NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

kern/60716: focusrite 2i2 format mismatch in uaudio.c triggers panic



>Number:         60716
>Category:       kern
>Synopsis:       focusrite 2i2 format mismatch in uaudio.c triggers panic
>Confidential:   no
>Severity:       critical
>Priority:       medium
>Responsible:    kern-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Fri Sep 11 19:50:01 +0000 2026
>Originator:     Camaren
>Release:        11.99.8 amd64
>Organization:
>Environment:
NetBSD  11.99.8 NetBSD 11.99.8 (GENERIC) #0: Fri Sep 11 06:56:48 UTC 2026  mkrepro%mkrepro.NetBSD.org@localhost:/usr/src/sys/arch/amd64/compile/GENERIC amd64
>Description:
When attempting to boot with the Focusrite 2i2 3rd generation audio interface attached to xhci (qemu-system-x86_64 -device qemu-xhci,id=xhci -device usb-host,bus=xhci.0,hostbus=1,hostaddr=15) the kernel panics exactly when attempting to attach the interface/usb audio device. I would like to note this occurs when booting into standard NetBSD 11 installation image as well.
Results are from qemu running on a Linux 6.12.103 host.


[   1.1434112] uhub0 at usb0: NetBSD (0x0000) xHCI root hub (0x0000), class 9/0, rev 3.00/1.00, addr 0
[   1.1531568] uhub1 at usb1: NetBSD (0x0000) xHCI root hub (0x0000), class 9/0, rev 2.00/1.00, addr 0
[   1.8635000] uaudio0 at uhub1 port 1 configuration 1 interface 0
[   1.8635000] uaudio0: Focusrite (0x1235) Scarlett 2i2 USB (0x8210), rev 2.00/6.45, addr 1
[   1.8837462] uaudio0: audio rev 2.00
[   1.8934887] audio0 at uaudio0: playback, capture, full duplex, independent
[   1.8934887] panic: audio_indexof_format: cannot find matched format

[   1.8934887] cpu0: Begin traceback...
[   1.9034676] vpanic() at netbsd:vpanic+0x189
[   1.9234552] panic() at netbsd:panic+0x3c
[   1.9434328] audio_indexof_format() at netbsd:audio_indexof_format+0x9b
[   1.9634616] uaudio_set_format() at netbsd:uaudio_set_format+0xa7
[   1.9834120] audio_hw_set_format() at netbsd:audio_hw_set_format+0x95
[   1.9934272] audioattach() at netbsd:audioattach+0x42d
[   2.0034270] config_attach_internal() at netbsd:config_attach_internal+0x1d6
[   2.0134204] config_found_acquire() at netbsd:config_found_acquire+0x5d
[   2.0234068] config_found() at netbsd:config_found+0x31
[   2.0234068] audio_attach_mi() at netbsd:audio_attach_mi+0x70
[   2.0333667] uaudio_attach() at netbsd:uaudio_attach+0x13a7
[   2.0433985] config_attach_internal() at netbsd:config_attach_internal+0x1d6
[   2.0536463] config_found_acquire() at netbsd:config_found_acquire+0x5d
[   2.0634121] config_found() at netbsd:config_found+0x31
[   2.0734202] usbd_attachinterfaces.isra.0() at netbsd:usbd_attachinterfaces.isra.0+0x224
[   2.0834091] usbd_probe_and_attach() at netbsd:usbd_probe_and_attach+0xa2
[   2.0934044] xhci_new_device() at netbsd:xhci_new_device+0x62e
[   2.1034122] uhub_explore() at netbsd:uhub_explore+0x446
[   2.1134171] usb_discover() at netbsd:usb_discover+0x4d
[   2.1234188] usb_event_thread() at netbsd:usb_event_thread+0x48
[   2.1234188] cpu0: End traceback...
[   2.1234188] fatal breakpoint trap in supervisor mode
[   2.1234188] trap type 1 code 0 rip 0xffffffff8023541d cs 0x8 rflags 0x202 cr2 0 ilevel 0 rsp 0xffff8d0042bd2630
[   2.1234188] curlwp 0xffff807febdcd000 pid 0.107 lowest kstack 0xffff8d0042bce2c0
Stopped in pid 0.107 (system) at        netbsd:breakpoint+0x5:  leave
breakpoint() at netbsd:breakpoint+0x5
vpanic() at netbsd:vpanic+0x189
panic() at netbsd:panic+0x3c
audio_indexof_format() at netbsd:audio_indexof_format+0x9b
uaudio_set_format() at netbsd:uaudio_set_format+0xa7
audio_hw_set_format() at netbsd:audio_hw_set_format+0x95
audioattach() at netbsd:audioattach+0x42d
config_attach_internal() at netbsd:config_attach_internal+0x1d6
config_found_acquire() at netbsd:config_found_acquire+0x5d
config_found() at netbsd:config_found+0x31
audio_attach_mi() at netbsd:audio_attach_mi+0x70
uaudio_attach() at netbsd:uaudio_attach+0x13a7
config_attach_internal() at netbsd:config_attach_internal+0x1d6
config_found_acquire() at netbsd:config_found_acquire+0x5d
config_found() at netbsd:config_found+0x31
usbd_attachinterfaces.isra.0() at netbsd:usbd_attachinterfaces.isra.0+0x224
usbd_probe_and_attach() at netbsd:usbd_probe_and_attach+0xa2
xhci_new_device() at netbsd:xhci_new_device+0x62e
uhub_explore() at netbsd:uhub_explore+0x446
usb_discover() at netbsd:usb_discover+0x4d
usb_event_thread() at netbsd:usb_event_thread+0x48
ds          0
--db_more--

