* kernel BUG at mm/slab.c:601
@ 2008-11-18 23:24 Brian Phelps
2008-11-19 13:40 ` Brian Phelps
2008-11-19 22:19 ` Vegard Nossum
0 siblings, 2 replies; 11+ messages in thread
From: Brian Phelps @ 2008-11-18 23:24 UTC (permalink / raw)
To: linux-kernel
This possible kernel bug (see bottom) is very reproducible when the
pci bus gets loaded with traffic, specifically video data.
It has been reproduced on 2 identical machines.
Please let me know if you need more information
# uname -r
2.6.27.6
# free -m
total used free shared buffers cached
Mem: 487 139 347 0 2 24
-/+ buffers/cache: 113 374
Swap: 0 0 0
#gcc -v
Using built-in specs.
Target: i486-linux-gnu
Configured with: ../src/configure -v --with-pkgversion='Debian
4.3.2-1' --with-bugurl=file:///usr/share/doc/gcc-4.3/README.Bugs
--enable-languages=c,c++,fortran,objc,obj-c++ --prefix=/usr
--enable-shared --with-system-zlib --libexecdir=/usr/lib
--without-included-gettext --enable-threads=posix --enable-nls
--with-gxx-include-dir=/usr/include/c++/4.3 --program-suffix=-4.3
--enable-clocale=gnu --enable-libstdcxx-debug --enable-objc-gc
--enable-mpfr --enable-targets=all --enable-cld
--enable-checking=release --build=i486-linux-gnu --host=i486-linux-gnu
--target=i486-linux-gnu
Thread model: posix
gcc version 4.3.2 (Debian 4.3.2-1)
# lspci -v
00:00.0 Host bridge: Intel Corporation 82G33/G31/P35/P31 Express DRAM
Controller (rev 10)
Flags: bus master, fast devsel, latency 0
Capabilities: [e0] Vendor Specific Information <?>
Kernel driver in use: agpgart-intel
Kernel modules: intel-agp
00:01.0 PCI bridge: Intel Corporation 82G33/G31/P35/P31 Express PCI
Express Root Port (rev 10) (prog-if 00 [Normal decode])
Flags: bus master, fast devsel, latency 0
Bus: primary=00, secondary=01, subordinate=01, sec-latency=0
Capabilities: [88] Subsystem: Intel Corporation Device 0000
Capabilities: [80] Power Management version 3
Capabilities: [90] Message Signalled Interrupts: Mask- 64bit-
Queue=0/0 Enable+
Capabilities: [a0] Express Root Port (Slot+), MSI 00
Capabilities: [100] Virtual Channel <?>
Capabilities: [140] Root Complex Link <?>
Kernel driver in use: pcieport-driver
Kernel modules: shpchp
00:02.0 VGA compatible controller: Intel Corporation 82G33/G31 Express
Integrated Graphics Controller (rev 10) (prog-if 00 [VGA controller])
Subsystem: Intel Corporation 82G33/G31 Express Integrated
Graphics Controller
Flags: bus master, fast devsel, latency 0, IRQ 16
Memory at feb00000 (32-bit, non-prefetchable) [size=512K]
I/O ports at e140 [size=8]
Memory at c0000000 (32-bit, prefetchable) [size=256M]
Memory at fe900000 (32-bit, non-prefetchable) [size=1M]
Capabilities: [90] Message Signalled Interrupts: Mask- 64bit-
Queue=0/0 Enable-
Capabilities: [d0] Power Management version 2
00:1b.0 Audio device: Intel Corporation 82801G (ICH7 Family) High
Definition Audio Controller (rev 01)
Subsystem: Intel Corporation Device d608
Flags: bus master, fast devsel, latency 0, IRQ 16
Memory at feb80000 (64-bit, non-prefetchable) [size=16K]
Capabilities: [50] Power Management version 2
Capabilities: [60] Message Signalled Interrupts: Mask- 64bit+
Queue=0/0 Enable-
Capabilities: [70] Express Root Complex Integrated Endpoint, MSI 00
Capabilities: [100] Virtual Channel <?>
Capabilities: [130] Root Complex Link <?>
Kernel driver in use: HDA Intel
Kernel modules: snd-hda-intel
00:1c.0 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express
Port 1 (rev 01) (prog-if 00 [Normal decode])
Flags: bus master, fast devsel, latency 0
Bus: primary=00, secondary=02, subordinate=02, sec-latency=0
Capabilities: [40] Express Root Port (Slot+), MSI 00
Capabilities: [80] Message Signalled Interrupts: Mask- 64bit-
Queue=0/0 Enable+
Capabilities: [90] Subsystem: Intel Corporation 82801G (ICH7
Family) PCI Express Port 1
Capabilities: [a0] Power Management version 2
Capabilities: [100] Virtual Channel <?>
Capabilities: [180] Root Complex Link <?>
Kernel driver in use: pcieport-driver
Kernel modules: shpchp
00:1c.1 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express
Port 2 (rev 01) (prog-if 00 [Normal decode])
Flags: bus master, fast devsel, latency 0
Bus: primary=00, secondary=03, subordinate=03, sec-latency=0
I/O behind bridge: 0000d000-0000dfff
Memory behind bridge: fea00000-feafffff
Capabilities: [40] Express Root Port (Slot+), MSI 00
Capabilities: [80] Message Signalled Interrupts: Mask- 64bit-
Queue=0/0 Enable+
Capabilities: [90] Subsystem: Intel Corporation 82801G (ICH7
Family) PCI Express Port 2
Capabilities: [a0] Power Management version 2
Capabilities: [100] Virtual Channel <?>
Capabilities: [180] Root Complex Link <?>
Kernel driver in use: pcieport-driver
Kernel modules: shpchp
00:1d.0 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
UHCI Controller #1 (rev 01) (prog-if 00 [UHCI])
Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #1
Flags: bus master, medium devsel, latency 0, IRQ 23
I/O ports at e080 [size=32]
Kernel driver in use: uhci_hcd
Kernel modules: uhci-hcd
00:1d.1 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
UHCI Controller #2 (rev 01) (prog-if 00 [UHCI])
Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #2
Flags: bus master, medium devsel, latency 0, IRQ 19
I/O ports at e060 [size=32]
Kernel driver in use: uhci_hcd
Kernel modules: uhci-hcd
00:1d.2 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
UHCI Controller #3 (rev 01) (prog-if 00 [UHCI])
Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #3
Flags: bus master, medium devsel, latency 0, IRQ 18
I/O ports at e040 [size=32]
Kernel driver in use: uhci_hcd
Kernel modules: uhci-hcd
00:1d.3 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
UHCI Controller #4 (rev 01) (prog-if 00 [UHCI])
Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #4
Flags: bus master, medium devsel, latency 0, IRQ 16
I/O ports at e020 [size=32]
Kernel driver in use: uhci_hcd
Kernel modules: uhci-hcd
00:1d.7 USB Controller: Intel Corporation 82801G (ICH7 Family) USB2
EHCI Controller (rev 01) (prog-if 20 [EHCI])
Subsystem: Intel Corporation 82801G (ICH7 Family) USB2 EHCI Controller
Flags: bus master, medium devsel, latency 0, IRQ 23
Memory at feb84000 (32-bit, non-prefetchable) [size=1K]
Capabilities: [50] Power Management version 2
Capabilities: [58] Debug port: BAR=1 offset=00a0
Kernel driver in use: ehci_hcd
Kernel modules: ehci-hcd
00:1e.0 PCI bridge: Intel Corporation 82801 PCI Bridge (rev e1)
(prog-if 01 [Subtractive decode])
Flags: bus master, fast devsel, latency 0
Bus: primary=00, secondary=04, subordinate=06, sec-latency=248
Prefetchable memory behind bridge: 00000000d0000000-00000000d01fffff
Capabilities: [50] Subsystem: Gammagraphx, Inc. Device 0000
00:1f.0 ISA bridge: Intel Corporation 82801GB/GR (ICH7 Family) LPC
Interface Bridge (rev 01)
Subsystem: Intel Corporation DeskTop Board D945GTP
Flags: bus master, medium devsel, latency 0
Capabilities: [e0] Vendor Specific Information <?>
Kernel modules: intel-rng, iTCO_wdt
00:1f.1 IDE interface: Intel Corporation 82801G (ICH7 Family) IDE
Controller (rev 01) (prog-if 8a [Master SecP PriP])
Subsystem: Intel Corporation 82801G (ICH7 Family) IDE Controller
Flags: bus master, medium devsel, latency 0, IRQ 18
I/O ports at 01f0 [size=8]
I/O ports at 03f4 [size=1]
I/O ports at 0170 [size=8]
I/O ports at 0374 [size=1]
I/O ports at e0f0 [size=16]
Kernel driver in use: PIIX_IDE
Kernel modules: ata_piix, piix
00:1f.2 IDE interface: Intel Corporation 82801GB/GR/GH (ICH7 Family)
SATA IDE Controller (rev 01) (prog-if 8f [Master SecP SecO PriP PriO])
Subsystem: Intel Corporation 82801GB/GR/GH (ICH7 Family) SATA
IDE Controller
Flags: bus master, 66MHz, medium devsel, latency 0, IRQ 19
I/O ports at e0e0 [size=8]
I/O ports at e0d0 [size=4]
I/O ports at e0c0 [size=8]
I/O ports at e0b0 [size=4]
I/O ports at e0a0 [size=16]
Capabilities: [70] Power Management version 2
Kernel driver in use: ata_piix
Kernel modules: ata_piix
00:1f.3 SMBus: Intel Corporation 82801G (ICH7 Family) SMBus Controller (rev 01)
Subsystem: Intel Corporation Device d608
Flags: medium devsel, IRQ 19
I/O ports at e000 [size=32]
Kernel driver in use: i801_smbus
Kernel modules: i2c-i801
03:00.0 Ethernet controller: Realtek Semiconductor Co., Ltd.
RTL8111/8168B PCI Express Gigabit Ethernet controller (rev 01)
Subsystem: Intel Corporation Device d608
Flags: bus master, fast devsel, latency 0, IRQ 1276
I/O ports at d000 [size=256]
Memory at fea20000 (64-bit, non-prefetchable) [size=4K]
Expansion ROM at fea00000 [disabled] [size=128K]
Capabilities: [40] Power Management version 2
Capabilities: [48] Vital Product Data <?>
Capabilities: [50] Message Signalled Interrupts: Mask- 64bit+
Queue=0/1 Enable+
Capabilities: [60] Express Endpoint, MSI 00
Capabilities: [84] Vendor Specific Information <?>
Capabilities: [100] Advanced Error Reporting <?>
Capabilities: [12c] Virtual Channel <?>
Capabilities: [148] Device Serial Number 68-81-ec-00-00-00-00-00
Capabilities: [154] Power Budgeting <?>
Kernel driver in use: r8169
Kernel modules: r8169
04:05.0 PCI bridge: Hint Corp HB6 Universal PCI-PCI bridge
(non-transparent mode) (rev 11) (prog-if 00 [Normal decode])
Flags: bus master, medium devsel, latency 248
Bus: primary=04, secondary=05, subordinate=05, sec-latency=248
Prefetchable memory behind bridge: d0100000-d01fffff
Capabilities: [80] Power Management version 2
Capabilities: [90] CompactPCI hot-swap <?>
Kernel modules: shpchp
04:06.0 PCI bridge: Hint Corp HB6 Universal PCI-PCI bridge
(non-transparent mode) (rev 11) (prog-if 00 [Normal decode])
Flags: bus master, medium devsel, latency 248
Bus: primary=04, secondary=06, subordinate=06, sec-latency=248
Prefetchable memory behind bridge: d0000000-d00fffff
Capabilities: [80] Power Management version 2
Capabilities: [90] CompactPCI hot-swap <?>
Kernel modules: shpchp
05:08.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa00:1460
Flags: bus master, medium devsel, latency 248, IRQ 20
Memory at d0107000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
05:08.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa00:1460
Flags: bus master, medium devsel, latency 248, IRQ 11
Memory at d0106000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
05:09.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa01:1461
Flags: bus master, medium devsel, latency 248, IRQ 21
Memory at d0105000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
05:09.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa01:1461
Flags: bus master, medium devsel, latency 248, IRQ 10
Memory at d0104000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
05:0a.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa02:1462
Flags: bus master, medium devsel, latency 248, IRQ 22
Memory at d0103000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
05:0a.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa02:1462
Flags: bus master, medium devsel, latency 248, IRQ 5
Memory at d0102000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
05:0b.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa03:1463
Flags: bus master, medium devsel, latency 248, IRQ 23
Memory at d0101000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
05:0b.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa03:1463
Flags: bus master, medium devsel, latency 248, IRQ 5
Memory at d0100000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
06:08.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa00:1460
Flags: bus master, medium devsel, latency 248, IRQ 21
Memory at d0007000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
06:08.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa00:1460
Flags: bus master, medium devsel, latency 248, IRQ 10
Memory at d0006000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
06:09.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa01:1461
Flags: bus master, medium devsel, latency 248, IRQ 22
Memory at d0005000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
06:09.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa01:1461
Flags: bus master, medium devsel, latency 248, IRQ 5
Memory at d0004000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
06:0a.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa02:1462
Flags: bus master, medium devsel, latency 248, IRQ 23
Memory at d0003000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
06:0a.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa02:1462
Flags: bus master, medium devsel, latency 248, IRQ 5
Memory at d0002000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
06:0b.0 Multimedia video controller: Brooktree Corporation Bt878 Video
Capture (rev 11)
Subsystem: Device aa03:1463
Flags: bus master, medium devsel, latency 248, IRQ 20
Memory at d0001000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
Kernel driver in use: bttv
Kernel modules: bttv
06:0b.1 Multimedia controller: Brooktree Corporation Bt878 Audio
Capture (rev 11)
Subsystem: Device aa03:1463
Flags: bus master, medium devsel, latency 248, IRQ 11
Memory at d0000000 (32-bit, prefetchable) [size=4K]
Capabilities: [44] Vital Product Data <?>
Capabilities: [4c] Power Management version 2
My processor is:
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 15
model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
stepping : 11
cpu MHz : 2399.941
cache size : 4096 KB
physical id : 0
siblings : 4
core id : 0
cpu cores : 4
apicid : 0
initial apicid : 0
fpu : yes
fpu_exception : yes
cpuid level : 10
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
bogomips : 4799.88
clflush size : 64
cache_alignment : 64
address sizes : 36 bits physical, 48 bits virtual
power management:
processor : 1
vendor_id : GenuineIntel
cpu family : 6
model : 15
model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
stepping : 11
cpu MHz : 2399.941
cache size : 4096 KB
physical id : 0
siblings : 4
core id : 1
cpu cores : 4
apicid : 1
initial apicid : 1
fpu : yes
fpu_exception : yes
cpuid level : 10
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
bogomips : 4799.94
clflush size : 64
cache_alignment : 64
address sizes : 36 bits physical, 48 bits virtual
power management:
processor : 2
vendor_id : GenuineIntel
cpu family : 6
model : 15
model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
stepping : 11
cpu MHz : 2399.941
cache size : 4096 KB
physical id : 0
siblings : 4
core id : 2
cpu cores : 4
apicid : 2
initial apicid : 2
fpu : yes
fpu_exception : yes
cpuid level : 10
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
bogomips : 4799.97
clflush size : 64
cache_alignment : 64
address sizes : 36 bits physical, 48 bits virtual
power management:
processor : 3
vendor_id : GenuineIntel
cpu family : 6
model : 15
model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
stepping : 11
cpu MHz : 2399.941
cache size : 4096 KB
physical id : 0
siblings : 4
core id : 3
cpu cores : 4
apicid : 3
initial apicid : 3
fpu : yes
fpu_exception : yes
cpuid level : 10
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
bogomips : 4799.95
clflush size : 64
cache_alignment : 64
address sizes : 36 bits physical, 48 bits virtual
power management:
[ 213.780055] ------------[ cut here ]------------
[ 213.780060] kernel BUG at mm/slab.c:601!
