Bug#394742: linux-image-2.6.17-2-686: Bluetooth related panic
On Sun, Oct 22, 2006 at 10:43:36PM +0300, Mikko Rapeli wrote: When a GPRS/Bluetooth/ppp connection is open and I do poweroff or 'telinit 1' the kernel panics with this output (handwritten from camera screen shots): Thanks Mikko. Can you reproduce with the 2.6.18 kernel in sid? It should install fine on an etch system, and is the kernel we plan to ship in etch. -- dann frazier -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]
Bug#394742: linux-image-2.6.17-2-686: Bluetooth related panic
On Mon, Oct 23, 2006 at 12:33:39PM -0600, dann frazier wrote: Thanks Mikko. Can you reproduce with the 2.6.18 kernel in sid? It should install fine on an etch system, and is the kernel we plan to ship in etch. Yes. Exact steps in this case: boot to run level 2, login as root on virtual terminal 2, run screen, 'pon gprs-bt', open another shell to ping some host, open a third shell to do 'telinit 1'. Running 'pon gprs-bt' inside an X session didn't crash this time. Hand written trace from camera shots: release_dev: rfcomm1: read/write wait queue active! ...[gazillion times] BUG: unable to handel kernel NULL pointer dereference at virtual address 0005 printing eip: 0005 *pde = Oops: [#3] SMP: Modules linkde in: ... CPU:0 EIP:0060:[0005] Not tainted VLI EFLAGS: 00010012(2.6.18-1-686 #1) EIP is at 0x5 eax: ca84df28 ebx: ca84df28 ecx: edx: 0003 esi: ca3d1ab0 edi: 0001 ebp: ca24fc50 esp: ca24fc30 ds: 007b es: 007b ss: 0068 Process pppd (pid: 3166, ti=ca24e000 task=ca3d1030 task.ti=ca24e000) Stack: ... Call Trace: [c011624d] __wake_up_common+0x2f/0x53 [c011669e] __wake_up+0x2a/0x3d [c01f8d5b] release_dev+0x239/0x5ee [c0220a1d] _spin_lock_bh+0x8/0x18 ...[too much hex for my fingers and eyes] lock_sock+0x89/0x91 lock_sock+0x89/0x91 inet6_destroy_sock+0x22/0x3a [ipv6] tty_release+0xf/0x18 __fput+0x8a/0x13f flip_close+0x4e/0x54 put_files_struct+0x65/0xa7 do_exit+0x1d1/0x714 die+0x1e2/0x28a die+0x265/0x28a do_page_fault+0x3b4/0x481 do_page_fault+0x0/0x481 error_code+0x39/0x40 cp_new_stat+0xed/0x152 rfcomm_tty_chars_in_buffer+0x8/0x19 [rfcomm] tty_wait_until_sent+0x74/0xb9 default_wake_funtion+0x0/0xc n_tty_ioctl+0x0/0x40d set_termios+0xbe/0x2e9 do_path_lookup+0x20a/0x255 path_lookup+0xf/0x11 n_tty_ioctl++xb4d/0xbac unix_dgram_connect+0x6a/0x137 sys_connect+0x7d/0xa9 do_wp_page+0x12b/0x344 inotify_d_instantiate+0x36/0x59 __handle_mm_fault+0x6d8/0x740 do_ioctl+0x47/0x5d vfs_ioctl+0x24a/0x25c sys_ioctl+0x48/0x5f syscall_call+0x7/0xb Code: Bad EIP value. EIP: [0005] 0x5 SS:ESP 0068:ca24fc30 1Fixing recursive fault but reboot is needed! -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]
Bug#394742: linux-image-2.6.17-2-686: Bluetooth related panic
Package: linux-image-2.6.17-2-686 Version: 2.6.17-9 Severity: normal *** Please type your report below this line *** When a GPRS/Bluetooth/ppp connection is open and I do poweroff or 'telinit 1' the kernel panics with this output (handwritten from camera screen shots): release_dev: rfcomm1: read/write wait queue active! ...[screenloads of same] release_dev: rfcomm1: read/write wait queue active! done invalid opcode: [#3] SMP Modules linked in: ... CPU:0 EIP:0060:[bff995b5] Not tainted VLI EFLAGS: 00010016(2.6.17-2-686 #1) EIP is at 0xbff995b5 eax: b9c23f28 ebx: b9c27e28 ecx: edx: 0003 esi: b1203ca0 edi: 0001 ebp: ba58bc3c esp: ba58bc1b ds: 007bes: 007bss: 0068 Process pppd (pid: 4586, threadinfo=ba58a000 task=bffae050) Stack: 115f0aba 00b0 0300 65b13400 ea3bb8ba 65b134bf 00ba 0100 58bc6000 117cb2ba 00b0 0300 00029200 65b0 00ba 58bca800 00ba 1f1a0200 00b0 0100 82b0ea00 58bca0bf 80bdc2ba Call Trace: Code: ... EIP: [bff995b5] 0xbff995b5 SS:ESP 0068:ba58bc1b 1Fixing recursive fault but reboot is needed! Computer is a IBM T20 with a Bluetooth USB dongle: # lspci 00:00.0 Host bridge: Intel Corporation 440BX/ZX/DX - 82443BX/ZX/DX Host bridge (rev 03) 00:01.0 PCI bridge: Intel Corporation 440BX/ZX/DX - 82443BX/ZX/DX AGP bridge (rev 03) 00:02.0 CardBus bridge: Texas Instruments PCI1450 (rev 03) 00:02.1 CardBus bridge: Texas Instruments PCI1450 (rev 03) 00:03.0 Ethernet controller: Intel Corporation 82557/8/9 [Ethernet Pro 100] (rev 09) 00:03.1 Serial controller: Xircom Mini-PCI V.90 56k Modem 00:05.0 Multimedia audio controller: Cirrus Logic CS 4614/22/24 [CrystalClear SoundFusion Audio Accelerator] (rev 01) 00:07.0 Bridge: Intel Corporation 82371AB/EB/MB PIIX4 ISA (rev 02) 00:07.1 IDE interface: Intel Corporation 82371AB/EB/MB PIIX4 IDE (rev 01) 00:07.2 USB Controller: Intel Corporation 82371AB/EB/MB PIIX4 USB (rev 01) 00:07.3 Bridge: Intel Corporation 82371AB/EB/MB PIIX4 ACPI (rev 03) 01:00.0 VGA compatible controller: S3 Inc. 86C270-294 Savage/IX-MV (rev 11) # lsusb Bus 001 Device 002: ID 0a12:0001 Cambridge Silicon Radio, Ltd Bluetooth Dongle (HCI mode) Bus 001 Device 001: ID : I can't get the panic screen shots out of the camera at the moment. Anything else I could do to help debug this? -Mikko -- System Information: Debian Release: testing APT prefers testing APT policy: (990, 'testing'), (500, 'unstable'), (500, 'stable') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.17-2-686 Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968) Versions of packages linux-image-2.6.17-2-686 depends on: ii initramfs-tools [linux-initra 0.83 tools for generating an initramfs ii module-init-tools 3.2.2-3tools for managing Linux kernel mo Versions of packages linux-image-2.6.17-2-686 recommends: pn libc6-i686none (no description available) -- debconf information excluded -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]