Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-115436

[Integration Testing Task]RIP: 0010:xfrm6_tunnel_free_spi+0x76/0x160 [xfrm6_tunnel] [rhel-10.0.z]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • 1
    • rhel-net-core-2
    • NST-Core2-25W38
    • 1
    • False
    • Hide

      None

      Show
      None
    • None

      This is a clone of issue RHEL-70101 to use for version rhel-10.0.z

      Original description:

      What were you trying to do that didn't work?

      system reboots when run a batch of ipsec test cases.

      the issue was found in several MR kernel-rt, but I think this issue might exists on general kernels.

      no simple reproducer, and not reproduced every time. 

      https://beaker.engineering.redhat.com/jobs/10261755 

      https://beaker.engineering.redhat.com/jobs/10191322 

      https://beaker.engineering.redhat.com/jobs/10185935 

       

      /kernel/networking/ipsec/ipsec_basic/ipsec_basic_netns

      SUB_PARAM="-6 -p esp -e des3_ede -a sha1 -m beet -s '65494'"

      [ 3593.445979] ------------[ cut here ]------------ 
      [ 3593.445982] WARNING: CPU: 26 PID: 295 at net/ipv6/xfrm6_tunnel.c:341 xfrm6_tunnel_net_exit+0x65/0xc0 [xfrm6_tunnel] 
      [ 3593.462787] Modules linked in: bridge(-) stp ipcomp6 xfrm6_tunnel tunnel6 xfrm4_tunnel tunnel4 ipcomp xfrm_ipcomp des_generic des3_ede_x86_64 libdes esp4 echainiv esp6 ah6 ib_core geneve ah4 llc sctp ip6_udp_tunnel udp_tunnel tls sunrpc intel_rapl_msr platform_profile intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common dell_wmi_descriptor sb_edac mei_me mgag200 mei sparse_keymap rfkill video ipmi_ssif x86_pkg_temp_thermal iTCO_wdt dcdbas i40e mxm_wmi ixgbe igb iTCO_vendor_support i2c_algo_bit pcspkr intel_powerclamp lpc_ich coretemp acpi_power_meter libie mdio dca rapl intel_cstate sg ipmi_si intel_uncore acpi_ipmi ipmi_devintf ipmi_msghandler loop fuse nfnetlink xfs sd_mod ahci libahci crct10dif_pclmul crc32_pclmul libata crc32c_intel ghash_clmulni_intel wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: veth] 
      [ 3593.545650] CPU: 26 UID: 0 PID: 295 Comm: kworker/u112:22 Kdump: loaded Not tainted 6.12.0-31.37_1561719302.el10.x86_64+rt #1 
      [ 3593.558267] Hardware name: Dell Inc. PowerEdge R730/072T6D, BIOS 2.17.0 03/15/2023 
      [ 3593.566715] Workqueue: netns cleanup_net 
      [ 3593.571092] RIP: 0010:xfrm6_tunnel_net_exit+0x65/0xc0 [xfrm6_tunnel] 
      [ 3593.578185] Code: f1 2e 58 d7 31 c0 eb 17 66 66 2e 0f 1f 84 00 00 00 00 00 66 90 83 c0 01 3d 00 01 00 00 74 17 89 c2 48 8b 14 d3 48 85 d2 74 eb <0f> 0b 83 c0 01 3d 00 01 00 00 75 e9 31 c0 eb 25 66 66 2e 0f 1f 84 
      [ 3593.599142] RSP: 0018:ffffa78d40c03dc0 EFLAGS: 00010286 
      [ 3593.604973] RAX: 0000000000000021 RBX: ffff8faf3ef8c000 RCX: 0000000000000000 
      [ 3593.612937] RDX: ffff8faf453d2c00 RSI: ffffffff9905a836 RDI: 00000000ffffffff 
      [ 3593.620902] RBP: ffff8faf2caa3900 R08: 0000000000000001 R09: ffffffff9848d862 
      [ 3593.628864] R10: 0000000080270020 R11: ffff8faf01cd1b10 R12: ffffffffc0f0c0a0 
      [ 3593.636828] R13: ffffffffffffff88 R14: ffffffff9830b830 R15: ffff8faf3459a698 
