Bug 108692 - [CI][SHARDS] igt@gem_userptr_blits@stress-mm-invalidate-close-overlap - dmesg-warn - stack segment: 0000 [#1] PREEMPT SMP NOPTI
Summary: [CI][SHARDS] igt@gem_userptr_blits@stress-mm-invalidate-close-overlap - dmesg...
Status: RESOLVED WORKSFORME
Alias: None
Product: DRI
Classification: Unclassified
Component: DRM/Intel (show other bugs)
Version: DRI git
Hardware: Other All
: high normal
Assignee: Andi
QA Contact: Intel GFX Bugs mailing list
URL:
Whiteboard: ReadyForDev
Keywords:
Depends on:
Blocks:
 
Reported: 2018-11-08 09:07 UTC by Martin Peres
Modified: 2019-01-09 07:51 UTC (History)
1 user (show)

See Also:
i915 platform: BXT
i915 features: GEM/Other


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Peres 2018-11-08 09:07:45 UTC
https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_5097/shard-apl5/igt@gem_userptr_blits@stress-mm-invalidate-close-overlap.html

<4> [821.766372] stack segment: 0000 [#1] PREEMPT SMP NOPTI
<4> [821.766397] CPU: 1 PID: 157 Comm: kworker/1:3 Tainted: G     U  W         4.20.0-rc1-CI-CI_DRM_5097+ #1
<4> [821.766417] Hardware name:  /NUC6CAYB, BIOS AYAPLCEL.86A.0050.2018.0521.1533 05/21/2018
<4> [821.766440] Workqueue: events free_obj_work
<4> [821.766454] RIP: 0010:free_obj_work+0x143/0x210
<4> [821.766466] Code: dd 00 00 00 49 bd 00 01 00 00 00 00 ad de 49 bc 00 02 00 00 00 00 ad de 48 89 43 08 4c 89 2e 4c 89 66 08 e8 3f 0e d6 ff eb 16 <48> 89 45 08 48 89 de 4c 89 2b 4c 89 63 08 48 89 eb e8 27 0e d6 ff
<4> [821.766499] RSP: 0018:ffffc90000233e30 EFLAGS: 00010202
<4> [821.766512] RAX: ffffc90000233e30 RBX: ffff88014f22d610 RCX: 0000000000000000
<4> [821.766527] RDX: 0000000000000002 RSI: 0000000000000000 RDI: ffff880276816a80
<4> [821.766542] RBP: 6b6b6b6b6b6b6b6b R08: 0000000000000000 R09: 0000000000000000
<4> [821.766556] R10: 0000000000000000 R11: 0000000000000178 R12: dead000000000200
<4> [821.766571] R13: dead000000000100 R14: 0000000000000000 R15: 0000000000000000
<4> [821.766586] FS:  0000000000000000(0000) GS:ffff880277a80000(0000) knlGS:0000000000000000
<4> [821.766603] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
<4> [821.766616] CR2: 00007fa8241cd100 CR3: 00000002709aa000 CR4: 00000000003406e0
<4> [821.766630] Call Trace:
<4> [821.766647]  process_one_work+0x262/0x630
<4> [821.766663]  worker_thread+0x37/0x380
<4> [821.766676]  ? process_one_work+0x630/0x630
<4> [821.766687]  kthread+0x119/0x130
<4> [821.766698]  ? kthread_park+0x80/0x80
<4> [821.766711]  ret_from_fork+0x3a/0x50
<4> [821.766727] Modules linked in: vgem snd_hda_codec_hdmi snd_hda_codec_realtek snd_hda_codec_generic x86_pkg_temp_thermal coretemp crct10dif_pclmul crc32_pclmul ghash_clmulni_intel i915 lpc_ich r8169 snd_hda_intel snd_hda_codec snd_hwdep snd_hda_core snd_pcm mei_me mei pinctrl_broxton pinctrl_intel prime_numbers
Comment 1 Chris Wilson 2018-11-08 09:12:29 UTC
Scary use-after-free, though the immediate suspicious falls onto debugobjects -- it being a use-after-free on its workqueue.
Comment 2 Francesco Balestrieri 2019-01-09 07:51:34 UTC
Once two months ago, then never again. Closing.


Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.