Description of problem: Booting up kernel 4.2.3-200.fc22.x86_64 with e.g. shorewall immediately drops all packets. dmesg is flooded by nf_conntrack: table full, dropping packet Version-Release number of selected component (if applicable): 4.2.3-200.fc22.x86_64 How reproducible: Boot kernel 4.2.3-200.fc22.x86_64 with shorewall enabled, have traffic on it (e.g. a lot of connections). Actual results: Packets are dropped and machine is therefore unusable. Even no ssh login is possible. Expected results: Working iptables and firewall Additional info: Known major problem in the kernel, fix available, please integrate it urgently: https://lists.debian.org/debian-kernel/2015/10/msg00007.html https://lists.debian.org/debian-kernel/2015/09/msg00250.html https://lists.debian.org/debian-kernel/2015/10/msg00034.html https://lists.debian.org/debian-kernel/2015/10/msg00119.html https://lists.debian.org/debian-kernel/2015/10/msg00094.html
The patch you've highlighted is queued for the 4.2.4 stable kernel release. That should be released sometime today, and Fedora will get an update for it very shortly after that. There will be no build before 4.2.4 anyway.
Kernel 4.2.4 has been released with the patch included, please release a kernel soon.
Build failed, please release a new build: http://koji.fedoraproject.org/koji/buildinfo?buildID=693902
Looks like build server is out of diskspace: <type 'exceptions.OSError'>: [Errno 28] No space left on device: '/mnt/koji/work/tasks/639/11560639'
Build from SRPM source: kernel is not stable: I'm using shorewall and shorewall6 (ipv6) with ipset command rules. Still same behavior: machine is pingable for ~20s, then machine network is dead After some tries I was able to boot into the old kernel (currently no console cable available ...) I had once messages on the console: Message from syslogd@arm at Oct 24 20:05:09 ... kernel:Internal error: : 1 [#1] SMP ARM e Message from syslogd@arm at Oct 24 20:05:09 ... kernel:Process ipset (pid: 2055, stack limit = 0xe8404220) Message from syslogd@arm at Oct 24 20:05:09 ... kernel:Stack: (0xe8405c40 to 0xe8406000) Message from syslogd@arm at Oct 24 20:05:09 ... kernel:5c40: 00000001 00000008 ee727912 c0567698 e8405ca3 00000001 ee727912 e80dd078 /var/log/messages: Oct 24 20:05:08 arm shorewall6: Compiling /etc/shorewall6/rules... Oct 24 20:05:08 arm audit: <audit-1325> table=filter family=10 entries=14 Oct 24 20:05:08 arm audit: <audit-1325> table=filter family=10 entries=15 Oct 24 20:05:09 arm audit: <audit-1325> table=filter family=10 entries=16 Oct 24 20:05:09 arm audit: <audit-1325> table=filter family=10 entries=17 Oct 24 20:05:09 arm audit: <audit-1325> table=filter family=10 entries=18 Oct 24 20:05:09 arm audit: <audit-1325> table=filter family=10 entries=19 Oct 24 20:05:09 arm kernel: Alignment trap: not handling instruction e1b62f9f at [<bf0e5db4>] Oct 24 20:05:09 arm kernel: Unhandled fault: alignment exception (0x001) at 0xee72792a Oct 24 20:05:09 arm kernel: pgd = ceb3c000 Oct 24 20:05:09 arm kernel: [ee72792a] *pgd=6e61141e(bad) Oct 24 20:05:09 arm kernel: Internal error: : 1 [#1] SMP ARM Looks to me that iptables with ipset is still broken ....(several ipset commands are issued to add the ip addresses to the according ipsets)
