public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* BUG UNIX: Poison overwritten with 2.6.31-rc6-00223-g6c30c53
@ 2009-08-27  8:45 Jike Song
  2009-09-08  2:23 ` Jike Song
  0 siblings, 1 reply; 8+ messages in thread
From: Jike Song @ 2009-08-27  8:45 UTC (permalink / raw)
  To: Linux Kernel Mailing List

hi, I hit this with vnc. Below is part of dmesg :



general protection fault: 0000 [#1] SMP
last sysfs file: /sys/devices/virtual/tty/tty9/uevent
CPU 1
Modules linked in: fuse ipv6 cpufreq_ondemand acpi_cpufreq freq_table
dm_multipath uinput snd_hda_codec_atihdmi snd_hda_codec_realtek radeon
snd_hda_intel btusb bluetooth snd_hda_codec snd_hwdep ttm drm snd_pcm
snd_timer usb_storage snd i2c_i801 i2c_algo_bit e1000e soundcore
pcspkr i2c_core firewire_ohci firewire_core crc_itu_t dcdbas serio_raw
snd_page_alloc joydev iTCO_wdt iTCO_vendor_support ata_generic
pata_acpi [last unloaded: microcode]
Pid: 2663, comm: gvfsd-trash Not tainted 2.6.31-rc6-00223-g6c30c53 #1
Studio XPS 435MT
RIP: 0010:[<ffffffff814f89fa>]  [<ffffffff814f89fa>] unix_write_space+0x52/0x9d
RSP: 0018:ffff88019b3a7c48  EFLAGS: 00010202
RAX: 6b6b6b6b6b6b6bab RBX: ffff88019150a080 RCX: ffffffff814f89d9
RDX: ffff8800323f0500 RSI: ffffffff814f89d9 RDI: 6b6b6b6b6b6b6b6b
RBP: ffff88019b3a7c68 R08: ffff88019b11abb0 R09: 0000000000000000
R10: ffffffff81dfb3f0 R11: 0000000000000000 R12: ffff88019150a3a8
R13: 0000000000000139 R14: ffff88018edc7401 R15: ffff880194842140
FS:  00007f65e4dbb790(0000) GS:ffff8800323df000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000f1a020 CR3: 000000019b038000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process gvfsd-trash (pid: 2663, threadinfo ffff88019b3a6000, task
ffff88019b11a3f0)
Stack:
 ffff88019b3a7c58 00000000a3909618 ffff88019150a080 00000000fffffec8
<0> ffff88019b3a7ca8 ffffffff8145bc76 ffff880191508190 00000000a3909618
<0> ffff88019b3a7cb8 ffff880194842140 0000000000000000 ffffffff814f8e4b
Call Trace:
 [<ffffffff8145bc76>] sock_wfree+0x55/0x86
 [<ffffffff814f8e4b>] ? unix_release_sock+0x1cd/0x23f
 [<ffffffff814601e0>] skb_release_head_state+0x89/0xfd
 [<ffffffff8145fea3>] __kfree_skb+0x25/0xa7
 [<ffffffff8145fff4>] kfree_skb+0x79/0x98
 [<ffffffff814f8e4b>] unix_release_sock+0x1cd/0x23f
 [<ffffffff814f8e43>] unix_release_sock+0x1c5/0x23f
 [<ffffffff814f8ef4>] unix_release+0x37/0x4d
 [<ffffffff814579f6>] sock_release+0x32/0x98
 [<ffffffff81457a94>] sock_close+0x38/0x50
 [<ffffffff8113c92b>] __fput+0x137/0x1f8
 [<ffffffff8113ca19>] fput+0x2d/0x43
 [<ffffffff81138c14>] filp_close+0x77/0x97
 [<ffffffff81138cf4>] sys_close+0xc0/0x110
 [<ffffffff81012f02>] system_call_fastpath+0x16/0x1b
Code: 31 c0 4c 89 e7 e8 99 77 03 00 8b 83 84 01 00 00 c1 e0 02 3b 83
8c 01 00 00 7f 37 48 8b bb 20 01 00 00 48 85 ff 74 19 48 8d 47 40 <48>
39 47 40 74 0f ba 01 00 00 00 be 01 00 00 00 e8 ab 81 b5 ff
RIP  [<ffffffff814f89fa>] unix_write_space+0x52/0x9d
 RSP <ffff88019b3a7c48>
---[ end trace 1fa193deb8611c3d ]---
=============================================================================
BUG UNIX: Poison overwritten
-----------------------------------------------------------------------------

INFO: 0xffff88019150a3a8-0xffff88019150a3e7. First byte 0x6a instead of 0x6b
INFO: Allocated in sk_prot_alloc+0x48/0x111 age=192 cpu=4 pid=3562
INFO: Freed in __sk_free+0xe8/0x119 age=191 cpu=4 pid=3562
INFO: Slab 0xffffea000a308b40 objects=19 used=6 fp=0xffff88019150a080
flags=0x400000000040c3
INFO: Object 0xffff88019150a080 @offset=8320 fp=0xffff88019150ad80

