From sec@42.org Thu Aug 13 19:13:04 2009 Return-Path: Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A96941065670 for ; Thu, 13 Aug 2009 19:13:04 +0000 (UTC) (envelope-from sec@42.org) Received: from ice.42.org (v6.42.org [IPv6:2001:608:9::1]) by mx1.freebsd.org (Postfix) with ESMTP id 5C4988FC16 for ; Thu, 13 Aug 2009 19:13:02 +0000 (UTC) Received: by ice.42.org (Postfix, from userid 1000) id B67B4228C3; Thu, 13 Aug 2009 21:12:59 +0200 (CEST) Message-Id: <20090813191259.B67B4228C3@ice.42.org> Date: Thu, 13 Aug 2009 21:12:59 +0200 (CEST) From: Stefan `Sec` Zehl Reply-To: Stefan `Sec` Zehl To: FreeBSD-gnats-submit@freebsd.org Cc: Subject: snd_hda panics on 8.0-BETA2 X-Send-Pr-Version: 3.113 X-GNATS-Notify: >Number: 137746 >Category: kern >Synopsis: [snd_hda] [panic] snd_hda panics on 8.0-BETA2 >Confidential: no >Severity: serious >Priority: high >Responsible: gavin >State: closed >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Thu Aug 13 19:20:01 UTC 2009 >Closed-Date: Fri Aug 21 09:35:06 UTC 2009 >Last-Modified: Fri Aug 21 09:35:06 UTC 2009 >Originator: Stefan `Sec` Zehl >Release: >Organization: >Environment: FreeBSD karoshi.42.org 8.0-BETA2 FreeBSD 8.0-BETA2 #5: Thu Aug 13 13:01:24 CEST 2009 root@karoshi.42.org:/usr/obj/usr/src/sys/GENERIC i386 >Description: karoshi.42.org dumped core - see /var/crash/vmcore.5 Thu Aug 13 20:59:12 CEST 2009 FreeBSD karoshi.42.org 8.0-BETA2 FreeBSD 8.0-BETA2 #5: Thu Aug 13 13:01:24 CEST 2009 root@karoshi.42.org:/usr/obj/usr/src/sys/GENERIC i386 panic: _sx_xlock_hard: recursed on non-recursive sx newbus @ /usr/src/sys/kern/subr_bus.c:219 GNU gdb 6.1.1 [FreeBSD] Copyright 2004 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "i386-marcel-freebsd"... Unread portion of the kernel message buffer: hdac0: mem 0xfe220000-0xfe223fff irq 17 at device 27.0 on pci0 hdac0: HDA Driver Revision: 20090624_0136 hdac0: [ITHREAD] panic: _sx_xlock_hard: recursed on non-recursive sx newbus @ /usr/src/sys/kern/subr_bus.c:219 cpuid = 0 KDB: enter: panic panic: from debugger cpuid = 0 Uptime: 1h15m15s Physical memory: 3030 MB Dumping 191 MB: 176 160 144 128 112 96 80 64 48 32 16 Reading symbols from /boot/modules/nvidia.ko...done. Loaded symbols for /boot/modules/nvidia.ko Reading symbols from /boot/kernel/linux.ko...Reading symbols from /boot/kernel/linux.ko.symbols...done. done. Loaded symbols for /boot/kernel/linux.ko Reading symbols from /boot/kernel/if_iwn.ko...Reading symbols from /boot/kernel/if_iwn.ko.symbols...done. done. Loaded symbols for /boot/kernel/if_iwn.ko Reading symbols from /boot/kernel/iwnfw.ko...Reading symbols from /boot/kernel/iwnfw.ko.symbols...done. done. Loaded symbols for /boot/kernel/iwnfw.ko Reading symbols from /boot/kernel/snd_ich.ko...Reading symbols from /boot/kernel/snd_ich.ko.symbols...done. done. Loaded symbols for /boot/kernel/snd_ich.ko Reading symbols from /boot/kernel/sound.ko...Reading symbols from /boot/kernel/sound.ko.symbols...done. done. Loaded symbols for /boot/kernel/sound.ko Reading symbols from /boot/kernel/snd_hda.ko...Reading symbols from /boot/kernel/snd_hda.ko.symbols...done. done. Loaded symbols for /boot/kernel/snd_hda.ko #0 doadump () at pcpu.h:246 246 pcpu.h: No such file or directory. in pcpu.h (kgdb) #0 doadump () at pcpu.h:246 #1 0xc085b72c in boot (howto=260) at /usr/src/sys/kern/kern_shutdown.c:419 #2 0xc085ba12 in panic (fmt=Variable "fmt" is not available. ) at /usr/src/sys/kern/kern_shutdown.c:575 #3 0xc04c5f67 in db_panic (addr=Could not find the frame base for "db_panic". ) at /usr/src/sys/ddb/db_command.c:478 #4 0xc04c655e