====================================== | [ 323.349924][ T3867] br0: port 2(vx0) entered forwarding state | [ 324.427811][ C1] ------------[ cut here ]------------ | [ 324.428235][ C1] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 324.428601][ C1] load of value 107 is not a valid value for type '_Bool' [ 324.429374][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 324.430005][ C1] Call Trace: [ 324.430185][ C1] [ 324.430344][ C1] dump_stack_lvl (lib/dump_stack.c:107) [ 324.430590][ C1] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 324.430925][ C1] br_forward_finish.cold (./include/linux/skbuff.h:4267 net/bridge/br_forward.c:65) [ 324.431201][ C1] deliver_clone (net/bridge/br_forward.c:132) [ 324.431443][ C1] maybe_deliver (net/bridge/br_forward.c:191) [ 324.431696][ C1] br_flood (net/bridge/br_forward.c:236) [ 324.431927][ C1] br_dev_xmit (net/bridge/br_device.c:100) [ 324.432170][ C1] ? __pfx_br_dev_xmit (net/bridge/br_device.c:29) [ 324.432446][ C1] ? __pfx_skb_network_protocol (net/core/dev.c:3341) [ 324.432755][ C1 DETECTED CRASH, lowering timeout ] ? __pfx_qdisc_pkt_len_init (net/core/dev.c:3679) [ 324.433049][ C1] ? __pfx_passthru_features_check (net/core/dev.c:3436) [ 324.433373][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 324.433656][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 324.433921][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5137) [ 324.434195][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 324.434482][ C1] ? __dev_queue_xmit (./include/linux/bottom_half.h:20 ./include/linux/rcupdate.h:802 net/core/dev.c:4262) [ 324.434754][ C1] ? __pfx_skb_network_protocol (net/core/dev.c:3341) [ 324.435066][ C1] vlan_dev_hard_start_xmit (net/8021q/vlan_dev.c:130) [ 324.435374][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 324.435654][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 324.435917][ C1] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 324.436146][ C1] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 324.436379][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 324.436636][ C1] ? eth_header (net/ethernet/eth.c:100) [ 324.436880][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 324.437184][ C1] ip6_finish_output2 (./include/net/neighbour.h:542 net/ipv6/ip6_output.c:137) [ 324.437461][ C1] ip6_finish_output (net/ipv6/ip6_output.c:211 net/ipv6/ip6_output.c:222) [ 324.437724][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 324.437969][ C1] ip6_output (./include/linux/netfilter.h:303 net/ipv6/ip6_output.c:243) [ 324.438205][ C1] ? __pfx_ip6_output (net/ipv6/ip6_output.c:230) [ 324.438485][ C1] NF_HOOK.constprop.0 (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 ./include/linux/netfilter.h:238 ./include/linux/netfilter.h:312) [ 324.438755][ C1] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308) [ 324.439051][ C1] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719) [ 324.439353][ C1] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4292 kernel/locking/lockdep.c:4359) [ 324.439710][ C1] ndisc_send_skb (net/ipv6/ndisc.c:512 (discriminator 60)) [ 324.439972][ C1] ? __pfx_ndisc_send_skb (net/ipv6/ndisc.c:473) [ 324.440260][ C1] ? __ndisc_fill_addr_option (net/ipv6/ndisc.c:160) [ 324.440569][ C1] addrconf_rs_timer (net/ipv6/addrconf.c:4047) [ 324.440839][ C1] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023) [ 324.441131][ C1] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 324.441380][ C1] ? call_timer_fn (kernel/time/timer.c:1697) [ 324.441640][ C1] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023) [ 324.441926][ C1] call_timer_fn (kernel/time/timer.c:1700) [ 324.442175][ C1] ? __pfx_call_timer_fn (kernel/time/timer.c:1677) [ 324.442468][ C1] __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038) [ 324.442738][ C1] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023) [ 324.443032][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5406) [ 324.443307][ C1] ? __pfx___run_timers.part.0 (kernel/time/timer.c:2007) [ 324.443610][ C1] ? clockevents_program_event (kernel/time/clockevents.c:326) [ 324.443916][ C1] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:94 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86) [ 324.444193][ C1] ? ktime_get (kernel/time/timekeeping.c:195 (discriminator 4) kernel/time/timekeeping.c:289 (discriminator 4) kernel/time/timekeeping.c:388 (discriminator 4) kernel/time/timekeeping.c:848 (discriminator 4)) [ 324.444424][ C1] ? hrtimer_interrupt (kernel/time/hrtimer.c:1828) [ 324.444697][ C1] ? clockevents_program_event (kernel/time/clockevents.c:334 (discriminator 3)) [ 324.445014][ C1] run_timer_softirq (kernel/time/timer.c:2012 kernel/time/timer.c:2053) [ 324.445278][ C1] __do_softirq (kernel/softirq.c:553) [ 324.445530][ C1] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644) [ 324.445761][ C1] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14)) [ 324.446060][ C1] [ 324.446216][ C1] [ 324.446391][ C1] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649) [ 324.446706][ C1] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743) [ 324.446972][ C1] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 23 d5 3d 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 All code ======== 0: 4c 01 c7 add %r8,%rdi 3: 4c 29 c2 sub %r8,%rdx 6: e9 72 ff ff ff jmp 0xffffffffffffff7d b: 90 nop c: 90 nop d: 90 nop e: 90 nop f: 90 nop 10: 90 nop 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop 16: 90 nop 17: 90 nop 18: 90 nop 19: 90 nop 1a: 90 nop 1b: f3 0f 1e fa endbr64 1f: 66 90 xchg %ax,%ax 21: 0f 00 2d 23 d5 3d 00 verw 0x3dd523(%rip) # 0x3dd54b 28: fb sti 29: f4 hlt 2a:* fa cli <-- trapping instruction 2b: c3 ret 2c: cc int3 2d: cc int3 2e: cc int3 2f: cc int3 30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) 37: 00 00 00 00 3b: 90 nop 3c: 90 nop 3d: 90 nop 3e: 90 nop 3f: 90 nop Code starting with the faulting instruction =========================================== 0: fa cli 1: c3 ret 2: cc int3 3: cc int3 4: cc int3 5: cc int3 6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) d: 00 00 00 00 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop [ 324.447973][ C1] RSP: 0018:ffffc9000013fdf8 EFLAGS: 00000242 [ 324.448291][ C1] RAX: 0000000000587131 RBX: 1ffff92000027fc1 RCX: ffffffffb9c83792 [ 324.448707][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffb749a146 [ 324.449118][ C1] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1005d7eea4 [ 324.449529][ C1] R10: ffff88802ebf7523 R11: ffff88802ebfc508 R12: 0000000000000000 [ 324.449938][ C1] R13: ffff888001d28040 R14: dffffc0000000000 R15: 0000000000000000 [ 324.450362][ C1] ? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:147) [ 324.450662][ C1] ? cpuidle_idle_call (kernel/sched/idle.c:171) [ 324.450936][ C1] default_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:98) [ 324.451189][ C1] cpuidle_idle_call (kernel/sched/idle.c:171) [ 324.451452][ C1] ? __pfx_cpuidle_idle_call (kernel/sched/idle.c:147) [ 324.451743][ C1] ? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59) [ 324.452032][ C1] do_idle (kernel/sched/idle.c:312) [ 324.452250][ C1] cpu_startup_entry (kernel/sched/idle.c:409 (discriminator 1)) [ 324.452504][ C1] start_secondary (arch/x86/kernel/smpboot.c:224 arch/x86/kernel/smpboot.c:304) [ 324.452757][ C1] ? __pfx_start_secondary (arch/x86/kernel/smpboot.c:254) Finger prints: dump_stack_lvl:__ubsan_handle_load_invalid_value:deliver_clone:maybe_deliver