====================================== | [ 50.361692][ C1] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129) | [ 50.361922][ C1] | [ 50.362015][ C1] | [ 50.362015][ C1] stack backtrace: [ 50.362726][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 50.363241][ C1] Call Trace: [ 50.363382][ C1] <IRQ> [ 50.363475][ C1] dump_stack_lvl (lib/dump_stack.c:117) [ 50.363654][ C1] print_irq_inversion_bug.part.0 (kernel/locking/lockdep.c:4024) [ 50.363973][ C1] ? __pfx_print_irq_inversion_bug.part.0 (kernel/locking/lockdep.c:4024) [ 50.364186][ C1] ? __pfx_usage_skip (kernel/locking/lockdep.c:2264) [ 50.364352][ C1] ? __pfx_usage_match (kernel/locking/lockdep.c:2256) [ 50.364527][ C1] ? arch_stack_walk (arch/x86/kernel/stacktrace.c:26) [ 50.364694][ C1] mark_lock_irq (kernel/locking/lockdep.c:4244) [ 50.364975][ C1] ? __pfx_mark_lock_irq (kernel/locking/lockdep.c:4207) [ 50.365145][ C1] ? stack_trace_save (kernel/stacktrace.c:123) [ 50.365314][ C1] ? add_chain_cache (kernel/locking/lockdep.c:3730) [ 50.365484][ C1] ? save_trace (kernel/locking/lockdep.c:586) [ 50.365655][ C1] mark_lock (kernel/locking/lockdep.c:4678) [ 50.365781][ C1] mark_usage (kernel/locking/lockdep.c:4567) [ 50.365910][ C1] __lock_acquire (kernel/locking/lockdep.c:5091) [ 50.366078][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5137) [ 50.366244][ C1] ? __pfx_br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:80) bridge [ 50.366637][ C1] lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756) [ 50.366936][ C1] ? br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:87) bridge [ 50.367279][ C1] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719) [ 50.367553][ C1] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 52)) [ 50.367838][ C1] ? br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:87) bridge [ 50.368257][ C1] ? lock_acquire (kernel/locking/lockdep.c:5727) [ 50.368527][ C1] ? br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:87) bridge [ 50.369135][ C1] _raw_spin_lock (./include/linux/spinlock_api_smp.h:134 kernel/locking/spinlock.c:154) [ 50.369414][ C1] ? br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:87) bridge [ 50.369824][ C1] br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:87) bridge [ 50.370234][ C1] ? __pfx_br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:80) bridge [ 50.370701][ C1] call_timer_fn (kernel/time/timer.c:1793) [ 50.370971][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1783) [ 50.371241][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1783) [ 50.371507][ C1] ? __pfx_call_timer_fn (kernel/time/timer.c:1770) [ 50.371781][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 50.372059][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 50.372338][ C1] __run_timers (kernel/time/timer.c:1845 kernel/time/timer.c:2418) [ 50.372612][ C1] ? __pfx_br_forward_delay_timer_expired (net/bridge/br_stp_timer.c:80) bridge [ 50.373084][ C1] ? __pfx___run_timers (kernel/time/timer.c:2389) [ 50.373350][ C1] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:115 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 50.373621][ C1] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 50.373900][ C1] ? lock_acquire (kernel/locking/lockdep.c:5727) [ 50.374171][ C1] ? run_timer_softirq (kernel/time/timer.c:2429 kernel/time/timer.c:2422 kernel/time/timer.c:2438 kernel/time/timer.c:2448) [ 50.374439][ C1] run_timer_softirq (kernel/time/timer.c:2430 kernel/time/timer.c:2422 kernel/time/timer.c:2438 kernel/time/timer.c:2448) [ 50.374705][ C1] __do_softirq (kernel/softirq.c:554) [ 50.374980][ C1] irq_exit_rcu (kernel/softirq.c:428 kernel/softirq.c:633 kernel/softirq.c:645) [ 50.375185][ C1] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1043 arch/x86/kernel/apic/apic.c:1043) [ 50.375462][ C1] </IRQ> [ 50.375604][ C1] <TASK> [ 50.375747][ C1] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 50.376083][ C1] RIP: 0010:ftrace_graph_ret_addr (kernel/trace/fgraph.c:334) [ 50.376332][ C1] Code: 04 e8 ce 9d 44 00 8b 44 24 04 eb bf 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 41 57 <48> 89 d0 48 ba 00 00 00 00 00 fc ff df 41 56 41 55 41 54 49 89 cc All code ======== 0: 04 e8 add $0xe8,%al 2: ce (bad) 3: 9d popf 4: 44 00 8b 44 24 04 eb add %r9b,-0x14fbdbbc(%rbx) b: bf 0f 1f 84 00 mov $0x841f0f,%edi 10: 00 00 add %al,(%rax) 12: 00 00 add %al,(%rax) 14: 90 nop 15: 90 nop 16: 90 nop 17: 90 nop 18: 90 nop 19: 90 nop 1a: 90 nop 1b: 90 nop 1c: 90 nop 1d: 90 nop 1e: 90 nop 1f: 90 nop 20: 90 nop 21: 90 nop 22: 90 nop 23: 90 nop 24: 66 0f 1f 00 nopw (%rax) 28: 41 57 push %r15 2a:* 48 89 d0 mov %rdx,%rax <-- trapping instruction 2d: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx 34: fc ff df 37: 41 56 push %r14 39: 41 55 push %r13 3b: 41 54 push %r12 3d: 49 89 cc mov %rcx,%r12 Code starting with the faulting instruction =========================================== 0: 48 89 d0 mov %rdx,%rax 3: 48 ba 00 00 00 00 00 movabs $0xdffffc0000000000,%rdx a: fc ff df d: 41 56 push %r14 f: 41 55 push %r13 11: 41 54 push %r12 13: 49 89 cc mov %rcx,%r12 [ 50.376924][ C1] RSP: 0018:ffffc90000cdf0c8 EFLAGS: 00000246 [ 50.377194][ C1] RAX: dffffc0000000000 RBX: 0000000000000001 RCX: ffffc90000cdfbe8 [ 50.377458][ C1] RDX: ffffffff96013fb3 RSI: ffffc90000cdf208 RDI: ffff888012f50040 [ 50.377717][ C1] RBP: ffffc90000cdf230 R08: ffffc90000cdf218 R09: 1ffff9200019be24 [ 50.377963][ C1] R10: ffffc90000cdf1d8 R11: ffffc90000cdf219 R12: 1ffff9200019be24 [ 50.378209][ C1] R13: ffffc90000cdf1d8 R14: ffffffff99f9be3c R15: ffffc90000cdfbe8 [ 50.378464][ C1] ? do_filp_open (fs/namei.c:3826) [ 50.378629][ C1] unwind_next_frame (./arch/x86/include/asm/unwind.h:111 ./arch/x86/include/asm/unwind.h:127 arch/x86/kernel/unwind_orc.c:588) [ 50.378797][ C1] ? path_openat (fs/namei.c:3795) [ 50.378966][ C1] ? __pfx_unwind_next_frame (arch/x86/kernel/unwind_orc.c:469) [ 50.379136][ C1] ? path_openat (fs/namei.c:3795) [ 50.379304][ C1] ? kernel_text_address (kernel/extable.c:99) [ 50.379477][ C1] ? __pfx_stack_trace_consume_entry (kernel/stacktrace.c:83) [ 50.379683][ C1] arch_stack_walk (arch/x86/kernel/stacktrace.c:24) [ 50.379857][ C1] ? do_filp_open (fs/namei.c:3826) [ 50.380026][ C1] stack_trace_save (kernel/stacktrace.c:123) [ 50.380194][ C1] ? __pfx_stack_trace_save (kernel/stacktrace.c:114) [ 50.380366][ C1] set_track_prepare (mm/slub.c:886) [ 50.380539][ C1] ? kasan_quarantine_reduce (./include/linux/srcu.h:285 mm/kasan/quarantine.c:287) [ 50.380703][ C1] ? __kasan_slab_alloc (mm/kasan/common.c:322) [ 50.380873][ C1] ? __kmalloc (mm/slub.c:3799 mm/slub.c:3845 mm/slub.c:3965 mm/slub.c:3979) [ 50.381037][ C1] ? p9_fcall_init (net/9p/client.c:232) [ 50.381207][ C1] ? p9_tag_alloc (net/9p/client.c:295) [ 50.381375][ C1] ? p9_client_prepare_req (net/9p/client.c:641) [ 50.381543][ C1] ? p9_client_rpc (net/9p/client.c:688 (discriminator 4)) [ 50.381711][ C1] ? p9_client_readlink (net/9p/client.c:2238) [ 50.381878][ C1] ? v9fs_vfs_get_link_dotl (fs/9p/vfs_inode_dotl.c:822 fs/9p/vfs_inode_dotl.c:806) [ 50.382049][ C1] ? pick_link (fs/namei.c:1806) [ 50.382213][ C1] ? step_into (fs/namei.c:1874) [ 50.382378][ C1] ? link_path_walk.part.0.constprop.0 (fs/namei.c:2331) [ 50.382585][ C1] ? path_openat (fs/namei.c:3795) [ 50.382751][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 50.382911][ C1] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 50.383035][ C1] free_to_partial_list (mm/slub.c:4026) [ 50.383198][ C1] ? qlist_free_all (mm/kasan/quarantine.c:163 mm/kasan/quarantine.c:179) [ 50.383415][ C1] qlist_free_all (mm/kasan/quarantine.c:174) [ 50.383842][ C1] ? p9_fcall_init (net/9p/client.c:232) [ 50.384113][ C1] kasan_quarantine_reduce (./include/linux/srcu.h:285 mm/kasan/quarantine.c:287) [ 50.384400][ C1] __kasan_slab_alloc (mm/kasan/common.c:322) [ 50.384675][ C1] __kmalloc (mm/slub.c:3799 mm/slub.c:3845 mm/slub.c:3965 mm/slub.c:3979) [ 50.385087][ C1] p9_fcall_init (net/9p/client.c:232) [ 50.385358][ C1] p9_tag_alloc (net/9p/client.c:295) [ 50.385523][ C1] ? __pfx_p9_tag_alloc (net/9p/client.c:277) [ 50.385688][ C1] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 50.385818][ C1] p9_client_prepare_req (net/9p/client.c:641) [ 50.385986][ C1] ? __pfx_p9_client_prepare_req (net/9p/client.c:625) [ 50.386205][ C1] ? find_held_lock (kernel/locking/lockdep.c:5244) [ 50.386379][ C1] p9_client_rpc (net/9p/client.c:688 (discriminator 4)) [ 50.386546][ C1] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:115 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 50.386713][ C1] ? __pfx_p9_client_rpc (net/9p/client.c:672) [ 50.386878][ C1] ? v9fs_fid_find (fs/9p/fid.c:114) [ 50.387051][ C1] ? do_raw_spin_unlock (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/atomic/atomic-instrumented.h:33 ./include/asm-generic/qspinlock.h:57 kernel/locking/spinlock_debug.c:101 kernel/locking/spinlock_debug.c:141) [ 50.387217][ C1] ? _raw_spin_unlock (./arch/x86/include/asm/preempt.h:94 ./include/linux/spinlock_api_smp.h:143 kernel/locking/spinlock.c:186) [ 50.387493][ C1] ? __pfx_v9fs_fid_find (fs/9p/fid.c:114) [ 50.387661][ C1] ? find_held_lock (kernel/locking/lockdep.c:5244) [ 50.387831][ C1] p9_client_readlink (net/9p/client.c:2238) [ 50.388014][ C1] v9fs_vfs_get_link_dotl (fs/9p/vfs_inode_dotl.c:822 fs/9p/vfs_inode_dotl.c:806) [ 50.388398][ C1] ? __pfx_v9fs_vfs_get_link_dotl (fs/9p/vfs_inode_dotl.c:809) [ 50.388622][ C1] ? try_to_unlazy (fs/namei.c:786) [ 50.388802][ C1] pick_link (fs/namei.c:1806) [ 50.388939][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5406) [ 50.389222][ C1] ? __pfx_v9fs_vfs_get_link_dotl (fs/9p/vfs_inode_dotl.c:809) [ 50.389446][ C1] step_into (fs/namei.c:1874) [ 50.389581][ C1] ? read_word_at_a_time (./include/asm-generic/rwonce.h:86) [ 50.389767][ C1] ? __d_lookup_rcu (./arch/x86/include/asm/word-at-a-time.h:85 fs/dcache.c:226 fs/dcache.c:277 fs/dcache.c:2228) [ 50.389944][ C1] ? __pfx_step_into (fs/namei.c:1839) [ 50.390233][ C1] link_path_walk.part.0.constprop.0 (fs/namei.c:2331) [ 50.390457][ C1] ? __pfx_link_path_walk.part.0.constprop.0 (fs/namei.c:2249) [ 50.390682][ C1] path_openat (fs/namei.c:3795) [ 50.390965][ C1] ? __pfx_path_openat (fs/namei.c:3781) [ 50.391147][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5137) [ 50.391333][ C1] do_filp_open (fs/namei.c:3826) [ 50.391551][ C1] ? __pfx_do_filp_open (fs/namei.c:3820) [ 50.391729][ C1] ? find_held_lock (kernel/locking/lockdep.c:5244) [ 50.392047][ C1] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 50.392226][ C1] ? alloc_fd (fs/file.c:555 (discriminator 10)) [ 50.392361][ C1] ? do_raw_spin_unlock (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/atomic/atomic-instrumented.h:33 ./include/asm-generic/qspinlock.h:57 kernel/locking/spinlock_debug.c:101 kernel/locking/spinlock_debug.c:141) [ 50.392537][ C1] ? _raw_spin_unlock (./arch/x86/include/asm/preempt.h:94 ./include/linux/spinlock_api_smp.h:143 kernel/locking/spinlock.c:186) [ 50.392718][ C1] ? alloc_fd (fs/file.c:555 (discriminator 10)) [ 50.392857][ C1] do_sys_openat2 (fs/open.c:1406) [ 50.393035][ C1] ? vfs_fstatat (fs/stat.c:308) [ 50.393215][ C1] ? __pfx_do_sys_openat2 (fs/open.c:1392) [ 50.393394][ C1] ? __pfx___do_sys_newfstatat (fs/stat.c:464) [ 50.393575][ C1] __x64_sys_openat (fs/open.c:1432) [ 50.393752][ C1] ? __pfx___x64_sys_openat (fs/open.c:1432) [ 50.393928][ C1] ? __pfx_do_faccessat (fs/open.c:465) [ 50.394108][ C1] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 50.394292][ C1] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129) [ 50.394515][ C1] RIP: 0033:0x7f0e4ee790e8 [ 50.394696][ C1] Code: f9 41 89 f0 41 83 e2 40 75 30 89 f0 25 00 00 41 00 3d 00 00 41 00 74 22 44 89 c2 4c 89 ce bf 9c ff ff ff b8 01 01 00 00 0f 05 <48> 3d 00 f0 ff ff 77 30 c3 0f 1f 80 00 00 00 00 48 8d 44 24 08 c7 All code ======== 0: f9 stc 1: 41 89 f0 mov %esi,%r8d 4: 41 83 e2 40 and $0x40,%r10d 8: 75 30 jne 0x3a a: 89 f0 mov %esi,%eax c: 25 00 00 41 00 and $0x410000,%eax 11: 3d 00 00 41 00 cmp $0x410000,%eax 16: 74 22 je 0x3a 18: 44 89 c2 mov %r8d,%edx 1b: 4c 89 ce mov %r9,%rsi 1e: bf 9c ff ff ff mov $0xffffff9c,%edi 23: b8 01 01 00 00 mov $0x101,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 30 ja 0x62 32: c3 ret 33: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 3a: 48 8d 44 24 08 lea 0x8(%rsp),%rax 3f: c7 .byte 0xc7 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 30 ja 0x38 8: c3 ret 9: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 10: 48 8d 44 24 08 lea 0x8(%rsp),%rax 15: c7 .byte 0xc7 [ 50.395435][ C1] RSP: 002b:00007ffe9ab9c2d8 EFLAGS: 00000287 ORIG_RAX: 0000000000000101 [ 50.395702][ C1] RAX: ffffffffffffffda RBX: 00007ffe9ab9c55f RCX: 00007f0e4ee790e8 [ 50.396053][ C1] RDX: 0000000000080000 RSI: 00007ffe9ab9c350 RDI: 00000000ffffff9c [ 50.396294][ C1] RBP: 00007ffe9ab9c340 R08: 0000000000080000 R09: 00007ffe9ab9c350 [ 50.396540][ C1] R10: 0000000000000000 R11: 0000000000000287 R12: 00007ffe9ab9c357 Finger prints: dump_stack_lvl:mark_lock_irq:mark_lock:mark_usage