====================================== | WAIT TIMEOUT stdout | [ 31.564800][ C1] TCP: TCP-AO: the keyid 100 from SYN packet is not present - not sending SYNACK | [ 32.571124][ C1] Oops: general protection fault, probably for non-canonical address 0xdffffc000000000e: 0000 [#1] PREEMPT SMP KASAN NOPTI | [ 32.571594][ C1] KASAN: null-ptr-deref in range [0x0000000000000070-0x0000000000000077] [ 32.572064][ C1] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 32.572413][ C1] RIP: 0010:__inet_csk_reqsk_queue_drop (./include/linux/list.h:958 ./include/net/sock.h:744 ./include/net/sock.h:749 net/ipv4/inet_connection_sock.c:1042 net/ipv4/inet_connection_sock.c:1058) [ 32.572618][ C1] Code: 00 00 00 00 00 fc ff df 41 57 4c 8d 7e 70 41 56 41 55 41 89 d5 4c 89 fa 41 54 48 c1 ea 03 55 48 89 f5 53 48 89 fb 48 83 ec 08 <80> 3c 02 00 0f 85 6c 05 00 00 45 31 e4 48 83 7d 70 00 0f 84 0f 01 All code ======== 0: 00 00 add %al,(%rax) 2: 00 00 add %al,(%rax) 4: 00 fc add %bh,%ah 6: ff (bad) 7: df 41 57 filds 0x57(%rcx) a: 4c 8d 7e 70 lea 0x70(%rsi),%r15 e: 41 56 push %r14 10: 41 55 push %r13 12: 41 89 d5 mov %edx,%r13d 15: 4c 89 fa mov %r15,%rdx 18: 41 54 push %r12 1a: 48 c1 ea 03 shr $0x3,%rdx 1e: 55 push %rbp 1f: 48 89 f5 mov %rsi,%rbp 22: 53 push %rbx 23: 48 89 fb mov %rdi,%rbx 26: 48 83 ec 08 sub $0x8,%rsp 2a:* 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1) <-- trapping instruction 2e: 0f 85 6c 05 00 00 jne 0x5a0 34: 45 31 e4 xor %r12d,%r12d 37: 48 83 7d 70 00 cmpq $0x0,0x70(%rbp) 3c: 0f .byte 0xf 3d: 84 0f test %cl,(%rdi) 3f: 01 .byte 0x1 Code starting with the faulting instruction =========================================== 0: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1) 4: 0f 85 6c 05 00 00 jne 0x576 a: 45 31 e4 xor %r12d,%r12d d: 48 83 7d 70 00 cmpq $0x0,0x70(%rbp) 12: 0f .byte 0xf 13: 84 0f test %cl,(%rdi) 15: 01 .byte 0x1 [ 32.573163][ C1] RSP: 0018:ffffc900001e8c28 EFLAGS: 00010296 [ 32.573353][ C1] RAX: dffffc0000000000 RBX: ffff888005790040 RCX: 1ffff11000b435a5 [ 32.573579][ C1] RDX: 000000000000000e RSI: 0000000000000000 RDI: ffff888005790040 [ 32.573800][ C1] RBP: 0000000000000000 R08: ffffffffa9907caf R09: fffffbfff57ab9b1 [ 32.574020][ C1] R10: ffffffffabd5cd8f R11: ffffc900001e89e1 R12: 0000000000000000 [ 32.574244][ C1] R13: 0000000000000001 R14: ffff888007baa0a0 R15: 0000000000000070 [ 32.574604][ C1] FS: 00007fa1673acf00(0000) GS:ffff888036080000(0000) knlGS:0000000000000000 [ 32.574871][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 32.575059][ C1] CR2: 00007f58a80231a8 CR3: 0000000003fe2001 CR4: 0000000000772ef0 [ 32.575280][ C1] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 32.575500][ C1] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 32.575726][ C1] PKRU: 55555554 [ 32.575840][ C1] Call Trace: [ 32.575953][ C1] [ 32.576030][ C1] ? die_addr (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:460) [ 32.576149][ C1] ? exc_general_protection (arch/x86/kernel/traps.c:751 arch/x86/kernel/traps.c:693) [ 32.576299][ C1] ? asm_exc_general_protection (./arch/x86/include/asm/idtentry.h:617) [ 32.576451][ C1] ? reuseport_migrate_sock (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 net/core/sock_reuseport.c:674) [ 32.576603][ C1] ? __inet_csk_reqsk_queue_drop (./include/linux/list.h:958 ./include/net/sock.h:744 ./include/net/sock.h:749 net/ipv4/inet_connection_sock.c:1042 net/ipv4/inet_connection_sock.c:1058) [ 32.576786][ C1] ? lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5827) [ 32.576937][ C1] reqsk_timer_handler (./include/net/request_sock.h:148 net/ipv4/inet_connection_sock.c:1194) [ 32.577087][ C1] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5790) [ 32.577234][ C1] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 52)) [ 32.577389][ C1] ? __pfx_reqsk_timer_handler (net/ipv4/inet_connection_sock.c:1085) [ 32.577536][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1784) [ 32.577707][ C1] ? lock_acquire (kernel/locking/lockdep.c:5798) [ 32.577854][ C1] ? __pfx_reqsk_timer_handler (net/ipv4/inet_connection_sock.c:1085) [ 32.578001][ C1] call_timer_fn (kernel/time/timer.c:1794) [ 32.578151][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1784) [ 32.578299][ C1] ? call_timer_fn (./include/linux/lockdep.h:31 kernel/time/timer.c:1784) [ 32.578446][ C1] ? __pfx_call_timer_fn (kernel/time/timer.c:1771) [ 32.578594][ C1] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228) [ 32.578744][ C1] ? mark_held_locks (kernel/locking/lockdep.c:4321) [ 32.578891][ C1] __run_timers (kernel/time/timer.c:1846 kernel/time/timer.c:2419) [ 32.579042][ C1] ? __pfx_reqsk_timer_handler (net/ipv4/inet_connection_sock.c:1085) [ 32.579192][ C1] ? __pfx___run_timers (kernel/time/timer.c:2390) [ 32.579342][ C1] ? do_raw_spin_lock (./arch/x86/include/asm/atomic.h:107 ./include/linux/atomic/atomic-arch-fallback.h:2170 ./include/linux/atomic/atomic-instrumented.h:1302 ./include/asm-generic/qspinlock.h:111 kernel/locking/spinlock_debug.c:116) [ 32.579489][ C1] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 32.579637][ C1] ? lock_acquire (kernel/locking/lockdep.c:5798) [ 32.579784][ C1] ? run_timer_softirq (kernel/time/timer.c:2430 kernel/time/timer.c:2423 kernel/time/timer.c:2439 kernel/time/timer.c:2447) [ 32.579933][ C1] run_timer_softirq (kernel/time/timer.c:2431 kernel/time/timer.c:2423 kernel/time/timer.c:2439 kernel/time/timer.c:2447) [ 32.580079][ C1] handle_softirqs (kernel/softirq.c:554) [ 32.580227][ C1] irq_exit_rcu (kernel/softirq.c:589 kernel/softirq.c:428 kernel/softirq.c:637 kernel/softirq.c:649) [ 32.580344][ C1] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1037 arch/x86/kernel/apic/apic.c:1037) [ 32.580499][ C1] [ 32.580577][ C1] [ 32.580653][ C1] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) [ 32.580837][ C1] RIP: 0010:_raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194) [ 32.581042][ C1] Code: 10 e8 91 28 8d fd 48 89 ef e8 a9 99 8d fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d e5 94 00 56 <74> 0e 5b 5d c3 cc cc cc cc e8 df 69 b2 fd eb dc 0f 1f 44 00 00 5b All code ======== 0: 10 e8 adc %ch,%al 2: 91 xchg %eax,%ecx 3: 28 8d fd 48 89 ef sub %cl,-0x1076b703(%rbp) 9: e8 a9 99 8d fd call 0xfffffffffd8d99b7 e: 81 e3 00 02 00 00 and $0x200,%ebx 14: 75 1d jne 0x33 16: 9c pushf 17: 58 pop %rax 18: f6 c4 02 test $0x2,%ah 1b: 75 29 jne 0x46 1d: 48 85 db test %rbx,%rbx 20: 74 01 je 0x23 22: fb sti 23: 65 ff 0d e5 94 00 56 decl %gs:0x560094e5(%rip) # 0x5600950f 2a:* 74 0e je 0x3a <-- trapping instruction 2c: 5b pop %rbx 2d: 5d pop %rbp 2e: c3 ret 2f: cc int3 30: cc int3 31: cc int3 32: cc int3 33: e8 df 69 b2 fd call 0xfffffffffdb26a17 38: eb dc jmp 0x16 3a: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 3f: 5b pop %rbx Code starting with the faulting instruction =========================================== 0: 74 0e je 0x10 2: 5b pop %rbx 3: 5d pop %rbp 4: c3 ret 5: cc int3 6: cc int3 7: cc int3 8: cc int3 9: e8 df 69 b2 fd call 0xfffffffffdb269ed e: eb dc jmp 0xffffffffffffffec 10: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1) 15: 5b pop %rbx [ 32.581579][ C1] RSP: 0018:ffffc90000abfa98 EFLAGS: 00000286 [ 32.581775][ C1] RAX: 0000000000000006 RBX: 0000000000000200 RCX: 1ffffffff5a78a5b [ 32.581998][ C1] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffaa033431 [ 32.582220][ C1] RBP: ffffffffadc89420 R08: 0000000000000001 R09: fffffbfff5a73bd0 [ 32.582440][ C1] R10: ffffffffad39de87 R11: ffff88800440c990 R12: 0000000000001000 [ 32.582680][ C1] R13: ffffffffadc89528 R14: 0000000000000282 R15: ffffffffadc89560 [ 32.582902][ C1] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) [ 32.583098][ C1] uart_write_room (drivers/tty/serial/serial_core.c:74 drivers/tty/serial/serial_core.c:649) [ 32.583252][ C1] process_output_block (drivers/tty/n_tty.c:532) [ 32.583399][ C1] ? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4347 kernel/locking/lockdep.c:4406) [ 32.583593][ C1] n_tty_write (drivers/tty/n_tty.c:2390) [ 32.583750][ C1] ? __pfx_n_tty_write (drivers/tty/n_tty.c:2360) [ 32.583897][ C1] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 52)) [ 32.584052][ C1] ? __pfx_woken_wake_function (kernel/sched/wait.c:439) [ 32.584198][ C1] ? iterate_tty_write (drivers/tty/tty_io.c:948 drivers/tty/tty_io.c:967) [ 32.584352][ C1] ? lock_acquire (kernel/locking/lockdep.c:5798) [ 32.584502][ C1] ? iterate_tty_write (drivers/tty/tty_io.c:948 drivers/tty/tty_io.c:967) [ 32.584649][ C1] iterate_tty_write (drivers/tty/tty_io.c:1015) [ 32.584796][ C1] ? tty_ldisc_ref_wait (drivers/tty/tty_ldisc.c:244) [ 32.584950][ C1] file_tty_write.constprop.0 (drivers/tty/tty_io.c:1090) [ 32.585116][ C1] vfs_write (fs/read_write.c:590 fs/read_write.c:683) [ 32.585238][ C1] ? __pfx___lock_release (kernel/locking/lockdep.c:5477) [ 32.585396][ C1] ? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 52)) [ 32.585557][ C1] ? __might_fault (mm/memory.c:6700 mm/memory.c:6693) [ 32.585716][ C1] ? lock_acquire (kernel/locking/lockdep.c:5798) [ 32.585875][ C1] ? __pfx_vfs_write (fs/read_write.c:664) [ 32.586035][ C1] ? __might_fault (mm/memory.c:6700 mm/memory.c:6693) [ 32.586191][ C1] ? __rseq_handle_notify_resume (kernel/rseq.c:316) [ 32.586384][ C1] ksys_write (fs/read_write.c:736) [ 32.586499][ C1] ? __pfx_ksys_write (fs/read_write.c:726) [ 32.586646][ C1] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) [ 32.586794][ C1] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) [ 32.586978][ C1] RIP: 0033:0x7fa167601957 [ 32.587142][ C1] Code: 0b 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24 All code ======== 0: 0b 00 or (%rax),%eax 2: f7 d8 neg %eax 4: 64 89 02 mov %eax,%fs:(%rdx) 7: 48 c7 c0 ff ff ff ff mov $0xffffffffffffffff,%rax e: eb b7 jmp 0xffffffffffffffc7 10: 0f 1f 00 nopl (%rax) 13: f3 0f 1e fa endbr64 17: 64 8b 04 25 18 00 00 mov %fs:0x18,%eax 1e: 00 1f: 85 c0 test %eax,%eax 21: 75 10 jne 0x33 23: b8 01 00 00 00 mov $0x1,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 51 ja 0x83 32: c3 ret 33: 48 83 ec 28 sub $0x28,%rsp 37: 48 89 54 24 18 mov %rdx,0x18(%rsp) 3c: 48 rex.W 3d: 89 .byte 0x89 3e: 74 24 je 0x64 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 51 ja 0x59 8: c3 ret 9: 48 83 ec 28 sub $0x28,%rsp d: 48 89 54 24 18 mov %rdx,0x18(%rsp) 12: 48 rex.W 13: 89 .byte 0x89 14: 74 24 je 0x3a [ 32.587666][ C1] RSP: 002b:00007ffc812c2498 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 32.587897][ C1] RAX: ffffffffffffffda RBX: 000055facf3e4300 RCX: 00007fa167601957 [ 32.588136][ C1] RDX: 0000000000000001 RSI: 000055facf3e4300 RDI: 0000000000000001 [ 32.588352][ C1] RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000001 [ 32.588571][ C1] R10: 0000000000000001 R11: 0000000000000246 R12: 000055facf3d05b0 Finger prints: __inet_csk_reqsk_queue_drop:reqsk_timer_handler:call_timer_fn:__run_timers:run_timer_softirq