Project

General

Profile

Actions

Bug #1498

closed

Panic when configure ath0 device

Added by ahuete.devel about 15 years ago. Updated almost 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Driver
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:

Description

Hi all,

---------------------------------------
Details
Acer Aspire One ZG5
Kernel: DragonFly v2.3.2.818.gb7feb-DEVELOPMENT (snapshot 7-september-09)
Filesystem: HAMMER
Memory: 1024 DDR2
Wireless chip:
ath0@pci0:3:0:0: class=0x020000 card=0xe008105b
chip=0x001c168c rev=0x01 hdr=0x00
vendor = 'Atheros Communications Inc.'
device = 'USB\VID_08FF&PID_1600\5&3AEE5BD7&0&3
HDAUDIO\FUNC_01&VEN_14F1&DEV_5051&SUBSYS_103C3608&REV_1000'
class = network
subclass = ethernet
---------------------------------------

If you want the kernel core, I can upload it to leaf.
Panic when configuring ath0 device. Just did this:

ifconfig ath0 ssid WLAN_0B
ifconfig ath0 channel 9
ifconfig ath0 bssid 00:02:cf:73:cb:80
ifconfig ath0 deftxkey 1
ifconfig ath0 authmode shared
ifconfig ath0 mode mixed
ifconfig ath0 wepkey XXXXXXXXXXXX
ifconfig ath0 up

Backtrace:
---
(kgdb) bt
#0 dumpsys () at ./machine/thread.h:83
#1 0xc03186c6 in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:375
#2 0xc03187e7 in panic (fmt=0xc0577270 "from debugger") at
/usr/src/sys/kern/kern_shutdown.c:802
#3 0xc016d11d in db_panic (addr=-1068362545, have_addr=0, count=1,
modif=0xcc611a44 "") at /usr/src/sys/ddb/db_command.c:448
#4 0xc016d792 in db_command_loop () at /usr/src/sys/ddb/db_command.c:344
#5 0xc016fd60 in db_trap (type=12, code=2) at /usr/src/sys/ddb/db_trap.c:71
#6 0xc0512808 in kdb_trap (type=12, code=2, regs=0xcc611b8c) at
/usr/src/sys/platform/pc32/i386/db_interface.c:152
#7 0xc0522ae8 in trap_fatal (frame=0xcc611b8c, eva=<value optimized
out>) at /usr/src/sys/platform/pc32/i386/trap.c:1088
#8 0xc0522c78 in trap_pfault (frame=0xcc611b8c, usermode=0, eva=28)
at /usr/src/sys/platform/pc32/i386/trap.c:994
#9 0xc052350c in trap (frame=0xcc611b8c) at
/usr/src/sys/platform/pc32/i386/trap.c:674
#10 0xc0513547 in calltrap () at /usr/src/sys/platform/pc32/i386/exception.s:785
#11 0xc05214cf in asm_generic_bcopy () at
/usr/src/sys/platform/pc32/i386/bcopy.s:169
#12 0xc2a8f500 in ?? ()
#13 0xc03d0cbc in ip6_output (m0=0xc2a92200, opt=0xc06b7640, ro=0x0,
flags=0, im6o=0xcc611d24, ifpp=0xcc611d20, inp=0x0)
at /usr/src/sys/netinet6/ip6_output.c:197
#14 0xc03d81b5 in mld6_sendpkt (in6m=0xc2883ff0, type=<value optimized
out>, dst=0x0) at /usr/src/sys/netinet6/mld6.c:452
#15 0xc03d873b in mld6_fasttimeo () at /usr/src/sys/netinet6/mld6.c:362
#16 0xc03c4928 in icmp6_fasttimo () at /usr/src/sys/netinet6/icmp6.c:2108
#17 0xc0346563 in pffasttimo (arg=0x0) at /usr/src/sys/kern/uipc_domain.c:261
#18 0xc0328cce in softclock_handler (arg=0xc068d260) at
/usr/src/sys/kern/kern_timeout.c:305
#19 0xc032028c in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /usr/src/sys/kern/lwkt_thread.c:269
Backtrace stopped: previous frame inner to this frame (corrupt stack?)

Actions #1

Updated by tuxillo about 15 years ago

ath_hal: 081128
ath0: <Atheros 5424/2424> mem 0x55200000-0x5520ffff irq 11 at device 0.0 on pci3
boundary check failed
alignment check failed
alignment check failed
ath0: MAC address: XX:24:XX:0e:XX:e4
ath0: mac 14.2 phy 7.0 radio 10.2

Actions #2

Updated by corecode about 15 years ago

Antonio Huete Jimenez wrote:

#10 0xc0513547 in calltrap () at /usr/src/sys/platform/pc32/i386/exception.s:785
#11 0xc05214cf in asm_generic_bcopy () at
/usr/src/sys/platform/pc32/i386/bcopy.s:169
#12 0xc2a8f500 in ?? ()
#13 0xc03d0cbc in ip6_output (m0=0xc2a92200, opt=0xc06b7640, ro=0x0,

