Bug #1498

Panic when configure ath0 device

Added by ahuete.devel about 5 years ago. Updated 8 months ago.

Status:ClosedStart date:
Priority:NormalDue date:
Assignee:-% Done:

0%

Category:Driver
Target version:3.8.0

Description

Hi all,

---------------------------------------
Details
Acer Aspire One ZG5
Kernel: DragonFly v2.3.2.818.gb7feb-DEVELOPMENT (snapshot 7-september-09)
Filesystem: HAMMER
Memory: 1024 DDR2
Wireless chip:
ath0@pci0:3:0:0: class=0x020000 card=0xe008105b
chip=0x001c168c rev=0x01 hdr=0x00
vendor = 'Atheros Communications Inc.'
device = 'USB\VID_08FF&PID_1600\5&3AEE5BD7&0&3
HDAUDIO\FUNC_01&VEN_14F1&DEV_5051&SUBSYS_103C3608&REV_1000'
class = network
subclass = ethernet
---------------------------------------

If you want the kernel core, I can upload it to leaf.
Panic when configuring ath0 device. Just did this:

ifconfig ath0 ssid WLAN_0B
ifconfig ath0 channel 9
ifconfig ath0 bssid 00:02:cf:73:cb:80
ifconfig ath0 deftxkey 1
ifconfig ath0 authmode shared
ifconfig ath0 mode mixed
ifconfig ath0 wepkey XXXXXXXXXXXX
ifconfig ath0 up

Backtrace:
---
(kgdb) bt
#0 dumpsys () at ./machine/thread.h:83
#1 0xc03186c6 in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:375
#2 0xc03187e7 in panic (fmt=0xc0577270 "from debugger") at
/usr/src/sys/kern/kern_shutdown.c:802
#3 0xc016d11d in db_panic (addr=-1068362545, have_addr=0, count=1,
modif=0xcc611a44 "") at /usr/src/sys/ddb/db_command.c:448
#4 0xc016d792 in db_command_loop () at /usr/src/sys/ddb/db_command.c:344
#5 0xc016fd60 in db_trap (type=12, code=2) at /usr/src/sys/ddb/db_trap.c:71
#6 0xc0512808 in kdb_trap (type=12, code=2, regs=0xcc611b8c) at
/usr/src/sys/platform/pc32/i386/db_interface.c:152
#7 0xc0522ae8 in trap_fatal (frame=0xcc611b8c, eva=<value optimized
out>) at /usr/src/sys/platform/pc32/i386/trap.c:1088
#8 0xc0522c78 in trap_pfault (frame=0xcc611b8c, usermode=0, eva=28)
at /usr/src/sys/platform/pc32/i386/trap.c:994
#9 0xc052350c in trap (frame=0xcc611b8c) at
/usr/src/sys/platform/pc32/i386/trap.c:674
#10 0xc0513547 in calltrap () at /usr/src/sys/platform/pc32/i386/exception.s:785
#11 0xc05214cf in asm_generic_bcopy () at
/usr/src/sys/platform/pc32/i386/bcopy.s:169
#12 0xc2a8f500 in ?? ()
#13 0xc03d0cbc in ip6_output (m0=0xc2a92200, opt=0xc06b7640, ro=0x0,
flags=0, im6o=0xcc611d24, ifpp=0xcc611d20, inp=0x0)
at /usr/src/sys/netinet6/ip6_output.c:197
#14 0xc03d81b5 in mld6_sendpkt (in6m=0xc2883ff0, type=<value optimized
out>, dst=0x0) at /usr/src/sys/netinet6/mld6.c:452
#15 0xc03d873b in mld6_fasttimeo () at /usr/src/sys/netinet6/mld6.c:362
#16 0xc03c4928 in icmp6_fasttimo () at /usr/src/sys/netinet6/icmp6.c:2108
#17 0xc0346563 in pffasttimo (arg=0x0) at /usr/src/sys/kern/uipc_domain.c:261
#18 0xc0328cce in softclock_handler (arg=0xc068d260) at
/usr/src/sys/kern/kern_timeout.c:305
#19 0xc032028c in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /usr/src/sys/kern/lwkt_thread.c:269
Backtrace stopped: previous frame inner to this frame (corrupt stack?)

