====================================== | [ 13.506015][ C0] #1: ffffffff93b81e90 (remove_cache_srcu){.+.+}-{0:0}, at: kasan_quarantine_reduce (./include/linux/srcu.h:161 ./include/linux/srcu.h:253 mm/kasan/quarantine.c:259) | [ 13.506490][ C0] #2: ffffffff939793c0 (rcu_callback){....}-{0:0}, at: rcu_do_batch (./include/linux/rcupdate.h:331 kernel/rcu/tree.c:2570) | [ 13.506910][ C0] | [ 13.506910][ C0] stack backtrace: [ 13.507203][ C0] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 13.507206][ C0] Call Trace: [ 13.507208][ C0] [ 13.507210][ C0] dump_stack_lvl (lib/dump_stack.c:123) [ 13.507218][ C0] print_usage_bug.part.0 (kernel/locking/lockdep.c:4048) [ 13.507223][ C0] mark_lock_irq (kernel/locking/lockdep.c:4013 kernel/locking/lockdep.c:4059 kernel/locking/lockdep.c:4270) [ 13.507229][ C0] mark_lock (kernel/locking/lockdep.c:4756) [ 13.507232][ C0] mark_usage (kernel/locking/lockdep.c:4645) [ 13.507236][ C0] __lock_acquire (kernel/locking/lockdep.c:5194) [ 13.507238][ C0] ? unwind_next_frame (./include/linux/rcupdate.h:874 ./include/linux/rcupdate.h:1155 arch/x86/kernel/unwind_orc.c:479) [ 13.507246][ C0] ? free_to_partial_list (mm/slub.c:4388) [ 13.507253][ C0] lock_acquire.part.0 (kernel/locking/lockdep.c:473 kernel/locking/lockdep.c:5873) [ 13.507256][ C0] ? xa_set_mark (lib/xarray.c:2076 lib/xarray.c:2146) [ 13.507260][ C0] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 13.507263][ C0] ? lock_acquire (./include/trace/events/lock.h:24 kernel/locking/lockdep.c:5834) [ 13.507265][ C0] ? xa_set_mark (lib/xarray.c:2076 lib/xarray.c:2146) [ 13.507269][ C0] _raw_spin_lock (./include/linux/spinlock_api_smp.h:134 kernel/locking/spinlock.c:154) [ 13.507273][ C0] ? xa_set_mark (lib/xarray.c:2076 lib/xarray.c:2146) [ 13.507275][ C0] xa_set_mark (lib/xarray.c:2076 lib/xarray.c:2146) [ 13.507278][ C0] ? __pfx_xa_set_mark (lib/xarray.c:2144) [ 13.507280][ C0] ? __lock_acquire (kernel/locking/lockdep.c:5240) [ 13.507285][ C0] ? find_held_lock (kernel/locking/lockdep.c:5353) [ 13.507290][ C0] ref_tracker_dir_exit (lib/ref_tracker.c:54 lib/ref_tracker.c:223) [ 13.507296][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4328) [ 13.507299][ C0] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 13.507302][ C0] ? __pfx_ref_tracker_dir_exit (lib/ref_tracker.c:213) [ 13.507307][ C0] ? ref_tracker_free (lib/ref_tracker.c:281) [ 13.507311][ C0] ? __lock_acquire (kernel/locking/lockdep.c:5240) [ 13.507313][ C0] ? __pfx_ref_tracker_free (lib/ref_tracker.c:281) [ 13.507317][ C0] ? __sk_destruct (./include/linux/instrumented.h:96 ./include/linux/atomic/atomic-instrumented.h:400 ./include/linux/refcount.h:389 ./include/linux/refcount.h:432 ./include/linux/refcount.h:450 ./include/net/net_namespace.h:287 ./include/net/net_namespace.h:390 net/core/sock.c:2368) [ 13.507322][ C0] ? rcu_do_batch (./include/linux/rcupdate.h:341 kernel/rcu/tree.c:2578) [ 