[ 213.780063] invalid opcode: 0000 [1] SMP
[ 213.780066] CPU 3
[ 213.780068] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom i2c_i801 rng_core
i2c_core ftdi_sio video snd_pcsp snd_hda_intel shpchp pci_hotplug
iTCO_wdt output usbserial button snd_pcm intel_agp snd_timer snd
soundcore snd_page_alloc evdev ext2 mbcache sd_mod ata_piix usbhid hid
ff_memless ata_generic piix libata scsi_mod dock floppy
ide_pci_generic ide_core ehci_hcd r8169 mii uhci_hcd thermal processor
fan thermal_sys
[ 213.780117] Pid: 18, comm: events/3 Not tainted 2.6.27.6 #3
[ 213.780119] RIP: 0010:[<ffffffff8029c3d3>] [<ffffffff8029c3d3>]
free_block+0x59/0x11f
[ 213.780128] RSP: 0000:ffff88001ea2ddd0 EFLAGS: 00010002
[ 213.780131] RAX: 0100000000010068 RBX: ffff88001c8043c0 RCX: ffffe20000000000
[ 213.780134] RDX: ffffe200005e5830 RSI: ffff88001cc0c018 RDI: ffff88001af4a580
[ 213.780136] RBP: ffff88001af4a580 R08: 0000000000000000 R09: ffff88001eefba18
[ 213.780139] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
[ 213.780141] R13: ffff88001cc0c018 R14: 000000000000002c R15: 000000000000002c
[ 213.780144] FS: 0000000000000000(0000) GS:ffff88001e9d5940(0000)
knlGS:0000000000000000
[ 213.780147] CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b
[ 213.780150] CR2: 00000000f7efff05 CR3: 000000000612c000 CR4: 00000000000006e0
[ 213.780152] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 213.780155] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 213.780158] Process events/3 (pid: 18, threadinfo ffff88001ea2c000,
task ffff88001ea2b500)
[ 213.780160] Stack: 0000000000000000 ffff88001cc0c018
000000000000002c ffff88001cc0c000
[ 213.780166] ffff88001cc9ac40 0000000000000000 ffff88001c8043c0
ffffffff8029c651
[ 213.780171] 0000000000000000 ffffffff805f61d0 ffff88001cc9ac40
ffff88001c8043c0
[ 213.780175] Call Trace:
[ 213.780179] [<ffffffff8029c651>] ? drain_array+0x89/0xbb
[ 213.780182] [<ffffffff8029d323>] ? cache_reap+0x105/0x205
[ 213.780186] [<ffffffff8029d21e>] ? cache_reap+0x0/0x205
[ 213.780190] [<ffffffff80244f04>] ? run_workqueue+0x79/0xfe
[ 213.780193] [<ffffffff80245061>] ? worker_thread+0xd8/0xe7
[ 213.780197] [<ffffffff8024839a>] ? autoremove_wake_function+0x0/0x2e
[ 213.780200] [<ffffffff80244f89>] ? worker_thread+0x0/0xe7
[ 213.780203] [<ffffffff80248076>] ? kthread+0x47/0x73
[ 213.780207] [<ffffffff80233bd8>] ? schedule_tail+0x27/0x5f
[ 213.780211] [<ffffffff8020ce69>] ? child_rip+0xa/0x11
[ 213.780215] [<ffffffff8024802f>] ? kthread+0x0/0x73
[ 213.780218] [<ffffffff8020ce5f>] ? child_rip+0x0/0x11
[ 213.780219]
[ 213.780220]
[ 213.780222] Code: fc 5c f8 ff 48 c1 e8 0c 48 b9 00 00 00 00 00 e2
ff ff 48 6b c0 38 48 8d 14 08 48 8b 02 f6 c4 40 74 04 48 8b 52 10 80
3a 00 78 04 <0f> 0b eb fe 48 8b 72 30 4a 8b 4c f3 08 48 8b 16 48 8b 46
08 48
[ 213.780256] RIP [<ffffffff8029c3d3>] free_block+0x59/0x11f
[ 213.780260] RSP <ffff88001ea2ddd0>
[ 213.780263] ---[ end trace 9ddcc7899ba6622f ]---
^ permalink raw reply [flat|nested] 11+ messages in thread* Re: kernel BUG at mm/slab.c:601
2008-11-18 23:24 kernel BUG at mm/slab.c:601 Brian Phelps
@ 2008-11-19 13:40 ` Brian Phelps
2008-11-19 22:19 ` Vegard Nossum
1 sibling, 0 replies; 11+ messages in thread
From: Brian Phelps @ 2008-11-19 13:40 UTC (permalink / raw)
To: linux-kernel
Another crash, different output
[ 2128.370238] monitor: Corrupted page table at address 82a4468
[ 2128.370257] PGD 10869067 PUD 23232323 BAD
[ 2128.370271] Bad pagetable: 000d [1] SMP
[ 2128.370276] CPU 2
[ 2128.370281] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom i2c_i801 shpchp
pci_hotplug rng_core i2c_core iTCO_wdt ftdi_sio usbserial video output
button snd_pcsp intel_agp snd_hda_intel snd_pcm snd_timer snd
soundcore snd_page_alloc evdev ext2 mbcache sd_mod usbhid hid
ff_memless ata_piix ata_generic libata scsi_mod dock piix floppy
ide_pci_generic ide_core ehci_hcd r8169 mii uhci_hcd thermal processor
fan thermal_sys
[ 2128.370401] Pid: 2867, comm: monitor Not tainted 2.6.27.6 #3
[ 2128.370403] RIP: 0023:[<00000000f715f2a0>] [<00000000f715f2a0>] 0xf715f2a0
[ 2128.370419] RSP: 002b:00000000ffb3aaa0 EFLAGS: 00010292
[ 2128.370421] RAX: 0000000000000b33 RBX: 00000000f716cff4 RCX: 00000000ffb3abdc
[ 2128.370423] RDX: 00000000082a445c RSI: 00000000082a4450 RDI: 00000000ffb3ab5c
[ 2128.370424] RBP: 00000000ffb3aae8 R08: ffffffffffffff10 R09: 00000000082a4450
[ 2128.370426] R10: 0000000000000000 R11: 0000000000001000 R12: 0000000000000000
[ 2128.370428] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
[ 2128.370430] FS: 0000000000000000(0000) GS:ffff88001e93f1c0(0063)
knlGS:00000000f7015aa0
[ 2128.370432] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
[ 2128.370434] CR2: ffff880023232208 CR3: 000000001209f000 CR4: 00000000000006e0
[ 2128.370435] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 2128.370437] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 2128.370439] Process monitor (pid: 2867, threadinfo
ffff8800108da000, task ffff88001ed5e700)
[ 2128.370441]
[ 2128.370442] RIP [<00000000f715f2a0>] 0xf715f2a0
[ 2128.370445] RSP <00000000ffb3aaa0>
[ 2128.370451] ---[ end trace ed9f32be6ace5f07 ]---
[ 2128.370572] mm/memory.c:124: bad pud ffff880010869000(0000000023232323).
[ 2128.458293] ------------[ cut here ]------------
[ 2128.458306] kernel BUG at mm/mmap.c:2088!
[ 2128.458308] invalid opcode: 0000 [2] SMP
[ 2128.458311] CPU 2
[ 2128.458315] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom i2c_i801 shpchp
pci_hotplug rng_core i2c_core iTCO_wdt ftdi_sio usbserial video output
button snd_pcsp intel_agp snd_hda_intel snd_pcm snd_timer snd
soundcore snd_page_alloc evdev ext2 mbcache sd_mod usbhid hid
ff_memless ata_piix ata_generic libata scsi_mod dock piix floppy
ide_pci_generic ide_core ehci_hcd r8169 mii uhci_hcd thermal processor
fan thermal_sys
[ 2128.458352] Pid: 2867, comm: monitor Tainted: G D 2.6.27.6 #3
[ 2128.458353] RIP: 0010:[<ffffffff80288a5c>] [<ffffffff80288a5c>]
exit_mmap+0xe9/0xf4
[ 2128.458363] RSP: 0000:ffff8800108dbd38 EFLAGS: 00010202
[ 2128.458364] RAX: 0000000000000000 RBX: ffff880001023380 RCX: 000000000000028b
[ 2128.458366] RDX: ffff88001ccf62e0 RSI: ffff88001e079e48 RDI: ffff88001e822380
[ 2128.458368] RBP: 0000000000000000 R08: 0000000000000000 R09: ffff88001e9b3200
[ 2128.458370] R10: 0000000000000002 R11: ffffffff802faf6a R12: ffff88001ccf6280
[ 2128.458372] R13: ffff88001ccf62e0 R14: ffff88001ed5e700 R15: ffff88001ccf62e0
[ 2128.458374] FS: 0000000000000000(0000) GS:ffff88001e93f1c0(0000)
knlGS:0000000000000000
[ 2128.458376] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
[ 2128.458377] CR2: ffff880023232208 CR3: 000000001192b000 CR4: 00000000000006e0
[ 2128.458379] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 2128.458381] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 2128.458383] Process monitor (pid: 2867, threadinfo
ffff8800108da000, task ffff88001ed5e700)
[ 2128.458384] Stack: 0000000000000d39 ffff880001023380
ffff88001ccf6280 ffff88001ed5e700
[ 2128.458389] ffff88001ccf6280 ffffffff802347a8 0000000000000000
ffffffff80237c8f
[ 2128.458392] 0000000000000282 ffff88001ed5e700 0000000000000001
ffff88001ed5e700
[ 2128.458394] Call Trace:
[ 2128.458399] [<ffffffff802347a8>] mmput+0x20/0x9e
[ 2128.458402] [<ffffffff80237c8f>] exit_mm+0xfd/0x108
[ 2128.458405] [<ffffffff802399e5>] do_exit+0x208/0x318
[ 2128.458408] [<ffffffff8020d4e9>] oops_begin+0x0/0x86
[ 2128.458413] [<ffffffff80221bc3>] do_page_fault+0x1a9/0x68e
[ 2128.458417] [<ffffffff802cdafd>] compat_do_readv_writev+0x238/0x259
[ 2128.458419] [<ffffffff802cd360>] compat_sys_select+0x9e/0x13d
[ 2128.458423] [<ffffffff8043d209>] error_exit+0x0/0x51
[ 2128.458424]
[ 2128.458425]
[ 2128.458426] Code: 7b 18 e8 80 64 00 00 c7 43 08 00 00 00 00 eb 0b
48 89 ef e8 c0 fe ff ff 48 89 c5 48 85 ed 75 f0 49 83 bc 24 e8 00 00
00 00 74 04 <0f> 0b eb fe 59 5e 5b 5d 41 5c c3 41 56 41 be f4 ff ff ff
41 55
[ 2128.458449] RIP [<ffffffff80288a5c>] exit_mmap+0xe9/0xf4
[ 2128.458451] RSP <ffff8800108dbd38>
[ 2128.458471] ---[ end trace ed9f32be6ace5f07 ]---
[ 2128.458473] Fixing recursive fault but reboot is needed!