Bytes b4 0xffff88019150a070:  5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a
5a 5a 5a ZZZZZZZZZZZZZZZZ
  Object 0xffff88019150a080:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a090:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a0a0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a0b0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a0c0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a0d0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a0e0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a0f0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a100:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a110:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a120:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a130:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a140:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a150:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a160:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a170:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a180:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a190:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a1a0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a1b0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a1c0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a1d0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a1e0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a1f0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a200:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a210:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a220:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a230:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a240:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a250:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a260:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a270:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a280:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a290:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a2a0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a2b0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a2c0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a2d0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a2e0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a2f0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a300:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a310:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a320:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a330:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a340:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a350:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a360:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a370:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a380:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a390:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a3a0:  6b 6b 6b 6b 6b 6b 6b 6b 6a 6b 6b 6b 6b
6b 6b 6b kkkkkkkkjkkkkkkk
  Object 0xffff88019150a3b0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a3c0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a3d0:  6b 6b 6b 6b 6b 6b 6b 6b 01 00 00 00 6b
6b 6b 6b kkkkkkkk....kkkk
  Object 0xffff88019150a3e0:  d9 89 4f 81 ff ff ff ff 6b 6b 6b 6b 6b
6b 6b 6b Ù.O.ÿÿÿÿkkkkkkkk
  Object 0xffff88019150a3f0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a400:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a410:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a420:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a430:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a440:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a450:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a460:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a470:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a480:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a490:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a4a0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a4b0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a4c0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a4d0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a4e0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a4f0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a500:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a510:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a520:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a530:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a540:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a550:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a560:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a570:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a580:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a590:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a5a0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a5b0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a5c0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a5d0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a5e0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a5f0:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a600:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a610:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a620:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a630:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a640:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a650:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a660:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b 6b kkkkkkkkkkkkkkkk
  Object 0xffff88019150a670:  6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b
6b 6b a5 kkkkkkkkkkkkkkk¥
 Redzone 0xffff88019150a680:  bb bb bb bb bb bb bb bb
       »»»»»»»»
 Padding 0xffff88019150a6c0:  5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a
5a 5a 5a ZZZZZZZZZZZZZZZZ
 Padding 0xffff88019150a6d0:  5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a
5a 5a 5a ZZZZZZZZZZZZZZZZ
 Padding 0xffff88019150a6e0:  5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a
5a 5a 5a ZZZZZZZZZZZZZZZZ
 Padding 0xffff88019150a6f0:  5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a
5a 5a 5a ZZZZZZZZZZZZZZZZ
Pid: 3627, comm: gvfsd-trash Tainted: G      D    2.6.31-rc6-00223-g6c30c53 #1
Call Trace:
 [<ffffffff8112c651>] print_trailer+0x153/0x174
 [<ffffffff8112cc89>] check_bytes_and_report+0xc9/0x10e
 [<ffffffff8112cda7>] check_object+0xd9/0x1d3
 [<ffffffff8112f1d3>] __slab_alloc+0x332/0x3f0
 [<ffffffff8145c060>] ? sk_prot_alloc+0x48/0x111
 [<ffffffff8112f50d>] kmem_cache_alloc+0xcb/0x18a
 [<ffffffff8145c060>] ? sk_prot_alloc+0x48/0x111
 [<ffffffff8145c060>] sk_prot_alloc+0x48/0x111
 [<ffffffff811512f1>] ? new_inode+0x43/0x99
 [<ffffffff8145c22a>] sk_alloc+0x3d/0x88
 [<ffffffff814f92e8>] unix_create1+0x5e/0x1a3
 [<ffffffff814f94a5>] unix_create+0x78/0x97
 [<ffffffff81457c4d>] __sock_create+0x1a1/0x270
 [<ffffffff81457bb7>] ? __sock_create+0x10b/0x270
 [<ffffffff81457dac>] sock_create+0x43/0x59
 [<ffffffff8145802f>] sys_socket+0x3a/0x7f
 [<ffffffff81012f02>] system_call_fastpath+0x16/0x1b
FIX UNIX: Restoring 0xffff88019150a3a8-0xffff88019150a3e7=0x6b

FIX UNIX: Marking all objects used
general protection fault: 0000 [#2] SMP
last sysfs file: /sys/devices/virtual/tty/tty9/uevent
CPU 1
Modules linked in: fuse ipv6 cpufreq_ondemand acpi_cpufreq freq_table
dm_multipath uinput snd_hda_codec_atihdmi snd_hda_codec_realtek radeon
snd_hda_intel btusb bluetooth snd_hda_codec snd_hwdep ttm drm snd_pcm
snd_timer usb_storage snd i2c_i801 i2c_algo_bit e1000e soundcore
pcspkr i2c_core firewire_ohci firewire_core crc_itu_t dcdbas serio_raw
snd_page_alloc joydev iTCO_wdt iTCO_vendor_support ata_generic
pata_acpi [last unloaded: microcode]
Pid: 3627, comm: gvfsd-trash Tainted: G      D
2.6.31-rc6-00223-g6c30c53 #1 Studio XPS 435MT
RIP: 0010:[<ffffffff814f89fa>]  [<ffffffff814f89fa>] unix_write_space+0x52/0x9d
RSP: 0018:ffff88018c795c48  EFLAGS: 00010202
RAX: 6b6b6b6b6b6b6bab RBX: ffff8801854ece00 RCX: ffffffff814f89d9
RDX: 0000000000000000 RSI: ffff8801854ed140 RDI: 6b6b6b6b6b6b6b6b
RBP: ffff88018c795c68 R08: 0000000000000002 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8801854ed128
R13: 0000000000000139 R14: ffff88018ec18a01 R15: ffff8801a9896280
FS:  00007f3715d90790(0000) GS:ffff8800323df000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000001d0f0e8 CR3: 000000018c4af000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process gvfsd-trash (pid: 3627, threadinfo ffff88018c794000, task
ffff8801b4c20000)
Stack:
 ffff88018c795cb8 00000000e5f5a36f ffff8801854ece00 00000000fffffec8
<0> ffff88018c795ca8 ffffffff8145bc76 ffff88018c795cd8 00000000e5f5a36f
<0> ffff88018c795cb8 ffff8801a9896280 0000000000000000 ffffffff814f8e4b
Call Trace:
 [<ffffffff8145bc76>] sock_wfree+0x55/0x86
 [<ffffffff814f8e4b>] ? unix_release_sock+0x1cd/0x23f
 [<ffffffff814601e0>] skb_release_head_state+0x89/0xfd
 [<ffffffff8145fea3>] __kfree_skb+0x25/0xa7
 [<ffffffff8145fff4>] kfree_skb+0x79/0x98
 [<ffffffff814f8e4b>] unix_release_sock+0x1cd/0x23f
 [<ffffffff814f8e43>] unix_release_sock+0x1c5/0x23f
 [<ffffffff814f8ef4>] unix_release+0x37/0x4d
 [<ffffffff814579f6>] sock_release+0x32/0x98
 [<ffffffff81457a94>] sock_close+0x38/0x50
 [<ffffffff8113c92b>] __fput+0x137/0x1f8
 [<ffffffff81138c7a>] ? sys_close+0x46/0x110
 [<ffffffff8113ca19>] fput+0x2d/0x43
 [<ffffffff81138c14>] filp_close+0x77/0x97
 [<ffffffff81138cf4>] sys_close+0xc0/0x110
 [<ffffffff81012f02>] system_call_fastpath+0x16/0x1b
Code: 31 c0 4c 89 e7 e8 99 77 03 00 8b 83 84 01 00 00 c1 e0 02 3b 83
8c 01 00 00 7f 37 48 8b bb 20 01 00 00 48 85 ff 74 19 48 8d 47 40 <48>
39 47 40 74 0f ba 01 00 00 00 be 01 00 00 00 e8 ab 81 b5 ff
RIP  [<ffffffff814f89fa>] unix_write_space+0x52/0x9d
 RSP <ffff88018c795c48>
---[ end trace 1fa193deb8611c3e ]---

^ permalink raw reply	[flat|nested] 8+ messages in thread
* Re: BUG UNIX: Poison overwritten with 2.6.31-rc6-00223-g6c30c53
@ 2009-09-08  3:56 Parag Warudkar
  2009-09-08  4:51 ` Jike Song
  0 siblings, 1 reply; 8+ messages in thread
From: Parag Warudkar @ 2009-09-08  3:56 UTC (permalink / raw)
  To: albcamus; +Cc: linux-kernel


On Thu, Aug 27, 2009 at 4:45 PM, Jike Song<albcamus@gmail.com> wrote:
>> hi, I hit this with vnc. Below is part of dmesg :

> Still producible in 2.6.31-rc9, anybody helps?

How does one go about reproducing this? You said VNC triggers this but 
what VNC version, server or client? What distro and what needs to be done 
with VNC to trigger this problem? I ask since I use VNC myself and test -git kernels 
and have not encountered this issue.

Parag


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2009-09-08 12:12 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-27  8:45 BUG UNIX: Poison overwritten with 2.6.31-rc6-00223-g6c30c53 Jike Song
2009-09-08  2:23 ` Jike Song
2009-09-08  3:23   ` Eric Dumazet
  -- strict thread matches above, loose matches on Subject: below --
2009-09-08  3:56 Parag Warudkar
2009-09-08  4:51 ` Jike Song
2009-09-08  7:38   ` Eric Dumazet
2009-09-08  8:09     ` Jike Song
2009-09-08 12:12       ` Eric Dumazet

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox