====================================== | [ 27.810534][ T268] veth3: entered allmulticast mode | [ 27.813973][ T268] veth3: entered promiscuous mode | [ 27.959075][ C2] BUG: spinlock bad magic on CPU#2, ip/269 | [ 27.959350][ C2] lock: noop_qdisc+0x240/0x300, .magic: 00000000, .owner: ip/269, .owner_cpu: 2 [ 27.959849][ C2] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 27.960190][ C2] Call Trace: [ 27.960306][ C2] [ 27.960382][ C2] dump_stack_lvl (lib/dump_stack.c:122) [ 27.960535][ C2] do_raw_spin_unlock (kernel/locking/spinlock_debug.c:100 kernel/locking/spinlock_debug.c:141) [ 27.960686][ C2] _raw_spin_unlock (./arch/x86/include/asm/preempt.h:94 ./include/linux/spinlock_api_smp.h:143 kernel/locking/spinlock.c:186) [ 27.960838][ C2] __dev_xmit_skb (./include/net/sch_generic.h:226 ./include/net/sch_generic.h:217 net/core/dev.c:3879) [ 27.960995][ C2] ? __pfx___dev_xmit_skb (net/core/dev.c:3784) [ 27.961152][ C2] ? __dev_queue_xmit (./include/linux/bottom_half.h:20 ./include/linux/rcupdate.h:890 net/core/dev.c:4348) [ 27.961304][ C2] ? lock_acquire (kernel/locking/lockdep.c:5732) [ 27.961459][ C2] ? __dev_queue_xmit (./include/linux/bottom_half.h:20 ./include/linux/rcupdate.h:890 net/core/dev.c:4348) [ 27.961607][ C2] __dev_queue_xmit (net/core/dev.c:4389) [ 27.961755][ C2] ? __lock_release (kernel/locking/lockdep.c:5435) [ 27.961902][ C2] ? ip_finish_output2 (./include/net/neighbour.h:542 net/ipv4/ip_output.c:235) [ 27.962050][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5411) [ 27.962195][ C2] ? __pfx___dev_queue_xmit (net/core/dev.c:4332) [ 27.962341][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4273) [ 27.962488][ C2] ? eth_header (net/ethernet/eth.c:100) [ 27.962641][ C2] ? neigh_resolve_output (./include/linux/netdevice.h:3159 net/core/neighbour.c:1560 net/core/neighbour.c:1545) [ 27.962790][ C2] ip_finish_output2 (./include/net/neighbour.h:542 net/ipv4/ip_output.c:235) [ 27.962936][ C2] ? find_held_lock (kernel/locking/lockdep.c:5249) [ 27.963083][ C2] ? __pfx_ip_finish_output2 (net/ipv4/ip_output.c:199) [ 27.963230][ C2] ? igmpv3_send_cr (./include/linux/rcupdate.h:336 ./include/linux/rcupdate.h:869 net/ipv4/igmp.c:719) [ 27.963380][ C2] ? __ip_finish_output (./include/linux/skbuff.h:1666 ./include/linux/skbuff.h:4954 net/ipv4/ip_output.c:307 net/ipv4/ip_output.c:295) [ 27.963527][ C2] ip_output (./include/linux/netfilter.h:303 net/ipv4/ip_output.c:433) [ 27.963639][ C2] ? __pfx_ip_output (net/ipv4/ip_output.c:427) [ 27.963795][ C2] ? igmpv3_send_cr (net/ipv4/igmp.c:721) [ 27.963948][ C2] ? ip_local_out (net/ipv4/ip_output.c:128) [ 27.964098][ C2] igmp_ifc_timer_expire (net/ipv4/igmp.c:815) [ 27.964246][ C2] ? __pfx_igmp_ifc_timer_expire (net/ipv4/igmp.c:809) [ 27.964428][ C2] call_timer_fn (kernel/time/timer.c:1792) [ 27.964575][ C2] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1782) [ 27.964721][ C2] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1782) [ 27.964873][ C2] ? __pfx_call_timer_fn (kernel/time/timer.c:1769) [ 27.965022][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:227) [ 27.965178][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4273) [ 27.965332][ C2] __run_timers (kernel/time/timer.c:1844 kernel/time/timer.c:2417) [ 27.965484][ C2] ? __pfx_igmp_ifc_timer_expire (net/ipv4/igmp.c:809) [ 27.965670][ C2] ? __pfx___run_timers (kernel/time/timer.c:2388) [ 27.965818][ C2] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 