(gdb) where
#0  0xffffffff80234c4f in bus_space_read_stream_1 ()
#1  0xffffffff805ea587 in com_common_getc ()
#2  0xffffffff80242b23 in cngetc ()
#3  0xffffffff80b9c7b4 in db_putchar ()
#4  0xffffffff80e770d4 in kprintf ()
#5  0xffffffff80e7872b in db_printf ()
#6  0xffffffff80b9d6d6 in db_show_regs ()
#7  0xffffffff80b9984b in db_command ()
#8  0xffffffff80b99e0f in db_command_loop ()
#9  0xffffffff80b9e1fb in db_trap ()
#10 0xffffffff80236c2a in kdb_trap ()
#11 0xffffffff8023c795 in trap ()
#12 0xffffffff80234ad4 in alltraps ()
#13 0xffffffff8023541d in breakpoint ()
#14 0xffffffff80e7970b in vpanic ()
#15 0xffffffff80e797ea in panic ()
#16 0xffffffff80ba967f in audio_indexof_format ()
#17 0xffffffff804c8584 in uaudio_set_format ()
#18 0xffffffff80ba2b21 in audio_hw_set_format ()
#19 0xffffffff80ba7b39 in audioattach ()
#20 0xffffffff80e5873c in config_attach_internal ()
#21 0xffffffff80e58945 in config_found_acquire ()
#22 0xffffffff80e58a7d in config_found ()
--Type <RET> for more, q to quit, c to continue without paging--
#23 0xffffffff80ba91ba in audio_attach_mi ()
#24 0xffffffff804cbd7e in uaudio_attach ()
#25 0xffffffff80e5873c in config_attach_internal ()
#26 0xffffffff80e58945 in config_found_acquire ()
#27 0xffffffff80e58a7d in config_found ()
#28 0xffffffff804bfe70 in usbd_attachinterfaces.isra ()
#29 0xffffffff804c1eef in usbd_probe_and_attach ()
#30 0xffffffff8071e74a in xhci_new_device ()
#31 0xffffffff804c69ed in uhub_explore ()
#32 0xffffffff804b9cbb in usb_discover ()
#33 0xffffffff804ba04b in usb_event_thread ()
#34 0xffffffff80210327 in lwp_trampoline ()
#35 0x0000000000000000 in ?? ()

