Bug 2221858 - [abrt] __die: BUG: kernel NULL pointer dereference, address: 000000000000070e
Summary: [abrt] __die: BUG: kernel NULL pointer dereference, address: 000000000000070e
Keywords:
Status: CLOSED COMPLETED
Alias: None
Product: Fedora
Classification: Fedora
Component: kernel
Version: 38
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Kernel Maintainer List
QA Contact: Fedora Extras Quality Assurance
URL: https://retrace.fedoraproject.org/faf...
Whiteboard: abrt_hash:7f42448fba974a8c70b6050c874...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-11 06:00 UTC by Max Chernoff
Modified: 2023-07-24 07:16 UTC (History)
19 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-07-24 07:16:15 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: dmesg (116.80 KB, text/plain)
2023-07-11 06:00 UTC, Max Chernoff
no flags Details

Description Max Chernoff 2023-07-11 06:00:07 UTC
Description of problem:
I rebooted my computer, gdm opened, and I was halfway through typing my password when the screen froze. Neither Alt-F{1-6} nor Alt+SysRq+{reisubk} had any effect, so I had to hold the power button to force a reboot.

Additional info:
reporter:       libreport-2.17.11
BUG: kernel NULL pointer dereference, address: 000000000000070e
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 5 PID: 691 Comm: kworker/5:2 Not tainted 6.3.11-200.fc38.x86_64 #1
Hardware name: HP OMEN by HP Laptop 16-c0xxx/8902, BIOS F.11 09/01/2021
RIP: 0010:wq_worker_running+0xe/0x50
Code: 1c 6b 00 83 f0 01 e9 40 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 e8 d2 60 00 00 <8b> 50 70 85 d2 74 20 65 ff 05 6c bb ef 4e f7 40 68 c8 01 00 00 74
RSP: 0018:ffffb96c01307ed8 EFLAGS: 00010202
RAX: 000000000000069e RBX: ffff93ab06cc4900 RCX: 0000000000000002
RDX: 0000000000000000 RSI: 0000000055555554 RDI: ffff93ab0e7a28c0
RBP: ffff93ae0e773440 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000110 R12: ffff93ab06cc4930
R13: ffff93ae0e773468 R14: ffff93ab0e7a28c0 R15: ffff93ae0e773440
FS:  0000000000000000(0000) GS:ffff93ae0e740000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000000070e CR3: 000000016adba000 CR4: 0000000000750ee0
PKRU: 55555554
Call Trace:
 <TASK>
 ? __die+0x23/0x70
 ? page_fault_oops+0x171/0x4e0
 ? exc_page_fault+0x7c/0x180
 ? asm_exc_page_fault+0x26/0x30
 ? wq_worker_running+0xe/0x50
 ? wq_worker_running+0xe/0x50
 worker_thread+0xb3/0x390
 ? __pfx_worker_thread+0x10/0x10
 kthread+0xde/0x110
 ? __pfx_kthread+0x10/0x10
 ret_from_fork+0x2c/0x50
 </TASK>
Modules linked in: rfcomm snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink qrtr bnep sunrpc binfmt_misc iwlmvm snd_soc_dmic snd_acp3x_pdm_dma snd_acp3x_rn snd_sof_amd_rembrandt snd_sof_amd_renoir snd_sof_amd_acp mac80211 snd_sof_pci snd_sof_xtensa_dsp snd_sof snd_ctl_led snd_hda_codec_realtek snd_sof_utils snd_hda_codec_generic libarc4 ledtrig_audio snd_soc_core snd_hda_codec_hdmi snd_hda_intel intel_rapl_msr vfat snd_intel_dspcfg intel_rapl_common snd_intel_sdw_acpi fat snd_hda_codec iwlwifi edac_mce_amd snd_compress uvcvideo snd_hda_core ac97_bus btusb snd_pcm_dmaengine snd_hwdep uvc snd_pci_ps kvm_amd btrtl btbcm videobuf2_vmalloc snd_seq videobuf2_memops btintel videobuf2_v4l2 snd_rpl_pci_acp6x snd_pci_acp6x snd_seq_device videobuf2_common btmtk kvm cfg80211 snd_pci_acp5x
 bluetooth snd_pcm snd_rn_pci_acp3x videodev irqbypass snd_acp_config hp_wmi snd_timer snd_soc_acpi sparse_keymap platform_profile snd mc rapl wmi_bmof i2c_piix4 pcspkr snd_pci_acp3x k10temp rfkill soundcore acpi_cpufreq acpi_tad joydev loop zram amdgpu ccp hid_logitech_hidpp i2c_algo_bit drm_ttm_helper ttm iommu_v2 drm_buddy nvme gpu_sched sdhci_pci nvme_core cqhci drm_display_helper crct10dif_pclmul sdhci crc32_pclmul crc32c_intel polyval_clmulni video ucsi_acpi polyval_generic hid_multitouch mmc_core typec_ucsi ghash_clmulni_intel r8169 sha512_ssse3 cec typec sp5100_tco nvme_common i2c_hid_acpi wmi i2c_hid serio_raw hid_logitech_dj ip6_tables ip_tables fuse
CR2: 000000000000070e

