====================================== | [ 2900.792961] #PF: supervisor read access in kernel mode | [ 2900.793017] #PF: error_code(0x0000) - not-present page | [ 2900.793053] PGD 8fd6067 P4D 8fd6067 PUD 6402067 PMD 0 | [ 2900.793097] Oops: Oops: 0000 [#1] SMP NOPTI [ 2900.793200] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 2900.793245] RIP: 0010:ip6_pol_route (./include/net/net_namespace.h:409 ./include/linux/netdevice.h:2713 net/ipv6/route.c:1418 net/ipv6/route.c:1467 net/ipv6/route.c:2304) [ 2900.793290] Code: 0c 24 0f 85 fb 01 00 00 09 ca 0f 88 2f 01 00 00 e8 cf 11 43 ff 83 cb 08 48 8d 7c 24 18 e8 32 7b ff ff 0f b7 cb ba ff ff ff ff <4c> 8b 80 08 01 00 00 48 89 c6 49 89 c7 49 8d b8 80 06 00 00 4c 89 All code ======== 0: 0c 24 or $0x24,%al 2: 0f 85 fb 01 00 00 jne 0x203 8: 09 ca or %ecx,%edx a: 0f 88 2f 01 00 00 js 0x13f 10: e8 cf 11 43 ff call 0xffffffffff4311e4 15: 83 cb 08 or $0x8,%ebx 18: 48 8d 7c 24 18 lea 0x18(%rsp),%rdi 1d: e8 32 7b ff ff call 0xffffffffffff7b54 22: 0f b7 cb movzwl %bx,%ecx 25: ba ff ff ff ff mov $0xffffffff,%edx 2a:* 4c 8b 80 08 01 00 00 mov 0x108(%rax),%r8 <-- trapping instruction 31: 48 89 c6 mov %rax,%rsi 34: 49 89 c7 mov %rax,%r15 37: 49 8d b8 80 06 00 00 lea 0x680(%r8),%rdi 3e: 4c rex.WR 3f: 89 .byte 0x89 Code starting with the faulting instruction =========================================== 0: 4c 8b 80 08 01 00 00 mov 0x108(%rax),%r8 7: 48 89 c6 mov %rax,%rsi a: 49 89 c7 mov %rax,%r15 d: 49 8d b8 80 06 00 00 lea 0x680(%r8),%rdi 14: 4c rex.WR 15: 89 .byte 0x89 [ 2900.793422] RSP: 0018:ffffc08a0932f480 EFLAGS: 00010246 [ 2900.793460] RAX: 0000000000000000 RBX: 0000000000000008 RCX: 0000000000000008 [ 2900.793521] RDX: 00000000ffffffff RSI: ffffc08a0932f740 RDI: ffff9adac8c8f1a8 [ 2900.793580] RBP: ffff9adac87458c0 R08: 0000000000000000 R09: 0000000000000000 [ 2900.793635] R10: 0000000000000000 R11: 0000000000000040 R12: ffff9adac82e362c [ 2900.793692] R13: ffff9adac82e3600 R14: 0000000000000080 R15: 0000000000000000 [ 2900.793752] FS: 00007f3418913740(0000) GS:ffff9adb7373a000(0000) knlGS:0000000000000000 [ 2900.793816] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2900.793864] CR2: 0000000000000108 CR3: 0000000008007004 CR4: 0000000000772ef0 [ 2900.793920] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 2900.793977] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 2900.794031] PKRU: 55555554 [ 2900.794050] Call Trace: [ 2900.794070] [ 2900.794090] ? __pfx_ip6_pol_route_output (net/ipv6/route.c:2649) [ 2900.794131] fib6_rule_action (./include/net/ip6_fib.h:617 net/ipv6/fib6_rules.c:237 net/ipv6/fib6_rules.c:275) [ 2900.794166] fib_rules_lookup (net/core/fib_rules.c:339 (discriminator 1)) [ 2900.794200] ? __pfx_ip6_pol_route_output (net/ipv6/route.c:2649) [ 2900.794241] fib6_rule_lookup (net/ipv6/fib6_rules.c:115) [ 2900.794271] ? __pfx_ip6_pol_route_output (net/ipv6/route.c:2649) [ 2900.794310] ip6_route_output_flags (net/ipv6/route.c:2683 net/ipv6/route.c:2695) [ 2900.794353] ip6_dst_lookup_tail.constprop.0 (net/ipv6/ip6_output.c:1156) [ 2900.794394] ip6_dst_lookup_flow (net/ipv6/ip6_output.c:1260) [ 2900.794422] vrf_xmit (drivers/net/vrf.c:436 drivers/net/vrf.c:556 drivers/net/vrf.c:568) [ 2900.794459] dev_hard_start_xmit (./include/linux/netdevice.h:5215 ./include/linux/netdevice.h:5224 