(gdb) disassemble /m audio_indexof_format
Dump of assembler code for function audio_indexof_format:
   0xffffffff80ba95e4 <+0>:     test   %esi,%esi
   0xffffffff80ba95e6 <+2>:     jle    0xffffffff80ba9666 <audio_indexof_format+130>
   0xffffffff80ba95e8 <+4>:     mov    %esi,%r8d
   0xffffffff80ba95eb <+7>:     lea    0x24(%rdi),%rax
   0xffffffff80ba95ef <+11>:    xor    %esi,%esi
   0xffffffff80ba95f1 <+13>:    mov    -0x1c(%rax),%edi
   0xffffffff80ba95f4 <+16>:    test   %edi,%edi
   0xffffffff80ba95f6 <+18>:    js     0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba95f8 <+20>:    test   %edx,%edi
   0xffffffff80ba95fa <+22>:    je     0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba95fc <+24>:    mov    0x4(%rcx),%edi
   0xffffffff80ba95ff <+27>:    cmp    %edi,-0x18(%rax)
   0xffffffff80ba9602 <+30>:    jne    0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba9604 <+32>:    mov    0x8(%rcx),%edi
   0xffffffff80ba9607 <+35>:    cmp    %edi,-0x14(%rax)
   0xffffffff80ba960a <+38>:    jne    0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba960c <+40>:    mov    0x10(%rcx),%edi
--Type <RET> for more, q to quit, c to continue without paging--
   0xffffffff80ba960f <+43>:    cmp    %edi,-0xc(%rax)
   0xffffffff80ba9612 <+46>:    jne    0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba9614 <+48>:    mov    -0x4(%rax),%r11d
   0xffffffff80ba9618 <+52>:    mov    (%rcx),%r10d
   0xffffffff80ba961b <+55>:    test   %r11d,%r11d
   0xffffffff80ba961e <+58>:    jne    0xffffffff80ba962e <audio_indexof_format+74>
   0xffffffff80ba9620 <+60>:    cmp    (%rax),%r10d
   0xffffffff80ba9623 <+63>:    jb     0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba9625 <+65>:    cmp    %r10d,0x4(%rax)
   0xffffffff80ba9629 <+69>:    jb     0xffffffff80ba9656 <audio_indexof_format+114>
   0xffffffff80ba962b <+71>:    mov    %esi,%eax
   0xffffffff80ba962d <+73>:    ret
   0xffffffff80ba962e <+74>:    mov    %rax,%r9
   0xffffffff80ba9631 <+77>:    xor    %edi,%edi
   0xffffffff80ba9633 <+79>:    xchg   %ax,%ax
   0xffffffff80ba9635 <+81>:    data16 cs nopw 0x0(%rax,%rax,1)
   0xffffffff80ba9640 <+92>:    cmp    %r10d,(%r9)
   0xffffffff80ba9643 <+95>:    je     0xffffffff80ba9651 <audio_indexof_format+109>
--Type <RET> for more, q to quit, c to continue without paging--
   0xffffffff80ba9645 <+97>:    add    $0x1,%edi
   0xffffffff80ba9648 <+100>:   add    $0x4,%r9
   0xffffffff80ba964c <+104>:   cmp    %r11d,%edi
   0xffffffff80ba964f <+107>:   jne    0xffffffff80ba9640 <audio_indexof_format+92>
   0xffffffff80ba9651 <+109>:   cmp    %edi,%r11d
   0xffffffff80ba9654 <+112>:   jne    0xffffffff80ba962b <audio_indexof_format+71>
   0xffffffff80ba9656 <+114>:   add    $0x1,%esi
   0xffffffff80ba9659 <+117>:   add    $0x68,%rax
   0xffffffff80ba965d <+121>:   cmp    %esi,%r8d
   0xffffffff80ba9660 <+124>:   jne    0xffffffff80ba95f1 <audio_indexof_format+13>
   0xffffffff80ba9666 <+130>:   push   %rbp
   0xffffffff80ba9667 <+131>:   mov    %rsp,%rbp
   0xffffffff80ba966a <+134>:   mov    $0xffffffff81534fb0,%rsi
   0xffffffff80ba9671 <+141>:   mov    $0xffffffff816d47b0,%rdi
   0xffffffff80ba9678 <+148>:   xor    %eax,%eax
   0xffffffff80ba967a <+150>:   call   0xffffffff80e797ae <panic>
End of assembler dump.
>How-To-Repeat:
Have a 3rd generation Focusrite 2i2 connected directly to your normal usb controller on the host system (Linux in this case), build the latest current with anita, and run qemu on the host with ""qemu-system-x86_64 -device qemu-xhci,id=xhci -device usb-host,bus=xhci.0,hostbus=1,hostaddr=15 -nographic -snapshot -hda work/wd0.img -m 256 -gdb tcp:0.0.0.0:1234"". Run a separate vm for debugging (same current snapshot as the target vm) ""qemu-system-x86_64 -nographic -snapshot -hda work/wd0.img -m 512"", then run gdb in the debugging vm as listed above to produce the same results.
>Fix:




Home | Main Index | Thread Index | Old Index