====================================== | [ 476.736255][ C1] #0: ffffffff9ff42e30 (remove_cache_srcu){.+.+}-{0:0}, at: kasan_quarantine_reduce (./include/linux/srcu.h:164 ./include/linux/srcu.h:256 mm/kasan/quarantine.c:259) | [ 476.736686][ C1] #1: ffffc900001e0ae8 ((&n->timer)){+.-.}-{0:0}, at: call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1779) | [ 476.737053][ C1] | [ 476.737053][ C1] stack backtrace: [ 476.737362][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 476.737365][ C1] Call Trace: [ 476.737367][ C1] [ 476.737370][ C1] dump_stack_lvl (lib/dump_stack.c:123) [ 476.737379][ C1] lockdep_rcu_suspicious (kernel/locking/lockdep.c:6848) [ 476.737390][ C1] icmp6_send (./include/net/net_namespace.h:404 ./include/linux/netdevice.h:2669 net/ipv6/icmp.c:476) [ 476.737398][ C1] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 476.737404][ C1] ? validate_chain (kernel/locking/lockdep.c:3799 kernel/locking/lockdep.c:3819 kernel/locking/lockdep.c:3874) [ 476.737410][ C1] ? __pfx_validate_chain (kernel/locking/lockdep.c:3862) [ 476.737421][ C1] ? __pfx_icmp6_send (net/ipv6/icmp.c:452) [ 476.737430][ C1] ? __pfx_validate_chain (kernel/locking/lockdep.c:3862) [ 476.737434][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 476.737437][ C1] ? mark_lock (kernel/locking/lockdep.c:4729 (discriminator 3)) [ 476.737447][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5228) [ 476.737453][ C1] ? find_held_lock (kernel/locking/lockdep.c:5341) [ 476.737459][ C1] ? __lock_release (kernel/locking/lockdep.c:5527) [ 476.737462][ C1] ? neigh_invalidate (net/core/neighbour.c:1008) [ 476.737468][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 476.737471][ C1] ? lock_acquire.part.0 (kernel/locking/lockdep.c:469 kernel/locking/lockdep.c:5853) [ 476.737482][ C1] ip6_link_failure (./include/linux/skbuff.h:1152 net/ipv6/route.c:2801) [ 476.737491][ C1] ndisc_error_report (./include/net/dst.h:429 net/ipv6/ndisc.c:731) [ 476.737498][ C1] neigh_invalidate (net/core/neighbour.c:1008) [ 476.737507][ C1] neigh_timer_handler (net/core/neighbour.c:1109 (discriminator 2)) [ 476.737517][ C1] ? __pfx_neigh_timer_handler (net/core/neighbour.c:1032) [ 476.737522][ C1] call_timer_fn (kernel/time/timer.c:1789) [ 476.737526][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1779) [ 476.737529][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1779) [ 476.737533][ C1] ? __pfx_call_timer_fn (kernel/time/timer.c:1766) [ 476.737536][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 476.737543][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4323) [ 476.737554][ C1] __run_timers (kernel/time/timer.c:1841 kernel/time/timer.c:2414) [ 476.737558][ C1] ? __pfx_neigh_timer_handler (net/core/neighbour.c:1032) [ 476.737568][ C1] ? __pfx___run_timers (kernel/time/timer.c:2385) [ 476.737570][ C1] ? __lock_release (kernel/locking/lockdep.c:5527) [ 476.737578][ C1] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 476.737584][ C1] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 476.737588][ C1] ? lock_acquire (kernel/locking/lockdep.c:5824) [ 476.737591][ C1] ? timer_expire_remote (kernel/time/timer.c:2426 kernel/time/timer.c:2418 kernel/time/timer.c:2177) [ 476.737601][ C1] timer_expire_remote (kernel/time/timer.c:2427 kernel/time/timer.c:2418 kernel/time/timer.c:2177) [ 476.737605][ C1] tmigr_handle_remote_cpu (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:87 ./arch/x86/include/asm/irqflags.h:147 kernel/time/timer_migration.c:961) [ 476.737612][ C1] ? __pfx_tmigr_handle_remote_cpu (kernel/time/timer_migration.c:905) [ 476.737615][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 476.737620][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 476.737622][ C1] ? mark_lock (kernel/locking/lockdep.c:4729 (discriminator 3)) [ 476.737629][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4323) [ 476.737640][ C1] tmigr_handle_remote_up (kernel/time/timer_migration.c:1038) [ 476.737645][ C1] ? __pfx_tmigr_handle_remote_up (kernel/time/timer_migration.c:1005) [ 476.737650][ C1] __walk_groups.isra.0 (kernel/time/timer_migration.c:533) [ 476.737660][ C1] tmigr_handle_remote (kernel/time/timer_migration.c:1096) [ 476.737664][ C1] ? __pfx_tmigr_handle_remote (kernel/time/timer_migration.c:1059) [ 476.737669][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:230) [ 476.737676][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4323) [ 476.737685][ C1] handle_softirqs (kernel/softirq.c:561) [ 476.737698][ C1] __irq_exit_rcu (kernel/softirq.c:596 kernel/softirq.c:435 kernel/softirq.c:662) [ 476.737701][ C1] irq_exit_rcu (kernel/softirq.c:680) [ 476.737704][ C1] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1049 arch/x86/kernel/apic/apic.c:1049) [ 476.737710][ C1] [ 476.737711][ C1] [ 476.737713][ C1] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 476.737718][ C1] RIP: 0010:_raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) [ 476.737724][ C1] Code: 10 e8 81 74 88 fd 48 89 ef e8 c9 e4 88 fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d 75 7d 30 61 <74> 0e 5b 5d c3 cc cc cc cc e8 8f 03 ae fd eb dc 0f 1f 44 00 00 5b All code ======== 0: 10 e8 adc %ch,%al 2: 81 74 88 fd 48 89 ef xorl $0xe8ef8948,-0x3(%rax,%rcx,4) 9: e8 a: c9 leave b: e4 88 in $0x88,%al d: fd std e: 81 e3 00 02 00 00 and $0x200,%ebx 14: 75 1d jne 0x33 16: 9c pushf 17: 58 pop %rax 18: f6 c4 02 test $0x2,%ah 1b: 75 29 jne 0x46 1d: 48 85 db test %rbx,%rbx 20: 74 01 je 0x23 22: fb sti 23: 65 ff 0d 75 7d 30 61 decl %gs:0x61307d75(%rip) # 0x61307d9f 2a:* 74 0e je 0x3a <-- trapping instruction 2c: 5b pop %rbx 2d: 5d pop %rbp 2e: c3 ret 2f: cc int3 30: cc int3 31: cc int3 32: cc int3 33: e8 8f 03 ae fd call 0xfffffffffdae03c7 38: eb dc jmp 0x16 3a: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 3f: 5b pop %rbx Code starting with the faulting instruction =========================================== 0: 74 0e je 0x10 2: 5b pop %rbx 3: 5d pop %rbp 4: c3 ret 5: cc int3 6: cc int3 7: cc int3 8: cc int3 9: e8 8f 03 ae fd call 0xfffffffffdae039d e: eb dc jmp 0xffffffffffffffec 10: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 15: 5b pop %rbx [ 476.737727][ C1] RSP: 0018:ffffc90001b77608 EFLAGS: 00000246 [ 476.737730][ C1] RAX: 0000000000000006 RBX: 0000000000000200 RCX: 1ffffffff43c64c3 [ 476.737732][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff9ed34761 [ 476.737734][ C1] RBP: ffff888001040e00 R08: 0000000000000001 R09: fffffbfff43c43e5 [ 476.737735][ C1] R10: ffffffffa1e21f2f R11: ffff88800a96c5c0 R12: ffff88800a11b380 [ 476.737737][ C1] R13: 0000000000000000 R14: ffffc90001b77658 R15: ffff88800b909464 [ 476.737748][ C1] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 476.737756][ C1] qlist_free_all (mm/kasan/quarantine.c:174) [ 476.737766][ C1] kasan_quarantine_reduce (./include/linux/srcu.h:357 mm/kasan/quarantine.c:287) [ 476.737772][ C1] __kasan_slab_alloc (mm/kasan/common.c:329) [ 476.737780][ C1] kmem_cache_alloc_node_noprof (mm/slub.c:4116 mm/slub.c:4164 mm/slub.c:4216) [ 476.737793][ C1] __alloc_skb (net/core/skbuff.c:668) [ 476.737801][ C1] ? __pfx___alloc_skb (net/core/skbuff.c:651) [ 476.737804][ C1] ? ipv6_dev_get_saddr (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 net/ipv6/addrconf.c:1900) [ 476.737809][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 476.737829][ C1] alloc_skb_with_frags (./include/linux/skbuff.h:1331 net/core/skbuff.c:6612) [ 476.737837][ C1] ? ipv6_dev_get_saddr (net/ipv6/addrconf.c:1809) [ 476.737845][ C1] sock_alloc_send_pskb (net/core/sock.c:2899) [ 476.737850][ C1] ? __pfx_validate_chain (kernel/locking/lockdep.c:3862) [ 476.737864][ C1] ? __pfx_sock_alloc_send_pskb (net/core/sock.c:2870) [ 476.737874][ C1] ? __pfx_xfrm_lookup_with_ifid (net/xfrm/xfrm_policy.c:3174) [ 476.737883][ C1] ? find_held_lock (kernel/locking/lockdep.c:5341) [ 476.737890][ C1] rawv6_send_hdrinc (./include/net/sock.h:1804 net/ipv6/raw.c:614) [ 476.737903][ C1] ? __pfx_rawv6_send_hdrinc (net/ipv6/raw.c:596) [ 476.737909][ C1] ? ip6_dst_hoplimit.part.0.isra.0 (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 net/ipv6/output_core.c:117) [ 476.737921][ C1] rawv6_sendmsg (net/ipv6/raw.c:915) [ 476.737930][ C1] ? trace_raw_output_lock (./include/trace/events/lock.h:50 (discriminator 2)) [ 476.737938][ C1] ? __pfx_rawv6_sendmsg (net/ipv6/raw.c:741) [ 476.737944][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5228) [ 476.737955][ C1] ? __pfx_validate_chain (kernel/locking/lockdep.c:3862) [ 476.737963][ C1] ? find_held_lock (kernel/locking/lockdep.c:5341) [ 476.737969][ C1] ? __lock_release (kernel/locking/lockdep.c:5527) [ 476.737972][ C1] ? __might_fault (mm/memory.c:6840 mm/memory.c:6833) [ 476.737987][ C1] ? __might_fault (mm/memory.c:6840 mm/memory.c:6833) [ 476.737992][ C1] ? __might_fault (mm/memory.c:6840 mm/memory.c:6833) [ 476.738002][ C1] ? __sys_sendto (net/socket.c:713 net/socket.c:728 net/socket.c:2182) [ 476.738008][ C1] __sys_sendto (net/socket.c:713 net/socket.c:728 net/socket.c:2182) [ 476.738013][ C1] ? __pfx___sys_sendto (net/socket.c:2149) [ 476.738016][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5503) [ 476.738019][ C1] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 21)) [ 476.738032][ C1] ? rseq_update_cpu_node_id (kernel/rseq.c:188 (discriminator 10)) [ 476.738045][ C1] ? __pfx___rseq_handle_notify_resume (kernel/rseq.c:403) [ 476.738061][ C1] __x64_sys_sendto (net/socket.c:2185) [ 476.738065][ C1] ? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4349 kernel/locking/lockdep.c:4408) [ 476.738070][ C1] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 476.738079][ C1] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 476.738082][ C1] RIP: 0033:0x7f1880e0da4a [ 476.738088][ C1] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89 All code ======== 0: d8 64 89 02 fsubs 0x2(%rcx,%rcx,4) 4: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax b: eb b8 jmp 0xffffffffffffffc5 d: 0f 1f 00 nopl (%rax) 10: f3 0f 1e fa endbr64 14: 41 89 ca mov %ecx,%r10d 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 15 jne 0x38 23: b8 2c 00 00 00 mov $0x2c,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 7e ja 0xb0 32: c3 ret 33: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 38: 41 54 push %r12 3a: 48 83 ec 30 sub $0x30,%rsp 3e: 44 rex.R 3f: 89 .byte 0x89 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 7e ja 0x86 8: c3 ret 9: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) e: 41 54 push %r12 10: 48 83 ec 30 sub $0x30,%rsp 14: 44 rex.R 15: 89 .byte 0x89 [ 476.738090][ C1] RSP: 002b:00007ffc368fa658 EFLAGS: 00000246 ORIG_RAX: 000000000000002c [ 476.738093][ C1] RAX: ffffffffffffffda RBX: 0000000002d899d0 RCX: 00007f1880e0da4a [ 476.738095][ C1] RDX: 0000000000000070 RSI: 0000000002d89c70 RDI: 0000000000000005 [ 476.738096][ C1] RBP: 0000000002d899d0 R08: 00007ffc368fa660 R09: 000000000000001c [ 476.738098][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000070 Finger prints: lockdep_rcu_suspicious:icmp6_send:ip6_link_failure:ndisc_error_report:neigh_invalidate