Netfilter "Flow offload" / HW NAT


#21

Which of the following 3 modules are required? And am I missing any?

kmod-ipt-offload
kmod-nf-flow
kmod-nft-offload

#22

So.... the 2nd rule in the FORWARD chain? Nope.


#23

Try this: Optimized build for the D-Link DIR-860L


#24

Thanks, and so she be where some may look:

iptables -I FORWARD 1 -m conntrack --ctstate RELATED,ESTABLISHED -j FLOWOFFLOAD

Nope: for me it keeps resetting an established connection; my irc client. I will check my image contents again.

With image from config.seed, running on rango target, my irc client(irssi on an ubuntu box) continually resets its connection every few minutes upon installing FLOWOFFLOAD.

Should maybe add that the irc connection is a secure connection.

The latest series of patches addressed this issue, things appear to be working.


#25

The issues should be fixed now. Please try the latest version


#26

iptables -I FORWARD 1 -m conntrack --ctstate RELATED,ESTABLISHED -j FLOWOFFLOAD

This command messes up w/ NAT Loopback. If I delete it, NAT loopback works again.


#27

What do you mean by "NAT loopback"? Also, please try my staging tree at https://git.openwrt.org/?p=openwrt/staging/nbd.git;a=summary to see if it fixes those issues.


#28

Hi,

I mean the port forwarding with reflection a.k.a. hairpin NAT. I have a few services that I access using the external IP and it doesn't work with the FLOWOFFLOAD as the first rule in the FORWARD chain.

Still happens on the latest staging build.


#29

Should be fixed now. Please try the latest version


#30

Fri Mar 30 09:58:45 2018 kern.warn kernel: [ 178.954091] dst_release: dst:87c41cb8 refcnt:-2035027009
Fri Mar 30 09:58:53 2018 kern.warn kernel: [ 186.999691] dst_release: dst:87c09e00 refcnt:-2026352449
Fri Mar 30 09:58:54 2018 kern.warn kernel: [ 187.995490] dst_release: dst:87c41cb8 refcnt:-2039040705
Fri Mar 30 09:58:54 2018 kern.warn kernel: [ 188.001052] dst_release: dst:87c41cb8 refcnt:-2039040706
Fri Mar 30 09:58:55 2018 kern.warn kernel: [ 188.996663] dst_release: dst:87c41cb8 refcnt:-1

I have log full of this if i enable flowoffload. Xiaomi mini, ramips, mt7620a. Should i fill bugreport or send you email?


#31

Hi,
My device is turris omnia with latest openwrt compiled by myself,and these days when i turn on the "Flow offload",my omnia always got a crash and then reboot itself.
The crash log:

