)]}'
{
  "commit": "6aa65472d18703064898eefb5eb58f7ecd0d8912",
  "tree": "d7085a9599febe317937dab77abddf857910f55b",
  "parents": [
    "e6f47f978bcd5413fff610613b18e9e0eab9bc1b"
  ],
  "author": {
    "name": "Michael Buesch",
    "email": "mb@bu3sch.de",
    "time": "Mon Jun 26 00:25:30 2006 -0700"
  },
  "committer": {
    "name": "Linus Torvalds",
    "email": "torvalds@g5.osdl.org",
    "time": "Mon Jun 26 09:58:22 2006 -0700"
  },
  "message": "[PATCH] CAPI crash / race condition\n\nI am getting more or less reproducible crashes from the CAPI subsystem\nusing the fcdsl driver:\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000010\n printing eip:\nc39bbca4\n*pde \u003d 00000000\nOops: 0000 [#1]\nModules linked in: netconsole capi capifs 3c59x mii fcdsl kernelcapi uhci_hcd usbcore ide_cd cdrom\nCPU:    0\nEIP:    0060:[\u003cc39bbca4\u003e]    Tainted: P      VLI\nEFLAGS: 00010202   (2.6.16.11 #3)\nEIP is at handle_minor_send+0x17a/0x241 [capi]\neax: c24abbc0   ebx: c0b4c980   ecx: 00000010   edx: 00000010\nesi: c1679140   edi: c2783016   ebp: 0000c28d   esp: c0327e24\nds: 007b   es: 007b   ss: 0068\nProcess swapper (pid: 0, threadinfo\u003dc0326000 task\u003dc02e1300)\nStack: \u003c0\u003e000005b4 c1679180 00000000 c28d0000 c1ce04e0 c2f69654 c221604e c1679140\n       c39bc19a 00000038 c20c0400 c075c560 c1f2f800 00000000 c01dc9b5 c1e96a40\n       c075c560 c2ed64c0 c1e96a40 c01dcd3b c2fb94e8 c075c560 c0327f00 c1e96a40\nCall Trace:\n [\u003cc39bc19a\u003e] capinc_tty_write+0xda/0xf3 [capi]\n [\u003cc01dc9b5\u003e] ppp_sync_push+0x52/0xfe\n [\u003cc01dcd3b\u003e] ppp_sync_send+0x1f5/0x204\n [\u003cc01d9bc1\u003e] ppp_push+0x3e/0x9c\n [\u003cc01dacd4\u003e] ppp_xmit_process+0x422/0x4cc\n [\u003cc01daf3f\u003e] ppp_start_xmit+0x1c1/0x1f6\n [\u003cc0213ea5\u003e] qdisc_restart+0xa7/0x135\n [\u003cc020b112\u003e] dev_queue_xmit+0xba/0x19e\n [\u003cc0223f69\u003e] ip_output+0x1eb/0x236\n [\u003cc0220907\u003e] ip_forward+0x1c1/0x21a\n [\u003cc021fa6c\u003e] ip_rcv+0x38e/0x3ea\n [\u003cc020b4c2\u003e] netif_receive_skb+0x166/0x195\n [\u003cc020b55e\u003e] process_backlog+0x6d/0xd2\n [\u003cc020a30f\u003e] net_rx_action+0x6a/0xff\n [\u003cc0112909\u003e] __do_softirq+0x35/0x7d\n [\u003cc0112973\u003e] do_softirq+0x22/0x26\n [\u003cc0103a9d\u003e] do_IRQ+0x1e/0x25\n [\u003cc010255a\u003e] common_interrupt+0x1a/0x20\n [\u003cc01013c5\u003e] default_idle+0x2b/0x53\n [\u003cc0101426\u003e] cpu_idle+0x39/0x4e\n [\u003cc0328386\u003e] start_kernel+0x20b/0x20d\nCode: c0 e8 b3 b6 77 fc 85 c0 75 10 68 d8 c8 9b c3 e8 82 3d 75 fc 8b 43 60 5a eb 50 8d 56 50 c7 00 00 00 00 00 66 89 68 04 eb 02 89\nca \u003c8b\u003e 0a 85 c9 75 f8 89 02 89 da ff 46 54 8b 46 10 e8 30 79 fd ff\n \u003c0\u003eKernel panic - not syncing: Fatal exception in interrupt\n\nThat oops took me to the \"ackqueue\" implementation in capi.c.  The crash\noccured in capincci_add_ack() (auto-inlined by the compiler).\n\nI read the code a bit and finally decided to replace the custom linked list\nimplementation (struct capiminor-\u003eackqueue) by a struct list_head.  