last executing test programs: 3.848995355s ago: executing program 3 (id=236): r0 = socket$packet(0x11, 0x3, 0x300) setsockopt$packet_tx_ring(r0, 0x107, 0x5, 0x0, 0x0) setsockopt$packet_rx_ring(r0, 0x107, 0x5, &(0x7f0000000100)=@req3={0xfffffffd, 0x0, 0x0, 0x0, 0x0, 0x0, 0x861}, 0x1c) 3.675734172s ago: executing program 3 (id=241): r0 = socket$inet(0x2, 0x4000000000000001, 0x0) setsockopt$inet_tcp_int(r0, 0x6, 0x80000000000002, &(0x7f00000004c0)=0x79, 0x4) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e23, @local}, 0x10) sendto$inet(r0, 0x0, 0x0, 0x200007fd, &(0x7f0000e68000)={0x2, 0x4e23, @local}, 0x10) setsockopt$sock_int(r0, 0x1, 0x8, &(0x7f0000000600)=0xdfa, 0x4) sendto$inet(r0, &(0x7f0000000580)='H', 0xfffffffffffffe64, 0x10008095, 0x0, 0x0) 2.746222233s ago: executing program 3 (id=257): bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000085000000070000001801000020756c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b70300000000a5df850000002d00000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000280)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x40f00, 0x9, '\x00', 0x0, @fallback=0x22, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00', r0}, 0x10) r1 = socket$igmp(0x2, 0x3, 0x2) setsockopt$MRT_ADD_VIF(r1, 0x0, 0xca, &(0x7f0000000140)={0x1, 0x1, 0xc, 0x5, @vifc_lcl_ifindex, @private=0xa010102}, 0x10) setsockopt$MRT_FLUSH(r1, 0x0, 0xd4, &(0x7f0000000040)=0x8, 0x4) 2.326579123s ago: executing program 3 (id=263): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000008c0)=ANY=[@ANYBLOB="0a00000002000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000007c0)={0x14, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x31, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r1}, 0x10) r2 = socket$netlink(0x10, 0x3, 0x10) r3 = socket$netlink(0x10, 0x3, 0x10) bind$netlink(r3, &(0x7f0000514ff4)={0x10, 0x0, 0x0, 0x2ffffffff}, 0xc) setsockopt$sock_int(r3, 0x1, 0x8, &(0x7f0000000000)=0x80, 0x4) setsockopt$netlink_NETLINK_BROADCAST_ERROR(r3, 0x10e, 0x4, &(0x7f0000000180)=0x800, 0x4) r4 = syz_genetlink_get_family_id$devlink(&(0x7f0000000040), 0xffffffffffffffff) sendmsg$DEVLINK_CMD_RATE_NEW(r2, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000700)={&(0x7f0000000300)={0x34, r4, 0x1, 0x0, 0x25dfdbfb, {0x25}, [@handle=@nsim={{0xe}, {0xf, 0x2, {'netdevsim', 0x0}}}]}, 0x34}, 0x1, 0x0, 0x0, 0x41}, 0x0) r5 = syz_genetlink_get_family_id$team(&(0x7f00000000c0), 0xffffffffffffffff) ioctl$ifreq_SIOCGIFINDEX_team(r2, 0x8933, &(0x7f0000000240)={'team0\x00', 0x0}) sendmsg$TEAM_CMD_OPTIONS_SET(r2, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000500)={&(0x7f0000000840)={0x58, r5, 0x1, 0x70bd2a, 0x25dfdbfc, {}, [{{0x8, 0x1, r6}, {0x3c, 0x2, 0x0, 0x1, [{0x38, 0x1, @mcast_rejoin_interval={{0x24}, {0x5}, {0x8, 0x4, 0xfffbfff9}}}]}}]}, 0x58}, 0x1, 0x1000000, 0x0, 0x24004000}, 0x24040840) 1.783050183s ago: executing program 4 (id=272): r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000640)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000000000000b703000000000000850000007300000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000180)='sys_enter\x00', r0}, 0x10) preadv(0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0) 1.587596214s ago: executing program 4 (id=276): r0 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_int(r0, 0x6, 0x13, &(0x7f0000000040)=0x100000001, 0x76dc) connect$inet6(r0, &(0x7f0000000100)={0xa, 0x0, 0x0, @empty}, 0x1c) setsockopt$inet6_tcp_TCP_ULP(r0, 0x6, 0x1f, &(0x7f00000002c0), 0x4) setsockopt$inet6_tcp_TCP_REPAIR_QUEUE(r0, 0x6, 0x14, &(0x7f0000000400)=0x1, 0x4) recvfrom$inet6(r0, &(0x7f0000000300)=""/218, 0xda, 0x120, 0x0, 0x0) syz_genetlink_get_family_id$ethtool(&(0x7f0000000240), r0) mmap(&(0x7f0000000000/0x95c000)=nil, 0x95c000, 0x9, 0x8c4b815a5465c2b1, 0xffffffffffffffff, 0x0) connect$inet6(r0, &(0x7f00000001c0)={0xa, 0x4e23, 0x4, @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}}, 0x1c) shutdown(r0, 0x0) 1.433581516s ago: executing program 4 (id=278): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0e000000040000000800000008"], 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000380)={&(0x7f0000000040)='kmem_cache_free\x00', r1}, 0x18) r2 = socket$packet(0x11, 0x3, 0x300) ioctl$sock_SIOCGIFINDEX(r2, 0x8933, &(0x7f0000000180)={'geneve1\x00', 0x0}) sendto$packet(r2, &(0x7f00000002c0)="1441c05465f0006fc8afa8e40800", 0xe, 0x4000000, &(0x7f00000000c0)={0x11, 0x0, r3, 0x1, 0x0, 0x6, @multicast}, 0x14) 1.158967816s ago: executing program 4 (id=284): r0 = socket$inet(0x2, 0x4000000000000001, 0x0) setsockopt$inet_tcp_int(r0, 0x6, 0x80000000000002, &(0x7f00000004c0)=0x79, 0x4) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e23, @local}, 0x10) setsockopt$SO_ATTACH_FILTER(r0, 0x1, 0x1a, &(0x7f0000000140)={0x1, &(0x7f0000000280)=[{0x6, 0x0, 0x0, 0xe4}]}, 0x10) sendto$inet(r0, 0x0, 0x0, 0x200007fd, &(0x7f0000e68000)={0x2, 0x4e23, @local}, 0x10) sendmmsg$inet(r0, &(0x7f0000000cc0)=[{{0x0, 0x0, &(0x7f0000000000)=[{&(0x7f0000000180)="acc870bde54caaeacb0000108cef4fa7bf44702b284b2e80cb32d33a86853c8c2879", 0x22}], 0x1}}], 0x1, 0xc0) setsockopt$sock_int(r0, 0x1, 0x8, &(0x7f0000000600)=0xdfa, 0x4) sendto$inet(r0, &(0x7f0000000580)='H', 0xfffffffffffffe64, 0x10008095, 0x0, 0x0) 1.040154392s ago: executing program 3 (id=287): bpf$ENABLE_STATS(0x20, 0x0, 0x0) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x13, &(0x7f0000000280)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020756c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b70300000000000085000000b0000000180100002020782500000000f01f20207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000002d00000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000340)={&(0x7f0000000400)='virtio_transport_alloc_pkt\x00', r0}, 0x18) r1 = socket$vsock_stream(0x28, 0x1, 0x0) connect$vsock_stream(r1, &(0x7f0000000140)={0x28, 0x0, 0x0, @my=0x1}, 0x10) 1.039792051s ago: executing program 0 (id=288): r0 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_int(r0, 0x6, 0x13, &(0x7f0000000040)=0x100000001, 0x76dc) connect$inet6(r0, &(0x7f0000000100)={0xa, 0x0, 0x0, @empty}, 0x1c) setsockopt$inet6_tcp_TCP_ULP(r0, 0x6, 0x1f, &(0x7f00000002c0), 0x4) setsockopt$inet6_tcp_TCP_REPAIR_QUEUE(r0, 0x6, 0x14, &(0x7f0000000400)=0x1, 0x4) recvfrom$inet6(r0, &(0x7f0000000300)=""/218, 0xda, 0x120, 0x0, 0x0) syz_genetlink_get_family_id$ethtool(&(0x7f0000000240), r0) mmap(&(0x7f0000000000/0x95c000)=nil, 0x95c000, 0x9, 0x8c4b815a5465c2b1, 0xffffffffffffffff, 0x0) connect$inet6(r0, &(0x7f00000001c0)={0xa, 0x4e23, 0x4, @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}}, 0x1c) shutdown(r0, 0x0) 988.569325ms ago: executing program 1 (id=289): socket$unix(0x1, 0x1, 0x0) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000440)={0x18, 