Re: Boot panic on Lenovo P50s since r367998

From: Tomoaki AOKI <junchoon_at_dec.sakura.ne.jp>
Date: Fri, 25 Dec 2020 09:02:19 +0900
On Thu, 24 Dec 2020 10:34:49 +0100
Marc Veldman <marc_at_bumblingdork.com> wrote:

> Hello,
> 
> since r367998 my Lenovo P50s panics on boot:
> 
> mmc0: detached
> panic: Bad link elm 0xfffff80003a73300 next->prep != elm
> cupid=3
> time=2
> KDB: stack backtrace:
> db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xffffffff8299a9c0
> vpanic() at vpanic+0x181/frame 0xffffffff8299aa10
> panic() at panic+0x43/frame 0xffffffff8299aa70
> config_intrhook_disestablish() at config_intrhook_disestablish+0xf3/frame 0xffffffff8299aa90
> config_intrhook_oneshot_func() at config_intrhook_oneshot_func+0x18/frame 0xffffffff8299aab0
> run_interrupt_driven_config_hooks() at run_interrupt_driven_config_hooks+0x77/frame 0xffffffff8299aad0
> boot_run_interrupt_driven_config_hooks() at boot_run_interrupt_driven_config_hooks+0x1f/frame 0xffffffff8299ab60
> mi_startup() at mi_startup+0xec/frame 0xffffffff8299abb0
> btext() at btext+0x2c
> KDB: enter: panic
> [thread pid 0 tid 100000]
> Stopped at     kdb_enter+0x37: movq     $0,0x10ada46(%rip)
> 
> If needed, I can test patches
> 
> Dmesg (with r367977 kernel)
> 
> ---<<BOOT>>---
> Copyright (c) 1992-2020 The FreeBSD Project.
> Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
> 	The Regents of the University of California. All rights reserved.
> FreeBSD is a registered trademark of The FreeBSD Foundation.
> FreeBSD 13.0-CURRENT #0 r367997: Tue Dec 22 16:47:30 CET 2020
>     root_at_devnovo:/usr/obj/usr/src/amd64.amd64/sys/GENERIC amd64
> FreeBSD clang version 11.0.0 (git_at_github.com:llvm/llvm-project.git llvmorg-11.0.0-0-g176249bd673)
> WARNING: WITNESS option enabled, expect reduced performance.
> VT(efifb): resolution 1920x1080
> CPU: Intel(R) Core(TM) i7-6500U CPU _at_ 2.50GHz (2592.10-MHz K8-class CPU)
>   Origin="GenuineIntel"  Id=0x406e3  Family=0x6  Model=0x4e  Stepping=3
>   Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
>   Features2=0x7ffafbbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,FMA,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,AVX,F16C,RDRAND>
>   AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
>   AMD Features2=0x121<LAHF,ABM,Prefetch>
>   Structured Extended Features=0x29c67af<FSGSBASE,TSCADJ,SGX,BMI1,AVX2,SMEP,BMI2,ERMS,INVPCID,NFPUSG,MPX,RDSEED,ADX,SMAP,CLFLUSHOPT,PROCTRACE>
>   Structured Extended Features3=0x9c000000<IBPB,STIBP,L1DFL,SSBD>
>   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
>   VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID
>   TSC: P-state invariant, performance statistics
> real memory  = 17179869184 (16384 MB)
> avail memory = 16421109760 (15660 MB)
> Event timer "LAPIC" quality 600
> ACPI APIC Table: <LENOVO TP-N1K  >
> FreeBSD/SMP: Multiprocessor System Detected: 4 CPUs
> FreeBSD/SMP: 1 package(s) x 2 core(s) x 2 hardware threads
> random: registering fast source Intel Secure Key RNG
> random: fast provider: "Intel Secure Key RNG"
> random: unblocking device.
> ioapic0 <Version 2.0> irqs 0-119
> Launching APs: 1 3 2
> Timecounter "TSC-low" frequency 1296050980 Hz quality 1000
> random: entropy device external interface
> WARNING: Device "kbd" is Giant locked and may be deleted before FreeBSD 13.0.
> kbd1 at kbdmux0
> 000.000045 [4346] netmap_init               netmap: loaded module
> [ath_hal] loaded
> nexus0
> efirtc0: <EFI Realtime Clock>
> efirtc0: registered as a time-of-day clock, resolution 1.000000s
> cryptosoft0: <software crypto>
> aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS>
> acpi0: <LENOVO TP-N1K>
> acpi_ec0: <Embedded Controller: GPE 0x16, ECDT> port 0x62,0x66 on acpi0
> acpi0: Power Button (fixed)
> cpu0: <ACPI CPU> on acpi0
> attimer0: <AT timer> port 0x40-0x43 irq 0 on acpi0