Potential duplicate: bug 2089019

Comment 1 Max Chernoff 2023-07-11 06:00:12 UTC
Created attachment 1975084 [details]
File: dmesg

Comment 2 Max Chernoff 2023-07-11 06:04:32 UTC
I've also seen https://retrace.fedoraproject.org/faf/reports/751122/ a few times, starting a couple of days ago. Possibly related?

Comment 3 Igor Krasnyukov 2023-07-11 14:26:09 UTC
Description of problem:
I guess this is a problem introduced in 6.3.x kernel version. It is usial occuring while booting too.
Laptop is just deadly freezing or unable to boot at all.

Version-Release number of selected component:
kernel-core-6.3.11-200.fc38

Additional info:
reporter:       libreport-2.17.11
runlevel:       N 5
kernel:         6.3.11-200.fc38.x86_64
crash_function: __die
package:        kernel-core-6.3.11-200.fc38
cmdline:        BOOT_IMAGE=(hd0,gpt2)/vmlinuz-6.3.11-200.fc38.x86_64 root=UUID=9190e9cc-a32c-4c37-8f6c-6935bdc919b2 ro rhgb quiet module_blacklist=ucsi_acpi
reason:         BUG: kernel NULL pointer dereference, address: 0000000000000184
type:           Kerneloops

Truncated backtrace:
BUG: kernel NULL pointer dereference, address: 0000000000000184
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 550 Comm: kworker/1:12 Not tainted 6.3.11-200.fc38.x86_64 #1
Hardware name: Acer Aspire A315-42/Sleepy_PK, BIOS V1.10 06/23/2020
RIP: 0010:wq_worker_running+0xe/0x50
Code: 1c 6b 00 83 f0 01 e9 40 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 e8 d2 60 00 00 <8b> 50 70 85 d2 74 20 65 ff 05 6c bb ef 54 f7 40 68 c8 01 00 00 74
RSP: 0018:ffffb52d0143fed8 EFLAGS: 00010202
RAX: 0000000000000114 RBX: ffff97bc4e53b240 RCX: 0000000000000002
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff97bc42ab8000
RBP: ffff97be04a73440 R08: 0000000000000014 R09: 000000003152c940
R10: 00000000000051b8 R11: 0000000000000000 R12: ffff97bc4e53b270
R13: ffff97be04a73468 R14: ffff97bc42ab8000 R15: ffff97be04a73440
FS:  0000000000000000(0000) GS:ffff97be04a40000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000184 CR3: 0000000132970000 CR4: 00000000003506e0
Call Trace:
 <TASK>
 ? __die+0x23/0x70
 ? page_fault_oops+0x171/0x4e0
 ? exc_page_fault+0x7c/0x180
 ? asm_exc_page_fault+0x26/0x30
 ? wq_worker_running+0xe/0x50
 ? wq_worker_running+0xe/0x50
 worker_thread+0xb3/0x390
 ? __pfx_worker_thread+0x10/0x10
 kthread+0xde/0x110
 ? __pfx_kthread+0x10/0x10
 ret_from_fork+0x2c/0x50
 </TASK>
Modules linked in: uinput xt_conntrack xt_MASQUERADE nf_conntrack_netlink xt_addrtype nft_compat br_netfilter bridge stp llc rfcomm snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 overlay ip_set nf_tables nfnetlink qrtr bnep sunrpc ath10k_pci ath10k_core snd_sof_amd_rembrandt snd_ctl_led snd_sof_amd_renoir mac80211 snd_sof_amd_acp snd_sof_pci snd_sof_xtensa_dsp snd_hda_codec_realtek snd_sof snd_hda_codec_generic snd_sof_utils snd_soc_core ledtrig_audio snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_compress intel_rapl_msr snd_hda_codec btusb intel_rapl_common uvcvideo ac97_bus snd_pcm_dmaengine snd_pci_ps btrtl snd_hda_core snd_rpl_pci_acp6x btbcm uvc videobuf2_vmalloc videobuf2_memops edac_mce_amd videobuf2_v4l2 libarc4 videobuf2_common snd_pci_acp6x snd_hwdep btintel binfmt_misc ath
 btmtk snd_seq kvm_amd videodev snd_seq_device vfat kvm fat bluetooth snd_pcm cfg80211 mc acer_wmi irqbypass snd_timer rapl sparse_keymap snd_pci_acp5x wmi_bmof snd_rn_pci_acp3x pcspkr k10temp snd_acp_config snd i2c_piix4 snd_soc_acpi snd_pci_acp3x rfkill soundcore acer_wireless acpi_cpufreq joydev loop zram amdgpu i2c_algo_bit drm_ttm_helper crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni ttm nvme polyval_generic hid_multitouch iommu_v2 drm_buddy gpu_sched drm_display_helper ghash_clmulni_intel nvme_core sha512_ssse3 ccp sp5100_tco cec r8169 nvme_common video wmi i2c_hid_acpi i2c_hid serio_raw ip6_tables ip_tables fuse
CR2: 0000000000000184

