openwrt / openwrt/mt76

crash on my redmi ac2100

Open
#463 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
888
Forks
436
PR merge metrics
No merged PRs in 30d

Description

<1>[ 1952.981066] BUG: Bad page state in process swapper/3  pfn:05c48
<4>[ 1952.987017] page:808f5900 refcount:-1 mapcount:0 mapping:00000000 index:0x0 compound_mapcount: 1
<4>[ 1952.995789] flags: 0x10000(head)
<4>[ 1952.999030] raw: 00010000 00000100 00000122 00000000 00000000 00000000 ffffffff ffffffff
<4>[ 1953.007118] page dumped because: nonzero _refcount
<4>[ 1953.011898] Modules linked in: pppoe ppp_async pptp pppox ppp_mppe ppp_generic mt7615e mt7615_common mt7603e mt76 mac80211 ipt_REJECT cfg80211 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_socket xt_recent xt_quota xt_pkttype xt_physdev xt_owner xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_iprange xt_ipp2p xt_iface xt_hl xt_helper xt_hashlimit xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_addrtype xt_TPROXY xt_TCPMSS xt_REDIRECT xt_NETMAP xt_MASQUERADE xt_LOG xt_IPMARK xt_HL xt_DSCP xt_CT xt_CLASSIFY wireguard ts_fsm ts_bm slhc sch_cake nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_objref nft_numgen nft_meta_bridge nft_log nft_limit nft_hash nft_fwd_netdev nft_dup_netdev nft_ct nft_counter nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables_set nf_tables nf_socket_ipv6 nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_rtsp nf_nat_pptp nf_nat_irc nf_nat_h323
<4>[ 1953.012085]  nf_nat_ftp nf_nat_amanda nf_log_ipv4 nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_rtsp nf_conntrack_rtcache nf_conntrack_pptp nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast ts_kmp nf_conntrack_amanda nf_conncount macvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ah ipt_ECN ip_tables crc_ccitt compat_xtables compat br_netfilter asn1_decoder natflow natcap tcp_bbr sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_tcindex cls_route cls_matchall cls_fw cls_flow cls_basic act_skbedit act_mirred ledtrig_heartbeat xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6table_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4
<4>[ 1953.099253]  ip6t_NPT ip6t_rt ip6t_mh ip6t_ipv6header ip6t_hbh ip6t_frag ip6t_eui64 ip6t_ah nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 ip6_gre ip_gre gre ifb ip6_udp_tunnel udp_tunnel sit ip6_tunnel tunnel6 tunnel4 ip_tunnel tun nls_utf8 nls_iso8859_1 nls_base sha1_generic ecb arc4 leds_gpio softdog gpio_button_hotplug
<4>[ 1953.220069] CPU: 3 PID: 0 Comm: swapper/3 Not tainted 5.4.61 #0
<4>[ 1953.225963] Stack : ffffffff 80072a8c 80650000 80652fc0 806c0000 80652f88 806520ec 87c13cfc
<4>[ 1953.234286]         80800000 87c3c974 8069ac23 805e7a68 00000003 00000001 87c13ca0 1b38ddbc
<4>[ 1953.242606]         00000000 00000000 80840000 00000000 00000030 0000014c 342e3520 2031362e
<4>[ 1953.250925]         00000000 00000061 00000000 00035ba5 00000000 806c0000 00000000 80830000
<4>[ 1953.259245]         805ecc88 80690000 808f5a00 0030f231 00000002 802fc7e0 0000000c 8080000c
<4>[ 1953.267565]         ...
<4>[ 1953.270002] Call Trace:
<4>[ 1953.272470] [<8000b5fc>] show_stack+0x30/0x100
<4>[ 1953.276919] [<80532304>] dump_stack+0xa4/0xdc
<4>[ 1953.281275] [<80121184>] bad_page+0x120/0x154
<4>[ 1953.285617] [<80121e48>] __free_pages_ok+0x388/0x5dc
<4>[ 1953.290576] [<803b9d08>] consume_skb+0x30/0x80
<4>[ 1953.295030] [<860e6000>] mt76_tx_complete_skb+0x104/0x4ac [mt76]
<4>[ 1953.301021] [<860e5688>] mt76_queue_tx_complete+0x2c/0x74 [mt76]
<4>[ 1953.307008] [<860e0d6c>] mt76_put_txwi+0x624/0x81c [mt76]
<4>[ 1953.312536] Disabling lock debugging due to kernel taint
<1>[ 1953.529767] CPU 0 Unable to handle kernel paging request at virtual address 00000104, epc == 860e0670, ra == 860e0658
<4>[ 1953.540390] Oops[#1]:
<4>[ 1953.542663] CPU: 0 PID: 1282 Comm: mt76-tx phy0 Tainted: G    B             5.4.61 #0
<4>[ 1953.550455] $ 0   : 00000000 00000001 859ea2a0 86042770
<4>[ 1953.555665] $ 4   : 00000100 00000000 00000000 872d67a4