Mar 31 21:58:06 192.168.1.1 pppd[28332]: Connect: pppoe-wan2 <--> lan4
Mar 31 21:58:06 192.168.1.1 kernel: [63771.886868] Unable to handle kernel paging request at virtual address 48000082
Mar 31 21:58:06 192.168.1.1 kernel: [63771.894117] pgd = c0004000
Mar 31 21:58:06 192.168.1.1 kernel: [63771.896850] [48000082] *pgd=00000000
Mar 31 21:58:06 192.168.1.1 kernel: [63771.900441] Internal error: Oops: 5 [#1] SMP ARM
Mar 31 21:58:06 192.168.1.1 kernel: [63771.905072] Modules linked in: ath9k ath9k_common pppoe ppp_async ath9k_hw ath10k_pci ath10k_core ath pppox ppp_mppe ppp_generic nf_conntrack_ipv6 mac80211 iptable_nat ipt_REJECT ipt_MASQUERADE cfg80211 xt_u32 xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_recent xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_hl xt_helper xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_TCPMSS xt_REDIRECT xt_LOG xt_HL xt_FLOWOFFLOAD xt_DSCP xt_CLASSIFY wireguard usblp slhc nf_reject_ipv4 nf_nat_redirect nf_nat_masquerade_ipv4 nf_conntrack_ipv4 nf_nat_ipv4 nf_nat nf_log_ipv4 nf_flow_table nf_defrag_ipv6 nf_defrag_ipv4 nf_conntrack_rtcache nf_conntrack_netlink macvlan iptable_mangle iptable_filter ipt_ECN ip_tables crc_ccitt compat sch_cake act_connmark nf_conntrack act_skbedit
Mar 31 21:58:06 192.168.1.1 kernel: [63771.976644]  act_mirred em_u32 cls_u32 cls_tcindex cls_flow cls_route cls_fw sch_tbf sch_htb sch_hfsc sch_ingress cryptodev xt_set ip_set_list_set ip_set_hash_netiface ip_set_hash_netport ip_set_hash_netnet ip_set_hash_net ip_set_hash_netportnet ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables x_tables ip_gre gre ifb ip6_udp_tunnel udp_tunnel sit tunnel4 ip_tunnel tun ntfs autofs4 nls_utf8 nls_cp950 nls_cp936 sha512_generic sha256_generic md5 ecb authenc vfat fat nls_iso8859_1 nls_cp437 gpio_button_hotplug
Mar 31 21:58:06 192.168.1.1 kernel: [63772.041851] CPU: 1 PID: 9040 Comm: kworker/1:3 Not tainted 4.14.29 #0
Mar 31 21:58:06 192.168.1.1 kernel: [63772.048310] Hardware name: Marvell Armada 380/385 (Device Tree)
Mar 31 21:58:06 192.168.1.1 kernel: [63772.054261] Workqueue: events_power_efficient xt_flowoffload_hook_work [xt_FLOWOFFLOAD]
Mar 31 21:58:06 192.168.1.1 kernel: [63772.062291] task: eea35500 task.stack: e91a6000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.066845] PC is at __nf_unregister_net_hook+0x8/0xcc
Mar 31 21:58:06 192.168.1.1 kernel: [63772.072001] LR is at nf_unregister_net_hook+0x9c/0xc0
Mar 31 21:58:06 192.168.1.1 kernel: [63772.077068] pc : [<c0555734>]    lr : [<c0555894>]    psr: 20000013
Mar 31 21:58:06 192.168.1.1 kernel: [63772.083353] sp : e91a7f00  ip : 00000000  fp : eefdfc00
Mar 31 21:58:06 192.168.1.1 kernel: [63772.088594] r10: 00000008  r9 : 00000000  r8 : 00000100
Mar 31 21:58:06 192.168.1.1 kernel: [63772.093836] r7 : 00000200  r6 : c0a29400  r5 : e9cdd1c8  r4 : ea63ba30
Mar 31 21:58:06 192.168.1.1 kernel: [63772.100384] r3 : 00000000  r2 : 00000000  r1 : e9cdd1c8  r0 : 48000082
Mar 31 21:58:06 192.168.1.1 kernel: [63772.106931] Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment none
Mar 31 21:58:06 192.168.1.1 kernel: [63772.114089] Control: 10c5387d  Table: 2bbb004a  DAC: 00000051
Mar 31 21:58:06 192.168.1.1 kernel: [63772.119849] Process kworker/1:3 (pid: 9040, stack limit = 0xe91a6210)
Mar 31 21:58:06 192.168.1.1 kernel: [63772.126303] Stack: (0xe91a7f00 to 0xe91a8000)
Mar 31 21:58:06 192.168.1.1 kernel: [63772.130671] 7f00: ea63ba30 c0555894 e9cdd1c0 bf3ba200 bf3ba200 bf3b8398 00000000 01699000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.138868] 7f20: bf3ba2a0 ebba2f80 eefdfc00 eefe2f00 00000000 c01377c4 eefdfc18 ffffe000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.147066] 7f40: ebba2f80 eefdfc00 ebba2f98 eefdfc18 ffffe000 c0a02d00 00000008 c0138760
Mar 31 21:58:06 192.168.1.1 kernel: [63772.155263] 7f60: eea35500 eca5cc00 e91a6000 ea76ab00 00000000 eca5cc1c ebba2f80 c0138430
Mar 31 21:58:06 192.168.1.1 kernel: [63772.163460] 7f80: ea7fbed8 c013ccac e91a6000 ea76ab00 c013cb80 00000000 00000000 00000000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.171656] 7fa0: 00000000 00000000 00000000 c0107a68 00000000 00000000 00000000 00000000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.179852] 7fc0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.188047] 7fe0: 00000000 00000000 00000000 00000000 00000013 00000000 00000000 00000000
Mar 31 21:58:06 192.168.1.1 kernel: [63772.196257] [<c0555734>] (__nf_unregister_net_hook) from [<bf3ba200>] (cleanup_module+0x1c74/0xa74 [xt_FLOWOFFLOAD])
Mar 31 21:58:06 192.168.1.1 kernel: [63772.206807] Code: e28dd00c e8bd8ff0 e92d4010 e3a03000 (e1d0c0b0)
Mar 31 21:58:06 192.168.1.1 kernel: [63772.212933] ---[ end trace 7c38ec001676f581 ]---

Is there anyway to fix this? thanks.