Comment 4 Max Chernoff 2023-07-11 23:09:42 UTC
I've looked through 5 of the abrt retraces, and all of the affected systems appear to be laptops with AMD processors and Intel AX2xx WiFi. The timing and hardware on all of these matches the upgrades to `iwlwifi-mvm-firmware-20230625-151`, `iwlwifi-dvm-firmware-20230625-151`, `kernel-6.3.11-200`, and `amd-gpu-firmware-20230625-151`.

Considering that this occurred at the exact same as the big transition in the Intel wireless firmware packages, I strongly suspect that those are the cause. 

Maybe related to https://lore.kernel.org/netdev/c65d0837-5e64-bec7-9e56-04aa91148d05@leemhuis.info/T/ ?

@imkrasnyukov, can you try running the following to downgrade the iwl firmware:

```sh
sudo dnf install fedora-repos-archive  # If not already installed

tmp=$(mktemp)
echo "remove $(dnf history info iwlwifi-dvm-firmware | grep 'Install *iwl' | awk '{ORS=" "; print $2}')" >> $tmp
echo "install $(dnf history info iwlwifi-dvm-firmware | grep 'Obsoleted *iwl' | awk '{ORS=" "; print $2}')" >> $tmp
echo "run" >> $tmp

sudo dnf shell --refresh $tmp
```

I've tried this, but the bug is pretty sporadic on my computer so I can't tell if it made any difference quite yet.

Comment 5 Max Chernoff 2023-07-11 23:35:35 UTC
Ok, that didn't work:

