last executing test programs: 24.645309284s ago: executing program 1 (id=1086): r0 = openat$snapshot(0xffffffffffffff9c, &(0x7f00000000c0), 0xc2d41, 0x0) syz_emit_ethernet(0x6f, &(0x7f00000002c0)=ANY=[@ANYBLOB="aaaaaaaaaaaaaaaaaaaaaabb0800450000610000000000069078ac1414bbac1414aa00004001", @ANYRES32=0x41424344, @ANYRES32=0x41424344, @ANYBLOB="500208009078000089668ad37d64d0c044d604d5d763e5b32a1fd298c04d9987179a7bf089347dd07dd9d2e5dc0a858dcb33b28fb9ee3f05874413a64913610182c943eae8ab762207643eaa6ff93934d7bb9d0dc522d47ffb542ba1f43fb7388c83a2d872971adaf7590683db9a87e9146184b67923ae6494e0384fd37d5ccad378a46464959e234395657b0ed70f33afc4feffc8580d80c080e834d2c2a26e584b457d3aa104da9aa4c1774b96a2a8c0ad89f2c9b2ad3d9f2cc353e97f79e0df7c106f4dba105326af868e4eecf6a976137b13660616529a6a78d0af7e9454b257104096deacbb438df4443297da223809f35d636b43188ed203239778c6b06118b24baacf01eabb5bbf3947a558d6b19a2df284235f09975e09eb669ed1e1fd5695dd856b3ade"], 0x0) syz_usb_connect$hid(0x6, 0x36, &(0x7f0000000180)=ANY=[], 0x0) ioctl$SNAPSHOT_AVAIL_SWAP_SIZE(r0, 0x80083313, 0x0) r1 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) r2 = syz_open_dev$sg(&(0x7f0000000000), 0xf9ba, 0x80000) ioctl$SCSI_IOCTL_SEND_COMMAND(r2, 0x1, &(0x7f00000002c0)={0x0, 0x401, 0x55}) fcntl$getflags(r1, 0xb) ioctl$FS_IOC_FSSETXATTR(r1, 0x401c5820, &(0x7f00000008c0)={0xc0}) creat(&(0x7f0000000080)='./bus\x00', 0xa) openat$snapshot(0xffffffffffffff9c, &(0x7f00000000c0), 0xc2d41, 0x0) (async) syz_emit_ethernet(0x6f, &(0x7f00000002c0)=ANY=[@ANYBLOB="aaaaaaaaaaaaaaaaaaaaaabb0800450000610000000000069078ac1414bbac1414aa00004001", @ANYRES32=0x41424344, @ANYRES32=0x41424344, @ANYBLOB="500208009078000089668ad37d64d0c044d604d5d763e5b32a1fd298c04d9987179a7bf089347dd07dd9d2e5dc0a858dcb33b28fb9ee3f05874413a64913610182c943eae8ab762207643eaa6ff93934d7bb9d0dc522d47ffb542ba1f43fb7388c83a2d872971adaf7590683db9a87e9146184b67923ae6494e0384fd37d5ccad378a46464959e234395657b0ed70f33afc4feffc8580d80c080e834d2c2a26e584b457d3aa104da9aa4c1774b96a2a8c0ad89f2c9b2ad3d9f2cc353e97f79e0df7c106f4dba105326af868e4eecf6a976137b13660616529a6a78d0af7e9454b257104096deacbb438df4443297da223809f35d636b43188ed203239778c6b06118b24baacf01eabb5bbf3947a558d6b19a2df284235f09975e09eb669ed1e1fd5695dd856b3ade"], 0x0) (async) syz_usb_connect$hid(0x6, 0x36, &(0x7f0000000180)=ANY=[], 0x0) (async) ioctl$SNAPSHOT_AVAIL_SWAP_SIZE(r0, 0x80083313, 0x0) (async) openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) (async) syz_open_dev$sg(&(0x7f0000000000), 0xf9ba, 0x80000) (async) ioctl$SCSI_IOCTL_SEND_COMMAND(r2, 0x1, &(0x7f00000002c0)={0x0, 0x401, 0x55}) (async) fcntl$getflags(r1, 0xb) (async) ioctl$FS_IOC_FSSETXATTR(r1, 0x401c5820, &(0x7f00000008c0)={0xc0}) (async) creat(&(0x7f0000000080)='./bus\x00', 0xa) (async) 24.581124945s ago: executing program 1 (id=1087): r0 = syz_open_dev$radio(&(0x7f0000000000), 0x1, 0x2) mkdir(&(0x7f0000000000)='./file0\x00', 0x0) mount$tmpfs(0x0, &(0x7f0000000040)='./file0\x00', &(0x7f0000000080), 0x0, &(0x7f0000000100)={[{@nr_inodes={'nr_inodes', 0x3d, [0x31]}}]}) chdir(&(0x7f0000000200)='./file0\x00') r1 = socket$unix(0x1, 0x5, 0x0) bind$unix(r1, &(0x7f0000000140)=@file={0x1, '\xe9\x1fq\x89Y\x1e\x923aK\x00'}, 0x6e) ioctl$VIDIOC_S_EXT_CTRLS(r0, 0xc0205648, &(0x7f0000000100)={0x0, 0x1, 0x7, 0xffffffffffffffff, 0x0, &(0x7f00000002c0)={0x9b090d, 0x2, '\x00', @p_u32=0x0}}) 24.580154498s ago: executing program 1 (id=1088): r0 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r0, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000000)=ANY=[@ANYBLOB="54010000100013070000000000000000ac1414bb000000000000000000000000e0000001000000000000000000000000000000090000fffe0a00000000000000", @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="e00000020000000020000000000000000000000032000000ac1e0001000000000000000000000000060000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000fcffffffffffffff00000000000000000000000000000000030000000000000002000000000000000000000000000000000000000000000000000000000000000000000002000400000000000000000048000200656362286369706865725f6e756c6c29000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001c0004000100000000000000e000000100"/268], 0x154}}, 0x0) socket$nl_xfrm(0x10, 0x3, 0x6) 24.579674449s ago: executing program 1 (id=1089): mkdir(&(0x7f0000000440)='./file1\x00', 0x0) mount(0x0, &(0x7f0000000240)='./file1\x00', &(0x7f0000000000)='tmpfs\x00', 0x0, &(0x7f0000000300)='usrquota') chdir(&(0x7f0000000140)='./file1\x00') r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000040)='net_prio.prioidx\x00', 0x275a, 0x0) quotactl_fd$Q_SETQUOTA(r0, 0xffffffff80000800, 0x0, &(0x7f00000000c0)={0x0, 0x5b81, 0xc0, 0x2, 0x9, 0x9, 0x0, 0x0, 0xde}) mkdir(&(0x7f00000003c0)='./file0\x00', 0x21) mkdirat(0xffffffffffffff9c, &(0x7f0000000040)='./file1\x00', 0x0) mkdir(&(0x7f0000000200)='./bus\x00', 0x10) (async) mkdir(&(0x7f0000000200)='./bus\x00', 0x10) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x200902, &(0x7f0000000100)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) socket$nl_generic(0x10, 0x3, 0x10) (async) r1 = socket$nl_generic(0x10, 0x3, 0x10) madvise(&(0x7f0000bdc000/0x4000)=nil, 0x86ac726dff2f4713, 0xa) (async) madvise(&(0x7f0000bdc000/0x4000)=nil, 0x86ac726dff2f4713, 0xa) syz_clone(0x84000, 0x0, 0x0, 0x0, 0x0, 0x0) (async) syz_clone(0x84000, 0x0, 0x0, 0x0, 0x0, 0x0) r2 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r2, &(0x7f00000005c0)={0x0, 0x0, &(0x7f0000000580)={&(0x7f0000000240)=@migrate={0x27c, 0x21, 0x1, 0x0, 0x1, {{@in, @in6=@remote}}, [@migrate={0x219, 0x11, [{@in=@multicast1, @in=@local, @in=@local, @in=@broadcast, 0x3c, 0x4, 0x0, 0x3505, 0xa, 0x2}, {@in=@empty, @in=@initdev={0xac, 0x1e, 0x0, 0x0}, @in=@multicast2, @in6=@empty, 0x6c, 0x1, 0x0, 0x3506, 0x2, 0x2}, {@in=@empty, @in=@private=0xa010100, @in6=@remote, @in6=@mcast2, 0x33, 0x2, 0x0, 0x0, 0xa, 0xa}, {@in=@local, @in6=@local, @in6=@empty, @in6=@private2, 0xff, 0x3, 0x0, 0x3503, 0x8, 0x2}, {@in=@broadcast, @in6=@ipv4={'\x00', '\xff\xff', @multicast2}, @in=@private, @in=@dev, 0x0, 0x1, 0x0, 0x3506, 0x2, 0xf}, {@in6=@mcast2, @in=@broadcast, @in6=@private2, @in6=@remote}]}, @policy_type={0xa}, @replay_esn_val={0x40, 0x17, {0x9, 0x70bd29, 0x70bd2d, 0x70bd27, 0x70bd28, 0x7f, [0x0, 0x7, 0x7, 0x5, 0x80, 0x0, 0x5, 0xfffffff7, 0x6]}}, @proto={0x5, 0x19, 0x6c}, @mark={0xc, 0x15, {0x35075d, 0x3}}]}, 0x27c}}, 0x0) r3 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000a00), 0xffffffffffffffff) socket$nl_generic(0x10, 0x3, 0x10) (async) r4 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$sock_SIOCGIFINDEX_80211(r4, 0x8933, &(0x7f00000000c0)={'wlan0\x00'}) (async) ioctl$sock_SIOCGIFINDEX_80211(r4, 0x8933, &(0x7f00000000c0)={'wlan0\x00', 0x0}) sendmsg$NL80211_CMD_DEL_KEY(r1, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000000)=ANY=[@ANYBLOB=',\x00\x00\x00', @ANYRES16=r3, @ANYBLOB="01002cbd7000fedbdf250c00000008000300", @ANYRES32=r5, @ANYBLOB="05000100010000000800370001003e16d2f376bfed0000011d4c7dfda1f76797b6b95743df4f25e6ff8c270e283e2021abe343154e54acf46443ad91897f991d808ae129b229482d7487d976fbe5145d6862b120edc0ec5f24a6ce97700466ff543d45249cd30809ed6186ef104ccd1056"], 0x2c}, 0x1, 0x0, 0x0, 0x48000}, 0x20) 24.430812743s ago: executing program 1 (id=1090): r0 = syz_open_dev$radio(&(0x7f0000001640), 0x0, 0x2) r1 = syz_open_dev$radio(&(0x7f0000000000), 0x0, 0x2) r2 = socket$inet_mptcp(0x2, 0x1, 0x106) bind$inet(r2, &(0x7f0000000080)={0x2, 0x4e24, @multicast2}, 0x10) connect$inet(r2, &(0x7f00000009c0)={0x2, 0x4e24, @dev={0xac, 0x14, 0x14, 0x1a}}, 0x10) r3 = epoll_create1(0x80000) epoll_ctl$EPOLL_CTL_ADD(r3, 0x1, r2, &(0x7f0000000100)={0x80002004}) shutdown(r2, 0x1) readv(r0, &(0x7f00000001c0)=[{&(0x7f0000003400)=""/4096, 0x1000}], 0x1) r4 = dup2(r1, r1) read$FUSE(r4, &(0x7f0000000540)={0x2020}, 0x2020) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0xc, 0xe, &(0x7f0000000bc0)=ANY=[@ANYBLOB="b702000000000000bfa300000000000007030000f0ffffff7a0af0ff0000002071a4f0ff00000000b706000000000081ad64020000000000450404000100ff0f1704000001130a00b7050000010071ec7c45f2fe0000000085000000a3000000b700000000000000950001000000000000e154cd8445974b26c933f7ffffffffe4fbffffff55bb2007ee51050505f8e6fb0fd7ddcb12b5b42128aa090a79507df79f298129daa7a6b2f91af50342115e17392ac627c87881c000006146001e04aeacea799a22a2fa798b5adc43eb27d53319d0ad229e5752548300000000dbc2777df150b7cdd77b85b941092314fd085f028f2ed1a4535550614e09d6378198a6097a670838337af2abd55a87ac0394b2f92ffab7d153d62058d0a413b2173619ccf55520f22c9ca8b6712f3024b7041b1df65b3e1b9bf115646d14ce53d13d0ccacda1ef0900094fa737c20500000000000000cceaede3faedc51d29a47fc8136bf97f2f33e2ea2e534300bcb3fdc4b4861004eefbda7f54f82a804da4f85db47a4a69bf9bc5fa96ee293fbd165a5a68488e40b001000000a097b1b44b451de736bb6d43db8db03d4b7745fef1d04ec633dee254a6d491b849a5b787e814c4fd21a18986252a70f8f92eb6f0e8c7db4bf23242a1f2c28159f09943b1b0452d1b72323cc924e627f2f4b775dd4e9e3070756f97ad791fa99dac06b57479321a0574fb30ff0000001989328c8ddc20ea011bf5742e0e0d4334db8b20ce3f9f16cb7fc20fb4791ec85821d0c48fb657c29b309c73f0977e7cde65a82b94c461d7962b0d2277a84af326f37f3e2c25a61ec45c3af97a8f17da954aff3fc8c108755f75ca13fb7c8bbd8b6e7dac1aba4b20dc7de058a4dfa7e85a8bdf1d41a2d8bda74d66f47cc180f82c5f573c6d294d3665016ac59dda0fda4745db06753a7ac74a2d32f7528751313694bf5700b20ef0c248ddd3da32396a614cacad4aff2066bb5d4045c958559b7dcb98a6273b8c651e24d9f679e4fbe948dfb4cc4a389469608241730459f0123fd39206000000000000eb55dad46de56ef907b059b90b8aa49afb9a79ae5498f6589880ed6eea7b9c670012be05e7de0940313c5870786554df26236ebced9390cb6941b8375d936a7d2120eca291963eb2d537d8ee4de5c183c960119451c31539b22809e1d7f0cda06a9fa87d64cb77872a2cd8a104e16bb1a2bacf13464ca03aff14a9aa4bd9539f5096412b9243ff98df3347f0e399d1b9f27e3c33269c0e153b28b2d4410572bc45b9d3fa02208d304d455c36300000000022320178b00cc6ed7966130b547dbf8b497af002000000cd1d00000020000000ef19349ee7f31abc11c800000000000000000000000928ee53595a779d243a48cea769470424d28804c04b2c4324ab7f4a5c81921f0128dfd70b438af60b0600000000000000564a2b49b745f3bf2cf7908b6d7d748308eea09fb4735efbf3411718d6ee7aebf9ef679dbfae9fb4a79f8a836804ed3a1079b0282a12043408cd60b687dcff91af19010000000000000000456f7d2a42bd13da2022f23daec61854f640f701db0276652f6c74f20675eb781925441578e93046aaddea8ec4ca37f71c2710a7e58ae0dc214e1cc275b26adfa892e6de92000000000000000000ddff004cff9ec780f535e62f4eeee50e5bafecea4d4134f9d006c8d6883eca5c9c58c9e93311ab5009c68c73de2f04f15d005387577f480000ea65559eb00e76e9d0ada201bcbb5c252b28a60ca770663da451790cc36000906d5a9fad98c308e39bd5ffb6151d79c1a5e1cd102e3c8e63e9fba05e3633be3f00000015762e5f5a3a0bc33fdbe28a5ffc83f2b485185cc92fe7f791e8f6429309d6adab4b7e508e5bf024ed8f8a005f2bbf96c89739f5cf1e750d50517a59a3ad09e8802e8f4f535447cc0fc9cdf99a73145dfcedad69da9cd4375c624600e78f4458542b14f29611f95d4a31838eee46eb20c20bb82aa31771cd379ec83554cea5e6539d85b980e358d81f2f2653c4d9818708e27c89b552d7fcd116bce9c764c714c9402c21d181aac59efb28d4f9166965a53beb05142e1b1550a8cb7852f6750b6ec962802c0320f8059195729d60c534ee8e8ff0010067fe4c25edb85bcff24c757aa8090000000000008c420eb4304f66e3a37aaf000000c42a570f0e9dd5fd545470f862f8c3c14fa9ecd1e877b0d8ca84c044859e85e6158f9184bc61a9a284db80e4636c25b9617432e251d14b283f7d82761c26e329555f9290af4100000000000000749efd3763655500344bae34137f5ab0d534b8d63e4ca3b671f2de1cdf519192c6b59a601fd419adc16e2055b85058f793484305d7a1759782e4c571ee855a47bc00edf5e9020c09ab004321610b857e8717764b633b21cb32f0e03280e09758bd445ab91d20baca005452b79d7b574a247f1d2fe45b3c4e93da3d51de647c10dd49944dc87c92332af00f191b0000000032a91f0e2e9120be61e58c79d497247d278888901d442ad7f8536605a644e9e3d769db497c3960dfde12182334caee994adc38a436367a54b9e182b78e9a0ceb9a2c4f63902c1ad1a7c5a08d0920a23c2a86abbdf357849a651733e57f31019876026888c8ccb85c86b4f8ffffff7f000000002c331fca0e541b7ca211c28ed61c525708a13d115b43f8b1894c8fa8a14dc4810f61ae96c18cc7130000000000002157a3609b6fd9843ee19ec647249a9375de5858818f3c2432e6ced4380217ac51a84a4fa6ce46f4d42b07199de8b99231ace58c77819ee214e49666c464d35ca9b5143ed3b3dc8c17a23692759ccf5a205111b7ab22532697b861dfb54609fd88e6043bd52ae84c1bb0c8a6c769f952283a1f4e3842edb3d42c8ebc62887aa46e820a74f91381dcc198e353047db70686d147357024eb3cb94f1e89cb5ba0a56aa046b4dc521a3d9356b4b8b5917c4c860495b240e800fd00000000007271e28ef6806bc8e139c49b91c76bea3858f7f05b47d3e519f1634e8fbd8d31330d89069f9648a2ff93060ff073b3a113e47edf76f7d116d2b0976cf2ec447c030931651dd315003b7a6a5433a2bb560ae99ec4b227eda2e63a1c31a2c2bd48a822cbe92b6524e0cd809269f816fa748b20ecaa34e19e7141d5e221509342bfe7d294d1eb3de6a50ca0301f89c2ee627e949c68b3a4a426a996d503a26e9a714ee5f72d8805dd1bfbd081f6a5d1f9289dfe14cb9194e26a44fac273461fc5c0e0a33db7f2d43ea8086cf059f40fa2640b6bfb74dd35f5a31059c01517cf4b6641fce9a24b96767b837ca037a1199735c375c705c798e0e208e4a5259d0bfa526b462af45a6eab34000000000000000000000000c4426344ec1a3366515dee221e747f55d7dd02534bc503b9b28277c253e410986bef2111a99cc448d652929f8a67a6a1d3f00dcad91aff428aade3f05714a1d3ef29acd4d49b62339c10c2ec0dac4728288e78980c1184d8223edbccbf9258b7374e79a1f8bf3fb73c8c6dbb7bbdfc399847a11921f97eba0ea14c4fed9a71eedb97c02461792e3a49dac16c60c3fcaab222025d78963c3ac899fa8b63f58a30212c9b2d7fe751e2046b78f86e22861b6504c667350244dd6d9189a8b9c45f8aaff9db694811ca86ed978f23eed7459c0382074170cf1e25b0e9ba3d1cc30935455f6de5b64bcdfaf8ac04ce96c421e5dbc85e168d3559ab13df98163e39e4065e65a2f43412535d6f7c09830f3a086535bd07820e690d2755768612bb7330a8b285f2584892eaff1889a61ee0c2a6d1831d41805707bb43991d40feb5dd0700000000000011b64b378ee96af15cbbc65d72ae980b6df22b5ca3ea377f36beb44b45c6f84b3f4d2c62ca91b4df16fc8cc5d18b35213e5f67ec200e768ab28feaff2195724b2965ebca822af6c0a4e598d34f9b5f1eb43de209cd5541fe72d89d5f9819c1529c242b72ccdb9541e54fcccf12457df695126458ebffaaebe98748dea4f0a0b0a1683ff327ca05070000000000000088a571761be31e4fdd530604d32149c22f81adc983adc81b335d0579f47763a97af46500c91d5b2640242661beca1b4e695f7aac5ae46a72ac99ec395bdf16e3fc75e7acbb2d10060bef6a793082f8cfd4721588787c8a8c6257a8a11d49f7f7ed9de6efb7dd8058fb0c8125ee9c1691afa39b5a70d489efcd3e95a483c59f8fa7443e795eac454a68ab647e0d5381df6528858895d57274e97046659ac9488c85e5728987fa9d43660eb28b7befbb981f8fde8754d792146e49ee14bff102540e247a8780c80e3ff0688e8cb5c500446756d0b76244766deecc69c4c3435c125f0f06c772a051b690113e59485586e0ff"], &(0x7f0000002580)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1c, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000040), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) timer_create(0x0, &(0x7f0000000240)={0x0, 0x21}, &(0x7f0000bbdffc)) timer_settime(0x0, 0x0, &(0x7f000006b000)={{0x0, 0x8}, {0x0, 0x9}}, 0x0) r5 = syz_open_dev$sg(&(0x7f00000060c0), 0x0, 0x0) setresgid(0x0, 0xee01, 0xffffffffffffffff) r6 = msgget$private(0x0, 0x383) msgsnd(0x0, &(0x7f0000000d00)=ANY=[], 0x401, 0x800) msgsnd(r6, &(0x7f0000000200)=ANY=[@ANYBLOB="0000ff"], 0x8, 0x0) lstat(&(0x7f0000000440)='./file1\x00', &(0x7f0000000500)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) setregid(0x0, r7) bpf$PROG_LOAD(0x5, &(0x7f00000025c0)={0x4, 0x16, &(0x7f0000000180)=ANY=[@ANYBLOB="611230000000000061134c0000000000bf2000000000000015000200071b1750bd030100000000009500000000000000bc26080000000000bf67000000000000070300000fff0700670200000300000016060a000ee600f0bf050000000000000f650000000000006507f4ff02000000070700004c0040001f75000000000000bf54000000000000070500000300f9ffad430100000000009500000000000000050000000000000095000000000000004d9bd591d568253e9988431ec068e3a82983d58719d72183f2cb7f43dd55788be820b236dcb695dbfd737cbf719506d2d6b05fe7030586"], &(0x7f0000000100)='GPL\x00', 0x4, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x4, &(0x7f0000000340)=ANY=[@ANYRESHEX=r2], &(0x7f0000000200)='GPL\x00', 0x6, 0x0, 0x0, 0x0, 0x48, '\x00', 0x0, @fallback=0x2f, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r4, 0x50, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) ioctl$SG_IO(r5, 0x2285, &(0x7f0000000180)={0x53, 0x0, 0x6, 0xa, @scatter={0x9, 0x0, &(0x7f0000002b00)=[{&(0x7f0000000380)=""/20, 0x14}, {&(0x7f0000002680)=""/205, 0xcd}, {&(0x7f00000003c0)=""/96, 0x60}, {&(0x7f0000000480)=""/92, 0x5c}, {&(0x7f0000002780)=""/83, 0x53}, {&(0x7f0000002800)=""/181, 0xb5}, {&(0x7f00000028c0)=""/135, 0x87}, {&(0x7f0000002980)=""/230, 0xe6}, {&(0x7f0000002a80)=""/74, 0x4a}]}, &(0x7f0000000280)="1201b0048020", 0x0, 0x0, 0x4, 0x0, 0x0}) socket$packet(0x11, 0x3, 0x300) r8 = openat$vnet(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) ioctl$int_in(r8, 0x40000000af01, 0x0) ioctl$VHOST_SET_VRING_ADDR(r8, 0x4028af11, &(0x7f0000000140)={0x1, 0x0, 0x0, &(0x7f0000000280)=""/167, 0x0}) bpf$BPF_BTF_GET_NEXT_ID(0x17, &(0x7f0000000040)={0x9}, 0x8) 23.972799195s ago: executing program 1 (id=1098): r0 = socket(0x10, 0x803, 0x0) r1 = socket(0x10, 0x3, 0x0) r2 = socket$nl_route(0x10, 0x3, 0x0) r3 = socket(0x10, 0x803, 0x0) syz_genetlink_get_family_id$mptcp(&(0x7f00000000c0), r3) getsockname$packet(r3, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f00000003c0)=0x14) sendmsg$nl_route(r2, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000040)=ANY=[@ANYBLOB="3c0000001000010400eeffff11ffffffff000000", @ANYRES32=r4, @ANYBLOB="01000000010000001c0012000c000100627269646765"], 0x3c}}, 0x0) sendmsg$nl_route_sched(r1, &(0x7f0000005840)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000001240)=@newqdisc={0x2c, 0x24, 0x5820a61ca228651, 0x0, 0x0, {0x0, 0x0, 0x0, r4, {}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_qfg={0x8}]}, 0x2c}}, 0x0) setsockopt$netlink_NETLINK_LISTEN_ALL_NSID(r1, 0x10e, 0x8, &(0x7f0000000080)=0x401, 0x4) r5 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r5, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000003c0)={{0x14}, [@NFT_MSG_NEWTABLE={0x20, 0x0, 0xa, 0x5, 0x0, 0x0, {0x7}, [@NFTA_TABLE_NAME={0x9, 0x1, 'syz0\x00'}]}, @NFT_MSG_NEWSET={0x50, 0x9, 0xa, 0x401, 0x0, 0x0, {0x7}, [@NFTA_SET_ID={0x8}, @NFTA_SET_NAME={0x9, 0x2, 'syz1\x00'}, @NFTA_SET_TABLE={0x9, 0x1, 'syz0\x00'}, @NFTA_SET_KEY_LEN={0x8, 0x5, 0x1, 0x0, 0x4}, @NFTA_SET_DESC={0x14, 0x9, 0x0, 0x1, [@NFTA_SET_DESC_CONCAT={0x10, 0x2, 0x0, 0x1, [{0xc, 0x1, 0x0, 0x1, [@NFTA_SET_FIELD_LEN={0x8, 0x1, 0x1, 0x0, 0x2}]}]}]}]}], {0x14, 0x10, 0x1, 0x0, 0x0, {0x0, 0x84}}}, 0x98}, 0x1, 0x0, 0x0, 0x20000080}, 0x0) sendmsg$nl_route(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000180)=@newlink={0x28, 0x10, 0x401, 0x0, 0x1, {0x0, 0x0, 0x0, 0x0, 0x2500, 0x2a000}, [@IFLA_NET_NS_FD={0x8}]}, 0x28}, 0x1, 0x0, 0x0, 0x48000}, 0x20004090) 23.859608099s ago: executing program 32 (id=1098): r0 = socket(0x10, 0x803, 0x0) r1 = socket(0x10, 0x3, 0x0) r2 = socket$nl_route(0x10, 0x3, 0x0) r3 = socket(0x10, 0x803, 0x0) syz_genetlink_get_family_id$mptcp(&(0x7f00000000c0), r3) getsockname$packet(r3, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f00000003c0)=0x14) sendmsg$nl_route(r2, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000040)=ANY=[@ANYBLOB="3c0000001000010400eeffff11ffffffff000000", @ANYRES32=r4, @ANYBLOB="01000000010000001c0012000c000100627269646765"], 0x3c}}, 0x0) sendmsg$nl_route_sched(r1, &(0x7f0000005840)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000001240)=@newqdisc={0x2c, 0x24, 0x5820a61ca228651, 0x0, 0x0, {0x0, 0x0, 0x0, r4, {}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_qfg={0x8}]}, 0x2c}}, 0x0) setsockopt$netlink_NETLINK_LISTEN_ALL_NSID(r1, 0x10e, 0x8, &(0x7f0000000080)=0x401, 0x4) r5 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r5, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000003c0)={{0x14}, [@NFT_MSG_NEWTABLE={0x20, 0x0, 0xa, 0x5, 0x0, 0x0, {0x7}, [@NFTA_TABLE_NAME={0x9, 0x1, 'syz0\x00'}]}, @NFT_MSG_NEWSET={0x50, 0x9, 0xa, 0x401, 0x0, 0x0, {0x7}, [@NFTA_SET_ID={0x8}, @NFTA_SET_NAME={0x9, 0x2, 'syz1\x00'}, @NFTA_SET_TABLE={0x9, 0x1, 'syz0\x00'}, @NFTA_SET_KEY_LEN={0x8, 0x5, 0x1, 0x0, 0x4}, @NFTA_SET_DESC={0x14, 0x9, 0x0, 0x1, [@NFTA_SET_DESC_CONCAT={0x10, 0x2, 0x0, 0x1, [{0xc, 0x1, 0x0, 0x1, [@NFTA_SET_FIELD_LEN={0x8, 0x1, 0x1, 0x0, 0x2}]}]}]}]}], {0x14, 0x10, 0x1, 0x0, 0x0, {0x0, 0x84}}}, 0x98}, 0x1, 0x0, 0x0, 0x20000080}, 0x0) sendmsg$nl_route(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000180)=@newlink={0x28, 0x10, 0x401, 0x0, 0x1, {0x0, 0x0, 0x0, 0x0, 0x2500, 0x2a000}, [@IFLA_NET_NS_FD={0x8}]}, 0x28}, 0x1, 0x0, 0x0, 0x48000}, 0x20004090) 3.936268296s ago: executing program 4 (id=1397): r0 = socket(0x10, 0x3, 0x0) socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000240)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFINDEX(r1, 0x8933, &(0x7f0000000000)={'lo\x00', 0x0}) sendmsg$nl_route_sched(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000080)={&(0x7f000000cf00)=@newqdisc={0x48, 0x24, 0xf0b, 0x0, 0x1000000, {0x60, 0x0, 0x0, r2, {}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_cake={{0x9}, {0x18, 0x2, [@TCA_CAKE_BASE_RATE64={0xc, 0x2, 0x1003}, @TCA_CAKE_ACK_FILTER={0x8, 0x10, 0x1}]}}]}, 0x48}}, 0x0) r3 = socket$pppoe(0x18, 0x1, 0x0) connect$pppoe(r3, &(0x7f0000000400)={0x18, 0x0, {0x2, @dev={'\xaa\xaa\xaa\xaa\xaa', 0xa}, 'lo\x00'}}, 0x1e) sendmmsg(r3, &(0x7f000000f380)=[{{0x0, 0x0, 0x0}}, {{0x0, 0x0, 0x0}}, {{0x0, 0x0, 0x0}}], 0x3, 0x0) fcntl$notify(0xffffffffffffffff, 0x402, 0x8000003d) 3.871584057s ago: executing program 4 (id=1401): socket$inet_tcp(0x2, 0x1, 0x0) (async) r0 = socket$inet_tcp(0x2, 0x1, 0x0) r1 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) ioctl$TUNSETIFF(r1, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) socket(0x400000000010, 0x3, 0x0) (async) r2 = socket(0x400000000010, 0x3, 0x0) r3 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000040), 0x264040, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000005c0)=@base={0x7, 0x4, 0x18, 0xa042, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x18, 0x0, 0x0, @void, @value, @void, @value}, 0x48) (async) bpf$MAP_CREATE(0x0, &(0x7f00000005c0)=@base={0x7, 0x4, 0x18, 0xa042, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x18, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r4 = ioctl$KVM_CREATE_VM(r3, 0xae01, 0x0) ioctl$KVM_CAP_DIRTY_LOG_RING(r4, 0x4068aea3, &(0x7f0000000180)={0xc0, 0x0, 0x4000}) ioctl$KVM_RESET_DIRTY_RINGS(r4, 0xaec7) r5 = socket$unix(0x1, 0x1, 0x0) r6 = socket$inet6_udp(0xa, 0x2, 0x0) setsockopt$IP6T_SO_SET_REPLACE(r6, 0x29, 0x40, &(0x7f0000000000)=@raw={'raw\x00', 0x3c1, 0x3, 0x458, 0x258, 0x4c, 0x232, 0x258, 0x0, 0x388, 0x2e8, 0x2e8, 0x388, 0x2e8, 0x3, 0x0, {[{{@ipv6={@mcast2, @mcast2, [], [], 'veth1_to_bond\x00', 'ip6gre0\x00', {}, {}, 0x6, 0x0, 0x3}, 0x0, 0x230, 0x258, 0x0, {}, [@common=@unspec=@cluster={{0x30}}, @common=@inet=@policy={{0x158}, {[{@ipv4=@dev, [], @ipv4=@initdev={0xac, 0x1e, 0x0, 0x0}}, {@ipv4, [], @ipv4=@broadcast}, {@ipv4=@multicast2, [], @ipv4=@dev}, {@ipv6=@loopback, [], @ipv6=@private2}], 0x1}}]}, @common=@inet=@SYNPROXY={0x28}}, {{@ipv6={@ipv4={'\x00', '\xff\xff', @remote}, @private1, [], [], 'team_slave_0\x00', 'xfrm0\x00'}, 0x0, 0xf8, 0x130, 0x0, {}, [@inet=@rpfilter={{0x28}}, @inet=@rpfilter={{0x28}}]}, @common=@inet=@SET3={0x38}}], {{'\x00', 0x0, 0xa8, 0xd0}, {0x28}}}}, 0x4b8) ioctl$sock_SIOCGIFINDEX(r5, 0x8933, &(0x7f0000000100)={'syzkaller0\x00'}) (async) ioctl$sock_SIOCGIFINDEX(r5, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r2, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2d, 0xffffffff, {0x0, 0x0, 0x0, r7, {0x0, 0xfff1}, {0xffff, 0xffff}, {0x1, 0x10}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8, 0x2, {0x28}}}]}, 0x38}}, 0x0) (async) sendmsg$nl_route_sched(r2, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2d, 0xffffffff, {0x0, 0x0, 0x0, r7, {0x0, 0xfff1}, {0xffff, 0xffff}, {0x1, 0x10}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8, 0x2, {0x28}}}]}, 0x38}}, 0x0) mprotect(&(0x7f0000ffd000/0x1000)=nil, 0x1000, 0x0) sendmsg$nl_route_sched(r2, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000440)={&(0x7f0000001300)=@newtfilter={0x38, 0x2c, 0xd27, 0x70bd28, 0x8000, {0x0, 0x0, 0x0, r7, {0x0, 0xfff3}, {0xfff3}}, [@filter_kind_options=@f_u32={{0x8}, {0xc, 0x2, [@TCA_U32_DIVISOR={0x8, 0x4, 0x2}]}}]}, 0x38}, 0x1, 0x0, 0x0, 0x80}, 0x20004014) timerfd_create(0x9, 0x80000) read(0xffffffffffffffff, 0x0, 0x0) openat$kvm(0xffffffffffffff9c, &(0x7f0000000540), 0x10d000, 0x0) (async) r8 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000540), 0x10d000, 0x0) ioctl$KVM_GET_SUPPORTED_CPUID(r8, 0xc008ae05, &(0x7f0000001340)=""/4096) (async) ioctl$KVM_GET_SUPPORTED_CPUID(r8, 0xc008ae05, &(0x7f0000001340)=""/4096) r9 = openat$sysfs(0xffffffffffffff9c, &(0x7f00000004c0)='/sys/kernel/address_bits', 0x40, 0x1d8) r10 = socket$inet6_sctp(0xa, 0x1, 0x84) bind$inet6(r10, &(0x7f0000000280)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendto$inet6(r10, &(0x7f00000002c0)="9e", 0x1, 0x0, &(0x7f0000000200)={0xa, 0x4e23, 0x0, @loopback, 0xe}, 0x1c) (async) sendto$inet6(r10, &(0x7f00000002c0)="9e", 0x1, 0x0, &(0x7f0000000200)={0xa, 0x4e23, 0x0, @loopback, 0xe}, 0x1c) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r10, 0x84, 0x72, 0x0, 0x0) (async) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r10, 0x84, 0x72, 0x0, 0x0) sendmsg$inet6(r10, &(0x7f0000000440)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f0000000040)='h', 0x1}], 0x1}, 0x0) writev(r10, &(0x7f0000000100)=[{&(0x7f0000000240)=',', 0x34000}], 0x1) r11 = openat$vimc0(0xffffffffffffff9c, &(0x7f0000000500), 0x2, 0x0) dup3(r9, r11, 0x80000) close_range(r0, 