====================================== | [ 22.733011][ C3] #0: ffffffffb11905f8 (remove_cache_srcu){.+.+}-{0:0}, at: kasan_quarantine_reduce (./include/linux/srcu.h:187 (discriminator 2) ./include/linux/srcu.h:294 (discriminator 2) mm/kasan/quarantine.c:259 (discriminator 2)) | [ 22.733188][ C3] #1: ffffffffb0f77c00 (rcu_callback){....}-{0:0}, at: rcu_do_batch (./include/linux/rcupdate.h:300 (discriminator 2) kernel/rcu/tree.c:2611 (discriminator 2)) | [ 22.733339][ C3] | [ 22.733339][ C3] stack backtrace: [ 22.733447][ C3] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 22.733449][ C3] Call Trace: [ 22.733451][ C3] [ 22.733452][ C3] dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120) [ 22.733457][ C3] print_usage_bug.part.0.cold (kernel/locking/lockdep.c:4042) [ 22.733460][ C3] ? filter_irq_stacks (kernel/stacktrace.c:402) [ 22.733463][ C3] mark_lock_irq (kernel/locking/lockdep.c:4013 kernel/locking/lockdep.c:4056 kernel/locking/lockdep.c:4267) [ 22.733464][ C3] ? sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 37) arch/x86/kernel/apic/apic.c:1061 (discriminator 37)) [ 22.733466][ C3] ? asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:697) [ 22.733469][ C3] ? save_trace (kernel/locking/lockdep.c:589) [ 22.733470][ C3] ? __noinstr_text_start (??:?) [ 22.733472][ C3] mark_lock (kernel/locking/lockdep.c:4753) [ 22.733474][ C3] mark_usage (kernel/locking/lockdep.c:4642) [ 22.733475][ C3] __lock_acquire (kernel/locking/lockdep.c:5191) [ 22.733477][ C3] ? mark_held_locks (kernel/locking/lockdep.c:4325) [ 22.733478][ C3] ? rcu_do_batch (./include/linux/rcupdate.h:310 (discriminator 2) kernel/rcu/tree.c:2619 (discriminator 2)) [ 22.733480][ C3] lock_acquire.part.0 (kernel/locking/lockdep.c:5868 (discriminator 1)) [ 22.733482][ C3] ? tcf_mirred_release (./include/linux/spinlock.h:342 net/sched/act_mirred.c:78) act_mirred [ 22.733484][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 22.733486][ C3] ? lock_acquire (./include/trace/events/lock.h:24 (discriminator 22) kernel/locking/lockdep.c:5831 (discriminator 22)) [ 22.733487][ C3] _raw_spin_lock (./include/linux/spinlock_api_smp.h:158 (discriminator 1) kernel/locking/spinlock.c:158 (discriminator 1)) [ 22.733489][ C3] ? tcf_mirred_release (./include/linux/spinlock.h:342 net/sched/act_mirred.c:78) act_mirred [ 22.733490][ C3] tcf_mirred_release (./include/linux/spinlock.h:342 net/sched/act_mirred.c:78) act_mirred [ 22.733492][ C3] tcf_action_rcu_free (net/sched/act_api.c:367 net/sched/act_api.c:378) [ 22.733494][ C3] ? rcu_do_batch (./include/linux/rcupdate.h:310 (discriminator 2) kernel/rcu/tree.c:2619 (discriminator 2)) [ 22.733495][ C3] rcu_do_batch (kernel/rcu/tree.c:2617) [ 22.733498][ C3] ? trace_rcu_batch_end (./include/trace/events/rcu.h:714 (discriminator 19)) [ 22.733500][ C3] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:470 (discriminator 2) kernel/locking/lockdep.c:4411 (discriminator 2)) [ 22.733501][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4472) [ 22.733503][ C3] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:178 (discriminator 6) kernel/locking/spinlock.c:198 (discriminator 6)) [ 22.733504][ C3] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:179 (discriminator 1) kernel/locking/spinlock.c:198 (discriminator 1)) [ 22.733506][ C3] rcu_core (kernel/rcu/tree.c:2869) [ 22.733508][ C3] handle_softirqs (kernel/softirq.c:622) [ 22.733510][ C3] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 22.733518][ C3] ? __lock_release.isra.0 (kernel/locking/lockdep.c:5535) [ 22.733519][ C3] ? _local_bh_enable (kernel/softirq.c:405 (discriminator 1)) [ 22.733521][ C3] __irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) [ 22.733523][ C3] irq_exit_rcu (kernel/softirq.c:752) [ 22.733524][ C3] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 37) arch/x86/kernel/apic/apic.c:1061 (discriminator 37)) [ 22.733526][ C3] [ 22.733527][ C3] [ 22.733527][ C3] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:697) [ 22.733529][ C3] RIP: 0010:qlist_free_all (mm/kasan/quarantine.c:177) [ 22.733532][ C3] Code: ec 00 00 00 4c 89 6c 24 18 49 89 f5 4c 89 74 24 20 49 89 fe 48 89 6c 24 08 4c 89 64 24 10 eb 34 48 63 85 b8 00 00 00 4c 8b 23 <48> 89 ef 48 29 c3 48 89 de e8 28 ef ff ff 66 90 48 89 de 48 89 ef All code ======== 0: ec in (%dx),%al 1: 00 00 add %al,(%rax) 3: 00 4c 89 6c add %cl,0x6c(%rcx,%rcx,4) 7: 24 18 and $0x18,%al 9: 49 89 f5 mov %rsi,%r13 c: 4c 89 74 24 20 mov %r14,0x20(%rsp) 11: 49 89 fe mov %rdi,%r14 14: 48 89 6c 24 08 mov %rbp,0x8(%rsp) 19: 4c 89 64 24 10 mov %r12,0x10(%rsp) 1e: eb 34 jmp 0x54 20: 48 63 85 b8 00 00 00 movslq 0xb8(%rbp),%rax 27: 4c 8b 23 mov (%rbx),%r12 2a:* 48 89 ef mov %rbp,%rdi <-- trapping instruction 2d: 48 29 c3 sub %rax,%rbx 30: 48 89 de mov %rbx,%rsi 33: e8 28 ef ff ff call 0xffffffffffffef60 38: 66 90 xchg %ax,%ax 3a: 48 89 de mov %rbx,%rsi 3d: 48 89 ef mov %rbp,%rdi Code starting with the faulting instruction =========================================== 0: 48 89 ef mov %rbp,%rdi 3: 48 29 c3 sub %rax,%rbx 6: 48 89 de mov %rbx,%rsi 9: e8 28 ef ff ff call 0xffffffffffffef36 e: 66 90 xchg %ax,%ax 10: 48 89 de mov %rbx,%rsi 13: 48 89 ef mov %rbp,%rdi [ 22.733533][ C3] RSP: 0018:ffa0000000857a40 EFLAGS: 00000246 [ 22.733536][ C3] RAX: 0000000000000000 RBX: ff110000027c8d70 RCX: ffffffffffffffff [ 22.733537][ C3] RDX: ffd400000009f200 RSI: 00000000027c8d70 RDI: ff110000027c8d70 [ 22.733538][ C3] RBP: ff1100000103fe40 R08: 0000000000000000 R09: 0000000000000000 [ 22.733539][ C3] R10: 0000000000000003 R11: 0000000000000001 R12: ff11000008fb0be8 [ 22.733540][ C3] R13: 0000000000000000 R14: ffa0000000857a70 R15: 0000000000000000 [ 22.733542][ C3] kasan_quarantine_reduce (mm/kasan/quarantine.c:286) [ 22.733544][ C3] __kasan_slab_alloc (mm/kasan/common.c:350) [ 22.733546][ C3] kmem_cache_alloc_node_noprof (./include/linux/kasan.h:253 mm/slub.c:4570 mm/slub.c:4899 mm/slub.c:4951) [ 22.733550][ C3] dup_task_struct (kernel/fork.c:187 (discriminator 7) kernel/fork.c:918 (discriminator 7)) [ 22.733552][ C3] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4472) [ 22.733554][ C3] copy_process (kernel/fork.c:2090 (discriminator 1)) [ 22.733555][ C3] ? restore_fpregs_from_user (arch/x86/kernel/fpu/signal.c:300) [ 22.733559][ C3] ? rcu_lockdep_current_cpu_online (kernel/rcu/tree.c:4040 (discriminator 3) kernel/rcu/tree.c:4032 (discriminator 3)) [ 22.733561][ C3] ? rcu_read_lock_any_held (./include/linux/lockdep.h:249 kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 22.733562][ C3] ? validate_chain (kernel/locking/lockdep.c:3801 (discriminator 2) kernel/locking/lockdep.c:3821 (discriminator 2) kernel/locking/lockdep.c:3876 (discriminator 2)) [ 22.733564][ C3] ? pidfd_prepare (./include/linux/list.h:1021 (discriminator 3)) [ 22.733566][ C3] ? rcu_lockdep_current_cpu_online (kernel/rcu/tree.c:4040 (discriminator 3) kernel/rcu/tree.c:4032 (discriminator 3)) [ 22.733567][ C3] ? rcu_lockdep_current_cpu_online (kernel/rcu/tree.c:4040 (discriminator 3) kernel/rcu/tree.c:4032 (discriminator 3)) [ 22.733569][ C3] ? rcu_read_lock_any_held (./include/linux/lockdep.h:249 kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 22.733570][ C3] kernel_clone (kernel/fork.c:2722) [ 22.733572][ C3] ? create_io_thread (kernel/fork.c:2660) [ 22.733574][ C3] ? __might_fault (mm/memory.c:7340 (discriminator 5)) [ 22.733576][ C3] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 22.733579][ C3] __do_sys_clone (kernel/fork.c:2863) [ 22.733580][ C3] ? kernel_clone (./include/trace/events/sched.h:396 (discriminator 19)) [ 22.733583][ C3] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 22.733585][ C3] ? trace_irq_enable.constprop.0 (./include/trace/events/preemptirq.h:40 (discriminator 22)) [ 22.733588][ C3] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 22.733589][ C3] ? trace_hardirqs_off (kernel/trace/trace_preemptirq.c:104 (discriminator 1)) [ 22.733591][ C3] ? exc_page_fault (arch/x86/mm/fault.c:1480 (discriminator 3) arch/x86/mm/fault.c:1527 (discriminator 3)) [ 22.733592][ C3] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) [ 22.733594][ C3] RIP: 0033:0x7feddd846226 [ 22.733596][ C3] Code: 7d e0 e8 7d a4 f5 ff 45 31 c0 31 d2 31 f6 64 48 8b 04 25 10 00 00 00 bf 11 00 20 01 4c 8d 90 d0 02 00 00 b8 38 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 5a 89 c3 85 c0 75 2f 64 48 8b 04 25 10 00 00 All code ======== 0: 7d e0 jge 0xffffffffffffffe2 2: e8 7d a4 f5 ff call 0xfffffffffff5a484 7: 45 31 c0 xor %r8d,%r8d a: 31 d2 xor %edx,%edx c: 31 f6 xor %esi,%esi e: 64 48 8b 04 25 10 00 mov %fs:0x10,%rax 15: 00 00 17: bf 11 00 20 01 mov $0x1200011,%edi 1c: 4c 8d 90 d0 02 00 00 lea 0x2d0(%rax),%r10 23: b8 38 00 00 00 mov $0x38,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 5a ja 0x8c 32: 89 c3 mov %eax,%ebx 34: 85 c0 test %eax,%eax 36: 75 2f jne 0x67 38: 64 fs 39: 48 rex.W 3a: 8b .byte 0x8b 3b: 04 25 add $0x25,%al 3d: 10 00 adc %al,(%rax) ... Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 5a ja 0x62 8: 89 c3 mov %eax,%ebx a: 85 c0 test %eax,%eax c: 75 2f jne 0x3d e: 64 fs f: 48 rex.W 10: 8b .byte 0x8b 11: 04 25 add $0x25,%al 13: 10 00 adc %al,(%rax) ... [ 22.733597][ C3] RSP: 002b:00007fff3429f8f0 EFLAGS: 00000246 ORIG_RAX: 0000000000000038 [ 22.733598][ C3] RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007feddd846226 [ 22.733599][ C3] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001200011 [ 22.733600][ C3] RBP: 00007fff3429f910 R08: 0000000000000000 R09: 0000000000000040 [ 22.733601][ C3] R10: 00007feddd783e50 R11: 0000000000000246 R12: 00005561b6451d20 Finger prints: mark_lock_irq:mark_lock:mark_usage:__lock_acquire:_raw_spin_lock