Jul 11 17:06:08 kernel: Linux version 6.3.11-200.fc38.x86_64 (mockbuild@375e694195ec4df6b93501f3da7da879) (gcc (GCC) 13.1.1 20230614 (Red Hat 13.1.1-4), GNU ld version 2.39-9.fc38) #1 SMP PREEMPT_DYNAMIC Sun Jul  2 13:17:31 UTC 2023
[...]
Jul 11 17:06:22 kernel: wlo1: authenticate with <AP 1>
Jul 11 17:06:22 kernel: wlo1: send auth to <AP 1> (try 1/3)
Jul 11 17:06:22 kernel: wlo1: authenticated
Jul 11 17:06:22 kernel: wlo1: associate with <AP 1> (try 1/3)
Jul 11 17:06:22 kernel: wlo1: RX AssocResp from <AP 1> (capab=0x11 status=0 aid=4)
Jul 11 17:06:22 kernel: wlo1: associated
Jul 11 17:06:22 kernel: IPv6: ADDRCONF(NETDEV_CHANGE): wlo1: link becomes ready
Jul 11 17:06:25 kernel: rfkill: input handler enabled
Jul 11 17:06:26 kernel: warning: `pool-gnome-shel' uses wireless extensions which will stop working for Wi-Fi 7 hardware; use nl80211
Jul 11 17:06:26 kernel: rfkill: input handler disabled
Jul 11 17:11:34 kernel: wlo1: disconnect from AP <AP 1> for new auth to <AP 2>
Jul 11 17:11:34 kernel: wlo1: authenticate with <AP 2>
Jul 11 17:11:34 kernel: wlo1: send auth to <AP 2> (try 1/3)
Jul 11 17:11:34 kernel: wlo1: authenticated
Jul 11 17:11:34 kernel: wlo1: associate with <AP 2> (try 1/3)
Jul 11 17:11:34 kernel: wlo1: RX ReassocResp from <AP 2> (capab=0x1131 status=0 aid=5)
Jul 11 17:11:34 kernel: wlo1: associated
Jul 11 17:11:34 kernel: wlo1: Limiting TX power to 30 (30 - 0) dBm as advertised by <AP 2>
Jul 11 17:19:57 kernel: BUG: kernel NULL pointer dereference, address: 0000000000000117
Jul 11 17:19:57 kernel: #PF: supervisor read access in kernel mode
Jul 11 17:19:57 kernel: #PF: error_code(0x0000) - not-present page
Jul 11 17:19:57 kernel: PGD 0 P4D 0 
Jul 11 17:19:57 kernel: Oops: 0000 [#1] PREEMPT SMP NOPTI
Jul 11 17:19:57 kernel: CPU: 13 PID: 8359 Comm: kworker/13:2 Not tainted 6.3.11-200.fc38.x86_64 #1
Jul 11 17:19:57 kernel: Hardware name: HP OMEN by HP Laptop 16-c0xxx/8902, BIOS F.11 09/01/2021
Jul 11 17:19:57 kernel: Workqueue: events bpf_prog_free_deferred
Jul 11 17:19:57 kernel: RIP: 0010:refill_obj_stock+0x4c/0x180
Jul 11 17:19:57 kernel: Code: 00 49 c7 c7 00 06 03 00 65 4c 03 3d c6 8d bf 6e 49 39 7f 10 0f 84 9c 00 00 00 4c 89 ff e8 ec f2 ff ff 49 89 c6 e8 64 ab d9 ff <48> 8b 45 00 a8 03 0f 85 c9 00 00 00 65 48 ff 00 e8 df e3 d9 ff 49
Jul 11 17:19:57 kernel: RSP: 0018:ffffac9252b07e20 EFLAGS: 00010002
Jul 11 17:19:57 kernel: RAX: 0000000000000001 RBX: 0000000000000808 RCX: 0000000000000010
Jul 11 17:19:57 kernel: RDX: ffff959ed0b25180 RSI: 000000000000000d RDI: ffff959ed0b25180
Jul 11 17:19:57 kernel: RBP: 0000000000000117 R08: ffff959d0097e001 R09: 0000000000000000
Jul 11 17:19:57 kernel: R10: ffffffff93323120 R11: 0000000000000030 R12: 0000000000000202
Jul 11 17:19:57 kernel: R13: ffffffff912ae7eb R14: ffff959d36e0cb00 R15: ffff95a00e970600
Jul 11 17:19:57 kernel: FS:  0000000000000000(0000) GS:ffff95a00e940000(0000) knlGS:0000000000000000
Jul 11 17:19:57 kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Jul 11 17:19:57 kernel: CR2: 0000000000000117 CR3: 00000003ef022000 CR4: 0000000000750ee0
Jul 11 17:19:57 kernel: PKRU: 55555554
Jul 11 17:19:57 kernel: Call Trace:
Jul 11 17:19:57 kernel:  <TASK>
Jul 11 17:19:57 kernel:  ? __die+0x23/0x70
Jul 11 17:19:57 kernel:  ? page_fault_oops+0x171/0x4e0
Jul 11 17:19:57 kernel:  ? prb_read_valid+0x1b/0x30
Jul 11 17:19:57 kernel:  ? exc_page_fault+0x7c/0x180
Jul 11 17:19:57 kernel:  ? asm_exc_page_fault+0x26/0x30
Jul 11 17:19:57 kernel:  ? __bpf_prog_free+0x2b/0x50
Jul 11 17:19:57 kernel:  ? refill_obj_stock+0x4c/0x180
Jul 11 17:19:57 kernel:  ? __bpf_prog_free+0x2b/0x50
Jul 11 17:19:57 kernel:  __kmem_cache_free+0x22e/0x360
Jul 11 17:19:57 kernel:  __bpf_prog_free+0x2b/0x50
Jul 11 17:19:57 kernel:  process_one_work+0x1c7/0x3d0
Jul 11 17:19:57 kernel:  worker_thread+0x51/0x390
Jul 11 17:19:57 kernel:  ? __pfx_worker_thread+0x10/0x10
