======================================
| [ 6273.049067][ T5965] br0: port 2(eth1) entered forwarding state
| [ 6278.637900][ C3] ------------[ cut here ]------------
| [ 6278.638495][ C3] WARNING: CPU: 3 PID: 9144 at ./include/linux/skbuff.h:1164 icmp_route_lookup.constprop.0 (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/icmp.c:548)
| [ 6278.639190][ C3] Modules linked in: sch_fq act_mirred xfrm_user l2tp_ip6 l2tp_eth l2tp_ip l2tp_netlink l2tp_core vxcan can_dev xfrm_interface ip6_gre ip_gre gre macsec ipvlan unix_diag cls_matchall act_gact cls_flower chacha chacha_x86_64 libchacha chacha20poly1305 libpoly1305 poly1305_x86_64 tls cls_bpf sch_ingress ip6t_rpfilter vxlan mpls_gso mpls_iptunnel mpls_router xt_HL nft_compat nf_tables amt [last unloaded: test_bpf]
[ 6278.642982][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 6278.643556][ C3] RIP: 0010:icmp_route_lookup.constprop.0 (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/icmp.c:548)
[ 6278.644015][ C3] Code: ea 03 80 3c 02 00 0f 85 4f 05 00 00 49 8b 44 24 58 48 89 44 24 08 a8 01 0f 85 39 02 00 00 48 f7 44 24 08 fe ff ff ff 74 04 90 <0f> 0b 90 48 b8 00 00 00 00 00 fc ff df 4c 89 da 48 c1 ea 03 80 3c
All code
========
0: ea (bad)
1: 03 80 3c 02 00 0f add 0xf00023c(%rax),%eax
7: 85 4f 05 test %ecx,0x5(%rdi)
a: 00 00 add %al,(%rax)
c: 49 8b 44 24 58 mov 0x58(%r12),%rax
11: 48 89 44 24 08 mov %rax,0x8(%rsp)
16: a8 01 test $0x1,%al
18: 0f 85 39 02 00 00 jne 0x257
1e: 48 f7 44 24 08 fe ff testq $0xfffffffffffffffe,0x8(%rsp)
25: ff ff
27: 74 04 je 0x2d
29: 90 nop
2a:* 0f 0b ud2 <-- trapping instruction
2c: 90 nop
2d: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
34: fc ff df
37: 4c 89 da mov %r11,%rdx
3a: 48 c1 ea 03 shr $0x3,%rdx
3e: 80 .byte 0x80
3f: 3c .byte 0x3c
Code starting with the faulting instruction
===========================================
0: 0f 0b ud2
2: 90 nop
3: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
a: fc ff df
d: 4c 89 da mov %r11,%rdx
10: 48 c1 ea 03 shr $0x3,%rdx
14: 80 .byte 0x80
15: 3c .byte 0x3c
[ 6278.645235][ C3] RSP: 0018:ffffc900002705e8 EFLAGS: 00010286
[ 6278.645664][ C3] RAX: ffff88800ea081c0 RBX: 1ffff9200004e0c1 RCX: 0000000000000002
[ 6278.646176][ C3] RDX: 1ffff1100162db23 RSI: ffffffffaff123fb RDI: ffffc9000027069a
[ 6278.646706][ C3] RBP: ffff88800a900040 R08: 0000000000000001 R09: ffff88800ea09cc0
[ 6278.647234][ C3] R10: ffffe8ffffd9782f R11: ffff88800b16d918 R12: ffff88800b16d8c0
[ 6278.647746][ C3] R13: ffffc90000270898 R14: ffff88800ea09540 R15: ffffc90000270628
[ 6278.648263][ C3] FS: 00007f6ca195f300(0000) GS:ffff8880bab12000(0000) knlGS:0000000000000000
[ 6278.648874][ C3] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 6278.649304][ C3] CR2: 00007f6ca1baf8b0 CR3: 000000001da89004 CR4: 0000000000772ef0
[ 6278.649826][ C3] PKRU: 55555554
[ 6278.650083][ C3] Call Trace:
[ 6278.650338][ C3]
[ 6278.650520][ C3] ? __pfx_icmp_route_lookup.constprop.0 (net/ipv4/icmp.c:480)
[ 6278.650972][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 6278.651322][ C3] ? __ip_options_echo (net/ipv4/ip_options.c:86)
[ 6278.651665][ C3] ? __icmp_send (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 net/ipv4/icmp.c:718)
[ 6278.652006][ C3] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 6278.652348][ C3] __icmp_send (net/ipv4/icmp.c:746)
[ 6278.652706][ C3] ? __pfx___icmp_send (net/ipv4/icmp.c:596)
[ 6278.653059][ C3] ? fib_lookup.constprop.0 (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 ./include/net/ip_fib.h:403)
[ 6278.653402][ C3] ? ip_route_input_slow (net/ipv4/route.c:2177 net/ipv4/route.c:2385)
[ 6278.653748][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 6278.654108][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745)
[ 6278.654454][ C3] ip_rt_send_redirect (net/ipv4/route.c:920)