[ 2207.781696] BUG: unable to handle kernel paging request at ffffe3a407000000
[ 2207.781712] IP: [<ffffffff8029c3c2>] free_block+0x48/0x11f
[ 2207.781727] PGD 0
[ 2207.781729] Oops: 0000 [3] SMP
[ 2207.781732] CPU 3
[ 2207.781734] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom i2c_i801 shpchp
pci_hotplug rng_core i2c_core iTCO_wdt ftdi_sio usbserial video output
button snd_pcsp intel_agp snd_hda_intel snd_pcm snd_timer snd
soundcore snd_page_alloc evdev ext2 mbcache sd_mod usbhid hid
ff_memless ata_piix ata_generic libata scsi_mod dock piix floppy
ide_pci_generic ide_core ehci_hcd r8169 mii uhci_hcd thermal processor
fan thermal_sys
[ 2207.781770] Pid: 18, comm: events/3 Tainted: G D 2.6.27.6 #3
[ 2207.781772] RIP: 0010:[<ffffffff8029c3c2>] [<ffffffff8029c3c2>]
free_block+0x48/0x11f
[ 2207.781776] RSP: 0000:ffff88001ea2ddd0 EFLAGS: 00010016
[ 2207.781777] RAX: 000001a407000000 RBX: ffff88001ea78500 RCX: ffffe20000000000
[ 2207.781779] RDX: ffffe3a407000000 RSI: ffff88001e00e018 RDI: 0000000200000000
[ 2207.781781] RBP: 0000000200000000 R08: 0000000000000000 R09: ffff880001034e20
[ 2207.781783] R10: 0000000000000000 R11: 0000000200000000 R12: 0000000000000000
[ 2207.781784] R13: ffff88001e00e018 R14: 000000000000002c R15: 0000000000000060
[ 2207.781786] FS: 0000000000000000(0000) GS:ffff88001e9d5940(0000)
knlGS:0000000000000000
[ 2207.781788] CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b
[ 2207.781790] CR2: ffffe3a407000000 CR3: 00000000105ae000 CR4: 00000000000006e0
[ 2207.781792] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 2207.781794] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 2207.781796] Process events/3 (pid: 18, threadinfo ffff88001ea2c000,
task ffff88001ea2b500)
[ 2207.781797] Stack: 0000000000000000 ffff88001e00e018
0000000000000060 ffff88001e00e000
[ 2207.781801] ffff88001e04ea40 0000000000000000 ffff88001ea78500
ffffffff8029c651
[ 2207.781804] 0000000000000000 ffffffff805f61d0 ffff88001e04ea40
ffff88001ea78500
[ 2207.781807] Call Trace:
[ 2207.781810] [<ffffffff8029c651>] ? drain_array+0x89/0xbb
[ 2207.781813] [<ffffffff8029d323>] ? cache_reap+0x105/0x205
[ 2207.781815] [<ffffffff8029d21e>] ? cache_reap+0x0/0x205
[ 2207.781818] [<ffffffff80244f04>] ? run_workqueue+0x79/0xfe
[ 2207.781820] [<ffffffff80245061>] ? worker_thread+0xd8/0xe7
[ 2207.781824] [<ffffffff8024839a>] ? autoremove_wake_function+0x0/0x2e
[ 2207.781826] [<ffffffff80244f89>] ? worker_thread+0x0/0xe7
[ 2207.781829] [<ffffffff80248076>] ? kthread+0x47/0x73
[ 2207.781834] [<ffffffff80233bd8>] ? schedule_tail+0x27/0x5f
[ 2207.781839] [<ffffffff8020ce69>] ? child_rip+0xa/0x11
[ 2207.781841] [<ffffffff8024802f>] ? kthread+0x0/0x73
[ 2207.781843] [<ffffffff8020ce5f>] ? child_rip+0x0/0x11
[ 2207.781844]
[ 2207.781845]
[ 2207.781846] Code: 48 83 ec 08 e9 e3 00 00 00 49 8b 6d 00 48 89 ef
e8 fc 5c f8 ff 48 c1 e8 0c 48 b9 00 00 00 00 00 e2 ff ff 48 6b c0 38
48 8d 14 08 <48> 8b 02 f6 c4 40 74 04 48 8b 52 10 80 3a 00 78 04 0f 0b
eb fe
[ 2207.781869] RIP [<ffffffff8029c3c2>] free_block+0x48/0x11f
[ 2207.781871] RSP <ffff88001ea2ddd0>
[ 2207.781873] CR2: ffffe3a407000000
[ 2207.781875] ---[ end trace ed9f32be6ace5f07 ]---
On Tue, Nov 18, 2008 at 6:24 PM, Brian Phelps <lm317t@gmail.com> wrote:
> This possible kernel bug (see bottom) is very reproducible when the
> pci bus gets loaded with traffic, specifically video data.
> It has been reproduced on 2 identical machines.
>
> Please let me know if you need more information
>
> # uname -r
> 2.6.27.6
>
> # free -m
> total used free shared buffers cached
> Mem: 487 139 347 0 2 24
> -/+ buffers/cache: 113 374
> Swap: 0 0 0
>
> #gcc -v
> Using built-in specs.
> Target: i486-linux-gnu
> Configured with: ../src/configure -v --with-pkgversion='Debian
> 4.3.2-1' --with-bugurl=file:///usr/share/doc/gcc-4.3/README.Bugs
> --enable-languages=c,c++,fortran,objc,obj-c++ --prefix=/usr
> --enable-shared --with-system-zlib --libexecdir=/usr/lib
> --without-included-gettext --enable-threads=posix --enable-nls
> --with-gxx-include-dir=/usr/include/c++/4.3 --program-suffix=-4.3
> --enable-clocale=gnu --enable-libstdcxx-debug --enable-objc-gc
> --enable-mpfr --enable-targets=all --enable-cld
> --enable-checking=release --build=i486-linux-gnu --host=i486-linux-gnu
> --target=i486-linux-gnu
> Thread model: posix
> gcc version 4.3.2 (Debian 4.3.2-1)
>
>
>
> # lspci -v
> 00:00.0 Host bridge: Intel Corporation 82G33/G31/P35/P31 Express DRAM
> Controller (rev 10)
> Flags: bus master, fast devsel, latency 0
> Capabilities: [e0] Vendor Specific Information <?>
> Kernel driver in use: agpgart-intel
> Kernel modules: intel-agp
>
> 00:01.0 PCI bridge: Intel Corporation 82G33/G31/P35/P31 Express PCI
> Express Root Port (rev 10) (prog-if 00 [Normal decode])
> Flags: bus master, fast devsel, latency 0
> Bus: primary=00, secondary=01, subordinate=01, sec-latency=0
> Capabilities: [88] Subsystem: Intel Corporation Device 0000
> Capabilities: [80] Power Management version 3
> Capabilities: [90] Message Signalled Interrupts: Mask- 64bit-
> Queue=0/0 Enable+
> Capabilities: [a0] Express Root Port (Slot+), MSI 00
> Capabilities: [100] Virtual Channel <?>
> Capabilities: [140] Root Complex Link <?>
> Kernel driver in use: pcieport-driver
> Kernel modules: shpchp
>
> 00:02.0 VGA compatible controller: Intel Corporation 82G33/G31 Express
> Integrated Graphics Controller (rev 10) (prog-if 00 [VGA controller])
> Subsystem: Intel Corporation 82G33/G31 Express Integrated
> Graphics Controller
> Flags: bus master, fast devsel, latency 0, IRQ 16
> Memory at feb00000 (32-bit, non-prefetchable) [size=512K]
> I/O ports at e140 [size=8]
> Memory at c0000000 (32-bit, prefetchable) [size=256M]
> Memory at fe900000 (32-bit, non-prefetchable) [size=1M]
> Capabilities: [90] Message Signalled Interrupts: Mask- 64bit-
> Queue=0/0 Enable-
> Capabilities: [d0] Power Management version 2
>
> 00:1b.0 Audio device: Intel Corporation 82801G (ICH7 Family) High
> Definition Audio Controller (rev 01)
> Subsystem: Intel Corporation Device d608
> Flags: bus master, fast devsel, latency 0, IRQ 16
> Memory at feb80000 (64-bit, non-prefetchable) [size=16K]
> Capabilities: [50] Power Management version 2
> Capabilities: [60] Message Signalled Interrupts: Mask- 64bit+
> Queue=0/0 Enable-
> Capabilities: [70] Express Root Complex Integrated Endpoint, MSI 00
> Capabilities: [100] Virtual Channel <?>
> Capabilities: [130] Root Complex Link <?>
> Kernel driver in use: HDA Intel
> Kernel modules: snd-hda-intel
>
> 00:1c.0 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express
> Port 1 (rev 01) (prog-if 00 [Normal decode])
> Flags: bus master, fast devsel, latency 0
> Bus: primary=00, secondary=02, subordinate=02, sec-latency=0
> Capabilities: [40] Express Root Port (Slot+), MSI 00
> Capabilities: [80] Message Signalled Interrupts: Mask- 64bit-
> Queue=0/0 Enable+
> Capabilities: [90] Subsystem: Intel Corporation 82801G (ICH7
> Family) PCI Express Port 1
> Capabilities: [a0] Power Management version 2
> Capabilities: [100] Virtual Channel <?>
> Capabilities: [180] Root Complex Link <?>
> Kernel driver in use: pcieport-driver
> Kernel modules: shpchp
>
> 00:1c.1 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express
> Port 2 (rev 01) (prog-if 00 [Normal decode])
> Flags: bus master, fast devsel, latency 0
> Bus: primary=00, secondary=03, subordinate=03, sec-latency=0
> I/O behind bridge: 0000d000-0000dfff
> Memory behind bridge: fea00000-feafffff
> Capabilities: [40] Express Root Port (Slot+), MSI 00
> Capabilities: [80] Message Signalled Interrupts: Mask- 64bit-
> Queue=0/0 Enable+
> Capabilities: [90] Subsystem: Intel Corporation 82801G (ICH7
> Family) PCI Express Port 2
> Capabilities: [a0] Power Management version 2
> Capabilities: [100] Virtual Channel <?>
> Capabilities: [180] Root Complex Link <?>
> Kernel driver in use: pcieport-driver
> Kernel modules: shpchp
>
> 00:1d.0 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
> UHCI Controller #1 (rev 01) (prog-if 00 [UHCI])
> Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #1
> Flags: bus master, medium devsel, latency 0, IRQ 23
> I/O ports at e080 [size=32]
> Kernel driver in use: uhci_hcd
> Kernel modules: uhci-hcd
>
> 00:1d.1 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
> UHCI Controller #2 (rev 01) (prog-if 00 [UHCI])
> Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #2
> Flags: bus master, medium devsel, latency 0, IRQ 19
> I/O ports at e060 [size=32]
> Kernel driver in use: uhci_hcd
> Kernel modules: uhci-hcd
>
> 00:1d.2 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
> UHCI Controller #3 (rev 01) (prog-if 00 [UHCI])
> Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #3
> Flags: bus master, medium devsel, latency 0, IRQ 18
> I/O ports at e040 [size=32]
> Kernel driver in use: uhci_hcd
> Kernel modules: uhci-hcd
>
> 00:1d.3 USB Controller: Intel Corporation 82801G (ICH7 Family) USB
> UHCI Controller #4 (rev 01) (prog-if 00 [UHCI])
> Subsystem: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #4
> Flags: bus master, medium devsel, latency 0, IRQ 16
> I/O ports at e020 [size=32]
> Kernel driver in use: uhci_hcd
> Kernel modules: uhci-hcd
>
> 00:1d.7 USB Controller: Intel Corporation 82801G (ICH7 Family) USB2
> EHCI Controller (rev 01) (prog-if 20 [EHCI])
> Subsystem: Intel Corporation 82801G (ICH7 Family) USB2 EHCI Controller
> Flags: bus master, medium devsel, latency 0, IRQ 23
> Memory at feb84000 (32-bit, non-prefetchable) [size=1K]
> Capabilities: [50] Power Management version 2
> Capabilities: [58] Debug port: BAR=1 offset=00a0
> Kernel driver in use: ehci_hcd
> Kernel modules: ehci-hcd
>
> 00:1e.0 PCI bridge: Intel Corporation 82801 PCI Bridge (rev e1)
> (prog-if 01 [Subtractive decode])
> Flags: bus master, fast devsel, latency 0
> Bus: primary=00, secondary=04, subordinate=06, sec-latency=248
> Prefetchable memory behind bridge: 00000000d0000000-00000000d01fffff
> Capabilities: [50] Subsystem: Gammagraphx, Inc. Device 0000
>
> 00:1f.0 ISA bridge: Intel Corporation 82801GB/GR (ICH7 Family) LPC
> Interface Bridge (rev 01)
> Subsystem: Intel Corporation DeskTop Board D945GTP
> Flags: bus master, medium devsel, latency 0
> Capabilities: [e0] Vendor Specific Information <?>
> Kernel modules: intel-rng, iTCO_wdt
>
> 00:1f.1 IDE interface: Intel Corporation 82801G (ICH7 Family) IDE
> Controller (rev 01) (prog-if 8a [Master SecP PriP])
> Subsystem: Intel Corporation 82801G (ICH7 Family) IDE Controller
> Flags: bus master, medium devsel, latency 0, IRQ 18
> I/O ports at 01f0 [size=8]
> I/O ports at 03f4 [size=1]
> I/O ports at 0170 [size=8]
> I/O ports at 0374 [size=1]
> I/O ports at e0f0 [size=16]
> Kernel driver in use: PIIX_IDE
> Kernel modules: ata_piix, piix
>
> 00:1f.2 IDE interface: Intel Corporation 82801GB/GR/GH (ICH7 Family)
> SATA IDE Controller (rev 01) (prog-if 8f [Master SecP SecO PriP PriO])
> Subsystem: Intel Corporation 82801GB/GR/GH (ICH7 Family) SATA
> IDE Controller
> Flags: bus master, 66MHz, medium devsel, latency 0, IRQ 19
> I/O ports at e0e0 [size=8]
> I/O ports at e0d0 [size=4]
> I/O ports at e0c0 [size=8]
> I/O ports at e0b0 [size=4]
> I/O ports at e0a0 [size=16]
> Capabilities: [70] Power Management version 2
> Kernel driver in use: ata_piix
> Kernel modules: ata_piix
>
> 00:1f.3 SMBus: Intel Corporation 82801G (ICH7 Family) SMBus Controller (rev 01)
> Subsystem: Intel Corporation Device d608
> Flags: medium devsel, IRQ 19
> I/O ports at e000 [size=32]
> Kernel driver in use: i801_smbus
> Kernel modules: i2c-i801
>
> 03:00.0 Ethernet controller: Realtek Semiconductor Co., Ltd.
