Bug 708718 (elv_may_queue) - elv_may_queue oops.
Summary: elv_may_queue oops.
Keywords:
Status: CLOSED ERRATA
Alias: elv_may_queue
Product: Fedora
Classification: Fedora
Component: kernel
Version: 15
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Kernel Maintainer List
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:1594c7b5f8e4752c16fcea8fbe8...
: 708717 709670 709946 710734 712825 713037 714489 716660 717099 717756 718356 719744 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-05-29 03:25 UTC by Rod Johnson
Modified: 2012-06-06 15:28 UTC (History)
16 users (show)

Fixed In Version: kernel-2.6.38.8-35.fc15
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-07-12 05:26:06 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Rod Johnson 2011-05-29 03:25:39 UTC
abrt version: 2.0.1
architecture:   x86_64
cmdline:        ro root=/dev/mapper/vg_b6230-lv_root rd_LVM_LV=vg_b6230/lv_root rd_LVM_LV=vg_b6230/lv_swap rd_NO_LUKS rd_NO_MD rd_NO_DM LANG=en_US.UTF-8 SYSFONT=latarcyrheb-sun16 KEYTABLE=us rhgb quiet
component:      kernel
kernel:         2.6.38.6-27.fc15.x86_64
kernel_tainted: 128
os_release:     Fedora release 15 (Lovelock)
package:        kernel
reason:         BUG: unable to handle kernel paging request at 0000000000001000
time:           Sat May 28 03:01:29 2011

backtrace:
:BUG: unable to handle kernel paging request at 0000000000001000
:IP: [<0000000000001000>] 0x1000
:PGD 170ae067 PUD 11870067 PMD 0 
:Oops: 0010 [#1] SMP 
:last sysfs file: /sys/devices/virtual/net/vnet0/statistics/collisions
:CPU 0 
:Modules linked in: tun usb_storage uas fuse ebtable_nat ebtables ipt_MASQUERADE iptable_nat nf_nat xt_CHECKSUM iptable_mangle bridge stp llc sunrpc cpufreq_ondemand acpi_cpufreq freq_table mperf rfcomm sco bnep l2cap ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6 ip6table_filter ip6_tables snd_hda_codec_realtek snd_hda_intel snd_hda_codec snd_hwdep btusb bluetooth snd_seq arc4 ath5k ath mac80211 snd_seq_device cfg80211 snd_pcm fujitsu_laptop input_polldev snd_timer rfkill iTCO_wdt iTCO_vendor_support serio_raw joydev sky2 microcode i2c_i801 snd soundcore snd_page_alloc virtio_net kvm_intel kvm ipv6 yenta_socket i915 drm_kms_helper drm i2c_algo_bit i2c_core video [last unloaded: scsi_wait_scan]
:Pid: 25395, comm: qemu-kvm Not tainted 2.6.38.6-27.fc15.x86_64 #1 FUJITSU LifeBook B6230/FJNB1DC
:RIP: 0010:[<0000000000001000>]  [<0000000000001000>] 0x1000
:RSP: 0018:ffff8800119dbae0  EFLAGS: 00010006
:RAX: 0000000000000000 RBX: ffff880039223d50 RCX: 0000000000000010
:RDX: 0000000000001000 RSI: 0000000000000000 RDI: ffff880039223d50
:RBP: ffff8800119dbae8 R08: 0000000000000000 R09: ffff88003b9d8900
:R10: ffff88001738a490 R11: 0000000000000293 R12: ffff8800119dbb90
:R13: 0000000000000000 R14: ffff88003b9d8900 R15: 0000000000000001
:FS:  00007f58eba559c0(0000) GS:ffff88003f400000(0000) knlGS:0000000000000000
:CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
:CR2: 0000000000001000 CR3: 000000002edec000 CR4: 00000000000026f0
:DR0: 00000000000000a0 DR1: 0000000000000000 DR2: 0000000000000003
:DR3: 00000000000000b0 DR6: 00000000ffff0ff0 DR7: 0000000000000400
:Process qemu-kvm (pid: 25395, threadinfo ffff8800119da000, task ffff8800119cdc80)
:Stack:
: ffffffff812115fb ffff8800119dbb48 ffffffff81215cc9 0000000000000000
: 0000000000000000 000000103f4140c8 ffff8800119cdc80 ffffffff810d8067
: ffff880039223d50 ffff8800119dbb90 0000000000000000 ffff88003b9d8900
:Call Trace:
: [<ffffffff812115fb>] ? elv_may_queue+0x1d/0x1f
: [<ffffffff81215cc9>] get_request+0x33/0x262
: [<ffffffff810d8067>] ? sync_page+0x0/0x4f
: [<ffffffff81216891>] get_request_wait+0x35/0x193
: [<ffffffff8122d17c>] ? radix_tree_delete+0xd7/0x1f5
: [<ffffffff810d8067>] ? sync_page+0x0/0x4f
: [<ffffffff81474826>] ? __wait_on_bit+0x69/0x7b
: [<ffffffff81216a2e>] blk_get_request+0x3f/0x6e
: [<ffffffff812fc965>] scsi_execute+0x41/0x146
: [<ffffffff812fcb06>] scsi_execute_req+0x9c/0xce
: [<ffffffff812f8ba0>] ioctl_internal_command.constprop.1+0x6b/0x163
: [<ffffffff812f8cf1>] scsi_set_medium_removal+0x59/0x94
: [<ffffffff8130b41d>] sr_lock_door+0x20/0x22
: [<ffffffff8132c634>] cdrom_release+0x195/0x205
: [<ffffffff810f1537>] ? pmd_offset+0x19/0x3f
: [<ffffffff8104127e>] ? should_resched+0xe/0x2d
: [<ffffffff814742d0>] ? _cond_resched+0xe/0x22
: [<ffffffff8130a3b1>] sr_block_release+0x30/0x4d
: [<ffffffff81149c0e>] __blkdev_put+0xc6/0x179
: [<ffffffff81149dc5>] blkdev_put+0x104/0x10c
: [<ffffffff81149df2>] blkdev_close+0x25/0x27
: [<ffffffff81122b15>] fput+0x121/0x1bb
: [<ffffffff8112007f>] filp_close+0x66/0x70
: [<ffffffff81120126>] sys_close+0x9d/0xda
: [<ffffffff81009bc2>] system_call_fastpath+0x16/0x1b
:Code:  Bad RIP value.
:RIP  [<0000000000001000>] 0x1000
: RSP <ffff8800119dbae0>

