last executing test programs: 2m35.160294575s ago: executing program 2 (id=226): r0 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000300)='./binderfs/binder0\x00', 0x0, 0x0) ioctl$BINDER_SET_CONTEXT_MGR_EXT(r0, 0x4018620d, &(0x7f0000000100)={0x73622a85, 0x0, 0x2}) r1 = shmget$private(0x0, 0x13000, 0x1, &(0x7f0000feb000/0x13000)=nil) syz_open_dev$tty1(0xc, 0x4, 0x1) bind$inet(0xffffffffffffffff, &(0x7f0000000000)={0x2, 0x4e22, @local}, 0xfffffffffffffcd1) r2 = bpf$MAP_CREATE(0x0, 0x0, 0x48) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r2, @ANYBLOB="0000000000000000b7080000000400007b8af8ff0000039cf98b00000000000007020000fcffffffb703000008000000b7"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x22, '\x00', 0x0, @fallback=0x11, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000340)={&(0x7f0000000300)='sched_switch\x00', r3}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0xa, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r4 = getpid() sched_setscheduler(r4, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeea, 0x8031, 0xffffffffffffffff, 0x28f43000) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000280)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r5, &(0x7f0000000180)=@abs, 0x6e) sendmmsg$unix(r6, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r5, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r7 = signalfd(0xffffffffffffffff, &(0x7f00007aeff8), 0x8) read(r7, 0x0, 0x0) rt_sigprocmask(0x0, &(0x7f0000000000)={[0xfffffffffffffffd]}, 0x0, 0x8) timer_create(0x3, 0x0, 0x0) syz_init_net_socket$nl_rdma(0x10, 0x3, 0x10) r8 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000300)=ANY=[@ANYBLOB="18010000120000000000000000000000850000006d000000180100002020642500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000600000095"], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r3, 0x0, 0x0, 0x0, 0x0, 0x1, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000240)={&(0x7f0000000380)='fsi_master_gpio_in\x00', r8}, 0x18) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0xe, 0x4, 0x8, 0x8, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r9 = socket$inet_udp(0x2, 0x2, 0x0) setsockopt$inet_buf(r9, 0x0, 0x8008000000010, &(0x7f0000005e40)="17000000020001000003d68c5ee17688a2006c08020300ecff3f0200000300000a000000009afc5ad9485bbb6a880000d6c8db0000dba67e06018000020000f10607bdff59100ac45761407a681f009cee4a5acb3da400001fb700674f19b44e09f9315033bf79ac2dff060115003901000000000000ea000000000000000009ffff02dfccebf6ba0008400200000000e90554062a80e605007f71174aa951f3c63e5c83f1ba2112ce68bf17a6e00000000000", 0xb3) shmat(r1, &(0x7f0000ff7000/0x3000)=nil, 0x400c) 2m34.142182605s ago: executing program 2 (id=230): socket$nl_generic(0x10, 0x3, 0x10) r0 = socket$nl_generic(0x10, 0x3, 0x10) syz_open_dev$ttys(0xc, 0x2, 0x1) r1 = syz_genetlink_get_family_id$ethtool(&(0x7f0000000040), r0) r2 = fsmount(0xffffffffffffffff, 0x0, 0xc) socketpair$tipc(0x1e, 0x2, 0x0, &(0x7f0000000000)={0xffffffffffffffff}) r4 = openat$sndtimer(0xffffffffffffff9c, &(0x7f00000000c0), 0x0) ioctl$SNDRV_TIMER_IOCTL_SELECT(r4, 0x40345410, &(0x7f0000000040)={{0x1, 0x1, 0x7fffffff}}) ioctl$SNDRV_TIMER_IOCTL_INFO(r4, 0x80e85411, &(0x7f0000001240)=""/4111) setsockopt$TIPC_MCAST_REPLICAST(r3, 0x10f, 0x86) r5 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$ETHTOOL_MSG_COALESCE_SET(r5, &(0x7f0000000080)={&(0x7f0000000000)={0x10, 0x0, 0x0, 0x200000}, 0xfffffffffffffed5, &(0x7f0000000180)={&(0x7f00000001c0)=ANY=[@ANYRESHEX=0x0, @ANYRESDEC=r2, @ANYRES16=r1, @ANYRES8=r5], 0x24}, 0x1, 0x0, 0x0, 0x844}, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="18000000000000000000000000000000181100", @ANYRES32, @ANYBLOB="0000000000000000b7080000080000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000140)={0x0, 0x4, &(0x7f0000000200)=ANY=[@ANYBLOB="180000000000000000000000000000007112370000000000950000000000000089e2d90aa1795cc26efb1dacf01150510936875c66d6a7d6eb12d4cdbc5c0ce0d29df91940d8ca08008e7aa5b3c9a10909d6e18b263131bf965f55746df5189a2e23905ae4dc5340e0eb74eb523d5b77a763cccb768b4453c8b1b1dd0a71983b5c2cfe11f3d30228772b0b798ebaf5abde2ce3ec34f8c6f13ee1f181ac563ba7a7edc9be94452da6d7eb67ae3243cb393245efd0dd21de9553cbd1a8516282de458c44d1ddae97af584de743d44ed18d20dd3b2c42cf1e8b27788dfc562367d46197198cd19fda89a6feca6c738b1d4b2522"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x24, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) syz_usb_connect(0x0, 0x36, &(0x7f00000002c0)=ANY=[@ANYBLOB="1201000014da2108ab12a390eb1e000000010902240001b30000040904410017ff5d810009050f1f010400000009058303"], 0x0) r6 = openat$vnet(0xffffffffffffff9c, &(0x7f0000000180), 0x2, 0x0) ioctl$int_in(r6, 0x40000000af01, 0x0) ioctl$VHOST_SET_VRING_ADDR(r6, 0x4028af11, &(0x7f0000000200)={0x1, 0x1, 0x0, &(0x7f0000000740)=""/51, 0x0}) r7 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_MSG_GETSETELEM(r7, &(0x7f0000002600)={0x0, 0x0, &(0x7f00000025c0)={&(0x7f00000004c0)=ANY=[@ANYBLOB="180000000d0a81080000000000d452ad208c5ecc7e30efb472570304000380fa997ab7bdc03cda70872d07503c60161cf1337ec65f0100d3ff71030b45bc73cd89100f790295c5d0483668f568b63c119f176bd5c99eb534c24e831451e4a83ebee06b5e03c2c3757236ed19e4fcdc973c911b5ca016a8bbe49241a9c20b8356c552652c59854925da135f08595b61dbb2c8790152464e60a0b9ac4a44f653169595ae61212b842482bfb20b1cbd1b0039af682bf8c46928382d7b06ddf613ef43243e07ede931a641f40490a3ba2c393cde90508f91bfd9a276f15fbe88bfc47259"], 0x18}}, 0x8000) r8 = socket$packet(0x11, 0x3, 0x300) ioctl$VHOST_SET_MEM_TABLE(r6, 0x4008af03, &(0x7f0000000340)) r9 = dup(r8) bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000040)={0x1b, 0x0, 0x0, 0x4, 0x0, r9, 0x2ba726c0, '\x00', 0x0, r9, 0x3, 0x4, 0x3, 0x0, @void, @value, @void, @value}, 0x50) ioctl$VHOST_NET_SET_BACKEND(r6, 0x4008af30, &(0x7f0000000000)={0x1, r9}) r10 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b00000005000000000400000d00000001"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000440)=ANY=[@ANYBLOB="18000000008000000000", @ANYRES32=r10], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2, @void, @value}, 0x94) r11 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x6, 0xc, &(0x7f0000000440)=ANY=[], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x36, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000180)={r11, 0x2000000, 0x0, 0x0, 0x0, 0x0, 0x3800, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) bpf$MAP_CREATE_TAIL_CALL(0x0, &(0x7f0000000380)=ANY=[@ANYBLOB="0300000004000000040000000a00000000000000", @ANYRES32, @ANYBLOB='\a\x00'/20, @ANYRES32=0x0, @ANYRES32=r9, @ANYBLOB="03000008000000000000000000000000000094000000000000000000"], 0x50) 2m31.692609988s ago: executing program 2 (id=238): syz_open_dev$vim2m(0x0, 0x800, 0x2) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f0000000300)=ANY=[@ANYBLOB="180100"/13], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x18) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket(0xa, 0x3, 0x3a) setsockopt$MRT6_ADD_MFC_PROXY(r4, 0x29, 0xd2, &(0x7f00000000c0)={{0xa, 0x4e24, 0x0, @loopback}, {0xa, 0x0, 0x0, @empty}, 0x0, {[0x0, 0x0, 0x2]}}, 0x5c) sendmmsg(0xffffffffffffffff, &(0x7f0000004340)=[{{0x0, 0x0, &(0x7f0000000480)=[{&(0x7f0000000580)="a760afbe2e8de8d40b7a4f83eeb964403418c26d28b5ef010072da83552a6fba20f162321da66859c8335b615d1e362d57a77b0b18241b439fbd65ae8b86aef876871efe7a4b81db57a87e55df150e05b25d27c80d1e6ed2c6198086f7d4de5d73440c73d7be3697afa564bf145eba2e805d272a6044e5288f0bc7d5dccdf48e27019ba59e78ee242e99a3405922b0250e45cea0bfa9a1914e7dbba6db8f1f56a1b96816cc4cc9edd5a9df92acac602ca518832b2c4431ff803032813b45d3eaf1fce356e85e7823d12119c88c6521c7441400cc9d9bbeab8279efeea8f2d3daae8df644caf73c52efb043419fe7e72907886afc62a17ffbe524175c04d4b0b0db1c609a3b38d4e2582b1e5077cf6e689b565d65796b884cd3c11ea26dfcd4ce6574c847b85e8c936d11b1de59f16f0159b83017be43e92a27c05171f7d55010c050047da9c092941c0dd4d807cb94a1a9ee6fd787ad8160cdf9a2257f8e0759ca2e10ebe17b5264e9289267882f1dda45198dd75e953167f23406d05158830ac9664998cc8cdbf2d92ae15d61c6c5f4b2763b44e76a88b3514a2da9d8d73d516a745875be2505b835f8a227c68954c39ace6c2f273952b6c47f1e6f7ae3655f1fd38c3387e390321f2db8dec04815e510a78a2bb216392a4005c770ef2bf74564f506981dbfeebd1c5680d598c80d0e51148e92b77d6b818ffcbb58b48004dd7725183503f2ef71e6d1dfd9501db73068255ba2eae5840c9b8fc503b81a8bca864b7e00091dc99ff4876110d5f5f0167cbcd3ce3b882675959d2da3361ecfefa923d446c3b58db99845c899410e56397c4bbfd84aedecce81f848691674303b0258ac9e656f818cdb1d7c91dfe3cf3b728c9c38a0d17d52d7c3abe892f7e93dcca74bab7dc6eef99b4d9563ef8786dab2447162bce8cf7bb03ed86ce410bf3c7bd175b5906846df5bd0a00dbee7dcefaf923c65932df8cbd2b67e99fba4e6c807a64244ee5ed0025b283e33cd3512e5bd47feed786d0c203ee70295acb4d73ce7ac4d29a4a13a68c3e4452092a050058a3396c642be503c3bd8fd5c65b81faec8b92a5bdf816a412b6e8e670514acaaf5fb50457a35f16fa119531a1f2307a82d4b7b43006309562eb5575168dae2cfdf87181b9bc7c94b19e4750a03a9cf9fa472009dc577db1626d9dfcd8a1d48d777132036e842b073deafa1cc6ef2bf3156dce6fb111fd044f99f49bf3984ddcc925fbe2609edbb554efabfea8eb4b234b03ad454962d64ea6389a205d902f842f6fdbe09ee67f116baecbf8c393f97472bb6c11a234e7cec898417e03878b2682aeaa9fc6311c914d8fef61f9bc541a61ebf7d1ee0e692e1f3641e06c8197f2be2957da0d91fc5c23761f8908c503fdc4c07dfca795460e64a1f45645c72a88ab322f035932c548cb2f18d1ef7cff1bb79e3a954ec47778634deffc3e5b97cba7d34e8529431372fc04ade084b6a74cc7e822fd8290b68119c5af7136334091850b8772e59398d495bf525477d5f1f47c5e52035db8985e6a19aba0ed310b820b33305b71b31f96b12e132934d8ffbc0fc8f492329d7b39745bd89f1ea25232756b17ed0e1962b6cd3bfa201d9c44f6417105fc744d38db0dcb00b95df7ecb2ff083080fddbda3fa87912cd924a9f1a266ca4381be7c21895b8285019b8f781493eb8f0c080f1dfee5d1ee2d5568b4b4c0d7880e6ce49ea5315590d6026b01b333baf71eef5e386aa59f4db0feb2564cd32e40fb67c8186010ccc5e718132bf220bd6a9bb348cf1024238c29751bae245b28d8809eda0bb05c52fe4b06d4bfa14eb6483c82e4134a3db378fa67cc828460bf78d7b065349257ff7dab3d5e5031137c6fa746352ba6f99fefa4c83a71f0c49ee11cd093a1512da116b8e7cd64aa7a5bab63f42cc6c0be9ef61fc6f2bf80d9dd8ee438867224daa04937a8fa39f1bb4dd5c3581a4755b098d8a815f1ce5173d2f47f34eaec59212a110bdcbb942eeb302cfb8f0d1ea69552ba0e3faf1d6fa1f121ce86b8d3cad3665eb7f76c8068b586012cc46fefff38fd4ff3f35ac1cef079e6a12cd853169d2e9027b1323447147ffe92fb273aec9ff13f1e8bb59fb1ee070e8e4c54489cf347a426b3f7f44d4991372e6358ded34cd059ff27af5b56a8e2d78eea2f3558953c04c4a22783d90e04253b9267eee4af52719a10477bdd60ccd5292315c506ae5bba4114e7f86419de6052f675286bf4508f0afc7d3a9c39f347e8fba61b76c53e034b1671c42412b5d37548241f5443bbc00d87d989de8d23b097aa6cb2fb9fbd62dcd943ac3db5c230231670b5326eb8a895a21cc6b773ea26fecec12ce3afa8ab3bdc1e0a1f09ea014db9c134484f47728e6afb0259140c65088514f3c0404f608d1ff7d0d1a2a7a83cff7f23e6ab05faac46f22c7cf8feaa2a03770635bcc1ef3919168218806f4ac837584427d6403069ec00964c587446426588d8169daa861f9d56e49035f716eb4cef4ed02d1f20c8cfa4995b178d13f6ab84e23a55d2d1f58e9fc4ee4138efe09d072d1a298369592d56dc44b097129120300c1f393f29740512fbae9758eac5875b7f6aa6fc0cb8f36b33cb9259dac71a0fd53838b938a71e276f5b59a38efa31cab7409a52687866c495204dea35715054d57ca74106c6e2467ad895d660327cbdb6f0ae17b8caa85bc70dfc2e99e0884a020c32ec63e6f4f24eda34e3916c33fa6725839f4c74764e0ecfbdeb07d1e15a1362ea65ff595ccfa67db4c06f5a344bd5b15f376f2780df78aaaf318be1c271a4fd86f53da2a680e4e7cacdc203444acdb7cd9569052be868f5eb74ee7eb324b26652e74c0c25802f827c8470d550842e6d6957b8c5cfbbc6868156c59da41fb922368cd718354f0d4fe118b9d7669a831a38a5c5c54f506eb46828d91bb8f11ecb49b9ab1b8b619ef0c3af2a0db95a1dab11795eb42aa5c3e9b5a6e73719d0f772b24a22bfb0e8b87d5dca883d20f9e2220991b85f57797d183e3131792966234c7c9e170aa0ea9da4247226c8d93e3985cf18db170e5d24dba46aff834741c4654c6858ccb1a0c0e0ec5d809055b0b6f65cc2f760632f8f87cd7bcb8d134f702d6386eb62e53b72218491604ff601af561daa738733e5ad33a0645819c6e747756fc113486a2d1c2d6cdf54a25177a412b52f8bdfbe6d3757d2f0cb90c4712e7d5f79d14623360771e0ecc2a740e76c01aec475b70828d9438ee28cf5ea44456fbcc9e5d8bd9f8c692d2a93c51dc805652831381d0a61cc054e8b42bd4f6cd040dc27dfdfdcd269ee24b2f01074fd19f40c7923971c22aef6650af290969171ba569799fb0b0f36f8e0cc92332668a02592d313f1644943cf0a71c134c1023338f4da8747ff1b68bf502d11cf8157804cd0e6f844617c2e4e3c370446f8e65e73c4f88de129090bbb338f2f87dec7ac6a6159214c37e56c533ac6259aa02be9eeb0956a1587d38ae92b5c75fd57ca8f0b7fcbff52277b5bbf0bba03b0a4cb7e5698247155ceadbd430a0097d4d77dd7f58c278bbba4323a195b06bfdced5484d7ff19157fd20d486c3b645dff8a2b96b21cacee48943205c55de7bea302544a5667ae1ed186aea68e03fd3cc141c0f6a4a72bf165b735493b9ab90b5637c1c58c5b65d3de9def4997d3108f87081d249dd5462c0ac744c754631331a33426646bdb588549174ba42a7bd5e04214c5feda110e5d68b7d295b84fa6693653e08bd7b169eb4841719825e8c44827ce451d6bdebaa0d7976dd0d0e72949cac19f23c9067b0183a6ff6df1fe6645bda015926fec23adb887edf3c1621bc64958d6395eb58318d134ef62c91dc3044593834df28069f4c18f05ebc91b5dd59f637a170ca996d69f3cc52080323282ddefdd504d6f733c7fb2f28862ad0a84df159ce2245ee5f43d5c64122776db96148da34ae199f67a79af629415e707f1704ffb58fa39080fd38307538957be37b4a5b2aa6701da3651b734e146f35b1703a888356566ba745c92d362b61aef5b5ccedcd37bbbe645914cd5471c879fa153f8379a8417a78d5040cfb6a84125ba728ba1271230510f8d72f18f320c08cbca865935bba4f6e61b08433bc3e2e26c86fe5945b308e987f6aa0e77e7b12b8298949e85f993bd997ca9015cf583d739bdc7da932f432a121da654f5d2fbf0f6db4e11cfe807861eb8c7bde5d48df44eecb2f8fbcc31c9757c1b77bf6d3bdff7c548c7bb41cd07b0f3ddf7c43bf62d2c56f6e4c7e7f2a2db371c6a145cb836787ac34e501546fd556589beaebcf1dd9162a6c106437d80312b22c9b74dee9b7637407692fb76030c024d394bc0725c04493bde07d8c6385a364fdfc75f435b6fdc802308428c723004ff7577ec478a30ef80807ec28cf276188ecdecbebcd9cb49b052b3d395d166189f94418280e49f2b7f8fe9b73005ef228345951390ffc9bdc6d5f78ec14e22963b187f933049c90d8b7cfedce7955c9d50517ed67dee38a348c4e5a019dbc824e5f4a54bf740b38bb5b83c5b3fbfc861c07055c008b57b6ee42b456f88c8732a694a7e71a8db330ba14cece1f665efd68a5d75347af72ba1cc3dd0ac361d11b7eeb39da8328306c60b66329afc6dde4861aec7ac6440f7edf619aecd63f3268137895c12c3fdf3199055be3d38f3b5dc527d7f10d7b727e939e020bcc79652651b8493d510f2e10aba8d6912646bc59b073802661d48fc67c452ebb06f9cd896fc6f60f991c5385eb9d17178b6c8f2e3f787d725f6cb6a458b62a4dda7802fd37da1f4629a53ee59ecfb334cc90f4b157a34aa28897255ee27d88922bf3fd97329d7cfedd1c7b36f6f713df969f79fd9ca1d5e73ef474c7296c1e264975bf2ef71b30798c5d84b077f1c40a0875e6d14f92c102cea9894abc24f3c5302cd100831761996e6c227070f0b3e75c09856e61cf87d8b7974a6ba65d60790d8dd81f719c6205817e77e2afb12f0d996bd13bcc5659a4ed3b41c9b659060c65795e98749bea34b839efebfc88a49f1f77611ccd52c5b5803bad9412b5f3dc5c357ac7c9a38510d0526a3d9e235ad52853c136ddddaf1ceb407b829d276cf361a155ea292cc74f9934a9ef34c8b3add534ad3f40110cc182f0a40fbac0ae6b7750c2d7ca1a644c803872e110791a6215dd8ac519c35eee2fe118a2ed07ef7aa4fd512984fc5f41c858dbb90cd2eb14f5b19762852f037124840a3339378b3c96c9afc9e4e4209a6fe1f36ccf215836e560d7480bc5e71c4729122fb5932efd572ee760da93bae91118ac4133bab066d59f2ef934ec78aa995af80eddc079affc4e32e92fe9c8badd44382323663b2ef25347bd148989c9d46508ac6efe0b30ab55ee2f8b06ab0928e863fd154a1eca0861ff7aaf89f7eab00ff0de2eb0efad1ba6ba07a16549e043336c57a8e1740342bb32d36d90f6ccc0431c87017b2e2e36f97f401217a832451bbcdc3900510cba3f85ec0515a78d93a8b38950dfa599dd179cb0b7e5d2390162323d0516b471faa2ae880f921b71c7f2b7167f2274e6db7af3ec7d62f0affd4df1c44bb39915c1514701ad1522c116482f580e3b8df20ec34b07298b3eac8d8809e5d0504f06a915e7df4262668ff716864c12f97f22aef86e0f122b1c00c1760ea0ff78d7fb8e5bd03f141536437036678ecebc4cec6ad3265186a1db45b71491ff05f190004f663bdf9b05d0f7bf420b518f319c7494a1823ed8550316276915709e22f813a682373db25c1979b", 0x1000}, {&(0x7f00000003c0)="022091f5ef6d962828211136656e28071cee2984bb6a1151bd7294df1778daf02a5096a71812acaa47fcfa6884b3835bc383", 0x32}, {&(0x7f0000000400)="a18253b967bcc956d96e573353f0cb67618d80a77ff4a5fc77384a001f56ec5113e245a137dab5264aef654f308f300b7757a782b84b2ebc432304549d9f7ad3aacb1c1ca2c8fdbf068d09eebb8b6fab7174b703e6454cbf5c0375410b1e96326bc028b28265cb1ad3187c4b67ecbb6576bfdb1f9a6bee6b", 0x78}], 0x3, &(0x7f0000001580)=[{0x30, 0x118, 0x2702, "a18eba8eef38ce8ef85553b6356fe9c5bff7461a9d1429e0235bb809a1"}, {0x108, 0x0, 0x7ff, "020c3cba030d9a2beda72e76881e57be98e04bf714a3f3988db13cd205f329df301d17d353a825ef366dae27fe4ee15c2a77f0abbbcb14ee15e3238928489e99a35059fe41b35afb0d278d0385cd4d8e7ef3df9997aed43e494aa3361241d7837b0423184e58dd183fabd44090518758387947fea0a6fc841b350e1928a7bdb45c5cf5d6dee95d0f6af36670c35cbfa58d8092251833ee0b941c077f83e96a9ecc3e9725ec4f7ad45099f3cb5713a4cf35085d5f1e864b9498823c65bc67ac36cba710a6f5e23df7e8cdb6af0b66905f3fd54051886e96f9076c94a14371004263aeac3010689e39e64af31f4b4de3ff1226a6"}, {0xd0, 0x118, 0x1, "015d9095f36bf36a087d3a7282b6597d74cb1be72932a4ba7476ffec1c3e21a177a438b0bb910c032c04dda7853ebc8bebb02dd071707b0b570f9edb22327cedac8046749595a4072c1534df75fd238d1fac5b9254ad687a35d40f130040554dd0e5717b044310fb0e3f2b482c7a25717b644b5fa1c6bab3797b0f1b603dca2ffde8b0815a8a7d630ece03a1095f93d492b80e71cff0d5ed57c44e3abb8a0e89d60969ed8a7afbaaccb649cf172493f7246cbe5834fa607cc5bdd108a4"}, {0xd0, 0x115, 0xbda, "9594b8d829b7d049f1d80381c6cd3fd2a246185ce7bb83bd37e2f8206e0ecb919b4da40b0e75ee3c1d5e0676aaf017f5a727a2d563cabcc29a02f86cf2a2a3d7e1fb4bf9952d28c186431859360e3e20f986d96e72bef333a63b8194200f4214f06b40f2f771a5147cb5d6cc25cb20ce92983674778b19e3068087a6e065d01607e4f6bf47a5cdcfdcfe7e37c5a2a34092e64788e0902c12af67ce0eb0761460c2b74277c874a48e7e52c6fb58b4eea7cddc84fe7f189a5a946876741963d9"}, {0x28, 0x10d, 0x5, "277205454978fde4e7c49288db732b5c5ecb"}, {0x98, 0x10e, 0x870f, "5ccc2412a97e0aff94734d36d4cea8e8c37b4c48b859defd7ddde41a10bb11da9dbeb39da9581bdacba3d201d07484a64dced95faf2a4f3c96ac8920447a294bb7741e39a1fcd625b754238ff7e08d085bf52c63fa6aec45411b6d2d776f8cf7a360588a78ee376f6338b1b6fcd95f8c2d53bf4e194b3509c73d897ad84f53737b7bd31c8ea63b"}, {0x40, 0x116, 0x9, "6207dc8d6959b5dd8c55bfc46e18f52d266aeeb4d18a56e2e3f17d48035e65d06a72a2cd20ddb2149da0"}, {0x1010, 0x3a, 0x200, "4ddff663194019dc3e39e3d2ff84b8cc4f521b41896ac9c72b05d9f28070727745d4b04575e89a57cea7bc170d725eacdc59e4e81fa788cfbeb00c3348675e5866d2b61e0ce0c149e08ba0dd1f20e9a9522c0e98beb1381907898a3600c23469f95dbaa71317f86b9334283c16ac775bbce32a36a7938983f6753ea3c7b7747989f821bb13f64de416d63270c8055846a63cdce71bb4649ee53c5556a828b73cf4e9cadaa1e5199304aca064b4203783cc283c61688646cb3890ae198c8eebee7b22232545fe9686356c9ceae2e7204189c1680d5723a48e467ea10df7f482118157b3f0207c87091bee99190c918cb286a2dc781fa5098aa17e29a180e0ee1a648c830f5ff98801837b6dbb820b3adc7f8dd1eed4be5495921506089e1f524a6585c692cca34dcf48b2abba5750877a5b3b93f7eb43b776564cde82b9b0b2f19324e1c4794bba37378cbfbcaa5dc82010a8497f92b06f3f9ba687f8910ec8b686d72b8eb0580ccc827efea39ad92be5e7c2e5f7c024710b9305396e858fa95b428175b3121abee5e2c244702c100946ef51b73196eb5bd540e3fa4519470f57db198a12bbea5c4c6261899e0f0207b4bad1cde4ea5cf7f331c35f3e0d0c3b114f70fa3d31dc0bec1806690ec9b7dd288528ac4369bf27e13eaa8ad58bdfbe46f9dde5f80537b0adea3baa040761e0c8529cc5e0688f097eac7c462391fac9fc16be539275f80596b7f43d77bacb15f7e1a216fde7ae4cfb7dfe4f894a284756397f6f075746a6ccc0f51ce39607790728f1da86573abc43fc6f1c996f28dbde5c3f2d113feea21d46c0be804fd98e650630c5e619d493b410d1ff88e2967116ff060c62c0ac8dae797e79867d49db1709a218b4f9792037d15b707e140d5170b997085bdf5b7c3fb2501c47e0e33b86b5276a955a9be97d96eef68dd78a687018a570c31158343b60e1c01a6603f06184eab149c4f30463d5ec978961436c00127578e1fce3c88a2759ff76ea8568f8f57aa7a1d1bb5f026257a931c63d306720a6e3c03ab7a43eb7701a53dbe3266483d5c500ac69d696ea3f92532cbf9ed4b21d7766c681230d2b4de0fa44c97e9524521fbc19bbc33d26660ec906a5ba911a04c85bfc7e3581671ae831716a6ad017a18dc72afbd5ec4b610213d71919fb5fdbe1fb03de44d7319588292bfbda618039b74cb64879439b6f613e613ef3f3f2893f25e0a1d616307d8c82941c73f1a4d0f4e021144120c3808717a6d094409cd034e458464968ea7d15c7ce9c87adac4d8ef39f97d1d28c91d2d6f793d4ceab96ebe3e115d2200a55aba0eaa0ab7919622502748097cfe2e8d951282eba7739af7861a2d0bf86e1d39032638c2953c3f86c39056def5b9061c8840594e1aa796a2dbabb90a041c4a7c7d641d0841fb9d8d77aab958ce421b2b6349aea3b017e0de881ea08b538f773dea155347459a5800262c3bd7554d08b8bed0680dbce061f90519824a7dc439075d780e3cd40bac648311b2360732cf2f0741130b163aefc9992fedba9bf27f5650975b7e16b9824bc4a8a0c5df15377b91a24f4f7f120d4cc2c45bcdf3038d8e71c0a7735d595088727d42c9c54157f07d6abdb72ac7013d74b27c7e10215e0631d1f20d8bc3277568c1e148945d7071785efaa7ae3ecda5ecde241b417934b1222af85f9daff717d05b774cae2f10ade8d375bb6aa7f25c5e5af022e114e5c6f579b0345c319516471dbc20891e25151a53fb4fde3ebcb534b9481ada2abaca8a868411b96d2e3008855a50d3630ba349f61aa409dc5299be9d2dfd1edc5e1cc1c378b4cbfeb2f56ac74ef6c8b258efc3fe4c13586ce1e61fe458b479caecf0176736f78d048adc0610cf8260a34edc23b15b14aeee69e8682e9bf6117e44646cb583795343973fd46fbd57193ffba4892c8148c93880f8a82cbae19893e3472fde3a38a1c433f90e5e809fa069746a2edc1c5084fd95d6483a509ae046efdb1784115ab8a4efddb0247fdb32c6418f33b36381b37981472596a62ecbbdb5f304280ca0bfb1da42715165b845087f5897360a378eb643e965da68e8bfa607e8c72a9aa4c5b7b7406e6faf022f291d57415272f44e1934e35bcb8242bf20ef8192041c661aa3079bff2e3665439337d82a03c3d10c62dbdc6e19d28c6178cdb5b1e3f0c235affea2c106a6aafb4d59f33f44af103866f6491f87d34754e5eb5c05fcc0e15f87e3a57676c34e7d7fe7754060b5519f13b75677cf1ad3aebb1fbc3040b99d004c6be18321875a483c99a7ae1b69339134221f5e84fb10d6807de5b9ec63d6d31138a714e3f4002e914ca22787dbf71903bd391290990e63e970d1e23d18f05c316218f7fa6057ddaf75e71c2a9f2795a87e88fd9def1bcdb22c92169f318a4b35b545efc65c85340329479553778bb2bd0e9d16cd2f68cbd286f1194eb95780ef4eb656a8943e2a1796755384d1c57bd6f52c02eaedbf338d2f5f2943500ec7658eada54d1426a02fa257d08cabcaa4e858f47a233977ee884469f322535180f37aac27e56670ab8216a68927af6b6a380c4d0db12987cfd1144f7cef88fb51cd7d3d66cbb85c557a0b05a0014caf100c4d286ece91ad69284a720bc4726ebebd43bfdbc21fee46aa6e59a25ae4c36952d62a8eb11ea62696495b6b26c0353254399cd69d7bb3c33f7031d4060fbc33b507589b7d987ddb1b9154195e7f58fba3efc359e21309a1a2c594933d41c7eec619ca4783e081d61213d2ac9fa3f27b2cd842e8baf5085bc966b5cea7d7fac2cc2e6d729aa7f519274a4925df8c195ff6b60cfb976ccfc2404cb5dd359f3e5526b586e0b743847509e2be0964df9a7a6ba4a55082b62085751c63029cc5137848aca4344b7bdfd45622a67fed3d6b8c7f2aca55dfdb8e705dd0ebaffd59e217c4dce07690ce2626a36aedd123dc751311886abcacc358b0dd2855a1ffd3d71486a0c908e91e678d44fb9d09cc67674217a84c469523d540a1007475cfa57ed19a99b1c9be4e81571450104da31d2a6368059721256c19e3809988a01a46f89c389d4914a9e4c0a9be8b863e94e75f44276a8dcf5ebc05fdc280d1c4cea01e6cb2fa578264c5c1b4c15ef5d54cda42044ab7acebceee28be7fc9c1fe05d335269d3c26d7d3dbcb98c9bf2092327ebb0c0b63434176aad68655d961d0f1c6a52d0d3fd8ad9495c0b933122ee2e625fb7fb74fad71511f1123faf10ed8989c7532e8e4a2434f9e83e2a21722f2341700593d9e8c7a90c0bfd30dadc809e768f0288b1c41977538a761075eea3a5954eac1668b33991acef83dbd28be62b2e9484c084d9b55aa5bf6e5d02c519901fe9b3ca33446161d1fce972f9cdc29b5870c4fab1c126f801d125d951af3a6d92126725c36c197303efa037dcae947fd1e77626fb503585abd2beaf7d00668391598c60965f414dd064a4aa4b43b977b44076b914fd94c50fc253e48348ca6472d6edbb062d629a2430c6c131b0140ca1043a4da75365e0a6514cf07db34e8be4b1589602a12c44397aefb18fb8326a1feb27013540eb0e9e485f227a9e2b0505ac2490cc089cab09e47637ed7a56c34ae14b18981873161e2e52347dd9dae8c8b07a21b3bdd6d3847fa5d4957d5dada2ed9dc779b11272295e9d71d46c3a79600c8e6ee9807d8f4450ae7adcd2c2fd997ba0186ed7bfadc9f43f2207b2223424d63a3f0adae1e0bdad16bf2433eee6e1566e3e957689181fce414c9d61cb96721137b7a6561f24b1e9d602e70caf0f0bb48fb4f3cbd62655655ad6e5b9c0d14722198eada71a01bb36df9135d81f64c002a2f76d27edd3334938f4641cdf7fed2961f03dd967e70363cd63ebcba5c4bc5fef975723c947823aa20cc3368a46de483abba71965bba14589568807b4f2fb6d74e26b94eccb914315d86af3a281df132d9ea91235d6cffe25872f97ea1607eb775435452ee80825308c274acf23686b25f79367d561f9aa154fd09cba381b1b1a4ee4213a14903d0b40c69fa1859853ad54fbadc87d2091c3fa08f27b56e4b2dd616c735ac7ec4fe3e09dca00245c5076141346edd09edc34ef32f53bacfb7804c98a2e0edbc8fbd8383253563056e6e948265d2096231cfe1c291e0042257599e97bc0ce73ae27f94bf18bb1455eb8caf8682c5c8215d8412c62cbe4ef66cbe39e676202c0c12994e2564e683f4d73cdd53bcf89becf1dbc32c127b838efb22313b163d169b8283c1e13253837d72385b3047096cc3722717ebb57b55b2e546f360bdd9f108e60f50756ee8a454c88ce0b41ace1bc3036ee611b236a56c156cd429b3dd8459922e2a9d0f9fb5decf5a77e8298e05319cfe7623d3c567027a2b9cd4af8487cb2459a92021e289ee974b21cef1165748e80ef9af8f909c070c054e394e7bc67c67fb43e9934f880030842a969081f63ab6386d05bf38e4b05a8690f2c865d0bfef110b1c90ddd045c759ab8866102935a6dcf6eb59001f91ef4ae63f939cf49f4c18ed3886397604eb3e38369f95012c35da2d61eb3884bc0fed039cf27d9267755fa48df85ff09c6a10bee794943bf6ed8e9b81545344a96bcb1624cc5e7a88d11695a948dbd2a492769ca69d18782528f2b242bc33544eb66d8787eda97eb3291f957377c28fc7e48e31cdd26de5a476df12adf76534b48ee7f3c332f801506692b527dfba2587f23460a1b0325dba96786ce7475beb7bddc8cfea14cdf628dbbdbaa98c88235b8625e61e6b0b4e9c13c9b239ab711230c5e561db0dbdcf7b7a458598e9b7be9d49e5efdf5c9bd8b65eb07e3d5844aff6c7a5d78ef98f02789dbf0ad1b2a17f6b62ba0fc7602e856b51440e04d8345f92077c47ed9c17592d166ae960d57159a4dcc48aa11c1b7efdbb8bc96c604ba7b132b1450f6c3c03c61a73d40a01ed8e59c3712e47fbcf87802ab452d3d1b31fb82cb6a961d88250cba46101b0c6c758b318004d8bf6d5b0bc58c2d927894cfe2a0e310e58a374436aa4cdb1db0dc0893fcb55e40a5da5dadc373be5b221c6c8ec862e64b7fdfe6a084db50477848b6a0be15c4bb0bbcee5032c29bec7a3534920aa237f76eed6cde04e68699f4acac95da428f916f37191685ff3997024e23b08a2798693e86c1434ab644f21225fd5eacdb6998ca92980d2ea605747cf8f23d3fa1e0f93bce0f57ad4894d7ddd1e137f414f9e011cfeb0af6713e2de9729b3f996ff8eaf5be7e9b9c50a743ff75222e6ed293b3903f350312c000a68f1717865aa1afdc91cd287d6e8ff655cbbe85bd8456d57e5815276ba0e87899332f6ade8e05463f6addc8f669125c0e3a1a1f8e711c83f1f71f1b80798ab4c6ab0d66937fdfe3fd128eb650cc5360b6f610f51d9584667adeda4a07934c22f9d13928c992cdee2e687f00d502bebc9de022263230d4506094c29e54786d94668dad924c5d70781080f3647c619c1d2f7937607eb9746da0c8f570be6e300ab15d29f198fbb3bb0d6c07234ba87e5671132a4ba2f86d44768f1ce008b03be024696570454c2b179dc74aa79f7659f982701f51716185acfcfd61a9b8be3416084c9b899f1381139a2cf03278c6d21bd7f56ca854a1f7d0df9aaaa83fd8387341fa10992e8dc4ef448f6c37eda86a198e420b01eb25b89fa5a64f588e697573ccda15bdf238e2cfc416493db147909694c44b25200a2e02bd4153337e0baaf3aa917f144005359b5db26cb1ece62821c21dc1a7b35fc78af4bfc97e920888ea26bab08b0849aad45d"}, {0xb8, 0x114, 0xdd31, "b16eeb60f7038047ebfab8111da8fd9a6a6de8bace599b8889a0d30238c3cc6149377ddcfe29088f2e95c449190062ca59f7d80d2b1a0a494ebb8e65bded4e5af360e8c9b4e7bf67da798e7fb91404dfb8c45576bc64e30183596c1f062f5b11e72359b69ada62114673b8a4b15b14987d1ae9693fae9f45cd0ab5f93064e1a31383d24607b778ff691d25191c327c3a610f655cedf3f61c2a8567f76e450af75cbad6287a"}, {0xa0, 0x84, 0x4, "06b2db73b5a706d6fd4d509ebb4db20631c2e0940153332285bd80065f8abe900319f77cbfeecfcfb2eef21fb4ae821398e92b9ce770c3ace7cfb0da344802540fa41cc2e846ed22ffdeb5e4406e105e1e282c736609b794276ac0f28289adca47e41c4bb4576116dd562615d89f8ec5808c618c033b48e44f4e35ae3996b8a3af5f5bc6342dca7d684524a5b9"}], 0x1540}}, {{0x0, 0x0, &(0x7f0000002d00)=[{0x0}, {&(0x7f0000000500)="226acf8138460f5927addeaaf62b34a6922c179cb17f8af591", 0x19}, {&(0x7f0000002ac0)}, {&(0x7f0000002bc0)="bdccb95daf8453c22707554e65be5b183b133fc338c5e90b9f4514e73a8ba5140509c41a8435297911543b7332f72c658490f294e0870bfc99483edc5116104800fd0285c0f458850667e9aa489fb230adb3f10798cd5945edda9f582a0105ffe8f36734ba414453eb187ccb0dab08f7bc931c8b3c04", 0x76}, {&(0x7f0000002c40)="35d87ef2196f5c82cc08e13166177048108f18f5e332c85ce071feed33a4bdb4a1123968c50d5dfe45041dae736ccf280013224dadb0e66a74185539d8b50e7840c9e33ad605aac28e96d63496f5c482e65e4f0115f9fba79c55ab2c3ead8b7b263e029c093fb5eda03e584105244b67076b32ea35311e7440434220ce828599e9e0a162ebfab4e3de53c04577da89f728143803fd55b88b966c4823", 0x9c}], 0x5}}, {{&(0x7f0000002d80)=@l2tp6={0xa, 0x0, 0x101, @mcast1, 0x1, 0x1}, 