History

#1 Updated by tuxillo about 5 years ago

ath_hal: 081128
ath0: <Atheros 5424/2424> mem 0x55200000-0x5520ffff irq 11 at device 0.0 on pci3
boundary check failed
alignment check failed
alignment check failed
ath0: MAC address: XX:24:XX:0e:XX:e4
ath0: mac 14.2 phy 7.0 radio 10.2

#2 Updated by corecode about 5 years ago

Antonio Huete Jimenez wrote:
> #10 0xc0513547 in calltrap () at /usr/src/sys/platform/pc32/i386/exception.s:785
> #11 0xc05214cf in asm_generic_bcopy () at
> /usr/src/sys/platform/pc32/i386/bcopy.s:169
> #12 0xc2a8f500 in ?? ()
> #13 0xc03d0cbc in ip6_output (m0=0xc2a92200, opt=0xc06b7640, ro=0x0,

Can you post this part of the backtrace? You'll have to load the
modules into kgdb to get a proper backtrace. Use "source
/usr/src/test/debug/gdb.kernel" in gdb, run "kldstat" in gdb and paste
the output into the "asf" tool. then run "source .asf".

cheers
simon

#3 Updated by tuxillo about 5 years ago

Hi,

I suspect the cause of the panics is going to be hard to find. I've tried to
reproduce the issue a couple of times, each time with a different backtrace. See
below:

(kgdb) bt
#0 dumpsys () at ./machine/thread.h:83
#1 0xc031dace in boot (howto=260) at
/home/source/dfbsd/sys/kern/kern_shutdown.c:378
#2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
/home/source/dfbsd/sys/kern/kern_shutdown.c:813
#3 0xc0171d39 in db_panic (addr=-1069681161, have_addr=0, count=-1,
modif=0xc13fcb7c "")
at /home/source/dfbsd/sys/ddb/db_command.c:448
#4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
#5 0xc017497c in db_trap (type=12, code=2) at
/home/source/dfbsd/sys/ddb/db_trap.c:71
#6 0xc051e078 in kdb_trap (type=12, code=2, regs=0xc13fccc4)
at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
#7 0xc052e578 in trap_fatal (frame=0xc13fccc4, eva=<value optimized out>)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
#8 0xc052e708 in trap_pfault (frame=0xc13fccc4, usermode=0, eva=24)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
#9 0xc052ef9c in trap (frame=0xc13fccc4) at
/home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
#10 0xc051edb7 in calltrap () at
/home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
#11 0xc03df5f7 in mld6_sendpkt (in6m=0xc14a4140, type=131, dst=0x0) at
/home/source/dfbsd/sys/netinet6/mld6.c:425
#12 0xc03dfc1b in mld6_fasttimeo () at /home/source/dfbsd/sys/netinet6/mld6.c:362
#13 0xc03cbe08 in icmp6_fasttimo () at /home/source/dfbsd/sys/netinet6/icmp6.c:2108
#14 0xc034d5d7 in pffasttimo (arg=0x0) at
/home/source/dfbsd/sys/kern/uipc_domain.c:261
#15 0xc032e4f6 in softclock_handler (arg=0xc0697fc0) at
/home/source/dfbsd/sys/kern/kern_timeout.c:305
#16 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271

----------------------

#0 dumpsys () at ./machine/thread.h:83
#1 0xc031dace in boot (howto=260) at
/home/source/dfbsd/sys/kern/kern_shutdown.c:378
#2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
/home/source/dfbsd/sys/kern/kern_shutdown.c:813
#3 0xc0171d39 in db_panic (addr=-1069923399, have_addr=0, count=-1,
modif=0xc9cb4af8 "")
at /home/source/dfbsd/sys/ddb/db_command.c:448
#4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
#5 0xc017497c in db_trap (type=12, code=0) at
/home/source/dfbsd/sys/ddb/db_trap.c:71
#6 0xc051e078 in kdb_trap (type=12, code=0, regs=0xc9cb4c40)
at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
#7 0xc052e578 in trap_fatal (frame=0xc9cb4c40, eva=<value optimized out>)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
#8 0xc052e708 in trap_pfault (frame=0xc9cb4c40, usermode=0, eva=2048)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
#9 0xc052ef9c in trap (frame=0xc9cb4c40) at
/home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
#10 0xc051edb7 in calltrap () at
/home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
#11 0xc03a43b9 in ieee80211_find_rxnode_withkey (ic=0xc9e0f0b8, wh=0x800,
keyix=65535)
at /home/source/dfbsd/sys/netproto/802_11/wlan/ieee80211_node.c:1418
#12 0xcd00c701 in ?? ()
#13 0xc03281bf in lwkt_serialize_handler_call (s=0xcd07f000, func=0xcd00c220,
arg=0xc9e0f0b8, frame=0x0)
at /home/source/dfbsd/sys/kern/lwkt_serialize.c:228
#14 0xc02fed5a in ithread_handler (arg=0xb) at
/home/source/dfbsd/sys/kern/kern_intr.c:804
#15 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271
Backtrace stopped: previous frame inner to this frame (corrupt stack?)

Let me know if you need the core files.