> Timecounter "i8254" frequency 1193182 Hz quality 0
> Event timer "i8254" frequency 1193182 Hz quality 100
> hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
> Timecounter "HPET" frequency 24000000 Hz quality 950
> Event timer "HPET" frequency 24000000 Hz quality 550
> Event timer "HPET1" frequency 24000000 Hz quality 440
> Event timer "HPET2" frequency 24000000 Hz quality 440
> Event timer "HPET3" frequency 24000000 Hz quality 440
> Event timer "HPET4" frequency 24000000 Hz quality 440
> atrtc0: <AT realtime clock> port 0x70-0x71 irq 8 on acpi0
> atrtc0: registered as a time-of-day clock, resolution 1.000000s
> Event timer "RTC" frequency 32768 Hz quality 0
> Timecounter "ACPI-fast" frequency 3579545 Hz quality 900
> acpi_timer0: <24-bit timer at 3.579545MHz> port 0x1808-0x180b on acpi0
> acpi_lid0: <Control Method Lid Switch> on acpi0
> acpi_button0: <Sleep Button> on acpi0
> pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
> pci0: <ACPI PCI bus> on pcib0
> vgapci0: <VGA-compatible display> port 0xe000-0xe03f mem 0xf2000000-0xf2ffffff,0xd0000000-0xdfffffff irq 16 at device 2.0 on pci0
> vgapci0: Boot video device
> xhci0: <Intel Sunrise Point-LP USB 3.0 controller> mem 0xf4220000-0xf422ffff at device 20.0 on pci0
> xhci0: 32 bytes context size, 64-bit DMA
> usbus0 on xhci0
> usbus0: 5.0Gbps Super Speed USB v3.0
> pci0: <simple comms> at device 22.0 (no driver attached)
> ahci0: <Intel Sunrise Point-LP AHCI SATA controller> port 0xe080-0xe087,0xe088-0xe08b,0xe060-0xe07f mem 0xf4248000-0xf4249fff,0xf424f000-0xf424f0ff,0xf424d000-0xf424d7ff at device 23.0 on pci0
> ahci0: AHCI v1.31 with 1 6Gbps ports, Port Multiplier not supported
> ahcich1: <AHCI channel> at channel 1 on ahci0
> pcib1: <ACPI PCI-PCI bridge> at device 28.0 on pci0
> pci1: <ACPI PCI bus> on pcib1
> pci1: <unknown> at device 0.0 (no driver attached)
> pcib2: <ACPI PCI-PCI bridge> at device 28.2 on pci0
> pci2: <ACPI PCI bus> on pcib2
> pci2: <network> at device 0.0 (no driver attached)
> pcib3: <ACPI PCI-PCI bridge> at device 29.0 on pci0
> pci3: <ACPI PCI bus> on pcib3
> vgapci1: <VGA-compatible display> port 0xd000-0xd07f mem 0xf3000000-0xf3ffffff,0xe0000000-0xefffffff,0xf0000000-0xf1ffffff at device 0.0 on pci3
> isab0: <PCI-ISA bridge> at device 31.0 on pci0
> isa0: <ISA bus> on isab0
> pci0: <memory> at device 31.2 (no driver attached)
> hdac0: <Intel Sunrise Point-LP HDA Controller> mem 0xf4240000-0xf4243fff,0xf4230000-0xf423ffff at device 31.3 on pci0
> em0: <Intel(R) PRO/1000 Network Connection> mem 0xf4200000-0xf421ffff at device 31.6 on pci0
> em0: Using 1024 TX descriptors and 1024 RX descriptors
> em0: Using an MSI interrupt
> em0: Ethernet address: 54:ee:75:cb:0d:e3
> em0: netmap queues/slots: TX 1/1024, RX 1/1024
> acpi_tz0: <Thermal Zone> on acpi0
> atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0
> atkbd0: <AT Keyboard> irq 1 on atkbdc0
> kbd0 at atkbd0
> atkbd0: [GIANT-LOCKED]
> psm0: <PS/2 Mouse> irq 12 on atkbdc0
> psm0: [GIANT-LOCKED]
> WARNING: Device "psm" is Giant locked and may be deleted before FreeBSD 13.0.
> psm0: model Synaptics Touchpad, device ID 0
> battery0: <ACPI Control Method Battery> on acpi0
> battery1: <ACPI Control Method Battery> on acpi0
> acpi_acad0: <AC Adapter> on acpi0
> orm0: <ISA Option ROM> at iomem 0xc0000-0xcffff pnpid ORM0000 on isa0
> hwpstate_intel0: <Intel Speed Shift> on cpu0
> hwpstate_intel1: <Intel Speed Shift> on cpu1
> hwpstate_intel2: <Intel Speed Shift> on cpu2
> hwpstate_intel3: <Intel Speed Shift> on cpu3
> Timecounters tick every 1.000 msec
> ZFS filesystem version: 5
> ZFS storage pool version: features support (5000)
> hdacc0: <Realtek ALC293 HDA CODEC> at cad 0 on hdac0
> ugen0.1: <0x8086 XHCI root HUB> at usbus0
> hdaa0: <Realtek ALC293 Audio Function Group> at nid 1 on hdacc0
> pcm0: <Realtek ALC293 (Analog)> at nid 20 and 26 on hdaa0
> pcm1: <Realtek ALC293 (Analog)> at nid 21 and 18 on hdaa0
> hdacc1: <Intel Skylake HDA CODEC> at cad 2 on hdac0
> hdaa1: <Intel Skylake Audio Function Group> at nid 1 on hdacc1
> pcm2: <Intel Skylake (HDMI/DP 8ch)> at nid 3 on hdaa1
> Trying to mount root from zfs:zroot/ROOT/default []...
> Root mount waiting for: usbus0 CAM
> WARNING: WITNESS option enabled, expect reduced performance.
> uhub0 on usbus0
> uhub0: <0x8086 XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus0
> ada0 at ahcich1 bus 0 scbus0 target 0 lun 0
> ada0: <Samsung SSD 850 PRO 512GB EXM04B6Q> ACS-2 ATA SATA 3.x device
> ada0: Serial Number S39FNX0J625463T
> ada0: 600.000MB/s transfers (SATA 3.x, UDMA6, PIO 512bytes)
> ada0: Command Queueing enabled
> ada0: 488386MB (1000215216 512 byte sectors)
> ada0: quirks=0x3<4K,NCQ_TRIM_BROKEN>
> GEOM_ELI: Device ada0p4.eli created.
> GEOM_ELI: Encryption: AES-XTS 256
> GEOM_ELI:     Crypto: accelerated software
> uhub0: 18 ports with 18 removable, self powered
> Root mount waiting for: usbus0
> ugen0.2: <Prolific Technology Inc. USB-Serial Controller> at usbus0
> Root mount waiting for: usbus0
> ugen0.3: <vendor 0x8087 product 0x0a2b> at usbus0
> ugen0.4: <SunplusIT Inc Integrated Camera> at usbus0
> Root mount waiting for: usbus0
> ugen0.5: <vendor 0x138a product 0x0017> at usbus0
> lo0: link state changed to UP
> pchtherm0: <Skylake PCH Thermal Subsystem> mem 0xf424b000-0xf424bfff at device 20.2 on pci0
> iwm0: <Intel(R) Dual Band Wireless AC 8260> mem 0xf4000000-0xf4001fff at device 0.0 on pci2
> iwm0: hw rev 0x200, fw ver 22.361476.0, address f4:8c:50:50:22:83
> ichsmb0: <Intel Sunrise Point-LP SMBus controller> port 0xefa0-0xefbf mem 0xf424e000-0xf424e0ff at device 31.4 on pci0
> smbus0: <System Management Bus> on ichsmb0
> acpi_wmi0: <ACPI-WMI mapping> on acpi0
> acpi_wmi0: Embedded MOF found
> ACPI: \134_SB.WMI1.WQBA: 1 arguments were passed to a non-method ACPI object (Buffer) (20201113/nsarguments-361)
> acpi_wmi1: <ACPI-WMI mapping> on acpi0
> acpi_wmi1: Embedded MOF found
> ACPI: \134_SB.WMI2.WQBB: 1 arguments were passed to a non-method ACPI object (Buffer) (20201113/nsarguments-361)
> acpi_wmi2: <ACPI-WMI mapping> on acpi0
> acpi_wmi2: Embedded MOF found
> ACPI: \134_SB.WMI3.WQBC: 1 arguments were passed to a non-method ACPI object (Buffer) (20201113/nsarguments-361)
> uplcom0 on uhub0
> uplcom0: <Prolific Technology Inc. USB-Serial Controller, class 0/0, rev 1.10/3.00, addr 1> on usbus0
> wlan0: Ethernet address: f4:8c:50:50:22:83
> ng_ubt: HCI command 0xfc05 timed out
> ubt0 on uhub0
> ubt0: <vendor 0x8087 product 0x0a2b, class 224/1, rev 2.00/0.01, addr 2> on usbus0
> wlan0: link state changed to UP
> WARNING: attempt to domain_add(bluetooth) after domainfinalize()
> WARNING: attempt to domain_add(netgraph) after domainfinalize()
> iwm0: code ce, frame 2/216 b800002c unhandled
> Security policy loaded: MAC/ntpd (mac_ntpd)
> 
> _______________________________________________
> freebsd-current_at_freebsd.org mailing list
> https://lists.freebsd.org/mailman/listinfo/freebsd-current
> To unsubscribe, send any mail to "freebsd-current-unsubscribe_at_freebsd.org"

Hi.
You would be bitten by a known issue with ThinkPad P50s described in
rtsx (4) man page.

Try adding dev.rtsx.0.inversion=1 in /boot/loader.conf.

Unfortunately, man pages for head cannot read via FreeBSD project top
page. So read raw manpage data with svn commit mail archive below.

 https://lists.freebsd.org/pipermail/svn-src-head/2020-November/141972.html

In addition, write attempts to write-protected card causes 100% panic.
For example, sysutils/automount trys fsck on mount.
This causes 100% panic (not only rtsx, but every adapters), avoidable
by write-protect off.


-- 
Tomoaki AOKI    <junchoon_at_dec.sakura.ne.jp>
Received on Thu Dec 24 2020 - 23:02:35 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:26 UTC