0x80, &(0x7f0000004180)=[{&(0x7f0000002e00)="79614c3369fbdb603b4c593abf42501d1067dc83e7f582ce1bcae4b4afec6e1534a60cfb311e7dc007c337ad1f54a76cefc15bab0c9bcea943c5aa0116d2043c7a8b6345402aaab7a1342b632548a3d8b5c62793c788b4c18beca5f4881d81f317089d8e742d47cc24c6b3341d2d700fc7c8c1326902f8f4f55d13d7ebade4e7751b0c456f7a5d3ab44ad292cf798a53a5a5df3fbae3e97833b8977143c38d9679a966a7e52557440ae2ff607f91f22f1b26234ffb573063805171c9c1ac1335ba6eb7827e1b968001e9ea1773ea344db2c0fb490131e98da729c0fb82e69c127c00f9775b76430c853d5eb4af110c830e4f838d1b650f37c879871d609f77968c4469179ca832ce32d19fec8020ccf874fd3736022d8bcf5097166cb5ef38bdc98524b37007f41344d9979d125e71c1d85bad624997dcd8d942d67671571a90778e067093472673be48ce6e1c9b072db68bdf9fb97221d71c26c51ef706cfaed54f0f6670199fc4098be9a7794912da781e6f8639bdcdf9fdd279a43bb6fac954b5a3618b9304fdf3de517a0ba6ef293b613488117c25663170deee1e0b7ed2f043dbb8bdadfd59d4b685a053742aa407c2baf6c0db09890d67c3705f6cc496ecd0c73689631c3ec07e9776e66f1f7f05e26fcba5ccc946666c5e036dacc3ea5c2a01c52d3b08ee3869b857d2b67d92d6fee658c65d8c3d082dd9b360dc4fb90f8a76c18fb86e4fedb519c676a2a59be1f44cd44986dd64eca712e22ea0ef4e7e0de617d8651886833376692dfb661246c0ae38eb730549ccd07003e5358e82762787f1007b4ce968a0b7806dd83f3fd449637950f8eaf83d79073fe1bbe9818f02bf499a94d25d23766185604723e015b2d2f75bf2e7bb8fed409993e75f46808519a1a4b67dd5bc347f99f9e223e98bb060b0fc5a3d47c29de0674c10e36ab49fa674b2bb34c79a5dd30437c1e4349917d7a240726e884679aa0dbed46741ada4502f2307a82e50c09be19ed07b8c5fae0231388157129bd3558323ca57959b1128de4502067d9139fe2d7df7ff68903b69bba817b43ca7cfdbfb1a5f4cf73c3ca5cc7e1da29720078e5844520b6be033d97118c01befa05f7edb7289d75f0a9877caf0e006df4ed6be85cc63eea10f7a57e848c1f2c0b0442ff850ca0de21240380aae2f7f8a862a842015f2b99dd1f9b5a25610b31562f0bd1820e56ecc833e60002183c71dc9dc65885faeb45d7ec639c276266323f439e317749904ec65396542ff50062c94278b52f704a937a22ee76238808f561893aaf0f013729b789221f4f723cdfc90910cfc02533e99f6943e60e7d49351ed5f7bcb0a076fba83a87d48bce036781330212457d0afe05f1d2a8aecf101a500ca65d6979999d041020f8ec53c7f4bf0ec4d612913f393f6d099395b6a6937ee70271c39fbc9efac6bf32768a57189f22c702e70450453b9f63366a788a7affee378edc509e9f83ba76962d535ffdb6d38d5644b9209dd4279631c96b9266d4bacda2b31904d4acc103f852451b02b29689c01aecd5ce3e1f999fe673b6d88b860dde5fc65acc92748bb455bc55fa0ca7cb633bac5804fc0cf12aa86ffe7b3c4dcbf93284ffd326b64de11278fade7576ba31012dbab4bad147250b5049ad2fc042b718886871f5e291fe8de856af8f7cf1318c9305347e4dc0b71ede21b0b7597d0edb7ebd4cd9cb5ddd9f4ba31b6c74fe4dc132ee8856c56a0d93aa39bc66653c9b50cb6162f6679bece416ac6beda80635fb8bb832480a2b20ce8028342e9d1549a710d7da8329d444cf58f310395c2745fde1e2f6206830e3499d72db7039d3a2e03d887b1f70925576d4fb6f87099c417bd419548a63ed9a2e42c479aafc3bbf92ea227a4ee6a57a81f9d36b8a64ada572330f8dd8535cce89dd88d57fb0563b760fac4992087c5171c0ad38d8f46b8223708d18cfc01b9d30576b400ff485728bd92248be8379a038b8ddf358a83618cf617f10cacc34d27d31a4f5d2b8663f3da20bdbd8ce61e217f358f20fd812540634223591913cc76f9919acce8b5e733fd38fcd78545dc2df4b400e5e8db1f309b6b495393d678540058de26f0aa665975181a4dbfd2989f2941d030edf2a6c0b9b5edb85d4ddcf74fd1c0de51857154732b56fbb6a296aa30b6ff13d3f5cd57eeafa7733d71fe2c2088e11f63108d7e664ed9b30b84cbca14cf5041e724c191feb2b8e6ce219411486ff5b7c2d6705cb05711d74bb6cc9ede64783887fd24e50c22351e7588a4b21388d42528ce661452ec20a449795c358e0e6180846b33d3fc644d7d8f53ed6c9fc4b9d17108347e2c21000d3466648e0804522238d4ada2bac66f66044c5431bcb1fa2be264af921c4461bd1dec497178834579c6c88711c137039fb725e4865cecbd4781db6621a60f0b4ba1d459273b583265499ee9a1f87e87bda798f0632ddc67c4c1a76e487f989eb4b872e79fe3ad3f359193bb79342064c86231224ea3c414cc3418632f4641d54ce27d36bb7cb9c9b8ae659d3b84c6733ad8c213838c4cc174aba4e38443c37c43291b4af2e6513fa86e48eda1ac4ed44609ab5e066eaf96b795b0d9ce4815e21e608cf0d67b0f2dcf3826362917337b9279fdc3b5a062a66209db9796f28aca67bcb9d59a42458c6ae79c2d4533824f272857adf50dbcc5641dbe9936ab83164587b5aa5abc56bc2a6b351ff2bfc16aa74b0d0849bb509f01e5f3cddc45e26b5ed15cf573cef36aa175bcbcd2c31422e7f2e9d4e64a05db417e297fe80c85d024267c3d0190307a4d8e39fd9e29779c084c5ba85e9ef05931ada0c7a6341d0970f5419b7bf00c12f2482333655f71a54b770599bbb9320b6bbcf4869699f2def0ae8052a28433e5114d5a59c7726a9aef5faff32f4c1786b16d95989b73819df980b4ef08378c32a94fcad57ef08c161019a16f4a4ac5782f53d5a162b9c79c9318a24b87483edf83a93c70938435ce406c3c833fa73cee7f55a97aa9546d2f32340fa7f46b9f757a57d733864599fd07d8bae6f5222364f07a751b94930c355aabf422c1c55dfdac89df5098e9646ae4661cc6f3cab20d7f01db92cf49d198b55e18abe7ad348927fe0ad8dafe7b00e0e7750f08fca3189270dcd10ebee3b96b604f1e63f4ac865facb2fd7b4c5a03607813e8dcc64a01eb55c2b729bf2a84d06fb0eab163f01292065b43826ca3840ebc4973582deb37f457f7b64fa9c12ec237c076113effacd133440648cd9d9195159306af8f427a66ecb37bffd77db63bc3b8d62f887e7ccf5056379119fb3e449171171ce59f51f351be1355178e41ce82014152f889fb09c20f4ed6831d90fec53bf1ef4c5c0b149c0c6bb7d45a81b0bda3f700f970f49ce4f2e5ff70c8a807f4489334402d14211e3b5b7649c2dd272223accd4762ccd3396716c8e367533f0609fb91715c14935d62ae98adcb83ca7156f24202f78245a53705a902c56312b321ce4c495396930396a0cb64c9e3bc9abc0f514d890dff2f9e2104910d0ae1c20e452c1fba10a41d46e9a8ff629f8b15236ea53382746d2174b477eb29d1d0de77f9a60103f2f886d3378964d802556bb1bd424b988dacb113c97964cba821ac0ca7c1171a402afab22c12ce9ec1b711529596df0990089fe952a577738603976b17751fe2b02a7018fc6bae236b34862dec0829f7929916842372c6bcd9b9d31cbdfa8504f4b7fe49a5e7c8620e3f7f18dd7622316d586ef5d4dd226e49e15fb1d34418802262317c8e58810dc128bbe451cac072d764ecf3b94c025fd3f7c8926ef792bf9120a8dacad09080fb6be2519143cf51dfbecfcdf532cd7b0bef07f5969a7ff076d7ef20e05a1732f898215b1539ecbfceee6a361ce66462d0bc7780b23275b27988744b33b410c768b6d6e5d00b891c679a846eded20d694706a8dc16385741027549b344fd4884df30e9895ea7da8b2bf1035fae350565b8eacb7ababae6632afd888222885d1d360971cb6f9c6d9d79eddcf82e786dd2ff3acbfa2f5be0e1f5e6cb571311cffc44f5b4811c7b663174b685b49a690f3332287dfa861af360ece991cdd4cc33f47f117a4a2dfbfa31d527fc0491738459f723d385c86db89d97590ceaf5ab5bd9aa0c9a36e05cc3944f73b8690ea753bf52539ad301366a12662822ff48d1da442e56f809e467818dc9542ff7b14eee217fc0a7d340dd9fdb667ccb3a85ca8c4f2cc993fff68f0a748d5bc9d41f5022bf39ece0b58f566600e0ec29c6ac65a94189f3e0244efa944186b2f08b14161b63076ec0d17642679eafc4fc32068b9e9034b85d9a1e1930d987a7ac4e5c47c3ab969251b7d5a8fb701f2e88a42a12fee82253a6dacc0843f4635a9baa86b49568fff918b6f78e567e419733c5a12ddb0d5d145d399f63dd554e165a7fceff3ba1cc226dae271e7f592afb8abc3efe4211889dd93b3cd1b2800d9dfd5a463898dc152b1d210c45163a5bd0da2817601246110976681ca87749a537435e906c1ee1dc4178b2acff3e74bec08bb5d5bdcbbff3d88187db2a2efcac7dad46710e8eb3fd0272b504696b7645c79ed4de79b0fc60ffd98549630f0c34d5719f18a839d5308c7a66440e0f2dd6bfd7572da05ee3e8f4d1327f50c83e64cce0e312afc57c3852854e1be1ba26612f8dbb5ca49716cfe9c051144693475c7e92f265d407a9803caef3359e0aa6b076c88da87379bb44b8ed67f0c167c95f8964a48a8f74cfa499d4590c41bbbd7cd8a6ce5e977bfe1ed6dee8c281abbe18c6051298ae97221305f07471f7a4e0ca98c99f7d17831ad2b5accb5501aaaa4a2d5a38f24364fbfb531794f52235dd7d96201fe3a456cee586f68dbe79e28f2838c808a185321180dc04a6c3fd896c2f718f57705f6863d690c3952e1231b32a4475251fe4f0fde771d207a1ce8b1ae53d4a8212a5030dc4774da0b1fe9a409e41cc304863d3a7203385a2f20200a66540bf664a7381e4e2cbc25ac207a35fa08f28e6ff8060b03782c7d268ea622f6687cb29b4ecf3f4d2315c6ab59d6e847a90263e094ac517d776bc002fb421fac328b917bdf1233373133ba4833f1297027a4be8ddcb33b2a8256d7cbd57c247b5884f100a33d0fec384bd2254a18241706d64bae57afb826cdea7552a291f5b8214f80b9e363fcbdb70a00f8ea2d02b8777e625e640c21aac236c81745072c9d8d3d1854bf12b864ea22ee39c381699381940a7d3780c56c8fe3dee1c14f724275bfe69357d928f25de15a409a152d8828af05d56ac013585443eeab4ad6b5baeb500b32461f6799ac1ac0fd9544f99b8e39891bbab811939e29959e5c839f611786ae4905aa9e4b1979ca14a694ca5dea99f4fd269555d265b7d6f5a017b62202c45fda3cb3f5489b809a3fd96e60ead14cd3d3742a0f0f645e761d42113b44b186505b8b9472616b1fb06633ec055cf35c7d2bff6c754bfed7a7fb2936de957dad278893caf1ba77957edcd86952714966b62bfd0b0095049d3d9030ec7e470fd28c05f7d91ca6c2c30bc9bbe717cda14075ddfa5e0bf078963d5ad984981a150048f9960fb07d39a8b5d43db19d1523c775c14c0c0d01f22fc3b2557f59371dee79f3e4f772b2ca7e6ff6fc7d30fea2d6e9618cc9fa5951653879bad811d704c296e75dac6d4ea31", 0xfc0}, {&(0x7f0000003e00)="8cb4a6a6955265e293c827c65cc0ab7189b1cc4cf796e0e33b50656843e5995f6f62b1f61848ae688b61675a9b53ee0963e526958f9b114540dbaa1f82483c8756f20e797fc0d2f9eaede69d6f4cc0d730b6fcaee0bf204eb2c4833aadb4897672924175973c310b25946841292d6070bcb834a4932cc44f03d953d3432ee715c0", 0x81}, {&(0x7f0000003ec0)="ed38e25acc13a42c401649b50623cf5aa24d8290e5be8455dd4550dca7996500d599cc1939d2e30ad4fc11298e225524e3390ccd57987b163625e1296bd80995577210ae38f573f857b384e35f2831895b8e3ae4220fab95fc96f1da48a869e6707fd6f442684265dd1e8c6cc9ec7fbd2d44b789fb529108d6594601f2ac580507cb56bcb17052702cd4a559ede7635ca74877c7d80d63e8736c99ffc02269afe489528b65548948019cca619965732a61fdd808117012fff63d9d575509c3cf35df6e7b9b9e01069cf1a33d03b8133abe7d639d383e769fa7124a57be3e63117c1df763efa3bbc8220e88aa", 0xec}, {&(0x7f0000004080)}], 0x4, &(0x7f0000004200)=ANY=[@ANYBLOB="600000000000000011000000810000006b0824cc6afd82cc8b1dbb834887b929480c14e21463e236dcefe19a2af8f94f7969e65e071c7695fdbae53891b41ca4b71ecd3d8860cc8ca574163f247826f57db23804a3202ce22dccfa847e610000b000000000000000010100000500000073c3c1895401cc4832d2d744c5387f38b8c29262f663ed05440821825833e3b6ce539bcf1d86d628fb2601401a9b38b7bf9ca16017550506f104eb3804c948783ff95145f6713a70e4fae866863c9d0d9b791d075d80657ff47b9116f05eb99d840a838fff4727dcf675f946ca97c8130e2cc84def80cce185483d98ea828f2d3db59bc453e95958351c494363d38d4bcb0a5cb7e4d040db3d9546f468892d84"], 0x110}}], 0x3, 0x4000000) r5 = syz_init_net_socket$netrom(0x6, 0x5, 0x0) r6 = openat$fb0(0xffffffffffffff9c, &(0x7f0000000000), 0x180300, 0x0) ioctl$FBIOPUT_VSCREENINFO(r6, 0x4601, &(0x7f0000000040)={0x191, 0x258, 0x320, 0x3f, 0x8, 0x3, 0x0, 0x0, {}, {0xffffffff, 0x7}, {0x0, 0x0, 0x4}, {0x0, 0x0, 0xffffffff}, 0x0, 0x0, 0x0, 0x4, 0x0, 0x3, 0x6, 0x6, 0x0, 0x4, 0x0, 0x9, 0x4, 0x0, 0x3}) connect$netrom(r5, &(0x7f0000000300)={{0x6, @default, 0x1}, [@default, @default, @null, @null, @remote={0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0x1}, @null, @rose={0xbb, 0xbb, 0xbb, 0x1, 0x0}, @bcast]}, 0x48) unshare(0x26020480) getpeername$ax25(r4, &(0x7f0000000180)={{0x3, @null}, [@netrom, @null, @netrom, @bcast, @bcast, @null, @bcast, @default]}, &(0x7f0000000380)=0x48) 2m30.665566847s ago: executing program 2 (id=241): r0 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) r1 = openat$tun(0xffffffffffffff9c, &(0x7f0000000000), 0x400, 0x0) r2 = socket$inet6_mptcp(0xa, 0x1, 0x106) setsockopt$inet6_tcp_TLS_TX(r2, 0x6, 0x1, &(0x7f00000000c0)=@ccm_128={{0x304}, "7de081a3da3d21ed", "4768f28ca9b523293ee06f2e252623b8", "973b9369", "db0d0e94e4bd2162"}, 0x28) r3 = syz_init_net_socket$bt_hci(0x1f, 0x3, 0x1) bind$bt_hci(r3, &(0x7f0000000080)={0x1f, 0x1, 0x2}, 0x6) ioctl$TUNSETIFF(r1, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) ioctl$TUNSETCARRIER(r0, 0x400454e2, &(0x7f0000000300)=0x1) 2m30.489275029s ago: executing program 2 (id=243): mkdirat(0xffffffffffffff9c, &(0x7f0000000280)='./file0\x00', 0x10) r0 = openat$cgroup_ro(0xffffffffffffffff, &(0x7f00000003c0)='blkio.bfq.io_serviced\x00', 0x275a, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000140)='./file1\x00', 0x0) (async) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) (async) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000340), 0x0, &(0x7f0000000080)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) (async) socket$inet_tcp(0x2, 0x1, 0x0) (async) ioctl$SIOCRSGCAUSE(0xffffffffffffffff, 0x89e0, &(0x7f0000000000)) (async) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xc, &(0x7f00000000c0)={0x1, &(0x7f0000000100)=[{0x6, 0x6, 0x0, 0x7fff0006}]}) (async) mkdir(&(0x7f0000000000)='./cgroup/../file0\x00', 0x8) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) (async) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) (async) r1 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) (async) sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x6) (async, rerun: 32) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) (async, rerun: 32) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000380)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) (async) sendmmsg$unix(r3, &(0x7f0000000000), 0x400000000000041, 0x0) sched_setaffinity(r1, 0x8, &(0x7f0000000240)=0x2) (async) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) (async, rerun: 64) r4 = socket$inet6_tcp(0xa, 0x1, 0x0) (rerun: 64) setsockopt$inet6_tcp_TCP_MD5SIG(r4, 0x6, 0xe, &(0x7f00000010c0)={@in6={{0xa, 0x0, 0x0, @ipv4={'\x00', '\xff\xff', @multicast2}}}, 0x0, 0x0, 0x1b, 0x0, "61a1ed8439cde8054f2ada6fcd5fe76b933e8bb0ac60081e33dffa150835f7519d5f73b4f5d80eb4881a5b98cb9fb96d225d602392f816d0bdcc09b5063087117502d8c24f1fe97f61fd27a06d6a38a7"}, 0xd8) (async) fcntl$getownex(r3, 0x10, 0x0) (async, rerun: 32) sendto$inet6(r4, 0x0, 0x0, 0x20000841, &(0x7f0000b63fe4)={0xa, 0x2, 0x0, @empty}, 0x1c) (rerun: 32) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000280)={&(0x7f0000000140)=ANY=[@ANYBLOB="9feb01000b0000000000000030000000300000000900005460ee2c00bdc868f8a852e212bec7490d3e7490e28101a892d9cd4f160000000000000000000000360100000000000003329e872dfb"], 0x0, 0x51, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x20) (async, rerun: 64) socket$nl_netfilter(0x10, 0x3, 0xc) (async, rerun: 64) setsockopt$inet_sctp6_SCTP_PEER_ADDR_PARAMS(0xffffffffffffffff, 0x84, 0x9, &(0x7f0000000500)={0x0, @in6={{0xa, 0x4e20, 0x8, @private2={0xfc, 0x2, '\x00', 0x1}, 0x9}}, 0xa, 0xb130, 0x9f, 0xc, 0x0, 0x200, 0xc}, 0x9c) recvmsg$inet_nvme(r0, &(0x7f0000000480)={&(0x7f0000000400)=@xdp, 0x80, &(0x7f00000001c0)=[{&(0x7f00000011c0)=""/4096, 0x1000}, {&(0x7f00000005c0)=""/193, 0xc1}], 0x2}, 0x2020) (async) sendmsg$IPSET_CMD_CREATE(r3, &(0x7f0000001080)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000000000)=ANY=[@ANYBLOB="6c00000002060104db406e3e0004000200000000100003006269746d61703a706f72740005000400000000000900020073797a32000000000500050000006c00050001000600000024000780080008400009137906000440fffff0000600054000000000080006"], 0x6c}, 0x1, 0x0, 0x0, 0x1}, 0x0) (async, rerun: 64) openat$sysfs(0xffffffffffffff9c, &(0x7f0000000080)='/sys/power/resume', 0x149a82, 0x0) (rerun: 64) 2m30.337742081s ago: executing program 2 (id=245): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) socket$nl_netfilter(0x10, 0x3, 0xc) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000680)={0x18, 0x0, 0x0, 0x0, 0xfffffffe, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000300)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r0, 0x8914, &(0x7f0000000900)={'bridge0\x00', @remote}) bpf$PROG_LOAD(0x5, &(0x7f00000003c0)={0x11, 0x3, &(0x7f0000000540)=ANY=[@ANYBLOB="180000000002000000"], &(0x7f0000000200)='GPL\x00', 0xff, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x2c, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8, @void, @value}, 0x94) syz_open_dev$MSR(&(0x7f0000000080), 0x3, 0x0) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r1, 0x89a1, &(0x7f0000000900)={'bridge0\x00', @broadcast}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) socket$inet_mptcp(0x2, 0x1, 0x106) sched_setaffinity(0x0, 0x8, &(0x7f0000000200)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r2, &(0x7f0000002000)=""/102400, 0x19000) r3 = openat$nci(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) r4 = socket$kcm(0x29, 0x2, 0x0) r5 = bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x1, 0x5, &(0x7f0000001000)=ANY=[@ANYBLOB="bf16000000000000b70700000100f0ff5070000000000000300000000000c00095000000000000002ba728041598d6fbd30cb599e83d24bd8137a3aa81e0ed139a85d36bb3019d13bd2321af3c2bd67ce68f15c0ec71d0e6adfefcf1d8f7faf75e0f226bd917060000007142fa9ea4318123751c0a0e168c1886d0d4d35379bd223ec839bc16ee988e6e0dc8cedf3ceb9fbfbf9b0a49ef42d430f6296b72a83438810720a159cda90363db3d221e152dfca64057ff3c4744aeaccd3641110bec4e9027a0c8055bbfc3a96d2e8910c2c39e4babe802f5ab3e89cf6c662ed40000000022278d00031e5388ee5c867ddd58211d6ece3ccb0cd2b6d3cffd962867a3a2f624f992daa94a6a556f3218ce740068725c37074e468ee207d2f73902ebcfcf49822775985bf31b715f5888b24efa190000000000000000000000000000ddffffff020000000000000000ddffffff0000b27cf3d1848a54d7132be1bfb0adf9deab3323aa9fdfb52faf9cb09c3bfd09000000b91ab219ef00bb7b3de8f67ffcad3f6c3c2b1f03550000000000001cf41ab11f12fb1e0a494034007de7c6592df1a6c64d8f20a67745409e011f1264d43f153b3d34889f40159e800ea2474b540500a30b23bcee46762e2093bcc9eae5ee3e980026c96f80ee1a00000000740750fa4d9aaa705989b8e673e3296e52d337c56abf112874ec51d6fe048ba6866adebab53168770a71ad901ace383e41d277b103923a9d961f7a2591dbe4a912ffaf6f658f3f9cd16286744f83a83f138f8f92efd92239eafcc5c1b3f97a297c9e49a0c3300ef7b7fb5f09e0c8a868a353409e34d3e82279637599f35ad3f7ffffff3cac394c7bbdcd0e0eb52162e0c410ade7000026a4e739c60f03cc4146a77af02c1d4cefd4a2b94c0aed8477dfa8ceefb467f05c6977c78cdbf3f704ec73754910fe050038ec9e47de89298b7bf4d769ccc18eedd9068ca1457870eb30d219e23ccc8e06dddeb61799257ab5000013c86ba99523d61a00000000c270246c878d01160e6c07bf6cf8809c3a0d062357ba2515567230a6f8b2ad1e1f4933545fc3c741374211663f6b63b1dd044dd0a2768e825972fc4300001467c89fa0f82e8440105051e5510a33dcda5e4e202bd622549c4cffffff501d3a5dd7143fbf221fff161c12ca389cbe0000000000000fff2ecf631c6c5fd9c26a54d43fa050b88d1d43a8645bd9109b7e07869bba7131421c0f397073943330baafd243c0c6ffe673bab4113be7664e08bdd7115c61afcb718cf3c4680b2f6c7a8400e378a9b15bc20f49e298727340e87cdefb40e56e9cfad9931b8c552b2c7c503f3d0e7ab0e958adb8629aeec90e6d1857da822e40009995ae166deb9856291a43a6f7eb2e32cefbf463789eaf79b8d4c22be89f44b032dad13007b82e6044f643fc8cd07ae636a5dbe9864a117d27326850a7c3b570863f532c218b10af13d7be94987005088a83880ccab9c9920c2d2af8c5e13d52c83ac3fa7c3ae6c08384865b66d2204c2e4f3ae200f279b512b4dcb5dd9cba16b62040bf8702ae12c77e6e34991af603e3856a346cf708feeb708ab22b560cf8a4a6f31ba6d9b8cb0908000000000000001a342c010000000000e667a7592b33406f1f71c739b55db91d2309dc7ae401005f52053a39e7307c09ff3ac3e820b01c57dd74d4aafc4c383a17bc1de5347bb71ca16dcbbbaa2935ae662082b56cf666e63a759e0ef3ea7af6881513be94b362e15ffca8ec453b3a2a67be70c17b0f9c2eac765816c30c2e7133dca1c7669522e8dff8bc570a93fbdb688c3aef810000007a6ea6b11163392a19d87995b51cb6febd5f34a34998d2010fd5facf68c4f84e2f66e27c81a149d7b331983d3b74444953fc1216dfec10b724be3733c26f12538376e177ffef6fd2020000000000000008e4919a463d5332a2546032a3c06b94f168e8fc4bda0c294723fe306f26c477af4b926644672985fab7cc67bc5b5f5d38cdd8df95147ebe1cd88b0a4c6cde9951be10ba7dfddfefb238fac2303cc8982f1e55b005afcfea5eb037248fefad6bb02c162ce92ab17744c8ec3d2e80cf3205d36699fd381bc81231fb5e12e45f3059f361d08d6a6d019ebf105eaf43083c29512bcedd79ca9bf24e063d0c273ed70a2b70be521ea27dc8cf3c9bdf83b93405db07e82e2db484f8673e0e97dd7e8a872148613c3a04f3d67f4375ba5c7f1b00ffffff7f000000000801f71d79d812ced782646b5f79c8fc08bb5c11020108d702edd2ea9c96cf0d2d48aa5fc0a7bf1b51afd85350ad00b78c598fa8701b000884de790b54e5ab2e8ff0c7ae23e0b6eeac95c4c2eef2e5eb1d019d52099fbd404e8ece970f67856ba7e960bd8b1e4105ce7e31f7c9c3e3fa61aaa967b90087e91d703e98535b107b8f4653be4c46a3a1adb07d226952b8573b417018316fa96e2b8e7370baa16d4122c863709b08d4639a19a46ac90ac48a13ee9bcaa875fc700000000000003b40dc5c745fe2491e8425e600000000000000000000000000000000000000000000000000000000000000250318a44ad31baac0520a913301e630ae540f3289aebde8633f6f450c0738e16df6c7f1e0832a2a16fe6e39959735758248032cdf7320c6dc87b01e3f9a7811b200000000ae189de4b9b25f7c7a9c070000002af1c06315270de4a6605e4b4b58bef76fac54f11b84bd7bcd6b6a485edfb7684c770a39b38b08e18a51a4d4e66ca21c06a4b4198e1bc2ef990c9ba911efed626e5ee341a17bf8132b09000000d31df213c802d74797056fd3bca8b2d6cb134437cba0193ba4360bdcc98aad2560aa48291c4eb9d4e08ad7a9c5f04be1ab597124d84dfc7bd8cca8f68154a0ed356e773a797ca6d66748857b4abbf8830abeea2a46342e6a7378173cb29d5cdcd698a0203f78116b710008000000000000007c2d86b94472807c10eb9a8e2fb8bd79fe3a8316deff3ee641c9a080a2173642e673a672279bae4e7e28055da9497d7edb53be6e80482bd4d9a74b8dd4221fff0f0000705d7257ff7f76c78ba0b44ec0bdfa0d32d7042059b13a079639f14f9032b856d892ad6af5124c9c3130485e9682ff1f3c54e475d5bb496aef4bb537d7e191dfdeba109fdcf7864763f87a6d711cf52e520a6ce30e134c55e0caac037209d2f14fcddd00000000000000000000000000000000e609893bdce015e8ccfb36399844db61f6171b0b0e845e48728450c6ba4f7098f8e000676b59ab9f851f3ab77847ce05c89411277ec69c409b7ec50a3337a78675f38a568612c235ab5f2cd6d035d5f5f6a693c381adbbf7b37e37292783b2c7efe7d3a067906552f76d419e0300000000000000000000008f3a20b49fe7636806867283e35cff8d00e7b251bab3cf6377a24f8e8d4bda7503674bc94bf7f4d2fa6f25944bf0a186436d9f6831995976328a1fdc78492c65c1434855dc35c3cf7cf9610c5387794443c99b304799114132362849c3fa85d6379729ff9094933db0cfbe8887c50b87e1469fdf454cef4cbc5f7bf384000000000000a4e8c1a25f47c440144a9776be6cb40aafdb9d3cc8f6a6050974e1c4000000000000008b753f4e1bef9556efcc087a99db"], &(0x7f0000000140)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r6 = socket$kcm(0x2, 0x1, 0x0) sendmsg$kcm(r4, &(0x7f0000000600)={0x0, 0x0, 0x0}, 0x20000000) ioctl$sock_kcm_SIOCKCMATTACH(r4, 0x89e0, &(0x7f0000000400)={r6, r5}) r7 = syz_genetlink_get_family_id$nfc(&(0x7f0000000100), 0xffffffffffffffff) ioctl$IOCTL_GET_NCIDEV_IDX(r3, 0x0, &(0x7f00000000c0)) sendmsg$NFC_CMD_DEV_UP(0xffffffffffffffff, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000000)={0x14, r7, 0x1, 0x70bd26, 0x23c}, 0x14}}, 0x0) setsockopt$sock_int(0xffffffffffffffff, 0x1, 0xf, &(0x7f0000356ffc)=0xffffffffffffff40, 0x4) setsockopt$SO_ATTACH_FILTER(0xffffffffffffffff, 0x1, 0x33, &(0x7f00000a2000)={0x1, &(0x7f0000f07000)=[{0x6}]}, 0x10) listen(0xffffffffffffffff, 0x0) 2m28.617676641s ago: executing program 4 (id=250): socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) accept(r1, &(0x7f0000000080)=@rc={0x1f, @fixed}, &(0x7f0000000440)=0x80) ioctl$SIOCSIFHWADDR(r1, 0x89a1, &(0x7f0000000900)={'bridge0\x00', @broadcast}) ioctl$sock_SIOCGSKNS(r0, 0x894c, &(0x7f00000002c0)=0x2) openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000100)='blkio.bfq.time_recursive\x00', 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000054c0)={0x3, 0x16, &(0x7f0000000940)=ANY=[@ANYRESHEX=r1], &(0x7f0000000100)='GPL\x00', 0x3, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x2f, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) mmap$IORING_OFF_SQ_RING(&(0x7f0000400000/0xc00000)=nil, 0xc00000, 0x0, 0x110, 0xffffffffffffffff, 0x0) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020207025000000002dba513d7b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000008fd885000000040000"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x7, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000180)='kfree\x00', r2}, 0x10) creat(0x0, 0xecf86c37d53049e1) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000080)={0x24, 0x3c, 0x107, 0x70bd2c, 0x0, {0x3, 0x7c}, [@nested={0x4, 0xfc}, @nested={0xc, 0x1, 0x0, 0x1, [@typed={0x6, 0x6, 0x0, 0x0, @str='\x80\n'}]}]}, 0x11}, 0x1, 0x0, 0x0, 0xc000}, 0x400c801) prlimit64(0x0, 0xe, 0x0, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x3) sched_setaffinity(0x0, 0x8, &(0x7f00000000c0)=0xa) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r4 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r4, &(0x7f0000019680)=""/102392, 0x18ff8) add_key(&(0x7f0000000140)='encrypted\x00', &(0x7f0000000180), 0x0, 0x0, 0xfffffffffffffffe) socketpair$unix(0x1, 0x5, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000000)={0x16, 0x8, &(0x7f0000000dc0)=ANY=[@ANYBLOB="7a0af8ff7525787cbfa100000000000007010000f8ffffffb702000005000000bf130000000000008500000006000000b700000000000000950000ff00000000b2595285faa6ead0169191d54f8196217fc563e2fc91f6da4dad4fdc2eb1b5986fc4a3f611a7c80000040000000000b1a297cfddd73f30f2382f6cda4bfdd45be583823c0f092248a57d48621f3c1c65ee19ee875daf45006a4c4ea5e15b2f9618d547244a22000000000800db583620ce7243d1ae9f2cfe401dbef6619358399aa9c2acd068c03efefd8bc77edf2d34b12cd48a1b20fb7dd843267e0331759f4ec6b5b0af58e604f494eff289026d5045ef08000000000000007718a09f4800afc26abba34635d0e8b598a51bc742135a6e1d33fe226c944bc70bb30d435aa8b5202db761014b1b999a12df6bee431a6681000000263b6233e1c0fe30e384c3cb07b74a72291a1a2b523dd81b6651b1ee48bb004823ebcd8c65743f31f84b263ab9b3426692f01ad194f302d7a658e90000000001000000b6b2f25ddb8c640ab321a402058c9221b6870814cf4ee23ddb79fff5eb156e0a000000000000f2bd1d4a178d86d6935eb8b75bc4eb680d10e8b6ad4c6c8674caf63ff76622939a20d4aadf85db40179c2cf83ee07e30a279d8f9f3bc282deb43a03409f8e6972f3f720d045923702cede0f3e91411f3f1b16f065624f280a7dc938db910f93c49b9e0aa390d0da6972ed719d7e0efb2bb713d1890e317c8de105c3933fd5d5bf38f6b9fc39fc829dcfe4af8ac5f"], &(0x7f00000001c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = socket$rds(0x15, 0x5, 0x0) ppoll(&(0x7f00000001c0)=[{r5}], 0x1, 0x0, 0x0, 0x0) bind$rds(r5, &(0x7f0000000040)={0x2, 0x4e21, @local}, 0x10) fsconfig$FSCONFIG_SET_STRING(0xffffffffffffffff, 0x1, &(0x7f0000000680)='fuseblk\x00', &(0x7f0000000200)='fuseblk\x00', 0x0) close(0xffffffffffffffff) sendmsg$rds(r5, &(0x7f0000000080)={&(0x7f0000000180)={0x2, 0x4e22, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10, 0x0}, 0x0) setsockopt$RDS_CANCEL_SENT_TO(r5, 0x114, 0x1, &(0x7f0000000ec0)={0x2, 0x4e22, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10) 2m27.714308963s ago: executing program 0 (id=253): r0 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0) r1 = dup(r0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r2, &(0x7f0000000000/0x18000)=nil, 0x0, 0x0, 0x11, 0x0, 0x0) sendto$inet(0xffffffffffffffff, 0x0, 0x0, 0x4008880, 0x0, 0x0) ioctl$KVM_SET_SIGNAL_MASK(r2, 0x4004ae8b, &(0x7f0000000140)={0x6b, "7be0647acdbcd2dee20f53172378cdb6bbae8e440282ccd82995286fa6cebe3709325a31f9a7ff1f266ce87acd1dbc52ef7001e147eaee143de3f0fc41fad131859b7098079cfe3852ad828acaee9da4c72a37ce57f4b68babc9501723f827cc623bed012748f8d0026de7"}) socketpair$unix(0x1, 0x2, 0x0, 0x0) sendmmsg$unix(0xffffffffffffffff, 0x0, 0x0, 0x0) openat$binderfs(0xffffffffffffff9c, &(0x7f0000000100)='./binderfs2/custom1\x00', 0x800, 0x0) syz_emit_vhci(&(0x7f0000000000)=ANY=[@ANYBLOB="040e04004220"], 0x7) write$UHID_INPUT(0xffffffffffffffff, 0x0, 0x0) sendmsg$NFT_BATCH(0xffffffffffffffff, &(0x7f000000c2c0)={0x0, 0x0, &(0x7f0000000200)={0x0, 0x7c}}, 0x0) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000180)={0x1, &(0x7f0000000040)=[{0x200000000006, 0x0, 0x0, 0x7ffc0002}]}) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x13, &(0x7f0000000240)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020641700000000002020007b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000600000018010000696c6c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000400000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000bc0)={&(0x7f0000000040)='kmem_cache_free\x00', r3}, 0x10) getrandom(0x0, 0x0, 0x2) sendmsg$NFT_BATCH(0xffffffffffffffff, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000080)={0x0, 0xdc}}, 0x0) 2m27.465681354s ago: executing program 0 (id=254): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000001200)=ANY=[@ANYBLOB="18000000000000001100000051e200009500000000000000276ec41c32e518bca26ea967150eea8d70ae94c399b30c502b5a6fa70e61f89202e9e18609c4b4129a003b"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000040)='contention_end\x00', r0}, 0x10) write$UHID_INPUT(0xffffffffffffffff, &(0x7f0000000180)={0x8, {"d1347423facc5d1c40c9990badb12af40568dcf49f9a8810b8b798247df29281d071fae787e8ef6eb83481d5060be1bd1d5f4221ee4951277e25aac97f5e4b7765b0408038c6ba8f6fd9c57f3b4ffb6b2762c807cccd0d63c8b7b4e5c66e65bf436355d47d0b07e3afe376c4796d06d228507a9b36640ea5e90f393a5b251138781833fed0b6c3df77ffd6c4d0ce481977b27e84359a45d225231ce0ab05985b65c524dfaf90433e5dc08e663015d86270ce0b7b87a1d7fac3d02279d75b4928bf043317cadd8146b5e3dded47f5f74e7b0cb026dbeacb11eb7001a9e3a974e76e8ae491db04e5e060af7e956306168cb1afed82be4b2e66fc7a47117b49274747d23367c2d65f1b8d7a2b8c28e3b3115bbb90ec09f2add68bad5f9f125572d00249173c1046f043ee0aaadab9700cfc8910820cdd9ff89fbc21b37c708228104471e1b5414b87b3113d6e24d2b5b2515e4aa305cfe4aa0e30a75d682ededddcf5c5df45c1e113eeacba8104313959644fbc8c1813dac5c77314bd35981fdd95b3d46fc3f65e98b8b80c50064cd24e6d99a808cb7573755f97a4f1e771a362b41b2c1383603207c004fbf9e16db9f8fe71f9be9752c496be52bbaafd0722bb0013e33209d56557d5d3c3e76d4d3d2b4c27b0b800691291f31798fe0bf9efc57b83d5444dbcaae41f40ee4944d5b6c5b53ddf03fe6c81cf31809023765bdac31076e91864db9a73b654e7f53375a063ed3a3ca8aba998cddc9e5f9973e0ee8084388f5b8497fa33ff843dbceae13e8ef9e549252aa30d081c11951253f8d8e3b578b3ad02e2ea168c7c9e54f71a8755d7f83e0ad9a3fabb85e3c12a45f3beb48385d26d9dd22c00ead8c9b30a1959d3e345d1ba7ee049f1cba644defff7c3ba2ad549a3130103497efcf5e9c44079dcfaf4f6f55d0c488616de63d6cf659749b31dda2940923002e4395c232d376d0e8917e433e0506e96d078b9e1c050d3783b61c6ce3ba25aa745a2c97f246a0df5e4518d7e696de40b41e50dfe42935f76a4655aaf89b62df109f3ee5cced942083c2e015979e8017d0a435ccef44a6d122a7a61beb38fb0bf2cf20ff6538b343d33de81649f06b29536867760cd8fbec922f26d5373882bdf82bf7b4ce169d73cfb90e9b5366e630b1e6f86e79f935625fc84c9da002f89ed69cc902a755a0f65946466356c4d10501306c4afd04042cf9caa2ba5cdaf021549ff0f4e5329a6cf103e16be76907f038b983768c6608c29d52d5c0ecbc4d18de0d6511f976f03bf433a575680b3faa3069fb0725a46688a206cd6ac37a993fb98534c87a88517e8a8fdc1dff9243c3f328c96c5520c1549044ff729f4c1645d438afabd12f9a937c7f7eedfe11668211b595ffe174347a3a8b8c05175c8069dc44d35144a15e2cc0f4d6d2625fc2b8c89ade5d5ce723bf624694284baacefc181053d3e3cad426c832438f81177256f12e89c0cfe7647355017118a3a055e8869fa6de5ae0aba0bf0d3aa6dbc861a1ff61bbe8746d02f52c0d0d43671e153824c0db8cbbc56590b63dc87c84782ffbb6ef9ef0686501d1fdb7d7dcb1106c0c6a5fafcf82470a33009d953d64f657ddeb3a899822e41a92a089f9a9a5670c37e87c954214a05ee850e1f5387b2d8cdee9f75e8a4187053b838f7e759386bca861fa4f3a78de19c40825f77af4f316519df5a7e927b66399a6e7a6a5eb226252717fc40a1deabdff88ed50a760a3eb330038869f9b5d5b3d30c119b02e0e55fe61e1042243e912042989eae1e5ebd4e1c7b27230479e25f95eae977adb855ff10c5e6d0130d3b80c50e089c22d52943bf3a3ae6fd8f0f257ece4af2749b6c1f6b11db67c0770c6b2b86de957af81f10a06d76f9af780e805f704b823424e9782412e5788d6188d96c80c12a4e1e725e5dc6a9dbad152a688485c49b3b58f8412cad7ef04392bb8d51fe5de21dd2c49cf74c1d5bca87e339c522762cc65f7b45009e2ff57aeb067ea5bbf155d009b97ce1ee0eb0f4b5a02beb09d8fa54b63bc636ba2fa05dfe27d6e71d9f2c54a748bcdd8de453c3e7cfb039eaae05445f5146ae19eea8d1bc21364ad98439e1ee3229b1bf4e6506016ad5b526eae3d53adbcc930654a70169b895f70e64671cb5db886686ce829d6ba71c41ae6f4be6c7f2b8e770c8aecc8991ca0793abc970d2f595329d5cab231f22848415053290e33a87874a34f8f9f63847ed75bc29d48b038e3bc471da7e04bfaf14e447300a42febcd4eda28a44c45ada90acdd71a7314f7602d1f8bb46ff9d7ffdd5c246e5fb0e34df6303e7185a5897eca8bebdadb27d6754144a8aeeb9d9f0dd680fe81d22304c05f2b9020ad442ee2a98cde4e94c7a9a3c1c5db63c4b1b583e768f28c6b15d3cc8efa7d96d4a0eab8ec891a141d6b6f63530a93527ad1b47b2659a6a3d5a680f62d78adc78348affba123d8554aadd30f956b371d713654c3ee9731f9052b2b0b17a1470af0bf0f0e4d4797295ae08c96b09eef9c071bc71cdeef6bea0877f61a80a7975107f07e79fa0261f9a172c0c9841ee5a2a32c32b3882fd0a7c96f71cac2fddfd8acfff1b135a1f7b3ccf966b8b0fb32eadcfaa0c54ff11bf0abaebeaac4b0795180f240148b393668ec8911b38fb11a7042623f0c57a248b2afd30603ce8a20bc88180638d0571e51c0e3fce6f194a01762880d665369b335819d1e879307b0b01fb250577bbfe8ae03d33d0b97ceb697a1855a15f761a0108d3c59ead2194ea18c42487d900a0de473910bb0271cb54ee98b293305263ccf93a18e2a4b320ecc8e23b6d450f48b83d01f75f5b7f3354635b6e5022313f04e4cfefddcf284c2e5dde920a07303f442949ce949fbf2b08264f36dcfabdcece29d1743f839aa94cf7e747a48e6d1a4a65e9445def8c5e3d5ddf3040d24da56a7eec5edb2687eabf174b690d05bdbcdff9aec0a8dcfb94e4fff5a5b441fe3ef5b6189b2971dfb7b4976564a11bb8672d74e54251707acea501c02b66b0b7fe792e8180788b00aade3195f12b837144945e1f9263fd9894c52bea060578933702c85796c618a31243f7af6f6d4c22606fbe5ca70dadea0afa10c0ab3ae9beec09cddffa07be5b072f2dd5f3e54e3de8c232584ac76fa5dcdaeab544225c9c4786d9566eef1f0659e3ae462f9f3bef10117f77a26cf6ef3d0fa6a1d218d555f866da6e4efd5215813d28a54a98e8ef1529515f6a2bfa2cdf88797837d181965905f6878597834699995335fac5a58b5e10a4dfc8a96f2dcfd0fa122ffa0929d858a5cdf8a6347968d672e7dfea5210d2fa145c1d5731d9f8c1d37c97a8f779dc4c31ab5e7123f06c44f0efe58989bb70d4a3bfe2063360d9772653d7328f117607b5f447ea5beaf0df2408a8cb06d6d698915b8d19b9795bd411f4c129ad817bc02b563b3f92da951f952a05195f980e74d15ec221d5ccd1bf13a1bcc36d5de16b29a9465359b580230a34c2f3ed7c247ad15ffa3203d0020b5651c6b85f72c912c063b886b012b1a45c6a19d228cd8164951825de096a07d00b2e1d95d6d622682b515f1b9c72fb3f0acba749d4d4e0d8a30e3f07793d7efc567e47a90f03f01efc16fe174c8e16f84d9eff10d12175a13f064288094e9a873106c82b170858574bbcc16c5d901997b2357f750952e1155a9c2d542668cdcc31e038011b9214b7ca033aec807e07559f65879ed836be06950040fe314ff9939426ccdf47578999a517fe66a1dcadd05f6ef7659faa5cdbf0f9513677b9284dbe54497b18ac415585ef36b4a0a33972207a02c7e76960756eecff183a27be94143adf47179d8dc58c6d8834018d8169257743d77cd48a56516cfab7ce275a81e3359b72aaecf653fc52d88532adae33a1477c492aa307273252c7b61e44d7dc8e6270926560cf4abb2bdf3e821badfe807b9c69b73646e1c5d25e0d06a66c0b00b5069008c0ddaeb89d15fe63816dacd2496395e7f7c6237647dd6ebc286801ae91c05bad19a84ff8aef6628e633249ce60a5041b271ad8ceed29b75c9b9fc039854e55cb01b8bc83a89a7f69a7a6f6717c7920f030bb6617342e3418600681ced7360835323cb58d1b98c344cae84cc88fec716ba5682e786dc16e9370ada8e38e68018f770302a9e8a086b0e08f9a359d3e9c8beba655b1a247688e98650cefb822fa40c4b69221cd5e2208a76cae84fac46802887230846f74bb95da04a7bdfcaad2e9f2db404a985756a1be077e8a8c01a149818487ae896b91ff8d82bf2863712acaa564337d6e925a90b4646d06947ccf2a74d4a1a97d4cb50a53dac0a03c3e09c699a1708a0c26b7c386c97640c2a8f30d2d3bae0db2d018ce658dc3fd9802c308b00a86872fcd8d806dccc46bc763e8292f7d3d681d8cffcc95333e78ebf67bda3e90452a2e08c52957daa98ce0cf2329abda5ccac2b013bde8a4fc75b8258824e14fb87c154b7ac22f58531fcde7082aabd47cbbd0a3a112df521a5391bb047ac4fdb3ea39da1efead0860de63037253708d5e9fd63dc6ee7eacc17b6d9f5a2ea0a27059ec8ec7e696ee05727756fb31ffca4c9261cb8f72023a00d551da0bc08c21174882d5159842aa6316b4624a7d46cecc399bcfce0fca0cc5d3d307194e8bd60a76e43e0b3539ffa23a2b2a58942b1bd21f7c86cd824f4878a7e6dc946db839610f31b24d428cbd0038e314badd51f0f3dc85c3f5df1d08adacdb3553df04803700e53802c67d992e0b7ae12c660fd83cd84fe5ebd2584a5b27db59c948f9793868475b0e1b7a94b4b91555aeb2211f5518883c0f6c9662da5e9271d8e4075a92fae0c013952a947646d84e0d80ea05c6ff5a8308a32b3106e5e0299521d3facc2ab23331054429207bf895d62c949dcca014f136b99d6d42e62cb8ce740c2d10073956a66e95751d3df58e8f8be906baa58720a728ec17bcdca87f8c2e6eb458672b24105a5b4f028fc1c245b129ba99850af1688646eb8df27eb6f1c2804878b5da2280ae9f65416311709304f5e088acbd4ccca49b46ef5a5c256b1c4abd3ca07d9f8f74eefecd736b4fdf1cdfe9bdd084ed472746337afce3b6feadb9923a8b34db65b4e69c933aad7d7fd5648b2ec16c773890483dc2917ca4acd2cb4356aa6ba9769f37c550f0a3ab843d1d9b22b6b4fc6662f63b35f0f81f1b475491aa613f40ff96360ca29d07857f061fb66745caf98f7922ee920f499b56bd8a708df5cce704766ff09dcd49c952c49e1062e9b7b1ffc73982a20c71747015bcdac7fba9da1b8d9447f923b550e27a4e68f8d3b74c138e1291ead6637db271daa182cff002e3d78040378ac4b1aa3802ea70290bcd36efac75a2944ac63d0aaedca5d35f29ef168fa6c9f1f6f00a624fdee74ef2a110fe5b61e0af026b9e33a76639753b85326292a1b866b158576ae797509d6b0d1292afeed41e4d770f6b3df73140a699868ad2aa492f5f2d33447c86cbd65b02ea2fc0ac6f6741c6cb0aab6e0213ff77ad7290eb77edbcd538d7ee9d62d231382cc6e8af6d37cc37193c777faa5468023ef21ff6741905b3fd6d37476e2f2535201d9ee4b87ed35b65838757b74d7eccc00c1351fa0cf076026695c749dcdbb8ba5cc0cb17792712124b3ed779a945c5cd795ced3bb7611f26913512f34f38b946b1f06fa68c948d34ead4e162d893cae23e2389d8c22570fe9c76a0a1dc53f8a50f08872517b459d27e32ce15225c3dd27b19cdf09a2921f2d2a77b7db9c595e38d84d18cf5aac564168f", 