> RTL8111/8168B PCI Express Gigabit Ethernet controller (rev 01)
> Subsystem: Intel Corporation Device d608
> Flags: bus master, fast devsel, latency 0, IRQ 1276
> I/O ports at d000 [size=256]
> Memory at fea20000 (64-bit, non-prefetchable) [size=4K]
> Expansion ROM at fea00000 [disabled] [size=128K]
> Capabilities: [40] Power Management version 2
> Capabilities: [48] Vital Product Data <?>
> Capabilities: [50] Message Signalled Interrupts: Mask- 64bit+
> Queue=0/1 Enable+
> Capabilities: [60] Express Endpoint, MSI 00
> Capabilities: [84] Vendor Specific Information <?>
> Capabilities: [100] Advanced Error Reporting <?>
> Capabilities: [12c] Virtual Channel <?>
> Capabilities: [148] Device Serial Number 68-81-ec-00-00-00-00-00
> Capabilities: [154] Power Budgeting <?>
> Kernel driver in use: r8169
> Kernel modules: r8169
>
> 04:05.0 PCI bridge: Hint Corp HB6 Universal PCI-PCI bridge
> (non-transparent mode) (rev 11) (prog-if 00 [Normal decode])
> Flags: bus master, medium devsel, latency 248
> Bus: primary=04, secondary=05, subordinate=05, sec-latency=248
> Prefetchable memory behind bridge: d0100000-d01fffff
> Capabilities: [80] Power Management version 2
> Capabilities: [90] CompactPCI hot-swap <?>
> Kernel modules: shpchp
>
> 04:06.0 PCI bridge: Hint Corp HB6 Universal PCI-PCI bridge
> (non-transparent mode) (rev 11) (prog-if 00 [Normal decode])
> Flags: bus master, medium devsel, latency 248
> Bus: primary=04, secondary=06, subordinate=06, sec-latency=248
> Prefetchable memory behind bridge: d0000000-d00fffff
> Capabilities: [80] Power Management version 2
> Capabilities: [90] CompactPCI hot-swap <?>
> Kernel modules: shpchp
>
> 05:08.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa00:1460
> Flags: bus master, medium devsel, latency 248, IRQ 20
> Memory at d0107000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 05:08.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa00:1460
> Flags: bus master, medium devsel, latency 248, IRQ 11
> Memory at d0106000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 05:09.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa01:1461
> Flags: bus master, medium devsel, latency 248, IRQ 21
> Memory at d0105000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 05:09.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa01:1461
> Flags: bus master, medium devsel, latency 248, IRQ 10
> Memory at d0104000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 05:0a.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa02:1462
> Flags: bus master, medium devsel, latency 248, IRQ 22
> Memory at d0103000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 05:0a.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa02:1462
> Flags: bus master, medium devsel, latency 248, IRQ 5
> Memory at d0102000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 05:0b.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa03:1463
> Flags: bus master, medium devsel, latency 248, IRQ 23
> Memory at d0101000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 05:0b.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa03:1463
> Flags: bus master, medium devsel, latency 248, IRQ 5
> Memory at d0100000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 06:08.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa00:1460
> Flags: bus master, medium devsel, latency 248, IRQ 21
> Memory at d0007000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 06:08.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa00:1460
> Flags: bus master, medium devsel, latency 248, IRQ 10
> Memory at d0006000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 06:09.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa01:1461
> Flags: bus master, medium devsel, latency 248, IRQ 22
> Memory at d0005000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 06:09.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa01:1461
> Flags: bus master, medium devsel, latency 248, IRQ 5
> Memory at d0004000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 06:0a.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa02:1462
> Flags: bus master, medium devsel, latency 248, IRQ 23
> Memory at d0003000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 06:0a.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa02:1462
> Flags: bus master, medium devsel, latency 248, IRQ 5
> Memory at d0002000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
> 06:0b.0 Multimedia video controller: Brooktree Corporation Bt878 Video
> Capture (rev 11)
> Subsystem: Device aa03:1463
> Flags: bus master, medium devsel, latency 248, IRQ 20
> Memory at d0001000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
> Kernel driver in use: bttv
> Kernel modules: bttv
>
> 06:0b.1 Multimedia controller: Brooktree Corporation Bt878 Audio
> Capture (rev 11)
> Subsystem: Device aa03:1463
> Flags: bus master, medium devsel, latency 248, IRQ 11
> Memory at d0000000 (32-bit, prefetchable) [size=4K]
> Capabilities: [44] Vital Product Data <?>
> Capabilities: [4c] Power Management version 2
>
>
> My processor is:
>
> processor : 0
> vendor_id : GenuineIntel
> cpu family : 6
> model : 15
> model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
> stepping : 11
> cpu MHz : 2399.941
> cache size : 4096 KB
> physical id : 0
> siblings : 4
> core id : 0
> cpu cores : 4
> apicid : 0
> initial apicid : 0
> fpu : yes
> fpu_exception : yes
> cpuid level : 10
> wp : yes
> flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
> mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
> syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
> monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
> bogomips : 4799.88
> clflush size : 64
> cache_alignment : 64
> address sizes : 36 bits physical, 48 bits virtual
> power management:
>
> processor : 1
> vendor_id : GenuineIntel
> cpu family : 6
> model : 15
> model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
> stepping : 11
> cpu MHz : 2399.941
> cache size : 4096 KB
> physical id : 0
> siblings : 4
> core id : 1
> cpu cores : 4
> apicid : 1
> initial apicid : 1
> fpu : yes
> fpu_exception : yes
> cpuid level : 10
> wp : yes
> flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
> mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
> syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
> monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
> bogomips : 4799.94
> clflush size : 64
> cache_alignment : 64
> address sizes : 36 bits physical, 48 bits virtual
> power management:
>
> processor : 2
> vendor_id : GenuineIntel
> cpu family : 6
> model : 15
> model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
> stepping : 11
> cpu MHz : 2399.941
> cache size : 4096 KB
> physical id : 0
> siblings : 4
> core id : 2
> cpu cores : 4
> apicid : 2
> initial apicid : 2
> fpu : yes
> fpu_exception : yes
> cpuid level : 10
> wp : yes
> flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
> mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
> syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
> monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
> bogomips : 4799.97
> clflush size : 64
> cache_alignment : 64
> address sizes : 36 bits physical, 48 bits virtual
> power management:
>
> processor : 3
> vendor_id : GenuineIntel
> cpu family : 6
> model : 15
> model name : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
> stepping : 11
> cpu MHz : 2399.941
> cache size : 4096 KB
> physical id : 0
> siblings : 4
> core id : 3
> cpu cores : 4
> apicid : 3
> initial apicid : 3
> fpu : yes
> fpu_exception : yes
> cpuid level : 10
> wp : yes
> flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
> mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe
> syscall nx lm constant_tsc arch_perfmon pebs bts rep_good nopl pni
> monitor ds_cpl vmx est tm2 ssse3 cx16 xtpr lahf_lm
> bogomips : 4799.95
> clflush size : 64
> cache_alignment : 64
> address sizes : 36 bits physical, 48 bits virtual
> power management:
>
> [ 213.780055] ------------[ cut here ]------------
> [ 213.780060] kernel BUG at mm/slab.c:601!
> [ 213.780063] invalid opcode: 0000 [1] SMP
> [ 213.780066] CPU 3
> [ 213.780068] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
> dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
> compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
> videobuf_dma_sg videobuf_core btcx_risc tveeprom i2c_i801 rng_core
> i2c_core ftdi_sio video snd_pcsp snd_hda_intel shpchp pci_hotplug
> iTCO_wdt output usbserial button snd_pcm intel_agp snd_timer snd
> soundcore snd_page_alloc evdev ext2 mbcache sd_mod ata_piix usbhid hid
> ff_memless ata_generic piix libata scsi_mod dock floppy
> ide_pci_generic ide_core ehci_hcd r8169 mii uhci_hcd thermal processor
> fan thermal_sys
> [ 213.780117] Pid: 18, comm: events/3 Not tainted 2.6.27.6 #3
> [ 213.780119] RIP: 0010:[<ffffffff8029c3d3>] [<ffffffff8029c3d3>]
> free_block+0x59/0x11f
> [ 213.780128] RSP: 0000:ffff88001ea2ddd0 EFLAGS: 00010002
> [ 213.780131] RAX: 0100000000010068 RBX: ffff88001c8043c0 RCX: ffffe20000000000
> [ 213.780134] RDX: ffffe200005e5830 RSI: ffff88001cc0c018 RDI: ffff88001af4a580
> [ 213.780136] RBP: ffff88001af4a580 R08: 0000000000000000 R09: ffff88001eefba18
> [ 213.780139] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
> [ 213.780141] R13: ffff88001cc0c018 R14: 000000000000002c R15: 000000000000002c
> [ 213.780144] FS: 0000000000000000(0000) GS:ffff88001e9d5940(0000)
> knlGS:0000000000000000
> [ 213.780147] CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b
> [ 213.780150] CR2: 00000000f7efff05 CR3: 000000000612c000 CR4: 00000000000006e0
> [ 213.780152] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> [ 213.780155] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
> [ 213.780158] Process events/3 (pid: 18, threadinfo ffff88001ea2c000,
> task ffff88001ea2b500)
> [ 213.780160] Stack: 0000000000000000 ffff88001cc0c018
> 000000000000002c ffff88001cc0c000
> [ 213.780166] ffff88001cc9ac40 0000000000000000 ffff88001c8043c0
> ffffffff8029c651
> [ 213.780171] 0000000000000000 ffffffff805f61d0 ffff88001cc9ac40
> ffff88001c8043c0
> [ 213.780175] Call Trace:
> [ 213.780179] [<ffffffff8029c651>] ? drain_array+0x89/0xbb
> [ 213.780182] [<ffffffff8029d323>] ? cache_reap+0x105/0x205
> [ 213.780186] [<ffffffff8029d21e>] ? cache_reap+0x0/0x205
> [ 213.780190] [<ffffffff80244f04>] ? run_workqueue+0x79/0xfe
> [ 213.780193] [<ffffffff80245061>] ? worker_thread+0xd8/0xe7
> [ 213.780197] [<ffffffff8024839a>] ? autoremove_wake_function+0x0/0x2e
> [ 213.780200] [<ffffffff80244f89>] ? worker_thread+0x0/0xe7
> [ 213.780203] [<ffffffff80248076>] ? kthread+0x47/0x73
> [ 213.780207] [<ffffffff80233bd8>] ? schedule_tail+0x27/0x5f
> [ 213.780211] [<ffffffff8020ce69>] ? child_rip+0xa/0x11
> [ 213.780215] [<ffffffff8024802f>] ? kthread+0x0/0x73
> [ 213.780218] [<ffffffff8020ce5f>] ? child_rip+0x0/0x11
> [ 213.780219]
> [ 213.780220]
> [ 213.780222] Code: fc 5c f8 ff 48 c1 e8 0c 48 b9 00 00 00 00 00 e2
> ff ff 48 6b c0 38 48 8d 14 08 48 8b 02 f6 c4 40 74 04 48 8b 52 10 80
> 3a 00 78 04 <0f> 0b eb fe 48 8b 72 30 4a 8b 4c f3 08 48 8b 16 48 8b 46
> 08 48
> [ 213.780256] RIP [<ffffffff8029c3d3>] free_block+0x59/0x11f
> [ 213.780260] RSP <ffff88001ea2ddd0>
> [ 213.780263] ---[ end trace 9ddcc7899ba6622f ]---
>
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: kernel BUG at mm/slab.c:601
2008-11-18 23:24 kernel BUG at mm/slab.c:601 Brian Phelps
2008-11-19 13:40 ` Brian Phelps
@ 2008-11-19 22:19 ` Vegard Nossum
2008-11-20 17:01 ` Brian Phelps
1 sibling, 1 reply; 11+ messages in thread
From: Vegard Nossum @ 2008-11-19 22:19 UTC (permalink / raw)
To: Brian Phelps
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki
On Wed, Nov 19, 2008 at 12:24 AM, Brian Phelps <lm317t@gmail.com> wrote:
> This possible kernel bug (see bottom) is very reproducible when the
> pci bus gets loaded with traffic, specifically video data.
