#1621: kernel oopses with wlanconfig ath0 destroy, almost always reproducable 
when
wep is used and station is assosiated.
----------------------------------+-----------------------------------------
      Reporter:  anonymous        |       Owner:            
          Type:  defect           |      Status:  new       
      Priority:  blocker          |   Milestone:            
     Component:  madwifi: driver  |     Version:  trunk     
    Resolution:                   |    Keywords:  oops crash
Patch_attached:  0                |  
----------------------------------+-----------------------------------------
Comment (by mtaylor):

 I believe this is a node refcount bug that happens when a node has already
 been freed, but the pointer in the buffer still exists as we are sweeping
 through the queue to drain it.  I'm still trying to narrow this down, but
 it appears to have been exposed by a recent fix where a reference count
 was being bumped five times inadvertently due to a macro in r2792 which
 was causing nodes to stick around beyond ath_draintxq.

 I've found a few places where we aren't unreferencing enough, but this bug
 is from unreferencing without zeroing out a pointer.  I've found only one
 or two possible cases of this and I'm testing a patch for it now.

-- 
Ticket URL: <http://madwifi.org/ticket/1621#comment:2>
madwifi.org <http://madwifi.org/>
Multiband Atheros Driver for Wireless Fidelity
-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
Madwifi-tickets mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/madwifi-tickets

Reply via email to