Dump on kernel 4.2.4: See also kernel mailing list, netdev, netfilter-devel mailing list [ 51.628258] Alignment trap: not handling instruction e1b62f9f at [<bf4b1db4>] [ 51.635464] Unhandled fault: alignment exception (0x001) at 0xcee0fc2a [ 51.642024] pgd = eb9e0000 [ 51.644731] [cee0fc2a] *pgd=4ee1141e(bad) [ 51.648786] Internal error: : 1 [#1] SMP ARM [ 51.653055] Modules linked in: xt_set ip_set_hash_ip xt_comment ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_nat_ipv6 ip6t_REJECT nf_reject_ipv6 xt_addrtype ip_set_hash_net ip_set iptable_mangle xt_mark ip6table_mangle iptable_raw nf_conntrack_ipv4 nf_defrag_ipv4 xt_CT ip6table_raw xt_multiport nf_conntrack_ipv6 nf_defrag_ipv6 nf_log_ipv4 xt_conntrack nf_nat_tftp nf_nat_snmp_basic nf_conntrack_snmp nf_nat_sip nf_nat_pptp nf_nat_proto_gre nf_nat_irc xt_NFLOG nfnetlink_log nf_nat_h323 nf_nat_ftp xt_LOG nf_nat_amanda nf_nat nf_log_ipv6 nf_log_common nf_conntrack_tftp nf_conntrack_sip nf_conntrack_sane nf_conntrack_proto_udplite nf_conntrack_proto_sctp nf_conntrack_pptp nf_conntrack_proto_gre nf_conntrack_netlink nfnetlink nf_conntrack_netbios_ns nf_conntrack_broadcast nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp ts_kmp nf_conntrack_amanda nf_conntrack ccm ip6table_filter ip6_tables bridge 8021q garp mrp stp llc sit tunnel4 ip_tunnel arc4 rtl8192cu rtl_usb rtl8192c_common rtlwifi mac80211 cfg80211 rfkill uas usb_storage axp20x_pek axp20x_regulator sun4i_ts sunxi_wdt sunxi_sid spi_sun4i phy_sun4i_usb leds_gpio cpufreq_dt nfsd mmc_block dwmac_sunxi stmmac_platform stmmac ptp pps_core i2c_mv64xxx rtc_sunxi sunxi_mmc ahci_sunxi libahci_platform ohci_platform ehci_platform mmc_core [ 51.768400] CPU: 0 PID: 2005 Comm: ipset Not tainted 4.2.4-200.BPiR1.fc22.armv7hl #1 [ 51.776133] Hardware name: Allwinner sun7i (A20) Family [ 51.781354] task: cea6ba80 ti: ceede000 task.ti: ceede000 [ 51.786775] PC is at ip_set_put_extensions+0xa0/0x230 [ip_set] [ 51.792620] LR is at hash_net6_list+0x350/0x398 [ip_set_hash_net] [ 51.798709] pc : [<bf4b1db8>] lr : [<bf4bf53c>] psr: 200d0013 [ 51.798709] sp : ceedfc40 ip : ee7a1098 fp : ee7a107c [ 51.810171] r10: cee0fc00 r9 : ebf20000 r8 : 00000000 [ 51.815392] r7 : cee0fc12 r6 : cee0fc2a r5 : ceba3c00 r4 : ebf20000 [ 51.821913] r3 : 00000002 r2 : 00000002 r1 : ebf20000 r0 : ceba3c00 [ 51.828434] Flags: nzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment user [ 51.835562] Control: 10c5387d Table: 6b9e006a DAC: 00000015 [ 51.841304] Process ipset (pid: 2005, stack limit = 0xceede220) [ 51.847218] Stack: (0xceedfc40 to 0xceee0000) [ 51.851576] fc40: 00000001 00000008 cee0fc12 c0567698 ceedfca3 00000001 cee0fc12 ee7a1078 [ 51.859748] fc60: 00000000 c0567704 ceba3c00 ceba3c00 ced90a2c cee0fc12 ee7a1078 bf4bf53c [ 51.867919] fc80: ee7a104c ee7a1074 ceba3c00 ee3f0000 ee7a107c ee7a1080 00000000 00000000 [ 51.876091] fca0: 80000000 38070000 08000000 ced90a2c ebf20000 ceba3c00 00000002 ebf90780 [ 51.884261] fcc0: 00000000 ee7a1000 bf4b65d8 bf4b3708 00000007 c0373910 ceba3c00 00000000 [ 51.892432] fce0: 00000024 00000003 000a062c 00000006 ee5b7214 ee5b721c 00000000 00000000 [ 51.900602] fd00: 00000000 00000000 00000000 00000000 00000000 00000000 ceba3c00 ced90800 [ 51.908773] fd20: ceba3c00 00000f40 ced90a2c ced90a2c ee5b7200 00000006 ceedfe2c c0810454 [ 51.916945] fd40: ceba3780 c08100fc c0e714c0 000007d5 ebe93800 ced90800 ceba3780 ceedfd8c [ 51.925116] fd60: ced9085c c0810b40 ebe93800 ceba3780 ee5b7200 00000007 bf4b4a08 ceedfdb8 [ 51.933287] fd80: 00000006 bf4b39e0 ceedfdb8 bf4b3328 bf4b39fc 00000000 bf4b6880 00000000 [ 51.941458] fda0: ee5b7200 bf4b3970 ceba3780 bf3ce388 bf4b48f0 00000000 00000000 ee5b7214 [ 51.949630] fdc0: ee5b721c 00000000 00000000 00000000 00000000 00000000 00000000 00000000 [ 51.957800] fde0: 00000000 c0253da0 bf3cee00 bf3ceea8 bf4b4a94 bf3ceec0 