Bisect identified the problem. It's the attached patch. I applied it to 4.4.152 with patch -Rp1 and I'm running the resulting kernel now. MSB -- For every idiot-proof system there exists at least one system-proof idiot.