Description of problem: I was using mobile broadband connection via bluetooth. Crash occurred when I chose to disconnect. Problem was reproducable with Nokia E63 and Nokia E7, using different operators. Additional info: kernel BUG at kernel/workqueue.c:609! invalid opcode: 0000 [#1] SMP Modules linked in: ppp_deflate zlib_deflate bsd_comp ppp_async crc_ccitt ppp_generic slhc ebtable_nat fuse ipt_MASQUERADE nf_conntrack_netbios_ns nf_conntrack_broadcast ip6table_mangle ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6 iptable_nat nf_nat_ipv4 nf_nat iptable_mangle nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack nf_conntrack ebtable_filter ebtables rfcomm ip6table_filter ip6_tables bnep be2iscsi iscsi_boot_sysfs bnx2i cnic uio cxgb4i cxgb4 cxgb3i cxgb3 mdio libcxgbi ib_iser rdma_cm ib_addr iw_cm ib_cm ib_sa ib_mad ib_core iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi snd_hda_codec_hdmi snd_hda_codec_realtek iTCO_wdt iTCO_vendor_support coretemp microcode snd_hda_intel arc4 snd_hda_codec snd_hwdep i2c_i801 snd_seq snd_seq_device cdc_mbim uvcvideo btusb videobuf2_vmalloc videobuf2_memops bluetooth videobuf2_core videodev snd_pcm media iwldvm mac80211 cdc_ncm usbnet mii cdc_wdm cdc_acm iwlwifi lpc_ich mfd_core cfg80211 snd_page_alloc e1000e snd_timer mei thinkpad_acpi kvm snd soundcore rfkill uinput crc32c_intel ghash_clmulni_intel i915 sdhci_pci sdhci i2c_algo_bit mmc_core drm_kms_helper drm i2c_core wmi video CPU 3 Pid: 2266, comm: pppd Not tainted 3.8.1-201.fc18.x86_64 #1 LENOVO 2356GDG/2356GDG RIP: 0010:[<ffffffff81079ad9>] [<ffffffff81079ad9>] get_work_gcwq+0x69/0x70 RSP: 0018:ffff8801dac4fd58 EFLAGS: 00010007 RAX: ffffffff81e8da00 RBX: ffff8801f32f8e00 RCX: 0000000180800065 RDX: 0000000000f9975f RSI: 0000000000000000 RDI: ffff8801f32f8e00 RBP: ffff8801dac4fd58 R08: 0000000000000000 R09: 0000000000000001 R10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000000 R13: 0000000000000000 R14: ffff8801fc0a2400 R15: ffff8802120286c0 FS: 00007f4f00374800(0000) GS:ffff88021e2c0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f11d44fa138 CR3: 00000001e47c8000 CR4: 00000000001407e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400 Process pppd (pid: 2266, threadinfo ffff8801dac4e000, task ffff880200374620) Stack: ffff8801dac4fd98 ffffffff8107c29b ffff8801dac4fd88 0000000000000282 ffff8801dac4fdc8 0000000000000000 ffff8801fc0a2400 0000000000000000 ffff8801dac4fda8 ffffffff8107c340 ffff8801dac4fdb8 ffffffff813b02fd Call Trace: [<ffffffff8107c29b>] __cancel_work_timer+0x3b/0xb0 [<ffffffff8107c340>] cancel_work_sync+0x10/0x20 [<ffffffff813b02fd>] tty_ldisc_halt+0x1d/0x30 [<ffffffff813b115f>] tty_ldisc_release+0x1f/0x80 [<ffffffff813a98b7>] tty_release+0x447/0x550 [<ffffffff8119ec8c>] __fput+0xec/0x240 [<ffffffff8119edee>] ____fput+0xe/0x10 [<ffffffff8107ec47>] task_work_run+0xa7/0xe0 [<ffffffff81014981>] do_notify_resume+0x71/0xb0 [<ffffffff81657ed2>] int_signal+0x12/0x17 Code: 00 48 03 04 d5 e0 ec cd 81 5d c3 0f 1f 80 00 00 00 00 30 c0 48 8b 00 5d 48 8b 00 c3 66 0f 1f 44 00 00 31 c0 5d c3 83 c2 80 74 de <0f> 0b 0f 1f 44 00 00 0f 1f 44 00 00 55 48 89 e5 e8 82 ff ff ff RIP [<ffffffff81079ad9>] get_work_gcwq+0x69/0x70 RSP <ffff8801dac4fd58>
Same here Mar 13 00:24:10 mireille kernel: [ 1824.884210] ------------[ cut here ]------------ Mar 13 00:24:10 mireille kernel: [ 1824.885226] kernel BUG at kernel/workqueue.c:610! Mar 13 00:24:10 mireille kernel: [ 1824.886237] invalid opcode: 0000 [#1] SMP Mar 13 00:24:10 mireille kernel: [ 1824.887254] Modules linked in: ppp_deflate bsd_comp ppp_async crc_ccitt ppp_generic slhc btrfs zlib_deflate hfsplus hfs minix vfat msdos fat jfs xfs libcrc32c reiserfs fuse ebtable_nat xt_CHECKSUM ipt_MASQUERADE nf_conntrack_netbios_ns nf_conntrack_broadcast tun bridge stp llc ip6table_mangle ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6 iptable_nat nf_nat_ipv4 nf_nat iptable_mangle nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack nf_conntrack ebtable_filter ebtables ip6table_filter ip6_tables rfcomm bnep binfmt_misc snd_hda_codec_hdmi snd_hda_codec_realtek iTCO_wdt iTCO_vendor_support snd_hda_intel uvcvideo snd_hda_codec videobuf2_vmalloc snd_hwdep videobuf2_memops videobuf2_core snd_seq snd_seq_device coretemp kvm_intel videodev snd_pcm arc4 kvm crc32c_intel iwldvm media btusb mac80211 bluetooth microcode snd_page_alloc iwlwifi snd_timer lpc_ich mfd_core i2c_i801 serio_raw cfg80211 r8169 mii snd soundcore mei wmi ideapad_laptop sparse_keymap rfkill i915 i2c_algo_bit drm_kms_helper drm i2c_core video Mar 13 00:24:10 mireille kernel: [ 1824.895307] Pid: 2530, comm: pppd Not tainted 3.8.2-206.fc18.i686.PAE #1 LENOVO IdeaPad Z470 /KL6 Mar 13 00:24:10 mireille kernel: [ 1824.896849] EIP: 0060:[<c0466579>] EFLAGS: 00210002 CPU: 1 Mar 13 00:24:10 mireille kernel: [ 1824.898452] EIP is at get_work_gcwq+0x49/0x50 Mar 13 00:24:10 mireille kernel: [ 1824.900027] EAX: c0d61600 EBX: ea3ef000 ECX: 00000000 EDX: 00751f7b Mar 13 00:24:10 mireille kernel: [ 1824.901272] ESI: 00000000 EDI: 00000000 EBP: e7dc1e94 ESP: e7dc1e94 Mar 13 00:24:10 mireille kernel: [ 1824.902636] DS: 007b ES: 007b FS: 00d8 GS: 00e0 SS: 0068 Mar 13 00:24:10 mireille kernel: [ 1824.903729] CR0: 80050033 CR2: 091e0004 CR3: 2a35a000 CR4: 000407f0 Mar 13 00:24:10 mireille kernel: [ 1824.904909] DR0: 00000000 DR1: 00000000 DR2: 00000000 DR3: 00000000 Mar 13 00:24:10 mireille kernel: [ 1824.906414] DR6: ffff0ff0 DR7: 00000400 Mar 13 00:24:10 mireille kernel: [ 1824.907784] Process pppd (pid: 2530, ti=e7dc0000 task=e7cc7230 task.ti=e7dc0000) Mar 13 00:24:10 mireille