      [ 3593.644789] FS:  0000000000000000(0000) GS:ffff8fcdffd00000(0000) knlGS:0000000000000000 
      [ 3593.653820] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 
      [ 3593.660231] CR2: 000055b7b3ace10c CR3: 0000000118bd2004 CR4: 00000000003706f0 
      [ 3593.668194] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 
      [ 3593.676155] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 
      [ 3593.684118] Call Trace: 
      [ 3593.686845]  <TASK> 
      [ 3593.689184]  ? show_trace_log_lvl+0x1b0/0x2f0 
      [ 3593.694038]  ? show_trace_log_lvl+0x1b0/0x2f0 
      [ 3593.698900]  ? ops_exit_list+0x33/0x70 
      [ 3593.703082]  ? xfrm6_tunnel_net_exit+0x65/0xc0 [xfrm6_tunnel] 
      [ 3593.709494]  ? __warn.cold+0x93/0xf4 
      [ 3593.713483]  ? xfrm6_tunnel_net_exit+0x65/0xc0 [xfrm6_tunnel] 
      [ 3593.719895]  ? report_bug+0xea/0x170 
      [ 3593.723884]  ? handle_bug+0x53/0x90 
      [ 3593.727777]  ? exc_invalid_op+0x17/0x70 
      [ 3593.732057]  ? asm_exc_invalid_op+0x1a/0x20 
      [ 3593.736724]  ? cleanup_net+0xc0/0x4a0 
      [ 3593.740811]  ? xfrm_state_flush+0x322/0x380 
      [ 3593.745478]  ? xfrm6_tunnel_net_exit+0x65/0xc0 [xfrm6_tunnel] 
      [ 3593.751889]  ops_exit_list+0x33/0x70 
      [ 3593.755877]  cleanup_net+0x2db/0x4a0 
      [ 3593.759866]  process_one_work+0x177/0x330 
      [ 3593.764341]  worker_thread+0x252/0x390 
      [ 3593.768524]  ? __pfx_worker_thread+0x10/0x10 
      [ 3593.773289]  kthread+0xe1/0x110 
      [ 3593.776792]  ? __pfx_kthread+0x10/0x10 
      [ 3593.780974]  ret_from_fork+0x34/0x50 
      [ 3593.784962]  ? __pfx_kthread+0x10/0x10 
      [ 3593.789145]  ret_from_fork_asm+0x1a/0x30 
      [ 3593.793524]  </TASK> 
      [ 3593.795959] ---[ end trace 0000000000000000 ]--- 
      [ 3593.801136] ------------[ cut here ]------------ 
      [ 3593.801138] WARNING: CPU: 26 PID: 295 at net/ipv6/xfrm6_tunnel.c:344 xfrm6_tunnel_net_exit+0xac/0xc0 [xfrm6_tunnel] 
      [ 3593.817937] Modules linked in: bridge(-) stp ipcomp6 xfrm6_tunnel tunnel6 xfrm4_tunnel tunnel4 ipcomp xfrm_ipcomp des_generic des3_ede_x86_64 libdes esp4 echainiv esp6 ah6 ib_core geneve ah4 llc sctp ip6_udp_tunnel udp_tunnel tls sunrpc intel_rapl_msr platform_profile intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common dell_wmi_descriptor sb_edac mei_me mgag200 mei sparse_keymap rfkill video ipmi_ssif x86_pkg_temp_thermal iTCO_wdt dcdbas i40e mxm_wmi ixgbe igb iTCO_vendor_support i2c_algo_bit pcspkr intel_powerclamp lpc_ich coretemp acpi_power_meter libie mdio dca rapl intel_cstate sg ipmi_si intel_uncore acpi_ipmi ipmi_devintf ipmi_msghandler loop fuse nfnetlink xfs sd_mod ahci libahci crct10dif_pclmul crc32_pclmul libata crc32c_intel ghash_clmulni_intel wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: veth] 
      [ 3593.900792] CPU: 26 UID: 0 PID: 295 Comm: kworker/u112:22 Kdump: loaded Tainted: G        W         -------  ---  6.12.0-31.37_1561719302.el10.x86_64+rt #1 
      [ 3593.916310] Tainted: [W]=WARN 
      [ 3593.919617] Hardware name: Dell Inc. PowerEdge R730/072T6D, BIOS 2.17.0 03/15/2023 