[ 6278.654808][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 6278.655157][ C3] ? __pfx_ip_rt_send_redirect (net/ipv4/route.c:868)
[ 6278.655500][ C3] ? ip_dst_mtu_maybe_forward.constprop.0 (./include/linux/rcupdate.h:873 ./include/net/ip.h:501)
[ 6278.655931][ C3] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 6278.656273][ C3] ? ip_forward (net/ipv4/ip_forward.c:157)
[ 6278.656612][ C3] ip_forward (net/ipv4/ip_forward.c:157)
[ 6278.656960][ C3] ? debug_object_activate (lib/debugobjects.c:837)
[ 6278.657298][ C3] ip_rcv (./include/net/dst.h:471 ./include/net/dst.h:469 net/ipv4/ip_input.c:454 ./include/linux/netfilter.h:317 ./include/linux/netfilter.h:311 net/ipv4/ip_input.c:574)
[ 6278.657549][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:567)
[ 6278.657896][ C3] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380)
[ 6278.658232][ C3] ? validate_chain (kernel/locking/lockdep.c:3804 kernel/locking/lockdep.c:3824 kernel/locking/lockdep.c:3879)
[ 6278.658571][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 6278.658928][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:567)
[ 6278.659252][ C3] ? process_backlog (./include/linux/local_lock_internal.h:54 net/core/dev.c:6442)
[ 6278.659579][ C3] __netif_receive_skb_one_core (net/core/dev.c:5979 (discriminator 4))
[ 6278.659999][ C3] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5972)
[ 6278.660410][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745)
[ 6278.660777][ C3] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5834)
[ 6278.661111][ C3] ? process_backlog (./include/linux/local_lock_internal.h:54 net/core/dev.c:6442)
[ 6278.661447][ C3] process_backlog (./include/linux/rcupdate.h:869 net/core/dev.c:6445)
[ 6278.661812][ C3] __napi_poll.constprop.0 (net/core/dev.c:7482)
[ 6278.662141][ C3] net_rx_action (net/core/dev.c:7546 net/core/dev.c:7673)
[ 6278.662482][ C3] ? __pfx_net_rx_action (net/core/dev.c:7635)
[ 6278.662838][ C3] ? sched_ttwu_pending (kernel/sched/sched.h:1795 kernel/sched/sched.h:1863 kernel/sched/core.c:3858)
[ 6278.663173][ C3] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 6278.663514][ C3] ? do_raw_spin_unlock (./arch/x86/include/asm/atomic.h:23 ./include/linux/atomic/atomic-arch-fallback.h:457 ./include/linux/atomic/atomic-instrumented.h:33 ./include/asm-generic/qspinlock.h:57 kernel/locking/spinlock_debug.c:101 kernel/locking/spinlock_debug.c:141)
[ 6278.663860][ C3] ? _raw_spin_unlock (./arch/x86/include/asm/preempt.h:104 ./include/linux/spinlock_api_smp.h:143 kernel/locking/spinlock.c:186)
[ 6278.664224][ C3] handle_softirqs (kernel/softirq.c:580)
[ 6278.664578][ C3] ? __dev_queue_xmit (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:908 net/core/dev.c:4740)
[ 6278.664924][ C3] do_softirq (kernel/softirq.c:480 kernel/softirq.c:467)
[ 6278.665176][ C3]
[ 6278.665346][ C3]
[ 6278.665518][ C3] __local_bh_enable_ip (kernel/softirq.c:407)
[ 6278.665875][ C3] ? __dev_queue_xmit (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:908 net/core/dev.c:4740)
[ 6278.666200][ C3] __dev_queue_xmit (net/core/dev.c:4741)
[ 6278.666533][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 6278.666882][ C3] ? __pfx___dev_queue_xmit (net/core/dev.c:4621)
[ 6278.667213][ C3] ? neigh_hh_output (./include/linux/seqlock.h:74 ./include/linux/seqlock.h:836 ./include/net/neighbour.h:501)
[ 6278.667540][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 6278.667879][ C3] ? neigh_hh_output (./include/linux/seqlock.h:74 ./include/linux/seqlock.h:836 ./include/net/neighbour.h:501)
[ 6278.668215][ C3] ip_finish_output2 (./include/net/neighbour.h:545 net/ipv4/ip_output.c:235)
[ 6278.668543][ C3] ? ip_skb_dst_mtu (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 ./include/net/ip.h:501 ./include/net/ip.h:515)
[ 6278.668897][ C3] ? __pfx_ip_finish_output2 (net/ipv4/ip_output.c:199)
