======================================
| 0
| xx__-> [ 57.143734][ C3] ------------[ cut here ]------------
| [ 57.144288][ C3] WARNING: CPU: 3 PID: 858 at ./include/linux/skbuff.h:1164 ip_route_me_harder (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/netfilter.c:68)
| [ 57.145024][ C3] Modules linked in: nft_synproxy nf_synproxy_core nft_ct nf_conntrack_netlink veth nft_nat nft_numgen nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables
[ 57.146955][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 57.147432][ C3] RIP: 0010:ip_route_me_harder (./include/linux/skbuff.h:1164 ./include/linux/skbuff.h:1178 net/ipv4/netfilter.c:68)
[ 57.147910][ C3] Code: 31 db e9 9a f7 ff ff 80 3c 02 00 0f 85 ee 05 00 00 49 8b 46 58 48 89 c3 48 83 e3 fe a8 01 0f 85 f5 02 00 00 48 85 db 74 04 90 <0f> 0b 90 48 b8 00 00 00 00 00 fc ff df 4c 89 ea 48 c1 ea 03 80 3c
All code
========
0: 31 db xor %ebx,%ebx
2: e9 9a f7 ff ff jmp 0xfffffffffffff7a1
7: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
b: 0f 85 ee 05 00 00 jne 0x5ff
11: 49 8b 46 58 mov 0x58(%r14),%rax
15: 48 89 c3 mov %rax,%rbx
18: 48 83 e3 fe and $0xfffffffffffffffe,%rbx
1c: a8 01 test $0x1,%al
1e: 0f 85 f5 02 00 00 jne 0x319
24: 48 85 db test %rbx,%rbx
27: 74 04 je 0x2d
29: 90 nop
2a:* 0f 0b ud2 <-- trapping instruction
2c: 90 nop
2d: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
34: fc ff df
37: 4c 89 ea mov %r13,%rdx
3a: 48 c1 ea 03 shr $0x3,%rdx
3e: 80 .byte 0x80
3f: 3c .byte 0x3c
Code starting with the faulting instruction
===========================================
0: 0f 0b ud2
2: 90 nop
3: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
a: fc ff df
d: 4c 89 ea mov %r13,%rdx
10: 48 c1 ea 03 shr $0x3,%rdx
14: 80 .byte 0x80
15: 3c .byte 0x3c
[ 57.149216][ C3] RSP: 0018:ffffc900002703f8 EFLAGS: 00010282
[ 57.149680][ C3] RAX: ffff888017edd540 RBX: ffff888017edd540 RCX: 1ffff11002fdbaa8
[ 57.150242][ C3] RDX: 1ffff11000a31793 RSI: 0000000000000000 RDI: ffff88800e1b90e0
[ 57.150806][ C3] RBP: ffff888009461bc0 R08: 1ffff9200004e091 R09: 0000000000000000
[ 57.151354][ C3] R10: ffffe8ffffd84f47 R11: dffffc0000000000 R12: 0000000000000000
[ 57.151908][ C3] R13: ffff88800518bc98 R14: ffff88800518bc40 R15: ffff88800518bcc1
[ 57.152459][ C3] FS: 00007fabec20ed40(0000) GS:ffff888079424000(0000) knlGS:0000000000000000
[ 57.153105][ C3] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 57.153563][ C3] CR2: 00007fabeca42730 CR3: 000000000b8eb005 CR4: 0000000000772ef0
[ 57.154135][ C3] PKRU: 55555554
[ 57.154607][ C3] Call Trace:
[ 57.154893][ C3]
[ 57.155092][ C3] ? __pfx_ip_route_me_harder (net/ipv4/netfilter.c:22)
[ 57.155469][ C3] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)
[ 57.155929][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 57.156294][ C3] ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/preempt.h:104 ./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194)
[ 57.156747][ C3] ? __do_once_start (./include/linux/spinlock.h:406 lib/once.c:47 lib/once.c:42)
[ 57.157123][ C3] ? cookie_hash (net/ipv4/syncookies.c:48 (discriminator 9))
