qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Stefan Hajnoczi <stefanha@gmail.com>
To: Oleksii Shevchuk <alxchk@gmail.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>,
	qemu-devel Developers <qemu-devel@nongnu.org>
Subject: Re: [Qemu-devel] qemu git (f03d07d46) / e100 / sending large packets causes SIGABRT
Date: Mon, 29 Jul 2013 10:50:09 +0200	[thread overview]
Message-ID: <20130729085008.GE26410@stefanha-thinkpad.redhat.com> (raw)
In-Reply-To: <87zjtcw9c6.fsf@iit.kharkov.ua>

On Wed, Jul 24, 2013 at 01:17:29PM +0300, Oleksii Shevchuk wrote:
> 
> 1. qemu-kvm -sdl -nodefaults -name NP1-C1                           \
>   -uuid b71057e9-5705-420b-a780-52339afa6ed9                        \
>   -boot c                                                           \
>   -hda np1UD.disk                                                   \
>   -hdb fat:exchange                                                 \
>   -device i82559c,netdev=vin0,romfile="",mac="00:11:22:33:44:54"    \
>   -netdev tap,id=vin0,ifname=vin0,script=no                         \
>   -device cirrus-vga                                                \
>   -serial pty                                                       \
>   &
> 
> 2. ping -s 65000
> 
> 3. Program received signal SIGABRT, Aborted.

Here is an annotated backtrace:

> #7  tx_command (s=s@entry=0x7f9aac086820) at /tmp/portage/app-emulation/qemu-9999/work/qemu-9999/hw/net/eepro100.c:804
> #6  pci_dma_read (len=0x53f, buf=0x7f9a97ffe022, addr=0x86fa4000, dev=0x7f9aac086820) at /tmp/portage/app-emulation/qemu-9999/work/qemu-9999/include/hw/pci/pci.h:659

len=0x53f is an odd number: 1343

> #5  pci_dma_rw (dir=DMA_DIRECTION_TO_DEVICE, len=0x53f, buf=0x7f9a97ffe022, addr=0x86fa4000, dev=0x7f9aac086820) at /tmp/portage/app-emulation/qemu-9999/work/qemu-9999/include/hw/pci/pci.h:652
> #4  dma_memory_rw (dir=DMA_DIRECTION_TO_DEVICE, len=0x53f, buf=0x7f9a97ffe022, addr=0x86fa4000, as=0x7f9aac086a40) at /tmp/portage/app-emulation/qemu-9999/work/qemu-9999/include/sysemu/dma.h:112
> #3  0x00007f9aa96d6349 in dma_memory_rw_relaxed (dir=DMA_DIRECTION_TO_DEVICE, len=0x53f, buf=0x7f9a97ffe022, addr=0x86fa4000, as=0x7f9aac086a40) at /tmp/portage/app-emulation/qemu-9999/work/qemu-9999/include/sysemu/dma.h:90
> #2  0x00007f9aa97cb9ac in address_space_rw (as=as@entry=0x7f9aac086a40, addr=0x86fa453c, addr@entry=0x86fa4000, buf=0x7f9a97ffe55e "\327\060\061\061\272?32\330\061\062\062\276@43\331\062\063\063\302A54\332\063\064\064\306B65\333\064\065\065\312C76\334\065\066\066\316D87\335\066\067\067\322E98\336\067\070\070\326F:9\337\070\071\071\332G;:\340\071::\336H<;\341:;;\342I=<\342;<<\346J>=\343<==\352K?>\344=>>", '\377' <repeats 92 times>..., buf@entry=0x7f9a97ffe022 '\377' <repeats 200 times>..., len=0x3, len@entry=0x53f, is_write=is_write@entry=0x0) at /tmp/portage/app-emulation/qemu-9999/work/qemu-9999/exec.c:2005

There are only a few bytes remaining: len=0x3.  The abort(3) comes from address_space_rw():

if (!memory_access_is_direct(mr, is_write)) {
    /* I/O case */
    l = memory_access_size(mr, l, addr1);
    switch (l) {
    case 8:
        ...
    case 4:
        ...
    case 2:
        ...
    case 1:
        ...
    default:
        abort();  <-- we abort here
}

Paolo: Do you know how the memory API is supposed to work here?

Stefan

  reply	other threads:[~2013-07-29  8:50 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-07-24 10:17 [Qemu-devel] qemu git (f03d07d46) / e100 / sending large packets causes SIGABRT Oleksii Shevchuk
2013-07-29  8:50 ` Stefan Hajnoczi [this message]
2013-07-29 10:53   ` Paolo Bonzini
2013-07-29 11:40     ` Stefan Hajnoczi
2013-07-29 12:03       ` Oleksii Shevchuk

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20130729085008.GE26410@stefanha-thinkpad.redhat.com \
    --to=stefanha@gmail.com \
    --cc=alxchk@gmail.com \
    --cc=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).