kernel: [ 1824.909287] Stack: Mar 13 00:24:10 mireille kernel: [ 1824.910549] e7dc1eac c0468550 00200286 00000000 ea3eea00 00000000 e7dc1eb4 c04685df Mar 13 00:24:10 mireille kernel: [ 1824.911722] e7dc1ebc c073c97b e7dc1ecc c073d5ca ea3eea00 00000000 e7dc1f50 c0736c89 Mar 13 00:24:10 mireille kernel: [ 1824.913375] ea392ff4 00000200 e7dc1f74 c041b63f ea3eeb44 ea3eeb48 ef4c1b40 00000001 Mar 13 00:24:10 mireille kernel: [ 1824.915026] Call Trace: Mar 13 00:24:10 mireille kernel: [ 1824.916712] [<c0468550>] __cancel_work_timer+0x30/0x90 Mar 13 00:24:10 mireille kernel: [ 1824.918347] [<c04685df>] cancel_work_sync+0xf/0x20 Mar 13 00:24:10 mireille kernel: [ 1824.919455] [<c073c97b>] tty_ldisc_halt+0x1b/0x20 Mar 13 00:24:10 mireille kernel: [ 1824.920562] [<c073d5ca>] tty_ldisc_release+0x1a/0x70 Mar 13 00:24:10 mireille kernel: [ 1824.922104] [<c0736c89>] tty_release+0x379/0x480 Mar 13 00:24:10 mireille kernel: [ 1824.923310] [<c041b63f>] ? __restore_xstate_sig+0x1ff/0x510 Mar 13 00:24:10 mireille kernel: [ 1824.924474] [<c05697ca>] ? do_vfs_ioctl+0x7a/0x590 Mar 13 00:24:10 mireille kernel: [ 1824.925578] [<c063804a>] ? inode_has_perm.isra.31.constprop.62+0x3a/0x50 Mar 13 00:24:10 mireille kernel: [ 1824.926691] [<c055b686>] __fput+0xc6/0x1f0 Mar 13 00:24:10 mireille kernel: [ 1824.927802] [<c055b7bd>] ____fput+0xd/0x10 Mar 13 00:24:10 mireille kernel: [ 1824.928908] [<c046ab31>] task_work_run+0x81/0xa0 Mar 13 00:24:10 mireille kernel: [ 1824.930017] [<c0412841>] do_notify_resume+0x61/0xa0 Mar 13 00:24:10 mireille kernel: [ 1824.931129] [<c0999e31>] work_notifysig+0x30/0x37 Mar 13 00:24:10 mireille kernel: [ 1824.932245] Code: b8 00 16 d6 c0 73 1f 83 fa 20 74 0c b8 c0 24 d0 c0 03 04 95 c0 9c c5 c0 5d c3 30 c0 8b 00 5d 8b 00 c3 31 c0 5d c3 83 fa 20 74 ed <0f> 0b 90 8d 74 26 00 55 89 e5 66 66 66 66 90 e8 a3 ff ff ff 85 Mar 13 00:24:10 mireille kernel: [ 1824.934782] EIP: [<c0466579>] get_work_gcwq+0x49/0x50 SS:ESP 0068:e7dc1e94 Mar 13 00:24:10 mireille kernel: [ 1824.940476] type=1400 audit(1363159450.547:4): avc: denied { open } for pid=498 comm=72733A6D61696E20513A526567 path="/dev/pts/0" dev="devpts" ino=3 scontext=system_u:system_r:syslogd_t:s0 tcontext=unconfined_u:object_r:user_devpts_t:s0 tclass=chr_file Mar 13 00:24:10 mireille kernel: [ 1824.958572] ---[ end trace ec3e2a1d3c008d17 ]---
P.S. 3.8.2-206.fc18.i686.PAE
1. Enable mobile broadband connection (bluetooth, Nokia N9) 2. some surfing on the internet 3. Click to disable the mobile broadband connection in Fedora's top bar 4. On this action the kernel crashes Package: kernel OS Release: Fedora release 18 (Spherical Cow)
I've got the same issue right after disconnecting an Android bluetooth device. It happens in kernel (64 bits) 3.8.3-202 and 3.8.4-203. And doesn't happen in 3.7.9-201.
