I got a BUG: unable to handle kernel NULL pointer dereference at virtual address 00000054 in cfq_dispatch_requests+0x2c5/0x454. I'm running 2.6.17-rc5-mm2 with Forrest Zhao's ahci resume patches of the other day. The system was basically idle with very little IO going on. It happens fairly regularly, but not triggered by any particular activity. The system had not been through a suspend/resume cycle. The oops is: BUG: unable to handle kernel NULL pointer dereference at virtual address 00000054 printing eip: c01da8af *pde = 2ff37001 Oops: 0000 [#1] SMP last sysfs file: /devices/system/cpu/cpu1/cpufreq/scaling_cur_freq Modules linked in: usb_storage uhci_hcd netconsole i915 drm cpufreq_conservative ipv6 autofs4 hidp rfcomm l2cap bluetooth sunrpc ip_conntrack_netbios_ns ipt_REJECT xt_state ip_conntrack nfnetlink xt_tcpudp iptable_filter ip_tables x_tables vfat fat dm_mirror dm_mod video sony_acpi ibm_acpi button battery asus_acpi ac lp parport_pc parport nvram snd_hda_intel snd_hda_codec snd_seq_dummy snd_seq_oss snd_seq_midi_event snd_seq snd_seq_device snd_pcm_oss mmc_block snd_mixer_oss sdhci snd_pcm ath_hal ohci1394 snd_timer sg ieee1394 e1000 mmc_core i2c_i801 snd i2c_core ehci_hcd soundcore snd_page_alloc pcspkr ext3 jbd ahci libata sd_mod scsi_mod CPU: 1 EIP: 0060:[] Tainted: P VLI EFLAGS: 00010046 (2.6.17-rc5-mm2 #17) EIP is at cfq_dispatch_requests+0x2c5/0x454 eax: 00000000 ebx: 00000000 ecx: 000e2e3b edx: 00000000 esi: c275fa30 edi: c275fa00 ebp: f47e1188 esp: eec12d18 ds: 007b es: 007b ss: 0068 Process su (pid: 4787, threadinfo=eec12000 task=ef6c8bf0) Stack: 000003e8 00000000 f5371b64 f5371b64 000001b3 00000004 00000000 00060001 efbd93c0 c275fa34 00000001 c26420b8 c26420b8 f7e04000 c26420b8 c01d02fb eec12d7c c014cbc0 c0314abf c2765548 c26420b8 c2765400 f7e04000 f88c69ef Call Trace: elv_next_request+0x11b/0x12a sync_page+0x0/0x3b _spin_lock_irqsave+0x9/0xd scsi_request_fn+0x5d/0x31d [scsi_mod] del_timer+0x41/0x47 blk_remove_plug+0x52/0x5e sync_page+0x0/0x3b __generic_unplug_device+0x1d/0x1f generic_unplug_device+0x29/0x35 blk_backing_dev_unplug+0xc/0xd block_sync_page+0x31/0x32 sync_page+0x33/0x3b __wait_on_bit_lock+0x2a/0x52 __lock_page+0x5a/0x60 wake_bit_function+0x0/0x3c do_generic_mapping_read+0x36e/0x5ef __generic_file_aio_read+0x182/0x1c7 file_read_actor+0x0/0xe0 generic_file_aio_read+0x40/0x47 do_sync_read+0xc3/0xfd autoremove_wake_function+0x0/0x35 do_sync_read+0x0/0xfd vfs_read+0xa6/0x157 sys_read+0x41/0x67 sysenter_past_esp+0x56/0x79 Code: 8d 46 34 39 46 34 74 32 8b 46 34 83 7e 10 01 8b 54 24 24 8b 0d 00 dc 43 c0 8b 68 3c 19 c0 83 e0 fc 8b 84 10 00 01 00 00 8b 55 14 <03> 42 54 39 c8 79 08 83 cb 20 89 5e 60 eb 03 8b 6e 20 8b 07 89 EIP: [] cfq_dispatch_requests+0x2c5/0x454 SS:ESP 0068:eec12d18 <3>BUG: sleeping function called from invalid context at include/linux/rwsem.h:53 in_atomic():0, irqs_disabled():1 blocking_notifier_call_chain+0x18/0x4b do_exit+0x19/0x797 printk+0x1b/0x1f die+0x296/0x2bb do_page_fault+0x57b/0x6e8 __do_page_cache_readahead+0x155/0x232 ext3_get_block+0x0/0xd3 [ext3] do_page_fault+0x0/0x6e8 error_code+0x39/0x40 cfq_dispatch_requests+0x2c5/0x454 elv_next_request+0x11b/0x12a sync_page+0x0/0x3b _spin_lock_irqsave+0x9/0xd scsi_request_fn+0x5d/0x31d [scsi_mod] del_timer+0x41/0x47 blk_remove_plug+0x52/0x5e sync_page+0x0/0x3b __generic_unplug_device+0x1d/0x1f generic_unplug_device+0x29/0x35 blk_backing_dev_unplug+0xc/0xd block_sync_page+0x31/0x32 sync_page+0x33/0x3b __wait_on_bit_lock+0x2a/0x52 __lock_page+0x5a/0x60 wake_bit_function+0x0/0x3c do_generic_mapping_read+0x36e/0x5ef __generic_file_aio_read+0x182/0x1c7 file_read_actor+0x0/0xe0 sys_read+0x41/0x67 sysenter_past_esp+0x56/0x79 BUG: spinlock recursion on CPU#1, su/4787 lock: c26421d8, .magic: dead4ead, .owner: su/4787, .owner_cpu: 1 _raw_spin_lock+0x36/0xe4 cfq_exit_io_context+0x6c/0x104 exit_io_context+0x65/0x6f do_exit+0x764/0x797 printk+0x1b/0x1f die+0x296/0x2bb do_page_fault+0x57b/0x6e8 BUG: spinlock lockup on CPU#0, syslogd/1777, c26421d8 _raw_spin_lock+0xc8/0xe4 __make_request+0x6b/0x333 generic_make_request+0x210/0x241 ext3_journal_dirty_data+0x0/0x32 [ext3] generic_file_buffered_write+0x4e5/0x613 submit_bio+0xb7/0xbe mempool_alloc+0x37/0xd3 bio_alloc_bioset+0x9b/0xf3 submit_bh+0xe4/0x102 __block_write_full_page+0x23a/0x340 ext3_get_block+0x0/0xd3 [ext3] block_write_full_page+0xd4/0xdc ext3_get_block+0x0/0xd3 [ext3] ext3_ordered_writepage+0xe7/0x194 [ext3] bget_one+0x0/0x7 [ext3] mpage_writepages+0x1b2/0x33c ext3_ordered_writepage+0x0/0x194 [ext3] mutex_lock+0x1a/0x28 do_writepages+0x2b/0x32 __filemap_fdatawrite_range+0x65/0x70 filemap_fdatawrite+0x23/0x27 do_fsync+0x36/0xa5 __do_fsync+0x1d/0x2b sysenter_past_esp+0x56/0x79 <0>BUG: spinlock lockup on CPU#1, su/4787, c26421d8 _raw_spin_lock+0xc8/0xe4 cfq_exit_io_context+0x6c/0x104 exit_io_context+0x65/0x6f do_exit+0x764/0x797 printk+0x1b/0x1f die+0x296/0x2bb do_page_fault+0x57b/0x6e8 __do_page_cache_readahead+0x155/0x232 ext3_get_block+0x0/0xd3 [ext3] do_page_fault+0x0/0x6e8 error_code+0x39/0x40 cfq_dispatch_requests+0x2c5/0x454 elv_next_request+0x11b/0x12a sync_page+0x0/0x3b _spin_lock_irqsave+0x9/0xd scsi_request_fn+0x5d/0x31d [scsi_mod] del_timer+0x41/0x47 blk_remove_plug+0x52/0x5e sync_page+0x0/0x3b __generic_unplug_device+0x1d/0x1f generic_unplug_device+0x29/0x35 blk_backing_dev_unplug+0xc/0xd block_sync_page+0x31/0x32 sync_page+0x33/0x3b __wait_on_bit_lock+0x2a/0x52 __lock_page+0x5a/0x60 wake_bit_function+0x0/0x3c do_generic_mapping_read+0x36e/0x5ef __generic_file_aio_read+0x182/0x1c7 file_read_actor+0x0/0xe0 generic_file_aio_read+0x40/0x47 do_sync_read+0xc3/0xfd autoremove_wake_function+0x0/0x35 do_sync_read+0x0/0xfd vfs_read+0xa6/0x157 sys_read+0x41/0x67 sysenter_past_esp+0x56/0x79 .config & boot dmesg attached. J