* crash with bcm43xx_dscape and multiple interfaces
@ 2006-08-11 7:53 Johannes Berg
0 siblings, 0 replies; only message in thread
From: Johannes Berg @ 2006-08-11 7:53 UTC (permalink / raw)
To: mbuesch, netdev, bcm43xx-dev
Hey,
I managed to crash it again :P
Here's approximately what I did:
johannes:/home/johannes# ifconfig wlan0 down
johannes:/home/johannes# cd /sys/class/ieee80211/phy0/
johannes:/sys/class/ieee80211/phy0# echo -n moni0 > add_iface
johannes:/sys/class/ieee80211/phy0# iwconfig wlan0 mode master
johannes:/sys/class/ieee80211/phy0# iwconfig wlan0 essid test
johannes:/sys/class/ieee80211/phy0# ifconfig moni0 down
johannes:/sys/class/ieee80211/phy0# iwconfig moni0 mode monitor
johannes:/sys/class/ieee80211/phy0# ifconfig wlan0 up
johannes:/sys/class/ieee80211/phy0# ifconfig moni0 up
Segmentation fault
bcm43xx_d80211: ASSERTION FAILED (bcm->cached_beacon) at: drivers/net/wireless/d80211/bcm43xx/bcm43xx_main.c:1754:bcm43xx_update_templates()
bcm43xx_d80211: ASSERTION FAILED (bcm->cached_beacon) at: drivers/net/wireless/d80211/bcm43xx/bcm43xx_main.c:1603:bcm43xx_write_beacon_template()
Unable to handle kernel paging request for data at address 0x00000060
Faulting instruction address: 0xf24cf308
Oops: Kernel access of bad area, sig: 11 [#1]
Aug 10 20:55:18 johannes kernel: [ 1095.326784]
Modules linked in: af_packet radeon drm binfmt_misc hci_usb rfcomm l2cap bluetooth nls_utf8 hfsplus nls_base joydev appletouch usbhid snd_aoa_codec_tas snd_aoa_fabric_layout snd_aoa arc4 rate_control evdev bcm43xx_d80211 firmware_class snd_aoa_i2sbus snd_pcm snd_timer snd_page_alloc snd uninorth_agp ohci1394 ieee1394 agpgart soundcore snd_aoa_soundbus yenta_socket rsrc_nonstatic pcmcia_core ohci_hcd ehci_hcd usbcore 80211 unix
NIP: F24CF308 LR: F24CF348 CTR: C01BACA4
REGS: c1e83c70 TRAP: 0300 Not tainted (2.6.18-rc4)
MSR: 00001032 <ME,IR,DR> CR: 24008422 XER: 00000000
DAR: 00000060, DSISR: 40000000
TASK = e8b88070[3419] 'ifconfig' THREAD: c1e82000
GPR00: F24CF348 C1E83D20 E8B88070 000000A4 0000A2E8 FFFFFFFF C0560000 00200000
GPR08: 00000033 00000000 00200000 C0510000 44008488 10018A14 28004422 00000000
GPR16: 1023D638 100D0000 100B0000 100D0000 10010474 E5A48000 C1E83E58 FFFF8914
GPR24: E5A48280 EFEC2400 00000004 00000000 00000068 00000002 00000018 EFEC2400
NIP [F24CF308] bcm43xx_write_beacon_template+0x50/0x98 [bcm43xx_d80211]
LR [F24CF348] bcm43xx_write_beacon_template+0x90/0x98 [bcm43xx_d80211]
Call Trace:
[C1E83D20] [F24CF348] bcm43xx_write_beacon_template+0x90/0x98 [bcm43xx_d80211] (unreliable)
[C1E83D40] [F24CFE44] bcm43xx_refresh_templates+0x48/0x268 [bcm43xx_d80211]
[C1E83D70] [F24D24AC] bcm43xx_add_interface+0xe4/0x118 [bcm43xx_d80211]
[C1E83DA0] [F20BDFD4] ieee80211_open+0x120/0x398 [80211]
[C1E83DF0] [C021E8C8] dev_open+0x78/0xcc
[C1E83E10] [C021C7E0] dev_change_flags+0x13c/0x168
[C1E83E30] [C0261C80] devinet_ioctl+0x5bc/0x71c
[C1E83EA0] [C02623F8] inet_ioctl+0xb0/0xdc
[C1E83EB0] [C0210810] sock_ioctl+0x160/0x28c
[C1E83ED0] [C0096604] do_ioctl+0x38/0x84
[C1E83EE0] [C00966D4] vfs_ioctl+0x84/0x43c
[C1E83F10] [C0096ACC] sys_ioctl+0x40/0x74
[C1E83F40] [C0010C88] ret_from_syscall+0x0/0x38
--- Exception: c01 at 0xff62780
LR = 0xffecf54
Instruction dump:
3c80f24f 7cbe2b78 3ca0f24f 7cdd3378 3884c650 38a5c3f8 812304f8 3c60f24f
38c00643 3863c3b8 2f890000 419e0040 <80a90060> 7fe3fb78 7f86e378 7fc7f378
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2006-08-11 7:53 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-08-11 7:53 crash with bcm43xx_dscape and multiple interfaces Johannes Berg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).