======================================
| 0
| xx__-> [ 24.414632][ C1] ------------[ cut here ]------------
| [ 24.415253][ C1] WARNING: CPU: 1 PID: 303 at ./include/linux/skbuff.h:1164 ip_route_me_harder (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/netfilter.c:68)
| [ 24.416022][ C1] Modules linked in: nft_synproxy nf_synproxy_core nft_ct nf_tables veth nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4
[ 24.417596][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 24.418070][ C1] RIP: 0010:ip_route_me_harder (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/netfilter.c:68)
[ 24.418548][ C1] Code: 31 db e9 9a f7 ff ff 80 3c 02 00 0f 85 ee 05 00 00 49 8b 46 58 48 89 c3 48 83 e3 fe a8 01 0f 85 f5 02 00 00 48 85 db 74 04 90 <0f> 0b 90 48 b8 00 00 00 00 00 fc ff df 4c 89 ea 48 c1 ea 03 80 3c
All code
========
0: 31 db xor %ebx,%ebx
2: e9 9a f7 ff ff jmp 0xfffffffffffff7a1
7: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
b: 0f 85 ee 05 00 00 jne 0x5ff
11: 49 8b 46 58 mov 0x58(%r14),%rax
15: 48 89 c3 mov %rax,%rbx
18: 48 83 e3 fe and $0xfffffffffffffffe,%rbx
1c: a8 01 test $0x1,%al
1e: 0f 85 f5 02 00 00 jne 0x319
24: 48 85 db test %rbx,%rbx
27: 74 04 je 0x2d
29: 90 nop
2a:* 0f 0b ud2 <-- trapping instruction
2c: 90 nop
2d: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
34: fc ff df
37: 4c 89 ea mov %r13,%rdx
3a: 48 c1 ea 03 shr $0x3,%rdx
3e: 80 .byte 0x80
3f: 3c .byte 0x3c
Code starting with the faulting instruction
===========================================
0: 0f 0b ud2
2: 90 nop
3: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
a: fc ff df
d: 4c 89 ea mov %r13,%rdx
10: 48 c1 ea 03 shr $0x3,%rdx
14: 80 .byte 0x80
15: 3c .byte 0x3c
[ 24.419875][ C1] RSP: 0018:ffffc900001c03f8 EFLAGS: 00010282
[ 24.420350][ C1] RAX: ffff88800c06ef40 RBX: ffff88800c06ef40 RCX: 1ffff1100180dde8
[ 24.420914][ C1] RDX: 1ffff11001184813 RSI: 0000000000000000 RDI: ffff88800bdf40e0
[ 24.421483][ C1] RBP: ffff888004c88040 R08: 1ffff92000038091 R09: 0000000000000000
[ 24.422032][ C1] R10: ffffe8ffffc84f6f R11: dffffc0000000000 R12: 0000000000000000
[ 24.422579][ C1] R13: ffff888008c24098 R14: ffff888008c24040 R15: ffff888008c240c1
[ 24.423132][ C1] FS: 00007f53eda35d40(0000) GS:ffff88807d124000(0000) knlGS:0000000000000000
[ 24.423907][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 24.424364][ C1] CR2: 00007f53ee269730 CR3: 000000000ae52001 CR4: 0000000000772ef0
[ 24.424914][ C1] PKRU: 55555554
[ 24.425190][ C1] Call Trace:
[ 24.425445][ C1]
[ 24.425625][ C1] ? __pfx_ip_route_me_harder (net/ipv4/netfilter.c:22)
[ 24.425982][ C1] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)
[ 24.426425][ C1] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 24.426793][ C1] ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/preempt.h:104 ./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194)
[ 24.427241][ C1] ? __do_once_start (./include/linux/spinlock.h:406 lib/once.c:47 lib/once.c:42)
[ 24.427600][ C1] ? cookie_hash (net/ipv4/syncookies.c:48 (discriminator 9))
[ 24.427973][ C1] ? __pfx_cookie_hash (net/ipv4/syncookies.c:48)
[ 24.428352][ C1] synproxy_send_tcp.isra.0 (net/netfilter/nf_synproxy_core.c:431) nf_synproxy_core
[ 24.428901][ C1] synproxy_send_client_synack (net/netfilter/nf_synproxy_core.c:484) nf_synproxy_core
[ 24.429438][ C1] ? __pfx_synproxy_send_client_synack (net/netfilter/nf_synproxy_core.c:450) nf_synproxy_core
[ 24.429953][ C1] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:95 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86)
[ 24.430339][ C1] ? __mod_timer (kernel/time/timer.c:1118)
[ 24.430728][ C1] nft_synproxy_do_eval (net/netfilter/nft_synproxy.c:60 net/netfilter/nft_synproxy.c:141) nft_synproxy
[ 24.431198][ C1] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 24.431557][ C1] ? __pfx_nft_synproxy_do_eval (net/netfilter/nft_synproxy.c:109) nft_synproxy
[ 24.432008][ C1] ? unwind_next_frame (./include/linux/rcupdate.h:874 ./include/linux/rcupdate.h:1155 arch/x86/kernel/unwind_orc.c:479)
[ 24.432386][ C1] ? __tcp_transmit_skb (net/ipv4/tcp_output.c:1625 (discriminator 4))