13.507325][ C0] ? rcu_core (kernel/rcu/tree.c:2834) [ 13.507329][ C0] ? handle_softirqs (kernel/softirq.c:580) [ 13.507333][ C0] __put_net (./include/linux/llist.h:238 ./include/linux/llist.h:265 net/core/net_namespace.c:732) [ 13.507339][ C0] ? stack_trace_save (kernel/stacktrace.c:123) [ 13.507345][ C0] ? __pfx___put_net (net/core/net_namespace.c:729) [ 13.507349][ C0] ? bpf_sk_storage_free (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 net/core/bpf_sk_storage.c:61) [ 13.507354][ C0] __sk_destruct (./include/net/net_namespace.h:288 ./include/net/net_namespace.h:390 net/core/sock.c:2368) [ 13.507358][ C0] ? rcu_do_batch (kernel/rcu/tree.c:2576) [ 13.507361][ C0] rcu_do_batch (./include/linux/rcupdate.h:341 kernel/rcu/tree.c:2578) [ 13.507365][ C0] ? find_held_lock (kernel/locking/lockdep.c:5353) [ 13.507370][ C0] ? __pfx_rcu_do_batch (kernel/rcu/tree.c:2500) [ 13.507374][ C0] ? mark_held_locks (kernel/locking/lockdep.c:4328) [ 13.507376][ C0] ? note_gp_changes (kernel/rcu/tree.c:1326 (discriminator 1)) [ 13.507380][ C0] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475) [ 13.507387][ C0] rcu_core (kernel/rcu/tree.c:2834) [ 13.507390][ C0] handle_softirqs (kernel/softirq.c:580) [ 13.507395][ C0] __irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680) [ 13.507398][ C0] irq_exit_rcu (kernel/softirq.c:698) [ 13.507400][ C0] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 arch/x86/kernel/apic/apic.c:1050) [ 13.507404][ C0] [ 13.507405][ C0] [ 13.507407][ C0] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 13.507411][ C0] RIP: 0010:lock_release (kernel/locking/lockdep.c:5896) [ 13.507415][ C0] Code: c7 19 fd 48 93 e8 2f 1c 7f 02 b8 ff ff ff ff 65 0f c1 05 02 63 36 05 83 f8 01 75 16 9c 58 f6 c4 02 75 2c 80 e7 02 74 01 fb 5b <5d> 41 5c e9 d7 5b 81 02 90 0f 0b 90 48 c7 c7 e1 76 4a 93 e8 f7 1b All code ======== 0: c7 (bad) 1: 19 fd sbb %edi,%ebp 3: 48 93 xchg %rax,%rbx 5: e8 2f 1c 7f 02 call 0x27f1c39 a: b8 ff ff ff ff mov $0xffffffff,%eax f: 65 0f c1 05 02 63 36 xadd %eax,%gs:0x5366302(%rip) # 0x5366319 16: 05 17: 83 f8 01 cmp $0x1,%eax 1a: 75 16 jne 0x32 1c: 9c pushf 1d: 58 pop %rax 1e: f6 c4 02 test $0x2,%ah 21: 75 2c jne 0x4f 23: 80 e7 02 and $0x2,%bh 26: 74 01 je 0x29 28: fb sti 29: 5b pop %rbx 2a:* 5d pop %rbp <-- trapping instruction 2b: 41 5c pop %r12 2d: e9 d7 5b 81 02 jmp 0x2815c09 32: 90 nop 33: 0f 0b ud2 35: 90 nop 36: 48 c7 c7 e1 76 4a 93 mov $0xffffffff934a76e1,%rdi 3d: e8 .byte 0xe8 3e: f7 1b negl (%rbx) Code starting with the faulting instruction =========================================== 0: 5d pop %rbp 1: 41 5c pop %r12 3: e9 d7 5b 81 02 jmp 0x2815bdf 8: 90 nop 9: 0f 0b ud2 b: 90 nop c: 48 c7 c7 e1 76 4a 93 mov $0xffffffff934a76e1,%rdi 13: e8 .byte 0xe8 14: f7 1b negl (%rbx) [ 13.507417][ C0] RSP: 0018:ffffc90000ab7510 EFLAGS: 00000202 [ 13.507421][ C0] RAX: 0000000000000046 RBX: 1ffff92000156eae