[ 6278.669246][ C3] ? __ip_finish_output (./include/linux/skbuff.h:1685 ./include/linux/skbuff.h:5079 net/ipv4/ip_output.c:307 net/ipv4/ip_output.c:295)
[ 6278.669583][ C3] ip_output (./include/linux/netfilter.h:306 net/ipv4/ip_output.c:433)
[ 6278.669843][ C3] ? __ip_local_out (net/ipv4/ip_output.c:96 net/ipv4/ip_output.c:107)
[ 6278.670178][ C3] ? __pfx_ip_output (net/ipv4/ip_output.c:427)
[ 6278.670509][ C3] ? __ip_make_skb (net/ipv4/ip_output.c:1382 net/ipv4/ip_output.c:1492)
[ 6278.670866][ C3] ? __pfx_raw_getfrag (net/ipv4/raw.c:453)
[ 6278.671206][ C3] ? ip_append_data (net/ipv4/ip_output.c:1371 net/ipv4/ip_output.c:1350)
[ 6278.671550][ C3] ip_push_pending_frames (./include/net/dst.h:461 net/ipv4/ip_output.c:129 net/ipv4/ip_output.c:1501 net/ipv4/ip_output.c:1521)
[ 6278.671903][ C3] raw_sendmsg (net/ipv4/raw.c:658)
[ 6278.672236][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 6278.672562][ C3] ? __pfx_raw_sendmsg (net/ipv4/raw.c:483)
[ 6278.672896][ C3] ? do_fault_around (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 mm/memory.c:5551)
[ 6278.673224][ C3] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 6278.673578][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 6278.673916][ C3] ? __might_fault (mm/memory.c:6971 mm/memory.c:6965)
[ 6278.674245][ C3] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 6278.674594][ C3] ? __might_fault (mm/memory.c:6971 mm/memory.c:6965)
[ 6278.674944][ C3] __sys_sendto (net/socket.c:714 net/socket.c:729 net/socket.c:2228)
[ 6278.675283][ C3] ? __pfx___sys_sendto (net/socket.c:2195)
[ 6278.675631][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745)
[ 6278.675975][ C3] ? rseq_update_cpu_node_id (kernel/rseq.c:189 (discriminator 10))
[ 6278.676315][ C3] ? __rseq_handle_notify_resume (kernel/rseq.c:442)
[ 6278.676735][ C3] ? __pfx___rseq_handle_notify_resume (kernel/rseq.c:425)
[ 6278.677174][ C3] __x64_sys_sendto (net/socket.c:2231)
[ 6278.677517][ C3] ? do_syscall_64 (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 ./include/linux/entry-common.h:199 arch/x86/entry/syscall_64.c:90)
[ 6278.677875][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 6278.678216][ C3] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
[ 6278.678555][ C3] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
[ 6278.678982][ C3] RIP: 0033:0x7f6ca1bf628a
[ 6278.679334][ C3] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89
All code
========
0: d8 64 89 02 fsubs 0x2(%rcx,%rcx,4)
4: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax
b: eb b8 jmp 0xffffffffffffffc5
d: 0f 1f 00 nopl (%rax)
10: f3 0f 1e fa endbr64
14: 41 89 ca mov %ecx,%r10d
17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax
1e: 00
1f: 85 c0 test %eax,%eax
21: 75 15 jne 0x38
23: b8 2c 00 00 00 mov $0x2c,%eax
28: 0f 05 syscall
2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction
30: 77 7e ja 0xb0
32: c3 ret
33: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1)
38: 41 54 push %r12
3a: 48 83 ec 30 sub $0x30,%rsp
3e: 44 rex.R
3f: 89 .byte 0x89
Code starting with the faulting instruction
===========================================
0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax
6: 77 7e ja 0x86
8: c3 ret
9: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1)
e: 41 54 push %r12
10: 48 83 ec 30 sub $0x30,%rsp
14: 44 rex.R
15: 89 .byte 0x89
[ 6278.680555][ C3] RSP: 002b:00007ffe3966fd58 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
[ 6278.681078][ C3] RAX: ffffffffffffffda RBX: 0000000000000040 RCX: 00007f6ca1bf628a
[ 6278.681585][ C3] RDX: 0000000000000048 RSI: 00000000362792a0 RDI: 0000000000000005
[ 6278.682445][ C3] RBP: 00007ffe3966fdb0 R08: 00000000004185e0 R09: 0000000000000010
[ 6278.682972][ C3] R10: 0000000000000000 R11: 0000000000000246 R12: 000000000000005c
Finger prints:
__icmp_send:ip_rt_send_redirect:ip_forward:ip_rcv:__netif_receive_skb_one_core