kmssink crashes on Pi3B+ running 5.4.72-v7+ (vc4_plane_mode_set)

Open
#3,959 10 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
c, linux, raspberry-pi

Research direction

Start with the vc4_plane_mode_set path named in the kernel trace and reproduce the crash using the supplied gst-launch-1.0 command on a Pi 3B+ with Full KMS. Compare the failing vc4 atomic plane-check path with the reported NULL dereference; done means playback no longer triggers the kernel crash under the stated configuration.

Written by the indexing model from the issue text.

Description

Describe the bug
When attempting to playback the test H264 video with GStreamer outside of X using the kmssink, I am repeatedly getting the following crash (although it does work at times). This is running the Full KMS stack.

[  157.132120] 8<--- cut here ---
[  157.132204] Unable to handle kernel NULL pointer dereference at virtual address 00000064
[  157.132317] pgd = e8cdcaa1
[  157.132358] [00000064] *pgd=36d93835, *pte=00000000, *ppte=00000000
[  157.132455] Internal error: Oops: 17 [#1] SMP ARM
[  157.132514] Modules linked in: rfcomm bnep hci_uart btbcm bluetooth ecdh_generic ecc 8021q garp stp llc joydev vc4 cec drm_kms_helper drm brcmfmac brcmutil drm_panel_orientation_quirks snd_soc_core sha256_generic snd_compress libsha256 snd_pcm_dmaengine syscopyarea sysfillrect sysimgblt fb_sys_fops raspberrypi_hwmon cfg80211 rfkill bcm2835_codec(C) bcm2835_v4l2(C) i2c_bcm2835 v4l2_mem2mem bcm2835_isp(C) bcm2835_mmal_vchiq(C) snd_bcm2835(C) videobuf2_vmalloc videobuf2_dma_contig videobuf2_memops videobuf2_v4l2 snd_pcm videobuf2_common snd_timer videodev snd vc_sm_cma(C) mc uio_pdrv_genirq uio fixed i2c_dev ip_tables x_tables ipv6
[  157.133208] CPU: 2 PID: 691 Comm: v4l2h264dec0:sr Tainted: G         C        5.4.72-v7+ #1356
[  157.133311] Hardware name: BCM2835
[  157.133440] PC is at vc4_plane_mode_set+0x9d8/0x13e0 [vc4]
[  157.133551] LR is at vc4_plane_mode_set+0xbc0/0x13e0 [vc4]
[  157.133614] pc : [<7f445748>]    lr : [<7f445930>]    psr: 20000013
[  157.133695] sp : b24ffa98  ip : b24ffa98  fp : b24ffb34
[  157.133755] r10: b53e00c0  r9 : ffff0000  r8 : 00000001
[  157.133813] r7 : 000003c0  r6 : b53e0104  r5 : 00000001  r4 : b8285000
[  157.133889] r3 : 00000060  r2 : 00000002  r1 : 00000780  r0 : b8285000
[  157.133962] Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment user
[  157.134040] Control: 10c5383d  Table: 324a406a  DAC: 00000055
[  157.134114] Process v4l2h264dec0:sr (pid: 691, stack limit = 0x15237604)
[  157.134194] Stack: (0xb24ffa98 to 0xb2500000)
[  157.134251] fa80:                                                       b24ffb00 00000001
[  157.134343] faa0: 00000000 b24ffab0 00000000 00000000 00000000 00000002 00000002 00000000