      [ 3593.928066] Workqueue: netns cleanup_net 
      [ 3593.932441] RIP: 0010:xfrm6_tunnel_net_exit+0xac/0xc0 [xfrm6_tunnel] 
      [ 3593.939532] Code: 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 83 c0 01 3d 00 01 00 00 74 1e 89 c2 48 81 c2 00 01 00 00 48 8b 14 d3 48 85 d2 74 e4 <0f> 0b 83 c0 01 3d 00 01 00 00 75 e2 5b 5d c3 cc cc cc cc 90 90 90 
      [ 3593.960487] RSP: 0018:ffffa78d40c03dc0 EFLAGS: 00010282 
      [ 3593.966319] RAX: 0000000000000002 RBX: ffff8faf3ef8c000 RCX: 0000000000000000 
      [ 3593.974281] RDX: ffff8faf453d2c10 RSI: ffffffff9905a836 RDI: 00000000ffffffff 
      [ 3593.982244] RBP: ffff8faf2caa3900 R08: 0000000000000001 R09: ffffffff9848d862 
      [ 3593.990207] R10: 0000000080270020 R11: ffff8faf01cd1b10 R12: ffffffffc0f0c0a0 
      [ 3593.998169] R13: ffffffffffffff88 R14: ffffffff9830b830 R15: ffff8faf3459a698 
      [ 3594.006132] FS:  0000000000000000(0000) GS:ffff8fcdffd00000(0000) knlGS:0000000000000000 
      [ 3594.015163] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 
      [ 3594.021573] CR2: 000055b7b3ace10c CR3: 0000000118bd2004 CR4: 00000000003706f0 
      [ 3594.029537] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 
      [ 3594.037501] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 
      [ 3594.045463] Call Trace: 
      [ 3594.048190]  <TASK> 
      [ 3594.050528]  ? show_trace_log_lvl+0x1b0/0x2f0 
      [ 3594.055389]  ? show_trace_log_lvl+0x1b0/0x2f0 
      [ 3594.060250]  ? ops_exit_list+0x33/0x70 
      [ 3594.064433]  ? xfrm6_tunnel_net_exit+0xac/0xc0 [xfrm6_tunnel] 
      [ 3594.070845]  ? __warn.cold+0x93/0xf4 
      [ 3594.074833]  ? xfrm6_tunnel_net_exit+0xac/0xc0 [xfrm6_tunnel] 
      [ 3594.081246]  ? report_bug+0xea/0x170 
      [ 3594.085234]  ? handle_bug+0x53/0x90 
      [ 3594.089125]  ? exc_invalid_op+0x17/0x70 
      [ 3594.093404]  ? asm_exc_invalid_op+0x1a/0x20 
      [ 3594.098072]  ? cleanup_net+0xc0/0x4a0 
      [ 3594.102157]  ? xfrm_state_flush+0x322/0x380 
      [ 3594.106826]  ? xfrm6_tunnel_net_exit+0xac/0xc0 [xfrm6_tunnel] 
      [ 3594.113237]  ops_exit_list+0x33/0x70 
      [ 3594.117226]  cleanup_net+0x2db/0x4a0 
      [ 3594.121214]  process_one_work+0x177/0x330 
      [ 3594.125689]  worker_thread+0x252/0x390 
      [ 3594.129871]  ? __pfx_worker_thread+0x10/0x10 
      [ 3594.134636]  kthread+0xe1/0x110 
      [ 3594.138139]  ? __pfx_kthread+0x10/0x10 
      [ 3594.142321]  ret_from_fork+0x34/0x50 
      [ 3594.146309]  ? __pfx_kthread+0x10/0x10 
      [ 3594.150490]  ret_from_fork_asm+0x1a/0x30 
      [ 3594.154868]  </TASK> 
      [ 3594.157302] ---[ end trace 0000000000000000 ]--- 
      [ 3593.385499] restraintd[4271]: ** Completed Task : 187550134 
      [ 3594.033139] restraintd[4271]: ** Fetching task: 187550135 [/mnt/tests/gitlab.cee.redhat.com/kernel-qe/kernel/-/archive/master/kernel-master.tar.gz/networking/ipsec/ipsec_basic/ipsec_basic_netns] 
      [ 3597.934591] restraintd[4271]: ** Preparing metadata 
      [ 3598.486037] restraintd[4271]: ** Refreshing peer role hostnames: Retries 0 
      [ 3599.065049] restraintd[4271]: ** Updating env vars 
