
r10: c048a60c  r9 : c048a40c  r8 : cf85e110
r7 : cf2bc000  r6 : 40000113  r5 : c0489800  r4 : cf85e110
r3 : 00000004  r2 : 00000006  r1 : fa0ab000  r0 : cf8a7000
Flags: Nzcv  IRQs off  FIQs on  Mode SVC_32  ISA ARM  Segment user
Control: 10c5387d  Table: 8faac019  DAC: 00000015
Process reboot (pid: 769, stack limit = 0xcf2bc2f0)
Stack: (0xcf2bdd80 to 0xcf2be000)
dd80: 00000103 c0489800 c02377b4 c005fa34 00000555 c0071a8c c04a3858 cf2bdda8
dda0: 00000555 c048a00c cf2bdda8 cf2bdda8 1838beb0 00000103 00000004 cf2bc000
ddc0: 00000001 00000001 c04896c8 0000000a 00000000 c005ac14 00000001 c003f32c
dde0: 00000000 00000025 00000000 cf2bc000 00000002 00000001 cf2bc000 00000000
de00: 00000001 c005ad08 cf2bc000 c002e07c c03ec039 ffffffff fa200000 c0033608
de20: 00000001 00000000 cf852c14 cf81f200 c045b714 c045b708 cf2bc000 c04a37e8
de40: c0033c04 cf2bc000 00000000 00000001 cf2bde68 cf2bde68 c01c3abc c004f7d8
de60: 60000013 ffffffff c0033c04 00000000 01234567 fee1dead 00000000 c006627c
de80: 00000001 c00662c8 28121969 c00663ec cfa38c40 cf9f6a00 cf2bded0 cf9f6a0c
dea0: 00000000 cf92f000 00008914 c02cd284 c04a55c8 c028b398 c00715c0 becf24a8
dec0: 30687465 00000000 00000000 00000000 00000002 1301a8c0 00000000 00000000
dee0: 00000002 1301a8c0 00000000 00000000 c0450494 cf527920 00011f10 cf2bdf08
df00: 00011f10 cf2bdf10 00011f10 cf2bdf18 c00f0b44 c004f7e8 cf2bdf18 cf2bdf18
df20: 00011f10 cf2bdf30 00011f10 cf2bdf38 cf401300 cf486100 00000008 c00d2b28
df40: 00011f10 cf401300 00200200 c00d3388 00011f10 cfb63a88 cfb63a80 c00c2f08
df60: 00000000 00000000 cfb63a80 00000000 cf0a3480 00000006 c0033c04 cfb63a80
df80: 00000000 c00c0104 00000003 cf0a3480 cfb63a80 00000000 00000001 00000004
dfa0: 00000058 c0033a80 00000000 00000001 fee1dead 28121969 01234567 00000000
dfc0: 00000000 00000001 00000004 00000058 00000001 00000001 00000000 00000001
dfe0: 4024d200 becf2cb0 00009210 4024d218 60000010 fee1dead 00000000 00000000
[<c02377d8>] (musb_do_idle+0x24/0x138) from [<c005fa34>] (run_timer_softirq+0x1a8/0x26)
[<c005fa34>] (run_timer_softirq+0x1a8/0x26c) from [<c005ac14>] (__do_softirq+0x88/0x13)
[<c005ac14>] (__do_softirq+0x88/0x138) from [<c005ad08>] (irq_exit+0x44/0x98)
[<c005ad08>] (irq_exit+0x44/0x98) from [<c002e07c>] (asm_do_IRQ+0x7c/0xa0)
[<c002e07c>] (asm_do_IRQ+0x7c/0xa0) from [<c0033608>] (__irq_svc+0x48/0xa8)
Exception stack(0xcf2bde20 to 0xcf2bde68)
de20: 00000001 00000000 cf852c14 cf81f200 c045b714 c045b708 cf2bc000 c04a37e8
de40: c0033c04 cf2bc000 00000000 00000001 cf2bde68 cf2bde68 c01c3abc c004f7d8
de60: 60000013 ffffffff
[<c0033608>] (__irq_svc+0x48/0xa8) from [<c004f7d8>] (sub_preempt_count+0x0/0xb8)
Code: ebf86030 e5940098 e594108c e5902010 (e5d13060)
---[ end trace 3689c0d808f9bf7c ]---
Kernel panic - not syncing: Fatal exception in interrupt

