last executing test programs: 3m11.383060884s ago: executing program 5 (id=87): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000000)={0x26, 'aead\x00', 0x0, 0x0, 'aegis128-aesni\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, &(0x7f0000000140)="2c385aa3d49100dc6626c892b6bc436a", 0x10) r1 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$alg(r1, &(0x7f0000000100)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000080)=[@assoc={0x18, 0x117, 0x4, 0x200}], 0x18}, 0x0) sendmsg$nl_route_sched_retired(r1, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000012100), 0xe078}}, 0x0) recvmmsg(r1, &(0x7f0000000180)=[{{0x0, 0x0, 0x0}, 0x1}, {{0x0, 0x0, &(0x7f0000000200)=[{&(0x7f0000000500)=""/229, 0xe5}], 0x1}}], 0x2, 0x10, 0x0) 3m10.59245357s ago: executing program 5 (id=91): r0 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000080), 0x4000000004002, 0x0) r1 = dup(r0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2000007, 0x38011, r1, 0x0) preadv(0xffffffffffffffff, &(0x7f0000000240)=[{&(0x7f0000033a80)=""/102386, 0xfffffd6e}], 0x1, 0x0, 0x0) r2 = syz_open_dev$vbi(&(0x7f0000000000), 0x1, 0x2) ioctl$VIDIOC_CREATE_BUFS(r2, 0xc100565c, &(0x7f00000013c0)={0x3, 0x2, 0x2, {0x5, @vbi={0xb5, 0x4, 0x3, 0x0, [0x0, 0x18000000], [0x8200, 0x1]}}}) ioctl$VIDIOC_QBUF(r2, 0xc058565d, &(0x7f0000000200)=@fd={0x0, 0x5, 0x4, 0x10, 0x0, {}, {0x0, 0x0, 0x0, 0x4, 0x0, 0x0, "001500"}, 0x0, 0x2, {}, 0x18603}) 3m10.093467323s ago: executing program 5 (id=94): r0 = fsopen(&(0x7f00000001c0)='ramfs\x00', 0x0) fsconfig$FSCONFIG_CMD_CREATE(r0, 0x6, 0x0, 0x0, 0x0) r1 = fsmount(r0, 0x0, 0x0) fchdir(r1) mkdir(&(0x7f0000000000)='./file0\x00', 0x0) mkdir(&(0x7f0000001200)='./control\x00', 0x0) rename(&(0x7f0000000380)='./file0\x00', &(0x7f0000000340)='./control\x00') 3m9.617281306s ago: executing program 5 (id=97): mkdirat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x1c0) r0 = openat$dir(0xffffffffffffff9c, &(0x7f0000000240)='./file0\x00', 0x0, 0x0) r1 = fanotify_init(0xf00, 0x1000) fanotify_mark(r1, 0x105, 0x5000003a, r0, 0x0) openat(0xffffffffffffff9c, &(0x7f0000000100)='./bus\x00', 0x42, 0x0) renameat2(0xffffffffffffff9c, &(0x7f0000000480)='./bus\x00', 0xffffffffffffff9c, &(0x7f00000004c0)='./file0\x00', 0x2) readv(r1, &(0x7f0000000c40)=[{&(0x7f0000000500)=""/169, 0xa9}], 0x1) 3m9.116417706s ago: executing program 5 (id=101): syz_mount_image$fuse(0x0, &(0x7f0000000080)='./file1\x00', 0x0, 0x0, 0x0, 0x0, 0x0) mount$fuse(0x0, 0x0, 0x0, 0x0, &(0x7f0000000400)=ANY=[@ANYBLOB='fd=', @ANYRESHEX=0x0]) mount(0x0, &(0x7f0000000380)='./file1\x00', &(0x7f0000000000)='autofs\x00', 0x0, &(0x7f0000000400)) chdir(&(0x7f0000000080)='./file1\x00') r0 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f0000000000)='./bus\x00', 0xe, &(0x7f0000000200)={[{}, {@oldalloc}, {@resuid}, {@noblock_validity}, {@block_validity}, {@jqfmt_vfsv1}]}, 0x6, 0x447, &(0x7f0000003380)="$eJzs28tvG8UfAPDvruP019cvoZRHH0CgICIeSZMW6IELCCQOICHBoRxDklalboOaINGqgoBQOaJK3BFHJP4CTnBBwAmJK9xRpQr10sIFo7V3G8exnUedOODPR9p2Znesma9nx57ZiQPoWyPZP0nEnoj4NSKG6tnlBUbq/926cXn6zxuXp5OoVt/4I6mVu3nj8nRRtHjd7jwzmkaknyRxqEW98xcvnZ2qVGYv5PnxhXPvjs9fvPT0mXNTp2dPz56fPHHi+LGJ556dfKYrcWZtunnwg7nDB1556+pr0yevvv3j10kRf1McXTLS6eJj1WqXq+utvQ3pZKCHDWFdShGRdVe5Nv6HohRLnTcUL3/c08YBm6parVZ3t7+8WAX+w5LodQuA3ii+6LP1b3Fs0dRjW7j+Qn0BlMV9Kz/qVwYizcuUm9a33TQSEScX//oiO2JznkMAACzzbTb/earV/C+NexvK/T/fGxqOiLsiYl9E3B0R+yPinoha2fsi4v511t+8SbJy/pNe21Bga5TN/57P97aWz/+K2V8Ml/Lc3lr85eTUmcrs0fw9GY3yjiw/0aGO71765bN21xrnf9mR1V/MBfN2XBvYsfw1M1MLU3cSc6PrH0UcHGgVf3J7JyCJiAMRcXCDdZx54qvD7a6tHn8HXdhnqn4Z8Xi9/xejKf5C0nl/cvx/UZk9Ol7cFSv99POV19vVf0fxd0HW/7ta3v+34x9OGvdr59dfx5XfPm27piniH1zn/T+YvFlLD+bn3p9aWLgwETGYvFpvdOP5yaXXFvmifBb/6JHW439fLL0ThyIiu4kfiIgHI+KhvO0PR8QjEXGkQ/w/vPjoO6vFf3Lx7571/8y6+n8pMRjNZ1onSme//2ZZpcOt4u/U/8drqdH8zFo+/9bSro3dzQAAAPDvk0bEnkjSsdvpNB0bq/+9/P7YlVbm5heePDX33vmZ+m8EhqOcFk+6hhqeh07ky/oiP9mUP5Y/N/68tLOWH5ueq8z0Onjoc7vbjP/M76Vetw7YdH6vBf3L+If+ZfxD/zL+oX+1GP87e9EOYOu1+v7/sAftALZe0/i37Qd9xPof+pfxD/3L+Ie+NL8zVv+RvITEikSk26IZZ7O7eAvqKucDZjuEvCWJ3n4uAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAdMs/AQAA//94FuFt") ioctl$AUTOFS_DEV_IOCTL_REQUESTER(r0, 0x810c9365, 0x0) 3m8.092447893s ago: executing program 5 (id=105): r0 = syz_usb_connect$cdc_ncm(0x0, 0x6e, &(0x7f0000000480)={{0x12, 0x1, 0x0, 0x2, 0x0, 0x0, 0x40, 0x525, 0xa4a1, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x5c, 0x2, 0x1, 0x0, 0x0, 0x0, {{0x9, 0x4, 0x0, 0x0, 0x1, 0x2, 0xd, 0x0, 0x0, {{0x5}, {0x5}, {0xd}, {0x6}}, {{0x9, 0x5, 0x81, 0x3, 0x200}}}, {}, {0x9, 0x4, 0x1, 0x1, 0x2, 0x2, 0xd, 0x0, 0x0, "", {{{0x9, 0x5, 0x82, 0x2, 0x200}}, {{0x9, 0x5, 0x3, 0x2, 0x200}}}}}}}]}}, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, &(0x7f0000000340)={0x44, 0x0, 0x0, 0x0, &(0x7f0000000200)={0x20, 0x80, 0x1c, {0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10}}, 0x0, 0x0, 0x0, 0x0}) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, &(0x7f0000000080)={0x14, 0x0, &(0x7f0000000040)={0x0, 0x3, 0x1a, {0x1a}}}, 0x0) syz_usb_ep_write(r0, 0x82, 0x5, &(0x7f0000002340)='hello') 2m52.839817096s ago: executing program 32 (id=105): r0 = syz_usb_connect$cdc_ncm(0x0, 0x6e, &(0x7f0000000480)={{0x12, 0x1, 0x0, 0x2, 0x0, 0x0, 0x40, 0x525, 0xa4a1, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x5c, 0x2, 0x1, 0x0, 0x0, 0x0, {{0x9, 0x4, 0x0, 0x0, 0x1, 0x2, 0xd, 0x0, 0x0, {{0x5}, {0x5}, {0xd}, {0x6}}, {{0x9, 0x5, 0x81, 0x3, 0x200}}}, {}, {0x9, 0x4, 0x1, 0x1, 0x2, 0x2, 0xd, 0x0, 0x0, "", {{{0x9, 0x5, 0x82, 0x2, 0x200}}, {{0x9, 0x5, 0x3, 0x2, 0x200}}}}}}}]}}, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, &(0x7f0000000340)={0x44, 0x0, 0x0, 0x0, &(0x7f0000000200)={0x20, 0x80, 0x1c, {0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10, 0x10}}, 0x0, 0x0, 0x0, 0x0}) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, &(0x7f0000000080)={0x14, 0x0, &(0x7f0000000040)={0x0, 0x3, 0x1a, {0x1a}}}, 0x0) syz_usb_ep_write(r0, 0x82, 0x5, &(0x7f0000002340)='hello') 11.807069942s ago: executing program 3 (id=959): syz_mount_image$fuse(0x0, &(0x7f0000004040)='./file0\x00', 0x2000080, 0x0, 0xfd, 0x0, 0x0) r0 = openat$fuse(0xffffffffffffff9c, &(0x7f0000000280), 0x42, 0x0) mount$fuse(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f00000000c0), 0x0, &(0x7f00000001c0)=ANY=[@ANYBLOB='fd=', @ANYRESDEC=r0, @ANYBLOB=',rootmode=00000000000000000040000,user_id=', @ANYRESDEC=0x0, @ANYBLOB=',group_id=', @ANYRESDEC=0x0]) r1 = epoll_create1(0x0) epoll_ctl$EPOLL_CTL_ADD(r1, 0x1, r0, &(0x7f0000000000)={0x18}) chroot(&(0x7f0000000240)='./file0\x00') syz_fuse_handle_req(r0, &(0x7f0000000900)="a1af56567af19ce4706948d30f35abf6494690656d554e6190797369db23a30bf328aa47a2e54509379ba2e477e6e0461d2e45920d509fa49de04732cd2f4a4e34d73eb464d09605a698ad2219a2175ebcc560f740fe531ba46ded4232d273d1865282844f5a3b54d7f154c21a8a82228e27b2c1af662a92e53d81cae3ea68707ce43f89c3321797039a0a39e24b83035dbfb1ac9668b5f87c4ae50250e92c8b113ed58f60015d9c1990253e6646c02901b08a2ec0acceb7ac1e28f59b1e22663432bd5435083b604934bda5f4897467677ac5609bb6e1d1f938a1a8238d2df6db69fcffa48a08ef9231830ceb045a999a9ba43b4d605ce7bb4736ee8bdaac3399576ad3d434c12f1ae8fc5e06dbbfac985d7105c3b7f431854465b6f732e1397e4647e88a86b0a3b01c1ef689a4bd3963deb3b06190576c690ab257b9845b4d412f248184e124b5228f4236d020d4b80ff0772d9515685918c41cad06498a6833d591c191916067759bfeceec176d582621bf23b8d827e2c8977822d64ca19c168fa8a4ea90a60ed60854342e7c42ce11f414dcff1fff715d10ed263d305e5c563ee13a1527795b012e01b8442026032a761cf5104f00dc28a761596d8393e3750be1a8788fa7152a3cd8e051a963120417af9bd3e659bbaac6406a70ba347641aeffac9436fc2352bf7822dabd7a4911a5b947f9c07f805e67ec8c7d787ff358b426494b87aaac46c2d4061cddf2b257cacbba656cda626b0d3fa11881e99799b92f0a07813eac359a64a61a03d6527a24a4fee8e6cbd74932adba5ad3a865788e874b796cc8555522b19f76676646f21f31fad8c360982ce2b23fd4aec43bff16e0f3f1e1e804daf28f236081d0686108fde25f7e6a7bef08b793beca5b21b5f4893543ef1e3a216378cb76a54fa879ad9624a60a0b3306c8548e1a22b735213969421dc9ef70338bb780ad55adfb6b4f4ca3d8ce7c697ce3f0a6210a27cc900ea2218c52ac06bbcbb91adff643f1a3b93db67d7902f23eb89ab2f892970551127b39e7bb9f37c62adb8abed20c8c84531d143c6be2b8b05766e248a94aae400b36a3399ba174ffe14ffd354f508ce30ea991f57018a3534e0eac9cb49d0e6085f93b367d817ee83b24c11f9d38044a9739f4fd41b6a8129fda808bb930beba6223dfe154b23d7c39ac4fb6656169275c31e15d37d3d96b0aaa13637f1c28178f5fc4ebbe1af6acc985c783a30dffde8d7eb0c8863e3481caf2606a4b6930c234736404d4eeefdda697193f57d332540a423831db671d7d3e8e15ef3d6a26b83a5053bdc2f0b378c6b39ad0b8b9c7bd5c4bf81018ce15d0b344772f6c6f469e40c9848cbcb1b3ccb721b4b1f895a6e034380d882bd30a20f1c2b8ae138e6728306e16f6093774d21b798cd73a16bc577be751deb434ef019dd454fa3ce3cc3b2634ea4957548bf226d0b24bce757382c639dae891e55dcb24ffc9dc2c08acfafabd4565dbcad34e1a8e781c56e9144f0e85a5cf6c79a5d1a8b3479cdc178215f05081eebdc03607798c66fd043824756e896c2b69fe5e843e0eb26c86a37a8944e93a7f3b2a863136d56579d0377f9424cf00dd6da7b19066f990ce05e1b93479f125cbcc5c91aea56ef04950164079f5e22ebfd77d54676b2de392ab20298876bce1ae9941ae109d7088edb29d02539aec8f276b862bb28fa6a68bb1a0bda1b0ec6e5891e93777d9b126d6add7eb36a7f75c435618d368c04156f8a116d0c843ad04842d7b7c84cd87e75fb81ec16ef184fd3119c16c950b84bca9a12a86f0e333d9fe34130a0000e9772dc8b94c491e16db0c537e211b01c9f13f9e7a7b2f4d8053baded5d6018561b547562efbeab2946f3ef872d0256196c75fd7f520da7aea0f63a278052925c6c88307bed0336c5632ca98086e7712af309f99a6adb3ec4417eaa9aefe3fd43c4402bc13868832d6dfaa97de7ed43fe3711917de97058d60067d5eeb90ecb428182d07092c516e6eef6781756e308926faa9796dd1a29dd4c3827115fa8e14bbe449f4144785b9581a198273adb8bab0d4080adbb592b25fd74d426233f537562a4a98b07f4b2060b4f496c66a0169391b713fdd991fa90cfc313245f57900d980adcbd46ada0a7bdfdfec4bf8ba12e37724c9dfd7fbbe4541bf21cc393249a555746268e7e33bdb43f2cd4932e39fc818e49d0e588d12a3a297be074ad83db57be9d4455ab0685b087e8ee9f5c7c33e10c9d6be572b58c88b79756c45eb9eed6d0275944d9cc1cbc8c498917aa2fd79c00567d4f9f768579f891e23fa9548c5fbff150d2873ecc72da8d0077a223f9d18700b690d8046783bba756a2c9863b7ffc7022b2da68a332f72f704bc38a0fcc4f445891f1ca1ef5dad28b87ce8bdef23ffe29ee23f2c0a002c80cf99399dc7276aec6f9d8b6ff3d7554409a4e38d2029a43f8a70da62b33c44f5f4f299eec825302c52e5f83d462b81512775107059826c8880578f01d8cb53af86ad61a7e36c2ccdf55ce197ec2a78219a5b952a9bd12ac2cc3271e84e6dad464c7ec9d9f0310614200a98cfa933d5db05c00c95c59fc5bb8844ff856ee7f9b091700b1a93ae1c00a40d9e5e6ce036f90a6dc34faa9dc8e8972c49b055f9a43ae10251705a960f2cfc8430cf9bcafc26c8eccc8b75a788beb41d180d4364f3083f3ffb5e39049979903c76f440810b7ea608ff84f5e56f9e0653bf15b6b6332d458f8d2e2b17d7bd2305a8909996d2ebfc2ee2ff697fccb215bd8c73d4b9f5b597308f98ed8fbda58f52cf8443f5a9db7f0f6e75e1c9e47d73f8d0624e9e6f33c2dee3c6ff394082d78ffd3a68309b3085e1a7c106f62c3959a353672cadadf6c058fe366b03fcd95a23f564c55a3ce9a914c11c8b2d6040147a1539b106adecce531646fea4db06775fe5d1bf9cb0107941b620043ac9b7936b2af9849eca9c46062945b137dfa355a7ee0c81a0193fa60a70e59b407af06a7f181a3e4ccc81f2c580a6c6cf67a8bf93eb8ff2151b7074144bf7c5cff97814e0c00c138d984559ac8b95a45a4497174130bbb0db22fa53187db1d923d9ded441a4d2fcbe0ff5736ecc3d94bfbb2df632ac88a02f2c9f73312e7a9c2d8d6c0bbfc774595e2e63669f2b5bbf6ee6a1ab0c25e313d819b02c785494eda4cace033e96b1ecc5b155a14e0c8d51d54d8bf33e499d0913d9605a419bc6c73c6bb07d1a306adb27dfedbe81a386fb3bb659764442c4d9d66673a916ee5a6ae59abc994fff64f2db0c83e2b18944f619cfdea0ea0911064ab690b2e03670a3e3667651c1980d0491a40312307e4534671c9c8ca8712506eff211577783c81dc05ffae4a9c6d7554f9fec07b25451c70e6f4d4b160544b66d66dd88ef1c77f09133db317c39fca05b68ef3eee3c28cbe31982adb0693fe9699d06654150346915ccdb17c69ea3aa8bb36b5f321060f6237dec73a011b233b81a6337bd77da5da753593fe30282456a0da2c4a18911ab5a8af13c8f623e5684f74f322ba103482d9abec31a684707671759ac8bb2592d66350745f77f18bd6a6cba542644f1fdf0dca14a08f4ffd1365969ee896cb39e845f71590eb4c73cc624cdcfbdea2352ad5173e5e919fcb98f6d960341047d181075ec8b1e92f40ecd5a1bf157925329748cc7af0239a7803a0c947479e070b026baf6738c29c9a8351685abd43775726ec0bfeff4d51fd3fcb04b108de286c5f61a82ef496e20133ef8b4ae243e81b20822ea6285c70bf1a33cb9f4ceeec053f60992c0023bd5acb0d4a9a55ef377f2837784ada634070a85b0a42fabf288130d6b74ca23473fbce932bedb44cd51dae78efd058dde5d7eb4aadfe3dd8346420567e745ced5189db6df22edbc66580a236f6ab148a3efd69bdea3dac7cffb47df44dbef7fcb436902bb30d65d65d5320c3b76ac17f43d27b2deda8692ba03ac2ae60e4ed2a9232c71a98b9869259a410b901f38cd6712f69f2dc3f92b7c5909f3595e99c9fc77d4d33f9a0e57d5f121e2de782b22cf7fb9bf22fc6afde5e42876ff8005f8a042bb5a9b67d60f40a7ad1cd73810a4f704f14823d4074e5a32b028c8360432b8aff539705961fee84d6c60b2b4d2efad60fb20c1da653869349b81e6c3d56c96ce56a833ee9a2b3e92a4b96c5a545910406751b4e7da24a328de0e20042d1ecc3bf7fd97071bb2740f497307501d90fa9c8e5cd63a703096955f4934d9140ad295cae59232cf005574d875e098637ecb757305a51d102ae5323b23a61c1a1b888c5974a243e42bfc391114ba5ba28e2375cf1d6d1a63e6bd5cf9aff9af16bdc927f642151597fe6d18ab008426f25054ee8e39136e2c217ad1f4cbfccdaf9a0cbd97edef5fef9b2ec486a4b21d79021103deec2ceb26c0b0035856ea2370aa3a8de925797722aeeee2d504184988f9f8727915c389f043c3de2b0d8e3046c46b33cb1615f291f272ade0029cad1f1d2e723e62cf739b667b005de14c3ed265e3bc2d553bb232f88b92a8284996c50e141608623ca7677a9cefb85fb0e0e77e23b9767dd65fbc119a15969ecd10f8033d9f37a748a895fd39390563f5f7998bb10eda8610855eaeb2499d8234975edb16c438069e8701bec0a86ae108a19b9f54782648af4b7b04a1d7b6b3a853c24f2393120918d1eed7b40f467c88857ee9cddf5f01db495f3138984387adfe3cf51a47dca021f9f31b44af1d12e7c9f4c768f2a46d5c012a937985f56436ae15528ae3597590c927be9676a4ca80a19d44457b06991c02488c96e31094cd963b64e8623fc7000009ddb29b0dbb13671c321d24e322a05cf215dd04eabc2cc6fdaed762d3f9da0f1e0e4b7ba13a6036771c9403457dfddecb71579de33c597860a2e49d7b5052a6b018ddb409a7a84f8f6651d070a4c913b7a721490c8f97c085de8315019952deae16434a3e5fd5d242b1b333d8a801aaa67e4aa599b818c8e747ecac2e9c6176bec7e34ecb84450903f5aa6c6c6bf539b240506562d73c5dfbacdfbcc9db3089701f2c7fe6d6b8d6728f8a1b90a911338463e6fd824ecda51578865b3c363b4b79f6c698e27760c1090f8ae52d6fd3f0f9488f1c25feab4b48c03ddcf74a8b6d2b0fc6b5a89b8051c99edee357fcb875f523f7a88a5f25222fc0ba159873b47fe906e88f920943e453048cdea455dd98fe77f55d9c92e205b87120ac5ef791cd7d6ce7d2cfe689db61096c6e4fc359c9aa4dd3d1205358da38882073ef7268239f7c74b0f3cd60ca239b2fcdc3f5c774559ffbb2b821f1314987d8cbe5342db9567a864d569abfde85f1124e2b178be4d020c4244ddb0cf4ef7124f295a81b9c10227ea886e6f6ea2dca031a026a4f946f49598b76141a0b18170bb3cfa9136c49c69d71732aa223db1e65553aa03bec9b0a35c31eb4e6b0dab02ec2c2d851a731be9cec6078456631c68761e14dbc9afa2c3f631a160ebf9d1fd3c2ecccf6d4aebaf0fafe2e9f47ea9d386425a7950671cde77c6951ef43a1ed32f0ed6fcda74ca9333d2513e4a40cfca01a17bfbc13b0229e2b16400880d96e4c687fc54ed0b34326126f845bd7cd2063c51abbf8bb61f6f1dc3606959f2dececc6e3e08d808841c4779ca0f5f51e7e03260d0b75b1b0355f8544c1639b2f0bfd6f95c4f6d151073a086ecc890d6366acbcee869020cf347e700a8361bd8d5c53e6480526aaf31c9c655eae11831184746a709387e60d68c062e5e05e578d11687f6a5411ffac4cfd62331f63a9726ae77c5799bcca05d6983c985cd23d025e3367ef8c7ee903de557322f38629628ee3076ac483f8257c6335a478412cad1d73b6fd43c37a62dd7a0ae7601f12b4478c3f2ee105a915ff0552d23a8b9af3ca59013f553006259d4cce52212862d22c08c29affa3520b33a6b68cf2b9f91d9258dc5052bf360977ba81a37701118f635379d852b6481843604c111bcfa4970afd5a0fa52824cb27ac9a77b7575e3e0cd043c29c5682a47fe94fd6c2c225b6d9939b99c18b5fb898c5f28e87a5b6a0bbeaa2c4725cf5494765d79a50d2417e84130bb37f540e8db7064e57935ec3c6f9caa2a9a1ced0f8c6eebcb9b688490b31f864dcd9b726628218b42f45aa82f2bcdf2c7532c9669ea7ffb6842451ac314a35cdb0855312448c24efd6583a582e15ad5e7f7b714f0ac703a24e2ee8769a868079af8660931ba325ea1c9b636ef7b13776204dd733c3bc69f11e026c382ac0fa5ce8413fb9f84408e4648a5e66b8592093a17a42cb105b616b8239d2031200eecb9beca6d411a71f072fd159eac0a4f4392a0cedb96248dad497b2379f3162254045ce276503093e5e7ab062b942cf6f2302a5ab9af1b3a315ec67faf84b70fdbdb39044a22cd7bd0f62ba66ce2257f3aa0f56d53c8157c4db3297087e25ec24696813430f386f5ad55bf6289f62e1492dc6ac3bb5047e933d54ec338cafb3bfae8336215611bc3e8a5cafaca7c70f580570518a675cc2075c7593e1d98ef02b74f06b041b6ed9b06e820d32b413de06235441a52346c3fd2e723816c7b481fbf564a525646ba62c615060b2f9fb0ff0f00c376c6dfcdb060aca7af2f07f6030a2ca324c8380c11f9c1182acdea2123c52f5a40b44909180a14037c760c4ecc10f20206445aa65cf835f09633491f608598f1fe5cb5175ddc48070fe0608335af27ded864f97dd52c235b7c4ece6bda153224b773c64235c1099054a55849cd1af7832abd1383e82f63715c9cc24543397bd56e34fd5d28e49021bb483617a3444fdcf8cdeb33bd8675334a897e17966fcbc1e5c5c5399bb6bf02a9bbfaa5f3c58d2efd007dcb1190af4ab4b71987ff7824bd9b9c6d6fb0b144c1fd462805aabf2c7fbb043ff22b496e41a4a81957892efe74d614d62d4b04bbf544fb03826e9baa2a84f32da4d1154c1d0fbdcc17f24a49633761d2b5962e618d8a9be2bf373cdc9c45ecff0148f355075fde5ad5e8da5d59498eb2b7f77a4c0622edd29d7dfedd748b750d0b48057fa7b8ff575714a408a926f6e0cad081eb24780fdbb116fb8dfefb2006f765ff95fe4def6b83fa97b3f54204a0c00cf71c4a1efeface1198a94610570816d08c19af76b03afa42f722abbfebb2c99a905300918dbcd131fce84632bf4f7f5dabd1b5b05742755b45e50eb89ee278e0f6f1a8ad3d9f907b9accbe4845f6591f8361b52e4dd8f19823efd7e89c2ba80c70671eea397e1953daa12907ce59d940a6dcfb3eef7ba7405bb489c38319ac4fee62dec986f4f0975dc1b9f576ebdbca90c42e7f3b1928154af66de5e54b16d8b6541f55daa90812ea7dab78a87d969e4bf95c47f70ce84f9e41e542bbb91f77105c8314e8bd5d8d37e11d9af07c5dcedfab1f21642bb30fb332f7c6bfe13cde2f28f104344777066afe5b0f6db14390f587e64417b0dab027cef4c5daedc75812a7452d45e57e8e274ad8cd8a10b2b9ce0f371809101e9340f2fa0a59501020e48f862572fef70b350938e00a921fb1c080e933eaad2d56daeed692e7d69d4b95a2d1a620da88247314bd73a20cc7a504427df77ba969b5adbf74321e982c2a1913b66a8687960c8fb71a850c1003c76fe1c3bbbc8eb142dfa01f5df52b72bde0c8884374f72eeb8038ad57beb6c732c511bd5847ae8d4b69e195f87b03379279936dda69e11cfda279f37e53a05cb787f118d66f62a87037981937d6083e47e31de6a2700cb7976c0dfcf972bdd458e561f13b3e30368c8bacb722611db7627ad4e00a34f69a5eb9edc7eae464b2422a4c38bed04c49b15fce25ccd22347720273127236d6e8178cb414d1b4dc36cabd19f713782bde48db7094577042083cf5d42224eaa69e0d70b57e6f1764a825909c48858cda13ab13ee203fd0d57291acf508f91f9bc428d4c9ea06a9df3c9ce183e0c101a4d52fd87866c2146219beb15e616ce239cb025ef3dfdb3a2568a833c88a66a580ca9d3f2b770647d5baa42a707351688dc0be3b15d2cead64792e9e9688ef95ea5274c08ee13c4a3797ce346dceeaf7d81a18181839ebeed412baf43ec1abb35b7930ed7a528f9a0bbccd1ea6eb525488c6731150afe791bf58e524de4cc62e174d134bf5d170132efdb2cbb42b882219de563cbe6280ce4cd8482699442b236d1bd54517c3ad25fb3d68a649920357d85f343f0b46ce4a78b1836b6ecb198f1f1686597206c09ad4534717402eefc0d5a90639f91b84d3de00e7d815059640ada64140687c3e404432c74e91907cdcf3e07e997eed9de114767829833920a9fa5bebf7d99fc4f461375f3426b136b680230c7aa135f0d2d72be7bdf8667a8cf0dd0bf5490e393b5a465d37b9ee0d659c8c0f96681b71a867978b3503a45dfe95e49b9d11b8ca953ab01ec1714ca9ca1e1ed5998e02934901dcac10a2553a94618db7d79c4a48741afe3bceaa994833595808f8080f6eafadd31caee252a7d115db962320be9503147d39a8f3f1b1cd4cf2cd4bf94d9036ea61b2d4791c6326af653847d2b6dd83f5df51eb9473ae0c305abe5f3896175d82a2b569bf100166004886dc58432cd678c0a4a152013b2646a68284567b898e6f3d38a9187b6d10075234b2e11b7c929b308bbcb82f4a8ceafc503f18536092f2965d13875060c926b5404ccf3bcfb1389688fb4bf57ff79201d8a00cbb54a12b3be4693b4a295284c90e7d0f08b632eb0411bbd01d51112afe5db173a8159dd38fe6e9804f6ae779479ffdc697ec572b0934704dfcc3e9b2bec95587285299d1d79192b2324e4eaf4de74df050170562c08e0a821f47745f63ecbbb767846ddcc331f459013ec90de697346f1e57345a51fd9d2233cb3591c406bc25ff5c098c331cd026aca7ac1fb1c35c3d3597c7deb89620a364044b30c77d5071bea5b196a0c380ad40370985713838b1c830130a5fc15c5501748a2c8369e77c3fd4ec2f5de572ee183f526359f28865d68eb87c21f8fcd4a09d76ee6d9ef31561d9c97ae3672500e342a798b04177f2c5896bd06b4c96a58aa839185ae44b838d763872bbf1e7b665848f1e186b5ab6cd4628f4725324981b0aff0b9af2f78883dc8433d2dc26c1766e0ec77c4eb63da1f859c09ace8889fd2c5ec7f7e11eeb547900dd9332b7b96ea6be35aea692e54c1cc3d1211bc843f8e8ce71abb88873e132fe214a7e7670fcac38516b6935b9e0a2eeb43a0aebd25676db551d8cff4fe0b6cecbd59701317022511a2d612864c09496c99af48e1cd066c5bae55b415ec08e99947ac94885ddf875d8f8af199aba32c0bfc27f6e19e57380618e7940481077edf6270ea3befce28a55c2a68a961142e959690ba294afd57c5530a5fbd5f60d791a3f06720947c74cec26a571a9f2e5cf98cccefba8beff72f2570f8a0e1a130c0e85d4fbb6a6f0b881af274c9eb063ef09176d43f8f18bdb35a0acb1c6305ba5563d1b6baff53b1251305de413052667c4cf9f94460bf348fb27ab5719ae44faf02dae55d8eab643040834b04aab15a197568e8ebd296638b01e5ea34e39ed47ffb58a47027d4b7d978028b7812a141df233065e93c20dc736af1cdcedcf7e766eab238b3b4d3df022f50b43973c47d1c80055e4fdf569e50fd382e840b76a6db6c06b1f0603a2234b9175c5e15a22855b57cd5257d9b5a456712f281f83e1c6c87f58be8166f8b2e85e9f54d24fe3b420d77a22745dfc7ebc89e21acf1c6649324f4c5bf53e188ce3216dbdec21a06fa9e61d830814697727305fb48c705c4d6c4bdfb874e43a8fb1423e2d2d6bdfe22a0d2b211d3beb86937c639c934cfe9a4b6c2853ff353829028854e8d7d75f29f01c4d7c297fe0236345ecce914b3be4907788a39c093c9f9e2c930a15563cc453d08123deadf853c83db0e3986d993e44e441a874411b7905708462e1ba42ea22521d7c57089a77b14b6dbe57f0ce69c7c4f1c0d53385655a8ed6294f113d33ad8867ac05e80403e6a8103d1574fab80f43a4a3af93a67678346d7b3b977a1381afb93990b1cc3aa73cc463f72bd898f647f3f5a3b342fb5e37140ddc499edda92ee624039ef3f802c9055e20b7d6e4f5a109cb4ca1bf84d37d1e78d45a10f45602b61216ea8969eba3a0075256faf8e577de835bf0b37311d16310645effca6751cf502a035d7ac7d1ca2c23547a739116efb586dfe2762ca4bf5ce5fc48913efb41a4a93fdb240f0895cdf306ddd13337d38a58402561dd663bbc675e1a378d4f770ba5e308c6ada84faf18ab2b387b0ac139a57dc534e278a1afecafcaed3746701cee14edcd3f35cc39c91ed5be8a178d2fcd97567e8ab661d573278062bfc3c83acbfcdeec7f08d3c1197ccf830c883eaaa01e2cc44e91cdc1c47c03797528a9dd63cde259b4b211b57af121b125fefb26c110da83bbc150e2663a22273cc855cb3c52d02fd92db59a7c876d1a18e66cd64708aa478f3f10e726210dbbe2fb1afedb2034a7d59ad774e73f97d7b4b121cc25b90dd4fb5179816174dc4650b2da366d11a519f4310972944625c839b01040c712c635d967269c6c07189b5b1b496403e35e9ef01ecf7e795c357ae08b4736d2c1bcbe556cc671ffa37677b740baebaeb1b74c922d1ac83cb3ab86735d07ebffe072ca08ebd56d0ae89d5535a63bee75810468b1560534ecdb4a16495f9a7f42164df055942e94011848c5dac783a69fbdcac9c477850320af0c10da48775434088c7d090202f927463123639dbc1d48a871e4f20f75563f6dba586db6d12e2e7f36e7da4915037fcddb4413336b423f6b888bcf297fb8d33493e9fc2e992afeb1b83aaeaf46f4aba9bb0aa2708272ce5b0c90ef9f6c366c20e90d0f87aeba828196acdc4306131c515319776dfab27de1e3a501cfc560bd3a1dd29e54b87de9a01d0351184ed5cc3323cef72fd423dfbb0ac90eeec5474432ec1e4c64d68605c378320c0e97a3d77a409b7d969d6e116c2ba861f57418d8eaac5bff85c416ec5224d92df53d8f272c7e02e832bd21ef4d6b4a9bd307f8c1756c3e6c155bb2ce5807311d60b2fb31357c89119af443af2d3a4d08fb6221aaeee97bfdae51ebf6c51f98300033ec513ad6996041441d474ccf3a2548a11b94527ebc2e24d7519b1ded645da3af62060a4ae19eddc3bf331c4c762d9672de22558c655ba05338d985da134230fef2d0639743bdb4695517dd9e3733827050617b3cc792d12b3280e0000b22ad5130b27f9a5e25b965028874db5b5efdf881043e1279187294bbc35865af7662b23b9adf614a9af41fe4d0c9cfe62106a2bb6d294d3ca554062b2c7a0299f82fd37ee36062055c9f52b3272f411709db86d59db530fd1ed9cc2138817c290a2777d1d54cf4b7b2f8737444b58334a1c26f63ffda10b749b5796fa61ce6f74fecef2c4766a05d0468c1d7056beb8fa9cf7d51d5115690bcb889f09dbe01b1c55ac860a00cc159f6683d33fdca16d815fab5bbf00", 0x2000, &(0x7f0000000440)={&(0x7f0000000340)={0x50, 0x0, 0x7f94, {0x7, 0x28, 0x3, 0x42800}}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) 10.878489905s ago: executing program 3 (id=964): syz_mount_image$exfat(&(0x7f0000000280), &(0x7f00000000c0)='./file0\x00', 0x810, &(0x7f00000018c0)=ANY=[], 0xfd, 0x1501, &(0x7f00000002c0)="$eJzs3Am4T1X3OPC19t6H62b4JpnP2uvwTYZNkoSSZEiSJCRzQpIkSZK4ZEpCEjLeJHPInG665nnInHTzSpIkJCTZ/+c2/P16h5/3fX/9/vq/d32e5zz2cs7aZ+27nu89w/Pc79ddh1VvVKNKfWaGf4f+bYC//JMEAAkAMBAAcgBAAABlc5bNmb4/i8akf+sk4n9JgxlXugJxJUn/Mzbpf8Ym/c/YpP8Zm/Q/Y5P+Z2zS/4xN+i9EhjYr39WyZdxN3v//f079T5Ll+p8h4D/aIf3/T6P/paOl/xmb9D9jk/5nbNL/jCy40gWIK0w+/xmb9F+IDO0Pf6e84dyVfqct27+wCSGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQ/w+c85cYAPhtfKXrEkIIIYQQQgghxB/Hv3ulKxBCCCGEEEIIIcT/PgQFGgwEkAkyQwJkgUS4CrJCNsgOOSAGV0NOuAZywbWQG/JAXsgH+aEAFIQQCCwwRFAICkMcroMicD0UhWJQHEqAg5JQCm6A0nAjlIGboCzcDOXgFigPFX4+Z7rboTLcAVXgTqgK1aA61IC7oCbcDbXgHqgN90IduA/qwv1QDx6A+tAAGsKD0AgegsbQBJpCM2gOLaDlZfKTc/y9/OehB7wAPaEXJEFv6AMvQl/oB/1hAAyEl2AQvAyD4RUYAkNhGLwKw+E1GAGvw0gYBaPhDRgDY2EcjIcJMBGS4U2YBG/BZHj7oWwwFabBdJgBM2EWvAOzYQ7MhXdhHsyHBZCcZREshiXwHiyF9yEFPoBl8CGkwnJYASthFayGNbAW1sF62AAbYRNshi2wFbbBR7AddsBO2AW7YQ/shY9hH3wC++FTSMPP/sX8s7/Ph24ICKhQoUGDmTATJmACJmIiZsWsmB2zYwxjmBNzYi7MhbkxN+bFvJiE+bEgFkRCQkbGQlgI4xjHIlgEi2JRLI7F0aHDUlgKS+ONWAbLYFksi+WwHJbHClgBb8VbsRJWwspYGatgFayKVbE6Vse78C68G2thLayNtbEO1sG6WBfrYT2sj/WxITbERtgIG2NjbIpNsTk2x5bYElthK2yNrbEttsV22A7bY3vsgB2wI3bETtgJO2Nn7IJdsCt2xW74HD6Hz+Pz+AK+gL2wquqNfbAP9sW+2B8H4AB8CQfhy/gyvoJDcCgOw1fxVXwNR+AZHImjcDSOxkpqLI7D8chqIiZjMmaGSTgZJ+MUnIpTcTrOwJk4C2fhbJyDc/BdnIfzcT4uxIW4GJfgElyK72MKpuAyPIupuBxX4EpchatxFa7FdbgWN+BG3ICbcTNuxa34EX6EO3AH7sJduAf34Mf4MX6Cn+AQTMM0PIAH8CAexEN4CA/jYTyCR/AoHsVjeAyP43E8gSfxFJ7E03gaz+BZPAcA5/E8XsALeBEvpn/4VTqjjMqkMqkElaASVaLKqrKq7Cq7iqmYyqlyqlwql8qtcqu8Kq/Kr/KrgqqgIkWKVaQKqUIqruKqiCqiiqqiqrgqrpxyqpQqpUqr0qqMKqPKqptVOXWLKq8qqDbuVnWrqqTausrqDlVFVVFVVTVVXdVQNVRNVVPVUrVUbVVb1VF1VF11v6qnemN/bKDSO9NIDcXGahg2Vc1Uc9VCvYYPq1ZqBLZWbVRb9agahSOxvWrlOqgnVEc1Djupp9R4fFp1UROxq3pWdVPPqe7qedVDtXY9VS81BXurPmo69lX9VH81QM3Gaiq9Y9XVK+r5zEPVMPWqWoyvqRHqdTVSjVKj1RtqjBqrxqnxaoKaqJLVm2qSektNVm+rKWqqmqamqxlqppql3lGz1Rw1V72r5qn5aoFaqBapxWqJek8tVe+rFPWBWqY+VKlquVqhVqpVarVao9aqdWq92qA2qk1qs9qitqpt6iO1Xe1QO9UutVvtUXvVx2qf+kTtV5+qNPWZOqD+og6qz9Uh9YU6rL5UR9RX6qj6Wh1T36jj6lt1Qp1Up9R36rT6Xp1RZ9U59YM6r35UF9RP6qLyCjRqpbU2OtCZdGadoLPoRH2Vzqqz6ew6h47pq3VOfY3Opa/VuXUendfk0/l1AV1Qh5q01awjXUgX1nF9nS6ir9dFdTFdXJfQTpfUpfQNurS+UZfRN+my+mZdTt+iy+sKuqIHfZuupG/XlfUduoq+U1fV1XR1XUPfpWvqu3UtfY+ure/VdfR9uq6+X9fTD+j6uoFuqB/UjfRDurFuopvqZrq5bqFb6od1K/2Ibq3b6Lb6Ud1OP6bb68d1B/2E7qif1J30U7qzflp30c/orvpZ3U0/p7vrn/RF7XVP3Usn6d66j35R99X9dH89QA/UL+lB+mU9WL+ih+iheph+VQ/Xr+kR+nU9Uo/So/Ubeoweq8fp8XqCnqiT9Zt6kn5LT9Zv6yl6qp6mp+sZeqbu/+tMc/+J/Lf+Tv7gn8++VW/TH+nteofeqXfp3XqP3qv36n16n96v9+s0naYP6AP6oD6oD+lD+rA+rI/oI/qoPqqP6WP6uD6uT+iT+gf9nT6tv9dn9Fl9Vv+gz+vz+sKvPwMwaJTRxpjAZDKZTYLJYhLNVSaryWaymxwmZq42Oc01Jpe51uQ2eUxek8/kNwVMQRMaMtawiUwhU9jEzXWmiLneFDXFTHFTwjhT0pQyN/yP8y9XX0vT0rQyrUxr09q0NW1NO9POtDftTQfTwXQ0HU0n08l0Np1NF9PFdDVdTTfTzXQ33U0P08P0ND1NkkkyfcyLpq/pZ/qbAWageckMMoPMYDPYDDFDzDAzzAw3w80IM8KMNCPNaDPajDFjzDgzzkwwE0yyz2EmmUlmsplsppgpZtrAHGaGmWFmmVlmtplt5pq5Zp6ZZxaYBWaRWWSWmCVmqVlqUkyKWWaWmVSz3Cw3K81Ks9qsNmvNWrPerDcbzUaz2Ww2qWab2Wa2m+1mp9lpdpvdZq/Za/aZfWa/2W/STJo5YA6Yg+agOWQOmcPmsDlijpij5qg5Zo6Z4+a4OWFOmFPmlDltTpsz5ow5Z86Z8+a8uWAumIvmYvptX6ACFZjABJmCTEFCkBAkBolB1iBrkD3IHsSCWJAzyBnkCq4Ncgd5grxBviB/UCAoGIQBBTbgIAoKBYWDeHBdUCS4PigaFAuKByUCF5QMSgU3BKWDG4MywU1B2eDmoFxwS1A+qBBUDG4NbgsqBbcHlYM7girBnUHVoFpQPagR3BXUDO4OagX3BLWDe4M6wX1B3eD+oF7wQFA/aBA0DB4MGgUPBY2DJkHToFnQPGgRtPxD5/f+TJ5HXM+wV5gU9g77hC+GfcN+Yf9wQDgwfCkcFL4cDg5fCYeEQ8Nh4avh8PC1cET4ejgyHBWODt8Ix4Rjw3Hh+HBCODFMDt8MJ4VvhZPDt8Mp4dRwWjA9nBHODGeF74Szwznh3PDdcF44P1wQLgwXhYtD/OWWGFLCD8Jl4Ydharg8XBGuDFeFq8M14dpwXbg+3BBuDDeFm8sO+uXQcHu4I9wZ7gp3h3vCveHH4b7wk3B/+GmYFn4WHgj/Eh4MPw8PhV+Eh8MvwyPhV+HR8OvwWPhNeDz8NjwRngxPhd+Fp8PvwzPh2fBc+EN4PvwxvBD+FF4MffrNffrlnQwZykSZKIESKJESKStlpeyUnWIUo5yUk3JRLspNuSkv5aX8lJ8KUkFKx8RUiApRnOJUhIpQUSpKxak4OXJUikpRaSpNZagMlaWyVI7KUXkqTxWpIt1Gt9HtdDvdQXfQnXQnVaNqVINqUE2qSbWoFtWm2lSH6lBdqkv1qB7Vp/rUkBpSI2pEjakxNaWm1JyaU0tqSa2oFbWm1tSW2lI7akftqT11oA7UkTpSJ+pEnakzdaEu1JW6UjfqRt2pO/WgHtSTelISJVEf6kN9qS/1p/40kAbSIBpEg2kwDaEhNIyG0XAaTiNoBI2kUTSa3qAxNJbG0XiaQBMpmZJpEk2iyTSZptAUmkbTaAbNoFk0i2bTbJpLc2kezaMFtIAW0SJaQktoKS2lFEqhZbSMUimVVtAKWkWraA2toXW0jjbQBtpEm2gLbaFttI2203baSTtpN+2mvbSX9tE+2k/7KY3S6AAdoIN0kA7RITpMh+kIHaGjdJSO0TE6TsfpBJ2gU3SKTtNpOkNn6Bydo/P0I12gn+gieUqwWWyivcpmtdlsdpvD/nWc1+az+W0BW9CGNrfN87uYrLVFbTFb3Jawzpa0pewNfxOXtxVsRXurvc1Wsrfbyra8zQL/Na5p77a17D22tr3X1rB3/S6uY++zde1Dtp5tYuvbZrahbWEb2YdsY9vENrXNbHPbwrazj9n29nHbwT5hO9on/yZeat+36+x6u8FutPvsJ/ac/cEetV/b8/ZH29P2sgPtS3aQfdkOtq/YIXbo72MAO9q+YcfYsXacHW8n2Il/E0+z0+0MO9POsu/Y2XbO38RL7Ht2nk2xC+xCu8gu/jlOrynFfmCX2Q9tql1uV9iVdpVdbdfYtf+31pV2s91it9q99mO73e6wO+0uu9vu+TlOX8d++6lNs5/ZI/Yre9B+bg/ZY/aw/fLnOH19x+w39rj91p6wJ+0p+509bb+3Z+zZn9efvvbv7E/2ovUWGFmxZsMBZ+LMnMBZOJGv4qycjbNzDo7x1ZyTr+FcfC3n5jycl/Nxfi7ABTlkYsvMERfiwhzn67gIX89FuRgX5xLsuCSX4hu4NN/IZfgmLss3czm+hctzBa7It/JtXIlv58p8B1fhO7kqV+PqXIPv4pp8N9fie7g238t1+D6uy/dzPX6A63MDbsgPciN+iBtzE27Kzbg5t+CW/DC34ke4Nbfhtvwot+PHuD0/zh34Ce7IT3Infoo789PchZ/hrvwsd+PnuDs/zz34Be7JvTiJe3MffpH7cj/uzwN4IL/Eg/hlHsyv8BAeysP4VR7Or/EIfp1H8igezW/wGB7L43g8T+CJnMxv8iR+iyfz2zyFp/I0ns4zeCbP4nd4Ns/hufwuz+P5vIAX8iJezEv4PV7K73MKf8DL+ENO5eW8glfyKl7Na3gtr+P1vIE38ibezFt4K2/jj3g77+CdvIt38x7eyx/zPv6E9/OnnMaf8QH+Cx/kz/kQf8GH+Us+wl/xUf6aj/E3fJy/5RN8kk/xd3yav+czfJbP8Q98nn/kC/wTX2TPEGGkIh2ZKIgyRZmjhChLlBhdFWWNskXZoxxRLLo6yhldE+WKro1yR3mivFG+KH9UICoYhRFFNuIoigpFhaN4dF1UJLo+KhoVi4pHJSIXlYxKRTdEpaMbozLRTVHZ6OaoXHRLVD6qEFWMbo1uiypFt0eVozuiKtGdUdWoWlQ9qhHdFdWM7o5qRfdEtaN7ozLRfVHd6P6oXvRAVD9qEDWMHowaRQ9FjaMmUdOoWdQ8ahG1jB6OWkWPRK2jNlHb6NGoXfRY1D56POoQPRF1jJ68tL9Y8MvV9K/2J0W9I/3rG7J79KL44viS+HvxpfH34ynxD+LL4h/GU+PL4yviK+Or4qvja+Jr4+vi6+Mb4hvjm+Kb41viW+Pe18gMDtMfhMG4wGVymV2Cy+IS3VUuq8vmsrscLuaudjndNS6Xu9bldnlcXpfP5XcFXEEXOnLWsYtcIVfYxd11roi73hV1xVxxV8I5V9KVci1cS9fStXKPuNaujWvrHnWPusfcY+7xhF8Ld53cU66ze9p1cc+4Z9yzrpt7znV3z7se7gXX0/VySS7J9XF9XF/X1/V3/d1AN9ANcoPcYDfYDXFD3DA3zA13w90IN8KNdCPdaDfajXFj3Dg3zk1wE1yyS3aT3CQ32U12U9wUN81NczPcDDfLzXKz3Ww3181189w8t8AtcIvcIrfELXFL3VKX4lLcMrfMpbpUt8KtcKvcKrfGrXHr3Dq3wW1wm9wmt8VtcdvcNrfdbXc73U632+12e91et8/tc/vdfpfm0twBd8AddAfdIfeFO+y+dEfcV+6o+9odc9+44+5bd8KddKec16fd9+6MO+vOuR/cefeju+B+chedd8mxN2OTYm/FJsfejk2JTY1Ni02PzYjNjM2KvRObHZsTmxt7NzYvNj+2ILYwtii2OLYk9l5saez9WErsg9iy2Iex1Njy2IrYytiq2OqY9wW2R76QL+zj/jpfxF/vi/pivrgv4Z0v6Uv5G3xpf6Mv42/yZf3Nvpy/xZf3FXxF38Q39c18c9/Ct/QP+1b+Ed/at/Ft/aO+nX/Mt/eP+w7+Cd/RP+k7+ad8Z/+07+Kf8V39s/N/7bLv4V/wPX0vn+R7+z7+Rd/X9/P9/QA/0L/kB/mX/WD/ih/ih/ph/lU/3L/mR/jX/Ug/yo/2b/gxfqwf58f7CX6iT/Zv+kn+LT/Zv+2n+Kl+mp/uZ/iZfpZ/x8/2c/xc/66f5+f7BX6hX+QX+yX+Pb/Uv+9T/Ad+mf/Qp/rlfoVf6Vf51X6NX+vX+fV+g9/oN/nNfovf6rf5j/x2v8Pv9Lv8br/H7/Uf+33+E7/ff+rT/Gf+gP+LP+g/94f8F/6w/9If8V/5o/5rf8x/44/7b/0Jf9Kf8t/50/57f8af9ef8D/68/9Ff8D/5i/I3a0IIIYQQ/xR9mf29/87/qV+3dH0AINuOfIf/es5NuX8Z91P7OsYA4IleXRv8tjVokJSU9OuxqRqCwgsBIHYp/+fvH/g1Xg5t4THoAG2g9N+tr5+q+PN93383f/xmgESALL/lpD8eJcJfz3/jP5i/yXt8ufkXAhQtfCkn/US/xZfmL/MP5t/T7jLzZ/k8GaD1f8nJCpfiS/OXgkfgSejwuyOFEEIIIYQQQohf9FPnu13u+Tb9+Ty/uZSTGS7Fl3s+v4zKf8QahBBCCCGEEEII8d97+rnujz/coUObzv/Jg8x/jjL+BAMEgD9BGTL48w+u9G8mIYQQQgghxB/t0k3/la5ECCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYTIuP79bwhT//TBV3qNQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghhBBCCCGEEEIIIYQQQgghxJX2fwIAAP//5g1V0w==") openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='memory.events\x00', 0x26e1, 0x0) pipe(&(0x7f0000000440)={0xffffffffffffffff, 0xffffffffffffffff}) r2 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000140)='memory.events\x00', 0x7a05, 0x1700) splice(r0, 0x0, r2, 0x0, 0x88000cc, 0x0) fcntl$setpipe(r1, 0x407, 0x8900003) write$eventfd(r1, &(0x7f0000000000), 0x8) 8.815685656s ago: executing program 3 (id=966): r0 = io_uring_setup(0x38cb, &(0x7f0000000300)={0x0, 0x142a, 0x40, 0x1, 0x3d3}) r1 = syz_usb_connect$hid(0x0, 0x36, &(0x7f0000000100)=ANY=[@ANYBLOB="12013f00000000407f04ffff000000000001090224000100000000090400001503000000092140000001220f000905", @ANYRES16], 0x0) syz_usb_control_io$hid(r1, 0x0, 0x0) syz_usb_control_io$hid(r1, &(0x7f0000000280)={0x24, 0x0, 0x0, &(0x7f00000001c0)={0x0, 0x22, 0xf, {[@local=@item_4={0x3, 0x2, 0x0, "2e2b5aa4"}, @local=@item_4={0x3, 0x2, 0x0, "f85edaca"}, @main=@item_4={0x3, 0x0, 0x8}]}}, 0x0}, 0x0) r2 = syz_open_dev$hiddev(&(0x7f0000000540), 0x0, 0x0) readv(r2, &(0x7f0000000680)=[{&(0x7f0000001580)=""/4083, 0xff3}], 0x1) close_range(r0, 0xffffffffffffffff, 0x0) 7.720091211s ago: executing program 1 (id=957): syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./file2\x00', 0x404, &(0x7f00000000c0)={[{@nojournal_checksum}, {@grpquota}, {@debug_want_extra_isize={'debug_want_extra_isize', 0x3d, 0x68}}, {@mb_optimize_scan={'mb_optimize_scan', 0x3d, 0x1}}, {@block_validity}, {@dioread_lock}]}, 0x3, 0x439, &(0x7f0000002380)="$eJzs3MtvG0UYAPBv105LXyRU5dEHECiIikfSpKX0wAUEEgeQkOBQjiFJq1K3QU2QaFVBQKgcUSXuiCMSfwEnuCDghMQV7qhShXJp4WS09m5iO3aauE5c8O8nrTuzO9bM592xZ3a6CWBgjWYvScTuiPg9Iobr2eYCo/V/bi1dmf576cp0EtXqW38ltXI3l65MF0WL9+0qMuWI9LMkDrapd/7S5XNTlcrsxTw/vnD+/fH5S5efO3t+6szsmdkLkydPHj828cKJyed7EmcW180DH80d2v/aO9femD517d2fv02K+Fvi6JHRtQ4+Wa32uLr+2tOQTsp9bAgbUqp30xiq9f/hKMXKyRuOVz/ta+OATVWtVqsPdD68WAX+x5LodwuA/ih+6LP5b7Ft0dDjrnDjpfoEKIv7Vr7Vj5QjzcsMtcxve2k0Ik4t/vNVtsXm3IcAAGjyfTb+ebbd+C+NxvtC9+ZrKCMRcV9E7I2IExGxLyLuj6iVfTAiHtpg/a2LJKvHP+n1rgJbp2z892K+ttU8/itGfzFSynN7avEPJafPVmaP5p/JkRjanuUn1qjjh1d++6LTscbxX7Zl9Rdjwbwd18vbm98zM7UwdScxN7rxScSBcrv4k+WVgCQi9kfEgS7rOPv0N4c6Hbt9/GvowTpT9euIp+rnfzFa4i8ka69Pjt8Tldmj48VVsdovv159s1P9dxR/D2Tnf2fb6385/pGkcb12fuN1XP3j845zmm6v/23J2037PpxaWLg4EbEteb3e6JX9pYuTLeUmV8pn8R853L7/742VT+JgRGQX8cMR8UhEPJq3/bGIeDwiDq8R/08vP/Fe9/Fvriz+mQ2d/5XEtmjd0z5ROvfjd02Vjmwk/uz8H6+ljuR71vP9t552dXc1AwAAwH9PGhG7I0nHltNpOjZW/z/8+2JnWpmbX3jm9NwHF2bqzwiMxFBa3OkabrgfOpFP64v8ZEv+WH7f+MvSjlp+bHquMtPv4GHA7erQ/zN/lvrdOmDTdbeOlva8HcDW87wmDC79HwaX/g+Dq03/39GPdgBbr93v/8d9aAew9coNr/nfBAMGhPk/DC79HwaX/g8DaX5H3P4heQmJVYlI74pmSGxSot/fTAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAL3xbwAAAP//1Xjmag==") r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000840)='memory.events.local\x00', 0x275a, 0x0) write$binfmt_script(r0, &(0x7f0000000040), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r0, 0x0) fdatasync(r0) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x15) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) 6.624697926s ago: executing program 3 (id=967): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) mmap(&(0x7f0000000000/0xff5000)=nil, 0xff5000, 0x2, 0x4c831, 0xffffffffffffffff, 0x0) mbind(&(0x7f0000000000/0x600000)=nil, 0x600000, 0x1, 0x0, 0x0, 0x2) madvise(&(0x7f0000000000/0x600000)=nil, 0x600002, 0x9) 6.606978904s ago: executing program 1 (id=970): r0 = socket(0x2a, 0x2, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000400)={&(0x7f0000000a80)=@deltfilter={0x24, 0x2d, 0x10, 0x70bd2d, 0x25dfdbfc, {0x0, 0x0, 0x0, 0x0, {0x6, 0x4}, {0x6, 0x4}, {0xfff3, 0x5}}}, 0x24}}, 0x0) getsockname$packet(r0, &(0x7f0000000200)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000040)=0x14) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000140)=@newqdisc={0x58, 0x24, 0xf0b, 0x13, 0x0, {0x0, 0x0, 0x0, r1, {0x0, 0x5}, {0xffff, 0xffff}, {0xffff}}, [@qdisc_kind_options=@q_sfb={{0x8}, {0x2c, 0x2, @TCA_SFB_PARMS={0x28, 0x1, {0x1ff, 0x4, 0x10001, 0x5902, 0x7f, 0x400, 0x800, 0x2, 0xffff294f}}}}]}, 0x58}}, 0x8000) sendmsg$nl_route_sched(r0, &(0x7f0000000340)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000640)=@newtfilter={0x24, 0x2c, 0xd27, 0x0, 0x0, {0x0, 0x0, 0x0, r1, {0xe, 0x9}, {0xfff3, 0x5}, {0xe, 0x2613a1b406814a86}}}, 0x24}}, 0x44804) r2 = socket$netlink(0x10, 0x3, 0x0) sendmmsg(r2, &(0x7f00000002c0), 0x40000000000009f, 0x0) 6.33623032s ago: executing program 1 (id=975): syz_mount_image$btrfs(&(0x7f0000005100), &(0x7f0000000000)='./file1\x00', 0x810, &(0x7f00000000c0), 0x1, 0x5101, &(0x7f0000005140)="$eJzs3U+IVVUcB/Dz5s04k4LzEgJbZRFItXBwExHRUyaoKHrlYjACpxZBunASJFoIYov+LXwlRS0kV1KLZBZGUBsXUhiB29AwF24UA8lFO4159547753ru+/NpI3p5yMz9577u+fc8x538b7PufcGAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACCG88Ptnh6rqp65Nnzk309x5YMvM5X3T606HUOtsr+X1HVuffeXNbTtenIgdZl/Olo1GvyGzruezxqqejQv9en9eDyGMJQPU8+Uza0qjdq/uKQ9Y6frF3Uc37W1uPH64Xb966ezJ8ktnwcRKT2Cl5OfVhcVzqdn5PZLsUbS7Tr1azyma9U9PuP/kRQAASzLV6iyKj6P5R9yivT+tJ+1m0m4n7fgJod3dWI5s3FX95rkhra/QPJtZVBjvO8+knr//RbuV9k/aSdRYwjx7d80jzUS/ec4l9ZWaJwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMDt5JG3Rx+qqp+6Nn3m3Exz54EtM5f3Ta87HUKjs72WlWur3z/c/OvbrccO/Lj5q+MXnn+s3tncLPqPdu0cfosrT0yG8EZX5UIc9uLaEFq9hU4zfFkuvNVZeS4WAAAAuJPc3/k9UrSzODjW06510mSt8y/KwuL1i7uPbtrb3Hj8cLt+9dLZk8sfr9VnvOYNxyvajcWfWlcwjvE3HW+xHnfdUxqnWjpimucfPz/1d1X/Uv5vVOf/+M7V86X8DwAAwHLI/+k41Qbl/+9e++OTqv6l/L+h55Cl/B9nHPP/SFhe/gcAAIDb2a3O/83SONUG5f/xl8a+rupfyv9Tw+X/0e5px42/xgnvmgxhatDUAQAAgD7i/7svfrUQ83r2zUGa15969OC5qvFK+b85XP4fu6mvCgAAAPg3jnyx/eGqein/t4bL/+O3dNYAAADAUrzz4cQHVfVS/p8dLv+vzpf5lQ9Zp5/iXyEcmgxhYmFlLiv8HNpPFwUAAADgJok5/c9Pd/5QtV8p/89V3/8/3ukgXv/fc/+/0vX/XYXsrn9PujEAAAAAd6Py9fzx9vjZkwtu/Pz94a//f+Ceg69WHb+U//cPl//r3cub+fw/AAAAWIb/2/P/tpfGqTbo/v/3ffTuL1X9S/m/PVz+j8s13S/vRK2WvT/vTYawfmElv5vgN/Fwu5LC/FhXoaOV9NgWe+SF+fGuQsdc0mPzZAgPLqzsTwr3xkI7KVxZmxeOJIXTsZCfD0XhWFI4Ec+0z9fm000L38dCfoHFfLyCYk1xSUTS42q/HguFG/Y4WxwcAADgrhLDc55lx3qbIY2y87VBO6wetMPIoB3qg3YYTXZId+y3Pcz2FuL29pmNS3v+/5Hh8n98K1Zli37X/4d4/X/+XMPi+v/ZWGgkhflYaKV3DGjFY2Rh9+N4jEYr73FlfVEAAACAO1r8XqC+wvMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD4h717j5Grug8HfvY53ofXC8lPIfyiZJPUOG7i9domJGqpsqZUjUhp1g0FVRHFxl6TxQt2bFNiFCJjE9EIQWmDlPxRhFEU1fwBtQIRSQHhIsURKo+IqiiAQKE1REGklCQiTZBCNXvvmb1z7s7DjzVe+Hwk75yZ73neeXjOvXfOBQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA4J3h4Fev/ttm8Ud+d+4zz180fvmetRe9cu25pz4RwsTM4x1ZuKP/htvGf3HXOXfvuX/17fcePu+jvXm5PB4Gqn868zvXx1oPLw7hvo4QutPAisEs0JPfH4z1vW8whFPCbKBWYrI/K5E2HH7QF8K+MBuoVfX9vhAGC4ELnnz4oZuqiVv7QlgaQqikbTxXydroSwNn9GaB/jSwtTsL/PrNTC3wvc4sAMcsvhlqL/oDE/UZhucu1+D113PcOvbWSofXFRPDjfP9fO08d6qgN31g4pietlJ1zIvS2+Ogd9sCeLeVtvMtnrbiF6n8G8qbs6FK6Nw0uXnDVdM74yOdYXS0q1FN8/Q8P/3alzceSXrBvA5jB4aPy+vw5seX3tW1/PzH7l2x9KX9H9v78rF288eFTVpMz7dKyF9zC+Z5jMZ9niyAt1/pW9KIL10hhM1f+L3PNouX5v/Dzef/8eUcbzvrcsda3xjK5ubxkcGYeHUom5sDAADAgrEQ9ppuHX3wk83qK83/R9o7/h8P+eeT+Wy0B0MYn0nsXRLCaTOPZ4E7Y3OXLgnhgzOpifrA2iRwMIT3ziSW16pKSiyKJUaSwE+H8sB4EjgUAxNJ4NsxcEsSuD4GDiSBjTFwMAmcEwNhqn4cvz+Uj6PtQF8MrM824oF4FsIvh2JrybZ6tlYVAADAcZLPDnvq7xbOdTjWDHF6eaCvVYZ4BnbDDJWkhnQGW5tWNayhu1UNna1qqI17d/Phl2ruaFVz6TSMjvoMt/3qbz4XmijN/8eaz/8rc3Sko3T8P4R1M39j7s48Ml2Lr5+oywAAAAAcg4H/feFbzeKl+f94e+f/x30iXYXM4dG4G2LLkhDG6gNZtX9YDmRHvQfyAAAAACwEtePxtWPhU/ltdop2Op8u5584wvzxwP/4nPl7Dz6wvll/S/P/ifbO/++vv806cSj24utLQlhUCPww9rIamDESAz/5VH0gH/+huAFujFXlJybUqroxllgfA2NJYF+jEj+qlTitPpA/WbXG99bGMZWXKAQAAADghIu7A+Jx+Xj+/4d+u/rqZuVK8//1R3b+/8w8uHR6//RACCu7Q+hKfxjwaH+2MGAMDHbkiQf7s7q60qqu6w/h7OrA0qpeyNf/707XGHyyL6sqBk770P7XzqgmvtUXwspi4KnP3/HxamJnEqg1/pd9IXygOtq08e8uyhrvSRv/xqIQ3l8I1Kq6dFEI1cZ606oeruTXMUir+udKCO8qBGpVnVUJYVcAYIGK/5VuKj64Y9c1WzZMT09un8dE3IffFzZPTU+Obtw6vanSoE+bkj7XLWN0XXlM7V755tl8iaIL71k32E669jvBsWJb+X780omD+f34XahnZpyre+rurkmH/JEPl5sIhW9SjYbcOc9D7i9WMvskluqP+XvDQFh01Y7J7aNf2rBz5/ZV2d92s6/O/sbDTNm2WpVuq/65+tbGy6PhalmJo91Wy4qVrNx5xbaVO3Zds2Lqig2XTV42eeWqs1aPnTm2ZuwTZ66sjmos+9tiqMvmqjoZ6pt3tDmu4zjU07sLlZyITw0JCYmFltg6sKzp/8ml+f+25vP/+KkTP/nz9RkaHf8fjof5s8dnD/Ovj4F97R7/H250NL92YsBIEtgdA7sd5gcAAODtIU7y497MuFf6Z8u/+1KzcqX5/+72fv9/nNb/ry1df16jZf6XxxJjjdb/T5f5r63/v7vR+v/pMv+19f/3vQXr/19VCySb5JfW/wcAAN4OTtz6/y2X908vEFDK0HJ5//QCAaUMLZfxb/cCAUe8/v9z//lX/x2aKM3/b2lv/m/hfgAAADh5fOXPrv5/zeKl+f++9ub/J379v9Do/P+RRoGJRgsDWv8PAACABarR+n/DN/Rf0qxcaf5/oL35fzztorMud6z1jaFsTbuQrmn36lDtJwMAAACwMHSG0dGeNvPWrYy69ujbfDpfCrRZuuiFPzl8ZOf/H2xv/l/3u4ybH196V9fy8x97494VS1/a/7G9L88e/wcAAADmT7v7JQAAAAAAAAAAAAAAgLfeC/+xZ02zeOn3/2HdzOONfv8fr/sXf1/w7rrcsdbW6//l9y/4zN27ZpYsfHQohA8XA1v2bDkl5NfmX1YMPHTx8vdUE3vSEg88f86L1cQlaeDTK059vZo4Owmsj4skvjcNxKsqvr44CcTlFf89DcTtcSAN9OaBry3OxtGRbqufDWbbqiPdVs8MhrCkEKhtq/sGszY60gHemgRqA/xiGogD/PM80Jn26u6BrFcxMBiL3j6Q9QoAgJNW/BbYEzZPTU+Oxa/w8fb07vrbqG7JsuvK1Xa02fyz+dJkF96zbrCddFf6XXT2WuM9oVIdwqrS19Vilo6ZUR6fWlpsunc3GHKr1d46G5RLHemm6208or5sRKMbt05v6mk58DWts6zubpllVWmyU8zSObNJ26iljb60MaI2t00bXY73O8PoaFeS6w9icDjUafWKaPf3+sV1/hq9Cop5rjy899fN6ivN/4fbm/9XiuN6Pb8YwO54Zb2/W2KZfwAAAJhfX1v7m2/Gf5+74ZGnmuUtzf9H2pv/xz1Y+aHgbG/HwXj9/71LQpi5tP5wFrgzNnfpkhA+OJOaiCWyC+qfF0uMZYE74w6T5bHE+on6qhbFwIEk8NOhPHAwCRyKgXwvxf6Q78r5+6EQPj6TWldfYlssMZwEPhsDI0lgNAbGksDiGBhPAq8szgMTSeDfYiBM1W+rexbn2woAAOBI5POsnvq7IZ3nHehulaGjVYb+Vhk6W2WotMrQaBTx/ndihp7k5JWOQqaetNa+pJZShngx/CPuVylD+FF9zrRgeprAgXj+Qe18g476mu//ZHclNFGa/4+1N//vr7/NWj8U5/+z1//LAj+M3ft6PHV8JAZ+8qn6QL5j4FCc7N5Yq2oiL5FP2m+MJcZjYCQJbIuB8SSwfl0e2Pee+kA+0641vrfW+FReohAAAACAEy7uIIi7aeL8//YdXx1oVq40/x9vb/4f2xsoNnZ9rPXw4hDu65jtTS2wYjALxP0Yg/Hn8e8bDOGUwg6OWonJ/qxEb9Jw+EFf9gv13rSq7/dlPz6I9y948uGHbqombu0LYWlh70utjecqWRt9aeCM3izQnwa2dmeBuOenFvheZxaAY1bb2xdfUPmpLjXDc5dr8Pp7u1wTNB1eaR/oHPnm+s3VfCntcM33qdYc2dPWdP8tx03p7XHQu20hvtuG34nvtr70gdoXqfwbypuzoUro3DS5ecNV0zvjI8VfspbM0/Nc/JVqO+nj8DrcffS9ba2SdmAs+fgYm7vc3K/DjljdzY8vvatr+fmP3bti6Uv7P7b35ba70UD8ofDD1/7r4I8Lm3e+VUL+mltwnycT78TPk5IF97SNeNpCCOte+caNzeKl+f9Ee/P/7uR2xm/ixtyxJISPFDbuo3Hz//GS7HOwEMg+Jd9VDmSH3P9rqOEnJwAAABxvtd0dtf0FU/ltdkJ4Ok8u5584wvxxf8X4nPnb7Xf/X1+8tFm8NP9f33z+vyjppuP/jv8zTxz/n9PJvit6UfrA7mPaFV2qjnnh+P+cTvZ3m+P/c3L83/H/uTj+34Lj/3M62Z+20rekbb50hRBe+qMHn2kWL83/t7U3/7f+39yL9tXW/1vfaP2/bY3W/9tt/T8AAGBeNVhoLp3nlVbvK2VIV+8rZWi5QGDLJQat/1dqutX6fy+e/txvQxOl+f/u9ub/8eUwUGx9oaz/N7KuQVW3xMA2CwMCAABwMmq0gwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIC31v3/8D+bmsUf+d25zzx/0fjle9Ze9Mq15576RAhTM493ZOGO/htuG//FXefcvef+1bffe/i8j1bycj357f+vyx1rfWMohH2FRwZj4tWh6p3ZwAWfuXtXdzXx6FAIHy4GtuzZcko18e2hEJYVAw9dvPw91cSetMQDz5/zYjVxSRr49IpTX68mzs4DHWl3/3Fx1t2OtLs3LQ5hSSFQ6+7li+urqrXxp3mgM23jnwazNmJgMBb95mDWRgxMxxJTi0JY2R1CV1rVI5Wsqq60qn+pZFV1pVV9pRLC2SGE7rSq53uzqrrTkT/Rm1UVA6d9aP9rZ1QT+3pDWFkMPPX5Oz5eTXwxCdQa/4veED5QfcmkjX+nJ2u8J2381p4Q3h9C6E1L/Ko7K9GblnihO4R3FQK1xr/QHcKuwNtC/PCp+0TbseuaLRumpye3z2OiN2+rL2yemp4c3bh1elMl6VMjHYX0m9cd/diffe3LG6u3F96zbrCddHdermemy6t76u6uOdl7H/vVX6xk9vko1R/z94aBsOiqHZPbR7+0YefO7auyv+1mX5397cqj2bZatVC21bJiJSt3XrFt5Y5d16yYumLDZZOXTV656qzVY2eOrRn7xJkrq6May/4ej6HeceKHenp3oZIT8QEgISGx0BKddZ9uYyf7B3npi/5sR3tCZeYDujStKGbpmBnl8Rj02qMc8dF8T2k5olWliUMpy+o5slxXn2VNaTIxW0tflmXme11pclhsrHNmk8b7nWF0tKvRdhiuv1vcvD8/hs37dL7p2k0DAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPB/7MCBAAAAAACQ/2sjVFVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVWEHDgQAAAAAgPxfG6GqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqoKO3AsAAAAACDM3zqMng0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAuBQAAP//O24jzg==") r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000001c0)='cpu.stat\x00', 0x275a, 0x0) write$binfmt_script(r0, &(0x7f0000000040), 0xfd12) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r0, 0x0) sendmsg$NLBL_CIPSOV4_C_ADD(0xffffffffffffffff, &(0x7f0000000580)={0x0, 0x0, &(0x7f0000000540)={&(0x7f0000006040)=ANY=[@ANYBLOB], 0x14}}, 0x0) prlimit64(0x0, 0x6, &(0x7f000000cb40)={0x3, 0x5a}, &(0x7f000000e680)) fdatasync(r0) 5.833701583s ago: executing program 0 (id=989): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000300)={0x18, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="180000001800ff0f00000000001b0000850000006d00000085"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x28, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000080)='sched_switch\x00', r0}, 0x10) r1 = gettid() r2 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000080), 0x2082) read(r2, &(0x7f0000000100)=""/140, 0xde) ioctl$SNDRV_SEQ_IOCTL_REMOVE_EVENTS(r2, 0x4040534e, &(0x7f0000000040)={0x197, @tick=0x8, 0x0, {}, 0xff, 0x2}) tkill(r1, 0x7) ioctl$SNDRV_SEQ_IOCTL_QUERY_SUBS(r2, 0xc058534f, &(0x7f0000000240)={{0x8, 0x7}, 0x1, 0x50ec, 0xdf, {0x3e, 0x6}, 0x3, 0x9}) 5.281689489s ago: executing program 0 (id=994): syz_mount_image$ocfs2(&(0x7f0000004440), &(0x7f0000000040)='./file1\x00', 0x8c0, &(0x7f0000000400)=ANY=[@ANYBLOB="61636c2c6865617274626561743d6e6f6e652c6e6f757365725f78617474722c636f686572656e63793d66756c6c2c646174613d77726974656261636b2c6c6f63616c616c6c6f633d30303030303030303030303030303030303030312c61636c2c6e6f61636c2c6c6f63616c616c6c6f633d30303030303030303030303030303030302c00a89f6b8d5800aa954e6c8735dcd52921ce08462fb4ce7c1600883251443ac332f4d17b77d29867e4321610916dbc5963e9fb59a032c92e32ebffc3b739951e866d52bff6bd63136a656222062a8eea0cf97480bc8ac6c0e8a2aa38ffa8fa758cd54b9ef39a7f536d7b85173a83c34d78e210ecf4d040817bbe989e9eb015acb84b99b2ed90f71810cd92eeca69f5275cb7b7027d4babf643bd69b0a68134c022fe5dcd03834f547325ac2d1a5d16f074d898946ff71afa90180b317e645dd58a922e5d907462cd50dc23801c48c0d49ab012961d84d2eb85a3730a3f3177da048c3bc991216b11dca020afefc24ae7583b59534a0ab1fca82bf473216141db8e9864f7861d0500a920e1a8d3352d0662f586e743386e87b6c0c5ed6e4d192ef2990b44cedbb708e7a18b20dcd5573b603c4d659992647ffa8210abf4e9d232b52a8ea1dd1c045afd8e472cd1fbb775e89cca49d136a6"], 0x1, 0x442d, &(0x7f0000004480)="$eJzs3c9PHGUfAPBnBvoW+rZ9oW8PfZM3cRObaNQQ6EmliZTSUmixptrGeNkusG3RhW1gMR56wFsTTyYejIdGE2+cGg5e65/gxWM9N9GDFxOTRszuzgIz7IaVsGDr53NgmOc3fGeefeYw+8SJyp25pdzcUq6wkCvP3Fo6k/u4XFqeL4Z4nzTt/9D+9U97OnGdHPS190929fzFd2+cCeH72R+frK+vr4eq7tDU0Jbff/v13szWY0OcqVNtt3lre+WDEMLJbeOq6gohvP9dCFEI4VySNpoce0MIx0I978a9z27m9mg0Dx8Xz+afTt1fGz49ufpgrfXfHoXwVel/r92e//nFruGfXtmj7gEAAAAAAAAAAAAAAAAAeMaNX7t6/Z3BofAoCt2r0fb3dceTY6v3Y9f3zAsh9HX+7wUAAAAAAAAAAAAAAAAAAIC/o833/3PRiSbv/48lx5EW9dff6vwY6ZyJt6+OXRgcSvZ/j7blv54k/XKuK/Q32fc9u//7uUz95vu/b+9ntxrja/TbF6J4IHUexwMDIXyTbPx+KjoSl8pLlVdvlZcXZvdsGM+sdPzru/enopNs6N9u/Ecz7Xd+////bruaquc39+4Se66l49/Vsty3n0Ztxf98pt5+xJ/dS8e/u5bWu7XASH0CqMb/8+6d4z+Wab9T8T8eQshF1bHmUjNAdQ1TTW+1XiEtHf9DtbTU1Jn8I1vd/79n4n8h0/5Bzf8r2Q8imkrH/1+1tJ5Uic37vz/e+f6/mGn/IOJfHf+Kz/+2pON/uJ7YnSpS+0+2O/+PZ9rvVPyvx8k4j0epK2A1qqe3+r460tLx79mWv/n8F7e1/ruUqb9fz3+NfhvPf43p/+Wo/vxHc+n497Ys1+79P5Gp1+n5f6S2/mO30vE/UktLr53rX8rZbvwnM+13Kv61VUlPI/6b88kfh+vpX1v/tSUd/3/XE+OtJVZqP2vrv2jn9f/lTPsHsf6rjn8l7myvz4t0/I+2LFeN/w9tfP5fydTrfPxDGLTW37V0/I+1LFe7/3t2jv9Upl6n4/9SJxsHAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAeAaMJse+EMUDqfM4HhgI4XxyfiociaYLs/npUnnmo6UQxpL0XDgR3S6Vpwul/NxCebaYL5RK5ZkQLiT5J0NPtFQqV/LzhbsXN9rqje4UC4uV6WKhEkIYT9L/H4412pqeq8wX7oYQLm3k/ScuL969U1jIz84tvjk4ODgYJjbG0B8VP6kUFyr13uu5IUxu1O2Ltgyuln15YyxHow/Ly4sLhVIt/cqWOqXyTKG0pc5UkvdF6I8qi8sLM4VKMV8q3270d5BGkuPYxLX3rl0Z2pZ/M6ofR/d3WAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD8RY+G3/gyhNBdP4tDCCONX6Jm5R8+Lp7NP526vzZ8enL1wdqTVuUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADgT3bgQAAAAAAAyP+1EaqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqwS8coDQRRGIDfjIXaeQyrZbezXVFEC1cET6DH8DB6FC/hHVKkSJsiBJJZCJtd2Capvq95MD8z78E8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYJ6n9+7jrW4iUlxtLiP+vv4Xh/lLqT/34/cvzjAjp/P82j081k3593SU35WjZZt36Xr1/Rkjtfc72JPhPu31fa4n55rat6n5+r43kXIVEW3Jb1POVTXvLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAtO3AgAAAAAADk/9oIVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVdiBYwEAAAAAYf7WUfRtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPwKAAD//+UFHyA=") mknod$loop(&(0x7f0000000000)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', 0x0, 0x1) creat(&(0x7f0000000e00)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', 0x0) creat(&(0x7f0000000e00)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', 0x0) symlink(0x0, &(0x7f0000000000)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00') r0 = open(&(0x7f00000000c0)='.\x00', 0x0, 0x0) lseek(r0, 0x7ff, 0x1) getdents64(r0, 0x0, 0x10) 4.894411348s ago: executing program 6 (id=981): bpf$ENABLE_STATS(0x20, 0x0, 0x0) bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000340)={0x2, 0x4, 0x8, 0x1, 0x80, 0x0, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000340)=ANY=[@ANYBLOB="05"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000001070000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000180)={{r0}, &(0x7f0000000000), &(0x7f0000000080)}, 0x20) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x16, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000000)={r1, 0x2000000, 0xe, 0x0, &(0x7f0000000200)="63eced8e46dc3f0adf33c9f7b986", 0x0, 0xfffffffe, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) 3.91830868s ago: executing program 4 (id=984): r0 = socket$tipc(0x1e, 0x2, 0x0) setsockopt$TIPC_GROUP_JOIN(r0, 0x10f, 0x87, &(0x7f0000000040)={0x41}, 0x10) r1 = socket$tipc(0x1e, 0x2, 0x0) setsockopt$TIPC_GROUP_JOIN(r1, 0x10f, 0x87, &(0x7f0000000280)={0x41}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$tipc(&(0x7f00000000c0), 0xffffffffffffffff) sendmsg$TIPC_CMD_SHOW_NAME_TABLE(r2, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000600)={0x30, r3, 0x1, 0x0, 0x0, {{}, {}, {0x14, 0x19, {0x3, 0x1, 0x1}}}}, 0x30}}, 0x0) 3.684988011s ago: executing program 3 (id=986): r0 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$sock_int(r0, 0x1, 0x3c, &(0x7f0000000040)=0x1, 0x4) setsockopt$inet_tcp_TCP_REPAIR(r0, 0x6, 0x13, &(0x7f00000000c0)=0x1, 0x4) connect$inet(r0, &(0x7f0000000080)={0x2, 0x0, @loopback}, 0x10) setsockopt$inet_tcp_TCP_REPAIR(r0, 0x6, 0x13, &(0x7f00000001c0)=0xffffffffffffffff, 0x4) capset(&(0x7f00000003c0)={0x19980330}, &(0x7f0000000400)={0x3, 0x7, 0x1, 0x3, 0x8001, 0x401}) sendmmsg$inet(r0, &(0x7f0000000d00)=[{{0x0, 0x0, &(0x7f0000002c00)=[{&(0x7f0000001500)="b25b365c0254", 0x6}], 0x1}}, {{0x0, 0x0, &(0x7f0000002f00)=[{&(0x7f0000001580)="ce90bfdb", 0x4}], 0x1}}], 0x2, 0x4000000) 3.578587504s ago: executing program 1 (id=987): pipe(&(0x7f00000001c0)={0xffffffffffffffff, 0xffffffffffffffff}) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) writev(r1, &(0x7f0000002a80)=[{&(0x7f0000000a00)="1b", 0x1}], 0x1) pipe(&(0x7f0000000380)={0xffffffffffffffff, 0xffffffffffffffff}) splice(r3, 0x0, r4, 0x0, 0xf3a, 0x0) write$cgroup_pid(r4, &(0x7f0000000000), 0xffffff98) splice(r0, 0x0, r4, 0x0, 0x80, 0x6) write(r2, 0x0, 0x0) 3.420033952s ago: executing program 6 (id=991): r0 = syz_open_dev$loop(&(0x7f0000000480), 0xd76, 0x181400) mkdir(&(0x7f0000000040)='./file0\x00', 0x0) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) mkdir(&(0x7f0000000440)='./file1\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000240), 0x0, &(0x7f0000000500)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) chdir(&(0x7f0000000140)='./bus\x00') r1 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000140)='cgroup.stat\x00', 0x275a, 0x0) ioctl$LOOP_CONFIGURE(r0, 0x4c0a, &(0x7f00000002c0)={r1, 0x0, {0x2a00, 0x80010000, 0x0, 0x2, 0x0, 0x0, 0x0, 0x10, 0x1c, "fee8a2ab78fc979fd1e00d96072000001ea89de2b7fb0000e60080b8785d96000100", "2809e8dbe108598948224ad54afac11d875397bdb22d0000b420a1a93c5240f45f819e01177d3d458dd4992861ac00", "90be8b1c551265406c7f306003d8a0f4bd00"}}) 3.414144428s ago: executing program 4 (id=992): r0 = socket$inet6_icmp_raw(0xa, 0x3, 0x3a) r1 = openat$udambuf(0xffffffffffffff9c, &(0x7f0000000440), 0x2) r2 = memfd_create(&(0x7f00000009c0)='y\x105\xfb\xf7u\x83%:r\xc2\xb9x\xa4q\xc1\xea_\x8cZ7\xe7a\x9b\x11x\x0e\xa1\xcf\x1a\x98S7\xc9\x00\x00\x00\x00\x00\x00\a\x00\x00\x00\x00\x00\x00\x04\x879\xa24\xa9am\xde\xb2\xd3\xcbZJoa\xc4\x1acB\xaa\xc1\xfb Q\xd4\xf4\x01\xa52\xe2DG\xd4\xbd{\x9f\xa9\x97\x9b@\xdbU\xb1\xe1br\xb6\x008\xe3\x10\xff\xc2\x9d\r2\x9e\x8e\x04sW\x1b\xb7\xb3\xa2\xc9&@\xca\xda\xdc\xe2/\x97X\xac\b\xb0\xc2<\x80E\x1a\xbc\xc7W\xda9VsA\xaf\xc6\x90i\xa1\xb5M\xa2\x85\xa6y\xc4J\xf1\xf7\xfcD\x95\xe3\xeb\xc7\xbc\x91\xb0\xa8\x9eo\xebF(\x9dL\x01vRk\xaacB\x04\xa7I\v\x86EZ\x96\xd5\x14O\xf8\xb5C\x1f\xb6b8b\x06A2@D\\\xe8R\xe4\xcd\xec\xcc\xd1\x0fre\xe86\xcd\xeb\xc4$\x98\x06J\xd6dD\x8d_U`ji{\xab\x97\xaf;l\x1f\xaf\xb38U\xcb\xfa\xb3j\x92\f\x81\xa0\xa2-g\b\x99\x0e\x8d\x8d\x16\x05\x00\x00\x00\x00\x00\x00\x00\'\x93\xef\x1d\xa0H\xd9\xbd\xd9\xaf\x12$\x8d\x16%\x8b\x00\x88\xd1\x1eQB\x18\xc1-\xc4\x8fK\xf8\xfa\xb6\xf8\v;\xaa\x8fW\xcc\n\x17\x7f\x98\xb7\xcdqV\xd4\xf0)\xfa\x0fG\xc8\xbf\xfd\xe8>K\f\xcd+\xb0\x99Q\xba/\xa8\xb9`k\b\xd1\xcc\xfc\xeaA\"\v=\x83fC\x90%\xa1d\x91\xf8:\x16<\xad\xc2\x18\xdf\x01\xe2\x96\xfcj\xe9\xa4\x065m\x03\x05Np\xda\"\xf1\xb6\xbcP\x8fP\x8d\x89%\xf2\x12T\xd0\xc3\x15W\x9c\x87\x1b\x8c\xc9\xd9\xc6\xad\x96-d\xa2wFB\xcaB\xa5\x15\xf8,\x04\x1c*\xd98\x8bG\x90\x81`\x03\xe0\xde\x9c\x9a\x0f\x1b\x8f\xd2%*&$Wc\xb3\xa6\xc4TK1}2\xb3\xab\xf4\xb7\xb7\x85\apa\xaf\x1c\x10i\xb9\x9f\x06\xff4%\"7f \x0e\xf5Bk\r\xac\"\x13tNx\xc0$\x85\x9f', 0x3) ftruncate(r2, 0xffff) fcntl$addseals(r2, 0x409, 0x7) r3 = ioctl$UDMABUF_CREATE(r1, 0x40187542, &(0x7f0000000100)={r2, 0x0, 0x0, 0x1000}) ioctl$DMA_BUF_IOCTL_SYNC(r3, 0x40086200, &(0x7f0000000000)=0x3) close_range(r0, 0xffffffffffffffff, 0x0) 3.256133258s ago: executing program 3 (id=993): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = socket(0x10, 0x2, 0x0) sendmsg$nl_route(r2, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000100)={&(0x7f00000000c0)=@getneightbl={0x14, 0x42, 0x89745301ffea7a81}, 0x14}}, 0x0) recvmmsg(r2, &(0x7f0000002ec0), 0x400000000000ec0, 0x2, &(0x7f00000001c0)={0x77359400}) 2.939302241s ago: executing program 4 (id=995): prctl$PR_SET_SECCOMP(0x16, 0x2, 0x0) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000fbff000000000000001d8500000007000000a50000002a00000095"], &(0x7f0000000400)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000002c0)={&(0x7f00000001c0)='kmem_cache_free\x00', r0}, 0x10) capset(&(0x7f0000000080)={0x20071026}, &(0x7f0000000000)={0x200000, 0x200000, 0x0, 0x0, 0x0, 0x1}) r1 = syz_init_net_socket$bt_hci(0x1f, 0x3, 0x1) bind$bt_hci(r1, &(0x7f0000000080)={0x1f, 0xffff, 0x3}, 0x6) write(r1, &(0x7f0000000140)="24000000010006", 0x7) 2.938773391s ago: executing program 0 (id=997): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000840)=ANY=[@ANYBLOB="0a000000050000000200000004"], 0x48) r1 = bpf$MAP_CREATE(0x0, &(0x7f0000000dc0)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000001c40)={0x0, 0x10, &(0x7f0000000180)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b702000001000000850000008600000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x54, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x1, 0x10, &(0x7f0000000180)=ANY=[], &(0x7f0000000980)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) setsockopt$sock_attach_bpf(r2, 0x1, 0x32, &(0x7f00000000c0)=r4, 0x4) sendmsg$unix(r3, &(0x7f00000006c0)={0x0, 0x0, 0x0}, 0x0) 2.925997183s ago: executing program 2 (id=998): mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x10) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mkdir(&(0x7f00000004c0)='./bus\x00', 0x92) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000400)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) chdir(&(0x7f0000000140)='./bus\x00') r0 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) lseek(r0, 0xffffffffffffa937, 0x0) 2.599984254s ago: executing program 6 (id=999): socketpair$unix(0x1, 0x5, 0x0, &(0x7f00000006c0)={0xffffffffffffffff, 0xffffffffffffffff}) sendmsg$inet(r1, &(0x7f0000001b00)={0x0, 0x0, 0x0, 0x0, &(0x7f0000001d80)=ANY=[@ANYBLOB="28010000000000000100000001"], 0x128}, 0x4050) recvmsg$unix(r0, &(0x7f0000000000)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000080), 0x100}, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000100)={0xffffffffffffffff, 0xffffffffffffffff}) sendmsg$inet(r3, &(0x7f0000001b00)={0x0, 0x0, 0x0, 0x0, &(0x7f0000001d80)=ANY=[], 0x128}, 0x0) recvmsg$unix(r2, &(0x7f0000000000)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000080), 0x100}, 0x0) newfstatat(0xffffffff0000005d, 0x0, 0x0, 0x1000) 2.366935278s ago: executing program 4 (id=1000): socket$nl_generic(0x10, 0x3, 0x10) syz_open_dev$sg(&(0x7f0000000500), 0x0, 0x22c00) setreuid(0x0, 0xee00) r0 = syz_io_uring_setup(0xa0, &(0x7f0000000640)={0x0, 0x105cc6, 0x0, 0x0, 0x207}, &(0x7f0000000040)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r1, 0x4, &(0x7f0000000180)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r1, r2, &(0x7f0000000200)=@IORING_OP_READV=@pass_iovec={0x1, 0x0, 0x0, @fd_index=0x4, 0x0, &(0x7f0000000080)=[{&(0x7f0000001800)=""/216, 0xd8}], 0x1}) io_uring_enter(r0, 0x847ba, 0x0, 0xe, 0x0, 0x0) 2.333336226s ago: executing program 2 (id=1001): syz_emit_ethernet(0x4a, &(0x7f0000000240)=ANY=[@ANYBLOB="aaaa"], 0x0) bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000300)=@bpf_lsm={0xd, 0x4, &(0x7f0000000040)=ANY=[@ANYBLOB="760a0000000000006111500000000000979a01"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x20, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000440)={0x8, 0xf, &(0x7f0000000200)=ANY=[@ANYBLOB="1800008080b63428e900"/20, @ANYRES32, @ANYBLOB="0000000000000000b702000014000000b7020000000000008500000051000000bf0900000000000055"], 0x0, 0x7, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x6, @void, @value}, 0x94) r0 = syz_open_dev$loop(&(0x7f0000000100), 0x2, 0x0) r1 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000200)='blkio.bfq.io_service_bytes_recursive\x00', 0x275a, 0x0) write$binfmt_misc(r1, &(0x7f0000000040), 0xe09) ioctl$LOOP_CONFIGURE(r0, 0x4c0a, &(0x7f00000002c0)={r1, 0x0, {0x2a00, 0x80010000, 0x0, 0x2, 0x0, 0x0, 0x0, 0xb, 0x1c, "fee8a2ab78fc979fd1e00d96072000001ea89de2b7fb0000e60080b8785d96000100", "2809e8dbe108598948224ad54afac11d875397bdb22d0000b420a1a93c5240f45f819e01177d3d458dd4992861ac00", "f4bd000000801900", [0x0, 0x2000000000001]}}) 2.170869521s ago: executing program 6 (id=1002): mknodat$null(0xffffffffffffff9c, &(0x7f0000000180)='./file0\x00', 0x0, 0x103) r0 = openat$fuse(0xffffffffffffff9c, &(0x7f00000001c0), 0x2, 0x0) mount$fuse(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f0000000140), 0x0, &(0x7f0000002280)={{'fd', 0x3d, r0}, 0x2c, {'rootmode', 0x3d, 0x8000}}) statx(0xffffffffffffff9c, &(0x7f00000001c0)='./file0\x00', 0x100, 0x800, 0x0) read$FUSE(r0, &(0x7f0000006380)={0x2020, 0x0, 0x0, 0x0, 0x0}, 0x2020) syz_fuse_handle_req(r0, &(0x7f0000002300)="00e7a0633e8438bafa888b9b02144af32e296a0a01dc194d649b6fa26d6d5e63bac4a04baeeb8aacb22c6eec461b67db6a737737c6d2687acb00572f92e3fdb5d0cb2f11121c557a943020200755bcab77b39c406b733239e2bb1175b9322ba39dc7d67da8f77aed1714dae2e6c24c3ea96be9d151c6ab7b3c54bbe507b8b2461fb4be8dc90042184af6d48f8ace16abb5e3fc943cf61cdb75624a259bdb5f7829b9775820f85f2d1a6ee6c6b8a41ecb2612abf13cd2c6f9f3e6db505e4bbe68cc000cf5fa6d5636191a4b366ab59af52132a3f9678d4ed1bd577bacffb3b52850804005eebf3dfa4763168ff30490a11acdbbf4c3312a45f30139f6b72b1e7cdec185006bb30e0e8fa88da2cefc718cae7e9830f7ca101e4e23c6bd16bfacf4a9927fb13af4b79c86ab999beda4ad396abdda354a42fb4ef21d6749175dc21a0cf9191aa4f90d274b50370a580ad8dcd166d2b06c0d8b071973c3fde30f7e2bc371a51ca5866bf8b24eaac75bf482dd4436b214ff62d32e20df223b0b680ede28b3a49e66e330a8a3ecace0db9855d235d5ff23765e742d1a739c2ac8743f4c62664a3b347279da55a1a5b16e1e2828b584a013577d50f890e3894d9e8d6bfccdfb2b70221f12a7fac24b7a8818edce72b65f622c77bf1312771a2c0d805ec9a25c536c91868762032255be78903b77b2c1a773a03996fabba69214e76f5df6df0375b592692a2c3c86c75a3be56fe598ddaea0b9901d20db7e43e128e04e5509283f833c24c625887288459db5727210ba9a301fb8c934dd1d8dca68039fe5b2e1a8d7cdfc6d875e5851098100c3cd42544ed90bb55b58d20a501fabbc485d148c615a3b070fa0520da2ed68ee115a4411d5418b47f3d95616096f67a7a36d68f1e8df82eca8ef96fb4a96b3422fe046a37ea5f5967513a559bd770fecab7228b0692f439765c9e9c6ea4fc608e0b27f9b49064daa2bac06f83f6d87ebc61fa3a29bb5ed39641245ce8cf43770df32a84838802b0827ca5a40e2003915e2ed108a005637bb028d29bd2cfd28a1bd55e67ed1b6b7b72163c27c4b0e36d1b134d6dfdb165a66fb46498fc04bb8053b84098af5b18758631d1318d625a6fa4d3ce5a4d3a90e10c6363a26b5ae96c2d56f87ad21a6118af6847d041f88f852ddc3f250c088ef5cb31198f3ac81cff9a5bab26ed56c09f8416188974e08349f7da28fc754b98c1ac4ea0060ac1e1b1c49f7dbadbc59254b265dc418cab9ac14e2bbecc4c3103543e37984efb1f61315e10d2b422732217d3a9b0cfe4561f3765d3bda60be239e02bdc164dd631582e8c87dd8fa60d63dcf9e7f3dadc4ce5e4433a42425b8ee8cb8a2defab0bf9b6109c90b5655b79b18c06884f2670a985d454e08e54de69f645cb0cbb70620bd988ee717c310ae77b4abe81c01c6e7f47268ee20bc30b9062830917705682eba2c5ef966b877f33294aa5f8b29d3dd5ed92302087f34fa18d19a005de05f925e3e93c8c0f24507ff20cd23d9ae5452c32ff58c78ccdb1ab32c98edfaa6d2c3971934ca8f849ac360c286566eb72b0793f12cef84bd282368d533247ee750f18aeda484167f3d680e4aaa3aa0694441d4ff6a71531f1a30f87eeb71afd04c5d686e1f86f27586f4e2c8ff77c09612ba1af9b3fb93efd31af42f8e0498f35d07c662b743a08f2839cad8f95b90cbb4fc0ed2ca45dd093a549cde4c6ff08ce09a2cbc6f9f78b6f96643357f92f8f403202742057731fd3e343a87c0affe803cfdbddb8c2694ab63f2dc35da705624747e30a943000fc82c40f10e1975d2e2ec15aefd531b6dbc053606b054dc976f44d5b5a5f37e9c08532ce16cf8bca55ab6c814ceb855ab50b8b52620f8645a9dc25fcb732080d84bf39c3ebb235b4d96da527b64ec4b72f69e91d16a4efcaf76f2e1f968ca68a06f60b01ec7becc9ffd7877c0992cb0f80fb3daabc039513896bd7697843be06aba53e7761e11e075c61ef2d897d4d9f90041c14283746feeb3f0d456ba4be27843350fe43e7c1110b4439489139f6dae01c43f23ec71f08d3042663c65e059d368e4e2c6e49de45bf078d3182a1bc1208bc59379e705aa3309579947409f2a8b3d79099c8619f916e7a6fa333d2312a274247156b8c25cbcfcc59ef13339c700f56a8691dff39bd4338789001872c0d90929037dc0ad99b380a6ba73f331f73f9274f4c2bf5233d7482edf37bf6ffed4f2c0ee44a1d57cae0d644f25591dc03bf837571a82d0c31b61be7ff85a5b3843e8f96a50eaa43f5c137ecfc4e4530d08a2afa4ba02fcc50117a4ad0d5862302017639344c82749f673dbd650e49b35302d0acbab45c0973198291bb42b4cfcd3b0c252074341ea8eca19e122cd234da6d41bf5eedb706e16c17687ed8b84db67130796d26b94eac83bbcd785b603242bd6252c155711efd7dd22cc54e1eaf6d910d0f22c701f3d4da0314dd2829c6ee13bbcbd126558b47b8066bf0766c792a012315bd29bfeda8f28a2c1f4e638b701758e19a0e5bd5b4f19048b00a877d956292e345f8a3a8367892f955bcb5e50ca145ec5e2c9309e25941bd277e393aaad38f9b72a42514b27da6856223c37a1fc1327fa760551d3fdeb0b222ab180b16c9eea138cf4f327e88fdfee293c5b6b007028eb796a60772148282dcd17ffc1c90ed8b6540ede933545ed5a5301d6ff39734444ff3d85cda4ac3befa5083a4685e9e231eba4a91a35f4f7f48fd5ac2447c64c010e2a9f8e80691c95460e1995444466ec5f3cd71fe509a26ff0b7f3254bc8c3255e903834e841b37c70b267fb33deb0d1ed4ea84a869453ba508fc255b12cf847103d5195046c930ae4a75c956f22fcfe4186d547686b54bd7a534940d5d62216994eac0e8ed3bd2bd59354e6b9c6b5b10511d54a8b928040f1e1024a423b0cf519fc6e9673df5c48c0778c7edb8fa8d8ace77463a77d2d6313160e1ee72742953e433b6732ced59c93464fd91520847db238610ed0c289fc55647881a7d6257cf28090c75a6f19df079cfd35742a74a5ab270314f7c8039c20ff0f3f543d029b75a741b5dc6425241ac2ffabf1f96288e6d4ba34da09fb6049c2c8753fbd41fdb4bc68c57bf374ef4feb0df00c41319debb26afba2ff39e1799a1c2137f4e920ee5b02d93789b6b0c853e8143dae5b08ee85da2ea7c31803610ce797293ea95c16ade6dae2afb008e59d8b9505737f008b5227df5f1e4eb5d707f502698a17ead9b1f5ec09dff34248ff2fb153dc6df4812e39754a4baa42e1d8b77fbddef3ca091701ac28ae5fd422dbd8db5b122d3965383abc37a52d2fca5ce56eba974dba3d059cefe40e3c35c9daa8ae31198214303c1dcb90d58fc983ccfd504fa43925636f94b128d44e8aa5cd3ecfabd50a84062d03f7508a0575ab65ecc749d3ef566fdbc529a8139b7a7fb3a9bd784df52cddc6f2699044ba47615163fbbe19f3d88d38a8b71fe52b2611ca74341429d1cef1a7e350545be29d2caa560e60352cab074c298c44ca2c07f9795ce52f10aa3e2fcdef371f24e309b19e52218881f25a4674527edbe3b3bd0b9b536d810c6f9500c0c81bcfd9a440dd91c1d35c52758d2b2ae1a8497bb394c4f09d3947cf777727b0d1daf5ac4fe4fa3c247a791702cb84b96321b7fec81bf549d4eb5d6dafe019b26187417c68b064e4308908535a3e77b6cd3e28caaf12d726f15590b7958e40134d045a38cbb689131a7e85532f1c63dd4bac9e4d00645cd7b2b71704563f3738b92044a8158000a717800ab7cb238175c376d7add2c5ec38e4c856f1ab9c3ee33f6ca6d576ae908dd290e4bae23470182e253765e04e8eb02a791c4396a511ef467879a9e2818b8a4b1b0b39a6c44e816e3ebf6e3be93929dfcb38d5dad7d20b60215447674d0608b8b02331ac20e57083cb9b4449fecbb149441aea0ad82f00a82d87d743fc80d410922bc20923516885440f43c9f32beb81ce148def6140952583a7825c2d00e012d52d30ef66d32a8a0864ac5c1737e2506228d41ff0515ee80be4cf012927dde0fd2a07cac68eff8c4437f2844d4df07936fd8753e5909f962c5c767f8719cc295bdfa8a16f3f36ff56e34d7b14b6b8c46d5af248b04a9c5396f84990e23d145670950bce5f5638e5e2cea37c371a4483729338f1305cbb32fa1c05dd9d21d2a69e5fa3abe9a2dad2237be20b4088393c04aa66cf13718de4bffac72f641a8c017a1d5568fa15a6a06e4dc833874ec95af6f115bdadf15179bfc8c4e3e64f26f1299e282c4ab397340934efc1e601afc630fe195e8ae7d8da1310568cab4f2fad085d0ec39710d8b7c812b3fd55c6f50925bcfc90fbcb35b8daa0f1e1f69d82fae2034039f7ad6921694ed48a55a68bc541e6d86f1e33c261a92d48b50eb58a03d8e31b2f6564a4ddc3ee988d0dc47b4b610a9a9dcb87571b5c1edb3362df0ec3d58872157e0f7247dfa8100b4478b705702a5620c9201010f40232327550db333e845dbecd6aadbd0a94c064862b1100b4dd45ece811b8c0275e3753e11b4bcd8bc5ed7668e72afa5bc5cc17b4c313273755f532ecfdefdf2d5c47999453a3b7c158d98332f0bd3a820cfb2c8c3bcd43197e7395a032cec6e41662079f2f654965aebc393e22b5c8516d9b8ad01e33ee481a4ac46a2df304dadeaa9e5274d340aaebe14dcea315fe1279f1a41a5c7aa8c94bf4b3d48757503171f53488e01210145e62c0de7c39737848dbdb1b207d4d33b8de180b020e8a76b1b521905e5e3ce97292f8558fb68efdee774681bfffcf1dc3eef35f660dd1659a32950de2d50e762313beee330d9c2a9fe8ce5e4e61ddd86378d3551335f6ef62053d3b248a8c33a11abdf3f3aa1975a15f4a6957a13d5b12a44d0f2b52b9a2d996e98c630c0f2abca80c7ae89efcf81ae284a0d19582cb1319d207077e5657d245533181ed6e07e0f7647123fc46c37bd75b4f4d181112b4a08acdcf445332cb9dde69a0923dd9244dd2ecd818b19588939922e3b2d8dd9d9fed95fa55b0e4564b38aca2c4d24eebc634664400177fbdeaeb278bb1d8eb11baf4be5c87d4f8d9a855bfa75df4c51fb4eec87a27c59df9a47d82523b08022a1c0fb22ff6f93c3d2cc22a4111a6ec5be428cba33617be65739c2240248f3a02d01ddf2d6aca9e537a2296b16d082d2b868504371dd5e41898885b03ebfaca73b40e8924ece83c1c80de6ce14943e1199c6f81bf359f44c3ed5ae3c6eacb730b1039f0b6555347bd566dfff45a7a2176420ab2b40916a73b66a3ad07af6e1ac5597393d203fa1ad34d4564af956a0a3e2997e27a4e5eff67dd89cce8875d995e00c1858234f149f6ad4cac2b8056966f726df57b8c4ee8f22f23097ba1471b1f1036e3a499400fccdb75b56eb13e9eca1407d5bff4b075b06d00fcbfcafc28431eb33156232e73c6577e3eca437330c494ede57b9609e1f40634918dea767338b5542197410cdc000143ace89ca0b7bf645b3267f74767d7c7fce05d2f59c137204e56bfa711f66903c511f681cf7a1b4f9fc0f42b7c438ff8957e1059375321df5b0c5c884f46d94c21686e1300582d34928bc398653118f79b0cea2e7cfbbf31a7718f4aab50fae57db94203d43e060365c9a7455241be03d82dffc3783d0f6aa170c0866eb0dad07485831526922d8348a7a16e2e9903a2ac93c58c6dce83127fab17703ec004a519ae5675baffb31bf4b52f9ca992a84017a44d68dc693abd829947342f277fdcbc87168bcc03c32b8b1e81a1915af2517c464af07d52b79d1b0e53164c82ba049f81e92ed1dc20a88fd72e9ce7aa4b22a7cc57dc5527d14f62bc29cfc9d57ed26fd523cac39ac00ba12d3a49d694709924275fc0793d56acf9558818dc9eb210749fa5307d45886b879257d627cee0542b51c2ce6ce134100efb47c92456ece5b73cdc051f570810a8d534222649eb56cf73a377162b753de6c282bcd4a25dda21dd10901bd8dfe8fd4ba8a70811c39707beded23dd60f23e2933372e3a6bce099899b07f0a4c4956fd98e956a8649622c77717de099463c0c6c9389ab4a1ae10f8ddd086d876af2943ee0b6b402ae5f89e09922e8c510ec0caa0a83e366e916400bfec88a52ab457037a35ddc6a8e2289c33684a5915c37bf5d227cbc65a737b52bdcb4fbbb7b4e7f965db116b4604407000000c730dce12e120b1fe6dd5798ced24cad72c59a3f44de4978b8bc05a1dbeb766be6e2abf6ef46c67a58a370e54e92d89e5f44525e82b94a388d8d0cb20c3469a258c1633c9dddb6854aee255f93f59435ff317622f6899250aa185c207644275278580c5d32401741fe264a2e03b80f442ed58fd0704ebac923ac6a5abb7f0c695252f82e3fbcf2b99d721589a8fe3fad4d5926aee3d7bfafb6739e525faae3d25b12841fa2cc61dddc44d36acb9a8b72d60ecdd9c8cf04f9bac341b5e0f9bc59042db8126324888b07afe72b18cce36d61eec975b6b4ef5dc4a16ac14440cf770599bd4db630bd110eb63a03a80cd95c16d314a4de60cc5115bf0754cb7ab84a827ecefafa96069c721a5979f227fdc2467b4cd1975dafb5b28e1d6f3c1c3a2816ad831dd98c1378a03798c128f176426eaa0e361571e758d54bf4ec2c988355f016e16d6cd5cf97bb4891ab33f5623b7e796af313cc7a9e2f9510cd2bead1ea5dd080d9de1f595b2629ebccf69a0feaed3963ae8a6c89edd66fbf6e566379898185828925f8669668d6bddff961b08aaedbbe7fc196931a887ec740da6bcdab8f826a34aa2aa1e406a258558f3baf022a64222df4d6ee8726c79ba3dd6e11a19e4b4bb49b4a8cd99c189e6392f08ad731e415b65d0ccb919dca46efe9f79e21437111ab09e926d3038182044ae047bf1cc92e2d2644c528985719667a1a8abaf65d0f211172ea789b2fa016e1a88325d1ed706239da4dbb9e2079e3598b4ae5885667587ba1e0921c9ba55d7a3be4c47bc2f2f3547ce9efe32e5a22855f761bd4cbe1cd9337eda4bd7d82a918084d7e116b656104ca87e64b1b8c62323c3c296c5b5b98051feb607b872edf9f789744aff710c4b7279711182bcac6b76c05f5cd982f52f451e7e29046550e012e01d8cdd3e305427030f4247488c9136303084c12175c5c781cdd08aede5a356ea0ccdd05a460be3c7b4bfd62c3ce9ab68e285a36c1546d0b18edad71f69f5bedb340772e1bbb035514b085067259e39f59dc292a12557350c66904b253efee29a5eb7a6920f583c899dc46a1d3e2af2db3a3d1a0e8d1f98722a16c6cc1e401058d60c8c436d8f1166ba53bdde5810f9d0288528affd486c266546a864c92af3df8abd451cc1e0d6bfea534865cea9d49b3ea5e390fa823118df8a61e31022f5fbb8ceee870bf2e60890263c4d14e24d053d0fddf665ff80a66fa00a5957f8a30fe82a4b82cf2f6b4d49def98f66bfcdaa0aef13314e950ca9f3849b1edf3b82eaf74a0dbcf45c3dba9bd2d853281a78484f1efaf4150da1207ec3cb61fbcbf759f8182b7052b28d7164b73197b0a440759fe9d5ddf827f1897a174e82fb968a9a07c61bee44bc1f7f9ee5c6de04c02d57735c5fab741b36aec7c8642e56cba932a08b8e8a9d3eb066a4ee7cbf22e5abbd4346de59eca1f24ad9f7f9ff7621e5f30dd08f4cddda8e80e496908109f5212a72bab1378d1237def07bdda4178719975346c68405de15153031fb17535894e5e3c1de6fdd507333f0226b78ba7cae509cfb48d6735ede9392650bf85ac1db919b1e9fe0a823119d8253204dbb2f7a8f524be6d419f3a45c5051a7a88ef0bd41586d90c11a894d647f03895f671a6e19f1c70e32668653aba8366a3d372522f49844081a9637db080663ab02f4a8af502955d5411461b62f85308c91852f8fb9f0bdddd500b4a133791d3a2f91a82dc4b09f5ad2196a9172ab0cd3fafe7266e9f6d159110d99ca8da8a34b17be17a04ad4509a9fffab1e45e10f10e0cf9cfbd9c761ad044064c07e473fdc626289cfb88b13a11455c069b70aa02426d9119ac878a14c9483be9c0d5bcbb5fa76c8d06531f59c7cf7c26372e750e2f332418ca769e5e7fbeb3ada7bb58b573a0635e2e3ad9a53ddb809ea01086a3fa993ad57e89da6f9c7e61bd0f8ba69212a386b2aa1ae17520d7fb989dbe14021885eb50fa3048aebd42c861a09a308b660d382c0480ead8a52a1e14927c7c77957f94bb59ccfd557f8c4a7af23360a298a603d20ebc386db041d8c306b3e32b0bff541bdec5ff75c3b40950815cf9f89d48a382f67e44c409d046c01fb1262aca0df6f5238a3c3c09977261494f7361ba326815d6e23f49e4d6d4b54665081067332265fff59cf54af9da0db9d19bc611cbcb6e6f3f1e2e1ffb6cdd6253578d78d06a2ff5f9250f1994c5749e3ce49231fbd63bba28e948f9150933e3ae31299babaa41043b181a100882e613b4b4b8f49ceeb742d22f860853a9b917f5a323a8a1fb1f3363a7be4407fba44b408f259b5db79a055b92ce3d7a0649cc59f4afa2b1f69959d5c6f5eef1fa7987a47bee4491f685c52e9db1ee1a231ab5a4bae1019c97868a409dd0d57b32525394a233023c4a7ac429808bbcb57a34b41883202744c3bdebc0a637773273f19c2be6e806bef7fc1002846db762ee4e16867773808c5477987d5851d5b1641d070feabc203cb3d7943ffb206272fcac1bccb616352d85975f5a22c0f247548535ad9fb83fb2be17689453f10691143c060cd964df63c3c70e7b1cfc7e2b468015f327f9869353477bfeeed330b03ddd9e4e0a2441182244da283d7a59d2b2b20e6de3e3a47c26aeef4944c1190bba674523a6c3c4ed6bac53b9edffcb0e9fb19d8bf36949d03ef6a7e59eb903a00d9614f642d1932c766421906f5b177963c71e881453560e3ffcec792e8dc46b1832a8fcb2ab2268a9c1fb648d1c6fa1c8cbd50d5a2d8264fbc6c063e6daac5519d362da389dcd3d12c8039f991de91e728abf5bab95c3aef66dd8cc36c60e73cb10afb02eff6df20ff12c59b142b07fc48fe94612de80b8b958f78256fd7cf3c6f79a83867f3bb5f70da392957badadecefdf7b6e4ebd39ff945397c7d302ca0a5a3918d8abb893cd9cdd680916a50fe19699ff0476ad82e6ba46523f26ccc5eb65313c1df1077c8876d2b73bf86ba311862d12b0c557a92ef827197121512e87f817167d4b17c7e225a48b3f8fbbf4187438e0e9b78e905cdbeb72e80dfb37ec0104f5186b39b4ff34f0cdf4b74dc915acd3f98874cd6a67308d0ad9697121ac477550b1affe004f433705933f9647522be65cb5a7471120ec942aeb956f195be0c1783102cf7d842f2968222ae1a7fa6513f200d3fa85d71724956ed697f0673ee3b40a4d46ba4850439ec125b708ed52b52b9f72906477d520c90a9f5dd49a7a33a328137a183f439895532b78ae451a8c3db789bc862fbc37241d523027e1a008629c969380f6eb55f9cf3f0675bca6851f00df6aaf90de9f62d5c179945ef81d1073850301f97e379ea415d830e3f3751cf83e2dba541cb6cdd89e6b674f2c53e329e5f3dd418d534ada6469a5b3bca5b7cfbdfdd6df4abaf77d4520d0311e801145c91b52586a56086e663841b702f52cef9fff8cfb7b33dfa125688ba6b4fadd1dca8defaf4259ca85323b23d3bbb45933562c25af3e8d7bc6ad4a50ae974f8d207994b3bd74a6812ab6a40fcaf96bb4e17bd20d742b14c72226caef3e0f5c56c4930071e9f9a894f18650fbb785c6f707605c86b634c9722c8690cf3a954f68d7c2db3a257339ade67a41259f6f878dd0ab7876deffa77f6f00819282a8f4c4da84c6cf4f335cd0410770a2b1a1fbb3f85f674aeb96b78bbfddb2d1866c57b41f6ed179a0bc3750a486403d23473f2feef43ebc5af1018d9c20089e277d77fb9c34f425c8f8af4c49864b57572fa8c232e61ef37194251a1ddc2f73ffecd57e638751cb72bcb2c40d22540166ca1e8588f24b010c9fbd962e3a2c23a7e93f131df61b8703ce326ed80cc87912d3c6aaa27574bbe8d65bcaecd660c31cead132a44b1d0e4a53cacc0b82a263c4e7783944af0af08ea9e68e8e25ed9111cfef841f1b2fd24164f9097f70efe09b1109e5cb91fe68a2760381fd63a7fd422dd578a60661abc9ee3a5db1c2cde2fb21f2040f1ed3fc27b99e254256949d0560e8b98fa028fca50768caa951a89bf8969af498d50a9ee773c9caa7d9f7d8e1955506013f198cda316d79b1f6e59f233b98f727afd2494fc18642f0015adab756ea6742690c7d00f28655b915ce4eb8b3ba2e8559ba23e1ff1ccc9f79ae2df85f924459c56715dec78ef4592352eb1a850cd65ecd36e1a9121e888586b7b2fa84da920b8cf44480433e61ab076b10171c0537524bb170a4b99b0b0c437418a665b7ef909652b6483b20362e557c1480c2a2a0efa221fc59054a48122b52d38245f9bd026001635be5b155f5c766a59306fbde231fa72b4d74449a2fe8fb969496ee26af5881adaafb4189b439877ab8f78709cfd32c10ea576a010bfc137b7a4aae137ea3d29070ce3bc8dbe6655e967115ca3461ad9d28b9cf8af07441e68a54ec5e889846f3978f07ba51f7d5af5da78c5c675dc5d0c1a4a399ff4247203573a46fb903eaf7bc886e6cbd3126fa4a3fe3bb13bbdfea7da871f6563aa750f6ad7895b34b2809563dcf5ed30f1c60cef4138aa49d4f55e396534ed10cf4d857723a2b442f47d79de162c30ec6c4daf939b4c88649494e3682d1da81b4a5928d8e18a16c46707a685305e592589acb484e28e9d5af89c44b6e563d125ec97c0155410527406d94b90bc957e08f22ea0e8fd31919d53fa6aaf980e31ca7f8610e695a41919c24136a8406c62d5f15fca365892a2b54ece17664b5247583ad60d863f283f3c288946139575dcaedc978762e85f534e56334ef0221c34ffae054ddf79339b8f08701e9699b11041df8f518dd33203363c8098fbefb01555bcc2542422777b38d8dff11b15aadb0c251ce2c5b32f8735b3cb784f2e5731b48feb5a0e791a1106abdea0f7d1f087737cbe7fdf523fa14c9be2a2987511004c5b7ac1814ef6961db16799698242452c469a07c30e4a1f73193c74a41bdd88aef50035e4648bc9dfa276951798420a45e4085932bdb9381af3cc4678bd962af616549e4020d2c9fd25e2117a6d8934fde2218273d7833d60ea492e251417a27e7fb32012a940a6b6487af4b64958bf05f1b1107732149d227eeda5ca5a43cf583dc297d66072a1acd75e93a7caefd36a0d581e21d5cb08654c4ecef46ebac5391546e0b7d2a6418548d8f816446bcf237f676e873e6bae9107234abe5ab24c53ea472ad10653cef068fd9f4e729fc0d526e489f8df13af5575f1e70e0ec22899728b0659d70fc2dd509d9df3ec170638f89e540f4d3f02aa9b1b1819f84da596e0d7b45a5818061728f8eeccd2bea0f460dd7e18cb95f2364c50e351f0690e184eb63ebbb14a0b4b2117e44f3b2b300", 0x2000, &(0x7f0000000b40)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, &(0x7f0000000a00)={0x130, 0x0, 0x80000001, {0x3ff, 0x100, 0x0, '\x00', {0x7ff, 0x4, 0x400000004, 0x3, r2, r3, 0x8000, '\x00', 0x1, 0x0, 0xb4e7, 0x0, {0x8003, 0x8}, {0x6, 0x10001}, {0x100000000, 0x5}, {0x9, 0xa00}, 0x4, 0xb, 0x4, 0x3}}}}) write$FUSE_INIT(r0, &(0x7f0000001200)={0x50, 0x0, r1, {0x7, 0x2b, 0x0, 0x6000000}}, 0x50) 2.022539117s ago: executing program 0 (id=1003): r0 = openat$sw_sync(0xffffffffffffff9c, &(0x7f0000000280), 0x80a00, 0x0) ioctl$SW_SYNC_IOC_CREATE_FENCE(r0, 0xc0285700, &(0x7f0000000180)={0x80000001, "0600000000000000c64c3b6e6ff82a75e5318fca4288c2ffbdbec772020acd2c", 0xffffffffffffffff}) dup3(r1, r0, 0x0) r2 = syz_io_uring_setup(0x88b, &(0x7f0000000640)={0x0, 0xaee2, 0x0, 0x2, 0xbfdffffc}, &(0x7f0000000000)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r3, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r3, r4, &(0x7f00000002c0)=@IORING_OP_POLL_ADD={0x6, 0x0, 0x0, @fd_index=0x3, 0x0, 0x0, 0x0, {0x6101}}) io_uring_enter(r2, 0x47f6, 0x0, 0x4, 0x0, 0x0) 1.930585673s ago: executing program 1 (id=1004): socket$nl_route(0x10, 0x3, 0x0) r0 = socket$rxrpc(0x21, 0x2, 0xa) bind$rxrpc(r0, &(0x7f0000000100)=@in6={0x21, 0x3, 0x2, 0x1c, {0xa, 0x4e22, 0x9, @loopback, 0x3}}, 0x24) r1 = syz_io_uring_setup(0x497, &(0x7f0000000300)={0x0, 0x7079, 0x1000, 0x14, 0x28b}, &(0x7f0000000180)=0x0, &(0x7f00000001c0)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r2, r3, &(0x7f00000002c0)=@IORING_OP_WRITEV={0x2, 0x0, 0x0, @fd_index=0x4, 0x0, 0x0}) io_uring_enter(r1, 0x3516, 0x0, 0x0, 0x0, 0x0) bind$rxrpc(r0, &(0x7f0000000000)=@in4={0x21, 0x3, 0x2, 0x10, {0x2, 0x4e24, @multicast1}}, 0x24) 1.792486402s ago: executing program 2 (id=1005): r0 = openat$dir(0xffffffffffffff9c, &(0x7f0000000000)='.\x00', 0x0, 0x0) r1 = fanotify_init(0x20, 0x0) r2 = openat$dir(0xffffffffffffff9c, &(0x7f0000000000)='.\x00', 0x0, 0x0) fanotify_mark(r1, 0x71, 0x8000000, r2, 0x0) r3 = openat$dir(0xffffffffffffff9c, &(0x7f0000000100)='.\x00', 0x0, 0x0) r4 = fanotify_init(0x200, 0x0) fanotify_mark(r4, 0x39, 0x1a, r3, 0x0) fanotify_mark(r1, 0x12, 0x8000001, r0, 0x0) 1.759284477s ago: executing program 4 (id=1006): r0 = creat(&(0x7f0000000040)='./file0\x00', 0x4b) close(r0) r1 = syz_open_dev$dri(&(0x7f0000000000), 0x1, 0x0) ioctl$DRM_IOCTL_MODE_GETRESOURCES(r1, 0xc04064a0, &(0x7f0000000140)={0x0, &(0x7f0000000380)=[0x0], 0x0, 0x0, 0x0, 0x1}) ioctl$DRM_IOCTL_MODE_GETCRTC(r1, 0xc06864a1, &(0x7f0000000300)={0x0, 0x0, r2, 0x0}) ioctl$DRM_IOCTL_MODE_GETFB2(r0, 0xc06864ce, &(0x7f0000000600)={r3, 0x0, 0x5, 0x4000000, 0x2, [0x0, 0x0, 0x0, 0x0], [0xbc2], [0x805, 0x1001000, 0x0, 0x3], [0x0, 0x1, 0xe8a6]}) ioctl$DRM_IOCTL_MODE_ADDFB2(r0, 0xc06864b8, &(0x7f00000001c0)={0x0, 0xae, 0x3ff, 0x34325241, 0x2, [r4, 0x0, 0x0, r5], [0x2b8]}) ioctl$DRM_IOCTL_MODE_GETRESOURCES(r0, 0xc04064a0, &(0x7f0000000400)={&(0x7f00000000c0)=[0x0], 0x0, 0x0, 0x0, 0x1}) 1.552473928s ago: executing program 6 (id=1007): r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) pselect6(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, 0x0) syz_init_net_socket$nl_rdma(0x10, 0x3, 0x10) bpf$PROG_LOAD(0x5, 0x0, 0x0) landlock_create_ruleset(0x0, 0x0, 0x1) prlimit64(0x0, 0xe, 0x0, 0x0) syz_emit_vhci(&(0x7f0000000080)=ANY=[@ANYBLOB="02c9000c00080005000702040004000200"], 0x11) 1.403348194s ago: executing program 2 (id=1008): r0 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000440), 0x180, 0x0) r1 = syz_io_uring_setup(0x6, &(0x7f0000000480)={0x0, 0x8a73, 0x100, 0x22, 0x31a}, &(0x7f0000000080)=0x0, &(0x7f00000001c0)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000000)=0x103, 0x0, 0x4) syz_io_uring_submit(r2, r3, &(0x7f0000000200)=@IORING_OP_READV=@pass_iovec={0x1, 0x0, 0x6000, @fd=r0, 0x5, &(0x7f0000000040)=[{&(0x7f0000000140)=""/65, 0x41}], 0x1, 0x1a, 0x1}) io_uring_enter(r1, 0x47ba, 0x0, 0x0, 0x0, 0x0) ioctl$TCSETSW(0xffffffffffffffff, 0x5403, &(0x7f0000000040)={0x0, 0x0, 0xfffffffc, 0x0, 0x1a, "90737f0000ff256003abbc74dd8e277fffffeb"}) io_uring_enter(r1, 0x617, 0xf7ad, 0x0, 0x0, 0x0) 1.229716882s ago: executing program 4 (id=1009): r0 = socket$alg(0x26, 0x5, 0x0) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) bind$alg(r0, &(0x7f0000000100)={0x26, 'hash\x00', 0x0, 0x0, 'md5-generic\x00'}, 0x5a) r1 = accept4(r0, 0x0, 0x0, 0x0) write(r1, &(0x7f0000000040)="cb", 0xfffffdef) syz_clone(0x23802400, 0x0, 0x0, 0x0, 0x0, 0x0) 1.016077188s ago: executing program 2 (id=1010): r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000000)='cgroup.kill\x00', 0x275a, 0x0) write$binfmt_script(r0, &(0x7f0000000080), 0xfecc) mmap(&(0x7f0000000000/0x3000)=nil, 0x3000, 0x1, 0x12, r0, 0x0) unlinkat(0xffffffffffffff9c, &(0x7f0000000140)='./file1\x00', 0x0) r1 = syz_open_dev$tty1(0xc, 0x4, 0x1) prctl$PR_SET_TAGGED_ADDR_CTRL(0x37, 0x1) ioctl$TIOCL_SETSEL(r1, 0x541c, &(0x7f00000000c0)={0x2, {0x2, 0x3bf, 0x4, 0x150, 0x9}}) 1.01516804s ago: executing program 1 (id=1022): r0 = socket$inet6_tcp(0xa, 0x1, 0x0) r1 = syz_open_dev$loop(&(0x7f0000000140), 0x75f, 0xa382) r2 = memfd_create(&(0x7f0000000880)='C\x13\xfc2\x95WD\xaa\xba^\x90\xfd\x8d\xc2\xb1[\x81\xda\xda\xd6\x8c\xc99\xec\x0e*||\xe4\xb3\xc4\xb6\v\xaa\x15\x86,\xac\x8d\x89cu\x10\xdc\x93\x9b\xb4\x93\xafE*:\xe4\xdd\xa5\xa75\xb8\x1e;7\xb7.V\xdcrw[\r\x98\x93j\x9c\xf6\xf8\x99\xefF_\xcd\xdf!b\xc5\xec\ntb\xff\b\xaaF?!\x9f\a\x1a\x03\f\xe94\x1deU\x06zS\xc90\xb9voI\xa5/\xb4\xa7@\xa1\\B\xc2@\r_b\x9a\xeb\b\x81\x00V\xd6/N\xc5\xc6f\xb1\x95Z\xe5w^\xd8\xe7J\x80\xf7\xae\xafuv\x84\x9eG\xd1\xe7\x9b\xf0_9\xc2\x9b\xfd\xc3\xf3\xe4\x95P\xf1m\xcf\xc2\xe1\xe6\xa6\x8c\x11\xfb\xb8S\x8b\x92\\\asW-Ee\x02\x00\x00\x00\xd0;Q\xc1~\x89\xec\xc8\x9b\x88\a\xf2\x93\x82(\x8b\x00\xd8\xb4T\x80\x95\x93\x9c5\xcf\t\x04\x00\x00\x00\x00\x00\x00v\xef\xee+\xab\x9c\x00^R\xb2n?i=\xbe\x16\x8a\xbf\xe3\xcdB\xed\xe14\xe8\xd0\xb7\xff\xfeQ\x1c\x85n8\x1b\xc1\b\x00\x00\x00\x00\x00\x00\x00\x17\x94\xdfW\x92z\xbe\xb2R)\xf1K\xd7\xaf\x99\xf6d\xe8\xec\xb7\xbd+T3\xa6\xa9\xfaY-1qs\x82\xefn*\x96\xc9\x1e\xf4\xd1\x02Dt\xc0\x19\xf7\x89\x96.D [F\xeeYW\x95\x13\xc7;\x94\x13^\x13\xaf\xf0C\x9c\xabf\x1daCS2\x02\xb0\xef\xc7\x8c\x9e\xed\a\n [ 167.296312][ T59] F2FS-fs (loop3): Stopped filesystem due to reason: 3 [ 167.413447][ T6678] BTRFS info (device loop4): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 167.425043][ T6678] BTRFS info (device loop4): using crc32c (crc32c-x86_64) checksum algorithm [ 167.435180][ T6678] BTRFS info (device loop4): using free-space-tree [ 167.567417][ T6678] workqueue: Failed to create a rescuer kthread for wq "btrfs-compressed-write": -EINTR [ 167.567979][ T6678] workqueue: Failed to create a rescuer kthread for wq "btrfs-freespace-write": -EINTR [ 167.611641][ T6678] workqueue: Failed to create a rescuer kthread for wq "btrfs-delayed-meta": -EINTR [ 167.625314][ T24] usb 1-1: new full-speed USB device number 4 using dummy_hcd [ 167.625662][ T6678] workqueue: Failed to create a rescuer kthread for wq "btrfs-qgroup-rescan": -EINTR [ 167.744704][ T6678] BTRFS error (device loop4): open_ctree failed: -12 [ 167.857181][ T24] usb 1-1: config 0 has no interfaces? [ 167.926992][ T24] usb 1-1: New USB device found, idVendor=07d0, idProduct=4101, bcdDevice=ec.5c [ 167.957674][ T24] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 167.987512][ T24] usb 1-1: Product: syz [ 168.010544][ T24] usb 1-1: Manufacturer: syz [ 168.020528][ T24] usb 1-1: SerialNumber: syz [ 168.036722][ T24] usb 1-1: config 0 descriptor?? [ 168.276795][ T24] usb 1-1: USB disconnect, device number 4 [ 169.180633][ T6720] loop0: detected capacity change from 0 to 512 [ 169.231541][ T6720] EXT4-fs (loop0): encrypted files will use data=ordered instead of data journaling mode [ 169.307546][ T6720] EXT4-fs warning (device loop0): ext4_expand_extra_isize_ea:2847: Unable to expand inode 15. Delete some EAs or run e2fsck. [ 169.354749][ T6720] EXT4-fs (loop0): 1 truncate cleaned up [ 169.362709][ T6720] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 169.603124][ T24] usb 4-1: new high-speed USB device number 3 using dummy_hcd [ 169.740147][ T1151] team0 (unregistering): Port device team_slave_1 removed [ 169.773230][ T24] usb 4-1: Using ep0 maxpacket: 32 [ 169.780992][ T24] usb 4-1: config 0 has an invalid interface number: 184 but max is 0 [ 169.801808][ T24] usb 4-1: config 0 has no interface number 0 [ 169.832078][ T24] usb 4-1: config 0 interface 184 has no altsetting 0 [ 169.844297][ T24] usb 4-1: New USB device found, idVendor=0424, idProduct=7500, bcdDevice=69.ee [ 169.862915][ T24] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 169.867436][ T5837] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 169.879158][ T24] usb 4-1: Product: syz [ 169.884689][ T24] usb 4-1: Manufacturer: syz [ 169.920022][ T24] usb 4-1: SerialNumber: syz [ 169.954132][ T24] usb 4-1: config 0 descriptor?? [ 169.985017][ T1151] team0 (unregistering): Port device team_slave_0 removed [ 169.991817][ T24] smsc75xx v1.0.0 [ 170.164651][ T6734] loop0: detected capacity change from 0 to 2048 [ 170.175690][ T6734] EXT4-fs: Ignoring removed bh option [ 170.288163][ T6734] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 170.389284][ T6734] EXT4-fs error (device loop0): ext4_mb_generate_buddy:1217: group 0, block bitmap and bg descriptor inconsistent: 25 vs 150994969 free clusters [ 170.413588][ T6734] EXT4-fs (loop0): Delayed block allocation failed for inode 15 at logical offset 0 with max blocks 2 with error 28 [ 170.440338][ T6734] EXT4-fs (loop0): This should not happen!! Data will be lost [ 170.440338][ T6734] [ 170.452690][ T6740] EXT4-fs (loop0): shut down requested (2) [ 170.460919][ T30] audit: type=1804 audit(1749620420.796:27): pid=6740 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.0.234" name="/newroot/49/file1/file1" dev="loop0" ino=15 res=1 errno=0 [ 170.505800][ T6734] EXT4-fs (loop0): Total free blocks count 0 [ 170.511967][ T6734] EXT4-fs (loop0): Free/Dirty block details [ 170.519096][ T6734] EXT4-fs (loop0): free_blocks=2415919104 [ 170.525625][ T6734] EXT4-fs (loop0): dirty_blocks=16 [ 170.530815][ T6734] EXT4-fs (loop0): Block reservation details [ 170.537035][ T6734] EXT4-fs (loop0): i_reserved_data_blocks=1 [ 170.980759][ T6515] team0: Port device team_slave_1 added [ 171.322507][ T6515] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 171.354528][ T6515] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 171.425800][ T24] smsc75xx 4-1:0.184 (unnamed net_device) (uninitialized): Failed to write reg index 0x00000040: -71 [ 171.450447][ T24] smsc75xx 4-1:0.184 (unnamed net_device) (uninitialized): Error writing E2P_CMD [ 171.470986][ T6515] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 171.487967][ T24] smsc75xx 4-1:0.184 (unnamed net_device) (uninitialized): Failed to read reg index 0x00000014: -71 [ 171.519385][ T24] smsc75xx 4-1:0.184 (unnamed net_device) (uninitialized): Failed to read PMT_CTL: -71 [ 171.551563][ T24] smsc75xx 4-1:0.184 (unnamed net_device) (uninitialized): device not ready in smsc75xx_reset [ 171.595604][ T6515] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 171.624210][ T24] smsc75xx 4-1:0.184 (unnamed net_device) (uninitialized): smsc75xx_reset error -71 [ 171.641090][ T6515] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 171.686245][ T24] smsc75xx 4-1:0.184: probe with driver smsc75xx failed with error -71 [ 171.709800][ T24] usb 4-1: USB disconnect, device number 3 [ 171.738039][ T6515] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 173.435742][ T6515] hsr_slave_0: entered promiscuous mode [ 173.555702][ T6515] hsr_slave_1: entered promiscuous mode [ 173.685666][ T6515] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 173.765136][ T6515] Cannot create hsr debugfs directory [ 174.039327][ T6764] loop4: detected capacity change from 0 to 32768 [ 174.207619][ T6764] bcachefs (/dev/loop4): error validating superblock: Invalid superblock section replicas: bad nr_required in entry (unknown data_type 254): 255/255 [0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 4 5 6 7 10 11 11 11 24 26 33 34 45 45 56 80 255 255 255 255 255] [ 174.207619][ T6764] replicas (size 40): [ 174.207619][ T6764] (unknown data_type 254): 255/255 [255 255 255 255 255 7 0 0 0 0 0 0 0 24 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 80 0 0 0 10 0 0 0 0 0 0 0 0 0 0 0 56 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 34 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 45 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 45 0 [ 174.209700][ T6764] bcachefs: bch2_fs_get_tree() error: invalid_replicas_entry [ 176.039081][ T6777] overlayfs: upper fs does not support RENAME_WHITEOUT. [ 176.064392][ T6777] overlayfs: failed to set xattr on upper [ 176.090901][ T6777] overlayfs: ...falling back to redirect_dir=nofollow. [ 176.117809][ T6777] overlayfs: ...falling back to index=off. [ 176.160787][ T6777] overlayfs: ...falling back to uuid=null. [ 176.193477][ T6777] overlayfs: ...falling back to xino=off. [ 176.199452][ T6777] overlayfs: conflicting lowerdir path [ 176.561607][ T6515] netdevsim netdevsim6 netdevsim0: renamed from eth0 [ 176.637893][ T6515] netdevsim netdevsim6 netdevsim1: renamed from eth1 [ 176.686843][ T6515] netdevsim netdevsim6 netdevsim2: renamed from eth2 [ 176.739379][ T6515] netdevsim netdevsim6 netdevsim3: renamed from eth3 [ 177.031127][ T6515] 8021q: adding VLAN 0 to HW filter on device bond0 [ 177.107998][ T6515] 8021q: adding VLAN 0 to HW filter on device team0 [ 177.153125][ T36] bridge0: port 1(bridge_slave_0) entered blocking state [ 177.160304][ T36] bridge0: port 1(bridge_slave_0) entered forwarding state [ 177.279075][ T36] bridge0: port 2(bridge_slave_1) entered blocking state [ 177.286436][ T36] bridge0: port 2(bridge_slave_1) entered forwarding state [ 177.444802][ T6515] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 177.480582][ T6515] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 177.876780][ T6809] loop3: detected capacity change from 0 to 512 [ 177.928240][ T6815] netlink: 12 bytes leftover after parsing attributes in process `syz.2.257'. [ 177.937368][ T6809] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 177.990965][ T6815] netlink: 'syz.2.257': attribute type 5 has an invalid length. [ 178.020992][ T6809] EXT4-fs (loop3): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 178.110504][ T6809] ext4 filesystem being mounted at /37/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 178.181599][ T6815] netdevsim netdevsim2 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 178.191161][ T6815] netdevsim netdevsim2 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 178.199949][ T6815] netdevsim netdevsim2 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 178.208932][ T6815] netdevsim netdevsim2 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 178.251179][ T6815] vxlan0: entered promiscuous mode [ 178.271780][ T30] audit: type=1800 audit(1749620428.616:28): pid=6809 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.3.255" name="file0" dev="overlay" ino=15 res=0 errno=0 [ 178.417178][ T6515] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 178.503567][ T5836] EXT4-fs (loop3): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 178.576284][ T6826] loop4: detected capacity change from 0 to 128 [ 178.610835][ T6826] EXT4-fs (loop4): mounted filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09 r/w without journal. Quota mode: none. [ 178.690521][ T6826] ext4 filesystem being mounted at /49/mnt supports timestamps until 2038-01-19 (0x7fffffff) [ 178.805075][ T6826] syz.4.259 (pid 6826) is setting deprecated v1 encryption policy; recommend upgrading to v2. [ 180.411586][ T6842] loop0: detected capacity change from 0 to 32768 [ 182.086635][ T6842] bcachefs (/dev/loop0): error validating superblock: Invalid superblock section replicas: bad nr_required in entry (unknown data_type 254): 255/255 [0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 4 5 6 7 10 11 11 11 24 26 33 34 45 45 56 80 255 255 255 255 255] [ 182.086635][ T6842] replicas (size 40): [ 182.086635][ T6842] (unknown data_type 254): 255/255 [255 255 255 255 255 7 0 0 0 0 0 0 0 24 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 80 0 0 0 10 0 0 0 0 0 0 0 0 0 0 0 56 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 34 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 45 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 45 0 [ 182.086895][ T6842] bcachefs: bch2_fs_get_tree() error: invalid_replicas_entry [ 182.112880][ T30] audit: type=1326 audit(1749620432.446:29): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab6b8e929 code=0x7ffc0000 [ 182.258953][ T30] audit: type=1326 audit(1749620432.446:30): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=237 compat=0 ip=0x7f2ab6b8e929 code=0x7ffc0000 [ 182.295516][ T30] audit: type=1326 audit(1749620432.446:31): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab6b8e929 code=0x7ffc0000 [ 182.323421][ T30] audit: type=1326 audit(1749620432.446:32): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=319 compat=0 ip=0x7f2ab6b8e929 code=0x7ffc0000 [ 182.385651][ T30] audit: type=1326 audit(1749620432.446:33): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=9 compat=0 ip=0x7f2ab6b8e963 code=0x7ffc0000 [ 182.441072][ T5848] EXT4-fs (loop4): unmounting filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09. [ 182.473332][ T30] audit: type=1326 audit(1749620432.446:34): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=1 compat=0 ip=0x7f2ab6b8d3df code=0x7ffc0000 [ 182.495677][ T30] audit: type=1326 audit(1749620432.456:35): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=11 compat=0 ip=0x7f2ab6b8e9b7 code=0x7ffc0000 [ 182.550634][ T30] audit: type=1326 audit(1749620432.456:36): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7f2ab6b8d290 code=0x7ffc0000 [ 182.730349][ T30] audit: type=1326 audit(1749620432.456:37): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6844 comm="syz.2.262" exe="/root/syz-executor" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f2ab6b8d58a code=0x7ffc0000 [ 183.119288][ T6515] veth0_vlan: entered promiscuous mode [ 183.205675][ T6515] veth1_vlan: entered promiscuous mode [ 183.395918][ T6515] veth0_macvtap: entered promiscuous mode [ 183.463393][ T6515] veth1_macvtap: entered promiscuous mode [ 183.611053][ T6515] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 183.690634][ T6515] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 183.800250][ T6515] netdevsim netdevsim6 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 183.857884][ T6515] netdevsim netdevsim6 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 183.897418][ T6515] netdevsim netdevsim6 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 183.952891][ T6515] netdevsim netdevsim6 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 184.579417][ T12] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 184.624170][ T12] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 184.799212][ T13] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 184.852951][ T13] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 185.631491][ T6872] loop4: detected capacity change from 0 to 32768 [ 185.677764][ T6872] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop4 (7:4) scanned by syz.4.269 (6872) [ 185.777435][ T6895] netlink: 120 bytes leftover after parsing attributes in process `syz.3.273'. [ 185.789204][ T6872] BTRFS info (device loop4): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 185.862457][ T6872] BTRFS info (device loop4): using crc32c (crc32c-x86_64) checksum algorithm [ 185.903324][ T6872] BTRFS info (device loop4): using free-space-tree [ 186.639591][ T6939] loop1: detected capacity change from 0 to 512 [ 186.744772][ T6939] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 186.797376][ T6939] ext4 filesystem being mounted at /49/bus supports timestamps until 2038-01-19 (0x7fffffff) [ 186.958241][ T6939] EXT4-fs error (device loop1): ext4_do_update_inode:5568: inode #2: comm syz.1.277: corrupted inode contents [ 187.006796][ T6939] EXT4-fs error (device loop1): ext4_dirty_inode:6459: inode #2: comm syz.1.277: mark_inode_dirty error [ 187.078302][ T6939] EXT4-fs error (device loop1): ext4_do_update_inode:5568: inode #2: comm syz.1.277: corrupted inode contents [ 187.120596][ T5848] BTRFS info (device loop4): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 187.164797][ T6939] EXT4-fs error (device loop1): __ext4_ext_dirty:206: inode #2: comm syz.1.277: mark_inode_dirty error [ 187.426760][ T6951] loop0: detected capacity change from 0 to 1024 [ 187.474130][ T6951] EXT4-fs: Ignoring removed nobh option [ 187.479808][ T6951] EXT4-fs: Ignoring removed bh option [ 187.525016][ T6955] loop3: detected capacity change from 0 to 128 [ 187.563761][ T6955] FAT-fs (loop3): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 187.649519][ T6955] FAT-fs (loop3): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 187.680775][ T5839] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 187.683489][ T6960] sch_tbf: burst 19872 is lower than device lo mtu (65550) ! [ 187.753362][ T6951] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 187.822333][ T30] kauditd_printk_skb: 8 callbacks suppressed [ 187.822357][ T30] audit: type=1326 audit(1749620438.146:46): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6954 comm="syz.3.288" exe="/root/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7fb0f1d8e929 code=0x0 [ 188.345938][ T6967] EXT4-fs error (device loop0): mb_free_blocks:1945: group 0, inode 15: block 97:freeing already freed block (bit 6); block bitmap corrupt. [ 188.619152][ T1320] FAT-fs (loop3): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 188.729899][ T5837] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 188.803112][ T6979] netlink: 8 bytes leftover after parsing attributes in process `syz.6.293'. [ 188.836063][ T6979] netlink: 8 bytes leftover after parsing attributes in process `syz.6.293'. [ 189.251770][ T6989] loop0: detected capacity change from 0 to 256 [ 189.290418][ T6989] exFAT-fs (loop0): failed to load upcase table (idx : 0x0000fd4f, chksum : 0x3963664b, utbl_chksum : 0xe619d30d) [ 190.376202][ T7023] netlink: 'syz.6.308': attribute type 10 has an invalid length. [ 190.506301][ T7023] syz_tun: entered promiscuous mode [ 190.600959][ T7023] bond0: (slave syz_tun): Enslaving as an active interface with an up link [ 191.080218][ T7041] capability: warning: `syz.6.316' uses 32-bit capabilities (legacy support in use) [ 191.123268][ T7042] sg_read: process 143 (syz.1.317) changed security contexts after opening file descriptor, this is not allowed. [ 191.278241][ T7036] loop4: detected capacity change from 0 to 8192 [ 191.633945][ T7051] capability: warning: `syz.6.320' uses deprecated v2 capabilities in a way that may be insecure [ 192.016654][ T7057] veth0_to_hsr: entered promiscuous mode [ 192.045897][ T7057] veth0_to_hsr: entered allmulticast mode [ 192.144184][ T7057] lo: entered promiscuous mode [ 192.174873][ T7056] lo: left promiscuous mode [ 192.179961][ T7056] veth0_to_hsr: left allmulticast mode [ 192.228289][ T7056] veth0_to_hsr: left promiscuous mode [ 192.388452][ T7027] loop0: detected capacity change from 0 to 32768 [ 192.632930][ T7027] ocfs2: Mounting device (7,0) on (node local, slot 0) with ordered data mode. [ 192.806724][ T7073] loop2: detected capacity change from 0 to 7 [ 192.867830][ T7073] Dev loop2: unable to read RDB block 7 [ 192.913037][ T7073] loop2: unable to read partition table [ 192.948657][ T7073] loop2: partition table beyond EOD, truncated [ 192.969502][ T7073] loop_reread_partitions: partition scan of loop2 (þ被xü—ŸÑà– ) failed (rc=-5) [ 193.267942][ T5837] ocfs2: Unmounting device (7,0) on (node local) [ 193.538638][ T7084] overlayfs: upper fs does not support RENAME_WHITEOUT. [ 193.583077][ T7084] overlayfs: failed to set xattr on upper [ 193.603046][ T7084] overlayfs: ...falling back to redirect_dir=nofollow. [ 193.672690][ T7084] overlayfs: ...falling back to index=off. [ 193.730753][ T7084] overlayfs: ...falling back to uuid=null. [ 193.763091][ T7084] overlayfs: maximum fs stacking depth exceeded [ 194.279203][ T5941] usb 1-1: new high-speed USB device number 5 using dummy_hcd [ 194.477881][ T5941] usb 1-1: New USB device found, idVendor=055f, idProduct=c230, bcdDevice=b6.ac [ 194.508908][ T5941] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 194.539364][ T5941] usb 1-1: Product: syz [ 194.557707][ T5941] usb 1-1: Manufacturer: syz [ 194.589808][ T5941] usb 1-1: SerialNumber: syz [ 194.627743][ T5941] usb 1-1: config 0 descriptor?? [ 194.682135][ T5941] gspca_main: sunplus-2.14.0 probing 055f:c230 [ 194.882713][ T7099] cgroup: fork rejected by pids controller in /syz0 [ 195.113439][ T5925] usb 1-1: USB disconnect, device number 5 [ 195.308304][ T7133] loop4: detected capacity change from 0 to 256 [ 195.405835][ T7133] exfat: Deprecated parameter 'namecase' [ 195.459689][ T7133] exfat: Deprecated parameter 'utf8' [ 195.602595][ T7133] exFAT-fs (loop4): failed to load upcase table (idx : 0x00010000, chksum : 0xdc42f586, utbl_chksum : 0xe619d30d) [ 196.282003][ T7154] syz.1.354: attempt to access beyond end of device [ 196.282003][ T7154] nbd1: rw=0, sector=64, nr_sectors = 1 limit=0 [ 196.298539][ T7147] syz.4.352 uses obsolete (PF_INET,SOCK_PACKET) [ 196.353490][ T7154] syz.1.354: attempt to access beyond end of device [ 196.353490][ T7154] nbd1: rw=0, sector=256, nr_sectors = 1 limit=0 [ 196.422747][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=256, location=256 [ 196.437677][ T7154] syz.1.354: attempt to access beyond end of device [ 196.437677][ T7154] nbd1: rw=0, sector=512, nr_sectors = 1 limit=0 [ 196.453524][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=512, location=512 [ 196.496951][ T7154] syz.1.354: attempt to access beyond end of device [ 196.496951][ T7154] nbd1: rw=0, sector=64, nr_sectors = 2 limit=0 [ 196.543428][ T7154] syz.1.354: attempt to access beyond end of device [ 196.543428][ T7154] nbd1: rw=0, sector=512, nr_sectors = 2 limit=0 [ 196.562997][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=256, location=256 [ 196.595486][ T7154] syz.1.354: attempt to access beyond end of device [ 196.595486][ T7154] nbd1: rw=0, sector=1024, nr_sectors = 2 limit=0 [ 196.659064][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=512, location=512 [ 196.686016][ T7154] syz.1.354: attempt to access beyond end of device [ 196.686016][ T7154] nbd1: rw=0, sector=64, nr_sectors = 4 limit=0 [ 196.700972][ T7154] syz.1.354: attempt to access beyond end of device [ 196.700972][ T7154] nbd1: rw=0, sector=1024, nr_sectors = 4 limit=0 [ 196.716567][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=256, location=256 [ 196.745128][ T7154] syz.1.354: attempt to access beyond end of device [ 196.745128][ T7154] nbd1: rw=0, sector=2048, nr_sectors = 4 limit=0 [ 196.759306][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=512, location=512 [ 196.773273][ T7154] syz.1.354: attempt to access beyond end of device [ 196.773273][ T7154] nbd1: rw=0, sector=64, nr_sectors = 8 limit=0 [ 196.787087][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=256, location=256 [ 196.798476][ T7154] UDF-fs: error (device nbd1): udf_read_tagged: read failed, block=512, location=512 [ 196.819135][ T7154] UDF-fs: warning (device nbd1): udf_fill_super: No partition found (1) [ 197.366348][ T59] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 197.679656][ T59] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 197.782229][ T7153] loop3: detected capacity change from 0 to 32768 [ 197.814819][ T7153] BTRFS: device fsid 5e4b7888-5e56-43f0-8345-635ad0fd87c6 devid 1 transid 8 /dev/loop3 (7:3) scanned by syz.3.355 (7153) [ 197.900708][ T7153] BTRFS info (device loop3): first mount of filesystem 5e4b7888-5e56-43f0-8345-635ad0fd87c6 [ 197.921147][ T7153] BTRFS info (device loop3): using blake2b (blake2b-256-generic) checksum algorithm [ 197.937351][ T59] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 197.990398][ T7153] BTRFS info (device loop3): using free-space-tree [ 198.265990][ T7203] loop1: detected capacity change from 0 to 128 [ 198.323698][ T59] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 198.415115][ T7203] EXT4-fs (loop1): mounted filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09 r/w without journal. Quota mode: none. [ 198.473873][ T7203] ext4 filesystem being mounted at /65/mnt supports timestamps until 2038-01-19 (0x7fffffff) [ 198.965341][ T5839] EXT4-fs (loop1): unmounting filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09. [ 198.992337][ T5836] BTRFS info (device loop3): last unmount of filesystem 5e4b7888-5e56-43f0-8345-635ad0fd87c6 [ 199.253411][ T59] bridge_slave_1: left allmulticast mode [ 199.291465][ T59] bridge_slave_1: left promiscuous mode [ 199.340154][ T59] bridge0: port 2(bridge_slave_1) entered disabled state [ 199.435410][ T59] bridge_slave_0: left allmulticast mode [ 199.441122][ T59] bridge_slave_0: left promiscuous mode [ 199.447121][ T7220] overlayfs: failed to decode file handle (len=6, type=251, flags=0, err=-22) [ 199.500081][ T59] bridge0: port 1(bridge_slave_0) entered disabled state [ 199.606971][ T5840] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 199.653998][ T5840] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 199.662349][ T5840] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 199.684093][ T5840] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 199.700771][ T5840] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 201.258461][ T7252] loop6: detected capacity change from 0 to 128 [ 201.735146][ T5857] Bluetooth: hci0: command tx timeout [ 201.866648][ T972] usb 5-1: new high-speed USB device number 3 using dummy_hcd [ 202.051384][ T972] usb 5-1: Using ep0 maxpacket: 32 [ 202.102933][ T972] usb 5-1: config index 0 descriptor too short (expected 156, got 27) [ 202.111158][ T972] usb 5-1: too many endpoints for config 0 interface 0 altsetting 191: 144, using maximum allowed: 30 [ 202.165094][ T972] usb 5-1: config 0 interface 0 altsetting 191 endpoint 0x87 has an invalid bInterval 0, changing to 7 [ 202.183100][ T972] usb 5-1: config 0 interface 0 altsetting 191 has 1 endpoint descriptor, different from the interface descriptor's value: 144 [ 202.272876][ T972] usb 5-1: config 0 interface 0 has no altsetting 0 [ 202.298542][ T972] usb 5-1: New USB device found, idVendor=0f11, idProduct=1021, bcdDevice=86.66 [ 202.322901][ T972] usb 5-1: New USB device strings: Mfr=85, Product=120, SerialNumber=172 [ 202.350671][ T972] usb 5-1: Product: syz [ 202.362221][ T972] usb 5-1: Manufacturer: syz [ 202.379165][ T972] usb 5-1: SerialNumber: syz [ 202.409589][ T972] usb 5-1: config 0 descriptor?? [ 202.444694][ T972] ldusb 5-1:0.0: Interrupt out endpoint not found (using control endpoint instead) [ 202.471072][ T972] ldusb 5-1:0.0: LD USB Device #0 now attached to major 180 minor 0 [ 202.527642][ T59] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 202.573451][ T59] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 202.611257][ T59] bond0 (unregistering): Released all slaves [ 202.623350][ T24] usb 2-1: new high-speed USB device number 7 using dummy_hcd [ 202.798560][ T24] usb 2-1: Using ep0 maxpacket: 32 [ 202.825568][ T24] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 202.851128][ T24] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 202.872915][ T972] usb 7-1: new high-speed USB device number 2 using dummy_hcd [ 202.897101][ T24] usb 2-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 202.935424][ T24] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 202.984401][ T24] usb 2-1: config 0 descriptor?? [ 203.030251][ T5821] usb 5-1: USB disconnect, device number 3 [ 203.030266][ C1] ldusb 5-1:0.0: usb_submit_urb failed (-19) [ 203.043147][ T972] usb 7-1: Using ep0 maxpacket: 16 [ 203.051750][ T24] hub 2-1:0.0: USB hub found [ 203.057011][ T7281] ldusb 5-1:0.0: Couldn't submit HID_REQ_SET_REPORT -71 [ 203.070634][ T972] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 203.100269][ T972] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 203.110030][ T5821] ldusb 5-1:0.0: LD USB Device #0 now disconnected [ 203.110170][ T972] usb 7-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 3 [ 203.189590][ T972] usb 7-1: New USB device found, idVendor=0955, idProduct=7214, bcdDevice=ed.00 [ 203.220032][ T24] hub 2-1:0.0: 1 port detected [ 203.247973][ T972] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 203.311223][ T972] usb 7-1: config 0 descriptor?? [ 203.729163][ T59] hsr_slave_0: left promiscuous mode [ 203.759022][ T972] shield 0003:0955:7214.0004: unknown main item tag 0x0 [ 203.803123][ T59] hsr_slave_1: left promiscuous mode [ 203.809292][ T59] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 203.813056][ T972] shield 0003:0955:7214.0004: unknown main item tag 0x0 [ 203.835383][ T5857] Bluetooth: hci0: command tx timeout [ 203.843676][ T24] hub 2-1:0.0: activate --> -90 [ 203.859604][ T972] shield 0003:0955:7214.0004: unknown main item tag 0x0 [ 203.868031][ T972] shield 0003:0955:7214.0004: unknown main item tag 0x0 [ 203.875380][ T972] shield 0003:0955:7214.0004: unknown main item tag 0x0 [ 203.884168][ T59] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 203.898265][ T1299] ieee802154 phy0 wpan0: encryption failed: -22 [ 203.899139][ T972] input: HID 0955:7214 Haptics as /devices/virtual/input/input8 [ 203.906082][ T1299] ieee802154 phy1 wpan1: encryption failed: -22 [ 203.940793][ T7277] random: crng reseeded on system resumption [ 204.009221][ T59] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 204.067386][ T59] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 204.091889][ T7309] loop3: detected capacity change from 0 to 1024 [ 204.109158][ T972] shield 0003:0955:7214.0004: Registered Thunderstrike controller [ 204.129979][ T7309] EXT4-fs: Ignoring removed oldalloc option [ 204.155099][ T972] shield 0003:0955:7214.0004: : USB HID v0.00 Device [HID 0955:7214] on usb-dummy_hcd.6-1/input0 [ 204.176160][ T7309] EXT4-fs: Ignoring removed orlov option [ 204.200928][ T7309] EXT4-fs (loop3): stripe (2) is not aligned with cluster size (16), stripe is disabled [ 204.234967][ T59] veth1_macvtap: left promiscuous mode [ 204.259702][ T59] veth0_macvtap: left promiscuous mode [ 204.269594][ T6022] shield 0003:0955:7214.0004: Failed to output Thunderstrike HOSTCMD request HID report due to -EPROTO [ 204.287795][ T972] usb 7-1: USB disconnect, device number 2 [ 204.301374][ T59] veth1_vlan: left promiscuous mode [ 204.308593][ T6022] shield 0003:0955:7214.0004: Failed to output Thunderstrike HOSTCMD request HID report due to -ENODEV [ 204.335595][ T59] veth0_vlan: left promiscuous mode [ 204.346524][ T6022] shield 0003:0955:7214.0004: Failed to output Thunderstrike HOSTCMD request HID report due to -ENODEV [ 204.363324][ T7309] EXT4-fs (loop3): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 204.423915][ T6022] shield 0003:0955:7214.0004: Failed to output Thunderstrike HOSTCMD request HID report due to -ENODEV [ 204.468339][ T5932] usb 2-1: USB disconnect, device number 7 [ 204.547304][ T7309] EXT4-fs error (device loop3): mb_free_blocks:1945: group 0, inode 15: block 225:freeing already freed block (bit 14); block bitmap corrupt. [ 204.574111][ T24] usb 2-1-port1: config error [ 204.857520][ T5836] EXT4-fs (loop3): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 205.752223][ T59] team0 (unregistering): Port device team_slave_1 removed [ 205.795529][ T59] team0 (unregistering): Port device team_slave_0 removed [ 205.893116][ T5857] Bluetooth: hci0: command tx timeout [ 206.969785][ T7361] loop6: detected capacity change from 0 to 1024 [ 207.018118][ T7361] EXT4-fs: Ignoring removed orlov option [ 207.203851][ T7361] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 207.406063][ T30] audit: type=1804 audit(1749620457.756:47): pid=7361 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.6.405" name="/newroot/27/bus/bus" dev="loop6" ino=18 res=1 errno=0 [ 207.513316][ T30] audit: type=1804 audit(1749620457.756:48): pid=7376 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=ToMToU comm="syz.6.405" name="/newroot/27/bus/bus" dev="loop6" ino=18 res=1 errno=0 [ 207.671915][ T7223] chnl_net:caif_netlink_parms(): no params data found [ 207.938291][ T6515] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 207.983876][ T5857] Bluetooth: hci0: command tx timeout [ 208.376784][ T7223] bridge0: port 1(bridge_slave_0) entered blocking state [ 208.386450][ T7223] bridge0: port 1(bridge_slave_0) entered disabled state [ 208.402621][ T7223] bridge_slave_0: entered allmulticast mode [ 208.425700][ T7223] bridge_slave_0: entered promiscuous mode [ 208.467910][ T7223] bridge0: port 2(bridge_slave_1) entered blocking state [ 208.490633][ T7223] bridge0: port 2(bridge_slave_1) entered disabled state [ 208.513026][ T7223] bridge_slave_1: entered allmulticast mode [ 208.549955][ T7223] bridge_slave_1: entered promiscuous mode [ 208.811497][ T7365] loop1: detected capacity change from 0 to 40427 [ 208.861169][ T7223] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 208.870760][ T7365] F2FS-fs (loop1): build fault injection rate: 690 [ 208.900856][ T7365] F2FS-fs (loop1): invalid crc value [ 208.960258][ T7223] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 209.320711][ T7365] F2FS-fs (loop1): Mounted with checkpoint version = 48b305e5 [ 209.440115][ T49] bio_check_eod: 2 callbacks suppressed [ 209.440139][ T49] kworker/u8:3: attempt to access beyond end of device [ 209.440139][ T49] loop1: rw=2049, sector=45096, nr_sectors = 8 limit=40427 [ 209.489802][ T7427] syz.1.407: attempt to access beyond end of device [ 209.489802][ T7427] loop1: rw=524288, sector=45064, nr_sectors = 8 limit=40427 [ 209.492161][ T7223] team0: Port device team_slave_0 added [ 209.550088][ T49] CPU: 0 UID: 0 PID: 49 Comm: kworker/u8:3 Not tainted 6.16.0-rc1-syzkaller-00004-gaef17cb3d3c4 #0 PREEMPT(full) [ 209.550142][ T49] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 209.550167][ T49] Workqueue: writeback wb_workfn (flush-7:1) [ 209.550213][ T49] Call Trace: [ 209.550224][ T49] [ 209.550237][ T49] dump_stack_lvl+0x16c/0x1f0 [ 209.550304][ T49] f2fs_handle_critical_error+0x621/0x9f0 [ 209.550352][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.550398][ T49] ? f2fs_build_fault_attr+0x53/0x1f0 [ 209.550447][ T49] f2fs_write_end_io+0x785/0xc20 [ 209.550500][ T49] ? __pfx_f2fs_write_end_io+0x10/0x10 [ 209.550555][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.550609][ T49] ? __pfx_f2fs_write_end_io+0x10/0x10 [ 209.550658][ T49] bio_endio+0x70d/0x850 [ 209.550699][ T49] submit_bio_noacct+0x56d/0x1eb0 [ 209.550761][ T49] __submit_merged_bio+0x33c/0x770 [ 209.550824][ T49] __submit_merged_write_cond+0x319/0x3f0 [ 209.550885][ T49] f2fs_write_cache_pages+0x2067/0x2570 [ 209.550973][ T49] ? __pfx_f2fs_write_cache_pages+0x10/0x10 [ 209.551028][ T49] ? ret_from_fork+0x5d7/0x6f0 [ 209.551086][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551132][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551176][ T49] ? unwind_get_return_address+0x59/0xa0 [ 209.551238][ T49] ? arch_stack_walk+0x88/0x100 [ 209.551298][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551422][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551475][ T49] f2fs_write_data_pages+0x4ad/0xd90 [ 209.551540][ T49] ? __pfx_f2fs_write_data_pages+0x10/0x10 [ 209.551609][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551658][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551702][ T49] ? __pfx_f2fs_write_data_pages+0x10/0x10 [ 209.551762][ T49] do_writepages+0x27a/0x600 [ 209.551832][ T49] ? __pfx_do_writepages+0x10/0x10 [ 209.551888][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.551932][ T49] ? reacquire_held_locks+0xcd/0x1f0 [ 209.551990][ T49] ? writeback_sb_inodes+0x3a4/0xf90 [ 209.552056][ T49] __writeback_single_inode+0x160/0xfb0 [ 209.552120][ T49] ? __pfx___writeback_single_inode+0x10/0x10 [ 209.552179][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.552223][ T49] ? do_raw_spin_unlock+0x172/0x230 [ 209.552262][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.552314][ T49] writeback_sb_inodes+0x601/0xf90 [ 209.552397][ T49] ? __pfx_writeback_sb_inodes+0x10/0x10 [ 209.552458][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.552501][ T49] ? do_raw_spin_lock+0x12c/0x2b0 [ 209.552603][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.552647][ T49] ? rcu_is_watching+0x12/0xc0 [ 209.552692][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.552736][ T49] ? queue_io+0x3f6/0x520 [ 209.552802][ T49] wb_writeback+0x419/0xb70 [ 209.552874][ T49] ? __pfx_wb_writeback+0x10/0x10 [ 209.552929][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.552987][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553031][ T49] ? mark_held_locks+0x49/0x80 [ 209.553097][ T49] wb_workfn+0x14d/0xbe0 [ 209.553136][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553179][ T49] ? try_to_wake_up+0x157/0x1680 [ 209.553224][ T49] ? __pfx_wb_workfn+0x10/0x10 [ 209.553289][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553339][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553389][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553432][ T49] ? rcu_is_watching+0x12/0xc0 [ 209.553485][ T49] process_one_work+0x9cf/0x1b70 [ 209.553538][ T49] ? __pfx_batadv_nc_worker+0x10/0x10 [ 209.553597][ T49] ? __pfx_process_one_work+0x10/0x10 [ 209.553635][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553711][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553755][ T49] ? assign_work+0x1a0/0x250 [ 209.553831][ T49] worker_thread+0x6c8/0xf10 [ 209.553880][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553926][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.553970][ T49] ? __kthread_parkme+0x19e/0x250 [ 209.554018][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.554065][ T49] ? __pfx_worker_thread+0x10/0x10 [ 209.554103][ T49] kthread+0x3c5/0x780 [ 209.554164][ T49] ? __pfx_kthread+0x10/0x10 [ 209.554226][ T49] ? srso_alias_return_thunk+0x5/0xfbef5 [ 209.554270][ T49] ? rcu_is_watching+0x12/0xc0 [ 209.554315][ T49] ? __pfx_kthread+0x10/0x10 [ 209.554375][ T49] ret_from_fork+0x5d7/0x6f0 [ 209.554428][ T49] ? __pfx_kthread+0x10/0x10 [ 209.554489][ T49] ret_from_fork_asm+0x1a/0x30 [ 209.554551][ T49] [ 210.041433][ T49] F2FS-fs (loop1): Stopped filesystem due to reason: 3 [ 210.050472][ T7223] team0: Port device team_slave_1 added [ 210.073223][ T7427] syz.1.407: attempt to access beyond end of device [ 210.073223][ T7427] loop1: rw=0, sector=45064, nr_sectors = 8 limit=40427 [ 210.582395][ T7445] netlink: 4 bytes leftover after parsing attributes in process `syz.6.428'. [ 210.639869][ T7223] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 210.673221][ T7223] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 210.789753][ T7223] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 211.193676][ T7223] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 211.200672][ T7223] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 211.324806][ T7223] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 211.806887][ T7469] Driver unsupported XDP return value 0 on prog (id 77) dev N/A, expect packet loss! [ 211.883779][ T49] Bluetooth: hci4: Frame reassembly failed (-84) [ 211.967372][ T7223] hsr_slave_0: entered promiscuous mode [ 211.988666][ T7223] hsr_slave_1: entered promiscuous mode [ 212.015615][ T7223] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 212.038292][ T7223] Cannot create hsr debugfs directory [ 212.400231][ T7487] xt_CT: You must specify a L4 protocol and not use inversions on it [ 212.449064][ T7487] syzkaller0: tun_chr_ioctl cmd 1074025678 [ 212.463132][ T7487] syzkaller0: group set to 60929 [ 212.892569][ T7499] loop4: detected capacity change from 0 to 256 [ 212.961149][ T7499] exFAT-fs (loop4): Volume was not properly unmounted. Some data may be corrupt. Please run fsck. [ 213.104189][ T7499] exFAT-fs (loop4): Medium has reported failures. Some data may be lost. [ 213.216333][ T7499] exFAT-fs (loop4): failed to load upcase table (idx : 0x00010000, chksum : 0xe62de5da, utbl_chksum : 0xe619d30d) [ 213.402188][ T7499] exFAT-fs (loop4): abnormal access to deleted dentry [ 213.523112][ T5821] usb 2-1: new high-speed USB device number 8 using dummy_hcd [ 213.708143][ T5821] usb 2-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 213.752538][ T5821] usb 2-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 213.819618][ T5821] usb 2-1: New USB device found, idVendor=08b7, idProduct=0000, bcdDevice= 0.00 [ 213.864312][ T5821] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=3 [ 213.893327][ T5840] Bluetooth: hci4: command 0x1003 tx timeout [ 213.895280][ T5857] Bluetooth: hci4: Opcode 0x1003 failed: -110 [ 213.915734][ T5821] usb 2-1: SerialNumber: syz [ 214.122943][ T3399] usb 5-1: new high-speed USB device number 4 using dummy_hcd [ 214.189317][ T5821] usb 2-1: 0:2 : does not exist [ 214.292018][ T5821] usb 2-1: USB disconnect, device number 8 [ 214.323587][ T3399] usb 5-1: Using ep0 maxpacket: 8 [ 214.339670][ T3399] usb 5-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid maxpacket 56832, setting to 1024 [ 214.389899][ T3399] usb 5-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 1024 [ 214.421778][ T6687] udevd[6687]: error opening ATTR{/sys/devices/platform/dummy_hcd.1/usb2/2-1/2-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 214.445229][ T3399] usb 5-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 214.483396][ T3399] usb 5-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 214.525927][ T3399] usb 5-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 214.555934][ T3399] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 214.833109][ T3399] usb 5-1: GET_CAPABILITIES returned 0 [ 214.838709][ T3399] usbtmc 5-1:16.0: can't read capabilities [ 214.929139][ T7223] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 214.995610][ T24] usb 4-1: new high-speed USB device number 4 using dummy_hcd [ 215.041775][ T7223] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 215.072745][ T5821] usb 5-1: USB disconnect, device number 4 [ 215.111083][ T7223] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 215.152400][ T7548] loop1: detected capacity change from 0 to 2048 [ 215.169254][ T24] usb 4-1: Using ep0 maxpacket: 32 [ 215.180229][ T7548] UDF-fs: warning (device loop1): udf_load_vrs: No anchor found [ 215.196486][ T7223] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 215.217880][ T24] usb 4-1: config index 0 descriptor too short (expected 29220, got 36) [ 215.228501][ T7548] UDF-fs: Scanning with blocksize 512 failed [ 215.244179][ T24] usb 4-1: config 0 has too many interfaces: 81, using maximum allowed: 32 [ 215.269014][ T7548] UDF-fs: INFO Mounting volume 'LinuxUDF', timestamp 2022/11/22 14:59 (1000) [ 215.291541][ T24] usb 4-1: config 0 has 1 interface, different from the descriptor's value: 81 [ 215.311445][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x1 has invalid wMaxPacketSize 0 [ 215.363459][ T24] usb 4-1: config 0 interface 0 altsetting 0 bulk endpoint 0x1 has invalid maxpacket 0 [ 215.400150][ T24] usb 4-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 18 [ 215.468483][ T24] usb 4-1: New USB device found, idVendor=03f0, idProduct=6c17, bcdDevice= 0.40 [ 215.500112][ T24] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 215.548039][ T24] usb 4-1: config 0 descriptor?? [ 215.782658][ T7223] 8021q: adding VLAN 0 to HW filter on device bond0 [ 215.860732][ T24] usblp 4-1:0.0: usblp0: USB Bidirectional printer dev 4 if 0 alt 0 proto 3 vid 0x03F0 pid 0x6C17 [ 215.966487][ T7223] 8021q: adding VLAN 0 to HW filter on device team0 [ 216.006426][ T24] usb 4-1: USB disconnect, device number 4 [ 216.052666][ T1320] bridge0: port 1(bridge_slave_0) entered blocking state [ 216.059907][ T1320] bridge0: port 1(bridge_slave_0) entered forwarding state [ 216.093375][ T24] usblp0: removed [ 216.128399][ T1320] bridge0: port 2(bridge_slave_1) entered blocking state [ 216.135635][ T1320] bridge0: port 2(bridge_slave_1) entered forwarding state [ 216.462236][ T7579] netlink: 'syz.4.468': attribute type 1 has an invalid length. [ 216.508777][ T24] usb 4-1: new full-speed USB device number 5 using dummy_hcd [ 216.568480][ T7584] netlink: 4 bytes leftover after parsing attributes in process `syz.4.468'. [ 216.641979][ T7579] 8021q: adding VLAN 0 to HW filter on device bond1 [ 216.704384][ T24] usb 4-1: config index 0 descriptor too short (expected 29220, got 36) [ 216.736992][ T24] usb 4-1: config 0 has too many interfaces: 81, using maximum allowed: 32 [ 216.780905][ T24] usb 4-1: config 0 has 1 interface, different from the descriptor's value: 81 [ 216.812427][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x1 has invalid wMaxPacketSize 0 [ 216.843836][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x82 has invalid maxpacket 512, setting to 64 [ 216.881824][ T24] usb 4-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 18 [ 216.925404][ T24] usb 4-1: New USB device found, idVendor=03f0, idProduct=6c17, bcdDevice= 0.40 [ 216.984632][ T24] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 217.035569][ T24] usb 4-1: config 0 descriptor?? [ 217.042467][ T7541] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 217.297385][ T24] usblp 4-1:0.0: usblp0: USB Bidirectional printer dev 5 if 0 alt 0 proto 3 vid 0x03F0 pid 0x6C17 [ 217.462161][ T7605] overlayfs: failed to decode file handle (len=5, type=251, flags=0, err=-22) [ 217.522193][ T7584] bond1 (unregistering): Released all slaves [ 217.571235][ C1] usblp0: nonzero read bulk status received: -71 [ 217.595258][ T7541] usblp0: error -71 reading from printer [ 217.605598][ C0] usblp0: nonzero read bulk status received: -71 [ 217.618694][ T5821] usb 4-1: USB disconnect, device number 5 [ 217.652256][ T7602] ipip0: entered promiscuous mode [ 217.663656][ T5821] usblp0: removed [ 218.178313][ T7223] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 218.515834][ T7223] veth0_vlan: entered promiscuous mode [ 218.572476][ T7631] Bluetooth: MGMT ver 1.23 [ 218.605782][ T7223] veth1_vlan: entered promiscuous mode [ 219.009540][ T7223] veth0_macvtap: entered promiscuous mode [ 219.065134][ T7223] veth1_macvtap: entered promiscuous mode [ 219.176828][ T7223] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 219.306480][ T7648] netlink: 'syz.2.492': attribute type 1 has an invalid length. [ 219.376980][ T7652] netlink: 4 bytes leftover after parsing attributes in process `syz.2.492'. [ 219.472148][ T7648] 8021q: adding VLAN 0 to HW filter on device bond2 [ 219.604232][ T7650] macvlan1: entered promiscuous mode [ 219.675303][ T7650] ipvlan0: entered promiscuous mode [ 219.710832][ T7650] ipvlan0: left promiscuous mode [ 219.734017][ T7650] macvlan1: left promiscuous mode [ 220.011153][ T7628] loop3: detected capacity change from 0 to 32768 [ 220.052567][ T7628] XFS: attr2 mount option is deprecated. [ 220.141318][ T7628] XFS (loop3): DAX unsupported by block device. Turning off DAX. [ 220.172325][ T7628] XFS (loop3): Mounting V5 Filesystem c496e05e-540d-4c72-b591-04d79d8b4eeb [ 220.335674][ T7628] XFS (loop3): Ending clean mount [ 220.363905][ T7669] loop6: detected capacity change from 0 to 1024 [ 220.384436][ T7669] EXT4-fs: Ignoring removed nobh option [ 220.426378][ T7669] EXT4-fs: Ignoring removed bh option [ 220.572335][ T7669] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 220.729817][ T7669] EXT4-fs warning (device loop6): ext4_rename_delete:3724: inode #12: comm syz.6.497: Deleting old file: nlink 2, error=-2 [ 220.755873][ T7652] bond2 (unregistering): Released all slaves [ 220.967811][ T7223] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 221.009435][ T6515] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 221.132911][ T5836] XFS (loop3): Unmounting Filesystem c496e05e-540d-4c72-b591-04d79d8b4eeb [ 221.180979][ T7223] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 221.251707][ T7223] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 221.261150][ T7223] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 221.274254][ T7223] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 222.519114][ T7700] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 222.586090][ T7700] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 222.736184][ T59] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 222.788154][ T59] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 223.179338][ T7741] overlayfs: failed to resolve './file0/../file0': -2 [ 223.272157][ T7753] syzkaller1: entered promiscuous mode [ 223.298165][ T7753] syzkaller1: entered allmulticast mode [ 223.939557][ T7769] netlink: 'syz.0.514': attribute type 1 has an invalid length. [ 224.001168][ T7769] netlink: 4 bytes leftover after parsing attributes in process `syz.0.514'. [ 224.173705][ T7777] loop4: detected capacity change from 0 to 1024 [ 224.341662][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.413447][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.466473][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.643299][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.684447][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.691780][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.793991][ T7779] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.823086][ T7779] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.849843][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.876337][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.888131][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.902750][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.920448][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.934638][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 224.985960][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.026932][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.109258][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.133125][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.173395][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.180732][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.253138][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.260662][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.338127][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.385708][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.445117][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.480952][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.499481][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.562850][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.592252][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.631290][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.669451][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.682408][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.770442][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.800461][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.922976][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.944885][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 225.984212][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 226.017741][ T7777] hfsplus: request for non-existent node 16777216 in B*Tree [ 226.045184][ T30] audit: type=1800 audit(1749620476.386:49): pid=7777 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.4.517" name="file1" dev="loop4" ino=20 res=0 errno=0 [ 226.127012][ T7815] loop1: detected capacity change from 0 to 32768 [ 226.162548][ T7815] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop1 (7:1) scanned by syz.1.529 (7815) [ 226.180486][ T7815] BTRFS info (device loop1): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 226.190709][ T7815] BTRFS info (device loop1): using crc32c (crc32c-x86_64) checksum algorithm [ 226.199559][ T7815] BTRFS info (device loop1): using free-space-tree [ 226.297406][ T7700] hfsplus: request for non-existent node 16777216 in B*Tree [ 226.372112][ T7700] hfsplus: request for non-existent node 16777216 in B*Tree [ 226.664531][ T7845] netlink: 'syz.6.531': attribute type 1 has an invalid length. [ 226.749350][ T7845] 8021q: adding VLAN 0 to HW filter on device bond1 [ 226.783592][ T7851] netlink: 4 bytes leftover after parsing attributes in process `syz.6.531'. [ 226.860158][ T5839] BTRFS info (device loop1): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 227.013363][ T7849] loop4: detected capacity change from 0 to 4096 [ 227.147749][ T7854] NILFS (loop4): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 228.526636][ T7851] bond1 (unregistering): Released all slaves [ 228.744186][ T7860] netlink: 8 bytes leftover after parsing attributes in process `syz.1.533'. [ 228.780152][ T7860] netlink: 8 bytes leftover after parsing attributes in process `syz.1.533'. [ 228.789206][ T7873] syz_tun: entered allmulticast mode [ 228.854248][ T7871] syz_tun: left allmulticast mode [ 228.957939][ T3399] usb 5-1: new high-speed USB device number 5 using dummy_hcd [ 229.142960][ T3399] usb 5-1: Using ep0 maxpacket: 8 [ 229.185588][ T3399] usb 5-1: New USB device found, idVendor=0c45, idProduct=613a, bcdDevice=c4.6d [ 229.212898][ T3399] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 229.238893][ T3399] usb 5-1: Product: syz [ 229.252564][ T3399] usb 5-1: Manufacturer: syz [ 229.273515][ T3399] usb 5-1: SerialNumber: syz [ 229.316880][ T3399] usb 5-1: config 0 descriptor?? [ 229.350656][ T3399] gspca_main: sonixj-2.14.0 probing 0c45:613a [ 230.802900][ T3399] gspca_sonixj: i2c_w8 err -71 [ 230.915276][ T3399] sonixj 5-1:0.0: probe with driver sonixj failed with error -71 [ 230.962596][ T3399] usb 5-1: USB disconnect, device number 5 [ 231.000827][ T7908] loop1: detected capacity change from 0 to 32768 [ 231.391308][ T7920] netlink: 76 bytes leftover after parsing attributes in process `syz.0.553'. [ 231.585994][ T5150] Bluetooth: hci1: command 0x0406 tx timeout [ 231.594356][ T5150] Bluetooth: hci3: command 0x0406 tx timeout [ 231.600803][ T5844] Bluetooth: hci2: command 0x0406 tx timeout [ 231.608736][ T5847] Bluetooth: hci5: command 0x0406 tx timeout [ 231.960688][ T7908] JBD2: Ignoring recovery information on journal [ 232.634467][ T7909] loop3: detected capacity change from 0 to 32768 [ 232.727228][ T7909] XFS (loop3): Mounting V5 Filesystem bfdc47fc-10d8-4eed-a562-11a831b3f791 [ 232.948944][ T7908] ocfs2: Mounting device (7,1) on (node local, slot 0) with writeback data mode. [ 232.997873][ T7909] XFS (loop3): Ending clean mount [ 233.018425][ T7909] XFS (loop3): Quotacheck needed: Please wait. [ 233.032321][ T7908] (syz.1.550,7908,1):ocfs2_remove_inode_range:1794 ERROR: status = -22 [ 233.043668][ T7908] (syz.1.550,7908,1):__ocfs2_change_file_space:2045 ERROR: status = -22 [ 233.150801][ T7909] XFS (loop3): Quotacheck: Done. [ 233.273095][ T30] audit: type=1800 audit(1749620483.606:50): pid=7909 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.548" name="file1" dev="loop3" ino=9286 res=0 errno=0 [ 233.447107][ T30] audit: type=1800 audit(1749620483.666:51): pid=7909 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.548" name="file2" dev="loop3" ino=9287 res=0 errno=0 [ 233.516616][ T5839] ocfs2: Unmounting device (7,1) on (node local) [ 233.597435][ T7916] loop6: detected capacity change from 0 to 262144 [ 233.611432][ T7916] BTRFS: device fsid 7e32c2af-f87a-45a1-bcba-64dea7c56a53 devid 1 transid 8 /dev/loop6 (7:6) scanned by syz.6.552 (7916) [ 234.287573][ T7944] loop0: detected capacity change from 0 to 65536 [ 234.382191][ T7957] netlink: 'syz.1.554': attribute type 1 has an invalid length. [ 234.393572][ T7944] XFS (loop0): Mounting V5 Filesystem 9b7348e5-2fa0-41a5-9526-c53a678b01f3 [ 234.422907][ T972] usb 5-1: new high-speed USB device number 6 using dummy_hcd [ 234.441456][ T5836] XFS (loop3): Unmounting Filesystem bfdc47fc-10d8-4eed-a562-11a831b3f791 [ 234.450436][ T7963] netlink: 4 bytes leftover after parsing attributes in process `syz.1.554'. [ 234.482322][ T7944] XFS (loop0): Ending clean mount [ 234.666340][ T972] usb 5-1: Using ep0 maxpacket: 8 [ 234.705101][ T972] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 234.733129][ T972] usb 5-1: New USB device found, idVendor=046d, idProduct=0892, bcdDevice=6d.2a [ 234.753183][ T972] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 234.769199][ T7957] 8021q: adding VLAN 0 to HW filter on device bond1 [ 234.776060][ T972] usb 5-1: config 0 descriptor?? [ 234.815788][ T972] gspca_main: vc032x-2.14.0 probing 046d:0892 [ 235.414404][ T7223] XFS (loop0): Unmounting Filesystem 9b7348e5-2fa0-41a5-9526-c53a678b01f3 [ 235.966491][ T7963] bond1 (unregistering): Released all slaves [ 236.240326][ T972] gspca_vc032x: reg_w err -71 [ 236.250432][ T972] vc032x 5-1:0.0: probe with driver vc032x failed with error -71 [ 236.360172][ T972] usb 5-1: USB disconnect, device number 6 [ 237.199927][ T8008] netlink: 28 bytes leftover after parsing attributes in process `syz.4.582'. [ 237.246156][ T8008] netlink: 'syz.4.582': attribute type 7 has an invalid length. [ 237.275185][ T8008] netlink: 'syz.4.582': attribute type 8 has an invalid length. [ 237.305199][ T8008] netlink: 4 bytes leftover after parsing attributes in process `syz.4.582'. [ 238.106782][ T8019] loop6: detected capacity change from 0 to 40427 [ 238.146550][ T8019] F2FS-fs (loop6): Invalid log_blocksize (268), supports only 12 [ 238.154371][ T8019] F2FS-fs (loop6): Can't find valid F2FS filesystem in 1th superblock [ 238.211738][ T8019] F2FS-fs (loop6): invalid crc value [ 238.400921][ T8019] F2FS-fs (loop6): Try to recover 1th superblock, ret: 0 [ 238.412305][ T8019] F2FS-fs (loop6): Mounted with checkpoint version = 48b305e5 [ 238.770763][ T8023] bridge0: port 2(bridge_slave_1) entered disabled state [ 238.786197][ T8029] loop3: detected capacity change from 0 to 4096 [ 239.056859][ T8038] NILFS (loop3): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 239.481588][ T8047] loop0: detected capacity change from 0 to 128 [ 239.661886][ T30] audit: type=1800 audit(1749620489.986:52): pid=8047 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.0.583" name="file0" dev="loop0" ino=1048624 res=0 errno=0 [ 239.930702][ T8052] loop4: detected capacity change from 0 to 512 [ 240.053577][ T8052] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000d40000 r/w without journal. Quota mode: writeback. [ 240.163071][ T8052] ext4 filesystem being mounted at /98/file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa supports timestamps until 2038-01-19 (0x7fffffff) [ 240.219105][ T8050] syz.0.583: attempt to access beyond end of device [ 240.219105][ T8050] loop0: rw=0, sector=121, nr_sectors = 8 limit=128 [ 240.528087][ T8064] EXT4-fs error (device loop4): ext4_ext_check_inode:523: inode #12: comm syz.4.584: pblk 0 bad header/extent: invalid extent entries - magic f30a, entries 1, max 4(4), depth 0(0) [ 240.687032][ T7710] kworker/u8:13: attempt to access beyond end of device [ 240.687032][ T7710] loop0: rw=1, sector=129, nr_sectors = 912 limit=128 [ 240.834308][ T8071] gretap0: entered promiscuous mode [ 240.895284][ T8071] vlan2: entered promiscuous mode [ 241.079688][ T5848] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000d40000. [ 241.479685][ T8080] overlayfs: failed to decode file handle (len=6, type=0, flags=0, err=-22) [ 241.634630][ T8082] batman_adv: Cannot find parent device. Skipping batadv-on-batadv check for ip6gretap1 [ 241.746942][ T8082] batman_adv: batadv0: Adding interface: ip6gretap1 [ 241.808535][ T8082] batman_adv: batadv0: The MTU of interface ip6gretap1 is too small (1434) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 241.905067][ T8095] serio: Serial port ptm0 [ 241.992988][ T8082] batman_adv: batadv0: Interface activated: ip6gretap1 [ 242.620727][ T8108] loop6: detected capacity change from 0 to 4096 [ 242.719544][ T30] audit: type=1326 audit(1749620493.066:53): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=8112 comm="syz.2.601" exe="/root/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7f2ab6b8e929 code=0x0 [ 242.789853][ T8118] NILFS (loop6): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 243.660613][ T8131] loop1: detected capacity change from 0 to 4096 [ 243.729824][ T8131] ntfs3: Invalid value for dmask. [ 243.944343][ T8143] netlink: 'syz.4.612': attribute type 1 has an invalid length. [ 243.993512][ T8143] netlink: 'syz.4.612': attribute type 4 has an invalid length. [ 244.035053][ T8143] netlink: 9462 bytes leftover after parsing attributes in process `syz.4.612'. [ 244.516655][ T8117] loop0: detected capacity change from 0 to 32768 [ 244.562363][ T8117] BTRFS: device fsid 5e4b7888-5e56-43f0-8345-635ad0fd87c6 devid 1 transid 8 /dev/loop0 (7:0) scanned by syz.0.603 (8117) [ 244.663622][ T8117] BTRFS info (device loop0): first mount of filesystem 5e4b7888-5e56-43f0-8345-635ad0fd87c6 [ 244.716872][ T8117] BTRFS info (device loop0): using blake2b (blake2b-256-generic) checksum algorithm [ 244.767630][ T8117] BTRFS info (device loop0): using free-space-tree [ 244.775400][ T3399] usb 7-1: new high-speed USB device number 3 using dummy_hcd [ 244.972894][ T3399] usb 7-1: Using ep0 maxpacket: 8 [ 245.004164][ T3399] usb 7-1: New USB device found, idVendor=04a5, idProduct=3003, bcdDevice=3a.b2 [ 245.062887][ T3399] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 245.114853][ T3399] usb 7-1: Product: syz [ 245.119070][ T3399] usb 7-1: Manufacturer: syz [ 245.185970][ T3399] usb 7-1: SerialNumber: syz [ 245.244099][ T3399] usb 7-1: config 0 descriptor?? [ 245.323152][ T30] audit: type=1800 audit(1749620495.666:54): pid=8117 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.0.603" name="file1" dev="loop0" ino=260 res=0 errno=0 [ 245.563826][ T3399] gspca_main: sunplus-2.14.0 probing 04a5:3003 [ 245.891085][ T7223] BTRFS info (device loop0): last unmount of filesystem 5e4b7888-5e56-43f0-8345-635ad0fd87c6 [ 246.673160][ T1331] Bluetooth: hci4: Frame reassembly failed (-84) [ 246.732461][ T3399] gspca_sunplus: reg_w_riv err -71 [ 246.758062][ T3399] sunplus 7-1:0.0: probe with driver sunplus failed with error -71 [ 246.810486][ T3399] usb 7-1: USB disconnect, device number 3 [ 246.860720][ T8208] loop1: detected capacity change from 0 to 4096 [ 246.991984][ T8212] NILFS (loop1): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 247.406596][ T8218] loop0: detected capacity change from 0 to 512 [ 247.455974][ T8218] EXT4-fs (loop0): mounting ext3 file system using the ext4 subsystem [ 247.565164][ T8218] [EXT4 FS bs=1024, gc=1, bpg=8192, ipg=32, mo=8042c119, mo2=0002] [ 247.702959][ T8218] EXT4-fs error (device loop0): ext4_iget_extra_inode:5034: inode #15: comm syz.0.638: corrupted in-inode xattr: e_value size too large [ 247.777136][ T8218] EXT4-fs error (device loop0): ext4_orphan_get:1396: comm syz.0.638: couldn't read orphan inode 15 (err -117) [ 247.854028][ T8218] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 248.377328][ T8205] loop4: detected capacity change from 0 to 32768 [ 248.409009][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 248.460685][ T8205] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop4 (7:4) scanned by syz.4.624 (8205) [ 248.533011][ T8205] BTRFS info (device loop4): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 248.574401][ T8205] BTRFS info (device loop4): using crc32c (crc32c-x86_64) checksum algorithm [ 248.668580][ T8205] BTRFS info (device loop4): disk space caching is enabled [ 248.693069][ T5843] Bluetooth: hci4: command 0x1003 tx timeout [ 248.700885][ T5851] Bluetooth: hci4: Opcode 0x1003 failed: -110 [ 248.713239][ T8205] BTRFS warning (device loop4): space cache v1 is being deprecated and will be removed in a future release, please use -o space_cache=v2 [ 249.131227][ T8205] BTRFS info (device loop4): rebuilding free space tree [ 249.226149][ T8205] BTRFS info (device loop4): disabling free space tree [ 249.263068][ T8205] BTRFS info (device loop4): clearing compat-ro feature flag for FREE_SPACE_TREE (0x1) [ 249.300197][ T8205] BTRFS info (device loop4): clearing compat-ro feature flag for FREE_SPACE_TREE_VALID (0x2) [ 249.428336][ T8266] loop6: detected capacity change from 0 to 4096 [ 249.510231][ T8266] NILFS (loop6): invalid segment: Checksum error in segment payload [ 249.597728][ T8266] NILFS (loop6): trying rollback from an earlier position [ 249.747715][ T5848] BTRFS info (device loop4): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 249.771374][ T8266] NILFS (loop6): recovery complete [ 249.811533][ T8280] NILFS (loop6): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 249.995721][ T8266] overlayfs: failed to create directory ./file0/work (errno: 1); mounting read-only [ 250.060536][ T8266] overlayfs: failed to get uuid (/file2, err=-95); falling back to uuid=null. [ 250.256433][ T8283] netlink: 168 bytes leftover after parsing attributes in process `syz.3.641'. [ 250.687565][ T8290] process 'syz.0.645' launched './file0' with NULL argv: empty string added [ 250.713386][ T8293] sch_tbf: burst 19872 is lower than device lo mtu (65550) ! [ 251.678106][ T8310] loop3: detected capacity change from 0 to 512 [ 251.857320][ T8310] EXT4-fs (loop3): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 251.901208][ T8310] ext4 filesystem being mounted at /95/bus supports timestamps until 2038-01-19 (0x7fffffff) [ 251.973824][ T8312] loop6: detected capacity change from 0 to 2048 [ 252.045320][ T8312] UDF-fs: INFO Mounting volume 'LinuxUDF', timestamp 2022/11/22 14:59 (1000) [ 252.508120][ T5836] EXT4-fs (loop3): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 252.516855][ T8328] loop1: detected capacity change from 0 to 16 [ 252.645752][ T8328] erofs (device loop1): mounted with root inode @ nid 36. [ 252.752016][ T8328] syz.1.654: attempt to access beyond end of device [ 252.752016][ T8328] loop1: rw=0, sector=14546590680, nr_sectors = 16 limit=16 [ 252.818922][ T8328] erofs (device loop1): read error -5 @ 43 of nid 36 [ 252.907029][ T8336] syz.1.654: attempt to access beyond end of device [ 252.907029][ T8336] loop1: rw=0, sector=14546590680, nr_sectors = 16 limit=16 [ 252.941230][ T8336] erofs (device loop1): read error -5 @ 43 of nid 36 [ 252.993275][ T8338] netlink: 24 bytes leftover after parsing attributes in process `syz.3.656'. [ 253.085770][ T8328] erofs (device loop1): readahead error at folio 40 @ nid 36 [ 253.162949][ T8328] erofs (device loop1): readahead error at folio 39 @ nid 36 [ 253.210500][ T8304] loop4: detected capacity change from 0 to 32768 [ 253.224787][ T8328] erofs (device loop1): readahead error at folio 38 @ nid 36 [ 253.293263][ T8304] ocfs2: Slot 0 on device (7,4) was already allocated to this node! [ 253.293707][ T8343] sch_tbf: burst 511 is lower than device veth3 mtu (1514) ! [ 253.354729][ T8328] erofs (device loop1): readahead error at folio 34 @ nid 36 [ 253.362395][ T8328] erofs (device loop1): readahead error at folio 32 @ nid 36 [ 253.370095][ T8328] erofs (device loop1): readahead error at folio 30 @ nid 36 [ 253.377715][ T8328] erofs (device loop1): readahead error at folio 27 @ nid 36 [ 253.385451][ T8328] erofs (device loop1): readahead error at folio 26 @ nid 36 [ 253.400477][ T8328] erofs (device loop1): readahead error at folio 25 @ nid 36 [ 253.408498][ T8328] erofs (device loop1): readahead error at folio 24 @ nid 36 [ 253.420836][ T8328] erofs (device loop1): readahead error at folio 23 @ nid 36 [ 253.436052][ T8328] erofs (device loop1): readahead error at folio 22 @ nid 36 [ 253.463228][ T8328] erofs (device loop1): readahead error at folio 21 @ nid 36 [ 253.470795][ T8328] erofs (device loop1): readahead error at folio 20 @ nid 36 [ 253.486808][ T8304] ocfs2: Mounting device (7,4) on (node local, slot 0) with ordered data mode. [ 253.513119][ T8328] erofs (device loop1): readahead error at folio 18 @ nid 36 [ 253.543377][ T8328] erofs (device loop1): readahead error at folio 12 @ nid 36 [ 253.571628][ T8328] erofs (device loop1): readahead error at folio 10 @ nid 36 [ 253.647682][ T8328] erofs (device loop1): readahead error at folio 6 @ nid 36 [ 253.687527][ T8328] erofs (device loop1): readahead error at folio 4 @ nid 36 [ 253.721540][ T8328] erofs (device loop1): invalid logical cluster 0 at nid 36 [ 253.743427][ T8328] erofs (device loop1): readahead error at folio 0 @ nid 36 [ 253.780063][ T8328] syz.1.654: attempt to access beyond end of device [ 253.780063][ T8328] loop1: rw=524288, sector=296, nr_sectors = 16 limit=16 [ 253.842697][ T8328] syz.1.654: attempt to access beyond end of device [ 253.842697][ T8328] loop1: rw=524288, sector=1049264, nr_sectors = 16 limit=16 [ 253.940718][ T8328] syz.1.654: attempt to access beyond end of device [ 253.940718][ T8328] loop1: rw=524288, sector=6520, nr_sectors = 16 limit=16 [ 254.025059][ T8328] syz.1.654: attempt to access beyond end of device [ 254.025059][ T8328] loop1: rw=524288, sector=34359736328, nr_sectors = 16 limit=16 [ 254.083175][ T8328] syz.1.654: attempt to access beyond end of device [ 254.083175][ T8328] loop1: rw=524288, sector=720, nr_sectors = 16 limit=16 [ 254.123773][ T8328] syz.1.654: attempt to access beyond end of device [ 254.123773][ T8328] loop1: rw=524288, sector=536576856, nr_sectors = 16 limit=16 [ 254.211670][ T8328] syz.1.654: attempt to access beyond end of device [ 254.211670][ T8328] loop1: rw=524288, sector=13478624032, nr_sectors = 8 limit=16 [ 254.290544][ T8328] syz.1.654: attempt to access beyond end of device [ 254.290544][ T8328] loop1: rw=524288, sector=13716630376, nr_sectors = 8 limit=16 [ 254.293201][ T5848] ocfs2: Unmounting device (7,4) on (node local) [ 254.329661][ T8365] loop6: detected capacity change from 0 to 4096 [ 254.356267][ T8328] erofs (device loop1): readahead error at folio 86 @ nid 36 [ 254.432926][ T8328] erofs (device loop1): readahead error at folio 84 @ nid 36 [ 254.469943][ T8373] NILFS (loop6): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 254.494604][ T8328] erofs (device loop1): readahead error at folio 80 @ nid 36 [ 254.527902][ T8328] erofs (device loop1): readahead error at folio 74 @ nid 36 [ 254.565701][ T8328] erofs (device loop1): readahead error at folio 72 @ nid 36 [ 254.573797][ T8365] mkiss: ax0: crc mode is auto. [ 254.600110][ T8328] erofs (device loop1): readahead error at folio 70 @ nid 36 [ 254.673239][ T8328] erofs (device loop1): bogus lookback distance 1388 @ lcn 62 of nid 36 [ 254.713803][ T8328] erofs (device loop1): readahead error at folio 63 @ nid 36 [ 254.721235][ T8328] erofs (device loop1): bogus lookback distance 1388 @ lcn 62 of nid 36 [ 254.762982][ T8328] erofs (device loop1): readahead error at folio 62 @ nid 36 [ 254.775690][ T8328] erofs (device loop1): readahead error at folio 58 @ nid 36 [ 254.852650][ T8328] erofs (device loop1): readahead error at folio 57 @ nid 36 [ 254.914785][ T8328] erofs (device loop1): readahead error at folio 54 @ nid 36 [ 254.943054][ T8328] erofs (device loop1): readahead error at folio 53 @ nid 36 [ 254.991178][ T8328] erofs (device loop1): readahead error at folio 52 @ nid 36 [ 255.024010][ T8328] erofs (device loop1): readahead error at folio 51 @ nid 36 [ 255.031440][ T8328] erofs (device loop1): bogus lookback distance 363 @ lcn 50 of nid 36 [ 255.074880][ T8328] erofs (device loop1): readahead error at folio 50 @ nid 36 [ 255.130018][ T8328] erofs (device loop1): readahead error at folio 47 @ nid 36 [ 255.137971][ T8328] erofs (device loop1): readahead error at folio 46 @ nid 36 [ 255.157243][ T8379] loop0: detected capacity change from 0 to 4096 [ 255.227467][ T8384] NILFS (loop0): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 255.869475][ T8371] loop3: detected capacity change from 0 to 32768 [ 256.053196][ T8371] BTRFS: device fsid ed167579-eb65-4e76-9a50-61ac97e9b59d devid 1 transid 8 /dev/loop3 (7:3) scanned by syz.3.665 (8371) [ 256.119850][ T8371] BTRFS info (device loop3): first mount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 256.211376][ T8371] BTRFS info (device loop3): using sha256 (sha256-x86_64) checksum algorithm [ 256.277006][ T8371] BTRFS info (device loop3): using free-space-tree [ 256.492040][ T8413] binder: 8407:8413 ioctl c0306201 2000000003c0 returned -14 [ 256.639221][ T8371] BTRFS info (device loop3): rebuilding free space tree [ 256.904266][ T30] audit: type=1804 audit(1749620507.256:55): pid=8371 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.3.665" name="/newroot/98/bus/bus" dev="loop3" ino=263 res=1 errno=0 [ 257.952198][ T5836] BTRFS info (device loop3): last unmount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 258.282963][ T6022] usb 1-1: new high-speed USB device number 6 using dummy_hcd [ 258.482894][ T6022] usb 1-1: Using ep0 maxpacket: 16 [ 258.529513][ T8398] loop4: detected capacity change from 0 to 32768 [ 258.529594][ T8451] loop6: detected capacity change from 0 to 128 [ 258.602949][ T6022] usb 1-1: config 0 has an invalid interface number: 243 but max is 0 [ 258.611174][ T6022] usb 1-1: config 0 has no interface number 0 [ 258.652944][ T6022] usb 1-1: config 0 interface 243 altsetting 0 bulk endpoint 0x81 has invalid maxpacket 1023 [ 258.720047][ T8449] loop1: detected capacity change from 0 to 4096 [ 258.748568][ T6022] usb 1-1: New USB device found, idVendor=06cd, idProduct=010c, bcdDevice=d0.ce [ 258.798837][ T6022] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 258.845791][ T6022] usb 1-1: Product: syz [ 258.865198][ T8453] syz_tun: entered allmulticast mode [ 258.932777][ T6022] usb 1-1: Manufacturer: syz [ 258.952342][ T6022] usb 1-1: SerialNumber: syz [ 258.966250][ T6022] usb 1-1: config 0 descriptor?? [ 258.982160][ T8441] raw-gadget.0 gadget.0: fail, usb_ep_enable returned -22 [ 258.992470][ T6022] keyspan 1-1:0.243: Keyspan 1 port adapter converter detected [ 259.011085][ T6022] keyspan 1-1:0.243: found no endpoint descriptor for endpoint 84 [ 259.052725][ T6022] keyspan 1-1:0.243: found no endpoint descriptor for endpoint 82 [ 259.054033][ T8455] NILFS (loop1): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds [ 259.112395][ T8452] syz_tun: left allmulticast mode [ 259.165997][ T6022] keyspan 1-1:0.243: found no endpoint descriptor for endpoint 1 [ 259.254002][ T6022] keyspan 1-1:0.243: found no endpoint descriptor for endpoint 2 [ 259.284406][ T8449] mkiss: ax0: crc mode is auto. [ 259.292314][ T6022] keyspan 1-1:0.243: found no endpoint descriptor for endpoint 83 [ 259.317245][ T8458] netlink: 8 bytes leftover after parsing attributes in process `syz.3.687'. [ 259.359438][ T6022] keyspan 1-1:0.243: found no endpoint descriptor for endpoint 3 [ 259.416888][ T6022] usb 1-1: Keyspan 1 port adapter converter now attached to ttyUSB0 [ 259.540662][ T6022] usb 1-1: USB disconnect, device number 6 [ 259.634036][ T6022] keyspan_1 ttyUSB0: Keyspan 1 port adapter converter now disconnected from ttyUSB0 [ 259.674533][ T8466] netlink: 2048 bytes leftover after parsing attributes in process `syz.6.688'. [ 259.723819][ T6022] keyspan 1-1:0.243: device disconnected [ 259.733245][ T8466] netlink: 4 bytes leftover after parsing attributes in process `syz.6.688'. [ 259.836773][ T8468] 9pnet: p9_errstr2errno: server reported unknown error ../file0 [ 261.396033][ T8484] loop4: detected capacity change from 0 to 40427 [ 261.433267][ T8484] F2FS-fs (loop4): build fault injection rate: 690 [ 261.440620][ T8484] F2FS-fs (loop4): Image doesn't support compression [ 261.447882][ T8484] F2FS-fs (loop4): Image doesn't support compression [ 261.472021][ T8484] F2FS-fs (loop4): invalid crc value [ 261.591309][ T8494] loop0: detected capacity change from 0 to 512 [ 261.624108][ T8484] F2FS-fs (loop4): Mounted with checkpoint version = 48b305e5 [ 261.629752][ T8494] EXT4-fs (loop0): encrypted files will use data=ordered instead of data journaling mode [ 261.664020][ T8484] F2FS-fs (loop4): Stopped filesystem due to reason: 0 [ 261.670030][ T8500] loop1: detected capacity change from 0 to 256 [ 261.741305][ T8494] EXT4-fs (loop0): 1 truncate cleaned up [ 261.774054][ T8500] exFAT-fs (loop1): failed to load upcase table (idx : 0x000104d0, chksum : 0x60d18cac, utbl_chksum : 0xe619d30d) [ 261.860697][ T8494] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 262.064559][ T8500] exFAT-fs (loop1): error, exfat_alloc_cluster: invalid used clusters(t:15,u:4294967287) [ 262.064559][ T8500] [ 262.094542][ T8494] fscrypt: key with description 'fscrypt:0000111122223333' has invalid payload [ 262.117361][ T8507] loop6: detected capacity change from 0 to 1024 [ 262.142974][ T8500] exFAT-fs (loop1): Filesystem has been set read-only [ 262.340915][ T8507] hfsplus: unable to find HFS+ superblock [ 262.416219][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 262.734989][ T8509] loop3: detected capacity change from 0 to 4096 [ 262.777163][ T8509] ntfs3(loop3): Different NTFS sector size (1024) and media sector size (512). [ 262.898786][ T8513] input: syz1 as /devices/virtual/input/input9 [ 263.303227][ T8518] netlink: 'syz.6.711': attribute type 1 has an invalid length. [ 263.346479][ T8518] netlink: 'syz.6.711': attribute type 4 has an invalid length. [ 263.372551][ T8518] netlink: 9462 bytes leftover after parsing attributes in process `syz.6.711'. [ 263.463070][ T8521] netlink: 'syz.6.711': attribute type 1 has an invalid length. [ 263.513312][ T8521] netlink: 'syz.6.711': attribute type 4 has an invalid length. [ 263.543024][ T8521] netlink: 9462 bytes leftover after parsing attributes in process `syz.6.711'. [ 264.020881][ T8530] loop4: detected capacity change from 0 to 256 [ 264.072978][ T8530] exFAT-fs (loop4): Volume was not properly unmounted. Some data may be corrupt. Please run fsck. [ 264.137774][ T8530] exFAT-fs (loop4): Medium has reported failures. Some data may be lost. [ 264.165026][ T8534] netlink: 40 bytes leftover after parsing attributes in process `syz.3.717'. [ 264.230359][ T8530] exFAT-fs (loop4): failed to load upcase table (idx : 0x00010000, chksum : 0xe62de5da, utbl_chksum : 0xe619d30d) [ 264.325319][ T8536] overlayfs: failed to clone upperpath [ 264.368536][ T8511] loop1: detected capacity change from 0 to 32768 [ 264.441394][ T8511] BTRFS: device fsid a6a605fc-d5f1-4e66-8595-3726e2b761d6 devid 1 transid 8 /dev/loop1 (7:1) scanned by syz.1.709 (8511) [ 264.566785][ T8511] BTRFS info (device loop1): first mount of filesystem a6a605fc-d5f1-4e66-8595-3726e2b761d6 [ 264.579904][ T8542] loop3: detected capacity change from 0 to 512 [ 264.627909][ T8542] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 264.640615][ T8511] BTRFS info (device loop1): using blake2b (blake2b-256-generic) checksum algorithm [ 264.727996][ T8511] BTRFS info (device loop1): using free-space-tree [ 264.753493][ T8542] EXT4-fs (loop3): 1 truncate cleaned up [ 264.761302][ T8542] EXT4-fs (loop3): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 264.957078][ T8542] fscrypt: key with description 'fscrypt:0000111122223333' has invalid payload [ 265.258688][ T8549] netlink: 16 bytes leftover after parsing attributes in process `syz.4.722'. [ 265.298981][ T5836] EXT4-fs (loop3): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 265.353969][ T1299] ieee802154 phy0 wpan0: encryption failed: -22 [ 265.360675][ T1299] ieee802154 phy1 wpan1: encryption failed: -22 [ 265.589617][ T5839] BTRFS info (device loop1): last unmount of filesystem a6a605fc-d5f1-4e66-8595-3726e2b761d6 [ 265.798038][ T8571] input: Bluetooth HID Boot Protocol Device as /devices/virtual/bluetooth/hci0/hci0:200/input10 [ 267.112595][ T8538] loop6: detected capacity change from 0 to 32768 [ 267.198452][ T8538] BTRFS: device fsid 3d39d0ba-bdae-447e-827b-b091e1a68885 devid 1 transid 8 /dev/loop6 (7:6) scanned by syz.6.719 (8538) [ 267.322394][ T8538] BTRFS error (device loop6): open_ctree failed: -4 [ 267.473278][ T8598] binder: 8597:8598 ioctl c0306201 200000000040 returned -14 [ 268.587187][ T8594] loop1: detected capacity change from 0 to 32768 [ 268.658943][ T8594] BTRFS: device fsid ed167579-eb65-4e76-9a50-61ac97e9b59d devid 1 transid 8 /dev/loop1 (7:1) scanned by syz.1.731 (8594) [ 268.753326][ T8594] BTRFS info (device loop1): first mount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 268.822953][ T8594] BTRFS info (device loop1): using sha256 (sha256-x86_64) checksum algorithm [ 268.872333][ T8594] BTRFS info (device loop1): using free-space-tree [ 269.244553][ T8601] loop3: detected capacity change from 0 to 32768 [ 269.257521][ T8594] BTRFS info (device loop1): rebuilding free space tree [ 269.371145][ T8601] XFS (loop3): Mounting V5 Filesystem d7dc424e-7990-42cb-9f91-9cb7200a101d [ 269.515830][ T8601] XFS (loop3): Ending clean mount [ 269.540328][ T8606] loop4: detected capacity change from 0 to 32768 [ 269.557283][ T30] audit: type=1804 audit(1749620519.906:56): pid=8594 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.1.731" name="/newroot/126/bus/bus" dev="loop1" ino=263 res=1 errno=0 [ 269.700733][ T30] audit: type=1800 audit(1749620520.046:57): pid=8601 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.735" name="file1" dev="loop3" ino=6150 res=0 errno=0 [ 269.704139][ T8606] XFS (loop4): Mounting V5 Filesystem d7dc424e-7990-42cb-9f91-9cb7200a101d [ 269.822921][ T30] audit: type=1800 audit(1749620520.166:58): pid=8651 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.735" name="file1" dev="loop3" ino=6150 res=0 errno=0 [ 269.907484][ T8606] XFS (loop4): Ending clean mount [ 270.032729][ T8656] loop6: detected capacity change from 0 to 512 [ 270.064559][ T5839] BTRFS info (device loop1): last unmount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 270.084515][ T30] audit: type=1800 audit(1749620520.436:59): pid=8606 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.4.737" name="file1" dev="loop4" ino=6150 res=0 errno=0 [ 270.263697][ T8656] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 270.419162][ T8656] ext4 filesystem being mounted at /96/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 270.429713][ T30] audit: type=1800 audit(1749620520.746:60): pid=8659 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.4.737" name="file1" dev="loop4" ino=6150 res=0 errno=0 [ 270.534066][ T5836] XFS (loop3): Unmounting Filesystem d7dc424e-7990-42cb-9f91-9cb7200a101d [ 270.560194][ T8656] EXT4-fs error (device loop6): ext4_do_update_inode:5568: inode #2: comm syz.6.744: corrupted inode contents [ 270.622116][ T8656] EXT4-fs error (device loop6): ext4_dirty_inode:6459: inode #2: comm syz.6.744: mark_inode_dirty error [ 270.642935][ T8656] EXT4-fs error (device loop6): ext4_do_update_inode:5568: inode #2: comm syz.6.744: corrupted inode contents [ 270.661747][ T8656] EXT4-fs error (device loop6): __ext4_ext_dirty:206: inode #2: comm syz.6.744: mark_inode_dirty error [ 270.826817][ T5848] XFS (loop4): Unmounting Filesystem d7dc424e-7990-42cb-9f91-9cb7200a101d [ 271.203037][ T6515] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 271.951736][ T8683] binder: 8681:8683 ioctl c0306201 200000000040 returned -14 [ 273.089098][ T5941] usb 2-1: new low-speed USB device number 9 using dummy_hcd [ 273.188321][ T8701] loop0: detected capacity change from 0 to 2048 [ 273.221882][ T8701] UDF-fs: INFO Mounting volume 'LiuxUDF', timestamp 2022/11/22 14:59 (1000) [ 273.276226][ T8701] UDF-fs: warning (device loop0): udf_truncate_tail_extent: Too long extent after EOF in inode 1368: i_size: 0 lbcount: 3584 extent 57+3584 [ 273.302275][ T8701] UDF-fs: error (device loop0): udf_truncate_tail_extent: Extent after EOF in inode 1368 [ 273.321439][ T5941] usb 2-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 273.734725][ T5941] usb 2-1: config 1 has 1 interface, different from the descriptor's value: 2 [ 273.752896][ T5941] usb 2-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 10 [ 273.763966][ T5941] usb 2-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 273.793813][ T5941] usb 2-1: New USB device found, idVendor=0225, idProduct=0000, bcdDevice= 0.00 [ 273.823888][ T5941] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 274.021404][ T5941] hub 2-1:1.0: bad descriptor, ignoring hub [ 274.027457][ T5941] hub 2-1:1.0: probe with driver hub failed with error -5 [ 274.036633][ T5941] cdc_wdm 2-1:1.0: skipping garbage [ 274.041866][ T5941] cdc_wdm 2-1:1.0: skipping garbage [ 274.113644][ T5941] cdc_wdm 2-1:1.0: cdc-wdm0: USB WDM device [ 274.119728][ T5941] cdc_wdm 2-1:1.0: Unknown control protocol [ 274.196983][ T5941] usb 2-1: USB disconnect, device number 9 [ 274.250168][ T8719] loop3: detected capacity change from 0 to 64 [ 274.267773][ T8717] input: Bluetooth HID Boot Protocol Device as /devices/virtual/bluetooth/hci0/hci0:200/input11 [ 275.326343][ T8743] loop3: detected capacity change from 0 to 2048 [ 275.376617][ T8743] UDF-fs: INFO Mounting volume 'LiuxUDF', timestamp 2022/11/22 14:59 (1000) [ 275.471198][ T8743] UDF-fs: warning (device loop3): udf_truncate_tail_extent: Too long extent after EOF in inode 1368: i_size: 0 lbcount: 3584 extent 57+3584 [ 275.515709][ T8743] UDF-fs: error (device loop3): udf_truncate_tail_extent: Extent after EOF in inode 1368 [ 275.534299][ T8715] loop0: detected capacity change from 0 to 32768 [ 275.581417][ T8715] BTRFS: device fsid ed167579-eb65-4e76-9a50-61ac97e9b59d devid 1 transid 8 /dev/loop0 (7:0) scanned by syz.0.759 (8715) [ 275.642072][ T8715] BTRFS info (device loop0): first mount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 275.664402][ T8715] BTRFS info (device loop0): using sha256 (sha256-x86_64) checksum algorithm [ 275.700305][ T8715] BTRFS info (device loop0): using free-space-tree [ 275.803033][ T8755] loop4: detected capacity change from 0 to 512 [ 275.833246][ T8755] EXT4-fs (loop4): encrypted files will use data=ordered instead of data journaling mode [ 275.955244][ T8755] EXT4-fs (loop4): 1 truncate cleaned up [ 275.996638][ T8755] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 276.032736][ T8771] loop1: detected capacity change from 0 to 512 [ 276.071851][ T8715] BTRFS info (device loop0): rebuilding free space tree [ 276.216768][ T8771] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000d40000 r/w without journal. Quota mode: writeback. [ 276.246068][ T8771] ext4 filesystem being mounted at /130/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 276.462346][ T30] audit: type=1804 audit(1749620526.806:61): pid=8715 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.0.759" name="/newroot/49/bus/bus" dev="loop0" ino=263 res=1 errno=0 [ 276.723559][ T5839] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000d40000. [ 276.726698][ T5848] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 276.965604][ T7223] BTRFS info (device loop0): last unmount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 279.610420][ T8835] loop0: detected capacity change from 0 to 512 [ 279.785398][ T8835] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000d40000 r/w without journal. Quota mode: writeback. [ 279.932656][ T8835] ext4 filesystem being mounted at /52/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 280.237270][ T8815] loop1: detected capacity change from 0 to 32768 [ 280.352256][ T8815] ocfs2: Mounting device (7,1) on (node local, slot 0) with writeback data mode. [ 280.422471][ T30] audit: type=1800 audit(1749620530.766:62): pid=8815 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.1.791" name="file1" dev="loop1" ino=17058 res=0 errno=0 [ 280.632054][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000d40000. [ 280.871932][ T8852] loop3: detected capacity change from 0 to 512 [ 280.876778][ T8855] netlink: 4 bytes leftover after parsing attributes in process `syz.4.814'. [ 280.920768][ T8852] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 280.974542][ T8855] netlink: 12 bytes leftover after parsing attributes in process `syz.4.814'. [ 281.042282][ T5839] ocfs2: Unmounting device (7,1) on (node local) [ 281.084581][ T8852] EXT4-fs (loop3): 1 truncate cleaned up [ 281.155817][ T8852] EXT4-fs (loop3): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 281.716807][ T8844] loop6: detected capacity change from 0 to 32768 [ 281.776758][ T8844] BTRFS: device fsid ed167579-eb65-4e76-9a50-61ac97e9b59d devid 1 transid 8 /dev/loop6 (7:6) scanned by syz.6.798 (8844) [ 281.923122][ T8844] BTRFS info (device loop6): first mount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 281.952161][ T5836] EXT4-fs (loop3): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 281.995048][ T8844] BTRFS info (device loop6): using sha256 (sha256-x86_64) checksum algorithm [ 282.043032][ T8844] BTRFS info (device loop6): using free-space-tree [ 282.477464][ T8844] BTRFS info (device loop6): rebuilding free space tree [ 282.882933][ T5843] Bluetooth: hci6: command 0x0406 tx timeout [ 283.204318][ T6515] BTRFS info (device loop6): last unmount of filesystem ed167579-eb65-4e76-9a50-61ac97e9b59d [ 285.671689][ T8939] loop6: detected capacity change from 0 to 512 [ 285.749112][ T8939] EXT4-fs (loop6): encrypted files will use data=ordered instead of data journaling mode [ 285.925864][ T8939] EXT4-fs (loop6): 1 truncate cleaned up [ 285.978521][ T8939] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 286.075913][ T8946] netlink: 'syz.4.826': attribute type 1 has an invalid length. [ 286.302613][ T8946] bond1: entered promiscuous mode [ 286.346070][ T8946] bond1: entered allmulticast mode [ 286.409289][ T8948] geneve2: entered allmulticast mode [ 286.441945][ T8948] bond1: (slave geneve2): making interface the new active one [ 286.468030][ T8948] geneve2: entered promiscuous mode [ 286.489556][ T8948] bond1: (slave geneve2): Enslaving as an active interface with an up link [ 286.942285][ T6515] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 287.029845][ T8958] loop0: detected capacity change from 0 to 512 [ 287.156970][ T8958] EXT4-fs error (device loop0): ext4_iget_extra_inode:5034: inode #15: comm syz.0.830: corrupted in-inode xattr: invalid ea_ino [ 287.289696][ T8958] EXT4-fs error (device loop0): ext4_orphan_get:1396: comm syz.0.830: couldn't read orphan inode 15 (err -117) [ 287.936760][ T8958] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 288.298248][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 288.341533][ T8977] loop1: detected capacity change from 0 to 2048 [ 288.360968][ T8977] EXT4-fs: Ignoring removed bh option [ 288.413307][ T8977] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 288.501479][ T8977] EXT4-fs error (device loop1): ext4_mb_generate_buddy:1217: group 0, block bitmap and bg descriptor inconsistent: 25 vs 150994969 free clusters [ 288.519940][ T8977] EXT4-fs (loop1): Delayed block allocation failed for inode 15 at logical offset 0 with max blocks 2 with error 28 [ 288.562279][ T8977] EXT4-fs (loop1): This should not happen!! Data will be lost [ 288.562279][ T8977] [ 288.585139][ T8977] EXT4-fs (loop1): Total free blocks count 0 [ 288.596603][ T8990] EXT4-fs (loop1): shut down requested (2) [ 288.599187][ T30] audit: type=1804 audit(1749620538.946:63): pid=8990 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.1.835" name="/newroot/137/file1/file1" dev="loop1" ino=15 res=1 errno=0 [ 288.666442][ T8977] EXT4-fs (loop1): Free/Dirty block details [ 288.695444][ T8977] EXT4-fs (loop1): free_blocks=2415919104 [ 288.725259][ T8977] EXT4-fs (loop1): dirty_blocks=16 [ 288.773618][ T8977] EXT4-fs (loop1): Block reservation details [ 288.791994][ T8977] EXT4-fs (loop1): i_reserved_data_blocks=1 [ 288.850544][ T8992] overlayfs: failed to resolve './file0': -2 [ 288.898738][ T8995] loop6: detected capacity change from 0 to 256 [ 288.968455][ T8995] exFAT-fs (loop6): failed to load upcase table (idx : 0x00010000, chksum : 0x36e00b20, utbl_chksum : 0xe619d30d) [ 289.080594][ T8995] netlink: 44 bytes leftover after parsing attributes in process `syz.6.843'. [ 289.133000][ T8995] netlink: 'syz.6.843': attribute type 6 has an invalid length. [ 289.193054][ T8995] netlink: 'syz.6.843': attribute type 5 has an invalid length. [ 289.211127][ T8995] netlink: 'syz.6.843': attribute type 4 has an invalid length. [ 289.610153][ T9007] loop0: detected capacity change from 0 to 512 [ 289.623489][ T5932] usb 4-1: new high-speed USB device number 6 using dummy_hcd [ 289.691729][ T9007] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 289.735774][ T5851] Bluetooth: hci1: command 0x0406 tx timeout [ 289.745225][ T9007] ext4 filesystem being mounted at /63/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 289.818288][ T5932] usb 4-1: Using ep0 maxpacket: 16 [ 289.826830][ T5932] usb 4-1: config 1 interface 1 altsetting 1 endpoint 0x1 has an invalid bInterval 0, changing to 7 [ 289.838002][ T5932] usb 4-1: config 1 interface 1 altsetting 1 endpoint 0x1 has invalid wMaxPacketSize 0 [ 289.847798][ T5932] usb 4-1: config 1 interface 2 altsetting 1 endpoint 0x82 has an invalid bInterval 0, changing to 7 [ 289.872455][ T5932] usb 4-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 289.882776][ T5932] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 289.912740][ T5932] usb 4-1: Product: syz [ 289.922201][ T5932] usb 4-1: Manufacturer: syz [ 289.944867][ T5932] usb 4-1: SerialNumber: syz [ 289.953486][ T9007] EXT4-fs error (device loop0): ext4_get_first_dir_block:3547: inode #12: comm syz.0.849: directory missing '..' [ 290.103848][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 290.373016][ T30] audit: type=1326 audit(1749620540.706:64): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff30898e929 code=0x7ffc0000 [ 290.381606][ T9017] loop0: detected capacity change from 0 to 256 [ 290.424428][ T5932] usb 4-1: 2:1 : format type 0 is detected, processed as PCM [ 290.435411][ T30] audit: type=1326 audit(1749620540.706:65): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=237 compat=0 ip=0x7ff30898e929 code=0x7ffc0000 [ 290.529880][ T30] audit: type=1326 audit(1749620540.706:66): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff30898e929 code=0x7ffc0000 [ 290.624437][ T30] audit: type=1326 audit(1749620540.706:67): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=319 compat=0 ip=0x7ff30898e929 code=0x7ffc0000 [ 290.649518][ T30] audit: type=1326 audit(1749620540.716:68): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=9 compat=0 ip=0x7ff30898e963 code=0x7ffc0000 [ 290.839838][ T30] audit: type=1326 audit(1749620540.716:69): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=1 compat=0 ip=0x7ff30898d3df code=0x7ffc0000 [ 290.896187][ T30] audit: type=1326 audit(1749620540.726:70): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=11 compat=0 ip=0x7ff30898e9b7 code=0x7ffc0000 [ 290.919732][ T30] audit: type=1326 audit(1749620540.726:71): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7ff30898d290 code=0x7ffc0000 [ 290.951502][ T30] audit: type=1326 audit(1749620540.726:72): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9016 comm="syz.0.851" exe="/root/syz-executor" sig=0 arch=c000003e syscall=16 compat=0 ip=0x7ff30898e52b code=0x7ffc0000 [ 291.044526][ T9005] loop1: detected capacity change from 0 to 32768 [ 291.070876][ T9005] XFS (loop1): DAX unsupported by block device. Turning off DAX. [ 291.095354][ T9005] XFS (loop1): Mounting V5 Filesystem bfdc47fc-10d8-4eed-a562-11a831b3f791 [ 291.202540][ T9005] XFS (loop1): Ending clean mount [ 291.211906][ T9005] XFS (loop1): Quotacheck needed: Please wait. [ 291.290185][ T9005] XFS (loop1): Quotacheck: Done. [ 291.489859][ T5932] usb 4-1: USB disconnect, device number 6 [ 291.611511][ T5839] XFS (loop1): Unmounting Filesystem bfdc47fc-10d8-4eed-a562-11a831b3f791 [ 292.698581][ T9052] overlayfs: upper fs does not support RENAME_WHITEOUT. [ 292.767411][ T9052] overlayfs: failed to set xattr on upper [ 292.897769][ T9052] overlayfs: ...falling back to redirect_dir=nofollow. [ 292.958879][ T9052] overlayfs: ...falling back to index=off. [ 292.982953][ T9052] overlayfs: ...falling back to uuid=null. [ 292.988974][ T9052] overlayfs: ...falling back to xino=off. [ 293.030696][ T9052] overlayfs: conflicting lowerdir path [ 293.805699][ T9066] netlink: 'syz.1.865': attribute type 1 has an invalid length. [ 294.071424][ T9070] loop3: detected capacity change from 0 to 2048 [ 294.128607][ T9070] EXT4-fs: Ignoring removed bh option [ 294.161605][ T9066] bond1: entered promiscuous mode [ 294.167694][ T9073] loop0: detected capacity change from 0 to 512 [ 294.206564][ T9070] EXT4-fs (loop3): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 294.208608][ T9066] bond1: entered allmulticast mode [ 294.250690][ T9073] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 294.275502][ T9070] EXT4-fs error (device loop3): ext4_mb_generate_buddy:1217: group 0, block bitmap and bg descriptor inconsistent: 25 vs 150994969 free clusters [ 294.303342][ T9070] EXT4-fs (loop3): Delayed block allocation failed for inode 15 at logical offset 0 with max blocks 2 with error 28 [ 294.323474][ T9069] geneve2: entered allmulticast mode [ 294.335037][ T9069] bond1: (slave geneve2): making interface the new active one [ 294.375292][ T9073] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 294.399905][ T9069] geneve2: entered promiscuous mode [ 294.415542][ T9073] ext4 filesystem being mounted at /68/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 294.419975][ T9070] EXT4-fs (loop3): This should not happen!! Data will be lost [ 294.419975][ T9070] [ 294.437636][ T9069] bond1: (slave geneve2): Enslaving as an active interface with an up link [ 294.453755][ T9070] EXT4-fs (loop3): Total free blocks count 0 [ 294.461740][ T9070] EXT4-fs (loop3): Free/Dirty block details [ 294.468307][ T9070] EXT4-fs (loop3): free_blocks=2415919104 [ 294.474115][ T9070] EXT4-fs (loop3): dirty_blocks=16 [ 294.479259][ T9070] EXT4-fs (loop3): Block reservation details [ 294.486456][ T9070] EXT4-fs (loop3): i_reserved_data_blocks=1 [ 294.492535][ T9081] EXT4-fs (loop3): shut down requested (2) [ 294.515135][ T30] kauditd_printk_skb: 16 callbacks suppressed [ 294.515157][ T30] audit: type=1804 audit(1749620544.826:89): pid=9081 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.3.866" name="/newroot/128/file1/file1" dev="loop3" ino=15 res=1 errno=0 [ 294.707843][ T30] audit: type=1800 audit(1749620545.056:90): pid=9073 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.0.879" name="file0" dev="overlay" ino=15 res=0 errno=0 [ 295.144125][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 295.242948][ T5932] usb 2-1: new high-speed USB device number 10 using dummy_hcd [ 295.405665][ T5932] usb 2-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 295.418509][ T5932] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 295.439723][ T5932] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 295.459755][ T5932] usb 2-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 295.502906][ T5932] usb 2-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 295.512939][ T5932] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 295.536669][ T5932] usb 2-1: config 0 descriptor?? [ 295.987791][ T5932] plantronics 0003:047F:FFFF.0005: No inputs registered, leaving [ 296.029709][ T5932] plantronics 0003:047F:FFFF.0005: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.1-1/input0 [ 296.372642][ T5932] usb 2-1: USB disconnect, device number 10 [ 297.191956][ T9094] loop6: detected capacity change from 0 to 32768 [ 297.425878][ T9094] XFS (loop6): DAX unsupported by block device. Turning off DAX. [ 297.504568][ T9094] XFS (loop6): Mounting V5 Filesystem bfdc47fc-10d8-4eed-a562-11a831b3f791 [ 297.761082][ T9094] XFS (loop6): Ending clean mount [ 297.794850][ T9094] XFS (loop6): Quotacheck needed: Please wait. [ 297.906455][ T9094] XFS (loop6): Quotacheck: Done. [ 298.143229][ T30] audit: type=1804 audit(1749620548.486:91): pid=9094 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=open_writers comm="syz.6.872" name="/newroot/117/bus/bus" dev="loop6" ino=9290 res=1 errno=0 [ 298.462338][ T6515] XFS (loop6): Unmounting Filesystem bfdc47fc-10d8-4eed-a562-11a831b3f791 [ 298.493241][ T972] usb 2-1: new high-speed USB device number 11 using dummy_hcd [ 298.672943][ T972] usb 2-1: Using ep0 maxpacket: 16 [ 298.707088][ T972] usb 2-1: config 1 interface 1 altsetting 1 endpoint 0x1 has an invalid bInterval 0, changing to 7 [ 298.796778][ T972] usb 2-1: config 1 interface 1 