0xffffffffffffffff, 0x0) (async) close_range(r0, 0xffffffffffffffff, 0x0) 3.666942643s ago: executing program 4 (id=1409): ioctl$sock_SIOCGIFINDEX(0xffffffffffffffff, 0x8933, &(0x7f00000000c0)={'veth0_to_team\x00', 0x0}) sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000001140)={&(0x7f0000000040)=ANY=[@ANYBLOB="680000001000030500"/20, @ANYRES32=0x0, @ANYBLOB="0000000000dfab87fbc98ebb609f6b52a304ccbaa7e7a9bf423f23828ee8dffe00000040001201006d6163766c616e003000028009000100b0ce4754cfd012ba9ed827f266492cda10000000", @ANYRES32=r0], 0x68}}, 0x0) r1 = socket$kcm(0x2, 0x3, 0x84) sendmsg$inet(r1, &(0x7f0000001000)={&(0x7f0000000000)={0x2, 0x0, @multicast2}, 0x10, 0x0, 0x0, &(0x7f0000000140)=[@ip_pktinfo={{0x1c, 0x0, 0x8, {0x0, @local, @loopback}}}, @ip_ttl={{0x14, 0x0, 0x2, 0x1}}], 0x38}, 0x0) r2 = socket$nl_route(0x10, 0x3, 0x0) r3 = accept$inet(0xffffffffffffffff, &(0x7f0000000100)={0x2, 0x0, @broadcast}, &(0x7f0000000140)=0x10) setsockopt$IP_VS_SO_SET_STOPDAEMON(r3, 0x0, 0x48c, &(0x7f0000000180)={0x2, 'veth1_virt_wifi\x00', 0x1}, 0x18) sendmsg$nl_route_sched(r2, &(0x7f0000000280)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000000)=@delchain={0x24, 0x11, 0x1, 0x1f, 0x0, {0x0, 0x0, 0x0, r0, {0xa}}}, 0x24}}, 0x0) 3.574011383s ago: executing program 4 (id=1410): r0 = openat$pmem0(0xffffffffffffff9c, &(0x7f0000002340), 0x80d01, 0x0) ioctl$BLKPG(r0, 0x1269, &(0x7f0000000180)={0x1, 0x0, 0x98, &(0x7f00000000c0)={0x400400, 0x1000, 0xc}}) syz_usb_connect$cdc_ncm(0x3, 0x0, 0x0, 0x0) r1 = syz_io_uring_setup(0x68aa, &(0x7f0000000000)={0x0, 0xfde2, 0x0, 0x1, 0xa7}, &(0x7f0000000100), &(0x7f0000000140)) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f00000001c0)=ANY=[@ANYRESOCT=r0], &(0x7f0000000200)='GPL\x00', 0xfffffffd, 0x0, 0x0, 0x40f00, 0x11, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) io_uring_enter(r1, 0x43c0, 0x5cb, 0x8, &(0x7f0000000180)={[0x5]}, 0x8) r2 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000340), 0x48980, 0x0) ioctl$TIOCSETD(r2, 0x5423, &(0x7f00000000c0)=0xf) r3 = syz_init_net_socket$x25(0x9, 0x5, 0x0) ioctl$SIOCX25SDTEFACILITIES(r3, 0x89eb, &(0x7f0000000000)={0x8, 0x101, 0x3de6, 0x4, 0x6, 0xa, 0x26, "8ae43da29112f10ec044f03f543e92ae77e5ac38", "92ef0b45acd1352a8431db82d3c65de242dd8fc5"}) ioctl$TCFLSH(r2, 0x400455c8, 0x4000000000000) ioctl$TIOCSETD(r2, 0x5423, &(0x7f0000000080)=0x7) 1.905824115s ago: executing program 2 (id=1445): syz_emit_ethernet(0x12, &(0x7f0000000000)={@broadcast, @remote, @val={@void, {0x8100, 0x0, 0x0, 0x800}}, {@generic={0x88ca}}}, 0x0) r0 = openat$ttyS3(0xffffffffffffff9c, &(0x7f00000000c0), 0x121602, 0x0) ioctl$TIOCVHANGUP(r0, 0x5437, 0x2) openat$ttyS3(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) 1.841377604s ago: executing program 2 (id=1446): r0 = socket(0x10, 0x3, 0x0) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000240)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFINDEX(r1, 0x8933, &(0x7f0000000000)={'lo\x00', 0x0}) sendmsg$nl_route_sched(r0, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000780)={&(0x7f00000021c0)=@newqdisc={0x4c, 0x24, 0xd0f, 0x70bd2d, 0x0, {0x60, 0x0, 0x0, r2, {0x0, 0xa}, {0xffff, 0xffff}, {0xc, 0xffff}}, [@qdisc_kind_options=@q_netem={{0xa}, {0x1c, 0x2, {{0x4, 0x7fffffff, 0xf, 0xf07}}}}]}, 0x4c}, 0x1, 0x0, 0x0, 0x4040000}, 0x44080) (async) sendmsg$nl_route_sched(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000780)={&(0x7f0000000100)=@newqdisc={0x48, 0x24, 0xd0f, 0x70bd2c, 0x0, {0x60, 0x0, 0x0, r2, {}, {0xffe0, 0xa}, {0x3, 0xe}}, [@qdisc_kind_options=@q_choke={{0xa}, {0x18, 0x2, [@TCA_CHOKE_PARMS={0x14, 0x1, {0x14, 0x8, 0x3fc55862, 0x1c, 0x4, 0x4, 0x7}}]}}]}, 0x48}}, 0xc010) 1.840151371s ago: executing program 2 (id=1447): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000540)={0x26, 'skcipher\x00', 0x0, 0x0, 'cbc-blowfish-asm\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, &(0x7f0000000140)="2c385aa3", 0x4) r1 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$alg(r1, &(0x7f00000003c0)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000180)=[@op={0x18, 0x117, 0x3, 0x1}], 0x18, 0x800}, 0x4000010) r2 = socket$inet6(0xa, 0x2, 0x0) bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000180)=@bpf_lsm={0x6, 0x3, 0x0, &(0x7f0000000140)='GPL\x00', 0x4, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bind$inet6(r2, &(0x7f0000f5dfe4)={0xa, 0x4e20, 0x0, @empty}, 0x18) recvmmsg(r2, &(0x7f0000000040), 0x400000000000284, 0x2, 0x0) syz_emit_ethernet(0x2e, &(0x7f0000000500)={@broadcast, @link_local, @void, {@ipv4={0x800, @udp={{0x5, 0x4, 0x0, 0x17, 0x20, 0x3, 0x0, 0x0, 0x11, 0x0, @empty, @empty}, {0x0, 0x4e20, 0xc, 0x0, @gue={{0x1, 0x0, 0x2, 0x0, 0x0, @void}}}}}}}, 0x0) syz_genetlink_get_family_id$tipc2(&(0x7f0000000000), r1) 1.338745447s ago: executing program 0 (id=1452): r0 = syz_open_dev$dri(&(0x7f0000000180), 0x1, 0x0) ioctl$DRM_IOCTL_MODE_CREATE_DUMB(r0, 0xc02064b2, &(0x7f0000000000)={0x6, 0x2, 0x80000000}) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0a00000004000000fd0f00000700000000000000", @ANYRES32, @ANYBLOB="000000000000cfb507cc909cb4e3000000000000", @ANYRES32=0x0, @ANYRES32, @ANYBLOB='\x00'/28], 0x48) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000900)='syzkaller\x00', 0x0, 0xfffffffffffffe1a, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x3, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000180)='sched_switch\x00', r2}, 0x10) r3 = socket$nl_route(0x10, 0x3, 0x0) bpf$BPF_GET_MAP_INFO(0xf, &(0x7f0000000000)={r1, 0x58, &(0x7f0000000240)}, 0x10) sendmsg$nl_route(r3, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000340)=ANY=[@ANYBLOB="500000001000010400000000000000000000ffff", @ANYRES32=0x0, @ANYBLOB="00000000000000001c001280090001007866726d000000000c00028008000200ea000000140003007866726d30"], 0x50}}, 0x0) 1.253936193s ago: executing program 0 (id=1453): r0 = socket$inet6_sctp(0xa, 0x5, 0x84) setsockopt$inet_sctp6_SCTP_PEER_ADDR_PARAMS(r0, 0x84, 0x9, &(0x7f0000000580)={0x0, @in={{0x2, 0x0, @empty}}, 0x0, 0x0, 0x3fc, 0x0, 0x32}, 0x9c) bind$inet6(r0, &(0x7f00004b8fe4)={0xa, 0x4e23, 0x0, @empty}, 0x1c) r1 = openat$sysfs(0xffffffffffffff9c, &(0x7f00000002c0)='/sys/power/resume', 0x141a82, 0x0) write$cgroup_int(r1, &(0x7f0000000040)=0x900, 0x12) sendto$inet6(r0, &(0x7f0000847fff)='X', 0x34000, 0x0, &(0x7f000005ffe4)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) r2 = openat$ptmx(0xffffffffffffff9c, &(0x7f00000000c0), 0x80102, 0x0) r3 = dup(r2) ioctl$TCSETA(r3, 0x5406, &(0x7f0000002280)={0x7, 0x1, 0xffc0, 0x0, 0x9, "803d5490e545a3eb"}) setsockopt$inet_sctp6_SCTP_PEER_ADDR_PARAMS(r0, 0x84, 0x9, &(0x7f0000000a00)={0x0, @in6={{0xa, 0x4e23, 0x0, @loopback}}, 0x100, 0x0, 0x0, 0x0, 0x54}, 0x9c) r4 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000000300)=ANY=[@ANYBLOB="180000000021da00000000000000000095"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000040)='contention_end\x00', r4}, 0x10) r5 = syz_genetlink_get_family_id$nl80211(&(0x7f00000004c0), 0xffffffffffffffff) r6 = socket$nl_generic(0x10, 0x3, 0x10) bpf$MAP_CREATE(0x0, 0x0, 0x48) bind$netlink(r6, &(0x7f0000000100)={0x10, 0x0, 0x25dfdbfd, 0x8000}, 0xc) r7 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r7, &(0x7f0000000380)={0x2, 0x4e22, @empty}, 0x10) listen(r7, 0x5) r8 = openat$mice(0xffffffffffffff9c, &(0x7f0000000140), 0x1) setsockopt$inet_sctp6_SCTP_PARTIAL_DELIVERY_POINT(r8, 0x84, 0x13, &(0x7f0000000180)=0x5, 0x4) syz_emit_ethernet(0x36, &(0x7f0000000080)={@local, @broadcast, @void, {@ipv4={0x800, @tcp={{0x5, 0x4, 0x0, 0x0, 0x28, 0x0, 0x0, 0x0, 0x6, 0x0, @empty, @empty}, {{0x0, 0x4e22, 0x41424344, 0x41424344, 0x0, 0x0, 0x5, 0x10}}}}}}, 0x0) ioctl$sock_SIOCGIFINDEX_80211(r6, 0x8933, &(0x7f0000000040)={'wlan0\x00', 0x0}) sendmsg$NL80211_CMD_VENDOR(r6, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000001b40)={&(0x7f00000000c0)={0x1c, r5, 0x62c21a4ade68aba1, 0x70bd28, 0x0, {{0x32}, {@void, @val={0x8, 0x3, r9}, @void}}}, 0x1c}, 0x1, 0x0, 0x0, 0x40}, 0x4000080) 867.050162ms ago: executing program 2 (id=1454): syz_open_dev$sg(&(0x7f0000000080), 0x7df1, 0x101000) (async) r0 = syz_open_dev$sg(&(0x7f0000000080), 0x7df1, 0x101000) r1 = openat(0xffffffffffffff9c, &(0x7f0000000500)='.\x00', 0x0, 0x0) fsetxattr$system_posix_acl(r1, &(0x7f0000000040)='system.posix_acl_default\x00', 0x0, 0x0, 0x0) (async) fsetxattr$system_posix_acl(r1, &(0x7f0000000040)='system.posix_acl_default\x00', 0x0, 0x0, 0x0) ioctl$KDENABIO(r1, 0x4b36) ioctl$SG_BLKSECTGET(r0, 0x1267, &(0x7f0000000180)) r2 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000440)={0x6, 0x20, &(0x7f0000000000)=@ringbuf={{0x18, 0x0, 0x0, 0x0, 0x6fa, 0x0, 0x0, 0x0, 0x4}, {}, {}, [@map_idx={0x18, 0x0, 0x5, 0x0, 0x3}, @cb_func={0x18, 0x9, 0x4, 0x0, 0xfffffffffffffff9}, @snprintf={{}, {}, {0x7, 0x0, 0xb, 0x8, 0x0, 0x0, 0x40}}], {{}, {0x7, 0x0, 0xb, 0x2, 0x0, 0x0, 0x3}, {0x85, 0x0, 0x0, 0x85}}}, &(0x7f00000001c0)='GPL\x00', 0x416, 0x2c, &(0x7f0000000200)=""/44, 0x40f00, 0x10, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, &(0x7f0000000240)={0x6, 0x4}, 0x8, 0x10, &(0x7f0000000280)={0x2, 0x1, 0x101, 0x5}, 0x10, 0x0, 0x0, 0x9, &(0x7f00000002c0)=[0x1, 0x1, 0x1], &(0x7f0000000380)=[{0x2, 0x4, 0xa, 0xc}, {0x5, 0x4, 0x5, 0x3}, {0x2, 0x1, 0xe, 0x4}, {0x4, 0x4, 0x9, 0x9}, {0x1, 0x2, 0xb, 0x9}, {0x0, 0x4, 0x8421, 0x1}, {0x4, 0x3, 0x4, 0xa}, {0x5, 0x5, 0x10, 0x5}, {0x2, 0x5, 0xd}], 0x10, 0x7, @void, @value}, 0x94) r3 = syz_init_net_socket$bt_l2cap(0x1f, 0x1, 0x3) ioctl$int_in(r3, 0x5421, &(0x7f0000000000)=0xf4e) r4 = socket$nl_generic(0x10, 0x3, 0x10) r5 = syz_genetlink_get_family_id$batadv(&(0x7f0000000040), 0xffffffffffffffff) ioctl$ifreq_SIOCGIFINDEX_batadv_mesh(r4, 0x8933, &(0x7f0000000100)={'batadv0\x00', 0x0}) sendmsg$BATADV_CMD_SET_MESH(r4, &(0x7f0000000240)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000640)=ANY=[@ANYBLOB='$\x00\x00\x00', @ANYRES16=r5, @ANYBLOB="010600000000fddbdf250f000000050035000400000008000300", @ANYRES32=r6, @ANYBLOB="9623f06e9a0523c892da8c2aa9a7922cd86df56a0cc8dc7364b1e33cf15e78c5b546a8cb7dcf7d287e12544bb581f9ff5a2bfa0d90512d7a054fd3c77174102b31292a588543524268092e2d8989af6f19bd81bf71234fa08817ea03c2a2fedcff81cc29ee656367a8e65dca55300c7fbb4d09dfa57eaeb3ee910a997e0200808b10bbe468bad656c1b480f5f62328e1e16c87247db5e5519ab2395e7e7a1b56589e6c63cabe09c40f15af2573914fbe00667bf488da4771bf4d4cb24ccac6bd495df99f677729eca58546a341e052140b2b360bc94922a6ca3be7fe7eb28671"], 0x24}}, 0x0) sendmsg$nl_route_sched(r1, &(0x7f0000000600)={&(0x7f0000000300)={0x10, 0x0, 0x0, 0x20000000}, 0xc, &(0x7f0000000580)={&(0x7f0000000540)=@newtfilter={0x34, 0x2c, 0x400, 0x70bd2b, 0x25dfdbfb, {0x0, 0x0, 0x0, r6, {0x8, 0x5}, {0x2, 0xfff2}, {0xffff, 0xffe0}}, [@TCA_CHAIN={0x8, 0xb, 0x80000000}, @TCA_CHAIN={0x8, 0xb, 0xfce}]}, 0x34}, 0x1, 0x0, 0x0, 0x8000}, 0x0) (async) sendmsg$nl_route_sched(r1, &(0x7f0000000600)={&(0x7f0000000300)={0x10, 0x0, 0x0, 0x20000000}, 0xc, &(0x7f0000000580)={&(0x7f0000000540)=@newtfilter={0x34, 0x2c, 0x400, 0x70bd2b, 0x25dfdbfb, {0x0, 0x0, 0x0, r6, {0x8, 0x5}, {0x2, 0xfff2}, {0xffff, 0xffe0}}, [@TCA_CHAIN={0x8, 0xb, 0x80000000}, @TCA_CHAIN={0x8, 0xb, 0xfce}]}, 0x34}, 0x1, 0x0, 0x0, 0x8000}, 0x0) writev(r3, &(0x7f0000019880)=[{&(0x7f0000000400)="fb", 0xffffff5c}, {&(0x7f00000197c0)="1902eb02d5e5f29e59e1a7caec33eb76d2430da474d87e367f6598d026438b65eda8341073b6752abdcee080c8e1e876b25227c37d7dd79886ce33f13e857c8eda1cecf6ac36c03dbf54e3cb5136da5a33fee76fb3113f8b6700e9e5fc006b8eed665fed48738d59395ad07438c3610ae3976aac75caf2facafa21c25be3c2", 0x7f}], 0x2) (async) writev(r3, &(0x7f0000019880)=[{&(0x7f0000000400)="fb", 0xffffff5c}, {&(0x7f00000197c0)="1902eb02d5e5f29e59e1a7caec33eb76d2430da474d87e367f6598d026438b65eda8341073b6752abdcee080c8e1e876b25227c37d7dd79886ce33f13e857c8eda1cecf6ac36c03dbf54e3cb5136da5a33fee76fb3113f8b6700e9e5fc006b8eed665fed48738d59395ad07438c3610ae3976aac75caf2facafa21c25be3c2", 0x7f}], 0x2) socket$nl_generic(0x10, 0x3, 0x10) (async) r7 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r7, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000100)={0x20, 0x44, 0x107, 0xfffffffc, 0x0, {0x1, 0x7c}, [@nested={0xc, 0x3, 0x0, 0x1, [@typed={0x2c, 0x6, 0x0, 0x0, @str='\x8e\n'}]}]}, 0x20}, 0x1, 0x0, 0x0, 0x488c0}, 0xc000) bpf$PROG_LOAD(0x5, &(0x7f0000000100)={0x13, 0x4, &(0x7f00000005c0)=ANY=[@ANYBLOB="1800000000000000000000000000000071121f000000000095"], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r2, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 866.878479ms ago: executing program 2 (id=1455): r0 = openat$fb0(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) ioctl$FBIOPUT_VSCREENINFO(r0, 0x4601, &(0x7f0000000240)={0x400, 0x30, 0xf0, 0x0, 0x0, 0x1f, 0x0, 0x0, {}, {}, {}, {}, 0x0, 0x40, 0x0, 0x7, 0x0, 0x5, 0x0, 0x0, 0x4000, 0x0, 0x0, 0x0, 0x16, 0x0, 0x0, 0x5}) socketpair$unix(0x1, 0x5, 0x0, &(0x7f00000001c0)={0xffffffffffffffff, 0xffffffffffffffff}) setsockopt$SO_ATTACH_FILTER(r1, 0x1, 0x1a, &(0x7f0000000000)={0x2, &(0x7f00000004c0)=[{0x81}, {0x6}]}, 0x10) openat$fb0(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) (async) ioctl$FBIOPUT_VSCREENINFO(r0, 0x4601, &(0x7f0000000240)={0x400, 0x30, 0xf0, 0x0, 0x0, 0x1f, 0x0, 0x0, {}, {}, {}, {}, 0x0, 0x40, 0x0, 0x7, 0x0, 0x5, 0x0, 0x0, 0x4000, 0x0, 0x0, 0x0, 0x16, 0x0, 0x0, 0x5}) (async) socketpair$unix(0x1, 0x5, 0x0, &(0x7f00000001c0)) (async) setsockopt$SO_ATTACH_FILTER(r1, 0x1, 0x1a, &(0x7f0000000000)={0x2, &(0x7f00000004c0)=[{0x81}, {0x6}]}, 0x10) (async) 751.520612ms ago: executing program 2 (id=1456): mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xf, 0x4008031, 0xffffffffffffffff, 0x0) (async, rerun: 32) r0 = socket$inet6_udp(0xa, 0x2, 0x0) (rerun: 32) setsockopt$inet6_IPV6_PKTINFO(r0, 0x29, 0x32, &(0x7f0000000280)={@mcast2}, 0x14) (async) accept(r0, &(0x7f0000000000)=@pppol2tpv3in6={0x18, 0x1, {0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, {0xa, 0x0, 0x0, @mcast1}}}, &(0x7f0000000080)=0x80) (async, rerun: 64) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x19) (rerun: 64) migrate_pages(0x0, 0x3, &(0x7f00000002c0)=0x7f, &(0x7f0000000300)=0xa) 686.405211ms ago: executing program 4 (id=1457): r0 = socket$inet6(0xa, 0x2, 0x0) setsockopt$inet6_IPV6_XFRM_POLICY(r0, 0x29, 0x23, &(0x7f00000004c0)={{{@in=@loopback, @in=@private=0xa010100, 0x0, 0x0, 0x0, 0xfffd, 0xa}, {0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffd}}, {{@in=@private=0xa010102, 0x0, 0x2b}, 0x0, @in6=@initdev={0xfe, 0x88, '\x00', 0x0, 0x0}}}, 0xe8) (async) mount$9p_virtio(0x0, &(0x7f0000000180)='./file0\x00', 0x0, 0xa0050, 0x0) socket$nl_xfrm(0x10, 0x3, 0x6) (async) recvmsg$kcm(0xffffffffffffffff, 0x0, 0x18000) r1 = syz_init_net_socket$x25(0x9, 0x5, 0x0) r2 = syz_init_net_socket$x25(0x9, 0x5, 0x0) bind$x25(r2, &(0x7f0000000e00), 0x12) (async, rerun: 64) bind$x25(r1, &(0x7f0000000080), 0x12) (rerun: 64) setsockopt$inet6_IPV6_XFRM_POLICY(r0, 0x29, 0x23, 0x0, 0x0) bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000300)=@bpf_lsm={0xd, 0x5, &(0x7f0000000040)=ANY=[@ANYBLOB="650a0000000000006111"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) (async) r3 = syz_open_dev$sg(&(0x7f0000000200), 0x0, 0x0) ioctl$SCSI_IOCTL_SEND_COMMAND(r3, 0x1, &(0x7f0000000040)=ANY=[@ANYBLOB="cc0000000000000012"]) 685.279555ms ago: executing program 4 (id=1458): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000000c0)=@base={0x1b, 0x0, 0x0, 0x8000, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x7, &(0x7f0000000540)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7020000030000008500000086000000"], &(0x7f00000004c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb, 0x4008032, 0xffffffffffffffff, 0x0) madvise(&(0x7f0000000000/0x600000)=nil, 0x600000, 0x15) r2 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$inet_tcp_int(r2, 0x6, 0x210000000013, &(0x7f00000000c0)=0x100000001, 0x4) connect$inet(r2, &(0x7f0000000140)={0x2, 0x0, @remote}, 0x10) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r2, 0x6, 0x16, &(0x7f0000000000)=[@sack_perm, @window, @sack_perm, @sack_perm, @timestamp, @timestamp, @timestamp, @timestamp], 0x20000149) madvise(&(0x7f0000000000/0x600000)=nil, 0x600002, 0x8) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000400)={&(0x7f0000000380)='sys_enter\x00', r1}, 0x10) getpriority(0x0, 0x0) r3 = openat$sequencer2(0xffffffffffffff9c, &(0x7f0000000000), 0x181c82, 0x0) write$sequencer(r3, &(0x7f00000000c0)=[@t={0x81, 0x3, 0x0, 0x0, @generic}], 0x8) r4 = syz_open_dev$ndb(&(0x7f0000000000), 0x0, 0x2) ioctl$NBD_SET_TIMEOUT(r4, 0xab09, 0x0) syz_usb_connect(0x1, 0x660, &(0x7f0000000040)={{0x12, 0x1, 0x101, 0xcc, 0x4b, 0x39, 0x40, 0x2537, 0x1068, 0x1dc6, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x64e, 0x4, 0x3, 0x4, 0x90, 0x89, [{{0x9, 0x4, 0x5c, 0x38, 0x2, 0x34, 0x7f, 0xc, 0x1, [], [{{0x9, 0x5, 0xf, 0x0, 0x8, 0xd3, 0x2, 0x3, [@uac_iso={0x7, 0x25, 0x1, 0x0, 0x2, 0x529}]}}, {{0x9, 0x5, 0x7, 0x0, 0x400, 0x8, 0xc5, 0x0, [@uac_iso={0x7, 0x25, 0x1, 0x2, 0x1, 0x1}, @generic={0xb, 0xa, "ad7f0482ee81bbc13c"}]}}]}}, {{0x9, 0x4, 0x77, 0xfb, 0x4, 0x11, 0x3c, 0xc, 0x5, [], [{{0x9, 0x5, 0xd, 0x10, 0x200, 0x5, 0x0, 0x1, [@generic={0x6, 0x23, "5719f53b"}]}}, {{0x9, 0x5, 0x8, 0xc, 0x20, 0x3, 0xf8, 0x1, [@generic={0xa6, 0xf, "406ba550eb3030a1bac44c723b828273aade177195ec4e45a9b8fc8a2b4bb6f5613e8224c7e209b6ecb283a9ec61a73a7e7654b7649a015680b637f384afb9d5d271da8aedf052d5c3af93369c7eadc066adf9f547e0a552ae4e34cf360d563da9b4471d75d6b50d82616f3b1d8170f4bb700f4a16f9bb01625282db1bd0659901d5b2efc4e52fdcab7e9ee9611254e8c45bf157408dd9ab7ee90f4036d6045bee9429c1"}]}}, {{0x9, 0x5, 0xc, 0xc, 0x3ff, 0x80, 0xf7, 0x7, [@uac_iso={0x7, 0x25, 0x1, 0x840b0672fe1be5ed, 0x3}, @generic={0x14, 0x31, "c2fbcd72b6d2832f8bb8341bc5dd996ad928"}]}}, {{0x9, 0x5, 0x9, 0x0, 0x200, 0xf0, 0x9, 0x7, [@generic={0x2d, 0x11, "6e2613a36703e9b459258a346dd07c52e1287f99162c621e198992582f06a8f487a0f9f373e95baaa1bf5d"}, @generic={0x1a, 0x3, "1afd658756eabc82c6ba40fb36f8b3ab7513b77222e77fac"}]}}]}}, {{0x9, 0x4, 0xeb, 0xd4, 0x6, 0xff, 0x5d, 0x81, 0x1, [], [{{0x9, 0x5, 0xc, 0x21, 0x20, 0x2, 0x0, 0x7, [@uac_iso={0x7, 0x25, 0x1, 0x1, 0x4f, 0xa9a}, @uac_iso={0x7, 0x25, 0x1, 0x81, 0x5}]}}, {{0x9, 0x5, 0x6, 0x10, 0x3ff, 0xc9, 0x9, 0x9, [@generic={0x4d, 0x7, "93095ef1993529d6df38dd0b3f437827b25652d972288062cd39b621fe8567b6f68ac38fcbd6165db1c225d2dfb3a7ad86fe48fdc15d679a119e38e4223efb0ea622e0d875327ece16ae6e"}, @uac_iso={0x7, 0x25, 0x1, 0x3, 0xf, 0x4bf}]}}, {{0x9, 0x5, 0x7, 0x0, 0x400, 0xbf, 0x4, 0x2, [@uac_iso={0x7, 0x25, 0x1, 0x83, 0x8, 0x4a}]}}, {{0x9, 0x5, 0xc, 0x10, 0x8, 0x4, 0x9, 0x32, [@uac_iso={0x7, 0x25, 0x1, 0x3, 0x7, 0x7c}, @generic={0x74, 0x35, "a72d7173a86fd39449c8b561fcfb6336fc8bb5a4c5620242c1141b59945dfcef3cd2c80e5a9ff8d507d96aa3ee4a33e1ecbfb0afcd477baa533a1cdd31031e38392f027458aa3a5fd27056fda66e2e9d40811da7554aee239b17d01078bfbc2ada51e4226870db7217d384bb4ab29e92b229"}]}}, {{0x9, 0x5, 0x9, 0x10, 0x400, 0xf9, 0xff, 0x7f}}, {{0x9, 0x5, 0x7, 0x3, 0x200, 0xfc, 0x5b}}]}}, {{0x9, 0x4, 0x3f, 0x9, 0xb, 0x12, 0x67, 0x9c, 0xd, [@hid_hid={0x9, 0x21, 0x6, 0x9, 0x1, {0x22, 0xec6}}, @generic={0x52, 0xe, "c6ad60246983d58701b2a0378a1e3d12adf5c5a01724b1346ec2cdb6e558bf12c35984b8a975153ce8ec771ae31e648e8bdd46ba25d6c19f06f9974d6b813f440aaf3659f885b2d22c1e46678aad1863"}], [{{0x9, 0x5, 0xb, 0x10, 0x10, 0x1, 0xdc, 0x2, [@uac_iso={0x7, 0x25, 0x1, 0x80, 0x2, 0x2}]}}, {{0x9, 0x5, 0x6, 0x0, 0x400, 0x1, 0x7f, 0xa0, [@generic={0x6d, 0x11, "3ad86d497f418861f39d36cbcc1ee2a722346b15ed088ddd788c7ee6cf3398d57ed4e60fb26d0f5a04bdfc4af066cb763f2f8410cd79dd1e84a93fdaabcec87af86242a611b4361d254dce604ed43e54841077c7b11c4edf45cc1df20553d2a02aaef78e730e0f14ca91bd"}]}}, {{0x9, 0x5, 0x0, 0x10, 0x20, 0x5, 0x1, 0x1d}}, {{0x9, 0x5, 0xd, 0x0, 0x3ff, 0x3, 0x1, 0x9, [@uac_iso={0x7, 0x25, 0x1, 0x81, 0x2, 0x7}, @uac_iso={0x7, 0x25, 0x1, 0x82, 0x5, 0x1}]}}, {{0x9, 0x5, 0x9, 0x0, 0x10, 0x1, 0x2, 0x3}}, {{0x9, 0x5, 0xb, 0x14, 0x400, 0x84, 0x8, 0x10, [@generic={0x60, 0x24, "7789e3c4a170fde0c3e6cf162f974e2e12cf3c52b247589589c38fbc175c680d18c528c08f8b3155017e54f022e03621f7720b08a373bcc5c2bdc4007ad92cb8fb1effd9b3621da00cb5647703e3ea74bfa414f53af3a5dfbba90961dcc0"}, @generic={0xdc, 0x11, "873ab51fea93dcfdd3a69f24521219f8f3d6f7816c4d2870b28c62208a14d8646e96d25628e26a0290a3efd1f23de6f790e98999bfbeb02350ce34306f3c89d97dcd98bc3761c42c660425ff5f2c84193d2d9db07fbddcb80c6b568e7aa2b6fdfa24e0c26d057e238ae685ce67ce220e39a2e43d2b4b80e5e176796931b600a4b7b4e3e4bbcfd98e4f6e1c1f31aecd636665851ce71afb71eb3d69d773bbfe685d9c40aba204b213c983292fcaae3a06ba2b25c10e94cf1e260c1d034bf393b7688a0bdd436c3089476e4cc4ff012ed90b73dd6272f127edad54"}]}}, {{0x9, 0x5, 0x5, 0x10, 0x400, 0x1, 0x0, 0x7, [@uac_iso={0x7, 0x25, 0x1, 0x2, 0x0, 0x10}]}}, {{0x9, 0x5, 0x3, 0x2, 0x10, 0xd, 0xb9, 0x4, [@uac_iso={0x7, 0x25, 0x1, 0x3, 0xcf, 0x4}, @generic={0x2b, 0x8, "d4d1e9433cc750eda93ea80e5893b9c56f08da52e01548799d9fe79394014f4f6d928a9f630906124d"}]}}, {{0x9, 0x5, 0x0, 0x4, 0x10, 0x7, 0x3, 0xe, [@generic={0x28, 0x3, "66e1d28867cd97738b07fc3f7a50a42873be75410534e304165a0fd0cc09e6c66accb1ea4e3a"}]}}, {{0x9, 0x5, 0x2, 0x1, 0x20, 0x3, 0xc, 0x8, [@generic={0xcd, 0x21, "e669e29ec88dbbefcb908017454f244b744fab4b1e7f6620e934953e43bda4d8727f7de9b9c27de7207c88958bd2df4ae24c96450f08c48413289c6538217c8fbac5c36619985e431aeffc4bd647a66ccde9d8421297d371245dddfe9a2907e5320a5e249d8a6d2cd79964dc2def9fc791d2db8e435efec7ea47562fd27a0e87082ecfa44ec14fddcc606badb1b846005cbe2e3db82b2902081da8d9b4bd0465e0c7457308a2f17b2b195f62cdd0b70fc02c9cfe5ac66b1ad39324c4ff58dbc46dca22b56a26cc9d6541ff"}]}}, {{0x9, 0x5, 0x2, 0x0, 0x10, 0x0, 0x9, 0xff}}]}}]}}]}}, &(0x7f0000000880)={0xa, &(0x7f00000006c0)={0xa, 0x6, 0x300, 0xf7, 0x1, 0xfc, 0xff, 0x9}, 0x8, &(0x7f0000000700)={0x5, 0xf, 0x8, 0x1, [@ptm_cap={0x3}]}, 0x2, [{0x4, &(0x7f0000000740)=@lang_id={0x4, 0x3, 0x444}}, {0xca, &(0x7f0000000780)=@string={0xca, 0x3, "07dfce9bea6c701c4df45deb2726b9c6cf567711491229ca3f449459f22db6ea54c7ed62e1af2f7004370cf90c033b57a4bcf82442c0319dc1afb4b84bec2cd37371dcad63badedd27ee0e5ca1c0857c44afacfda3c0f4455660b67f594d6631e19b6934d175c3f68e5bc86bd824f799582e3188055256b4408d39a94c0181e56c76d576eacd53a923d9b87f8a72af7ac6c0d467c381e91798d1411e00341b105ea9cfdbf6f9fac57c8ae417f251cf32b9d145a3130288666695b9a848e2cd269d7beef36db509bf"}}]}) 373.956218ms ago: executing program 3 (id=1465): r0 = socket$inet(0xa, 0x801, 0x84) connect$inet(r0, &(0x7f0000004cc0)={0x2, 0x0, @remote={0xac, 0x14, 0xffffffffffffffff}}, 0x10) listen(r0, 0x8) mq_open(0x0, 0x0, 0x0, &(0x7f0000000180)={0x8001}) r1 = add_key$user(&(0x7f00000003c0), &(0x7f0000000440), &(0x7f00000000c0), 0xc9, 0xfffffffffffffffd) keyctl$dh_compute(0x17, &(0x7f0000000040)={r1, r1, r1}, &(0x7f0000001cc0)=""/194, 0xc2, 0x0) r2 = accept4(r0, 0x0, 0x0, 0x0) r3 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000003c0)={0x1b, 0x0, 0x0, 0x5, 0x0, r0, 0x3, '\x00', 0x0, 0xffffffffffffffff, 0x3, 0x3, 0x4, 0x0, @void, @value, @void, @value}, 0x50) bpf$MAP_LOOKUP_ELEM(0x1, &(0x7f0000000600)={r3, &(0x7f0000000440)="3c160a095a0574a5baf4e505cd0e6de6a82797ff8a1fc1fe114f3da7f4173df123a2f10889333253efc033f66103ac461f5a7f2b22299dd99f18258552b9289ffb7aa14e75786e68fbeb39248aa484136e9fcb683fa6392da9fcf7db8681aa90bbfe7bddd5f1bc2683d40f82fbc9737770ab0d5b7847b2737dc6af97e9e778efecc3ba716e9be14fb59c6455bec10c0b668e0fbf7a1471d0b81e4143481f9a6ac65ee65b9140812428f32f6c5aed9f114e6994dcafd0eb67bb413a2321768e449519982532a71933dee3dd5ae0626fa6", &(0x7f0000000540)=""/151, 0x4}, 0x20) r4 = socket(0x1d, 0x2, 0x6) ioctl$ifreq_SIOCGIFINDEX_vcan(r4, 0x8933, &(0x7f0000000000)={'vxcan0\x00', 0x0}) bind$can_j1939(r4, &(0x7f0000000380)={0x1d, r5, 0x1, {0x2, 0x1, 0x3}, 0xfd}, 0x18) bind$can_j1939(r4, &(0x7f00000000c0)={0x1d, r5, 0xffffffffffffffff, {0x1, 0xf0, 0x4}, 0x1}, 0xfe63) getsockopt$inet_sctp6_SCTP_PR_ASSOC_STATUS(r2, 0x84, 0x73, &(0x7f0000000200)={0x0, 0x5, 0x30, 0x4, 0x3}, &(0x7f0000000240)=0x18) sendto$l2tp6(r2, &(0x7f0000000100)="f4fee81898d15d1816c2d55427ba8b3e66005126c90fe72752978f4547c517ab93ffc18ec048ae2a583a3c75b5d42be0dab9ced13a3a6928d72e0bbdca5a5faf43176a589c0e3fcbb03a715a81b4963e358d9f095cab44e7a8b06448ec9e6ca1b41ce625aae15e01857b", 0x6d, 0x40004, &(0x7f0000000000)={0xa, 0x0, 0x9913, @dev={0xfe, 0x80, '\x00', 0xb}, 0x10000001, 0x2}, 0x20) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000040), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(r6, 0x8933, &(0x7f0000000080)={'wlan0\x00', 0x0}) sendmsg$NL80211_CMD_JOIN_MESH(r6, &(0x7f0000000180)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000280)=ANY=[@ANYBLOB='(\x00\x00\x00', @ANYRES16=r7, @ANYBLOB="050000000000030000004400000008000300", @ANYRES32=r8, @ANYBLOB="a3aa40bc02da4c00000000006bbff79db6ee46fa67be84b268faae94f19dd520391d0c46b784a302e0c812e2cbc9a4896847752d8185310e643cce4e4c14b81e4eedade24a3140c5127ebce6711b666a48850b23c3feaa9748c8b69867fb0805cb2246f944d8a750081152c4dfdf408486705ca28ce9a52a41fe766c739055141302a5b8e10e53b48a652ede3ad0030000009cffe62f35e0fd8fd3556e966e747c21474aa7ce80710f2a5df8941ec75f2e51a81130b065c85557b9f40232157106919f3a7d008dd4fc62a5"], 0x28}}, 0x0) 312.636785ms ago: executing program 0 (id=1466): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r1, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000cc0)={&(0x7f0000000500)=ANY=[@ANYBLOB="54010000100013070000000000000000ac1414aa000000000100000000000000fe80000000000000ff0300000000000000000000000000000000000000d00000", @ANYRES32=0x0, @ANYRES32, @ANYBLOB="00000000000000000000000000000000000000003200000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000000000000000000048000200656362286369706865725f6e756c6c29000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001c001c0044"], 0x154}, 0x1, 0x0, 0x0, 0x40000}, 0x0) r2 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000040), r0) r3 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$nl80211(&(0x7f00000000c0), r0) (async) r4 = syz_genetlink_get_family_id$nl80211(&(0x7f00000000c0), r0) r5 = socket$unix(0x1, 0x5, 0x0) ppoll(&(0x7f0000000d40)=[{r5, 0x3a60}], 0x1, 0x0, 0x0, 0x0) (async) ppoll(&(0x7f0000000d40)=[{r5, 0x3a60}], 0x1, 0x0, 0x0, 0x0) ioctl$sock_SIOCGIFINDEX_80211(r3, 0x8933, &(0x7f00000002c0)={'wlan1\x00', 0x0}) sendmsg$NL80211_CMD_AUTHENTICATE(r3, &(0x7f0000000200)={&(0x7f0000000080)={0x10, 0x0, 0x0, 0x20}, 0xc, &(0x7f00000001c0)={&(0x7f0000000640)={0xec, r4, 0x300, 0x70bd2d, 0x25dfdbfd, {{}, {@val={0x8, 0x3, r6}, @val={0xc, 0x99, {0x0, 0x7}}}}, [@NL80211_ATTR_MAC={0xa, 0x6, @random="fb1c00001d00"}, @NL80211_ATTR_AUTH_TYPE={0x8, 0x35, 0x5}, @key_params=[@NL80211_ATTR_KEY_DATA_WEP104={0x11, 0x7, "7b5d875ac7bd17bc0405a2a7e3"}, @NL80211_ATTR_KEY_CIPHER={0x8, 0x9, 0xfac05}, @NL80211_ATTR_KEY_DATA_WEP104={0x11, 0x7, "283a78591d0300"}, @NL80211_ATTR_KEY_DEFAULT_MGMT={0x4}, @NL80211_ATTR_KEY_SEQ={0xf, 0xa, "c992d539b3b7ae7fb78c9b"}, @NL80211_ATTR_MAC={0xa}, @NL80211_ATTR_KEY_DEFAULT={0x4}, @NL80211_ATTR_KEY_DEFAULT_TYPES={0x8, 0x6e, 0x0, 0x1, [@NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x1}]}, @NL80211_ATTR_KEY_DATA_WEP40={0x9, 0x7, "fb730a1ad9"}, @NL80211_ATTR_KEY={0x30, 0x50, 0x0, 0x1, [@NL80211_KEY_DEFAULT_TYPES={0x1c, 0x8, 0x0, 0x1, [@NL80211_KEY_DEFAULT_TYPE_UNICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_UNICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_UNICAST={0x4}]}, @NL80211_KEY_CIPHER={0x8, 0x3, 0xfac05}, @NL80211_KEY_MODE={0x5}]}], @NL80211_ATTR_MAC={0xa, 0x6, @from_mac}, @NL80211_ATTR_SSID={0xa, 0x34, @default_ap_ssid}]}, 0xec}, 0x1, 0x0, 0x0, 0x8045}, 0xc000) (async) sendmsg$NL80211_CMD_AUTHENTICATE(r3, &(0x7f0000000200)={&(0x7f0000000080)={0x10, 0x0, 0x0, 0x20}, 0xc, &(0x7f00000001c0)={&(0x7f0000000640)={0xec, r4, 0x300, 0x70bd2d, 0x25dfdbfd, {{}, {@val={0x8, 0x3, r6}, @val={0xc, 0x99, {0x0, 0x7}}}}, [@NL80211_ATTR_MAC={0xa, 0x6, @random="fb1c00001d00"}, @NL80211_ATTR_AUTH_TYPE={0x8, 0x35, 0x5}, @key_params=[@NL80211_ATTR_KEY_DATA_WEP104={0x11, 0x7, "7b5d875ac7bd17bc0405a2a7e3"}, @NL80211_ATTR_KEY_CIPHER={0x8, 0x9, 0xfac05}, @NL80211_ATTR_KEY_DATA_WEP104={0x11, 0x7, "283a78591d0300"}, @NL80211_ATTR_KEY_DEFAULT_MGMT={0x4}, @NL80211_ATTR_KEY_SEQ={0xf, 0xa, "c992d539b3b7ae7fb78c9b"}, @NL80211_ATTR_MAC={0xa}, @NL80211_ATTR_KEY_DEFAULT={0x4}, @NL80211_ATTR_KEY_DEFAULT_TYPES={0x8, 0x6e, 0x0, 0x1, [@NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x1}]}, @NL80211_ATTR_KEY_DATA_WEP40={0x9, 0x7, "fb730a1ad9"}, @NL80211_ATTR_KEY={0x30, 0x50, 0x0, 0x1, [@NL80211_KEY_DEFAULT_TYPES={0x1c, 0x8, 0x0, 0x1, [@NL80211_KEY_DEFAULT_TYPE_UNICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_MULTICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_UNICAST={0x4}, @NL80211_KEY_DEFAULT_TYPE_UNICAST={0x4}]}, @NL80211_KEY_CIPHER={0x8, 0x3, 0xfac05}, @NL80211_KEY_MODE={0x5}]}], @NL80211_ATTR_MAC={0xa, 0x6, @from_mac}, @NL80211_ATTR_SSID={0xa, 0x34, @default_ap_ssid}]}, 0xec}, 0x1, 0x0, 0x0, 0x8045}, 0xc000) ioctl$sock_SIOCGIFINDEX_80211(r3, 0x8933, &(0x7f00000003c0)={'wlan0\x00', 0x0}) sendmsg$NL80211_CMD_SET_TX_BITRATE_MASK(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000100)=ANY=[@ANYBLOB, @ANYRES16=r2, @ANYBLOB="010000000000ffdbdf253900000008000300", @ANYRES32=r7, @ANYBLOB="0c005a801400038005000600000000000500070002000000"], 0x34}}, 0x4800) (async) sendmsg$NL80211_CMD_SET_TX_BITRATE_MASK(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000100)=ANY=[@ANYBLOB, @ANYRES16=r2, @ANYBLOB="010000000000ffdbdf253900000008000300", @ANYRES32=r7, @ANYBLOB="0c005a801400038005000600000000000500070002000000"], 0x34}}, 0x4800) 311.904091ms ago: executing program 3 (id=1467): r0 = bpf$MAP_CREATE(0x100000000000000, &(0x7f0000000680)=@base={0xa, 0x16, 0xb4, 0x3, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) r1 = socket(0x10, 0x3, 0x0) setsockopt$netlink_NETLINK_TX_RING(r1, 0x10e, 0xc, &(0x7f0000000040)={0x802, 0x0, 0x0, 0x7}, 0x10) sendmsg$nl_generic(r1, &(0x7f0000000000)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000100)=ANY=[@ANYBLOB="200000005200010003000000000000000a0000000c00", @ANYRES32=r1], 0x20}}, 0x0) mkdir(&(0x7f0000000400)='./file0\x00', 0x0) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000240)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}, {@index_on}, {@volatile}]}) r2 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000000200)='mounts\x00') read$FUSE(r2, &(0x7f0000002140)={0x2020}, 0x2100) r3 = socket(0x400000000010, 0x3, 0x0) r4 = socket$unix(0x1, 0x1, 0x0) ioctl$sock_SIOCGIFINDEX(r4, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r3, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2a, 0xffffffff, {0x0, 0x0, 0x0, r5, {0x0, 0xfff1}, {0xffff, 0xffff}, {0xffe0, 0xf}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8, 0x2, {0x1}}}]}, 0x38}, 0x1, 0x0, 0x0, 0xc080}, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000006040)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000ac0)=@newtfilter={0x30, 0x2c, 0xd2b, 0x0, 0x25dfdbfd, {0x0, 0x0, 0x0, r5, {0x1, 0x2}, {}, {0xe, 0xffe0}}, [@filter_kind_options=@f_fw={{0x7}, {0x4}}]}, 0x30}, 0x1, 0x0, 0x0, 0x1}, 0x4000084) r6 = bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000280)=@bpf_lsm={0x6, 0x3, &(0x7f00000003c0)=ANY=[@ANYBLOB="18000000003f000000000000000000f195"], &(0x7f0000000140)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) setsockopt$inet_MCAST_JOIN_GROUP(r3, 0x0, 0x2a, &(0x7f0000000500)={0x9a2, {{0x2, 0x4e24, @dev={0xac, 0x14, 0x14, 0x19}}}}, 0x88) r7 = bpf$ITER_CREATE(0xb, &(0x7f00000004c0)={r6}, 0x8) r8 = bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000280)=@bpf_lsm={0x6, 0x3, &(0x7f00000003c0)=ANY=[], &(0x7f0000000140)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r9 = bpf$ITER_CREATE(0xb, &(0x7f0000000180)={r7}, 0x8) close(r9) bpf$BPF_PROG_TEST_RUN(0x1c, &(0x7f0000000240)={r8, 0x8, 0x25, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x40) bpf$BPF_LINK_UPDATE(0x1d, &(0x7f00000005c0)={r7, r6, 0x4, r8}, 0x10) ioctl$sock_ipv6_tunnel_SIOCADDTUNNEL(r1, 0x89f1, &(0x7f00000000c0)={'syztnl1\x00', &(0x7f0000000040)={'ip6_vti0\x00', r5, 0x4, 0x3, 0x10, 0x33b, 0x45, @local, @private0, 0x40, 0x10, 0x9, 0x684}}) socket$inet(0x2, 0x3, 0x4) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000440)={0x11, 0x6, &(0x7f0000000280)=@framed={{0x18, 0x8}, [@map_fd={0x18, 0x0, 0x1, 0x0, r0}, @generic={0x77, 0x0, 0x0, 0x1, 0x6}]}, &(0x7f0000000000)='GPL\x00', 0x2, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 311.737333ms ago: executing program 0 (id=1468): r0 = socket(0x10, 0x3, 0x0) ioctl$sock_SIOCGIFINDEX(r0, 0x8933, &(0x7f0000000040)={'sit0\x00', 0x0}) sendmsg$nl_route(r0, &(0x7f0000000080)={0xffffffffffffffff, 0x0, &(0x7f00000001c0)={&(0x7f0000000100)=ANY=[@ANYBLOB="3c0000006800010000000000fbdbdf25020000000000000006000700040000000c000880050004000100000008000600f200000008000500", @ANYRES64=r1], 0x3c}, 0x1, 0x0, 0x0, 0x4402}, 0x0) mount(&(0x7f0000000040)=@loop={'/dev/loop', 0x0}, &(0x7f0000000000)='./cgroup\x00', &(0x7f00000001c0)='qnx4\x00', 0x208004, 0x0) 225.990031ms ago: executing program 0 (id=1469): r0 = socket$nl_generic(0x10, 0x3, 0x10) (async) r1 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$SG_GET_PACK_ID(r1, 0x227c, &(0x7f0000000000)) r2 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000540), 0x1) ioctl$SNDRV_SEQ_IOCTL_CREATE_QUEUE(r2, 0xc08c5332, &(0x7f0000000280)={0x0, 0x0, 0x0, 'queue0\x00'}) write$sndseq(r2, &(0x7f0000000100)=[{0x5, 0x3, 0x0, 0x0, @time, {}, {0x0, 0x3}, @queue={0x4, {0x7, 0xfffffff7}}}], 0x1c) (async) close(r2) r3 = socket$pppl2tp(0x18, 0x1, 0x1) r4 = socket$inet_udp(0x2, 0x2, 0x0) connect$pppl2tp(r3, &(0x7f0000000240)=@pppol2tpin6={0x18, 0x1, {0x0, r4, 0x2, 0x0, 0x0, 0x0, {0xa, 0x0, 0x0, @rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02'}}}, 0x32) r5 = socket$nl_generic(0x10, 0x3, 0x10) r6 = syz_genetlink_get_family_id$l2tp(&(0x7f0000000040), 0xffffffffffffffff) sendmsg$L2TP_CMD_TUNNEL_DELETE(r5, &(0x7f0000000440)={0x0, 0x0, &(0x7f0000000400)={&(0x7f0000000380)={0x1c, r6, 0x1, 0x70bd28, 0x25dfdbfc, {}, [@L2TP_ATTR_CONN_ID={0x8, 0x9, 0x2}]}, 0x1c}}, 0x40) sendmsg$nl_generic(r0, &(0x7f00000029c0)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000840)=ANY=[@ANYBLOB="240000001000010700000000000000000a000000060001001300000008000a0005"], 0x24}, 0x1, 0x0, 0x0, 0x8884}, 0x0) 225.83659ms ago: executing program 0 (id=1470): r0 = syz_open_dev$swradio(&(0x7f0000000a80), 0x0, 0x2) syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) syz_usb_disconnect(0xffffffffffffffff) timer_create(0x0, &(0x7f00000000c0)={0x0, 0x12, 0x0, @thr={0x0, 0x0}}, &(0x7f0000000100)=0x0) timer_settime(r1, 0x0, &(0x7f0000000280)={{}, {0x0, 0x3938700}}, 0x0) r2 = gettid() rt_sigaction(0x16, &(0x7f0000000080)={0x0, 0x90000000, 0x0}, 0x0, 0x8, &(0x7f0000000200)) tkill(r2, 0x16) mprotect(&(0x7f0000000000/0x4000)=nil, 0x4000, 0x1) ioctl$VIDIOC_G_TUNER(r0, 0xc054561d, &(0x7f0000000ac0)={0x1, "12f7f538cc9ad9f769d66b3d1dd9cd911e9a080bd3ae2ae3ea00"}) 225.22522ms ago: executing program 3 (id=1471): mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x1) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) r0 = socket$packet(0x11, 0x2, 0x300) setsockopt$packet_tx_ring(r0, 0x107, 0x5, &(0x7f0000000080)=@req3={0x8000, 0x6, 0x8000, 0x6}, 0x1c) close(r0) r1 = openat$fb0(0xffffffffffffff9c, &(0x7f0000000580), 0x40000, 0x0) ioctl$FBIOPUTCMAP(r1, 0x4605, &(0x7f0000000100)={0x7, 0x7, &(0x7f0000000140)=[0xe4a4, 0x2, 0xaab, 0x2, 0xedae, 0x5, 0x7fff], 0x0, 0x0, 0x0}) socketpair$unix(0x1, 0x1, 0x0, &(0x7f00000000c0)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFBR(r2, 0x8941, &(0x7f0000000080)=@add_del={0x3, &(0x7f0000000100)='ip6erspan0\x00', 0x2a0ffffffff}) r3 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0) syz_kvm_setup_cpu$x86(r3, 0xffffffffffffffff, &(0x7f00002a9000/0x18000)=nil, &(0x7f00000000c0)=[@text32={0x20, &(0x7f0000000040)="c4e2999284bc010000000f20e035080000000f22e0ea970000008300660f602266d9fef8b97f0a0000b807000000ba000000000f30f3acc4e17de7910000010066b85c008ed8", 0x46}], 0x1, 0x21, &(0x7f0000000140), 0x0) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) mbind(&(0x7f0000001000/0x800000)=nil, 0x800000, 0x0, 0x0, 0x0, 0x2) mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x1) (async) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) (async) socket$packet(0x11, 0x2, 0x300) (async) setsockopt$packet_tx_ring(r0, 0x107, 0x5, &(0x7f0000000080)=@req3={0x8000, 0x6, 0x8000, 0x6}, 0x1c) (async) close(r0) (async) openat$fb0(0xffffffffffffff9c, &(0x7f0000000580), 0x40000, 0x0) (async) ioctl$FBIOPUTCMAP(r1, 0x4605, &(0x7f0000000100)={0x7, 0x7, &(0x7f0000000140)=[0xe4a4, 0x2, 0xaab, 0x2, 0xedae, 0x5, 0x7fff], 0x0, 0x0, 0x0}) (async) socketpair$unix(0x1, 0x1, 0x0, &(0x7f00000000c0)) (async) ioctl$sock_SIOCGIFBR(r2, 0x8941, &(0x7f0000000080)=@add_del={0x3, &(0x7f0000000100)='ip6erspan0\x00', 0x2a0ffffffff}) (async) ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0) (async) syz_kvm_setup_cpu$x86(r3, 0xffffffffffffffff, &(0x7f00002a9000/0x18000)=nil, &(0x7f00000000c0)=[@text32={0x20, &(0x7f0000000040)="c4e2999284bc010000000f20e035080000000f22e0ea970000008300660f602266d9fef8b97f0a0000b807000000ba000000000f30f3acc4e17de7910000010066b85c008ed8", 0x46}], 0x1, 0x21, &(0x7f0000000140), 0x0) (async) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) (async) mbind(&(0x7f0000001000/0x800000)=nil, 0x800000, 0x0, 0x0, 0x0, 0x2) (async) 131.205052ms ago: executing program 3 (id=1472): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000440), 0xc0580, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = openat$rdma_cm(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r2, &(0x7f0000000040)={0x0, 0x18, 0xfa00, {0x0, &(0x7f0000000080)={0xffffffffffffffff}, 0x13f, 0x9}}, 0x20) write$RDMA_USER_CM_CMD_JOIN_MCAST(r2, &(0x7f00000001c0)={0x16, 0x98, 0xfa00, {0x0, 0x1, r3, 0x10, 0x0, @in={0x2, 0x4e24, @multicast2}}}, 0xa0) r4 = socket$netlink(0x10, 0x3, 0x0) sendmsg$nl_route(r4, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000700)=@newlink={0x38, 0x12, 0xff05, 0x0, 0x0, {0x0, 0x0, 0x4a00}, [@IFLA_LINKINFO={0x18, 0x12, 0x0, 0x1, @wireguard={{0xe}, {0x4}}}]}, 0x38}}, 0x0) ioctl$KVM_SET_IRQCHIP(r1, 0x4048aec9, &(0x7f0000000840)={0x6, 0x0, @ioapic={0x0, 0x5, 0x8, 0x2, 0x0, [{0x81, 0x80, 0xa, '\x00', 0x5}, {0x4, 0x3, 0xc, '\x00', 0x5}, {0x5, 0x7f, 0x88, '\x00', 0xe9}, {0x0, 0x9, 0x7, '\x00', 0x9}, {0x1, 0xc0, 0x0, '\x00', 0xf}, {0x6, 0x1, 0x9, '\x00', 0xe}, {0x4a, 0x2, 0x7, '\x00', 0x2}, {0xff, 0x7, 0x2, '\x00', 0x6}, {0xc7, 0x5, 0x59, '\x00', 0xed}, {0x9, 0x9, 0x8, '\x00', 0x3}, {0x9, 0x6, 0x23, '\x00', 0x2}, {0x6, 0x87, 0x2, '\x00', 0x9}, {0x7, 0xd6, 0xad, '\x00', 0x24}, {0x2, 0x9, 0xc, '\x00', 0x8}, {0x8, 0x1, 0x80, '\x00', 0x3a}, {0x2, 0x8}, {0x6, 0x3, 0x8, '\x00', 0x7}, {0xf4, 0xa1, 0x3, '\x00', 0x80}, {0x8, 0x1, 0x9, '\x00', 0x42}, {0x4, 0x44, 0x0, '\x00', 0x8}, {0xfc, 0x1, 0x8, '\x00', 0x7}, {0x1, 0x7, 0xe7, '\x00', 0x5}, {0x9, 0x3, 0x48, '\x00', 0xf}, {0x7, 0x11, 0x1, '\x00', 0x5}]}}) 1.906482ms ago: executing program 3 (id=1473): r0 = socket$inet_udplite(0x2, 0x2, 0x88) ioctl$sock_ipv6_tunnel_SIOCDELPRL(r0, 0x89f6, &(0x7f0000000000)={'sit0\x00', &(0x7f00000002c0)={@private=0xa010100, 0x0, 0x0, 0x50, 0x0, [{@private}, {@local}, {@broadcast}, {@remote}, {@multicast1}]}}) r1 = io_uring_setup(0x194e, &(0x7f0000000a80)={0x0, 0xd3d9, 0x40, 0x2, 0x2b1}) ioctl$BTRFS_IOC_GET_SUPPORTED_FEATURES(r1, 0x80489439, &(0x7f0000000140)) r2 = getpid() r3 = syz_pidfd_open(r2, 0x0) bpf$ITER_CREATE(0x21, &(0x7f0000000000)={0xffffffffffffffff, 0x300}, 0x8) setns(r3, 0x24020000) r4 = open_tree(0xffffffffffffff9c, &(0x7f0000000640)='\x00', 0x89901) close(r4) r5 = openat$vhost_vsock(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) ioctl$VHOST_SET_VRING_BASE(r5, 0xaf01, 0x0) ioctl$VHOST_SET_MEM_TABLE(r5, 0x4008af03, &(0x7f0000000280)) ioctl$VHOST_SET_FEATURES(r5, 0x4008af00, &(0x7f0000000080)=0x200000000) io_uring_setup(0x6ff8, &(0x7f00000001c0)={0x0, 0x6424, 0x0, 0x1, 0x28e, 0x0, r1}) ioctl$VHOST_VSOCK_SET_RUNNING(r5, 0x4004af61, &(0x7f0000000040)=0xffffffff) r6 = openat$selinux_avc_cache_threshold(0xffffffffffffff9c, &(0x7f0000000280), 0x2, 0x0) write$cgroup_int(r6, &(0x7f0000000700)=0x8, 0x3c) close_range(r1, 0xffffffffffffffff, 0x0) 0s ago: executing program 3 (id=1474): r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) r1 = socket(0x11, 0xa, 0x0) write$vga_arbiter(0xffffffffffffffff, &(0x7f0000000000)=@unlock_all, 0x7) (async) sendmsg$can_bcm(r1, &(0x7f0000000140)={&(0x7f0000000000), 0x10, &(0x7f0000000080)={0x0, 0xe00}, 0x8}, 0x0) (async) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) (async) r2 = fcntl$dupfd(r0, 0x0, r0) ioctl$TCFLSH(r0, 0x400455c8, 0x1000000000000002) (async) ioctl$TIOCSETD(r2, 0x5412, &(0x7f0000000140)=0xffbfffc0) (async) ioctl$TIOCSTI(r2, 0x5412, &(0x7f0000000100)=0x12) (async) ioctl$TIOCSTI(r0, 0x5412, &(0x7f0000000340)=0xff) (async) r3 = openat$ptp1(0xffffffffffffff9c, &(0x7f0000000000), 0x20001, 0x0) ioctl$PTP_EXTTS_REQUEST(r3, 0x40103d02, &(0x7f0000000040)={0x70, 0x1}) (async) r4 = syz_genetlink_get_family_id$batadv(&(0x7f00000002c0), r2) (async, rerun: 32) r5 = openat$ptmx(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) (rerun: 32) ioctl$TIOCSTI(r5, 0x5412, &(0x7f0000000380)=0xe9) (async) sendmsg$BATADV_CMD_SET_VLAN(r2, &(0x7f0000000400)={&(0x7f0000000280)={0x10, 0x0, 0x0, 0x1000000}, 0xc, &(0x7f0000000300)={&(0x7f0000000740)=ANY=[@ANYBLOB='X\x00\x00\x00', @ANYRES16=r4, @ANYBLOB="00042dbd7000fddbdf000000000005002a000100000008000b000700000008003400000000000800310006000000050033000b00060000000a000900aaaaaaaaaaaa0000050029000000000016372fb27fd992835455911a229c6ecebda459d9786bcf4b87d9ef33316628d5b86792bfaee299abd363f88c49d3ab7b5525516060f7a7d31389716725f503e7bc267d1ae7badae62e8f909d110dc1545699bafe39ab0bea2250ca3e94cca031ebf2f6f6457559b15ba2b7019e26c770ed9ab1a78ef3d210cbe748500e9c826caa20f2e21839b07f1bc9976d"], 0x58}, 0x1, 0x0, 0x0, 0x404c000}, 0x0) (async) ioctl$TIOCSTI(r0, 0x5412, &(0x7f0000000180)) r6 = socket$nl_route(0x10, 0x3, 0x0) (async, rerun: 64) r7 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, @fallback=0x22, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) (async, rerun: 64) r8 = socket(0x10, 0x3, 0x0) r9 = openat$ppp(0xffffffffffffff9c, &(0x7f00000003c0), 0x0, 0x0) sendmsg$nl_route(r8, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000480)=ANY=[@ANYBLOB="400000001000030429bd70000000000000000000", @ANYRES32=0x0, @ANYBLOB="01000000000000001800128008000100707070000c00028008000100", @ANYRES32=r9, @ANYBLOB="08001f"], 0x40}}, 0x0) (async) sendmsg$IPCTNL_MSG_CT_NEW(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000080)=ANY=[@ANYBLOB="a800000000010904000500000000000002000000240001801400018008000100e000000108000200ac1e01010c00028005000100000009002400028014000180080001000000010908000200ac1e00010c000280050001000000000044000f800800"], 0xa8}}, 0x0) (async) sendmsg$nl_route(r6, &(0x7f0000000e00)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000000c0)=ANY=[@ANYBLOB="300000001900015c672b4d6c48273300802000000011000500000000140009"], 0x30}}, 0x0) (async, rerun: 64) ioctl$TIOCSTI(r0, 0x5412, &(0x7f0000000240)=0x7) (async, rerun: 64) ioctl$TIOCSTI(r2, 0x5412, &(0x7f00000001c0)) bpf$BPF_GET_PROG_INFO(0xf, &(0x7f0000000700)={r7, 0xe0, &(0x7f0000000600)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4, &(0x7f0000000440)=[0x0, 0x0, 0x0, 0x0], ""/16, 0x0, 0x0, 0x0, 0x0, 0x1, 0x8, &(0x7f0000000480)=[0x0], &(0x7f00000004c0)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0], 0x0, 0x70, &(0x7f0000000500)=[{}, {}, {}, {}, {}, {}], 0x30, 0x10, &(0x7f0000000540), &(0x7f0000000580), 0x8, 0xd0, 0x8, 0x8, &(0x7f00000005c0)}}, 0x10) socket$nl_generic(0x10, 0x3, 0x10) (async, rerun: 32) bpf$PROG_LOAD(0x5, &(0x7f00000054c0)={0x2, 0x16, &(0x7f0000000180)=ANY=[@ANYBLOB="611230000000000061134c0000000000bf2000000000000016001000071b48013d030100000000000f02000000000000bc26100000000000bf67200000000000160200000fff07006702000007000000360600000ee600f0bf050000000000000f650000000000006507f4ff02000000070700004c0040001f75000000000000bf54000000000000070500000300f9ffad430100000000009500000000000000050000000000000095000000000000004d9bd591d568253e9988431ec068e3a83683d58719d72183f2cb7f43dd55788be820b236dcb695dbfd737cbf5fe7030586"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, r10, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) (rerun: 32) kernel console output (not intermixed with test programs): read } for pid=7441 comm="syz.2.415" name="msr" dev="devtmpfs" ino=93 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cpu_device_t tclass=chr_file permissive=1 [ 78.906967][ T40] audit: type=1400 audit(1749311209.201:460): avc: denied { open } for pid=7441 comm="syz.2.415" path="/dev/cpu/3/msr" dev="devtmpfs" ino=93 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cpu_device_t tclass=chr_file permissive=1 [ 78.914610][ T7443] IPVS: sync thread started: state = BACKUP, mcast_ifn = hsr0, syncid = 4, id = 0 [ 78.949436][ T7445] xt_l2tp: unknown flags: 17 [ 78.951593][ T40] audit: type=1400 audit(1749311209.248:461): avc: denied { map } for pid=7444 comm="syz.0.416" path="socket:[18017]" dev="sockfs" ino=18017 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=udp_socket permissive=1 [ 78.985860][ T7449] syzkaller0: entered promiscuous mode [ 78.987674][ T7449] syzkaller0: entered allmulticast mode [ 79.073971][ T40] audit: type=1400 audit(1749311209.361:462): avc: denied { append } for pid=7453 comm="syz.0.418" name="card0" dev="devtmpfs" ino=635 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:dri_device_t tclass=chr_file permissive=1 [ 79.110844][ T7456] netlink: 8 bytes leftover after parsing attributes in process `syz.0.419'. [ 79.323781][ T7460] @: renamed from vlan0 (while UP) [ 79.362124][ T7465] netlink: 'syz.3.422': attribute type 20 has an invalid length. [ 79.444149][ T40] audit: type=1400 audit(1749311209.707:463): avc: denied { mount } for pid=7466 comm="syz.1.423" name="/" dev="cgroup2" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cgroup_t tclass=filesystem permissive=1 [ 79.488099][ T7478] netlink: 24 bytes leftover after parsing attributes in process `syz.2.427'. [ 79.491047][ T40] audit: type=1400 audit(1749311209.753:464): avc: denied { write } for pid=7466 comm="syz.1.423" name="msr" dev="devtmpfs" ino=87 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cpu_device_t tclass=chr_file permissive=1 [ 79.498697][ T40] audit: type=1400 audit(1749311209.753:465): avc: denied { ioctl } for pid=7466 comm="syz.1.423" path="/dev/cpu/0/msr" dev="devtmpfs" ino=87 ioctlcmd=0x63a1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cpu_device_t tclass=chr_file permissive=1 [ 79.525791][ T7478] SELinux: unrecognized netlink message: protocol=4 nlmsg_type=16 sclass=netlink_tcpdiag_socket pid=7478 comm=syz.2.427 [ 79.547998][ T7478] xfrm0 speed is unknown, defaulting to 1000 [ 79.696249][ T7499] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 79.771508][ T7505] xfrm0 speed is unknown, defaulting to 1000 [ 79.818964][ T40] audit: type=1326 audit(1749311210.062:466): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=7504 comm="syz.3.437" exe="/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7f3682b8e929 code=0x0 [ 79.878475][ T7510] netlink: 'syz.1.439': attribute type 3 has an invalid length. [ 79.881807][ T7510] netlink: 199836 bytes leftover after parsing attributes in process `syz.1.439'. [ 79.910685][ T7512] netlink: 12 bytes leftover after parsing attributes in process `syz.1.440'. [ 79.956932][ T7512] netlink: 27 bytes leftover after parsing attributes in process `syz.1.440'. [ 80.009855][ T1460] cfg80211: failed to load regulatory.db [ 80.080268][ T40] audit: type=1400 audit(1749311210.296:467): avc: denied { bind } for pid=7524 comm="syz.1.444" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 80.675387][ T7575] xt_ecn: cannot match TCP bits for non-tcp packets [ 81.087410][ T7592] netlink: 'syz.0.450': attribute type 3 has an invalid length. [ 81.283694][ T7601] SELinux: Context system_u:object_r:crond_var_run_t:s0 is not valid (left unmapped). [ 81.487962][ T7618] netlink: 'syz.0.458': attribute type 2 has an invalid length. [ 81.490428][ T7618] netlink: 784 bytes leftover after parsing attributes in process `syz.0.458'. [ 81.656021][ T6000] usb 7-1: new high-speed USB device number 11 using dummy_hcd [ 81.816995][ T6000] usb 7-1: Using ep0 maxpacket: 8 [ 81.823408][ T6000] usb 7-1: config 168 descriptor has 1 excess byte, ignoring [ 81.826128][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 81.830994][ T6000] usb 7-1: config 168 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 81.837646][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 81.841557][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 81.845925][ T6000] usb 7-1: config 168 descriptor has 1 excess byte, ignoring [ 81.849299][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 81.852828][ T6000] usb 7-1: config 168 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 81.852847][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 81.852860][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 81.858667][ T7633] netlink: 32 bytes leftover after parsing attributes in process `syz.0.463'. [ 81.862126][ T6000] usb 7-1: config 168 descriptor has 1 excess byte, ignoring [ 81.868546][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 81.869640][ T7633] netlink: 'syz.0.463': attribute type 3 has an invalid length. [ 81.872233][ T6000] usb 7-1: config 168 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 81.874385][ T7633] netlink: 224 bytes leftover after parsing attributes in process `syz.0.463'. [ 81.881754][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 81.885194][ T6000] usb 7-1: config 168 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 81.904105][ T6000] usb 7-1: string descriptor 0 read error: -22 [ 81.906181][ T6000] usb 7-1: New USB device found, idVendor=0a07, idProduct=0064, bcdDevice=40.6e [ 81.911659][ T6000] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 81.919903][ T6000] adutux 7-1:168.0: ADU100 now attached to /dev/usb/adutux0 [ 81.930467][ T7635] xfrm0 speed is unknown, defaulting to 1000 [ 82.026986][ T7635] binder_alloc: 7634: binder_alloc_buf, no vma [ 82.184911][ T7651] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=7651 comm=syz.0.468 [ 82.195206][ T7652] fuse: Bad value for 'group_id' [ 82.198617][ T7652] fuse: Bad value for 'group_id' [ 83.278991][ T7687] SET target