0x1000}}, 0x1006) r1 = syz_usb_connect(0x0, 0x36, &(0x7f0000000bc0)=ANY=[@ANYBLOB="12010000ffd26f10cb060600eb9a0102030109022400010000000009040001020a16d100090507000000000000090589"], 0x0) sendmsg$IPCTNL_MSG_EXP_NEW(0xffffffffffffffff, &(0x7f0000000100)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000280)=ANY=[@ANYBLOB="b00000000002010400000000000000000700000608000940ffffffff0800044000000081080008400000000320000180"], 0xb0}, 0x1, 0x0, 0x0, 0x8004}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r2, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000280)=ANY=[@ANYBLOB="440000003e000701feffffff00000000017c0000040042800c00018006000600800a0000200002801c00178018"], 0x44}, 0x1, 0x0, 0x0, 0x40040c0}, 0xc000) syz_usb_control_io$printer(r1, 0x0, 0x0) r3 = openat$mice(0xffffff9c, &(0x7f0000000040), 0x105040) ioctl$DRM_IOCTL_MODE_CREATE_LEASE(0xffffffffffffffff, 0xc01864c6, &(0x7f0000000000)={0x0, 0xfffffe26, 0x80800}) r4 = ioctl$KVM_CREATE_VM(r3, 0xae01, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r4, 0x4020ae46, &(0x7f0000000080)={0x10004, 0x0, 0xffff1000, 0x1000, &(0x7f0000ffe000/0x1000)=nil}) bpf$MAP_CREATE(0x0, &(0x7f0000000140)=ANY=[@ANYBLOB="15c2533000"], 0x50) pwrite64(0xffffffffffffffff, &(0x7f0000000000)=':', 0x1, 0x4fed0) r5 = syz_init_net_socket$bt_hci(0x1f, 0x3, 0x1) bind$bt_hci(r5, &(0x7f0000000100)={0x1f, 0xffff, 0x3}, 0x6) write$binfmt_misc(r5, &(0x7f0000000000), 0xd) setsockopt$IPT_SO_SET_REPLACE(r3, 0x0, 0x40, &(0x7f0000001480)=@security={'security\x00', 0xe, 0x4, 0x418, 0xffffffff, 0x228, 0x228, 0x228, 0xffffffff, 0xffffffff, 0x380, 0x380, 0x380, 0xffffffff, 0x4, &(0x7f00000011c0), {[{{@ip={@dev={0xac, 0x14, 0x14, 0x39}, @local, 0xffffff00, 0x0, 'erspan0\x00', 'syzkaller1\x00', {0xff}, {0xff}, 0x1, 0x2}, 0x0, 0x90, 0xd0, 0x0, {}, [@common=@socket0={{0x20}}]}, @common=@inet=@LOG={0x40, 'LOG\x00', 0x0, {0x9, 0x8, "c82f5f2ebe892e1e6900d0e9da8d34133fb51c210eb5af72424b3e69606b"}}}, {{@ip={@multicast2, @local, 0xff, 0xffffff00, 'macsec0\x00', 'bridge_slave_0\x00', {}, {0xff}, 0x6c, 0x1, 0x30}, 0x0, 0xf8, 0x158, 0x0, {}, [@common=@unspec=@connbytes={{0x38}, {[{0x4}, {0x3}], 0x2, 0x2}}, @common=@osf={{0x50}, {'syz1\x00', 0x0, 0xd, 0x0, 0x2}}]}, @common=@SET={0x60, 'SET\x00', 0x0, {{0x0, [0x4, 0x4, 0x0, 0x6, 0x1, 0x2], 0x4, 0x3}, {0xffffffffffffffff, [0x3, 0x5, 0x2, 0x3, 0x1, 0x2], 0x5, 0x5}}}}, {{@uncond, 0x0, 0xf8, 0x158, 0x0, {}, [@common=@unspec=@nfacct={{0x48}, {'syz1\x00'}}, @common=@set={{0x40}, {{0x1, [0x3, 0x4, 0x3, 0x4, 0x2, 0x1], 0x4, 0x1}}}]}, @common=@CLUSTERIP={0x60, 'CLUSTERIP\x00', 0x0, {0x1, @empty, 0x3, 0x10, [0x37, 0x22, 0x22, 0x1a, 0x2d, 0x3d, 0x24, 0x35, 0x1b, 0x3f, 0x33, 0x30, 0x32, 0x27, 0x36, 0x1a], 0x2, 0xfffffffc, 0xebd}}}], {{'\x00', 0x0, 0x70, 0x98}, {0x28}}}}, 0x478) 2m26.261527706s ago: executing program 4 (id=255): mkdir(0x0, 0x0) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) mkdir(&(0x7f0000000100)='./file1\x00', 0xc) mount$overlay(0x0, 0x0, &(0x7f0000000340), 0x0, &(0x7f0000000080)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}, {@verity_require}]}) chdir(&(0x7f0000000140)='./bus\x00') ioctl$VFAT_IOCTL_READDIR_BOTH(0xffffffffffffffff, 0x82307201, &(0x7f0000000700)=[{0x0, 0x0, 0x100}, {0x0, 0x0, 0x100}]) r0 = socket$alg(0x26, 0x5, 0x0) syz_clone(0x80842111, 0x0, 0x0, 0x0, 0x0, 0x0) pipe(&(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) io_setup(0x3ff, &(0x7f0000000500)=0x0) io_submit(r3, 0x2, &(0x7f0000000300)=[&(0x7f0000000000)={0x0, 0x0, 0x0, 0x0, 0x0, r1, 0x0, 0x4e}, &(0x7f0000000080)={0x0, 0x0, 0x0, 0x4, 0x6, r2, &(0x7f00000001c0)='m', 0x1, 0x1}]) mprotect(&(0x7f0000000000/0x4000)=nil, 0x4000, 0x1) ioctl$AUTOFS_DEV_IOCTL_SETPIPEFD(0xffffffffffffffff, 0xc0189378, &(0x7f0000000240)={{0x1, 0x1, 0x18, 0xffffffffffffffff, {r0}}, './file1\x00'}) accept4(r0, 0x0, 0x0, 0x0) r4 = syz_io_uring_setup(0x9e, &(0x7f0000000000)={0x0, 0x5867, 0x10, 0xfffffffc, 0x24d}, &(0x7f00000006c0)=0x0, &(0x7f00000001c0)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r5, 0x4, &(0x7f00000002c0)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r5, r6, &(0x7f0000000200)=@IORING_OP_READV=@pass_iovec={0x1, 0x0, 0x4007, @fd_index=0x4, 0x0, 0x0, 0x0, 0xd, 0x1}) io_uring_enter(r4, 0x100847c0, 0x0, 0x1, 0x0, 0x0) write$binfmt_script(0xffffffffffffffff, &(0x7f0000000040), 0x4) lchown(&(0x7f0000000000)='./file0\x00', 0x0, 0x0) ioctl$VIDIOC_ENUM_FREQ_BANDS(0xffffffffffffffff, 0xc0405665, &(0x7f0000000180)={0x2, 0x3, 0x5, 0x2, 0x3, 0x7}) 2m25.915144472s ago: executing program 0 (id=257): r0 = syz_open_dev$vim2m(&(0x7f0000000000), 0x800, 0x2) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f0000000300)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x11, 0x8, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) writev(0xffffffffffffffff, &(0x7f00000000c0)=[{&(0x7f0000000080), 0xfffffebe}], 0x1) open_by_handle_at(0xffffffffffffffff, 0x0, 0x1) r4 = syz_init_net_socket$netrom(0x6, 0x5, 0x0) connect$netrom(r4, &(0x7f0000000300)={{0x6, @default, 0x1}, [@default, @default, @null, @null, @remote={0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0x1}, @null, @rose={0xbb, 0xbb, 0xbb, 0x1, 0x0}, @bcast]}, 0x48) unshare(0x26020480) ioctl$vim2m_VIDIOC_S_FMT(r0, 0xc0d05605, &(0x7f0000000200)={0x2, @vbi={0x9, 0x7, 0x80000000, 0x34524742, [0x1001, 0x7], [0x9, 0xfff], 0x108}}) r5 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r5, &(0x7f0000000600)={0x0, 0x0, &(0x7f0000000040)=[{&(0x7f0000000000)="2e00000010008188e6b62aa73772cc9f1ba1f848100000005e140602000000000e0021000f000000028000001294", 0x2e}], 0x1}, 0x0) 2m25.914547272s ago: executing program 4 (id=258): r0 = syz_open_dev$sndctrl(&(0x7f0000001440), 0x0, 0x0) ioctl$SNDRV_CTL_IOCTL_PCM_PREFER_SUBDEVICE(r0, 0x40045532, &(0x7f0000000200)) r1 = openat$audio(0xffffffffffffff9c, &(0x7f0000000100), 0x80002, 0x0) r2 = syz_open_dev$sndpcmp(&(0x7f0000000000), 0x1ff, 0xa2c25) ioctl$SNDCTL_DSP_CHANNELS(r1, 0xc0045006, &(0x7f0000000340)=0xe) writev(r2, &(0x7f00000001c0)=[{&(0x7f0000000240)='x', 0x1}], 0x1) 2m25.169898839s ago: executing program 4 (id=260): madvise(&(0x7f0000000000/0x3000)=nil, 0x7fffffffffffffff, 0x3) (fail_nth: 1) 2m25.138507213s ago: executing program 4 (id=261): socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) accept(r1, &(0x7f0000000080)=@rc={0x1f, @fixed}, &(0x7f0000000440)=0x80) ioctl$SIOCSIFHWADDR(r1, 0x89a1, &(0x7f0000000900)={'bridge0\x00', @broadcast}) ioctl$sock_SIOCGSKNS(r0, 0x894c, &(0x7f00000002c0)=0x2) openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000100)='blkio.bfq.time_recursive\x00', 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000054c0)={0x3, 0x16, &(0x7f0000000940)=ANY=[@ANYRESHEX=r1], &(0x7f0000000100)='GPL\x00', 0x3, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x2f, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) mmap$IORING_OFF_SQ_RING(&(0x7f0000400000/0xc00000)=nil, 0xc00000, 0x0, 0x110, 0xffffffffffffffff, 0x0) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020207025000000002dba513d7b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000008fd885000000040000"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x7, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000180)='kfree\x00', r2}, 0x10) creat(0x0, 0xecf86c37d53049e1) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000080)={0x24, 0x3c, 0x107, 0x70bd2c, 0x0, {0x3, 0x7c}, [@nested={0x4, 0xfc}, @nested={0xc, 0x1, 0x0, 0x1, [@typed={0x6, 0x6, 0x0, 0x0, @str='\x80\n'}]}]}, 0x11}, 0x1, 0x0, 0x0, 0xc000}, 0x400c801) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, 0x0) sched_setaffinity(0x0, 0x8, &(0x7f00000000c0)=0xa) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r4 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r4, &(0x7f0000019680)=""/102392, 0x18ff8) add_key(&(0x7f0000000140)='encrypted\x00', &(0x7f0000000180), 0x0, 0x0, 0xfffffffffffffffe) socketpair$unix(0x1, 0x5, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000000)={0x16, 0x8, &(0x7f0000000dc0)=ANY=[@ANYBLOB="7a0af8ff7525787cbfa100000000000007010000f8ffffffb702000005000000bf130000000000008500000006000000b700000000000000950000ff00000000b2595285faa6ead0169191d54f8196217fc563e2fc91f6da4dad4fdc2eb1b5986fc4a3f611a7c80000040000000000b1a297cfddd73f30f2382f6cda4bfdd45be583823c0f092248a57d48621f3c1c65ee19ee875daf45006a4c4ea5e15b2f9618d547244a22000000000800db583620ce7243d1ae9f2cfe401dbef6619358399aa9c2acd068c03efefd8bc77edf2d34b12cd48a1b20fb7dd843267e0331759f4ec6b5b0af58e604f494eff289026d5045ef08000000000000007718a09f4800afc26abba34635d0e8b598a51bc742135a6e1d33fe226c944bc70bb30d435aa8b5202db761014b1b999a12df6bee431a6681000000263b6233e1c0fe30e384c3cb07b74a72291a1a2b523dd81b6651b1ee48bb004823ebcd8c65743f31f84b263ab9b3426692f01ad194f302d7a658e90000000001000000b6b2f25ddb8c640ab321a402058c9221b6870814cf4ee23ddb79fff5eb156e0a000000000000f2bd1d4a178d86d6935eb8b75bc4eb680d10e8b6ad4c6c8674caf63ff76622939a20d4aadf85db40179c2cf83ee07e30a279d8f9f3bc282deb43a03409f8e6972f3f720d045923702cede0f3e91411f3f1b16f065624f280a7dc938db910f93c49b9e0aa390d0da6972ed719d7e0efb2bb713d1890e317c8de105c3933fd5d5bf38f6b9fc39fc829dcfe4af8ac5f"], &(0x7f00000001c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = socket$rds(0x15, 0x5, 0x0) ppoll(&(0x7f00000001c0)=[{r5}], 0x1, 0x0, 0x0, 0x0) bind$rds(r5, &(0x7f0000000040)={0x2, 0x4e21, @local}, 0x10) fsconfig$FSCONFIG_SET_STRING(0xffffffffffffffff, 0x1, &(0x7f0000000680)='fuseblk\x00', &(0x7f0000000200)='fuseblk\x00', 0x0) close(0xffffffffffffffff) sendmsg$rds(r5, &(0x7f0000000080)={&(0x7f0000000180)={0x2, 0x4e22, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10, 0x0}, 0x0) setsockopt$RDS_CANCEL_SENT_TO(r5, 0x114, 0x1, &(0x7f0000000ec0)={0x2, 0x4e22, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10) 2m24.896806909s ago: executing program 0 (id=264): r0 = creat(&(0x7f0000000000)='./file0\x00', 0x0) r1 = socket$inet6_tcp(0xa, 0x1, 0x0) close(r1) r2 = socket$inet6_mptcp(0xa, 0x1, 0x106) bind$inet6(r1, &(0x7f0000000040)={0xa, 0x4e22, 0x0, @empty}, 0x1c) listen(r2, 0x0) r3 = socket$inet_mptcp(0x2, 0x1, 0x106) socket$nl_route(0x10, 0x3, 0x0) connect$inet(r3, &(0x7f0000000000)={0x2, 0x4e22, @empty}, 0x10) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r4, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000600)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a01030000000000000000010000000900010073797a300000000040000000030a01080000000000000000010000000900030073797a32000000001400048008000240fffffffe08000140000000040900010073797a300000000014000000110001"], 0x88}, 0x1, 0x0, 0x0, 0x2000c045}, 0x24000004) socket$nl_netfilter(0x10, 0x3, 0xc) close_range(r0, 0xffffffffffffffff, 0x0) 2m24.716699964s ago: executing program 0 (id=266): r0 = socket$inet6(0xa, 0x5, 0x0) syz_usb_connect(0x1, 0x3d, &(0x7f00000001c0)=ANY=[@ANYBLOB="12010000bdce4208110f80106afc0000000109022b00010000000009043700022ee5cd0009058010ff037f790209050e0320000980070705ab0b78"], 0x0) syz_open_dev$char_usb(0xc, 0xb4, 0x0) pselect6(0x40, &(0x7f0000000100), 0x0, &(0x7f0000000240)={0x1f}, &(0x7f0000000280)={0x0, 0x3938700}, 0x0) setsockopt$sock_int(r0, 0x1, 0xf, &(0x7f0000fee000)=0x3fa, 0x4) listen(r0, 0x50) r1 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000040)={0x1, &(0x7f0000000000)=[{0x6, 0x0, 0x0, 0x7fff7ffc}]}) close_range(r1, 0xffffffffffffffff, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x0) mount$bind(&(0x7f0000000380)='./file0\x00', &(0x7f0000000200)='./file0\x00', 0x0, 0x2125099, 0x0) mount$bind(0x0, &(0x7f00000005c0)='./file0\x00', 0x0, 0x100000, 0x0) r2 = open_tree(0xffffffffffffff9c, &(0x7f0000000640)='\x00', 0x89901) move_mount(r2, &(0x7f0000000140)='.\x00', 0xffffffffffffff9c, &(0x7f0000000180)='./file0\x00', 0x0) mount$bind(&(0x7f0000000000)='./file0/../file0\x00', &(0x7f0000000340)='./file0/file0\x00', 0x0, 0x89101a, 0x0) mount$bind(0x0, &(0x7f0000000140)='./file0/file0\x00', 0x0, 0x80000, 0x0) mount$bind(&(0x7f0000000100)='./file0\x00', &(0x7f0000000280)='./file0/../file0\x00', 0x0, 0x1adc51, 0x0) move_mount(r2, &(0x7f0000000080)='./file0/file0\x00', r2, &(0x7f0000000040)='./file0/../file0\x00', 0x0) mount$bind(&(0x7f00000003c0)='./file0\x00', &(0x7f0000000440)='./file0\x00', 0x0, 0x12f451, 0x0) umount2(&(0x7f00000000c0)='./file0/file0\x00', 0x1) 2m23.683125372s ago: executing program 4 (id=270): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000100)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sendmmsg$unix(0xffffffffffffffff, 0x0, 0x0, 0x0) r3 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$TIOCSETD(r3, 0x5423, &(0x7f00000000c0)=0xf) r4 = fcntl$dupfd(r3, 0x0, r3) ioctl$TCFLSH(r4, 0x400455c8, 0x0) ioctl$TIOCSTI(r3, 0x5412, &(0x7f0000000080)=0x4) ioctl$TIOCSTI(r4, 0x5412, &(0x7f0000000040)=0x3f) 2m22.285994356s ago: executing program 0 (id=272): r0 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r0, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000200)=ANY=[@ANYBLOB="1400000038000107000000000000000008000000e2ccd84bd51aa87f1ed12a18e5c3e8c543da10e92f91b9b19a89f7db51df29470a77f99728453bbce63a9e191636504d14a5bd67b1f3b2f064c68991dc561f"], 0x14}, 0x1, 0x0, 0x0, 0x48010}, 0x4000000) 2m14.857870011s ago: executing program 32 (id=245): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) socket$nl_netfilter(0x10, 0x3, 0xc) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000680)={0x18, 0x0, 0x0, 0x0, 0xfffffffe, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000300)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r0, 0x8914, &(0x7f0000000900)={'bridge0\x00', @remote}) bpf$PROG_LOAD(0x5, &(0x7f00000003c0)={0x11, 0x3, &(0x7f0000000540)=ANY=[@ANYBLOB="180000000002000000"], &(0x7f0000000200)='GPL\x00', 0xff, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x2c, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8, @void, @value}, 0x94) syz_open_dev$MSR(&(0x7f0000000080), 0x3, 0x0) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r1, 0x89a1, &(0x7f0000000900)={'bridge0\x00', @broadcast}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) socket$inet_mptcp(0x2, 0x1, 0x106) sched_setaffinity(0x0, 0x8, &(0x7f0000000200)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r2, &(0x7f0000002000)=""/102400, 0x19000) r3 = openat$nci(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) r4 = socket$kcm(0x29, 0x2, 0x0) r5 = bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x1, 0x5, &(0x7f0000001000)=ANY=[@ANYBLOB="bf16000000000000b70700000100f0ff5070000000000000300000000000c00095000000000000002ba728041598d6fbd30cb599e83d24bd8137a3aa81e0ed139a85d36bb3019d13bd2321af3c2bd67ce68f15c0ec71d0e6adfefcf1d8f7faf75e0f226bd917060000007142fa9ea4318123751c0a0e168c1886d0d4d35379bd223ec839bc16ee988e6e0dc8cedf3ceb9fbfbf9b0a49ef42d430f6296b72a83438810720a159cda90363db3d221e152dfca64057ff3c4744aeaccd3641110bec4e9027a0c8055bbfc3a96d2e8910c2c39e4babe802f5ab3e89cf6c662ed40000000022278d00031e5388ee5c867ddd58211d6ece3ccb0cd2b6d3cffd962867a3a2f624f992daa94a6a556f3218ce740068725c37074e468ee207d2f73902ebcfcf49822775985bf31b715f5888b24efa190000000000000000000000000000ddffffff020000000000000000ddffffff0000b27cf3d1848a54d7132be1bfb0adf9deab3323aa9fdfb52faf9cb09c3bfd09000000b91ab219ef00bb7b3de8f67ffcad3f6c3c2b1f03550000000000001cf41ab11f12fb1e0a494034007de7c6592df1a6c64d8f20a67745409e011f1264d43f153b3d34889f40159e800ea2474b540500a30b23bcee46762e2093bcc9eae5ee3e980026c96f80ee1a00000000740750fa4d9aaa705989b8e673e3296e52d337c56abf112874ec51d6fe048ba6866adebab53168770a71ad901ace383e41d277b103923a9d961f7a2591dbe4a912ffaf6f658f3f9cd16286744f83a83f138f8f92efd92239eafcc5c1b3f97a297c9e49a0c3300ef7b7fb5f09e0c8a868a353409e34d3e82279637599f35ad3f7ffffff3cac394c7bbdcd0e0eb52162e0c410ade7000026a4e739c60f03cc4146a77af02c1d4cefd4a2b94c0aed8477dfa8ceefb467f05c6977c78cdbf3f704ec73754910fe050038ec9e47de89298b7bf4d769ccc18eedd9068ca1457870eb30d219e23ccc8e06dddeb61799257ab5000013c86ba99523d61a00000000c270246c878d01160e6c07bf6cf8809c3a0d062357ba2515567230a6f8b2ad1e1f4933545fc3c741374211663f6b63b1dd044dd0a2768e825972fc4300001467c89fa0f82e8440105051e5510a33dcda5e4e202bd622549c4cffffff501d3a5dd7143fbf221fff161c12ca389cbe0000000000000fff2ecf631c6c5fd9c26a54d43fa050b88d1d43a8645bd9109b7e07869bba7131421c0f397073943330baafd243c0c6ffe673bab4113be7664e08bdd7115c61afcb718cf3c4680b2f6c7a8400e378a9b15bc20f49e298727340e87cdefb40e56e9cfad9931b8c552b2c7c503f3d0e7ab0e958adb8629aeec90e6d1857da822e40009995ae166deb9856291a43a6f7eb2e32cefbf463789eaf79b8d4c22be89f44b032dad13007b82e6044f643fc8cd07ae636a5dbe9864a117d27326850a7c3b570863f532c218b10af13d7be94987005088a83880ccab9c9920c2d2af8c5e13d52c83ac3fa7c3ae6c08384865b66d2204c2e4f3ae200f279b512b4dcb5dd9cba16b62040bf8702ae12c77e6e34991af603e3856a346cf708feeb708ab22b560cf8a4a6f31ba6d9b8cb0908000000000000001a342c010000000000e667a7592b33406f1f71c739b55db91d2309dc7ae401005f52053a39e7307c09ff3ac3e820b01c57dd74d4aafc4c383a17bc1de5347bb71ca16dcbbbaa2935ae662082b56cf666e63a759e0ef3ea7af6881513be94b362e15ffca8ec453b3a2a67be70c17b0f9c2eac765816c30c2e7133dca1c7669522e8dff8bc570a93fbdb688c3aef810000007a6ea6b11163392a19d87995b51cb6febd5f34a34998d2010fd5facf68c4f84e2f66e27c81a149d7b331983d3b74444953fc1216dfec10b724be3733c26f12538376e177ffef6fd2020000000000000008e4919a463d5332a2546032a3c06b94f168e8fc4bda0c294723fe306f26c477af4b926644672985fab7cc67bc5b5f5d38cdd8df95147ebe1cd88b0a4c6cde9951be10ba7dfddfefb238fac2303cc8982f1e55b005afcfea5eb037248fefad6bb02c162ce92ab17744c8ec3d2e80cf3205d36699fd381bc81231fb5e12e45f3059f361d08d6a6d019ebf105eaf43083c29512bcedd79ca9bf24e063d0c273ed70a2b70be521ea27dc8cf3c9bdf83b93405db07e82e2db484f8673e0e97dd7e8a872148613c3a04f3d67f4375ba5c7f1b00ffffff7f000000000801f71d79d812ced782646b5f79c8fc08bb5c11020108d702edd2ea9c96cf0d2d48aa5fc0a7bf1b51afd85350ad00b78c598fa8701b000884de790b54e5ab2e8ff0c7ae23e0b6eeac95c4c2eef2e5eb1d019d52099fbd404e8ece970f67856ba7e960bd8b1e4105ce7e31f7c9c3e3fa61aaa967b90087e91d703e98535b107b8f4653be4c46a3a1adb07d226952b8573b417018316fa96e2b8e7370baa16d4122c863709b08d4639a19a46ac90ac48a13ee9bcaa875fc700000000000003b40dc5c745fe2491e8425e600000000000000000000000000000000000000000000000000000000000000250318a44ad31baac0520a913301e630ae540f3289aebde8633f6f450c0738e16df6c7f1e0832a2a16fe6e39959735758248032cdf7320c6dc87b01e3f9a7811b200000000ae189de4b9b25f7c7a9c070000002af1c06315270de4a6605e4b4b58bef76fac54f11b84bd7bcd6b6a485edfb7684c770a39b38b08e18a51a4d4e66ca21c06a4b4198e1bc2ef990c9ba911efed626e5ee341a17bf8132b09000000d31df213c802d74797056fd3bca8b2d6cb134437cba0193ba4360bdcc98aad2560aa48291c4eb9d4e08ad7a9c5f04be1ab597124d84dfc7bd8cca8f68154a0ed356e773a797ca6d66748857b4abbf8830abeea2a46342e6a7378173cb29d5cdcd698a0203f78116b710008000000000000007c2d86b94472807c10eb9a8e2fb8bd79fe3a8316deff3ee641c9a080a2173642e673a672279bae4e7e28055da9497d7edb53be6e80482bd4d9a74b8dd4221fff0f0000705d7257ff7f76c78ba0b44ec0bdfa0d32d7042059b13a079639f14f9032b856d892ad6af5124c9c3130485e9682ff1f3c54e475d5bb496aef4bb537d7e191dfdeba109fdcf7864763f87a6d711cf52e520a6ce30e134c55e0caac037209d2f14fcddd00000000000000000000000000000000e609893bdce015e8ccfb36399844db61f6171b0b0e845e48728450c6ba4f7098f8e000676b59ab9f851f3ab77847ce05c89411277ec69c409b7ec50a3337a78675f38a568612c235ab5f2cd6d035d5f5f6a693c381adbbf7b37e37292783b2c7efe7d3a067906552f76d419e0300000000000000000000008f3a20b49fe7636806867283e35cff8d00e7b251bab3cf6377a24f8e8d4bda7503674bc94bf7f4d2fa6f25944bf0a186436d9f6831995976328a1fdc78492c65c1434855dc35c3cf7cf9610c5387794443c99b304799114132362849c3fa85d6379729ff9094933db0cfbe8887c50b87e1469fdf454cef4cbc5f7bf384000000000000a4e8c1a25f47c440144a9776be6cb40aafdb9d3cc8f6a6050974e1c4000000000000008b753f4e1bef9556efcc087a99db"], &(0x7f0000000140)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r6 = socket$kcm(0x2, 0x1, 0x0) sendmsg$kcm(r4, &(0x7f0000000600)={0x0, 0x0, 0x0}, 0x20000000) ioctl$sock_kcm_SIOCKCMATTACH(r4, 0x89e0, &(0x7f0000000400)={r6, r5}) r7 = syz_genetlink_get_family_id$nfc(&(0x7f0000000100), 0xffffffffffffffff) ioctl$IOCTL_GET_NCIDEV_IDX(r3, 0x0, &(0x7f00000000c0)) sendmsg$NFC_CMD_DEV_UP(0xffffffffffffffff, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000000)={0x14, r7, 0x1, 0x70bd26, 0x23c}, 0x14}}, 0x0) setsockopt$sock_int(0xffffffffffffffff, 0x1, 0xf, &(0x7f0000356ffc)=0xffffffffffffff40, 0x4) setsockopt$SO_ATTACH_FILTER(0xffffffffffffffff, 0x1, 0x33, &(0x7f00000a2000)={0x1, &(0x7f0000f07000)=[{0x6}]}, 0x10) listen(0xffffffffffffffff, 0x0) 2m7.868209682s ago: executing program 33 (id=270): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000100)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sendmmsg$unix(0xffffffffffffffff, 0x0, 0x0, 0x0) r3 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$TIOCSETD(r3, 0x5423, &(0x7f00000000c0)=0xf) r4 = fcntl$dupfd(r3, 0x0, r3) ioctl$TCFLSH(r4, 0x400455c8, 0x0) ioctl$TIOCSTI(r3, 0x5412, &(0x7f0000000080)=0x4) ioctl$TIOCSTI(r4, 0x5412, &(0x7f0000000040)=0x3f) 2m6.772578756s ago: executing program 34 (id=272): r0 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r0, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000200)=ANY=[@ANYBLOB="1400000038000107000000000000000008000000e2ccd84bd51aa87f1ed12a18e5c3e8c543da10e92f91b9b19a89f7db51df29470a77f99728453bbce63a9e191636504d14a5bd67b1f3b2f064c68991dc561f"], 0x14}, 0x1, 0x0, 0x0, 0x48010}, 0x4000000) 1m57.034224874s ago: executing program 3 (id=337): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) bind$inet6(r0, &(0x7f00004b8fe4)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) r1 = openat$selinux_checkreqprot(0xffffffffffffff9c, 0x0, 0x800, 0x0) setsockopt$MRT6_FLUSH(r1, 0x29, 0xd4, 0x0, 0x0) socket$nl_netfilter(0x10, 0x3, 0xc) pipe2$9p(&(0x7f00000001c0)={0xffffffffffffffff, 0xffffffffffffffff}, 0x0) write$P9_RVERSION(r3, &(0x7f0000000300)=ANY=[@ANYBLOB="1500000065ffff017f000e0800395032303030"], 0x15) bpf$MAP_CREATE(0x0, 0x0, 0x48) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x6, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r4 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r4, &(0x7f0000019680)=""/102392, 0x18ff8) ioctl$KDFONTOP_SET(0xffffffffffffffff, 0x4b6a, 0x0) r5 = dup(r3) open(0x0, 0x440, 0x0) write$FUSE_BMAP(r5, &(0x7f0000000000)={0x18, 0x0, 0x0, {0x3b9}}, 0x18) write$FUSE_DIRENTPLUS(r5, &(0x7f00000003c0)=ANY=[@ANYBLOB="b0"], 0xb0) write$FUSE_GETXATTR(r5, &(0x7f00000000c0)={0x18}, 0x18) mount$9p_fd(0x0, &(0x7f0000000400)='./file0\x00', &(0x7f0000000080), 0x1010412, &(0x7f0000000700)={'trans=fd,', {'rfdno', 0x3d, r2}, 0x2c, {'wfdno', 0x3d, r5}, 0x2c, {[{@cache_fscache}]}}) 1m56.675328542s ago: executing program 3 (id=338): socket$can_bcm(0x1d, 0x2, 0x2) r0 = socket$can_bcm(0x1d, 0x2, 0x2) connect$can_bcm(r0, &(0x7f00000000c0), 0x10) r1 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_RENAME(r1, 0x0, 0x4000) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) r2 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000ac0), 0x242940, 0x0) ioctl$BLKPG(r2, 0x1269, &(0x7f00000000c0)={0x1f400000, 0x0, 0x94, &(0x7f0000000000)={0x0, 0x200, 0xe}}) r3 = gettid() timer_create(0x0, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004, @tid=r3}, &(0x7f0000bbdffc)) r4 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) timer_settime(0x0, 0x0, &(0x7f0000000280)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) ioctl$PTP_SYS_OFFSET(r4, 0x43403d05, &(0x7f0000000b40)={0x17}) futex_waitv(&(0x7f0000001080)=[{0x3, &(0x7f0000001040)=0x3, 0x82}], 0x1, 0x0, 0x0, 0x1) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8c}, 0x0) sched_setscheduler(r3, 0x1, &(0x7f0000000380)=0xf2) r5 = socket$inet6(0x10, 0x3, 0x0) sendto$inet6(r5, &(0x7f0000000180)="900000001c001f4d154a817393278bff0a80a578020000000404840014000100ac1414bb0542d6401051a2d708f37ac8da1a297e0099c5ac0000c5b068d0bf46d323456536016466fcb78dcaaf6c3efed495a46215", 0x55, 0x0, 0x0, 0x0) sched_setaffinity(0x0, 0x8, &(0x7f0000000280)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r6 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r6, &(0x7f0000019680)=""/102392, 0x18ff8) mount$tmpfs(0x0, &(0x7f0000000000)='./file1\x00', &(0x7f0000000080), 0x1000000, &(0x7f0000000680)=ANY=[@ANYBLOB="687567653d04090000002c6769643d", @ANYRESHEX=0xee01, @ANYBLOB='lmpol=bind:3868,\x00']) bind$vsock_stream(0xffffffffffffffff, &(0x7f0000000040)={0x28, 0x0, 0x2710, @local}, 0x10) r7 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r7, &(0x7f0000000000)={0x0, 0xfffffffffffffffd, &(0x7f0000000040)={&(0x7f0000004a40)=ANY=[@ANYBLOB="c0260000410007010000000007000000027c00000400fc80a72601", @ANYRES32], 0x26c0}, 0x1, 0x0, 0x0, 0x40000}, 0x24000000) fcntl$lock(0xffffffffffffffff, 0x7, &(0x7f0000000100)={0x0, 0x0, 0x0, 0x6}) write$UHID_CREATE2(r1, &(0x7f0000000b00)=ANY=[@ANYBLOB, @ANYRES8], 0x154) socket$vsock_stream(0x28, 0x1, 0x0) 1m55.541779227s ago: executing program 3 (id=341): syz_open_dev$usbfs(0x0, 0x76, 0x141301) r0 = socket$kcm(0x2, 0x1000000000000005, 0x0) setsockopt$SO_BINDTODEVICE_wg(r0, 0x1, 0x19, 0x0, 0x0) getsockname$packet(0xffffffffffffffff, 0x0, &(0x7f00000000c0)) syz_genetlink_get_family_id$devlink(&(0x7f0000000100), 0xffffffffffffffff) r1 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$DEVLINK_CMD_TRAP_GROUP_SET(r1, &(0x7f0000000400)={0x0, 0x0, &(0x7f0000000000)={0x0}}, 0x0) openat$sndseq(0xffffffffffffff9c, &(0x7f0000000300), 0x480) prlimit64(0x0, 0xe, &(0x7f00000003c0)={0x8, 0xab}, 0x0) mknodat$loop(0xffffffffffffff9c, &(0x7f0000000140)='./file0\x00', 0x1000, 0x1) r2 = gettid() timer_create(0x0, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004, @tid=r2}, &(0x7f0000bbdffc)) timer_settime(0x0, 0x0, &(0x7f0000000340)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) name_to_handle_at(0xffffffffffffff9c, &(0x7f0000000080)='./file0\x00', &(0x7f00000000c0)=ANY=[], &(0x7f0000000180), 0x0) open_by_handle_at(0xffffffffffffff9c, &(0x7f00000000c0)=ANY=[], 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) r3 = syz_open_dev$MSR(&(0x7f0000000000), 0x0, 0x0) read$msr(r3, &(0x7f0000019680)=""/102392, 0x18ff8) setsockopt$inet_tcp_TCP_CONGESTION(0xffffffffffffffff, 0x6, 0xd, &(0x7f0000000040)='htcp\x00', 0x5) 1m55.502243493s ago: executing program 3 (id=342): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) (async) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) openat$fuse(0xffffffffffffff9c, &(0x7f0000000040), 0x2, 0x0) (async) prlimit64(r0, 0xb, &(0x7f0000000100)={0xa, 0x100105}, 0x0) (async) socket$nl_audit(0x10, 0x3, 0x9) (async) sched_setscheduler(0x0, 0x1, &(0x7f0000000300)=0x7) (async) r2 = getpid() sched_setscheduler(r2, 0x2, &(0x7f0000000200)=0x3) (async) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) (async) syz_clone(0x600, 0x0, 0x33, 0x0, 0x0, 0x0) (async) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x3, 0x0) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x400000bce) (async) r3 = syz_open_dev$MSR(&(0x7f0000000180), 0x0, 0x0) read$msr(r3, &(0x7f0000019680)=""/102392, 0x18ff8) (async) r4 = socket$inet6(0xa, 0x2, 0x36) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r4, 0x8933, &(0x7f0000000000)={'batadv_slave_1\x00'}) bpf$MAP_CREATE(0x0, 0x0, 0x0) (async) r5 = syz_init_net_socket$bt_rfcomm(0x1f, 0x1, 0x3) r6 = openat$uhid(0xffffffffffffff9c, &(0x7f0000000240), 0x544f4ae058545480, 0x0) fchdir(r6) (async) bind$bt_rfcomm(r5, &(0x7f00000001c0)={0x1f, @none, 0xff}, 0xa) (async) connect$bt_rfcomm(r5, &(0x7f00000000c0)={0x1f, @none, 0x6}, 0xa) listen(0xffffffffffffffff, 0x80) (async) socket$nl_generic(0x10, 0x3, 0x10) write$RDMA_USER_CM_CMD_RESOLVE_IP(0xffffffffffffffff, &(0x7f0000000340)={0x3, 0x40, 0xfa00, {{0xa, 0x4e23, 0x400007, @private2={0xfc, 0x2, '\x00', 0x1}, 0x8001}, {0xa, 0x4e20, 0x2, @mcast1, 0xc}, 0xffffffffffffffff, 0x6}}, 0x48) 1m55.343289522s ago: executing program 3 (id=343): r0 = socket$inet6(0xa, 0x5, 0x0) syz_usb_connect(0x1, 0x3d, &(0x7f00000001c0)=ANY=[@ANYBLOB="12010000bdce4208110f80106afc0000000109022b00010000000009043700022ee5cd0009058010ff037f790209050e0320000980070705ab0b78"], 0x0) syz_open_dev$char_usb(0xc, 0xb4, 0x0) pselect6(0x40, &(0x7f0000000100), 0x0, &(0x7f0000000240)={0x1f}, &(0x7f0000000280)={0x0, 0x3938700}, 0x0) setsockopt$sock_int(r0, 0x1, 0xf, &(0x7f0000fee000)=0x3fa, 0x4) listen(r0, 0x50) r1 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000040)={0x1, &(0x7f0000000000)=[{0x6, 0x0, 0x0, 0x7fff7ffc}]}) close_range(r1, 0xffffffffffffffff, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x0) mount$bind(&(0x7f0000000380)='./file0\x00', &(0x7f0000000200)='./file0\x00', 0x0, 0x2125099, 0x0) mount$bind(0x0, &(0x7f00000005c0)='./file0\x00', 0x0, 0x100000, 0x0) r2 = open_tree(0xffffffffffffff9c, &(0x7f0000000640)='\x00', 0x89901) move_mount(r2, &(0x7f0000000140)='.