Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1167231

Summary: [virtio-win][balloon]BSOD occurs when reboot guest after enlarging memory during runtime
Product: Red Hat Enterprise Linux 7 Reporter: Mike Cao <bcao>
Component: virtio-winAssignee: Gal Hammer <ghammer>
Status: CLOSED ERRATA QA Contact: Virtualization Bugs <virt-bugs>
Severity: high Docs Contact:
Priority: high    
Version: 7.1CC: amit.shah, bcao, ghammer, hhuang, michen, ovasik, rbalakri, shuyu, tlavigne, virt-maint, vrozenfe
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: virtio-win-prewhql-0.1-96 Doc Type: Bug Fix
Doc Text:
Cause: BSOD occurs when reboot guest after enlarging memory during runtime. Consequence: SYSTEM_THREAD_EXCEPTION_NOT_HANDLED BSOD will happen when rebooting VM after deflating balloon. Fix: stop service on shutdown notification Result: Now, after enlarging memory during runtime, VM can be rebooted without falling into BSOD.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-03-05 05:34:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mike Cao 2014-11-24 09:24:44 UTC
Description of problem:


Version-Release number of selected component (if applicable):
3.10.0-208.el7.x86_64
qemu-kvm-rhev-2.1.2-12.el7.x86_64
seabios-1.7.5-5.el7.x86_64
virtio-win-prewhql-94

How reproducible:
100%

Steps to Reproduce:
1. Start guest with virtio-balloon-pci,
CLI:usr/libexec/qemu-kvm -name 094BLNWIN732O97 -enable-kvm -m 2G -smp 2 -uuid 6ab29e95-4044-42e2-ad69-76fc352a2099 -nodefconfig -nodefaults -chardev socket,id=charmonitor,path=/tmp/094BLNWIN732O97,server,nowait -mon chardev=charmonitor,id=monitor,mode=control -rtc base=localtime,driftfix=slew -boot order=cd,menu=on -device piix3-usb-uhci,id=usb,bus=pci.0,addr=0x1.0x2 -drive file=094BLNWIN732O97,if=none,id=drive-ide0-0-0,format=raw,serial=mike_cao,cache=none -device ide-drive,bus=ide.0,unit=0,drive=drive-ide0-0-0,id=ide0-0-0 -drive file=en_windows_7_ultimate_with_sp1_x86_dvd_u_677460.iso,if=none,media=cdrom,id=drive-ide0-1-0,readonly=on,format=raw -device ide-drive,bus=ide.1,unit=0,drive=drive-ide0-1-0,id=ide0-1-0 -drive file=094BLNWIN732O97.vfd,if=none,id=drive-fdc0-0-0,format=raw,cache=none -global isa-fdc.driveA=drive-fdc0-0-0 -netdev tap,script=/etc/qemu-ifup,downscript=no,id=hostnet0 -device rtl8139,netdev=hostnet0,id=net0,mac=00:52:26:58:da:1b,bus=pci.0,addr=0x3 -chardev pty,id=charserial0 -device isa-serial,chardev=charserial0,id=isa_serial0 -device usb-tablet,id=input0 -vnc 0.0.0.0:0 -vga cirrus -device virtio-balloon-pci,id=balloon0,bus=pci.0,addr=0x7
2.Using #verifier /querysettings in the guest to check whether balloon.sys verifier enabled 
If No ,pls exec # verifier.exe /standard /driver balloon.sys , then reboot the guest and recheck #verifier /querysettings 
3. balloon guest memory to 400MB
on the host #nc 0 4444
{"execute":"qmp_capabilities"}
{"execute":"balloon","arguments":{"value":419430400}}
4. After step3 ,balloon guest memory to max
{"execute":"balloon","arguments":{"value":8589934592}}
5. During step4,reboot guest
eg: start --->reboot

Actual results:
BSOD occurs 

Expected results:
no BSOD happened

Additional info:

Comment 1 Mike Cao 2014-11-24 09:36:31 UTC
0: kd> !analyze -v 
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: 80000003, The exception code that was not handled
Arg2: 8267b118, The address that the exception occurred at
Arg3: 821e99fc, Exception Record Address
Arg4: 821e95e0, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (HRESULT) 0x80000003 (2147483651) - One or more arguments are invalid

