Bug 2022980

Summary: [abrt] radeon_bo_unref: WARNING: CPU: 4 PID: 1408 at drivers/gpu/drm/radeon/radeon_object.c:83 radeon_ttm_bo_destroy+0xde/0xf0 [radeon] [radeon]
Product: [Fedora] Fedora Reporter: Nicolas Sapa <redhat>
Component: xorg-x11-drv-atiAssignee: X/OpenGL Maintenance List <xgl-maint>
Status: CLOSED EOL QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 35CC: aawitherspoon, bennoprins, caillon+fedoraproject, dkita, epixtoxin, jglisse, kernel-maint, max1, mdaenzer, ofourdan, rhbugs, rhughes, rstrode, sandmann, sjricaro, spotrh, xgl-maint
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
URL: https://retrace.fedoraproject.org/faf/reports/bthash/2ea8bbe06bc4ef6c21c5e74e76cea3b8a630e1be
Whiteboard: abrt_hash:7ca4cb452f69af8a0c8fc8231f3e427c95b66d42;
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-12-13 15:52:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
File: dmesg
none
Kernel log with a "ring stalled" error none

Description Nicolas Sapa 2021-11-13 16:25:58 UTC
Additional info:
reporter:       libreport-2.15.2
WARNING: CPU: 4 PID: 1408 at drivers/gpu/drm/radeon/radeon_object.c:83 radeon_ttm_bo_destroy+0xde/0xf0 [radeon]
Modules linked in: snd_seq_dummy snd_hrtimer rfcomm nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_tables ebtable_nat ebtable_broute ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security ip_set nfnetlink ebtable_filter ebtables ip6table_filter ip6_tables iptable_filter qrtr ns bnep sunrpc vfat fat intel_rapl_msr intel_rapl_common x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel iwlmvm kvm iTCO_wdt dell_laptop irqbypass intel_pmc_bxt at24 mei_wdt mei_hdcp ppdev iTCO_vendor_support dell_smm_hwmon mac80211 rapl intel_cstate btusb intel_uncore libarc4 btrtl btbcm btintel uvcvideo dell_wmi bluetooth dell_smbios videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 dcdbas pcspkr iwlwifi snd_hda_codec_realtek sparse_keymap wmi_bmof videobuf2_common dell_wmi_descriptor videodev cfg80211
 snd_hda_codec_generic i2c_i801 ledtrig_audio i2c_smbus ecdh_generic snd_hda_codec_hdmi mc joydev snd_soc_rt5640 lpc_ich snd_hda_intel snd_soc_rl6231 snd_intel_dspcfg snd_soc_core snd_intel_sdw_acpi snd_hda_codec mei_me mei snd_hda_core snd_compress ac97_bus snd_pcm_dmaengine snd_hwdep snd_seq snd_seq_device snd_pcm snd_timer snd parport_pc parport dell_rbtn soundcore dell_smo8800 rfkill binfmt_misc zram ip_tables dm_crypt trusted asn1_encoder amdgpu iommu_v2 gpu_sched i915 radeon crct10dif_pclmul crc32_pclmul crc32c_intel i2c_algo_bit drm_ttm_helper sdhci_pci ttm drm_kms_helper serio_raw cqhci ghash_clmulni_intel sdhci cec mmc_core drm e1000e wmi video ipmi_devintf ipmi_msghandler fuse
CPU: 4 PID: 1408 Comm: Xorg Not tainted 5.14.16-301.fc35.x86_64 #1
Hardware name: Dell Inc. Precision M2800/07C6X3, BIOS A17 06/13/2019
RIP: 0010:radeon_ttm_bo_destroy+0xde/0xf0 [radeon]
Code: 00 00 00 74 0f 48 8b b5 b0 01 00 00 48 89 ef e8 08 fa de ff 48 89 ef e8 20 02 de ff 4c 89 e7 5b 5d 41 5c 41 5d e9 a2 da c2 c8 <0f> 0b eb cd 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 0f 1f 44 00
RSP: 0018:ffffb10b00783d20 EFLAGS: 00010202
RAX: ffff89037332fa70 RBX: ffffffffffffffff RCX: 0000000000000000
RDX: ffff890374b0f780 RSI: ffff89037332f800 RDI: ffff89034c0a1ca8
RBP: ffff89037332f878 R08: ffff89034c0a1cc8 R09: 0000000000000000
R10: ffff89037756e600 R11: 0000000000000000 R12: ffff89037332f800
R13: ffff89037977b330 R14: ffff89037977b240 R15: ffff89037895c028
FS:  0000000000000000(0000) GS:ffff89065eb00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff0c869c734 CR3: 000000003ae10003 CR4: 00000000001706e0
Call Trace:
 radeon_bo_unref+0x1a/0x30 [radeon]
 radeon_gem_object_free+0x20/0x30 [radeon]
 drm_gem_object_release_handle+0x6b/0x80 [drm]
 ? drm_gem_object_handle_put_unlocked+0xd0/0xd0 [drm]
 idr_for_each+0x4e/0xc0
 drm_gem_release+0x1c/0x30 [drm]
 drm_file_free.part.0+0x1e3/0x250 [drm]
 drm_release+0x65/0x110 [drm]
 __fput+0x94/0x240
 task_work_run+0x65/0xa0
 do_exit+0x33d/0xa90
 do_group_exit+0x33/0xa0
 __x64_sys_exit_group+0x14/0x20
 do_syscall_64+0x3b/0x90
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7ff0c8eab561
Code: Unable to access opcode bytes at RIP 0x7ff0c8eab537.
RSP: 002b:00007ffd51068778 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007ff0c8fca510 RCX: 00007ff0c8eab561
RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000000
RBP: 0000000000000000 R08: fffffffffffffc78 R09: 0000000000000000
R10: 00007ff0c8dd7e88 R11: 0000000000000246 R12: 00007ff0c8fca510
R13: 0000000000000000 R14: 00007ff0c8fca9e8 R15: 00007ff0c8fcaa00