Cheers,
Antonio Huete

#4 Updated by sepherosa about 5 years ago

On Fri, Oct 16, 2009 at 6:22 AM, Antonio Huete Jimenez (via DragonFly
issue tracker) <> wrote:
>
> Antonio Huete Jimenez <> added the comment:
>
> Hi,
>
> I suspect the cause of the panics is going to be hard to find. I've tried to
> reproduce the issue a couple of times, each time with a different backtrace. See
> below:

If possible, please throw the core dumps onto leaf. Thanks

>
> (kgdb) bt
> #0 dumpsys () at ./machine/thread.h:83
> #1 0xc031dace in boot (howto=260) at
> /home/source/dfbsd/sys/kern/kern_shutdown.c:378
> #2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
> /home/source/dfbsd/sys/kern/kern_shutdown.c:813
> #3 0xc0171d39 in db_panic (addr=-1069681161, have_addr=0, count=-1,
> modif=0xc13fcb7c "")
> at /home/source/dfbsd/sys/ddb/db_command.c:448
> #4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
> #5 0xc017497c in db_trap (type=12, code=2) at
> /home/source/dfbsd/sys/ddb/db_trap.c:71
> #6 0xc051e078 in kdb_trap (type=12, code=2, regs=0xc13fccc4)
> at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
> #7 0xc052e578 in trap_fatal (frame=0xc13fccc4, eva=<value optimized out>)
> at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
> #8 0xc052e708 in trap_pfault (frame=0xc13fccc4, usermode=0, eva=24)
> at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
> #9 0xc052ef9c in trap (frame=0xc13fccc4) at
> /home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
> #10 0xc051edb7 in calltrap () at
> /home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
> #11 0xc03df5f7 in mld6_sendpkt (in6m=0xc14a4140, type=131, dst=0x0) at
> /home/source/dfbsd/sys/netinet6/mld6.c:425
> #12 0xc03dfc1b in mld6_fasttimeo () at /home/source/dfbsd/sys/netinet6/mld6.c:362
> #13 0xc03cbe08 in icmp6_fasttimo () at /home/source/dfbsd/sys/netinet6/icmp6.c:2108
> #14 0xc034d5d7 in pffasttimo (arg=0x0) at
> /home/source/dfbsd/sys/kern/uipc_domain.c:261
> #15 0xc032e4f6 in softclock_handler (arg=0xc0697fc0) at
> /home/source/dfbsd/sys/kern/kern_timeout.c:305
> #16 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
> ) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271
>
> ----------------------
>
> #0 dumpsys () at ./machine/thread.h:83
> #1 0xc031dace in boot (howto=260) at
> /home/source/dfbsd/sys/kern/kern_shutdown.c:378
> #2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
> /home/source/dfbsd/sys/kern/kern_shutdown.c:813
> #3 0xc0171d39 in db_panic (addr=-1069923399, have_addr=0, count=-1,
> modif=0xc9cb4af8 "")
> at /home/source/dfbsd/sys/ddb/db_command.c:448
> #4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
> #5 0xc017497c in db_trap (type=12, code=0) at
> /home/source/dfbsd/sys/ddb/db_trap.c:71
> #6 0xc051e078 in kdb_trap (type=12, code=0, regs=0xc9cb4c40)
> at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
> #7 0xc052e578 in trap_fatal (frame=0xc9cb4c40, eva=<value optimized out>)
> at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
> #8 0xc052e708 in trap_pfault (frame=0xc9cb4c40, usermode=0, eva=2048)
> at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
> #9 0xc052ef9c in trap (frame=0xc9cb4c40) at
> /home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
> #10 0xc051edb7 in calltrap () at
> /home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
> #11 0xc03a43b9 in ieee80211_find_rxnode_withkey (ic=0xc9e0f0b8, wh=0x800,
> keyix=65535)
> at /home/source/dfbsd/sys/netproto/802_11/wlan/ieee80211_node.c:1418
> #12 0xcd00c701 in ?? ()
> #13 0xc03281bf in lwkt_serialize_handler_call (s=0xcd07f000, func=0xcd00c220,
> arg=0xc9e0f0b8, frame=0x0)
> at /home/source/dfbsd/sys/kern/lwkt_serialize.c:228
> #14 0xc02fed5a in ithread_handler (arg=0xb) at
> /home/source/dfbsd/sys/kern/kern_intr.c:804
> #15 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
> ) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271
> Backtrace stopped: previous frame inner to this frame (corrupt stack?)
>
> Let me know if you need the core files.
>
> Cheers,
> Antonio Huete
>
> _____________________________________________________
> DragonFly issue tracker <>
> <http://bugs.dragonflybsd.org/issue1498>
> _____________________________________________________
>

#5 Updated by tuxillo about 5 years ago

Sephe,

Here you are. They are coredumps for the last two panics I've pasted.
http://leaf.dragonflybsd.org/~tuxillo/bugs/1498/

Path on leaf is 777, so you can write if you need:
/home/tuxillo/public_html/bugs/1498

Cheers,
Antonio

#6 Updated by tuxillo 8 months ago

  • Description updated (diff)
  • Category set to Driver
  • Status changed from New to Closed
  • Assignee deleted (0)
  • Target version set to 3.8.0

Hi,

This problem is no longer relevant.

Cheers,
Antonio Huete

Also available in: Atom PDF