Fireqos and kernel with SECCOMP because of ssh 10.4+
Jorge Bastos
mysql.jorge at decimal.pt
Wed Jul 15 22:25:18 BST 2026
Forgot to paste, check this with 7.1.3, with SECCOMP, starting fireqos
BUG: kernel NULL pointer dereference, address: 0000000000000628
#PF: supervisor write access in kernel mode
#PF: error_code(0x0002) - not-present page
PGD 0 P4D 0
Oops: Oops: 0002 [#1] SMP PTI
CPU: 1 UID: 0 PID: 14042 Comm: tc Not tainted 7.1.3 #1 PREEMPT(full)
Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine,
BIOS 090007 05/18/2018
RIP: 0010:tcx_miniq_inc+0x2c/0x40 [sch_ingress]
Code: 89 fb e8 f7 77 52 e1 85 c0 75 18 48 8d 3d 1c 3d e7 ff ba 81 00 00
00 48 c7 c6 23 70 0d a0 67 48 0f b9 3a 48 8b 83 00 02 00 00 <ff> 80 28
06 00 00 5b c3 cc cc cc cc 0f 1f 84 00 00 00 00 00 90 90
RSP: 0018:ffffc9000064f930 EFLAGS: 00010202
RAX: 0000000000000000 RBX: ffff88805783b808 RCX: 0000000000000000
RDX: ffff88805783b800 RSI: 0000000000000082 RDI: ffffffff82465bc0
RBP: 00000000fffffff4 R08: ffff888004cc6e88 R09: 00000000000000d4
R10: 00000000000000d0 R11: 00000000000000d5 R12: ffff88805783b808
R13: ffff88808c92efa8 R14: ffff888004651000 R15: ffffc9000064fb48
FS: 00007fb985608780(0000) GS:ffff888180ab3000(0000)
knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000628 CR3: 00000000a2b34004 CR4: 00000000001706b0
Call Trace:
<TASK>
ingress_init+0x6e/0x110 [sch_ingress]
qdisc_create+0x297/0x370
tc_modify_qdisc+0x639/0x6c0
rtnetlink_rcv_msg+0x278/0x2d0
? __kmalloc_node_track_caller_noprof+0x37/0x320
? __alloc_skb+0xc3/0x110
? __pfx_rtnetlink_rcv_msg+0x10/0x10
netlink_rcv_skb+0x83/0xe0
netlink_unicast+0x11c/0x1b0
netlink_sendmsg+0x271/0x2d0
sock_sendmsg_nosec+0x32/0x40
____sys_sendmsg+0x10b/0x180
? copy_msghdr_from_user+0x6a/0xa0
___sys_sendmsg+0x79/0xc0
? ___sys_recvmsg+0x82/0xb0
? __handle_mm_fault+0x71f/0x7a0
? css_uses_rstat+0x9/0x20
? __css_rstat_updated+0x22/0x70
__sys_sendmsg+0x63/0xa0
do_syscall_64+0x116/0x2a0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
RIP: 0033:0x7fb98529bcb2
Code: 18 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 75 1a 83 e2 39 83 fa 08
75 12 e8 2b ff ff ff 0f 1f 00 49 89 ca 48 8b 44 24 20 0f 05 <48> 83 c4
18 c3 66 0f 1f 84 00 00 00 00 00 48 83 ec 10 ff 74 24 18
RSP: 002b:00007ffd5106e180 EFLAGS: 00000202 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 000055bdbf033640 RCX: 00007fb98529bcb2
RDX: 0000000000000000 RSI: 00007ffd5106e240 RDI: 0000000000000003
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000
R13: 000000006a57f9a8 R14: 00007ffd5107e540 R15: 000055bdbf033640
</TASK>
Modules linked in: sch_ingress sch_htb ifb xt_tcpmss iptable_mangle
xt_tcpudp xt_conntrack iptable_nat nf_nat nf_conntrack nf_defrag_ipv6
nf_defrag_ipv4 iptable_filter ip_tables x_tables aesni_intel gf128mul
libaes aead crypto_skcipher rtc_cmos button sg sch_fq_codel loop fuse
configfs
CR2: 0000000000000628
---[ end trace 0000000000000000 ]---
RIP: 0010:tcx_miniq_inc+0x2c/0x40 [sch_ingress]
Code: 89 fb e8 f7 77 52 e1 85 c0 75 18 48 8d 3d 1c 3d e7 ff ba 81 00 00
00 48 c7 c6 23 70 0d a0 67 48 0f b9 3a 48 8b 83 00 02 00 00 <ff> 80 28
06 00 00 5b c3 cc cc cc cc 0f 1f 84 00 00 00 00 00 90 90
RSP: 0018:ffffc9000064f930 EFLAGS: 00010202
RAX: 0000000000000000 RBX: ffff88805783b808 RCX: 0000000000000000
RDX: ffff88805783b800 RSI: 0000000000000082 RDI: ffffffff82465bc0
RBP: 00000000fffffff4 R08: ffff888004cc6e88 R09: 00000000000000d4
R10: 00000000000000d0 R11: 00000000000000d5 R12: ffff88805783b808
R13: ffff88808c92efa8 R14: ffff888004651000 R15: ffffc9000064fb48
FS: 00007fb985608780(0000) GS:ffff888180ab3000(0000)
knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000628 CR3: 00000000a2b34004 CR4: 00000000001706b0
On 2026-07-15 22:16, Jorge Bastos wrote:
> Hi there,
>
> I'm on debian sid, with vanilla kernel compiled by me,
>
> But my SSH it 10.4p1,
>
> What could i do to solve this?
>
> On 2026-07-15 21:27, Bradley D. Thornton wrote:
>
> Running Debian Forky here w/the 7.1.3+deb14-amd64 kernel and both the
> OpenSSH client and server versions installed are version 10.3p1-5 -
> everything is humming along just fine.
>
> Are we expecting to have any similar issues coming up, or is this just
> a Windows centric issue we can ignore and move on from?
>
> On 7/14/26 4:25 AM, Jorge Bastos wrote:
>
> Howdy,
>
> I've been using fireqos and perfect,
> But now that i have to use SECCOMP due to SSH 10.4+ needs, fireqos
> crashes my kernel.
>
> Is there any workarroung or fix already?
> Thanks in advanced,
>
> BUG: kernel NULL pointer dereference, address: 0000000000000628
> #PF: supervisor write access in kernel mode
> #PF: error_code(0x0002) - not-present page
> PGD 0 P4D 0
> Oops: Oops: 0002 [#1] SMP PTI
> CPU: 0 UID: 0 PID: 50796 Comm: tc Not tainted 6.18.38 #3 PREEMPT(none)
> Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine,
> BIOS 090007 05/18/2018
> RIP: 0010:tcx_miniq_inc+0x3e/0x50 [sch_ingress]
> Code: 75 21 ba 81 00 00 00 48 c7 c6 00 a0 0c a0 48 c7 c7 14 a0 0c a0 c6
> 05 72 9f e6 ff 01 e8 8b ef 00 e1 0f 0b 48 8b 83 00 02 00 00 <ff> 80 28
> 06 00 00 5b e9 46 26 65 e1 66 0f 1f 44 00 00 90 90 90 90
> RSP: 0018:ffffc90000383938 EFLAGS: 00010202
> RAX: 0000000000000000 RBX: ffff8880d2b64808 RCX: 0000000000000000
> RDX: ffff8880d2b64800 RSI: 0000000000000082 RDI: ffffffff81ef82a0
> RBP: 00000000fffffff4 R08: ffff888102fb8988 R09: 0000000000000174
> R10: 0000000000000170 R11: 0000000000000175 R12: ffff8880d2b64808
> R13: ffff88804e33d5a8 R14: ffff888103132000 R15: ffffc90000383b50