dimension over the limit! [ 83.946027][ T40] kauditd_printk_skb: 16 callbacks suppressed [ 83.946039][ T40] audit: type=1400 audit(1749311213.916:484): avc: denied { map } for pid=7710 comm="syz.3.488" path="socket:[20641]" dev="sockfs" ino=20641 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 83.955816][ T40] audit: type=1400 audit(1749311213.916:485): avc: denied { read } for pid=7710 comm="syz.3.488" path="socket:[20641]" dev="sockfs" ino=20641 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 83.970853][ T7715] tmpfs: Bad value for 'mpol' [ 84.018677][ T52] usb 5-1: new high-speed USB device number 6 using dummy_hcd [ 84.141789][ T7719] syzkaller0: refused to change device tx_queue_len [ 84.179130][ T52] usb 5-1: Using ep0 maxpacket: 32 [ 84.183154][ T52] usb 5-1: config 2 has an invalid interface number: 254 but max is 2 [ 84.185843][ T52] usb 5-1: config 2 has an invalid interface number: 5 but max is 2 [ 84.188304][ T52] usb 5-1: config 2 has an invalid descriptor of length 64, skipping remainder of the config [ 84.191583][ T52] usb 5-1: config 2 has 2 interfaces, different from the descriptor's value: 3 [ 84.194319][ T52] usb 5-1: config 2 has no interface number 0 [ 84.196249][ T52] usb 5-1: config 2 has no interface number 1 [ 84.198222][ T52] usb 5-1: config 2 interface 254 altsetting 8 has 0 endpoint descriptors, different from the interface descriptor's value: 12 [ 84.203785][ T52] usb 5-1: too many endpoints for config 2 interface 5 altsetting 6: 131, using maximum allowed: 30 [ 84.207234][ T52] usb 5-1: config 2 interface 5 altsetting 6 has 0 endpoint descriptors, different from the interface descriptor's value: 131 [ 84.211426][ T52] usb 5-1: config 2 interface 254 has no altsetting 0 [ 84.213590][ T52] usb 5-1: config 2 interface 5 has no altsetting 0 [ 84.217554][ T52] usb 5-1: New USB device found, idVendor=1a72, idProduct=1001, bcdDevice=f7.bd [ 84.220487][ T52] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 84.223075][ T52] usb 5-1: Product: О [ 84.224408][ T52] usb 5-1: Manufacturer: ä­žã½âžžä±¹ë‰‹Ê䀳삂왴读᫆㌉斚ã¸å¯ä¼ºé‰¬êµ³îŒ‹ç’¬è‡´å¼á‘宩퓊۰羚窮 [ 84.228102][ T52] usb 5-1: SerialNumber: syz [ 84.252591][ T7722] xfrm0 speed is unknown, defaulting to 1000 [ 84.258560][ T7723] xfrm0 speed is unknown, defaulting to 1000 [ 84.448502][ T7706] __nla_validate_parse: 9 callbacks suppressed [ 84.448514][ T7706] netlink: 24 bytes leftover after parsing attributes in process `syz.0.486'. [ 84.453498][ T7706] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 84.454338][ T7727] netlink: 20 bytes leftover after parsing attributes in process `syz.3.492'. [ 84.463896][ T52] ftdi_sio 5-1:2.254: FTDI USB Serial Device converter detected [ 84.467961][ T52] ftdi_sio ttyUSB0: unknown device type: 0xf7bd [ 84.472842][ T52] hub 5-1:2.5: Invalid hub with more than one config or interface [ 84.475304][ T52] hub 5-1:2.5: probe with driver hub failed with error -22 [ 84.477964][ T52] ftdi_sio 5-1:2.5: FTDI USB Serial Device converter detected [ 84.481782][ T52] ftdi_sio ttyUSB1: unknown device type: 0xf7bd [ 84.492904][ T52] usb 5-1: USB disconnect, device number 6 [ 84.496929][ T52] ftdi_sio 5-1:2.254: device disconnected [ 84.500387][ T72] usb 7-1: USB disconnect, device number 11 [ 84.501447][ T52] ftdi_sio 5-1:2.5: device disconnected [ 84.568432][ T7734] netlink: 8 bytes leftover after parsing attributes in process `syz.3.495'. [ 84.571198][ T7734] netlink: 12 bytes leftover after parsing attributes in process `syz.3.495'. [ 84.574017][ T7734] netlink: 'syz.3.495': attribute type 18 has an invalid length. [ 84.673641][ T7739] netlink: 'syz.3.498': attribute type 1 has an invalid length. [ 84.688830][ T40] audit: type=1400 audit(1749311214.608:486): avc: denied { append } for pid=7740 comm="syz.2.497" name="mice" dev="devtmpfs" ino=940 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:mouse_device_t tclass=chr_file permissive=1 [ 84.713458][ T7739] 8021q: adding VLAN 0 to HW filter on device bond2 [ 84.723503][ T7739] bond2: (slave geneve2): making interface the new active one [ 84.727350][ T7739] bond2: (slave geneve2): Enslaving as an active interface with an up link [ 84.746463][ T7739] veth3: entered promiscuous mode [ 84.748492][ T40] audit: type=1400 audit(1749311214.674:487): avc: denied { ioctl } for pid=7740 comm="syz.2.497" path="/dev/input/mice" dev="devtmpfs" ino=940 ioctlcmd=0x541c scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:mouse_device_t tclass=chr_file permissive=1 [ 84.750695][ T7739] bond2: (slave veth3): Enslaving as an active interface with a down link [ 84.774294][ T7739] vlan0: entered allmulticast mode [ 84.775993][ T7739] bond2: entered allmulticast mode [ 84.778511][ T7739] geneve2: entered allmulticast mode [ 84.781113][ T7739] bond2: (slave vlan0): the slave hw address is in use by the bond; couldn't find a slave with a free hw address to give it (this should not have happened) [ 84.825327][ T7747] netlink: 4 bytes leftover after parsing attributes in process `syz.2.500'. [ 84.898386][ T40] audit: type=1800 audit(1749311214.814:488): pid=7751 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=collect_data cause=failed comm="syz.3.501" name="SYSV00000000" dev="tmpfs" ino=1 res=0 errno=0 [ 84.932994][ T40] audit: type=1400 audit(1749311214.842:489): avc: denied { append } for pid=7752 comm="syz.2.503" name="nvram" dev="devtmpfs" ino=631 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nvram_device_t tclass=chr_file permissive=1 [ 84.951317][ T7755] xs_local_setup_socket: unhandled error (13) connecting to /var/run/rpcbind.sock [ 85.117142][ T40] audit: type=1400 audit(1749311215.001:490): avc: denied { execute } for pid=7764 comm="syz.3.507" path="/dev/nullb0" dev="devtmpfs" ino=707 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:device_t tclass=blk_file permissive=1 [ 85.123365][ T7780] netlink: 8 bytes leftover after parsing attributes in process `syz.0.511'. [ 85.129988][ T7780] netlink: 20 bytes leftover after parsing attributes in process `syz.0.511'. [ 85.144116][ T7780] macsec1: entered promiscuous mode [ 85.199246][ T7778] netlink: 24 bytes leftover after parsing attributes in process `syz.3.507'. [ 85.306830][ T7783] openvswitch: netlink: IP tunnel attribute has 20 unknown bytes. [ 85.530047][ T7796] netlink: 8 bytes leftover after parsing attributes in process `syz.3.517'. [ 85.601313][ T7805] netlink: 'syz.3.520': attribute type 10 has an invalid length. [ 85.615434][ T7805] bond0: (slave wlan1): Enslaving as an active interface with an up link [ 85.623907][ T40] audit: type=1400 audit(1749311215.487:491): avc: denied { write } for pid=7800 comm="syz.3.520" name="file0" dev="9p" ino=36047791 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 85.630726][ T40] audit: type=1400 audit(1749311215.487:492): avc: denied { open } for pid=7800 comm="syz.3.520" path="/128/file0/file0" dev="9p" ino=36047791 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 86.526057][ T40] audit: type=1400 audit(1749311216.329:493): avc: denied { mount } for pid=7824 comm="syz.1.523" name="/" dev="devpts" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:devpts_t tclass=filesystem permissive=1 [ 86.526824][ T7825] devpts: Unknown parameter 'TiÿÒ' [ 86.831998][ T7842] sch_tbf: peakrate 8 is lower than or equals to rate 12 ! [ 86.866203][ T7839] netlink: 12 bytes leftover after parsing attributes in process `syz.0.529'. [ 87.134552][ T7863] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 87.150044][ T7868] openvswitch: netlink: Either Ethernet header or EtherType is required. [ 87.243187][ T7863] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 87.260228][ T7875] MTD: Attempt to mount non-MTD device "/dev/sr0" [ 87.271751][ T7875] cramfs: wrong magic [ 87.333926][ T7863] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 87.438576][ T7863] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 87.530696][ T7863] netdevsim netdevsim3 eth0: set [1, 0] type 2 family 0 port 6081 - 0 [ 87.543681][ T7863] netdevsim netdevsim3 eth1: set [1, 0] type 2 family 0 port 6081 - 0 [ 87.555192][ T7863] netdevsim netdevsim3 eth2: set [1, 0] type 2 family 0 port 6081 - 0 [ 87.570658][ T7863] netdevsim netdevsim3 eth3: set [1, 0] type 2 family 0 port 6081 - 0 [ 87.662476][ T52] usb 6-1: new high-speed USB device number 9 using dummy_hcd [ 87.801129][ T7882] afs: Unknown parameter '' [ 87.825641][ T52] usb 6-1: config 0 interface 0 altsetting 251 endpoint 0x9 has invalid wMaxPacketSize 0 [ 87.828680][ T52] usb 6-1: config 0 interface 0 has no altsetting 0 [ 87.832524][ T52] usb 6-1: New USB device found, idVendor=045e, idProduct=0283, bcdDevice=99.0b [ 87.837161][ T52] usb 6-1: New USB device strings: Mfr=1, Product=228, SerialNumber=2 [ 87.839684][ T52] usb 6-1: Product: syz [ 87.841004][ T52] usb 6-1: Manufacturer: syz [ 87.842462][ T52] usb 6-1: SerialNumber: syz [ 87.845473][ T52] usb 6-1: config 0 descriptor?? [ 87.849734][ T52] usb 6-1: selecting invalid altsetting 0 [ 87.899795][ T7883] bridge4: entered promiscuous mode [ 88.059241][ T7900] program syz.0.551 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 88.064731][ T7879] openvswitch: netlink: Tunnel attr 14 has unexpected len 2 expected 0 [ 88.067914][ T52] usb 6-1: USB disconnect, device number 9 [ 88.138174][ T7907] fuse: Bad value for 'rootmode' [ 88.332087][ T1255] nci: nci_rsp_packet: unknown rsp opcode 0x116 [ 88.388540][ T7911] nci: __nci_request: wait_for_completion_interruptible_timeout failed -512 [ 88.563769][ T7920] af_packet: tpacket_rcv: packet too big, clamped from 36 to 4294967272. macoff=96 [ 88.691698][ T7927] SELinux: unknown common  [ 88.693343][ T7927] SELinux: failed to load policy [ 89.542330][ T7970] netlink: 'syz.1.571': attribute type 29 has an invalid length. [ 89.546821][ T7970] netlink: 'syz.1.571': attribute type 29 has an invalid length. [ 89.920830][ T40] kauditd_printk_skb: 18 callbacks suppressed [ 89.920842][ T40] audit: type=1400 audit(88.927:512): avc: denied { write } for pid=7999 comm="syz.1.581" path="socket:[21694]" dev="sockfs" ino=21694 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netrom_socket permissive=1 [ 90.240491][ T6111] usb 5-1: new high-speed USB device number 7 using dummy_hcd [ 90.323138][ T8012] binder: 8010:8012 ioctl c0306201 2000000003c0 returned -14 [ 90.400831][ T6111] usb 5-1: Using ep0 maxpacket: 8 [ 90.404228][ T6111] usb 5-1: config 1 interface 0 altsetting 7 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 90.408583][ T6111] usb 5-1: config 1 interface 0 altsetting 7 endpoint 0x2 has an invalid bInterval 0, changing to 7 [ 90.412660][ T6111] usb 5-1: config 1 interface 0 has no altsetting 0 [ 90.417168][ T6111] usb 5-1: New USB device found, idVendor=5543, idProduct=0522, bcdDevice= 0.40 [ 90.420339][ T6111] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 90.422830][ T6111] usb 5-1: Product: 씒쌣,邎℗⟯⡷㧽㘌í®é®ºî²®ë¸à¸±ëˆ˜î¤¤ä¿ˆã¸§æ¡†ßšížé§¹åˆ®ìš¸ãž¢âƒâ–Ÿë –覅锲ᮄã®â²®é™©ï°‚䆺í›ê¯”ã§€ç“®à¹¦Øœî©ŒÅ—îŸ›ã†™ì¡¬ì¦æŠªä•Ꭿ꣜⇊⼥ìŒìˆ¹ã¾³ç·«ç†Ÿä‡¬ï­œî—„à¼ïŽ“í€†è§˜â‚€è˜Žë¥±è°ªã¼²æ”ºå‰ªâ¦¯í—±ì†µæ§á¸éŸƒë¤¢é«Ÿë™¸ìƒ±å’–î§à»…웃á³ëªºéµ¤í‡‹ë·­ë»èŒ† [ 90.431516][ T6111] usb 5-1: Manufacturer: ë°– [ 90.433096][ T6111] usb 5-1: SerialNumber: 澃挻⑷ážî¸¤á§®é“Žãº°ã¶»Í¯âˆ‹å†€ä»‘䉪簭ӊᡶ⸆롲㡄裡䧅駥ïµì­ˆì½¢é¨ºè‘¨á± å¹¯è®²æ–‹ç¶„仿ꔦ낫 [ 90.655419][ T40] audit: type=1400 audit(89.610:513): avc: denied { write } for pid=8008 comm="syz.0.583" name="cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 90.662109][ T6111] usbhid 5-1:1.0: can't add hid device: -71 [ 90.665091][ T40] audit: type=1400 audit(89.610:514): avc: denied { open } for pid=8008 comm="syz.0.583" path="/dev/cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 90.666796][ T6111] usbhid 5-1:1.0: probe with driver usbhid failed with error -71 [ 90.680591][ T6111] usb 5-1: USB disconnect, device number 7 [ 91.187604][ T40] audit: type=1400 audit(90.115:515): avc: denied { view } for pid=8013 comm="syz.1.585" scontext=root:sysadm_r:sysadm_t tcontext=system_u:system_r:kernel_t tclass=key permissive=1 [ 91.190161][ T8014] netlink: 'syz.1.585': attribute type 11 has an invalid length. [ 91.197794][ T8014] netlink: 'syz.1.585': attribute type 11 has an invalid length. [ 91.200318][ T8014] __nla_validate_parse: 5 callbacks suppressed [ 91.200325][ T8014] netlink: 224 bytes leftover after parsing attributes in process `syz.1.585'. [ 91.228903][ T40] audit: type=1400 audit(90.152:516): avc: denied { map } for pid=8013 comm="syz.1.585" path="socket:[21387]" dev="sockfs" ino=21387 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_route_socket permissive=1 [ 91.285652][ T8019] syzkaller1: entered promiscuous mode [ 91.288074][ T8019] syzkaller1: entered allmulticast mode [ 91.296462][ T40] audit: type=1326 audit(90.208:517): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=8018 comm="syz.1.587" exe="/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7faff7b8e929 code=0x0 [ 91.411394][ T40] audit: type=1400 audit(90.320:518): avc: denied { getopt } for pid=8031 comm="syz.3.591" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=kcm_socket permissive=1 [ 91.715875][ T60] usb 5-1: new high-speed USB device number 8 using dummy_hcd [ 91.899175][ T60] usb 5-1: config 0 has no interfaces? [ 91.902905][ T60] usb 5-1: New USB device found, idVendor=19d2, idProduct=ff4a, bcdDevice=ec.53 [ 91.905685][ T60] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 91.908271][ T60] usb 5-1: Product: syz [ 91.909598][ T60] usb 5-1: Manufacturer: syz [ 91.911358][ T60] usb 5-1: SerialNumber: syz [ 91.915005][ T60] usb 5-1: config 0 descriptor?? [ 92.132840][ T8016] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=14426 sclass=netlink_route_socket pid=8016 comm=syz.0.586 [ 92.138108][ T73] usb 5-1: USB disconnect, device number 8 [ 92.243785][ T8058] xt_hashlimit: size too large, truncated to 1048576 [ 92.667269][ T73] usb 6-1: new high-speed USB device number 10 using dummy_hcd [ 92.705738][ T8066] netlink: 12 bytes leftover after parsing attributes in process `syz.0.598'. [ 92.711353][ T40] audit: type=1400 audit(91.536:519): avc: denied { open } for pid=8065 comm="syz.0.598" path="/dev/ttyq5" dev="devtmpfs" ino=388 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:bsdpty_device_t tclass=chr_file permissive=1 [ 92.828612][ T73] usb 6-1: Using ep0 maxpacket: 8 [ 92.831414][ T73] usb 6-1: config 168 descriptor has 1 excess byte, ignoring [ 92.831454][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 92.831477][ T73] usb 6-1: config 168 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 92.831498][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 92.831519][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 92.835003][ T73] usb 6-1: config 168 descriptor has 1 excess byte, ignoring [ 92.835027][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 92.835041][ T73] usb 6-1: config 168 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 92.835054][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 92.835067][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 92.849183][ T73] usb 6-1: config 168 descriptor has 1 excess byte, ignoring [ 92.849208][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 92.849222][ T73] usb 6-1: config 168 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 92.849256][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 92.849270][ T73] usb 6-1: config 168 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 92.891301][ T73] usb 6-1: string descriptor 0 read error: -22 [ 92.891362][ T73] usb 6-1: New USB device found, idVendor=0a07, idProduct=0064, bcdDevice=40.6e [ 92.891374][ T73] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 92.899383][ T73] adutux 6-1:168.0: ADU100 now attached to /dev/usb/adutux0 [ 93.109584][ T54] usb 6-1: USB disconnect, device number 10 [ 93.329220][ T8073] adutux: No device or device unplugged -19 [ 93.366345][ T40] audit: type=1400 audit(92.154:520): avc: denied { mount } for pid=8075 comm="syz.1.599" name="/" dev="autofs" ino=20456 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:autofs_t tclass=filesystem permissive=1 [ 93.372351][ T8076] netlink: 8 bytes leftover after parsing attributes in process `syz.1.599'. [ 93.376295][ T8076] netlink: 8 bytes leftover after parsing attributes in process `syz.1.599'. [ 93.392661][ T40] audit: type=1400 audit(92.173:521): avc: denied { unmount } for pid=5939 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:autofs_t tclass=filesystem permissive=1 [ 93.519994][ T8081] netlink: 4 bytes leftover after parsing attributes in process `syz.1.601'. [ 93.522861][ T8081] netlink: 40 bytes leftover after parsing attributes in process `syz.1.601'. [ 93.688035][ T8099] netlink: 32 bytes leftover after parsing attributes in process `syz.0.605'. [ 93.690893][ T8099] netlink: 4 bytes leftover after parsing attributes in process `syz.0.605'. [ 93.727898][ T8104] netlink: 32 bytes leftover after parsing attributes in process `syz.1.606'. [ 93.930528][ T8132] netlink: 12 bytes leftover after parsing attributes in process `syz.0.611'. [ 93.958265][ T8135] batadv_slave_0: entered promiscuous mode [ 93.986368][ T8139] binder: 8138:8139 ioctl c0306201 200000000640 returned -22 [ 94.014321][ T8135] batadv_slave_0 (unregistering): left promiscuous mode [ 94.016748][ T8135] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 94.090588][ T8145] block nbd0: shutting down sockets [ 94.094476][ T8139] binfmt_misc: register: failed to install interpreter file ./file0 [ 94.131222][ T8148] overlayfs: failed to resolve './file0': -2 [ 94.209598][ T8152] xfrm0 speed is unknown, defaulting to 1000 [ 94.306853][ T8158] mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium [ 94.430858][ T8167] binder: 8166:8167 unknown command 65616 [ 94.433150][ T8167] binder: 8166:8167 ioctl c0306201 200000000100 returned -22 [ 94.603563][ T73] usb 6-1: new low-speed USB device number 11 using dummy_hcd [ 94.764263][ T73] usb 6-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 94.768397][ T73] usb 6-1: config 1 has 1 interface, different from the descriptor's value: 2 [ 94.771578][ T73] usb 6-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 10 [ 94.776024][ T73] usb 6-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 94.779846][ T73] usb 6-1: New USB device found, idVendor=0225, idProduct=0000, bcdDevice= 0.00 [ 94.782693][ T73] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 94.788691][ T73] hub 6-1:1.0: bad descriptor, ignoring hub [ 94.790613][ T73] hub 6-1:1.0: probe with driver hub failed with error -5 [ 94.793155][ T73] cdc_wdm 6-1:1.0: skipping garbage [ 94.794992][ T73] cdc_wdm 6-1:1.0: skipping garbage [ 94.798434][ T73] cdc_wdm 6-1:1.0: cdc-wdm0: USB WDM device [ 94.800298][ T73] cdc_wdm 6-1:1.0: Unknown control protocol [ 94.962904][ T8184] xfrm0 speed is unknown, defaulting to 1000 [ 94.979082][ T8185] xfrm0 speed is unknown, defaulting to 1000 [ 95.085000][ T8161] cdc_wdm 6-1:1.0: Error submitting int urb - -90 [ 95.181361][ T8189] cdc_wdm 6-1:1.0: Error submitting int urb - -90 [ 95.213874][ T5565] usb 6-1: USB disconnect, device number 11 [ 95.687929][ T8217] kAFS: unable to lookup cell '/,c¾ûL' [ 95.743158][ T8223] capability: warning: `syz.3.635' uses 32-bit capabilities (legacy support in use) [ 95.788487][ T40] kauditd_printk_skb: 7 callbacks suppressed [ 95.788499][ T40] audit: type=1400 audit(94.408:529): avc: denied { accept } for pid=8226 comm="syz.3.636" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=llc_socket permissive=1 [ 95.796425][ T40] audit: type=1400 audit(94.417:530): avc: denied { getopt } for pid=8226 comm="syz.3.636" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 95.911008][ T8229] netlink: 'syz.3.637': attribute type 39 has an invalid length. [ 95.923298][ T8233] dlm: no locking on control device [ 95.926394][ T8235] dlm: no locking on control device [ 95.946997][ T8234] netlink: 'syz.2.638': attribute type 32 has an invalid length. [ 95.950470][ T8234] (unnamed net_device) (uninitialized): option coupled_control: invalid value (86) [ 96.162735][ T40] audit: type=1400 audit(94.764:531): avc: denied { read write } for pid=8241 comm="syz.1.642" name="file0" dev="fuse" ino=0 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fusefs_t tclass=chr_file permissive=1 [ 96.171665][ T40] audit: type=1400 audit(94.764:532): avc: denied { open } for pid=8241 comm="syz.1.642" path="/153/file0/file0" dev="fuse" ino=0 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fusefs_t tclass=chr_file permissive=1 [ 96.217191][ T6000] usb 5-1: new high-speed USB device number 9 using dummy_hcd [ 96.378788][ T6000] usb 5-1: config index 0 descriptor too short (expected 14215, got 36) [ 96.381389][ T6000] usb 5-1: config 72 has too many interfaces: 150, using maximum allowed: 32 [ 96.384071][ T6000] usb 5-1: config 72 has an invalid descriptor of length 0, skipping remainder of the config [ 96.387215][ T6000] usb 5-1: config 72 has 0 interfaces, different from the descriptor's value: 150 [ 96.390993][ T6000] usb 5-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 96.393799][ T6000] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 96.473156][ T5981] usb 7-1: new high-speed USB device number 12 using dummy_hcd [ 96.645661][ T5981] usb 7-1: config 2 has an invalid descriptor of length 10, skipping remainder of the config [ 96.648820][ T5981] usb 7-1: config 2 has 0 interfaces, different from the descriptor's value: 1 [ 96.651589][ T5981] usb 7-1: New USB device found, idVendor=1199, idProduct=9041, bcdDevice=5c.09 [ 96.654381][ T5981] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 96.832895][ T8237] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 96.836907][ T8237] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 96.842504][ T7951] usb 5-1: USB disconnect, device number 9 [ 96.886503][ T8239] kvm: requested 3352 ns i8254 timer period limited to 200000 ns [ 96.970922][ T8264] netdevsim netdevsim2 netdevsim0: entered promiscuous mode [ 96.978244][ T8264] __nla_validate_parse: 6 callbacks suppressed [ 96.978257][ T8264] netlink: 204 bytes leftover after parsing attributes in process `syz.2.641'. [ 97.061925][ T8267] mac80211_hwsim hwsim9 wlan1: entered allmulticast mode [ 97.074302][ T8270] mac80211_hwsim hwsim9 wlan1: left allmulticast mode [ 97.085934][ T1460] usb 7-1: USB disconnect, device number 12 [ 97.158060][ T8274] hub 8-0:1.0: USB hub found [ 97.159707][ T8274] hub 8-0:1.0: 1 port detected [ 97.181686][ T40] audit: type=1400 audit(95.718:533): avc: denied { bind } for pid=8273 comm="syz.3.650" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rxrpc_socket permissive=1 [ 97.344905][ T40] audit: type=1400 audit(95.867:534): avc: denied { append } for pid=8277 comm="syz.1.651" name="autofs" dev="devtmpfs" ino=104 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:autofs_device_t tclass=chr_file permissive=1 [ 97.378750][ T40] audit: type=1400 audit(95.905:535): avc: denied { setattr } for pid=8281 comm="syz.1.653" path="anon_inode:[userfaultfd]" dev="anon_inodefs" ino=22102 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:sysadm_t tclass=anon_inode permissive=1 [ 97.450257][ T8288] A link change request failed with some changes committed already. Interface bond0 may have been left with an inconsistent configuration, please check. [ 97.525461][ T8301] fuse: Unknown parameter 'group_i00000000000000000000' [ 97.703202][ T8309] loop6: detected capacity change from 0 to 524287999 [ 97.932053][ T8327] netlink: 8 bytes leftover after parsing attributes in process `syz.0.667'. [ 98.012306][ T40] audit: type=1400 audit(96.494:536): avc: denied { ioctl } for pid=8341 comm="syz.1.672" path="socket:[22850]" dev="sockfs" ino=22850 ioctlcmd=0x8917 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 98.053758][ T8346] netlink: 12 bytes leftover after parsing attributes in process `syz.1.673'. [ 98.085809][ T8349] netlink: 96 bytes leftover after parsing attributes in process `syz.2.675'. [ 98.144463][ T40] audit: type=1400 audit(96.625:537): avc: denied { bind } for pid=8361 comm="syz.0.679" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 98.177746][ T40] audit: type=1400 audit(96.653:538): avc: denied { getopt } for pid=8366 comm="syz.3.680" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_netfilter_socket permissive=1 [ 98.440048][ T8384] netlink: 44 bytes leftover after parsing attributes in process `syz.3.683'. [ 99.883436][ T60] usb 6-1: new high-speed USB device number 12 using dummy_hcd [ 100.067255][ T60] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 100.070776][ T60] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 100.073478][ T60] usb 6-1: New USB device found, idVendor=0926, idProduct=3333, bcdDevice= 0.40 [ 100.076136][ T60] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 100.079705][ T60] usb 6-1: config 0 descriptor?? [ 100.243836][ T8406] netlink: 28 bytes leftover after parsing attributes in process `syz.3.691'. [ 100.379004][ T60] usbhid 6-1:0.0: can't add hid device: -71 [ 100.385926][ T60] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 100.390545][ T60] usb 