From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Larry W. Finger" Subject: Kernel oops in 2.6.1 when loading aha152x_cs.ko Date: Fri, 09 Jan 2004 13:14:52 -0700 Sender: linux-scsi-owner@vger.kernel.org Message-ID: <6.0.0.22.0.20040109124348.01b86068@pop-server.kc.rr.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed Return-path: Received: from mtiwmhc11.worldnet.att.net ([204.127.131.115]:3755 "EHLO mtiwmhc11.worldnet.att.net") by vger.kernel.org with ESMTP id S264256AbUAIUQm (ORCPT ); Fri, 9 Jan 2004 15:16:42 -0500 List-Id: linux-scsi@vger.kernel.org To: linux-scsi@vger.kernel.org Cc: linux-kernel@vger.kernel.org When loading module aha152x_cs with kernel 2.6.1 and cardmgr 3.2.5, I get a kernel oops. This problem has existed at least since 2.5.63, which is when I started trying the new version. I am reporting this problem now because since 2.6.0-rc1, the driver now works except for this problem. What I believe to be the pertinent sections of the output of dmesg are listed below: =================================================================== Linux version 2.6.1 (root@lwflap) (gcc version 3.3.1) #1 Fri Jan 9 09:56:28 MST 2004 ...snip... Linux Kernel Card Services options: [pci] [cardbus] [pm] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 11 ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11 ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 10 ..snip.. Yenta: CardBus bridge found at 0000:00:0a.0 [103c:0022] Yenta: ISA IRQ mask 0x00b8, PCI irq 11 Socket status: 30000007 ..snip.. cs: IO port probe 0x0100-0x04ff: excluding 0x2c8-0x2cf 0x378-0x37f 0x3c0-0x3df 0x4d0-0x4d7 cs: IO port probe 0x0800-0x08ff: clean. cs: IO port probe 0x0c00-0x0cff: clean. cs: memory probe 0x60000000-0x60ffffff: clean. Unable to handle kernel NULL pointer dereference at virtual address 00000000 printing eip: c02b5f60 *pde = 00000000 Oops: 0002 [#1] CPU: 0 EIP: 0060:[] Not tainted EFLAGS: 00010282 EIP is at scsi_register+0x40/0x70 eax: c7bf1a10 ebx: c7bf17f8 ecx: 00000000 edx: cf986cf4 esi: cf986c80 edi: c8a2fa24 ebp: c8a2f7b0 esp: c8a2f7a0 ds: 007b es: 007b ss: 0068 Process cardmgr (pid: 1088, threadinfo=c8a2e000 task=ca31d960) Stack: cf986c80 00000350 00000000 c8a2f9fc c8a2f7fc cf97ca30 cf986c80 00000350 c73ab180 c8a2f7fc 00000282 cefef080 c73abe90 0000006b c8a2f7fc 073abe90 cf97c42e c73abe90 cefe5ef8 00000282 00000000 c8a2f9fc c8a2fa24 c8a2fa38 Call Trace: [] aha152x_probe_one+0x20/0x460 [aha152x_cs] [] aha152x_config_cs+0x25e/0x360 [aha152x_cs] [] aha152x_config_cs+0x2bc/0x360 [aha152x_cs] [] scheduler_tick+0x2d0/0x5b0 [] mark_offset_tsc+0x3ad/0x560 [] update_process_times+0x46/0x50 [] update_wall_time+0xd/0x40 [] run_timer_softirq+0x303/0x430 [] apic_timer_interrupt+0x1a/0x20 [] yenta_set_mem_map+0x1f2/0x250 [] exca_writew+0x63/0x80 [] yenta_set_mem_map+0x1f2/0x250 [] exca_writew+0x63/0x80 [] socket_detect_change+0x32/0x80 [] check_poison_obj+0x29/0x1a0 [] set_cis_map+0x3e/0x110 [] check_poison_obj+0x29/0x1a0 [] unblank_screen+0xfb/0x100 [] aha152x_event+0x6d/0x140 [aha152x_cs] [] __delay+0x14/0x20 [] __ide_dma_begin+0x37/0x50 [] __ide_dma_count+0x15/0x20 [] __ide_dma_read+0xc5/0xd0 [] ide_dma_intr+0x0/0xb0 [] dma_timer_expiry+0x0/0x80 [] do_rw_taskfile+0x1bb/0x2b0 [] kernel_map_pages+0x28/0x90 [] pcmcia_get_first_tuple+0x92/0x130 [] read_tuple+0x98/0xb0 [] check_poison_obj+0x29/0x1a0 [] pcmcia_register_client+0x1c6/0x2b0 [] __kmalloc+0x19c/0x250 [] pcmcia_register_client+0x254/0x2b0 [] aha152x_attach+0x20/0x140 [aha152x_cs] [] kernel_map_pages+0x28/0x90 [] CardServices+0x19a/0x346 [] kmem_cache_alloc+0x170/0x220 [] aha152x_attach+0xf4/0x140 [aha152x_cs] [] aha152x_event+0x0/0x140 [aha152x_cs] [] kmem_cache_alloc+0x170/0x220 [] bind_request+0x114/0x240 [] pcmcia_get_socket_by_nr+0x24/0xb0 [] ds_ioctl+0x539/0x680 [] buffered_rmqueue+0xd2/0x270 [] __alloc_pages+0x31e/0x380 [] kernel_map_pages+0x28/0x90 [] __mmdrop+0x36/0x45 [] __mmdrop+0x36/0x45 [] kernel_map_pages+0x28/0x90 [] zap_pmd_range+0x4e/0x70 [] unmap_page_range+0x41/0x70 [] unmap_vmas+0xf0/0x330 [] unmap_vma_list+0x1f/0x30 [] unmap_vma_list+0x1f/0x30 [] do_munmap+0x1d0/0x290 [] sys_ioctl+0x205/0x3f0 [] syscall_call+0x7/0xb Code: 89 01 89 48 04 89 d8 8b 75 fc 8b 5d f8 c9 c3 8b 46 04 c7 04 =================================================================== My kernel debugging skills are minimal; however, I tracked this error to drivers/scsi/hosts.c where a call is made to list_add_tail with the sht->legacy_hosts list_head == NULL. The problem is fixed by the patch that follows. I am aware that this patch fixes the symptom rather than the cause and this driver should never hit this code. However, the current version uses scsi_register rather than scsi_host_alloc and has a problem. In defense of the patch, (1) the driver works with it installed, and (2) the modified code is only invoked when this particular case occurs. =================================================================== --- a/drivers/scsi/hosts.c.orig 2004-01-08 09:13:39.374648400 -0700 +++ linux-2.6.1/drivers/scsi/hosts.c 2004-01-08 09:13:45.958647480 -0700 @@ -300,8 +300,13 @@ dump_stack(); } - if (shost) + if (shost) { + if (sht->legacy_hosts.next == NULL) { + printk(KERN_INFO "sht->legacy_hosts list_head is NULL!\n"); + INIT_LIST_HEAD(&sht->legacy_hosts); + } list_add_tail(&shost->sht_legacy_list, &sht->legacy_hosts); + } return shost; } =================================================================== Larry Finger