ceedfde0 c0e714c0 [ 51.965971] fe00: 0000008c 00000006 0000002c ee5b7200 ceba3780 bf3ce1b4 ced90800 00000000 [ 51.974142] fe20: 00000008 00000000 0000002c c0812d48 ebe93800 0000002c ceba3780 c0812524 [ 51.982313] fe40: ced90800 7fffffff 00000000 ced90800 ceba3780 ceedfee4 00000000 c0812bc8 [ 51.990484] fe60: ceedfeb8 e9991880 0000b140 c07ccf00 00000000 bec45ad4 ced457c0 00000000 [ 51.998655] fe80: 000007d5 00000000 00000000 00000000 c0e714c0 ceedfee4 e9991880 e9991880 [ 52.006826] fea0: 0000000c b6dc7a40 ceede000 00000000 0000b140 c07cc53c ceedff10 00000000 [ 52.014996] fec0: e9991880 c07cd748 ceedfeec bec45c48 0000000c 00000000 00000000 00d4a474 [ 52.023167] fee0: 0000002c ceedff10 0000000c 00000001 00000000 00000000 ceedfee4 00000000 [ 52.031337] ff00: 00000000 00000000 00000000 c02092f8 00000010 00000000 00000000 00000000 [ 52.039508] ff20: 00000000 c0383e80 ceba3f00 eb983900 c0d88adc c02ae8bc e9991880 bec45ae0 [ 52.047678] ff40: 00000000 00000129 c020fb24 ceede000 00000000 c07cdc28 00000000 0000004e [ 52.055848] ff60: c020fb24 00000000 0000001c ceedfeb8 0000000c 00000000 0000001c 000000e4 [ 52.064017] ff80: ceedfe78 00000001 00000000 00000000 b6dc7a40 0000000c 00000007 00000122 [ 52.072189] ffa0: c020fb24 c020f9a0 b6dc7a40 0000000c 00000003 00d4a474 0000002c 00000000 [ 52.080359] ffc0: b6dc7a40 0000000c 00000007 00000122 ffffffff 00014100 00000005 0000b140 [ 52.088529] ffe0: bec45c20 bec45c14 b6dc680c b6eb4168 400d0010 00000003 7e1c1000 bb00007a [ 52.096806] [<bf4b1db8>] (ip_set_put_extensions [ip_set]) from [<bf4bf53c>] (hash_net6_list+0x350/0x398 [ip_set_hash_net]) [ 52.107905] [<bf4bf53c>] (hash_net6_list [ip_set_hash_net]) from [<bf4b3708>] (ip_set_dump_start+0x3e0/0x648 [ip_set]) [ 52.118619] [<bf4b3708>] (ip_set_dump_start [ip_set]) from [<c0810454>] (netlink_dump+0xd4/0x24c) [ 52.127493] [<c0810454>] (netlink_dump) from [<c0810b40>] (__netlink_dump_start+0xfc/0x198) [ 52.135858] [<c0810b40>] (__netlink_dump_start) from [<bf4b39e0>] (ip_set_dump+0x70/0x8c [ip_set]) [ 52.144835] [<bf4b39e0>] (ip_set_dump [ip_set]) from [<bf3ce388>] (nfnetlink_rcv_msg+0x1d4/0x214 [nfnetlink]) [ 52.154773] [<bf3ce388>] (nfnetlink_rcv_msg [nfnetlink]) from [<c0812d48>] (netlink_rcv_skb+0x60/0xbc) [ 52.164078] [<c0812d48>] (netlink_rcv_skb) from [<c0812524>] (netlink_unicast+0xe8/0x19c) [ 52.172255] [<c0812524>] (netlink_unicast) from [<c0812bc8>] (netlink_sendmsg+0x530/0x548) [ 52.180520] [<c0812bc8>] (netlink_sendmsg) from [<c07cc53c>] (sock_sendmsg+0x3c/0x4c) [ 52.188352] [<c07cc53c>] (sock_sendmsg) from [<c07cd748>] (SyS_sendto+0xc0/0xe4) [ 52.195749] [<c07cd748>] (SyS_sendto) from [<c020f9a0>] (ret_fast_syscall+0x0/0x3c) [ 52.203402] Code: ea000061 e594603c e0876006 e1b62f9f (e3041018) [ 52.209683] ---[ end trace 900abcf76ab99220 ]--- [ 52.214384] Kernel panic - not syncing: Fatal exception in interrupt [ 52.220741] CPU1: stopping [ 52.223459] CPU: 1 PID: 1021 Comm: openvpn Tainted: G D 4.2.4-200.BPiR1.fc22.armv7hl #1 [ 52.232577] Hardware name: Allwinner sun7i (A20) Family [ 52.237823] [<c02184f8>] (unwind_backtrace) from [<c02135c4>] (show_stack+0x18/0x1c) [ 52.245564] [<c02135c4>] (show_stack) from [<c08feea0>] (dump_stack+0x74/0x90) [ 52.252784] [<c08feea0>] (dump_stack) from [<c021641c>] (handle_IPI+0x118/0x20c) [ 52.260178] [<c021641c>] (handle_IPI) from [<c02096b0>] (gic_handle_irq+0x64/0x6c) [ 52.267743] [<c02096b0>] (gic_handle_irq) from [<c0905064>] (__irq_usr+0x44/0x60) [ 52.275214] Exception stack(0xcecbbfb0 to 0xcecbbff8) [ 52.280261] bfa0: bee41a38 80461f28 7b551f45 80455620 [ 52.288430] bfc0: bee418dc e6d23eac 245f4595 fb5cf903 ab151885 000004f1 22374ea6 00000000 [ 52.296598] bfe0: 1a607660 bee4183c 1a60765f b6cd0d90 200e0010 ffffffff [ 52.303208] ---[ end Kernel panic - not syncing: Fatal exception in interrupt Used commands: /sbin/ipset create -q sw6-trusted hash:net counters family inet6 /sbin/ipset destroy -q sw6-trusted-swap /sbin/ipset create -q sw6-trusted-swap hash:net counters family inet6 /sbin/ipset add -q -exist sw6-trusted-swap myhost.com. /sbin/ipset add -q -exist sw6-trusted-swap my-server /sbin/ipset add -exist sw6-trusted-swap [my-server] /sbin/ipset add -q -exist sw6-trusted-swap my-workstation1 /sbin/ipset add -exist sw6-trusted-swap [my-workstation1] /sbin/ipset add -q -exist sw6-trusted-swap 2001:abcd:abcd:100::/48 /sbin/ipset list /sbin/ipset swap sw6-trusted-swap sw6-trusted /sbin/ipset destroy sw6-trusted-swap
Also kernel 4.1.10 has crash problems when playing with the ipset commands (adding, swapping, etc.) with at least IPv6: [ 632.707748] Alignment trap: not handling instruction e1ba2f9f at [<bf46c144>] [ 632.714938] Unhandled fault: alignment exception (0x001) at 0xee52c754 [ 632.721506] pgd = ce930000 [ 632.724257] [ee52c754] *pgd=6e41141e(bad) [ 632.728404] Internal error: : 1 [#1] SMP ARM [ 632.732674] Modules linked in: ipt_MASQUERADE nf_nat_masquerade_ipv4 xt_AUDIT iptable_nat nf_nat_ipv4 tun xt_recent xt_set ip_set_hash_ip xt_comment ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_nat_ipv6 ip6t_REJECT nf_reject_ipv6 xt_addrtype ip_set_hash_net ip_set iptable_mangle iptable_raw nf_conntrack_ipv4 xt_mark nf_defrag_ipv4 ip6table_mangle xt_CT ip6table_raw xt_multiport nf_log_ipv4 nf_conntrack_ipv6 nf_nat_tftp nf_defrag_ipv6 nf_nat_snmp_basic nf_conntrack_snmp xt_conntrack nf_nat_sip nf_nat_pptp nf_nat_proto_gre nf_nat_irc nf_nat_h323 xt_NFLOG nfnetlink_log nf_nat_ftp nf_nat_amanda nf_nat xt_LOG nf_log_ipv6 nf_log_common nf_conntrack_tftp nf_conntrack_sip nf_conntrack_sane nf_conntrack_proto_udplite nf_conntrack_proto_sctp nf_conntrack_pptp nf_conntrack_proto_gre nf_conntrack_netlink nfnetlink nf_conntrack_netbios_ns nf_conntrack_broadcast nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp ts_kmp nf_conntrack_amanda nf_conntrack ip6table_filter ip6_tables ccm bridge 8021q garp mrp stp llc sit tunnel4 ip_tunnel arc4 rtl8192cu rtl_usb rtl8192c_common rtlwifi mac80211 cfg80211 rfkill uas usb_storage sun4i_ts sunxi_sid sunxi_wdt phy_sun4i_usb spi_sun4i leds_gpio nfsd mmc_block stmmac_platform stmmac ptp pps_core i2c_mv64xxx rtc_sunxi ahci_sunxi libahci_platform ohci_platform sunxi_mmc ehci_platform mmc_core [ 632.850994] CPU: 0 PID: 4711 Comm: ipset Not tainted 4.1.10-200.BPiR1.fc22.armv7hl #1 [ 632.858811] Hardware name: Allwinner sun7i (A20) Family [ 632.864032] task: eb9c1080 ti: cedca000 task.ti: cedca000 [ 632.869445] PC is at hash_net6_list+0x344/0x554 [ip_set_hash_net] [ 632.875539] LR is at nla_put+0x30/0x40 [ 632.879287] pc : [<bf46c148>] lr : [<c0554404>] psr: 200c0013 [ 632.879287] sp : cedcbd08 ip : ee3dd01c fp : ee3dcfc4 [ 632.890747] r10: ee52c754 r9 : 00000001 r8 : ee3dcfc0 [ 632.895966] r7 : ebff5e34 r6 : ee52c73c r5 : ceff3a00 r4 : ee64ac00 [ 632.902484] r3 : 00000002 r2 : 80000000 r1 : cedcbd32 r0 : 00000000 [ 632.909005] Flags: nzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment user [ 632.916130] Control: 10c5387d Table: 4e93006a DAC: 00000015 [ 632.921870] Process ipset (pid: 4711, stack limit = 0xcedca220) [ 632.927781] Stack: (0xcedcbd08 to 0xcedcc000) [ 632.932138] bd00: 00000004 