Can you post this part of the backtrace? You'll have to load the
modules into kgdb to get a proper backtrace. Use "source
/usr/src/test/debug/gdb.kernel" in gdb, run "kldstat" in gdb and paste
the output into the "asf" tool. then run "source .asf".

cheers
simon

Actions #3

Updated by tuxillo about 15 years ago

Hi,

I suspect the cause of the panics is going to be hard to find. I've tried to
reproduce the issue a couple of times, each time with a different backtrace. See
below:

(kgdb) bt
#0 dumpsys () at ./machine/thread.h:83
#1 0xc031dace in boot (howto=260) at
/home/source/dfbsd/sys/kern/kern_shutdown.c:378
#2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
/home/source/dfbsd/sys/kern/kern_shutdown.c:813
#3 0xc0171d39 in db_panic (addr=-1069681161, have_addr=0, count=-1,
modif=0xc13fcb7c "")
at /home/source/dfbsd/sys/ddb/db_command.c:448
#4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
#5 0xc017497c in db_trap (type=12, code=2) at
/home/source/dfbsd/sys/ddb/db_trap.c:71
#6 0xc051e078 in kdb_trap (type=12, code=2, regs=0xc13fccc4)
at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
#7 0xc052e578 in trap_fatal (frame=0xc13fccc4, eva=<value optimized out>)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
#8 0xc052e708 in trap_pfault (frame=0xc13fccc4, usermode=0, eva=24)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
#9 0xc052ef9c in trap (frame=0xc13fccc4) at
/home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
#10 0xc051edb7 in calltrap () at
/home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
#11 0xc03df5f7 in mld6_sendpkt (in6m=0xc14a4140, type=131, dst=0x0) at
/home/source/dfbsd/sys/netinet6/mld6.c:425
#12 0xc03dfc1b in mld6_fasttimeo () at /home/source/dfbsd/sys/netinet6/mld6.c:362
#13 0xc03cbe08 in icmp6_fasttimo () at /home/source/dfbsd/sys/netinet6/icmp6.c:2108
#14 0xc034d5d7 in pffasttimo (arg=0x0) at
/home/source/dfbsd/sys/kern/uipc_domain.c:261
#15 0xc032e4f6 in softclock_handler (arg=0xc0697fc0) at
/home/source/dfbsd/sys/kern/kern_timeout.c:305
#16 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271


#0 dumpsys () at ./machine/thread.h:83
#1 0xc031dace in boot (howto=260) at
/home/source/dfbsd/sys/kern/kern_shutdown.c:378
#2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
/home/source/dfbsd/sys/kern/kern_shutdown.c:813
#3 0xc0171d39 in db_panic (addr=-1069923399, have_addr=0, count=-1,
modif=0xc9cb4af8 "")
at /home/source/dfbsd/sys/ddb/db_command.c:448
#4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
#5 0xc017497c in db_trap (type=12, code=0) at
/home/source/dfbsd/sys/ddb/db_trap.c:71
#6 0xc051e078 in kdb_trap (type=12, code=0, regs=0xc9cb4c40)
at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
#7 0xc052e578 in trap_fatal (frame=0xc9cb4c40, eva=<value optimized out>)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
#8 0xc052e708 in trap_pfault (frame=0xc9cb4c40, usermode=0, eva=2048)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
#9 0xc052ef9c in trap (frame=0xc9cb4c40) at
/home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
#10 0xc051edb7 in calltrap () at
/home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
#11 0xc03a43b9 in ieee80211_find_rxnode_withkey (ic=0xc9e0f0b8, wh=0x800,
keyix=65535)
at /home/source/dfbsd/sys/netproto/802_11/wlan/ieee80211_node.c:1418
#12 0xcd00c701 in ?? ()
#13 0xc03281bf in lwkt_serialize_handler_call (s=0xcd07f000, func=0xcd00c220,
arg=0xc9e0f0b8, frame=0x0)
at /home/source/dfbsd/sys/kern/lwkt_serialize.c:228
#14 0xc02fed5a in ithread_handler (arg=0xb) at
/home/source/dfbsd/sys/kern/kern_intr.c:804
#15 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271
Backtrace stopped: previous frame inner to this frame (corrupt stack?)

Let me know if you need the core files.