27.965970][ C2] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 27.966117][ C2] ? lock_acquire (kernel/locking/lockdep.c:5732) [ 27.966276][ C2] ? run_timer_softirq (kernel/time/timer.c:2428 kernel/time/timer.c:2421 kernel/time/timer.c:2437 kernel/time/timer.c:2447) [ 27.966428][ C2] run_timer_softirq (kernel/time/timer.c:2429 kernel/time/timer.c:2421 kernel/time/timer.c:2437 kernel/time/timer.c:2447) [ 27.966579][ C2] handle_softirqs (kernel/softirq.c:554) [ 27.966729][ C2] irq_exit_rcu (kernel/softirq.c:589 kernel/softirq.c:428 kernel/softirq.c:637 kernel/softirq.c:649) [ 27.966840][ C2] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1043 arch/x86/kernel/apic/apic.c:1043) [ 27.966994][ C2] [ 27.967074][ C2] [ 27.967149][ C2] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 27.967350][ C2] RIP: 0010:_raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) [ 27.967540][ C2] Code: 10 e8 b1 39 8e fd 48 89 ef e8 59 aa 8e fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d b5 80 02 68 <74> 0e 5b 5d c3 cc cc cc cc e8 7f 77 b2 fd eb dc 0f 1f 44 00 00 5b All code ======== 0: 10 e8 adc %ch,%al 2: b1 39 mov $0x39,%cl 4: 8e fd mov %ebp,%? 6: 48 89 ef mov %rbp,%rdi 9: e8 59 aa 8e fd call 0xfffffffffd8eaa67 e: 81 e3 00 02 00 00 and $0x200,%ebx 14: 75 1d jne 0x33 16: 9c pushf 17: 58 pop %rax 18: f6 c4 02 test $0x2,%ah 1b: 75 29 jne 0x46 1d: 48 85 db test %rbx,%rbx 20: 74 01 je 0x23 22: fb sti 23: 65 ff 0d b5 80 02 68 decl %gs:0x680280b5(%rip) # 0x680280df 2a:* 74 0e je 0x3a <-- trapping instruction 2c: 5b pop %rbx 2d: 5d pop %rbp 2e: c3 ret 2f: cc int3 30: cc int3 31: cc int3 32: cc int3 33: e8 7f 77 b2 fd call 0xfffffffffdb277b7 38: eb dc jmp 0x16 3a: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 3f: 5b pop %rbx Code starting with the faulting instruction =========================================== 0: 74 0e je 0x10 2: 5b pop %rbx 3: 5d pop %rbp 4: c3 ret 5: cc int3 6: cc int3 7: cc int3 8: cc int3 9: e8 7f 77 b2 fd call 0xfffffffffdb2778d e: eb dc jmp 0xffffffffffffffec 10: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 15: 5b pop %rbx [ 27.968097][ C2] RSP: 0018:ffffc900005bf5a8 EFLAGS: 00000286 [ 27.968286][ C2] RAX: 0000000000000002 RBX: 0000000000000200 RCX: 1ffffffff36741df [ 27.968520][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff98014821 [ 27.968787][ C2] RBP: ffff8880032bfe40 R08: 0000000000000001 R09: fffffbfff3672101 [ 27.969041][ C2] R10: ffffffff9b39080f R11: ffffc900005bf3d9 R12: ffff888007a00940 [ 27.969282][ C2] R13: 0000000000000000 R14: ffffc900005bf5f8 R15: ffff8880033563d8 [ 27.969527][ C2] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 27.969722][ C2] qlist_free_all (mm/kasan/quarantine.c:174) [ 27.969896][ C2] kasan_quarantine_reduce (./include/linux/srcu.h:320 mm/kasan/quarantine.c:287) [ 27.970057][ C2] __kasan_slab_alloc (mm/kasan/common.c:322) [ 27.970227][ C2] kmem_cache_alloc_node_noprof (mm/slub.c:3989 mm/slub.c:4037 mm/slub.c:4080) [ 27.970442][ C2] __alloc_skb (net/core/skbuff.c:664) [ 27.970607][ C2] ? __pfx___alloc_skb (net/core/skbuff.c:647) [ 27.970776][ C2] ? rtnetlink_rcv_msg (net/core/rtnetlink.c:6652) [ 27.970940][ C2] netlink_ack (./include/linux/skbuff.h:1320 ./include/net/netlink.h:1015 net/netlink/af_netlink.c:2487) [ 27.971113][ C2] netlink_rcv_skb (net/netlink/af_netlink.c:2556) [ 27.971277][ C2] ? __pfx_rtnetlink_rcv_msg (net/core/rtnetlink.c:6541) [ 27.971443][ C2] ? __pfx_netlink_rcv_skb (net/netlink/af_netlink.c:2527) [ 27.971621][ C2] ? netlink_deliver_tap (./include/linux/rcupdate.h:336 ./include/linux/rcupdate.h:869 net/netlink/af_netlink.c:340) [ 27.971778][ C2] ? netlink_deliver_tap (./include/linux/rcupdate.h:336 ./include/linux/rcupdate.h:869 ./include/net/netns/generic.h:48 net/netlink/af_netlink.c:333) [ 27.971940][ C2] netlink_unicast (net/netlink/af_netlink.c:1331 net/netlink/af_netlink.c:1357) [ 27.972107][ C2] ? __pfx_netlink_unicast (net/netlink/af_netlink.c:1342) [ 27.972268][ C2] ? find_held_lock (kernel/locking/lockdep.c:5249) [ 27.972431][ C2] netlink_sendmsg (net/netlink/af_netlink.c:1901) [ 27.972597][ C2] ? __pfx_netlink_sendmsg (net/netlink/af_netlink.c:1820) [ 27.972755][ C2] ? __might_fault (mm/memory.c:6388 mm/memory.c:6381) [ 27.972922][ C2] ? __import_iovec (lib/iov_iter.c:1263 lib/iov_iter.c:1279) [ 27.973088][ C2] ____sys_sendmsg (net/socket.c:730 net/socket.c:745 net/socket.c:2597) [ 27.973251][ C2] ? __pfx_____sys_sendmsg (net/socket.c:2543) [ 27.973410][ C2] ? __pfx_copy_msghdr_from_user (net/socket.c:2523) [ 27.973615][ C2] ? __pfx_validate_chain (kernel/locking/lockdep.c:3824) [ 27.973781][ C2] ___sys_sendmsg (net/socket.c:2653) [ 27.973945][ C2] ? __pfx____sys_sendmsg (net/socket.c:2640) [ 27.974107][ C2] ? find_held_lock (kernel/locking/lockdep.c:5249) [ 27.974282][ C2] ? __lock_release (kernel/locking/lockdep.c:5435) [ 27.974441][ C2] ? __debug_check_no_obj_freed (lib/debugobjects.c:1001) [ 27.974651][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5411) [ 27.974813][ C2] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 27.975002][ C2] ? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4299 kernel/locking/lockdep.c:4358) [ 27.975185][ C2] ? __fget_light (./include/linux/atomic/atomic-arch-fallback.h:479 ./include/linux/atomic/atomic-instrumented.h:50 fs/file.c:1145) [ 27.975376][ C2] __sys_sendmsg (./include/linux/file.h:34 net/socket.c:2682) [ 27.975536][ C2] ? __pfx___sys_sendmsg (net/socket.c:2668) [ 27.975703][ C2] ? __virt_addr_valid (./arch/x86/include/asm/preempt.h:94 ./include/linux/rcupdate.h:953 ./include/linux/mmzone.h:2034 arch/x86/mm/physaddr.c:65) [ 27.975878][ C2] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 27.976042][ C2] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 27.976249][ C2] RIP: 0033:0x7fd7195417b7 [ 27.976430][ C2] Code: 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 All code ======== 0: 0a 00 or (%rax),%al 2: f7 d8 neg %eax 4: 64 89 02 mov %eax,%fs:(%rdx) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b9 jmp 0xffffffffffffffc9 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 2e 00 00 00 mov $0x2e,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 89 54 24 1c mov %edx,0x1c(%rsp) 3b: 48 89 74 24 10 mov %rsi,0x10(%rsp) Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 89 54 24 1c mov %edx,0x1c(%rsp) 11: 48 89 74 24 10 mov %rsi,0x10(%rsp) [ 27.977027][ C2] RSP: 002b:00007fff68d2d6d8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 27.977272][ C2] RAX: ffffffffffffffda RBX: 00007fff68d2de00 RCX: 00007fd7195417b7 [ 27.977520][ C2] RDX: 0000000000000000 RSI: 00007fff68d2d740 RDI: 0000000000000005 [ 27.977758][ C2] RBP: 0000000000000003 R08: 0000000000000003 R09: 0000000000000078 [ 27.978000][ C2] R10: 00007fd7193ffef8 R11: 0000000000000246 R12: 0000000000000003 Finger prints: do_raw_spin_unlock:_raw_spin_unlock:__dev_xmit_skb:__dev_queue_xmit:ip_finish_output2