\x00', 0xffffffffffffff9c, &(0x7f0000000180)='./file0\x00', 0x0) mount$bind(&(0x7f0000000000)='./file0/../file0\x00', &(0x7f0000000340)='./file0/file0\x00', 0x0, 0x89101a, 0x0) mount$bind(0x0, &(0x7f0000000140)='./file0/file0\x00', 0x0, 0x80000, 0x0) 1m54.014005158s ago: executing program 3 (id=344): mount(&(0x7f00000000c0)=@loop={'/dev/loop', 0x0}, &(0x7f0000000140)='./bus\x00', 0x0, 0x73d014, 0x0) mkdir(0x0, 0x0) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x0, 0x0, 0x0, 0x80000001, 0x0, 0x0, 0x0, 0x8, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x7, 0x100}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket(0x10, 0x3, 0x0) sendmsg$nl_generic(r4, 0x0, 0x0) r5 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000400)={0x1, &(0x7f0000000380)=[{0x6, 0x0, 0x0, 0x7fffffff}]}) r6 = openat$dma_heap(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$DMA_HEAP_IOCTL_ALLOC(r6, 0xc0184800, &(0x7f0000000100)={0x4004, r5, 0x2}) lseek(r7, 0x289e0cb9, 0x0) r8 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r8, &(0x7f0000000180)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000000)=ANY=[@ANYBLOB="b800000015"], 0xb8}}, 0x0) ioctl$SIOCSIFHWADDR(r7, 0x8924, &(0x7f00000002c0)={'veth0_to_hsr\x00', @random="38d6202d9fc1"}) 1m38.36128149s ago: executing program 35 (id=344): mount(&(0x7f00000000c0)=@loop={'/dev/loop', 0x0}, &(0x7f0000000140)='./bus\x00', 0x0, 0x73d014, 0x0) mkdir(0x0, 0x0) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x0, 0x0, 0x0, 0x80000001, 0x0, 0x0, 0x0, 0x8, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x7, 0x100}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket(0x10, 0x3, 0x0) sendmsg$nl_generic(r4, 0x0, 0x0) r5 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000400)={0x1, &(0x7f0000000380)=[{0x6, 0x0, 0x0, 0x7fffffff}]}) r6 = openat$dma_heap(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$DMA_HEAP_IOCTL_ALLOC(r6, 0xc0184800, &(0x7f0000000100)={0x4004, r5, 0x2}) lseek(r7, 0x289e0cb9, 0x0) r8 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r8, &(0x7f0000000180)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000000)=ANY=[@ANYBLOB="b800000015"], 0xb8}}, 0x0) ioctl$SIOCSIFHWADDR(r7, 0x8924, &(0x7f00000002c0)={'veth0_to_hsr\x00', @random="38d6202d9fc1"}) 2.325170644s ago: executing program 1 (id=475): socket$inet6_icmp_raw(0xa, 0x3, 0x3a) r0 = socket(0x10, 0x803, 0x0) sendmsg$nl_route(r0, &(0x7f00000006c0)={0x0, 0x0, &(0x7f0000000680)={0x0, 0x18}}, 0x0) r1 = socket(0x18, 0x3, 0x0) setsockopt$netlink_NETLINK_TX_RING(r1, 0x10e, 0xc, &(0x7f0000000000)={0x4800}, 0x10) r2 = syz_open_dev$vim2m(&(0x7f00000000c0), 0x0, 0x2) ioctl$VIDIOC_G_SELECTION(r2, 0xc040565e, &(0x7f0000000180)={0x2, 0x2, 0x7, {0x6, 0x0, 0x2, 0xb}}) creat(&(0x7f0000000100)='./file0\x00', 0x0) syz_init_net_socket$rose(0xb, 0x5, 0x0) r3 = syz_io_uring_setup(0x49a, &(0x7f0000000380)={0x0, 0x761, 0x8, 0x8008000, 0x2d1}, &(0x7f0000000340)=0x0, &(0x7f0000000040)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r4, 0x4, &(0x7f0000000000)=0xffb, 0x0, 0x4) syz_io_uring_submit(r4, r5, &(0x7f00000002c0)=@IORING_OP_TIMEOUT={0xb, 0x11, 0x0, 0x0, 0x0, &(0x7f0000000100), 0x1, 0x40, 0x1}) io_uring_enter(r3, 0x628, 0xc88d, 0x43, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000400)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r6 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r6, &(0x7f0000019680)=""/102392, 0x18ff8) r7 = openat$sysctl(0xffffffffffffff9c, &(0x7f0000000040)='/proc/sys/vm/drop_caches\x00', 0x1, 0x0) writev(r7, &(0x7f00000000c0)=[{&(0x7f0000000140)='2', 0x1}], 0x1) open$dir(&(0x7f0000000080)='./file0\x00', 0x0, 0x0) r8 = syz_open_dev$ttys(0xc, 0x2, 0x0) ioctl$TIOCSETD(r8, 0x5423, 0x0) ioctl$TIOCSETD(0xffffffffffffffff, 0x5423, &(0x7f0000000280)=0x15) openat$sysfs(0xffffffffffffff9c, &(0x7f00000003c0)='/sys/kernel/crash_elfcorehdr_size', 0x270040, 0x100) close_range(0xffffffffffffffff, 0xffffffffffffffff, 0x0) bpf$BPF_BTF_GET_NEXT_ID(0x17, &(0x7f0000000180)={0x9}, 0x8) 1.910245595s ago: executing program 1 (id=476): pipe(&(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) vmsplice(r1, &(0x7f00000000c0)=[{&(0x7f0000000180)="77690addcfbe1fbb66ec", 0xff3b}], 0x1, 0x1) close(r1) r2 = socket$nl_route(0x10, 0x3, 0x0) ioctl$sock_SIOCGIFINDEX(r1, 0x8933, &(0x7f0000000000)={'bond_slave_0\x00', 0x0}) bpf$PROG_LOAD_XDP(0x5, &(0x7f00000001c0)={0xd, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0xf, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000000180)=ANY=[@ANYBLOB="4400000010000100"/20, @ANYRES32=r3, @ANYBLOB="000024000000000024001200140001006272696467655f736c617665800000000c000500080005"], 0x3}}, 0x0) splice(r0, 0x0, r2, 0x0, 0x10d00, 0x0) userfaultfd(0x800) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r4, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000300)={{0x14, 0x10, 0x1, 0x0, 0x0, {0x3}}, [@NFT_MSG_NEWTABLE={0x20, 0x0, 0xa, 0x3, 0x0, 0x0, {0x7}, [@NFTA_TABLE_NAME={0x9, 0x1, 'syz0\x00'}]}, @NFT_MSG_NEWSET={0x84, 0x9, 0xa, 0x401, 0x0, 0x0, {0x7}, [@NFTA_SET_ID={0x8}, @NFTA_SET_NAME={0x9, 0x2, 'syz0\x00'}, @NFTA_SET_TABLE={0x9, 0x1, 'syz0\x00'}, @NFTA_SET_KEY_LEN={0x8, 0x5, 0x1, 0x0, 0x2f}, @NFTA_SET_EXPRESSIONS={0x40, 0x12, 0x0, 0x1, [{0x14, 0x1, 0x0, 0x1, @last={{0x9}, @val={0x4}}}, {0x14, 0x1, 0x0, 0x1, @counter={{0xc}, @val={0x4}}}, {0x14, 0x1, 0x0, 0x1, @counter={{0xc}, @val={0x4}}}]}, @NFTA_SET_FLAGS={0x8, 0x3, 0x1, 0x0, 0x110}]}], {0x14, 0x10, 0x1, 0x0, 0x0, {0x0, 0x84}}}, 0xcc}}, 0x20050800) r5 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r5, &(0x7f0000000080)={0x2, 0x4e21, @empty}, 0xffffffffffffff9c) setsockopt$inet_tcp_TCP_CONGESTION(r5, 0x6, 0xd, &(0x7f0000000000)='hybla\x00', 0x6) sendto$inet(r5, 0x0, 0x0, 0xb, 0x0, 0x0) recvfrom$inet(r5, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0xc9100120, 0x0, 0xfffffffffffffd25) connect$pppl2tp(0xffffffffffffffff, 0x0, 0x0) connect$pppl2tp(0xffffffffffffffff, 0x0, 0x0) socketpair$tipc(0x1e, 0x5, 0x0, 0x0) syz_io_uring_setup(0x110, &(0x7f00000000c0)={0x0, 0x3232, 0xff, 0x0, 0x26d}, 0x0, 0x0) socket$nl_generic(0x10, 0x3, 0x10) r6 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) ioctl$IOMMU_VFIO_IOAS$CLEAR(r6, 0x3b88, 0x0) r7 = openat$rdma_cm(0xffffffffffffff9c, &(0x7f0000001400), 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r7, &(0x7f00000000c0)={0x0, 0x18, 0xfa00, {0x0, &(0x7f0000000080)={0xffffffffffffffff}, 0x111}}, 0xfffffecd) write$RDMA_USER_CM_CMD_RESOLVE_IP(r7, &(0x7f0000000100)={0x3, 0x40, 0xfa00, {{0xa, 0x0, 0x0, @loopback, 0xa09c}, {0xa, 0x0, 0xfffffffe, @private0}, r8, 0x99d}}, 0x48) writev(r7, &(0x7f0000000040)=[{&(0x7f0000000100), 0x86}], 0x2) 1.82468348s ago: executing program 1 (id=477): prlimit64(0x0, 0xe, &(0x7f0000000140)={0xa, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r0 = getpid() sched_setaffinity(0x0, 0x0, 0x0) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000b00)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f0000000180)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x3, 0x4, &(0x7f0000000340)=ANY=[], &(0x7f0000003ff6)='GPL\x00', 0x5, 0x0, 0x0, 0x0, 0x8, '\x00', 0x0, @sched_cls, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, 0x0, 0x0) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_int(r3, 0x6, 0x1e, &(0x7f0000000180)=0x400000001, 0xc2) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) connect$inet6(r3, &(0x7f0000000200)={0xa, 0x0, 0x700, @empty}, 0x1c) writev(0xffffffffffffffff, 0x0, 0x0) 917.770358ms ago: executing program 1 (id=478): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, 0x0, &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x10) openat$ptmx(0xffffffffffffff9c, 0x0, 0x3043, 0x0) socket$xdp(0x2c, 0x3, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000380)={0x8, 0x100008b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000000)=0x7) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x80200, 0x0) r1 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r1, &(0x7f0000000840)=[{&(0x7f00000002c0)}, {0x0}], 0x2) r2 = socket(0x10, 0x3, 0x0) setsockopt$netlink_NETLINK_TX_RING(r2, 0x10e, 0xc, &(0x7f0000000000)={0x9}, 0x10) openat$tun(0xffffffffffffff9c, &(0x7f0000000500), 0x240, 0x0) timer_gettime(0x0, 0x0) r3 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000380)='./binderfs/binder0\x00', 0x802, 0x0) ioctl$BINDER_SET_CONTEXT_MGR_EXT(r3, 0x4018620d, &(0x7f00000000c0)={0x73622a85, 0x110b, 0x8000000000002}) r4 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000200)='./binderfs/binder0\x00', 0x0, 0x0) ioctl$BINDER_WRITE_READ(r4, 0xc0306201, &(0x7f0000000080)={0x8, 0x0, &(0x7f0000000400)=[@increfs], 0x0, 0x0, 0x0}) r5 = dup3(r4, r3, 0x0) r6 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000000)='./binderfs/binder0\x00', 0x802, 0x0) mmap$binder(&(0x7f0000ffd000/0x3000)=nil, 0x3000, 0x1, 0x11, r6, 0x0) ioctl$BINDER_SET_CONTEXT_MGR_EXT(r6, 0x4018620d, &(0x7f0000000040)={0x73622a85, 0x10a}) ioctl$BINDER_WRITE_READ(r5, 0xc0306201, &(0x7f00000003c0)={0x8, 0x0, &(0x7f0000000340)=[@acquire], 0x0, 0x0, 0x0}) ioctl$BINDER_WRITE_READ(r3, 0xc0306201, &(0x7f00000001c0)={0x4c, 0x0, &(0x7f0000000740)=[@transaction_sg={0x40486311, {0x1, 0x0, 0x0, 0x0, 0x11, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x1440}], 0x0, 0x0, 0x0}) 884.718293ms ago: executing program 1 (id=479): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = socket$alg(0x26, 0x5, 0x0) bind$alg(r2, &(0x7f0000000600)={0x26, 'rng\x00', 0x0, 0x0, 'drbg_pr_ctr_aes256\x00'}, 0x58) setsockopt$ALG_SET_KEY(r2, 0x117, 0x1, 0x0, 0x0) r3 = accept4(r2, 0x0, 0x0, 0x80000) recvmsg$can_raw(r3, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000480)=[{&(0x7f0000000140)=""/103, 0x67}], 0x1, 0x0, 0x0, 0x8800}, 0x40010022) 0s ago: executing program 1 (id=480): syz_clone3(&(0x7f0000002c00)={0x9828000, 0x0, 0x0, 0x0, {}, 0x0, 0x0, 0x0, 0x0}, 0x58) syz_init_net_socket$nl_rdma(0x10, 0x3, 0x10) prlimit64(0x0, 0xe, &(0x7f00000007c0)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) r0 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) madvise(&(0x7f0000ffc000/0x4000)=nil, 0x4000, 0x65) writev(r0, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r1 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r1, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000000)=@ipv6_delroute={0x3c, 0x19, 0x1, 0x70bd27, 0x0, {0xa, 0x0, 0x0, 0x0, 0x0, 0x2, 0x0, 0x0, 0x1000}, [@RTA_PRIORITY={0x8, 0x1e, 0x1}, @RTA_ENCAP={0x18, 0x16, 0x0, 0x1, @LWTUNNEL_IP6_DST={0x14, 0x2, @initdev={0xfe, 0x88, '\x00', 0x1, 0x0}}}]}, 0x3c}}, 0x0) r2 = socket$inet_mptcp(0x2, 0x1, 0x106) syz_init_net_socket$bt_hci(0x1f, 0x3, 0x1) setsockopt$sock_int(r2, 0x1, 0x12, &(0x7f0000000140)=0xffff0000, 0x4) sendto$inet6(0xffffffffffffffff, &(0x7f0000000200)="d34c4b2fd7d09e145902dcf7495c823dee541dd353f2d6eab93d8a3b0f7059fcee67ca6699e3465a77b5d8696d9a5e1e7d32e6afcc8e5ffe4d6561460c4ecb134b88f1ceeaa3ade17f47a702f5ab3a5a3232f7906b4deced3e43332e7fb21e65728fd4b026dec1d0a32f507b2d8628f990c4b7bf7791dd4649db203159614af3f31496df94b8c07664beb5bd87efe223c2d7", 0x92, 0x20000040, 0x0, 0x0) bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) pselect6(0x0, 0x0, 0x0, &(0x7f00000002c0)={0x3ff, 0x0, 0x0, 0x9, 0x0, 0x0, 0x7fffffff}, 0x0, 0x0) r3 = openat$misdntimer(0xffffffffffffff9c, 0x0, 0x0, 0x0) ioctl$IMADDTIMER(r3, 0x80044940, &(0x7f0000000080)=0x14) sendto$inet6(0xffffffffffffffff, &(0x7f0000847fff), 0x0, 0x0, &(0x7f000005ffe4)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendmsg$netlink(0xffffffffffffffff, 0x0, 0x0) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000e80)={&(0x7f0000000cc0)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x0, 0x0, 0x2}}, 0x0, 0x1a, 0x0, 0x1, 0x101, 0x0, @void, @value}, 0x28) mkdir(&(0x7f0000000180)='./file0\x00', 0x30) mount(&(0x7f0000000040)=@nbd={'/dev/nbd', 0x0}, &(0x7f0000000a80)='./file0\x00', &(0x7f0000000ac0)='jfs\x00', 0x0, &(0x7f0000000140)='grpquota') bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) syz_genetlink_get_family_id$nl80211(&(0x7f0000000040), 0xffffffffffffffff) socket$nl_generic(0x10, 0x3, 0x10) kernel console output (not intermixed with test programs): T48] usb 4-1: new full-speed USB device number 7 using dummy_hcd [ 83.123529][ T5866] usb 5-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 83.140605][ T1206] usb 2-1: new full-speed USB device number 4 using dummy_hcd [ 83.142077][ T5866] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 83.156322][ T5866] usb 5-1: Product: syz [ 83.161697][ T5866] usb 5-1: Manufacturer: syz [ 83.166328][ T5866] usb 5-1: SerialNumber: syz [ 83.179543][ T5866] usb 5-1: config 0 descriptor?? [ 83.190743][ T5866] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 83.201957][ T5866] dvb-usb: bulk message failed: -22 (3/0) [ 83.222611][ T5866] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 83.232685][ T5866] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 83.244791][ T5866] usb 5-1: media controller created [ 83.260367][ T5866] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 83.302489][ T1206] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 83.313669][ T5866] dvb-usb: bulk message failed: -22 (6/0) [ 83.320005][ T5866] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 83.368551][ T1206] usb 2-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 83.783060][ T1206] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 83.799433][ T5866] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.4/usb5/5-1/input/input8 [ 83.811225][ T6117] dibusb: i2c wr: len=61 is too big! [ 83.811225][ T6117] [ 83.812899][ T1206] usb 2-1: Product: syz [ 83.823848][ T1206] usb 2-1: Manufacturer: syz [ 83.828439][ T1206] usb 2-1: SerialNumber: syz [ 83.863425][ T1206] usb 2-1: config 0 descriptor?? [ 83.894277][ T1206] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 83.936648][ T1206] dvb-usb: bulk message failed: -22 (3/0) [ 83.937054][ T5866] dvb-usb: schedule remote query interval to 150 msecs. [ 83.949380][ T48] usb 4-1: unable to get BOS descriptor or descriptor too short [ 83.972836][ T1206] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 83.983092][ T1206] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 83.983566][ T5866] dvb-usb: bulk message failed: -22 (3/0) [ 83.998392][ T1206] usb 2-1: media controller created [ 84.005542][ T48] usb 4-1: unable to read config index 0 descriptor/start: -71 [ 84.008420][ T1206] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 84.021818][ T48] usb 4-1: can't read configurations, error -71 [ 84.025086][ T1206] dvb-usb: bulk message failed: -22 (6/0) [ 84.035915][ T1206] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 84.050426][ T5866] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 84.051310][ T1206] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.1/usb2/2-1/input/input9 [ 84.079237][ T1206] dvb-usb: schedule remote query interval to 150 msecs. [ 84.091096][ T1206] dvb-usb: bulk message failed: -22 (3/0) [ 84.120736][ T6127] dibusb: i2c wr: len=61 is too big! [ 84.120736][ T6127] [ 84.138747][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 84.164403][ T5866] usb 5-1: USB disconnect, device number 2 [ 84.220906][ T1206] usb 2-1: USB disconnect, device number 4 [ 84.492618][ T5860] dvb-usb: bulk message failed: -22 (1/0) [ 84.498394][ T5860] dvb-usb: error while querying for an remote control event. [ 84.629658][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 84.631875][ T5866] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 85.288301][ T30] kauditd_printk_skb: 1 callbacks suppressed [ 85.288315][ T30] audit: type=1400 audit(1748476554.467:194): avc: denied { setopt } for pid=6146 comm="syz.4.64" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 85.458815][ T6152] bridge0: port 3(netdevsim0) entered blocking state [ 85.465919][ T6152] bridge0: port 3(netdevsim0) entered disabled state [ 85.473297][ T6152] netdevsim netdevsim3 netdevsim0: entered allmulticast mode [ 85.556267][ T5866] usb 5-1: new high-speed USB device number 3 using dummy_hcd [ 85.894557][ T6152] netdevsim netdevsim3 netdevsim0: entered promiscuous mode [ 85.903166][ T6152] bridge0: port 3(netdevsim0) entered blocking state [ 85.909963][ T6152] bridge0: port 3(netdevsim0) entered forwarding state [ 86.442452][ T5866] usb 5-1: unable to get BOS descriptor or descriptor too short [ 86.463494][ T5866] usb 5-1: config 249 has an invalid interface number: 177 but max is 0 [ 86.480358][ T5866] usb 5-1: config 249 has no interface number 0 [ 86.491819][ T5866] usb 5-1: config 249 interface 177 altsetting 0 has an endpoint descriptor with address 0x1A, changing to 0xA [ 86.630295][ T5866] usb 5-1: config 249 interface 177 altsetting 0 has 4 endpoint descriptors, different from the interface descriptor's value: 3 [ 86.645466][ T5866] usb 5-1: New USB device found, idVendor=057c, idProduct=3800, bcdDevice=5a.9d [ 86.655152][ T5866] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 86.768545][ T6167] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=25621 sclass=netlink_xfrm_socket pid=6167 comm=syz.3.66 [ 86.930125][ T10] usb 2-1: new full-speed USB device number 5 using dummy_hcd [ 87.100328][ T5866] usb 5-1: Product: syz [ 87.104590][ T5866] usb 5-1: Manufacturer: syz [ 87.109400][ T5866] usb 5-1: SerialNumber: syz [ 87.110978][ T30] audit: type=1400 audit(1748476555.967:195): avc: denied { create } for pid=6156 comm="syz.3.66" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 87.138744][ T6149] raw-gadget.0 gadget.4: fail, usb_ep_enable returned -22 [ 87.147748][ T30] audit: type=1400 audit(1748476555.967:196): avc: denied { write } for pid=6156 comm="syz.3.66" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 87.179165][ T30] audit: type=1400 audit(1748476556.347:197): avc: denied { create } for pid=6158 comm="syz.0.67" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=qipcrtr_socket permissive=1 [ 87.216543][ T30] audit: type=1400 audit(1748476556.347:198): avc: denied { create } for pid=6158 comm="syz.0.67" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=llc_socket permissive=1 [ 87.235844][ T30] audit: type=1400 audit(1748476556.347:199): avc: denied { getopt } for pid=6158 comm="syz.0.67" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=llc_socket permissive=1 [ 87.302416][ T10] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 87.314590][ T10] usb 2-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 87.410132][ T10] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 87.418264][ T10] usb 2-1: Product: syz [ 87.467238][ T10] usb 2-1: Manufacturer: syz [ 87.496758][ T10] usb 2-1: SerialNumber: syz [ 87.537070][ T10] usb 2-1: config 0 descriptor?? [ 87.546442][ T30] audit: type=1400 audit(1748476556.747:200): avc: denied { write } for pid=6146 comm="syz.4.64" name="kvm" dev="devtmpfs" ino=84 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:kvm_device_t tclass=chr_file permissive=1 [ 87.590215][ T6149] netlink: 52 bytes leftover after parsing attributes in process `syz.4.64'. [ 87.599185][ T30] audit: type=1400 audit(1748476556.787:201): avc: denied { read } for pid=6168 comm="syz.3.70" name="loop-control" dev="devtmpfs" ino=646 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:loop_control_device_t tclass=chr_file permissive=1 [ 87.623149][ C0] vkms_vblank_simulate: vblank timer overrun [ 87.709749][ T30] audit: type=1400 audit(1748476556.787:202): avc: denied { open } for pid=6168 comm="syz.3.70" path="/dev/loop-control" dev="devtmpfs" ino=646 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:loop_control_device_t tclass=chr_file permissive=1 [ 87.790991][ T10] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 88.436601][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 88.682655][ T10] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 88.697840][ T6166] dibusb: i2c wr: len=61 is too big! [ 88.697840][ T6166] [ 88.719193][ T10] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 88.786704][ T10] usb 2-1: media controller created [ 89.038110][ T10] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 89.074432][ T5866] usb 5-1: USB disconnect, device number 3 [ 89.077894][ T10] dvb-usb: bulk message failed: -22 (6/0) [ 89.130846][ T10] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 89.167807][ T10] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.1/usb2/2-1/input/input10 [ 89.187839][ T10] dvb-usb: schedule remote query interval to 150 msecs. [ 89.197793][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 89.231622][ T10] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 89.274709][ T10] usb 2-1: USB disconnect, device number 5 [ 89.305757][ T10] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 92.055997][ T5866] usb 4-1: new high-speed USB device number 9 using dummy_hcd [ 93.140974][ T5866] usb 4-1: unable to get BOS descriptor or descriptor too short [ 93.159112][ T5866] usb 4-1: config 249 has an invalid interface number: 177 but max is 0 [ 93.272298][ T5866] usb 4-1: config 249 has no interface number 0 [ 93.291315][ T5866] usb 4-1: config 249 interface 177 altsetting 0 has an endpoint descriptor with address 0x1A, changing to 0xA [ 93.446445][ T5866] usb 4-1: config 249 interface 177 altsetting 0 has 4 endpoint descriptors, different from the interface descriptor's value: 3 [ 93.467443][ T5866] usb 4-1: New USB device found, idVendor=057c, idProduct=3800, bcdDevice=5a.9d [ 93.477639][ T5866] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 93.925649][ T5866] usb 4-1: Product: syz [ 93.944938][ T5866] usb 4-1: Manufacturer: syz [ 93.969901][ T5866] usb 4-1: SerialNumber: syz [ 94.001107][ T6220] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 95.216915][ T6249] netlink: 8 bytes leftover after parsing attributes in process `syz.3.83'. [ 96.012129][ T5866] usb 4-1: USB disconnect, device number 9 [ 96.161948][ T6261] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 96.760500][ T5813] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 101.049078][ T6289] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=25647 sclass=netlink_xfrm_socket pid=6289 comm=syz.0.100 [ 101.560610][ T5813] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 102.085818][ T6297] overlayfs: failed to resolve './file0': -2 [ 102.546092][ T30] audit: type=1400 audit(1748476571.747:203): avc: denied { unmount } for pid=5815 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 102.587789][ T6302] kAFS: No cell specified [ 102.660223][ T30] audit: type=1400 audit(1748476571.787:204): avc: denied { mounton } for pid=6301 comm="syz.4.104" path="/22/file0" dev="tmpfs" ino=144 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=fifo_file permissive=1 [ 103.183861][ T6314] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=25621 sclass=netlink_xfrm_socket pid=6314 comm=syz.2.105 [ 103.673132][ T30] audit: type=1400 audit(1748476572.437:205): avc: denied { bind } for pid=6301 comm="syz.4.104" lport=29 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rawip_socket permissive=1 [ 103.945174][ T30] audit: type=1400 audit(1748476572.437:206): avc: denied { node_bind } for pid=6301 comm="syz.4.104" saddr=fe88::5 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=rawip_socket permissive=1 [ 104.143488][ T30] audit: type=1400 audit(1748476573.347:207): avc: denied { create } for pid=6322 comm="syz.1.109" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 104.170288][ T5866] usb 5-1: new high-speed USB device number 4 using dummy_hcd [ 104.191640][ T30] audit: type=1400 audit(1748476573.347:208): avc: denied { bind } for pid=6322 comm="syz.1.109" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 104.344395][ T5866] usb 5-1: New USB device found, idVendor=17e9, idProduct=8b4e, bcdDevice=9c.08 [ 104.353574][ T5866] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 104.412589][ T5866] usb 5-1: config 0 descriptor?? [ 105.480397][ T5937] usb 3-1: new full-speed USB device number 7 using dummy_hcd [ 105.813948][ T5866] usb 5-1: USB disconnect, device number 4 [ 106.006840][ T5937] usb 3-1: unable to get BOS descriptor or descriptor too short [ 106.024248][ T6331] openvswitch: netlink: Unexpected mask (mask=200040, allowed=10048) [ 106.047309][ T5937] usb 3-1: unable to read config index 0 descriptor/start: -71 [ 106.061862][ T5937] usb 3-1: can't read configurations, error -71 [ 106.127848][ T5813] Bluetooth: hci5: command 0x1003 tx timeout [ 106.134649][ T5134] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 106.829276][ T30] audit: type=1400 audit(1748476575.757:209): avc: denied { mount } for pid=6330 comm="syz.4.112" name="/" dev="ramfs" ino=9170 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ramfs_t tclass=filesystem permissive=1 [ 106.860346][ T30] audit: type=1400 audit(1748476576.027:210): avc: denied { map } for pid=6333 comm="syz.3.113" path="socket:[9103]" dev="sockfs" ino=9103 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 106.884117][ C1] vkms_vblank_simulate: vblank timer overrun [ 106.890391][ T30] audit: type=1400 audit(1748476576.027:211): avc: denied { read accept } for pid=6333 comm="syz.3.113" path="socket:[9103]" dev="sockfs" ino=9103 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 106.913745][ C1] vkms_vblank_simulate: vblank timer overrun [ 108.210689][ T30] audit: type=1400 audit(1748476577.407:212): avc: denied { create } for pid=6345 comm="syz.2.116" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=pppox_socket permissive=1 [ 108.230090][ C1] vkms_vblank_simulate: vblank timer overrun [ 109.937478][ T6369] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=16 sclass=netlink_audit_socket pid=6369 comm=syz.0.120 [ 109.949924][ T6369] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=17 sclass=netlink_audit_socket pid=6369 comm=syz.0.120 [ 110.104139][ T30] audit: type=1400 audit(1748476579.167:213): avc: denied { audit_write } for pid=6359 comm="syz.0.120" capability=29 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=capability permissive=1 [ 110.104216][ T1206] usb 5-1: new full-speed USB device number 5 using dummy_hcd [ 110.421216][ T5937] usb 1-1: new full-speed USB device number 3 using dummy_hcd [ 110.523716][ T1206] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 110.613084][ T1206] usb 5-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 110.640969][ T1206] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 110.651962][ T30] audit: type=1400 audit(1748476579.857:214): avc: denied { getopt } for pid=6374 comm="syz.2.122" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 110.673829][ T5937] usb 1-1: config 1 contains an unexpected descriptor of type 0x2, skipping [ 110.686930][ T1206] usb 5-1: Product: syz [ 110.719450][ T30] audit: type=1400 audit(1748476579.877:215): avc: denied { ioctl } for pid=6374 comm="syz.2.122" path="anon_inode:[userfaultfd]" dev="anon_inodefs" ino=10251 ioctlcmd=0xaa3f scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:sysadm_t tclass=anon_inode permissive=1 [ 110.756950][ T30] audit: type=1400 audit(1748476579.887:216): avc: denied { create } for pid=6374 comm="syz.2.122" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=caif_socket permissive=1 [ 110.778600][ T1206] usb 5-1: Manufacturer: syz [ 110.787615][ T5937] usb 1-1: config 1 has an invalid descriptor of length 48, skipping remainder of the config [ 110.817397][ T1206] usb 5-1: SerialNumber: syz [ 110.846700][ T1206] usb 5-1: config 0 descriptor?? [ 110.854257][ T5937] usb 1-1: config 1 has 2 interfaces, different from the descriptor's value: 3 [ 110.898848][ T1206] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 110.910542][ T5937] usb 1-1: config 1 has no interface number 1 [ 110.918023][ T5937] usb 1-1: config 1 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 0 [ 110.931689][ T1206] dvb-usb: bulk message failed: -22 (3/0) [ 110.938406][ T5937] usb 1-1: config 1 interface 2 altsetting 1 endpoint 0x82 has invalid maxpacket 12336, setting to 64 [ 110.956282][ T1206] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 110.987571][ T5937] usb 1-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 111.037063][ T5937] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 111.060377][ T5937] usb 1-1: Product: syz [ 111.064957][ T1206] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 111.085866][ T5937] usb 1-1: Manufacturer: syz [ 111.091001][ T1206] usb 5-1: media controller created [ 111.097904][ T5937] usb 1-1: SerialNumber: syz [ 111.113202][ T1206] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 111.138169][ T1206] dvb-usb: bulk message failed: -22 (6/0) [ 111.164063][ T1206] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 111.310694][ T5937] usb 1-1: USB disconnect, device number 3 [ 111.325626][ T6390] overlayfs: failed to resolve './file0': -2 [ 111.341715][ T1206] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.4/usb5/5-1/input/input11 [ 111.408552][ T6391] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=25621 sclass=netlink_xfrm_socket pid=6391 comm=syz.3.125 [ 111.492480][ T1206] dvb-usb: schedule remote query interval to 150 msecs. [ 111.499593][ T1206] dvb-usb: bulk message failed: -22 (3/0) [ 111.520770][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 111.535036][ T6018] udevd[6018]: error opening ATTR{/sys/devices/platform/dummy_hcd.0/usb1/1-1/1-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 111.622000][ T1206] usb 5-1: USB disconnect, device number 5 [ 112.002827][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 112.270329][ T5937] usb 1-1: new full-speed USB device number 4 using dummy_hcd [ 112.890000][ T30] audit: type=1400 audit(1748476582.087:217): avc: denied { create } for pid=6404 comm="syz.1.128" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 113.128237][ T5937] usb 1-1: unable to get BOS descriptor or descriptor too short [ 113.151308][ T30] audit: type=1400 audit(1748476582.347:218): avc: denied { name_bind } for pid=6403 comm="syz.4.129" src=20002 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unreserved_port_t tclass=tcp_socket permissive=1 [ 113.430570][ T5937] usb 1-1: unable to read config index 0 descriptor/start: -71 [ 113.455968][ T5937] usb 1-1: can't read configurations, error -71 [ 113.534834][ T30] audit: type=1400 audit(1748476582.347:219): avc: denied { node_bind } for pid=6403 comm="syz.4.129" src=20002 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=tcp_socket permissive=1 [ 114.464539][ T30] audit: type=1400 audit(1748476583.667:220): avc: denied { nlmsg_write } for pid=6410 comm="syz.3.130" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 114.600194][ T1206] usb 3-1: new full-speed USB device number 9 using dummy_hcd [ 114.720141][ T5937] usb 5-1: new high-speed USB device number 6 using dummy_hcd [ 115.650261][ T5937] usb 5-1: device descriptor read/64, error -71 [ 115.706474][ T6432] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=25621 sclass=netlink_xfrm_socket pid=6432 comm=syz.1.137 [ 115.822556][ T1206] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 115.890695][ T1206] usb 3-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 115.930699][ T1206] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 115.946926][ T1206] usb 3-1: Product: syz [ 115.974030][ T1206] usb 3-1: Manufacturer: syz [ 116.118125][ T5937] usb 5-1: new high-speed USB device number 7 using dummy_hcd [ 116.134225][ T1206] usb 3-1: SerialNumber: syz [ 116.194042][ T1206] usb 3-1: config 0 descriptor?? [ 116.197130][ T6437] bridge0: port 3(netdevsim0) entered disabled state [ 116.205771][ T6437] bridge0: port 2(bridge_slave_1) entered disabled state [ 116.213023][ T6437] bridge0: port 1(bridge_slave_0) entered disabled state [ 116.225326][ T6437] bridge0: entered allmulticast mode [ 116.228952][ T1206] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 116.236970][ T6437] netdevsim netdevsim3 netdevsim0: left allmulticast mode [ 116.249524][ T1206] dvb-usb: bulk message failed: -22 (3/0) [ 116.249609][ T6437] netdevsim netdevsim3 netdevsim0: left promiscuous mode [ 116.263394][ T6437] bridge0: port 3(netdevsim0) entered disabled state [ 116.273084][ T6437] bridge_slave_1: left allmulticast mode [ 116.274206][ T1206] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 116.282409][ T6437] bridge_slave_1: left promiscuous mode [ 116.288997][ T1206] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 116.296425][ T6437] bridge0: port 2(bridge_slave_1) entered disabled state [ 116.304166][ T5937] usb 5-1: device descriptor read/64, error -71 [ 116.327445][ T6437] bridge_slave_0: left allmulticast mode [ 116.334473][ T6437] bridge_slave_0: left promiscuous mode [ 116.340182][ T1206] usb 3-1: media controller created [ 116.351761][ T1206] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 116.367024][ T1206] dvb-usb: bulk message failed: -22 (6/0) [ 116.376127][ T1206] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 116.459181][ T5937] usb usb5-port1: attempt power cycle [ 116.470110][ T6437] bridge0: port 1(bridge_slave_0) entered disabled state [ 116.478340][ T6423] dibusb: i2c wr: len=61 is too big! [ 116.478340][ T6423] [ 116.493005][ T1206] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.2/usb3/3-1/input/input12 [ 116.625230][ T1206] dvb-usb: schedule remote query interval to 150 msecs. [ 116.642359][ T1206] dvb-usb: bulk message failed: -22 (3/0) [ 117.102043][ T9] dvb-usb: bulk message failed: -22 (1/0) [ 117.107823][ T9] dvb-usb: error while querying for an remote control event. [ 117.128381][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 117.156731][ T5937] usb 5-1: new high-speed USB device number 8 using dummy_hcd [ 117.187954][ T1206] usb 3-1: USB disconnect, device number 9 [ 117.211024][ T5937] usb 5-1: device descriptor read/8, error -71 [ 117.261831][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 117.460892][ T5937] usb 5-1: new high-speed USB device number 9 using dummy_hcd [ 117.503418][ T5937] usb 5-1: device descriptor read/8, error -71 [ 117.953418][ T30] audit: type=1400 audit(1748476586.937:221): avc: denied { bind } for pid=6453 comm="syz.0.143" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 118.031980][ T30] audit: type=1400 audit(1748476586.947:222): avc: denied { write } for pid=6453 comm="syz.0.143" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 118.050390][ T5937] usb usb5-port1: unable to enumerate USB device [ 118.224108][ T30] audit: type=1400 audit(1748476586.947:223): avc: denied { setopt } for pid=6453 comm="syz.0.143" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 120.283814][ T30] audit: type=1400 audit(1748476589.487:224): avc: denied { listen } for pid=6473 comm="syz.0.148" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 120.514938][ T30] audit: type=1400 audit(1748476589.717:225): avc: denied { ioctl } for pid=6479 comm="syz.4.149" path="/dev/vhost-vsock" dev="devtmpfs" ino=1275 ioctlcmd=0xaf01 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:vhost_device_t tclass=chr_file permissive=1 [ 120.730096][ T30] audit: type=1400 audit(1748476589.917:226): avc: denied { read write } for pid=6479 comm="syz.4.149" name="event0" dev="devtmpfs" ino=918 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 120.804708][ T30] audit: type=1400 audit(1748476589.917:227): avc: denied { open } for pid=6479 comm="syz.4.149" path="/dev/input/event0" dev="devtmpfs" ino=918 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 120.838693][ T30] audit: type=1400 audit(1748476589.917:228): avc: denied { ioctl } for pid=6479 comm="syz.4.149" path="/dev/input/event0" dev="devtmpfs" ino=918 ioctlcmd=0x4518 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 122.297444][ T6502] xt_bpf: check failed: parse error [ 122.408615][ T6508] netlink: 'syz.0.148': attribute type 4 has an invalid length. [ 122.434335][ T6509] netlink: 'syz.1.155': attribute type 2 has an invalid length. [ 122.559010][ T6509] ‰lm;Ê-: entered promiscuous mode [ 122.581607][ T6509] netlink: 44 bytes leftover after parsing attributes in process `syz.1.155'. [ 122.597138][ T6509] netlink: 44 bytes leftover after parsing attributes in process `syz.1.155'. [ 122.680600][ T5861] usb 5-1: new full-speed USB device number 10 using dummy_hcd [ 122.766630][ T30] audit: type=1400 audit(1748476591.967:229): avc: denied { read } for pid=6510 comm="syz.1.156" dev="sockfs" ino=9761 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_netfilter_socket permissive=1 [ 122.833956][ T5861] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 122.847669][ T5861] usb 5-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 122.859524][ T5861] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 122.868354][ T5861] usb 5-1: Product: syz [ 122.878315][ T5861] usb 5-1: Manufacturer: syz [ 122.883619][ T5861] usb 5-1: SerialNumber: syz [ 122.897273][ T5861] usb 5-1: config 0 descriptor?? [ 122.911952][ T5861] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 122.925680][ T5861] dvb-usb: bulk message failed: -22 (3/0) [ 122.954810][ T5861] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 122.964698][ T5861] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 122.976945][ T5861] usb 5-1: media controller created [ 123.017760][ T5861] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 123.050964][ T5861] dvb-usb: bulk message failed: -22 (6/0) [ 123.056821][ T5861] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 123.084737][ T5861] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.4/usb5/5-1/input/input13 [ 123.114732][ T6506] dibusb: i2c wr: len=61 is too big! [ 123.114732][ T6506] [ 123.172465][ T5861] dvb-usb: schedule remote query interval to 150 msecs. [ 123.200033][ T5861] dvb-usb: bulk message failed: -22 (3/0) [ 123.335506][ T30] audit: type=1400 audit(1748476592.537:230): avc: denied { read } for pid=6518 comm="syz.0.158" name="sg0" dev="devtmpfs" ino=761 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 123.415297][ T920] dvb-usb: bulk message failed: -22 (1/0) [ 123.421061][ T5861] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 123.435154][ T920] dvb-usb: error while querying for an remote control event. [ 123.938115][ T30] audit: type=1400 audit(1748476592.537:231): avc: denied { open } for pid=6518 comm="syz.0.158" path="/dev/sg0" dev="devtmpfs" ino=761 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 123.969874][ T30] audit: type=1400 audit(1748476593.133:232): avc: denied { create } for pid=6518 comm="syz.0.158" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 124.199346][ T920] dvb-usb: bulk message failed: -22 (1/0) [ 124.216494][ T5861] usb 5-1: USB disconnect, device number 10 [ 124.229726][ T920] dvb-usb: error while querying for an remote control event. [ 124.324124][ T5861] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 124.596610][ T30] audit: type=1400 audit(1748476593.793:233): avc: denied { bind } for pid=6526 comm="syz.2.161" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 124.767435][ T6535] netlink: 17248 bytes leftover after parsing attributes in process `syz.2.161'. [ 125.358860][ T30] audit: type=1400 audit(1748476593.803:234): avc: denied { write } for pid=6526 comm="syz.2.161" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 126.137638][ T6553] trusted_key: syz.2.168 sent an empty control message without MSG_MORE. [ 126.148897][ T30] audit: type=1400 audit(1748476595.353:235): avc: denied { execute } for pid=6547 comm="syz.0.167" path="/31/pids.events" dev="tmpfs" ino=192 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 126.471405][ T30] audit: type=1400 audit(1748476595.633:236): avc: denied { connect } for pid=6557 comm="syz.0.170" lport=20001 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 126.665671][ T30] audit: type=1400 audit(1748476595.633:237): avc: denied { name_connect } for pid=6557 comm="syz.0.170" dest=20001 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unreserved_port_t tclass=sctp_socket permissive=1 [ 126.690245][ T30] audit: type=1400 audit(1748476595.803:238): avc: denied { map } for pid=6557 comm="syz.0.170" path="/dev/video3" dev="devtmpfs" ino=934 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:v4l_device_t tclass=chr_file permissive=1 [ 126.754635][ T30] audit: type=1400 audit(1748476595.823:239): avc: denied { read } for pid=6562 comm="syz.1.172" name="ptp0" dev="devtmpfs" ino=1265 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 126.781017][ T30] audit: type=1400 audit(1748476595.823:240): avc: denied { open } for pid=6562 comm="syz.1.172" path="/dev/ptp0" dev="devtmpfs" ino=1265 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 127.098507][ T30] audit: type=1400 audit(1748476595.823:241): avc: denied { setopt } for pid=6557 comm="syz.0.170" lport=20001 faddr=::ffff:172.20.20.20 fport=20001 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 127.123607][ T30] audit: type=1400 audit(1748476595.843:242): avc: denied { ioctl } for pid=6562 comm="syz.1.172" path="/dev/ptp0" dev="devtmpfs" ino=1265 ioctlcmd=0x3d0f scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 127.703055][ T30] audit: type=1400 audit(1748476596.913:243): avc: denied { create } for pid=6576 comm="syz.2.174" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 128.493347][ T6578] Bluetooth: hci5: Frame reassembly failed (-84) [ 128.516368][ T54] Bluetooth: hci5: Frame reassembly failed (-84) [ 128.539331][ T6575] Bluetooth: hci5: Frame reassembly failed (-84) [ 129.453450][ T6600] netlink: 4 bytes leftover after parsing attributes in process `syz.0.181'. [ 129.502062][ T6601] binder: 6597:6601 ioctl 40085112 2000000001c0 returned -22 [ 130.019088][ T6598] could not allocate digest TFM handle sha1-ce [ 130.563306][ T6607] Can't find a SQUASHFS superblock on nullb0 [ 130.877450][ T5813] Bluetooth: hci5: command 0x1003 tx timeout [ 130.910191][ T5134] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 131.026333][ T30] kauditd_printk_skb: 3 callbacks suppressed [ 131.026342][ T30] audit: type=1400 audit(1748476599.751:247): avc: denied { accept } for pid=6606 comm="syz.3.183" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_dgram_socket permissive=1 [ 131.060302][ T30] audit: type=1800 audit(1748476599.761:248): pid=6607 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=collect_data cause=failed comm="syz.3.183" name="SYSV00000000" dev="tmpfs" ino=0 res=0 errno=0 [ 131.161134][ T5134] Bluetooth: hci3: Controller not accepting commands anymore: ncmd = 0 [ 131.170265][ T5134] Bluetooth: hci3: Injecting HCI hardware error event [ 131.177481][ T5813] Bluetooth: hci3: hardware error 0x00 [ 131.216062][ T30] audit: type=1400 audit(1748476599.761:249): avc: denied { mounton } for pid=6606 comm="syz.3.183" path="/syzcgroup/unified/syz3" dev="cgroup2" ino=67 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cgroup_t tclass=dir permissive=1 [ 131.504696][ T30] audit: type=1400 audit(1748476600.711:250): avc: denied { create } for pid=6616 comm="syz.0.186" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 131.608580][ T920] usb 5-1: new full-speed USB device number 11 using dummy_hcd [ 131.640128][ T5134] Bluetooth: hci1: command tx timeout [ 131.650574][ T30] audit: type=1400 audit(1748476600.731:251): avc: denied { bind } for pid=6616 comm="syz.0.186" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 131.713251][ T30] audit: type=1400 audit(1748476600.731:252): avc: denied { name_bind } for pid=6616 comm="syz.0.186" src=118 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:port_t tclass=icmp_socket permissive=1 [ 131.950930][ T920] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 131.971292][ T30] audit: type=1400 audit(1748476600.731:253): avc: denied { node_bind } for pid=6616 comm="syz.0.186" src=118 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=icmp_socket permissive=1 [ 131.991673][ C1] vkms_vblank_simulate: vblank timer overrun [ 132.020023][ T920] usb 5-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 132.116774][ T920] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 132.169665][ T920] usb 5-1: Product: syz [ 132.174814][ T30] audit: type=1400 audit(1748476601.151:254): avc: denied { create } for pid=6621 comm="syz.2.187" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 132.210359][ T920] usb 5-1: Manufacturer: syz [ 132.214973][ T920] usb 5-1: SerialNumber: syz [ 132.233549][ T920] usb 5-1: config 0 descriptor?? [ 132.242217][ T30] audit: type=1400 audit(1748476601.151:255): avc: denied { ioctl } for pid=6613 comm="syz.4.184" path="/dev/raw-gadget" dev="devtmpfs" ino=820 ioctlcmd=0x5503 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:device_t tclass=chr_file permissive=1 [ 132.296479][ T30] audit: type=1400 audit(1748476601.341:256): avc: denied { read } for pid=6627 comm="syz.1.189" name="system" dev="devtmpfs" ino=700 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:device_t tclass=chr_file permissive=1 [ 132.337399][ T6633] xt_cluster: you have exceeded the maximum number of cluster nodes (127 > 32) [ 132.412266][ T1299] ieee802154 phy0 wpan0: encryption failed: -22 [ 132.418704][ T1299] ieee802154 phy1 wpan1: encryption failed: -22 [ 132.422092][ T920] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 132.438200][ T920] dvb-usb: bulk message failed: -22 (3/0) [ 132.492210][ T920] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 132.501692][ T920] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 132.517554][ T920] usb 5-1: media controller created [ 132.531809][ T920] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 132.660788][ T13] Bluetooth: hci6: Frame reassembly failed (-84) [ 132.676405][ T920] dvb-usb: bulk message failed: -22 (6/0) [ 132.710457][ T920] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 132.782948][ T920] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.4/usb5/5-1/input/input14 [ 132.828187][ T920] dvb-usb: schedule remote query interval to 150 msecs. [ 132.856981][ T920] dvb-usb: bulk message failed: -22 (3/0) [ 132.882884][ T920] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 132.915823][ T920] usb 5-1: USB disconnect, device number 11 [ 132.981614][ T920] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 133.320267][ T5813] Bluetooth: hci3: Opcode 0x0c03 failed: -110 [ 133.549626][ T6648] Bluetooth: hci7: Frame reassembly failed (-84) [ 133.561113][ T6648] Bluetooth: hci7: Frame reassembly failed (-84) [ 133.635052][ T13] Bluetooth: hci7: Frame reassembly failed (-84) [ 133.892284][ T6650] FAULT_INJECTION: forcing a failure. [ 133.892284][ T6650] name fail_usercopy, interval 1, probability 0, space 0, times 1 [ 133.905551][ T6650] CPU: 0 UID: 0 PID: 6650 Comm: syz.4.195 Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 133.905573][ T6650] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 133.905582][ T6650] Call Trace: [ 133.905588][ T6650] [ 133.905594][ T6650] dump_stack_lvl+0x16c/0x1f0 [ 133.905615][ T6650] should_fail_ex+0x512/0x640 [ 133.905640][ T6650] _copy_from_iter+0x29f/0x16f0 [ 133.905659][ T6650] ? __pfx_avc_has_perm+0x10/0x10 [ 133.905683][ T6650] ? __pfx__copy_from_iter+0x10/0x10 [ 133.905705][ T6650] ? sock_has_perm+0x259/0x2f0 [ 133.905727][ T6650] ? __pfx_sock_has_perm+0x10/0x10 [ 133.905753][ T6650] hci_sock_sendmsg+0x46d/0x25e0 [ 133.905778][ T6650] ? __pfx_hci_sock_sendmsg+0x10/0x10 [ 133.905806][ T6650] sock_write_iter+0x4ff/0x5b0 [ 133.905824][ T6650] ? __pfx_sock_write_iter+0x10/0x10 [ 133.905851][ T6650] ? bpf_lsm_file_permission+0x9/0x10 [ 133.905873][ T6650] ? security_file_permission+0x71/0x210 [ 133.905890][ T6650] ? rw_verify_area+0xcf/0x680 [ 133.905917][ T6650] vfs_write+0x6c4/0x1150 [ 133.905942][ T6650] ? __pfx_sock_write_iter+0x10/0x10 [ 133.905962][ T6650] ? __pfx_vfs_write+0x10/0x10 [ 133.905984][ T6650] ? find_held_lock+0x2b/0x80 [ 133.906022][ T6650] ksys_write+0x1f8/0x250 [ 133.906046][ T6650] ? __pfx_ksys_write+0x10/0x10 [ 133.906079][ T6650] do_syscall_64+0xcd/0x4c0 [ 133.906098][ T6650] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 133.906114][ T6650] RIP: 0033:0x7fd5c258e969 [ 133.906128][ T6650] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 133.906143][ T6650] RSP: 002b:00007fd5c3495038 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 133.906158][ T6650] RAX: ffffffffffffffda RBX: 00007fd5c27b5fa0 RCX: 00007fd5c258e969 [ 133.906169][ T6650] RDX: 000000000000000d RSI: 0000200000000000 RDI: 0000000000000006 [ 133.906178][ T6650] RBP: 00007fd5c3495090 R08: 0000000000000000 R09: 0000000000000000 [ 133.906187][ T6650] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000002 [ 133.906196][ T6650] R13: 0000000000000000 R14: 00007fd5c27b5fa0 R15: 00007ffcc879e938 [ 133.906218][ T6650] [ 134.204739][ T5825] Bluetooth: hci5: command 0x1003 tx timeout [ 134.211229][ T5134] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 134.480132][ T5861] usb 5-1: new full-speed USB device number 12 using dummy_hcd [ 134.600154][ T920] usb 1-1: new full-speed USB device number 6 using dummy_hcd [ 134.662058][ T5861] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 134.675146][ T5861] usb 5-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 134.684286][ T5811] Bluetooth: hci6: Opcode 0x1003 failed: -110 [ 134.694306][ T5861] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 134.774092][ T5861] usb 5-1: Product: syz [ 134.778442][ T5861] usb 5-1: Manufacturer: syz [ 134.787132][ T5861] usb 5-1: SerialNumber: syz [ 134.796997][ T920] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 134.808606][ T5861] usb 5-1: config 0 descriptor?? [ 134.816051][ T5861] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 134.830234][ T5861] dvb-usb: bulk message failed: -22 (3/0) [ 134.836818][ T920] usb 1-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 134.851501][ T920] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 134.859508][ T920] usb 1-1: Product: syz [ 134.867189][ T5861] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 134.875627][ T920] usb 1-1: Manufacturer: syz [ 134.880393][ T920] usb 1-1: SerialNumber: syz [ 134.885736][ T5861] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 134.903601][ T920] usb 1-1: config 0 descriptor?? [ 134.922430][ T920] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 134.934389][ T5861] usb 5-1: media controller created [ 134.947369][ T5861] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 134.958441][ T920] dvb-usb: bulk message failed: -22 (3/0) [ 134.970957][ T5861] dvb-usb: bulk message failed: -22 (6/0) [ 134.976763][ T5861] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 134.993855][ T5861] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.4/usb5/5-1/input/input15 [ 135.007164][ T920] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 135.017375][ T6652] dibusb: i2c wr: len=61 is too big! [ 135.017375][ T6652] [ 135.032394][ T920] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 135.044759][ T920] usb 1-1: media controller created [ 135.050731][ T5861] dvb-usb: schedule remote query interval to 150 msecs. [ 135.057709][ T5861] dvb-usb: bulk message failed: -22 (3/0) [ 135.065800][ T920] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 135.081508][ T920] dvb-usb: bulk message failed: -22 (6/0) [ 135.087284][ T920] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 135.103872][ T5861] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 135.119111][ T920] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.0/usb1/1-1/input/input16 [ 135.139885][ T6656] dibusb: i2c wr: len=61 is too big! [ 135.139885][ T6656] [ 135.160364][ T1206] usb 4-1: new high-speed USB device number 10 using dummy_hcd [ 135.169887][ T5861] usb 5-1: USB disconnect, device number 12 [ 135.179757][ T920] dvb-usb: schedule remote query interval to 150 msecs. [ 135.193326][ T920] dvb-usb: bulk message failed: -22 (3/0) [ 135.210641][ T920] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 135.229519][ T5861] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 135.280401][ T920] usb 1-1: USB disconnect, device number 6 [ 135.340676][ T1206] usb 4-1: Using ep0 maxpacket: 16 [ 135.343279][ T920] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 135.356137][ T1206] usb 4-1: config index 0 descriptor too short (expected 821, got 36) [ 135.392641][ T1206] usb 4-1: config 187 has too many interfaces: 41, using maximum allowed: 32 [ 135.405562][ T1206] usb 4-1: config 187 has an invalid descriptor of length 0, skipping remainder of the config [ 135.432225][ T1206] usb 4-1: config 187 has 0 interfaces, different from the descriptor's value: 41 [ 135.442713][ T1206] usb 4-1: New USB device found, idVendor=04d8, idProduct=00dd, bcdDevice= 0.00 [ 135.452635][ T1206] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 135.720140][ T5813] Bluetooth: hci7: Opcode 0x1003 failed: -110 [ 135.721674][ T5134] Bluetooth: hci7: command 0x1003 tx timeout [ 137.069451][ T1206] usb 4-1: string descriptor 0 read error: -71 [ 137.096993][ T1206] usb 4-1: USB disconnect, device number 10 [ 139.296014][ T30] kauditd_printk_skb: 5 callbacks suppressed [ 139.319514][ T30] audit: type=1400 audit(1748476608.501:262): avc: denied { ioctl } for pid=6700 comm="syz.3.212" path="socket:[10211]" dev="sockfs" ino=10211 ioctlcmd=0x89e1 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 139.446285][ T6708] netlink: 32 bytes leftover after parsing attributes in process `syz.2.213'. [ 139.527763][ T30] audit: type=1400 audit(1748476608.731:263): avc: denied { write } for pid=6707 comm="syz.2.213" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=qipcrtr_socket permissive=1 [ 139.758201][ T6712] FAULT_INJECTION: forcing a failure. [ 139.758201][ T6712] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 139.772760][ T6712] CPU: 0 UID: 0 PID: 6712 Comm: syz.1.215 Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 139.772782][ T6712] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 139.772790][ T6712] Call Trace: [ 139.772796][ T6712] [ 139.772802][ T6712] dump_stack_lvl+0x16c/0x1f0 [ 139.772828][ T6712] should_fail_ex+0x512/0x640 [ 139.772847][ T6712] _copy_to_user+0x32/0xd0 [ 139.772866][ T6712] simple_read_from_buffer+0xcb/0x170 [ 139.772893][ T6712] proc_fail_nth_read+0x197/0x270 [ 139.772920][ T6712] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 139.772946][ T6712] ? rw_verify_area+0xcf/0x680 [ 139.772968][ T6712] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 139.772992][ T6712] vfs_read+0x1e4/0xc60 [ 139.773011][ T6712] ? __pfx___mutex_lock+0x10/0x10 [ 139.773021][ T6712] ? __pfx_vfs_read+0x10/0x10 [ 139.773040][ T6712] ? __fget_files+0x20e/0x3c0 [ 139.773053][ T6712] ksys_read+0x12a/0x250 [ 139.773068][ T6712] ? __pfx_ksys_read+0x10/0x10 [ 139.773084][ T6712] ? fput+0x70/0xf0 [ 139.773097][ T6712] do_syscall_64+0xcd/0x4c0 [ 139.773108][ T6712] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 139.773119][ T6712] RIP: 0033:0x7f40e418d37c [ 139.773128][ T6712] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 139.773138][ T6712] RSP: 002b:00007f40e4fcd030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 139.773147][ T6712] RAX: ffffffffffffffda RBX: 00007f40e43b5fa0 RCX: 00007f40e418d37c [ 139.773153][ T6712] RDX: 000000000000000f RSI: 00007f40e4fcd0a0 RDI: 0000000000000004 [ 139.773159][ T6712] RBP: 00007f40e4fcd090 R08: 0000000000000000 R09: 0000000000000000 [ 139.773165][ T6712] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 139.773170][ T6712] R13: 0000000000000000 R14: 00007f40e43b5fa0 R15: 00007fff9dd5b9e8 [ 139.773183][ T6712] [ 139.777398][ T30] audit: type=1400 audit(1748476608.961:264): avc: denied { ioctl } for pid=6711 comm="syz.1.215" path="/dev/ptyq6" dev="devtmpfs" ino=125 ioctlcmd=0x5423 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:bsdpty_device_t tclass=chr_file permissive=1 [ 141.817400][ T30] audit: type=1400 