6-1: USB disconnect, device number 12 [ 100.404513][ T8422] IPVS: sync thread started: state = MASTER, mcast_ifn = veth0_to_bond, syncid = 33554432, id = 0 [ 100.405140][ T8421] IPVS: stopping master sync thread 8422 ... [ 100.414715][ T8421] SELinux: syz.1.695 (8421) set checkreqprot to 1. This is no longer supported. [ 100.603326][ T8448] block nbd0: not configured, cannot reconfigure [ 100.852811][ T8471] program syz.1.709 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 100.963295][ T60] usb 5-1: new full-speed USB device number 10 using dummy_hcd [ 101.086920][ T8483] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=8483 comm=syz.1.713 [ 101.095875][ T8483] gretap1: entered promiscuous mode [ 101.124737][ T60] usb 5-1: config 0 has no interfaces? [ 101.126483][ T60] usb 5-1: New USB device found, idVendor=04f3, idProduct=0755, bcdDevice= 0.00 [ 101.129410][ T60] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 101.133496][ T60] usb 5-1: config 0 descriptor?? [ 101.210426][ T8485] binder: 8484:8485 ioctl c018620c 2000000000c0 returned -22 [ 101.214784][ T8485] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=8485 comm=syz.1.714 [ 101.223001][ T40] kauditd_printk_skb: 16 callbacks suppressed [ 101.223014][ T40] audit: type=1400 audit(99.497:555): avc: denied { getopt } for pid=8484 comm="syz.1.714" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=alg_socket permissive=1 [ 101.235417][ T40] audit: type=1400 audit(99.515:556): avc: denied { setopt } for pid=8484 comm="syz.1.714" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 101.284716][ T8489] netlink: 12 bytes leftover after parsing attributes in process `syz.1.716'. [ 101.288271][ T8488] uprobe: syz.1.716:8488 failed to unregister, leaking uprobe [ 101.390324][ T40] audit: type=1400 audit(99.656:557): avc: denied { ioctl } for pid=8498 comm="syz.1.720" path="/dev/fuse" dev="devtmpfs" ino=105 ioctlcmd=0x6685 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fuse_device_t tclass=chr_file permissive=1 [ 101.423173][ T8504] netlink: 'syz.3.721': attribute type 1 has an invalid length. [ 101.427256][ T8504] netlink: 17 bytes leftover after parsing attributes in process `syz.3.721'. [ 101.431938][ T8506] netlink: 'syz.3.721': attribute type 1 has an invalid length. [ 101.435555][ T8506] netlink: 17 bytes leftover after parsing attributes in process `syz.3.721'. [ 101.550555][ T40] audit: type=1400 audit(99.805:558): avc: denied { write } for pid=8514 comm="syz.2.724" scontext=root:sysadm_r:sysadm_t tcontext=system_u:system_r:kernel_t tclass=key permissive=1 [ 101.695548][ T8526] netlink: 212408 bytes leftover after parsing attributes in process `syz.2.727'. [ 101.695882][ T8525] netlink: 'syz.1.726': attribute type 1 has an invalid length. [ 101.719578][ T8525] bond3: (slave ip6gretap1): Enslaving as a backup interface with an up link [ 101.722515][ T6000] usb 8-1: new high-speed USB device number 3 using dummy_hcd [ 101.765525][ T40] audit: type=1400 audit(100.011:559): avc: denied { watch_sb } for pid=8529 comm="syz.1.728" path="/188/file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" dev="tmpfs" ino=1035 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 101.768729][ T8530] overlayfs: missing 'workdir' [ 101.865448][ T40] audit: type=1400 audit(100.105:560): avc: denied { append } for pid=8534 comm="syz.2.730" name="ppp" dev="devtmpfs" ino=731 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ppp_device_t tclass=chr_file permissive=1 [ 101.885129][ T6000] usb 8-1: Using ep0 maxpacket: 8 [ 101.888775][ T6000] usb 8-1: config index 0 descriptor too short (expected 301, got 45) [ 101.892199][ T6000] usb 8-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 101.898419][ T6000] usb 8-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 0 [ 101.902747][ T6000] usb 8-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 101.908695][ T6000] usb 8-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 101.912745][ T6000] usb 8-1: New USB device found, idVendor=ee8d, idProduct=db1e, bcdDevice=61.23 [ 101.913706][ T8542] random: crng reseeded on system resumption [ 101.915925][ T6000] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 101.972216][ T8547] mmap: syz.1.734 (8547) uses deprecated remap_file_pages() syscall. See Documentation/mm/remap_file_pages.rst. [ 102.010416][ T8551] netlink: 'syz.1.735': attribute type 2 has an invalid length. [ 102.043033][ T5955] Bluetooth: hci2: command 0x0406 tx timeout [ 102.132689][ T6000] usb 8-1: usb_control_msg returned -32 [ 102.134547][ T6000] usbtmc 8-1:16.0: can't read capabilities [ 102.177276][ T40] audit: type=1400 audit(100.395:561): avc: denied { mounton } for pid=8558 comm="syz.1.737" path="/194/bus" dev="tmpfs" ino=1070 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=fifo_file permissive=1 [ 102.511917][ T8571] usbtmc 8-1:16.0: stb usb_control_msg returned -32 [ 102.514980][ T8511] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 102.517948][ T8511] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 102.530126][ T1460] usb 8-1: USB disconnect, device number 3 [ 102.648814][ T8581] openvswitch: netlink: Unknown VXLAN extension attribute 0 [ 102.712533][ T40] audit: type=1400 audit(100.890:562): avc: denied { mount } for pid=8583 comm="syz.2.744" name="/" dev="configfs" ino=3275 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:configfs_t tclass=filesystem permissive=1 [ 102.714148][ T8585] __nla_validate_parse: 2 callbacks suppressed [ 102.714158][ T8585] netlink: 16 bytes leftover after parsing attributes in process `syz.2.744'. [ 102.720590][ T40] audit: type=1400 audit(100.890:563): avc: denied { search } for pid=8583 comm="syz.2.744" name="/" dev="configfs" ino=3275 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:configfs_t tclass=dir permissive=1 [ 102.720616][ T40] audit: type=1400 audit(100.890:564): avc: denied { search } for pid=8583 comm="syz.2.744" name="/" dev="configfs" ino=3275 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:configfs_t tclass=dir permissive=1 [ 102.840250][ T8596] Bluetooth: MGMT ver 1.23 [ 103.057255][ T8611] xfrm0 speed is unknown, defaulting to 1000 [ 103.203676][ T8611] tmpfs: Unknown parameter 'dont_appraise' [ 103.342449][ T8617] netlink: 8 bytes leftover after parsing attributes in process `syz.2.754'. [ 103.386042][ T8617] netlink: 20 bytes leftover after parsing attributes in process `syz.2.754'. [ 103.444758][ T8622] ALSA: seq fatal error: cannot create timer (-22) [ 103.640601][ T8642] netlink: 4 bytes leftover after parsing attributes in process `syz.1.762'. [ 103.923614][ T54] usb 5-1: USB disconnect, device number 10 [ 103.937835][ T8653] block nbd0: shutting down sockets [ 103.961090][ T8661] netlink: ct family unspecified [ 103.962684][ T8661] openvswitch: netlink: Actions may not be safe on all matching packets [ 103.966086][ T8661] netlink: ct family unspecified [ 103.968284][ T8661] openvswitch: netlink: Actions may not be safe on all matching packets [ 104.009325][ T8667] random: crng reseeded on system resumption [ 104.124773][ T8685] netlink: 'syz.0.775': attribute type 13 has an invalid length. [ 104.150031][ T8685] gretap0: refused to change device tx_queue_len [ 104.152774][ T8685] A link change request failed with some changes committed already. Interface gretap0 may have been left with an inconsistent configuration, please check. [ 104.199142][ T8700] fuse: Bad value for 'group_id' [ 104.200834][ T8700] fuse: Bad value for 'group_id' [ 104.242768][ T8707] netlink: 12 bytes leftover after parsing attributes in process `syz.1.780'. [ 104.246894][ T8703] netlink: 8 bytes leftover after parsing attributes in process `syz.3.778'. [ 104.257337][ T8707] 8021q: adding VLAN 0 to HW filter on device bond4 [ 105.095232][ T8722] bridge0: entered allmulticast mode [ 105.109884][ T8722] pim6reg: entered allmulticast mode [ 105.118926][ T8722] netlink: 4 bytes leftover after parsing attributes in process `syz.1.784'. [ 105.122460][ T8722] bridge_slave_1: left allmulticast mode [ 105.124712][ T8722] bridge_slave_1: left promiscuous mode [ 105.128007][ T8722] bridge0: port 2(bridge_slave_1) entered disabled state [ 105.132879][ T8722] bridge_slave_0: left allmulticast mode [ 105.135064][ T8722] bridge_slave_0: left promiscuous mode [ 105.137346][ T8722] bridge0: port 1(bridge_slave_0) entered disabled state [ 105.154578][ T8722] bridge0 (unregistering): left allmulticast mode [ 105.430552][ T8755] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=41213 sclass=netlink_route_socket pid=8755 comm=syz.2.794 [ 105.467343][ T8758] netlink: 'syz.2.795': attribute type 10 has an invalid length. [ 105.470760][ T8758] lo: entered promiscuous mode [ 105.475059][ T8758] bond0: (slave lo): enslaved VLAN challenged slave. Adding VLANs will be blocked as long as it is part of bond. [ 105.520020][ T8762] netlink: 'syz.1.798': attribute type 1 has an invalid length. [ 105.523271][ T8762] IPv6: RTM_NEWROUTE with no NLM_F_CREATE or NLM_F_REPLACE [ 105.523996][ T8764] vivid-000: disconnect [ 105.526591][ T8762] IPv6: NLM_F_CREATE should be set when creating new route [ 105.530165][ T8763] vivid-000: reconnect [ 105.870314][ T6111] usb 6-1: new low-speed USB device number 13 using dummy_hcd [ 106.030649][ T6111] usb 6-1: Invalid ep0 maxpacket: 32 [ 106.171657][ T6111] usb 6-1: new low-speed USB device number 14 using dummy_hcd [ 106.257381][ T8804] fuse: Unknown parameter '000000000000000000030000000000000000000000000000000000000000003' [ 106.262257][ T8806] fuse: Unknown parameter '000000000000000000030000000000000000000000000000000000000000003' [ 106.340883][ T6111] usb 6-1: Invalid ep0 maxpacket: 32 [ 106.345675][ T6111] usb usb6-port1: attempt power cycle [ 106.624278][ T8818] netlink: 8 bytes leftover after parsing attributes in process `syz.0.815'. [ 106.628027][ T8818] netlink: 12 bytes leftover after parsing attributes in process `syz.0.815'. [ 106.674741][ T8820] netlink: 8 bytes leftover after parsing attributes in process `syz.0.816'. [ 106.687730][ T40] kauditd_printk_skb: 13 callbacks suppressed [ 106.687745][ T40] audit: type=1400 audit(104.613:578): avc: denied { firmware_load } for pid=8819 comm="syz.0.816" path="/lib/firmware/regulatory.db" dev="sda1" ino=448 scontext=system_u:system_r:kernel_t tcontext=system_u:object_r:lib_t tclass=system permissive=1 [ 106.716046][ T6111] usb 6-1: new low-speed USB device number 15 using dummy_hcd [ 106.736731][ T6111] usb 6-1: Invalid ep0 maxpacket: 32 [ 106.759290][ T8824] openvswitch: netlink: Missing key (keys=40, expected=2000) [ 106.762766][ T8824] veth1_to_team: entered promiscuous mode [ 106.765768][ T8824] veth1_to_team: left promiscuous mode [ 106.811592][ T8820] syz.0.816 (8820) used greatest stack depth: 17096 bytes left [ 106.862276][ T40] audit: type=1400 audit(104.772:579): avc: denied { getopt } for pid=8837 comm="syz.0.820" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 106.875164][ T6111] usb 6-1: new low-speed USB device number 16 using dummy_hcd [ 106.888540][ T8838] A link change request failed with some changes committed already. Interface geneve0 may have been left with an inconsistent configuration, please check. [ 106.893818][ T8839] wg1: entered promiscuous mode [ 106.895419][ T8839] wg1: entered allmulticast mode [ 106.897048][ T6111] usb 6-1: Invalid ep0 maxpacket: 32 [ 106.897335][ T6111] usb usb6-port1: unable to enumerate USB device [ 106.904519][ T8845] netlink: 'syz.2.823': attribute type 29 has an invalid length. [ 106.920602][ T40] audit: type=1400 audit(104.828:580): avc: denied { mount } for pid=8844 comm="syz.2.823" name="/" dev="9p" ino=36047789 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 106.924899][ T8845] netfs: Couldn't get user pages (rc=-14) [ 106.946109][ T40] audit: type=1400 audit(104.847:581): avc: denied { unmount } for pid=5948 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 107.342268][ T8861] openvswitch: netlink: Tunnel attr 16370 out of range max 16 [ 107.345687][ T8861] batadv_slave_0: entered promiscuous mode [ 107.348292][ T8861] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 107.386080][ T8861] batadv_slave_0 (unregistering): left promiscuous mode [ 107.389117][ T8861] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 107.535685][ T8868] fuse: Unknown parameter 'groué0PAÆí¾“óéXõ&®hÇÍ✕J9èµ2ÓÎZÄ/X^i9M…­·dL„{é¸Þæ [ 107.535685][ T8868] b`Â'bQ²ñÕB[$ëL$$Å€léä¯Ifç€ÕJ ¬FVÜO:“Õå2jû«æF ýI00000000000000000000' [ 107.767870][ T40] audit: type=1400 audit(105.624:582): avc: denied { accept } for pid=8878 comm="syz.3.832" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rose_socket permissive=1 [ 107.987045][ T40] audit: type=1400 audit(105.820:583): avc: denied { map } for pid=8889 comm="syz.0.835" path="/dev/bus/usb/006/001" dev="devtmpfs" ino=759 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usb_device_t tclass=chr_file permissive=1 [ 108.116757][ T7951] usb 6-1: new low-speed USB device number 17 using dummy_hcd [ 108.123831][ T8910] __nla_validate_parse: 8 callbacks suppressed [ 108.123846][ T8910] netlink: 4 bytes leftover after parsing attributes in process `syz.2.840'. [ 108.205821][ T8910] bridge_slave_1 (unregistering): left allmulticast mode [ 108.208070][ T8910] bridge_slave_1 (unregistering): left promiscuous mode [ 108.210314][ T8910] bridge0: port 2(bridge_slave_1) entered disabled state [ 108.275780][ T7951] usb 6-1: Invalid ep0 maxpacket: 32 [ 108.347553][ T8930] netlink: 8 bytes leftover after parsing attributes in process `syz.3.842'. [ 108.351897][ T8930] netlink: 24 bytes leftover after parsing attributes in process `syz.3.842'. [ 108.414607][ T7951] usb 6-1: new low-speed USB device number 18 using dummy_hcd [ 108.577798][ T7951] usb 6-1: Invalid ep0 maxpacket: 32 [ 108.580673][ T7951] usb usb6-port1: attempt power cycle [ 108.586642][ T8949] netlink: 8 bytes leftover after parsing attributes in process `syz.2.847'. [ 108.589756][ T8949] IPv6: Can't replace route, no match found [ 108.813836][ T8966] netlink: 20 bytes leftover after parsing attributes in process `syz.2.852'. [ 108.953015][ T40] audit: type=1800 audit(106.727:584): pid=8974 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=collect_data cause=failed comm="syz.2.856" name="SYSV00000000" dev="tmpfs" ino=3 res=0 errno=0 [ 108.995267][ T8977] netlink: 'syz.2.857': attribute type 1 has an invalid length. [ 109.008014][ T8977] 8021q: adding VLAN 0 to HW filter on device bond1 [ 109.101503][ T8986] ALSA: mixer_oss: invalid OSS volume '' [ 109.107757][ T8986] team0: Device gtp1 is of different type [ 109.175930][ T8992] netlink: 12 bytes leftover after parsing attributes in process `syz.2.860'. [ 109.180819][ T40] audit: type=1400 audit(106.943:585): avc: denied { mounton } for pid=8985 comm="syz.2.860" path="/175/file0/file0" dev="9p" ino=36047791 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 109.197053][ T40] audit: type=1400 audit(106.961:586): avc: denied { getattr } for pid=8985 comm="syz.2.860" name="/" dev="9p" ino=36047789 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 109.272876][ T40] audit: type=1400 audit(107.027:587): avc: denied { read } for pid=9000 comm="syz.3.866" name="file0" dev="fuse" ino=64 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fusefs_t tclass=blk_file permissive=1 [ 109.290331][ T9003] block device autoloading is deprecated and will be removed. [ 109.342771][ T9009] loop6: detected capacity change from 0 to 524287999 [ 109.355633][ T7951] usb usb6-port1: Cannot enable. Maybe the USB cable is bad? [ 109.417466][ T9013] pim6reg1: entered promiscuous mode [ 109.419224][ T9013] pim6reg1: entered allmulticast mode [ 109.507747][ T7951] usb 6-1: new high-speed USB device number 20 using dummy_hcd [ 109.528529][ T7951] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 109.532898][ T7951] usb 6-1: New USB device found, idVendor=0926, idProduct=3333, bcdDevice= 0.40 [ 109.536382][ T7951] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 109.541943][ T7951] usb 6-1: config 0 descriptor?? [ 109.695143][ T9036] netlink: 28 bytes leftover after parsing attributes in process `syz.3.872'. [ 109.765411][ T7951] usbhid 6-1:0.0: can't add hid device: -71 [ 109.767616][ T7951] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 109.772502][ T7951] usb 6-1: USB disconnect, device number 20 [ 109.837891][ T9046] netlink: 830 bytes leftover after parsing attributes in process `syz.0.875'. [ 109.898773][ T9050] netlink: 'syz.0.875': attribute type 1 has an invalid length. [ 109.938972][ T9049] loop2: detected capacity change from 0 to 7 [ 109.951123][ T9049] loop2: [CUMANA/ADFS] p1 [ADFS] p1 [ 109.953006][ T9049] loop2: partition table partially beyond EOD, truncated [ 109.958445][ T9049] loop2: p1 size 2989602745 extends beyond EOD, truncated [ 110.046105][ T5352] loop2: [CUMANA/ADFS] p1 [ADFS] p1 [ 110.048376][ T5352] loop2: partition table partially beyond EOD, truncated [ 110.052691][ T5352] loop2: p1 size 2989602745 extends beyond EOD, truncated [ 110.095997][ T5940] udevd[5940]: inotify_add_watch(7, /dev/loop2p1, 10) failed: No such file or directory [ 110.183021][ T9068] netlink: 8 bytes leftover after parsing attributes in process `syz.3.882'. [ 110.229848][ T9070] syz.2.883: vmalloc error: size 6291456, failed to allocated page array size 12288, mode:0x400dc2(GFP_KERNEL_ACCOUNT|__GFP_HIGHMEM|__GFP_ZERO), nodemask=(null),cpuset=/,mems_allowed=0-1 [ 110.236736][ T9070] CPU: 0 UID: 0 PID: 9070 Comm: syz.2.883 Not tainted 6.15.0-syzkaller-13655-gbdc7f8c5adad #0 PREEMPT(full) [ 110.236752][ T9070] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 [ 110.236760][ T9070] Call Trace: [ 110.236764][ T9070] [ 110.236768][ T9070] dump_stack_lvl+0x16c/0x1f0 [ 110.236806][ T9070] warn_alloc+0x248/0x3a0 [ 110.236822][ T9070] ? __pfx_warn_alloc+0x10/0x10 [ 110.236842][ T9070] ? hash_ipport_create+0x843/0x1a20 [ 110.236855][ T9070] ? __vmalloc_node_noprof+0xad/0xf0 [ 110.236875][ T9070] __vmalloc_node_range_noprof+0x101b/0x14b0 [ 110.236887][ T9070] ? ip_set_create+0x7e4/0x14d0 [ 110.236908][ T9070] ? hash_ipport_create+0x843/0x1a20 [ 110.236924][ T9070] ? __pfx___vmalloc_node_range_noprof+0x10/0x10 [ 110.236937][ T9070] ? __alloc_pages_noprof+0xb/0x1b0 [ 110.236952][ T9070] ? ___kmalloc_large_node+0x84/0x1e0 [ 110.236967][ T9070] __kvmalloc_node_noprof+0x30a/0x620 [ 110.236982][ T9070] ? hash_ipport_create+0x843/0x1a20 [ 110.236994][ T9070] ? hash_ipport_create+0x843/0x1a20 [ 110.237009][ T9070] ? hash_ipport_create+0x843/0x1a20 [ 110.237021][ T9070] hash_ipport_create+0x843/0x1a20 [ 110.237037][ T9070] ? __pfx_hash_ipport_create+0x10/0x10 [ 110.237053][ T9070] ? __pfx_hash_ipport_create+0x10/0x10 [ 110.237066][ T9070] ? ip_set_create+0x7e4/0x14d0 [ 110.237082][ T9070] ? ip_set_create+0x6da/0x14d0 [ 110.237097][ T9070] ip_set_create+0x7e4/0x14d0 [ 110.237117][ T9070] ? __pfx_ip_set_create+0x10/0x10 [ 110.237144][ T9070] ? find_held_lock+0x2b/0x80 [ 110.237162][ T9070] nfnetlink_rcv_msg+0x9fc/0x1200 [ 110.237182][ T9070] ? __pfx_nfnetlink_rcv_msg+0x10/0x10 [ 110.237199][ T9070] ? __lock_acquire+0x622/0x1c90 [ 110.237228][ T9070] ? avc_has_perm_noaudit+0x149/0x3b0 [ 110.237249][ T9070] netlink_rcv_skb+0x158/0x420 [ 110.237262][ T9070] ? __pfx_nfnetlink_rcv_msg+0x10/0x10 [ 110.237278][ T9070] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 110.237297][ T9070] ? ns_capable+0xd7/0x110 [ 110.237311][ T9070] nfnetlink_rcv+0x1b3/0x430 [ 110.237326][ T9070] ? __pfx_nfnetlink_rcv+0x10/0x10 [ 110.237340][ T9070] ? netlink_deliver_tap+0x1ae/0xd30 [ 110.237354][ T9070] netlink_unicast+0x53d/0x7f0 [ 110.237368][ T9070] ? __pfx_netlink_unicast+0x10/0x10 [ 110.237385][ T9070] netlink_sendmsg+0x8d1/0xdd0 [ 110.237400][ T9070] ? __pfx_netlink_sendmsg+0x10/0x10 [ 110.237418][ T9070] ____sys_sendmsg+0xa98/0xc70 [ 110.237432][ T9070] ? copy_msghdr_from_user+0x10a/0x160 [ 110.237460][ T9070] ? __pfx_____sys_sendmsg+0x10/0x10 [ 110.237476][ T9070] ? __pfx_futex_wake_mark+0x10/0x10 [ 110.237491][ T9070] ___sys_sendmsg+0x134/0x1d0 [ 110.237509][ T9070] ? __pfx____sys_sendmsg+0x10/0x10 [ 110.237525][ T9070] ? __lock_acquire+0x622/0x1c90 [ 110.237559][ T9070] __sys_sendmsg+0x16d/0x220 [ 110.237576][ T9070] ? __pfx___sys_sendmsg+0x10/0x10 [ 110.237593][ T9070] ? __x64_sys_futex+0x1e0/0x4c0 [ 110.237618][ T9070] do_syscall_64+0xcd/0x4c0 [ 110.237629][ T9070] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 110.237641][ T9070] RIP: 0033:0x7f61ce38e929 [ 110.237650][ T9070] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 110.237661][ T9070] RSP: 002b:00007f61cf1f6038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 110.237671][ T9070] RAX: ffffffffffffffda RBX: 00007f61ce5b5fa0 RCX: 00007f61ce38e929 [ 110.237678][ T9070] RDX: 0000000000000000 RSI: 0000200000000040 RDI: 0000000000000003 [ 110.237684][ T9070] RBP: 00007f61ce410b39 R08: 0000000000000000 R09: 0000000000000000 [ 110.237690][ T9070] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 110.237696][ T9070] R13: 0000000000000000 R14: 00007f61ce5b5fa0 R15: 00007fff4cd08398 [ 110.237710][ T9070] [ 110.237714][ T9070] Mem-Info: [ 110.358252][ T6111] usb 6-1: new high-speed USB device number 21 using dummy_hcd [ 110.358272][ T9070] active_anon:20232 inactive_anon:0 isolated_anon:0 [ 110.358272][ T9070] active_file:6920 inactive_file:50887 isolated_file:0 [ 110.358272][ T9070] unevictable:1768 dirty:67 writeback:0 [ 110.358272][ T9070] slab_reclaimable:12276 slab_unreclaimable:74082 [ 110.358272][ T9070] mapped:25113 shmem:2410 pagetables:1487 [ 110.358272][ T9070] sec_pagetables:305 bounce:0 [ 110.358272][ T9070] kernel_misc_reclaimable:0 [ 110.358272][ T9070] free:425832 free_pcp:13250 free_cma:0 [ 110.375559][ T9070] Node 0 active_anon:81052kB inactive_anon:0kB active_file:27588kB inactive_file:203348kB unevictable:3536kB isolated(anon):0kB isolated(file):0kB mapped:100360kB dirty:204kB writeback:0kB shmem:6104kB shmem_thp:0kB shmem_pmdmapped:0kB anon_thp:2048kB writeback_tmp:0kB kernel_stack:13776kB pagetables:5884kB sec_pagetables:1220kB all_unreclaimable? no Balloon:0kB [ 110.386682][ T9070] Node 1 active_anon:0kB inactive_anon:0kB active_file:92kB inactive_file:200kB unevictable:3536kB isolated(anon):0kB isolated(file):0kB mapped:92kB dirty:64kB writeback:0kB shmem:3536kB shmem_thp:0kB shmem_pmdmapped:0kB anon_thp:0kB writeback_tmp:0kB kernel_stack:144kB pagetables:188kB sec_pagetables:0kB all_unreclaimable? no Balloon:0kB [ 110.396192][ T9070] Node 0 DMA free:13288kB boost:0kB min:340kB low:424kB high:508kB reserved_highatomic:0KB free_highatomic:0KB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15360kB mlocked:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB [ 110.406004][ T9070] lowmem_reserve[]: 0 1235 1235 1235 1235 [ 110.408231][ T9070] Node 0 DMA32 free:92264kB boost:0kB min:27516kB low:34392kB high:41268kB reserved_highatomic:0KB free_highatomic:0KB active_anon:80928kB inactive_anon:0kB active_file:27588kB inactive_file:203348kB unevictable:3536kB writepending:204kB present:2080628kB managed:1264740kB mlocked:0kB bounce:0kB free_pcp:25764kB local_pcp:5604kB free_cma:0kB [ 110.419671][ T9070] lowmem_reserve[]: 0 0 0 0 0 [ 110.421484][ T9070] Node 1 Normal free:1596996kB boost:0kB min:39720kB low:49648kB high:59576kB reserved_highatomic:0KB free_highatomic:0KB active_anon:0kB inactive_anon:0kB active_file:92kB inactive_file:200kB unevictable:3536kB writepending:64kB present:2097152kB managed:1781948kB mlocked:0kB bounce:0kB free_pcp:28632kB local_pcp:5744kB free_cma:0kB [ 110.423733][ T9083] netlink: 8 bytes leftover after parsing attributes in process `syz.3.886'. [ 110.431192][ T9070] lowmem_reserve[]: 0 0 0 0 0 [ 110.431216][ T9070] Node 0 DMA: 2*4kB (U) 4*8kB (U) 4*16kB (U) 2*32kB (U) 3*64kB (U) 3*128kB (U) 3*256kB (U) 3*512kB (U) 2*1024kB (U) 4*2048kB (UM) 0*4096kB = 13288kB [ 110.431306][ T9070] Node 0 DMA32: 204*4kB (ME) 189*8kB (UME) 372*16kB (UME) 436*32kB (UME) 157*64kB (UME) 89*128kB (UME) 65*256kB (UME) 36*512kB (UME) 7*1024kB (UME) 3*2048kB (UM) 0*4096kB = 92056kB [ 110.431396][ T9070] Node 1 Normal: 18*4kB (UME) 40*8kB (UE) 64*16kB (UE) 120*32kB (UE) 29*64kB (UME) 15*128kB (UE) 7*256kB (UE) 4*512kB (UME) 5*1024kB (U) 1*2048kB (M) 385*4096kB (UM) = 1597000kB [ 110.431488][ T9070] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 110.431498][ T9070] Node 0 hugepages_total=2 hugepages_free=2 hugepages_surp=0 hugepages_size=2048kB [ 110.431506][ T9070] Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 110.463416][ T9070] Node 1 hugepages_total=2 hugepages_free=2 hugepages_surp=0 hugepages_size=2048kB [ 110.467866][ T9070] 60213 total pagecache pages [ 110.469422][ T9070] 0 pages in swap cache [ 110.470861][ T9070] Free swap = 124996kB [ 110.472174][ T9070] Total swap = 124996kB [ 110.473494][ T9070] 1048443 pages RAM [ 110.474796][ T9070] 0 pages HighMem/MovableOnly [ 110.476325][ T9070] 282931 pages reserved [ 110.477711][ T9070] 0 pages cma reserved [ 110.511840][ T9090] SELinux: unrecognized netlink message: protocol=4 nlmsg_type=108 sclass=netlink_tcpdiag_socket pid=9090 comm=syz.2.887 [ 110.531455][ T6111] usb 6-1: Using ep0 maxpacket: 32 [ 110.537534][ T6111] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 110.543242][ T6111] usb 6-1: New USB device found, idVendor=0f11, idProduct=1021, bcdDevice= 0.40 [ 110.547065][ T6111] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 110.553306][ T6111] usb 6-1: config 0 descriptor?? [ 110.559222][ T6111] ldusb 6-1:0.0: Interrupt out endpoint not found (using control endpoint instead) [ 110.567427][ T6111] ldusb 6-1:0.0: LD USB Device #0 now attached to major 180 minor 0 [ 110.793757][ T9104] i2c i2c-1: Invalid block write size 34 [ 110.797559][ C0] ldusb 6-1:0.0: Ring buffer overflow, 8 bytes dropped [ 111.052182][ T9119] pim6reg1: entered promiscuous mode [ 111.053995][ T9119] pim6reg1: entered allmulticast mode [ 111.147612][ T9122] ldusb 6-1:0.0: Read buffer overflow, 3 bytes dropped [ 111.151888][ C1] ldusb 6-1:0.0: Ring buffer overflow, 8 bytes dropped [ 111.479844][ T9152] openvswitch: netlink: Duplicate key (type 0). [ 111.574656][ T9160] IPv6: RTM_NEWROUTE with no NLM_F_CREATE or NLM_F_REPLACE [ 111.576938][ T9160] IPv6: NLM_F_CREATE should be set when creating new route [ 111.579309][ T9160] IPv6: NLM_F_CREATE should be set when creating new route [ 111.611073][ T6000] usb 8-1: new high-speed USB device number 4 using dummy_hcd [ 111.708413][ T9170] lo: entered allmulticast mode [ 111.712427][ T9169] lo: left allmulticast mode [ 111.782630][ T6000] usb 8-1: Using ep0 maxpacket: 8 [ 111.787933][ T6000] usb 8-1: config index 0 descriptor too short (expected 301, got 45) [ 111.790560][ T6000] usb 8-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 111.794058][ T6000] usb 8-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 0 [ 111.797197][ T6000] usb 8-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 111.800227][ T6000] usb 8-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 111.805603][ T6000] usb 8-1: New USB device found, idVendor=ee8d, idProduct=db1e, bcdDevice=61.23 [ 111.808640][ T6000] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 111.939640][ T9181] netlink: 'syz.2.918': attribute type 27 has an invalid length. [ 111.942010][ T9181] lo: left promiscuous mode [ 111.961221][ T9181] netdevsim netdevsim2 netdevsim0: left promiscuous mode [ 111.965314][ T9181] macsec1: left promiscuous mode [ 112.024797][ T9181] 8021q: adding VLAN 0 to HW filter on device bond0 [ 112.027736][ T9181] 8021q: adding VLAN 0 to HW filter on device team0 [ 112.030468][ T9181] batman_adv: batadv0: Interface activated: team0 [ 112.030509][ T6000] usb 8-1: GET_CAPABILITIES returned 0 [ 112.034456][ T6000] usbtmc 8-1:16.0: can't read capabilities [ 112.037148][ T9181] A link change request failed with some changes committed already. Interface caif0 may have been left with an inconsistent configuration, please check. [ 112.038809][ T7951] GRED: Unable to relocate VQ 0x0 after dequeue, screwing up backlog [ 112.070798][ T1460] GRED: Unable to relocate VQ 0x0 after dequeue, screwing up backlog [ 112.157207][ T1460] GRED: Unable to relocate VQ 0x0 after dequeue, screwing up backlog [ 112.162157][ T40] kauditd_printk_skb: 15 callbacks suppressed [ 112.162166][ T40] audit: type=1400 audit(110.735:603): avc: denied { bind } for pid=9190 comm="syz.2.921" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 112.163111][ T9192] netlink: 'syz.2.921': attribute type 12 has an invalid length. [ 112.185178][ T9192] SELinux: policydb string SE Linm does not match my string SE Linux [ 112.190646][ T9192] SELinux: failed to load policy [ 112.244962][ T1460] usb 8-1: USB disconnect, device number 4 [ 112.500986][ T1460] usb 6-1: USB disconnect, device number 21 [ 112.505709][ T1460] ldusb 6-1:0.0: LD USB Device #0 now disconnected [ 112.587010][ T40] audit: type=1400 audit(111.128:604): avc: denied { setopt } for pid=9204 comm="syz.1.924" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=phonet_socket permissive=1 [ 112.593832][ T9209] netlink: 'syz.2.925': attribute type 11 has an invalid length. [ 112.596414][ T9209] netlink: 'syz.2.925': attribute type 11 has an invalid length. [ 112.632657][ T40] audit: type=1400 audit(111.175:605): avc: denied { ioctl } for pid=9210 comm="syz.2.926" path="/dev/infiniband/rdma_cm" dev="devtmpfs" ino=1295 ioctlcmd=0x890c scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:infiniband_device_t tclass=chr_file permissive=1 [ 112.979555][ T5950] Bluetooth: hci4: command 0x1003 tx timeout [ 112.982688][ T5955] Bluetooth: hci4: Opcode 0x1003 failed: -110 [ 113.032270][ T40] audit: type=1400 audit(111.540:606): avc: denied { write } for pid=9217 comm="syz.3.929" name="file0" dev="tmpfs" ino=1246 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 113.042052][ T40] audit: type=1400 audit(111.540:607): avc: denied { open } for pid=9217 comm="syz.3.929" path="/233/file0" dev="tmpfs" ino=1246 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 113.174185][ T40] audit: type=1400 audit(111.680:608): avc: denied { create } for pid=9234 comm="syz.3.932" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 113.207072][ T40] audit: type=1400 audit(111.680:609): avc: denied { connect } for pid=9234 comm="syz.3.932" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 113.488501][ T9277] xt_l2tp: v2 tid > 0xffff: 150994944 [ 113.491663][ T9277] __nla_validate_parse: 10 callbacks suppressed [ 113.491672][ T9277] netlink: 28 bytes leftover after parsing attributes in process `syz.1.945'. [ 113.516088][ T6000] usb 8-1: new high-speed USB device number 5 using dummy_hcd [ 113.688345][ T6000] usb 8-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 113.692838][ T6000] usb 8-1: config 27 interface 0 altsetting 0 bulk endpoint 0xB has invalid maxpacket 47 [ 113.697075][ T6000] usb 8-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 113.700646][ T6000] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 113.705804][ T9248] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 113.711386][ T6000] usb 8-1: Quirk or no altset; falling back to MIDI 1.0 [ 113.927997][ T6000] usb 8-1: USB disconnect, device number 5 [ 114.126657][ T9305] netlink: 24 bytes leftover after parsing attributes in process `syz.2.952'. [ 114.236537][ T40] audit: type=1400 audit(112.672:610): avc: denied { listen } for pid=9310 comm="syz.3.954" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rose_socket permissive=1 [ 114.476003][ T40] audit: type=1400 audit(112.887:611): avc: denied { bind } for pid=9318 comm="syz.3.956" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=phonet_socket permissive=1 [ 114.519683][ T40] audit: type=1400 audit(112.934:612): avc: denied { read } for pid=9316 comm="syz.0.955" name="cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 114.524874][ T9331] IPv6: sit1: Disabled Multicast RS [ 114.529149][ T9331] sit1: entered allmulticast mode [ 114.562670][ T9336] netlink: 8 bytes leftover after parsing attributes in process `syz.1.962'. [ 114.565429][ T9338] netlink: 276 bytes leftover after parsing attributes in process `syz.0.961'. [ 114.566103][ T9336] netlink: 244 bytes leftover after parsing attributes in process `syz.1.962'. [ 114.612992][ T9340] xfrm0 speed is unknown, defaulting to 1000 [ 114.653421][ T9349] vlan3: entered promiscuous mode [ 114.655087][ T9349] veth1_virt_wifi: entered promiscuous mode [ 114.672407][ T9350] veth0_vlan: left promiscuous mode [ 114.674500][ T9350] veth0_vlan: entered promiscuous mode [ 114.719971][ T9359] tun0: tun_chr_ioctl cmd 1074025677 [ 114.721803][ T9359] tun0: linktype set to 257 [ 114.729244][ T9359] tun0: tun_chr_ioctl cmd 1074025675 [ 114.730915][ T9359] tun0: persist disabled [ 114.866272][ T9371] loop6: detected capacity change from 0 to 63 [ 114.895424][ T5940] Buffer I/O error on dev loop6, logical block 0, async page read [ 114.898524][ T5940] Buffer I/O error on dev loop6, logical block 0, async page read [ 114.901245][ T5940] Buffer I/O error on dev loop6, logical block 0, async page read [ 114.904377][ T5940] Buffer I/O error on dev loop6, logical block 0, async page read [ 114.912307][ T5940] Buffer I/O error on dev loop6, logical block 0, async page read [ 114.916256][ T5940] Buffer I/O error on dev loop6, logical block 0, async page read [ 114.919412][ T5940] Buffer I/O error on dev loop6, logical block 3, async page read [ 115.111035][ T9395] pimreg: entered allmulticast mode [ 115.115244][ T9395] binder: BC_ACQUIRE_RESULT not supported [ 115.117211][ T9395] binder: 9394:9395 ioctl c0306201 200000000100 returned -22 [ 115.121239][ T9395] netlink: 4 bytes leftover after parsing attributes in process `syz.1.978'. [ 115.124475][ T9395] netlink: 12 bytes leftover after parsing attributes in process `syz.1.978'. [ 115.160677][ T52] usb 5-1: new high-speed USB device number 11 using dummy_hcd [ 115.206194][ T9409] netlink: 8 bytes leftover after parsing attributes in process `syz.1.982'. [ 115.209248][ T9409] netlink: 4 bytes leftover after parsing attributes in process `syz.1.982'. [ 115.216189][ T9409] netdevsim netdevsim1 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 115.219219][ T9409] netdevsim netdevsim1 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 115.221903][ T9409] netdevsim netdevsim1 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 115.224656][ T9409] netdevsim netdevsim1 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 115.229502][ T9409] netlink: 8 bytes leftover after parsing attributes in process `syz.1.982'. [ 115.356665][ T52] usb 5-1: Using ep0 maxpacket: 32 [ 115.361442][ T52] usb 5-1: config 5 has an invalid interface number: 90 but max is 0 [ 115.365124][ T52] usb 5-1: config 5 contains an unexpected descriptor of type 0x1, skipping [ 115.368688][ T52] usb 5-1: config 5 has no interface number 0 [ 115.371093][ T52] usb 5-1: config 5 interface 90 altsetting 7 endpoint 0xE has invalid maxpacket 512, setting to 64 [ 115.375685][ T52] usb 5-1: config 5 interface 90 altsetting 7 bulk endpoint 0x1 has invalid maxpacket 536 [ 115.377807][ T9429] xfrm0 speed is unknown, defaulting to 1000 [ 115.379600][ T52] usb 5-1: config 5 interface 90 altsetting 7 endpoint 0x2 has invalid maxpacket 1024, setting to 64 [ 115.386608][ T52] usb 5-1: config 5 interface 90 altsetting 7 has a duplicate endpoint with address 0x3, skipping [ 115.390854][ T52] usb 5-1: config 5 interface 90 altsetting 7 has an endpoint descriptor with address 0x14, changing to 0x4 [ 115.394888][ T52] usb 5-1: config 5 interface 90 altsetting 7 endpoint 0x4 has invalid maxpacket 1024, setting to 64 [ 115.398523][ T52] usb 5-1: config 5 interface 90 altsetting 7 has an invalid descriptor for endpoint zero, skipping [ 115.401930][ T52] usb 5-1: config 5 interface 90 altsetting 7 has a duplicate endpoint with address 0x5, skipping [ 115.405304][ T52] usb 5-1: config 5 interface 90 altsetting 7 endpoint 0xF has invalid maxpacket 1023, setting to 64 [ 115.408745][ T52] usb 5-1: config 5 interface 90 altsetting 7 has a duplicate endpoint with address 0x5, skipping [ 115.412142][ T52] usb 5-1: config 5 interface 90 has no altsetting 0 [ 115.415904][ T52] usb 5-1: New USB device found, idVendor=050d, idProduct=1102, bcdDevice=9b.e5 [ 115.418939][ T52] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 115.421394][ T52] usb 5-1: Product: 쨼⟿祕킉쉂逩뤃ﱘ⟟㡖秳匊á•çŸê¬ ã­²á•°ëŽ…ä™Šè” á³†á‡¯é»ë¤ê˜¬í™’ﭥ윚츼ì§ì¸ºì€ƒì¥½é¹¥â†½é’¾ì– áº‚áŸëµ½Ó¢è¨‡è»…씜뽑ﮛ䱡ï„ëˆì°»à¡¢Úƒã‹á¢è’³â‘„絺鵓ᢢ꒼áƒé²–縘䟣犞✹耀竳巰ã­ï“闻⪔⿈ࢧ쩥䵊ä¦ì½”ࣜ廓骡蓲⺩ [ 115.429538][ T52] usb 5-1: Manufacturer: 髞í¸â …éŠé¯‡á—¢ê‘…å£å¹Žâ¨œî‚…䩲缈⳴梯堋꼤ꊕ㤶☠ⲓ騋è®è§£ê›ªâ§®ï±ì½«çž¥ë½˜ç¬‚ì´å…½à«‰à°‚ [ 115.434161][ T52] usb 5-1: SerialNumber: 忻㳜攆铵똚쟄뭋茔ã¢ì©±è³°ìœï——瓯藰⻔옱톌ç‚⩑鄯孬깸㳠솄퓾ᾒï£é†®å•¥ç’²âŸ¯æ¥­è…Žç´»è”²ì®¦ëƒŸë­Šæ£€ã£’좦곗Ñᷜ뾦ꎡ翾ۖ⤡伀巎閞é©ï²å£·æ«æ°°ã£„ቡㄞꀺ犛ୋ歈㩞퇰誮í¢é›†æš„넛峸ᧂ堢꿙ꗙ퓺 [ 115.444462][ T9381] raw-gadget.0 gadget.0: fail, usb_ep_enable returned -22 [ 115.463178][ T9442] 9pnet: Found fid 0 not clunked [ 115.478895][ T9444] xt_hashlimit: invalid rate [ 115.642116][ T9454] Invalid ELF header type: 0 != 1 [ 115.676108][ T9456] EXT4-fs: Value of option "test_dummy_encryption" is unrecognized [ 115.687772][ T52] usb 5-1: USB disconnect, device number 11 [ 115.762537][ T9461] bridge_slave_0: left allmulticast mode [ 115.764475][ T9461] bridge_slave_0: left promiscuous mode [ 115.766397][ T9461] bridge0: port 1(bridge_slave_0) entered disabled state [ 115.782205][ T9461] bridge_slave_1: left allmulticast mode [ 115.783975][ T9461] bridge_slave_1: left promiscuous mode [ 115.785800][ T9461] bridge0: port 2(bridge_slave_1) entered disabled state [ 115.795843][ T9461] bond0: (slave bond_slave_0): Releasing backup interface [ 115.800785][ T9461] bond0: (slave bond_slave_1): Releasing backup interface [ 115.823911][ T9461] team0: Port device team_slave_0 removed [ 115.832843][ T9461] team0: Port device team_slave_1 removed [ 115.838801][ T9461] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 115.841635][ T9461] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 115.846158][ T9461] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 115.848593][ T9461] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 115.856861][ T9461] bond0: (slave wlan1): Releasing backup interface [ 115.867369][ T9461] bond1: (slave ip6gretap1): Releasing active interface [ 115.869566][ T9461] ip6gretap1: left promiscuous mode [ 115.871254][ T9461] ip6gretap1: left allmulticast mode [ 115.876041][ T9461] bond2: (slave geneve2): Releasing active interface [ 115.878562][ T9461] bond2: (slave geneve2): the permanent HWaddr of slave - e2:83:69:92:8a:19 - is still in use by bond - set the HWaddr of slave to a different address to avoid conflicts [ 115.883813][ T9461] geneve2: left allmulticast mode [ 115.889862][ T9461] bond2: (slave veth3): Releasing active interface [ 116.101974][ T72] usb 7-1: new low-speed USB device number 13 using dummy_hcd [ 116.257472][ T9490] netlink: 'syz.0.1008': attribute type 3 has an invalid length. [ 116.299898][ T72] usb 7-1: config 0 has an invalid interface number: 1 but max is 0 [ 116.303061][ T72] usb 7-1: config 0 has no interface number 0 [ 116.305259][ T72] usb 7-1: config 0 interface 1 altsetting 0 endpoint 0x82 has an invalid bInterval 0, changing to 10 [ 116.315641][ T72] usb 7-1: config 0 interface 1 altsetting 0 endpoint 0x82 has invalid wMaxPacketSize 0 [ 116.319113][ T72] usb 7-1: New USB device found, idVendor=07c0, idProduct=1512, bcdDevice=30.22 [ 116.322744][ T72] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 116.329542][ T72] usb 7-1: config 0 descriptor?? [ 116.334024][ T72] iowarrior 7-1:0.1: IOWarrior product=0x1512, serial= interface=1 now attached to iowarrior0 [ 116.380034][ T9504] openvswitch: netlink: Either Ethernet header or EtherType is required. [ 116.426724][ T9518] macsec0: entered promiscuous mode [ 116.548292][ T9470] iowarrior 7-1:0.1: Error -90 while submitting URB [ 116.577731][ T9545] autofs: Bad value for 'fd' [ 116.818160][ T9568] sit0: entered promiscuous mode [ 116.824080][ T9568] netlink: 'syz.3.1028': attribute type 1 has an invalid length. [ 117.150691][ T9581] fuse: Unknown parameter 'fbö0x0000000000000003' [ 118.167859][ T9609] program syz.3.1039 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 118.246830][ T9614] netlink: 'syz.3.1040': attribute type 10 has an invalid length. [ 118.261345][ T9614] netlink: 'syz.3.1040': attribute type 1 has an invalid length. [ 118.572737][ T9629] netlink: 'syz.3.1045': attribute type 1 has an invalid length. [ 118.575257][ T9629] netlink: 'syz.3.1045': attribute type 2 has an invalid length. [ 118.701012][ T9637] fuse: Unknown parameter '' [ 119.130916][ T6111] usb 7-1: USB disconnect, device number 13 [ 119.160057][ T40] kauditd_printk_skb: 12 callbacks suppressed [ 119.160069][ T40] audit: type=1400 audit(117.283:625): avc: denied { name_connect } for pid=9639 comm="syz.2.1049" dest=32 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:reserved_port_t tclass=sctp_socket permissive=1 [ 119.537552][ T9646] Cannot find del_set index 85 as target [ 119.602107][ T40] audit: type=1400 audit(117.695:626): avc: denied { listen } for pid=9645 comm="syz.0.1051" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netrom_socket permissive=1 [ 119.811889][ T9670] set match dimension is over the limit! [ 119.867103][ T9677] 9pnet_virtio: no channels available for device syz [ 119.869399][ T9677] 9pnet_virtio: no channels available for device syz [ 119.872003][ T9677] 9pnet_virtio: no channels available for device syz [ 119.874958][ T9677] 9pnet_virtio: no channels available for device syz [ 119.877488][ T9677] 9pnet_virtio: no channels available for device syz [ 119.879857][ T9677] 9pnet_virtio: no channels available for device syz [ 119.882179][ T9677] 9pnet_virtio: no channels available for device syz [ 119.882845][ T9681] __nla_validate_parse: 10 callbacks suppressed [ 119.882855][ T9681] netlink: 144 bytes leftover after parsing attributes in process `syz.0.1061'. [ 119.884501][ T9677] 9pnet_virtio: no channels available for device syz [ 119.893648][ T9677] 9pnet_virtio: no channels available for device syz [ 119.906499][ T9677] 9pnet_virtio: no channels available for device syz [ 120.010850][ T9691] netlink: 212376 bytes leftover after parsing attributes in process `syz.3.1065'. [ 120.016976][ T9691] QAT: Stopping all acceleration devices. [ 120.076141][ T9693] trusted_key: encrypted_key: keylen for the ecryptfs format must be equal to 64 bytes [ 120.140472][ T9708] sctp: [Deprecated]: syz.1.1072 (pid 9708) Use of struct sctp_assoc_value in delayed_ack socket option. [ 120.140472][ T9708] Use struct sctp_sack_info instead [ 120.149562][ T40] audit: type=1400 audit(118.200:627): avc: denied { getopt } for pid=9705 comm="syz.2.1071" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=x25_socket permissive=1 [ 120.183142][ T9717] netlink: 16186 bytes leftover after parsing attributes in process `syz.1.1074'. [ 120.186482][ T9716] netlink: 16186 bytes leftover after parsing attributes in process `syz.1.1074'. [ 120.198316][ T9717] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=9717 comm=syz.1.1074 [ 120.355294][ T9733] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1075'. [ 120.488438][ T9740] netlink: 196 bytes leftover after parsing attributes in process `syz.0.1081'. [ 120.492261][ T9740] netlink: 196 bytes leftover after parsing attributes in process `syz.0.1081'. [ 120.496402][ T9740] netlink: 19 bytes leftover after parsing attributes in process `syz.0.1081'. [ 120.502835][ T9740] loop6: detected capacity change from 0 to 524287999 [ 120.511000][ T9740] netlink: 'syz.0.1081': attribute type 3 has an invalid length. [ 120.514307][ T9740] netlink: 12 bytes leftover after parsing attributes in process `syz.0.1081'. [ 120.525661][ T9740] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1081'. [ 120.695421][ T9743] pimreg: entered allmulticast mode [ 120.697827][ T9744] pimreg: left allmulticast mode [ 120.856154][ T9751] sch_tbf: burst 19872 is lower than device lo mtu (65550) ! [ 120.878457][ T9753] xt_l2tp: v2 doesn't support IP mode [ 120.895908][ T40] audit: type=1400 audit(118.901:628): avc: denied { unmount } for pid=5939 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cgroup_t tclass=filesystem permissive=1 [ 120.926079][ T9755] random: crng reseeded on system resumption [ 120.936151][ T9755] program syz.1.1086 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 121.572366][ T9792] (unnamed net_device) (uninitialized): option downdelay: invalid value (18446744073709551615) [ 121.576649][ T9792] (unnamed net_device) (uninitialized): option downdelay: allowed values 0 - 2147483647 [ 121.661289][ T8934] netdevsim netdevsim1 netdevsim3 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 121.664946][ T40] audit: type=1400 audit(119.622:629): avc: denied { execute } for pid=9793 comm="syz-executor" name="syz-executor" dev="sda1" ino=2020 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:etc_runtime_t tclass=file permissive=1 [ 121.664990][ T8934] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 121.673435][ T40] audit: type=1400 audit(119.622:630): avc: denied { execute_no_trans } for pid=9793 comm="syz-executor" path="/syz-executor" dev="sda1" ino=2020 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:etc_runtime_t tclass=file permissive=1 [ 121.767969][ T8934] netdevsim netdevsim1 netdevsim2 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 121.771486][ T8934] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 121.819237][ T5950] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 121.819816][ T40] audit: type=1400 audit(119.762:631): avc: denied { read } for pid=9801 comm="syz.0.1103" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_crypto_socket permissive=1 [ 121.824581][ T5950] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 121.833772][ T5950] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 121.837555][ T5950] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 121.846616][ T5950] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 121.868433][ T8934] netdevsim netdevsim1 netdevsim1 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 121.872719][ T8934] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 121.896698][ T9805] (unnamed net_device) (uninitialized): option active_slave: mode dependency failed, not supported in mode balance-rr(0) [ 121.929889][ T9802] xfrm0 speed is unknown, defaulting to 1000 [ 121.973349][ T8934] netdevsim netdevsim1 netdevsim0 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 121.977240][ T8934] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 122.057400][ T9802] chnl_net:caif_netlink_parms(): no params data found [ 122.151329][ T9817] 0·: renamed from hsr0 [ 122.155416][ T9817] 0·: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 122.159501][ T9817] 0·: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 122.169014][ T9817] 0·: entered allmulticast mode [ 122.172576][ T9817] hsr_slave_0: entered allmulticast mode [ 122.175416][ T9817] hsr_slave_1: entered allmulticast mode [ 122.179102][ T9817] A link change request failed with some changes committed already. Interface 70· may have been left with an inconsistent configuration, please check. [ 122.292967][ T8934] bond3 (unregistering): (slave ip6gretap1): Releasing backup interface [ 122.748464][ T8934] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 122.752237][ T8934] bond0 (unregistering): Released all slaves [ 122.759233][ T8934] bond1 (unregistering): Released all slaves [ 122.765534][ T8934] bond2 (unregistering): Released all slaves [ 122.771739][ T8934] bond3 (unregistering): Released all slaves [ 122.782830][ T6000] usb 5-1: new high-speed USB device number 12 using dummy_hcd [ 122.836207][ T8934] bond4 (unregistering): Released all slaves [ 122.842032][ T9802] bridge0: port 1(bridge_slave_0) entered blocking state [ 122.844383][ T9802] bridge0: port 1(bridge_slave_0) entered disabled state [ 122.846716][ T9802] bridge_slave_0: entered allmulticast mode [ 122.849513][ T9802] bridge_slave_0: entered promiscuous mode [ 122.852363][ T9] xfrm0 speed is unknown, defaulting to 1000 [ 122.854501][ T9] syz0: Port: 1 Link DOWN [ 122.855549][ T9802] bridge0: port 2(bridge_slave_1) entered blocking state [ 122.858397][ T9802] bridge0: port 2(bridge_slave_1) entered disabled state [ 122.860732][ T9802] bridge_slave_1: entered allmulticast mode [ 122.863654][ T9802] bridge_slave_1: entered promiscuous mode [ 122.893007][ T9802] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 122.897459][ T9802] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 122.937194][ T9802] team0: Port device team_slave_0 added [ 122.941445][ T9802] team0: Port device team_slave_1 added [ 122.943160][ T6000] usb 5-1: Using ep0 maxpacket: 8 [ 122.947044][ T6000] usb 5-1: config index 0 descriptor too short (expected 301, got 45) [ 122.950672][ T6000] usb 5-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 122.954917][ T6000] usb 5-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 0 [ 122.959095][ T6000] usb 5-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 122.963274][ T6000] usb 5-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 122.969265][ T6000] usb 5-1: New USB device found, idVendor=ee8d, idProduct=db1e, bcdDevice=61.23 [ 122.973141][ T6000] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 122.990815][ T9802] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 122.993892][ T9802] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 123.002856][ T9802] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 123.007077][ T9802] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 123.009351][ T9802] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 123.017232][ T9802] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 123.064530][ T9802] hsr_slave_0: entered promiscuous mode [ 123.066752][ T9802] hsr_slave_1: entered promiscuous mode [ 123.069212][ T9802] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 123.073514][ T9802] Cannot create hsr debugfs directory [ 123.196185][ T6000] usb 5-1: usb_control_msg returned -32 [ 123.198450][ T6000] usbtmc 5-1:16.0: can't read capabilities [ 123.230690][ T9844] Bluetooth: MGMT ver 1.23 [ 123.283633][ T9802] netdevsim netdevsim4 netdevsim0: renamed from eth0 [ 123.291245][ T9802] netdevsim netdevsim4 netdevsim1: renamed from eth1 [ 123.294431][ T9802] netdevsim netdevsim4 netdevsim2: renamed from eth2 [ 123.303589][ T9802] netdevsim netdevsim4 netdevsim3: renamed from eth3 [ 123.353177][ T9802] 8021q: adding VLAN 0 to HW filter on device bond0 [ 123.391629][ T9865] syzkaller1: entered promiscuous mode [ 123.393784][ T9865] syzkaller1: entered allmulticast mode [ 123.398603][ T9802] 8021q: adding VLAN 0 to HW filter on device team0 [ 123.407312][ T6913] bridge0: port 1(bridge_slave_0) entered blocking state [ 123.409613][ T6913] bridge0: port 1(bridge_slave_0) entered forwarding state [ 123.430872][ T1203] bridge0: port 2(bridge_slave_1) entered blocking state [ 123.433298][ T1203] bridge0: port 2(bridge_slave_1) entered forwarding state [ 123.460681][ T40] audit: type=1400 audit(121.305:632): avc: denied { sendto } for pid=73 comm="kworker/0:2" daddr=ff02::16 netif=wpan1 scontext=system_u:object_r:unlabeled_t tcontext=system_u:object_r:node_t tclass=node permissive=1 [ 123.504089][ T9802] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 123.632017][ T9802] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 123.686205][ T40] audit: type=1400 audit(121.511:633): avc: denied { read write } for pid=5941 comm="syz-executor" name="loop3" dev="devtmpfs" ino=661 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file permissive=1 [ 123.713671][ T40] audit: type=1400 audit(121.511:634): avc: denied { open } for pid=5941 comm="syz-executor" path="/dev/loop3" dev="devtmpfs" ino=661 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file permissive=1 [ 123.791495][ T6111] usb 5-1: USB disconnect, device number 12 [ 123.820997][ T9802] veth0_vlan: entered promiscuous mode [ 123.826274][ T9802] veth1_vlan: entered promiscuous mode [ 123.848621][ T9802] veth0_macvtap: entered promiscuous mode [ 123.855819][ T9802] veth1_macvtap: entered promiscuous mode [ 123.892796][ T9802] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 123.902326][ T9802] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 123.908150][ T9802] netdevsim netdevsim4 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 123.910966][ T9802] netdevsim netdevsim4 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 123.913742][ T9802] netdevsim netdevsim4 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 123.918703][ T9802] netdevsim netdevsim4 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 123.968352][ T9913] fuse: Unknown parameter '' [ 123.968735][ T6914] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 123.973444][ T6914] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 123.974075][ T9914] fuse: Unknown parameter '' [ 123.987795][ T6912] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 123.990623][ T6912] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 124.012840][ T5950] Bluetooth: hci0: command tx timeout [ 124.258707][ T9953] xt_hashlimit: size too large, truncated to 1048576 [ 124.263274][ T9956] qrtr: Invalid version 0 [ 124.286958][ T9960] tmpfs: Bad value for 'mpol' [ 124.477830][ T9989] No source specified [ 124.484073][ T9989] PKCS7: Unknown OID: [4] 5.25.43204.122 [ 124.486151][ T9989] PKCS7: Only support pkcs7_signedData type [ 124.585401][T10009] overlayfs: workdir and upperdir must reside under the same mount [ 124.632284][ T7951] usb 9-1: new high-speed USB device number 2 using dummy_hcd [ 124.663798][ T40] kauditd_printk_skb: 5 callbacks suppressed [ 124.663817][ T40] audit: type=1400 audit(122.418:640): avc: denied { setattr } for pid=10014 comm="syz.3.1144" name="UDP-Lite" dev="sockfs" ino=32630 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rawip_socket permissive=1 [ 124.781445][ T40] audit: type=1400 audit(122.531:641): avc: denied { setopt } for pid=10018 comm="syz.3.1145" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=isdn_socket permissive=1 [ 124.793387][ T7951] usb 9-1: Using ep0 maxpacket: 8 [ 124.796552][ T7951] usb 9-1: config index 0 descriptor too short (expected 1563, got 27) [ 124.799139][ T7951] usb 9-1: config 2 interface 0 altsetting 8 endpoint 0x9 has an invalid bInterval 233, changing to 7 [ 124.802755][ T7951] usb 9-1: config 2 interface 0 has no altsetting 0 [ 124.808071][ T7951] usb 9-1: New USB device found, idVendor=04e2, idProduct=1412, bcdDevice=ca.10 [ 124.811175][ T7951] usb 9-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 124.813748][ T7951] usb 9-1: Product: syz [ 124.815220][ T7951] usb 9-1: Manufacturer: syz [ 124.816655][ T7951] usb 9-1: SerialNumber: syz [ 124.845436][T10032] vimc link validate: Scaler:src:640x480 (0x33424752, 8, 0, 0, 0) RGB/YUV Capture:snk:640x480 (0x33424752, 8, 0, 0, 0) [ 124.863141][T10018] delete_channel: no stack [ 124.991985][T10045] program syz.3.1149 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 125.035824][ T9964] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 125.038951][ T9964] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 125.043154][ T9964] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 125.046440][ T9964] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 125.048240][T10049] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=10049 comm=syz.0.1151 [ 125.051837][ T9964] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 125.055966][ T9964] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 125.058298][T10049] netlink: 'syz.0.1151': attribute type 8 has an invalid length. [ 125.060668][ T9964] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 125.064712][ T9964] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 125.065267][T10049] bridge0: port 1(bridge_slave_0) entered disabled state [ 125.068498][ T9964] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 125.075107][ T9964] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 125.084665][T10049] bridge0: entered allmulticast mode [ 125.099892][ T7951] usb 9-1: USB disconnect, device number 2 [ 125.179068][ T40] audit: type=1400 audit(122.914:642): avc: denied { node_bind } for pid=10056 comm="syz.0.1155" saddr=::1 src=20003 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=sctp_socket permissive=1 [ 125.235916][ T40] audit: type=1400 audit(122.961:643): avc: denied { ioctl } for pid=10062 comm="syz.0.1157" path="socket:[32657]" dev="sockfs" ino=32657 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rxrpc_socket permissive=1 [ 125.246489][T10063] __nla_validate_parse: 6 callbacks suppressed [ 125.246504][T10063] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1157'. [ 125.253473][T10063] netlink: 24 bytes leftover after parsing attributes in process `syz.0.1157'. [ 125.387475][T10072] sctp: [Deprecated]: syz.0.1159 (pid 10072) Use of struct sctp_assoc_value in delayed_ack socket option. [ 125.387475][T10072] Use struct sctp_sack_info instead [ 125.393752][T10072] openvswitch: netlink: IP tunnel attribute has 20 unknown bytes. [ 125.735365][T10094] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(3) [ 125.738129][T10094] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 125.742452][T10094] vhci_hcd vhci_hcd.0: Device attached [ 125.841378][T10095] vhci_hcd: connection closed [ 125.841584][ T6914] vhci_hcd: stop threads [ 125.850955][ T6914] vhci_hcd: release socket [ 125.852505][ T6914] vhci_hcd: disconnect device [ 126.238377][ T5950] Bluetooth: hci0: command tx timeout [ 126.253915][T10108] ptrace attach of "/syz-executor exec"[9802] was attempted by "/syz-executor exec"[10108] [ 126.296623][T10113] netlink: 'syz.3.1168': attribute type 3 has an invalid length. [ 126.537321][T10133] netlink: 'syz.4.1174': attribute type 27 has an invalid length. [ 126.570657][T10137] netlink: 'syz.0.1176': attribute type 17 has an invalid length. [ 126.573988][T10137] netlink: 5 bytes leftover after parsing attributes in process `syz.0.1176'. [ 126.581503][T10133] bridge0: port 2(bridge_slave_1) entered disabled state [ 126.584985][T10133] bridge0: port 1(bridge_slave_0) entered disabled state [ 126.642972][T10133] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 126.647985][T10143] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=2306 sclass=netlink_route_socket pid=10143 comm=syz.4.1174 [ 126.649398][T10133] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 126.702767][T10133] netdevsim netdevsim4 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 126.706549][T10133] netdevsim netdevsim4 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 126.710323][T10133] netdevsim netdevsim4 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 126.714027][T10133] netdevsim netdevsim4 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 126.741192][T10137] macvtap0: entered allmulticast mode [ 126.748975][T10137] veth0_macvtap: entered allmulticast mode [ 126.751245][T10137] A link change request failed with some changes committed already. Interface macvtap0 may have been left with an inconsistent configuration, please check. [ 126.771922][T10138] 8021q: adding VLAN 0 to HW filter on device bond0 [ 126.774807][T10138] 8021q: adding VLAN 0 to HW filter on device team0 [ 126.779660][T10138] A link change request failed with some changes committed already. Interface caif0 may have been left with an inconsistent configuration, please check. [ 126.801251][T10149] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1180'. [ 126.806082][T10149] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1180'. [ 126.821019][T10149] xt_hashlimit: size too large, truncated to 1048576 [ 126.862424][T10158] NILFS (nullb0): couldn't find nilfs on the device [ 126.942597][T10166] netlink: 'syz.2.1186': attribute type 13 has an invalid length. [ 126.956322][T10166] gretap0: refused to change device tx_queue_len [ 126.958432][T10166] A link change request failed with some changes committed already. Interface gretap0 may have been left with an inconsistent configuration, please check. [ 127.068807][T10180] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1189'. [ 127.092129][ T40] audit: type=1400 audit(124.692:644): avc: denied { ioctl } for pid=10183 comm="syz.2.1191" path="socket:[32749]" dev="sockfs" ino=32749 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 127.097661][T10189] /dev/nullb0: Can't open blockdev [ 127.100058][ T40] audit: type=1400 audit(124.692:645): avc: denied { connect } for pid=10178 comm="syz.3.1189" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 127.130117][T10193] 9pnet_fd: p9_fd_create_unix (10193): address too long: ./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa [ 127.193391][T10201] [U] vÔ3¸Âfù¾"SçÁ/Éê4:ÃXTz“W¡t‘’lWµ«= [ 127.237125][T10201] [U] J"—e:ÀÆ" [ 127.267096][T10208] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=35 sclass=netlink_route_socket pid=10208 comm=syz.3.1198 [ 127.444027][T10217] kvm: MWAIT instruction emulated as NOP! [ 127.446627][T10217] netlink: 8 bytes leftover after parsing attributes in process `syz.4.1201'. [ 127.447873][T10224] netlink: 'syz.3.1204': attribute type 1 has an invalid length. [ 127.457454][T10224] netlink: 224 bytes leftover after parsing attributes in process `syz.3.1204'. [ 127.461563][T10223] netlink: 'syz.0.1203': attribute type 12 has an invalid length. [ 127.468382][T10223] netlink: 'syz.0.1203': attribute type 29 has an invalid length. [ 127.471832][T10223] netlink: 148 bytes leftover after parsing attributes in process `syz.0.1203'. [ 127.657090][T10241] netlink: 'syz.4.1207': attribute type 1 has an invalid length. [ 127.665692][T10241] netlink: 160 bytes leftover after parsing attributes in process `syz.4.1207'. [ 128.427433][ T1460] usb 7-1: new high-speed USB device number 14 using dummy_hcd [ 128.462184][ T5950] Bluetooth: hci0: command tx timeout [ 128.611145][ T1460] usb 7-1: config 1 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 18 [ 128.620252][ T1460] usb 7-1: New USB device found, idVendor=0525, idProduct=a4a1, bcdDevice= 0.40 [ 128.623180][ T1460] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=1 [ 128.625685][ T1460] usb 7-1: SerialNumber: syz [ 129.183263][T10310] fanotify: failed to encode fid (type=0, len=0, err=-2) [ 129.383945][ T1460] cdc_ether 7-1:1.0: probe with driver cdc_ether failed with error -71 [ 129.388369][ T1460] usb 7-1: USB disconnect, device number 14 [ 130.003310][ T40] audit: type=1400 audit(127.423:646): avc: denied { relabelfrom } for pid=10349 comm="syz.2.1237" name="" dev="pipefs" ino=34564 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=fifo_file permissive=1 [ 130.118895][ T40] audit: type=1400 audit(127.526:647): avc: denied { accept } for pid=10351 comm="syz.2.1238" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netrom_socket permissive=1 [ 130.257107][ T40] audit: type=1400 audit(127.657:648): avc: denied { read } for pid=10363 comm="syz.4.1240" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=qipcrtr_socket permissive=1 [ 130.263124][ T40] audit: type=1400 audit(127.657:649): avc: denied { create } for pid=10363 comm="syz.4.1240" name="file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:unlabeled_t tclass=lnk_file permissive=1 [ 130.683244][ T5950] Bluetooth: hci0: command tx timeout [ 130.961971][ T40] audit: type=1400 audit(128.321:650): avc: denied { write } for pid=10373 comm="syz.3.1241" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 131.148556][ T40] audit: type=1400 audit(128.489:651): avc: denied { kexec_image_load } for pid=10390 comm="syz.3.1246" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=system permissive=1 [ 131.232425][ T40] audit: type=1400 audit(128.573:652): avc: denied { rename } for pid=10396 comm="syz.4.1247" name="#27" dev="tmpfs" ino=175 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 131.312276][T10402] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=10402 comm=syz.4.1248 [ 131.377471][T10406] tmpfs: Bad value for 'gid' [ 131.379678][T10406] tmpfs: Bad value for 'gid' [ 131.493614][ T40] audit: type=1400 audit(128.807:653): avc: denied { ioctl } for pid=10416 comm="syz.3.1251" path="socket:[36104]" dev="sockfs" ino=36104 ioctlcmd=0x5006 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 131.504385][T10412] can0: slcan on ttyS3. [ 131.562603][T10412] can0 (unregistered): slcan off ttyS3. [ 131.790500][T10448] can0: slcan on ttyS3. [ 131.826271][T10450] __nla_validate_parse: 1 callbacks suppressed [ 131.826286][T10450] netlink: 32 bytes leftover after parsing attributes in process `syz.4.1261'. [ 131.848740][T10448] can0 (unregistered): slcan off ttyS3. [ 131.941154][ T40] audit: type=1400 audit(129.228:654): avc: denied { nlmsg_write } for pid=10456 comm="syz.4.1262" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_audit_socket permissive=1 [ 132.070733][T10471] netlink: 480 bytes leftover after parsing attributes in process `syz.4.1265'. [ 132.076606][T10471] netlink: 128 bytes leftover after parsing attributes in process `syz.4.1265'. [ 132.082496][ T40] audit: type=1400 audit(129.359:655): avc: denied { getopt } for pid=10470 comm="syz.4.1265" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 132.192914][T10479] netlink: 40 bytes leftover after parsing attributes in process `syz.2.1266'. [ 132.202988][ T40] audit: type=1400 audit(129.481:656): avc: denied { setopt } for pid=10478 comm="syz.2.1266" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 132.321633][T10492] binder: 10491:10492 ioctl c0306201 200000000640 returned -22 [ 132.326150][T10492] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1269'. [ 132.331035][T10492] openvswitch: netlink: nsh attribute has 2338 unknown bytes. [ 132.334217][T10492] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 132.340242][ T9] usb 9-1: new low-speed USB device number 3 using dummy_hcd [ 132.490171][ T9] usb 9-1: device descriptor read/64, error -71 [ 132.506546][T10508] netlink: 16 bytes leftover after parsing attributes in process `syz.2.1272'. [ 132.510404][T10508] netlink: 32 bytes leftover after parsing attributes in process `syz.2.1272'. [ 132.749266][ T9] usb 9-1: new low-speed USB device number 4 using dummy_hcd [ 132.888929][ T9] usb 9-1: device descriptor read/64, error -71 [ 133.003282][ T9] usb usb9-port1: attempt power cycle [ 133.369503][ T9] usb 9-1: new low-speed USB device number 5 using dummy_hcd [ 133.389573][ T9] usb 9-1: device descriptor read/8, error -71 [ 133.645720][ T9] usb 9-1: new low-speed USB device number 6 using dummy_hcd [ 133.666230][ T9] usb 9-1: device descriptor read/8, error -71 [ 133.766482][T10552] overlayfs: missing 'lowerdir' [ 133.786586][ T9] usb usb9-port1: unable to enumerate USB device [ 133.811295][T10568] xt_l2tp: missing protocol rule (udp|l2tpip) [ 133.864611][T10576] netlink: 40 bytes leftover after parsing attributes in process `syz.0.1280'. [ 133.998999][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.002049][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.004573][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.007124][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.010099][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.012598][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.015490][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.018100][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.021505][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.024992][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.027570][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.030339][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.032859][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.035354][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.039123][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.042498][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.045023][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.047490][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.050005][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.053071][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.055594][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.058216][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.060700][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.063469][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.065966][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.068490][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.070928][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.073475][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.075980][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.078543][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.081020][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.084459][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.087917][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.090505][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.093126][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.095712][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.098456][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.100948][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.103579][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.106398][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.109080][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.111712][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.114255][ T72] hid-generic 0000:0000:20000000.0002: unknown main item tag 0x0 [ 134.123257][ T72] hid-generic 0000:0000:20000000.0002: hidraw1: HID v0.01 Device [syz0] on syz1 [ 134.161304][T10606] fido_id[10606]: Failed to open report descriptor at '/sys/devices/virtual/misc/uhid/report_descriptor': No such file or directory [ 134.214924][T10614] netlink: 4 bytes leftover after parsing attributes in process `syz.2.1297'. [ 134.944034][T10632] team0: entered allmulticast mode [ 134.946200][T10632] team_slave_0: entered allmulticast mode [ 134.949907][T10632] team_slave_1: entered allmulticast mode [ 135.102762][T10614] ceph: No mds server is up or the cluster is laggy [ 135.305850][T10650] x_tables: duplicate underflow at hook 1 [ 135.644137][ T1460] usb 7-1: new high-speed USB device number 15 using dummy_hcd [ 135.807186][ T1460] usb 7-1: New USB device found, idVendor=0cf3, idProduct=9271, bcdDevice= 1.08 [ 135.810200][ T1460] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 135.812909][ T1460] usb 7-1: Product: syz [ 135.814267][ T1460] usb 7-1: Manufacturer: syz [ 135.816344][ T1460] usb 7-1: SerialNumber: syz [ 135.821786][ T1460] usb 7-1: ath9k_htc: Firmware ath9k_htc/htc_9271-1.4.0.fw requested [ 135.844384][ T5565] usb 7-1: ath9k_htc: Transferred FW: ath9k_htc/htc_9271-1.4.0.fw, size: 51008 [ 136.094351][ T1460] usb 7-1: USB disconnect, device number 15 [ 136.204566][T10684] use of bytesused == 0 is deprecated and will be removed in the future, [ 136.216348][T10684] use the actual size instead. [ 136.275195][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.277724][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.285939][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.288318][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.290638][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.292974][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.296349][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.298724][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.301121][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.303558][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.306001][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.309552][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.311903][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.314206][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.316584][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.319013][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.321391][ T9] hid-generic 0002:0004:0009.0003: unknown main item tag 0x0 [ 136.331188][ T9] hid-generic 0002:0004:0009.0003: hidraw1: HID v0.04 Device [syz0] on syz0 [ 136.361322][T10715] fido_id[10715]: Failed to open report descriptor at '/sys/devices/virtual/misc/uhid/report_descriptor': No such file or directory [ 136.429945][ T1425] ieee802154 phy0 wpan0: encryption failed: -22 [ 136.432110][ T1425] ieee802154 phy1 wpan1: encryption failed: -22 [ 136.458467][T10691] netdevsim netdevsim3 eth0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.463604][T10691] netdevsim netdevsim3 eth1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.466221][T10691] netdevsim netdevsim3 eth2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.472212][T10691] netdevsim netdevsim3 eth3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.529534][ T40] kauditd_printk_skb: 7 callbacks suppressed [ 136.529549][ T40] audit: type=1400 audit(133.522:664): avc: denied { create } for pid=10729 comm="syz.4.1324" name="file0" scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=blk_file permissive=1 [ 136.562502][ T40] audit: type=1400 audit(133.550:665): avc: denied { unlink } for pid=9802 comm="syz-executor" name="file0" dev="tmpfs" ino=263 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=blk_file permissive=1 [ 136.599153][T10738] netlink: 8 bytes leftover after parsing attributes in process `syz.4.1326'. [ 136.609403][T10738] macsec1: entered promiscuous mode [ 136.672511][T10745] mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium [ 136.783155][T10763] netlink: 'syz.0.1331': attribute type 7 has an invalid length. [ 136.926378][ T5565] ath9k_htc 7-1:1.0: ath9k_htc: Target is unresponsive [ 136.929164][ T5565] ath9k_htc: Failed to initialize the device [ 136.932841][ T1460] usb 7-1: ath9k_htc: USB layer deinitialized [ 137.327269][T10788] __nla_validate_parse: 1 callbacks suppressed [ 137.327280][T10788] netlink: 144 bytes leftover after parsing attributes in process `syz.4.1335'. [ 137.398925][T10792] netlink: 72 bytes leftover after parsing attributes in process `syz.4.1337'. [ 137.459561][ T40] audit: type=1400 audit(134.392:666): avc: denied { mounton } for pid=10791 comm="syz.4.1337" path="mnt:[4026532879]" dev="nsfs" ino=4026532879 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nsfs_t tclass=file permissive=1 [ 137.515028][ T72] e1000: eth0 NIC Link is Up 1000 Mbps Full Duplex, Flow Control: None [ 137.538176][ T40] audit: type=1400 audit(134.476:667): avc: denied { getopt } for pid=10794 comm="syz.4.1338" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 137.619640][T10798] netlink: 40 bytes leftover after parsing attributes in process `syz.4.1339'. [ 137.777034][ T40] audit: type=1326 audit(134.691:668): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=10812 comm="syz.4.1342" exe="/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7f3630b8e929 code=0x0 [ 138.555259][T10841] IPv6: NLM_F_CREATE should be specified when creating new route [ 138.558989][T10841] IPv6: Can't replace route, no match found [ 138.730596][T10848] netlink: 256 bytes leftover after parsing attributes in