====================================== | 0 | xx__-> [ 1175.487073][ C3] ------------[ cut here ]------------ | [ 1175.487493][ C3] WARNING: ./include/linux/skbuff.h:3239 at __udp4_lib_err_encap+0x6cc/0xae0, CPU#3: mausezahn/5428 | [ 1175.487894][ C3] Modules linked in: act_tunnel_key cls_matchall vxlan ip6_udp_tunnel udp_tunnel sch_tbf act_gact cls_flower sch_ingress bridge stp llc 8021q vrf veth [ 1175.488672][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 1175.488848][ C3] RIP: 0010:__udp4_lib_err_encap (./include/linux/skbuff.h:3239 (discriminator 3) ./include/linux/skbuff.h:3235 (discriminator 3) net/ipv4/udp.c:864 (discriminator 3)) [ 1175.489036][ C3] Code: 70 02 00 00 0f b6 2e 83 e5 0f 90 0f 0b 90 e9 e4 fa ff ff 90 0f 0b 90 90 0f 0b 90 e9 b8 fc ff ff 90 0f 0b 90 e9 3a fa ff ff 90 <0f> 0b 90 e9 48 fa ff ff 4c 8b 6c 24 20 45 31 e4 e9 38 fd ff ff 48 All code ======== 0: 70 02 jo 0x4 2: 00 00 add %al,(%rax) 4: 0f b6 2e movzbl (%rsi),%ebp 7: 83 e5 0f and $0xf,%ebp a: 90 nop b: 0f 0b ud2 d: 90 nop e: e9 e4 fa ff ff jmp 0xfffffffffffffaf7 13: 90 nop 14: 0f 0b ud2 16: 90 nop 17: 90 nop 18: 0f 0b ud2 1a: 90 nop 1b: e9 b8 fc ff ff jmp 0xfffffffffffffcd8 20: 90 nop 21: 0f 0b ud2 23: 90 nop 24: e9 3a fa ff ff jmp 0xfffffffffffffa63 29: 90 nop 2a:* 0f 0b ud2 <-- trapping instruction 2c: 90 nop 2d: e9 48 fa ff ff jmp 0xfffffffffffffa7a 32: 4c 8b 6c 24 20 mov 0x20(%rsp),%r13 37: 45 31 e4 xor %r12d,%r12d 3a: e9 38 fd ff ff jmp 0xfffffffffffffd77 3f: 48 rex.W Code starting with the faulting instruction =========================================== 0: 0f 0b ud2 2: 90 nop 3: e9 48 fa ff ff jmp 0xfffffffffffffa50 8: 4c 8b 6c 24 20 mov 0x20(%rsp),%r13 d: 45 31 e4 xor %r12d,%r12d 10: e9 38 fd ff ff jmp 0xfffffffffffffd4d 15: 48 rex.W [ 1175.489551][ C3] RSP: 0018:ffa0000000280868 EFLAGS: 00010293 [ 1175.489737][ C3] RAX: ff1100000c520424 RBX: ff1100000d1e78c0 RCX: 0000000000000000 [ 1175.489947][ C3] RDX: ff1100000c520440 RSI: ff1100000c52042c RDI: fffffffffffffff8 [ 1175.490160][ C3] RBP: ff1100000c520400 R08: ff1100000c52042c R09: 00000000000003e8 [ 1175.490378][ C3] R10: ffffffffb3d35c00 R11: 0000000000000001 R12: 0000000000000000 [ 1175.490592][ C3] R13: ff1100000d1e7980 R14: ff1100000c520440 R15: ff1100000c52042c [ 1175.490811][ C3] FS: 00007fea1d049c80(0000) GS:ff1100008332b000(0000) knlGS:0000000000000000 [ 1175.491060][ C3] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1175.491247][ C3] CR2: 00005634d9b8e680 CR3: 000000000a360005 CR4: 0000000000771ef0 [ 1175.491462][ C3] PKRU: 55555554 [ 1175.491569][ C3] Call Trace: [ 1175.491682][ C3] [ 1175.491759][ C3] ? udp_err (net/ipv4/udp.c:926 (discriminator 1)) [ 1175.491867][ C3] udp_err (net/ipv4/udp.c:933) [ 1175.491975][ C3] icmp_unreach (net/ipv4/icmp.c:1196) [ 1175.492119][ C3] ? __skb_checksum_complete (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/atomic/atomic-instrumented.h:33 ./include/linux/refcount.h:170 ./include/linux/skbuff.h:2112 net/core/skbuff.c:3785) [ 1175.492268][ C3] icmp_rcv (net/ipv4/icmp.c:1525 (discriminator 1)) [ 1175.492376][ C3] ip_protocol_deliver_rcu (net/ipv4/ip_input.c:209) [ 1175.492518][ C3] ? process_backlog (./include/linux/local_lock_internal.h:62 (discriminator 2) net/core/dev.c:6671 (discriminator 2)) [ 1175.492665][ C3] ip_local_deliver_finish (./include/linux/rcupdate.h:867 net/ipv4/ip_input.c:242) [ 