openwrt / openwrt/mt76

crash log on mir3

Open
#833 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
888
Forks
436
PR merge metrics
No merged PRs in 30d

Description

<3>[58424.323147] mt76x2e 0000:01:00.0: MCU message 1f (seq 5) timed out
<6>[58424.369572] mt76x2e 0000:01:00.0: Firmware Version: 0.0.00
<6>[58424.375217] mt76x2e 0000:01:00.0: Build: 1
<6>[58424.379479] mt76x2e 0000:01:00.0: Build Time: 201607111443____
<6>[58424.399821] mt76x2e 0000:01:00.0: Firmware running!
<6>[58424.406468] ieee80211 phy0: Hardware restart was requested
<3>[60077.384126] mt76x2e 0000:01:00.0: MCU message 1f (seq 14) timed out
<6>[60077.427915] mt76x2e 0000:01:00.0: Firmware Version: 0.0.00
<6>[60077.433537] mt76x2e 0000:01:00.0: Build: 1
<6>[60077.437782] mt76x2e 0000:01:00.0: Build Time: 201607111443____
<6>[60077.452736] mt76x2e 0000:01:00.0: Firmware running!
<6>[60077.459507] ieee80211 phy0: Hardware restart was requested
<3>[60077.812250] mt76x2e 0000:01:00.0: MCU message 02 (seq 2) timed out
<3>[60078.215655] mt76x2e 0000:01:00.0: MCU message 1f (seq 3) timed out
<6>[60078.510781] mt76x2e 0000:01:00.0: Firmware Version: 0.0.00
<6>[60078.516402] mt76x2e 0000:01:00.0: Build: 1
<6>[60078.520678] mt76x2e 0000:01:00.0: Build Time: 201607111443____
<6>[60078.569403] mt76x2e 0000:01:00.0: Firmware running!
<6>[60078.583640] ieee80211 phy0: Hardware restart was requested
<6>[60079.324360] br-lan: port 2(phy0-ap0) entered disabled state
<6>[60081.167646] phy0-sta0: authenticate with 0a:xx:70:c7:xx:xx
<6>[60081.561069] phy0-sta0: send auth to 0a:xx:70:c7:xx:xx (try 1/3)
<6>[60081.570355] phy0-sta0: authenticated
<6>[60081.639488] phy0-sta0: associate with 0a:xx:70:c7:xx:xx (try 1/3)
<6>[60081.655615] phy0-sta0: RX AssocResp from 0a:xx:70:c7:xx:xx (capab=0x11 status=0 aid=4)
<6>[60081.664161] phy0-sta0: associated
<7>[60081.714961] phy0-sta0: Limiting TX power to 27 (30 - 3) dBm as advertised by 0a:xx:70:c7:xx:xx
<6>[60083.044169] br-lan: port 2(phy0-ap0) entered blocking state
<6>[60083.049961] br-lan: port 2(phy0-ap0) entered forwarding state
<3>[60118.390140] mt76x2e 0000:01:00.0: MCU message 1f (seq 3) timed out
<6>[60118.461474] mt76x2e 0000:01:00.0: Firmware Version: 0.0.00
<6>[60118.467381] mt76x2e 0000:01:00.0: Build: 1
<6>[60118.471685] mt76x2e 0000:01:00.0: Build Time: 201607111443____
<6>[60118.501051] mt76x2e 0000:01:00.0: Firmware running!
<6>[60118.516559] ieee80211 phy0: Hardware restart was requested
<1>[60118.522590] CPU 0 Unable to handle kernel paging request at virtual address 00000004, epc == 82984308, ra == 829842e4
<4>[60118.533491] Oops[#1]:
<4>[60118.535817] CPU: 0 PID: 2227 Comm: hostapd Not tainted 5.10.179 #0
<4>[60118.542119] $ 0   : 00000000 00000001 8409d9f8 00000000
<4>[60118.547471] $ 4   : 00000000 00000200 00000000 00000000
<4>[60118.552814] $ 8   : 00000000 0000000f 00000000 80917860
<4>[60118.558157] $12   : 00000002 00000000 00000402 8409da18
<4>[60118.563501] $16   : 829996e0 82d1d9ec 8409d91c 00000010
<4>[60118.568846] $20   : 8409d784 00000000 82be6ff8 00000001
<4>[60118.574189] $24   : 00000040 00000000                  
<4>[60118.579535] $28   : 82d1c000 82d1d9d8 00000000 829842e4
<4>[60118.584881] Hi    : 00000009
<4>[60118.587817] Lo    : 9999999c
<4>[60118.590792] epc   : 82984308 mt76_wcid_cleanup+0x74/0x180 [mt76]
<4>[60118.596928] ra    : 829842e4 mt76_wcid_cleanup+0x50/0x180 [mt76]
<4>[60118.603051] Status: 1100f403	KERNEL EXL IE 
<4>[60118.607332] Cause : 4080000c (ExcCode 03)
<4>[60118.611418] BadVA : 00000004
<4>[60118.614354] PrId  : 00019650 (MIPS 24KEc)
