From: Johannes Thumshirn <jthumshirn@suse.de>
To: Chaitanya Kulkarni <Chaitanya.Kulkarni@wdc.com>
Cc: Daniel Wagner <dwagner@suse.de>,
linux-nvme@lists.infradead.org, Sagi Grimberg <sagi@grimberg.me>,
linux-kernel@vger.kernel.org, Christoph Hellwig <hch@lst.de>
Subject: Re: [RFC] nvmet: Always remove processed AER elements from list
Date: Thu, 31 Oct 2019 08:06:10 +0100 [thread overview]
Message-ID: <82e496f61183ebdf7924d660d3b8c90e@suse.de> (raw)
In-Reply-To: <BYAPR04MB5749158C2EBD47FC48A79FF286600@BYAPR04MB5749.namprd04.prod.outlook.com>
On 2019-10-30 20:58, Chaitanya Kulkarni wrote:
> On 10/30/2019 08:24 AM, Daniel Wagner wrote:
>> Hi,
>>
>> I've got following oops:
>>
>> PID: 79413 TASK: ffff92f03a814ec0 CPU: 19 COMMAND: "kworker/19:2"
>> #0 [ffffa5308b8c3c58] machine_kexec at ffffffff8e05dd02
>> #1 [ffffa5308b8c3ca8] __crash_kexec at ffffffff8e12102a
>> #2 [ffffa5308b8c3d68] crash_kexec at ffffffff8e122019
>> #3 [ffffa5308b8c3d80] oops_end at ffffffff8e02e091
>> #4 [ffffa5308b8c3da0] general_protection at ffffffff8e8015c5
>> [exception RIP: nvmet_async_event_work+94]
>> RIP: ffffffffc0d9a80e RSP: ffffa5308b8c3e58 RFLAGS: 00010202
>> RAX: dead000000000100 RBX: ffff92dcbc7464b0 RCX:
>> 0000000000000002
>> RDX: 0000000000040002 RSI: 38ffff92dc9814cf RDI:
>> ffff92f217722f20
>> RBP: ffff92dcbc746418 R8: 0000000000000000 R9:
>> 0000000000000000
>> R10: 000000000000035b R11: ffff92efb8dd2091 R12:
>> ffff92dcbc7464a0
>> R13: ffff92dbe03a5f29 R14: 0000000000000000 R15:
>> 0ffff92f92f26864
>> ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018
>> #5 [ffffa5308b8c3e78] process_one_work at ffffffff8e0a3b0c
>> #6 [ffffa5308b8c3eb8] worker_thread at ffffffff8e0a41e7
>> #7 [ffffa5308b8c3f10] kthread at ffffffff8e0a93af
>> #8 [ffffa5308b8c3f50] ret_from_fork at ffffffff8e800235
>>
>> this maps to nvmet_async_event_results. So it looks like this function
>> access a stale aen pointer:
>>
>> static u32 nvmet_async_event_result(struct nvmet_async_event *aen)
>> {
>> return aen->event_type | (aen->event_info << 8) |
>> (aen->log_page << 16);
>> }
> Can you please explain the test setup ? Is that coming from the tests
> present in the blktests ? if so you can please provide test number ?
No unfortunately this is coming from a customer bug report. We _think_
we're having a race between AEN processing and nvmet_sq_destroy(), but
we're not 100% sure. Hence this RFC.
next prev parent reply other threads:[~2019-10-31 7:06 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-10-30 15:24 [RFC] nvmet: Always remove processed AER elements from list Daniel Wagner
2019-10-30 19:58 ` Chaitanya Kulkarni
2019-10-31 7:06 ` Johannes Thumshirn [this message]
2019-10-31 14:51 ` Christoph Hellwig
2019-11-03 18:55 ` Chaitanya Kulkarni
2019-11-03 19:48 ` Chaitanya Kulkarni
2019-11-03 20:14 ` Chaitanya Kulkarni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=82e496f61183ebdf7924d660d3b8c90e@suse.de \
--to=jthumshirn@suse.de \
--cc=Chaitanya.Kulkarni@wdc.com \
--cc=dwagner@suse.de \
--cc=hch@lst.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).