Cheers,
Antonio Huete

Actions #4

Updated by sepherosa about 15 years ago

On Fri, Oct 16, 2009 at 6:22 AM, Antonio Huete Jimenez (via DragonFly
issue tracker) <> wrote:

Antonio Huete Jimenez <> added the comment:

Hi,

I suspect the cause of the panics is going to be hard to find. I've tried to
reproduce the issue a couple of times, each time with a different backtrace. See
below:

If possible, please throw the core dumps onto leaf. Thanks

(kgdb) bt
#0 dumpsys () at ./machine/thread.h:83
#1 0xc031dace in boot (howto=260) at
/home/source/dfbsd/sys/kern/kern_shutdown.c:378
#2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
/home/source/dfbsd/sys/kern/kern_shutdown.c:813
#3 0xc0171d39 in db_panic (addr=-1069681161, have_addr=0, count=-1,
modif=0xc13fcb7c "")
at /home/source/dfbsd/sys/ddb/db_command.c:448
#4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
#5 0xc017497c in db_trap (type=12, code=2) at
/home/source/dfbsd/sys/ddb/db_trap.c:71
#6 0xc051e078 in kdb_trap (type=12, code=2, regs=0xc13fccc4)
at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
#7 0xc052e578 in trap_fatal (frame=0xc13fccc4, eva=<value optimized out>)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
#8 0xc052e708 in trap_pfault (frame=0xc13fccc4, usermode=0, eva=24)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
#9 0xc052ef9c in trap (frame=0xc13fccc4) at
/home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
#10 0xc051edb7 in calltrap () at
/home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
#11 0xc03df5f7 in mld6_sendpkt (in6m=0xc14a4140, type=131, dst=0x0) at
/home/source/dfbsd/sys/netinet6/mld6.c:425
#12 0xc03dfc1b in mld6_fasttimeo () at /home/source/dfbsd/sys/netinet6/mld6.c:362
#13 0xc03cbe08 in icmp6_fasttimo () at /home/source/dfbsd/sys/netinet6/icmp6.c:2108
#14 0xc034d5d7 in pffasttimo (arg=0x0) at
/home/source/dfbsd/sys/kern/uipc_domain.c:261
#15 0xc032e4f6 in softclock_handler (arg=0xc0697fc0) at
/home/source/dfbsd/sys/kern/kern_timeout.c:305
#16 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271


#0 dumpsys () at ./machine/thread.h:83
#1 0xc031dace in boot (howto=260) at
/home/source/dfbsd/sys/kern/kern_shutdown.c:378
#2 0xc031dbef in panic (fmt=0xc057ef3e "from debugger") at
/home/source/dfbsd/sys/kern/kern_shutdown.c:813
#3 0xc0171d39 in db_panic (addr=-1069923399, have_addr=0, count=-1,
modif=0xc9cb4af8 "")
at /home/source/dfbsd/sys/ddb/db_command.c:448
#4 0xc01723ae in db_command_loop () at /home/source/dfbsd/sys/ddb/db_command.c:344
#5 0xc017497c in db_trap (type=12, code=0) at
/home/source/dfbsd/sys/ddb/db_trap.c:71
#6 0xc051e078 in kdb_trap (type=12, code=0, regs=0xc9cb4c40)
at /home/source/dfbsd/sys/platform/pc32/i386/db_interface.c:152
#7 0xc052e578 in trap_fatal (frame=0xc9cb4c40, eva=<value optimized out>)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:1088
#8 0xc052e708 in trap_pfault (frame=0xc9cb4c40, usermode=0, eva=2048)
at /home/source/dfbsd/sys/platform/pc32/i386/trap.c:994
#9 0xc052ef9c in trap (frame=0xc9cb4c40) at
/home/source/dfbsd/sys/platform/pc32/i386/trap.c:674
#10 0xc051edb7 in calltrap () at
/home/source/dfbsd/sys/platform/pc32/i386/exception.s:785
#11 0xc03a43b9 in ieee80211_find_rxnode_withkey (ic=0xc9e0f0b8, wh=0x800,
keyix=65535)
at /home/source/dfbsd/sys/netproto/802_11/wlan/ieee80211_node.c:1418
#12 0xcd00c701 in ?? ()
#13 0xc03281bf in lwkt_serialize_handler_call (s=0xcd07f000, func=0xcd00c220,
arg=0xc9e0f0b8, frame=0x0)
at /home/source/dfbsd/sys/kern/lwkt_serialize.c:228
#14 0xc02fed5a in ithread_handler (arg=0xb) at
/home/source/dfbsd/sys/kern/kern_intr.c:804
#15 0xc032592d in lwkt_deschedule_self (td=Cannot access memory at address 0x8
) at /home/source/dfbsd/sys/kern/lwkt_thread.c:271
Backtrace stopped: previous frame inner to this frame (corrupt stack?)

Let me know if you need the core files.

Cheers,
Antonio Huete

_____________________________________________
DragonFly issue tracker <>
<http://bugs.dragonflybsd.org/issue1498>
_____________________________________________

Actions #5

Updated by tuxillo about 15 years ago

Sephe,

Here you are. They are coredumps for the last two panics I've pasted.
http://leaf.dragonflybsd.org/~tuxillo/bugs/1498/

Path on leaf is 777, so you can write if you need:
/home/tuxillo/public_html/bugs/1498

Cheers,
Antonio

Actions #6

Updated by tuxillo almost 11 years ago

  • Description updated (diff)
  • Category set to Driver
  • Status changed from New to Closed
  • Assignee deleted (0)
  • Target version set to 3.8

Hi,

This problem is no longer relevant.

Cheers,
Antonio Huete

Actions

Also available in: Atom PDF