====================================== | [ 33.172888][ T23] br1: port 2(veth1) entered forwarding state | [ 33.363280][ C0] ------------[ cut here ]------------ | [ 33.363865][ C0] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 33.364425][ C0] load of value 107 is not a valid value for type '_Bool' [ 33.365587][ C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 33.366529][ C0] Workqueue: ipv6_addrconf addrconf_dad_work [ 33.367018][ C0] Call Trace: [ 33.367286][ C0] [ 33.367510][ C0] dump_stack_lvl (lib/dump_stack.c:107) [ 33.367885][ C0] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 33.368379][ C0] br_forward_finish.cold (./include/linux/spinlock.h:396 net/bridge/br.c:81) bridge [ 33.368961][ C0] deliver_clone (net/bridge/br_forward.c:132) bridge [ 33.369450][ C0] br_handle_frame_finish (net/bridge/br_input.c:215) bridge [ 33.370024][ C0] ? __pfx_br_handle_frame_finish (net/bridge/br_input.c:75) bridge [ 33.370678][ C0] br_handle_frame+0x612/0xe70 DETECTED CRASH, lowering timeout [bridge] [ 33.371176][ C0] ? __pfx_br_handle_frame (net/bridge/br_input.c:321) bridge [ 33.371720][ C0] __netif_receive_skb_core.constprop.0 (net/core/dev.c:5448) [ 33.372258][ C0] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 33.372623][ C0] ? __lock_acquire (kernel/locking/lockdep.c:5137) [ 33.373020][ C0] ? __pfx___netif_receive_skb_core.constprop.0 (net/core/dev.c:5341) [ 33.373586][ C0] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756) [ 33.374008][ C0] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995) [ 33.374410][ C0] __netif_receive_skb_one_core (net/core/dev.c:5553) [ 33.374874][ C0] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547) [ 33.375381][ C0] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 33.375750][ C0] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995) [ 33.376149][ C0] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997) [ 33.376535][ C0] __napi_poll.constprop.0 (net/core/dev.c:6625) [ 33.376950][ C0] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827) [ 33.377311][ C0] ? _nohz_idle_balance.isra.0 (kernel/sched/sched.h:1411 kernel/sched/sched.h:1708 kernel/sched/fair.c:12168) [ 33.377763][ C0] ? __pfx_net_rx_action (net/core/dev.c:6791) [ 33.378180][ C0] ? hlock_class (kernel/locking/lockdep.c:223) [ 33.378535][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 33.378910][ C0] __do_softirq (kernel/softirq.c:553) [ 33.379290][ C0] ? __dev_queue_xmit (./include/linux/rcupdate.h:308 ./include/linux/rcupdate.h:818 net/core/dev.c:4364) [ 33.379704][ C0] do_softirq (kernel/softirq.c:454 kernel/softirq.c:441) [ 33.380023][ C0] [ 33.380248][ C0] [ 33.380468][ C0] __local_bh_enable_ip (kernel/softirq.c:381) [ 33.380845][ C0] ? __dev_queue_xmit (./include/linux/rcupdate.h:308 ./include/linux/rcupdate.h:818 net/core/dev.c:4364) [ 33.381216][ C0] __dev_queue_xmit (net/core/dev.c:4365) [ 33.381592][ C0] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 33.381952][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 33.382305][ C0] ? eth_header (net/ethernet/eth.c:100) [ 33.382659][ C0] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 33.383078][ C0] ip6_finish_output2 (./include/net/neighbour.h:542 net/ipv6/ip6_output.c:137) [ 33.383463][ C0] ip6_finish_output (net/ipv6/ip6_output.c:211 net/ipv6/ip6_output.c:222) [ 33.383831][ C0] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 33.384179][ C0] ip6_output (./include/linux/netfilter.h:303 net/ipv6/ip6_output.c:243) [ 33.384509][ C0] ? __pfx_ip6_output (net/ipv6/ip6_output.c:230) [ 33.384901][ C0] NF_HOOK.constprop.0 (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 ./include/linux/netfilter.h:238 ./include/linux/netfilter.h:312) [ 33.385300][ C0] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308) [ 33.385749][ C0] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719) [ 33.386192][ C0] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4300 kernel/locking/lockdep.c:4359) [ 33.386715][ C0] ndisc_send_skb (net/ipv6/ndisc.c:512 (discriminator 60)) [ 33.387094][ C0] ? __pfx_ndisc_send_skb (net/ipv6/ndisc.c:473) [ 33.387528][ C0] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 33.387892][ C0] ? __lock_release (kernel/locking/lockdep.c:353 kernel/locking/lockdep.c:5436) [ 33.388277][ C0] ndisc_send_ns (net/ipv6/ndisc.c:653) [ 33.388621][ C0] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 33.388970][ C0] ? __pfx_ndisc_send_ns (net/ipv6/ndisc.c:653) [ 33.389367][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 33.389759][ C0] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4300 kernel/locking/lockdep.c:4359) [ 33.390274][ C0] addrconf_dad_work (net/ipv6/addrconf.c:4282) [ 33.390667][ C0] ? __pfx_addrconf_dad_work (net/ipv6/addrconf.c:4180) [ 33.391100][ C0] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 33.391470][ C0] ? process_one_work (kernel/workqueue.c:2609) [ 33.391892][ C0] process_one_work (kernel/workqueue.c:2633) [ 33.392292][ C0] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 33.392650][ C0] ? __pfx_process_one_work (kernel/workqueue.c:2542) [ 33.393089][ C0] ? assign_work (kernel/workqueue.c:1101) [ 33.393466][ C0] worker_thread (kernel/workqueue.c:2700 kernel/workqueue.c:2787) [ 33.393874][ C0] ? __pfx_worker_thread (kernel/workqueue.c:2733) [ 33.394268][ C0] kthread (kernel/kthread.c:388) [ 33.394592][ C0] ? __pfx_kthread (kernel/kthread.c:341) [ 33.394956][ C0] ret_from_fork (arch/x86/kernel/process.c:147) [ 33.395301][ C0] ? __pfx_kthread (kernel/kthread.c:341) [ 33.395669][ C0] ret_from_fork_asm (arch/x86/entry/entry_64.S:250) | [ 34.484833][ T340] br2: port 2(veth2.20) entered forwarding state | [ 36.875278][ C3] ------------[ cut here ]------------ | [ 36.875624][ C3] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 36.875987][ C3] load of value 107 is not a valid value for type '_Bool' [ 36.876770][ C3] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 36.877393][ C3] Call Trace: [ 36.877568][ C3] [ 36.877723][ C3] dump_stack_lvl (lib/dump_stack.c:107) [ 36.877968][ C3] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 36.878298][ C3] ip_forward_finish.cold (./include/linux/skbuff.h:4267 net/ipv4/ip_forward.c:79) [ 36.878580][ C3] NF_HOOK.constprop.0 (./include/linux/netfilter.h:314) [ 36.878879][ C3] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308) [ 36.879201][ C3] ? __netif_receive_skb_core.constprop.0 (net/core/dev.c:5442) [ 36.879614][ C3] ? __xfrm_policy_check2.constprop.0 (./include/net/net_namespace.h:383 ./include/linux/netdevice.h:2654 ./include/net/xfrm.h:1165) [ 36.879961][ C3] ? ip_forward (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/atomic/atomic-instrumented.h:33 ./include/linux/skbuff.h:1922 ./include/linux/skbuff.h:3664 net/ipv4/ip_forward.c:144) [ 36.880227][ C3] ? vrf_l3_rcv (drivers/net/vrf.c:1222 drivers/net/vrf.c:1456 drivers/net/vrf.c:1468) vrf [ 36.880530][ C3] ip_rcv (./include/net/dst.h:460 ./include/net/dst.h:458 net/ipv4/ip_input.c:449 ./include/linux/netfilter.h:314 ./include/linux/netfilter.h:308 net/ipv4/ip_input.c:569) [ 36.880743][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:562) [ 36.880987][ C3] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756) [ 36.881261][ C3] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995) [ 36.881523][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:562) [ 36.881760][ C3] __netif_receive_skb_one_core (net/core/dev.c:5554 (discriminator 4)) [ 36.882105][ C3] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547) [ 36.882466][ C3] ? __pfx_do_raw_spin_trylock (kernel/locking/spinlock_debug.c:122) [ 36.882796][ C3] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 36.883052][ C3] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995) [ 36.883336][ C3] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997) [ 36.883616][ C3] __napi_poll.constprop.0 (net/core/dev.c:6625) [ 36.883943][ C3] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827) [ 36.884215][ C3] ? __pfx_net_rx_action (net/core/dev.c:6791) [ 36.884501][ C3] __do_softirq (kernel/softirq.c:553) [ 36.884760][ C3] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644) [ 36.885024][ C3] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14)) [ 36.885317][ C3] [ 36.885474][ C3] [ 36.885631][ C3] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649) [ 36.885946][ C3] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743) [ 36.886234][ C3] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 83 57 3f 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 All code ======== 0: 4c 01 c7 add %r8,%rdi 3: 4c 29 c2 sub %r8,%rdx 6: e9 72 ff ff ff jmp 0xffffffffffffff7d b: 90 nop c: 90 nop d: 90 nop e: 90 nop f: 90 nop 10: 90 nop 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop 16: 90 nop 17: 90 nop 18: 90 nop 19: 90 nop 1a: 90 nop 1b: f3 0f 1e fa endbr64 1f: 66 90 xchg %ax,%ax 21: 0f 00 2d 83 57 3f 00 verw 0x3f5783(%rip) # 0x3f57ab 28: fb sti 29: f4 hlt 2a:* fa cli <-- trapping instruction 2b: c3 ret 2c: cc int3 2d: cc int3 2e: cc int3 2f: cc int3 30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) 37: 00 00 00 00 3b: 90 nop 3c: 90 nop 3d: 90 nop 3e: 90 nop 3f: 90 nop Code starting with the faulting instruction =========================================== 0: fa cli 1: c3 ret 2: cc int3 3: cc int3 4: cc int3 5: cc int3 6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) d: 00 00 00 00 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop [ 36.887278][ C3] RSP: 0018:ffffc9000015fdf8 EFLAGS: 00000242 [ 36.887626][ C3] RAX: 000000000007c479 RBX: 1ffff9200002bfc1 RCX: ffffffff83a6b532 [ 36.888094][ C3] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff81498376 [ 36.888519][ C3] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1006bfeea4 [ 36.888937][ C3] R10: ffff888035ff7523 R11: ffff888035ffc348 R12: 0000000000000000 [ 36.889379][ C3] R13: ffff888001d1cc40 R14: dffffc0000000000 R15: 0000000000000000 [ 36.889794][ C3] ? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:147) [ 36.890113][ C3] ? cpuidle_idle_call (kernel/sched/idle.c:171) [ 36.890416][ C3] default_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:98) [ 36.890685][ C3] cpuidle_idle_call (kernel/sched/idle.c:171) [ 36.890944][ C3] ? __pfx_cpuidle_idle_call (kernel/sched/idle.c:147) [ 36.891237][ C3] ? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59) [ 36.891547][ C3] do_idle (kernel/sched/idle.c:312) [ 36.891769][ C3] cpu_startup_entry (kernel/sched/idle.c:409 (discriminator 1)) [ 36.892071][ C3] start_secondary (arch/x86/kernel/smpboot.c:224 arch/x86/kernel/smpboot.c:304) [ 36.892336][ C3] ? __pfx_start_secondary (arch/x86/kernel/smpboot.c:254) [ 36.892644][ C3] secondary_startup_64_no_verify (arch/x86/kernel/head_64.S:461) | [ 36.893185][ C3] ---[ end trace ]--- | [ 38.922742][ C1] ------------[ cut here ]------------ | [ 38.923157][ C1] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 38.923581][ C1] load of value 107 is not a valid value for type '_Bool' [ 38.924412][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 38.925083][ C1] Call Trace: [ 38.925259][ C1] [ 38.925425][ C1] dump_stack_lvl (lib/dump_stack.c:107) [ 38.925695][ C1] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 38.926052][ C1] skb_scrub_packet.cold (./include/linux/skbuff.h:4267 net/core/skbuff.c:6030) [ 38.926349][ C1] __dev_forward_skb2 (./include/linux/netdevice.h:4115 net/core/dev.c:2135) [ 38.926621][ C1] veth_xmit (drivers/net/veth.c:319 drivers/net/veth.c:374) veth [ 38.926888][ C1] ? __pfx_passthru_features_check (net/core/dev.c:3436) [ 38.927217][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 38.927496][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 38.927757][ C1] ? __pfx_do_raw_write_trylock (kernel/locking/spinlock_debug.c:216) [ 38.928065][ C1] ? eth_header (net/ethernet/eth.c:100) [ 38.928306][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 38.928589][ C1] ? neigh_resolve_output (./include/linux/netdevice.h:3226 net/core/neighbour.c:1558 net/core/neighbour.c:1543) [ 38.928874][ C1] ? __neigh_update (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/neighbour.c:1446) [ 38.929138][ C1] __neigh_update (net/core/neighbour.c:1461) [ 38.929407][ C1] arp_process (./include/linux/instrumented.h:96 (discriminator 4) ./include/linux/atomic/atomic-instrumented.h:400 (discriminator 4) ./include/linux/refcount.h:261 (discriminator 4) ./include/linux/refcount.h:304 (discriminator 4) ./include/linux/refcount.h:322 (discriminator 4) ./include/net/neighbour.h:444 (discriminator 4) net/ipv4/arp.c:934 (discriminator 4)) [ 38.929655][ C1] ? __pfx_arp_process (net/ipv4/arp.c:699) [ 38.929926][ C1] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756) [ 38.930202][ C1] ? __pfx_arp_rcv (net/ipv4/arp.c:965) [ 38.930445][ C1] __netif_receive_skb_one_core (net/core/dev.c:5554 (discriminator 5)) [ 38.930754][ C1] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547) [ 38.931083][ C1] ? __pfx_do_raw_spin_trylock (kernel/locking/spinlock_debug.c:122) [ 38.931381][ C1] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 38.931626][ C1] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995) [ 38.931914][ C1] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997) [ 38.932204][ C1] __napi_poll.constprop.0 (net/core/dev.c:6625) [ 38.932518][ C1] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827) [ 38.932801][ C1] ? __pfx_net_rx_action (net/core/dev.c:6791) [ 38.933096][ C1] ? __pfx___schedule (kernel/sched/core.c:6608) [ 38.933360][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5406) [ 38.933666][ C1] __do_softirq (kernel/softirq.c:553) [ 38.933936][ C1] ? __pfx_run_ksoftirqd (kernel/softirq.c:914) [ 38.934229][ C1] run_ksoftirqd (kernel/softirq.c:410 kernel/softirq.c:922 kernel/softirq.c:913) [ 38.934478][ C1] smpboot_thread_fn (kernel/smpboot.c:164 (discriminator 3)) [ 38.934747][ C1] ? __pfx_smpboot_thread_fn (kernel/smpboot.c:107) [ 38.935050][ C1] ? __pfx_smpboot_thread_fn (kernel/smpboot.c:107) [ 38.935362][ C1] kthread (kernel/kthread.c:388) [ 38.935599][ C1] ? __pfx_kthread (kernel/kthread.c:341) [ 38.935854][ C1] ret_from_fork (arch/x86/kernel/process.c:147) [ 38.936109][ C1] ? __pfx_kthread (kernel/kthread.c:341) Finger prints: dump_stack_lvl:__ubsan_handle_load_invalid_value:deliver_clone:br_handle_frame_finish dump_stack_lvl:__ubsan_handle_load_invalid_value:ip_rcv:__netif_receive_skb_one_core dump_stack_lvl:__ubsan_handle_load_invalid_value:__dev_forward_skb2:veth_xmit