======================================
| [ 1106.917143] #PF: supervisor read access in kernel mode
| [ 1106.917179] #PF: error_code(0x0000) - not-present page
| [ 1106.917216] PGD 0 P4D 0
| [ 1106.917245] Oops: 0000 [#1] PREEMPT SMP NOPTI
[ 1106.917339] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[ 1106.917413] RIP: 0010:sock_wfree (./arch/x86/include/asm/bitops.h:206 ./arch/x86/include/asm/bitops.h:238 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 net/core/sock.c:3399 net/core/sock.c:2470)
[ 1106.917458] Code: 6b 45 6b ff 84 db 0f 84 b6 fe ff ff e9 10 ff ff ff be 03 00 00 00 4c 89 e7 e8 41 8a a6 ff e9 61 ff ff ff 48 8b 85 20 01 00 00 <48> 8b 50 08 83 e2 04 74 cc f0 80 60 08 fb eb 99 48 8b bd 00 01 00
All code
========
0: 6b 45 6b ff imul $0xffffffff,0x6b(%rbp),%eax
4: 84 db test %bl,%bl
6: 0f 84 b6 fe ff ff je 0xfffffffffffffec2
c: e9 10 ff ff ff jmp 0xffffffffffffff21
11: be 03 00 00 00 mov $0x3,%esi
16: 4c 89 e7 mov %r12,%rdi
19: e8 41 8a a6 ff call 0xffffffffffa68a5f
1e: e9 61 ff ff ff jmp 0xffffffffffffff84
23: 48 8b 85 20 01 00 00 mov 0x120(%rbp),%rax
2a:* 48 8b 50 08 mov 0x8(%rax),%rdx <-- trapping instruction
2e: 83 e2 04 and $0x4,%edx
31: 74 cc je 0xffffffffffffffff
33: f0 80 60 08 fb lock andb $0xfb,0x8(%rax)
38: eb 99 jmp 0xffffffffffffffd3
3a: 48 rex.W
3b: 8b .byte 0x8b
3c: bd .byte 0xbd
3d: 00 01 add %al,(%rcx)
...
Code starting with the faulting instruction
===========================================
0: 48 8b 50 08 mov 0x8(%rax),%rdx
4: 83 e2 04 and $0x4,%edx
7: 74 cc je 0xffffffffffffffd5
9: f0 80 60 08 fb lock andb $0xfb,0x8(%rax)
e: eb 99 jmp 0xffffffffffffffa9
10: 48 rex.W
11: 8b .byte 0x8b
12: bd .byte 0xbd
13: 00 01 add %al,(%rcx)
...
[ 1106.917567] RSP: 0018:ffffbeb54011ce30 EFLAGS: 00010206
[ 1106.917603] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000003dc0
[ 1106.917654] RDX: 0000000000001d40 RSI: ffff9a64471a8000 RDI: 0000000000000000
[ 1106.917704] RBP: ffff9a64419639c0 R08: ffff9a64421788ac R09: 0000000000000001
[ 1106.917755] R10: ffffffff836060c0 R11: ffffbeb54011cff8 R12: ffff9a6441963b3c
[ 1106.917806] R13: 000000000000004b R14: 0000000000000000 R15: ffff9a64471a8000
[ 1106.917858] FS: 0000000000000000(0000) GS:ffff9a647ed00000(0000) knlGS:0000000000000000
[ 1106.917908] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 1106.917953] CR2: 0000000000000008 CR3: 000000000b444005 CR4: 0000000000770ef0
[ 1106.918014] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 1106.918064] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[ 1106.918114] PKRU: 55555554
[ 1106.918129] Call Trace:
[ 1106.918151]
[ 1106.918177] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)
[ 1106.918216] ? page_fault_oops (arch/x86/mm/fault.c:713)
[ 1106.918251] ? find_busiest_group (kernel/sched/fair.c:10845)
[ 1106.918287] ? exc_page_fault (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/mm/fault.c:1513 arch/x86/mm/fault.c:1563)
[ 1106.918322] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:623)
[ 1106.918354] ? sock_wfree (./arch/x86/include/asm/bitops.h:206 ./arch/x86/include/asm/bitops.h:238 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 net/core/sock.c:3399 net/core/sock.c:2470)
