Bug 505419

Summary: kernel panic in kernel-xen on intel tylersburg platform.
Product: Red Hat Enterprise Linux 5 Reporter: Gurhan Ozen <gozen>
Component: kernel-xenAssignee: Herbert Xu <herbert.xu>
Status: CLOSED DUPLICATE QA Contact: Red Hat Kernel QE team <kernel-qe>
Severity: high Docs Contact:
Priority: high    
Version: 5.4CC: haicheng.li, jburke, xen-maint
Target Milestone: betaKeywords: Regression
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-06-16 13:57:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Gurhan Ozen 2009-06-11 20:31:56 UTC
Description of problem:
----------- [cut here ] --------- [please bite here ] ---------
Kernel BUG at drivers/xen/netback/loopback.c:100
invalid opcode: 0000 [1] SMP 
last sysfs file: /class/net/eth0/address
CPU 0 
Modules linked in: ipt_MASQUERADE iptable_nat ip_nat xt_state ip_conntrack nfnetlink ipt_REJECT xt_tcpudp iptable_filter ip_tables netloop x_tables netbk blktap blkbk bridge autofs4 hidp rfcomm l2cap bluetooth lockd sunrpc ipv6 xfrm_nalgo crypto_api ib_iser rdma_cm ib_cm iw_cm ib_sa ib_mad ib_core ib_addr iscsi_tcp libiscsi_tcp libiscsi2 scsi_transport_iscsi2 scsi_transport_iscsi cpufreq_ondemand acpi_cpufreq freq_table dm_multipath scsi_dh video hwmon backlight sbs i2c_ec button battery asus_acpi ac parport_pc lp parport i2c_i801 sr_mod cdrom igb serio_raw i2c_core 8021q serial_core shpchp sg pcspkr dm_raid45 dm_message dm_region_hash dm_mem_cache dm_snapshot dm_zero dm_mirror dm_log dm_mod ahci libata sd_mod scsi_mod ext3 jbd uhci_hcd ohci_hcd ehci_hcd
Pid: 0, comm: swapper Not tainted 2.6.18-152.el5xen #1
RIP: e030:[<ffffffff885c00c6>]  [<ffffffff885c00c6>] :netloop:loopback_start_xmit+0x20/0x2f6
RSP: e02b:ffffffff8067cc90  EFLAGS: 00010282
RAX: ffff8805c44d7c80 RBX: ffff8805c8acea80 RCX: 0000000000000022
RDX: 0000000000000022 RSI: ffff8805c5bd5000 RDI: ffff8805c8acea80
RBP: ffff8805c5bd5000 R08: 0000000000000000 R09: ffffffff88543cea
R10: 0000000080000000 R11: ffffffff885c00a6 R12: ffff8805c5bd5200
R13: ffff8805c5bd5500 R14: 0000000000000000 R15: 0000000000000000
FS:  00002b0b920f7190(0000) GS:ffffffff805c9000(0000) knlGS:0000000000000000
CS:  e033 DS: 0000 ES: 0000
Process swapper (pid: 0, threadinfo ffffffff8063a000, task ffffffff804edb00)
Stack:  ffff8805c8acea80  ffff8805c5bd5000  ffff8805c5bd5200  ffff8805c44d7c22 
 0000000000000000  ffffffff802314e6  ffff8805c8acea80  ffff8805b98e5500 
 ffff8805c8acea80  ffffffff88543e8e 
Call Trace:
 <IRQ>  [<ffffffff802314e6>] dev_queue_xmit+0x2d4/0x395
 [<ffffffff88543e8e>] :bridge:br_dev_queue_push_xmit+0x1a4/0x1cb
 [<ffffffff88543f04>] :bridge:br_forward_finish+0x4f/0x51
 [<ffffffff88543f70>] :bridge:__br_forward+0x6a/0x6d
 [<ffffffff885449c2>] :bridge:br_handle_frame_finish+0xd4/0xf8
 [<ffffffff88544b6b>] :bridge:br_handle_frame+0x185/0x1a2
 [<ffffffff8043ede7>] tcp_gro_receive+0x1b5/0x233
 [<ffffffff802216fe>] netif_receive_skb+0x328/0x3f2
 [<ffffffff80419dcc>] dev_gro_receive+0xf0/0x209
 [<ffffffff80419fdd>] napi_gro_receive+0x20/0x2f
 [<ffffffff8820c9ac>] :igb:igb_poll+0x494/0x960
 [<ffffffff8020d53a>] net_rx_action+0xa8/0x1c1
 [<ffffffff8820b9c9>] :igb:igb_xmit_frame_adv+0x0/0x6e2
 [<ffffffff8021339c>] __do_softirq+0x8d/0x13b
 [<ffffffff80260da4>] call_softirq+0x1c/0x278
 [<ffffffff8026e0c7>] do_softirq+0x31/0x98
 [<ffffffff8026df53>] do_IRQ+0xec/0xf5
 [<ffffffff803aecbb>] evtchn_do_upcall+0x13b/0x1fb
 [<ffffffff802608d6>] do_hypervisor_callback+0x1e/0x2c
 <EOI>  [<ffffffff802063aa>] hypercall_page+0x3aa/0x1000
 [<ffffffff802063aa>] hypercall_page+0x3aa/0x1000
 [<ffffffff802999bf>] rcu_pending+0x26/0x50
 [<ffffffff8026f4f1>] raw_safe_halt+0x84/0xa8
 [<ffffffff8026ca6c>] xen_idle+0x38/0x4a
 [<ffffffff8024b130>] cpu_idle+0x97/0xba
 [<ffffffff80644b09>] start_kernel+0x21f/0x224
 [<ffffffff806441e5>] _sinittext+0x1e5/0x1eb


Code: 0f 0b 68 3f 04 5c 88 c2 64 00 f6 83 9c 00 00 00 02 74 20 8b 
RIP  [<ffffffff885c00c6>] :netloop:loopback_start_xmit+0x20/0x2f6
 RSP <ffffffff8067cc90>
 <0>Kernel panic - not syncing: Fatal exception
 (XEN) Domain 0 crashed: rebooting machine in 5 seconds.




Version-Release number of selected component (if applicable):
RHEL5.4-Server-20090608.0 tree 
It was on this box: http://lab.rhts.bos.redhat.com/cgi-bin/rhts/system.cgi?id=1106

How reproducible:
Very.

Steps to Reproduce:
1. Just install and boot on the said box. It seems like installation went fine but when booting during the rhts service startup time , it'd panicking.
2.
3.
  
Actual results:


Expected results:


Additional info:

Comment 2 Herbert Xu 2009-06-16 11:21:53 UTC
This is the same crash that Don saw earlier.  The patch is already posted.

Comment 3 Herbert Xu 2009-06-16 13:56:20 UTC
Should be fixed in -153 in fact.

Comment 4 Herbert Xu 2009-06-16 13:57:15 UTC

*** This bug has been marked as a duplicate of bug 499347 ***

Comment 5 Herbert Xu 2009-06-23 01:33:38 UTC
*** Bug 507189 has been marked as a duplicate of this bug. ***