Comment 1 Nicolas Sapa 2021-11-13 16:26:03 UTC
Created attachment 1841576 [details]
File: dmesg

Comment 2 Maksym Sanzharov 2021-11-14 18:08:50 UTC
Description of problem:
I was scrolling photos in gthumb, by using next/previous functions. But I am not sure this was the reason.
I was using Gnome on Xorg.
The system froze after this, I had to restart it with a reset button.
The fault is preceded with error messages "ring 3 stalled for more than 10080msec" and "GPU lockup (current fence id 0x00000000000d800e last fence id 0x00000000000d807c on ring 3)".

Version-Release number of selected component:
kernel-core-5.14.16-301.fc35

Additional info:
reporter:       libreport-2.15.2
cmdline:        BOOT_IMAGE=(hd0,msdos6)/vmlinuz-5.14.16-301.fc35.x86_64 root=/dev/mapper/fedora_max--home-root ro rd.lvm.lv=fedora_max-home/root rd.lvm.lv=fedora_max-home/swap rhgb quiet
crash_function: radeon_bo_unref
kernel:         5.14.16-301.fc35.x86_64
runlevel:       N 5
type:           Kerneloops

Truncated backtrace:
WARNING: CPU: 3 PID: 3823 at drivers/gpu/drm/radeon/radeon_object.c:83 radeon_ttm_bo_destroy+0xde/0xf0 [radeon]
Modules linked in: binfmt_misc nls_cp866 vfat fat rfcomm snd_seq_dummy snd_hrtimer xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_nat_tftp nf_conntrack_tftp bridge stp llc nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_tables ebtable_nat ebtable_broute ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security ip_set nfnetlink ebtable_filter ebtables ip6table_filter ip6_tables iptable_filter bnep qrtr ns it87 hwmon_vid isofs loop sunrpc snd_usb_audio snd_usbmidi_lib snd_rawmidi uvcvideo videobuf2_vmalloc snd_hda_codec_realtek videobuf2_memops videobuf2_v4l2 snd_hda_codec_hdmi videobuf2_common snd_hda_codec_generic videodev ledtrig_audio mc snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hda_core snd_hwdep
 eeepc_wmi snd_seq btusb snd_seq_device snd_pcm btrtl wmi_bmof asus_wmi snd_timer edac_mce_amd btbcm kvm_amd btintel ccp bluetooth kvm irqbypass sparse_keymap ecdh_generic rfkill pcspkr fam15h_power k10temp snd soundcore i2c_piix4 acpi_cpufreq essiv dm_crypt trusted asn1_encoder zram ip_tables amdgpu iommu_v2 gpu_sched radeon crct10dif_pclmul crc32_pclmul crc32c_intel i2c_algo_bit drm_ttm_helper ttm ghash_clmulni_intel drm_kms_helper cec serio_raw r8169 drm sp5100_tco hid_a4tech wmi video hid_jabra ipmi_devintf ipmi_msghandler fuse