Jul 11 17:19:57 kernel:  kthread+0xde/0x110
Jul 11 17:19:57 kernel:  ? __pfx_kthread+0x10/0x10
Jul 11 17:19:57 kernel:  ret_from_fork+0x2c/0x50
Jul 11 17:19:57 kernel:  </TASK>
Jul 11 17:19:57 kernel: Modules linked in: uinput rfcomm snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink qrtr bnep sunrpc binfmt_misc vfat fat iwlmvm mac80211 snd_acp3x_pdm_dma snd_acp3x_rn snd_soc_dmic snd_sof_amd_rembrandt snd_sof_amd_renoir snd_sof_amd_acp snd_sof_pci snd_ctl_led snd_sof_xtensa_dsp snd_hda_codec_realtek snd_sof libarc4 snd_hda_codec_generic snd_sof_utils intel_rapl_msr ledtrig_audio snd_hda_codec_hdmi snd_soc_core intel_rapl_common snd_hda_intel uvcvideo edac_mce_amd snd_intel_dspcfg snd_intel_sdw_acpi uvc videobuf2_vmalloc snd_compress snd_hda_codec kvm_amd videobuf2_memops ac97_bus snd_hda_core snd_pcm_dmaengine btusb videobuf2_v4l2 iwlwifi snd_hwdep snd_pci_ps btrtl kvm videobuf2_common snd_rpl_pci_acp6x btbcm btintel btmtk snd_seq snd_pci_acp6x videodev bluetooth irqbypass hp_wmi
Jul 11 17:19:57 kernel:  snd_seq_device snd_pci_acp5x cfg80211 sparse_keymap mc snd_pcm rapl k10temp pcspkr platform_profile wmi_bmof snd_timer snd_rn_pci_acp3x snd_acp_config i2c_piix4 snd_soc_acpi snd snd_pci_acp3x rfkill soundcore acpi_cpufreq acpi_tad joydev loop zram amdgpu ccp hid_logitech_hidpp i2c_algo_bit drm_ttm_helper ttm iommu_v2 nvme drm_buddy sdhci_pci gpu_sched nvme_core cqhci drm_display_helper crct10dif_pclmul crc32_pclmul sdhci crc32c_intel video polyval_clmulni ucsi_acpi polyval_generic hid_multitouch ghash_clmulni_intel mmc_core typec_ucsi sha512_ssse3 r8169 cec typec sp5100_tco nvme_common i2c_hid_acpi wmi i2c_hid serio_raw hid_logitech_dj ip6_tables ip_tables fuse
Jul 11 17:19:57 kernel: CR2: 0000000000000117
Jul 11 17:19:57 kernel: ---[ end trace 0000000000000000 ]---
Jul 11 17:19:57 kernel: RIP: 0010:refill_obj_stock+0x4c/0x180
Jul 11 17:19:57 kernel: Code: 00 49 c7 c7 00 06 03 00 65 4c 03 3d c6 8d bf 6e 49 39 7f 10 0f 84 9c 00 00 00 4c 89 ff e8 ec f2 ff ff 49 89 c6 e8 64 ab d9 ff <48> 8b 45 00 a8 03 0f 85 c9 00 00 00 65 48 ff 00 e8 df e3 d9 ff 49
Jul 11 17:19:57 kernel: RSP: 0018:ffffac9252b07e20 EFLAGS: 00010002
Jul 11 17:19:57 kernel: RAX: 0000000000000001 RBX: 0000000000000808 RCX: 0000000000000010
Jul 11 17:19:57 kernel: RDX: ffff959ed0b25180 RSI: 000000000000000d RDI: ffff959ed0b25180
Jul 11 17:19:57 kernel: RBP: 0000000000000117 R08: ffff959d0097e001 R09: 0000000000000000
Jul 11 17:19:57 kernel: R10: ffffffff93323120 R11: 0000000000000030 R12: 0000000000000202
Jul 11 17:19:57 kernel: R13: ffffffff912ae7eb R14: ffff959d36e0cb00 R15: ffff95a00e970600
Jul 11 17:19:57 kernel: FS:  0000000000000000(0000) GS:ffff95a00e940000(0000) knlGS:0000000000000000
Jul 11 17:19:57 kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Jul 11 17:19:57 kernel: CR2: 0000000000000117 CR3: 00000003ef022000 CR4: 0000000000750ee0
Jul 11 17:19:57 kernel: PKRU: 55555554
Jul 11 17:19:57 kernel: note: kworker/13:2[8359] exited with irqs disabled
Jul 11 17:21:44 kernel: wlo1: disconnect from AP <AP 2> for new auth to <AP 1>
Jul 11 17:21:44 kernel: wlo1: authenticate with <AP 1>
Jul 11 17:21:44 kernel: wlo1: send auth to <AP 1> (try 1/3)
Jul 11 17:21:44 kernel: wlo1: <AP 1> denied authentication (status 1)
Jul 11 17:21:44 kernel: wlo1: authenticate with <AP 2>
Jul 11 17:21:44 kernel: wlo1: send auth to <AP 2> (try 1/3)
Jul 11 17:21:44 kernel: wlo1: authenticated
Jul 11 17:21:44 kernel: wlo1: associate with <AP 2> (try 1/3)
Jul 11 17:21:44 kernel: wlo1: RX ReassocResp from <AP 2> (capab=0x1131 status=0 aid=5)
Jul 11 17:21:45 kernel: wlo1: associated
Jul 11 17:21:45 kernel: wlo1: Limiting TX power to 30 (30 - 0) dBm as advertised by <AP 2>
Jul 11 17:24:17 kernel: sysrq: Keyboard mode set to system default
[system mostly frozen here ^^^^^^^ but Alt-SysRq still worked to reboot]