That\ndid not solve the crash, but produced the following interresting oops:\n\nUnable to handle kernel paging request at virtual address 00200200\n printing eip:\nc39bb1f5\n*pde \u003d 00000000\nOops: 0002 [#1]\nModules linked in: netconsole capi capifs 3c59x mii fcdsl kernelcapi uhci_hcd usbcore ide_cd cdrom\nCPU:    0\nEIP:    0060:[\u003cc39bb1f5\u003e]    Tainted: P      VLI\nEFLAGS: 00010246   (2.6.16.11 #3)\nEIP is at capiminor_del_ack+0x18/0x49 [capi]\neax: 00200200   ebx: c18d41a0   ecx: c1385620   edx: 00100100\nesi: 0000d147   edi: 00001103   ebp: 0000d147   esp: c1093f3c\nds: 007b   es: 007b   ss: 0068\nProcess events/0 (pid: 3, threadinfo\u003dc1092000 task\u003dc1089030)\nStack: \u003c0\u003ec2a17580 c18d41a0 c39bbd16 00000038 c18d41e0 00000000 d147c640 c29e0b68\n       c29e0b90 00000212 c29e0b68 c39932b2 c29e0bb0 c10736a0 c0119ef0 c399326c\n       c10736a8 c10736a0 c10736b0 c0119f93 c011a06e 00000001 00000000 00000000\nCall Trace:\n [\u003cc39bbd16\u003e] handle_minor_send+0x1af/0x241 [capi]\n [\u003cc39932b2\u003e] recv_handler+0x46/0x5f [kernelcapi]\n [\u003cc0119ef0\u003e] run_workqueue+0x5e/0x8d\n [\u003cc399326c\u003e] recv_handler+0x0/0x5f [kernelcapi]\n [\u003cc0119f93\u003e] worker_thread+0x0/0x10b\n [\u003cc011a06e\u003e] worker_thread+0xdb/0x10b\n [\u003cc010c998\u003e] default_wake_function+0x0/0xc\n [\u003cc011c399\u003e] kthread+0x90/0xbc\n [\u003cc011c309\u003e] kthread+0x0/0xbc\n [\u003cc0100a65\u003e] kernel_thread_helper+0x5/0xb\nCode: 7e 02 89 ee 89 f0 5a f7 d0 c1 f8 1f 5b 21 f0 5e 5f 5d c3 56 53 8b 48 50 89 d6 89 c3 8b 11 eb 2f 66 39 71 08 75 25 8b 41 04 8b 11 \u003c89\u003e 10 89 42 04 c7 01 00 01 10 00 89 c8 c7 41 04 00 02 20 00 e8\n\nThe interresting part of it is the \"virtual address 00200200\", which is\nLIST_POISON2.  I thought about some race condition, but as this is an UP\nsystem, it leads to questions on how it can happen.  If we look at EFLAGS:\n00010202, we see that interrupts are enabled at the time of the crash\n(eflags \u0026 0x200).\n\nFinally, I don\u0027t understand all the capi code, but I think that\nhandle_minor_send() is racing somehow against capi_recv_message(), which\ncall both capiminor_del_ack().  So if an IRQ occurs in the middle of\ncapiminor_del_ack() and another instance of it is invoked, it leads to\nlinked list corruption.\n\nI came up with the following patch.  With this, I could not reproduce the\ncrash anymore.  Clearly, this is not the correct fix for the issue.  As this\nseems to be some locking issue, there might be more locking issues in that\ncode.  For example, doesn\u0027t the whole struct capiminor have to be locked\nsomehow?\n\nCc: Carsten Paeth \u003ccalle@calle.de\u003e\nCc: Kai Germaschewski \u003ckai.germaschewski@gmx.de\u003e\nCc: Karsten Keil \u003ckkeil@suse.de\u003e\nSigned-off-by: Andrew Morton \u003cakpm@osdl.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@osdl.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "173c899a1fb40cb9eca8ff5b02844a95519b2527",
      "old_mode": 33188,
      "old_path": "drivers/isdn/capi/capi.c",
      "new_id": "2e541fa020241c468d95dff4f38047cf344f929b",
      "new_mode": 33188,
      "new_path": "drivers/isdn/capi/capi.c"
    }
  ]
}
