I've been playing with PAGE_OFFSET as a config option for a while, but it appears that it broke in 2.5 around 2.5.40, when I'm not using a normal 3:1 split. I've attached my current patch. This oops shows it dying at include/asm/apic.h:36, but I've also seen it die at include/asm/smp.h:108 too. Both of these do things casting APIC_BASE and dereferencing it: ((volatile unsigned long *)(APIC_BASE+reg)); GET_APIC_LOGICAL_ID(*(unsigned long *)(APIC_BASE+APIC_LDR)); Any ideas? Unable to handle kernel paging request at virtual address ffffe020 803987c9 *pde = 00000000 Oops: 0000 CPU: 1 EIP: 0060:[<803987c9>] Not tainted Using defaults from ksymoops -t elf32-i386 -a i386 EFLAGS: 00010002 eax: 00000001 ebx: 00000003 ecx: 802f1d38 edx: 000000c0 esi: 00000000 edi: 00000000 ebp: 00000000 esp: bff8bfbc ds: 0068 es: 0068 ss: 0068 Stack: 00000003 8039889a 00000e7a ffffffff 00000246 fffff186 8011ba3e 00000e4d 00000000 803f10ea 00000246 8011b975 80375800 00000b6f 10624dd3 00000000 8011380e >>EIP; 803987c9 <===== >>ecx; 802f1d38 Trace; 8011ba3e Trace; 8011b975 Trace; 8011380e Code; 803987c9 00000000 <_EIP>: Code; 803987c9 <===== 0: 8b 15 20 e0 ff ff mov 0xffffe020,%edx <===== Code; 803987cf 6: b8 00 e0 ff ff mov $0xffffe000,%eax Code; 803987d4 b: 21 e0 and %esp,%eax Code; 803987d6 d: 8b 58 0c mov 0xc(%eax),%ebx Code; 803987d9 10: c1 ea 18 shr $0x18,%edx Code; 803987dc 13: 83 00 00 addl $0x0,(%eax) -- Dave Hansen haveblue@us.ibm.com