====================================== | [ 31.648267][ T251] tun: Universal TUN/TAP device driver, 1.6 | [ 41.806636][ T284] packetdrill (284) used greatest stack depth: 23936 bytes left | [ 90.108934][ C3] Oops: general protection fault, probably for non-canonical address 0xdffffc000000000e: 0000 [#1] PREEMPT SMP KASAN NOPTI | [ 90.109326][ C3] KASAN: null-ptr-deref in range [0x0000000000000070-0x0000000000000077] [ 90.109763][ C3] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 90.110081][ C3] RIP: 0010:__inet_csk_reqsk_queue_drop (./include/linux/list.h:958 ./include/net/sock.h:744 ./include/net/sock.h:749 net/ipv4/inet_connection_sock.c:1042 net/ipv4/inet_connection_sock.c:1058) [ 90.110267][ C3] Code: 00 00 00 00 00 fc ff df 41 57 4c 8d 7e 70 41 56 41 55 41 89 d5 4c 89 fa 41 54 48 c1 ea 03 55 48 89 f5 53 48 89 fb 48 83 ec 08 <80> 3c 02 00 0f 85 6c 05 00 00 45 31 e4 48 83 7d 70 00 0f 84 0f 01 All code ======== 0: 00 00 add %al,(%rax) 2: 00 00 add %al,(%rax) 4: 00 fc add %bh,%ah 6: ff (bad) 7: df 41 57 filds 0x57(%rcx) a: 4c 8d 7e 70 lea 0x70(%rsi),%r15 e: 41 56 push %r14 10: 41 55 push %r13 12: 41 89 d5 mov %edx,%r13d 15: 4c 89 fa mov %r15,%rdx 18: 41 54 push %r12 1a: 48 c1 ea 03 shr $0x3,%rdx 1e: 55 push %rbp 1f: 48 89 f5 mov %rsi,%rbp 22: 53 push %rbx 23: 48 89 fb mov %rdi,%rbx 26: 48 83 ec 08 sub $0x8,%rsp 2a:* 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1) <-- trapping instruction 2e: 0f 85 6c 05 00 00 jne 0x5a0 34: 45 31 e4 xor %r12d,%r12d 37: 48 83 7d 70 00 cmpq $0x0,0x70(%rbp) 3c: 0f .byte 0xf 3d: 84 0f test %cl,(%rdi) 3f: 01 .byte 0x1 Code starting with the faulting instruction =========================================== 0: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1) 4: 0f 85 6c 05 00 00 jne 0x576 a: 45 31 e4 xor %r12d,%r12d d: 48 83 7d 70 00 cmpq $0x0,0x70(%rbp) 12: 0f .byte 0xf 13: 84 0f test %cl,(%rdi) 15: 01 .byte 0x1 [ 90.110776][ C3] RSP: 0000:ffffc90000298c28 EFLAGS: 00010296 [ 90.110959][ C3] RAX: dffffc0000000000 RBX: ffff888006da8d40 RCX: 1ffff11000b765a7 [ 90.111175][ C3] RDX: 000000000000000e RSI: 0000000000000000 RDI: ffff888006da8d40 [ 90.111390][ C3] RBP: 0000000000000000 R08: ffffffffb993fe6f R09: fffffbfff77ae809 [ 90.111606][ C3] R10: ffffffffbbd7404f R11: 0000000000000001 R12: 0000000000000000 [ 90.111823][ C3] R13: 0000000000000001 R14: ffff8880049e0278 R15: 0000000000000070 [ 90.112036][ C3] FS: 0000000000000000(0000) GS:ffff888036180000(0000) knlGS:0000000000000000 [ 90.112282][ C3] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 90.112462][ C3] CR2: 00007f14d54d6318 CR3: 0000000006ab0006 CR4: 0000000000772ef0 [ 90.112680][ C3] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 90.112890][ C3] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 90.113121][ C3] PKRU: 55555554 [ 90.113229][ C3] Call Trace: [ 90.113337][ C3] [ 90.113410][ C3] ? die_addr (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:460) [ 90.113522][ C3] ? exc_general_protection (arch/x86/kernel/traps.c:751 arch/x86/kernel/traps.c:693) [ 90.113668][ C3] ? asm_exc_general_protection (./arch/x86/include/asm/idtentry.h:617) [ 90.113815][ C3] ? reuseport_migrate_sock (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 net/core/sock_reuseport.c:674) [ 90.113960][ C3] ? __inet_csk_reqsk_queue_drop (./include/linux/list.h:958 ./include/net/sock.h:744 ./include/net/sock.h:749 net/ipv4/inet_connection_sock.c:1042 net/ipv4/inet_connection_sock.c:1058) [ 90.114136][ C3] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5827) [ 90.114283][ C3] reqsk_timer_handler (./include/net/request_sock.h:148 net/ipv4/inet_connection_sock.c:1194) [ 90.114429][ C3] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5790) [ 90.114569][ C3] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 52)) [ 90.114710][ C3] ? __pfx_reqsk_timer_handler (net/ipv4/inet_connection_sock.c:1085) [ 90.114854][ C3] ? call_timer_fn (kernel/time/timer.c:1791) [ 90.114997][ C3] ? lock_acquire (kernel/locking/lockdep.c:5798) [ 90.115140][ C3] ? __pfx_reqsk_timer_handler (net/ipv4/inet_connection_sock.c:1085) [ 90.115281][ C3] call_timer_fn (kernel/time/timer.c:1794) [ 90.115422][ C3] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1784) [ 90.115566][ C3] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1784) [ 90.115708][ C3] ? __pfx_call_timer_fn (kernel/time/timer.c:1771) [ 90.115848][ C3] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 90.115991][ C3] ? mark_held_locks (kernel/locking/lockdep.c:4321) [ 90.116138][ C3] __run_timers (kernel/time/timer.c:1846 kernel/time/timer.c:2419) [ 90.116278][ C3] ? __pfx_reqsk_timer_handler (net/ipv4/inet_connection_sock.c:1085) [ 90.116419][ C3] ? __pfx___run_timers (kernel/time/timer.c:2390) [ 90.116561][ C3] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 90.116704][ C3] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 90.116844][ C3] ? lock_acquire (kernel/locking/lockdep.c:5798) [ 90.116985][ C3] ? run_timer_softirq (kernel/time/timer.c:2430 kernel/time/timer.c:2423 kernel/time/timer.c:2439 kernel/time/timer.c:2447) [ 90.117127][ C3] run_timer_softirq (kernel/time/timer.c:2431 kernel/time/timer.c:2423 kernel/time/timer.c:2439 kernel/time/timer.c:2447) [ 90.117270][ C3] handle_softirqs (kernel/softirq.c:554) [ 90.117416][ C3] irq_exit_rcu (kernel/softirq.c:589 kernel/softirq.c:428 kernel/softirq.c:637 kernel/softirq.c:649) [ 90.117522][ C3] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1037 arch/x86/kernel/apic/apic.c:1037) [ 90.117665][ C3] [ 90.117738][ C3] [ 90.117809][ C3] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 90.117988][ C3] RIP: 0010:__orc_find (arch/x86/kernel/unwind_orc.c:87) [ 90.118134][ C3] Code: cc cc cc cc 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 00 00 41 57 41 56 41 55 49 89 cd <89> d1 41 54 4c 8d 64 8f fc 55 53 48 83 ec 08 85 d2 0f 84 99 00 00 All code ======== 0: cc int3 1: cc int3 2: cc int3 3: cc int3 4: 0f 1f 84 00 00 00 00 nopl 0x0(%rax,%rax,1) b: 00 c: 90 nop d: 90 nop e: 90 nop f: 90 nop 10: 90 nop 11: 90 nop 12: 90 nop 13: 90 nop 14: 90 nop 15: 90 nop 16: 90 nop 17: 90 nop 18: 90 nop 19: 90 nop 1a: 90 nop 1b: 90 nop 1c: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 21: 41 57 push %r15 23: 41 56 push %r14 25: 41 55 push %r13 27: 49 89 cd mov %rcx,%r13 2a:* 89 d1 mov %edx,%ecx <-- trapping instruction 2c: 41 54 push %r12 2e: 4c 8d 64 8f fc lea -0x4(%rdi,%rcx,4),%r12 33: 55 push %rbp 34: 53 push %rbx 35: 48 83 ec 08 sub $0x8,%rsp 39: 85 d2 test %edx,%edx 3b: 0f .byte 0xf 3c: 84 .byte 0x84 3d: 99 cltd ... Code starting with the faulting instruction =========================================== 0: 89 d1 mov %edx,%ecx 2: 41 54 push %r12 4: 4c 8d 64 8f fc lea -0x4(%rdi,%rcx,4),%r12 9: 55 push %rbp a: 53 push %rbx b: 48 83 ec 08 sub $0x8,%rsp f: 85 d2 test %edx,%edx 11: 0f .byte 0xf 12: 84 .byte 0x84 13: 99 cltd ... [ 90.118634][ C3] RSP: 0000:ffffc90000c8f7f8 EFLAGS: 00000286 [ 90.118814][ C3] RAX: 000000000001c4b6 RBX: 0000000000000001 RCX: ffffffffb79e7113 [ 90.119025][ C3] RDX: 0000000000000011 RSI: ffffffffbc162f78 RDI: ffffffffbbe2207c [ 90.119237][ C3] RBP: ffffc90000c8f970 R08: ffffc90000c8f958 R09: 1ffff92000191f0c [ 90.119450][ C3] R10: ffffc90000c8f918 R11: ffffc90000c8f959 R12: 1ffff92000191f0c [ 90.119660][ C3] R13: ffffffffb79e7113 R14: 0000000000000000 R15: ffffea00000e9d00 [ 90.119872][ C3] ? stack_trace_save (kernel/stacktrace.c:122) [ 90.120014][ C3] ? stack_trace_save (kernel/stacktrace.c:122) [ 90.120158][ C3] unwind_next_frame (arch/x86/kernel/unwind_orc.c:495) [ 90.120301][ C3] ? stack_trace_save (kernel/stacktrace.c:123) [ 90.120446][ C3] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 90.120593][ C3] ? __pfx_unwind_next_frame (arch/x86/kernel/unwind_orc.c:469) [ 90.120742][ C3] ? stack_trace_save (kernel/stacktrace.c:123) [ 90.120883][ C3] ? kernel_text_address (kernel/extable.c:99) [ 90.121026][ C3] ? __pfx_stack_trace_consume_entry (kernel/stacktrace.c:83) [ 90.121202][ C3] arch_stack_walk (arch/x86/kernel/stacktrace.c:24) [ 90.121347][ C3] ? stack_trace_save (kernel/stacktrace.c:123) [ 90.121487][ C3] stack_trace_save (kernel/stacktrace.c:123) [ 90.121631][ C3] ? __pfx_stack_trace_save (kernel/stacktrace.c:114) [ 90.121775][ C3] ? mark_held_locks (kernel/locking/lockdep.c:4321) [ 90.121918][ C3] set_track_prepare (mm/slub.c:946) [ 90.122062][ C3] ? get_partial_node.part.0 (mm/slub.c:2863) [ 90.122208][ C3] ___slab_alloc (mm/slub.c:977 mm/slub.c:3809) [ 90.122348][ C3] ? __lock_release (kernel/locking/lockdep.c:5501) [ 90.122488][ C3] ? __kmalloc_node_noprof (./arch/x86/include/asm/bitops.h:420 ./include/asm-generic/getorder.h:46 mm/slub.c:4255 mm/slub.c:4271) [ 90.122633][ C3] ? ptlock_alloc (mm/memory.c:6903) [ 90.122777][ C3] ? lock_downgrade (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5729) [ 90.122921][ C3] ? ptlock_alloc (mm/memory.c:6903) [ 90.123075][ C3] ? kmem_cache_alloc_noprof (mm/slub.c:3909 mm/slub.c:3962 mm/slub.c:4123 mm/slub.c:4142) [ 90.123215][ C3] kmem_cache_alloc_noprof (mm/slub.c:3909 mm/slub.c:3962 mm/slub.c:4123 mm/slub.c:4142) [ 90.123356][ C3] ? __lock_acquire (kernel/locking/lockdep.c:5202) [ 90.123500][ C3] ptlock_alloc (mm/memory.c:6903) [ 90.123608][ C3] pte_alloc_one (./include/linux/mm.h:2958 ./include/linux/mm.h:2985 ./include/asm-generic/pgalloc.h:73 arch/x86/mm/pgtable.c:33) [ 90.123748][ C3] do_fault_around (mm/memory.c:5234) [ 90.123891][ C3] do_pte_missing (mm/memory.c:5273 mm/memory.c:5416 mm/memory.c:3965) [ 90.124039][ C3] ? __lock_release (kernel/locking/lockdep.c:5547) [ 90.124182][ C3] __handle_mm_fault (mm/memory.c:5894) [ 90.124326][ C3] ? __pfx___handle_mm_fault (mm/memory.c:5803) [ 90.124466][ C3] ? lock_vma_under_rcu (./include/linux/mm.h:704 mm/memory.c:6228) [ 90.124611][ C3] ? __pfx_lock_vma_under_rcu (mm/memory.c:6218) [ 90.124751][ C3] handle_mm_fault (mm/memory.c:6074) [ 90.124891][ C3] ? __pfx_handle_mm_fault (mm/memory.c:6029) [ 90.125035][ C3] do_user_addr_fault (arch/x86/mm/fault.c:1338) [ 90.125176][ C3] exc_page_fault (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:87 ./arch/x86/include/asm/irqflags.h:147 arch/x86/mm/fault.c:1489 arch/x86/mm/fault.c:1539) [ 90.125320][ C3] asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:623) [ 90.125466][ C3] RIP: 0033:0x7f14d56f7db5 [ 90.125612][ C3] Code: 00 00 00 00 00 3d 53 e5 74 64 75 11 8b b5 2c ff ff ff 4c 89 f2 4c 89 ff e8 78 f3 ff ff 4d 39 b7 a8 02 00 00 0f 84 58 01 00 00 <41> 8b 46 c8 49 83 ee 38 83 f8 04 75 ce 49 8b 56 10 49 8b 07 4d 8b All code ======== 0: 00 00 add %al,(%rax) 2: 00 00 add %al,(%rax) 4: 00 3d 53 e5 74 64 add %bh,0x6474e553(%rip) # 0x6474e55d a: 75 11 jne 0x1d c: 8b b5 2c ff ff ff mov -0xd4(%rbp),%esi 12: 4c 89 f2 mov %r14,%rdx 15: 4c 89 ff mov %r15,%rdi 18: e8 78 f3 ff ff call 0xfffffffffffff395 1d: 4d 39 b7 a8 02 00 00 cmp %r14,0x2a8(%r15) 24: 0f 84 58 01 00 00 je 0x182 2a:* 41 8b 46 c8 mov -0x38(%r14),%eax <-- trapping instruction 2e: 49 83 ee 38 sub $0x38,%r14 32: 83 f8 04 cmp $0x4,%eax 35: 75 ce jne 0x5 37: 49 8b 56 10 mov 0x10(%r14),%rdx 3b: 49 8b 07 mov (%r15),%rax 3e: 4d rex.WRB 3f: 8b .byte 0x8b Code starting with the faulting instruction =========================================== 0: 41 8b 46 c8 mov -0x38(%r14),%eax 4: 49 83 ee 38 sub $0x38,%r14 8: 83 f8 04 cmp $0x4,%eax b: 75 ce jne 0xffffffffffffffdb d: 49 8b 56 10 mov 0x10(%r14),%rdx 11: 49 8b 07 mov (%r15),%rax 14: 4d rex.WRB 15: 8b .byte 0x8b [ 90.126112][ C3] RSP: 002b:00007ffdec296030 EFLAGS: 00010287 [ 90.126290][ C3] RAX: 0000000000000062 RBX: 000000006ffffdff RCX: 000000000000000e [ 90.126504][ C3] RDX: 00007f14d54d6040 RSI: 0000000000000029 RDI: 000000006fffffff [ 90.126712][ C3] RBP: 00007ffdec2964a0 R08: 00000000effffef5 R09: 0000000070000022 [ 90.126921][ C3] R10: 00007f14d54d6000 R11: 0000000000000032 R12: 000000006ffffeff Finger prints: __inet_csk_reqsk_queue_drop:reqsk_timer_handler:call_timer_fn:__run_timers:run_timer_softirq