[ 1106.918381] skb_release_head_state (net/core/skbuff.c:1162)
[ 1106.918418] consume_skb (net/core/skbuff.c:1174 net/core/skbuff.c:1189 net/core/skbuff.c:1411 net/core/skbuff.c:1405)
[ 1106.918449] dummy_xmit (drivers/net/dummy.c:66)
[ 1106.918480] dev_hard_start_xmit (./include/linux/netdevice.h:4877 ./include/linux/netdevice.h:4891 net/core/dev.c:3564 net/core/dev.c:3580)
[ 1106.918515] sch_direct_xmit (net/sched/sch_generic.c:343)
[ 1106.918551] __qdisc_run (net/sched/sch_generic.c:416)
[ 1106.918581] ? __hrtimer_run_queues (kernel/time/hrtimer.c:1707 kernel/time/hrtimer.c:1756)
[ 1106.918617] net_tx_action (./include/net/sch_generic.h:217 ./include/net/pkt_sched.h:128 ./include/net/pkt_sched.h:124 net/core/dev.c:5267)
[ 1106.918645] __do_softirq (kernel/softirq.c:554)
[ 1106.918683] irq_exit_rcu (kernel/softirq.c:428 kernel/softirq.c:633 kernel/softirq.c:645)
[ 1106.918715] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1043 arch/x86/kernel/apic/apic.c:1043)
[ 1106.918757]
[ 1106.918775]
[ 1106.918790] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702)
[ 1106.918830] RIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:72 arch/x86/kernel/process.c:743)
[ 1106.918861] Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d d3 fb 24 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90
All code
========
0: 4c 01 c7 add %r8,%rdi
3: 4c 29 c2 sub %r8,%rdx
6: e9 72 ff ff ff jmp 0xffffffffffffff7d
b: 90 nop
c: 90 nop
d: 90 nop
e: 90 nop
f: 90 nop
10: 90 nop
11: 90 nop
12: 90 nop
13: 90 nop
14: 90 nop
15: 90 nop
16: 90 nop
17: 90 nop
18: 90 nop
19: 90 nop
1a: 90 nop
1b: f3 0f 1e fa endbr64
1f: 66 90 xchg %ax,%ax
21: 0f 00 2d d3 fb 24 00 verw 0x24fbd3(%rip) # 0x24fbfb
28: fb sti
29: f4 hlt
2a:* fa cli <-- trapping instruction
2b: c3 ret
2c: cc int3
2d: cc int3
2e: cc int3
2f: cc int3
30: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
37: 00 00 00 00
3b: 90 nop
3c: 90 nop
3d: 90 nop
3e: 90 nop
3f: 90 nop
Code starting with the faulting instruction
===========================================
0: fa cli
1: c3 ret
2: cc int3
3: cc int3
4: cc int3
5: cc int3
6: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
d: 00 00 00 00
11: 90 nop
12: 90 nop
13: 90 nop
14: 90 nop
15: 90 nop
[ 1106.918997] RSP: 0018:ffffbeb5400b3ee8 EFLAGS: 00000256
[ 1106.919032] RAX: ffff9a647ed00000 RBX: ffff9a6441378000 RCX: 0000000000000000
[ 1106.919084] RDX: 4000000000000000 RSI: ffffffff832a1591 RDI: 0000000008ee7fcc
[ 1106.919135] RBP: 0000000000000002 R08: 0000000008ee7fcc R09: 0000000000000001
[ 1106.919190] R10: 0000000000000001 R11: 0000000000000002 R12: 0000000000000000
[ 1106.919235] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
[ 1106.919287] default_idle_call (./include/linux/cpuidle.h:144 kernel/sched/idle.c:118)
[ 1106.919314] do_idle (kernel/sched/idle.c:192 kernel/sched/idle.c:332)
[ 1106.919345] cpu_startup_entry (kernel/sched/idle.c:429 (discriminator 1))
[ 1106.919371] start_secondary (arch/x86/kernel/smpboot.c:313)
Finger prints:
sock_wfree:skb_release_head_state:consume_skb:dummy_xmit