net/core/dev.c:3828 net/core/dev.c:3844) [ 2900.794492] __dev_queue_xmit (net/core/dev.h:356 net/core/dev.c:4712) [ 2900.794519] ? finish_task_switch.isra.0 (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/sched/sched.h:1544 kernel/sched/core.c:5144 kernel/sched/core.c:5262) [ 2900.794561] ? __schedule (kernel/sched/core.c:6791) [ 2900.794595] ? timerqueue_del (lib/timerqueue.c:58) [ 2900.794624] ? __remove_hrtimer (kernel/time/hrtimer.c:1121) [ 2900.794654] ? hrtimer_try_to_cancel.part.0 (kernel/time/hrtimer.c:1371) [ 2900.794694] ip6_finish_output2 (./include/linux/netdevice.h:3355 ./include/net/neighbour.h:523 ./include/net/neighbour.h:537 net/ipv6/ip6_output.c:141) [ 2900.794728] ? tcp_poll (./include/net/sock.h:1390 net/ipv4/tcp.c:589) [ 2900.794761] ? poll_freewait (fs/select.c:140 (discriminator 3)) [ 2900.794795] ip6_finish_output (net/ipv6/ip6_output.c:215 net/ipv6/ip6_output.c:226) [ 2900.794824] ip6_xmit (./include/net/dst.h:459 ./include/linux/netfilter.h:317 ./include/linux/netfilter.h:311 net/ipv6/ip6_output.c:366) [ 2900.794852] ? ip6_dst_check (net/ipv6/route.c:2816) [ 2900.794883] ? __sk_dst_check (net/core/sock.c:605 (discriminator 1)) [ 2900.794917] ? inet6_csk_route_socket (net/ipv6/inet6_connection_sock.c:61 (discriminator 3) net/ipv6/inet6_connection_sock.c:89 (discriminator 3)) [ 2900.794956] ? __pfx_pollwake (fs/select.c:209) [ 2900.794984] inet6_csk_xmit (net/ipv6/inet6_connection_sock.c:120) [ 2900.795012] __tcp_transmit_skb (net/ipv4/tcp_output.c:1726 (discriminator 1)) [ 2900.795044] ? lock_timer_base (kernel/time/timer.c:1004) [ 2900.795080] tcp_write_xmit (net/ipv4/tcp_output.c:3090) [ 2900.795114] __tcp_push_pending_frames (net/ipv4/tcp_output.c:3273) [ 2900.795152] tcp_sendmsg_locked (net/ipv4/tcp.c:1360) [ 2900.795191] tcp_sendmsg (net/ipv4/tcp.c:1398) [ 2900.795220] sock_write_iter (net/socket.c:712 net/socket.c:727 net/socket.c:1131) [ 2900.795248] vfs_write (fs/read_write.c:593 fs/read_write.c:686) [ 2900.795277] ksys_write (fs/read_write.c:738) [ 2900.795305] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 2900.795334] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 2900.795378] RIP: 0033:0x7f3418a54b77 [ 2900.795410] Code: 0b 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24 All code ======== 0: 0b 00 or (%rax),%eax 2: f7 d8 neg %eax 4: 64 89 02 mov %eax,%fs:(%rdx) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b7 jmp 0xffffffffffffffc7 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 01 00 00 00 mov $0x1,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 48 89 54 24 18 mov %rdx,0x18(%rsp) 3c: 48 rex.W 3d: 89 .byte 0x89 3e: 74 24 je 0x64 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 48 89 54 24 18 mov %rdx,0x18(%rsp) 12: 48 rex.W 13: 89 .byte 0x89 14: 74 24 je 0x3a [ 2900.795545] RSP: 002b:00007ffd14774f28 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 2900.795604] RAX: ffffffffffffffda RBX: 000000000000001c RCX: 00007f3418a54b77 [ 2900.795661] RDX: 000000000000000c RSI: 00007ffd14775000 RDI: 0000000000000006 [ 2900.795719] RBP: 00007ffd14774f70 R08: 000000000000000c R09: 0000000000000000 [ 2900.795777] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000006 Finger prints: ip6_pol_route:fib6_rule_action:fib_rules_lookup:fib6_rule_lookup:ip6_route_output_flags