目前我这里docker是运行在centos 7.0系统里,使用1.5版本docker,最近一台服务器总是不定期死机,通过查看日志发现属于内核bug导致,报错信息如下
May 11 03:43:08 ip-10-10-29-201 kernel: BUG: soft lockup - CPU#4 stuck for 22s! [handler20:1542]May 11 03:43:08 ip-10-10-29-201 kernel: Modules linked in: iptable_nat nf_nat_ipv4 iptable_filter ip_tables binfmt_misc ipmi_si vfat fat usb_storage mpt3sas mpt2sas raid_class scsi_transport_sas mptctl mptbase dell_rbu tcp_diag inet_diag veth bridge stp llc dm_thin_pool dm_persistent_data dm_bio_prison dm_bufio loop dm_mod openvswitch vxlan ip_tunnel gre libcrc32c xt_nat ipt_MASQUERADE xt_addrtype nf_nat xt_limit ipt_REJECT nf_conntrack_ipv4 nf_defrag_ipv4 xt_multiport xt_conntrack sg nf_conntrack ipmi_devintf iTCO_wdt iTCO_vendor_support dcdbas coretemp kvm_intel kvm crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel aesni_intel lrw gf128mul glue_helper ablk_helper cryptd pcspkr sb_edac edac_core ses enclosure ipmi_msghandler tg3 wmi acpi_power_meter ptp pps_core mei_me mei ntb lpc_ich mperf mfd_core shpchp ext4May 11 03:43:08 ip-10-10-29-201 kernel: mbcache jbd2 sr_mod cdrom sd_mod crc_t10dif crct10dif_common mgag200 syscopyarea sysfillrect sysimgblt i2c_algo_bit drm_kms_helper ttm ahci drm libahci libata i2c_core megaraid_sas [last unloaded: ip_tables]May 11 03:43:08 ip-10-10-29-201 kernel: CPU: 4 PID: 1542 Comm: handler20 Tainted: G W -------------- 3.10.0-123.el7.x86_64 #1May 11 03:43:08 ip-10-10-29-201 kernel: Hardware name: Dell Inc. PowerEdge R720/0X6FFV, BIOS 1.6.0 03/07/2013May 11 03:43:08 ip-10-10-29-201 kernel: task: ffff880418adf1c0 ti: ffff8800c8d08000 task.ti: ffff8800c8d08000May 11 03:43:08 ip-10-10-29-201 kernel: RIP: 0010:[] [ ] _raw_spin_lock+0x37/0x50May 11 03:43:08 ip-10-10-29-201 kernel: RSP: 0018:ffff88041fc43ac8 EFLAGS: 00000206May 11 03:43:08 ip-10-10-29-201 kernel: RAX: 000000000000108b RBX: 0000000000000000 RCX: 0000000000000000May 11 03:43:08 ip-10-10-29-201 kernel: RDX: 0000000000000002 RSI: 0000000000000002 RDI: ffff88081609c318May 11 03:43:08 ip-10-10-29-201 kernel: RBP: ffff88041fc43ac8 R08: ffff8801049856d8 R09: ffff88041fc43a00May 11 03:43:08 ip-10-10-29-201 kernel: R10: 0000000000000000 R11: 00000000e1bec8f9 R12: ffff88041fc43a38May 11 03:43:08 ip-10-10-29-201 kernel: R13: ffffffff815f2d9d R14: ffff88041fc43ac8 R15: ffff88081609c300May 11 03:43:08 ip-10-10-29-201 kernel: FS: 00007fb082b8b700(0000) GS:ffff88041fc40000(0000) knlGS:0000000000000000May 11 03:43:08 ip-10-10-29-201 kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033May 11 03:43:08 ip-10-10-29-201 kernel: CR2: 00007f2a743e6000 CR3: 00000008183c9000 CR4: 00000000000407e0May 11 03:43:08 ip-10-10-29-201 kernel: DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000May 11 03:43:08 ip-10-10-29-201 kernel: DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400May 11 03:43:08 ip-10-10-29-201 kernel: Stack:May 11 03:43:08 ip-10-10-29-201 kernel: ffff88041fc43af8 ffffffffa042429f ffff88003714be00 ffffe8fbefc41540May 11 03:43:08 ip-10-10-29-201 kernel: ffff880419070e80 ffff88041fc43b30 ffff88041fc43be0 ffffffffa04239a4May 11 03:43:08 ip-10-10-29-201 kernel: 00000001b9ec8070 ffff88003714be00 ffff88041fc43b28 0000000000000246May 11 03:43:08 ip-10-10-29-201 kernel: Call Trace:May 11 03:43:08 ip-10-10-29-201 kernel: May 11 03:43:08 ip-10-10-29-201 kernel:May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ovs_flow_stats_update+0x4f/0xd0 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ovs_dp_process_received_packet+0x84/0x120 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ovs_vport_receive+0x2a/0x30 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] vxlan_rcv+0x6d/0x90 