Bug 14920 - oe-selftest-armhost qemu x86-64 kernel NULL pointer dereference in handle_level_irq/setup_IO_APIC
Summary: oe-selftest-armhost qemu x86-64 kernel NULL pointer dereference in handle_lev...
Status: RESOLVED WONTFIX
Alias: None
Product: Runtime Testing
Classification: QA/Testing
Component: oeqa/runtime (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: 4.3
Assignee: Ross Burton
QA Contact:
URL:
Whiteboard: AB-INT
Depends on:
Blocks:
 
Reported: 2022-09-29 00:27 UTC by Alexandre Belloni
Modified: 2023-05-25 14:59 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandre Belloni 2022-09-29 00:27:26 UTC
https://autobuilder.yoctoproject.org/typhoon/#/builders/127/builds/184/steps/14/logs/stdio

[    0.003000] APIC: Switch to symmetric I/O mode setup
[    0.014000] BUG: kernel NULL pointer dereference, address: 0000000000000000
[    0.014000] #PF: supervisor read access in kernel mode
[    0.014000] #PF: error_code(0x0000) - not-present page
[    0.014000] PGD 0 P4D 0 
[    0.014000] Oops: 0000 [#1] PREEMPT SMP PTI
[    0.014000] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.19.9-yocto-standard #1
[    0.014000] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
[    0.014000] RIP: 0010:mask_ioapic_irq+0x1d/0xc0
[    0.014000] Code: 00 00 00 00 eb d8 0f 1f 80 00 00 00 00 0f 1f 44 00 00 55 48 89 e5 53 48 8b 5f 30 48 c7 c7 c8 d5 04 8c e8 26 04 d1 00 48 89 c6 <48> 8b 0b 80 4b 12 01 48 39 cb 74 74 8b 41 14 8b 7b 10 44 8d 44 00
[    0.014000] RSP: 0000:ffff8db300003f90 EFLAGS: 00000046
[    0.014000] RAX: 0000000000000086 RBX: 0000000000000000 RCX: 4000000000000002
[    0.014000] RDX: 0000000000000001 RSI: 0000000000000086 RDI: 0000000000000001
[    0.014000] RBP: ffff8db300003f98 R08: 0000000000000001 R09: 0000000000000000
[    0.014000] R10: 0000000000000000 R11: ffff8db300003ff8 R12: ffff8b49c11da0a4
[    0.014000] R13: 0000000000000030 R14: 0000000000000000 R15: 0000000000000000
[    0.014000] FS:  0000000000000000(0000) GS:ffff8b49cf800000(0000) knlGS:0000000000000000
[    0.014000] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[    0.014000] CR2: 0000000000000000 CR3: 000000000620a000 CR4: 00000000000406b0
[    0.014000] Call Trace:
[    0.014000]  <IRQ>
[    0.014000]  handle_level_irq+0x123/0x190
[    0.014000]  __common_interrupt+0x6d/0x110
[    0.014000]  common_interrupt+0xac/0xd0
[    0.014000]  </IRQ>
[    0.014000]  <TASK>
[    0.014000]  asm_common_interrupt+0x27/0x40
[    0.014000] RIP: 0010:mp_irqdomain_alloc+0xf3/0x290
[    0.014000] Code: 00 48 63 43 30 4d 89 6d 00 4d 89 6d 08 49 89 47 08 48 8b 05 e7 11 9f 01 49 39 46 50 0f 84 62 01 00 00 49 c7 47 18 60 0f e2 8b <4c> 63 75 b0 4d 89 6f 30 8b 7d c0 4b 8d 04 f6 03 3c c5 d8 b1 04 8c
[    0.014000] RSP: 0000:ffffffff8bc03c70 EFLAGS: 00000246
[    0.014000] RAX: ffff8b49c1136780 RBX: ffffffff8bc03d80 RCX: 0000000000000000
[    0.014000] RDX: 0000000000000002 RSI: 0000000000000202 RDI: 00000000ffffffff
[    0.014000] RBP: ffffffff8bc03cc0 R08: 0000000000000001 R09: 0000000000000000
[    0.014000] R10: ffff8b49c11f0100 R11: ffffffff8bcbf388 R12: 0000000000000000
[    0.014000] R13: ffff8b49c104f420 R14: ffff8b49c11e2200 R15: ffff8b49c11da028
[    0.014000]  __irq_domain_alloc_irqs+0xe1/0x3c0
[    0.014000]  alloc_isa_irq_from_domain.constprop.0+0xb0/0xe0
[    0.014000]  mp_map_pin_to_irq+0x202/0x3b0
[    0.014000]  setup_IO_APIC+0x14d/0x8ba
[    0.014000]  apic_intr_mode_init+0x10a/0x115
[    0.014000]  x86_late_time_init+0x24/0x39
[    0.014000]  start_kernel+0x5ea/0x6a6
[    0.014000]  x86_64_start_reservations+0x24/0x2a
[    0.014000]  x86_64_start_kernel+0x8c/0x95
[    0.014000]  secondary_startup_64_no_verify+0xe0/0xeb
[    0.014000]  </TASK>
[    0.014000] Modules linked in:
[    0.014000] CR2: 0000000000000000
[    0.014000] ---[ end trace 0000000000000000 ]---
[    0.014000] RIP: 0010:mask_ioapic_irq+0x1d/0xc0
[    0.014000] Code: 00 00 00 00 eb d8 0f 1f 80 00 00 00 00 0f 1f 44 00 00 55 48 89 e5 53 48 8b 5f 30 48 c7 c7 c8 d5 04 8c e8 26 04 d1 00 48 89 c6 <48> 8b 0b 80 4b 12 01 48 39 cb 74 74 8b 41 14 8b 7b 10 44 8d 44 00
[    0.014000] RSP: 0000:ffff8db300003f90 EFLAGS: 00000046
[    0.014000] RAX: 0000000000000086 RBX: 0000000000000000 RCX: 4000000000000002
[    0.014000] RDX: 0000000000000001 RSI: 0000000000000086 RDI: 0000000000000001
[    0.014000] RBP: ffff8db300003f98 R08: 0000000000000001 R09: 0000000000000000
[    0.014000] R10: 0000000000000000 R11: ffff8db300003ff8 R12: ffff8b49c11da0a4
[    0.014000] R13: 0000000000000030 R14: 0000000000000000 R15: 0000000000000000
[    0.014000] FS:  0000000000000000(0000) GS:ffff8b49cf800000(0000) knlGS:0000000000000000
[    0.014000] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[    0.014000] CR2: 0000000000000000 CR3: 000000000620a000 CR4: 00000000000406b0
[    0.014000] Kernel panic - not syncing: Fatal exception in interrupt
[    0.014000] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---
Comment 1 Richard Purdie 2022-09-29 14:48:09 UTC
This is qemux86-64 running on arm which means the APIC isn't being emulated by KVM.
Comment 2 Randy MacLeod 2022-12-15 15:50:23 UTC
Anuj, Would anyone from your organization like to work on debugging this defect?
It may only happen *without kvm* perhaps but not necessarily only an arm64 host.
Comment 3 Richard Purdie 2023-01-26 15:49:26 UTC
I worry this is another way to expose the APIC issues we've seen on x86 without KVM in the past
Comment 4 Randy MacLeod 2023-05-25 14:59:22 UTC
Is this happens again please re-open. There have been some changes in the qemu apic handline code , hopefully that has fixed this problem.