NULL pointer dereference in iblock_do_task+0x1d/0x200 [target_core_mod]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



We seem to have gotten an oops from the target_core_mod module.  The
kernel log reports:

NULL pointer dereference at 0000000000000030
IP: [<ffffffffa042991d>] iblock_do_task+0x1d/0x200 [target_core_mod]
PGD 0 
Oops: 0000 [#1] SMP 
last sysfs file: /sys/devices/system/cpu/cpu23/cache/index2/shared_cpu_map
CPU 12 
Modules linked in: crc32c_intel nfs fscache ip6table_filter ip6_tables ebtable_nat ebtables ipt_MASQUERADE iptable_nat nf_nat nf_conntrack_ipv4 nf
_defrag_ipv4 xt_state nf_conntrack ipt_REJECT xt_CHECKSUM iptable_mangle iptable_filter ip_tables nfsd lockd nfs_acl auth_rpcgss exportfs autofs4 
iscsi_target_mod(U) target_core_mod(U) configfs sunrpc cpufreq_ondemand acpi_cpufreq freq_table mperf bridge stp llc ib_ipoib rdma_ucm ib_ucm ib_u
verbs ib_umad rdma_cm ib_cm iw_cm ib_addr ipv6 ib_sa ib_mad ib_core vhost_net macvtap macvlan tun kvm_intel kvm e1000e raid456 async_raid6_recov a
sync_pq raid6_pq async_xor xor async_memcpy async_tx microcode serio_raw i2c_i801 i2c_core sg iTCO_wdt iTCO_vendor_support ioatdma dca i7core_edac
 edac_core shpchp ext3 jbd mbcache sd_mod crc_t10dif ahci dm_mirror dm_region_hash dm_log dm_mod [last unloaded: scsi_wait_scan]

Pid: 2632, comm: LIO_iblock Not tainted 2.6.32-220.13.1.el6.x86_64 #1 Supermicro X8DTT-H/X8DTT-H
RIP: 0010:[<ffffffffa042991d>]  [<ffffffffa042991d>] iblock_do_task+0x1d/0x200 [target_core_mod]
RSP: 0018:ffff880336183dc0  EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffff8801e8f91d00 RCX: 00000000a5060a0b
RDX: ffff8802e7b81274 RSI: 0000000000000286 RDI: ffff8801e8f91d00
RBP: ffff880336183de0 R08: ffff8801e8f91e00 R09: 0000000000000001
R10: 0000000000000000 R11: 0000000000000000 R12: ffff880211da49c0
R13: ffff8806357d35d8 R14: ffff8806357d3474 R15: ffff8801e8f91d00
FS:  0000000000000000(0000) GS:ffff8800282c0000(0000) knlGS:0000000000000000
CS:  0010 DS: 0018 ES: 0018 CR0: 000000008005003b
CR2: 0000000000000030 CR3: 0000000001a85000 CR4: 00000000000026e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process LIO_iblock (pid: 2632, threadinfo ffff880336182000, task ffff880336312a80)
Stack:
 ffff880336183de0 ffff880211da49c0 ffff8806357d3400 ffff8806357d35d8
<0> ffff880336183e30 ffffffffa0422109 00000000000000f9 0000000000000286
<0> ffff8801e8f9d840 ffff8806357d3400 ffff8802122fe400 00000000000000f9
Call Trace:
 [<ffffffffa0422109>] __transport_execute_tasks+0x159/0x240 [target_core_mod]
 [<ffffffffa0427fc6>] transport_processing_thread+0xf6/0x770 [target_core_mod]
 [<ffffffff8105e952>] ? default_wake_function+0x12/0x20
 [<ffffffff81090c30>] ? autoremove_wake_function+0x0/0x40
 [<ffffffffa0427ed0>] ? transport_processing_thread+0x0/0x770 [target_core_mod]
 [<ffffffff810908c6>] kthread+0x96/0xa0
 [<ffffffff8100c14a>] child_rip+0xa/0x20
 [<ffffffff81090830>] ? kthread+0x0/0xa0
 [<ffffffff8100c140>] ? child_rip+0x0/0x20
Code: e0 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 55 48 89 e5 41 55 41 54 53 48 83 ec 08 0f 1f 44 00 00 48 8b 47 10 4c 8b 67 48 48 89 fb <48> 8b 50 30 41 f6 44 24 20 08 48 8b 70 28 48 8b 92 20 02 00 00 
RIP  [<ffffffffa042991d>] iblock_do_task+0x1d/0x200 [target_core_mod]^M^@
 RSP <ffff880336183dc0>
CR2: 0000000000000030

We saw this previously also with perhaps a bit more information:

------------[ cut here ]------------
WARNING: at lib/list_debug.c:51 list_del+0x8d/0xa0() (Not tainted)
Hardware name: X8DTT-H
list_del corruption. next->prev should be ffff8801e8a95180, but was dead000000200200
Modules linked in: crc32c_intel nfs fscache ip6table_filter ip6_tables ebtable_nat ebtables ipt_MASQUERADE iptable_nat nf_nat nf_conntrack_ipv4 nf
_defrag_ipv4 xt_state nf_conntrack ipt_REJECT xt_CHECKSUM iptable_mangle iptable_filter ip_tables nfsd lockd nfs_acl auth_rpcgss exportfs autofs4 
iscsi_target_mod(U) target_core_mod(U) configfs sunrpc cpufreq_ondemand acpi_cpufreq freq_table mperf bridge stp llc ib_ipoib rdma_ucm ib_ucm ib_u
verbs ib_umad rdma_cm ib_cm iw_cm ib_addr ipv6 ib_sa ib_mad ib_core vhost_net macvtap macvlan tun kvm_intel kvm e1000e raid456 async_raid6_recov a
sync_pq raid6_pq async_xor xor async_memcpy async_tx microcode serio_raw i2c_i801 i2c_core sg iTCO_wdt iTCO_vendor_support ioatdma dca i7core_edac
 edac_core shpchp ext3 jbd mbcache sd_mod crc_t10dif ahci dm_mirror dm_region_hash dm_log dm_mod [last unloaded: scsi_wait_scan]
Pid: 2595, comm: LIO_iblock Not tainted 2.6.32-220.13.1.el6.x86_64 #1
Call Trace:
 [<ffffffff81069ba7>] ? warn_slowpath_common+0x87/0xc0
 [<ffffffff81069c96>] ? warn_slowpath_fmt+0x46/0x50
 [<ffffffff8105e995>] ? wake_up_process+0x15/0x20
 [<ffffffff8127bbad>] ? list_del+0x8d/0xa0
 [<ffffffffa041de6b>] ? transport_get_task_from_execute_queue+0x3b/0x50 [target_core_mod]
 [<ffffffffa0422025>] ? __transport_execute_tasks+0x75/0x240 [target_core_mod]
 [<ffffffffa0427fc6>] ? transport_processing_thread+0xf6/0x770 [target_core_mod]
 [<ffffffff8105e952>] ? default_wake_function+0x12/0x20
 [<ffffffff81090c30>] ? autoremove_wake_function+0x0/0x40
 [<ffffffffa0427ed0>] ? transport_processing_thread+0x0/0x770 [target_core_mod]
 [<ffffffff810908c6>] ? kthread+0x96/0xa0
 [<ffffffff8100c14a>] ? child_rip+0xa/0x20
 [<ffffffff81090830>] ? kthread+0x0/0xa0
 [<ffffffff8100c140>] ? child_rip+0x0/0x20
---[ end trace e9a4b9f1e04e70cf ]---
BUG: unable to handle kernel NULL pointer dereference at 0000000000000030
IP: [<ffffffffa042991d>] iblock_do_task+0x1d/0x200 [target_core_mod]
PGD 0 
Oops: 0000 [#1] SMP 
last sysfs file: /sys/devices/system/cpu/cpu23/cache/index2/shared_cpu_map
CPU 8 
Modules linked in: crc32c_intel nfs fscache ip6table_filter ip6_tables ebtable_nat ebtables ipt_MASQUERADE iptable_nat nf_nat nf_conntrack_ipv4 nf_defrag_ipv4 xt_state nf_conntrack ipt_REJECT xt_CHECKSUM iptable_mangle iptable_filter ip_tables nfsd lockd nfs_acl auth_rpcgss exportfs autofs4 iscsi_target_mod(U) target_core_mod(U) configfs sunrpc cpufreq_ondemand acpi_cpufreq freq_table mperf bridge stp llc ib_ipoib rdma_ucm ib_ucm ib_uverbs ib_umad rdma_cm ib_cm iw_cm ib_addr ipv6 ib_sa ib_mad ib_core vhost_net macvtap macvlan tun kvm_intel kvm e1000e raid456 async_raid6_recov async_pq raid6_pq async_xor xor async_memcpy async_tx microcode serio_raw i2c_i801 i2c_core sg iTCO_wdt iTCO_vendor_support ioatdma dca i7core_edac edac_core shpchp ext3 jbd mbcache sd_mod crc_t10dif ahci dm_mirror dm_region_hash dm_log dm_mod [last unloaded: scsi_wait_scan]