audit(1748476611.021:265): avc: denied { associate } for pid=6729 comm="syz.4.221" name="161" scontext=root:object_r:sysadm_t tcontext=system_u:object_r:proc_t tclass=filesystem permissive=1 [ 142.104351][ T30] audit: type=1400 audit(1748476611.305:266): avc: denied { search } for pid=5478 comm="dhcpcd" name="/" dev="tmpfs" ino=1 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 142.153432][ T30] audit: type=1400 audit(1748476611.305:267): avc: denied { search } for pid=5478 comm="dhcpcd" name="udev" dev="tmpfs" ino=9 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 142.185121][ T6739] overlayfs: failed to resolve './file0': -2 [ 142.187936][ T30] audit: type=1400 audit(1748476611.305:268): avc: denied { search } for pid=5478 comm="dhcpcd" name="data" dev="tmpfs" ino=14 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 142.219791][ T30] audit: type=1400 audit(1748476611.305:269): avc: denied { read } for pid=5478 comm="dhcpcd" name="n100" dev="tmpfs" ino=2996 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1 [ 142.265286][ T30] audit: type=1400 audit(1748476611.335:270): avc: denied { open } for pid=5478 comm="dhcpcd" path="/run/udev/data/n100" dev="tmpfs" ino=2996 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1 [ 142.334857][ T30] audit: type=1400 audit(1748476611.335:271): avc: denied { getattr } for pid=5478 comm="dhcpcd" path="/run/udev/data/n100" dev="tmpfs" ino=2996 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1 [ 142.389803][ T6745] UDPLite: UDP-Lite is deprecated and scheduled to be removed in 2025, please contact the netdev mailing list [ 142.624887][ T6751] vhci_hcd vhci_hcd.0: pdev(4) rhport(0) sockfd(7) [ 142.631533][ T6751] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 142.702529][ T6751] vhci_hcd vhci_hcd.0: Device attached [ 142.743752][ T6754] vhci_hcd vhci_hcd.0: pdev(4) rhport(1) sockfd(9) [ 142.750290][ T6754] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 142.759379][ T6754] vhci_hcd vhci_hcd.0: Device attached [ 142.782736][ T6751] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 143.289534][ T6751] vhci_hcd vhci_hcd.0: pdev(4) rhport(3) sockfd(14) [ 143.296166][ T6751] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 143.311034][ T6751] vhci_hcd vhci_hcd.0: Device attached [ 143.320270][ T5937] vhci_hcd: vhci_device speed not set [ 143.335744][ T6751] vhci_hcd vhci_hcd.0: pdev(4) rhport(4) sockfd(17) [ 143.342348][ T6751] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 143.383240][ T6751] vhci_hcd vhci_hcd.0: Device attached [ 143.390164][ T5937] usb 41-1: new full-speed USB device number 2 using vhci_hcd [ 143.550707][ T6751] vhci_hcd vhci_hcd.0: pdev(4) rhport(5) sockfd(19) [ 143.557337][ T6751] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 143.579039][ T6754] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 143.656144][ T6751] vhci_hcd vhci_hcd.0: Device attached [ 143.841142][ T6774] vhci_hcd vhci_hcd.0: pdev(4) rhport(0) sockfd(24) [ 143.847776][ T6774] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 143.881795][ T6774] vhci_hcd vhci_hcd.0: Device attached [ 143.894481][ T6751] vhci_hcd vhci_hcd.0: pdev(4) rhport(7) sockfd(21) [ 143.901082][ T6751] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 143.920034][ T6751] vhci_hcd vhci_hcd.0: Device attached [ 144.010763][ T6751] vhci_hcd vhci_hcd.0: port 0 already used [ 144.045765][ T6778] vhci_hcd: connection closed [ 144.046691][ T306] vhci_hcd: stop threads [ 144.057214][ T6765] vhci_hcd: connection closed [ 144.057217][ T6756] vhci_hcd: connection closed [ 144.061950][ T6763] vhci_hcd: connection closed [ 144.066755][ T6752] vhci_hcd: connection reset by peer [ 144.068131][ T306] vhci_hcd: release socket [ 144.086354][ T6769] vhci_hcd: connection closed [ 144.088052][ T306] vhci_hcd: disconnect device [ 144.090093][ T6776] vhci_hcd: connection closed [ 144.097484][ T306] vhci_hcd: stop threads [ 144.115249][ T306] vhci_hcd: release socket [ 144.119832][ T306] vhci_hcd: disconnect device [ 144.127021][ T306] vhci_hcd: stop threads [ 144.136046][ T306] vhci_hcd: release socket [ 144.142777][ T306] vhci_hcd: disconnect device [ 144.148947][ T306] vhci_hcd: stop threads [ 144.155590][ T306] vhci_hcd: release socket [ 144.163459][ T306] vhci_hcd: disconnect device [ 144.168473][ T306] vhci_hcd: stop threads [ 144.175257][ T306] vhci_hcd: release socket [ 144.182919][ T306] vhci_hcd: disconnect device [ 144.195236][ T306] vhci_hcd: stop threads [ 144.199526][ T306] vhci_hcd: release socket [ 144.205061][ T306] vhci_hcd: disconnect device [ 144.212275][ T306] vhci_hcd: stop threads [ 144.221024][ T306] vhci_hcd: release socket [ 144.225656][ T306] vhci_hcd: disconnect device [ 144.280406][ T10] usb 3-1: new high-speed USB device number 10 using dummy_hcd [ 144.555712][ T10] usb 3-1: Using ep0 maxpacket: 8 [ 144.562221][ T10] usb 3-1: config 179 has an invalid interface number: 65 but max is 0 [ 144.581067][ T10] usb 3-1: config 179 has no interface number 0 [ 144.606259][ T10] usb 3-1: config 179 interface 65 altsetting 0 endpoint 0xF has an invalid bInterval 0, changing to 7 [ 144.617621][ T10] usb 3-1: config 179 interface 65 altsetting 0 endpoint 0xF has invalid maxpacket 1025, setting to 1024 [ 144.634193][ T10] usb 3-1: config 179 interface 65 altsetting 0 endpoint 0x83 has an invalid bInterval 0, changing to 7 [ 144.645451][ T10] usb 3-1: config 179 interface 65 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 23 [ 144.660255][ T10] usb 3-1: New USB device found, idVendor=12ab, idProduct=90a3, bcdDevice=1e.eb [ 144.669397][ T10] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 144.677491][ T6791] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(7) [ 144.683993][ T6791] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 144.692464][ T6791] vhci_hcd vhci_hcd.0: Device attached [ 144.737653][ T30] kauditd_printk_skb: 3 callbacks suppressed [ 144.737666][ T30] audit: type=1400 audit(1748476613.935:275): avc: denied { create } for pid=6794 comm="syz.4.234" name="#9" scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 144.760106][ T6791] vhci_hcd vhci_hcd.0: pdev(1) rhport(1) sockfd(9) [ 144.770523][ T6791] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 144.792855][ T6775] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 144.805489][ T30] audit: type=1400 audit(1748476613.935:276): avc: denied { link } for pid=6794 comm="syz.4.234" name="#9" dev="tmpfs" ino=300 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 144.880156][ T9] vhci_hcd: vhci_device speed not set [ 144.890327][ T6791] vhci_hcd vhci_hcd.0: Device attached [ 144.908290][ T6791] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 144.940152][ T9] usb 35-1: new full-speed USB device number 2 using vhci_hcd [ 144.949033][ T30] audit: type=1400 audit(1748476613.935:277): avc: denied { rename } for pid=6794 comm="syz.4.234" name="#a" dev="tmpfs" ino=300 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 144.973551][ T6800] netlink: 24 bytes leftover after parsing attributes in process `syz.4.235'. [ 144.991498][ T6802] vhci_hcd vhci_hcd.0: pdev(1) rhport(4) sockfd(17) [ 144.998107][ T6802] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 145.016328][ T6775] netlink: 4 bytes leftover after parsing attributes in process `syz.2.230'. [ 145.039809][ T30] audit: type=1326 audit(1748476614.235:278): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6798 comm="syz.4.235" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fd5c258e969 code=0x7ffc0000 [ 145.041987][ T5896] usb 3-1: USB disconnect, device number 10 [ 145.063157][ C0] xpad 3-1:179.65: xpad_irq_in - usb_submit_urb failed with result -19 [ 145.077595][ C0] xpad 3-1:179.65: xpad_irq_out - usb_submit_urb failed with result -19 [ 145.114653][ T6802] vhci_hcd vhci_hcd.0: Device attached [ 145.116956][ T6791] vhci_hcd vhci_hcd.0: pdev(1) rhport(3) sockfd(13) [ 145.126730][ T6791] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 145.259176][ T6791] vhci_hcd vhci_hcd.0: Device attached [ 145.280216][ T5861] usb 1-1: new full-speed USB device number 7 using dummy_hcd [ 145.416278][ T30] audit: type=1326 audit(1748476614.235:279): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6798 comm="syz.4.235" exe="/root/syz-executor" sig=0 arch=c000003e syscall=266 compat=0 ip=0x7fd5c258e969 code=0x7ffc0000 [ 145.418191][ T6802] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 145.444506][ T6808] vhci_hcd vhci_hcd.0: pdev(1) rhport(5) sockfd(20) [ 145.454505][ T6808] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 145.474385][ T30] audit: type=1326 audit(1748476614.235:280): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6798 comm="syz.4.235" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fd5c258e969 code=0x7ffc0000 [ 145.509442][ T30] audit: type=1326 audit(1748476614.235:281): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6798 comm="syz.4.235" exe="/root/syz-executor" sig=0 arch=c000003e syscall=278 compat=0 ip=0x7fd5c258e969 code=0x7ffc0000 [ 145.533923][ T6813] netlink: 4 bytes leftover after parsing attributes in process `syz.4.235'. [ 145.543064][ T6808] vhci_hcd vhci_hcd.0: Device attached [ 145.555322][ T6791] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(23) [ 145.561910][ T6791] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 145.572933][ T6791] vhci_hcd vhci_hcd.0: Device attached [ 145.572941][ T6802] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 145.581582][ T6802] vhci_hcd vhci_hcd.0: port 0 already used [ 145.605317][ T6817] vhci_hcd: connection closed [ 145.605542][ T6810] vhci_hcd: connection closed [ 145.605681][ T6803] vhci_hcd: connection closed [ 145.613889][ T6799] vhci_hcd: connection closed [ 145.620611][ T54] vhci_hcd: stop threads [ 145.631391][ T6796] vhci_hcd: connection closed [ 145.631554][ T6792] vhci_hcd: connection reset by peer [ 145.642006][ T54] vhci_hcd: release socket [ 145.647312][ T54] vhci_hcd: disconnect device [ 145.739960][ T1206] usb 4-1: new full-speed USB device number 11 using dummy_hcd [ 145.786284][ T54] vhci_hcd: stop threads [ 145.830509][ T54] vhci_hcd: release socket [ 145.860122][ T54] vhci_hcd: disconnect device [ 145.866474][ T5861] usb 1-1: unable to get BOS descriptor or descriptor too short [ 145.888358][ T54] vhci_hcd: stop threads [ 145.896948][ T54] vhci_hcd: release socket [ 145.902513][ T5861] usb 1-1: unable to read config index 0 descriptor/start: -71 [ 145.910885][ T5861] usb 1-1: can't read configurations, error -71 [ 145.917291][ T54] vhci_hcd: disconnect device [ 145.934059][ T54] vhci_hcd: stop threads [ 145.938305][ T54] vhci_hcd: release socket [ 145.952937][ T54] vhci_hcd: disconnect device [ 145.968956][ T54] vhci_hcd: stop threads [ 145.979007][ T54] vhci_hcd: release socket [ 145.990140][ T54] vhci_hcd: disconnect device [ 146.010543][ T54] vhci_hcd: stop threads [ 146.014795][ T54] vhci_hcd: release socket [ 146.138435][ T54] vhci_hcd: disconnect device [ 146.319373][ T1206] usb 4-1: unable to get BOS descriptor or descriptor too short [ 146.765682][ T1206] usb 4-1: unable to read config index 0 descriptor/start: -71 [ 146.785603][ T1206] usb 4-1: can't read configurations, error -71 [ 147.730123][ T5858] usb 5-1: new high-speed USB device number 13 using dummy_hcd [ 147.885462][ T5858] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x85 has an invalid bInterval 0, changing to 7 [ 147.940180][ T5858] usb 5-1: New USB device found, idVendor=2040, idProduct=1605, bcdDevice= a.94 [ 147.949305][ T5858] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 147.961088][ T5858] usb 5-1: config 0 descriptor?? [ 148.173524][ T6835] input: syz1 as /devices/virtual/input/input17 [ 148.220258][ T48] usb 5-1: USB disconnect, device number 13 [ 148.241688][ T5858] usb 1-1: new full-speed USB device number 9 using dummy_hcd [ 148.292792][ T30] audit: type=1400 audit(1748476617.495:282): avc: denied { read open } for pid=6865 comm="dhcpcd-run-hook" path="/run/dhcpcd/hook-state/resolv.conf" dev="tmpfs" ino=1837 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 148.318153][ C1] vkms_vblank_simulate: vblank timer overrun [ 148.386733][ T30] audit: type=1400 audit(1748476617.495:283): avc: denied { getattr } for pid=6865 comm="dhcpcd-run-hook" path="/run/dhcpcd/hook-state/resolv.conf" dev="tmpfs" ino=1837 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 148.412940][ C1] vkms_vblank_simulate: vblank timer overrun [ 148.467516][ T5858] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 148.491490][ T5858] usb 1-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 148.504013][ T5858] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 148.512319][ T5937] vhci_hcd: vhci_device speed not set [ 148.580545][ T5858] usb 1-1: Product: syz [ 148.607348][ T5858] usb 1-1: Manufacturer: syz [ 148.616410][ T5858] usb 1-1: SerialNumber: syz [ 148.633634][ T5858] usb 1-1: config 0 descriptor?? [ 148.647668][ T5858] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 148.658994][ T5858] dvb-usb: bulk message failed: -22 (3/0) [ 148.687749][ T5858] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 148.712519][ T5858] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 148.773376][ T5858] usb 1-1: media controller created [ 148.902101][ T6859] dvb-usb: bulk message failed: -22 (62/0) [ 148.953766][ T30] audit: type=1400 audit(1748476618.145:284): avc: denied { add_name } for pid=6863 comm="dhcpcd-run-hook" name="resolv.conf.lapb4.link" scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 149.350656][ T5858] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 149.443760][ T5858] dvb-usb: bulk message failed: -22 (6/0) [ 149.492303][ T5858] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 149.530453][ T5858] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.0/usb1/1-1/input/input18 [ 149.554264][ T5858] dvb-usb: schedule remote query interval to 150 msecs. [ 149.564125][ T5858] dvb-usb: bulk message failed: -22 (3/0) [ 149.592719][ T5858] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 149.618230][ T5858] usb 1-1: USB disconnect, device number 9 [ 149.759862][ T5858] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 149.840473][ T5860] usb 4-1: new high-speed USB device number 13 using dummy_hcd [ 149.960448][ T920] usb 2-1: new high-speed USB device number 6 using dummy_hcd [ 149.983111][ T5813] Bluetooth: hci0: unexpected event for opcode 0x2042 [ 149.991109][ T30] kauditd_printk_skb: 6 callbacks suppressed [ 149.991118][ T30] audit: type=1326 audit(1748476619.195:291): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.045443][ T5860] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 150.067720][ T9] vhci_hcd: vhci_device speed not set [ 150.096045][ T5860] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 150.114493][ T5860] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 150.135371][ T920] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 150.145652][ T5860] usb 4-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 150.159090][ T5860] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 150.169236][ T5866] usb usb42-port1: attempt power cycle [ 150.170300][ T30] audit: type=1326 audit(1748476619.225:292): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.203474][ T5860] usb 4-1: config 0 descriptor?? [ 150.213064][ T920] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 150.226326][ T30] audit: type=1326 audit(1748476619.225:293): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.229543][ T920] usb 2-1: New USB device found, idVendor=04e7, idProduct=0030, bcdDevice= 0.00 [ 150.275240][ T920] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 150.299759][ T5861] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 150.315407][ T5861] Bluetooth: hci0: Error when powering off device on rfkill (-110) [ 150.340449][ T920] usb 2-1: config 0 descriptor?? [ 150.359535][ T30] audit: type=1326 audit(1748476619.225:294): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.387719][ T1206] usb 1-1: new high-speed USB device number 10 using dummy_hcd [ 150.421025][ T30] audit: type=1326 audit(1748476619.225:295): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.453253][ T30] audit: type=1326 audit(1748476619.225:296): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=318 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.510128][ T30] audit: type=1326 audit(1748476619.225:297): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.537413][ T30] audit: type=1326 audit(1748476619.225:298): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=46 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.566063][ T30] audit: type=1326 audit(1748476619.225:299): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=6896 comm="syz.0.253" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7df118e969 code=0x7ffc0000 [ 150.589404][ T1206] usb 1-1: Using ep0 maxpacket: 16 [ 150.596558][ T1206] usb 1-1: config 0 interface 0 altsetting 1 endpoint 0x7 has invalid wMaxPacketSize 0 [ 150.596581][ T1206] usb 1-1: config 0 interface 0 altsetting 1 endpoint 0x89 has an invalid bInterval 170, changing to 11 [ 150.596603][ T1206] usb 1-1: config 0 interface 0 altsetting 1 endpoint 0x89 has invalid maxpacket 34661, setting to 1024 [ 150.596623][ T1206] usb 1-1: config 0 interface 0 has no altsetting 0 [ 150.598642][ T1206] usb 1-1: New USB device found, idVendor=06cb, idProduct=0006, bcdDevice=9a.eb [ 150.598663][ T1206] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 150.598681][ T1206] usb 1-1: Product: syz [ 150.598694][ T1206] usb 1-1: Manufacturer: syz [ 150.598705][ T1206] usb 1-1: SerialNumber: syz [ 150.602126][ T1206] usb 1-1: config 0 descriptor?? [ 150.606041][ T6903] raw-gadget.2 gadget.0: fail, usb_ep_enable returned -22 [ 150.689833][ T30] audit: type=1400 audit(1748476619.885:300): avc: denied { block_suspend } for pid=6889 comm="syz.1.252" capability=36 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=capability2 permissive=1 [ 150.814223][ T6903] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 150.814805][ C1] vkms_vblank_simulate: vblank timer overrun [ 150.816054][ T5866] usb usb42-port1: unable to enumerate USB device [ 150.827174][ T5860] plantronics 0003:047F:FFFF.0001: unbalanced collection at end of report description [ 150.851471][ T6903] raw-gadget.2 gadget.0: fail, usb_ep_enable returned -22 [ 150.873502][ T1206] input: syz syz as /devices/platform/dummy_hcd.0/usb1/1-1/1-1:0.0/input/input19 [ 150.890570][ T5860] plantronics 0003:047F:FFFF.0001: parse failed [ 150.900920][ T5860] plantronics 0003:047F:FFFF.0001: probe with driver plantronics failed with error -22 [ 150.969020][ T920] elo 0003:04E7:0030.0002: global environment stack underflow [ 150.981295][ T920] elo 0003:04E7:0030.0002: item 0 0 1 11 parsing failed [ 150.994529][ T920] elo 0003:04E7:0030.0002: parse failed [ 151.022090][ T920] elo 0003:04E7:0030.0002: probe with driver elo failed with error -22 [ 151.053031][ T1206] usb 4-1: USB disconnect, device number 13 [ 151.106278][ T5866] usb 1-1: USB disconnect, device number 10 [ 151.122601][ T5168] synaptics_usb 1-1:0.0: synusb_open - usb_submit_urb failed, error: -19 [ 151.304139][ T5818] usb 2-1: USB disconnect, device number 6 [ 152.000656][ T6949] netlink: 'syz.0.257': attribute type 33 has an invalid length. [ 152.440414][ T5813] Bluetooth: hci1: command 0x0c1a tx timeout [ 152.440935][ T5861] Bluetooth: hci1: Opcode 0x0c1a failed: -110 [ 152.476897][ T5861] Bluetooth: hci1: Error when powering off device on rfkill (-110) [ 153.360245][ T9] usb 1-1: new low-speed USB device number 11 using dummy_hcd [ 153.551762][ T9] usb 1-1: config 0 has an invalid interface number: 55 but max is 0 [ 153.579580][ T9] usb 1-1: config 0 has no interface number 0 [ 153.595932][ T9] usb 1-1: config 0 interface 55 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 153.627251][ T9] usb 1-1: config 0 interface 55 altsetting 0 endpoint 0xE has invalid maxpacket 32, setting to 8 [ 153.655425][ T9] usb 1-1: config 0 interface 55 altsetting 0 has an endpoint descriptor with address 0xAB, changing to 0x8B [ 153.704098][ T9] usb 1-1: config 0 interface 55 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 10 [ 153.724433][ T9] usb 1-1: config 0 interface 55 altsetting 0 endpoint 0x8B has invalid maxpacket 120, setting to 8 [ 153.752277][ T9] usb 1-1: config 0 interface 55 altsetting 0 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 153.800376][ T9] usb 1-1: New USB device found, idVendor=0f11, idProduct=1080, bcdDevice=fc.6a [ 153.832079][ T9] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 153.859868][ T9] usb 1-1: config 0 descriptor?? [ 153.871416][ T6978] raw-gadget.0 gadget.0: fail, usb_ep_enable returned -22 [ 153.897128][ T6978] raw-gadget.0 gadget.0: fail, usb_ep_enable returned -22 [ 153.953896][ T9] ldusb 1-1:0.55: LD USB Device #0 now attached to major 180 minor 0 [ 154.265384][ T5818] usb 1-1: USB disconnect, device number 11 [ 154.296685][ T7004] ======================================================= [ 154.296685][ T7004] WARNING: The mand mount option has been deprecated and [ 154.296685][ T7004] and is ignored by this kernel. Remove the mand [ 154.296685][ T7004] option from the mount to silence this warning. [ 154.296685][ T7004] ======================================================= [ 154.331541][ C1] vkms_vblank_simulate: vblank timer overrun [ 154.482112][ T5818] ldusb 1-1:0.55: LD USB Device #0 now disconnected [ 154.612195][ T5813] Bluetooth: hci2: command 0x0c1a tx timeout [ 154.618433][ T5861] Bluetooth: hci2: Opcode 0x0c1a failed: -110 [ 154.649642][ T5861] Bluetooth: hci2: Error when powering off device on rfkill (-110) [ 154.965230][ T7012] capability: warning: `syz.3.271' uses deprecated v2 capabilities in a way that may be insecure [ 155.050160][ T30] kauditd_printk_skb: 6 callbacks suppressed [ 155.050187][ T30] audit: type=1400 audit(1748476624.105:307): avc: denied { read write } for pid=7008 comm="syz.3.271" name="rdma_cm" dev="devtmpfs" ino=1271 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:infiniband_device_t tclass=chr_file permissive=1 [ 155.188446][ T30] audit: type=1400 audit(1748476624.105:308): avc: denied { open } for pid=7008 comm="syz.3.271" path="/dev/infiniband/rdma_cm" dev="devtmpfs" ino=1271 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:infiniband_device_t tclass=chr_file permissive=1 [ 155.238313][ T30] audit: type=1400 audit(1748476624.115:309): avc: denied { ioctl } for pid=7008 comm="syz.3.271" path="/dev/loop-control" dev="devtmpfs" ino=646 ioctlcmd=0x4c80 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:loop_control_device_t tclass=chr_file permissive=1 [ 155.613700][ T7016] FAULT_INJECTION: forcing a failure. [ 155.613700][ T7016] name failslab, interval 1, probability 0, space 0, times 1 [ 155.626397][ T7016] CPU: 1 UID: 0 PID: 7016 Comm: syz.3.274 Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 155.626413][ T7016] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 155.626420][ T7016] Call Trace: [ 155.626424][ T7016] [ 155.626428][ T7016] dump_stack_lvl+0x16c/0x1f0 [ 155.626442][ T7016] should_fail_ex+0x512/0x640 [ 155.626454][ T7016] ? kmem_cache_alloc_node_noprof+0x5e/0x3b0 [ 155.626466][ T7016] should_failslab+0xc2/0x120 [ 155.626477][ T7016] kmem_cache_alloc_node_noprof+0x71/0x3b0 [ 155.626487][ T7016] ? __alloc_skb+0x2b2/0x380 [ 155.626503][ T7016] __alloc_skb+0x2b2/0x380 [ 155.626514][ T7016] ? __pfx___alloc_skb+0x10/0x10 [ 155.626528][ T7016] ? __pfx_netlink_autobind.isra.0+0x10/0x10 [ 155.626545][ T7016] netlink_alloc_large_skb+0x69/0x130 [ 155.626561][ T7016] netlink_sendmsg+0x6a1/0xdd0 [ 155.626577][ T7016] ? __pfx_netlink_sendmsg+0x10/0x10 [ 155.626596][ T7016] ____sys_sendmsg+0xa95/0xc70 [ 155.626607][ T7016] ? copy_msghdr_from_user+0x10a/0x160 [ 155.626620][ T7016] ? __pfx_____sys_sendmsg+0x10/0x10 [ 155.626635][ T7016] ___sys_sendmsg+0x134/0x1d0 [ 155.626649][ T7016] ? __pfx____sys_sendmsg+0x10/0x10 [ 155.626666][ T7016] ? __lock_acquire+0x622/0x1c90 [ 155.626695][ T7016] __sys_sendmsg+0x16d/0x220 [ 155.626708][ T7016] ? __pfx___sys_sendmsg+0x10/0x10 [ 155.626729][ T7016] do_syscall_64+0xcd/0x4c0 [ 155.626741][ T7016] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 155.626751][ T7016] RIP: 0033:0x7f554c98e969 [ 155.626759][ T7016] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 155.626770][ T7016] RSP: 002b:00007f554d7b8038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 155.626780][ T7016] RAX: ffffffffffffffda RBX: 00007f554cbb5fa0 RCX: 00007f554c98e969 [ 155.626787][ T7016] RDX: 0000000004000000 RSI: 00002000000002c0 RDI: 0000000000000003 [ 155.626792][ T7016] RBP: 00007f554d7b8090 R08: 0000000000000000 R09: 0000000000000000 [ 155.626798][ T7016] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 155.626804][ T7016] R13: 0000000000000000 R14: 00007f554cbb5fa0 R15: 00007ffd30f6c488 [ 155.626816][ T7016] [ 156.840410][ T5813] Bluetooth: hci4: command 0x0c1a tx timeout [ 156.841380][ T5861] Bluetooth: hci4: Opcode 0x0c1a failed: -110 [ 156.853811][ T5861] Bluetooth: hci4: Error when powering off device on rfkill (-110) [ 157.180465][ T920] usb 4-1: new high-speed USB device number 14 using dummy_hcd [ 157.348822][ T920] usb 4-1: unable to get BOS descriptor or descriptor too short [ 157.412300][ T920] usb 4-1: config 249 has an invalid interface number: 177 but max is 0 [ 157.441932][ T920] usb 4-1: config 249 has no interface number 0 [ 157.448274][ T920] usb 4-1: config 249 interface 177 altsetting 0 has an endpoint descriptor with address 0x1A, changing to 0xA [ 157.466006][ T920] usb 4-1: config 249 interface 177 altsetting 0 has 4 endpoint descriptors, different from the interface descriptor's value: 3 [ 157.481967][ T920] usb 4-1: New USB device found, idVendor=057c, idProduct=3800, bcdDevice=5a.9d [ 157.491054][ T920] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 157.499040][ T920] usb 4-1: Product: syz [ 157.503252][ T920] usb 4-1: Manufacturer: syz [ 157.507832][ T920] usb 4-1: SerialNumber: syz [ 157.515074][ T7026] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 157.590277][ T5860] usb 2-1: new full-speed USB device number 7 using dummy_hcd [ 157.892388][ T5860] usb 2-1: unable to get BOS descriptor or descriptor too short [ 157.905624][ T5860] usb 2-1: unable to read config index 0 descriptor/start: -71 [ 157.908015][ T7026] netlink: 24 bytes leftover after parsing attributes in process `syz.3.278'. [ 157.915435][ T5860] usb 2-1: can't read configurations, error -71 [ 158.009457][ T920] usb 4-1: USB disconnect, device number 14 [ 158.478545][ T7037] syz_tun: entered allmulticast mode [ 158.487625][ T7036] syz_tun: left allmulticast mode [ 158.633671][ T7041] x_tables: duplicate underflow at hook 2 [ 159.187944][ T30] audit: type=1400 audit(1748476628.385:310): avc: denied { write } for pid=7045 comm="syz.3.285" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=smc_socket permissive=1 [ 159.215067][ T7049] overlayfs: upper fs does not support RENAME_WHITEOUT. [ 159.222179][ T7049] overlayfs: failed to set xattr on upper [ 159.227892][ T7049] overlayfs: ...falling back to redirect_dir=nofollow. [ 159.234885][ T7049] overlayfs: ...falling back to metacopy=off. [ 159.241000][ T7049] overlayfs: ...falling back to index=off. [ 159.246792][ T7049] overlayfs: ...falling back to uuid=null. [ 159.254215][ T30] audit: type=1400 audit(1748476628.415:311): avc: denied { mounton } for pid=7045 comm="syz.3.285" path="/bus" dev="ramfs" ino=12872 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:ramfs_t tclass=dir permissive=1 [ 160.531383][ T7065] FAULT_INJECTION: forcing a failure. [ 160.531383][ T7065] name failslab, interval 1, probability 0, space 0, times 0 [ 160.544132][ T7065] CPU: 0 UID: 0 PID: 7065 Comm: syz.3.291 Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 160.544154][ T7065] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 160.544164][ T7065] Call Trace: [ 160.544169][ T7065] [ 160.544175][ T7065] dump_stack_lvl+0x16c/0x1f0 [ 160.544195][ T7065] should_fail_ex+0x512/0x640 [ 160.544210][ T7065] ? __kmalloc_cache_noprof+0x57/0x3e0 [ 160.544238][ T7065] should_failslab+0xc2/0x120 [ 160.544257][ T7065] __kmalloc_cache_noprof+0x6a/0x3e0 [ 160.544281][ T7065] ? tcf_block_get_ext+0x3c6/0x1800 [ 160.544306][ T7065] ? kasan_save_track+0x14/0x30 [ 160.544324][ T7065] tcf_block_get_ext+0x3c6/0x1800 [ 160.544353][ T7065] tcf_block_get+0xa8/0x100 [ 160.544376][ T7065] ? __pfx_tcf_block_get+0x10/0x10 [ 160.544400][ T7065] ? __pfx_tcf_chain_head_change_dflt+0x10/0x10 [ 160.544421][ T7065] ? __pfx_qdisc_watchdog+0x10/0x10 [ 160.544435][ T7065] ? __hrtimer_setup+0x176/0x280 [ 160.544465][ T7065] cake_init+0x243/0x950 [ 160.544486][ T7065] ? qdisc_alloc+0x94f/0xc50 [ 160.544508][ T7065] ? __pfx_cake_init+0x10/0x10 [ 160.544527][ T7065] qdisc_create+0x457/0xfa0 [ 160.544548][ T7065] tc_modify_qdisc+0x1287/0x2100 [ 160.544564][ T7065] ? __pfx_tc_modify_qdisc+0x10/0x10 [ 160.544586][ T7065] ? __pfx_tc_modify_qdisc+0x10/0x10 [ 160.544601][ T7065] rtnetlink_rcv_msg+0x3c9/0xe90 [ 160.544617][ T7065] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 160.544638][ T7065] netlink_rcv_skb+0x16a/0x440 [ 160.544653][ T7065] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 160.544668][ T7065] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 160.544691][ T7065] ? netlink_deliver_tap+0x1ae/0xd30 [ 160.544708][ T7065] netlink_unicast+0x53d/0x7f0 [ 160.544724][ T7065] ? __pfx_netlink_unicast+0x10/0x10 [ 160.544743][ T7065] netlink_sendmsg+0x8d1/0xdd0 [ 160.544760][ T7065] ? __pfx_netlink_sendmsg+0x10/0x10 [ 160.544780][ T7065] ____sys_sendmsg+0xa95/0xc70 [ 160.544790][ T7065] ? copy_msghdr_from_user+0x10a/0x160 [ 160.544804][ T7065] ? __pfx_____sys_sendmsg+0x10/0x10 [ 160.544819][ T7065] ___sys_sendmsg+0x134/0x1d0 [ 160.544833][ T7065] ? __pfx____sys_sendmsg+0x10/0x10 [ 160.544845][ T7065] ? __lock_acquire+0x622/0x1c90 [ 160.544876][ T7065] __sys_sendmsg+0x16d/0x220 [ 160.544889][ T7065] ? __pfx___sys_sendmsg+0x10/0x10 [ 160.544911][ T7065] do_syscall_64+0xcd/0x4c0 [ 160.544923][ T7065] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 160.544933][ T7065] RIP: 0033:0x7f554c98e969 [ 160.544942][ T7065] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 160.544953][ T7065] RSP: 002b:00007f554d7b8038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 160.544963][ T7065] RAX: ffffffffffffffda RBX: 00007f554cbb5fa0 RCX: 00007f554c98e969 [ 160.544969][ T7065] RDX: 0000000000000000 RSI: 0000200000000140 RDI: 0000000000000003 [ 160.544975][ T7065] RBP: 00007f554d7b8090 R08: 0000000000000000 R09: 0000000000000000 [ 160.544981][ T7065] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000002 [ 160.544986][ T7065] R13: 0000000000000000 R14: 00007f554cbb5fa0 R15: 00007ffd30f6c488 [ 160.544999][ T7065] [ 161.319014][ T7068] syz.3.292 uses obsolete (PF_INET,SOCK_PACKET) [ 163.274394][ T30] audit: type=1400 audit(1748476632.475:312): avc: denied { create } for pid=7084 comm="syz.3.296" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 163.414935][ T7085] capability: warning: `syz.3.296' uses 32-bit capabilities (legacy support in use) [ 163.488835][ T30] audit: type=1400 audit(1748476632.635:313): avc: denied { ioctl } for pid=7084 comm="syz.3.296" path="/dev/sg0" dev="devtmpfs" ino=761 ioctlcmd=0x2285 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 163.557819][ T30] audit: type=1400 audit(1748476632.755:314): avc: denied { accept } for pid=7087 comm="syz.3.297" lport=35391 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 163.586939][ T7088] netlink: 4 bytes leftover after parsing attributes in process `syz.3.297'. [ 163.601190][ T30] audit: type=1400 audit(1748476632.795:315): avc: denied { listen } for pid=7087 comm="syz.3.297" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rawip_socket permissive=1 [ 166.240273][ T5866] usb 4-1: new high-speed USB device number 15 using dummy_hcd [ 166.410187][ T5866] usb 4-1: Using ep0 maxpacket: 8 [ 166.419757][ T5866] usb 4-1: config 179 has an invalid interface number: 65 but max is 0 [ 166.428086][ T5866] usb 4-1: config 179 has no interface number 0 [ 166.437193][ T5866] usb 4-1: config 179 interface 65 altsetting 0 endpoint 0xF has an invalid bInterval 0, changing to 7 [ 166.449790][ T5866] usb 4-1: config 179 interface 65 altsetting 0 endpoint 0xF has invalid maxpacket 1025, setting to 1024 [ 166.463779][ T5866] usb 4-1: config 179 interface 65 altsetting 0 endpoint 0x83 has an invalid bInterval 0, changing to 7 [ 166.475566][ T5866] usb 4-1: config 179 interface 65 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 23 [ 166.492989][ T5866] usb 4-1: New USB device found, idVendor=12ab, idProduct=90a3, bcdDevice=1e.eb [ 166.505663][ T5866] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 166.519291][ T7113] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 166.659102][ T30] audit: type=1400 audit(1748476635.855:316): avc: denied { read write } for pid=7114 comm="syz.1.305" name="nvram" dev="devtmpfs" ino=623 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nvram_device_t tclass=chr_file permissive=1 [ 166.684497][ T30] audit: type=1400 audit(1748476635.855:317): avc: denied { open } for pid=7114 comm="syz.1.305" path="/dev/nvram" dev="devtmpfs" ino=623 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nvram_device_t tclass=chr_file permissive=1 [ 166.746263][ T7113] netlink: 4 bytes leftover after parsing attributes in process `syz.3.304'. [ 166.758381][ T5860] usb 4-1: USB disconnect, device number 15 [ 166.758427][ C1] xpad 4-1:179.65: xpad_irq_in - usb_submit_urb failed with result -19 [ 166.773616][ C1] dummy_hcd dummy_hcd.3: timer fired with no URBs pending? [ 166.873646][ T30] audit: type=1400 audit(1748476636.075:318): avc: denied { create } for pid=7122 comm="syz.1.307" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=isdn_socket permissive=1 [ 166.877712][ T7123] overlay: Bad value for 'redirect_dir' [ 166.893090][ T30] audit: type=1400 audit(1748476636.075:319): avc: denied { ioctl } for pid=7122 comm="syz.1.307" path="socket:[13054]" dev="sockfs" ino=13054 ioctlcmd=0x4942 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=isdn_socket permissive=1 [ 166.922962][ C0] vkms_vblank_simulate: vblank timer overrun [ 166.932812][ T30] audit: type=1400 audit(1748476636.075:320): avc: denied { mount } for pid=7122 comm="syz.1.307" name="/" dev="tracefs" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:tracefs_t tclass=filesystem permissive=1 [ 166.936445][ T7122] delete_channel: no stack [ 166.954850][ C0] vkms_vblank_simulate: vblank timer overrun [ 166.958247][ T30] audit: type=1400 audit(1748476636.075:321): avc: denied { mounton } for pid=7122 comm="syz.1.307" path="/79/file0" dev="tracefs" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:tracefs_t tclass=dir permissive=1 [ 166.987651][ C0] vkms_vblank_simulate: vblank timer overrun [ 170.816947][ T30] kauditd_printk_skb: 1 callbacks suppressed [ 170.816961][ T30] audit: type=1400 audit(1748476640.015:323): avc: denied { unmount } for pid=5807 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fusefs_t tclass=filesystem permissive=1 [ 170.873673][ T30] audit: type=1400 audit(1748476640.075:324): avc: denied { connect } for pid=7148 comm="syz.3.316" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 171.110442][ T30] audit: type=1400 audit(1748476640.305:325): avc: denied { write } for pid=7148 comm="syz.3.316" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 173.070117][ T5818] usb 4-1: new full-speed USB device number 16 using dummy_hcd [ 173.221144][ T5818] usb 4-1: config 0 has an invalid interface number: 60 but max is 1 [ 173.229404][ T5818] usb 4-1: config 0 has an invalid descriptor of length 33, skipping remainder of the config [ 173.239656][ T5818] usb 4-1: config 0 has 1 interface, different from the descriptor's value: 2 [ 173.248536][ T5818] usb 4-1: config 0 has no interface number 0 [ 173.254840][ T5818] usb 4-1: config 0 interface 60 altsetting 4 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 173.267829][ T5818] usb 4-1: config 0 interface 60 has no altsetting 0 [ 173.276220][ T5818] usb 4-1: New USB device found, idVendor=06e1, idProduct=a155, bcdDevice=62.8f [ 173.285288][ T5818] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 173.293290][ T5818] usb 4-1: Product: syz [ 173.297421][ T5818] usb 4-1: Manufacturer: syz [ 173.302011][ T5818] usb 4-1: SerialNumber: syz [ 173.308067][ T5818] usb 4-1: config 0 descriptor?? [ 174.238410][ T5818] radio-si470x 4-1:0.60: could not find interrupt in endpoint [ 174.271263][ T5818] radio-si470x 4-1:0.60: probe with driver radio-si470x failed with error -5 [ 174.284544][ T5818] usbhid 4-1:0.60: couldn't find an input interrupt endpoint [ 174.298260][ T5818] usb 4-1: USB disconnect, device number 16 [ 174.349258][ T30] audit: type=1400 audit(1748476643.546:326): avc: denied { connect } for pid=7169 comm="syz.3.323" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=pppox_socket permissive=1 [ 174.383543][ T30] audit: type=1400 audit(1748476643.546:327): avc: denied { ioctl } for pid=7169 comm="syz.3.323" path="socket:[13172]" dev="sockfs" ino=13172 ioctlcmd=0x662a scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=pppox_socket permissive=1 [ 176.220262][ T5818] usb 4-1: new high-speed USB device number 17 using dummy_hcd [ 176.360155][ T5818] usb 4-1: device descriptor read/64, error -71 [ 176.601240][ T5818] usb 4-1: new high-speed USB device number 18 using dummy_hcd [ 176.740197][ T5818] usb 4-1: device descriptor read/64, error -71 [ 176.861001][ T5818] usb usb4-port1: attempt power cycle [ 177.200213][ T5818] usb 4-1: new high-speed USB device number 19 using dummy_hcd [ 177.220691][ T5818] usb 4-1: device descriptor read/8, error -71 [ 177.460124][ T5818] usb 4-1: new high-speed USB device number 20 using dummy_hcd [ 177.492283][ T5818] usb 4-1: device descriptor read/8, error -71 [ 177.611086][ T5818] usb usb4-port1: unable to enumerate USB device [ 179.606890][ T7202] netlink: 'syz.3.334': attribute type 12 has an invalid length. [ 179.825710][ T7206] Failed to get privilege flags for destination (handle=0x2:0xd) [ 180.946280][ T30] audit: type=1400 audit(1748476650.152:328): avc: denied { connect } for pid=7215 comm="syz.3.338" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 181.083148][ T7220] tmpfs: Bad value for 'huge' [ 182.510206][ T5860] usb 4-1: new low-speed USB device number 21 using dummy_hcd [ 182.671178][ T5860] usb 4-1: config 0 has an invalid interface number: 55 but max is 0 [ 182.679287][ T5860] usb 4-1: config 0 has no interface number 0 [ 182.686524][ T5860] usb 4-1: config 0 interface 55 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 182.697422][ T5860] usb 4-1: config 0 interface 55 altsetting 0 endpoint 0xE has invalid maxpacket 32, setting to 8 [ 182.708135][ T5860] usb 4-1: config 0 interface 55 altsetting 0 has an endpoint descriptor with address 0xAB, changing to 0x8B [ 182.719737][ T5860] usb 4-1: config 0 interface 55 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 10 [ 182.730885][ T5860] usb 4-1: config 0 interface 55 altsetting 0 endpoint 0x8B has invalid maxpacket 120, setting to 8 [ 182.741737][ T5860] usb 4-1: config 0 interface 55 altsetting 0 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 182.754779][ T5860] usb 4-1: New USB device found, idVendor=0f11, idProduct=1080, bcdDevice=fc.6a [ 182.764451][ T5860] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 182.773886][ T5860] usb 4-1: config 0 descriptor?? [ 182.780336][ T7234] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 182.787576][ T7234] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 182.798802][ T5860] ldusb 4-1:0.55: LD USB Device #0 now attached to major 180 minor 0 [ 183.054335][ T5859] usb 4-1: USB disconnect, device number 21 [ 183.064313][ T5859] ldusb 4-1:0.55: LD USB Device #0 now disconnected [ 190.599495][ T30] audit: type=1400 audit(1748476659.802:329): avc: denied { write } for pid=7261 comm="syz.1.353" name="rtc0" dev="devtmpfs" ino=921 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 191.509238][ T30] audit: type=1400 audit(1748476660.712:330): avc: denied { setopt } for pid=7264 comm="syz.1.354" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 191.524664][ T7265] process 'syz.1.354' launched './file0' with NULL argv: empty string added [ 191.539609][ T30] audit: type=1400 audit(1748476660.742:331): avc: denied { execute_no_trans } for pid=7264 comm="syz.1.354" path="/103/file0" dev="tmpfs" ino=559 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 191.542425][ T7265] netlink: 28 bytes leftover after parsing attributes in process `syz.1.354'. [ 191.850138][ T920] usb 2-1: new full-speed USB device number 9 using dummy_hcd [ 192.001692][ T920] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 192.013830][ T920] usb 2-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 192.022903][ T920] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 192.030948][ T920] usb 2-1: Product: syz [ 192.035092][ T920] usb 2-1: Manufacturer: syz [ 192.039652][ T920] usb 2-1: SerialNumber: syz [ 192.046403][ T920] usb 2-1: config 0 descriptor?? [ 192.053517][ T920] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 192.064601][ T920] dvb-usb: bulk message failed: -22 (3/0) [ 192.092430][ T920] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 192.101518][ T920] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 192.113041][ T920] usb 2-1: media controller created [ 192.118990][ T920] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 192.129633][ T920] dvb-usb: bulk message failed: -22 (6/0) [ 192.135406][ T920] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 192.148233][ T920] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.1/usb2/2-1/input/input20 [ 192.161520][ T920] dvb-usb: schedule remote query interval to 150 msecs. [ 192.168461][ T920] dvb-usb: bulk message failed: -22 (3/0) [ 192.190108][ T920] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 192.298346][ T7267] dibusb: i2c wr: len=61 is too big! [ 192.298346][ T7267] [ 192.308517][ T920] usb 2-1: USB disconnect, device number 9 [ 192.327665][ T920] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 193.806892][ T1299] ieee802154 phy0 wpan0: encryption failed: -22 [ 193.813288][ T1299] ieee802154 phy1 wpan1: encryption failed: -22 [ 197.310462][ T7289] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 199.054444][ T7296] netlink: 'syz.1.363': attribute type 29 has an invalid length. [ 199.063253][ T7296] netlink: 4 bytes leftover after parsing attributes in process `syz.1.363'. [ 199.079260][ T7296] netlink: 64 bytes leftover after parsing attributes in process `syz.1.363'. [ 199.100360][ T30] audit: type=1400 audit(1748476668.303:332): avc: denied { ioctl } for pid=7295 comm="syz.1.363" path="socket:[14480]" dev="sockfs" ino=14480 ioctlcmd=0x8983 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_netfilter_socket permissive=1 [ 199.670135][ T5860] usb 2-1: new full-speed USB device number 10 using dummy_hcd [ 200.002925][ T5860] usb 2-1: unable to get BOS descriptor or descriptor too short [ 200.015350][ T5860] usb 2-1: unable to read config index 0 descriptor/start: -71 [ 200.023612][ T5860] usb 2-1: can't read configurations, error -71 [ 200.702355][ T7309] netlink: 'syz.1.368': attribute type 5 has an invalid length. [ 200.718464][ T30] audit: type=1400 audit(1748476669.923:333): avc: denied { sqpoll } for pid=7308 comm="syz.1.368" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=io_uring permissive=1 [ 201.973573][ T30] audit: type=1400 audit(1748476671.183:334): avc: denied { listen } for pid=7316 comm="syz.1.371" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=smc_socket permissive=1 [ 201.992894][ T30] audit: type=1400 audit(1748476671.183:335): avc: denied { accept } for pid=7316 comm="syz.1.371" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=smc_socket permissive=1 [ 203.810219][ T5860] usb 2-1: new full-speed USB device number 12 using dummy_hcd [ 203.962255][ T5860] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 203.974145][ T5860] usb 2-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 203.983237][ T5860] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 203.991257][ T5860] usb 2-1: Product: syz [ 203.995403][ T5860] usb 2-1: Manufacturer: syz [ 203.999964][ T5860] usb 2-1: SerialNumber: syz [ 204.006182][ T5860] usb 2-1: config 0 descriptor?? [ 204.012860][ T5860] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 204.025366][ T5860] dvb-usb: bulk message failed: -22 (3/0) [ 204.052500][ T5860] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 204.061485][ T5860] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 204.073050][ T5860] usb 2-1: media controller created [ 204.078997][ T5860] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 204.089833][ T5860] dvb-usb: bulk message failed: -22 (6/0) [ 204.095672][ T5860] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 204.108525][ T5860] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.1/usb2/2-1/input/input21 [ 204.122232][ T5860] dvb-usb: schedule remote query interval to 150 msecs. [ 204.129181][ T5860] dvb-usb: bulk message failed: -22 (3/0) [ 204.150128][ T5860] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 204.269755][ T7328] dibusb: i2c wr: len=61 is too big! [ 204.269755][ T7328] [ 204.278302][ T5860] usb 2-1: USB disconnect, device number 12 [ 204.296849][ T5860] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 205.697367][ T7337] netlink: 'syz.1.376': attribute type 5 has an invalid length. [ 206.850627][ T7346] Cannot find set identified by id 0 to match [ 207.609642][ T30] audit: type=1400 audit(1748476676.813:336): avc: denied { ioctl } for pid=7350 comm="syz.1.380" path="socket:[13650]" dev="sockfs" ino=13650 ioctlcmd=0x5411 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rawip_socket permissive=1 [ 212.700554][ T9] usb 2-1: new high-speed USB device number 13 using dummy_hcd [ 212.860112][ T9] usb 2-1: Using ep0 maxpacket: 32 [ 212.866950][ T9] usb 2-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xA6, changing to 0x86 [ 212.880148][ T9] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x86 has an invalid bInterval 0, changing to 7 [ 212.891175][ T9] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x86 has invalid wMaxPacketSize 0 [ 212.900954][ T9] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x7 has an invalid bInterval 255, changing to 11 [ 212.912161][ T9] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x7 has invalid maxpacket 59391, setting to 1024 [ 212.924826][ T9] usb 2-1: New USB device found, idVendor=05ef, idProduct=020a, bcdDevice=91.36 [ 212.933877][ T9] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 212.941888][ T9] usb 2-1: Product: syz [ 212.946038][ T9] usb 2-1: Manufacturer: syz [ 212.950682][ T9] usb 2-1: SerialNumber: syz [ 212.956625][ T9] usb 2-1: config 0 descriptor?? [ 213.369293][ T9] iforce 2-1:0.0: usb_submit_urb failed: -32 [ 213.375507][ T9] input input22: Device does not respond to id packet M [ 213.382920][ T9] iforce 2-1:0.0: usb_submit_urb failed: -32 [ 213.388896][ T9] input input22: Device does not respond to id packet P [ 213.396531][ T9] iforce 2-1:0.0: usb_submit_urb failed: -32 [ 213.402714][ T9] input input22: Device does not respond to id packet B [ 213.411369][ T9] input input22: Limiting number of effects to 32 (device reports 115) [ 213.616553][ T30] audit: type=1400 audit(1748476682.822:337): avc: denied { remount } for pid=7362 comm="syz.1.384" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:tmpfs_t tclass=filesystem permissive=1 [ 213.639326][ T30] audit: type=1400 audit(1748476682.822:338): avc: denied { read } for pid=7362 comm="syz.1.384" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 213.669952][ T9] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 213.678988][ T9] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 213.688805][ T9] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 213.695250][ T9] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 213.703274][ T9] input: Unknown I-Force Device [%04x:%04x] as /devices/platform/dummy_hcd.1/usb2/2-1/2-1:0.0/input/input22 [ 213.723389][ T9] usb 2-1: USB disconnect, device number 13 [ 215.139827][ T7374] mmap: syz.1.386 (7374) uses deprecated remap_file_pages() syscall. See Documentation/mm/remap_file_pages.rst. [ 215.168640][ T30] audit: type=1400 audit(1748476684.362:339): avc: denied { map } for pid=7371 comm="syz.1.386" path="socket:[13720]" dev="sockfs" ino=13720 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 215.206503][ T30] audit: type=1400 audit(1748476684.362:340): avc: denied { read } for pid=7371 comm="syz.1.386" path="socket:[13720]" dev="sockfs" ino=13720 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 216.075364][ T7381] netlink: 8 bytes leftover after parsing attributes in process `syz.1.388'. [ 216.861681][ T7384] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 222.631385][ T5859] usb 2-1: new high-speed USB device number 14 using dummy_hcd [ 222.780087][ T5859] usb 2-1: Using ep0 maxpacket: 16 [ 222.786291][ T5859] usb 2-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 0 [ 222.800143][ T5859] usb 2-1: New USB device found, idVendor=05ac, idProduct=0244, bcdDevice= 0.00 [ 222.809149][ T5859] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 222.819316][ T5859] usb 2-1: config 0 descriptor?? [ 222.828583][ T5859] input: bcm5974 as /devices/platform/dummy_hcd.1/usb2/2-1/2-1:0.0/input/input23 [ 223.029336][ T30] audit: type=1400 audit(1748476692.232:341): avc: denied { write } for pid=7403 comm="syz.1.396" name="mice" dev="devtmpfs" ino=916 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:mouse_device_t tclass=chr_file permissive=1 [ 223.080150][ T5168] bcm5974 2-1:0.0: could not read from device [ 223.096299][ T5859] bcm5974 2-1:0.0: could not read from device [ 223.104328][ T5168] bcm5974 2-1:0.0: could not read from device [ 223.113276][ T5859] input: failed to attach handler mousedev to device input23, error: -5 [ 223.126756][ T5859] usb 2-1: USB disconnect, device number 14 [ 223.126946][ T5168] bcm5974 2-1:0.0: could not read from device [ 223.147350][ T7408] bcm5974 2-1:0.0: could not read from device [ 225.821353][ T5818] usb 2-1: new high-speed USB device number 15 using dummy_hcd [ 225.970239][ T5818] usb 2-1: Using ep0 maxpacket: 8 [ 225.976393][ T5818] usb 2-1: config 179 has an invalid interface number: 65 but max is 0 [ 225.984680][ T5818] usb 2-1: config 179 has no interface number 0 [ 225.991075][ T5818] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0xF has an invalid bInterval 0, changing to 7 [ 226.002263][ T5818] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0xF has invalid maxpacket 1025, setting to 1024 [ 226.013591][ T5818] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0x83 has an invalid bInterval 0, changing to 7 [ 226.024746][ T5818] usb 2-1: config 179 interface 65 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 23 [ 226.037975][ T5818] usb 2-1: New USB device found, idVendor=12ab, idProduct=90a3, bcdDevice=1e.eb [ 226.047013][ T5818] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 226.060444][ T7419] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 226.296344][ T7419] netlink: 4 bytes leftover after parsing attributes in process `syz.1.399'. [ 226.309785][ T5937] usb 2-1: USB disconnect, device number 15 [ 226.309854][ C1] xpad 2-1:179.65: xpad_irq_in - usb_submit_urb failed with result -19 [ 226.325585][ C1] dummy_hcd dummy_hcd.1: timer fired with no URBs pending? [ 227.100141][ T5860] usb 2-1: new low-speed USB device number 16 using dummy_hcd [ 227.261345][ T5860] usb 2-1: config 0 has an invalid interface number: 55 but max is 0 [ 227.269437][ T5860] usb 2-1: config 0 has no interface number 0 [ 227.275558][ T5860] usb 2-1: config 0 interface 55 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 227.286420][ T5860] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0xE has invalid maxpacket 32, setting to 8 [ 227.297037][ T5860] usb 2-1: config 0 interface 55 altsetting 0 has an endpoint descriptor with address 0xAB, changing to 0x8B [ 227.308612][ T5860] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 10 [ 227.319716][ T5860] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has invalid maxpacket 120, setting to 8 [ 227.330555][ T5860] usb 2-1: config 0 interface 55 altsetting 0 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 227.343563][ T5860] usb 2-1: New USB device found, idVendor=0f11, idProduct=1080, bcdDevice=fc.6a [ 227.352624][ T5860] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 227.362694][ T5860] usb 2-1: config 0 descriptor?? [ 227.368377][ T7423] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 227.375772][ T7423] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 227.387031][ T5860] ldusb 2-1:0.55: LD USB Device #0 now attached to major 180 minor 0 [ 227.641015][ T5937] usb 2-1: USB disconnect, device number 16 [ 227.649761][ T5937] ldusb 2-1:0.55: LD USB Device #0 now disconnected [ 228.460175][ T9] usb 2-1: new low-speed USB device number 17 using dummy_hcd [ 228.621549][ T9] usb 2-1: config 0 has an invalid interface number: 55 but max is 0 [ 228.629644][ T9] usb 2-1: config 0 has no interface number 0 [ 228.635767][ T9] usb 2-1: config 0 interface 55 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 228.646565][ T9] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0xE has invalid maxpacket 32, setting to 8 [ 228.657224][ T9] usb 2-1: config 0 interface 55 altsetting 0 has an endpoint descriptor with address 0xAB, changing to 0x8B [ 228.668803][ T9] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 10 [ 228.679855][ T9] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has invalid maxpacket 120, setting to 8 [ 228.690985][ T9] usb 2-1: config 0 interface 55 altsetting 0 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 228.704771][ T9] usb 2-1: New USB device found, idVendor=0f11, idProduct=1080, bcdDevice=fc.6a [ 228.713849][ T9] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 228.723347][ T9] usb 2-1: config 0 descriptor?? [ 228.729024][ T7431] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 228.736322][ T7431] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 228.745938][ T9] ldusb 2-1:0.55: LD USB Device #0 now attached to major 180 minor 0 [ 229.017334][ T9] usb 2-1: USB disconnect, device number 17 [ 229.028158][ T9] ldusb 2-1:0.55: LD USB Device #0 now disconnected [ 229.793298][ T7437] erofs (device nullb0): cannot find valid erofs superblock [ 230.710170][ T9] usb 2-1: new high-speed USB device number 18 using dummy_hcd [ 230.861537][ T9] usb 2-1: config 0 has an invalid interface number: 1 but max is 0 [ 230.869548][ T9] usb 2-1: config 0 has no interface number 0 [ 230.875666][ T9] usb 2-1: New USB device found, idVendor=0bed, idProduct=1100, bcdDevice=ec.c3 [ 230.884718][ T9] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 230.894127][ T9] usb 2-1: config 0 descriptor?? [ 230.901220][ T9] cp210x 2-1:0.1: cp210x converter detected [ 231.103811][ T9] cp210x 2-1:0.1: failed to get vendor val 0x370b size 1: -121 [ 231.111391][ T9] cp210x 2-1:0.1: querying part number failed [ 231.119336][ T9] usb 2-1: cp210x converter now attached to ttyUSB0 [ 233.479204][ T5859] usb 2-1: USB disconnect, device number 18 [ 233.504559][ T5859] cp210x ttyUSB0: cp210x converter now disconnected from ttyUSB0 [ 233.516148][ T5859] cp210x 2-1:0.1: device disconnected [ 237.505405][ T7460] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 240.426377][ T7469] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 243.523767][ T7480] xt_NFQUEUE: number of queues (65532) out of range (got 66665) [ 245.300146][ T5866] usb 2-1: new high-speed USB device number 19 using dummy_hcd [ 245.450084][ T5866] usb 2-1: Using ep0 maxpacket: 8 [ 245.456398][ T5866] usb 2-1: config 1 has 1 interface, different from the descriptor's value: 7 [ 245.466994][ T5866] usb 2-1: New USB device found, idVendor=082d, idProduct=0100, bcdDevice=70.4b [ 245.476055][ T5866] usb 2-1: New USB device strings: Mfr=44, Product=2, SerialNumber=3 [ 245.484147][ T5866] usb 2-1: Product: syz [ 245.488288][ T5866] usb 2-1: Manufacturer: syz [ 245.492947][ T5866] usb 2-1: SerialNumber: syz [ 245.705785][ T5866] usb 2-1: Handspring Visor / Palm OS: No valid connect info available [ 245.714064][ T5866] usb 2-1: Handspring Visor / Palm OS: port 167, is for unknown use [ 245.722182][ T5866] usb 2-1: Handspring Visor / Palm OS: port 62, is for unknown use [ 245.730122][ T5866] usb 2-1: Handspring Visor / Palm OS: Number of ports: 2 [ 245.913405][ T5866] visor 2-1:1.0: Handspring Visor / Palm OS converter detected [ 245.922413][ T5866] usb 2-1: Handspring Visor / Palm OS converter now attached to ttyUSB0 [ 245.933136][ T5866] usb 2-1: Handspring Visor / Palm OS converter now attached to ttyUSB1 [ 246.647211][ T5866] usb 2-1: USB disconnect, device number 19 [ 246.666205][ T5866] visor ttyUSB0: Handspring Visor / Palm OS converter now disconnected from ttyUSB0 [ 246.683248][ T5866] visor ttyUSB1: Handspring Visor / Palm OS converter now disconnected from ttyUSB1 [ 246.740660][ T5866] visor 2-1:1.0: device disconnected [ 247.120211][ T5866] usb 2-1: new full-speed USB device number 20 using dummy_hcd [ 247.423478][ T5866] usb 2-1: unable to get BOS descriptor or descriptor too short [ 247.433878][ T5866] usb 2-1: unable to read config index 0 descriptor/start: -71 [ 247.441479][ T5866] usb 2-1: can't read configurations, error -71 [ 250.111377][ T5937] usb 2-1: new high-speed USB device number 22 using dummy_hcd [ 250.260184][ T5937] usb 2-1: Using ep0 maxpacket: 8 [ 250.266341][ T5937] usb 2-1: config 179 has an invalid interface number: 65 but max is 0 [ 250.274656][ T5937] usb 2-1: config 179 has no interface number 0 [ 250.280974][ T5937] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0xF has an invalid bInterval 0, changing to 7 [ 250.292030][ T5937] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0xF has invalid maxpacket 1025, setting to 1024 [ 250.303248][ T5937] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0x83 has an invalid bInterval 0, changing to 7 [ 250.314392][ T5937] usb 2-1: config 179 interface 65 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 23 [ 250.327659][ T5937] usb 2-1: New USB device found, idVendor=12ab, idProduct=90a3, bcdDevice=1e.eb [ 250.336704][ T5937] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 250.347419][ T7501] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 