Bug 293770 - kernel panic: dma tag alignment 560, must be non-zero power of 2
Summary: kernel panic: dma tag alignment 560, must be non-zero power of 2
Status: In Progress
Alias: None
Product: Base System
Classification: Unclassified
Component: arm (show other bugs)
Version: 16.0-CURRENT
Hardware: arm Any
: --- Affects Some People
Assignee: Andrew Turner
URL: https://ci.freebsd.org/view/Test/job/...
Keywords: crash, regression
Depends on:
Blocks:
 
Reported: 2026-03-12 19:12 UTC by Siva Mahadevan
Modified: 2026-06-11 20:13 UTC (History)
3 users (show)

See Also:
linimon: mfc-stable15?
linimon: mfc-stable14?


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Siva Mahadevan freebsd_committer freebsd_triage 2026-03-12 19:12:11 UTC
armv7 CI is currently failing due to a kernel panic:


[...]
virtio_pci0: <VirtIO PCI (legacy) Entropy adapter> port 0x1000-0x101f mem 0x10000000-0x10000fff,0x10004000-0x10007fff irq 40 at device 1.0 on pci0
virtio_pci1: <VirtIO PCI (legacy) Block adapter> port 0x1080-0x10ff mem 0x10008000-0x10008fff,0x1000c000-0x1000ffff irq 41 at device 2.0 on pci0
vtblk0: <VirtIO Block Adapter> on virtio_pci1
panic: dma tag alignment 560, must be non-zero power of 2
cpuid = 0
time = 1
KDB: stack backtrace:
db_trace_self() at db_trace_self
	 pc = 0xc062c2ec  lr = 0xc0077700 (db_trace_self_wrapper+0x30)
	 sp = 0xc0f14880  fp = 0xc0f14998
db_trace_self_wrapper() at db_trace_self_wrapper+0x30
	 pc = 0xc0077700  lr = 0xc0309994 (vpanic+0x140)
	 sp = 0xc0f149a0  fp = 0xc0f149c0
	 r4 = 0x00000100  r5 = 0x00000000
	 r6 = 0xc077ceee  r7 = 0xc0b7a484
vpanic() at vpanic+0x140
	 pc = 0xc0309994  lr = 0xc0309854 (vpanic)
	 sp = 0xc0f149c8  fp = 0xc0f149cc
	 r4 = 0xd8480000  r5 = 0x00000230
	 r6 = 0x00000000  r7 = 0xd8411580
	 r8 = 0x00000230  r9 = 0xffffffff
	r10 = 0x00000230
vpanic() at vpanic
	 pc = 0xc0309854  lr = 0xc0628780 (bus_dma_tag_create+0x2fc)
	 sp = 0xc0f149d4  fp = 0xc0f14a00
	 r4 = 0xd8411580  r5 = 0x00000230
	 r6 = 0xffffffff  r7 = 0x00000230
	 r8 = 0xc0f149cc  r9 = 0xc0309854
	r10 = 0xc0f149d4
bus_dma_tag_create() at bus_dma_tag_create+0x2fc
	 pc = 0xc0628780  lr = 0xc01c67e0 (virtqueue_init_indirect+0xf8)
	 sp = 0xc0f14a08  fp = 0xc0f14a50
	 r4 = 0xd8480000  r5 = 0xffffffff
	 r6 = 0x00000000  r7 = 0xd82d8b00
	 r8 = 0xd8480018  r9 = 0xd84800a4
	r10 = 0x00000230
virtqueue_init_indirect() at virtqueue_init_indirect+0xf8
	 pc = 0xc01c67e0  lr = 0xc01c6638 (virtqueue_alloc+0x2c4)
	 sp = 0xc0f14a58  fp = 0xc0f14aa8
	 r4 = 0xd8480000  r5 = 0xc0f14ad0
	 r6 = 0x00000001  r7 = 0xffffffff
	 r8 = 0x00000000  r9 = 0xd82d8b00
	r10 = 0x00001000
virtqueue_alloc() at virtqueue_alloc+0x2c4
	 pc = 0xc01c6638  lr = 0xc01c84cc (vtpci_alloc_virtqueues+0x198)
	 sp = 0xc0f14ab0  fp = 0xc0f14af0
	 r4 = 0xd83bd000  r5 = 0xc0f14b60
	 r6 = 0xd82d8b00  r7 = 0x00000000
	 r8 = 0x00000100  r9 = 0x00000000
	r10 = 0x00000001
vtpci_alloc_virtqueues() at vtpci_alloc_virtqueues+0x198
	 pc = 0xc01c84cc  lr = 0xc01d5b34 (vtblk_attach+0x3e4)
	 sp = 0xc0f14af8  fp = 0xc0f14bb0
	 r4 = 0xc9043c24  r5 = 0xffffffff
	 r6 = 0xd82d8980  r7 = 0xc0f14b60
	 r8 = 0x00000023  r9 = 0xd82d8980
	r10 = 0xc9043c00
vtblk_attach() at vtblk_attach+0x3e4
	 pc = 0xc01d5b34  lr = 0xc034887c (device_attach+0x5c8)
	 sp = 0xc0f14bb8  fp = 0xc0f14c00
	 r4 = 0xd82d8980  r5 = 0xd82d8b00
	 r6 = 0x11fe6d86  r7 = 0x00000000
	 r8 = 0xc0bf0b64  r9 = 0xc7283f80
	r10 = 0x80040003
device_attach() at device_attach+0x5c8
	 pc = 0xc034887c  lr = 0xc01ca53c (vtpci_legacy_probe_and_attach_child+0x74)
	 sp = 0xc0f14c08  fp = 0xc0f14c18
	 r4 = 0xd82d8980  r5 = 0x00000000
	 r6 = 0xc725cc00  r7 = 0xd82d8b00
	 r8 = 0x00000014  r9 = 0x00000001
	r10 = 0xffffffff
vtpci_legacy_probe_and_attach_child() at vtpci_legacy_probe_and_attach_child+0x74
	 pc = 0xc01ca53c  lr = 0xc01c974c (vtpci_legacy_attach+0x210)
	 sp = 0xc0f14c20  fp = 0xc0f14c60
	 r4 = 0xc725cc08  r5 = 0xc725cc00
	 r6 = 0x00000000  r7 = 0x00000000
vtpci_legacy_attach() at vtpci_legacy_attach+0x210
	 pc = 0xc01c974c  lr = 0xc034887c (device_attach+0x5c8)
	 sp = 0xc0f14c68  fp = 0xc0f14cb0
	 r4 = 0xd82d8b00  r5 = 0xd82d8d00
	 r6 = 0x11f6f851  r7 = 0xc0946180
	 r8 = 0xc0bf0b64  r9 = 0xc7283f80
	r10 = 0x80040003
device_attach() at device_attach+0x5c8
	 pc = 0xc034887c  lr = 0xc0349f00 (bus_attach_children+0x50)
	 sp = 0xc0f14cb8  fp = 0xc0f14cc8
	 r4 = 0xd82d8b00  r5 = 0xc09b5950
	 r6 = 0xc07cdaca  r7 = 0xc0658040
	 r8 = 0x00000000  r9 = 0xc7283f80
	r10 = 0x80040003
bus_attach_children() at bus_attach_children+0x50
	 pc = 0xc0349f00  lr = 0xc00ffadc (pci_attach+0x11c)
	 sp = 0xc0f14cd0  fp = 0xc0f14cf8
	 r4 = 0xd82d8d00  r5 = 0x00000000
	 r6 = 0xc0945924 r10 = 0x80040003
pci_attach() at pci_attach+0x11c
	 pc = 0xc00ffadc  lr = 0xc034887c (device_attach+0x5c8)
	 sp = 0xc0f14d00  fp = 0xc0f14d48
	 r4 = 0xd82d8d00  r5 = 0xd82d9580
	 r6 = 0x0f5a98e7  r7 = 0x00000000
	 r8 = 0xc0bf0b64 r10 = 0x80040003
device_attach() at device_attach+0x5c8
	 pc = 0xc034887c  lr = 0xc0349f00 (bus_attach_children+0x50)
	 sp = 0xc0f14d50  fp = 0xc0f14d60
	 r4 = 0xd82d8d00  r5 = 0xc09b5950
	 r6 = 0xc07cdaca  r7 = 0x00000000
	 r8 = 0xc0bf0b64  r9 = 0xc7283f80
	r10 = 0x80040003
bus_attach_children() at bus_attach_children+0x50
	 pc = 0xc0349f00  lr = 0xc0659158 (pci_host_generic_fdt_attach+0x38)
	 sp = 0xc0f14d68  fp = 0xc0f14d70
	 r4 = 0xd82d9580  r5 = 0x00000000
	 r6 = 0x0ec44e3f r10 = 0x80040003
pci_host_generic_fdt_attach() at pci_host_generic_fdt_attach+0x38
	 pc = 0xc0659158  lr = 0xc034887c (device_attach+0x5c8)
	 sp = 0xc0f14d78  fp = 0xc0f14dc0
	 r4 = 0xd82d9580  r5 = 0xd82daa00
device_attach() at device_attach+0x5c8
	 pc = 0xc034887c  lr = 0xc034ab84 (bus_generic_new_pass+0x13c)
	 sp = 0xc0f14dc8  fp = 0xc0f14de0
	 r4 = 0xd82d9580  r5 = 0xc0945abc
	 r6 = 0xc09b5950  r7 = 0xc07cdaca
	 r8 = 0xc0b87cb0  r9 = 0xc09b5154
	r10 = 0xc0b69f28
bus_generic_new_pass() at bus_generic_new_pass+0x13c
	 pc = 0xc034ab84  lr = 0xc034ab10 (bus_generic_new_pass+0xc8)
	 sp = 0xc0f14de8  fp = 0xc0f14e00
	 r4 = 0xd82daa00  r5 = 0xc0945abc
	 r6 = 0xc09b5950  r7 = 0xc07cdaca
	 r8 = 0xc0b87cb0 r10 = 0xc0b69f28
bus_generic_new_pass() at bus_generic_new_pass+0xc8
	 pc = 0xc034ab10  lr = 0xc034ab10 (bus_generic_new_pass+0xc8)
	 sp = 0xc0f14e08  fp = 0xc0f14e20
	 r4 = 0xd82dab00  r5 = 0xc0945abc
	 r6 = 0xc09b5950  r7 = 0xc07cdaca
	 r8 = 0xc0b87cb0 r10 = 0xc0b69f28
bus_generic_new_pass() at bus_generic_new_pass+0xc8
	 pc = 0xc034ab10  lr = 0xc034d3dc (root_bus_configure+0x48)
	 sp = 0xc0f14e28  fp = 0xc0f14e40
	 r4 = 0xc0945abc  r5 = 0xd82daf00
	 r6 = 0xc0b87cb0  r7 = 0xc72b4c60
	 r8 = 0xc0b87cd8 r10 = 0xc0b69f28
root_bus_configure() at root_bus_configure+0x48
	 pc = 0xc034d3dc  lr = 0xc0288cc8 (mi_startup+0x128)
	 sp = 0xc0f14e48  fp = 0xc0f14e88
	 r4 = 0xc0b69f2c  r5 = 0x03800000
	 r6 = 0xc0946ba8  r7 = 0xc098cd1c
	 r8 = 0x00000000 r10 = 0xc0b69f28
mi_startup() at mi_startup+0x128
	 pc = 0xc0288cc8  lr = 0xc0288cc8 (mi_startup+0x128)
	 sp = 0xc0f14e6c  fp = 0xc0f14e88
KDB: enter: panic
[ thread pid 0 tid 100000 ]
Stopped at      kdb_enter+0x54: ldrb    r15, [r15, r15, ror r15]!


This is reproducible using Bricoler (master-python branch) with the following command:

bricoler freebsd-regression-test-suite --freebsd-src-git-checkout/url=/usr/src --freebsd-src-git-checkout/branch= --freebsd-src-build/kernel_config=GENERIC --freebsd-regression-test-suite/memory=3072 --freebsd-regression-test-suite/ncpus=2 --freebsd-regression-test-suite/parallelism=1 --freebsd-src-build/machine=arm/armv7 --freebsd-regression-test-suite/hypervisor=qemu --freebsd-vm-image/packages=

I bisected this failure to this commit: https://cgit.freebsd.org/src/commit/?id=c499ad6f997c8c5f61c88925e6d1e826d0c0f6c4 (virtio: Use bus_dma for ring and indirect buffer allocations).

Starting with andrew@ for triage.
Comment 1 Andrew Turner freebsd_committer freebsd_triage 2026-03-13 11:26:11 UTC
Can you try the patch in https://reviews.freebsd.org/D55843?
Comment 2 Siva Mahadevan freebsd_committer freebsd_triage 2026-03-13 13:42:49 UTC
Yes that patch fixes the issue.
Comment 3 commit-hook freebsd_committer freebsd_triage 2026-03-17 11:24:38 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/src/commit/?id=1d13d938fe6c7639d2bb4cb5248a1f81275b6891

commit 1d13d938fe6c7639d2bb4cb5248a1f81275b6891
Author:     Sarah Walker <sarah.walker2@arm.com>
AuthorDate: 2026-03-17 10:54:30 +0000
Commit:     Andrew Turner <andrew@FreeBSD.org>
CommitDate: 2026-03-17 10:56:27 +0000

    virtio: Ensure power-of-two alignment for indirect queue

    Some platforms enforce power-of-two alignment for bus_dma tags. Rounding up
    the natural size may result in over-alignment, but should be safe.

    PR:             293770
    Reviewed by:    andrew
    Fixes:          c499ad6f997c ("virtio: Use bus_dma for ring and indirect buffer allocations")
    Sponsored by:   Arm Ltd
    Differential Revision:  https://reviews.freebsd.org/D55843

 sys/dev/virtio/virtqueue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)