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] vxlan_udp_encap_recv+0xb8/0x130 [vxlan]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] udp_queue_rcv_skb+0x162/0x3d0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] __udp4_lib_rcv+0x19d/0x690May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? ip_rcv_finish+0x350/0x350May 11 03:43:08 ip-10-10-29-201 kernel: [ ] udp_rcv+0x1a/0x20May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ip_local_deliver_finish+0xb4/0x1f0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ip_local_deliver+0x48/0x80May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ip_rcv_finish+0x7d/0x350May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ip_rcv+0x234/0x380May 11 03:43:08 ip-10-10-29-201 kernel: [ ] __netif_receive_skb_core+0x676/0x870May 11 03:43:08 ip-10-10-29-201 kernel: [ ] __netif_receive_skb+0x18/0x60May 11 03:43:08 ip-10-10-29-201 kernel: [ ] process_backlog+0xae/0x180May 11 03:43:08 ip-10-10-29-201 kernel: [ ] net_rx_action+0x15a/0x250May 11 03:43:08 ip-10-10-29-201 kernel: [ ] __do_softirq+0xf7/0x290May 11 03:43:08 ip-10-10-29-201 kernel: [ ] call_softirq+0x1c/0x30May 11 03:43:08 ip-10-10-29-201 kernel: [ ] do_softirq+0x55/0x90May 11 03:43:08 ip-10-10-29-201 kernel: [ ] irq_exit+0x115/0x120May 11 03:43:08 ip-10-10-29-201 kernel: [ ] do_IRQ+0x58/0xf0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] common_interrupt+0x6d/0x6dMay 11 03:43:08 ip-10-10-29-201 kernel: May 11 03:43:08 ip-10-10-29-201 kernel:May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? ovs_flow_stats_get+0x145/0x180 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? ovs_flow_stats_get+0x133/0x180 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ovs_flow_cmd_fill_info+0x1c7/0x320 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ovs_flow_cmd_build_info.constprop.25+0x6c/0xa0 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ovs_flow_cmd_new_or_set+0x4c5/0x520 [openvswitch]May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? __wake_up_common+0x58/0x90May 11 03:43:08 ip-10-10-29-201 kernel: [ ] genl_family_rcv_msg+0x258/0x3d0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? genl_family_rcv_msg+0x3d0/0x3d0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] genl_rcv_msg+0x91/0xd0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] netlink_rcv_skb+0xa9/0xc0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] genl_rcv+0x28/0x40May 11 03:43:08 ip-10-10-29-201 kernel: [ ] netlink_unicast+0xed/0x1b0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] netlink_sendmsg+0x327/0x760May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? netlink_rcv_wake+0x44/0x60May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? netlink_recvmsg+0x1cb/0x3e0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] sock_sendmsg+0xb0/0xf0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? sock_recvmsg+0xbf/0x100May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? task_scan_min+0x3e/0x60May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? _raw_spin_unlock_bh+0x1b/0x40May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ___sys_sendmsg+0x3a9/0x3c0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? ep_scan_ready_list.isra.9+0x1b9/0x1f0May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? ep_poll+0x123/0x370May 11 03:43:08 ip-10-10-29-201 kernel: [ ] ? getrusage+0x43/0x70May 11 03:43:09 ip-10-10-29-201 kernel: [ ] __sys_sendmsg+0x51/0x90May 11 03:43:09 ip-10-10-29-201 kernel: [ ] SyS_sendmsg+0x12/0x20May 11 03:43:09 ip-10-10-29-201 kernel: [ ] system_call_fastpath+0x16/0x1bMay 11 03:43:09 ip-10-10-29-201 kernel: Code: 02 00 f0 0f c1 07 89 c2 c1 ea 10 66 39 c2 75 02 5d c3 83 e2 fe 0f b7 f2 b8 00 80 00 00 eb 0c 0f 1f 44 00 00 f3 90 83 e8 01 74 0a <0f> b7 0f 66 39 ca 75 f1 5d c3 66 66 66 90 66 66 90 eb da 66 0f
