====================================== | [ 466.715825][ T2019] br10: port 1(veth1.10) entered forwarding state | [ 466.721355][ C1] ------------[ cut here ]------------ | [ 466.721757][ C1] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 466.722119][ C1] load of value 107 is not a valid value for type '_Bool' [ 466.722904][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 466.723535][ C1] Call Trace: [ 466.723712][ C1] [ 466.723869][ C1] dump_stack_lvl (lib/dump_stack.c:107) [ 466.724112][ C1] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 466.724455][ C1] br_forward_finish.cold (./include/linux/spinlock.h:396 net/bridge/br.c:81) bridge [ 466.724847][ C1] deliver_clone+0x52 DETECTED CRASH, lowering timeout /0x90 [bridge] [ 466.725160][ C1] maybe_deliver (net/bridge/br_forward.c:191) bridge [ 466.725483][ C1] br_flood (net/bridge/br_forward.c:236) bridge [ 466.725784][ C1] br_dev_xmit (net/bridge/br_device.c:100) bridge [ 466.726098][ C1] ? __pfx_br_dev_xmit (net/bridge/br_device.c:29) bridge [ 466.726444][ C1] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756) [ 466.726719][ C1] ? __pfx_skb_network_protocol (net/core/dev.c:3341) [ 466.727020][ C1] ? __pfx_qdisc_pkt_len_init (net/core/dev.c:3679) [ 466.727316][ C1] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719) [ 466.727623][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 466.727919][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 466.728192][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 466.728460][ C1] ? eth_header (net/ethernet/eth.c:100) [ 466.728718][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 466.729006][ C1] ? neigh_resolve_output (./include/linux/netdevice.h:3226 net/core/neighbour.c:1558 net/core/neighbour.c:1543) [ 466.729317][ C1] ip_finish_output2 (./include/net/neighbour.h:542 net/ipv4/ip_output.c:235) [ 466.729603][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 466.729846][ C1] ? __pfx_ip_finish_output2 (net/ipv4/ip_output.c:199) [ 466.730148][ C1] ? __ip_finish_output (./include/linux/skbuff.h:1627 ./include/linux/skbuff.h:4943 net/ipv4/ip_output.c:307 net/ipv4/ip_output.c:295) [ 466.730430][ C1] ip_output (./include/linux/netfilter.h:303 net/ipv4/ip_output.c:433) [ 466.730672][ C1] ? __pfx_ip_output (net/ipv4/ip_output.c:427) [ 466.730925][ C1] ? igmpv3_send_cr (net/ipv4/igmp.c:721) [ 466.731189][ C1] ? ip_local_out (net/ipv4/ip_output.c:128) [ 466.731441][ C1] igmp_ifc_timer_expire (net/ipv4/igmp.c:815) [ 466.731715][ C1] ? __pfx_igmp_ifc_timer_expire (net/ipv4/igmp.c:809) [ 466.732037][ C1] call_timer_fn (kernel/time/timer.c:1700) [ 466.732283][ C1] ? __pfx_call_timer_fn (kernel/time/timer.c:1677) [ 466.732585][ C1] __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038) [ 466.732858][ C1] ? __pfx_igmp_ifc_timer_expire (net/ipv4/igmp.c:809) [ 466.733185][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5406) [ 466.733473][ C1] ? __pfx___run_timers.part.0 (kernel/time/timer.c:2007) [ 466.733781][ C1] ? clockevents_program_event (kernel/time/clockevents.c:326) [ 466.734091][ C1] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:94 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86) [ 466.734389][ C1] ? ktime_get (kernel/time/timekeeping.c:195 (discriminator 4) kernel/time/timekeeping.c:289 (discriminator 4) kernel/time/timekeeping.c:388 (discriminator 4) kernel/time/timekeeping.c:848 (discriminator 4)) [ 466.734618][ C1] ? hrtimer_interrupt (kernel/time/hrtimer.c:1828) [ 466.734903][ C1] ? clockevents_program_event (kernel/time/clockevents.c:334 (discriminator 3)) [ 466.735223][ C1] run_timer_softirq (kernel/time/timer.c:2012 kernel/time/timer.c:2053) [ 466.735489][ C1] __do_softirq (kernel/softirq.c:553) [ 466.735746][ C1] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644) [ 466.735990][ C1] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14)) [ 466.736303][ C1] [ 466.736460][ C1] [ 466.736629][ C1] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649) [ 466.736947][ C1] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743) [ 466.737228][ C1] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 83 57 3f 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 All code ======== 0: 4c 01 c7 add %r8,%rdi 3: 4c 29 c2 sub %r8,%rdx 6: e9 72 ff ff ff jmp 0xffffffffffffff7d b: 90 nop c: 90 nop d: 90 nop e: 90 nop f: 90 nop 10: 90 nop 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop 16: 90 nop 17: 90 nop 18: 90 nop 19: 90 nop 1a: 90 nop 1b: f3 0f 1e fa endbr64 1f: 66 90 xchg %ax,%ax 21: 0f 00 2d 83 57 3f 00 verw 0x3f5783(%rip) # 0x3f57ab 28: fb sti 29: f4 hlt 2a:* fa cli <-- trapping instruction 2b: c3 ret 2c: cc int3 2d: cc int3 2e: cc int3 2f: cc int3 30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) 37: 00 00 00 00 3b: 90 nop 3c: 90 nop 3d: 90 nop 3e: 90 nop 3f: 90 nop Code starting with the faulting instruction =========================================== 0: fa cli 1: c3 ret 2: cc int3 3: cc int3 4: cc int3 5: cc int3 6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) d: 00 00 00 00 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop [ 466.738254][ C1] RSP: 0018:ffffc9000013fdf8 EFLAGS: 00000242 [ 466.738592][ C1] RAX: 00000000003529e3 RBX: 1ffff92000027fc1 RCX: ffffffffba86b532 [ 466.739000][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffb8298376 [ 466.739415][ C1] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1005dbeea4 [ 466.739838][ C1] R10: ffff88802edf7523 R11: ffff88802edfc348 R12: 0000000000000000 [ 466.740265][ C1] R13: ffff888001d18040 R14: dffffc0000000000 R15: 0000000000000000 [ 466.740699][ C1] ? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:147) [ 466.741014][ C1] ? cpuidle_idle_call (kernel/sched/idle.c:171) [ 466.741298][ C1] default_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:98) [ 466.741556][ C1] cpuidle_idle_call (kernel/sched/idle.c:171) [ 466.741817][ C1] ? __pfx_cpuidle_idle_call (kernel/sched/idle.c:147) [ 466.742105][ C1] ? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59) [ 466.742391][ C1] do_idle (kernel/sched/idle.c:312) [ 466.742607][ C1] cpu_startup_entry (kernel/sched/idle.c:409 (discriminator 1)) [ 466.742856][ C1] start_secondary (arch/x86/kernel/smpboot.c:224 arch/x86/kernel/smpboot.c:304) [ 466.743114][ C1] ? __pfx_start_secondary (arch/x86/kernel/smpboot.c:254) Finger prints: dump_stack_lvl:__ubsan_handle_load_invalid_value:maybe_deliver:br_flood