Signed-off-by: Johan Hovold <jhovold@gmail.com>
Signed-off-by: Felipe Balbi <balbi@ti.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 drivers/usb/musb/omap2430.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/usb/musb/omap2430.c
+++ b/drivers/usb/musb/omap2430.c
@@ -317,6 +317,7 @@ static int musb_platform_resume(struct m
 
 int musb_platform_exit(struct musb *musb)
 {
+	del_timer_sync(&musb_idle_timer);
 
 	musb_platform_suspend(musb);
 



  reply	other threads:[~2011-03-05  1:20 UTC|newest]

Thread overview: 74+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-03-05  0:57 [00/73] 2.6.37.3-stable review Greg KH
2011-03-05  0:55 ` Greg KH [this message]
2011-03-05  0:55 ` [02/73] USB: add quirks entry for Keytouch QWERTY Panel Greg KH
2011-03-05  0:55 ` [03/73] USB: Add Samsung SGH-I500/Android modem ID switch to visor driver Greg KH
2011-03-05  0:55 ` [04/73] USB: Add quirk for Samsung Android phone modem Greg KH
2011-03-05  0:55 ` [05/73] USB: serial/usb_wwan, fix tty NULL dereference Greg KH
2011-03-05  0:55 ` [06/73] sierra: add new ID for Airprime/Sierra USB IP modem Greg KH
2011-03-05  0:55 ` [07/73] Revert "Bluetooth: Enable USB autosuspend by default on btusb" Greg KH
2011-03-05  0:55 ` [08/73] p54pci: update receive dma buffers before and after processing Greg KH
2011-03-05  0:55 ` [09/73] Revert "drm/radeon/kms: switch back to min->max pll post divider iteration" Greg KH
2011-03-05  0:55 ` [10/73] tcp: fix inet_twsk_deschedule() Greg KH
2011-03-05  0:55 ` [11/73] mm: prevent concurrent unmap_mapping_range() on the same inode Greg KH
2011-03-05  0:55 ` [12/73] staging: brcm80211: remove assert to avoid panic since 2.6.37 kernel Greg KH
2011-03-05  0:55 ` [13/73] staging: brcm80211: bugfix for softmac crash on multi cpu configurations Greg KH
2011-03-05  0:55 ` [14/73] staging: usbip: vhci: update reference count for usb_device Greg KH
2011-03-05  0:55 ` [15/73] staging: usbip: vhci: give back URBs from in-flight unlink requests Greg KH
2011-03-05  0:55 ` [16/73] staging: usbip: vhci: refuse to enqueue for dead connections Greg KH
2011-03-05  0:55 ` [17/73] staging: usbip: vhci: use urb->dev->portnum to find port Greg KH
2011-03-05  0:55 ` [18/73] epoll: prevent creating circular epoll structures Greg KH
2011-03-05  0:55 ` [19/73] swiotlb: fix wrong panic Greg KH
2011-03-05  0:55 ` [20/73] ldm: corrupted partition table can cause kernel oops Greg KH
2011-03-05  0:55 ` [21/73] drivers/rtc/rtc-ds3232.c: fix time range difference between linux and RTC chip Greg KH
2011-03-05  0:55 ` [22/73] mm: fix dubious code in __count_immobile_pages() Greg KH
2011-03-05  0:55 ` [23/73] md: correctly handle probe of an mdp device Greg KH
2011-03-05  0:55 ` [24/73] md: avoid spinlock problem in blk_throtl_exit Greg KH
2011-03-05  0:55 ` [25/73] md: Fix - again - partition detection when array becomes active Greg KH
2011-03-05  0:55 ` [26/73] Fix over-zealous flush_disk when changing device size Greg KH
2011-03-05  0:55 ` [27/73] PM: Make ACPI wakeup from S5 work again when CONFIG_PM_SLEEP is unset Greg KH
2011-03-05  0:55 ` [28/73] x86 quirk: Fix polarity for IRQ0 pin2 override on SB800 systems Greg KH
2011-03-05  0:55 ` [29/73] xhci: Avoid BUG() in interrupt context Greg KH
2011-03-05  0:55 ` [30/73] xhci: Clarify some expressions in the TRB math Greg KH
2011-03-05  0:55 ` [31/73] xhci: Fix errors in the running total calculations " Greg KH
2011-03-05  0:55 ` [32/73] xhci: Fix an error in count_sg_trbs_needed() Greg KH
2011-03-05  0:55 ` [33/73] USB: Reset USB 3.0 devices on (re)discovery Greg KH
2011-03-05  0:55 ` [34/73] USB: prevent buggy hubs from crashing the USB stack Greg KH
