====================================== | [ 20.935194][ C2] #1: ffffffffb5742e30 (remove_cache_srcu){.+.+}-{0:0}, at: kasan_quarantine_reduce (./include/linux/srcu.h:164 ./include/linux/srcu.h:256 mm/kasan/quarantine.c:259) | [ 20.935606][ C2] #2: ffffc90000238ae8 ((&n->timer)){+.-.}-{0:0}, at: call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1779) | [ 20.935959][ C2] | [ 20.935959][ C2] stack backtrace: [ 20.936223][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 20.936225][ C2] Call Trace: [ 20.936227][ C2] [ 20.936230][ C2] dump_stack_lvl (lib/dump_stack.c:123) [ 20.936239][ C2] lockdep_rcu_suspicious (kernel/locking/lockdep.c:6848) [ 20.936249][ C2] __icmp_send (./include/net/net_namespace.h:404 ./include/linux/netdevice.h:2669 net/ipv4/icmp.c:616) [ 20.936260][ C2] ? __lock_acquire (kernel/locking/lockdep.c:5228) [ 20.936267][ C2] ? __pfx___icmp_send (net/ipv4/icmp.c:596) [ 20.936277][ C2] ? trace_pelt_cfs_tp (./include/trace/events/sched.h:778 (discriminator 21)) [ 20.936287][ C2] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 20.936293][ C2] ? validate_chain (kernel/locking/lockdep.c:3799 kernel/locking/lockdep.c:3819 kernel/locking/lockdep.c:3874) [ 20.936305][ C2] ? __pfx_validate_chain (kernel/locking/lockdep.c:3862) [ 20.936309][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 20.936312][ C2] ? mark_lock (kernel/locking/lockdep.c:4729 (discriminator 3)) [ 20.936315][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 20.936324][ C2] ? __lock_acquire (kernel/locking/lockdep.c:5228) [ 20.936333][ C2] ipv4_send_dest_unreach (net/ipv4/route.c:1241) [ 20.936339][ C2] ? neigh_invalidate (net/core/neighbour.c:1008) [ 20.936345][ C2] ? __pfx_ipv4_send_dest_unreach (net/ipv4/route.c:1215) [ 20.936358][ C2] ipv4_link_failure (./include/linux/skbuff.h:1152 ./include/net/route.h:88 net/ipv4/route.c:1250) [ 20.936363][ C2] arp_error_report (./include/net/dst.h:429 net/ipv4/arp.c:296) [ 20.936370][ C2] neigh_invalidate (net/core/neighbour.c:1008) [ 20.936379][ C2] neigh_timer_handler (net/core/neighbour.c:1109 (discriminator 2)) [ 20.936389][ C2] ? __pfx_neigh_timer_handler (net/core/neighbour.c:1032) [ 20.936392][ C2] call_timer_fn (kernel/time/timer.c:1789) [ 20.936395][ C2] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1779) [ 20.936398][ C2] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1779) [ 20.936402][ C2] ? __pfx_call_timer_fn (kernel/time/timer.c:1766) [ 20.936406][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 20.936413][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4323) [ 20.936425][ C2] __run_timers (kernel/time/timer.c:1841 kernel/time/timer.c:2414) [ 20.936428][ C2] ? __pfx_neigh_timer_handler (net/core/neighbour.c:1032) [ 20.936439][ C2] ? __pfx___run_timers (kernel/time/timer.c:2385) [ 20.936442][ C2] ? __lock_release (kernel/locking/lockdep.c:5527) [ 20.936450][ C2] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 20.936456][ C2] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 20.936461][ C2] ? lock_acquire (kernel/locking/lockdep.c:5824) [ 20.936463][ C2] ? timer_expire_remote (kernel/time/timer.c:2426 kernel/time/timer.c:2418 kernel/time/timer.c:2177) [ 20.936474][ C2] timer_expire_remote (kernel/time/timer.c:2427 kernel/time/timer.c:2418 kernel/time/timer.c:2177) [ 20.936478][ C2] tmigr_handle_remote_cpu (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:87 ./arch/x86/include/asm/irqflags.h:147 kernel/time/timer_migration.c:961) [ 20.936486][ C2] ? __pfx_tmigr_handle_remote_cpu (kernel/time/timer_migration.c:905) [ 20.936489][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 20.936494][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 20.936497][ C2] ? mark_lock (kernel/locking/lockdep.c:4729 (discriminator 3)) [ 20.936503][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4323) [ 20.936514][ C2] tmigr_handle_remote_up (kernel/time/timer_migration.c:1038) [ 20.936520][ C2] ? __pfx_tmigr_handle_remote_up (kernel/time/timer_migration.c:1005) [ 20.936525][ C2] __walk_groups.isra.0 (kernel/time/timer_migration.c:533) [ 20.936536][ C2] tmigr_handle_remote (kernel/time/timer_migration.c:1096) [ 20.936540][ C2] ? __pfx_tmigr_handle_remote (kernel/time/timer_migration.c:1059) [ 20.936545][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 20.936552][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4323) [ 20.936562][ C2] handle_softirqs (kernel/softirq.c:561) [ 20.936576][ C2] __irq_exit_rcu (kernel/softirq.c:596 kernel/softirq.c:435 kernel/softirq.c:662) [ 20.936579][ C2] irq_exit_rcu (kernel/softirq.c:680) [ 20.936582][ C2] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1049 arch/x86/kernel/apic/apic.c:1049) [ 20.936587][ C2] [ 20.936588][ C2] [ 20.936591][ C2] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 20.936596][ C2] RIP: 0010:_raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) [ 20.936602][ C2] Code: 10 e8 81 74 88 fd 48 89 ef e8 c9 e4 88 fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d 75 7d b0 4b <74> 0e 5b 5d c3 cc cc cc cc e8 8f 03 ae fd eb dc 0f 1f 44 00 00 5b All code ======== 0: 10 e8 adc %ch,%al 2: 81 74 88 fd 48 89 ef xorl $0xe8ef8948,-0x3(%rax,%rcx,4) 9: e8 a: c9 leave b: e4 88 in $0x88,%al d: fd std e: 81 e3 00 02 00 00 and $0x200,%ebx 14: 75 1d jne 0x33 16: 9c pushf 17: 58 pop %rax 18: f6 c4 02 test $0x2,%ah 1b: 75 29 jne 0x46 1d: 48 85 db test %rbx,%rbx 20: 74 01 je 0x23 22: fb sti 23: 65 ff 0d 75 7d b0 4b decl %gs:0x4bb07d75(%rip) # 0x4bb07d9f 2a:* 74 0e je 0x3a <-- trapping instruction 2c: 5b pop %rbx 2d: 5d pop %rbp 2e: c3 ret 2f: cc int3 30: cc int3 31: cc int3 32: cc int3 33: e8 8f 03 ae fd call 0xfffffffffdae03c7 38: eb dc jmp 0x16 3a: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 3f: 5b pop %rbx Code starting with the faulting instruction =========================================== 0: 74 0e je 0x10 2: 5b pop %rbx 3: 5d pop %rbp 4: c3 ret 5: cc int3 6: cc int3 7: cc int3 8: cc int3 9: e8 8f 03 ae fd call 0xfffffffffdae039d e: eb dc jmp 0xffffffffffffffec 10: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 15: 5b pop %rbx [ 20.936605][ C2] RSP: 0018:ffffc900006e78c8 EFLAGS: 00000286 [ 20.936608][ C2] RAX: 0000000000000002 RBX: 0000000000000200 RCX: 1ffffffff6ec64c3 [ 20.936610][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffb4534761 [ 20.936612][ C2] RBP: ffff88800192d080 R08: 0000000000000001 R09: fffffbfff6ec43e5 [ 20.936615][ C2] R10: ffffffffb7621f2f R11: ffff8880101f8040 R12: ffff88800c48ed48 [ 20.936616][ C2] R13: 0000000000000000 R14: ffffc900006e7918 R15: ffff88800c4bcda8 [ 20.936628][ C2] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 20.936636][ C2] qlist_free_all (mm/kasan/quarantine.c:174) [ 20.936643][ C2] kasan_quarantine_reduce (./include/linux/srcu.h:357 mm/kasan/quarantine.c:287) [ 20.936650][ C2] __kasan_slab_alloc (mm/kasan/common.c:329) [ 20.936658][ C2] kmem_cache_alloc_noprof (./include/linux/kasan.h:250 mm/slub.c:4115 mm/slub.c:4164 mm/slub.c:4171) [ 20.936665][ C2] ? vma_merge_new_range (mm/vma.c:987 (discriminator 1)) [ 20.936675][ C2] vm_area_alloc (kernel/fork.c:472) [ 20.936680][ C2] __mmap_region (mm/vma.c:2342 mm/vma.c:2457) [ 20.936689][ C2] ? __pfx___mmap_region (mm/vma.c:2437) [ 20.936692][ C2] ? find_held_lock (kernel/locking/lockdep.c:5341) [ 20.936701][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 20.936716][ C2] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 20.936719][ C2] ? validate_chain (kernel/locking/lockdep.c:3799 kernel/locking/lockdep.c:3819 kernel/locking/lockdep.c:3874) [ 20.936762][ C2] ? mmap_region (./arch/x86/include/asm/bitops.h:206 ./arch/x86/include/asm/bitops.h:238 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 ./include/linux/mman.h:204 mm/vma.c:2519) [ 20.936772][ C2] do_mmap (mm/mmap.c:561) [ 20.936783][ C2] ? __pfx_do_mmap (mm/mmap.c:342) [ 20.936786][ C2] ? down_write_killable (./arch/x86/include/asm/atomic64_64.h:20 ./include/linux/atomic/atomic-arch-fallback.h:2629 ./include/linux/atomic/atomic-long.h:79 ./include/linux/atomic/atomic-instrumented.h:3224 kernel/locking/rwsem.c:143 kernel/locking/rwsem.c:268 kernel/locking/rwsem.c:1303 kernel/locking/rwsem.c:1318 kernel/locking/rwsem.c:1590) [ 20.936791][ C2] ? __pfx_down_write_killable (kernel/locking/rwsem.c:1586) [ 20.936796][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 20.936804][ C2] vm_mmap_pgoff (mm/util.c:575) [ 20.936817][ C2] ? __pfx_vm_mmap_pgoff (mm/util.c:565) [ 20.936823][ C2] ? do_user_addr_fault (./include/linux/mmap_lock.h:218 arch/x86/mm/fault.c:1417) [ 20.936838][ C2] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 20.936845][ C2] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 20.936848][ C2] RIP: 0033:0x7f8a26781116 [ 20.936853][ C2] Code: 5d 41 5c c3 f3 0f 1e fa 41 f7 c1 ff 0f 00 00 75 2b 55 48 89 fd 53 89 cb 48 85 ff 74 37 41 89 da 48 89 ef b8 09 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 62 5b 5d c3 0f 1f 80 00 00 00 00 c7 05 ae f0 All code ======== 0: 5d pop %rbp 1: 41 5c pop %r12 3: c3 ret 4: f3 0f 1e fa endbr64 8: 41 f7 c1 ff 0f 00 00 test $0xfff,%r9d f: 75 2b jne 0x3c 11: 55 push %rbp 12: 48 89 fd mov %rdi,%rbp 15: 53 push %rbx 16: 89 cb mov %ecx,%ebx 18: 48 85 ff test %rdi,%rdi 1b: 74 37 je 0x54 1d: 41 89 da mov %ebx,%r10d 20: 48 89 ef mov %rbp,%rdi 23: b8 09 00 00 00 mov $0x9,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 62 ja 0x94 32: 5b pop %rbx 33: 5d pop %rbp 34: c3 ret 35: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 3c: c7 .byte 0xc7 3d: 05 .byte 0x5 3e: ae scas %es:(%rdi),%al 3f: f0 lock Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 62 ja 0x6a 8: 5b pop %rbx 9: 5d pop %rbp a: c3 ret b: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 12: c7 .byte 0xc7 13: 05 .byte 0x5 14: ae scas %es:(%rdi),%al 15: f0 lock [ 20.936856][ C2] RSP: 002b:00007ffe62838778 EFLAGS: 00000206 ORIG_RAX: 0000000000000009 [ 20.936859][ C2] RAX: ffffffffffffffda RBX: 0000000000000032 RCX: 00007f8a26781116 [ 20.936861][ C2] RDX: 0000000000000003 RSI: 000000000000cf90 RDI: 00007f8a26682000 [ 20.936863][ C2] RBP: 00007f8a26682000 R08: 00000000ffffffff R09: 0000000000000000 [ 20.936864][ C2] R10: 0000000000000032 R11: 0000000000000206 R12: 00007ffe62838820 Finger prints: lockdep_rcu_suspicious:__icmp_send:ipv4_send_dest_unreach:ipv4_link_failure:arp_error_report