[  157.134436] fac0: b8285000 00000001 b8258440 00000008 b53e00c0 00000000 7f453ef0 00000000
[  157.134527] fae0: 00000780 00000000 00000003 00000000 b5042000 00000000 00000000 00000000
[  157.134614] fb00: 00000000 80e04f88 805a140c b8285000 b51b44c0 b831e240 b8285000 7f2eb8f8
[  157.134714] fb20: 7f44ffb0 00000003 b24ffb8c b24ffb38 7f4462b0 7f444d7c b51b44c0 00000002
[  157.134812] fb40: 00000002 00000002 b24f7884 b24f7880 b5042000 b51b44c0 b24ffbb4 b24ffb68
[  157.134904] fb60: 7f391f14 00000003 b51b44c0 b831e240 b8285000 7f2eb8f8 7f44ffb0 00000003
[  157.134994] fb80: b24ffbb4 b24ffb90 7f2e06d0 7f44627c 00000000 b51b44c0 b8258800 00000001
[  157.135085] fba0: 00000000 00000001 b24ffbd4 b24ffbb8 7f2e082c 7f2e05ec b51b44c0 b5042000
[  157.135185] fbc0: b51b44c0 00000001 b24ffc14 b24ffbd8 7f433664 7f2e07e4 b82585d8 b8258800
[  157.135288] fbe0: 00000005 80e04f88 b24ffc14 b5e20840 b5e20840 b51b44c0 00000001 b24f750c
[  157.135389] fc00: ffffffff b24f7508 b24ffca4 b24ffc18 7f38be60 7f43342c b24ffc3c b24ffc28
[  157.135478] fc20: 7f393298 7f39269c b5042000 b5e20840 b24ffc54 b24ffc40 7f2e3970 7f38b2fc
[  157.135569] fc40: b8258800 b5e20840 b6cdc200 07800000 7f42b680 7f3926cc b24ffc70 7f38b2fc
[  157.135660] fc60: b53e00d8 b53e00c0 b24ffc84 b24ffc78 805ad9a4 80e04f88 b24ffc9c b8285000
[  157.135754] fc80: b51b44c0 b8258800 b5e20840 00000000 b53e00c0 00000000 b24ffcc4 b24ffca8
[  157.135842] fca0: 7f38c0a4 7f38b89c b8285000 b51b44c0 b831e240 b5e20840 b24ffcf4 b24ffcc8
[  157.135928] fcc0: 7f2e179c 7f38c090 00000000 7f2e16b4 b53e00c0 b5e20840 00000000 00000000
[  157.136015] fce0: 07800000 04380000 b24ffd44 b24ffcf8 7f395244 7f2e16c0 00000000 00000780
[  157.136096] fd00: 00000438 00000000 00000000 07800000 04380000 b24ffd84 7f38af5c 04380000
[  157.136178] fd20: b53e00c0 b831e270 b5e20840 b831e240 00000000 00000000 b24ffdd4 b24ffd48
[  157.136260] fd40: 7f395a30 7f39514c 00000000 00000780 00000438 00000000 00000000 07800000
[  157.136344] fd60: 04380000 b24ffd84 00000000 07800000 00000000 00000000 00000438 00000780
[  157.136440] fd80: 805ca4a8 b50e9e80 0000099e 0000001c 00000000 00000000 b8258628 b8258908
[  157.136538] fda0: 00000100 80e04f88 00000002 00000000 b8258800 00000002 7f395910 b24ffe34
[  157.136627] fdc0: b52a7f00 c03064b7 b24ffe04 b24ffdd8 7f37a988 7f39591c 00000000 80e04f88
[  157.136721] fde0: 00000030 7f3aa8ac 00000030 b24ffe34 000000b7 b52a7f00 b24ffee4 b24ffe08
[  157.136819] fe00: 7f37abb4 7f37a8cc 00000001 7f3b8258 00000000 b24ffe38 76d75980 7f395910
[  157.136906] fe20: b953e540 00000030 b24ffe34 7477e5d4 00000000 0000004b 0000004a 000000c0
[  157.137005] fe40: 00000000 00000000 00000000 00000780 00000438 00000000 00000000 04380000
[  157.137103] fe60: 07800000 cf589d00 00000000 7fffffff 76d75980 000000f0 b24fff4c b24ffe88