FAULTING_IP: 
nt!DbgBreakPoint+0
8267b118 cc              int     3

EXCEPTION_RECORD:  821e99fc -- (.exr 0xffffffff821e99fc)
ExceptionAddress: 8267b118 (nt!DbgBreakPoint)
   ExceptionCode: 80000003 (Break instruction exception)
  ExceptionFlags: 00000000
NumberParameters: 3
   Parameter[0]: 00000000
   Parameter[1]: 87190d48
   Parameter[2]: 00000065

CONTEXT:  821e95e0 -- (.cxr 0xffffffff821e95e0;r)
eax=8ae18bd8 ebx=00000000 ecx=00000000 edx=00000065 esi=82676d3c edi=00000102
eip=8267b118 esp=821e9ac4 ebp=821e9ae0 iopl=0         nv up ei pl nz na po nc
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00000202
nt!DbgBreakPoint:
8267b118 cc              int     3
Last set context:
eax=8ae18bd8 ebx=00000000 ecx=00000000 edx=00000065 esi=82676d3c edi=00000102
eip=8267b118 esp=821e9ac4 ebp=821e9ae0 iopl=0         nv up ei pl nz na po nc
cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00000202
nt!DbgBreakPoint:
8267b118 cc              int     3
Resetting default scope

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

BUGCHECK_STR:  0x7E

PROCESS_NAME:  System

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0x80000003 - {EXCEPTION}  Breakpoint  A breakpoint has been reached.

EXCEPTION_PARAMETER1:  00000000

EXCEPTION_PARAMETER2:  87190d48

EXCEPTION_PARAMETER3:  00000065

ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre

LAST_CONTROL_TRANSFER:  from 84868c57 to 8267b118

STACK_TEXT:  
821e9ac0 84868c57 8ae13d28 8ae13b70 00000000 nt!DbgBreakPoint
821e9ae0 848584af 8ae13d28 8487ed18 751ec488 Wdf01000!_FX_DRIVER_GLOBALS::WaitForSignal+0x5e
821e9b00 8485a2a7 00000000 84881370 8ae10d30 Wdf01000!FxIoQueue::StopProcessingForPower+0xcf
821e9b20 84851e61 00000001 821e9b44 8486f1d2 Wdf01000!FxPkgIo::StopProcessingForPower+0xbd
821e9b2c 8486f1d2 8ae187f0 00000001 8ae10d30 Wdf01000!FxDeviceToMx::FxPkgIo_StopProcessingForPower+0x16
821e9b3c 8486fdd1 821e9bcc 8486ed81 8ae10d30 Wdf01000!FxPkgPnp::PowerGotoDx+0x3f
821e9b44 8486ed81 8ae10d30 8ae10e3c 8ae10d30 Wdf01000!FxPkgPnp::PowerGotoDxArmedForWake+0xd
821e9bcc 8486fbb2 0000031a 8ae10e3c 8ae10d30 Wdf01000!FxPkgPnp::PowerEnterNewState+0x11c
821e9bf0 848705bb 821e9c08 8ae18bd8 8ae10d30 Wdf01000!FxPkgPnp::PowerProcessEventInner+0x171
821e9c14 84878d61 00000001 8ae10d30 821e9c34 Wdf01000!FxPkgPnp::PowerProcessEvent+0x15c
821e9c24 84878fa1 821e9c68 8ae10d30 821e9c40 Wdf01000!FxPkgFdo::LowerDevicePower+0x19
821e9c34 84878fce 821e9c68 821e9c60 8486ce02 Wdf01000!FxPkgFdo::DispatchDeviceSetPower+0x9d
821e9c40 8486ce02 8ae10d30 821e9c68 8cfd4eb8 Wdf01000!FxPkgFdo::_DispatchSetPower+0x23
821e9c60 84849a3f 8cfd4eb8 821e9c88 84849c63 Wdf01000!FxPkgPnp::Dispatch+0x207
821e9c6c 84849c63 8ae10580 8cfd4eb8 90e3c210 Wdf01000!FxDevice::Dispatch+0x7f
821e9c88 82616863 8ae10580 8cfd4eb8 887bc616 Wdf01000!FxDevice::DispatchWithLock+0x7b
821e9ca0 829316b3 8cfd4fb0 8ae10580 8cfd4eb8 nt!IopPoHandleIrp+0x28
821e9cbc 8263754a 00000000 8cfd4fd4 8ae10580 nt!IovCallDriver+0x248
821e9cd0 82616cb1 821e9cf8 8294334b 8ae10580 nt!IofCallDriver+0x1b
821e9cd8 8294334b 8ae10580 8cfd4eb8 8ae13870 nt!PoCallDriver+0x10
821e9cf8 82615e6d 8ae13928 8cfd4eb8 00000000 nt!ViFilterDispatchPower+0x5e
821e9d50 82809f5e 8afa4670 a32ac821 00000000 nt!PopIrpWorker+0x351
821e9d90 826b1219 82615b1c 8afa4670 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19