RCX: ffffc90000ab74d4 [ 13.507423][ C0] RDX: 0000000000000002 RSI: ffffffff9348fd19 RDI: ffffffff92c5a2e0 [ 13.507425][ C0] RBP: ffffffff939794e0 R08: 0000000000000000 R09: ffffc90000ab76b9 [ 13.507426][ C0] R10: 0000000000000000 R11: ffffc90000ab76b8 R12: ffffffff8fe1ad7e [ 13.507428][ C0] R13: ffffc90000ab7678 R14: ffffc90000ab0000 R15: ffffc90000ab7670 [ 13.507430][ C0] ? unwind_next_frame (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 ./include/linux/rcupdate.h:1155 arch/x86/kernel/unwind_orc.c:479) [ 13.507437][ C0] unwind_next_frame (./include/linux/rcupdate.h:873 ./include/linux/rcupdate.h:1155 arch/x86/kernel/unwind_orc.c:479) [ 13.507441][ C0] ? __unwind_start (arch/x86/kernel/unwind_orc.c:712) [ 13.507446][ C0] ? __pfx_unwind_next_frame (arch/x86/kernel/unwind_orc.c:469) [ 13.507450][ C0] ? is_bpf_text_address (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:871 kernel/bpf/core.c:774) [ 13.507455][ C0] ? __lock_release (kernel/locking/lockdep.c:5539) [ 13.507457][ C0] ? get_stack_info_noinstr (arch/x86/kernel/dumpstack_64.c:173) [ 13.507462][ C0] __unwind_start (./arch/x86/include/asm/unwind.h:50 arch/x86/kernel/unwind_orc.c:755) [ 13.507467][ C0] ? __pfx_stack_trace_consume_entry (kernel/stacktrace.c:83) [ 13.507474][ C0] arch_stack_walk (arch/x86/kernel/stacktrace.c:24) [ 13.507486][ C0] ? arch_stack_walk (arch/x86/kernel/stacktrace.c:24) [ 13.507493][ C0] stack_trace_save (kernel/stacktrace.c:123) [ 13.507498][ C0] ? __pfx_stack_trace_save (kernel/stacktrace.c:114) [ 13.507501][ C0] ? check_bytes_and_report (mm/slub.c:1212) [ 13.507506][ C0] ? check_object (mm/slub.c:1289 mm/slub.c:1388) [ 13.507508][ C0] set_track_prepare (mm/slub.c:936) [ 13.507513][ C0] ? init_object (mm/slub.c:1182) [ 13.507518][ C0] free_to_partial_list (mm/slub.c:4388) [ 13.507521][ C0] ? qlist_free_all (mm/kasan/quarantine.c:163 mm/kasan/quarantine.c:179) [ 13.507526][ C0] qlist_free_all (mm/kasan/quarantine.c:174) [ 13.507530][ C0] ? tcp_ao_alloc_info (./include/linux/slab.h:905 ./include/linux/slab.h:1039 net/ipv4/tcp_ao.c:230) [ 13.507534][ C0] kasan_quarantine_reduce (./include/linux/srcu.h:400 mm/kasan/quarantine.c:287) [ 13.507538][ C0] __kasan_slab_alloc (mm/kasan/common.c:329) [ 13.507543][ C0] __kmalloc_cache_noprof (mm/slub.c:4149 mm/slub.c:4197 mm/slub.c:4354) [ 13.507548][ C0] tcp_ao_alloc_info (./include/linux/slab.h:905 ./include/linux/slab.h:1039 net/ipv4/tcp_ao.c:230) [ 13.507551][ C0] tcp_ao_add_cmd (net/ipv4/tcp_ao.c:1689) [ 13.507556][ C0] ? __pfx_tcp_ao_add_cmd (net/ipv4/tcp_ao.c:1598) [ 13.507559][ C0] ? check_prev_add (kernel/locking/lockdep.c:3172) [ 13.507561][ C0] ? check_prev_add (kernel/locking/lockdep.c:3206) [ 13.507563][ C0] ? add_chain_cache (kernel/locking/lockdep.c:3770) [ 13.507573][ C0] ? find_held_lock (kernel/locking/lockdep.c:5353) [ 13.507579][ C0] ? do_tcp_setsockopt (net/ipv4/tcp.c:4030) [ 13.507582][ C0] do_tcp_setsockopt (net/ipv4/tcp.c:4030) [ 13.507586][ C0] ? __pfx_do_tcp_setsockopt (net/ipv4/tcp.c:3770) [ 13.507589][ C0] ? __create_object (mm/kmemleak.c:771) [ 13.507594][ C0] ? __lock_release (kernel/locking/lockdep.c:5539) [ 13.507597][ C0] ? rcu_is_watching (./include/linux/context_tracking.h:128 kernel/rcu/tree.c:745) [ 13.507599][ C0] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 13.507603][ C0] ? lockdep_init_map_type (kernel/locking/lockdep.c:4976) [ 13.507608][ C0] ? __lock_acquire (kernel/locking/lockdep.c:5240) [ 13.507613][ C0] do_sock_setsockopt (net/socket.c:2296) [ 13.507617][ C0] ? __pfx_do_sock_setsockopt (net/socket.c:2265) [ 13.507620][ C0] ? fd_install (./include/linux/rcupdate.h:341 ./include/linux/rcupdate.h:953 fs/file.c:661) [ 13.507624][ C0] ? __lock_release (kernel/locking/lockdep.c:5539) [ 13.507630][ C0] __sys_setsockopt (./include/linux/file.h:62 ./include/linux/file.h:83 net/socket.c:2313) [ 13.507636][ C0] __x64_sys_setsockopt (net/socket.c:2324) [ 13.507639][ C0] ? do_syscall_64 (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:119 ./include/linux/entry-common.h:199 arch/x86/entry/syscall_64.c:90) [ 13.507643][ C0] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4475) [ 13.507646][ C0] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 13.507650][ C0] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 13.507652][ C0] RIP: 0033:0x7f51c4e0db0e [ 13.507657][ C0] Code: 0f 1f 40 00 48 8b 15 f1 92 0a 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b1 0f 1f 00 f3 0f 1e fa 49 89 ca b8 36 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 b9 All code ======== 0: 0f 1f 40 00 nopl 0x0(%rax) 4: 48 8b 15 f1 92 0a 00 mov 0xa92f1(%rip),%rdx # 0xa92fc b: f7 d8 neg %eax d: 64 89 02 mov %eax,%fs:(%rdx) 10: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax 17: eb b1 jmp 0xffffffffffffffca 19: 0f 1f 00 nopl (%rax) 1c: f3 0f 1e fa endbr64 20: 49 89 ca mov %rcx,%r10 23: b8 36 00 00 00 mov $0x36,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 0a ja 0x3c 32: c3 ret 33: 66 0f 1f 84 00 00 00 nopw 0x0(%rax,%rax,1) 3a: 00 00 3c: 48 rex.W 3d: 8b .byte 0x8b 3e: 15 .byte 0x15 3f: b9 .byte 0xb9 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 0a ja 0x12 8: c3 ret 9: 66 0f 1f 84 00 00 00 nopw 0x0(%rax,%rax,1) 10: 00 00 12: 48 rex.W 13: 8b .byte 0x8b 14: 15 .byte 0x15 15: b9 .byte 0xb9 [ 13.507660][ C0] RSP: 002b:00007ffe7510d528 EFLAGS: 00000206 ORIG_RAX: 0000000000000036 [ 13.507662][ C0] RAX: ffffffffffffffda RBX: 0000000000418340 RCX: 00007f51c4e0db0e [ 13.507664][ C0] RDX: 0000000000000026 RSI: 0000000000000006 RDI: 0000000000000005 [ 13.507666][ C0] RBP: 0000000000000005 R08: 0000000000000120 R09: 0000000000000000 [ 13.507668][ C0] R10: 00007ffe7510d530 R11: 0000000000000206 R12: 00007ffe7510d530 Finger prints: mark_lock_irq:mark_lock:mark_usage:__lock_acquire:_raw_spin_lock