The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* 2.6.22-rc1-mm1 cifs_mount oops
@ 2007-05-23  0:50 young dave
  2007-05-23  2:22 ` Andrew Morton
  0 siblings, 1 reply; 13+ messages in thread
From: young dave @ 2007-05-23  0:50 UTC (permalink / raw)
  To: Linux Kernel Mailing List

Hi,
when I use mount -t cifs , the kernel oops, seems break at
kthread_stop, I'm not sure.

But if I add the CONFIG_CIFS_DEBUG2=y to config file, rebuild kernel,
then the oops disappeared.

Below is the oops message:

BUG: unable to handle kernel NULL pointer dereference at virtual
address 00000008
 printing eip:
c012e910
*pde = 00000000
Oops: 0002 [#1]
PREEMPT
Modules linked in: cifs smbfs radeon drm ipv6 snd_seq_dummy
snd_seq_oss snd_seq_midi_event snd_seq snd_seq_device snd_pcm_oss
snd_mixer_oss capability commoncap e100 mii psmouse sg evdev serio_raw
snd_hda_intel snd_pcm snd_timer snd soundcore snd_page_alloc intel_agp
agpgart i2c_i801 pcspkr
CPU:    0
EIP:    0060:[<c012e910>]    Not tainted VLI
EFLAGS: 00210246   (2.6.22-rc1-mm1 #3)
EIP is at kthread_stop+0x10/0x90
eax: c051bde0   ebx: 00000000   ecx: c1fba000   edx: c1fef040
esi: 00000000   edi: 00000064   ebp: c2a36c80   esp: c1fbbd58
ds: 007b   es: 007b   fs: 0000  gs: 0033  ss: 0068
Process mount.cifs (pid: 3955, ti=c1fba000 task=c2b38540 task.ti=c1fba000)
Stack: c1fef040 ffffff90 ffffff90 f8a7a328 c285a504 f8a9a9fb 00000083 000000cf
       000000dc 0000000b c2b38540 c2af5740 c292c540 00000000 00000000 c285a4c0
       00000000 c411b400 c3a4f500 c3cec200 c1fef052 c291c1e0 c1fef037 c291c940
Call Trace:
 [<f8a7a328>] cifs_mount+0xbe8/0xf10 [cifs]
 [<c02633fe>] idr_get_new_above_int+0x3e/0x50
 [<f8a6d04e>] cifs_read_super+0x4e/0x160 [cifs]
 [<c0166fc0>] set_anon_super+0x0/0xd0
 [<f8a6d6c0>] cifs_get_sb+0x60/0xd0 [cifs]
 [<c0167491>] vfs_kern_mount+0x91/0x130
 [<c017d648>] permit_mount+0x28/0xa0
 [<c017e09a>] do_new_mount+0x8a/0x140
 [<c017e95e>] do_mount+0x25e/0x280
 [<c0440000>] schedule+0x2e0/0x680
 [<c017e602>] exact_copy_from_user+0x32/0x70
 [<c017e69a>] copy_mount_options+0x5a/0xc0
 [<c017ec19>] sys_mount+0x79/0xc0
 [<c01040bc>] syscall_call+0x7/0xb
 =======================
Code: 88 d1 d3 e0 89 43 5c 83 c4 18 5b c3 eb 0d 90 90 90 90 90 90 90
90 90 90 90 90 90 53 83 ec 08 89 c3 b8 e0 bd 51 c0 e8 90 26 31 00 <ff>
43 08 31 c9 b8 f0 c1 58 c0 89 0d ec c1 58 c0 e8 3b 01 00 00
EIP: [<c012e910>] kthread_stop+0x10/0x90 SS:ESP 0068:c1fbbd58

Regards
dave

^ permalink raw reply	[flat|nested] 13+ messages in thread
* Re: 2.6.22-rc1-mm1 cifs_mount oops
@ 2007-05-23 14:59 Steve French
  0 siblings, 0 replies; 13+ messages in thread
From: Steve French @ 2007-05-23 14:59 UTC (permalink / raw)
  To: akpm, linux-kernel, shaggy, hi_dave.darkstar

This is what I now have in the cifs git tree.  (only minor change is
that I now have since fixed the missing space after the if)

diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c
index 216fb62..f6963d1 100644
--- a/fs/cifs/connect.c
+++ b/fs/cifs/connect.c
@@ -2069,8 +2069,15 @@ cifs_mount(struct super_block *sb, struct
cifs_sb_info *cifs_sb,
                        srvTcp->tcpStatus = CifsExiting;
                        spin_unlock(&GlobalMid_Lock);
                        if (srvTcp->tsk) {
+                               struct task_struct *tsk;
+                               /* If we could verify that kthread_stop would
+                                  always wake up processes blocked in
+                                  tcp in recv_mesg then we could remove the
+                                  send_sig call */
                                send_sig(SIGKILL,srvTcp->tsk,1);
-                               kthread_stop(srvTcp->tsk);
+                               tsk = srvTcp->tsk;
+                               if(tsk)
+                                       kthread_stop(srvTcp->tsk);
                        }
                }
                 /* If find_unc succeeded then rc == 0 so we can not end */
@@ -2085,8 +2092,11 @@ cifs_mount(struct super_block *sb, struct
cifs_sb_info *cifs_sb,
                                        /* if the socketUseCount is now zero */
                                        if ((temp_rc == -ESHUTDOWN) &&
                                           (pSesInfo->server) &&
(pSesInfo->server->tsk)) {
+                                               struct task_struct *tsk;

send_sig(SIGKILL,pSesInfo->server->tsk,1);
-
kthread_stop(pSesInfo->server->tsk);
+                                               tsk = pSesInfo->server->tsk;
+                                               if(tsk)
+                                                       kthread_stop(tsk);
                                        }
                                } else
                                        cFYI(1, ("No session or bad tcon"));


-- 
Thanks,

Steve

^ permalink raw reply related	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2007-05-24  2:38 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-05-23  0:50 2.6.22-rc1-mm1 cifs_mount oops young dave
2007-05-23  2:22 ` Andrew Morton
2007-05-23  2:59   ` young dave
2007-05-23  3:21     ` Andrew Morton
2007-05-23  7:16       ` young dave
2007-05-23  8:37       ` young dave
2007-05-23 13:28         ` Steven French
2007-05-23 16:10           ` Andrew Morton
2007-05-23 22:14             ` Steven French
2007-05-24  1:05               ` young dave
2007-05-24  2:38                 ` Steven French
2007-05-23 13:56   ` Steven French
  -- strict thread matches above, loose matches on Subject: below --
2007-05-23 14:59 Steve French

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox