======================================
| [ 33.172888][ T23] br1: port 2(veth1) entered forwarding state
| [ 33.363280][ C0] ------------[ cut here ]------------
| [ 33.363865][ C0] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9
| [ 33.364425][ C0] load of value 107 is not a valid value for type '_Bool'
[ 33.365587][ C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[ 33.366529][ C0] Workqueue: ipv6_addrconf addrconf_dad_work
[ 33.367018][ C0] Call Trace:
[ 33.367286][ C0]
[ 33.367510][ C0] dump_stack_lvl (lib/dump_stack.c:107)
[ 33.367885][ C0] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419)
[ 33.368379][ C0] br_forward_finish.cold (./include/linux/spinlock.h:396 net/bridge/br.c:81) bridge
[ 33.368961][ C0] deliver_clone (net/bridge/br_forward.c:132) bridge
[ 33.369450][ C0] br_handle_frame_finish (net/bridge/br_input.c:215) bridge
[ 33.370024][ C0] ? __pfx_br_handle_frame_finish (net/bridge/br_input.c:75) bridge
[ 33.370678][ C0] br_handle_frame+0x612/0xe70
DETECTED CRASH, lowering timeout
[bridge]
[ 33.371176][ C0] ? __pfx_br_handle_frame (net/bridge/br_input.c:321) bridge
[ 33.371720][ C0] __netif_receive_skb_core.constprop.0 (net/core/dev.c:5448)
[ 33.372258][ C0] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3))
[ 33.372623][ C0] ? __lock_acquire (kernel/locking/lockdep.c:5137)
[ 33.373020][ C0] ? __pfx___netif_receive_skb_core.constprop.0 (net/core/dev.c:5341)
[ 33.373586][ C0] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756)
[ 33.374008][ C0] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995)
[ 33.374410][ C0] __netif_receive_skb_one_core (net/core/dev.c:5553)
[ 33.374874][ C0] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547)
[ 33.375381][ C0] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725)
[ 33.375750][ C0] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995)
[ 33.376149][ C0] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997)
[ 33.376535][ C0] __napi_poll.constprop.0 (net/core/dev.c:6625)
[ 33.376950][ C0] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827)
[ 33.377311][ C0] ? _nohz_idle_balance.isra.0 (kernel/sched/sched.h:1411 kernel/sched/sched.h:1708 kernel/sched/fair.c:12168)
[ 33.377763][ C0] ? __pfx_net_rx_action (net/core/dev.c:6791)
[ 33.378180][ C0] ? hlock_class (kernel/locking/lockdep.c:223)
[ 33.378535][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4274)
[ 33.378910][ C0] __do_softirq (kernel/softirq.c:553)
[ 33.379290][ C0] ? __dev_queue_xmit (./include/linux/rcupdate.h:308 ./include/linux/rcupdate.h:818 net/core/dev.c:4364)
[ 33.379704][ C0] do_softirq (kernel/softirq.c:454 kernel/softirq.c:441)
[ 33.380023][ C0]
[ 33.380248][ C0]
[ 33.380468][ C0] __local_bh_enable_ip (kernel/softirq.c:381)
[ 33.380845][ C0] ? __dev_queue_xmit (./include/linux/rcupdate.h:308 ./include/linux/rcupdate.h:818 net/core/dev.c:4364)
[ 33.381216][ C0] __dev_queue_xmit (net/core/dev.c:4365)
[ 33.381592][ C0] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3))
[ 33.381952][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4274)
[ 33.382305][ C0] ? eth_header (net/ethernet/eth.c:100)
[ 33.382659][ C0] ? __pfx___dev_queue_xmit (net/core/dev.c:4246)
[ 33.383078][ C0] ip6_finish_output2 (./include/net/neighbour.h:542 net/ipv6/ip6_output.c:137)
[ 33.383463][ C0] ip6_finish_output (net/ipv6/ip6_output.c:211 net/ipv6/ip6_output.c:222)
[ 33.383831][ C0] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 33.384179][ C0] ip6_output (./include/linux/netfilter.h:303 net/ipv6/ip6_output.c:243)
[ 33.384509][ C0] ? __pfx_ip6_output (net/ipv6/ip6_output.c:230)
[ 33.384901][ C0] NF_HOOK.constprop.0 (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 ./include/linux/netfilter.h:238 ./include/linux/netfilter.h:312)
[ 33.385300][ C0] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308)
[ 33.385749][ C0] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719)
[ 33.386192][ C0] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4300 kernel/locking/lockdep.c:4359)
[ 33.386715][ C0] ndisc_send_skb (net/ipv6/ndisc.c:512 (discriminator 60))
[ 33.387094][ C0] ? __pfx_ndisc_send_skb (net/ipv6/ndisc.c:473)
[ 33.387528][ C0] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 33.387892][ C0] ? __lock_release (kernel/locking/lockdep.c:353 kernel/locking/lockdep.c:5436)
[ 33.388277][ C0] ndisc_send_ns (net/ipv6/ndisc.c:653)
[ 33.388621][ C0] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3))
[ 33.388970][ C0] ? __pfx_ndisc_send_ns (net/ipv6/ndisc.c:653)
[ 33.389367][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4274)
[ 33.389759][ C0] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4300 kernel/locking/lockdep.c:4359)
[ 33.390274][ C0] addrconf_dad_work (net/ipv6/addrconf.c:4282)
[ 33.390667][ C0] ? __pfx_addrconf_dad_work (net/ipv6/addrconf.c:4180)
[ 33.391100][ C0] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725)
[ 33.391470][ C0] ? process_one_work (kernel/workqueue.c:2609)
[ 33.391892][ C0] process_one_work (kernel/workqueue.c:2633)
[ 33.392292][ C0] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 33.392650][ C0] ? __pfx_process_one_work (kernel/workqueue.c:2542)
[ 33.393089][ C0] ? assign_work (kernel/workqueue.c:1101)
[ 33.393466][ C0] worker_thread (kernel/workqueue.c:2700 kernel/workqueue.c:2787)
[ 33.393874][ C0] ? __pfx_worker_thread (kernel/workqueue.c:2733)
[ 33.394268][ C0] kthread (kernel/kthread.c:388)
[ 33.394592][ C0] ? __pfx_kthread (kernel/kthread.c:341)
[ 33.394956][ C0] ret_from_fork (arch/x86/kernel/process.c:147)
[ 33.395301][ C0] ? __pfx_kthread (kernel/kthread.c:341)
[ 33.395669][ C0] ret_from_fork_asm (arch/x86/entry/entry_64.S:250)
| [ 34.484833][ T340] br2: port 2(veth2.20) entered forwarding state
| [ 36.875278][ C3] ------------[ cut here ]------------
| [ 36.875624][ C3] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9
| [ 36.875987][ C3] load of value 107 is not a valid value for type '_Bool'
[ 36.876770][ C3] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[ 36.877393][ C3] Call Trace:
[ 36.877568][ C3]
[ 36.877723][ C3] dump_stack_lvl (lib/dump_stack.c:107)
[ 36.877968][ C3] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419)
[ 36.878298][ C3] ip_forward_finish.cold (./include/linux/skbuff.h:4267 net/ipv4/ip_forward.c:79)
[ 36.878580][ C3] NF_HOOK.constprop.0 (./include/linux/netfilter.h:314)
[ 36.878879][ C3] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308)
[ 36.879201][ C3] ? __netif_receive_skb_core.constprop.0 (net/core/dev.c:5442)
[ 36.879614][ C3] ? __xfrm_policy_check2.constprop.0 (./include/net/net_namespace.h:383 ./include/linux/netdevice.h:2654 ./include/net/xfrm.h:1165)
[ 36.879961][ C3] ? ip_forward (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/atomic/atomic-instrumented.h:33 ./include/linux/skbuff.h:1922 ./include/linux/skbuff.h:3664 net/ipv4/ip_forward.c:144)
[ 36.880227][ C3] ? vrf_l3_rcv (drivers/net/vrf.c:1222 drivers/net/vrf.c:1456 drivers/net/vrf.c:1468) vrf
[ 36.880530][ C3] ip_rcv (./include/net/dst.h:460 ./include/net/dst.h:458 net/ipv4/ip_input.c:449 ./include/linux/netfilter.h:314 ./include/linux/netfilter.h:308 net/ipv4/ip_input.c:569)
[ 36.880743][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:562)
[ 36.880987][ C3] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756)
[ 36.881261][ C3] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995)
[ 36.881523][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:562)
[ 36.881760][ C3] __netif_receive_skb_one_core (net/core/dev.c:5554 (discriminator 4))
[ 36.882105][ C3] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547)
[ 36.882466][ C3] ? __pfx_do_raw_spin_trylock (kernel/locking/spinlock_debug.c:122)
[ 36.882796][ C3] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725)
[ 36.883052][ C3] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995)
[ 36.883336][ C3] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997)
[ 36.883616][ C3] __napi_poll.constprop.0 (net/core/dev.c:6625)
[ 36.883943][ C3] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827)
[ 36.884215][ C3] ? __pfx_net_rx_action (net/core/dev.c:6791)
[ 36.884501][ C3] __do_softirq (kernel/softirq.c:553)
[ 36.884760][ C3] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644)
[ 36.885024][ C3] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14))
[ 36.885317][ C3]
[ 36.885474][ C3]
[ 36.885631][ C3] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649)
[ 36.885946][ C3] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743)
[ 36.886234][ C3] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 83 57 3f 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90
All code
========
0: 4c 01 c7 add %r8,%rdi
3: 4c 29 c2 sub %r8,%rdx
6: e9 72 ff ff ff jmp 0xffffffffffffff7d
b: 90 nop
c: 90 nop
d: 90 nop
e: 90 nop
f: 90 nop
10: 90 nop
11: 90 nop
12: 90 nop
13: 90 nop
14: 90 nop
15: 90 nop
16: 90 nop
17: 90 nop
18: 90 nop
19: 90 nop
1a: 90 nop
1b: f3 0f 1e fa endbr64
1f: 66 90 xchg %ax,%ax
21: 0f 00 2d 83 57 3f 00 verw 0x3f5783(%rip) # 0x3f57ab
28: fb sti
29: f4 hlt
2a:* fa cli <-- trapping instruction
2b: c3 ret
2c: cc int3
2d: cc int3
2e: cc int3
2f: cc int3
30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
37: 00 00 00 00
3b: 90 nop
3c: 90 nop
3d: 90 nop
3e: 90 nop
3f: 90 nop
Code starting with the faulting instruction
===========================================
0: fa cli
1: c3 ret
2: cc int3
3: cc int3
4: cc int3
5: cc int3
6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
d: 00 00 00 00
11: 90 nop
12: 90 nop
13: 90 nop
14: 90 nop
15: 90 nop
[ 36.887278][ C3] RSP: 0018:ffffc9000015fdf8 EFLAGS: 00000242
[ 36.887626][ C3] RAX: 000000000007c479 RBX: 1ffff9200002bfc1 RCX: ffffffff83a6b532
[ 36.888094][ C3] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff81498376
[ 36.888519][ C3] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1006bfeea4
[ 36.888937][ C3] R10: ffff888035ff7523 R11: ffff888035ffc348 R12: 0000000000000000
[ 36.889379][ C3] R13: ffff888001d1cc40 R14: dffffc0000000000 R15: 0000000000000000
[ 36.889794][ C3] ? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:147)
[ 36.890113][ C3] ? cpuidle_idle_call (kernel/sched/idle.c:171)
[ 36.890416][ C3] default_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:98)
[ 36.890685][ C3] cpuidle_idle_call (kernel/sched/idle.c:171)
[ 36.890944][ C3] ? __pfx_cpuidle_idle_call (kernel/sched/idle.c:147)
[ 36.891237][ C3] ? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59)
[ 36.891547][ C3] do_idle (kernel/sched/idle.c:312)
[ 36.891769][ C3] cpu_startup_entry (kernel/sched/idle.c:409 (discriminator 1))
[ 36.892071][ C3] start_secondary (arch/x86/kernel/smpboot.c:224 arch/x86/kernel/smpboot.c:304)
[ 36.892336][ C3] ? __pfx_start_secondary (arch/x86/kernel/smpboot.c:254)
[ 36.892644][ C3] secondary_startup_64_no_verify (arch/x86/kernel/head_64.S:461)
| [ 36.893185][ C3] ---[ end trace ]---
| [ 38.922742][ C1] ------------[ cut here ]------------
| [ 38.923157][ C1] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9
| [ 38.923581][ C1] load of value 107 is not a valid value for type '_Bool'
[ 38.924412][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[ 38.925083][ C1] Call Trace:
[ 38.925259][ C1]
[ 38.925425][ C1] dump_stack_lvl (lib/dump_stack.c:107)
[ 38.925695][ C1] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419)
[ 38.926052][ C1] skb_scrub_packet.cold (./include/linux/skbuff.h:4267 net/core/skbuff.c:6030)
[ 38.926349][ C1] __dev_forward_skb2 (./include/linux/netdevice.h:4115 net/core/dev.c:2135)
[ 38.926621][ C1] veth_xmit (drivers/net/veth.c:319 drivers/net/veth.c:374) veth
[ 38.926888][ C1] ? __pfx_passthru_features_check (net/core/dev.c:3436)
[ 38.927217][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546)
[ 38.927496][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338)
[ 38.927757][ C1] ? __pfx_do_raw_write_trylock (kernel/locking/spinlock_debug.c:216)
[ 38.928065][ C1] ? eth_header (net/ethernet/eth.c:100)
[ 38.928306][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246)
[ 38.928589][ C1] ? neigh_resolve_output (./include/linux/netdevice.h:3226 net/core/neighbour.c:1558 net/core/neighbour.c:1543)
[ 38.928874][ C1] ? __neigh_update (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/neighbour.c:1446)
[ 38.929138][ C1] __neigh_update (net/core/neighbour.c:1461)
[ 38.929407][ C1] arp_process (./include/linux/instrumented.h:96 (discriminator 4) ./include/linux/atomic/atomic-instrumented.h:400 (discriminator 4) ./include/linux/refcount.h:261 (discriminator 4) ./include/linux/refcount.h:304 (discriminator 4) ./include/linux/refcount.h:322 (discriminator 4) ./include/net/neighbour.h:444 (discriminator 4) net/ipv4/arp.c:934 (discriminator 4))
[ 38.929655][ C1] ? __pfx_arp_process (net/ipv4/arp.c:699)
[ 38.929926][ C1] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756)
[ 38.930202][ C1] ? __pfx_arp_rcv (net/ipv4/arp.c:965)
[ 38.930445][ C1] __netif_receive_skb_one_core (net/core/dev.c:5554 (discriminator 5))
[ 38.930754][ C1] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547)
[ 38.931083][ C1] ? __pfx_do_raw_spin_trylock (kernel/locking/spinlock_debug.c:122)
[ 38.931381][ C1] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725)
[ 38.931626][ C1] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995)
[ 38.931914][ C1] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997)
[ 38.932204][ C1] __napi_poll.constprop.0 (net/core/dev.c:6625)
[ 38.932518][ C1] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827)
[ 38.932801][ C1] ? __pfx_net_rx_action (net/core/dev.c:6791)
[ 38.933096][ C1] ? __pfx___schedule (kernel/sched/core.c:6608)
[ 38.933360][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5406)
[ 38.933666][ C1] __do_softirq (kernel/softirq.c:553)
[ 38.933936][ C1] ? __pfx_run_ksoftirqd (kernel/softirq.c:914)
[ 38.934229][ C1] run_ksoftirqd (kernel/softirq.c:410 kernel/softirq.c:922 kernel/softirq.c:913)
[ 38.934478][ C1] smpboot_thread_fn (kernel/smpboot.c:164 (discriminator 3))
[ 38.934747][ C1] ? __pfx_smpboot_thread_fn (kernel/smpboot.c:107)
[ 38.935050][ C1] ? __pfx_smpboot_thread_fn (kernel/smpboot.c:107)
[ 38.935362][ C1] kthread (kernel/kthread.c:388)
[ 38.935599][ C1] ? __pfx_kthread (kernel/kthread.c:341)
[ 38.935854][ C1] ret_from_fork (arch/x86/kernel/process.c:147)
[ 38.936109][ C1] ? __pfx_kthread (kernel/kthread.c:341)
Finger prints:
dump_stack_lvl:__ubsan_handle_load_invalid_value:deliver_clone:br_handle_frame_finish
dump_stack_lvl:__ubsan_handle_load_invalid_value:ip_rcv:__netif_receive_skb_one_core
dump_stack_lvl:__ubsan_handle_load_invalid_value:__dev_forward_skb2:veth_xmit