00000008 ebee8000 ee3dd000 00000000 ebee99fc [ 632.940307] bd20: 00000000 ceff3a00 00000000 ebee99f8 eb9b3000 ee3dcfbc ee64ac00 c0554404 [ 632.948477] bd40: ee64ac00 bf46dba0 00000000 00000000 00000000 00000000 08000000 ebff5e34 [ 632.956646] bd60: ceff3a00 ee64ac00 00000001 cea8a380 bf46be04 ee3dcf40 bf463190 bf46016c [ 632.964817] bd80: 00000007 000200da cedca000 ceff3a20 00000078 00000003 000a06d0 cedcbd06 [ 632.972987] bda0: c07b80dc 000010c0 cedcbe38 0000013c 0000b140 c07b803c ee64ac00 00001000 [ 632.981158] bdc0: 000012d0 c07b80e8 ee64ac00 ebff5c00 ee64ac00 00000f40 ebff5e34 00000000 [ 632.989328] bde0: cedcbe38 0000013c 0000b140 c07f218c ebff5c00 ee64ac00 e991e900 00000000 [ 632.997497] be00: cedcbe38 cedcbf6c ebff5c00 ee64ac00 e991e900 c07f2478 00000000 00000001 [ 633.005668] be20: cedcbe70 00000000 00001000 cedcbe34 eeecaa40 cedcbe78 00000000 00000000 [ 633.013838] be40: 00000000 00000000 00000000 00000000 00000000 cedcbf6c bead0520 00000000 [ 633.022007] be60: c07afc6c cedcbeb8 e991e900 c07b0314 00000000 bead0514 01a49474 00001000 [ 633.030177] be80: 4c949b40 00000093 00000093 eeec77b0 cedcbfb0 c02acef0 46ba830f 00000093 [ 633.038348] bea0: ffffffff 00ffffff eeec7500 eeecd8c0 00000000 c02a0bd0 00000010 00000000 [ 633.046519] bec0: 00000000 c02a0bd0 eeecb100 c0d852c0 c0d852c0 c02a1acc eeecb280 c0d854c0 [ 633.054688] bee0: eeecb118 c02a1bec eeecb280 c02a1c84 c0e5ecc0 c02a65a4 00000000 c02a87d8 [ 633.062858] bf00: 4c4873d9 c08edd54 cedcbf08 cedcbf08 00000003 cedca000 c0d530a4 00000009 [ 633.071029] bf20: 00000080 c02516c0 cedca000 c0d530a8 00000009 c02516c0 e991e900 bead0520 [ 633.079198] bf40: 00000000 00000129 c020faa4 cedca000 00000000 c07b10ac 00000000 00000000 [ 633.087367] bf60: 00000000 00000000 fffffff7 cedcbeb8 0000000c 00000000 0000013c 00000ec4 [ 633.095537] bf80: cedcbe78 00000001 00000000 00000000 00000000 00000000 000140e8 00000001 [ 633.103708] bfa0: 0000000c c020f920 000140e8 00000001 00000003 bead0520 00000000 bead050c [ 633.111879] bfc0: 000140e8 00000001 0000000c 00000129 00000010 00014100 00000005 0000b140 [ 633.120049] bfe0: 00000000 bead0504 b6d9d880 b6e8afa0 600c0010 00000003 00000000 00000000 [ 633.128321] [<bf46c148>] (hash_net6_list [ip_set_hash_net]) from [<bf46016c>] (ip_set_dump_start+0x374/0x58c [ip_set]) [ 633.139040] [<bf46016c>] (ip_set_dump_start [ip_set]) from [<c07f218c>] (netlink_dump+0xd4/0x24c) [ 633.147908] [<c07f218c>] (netlink_dump) from [<c07f2478>] (netlink_recvmsg+0x174/0x2e4) [ 633.155910] [<c07f2478>] (netlink_recvmsg) from [<c07b0314>] (___sys_recvmsg+0x98/0x11c) [ 633.164000] [<c07b0314>] (___sys_recvmsg) from [<c07b10ac>] (__sys_recvmsg+0x44/0x68) [ 633.171831] [<c07b10ac>] (__sys_recvmsg) from [<c020f920>] (ret_fast_syscall+0x0/0x3c) [ 633.179743] Code: ea00007a e595a03c e086a00a e1ba2f9f (e3041018) [ 633.186027] ---[ end trace 67695d3b677c205f ]--- [ 633.190721] Kernel panic - not syncing: Fatal exception in interrupt [ 633.197083] CPU1: stopping [ 633.199802] CPU: 1 PID: 0 Comm: swapper/1 Tainted: G D 4.1.10-200.BPiR1.fc22.armv7hl #1 [ 633.208919] Hardware name: Allwinner sun7i (A20) Family [ 633.214167] [<c02183c8>] (unwind_backtrace) from [<c02134fc>] (show_stack+0x18/0x1c) [ 633.221911] [<c02134fc>] (show_stack) from [<c08ddc80>] (dump_stack+0x74/0x90) [ 633.229131] [<c08ddc80>] (dump_stack) from [<c02162fc>] (handle_IPI+0x118/0x20c) [ 633.236524] [<c02162fc>] (handle_IPI) from [<c02096bc>] (gic_handle_irq+0x64/0x6c) [ 633.244092] [<c02096bc>] (gic_handle_irq) from [<c08e38c0>] (__irq_svc+0x40/0x54) [ 633.251564] Exception