diff for duplicates of <49A13E91.1090601@gmail.com> diff --git a/a/1.txt b/N1/1.txt index 74935ae..f0d2eb2 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -1,64 +1,38 @@ On 22.2.2009 12:18, Sitsofe Wheeler wrote: > While testing a linux-tip from yesterday, a > BUG kmalloc-4096: Poison overwritten -> warning appeared inside dmesg. I'm not aware of what I was doing othe= -r -> that browsing a few web pages and using ssh in the lead up to it. Out= -put +> warning appeared inside dmesg. I'm not aware of what I was doing other +> that browsing a few web pages and using ssh in the lead up to it. Output > is attached below: > > [ 3666.410818] ath5k phy0: unsupported jumbo > [ 4432.305651] ath5k phy0: unsupported jumbo -> [ 4466.022644] totem[4664]: segfault at 5bf7b980 ip b5b39cbb sp b0d5f= -130 error 6 in libpulse.so.0.4.1[b5afb000+4d000] -> [ 4617.353923] totem[5189]: segfault at 4c7a2ee0 ip b59bfdca sp b1c12= -ec0 error 6 in libpulse.so.0.4.1[b5981000+4d000] -> [ 7412.846146] =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= -=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= -=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= -=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D +> [ 4466.022644] totem[4664]: segfault at 5bf7b980 ip b5b39cbb sp b0d5f130 error 6 in libpulse.so.0.4.1[b5afb000+4d000] +> [ 4617.353923] totem[5189]: segfault at 4c7a2ee0 ip b59bfdca sp b1c12ec0 error 6 in libpulse.so.0.4.1[b5981000+4d000] +> [ 7412.846146] ============================================================================= > [ 7412.846159] BUG kmalloc-4096: Poison overwritten -> [ 7412.846163] ------------------------------------------------------= ------------------------ +> [ 7412.846163] ----------------------------------------------------------------------------- > [ 7412.846166] -> [ 7412.846172] INFO: 0xf6438010-0xf6438053. First byte 0x80 instead o= -f 0x6b -> [ 7412.846188] INFO: Allocated in dev_alloc_skb+0x21/0x40 age=3D629 c= -pu=3D0 pid=3D0 -> [ 7412.846197] INFO: Freed in skb_release_data+0x5e/0x90 age=3D21 cpu= -=3D0 pid=3D0 -> [ 7412.846204] INFO: Slab 0xc17a27e0 objects=3D7 used=3D5 fp=3D0xf643= -8000 flags=3D0x400020c3 -> [ 7412.846210] INFO: Object 0xf6438000 @offset=3D0 fp=3D0xf643a060 +> [ 7412.846172] INFO: 0xf6438010-0xf6438053. First byte 0x80 instead of 0x6b +> [ 7412.846188] INFO: Allocated in dev_alloc_skb+0x21/0x40 age=629 cpu=0 pid=0 +> [ 7412.846197] INFO: Freed in skb_release_data+0x5e/0x90 age=21 cpu=0 pid=0 +> [ 7412.846204] INFO: Slab 0xc17a27e0 objects=7 used=5 fp=0xf6438000 flags=0x400020c3 +> [ 7412.846210] INFO: Object 0xf6438000 @offset=0 fp=0xf643a060 > [ 7412.846212] -> [ 7412.846216] Object 0xf6438000: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b= - 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk -> [ 7412.846245] Object 0xf6438010: 80 00 00 00 ff ff ff ff ff ff 00= - 30 ab 1a 32 3f ....=FF=FF=FF=FF=FF=FF.0=AB.2? +> [ 7412.846216] Object 0xf6438000: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk +> [ 7412.846245] Object 0xf6438010: 80 00 00 00 ff ff ff ff ff ff 00 30 ab 1a 32 3f ....ÿÿÿÿÿÿ.0«.2? Hmm, beacon written after the memory was freed. -> [ 7412.846273] Object 0xf6438020: 00 30 ab 1a 32 3f e0 24 59 62 25= - b5 01 00 00 00 .0=AB.2?=E0$Yb%=B5.... -> [ 7412.846301] Object 0xf6438030: 64 00 31 00 00 08 57 69 72 65 6c= - 65 73 73 01 04 d.1...Wireless.. -> [ 7412.846329] Object 0xf6438040: 82 84 8b 96 03 01 06 05 04 01 02= - 00 00 55 fa af .............U=FA=AF -> [ 7412.846357] Object 0xf6438050: 5d 55 fa 5d 6b 6b 6b 6b 6b 6b 6b= - 6b 6b 6b 6b 6b ]U=FA]kkkkkkkkkkkk -> [ 7412.846385] Object 0xf6438060: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b= - 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk +> [ 7412.846273] Object 0xf6438020: 00 30 ab 1a 32 3f e0 24 59 62 25 b5 01 00 00 00 .0«.2?à$Yb%µ.... +> [ 7412.846301] Object 0xf6438030: 64 00 31 00 00 08 57 69 72 65 6c 65 73 73 01 04 d.1...Wireless.. +> [ 7412.846329] Object 0xf6438040: 82 84 8b 96 03 01 06 05 04 01 02 00 00 55 fa af .............Uú¯ +> [ 7412.846357] Object 0xf6438050: 5d 55 fa 5d 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b ]Uú]kkkkkkkkkkkk +> [ 7412.846385] Object 0xf6438060: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk -=2E.. +... -The unsupported jumbo message might be a clue. When we jump to the next= -:=20 -label, the buffer is at the end of the list in software, while in=20 -hardware it isn't. In theory, we might hit the bug with rx buffers=20 -exhaustion, because the test (bf_last =3D=3D bf) doesn't work as expect= -ed then. --- -To unsubscribe from this list: send the line "unsubscribe linux-wireles= -s" in -the body of a message to majordomo@vger.kernel.org -More majordomo info at http://vger.kernel.org/majordomo-info.html +The unsupported jumbo message might be a clue. When we jump to the next: +label, the buffer is at the end of the list in software, while in +hardware it isn't. In theory, we might hit the bug with rx buffers +exhaustion, because the test (bf_last == bf) doesn't work as expected then. diff --git a/a/content_digest b/N1/content_digest index d0e7aa7..5dcd39b 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -14,66 +14,40 @@ "On 22.2.2009 12:18, Sitsofe Wheeler wrote:\n" "> While testing a linux-tip from yesterday, a\n" "> BUG kmalloc-4096: Poison overwritten\n" - "> warning appeared inside dmesg. I'm not aware of what I was doing othe=\n" - "r\n" - "> that browsing a few web pages and using ssh in the lead up to it. Out=\n" - "put\n" + "> warning appeared inside dmesg. I'm not aware of what I was doing other\n" + "> that browsing a few web pages and using ssh in the lead up to it. Output\n" "> is attached below:\n" ">\n" "> [ 3666.410818] ath5k phy0: unsupported jumbo\n" "> [ 4432.305651] ath5k phy0: unsupported jumbo\n" - "> [ 4466.022644] totem[4664]: segfault at 5bf7b980 ip b5b39cbb sp b0d5f=\n" - "130 error 6 in libpulse.so.0.4.1[b5afb000+4d000]\n" - "> [ 4617.353923] totem[5189]: segfault at 4c7a2ee0 ip b59bfdca sp b1c12=\n" - "ec0 error 6 in libpulse.so.0.4.1[b5981000+4d000]\n" - "> [ 7412.846146] =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=\n" - "=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=\n" - "=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=\n" - "=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D\n" + "> [ 4466.022644] totem[4664]: segfault at 5bf7b980 ip b5b39cbb sp b0d5f130 error 6 in libpulse.so.0.4.1[b5afb000+4d000]\n" + "> [ 4617.353923] totem[5189]: segfault at 4c7a2ee0 ip b59bfdca sp b1c12ec0 error 6 in libpulse.so.0.4.1[b5981000+4d000]\n" + "> [ 7412.846146] =============================================================================\n" "> [ 7412.846159] BUG kmalloc-4096: Poison overwritten\n" - "> [ 7412.846163] ------------------------------------------------------=\n" - "-----------------------\n" + "> [ 7412.846163] -----------------------------------------------------------------------------\n" "> [ 7412.846166]\n" - "> [ 7412.846172] INFO: 0xf6438010-0xf6438053. First byte 0x80 instead o=\n" - "f 0x6b\n" - "> [ 7412.846188] INFO: Allocated in dev_alloc_skb+0x21/0x40 age=3D629 c=\n" - "pu=3D0 pid=3D0\n" - "> [ 7412.846197] INFO: Freed in skb_release_data+0x5e/0x90 age=3D21 cpu=\n" - "=3D0 pid=3D0\n" - "> [ 7412.846204] INFO: Slab 0xc17a27e0 objects=3D7 used=3D5 fp=3D0xf643=\n" - "8000 flags=3D0x400020c3\n" - "> [ 7412.846210] INFO: Object 0xf6438000 @offset=3D0 fp=3D0xf643a060\n" + "> [ 7412.846172] INFO: 0xf6438010-0xf6438053. First byte 0x80 instead of 0x6b\n" + "> [ 7412.846188] INFO: Allocated in dev_alloc_skb+0x21/0x40 age=629 cpu=0 pid=0\n" + "> [ 7412.846197] INFO: Freed in skb_release_data+0x5e/0x90 age=21 cpu=0 pid=0\n" + "> [ 7412.846204] INFO: Slab 0xc17a27e0 objects=7 used=5 fp=0xf6438000 flags=0x400020c3\n" + "> [ 7412.846210] INFO: Object 0xf6438000 @offset=0 fp=0xf643a060\n" "> [ 7412.846212]\n" - "> [ 7412.846216] Object 0xf6438000: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b=\n" - " 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n" - "> [ 7412.846245] Object 0xf6438010: 80 00 00 00 ff ff ff ff ff ff 00=\n" - " 30 ab 1a 32 3f ....=FF=FF=FF=FF=FF=FF.0=AB.2?\n" + "> [ 7412.846216] Object 0xf6438000: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n" + "> [ 7412.846245] Object 0xf6438010: 80 00 00 00 ff ff ff ff ff ff 00 30 ab 1a 32 3f ....\303\277\303\277\303\277\303\277\303\277\303\277.0\302\253.2?\n" "\n" "Hmm, beacon written after the memory was freed.\n" "\n" - "> [ 7412.846273] Object 0xf6438020: 00 30 ab 1a 32 3f e0 24 59 62 25=\n" - " b5 01 00 00 00 .0=AB.2?=E0$Yb%=B5....\n" - "> [ 7412.846301] Object 0xf6438030: 64 00 31 00 00 08 57 69 72 65 6c=\n" - " 65 73 73 01 04 d.1...Wireless..\n" - "> [ 7412.846329] Object 0xf6438040: 82 84 8b 96 03 01 06 05 04 01 02=\n" - " 00 00 55 fa af .............U=FA=AF\n" - "> [ 7412.846357] Object 0xf6438050: 5d 55 fa 5d 6b 6b 6b 6b 6b 6b 6b=\n" - " 6b 6b 6b 6b 6b ]U=FA]kkkkkkkkkkkk\n" - "> [ 7412.846385] Object 0xf6438060: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b=\n" - " 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n" + "> [ 7412.846273] Object 0xf6438020: 00 30 ab 1a 32 3f e0 24 59 62 25 b5 01 00 00 00 .0\302\253.2?\303\240$Yb%\302\265....\n" + "> [ 7412.846301] Object 0xf6438030: 64 00 31 00 00 08 57 69 72 65 6c 65 73 73 01 04 d.1...Wireless..\n" + "> [ 7412.846329] Object 0xf6438040: 82 84 8b 96 03 01 06 05 04 01 02 00 00 55 fa af .............U\303\272\302\257\n" + "> [ 7412.846357] Object 0xf6438050: 5d 55 fa 5d 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b ]U\303\272]kkkkkkkkkkkk\n" + "> [ 7412.846385] Object 0xf6438060: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n" "\n" - "=2E..\n" + "...\n" "\n" - "The unsupported jumbo message might be a clue. When we jump to the next=\n" - ":=20\n" - "label, the buffer is at the end of the list in software, while in=20\n" - "hardware it isn't. In theory, we might hit the bug with rx buffers=20\n" - "exhaustion, because the test (bf_last =3D=3D bf) doesn't work as expect=\n" - "ed then.\n" - "--\n" - "To unsubscribe from this list: send the line \"unsubscribe linux-wireles=\n" - "s\" in\n" - "the body of a message to majordomo@vger.kernel.org\n" - More majordomo info at http://vger.kernel.org/majordomo-info.html + "The unsupported jumbo message might be a clue. When we jump to the next: \n" + "label, the buffer is at the end of the list in software, while in \n" + "hardware it isn't. In theory, we might hit the bug with rx buffers \n" + exhaustion, because the test (bf_last == bf) doesn't work as expected then. -fdfafb13d109379bba0f09ede850899a538d17878e1791fcb45a5ec0f661cc03 +7c365dbb621027ec8f5c9e1f0677ee6ed0599d2c5297ce78f88d05e160a1c9a4
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.