FOLLOWUP_IP: 
Wdf01000!_FX_DRIVER_GLOBALS::WaitForSignal+5e
84868c57 8d45f4          lea     eax,[ebp-0Ch]

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  Wdf01000!_FX_DRIVER_GLOBALS::WaitForSignal+5e

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: Wdf01000

IMAGE_NAME:  Wdf01000.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bbf28

STACK_COMMAND:  .cxr 0xffffffff821e95e0 ; kb

FAILURE_BUCKET_ID:  0x7E_VRF_Wdf01000!_FX_DRIVER_GLOBALS::WaitForSignal+5e

BUCKET_ID:  0x7E_VRF_Wdf01000!_FX_DRIVER_GLOBALS::WaitForSignal+5e

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0x7e_vrf_wdf01000!_fx_driver_globals::waitforsignal+5e

FAILURE_ID_HASH:  {99f37ac0-c074-ae02-8d71-53033d2e83bf}

Followup: MachineOwner
---------

Comment 4 Ronen Hod 2014-11-24 15:25:36 UTC
Mike,
Not sure that this is a good question, but does it work well with Linux guests?

Comment 6 Mike Cao 2014-11-25 03:15:52 UTC
(In reply to Ronen Hod from comment #4)
> Mike,
> Not sure that this is a good question, but does it work well with Linux
> guests?

I can not reproduce it on RHEL7.1-64 , windows 8.1 either
I hit this issue on win7-32 bit guest.

Comment 8 Mike Cao 2014-11-25 05:43:18 UTC
windows 2k8R2 also affected.

QE confirmed that this bug only can be triggered then *balloon service" (blnsvr.exe -i) is started.

Mike

Comment 9 Mike Cao 2014-11-25 06:05:21 UTC
(In reply to Mike Cao from comment #6)
> (In reply to Ronen Hod from comment #4)
> > Mike,
> > Not sure that this is a good question, but does it work well with Linux
> > guests?
> 
> I can not reproduce it on RHEL7.1-64 , windows 8.1 either

Sorry ,I can reproduce it on win8.1 guest .Looks all guests are affected when blnsvr service is running 

Mike
> I hit this issue on win7-32 bit guest.

Comment 10 Shuang Yu 2014-11-25 10:14:30 UTC
win2008R2 guest with virtio-win-1.7.2 balloon driver hit the same issue 

kernel-3.10.0-208.el7.x86_64
qemu-kvm-rhev-2.1.2-12.el7.x86_64
seabios-1.7.5-5.el7.x86_64
virtio-win-1.7.2

Steps:
1.boot the guest with the CLI:
/usr/libexec/qemu-kvm -m 2G -smp 2 -monitor stdio -netdev tap,id=hostnet1,script=/etc/qemu-ifup -device e1000,netdev=hostnet1,id=net1,mac=00:52:54:00:23:54 -usb -device usb-tablet,id=tablet1 -drive file=win2008R2.qcow2,format=qcow2,if=none,id=drive1 -device ide-drive,drive=drive1,id=disk1 -name win2008R2 -uuid de35b3a3-653c-4137-b2c8-083fe49ef60d -vnc :0 -vga cirrus -device virtio-balloon-pci,id=balloon,addr=0x9 -qmp tcp:0:4444,server,nowait -drive file=/usr/share/virtio-win/virtio-win-1.7.2.iso,format=raw,if=none,id=drive2,media=cdrom,readonly=on -device ide-drive,drive=drive2,id=cdrom
2.in the guest, # verifier.exe /standard /driver balloon.sys , then reboot the guest and recheck #verifier /querysettings 
3.install balloon service in guest:
  cmd(run as administrator)
  blnsvr.exe -i
4. balloon guest memory to 400MB
on the host #nc 0 4444
{"execute":"qmp_capabilities"}
{"execute":"balloon","arguments":{"value":1073741824}}
5. After step3 ,balloon guest memory to max
{"execute":"balloon","arguments":{"value":2147483648}}
6. During step5,reboot guest

win2008R2 guest BSOD with 7e code.