#32

Please try the latest version


#33

I tried it on wrt3200acm and remote desktop is working very bad.
The download and upload where ok (pppoe 980/496), cpu usage was ~2x35%

I don't need this for the wrt but I was just testing to see how it's working
regards


#34

What kind of issue are you having with remote desktop?


#35

sorry for being late on reply
if I do remote desktop without offload, the feeling is smooth, the scrolling in browsing, alt tab, etc is like being in front of the remote computer.
with offload enabled on router (firewall restart, remote desktop reconnect) it jumps and it feels like a really bad lag, like 2-3 seconds, very bad experience, like being on a modem

the bandwidth between routers are like 500mbit up/down, but I test it on a wireless n laptop so, maximum 100+mbit

edit:
OpenWrt SNAPSHOT, r6614-1ef0be3e5b

root@home:~# cat /proc/net/nf_conntrack | grep OFFLOAD
ipv6     10 tcp      6 src=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 dst=xxxx:xxx:xxxx:xxxx:0000:0000:168b:9001 sport=55444 dport=443 packets=2 bytes=132 src=xxxx:xxx:xxxx:xxxx:0000:0000:168b:9001 dst=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 sport=443 dport=55444 packets=1 bytes=72 [OFFLOAD] mark=0 use=3
ipv4     2 tcp      6 src=xxx.xxx.34.124 dst=xxx.xxx.103.95 sport=57782 dport=26000 packets=2 bytes=92 src=192.168.123.118 dst=xxx.xxx.34.124 sport=3389 dport=57782 packets=1 bytes=52 [OFFLOAD] mark=0 use=3
ipv4     2 tcp      6 src=192.168.123.118 dst=151.101.12.133 sport=55430 dport=443 packets=4 bytes=174 src=151.101.12.133 dst=xxx.xxx.103.95 sport=443 dport=55430 packets=1 bytes=52 [OFFLOAD] mark=0 use=3
ipv6     10 tcp      6 src=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 dst=xxxx:xxx:xxxx:xxxx:0000:0000:168b:9001 sport=55438 dport=443 packets=2 bytes=132 src=xxxx:xxx:xxxx:xxxx:0000:0000:168b:9001 dst=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 sport=443 dport=55438 packets=1 bytes=72 [OFFLOAD] mark=0 use=3
ipv4     2 tcp      6 src=192.168.123.118 dst=xxx.xxx.226.250 sport=55448 dport=443 packets=2 bytes=92 src=xxx.xxx.226.250 dst=xxx.xxx.103.95 sport=443 dport=55448 packets=1 bytes=52 [OFFLOAD] mark=0 use=3
ipv6     10 udp      17 src=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 dst=2a00:1450:400d:0807:0000:0000:0000:200e sport=61439 dport=443 packets=2 bytes=2796 src=2a00:1450:400d:0807:0000:0000:0000:200e dst=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 sport=443 dport=61439 packets=1 bytes=86 [OFFLOAD] mark=0 use=3
ipv6     10 tcp      6 src=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 dst=2a00:1450:4014:080c:0000:0000:0000:200a sport=55409 dport=443 packets=6 bytes=376 src=2a00:1450:4014:080c:0000:0000:0000:200a dst=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 sport=443 dport=55409 packets=1 bytes=72 [OFFLOAD] mark=0 use=3
ipv4     2 tcp      6 src=192.168.123.118 dst=xxx.xxx.226.250 sport=55449 dport=443 packets=2 bytes=92 src=xxx.xxx.226.250 dst=xxx.xxx.103.95 sport=443 dport=55449 packets=1 bytes=52 [OFFLOAD] mark=0 use=3
ipv4     2 tcp      6 src=192.168.123.118 dst=151.101.12.133 sport=55431 dport=443 packets=4 bytes=174 src=151.101.12.133 dst=xxx.xxx.103.95 sport=443 dport=55431 packets=1 bytes=52 [OFFLOAD] mark=0 use=3
ipv6     10 tcp      6 src=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 dst=2a00:1450:400c:0c09:0000:0000:0000:00bc sport=55349 dport=443 packets=15 bytes=925 src=2a00:1450:400c:0c09:0000:0000:0000:00bc dst=xxxx:xxx:xxxx:004d:40fa:4f48:0bff:7646 sport=443 dport=55349 packets=1 bytes=72 [OFFLOAD] mark=0 use=3
ipv4     2 tcp      6 src=192.168.123.118 dst=xxx.xxx.197.42 sport=55314 dport=443 packets=2 bytes=92 src=xxx.xxx.197.42 dst=xxx.xxx.103.95 sport=443 dport=55314 packets=1 bytes=52 [OFFLOAD] mark=0 use=3