Pid: 2595, comm: LIO_iblock Tainted: G        W  ----------------   2.6.32-220.13.1.el6.x86_64 #1 Supermicro X8DTT-H/X8DTT-H
RIP: 0010:[<ffffffffa042991d>]  [<ffffffffa042991d>] iblock_do_task+0x1d/0x200 [target_core_mod]
RSP: 0018:ffff880331eafdc0  EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffff8801e8a95080 RCX: 0000000000000040
RDX: ffff8802dc267474 RSI: 0000000000000286 RDI: ffff8801e8a95080
RBP: ffff880331eafde0 R08: ffffffff81c006c0 R09: 0000000000000000
R10: 000000000000000f R11: 000000000000000e R12: ffff88021c100080
R13: ffff880331ed6dd8 R14: ffff880331ed6c74 R15: ffff8801e8a95080
FS:  0000000000000000(0000) GS:ffff88034ac40000(0000) knlGS:0000000000000000
CS:  0010 DS: 0018 ES: 0018 CR0: 000000008005003b
CR2: 0000000000000030 CR3: 0000000001a85000 CR4: 00000000000026e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process LIO_iblock (pid: 2595, threadinfo ffff880331eae000, task ffff880336b574c0)
Stack:
 0000000000000010 ffff88021c100080 ffff880331ed6c00 ffff880331ed6dd8
<0> ffff880331eafe30 ffffffffa0422109 00000000000000f9 0000000000000286
<0> ffff8801c47eff40 ffff880331ed6c00 ffff88021c1005c0 00000000000000f9
Call Trace:
 [<ffffffffa0422109>] __transport_execute_tasks+0x159/0x240 [target_core_mod]
 [<ffffffffa0427fc6>] transport_processing_thread+0xf6/0x770 [target_core_mod]
 [<ffffffff8105e952>] ? default_wake_function+0x12/0x20
 [<ffffffff81090c30>] ? autoremove_wake_function+0x0/0x40^M^@
 [<ffffffffa0427ed0>] ? transport_processing_thread+0x0/0x770 [target_core_mod]
 [<ffffffff810908c6>] kthread+0x96/0xa0
 [<ffffffff8100c14a>] child_rip+0xa/0x20
 [<ffffffff81090830>] ? kthread+0x0/0xa0
 [<ffffffff8100c140>] ? child_rip+0x0/0x20
Code: e0 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 55 48 89 e5 41 55 41 54 53 48 83 ec 08 0f 1f 44 00 00 48 8b 47 10 4c 8b 67 48 48 89 fb <48> 8b 50 30 41 f6 44 24 20 08 48 8b 70 28 48 8b 92 20 02 00 00 
RIP  [<ffffffffa042991d>] iblock_do_task+0x1d/0x200 [target_core_mod]
 RSP <ffff880331eafdc0>
CR2: 0000000000000030

We're currently building at b4633dac729bc46278ff6d5d3a294cce2217c91a.

Is this a known issue?

Cheers,
b.

Attachment: signature.asc
Description: OpenPGP digital signature


[Index of Archives]     [Linux SCSI]     [Kernel Newbies]     [Linux SCSI Target Infrastructure]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Linux IIO]     [Device Mapper]

  Powered by Linux