> FS: 00007f6743850740(0000) GS:ffff888180ac3000(0000)
> knlGS:0000000000000000
> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 0000000000000628 CR3: 0000000048028005 CR4: 00000000001706b0
> Call Trace:
> <TASK>
> ingress_init+0x6e/0x110 [sch_ingress]
> qdisc_create+0x297/0x370
> tc_modify_qdisc+0x639/0x6c0
> ? count_memcg_events+0x4e/0xa0
> rtnetlink_rcv_msg+0x278/0x2d0
> ? __pfx_rtnetlink_rcv_msg+0x10/0x10
> netlink_rcv_skb+0x83/0xe0
> netlink_unicast+0x11d/0x1c0
> netlink_sendmsg+0x271/0x2d0
> sock_sendmsg_nosec+0x23/0x40
> ____sys_sendmsg+0x10b/0x180
> ? copy_msghdr_from_user+0x6a/0xa0
> ___sys_sendmsg+0x79/0xc0
> ? ___sys_recvmsg+0x82/0xb0
> ? __handle_mm_fault+0x753/0x7d0
> ? css_uses_rstat+0x9/0x20
> ? __css_rstat_updated+0x22/0x70
> __sys_sendmsg+0x63/0xa0
> do_syscall_64+0x7f/0x1c0
> entry_SYSCALL_64_after_hwframe+0x76/0x7e
> RIP: 0033:0x7f67439a5cb2
> Code: 18 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 75 1a 83 e2 39 83 fa 08
> 75 12 e8 2b ff ff ff 0f 1f 00 49 89 ca 48 8b 44 24 20 0f 05 <48> 83 c4
> 18 c3 66 0f 1f 84 00 00 00 00 00 48 83 ec 10 ff 74 24 18
> RSP: 002b:00007ffdb3e46a40 EFLAGS: 00000202 ORIG_RAX: 000000000000002e
> RAX: ffffffffffffffda RBX: 00005591a47ca640 RCX: 00007f67439a5cb2
> RDX: 0000000000000000 RSI: 00007ffdb3e46b00 RDI: 0000000000000003
> RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
> R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000
> R13: 000000006a561b0f R14: 00007ffdb3e56e00 R15: 00005591a47ca640
> </TASK>
> Modules linked in: sch_ingress sch_htb ifb xt_tcpmss iptable_mangle
> xt_tcpudp xt_conntrack iptable_nat nf_nat nf_conntrack nf_defrag_ipv6
> nf_defrag_ipv4 iptable_filter ip_tables x_tables polyval_clmulni
> ghash_clmulni_intel aesni_intel gf128mul libaes rtc_cmos button sg
> sch_fq_codel loop fuse configfs
> CR2: 0000000000000628
> ---[ end trace 0000000000000000 ]---
> RIP: 0010:tcx_miniq_inc+0x3e/0x50 [sch_ingress]
> Code: 75 21 ba 81 00 00 00 48 c7 c6 00 a0 0c a0 48 c7 c7 14 a0 0c a0 c6
> 05 72 9f e6 ff 01 e8 8b ef 00 e1 0f 0b 48 8b 83 00 02 00 00 <ff> 80 28
> 06 00 00 5b e9 46 26 65 e1 66 0f 1f 44 00 00 90 90 90 90
> RSP: 0018:ffffc90000383938 EFLAGS: 00010202
> RAX: 0000000000000000 RBX: ffff8880d2b64808 RCX: 0000000000000000
> RDX: ffff8880d2b64800 RSI: 0000000000000082 RDI: ffffffff81ef82a0
> RBP: 00000000fffffff4 R08: ffff888102fb8988 R09: 0000000000000174
> R10: 0000000000000170 R11: 0000000000000175 R12: ffff8880d2b64808
> R13: ffff88804e33d5a8 R14: ffff888103132000 R15: ffffc90000383b50
> FS: 00007f6743850740(0000) GS:ffff888180ac3000(0000)
> knlGS:0000000000000000
> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 0000000000000628 CR3: 0000000048028005 CR4: 00000000001706b0
More information about the Firehol-support
mailing list