CPU: 3 PID: 3823 Comm: skypefor:shlo1 Not tainted 5.14.16-301.fc35.x86_64 #1
Hardware name: System manufacturer System Product Name/A88X-PLUS/USB 3.1, BIOS 0211 03/07/2016
RIP: 0010:radeon_ttm_bo_destroy+0xde/0xf0 [radeon]
Code: 00 00 00 74 0f 48 8b b5 b0 01 00 00 48 89 ef e8 08 ca ea ff 48 89 ef e8 20 d2 e9 ff 4c 89 e7 5b 5d 41 5c 41 5d e9 a2 8a ec e4 <0f> 0b eb cd 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 0f 1f 44 00
RSP: 0018:ffffab6788ccbbe8 EFLAGS: 00010206
RAX: ffff9ece5a55ae70 RBX: ffffffffffffffff RCX: 0000000000000000
RDX: ffff9ececd04d200 RSI: ffff9ece5a55ac00 RDI: ffff9ece4c5b5ca8
RBP: ffff9ece5a55ac78 R08: ffff9ecee81b6800 R09: 0000000000000000
R10: ffff9ed21d399501 R11: 0000000000000000 R12: ffff9ece5a55ac00
R13: ffff9ece58938530 R14: ffff9ece58938440 R15: ffff9ecf1f318028
FS:  00007f2d39ffb640(0000) GS:ffff9ed53fd80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2890ef7000 CR3: 0000000178e10000 CR4: 00000000000506e0
Call Trace:
 radeon_bo_unref+0x1a/0x30 [radeon]
 radeon_gem_object_free+0x20/0x30 [radeon]
 drm_gem_object_release_handle+0x6b/0x80 [drm]
 ? drm_gem_object_handle_put_unlocked+0xd0/0xd0 [drm]
 idr_for_each+0x4e/0xc0
 drm_gem_release+0x1c/0x30 [drm]
 drm_file_free.part.0+0x1e3/0x250 [drm]
 drm_release+0x65/0x110 [drm]
 __fput+0x94/0x240
 task_work_run+0x65/0xa0
 do_exit+0x33d/0xa90
 do_group_exit+0x33/0xa0
 get_signal+0x16b/0x8c0
 arch_do_signal_or_restart+0xfd/0x730
 ? __x64_sys_futex+0x63/0x1a0
 exit_to_user_mode_prepare+0x11a/0x240
 syscall_exit_to_user_mode+0x18/0x40
 do_syscall_64+0x48/0x90
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f2d60eaa77a
Code: Unable to access opcode bytes at RIP 0x7f2d60eaa750.
RSP: 002b:00007f2d39ffa5f0 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
RAX: fffffffffffffe00 RBX: 0000000000000000 RCX: 00007f2d60eaa77a
RDX: 0000000000000000 RSI: 0000000000000189 RDI: 0000557846df4550
RBP: 0000000000000000 R08: 0000000000000000 R09: 00000000ffffffff
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000557846df4550 R14: 0000000000000000 R15: 0000000000000000

Comment 3 aawitherspoon 2021-11-14 18:15:00 UTC
*** Bug 2023096 has been marked as a duplicate of this bug. ***

Comment 4 Maksym Sanzharov 2021-11-14 18:47:36 UTC
Created attachment 1841700 [details]
Kernel log with a "ring stalled" error

The reporter's kernel log for some reason does not contain kernel errors. Attaching mine.