Comment 11 Gal Hammer 2014-11-30 09:53:04 UTC
(In reply to Mike Cao from comment #8)
> windows 2k8R2 also affected.
> 
> QE confirmed that this bug only can be triggered then *balloon service"
> (blnsvr.exe -i) is started.
> 
> Mike

Weird. My Windows 7 32-bit with balloon build 94 always BSOD when the verifier is enabled.

Comment 12 Gal Hammer 2014-11-30 14:01:45 UTC
(In reply to Gal Hammer from comment #11)
> (In reply to Mike Cao from comment #8)
> > windows 2k8R2 also affected.
> > 
> > QE confirmed that this bug only can be triggered then *balloon service"
> > (blnsvr.exe -i) is started.
> > 
> > Mike
> 
> Weird. My Windows 7 32-bit with balloon build 94 always BSOD when the
> verifier is enabled.

Might be because I didn't install enough from the Windows' updates.

A patch was posted.

Comment 13 Shuang Yu 2014-12-04 10:33:14 UTC
Reproduce this issue with virtio-win-prewhql-94 balloon driver & win7-32 guest,BSOD occurs when reboot guest after enlarging memory during runtime.

Verify this issue with virtio-win-prewhql-96 balloon driver & win7-32 guest,guest can reboot successful after enlarging memory during runtime.

kernel-3.10.0-208.el7.x86_64
qemu-kvm-rhev-2.1.2-12.el7.x86_64
seabios-1.7.5-5.el7.x86_64

Steps:
Reproduce:
1.boot the guest with virtio-win-prewhql-94 balloon driver:
/usr/libexec/qemu-kvm -m 2G -smp 2 -monitor stdio -netdev tap,id=hostnet1,script=/etc/qemu-ifup -device e1000,netdev=hostnet1,id=net1,mac=00:52:54:00:23:54 -usb -device usb-tablet,id=tablet1 -drive file=win7-32.qcow2,format=qcow2,if=none,id=drive1 -device ide-drive,drive=drive1,id=disk1 -name win7-32 -vnc :0 -vga cirrus -device virtio-balloon-pci,id=balloon,addr=0x9 -qmp tcp:0:4455,server,nowait -cdrom en_windows_7_ultimate_x86_dvd_x15-65921.iso -uuid a52f22f7-7439-4b02-8be6-d51ae9b8cec2
2.in the guest, # verifier.exe /standard /driver balloon.sys , then reboot the guest and recheck #verifier /querysettings 
3.install balloon service in guest:
  cmd(run as administrator)
  blnsvr.exe -i
4. balloon guest memory 
on the host #nc 0 4455
{"execute":"qmp_capabilities"}
{"execute":"balloon","arguments":{"value":1073741824}}
5. After step4 ,balloon guest memory to max
{"execute":"balloon","arguments":{"value":2147483648}}
6. During step5,reboot guest
Verify:
7.boot the guest with virtio-win-prewhql-96 balloon driver:
/usr/libexec/qemu-kvm -m 2G -smp 2 -monitor stdio -netdev tap,id=hostnet1,script=/etc/qemu-ifup -device e1000,netdev=hostnet1,id=net1,mac=00:52:54:00:23:54 -usb -device usb-tablet,id=tablet1 -drive file=win7-32-2.qcow2,format=qcow2,if=none,id=drive1 -device ide-drive,drive=drive1,id=disk1 -name win7-32 -vnc :0 -vga cirrus -device virtio-balloon-pci,id=balloon,addr=0x9 -qmp tcp:0:4455,server,nowait -cdrom en_windows_7_ultimate_x86_dvd_x15-65921.iso -uuid a52f22f7-7439-4b02-8be6-d51ae9b8cec2
8.in the guest, # verifier.exe /standard /driver balloon.sys , then reboot the guest and recheck #verifier /querysettings 
9.install balloon service in guest:
  cmd(run as administrator)
  blnsvr.exe -i
10. balloon guest memory
on the host #nc 0 4455
{"execute":"qmp_capabilities"}
{"execute":"balloon","arguments":{"value":1073741824}}
11. After step10 ,balloon guest memory to max
{"execute":"balloon","arguments":{"value":2147483648}}
12. During step11,reboot guest

Actual Result:
after step6,the guest BSOD with 7e code.
after step12,the guest can reboot successful.

Comment 15 Mike Cao 2015-01-17 03:13:29 UTC
Move to Verified according to comment#13

Anyone can help to grant rhel7.1.0+ ?

Comment 18 errata-xmlrpc 2015-03-05 05:34:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2015-0289.html