通过在stackoverflow查询发现此问题属于内核bug,解决方法是升级内核。
下面是把centos 7.0默认3.10版本内核升级为4.0.2版本过程
1、导入yum源的认证key
rpm --import https://www.elrepo.org/RPM-GPG-KEY-elrepo.org
2、安装yum源
rpm -Uvh http://www.elrepo.org/elrepo-release-7.0-2.el7.elrepo.noarch.rpm
3、安装新内核
在yum的ELRepo源中,有mainline(4.0.2)这个内核版本
[root@ip-10-10-29-201 ~]# yum --enablerepo=elrepo-kernel install kernel-ml-devel kernel-mlLoaded plugins: fastestmirrorMooseFS | 951 B 00:00:00base | 3.6 kB 00:00:00elrepo | 2.9 kB 00:00:00elrepo-kernel | 2.9 kB 00:00:00extras | 3.4 kB 00:00:00updates | 3.4 kB 00:00:00(1/2): elrepo/primary_db | 233 kB 00:00:02(2/2): elrepo-kernel/primary_db | 782 kB 00:00:04MooseFS/primary | 4.2 kB 00:00:00Loading mirror speeds from cached hostfile * base: mirrors.yun-idc.com * elrepo: repos.lax-noc.com * elrepo-kernel: repos.lax-noc.com * extras: mirror.bit.edu.cn * updates: mirror.bit.edu.cnMooseFS 30/30Resolving Dependencies--> Running transaction check---> Package kernel-ml.x86_64 0:4.0.2-1.el7.elrepo will be installed---> Package kernel-ml-devel.x86_64 0:4.0.2-1.el7.elrepo will be installed--> Finished Dependency ResolutionDependencies Resolved========================================================================================================================================================================== Package Arch Version Repository Size==========================================================================================================================================================================Installing: kernel-ml x86_64 4.0.2-1.el7.elrepo elrepo-kernel 36 M kernel-ml-devel x86_64 4.0.2-1.el7.elrepo elrepo-kernel 9.5 MTransaction Summary==========================================================================================================================================================================Install 2 PackagesTotal download size: 45 MInstalled size: 199 MIs this ok [y/d/N]: yDownloading packages:(1/2): kernel-ml-4.0.2-1.el7.elrepo.x86_64.rpm | 36 MB 00:00:11(2/2): kernel-ml-devel-4.0.2-1.el7.elrepo.x86_64.rpm | 9.5 MB 00:00:31--------------------------------------------------------------------------------------------------------------------------------------------------------------------------Total 1.5 MB/s | 45 MB 00:00:31Running transaction checkRunning transaction testTransaction test succeededRunning transactionWarning: RPMDB altered outside of yum. Installing : kernel-ml-devel-4.0.2-1.el7.elrepo.x86_64 1/2 Installing : kernel-ml-4.0.2-1.el7.elrepo.x86_64 2/2 Verifying : kernel-ml-4.0.2-1.el7.elrepo.x86_64 1/2 Verifying : kernel-ml-devel-4.0.2-1.el7.elrepo.x86_64 2/2Installed: kernel-ml.x86_64 0:4.0.2-1.el7.elrepo kernel-ml-devel.x86_64 0:4.0.2-1.el7.elrepoComplete!
4、查看当前内核版本
[root@ip-10-10-29-201 ~]# uname -r3.10.0-123.el7.x86_64
重要:目前内核还是默认的版本,如果在这一步完成后你就直接reboot了,重启后使用的内核版本还是默认的3.10,不会使用新的4.0.2,想修改启动的顺序,需要进行下一步
查看默认启动顺序
[root@ip-10-10-29-201 ~]# awk -F\' '$1=="menuentry " {print $2}' /etc/grub2.cfgCentOS Linux (4.0.2-1.el7.elrepo.x86_64) 7 (Core)CentOS Linux, with Linux 3.10.0-123.el7.x86_64CentOS Linux, with Linux 0-rescue-18b184aa09434ecf9739a70c6b63638a
默认启动的顺序是从0开始,但我们新内核是从头插入(目前位置在1,而4.0.2的是在0),所以需要选择0,如果想生效最新的内核,需要
[root@ip-10-10-29-201 ~]# grub2-set-default 0
5、重启
Reboot
6、重启后查看内核
[root@ip-10-10-29-201 conf]# uname -r4.0.2-1.el7.elrepo.x86_64
经过升级后,20天没有出现此问题,所以判断此次文件为内核bug引起,通过升级内核解决。