====================================== | [ 1085.777504] #7: ffffffff9c9678c0 (rcu_read_lock){....}-{1:2}, at: netif_receive_skb (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5729 net/core/dev.c:5801) | [ 1085.777959] #8: ffffffff9c9678c0 (rcu_read_lock){....}-{1:2}, at: ip_local_deliver_finish (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/ipv4/ip_input.c:232) | [ 1085.778435] | [ 1085.778435] stack backtrace: [ 1085.779022] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 1085.779618] Call Trace: [ 1085.779756] [ 1085.779873] dump_stack_lvl (lib/dump_stack.c:108) [ 1085.780076] __lock_acquire (kernel/locking/lockdep.c:5138) [ 1085.780295] ? sk_filter_trim_cap (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/filter.c:151) [ 1085.780529] lock_acquire (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756 kernel/locking/lockdep.c:5719) [ 1085.780722] ? tcp_v4_rcv (./include/linux/skbuff.h:1624 ./include/net/tcp.h:2510 net/ipv4/tcp_ipv4.c:2326) [ 1085.780923] ? sk_filter_trim_cap (net/core/filter.c:165) [ 1085.781159] _raw_spin_lock_nested (kernel/locking/spinlock.c:379) [ 1085.781394] ? tcp_v4_rcv (./include/linux/skbuff.h:1624 ./include/net/tcp.h:2510 net/ipv4/tcp_ipv4.c:2326) [ 1085.781590] tcp_v4_rcv (./include/linux/skbuff.h:1624 ./include/net/tcp.h:2510 net/ipv4/tcp_ipv4.c:2326) [ 1085.781780] ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205 (discriminator 1)) [ 1085.782023] ip_local_deliver_finish (./include/linux/rcupdate.h:779 net/ipv4/ip_input.c:234) [ 1085.782266] __netif_receive_skb_one_core (net/core/dev.c:5542 (discriminator 4)) [ 1085.782526] netif_receive_skb (net/core/dev.c:5742 net/core/dev.c:5801) [ 1085.782742] tcf_mirred_to_dev (net/sched/act_mirred.c:327) act_mirred [ 1085.783023] tcf_mirred_act (net/sched/act_mirred.c:459 (discriminator 2)) act_mirred [ 1085.783284] ? tcf_skbedit_act (net/sched/act_skbedit.c:51 (discriminator 3)) act_skbedit [ 1085.783566] tcf_action_exec (net/sched/act_api.c:1101 net/sched/act_api.c:1074) [ 1085.783784] fl_classify (net/sched/cls_flower.c:345) cls_flower [ 1085.784043] ? fl_mask_lookup (./include/linux/rcupdate.h:308 ./include/linux/rcupdate.h:783 ./include/linux/rhashtable.h:673 net/sched/cls_flower.c:262 net/sched/cls_flower.c:295) cls_flower [ 1085.784326] ? fl_mask_lookup (net/sched/cls_flower.c:296) cls_flower [ 1085.784603] ? __pfx_usage_match (kernel/locking/lockdep.c:2256) [ 1085.784823] ? __bfs (kernel/locking/lockdep.c:1787) [ 1085.784995] ? check_irq_usage (kernel/locking/lockdep.c:2823) [ 1085.785215] ? check_path.constprop.0 (kernel/locking/lockdep.c:2145) [ 1085.785458] ? check_noncircular (kernel/locking/lockdep.c:2172) [ 1085.785686] ? __lock_acquire (kernel/locking/lockdep.c:5133 (discriminator 1)) [ 1085.785907] tcf_classify (./include/net/tc_wrapper.h:197 net/sched/cls_api.c:1734 net/sched/cls_api.c:1830) [ 1085.786119] tc_run (net/core/dev.c:3945) [ 1085.786296] __dev_queue_xmit (net/core/dev.c:4069 net/core/dev.c:4301) [ 1085.786516] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 1085.786730] ip_finish_output2 (./include/linux/netdevice.h:3171 ./include/net/neighbour.h:526 ./include/net/neighbour.h:540 net/ipv4/ip_output.c:235) [ 1085.786952] ? __ip_queue_xmit (net/ipv4/ip_output.c:535) [ 1085.787175] __ip_queue_xmit (net/ipv4/ip_output.c:535) [ 1085.787384] __tcp_transmit_skb (net/ipv4/tcp_output.c:1462 (discriminator 4)) [ 1085.787612] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 1085.787827] tcp_write_xmit (net/ipv4/tcp_output.c:2792) [ 1085.788039] __tcp_push_pending_frames (net/ipv4/tcp_output.c:2977) [ 1085.788291] tcp_rcv_state_process (net/ipv4/tcp_input.c:5654 net/ipv4/tcp_input.c:6870) [ 1085.788535] ? tcp_v4_rcv (./include/linux/skbuff.h:1624 ./include/net/tcp.h:2510 net/ipv4/tcp_ipv4.c:2326) [ 1085.788732] ? tcp_v4_do_rcv (net/ipv4/tcp_ipv4.c:1929) [ 1085.788940] tcp_v4_do_rcv (net/ipv4/tcp_ipv4.c:1929) [ 1085.789138] tcp_v4_rcv (net/ipv4/tcp_ipv4.c:2329) [ 1085.789328] ? process_backlog (net/core/dev.c:5978 (discriminator 2)) [ 1085.789543] ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205 (discriminator 1)) [ 1085.789782] ip_local_deliver_finish (./include/linux/rcupdate.h:779 net/ipv4/ip_input.c:234) [ 