Regards


#36

@nbd There was a discussion about this in another topic, but I wanted to ask you. Is there any chance you will backport sw flow offload to kernel 4.9? I am interested in ar71xx platform. Those week SoCs would benefit a lot from this feature but upgrading the kernel for that platform to 4.14 seems like a lot of work.


#37

Backporting flow offload is also a lot of work - I don't think it will happen.
The new ath79 target (ar71xx with 4.14, but based on device tree instead of mach files) is actually making progress now, and I think flow offload provides a nice incentive to work on more board support for it...


#38

If kernel 4.9 is a requirement, the shortcut-fe driver is an option. Won't be upstreamed but an option nonetheless if you compile your own builds.

Some ar71xx units support hardware offload, but I don't see anyone writing a driver for that.


#39

@nbd trying hw offload on a edgerouter x I get this in a loop

I'm using pppoe on wan1 and static ip on wan2 with mwan3
the crashes are starting after I enable and disable flow_ofloading[_hw] in firewall

[  425.886392] ------------[ cut here ]------------
[  425.886402] WARNING: CPU: 2 PID: 0 at net/netfilter/nf_conntrack_rtcache.c:197 0x8f0463d8
[  425.886404] Modules linked in: pppoe ppp_async pppox ppp_generic nf_conntrack_ipv6 iptable_nat ipt_REJECT ipt_MASQUERADE xt_time xt_tcpudp xt_tcpmss xt_statistic xt_state xt_recent xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_hl xt_helper xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_TCPMSS xt_REDIRECT xt_NETMAP xt_LOG xt_HL xt_FLOWOFFLOAD xt_DSCP xt_CLASSIFY wireguard slhc nf_reject_ipv4 nf_nat_redirect nf_nat_masquerade_ipv4 nf_conntrack_ipv4 nf_nat_ipv4 nf_nat nf_log_ipv4 nf_flow_table_hw nf_flow_table nf_defrag_ipv6 nf_defrag_ipv4 nf_conntrack_rtcache nf_conntrack iptable_mangle iptable_filter ipt_ECN ip_tables crc_ccitt xt_set ip_set_list_set ip_set_hash_netiface ip_set_hash_netport ip_set_hash_netnet ip_set_hash_net ip_set_hash_netportnet ip_set_hash_mac
[  425.886531]  ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables x_tables ip6_udp_tunnel udp_tunnel leds_gpio gpio_button_hotplug
[  425.886579] CPU: 2 PID: 0 Comm: swapper/2 Tainted: G        W       4.14.34 #0
[  425.886581] Stack : 00000000 00000000 00000000 00000000 805b7ada 00000042 00000000 00000000
[  425.886599]         8fc44834 805508a7 804e1b0c 00000002 00000000 00000001 8fc11c40 2c45ddf5
[  425.886617]         00000000 00000000 805b0000 e3ddf769 00000004 80440fec b2a193a6 00089e70
[  425.886636]         00000000 80550000 0000c195 805e0000 00000000 00000000 80570000 8f0463d8
[  425.886654]         00000009 000000c5 00000001 00000003 00000002 80550000 00000008 805b0008
[  425.886672]         ...
[  425.886677] Call Trace:
[  425.886685] [<80010498>] show_stack+0x58/0x100
[  425.886693] [<8042a1dc>] dump_stack+0x9c/0xe0
[  425.886700] [<8002e1d8>] __warn+0xe0/0x114
[  425.886708] [<8002e29c>] warn_slowpath_null+0x1c/0x30
[  425.886720] [<8f0463d8>] 0x8f0463d8
[  425.886728] ---[ end trace 7c39a3f673569d93 ]---
[  425.886808] ------------[ cut here ]------------