0xb, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000004f4b00000000001b000000180100002020702000000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000000000000b703000006ffffff850000007100000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x41000, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000080)='sched_switch\x00', r0}, 0x10) bpf$PROG_LOAD(0x5, 0x0, 0x0) r1 = syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) r2 = syz_genetlink_get_family_id$netlbl_cipso(&(0x7f0000000bc0), r1) sendmsg$NLBL_CIPSOV4_C_ADD(r1, &(0x7f0000000580)={0x0, 0x0, &(0x7f0000000540)={&(0x7f0000000800)=ANY=[@ANYBLOB="84010000", @ANYRES16=r2, @ANYBLOB="010000000000000000000100000004000480080002000100000008000100000000000400088058010c8054000b8008000a"], 0x184}}, 0x0) 944.049173ms ago: executing program 2 (id=290): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0500000004000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000700)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x26, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$MAP_UPDATE_CONST_STR(0x2, &(0x7f00000002c0)={{r1}, &(0x7f0000000040), &(0x7f0000000280)='%-010d \x00'}, 0x20) bpf$PROG_LOAD(0x5, &(0x7f0000000280)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1e, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r0, 0x84, 0x72, &(0x7f0000000240)={0x0, 0x0, 0x20}, 0xc) bind$inet6(r0, &(0x7f0000000000)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendto$inet6(r0, &(0x7f0000000180)="1a", 0x34000, 0x0, &(0x7f0000000480)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendmmsg$sock(r0, &(0x7f0000000900)=[{{0x0, 0x0, &(0x7f0000000100)=[{&(0x7f0000000080)=' ', 0x1}], 0x1}}], 0x1, 0x48800) shutdown(r0, 0x1) 881.993831ms ago: executing program 3 (id=291): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000003c0)={0x11, 0x1c, &(0x7f0000001980)=ANY=[@ANYBLOB="18000000fcff00000000000015f87a6606030100ff010000181b0000", @ANYBLOB="020f905d48754a10cec7ac2ebbf7da490bd9880ded7bf0e3bd61b129c1839a2bfa526326187f7fc29a17a5adc48f25370641e4558ac98e8f3d7b6152974bdabbf5346a074077844dac63ed6a572e30236291867ff9086efc9b0c84d33677ac86232f0ca3f8ad", @ANYBLOB="00000000000000008706500008000000b7080000000000007b8af8ff00000000b7080000090000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb70200000800000018230000", @ANYRES32=0x1, @ANYBLOB="0000000000000000b70500000800000085000000a5000000185800000700000000000000000000001830000002000000000000000000000018521b00070000000000000000000000852000000200000095000000000000009500000000000000"], &(0x7f0000000340)='GPL\x00', 0x4, 0x1000, &(0x7f0000000580)=""/4096, 0x41000, 0x64, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, &(0x7f0000000380), 0x10, 0x4, @void, @value}, 0x94) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0b00000007000000080000000800000005"], 0x48) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000004c0)={&(0x7f0000000180)='kfree\x00', 0xffffffffffffffff, 0x0, 0x20}, 0x18) bpf$MAP_CREATE(0x0, &(0x7f0000001840)=ANY=[@ANYBLOB="2100000000000000000000000000100000040000", @ANYRES32, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="0000000000000002000000000000000000000002000000000000000022be730d3a9ff11b2861881ce5a73d1fc01d7b236afc50bbe5dcc15465e56efc1132f1194c3e23fd3f536d6354f3308b308f8a6d1d6a3c6d2f279670db9d6c9204af6797e89b9f85fd5e152034e0e5a2445ea90d7c2fa2af8baf06ca713819eefabc713044b58f71f5040b261bba6937f98f9b52d98376e070ee018aa535befc9bbeb6ecd10cf4b183bc3dfb11178bfe9ad079f10df1e9075bdbccefebd0ac34a4bd0ba384a272f8a9cda329c542a5609b2b781ec93b46b7431e829df8"], 0x50) 881.291879ms ago: executing program 0 (id=292): r0 = socket$kcm(0x10, 0x3, 0x10) sendmsg$kcm(r0, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f0000000040)="1400000016000b63d25a80648c2594f92624fc60", 0x14}], 0x1}, 0x0) 767.966688ms ago: executing program 1 (id=293): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = syz_genetlink_get_family_id$batadv(&(0x7f0000000400), 0xffffffffffffffff) ioctl$ifreq_SIOCGIFINDEX_batadv_mesh(r0, 0x8933, &(0x7f0000000440)={'batadv0\x00', 0x0}) sendmsg$BATADV_CMD_SET_MESH(r0, &(0x7f0000000540)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000940)=ANY=[@ANYBLOB=',\x00\x00\x00', @ANYRES16=r1, @ANYBLOB="010000000040000000000f00000008000300", @ANYRES32=r2, @ANYBLOB="08002affed00000008002c"], 0x2c}, 0x1, 0x0, 0x0, 0x4004000}, 0x0) 767.698524ms ago: executing program 0 (id=294): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="170000000000000004000000ff"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b704000000000000850000005700000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000900)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000180)='GPL\x00', 0x2, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, @fallback=0x7, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffc, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00', r1}, 0x10) r2 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) ioctl$TUNSETIFF(r2, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) r3 = socket$unix(0x1, 0x5, 0x0) ioctl$sock_SIOCGIFINDEX(r3, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2a, 0xffffffff, {0x0, 0x0, 0x0, r4, {0x0, 0xfff1}, {0xffff, 0xffff}, {0x3, 0x8}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8}}]}, 0x38}}, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000006040)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000280)=@newtfilter={0x90, 0x2c, 0xd27, 0x70bd28, 0x0, {0x0, 0x0, 0x0, r4, {0x0, 0xfff1}, {}, {0x7}}, [@filter_kind_options=@f_fw={{0x7}, {0x5c, 0x2, [@TCA_FW_ACT={0x58, 0x4, [@m_nat={0x54, 0x1, 0x0, 0x0, {{0x8}, {0x2c, 0x2, 0x0, 0x1, [@TCA_NAT_PARMS={0x28, 0x1, {{0xfffffc00, 0x8, 0x10000000, 0x200000b, 0xff}, @broadcast, @local, 0xff, 0x1}}]}, {0x4}, {0xc, 0x7, {0x0, 0x1}}, {0xc, 0x8, {0x2, 0x2}}}}]}]}}, @TCA_RATE={0x6, 0x5, {0xd, 0x8}}]}, 0x90}, 0x1, 0x0, 0x0, 0x4}, 0x4000800) 697.008964ms ago: executing program 1 (id=295): r0 = socket$tipc(0x1e, 0x5, 0x0) bind$tipc(r0, &(0x7f0000000000)=@nameseq={0x1e, 0x1, 0x0, {0x41}}, 0x10) listen(r0, 0x0) r1 = socket$tipc(0x1e, 0x5, 0x0) r2 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b00000007000000010001004900000001", @ANYBLOB], 0x48) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000000)={{r2, 0xffffffffffffffff}, &(0x7f0000000580), &(0x7f00000005c0)}, 0x20) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000200)={0x11, 0xd, &(0x7f00000002c0)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r3, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7040000000000008500000003000000650000000800000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000140)='kmem_cache_free\x00', r4}, 0x10) sendmsg$tipc(r1, &(0x7f00000000c0)={&(0x7f0000000080)=@nameseq={0x1e, 0x2, 0x0, {0x41}}, 0x10, 0x0, 0x0, 0x0, 0x0, 0x480c0}, 0x0) accept4(r0, 0x0, 0x0, 0x400000000000000) 690.34984ms ago: executing program 2 (id=296): r0 = socket$inet_sctp(0x2, 0x1, 0x84) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e22, @local}, 0x10) sendmmsg$inet_sctp(r0, &(0x7f0000004900)=[{0x0, 0x0, &(0x7f0000000180)=[{&(0x7f0000000100)="f4", 0x1}], 0x1, &(0x7f0000000000)=[@sndinfo={0x20, 0x84, 0x2, {0x9, 0x3, 0x6, 0x8}}, @init={0x18, 0x84, 0x0, {0x3000, 0x4, 0x1, 0xc}}], 0x38}], 0x1, 0x0) 540.117328ms ago: executing program 0 (id=297): preadv(0xffffffffffffffff, 0x0, 0x0, 0x9, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) r0 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) ioctl$TUNSETIFF(r0, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) r1 = socket(0x10, 0x803, 0x0) r2 = socket$unix(0x1, 0x5, 0x0) ioctl$sock_SIOCGIFINDEX(r2, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r1, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2a, 0xffffffff, {0x0, 0x0, 0x0, r3, {0x0, 0x9}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8, 0x2, {0x4, 0xc00}}}]}, 0x38}}, 0x0) sendmsg$nl_route_sched(r1, &(0x7f0000006040)={0x0, 0x0, &(0x7f0000000300)={&(0x7f0000003500)=@newtfilter={0x70, 0x2c, 0xd27, 0xfffffffc, 0x0, {0x0, 0x0, 0x0, r3, {0xc, 0xfff1}, {}, {0x5, 0xf}}, [@filter_kind_options=@f_flow={{0x9}, {0x40, 0x2, [@TCA_FLOW_EMATCHES={0x3c, 0xb, 0x0, 0x1, [@TCA_EMATCH_TREE_HDR={0x8, 0x1, {0xfffb}}, @TCA_EMATCH_TREE_LIST={0x30, 0x2, 0x0, 0x1, [@TCF_EM_CANID={0x14, 0x1, 0x0, 0x0, {{0x7, 0x7, 0x2}, {{0x0, 0x1, 0x0, 0x1}, {0x0, 0x1, 0x1, 0x1}}}}, @TCF_EM_META={0x18, 0x2, 0x0, 0x0, {{0xfffb, 0x4, 0x2}, [@TCA_EM_META_HDR={0xc, 0x1, {{0x5, 0xe, 0x2}, {0x0, 0x7, 0x2}}}]}}]}]}]}}]}, 0x70}}, 0x20040054) 539.933707ms ago: executing program 1 (id=298): r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f00000009c0)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000083850000007100000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00', r0}, 0x10) r1 = socket$xdp(0x2c, 0x3, 0x0) setsockopt$XDP_UMEM_REG(r1, 0x11b, 0x4, &(0x7f0000000000)={0xfffffffffffffffc, 0x12000, 0x1000, 0x0, 0x2}, 0x20) 511.840354ms ago: executing program 2 (id=299): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=@base={0x2, 0x4, 0x8, 0xc, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000280)=@framed={{}, [@ringbuf_output={{0x18, 0x1, 0x1, 0x0, r0}, {}, {}, {}, {}, {}, {}, {0x85, 0x0, 0x0, 0x3}}]}, &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000180)='kfree\x00', r1}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000800), 0xffffffffffffffff) sendmsg$NL80211_CMD_SET_TID_CONFIG(r2, &(0x7f0000000340)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000000)={0x24, r3, 0xc4fc9e906872338b, 0x70bd2d, 0x0, {{0x15}, {@void, @void}}, [@NL80211_ATTR_TID_CONFIG={0x10, 0x11d, 0x0, 0x1, [{0xc, 0x0, 0x0, 0x1, [@NL80211_TID_CONFIG_ATTR_TX_RATE={0x8, 0xd, 0x0, 0x1, [@NL80211_BAND_6GHZ={0x4, 0x3, 0x0, 0x0}]}]}]}]}, 0x24}}, 0x0) 492.506508ms ago: executing program 1 (id=300): r0 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r0, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000000780)=@newlink={0x2c, 0x10, 0x801, 0x0, 0x0, {}, [@IFLA_PORT_SELF={0x4}, @IFLA_GROUP={0x8}]}, 0x2c}}, 0x0) 328.152723ms ago: executing program 2 (id=301): bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="1b0000000000000000000000000004"], 0x48) r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0e0000000400000008"], 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000b80)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000e00007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000005c0)={&(0x7f0000000000)='kmem_cache_free\x00', r1}, 0x18) syz_emit_ethernet(0xe, &(0x7f0000000200)={@link_local={0x1, 0x80, 0xc2, 0x0, 0x0, 0x5c39bf99f84da5cc}, @random="34f7091d6448", @void, {@generic={0x800}}}, 0x0) 284.833427ms ago: executing program 1 (id=302): bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000085000000070000001801000020756c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b70300000000a5df850000002d00000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="18090000000000000000000000000000850000006d0000001801000020696c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x34, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x2, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r0}, 0x10) r1 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) ioctl$TUNSETIFF(r1, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) r2 = socket(0x10, 0x803, 0x0) r3 = socket$unix(0x1, 0x1, 0x0) ioctl$sock_SIOCGIFINDEX(r3, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r2, &(0x7f0000001cc0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2b, 0xffffffff, {0x0, 0x0, 0x0, r4, {0x0, 0x7}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8}}]}, 0x38}}, 0x0) sendmsg$nl_route_sched(r2, &(0x7f0000006040)={0x0, 0x0, &(0x7f0000000300)={&(0x7f0000000140)=@newtfilter={0x5c, 0x2c, 0xd27, 0x30bd29, 0x2, {0x0, 0x0, 0x0, r4, {0x0, 0x6}, {}, {0x7, 0xa}}, [@filter_kind_options=@f_basic={{0xa}, {0x2c, 0x2, [@TCA_BASIC_EMATCHES={0x28, 0x2, 0x0, 0x1, [@TCA_EMATCH_TREE_HDR={0x8, 0x1, {0x1}}, @TCA_EMATCH_TREE_LIST={0x1c, 0x2, 0x0, 0x1, [@TCF_EM_META={0x18, 0x1, 0x0, 0x0, {{0x7, 0x4, 0x4}, [@TCA_EM_META_HDR={0xc, 0x1, {{0x4, 0x81, 0x1}, {0x2, 0xa5, 0x2}}}]}}]}]}]}}]}, 0x5c}}, 0x0) 260.733308ms ago: executing program 0 (id=303): socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) unshare(0x400) bind$unix(r0, 0x0, 0x0) 204.043827ms ago: executing program 2 (id=304): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000100)={{0x14, 0x10, 0x1, 0x0, 0x0, {0x1}}, [@NFT_MSG_NEWTABLE={0x20, 0x0, 0xa, 0x401, 0x0, 0x0, {0x1, 0x0, 0x3}, [@NFTA_TABLE_NAME={0x9, 0x1, 'syz0\x00'}]}, @NFT_MSG_NEWCHAIN={0x2c, 0x3, 0xa, 0x101, 0x0, 0x0, {0x1, 0x0, 0x200}, [@NFTA_CHAIN_TABLE={0x9, 0x1, 'syz0\x00'}, @NFTA_CHAIN_NAME={0x9, 0x3, 'syz2\x00'}]}, @NFT_MSG_NEWRULE={0x48, 0x6, 0xa, 0x401, 0x0, 0x0, {0x1}, [@NFTA_RULE_CHAIN_ID={0x8}, @NFTA_RULE_EXPRESSIONS={0x20, 0x4, 0x0, 0x1, [{0x1c, 0x1, 0x0, 0x1, @bitwise={{0xc}, @val={0xc, 0x2, 0x0, 0x1, [@NFTA_BITWISE_LEN={0x8, 0x3, 0x1, 0x0, 0x2}]}}}]}, @NFTA_RULE_TABLE={0x9, 0x1, 'syz0\x00'}]}], {0x14, 0x11, 0x1, 0x0, 0x0, {0x7}}}, 0xbc}}, 0x0) 203.767608ms ago: executing program 4 (id=305): r0 = socket$inet_icmp_raw(0x2, 0x3, 0x1) setsockopt$inet_IP_XFRM_POLICY(r0, 0x0, 0x11, &(0x7f0000005b80)={{{@in6=@remote, @in6=@rand_addr=' \x01\x00', 0x0, 0x0, 0x0, 0x0, 0x2}, {0x0, 0x0, 0x0, 0x7}}, {{@in=@dev={0xac, 0x14, 0x14, 0x1d}, 0x0, 0x6c}, 0x0, @in6=@dev}}, 0xe8) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="19000000040000000800000006"], 0x48) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xc, &(0x7f0000000580)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000400)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000040)='kmem_cache_free\x00', r2}, 0x10) syz_emit_ethernet(0x3e, &(0x7f0000000500)={@local, @random="f368656e065b", @void, {@ipv4={0x800, @icmp={{0x5, 0x4, 0x0, 0x0, 0x30, 0x0, 0x0, 0x0, 0x1, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}, @multicast1}, @time_exceeded={0x4, 0x0, 0x0, 0x3, 0x0, 0x0, {0x5, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @dev, @dev}}}}}}, 0x0) 102.781078ms ago: executing program 2 (id=306): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0500000004000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000700)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x26, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$MAP_UPDATE_CONST_STR(0x2, &(0x7f00000002c0)={{r1}, &(0x7f0000000040), &(0x7f0000000280)='%-010d \x00'}, 0x20) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000005c0)={&(0x7f0000000580)='kmem_cache_free\x00'}, 0x10) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r0, 0x84, 0x72, &(0x7f0000000240)={0x0, 0x0, 0x20}, 0xc) bind$inet6(r0, &(0x7f0000000000)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendto$inet6(r0, &(0x7f0000000180)="1a", 0x34000, 0x0, &(0x7f0000000480)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendmmsg$sock(r0, &(0x7f0000000900)=[{{0x0, 0x0, &(0x7f0000000100)=[{&(0x7f0000000080)=' ', 0x1}], 0x1}}], 0x1, 0x48800) shutdown(r0, 0x1) 92.58089ms ago: executing program 0 (id=307): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000000c0)=@base={0x1b, 0x0, 0x0, 0x8000, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018120000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7040000f6000000850000004300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x1f, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x1a, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, @void, @value}, 0x94) bpf$PROG_BIND_MAP(0xa, &(0x7f00000004c0)={r1}, 0xc) 0s ago: executing program 4 (id=308): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000580)=ANY=[@ANYBLOB="140000001000010000000000000000000100000a20000000020a01040000000000000000010080030900010073797a30000000002c000000030a01010000000000000000010000000900010073797a30000000000900030073797a310000000070000000060a010400000000000000000100000008000b400000000048000480440001800b000100657874686472000034000280080001400000000c080003400000000008000440000000220500020007000000080006400000000308000540000000000900010073797a30"], 0x248}}, 0x0) kernel console output (not intermixed with test programs): [ 60.217971][ T5494] 8021q: adding VLAN 0 to HW filter on device bond0 [ 60.245402][ T5494] eql: remember to turn off Van-Jacobson compression on your slave devices Starting crond: OK Starting sshd: [ 60.759209][ T5576] ssh-keygen (5576) used greatest stack depth: 20440 bytes left OK syzkaller Warning: Permanently added '10.128.0.48' (ED25519) to the list of known hosts. syzkaller login: [ 80.772736][ T5815] cgroup: Unknown subsys name 'net' [ 80.985765][ T5815] cgroup: Unknown subsys name 'cpuset' [ 80.996261][ T5815] cgroup: Unknown subsys name 'rlimit' Setting up swapspace version 1, size = 127995904 bytes [ 82.751118][ T5815] Adding 124996k swap on ./swap-file. Priority:0 extents:1 across:124996k [ 85.395558][ T5829] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 85.396552][ T5834] Bluetooth: hci1: unexpected cc 0x0c03 length: 249 > 1 [ 85.413994][ T5829] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 85.422391][ T5834] Bluetooth: hci1: unexpected cc 0x1003 length: 249 > 9 [ 85.431187][ T5834] Bluetooth: hci1: unexpected cc 0x1001 length: 249 > 9 [ 85.431233][ T5829] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 85.447179][ T5829] Bluetooth: hci1: unexpected cc 0x0c23 length: 249 > 4 [ 85.455168][ T5836] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 85.456112][ T5829] Bluetooth: hci1: unexpected cc 0x0c38 length: 249 > 2 [ 85.463326][ T5836] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 85.478372][ T5833] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 85.507583][ T5836] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 85.516579][ T5836] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 85.526694][ T5836] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 85.553824][ T5836] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 85.586679][ T5834] Bluetooth: hci3: unexpected cc 0x0c03 length: 249 > 1 [ 85.595902][ T5834] Bluetooth: hci3: unexpected cc 0x1003 length: 249 > 9 [ 85.604271][ T5834] Bluetooth: hci3: unexpected cc 0x1001 length: 249 > 9 [ 85.615178][ T5834] Bluetooth: hci3: unexpected cc 0x0c23 length: 249 > 4 [ 85.626931][ T5139] Bluetooth: hci4: unexpected cc 0x0c03 length: 249 > 1 [ 85.635635][ T5139] Bluetooth: hci3: unexpected cc 0x0c38 length: 249 > 2 [ 85.643145][ T5834] Bluetooth: hci4: unexpected cc 0x1003 length: 249 > 9 [ 85.653651][ T5834] Bluetooth: hci4: unexpected cc 0x1001 length: 249 > 9 [ 85.663986][ T5139] Bluetooth: hci4: unexpected cc 0x0c23 length: 249 > 4 [ 85.672072][ T5139] Bluetooth: hci4: unexpected cc 0x0c38 length: 249 > 2 [ 86.226580][ T5830] chnl_net:caif_netlink_parms(): no params data found [ 86.356281][ T5835] chnl_net:caif_netlink_parms(): no params data found [ 86.425085][ T5825] chnl_net:caif_netlink_parms(): no params data found [ 86.508248][ T5830] bridge0: port 1(bridge_slave_0) entered blocking state [ 86.517397][ T5830] bridge0: port 1(bridge_slave_0) entered disabled state [ 86.525462][ T5830] bridge_slave_0: entered allmulticast mode [ 86.534299][ T5830] bridge_slave_0: entered promiscuous mode [ 86.548538][ T5830] bridge0: port 2(bridge_slave_1) entered blocking state [ 86.556560][ T5830] bridge0: port 2(bridge_slave_1) entered disabled state [ 86.563845][ T5830] bridge_slave_1: entered allmulticast mode [ 86.571914][ T5830] bridge_slave_1: entered promiscuous mode [ 86.621172][ T5841] chnl_net:caif_netlink_parms(): no params data found [ 86.741170][ T5835] bridge0: port 1(bridge_slave_0) entered blocking state [ 86.748443][ T5835] bridge0: port 1(bridge_slave_0) entered disabled state [ 86.756918][ T5835] bridge_slave_0: entered allmulticast mode [ 86.765051][ T5835] bridge_slave_0: entered promiscuous mode [ 86.785823][ T5830] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 86.799344][ T5830] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 86.821140][ T5835] bridge0: port 2(bridge_slave_1) entered blocking state [ 86.828634][ T5835] bridge0: port 2(bridge_slave_1) entered disabled state [ 86.839423][ T5835] bridge_slave_1: entered allmulticast mode [ 86.847741][ T5835] bridge_slave_1: entered promiscuous mode [ 87.009366][ T5839] chnl_net:caif_netlink_parms(): no params data found [ 87.074132][ T5830] team0: Port device team_slave_0 added [ 87.120382][ T5835] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 87.154183][ T5830] team0: Port device team_slave_1 added [ 87.163371][ T5825] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.171797][ T5825] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.179661][ T5825] bridge_slave_0: entered allmulticast mode [ 87.187756][ T5825] bridge_slave_0: entered promiscuous mode [ 87.216988][ T5835] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 87.266906][ T5825] bridge0: port 2(bridge_slave_1) entered blocking state [ 87.274783][ T5825] bridge0: port 2(bridge_slave_1) entered disabled state [ 87.282763][ T5825] bridge_slave_1: entered allmulticast mode [ 87.290351][ T5825] bridge_slave_1: entered promiscuous mode [ 87.354762][ T5841] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.362169][ T5841] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.369386][ T5841] bridge_slave_0: entered allmulticast mode [ 87.378678][ T5841] bridge_slave_0: entered promiscuous mode [ 87.387050][ T5830] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 87.394182][ T5830] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 87.420742][ T5830] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 87.434936][ T5830] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 87.442013][ T5830] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 87.468435][ T5830] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 87.511872][ T5836] Bluetooth: hci0: command tx timeout [ 87.517588][ T5835] team0: Port device team_slave_0 added [ 87.524240][ T5841] bridge0: port 2(bridge_slave_1) entered blocking state [ 87.532176][ T5841] bridge0: port 2(bridge_slave_1) entered disabled state [ 87.539953][ T5841] bridge_slave_1: entered allmulticast mode [ 87.548800][ T5841] bridge_slave_1: entered promiscuous mode [ 87.582258][ T5825] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 87.591711][ T5829] Bluetooth: hci1: command tx timeout [ 87.591962][ T5836] Bluetooth: hci2: command tx timeout [ 87.611459][ T5835] team0: Port device team_slave_1 added [ 87.654667][ T5825] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 87.688075][ T5841] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 87.702011][ T5841] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 87.750825][ T5829] Bluetooth: hci3: command tx timeout [ 87.756582][ T5836] Bluetooth: hci4: command tx timeout [ 87.800486][ T5830] hsr_slave_0: entered promiscuous mode [ 87.808208][ T5830] hsr_slave_1: entered promiscuous mode [ 87.846996][ T5835] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 87.854231][ T5835] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 87.881232][ T5835] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 87.910480][ T5841] team0: Port device team_slave_0 added [ 87.919885][ T5825] team0: Port device team_slave_0 added [ 87.930235][ T5839] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.937591][ T5839] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.944903][ T5839] bridge_slave_0: entered allmulticast mode [ 87.952870][ T5839] bridge_slave_0: entered promiscuous mode [ 87.961443][ T5835] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 87.968619][ T5835] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 87.994918][ T5835] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.015325][ T5841] team0: Port device team_slave_1 added [ 88.023227][ T5825] team0: Port device team_slave_1 added [ 88.029672][ T5839] bridge0: port 2(bridge_slave_1) entered blocking state [ 88.037197][ T5839] bridge0: port 2(bridge_slave_1) entered disabled state [ 88.044781][ T5839] bridge_slave_1: entered allmulticast mode [ 88.052435][ T5839] bridge_slave_1: entered promiscuous mode [ 88.155543][ T5825] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.162865][ T5825] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.189845][ T5825] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.218194][ T5839] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 88.244811][ T5841] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.251937][ T5841] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.278434][ T5841] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.290928][ T5825] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.297929][ T5825] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.324677][ T5825] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.351811][ T5839] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 88.378268][ T5841] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.387923][ T5841] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.418302][ T5841] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.497188][ T5835] hsr_slave_0: entered promiscuous mode [ 88.504711][ T5835] hsr_slave_1: entered promiscuous mode [ 88.511944][ T5835] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 88.519712][ T5835] Cannot create hsr debugfs directory [ 88.603540][ T5839] team0: Port device team_slave_0 added [ 88.665193][ T5839] team0: Port device team_slave_1 added [ 88.698297][ T5825] hsr_slave_0: entered promiscuous mode [ 88.705363][ T5825] hsr_slave_1: entered promiscuous mode [ 88.712716][ T5825] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 88.720412][ T5825] Cannot create hsr debugfs directory [ 88.814224][ T5841] hsr_slave_0: entered promiscuous mode [ 88.821209][ T5841] hsr_slave_1: entered promiscuous mode [ 88.827441][ T5841] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 88.835182][ T5841] Cannot create hsr debugfs directory [ 88.871111][ T5839] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.878205][ T5839] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.904697][ T5839] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.917665][ T5839] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.924697][ T5839] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.951789][ T5839] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 89.208293][ T5839] hsr_slave_0: entered promiscuous mode [ 89.216333][ T5839] hsr_slave_1: entered promiscuous mode [ 89.223559][ T5839] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 89.232128][ T5839] Cannot create hsr debugfs directory [ 89.358023][ T5830] netdevsim netdevsim4 netdevsim0: renamed from eth0 [ 89.399311][ T5830] netdevsim netdevsim4 netdevsim1: renamed from eth1 [ 89.437253][ T5830] netdevsim netdevsim4 netdevsim2: renamed from eth2 [ 89.477543][ T5830] netdevsim netdevsim4 netdevsim3: renamed from eth3 [ 89.525576][ T5835] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 89.559726][ T5835] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 89.589501][ T5835] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 89.596882][ T5836] Bluetooth: hci0: command tx timeout [ 89.628412][ T5835] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 89.681556][ T5829] Bluetooth: hci1: command tx timeout [ 89.687186][ T5836] Bluetooth: hci2: command tx timeout [ 89.718610][ T5825] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 89.736860][ T5825] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 89.749251][ T5825] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 89.760251][ T5825] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 89.833090][ T5829] Bluetooth: hci3: command tx timeout [ 89.838872][ T5836] Bluetooth: hci4: command tx timeout [ 89.890345][ T5841] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 89.906175][ T5841] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 89.917571][ T5841] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 89.930460][ T5841] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 90.095206][ T5839] netdevsim netdevsim2 netdevsim0: renamed from eth0 [ 90.106514][ T5839] netdevsim netdevsim2 netdevsim1: renamed from eth1 [ 90.125057][ T5830] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.142628][ T5839] netdevsim netdevsim2 netdevsim2: renamed from eth2 [ 90.154651][ T5839] netdevsim netdevsim2 netdevsim3: renamed from eth3 [ 90.206470][ T5835] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.232114][ T5830] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.290022][ T5835] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.306713][ T5092] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.314098][ T5092] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.334140][ T5825] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.369318][ T5092] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.376538][ T5092] bridge0: port 2(bridge_slave_1) entered forwarding state [ 90.390366][ T5092] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.397601][ T5092] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.417782][ T5841] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.429567][ T5825] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.482711][ T12] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.489898][ T12] bridge0: port 2(bridge_slave_1) entered forwarding state [ 90.514085][ T12] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.521386][ T12] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.584161][ T12] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.591558][ T12] bridge0: port 2(bridge_slave_1) entered forwarding state [ 90.611718][ T5841] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.678770][ T12] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.686322][ T12] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.698419][ T12] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.705721][ T12] bridge0: port 2(bridge_slave_1) entered forwarding state [ 90.887902][ T5839] 8021q: adding VLAN 0 to HW filter on device bond0 [ 91.039661][ T5839] 8021q: adding VLAN 0 to HW filter on device team0 [ 91.074916][ T12] bridge0: port 1(bridge_slave_0) entered blocking state [ 91.082244][ T12] bridge0: port 1(bridge_slave_0) entered forwarding state [ 91.156837][ T12] bridge0: port 2(bridge_slave_1) entered blocking state [ 91.164360][ T12] bridge0: port 2(bridge_slave_1) entered forwarding state [ 91.438441][ T5830] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.503386][ T5835] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.638540][ T5825] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.677946][ T5836] Bluetooth: hci0: command tx timeout [ 91.750981][ T5836] Bluetooth: hci2: command tx timeout [ 91.756483][ T5836] Bluetooth: hci1: command tx timeout [ 91.813394][ T5835] veth0_vlan: entered promiscuous mode [ 91.862575][ T5841] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.913043][ T5829] Bluetooth: hci3: command tx timeout [ 91.918739][ T5836] Bluetooth: hci4: command tx timeout [ 91.927006][ T5825] veth0_vlan: entered promiscuous mode [ 91.949447][ T5835] veth1_vlan: entered promiscuous mode [ 92.012364][ T3076] cfg80211: failed to load regulatory.db [ 92.033071][ T5839] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 92.046155][ T5825] veth1_vlan: entered promiscuous mode [ 92.129378][ T5841] veth0_vlan: entered promiscuous mode [ 92.167632][ T5830] veth0_vlan: entered promiscuous mode [ 92.176622][ T5841] veth1_vlan: entered promiscuous mode [ 92.190662][ T5835] veth0_macvtap: entered promiscuous mode [ 92.218887][ T5830] veth1_vlan: entered promiscuous mode [ 92.248660][ T5835] veth1_macvtap: entered promiscuous mode [ 92.274311][ T5825] veth0_macvtap: entered promiscuous mode [ 92.306767][ T5825] veth1_macvtap: entered promiscuous mode [ 92.317420][ T5839] veth0_vlan: entered promiscuous mode [ 92.367443][ T5835] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 92.384334][ T5841] veth0_macvtap: entered promiscuous mode [ 92.399909][ T5830] veth0_macvtap: entered promiscuous mode [ 92.413502][ T5825] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 92.426568][ T5841] veth1_macvtap: entered promiscuous mode [ 92.438269][ T5835] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 92.446943][ T5839] veth1_vlan: entered promiscuous mode [ 92.462659][ T5830] veth1_macvtap: entered promiscuous mode [ 92.474582][ T5825] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 92.503232][ T5825] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.513997][ T5825] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.525114][ T5825] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.536886][ T5825] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.562624][ T5835] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.573806][ T5835] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.584054][ T5835] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.593606][ T5835] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.613808][ T5841] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 92.663177][ T5830] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 92.681375][ T5841] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 92.701107][ T5830] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 92.719190][ T5841] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.734097][ T5841] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.743228][ T5841] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.752460][ T5841] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.811807][ T5830] netdevsim netdevsim4 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.825106][ T5830] netdevsim netdevsim4 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.834623][ T5830] netdevsim netdevsim4 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.843978][ T5830] netdevsim netdevsim4 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.881073][ T5839] veth0_macvtap: entered promiscuous mode [ 92.903393][ T13] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 92.926979][ T13] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 92.946253][ T5839] veth1_macvtap: entered promiscuous mode [ 93.029479][ T36] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.041580][ T36] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.070568][ T5839] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 93.093743][ T5839] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 93.148738][ T5839] netdevsim netdevsim2 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.163987][ T5839] netdevsim netdevsim2 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.173652][ T5839] netdevsim netdevsim2 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.182660][ T5839] netdevsim netdevsim2 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.207458][ T5825] soft_limit_in_bytes is deprecated and will be removed. Please report your usecase to linux-mm@kvack.org if you depend on this functionality. [ 93.246768][ T36] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.256759][ T36] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.367789][ T53] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.368468][ T5914] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 93.378040][ T53] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.451896][ T36] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.459977][ T36] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.530526][ T62] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.530547][ T62] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.700801][ T5092] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.708871][ T5092] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.751971][ T5836] Bluetooth: hci0: command tx timeout [ 93.831975][ T5836] Bluetooth: hci1: command tx timeout [ 93.837595][ T5829] Bluetooth: hci2: command tx timeout [ 93.915105][ T5092] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.930790][ T13] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.972567][ T13] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.992037][ T5829] Bluetooth: hci4: command tx timeout [ 93.993842][ T5092] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.997808][ T5836] Bluetooth: hci3: command tx timeout [ 94.257763][ T36] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 94.286444][ T36] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 94.837782][ T5937] netlink: 'syz.2.3': attribute type 7 has an invalid length. [ 94.861533][ T5937] netlink: 8 bytes leftover after parsing attributes in process `syz.2.3'. [ 95.843063][ T5963] syzkaller1: entered promiscuous mode [ 95.858149][ T5963] syzkaller1: entered allmulticast mode [ 97.458766][ T6008] UDPLite: UDP-Lite is deprecated and scheduled to be removed in 2025, please contact the netdev mailing list [ 98.496678][ T6040] pim6reg: entered allmulticast mode [ 98.507704][ T6040] pim6reg: left allmulticast mode [ 98.650507][ T6043] Zero length message leads to an empty skb [ 98.967199][ T6052] sch_tbf: burst 3298 is lower than device lo mtu (65550) ! [ 99.113285][ T6056] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 99.362260][ T6063] netlink: 16402 bytes leftover after parsing attributes in process `syz.2.61'. [ 99.380552][ T6066] netlink: 8 bytes leftover after parsing attributes in process `syz.0.62'. [ 99.413051][ T6066] openvswitch: netlink: Flow key attr not present in new flow. [ 99.486421][ T6070] smc: net device bond0 applied user defined pnetid SYZ2 [ 99.514756][ T6070] smc: net device bond0 erased user defined pnetid SYZ2 [ 99.812883][ T6081] netlink: 4 bytes leftover after parsing attributes in process `syz.2.70'. [ 99.834319][ T6081] ipvlan2: entered promiscuous mode [ 100.128746][ T6091] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 100.341615][ T6097] netlink: 15 bytes leftover after parsing attributes in process `syz.2.78'. [ 100.666626][ T6109] netlink: 16402 bytes leftover after parsing attributes in process `syz.1.82'. [ 100.688816][ T6108] netlink: 'syz.3.83': attribute type 10 has an invalid length. [ 100.748821][ T6108] team0: Cannot enslave team device to itself [ 100.794988][ T6105] netlink: 16402 bytes leftover after parsing attributes in process `syz.1.82'. [ 101.135804][ T6119] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 101.366324][ T6127] netlink: 8 bytes leftover after parsing attributes in process `syz.4.91'. [ 101.846082][ T6150] netlink: 'syz.4.99': attribute type 1 has an invalid length. [ 102.037394][ T6155] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 102.473380][ T6169] syz.0.105 (6169) used greatest stack depth: 20296 bytes left [ 102.935318][ T6190] syz.4.111 uses obsolete (PF_INET,SOCK_PACKET) [ 102.948555][ T6170] syzkaller0: entered promiscuous mode [ 103.040737][ T6170] syzkaller0: entered allmulticast mode [ 104.287393][ T6221] netlink: 'syz.4.123': attribute type 10 has an invalid length. [ 104.295688][ T6221] netlink: 40 bytes leftover after parsing attributes in process `syz.4.123'. [ 104.719855][ T6199] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 104.787822][ T6220] netdevsim netdevsim4 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 104.943779][ T6221] team0: Failed to send port change of device geneve0 via netlink (err -105) [ 104.992653][ T6221] team0: Failed to send options change via netlink (err -105) [ 105.000281][ T6221] team0: Port device geneve0 added [ 105.197442][ T6220] netdevsim netdevsim4 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 105.232641][ T6231] netlink: 'syz.0.128': attribute type 7 has an invalid length. [ 105.250189][ T6231] netlink: 8 bytes leftover after parsing attributes in process `syz.0.128'. [ 105.344625][ T6220] netdevsim netdevsim4 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 105.609884][ T6220] netdevsim netdevsim4 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 105.617271][ T6245] netlink: 8 bytes leftover after parsing attributes in process `syz.3.134'. [ 105.698493][ T6225] netdevsim netdevsim1: Direct firmware load for ./file0 failed with error -2 [ 105.727561][ T6225] netdevsim netdevsim1: Falling back to sysfs fallback for: ./file0 [ 105.747912][ T6247] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 105.858082][ T6220] netdevsim netdevsim4 eth0: set [1, 0] type 2 family 0 port 6081 - 0 [ 105.914881][ T6220] netdevsim netdevsim4 eth1: set [1, 0] type 2 family 0 port 6081 - 0 [ 105.981547][ T6220] netdevsim netdevsim4 eth2: set [1, 0] type 2 family 0 port 6081 - 0 [ 106.026188][ T6220] netdevsim netdevsim4 eth3: set [1, 0] type 2 family 0 port 6081 - 0 [ 106.432843][ T6270] netlink: 'syz.0.143': attribute type 7 has an invalid length. [ 106.440719][ T6270] netlink: 8 bytes leftover after parsing attributes in process `syz.0.143'. [ 107.550079][ T6266] IPv6: Can't replace route, no match found [ 107.564080][ T6278] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 107.593962][ T6279] tipc: Started in network mode [ 107.608931][ T6279] tipc: Node identity 7f000001, cluster identity 4711 [ 107.641506][ T6279] tipc: Enabled bearer , priority 10 [ 107.814078][ T6284] pim6reg: entered allmulticast mode [ 107.848836][ T6284] pim6reg: left allmulticast mode [ 108.426127][ T6311] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 108.474701][ T6311] tipc: Enabling of bearer rejected, already enabled [ 108.755049][ T6321] netlink: 8 bytes leftover after parsing attributes in process `syz.4.166'. [ 108.765060][ T5873] tipc: Node number set to 2130706433 [ 108.801621][ T6321] IPVS: Error joining to the multicast group [ 108.930032][ T6329] netlink: 24 bytes leftover after parsing attributes in process `syz.0.170'. [ 109.085807][ T6329] netlink: 4 bytes