2011-03-05  0:55 ` [35/73] usb: musb: core: set has_tt flag Greg KH
2011-03-05  0:55 ` [36/73] ALSA: HDA: Add a new Conexant codec 506e (20590) Greg KH
2011-03-05  0:55 ` [37/73] ALSA: usb-audio: fix oops due to cleanup race when disconnecting Greg KH
2011-03-05  0:55 ` [38/73] ALSA: HDA: Fix mic initialization in VIA auto parser Greg KH
2011-03-05  0:55 ` [39/73] ALSA: HDA: Add ideapad quirk for two Dell machines Greg KH
2011-03-05  0:55 ` [40/73] ocfs2: Check heartbeat mode for kernel stacks only Greg KH
2011-03-05  0:55 ` [41/73] Ocfs2/refcounttree: Fix a bug for refcounttree to writeback clusters in a right number Greg KH
2011-03-05  0:55 ` [42/73] drm: fix unsigned vs signed comparison issue in modeset ctl ioctl Greg KH
2011-03-05  0:55 ` [43/73] ACPI / debugfs: Fix buffer overflows, double free Greg KH
2011-03-05  0:55 ` [44/73] mfd: Avoid tps6586x burst writes Greg KH
2011-03-05  0:55 ` [45/73] mfd: Fix NULL pointer due to non-initialized ucb1x00-ts absinfo Greg KH
2011-03-05  0:55 ` [46/73] x86: Use u32 instead of long to set reset vector back to 0 Greg KH
2011-03-05  0:55 ` [47/73] Bluetooth: add Atheros BT AR9285 fw supported Greg KH
2011-03-05  0:55 ` [48/73] Bluetooth: fix crash with quirky dongles doing sound Greg KH
2011-03-05  0:55 ` [49/73] Bluetooth: Add Atheros BT AR5BBU12 fw supported Greg KH
2011-03-05  0:55 ` [50/73] eukrea-tlv320: fix platform_name Greg KH
2011-03-05  0:55 ` [51/73] ASoC: correct pxa AC97 DAI names Greg KH
2011-03-05  0:55 ` [52/73] fuse: fix hang of single threaded fuseblk filesystem Greg KH
2011-03-05  0:55 ` [53/73] clockevents: Prevent oneshot mode when broadcast device is periodic Greg KH
2011-03-05  0:55 ` [54/73] ext2: Fix link count corruption under heavy link+rename load Greg KH
2011-03-05  0:56 ` [55/73] mm: vmstat: use a single setter function and callback for adjusting percpu thresholds Greg KH
2011-03-05  0:56 ` [56/73] e1000e: 82579 PHY incorrectly identified during init Greg KH
2011-03-05  0:56 ` [57/73] Staging: comedi: Add MODULE_LICENSE and similar to NI modules Greg KH
2011-03-05  0:56 ` [58/73] fix cfg80211_wext_siwfreq lock ordering Greg KH
2011-03-05  0:56 ` [59/73] tg3: Restrict phy ioctl access Greg KH
2011-03-05  0:56 ` [60/73] drm/i915: fix memory corruption with GM965 and >4GB RAM Greg KH
2011-03-05  0:56 ` [61/73] blk-throttle: Do not use kblockd workqueue for throtl work Greg KH
2011-03-05  0:56 ` [62/73] block: add @force_kblockd to __blk_run_queue() Greg KH
2011-03-05  0:56 ` [63/73] block: blk-flush shouldnt call directly into q->request_fn() __blk_run_queue() Greg KH
2011-03-05  0:56 ` [64/73] block: kill loop_mutex Greg KH
2011-03-05  0:56 ` [65/73] ath9k_htc: Fix an endian issue Greg KH
2011-03-05  0:56 ` [66/73] p54usb: add Senao NUB-350 usbid Greg KH
2011-03-05  0:56 ` [67/73] nilfs2: fix regression that i-flag is not set on changeless checkpoints Greg KH
2011-03-05  0:56 ` [68/73] carl9170: add Airlive X.USB a/b/g/n USBID Greg KH
2011-03-05  0:56 ` [69/73] r8169: disable ASPM Greg KH
2011-03-05  0:56 ` [70/73] dccp: fix oops on Reset after close Greg KH
2011-03-05  0:56 ` [71/73] e1000e: disable broken PHY wakeup for ICH10 LOMs, use MAC wakeup instead Greg KH
2011-03-05  0:56 ` [72/73] DNS: Fix a NULL pointer deref when trying to read an error key [CVE-2011-1076] Greg KH
2011-03-05  0:56 ` [73/73] arp_notify: unconditionally send gratuitous ARP for NETDEV_NOTIFY_PEERS Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110305005634.714960046@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=balbi@ti.com \
    --cc=jhovold@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®