From phk: .. ath0: <Atheros 5418> mem 0xf2500000-0xf250ffff irq 16 at device 0.0 on pci2 ath0: AR5418 mac 12.10 RF5133 phy 8.1 ath0: 2GHz radio: 0x0000; 5GHz radio: 0x00c0 .. wlan0: Ethernet address: 00:15:af:13:7c:5e ath0: ath_start: sc_inreset_cnt > 0; bailing drm0: <Mobile Intel® GM45 Express Chipset> on vgapci0 info: [drm] MSI enabled 1 message(s) info: [drm] AGP at 0xd0000000 256MB info: [drm] Initialized i915 1.6.0 20080730 wlan0: scan_task: OOPS! scan cancelled during driver call! ath0: ath_start: sc_inreset_cnt > 0; bailing ath0: ath_start: sc_inreset_cnt > 0; bailing ath0: ath_start: sc_inreset_cnt > 0; bailing ath0: ath_start: sc_inreset_cnt > 0; bailing ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ath0: ath_start: sc_inreset_cnt > 0; bailing ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA wlan0: link state changed to DOWN wlan0: link state changed to UP ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ath0: ath_start: sc_inreset_cnt > 0; bailing ar5416PerCalibrationN: NF calibration didn't finish; delaying CCA ath0: ath_rx_proc: kickpcu; handled 94 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 38 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 2 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 3 packets ath0: ath_rx_proc: kickpcu; handled 3 packets ath0: ath_rx_proc: kickpcu; handled 2 packets ath0: ath_rx_proc: kickpcu; handled 1 packets .. ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 2 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 3 packets ath0: ath_rx_proc: kickpcu; handled 3 packets ath0: ath_rx_proc: kickpcu; handled 2 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 2 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets Memory modified after free 0xfffffe00064f1000(2048) val=2c4208 @ 0xfffffe00064f1000 Memory modified after free 0xfffffe0006523000(2048) val=2c4208 @ 0xfffffe0006523000 Memory modified after free 0xfffffe0088220000(2048) val=80 @ 0xfffffe0088220000 Memory modified after free 0xfffffe0006b25800(2048) val=2c4208 @ 0xfffffe0006b25800 ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 2 packets Memory modified after free 0xfffffe0006aef800(2048) val=2c4208 @ 0xfffffe0006aef800 ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets Memory modified after free 0xfffffe00064f1000(2048) val=80 @ 0xfffffe00064f1000 ath0: ath_rx_proc: kickpcu; handled 0 packets Memory modified after free 0xfffffe0065f8e000(2048) val=80 @ 0xfffffe0065f8e000 ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets Memory modified after free 0xfffffe000653a000(2048) val=80 @ 0xfffffe000653a000 ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 0 packets Memory modified after free 0xfffffe0065fae000(2048) val=80 @ 0xfffffe0065fae000 Memory modified after free 0xfffffe000655a800(2048) val=80 @ 0xfffffe000655a800 ath0: ath_rx_proc: kickpcu; handled 1 packets Memory modified after free 0xfffffe000656f800(2048) val=80 @ 0xfffffe000656f800 ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets Memory modified after free 0xfffffe0006ae5000(2048) val=80 @ 0xfffffe0006ae5000 ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets Memory modified after free 0xfffffe0006b1d800(2048) val=80 @ 0xfffffe0006b1d800 ath0: ath_rx_proc: kickpcu; handled 1 packets ath0: ath_rx_proc: kickpcu; handled 0 packets Fix: Not sure yet. It could be a few things: * Are we somehow running multiple RX procs? (eg with rx + reset.) * is the hardware still DMAing stuff (eg from the FIFO) even once the RXEOL is posted? Even after stoppcurecv/stoprecvdma is called? How-To-Repeat: Not sure yet.
Responsible Changed From-To: freebsd-bugs->freebsd-wireless Over to maintainer(s).
batch change: For bugs that match the following - Status Is In progress AND - Untouched since 2018-01-01. AND - Affects Base System OR Documentation DO: Reset to open status. Note: I did a quick pass but if you are getting this email it might be worthwhile to double check to see if this bug ought to be closed.
I am also a hot spot freebsd user with use of freebsd on pfsense I am also getting the kickcpu error with ath0 driver <6>mvneta0: promiscuous mode enabled ath0: ath_rx_pkt: rs_antenna > 7 (8542452) ath0: ath_rx_pkt: rs_antenna > 7 (8542452) ath0: ath_rx_pkt: rs_antenna > 7 (8542452) ath0: ath_rx_proc: kickpcu; handled 413 packets x0: 0 x1: ffff00009c600000 ($d.6 + 999bb068) x2: 4038 x3: 4 x4: 1 x5: ffff000097280840 ($d.6 + 9463b8a8) x6: 0 x7: 200 x8: ffff000000ad0114 (generic_bs_r_4 + 0) x9: ffff000000acff6c (generic_bs_barrier + 0) x10: 0 x11: 0 x12: 1 x13: 1 x14: 286b x15: 2af8 x16: 2711 x17: 0 x18: ffff000097280880 ($d.6 + 9463b8e8) x19: ffff000096feb000 ($d.6 + 943a6068) x20: ffff00009c600000 ($d.6 + 999bb068) x21: 4038 x22: ffff00000213aa80 (memmap_bus + 0) x23: ffff00009c236a74 ($d.6 + 995f1adc) x24: ffffa000019efc80 x25: ffff000002191000 (version + 130) x26: 0 x27: ffff000002192e98 (Giant + 18) x28: ffffa000019efc80 x29: ffff000097280880 ($d.6 + 9463b8e8) sp: ffff000097280880 lr: ffff000000167114 (ath_hal_reg_read + cc) elr: ffff000000ad0118 (generic_bs_r_4 + 4) spsr: 20000045 far: ffff00009c604038 ($d.6 + 999bf0a0) panic: Unhandled EL1 external data abort cpuid = 1 time = 1715119511 KDB: enter: panic