Comment 5 aawitherspoon 2021-11-30 12:52:33 UTC
*** Bug 2027682 has been marked as a duplicate of this bug. ***

Comment 6 Denisa Kita 2021-12-04 12:48:47 UTC
*** Bug 2029052 has been marked as a duplicate of this bug. ***

Comment 7 Benno 2021-12-09 22:00:19 UTC
Description of problem:
- Have multiple user accounts
- Log off

Expected result: the OS switches to the SDDM logon screen.
Real result: screen goes blank and the laptop needs to be restarted completely

Version-Release number of selected component:
kernel-core-5.15.6-200.fc35

Additional info:
reporter:       libreport-2.15.2
cmdline:        BOOT_IMAGE=(hd0,gpt2)/vmlinuz-5.15.6-200.fc35.x86_64 root=UUID=129a2028-cf20-4724-91a7-5e23dc4db6db ro rootflags=subvol=root rhgb quiet
crash_function: radeon_bo_unref
kernel:         5.15.6-200.fc35.x86_64
runlevel:       unknown
type:           Kerneloops

Truncated backtrace:
WARNING: CPU: 2 PID: 1207 at drivers/gpu/drm/radeon/radeon_object.c:83 radeon_ttm_bo_destroy+0xde/0xf0 [radeon]
Modules linked in: apple_mfi_fastcharge uas usb_storage ib_core nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast rfcomm snd_seq_dummy snd_hrtimer uinput bnep nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security ip_set nf_tables nfnetlink ip6table_filter ip6_tables iptable_filter qrtr ns sunrpc vfat fat squashfs loop ath3k btusb btrtl btbcm rtsx_usb_ms btintel memstick uvcvideo bluetooth videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 videobuf2_common videodev mc ecdh_generic intel_rapl_msr intel_rapl_common x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel mei_hdcp at24 iTCO_wdt intel_pmc_bxt iTCO_vendor_support kvm ath9k ath9k_common ath9k_hw snd_hda_codec_conexant snd_hda_codec_generic mac80211 ledtrig_audio
 snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi irqbypass snd_hda_codec libarc4 rapl snd_hda_core intel_cstate intel_uncore snd_hwdep ath snd_seq snd_seq_device joydev snd_pcm i2c_i801 i2c_smbus pcspkr cfg80211 mei_me mei snd_timer lpc_ich snd soundcore ideapad_laptop sparse_keymap platform_profile rfkill wmi binfmt_misc zram ip_tables amdgpu iommu_v2 gpu_sched i915 radeon rtsx_usb_sdmmc mmc_core crct10dif_pclmul crc32_pclmul crc32c_intel drm_ttm_helper i2c_algo_bit ttm drm_kms_helper ghash_clmulni_intel cec drm serio_raw r8169 rtsx_usb video fuse ipmi_devintf ipmi_msghandler
CPU: 2 PID: 1207 Comm: Xorg Not tainted 5.15.6-200.fc35.x86_64 #1
Hardware name: LENOVO 20351/Lancer 5A2, BIOS 9ACN32WW 07/20/2015
RIP: 0010:radeon_ttm_bo_destroy+0xde/0xf0 [radeon]
Code: 00 00 00 74 0f 48 8b b5 b0 01 00 00 48 89 ef e8 58 f7 e4 ff 48 89 ef e8 50 02 e4 ff 4c 89 e7 5b 5d 41 5c 41 5d e9 52 df d5 dc <0f> 0b eb cd 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 0f 1f 44 00
RSP: 0018:ffffb2cbc0b47d20 EFLAGS: 00010287
RAX: ffff8c149eabaa70 RBX: ffffffffffffffff RCX: 0000000000100008
RDX: ffff8c1482a27200 RSI: ffff8c149eaba800 RDI: ffff8c148bcbdca8
RBP: ffff8c149eaba878 R08: ffff8c148bcbdcc8 R09: 0000000000100008
R10: 0000000040000000 R11: 0000000169c70000 R12: ffff8c149eaba800
R13: ffff8c148ac28330 R14: ffff8c148ac28240 R15: ffff8c14ce3b9dd0
FS:  0000000000000000(0000) GS:ffff8c15c7280000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa4fd169734 CR3: 000000002ae10006 CR4: 00000000001706e0
Call Trace:
 <TASK>
 radeon_bo_unref+0x1a/0x30 [radeon]
 radeon_gem_object_free+0x20/0x30 [radeon]
 drm_gem_object_release_handle+0x6b/0x80 [drm]
 ? drm_gem_object_handle_put_unlocked+0xd0/0xd0 [drm]
 idr_for_each+0x4e/0xc0
 drm_gem_release+0x1c/0x30 [drm]
 drm_file_free.part.0+0x1e3/0x250 [drm]
 drm_release+0x65/0x110 [drm]
 __fput+0x94/0x250
 task_work_run+0x65/0xa0
 do_exit+0x338/0xa90
 do_group_exit+0x33/0xa0
 __x64_sys_exit_group+0x14/0x20
 do_syscall_64+0x3b/0x90
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fa4fd9795a1
Code: Unable to access opcode bytes at RIP 0x7fa4fd979577.
RSP: 002b:00007ffd5f9d3538 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007fa4fda98510 RCX: 00007fa4fd9795a1
RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000000
RBP: 0000000000000000 R08: fffffffffffffc78 R09: 0000000000000000
R10: 00007fa4fd8a5e88 R11: 0000000000000246 R12: 00007fa4fda98510
R13: 0000000000000000 R14: 00007fa4fda989e8 R15: 00007fa4fda98a00
 </TASK>