[  157.141084] fe80: 801b7fec 801b5098 b5ea03c0 0046b000 00000054 00000040 b24fff24 b24ffea8
[  157.145200] fea0: 802c3170 802ccc10 00000000 80116138 b5f76200 80e04f88 b24ffefc 7477e5d4
[  157.149300] fec0: b5e6a3d8 c03064b7 7477e5d4 b953e540 00000008 00000036 b24fff6c b24ffee8
[  157.152935] fee0: 8031df80 7f37a9d8 b50e71ac bb29a090 00000000 80e04f88 b24fff24 b24fffb0
[  157.156569] ff00: 0046b290 00000017 b50e9e80 b5f76200 b5f76240 8092e134 b24fff74 80e04f88
[  157.160766] ff20: 8092e134 00000000 00000081 8032a93c 00026ee8 7477e5d4 c03064b7 80e04f88
[  157.164670] ff40: b24fff5c b953e541 00000000 c03064b7 7477e5d4 b953e540 00000008 00000036
[  157.168777] ff60: b24fff94 b24fff70 8031e414 8031dbbc 00026ee8 7477e5d4 c03064b7 00000036
[  157.172736] ff80: 801011c4 b24fe000 b24fffa4 b24fff98 8031e450 8031e3b4 00000000 b24fffa8
[  157.176736] ffa0: 80101000 8031e444 00026ee8 7477e5d4 00000008 c03064b7 7477e5d4 04380000
[  157.180362] ffc0: 00026ee8 7477e5d4 c03064b7 00000036 00000780 00000438 00000000 76efd660
[  157.184013] ffe0: 75ce908c 7477e5b4 75ccf88c 76bbd51c 80000010 00000008 00000000 00000000
[  157.187641] Backtrace:
[  157.191297] [<7f444d70>] (vc4_plane_mode_set [vc4]) from [<7f4462b0>] (vc4_plane_atomic_check+0x40/0x1a4 [vc4])
[  157.194994]  r10:00000003 r9:7f44ffb0 r8:7f2eb8f8 r7:b8285000 r6:b831e240 r5:b51b44c0
[  157.198673]  r4:b8285000
[  157.202414] [<7f446270>] (vc4_plane_atomic_check [vc4]) from [<7f2e06d0>] (drm_atomic_helper_check_planes+0xf0/0x1f8 [drm_kms_helper])
[  157.206144]  r10:00000003 r9:7f44ffb0 r8:7f2eb8f8 r7:b8285000 r6:b831e240 r5:b51b44c0
[  157.209935]  r4:00000003
[  157.213666] [<7f2e05e0>] (drm_atomic_helper_check_planes [drm_kms_helper]) from [<7f2e082c>] (drm_atomic_helper_check+0x54/0x9c [drm_kms_helper])
[  157.217309]  r9:00000001 r8:00000000 r7:00000001 r6:b8258800 r5:b51b44c0 r4:00000000
[  157.220945] [<7f2e07d8>] (drm_atomic_helper_check [drm_kms_helper]) from [<7f433664>] (vc4_atomic_check+0x244/0x448 [vc4])
[  157.224459]  r7:00000001 r6:b51b44c0 r5:b5042000 r4:b51b44c0
[  157.228154] [<7f433420>] (vc4_atomic_check [vc4]) from [<7f38be60>] (drm_atomic_check_only+0x5d0/0x7f4 [drm])
[  157.231742]  r10:b24f7508 r9:ffffffff r8:b24f750c r7:00000001 r6:b51b44c0 r5:b5e20840
[  157.235359]  r4:b5e20840
[  157.239153] [<7f38b890>] (drm_atomic_check_only [drm]) from [<7f38c0a4>] (drm_atomic_commit+0x20/0x60 [drm])
[  157.242852]  r10:00000000 r9:b53e00c0 r8:00000000 r7:b5e20840 r6:b8258800 r5:b51b44c0
[  157.246568]  r4:b8285000
[  157.250431] [<7f38c084>] (drm_atomic_commit [drm]) from [<7f2e179c>] (drm_atomic_helper_update_plane+0xe8/0xf8 [drm_kms_helper])
[  157.254206]  r7:b5e20840 r6:b831e240 r5:b51b44c0 r4:b8285000
[  157.258162] [<7f2e16b4>] (drm_atomic_helper_update_plane [drm_kms_helper]) from [<7f395244>] (__setplane_atomic+0x104/0x144 [drm])
[  157.262052]  r10:04380000 r9:07800000 r8:00000000 r7:00000000 r6:b5e20840 r5:b53e00c0
[  157.265950]  r4:7f2e16b4 r3:00000000
[  157.269997] [<7f395140>] (__setplane_atomic [drm]) from [<7f395a30>] (drm_mode_setplane+0x120/0x2c4 [drm])
[  157.273838]  r10:00000000 r9:00000000 r8:b831e240 r7:b5e20840 r6:b831e270 r5:b53e00c0
[  157.277680]  r4:04380000
[  157.281720] [<7f395910>] (drm_mode_setplane [drm]) from [<7f37a988>] (drm_ioctl_kernel+0xc8/0x10c [drm])
[  157.285626]  r10:c03064b7 r9:b52a7f00 r8:b24ffe34 r7:7f395910 r6:00000002 r5:b8258800
[  157.289529]  r4:00000000
[  157.293625] [<7f37a8c0>] (drm_ioctl_kernel [drm]) from [<7f37abb4>] (drm_ioctl+0x1e8/0x3a4 [drm])
[  157.297566]  r9:b52a7f00 r8:000000b7 r7:b24ffe34 r6:00000030 r5:7f3aa8ac r4:00000030
[  157.301625] [<7f37a9cc>] (drm_ioctl [drm]) from [<8031df80>] (do_vfs_ioctl+0x3d0/0x7f8)
[  157.305581]  r10:00000036 r9:00000008 r8:b953e540 r7:7477e5d4 r6:c03064b7 r5:b5e6a3d8
[  157.309533]  r4:7477e5d4
[  157.313471] [<8031dbb0>] (do_vfs_ioctl) from [<8031e414>] (ksys_ioctl+0x6c/0x90)
[  157.317448]  r10:00000036 r9:00000008 r8:b953e540 r7:7477e5d4 r6:c03064b7 r5:00000000
[  157.321427]  r4:b953e541
[  157.325375] [<8031e3a8>] (ksys_ioctl) from [<8031e450>] (sys_ioctl+0x18/0x1c)
[  157.329361]  r9:b24fe000 r8:801011c4 r7:00000036 r6:c03064b7 r5:7477e5d4 r4:00026ee8
[  157.333360] [<8031e438>] (sys_ioctl) from [<80101000>] (ret_fast_syscall+0x0/0x28)
[  157.337354] Exception stack(0xb24fffa8 to 0xb24ffff0)
[  157.341344] ffa0:                   00026ee8 7477e5d4 00000008 c03064b7 7477e5d4 04380000
[  157.345375] ffc0: 00026ee8 7477e5d4 c03064b7 00000036 00000780 00000438 00000000 76efd660
[  157.349413] ffe0: 75ce908c 7477e5b4 75ccf88c 76bbd51c
[  157.353425] Code: e594a008 e5922050 e5933010 e0833282 (e5930004)
[  157.357495] ---[ end trace 79bf510738c5f9b3 ]---

To reproduce
Enable full KMS, have the Pi boot to the console, run:

gst-launch-1.0 -e filesrc location=/opt/vc/src/hello_pi/hello_video/test.h264 ! h264parse ! v4l2h264dec capture-io-mode=4 ! kmssink

System

  • Which model of Raspberry Pi? Pi 3B+
  • Which OS and version (cat /etc/rpi-issue)? Generated using pi-gen, https://github.com/RPi-Distro/pi-gen, 825107f04027269db77426046f5085475b1ea22f, stage
  • Which firmware version (vcgencmd version)? version 74e754ff8947c58d2773253f77f6f68a303188f8 (clean) (release) (start)
  • Which kernel version (uname -a)? 5.4.72-v7+
Dominant language
C
Stars
13.2k
Forks
5.5k
Avg merge
2d 21h
Merged PRs (30d)
21

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from raspberrypi/linux

All issues in raspberrypi/linux

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.