From Bugzilla Helper: User-Agent: Mozilla/5.0 (X11; U; Linux i686; pt-BR; rv:1.8.1.3) Gecko/20070417 Fedora/2.0.0.3-4.fc7 Firefox/2.0.0.3 Description of problem: I'm using vanilla kernel 2.6.22-rc3 (and I try'ed with 2.6.21-fc7 fedora kernel) with a huawei e220 3g, and when I open amule after sometime kernel panics: list_add corruption. prev->next should be next (f7d28794), but was f0df8ed4 (prev=f0df8ed4) Kernel Bug at lib/list_debug.c:33 SMP Modules linhed in: ppp_deflate zlib_deflate ppp_async crc_ccitt pp_generic slhc sata_mv autofs4 hipd rfconn 12cap bluetooth sunrpc nf_conntrack_netbios_ns ipt_REJECT nf_conntrack_ipv4 xt_satte nf_conntrack nfnetlink iptable_filter ip_tables ip6t_REJECT xt_tcpudp ip6table_filter ip6_tables x_tables vfat fat fuse dm_mirror dm_multipatch dm_mod video sbs button dock battery ac radeon drm ipv6 lp option usbserial snd_emv10k1_synth snd_emux_synth snd_seq_virmidi snd_seq_midi_emulbt878 tuner snd_emu10k1 msp3400 snd_rawmidi bttv snd_hda_intell snd_ac97_codec ac97_bus snd_seq_dummy video_buf snd_seq_oss ir_common compat_isctl32 i2c_algo_bit snd_seq_midi_event sg btcx_risc snd_seq floppy snd_pcm_oss snd_mixer_oss snd_pcm snd_seq_device snd_timer pata_via tveeprom i2c_viapro snd_util_mem i2c_core snd_page_alloc snd_hwdep snd videodev atl1 v4l2_common soundcore mii v4l1_compat emu10k1_gp sr_mod gameport k8temp hwmon parport_pc parport cdrom serio_raw usb_storage sata_via ata_generic libata sd_mod scsi_mod ext3 jbd mbcache ehci_hcd ohci_hcd uhci_hcd CPU: 0 EIP: 0060:[<c04ddda5>] Not tainted VLI EFLAGS: 00010092 (2.6.22_rc3 #1) EIP is at __list_add+0x48/0x5c eax: 00000061 ebx: f0df8ed4 ecx: c06ced10 edx:00000086 esi: f0df8ed4 edi: 00000246 ebp: f7d28788 esp: c0750e68 ds: 007b es: 007b fs: 00d8 gs: 0033 ss: 0068 Process Amule (pid: 9719, ti=c0750000 task=d1da38b0 task.ti=c7899000) Satck: co69461e f7d28794 f0df8ed4 f0df8ed4 f0df8ec0 ffffffff c0558f09 00000040 00000021 f9316564 c180a120 00000000 d4884800 00000020 f7ece200 000000fc f7a45000 db1c8000 00000001 00000040 f90b8da0 f7a45000 d3740000 c409e470 Call Trace: [<c0558f09>] usb_hcd_sumit_urb+0x9a/0x778 [<f9316564>] ppp_async_push+0x38c/0x398 [ppp_async] [<f931657d>] ppp_async_send+0xd/0x36 [ppp_async] [<f932d677>] ppp_push+0x67/0x4c1 [ppp_generic] [<f9316564>] ppp_async_push+0x38c/0x398 [ppp_async] [<c043abdc>] timer_stats_update_stats+0x141/0x14d [<f90b73c6>] option_write+0xa1/0xe9 [option] [<f90ad586>] serial_write+0x9c/0xab [usbserial] [<f931627e>] ppp_async_push+0xa6/0x398 [ppp_async] [<f9316a31>] ppp_async_process+0x42/0x56 [ppp_async] [<c0427990>] tasklet_action+0x46/0x90 [<c04278c3>] __do_softirq+0x5d/0xc1 [<c0406cdb>] do_softirq+0x59/0xa8 [<c0427772>] irq_exit+0x38/0x6b [<c0416c60>] smp_apic_timer_interrupt+0x74/0x80 [<c04057e8>] apic_timer_interrupt+0x28/0x30 _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ Code: ce 45 69 c0 e8 3d 5c f4 ff 0f 0b eb fe 8b 32 39 ce 74 1c 89 54 24 0c 89 74 24 08 89 4c 24 04 c7 04 24 1e 46 69 c0 e8 1b 5c f4 ff <0f> 0b eb fe 89 59 04 89 0b 89 43 04 89 18 83 c4 10 5b 5e c3 8b EIP: [<c04ddda5>] __list_add+0x48/0x5c SS:ESP 0068:c0750e68 Kernel panic - not syncing: Fatal exception in interrupt Version-Release number of selected component (if applicable): vanilla kernel 2.6.22-rc3 (and I try'ed with 2.6.21-fc7 fedora kernel) How reproducible: Always Steps