      [ 3599.065106] restraintd[4271]: ** Updating external watchdog: 4200 seconds 
      [ 3599.759069] restraintd[4271]: ** Installing dependencies 
      [ 3623.133646] restraintd[4271]: ** Running task: 187550135 [/kernel/networking/ipsec/ipsec_basic/ipsec_basic_netns] 
      [ 3636.456773] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this. 
      [ 3636.542046] br0: port 1(ha_veth0_br) entered blocking state 
      [ 3636.542072] br0: port 1(ha_veth0_br) entered disabled state 
      [ 3636.542080] ha_veth0_br: entered allmulticast mode 
      [ 3636.542143] ha_veth0_br: entered promiscuous mode 
      [ 3636.544123] br0: port 2(hb_veth0_br) entered blocking state 
      [ 3636.544127] br0: port 2(hb_veth0_br) entered disabled state 
      [ 3636.544134] hb_veth0_br: entered allmulticast mode 
      [ 3636.544195] hb_veth0_br: entered promiscuous mode 
      [ 3636.721978] br0: port 1(ha_veth0_br) entered blocking state 
      [ 3636.721994] br0: port 1(ha_veth0_br) entered forwarding state 
      [ 3636.806810] br0: port 2(hb_veth0_br) entered blocking state 
      [ 3636.806824] br0: port 2(hb_veth0_br) entered forwarding state 
      [ 3638.655609] br0: entered promiscuous mode 
      [ 3647.066296] br0: left promiscuous mode 
      [ 3650.520929] br0: entered promiscuous mode 
      [ 3660.130596] br0: left promiscuous mode 
      [ 3663.609061] br0: entered promiscuous mode 
      [ 3673.212263] br0: left promiscuous mode 
      [ 3676.685004] br0: entered promiscuous mode 
      [ 3683.042281] restraintd[4271]: *** Current Time: Tue Nov 26 21:43:47 2024  Localwatchdog at: Tue Nov 26 22:22:48 2024 
      [ 3687.421100] br0: left promiscuous mode 
      [ 3690.881236] br0: entered promiscuous mode 
      [ 3701.611505] br0: left promiscuous mode 
      [ 3705.067712] br0: entered promiscuous mode 
      [ 3714.597812] br0: left promiscuous mode 
      [ 3721.911835] BUG: kernel NULL pointer dereference, address: 0000000000000108 
      [ 3721.919606] #PF: supervisor read access in kernel mode 
      [ 3721.925338] #PF: error_code(0x0000) - not-present page 
      [ 3721.931068] PGD 800000011f61d067 P4D 800000011f61d067 PUD 13b1de067 PMD 0  
      [ 3721.938741] Oops: Oops: 0000 [#1] PREEMPT_RT SMP PTI 
      [ 3721.944280] CPU: 7 UID: 0 PID: 139104 Comm: kworker/7:0 Kdump: loaded Tainted: G        W         -------  ---  6.12.0-31.37_1561719302.el10.x86_64+rt #1 
      [ 3721.959610] Tainted: [W]=WARN 
      [ 3721.962917] Hardware name: Dell Inc. PowerEdge R730/072T6D, BIOS 2.17.0 03/15/2023 
      [ 3721.971361] Workqueue: events xfrm_state_gc_task 
      [ 3721.976514] RIP: 0010:xfrm6_tunnel_free_spi+0x76/0x160 [xfrm6_tunnel] 
      [ 3721.983702] Code: 71 d7 48 8b 45 00 48 8b 55 08 48 89 c1 48 31 d1 48 89 ce 48 c1 ee 20 31 ce 89 f1 c1 e9 10 31 f1 89 ce c1 ee 08 31 f1 0f b6 c9 <48> 8b 3c cb 48 85 ff 75 31 eb 66 66 66 2e 0f 1f 84 00 00 00 00 00 
      [ 3722.004655] RSP: 0018:ffffa78d49e43e10 EFLAGS: 00010206 
      [ 3722.010483] RAX: 0000000000000020 RBX: 0000000000000000 RCX: 0000000000000021 
      [ 3722.018445] RDX: 0100000000000000 RSI: 0000000000010001 RDI: ffffffffc0f0c700 