[ 57.157491][ C3] ? __pfx_cookie_hash (net/ipv4/syncookies.c:48)
[ 57.157876][ C3] synproxy_send_tcp.isra.0 (net/netfilter/nf_synproxy_core.c:431) nf_synproxy_core
[ 57.158433][ C3] synproxy_send_client_synack (net/netfilter/nf_synproxy_core.c:484) nf_synproxy_core
[ 57.158990][ C3] ? __pfx_synproxy_send_client_synack (net/netfilter/nf_synproxy_core.c:450) nf_synproxy_core
[ 57.159532][ C3] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:95 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86)
[ 57.159906][ C3] ? __mod_timer (kernel/time/timer.c:1118)
[ 57.160279][ C3] nft_synproxy_do_eval (net/netfilter/nft_synproxy.c:60 net/netfilter/nft_synproxy.c:141) nft_synproxy
[ 57.160740][ C3] ? __lock_release (kernel/locking/lockdep.c:5539)
[ 57.161114][ C3] ? __pfx_nft_synproxy_do_eval (net/netfilter/nft_synproxy.c:109) nft_synproxy
[ 57.161570][ C3] ? unwind_next_frame (./include/linux/rcupdate.h:874 ./include/linux/rcupdate.h:1155 arch/x86/kernel/unwind_orc.c:479)
[ 57.161942][ C3] ? __tcp_transmit_skb (net/ipv4/tcp_output.c:1625 (discriminator 4))
[ 57.162317][ C3] nft_do_chain (net/netfilter/nf_tables_core.c:287) nf_tables
[ 57.162721][ C3] ? __pfx_nft_do_chain (net/netfilter/nf_tables_core.c:251) nf_tables
[ 57.163208][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 57.163577][ C3] ? rcu_read_lock_any_held (kernel/rcu/update.c:386 kernel/rcu/update.c:380)
[ 57.163957][ C3] ? validate_chain (kernel/locking/lockdep.c:3804 kernel/locking/lockdep.c:3824 kernel/locking/lockdep.c:3879)
[ 57.164321][ C3] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)
[ 57.164788][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 57.165159][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 57.165527][ C3] nft_do_chain_inet (net/netfilter/nft_chain_filter.c:145) nf_tables
[ 57.166024][ C3] ? __pfx_nft_do_chain_inet (net/netfilter/nft_chain_filter.c:145) nf_tables
[ 57.166504][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 57.166880][ C3] ? lock_acquire.part.0 (kernel/locking/lockdep.c:473 kernel/locking/lockdep.c:5873)
[ 57.167249][ C3] ? __pfx_nft_do_chain_inet (net/netfilter/nft_chain_filter.c:145) nf_tables
[ 57.167734][ C3] nf_hook_slow (./include/linux/netfilter.h:157 net/netfilter/core.c:623)
[ 57.168109][ C3] nf_hook.constprop.0 (./include/linux/netfilter.h:171 ./include/linux/netfilter.h:269)
[ 57.168477][ C3] ? __pfx_nf_hook.constprop.0 (./include/linux/netfilter.h:226)
[ 57.168845][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 57.169213][ C3] ? __pfx_ip_forward_finish (net/ipv4/ip_forward.c:66)
[ 57.169577][ C3] ? ip_dst_mtu_maybe_forward.constprop.0 (./include/linux/rcupdate.h:873 ./include/net/ip.h:501)
[ 57.170046][ C3] ip_forward (./include/linux/netfilter.h:316 net/ipv4/ip_forward.c:162)
[ 57.170412][ C3] ? skb_dst (net/ipv4/ip_input.c:1156 (discriminator 1))
[ 57.170690][ C3] ? __pfx_ip_rcv (net/ipv4/ip_input.c:567)
[ 57.171065][ C3] ? process_backlog (./include/linux/local_lock_internal.h:54 net/core/dev.c:6442)
[ 57.171429][ C3] __netif_receive_skb_one_core (net/core/dev.c:5979 (discriminator 4))
[ 57.171888][ C3] ? __pfx___netif_receive_skb_one_core (net/core/dev.c:5972)
[ 57.172342][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745)
[ 57.172704][ C3] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5834)
[ 57.173071][ C3] ? process_backlog (./include/linux/local_lock_internal.h:54 net/core/dev.c:6442)
[ 57.173438][ C3] process_backlog (./include/linux/rcupdate.h:869 net/core/dev.c:6445)
[ 57.173827][ C3] __napi_poll.constprop.0 (net/core/dev.c:7482)
[ 57.174200][ C3] net_rx_action (net/core/dev.c:7546 net/core/dev.c:7673)
[ 57.174577][ C3] ? __pfx_net_rx_action (net/core/dev.c:7635)
[ 57.174948][ C3] ? clockevents_program_event (kernel/time/clockevents.c:326)
[ 57.175312][ C3] ? __lock_release (kernel/locking/lockdep.c:5515)
[ 57.175681][ C3] ? kvm_clock_get_cycles (./arch/x86/include/asm/preempt.h:95 arch/x86/kernel/kvmclock.c:80 arch/x86/kernel/kvmclock.c:86)
[ 57.176053][ C3] ? ktime_get (kernel/time/timekeeping.c:251 (discriminator 4) kernel/time/timekeeping.c:360 (discriminator 4) kernel/time/timekeeping.c:778 (discriminator 4))
[ 57.176330][ C3] ? clockevents_program_event (kernel/time/clockevents.c:336 (discriminator 3))
[ 57.176802][ C3] handle_softirqs (kernel/softirq.c:579)
[ 57.177173][ C3] ? __dev_queue_xmit (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:908 net/core/dev.c:4740)
[ 57.177536][ C3] do_softirq (kernel/softirq.c:480 kernel/softirq.c:467)
[ 57.177819][ C3]
[ 57.178007][ C3]
[ 57.178192][ C3] __local_bh_enable_ip (kernel/softirq.c:407)
[ 57.178555][ C3] ? __dev_queue_xmit (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:908 net/core/dev.c:4740)
[ 57.178930][ C3] __dev_queue_xmit (net/core/dev.c:4741)
[ 57.179296][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5240)
[ 57.179672][ C3] ? __pfx___dev_queue_xmit (net/core/dev.c:4621)
[ 57.180051][ C3] ? neigh_hh_output (./include/linux/seqlock.h:74 ./include/linux/seqlock.h:836 ./include/net/neighbour.h:501)
[ 57.180414][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 57.180787][ C3] ? neigh_hh_output (./include/linux/seqlock.h:74 ./include/linux/seqlock.h:836 ./include/net/neighbour.h:501)
[ 57.181161][ C3] ip_finish_output2 (./include/net/neighbour.h:545 net/ipv4/ip_output.c:235)
[ 57.181528][ C3] ? ip_skb_dst_mtu (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 ./include/net/ip.h:501 ./include/net/ip.h:515)
[ 57.181903][ C3] ? __pfx_ip_finish_output2 (net/ipv4/ip_output.c:199)
[ 57.182277][ C3] ? __ip_finish_output (./include/linux/skbuff.h:1685 ./include/linux/skbuff.h:5079 net/ipv4/ip_output.c:307 net/ipv4/ip_output.c:295)
[ 57.182644][ C3] __ip_queue_xmit (./include/net/dst.h:461 net/ipv4/ip_output.c:129 net/ipv4/ip_output.c:527)
[ 57.183018][ C3] ? __skb_clone (./arch/x86/include/asm/atomic.h:53 (discriminator 4) ./include/linux/atomic/atomic-arch-fallback.h:992 (discriminator 4) ./include/linux/atomic/atomic-instrumented.h:436 (discriminator 4) net/core/skbuff.c:1566 (discriminator 4))
[ 57.183386][ C3] __tcp_transmit_skb (net/ipv4/tcp_output.c:1625 (discriminator 4))
[ 57.183768][ C3] ? __pfx___tcp_transmit_skb (net/ipv4/tcp_output.c:1446)
[ 57.184154][ C3] tcp_connect (net/ipv4/tcp_output.c:1643 net/ipv4/tcp_output.c:4319)
[ 57.184530][ C3] tcp_v4_connect (net/ipv4/tcp_ipv4.c:346)
[ 57.184909][ C3] ? __pfx_tcp_v4_connect (net/ipv4/tcp_ipv4.c:224)
[ 57.185272][ C3] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116)
[ 57.185638][ C3] ? find_held_lock (kernel/locking/lockdep.c:5353)
[ 57.186019][ C3] __inet_stream_connect (net/ipv4/af_inet.c:677)
[ 57.186385][ C3] ? __local_bh_enable_ip (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 kernel/softirq.c:412)
[ 57.186751][ C3] ? __pfx_inet_stream_connect (net/ipv4/af_inet.c:744)
[ 57.187126][ C3] inet_stream_connect (net/ipv4/af_inet.c:749)
[ 57.187495][ C3] __sys_connect (net/socket.c:2086 net/socket.c:2105)
[ 57.187868][ C3] ? __pfx___sys_connect (net/socket.c:2093)
[ 57.188232][ C3] ? fd_install (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:953 fs/file.c:661)
[ 57.188601][ C3] ? fd_install (./arch/x86/include/asm/preempt.h:104 ./include/linux/rcupdate.h:955 fs/file.c:661)
[ 57.188972][ C3] ? __sys_socket (net/socket.c:503 net/socket.c:1740)
[ 57.189336][ C3] ? __pfx___sys_socket (net/socket.c:1727)
[ 57.189706][ C3] __x64_sys_connect (net/socket.c:2108)
[ 57.190081][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475)
[ 57.190446][ C3] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
[ 57.190821][ C3] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
[ 57.191273][ C3] RIP: 0033:0x7fabeca23d77
[ 57.191650][ C3] Code: 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2a 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 18 89 54 24 0c 48 89 34 24 89
All code
========
0: 64 89 01 mov %eax,%fs:(%rcx)
3: 48 83 c8 ff or $0xffffffffffffffff,%rax
7: c3 ret
8: 66 2e 0f 1f 84 00 00 cs nopw 0x0(%rax,%rax,1)
f: 00 00 00
12: 90 nop
13: f3 0f 1e fa endbr64
17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax
1e: 00
1f: 85 c0 test %eax,%eax
21: 75 10 jne 0x33
23: b8 2a 00 00 00 mov $0x2a,%eax
28: 0f 05 syscall
2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction
30: 77 51 ja 0x83
32: c3 ret
33: 48 83 ec 18 sub $0x18,%rsp
37: 89 54 24 0c mov %edx,0xc(%rsp)
3b: 48 89 34 24 mov %rsi,(%rsp)
3f: 89 .byte 0x89
Code starting with the faulting instruction
===========================================
0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax
6: 77 51 ja 0x59
8: c3 ret
9: 48 83 ec 18 sub $0x18,%rsp
d: 89 54 24 0c mov %edx,0xc(%rsp)
11: 48 89 34 24 mov %rsi,(%rsp)
15: 89 .byte 0x89
[ 57.192961][ C3] RSP: 002b:00007ffde51b02b8 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
[ 57.193512][ C3] RAX: ffffffffffffffda RBX: 00000000ffffffff RCX: 00007fabeca23d77
[ 57.194074][ C3] RDX: 0000000000000010 RSI: 0000562d4fb4dc50 RDI: 0000000000000006
[ 57.194624][ C3] RBP: 0000000000000006 R08: 0000000000000003 R09: 0000000000000000
[ 57.195185][ C3] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000010
Finger prints:
ip_route_me_harder:synproxy_send_client_synack:nft_synproxy_do_eval:nft_do_chain:nft_do_chain_inet