OpenWrt SNAPSHOT, r6705-a18d88e863

EDIT:
I see that at line 194 there is dst_xfrm
I'll try your git commit kernel: avoid flow offload for connections with xfrm on the dst entry (should fix IPSec)

EDIT2: didn't paid attention the problem is actually at 197

EDIT3: mwan3 was using Local source interface br-lan that made the networking really unstable, after applying the patch and changing the Local source interface to none, for now, no kernel oops

regards


#40

bug report here?
on x86,

[   82.344428] br-lan: port 1(eth0) entered disabled state
[   82.359577] device eth0 left promiscuous mode
[   82.405571] br-lan: port 1(eth0) entered disabled state
[   82.625689] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
[   83.055146] general protection fault: 0000 [#1] SMP PTI
[   83.064858] Modules linked in: ath9k ath9k_common rt2800usb rt2800lib rt2500usb pppoe ppp_async l2tp_ppp ath9k_hw ath6kl_usb ath6kl_core ath10k_pci ath10k_core ath rtl8187 rt73usb rt2x00usb rt2x00lib pptp pppox ppp_mppe ppp_generic nf_nat_pptp nf_conntrack_pptp mt7601u mac80211 iptable_nat ipt_REJECT ipt_MASQUERADE ebtable_nat ebtable_filter ebtable_broute cfg80211 xt_u32 xt_time xt_tcpudp xt_tcpmss xt_string xt_statistic xt_state xt_recent xt_quota xt_policy xt_pkttype xt_physdev xt_owner xt_nat xt_multiport xt_mark xt_mac xt_limit xt_length xt_iprange xt_ipp2p xt_iface xt_hl xt_helper xt_hashlimit xt_esp xt_ecn xt_dscp xt_conntrack xt_connmark xt_connlimit xt_connbytes xt_comment xt_addrtype xt_TRACE xt_TPROXY xt_TEE xt_TCPMSS xt_REDIRECT xt_NETMAP xt_LOG xt_IPMARK xt_HL xt_FLOWOFFLOAD xt_DSCP
[   83.351328]  xt_CT xt_CLASSIFY usblp ums_usbat ums_sddr55 ums_sddr09 ums_karma ums_jumpshot ums_isd200 ums_freecom ums_datafab ums_cypress ums_alauda ts_fsm ts_bm slhc r8169 pcnet32 nf_reject_ipv4 nf_nat_tftp nf_nat_snmp_basic nf_nat_sip nf_nat_redirect nf_nat_proto_gre nf_nat_masquerade_ipv4 nf_nat_irc nf_conntrack_ipv4 nf_nat_ipv4 nf_nat_h323 nf_nat_ftp nf_nat_amanda nf_log_ipv4 nf_flow_table_hw nf_flow_table nf_dup_ipv6 nf_dup_ipv4 nf_defrag_ipv4 nf_conntrack_tftp nf_conntrack_snmp nf_conntrack_sip nf_conntrack_rtcache nf_conntrack_proto_gre nf_conntrack_netlink nf_conntrack_irc nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_broadcast ts_kmp nf_conntrack_amanda mmc_spi macvlan iptable_raw iptable_mangle iptable_filter ipt_rpfilter ipt_ah ipt_ECN ip6table_raw ip6t_rpfilter ip_tables ebtables ebt_vlan
[   83.549778]  ebt_stp ebt_snat ebt_redirect ebt_pkttype ebt_mark_m ebt_mark ebt_limit ebt_ip6 ebt_ip ebt_dnat ebt_arpreply ebt_arp ebt_among ebt_802_3 e1000e crc7 crc_itu_t crc_ccitt compat_xtables compat br_netfilter bnx2 natcap fuse sch_cake act_connmark act_skbedit act_mirred em_u32 cls_u32 cls_tcindex cls_flow cls_route cls_fw sch_tbf sch_htb sch_hfsc sch_ingress evdev i2c_piix4 i2c_i801 i2c_smbus i2c_dev xt_set ip_set_list_set ip_set_hash_netiface ip_set_hash_netport ip_set_hash_netnet ip_set_hash_net ip_set_hash_netportnet ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ip ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set nfnetlink ip6t_NPT ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_conntrack_ipv6 nf_defrag_ipv6