250.585137][ T7501] netlink: 4 bytes leftover after parsing attributes in process `syz.1.419'. [ 250.599912][ T5859] usb 2-1: USB disconnect, device number 22 [ 250.599943][ C0] xpad 2-1:179.65: xpad_irq_in - usb_submit_urb failed with result -19 [ 250.614498][ C0] dummy_hcd dummy_hcd.1: timer fired with no URBs pending? [ 254.765782][ T7522] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 255.249083][ T1299] ieee802154 phy0 wpan0: encryption failed: -22 [ 255.258769][ T1299] ieee802154 phy1 wpan1: encryption failed: -22 [ 257.930110][ T5937] usb 2-1: new full-speed USB device number 23 using dummy_hcd [ 258.236257][ T5937] usb 2-1: unable to get BOS descriptor or descriptor too short [ 258.248403][ T5937] usb 2-1: unable to read config index 0 descriptor/start: -71 [ 258.256091][ T5937] usb 2-1: can't read configurations, error -71 [ 258.815981][ T7533] netlink: 'syz.1.428': attribute type 5 has an invalid length. [ 259.310161][ T5937] usb 2-1: new high-speed USB device number 24 using dummy_hcd [ 259.460096][ T5937] usb 2-1: Using ep0 maxpacket: 16 [ 259.466480][ T5937] usb 2-1: New USB device found, idVendor=0471, idProduct=0327, bcdDevice=61.a4 [ 259.476942][ T5937] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 259.486634][ T5937] usb 2-1: config 0 descriptor?? [ 259.498701][ T5937] gspca_main: sonixj-2.14.0 probing 0471:0327 [ 260.708959][ T5937] gspca_sonixj: reg_w1 err -71 [ 260.730131][ T5937] sonixj 2-1:0.0: probe with driver sonixj failed with error -71 [ 260.739857][ T5937] usb 2-1: USB disconnect, device number 24 [ 263.320129][ T5866] usb 2-1: new full-speed USB device number 25 using dummy_hcd [ 263.471357][ T5866] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 263.485681][ T5866] usb 2-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 263.494797][ T5866] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 263.502789][ T5866] usb 2-1: Product: syz [ 263.506914][ T5866] usb 2-1: Manufacturer: syz [ 263.511528][ T5866] usb 2-1: SerialNumber: syz [ 263.517551][ T5866] usb 2-1: config 0 descriptor?? [ 263.524191][ T5866] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 263.535274][ T5866] dvb-usb: bulk message failed: -22 (3/0) [ 263.563863][ T5866] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 263.572757][ T5866] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 263.584277][ T5866] usb 2-1: media controller created [ 263.590418][ T5866] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 263.601246][ T5866] dvb-usb: bulk message failed: -22 (6/0) [ 263.606990][ T5866] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 263.619828][ T5866] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.1/usb2/2-1/input/input24 [ 263.631827][ T5866] dvb-usb: schedule remote query interval to 150 msecs. [ 263.638786][ T5866] dvb-usb: bulk message failed: -22 (3/0) [ 263.670149][ T5866] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 263.771925][ T7551] dibusb: i2c wr: len=61 is too big! [ 263.771925][ T7551] [ 263.780937][ T5866] usb 2-1: USB disconnect, device number 25 [ 263.799294][ T5866] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 265.265202][ T7559] netlink: 24 bytes leftover after parsing attributes in process `syz.1.435'. [ 265.550162][ T5866] usb 2-1: new full-speed USB device number 26 using dummy_hcd [ 265.701318][ T5866] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 265.713178][ T5866] usb 2-1: New USB device found, idVendor=1822, idProduct=3202, bcdDevice=13.4a [ 265.722265][ T5866] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 265.730300][ T5866] usb 2-1: Product: syz [ 265.734449][ T5866] usb 2-1: Manufacturer: syz [ 265.739009][ T5866] usb 2-1: SerialNumber: syz [ 265.745466][ T5866] usb 2-1: config 0 descriptor?? [ 265.752992][ T5866] dvb-usb: found a 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' in warm state. [ 265.764067][ T5866] dvb-usb: bulk message failed: -22 (3/0) [ 265.782919][ T5866] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 265.791691][ T5866] dvbdev: DVB: registering new adapter (TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device) [ 265.807112][ T5866] usb 2-1: media controller created [ 265.813294][ T5866] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 265.823678][ T5866] dvb-usb: bulk message failed: -22 (6/0) [ 265.829425][ T5866] dvb-usb: no frontend was attached by 'TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device' [ 265.842737][ T5866] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.1/usb2/2-1/input/input25 [ 265.854927][ T5866] dvb-usb: schedule remote query interval to 150 msecs. [ 265.861915][ T5866] dvb-usb: bulk message failed: -22 (3/0) [ 265.880097][ T5866] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I / HAMA USB1.1 DVB-T device successfully initialized and connected. [ 265.976122][ T7561] dibusb: i2c wr: len=61 is too big! [ 265.976122][ T7561] [ 265.984906][ T1206] usb 2-1: USB disconnect, device number 26 [ 266.004506][ T1206] dvb-usb: TwinhanDTV USB-Ter USB1.1 / Magic Box I successfully deinitialized and disconnected. [ 271.500087][ T920] usb 2-1: new high-speed USB device number 27 using dummy_hcd [ 271.670153][ T920] usb 2-1: Using ep0 maxpacket: 16 [ 271.676512][ T920] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x83 has an invalid bInterval 0, changing to 7 [ 271.689161][ T920] usb 2-1: New USB device found, idVendor=134c, idProduct=0002, bcdDevice=ec.7e [ 271.698204][ T920] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 271.706224][ T920] usb 2-1: Product: syz [ 271.710443][ T920] usb 2-1: Manufacturer: syz [ 271.715037][ T920] usb 2-1: SerialNumber: syz [ 271.721288][ T920] usb 2-1: config 0 descriptor?? [ 271.727455][ T920] hub 2-1:0.0: bad descriptor, ignoring hub [ 271.733461][ T920] hub 2-1:0.0: probe with driver hub failed with error -5 [ 271.742140][ T920] input: syz syz as /devices/platform/dummy_hcd.1/usb2/2-1/2-1:0.0/input/input26 [ 272.070788][ T5818] usb 2-1: USB disconnect, device number 27 [ 273.621869][ T7596] syz.1.445: attempt to access beyond end of device [ 273.621869][ T7596] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 273.635193][ T7596] syz.1.445: attempt to access beyond end of device [ 273.635193][ T7596] nbd1: rw=0, sector=120, nr_sectors = 8 limit=0 [ 273.665639][ T7596] Mount JFS Failure: -5 [ 273.698466][ T7596] jfs_mount failed w/return code = -5 [ 274.425402][ T30] audit: type=1400 audit(1748476743.629:342): avc: denied { watch watch_reads } for pid=7598 comm="syz.1.446" path="/194" dev="tmpfs" ino=1030 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=dir permissive=1 [ 277.004108][ T30] audit: type=1400 audit(1748476746.209:343): avc: denied { setopt } for pid=7615 comm="syz.1.450" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=pppox_socket permissive=1 [ 277.912447][ T7620] syz.1.450 (7620): drop_caches: 2 [ 279.140085][ T1206] usb 2-1: new low-speed USB device number 28 using dummy_hcd [ 279.291223][ T1206] usb 2-1: config 0 has an invalid interface number: 55 but max is 0 [ 279.299301][ T1206] usb 2-1: config 0 has no interface number 0 [ 279.305474][ T1206] usb 2-1: config 0 interface 55 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 279.317754][ T1206] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0xE has invalid maxpacket 32, setting to 8 [ 279.328418][ T1206] usb 2-1: config 0 interface 55 altsetting 0 has an endpoint descriptor with address 0xAB, changing to 0x8B [ 279.339995][ T1206] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 10 [ 279.351118][ T1206] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has invalid maxpacket 120, setting to 8 [ 279.361901][ T1206] usb 2-1: config 0 interface 55 altsetting 0 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 279.374866][ T1206] usb 2-1: New USB device found, idVendor=0f11, idProduct=1080, bcdDevice=fc.6a [ 279.383916][ T1206] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 279.393404][ T1206] usb 2-1: config 0 descriptor?? [ 279.399059][ T7628] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 279.406506][ T7628] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 279.418561][ T1206] ldusb 2-1:0.55: LD USB Device #0 now attached to major 180 minor 0 [ 279.685851][ T1206] usb 2-1: USB disconnect, device number 28 [ 279.701633][ T1206] ldusb 2-1:0.55: LD USB Device #0 now disconnected [ 282.727379][ T7645] syz.1.456 (7645): drop_caches: 2 [ 283.980080][ T1206] usb 2-1: new low-speed USB device number 29 using dummy_hcd [ 284.131910][ T1206] usb 2-1: config 0 has an invalid interface number: 55 but max is 0 [ 284.140071][ T1206] usb 2-1: config 0 has no interface number 0 [ 284.146155][ T1206] usb 2-1: config 0 interface 55 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 284.156981][ T1206] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0xE has invalid maxpacket 32, setting to 8 [ 284.167631][ T1206] usb 2-1: config 0 interface 55 altsetting 0 has an endpoint descriptor with address 0xAB, changing to 0x8B [ 284.182702][ T1206] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 10 [ 284.193920][ T1206] usb 2-1: config 0 interface 55 altsetting 0 endpoint 0x8B has invalid maxpacket 120, setting to 8 [ 284.204825][ T1206] usb 2-1: config 0 interface 55 altsetting 0 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 284.217835][ T1206] usb 2-1: New USB device found, idVendor=0f11, idProduct=1080, bcdDevice=fc.6a [ 284.226885][ T1206] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 284.236118][ T1206] usb 2-1: config 0 descriptor?? [ 284.241741][ T7652] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 284.249003][ T7652] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 284.261254][ T1206] ldusb 2-1:0.55: LD USB Device #0 now attached to major 180 minor 0 [ 284.532259][ T9] usb 2-1: USB disconnect, device number 29 [ 284.543029][ T9] ldusb 2-1:0.55: LD USB Device #0 now disconnected [ 285.174990][ T7661] syz.1.459: attempt to access beyond end of device [ 285.174990][ T7661] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 285.188300][ T7661] syz.1.459: attempt to access beyond end of device [ 285.188300][ T7661] nbd1: rw=0, sector=120, nr_sectors = 8 limit=0 [ 285.201528][ T7661] Mount JFS Failure: -5 [ 285.205708][ T7661] jfs_mount failed w/return code = -5 [ 286.174761][ T7667] syz.1.460: attempt to access beyond end of device [ 286.174761][ T7667] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 286.188041][ T7667] syz.1.460: attempt to access beyond end of device [ 286.188041][ T7667] nbd1: rw=0, sector=120, nr_sectors = 8 limit=0 [ 286.201229][ T7667] Mount JFS Failure: -5 [ 286.205421][ T7667] jfs_mount failed w/return code = -5 [ 287.107180][ T7675] syz.1.462 (7675): drop_caches: 2 [ 287.505805][ T7680] syz.1.463 (7680): drop_caches: 2 [ 291.963120][ T9] usb 2-1: new high-speed USB device number 30 using dummy_hcd [ 292.130129][ T9] usb 2-1: Using ep0 maxpacket: 16 [ 292.136814][ T9] usb 2-1: config 64 has an invalid interface number: 176 but max is 0 [ 292.145227][ T9] usb 2-1: config 64 has no interface number 0 [ 292.151418][ T9] usb 2-1: config 64 interface 176 has no altsetting 0 [ 292.159688][ T9] usb 2-1: New USB device found, idVendor=0c72, idProduct=0014, bcdDevice=14.8d [ 292.168779][ T9] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 292.176855][ T9] usb 2-1: Product: syz [ 292.181071][ T9] usb 2-1: Manufacturer: syz [ 292.185651][ T9] usb 2-1: SerialNumber: syz [ 292.420587][ T9] peak_usb 2-1:64.176 can0: unable to request usb[type=0 value=1] err=-71 [ 292.429115][ T9] peak_usb 2-1:64.176: unable to read PCAN-USB X6 firmware info (err -71) [ 292.480511][ T9] peak_usb 2-1:64.176: probe with driver peak_usb failed with error -71 [ 292.491890][ T9] usb 2-1: USB disconnect, device number 30 [ 293.117400][ T7721] syz.1.471 (7721): drop_caches: 2 [ 293.579158][ T7728] syz.1.473: attempt to access beyond end of device [ 293.579158][ T7728] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 293.593356][ T7728] syz.1.473: attempt to access beyond end of device [ 293.593356][ T7728] nbd1: rw=0, sector=120, nr_sectors = 8 limit=0 [ 293.606491][ T7728] Mount JFS Failure: -5 [ 293.610729][ T7728] jfs_mount failed w/return code = -5 [ 294.462233][ T7734] syz.1.474: attempt to access beyond end of device [ 294.462233][ T7734] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 294.476380][ T7734] syz.1.474: attempt to access beyond end of device [ 294.476380][ T7734] nbd1: rw=0, sector=120, nr_sectors = 8 limit=0 [ 294.489386][ T7734] Mount JFS Failure: -5 [ 294.493632][ T7734] jfs_mount failed w/return code = -5 [ 295.407624][ T7740] syz.1.475 (7740): drop_caches: 2 [ 295.742868][ T7742] netlink: 'syz.1.476': attribute type 5 has an invalid length. [ 297.737579][ T7758] syz.1.480: attempt to access beyond end of device [ 297.737579][ T7758] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 297.750968][ T7758] syz.1.480: attempt to access beyond end of device [ 297.750968][ T7758] nbd1: rw=0, sector=120, nr_sectors = 8 limit=0 [ 297.763974][ T7758] Mount JFS Failure: -5 [ 297.769079][ T7758] jfs_mount failed w/return code = -5 [ 298.121013][ T31] INFO: task kworker/1:7:5896 blocked for more than 143 seconds. [ 298.145096][ T31] Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 SYZFAIL: failed to recv rpc fd=3 want=4 recv=0 n=0 (errno 9: Bad file descriptor) [ 298.169082][ T31] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. [ 298.192557][ T31] task:kworker/1:7 state:D stack:22360 pid:5896 tgid:5896 ppid:2 task_flags:0x4208060 flags:0x00004000 [ 298.259287][ T31] Workqueue: events rfkill_global_led_trigger_worker [ 298.300641][ T31] Call Trace: [ 298.318414][ T31] [ 298.356410][ T31] __schedule+0x116a/0x5de0 [ 298.429711][ T31] ? find_held_lock+0x2b/0x80 [ 298.477558][ T31] ? _raw_spin_unlock_irqrestore+0x3b/0x80 [ 298.483474][ T31] ? __pfx___schedule+0x10/0x10 [ 298.488350][ T31] ? find_held_lock+0x2b/0x80 [ 298.493097][ T31] ? schedule+0x2d7/0x3a0 [ 298.497442][ T31] schedule+0xe7/0x3a0 [ 298.501549][ T31] schedule_preempt_disabled+0x13/0x30 [ 298.507017][ T31] __mutex_lock+0x6c7/0xb90 [ 298.511592][ T31] ? rfkill_global_led_trigger_worker+0x1b/0x160 [ 298.517927][ T31] ? __pfx___mutex_lock+0x10/0x10 [ 298.523128][ T31] ? _raw_spin_unlock_irqrestore+0x3b/0x80 [ 298.528944][ T31] ? finish_task_switch.isra.0+0x221/0xc10 [ 298.534857][ T31] ? rfkill_global_led_trigger_worker+0x1b/0x160 [ 298.541343][ T31] rfkill_global_led_trigger_worker+0x1b/0x160 [ 298.547510][ T31] process_one_work+0x9cf/0x1b70 [ 298.552552][ T31] ? __pfx_process_one_work+0x10/0x10 [ 298.558305][ T31] ? assign_work+0x1a0/0x250 [ 298.562940][ T31] worker_thread+0x6c8/0xf10 [ 298.567569][ T31] ? __kthread_parkme+0x19e/0x250 [ 298.572666][ T31] ? __pfx_worker_thread+0x10/0x10 [ 298.577787][ T31] kthread+0x3c5/0x780 [ 298.581902][ T31] ? __pfx_kthread+0x10/0x10 [ 298.590059][ T31] ? rcu_is_watching+0x12/0xc0 [ 298.594808][ T31] ? __pfx_kthread+0x10/0x10 [ 298.599377][ T31] ret_from_fork+0x5d4/0x6f0 [ 298.604025][ T31] ? __pfx_kthread+0x10/0x10 [ 298.610078][ T31] ret_from_fork_asm+0x1a/0x30 [ 298.614854][ T31] [ 298.617876][ T31] INFO: task syz.2.245:6848 blocked for more than 143 seconds. [ 298.625468][ T31] Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 [ 298.640122][ T31] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. [ 298.650062][ T31] task:syz.2.245 state:D stack:26488 pid:6848 tgid:6848 ppid:5815 task_flags:0x400040 flags:0x00004004 [ 298.662028][ T31] Call Trace: [ 298.670073][ T31] [ 298.673014][ T31] __schedule+0x116a/0x5de0 [ 298.677544][ T31] ? __pfx___schedule+0x10/0x10 [ 298.682473][ T31] ? find_held_lock+0x2b/0x80 [ 298.687161][ T31] ? schedule+0x2d7/0x3a0 [ 298.691568][ T31] schedule+0xe7/0x3a0 [ 298.695657][ T31] schedule_preempt_disabled+0x13/0x30 [ 298.710170][ T31] __mutex_lock+0x6c7/0xb90 [ 298.714694][ T31] ? rfkill_unregister+0xec/0x2c0 [ 298.719723][ T31] ? __pfx___mutex_lock+0x10/0x10 [ 298.724794][ T31] ? device_del+0x6b6/0x9f0 [ 298.730128][ T31] ? __pfx_device_del+0x10/0x10 [ 298.734996][ T31] ? rfkill_unregister+0xec/0x2c0 [ 298.750131][ T31] rfkill_unregister+0xec/0x2c0 [ 298.755001][ T31] nfc_unregister_device+0x94/0x330 [ 298.760236][ T31] ? __pfx_virtual_ncidev_close+0x10/0x10 [ 298.770058][ T31] virtual_ncidev_close+0x4b/0xa0 [ 298.780105][ T31] __fput+0x402/0xb70 [ 298.790535][ T31] task_work_run+0x14d/0x240 [ 298.795151][ T31] ? __pfx_task_work_run+0x10/0x10 [ 298.801277][ T31] ? __pfx___do_sys_close_range+0x10/0x10 [ 298.806999][ T31] ? xfd_validate_state+0x61/0x180 [ 298.812129][ T31] exit_to_user_mode_loop+0xeb/0x110 [ 298.817421][ T31] do_syscall_64+0x3f6/0x4c0 [ 298.822156][ T31] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 298.828044][ T31] RIP: 0033:0x7f286cd8e969 [ 298.832472][ T31] RSP: 002b:00007ffc7b959e68 EFLAGS: 00000246 ORIG_RAX: 00000000000001b4 [ 298.840932][ T31] RAX: 0000000000000000 RBX: 00007f286cfb7ba0 RCX: 00007f286cd8e969 [ 298.848899][ T31] RDX: 0000000000000000 RSI: 000000000000001e RDI: 0000000000000003 [ 298.856885][ T31] RBP: 00007f286cfb7ba0 R08: 0000000000005da0 R09: 0000001b7b95a15f [ 298.864875][ T31] R10: 00007f286cfb7ac0 R11: 0000000000000246 R12: 0000000000024417 [ 298.872859][ T31] R13: 00007f286cfb5fa0 R14: ffffffffffffffff R15: 00007ffc7b959f80 [ 298.880883][ T31] [ 298.883905][ T31] INFO: task syz.4.270:7005 blocked for more than 144 seconds. [ 298.891627][ T31] Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 [ 298.898929][ T31] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. [ 298.907626][ T31] task:syz.4.270 state:D stack:26280 pid:7005 tgid:6999 ppid:5817 task_flags:0x400140 flags:0x00004006 [ 298.919582][ T31] Call Trace: [ 298.923072][ T31] [ 298.926000][ T31] __schedule+0x116a/0x5de0 [ 298.930694][ T31] ? __lock_acquire+0x622/0x1c90 [ 298.935633][ T31] ? __pfx___schedule+0x10/0x10 [ 298.940631][ T31] ? find_held_lock+0x2b/0x80 [ 298.945304][ T31] ? schedule+0x2d7/0x3a0 [ 298.949613][ T31] schedule+0xe7/0x3a0 [ 298.953812][ T31] schedule_preempt_disabled+0x13/0x30 [ 298.959275][ T31] __mutex_lock+0x6c7/0xb90 [ 298.963798][ T31] ? rfkill_register+0x3a/0xb40 [ 298.968645][ T31] ? __pfx___mutex_lock+0x10/0x10 [ 298.973673][ T31] ? preempt_schedule_common+0x44/0xc0 [ 298.979132][ T31] ? lockdep_init_map_type+0x5c/0x280 [ 298.984520][ T31] ? __init_waitqueue_head+0xca/0x150 [ 298.989883][ T31] ? rfkill_register+0x3a/0xb40 [ 298.994757][ T31] ? rfkill_alloc+0x25b/0x330 [ 298.999435][ T31] rfkill_register+0x3a/0xb40 [ 299.004162][ T31] hci_register_dev+0x3cc/0xc60 [ 299.009015][ T31] hci_uart_tty_ioctl+0x7e2/0xc30 [ 299.014073][ T31] ? __pfx_hci_uart_tty_ioctl+0x10/0x10 [ 299.019636][ T31] tty_ioctl+0x6f6/0x1610 [ 299.023978][ T31] ? __pfx_tty_ioctl+0x10/0x10 [ 299.028732][ T31] ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 [ 299.035596][ T31] ? hook_file_ioctl_common+0x145/0x410 [ 299.041186][ T31] ? selinux_file_ioctl+0x180/0x270 [ 299.046385][ T31] ? selinux_file_ioctl+0xb4/0x270 [ 299.051512][ T31] ? __pfx_tty_ioctl+0x10/0x10 [ 299.056268][ T31] __x64_sys_ioctl+0x18e/0x210 [ 299.061063][ T31] do_syscall_64+0xcd/0x4c0 [ 299.065560][ T31] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 299.071480][ T31] RIP: 0033:0x7fd5c258e969 [ 299.075884][ T31] RSP: 002b:00007fd5c3453038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 299.084303][ T31] RAX: ffffffffffffffda RBX: 00007fd5c27b6160 RCX: 00007fd5c258e969 [ 299.092283][ T31] RDX: 0000000000000000 RSI: 00000000400455c8 RDI: 0000000000000006 [ 299.100273][ T31] RBP: 00007fd5c2610ab1 R08: 0000000000000000 R09: 0000000000000000 [ 299.108238][ T31] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 299.116231][ T31] R13: 0000000000000000 R14: 00007fd5c27b6160 R15: 00007ffcc879e938 [ 299.124240][ T31] [ 299.127279][ T31] [ 299.127279][ T31] Showing all locks held in the system: [ 299.135289][ T31] 1 lock held by khungtaskd/31: [ 299.141567][ T31] #0: ffffffff8e3c27c0 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x36/0x1c0 [ 299.151627][ T31] 1 lock held by klogd/5172: [ 299.156256][ T31] #0: ffff8880b843a218 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x7e/0x130 [ 299.166250][ T31] 2 locks held by getty/5567: [ 299.171015][ T31] #0: ffff888032ef60a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 [ 299.180838][ T31] #1: ffffc900036bb2f0 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x41b/0x14f0 [ 299.191100][ T31] 1 lock held by syz-executor/5806: [ 299.196282][ T31] #0: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_unregister+0xec/0x2c0 [ 299.206385][ T31] 1 lock held by syz-executor/5807: [ 299.211593][ T31] #0: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_unregister+0xec/0x2c0 [ 299.221703][ T31] 4 locks held by kworker/1:5/5861: [ 299.226882][ T31] #0: ffff88801b478d48 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x12a2/0x1b70 [ 299.237338][ T31] #1: ffffc90005487d10 ((rfkill_op_work).work){+.+.}-{0:0}, at: process_one_work+0x929/0x1b70 [ 299.247761][ T31] #2: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_epo+0x55/0x1d0 [ 299.257297][ T31] #3: ffff88805ca6c100 (&dev->mutex){....}-{4:4}, at: nfc_dev_down+0x2d/0x2e0 [ 299.266295][ T31] 1 lock held by kworker/1:6/5866: [ 299.271548][ T31] #0: ffff8880b843a218 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x7e/0x130 [ 299.281691][ T31] 3 locks held by kworker/1:7/5896: [ 299.286896][ T31] #0: ffff88801b478d48 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x12a2/0x1b70 [ 299.297336][ T31] #1: ffffc90005547d10 ((work_completion)(&rfkill_global_led_trigger_work)){+.+.}-{0:0}, at: process_one_work+0x929/0x1b70 [ 299.310250][ T31] #2: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_global_led_trigger_worker+0x1b/0x160 [ 299.321853][ T31] 2 locks held by kworker/u8:10/6021: [ 299.327212][ T31] #0: ffff8880b843a218 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x7e/0x130 [ 299.337139][ T31] #1: ffff8880b8424048 (&per_cpu_ptr(group->pcpu, cpu)->seq){-.-.}-{0:0}, at: psi_task_switch+0x2c1/0x8e0 [ 299.348613][ T31] 2 locks held by syz.2.245/6848: [ 299.353718][ T31] #0: ffff88805ca6c100 (&dev->mutex){....}-{4:4}, at: nfc_unregister_device+0x60/0x330 [ 299.363676][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_unregister+0xec/0x2c0 [ 299.373921][ T31] 2 locks held by syz.4.270/7005: [ 299.378941][ T31] #0: ffff88805a4480a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 [ 299.388702][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.398657][ T31] 2 locks held by syz-executor/7083: [ 299.404823][ T31] #0: ffff888033757118 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.414280][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.424221][ T31] 2 locks held by syz-executor/7142: [ 299.429489][ T31] #0: ffff88802a259118 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.438898][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.448845][ T31] 2 locks held by syz-executor/7151: [ 299.454155][ T31] #0: ffff8880771c0918 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.463595][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.473534][ T31] 2 locks held by syz-executor/7302: [ 299.478815][ T31] #0: ffff88802c054118 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.488533][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.498504][ T31] 2 locks held by syz-executor/7410: [ 299.503793][ T31] #0: ffff888031f9f918 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.513244][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.523212][ T31] 2 locks held by syz-executor/7441: [ 299.528480][ T31] #0: ffff8880292ed918 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.540064][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.551159][ T31] 2 locks held by syz-executor/7445: [ 299.556432][ T31] #0: ffff8880363ec118 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.566857][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.577203][ T31] 2 locks held by syz-executor/7538: [ 299.582514][ T31] #0: ffff88807da2e918 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.591975][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.601934][ T31] 2 locks held by syz-executor/7655: [ 299.607202][ T31] #0: ffff888033fb9918 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.616610][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.626571][ T31] 2 locks held by syz-executor/7699: [ 299.631881][ T31] #0: ffff888032e7b918 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.641317][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.651279][ T31] 2 locks held by syz-executor/7713: [ 299.656547][ T31] #0: ffff88805b280118 (&data->open_mutex){+.+.}-{4:4}, at: vhci_write+0x2b4/0x480 [ 299.665947][ T31] #1: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_register+0x3a/0xb40 [ 299.675908][ T31] 1 lock held by syz.1.480/7754: [ 299.680862][ T31] #0: ffffffff905d4b88 (rfkill_global_mutex){+.+.}-{4:4}, at: rfkill_unregister+0xec/0x2c0 [ 299.691003][ T31] [ 299.693322][ T31] ============================================= [ 299.693322][ T31] [ 299.701779][ T31] NMI backtrace for cpu 0 [ 299.701790][ T31] CPU: 0 UID: 0 PID: 31 Comm: khungtaskd Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 299.701810][ T31] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 299.701821][ T31] Call Trace: [ 299.701826][ T31] [ 299.701833][ T31] dump_stack_lvl+0x116/0x1f0 [ 299.701851][ T31] nmi_cpu_backtrace+0x27b/0x390 [ 299.701875][ T31] ? __pfx_nmi_raise_cpu_backtrace+0x10/0x10 [ 299.701898][ T31] nmi_trigger_cpumask_backtrace+0x29c/0x300 [ 299.701923][ T31] watchdog+0xf70/0x12c0 [ 299.701944][ T31] ? __pfx_watchdog+0x10/0x10 [ 299.701957][ T31] ? lockdep_hardirqs_on+0x7c/0x110 [ 299.701984][ T31] ? __kthread_parkme+0x19e/0x250 [ 299.702007][ T31] ? __pfx_watchdog+0x10/0x10 [ 299.702022][ T31] kthread+0x3c5/0x780 [ 299.702046][ T31] ? __pfx_kthread+0x10/0x10 [ 299.702071][ T31] ? rcu_is_watching+0x12/0xc0 [ 299.702089][ T31] ? __pfx_kthread+0x10/0x10 [ 299.702114][ T31] ret_from_fork+0x5d4/0x6f0 [ 299.702140][ T31] ? __pfx_kthread+0x10/0x10 [ 299.702165][ T31] ret_from_fork_asm+0x1a/0x30 [ 299.702194][ T31] [ 299.702200][ T31] Sending NMI from CPU 0 to CPUs 1: [ 299.819362][ C1] NMI backtrace for cpu 1 [ 299.819375][ C1] CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 299.819392][ C1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 299.819400][ C1] RIP: 0010:pv_native_safe_halt+0xf/0x20 [ 299.819424][ C1] Code: 66 5a 02 e9 43 fb 02 00 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d e3 43 14 00 fb f4 cc cc cc cc 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90 [ 299.819436][ C1] RSP: 0018:ffffc90000197df8 EFLAGS: 000002c6 [ 299.819447][ C1] RAX: 0000000000e30cb9 RBX: 0000000000000001 RCX: ffffffff8b75c0d9 [ 299.819456][ C1] RDX: 0000000000000000 RSI: ffffffff8dbf4484 RDI: ffffffff8bf51500 [ 299.819465][ C1] RBP: ffffed1003c5e488 R08: 0000000000000001 R09: ffffed10170a663d [ 299.819473][ C1] R10: ffff8880b85331eb R11: 0000000000000001 R12: 0000000000000001 [ 299.819481][ C1] R13: ffff88801e2f2440 R14: ffffffff90866450 R15: 0000000000000000 [ 299.819489][ C1] FS: 0000000000000000(0000) GS:ffff888124a9f000(0000) knlGS:0000000000000000 [ 299.819503][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 299.819511][ C1] CR2: 00005637a9033c68 CR3: 00000000347b4000 CR4: 00000000003526f0 [ 299.819520][ C1] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 299.819527][ C1] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 299.819535][ C1] Call Trace: [ 299.819539][ C1] [ 299.819544][ C1] default_idle+0x13/0x20 [ 299.819557][ C1] default_idle_call+0x6d/0xb0 [ 299.819570][ C1] do_idle+0x391/0x510 [ 299.819584][ C1] ? __pfx_do_idle+0x10/0x10 [ 299.819597][ C1] ? trace_sched_exit_tp+0x31/0x130 [ 299.819614][ C1] cpu_startup_entry+0x4f/0x60 [ 299.819627][ C1] start_secondary+0x21d/0x2b0 [ 299.819642][ C1] ? __pfx_start_secondary+0x10/0x10 [ 299.819658][ C1] common_startup_64+0x13e/0x148 [ 299.819680][ C1] [ 299.820535][ T31] Kernel panic - not syncing: hung_task: blocked tasks [ 299.820547][ T31] CPU: 0 UID: 0 PID: 31 Comm: khungtaskd Not tainted 6.15.0-syzkaller-03645-g3d413f0cfd7e #0 PREEMPT(full) [ 299.820566][ T31] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 299.820574][ T31] Call Trace: [ 299.820580][ T31] [ 299.820586][ T31] dump_stack_lvl+0x3d/0x1f0 [ 299.820603][ T31] panic+0x71c/0x800 [ 299.820622][ T31] ? __pfx_panic+0x10/0x10 [ 299.820640][ T31] ? preempt_schedule_thunk+0x16/0x30 [ 299.820661][ T31] ? __pfx_nmi_raise_cpu_backtrace+0x10/0x10 [ 299.820679][ T31] ? preempt_schedule_thunk+0x16/0x30 [ 299.820697][ T31] ? watchdog+0xdda/0x12c0 [ 299.820711][ T31] ? watchdog+0xdcd/0x12c0 [ 299.820727][ T31] watchdog+0xdeb/0x12c0 [ 299.820744][ T31] ? __pfx_watchdog+0x10/0x10 [ 299.820757][ T31] ? lockdep_hardirqs_on+0x7c/0x110 [ 299.820781][ T31] ? __kthread_parkme+0x19e/0x250 [ 299.820800][ T31] ? __pfx_watchdog+0x10/0x10 [ 299.820813][ T31] kthread+0x3c5/0x780 [ 299.820834][ T31] ? __pfx_kthread+0x10/0x10 [ 299.820855][ T31] ? rcu_is_watching+0x12/0xc0 [ 299.820882][ T31] ? __pfx_kthread+0x10/0x10 [ 299.820903][ T31] ret_from_fork+0x5d4/0x6f0 [ 299.820921][ T31] ? __pfx_kthread+0x10/0x10 [ 299.820942][ T31] ret_from_fork_asm+0x1a/0x30 [ 299.820965][ T31] [ 300.138140][ T31] Kernel Offset: disabled [ 300.142440][ T31] Rebooting in 86400 seconds..