fbnic-err: bad TWQ descriptor ordering, previous: 0 current 0 fbnic-err: bad TWQ descriptor ordering, previous: 0 current 0 [ 1162.795643][ T6582] ================================================================== [ 1162.795927][ T6582] BUG: KASAN: wild-memory-access in _copy_to_iter+0x1c7/0x1260 [ 1162.796188][ T6582] Read of size 982 at addr 0005088000000000 by task ncdevmem/6582 [ 1162.796442][ T6582] [ 1162.796531][ T6582] CPU: 2 UID: 0 PID: 6582 Comm: ncdevmem Not tainted 6.17.0-rc3-virtme #1 PREEMPT(full) [ 1162.796535][ T6582] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1162.796538][ T6582] Call Trace: [ 1162.796540][ T6582] [ 1162.796542][ T6582] dump_stack_lvl+0x82/0xc0 [ 1162.796552][ T6582] ? _copy_to_iter+0x1c7/0x1260 [ 1162.796555][ T6582] kasan_report+0xca/0x100 [ 1162.796563][ T6582] ? _copy_to_iter+0x1c7/0x1260 [ 1162.796567][ T6582] kasan_check_range+0x39/0x1b0 [ 1162.796572][ T6582] _copy_to_iter+0x1c7/0x1260 [ 1162.796575][ T6582] ? find_held_lock+0x2b/0x80 [ 1162.796583][ T6582] ? _copy_from_iter_flushcache+0x1470/0x1470 [ 1162.796587][ T6582] ? mark_held_locks+0x49/0x70 [ 1162.796591][ T6582] ? finish_task_switch.isra.0+0x245/0x960 [ 1162.796598][ T6582] ? finish_task_switch.isra.0+0x2a3/0x960 [ 1162.796603][ T6582] __skb_datagram_iter+0x439/0x770 [ 1162.796610][ T6582] ? skb_free_datagram+0x20/0x20 [ 1162.796614][ T6582] ? validate_chain+0x15e/0x4d0 [ 1162.796619][ T6582] skb_copy_datagram_iter+0x40/0x50 [ 1162.796623][ T6582] tcp_recvmsg_locked+0x1318/0x20d0 [ 1162.796631][ T6582] ? do_raw_spin_lock+0x130/0x270 [ 1162.796634][ T6582] ? tcp_update_recv_tstamps+0x1d0/0x1d0 [ 1162.796638][ T6582] ? __local_bh_enable_ip+0xa9/0x120 [ 1162.796644][ T6582] tcp_recvmsg+0xec/0x4f0 [ 1162.796647][ T6582] ? filemap_map_pages+0x95d/0xf90 [ 1162.796652][ T6582] ? tcp_recv_timestamp+0x5e0/0x5e0 [ 1162.796656][ T6582] ? rcu_read_lock_any_held+0x3f/0xa0 [ 1162.796663][ T6582] ? validate_chain+0x15e/0x4d0 [ 1162.796669][ T6582] inet6_recvmsg+0xf7/0x4e0 [ 1162.796673][ T6582] ? inet6_sk_rebuild_header+0x6f0/0x6f0 [ 1162.796678][ T6582] ____sys_recvmsg+0x21c/0x650 [ 1162.796684][ T6582] ? kernel_sendmsg+0x30/0x30 [ 1162.796686][ T6582] ? _copy_from_user+0x53/0x90 [ 1162.796691][ T6582] ? copy_msghdr_from_user+0xba/0x110 [ 1162.796694][ T6582] ? __copy_msghdr+0x3c0/0x3c0 [ 1162.796700][ T6582] ___sys_recvmsg+0xce/0x140 [ 1162.796703][ T6582] ? ___sys_sendmsg+0x170/0x170 [ 1162.796706][ T6582] ? __handle_mm_fault+0x3fc/0x5d0 [ 1162.796711][ T6582] ? __pmd_alloc+0x7e0/0x7e0 [ 1162.796717][ T6582] ? lock_vma_under_rcu+0x18a/0x3d0 [ 1162.796722][ T6582] __sys_recvmsg+0x108/0x1a0 [ 1162.796725][ T6582] ? __sys_recvmsg_sock+0x20/0x20 [ 1162.796728][ T6582] ? exc_page_fault+0x5d/0xb0 [ 1162.796737][ T6582] ? do_user_addr_fault+0x955/0xe00 [ 1162.796745][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1162.796750][ T6582] do_syscall_64+0xc1/0x370 [ 1162.796755][ T6582] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 1162.796759][ T6582] RIP: 0033:0x7f903797207d [ 1162.796763][ T6582] Code: eb b7 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 41 54 48 83 ec 10 64 8b 04 25 18 00 00 00 85 c0 75 22 b8 2f 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 5b 4c 63 e0 48 83 c4 10 4c 89 e0 41 5c c3 66 [ 1162.796765][ T6582] RSP: 002b:00007fff826123a0 EFLAGS: 00000246 ORIG_RAX: 000000000000002f [ 1162.796769][ T6582] RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007f903797207d [ 1162.796771][ T6582] RDX: 0000000002000000 RSI: 00007fff826123d0 RDI: 0000000000000008 [ 1162.796773][ T6582] RBP: 00007fff826ede80 R08: 0000000000000000 R09: 00007fff82610133 [ 1162.796775][ T6582] R10: 00007f90378721c8 R11: 0000000000000246 R12: 00007fff826edfe8 [ 1162.796776][ T6582] R13: 000000000040571b R14: 000000000042bdf0 R15: 00007f9037aaf000 [ 1162.796782][ T6582] [ 1162.796784][ T6582] ================================================================== [ 1162.807476][ T6582] Disabling lock debugging due to kernel taint fbnic-err: bad TWQ descriptor ordering, previous: 0 current 0 [ 1190.619947][ T6582] ncdevmem invoked oom-killer: gfp_mask=0x140cca(GFP_HIGHUSER_MOVABLE|__GFP_COMP), order=0, oom_score_adj=0 [ 1190.620459][ T6582] CPU: 5 UID: 0 PID: 6582 Comm: ncdevmem Tainted: G B 6.17.0-rc3-virtme #1 PREEMPT(full) [ 1190.620465][ T6582] Tainted: [B]=BAD_PAGE [ 1190.620467][ T6582] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1190.620469][ T6582] Call Trace: [ 1190.620472][ T6582] [ 1190.620474][ T6582] dump_stack_lvl+0xac/0xc0 [ 1190.620486][ T6582] dump_header+0x101/0x7d0 [ 1190.620495][ T6582] oom_kill_process+0x8b/0x180 [ 1190.620499][ T6582] out_of_memory+0x227/0x750 [ 1190.620502][ T6582] ? oom_killer_disable+0x220/0x220 [ 1190.620508][ T6582] __alloc_pages_may_oom+0x22e/0x3c0 [ 1190.620516][ T6582] ? __alloc_pages_direct_compact+0x590/0x590 [ 1190.620522][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620528][ T6582] __alloc_pages_slowpath.constprop.0+0x9fa/0x1420 [ 1190.620535][ T6582] ? warn_alloc+0x360/0x360 [ 1190.620541][ T6582] __alloc_frozen_pages_noprof+0x2e6/0x340 [ 1190.620545][ T6582] ? __alloc_pages_slowpath.constprop.0+0x1420/0x1420 [ 1190.620548][ T6582] ? page_cache_ra_unbounded+0x305/0x5e0 [ 1190.620551][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620555][ T6582] ? filemap_get_entry+0x153/0x2d0 [ 1190.620558][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620561][ T6582] ? trace_lock_release+0x26/0xc0 [ 1190.620568][ T6582] alloc_pages_mpol+0xbb/0x3b0 [ 1190.620574][ T6582] ? policy_nodemask+0x3c0/0x3c0 [ 1190.620577][ T6582] ? down_read+0x142/0x4a0 [ 1190.620586][ T6582] folio_alloc_noprof+0x17/0x200 [ 1190.620589][ T6582] __filemap_get_folio+0x24a/0x6d0 [ 1190.620594][ T6582] filemap_fault+0xae9/0x1530 [ 1190.620598][ T6582] ? folio_seek_hole_data+0x570/0x570 [ 1190.620600][ T6582] ? read_cache_page_gfp+0xe0/0xe0 [ 1190.620604][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620607][ T6582] ? do_fault_around+0x2c3/0x4b0 [ 1190.620610][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620613][ T6582] ? trace_lock_release+0x26/0xc0 [ 1190.620616][ T6582] ? lock_release+0x13/0xc0 [ 1190.620621][ T6582] __do_fault+0xea/0x390 [ 1190.620628][ T6582] do_pte_missing+0x695/0xeb0 [ 1190.620632][ T6582] handle_pte_fault+0x3f8/0x6f0 [ 1190.620635][ T6582] ? io_schedule_timeout+0x150/0x150 [ 1190.620639][ T6582] ? do_pte_missing+0xeb0/0xeb0 [ 1190.620642][ T6582] ? mtree_range_walk+0x200/0xaa0 [ 1190.620646][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620650][ T6582] __handle_mm_fault+0x3fc/0x5d0 [ 1190.620653][ T6582] ? __pmd_alloc+0x7e0/0x7e0 [ 1190.620658][ T6582] ? lock_release+0x13/0xc0 [ 1190.620662][ T6582] ? lock_vma_under_rcu+0x18a/0x3d0 [ 1190.620667][ T6582] handle_mm_fault+0x1fc/0x420 [ 1190.620670][ T6582] ? __handle_mm_fault+0x5d0/0x5d0 [ 1190.620673][ T6582] ? __rseq_handle_notify_resume+0x2b8/0x420 [ 1190.620679][ T6582] do_user_addr_fault+0x576/0xe00 [ 1190.620688][ T6582] ? rcu_is_watching+0x12/0xb0 [ 1190.620692][ T6582] exc_page_fault+0x5d/0xb0 [ 1190.620695][ T6582] asm_exc_page_fault+0x26/0x30 [ 1190.620699][ T6582] RIP: 0033:0x7f90378e6600 [ 1190.620704][ T6582] Code: c3 66 0f 1f 84 00 00 00 00 00 48 89 44 24 08 e8 b6 c5 ff ff 48 8b 44 24 08 e9 7f ff ff ff 0f 1f 40 00 31 c0 66 0f 1f 44 00 00 <41> 0f b6 14 07 88 14 07 48 83 c0 01 48 39 d8 75 ef 48 01 df 49 01 [ 1190.620707][ T6582] RSP: 002b:00007fff8260f710 EFLAGS: 00010246 [ 1190.620710][ T6582] RAX: 0000000000000000 RBX: 0000000000000001 RCX: 0000000000000001 [ 1190.620712][ T6582] RDX: 0000000000000001 RSI: 00007f9037a1e04a RDI: 00007fff8260fde4 [ 1190.620714][ T6582] RBP: 0000000000000d68 R08: 0000000000000000 R09: 00007f9037a12d40 [ 1190.620716][ T6582] R10: 00007f9037a12c40 R11: 00000000ffffffff R12: 00007f9037a579c0 [ 1190.620717][ T6582] R13: 00007fff8260fcd0 R14: 0000000000000001 R15: 00007f9037a1e04a [ 1190.620723][ T6582] [ 1190.633061][ T6582] Mem-Info: [ 1190.633199][ T6582] active_anon:51 inactive_anon:107873 isolated_anon:0 [ 1190.633199][ T6582] active_file:0 inactive_file:0 isolated_file:0 [ 1190.633199][ T6582] unevictable:0 dirty:0 writeback:0 [ 1190.633199][ T6582] slab_reclaimable:2044 slab_unreclaimable:38227 [ 1190.633199][ T6582] mapped:0 shmem:16124 pagetables:718 [ 1190.633199][ T6582] sec_pagetables:0 bounce:0 [ 1190.633199][ T6582] kernel_misc_reclaimable:0 [ 1190.633199][ T6582] free:1537 free_pcp:331 free_cma:0 [ 1190.634515][ T6582] Node 0 active_anon:204kB inactive_anon:431492kB active_file:0kB inactive_file:0kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:52kB dirty:0kB writeback:0kB shmem:64496kB kernel_stack:4288kB pagetables:2872kB sec_pagetables:0kB all_unreclaimable? yes Balloon:0kB [ 1190.635271][ T6582] Node 0 DMA free:3036kB boost:0kB min:68kB low:84kB high:100kB reserved_highatomic:0KB free_highatomic:0KB active_anon:0kB inactive_anon:12304kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15360kB