crash log on rm-ax6000 (mt7986)
Open
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 888
- Forks
- 436
- PR merge metrics
- No merged PRs in 30d
Description
<1>[ 32.529539] Unable to handle kernel paging request at virtual address 00000a801d000200
<1>[ 32.537483] Mem abort info:
<1>[ 32.540269] ESR = 0x0000000096000004
<1>[ 32.544001] EC = 0x25: DABT (current EL), IL = 32 bits
<1>[ 32.549308] SET = 0, FnV = 0
<1>[ 32.552354] EA = 0, S1PTW = 0
<1>[ 32.555483] FSC = 0x04: level 0 translation fault
<1>[ 32.560367] Data abort info:
<1>[ 32.563240] ISV = 0, ISS = 0x00000004
<1>[ 32.567073] CM = 0, WnR = 0
<1>[ 32.570031] [00000a801d000200] address between user and kernel address ranges
<0>[ 32.577159] Internal error: Oops: 96000004 [#1] SMP
<7>[ 32.582030] Modules linked in: pppoe ppp_async l2tp_ppp wireguard pptp pppox ppp_mppe ppp_generic nft_fib_inet mt7915e mt76_connac_lib mt76 mac80211 libchacha20poly1305 ipt_REJECT chacha_neon cfg80211 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_recent xt_policy xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_hl xt_helper xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_TCPMSS xt_REDIRECT xt_MASQUERADE xt_LOG xt_HL xt_DSCP xt_DNETMAP xt_DHCPMAC xt_CT xt_CLASSIFY xfrm_interface ts_fsm ts_bm tcp_scalable tcp_bbr slhc sch_cake poly1305_neon nft_tproxy nft_socket nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_queue nft_objref nft_numgen nft_nat nft_meta_bridge nft_masq nft_log nft_limit nft_hash nft_fwd_netdev nft_fib_ipv6 nft_fib_ipv4 nft_fib nft_dup_netdev nft_ct nft_counter nft_compat nft_chain_nat nfnetlink_queue nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables nf_socket_ipv6
<7>[ 32.582187] nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_pptp nf_nat_irc nf_nat_h323 nf_nat_ftp nf_nat_amanda nf_log_syslog nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_pptp nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast nf_conntrack_bridge ts_kmp nf_conntrack_amanda nf_conncount macvlan libcurve25519_generic libcrc32c libchacha ipvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ah ipt_ECN ip_tables crc_ccitt compat_xtables compat br_netfilter asn1_decoder natflow natcap nf_nat nf_conntrack crypto_safexcel sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_route cls_matchall cls_fw cls_flow cls_basic act_skbedit act_mirred act_gact xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark
<7>[ 32.668368] ip_set_hash_ipmac ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink jool_siit jool nf_defrag_ipv4 jool_common ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 bonding tls ip6_gre ip_gre gre ifb nat46 nf_defrag_ipv6 ip6_vti ip_vti sit l2tp_netlink l2tp_core ipcomp6 xfrm6_tunnel esp6 ah6 xfrm4_tunnel ipcomp esp4 ah4 ip6_tunnel tunnel6 tunnel4 ip_tunnel udp_diag tcp_diag raw_diag inet_diag tun ovpn_dco_v2 udp_tunnel ip6_udp_tunnel xfrm_user xfrm_ipcomp af_key xfrm_algo autofs4 nls_utf8 nls_iso8859_1 crypto_user algif_skcipher algif_rng algif_hash algif_aead af_alg sha1_generic seqiv md5 echainiv des_generic libdes chacha20poly1305 cbc authencesn authenc arc4 leds_ws2812b leds_gpio gpio_button_hotplug usbcore usb_common
<7>[ 32.825447] CPU: 1 PID: 1330 Comm: mt76-tx phy0 Not tainted 5.15.133 #0
<7>[ 32.832042] Hardware name: Xiaomi Redmi Router AX6000 (stock layout) (DT)
<7>[ 32.838809] pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
<7>[ 32.845751] pc : mt76_connac2_mac_tx_rate_val+0x2c/0x250 [mt76_connac_lib]
<7>[ 32.852615] lr : mt76_connac2_mac_write_txwi+0x3b4/0x580 [mt76_connac_lib]
<7>[ 32.859471] sp : ffffffc009183900
<7>[ 32.862769] x29: ffffffc009183900 x28: 0000000000000000 x27: 0000000000000000
<7>[ 32.869886] x26: ffffff80097a6840 x25: 0000000000000000 x24: ffffff8003fa6040
<7>[ 32.877001] x23: ffffff8006e40101 x22: 0000000000000000 x21: ffffff8003fa2040
<7>[ 32.884116] x20: ffffff8006e40101 x19: ffffff800793dc80 x18: 0000000000000000
<7>[ 32.891232] x17: 0000000000000000 x16: 0000000000000000 x15: 03003ff42407ff71
<7>[ 32.898346] x14: c71c71c71c71c71c x13: 0000000080000400 x12: 000000008000021f
<7>[ 32.905462] x11: 0000000000007800 x10: 000000004020021b x9 : 0000000000000000
<7>[ 32.912577] x8 : 0000000000000000 x7 : 0000000000007922 x6 : 0000000000007961
<7>[ 32.919693] x5 : 0000000000000005 x4 : 0000000000050000 x3 : 0000000000000000
<7>[ 32.926808] x2 : 0000000000000000 x1 : 00000a801d000200 x0 : 00000a801d000200
<7>[ 32.933924] Call trace:
<7>[ 32.936357] mt76_connac2_mac_tx_rate_val+0x2c/0x250 [mt76_connac_lib]
<7>[ 32.942868] mt76_connac2_mac_write_txwi+0x3b4/0x580 [mt76_connac_lib]
<7>[ 32.949377] mt7915_tx_prepare_skb+0xe4/0x224 [mt7915e]
<7>[ 32.954588] mt76_dma_cleanup+0x7ac/0x8f0 [mt76]
<7>[ 32.959193] mt76_tx_check_agg_ssn+0xa8/0x110 [mt76]
<7>[ 32.964141] mt76_txq_schedule_all+0x230/0x380 [mt76]
<7>[ 32.969177] mt76_tx_worker+0x2c/0x2f0 [mt76]
<7>[ 32.973519] __mt76_worker_fn+0x94/0x1f0 [mt76]
<7>[ 32.978034] kthread+0x11c/0x130
<7>[ 32.981255] ret_from_fork+0x10/0x20
<0>[ 32.984819] Code: a90363f7 f9422021 f100003f 9a810000 (f9400000)
<4>[ 32.990892] ---[ end trace 17b78c5614e839b7 ]---
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the reported call trace at mt76_connac2_mac_tx_rate_val and mt76_connac2_mac_write_txwi, then follow the mt7915_tx_prepare_skb path in the mt76 driver. Reproduce the crash on the Xiaomi Redmi Router AX6000 and identify the cause of the invalid address before defining and validating a fix.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, linux
- Domain
- networking, operating-systems
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100