[openib-general] [BUG] NULL pointer deref in ib_sa_mcmember_rec_callback()

Grant Grundler iod00d at hp.com
Mon Mar 28 22:33:17 PST 2005


I'm on a roll tonight...hit ^C after trying to start netperf 
from ionize (10.0.0.113) to a 4th node that didn't have IPoIB
module loaded or configured yet. I could no longer ping ionize
(10.0.0.113) nor ping out from it via IB.
I tried to unload ib_ipoib and got the NULL ptr deref segfault.
Will reboot the box at this point.

Same config/kernel as before: 2.6.11 + SVN gen2 version 2050.

Tombstone follows.

thanks,
grant


...
ionize:~# for i in 8192 8192 8192; do /usr/local/bin/netperf -c -l 60 -H 10.0.0.30 -t TCP_STREAM -- -m $i -s 262144 -S 262144; done
ionize:~# 
ionize:~# 
ionize:~# ifconfig ib0 down
Unable to handle kernel NULL pointer dereference (address 0000000000000000)
ib_mad1[1942]: Oops 8813272891392 [1]
Modules linked in: ib_ipoib ib_sa ib_mthca ib_mad ib_core tg3 dm_mod e1000 e100

Pid: 1942, CPU 1, comm:              ib_mad1
psr : 0000101008026018 ifs : 800000000000038b ip  : [<a0000002000a54d0>]    Not tainted
ip is at ib_sa_mcmember_rec_callback+0x90/0xe0 [ib_sa]
unat: 0000000000000000 pfs : 000000000000048d rsc : 0000000000000003
rnat: 0000000000000000 bsps: 0000000000000000 pr  : 000000000000a941
ldrs: 0000000000000000 ccv : 0000000000000000 fpsr: 0009804c8a74433f
csd : 0000000000000000 ssd : 0000000000000000
b0  : a0000002000a5a30 b6  : a000000100002d70 b7  : a0000002000a5440
f6  : 1003e8080808080808081 f7  : 1003e0000000000001400
f8  : 1003e0000000000001400 f9  : 1003e00000000000027d8
f10 : 1003e000000000ff00000 f11 : 1003e000000003b5f2d38
r1  : a0000002002a4000 r2  : a0000002000a7270 r3  : e000000101fcfd98
r8  : a0000002000a5440 r9  : 0000000000000006 r10 : 0000000000000003
r11 : 0000000000000001 r12 : e000000101fcfd20 r13 : e000000101fc8000
r14 : 0000000000000000 r15 : e00000003f582908 r16 : a0000002000a92d8
r17 : 0000000000000000 r18 : 0000000000000001 r19 : 0000000000000000
r20 : e00000003f577d40 r21 : 0000000000000000 r22 : e00000003f577d40
r23 : 0000000000000000 r24 : 0000000000000000 r25 : e0000001011c1368
r26 : e00000019dadcd18 r27 : 0000001008026018 r28 : e0000001011c1368
r29 : e000000100395430 r30 : 0000000000000000 r31 : a0000002000a9da0

Call Trace:
 [<a00000010000f3a0>] show_stack+0x80/0xa0
                                sp=e000000101fcf8e0 bsp=e000000101fc9180
 [<a00000010000fc00>] show_regs+0x7e0/0x800
                                sp=e000000101fcfab0 bsp=e000000101fc9120
 [<a000000100033730>] die+0x150/0x1c0
                                sp=e000000101fcfac0 bsp=e000000101fc90e0
 [<a000000100053b70>] ia64_do_page_fault+0x370/0x980
                                sp=e000000101fcfac0 bsp=e000000101fc9078
 [<a00000010000a780>] ia64_leave_kernel+0x0/0x260
                                sp=e000000101fcfb50 bsp=e000000101fc9078
 [<a0000002000a54d0>] ib_sa_mcmember_rec_callback+0x90/0xe0 [ib_sa]
                                sp=e000000101fcfd20 bsp=e000000101fc9020
 [<a0000002000a5a30>] send_handler+0x110/0x280 [ib_sa]
                                sp=e000000101fcfd70 bsp=e000000101fc8fd0
 [<a00000020011a5b0>] ib_mad_complete_send_wr+0x270/0x300 [ib_mad]
                                sp=e000000101fcfd70 bsp=e000000101fc8f90
 [<a00000020011a820>] ib_mad_send_done_handler+0x1e0/0x2e0 [ib_mad]
                                sp=e000000101fcfd70 bsp=e000000101fc8f20
 [<a00000020011ae00>] ib_mad_completion_handler+0x180/0x200 [ib_mad]
                                sp=e000000101fcfd80 bsp=e000000101fc8ed0
 [<a0000001000b1490>] worker_thread+0x3d0/0x520
                                sp=e000000101fcfdb0 bsp=e000000101fc8e48
 [<a0000001000bb9e0>] kthread+0x160/0x180
                                sp=e000000101fcfe20 bsp=e000000101fc8e10
 [<a000000100011410>] kernel_thread_helper+0xd0/0x100
                                sp=e000000101fcfe30 bsp=e000000101fc8de0
 [<a0000001000090e0>] start_kernel_thread+0x20/0x40
                                sp=e000000101fcfe30 bsp=e000000101fc8de0
 ionize:~#



More information about the general mailing list