mlocked:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB [ 1190.636317][ T6582] lowmem_reserve[]: 0 744 744 744 744 [ 1190.636487][ T6582] Node 0 DMA32 free:3112kB boost:0kB min:3444kB low:4304kB high:5164kB reserved_highatomic:2048KB free_highatomic:0KB active_anon:204kB inactive_anon:419188kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:1032060kB managed:762712kB mlocked:0kB bounce:0kB free_pcp:1312kB local_pcp:980kB free_cma:0kB [ 1190.637359][ T6582] lowmem_reserve[]: 0 0 0 0 0 [ 1190.637525][ T6582] Node 0 DMA: 5*4kB (U) 5*8kB (U) 6*16kB (UM) 2*32kB (UM) 4*64kB (UM) 2*128kB (UM) 1*256kB (M) 2*512kB (UM) 1*1024kB (M) 0*2048kB 0*4096kB = 3036kB [ 1190.638004][ T6582] Node 0 DMA32: 116*4kB (UM) 54*8kB (UM) 44*16kB (UM) 20*32kB (M) 13*64kB (M) 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 3072kB [ 1190.638422][ T6582] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 1190.638709][ T6582] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB [ 1190.638996][ T6582] 16163 total pagecache pages [ 1190.639161][ T6582] 0 pages in swap cache [ 1190.639290][ T6582] Free swap = 0kB [ 1190.639414][ T6582] Total swap = 0kB [ 1190.639537][ T6582] 262013 pages RAM [ 1190.639660][ T6582] 0 pages HighMem/MovableOnly [ 1190.639823][ T6582] 67495 pages reserved [ 1190.639947][ T6582] Tasks state (memory values in pages): [ 1190.640105][ T6582] [ pid ] uid tgid total_vm rss rss_anon rss_file rss_shmem pgtables_bytes swapents oom_score_adj name [ 1190.640461][ T6582] [ 158] 0 158 7359 389 335 54 0 77824 0 0 systemd-udevd [ 1190.640823][ T6582] [ 228] 0 228 3401 225 128 97 0 61440 0 0 bash [ 1190.641183][ T6582] [ 6518] 0 6518 2620 153 96 57 0 61440 0 0 make [ 1190.641532][ T6582] [ 6534] 0 6534 3335 66 64 2 0 61440 0 0 sh [ 1190.641847][ T6582] [ 6535] 0 6535 2653 131 128 3 0 65536 0 0 make [ 1190.642201][ T6582] [ 6540] 0 6540 3368 127 96 31 0 57344 0 0 sh [ 1190.642510][ T6582] [ 6561] 0 6561 3368 123 105 18 0 53248 0 0 sh [ 1190.642826][ T6582] [ 6562] 0 6562 3368 120 105 15 0 53248 0 0 sh [ 1190.643151][ T6582] [ 6563] 0 6563 3368 120 105 15 0 53248 0 0 sh [ 1190.643471][ T6582] [ 6564] 0 6564 3368 120 105 15 0 53248 0 0 sh [ 1190.643785][ T6582] [ 6565] 0 6565 3368 135 105 30 0 53248 0 0 sh [ 1190.644097][ T6582] [ 6566] 0 6566 3368 111 105 6 0 53248 0 0 sh [ 1190.644409][ T6582] [ 6567] 0 6567 666 11 0 11 0 45056 0 0 timeout [ 1190.644762][ T6582] [ 6568] 0 6568 2276 496 448 48 0 65536 0 0 perl [ 1190.645112][ T6582] [ 6569] 0 6569 666 6 0 6 0 40960 0 0 timeout [ 1190.645459][ T6582] [ 6570] 0 6570 147994 89930 89888 42 0 798720 0 0 python3 [ 1190.645811][ T6582] [ 6582] 0 6582 33026 32 32 0 0 49152 0 0 ncdevmem [ 1190.646159][ T6582] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=/,mems_allowed=0,task=python3,pid=6570,uid=0 [ 1190.646484][ T6582] Out of memory: Killed process 6570 (python3) total-vm:591976kB, anon-rss:359552kB, file-rss:168kB, shmem-rss:0kB, UID:0 pgtables:780kB oom_score_adj:0