======================================
| [ 323.349924][ T3867] br0: port 2(vx0) entered forwarding state
| [ 324.427811][ C1] ------------[ cut here ]------------
| [ 324.428235][ C1] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9
| [ 324.428601][ C1] load of value 107 is not a valid value for type '_Bool'
[ 324.429374][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[ 324.430005][ C1] Call Trace:
[ 324.430185][ C1]
[ 324.430344][ C1] dump_stack_lvl (lib/dump_stack.c:107)
[ 324.430590][ C1] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419)
[ 324.430925][ C1] br_forward_finish.cold (./include/linux/skbuff.h:4267 net/bridge/br_forward.c:65)
[ 324.431201][ C1] deliver_clone (net/bridge/br_forward.c:132)
[ 324.431443][ C1] maybe_deliver (net/bridge/br_forward.c:191)
[ 324.431696][ C1] br_flood (net/bridge/br_forward.c:236)
[ 324.431927][ C1] br_dev_xmit (net/bridge/br_device.c:100)
[ 324.432170][ C1] ? __pfx_br_dev_xmit (net/bridge/br_device.c:29)
[ 324.432446][ C1] ? __pfx_skb_network_protocol (net/core/dev.c:3341)
[ 324.432755][ C1
DETECTED CRASH, lowering timeout
] ? __pfx_qdisc_pkt_len_init (net/core/dev.c:3679)
[ 324.433049][ C1] ? __pfx_passthru_features_check (net/core/dev.c:3436)
[ 324.433373][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546)
[ 324.433656][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338)
[ 324.433921][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5137)
[ 324.434195][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246)
[ 324.434482][ C1] ? __dev_queue_xmit (./include/linux/bottom_half.h:20 ./include/linux/rcupdate.h:802 net/core/dev.c:4262)
[ 324.434754][ C1] ? __pfx_skb_network_protocol (net/core/dev.c:3341)
[ 324.435066][ C1] vlan_dev_hard_start_xmit (net/8021q/vlan_dev.c:130)
[ 324.435374][ C1] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546)
[ 324.435654][ C1] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338)
[ 324.435917][ C1] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3))
[ 324.436146][ C1] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3))
[ 324.436379][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4274)
[ 324.436636][ C1] ? eth_header (net/ethernet/eth.c:100)
[ 324.436880][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4246)
[ 324.437184][ C1] ip6_finish_output2 (./include/net/neighbour.h:542 net/ipv6/ip6_output.c:137)
[ 324.437461][ C1] ip6_finish_output (net/ipv6/ip6_output.c:211 net/ipv6/ip6_output.c:222)
[ 324.437724][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 324.437969][ C1] ip6_output (./include/linux/netfilter.h:303 net/ipv6/ip6_output.c:243)
[ 324.438205][ C1] ? __pfx_ip6_output (net/ipv6/ip6_output.c:230)
[ 324.438485][ C1] NF_HOOK.constprop.0 (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 ./include/linux/netfilter.h:238 ./include/linux/netfilter.h:312)
[ 324.438755][ C1] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308)
[ 324.439051][ C1] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719)
[ 324.439353][ C1] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4292 kernel/locking/lockdep.c:4359)
[ 324.439710][ C1] ndisc_send_skb (net/ipv6/ndisc.c:512 (discriminator 60))
[ 324.439972][ C1] ? __pfx_ndisc_send_skb (net/ipv6/ndisc.c:473)
[ 324.440260][ C1] ? __ndisc_fill_addr_option (net/ipv6/ndisc.c:160)
[ 324.440569][ C1] addrconf_rs_timer (net/ipv6/addrconf.c:4047)
[ 324.440839][ C1] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023)
[ 324.441131][ C1] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725)
[ 324.441380][ C1] ? call_timer_fn (kernel/time/timer.c:1697)
[ 324.441640][ C1] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023)
[ 324.441926][ C1] call_timer_fn (kernel/time/timer.c:1700)
[ 324.442175][ C1] ? __pfx_call_timer_fn (kernel/time/timer.c:1677)