*** Bug 918806 has been marked as a duplicate of this bug. ***
Same here using Xastir with a Bluetooth TNC. If the Bluetooth connection stops for any reason, and I attempt to unbind/bind the Bluetooth rfcomm connection, stopping Xastir results in a kernel oops. 0. Configure Bluetooth on /dev/rfcomm0 and xastir to use /dev/rfcomm0 1. sudo rfcomm bind 0 2. start xastir, automatically connecting to TNC on /dev/rfcomm0 3. power off TNC 4. xastir interface shows ERROR 5. power on TNC 6. attempt to reconnect xastir to TNC fails; interface shows ERROR 7. sudo rfcomm unbind 0 8. attempt to start the interface in xastir; interface shows DOWN 9. sudo rfcomm bind 0 10. attempt to start the interface in xastir a. interface shows DOWN b. xastir prints error message to console c. (upowerd:1088): UPower-Linux-WARNING **: unhandled action 'move' on /sys/devices/pci0000:00/0000:00:1d.1/usb3/3-1/3-1:1.0/bluetooth/hci0/hci0:12/rfcomm0 11. close/exit xastir 12. OOPS Apr 21 11:50:20 ruby kernel: [313309.711915] ------------[ cut here ]------------ Apr 21 11:50:20 ruby kernel: [313309.712022] kernel BUG at kernel/workqueue.c:610! Apr 21 11:50:20 ruby kernel: [313309.712022] invalid opcode: 0000 [#1] SMP Apr 21 11:50:20 ruby kernel: [313309.712022] Modules linked in: fuse ebtable_nat ipt_MASQUERADE nf_conntrack_netbios_ns nf_conntrack_broadcast ip6table_mangle ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6 iptable_nat nf_nat_ipv4 nf_nat iptable_mangle nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack nf_conntrack ebtable_filter ebtables ip6table_filter ip6_tables be2iscsi iscsi_boot_sysfs bnx2i cnic uio cxgb4i cxgb4 cxgb3i cxgb3 mdio libcxgbi ib_iser rdma_cm ib_addr iw_cm ib_cm ib_sa ib_mad ib_core iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi rfcomm bnep iTCO_wdt iTCO_vendor_support snd_hda_codec_realtek snd_hda_intel btusb bluetooth coretemp snd_hda_codec microcode snd_hwdep serio_raw i2c_i801 snd_seq of_i2c arc4 snd_seq_device rt2800pci rt2800lib rt2x00pci rt2x00lib eeprom_93cx6 lpc_ich mac80211 snd_pcm cfg80211 crc_ccitt r8169 snd_page_alloc mii snd_timer snd soundcore eeepc_laptop sparse_keymap rfkill binfmt_misc uinput nfsd auth_rpcgss nfs_acl lockd sunrpc i915 i2c_algo_bit drm_kms_helper drm i2c_core video ums_realtek usb_storage Apr 21 11:50:20 ruby kernel: [313309.712022] Pid: 2421, comm: xastir Tainted: G W 3.8.4-202.fc18.i686 #1 System manufacturer B202/P5LD2EB-DHS Apr 21 11:50:20 ruby kernel: [313309.712022] EIP: 0060:[<c0456f89>] EFLAGS: 00210006 CPU: 0 Apr 21 11:50:20 ruby kernel: [313309.712022] EIP is at get_work_gcwq+0x49/0x50 Apr 21 11:50:20 ruby kernel: [313309.712022] EAX: c0d2dc00 EBX: ef730e00 ECX: 00000000 EDX: 0077b980 Apr 21 11:50:20 ruby kernel: [313309.712022] ESI: 00000000 EDI: 00000000 EBP: ee0f1e28 ESP: ee0f1e28 Apr 21 11:50:20 ruby kernel: [313309.712022] DS: 007b ES: 007b FS: 00d8 GS: 00e0 SS: 0068 Apr 21 11:50:20 ruby kernel: [313309.712022] CR0: 8005003b CR2: 4b4250c4 CR3: 3030e000 CR4: 000007c0 Apr 21 11:50:20 ruby kernel: [313309.712022] DR0: 00000000 DR1: 00000000 DR2: 00000000 DR3: 00000000 Apr 21 11:50:20 ruby kernel: [313309.712022] DR6: ffff0ff0 DR7: 00000400 Apr 21 11:50:20 ruby kernel: [313309.712022] Process xastir (pid: 2421, ti=ee0f0000 task=f09f0000 task.ti=ee0f0000) Apr 21 11:50:20 ruby kernel: [313309.712022] Stack: Apr 21 11:50:20 ruby kernel: [313309.712022] ee0f1e40 c0458f60 00200286 00000000 f0355800 00000000 ee0f1e48 c0458fef Apr 21 11:50:20 ruby kernel: [313309.712022] ee0f1e50 c071cbcb ee0f1e60 c071d81a f0355800 00000000 ee0f1ee4 c0716ed9 Apr 21 11:50:20 ruby kernel: [313309.712022] ef748754 c087a798 ee45a61c c055ad38 f0355944 f0355948 ee14ff00 00000001 Apr 21 11:50:20 ruby kernel: [313309.712022] Call Trace: Apr 21 11:50:20 ruby kernel: [313309.712022] [<c0458f60>] __cancel_work_timer+0x30/0x90 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c0458fef>] cancel_work_sync+0xf/0x20 