====================================== | [ 3266.244570][T24834] br0: port 2(vx0) entered forwarding state | [ 3268.744499][ C2] ------------[ cut here ]------------ | [ 3268.744910][ C2] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 3268.745315][ C2] load of value 107 is not a valid value for type '_Bool' [ 3268.746139][ C2] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 3268.746834][ C2] Call Trace: [ 3268.747039][ C2] [ 3268.747195][ C2] dump_stack_lvl (lib/dump_stack.c:107) [ 3268.747468][ C2] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 3268.747826][ C2] br_forward_finish.cold (./include/linux/skbuff.h:4267 net/bridge/br_forward.c:65) [ 3268.748105][ C2] deliver_clone (net/bridge/br_forward.c:132) [ 3268.748379][ C2] maybe_deliver (net/bridge/br_forward.c:191) [ 3268.748646][ C2] br_flood (net/bridge/br_forward.c:236) [ 3268.748888][ C2] br_dev_xmit (net/bridge/br_device.c:100) [ 3268.749162][ C2] ? __pfx_br_dev_xmit (net/bridge/br_device.c:29) [ 3268.749449][ C2] ? __pfx_skb_network_protocol (net/core/dev.c:3341) [ 3268.749783][ C2 DETECTED CRASH, lowering timeout ] ? __pfx_qdisc_pkt_len_init (net/core/dev.c:3679) [ 3268.750077][ C2] ? __pfx_passthru_features_check (net/core/dev.c:3436) [ 3268.750428][ C2] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 3268.750710][ C2] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 3268.750976][ C2] ? __lock_acquire (kernel/locking/lockdep.c:5137) [ 3268.751250][ C2] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 3268.751537][ C2] ? __dev_queue_xmit (./include/linux/bottom_half.h:20 ./include/linux/rcupdate.h:802 net/core/dev.c:4262) [ 3268.751809][ C2] ? __pfx_skb_network_protocol (net/core/dev.c:3341) [ 3268.752118][ C2] vlan_dev_hard_start_xmit (net/8021q/vlan_dev.c:130) [ 3268.752416][ C2] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 3268.752697][ C2] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 3268.752959][ C2] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 3268.753186][ C2] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3)) [ 3268.753422][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4274) [ 3268.753678][ C2] ? eth_header (net/ethernet/eth.c:100) [ 3268.753921][ C2] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 3268.754247][ C2] ip6_finish_output2 (./include/net/neighbour.h:542 net/ipv6/ip6_output.c:137) [ 3268.754530][ C2] ip6_finish_output (net/ipv6/ip6_output.c:211 net/ipv6/ip6_output.c:222) [ 3268.754792][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 3268.755042][ C2] ip6_output (./include/linux/netfilter.h:303 net/ipv6/ip6_output.c:243) [ 3268.755277][ C2] ? __pfx_ip6_output (net/ipv6/ip6_output.c:230) [ 3268.755557][ C2] NF_HOOK.constprop.0 (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 ./include/linux/netfilter.h:238 ./include/linux/netfilter.h:312) [ 3268.755838][ C2] ? __pfx_NF_HOOK.constprop.0 (./include/linux/netfilter.h:308) [ 3268.756146][ C2] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719) [ 3268.756448][ C2] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:4292 kernel/locking/lockdep.c:4359) [ 3268.756831][ C2] ndisc_send_skb (net/ipv6/ndisc.c:512 (discriminator 60)) [ 3268.757127][ C2] ? __pfx_ndisc_send_skb (net/ipv6/ndisc.c:473) [ 3268.757413][ C2] ? __ndisc_fill_addr_option (net/ipv6/ndisc.c:160) [ 3268.757744][ C2] addrconf_rs_timer (net/ipv6/addrconf.c:4047) [ 3268.758023][ C2] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023) [ 3268.758342][ C2] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 3268.758616][ C2] ? call_timer_fn (kernel/time/timer.c:1697) [ 3268.758876][ C2] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023) [ 3268.759198][ C2] call_timer_fn (kernel/time/timer.c:1700) [ 3268.759462][ C2] ? __pfx_call_timer_fn (kernel/time/timer.c:1677) [ 3268.759767][ C2] __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038) [ 3268.760048][ C2] ? __pfx_addrconf_rs_timer (net/ipv6/addrconf.c:4023) [ 3268.760344][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5406) [ 3268.760644][ C2] ? __pfx___run_timers.part.0 (kernel/time/timer.c:2007) [ 3268.760968][ C2] ? clockevents_program_event (kernel/time/clockevents.c:326) [ 3268.761275][ C2] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:94 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86) [ 3268.761570][ C2] ? ktime_get (kernel/time/timekeeping.c:195 (discriminator 4) kernel/time/timekeeping.c:289 (discriminator 4) kernel/time/timekeeping.c:388 (discriminator 4) kernel/time/timekeeping.c:848 (discriminator 4)) [ 3268.761801][ C2] ? hrtimer_interrupt (kernel/time/hrtimer.c:1828) [ 3268.762082][ C2] ? clockevents_program_event (kernel/time/clockevents.c:334 (discriminator 3)) [ 3268.762446][ C2] run_timer_softirq (kernel/time/timer.c:2012 kernel/time/timer.c:2053) [ 3268.762708][ C2] __do_softirq (kernel/softirq.c:553) [ 3268.762992][ C2] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644) [ 3268.763222][ C2] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14)) [ 3268.763540][ C2] [ 3268.763697][ C2] [ 3268.763866][ C2] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649) [ 3268.764182][ C2] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743) [ 3268.764481][ C2] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 23 d5 3d 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 All code ======== 0: 4c 01 c7 add %r8,%rdi 3: 4c 29 c2 sub %r8,%rdx 6: e9 72 ff ff ff jmp 0xffffffffffffff7d b: 90 nop c: 90 nop d: 90 nop e: 90 nop f: 90 nop 10: 90 nop 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop 16: 90 nop 17: 90 nop 18: 90 nop 19: 90 nop 1a: 90 nop 1b: f3 0f 1e fa endbr64 1f: 66 90 xchg %ax,%ax 21: 0f 00 2d 23 d5 3d 00 verw 0x3dd523(%rip) # 0x3dd54b 28: fb sti 29: f4 hlt 2a:* fa cli <-- trapping instruction 2b: c3 ret 2c: cc int3 2d: cc int3 2e: cc int3 2f: cc int3 30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) 37: 00 00 00 00 3b: 90 nop 3c: 90 nop 3d: 90 nop 3e: 90 nop 3f: 90 nop Code starting with the faulting instruction =========================================== 0: fa cli 1: c3 ret 2: cc int3 3: cc int3 4: cc int3 5: cc int3 6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1) d: 00 00 00 00 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop [ 3268.765529][ C2] RSP: 0018:ffffc9000014fdf8 EFLAGS: 00000242 [ 3268.765866][ C2] RAX: 0000000001a6db61 RBX: 1ffff92000029fc1 RCX: ffffffffad483792 [ 3268.766334][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffaac9a146 [ 3268.766776][ C2] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1006b7eea4 [ 3268.767212][ C2] R10: ffff888035bf7523 R11: ffff888035bfc508 R12: 0000000000000000 [ 3268.767632][ C2] R13: ffff888001d2a640 R14: dffffc0000000000 R15: 0000000000000000 [ 3268.768079][ C2] ? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:147) [ 3268.768382][ C2] ? cpuidle_idle_call (kernel/sched/idle.c:171) [ 3268.768684][ C2] default_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:98) [ 3268.768938][ C2] cpuidle_idle_call (kernel/sched/idle.c:171) [ 3268.769217][ C2] ? __pfx_cpuidle_idle_call (kernel/sched/idle.c:147) [ 3268.769527][ C2] ? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59) [ 3268.769818][ C2] do_idle (kernel/sched/idle.c:312) [ 3268.770061][ C2] cpu_startup_entry (kernel/sched/idle.c:409 (discriminator 1)) [ 3268.770350][ C2] start_secondary (arch/x86/kernel/smpboot.c:224 arch/x86/kernel/smpboot.c:304) [ 3268.770614][ C2] ? __pfx_start_secondary (arch/x86/kernel/smpboot.c:254) [ 3268.770924][ C2] secondary_startup_64_no_verify (arch/x86/kernel/head_64.S:461) | [ 3268.771456][ C2] ---[ end trace ]--- | [ 3268.772670][ C2] ------------[ cut here ]------------ | [ 3268.773013][ C2] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9 | [ 3268.773406][ C2] load of value 107 is not a valid value for type '_Bool' [ 3268.774211][ C2] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 3268.774911][ C2] Call Trace: [ 3268.775088][ C2] [ 3268.775248][ C2] dump_stack_lvl (lib/dump_stack.c:107) [ 3268.775502][ C2] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419) [ 3268.775856][ C2] skb_scrub_packet.cold (./include/linux/skbuff.h:4267 net/core/skbuff.c:6030) [ 3268.776133][ C2] __dev_forward_skb2 (./include/linux/netdevice.h:4115 net/core/dev.c:2135) [ 3268.776446][ C2] veth_xmit (drivers/net/veth.c:319 drivers/net/veth.c:374) [ 3268.776680][ C2] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546) [ 3268.776961][ C2] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338) [ 3268.777224][ C2] ? __pfx_do_raw_write_trylock (kernel/locking/spinlock_debug.c:216) [ 3268.777532][ C2] ? eth_header (net/ethernet/eth.c:100) [ 3268.777778][ C2] ? __pfx___dev_queue_xmit (net/core/dev.c:4246) [ 3268.778061][ C2] ? neigh_resolve_output (./include/linux/netdevice.h:3226 net/core/neighbour.c:1558 net/core/neighbour.c:1543) [ 3268.778376][ C2] ? __neigh_update (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/neighbour.c:1446) [ 3268.778644][ C2] __neigh_update (net/core/neighbour.c:1461) [ 3268.778917][ C2] arp_process (./include/linux/instrumented.h:96 (discriminator 4) ./include/linux/atomic/atomic-instrumented.h:400 (discriminator 4) ./include/linux/refcount.h:261 (discriminator 4) ./include/linux/refcount.h:304 (discriminator 4) ./include/linux/refcount.h:322 (discriminator 4) ./include/net/neighbour.h:444 (discriminator 4) net/ipv4/arp.c:934 (discriminator 4)) [ 3268.779169][ C2] ? __pfx_arp_process (net/ipv4/arp.c:699) [ 3268.779455][ C2] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5756) [ 3268.779734][ C2] ? __pfx_arp_rcv (net/ipv4/arp.c:965) [ 3268.779979][ C2] __netif_receive_skb_one_core (net/core/dev.c:5554 (discriminator 5)) [ 3268.780291][ C2] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5547) [ 3268.780626][ C2] ? __pfx_do_raw_spin_trylock (kernel/locking/spinlock_debug.c:122) [ 3268.780928][ C2] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5725) [ 3268.781175][ C2] ? process_backlog (./include/linux/rcupdate.h:298 ./include/linux/rcupdate.h:750 net/core/dev.c:5995) [ 3268.781443][ C2] process_backlog (./include/linux/rcupdate.h:779 net/core/dev.c:5997) [ 3268.781705][ C2] __napi_poll.constprop.0 (net/core/dev.c:6625) [ 3268.781994][ C2] net_rx_action (net/core/dev.c:6694 net/core/dev.c:6827) [ 3268.782281][ C2] ? __pfx_net_rx_action (net/core/dev.c:6791) [ 3268.782555][ C2] ? __pfx___schedule (kernel/sched/core.c:6608) [ 3268.782816][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5406) [ 3268.783102][ C2] __do_softirq (kernel/softirq.c:553) [ 3268.783379][ C2] ? __pfx_run_ksoftirqd (kernel/softirq.c:914) [ 3268.783654][ C2] run_ksoftirqd (kernel/softirq.c:410 kernel/softirq.c:922 kernel/softirq.c:913) [ 3268.783901][ C2] smpboot_thread_fn (kernel/smpboot.c:164 (discriminator 3)) [ 3268.784198][ C2] ? __pfx_smpboot_thread_fn (kernel/smpboot.c:107) [ 3268.784491][ C2] ? __pfx_smpboot_thread_fn (kernel/smpboot.c:107) [ 3268.784808][ C2] kthread (kernel/kthread.c:388) [ 3268.785024][ C2] ? __pfx_kthread (kernel/kthread.c:341) [ 3268.785290][ C2] ret_from_fork (arch/x86/kernel/process.c:147) [ 3268.785527][ C2] ? __pfx_kthread (kernel/kthread.c:341) Finger prints: dump_stack_lvl:__ubsan_handle_load_invalid_value:deliver_clone:maybe_deliver dump_stack_lvl:__ubsan_handle_load_invalid_value:__dev_forward_skb2:veth_xmit