Comment 8 Samuel Ricaro 2021-12-21 05:30:01 UTC
*** Bug 2034485 has been marked as a duplicate of this bug. ***

Comment 9 epixtoxin 2022-06-30 23:17:50 UTC
*** Bug 2102891 has been marked as a duplicate of this bug. ***

Comment 10 chinasee 2022-07-08 16:04:48 UTC
Description of problem:
restart and login

Version-Release number of selected component:
kernel-core-5.18.9-100.fc35

Additional info:
reporter:       libreport-2.15.2
cmdline:        BOOT_IMAGE=(hd1,gpt2)/vmlinuz-5.18.9-100.fc35.x86_64 root=UUID=779e039d-8bc1-4650-8e27-be6b03023d26 ro rootflags=subvol=root rhgb quiet
crash_function: radeon_bo_unref
kernel:         5.18.9-100.fc35.x86_64
runlevel:       N 5
type:           Kerneloops

Truncated backtrace:
#1 [TASK] radeon_bo_unref in radeon
#2 [TASK] radeon_gem_object_free in radeon
#3 [TASK] drm_gem_object_release_handle in drm
#4 [TASK] ? drm_gem_object_handle_put_unlocked in drm
#5 [TASK] idr_for_each
#6 [TASK] drm_gem_release in drm
#7 [TASK] drm_file_free in drm
#8 [TASK] drm_release in drm
#9 [TASK] __fput
#10 [TASK] task_work_run

Comment 11 Ben Cotton 2022-11-29 17:18:49 UTC
This message is a reminder that Fedora Linux 35 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 35 on 2022-12-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '35'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'version' 
to a later Fedora Linux version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora Linux 35 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora Linux, you are encouraged to change the 'version' to a later version
prior to this bug being closed.

Comment 12 Ben Cotton 2022-12-13 15:52:03 UTC
Fedora Linux 35 entered end-of-life (EOL) status on 2022-12-13.

Fedora Linux 35 is no longer maintained, which means that it
will not receive any further security or bug fix updates. As a result we
are closing this bug.

If you can reproduce this bug against a currently maintained version of Fedora Linux
please feel free to reopen this bug against that version. Note that the version
field may be hidden. Click the "Show advanced fields" button if you do not see
the version field.

If you are unable to reopen this bug, please file a new report against an
active release.

Thank you for reporting this bug and we are sorry it could not be fixed.