openwrt / openwrt/mt76

crash log on rm-ax6000 (mt7986)

Open
#828 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
888
Forks
436
PR merge metrics
No merged PRs in 30d

Description

<1>[   32.529539] Unable to handle kernel paging request at virtual address 00000a801d000200
<1>[   32.537483] Mem abort info:
<1>[   32.540269]   ESR = 0x0000000096000004
<1>[   32.544001]   EC = 0x25: DABT (current EL), IL = 32 bits
<1>[   32.549308]   SET = 0, FnV = 0
<1>[   32.552354]   EA = 0, S1PTW = 0
<1>[   32.555483]   FSC = 0x04: level 0 translation fault
<1>[   32.560367] Data abort info:
<1>[   32.563240]   ISV = 0, ISS = 0x00000004
<1>[   32.567073]   CM = 0, WnR = 0
<1>[   32.570031] [00000a801d000200] address between user and kernel address ranges
<0>[   32.577159] Internal error: Oops: 96000004 [#1] SMP
<7>[   32.582030] Modules linked in: pppoe ppp_async l2tp_ppp wireguard pptp pppox ppp_mppe ppp_generic nft_fib_inet mt7915e mt76_connac_lib mt76 mac80211 libchacha20poly1305 ipt_REJECT chacha_neon cfg80211 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_recent xt_policy xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_hl xt_helper xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_TCPMSS xt_REDIRECT xt_MASQUERADE xt_LOG xt_HL xt_DSCP xt_DNETMAP xt_DHCPMAC xt_CT xt_CLASSIFY xfrm_interface ts_fsm ts_bm tcp_scalable tcp_bbr slhc sch_cake poly1305_neon nft_tproxy nft_socket nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_queue nft_objref nft_numgen nft_nat nft_meta_bridge nft_masq nft_log nft_limit nft_hash nft_fwd_netdev nft_fib_ipv6 nft_fib_ipv4 nft_fib nft_dup_netdev nft_ct nft_counter nft_compat nft_chain_nat nfnetlink_queue nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables nf_socket_ipv6
<7>[   32.582187]  nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_pptp nf_nat_irc nf_nat_h323 nf_nat_ftp nf_nat_amanda nf_log_syslog nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_pptp nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast nf_conntrack_bridge ts_kmp nf_conntrack_amanda nf_conncount macvlan libcurve25519_generic libcrc32c libchacha ipvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ah ipt_ECN ip_tables crc_ccitt compat_xtables compat br_netfilter asn1_decoder natflow natcap nf_nat nf_conntrack crypto_safexcel sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_route cls_matchall cls_fw cls_flow cls_basic act_skbedit act_mirred act_gact xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark
<7>[   32.668368]  ip_set_hash_ipmac ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink jool_siit jool nf_defrag_ipv4 jool_common ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 bonding tls ip6_gre ip_gre gre ifb nat46 nf_defrag_ipv6 ip6_vti ip_vti sit l2tp_netlink l2tp_core ipcomp6 xfrm6_tunnel esp6 ah6 xfrm4_tunnel ipcomp esp4 ah4 ip6_tunnel tunnel6 tunnel4 ip_tunnel udp_diag tcp_diag raw_diag inet_diag tun ovpn_dco_v2 udp_tunnel ip6_udp_tunnel xfrm_user xfrm_ipcomp af_key xfrm_algo autofs4 nls_utf8 nls_iso8859_1 crypto_user algif_skcipher algif_rng algif_hash algif_aead af_alg sha1_generic seqiv md5 echainiv des_generic libdes chacha20poly1305 cbc authencesn authenc arc4 leds_ws2812b leds_gpio gpio_button_hotplug usbcore usb_common
<7>[   32.825447] CPU: 1 PID: 1330 Comm: mt76-tx phy0 Not tainted 5.15.133 #0
<7>[   32.832042] Hardware name: Xiaomi Redmi Router AX6000 (stock layout) (DT)
<7>[   32.838809] pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
<7>[   32.845751] pc : mt76_connac2_mac_tx_rate_val+0x2c/0x250 [mt76_connac_lib]
<7>[   32.852615] lr : mt76_connac2_mac_write_txwi+0x3b4/0x580 [mt76_connac_lib]
<7>[   32.859471] sp : ffffffc009183900
<7>[   32.862769] x29: ffffffc009183900 x28: 0000000000000000 x27: 0000000000000000
<7>[   32.869886] x26: ffffff80097a6840 x25: 0000000000000000 x24: ffffff8003fa6040
<7>[   32.877001] x23: ffffff8006e40101 x22: 0000000000000000 x21: ffffff8003fa2040
<7>[   32.884116] x20: ffffff8006e40101 x19: ffffff800793dc80 x18: 0000000000000000
<7>[   32.891232] x17: 0000000000000000 x16: 0000000000000000 x15: 03003ff42407ff71
<7>[   32.898346] x14: c71c71c71c71c71c x13: 0000000080000400 x12: 000000008000021f
<7>[   32.905462] x11: 0000000000007800 x10: 000000004020021b x9 : 0000000000000000
<7>[   32.912577] x8 : 0000000000000000 x7 : 0000000000007922 x6 : 0000000000007961
<7>[   32.919693] x5 : 0000000000000005 x4 : 0000000000050000 x3 : 0000000000000000
<7>[   32.926808] x2 : 0000000000000000 x1 : 00000a801d000200 x0 : 00000a801d000200
<7>[   32.933924] Call trace:
<7>[   32.936357]  mt76_connac2_mac_tx_rate_val+0x2c/0x250 [mt76_connac_lib]
<7>[   32.942868]  mt76_connac2_mac_write_txwi+0x3b4/0x580 [mt76_connac_lib]
<7>[   32.949377]  mt7915_tx_prepare_skb+0xe4/0x224 [mt7915e]
<7>[   32.954588]  mt76_dma_cleanup+0x7ac/0x8f0 [mt76]
<7>[   32.959193]  mt76_tx_check_agg_ssn+0xa8/0x110 [mt76]
<7>[   32.964141]  mt76_txq_schedule_all+0x230/0x380 [mt76]
<7>[   32.969177]  mt76_tx_worker+0x2c/0x2f0 [mt76]
<7>[   32.973519]  __mt76_worker_fn+0x94/0x1f0 [mt76]
<7>[   32.978034]  kthread+0x11c/0x130
<7>[   32.981255]  ret_from_fork+0x10/0x20
<0>[   32.984819] Code: a90363f7 f9422021 f100003f 9a810000 (f9400000) 
<4>[   32.990892] ---[ end trace 17b78c5614e839b7 ]---

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the reported call trace at mt76_connac2_mac_tx_rate_val and mt76_connac2_mac_write_txwi, then follow the mt7915_tx_prepare_skb path in the mt76 driver. Reproduce the crash on the Xiaomi Redmi Router AX6000 and identify the cause of the invalid address before defining and validating a fix.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
networking, operating-systems
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.