in db_command (last_cmdp=0xc0d53fbc, cmd_table=0x0, dopager=1) at /usr/src/sys/ddb/db_command.c:445 #5 0xc04c6697 in db_command_loop () at /usr/src/sys/ddb/db_command.c:498 #6 0xc04c838f in db_trap (type=3, code=0) at /usr/src/sys/ddb/db_main.c:229 #7 0xc08881d4 in kdb_trap (type=3, code=0, tf=0xebbd1570) at /usr/src/sys/kern/subr_kdb.c:534 #8 0xc0b7315b in trap (frame=0xebbd1570) at /usr/src/sys/i386/i386/trap.c:685 #9 0xc0b5658b in calltrap () at /usr/src/sys/i386/i386/exception.s:165 #10 0xc0888335 in kdb_enter (why=0xc0c32948 "panic", msg=0xc0c32948 "panic") at cpufunc.h:71 #11 0xc085b9f3 in panic ( fmt=0xc0c331cf "_sx_xlock_hard: recursed on non-recursive sx %s @ %s:%d\n") at /usr/src/sys/kern/kern_shutdown.c:558 #12 0xc0862d21 in _sx_xlock_hard (sx=0xc0d97540, tid=3354417984, opts=0, file=0xc0c35266 "/usr/src/sys/kern/subr_bus.c", line=219) at /usr/src/sys/kern/kern_sx.c:484 #13 0xc086340a in _sx_xlock (sx=0xc0d97540, opts=0, file=0xc0c35266 "/usr/src/sys/kern/subr_bus.c", line=219) at sx.h:155 #14 0xc08821d6 in newbus_xlock () at /usr/src/sys/kern/subr_bus.c:219 #15 0xc8db2e06 in hdac_attach2 (arg=0xc73db000) at /usr/src/sys/modules/sound/driver/hda/../../../../dev/sound/pci/hda/hdac.c:7438 #16 0xc8dbbd1e in hdac_attach (dev=0xc7381d00) at /usr/src/sys/modules/sound/driver/hda/../../../../dev/sound/pci/hda/hdac.c:4193 #17 0xc0883397 in device_attach (dev=0xc7381d00) at device_if.h:178 #18 0xc0884065 in device_probe_and_attach (dev=0xc7381d00) at /usr/src/sys/kern/subr_bus.c:2602 #19 0xc06f700d in pci_driver_added (dev=0xc7381700, driver=0xc8dc0dc4) at /usr/src/sys/dev/pci/pci.c:2839 #20 0xc0881276 in devclass_driver_added (dc=0xc715bb80, driver=0xc8dc0dc4) at bus_if.h:183 #21 0xc0882d1b in driver_module_handler (mod=0xc78197c0, what=0, arg=0xc8dc0d94) at /usr/src/sys/kern/subr_bus.c:1084 #22 0xc084be20 in module_register_init (arg=0xc8dc0cf0) at /usr/src/sys/kern/kern_module.c:124 #23 0xc0843c05 in linker_load_module (kldname=Variable "kldname" is not available. ) at /usr/src/sys/kern/kern_linker.c:234 #24 0xc08440e8 in kern_kldload (td=0xc7f05b40, file=0xc75c7400 "snd_hda", fileid=0xebbd1c74) at /usr/src/sys/kern/kern_linker.c:1016 #25 0xc084420b in kldload (td=0xc7f05b40, uap=0xebbd1cf8) at /usr/src/sys/kern/kern_linker.c:1044 #26 0xc0b728da in syscall (frame=0xebbd1d38) at /usr/src/sys/i386/i386/trap.c:1073 #27 0xc0b565f0 in Xint0x80_syscall () at /usr/src/sys/i386/i386/exception.s:261 #28 0x00000033 in ?? () Previous frame inner to this frame (corrupt stack?) (kgdb) ------------------------------------------------------------------------ dmesg Copyright (c) 1992-2009 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD is a registered trademark of The FreeBSD Foundation. FreeBSD 8.0-BETA2 #5: Thu Aug 13 13:01:24 CEST 2009 root@karoshi.42.org:/usr/obj/usr/src/sys/GENERIC WARNING: WITNESS option enabled, expect reduced performance. Timecounter "i8254" frequency 1193182 Hz quality 0 CPU: Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz (2203.30-MHz 686-class CPU) Origin = "GenuineIntel" Id = 0x6fb Stepping = 11 Features=0xbfebfbff Features2=0xe3bd AMD Features=0x20100000 AMD Features2=0x1 TSC: P-state invariant real memory = 3221225472 (3072 MB) avail memory = 3115368448 (2971 MB) ACPI APIC Table: FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs FreeBSD/SMP: 1 package(s) x 2 core(s) cpu0 (BSP): APIC ID: 0 cpu1 (AP): APIC ID: 1 ACPI Warning: 32/64X length mismatch in Gpe1Block: 0/32 20090521 tbfadt-625 ACPI Warning: Optional field Gpe1Block has zero address or length: 0 102C/0 20090521 