process `syz.4.1349'. [ 138.769034][T10850] netlink: 4 bytes leftover after parsing attributes in process `syz.4.1350'. [ 139.052980][T10859] vhci_hcd vhci_hcd.0: pdev(4) rhport(0) sockfd(8) [ 139.055533][T10859] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 139.059835][T10859] vhci_hcd vhci_hcd.0: Device attached [ 139.106429][T10860] vhci_hcd: connection closed [ 139.106668][ T1203] vhci_hcd: stop threads [ 139.112686][ T1203] vhci_hcd: release socket [ 139.114447][ T1203] vhci_hcd: disconnect device [ 139.541192][T10869] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1357'. [ 139.545078][T10869] netlink: 12 bytes leftover after parsing attributes in process `syz.0.1357'. [ 139.548059][T10869] netlink: 'syz.0.1357': attribute type 12 has an invalid length. [ 139.853804][ T40] audit: type=1400 audit(136.627:669): avc: denied { accept } for pid=10886 comm="syz.0.1361" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=x25_socket permissive=1 [ 139.928610][T10896] dlm: no local IP address has been set [ 139.931977][T10896] dlm: cannot start dlm midcomms -107 [ 140.002652][T10903] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1367'. [ 140.056469][T10906] netlink: 48 bytes leftover after parsing attributes in process `syz.2.1368'. [ 140.095246][T10906] Cannot find del_set index 16 as target [ 140.159092][T10919] IPv6: syztnl0: Disabled Multicast RS [ 140.438762][T10945] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1379'. [ 140.458729][ T73] IPVS: starting estimator thread 0... [ 140.474900][ T40] audit: type=1400 audit(137.207:670): avc: denied { read } for pid=10948 comm="syz.0.1380" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 140.557206][ T40] audit: type=1400 audit(137.291:671): avc: denied { connect } for pid=10955 comm="syz.0.1382" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 140.572158][T10947] IPVS: using max 45 ests per chain, 108000 per kthread [ 140.595528][T10962] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(3) [ 140.598326][T10962] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 140.603354][T10962] vhci_hcd vhci_hcd.0: Device attached [ 140.618886][T10962] vhci_hcd vhci_hcd.0: pdev(0) rhport(1) sockfd(5) [ 140.621688][T10962] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 140.624846][T10962] vhci_hcd vhci_hcd.0: Device attached [ 140.631776][T10966] vhci_hcd: connection closed [ 140.631921][ T1203] vhci_hcd: stop threads [ 140.635397][ T1203] vhci_hcd: release socket [ 140.636231][T10964] vhci_hcd: connection closed [ 140.638327][ T1203] vhci_hcd: disconnect device [ 140.641484][ T1203] vhci_hcd: stop threads [ 140.642853][ T1203] vhci_hcd: release socket [ 140.644386][ T1203] vhci_hcd: disconnect device [ 141.125072][T10976] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 141.248960][T10988] binder: 10987:10988 ioctl c0046209 100000000000000 returned -22 [ 141.386836][T10991] syz.0.1387: attempt to access beyond end of device [ 141.386836][T10991] nbd0: rw=4096, sector=0, nr_sectors = 2 limit=0 [ 141.401594][T10991] XFS (nbd0): SB validate failed with error -5. [ 141.436382][ T40] audit: type=1326 audit(138.115:672): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=10987 comm="syz.4.1388" exe="/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3630b8e929 code=0x7fc00000 [ 141.448159][ T40] audit: type=1326 audit(138.115:673): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=10987 comm="syz.4.1388" exe="/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f3630b8e929 code=0x7fc00000 [ 141.572488][T11009] --map-set only usable from mangle table [ 141.639778][T11015] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=11015 comm=syz.2.1393 [ 141.727080][T11024] loop2: detected capacity change from 0 to 7 [ 141.744125][T11030] Cannot find add_set index 0 as target [ 141.747745][ T5940] loop2: [CUMANA/ADFS] p1 [ADFS] p1 [ 141.749607][ T5940] loop2: partition table partially beyond EOD, truncated [ 141.751908][ T5940] loop2: p1 size 2989602745 extends beyond EOD, truncated [ 141.764206][T11024] loop2: [CUMANA/ADFS] p1 [ADFS] p1 [ 141.765904][T11024] loop2: partition table partially beyond EOD, truncated [ 141.773615][T11024] loop2: p1 size 2989602745 extends beyond EOD, truncated [ 141.778909][ T5352] udevd[5352]: worker [5940] terminated by signal 33 (Unknown signal 33) [ 141.781704][ T5352] udevd[5352]: worker [5940] failed while handling '/devices/virtual/block/loop2' [ 141.800040][ T6702] udevd[6702]: inotify_add_watch(7, /dev/loop2p1, 10) failed: No such file or directory [ 141.820128][ T6702] udevd[6702]: inotify_add_watch(7, /dev/loop2p1, 10) failed: No such file or directory [ 141.986305][ T40] kauditd_printk_skb: 1273 callbacks suppressed [ 141.986320][ T40] audit: type=1400 audit(138.629:1947): avc: denied { append } for pid=11058 comm="syz.4.1410" name="pmem0" dev="devtmpfs" ino=710 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file permissive=1 [ 142.007591][ T5352] udevd[5352]: worker [6702] terminated by signal 33 (Unknown signal 33) [ 142.008167][T11062] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 142.010294][ T5352] udevd[5352]: worker [6702] failed while handling '/devices/LNXSYSTM:00/LNXSYBUS:00/ACPI0012:00/ndbus0/region0/namespace0.0/block/pmem0/pmem0p12' [ 142.020012][T11062] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 142.025614][T11063] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 142.037791][T11063] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 142.211259][T11076] netlink: 'syz.3.1417': attribute type 29 has an invalid length. [ 142.251742][ T40] audit: type=1400 audit(138.882:1948): avc: denied { write } for pid=11079 comm="syz.0.1419" name="/" dev="9p" ino=36047789 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=dir permissive=1 [ 142.317580][T11089] 9pnet_virtio: no channels available for device syz [ 142.405426][T11095] ip6gretap1: entered promiscuous mode [ 142.407256][T11095] ip6gretap1: entered allmulticast mode [ 142.505916][T11097] input: syz1 as /devices/virtual/input/input18 [ 142.679933][T11117] netlink: 'syz.3.1426': attribute type 2 has an invalid length. [ 142.681373][ T12] Bluetooth: hci5: Frame reassembly failed (-84) [ 142.682516][T11117] __nla_validate_parse: 5 callbacks suppressed [ 142.682524][T11117] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1426'. [ 142.871899][ T40] audit: type=1400 audit(139.461:1949): avc: denied { getopt } for pid=11122 comm="syz.0.1429" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 142.873631][T11123] fuse: Bad value for 'user_id' [ 142.880076][T11123] fuse: Bad value for 'user_id' [ 143.048209][T11126] tmpfs: Bad value for 'mpol' [ 143.129586][ T40] audit: type=1400 audit(139.705:1950): avc: denied { create } for pid=11135 comm="syz.0.1433" name="file0" scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:unlabeled_t tclass=dir permissive=1 [ 143.129711][T11137] o2cb: This node has not been configured. [ 143.140733][T11137] o2cb: Cluster check failed. Fix errors before retrying. [ 143.142808][T11137] (syz.0.1433,11137,2):user_dlm_register:674 ERROR: status = -22 [ 143.145307][T11137] (syz.0.1433,11137,2):dlmfs_mkdir:437 ERROR: Error -22 could not register domain "file0" [ 143.252980][T11143] kvm: vcpu 1: requested lapic timer restore with starting count register 0x390=1812281087 (231971979136 ns) > initial count (128 ns). Using initial count to start timer. [ 143.261711][ T40] audit: type=1326 audit(139.817:1951): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11144 comm="syz.2.1436" exe="/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f61ce38e929 code=0x7ffc0000 [ 143.268937][ T40] audit: type=1326 audit(139.817:1952): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11144 comm="syz.2.1436" exe="/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f61ce38e929 code=0x7ffc0000 [ 143.270747][T11145] loop6: detected capacity change from 0 to 7 [ 143.276004][ T40] audit: type=1326 audit(139.817:1953): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11144 comm="syz.2.1436" exe="/syz-executor" sig=0 arch=c000003e syscall=13 compat=0 ip=0x7f61ce38e929 code=0x7ffc0000 [ 143.281505][T11145] Dev loop6: unable to read RDB block 7 [ 143.286023][ T40] audit: type=1326 audit(139.817:1954): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11144 comm="syz.2.1436" exe="/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f61ce38e929 code=0x7ffc0000 [ 143.288934][T11145] loop6: unable to read partition table [ 143.294981][ T40] audit: type=1326 audit(139.817:1955): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11144 comm="syz.2.1436" exe="/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f61ce38e929 code=0x7ffc0000 [ 143.296586][T11145] loop6: partition table beyond EOD, [ 143.303837][ T40] audit: type=1326 audit(139.817:1956): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11144 comm="syz.2.1436" exe="/syz-executor" sig=0 arch=c000003e syscall=319 compat=0 ip=0x7f61ce38e929 code=0x7ffc0000 [ 143.305084][T11145] truncated [ 143.314750][T11145] loop_reread_partitions: partition scan of loop6 (þ被xü—ŸÑà– ) failed (rc=-5) [ 143.448369][T11149] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1438'. [ 143.452475][T11149] binder: 11148:11149 ioctl c0306201 200000000640 returned -22 [ 143.454951][T11149] binder: 11148:11149 ioctl ae01 0 returned -22 [ 144.196125][ T5950] Bluetooth: hci4: Opcode 0x1003 failed: -110 [ 144.199066][ T5945] Bluetooth: hci4: command 0x1003 tx timeout [ 144.221279][T11195] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1451'. [ 144.224534][T11060] sp0: Synchronizing with TNC [ 144.316696][T11201] block device autoloading is deprecated and will be removed. [ 144.320658][T11201] syz.0.1453: attempt to access beyond end of device [ 144.320658][T11201] md0: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 144.858621][T11215] program syz.4.1457 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 144.880241][ T5955] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 144.965411][T11222] openvswitch: netlink: Tunnel attr 16370 out of range max 16 [ 145.004421][T11225] netlink: 68 bytes leftover after parsing attributes in process `syz.3.1460'. [ 145.011401][T11225] fuse: Bad value for 'fd' [ 145.228814][T11236] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1465'. [ 145.241306][T11238] netdevsim netdevsim0 netdevsim1: Unsupported IPsec algorithm [ 145.284231][T11244] syz.0.1468: attempt to access beyond end of device [ 145.284231][T11244] loop0: rw=0, sector=1, nr_sectors = 1 limit=0 [ 145.289253][T11244] qnx4: unable to read the superblock [ 145.350581][ T52] usb 9-1: new low-speed USB device number 7 using dummy_hcd [ 145.511122][ T52] usb 9-1: Invalid ep0 maxpacket: 64 [ 145.588643][T11265] Oops: general protection fault, probably for non-canonical address 0xdffffc000000005f: 0000 [#1] SMP KASAN NOPTI SYZFAIL: failed to recv rpc fd=3 want=4 recv=0 n=0 (errno 9: Bad file descriptor) [ 145.593448][T11265] KASAN: null-ptr-deref in range [0x00000000000002f8-0x00000000000002ff] [ 145.597433][T11265] CPU: 0 UID: 0 PID: 11265 Comm: syz.3.1474 Not tainted 6.15.0-syzkaller-13655-gbdc7f8c5adad #0 PREEMPT(full) [ 145.602621][T11265] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 [ 145.606820][T11265] RIP: 0010:h5_recv+0x104/0x910 [ 145.608830][T11265] Code: c1 e8 03 4c 01 f0 48 89 44 24 08 48 8d 83 08 03 00 00 48 89 44 24 30 48 c1 e8 03 48 89 44 24 10 e8 21 74 4e f9 48 8b 44 24 08 <80> 38 00 0f 85 ae 01 00 00 48 89 ea 48 89 e9 4c 8b bb f8 02 00 00 [ 145.616224][T11265] RSP: 0018:ffffc90006fefc00 EFLAGS: 00010293 [ 145.618634][T11265] RAX: dffffc000000005f RBX: 0000000000000000 RCX: ffffffff886da21a [ 145.621646][T11265] RDX: ffff888061b20000 RSI: ffffffff886da25f RDI: 0000000000000005 [ 145.624772][T11265] RBP: ffffc90006fefd88 R08: 0000000000000005 R09: 0000000000000000 [ 145.627867][T11265] R10: 0000000000000001 R11: 0000000000000001 R12: 0000000000000001 [ 145.630838][T11265] R13: 0000000000000001 R14: dffffc0000000000 R15: ffffffff8cb34240 [ 145.633540][T11265] FS: 00007f3683a8c6c0(0000) GS:ffff8880d6754000(0000) knlGS:0000000000000000 [ 145.636358][T11265] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 145.638421][T11265] CR2: 00007f3683a8bf98 CR3: 0000000034372000 CR4: 0000000000352ef0 [ 145.640904][T11265] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 145.643365][T11265] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 145.645828][T11265] Call Trace: [ 145.646885][T11265] [ 145.647827][T11265] ? __pfx_h5_recv+0x10/0x10 [ 145.649309][T11265] hci_uart_tty_receive+0x251/0x7e0 [ 145.650937][T11265] ? __pfx_hci_uart_tty_receive+0x10/0x10 [ 145.652731][T11265] tty_ioctl+0x580/0x1640 [ 145.654109][T11265] ? __pfx_tty_ioctl+0x10/0x10 [ 145.655725][T11265] ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 [ 145.657953][T11265] ? hook_file_ioctl_common+0x145/0x410 [ 145.659754][T11265] ? selinux_file_ioctl+0x180/0x270 [ 145.660626][ T52] usb 9-1: new low-speed USB device number 8 using dummy_hcd [ 145.661396][T11265] ? selinux_file_ioctl+0xb4/0x270 [ 145.665352][T11265] ? __pfx_tty_ioctl+0x10/0x10 [ 145.666906][T11265] __x64_sys_ioctl+0x18e/0x210 [ 145.668443][T11265] do_syscall_64+0xcd/0x4c0 [ 145.669875][T11265] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 145.671746][T11265] RIP: 0033:0x7f3682b8e929 [ 145.673162][T11265] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 145.679086][T11265] RSP: 002b:00007f3683a8c038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 145.681715][T11265] RAX: ffffffffffffffda RBX: 00007f3682db6080 RCX: 00007f3682b8e929 [ 145.684171][T11265] RDX: 0000200000000140 RSI: 0000000000005412 RDI: 0000000000000005 [ 145.686623][T11265] RBP: 00007f3682c10b39 R08: 0000000000000000 R09: 0000000000000000 [ 145.689083][T11265] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 145.691518][T11265] R13: 0000000000000000 R14: 00007f3682db6080 R15: 00007ffed8be6ea8 [ 145.693977][T11265] [ 145.694963][T11265] Modules linked in: [ 145.696659][T11265] ---[ end trace 0000000000000000 ]--- [ 145.702436][T11265] RIP: 0010:h5_recv+0x104/0x910 [ 145.704178][T11265] Code: c1 e8 03 4c 01 f0 48 89 44 24 08 48 8d 83 08 03 00 00 48 89 44 24 30 48 c1 e8 03 48 89 44 24 10 e8 21 74 4e f9 48 8b 44 24 08 <80> 38 00 0f 85 ae 01 00 00 48 89 ea 48 89 e9 4c 8b bb f8 02 00 00 [ 145.710239][T11265] RSP: 0018:ffffc90006fefc00 EFLAGS: 00010293 [ 145.712192][T11265] RAX: dffffc000000005f RBX: 0000000000000000 RCX: ffffffff886da21a [ 145.714726][T11265] RDX: ffff888061b20000 RSI: ffffffff886da25f RDI: 0000000000000005 [ 145.717227][T11265] RBP: ffffc90006fefd88 R08: 0000000000000005 R09: 0000000000000000 [ 145.735484][T11265] R10: 0000000000000001 R11: 0000000000000001 R12: 0000000000000001 [ 145.737994][T11265] R13: 0000000000000001 R14: dffffc0000000000 R15: ffffffff8cb34240 [ 145.740475][T11265] FS: 00007f3683a8c6c0(0000) GS:ffff8880d6854000(0000) knlGS:0000000000000000 [ 145.743452][T11265] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 145.745540][T11265] CR2: 00005650a1942b00 CR3: 0000000034372000 CR4: 0000000000352ef0 [ 145.749909][T11265] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 145.752427][T11265] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 145.754913][T11265] Kernel panic - not syncing: Fatal exception [ 145.757366][T11265] Kernel Offset: disabled [ 145.758732][T11265] Rebooting in 86400 seconds.. VM DIAGNOSIS: 15:43:40 Registers: info registers vcpu 0 CPU#0 RAX=0000000000000030 RBX=00000000000003f8 RCX=0000000000000000 RDX=00000000000003f8 RSI=ffffffff855b4c85 RDI=ffffffff9b0883a0 RBP=ffffffff9b088360 RSP=ffffc90006fef600 R8 =0000000000000001 R9 =000000000000001f R10=0000000000000000 R11=000000004153414b R12=0000000000000000 R13=0000000000000030 R14=ffffffff9b088360 R15=ffffffff855b4c20 RIP=ffffffff855b4caf RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 00007f3683a8c6c0 ffffffff 00c00000 GS =0000 ffff8880d6754000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe0000003000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe0000001000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007f3683a8bf98 CR3=0000000034372000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000000008001 Opmask01=0000000000000014 Opmask02=000000000000003f Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682c11b12 ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682c11b1f ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682c11b19 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682c11b2d ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682c11bb3 ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682c11c91 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682d84488 00007f3682d84480 00007f3682d84478 00007f3682d84450 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f36838ed100 00007f3682d84440 00007f3682d84458 00007f3682d844a0 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3682d84498 00007f3682d84490 00007f3682d84488 00007f3682d84480 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000000524f525245 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00524f5252450040 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00e800a800000000 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 1 CPU#1 RAX=ffffea0000f82040 RBX=ffffea0000f82088 RCX=ffffffff82084339 RDX=ffff88802ca12440 RSI=ffffffff82085a2f RDI=0000000000000000 RBP=0000000000000867 RSP=ffffc9000402f830 R8 =0000000000000006 R9 =0000000000013d0d R10=000000000003e081 R11=0000000000007c7a R12=0000000000000001 R13=ffff888057bf9eb0 R14=dffffc0000000000 R15=000000000000002a RIP=ffffffff82085a55 RFL=00000246 [---Z-P-] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 0000000000000000 ffffffff 00c00000 GS =0000 ffff8880d6854000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe000004a000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe0000048000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007f1f6d0e7d60 CR3=000000003328a000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=00000000fcffc200 Opmask01=000000000000ffff Opmask02=00000000ffffffff Opmask03=0000000010000000 Opmask04=0000000000000000 Opmask05=00000000004007ff Opmask06=0000000007ffe7ff Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00000000000001a4 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=9c6f1c7760fbd57f 43993cbf261d292f 9c6f1c7760fbd57f 43993cbf261d292f 9c6f1c7760fbd57f 43993cbf261d292f 9c6f1c7760fbd57f 43993cbf261d292f ZMM18=fda76a964072561b 526ee4fe28205a51 fda76a964072561b 526ee4fe28205a51 fda76a964072561b 526ee4fe28205a51 fda76a964072561b 526ee4fe28205a51 ZMM19=a309000000000000 0000000000000005 a309000000000000 0000000000000004 a309000000000000 0000000000000003 a309000000000000 0000000000000002 ZMM20=0000000000000000 0000000000000004 0000000000000000 0000000000000004 0000000000000000 0000000000000004 0000000000000000 0000000000000004 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 030604840001a403 00020001a2030402 0001a00300080001 9803000800019003 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 08820400018c0314 0200018a030e0200 01880303a0080001 8003018004058003 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 05800406a0031808 0006900301800800 1003000800080300 0400040320040000 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0400068c03000000 0604060688032808 0006800306800401 800301800405a003 ZMM25=17c4de2f17c4de2f 17c4de2f17c4de2f 17c4de2f17c4de2f 17c4de2f17c4de2f 17c4de2f17c4de2f 17c4de2f17c4de2f 17c4de2f17c4de2f 17c4de2f17c4de2f ZMM26=ae1b41bcae1b41bc ae1b41bcae1b41bc ae1b41bcae1b41bc ae1b41bcae1b41bc ae1b41bcae1b41bc ae1b41bcae1b41bc ae1b41bcae1b41bc ae1b41bcae1b41bc ZMM27=fb6303fbfb6303fb fb6303fbfb6303fb fb6303fbfb6303fb fb6303fbfb6303fb fb6303fbfb6303fb fb6303fbfb6303fb fb6303fbfb6303fb fb6303fbfb6303fb ZMM28=000001700000016f 0000016e0000016d 0000016c0000016b 0000016a00000169 0000016800000167 0000016600000165 0000016400000163 0000016200000161 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=1c0700001c070000 1c0700001c070000 1c0700001c070000 1c0700001c070000 1c0700001c070000 1c0700001c070000 1c0700001c070000 1c0700001c070000 info registers vcpu 2 CPU#2 RAX=dffffc0000000000 RBX=0000000000000001 RCX=ffffffff9141b496 RDX=ffffc90006947338 RSI=ffffc90006947f10 RDI=ffffc90006947330 RBP=ffffc90006947f10 RSP=ffffc90006947298 R8 =0000000000000001 R9 =0000000000000000 R10=ffffc90006947330 R11=000000000000a583 R12=0000000000000008 R13=ffffc90006947330 R14=ffffc90006947338 R15=ffffc90006947364 RIP=ffffffff816ac5fc RFL=00000293 [--S-A-C] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c01300 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c01300 FS =0000 00007f61cf1f66c0 ffffffff 00c00000 GS =0000 ffff8880d6954000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe0000091000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe000008f000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007f23e49f5f98 CR3=0000000027397000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=00000000feffe000 Opmask01=0000000000000000 Opmask02=00000000ffff7fdf Opmask03=0000000001041000 Opmask04=00000000ffffefff Opmask05=00000000004007ff Opmask06=0000000007ffe7ff Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 44455a494c414954 494e495f43455355 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 44455a494c414954 494e495f43455355 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00005627abcab900 ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f65853f1b20 ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00ff000000000000 ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 1c1f115c435d4316 10120300161e121d ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 5c431d1c1a141601 5c43000611171d5c ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 3174726f702d3162 73752f302e313a30 2d312f316273752f 302e64313a30303a ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 005600051f40494c 43055c5155484005 424b4c55554c4e53 004057005b1a0f00 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 303030302f30303a 303030306963702f 736563697665642f 3d54524f505f544e ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000002cd1 0000000000000032 3170306d656d7000 306d656d702f6b63 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 322e392d3533712d 63707276703a2939 3030322c39484349 2b35335128435064 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 7261646e6174536e 703a554d45516e76 733a302e3072623a 343130322f31302f ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 343064623a312b32 316f70627e322d33 2e36312e312d6e61 696265642d332e36 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 323032302c313032 302c394631302c32 4331302c38423130 2c464131302c4541 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 282b2e2fdf37342d 280bbfbf23243324 26312033fc040f18 1317140d080b0412 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 343133bffc121104 1214041204110814 100411bffc040f18 1317140d080b0412 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 4141414141414141 4141414141414141 4141414141414141 4141414141414141 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 1a1a1a1a1a1a1a1a 1a1a1a1a1a1a1a1a 1a1a1a1a1a1a1a1a 1a1a1a1a1a1a1a1a ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2020202020202020 2020202020202020 2020202020202020 2020202020202020 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 3 CPU#3 RAX=0000000000000020 RBX=0000000000000000 RCX=ffffffff89ec2043 RDX=0000000000000000 RSI=0000000000000002 RDI=0000000000000005 RBP=ffffffff8cef4dc0 RSP=ffffc90006d5fb90 R8 =0000000000000005 R9 =0000000000000000 R10=0000000000000000 R11=0000000000000001 R12=0000000000000000 R13=0000000000000005 R14=0000000000000004 R15=0000000000bf5548 RIP=ffffffff81bc126b RFL=00000202 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 00007f3631ab26c0 ffffffff 00c00000 GS =0000 ffff8880d6a54000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe00000d8000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe00000d6000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=0000200000bf5000 CR3=00000000538de000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=00000000fffff800 Opmask01=0000000000000054 Opmask02=00000000000003ff Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3631a8ef70 0000003000000010 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3630c11b12 ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3630c11b1f ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3630c11b19 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3630c11b2d ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3630c11bb3 ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f3630c11c91 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2525252525252525 2525252525252525 2525252525252525 2525252525252525 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000342e63 64755f796d6d7564 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000000524f525245 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00524f5252450040 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00e800a800000000 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000