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c071cbcb>] tty_ldisc_halt+0x1b/0x20 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c071d81a>] tty_ldisc_release+0x1a/0x70 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c0716ed9>] tty_release+0x379/0x480 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c087a798>] ? sock_destroy_inode+0x28/0x30 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c055ad38>] ? __d_free+0x38/0x60 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c055ad38>] ? __d_free+0x38/0x60 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c055ada5>] ? d_free+0x45/0x50 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c055be2b>] ? d_kill+0x8b/0xf0 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c054a426>] __fput+0xc6/0x1f0 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c054a55d>] ____fput+0xd/0x10 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c045b541>] task_work_run+0x81/0xa0 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c044412a>] do_exit+0x26a/0x910 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c046f2cf>] ? wake_up_state+0xf/0x20 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c044fcfd>] ? signal_wake_up_state+0x1d/0x30 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c0450d3b>] ? zap_other_threads+0x6b/0x80 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c0444844>] do_group_exit+0x34/0xa0 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c04448c8>] sys_exit_group+0x18/0x20 Apr 21 11:50:20 ruby kernel: [313309.712022] [<c098348d>] sysenter_do_call+0x12/0x28 Apr 21 11:50:20 ruby kernel: [313309.712022] Code: b8 00 dc d2 c0 73 1f 83 fa 20 74 0c b8 c0 1b cd c0 03 04 95 80 10 c3 c0 5d c3 30 c0 8b 00 5d 8b 00 c3 31 c0 5d c3 83 fa 20 74 ed <0f> 0b 90 8d 74 26 00 55 89 e5 3e 8d 74 26 00 e8 a3 ff ff ff 85 Apr 21 11:50:20 ruby kernel: [313309.712022] EIP: [<c0456f89>] get_work_gcwq+0x49/0x50 SS:ESP 0068:ee0f1e28 Apr 21 11:50:20 ruby kernel: [313309.923049] ---[ end trace c421d73c5407da01 ]--- Apr 21 11:50:20 ruby kernel: [313309.923061] Fixing recursive fault but reboot is needed!
More information on the above problem. If I exit xastir while /dev/rfcomm0 is in ERROR state (after step 4) and then unbind/bind rfcomm0, xastir will successfully reopen /dev/rfcomm0 when restarted and the system remains stable.
I'm having this bug on various distributions and kernels, up to and including 3.10-rc2. Also, this LKML thread seems relevant: https://lkml.org/lkml/2013/5/16/55
*********** MASS BUG UPDATE ************** We apologize for the inconvenience. There is a large number of bugs to go through and several of them have gone stale. Due to this, we are doing a mass bug update across all of the Fedora 18 kernel bugs. Fedora 18 has now been rebased to 3.11.4-101.fc18. Please test this kernel update (or newer) and let us know if you issue has been resolved or if it is still present with the newer kernel. If you have moved on to Fedora 19, and are still experiencing this issue, please change the version to Fedora 19. If you experience different issues, please open a new bug report for those.
*********** MASS BUG UPDATE ************** We apologize for the inconvenience. There is a large number of bugs to go through and several of them have gone stale. It has been over a month since we asked you to test the 3.11 kernel updates and let us know if your issue has been resolved or is still a problem. When this happened, the bug was set to needinfo. Because the needinfo is still set, we assume either this is no longer a problem, or you cannot provide additional information to help us resolve the issue. As a result we are closing with insufficient data. If this is still a problem, we apologize, feel free to reopen the bug and provide more information so that we can work towards a resolution If you experience different issues, please open a new bug report for those.
I can't no longer produce this bug, having scrapped the phone long time ago.