stack(0xee147fa0 to 0xee147fe8) [ 633.256614] 7fa0: eeed8280 00000000 0001e1ec c02239c0 ee146000 00000015 c0d49404 ee147ff0 [ 633.264785] 7fc0: c0d53648 410fc074 00000000 00000000 00000001 ee147fe8 c0210450 c0210454 [ 633.272951] 7fe0: 60000013 ffffffff [ 633.276447] [<c08e38c0>] (__irq_svc) from [<c0210454>] (arch_cpu_idle+0x34/0x40) [ 633.283845] [<c0210454>] (arch_cpu_idle) from [<c0284688>] (cpu_startup_entry+0x1ec/0x224) [ 633.292145] [<c0284688>] (cpu_startup_entry) from [<4020976c>] (0x4020976c) [ 633.299106] ---[ end Kernel panic - not syncing: Fatal exception in interrupt
After patch from Jozsef Kadlecsik from the mailinglist for kernel 4.2.4: Still crashes ... [ 46.864730] xt_addrtype: ipv6 does not support BROADCAST matching [ 49.419887] Alignment trap: not handling instruction e1b62f9f at [<bf48edb4>] [ 49.427180] Unhandled fault: alignment exception (0x001) at 0xee6a492a [ 49.433845] pgd = ee6b0000 [ 49.436657] [ee6a492a] *pgd=6e61141e(bad) [ 49.440797] Internal error: : 1 [#1] SMP ARM [ 49.445085] Modules linked in: xt_set ip_set_hash_ip xt_comment ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_nat_ipv6 ip6t_REJECT nf_reject_ipv6 xt_addrtype ip_set_hash_net ip_set iptable_mangle iptable_raw nf_conntrack_ipv4 nf_defrag_ipv4 xt_mark ip6table_mangle xt_CT ip6table_raw xt_multiport nf_log_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_conntrack_ipv6 nf_conntrack_snmp nf_defrag_ipv6 nf_nat_sip xt_conntrack nf_nat_pptp nf_nat_proto_gre nf_nat_irc nf_nat_h323 xt_NFLOG nfnetlink_log nf_nat_ftp xt_LOG nf_nat_amanda nf_log_ipv6 nf_nat nf_log_common nf_conntrack_tftp nf_conntrack_sip nf_conntrack_sane nf_conntrack_proto_udplite nf_conntrack_proto_sctp nf_conntrack_pptp nf_conntrack_proto_gre nf_conntrack_netlink nfnetlink nf_conntrack_netbios_ns nf_conntrack_broadcast nf_conntrack_irc ts_kmp nf_conntrack_h323 nf_conntrack_amanda nf_conntrack_ftp nf_conntrack ccm ip6table_filter ip6_tables bridge 8021q garp mrp stp llc sit tunnel4 ip_tunnel arc4 rtl8192cu rtl_usb rtl8192c_common rtlwifi mac80211 cfg80211 rfkill uas usb_storage axp20x_pek axp20x_regulator sun4i_ts sunxi_sid sunxi_wdt phy_sun4i_usb spi_sun4i leds_gpio cpufreq_dt nfsd mmc_block dwmac_sunxi stmmac_platform stmmac ptp pps_core i2c_mv64xxx ahci_sunxi libahci_platform rtc_sunxi ehci_platform ohci_platform sunxi_mmc mmc_core [ 49.561393] CPU: 0 PID: 1957 Comm: ipset Not tainted 4.2.4-200.BPiR1.fc22.armv7hl #1 [ 49.569132] Hardware name: Allwinner sun7i (A20) Family [ 49.574355] task: ed35ce00 ti: ed5c8000 task.ti: ed5c8000 [ 49.579777] PC is at ip_set_put_extensions+0xa0/0x230 [ip_set] [ 49.585617] LR is at hash_net6_list+0x350/0x398 [ip_set_hash_net] [ 49.591709] pc : [<bf48edb8>] lr : [<bf49c53c>] psr: 200d0013 [ 49.591709] sp : ed5c9c40 ip : ee6c9098 fp : ee6c907c [ 49.603172] r10: ee6a4900 r9 : ed167080 r8 : 00000000 [ 49.608392] r7 : ee6a4912 r6 : ee6a492a r5 : ed4ee000 r4 : ed167080 [ 49.614911] r3 : 00000002 r2 : 00000002 r1 : ed167080 r0 : ed4ee000 [ 49.621433] Flags: nzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment user [ 49.628562] Control: 10c5387d Table: 6e6b006a DAC: 00000015 [ 49.634302] Process ipset (pid: 1957, stack limit = 0xed5c8220) [ 49.640216] Stack: (0xed5c9c40 to 0xed5ca000) [ 49.644574] 9c40: 00000001 00000008 ee6a4912 c0567698 ed5c9ca3 00000001 ee6a4912 ee6c9078 [ 49.652745] 9c60: 00000000 c0567704 ed4ee000 ed4ee000 ed5ee62c ee6a4912 ee6c9078 bf49c53c [ 49.660917] 9c80: ee6c904c ee6c9074 ed4ee000 ee3da000 ee6c907c ee6c9080 00000000 00000000 [ 49.669087] 9ca0: 30000000 38070000 08000000 ed5ee62c ed167080 ed4ee000 00000002 ed2f8140 [ 49.677258] 9cc0: 00000000 ee6c9000 bf4935d8 bf490708 00000007 c0373910 ed4ee000 00000000 [ 49.685428] 9ce0: 0000000c 00000003 000a062c 00000006 ee5d9014 ee5d901c 00000000 00000000 [ 49.693599] 9d00: 00000000 00000000 00000000 00000000 00000000 00000000 ed4ee000 ed5ee400 [ 49.701771] 9d20: ed4ee000 00000f40 ed5ee62c ed5ee62c ee5d9000 00000006 ed5c9e2c c0810454 [ 49.709942] 9d40: ed08c600 c08100fc c0e714c0 000007a5 ee688c00 ed5ee400 ed08c600 ed5c9d8c [ 49.718111] 9d60: ed5ee45c c0810b40 ee688c00 ed08c600 ee5d9000 00000007 bf491a08 ed5c9db8 [ 49.726280] 9d80: 00000006 bf4909e0 ed5c9db8 bf490328 bf4909fc 00000000 bf493880 00000000 [ 49.734449] 9da0: ee5d9000 bf490970 ed08c600 bf3ae388 bf4918f0 00000000 00000000 ee5d9014 [ 49.742616] 9dc0: ee5d901c 00000000 00000000 00000000 00000000 00000000 00000000 00000000 [ 49.750786] 9de0: 00000000 c0253da0 bf3aee00 bf3aeea8 bf491a94 bf3aeec0 ed5c9de0 c0e714c0 [ 49.758955] 9e00: 0000008c 00000006 0000002c ee5d9000 ed08c600 bf3ae1b4 ed5ee400 00000000 [ 49.767123] 9e20: 00000008 00000000 0000002c c0812d48 ee688c00 0000002c ed08c600 c0812524 [ 49.775292] 9e40: ed5ee400 7fffffff 00000000 ed5ee400 ed08c600 ed5c9ee4 00000000 c0812bc8 [ 49.783461] 9e60: ed5c9eb8 e99d7500 0000b140 c07ccf00 00000000 bec32ad4 ebf3e700 00000000 [ 49.791631] 9e80: 000007a5 00000000 00000000 00000000 75dbca29 ed5c9ee4 e99d7500 e99d7500 [ 49.799800] 9ea0: 0000000c b6d3fa40 ed5c8000 00000000 0000b140 c07cc53c ed5c9f10 00000000 [ 49.807969] 9ec0: e99d7500 c07cd748 ed5c9eec 0000bafa ee11b448 00000000 00000000 00e84474 [ 49.816138] 9ee0: 0000002c ed5c9f10 0000000c 00000001 00000000 00000000 ed5c9ee4 00000000 [ 49.824305] 9f00: 00000000 00000000 00000000 c026776c 00000010 00000000 00000000 00000001 [ 49.832474] 9f20: ee13c018 ed35ce00 eeeca140 ee11b400 ee6f3880 00000000 e99d7500 bec32ae0 [ 49.840643] 9f40: 00000000 00000129 c020fb24 ed5c8000 00000000 c07cdc28 00000000 c0d888a0 [ 49.848812] 9f60: c0901394 00000000 0000001c ed5c9eb8 0000000c 00000000 0000001c 000000e4 [ 49.856981] 9f80: ed5c9e78 00000001 00000000 00000000 b6d3fa40 0000000c 00000007 00000122 [ 49.865149] 9fa0: c020fb24 c020f9a0 b6d3fa40 0000000c 00000003 00e84474 0000002c 00000000 [ 49.873319] 9fc0: b6d3fa40 0000000c 00000007 00000122 ffffffff 00014100 00000005 0000b140 [ 49.881487] 9fe0: bec32c20 bec32c14 b6d3e80c b6e2c168 400d0010 00000003 fb183d00 0000001a [ 49.889758] [<bf48edb8>] (ip_set_put_extensions [ip_set]) from [<bf49c53c>] (hash_net6_list+0x350/0x398 [ip_set_hash_net]) [ 49.900826] [<bf49c53c>] (hash_net6_list [ip_set_hash_net]) from [<bf490708>] (ip_set_dump_start+0x3e0/0x648 [ip_set]) [ 49.911532] [<bf490708>] (ip_set_dump_start [ip_set]) from [<c0810454>] (netlink_dump+0xd4/0x24c) [ 49.920399] [<c0810454>] (netlink_dump) from [<c0810b40>] (__netlink_dump_start+0xfc/0x198) [ 49.928757] [<c0810b40>] (__netlink_dump_start) from [<bf4909e0>] (ip_set_dump+0x70/0x8c [ip_set]) [ 49.937728] [<bf4909e0>] (ip_set_dump [ip_set]) from [<bf3ae388>] (nfnetlink_rcv_msg+0x1d4/0x214 [nfnetlink]) [ 49.947644] [<bf3ae388>] (nfnetlink_rcv_msg [nfnetlink]) from [<c0812d48>] (netlink_rcv_skb+0x60/0xbc) [ 49.956943] [<c0812d48>] (netlink_rcv_skb) from [<c0812524>] (netlink_unicast+0xe8/0x19c) [ 49.965115] [<c0812524>] (netlink_unicast) from [<c0812bc8>] (netlink_sendmsg+0x530/0x548) [ 49.973376] [<c0812bc8>] (netlink_sendmsg) from [<c07cc53c>] (sock_sendmsg+0x3c/0x4c) [ 49.981207] [<c07cc53c>] (sock_sendmsg) from [<c07cd748>] (SyS_sendto+0xc0/0xe4) [ 49.988604] [<c07cd748>] (SyS_sendto) from [<c020f9a0>] (ret_fast_syscall+0x0/0x3c) [ 49.996255] Code: ea000061 e594603c e0876006 e1b62f9f (e3041018) [ 50.002532] ---[ end trace 45a9e39b0ea72d4a ]--- [ 50.007255] Kernel panic - not syncing: Fatal exception in interrupt [ 50.013622] CPU1: stopping [ 50.016341] CPU: 1 PID: 0 Comm: swapper/1 Tainted: G D 4.2.4-200.BPiR1.fc22.armv7hl #1 [ 50.025363] Hardware name: Allwinner sun7i (A20) Family [ 50.030613] [<c02184f8>] (unwind_backtrace) from [<c02135c4>] (show_stack+0x18/0x1c) [ 50.038355] [<c02135c4>] (show_stack) from [<c08feea0>] (dump_stack+0x74/0x90) [ 50.045576] [<c08feea0>] (dump_stack) from [<c021641c>] (handle_IPI+0x118/0x20c) [ 50.052968] [<c021641c>] (handle_IPI) from [<c02096b0>] (gic_handle_irq+0x64/0x6c) [ 50.060533] [<c02096b0>] (gic_handle_irq) from [<c0904dc0>] (__irq_svc+0x40/0x54) [ 50.068005] Exception stack(0xee145fa0 to 0xee145fe8) [ 50.073055] 5fa0: eeed6980 00000000 00006c20 c0223d80 ee144000 00000015 c0d7e424 ee145ff0 [ 50.081224] 5fc0: c0d87684 410fc074 00000000 00000000 00000000 ee145fe8 c02104d4 c02104d8 [ 50.089388] 5fe0: 60010013 ffffffff [ 50.092882] [<c0904dc0>] (__irq_svc) from [<c02104d8>] (arch_cpu_idle+0x34/0x40) [ 50.100278] [<c02104d8>] (arch_cpu_idle) from [<c0284378>] (cpu_startup_entry+0x1a4/0x210) [ 50.108539] [<c0284378>] (cpu_startup_entry) from [<4020974c>] (0x4020974c) [ 50.115498] ---[ end Kernel panic - not syncing: Fatal exception in interrupt
There are 2 unrelated issues: Issue 1: nf_conntrack: table full, dropping packet => Fixed with 4.2.4 Issue 2: Alignment trap: not handling instruction => Happens when ipset counters are enabled
Happens with IPv6 commands, but maybe also IPv4 affected. Maybe this is a strict alignment issue.
kernel-4.2.5-300.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2015-8fa458f35f
Issue 2: Alignment trap: not handling instruction => Happens when ipset counters are enabled Jozsef Kadlecsik has reproduced the second issue on a second platform with strict alignment (he tested on SPARC but happens on ARM, too). He is working for a fix.
kernel-4.2.5-200.fc22 has been submitted as an update to Fedora 22. https://bodhi.fedoraproject.org/updates/FEDORA-2015-5c899c64e2
kernel-4.2.5-201.fc22 has been submitted as an update to Fedora 22. https://bodhi.fedoraproject.org/updates/FEDORA-2015-7784dc12e8
kernel-4.2.5-300.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with $ su -c 'dnf --enablerepo=updates-testing update kernel' You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-8fa458f35f
kernel-4.2.5-201.fc22 has been pushed to the Fedora 22 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with $ su -c 'dnf --enablerepo=updates-testing update kernel' You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-7784dc12e8
Jozsef Kadlecsik has provided a patch, he tested on SPARC already. Patch compiled well, testing on ARM this weekend when having physical access to the machine.
kernel-4.2.5-300.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
kernel-4.2.5-201.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Patch works well. [PATCH 0/3] ipset patches for nf https://marc.info/?l=netfilter-devel&m=144690007708041&w=2 https://marc.info/?l=netfilter-devel&m=144690007808042&w=2 https://marc.info/?l=netfilter-devel&m=144690008608043&w=2 https://marc.info/?l=netfilter-devel&m=144690007708039&w=2 [ANNOUNCE] ipset 6.27 released https://marc.info/?l=netfilter-devel&m=144690048308099&w=2 See for details: #1279189 https://bugzilla.redhat.com/show_bug.cgi?id=1279189