> It has been reproduced on 2 identical machines.
>
> Please let me know if you need more information
Hi,
Can you reproduce this with CONFIG_DEBUG_SLAB=y?
Can you reproduce this with CONFIG_SLUB=y instead of SLAB? If not,
could be a genuine bug in SLAB (but I doubt it). If yes, then SLUB
debugging might help us more than SLAB debugging can.
It sounds likely that bttv driver is involved somehow -- it would fit
with your description too. Maybe the fact that the same driver is
serving many devices on the same IRQ? But I guess that shouldn't
really be a problem.
It would also be interesting to see if you can find more different
crashes in other places, like the corrupted page tables. Those are
important clues. Like this:
> [ 2128.370257] PGD 10869067 PUD 23232323 BAD
That looks like a magic number of sorts. This was the only one I could
find, however:
crypto/anubis.c: 0x83838383U, 0x1b1b1b1bU, 0x0e0e0e0eU, 0x23232323U,
But google has some more info. A google for "23232323 bug" turned up
this thread:
http://lkml.org/lkml/2008/1/5/51
...which also involves bttv driver. I've added the Ccs of that discussion.
But it seems that it is not a regression at least. Did you try earlier
kernels as well?
Vegard
--
"The animistic metaphor of the bug that maliciously sneaked in while
the programmer was not looking is intellectually dishonest as it
disguises that the error is the programmer's own creation."
-- E. W. Dijkstra, EWD1036
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: kernel BUG at mm/slab.c:601
2008-11-19 22:19 ` Vegard Nossum
@ 2008-11-20 17:01 ` Brian Phelps
2008-11-22 1:10 ` Vegard Nossum
0 siblings, 1 reply; 11+ messages in thread
From: Brian Phelps @ 2008-11-20 17:01 UTC (permalink / raw)
To: Vegard Nossum
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki
Okay guys, here is the crash with the debug enabled using "make
CONFIG_DEBUG_SLAB=y"
[ 11.846855] [drm] Initialized i915 1.6.0 20060119 on minor 0
[ 12.442537] set status page addr 0x00033000
[ 15.251686] set status page addr 0x00033000
[ 19.452026] eth1: no IPv6 routers present
[ 527.562250] BUG: unable to handle kernel paging request at ffffffff23232a3b
[ 527.562257] IP: [<ffffffff8043a2be>] mutex_lock+0x0/0xb
[ 527.562266] PGD 203067 PUD 0
[ 527.562269] Oops: 0002 [1] SMP
[ 527.562272] CPU 2
[ 527.562274] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom shpchp rng_core
pci_hotplug i2c_i801 snd_hda_intel snd_pcsp iTCO_wdt ftdi_sio i2c_core
usbserial video snd_pcm output snd_timer snd soundcore snd_page_alloc
button intel_agp evdev ext2 mbcache sd_mod usb_storage ata_piix
ata_generic libata scsi_mod piix dock usbhid hid ff_memless floppy
ide_pci_generic ide_core r8169 mii ehci_hcd uhci_hcd thermal processor
fan thermal_sys
[ 527.562324] Pid: 2740, comm: a.out Not tainted 2.6.27.6 #7
[ 527.562327] RIP: 0010:[<ffffffff8043a2be>] [<ffffffff8043a2be>]
mutex_lock+0x0/0xb
[ 527.562331] RSP: 0000:ffff880018d87ad0 EFLAGS: 00010297
[ 527.562334] RAX: ffffffffa0289f98 RBX: ffff88001e188000 RCX: ffff880018d87cd8
[ 527.562337] RDX: 0000000000000004 RSI: ffff88001e13c600 RDI: ffffffff23232a3b
[ 527.562339] RBP: ffff88001e13c600 R08: 0000000008048840 R09: 00000000ff804e78
[ 527.562342] R10: ffff880018d86000 R11: ffffffff802f9753 R12: ffffffff23232a3b
[ 527.562345] R13: 0000000000000280 R14: ffffffff23232323 R15: 00000000000001e0
[ 527.562348] FS: 0000000000000000(0000) GS:ffff88001e93f1c0(0063)
knlGS:00000000f7d9e6b0
[ 527.562351] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
[ 527.562353] CR2: ffffffff23232a3b CR3: 0000000011fcc000 CR4: 00000000000006e0
[ 527.562355] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 527.562358] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 527.562361] Process a.out (pid: 2740, threadinfo ffff880018d86000,
task ffff88001ed17400)
[ 527.562363] Stack: ffffffffa0281a87 ffffffff802ac916
0000000400000000 ffff88001e188018
[ 527.562369] ffffffffa0289f98 000002801e13c600 ffffffffa024693d
000008008022fc03
[ 527.562373] ffffffff8043b157 0000000000200200 ffffffffa02810d4
ffff88001e13c600
[ 527.562377] Call Trace:
[ 527.562390] [<ffffffffa0281a87>] ? buffer_prepare+0xf8/0x30a [bttv]
[ 527.562395] [<ffffffff802ac916>] ? __pollwait+0x0/0xe2
[ 527.562403] [<ffffffffa024693d>] ? videobuf_dqbuf+0x2b7/0x2f3
[videobuf_core]
[ 527.562406] [<ffffffff8043b157>] ? __down_read+0x15/0x99
[ 527.562417] [<ffffffffa02810d4>] ? bttv_qbuf+0x0/0x6c [bttv]
[ 527.562432] [<ffffffffa0246c2b>] ? videobuf_qbuf+0x2b2/0x397 [videobuf_core]
[ 527.562438] [<ffffffffa02810d4>] ? bttv_qbuf+0x0/0x6c [bttv]
[ 527.562443] [<ffffffffa0263caa>] ? __video_do_ioctl+0x1185/0x30d3 [videodev]
[ 527.562447] [<ffffffff80228e41>] ? enqueue_task+0x59/0x64
[ 527.562449] [<ffffffff80228f26>] ? activate_task+0x22/0x2a
[ 527.562451] [<ffffffff8022fbf1>] ? try_to_wake_up+0x183/0x195
[ 527.562454] [<ffffffff802291a8>] ? __wake_up_common+0x46/0x76
[ 527.562457] [<ffffffffa0265d74>] ? video_ioctl2+0x17c/0x20c [videodev]
[ 527.562461] [<ffffffff80247e06>] ? remove_wait_queue+0x12/0x41
[ 527.562464] [<ffffffffa026d04f>] ? native_ioctl+0x4f/0x60 [compat_ioctl32]
[ 527.562467] [<ffffffffa026e008>] ? v4l_compat_ioctl32+0xfa8/0x1770
[compat_ioctl32]
[ 527.562469] [<ffffffff80247e06>] ? remove_wait_queue+0x12/0x41
[ 527.562472] [<ffffffff8022a79f>] ? __wake_up+0x38/0x4f
[ 527.562475] [<ffffffff80376f1f>] ? tty_ldisc_deref+0x1e/0x6b
[ 527.562478] [<ffffffff8037271f>] ? tty_write+0x203/0x21e
[ 527.562481] [<ffffffff802cf564>] ? compat_sys_ioctl+0xc4/0x340
[ 527.562484] [<ffffffff802a0102>] ? vfs_write+0x121/0x156
[ 527.562486] [<ffffffff80225732>] ? ia32_sysret+0x0/0xa
[ 527.562487]
[ 527.562488]
[ 527.562489] Code: 1c 24 44 89 64 24 08 48 c7 44 24 20 b4 7c 24 80
48 89 44 24 28 48 89 44 24 30 e8 25 ff ff ff 48 83 c4 48 5b 41 5c 41
5d 41 5e c3 <f0> ff 0f 79 05 e8 fa 00 00 00 c3 f0 ff 07 7f 05 e8 75 02
00 00
[ 527.562512] RIP [<ffffffff8043a2be>] mutex_lock+0x0/0xb
[ 527.562514] RSP <ffff880018d87ad0>
[ 527.562516] CR2: ffffffff23232a3b
[ 527.562517] ---[ end trace 21ba9ea650bd284a ]---
[ 537.872407] BUG: unable to handle kernel paging request at ffff880026262200
[ 537.872412] IP: [<ffffffff802845da>] handle_mm_fault+0x11f/0x71b
[ 537.872419] PGD 202063 PUD 206063 PMD 0
[ 537.872423] Oops: 0000 [2] SMP
[ 537.872426] CPU 2
[ 537.872427] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom shpchp rng_core
pci_hotplug i2c_i801 snd_hda_intel snd_pcsp iTCO_wdt ftdi_sio i2c_core
usbserial video snd_pcm output snd_timer snd soundcore snd_page_alloc
button intel_agp evdev ext2 mbcache sd_mod usb_storage ata_piix
ata_generic libata scsi_mod piix dock usbhid hid ff_memless floppy
ide_pci_generic ide_core r8169 mii ehci_hcd uhci_hcd thermal processor
fan thermal_sys
[ 537.872477] Pid: 2738, comm: a.out Tainted: G D 2.6.27.6 #7
[ 537.872479] RIP: 0010:[<ffffffff802845da>] [<ffffffff802845da>]
handle_mm_fault+0x11f/0x71b
[ 537.872484] RSP: 0000:ffff880017d9bd78 EFLAGS: 00010286
[ 537.872487] RAX: ffff880026262200 RBX: ffff880018823000 RCX: 0000000000000000
[ 537.872490] RDX: 0000000000000200 RSI: ffff88001d4aece8 RDI: ffff88001d49ca80
[ 537.872492] RBP: 0000000008048cf6 R08: 0000000000000000 R09: 0000000000000000
[ 537.872495] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000014
[ 537.872497] R13: ffff88001e016f40 R14: ffff88001d4aece8 R15: 0000000008048cf6
[ 537.872500] FS: 0000000000000000(0000) GS:ffff88001e93f1c0(0063)
knlGS:00000000f7e0a6b0
[ 537.872503] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
[ 537.872506] CR2: ffff880026262200 CR3: 000000001d4a2000 CR4: 00000000000006e0
[ 537.872508] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 537.872511] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 537.872513] Process a.out (pid: 2738, threadinfo ffff880017d9a000,
task ffff88001e016f40)
[ 537.872516] Stack: 00000000c058560f 0000000000000000
0000000017d9bf40 ffff88001d49ca80
[ 537.872521] 0000000000000000 ffff880026262200 0000000000000008
0000000000000000
[ 537.872525] 0000000000000000 ffff88001d4aece8 0000000008048cf6
0000000000000014
[ 537.872529] Call Trace:
[ 537.872534] [<ffffffff80221c90>] ? do_page_fault+0x42b/0x81b
[ 537.872538] [<ffffffff8022a79f>] ? __wake_up+0x38/0x4f
[ 537.872542] [<ffffffff80376f1f>] ? tty_ldisc_deref+0x1e/0x6b
[ 537.872546] [<ffffffff802cbf76>] ? compat_sys_select+0x10c/0x13d
[ 537.872550] [<ffffffff8043b4e9>] ? error_exit+0x0/0x51
[ 537.872552]
[ 537.872553]
[ 537.872554] Code: 48 23 03 48 ba 00 00 00 00 00 88 ff ff 48 01 d0
4c 89 fa 48 c1 ea 12 81 e2 f8 0f 00 00 48 01 d0 48 89 44 24 28 0f 84
c8 05 00 00 <f6> 00 01 75 18 48 8b 7c 24 18 4c 89 fa 48 89 c6 e8 4d fe
ff ff
[ 537.872588] RIP [<ffffffff802845da>] handle_mm_fault+0x11f/0x71b
[ 537.872592] RSP <ffff880017d9bd78>
[ 537.872594] CR2: ffff880026262200
[ 537.872597] ---[ end trace 21ba9ea650bd284a ]---
[ 537.872605] mm/memory.c:124: bad pud ffff880018823000(0000000026262626).