      [ 3722.026406] RBP: ffff8faf6d013504 R08: ffff8fcdff3b6e70 R09: 0000000000000307 
      [ 3722.034368] R10: 0000000000000000 R11: ffff8faf057e1b10 R12: 00000000ffffffff 
      [ 3722.042329] R13: ffff8faf057e1a80 R14: ffffffff99d4dc20 R15: 0000000000000000 
      [ 3722.050291] FS:  0000000000000000(0000) GS:ffff8fcdff380000(0000) knlGS:0000000000000000 
      [ 3722.059318] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 
      [ 3722.065727] CR2: 0000000000000108 CR3: 0000000f35922005 CR4: 00000000003706f0 
      [ 3722.073689] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 
      [ 3722.081651] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 
      [ 3722.089612] Call Trace: 
      [ 3722.092337]  <TASK> 
      [ 3722.094675]  ? show_trace_log_lvl+0x1b0/0x2f0 
      [ 3722.099535]  ? show_trace_log_lvl+0x1b0/0x2f0 
      [ 3722.104394]  ? ___xfrm_state_destroy+0xae/0x160 
      [ 3722.109448]  ? __die_body.cold+0x8/0x12 
      [ 3722.113726]  ? page_fault_oops+0x15a/0x170 
      [ 3722.118296]  ? exc_page_fault+0x73/0x160 
      [ 3722.122670]  ? asm_exc_page_fault+0x26/0x30 
      [ 3722.127338]  ? xfrm6_tunnel_free_spi+0x76/0x160 [xfrm6_tunnel] 
      [ 3722.133846]  ___xfrm_state_destroy+0xae/0x160 
      [ 3722.138704]  xfrm_state_gc_task+0x9c/0xd0 
      [ 3722.143175]  process_one_work+0x177/0x330 
      [ 3722.147647]  worker_thread+0x252/0x390 
      [ 3722.151828]  ? _raw_spin_lock_irqsave+0x1b/0x50 
      [ 3722.156881]  ? __pfx_worker_thread+0x10/0x10 
      [ 3722.161644]  kthread+0xe1/0x110 
      [ 3722.165144]  ? __pfx_kthread+0x10/0x10 
      [ 3722.169324]  ret_from_fork+0x34/0x50 
      [ 3722.173310]  ? __pfx_kthread+0x10/0x10 
      [ 3722.177489]  ret_from_fork_asm+0x1a/0x30 
      [ 3722.181867]  </TASK> 
      [ 3722.184301] Modules linked in: veth bridge stp ipcomp6 xfrm6_tunnel tunnel6 xfrm4_tunnel tunnel4 ipcomp xfrm_ipcomp des_generic des3_ede_x86_64 libdes esp4 echainiv esp6 ah6 ib_core geneve ah4 llc sctp ip6_udp_tunnel udp_tunnel tls sunrpc intel_rapl_msr platform_profile intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common dell_wmi_descriptor sb_edac mei_me mgag200 mei sparse_keymap rfkill video ipmi_ssif x86_pkg_temp_thermal iTCO_wdt dcdbas i40e mxm_wmi ixgbe igb iTCO_vendor_support i2c_algo_bit pcspkr intel_powerclamp lpc_ich coretemp acpi_power_meter libie mdio dca rapl intel_cstate sg ipmi_si intel_uncore acpi_ipmi ipmi_devintf ipmi_msghandler loop fuse nfnetlink xfs sd_mod ahci libahci crct10dif_pclmul crc32_pclmul libata crc32c_intel ghash_clmulni_intel wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: stp] 
      [ 3722.267259] CR2: 0000000000000108  

      What is the impact of this issue to you?

      Please provide the package NVR for which the bug is seen:

      6.12.0-31.37_1561719302.el10.x86_64+rt

      How reproducible is this bug?:

      sometimes

      Steps to reproduce

      1.  clone the job. 
      2.  
      3.  

      Expected results

      Actual results

              MuXiumei Xiumei Mu
              MuXiumei Xiumei Mu
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: