====================================== | [ 714.581211][ C2] #1: ffffffff9d777d20 (rcu_read_lock){....}-{1:3}, at: unwind_next_frame (./include/linux/rcupdate.h:300 (discriminator 2) ./include/linux/rcupdate.h:838 (discriminator 2) ./include/linux/rcupdate.h:1181 (discriminator 2) arch/x86/kernel/unwind_orc.c:495 (discriminator 2)) | [ 714.581441][ C2] #2: ffffffff9d777c00 (rcu_callback){....}-{0:0}, at: rcu_do_batch (./include/linux/rcupdate.h:300 (discriminator 2) kernel/rcu/tree.c:2611 (discriminator 2)) | [ 714.581610][ C2] | [ 714.581610][ C2] stack backtrace: [ 714.581837][ C2] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 714.581839][ C2] Call Trace: [ 714.581841][ C2] [ 714.581843][ C2] dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120) [ 714.581848][ C2] print_usage_bug.part.0.cold (kernel/locking/lockdep.c:4042) [ 714.581850][ C2] ? filter_irq_stacks (kernel/stacktrace.c:402) [ 714.581854][ C2] mark_lock_irq (kernel/locking/lockdep.c:4013 kernel/locking/lockdep.c:4056 kernel/locking/lockdep.c:4267) [ 714.581855][ C2] ? sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 37) arch/x86/kernel/apic/apic.c:1061 (discriminator 37)) [ 714.581858][ C2] ? asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:697) [ 714.581860][ C2] ? save_trace (kernel/locking/lockdep.c:589) [ 714.581861][ C2] ? calculate_order (./include/asm-generic/getorder.h:41 mm/slub.c:7520) [ 714.581865][ C2] mark_lock (kernel/locking/lockdep.c:4753) [ 714.581867][ C2] mark_usage (kernel/locking/lockdep.c:4642) [ 714.581868][ C2] __lock_acquire (kernel/locking/lockdep.c:5191) [ 714.581870][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4325) [ 714.581871][ C2] ? rcu_do_batch (./include/linux/rcupdate.h:310 (discriminator 2) kernel/rcu/tree.c:2619 (discriminator 2)) [ 714.581874][ C2] lock_acquire.part.0 (kernel/locking/lockdep.c:5868 (discriminator 1)) [ 714.581875][ C2] ? tcf_mirred_release (./include/linux/spinlock.h:342 net/sched/act_mirred.c:78) act_mirred [ 714.581877][ C2] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 714.581879][ C2] ? lock_acquire (./include/trace/events/lock.h:24 (discriminator 22) kernel/locking/lockdep.c:5831 (discriminator 22)) [ 714.581881][ C2] _raw_spin_lock (./include/linux/spinlock_api_smp.h:158 (discriminator 1) kernel/locking/spinlock.c:158 (discriminator 1)) [ 714.581883][ C2] ? tcf_mirred_release (./include/linux/spinlock.h:342 net/sched/act_mirred.c:78) act_mirred [ 714.581885][ C2] tcf_mirred_release (./include/linux/spinlock.h:342 net/sched/act_mirred.c:78) act_mirred [ 714.581887][ C2] tcf_action_rcu_free (net/sched/act_api.c:367 net/sched/act_api.c:378) [ 714.581889][ C2] ? rcu_do_batch (./include/linux/rcupdate.h:310 (discriminator 2) kernel/rcu/tree.c:2619 (discriminator 2)) [ 714.581890][ C2] rcu_do_batch (kernel/rcu/tree.c:2617) [ 714.581893][ C2] ? trace_rcu_batch_end (./include/trace/events/rcu.h:714 (discriminator 19)) [ 714.581895][ C2] ? lockdep_hardirqs_on_prepare.part.0 (kernel/locking/lockdep.c:470 (discriminator 2) kernel/locking/lockdep.c:4411 (discriminator 2)) [ 714.581897][ C2] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4472) [ 714.581898][ C2] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:178 (discriminator 6) kernel/locking/spinlock.c:198 (discriminator 6)) [ 714.581900][ C2] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:179 (discriminator 1) kernel/locking/spinlock.c:198 (discriminator 1)) [ 714.581902][ C2] rcu_core (kernel/rcu/tree.c:2869) [ 714.581904][ C2] handle_softirqs (kernel/softirq.c:622) [ 714.581906][ C2] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 714.581909][ C2] ? __lock_release.isra.0 (kernel/locking/lockdep.c:5535) [ 714.581910][ C2] ? _local_bh_enable (kernel/softirq.c:405 (discriminator 1)) [ 714.581912][ C2] __irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) [ 714.581914][ C2] irq_exit_rcu (kernel/softirq.c:752) [ 714.581915][ C2] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 37) arch/x86/kernel/apic/apic.c:1061 (discriminator 37)) [ 714.581917][ C2] [ 714.581918][ C2] [ 714.581919][ C2] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:697) [ 714.581920][ C2] RIP: 0010:lock_acquire.part.0 (./arch/x86/include/asm/irqflags.h:158 (discriminator 1) kernel/locking/lockdep.c:5871 (discriminator 1)) [ 714.581922][ C2] Code: ff 65 0f c1 05 37 d9 33 04 83 f8 01 4c 8b 14 24 0f 85 30 01 00 00 9c 58 f6 c4 02 0f 85 4d 01 00 00 4d 85 d2 0f 85 16 01 00 00 <48> 8b 44 24 30 65 48 2b 05 a9 92 33 04 0f 85 43 01 00 00 48 83 c4 All code ======== 0: ff 65 0f jmp *0xf(%rbp) 3: c1 05 37 d9 33 04 83 roll $0x83,0x433d937(%rip) # 0x433d941 a: f8 clc b: 01 4c 8b 14 add %ecx,0x14(%rbx,%rcx,4) f: 24 0f and $0xf,%al 11: 85 30 test %esi,(%rax) 13: 01 00 add %eax,(%rax) 15: 00 9c 58 f6 c4 02 0f add %bl,0xf02c4f6(%rax,%rbx,2) 1c: 85 4d 01 test %ecx,0x1(%rbp) 1f: 00 00 add %al,(%rax) 21: 4d 85 d2 test %r10,%r10 24: 0f 85 16 01 00 00 jne 0x140 2a:* 48 8b 44 24 30 mov 0x30(%rsp),%rax <-- trapping instruction 2f: 65 48 2b 05 a9 92 33 sub %gs:0x43392a9(%rip),%rax # 0x43392e0 36: 04 37: 0f 85 43 01 00 00 jne 0x180 3d: 48 rex.W 3e: 83 .byte 0x83 3f: c4 .byte 0xc4 Code starting with the faulting instruction =========================================== 0: 48 8b 44 24 30 mov 0x30(%rsp),%rax 5: 65 48 2b 05 a9 92 33 sub %gs:0x43392a9(%rip),%rax # 0x43392b6 c: 04 d: 0f 85 43 01 00 00 jne 0x156 13: 48 rex.W 14: 83 .byte 0x83 15: c4 .byte 0xc4 [ 714.581924][ C2] RSP: 0018:ffa0000000517138 EFLAGS: 00000206 [ 714.581926][ C2] RAX: 0000000000000046 RBX: 0000000000000000 RCX: b3920c865c501c38 [ 714.581928][ C2] RDX: 0000000000000001 RSI: ffffffff9d1ebde8 RDI: ffffffff9cc6f6c0 [ 714.581929][ C2] RBP: 0000000000000000 R08: 0000000000000001 R09: ff1100000c8dd158 [ 714.581929][ C2] R10: 0000000000000200 R11: 0000000000000001 R12: ffffffff9d777d20 [ 714.581930][ C2] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000002 [ 714.581933][ C2] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 714.581934][ C2] ? lock_acquire (./include/trace/events/lock.h:24 (discriminator 22) kernel/locking/lockdep.c:5831 (discriminator 22)) [ 714.581936][ C2] unwind_next_frame (./include/linux/rcupdate.h:300 (discriminator 2) ./include/linux/rcupdate.h:838 (discriminator 2) ./include/linux/rcupdate.h:1181 (discriminator 2) arch/x86/kernel/unwind_orc.c:495 (discriminator 2)) [ 714.581938][ C2] ? unwind_next_frame (./include/linux/rcupdate.h:300 (discriminator 2) ./include/linux/rcupdate.h:838 (discriminator 2) ./include/linux/rcupdate.h:1181 (discriminator 2) arch/x86/kernel/unwind_orc.c:495 (discriminator 2)) [ 714.581939][ C2] ? ksys_mmap_pgoff (mm/mmap.c:606) [ 714.581942][ C2] ? kmem_cache_alloc_noprof (./include/linux/kasan.h:253 mm/slub.c:4570 mm/slub.c:4899 mm/slub.c:4906) [ 714.581944][ C2] ? stack_access_ok (./arch/x86/include/asm/stacktrace.h:55) [ 714.581945][ C2] ? kmem_cache_free (./include/linux/slab.h:950 (discriminator 1) mm/slub.c:2641 (discriminator 1) mm/slub.c:6251 (discriminator 1) mm/slub.c:6378 (discriminator 1)) [ 714.581948][ C2] ? __unwind_start (arch/x86/kernel/unwind_orc.c:787) [ 714.581949][ C2] ? write_profile (profile.c:?) [ 714.581952][ C2] arch_stack_walk (arch/x86/kernel/stacktrace.c:25) [ 714.581955][ C2] ? ksys_mmap_pgoff (mm/mmap.c:606) [ 714.581958][ C2] stack_trace_save (kernel/stacktrace.c:122 (discriminator 1)) [ 714.581960][ C2] ? filter_irq_stacks (kernel/stacktrace.c:402) [ 714.581963][ C2] set_track_prepare (mm/slub.c:1038) [ 714.581966][ C2] ? __kmalloc_cache_noprof (./include/linux/kmemleak.h:44 mm/slub.c:4575 mm/slub.c:4899 mm/slub.c:5415) [ 714.581967][ C2] ? kmem_cache_free (./include/linux/slab.h:950 (discriminator 1) mm/slub.c:2641 (discriminator 1) mm/slub.c:6251 (discriminator 1) mm/slub.c:6378 (discriminator 1)) [ 714.581969][ C2] ? vms_complete_munmap_vmas (mm/vma.c:1361) [ 714.581971][ C2] ? __mmap_region (mm/vma.c:2617 mm/vma.c:2780) [ 714.581973][ C2] ? mmap_region (mm/vma.c:2857) [ 714.581974][ C2] ? do_mmap (mm/mmap.c:560) [ 714.581975][ C2] ? vm_mmap_pgoff (mm/util.c:581) [ 714.581977][ C2] ? ksys_mmap_pgoff (mm/mmap.c:606) [ 714.581979][ C2] __alloc_object (mm/kmemleak.c:701) [ 714.581981][ C2] __create_object (mm/kmemleak.c:779) [ 714.581983][ C2] __kmalloc_cache_noprof (./include/linux/kmemleak.h:44 mm/slub.c:4575 mm/slub.c:4899 mm/slub.c:5415) [ 714.581985][ C2] ? vms_complete_munmap_vmas (mm/vma.c:1361) [ 714.581986][ C2] kmem_cache_free (./include/linux/slab.h:950 (discriminator 1) mm/slub.c:2641 (discriminator 1) mm/slub.c:6251 (discriminator 1) mm/slub.c:6378 (discriminator 1)) [ 714.581988][ C2] ? fput (./include/linux/preempt.h:468 ./include/linux/file_ref.h:150 fs/file_table.c:586) [ 714.581991][ C2] vms_complete_munmap_vmas (mm/vma.c:1361) [ 714.581993][ C2] ? __mmap_new_vma (./include/linux/fs.h:523 mm/vma.c:1840 mm/vma.c:2585) [ 714.581994][ C2] ? perf_event_mmap (./include/linux/instrumented.h:82 ./include/linux/atomic/atomic-instrumented.h:32 kernel/events/core.c:9932) [ 714.581997][ C2] ? __mmap_new_vma (mm/vma.h:615 mm/vma.h:623 mm/vma.c:2583) [ 714.582000][ C2] ? vma_set_page_prot (mm/mmap.c:87) [ 714.582002][ C2] __mmap_region (mm/vma.c:2617 mm/vma.c:2780) [ 714.582004][ C2] ? vma_merge_new_range (mm/vma.c:1083) [ 714.582005][ C2] ? rcu_lockdep_current_cpu_online (kernel/rcu/tree.c:4040 (discriminator 3) kernel/rcu/tree.c:4032 (discriminator 3)) [ 714.582007][ C2] ? rcu_read_lock_any_held (./include/linux/lockdep.h:249 kernel/rcu/update.c:386 kernel/rcu/update.c:380) [ 714.582009][ C2] ? __lock_acquire (kernel/locking/lockdep.c:5237) [ 714.582010][ C2] ? init_data_structures_once.part.0 (kernel/locking/lockdep.c:3378 kernel/locking/lockdep.c:3437 kernel/locking/lockdep.c:3482 kernel/locking/lockdep.c:1210) [ 714.582016][ C2] ? mas_prev (lib/maple_tree.c:5211 lib/maple_tree.c:5204) [ 714.582022][ C2] ? vm_unmapped_area (./include/trace/events/mmap.h:10 (discriminator 22) mm/mmap.c:674 (discriminator 22)) [ 714.582024][ C2] ? perf_trace_mm_lru_insertion (./include/trace/events/pagemap.h:28) [ 714.582027][ C2] ? arch_get_unmapped_area_topdown (./include/linux/instrumented.h:82 ./include/asm-generic/bitops/instrumented-non-atomic.h:141 ./include/linux/thread_info.h:133 arch/x86/kernel/sys_x86_64.c:177) [ 714.582030][ C2] mmap_region (mm/vma.c:2857) [ 714.582032][ C2] ? mm_take_all_locks (mm/vma.c:2266 (discriminator 1)) [ 714.582033][ C2] ? find_held_lock (kernel/locking/lockdep.c:5350) [ 714.582036][ C2] ? __get_unmapped_area (./include/linux/security.h:1187 mm/mmap.c:863) [ 714.582038][ C2] ? ovl_file_end_write (./include/linux/fs.h:1353) [ 714.582041][ C2] do_mmap (mm/mmap.c:560) [ 714.582044][ C2] ? __ia32_sys_brk (mm/mmap.c:116) [ 714.582046][ C2] ? down_write_killable (./include/linux/instrumented.h:55 ./include/linux/atomic/atomic-instrumented.h:4457 kernel/locking/rwsem.c:268 kernel/locking/rwsem.c:1346 kernel/locking/rwsem.c:1361 kernel/locking/rwsem.c:1639) [ 714.582048][ C2] ? down_write (kernel/locking/rwsem.c:1627) [ 714.582050][ C2] vm_mmap_pgoff (mm/util.c:581) [ 714.582052][ C2] ? randomize_page (mm/util.c:387) [ 714.582054][ C2] ? __fget_files (./include/linux/rcupdate.h:871 fs/file.c:1101) [ 714.582057][ C2] ksys_mmap_pgoff (mm/mmap.c:606) [ 714.582059][ C2] ? rcu_is_watching (./include/linux/context_tracking.h:128 (discriminator 3) kernel/rcu/tree.c:752 (discriminator 3)) [ 714.582061][ C2] ? lockdep_hardirqs_on (kernel/locking/lockdep.c:4472) [ 714.582063][ C2] ? do_syscall_64 (./include/linux/entry-common.h:177 arch/x86/entry/syscall_64.c:89) [ 714.582064][ C2] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 714.582065][ C2] ? trace_hardirqs_off (kernel/trace/trace_preemptirq.c:104 (discriminator 1)) [ 714.582068][ C2] ? exc_page_fault (arch/x86/mm/fault.c:1480 (discriminator 3) arch/x86/mm/fault.c:1527 (discriminator 3)) [ 714.582070][ C2] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) [ 714.582071][ C2] RIP: 0033:0x7f0aeba3e85c [ 714.582074][ C2] Code: 1e fa 41 f7 c1 ff 0f 00 00 75 33 55 48 89 e5 41 54 41 89 cc 53 48 89 fb 48 85 ff 74 51 45 89 e2 48 89 df b8 09 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 24 5b 41 5c 5d c3 0f 1f 80 00 00 00 00 c7 05 All code ======== 0: 1e (bad) 1: fa cli 2: 41 f7 c1 ff 0f 00 00 test $0xfff,%r9d 9: 75 33 jne 0x3e b: 55 push %rbp c: 48 89 e5 mov %rsp,%rbp f: 41 54 push %r12 11: 41 89 cc mov %ecx,%r12d 14: 53 push %rbx 15: 48 89 fb mov %rdi,%rbx 18: 48 85 ff test %rdi,%rdi 1b: 74 51 je 0x6e 1d: 45 89 e2 mov %r12d,%r10d 20: 48 89 df mov %rbx,%rdi 23: b8 09 00 00 00 mov $0x9,%eax 28: 0f 05 syscall 2a:* 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax <-- trapping instruction 30: 77 24 ja 0x56 32: 5b pop %rbx 33: 41 5c pop %r12 35: 5d pop %rbp 36: c3 ret 37: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 3e: c7 .byte 0xc7 3f: 05 .byte 0x5 Code starting with the faulting instruction =========================================== 0: 48 3d 00 f0 ff ff cmp $0xfffffffffffff000,%rax 6: 77 24 ja 0x2c 8: 5b pop %rbx 9: 41 5c pop %r12 b: 5d pop %rbp c: c3 ret d: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 14: c7 .byte 0xc7 15: 05 .byte 0x5 [ 714.582075][ C2] RSP: 002b:00007fffc9637d50 EFLAGS: 00000206 ORIG_RAX: 0000000000000009 [ 714.582077][ C2] RAX: ffffffffffffffda RBX: 00007f0aeb9d5000 RCX: 00007f0aeba3e85c [ 714.582077][ C2] RDX: 0000000000000003 RSI: 0000000000004000 RDI: 00007f0aeb9d5000 [ 714.582078][ C2] RBP: 00007fffc9637d60 R08: 0000000000000005 R09: 0000000000069000 [ 714.582079][ C2] R10: 0000000000000812 R11: 0000000000000206 R12: 0000000000000812 Finger prints: mark_lock_irq:mark_lock:mark_usage:__lock_acquire:_raw_spin_lock