[ 24.432763][ C1] nft_do_chain (net/netfilter/nf_tables_core.c:287) nf_tables
[ 24.433159][ C1] ? __pfx_nft_do_chain (net/netfilter/nf_tables_core.c:251) nf_tables
[ 24.433620][ C1] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 24.433973][ C1] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380)
[ 24.434313][ C1] ? validate_chain (kernel/locking/lockdep.c:3804 kernel/locking/lockdep.c:3824 kernel/locking/lockdep.c:3879)
[ 24.434652][ C1] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)
[ 24.435090][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 24.435438][ C1] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 24.435795][ C1] nft_do_chain_inet (net/netfilter/nft_chain_filter.c:145) nf_tables
[ 24.436284][ C1] ? __pfx_nft_do_chain_inet (net/netfilter/nft_chain_filter.c:145) nf_tables
[ 24.436765][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 24.437132][ C1] ? lock_acquire.part.0 (kernel/locking/lockdep.c:473 kernel/locking/lockdep.c:5873)
[ 24.437478][ C1] ? __pfx_nft_do_chain_inet (net/netfilter/nft_chain_filter.c:145) nf_tables
[ 24.437936][ C1] nf_hook_slow (./include/linux/netfilter.h:157 net/netfilter/core.c:623)
[ 24.438281][ C1] nf_hook.constprop.0 (./include/linux/netfilter.h:171 ./include/linux/netfilter.h:269)
[ 24.438623][ C1] ? __pfx_nf_hook.constprop.0 (./include/linux/netfilter.h:226)
[ 24.438968][ C1] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 24.439308][ C1] ? __pfx_ip_forward_finish (net/ipv4/ip_forward.c:66)
[ 24.439647][ C1] ? ip_dst_mtu_maybe_forward.constprop.0 (./include/linux/rcupdate.h:873 ./include/net/ip.h:501)
[ 24.440116][ C1] ip_forward (./include/linux/netfilter.h:316 net/ipv4/ip_forward.c:162)
[ 24.440485][ C1] ? skb_dst (net/ipv4/ip_input.c:1156 (discriminator 1))
[ 24.440774][ C1] ? __pfx_ip_rcv (net/ipv4/ip_input.c:567)
[ 24.441140][ C1] ? process_backlog (./include/linux/local_lock_internal.h:54 net/core/dev.c:6442)
[ 24.441508][ C1] __netif_receive_skb_one_core (net/core/dev.c:5979 (discriminator 4))
[ 24.441940][ C1] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5972)
[ 24.442365][ C1] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745)
[ 24.442719][ C1] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5834)
[ 24.443057][ C1] ? process_backlog (./include/linux/local_lock_internal.h:54 net/core/dev.c:6442)
[ 24.443428][ C1] process_backlog (./include/linux/rcupdate.h:869 net/core/dev.c:6445)
[ 24.443803][ C1] __napi_poll.constprop.0 (net/core/dev.c:7482)
[ 24.444165][ C1] net_rx_action (net/core/dev.c:7546 net/core/dev.c:7673)
[ 24.444531][ C1] ? __pfx_net_rx_action (net/core/dev.c:7635)
[ 24.444895][ C1] ? clockevents_program_event (kernel/time/clockevents.c:326)
[ 24.445253][ C1] ? __lock_release (kernel/locking/lockdep.c:5515)
[ 24.445598][ C1] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:95 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86)
[ 24.445944][ C1] ? ktime_get (kernel/time/timekeeping.c:251 (discriminator 4) kernel/time/timekeeping.c:360 (discriminator 4) kernel/time/timekeeping.c:778 (discriminator 4))
[ 24.446204][ C1] ? clockevents_program_event (kernel/time/clockevents.c:336 (discriminator 3))
[ 24.446633][ C1] handle_softirqs (kernel/softirq.c:579)
[ 24.446986][ C1] ? __dev_queue_xmit (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:908 net/core/dev.c:4740)
[ 24.447356][ C1] do_softirq (kernel/softirq.c:480 kernel/softirq.c:467)
[ 24.447625][ C1]
[ 24.447823][ C1]
[ 24.448005][ C1] __local_bh_enable_ip (kernel/softirq.c:407)
[ 24.448361][ C1] ? __dev_queue_xmit (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:908 net/core/dev.c:4740)
[ 24.448728][ C1] __dev_queue_xmit (net/core/dev.c:4741)
[ 24.449093][ C1] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 24.449439][ C1] ? __pfx___dev_queue_xmit (net/core/dev.c:4621)
[ 24.449792][ C1] ? neigh_hh_output (./include/linux/seqlock.h:74 ./include/linux/seqlock.h:836 ./include/net/neighbour.h:501)
[ 24.450165][ C1] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 24.450538][ C1] ? neigh_hh_output (./include/linux/seqlock.h:74 ./include/linux/seqlock.h:836 ./include/net/neighbour.h:501)
[ 24.450926][ C1] ip_finish_output2 (./include/net/neighbour.h:545 net/ipv4/ip_output.c:235)
[ 24.451311][ C1] ? ip_skb_dst_mtu (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 ./include/net/ip.h:501 ./include/net/ip.h:515)
[ 24.451649][ C1] ? __pfx_ip_finish_output2 (net/ipv4/ip_output.c:199)
[ 24.452002][ C1] ? __ip_finish_output (./include/linux/skbuff.h:1685 ./include/linux/skbuff.h:5079 net/ipv4/ip_output.c:307 net/ipv4/ip_output.c:295)
[ 24.452379][ C1] __ip_queue_xmit (./include/net/dst.h:461 net/ipv4/ip_output.c:129 net/ipv4/ip_output.c:527)
[ 24.452745][ C1] ? __skb_clone (./arch/x86/include/asm/atomic.h:53 (discriminator 4) ./include/linux/atomic/atomic-arch-fallback.h:992 (discriminator 4) ./include/linux/atomic/atomic-instrumented.h:436 (discriminator 4) net/core/skbuff.c:1566 (discriminator 4))
[ 24.453110][ C1] __tcp_transmit_skb (net/ipv4/tcp_output.c:1625 (discriminator 4))
[ 24.453478][ C1] ? __pfx___tcp_transmit_skb (net/ipv4/tcp_output.c:1446)
[ 24.453838][ C1] tcp_connect (net/ipv4/tcp_output.c:1643 net/ipv4/tcp_output.c:4319)
[ 24.454183][ C1] tcp_v4_connect (net/ipv4/tcp_ipv4.c:346)
[ 24.454531][ C1] ? __pfx_tcp_v4_connect (net/ipv4/tcp_ipv4.c:224)
[ 24.454878][ C1] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116)
[ 24.455221][ C1] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 24.455568][ C1] __inet_stream_connect (net/ipv4/af_inet.c:677)
[ 24.455916][ C1] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:412)
[ 24.456293][ C1] ? __pfx_inet_stream_connect (net/ipv4/af_inet.c:744)
[ 24.456650][ C1] inet_stream_connect (net/ipv4/af_inet.c:749)
[ 24.457018][ C1] __sys_connect (net/socket.c:2086 net/socket.c:2105)
[ 24.457377][ C1] ? __pfx___sys_connect (net/socket.c:2093)
[ 24.457740][ C1] ? fd_install (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:953 fs/file.c:661)
[ 24.458106][ C1] ? fd_install (./arch/x86/include/asm/preempt.h:104 ./include/linux/rcupdate.h:955 fs/file.c:661)
[ 24.458463][ C1] ? __sys_socket (net/socket.c:503 net/socket.c:1740)
[ 24.458829][ C1] ? __pfx___sys_socket (net/socket.c:1727)
[ 24.459202][ C1] __x64_sys_connect (net/socket.c:2108)
[ 24.459539][ C1] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 24.459888][ C1] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
[ 24.460295][ C1] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
[ 24.460759][ C1] RIP: 0033:0x7f53ee24ad77
[ 24.461177][ C1] Code: 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2a 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 18 89 54 24 0c 48 89 34 24 89
All code
========
0: 64 89 01 mov %eax,%fs:(%rcx)
3: 48 83 c8 ff or $0xffffffffffffffff,%rax
7: c3 ret
8: 66 2e 0f 1f 84 00 00 cs nopw 0x0(%rax,%rax,1)
f: 00 00 00
12: 90 nop
13: f3 0f 1e fa endbr64
17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax
1e: 00
1f: 85 c0 test %eax,%eax
21: 75 10 jne 0x33
23: b8 2a 00 00 00 mov $0x2a,%eax
28: 0f 05 syscall
2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction
30: 77 51 ja 0x83
32: c3 ret
33: 48 83 ec 18 sub $0x18,%rsp
37: 89 54 24 0c mov %edx,0xc(%rsp)
3b: 48 89 34 24 mov %rsi,(%rsp)
3f: 89 .byte 0x89
Code starting with the faulting instruction
===========================================
0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax
6: 77 51 ja 0x59
8: c3 ret
9: 48 83 ec 18 sub $0x18,%rsp
d: 89 54 24 0c mov %edx,0xc(%rsp)
11: 48 89 34 24 mov %rsi,(%rsp)
15: 89 .byte 0x89
[ 24.462405][ C1] RSP: 002b:00007ffd9275a9a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
[ 24.462930][ C1] RAX: ffffffffffffffda RBX: 00000000ffffffff RCX: 00007f53ee24ad77
[ 24.463451][ C1] RDX: 0000000000000010 RSI: 000055fb90705c50 RDI: 0000000000000006
[ 24.463973][ C1] RBP: 0000000000000006 R08: 0000000000000003 R09: 0000000000000000
[ 24.464527][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000010
Finger prints:
ip_route_me_harder:synproxy_send_client_synack:nft_synproxy_do_eval:nft_do_chain:nft_do_chain_inet