[ 537.992386] ------------[ cut here ]------------
[ 537.992391] kernel BUG at mm/mmap.c:2088!
[ 537.992394] invalid opcode: 0000 [3] SMP
[ 537.992397] CPU 0
[ 537.992399] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
videobuf_dma_sg videobuf_core btcx_risc tveeprom shpchp rng_core
pci_hotplug i2c_i801 snd_hda_intel snd_pcsp iTCO_wdt ftdi_sio i2c_core
usbserial video snd_pcm output snd_timer snd soundcore snd_page_alloc
button intel_agp evdev ext2 mbcache sd_mod usb_storage ata_piix
ata_generic libata scsi_mod piix dock usbhid hid ff_memless floppy
ide_pci_generic ide_core r8169 mii ehci_hcd uhci_hcd thermal processor
fan thermal_sys
[ 537.992450] Pid: 2738, comm: a.out Tainted: G D 2.6.27.6 #7
[ 537.992453] RIP: 0010:[<ffffffff8028797c>] [<ffffffff8028797c>]
exit_mmap+0xe9/0xf4
[ 537.992461] RSP: 0000:ffff880017d9ba58 EFLAGS: 00010202
[ 537.992464] RAX: 0000000000000000 RBX: ffff880001023380 RCX: 0000000000000144
[ 537.992467] RDX: ffff88001d49cae0 RSI: ffff88001ecf6c38 RDI: ffff88001e822380
[ 537.992469] RBP: 0000000000000000 R08: ffff88001ed4dd80 R09: ffff880001101100
[ 537.992472] R10: 0000000000000002 R11: ffffffff802f9752 R12: ffff88001d49ca80
[ 537.992475] R13: ffff88001d49cae0 R14: ffff880017d9bcc8 R15: ffff88001d49cae0
[ 537.992478] FS: 0000000000000000(0000) GS:ffffffff80576a00(0000)
knlGS:0000000000000000
[ 537.992480] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
[ 537.992483] CR2: 00000000f7e71000 CR3: 0000000018d45000 CR4: 00000000000006e0
[ 537.992485] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 537.992488] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[ 537.992491] Process a.out (pid: 2738, threadinfo ffff880017d9a000,
task ffff88001e016f40)
[ 537.992493] Stack: 0000000000000043 ffff880001023380
ffff88001d49ca80 ffff88001e016f40
[ 537.992498] ffff88001d49ca80 ffffffff80233d81 0000000000000000
ffffffff80237535
[ 537.992503] 0000000000000282 0000000000000009 ffff88001e016f40
0000000000000009
[ 537.992507] Call Trace:
[ 537.992511] [<ffffffff80233d81>] mmput+0x20/0x9e
[ 537.992515] [<ffffffff80237535>] exit_mm+0xfd/0x108
[ 537.992519] [<ffffffff8023901f>] do_exit+0x21b/0x7ff
[ 537.992523] [<ffffffff8020dc29>] show_registers+0x1f7/0x21d
[ 537.992526] [<ffffffff8020d4a9>] oops_begin+0x0/0x86
[ 537.992530] [<ffffffff80221fb3>] do_page_fault+0x74e/0x81b
[ 537.992535] [<ffffffff80228e41>] enqueue_task+0x59/0x64
[ 537.992538] [<ffffffff80228f26>] activate_task+0x22/0x2a
[ 537.992541] [<ffffffff8022fbf1>] try_to_wake_up+0x183/0x195
[ 537.992545] [<ffffffff802291a8>] __wake_up_common+0x46/0x76
[ 537.992549] [<ffffffff8043b4e9>] error_exit+0x0/0x51
[ 537.992553] [<ffffffff802845da>] handle_mm_fault+0x11f/0x71b
[ 537.992557] [<ffffffff80221c90>] do_page_fault+0x42b/0x81b
[ 537.992560] [<ffffffff8022a79f>] __wake_up+0x38/0x4f
[ 537.992565] [<ffffffff80376f1f>] tty_ldisc_deref+0x1e/0x6b
[ 537.992569] [<ffffffff802cbf76>] compat_sys_select+0x10c/0x13d
[ 537.992572] [<ffffffff8043b4e9>] error_exit+0x0/0x51
[ 537.992574]
[ 537.992576]
[ 537.992577] Code: 7b 18 e8 1c 65 00 00 c7 43 08 00 00 00 00 eb 0b
48 89 ef e8 c0 fe ff ff 48 89 c5 48 85 ed 75 f0 49 83 bc 24 e8 00 00
00 00 74 04 <0f> 0b eb fe 59 5e 5b 5d 41 5c c3 41 56 41 be f4 ff ff ff
41 55
[ 537.992615] RIP [<ffffffff8028797c>] exit_mmap+0xe9/0xf4
[ 537.992618] RSP <ffff880017d9ba58>
[ 537.992620] ---[ end trace 21ba9ea650bd284a ]---
[ 537.992621] Fixing recursive fault but reboot is needed!
On Wed, Nov 19, 2008 at 5:19 PM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
> On Wed, Nov 19, 2008 at 12:24 AM, Brian Phelps <lm317t@gmail.com> wrote:
>> This possible kernel bug (see bottom) is very reproducible when the
>> pci bus gets loaded with traffic, specifically video data.
>> It has been reproduced on 2 identical machines.
>>
>> Please let me know if you need more information
>
> Hi,
>
> Can you reproduce this with CONFIG_DEBUG_SLAB=y?
>
> Can you reproduce this with CONFIG_SLUB=y instead of SLAB? If not,
> could be a genuine bug in SLAB (but I doubt it). If yes, then SLUB
> debugging might help us more than SLAB debugging can.
>
> It sounds likely that bttv driver is involved somehow -- it would fit
> with your description too. Maybe the fact that the same driver is
> serving many devices on the same IRQ? But I guess that shouldn't
> really be a problem.
>
> It would also be interesting to see if you can find more different
> crashes in other places, like the corrupted page tables. Those are
> important clues. Like this:
>
>> [ 2128.370257] PGD 10869067 PUD 23232323 BAD
>
> That looks like a magic number of sorts. This was the only one I could
> find, however:
>
> crypto/anubis.c: 0x83838383U, 0x1b1b1b1bU, 0x0e0e0e0eU, 0x23232323U,
>
> But google has some more info. A google for "23232323 bug" turned up
> this thread:
>
> http://lkml.org/lkml/2008/1/5/51
>
> ...which also involves bttv driver. I've added the Ccs of that discussion.
>
> But it seems that it is not a regression at least. Did you try earlier
> kernels as well?
>
>
> Vegard
>
> --
> "The animistic metaphor of the bug that maliciously sneaked in while
> the programmer was not looking is intellectually dishonest as it
> disguises that the error is the programmer's own creation."
> -- E. W. Dijkstra, EWD1036
>
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: kernel BUG at mm/slab.c:601
2008-11-20 17:01 ` Brian Phelps
@ 2008-11-22 1:10 ` Vegard Nossum
2008-11-22 1:25 ` Vegard Nossum
0 siblings, 1 reply; 11+ messages in thread
From: Vegard Nossum @ 2008-11-22 1:10 UTC (permalink / raw)
To: Brian Phelps
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki
On Thu, Nov 20, 2008 at 6:01 PM, Brian Phelps <lm317t@gmail.com> wrote:
> Okay guys, here is the crash with the debug enabled using "make
> CONFIG_DEBUG_SLAB=y"
>
> [ 11.846855] [drm] Initialized i915 1.6.0 20060119 on minor 0
> [ 12.442537] set status page addr 0x00033000
> [ 15.251686] set status page addr 0x00033000
> [ 19.452026] eth1: no IPv6 routers present
> [ 527.562250] BUG: unable to handle kernel paging request at ffffffff23232a3b
Here is the number again, 23, with slight variations. In ASCII, this is: ##*;
> [ 527.562257] IP: [<ffffffff8043a2be>] mutex_lock+0x0/0xb
> [ 527.562266] PGD 203067 PUD 0
> [ 527.562269] Oops: 0002 [1] SMP
> [ 527.562272] CPU 2
> [ 527.562274] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
> dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
> compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
> videobuf_dma_sg videobuf_core btcx_risc tveeprom shpchp rng_core
> pci_hotplug i2c_i801 snd_hda_intel snd_pcsp iTCO_wdt ftdi_sio i2c_core
> usbserial video snd_pcm output snd_timer snd soundcore snd_page_alloc
> button intel_agp evdev ext2 mbcache sd_mod usb_storage ata_piix
> ata_generic libata scsi_mod piix dock usbhid hid ff_memless floppy
> ide_pci_generic ide_core r8169 mii ehci_hcd uhci_hcd thermal processor
> fan thermal_sys
> [ 527.562324] Pid: 2740, comm: a.out Not tainted 2.6.27.6 #7
> [ 527.562327] RIP: 0010:[<ffffffff8043a2be>] [<ffffffff8043a2be>]
> mutex_lock+0x0/0xb
> [ 527.562331] RSP: 0000:ffff880018d87ad0 EFLAGS: 00010297
> [ 527.562334] RAX: ffffffffa0289f98 RBX: ffff88001e188000 RCX: ffff880018d87cd8
> [ 527.562337] RDX: 0000000000000004 RSI: ffff88001e13c600 RDI: ffffffff23232a3b
> [ 527.562339] RBP: ffff88001e13c600 R08: 0000000008048840 R09: 00000000ff804e78
> [ 527.562342] R10: ffff880018d86000 R11: ffffffff802f9753 R12: ffffffff23232a3b
> [ 527.562345] R13: 0000000000000280 R14: ffffffff23232323 R15: 00000000000001e0
> [ 527.562348] FS: 0000000000000000(0000) GS:ffff88001e93f1c0(0063)
> knlGS:00000000f7d9e6b0
> [ 527.562351] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
> [ 527.562353] CR2: ffffffff23232a3b CR3: 0000000011fcc000 CR4: 00000000000006e0
> [ 527.562355] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> [ 527.562358] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
> [ 527.562361] Process a.out (pid: 2740, threadinfo ffff880018d86000,
> task ffff88001ed17400)
> [ 527.562363] Stack: ffffffffa0281a87 ffffffff802ac916
> 0000000400000000 ffff88001e188018
> [ 527.562369] ffffffffa0289f98 000002801e13c600 ffffffffa024693d
> 000008008022fc03
> [ 527.562373] ffffffff8043b157 0000000000200200 ffffffffa02810d4
> ffff88001e13c600
LIST_POISON2 on the stack:
include/linux/poison.h:#define LIST_POISON2 ((void *) 0x00200200)
> [ 527.562377] Call Trace:
> [ 527.562390] [<ffffffffa0281a87>] ? buffer_prepare+0xf8/0x30a [bttv]
> [ 527.562395] [<ffffffff802ac916>] ? __pollwait+0x0/0xe2
> [ 527.562403] [<ffffffffa024693d>] ? videobuf_dqbuf+0x2b7/0x2f3
> [videobuf_core]
> [ 527.562406] [<ffffffff8043b157>] ? __down_read+0x15/0x99
> [ 527.562417] [<ffffffffa02810d4>] ? bttv_qbuf+0x0/0x6c [bttv]
> [ 527.562432] [<ffffffffa0246c2b>] ? videobuf_qbuf+0x2b2/0x397 [videobuf_core]
> [ 527.562438] [<ffffffffa02810d4>] ? bttv_qbuf+0x0/0x6c [bttv]
> [ 527.562443] [<ffffffffa0263caa>] ? __video_do_ioctl+0x1185/0x30d3 [videodev]
> [ 527.562447] [<ffffffff80228e41>] ? enqueue_task+0x59/0x64
> [ 527.562449] [<ffffffff80228f26>] ? activate_task+0x22/0x2a
> [ 527.562451] [<ffffffff8022fbf1>] ? try_to_wake_up+0x183/0x195
> [ 527.562454] [<ffffffff802291a8>] ? __wake_up_common+0x46/0x76
> [ 527.562457] [<ffffffffa0265d74>] ? video_ioctl2+0x17c/0x20c [videodev]
> [ 527.562461] [<ffffffff80247e06>] ? remove_wait_queue+0x12/0x41
> [ 527.562464] [<ffffffffa026d04f>] ? native_ioctl+0x4f/0x60 [compat_ioctl32]
> [ 527.562467] [<ffffffffa026e008>] ? v4l_compat_ioctl32+0xfa8/0x1770
> [compat_ioctl32]
> [ 527.562469] [<ffffffff80247e06>] ? remove_wait_queue+0x12/0x41
> [ 527.562472] [<ffffffff8022a79f>] ? __wake_up+0x38/0x4f
> [ 527.562475] [<ffffffff80376f1f>] ? tty_ldisc_deref+0x1e/0x6b
> [ 527.562478] [<ffffffff8037271f>] ? tty_write+0x203/0x21e
> [ 527.562481] [<ffffffff802cf564>] ? compat_sys_ioctl+0xc4/0x340