[ 324.442468][ C1] __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038)
[ 324.442738][ C1] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023)
[ 324.443032][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5406)
[ 324.443307][ C1] ? __pfx___run_timers.part.0 (kernel/time/timer.c:2007)
[ 324.443610][ C1] ? clockevents_program_event (kernel/time/clockevents.c:326)
[ 324.443916][ C1] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:94 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86)
[ 324.444193][ C1] ? ktime_get (kernel/time/timekeeping.c:195 (discriminator 4) kernel/time/timekeeping.c:289 (discriminator 4) kernel/time/timekeeping.c:388 (discriminator 4) kernel/time/timekeeping.c:848 (discriminator 4))
[ 324.444424][ C1] ? hrtimer_interrupt (kernel/time/hrtimer.c:1828)
[ 324.444697][ C1] ? clockevents_program_event (kernel/time/clockevents.c:334 (discriminator 3))
[ 324.445014][ C1] run_timer_softirq (kernel/time/timer.c:2012 kernel/time/timer.c:2053)
[ 324.445278][ C1] __do_softirq (kernel/softirq.c:553)
[ 324.445530][ C1] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644)
[ 324.445761][ C1] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14))
[ 324.446060][ C1]
[ 324.446216][ C1]
[ 324.446391][ C1] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649)
[ 324.446706][ C1] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743)
[ 324.446972][ C1] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 23 d5 3d 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90
All code
========
0: 4c 01 c7 add %r8,%rdi
3: 4c 29 c2 sub %r8,%rdx
6: e9 72 ff ff ff jmp 0xffffffffffffff7d
b: 90 nop
c: 90 nop
d: 90 nop
e: 90 nop
f: 90 nop
10: 90 nop
11: 90 nop
12: 90 nop
13: 90 nop
14: 90 nop
15: 90 nop
16: 90 nop
17: 90 nop
18: 90 nop
19: 90 nop
1a: 90 nop
1b: f3 0f 1e fa endbr64
1f: 66 90 xchg %ax,%ax
21: 0f 00 2d 23 d5 3d 00 verw 0x3dd523(%rip) # 0x3dd54b
28: fb sti
29: f4 hlt
2a:* fa cli <-- trapping instruction
2b: c3 ret
2c: cc int3
2d: cc int3
2e: cc int3
2f: cc int3
30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
37: 00 00 00 00
3b: 90 nop
3c: 90 nop
3d: 90 nop
3e: 90 nop
3f: 90 nop
Code starting with the faulting instruction
===========================================
0: fa cli
1: c3 ret
2: cc int3
3: cc int3
4: cc int3
5: cc int3
6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
d: 00 00 00 00
11: 90 nop
12: 90 nop
13: 90 nop
14: 90 nop
15: 90 nop
[ 324.447973][ C1] RSP: 0018:ffffc9000013fdf8 EFLAGS: 00000242
[ 324.448291][ C1] RAX: 0000000000587131 RBX: 1ffff92000027fc1 RCX: ffffffffb9c83792
[ 324.448707][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffb749a146
[ 324.449118][ C1] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1005d7eea4
[ 324.449529][ C1] R10: ffff88802ebf7523 R11: ffff88802ebfc508 R12: 0000000000000000
[ 324.449938][ C1] R13: ffff888001d28040 R14: dffffc0000000000 R15: 0000000000000000
[ 324.450362][ C1] ? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:147)
[ 324.450662][ C1] ? cpuidle_idle_call (kernel/sched/idle.c:171)
[ 324.450936][ C1] default_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:98)
[ 324.451189][ C1] cpuidle_idle_call (kernel/sched/idle.c:171)
[ 324.451452][ C1] ? __pfx_cpuidle_idle_call (kernel/sched/idle.c:147)
[ 324.451743][ C1] ? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59)
[ 324.452032][ C1] do_idle (kernel/sched/idle.c:312)
[ 324.452250][ C1] cpu_startup_entry (kernel/sched/idle.c:409 (discriminator 1))
[ 324.452504][ C1] start_secondary (arch/x86/kernel/smpboot.c:224 arch/x86/kernel/smpboot.c:304)
[ 324.452757][ C1] ? __pfx_start_secondary (arch/x86/kernel/smpboot.c:254)
Finger prints:
dump_stack_lvl:__ubsan_handle_load_invalid_value:deliver_clone:maybe_deliver