tbfadt-655 ioapic0: Changing APIC ID to 1 ioapic0 irqs 0-23 on motherboard kbd1 at kbdmux0 acpi0: on motherboard acpi0: [ITHREAD] acpi_ec0: port 0x62,0x66 on acpi0 acpi0: Power Button (fixed) acpi0: reservation of 0, a0000 (3) failed acpi0: reservation of 100000, bef00000 (3) failed Timecounter "ACPI-safe" frequency 3579545 Hz quality 850 acpi_timer0: <24-bit timer at 3.579545MHz> port 0x1008-0x100b on acpi0 acpi_hpet0: iomem 0xfed00000-0xfed003ff on acpi0 Timecounter "HPET" frequency 14318180 Hz quality 900 acpi_lid0: on acpi0 acpi_button0: on acpi0 pcib0: port 0xcf8-0xcff on acpi0 pci0: on pcib0 pcib1: irq 16 at device 1.0 on pci0 pci1: on pcib1 vgapci0: port 0x2000-0x207f mem 0xd6000000-0xd6ffffff,0xe0000000-0xefffffff,0xd4000000-0xd5ffffff irq 16 at device 0.0 on pci1 nvidia0: on vgapci0 vgapci0: child nvidia0 requested pci_enable_busmaster vgapci0: child nvidia0 requested pci_enable_io vgapci0: child nvidia0 requested pci_enable_io nvidia0: [GIANT-LOCKED] nvidia0: [ITHREAD] em0: port 0x1840-0x185f mem 0xfe200000-0xfe21ffff,0xfe225000-0xfe225fff irq 20 at device 25.0 on pci0 em0: Using MSI interrupt em0: [FILTER] em0: Ethernet address: 00:1c:25:20:63:10 uhci0: port 0x1860-0x187f irq 20 at device 26.0 on pci0 uhci0: [ITHREAD] uhci0: LegSup = 0x0000 usbus0: on uhci0 uhci1: port 0x1880-0x189f irq 21 at device 26.1 on pci0 uhci1: [ITHREAD] uhci1: LegSup = 0x0000 usbus1: on uhci1 ehci0: mem 0xfe226c00-0xfe226fff irq 22 at device 26.7 on pci0 ehci0: [ITHREAD] usbus2: EHCI version 1.0 usbus2: on ehci0 pci0: at device 27.0 (no driver attached) pcib2: irq 20 at device 28.0 on pci0 pci2: on pcib2 pcib3: irq 21 at device 28.1 on pci0 pci3: on pcib3 pci3: at device 0.0 (no driver attached) pcib4: irq 22 at device 28.2 on pci0 pci4: on pcib4 pcib5: irq 23 at device 28.3 on pci0 pci5: on pcib5 pcib6: irq 20 at device 28.4 on pci0 pci13: on pcib6 uhci2: port 0x18a0-0x18bf irq 16 at device 29.0 on pci0 uhci2: [ITHREAD] uhci2: LegSup = 0x0000 usbus3: on uhci2 uhci3: port 0x18c0-0x18df irq 17 at device 29.1 on pci0 uhci3: [ITHREAD] uhci3: LegSup = 0x0000 usbus4: on uhci3 uhci4: port 0x18e0-0x18ff irq 18 at device 29.2 on pci0 uhci4: [ITHREAD] uhci4: LegSup = 0x0000 usbus5: on uhci4 ehci1: mem 0xfe227000-0xfe2273ff irq 19 at device 29.7 on pci0 ehci1: [ITHREAD] usbus6: EHCI version 1.0 usbus6: on ehci1 pcib7: at device 30.0 on pci0 pci21: on pcib7 cbb0: mem 0xf8100000-0xf8100fff irq 16 at device 0.0 on pci21 cardbus0: on cbb0 pccard0: <16-bit PCCard bus> on cbb0 cbb0: [FILTER] fwohci0: <1394 Open Host Controller Interface> mem 0xf8101000-0xf81017ff irq 17 at device 0.1 on pci21 fwohci0: [ITHREAD] fwohci0: OHCI version 1.10 (ROM=0) fwohci0: No. of Isochronous channels is 4. fwohci0: EUI64 00:01:6c:20:00:38:8e:89 fwohci0: Phy 1394a available S400, 1 ports. fwohci0: Link S400, max_rec 2048 bytes. firewire0: on fwohci0 dcons_crom0: on firewire0 dcons_crom0: bus_addr 0x1ca8000 fwe0: on firewire0 if_fwe0: Fake Ethernet address: 02:01:6c:38:8e:89 fwe0: Ethernet address: 02:01:6c:38:8e:89 fwip0: on firewire0 fwip0: Firewire address: 00:01:6c:20:00:38:8e:89 @ 0xfffe00000000, S400, maxrec 2048 sbp0: on firewire0 fwohci0: Initiate bus reset fwohci0: fwohci_intr_core: BUS reset fwohci0: fwohci_intr_core: node_id=0x00000000, SelfID Count=1, CYCLEMASTER mode pci21: at device 0.2 (no driver attached) pci21: at device 0.3 (no driver attached) pci21: at device 0.4 (no driver attached) pci21: at device 0.5 (no driver attached) isab0: at device 31.0 on pci0 isa0: on isab0 atapci0: port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0x1830-0x183f