> [ 527.562484] [<ffffffff802a0102>] ? vfs_write+0x121/0x156
> [ 527.562486] [<ffffffff80225732>] ? ia32_sysret+0x0/0xa
> [ 527.562487]
> [ 527.562488]
> [ 527.562489] Code: 1c 24 44 89 64 24 08 48 c7 44 24 20 b4 7c 24 80
> 48 89 44 24 28 48 89 44 24 30 e8 25 ff ff ff 48 83 c4 48 5b 41 5c 41
> 5d 41 5e c3 <f0> ff 0f 79 05 e8 fa 00 00 00 c3 f0 ff 07 7f 05 e8 75 02
> 00 00
> [ 527.562512] RIP [<ffffffff8043a2be>] mutex_lock+0x0/0xb
> [ 527.562514] RSP <ffff880018d87ad0>
> [ 527.562516] CR2: ffffffff23232a3b
> [ 527.562517] ---[ end trace 21ba9ea650bd284a ]---
Looks like the variations of 23 was scribbled here as well: &&"\0
> [ 537.872407] BUG: unable to handle kernel paging request at ffff880026262200
> [ 537.872412] IP: [<ffffffff802845da>] handle_mm_fault+0x11f/0x71b
> [ 537.872419] PGD 202063 PUD 206063 PMD 0
" c" and " `c"
> [ 537.872423] Oops: 0000 [2] SMP
> [ 537.872426] CPU 2
> [ 537.872427] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
> dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
> compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
> videobuf_dma_sg videobuf_core btcx_risc tveeprom shpchp rng_core
> pci_hotplug i2c_i801 snd_hda_intel snd_pcsp iTCO_wdt ftdi_sio i2c_core
> usbserial video snd_pcm output snd_timer snd soundcore snd_page_alloc
> button intel_agp evdev ext2 mbcache sd_mod usb_storage ata_piix
> ata_generic libata scsi_mod piix dock usbhid hid ff_memless floppy
> ide_pci_generic ide_core r8169 mii ehci_hcd uhci_hcd thermal processor
> fan thermal_sys
> [ 537.872477] Pid: 2738, comm: a.out Tainted: G D 2.6.27.6 #7
> [ 537.872479] RIP: 0010:[<ffffffff802845da>] [<ffffffff802845da>]
> handle_mm_fault+0x11f/0x71b
> [ 537.872484] RSP: 0000:ffff880017d9bd78 EFLAGS: 00010286
> [ 537.872487] RAX: ffff880026262200 RBX: ffff880018823000 RCX: 0000000000000000
> [ 537.872490] RDX: 0000000000000200 RSI: ffff88001d4aece8 RDI: ffff88001d49ca80
> [ 537.872492] RBP: 0000000008048cf6 R08: 0000000000000000 R09: 0000000000000000
> [ 537.872495] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000014
> [ 537.872497] R13: ffff88001e016f40 R14: ffff88001d4aece8 R15: 0000000008048cf6
> [ 537.872500] FS: 0000000000000000(0000) GS:ffff88001e93f1c0(0063)
> knlGS:00000000f7e0a6b0
> [ 537.872503] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
> [ 537.872506] CR2: ffff880026262200 CR3: 000000001d4a2000 CR4: 00000000000006e0
> [ 537.872508] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> [ 537.872511] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
> [ 537.872513] Process a.out (pid: 2738, threadinfo ffff880017d9a000,
> task ffff88001e016f40)
> [ 537.872516] Stack: 00000000c058560f 0000000000000000
> 0000000017d9bf40 ffff88001d49ca80
> [ 537.872521] 0000000000000000 ffff880026262200 0000000000000008
> 0000000000000000
> [ 537.872525] 0000000000000000 ffff88001d4aece8 0000000008048cf6
> 0000000000000014
> [ 537.872529] Call Trace:
> [ 537.872534] [<ffffffff80221c90>] ? do_page_fault+0x42b/0x81b
> [ 537.872538] [<ffffffff8022a79f>] ? __wake_up+0x38/0x4f
> [ 537.872542] [<ffffffff80376f1f>] ? tty_ldisc_deref+0x1e/0x6b
> [ 537.872546] [<ffffffff802cbf76>] ? compat_sys_select+0x10c/0x13d
> [ 537.872550] [<ffffffff8043b4e9>] ? error_exit+0x0/0x51
> [ 537.872552]
> [ 537.872553]
> [ 537.872554] Code: 48 23 03 48 ba 00 00 00 00 00 88 ff ff 48 01 d0
> 4c 89 fa 48 c1 ea 12 81 e2 f8 0f 00 00 48 01 d0 48 89 44 24 28 0f 84
> c8 05 00 00 <f6> 00 01 75 18 48 8b 7c 24 18 4c 89 fa 48 89 c6 e8 4d fe
> ff ff
> [ 537.872588] RIP [<ffffffff802845da>] handle_mm_fault+0x11f/0x71b
> [ 537.872592] RSP <ffff880017d9bd78>
> [ 537.872594] CR2: ffff880026262200
> [ 537.872597] ---[ end trace 21ba9ea650bd284a ]---
> [ 537.872605] mm/memory.c:124: bad pud ffff880018823000(0000000026262626).
&&&&
> [ 537.992386] ------------[ cut here ]------------
> [ 537.992391] kernel BUG at mm/mmap.c:2088!
> [ 537.992394] invalid opcode: 0000 [3] SMP
> [ 537.992397] CPU 0
> [ 537.992399] Modules linked in: i915 drm ipv6 dm_snapshot dm_mirror
> dm_log dm_mod coretemp w83627ehf hwmon_vid bttv ir_common
> compat_ioctl32 videodev v4l1_compat i2c_algo_bit v4l2_common
> videobuf_dma_sg videobuf_core btcx_risc tveeprom shpchp rng_core
> pci_hotplug i2c_i801 snd_hda_intel snd_pcsp iTCO_wdt ftdi_sio i2c_core
> usbserial video snd_pcm output snd_timer snd soundcore snd_page_alloc
> button intel_agp evdev ext2 mbcache sd_mod usb_storage ata_piix
> ata_generic libata scsi_mod piix dock usbhid hid ff_memless floppy
> ide_pci_generic ide_core r8169 mii ehci_hcd uhci_hcd thermal processor
> fan thermal_sys
> [ 537.992450] Pid: 2738, comm: a.out Tainted: G D 2.6.27.6 #7
> [ 537.992453] RIP: 0010:[<ffffffff8028797c>] [<ffffffff8028797c>]
> exit_mmap+0xe9/0xf4
> [ 537.992461] RSP: 0000:ffff880017d9ba58 EFLAGS: 00010202
> [ 537.992464] RAX: 0000000000000000 RBX: ffff880001023380 RCX: 0000000000000144
> [ 537.992467] RDX: ffff88001d49cae0 RSI: ffff88001ecf6c38 RDI: ffff88001e822380
> [ 537.992469] RBP: 0000000000000000 R08: ffff88001ed4dd80 R09: ffff880001101100
> [ 537.992472] R10: 0000000000000002 R11: ffffffff802f9752 R12: ffff88001d49ca80
> [ 537.992475] R13: ffff88001d49cae0 R14: ffff880017d9bcc8 R15: ffff88001d49cae0
> [ 537.992478] FS: 0000000000000000(0000) GS:ffffffff80576a00(0000)
> knlGS:0000000000000000
> [ 537.992480] CS: 0010 DS: 002b ES: 002b CR0: 000000008005003b
> [ 537.992483] CR2: 00000000f7e71000 CR3: 0000000018d45000 CR4: 00000000000006e0
> [ 537.992485] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> [ 537.992488] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
> [ 537.992491] Process a.out (pid: 2738, threadinfo ffff880017d9a000,
> task ffff88001e016f40)
> [ 537.992493] Stack: 0000000000000043 ffff880001023380
> ffff88001d49ca80 ffff88001e016f40
> [ 537.992498] ffff88001d49ca80 ffffffff80233d81 0000000000000000
> ffffffff80237535
> [ 537.992503] 0000000000000282 0000000000000009 ffff88001e016f40
> 0000000000000009
> [ 537.992507] Call Trace:
> [ 537.992511] [<ffffffff80233d81>] mmput+0x20/0x9e
> [ 537.992515] [<ffffffff80237535>] exit_mm+0xfd/0x108
> [ 537.992519] [<ffffffff8023901f>] do_exit+0x21b/0x7ff
> [ 537.992523] [<ffffffff8020dc29>] show_registers+0x1f7/0x21d
> [ 537.992526] [<ffffffff8020d4a9>] oops_begin+0x0/0x86
> [ 537.992530] [<ffffffff80221fb3>] do_page_fault+0x74e/0x81b
> [ 537.992535] [<ffffffff80228e41>] enqueue_task+0x59/0x64
> [ 537.992538] [<ffffffff80228f26>] activate_task+0x22/0x2a
> [ 537.992541] [<ffffffff8022fbf1>] try_to_wake_up+0x183/0x195
> [ 537.992545] [<ffffffff802291a8>] __wake_up_common+0x46/0x76
> [ 537.992549] [<ffffffff8043b4e9>] error_exit+0x0/0x51
> [ 537.992553] [<ffffffff802845da>] handle_mm_fault+0x11f/0x71b
> [ 537.992557] [<ffffffff80221c90>] do_page_fault+0x42b/0x81b
> [ 537.992560] [<ffffffff8022a79f>] __wake_up+0x38/0x4f
> [ 537.992565] [<ffffffff80376f1f>] tty_ldisc_deref+0x1e/0x6b
> [ 537.992569] [<ffffffff802cbf76>] compat_sys_select+0x10c/0x13d
> [ 537.992572] [<ffffffff8043b4e9>] error_exit+0x0/0x51
> [ 537.992574]
> [ 537.992576]
> [ 537.992577] Code: 7b 18 e8 1c 65 00 00 c7 43 08 00 00 00 00 eb 0b
> 48 89 ef e8 c0 fe ff ff 48 89 c5 48 85 ed 75 f0 49 83 bc 24 e8 00 00
> 00 00 74 04 <0f> 0b eb fe 59 5e 5b 5d 41 5c c3 41 56 41 be f4 ff ff ff
> 41 55
> [ 537.992615] RIP [<ffffffff8028797c>] exit_mmap+0xe9/0xf4
> [ 537.992618] RSP <ffff880017d9ba58>
> [ 537.992620] ---[ end trace 21ba9ea650bd284a ]---
> [ 537.992621] Fixing recursive fault but reboot is needed!
Would be nice to have your .config. Thanks,
Vegard
--
"The animistic metaphor of the bug that maliciously sneaked in while
the programmer was not looking is intellectually dishonest as it
disguises that the error is the programmer's own creation."
-- E. W. Dijkstra, EWD1036
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: kernel BUG at mm/slab.c:601
2008-11-22 1:10 ` Vegard Nossum
@ 2008-11-22 1:25 ` Vegard Nossum
2008-11-22 1:26 ` Vegard Nossum
0 siblings, 1 reply; 11+ messages in thread
From: Vegard Nossum @ 2008-11-22 1:25 UTC (permalink / raw)
To: Brian Phelps, Mauro Carvalho Chehab
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki
On Sat, Nov 22, 2008 at 2:10 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
>> [ 527.562373] ffffffff8043b157 0000000000200200 ffffffffa02810d4
>> ffff88001e13c600
>
> LIST_POISON2 on the stack:
>
> include/linux/poison.h:#define LIST_POISON2 ((void *) 0x00200200)
So looking at bttv source code, I wonder what the codes like these are
trying to do:
if (set->top->vb.queue.next)
list_del(&set->top->vb.queue);
Code is ancient, I'll ask Mauro.
Vegard
--
"The animistic metaphor of the bug that maliciously sneaked in while
the programmer was not looking is intellectually dishonest as it
disguises that the error is the programmer's own creation."
-- E. W. Dijkstra, EWD1036
^ permalink raw reply [flat|nested] 11+ messages in thread* Re: kernel BUG at mm/slab.c:601
2008-11-22 1:25 ` Vegard Nossum
@ 2008-11-22 1:26 ` Vegard Nossum
2008-11-22 1:50 ` Vegard Nossum
2008-11-24 10:39 ` kernel BUG at mm/slab.c:601 Mauro Carvalho Chehab
0 siblings, 2 replies; 11+ messages in thread
From: Vegard Nossum @ 2008-11-22 1:26 UTC (permalink / raw)
To: Brian Phelps, Mauro Carvalho Chehab
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki
[Resend with (I hope) working e-mail address for Mauro]
On Sat, Nov 22, 2008 at 2:25 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
> On Sat, Nov 22, 2008 at 2:10 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
>>> [ 527.562373] ffffffff8043b157 0000000000200200 ffffffffa02810d4
>>> ffff88001e13c600
>>
>> LIST_POISON2 on the stack:
>>
>> include/linux/poison.h:#define LIST_POISON2 ((void *) 0x00200200)
>
> So looking at bttv source code, I wonder what the codes like these are
> trying to do:
>
> if (set->top->vb.queue.next)
> list_del(&set->top->vb.queue);
>
> Code is ancient, I'll ask Mauro.