altsetting 1 endpoint 0x1 has invalid wMaxPacketSize 0 [ 298.868369][ T972] usb 2-1: config 1 interface 2 altsetting 1 endpoint 0x82 has an invalid bInterval 0, changing to 7 [ 298.882276][ T972] usb 2-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 298.892627][ T972] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 298.910300][ T972] usb 2-1: Product: syz [ 298.918171][ T972] usb 2-1: Manufacturer: syz [ 298.922802][ T972] usb 2-1: SerialNumber: syz [ 299.363348][ T972] usb 2-1: 2:1 : format type 0 is detected, processed as PCM [ 300.432960][ T3399] usb 5-1: new high-speed USB device number 7 using dummy_hcd [ 300.477724][ T972] usb 2-1: USB disconnect, device number 11 [ 300.557997][ T6105] udevd[6105]: error opening ATTR{/sys/devices/platform/dummy_hcd.1/usb2/2-1/2-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 300.619902][ T3399] usb 5-1: Using ep0 maxpacket: 32 [ 300.648361][ T3399] usb 5-1: config 0 has an invalid interface number: 184 but max is 0 [ 300.679478][ T3399] usb 5-1: config 0 has no interface number 0 [ 300.708899][ T3399] usb 5-1: config 0 interface 184 has no altsetting 0 [ 300.719245][ T3399] usb 5-1: New USB device found, idVendor=0424, idProduct=7500, bcdDevice=69.ee [ 300.733159][ T3399] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 300.741362][ T3399] usb 5-1: Product: syz [ 300.748680][ T3399] usb 5-1: Manufacturer: syz [ 300.759827][ T3399] usb 5-1: SerialNumber: syz [ 300.770414][ T3399] usb 5-1: config 0 descriptor?? [ 300.780015][ T3399] smsc75xx v1.0.0 [ 302.284519][ T3399] smsc75xx 5-1:0.184 (unnamed net_device) (uninitialized): Failed to write reg index 0x00000040: -71 [ 302.308083][ T3399] smsc75xx 5-1:0.184 (unnamed net_device) (uninitialized): Error writing E2P_CMD [ 302.334922][ T3399] smsc75xx 5-1:0.184 (unnamed net_device) (uninitialized): Failed to read reg index 0x00000014: -71 [ 302.363922][ T3399] smsc75xx 5-1:0.184 (unnamed net_device) (uninitialized): Failed to read PMT_CTL: -71 [ 302.378505][ T3399] smsc75xx 5-1:0.184 (unnamed net_device) (uninitialized): device not ready in smsc75xx_reset [ 302.400074][ T3399] smsc75xx 5-1:0.184 (unnamed net_device) (uninitialized): smsc75xx_reset error -71 [ 302.427771][ T3399] smsc75xx 5-1:0.184: probe with driver smsc75xx failed with error -71 [ 302.459597][ T3399] usb 5-1: USB disconnect, device number 7 [ 302.807166][ T5925] usb 7-1: new high-speed USB device number 4 using dummy_hcd [ 303.146836][ T5925] usb 7-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 303.189595][ T5925] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 303.281909][ T5925] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 303.408210][ T5925] usb 7-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 303.461909][ T5925] usb 7-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 303.513308][ T5925] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 303.580233][ T5925] usb 7-1: config 0 descriptor?? [ 304.030662][ T5925] plantronics 0003:047F:FFFF.0006: No inputs registered, leaving [ 304.114164][ T5925] plantronics 0003:047F:FFFF.0006: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.6-1/input0 [ 304.438833][ T5925] usb 7-1: USB disconnect, device number 4 [ 304.726180][ T9178] fido_id[9178]: Failed to open report descriptor at '/sys/devices/platform/dummy_hcd.6/usb7/report_descriptor': No such file or directory [ 305.233139][ T9186] netlink: 'syz.3.903': attribute type 1 has an invalid length. [ 305.241269][ T9188] overlayfs: failed to clone upperpath [ 305.498737][ T9186] bond1: entered promiscuous mode [ 305.520390][ T9186] bond1: entered allmulticast mode [ 305.574120][ T9189] geneve2: entered allmulticast mode [ 305.600102][ T9189] bond1: (slave geneve2): making interface the new active one [ 305.631507][ T9189] geneve2: entered promiscuous mode [ 305.652253][ T9189] bond1: (slave geneve2): Enslaving as an active interface with an up link [ 305.774641][ T9184] loop0: detected capacity change from 0 to 32768 [ 305.833599][ T9184] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop0 (7:0) scanned by syz.0.902 (9184) [ 305.902427][ T9184] BTRFS info (device loop0): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 305.942015][ T9184] BTRFS info (device loop0): using crc32c (crc32c-x86_64) checksum algorithm [ 305.951139][ T9184] BTRFS info (device loop0): using free-space-tree [ 306.640424][ T7223] BTRFS info (device loop0): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 307.120327][ T9215] loop1: detected capacity change from 0 to 512 [ 307.149700][ T9215] EXT4-fs (loop1): encrypted files will use data=ordered instead of data journaling mode [ 307.295181][ T9215] EXT4-fs (loop1): 1 truncate cleaned up [ 307.322933][ T972] usb 7-1: new high-speed USB device number 5 using dummy_hcd [ 307.332781][ T9215] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 307.506310][ T972] usb 7-1: Using ep0 maxpacket: 16 [ 307.518128][ T972] usb 7-1: config 1 interface 1 altsetting 1 endpoint 0x1 has an invalid bInterval 0, changing to 7 [ 307.556704][ T972] usb 7-1: config 1 interface 1 altsetting 1 endpoint 0x1 has invalid wMaxPacketSize 0 [ 307.612967][ T972] usb 7-1: config 1 interface 2 altsetting 1 endpoint 0x82 has an invalid bInterval 0, changing to 7 [ 307.645481][ T972] usb 7-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 307.663106][ T972] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 307.687369][ T24] usb 1-1: new high-speed USB device number 7 using dummy_hcd [ 307.713006][ T972] usb 7-1: Product: syz [ 307.732955][ T972] usb 7-1: Manufacturer: syz [ 307.737618][ T972] usb 7-1: SerialNumber: syz [ 307.831705][ T5839] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 307.869628][ T24] usb 1-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 307.922981][ T24] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 307.982563][ T24] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 308.019513][ T24] usb 1-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 308.042800][ T24] usb 1-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 308.062087][ T24] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 308.144209][ T24] usb 1-1: config 0 descriptor?? [ 308.191637][ T9213] loop3: detected capacity change from 0 to 32768 [ 308.211304][ T972] usb 7-1: 2:1 : format type 0 is detected, processed as PCM [ 308.231775][ T9213] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop3 (7:3) scanned by syz.3.920 (9213) [ 308.310962][ T9213] BTRFS info (device loop3): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 308.336679][ T9213] BTRFS info (device loop3): using crc32c (crc32c-x86_64) checksum algorithm [ 308.366003][ T9213] BTRFS info (device loop3): using free-space-tree [ 308.606924][ T24] plantronics 0003:047F:FFFF.0007: No inputs registered, leaving [ 308.667401][ T24] plantronics 0003:047F:FFFF.0007: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.0-1/input0 [ 308.690484][ T9247] loop1: detected capacity change from 0 to 512 [ 308.761003][ T9247] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 308.861971][ T9247] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 308.944825][ T9247] ext4 filesystem being mounted at /151/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 309.158120][ T5925] usb 1-1: USB disconnect, device number 7 [ 309.835226][ T972] usb 7-1: USB disconnect, device number 5 [ 310.118209][ T5836] BTRFS info (device loop3): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 310.281114][ T9269] netlink: 120 bytes leftover after parsing attributes in process `syz.4.921'. [ 310.377297][ T5839] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 311.285230][ T9291] netlink: 'syz.0.923': attribute type 1 has an invalid length. [ 311.365466][ T9291] bond1: entered promiscuous mode [ 311.394200][ T9291] bond1: entered allmulticast mode [ 311.482193][ T9293] geneve2: entered allmulticast mode [ 311.586713][ T9293] bond1: (slave geneve2): making interface the new active one [ 311.609241][ T9293] geneve2: entered promiscuous mode [ 311.627012][ T9293] bond1: (slave geneve2): Enslaving as an active interface with an up link [ 312.789013][ T9306] loop0: detected capacity change from 0 to 512 [ 312.854563][ T9306] EXT4-fs (loop0): encrypted files will use data=ordered instead of data journaling mode [ 312.981203][ T9306] EXT4-fs (loop0): 1 truncate cleaned up [ 313.020953][ T9306] EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 313.760309][ T5941] usb 5-1: new high-speed USB device number 8 using dummy_hcd [ 313.807689][ T7223] EXT4-fs (loop0): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 313.945020][ T5941] usb 5-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 313.975582][ T5941] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 314.009083][ T5941] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 314.041303][ T5941] usb 5-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 314.090756][ T5941] usb 5-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 314.117243][ T5941] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 314.149235][ T5941] usb 5-1: config 0 descriptor?? [ 314.422747][ T9323] loop1: detected capacity change from 0 to 32768 [ 314.482999][ T9323] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop1 (7:1) scanned by syz.1.934 (9323) [ 314.605242][ T9323] BTRFS info (device loop1): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 314.606286][ T5941] plantronics 0003:047F:FFFF.0008: No inputs registered, leaving [ 314.660845][ T5941] plantronics 0003:047F:FFFF.0008: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.4-1/input0 [ 314.674910][ T9323] BTRFS info (device loop1): using crc32c (crc32c-x86_64) checksum algorithm [ 314.734574][ T9323] BTRFS info (device loop1): using free-space-tree [ 315.003257][ T5941] usb 5-1: USB disconnect, device number 8 [ 315.568365][ T5839] BTRFS info (device loop1): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 315.926595][ T9366] loop4: detected capacity change from 0 to 512 [ 315.983904][ T9366] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 316.107845][ T9366] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 316.173006][ T9366] ext4 filesystem being mounted at /154/file0 supports timestamps until 2038-01-19 (0x7fffffff) [ 316.517859][ T30] audit: type=1800 audit(1749620566.866:92): pid=9366 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.4.941" name="file0" dev="overlay" ino=15 res=0 errno=0 [ 316.756720][ T9378] loop3: detected capacity change from 0 to 256 [ 316.861841][ T5848] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 316.906631][ T9378] exFAT-fs (loop3): failed to load upcase table (idx : 0x0000fd4f, chksum : 0x3963664b, utbl_chksum : 0xe619d30d) [ 317.248986][ T9379] loop1: detected capacity change from 0 to 8192 [ 318.824580][ T9391] netlink: 'syz.6.946': attribute type 1 has an invalid length. [ 318.857285][ T9396] netlink: 120 bytes leftover after parsing attributes in process `syz.2.969'. [ 318.893669][ T9391] bond1: entered promiscuous mode [ 318.899889][ T9391] bond1: entered allmulticast mode [ 318.981617][ T9399] geneve2: entered allmulticast mode [ 319.022974][ T24] usb 4-1: new high-speed USB device number 7 using dummy_hcd [ 319.039666][ T9399] bond1: (slave geneve2): making interface the new active one [ 319.069836][ T9399] geneve2: entered promiscuous mode [ 319.101525][ T9399] bond1: (slave geneve2): Enslaving as an active interface with an up link [ 319.187440][ T9401] loop1: detected capacity change from 0 to 1024 [ 319.209454][ T24] usb 4-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 319.232873][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 319.244094][ T9401] EXT4-fs: Ignoring removed nobh option [ 319.244159][ T9401] EXT4-fs: Ignoring removed bh option [ 319.309375][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 319.328021][ T24] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 319.342292][ T24] usb 4-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 319.353601][ T24] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 319.365538][ T24] usb 4-1: config 0 descriptor?? [ 319.378487][ T9401] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 319.525587][ T9409] EXT4-fs error (device loop1): mb_free_blocks:1945: group 0, inode 15: block 97:freeing already freed block (bit 6); block bitmap corrupt. [ 319.602932][ T9413] loop6: detected capacity change from 0 to 512 [ 319.711895][ T9413] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 319.775494][ T9413] ext4 filesystem being mounted at /127/bus supports timestamps until 2038-01-19 (0x7fffffff) [ 319.824957][ T24] plantronics 0003:047F:FFFF.0009: No inputs registered, leaving [ 319.828280][ T9413] EXT4-fs error (device loop6): ext4_do_update_inode:5568: inode #2: comm syz.6.953: corrupted inode contents [ 319.863507][ T5839] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 319.883690][ T24] plantronics 0003:047F:FFFF.0009: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.3-1/input0 [ 319.893980][ T9418] netlink: 8 bytes leftover after parsing attributes in process `syz.2.954'. [ 319.936709][ T9413] EXT4-fs error (device loop6): ext4_dirty_inode:6459: inode #2: comm syz.6.953: mark_inode_dirty error [ 319.948529][ T9418] netlink: 8 bytes leftover after parsing attributes in process `syz.2.954'. [ 319.998201][ T9413] EXT4-fs error (device loop6): ext4_do_update_inode:5568: inode #2: comm syz.6.953: corrupted inode contents [ 320.058439][ T9413] EXT4-fs error (device loop6): __ext4_ext_dirty:206: inode #2: comm syz.6.953: mark_inode_dirty error [ 320.187089][ T9421] loop1: detected capacity change from 0 to 512 [ 320.219094][ T6022] usb 4-1: USB disconnect, device number 7 [ 320.237561][ T9421] EXT4-fs (loop1): encrypted files will use data=ordered instead of data journaling mode [ 320.277943][ T9421] EXT4-fs (loop1): 1 truncate cleaned up [ 320.303007][ T9421] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 320.416161][ T6515] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 320.618722][ T30] audit: type=1326 audit(1749620570.966:93): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9425 comm="syz.2.961" exe="/root/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7f2ab6b8e929 code=0x0 [ 320.763417][ T5839] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 322.816007][ T9446] loop1: detected capacity change from 0 to 32768 [ 322.880206][ T9446] BTRFS: device fsid c9fe44da-de57-406a-8241-57ec7d4412cf devid 1 transid 8 /dev/loop1 (7:1) scanned by syz.1.975 (9446) [ 322.970820][ T9446] BTRFS info (device loop1): first mount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 323.055871][ T9446] BTRFS info (device loop1): using crc32c (crc32c-x86_64) checksum algorithm [ 323.117033][ T9446] BTRFS info (device loop1): using free-space-tree [ 323.434234][ T5200] udevd[5200]: worker [6687] terminated by signal 33 (Unknown signal 33) [ 323.468528][ T5200] udevd[5200]: worker [6687] failed while handling '/devices/virtual/block/loop1' [ 323.892740][ T9465] loop0: detected capacity change from 0 to 32768 [ 324.001259][ T5839] BTRFS info (device loop1): last unmount of filesystem c9fe44da-de57-406a-8241-57ec7d4412cf [ 324.115682][ T9465] ocfs2: Mounting device (7,0) on (node local, slot 0) with writeback data mode. [ 324.675171][ T7223] ocfs2: Unmounting device (7,0) on (node local) [ 325.018810][ T9522] overlayfs: failed to clone upperpath [ 326.724448][ T9556] loop7: detected capacity change from 0 to 16384 [ 326.785127][ T1299] ieee802154 phy0 wpan0: encryption failed: -22 [ 326.791894][ T1299] ieee802154 phy1 wpan1: encryption failed: -22 [ 326.944079][ T9560] overlayfs: conflicting lowerdir path [ 327.085760][ T9564] netlink: 'syz.2.1012': attribute type 4 has an invalid length. [ 327.178787][ T9565] netlink: 'syz.2.1012': attribute type 4 has an invalid length. [ 327.605177][ T9561] loop7: detected capacity change from 16384 to 16383 [ 327.653922][ T9561] [ 327.656303][ T9561] ====================================================== [ 327.663327][ T9561] WARNING: possible circular locking dependency detected [ 327.670342][ T9561] 6.16.0-rc1-syzkaller-00004-gaef17cb3d3c4 #0 Not tainted [ 327.677459][ T9561] ------------------------------------------------------ [ 327.684481][ T9561] syz.1.1022/9561 is trying to acquire lock: [ 327.690463][ T9561] ffffffff908b44a8 (uevent_sock_mutex){+.+.}-{4:4}, at: kobject_uevent_env+0xb36/0x1870 [ 327.700270][ T9561] [ 327.700270][ T9561] but task is already holding lock: [ 327.707627][ T9561] ffff88814337e278 (&q->q_usage_counter(io)#24){++++}-{0:0}, at: blk_mq_freeze_queue_nomemsave+0x15/0x20 [ 327.718917][ T9561] [ 327.718917][ T9561] which lock already depends on the new lock. [ 327.718917][ T9561] [ 327.729331][ T9561] [ 327.729331][ T9561] the existing dependency chain (in reverse order) is: [ 327.738345][ T9561] [ 327.738345][ T9561] -> #2 (&q->q_usage_counter(io)#24){++++}-{0:0}: [ 327.746989][ T9561] blk_alloc_queue+0x619/0x760 [ 327.752301][ T9561] blk_mq_alloc_queue+0x175/0x290 [ 327.757883][ T9561] __blk_mq_alloc_disk+0x29/0x120 [ 327.763461][ T9561] loop_add+0x49e/0xb70 [ 327.768166][ T9561] loop_init+0x164/0x270 [ 327.772968][ T9561] do_one_initcall+0x123/0x6e0 [ 327.778291][ T9561] kernel_init_freeable+0x5c2/0x900 [ 327.784081][ T9561] kernel_init+0x1c/0x2b0 [ 327.788963][ T9561] ret_from_fork+0x5d7/0x6f0 [ 327.794118][ T9561] ret_from_fork_asm+0x1a/0x30 [ 327.799421][ T9561] [ 327.799421][ T9561] -> #1 (fs_reclaim){+.+.}-{0:0}: [ 327.806684][ T9561] fs_reclaim_acquire+0x102/0x150 [ 327.812261][ T9561] kmem_cache_alloc_node_noprof+0x57/0x3b0 [ 327.818607][ T9561] __alloc_skb+0x2b2/0x380 [ 327.823579][ T9561] alloc_uevent_skb+0x7d/0x210 [ 327.828899][ T9561] kobject_uevent_env+0xca4/0x1870 [ 327.834554][ T9561] kobject_synth_uevent+0x7d4/0x8a0 [ 327.840316][ T9561] bus_uevent_store+0x3d/0x90 [ 327.845537][ T9561] bus_attr_store+0x74/0xb0 [ 327.850571][ T9561] sysfs_kf_write+0xf2/0x150 [ 327.855719][ T9561] kernfs_fop_write_iter+0x354/0x510 [ 327.861569][ T9561] vfs_write+0x6c7/0x1150 [ 327.866445][ T9561] ksys_write+0x12a/0x250 [ 327.871314][ T9561] do_syscall_64+0xcd/0x4c0 [ 327.876361][ T9561] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 327.882789][ T9561] [ 327.882789][ T9561] -> #0 (uevent_sock_mutex){+.+.}-{4:4}: [ 327.890666][ T9561] __lock_acquire+0x126f/0x1c90 [ 327.896160][ T9561] lock_acquire+0x179/0x350 [ 327.901219][ T9561] __mutex_lock+0x199/0xb90 [ 327.906359][ T9561] kobject_uevent_env+0xb36/0x1870 [ 327.912012][ T9561] set_capacity_and_notify+0x1ca/0x240 [ 327.918088][ T9561] loop_set_status+0x94c/0xb90 [ 327.923401][ T9561] loop_set_status_old+0x162/0x1d0 [ 327.929075][ T9561] lo_ioctl+0xb3f/0x2760 [ 327.933873][ T9561] blkdev_ioctl+0x277/0x6d0 [ 327.938922][ T9561] __x64_sys_ioctl+0x18e/0x210 [ 327.944335][ T9561] do_syscall_64+0xcd/0x4c0 [ 327.949387][ T9561] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 327.955809][ T9561] [ 327.955809][ T9561] other info that might help us debug this: [ 327.955809][ T9561] [ 327.966041][ T9561] Chain exists of: [ 327.966041][ T9561] uevent_sock_mutex --> fs_reclaim --> &q->q_usage_counter(io)#24 [ 327.966041][ T9561] [ 327.979829][ T9561] Possible unsafe locking scenario: [ 327.979829][ T9561] [ 327.987276][ T9561] CPU0 CPU1 [ 327.992641][ T9561] ---- ---- [ 327.998010][ T9561] lock(&q->q_usage_counter(io)#24); [ 328.003411][ T9561] lock(fs_reclaim); [ 328.009927][ T9561] lock(&q->q_usage_counter(io)#24); [ 328.017850][ T9561] lock(uevent_sock_mutex); [ 328.022457][ T9561] [ 328.022457][ T9561] *** DEADLOCK *** [ 328.022457][ T9561] [ 328.030599][ T9561] 3 locks held by syz.1.1022/9561: [ 328.035711][ T9561] #0: ffff888025d9c400 (&lo->lo_mutex){+.+.}-{4:4}, at: loop_set_status+0x2c/0xb90 [ 328.045524][ T9561] #1: ffff88814337e278 (&q->q_usage_counter(io)#24){++++}-{0:0}, at: blk_mq_freeze_queue_nomemsave+0x15/0x20 [ 328.057272][ T9561] #2: ffff88814337e2b0 (&q->q_usage_counter(queue)#20){+.+.}-{0:0}, at: blk_mq_freeze_queue_nomemsave+0x15/0x20 [ 328.069318][ T9561] [ 328.069318][ T9561] stack backtrace: [ 328.075205][ T9561] CPU: 0 UID: 0 PID: 9561 Comm: syz.1.1022 Not tainted 6.16.0-rc1-syzkaller-00004-gaef17cb3d3c4 #0 PREEMPT(full) [ 328.075251][ T9561] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 328.075272][ T9561] Call Trace: [ 328.075283][ T9561] [ 328.075295][ T9561] dump_stack_lvl+0x116/0x1f0 [ 328.075355][ T9561] print_circular_bug+0x275/0x350 [ 328.075413][ T9561] check_noncircular+0x14c/0x170 [ 328.075474][ T9561] __lock_acquire+0x126f/0x1c90 [ 328.075539][ T9561] lock_acquire+0x179/0x350 [ 328.075593][ T9561] ? kobject_uevent_env+0xb36/0x1870 [ 328.075639][ T9561] ? __pfx___might_resched+0x10/0x10 [ 328.075689][ T9561] __mutex_lock+0x199/0xb90 [ 328.075721][ T9561] ? kobject_uevent_env+0xb36/0x1870 [ 328.075763][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.075810][ T9561] ? kobject_uevent_env+0xb36/0x1870 [ 328.075855][ T9561] ? __pfx___mutex_lock+0x10/0x10 [ 328.075896][ T9561] ? __asan_memcpy+0x3c/0x60 [ 328.075928][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.075971][ T9561] ? kobject_get_path+0x8e/0x2a0 [ 328.076013][ T9561] ? kobject_uevent_env+0xb36/0x1870 [ 328.076055][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076099][ T9561] kobject_uevent_env+0xb36/0x1870 [ 328.076146][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076195][ T9561] set_capacity_and_notify+0x1ca/0x240 [ 328.076242][ T9561] ? __pfx_set_capacity_and_notify+0x10/0x10 [ 328.076291][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076334][ T9561] ? __asan_memcpy+0x3c/0x60 [ 328.076369][ T9561] loop_set_status+0x94c/0xb90 [ 328.076420][ T9561] loop_set_status_old+0x162/0x1d0 [ 328.076465][ T9561] ? __pfx_loop_set_status_old+0x10/0x10 [ 328.076509][ T9561] ? __lock_acquire+0x622/0x1c90 [ 328.076577][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076620][ T9561] ? find_held_lock+0x2b/0x80 [ 328.076663][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076729][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076772][ T9561] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 328.076813][ T9561] lo_ioctl+0xb3f/0x2760 [ 328.076855][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076898][ T9561] ? __lock_acquire+0xb8a/0x1c90 [ 328.076955][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.076998][ T9561] ? kasan_save_stack+0x42/0x60 [ 328.077028][ T9561] ? kasan_save_stack+0x33/0x60 [ 328.077057][ T9561] ? kasan_save_track+0x14/0x30 [ 328.077087][ T9561] ? kasan_save_free_info+0x3b/0x60 [ 328.077131][ T9561] ? __kasan_slab_free+0x51/0x70 [ 328.077163][ T9561] ? kfree+0x2b4/0x4d0 [ 328.077206][ T9561] ? tomoyo_path_number_perm+0x470/0x580 [ 328.077239][ T9561] ? security_file_ioctl+0x9b/0x240 [ 328.077274][ T9561] ? __x64_sys_ioctl+0xb7/0x210 [ 328.077321][ T9561] ? do_syscall_64+0xcd/0x4c0 [ 328.077347][ T9561] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 328.077383][ T9561] ? __pfx_lo_ioctl+0x10/0x10 [ 328.077434][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077470][ T9561] ? kasan_quarantine_put+0x10a/0x240 [ 328.077499][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077534][ T9561] ? lockdep_hardirqs_on+0x7c/0x110 [ 328.077581][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077618][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077652][ T9561] ? find_held_lock+0x2b/0x80 [ 328.077687][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077725][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077760][ T9561] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 328.077793][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077828][ T9561] ? blkdev_common_ioctl+0x1dd/0x2480 [ 328.077861][ T9561] ? __pfx_tomoyo_path_number_perm+0x10/0x10 [ 328.077895][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.077931][ T9561] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 328.077964][ T9561] ? __pfx_blkdev_common_ioctl+0x10/0x10 [ 328.078003][ T9561] ? __pfx_do_vfs_ioctl+0x10/0x10 [ 328.078065][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.078100][ T9561] ? find_held_lock+0x2b/0x80 [ 328.078133][ T9561] ? srso_alias_return_thunk+0x5/0xfbef5 [ 328.078169][ T9561] ? __pfx_lo_ioctl+0x10/0x10 [ 328.078205][ T9561] blkdev_ioctl+0x277/0x6d0 [ 328.078238][ T9561] ? __pfx_blkdev_ioctl+0x10/0x10 [ 328.078275][ T9561] ? __pfx_blkdev_ioctl+0x10/0x10 [ 328.078310][ T9561] __x64_sys_ioctl+0x18e/0x210 [ 328.078360][ T9561] do_syscall_64+0xcd/0x4c0 [ 328.078388][ T9561] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 328.078417][ T9561] RIP: 0033:0x7f59db58e929 [ 328.078439][ T9561] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 328.078468][ T9561] RSP: 002b:00007f59dc342038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 328.078493][ T9561] RAX: ffffffffffffffda RBX: 00007f59db7b6080 RCX: 00007f59db58e929 [ 328.078513][ T9561] RDX: 00002000000001c0 RSI: 0000000000004c02 RDI: 0000000000000004 [ 328.078532][ T9561] RBP: 00007f59db610b39 R08: 0000000000000000 R09: 0000000000000000 [ 328.078550][ T9561] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 328.078568][ T9561] R13: 0000000000000001 R14: 00007f59db7b6080 R15: 00007ffe1abde4c8 [ 328.078598][ T9561] [ 328.078623][ C0] vkms_vblank_simulate: vblank timer overrun [ 328.577369][ C0] vkms_vblank_simulate: vblank timer overrun