at device 31.1 on pci0 ata0: on atapci0 ata0: [ITHREAD] atapci1: port 0x1c48-0x1c4f,0x1c1c-0x1c1f,0x1c40-0x1c47,0x1c18-0x1c1b,0x1c20-0x1c3f mem 0xfe226000-0xfe2267ff irq 16 at device 31.2 on pci0 atapci1: [ITHREAD] atapci1: AHCI called from vendor specific driver atapci1: AHCI v1.10 controller with 3 1.5Gbps ports, PM not supported ata2: on atapci1 ata2: [ITHREAD] ata3: on atapci1 ata3: [ITHREAD] pci0: at device 31.3 (no driver attached) acpi_tz0: on acpi0 acpi_tz1: on acpi0 atrtc0: port 0x70-0x71 irq 8 on acpi0 atkbdc0: port 0x60,0x64 irq 1 on acpi0 atkbd0: irq 1 on atkbdc0 kbd0 at atkbd0 atkbd0: [GIANT-LOCKED] atkbd0: [ITHREAD] psm0: irq 12 on atkbdc0 psm0: [GIANT-LOCKED] psm0: [ITHREAD] psm0: model Generic PS/2 mouse, device ID 0 battery0: on acpi0 acpi_acad0: on acpi0 cpu0: on acpi0 est0: on cpu0 p4tcc0: on cpu0 cpu1: on acpi0 est1: on cpu1 p4tcc1: on cpu1 pmtimer0 on isa0 orm0: at iomem 0xc0000-0xcefff,0xcf000-0xcffff,0xd0000-0xd0fff,0xe0000-0xeffff pnpid ORM0000 on isa0 sc0: at flags 0x100 on isa0 sc0: VGA <16 virtual consoles, flags=0x300> vga0: at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0 ppc0: cannot reserve I/O port range Timecounters tick every 1.000 msec firewire0: 1 nodes, maxhop <= 0 cable IRM irm(0) (me) firewire0: bus manager 0 usbus0: 12Mbps Full Speed USB v1.0 usbus1: 12Mbps Full Speed USB v1.0 usbus2: 480Mbps High Speed USB v2.0 usbus3: 12Mbps Full Speed USB v1.0 usbus4: 12Mbps Full Speed USB v1.0 usbus5: 12Mbps Full Speed USB v1.0 usbus6: 480Mbps High Speed USB v2.0 acd0: DVDR at ata0-master UDMA33 ad4: 152627MB at ata2-master SATA150 ugen0.1: at usbus0 uhub0: on usbus0 GEOM: ad4s2: geometry does not match label (255h,63s != 16h,63s). uhub0: 2 ports with 2 removable, self powered ugen1.1: at usbus1 uhub1: on usbus1 uhub1: 2 ports with 2 removable, self powered ugen2.1: at usbus2 uhub2: on usbus2 uhub2: 4 ports with 4 removable, self powered ugen3.1: at usbus3 uhub3: on usbus3 uhub3: 2 ports with 2 removable, self powered ugen4.1: at usbus4 uhub4: on usbus4 uhub4: 2 ports with 2 removable, self powered ugen5.1: at usbus5 uhub5: on usbus5 uhub5: 2 ports with 2 removable, self powered ugen6.1: at usbus6 uhub6: on usbus6 SMP: AP CPU #1 Launched! WARNING: WITNESS option enabled, expect reduced performance. Root mount waiting for: cbb0 usbus6 Root mount waiting for: cbb0 usbus6 Root mount waiting for: cbb0 usbus6 uhub6: 6 ports with 6 removable, self powered Trying to mount root from ufs:/dev/ad4s2a ugen0.2: at usbus0 Entropy harvesting: interrupts ethernet point_to_point kickstart . /dev/ad4s2a: FILE SYSTEM CLEAN; SKIPPING CHECKS /dev/ad4s2a: clean, 41538 free (1602 frags, 4992 blocks, 0.6% fragmentation) /dev/ad4s2e: FILE SYSTEM CLEAN; SKIPPING CHECKS /dev/ad4s2e: clean, 2984034 free (151554 frags, 354060 blocks, 2.6% fragmentation) /dev/ad4s2d: FILE SYSTEM CLEAN; SKIPPING CHECKS /dev/ad4s2d: clean, 1542799 free (12951 frags, 191231 blocks, 0.6% fragmentation) Starting Network: lo0 em0. Generating host.conf. em0: link state changed to UP Starting hald. Starting local daemons: . Configuring syscons: keymap blanktime . Thu Aug 13 19:42:10 CEST 2009 lock order reversal: 1st 0xc78b2e2c filedesc structure (filedesc structure) @ /usr/src/sys/kern/sys_generic.c:1211 2nd 0xc7cbace8 devfs (devfs) @ /usr/src/sys/kern/vfs_vnops.c:863 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,e9b40960,c089a67f,c088bf9b,c0c38a18,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a18,c712c1d0,c712f9e0,e9b409bc,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a18,c7cbace8,c0c27a26,c712f9e0,c0c40e6c,...) at _witness_debugger+0x1e witness_checkorder(c7cbace8,9,c0c40e6c,35f,c7cbad04,...) at witness_checkorder+0x818 __lockmgr_args(c7cbace8,80400,c7cbad04,0,0,0,c0c40e6c,35f) at __lockmgr_args+0x771 vop_stdlock(e9b40ab8,c7a43ccc,e9b40b90,80400,c7cbac90,...) at vop_stdlock+0x5c VOP_LOCK1_APV(c0d14560,e9b40ab8,7ca,c0d51c40,c7cbac90,...) at VOP_LOCK1_APV+0xaf _vn_lock(c7cbac90,80400,c0c40e6c,35f,0,...) at _vn_lock+0x5e vn_poll(c7849380,1,c7825b00,c7b086c0,e9b40b60,...) at vn_poll+0x70 poll(c7b086c0,e9b40cf8,c,c0c3955b,c0d1903c,...) at poll+0x214 syscall(e9b40d38) at syscall+0x281 Xint0x80_syscall() at Xint0x80_syscall+0x20 --- syscall (209, FreeBSD ELF32, poll), eip = 0x282fb113, esp = 0xbfbfe32c, ebp = 0xbfbfe348 --- iwn0: mem 0xdf2fe000-0xdf2fffff irq 17 at device 0.0 on pci3 iwn0: Reg Domain: MoW2, address 00:1d:e0:4e:8c:b1 iwn0: [ITHREAD] iwn0: 11a rates: 6Mbps 9Mbps 12Mbps 18Mbps 24Mbps 36Mbps 48Mbps 54Mbps iwn0: 11b rates: 1Mbps 2Mbps 5.5Mbps 11Mbps iwn0: 11g rates: 1Mbps 2Mbps 5.5Mbps 11Mbps 6Mbps 9Mbps 12Mbps 18Mbps 24Mbps 36Mbps 48Mbps 54Mbps iwn0: 11na MCS: 15Mbps 30Mbps 45Mbps 60Mbps 90Mbps 120Mbps 135Mbps 150Mbps 30Mbps 60Mbps 90Mbps 120Mbps 180Mbps 240Mbps 270Mbps 300Mbps iwn0: 11ng MCS: 15Mbps 30Mbps 45Mbps 60Mbps 90Mbps 120Mbps 135Mbps 150Mbps 30Mbps 60Mbps 90Mbps 120Mbps 180Mbps 240Mbps 270Mbps 300Mbps wlan0: Ethernet address: 00:1d:e0:4e:8c:b1 iwn0: radio is disabled by hardware switch iwn0: RF switch: radio enabled iwn0: error, INTR=2000000 STATUS=0x0 iwn0: iwn_transfer_firmware: timeout waiting for first alive notice, error 35 iwn0: iwn_init_locked: could not load firmware, error 35 lock order reversal: 1st 0xc7fae014 iwn0_com_lock (iwn0_com_lock) @ /usr/src/sys/net80211/ieee80211_proto.c:1082 2nd 0xc7f53058 iwn0 (network driver) @ /usr/src/sys/modules/iwn/../../dev/iwn/if_iwn.c:2845 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,ebd1b9e4,c089a67f,c088bf9b,c0c38a18,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a18,c712fe58,c7129040,ebd1ba40,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a18,c7f53058,c737d420,c7129040,c7f4b5aa,...) at _witness_debugger+0x1e witness_checkorder(c7f53058,9,c7f4b5aa,b1d,0,...) at witness_checkorder+0x818 _mtx_lock_flags(c7f53058,0,c7f4b5aa,b1d,c089a45b,...) at _mtx_lock_flags+0xb8 iwn_wme_update(c7fae000,43a,ebd1baf8,c084ce56,c7fae014,...) at iwn_wme_update+0xb5 ieee80211_wme_updateparams_locked(c78a8000,0,c0c48a36,43a,4,...) at ieee80211_wme_updateparams_locked+0x247 ieee80211_wme_updateparams(c78a8000,c0bbe770,c0c48a36,36b,c7fae014,...) at ieee80211_wme_updateparams+0x42 ieee80211_wme_initparams(c78a8000,c7fae2f8,28,c7fae000,0,...) at ieee80211_wme_initparams+0x1b0 ieee80211_sta_join1(c7fc4000,c7eb732e,c7eb733f,1) at ieee80211_sta_join1+0xd0 ieee80211_sta_join(c78a8000,c7fae2f8,c7eb7300,c7e81800,c7fae000,...) at ieee80211_sta_join+0x1ed sta_pick_bss(c7e81800,c78a8000,c0c4919d,1f4,c0d86780,...) at sta_pick_bss+0xfa ieee80211_check_scan(c78a8000,2,7fffffff,0,0,...) at ieee80211_check_scan+0x1d9 ieee80211_check_scan_current(c78a8000,0,c0c497fd,d3,c7f4b5aa,...) at ieee80211_check_scan_current+0x45 sta_newstate(c78a8000,1,0,616,ebd1bca4,...) at sta_newstate+0x24a ieee80211_newstate_cb(c78a8000,1,c0c3737f,54,c7e8f6dc,...) at ieee80211_newstate_cb+0x173 taskqueue_run(c7e8f6c0,c7e8f6dc,0,c0c28819,0,...) at taskqueue_run+0x108 taskqueue_thread_loop(c7fae074,ebd1bd38,c0c2deaa,33e,c0d84420,...) at taskqueue_thread_loop+0x65 fork_exit(c0893cec,c7fae074,ebd1bd38) at fork_exit+0xb8 fork_trampoline() at fork_trampoline+0x8 --- trap 0, eip = 0, esp = 0xebd1bd70, ebp = 0 --- iwn0: iwn_config: could not set power mode, error 35 iwn0: iwn_config: could not set power mode, error 35 iwn0: iwn_config: could not set power mode, error 35 lock order reversal: 1st 0xc0d854a0 module subsystem sx lock (module subsystem sx lock) @ /usr/src/sys/kern/kern_linker.c:602 2nd 0xc0d97540 newbus (newbus) @ /usr/src/sys/kern/subr_bus.c:4127 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,ebbdab38,c089a67f,c088bf9b,c0c38a18,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a18,c712bc20,c712c9f0,ebbdab94,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a18,c0d97540,c0c35234,c712c9f0,c0c35266,...) at _witness_debugger+0x1e witness_checkorder(c0d97540,9,c0c35266,101f,0,...) at witness_checkorder+0x818 _sx_xlock(c0d97540,0,c0c35266,101f,c7f4d9d8,...) at _sx_xlock+0x7f driver_module_handler(c7e8f180,3,c7f4d9d8,fc,0,...) at driver_module_handler+0x43 module_quiesce(c7e8f180,0,c0c2f31d,25a,c0841349,...) at module_quiesce+0x43 linker_file_unload(c7d18a00,0,c0c2f31d,42c,c7f3d000,...) at linker_file_unload+0x9a kern_kldunload(c7f05480,5,0,ebbdad2c,c0b728da,...) at kern_kldunload+0xd0 kldunloadf(c7f05480,ebbdacf8,8,c0c39ada,c0d1a9f0,...) at kldunloadf+0x2d syscall(ebbdad38) at syscall+0x281 Xint0x80_syscall() at Xint0x80_syscall+0x20 --- syscall (444, FreeBSD ELF32, kldunloadf), eip = 0x280d29c7, esp = 0xbfbfe11c, ebp = 0xbfbfe968 --- lock order reversal: 1st 0xc0d84ddc kernel linker (kernel linker) @ /usr/src/sys/kern/kern_linker.c:1068 2nd 0xc0d97540 newbus (newbus) @ /usr/src/sys/kern/subr_bus.c:4127 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,ebbdab38,c089a67f,c088bf9b,c0c38a18,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a18,c712bc88,c712c9f0,ebbdab94,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a18,c0d97540,c0c35234,c712c9f0,c0c35266,...) at _witness_debugger+0x1e witness_checkorder(c0d97540,9,c0c35266,101f,0,...) at witness_checkorder+0x818 _sx_xlock(c0d97540,0,c0c35266,101f,c7f4d9d8,...) at _sx_xlock+0x7f driver_module_handler(c7e8f180,1,c7f4d9d8,109,0,...) at driver_module_handler+0x43 module_unload(c7e8f180,c0c2f31d,274,271,c0841349,...) at module_unload+0x43 linker_file_unload(c7d18a00,0,c0c2f31d,42c,c7f3d000,...) at linker_file_unload+0x14d kern_kldunload(c7f05480,5,0,ebbdad2c,c0b728da,...) at kern_kldunload+0xd0 kldunloadf(c7f05480,ebbdacf8,8,c0c39ada,c0d1a9f0,...) at kldunloadf+0x2d syscall(ebbdad38) at syscall+0x281 Xint0x80_syscall() at Xint0x80_syscall+0x20 --- syscall (444, FreeBSD ELF32, kldunloadf), eip = 0x280d29c7, esp = 0xbfbfe11c, ebp = 0xbfbfe968 --- iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: iwn_mem_lock: could not lock memory iwn0: detached lock order reversal: 1st 0xc0d84ddc kernel linker (kernel linker) @ /usr/src/sys/kern/kern_linker.c:1068 2nd 0xc0d865e4 sysctl lock (sysctl lock) @ /usr/src/sys/kern/kern_sysctl.c:256 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,ebbdaad8,c089a67f,c088bf9b,c0c38a18,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a18,c712bc88,c7129e10,ebbdab34,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a18,c0d865e4,c0c336b8,c7129e10,c0c335bf,...) at _witness_debugger+0x1e witness_checkorder(c0d865e4,9,c0c335bf,100,0,...) at witness_checkorder+0x818 _sx_xlock(c0d865e4,0,c0c335bf,100,c7432b80,...) at _sx_xlock+0x7f sysctl_ctx_free(c7432bcc,c7432b80,ebbdabbc,c088294c,c7432b80,...) at sysctl_ctx_free+0x30 device_sysctl_fini(c7432b80,0,c0d16de8,c737d420,c715a800,...) at device_sysctl_fini+0x1a device_detach(c7432b80,4,c0c35266,458,c7f4d9d8,...) at device_detach+0x1f7 