crash on my redmi ac2100
Open
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 888
- Forks
- 436
- PR merge metrics
- No merged PRs in 30d
Description
<1>[ 1952.981066] BUG: Bad page state in process swapper/3 pfn:05c48
<4>[ 1952.987017] page:808f5900 refcount:-1 mapcount:0 mapping:00000000 index:0x0 compound_mapcount: 1
<4>[ 1952.995789] flags: 0x10000(head)
<4>[ 1952.999030] raw: 00010000 00000100 00000122 00000000 00000000 00000000 ffffffff ffffffff
<4>[ 1953.007118] page dumped because: nonzero _refcount
<4>[ 1953.011898] Modules linked in: pppoe ppp_async pptp pppox ppp_mppe ppp_generic mt7615e mt7615_common mt7603e mt76 mac80211 ipt_REJECT cfg80211 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_socket xt_recent xt_quota xt_pkttype xt_physdev xt_owner xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_iprange xt_ipp2p xt_iface xt_hl xt_helper xt_hashlimit xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_addrtype xt_TPROXY xt_TCPMSS xt_REDIRECT xt_NETMAP xt_MASQUERADE xt_LOG xt_IPMARK xt_HL xt_DSCP xt_CT xt_CLASSIFY wireguard ts_fsm ts_bm slhc sch_cake nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_objref nft_numgen nft_meta_bridge nft_log nft_limit nft_hash nft_fwd_netdev nft_dup_netdev nft_ct nft_counter nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables_set nf_tables nf_socket_ipv6 nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_rtsp nf_nat_pptp nf_nat_irc nf_nat_h323
<4>[ 1953.012085] nf_nat_ftp nf_nat_amanda nf_log_ipv4 nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_rtsp nf_conntrack_rtcache nf_conntrack_pptp nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast ts_kmp nf_conntrack_amanda nf_conncount macvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ah ipt_ECN ip_tables crc_ccitt compat_xtables compat br_netfilter asn1_decoder natflow natcap tcp_bbr sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_tcindex cls_route cls_matchall cls_fw cls_flow cls_basic act_skbedit act_mirred ledtrig_heartbeat xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6table_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4
<4>[ 1953.099253] ip6t_NPT ip6t_rt ip6t_mh ip6t_ipv6header ip6t_hbh ip6t_frag ip6t_eui64 ip6t_ah nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 ip6_gre ip_gre gre ifb ip6_udp_tunnel udp_tunnel sit ip6_tunnel tunnel6 tunnel4 ip_tunnel tun nls_utf8 nls_iso8859_1 nls_base sha1_generic ecb arc4 leds_gpio softdog gpio_button_hotplug
<4>[ 1953.220069] CPU: 3 PID: 0 Comm: swapper/3 Not tainted 5.4.61 #0
<4>[ 1953.225963] Stack : ffffffff 80072a8c 80650000 80652fc0 806c0000 80652f88 806520ec 87c13cfc
<4>[ 1953.234286] 80800000 87c3c974 8069ac23 805e7a68 00000003 00000001 87c13ca0 1b38ddbc
<4>[ 1953.242606] 00000000 00000000 80840000 00000000 00000030 0000014c 342e3520 2031362e
<4>[ 1953.250925] 00000000 00000061 00000000 00035ba5 00000000 806c0000 00000000 80830000
<4>[ 1953.259245] 805ecc88 80690000 808f5a00 0030f231 00000002 802fc7e0 0000000c 8080000c
<4>[ 1953.267565] ...
<4>[ 1953.270002] Call Trace:
<4>[ 1953.272470] [<8000b5fc>] show_stack+0x30/0x100
<4>[ 1953.276919] [<80532304>] dump_stack+0xa4/0xdc
<4>[ 1953.281275] [<80121184>] bad_page+0x120/0x154
<4>[ 1953.285617] [<80121e48>] __free_pages_ok+0x388/0x5dc
<4>[ 1953.290576] [<803b9d08>] consume_skb+0x30/0x80
<4>[ 1953.295030] [<860e6000>] mt76_tx_complete_skb+0x104/0x4ac [mt76]
<4>[ 1953.301021] [<860e5688>] mt76_queue_tx_complete+0x2c/0x74 [mt76]
<4>[ 1953.307008] [<860e0d6c>] mt76_put_txwi+0x624/0x81c [mt76]
<4>[ 1953.312536] Disabling lock debugging due to kernel taint
<1>[ 1953.529767] CPU 0 Unable to handle kernel paging request at virtual address 00000104, epc == 860e0670, ra == 860e0658
<4>[ 1953.540390] Oops[#1]:
<4>[ 1953.542663] CPU: 0 PID: 1282 Comm: mt76-tx phy0 Tainted: G B 5.4.61 #0
<4>[ 1953.550455] $ 0 : 00000000 00000001 859ea2a0 86042770
<4>[ 1953.555665] $ 4 : 00000100 00000000 00000000 872d67a4
<4>[ 1953.560870] $ 8 : 0000000c 8054c970 00000000 00000000
<4>[ 1953.566071] $12 : 00000000 00000000 00000000 859970a0
<4>[ 1953.571273] $16 : 86041e60 86041e60 86041e60 04f20000
<4>[ 1953.576475] $20 : 00000000 86ac3984 8672dce4 86041e60
<4>[ 1953.581680] $24 : 3fff0000 8055327c
<4>[ 1953.586886] $28 : 8672c000 8672dc88 00000000 860e0658
<4>[ 1953.592089] Hi : 000041bf
<4>[ 1953.594950] Lo : 0497232e
<4>[ 1953.597838] epc : 860e0670 __mt76_worker_fn+0x140/0x1b0 [mt76]
<4>[ 1953.603823] ra : 860e0658 __mt76_worker_fn+0x128/0x1b0 [mt76]
<4>[ 1953.609800] Status: 11008403 KERNEL EXL IE
<4>[ 1953.613971] Cause : 4080000c (ExcCode 03)
<4>[ 1953.617967] BadVA : 00000104
<4>[ 1953.620838] PrId : 0001992f (MIPS 1004Kc)
<4>[ 1953.624913] Modules linked in: pppoe ppp_async pptp pppox ppp_mppe ppp_generic mt7615e mt7615_common mt7603e mt76 mac80211 ipt_REJECT cfg80211 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_socket xt_recent xt_quota xt_pkttype xt_physdev xt_owner xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_iprange xt_ipp2p xt_iface xt_hl xt_helper xt_hashlimit xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_addrtype xt_TPROXY xt_TCPMSS xt_REDIRECT xt_NETMAP xt_MASQUERADE xt_LOG xt_IPMARK xt_HL xt_DSCP xt_CT xt_CLASSIFY wireguard ts_fsm ts_bm slhc sch_cake nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_objref nft_numgen nft_meta_bridge nft_log nft_limit nft_hash nft_fwd_netdev nft_dup_netdev nft_ct nft_counter nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables_set nf_tables nf_socket_ipv6 nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_rtsp nf_nat_pptp nf_nat_irc nf_nat_h323
<4>[ 1953.625206] nf_nat_ftp nf_nat_amanda nf_log_ipv4 nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_rtsp nf_conntrack_rtcache nf_conntrack_pptp nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast ts_kmp nf_conntrack_amanda nf_conncount macvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ah ipt_ECN ip_tables crc_ccitt compat_xtables compat br_netfilter asn1_decoder natflow natcap tcp_bbr sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_tcindex cls_route cls_matchall cls_fw cls_flow cls_basic act_skbedit act_mirred ledtrig_heartbeat xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6table_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4
<4>[ 1953.712297] ip6t_NPT ip6t_rt ip6t_mh ip6t_ipv6header ip6t_hbh ip6t_frag ip6t_eui64 ip6t_ah nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 ip6_gre ip_gre gre ifb ip6_udp_tunnel udp_tunnel sit ip6_tunnel tunnel6 tunnel4 ip_tunnel tun nls_utf8 nls_iso8859_1 nls_base sha1_generic ecb arc4 leds_gpio softdog gpio_button_hotplug
<4>[ 1953.832834] Process mt76-tx phy0 (pid: 1282, threadinfo=a1bc386e, task=ffc36e92, tls=00000000)
<4>[ 1953.841402] Stack : 86c51870 00000001 00000000 86041e60 876be180 860e1b0c 00000001 85a56600
<4>[ 1953.849736] 86041e60 00000002 876be0c0 859970a0 00000002 00000000 86ac3980 00000020
<4>[ 1953.858067] 806b0000 00001f34 81000001 05a011a0 00000000 87c33480 01000000 00000000
<4>[ 1953.866400] 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
<4>[ 1953.874729] 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
<4>[ 1953.883059] ...
<4>[ 1953.885503] Call Trace:
<4>[ 1953.887961] [<860e0670>] __mt76_worker_fn+0x140/0x1b0 [mt76]
<4>[ 1953.893606] Code: 00000000 8c430004 8c440000 <ac830004> ac640000 24030100 ac430000 24030122 ac430004
<4>[ 1953.903335]
<4>[ 1953.905455] ---[ end trace 657f0dab93f1e8f0 ]---
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the traced mt76 entry points: mt76_tx_complete_skb, mt76_queue_tx_complete, mt76_put_txwi, and __mt76_worker_fn. Reproduce the crash on the Redmi AC2100 with kernel 5.4.61, then verify that the bad page state and mt76-tx paging oops no longer occur.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, linux
- Domain
- networking, operating-systems
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100