Description of problem: This is a reproducible bug for me. Everytime I shut down, it crashes, forcing me to do a hard shutdown. Not certain on the details, but if anyone needs more information, I'll gladly try to provide it! Additional info: reporter: libreport-2.6.2 kernel BUG at mm/slub.c:3413! invalid opcode: 0000 [#1] SMP Modules linked in: uinput uas usb_storage rfcomm fuse hidp cmac xt_CHECKSUM ipt_MASQUERADE nf_nat_masquerade_ipv4 tun nf_conntrack_netbios_ns nf_conntrack_broadcast ip6t_rpfilter ccm ip6t_REJECT nf_reject_ipv6 xt_conntrack ebtable_nat ebtable_broute bridge ebtable_filter ebtables ip6table_nat nf_conntrack_ipv6 nf_defrag_ipv6 nf_nat_ipv6 ip6table_mangle ip6table_security ip6table_raw ip6table_filter ip6_tables iptable_nat nf_conntrack_ipv4 nf_defrag_ipv4 nf_nat_ipv4 nf_nat nf_conntrack iptable_mangle iptable_security iptable_raw bnep vfat fat uvcvideo arc4 hp_wmi sparse_keymap videobuf2_vmalloc videobuf2_core videobuf2_memops ath9k btusb btbcm btintel v4l2_common kvm_amd snd_hda_codec_realtek ath9k_common ath9k_hw videodev bluetooth snd_hda_codec_generic snd_hda_codec_hdmi kvm media snd_hda_intel snd_hda_controller snd_hda_codec ath snd_hda_core mac80211 snd_hwdep snd_seq snd_seq_device snd_pcm cfg80211 snd_timer rtsx_pci_ms memstick rfkill k10temp wmi hp_wireless snd shpchp soundcore i2c_piix4 video acpi_cpufreq nfsd auth_rpcgss nfs_acl lockd grace sunrpc dm_crypt amdkfd amd_iommu_v2 radeon rtsx_pci_sdmmc mmc_core 8021q garp stp llc mrp r8169 rtsx_pci i2c_algo_bit drm_kms_helper serio_raw mfd_core ttm mii drm CPU: 0 PID: 2181 Comm: gnome-shell Not tainted 4.1.3-201.fc22.x86_64 #1 Hardware name: Hewlett-Packard HP 2000 Notebook PC/188B, BIOS F.37 06/26/2013 task: ffff8800ba639da0 ti: ffff8800d38b8000 task.ti: ffff8800d38b8000 RIP: 0010:[<ffffffff8120b9b2>] [<ffffffff8120b9b2>] kfree+0x152/0x160 RSP: 0018:ffff8800d38bb998 EFLAGS: 00010246 RAX: 003ffff800000000 RBX: ffff8800bac7c000 RCX: ffff8800adec7100 RDX: 000077ff80000000 RSI: ffff8800bac7c2d8 RDI: ffff8800bac7c000 RBP: ffff8800d38bb9b8 R08: ffff8800bac7c000 R09: ffffea0002eb1f00 R10: ffff880101428c00 R11: 0000000000100000 R12: ffff8800bac7c000 R13: ffffffffa012e18e R14: 0000000000000000 R15: ffff8801014283c0 FS: 00007f3c96ed1a40(0000) GS:ffff880106c00000(0000) knlGS:00000000f7269940 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f6c77139000 CR3: 0000000001c0b000 CR4: 00000000000007f0 Stack: ffff8800d38bb9b8 ffff8800bac7c068 ffff8800bac7c000 ffffffffffffffff ffff8800d38bb9e8 ffffffffa012e18e ffff8800bac7c09c ffff8800d75dc738 0000000000002480 0000000000000000 ffff8800d38bba28 ffffffffa00531d6 Call Trace: [<ffffffffa012e18e>] radeon_ttm_bo_destroy+0xce/0x100 [radeon] [<ffffffffa00531d6>] ttm_bo_release_list+0xa6/0x1a0 [ttm] [<ffffffffa0053635>] ttm_bo_release+0x1a5/0x250 [ttm] [<ffffffffa005370d>] ttm_bo_unref+0x2d/0x30 [ttm] [<ffffffffa012e6f9>] radeon_bo_unref+0x39/0x70 [radeon] [<ffffffffa0143e6b>] radeon_gem_object_free+0x4b/0x70 [radeon] [<ffffffffa0004417>] drm_gem_object_free+0x27/0x40 [drm] [<ffffffffa00049a8>] drm_gem_object_handle_unreference_unlocked+0x118/0x130 [drm] [<ffffffffa0004b37>] drm_gem_object_release_handle+0x57/0x80 [drm] [<ffffffff813ad94c>] idr_for_each+0xbc/0x120 [<ffffffffa0004ae0>] ? drm_gem_dumb_destroy+0x20/0x20 [drm] [<ffffffffa0005484>] drm_gem_release+0x24/0x40 [drm] [<ffffffffa000422b>] drm_release+0x3bb/0x4a0 [drm] [<ffffffff8122cb3c>] __fput+0xdc/0x1f0 [<ffffffff8122cc9e>] ____fput+0xe/0x10 [<ffffffff810bef84>] task_work_run+0xc4/0xe0 [<ffffffff810a3f2b>] do_exit+0x3bb/0xb30 [<ffffffff810a4737>] do_group_exit+0x47/0xb0 [<ffffffff810b052c>] get_signal+0x27c/0x610 [<ffffffff810d7bd4>] ? set_next_entity+0x74/0x440 [<ffffffff81014537>] do_signal+0x37/0x780 [<ffffffff810dee61>] ? pick_next_task_fair+0x7e1/0x980 [<ffffffff810136d6>] ? __switch_to+0x216/0x5d0 [<ffffffff8179d571>] ? __schedule+0x241/0x720 [<ffffffff81014cff>] do_notify_resume+0x7f/0xa0 [<ffffffff817a271e>] retint_signal+0x44/0x86 Code: 4c 89 cf e8 71 96 fa ff eb 8d 0f 1f 80 00 00 00 00 4c 89 d1 48 89 da 4c 89 ce e8 ca f9 ff ff e9 73 ff ff ff 0f 1f 44 00 00 0f 0b <0f> 0b 66 66 66 2e 0f 1f 84 00 00 00 00 00 66 66 66 66 90 55 48 RIP [<ffffffff8120b9b2>] kfree+0x152/0x160 RSP <ffff8800d38bb998>
Created attachment 1060888 [details] File: dmesg
Same here under Fedora 21 and 4.1.4-100. http://img.lampin.net/images/2015/08/17/P20150814180715.jpg i've got another oops when sometimes when I switched between console and desktop (Ctrl + Alt + F1/F2). I don't know if it's related or if I need to open a new ticket. http://img.lampin.net/images/2015/08/17/P201508142218078SqIf.jpg After downgrading to 3.17, everything works fine.
Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.