>
>
> Vegard
>
> --
> "The animistic metaphor of the bug that maliciously sneaked in while
> the programmer was not looking is intellectually dishonest as it
> disguises that the error is the programmer's own creation."
> -- E. W. Dijkstra, EWD1036
>
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: kernel BUG at mm/slab.c:601
2008-11-22 1:26 ` Vegard Nossum
@ 2008-11-22 1:50 ` Vegard Nossum
2008-11-22 11:20 ` [PATCH] bttv: don't compare list_head's .next with NULL Vegard Nossum
2008-11-24 10:39 ` kernel BUG at mm/slab.c:601 Mauro Carvalho Chehab
1 sibling, 1 reply; 11+ messages in thread
From: Vegard Nossum @ 2008-11-22 1:50 UTC (permalink / raw)
To: Brian Phelps, Mauro Carvalho Chehab, Julia Lawall
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki
On Sat, Nov 22, 2008 at 2:26 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
> [Resend with (I hope) working e-mail address for Mauro]
>
> On Sat, Nov 22, 2008 at 2:25 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
>> On Sat, Nov 22, 2008 at 2:10 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
>>>> [ 527.562373] ffffffff8043b157 0000000000200200 ffffffffa02810d4
>>>> ffff88001e13c600
>>>
>>> LIST_POISON2 on the stack:
>>>
>>> include/linux/poison.h:#define LIST_POISON2 ((void *) 0x00200200)
>>
>> So looking at bttv source code, I wonder what the codes like these are
>> trying to do:
>>
>> if (set->top->vb.queue.next)
>> list_del(&set->top->vb.queue);
>>
>> Code is ancient, I'll ask Mauro.
A semantic patch that finds such invalid list constructs (it is
invalid, isn't it?) would look like this:
@@
expression E;
statement S;
@@
(
* if (E.next) S
|
* if (!E.next) S
|
* if (E.prev) S
|
* if (!E.prev) S
)
I am guessing that the original code wanted to check whether the
object was the last in a list? (The invalid assumption is that NULL
ends the list. Or NULL means that the node is not on a list? But if
so, why take it off the list? In either case, the NULL test looks
wrong because of the poison pointers which prevent intent of the code
-- to check if there is a valid next entry.)
But for this test we actually need to know the list head too. And I
don't know where to find it.
Vegard
--
"The animistic metaphor of the bug that maliciously sneaked in while
the programmer was not looking is intellectually dishonest as it
disguises that the error is the programmer's own creation."
-- E. W. Dijkstra, EWD1036
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH] bttv: don't compare list_head's .next with NULL
2008-11-22 1:50 ` Vegard Nossum
@ 2008-11-22 11:20 ` Vegard Nossum
2008-11-24 17:13 ` Brian Phelps
0 siblings, 1 reply; 11+ messages in thread
From: Vegard Nossum @ 2008-11-22 11:20 UTC (permalink / raw)
To: Brian Phelps, Mauro Carvalho Chehab, Gerd Knorr
Cc: linux-kernel, Al Viro, Mikael Pettersson, Alexander Shaduri,
Alexey Dobriyan, Rafael J. Wysocki, Julia Lawall
Hi Brian,
Can you see if this patch helps your problem?
Vegard
>From 84396b14b9059de4a697df4ea4e036a22513436e Mon Sep 17 00:00:00 2001
From: Vegard Nossum <vegard.nossum@gmail.com>
Date: Sat, 22 Nov 2008 12:12:11 +0100
Subject: [PATCH] bttv: don't compare list_head's .next with NULL
The list implementation doesn't store NULLs in .next/.prev, but
uses poison values (for-sure invalid pointers). I assume that this
code wanted to test whether an entry was the last in a list.
This function is only ever called for the video capture list, so
we know which list to check (it could have been vcapture as well).
Patch is untested!
Signed-off-by: Vegard Nossum <vegard.nossum@gmail.com>
---
drivers/media/video/bt8xx/bttv-risc.c | 10 +++++-----
1 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/media/video/bt8xx/bttv-risc.c b/drivers/media/video/bt8xx/bttv-risc.c
index 5b1b8e4..7a54c99 100644
--- a/drivers/media/video/bt8xx/bttv-risc.c
+++ b/drivers/media/video/bt8xx/bttv-risc.c
@@ -649,14 +649,14 @@ bttv_buffer_activate_video(struct bttv *btv,
if (NULL != set->top && NULL != set->bottom) {
if (set->top == set->bottom) {
set->top->vb.state = VIDEOBUF_ACTIVE;
- if (set->top->vb.queue.next)
+ if (list_is_last(&set->top->vb.queue, &btv->capture))
list_del(&set->top->vb.queue);
} else {
set->top->vb.state = VIDEOBUF_ACTIVE;
set->bottom->vb.state = VIDEOBUF_ACTIVE;
- if (set->top->vb.queue.next)
+ if (list_is_last(&set->top->vb.queue, &btv->capture))
list_del(&set->top->vb.queue);
- if (set->bottom->vb.queue.next)
+ if (list_is_last(&set->bottom->vb.queue, &btv->capture))
list_del(&set->bottom->vb.queue);
}
bttv_apply_geo(btv, &set->top->geo, 1);
@@ -671,7 +671,7 @@ bttv_buffer_activate_video(struct bttv *btv,
~0x0f, BT848_COLOR_CTL);
} else if (NULL != set->top) {
set->top->vb.state = VIDEOBUF_ACTIVE;
- if (set->top->vb.queue.next)
+ if (list_is_last(&set->top->vb.queue, &btv->capture))
list_del(&set->top->vb.queue);
bttv_apply_geo(btv, &set->top->geo,1);
bttv_apply_geo(btv, &set->top->geo,0);
@@ -682,7 +682,7 @@ bttv_buffer_activate_video(struct bttv *btv,
btaor(set->top->btswap & 0x0f, ~0x0f, BT848_COLOR_CTL);
} else if (NULL != set->bottom) {
set->bottom->vb.state = VIDEOBUF_ACTIVE;
- if (set->bottom->vb.queue.next)
+ if (list_is_last(&set->bottom->vb.queue, &btv->capture))
list_del(&set->bottom->vb.queue);
bttv_apply_geo(btv, &set->bottom->geo,1);
bttv_apply_geo(btv, &set->bottom->geo,0);
--
1.5.6.5
^ permalink raw reply [flat|nested] 11+ messages in thread* Re: [PATCH] bttv: don't compare list_head's .next with NULL
2008-11-22 11:20 ` [PATCH] bttv: don't compare list_head's .next with NULL Vegard Nossum
@ 2008-11-24 17:13 ` Brian Phelps
0 siblings, 0 replies; 11+ messages in thread
From: Brian Phelps @ 2008-11-24 17:13 UTC (permalink / raw)
To: Vegard Nossum
Cc: Mauro Carvalho Chehab, Gerd Knorr, linux-kernel, Al Viro,
Mikael Pettersson, Alexander Shaduri, Alexey Dobriyan,
Rafael J. Wysocki, Julia Lawall
This patch seems to cause a select timeout to occur with v4l2's
example capture.c file
On Sat, Nov 22, 2008 at 6:20 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
> Hi Brian,
>
> Can you see if this patch helps your problem?
>
>
> Vegard
>
>
> From 84396b14b9059de4a697df4ea4e036a22513436e Mon Sep 17 00:00:00 2001
> From: Vegard Nossum <vegard.nossum@gmail.com>
> Date: Sat, 22 Nov 2008 12:12:11 +0100
> Subject: [PATCH] bttv: don't compare list_head's .next with NULL
>
> The list implementation doesn't store NULLs in .next/.prev, but
> uses poison values (for-sure invalid pointers). I assume that this
> code wanted to test whether an entry was the last in a list.
>
> This function is only ever called for the video capture list, so
> we know which list to check (it could have been vcapture as well).
>
> Patch is untested!
>
> Signed-off-by: Vegard Nossum <vegard.nossum@gmail.com>
> ---
> drivers/media/video/bt8xx/bttv-risc.c | 10 +++++-----
> 1 files changed, 5 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/media/video/bt8xx/bttv-risc.c b/drivers/media/video/bt8xx/bttv-risc.c
> index 5b1b8e4..7a54c99 100644
> --- a/drivers/media/video/bt8xx/bttv-risc.c
> +++ b/drivers/media/video/bt8xx/bttv-risc.c
> @@ -649,14 +649,14 @@ bttv_buffer_activate_video(struct bttv *btv,
> if (NULL != set->top && NULL != set->bottom) {
> if (set->top == set->bottom) {
> set->top->vb.state = VIDEOBUF_ACTIVE;
> - if (set->top->vb.queue.next)
> + if (list_is_last(&set->top->vb.queue, &btv->capture))
> list_del(&set->top->vb.queue);
> } else {
> set->top->vb.state = VIDEOBUF_ACTIVE;
> set->bottom->vb.state = VIDEOBUF_ACTIVE;
> - if (set->top->vb.queue.next)
> + if (list_is_last(&set->top->vb.queue, &btv->capture))
> list_del(&set->top->vb.queue);
> - if (set->bottom->vb.queue.next)
> + if (list_is_last(&set->bottom->vb.queue, &btv->capture))
> list_del(&set->bottom->vb.queue);
> }
> bttv_apply_geo(btv, &set->top->geo, 1);
> @@ -671,7 +671,7 @@ bttv_buffer_activate_video(struct bttv *btv,
> ~0x0f, BT848_COLOR_CTL);
> } else if (NULL != set->top) {
> set->top->vb.state = VIDEOBUF_ACTIVE;
> - if (set->top->vb.queue.next)
> + if (list_is_last(&set->top->vb.queue, &btv->capture))
> list_del(&set->top->vb.queue);
> bttv_apply_geo(btv, &set->top->geo,1);
> bttv_apply_geo(btv, &set->top->geo,0);
> @@ -682,7 +682,7 @@ bttv_buffer_activate_video(struct bttv *btv,
> btaor(set->top->btswap & 0x0f, ~0x0f, BT848_COLOR_CTL);
> } else if (NULL != set->bottom) {
> set->bottom->vb.state = VIDEOBUF_ACTIVE;
> - if (set->bottom->vb.queue.next)
> + if (list_is_last(&set->bottom->vb.queue, &btv->capture))
> list_del(&set->bottom->vb.queue);
> bttv_apply_geo(btv, &set->bottom->geo,1);
> bttv_apply_geo(btv, &set->bottom->geo,0);
> --
> 1.5.6.5
>
>
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: kernel BUG at mm/slab.c:601
2008-11-22 1:26 ` Vegard Nossum
2008-11-22 1:50 ` Vegard Nossum
@ 2008-11-24 10:39 ` Mauro Carvalho Chehab
1 sibling, 0 replies; 11+ messages in thread
From: Mauro Carvalho Chehab @ 2008-11-24 10:39 UTC (permalink / raw)
To: Vegard Nossum
Cc: Brian Phelps, linux-kernel, Al Viro, Mikael Pettersson,
Alexander Shaduri, Alexey Dobriyan, Rafael J. Wysocki
On Sat, 22 Nov 2008 02:26:52 +0100
"Vegard Nossum" <vegard.nossum@gmail.com> wrote:
> [Resend with (I hope) working e-mail address for Mauro]
>
> On Sat, Nov 22, 2008 at 2:25 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
> > On Sat, Nov 22, 2008 at 2:10 AM, Vegard Nossum <vegard.nossum@gmail.com> wrote:
> >>> [ 527.562373] ffffffff8043b157 0000000000200200 ffffffffa02810d4
> >>> ffff88001e13c600
> >>
> >> LIST_POISON2 on the stack:
> >>
> >> include/linux/poison.h:#define LIST_POISON2 ((void *) 0x00200200)
> >
> > So looking at bttv source code, I wonder what the codes like these are
> > trying to do:
> >
> > if (set->top->vb.queue.next)
> > list_del(&set->top->vb.queue);
> >
> > Code is ancient, I'll ask Mauro.
Your patch seemed correct. I'll test it later. Better alto to wait for Brian
updates, since I never saw this bug on my environment.
Cheers,
Mauro
^ permalink raw reply [flat|nested] 11+ messages in thread
end of thread, other threads:[~2008-11-24 17:13 UTC | newest]
Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2008-11-18 23:24 kernel BUG at mm/slab.c:601 Brian Phelps
2008-11-19 13:40 ` Brian Phelps
2008-11-19 22:19 ` Vegard Nossum
2008-11-20 17:01 ` Brian Phelps
2008-11-22 1:10 ` Vegard Nossum
2008-11-22 1:25 ` Vegard Nossum
2008-11-22 1:26 ` Vegard Nossum
2008-11-22 1:50 ` Vegard Nossum
2008-11-22 11:20 ` [PATCH] bttv: don't compare list_head's .next with NULL Vegard Nossum
2008-11-24 17:13 ` Brian Phelps
2008-11-24 10:39 ` kernel BUG at mm/slab.c:601 Mauro Carvalho Chehab
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®