Project

General

Profile

Bug #7075

ahci: NULL pointer dereference in ahci_add_doneq()

Added by James Dickens over 3 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
driver - device drivers
Start date:
2016-06-06
Due date:
% Done:

0%

Estimated time:
Difficulty:
Medium
Tags:
needs-triage

Description

::panicinfo
             cpu               10
          thread ffffff00ac8dac40
         message
BAD TRAP: type=e (#pf Page fault) rp=ffffff00ac8da8b0 addr=40 occurred in module "ahci" due to a NULL pointer dereference
             rdi ffffff17eb3e5000
             rsi                0
             rdx                1
             rcx         fffffffe
              r8                0
              r9               10
             rax                1
             rbx ffffff17eb3e5000
             rbp ffffff00ac8da9c0
             r10 ffffff00ac8da840
             r11                0
             r12                0
             r13                0
             r14                0
             r15                1
          fsbase                0
          gsbase ffffff179b6f8040
              ds               4b
              es               4b
              fs                0
              gs              1c3
          trapno                e
             err                0
             rip fffffffff8188d24
              cs               30
          rflags            10286
             rsp ffffff00ac8da9a0
              ss               38

 *panic_thread::findstack -v
stack pointer for thread ffffff00ac8dac40: ffffff00ac8da570
  ffffff00ac8da5e0 avl_find+0x72(fffffffffbc32430, ffffff00ac8da5f8, 0)
  ffffff00ac8da610 as_segat+0x3d(fffffffffbc323e0, 0)
  ffffff00ac8da700 as_fault+0x4e7(fffffffffb938770, fffffffffbc323e0, 40, ffffff00ac8da8b0, fffffffffb955b29, fffffffffb955a3f)
  ffffff00ac8da790 die+0xdf(e, ffffff00ac8da8b0, 40, a)
  ffffff00ac8da8a0 trap+0xdd8(ffffff00ac8da8b0, 40, a)
  ffffff00ac8da8b0 0xfffffffffb8001d6()
  ffffff00ac8da9c0 ahci_add_doneq+0x14(ffffff17eb3e5000, 0, 1)
  ffffff00ac8daa60 ahci_mop_commands+0x148(ffffff17eb3dde40, ffffff17eb3e5000, 0, 1, 0, 0, ffffff0000000000)
  ffffff00ac8dab00 ahci_fatal_error_recovery_handler+0x241(ffffff17eb3dde40, ffffff17eb3e5000, ffffff17c3d82830, 8000000)
  ffffff00ac8dab60 ahci_events_handler+0xda(ffffff17c3d0c6f0)
  ffffff00ac8dac20 taskq_thread+0x2d0(ffffff17eb3fd928)
  ffffff00ac8dac30 thread_start+8()

email me for a link to core kdump.0 if you need it.


Files

ahci_crash.xml (4.85 KB) ahci_crash.xml libvirt guest configuration Michal Nowak, 2017-11-18 06:35 PM

Related issues

Has duplicate illumos gate - Bug #7182: panic when booting with KVM SATA CDROMClosed2016-07-13

Actions
Has duplicate illumos gate - Bug #8001: guest virtualbox system dumps core when I attach Host drive DVD-RW with inserted audio CD to itClosed2017-03-24

Actions

History

#1

Updated by Yuri Pankov over 3 years ago

  • Description updated (diff)
#2

Updated by Marcel Telka about 3 years ago

  • Category set to driver - device drivers
#3

Updated by Marcel Telka about 3 years ago

  • Has duplicate Bug #7182: panic when booting with KVM SATA CDROM added
#4

Updated by Marcel Telka about 3 years ago

  • Subject changed from Marvell 88SE9235 crashes when not underload. to ahci: NULL pointer dereference in ahci_add_doneq()
#5

Updated by Marcel Telka almost 3 years ago

  • Has duplicate Bug #8001: guest virtualbox system dumps core when I attach Host drive DVD-RW with inserted audio CD to it added
#6

Updated by Alexander Pyhalov almost 3 years ago

Steps to reproduce (at least for me):
1) Create Virtualbox VM (used Virtualbox 4.3.30) running on OI.
2) Attach host drive to VM (Host CDrom device is attached to SATA controller - in real life and in Virtual Box VM).
3) Insert audio disk (or perhaps, just this exact disk) into CDrom.
4) Boot VM.
5) On boot you get it.

#7

Updated by Michal Nowak over 2 years ago

I can reproduce it on KVM with any recent OI ISO image attached as a SATA CDROM device with two vCPUs. OI with this combination at least once booted for me.

Also available in: Atom PDF