====================================== | 0 | xx__-> [ 4355.751847][ T9532] ------------[ cut here ]------------ | [ 4355.752440][ T9532] WARNING: CPU: 1 PID: 9532 at ./include/linux/skbuff.h:1164 ip_route_me_harder (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/netfilter.c:68) | [ 4355.753110][ T9532] Modules linked in: act_csum act_pedit cls_fw sch_ingress xt_statistic xt_length xt_bpf ipt_REJECT tcp_diag xt_mark nft_compat mptcp_diag inet_diag nft_tproxy nf_tproxy_ipv6 nf_tproxy_ipv4 nft_socket nf_socket_ipv4 nf_socket_ipv6 nf_tables sch_netem [ 4355.755282][ T9532] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 4355.755688][ T9532] RIP: 0010:ip_route_me_harder (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/netfilter.c:68) [ 4355.756104][ T9532] Code: 31 c9 e9 64 f8 ff ff 80 3c 02 00 0f 85 c0 06 00 00 48 8b 45 58 48 89 c6 48 83 e6 fe a8 01 0f 85 7c 03 00 00 48 85 f6 74 04 90 <0f> 0b 90 48 b8 00 00 00 00 00 fc ff df 4c 89 ea 48 c1 ea 03 80 3c All code ======== 0: 31 c9 xor %ecx,%ecx 2: e9 64 f8 ff ff jmp 0xfffffffffffff86b 7: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1) b: 0f 85 c0 06 00 00 jne 0x6d1 11: 48 8b 45 58 mov 0x58(%rbp),%rax 15: 48 89 c6 mov %rax,%rsi 18: 48 83 e6 fe and $0xfffffffffffffffe,%rsi 1c: a8 01 test $0x1,%al 1e: 0f 85 7c 03 00 00 jne 0x3a0 24: 48 85 f6 test %rsi,%rsi 27: 74 04 je 0x2d 29: 90 nop 2a:* 0f 0b ud2 <-- trapping instruction 2c: 90 nop 2d: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax 34: fc ff df 37: 4c 89 ea mov %r13,%rdx 3a: 48 c1 ea 03 shr $0x3,%rdx 3e: 80 .byte 0x80 3f: 3c .byte 0x3c Code starting with the faulting instruction =========================================== 0: 0f 0b ud2 2: 90 nop 3: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax a: fc ff df d: 4c 89 ea mov %r13,%rdx 10: 48 c1 ea 03 shr $0x3,%rdx 14: 80 .byte 0x80 15: 3c .byte 0x3c [ 4355.757240][ T9532] RSP: 0018:ffffc90007687288 EFLAGS: 00010282 [ 4355.757668][ T9532] RAX: ffff88801087a040 RBX: 1ffff92000ed0e57 RCX: 1ffff1100210f408 [ 4355.758150][ T9532] RDX: 1ffff110033f0137 RSI: ffff88801087a040 RDI: ffff88801ce4c0e0 [ 4355.758631][ T9532] RBP: ffff888019f80960 R08: 1ffff92000ed0e62 R09: ffff888019f809e1 [ 4355.759100][ T9532] R10: ffff88801087a083 R11: dffffc0000000000 R12: ffff8880179b0040 [ 4355.759572][ T9532] R13: ffff888019f809b8 R14: ffffc900076872e8 R15: ffff888020ab6840 [ 4355.760055][ T9532] FS: 00007fb8a2bdd740(0000) GS:ffff8880a20bb000(0000) knlGS:0000000000000000 [ 4355.760639][ T9532] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4355.761054][ T9532] CR2: 00007fb8a2cb9530 CR3: 0000000005b36001 CR4: 0000000000772ef0 [ 4355.761533][ T9532] PKRU: 55555554 [ 4355.761769][ T9532] Call Trace: [ 4355.762006][ T9532] [ 4355.762170][ T9532] ? __pfx_ip_route_me_harder (net/ipv4/netfilter.c:22) [ 4355.762813][ T9532] ? is_bpf_text_address (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 kernel/bpf/core.c:774) [ 4355.763137][ T9532] ? is_bpf_text_address (kernel/bpf/core.c:777) [ 4355.763452][ T9532] ? kernel_text_address (kernel/extable.c:97 kernel/extable.c:94) [ 4355.763774][ T9532] ? __kernel_text_address (kernel/extable.c:79) [ 4355.764082][ T9532] ? unwind_get_return_address (arch/x86/kernel/unwind_orc.c:369 arch/x86/kernel/unwind_orc.c:364) [ 4355.764389][ T9532] ? __pfx_stack_trace_consume_entry (kernel/stacktrace.c:83) [ 4355.764786][ T9532] nf_route_table_hook4 (net/netfilter/nft_chain_route.c:47) nf_tables [ 4355.765221][ T9532] ? __lock_acquire (kernel/locking/lockdep.c:5240) [ 4355.765547][ T9532] ? __pfx_nf_route_table_hook4 (net/netfilter/nft_chain_route.c:19) nf_tables [ 4355.765967][ T9532] ? __pfx_nf_route_table_hook4 (net/netfilter/nft_chain_route.c:19) nf_tables [ 4355.766377][ T9532] nf_hook_slow (./include/linux/netfilter.h:157 net/netfilter/core.c:623) [ 4355.766700][ T9532] __ip_local_out (./include/linux/netfilter.h:272 net/ipv4/ip_output.c:118) [ 4355.767013][ T9532] ? __pfx___ip_local_out (net/ipv4/ip_output.c:101) [ 4355.767324][ T9532] ? __pfx_dst_output (./include/net/dst.h:460) [ 4355.767649][ T9532] __ip_queue_xmit (net/ipv4/ip_output.c:127 (discriminator 4) net/ipv4/ip_output.c:527 (discriminator 4)) [ 4355.767970][ T9532] ? __skb_clone (./arch/x86/include/asm/atomic.h:53 (discriminator 4) ./include/linux/atomic/atomic-arch-fallback.h:992 (discriminator 4) ./include/linux/atomic/atomic-instrumented.h:436 (discriminator 4) net/core/skbuff.c:1566 (discriminator 4)) [ 4355.768283][ T9532] __tcp_transmit_skb (net/ipv4/tcp_output.c:1625 (discriminator 4)) [ 4355.768615][ T9532] ? __pfx___tcp_transmit_skb (net/ipv4/tcp_output.c:1446) [ 4355.768933][ T9532] ? tso_fragment (./arch/x86/include/asm/atomic.h:28 ./include/linux/atomic/atomic-arch-fallback.h:503 ./include/linux/atomic/atomic-instrumented.h:68 ./include/linux/skbuff.h:2060 net/ipv4/tcp_output.c:2351) [ 4355.769252][ T9532] tcp_write_xmit (net/ipv4/tcp_output.c:2984) [ 4355.769585][ T9532] ? __pfx_tcp_write_xmit (net/ipv4/tcp_output.c:2888) [ 4355.769895][ T9532] ? __pfx_mptcp_subflow_active (net/mptcp/protocol.c:1317) [ 4355.770215][ T9532] ? __subflow_push_pending (net/mptcp/protocol.h:415 net/mptcp/protocol.c:1462) [ 4355.770534][ T9532] __tcp_push_pending_frames (net/ipv4/tcp_output.c:3167) [ 4355.770850][ T9532] mptcp_push_release.isra.0 (net/mptcp/protocol.c:1416) [ 4355.771158][ T9532] __mptcp_push_pending (./include/linux/list.h:963 ./include/linux/timer.h:147 net/mptcp/protocol.c:845 net/mptcp/protocol.c:1558) [ 4355.771475][ T9532] ? __pfx___mptcp_push_pending (net/mptcp/protocol.c:1500) [ 4355.771805][ T9532] mptcp_sendmsg (net/mptcp/protocol.c:1846) [ 4355.772132][ T9532] ? __pfx_mptcp_sendmsg (net/mptcp/protocol.c:1728) [ 4355.772448][ T9532] ? __pfx_pollwake (fs/select.c:209) [ 4355.772769][ T9532] ? find_held_lock (kernel/locking/lockdep.c:5353) [ 4355.773084][ T9532] sock_write_iter (net/socket.c:714 net/socket.c:729 net/socket.c:1179) [ 4355.773396][ T9532] ? __pfx_sock_write_iter (net/socket.c:1163) [ 4355.773722][ T9532] ? validate_chain (kernel/locking/lockdep.c:3804 kernel/locking/lockdep.c:3824 kernel/locking/lockdep.c:3879) [ 4355.774038][ T9532] vfs_write (fs/read_write.c:594 fs/read_write.c:686) [ 4355.774276][ T9532] ? __pfx_vfs_write (fs/read_write.c:667) [ 4355.774602][ T9532] ? __pfx_timespec64_add_safe (kernel/time/time.c:848) [ 4355.774913][ T9532] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 4355.775223][ T9532] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:95 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86) [ 4355.775539][ T9532] ? ktime_get_ts64 (kernel/time/timekeeping.c:251 (discriminator 4) kernel/time/timekeeping.c:360 (discriminator 4) kernel/time/timekeeping.c:919 (discriminator 4)) [ 4355.775858][ T9532] ksys_write (fs/read_write.c:738) [ 4355.776088][ T9532] ? __x64_sys_poll (fs/select.c:1076 fs/select.c:1062 fs/select.c:1062) [ 4355.776404][ T9532] ? __pfx_ksys_write (fs/read_write.c:728) [ 4355.776720][ T9532] ? do_user_addr_fault (./arch/x86/include/asm/atomic.h:93 ./include/linux/atomic/atomic-arch-fallback.h:949 ./include/linux/atomic/atomic-instrumented.h:401 ./include/linux/refcount.h:389 ./include/linux/refcount.h:432 ./include/linux/mmap_lock.h:142 ./include/linux/mmap_lock.h:237 arch/x86/mm/fault.c:1338) [ 4355.777043][ T9532] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 4355.777354][ T9532] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 4355.777746][ T9532] RIP: 0033:0x7fb8a2cde337 [ 4355.778070][ T9532] Code: 0f 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24 All code ======== 0: 0f 00 (bad) 2: f7 d8 neg %eax 4: 64 89 02 mov %eax,%fs:(%rdx) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b7 jmp 0xffffffffffffffc7 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 01 00 00 00 mov $0x1,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 48 89 54 24 18 mov %rdx,0x18(%rsp) 3c: 48 rex.W 3d: 89 .byte 0x89 3e: 74 24 je 0x64 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 48 89 54 24 18 mov %rdx,0x18(%rsp) 12: 48 rex.W 13: 89 .byte 0x89 14: 74 24 je 0x3a [ 4355.779190][ T9532] RSP: 002b:00007fff7e285478 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 4355.779669][ T9532] RAX: ffffffffffffffda RBX: 0000000000000005 RCX: 00007fb8a2cde337 [ 4355.780135][ T9532] RDX: 0000000000001f9c RSI: 00007fff7e2876a4 RDI: 0000000000000005 [ 4355.780609][ T9532] RBP: 0000000000001f9c R08: 00007fb8a2dd921c R09: 00007fb8a2dd9280 [ 4355.781085][ T9532] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fff7e287640 Finger prints: ip_route_me_harder:nf_route_table_hook4:nf_hook_slow:__ip_local_out:__ip_queue_xmit