driver_module_handler(c7e8f180,1,c7f4d9d8,109,0,...) at driver_module_handler+0x330 module_unload(c7e8f180,c0c2f31d,274,271,c0841349,...) at module_unload+0x43 linker_file_unload(c7d18a00,0,c0c2f31d,42c,c7f3d000,...) at linker_file_unload+0x14d kern_kldunload(c7f05480,5,0,ebbdad2c,c0b728da,...) at kern_kldunload+0xd0 kldunloadf(c7f05480,ebbdacf8,8,c0c39ada,c0d1a9f0,...) at kldunloadf+0x2d syscall(ebbdad38) at syscall+0x281 Xint0x80_syscall() at Xint0x80_syscall+0x20 --- syscall (444, FreeBSD ELF32, kldunloadf), eip = 0x280d29c7, esp = 0xbfbfe11c, ebp = 0xbfbfe968 --- iwn0: mem 0xdf2fe000-0xdf2fffff irq 17 at device 0.0 on pci3 iwn0: Reg Domain: MoW2, address 00:1d:e0:4e:8c:b1 iwn0: [ITHREAD] iwn0: 11a rates: 6Mbps 9Mbps 12Mbps 18Mbps 24Mbps 36Mbps 48Mbps 54Mbps iwn0: 11b rates: 1Mbps 2Mbps 5.5Mbps 11Mbps iwn0: 11g rates: 1Mbps 2Mbps 5.5Mbps 11Mbps 6Mbps 9Mbps 12Mbps 18Mbps 24Mbps 36Mbps 48Mbps 54Mbps iwn0: 11na MCS: 15Mbps 30Mbps 45Mbps 60Mbps 90Mbps 120Mbps 135Mbps 150Mbps 30Mbps 60Mbps 90Mbps 120Mbps 180Mbps 240Mbps 270Mbps 300Mbps iwn0: 11ng MCS: 15Mbps 30Mbps 45Mbps 60Mbps 90Mbps 120Mbps 135Mbps 150Mbps 30Mbps 60Mbps 90Mbps 120Mbps 180Mbps 240Mbps 270Mbps 300Mbps wlan0: Ethernet address: 00:1d:e0:4e:8c:b1 iwn0: error, INTR=2000000 STATUS=0x0 iwn0: iwn_transfer_firmware: timeout waiting for first alive notice, error 35 iwn0: iwn_init_locked: could not load firmware, error 35 iwn0: iwn_config: could not set power mode, error 35 iwn0: iwn_config: could not set power mode, error 35 em0: link state changed to DOWN iwn0: iwn_config: could not set power mode, error 35 iwn0: error, INTR=2000000 STATUS=0x0 iwn0: iwn_config: could not set power mode, error 35 iwn0: iwn_transfer_firmware: timeout waiting for first alive notice, error 35 iwn0: iwn_init_locked: could not load firmware, error 35 iwn0: iwn_config: could not set power mode, error 35 em0: link state changed to UP lock order reversal: 1st 0xdb1be040 bufwait (bufwait) @ /usr/src/sys/kern/vfs_bio.c:2559 2nd 0xc7efea00 dirhash (dirhash) @ /usr/src/sys/ufs/ufs/ufs_dirhash.c:285 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,e9a7a764,c089a67f,c088bf9b,c0c38a18,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a18,c712bef8,c712fb18,e9a7a7c0,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a18,c7efea00,c0c59ae3,c712fb18,c0c5977c,...) at _witness_debugger+0x1e witness_checkorder(c7efea00,9,c0c5977c,11d,0,...) at witness_checkorder+0x818 _sx_xlock(c7efea00,0,c0c5977c,11d,c8060cb0,...) at _sx_xlock+0x7f ufsdirhash_acquire(db1bdfe0,ddc70228,1d8,ddc7023c,e9a7a890,...) at ufsdirhash_acquire+0x31 ufsdirhash_add(c8060cb0,e9a7a8d8,123c,e9a7a87c,e9a7a880,...) at ufsdirhash_add+0x13 ufs_direnter(c8058a78,c806296c,e9a7a8d8,e9a7abd4,0,...) at ufs_direnter+0x70e ufs_makeinode(e9a7abd4) at ufs_makeinode+0x4f8 ufs_create(e9a7aac0,e9a7aad8,0,0,e9a7aba8,...) at ufs_create+0x2c VOP_CREATE_APV(c0d391c0,e9a7aac0,e9a7abd4,e9a7aa58,0,...) at VOP_CREATE_APV+0xa2 vn_open_cred(e9a7aba8,e9a7ac60,180,0,c7eec100,...) at vn_open_cred+0x215 vn_open(e9a7aba8,e9a7ac60,180,c7e9ca80,c717a740,...) at vn_open+0x3b kern_openat(c7840480,ffffff9c,2c943ec8,0,203,...) at kern_openat+0x116 kern_open(c7840480,2c943ec8,0,202,180,...) at kern_open+0x35 open(c7840480,e9a7acf8,c,c0c3955b,c0d179ec,...) at open+0x30 syscall(e9a7ad38) at syscall+0x281 Xint0x80_syscall() at Xint0x80_syscall+0x20 --- syscall (5, FreeBSD ELF32, open), eip = 0x29bdbc77, esp = 0xbfbfcb08, ebp = 0xbfbfcb34 --- lock order reversal: 1st 0xc8a9cad0 ufs (ufs) @ /usr/src/sys/kern/vfs_lookup.c:497 2nd 0xdb324690 bufwait (bufwait) @ /usr/src/sys/ufs/ffs/ffs_softdep.c:6170 3rd 0xc8b0b6a0 ufs (ufs) @ /usr/src/sys/kern/vfs_subr.c:2083 KDB: stack backtrace: db_trace_self_wrapper(c0c35b4c,e9b8e2c0,c089a67f,c088bf9b,c0c38a31,...) at db_trace_self_wrapper+0x26 kdb_backtrace(c088bf9b,c0c38a31,c712bef8,c712fab0,e9b8e31c,...) at kdb_backtrace+0x29 _witness_debugger(c0c38a31,c8b0b6a0,c0c2b6cb,c712fab0,c0c3fca3,...) at _witness_debugger+0x1e witness_checkorder(c8b0b6a0,9,c0c3fca3,823,0,...) at witness_checkorder+0x818 __lockmgr_args(c8b0b6a0,80100,c8b0b6bc,0,0,...) at __lockmgr_args+0x771 ffs_lock(e9b8e424,c089a45b,c0c3f196,80100,c8b0b648,...) at ffs_lock+0x7d VOP_LOCK1_APV(c0d391c0,e9b8e424,c7cf1e24,c0d51c40,c8b0b648,...) at VOP_LOCK1_APV+0xaf _vn_lock(c8b0b648,80100,c0c3fca3,823,4,...) at _vn_lock+0x5e vget(c8b0b648,80100,c7cf1d80,50,0,...) at vget+0xb8 vfs_hash_get(c7955508,16a5db,80000,c7cf1d80,e9b8e580,...) at vfs_hash_get+0xdf ffs_vgetf(c7955508,16a5db,80000,e9b8e580,1,...) at ffs_vgetf+0x43 softdep_sync_metadata(c8a9ca78,0,c0c593f5,146,0,...) at softdep_sync_metadata+0x5a6 ffs_syncvnode(c8a9ca78,1,e9b8e618,c089a45b,c0c3111c,...) at ffs_syncvnode+0x3c9 ffs_truncate(c8a9ca78,400,0,880,c8141c00,...) at ffs_truncate+0x644 ufs_direnter(c8a9ca78,c8b39c90,e9b8e8d8,e9b8ebd4,0,...) at ufs_direnter+0x8d6 ufs_makeinode(e9b8ebd4) at ufs_makeinode+0x4f8 ufs_create(e9b8eac0,e9b8ead8,0,0,e9b8eba8,...) at ufs_create+0x2c VOP_CREATE_APV(c0d391c0,e9b8eac0,e9b8ebd4,e9b8ea58,0,...) at VOP_CREATE_APV+0xa2 vn_open_cred(e9b8eba8,e9b8ec60,1a4,0,c8141c00,...) at vn_open_cred+0x215 vn_open(e9b8eba8,e9b8ec60,1a4,c80328f8,1ef,...) at vn_open+0x3b kern_openat(c7cf1d80,ffffff9c,2832c844,0,602,...) at kern_openat+0x116 kern_open(c7cf1d80,2832c844,0,601,1b6,...) at kern_open+0x35 open(c7cf1d80,e9b8ecf8,c,e9b8ed2c,c0d179ec,...) at open+0x30 syscall(e9b8ed38) at syscall+0x281 Xint0x80_syscall() at Xint0x80_syscall+0x20 --- syscall (5, FreeBSD ELF32, open), eip = 0x281d0c77, esp = 0xbfbfde9c, ebp = 0xbfbfdf28 --- pid 1228 (wmx), uid 1001: exited on signal 11 (core dumped) Aug 13 20:56:14 karoshi xdm: pam_sm_close_session(): no utmp record for :0 hdac0: mem 0xfe220000-0xfe223fff irq 17 at device 27.0 on pci0 hdac0: HDA Driver Revision: 20090624_0136 hdac0: [ITHREAD] panic: _sx_xlock_hard: recursed on non-recursive sx newbus @ /usr/src/sys/kern/subr_bus.c:219 cpuid = 0 KDB: enter: panic panic: from debugger cpuid = 0 Uptime: 1h15m15s Physical memory: 3030 MB Dumping 191 MB: 176 160 144 128 112 96 80 64 48 32 16 ------------------------------------------------------------------------ >How-To-Repeat: kldload /boot/kernel/snd_hda.ko >Fix: none known. >Release-Note: >Audit-Trail: State-Changed-From-To: open->feedback State-Changed-By: gavin State-Changed-When: Sat Aug 15 13:18:25 UTC 2009 State-Changed-Why: Hi, This is a known problem. A fix has not yet been committed, but is available at http://people.freebsd.org/~attilio/hdac.diff - I believe this or a patch similar to this is planned to be committed before BETA3. Please could you test that patch and let us know if it fixes the problem you are seeing? Responsible-Changed-From-To: freebsd-bugs->gavin Responsible-Changed-By: gavin Responsible-Changed-When: Sat Aug 15 13:18:25 UTC 2009 Responsible-Changed-Why: Track http://www.freebsd.org/cgi/query-pr.cgi?pr=137746 State-Changed-From-To: feedback->closed State-Changed-By: gavin State-Changed-When: Fri Aug 21 09:34:19 UTC 2009 State-Changed-Why: Closing, as the change that introduced this bug has been reverted in r196403. http://www.freebsd.org/cgi/query-pr.cgi?pr=137746 >Unformatted: