#1621: kernel oopses with wlanconfig ath0 destroy, almost always reproducable
when
wep is used and station is assosiated.
----------------------------------+-----------------------------------------
Reporter: anonymous | Owner:
Type: defect | Status: new
Priority: blocker | Milestone:
Component: madwifi: driver | Version: trunk
Resolution: | Keywords: oops crash
Patch_attached: 0 |
----------------------------------+-----------------------------------------
Comment (by mtaylor):
I believe this is a node refcount bug that happens when a node has already
been freed, but the pointer in the buffer still exists as we are sweeping
through the queue to drain it. I'm still trying to narrow this down, but
it appears to have been exposed by a recent fix where a reference count
was being bumped five times inadvertently due to a macro in r2792 which
was causing nodes to stick around beyond ath_draintxq.
I've found a few places where we aren't unreferencing enough, but this bug
is from unreferencing without zeroing out a pointer. I've found only one
or two possible cases of this and I'm testing a patch for it now.
--
Ticket URL: <http://madwifi.org/ticket/1621#comment:2>
madwifi.org <http://madwifi.org/>
Multiband Atheros Driver for Wireless Fidelity
-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems? Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
Madwifi-tickets mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/madwifi-tickets