[Bug 283903] rtw88: possible skb leak
- In reply to: bugzilla-noreply_a_freebsd.org: "[Bug 283903] rtw88: possible skb leak"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 17 Jan 2025 06:47:31 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=283903
--- Comment #13 from oleg.nauman@gmail.com ---
(In reply to Bjoern A. Zeeb from comment #10)
It caused kernel panic after 1 hour 47 minutes of uptime
Jan 17 08:21:23 kernel: rtw880: ERROR lkpi_80211_txq_tx_one: skb alloc failed
48 + 163, lsta 0xfffff80003654000 sta 0xfffff80003654080 ni 0xfffffe0117b8d000
Jan 17 08:21:23 kernel: rtw880: tid 0 ltxq 0xfffff8000395f400 seen_dequeue 1
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 1 ltxq 0xfffff8000395f500 seen_dequeue 1
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 2 ltxq 0xfffff8000395f600 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 3 ltxq 0xfffff8000395f700 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 4 ltxq 0xfffff8000395f800 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 5 ltxq 0xfffff8000395f900 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 6 ltxq 0xfffff8000395fa00 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 7 ltxq 0xfffff8000395fb00 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 8 ltxq 0xfffff8000395fc00 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 9 ltxq 0xfffff8000395fd00 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 10 ltxq 0xfffff8000395fe00 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 11 ltxq 0xfffff8000395e100 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 12 ltxq 0xfffff80003761600 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 13 ltxq 0xfffff80003706100 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 14 ltxq 0xfffff80003706000 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel: rtw880: tid 15 ltxq 0xfffff800034afe00 seen_dequeue 0
stopped 0 skb_queue_len 0
Jan 17 08:21:23 kernel:
Jan 17 08:21:23 syslogd: last message repeated 1 times
Jan 17 08:21:23 kernel: Fatal trap 12: page fault while in kernel mode
Jan 17 08:21:23 kernel: cpuid = 1; apic id = 01
Jan 17 08:21:23 kernel: fault virtual address = 0xffffffffffffffb0
Jan 17 08:21:23 kernel: fault code = supervisor read data, page
not present
Jan 17 08:21:23 kernel: instruction pointer = 0x20:0xffffffff806fbafc
Jan 17 08:21:23 kernel: stack pointer = 0x28:0xfffffe00e466edb0
Jan 17 08:21:23 kernel: frame pointer = 0x28:0xfffffe00e466ee00
Jan 17 08:21:23 kernel: code segment = base 0x0, limit 0xfffff, type
0x1b
Jan 17 08:21:23 kernel: = DPL 0, pres 1, long 1, def32
0, gran 1
Jan 17 08:21:23 kernel: processor eflags = interrupt enabled, resume,
IOPL = 0
Jan 17 08:21:23 kernel: current process = 0 (thread taskq)
Jan 17 08:21:23 kernel: rdi: ffffffff80c48880 rsi: fffffe00e466ec40 rdx:
0000000000000043
Jan 17 08:21:23 kernel: rcx: ffffffffffffff80 r8: 0000000000000043 r9:
00000000000000f0
Jan 17 08:21:23 kernel: rax: 0000000000000000 rbx: fffff80003654000 rbp:
fffffe00e466ee00
Jan 17 08:21:23 kernel: r10: 0000000000000042 r11: fffffffffffff5cf r12:
fffffe0118cb3000
Jan 17 08:21:23 kernel: r13: fffffe0117b8d000 r14: fffff8054596e200 r15:
0000000000000010
Jan 17 08:21:23 kernel: trap number = 12
Jan 17 08:21:23 kernel: panic: page fault
Jan 17 08:21:23 kernel: cpuid = 1
Jan 17 08:21:23 kernel: time = 1737094737
Jan 17 08:21:23 kernel: Uptime: 1h47m51s
------------------------------------------
__curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:57
57 __asm("movq %%gs:%c1,%0" : "=r" (td)
(kgdb) #0 __curthread () at /usr/src/sys/amd64/include/pcpu_aux.h:57
td = <optimized out>
#1 doadump (textdump=<optimized out>) at /usr/src/sys/kern/kern_shutdown.c:404
error = 0
coredump = <optimized out>
#2 0xffffffff80510839 in kern_reboot (howto=260)
at /usr/src/sys/kern/kern_shutdown.c:524
once = 0
#3 0xffffffff80510cdb in vpanic (fmt=0xffffffff808946e7 "%s",
ap=ap@entry=0xfffffe00e466ec70) at /usr/src/sys/kern/kern_shutdown.c:979
buf = "page fault", '\000' <repeats 245 times>
__pc = 0x0
__pc = 0x0
__pc = 0x0
other_cpus = {__bits = {253, 0 <repeats 15 times>}}
td = 0xfffff8010282a740
bootopt = <unavailable>
newpanic = <optimized out>
#4 0xffffffff80510b73 in panic (fmt=<unavailable>)
at /usr/src/sys/kern/kern_shutdown.c:892
ap = {{gp_offset = 16, fp_offset = 48,
overflow_arg_area = 0xfffffe00e466eca0,
reg_save_area = 0xfffffe00e466ec40}}
#5 0xffffffff8083d396 in trap_fatal (frame=<optimized out>,
eva=<optimized out>) at /usr/src/sys/amd64/amd64/trap.c:960
type = <optimized out>
#6 0xffffffff8083d396 in trap_pfault (frame=0xfffffe00e466ecf0,
usermode=<optimized out>, signo=<optimized out>, ucode=<optimized out>)
__pc = 0x0
__pc = 0x0
__pc = 0x0
td = <optimized out>
p = <optimized out>
eva = 18446744073709551536
map = <optimized out>
ftype = <optimized out>
rv = <optimized out>
#7 <signal handler called>
No locals.
#8 lkpi_80211_txq_tx_one (lsta=lsta@entry=0xfffff80003654000,
m=0xfffff8054596e200)
at /usr/src/sys/compat/linuxkpi/common/src/linux_80211.c:3830
tid = 16
skb_alloc_failures = 1 '\001'
control = {sta = 0xfffffe00e466ed38}
ni = 0xfffffe0117b8d000
k = <optimized out>
wh = <optimized out>
ic = 0xfffffe0118cb3000
lhw = 0xfffffe0118ca3200
hw = <optimized out>
c = 0xfffffe0118cb34a4
skb = <optimized out>
sta = <optimized out>
ltxq = 0xffffffffffffff80
buf = <optimized out>
lvif = <optimized out>
vif = <optimized out>
hdr = <optimized out>
tid = <optimized out>
ac = <optimized out>
info = <optimized out>
#9 0xffffffff806fcce3 in lkpi_80211_txq_task (ctx=0xfffff80003654000,
pending=<optimized out>)
at /usr/src/sys/compat/linuxkpi/common/src/linux_80211.c:3999
mq = {mq_head = {stqh_first = 0x0, stqh_last = 0xfffffe00e466ee10},
mq_len = 0, mq_maxlen = 50}
m = 0xfffffe00e466ec40
lsta = <optimized out>
shall_tx = <optimized out>
#10 0xffffffff805708a2 in taskqueue_run_locked (
queue=queue@entry=0xfffff8000129d000)
at /usr/src/sys/kern/subr_taskqueue.c:517
et = {et_link = {tqe_next = 0xfffffe00e466eef0, tqe_prev = 0x0},
et_td = 0x0, et_section = {bucket = 0}, et_old_priority = 0 '\000'}
tb = {tb_running = 0xfffff80003654018, tb_seq = 511873,
tb_canceling = false, tb_link = {le_next = 0x0,
le_prev = 0xfffff8000129d010}}
in_net_epoch = false
pending = 1
task = <optimized out>
#11 0xffffffff80571a72 in taskqueue_thread_loop (
arg=arg@entry=0xffffffff80eedd50 <taskqueue_thread>)
at /usr/src/sys/kern/subr_taskqueue.c:829
tqp = <optimized out>
tq = 0xfffff8000129d000
#12 0xffffffff804d254b in fork_exit (
callout=0xffffffff805719b0 <taskqueue_thread_loop>,
arg=0xffffffff80eedd50 <taskqueue_thread>, frame=0xfffffe00e466ef40)
at /usr/src/sys/kern/kern_fork.c:1152
__pc = 0x0
__pc = 0x0
td = 0xfffff8010282a740
p = 0xffffffff80e7da98 <proc0>
dtd = <optimized out>
#13 <signal handler called>
No locals.
#14 0x4b92e29a0de050f2 in ?? ()
No symbol table info available.
Backtrace stopped: Cannot access memory at address 0x116bd3ff1f0b16f2
Thank you
--
You are receiving this mail because:
You are on the CC list for the bug.