1085.790021] __netif_receive_skb_one_core (net/core/dev.c:5542 (discriminator 4)) [ 1085.790298] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5985) [ 1085.790542] __napi_poll.constprop.0 (net/core/dev.c:6584) [ 1085.790820] net_rx_action (net/core/dev.c:6655 net/core/dev.c:6786) [ 1085.791071] __do_softirq (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/irq.h:142 kernel/softirq.c:554) [ 1085.791322] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644) [ 1085.791536] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14)) [ 1085.791793] [ 1085.791926] [ 1085.792077] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649) [ 1085.792414] RIP: 0010:_raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) [ 1085.792748] Code: c7 18 53 48 89 f3 48 8b 74 24 10 e8 81 4c 39 ff 48 89 ef e8 39 7d 39 ff 80 e7 02 74 06 e8 cf a5 46 ff fb 65 ff 0d cf f8 3f 64 <74> 07 5b 5d c3 cc cc cc cc 0f 1f 44 00 00 5b 5d c3 cc cc cc cc 66 All code ======== 0: c7 (bad) 1: 18 53 48 sbb %dl,0x48(%rbx) 4: 89 f3 mov %esi,%ebx 6: 48 8b 74 24 10 mov 0x10(%rsp),%rsi b: e8 81 4c 39 ff call 0xffffffffff394c91 10: 48 89 ef mov %rbp,%rdi 13: e8 39 7d 39 ff call 0xffffffffff397d51 18: 80 e7 02 and $0x2,%bh 1b: 74 06 je 0x23 1d: e8 cf a5 46 ff call 0xffffffffff46a5f1 22: fb sti 23: 65 ff 0d cf f8 3f 64 decl %gs:0x643ff8cf(%rip) # 0x643ff8f9 2a:* 74 07 je 0x33 <-- trapping instruction 2c: 5b pop %rbx 2d: 5d pop %rbp 2e: c3 ret 2f: cc int3 30: cc int3 31: cc int3 32: cc int3 33: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 38: 5b pop %rbx 39: 5d pop %rbp 3a: c3 ret 3b: cc int3 3c: cc int3 3d: cc int3 3e: cc int3 3f: 66 data16 Code starting with the faulting instruction =========================================== 0: 74 07 je 0x9 2: 5b pop %rbx 3: 5d pop %rbp 4: c3 ret 5: cc int3 6: cc int3 7: cc int3 8: cc int3 9: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) e: 5b pop %rbx f: 5d pop %rbp 10: c3 ret 11: cc int3 12: cc int3 13: cc int3 14: cc int3 15: 66 data16 [ 1085.793942] RSP: 0018:ffffa08f873ffdc0 EFLAGS: 00000286 [ 1085.794296] RAX: 000000000037e9bf RBX: 0000000000000292 RCX: 0000000000000080 [ 1085.794765] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff9bc2f671 [ 1085.795239] RBP: ffff8ab4c21e8508 R08: 0000000000000001 R09: 0000000000000001 [ 1085.795712] R10: 0000000000000001 R11: 0000000000000001 R12: 0000000000000001 [ 1085.796193] R13: 0000000000000292 R14: 0000000000000004 R15: ffffa08f873ffe68 [ 1085.796668] ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:77 ./arch/x86/include/asm/irqflags.h:135 ./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 1085.797007] __wake_up (kernel/sched/wait.c:110 kernel/sched/wait.c:127) [ 1085.797235] file_tty_write.constprop.0 (drivers/tty/tty_io.c:949 drivers/tty/tty_io.c:1046 drivers/tty/tty_io.c:1096) [ 1085.797576] vfs_write (./include/linux/fs.h:2085 fs/read_write.c:497 fs/read_write.c:590) [ 1085.797819] ksys_write (fs/read_write.c:643) [ 1085.798044] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 1085.798273] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129) [ 1085.798614] RIP: 0033:0x7f1c9122a957 [ 1085.798861] Code: 0b 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24 All code ======== 0: 0b 00 or (%rax),%eax 2: f7 d8 neg %eax 4: 64 89 02 mov %eax,%fs:(%rdx) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b7 jmp 0xffffffffffffffc7 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 01 00 00 00 mov $0x1,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 48 89 54 24 18 mov %rdx,0x18(%rsp) 3c: 48 rex.W 3d: 89 .byte 0x89 3e: 74 24 je 0x64 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 48 89 54 24 18 mov %rdx,0x18(%rsp) 12: 48 rex.W 13: 89 .byte 0x89 14: 74 24 je 0x3a [ 1085.800017] RSP: 002b:00007ffed4324508 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 1085.800509] RAX: ffffffffffffffda RBX: 00005651736e9db0 RCX: 00007f1c9122a957 [ 1085.800941] RDX: 0000000000000001 RSI: 00005651736e9db0 RDI: 0000000000000001 [ 1085.801313] RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000002000 [ 1085.801691] R10: 0000000000000001 R11: 0000000000000246 R12: 00005651736d64e0 Finger prints: dump_stack_lvl:__lock_acquire:lock_acquire:_raw_spin_lock_nested