1175.492805][ C3] ip_local_deliver (net/ipv4/ip_input.c:259) [ 1175.492945][ C3] ? ip_local_deliver_finish (net/ipv4/ip_input.c:251) [ 1175.493091][ C3] ? ip_rcv_finish_core (./include/net/net_namespace.h:419 (discriminator 7) ./include/linux/netdevice.h:2747 (discriminator 7) net/ipv4/ip_input.c:414 (discriminator 7)) [ 1175.493236][ C3] ? __asan_memset (mm/kasan/shadow.c:84 (discriminator 2)) [ 1175.493382][ C3] ? process_backlog (./include/linux/local_lock_internal.h:62 (discriminator 2) net/core/dev.c:6671 (discriminator 2)) [ 1175.493522][ C3] ip_rcv (./include/linux/netfilter.h:318 ./include/linux/netfilter.h:312 net/ipv4/ip_input.c:612) [ 1175.493633][ C3] ? ip_local_deliver (net/ipv4/ip_input.c:605) [ 1175.493776][ C3] ? mark_usage (kernel/locking/lockdep.c:4674 (discriminator 1)) [ 1175.493916][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 1175.494055][ C3] ? up_read_non_owner (kernel/locking/rwsem.c:1775 (discriminator 12)) [ 1175.494200][ C3] __netif_receive_skb_one_core (net/core/dev.c:6202) [ 1175.494380][ C3] ? lock_acquire.part.0 (kernel/locking/lockdep.c:470 (discriminator 2) kernel/locking/lockdep.c:5870 (discriminator 2)) [ 1175.494522][ C3] ? __netif_receive_skb_list_core (net/core/dev.c:6202) [ 1175.494701][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 1175.494843][ C3] process_backlog (./include/linux/rcupdate.h:867 net/core/dev.c:6674) [ 1175.494986][ C3] __napi_poll (net/core/dev.c:7737) [ 1175.495094][ C3] net_rx_action (net/core/dev.c:7800 net/core/dev.c:7957) [ 1175.495242][ C3] ? __napi_poll (net/core/dev.c:7919) [ 1175.495381][ C3] ? find_held_lock (kernel/locking/lockdep.c:5350 (discriminator 1)) [ 1175.495527][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 1175.495673][ C3] handle_softirqs (./arch/x86/include/asm/jump_label.h:37 ./include/trace/events/irq.h:142 kernel/softirq.c:623) [ 1175.495813][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 1175.495954][ C3] ? _local_bh_enable (kernel/softirq.c:580) [ 1175.496097][ C3] ? trace_csd_function_exit (./include/trace/events/csd.h:64 (discriminator 24)) [ 1175.496244][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 1175.496384][ C3] do_softirq (kernel/softirq.c:523 (discriminator 19) kernel/softirq.c:510 (discriminator 19)) [ 1175.496489][ C3] [ 1175.496560][ C3] [ 1175.496634][ C3] ? __dev_queue_xmit (./include/linux/rcupdate.h:310 (discriminator 2) ./include/linux/rcupdate.h:909 (discriminator 2) net/core/dev.c:4905 (discriminator 2)) [ 1175.496775][ C3] __local_bh_enable_ip (kernel/softirq.c:450) [ 1175.496915][ C3] __dev_queue_xmit (net/core/dev.c:4906) [ 1175.497054][ C3] ? _copy_from_iter (./arch/x86/include/asm/smap.h:47 ./arch/x86/include/asm/uaccess_64.h:121 ./arch/x86/include/asm/uaccess_64.h:141 lib/iov_iter.c:67 ./include/linux/iov_iter.h:30 ./include/linux/iov_iter.h:302 ./include/linux/iov_iter.h:330 lib/iov_iter.c:261 lib/iov_iter.c:272) [ 1175.497200][ C3] ? __alloc_skb (./arch/x86/include/asm/atomic.h:28 ./include/linux/atomic/atomic-arch-fallback.h:503 ./include/linux/atomic/atomic-instrumented.h:68 net/core/skbuff.c:408 net/core/skbuff.c:720) [ 1175.497348][ C3] ? napi_skb_cache_get (net/core/skbuff.c:674) [ 1175.497488][ C3] ? _copy_from_iter_flushcache (lib/iov_iter.c:266) [ 1175.497670][ C3] ? ref_tracker_get_stats (lib/ref_tracker.c:84) [ 1175.497813][ C3] ? netdev_core_pick_tx (net/core/dev.c:4767) [ 1175.497959][ C3] ? packet_release (net/packet/af_packet.c:1924) [ 1175.498109][ C3] packet_snd (net/packet/af_packet.c:3077 (discriminator 1)) [ 1175.498259][ C3] ? tpacket_snd (net/packet/af_packet.c:2941) [ 1175.498399][ C3] ? __might_fault (mm/memory.c:7230 (discriminator 6)) [ 1175.498544][ C3] ? __might_fault (mm/memory.c:7230 (discriminator 6)) [ 1175.498691][ C3] ? __might_fault (mm/memory.c:7230 (discriminator 6)) [ 1175.498831][ C3] __sys_sendto (net/socket.c:787 (discriminator 4) net/socket.c:802 (discriminator 4) net/socket.c:2265 (discriminator 4)) [ 1175.498975][ C3] ? __ia32_sys_getpeername (net/socket.c:2232) [ 1175.499124][ C3] ? sock_ioctl (net/socket.c:1435) [ 1175.499275][ C3] ? exc_page_fault (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:109 ./arch/x86/include/asm/irqflags.h:151 arch/x86/mm/fault.c:1480 arch/x86/mm/fault.c:1527) [ 1175.499420][ C3] __x64_sys_sendto (net/socket.c:2272 (discriminator 1) net/socket.c:2268 (discriminator 1) net/socket.c:2268 (discriminator 1)) [ 1175.499561][ C3] ? trace_irq_enable.constprop.0 (./include/trace/events/preemptirq.h:40 (discriminator 24)) [ 1175.499764][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4473) [ 1175.499904][ C3] ? do_syscall_64 (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 ./include/linux/entry-common.h:187 arch/x86/entry/syscall_64.c:89) [ 1175.500046][ C3] do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1)) [ 1175.500190][ C3] ? trace_hardirqs_off (kernel/trace/trace_preemptirq.c:106 (discriminator 9)) [ 1175.500335][ C3] ? exc_page_fault (arch/x86/mm/fault.c:1480 (discriminator 3) arch/x86/mm/fault.c:1527 (discriminator 3)) [ 1175.500476][ C3] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 1175.500659][ C3] RIP: 0033:0x7fea1d20822e [ 1175.500810][ C3] Code: 4d 89 d8 e8 94 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa All code ======== 0: 4d 89 d8 mov %r11,%r8 3: e8 94 bd 00 00 call 0xbd9c 8: 4c 8b 5d f8 mov -0x8(%rbp),%r11 c: 41 8b 93 08 03 00 00 mov 0x308(%r11),%edx 13: 59 pop %rcx 14: 5e pop %rsi 15: 48 83 f8 fc cmp $0xfffffffffffffffc,%rax 19: 74 11 je 0x2c 1b: c9 leave 1c: c3 ret 1d: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 24: 48 8b 45 10 mov 0x10(%rbp),%rax 28: 0f 05 syscall 2a:* c9 leave <-- trapping instruction 2b: c3 ret 2c: 83 e2 39 and $0x39,%edx 2f: 83 fa 08 cmp $0x8,%edx 32: 75 e7 jne 0x1b 34: e8 03 ff ff ff call 0xffffffffffffff3c 39: 0f 1f 00 nopl (%rax) 3c: f3 0f 1e fa endbr64 Code starting with the faulting instruction =========================================== 0: c9 leave 1: c3 ret 2: 83 e2 39 and $0x39,%edx 5: 83 fa 08 cmp $0x8,%edx 8: 75 e7 jne 0xfffffffffffffff1 a: e8 03 ff ff ff call 0xffffffffffffff12 f: 0f 1f 00 nopl (%rax) 12: f3 0f 1e fa endbr64 [ 1175.501329][ C3] RSP: 002b:00007ffc47bf4770 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 1175.501544][ C3] RAX: ffffffffffffffda RBX: 000056350881ae82 RCX: 00007fea1d20822e [ 1175.501761][ C3] RDX: 00000000000003c5 RSI: 000056350881ae82 RDI: 0000000000000005 [ 1175.501973][ C3] RBP: 00007ffc47bf4780 R08: 00007ffc47bf47d0 R09: 0000000000000014 [ 1175.502191][ C3] R10: 0000000000000000 R11: 0000000000000202 R12: 000056350881a830 Finger prints: __udp4_lib_err_encap:udp_err:icmp_unreach:icmp_rcv:ip_protocol_deliver_rcu