to Reproduce: 1.connect the network with huawei e220 3g 2.run amule or ktorrent 3. Actual Results: wait 30/45 minutes and the kernel panic appends Expected Results: I hope that I don't have the kernel panic and the network work well Additional info: list_add corruption. prev->next should be next (f7d28794), but was f0df8ed4 (prev=f0df8ed4) Kernel Bug at lib/list_debug.c:33 SMP Modules linhed in: ppp_deflate zlib_deflate ppp_async crc_ccitt pp_generic slhc sata_mv autofs4 hipd rfconn 12cap bluetooth sunrpc nf_conntrack_netbios_ns ipt_REJECT nf_conntrack_ipv4 xt_satte nf_conntrack nfnetlink iptable_filter ip_tables ip6t_REJECT xt_tcpudp ip6table_filter ip6_tables x_tables vfat fat fuse dm_mirror dm_multipatch dm_mod video sbs button dock battery ac radeon drm ipv6 lp option usbserial snd_emv10k1_synth snd_emux_synth snd_seq_virmidi snd_seq_midi_emulbt878 tuner snd_emu10k1 msp3400 snd_rawmidi bttv snd_hda_intell snd_ac97_codec ac97_bus snd_seq_dummy video_buf snd_seq_oss ir_common compat_isctl32 i2c_algo_bit snd_seq_midi_event sg btcx_risc snd_seq floppy snd_pcm_oss snd_mixer_oss snd_pcm snd_seq_device snd_timer pata_via tveeprom i2c_viapro snd_util_mem i2c_core snd_page_alloc snd_hwdep snd videodev atl1 v4l2_common soundcore mii v4l1_compat emu10k1_gp sr_mod gameport k8temp hwmon parport_pc parport cdrom serio_raw usb_storage sata_via ata_generic libata sd_mod scsi_mod ext3 jbd mbcache ehci_hcd ohci_hcd uhci_hcd CPU: 0 EIP: 0060:[<c04ddda5>] Not tainted VLI EFLAGS: 00010092 (2.6.22_rc3 #1) EIP is at __list_add+0x48/0x5c eax: 00000061 ebx: f0df8ed4 ecx: c06ced10 edx:00000086 esi: f0df8ed4 edi: 00000246 ebp: f7d28788 esp: c0750e68 ds: 007b es: 007b fs: 00d8 gs: 0033 ss: 0068 Process Amule (pid: 9719, ti=c0750000 task=d1da38b0 task.ti=c7899000) Satck: co69461e f7d28794 f0df8ed4 f0df8ed4 f0df8ec0 ffffffff c0558f09 00000040 00000021 f9316564 c180a120 00000000 d4884800 00000020 f7ece200 000000fc f7a45000 db1c8000 00000001 00000040 f90b8da0 f7a45000 d3740000 c409e470 Call Trace: [<c0558f09>] usb_hcd_sumit_urb+0x9a/0x778 [<f9316564>] ppp_async_push+0x38c/0x398 [ppp_async] [<f931657d>] ppp_async_send+0xd/0x36 [ppp_async] [<f932d677>] ppp_push+0x67/0x4c1 [ppp_generic] [<f9316564>] ppp_async_push+0x38c/0x398 [ppp_async] [<c043abdc>] timer_stats_update_stats+0x141/0x14d [<f90b73c6>] option_write+0xa1/0xe9 [option] [<f90ad586>] serial_write+0x9c/0xab [usbserial] [<f931627e>] ppp_async_push+0xa6/0x398 [ppp_async] [<f9316a31>] ppp_async_process+0x42/0x56 [ppp_async] [<c0427990>] tasklet_action+0x46/0x90 [<c04278c3>] __do_softirq+0x5d/0xc1 [<c0406cdb>] do_softirq+0x59/0xa8 [<c0427772>] irq_exit+0x38/0x6b [<c0416c60>] smp_apic_timer_interrupt+0x74/0x80 [<c04057e8>] apic_timer_interrupt+0x28/0x30 _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ Code: ce 45 69 c0 e8 3d 5c f4 ff 0f 0b eb fe 8b 32 39 ce 74 1c 89 54 24 0c 89 74 24 08 89 4c 24 04 c7 04 24 1e 46 69 c0 e8 1b 5c f4 ff <0f> 0b eb fe 89 59 04 89 0b 89 43 04 89 18 83 c4 10 5b 5e c3 8b EIP: [<c04ddda5>] __list_add+0x48/0x5c SS:ESP 0068:c0750e68 Kernel panic - not syncing: Fatal exception in interrupt
kernel panics always should be filed against kernel. userspace should never cause a panic, and if it does, it's still a kernel bug for allowing that to happen. :-)
report bugs from the upstream kernel to the upstream mailing list.