<4>[60118.618439] Modules linked in: rt2800soc rt2800mmio rt2800lib qcserial pppoe ppp_async option cdc_mbim wireguard usb_wwan sierra_net sierra rt2x00soc rt2x00mmio rt2x00lib rndis_host qmi_wwan pptp pppox ppp_mppe ppp_generic nft_fib_inet mt76x2e mt76x2_common mt76x02_lib mt76 mac80211 libchacha20poly1305 ipt_REJECT huawei_cdc_ncm cfg80211 cdc_ncm cdc_ether xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_recent xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_hl xt_helper xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_TCPMSS xt_REDIRECT xt_MASQUERADE xt_LOG xt_HL xt_DSCP xt_CT xt_CLASSIFY usbserial usbnet usblp ums_usbat ums_sddr55 ums_sddr09 ums_karma ums_jumpshot ums_isd200 ums_freecom ums_datafab ums_cypress ums_alauda ts_fsm ts_bm tcp_scalable tcp_bbr slhc sch_cake r8152 poly1305_mips ntfs3 nft_tproxy nft_socket nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet nft_reject_bridge nft_reject nft_redir nft_quota nft_queue nft_objref nft_numgen
<4>[60118.618924]  nft_nat nft_meta_bridge nft_masq nft_log nft_limit nft_hash nft_fwd_netdev nft_fib_ipv6 nft_fib_ipv4 nft_fib nft_dup_netdev nft_ct nft_counter nft_compat nft_chain_nat nfnetlink_queue nf_tproxy_ipv6 nf_tproxy_ipv4 nf_tables nf_socket_ipv6 nf_socket_ipv4 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_pptp nf_nat_irc nf_nat_h323 nf_nat_ftp nf_nat_amanda nf_log_ipv6 nf_log_ipv4 nf_log_common nf_dup_netdev nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_pptp nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast nf_conntrack_bridge ts_kmp nf_conntrack_amanda nf_conncount macvlan libcurve25519_generic libcrc32c ipvlan iptable_raw iptable_nat iptable_mangle iptable_filter ipt_ECN ipheth ip_tables crc_ccitt compat chacha_mips cdc_wdm br_netfilter asn1_decoder natflow natcap nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 sch_tbf sch_ingress sch_htb sch_hfsc em_u32 cls_u32 cls_route cls_matchall cls_fw cls_flow cls_basic
<4>[60118.708273]  act_skbedit act_mirred act_gact xt_set ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ipmac ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6table_mangle ip6table_filter ip6_tables ip6t_REJECT x_tables nf_reject_ipv6 nfsv4 nfs nfs_ssc msdos ip6_gre ip_gre gre ifb sit ip6_tunnel oid_registry tunnel6 tunnel4 ip_tunnel tun ovpn_dco_v2 udp_tunnel ip6_udp_tunnel lockd sunrpc grace autofs4 dns_resolver nls_utf8 nls_iso8859_1 nls_cp437 crypto_user algif_skcipher algif_rng algif_hash algif_aead af_alg sha512_generic sha256_generic libsha256 sha1_generic seqiv jitterentropy_rng drbg md5 md4 hmac ecb des_generic libdes cmac arc4 uas usb_storage leds_gpio ohci_platform ohci_hcd fsl_mph_dr_of ehci_platform ehci_fsl sd_mod scsi_mod ehci_hcd gpio_button_hotplug vfat fat ext4
<4>[60118.797311]  mbcache jbd2 exfat usbcore nls_base usb_common mii crc32c_generic
<4>[60118.894018] Process hostapd (pid: 2227, threadinfo=3db51018, task=198a971b, tls=77e80dfc)
<4>[60118.902354] Stack : 00000000 8409d91c 00000010 82ab038c 84001200 82d1d9ec 82d1d9ec 00000000
<4>[60118.910906]         00000010 829996e0 8409d91c 8298451c 8416d400 8409d034 8416d400 00000001
<4>[60118.919455]         8409d784 82be6ff8 82999ab8 829996e0 8409d784 82be64a0 829989a8 82984648
<4>[60118.928006]         82d1da44 82983a48 00000001 8409d000 8409d000 00000000 829984a0 82be64a0
<4>[60118.936556]         8409d784 82b0b63c 82be6000 0000000f 8515ea20 82998000 00000000 82a30d6c
<4>[60118.945106]         ...
<4>[60118.947610] Call Trace:
<4>[60118.950120] [<82984308>] mt76_wcid_cleanup+0x74/0x180 [mt76]
<4>[60118.955918] [<8298451c>] __mt76_sta_remove+0x84/0xe8 [mt76]
<4>[60118.961625] [<82984648>] mt76_sta_state+0xc8/0x1d0 [mt76]
<4>[60118.967309] [<82b0b63c>] sta_set_sinfo+0xe74/0xf74 [mac80211]
<4>[60118.973343] 
<4>[60118.974863] Code: 00000000  8e4300e0  8e4400dc <ac830004> ac640000  ae4200dc  ae4200e0  8e4300e4  264200e4 
<4>[60118.984844] 
<4>[60118.986452] ---[ end trace 59a986ca95b5159b ]---

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by inspecting mt76_wcid_cleanup and its callers __mt76_sta_remove and mt76_sta_state, then correlate them with the MCU timeout and hardware-restart sequence in the report. Reproduce the failure on the affected mt76x2e setup if possible and trace the invalid access. Done means the same recovery path no longer produces the kernel oops, with regression coverage where the project supports it.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
networking, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.