# EM9x91 crashing every now and then

**URL:** https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605
**Category:** MC/EM Series
**Created:** [November 5, 2025, 7:51am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605 "2025-11-05T07:51:10Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![sahokas](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@sahokas](https://forum.sierrawireless.com/u/sahokas)
#### Post date: [November 5, 2025, 7:51am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605/1 "2025-11-05T07:51:10Z")

</div>

Hi,

I’m experiencing sudden crashes of EM9191 and EM9291. They seem to happen maybe once in a couple of hours and looks like they happen during or right after our SW has sent at!nrinfo query to those modems. So, same symptoms with both modems. Only EM9191 produces crash dump and it looks like this:

ati  
Manufacturer: Sierra Wireless, Incorporated  
Model: EM9191  
Revision: SWIX55C\_03.17.09.00 269a54 jenkins 2025/07/24 09:04:02  
IMEI: 355890340763379  
IMEI SV: 29  
FSN: 782204521503A1  
+GCAP: +CGSM

OK  
at!gcdump

Src: FatalError  
File: atgd.c  
Line: 2550  
Str: SWI\_ABORT-M: SWI\_ASSERT(agcrc\_infop)  
00000000 00000000 00000000 00000000  
Prc: MPSS  
Task: NONE  
Time: 006E3890  
R0: 00000000 R1: 00000000 R2: 00000000 R3: 00000000 R4: 00000000  
R5: 00000000 R6: 00000000 R7: 00000000 R8: 00000000 R9: 00000000  
R10: 00000000 R11: 00000000 R12: 00000000 R13: 00000000 R14: 00000000  
R15: 00000000 R16: 00000000 R17: 00000000 R18: 00000000 R19: 00000000  
R20: 00000000 R21: 00000000 R22: 00000000 R23: 00000000 R24: 00000000  
R25: 00000000 R26: 00000000 R27: 00000000 R28: 00000000 SP: A983DAE0  
FP: A983EF48 LR: C0C78A00  
PC: 23CC2C6A  
CPSR: 00000000  
Mod: Unknown  
Ctr: ARM, IRQ dis,FIQ dis

TOS  
A983EF68 3A8EDF66 A983EF68 F56724C8 00000000 C4351C28 00000000  
00000006 A983EFE0 23CC2C6A 00000000 F5C2C118 00000000 00000000  
CBD638A4 000000FF D0408568 00000000 00000000 F6001080 00000000  
00000001 00000004 F56724C8 D0408DC4 00000001 00000000 00000000  
D0408DC4 00000001 0000000D F573700A  
BOS  
App ver: SWIX55C\_03.17.09.00

Src: FatalError  
Str: Internal error:  
00000000 00000000 00000000 00000000  
Prc: APSS  
Task:  
Time: 00000000  
R0: 00000000 R1: 00000000 R2: 00000000 R3: 00000000 R4: 00000000  
R5: 00000000 R6: 00000000 R7: 00000000 R8: 00000000 R9: 00000000  
R10: 00000000 R11: 00000000 R12: 00000000 R13: 00000000 R14: 00000000  
PC: 00000000  
CPSR: 00000000  
Mod: Unknown  
Ctr: ARM, IRQ dis,FIQ dis

TOS  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000  
BOS  
ffload stats  
\<3\>[12.600455] ipa ipa3\_uc\_debug\_stats\_alloc:1121 fail to alloc offload stats  
\<3\>[12.679117] ipa ipa3\_uc\_debug\_stats\_alloc:1121 fail to alloc offload stats  
\<3\>[12.679283] ipa ipa3\_uc\_debug\_stats\_alloc:1121 fail to alloc offload stats  
\<6\>[12.789976] diag: USB channel diag: Received Connect event  
\<6\>[18.034232] subsys-pil-tz 4080000.qcom,mss: modem: Brought out of reset  
\<6\>[18.105350] subsys-pil-tz 4080000.qcom,mss: Subsystem error monitoring/handling services are up  
\<6\>[18.105368] subsys-pil-tz 4080000.qcom,mss: modem: Power/Clock ready interrupt received  
\<6\>[18.108851] ipa-wan ipa3\_lcl\_mdm\_ssr\_notifier\_cb:3177 IPA received MPSS AFTER\_POWERUP  
\<6\>[18.108863] ipa-wan ipa3\_lcl\_mdm\_ssr\_notifier\_cb:3179 Set Modem up completed  
\<6\>[18.108871] ipa-wan ipa3\_lcl\_mdm\_ssr\_notifier\_cb:3184 IPA AFTER\_POWERUP handling is complete  
\<3\>[18.113598] qrtr: Modem QMI Readiness RX cmd:0x2 node[0x3]  
\<6\>[18.120656] sysmon-qmi: ssctl\_new\_server: Connection established between QMI handle and modem’s SSCTL service  
\<6\>[18.176854] coresight-remote-etm soc:modem\_etm0: Connection established between QMI handle and 2 service  
\<6\>[18.176872] coresight-remote-etm soc:modem\_etm1: Connection established between QMI handle and 2 service  
\<6\>[18.367476] Sending QMI\_IPA\_INIT\_MODEM\_DRIVER\_REQ\_V01  
\<6\>[18.371457] ipa-wan ipa3\_handle\_indication\_req:154 not send indication  
\<3\>[18.380844] ipa ipa3\_uc\_wdi\_event\_log\_info\_handler:357 WDI protocol missing 0x21  
\<3\>[18.380878] ipa ipa3\_uc\_ntn\_event\_log\_info\_handler:33 NTN stats sz invalid exp=224 is=112  
\<3\>[18.387317] ipa ipa3\_uc\_eogre\_event\_log\_info\_handler:72 EOGRE protocol missing 0x21  
\<6\>[18.397358] QMI\_IPA\_INIT\_MODEM\_DRIVER\_REQ\_V01 response received  
\<12\>[20.007376] syslog: Starting syslogd/klogd:  
\<12\>[20.078663] power\_config: Starting powerconfig for SDX55:  
\<6\>[20.128064] zram0: detected capacity change from 0 to 104857600  
\<6\>[20.218852] Adding 102396k swap on /dev/zram0. Priority:-2 extents:1 across:102396k SS  
\<12\>[20.219356] ++++ /etc/initscripts/power\_config → ENABLE-FTRACE START  
\<12\>[20.421727] syslog: done  
\<4\>[21.889715] swi\_netlink\_data\_ready: receive user pid:773, msg\_cached:0  
\<5\>[22.855549] audit: type=1325 audit(1762250960.081:2): table=mangle family=2 entries=6  
\<5\>[22.976052] audit: type=1325 audit(1762250960.201:3): table=mangle family=2 entries=8  
\<5\>[23.008324] audit: type=1325 audit(1762250960.231:4): table=mangle family=2 entries=9  
\<5\>[23.094419] audit: type=1325 audit(1762250960.321:5): table=mangle family=2 entries=11  
\<3\>[23.446361] ipa-wan ipa3\_wwan\_ioctl:2045 dev(rmnet\_data0) register to IPA  
\<3\>[45.299000] [glink\_pkt\_ioctl]: unrecognized ioctl command 0x8004c200  
\<6\>[64.480678] sierra\_startup\_monitor  
\<3\>[7220.515607] Fatal error on modem!  
\<3\>[7220.515762] modem subsystem failure reason: atgd.c:2550:SWI\_ABORT-M: SWI\_ASSERT(agcrc\_infop).  
\<6\>[7220.518010] subsys-restart: subsystem\_restart\_dev(): Restart sequence requested for modem, restart\_level = SYSTEM.  
\<3\>[7220.518215] Ramdump(ramdump\_microdump\_modem): No consumers. Aborting..  
\<6\>[7220.532335] microdump\_modem\_notifier\_nb: do\_ramdump() failed  
\<0\>[7220.640685] Kernel panic - not syncing: subsys-restart: Resetting the SoC - modem crashed.  
\<4\>[7220.640815] CPU: 0 PID: 14 Comm: kworker/0:1 Tainted: G W 4.14.206-perf #1  
\<4\>[7220.647914] Hardware name: Qualcomm Technologies, Inc. SDXPRAIRIE (Flattened Device Tree)  
\<4\>[7220.655864] Workqueue: events device\_restart\_work\_hdlr  
\<4\>[7220.664180] (unwind\_backtrace) from (show\_stack+0x10/0x14)  
\<4\>[7220.669210] (show\_stack) from (panic+0x180/0x3b4)  
\<4\>[7220.677104] (panic) from (subsys\_remove\_restart\_order+0x0/0x80)  
\<4\>[7220.683790] (subsys\_remove\_restart\_order) from (0xcafef800)  
\<3\>[7220.699954] ipa ipa3\_active\_clients\_panic\_notifier:300  
\<3\>[7220.699954] ---- Active Clients Table ----  
\<3\>[7220.699954]  
\<3\>[7220.699954] Total active clients count: 2  
\<3\>[7220.699954]

OK

What could be causing this?

br, Sami

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex025/user_avatar/forum.sierrawireless.com/jyijyi/32/4766_2.png) [@jyijyi](https://forum.sierrawireless.com/u/jyijyi)
#### Post date: [November 5, 2025, 8:10am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605/2 "2025-11-05T08:10:30Z")

</div>

do you mean if no AT!NRINFO is entered, there will not be crash?

---

<div class="post-metadata">

### Author: ![sahokas](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@sahokas](https://forum.sierrawireless.com/u/sahokas)
#### Post date: [November 5, 2025, 8:17am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605/3 "2025-11-05T08:17:11Z")

</div>

No. I mean that crash seems to always take place while at!nrinfo is being queried or right after that. But it doesn’t mean that every at!nrinfo query causes crash. There can be hundreds of successful queries before crash happens.

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex025/user_avatar/forum.sierrawireless.com/jyijyi/32/4766_2.png) [@jyijyi](https://forum.sierrawireless.com/u/jyijyi)
#### Post date: [November 5, 2025, 8:21am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605/4 "2025-11-05T08:21:43Z")

</div>

can you try not typing this command to confirm if this is related?

BTW, to know the root cause, you need to contact distributor to get a debug image for capturing specific debug information after crash happens

---

<div class="post-metadata">

### Author: ![sahokas](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@sahokas](https://forum.sierrawireless.com/u/sahokas)
#### Post date: [November 5, 2025, 8:26am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605/5 "2025-11-05T08:26:35Z")

</div>

I’ve already contacted our distributor, but they haven’t replied yet.

It is a bit difficult to skip nrinfo query because information provided by it is used by our SW.. but I’ll see if I can leave it out for testing purposes.

---

<div class="post-metadata">

### Author: ![sahokas](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@sahokas](https://forum.sierrawireless.com/u/sahokas)
#### Post date: [November 5, 2025, 10:35am UTC](https://forum.sierrawireless.com/t/em9x91-crashing-every-now-and-then/35605/6 "2025-11-05T10:35:59Z")

</div>

I dropped the at!nrinfo queries but it didn’t help. After about an hour and a half EM9191 crashed. Crash dump was quite short this time:

Src: FatalError  
Str: Internal error:  
00000000 00000000 00000000 00000000  
Prc: APSS  
Task:  
Time: 00000000  
R0: 00000000 R1: 00000000 R2: 00000000 R3: 00000000 R4: 00000000  
R5: 00000000 R6: 00000000 R7: 00000000 R8: 00000000 R9: 00000000  
R10: 00000000 R11: 00000000 R12: 00000000 R13: 00000000 R14: 00000000  
PC: 00000000  
CPSR: 00000000  
Mod: Unknown  
Ctr: ARM, IRQ dis,FIQ dis  
TOS  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000 00000000 00000000 00000000  
00000000 00000000 00000000 00000000  
BOS

OK