event_log:
:2011-05-28-23:24:20> Empty login or password, please check your configuration
:2011-05-28-23:24:20* (exited with 1)

Comment 1 Dave Jones 2011-06-07 18:31:39 UTC
There are quite a few variants of this backtrace in bugzilla, but this is the only one I've seen so far that is untainted.

The common thing seems to be virtual block devices. (vbox/vmware/qemu)

Comment 2 Dave Jones 2011-06-07 18:32:45 UTC
*** Bug 710734 has been marked as a duplicate of this bug. ***

Comment 3 Dave Jones 2011-06-07 18:33:20 UTC
*** Bug 709946 has been marked as a duplicate of this bug. ***

Comment 4 Dave Jones 2011-06-07 18:33:42 UTC
*** Bug 709670 has been marked as a duplicate of this bug. ***

Comment 5 Dave Jones 2011-06-07 19:21:39 UTC
http://permalink.gmane.org/gmane.linux.kernel.stable/12655 should be queued for the next stable release, and may be relevant here.

Comment 6 Dave Jones 2011-06-14 04:26:03 UTC
*** Bug 713037 has been marked as a duplicate of this bug. ***

Comment 7 Dave Jones 2011-06-14 04:29:08 UTC
please try this update, and see if it helps the situation any.

https://admin.fedoraproject.org/updates/kernel-2.6.38.8-32.fc15

Comment 8 Christophe Fergeau 2011-06-21 14:42:31 UTC
I think I'm hitting this bug (see trace below), it happens to me with an USB cdrom drive (self-powered, so it has a special USB cable using 2 USB ports to get enough power) with the 2.6.38.8-32 kernel. It happens to me about once every few hours when using the CD drive, so I can try to gather additional information. If this is a different bug, let me know, I'll open another once (in which case, sorry for the noise ;)

[25800.581645] hub 1-1:1.0: Cannot enable port 2.  Maybe the USB cable is bad?
[25801.591072] hub 1-1:1.0: cannot disable port 2 (err = -110)
[25802.600505] hub 1-1:1.0: cannot reset port 2 (err = -110)
[25803.054903] usb 1-1.2: reset high speed USB device using ehci_hcd and address 3
[25803.065489] DRHD: handling fault status reg 2
[25803.065495] ehci_hcd 0000:00:1a.0: fatal error
[25803.065507] DMAR:[DMA Read] Request device [00:1a.0] fault addr 0 
[25803.065510] DMAR:[fault reason 06] PTE Read access is not set
[25803.069369] ehci_hcd 0000:00:1a.0: HC died; cleaning up
[25803.072270] ehci_hcd 0000:00:1a.0: force halt; handshake ffffc900110a0024 00004000 00004000 -> -110
[25803.072276] ehci_hcd 0000:00:1a.0: HC died; cleaning up
[25803.072487] usb 1-1: USB disconnect, address 2
[25803.072492] usb 1-1.2: USB disconnect, address 3
[25803.076253] usb 1-1.2: device descriptor read/8, error -19
[25803.578983] usb 1-1.2: device not accepting address 3, error -22
[25803.578996] hub 1-1:1.0: cannot disable port 2 (err = -19)
[25803.579005] hub 1-1:1.0: cannot reset port 2 (err = -19)
[25803.579011] hub 1-1:1.0: cannot disable port 2 (err = -19)
[25803.579017] hub 1-1:1.0: cannot disable port 2 (err = -19)
[25803.579144] sr 6:0:0:0: Device offlined - not ready after error recovery
[25803.584974] usb 1-1.4: USB disconnect, address 4
[25803.585594] usb 1-1.6: USB disconnect, address 5
[25803.633257] BUG: unable to handle kernel NULL pointer dereference at 0000000000000078
[25803.633346] IP: [<ffffffff81211486>] elv_may_queue+0x10/0x1f
[25803.633411] PGD 0 
[25803.633435] Oops: 0000 [#1] SMP 
[25803.633472] last sysfs file: /sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.2/1-1.2:1.0/host6/target6:0:0/6:0:0:0/block/sr0/removable
[25803.633586] CPU 0 
[25803.633606] Modules linked in: tcp_lp kvm_intel kvm tun fuse sunrpc cpufreq_ondemand acpi_cpufreq freq_table mperf snd_hda_codec_hdmi snd_hda_codec_conexant arc4 snd_hda_intel snd_hda_codec snd_hwdep snd_seq snd_seq_device snd_pcm iwlagn uvcvideo videodev btusb bluetooth i2c_i801 microcode v4l2_compat_ioctl32 iwlcore joydev mac80211 iTCO_wdt iTCO_vendor_support snd_timer cfg80211 snd_page_alloc e1000e thinkpad_acpi wmi rfkill snd soundcore ipv6 xts gf128mul dm_crypt usb_storage i915 drm_kms_helper drm i2c_algo_bit i2c_core video [last unloaded: scsi_wait_scan]
[25803.634197] 
[25803.634215] Pid: 23271, comm: gvfsd-cdda Not tainted 2.6.38.8-32.fc15.x86_64 #1 LENOVO 3680B56/3680B56
[25803.634316] RIP: 0010:[<ffffffff81211486>]  [<ffffffff81211486>] elv_may_queue+0x10/0x1f
[25803.634399] RSP: 0018:ffff8800960ab9c8  EFLAGS: 00010096
[25803.634450] RAX: 0000000000000000 RBX: ffff88012bdd28e0 RCX: 0000000000000010
[25803.634521] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88012bdd28e0
[25803.634592] RBP: ffff8800960ab9c8 R08: 0000000000000000 R09: ffff8800960d3c60
[25803.634661] R10: ffff8800918db0d0 R11: ffff8800b2b310b0 R12: ffff8800960aba70
[25803.634732] R13: 0000000000000000 R14: ffff8800960d3c60 R15: 0000000000000001
[25803.634803] FS:  00007f99d74de7c0(0000) GS:ffff8800bb000000(0000) knlGS:0000000000000000
[25803.634879] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[25803.634913] CR2: 0000000000000078 CR3: 000000009ed70000 CR4: 00000000000026f0
[25803.634984] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[25803.635057] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
[25803.635127] Process gvfsd-cdda (pid: 23271, threadinfo ffff8800960aa000, task ffff88012bea5cc0)
[25803.635209] Stack:
[25803.635231]  ffff8800960aba28 ffffffff81215ba2 ffff880000000000 0000000000000000
[25803.635293]  00000010960abfd8 ffff8800960abfd8 0000000000013840 ffff88012bdd28e0
[25803.635343]  ffff8800960aba70 0000000000000000 ffff8800960d3c60 0000000000000000
[25803.635394] Call Trace:
[25803.635417]  [<ffffffff81215ba2>] get_request+0x33/0x262
[25803.635455]  [<ffffffff8121676a>] get_request_wait+0x35/0x193
[25803.635492]  [<ffffffff81228fb4>] ? cpumask_next_and+0x2c/0x39
[25803.635527]  [<ffffffff81216907>] blk_get_request+0x3f/0x6e
[25803.635563]  [<ffffffff812fc861>] scsi_execute+0x41/0x146
[25803.635597]  [<ffffffff812fca02>] scsi_execute_req+0x9c/0xce
[25803.635643]  [<ffffffff812f8a9c>] ioctl_internal_command.constprop.1+0x6b/0x163
[25803.635700]  [<ffffffff8100885c>] ? __switch_to+0x20e/0x220
[25803.635741]  [<ffffffff812f8bed>] scsi_set_medium_removal+0x59/0x94
[25803.635797]  [<ffffffff8130b225>] sr_lock_door+0x20/0x22
[25803.635849]  [<ffffffff8132c475>] cdrom_release+0x195/0x205
[25803.635896]  [<ffffffff8146fa9e>] ? __slab_free+0x27/0xeb
[25803.635948]  [<ffffffff8104127e>] ? should_resched+0xe/0x2d
[25803.636002]  [<ffffffff81474408>] ? _cond_resched+0xe/0x22
[25803.636056]  [<ffffffff8130a1b9>] sr_block_release+0x30/0x4d
[25803.636111]  [<ffffffff81149aa2>] __blkdev_put+0xc6/0x179
[25803.636161]  [<ffffffff81149c59>] blkdev_put+0x104/0x10c
[25803.636212]  [<ffffffff81149c86>] blkdev_close+0x25/0x27
[25803.636268]  [<ffffffff811229ad>] fput+0x121/0x1bb
[25803.636315]  [<ffffffff8111ff17>] filp_close+0x66/0x70
[25803.638743]  [<ffffffff81058046>] put_files_struct+0x6e/0xd5
[25803.640811]  [<ffffffff8105813a>] exit_files+0x41/0x46
[25803.642532]  [<ffffffff810586b0>] do_exit+0x293/0x732
[25803.644447]  [<ffffffff81129e21>] ? path_put+0x1f/0x23
[25803.646257]  [<ffffffff81058dd4>] do_group_exit+0x7a/0xa2
[25803.648011]  [<ffffffff81058e13>] __wake_up_parent+0x0/0x28
[25803.649736]  [<ffffffff81009bc2>] system_call_fastpath+0x16/0x1b
[25803.651412] Code: 1f 44 00 00 48 8b 47 18 48 8b 00 48 8b 40 70 48 85 c0 74 05 48 89 f7 ff d0 5d c3 55 48 89 e5 0f 1f 44 00 00 48 8b 47 18 48 8b 00 
[25803.651635]  8b 50 78 31 c0 48 85 d2 74 02 ff d2 5d c3 55 48 89 e5 0f 1f 
[25803.655091] RIP  [<ffffffff81211486>] elv_may_queue+0x10/0x1f
[25803.656796]  RSP <ffff8800960ab9c8>
[25803.658471] CR2: 0000000000000078
[25803.717135] ---[ end trace 1417e40b5dc87c61 ]---
[25803.717138] Fixing recursive fault but reboot is needed!

Comment 9 Chuck Ebbert 2011-06-27 07:39:13 UTC
*** Bug 712825 has been marked as a duplicate of this bug. ***

Comment 10 Fedora Update System 2011-07-07 01:00:58 UTC
kernel-2.6.38.8-35.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/kernel-2.6.38.8-35.fc15

Comment 11 Fedora Update System 2011-07-08 17:59:19 UTC
Package kernel-2.6.38.8-35.fc15:
* should fix your issue,
* was pushed to the Fedora 15 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing kernel-2.6.38.8-35.fc15'
as soon as you are able to, then reboot.
Please go to the following url:
https://admin.fedoraproject.org/updates/kernel-2.6.38.8-35.fc15
then log in and leave karma (feedback).

Comment 12 Chuck Ebbert 2011-07-11 19:13:41 UTC
*** Bug 717756 has been marked as a duplicate of this bug. ***

Comment 13 Dave Jones 2011-07-11 19:26:09 UTC
*** Bug 719744 has been marked as a duplicate of this bug. ***

Comment 14 Dave Jones 2011-07-11 21:12:19 UTC
*** Bug 718356 has been marked as a duplicate of this bug. ***

Comment 15 Dave Jones 2011-07-11 21:50:15 UTC
*** Bug 716660 has been marked as a duplicate of this bug. ***

Comment 16 Dave Jones 2011-07-11 22:22:04 UTC
*** Bug 708717 has been marked as a duplicate of this bug. ***

Comment 17 Dave Jones 2011-07-11 23:54:29 UTC
*** Bug 714489 has been marked as a duplicate of this bug. ***

Comment 18 Fedora Update System 2011-07-12 05:25:21 UTC
kernel-2.6.38.8-35.fc15 has been pushed to the Fedora 15 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 19 Josh Boyer 2012-06-06 15:28:42 UTC
*** Bug 717099 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.