[   83.970254]  nf_nat_ipv6 nf_nat nf_conntrack ip6t_rt ip6t_frag ip6t_hbh ip6t_eui64 ip6t_mh ip6t_ah ip6t_ipv6header ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 nf_log_common ip6table_mangle ip6table_filter ip6_tables x_tables nfsv4 nfsv3 nfsd nfs msdos bonding ip6_gre ip_gre gre ixgbe igb i2c_algo_bit e1000 ifb l2tp_ip6 l2tp_ip l2tp_eth sit mdio l2tp_netlink l2tp_core udp_tunnel ip6_udp_tunnel ipcomp6 xfrm6_tunnel xfrm6_mode_tunnel xfrm6_mode_transport xfrm6_mode_beet esp6 ah6 ipcomp xfrm4_tunnel xfrm4_mode_tunnel xfrm4_mode_transport xfrm4_mode_beet esp4 ah4 ip6_tunnel tunnel6 tunnel4 ip_tunnel rpcsec_gss_krb5 auth_rpcgss oid_registry tun af_key xfrm_user xfrm_ipcomp xfrm_algo vfat fat lockd sunrpc grace isofs autofs4 dns_resolver nls_utf8 nls_iso8859_1 nls_cp437 eeprom_93cx6 sha256_ssse3 sha256_generic
[   84.099473]  sha1_ssse3 sha1_generic jitterentropy_rng drbg md5 hmac echainiv des_generic deflate zlib_deflate cts cbc authenc crypto_acompress uas sdhci_pltfm xhci_plat_hcd softdog sata_mv ehci_platform exfat tg3 ssb ptp pps_core mii libphy
[   84.150255] CPU: 0 PID: 13 Comm: kworker/u2:1 Not tainted 4.14.36 #0
[   84.169050] Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
[   84.188081] Workqueue: events_power_efficient xt_flowoffload_hook_work [xt_FLOWOFFLOAD]
[   84.209326] task: ffff88000ecd0c80 task.stack: ffffc90000068000
[   84.224706] RIP: 0010:__nf_unregister_net_hook+0x1/0x90
[   84.242911] RSP: 0018:ffffc9000006be30 EFLAGS: 00010202
[   84.257405] RAX: 0000000000000000 RBX: ffff88000c5b3228 RCX: 0000000100170001
[   84.292175] RDX: ffff88000ecd0c80 RSI: ffff88000c5b3228 RDI: 6b6b6b6b6b6b6b6b
[   84.305095] RBP: ffffc9000006be58 R08: ffff88000c5b3578 R09: ffff88000c5b3538
[   84.325980] R10: ffffc9000006be50 R11: ffff88000fc1f310 R12: ffffffff81e6c580
[   84.396514] R13: ffff88000d1723d0 R14: ffff88000ec0fc00 R15: 0000000000000000
[   84.459500] FS:  0000000000000000(0000) GS:ffff88000fc00000(0000) knlGS:0000000000000000
[   84.525121] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   84.565460] CR2: 0000000000a931d8 CR3: 0000000001e08006 CR4: 00000000000606f0
[   84.638311] Call Trace:
[   84.655229]  ? nf_unregister_net_hook+0x88/0xd0
[   84.706898]  xt_flowoffload_hook_work+0x12a/0x17a [xt_FLOWOFFLOAD]
[   84.765504]  process_one_work+0x1c4/0x310
[   84.799558]  worker_thread+0x20b/0x3c0
[   84.850119]  kthread+0x112/0x120
[   84.884839]  ? process_one_work+0x310/0x310
[   84.923571]  ? kthread_create_on_node+0x40/0x40
[   84.966100]  ret_from_fork+0x35/0x40
[   84.981738] Code: 41 5c 41 5d 41 5e 41 5f 5d c3 48 8b 05 c1 f1 99 00 55 48 89 e5 48 85 c0 75 02 0f 0b e8 b9 f6 30 00 5d c3 0f 1f 80 00 00 00 00 55 <0f> b7 0f 48 89 e5 48 89 c8 48 c1 e0 04 48 8d 54 07 08 31 c0 eb 
[   85.100453] RIP: __nf_unregister_net_hook+0x1/0x90 RSP: ffffc9000006be30
[   85.111658] ---[ end trace 5c25a390045cac75 ]---
[   85.124535] Kernel panic - not syncing: Fatal exception
[   85.158899] Kernel Offset: disabled
[   85.164077] Rebooting in 3 seconds..