<4>[ 1953.560870] $ 8   : 0000000c 8054c970 00000000 00000000
<4>[ 1953.566071] $12   : 00000000 00000000 00000000 859970a0
<4>[ 1953.571273] $16   : 86041e60 86041e60 86041e60 04f20000
<4>[ 1953.576475] $20   : 00000000 86ac3984 8672dce4 86041e60
<4>[ 1953.581680] $24   : 3fff0000 8055327c                  
<4>[ 1953.586886] $28   : 8672c000 8672dc88 00000000 860e0658
<4>[ 1953.592089] Hi    : 000041bf
<4>[ 1953.594950] Lo    : 0497232e
<4>[ 1953.597838] epc   : 860e0670 __mt76_worker_fn+0x140/0x1b0 [mt76]
<4>[ 1953.603823] ra    : 860e0658 __mt76_worker_fn+0x128/0x1b0 [mt76]
<4>[ 1953.609800] Status: 11008403	KERNEL EXL IE 
<4>[ 1953.613971] Cause : 4080000c (ExcCode 03)
<4>[ 1953.617967] BadVA : 00000104
<4>[ 1953.620838] PrId  : 0001992f (MIPS 1004Kc)
<4>[ 1953.624913] Modules linked in: pppoe ppp_async pptp pppox ppp_mppe ppp_generic mt7615e mt7615_common mt7603e mt76 mac80211 ipt_REJECT cfg80211 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_socket xt_recent xt_quota xt_pkttype xt_physdev xt_owner xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_iprange xt_ipp2p xt_iface xt_hl xt_helper xt_hashlimit xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_addrtype xt_TPROXY xt_TCPMSS xt_REDIRECT xt_NETMAP xt_MASQUERADE xt_LOG xt_IPMARK xt_HL xt_DSCP xt_CT xt_CLASSIFY wireguard ts_fsm ts_bm slhc sch_cake nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_objref nft_numgen nft_meta_bridge nft_log nft_limit nft_hash nft_fwd_netdev nft_dup_netdev nft_ct nft_counter nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables_set nf_tables nf_socket_ipv6 nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_rtsp nf_nat_pptp nf_nat_irc nf_nat_h323
<4>[ 1953.625206]  nf_nat_ftp nf_nat_amanda nf_log_ipv4 nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_rtsp nf_conntrack_rtcache nf_conntrack_pptp nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast ts_kmp nf_conntrack_amanda nf_conncount macvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ah ipt_ECN ip_tables crc_ccitt compat_xtables compat br_netfilter asn1_decoder natflow natcap tcp_bbr sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_tcindex cls_route cls_matchall cls_fw cls_flow cls_basic act_skbedit act_mirred ledtrig_heartbeat xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6table_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4
<4>[ 1953.712297]  ip6t_NPT ip6t_rt ip6t_mh ip6t_ipv6header ip6t_hbh ip6t_frag ip6t_eui64 ip6t_ah nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 ip6_gre ip_gre gre ifb ip6_udp_tunnel udp_tunnel sit ip6_tunnel tunnel6 tunnel4 ip_tunnel tun nls_utf8 nls_iso8859_1 nls_base sha1_generic ecb arc4 leds_gpio softdog gpio_button_hotplug
<4>[ 1953.832834] Process mt76-tx phy0 (pid: 1282, threadinfo=a1bc386e, task=ffc36e92, tls=00000000)
<4>[ 1953.841402] Stack : 86c51870 00000001 00000000 86041e60 876be180 860e1b0c 00000001 85a56600
<4>[ 1953.849736]         86041e60 00000002 876be0c0 859970a0 00000002 00000000 86ac3980 00000020
<4>[ 1953.858067]         806b0000 00001f34 81000001 05a011a0 00000000 87c33480 01000000 00000000
<4>[ 1953.866400]         00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
<4>[ 1953.874729]         00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
<4>[ 1953.883059]         ...
<4>[ 1953.885503] Call Trace:
<4>[ 1953.887961] [<860e0670>] __mt76_worker_fn+0x140/0x1b0 [mt76]
<4>[ 1953.893606] Code: 00000000  8c430004  8c440000 <ac830004> ac640000  24030100  ac430000  24030122  ac430004 
<4>[ 1953.903335] 
<4>[ 1953.905455] ---[ end trace 657f0dab93f1e8f0 ]---

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the traced mt76 entry points: mt76_tx_complete_skb, mt76_queue_tx_complete, mt76_put_txwi, and __mt76_worker_fn. Reproduce the crash on the Redmi AC2100 with kernel 5.4.61, then verify that the bad page state and mt76-tx paging oops no longer occur.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
networking, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.