====================================== | [ 383.959539][ T2971] 1 lock held by iptables/2971: | [ 383.959952][ T2971] #0: ffff8880053f2cc8 (&nft_net->commit_mutex){+.+.}-{3:3}, at: nf_tables_valid_genid (./include/linux/jiffies.h:101 net/netfilter/nf_tables_api.c:10954) nf_tables | [ 383.960378][ T2971] | [ 383.960378][ T2971] stack backtrace: [ 383.960841][ T2971] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 383.961199][ T2971] Call Trace: [ 383.961327][ T2971] [ 383.961415][ T2971] dump_stack_lvl (lib/dump_stack.c:123) [ 383.961592][ T2971] lockdep_rcu_suspicious (kernel/locking/lockdep.c:6822) [ 383.961763][ T2971] __nft_rule_lookup (net/netfilter/nf_tables_api.c:3420 (discriminator 7)) nf_tables [ 383.961989][ T2971] nf_tables_delrule (net/netfilter/nf_tables_api.c:4300) nf_tables [ 383.962217][ T2971] ? __lock_release (kernel/locking/lockdep.c:5501) [ 383.962393][ T2971] ? net_generic (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 ./include/net/netns/generic.h:48) [ 383.962565][ T2971] ? __pfx_nf_tables_delrule (net/netfilter/nf_tables_api.c:4262) nf_tables [ 383.962790][ T2971] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 52)) [ 383.962962][ T2971] ? __nla_validate_parse (lib/nlattr.c:638) [ 383.963136][ T2971] nfnetlink_rcv_batch (net/netfilter/nfnetlink.c:524) [ 383.963314][ T2971] ? __pfx_nfnetlink_rcv_batch (net/netfilter/nfnetlink.c:373) [ 383.963479][ T2971] ? rcu_read_lock_any_held (kernel/rcu/update.c:387 kernel/rcu/update.c:380) [ 383.963647][ T2971] ? find_stack (lib/stackdepot.c:552 (discriminator 1)) [ 383.963815][ T2971] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 383.963982][ T2971] ? validate_chain (kernel/locking/lockdep.c:3797 kernel/locking/lockdep.c:3817 kernel/locking/lockdep.c:3872) [ 383.964161][ T2971] ? __pfx_validate_chain (kernel/locking/lockdep.c:3860) [ 383.964332][ T2971] ? __lock_acquire (kernel/locking/lockdep.c:5202) [ 383.964496][ T2971] ? __pfx_validate_nla (lib/nlattr.c:396) [ 383.964665][ T2971] ? find_held_lock (kernel/locking/lockdep.c:5315) [ 383.964833][ T2971] ? __nla_validate_parse (lib/nlattr.c:638) [ 383.965010][ T2971] nfnetlink_rcv (net/netfilter/nfnetlink.c:647 net/netfilter/nfnetlink.c:665) [ 383.965172][ T2971] ? __pfx_nfnetlink_rcv (net/netfilter/nfnetlink.c:651) [ 383.965339][ T2971] ? netlink_deliver_tap (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 ./include/net/netns/generic.h:48 net/netlink/af_netlink.c:333) [ 383.965508][ T2971] netlink_unicast (net/netlink/af_netlink.c:1331 net/netlink/af_netlink.c:1357) [ 383.965676][ T2971] ? __pfx_netlink_unicast (net/netlink/af_netlink.c:1342) [ 383.965843][ T2971] ? find_held_lock (kernel/locking/lockdep.c:5315) [ 383.966012][ T2971] netlink_sendmsg (net/netlink/af_netlink.c:1901) [ 383.966180][ T2971] ? __pfx_netlink_sendmsg (net/netlink/af_netlink.c:1820) [ 383.966344][ T2971] ? __might_fault (mm/memory.c:6705 mm/memory.c:6698) [ 383.966513][ T2971] ? __import_iovec (lib/iov_iter.c:1433 lib/iov_iter.c:1449) [ 383.966688][ T2971] ____sys_sendmsg (net/socket.c:729 net/socket.c:744 net/socket.c:2607) [ 383.966858][ T2971] ? __pfx_____sys_sendmsg (net/socket.c:2553) [ 383.967020][ T2971] ? __pfx_copy_msghdr_from_user (net/socket.c:2533) [ 383.967229][ T2971] ? sk_setsockopt (net/core/sock.c:1129 net/core/sock.c:1621) [ 383.967391][ T2971] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:97 kernel/softirq.c:387) [ 383.967563][ T2971] ___sys_sendmsg (net/socket.c:2663) [ 383.967735][ T2971] ? __pfx____sys_sendmsg (net/socket.c:2650) [ 383.967912][ T2971] ? __lock_acquire (kernel/locking/lockdep.c:5202) [ 383.968081][ T2971] ? usage_skip (kernel/locking/lockdep.c:2314) [ 383.968248][ T2971] ? trace_kfree (./include/trace/events/kmem.h:94 (discriminator 52)) [ 383.968430][ T2971] ? kfree (mm/slub.c:4716) [ 383.968560][ T2971] ? do_sock_setsockopt (net/socket.c:2303) [ 383.968726][ T2971] ? __pfx_do_sock_setsockopt (net/socket.c:2303) [ 383.968896][ T2971] ? fdget (./include/linux/atomic/atomic-arch-fallback.h:479 ./include/linux/atomic/atomic-instrumented.h:50 fs/file.c:1114 fs/file.c:1128) [ 383.969033][ T2971] __sys_sendmsg (./include/linux/file.h:35 net/socket.c:2692) [ 383.969201][ T2971] ? __pfx___sys_sendmsg (net/socket.c:2678) [ 383.969364][ T2971] ? __sys_setsockopt (./include/linux/file.h:35 net/socket.c:2359) [ 383.969534][ T2971] ? __pfx___sys_setsockopt (net/socket.c:2347) [ 383.969712][ T2971] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 383.969879][ T2971] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 383.970083][ T2971] RIP: 0033:0x7f08288ce7b7 [ 383.970252][ T2971] Code: 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 All code ======== 0: 0a 00 or (%rax),%al 2: f7 d8 neg %eax 4: 64 89 02 mov %eax,%fs:(%rdx) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b9 jmp 0xffffffffffffffc9 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 2e 00 00 00 mov $0x2e,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 89 54 24 1c mov %edx,0x1c(%rsp) 3b: 48 89 74 24 10 mov %rsi,0x10(%rsp) Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 89 54 24 1c mov %edx,0x1c(%rsp) 11: 48 89 74 24 10 mov %rsi,0x10(%rsp) [ 383.970833][ T2971] RSP: 002b:00007ffe97b675e8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 383.971082][ T2971] RAX: ffffffffffffffda RBX: 00007ffe97b675f0 RCX: 00007f08288ce7b7 [ 383.971327][ T2971] RDX: 0000000000000000 RSI: 00007ffe97b68680 RDI: 0000000000000005 [ 383.971569][ T2971] RBP: 00007ffe97b68c80 R08: 0000000000000004 R09: 0000000000000000 [ 383.971818][ T2971] R10: 00007ffe97b6866c R11: 0000000000000246 R12: 0000000000004000 Finger prints: lockdep_rcu_suspicious:__nft_rule_lookup:nf_tables_delrule:nfnetlink_rcv_batch:nfnetlink_rcv