Comment 6 Max Chernoff 2023-07-13 20:34:24 UTC
I've done some more testing, and this issue appears to be present with kernels `6.3.11-200.fc38` and `6.3.12-200.fc38`, but not `6.3.8-200.fc38`. 

If no one has any better leads, I can try bisecting this I guess. It'll be a bit of a pain though—sometimes it takes a couple of hours after booting for the issue to show up.

Comment 7 5tvpx9rsq 2023-07-15 16:47:55 UTC
Description of problem:
After updating using the Software app, computer froze after I got about 2 characters of my login password entered at login screen. 
I waited "a minute" (not actually timed) in hopes things were just a little slow.
Long pressed power button to hard reboot.
Login was fine this time around.
Was presented with option to submit bug report.
I don't know how to reproduce the bug.

Version-Release number of selected component:
kernel-core-6.3.12-200.fc38

Additional info:
reporter:       libreport-2.17.11
kernel:         6.3.12-200.fc38.x86_64
crash_function: __die
reason:         BUG: kernel NULL pointer dereference, address: 0000000000000529
type:           Kerneloops
cmdline:        BOOT_IMAGE=(hd0,gpt2)/vmlinuz-6.3.12-200.fc38.x86_64 root=UUID=dd66ba13-3f6e-48c6-99e8-c29629c3f660 ro rootflags=subvol=root rhgb quiet
package:        kernel-core-6.3.12-200.fc38
runlevel:       N 5

Truncated backtrace:
BUG: kernel NULL pointer dereference, address: 0000000000000529
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 6 PID: 548 Comm: kworker/u32:6 Not tainted 6.3.12-200.fc38.x86_64 #1
Hardware name: HUAWEI KPL-W0X/KPL-W0X, BIOS 1.19 01/11/2019
RIP: 0010:wq_worker_running+0xe/0x50
Code: 1c 6b 00 83 f0 01 e9 40 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 e8 d2 60 00 00 <8b> 50 70 85 d2 74 20 65 ff 05 6c bb ef 54 f7 40 68 c8 01 00 00 74
RSP: 0018:ffffa048807e3ed8 EFLAGS: 00010202
RAX: 00000000000004b9 RBX: ffff89d493382000 RCX: 0000000000000002
RDX: 0000000000000000 RSI: 0000000000000006 RDI: ffff89d489d40000
RBP: ffff89d480059000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000100 R12: ffff89d493382030
R13: ffff89d480059028 R14: ffff89d489d40000 R15: ffff89d480059000
FS:  0000000000000000(0000) GS:ffff89d5a7f80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000529 CR3: 0000000109cda000 CR4: 00000000003506e0
Call Trace:
 <TASK>
 ? __die+0x23/0x70
 ? page_fault_oops+0x171/0x4e0
 ? exc_page_fault+0x7c/0x180
 ? asm_exc_page_fault+0x26/0x30
 ? wq_worker_running+0xe/0x50
 ? wq_worker_running+0xe/0x50
 worker_thread+0xb3/0x390
 ? __pfx_worker_thread+0x10/0x10
 kthread+0xde/0x110
 ? __pfx_kthread+0x10/0x10
 ret_from_fork+0x2c/0x50
 </TASK>
Modules linked in: rfcomm snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink qrtr bnep sunrpc iwlmvm mac80211 snd_sof_amd_rembrandt snd_sof_amd_renoir snd_sof_amd_acp snd_ctl_led snd_sof_pci snd_hda_codec_realtek intel_rapl_msr libarc4 binfmt_misc snd_sof_xtensa_dsp intel_rapl_common snd_sof snd_hda_codec_generic snd_hda_codec_hdmi edac_mce_amd snd_hda_intel kvm_amd snd_sof_utils vfat snd_intel_dspcfg iwlwifi fat snd_intel_sdw_acpi uvcvideo snd_hda_codec kvm snd_soc_core btusb uvc videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 snd_hda_core snd_compress videobuf2_common ac97_bus snd_hwdep snd_pcm_dmaengine btrtl snd_pci_ps snd_rpl_pci_acp6x snd_pci_acp6x btbcm snd_seq btintel btmtk irqbypass videodev snd_seq_device huawei_wmi cfg80211 bluetooth snd_pcm mc ledtrig_audio rapl wmi_bmof
 sparse_keymap snd_pci_acp5x snd_rn_pci_acp3x pcspkr snd_acp_config snd_timer snd_soc_acpi snd i2c_piix4 k10temp snd_pci_acp3x soundcore rfkill acpi_cpufreq joydev loop zram amdgpu i2c_algo_bit drm_ttm_helper ttm iommu_v2 drm_buddy gpu_sched drm_display_helper crct10dif_pclmul wacom crc32_pclmul crc32c_intel polyval_clmulni polyval_generic hid_multitouch ghash_clmulni_intel sha512_ssse3 cec ccp sp5100_tco video wmi i2c_hid_acpi i2c_hid serio_raw ip6_tables ip_tables fuse
CR2: 0000000000000529

Comment 8 icro 2023-07-18 10:24:26 UTC
Description of problem:
Black screen and lockup after login screen.

Version-Release number of selected component:
kernel-core-6.3.11-200.fc38

Additional info:
reporter:       libreport-2.17.11
kernel:         6.3.11-200.fc38.x86_64
crash_function: __die
reason:         BUG: kernel NULL pointer dereference, address: 000000000000009e
type:           Kerneloops
package:        kernel-core-6.3.11-200.fc38
runlevel:       unknown
comment:        Black screen and lockup after login screen.
cmdline:        BOOT_IMAGE=(hd0,gpt2)/vmlinuz-6.3.11-200.fc38.x86_64 root=UUID=redacted ro rootflags=subvol=root rd.luks.uuid=luks-redacted rhgb quiet

Truncated backtrace:
BUG: kernel NULL pointer dereference, address: 000000000000009e
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 932 Comm: kworker/u32:5 Not tainted 6.3.11-200.fc38.x86_64 #1
Hardware name: LENOVO 82L7/LNVNB161216, BIOS GECN33WW(V1.17) 01/16/2023
RIP: 0010:wq_worker_running+0xe/0x50
Code: 1c 6b 00 83 f0 01 e9 40 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 e8 d2 60 00 00 <8b> 50 70 85 d2 74 20 65 ff 05 6c bb ef 75 f7 40 68 c8 01 00 00 74
RSP: 0018:ffffb25b411ffed8 EFLAGS: 00010202
RAX: 000000000000002e RBX: ffff9e4306af6480 RCX: 0000000000000002
RDX: 0000000000000000 RSI: 0000000055555554 RDI: ffff9e430ee78000
RBP: ffff9e4300059000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000100 R12: ffff9e4306af64b0
R13: ffff9e4300059028 R14: ffff9e430ee78000 R15: ffff9e4300059000
FS:  0000000000000000(0000) GS:ffff9e459fe00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000000009e CR3: 0000000140bb6000 CR4: 0000000000750ef0
PKRU: 55555554
Call Trace:
 <TASK>
 ? __die+0x23/0x70
 ? page_fault_oops+0x171/0x4e0
 ? exc_page_fault+0x7c/0x180
 ? asm_exc_page_fault+0x26/0x30
 ? wq_worker_running+0xe/0x50
 ? wq_worker_running+0xe/0x50
 worker_thread+0xb3/0x390
 ? __pfx_worker_thread+0x10/0x10
 kthread+0xde/0x110
 ? __pfx_kthread+0x10/0x10
 ret_from_fork+0x2c/0x50
 </TASK>
Modules linked in: rfcomm snd_seq_dummy snd_hrtimer nf_conntrack_netlink nfnetlink xt_addrtype br_netfilter xt_CHECKSUM xt_MASQUERADE ipt_REJECT nf_reject_ipv4 ip6table_mangle ip6table_nat iptable_mangle iptable_nat nf_nat bridge stp llc ppdev parport_pc qrtr parport vmw_vsock_vmci_transport vsock vmw_vmci overlay xt_hl ip6table_filter xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 bnep xt_limit iptable_filter sunrpc binfmt_misc vfat fat iwlmvm snd_ctl_led mac80211 snd_soc_dmic snd_acp3x_rn snd_acp3x_pdm_dma snd_sof_amd_rembrandt snd_sof_amd_renoir snd_hda_codec_realtek snd_sof_amd_acp libarc4 snd_hda_codec_generic snd_sof_pci snd_sof_xtensa_dsp ledtrig_audio snd_sof intel_rapl_msr snd_hda_codec_hdmi intel_rapl_common edac_mce_amd snd_hda_intel snd_sof_utils snd_intel_dspcfg uvcvideo kvm_amd snd_hda_codec btusb snd_intel_sdw_acpi btrtl uvc snd_soc_core iwlwifi snd_hda_core snd_compress videobuf2_vmalloc btbcm snd_hwdep videobuf2_memops snd_seq kvm ac97_bus snd_pcm_dmaengine videobuf2_v4l2 btintel
 snd_seq_device snd_pci_ps videobuf2_common btmtk snd_rpl_pci_acp6x snd_pci_acp6x snd_pci_acp5x snd_pcm videodev bluetooth irqbypass cfg80211 snd_rn_pci_acp3x mc snd_timer wmi_bmof k10temp rapl i2c_piix4 pcspkr ideapad_laptop snd snd_acp_config sparse_keymap snd_soc_acpi snd_pci_acp3x platform_profile soundcore rfkill acpi_cpufreq amd_pmc joydev loop zram dm_crypt amdgpu i2c_algo_bit drm_ttm_helper ttm nvme iommu_v2 rtsx_pci_sdmmc drm_buddy gpu_sched mmc_core nvme_core drm_display_helper crct10dif_pclmul crc32_pclmul crc32c_intel hid_sensor_hub video polyval_clmulni ucsi_acpi polyval_generic hid_multitouch ghash_clmulni_intel typec_ucsi sha512_ssse3 ccp rtsx_pci cec typec sp5100_tco nvme_common wmi i2c_hid_acpi i2c_hid serio_raw scsi_dh_rdac scsi_dh_emc scsi_dh_alua ip6_tables ip_tables dm_multipath fuse
CR2: 000000000000009e

Comment 9 James Watson 2023-07-24 02:49:06 UTC
I note that kernel 6.4.4-200.fc38.x86_64 is available. Is it likely that this bug is fixed? I am currently running 6.3.8-200.fc38.x86_64, as 6.3.11-200.fc38.x86_64 and 6.3.12-200.fc38.x86_64 freeze shortly after booting.

Comment 10 Max Chernoff 2023-07-24 03:08:49 UTC
It seems to be fixed for me at least. Kernel 6.3.8 was good, then kernels 6.3.11 and 6.3.12 were bad, and kernel 6.4.4 seems to be good again. 

I'll hold off on "resolving" this bug until someone else confirms that 6.4.4 is good for them too.

Comment 11 James Watson 2023-07-24 05:06:13 UTC
Thank you. 6.4.4 is good for me too (so far). I have been running it for almost 2 hours. 6.3.11 and 6.3.12 failed quicker than that.


Note You need to log in before you can comment on or make changes to this bug.