leftover after parsing attributes in process `syz.0.170'. [ 109.311766][ T6344] netlink: 'syz.2.175': attribute type 7 has an invalid length. [ 109.341086][ T6344] netlink: 8 bytes leftover after parsing attributes in process `syz.2.175'. [ 109.452481][ T6346] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 109.481096][ T6351] tipc: Started in network mode [ 109.508593][ T6351] tipc: Node identity 7f000001, cluster identity 4711 [ 109.540516][ T6351] tipc: Enabled bearer , priority 10 [ 109.637428][ T6359] IPv6: Can't replace route, no match found [ 110.048722][ T6381] netlink: 'syz.2.190': attribute type 7 has an invalid length. [ 110.060800][ T6381] netlink: 8 bytes leftover after parsing attributes in process `syz.2.190'. [ 110.094394][ T6383] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 110.106695][ T6383] tipc: Started in network mode [ 110.114596][ T6383] tipc: Node identity 7f000001, cluster identity 4711 [ 110.124272][ T6383] tipc: Enabled bearer , priority 10 [ 110.381450][ T6395] netlink: 4 bytes leftover after parsing attributes in process `syz.1.196'. [ 110.480388][ T6395] hsr_slave_0 (unregistering): left promiscuous mode [ 110.527986][ T6404] netlink: 12 bytes leftover after parsing attributes in process `syz.3.200'. [ 110.537768][ T5873] tipc: Node number set to 2130706433 [ 110.627745][ T6406] netlink: 'syz.4.202': attribute type 7 has an invalid length. [ 110.678299][ T6406] netlink: 8 bytes leftover after parsing attributes in process `syz.4.202'. [ 110.696733][ T6408] pim6reg1: entered promiscuous mode [ 110.711532][ T6408] pim6reg1: entered allmulticast mode [ 110.718519][ T6410] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 110.732406][ T6410] tipc: Enabling of bearer rejected, already enabled [ 110.851106][ T6419] Illegal XDP return value 3434155441 on prog (id 108) dev N/A, expect packet loss! [ 111.112497][ T6432] netlink: 4 bytes leftover after parsing attributes in process `syz.2.213'. [ 111.234830][ T6440] pim6reg1: entered promiscuous mode [ 111.240195][ T6440] pim6reg1: entered allmulticast mode [ 111.246398][ T5873] tipc: Node number set to 2130706433 [ 111.326975][ T6442] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 111.347321][ T6442] tipc: Started in network mode [ 111.362367][ T6442] tipc: Node identity 7f000001, cluster identity 4711 [ 111.371999][ T6442] tipc: Enabled bearer , priority 10 [ 111.617816][ T6457] netlink: 8 bytes leftover after parsing attributes in process `syz.0.223'. [ 111.739154][ T6457] syz.0.223 (6457) used greatest stack depth: 18168 bytes left [ 111.938948][ T6471] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 111.964985][ T6471] tipc: Enabling of bearer rejected, already enabled [ 112.009911][ T6474] netlink: 'syz.3.232': attribute type 7 has an invalid length. [ 112.017774][ T6474] netlink: 8 bytes leftover after parsing attributes in process `syz.3.232'. [ 112.079167][ T6476] netlink: 'syz.4.234': attribute type 13 has an invalid length. [ 112.127843][ T6476] gretap0: refused to change device tx_queue_len [ 112.142381][ T6476] A link change request failed with some changes committed already. Interface gretap0 may have been left with an inconsistent configuration, please check. [ 112.340955][ T6485] netlink: 224 bytes leftover after parsing attributes in process `syz.0.237'. [ 112.349995][ T6485] ksmbd: Unknown IPC event: 3, ignore. [ 112.458975][ T6497] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 112.501569][ T5873] tipc: Node number set to 2130706433 [ 112.514337][ T6497] tipc: Enabling of bearer rejected, already enabled [ 112.903080][ T6514] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 113.022186][ T6514] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 113.102835][ T6514] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 113.215038][ T6514] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 113.300116][ T6528] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 113.335201][ T6528] tipc: Started in network mode [ 113.344716][ T6528] tipc: Node identity 7f000001, cluster identity 4711 [ 113.375315][ T6528] tipc: Enabled bearer , priority 10 [ 113.432137][ T6531] dvmrp1: entered allmulticast mode [ 113.467805][ T6533] dvmrp1: left allmulticast mode [ 113.535994][ T6539] netlink: 12 bytes leftover after parsing attributes in process `syz.2.261'. [ 113.715703][ T6545] netlink: 24 bytes leftover after parsing attributes in process `syz.4.265'. [ 113.766801][ T6514] netdevsim netdevsim1 eth0: set [1, 0] type 2 family 0 port 6081 - 0 [ 113.858155][ T6514] netdevsim netdevsim1 eth1: set [1, 0] type 2 family 0 port 6081 - 0 [ 113.913815][ T6548] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 113.975939][ T6514] netdevsim netdevsim1 eth2: set [1, 0] type 2 family 0 port 6081 - 0 [ 114.031697][ T6548] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 114.048791][ T6560] netlink: 'syz.2.268': attribute type 7 has an invalid length. [ 114.087233][ T6514] netdevsim netdevsim1 eth3: set [1, 0] type 2 family 0 port 6081 - 0 [ 114.095844][ T6560] netlink: 8 bytes leftover after parsing attributes in process `syz.2.268'. [ 114.213204][ T6548] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 114.253175][ T6564] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 114.300079][ T6569] tipc: Enabling of bearer rejected, already enabled [ 114.347775][ T6548] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 114.358587][ T6567] netlink: 12 bytes leftover after parsing attributes in process `syz.1.273'. [ 114.370812][ T5873] tipc: Node number set to 2130706433 [ 114.381427][ T6571] netlink: 8 bytes leftover after parsing attributes in process `syz.2.274'. [ 114.433940][ T6571] vlan2: entered allmulticast mode [ 114.439268][ T6571] dummy0: entered allmulticast mode [ 114.614839][ T6548] netdevsim netdevsim3 eth0: set [1, 0] type 2 family 0 port 6081 - 0 [ 114.672361][ T6548] netdevsim netdevsim3 eth1: set [1, 0] type 2 family 0 port 6081 - 0 [ 114.736932][ T6548] netdevsim netdevsim3 eth2: set [1, 0] type 2 family 0 port 6081 - 0 [ 114.787620][ T6548] netdevsim netdevsim3 eth3: set [1, 0] type 2 family 0 port 6081 - 0 [ 114.935941][ T6596] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 114.957412][ T6596] tipc: Enabling of bearer rejected, already enabled [ 115.570387][ T6625] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 115.982475][ T6639] [ 115.985048][ T6639] ============================= [ 115.989963][ T6639] WARNING: suspicious RCU usage [ 115.995238][ T6639] 6.15.0-rc6-syzkaller-00207-g3fab2d2d901a #0 Not tainted [ 116.002566][ T6639] ----------------------------- [ 116.007457][ T6639] kernel/events/callchain.c:163 suspicious rcu_dereference_check() usage! [ 116.016085][ T6639] [ 116.016085][ T6639] other info that might help us debug this: [ 116.016085][ T6639] [ 116.028149][ T6639] [ 116.028149][ T6639] rcu_scheduler_active = 2, debug_locks = 1 [ 116.037599][ T6639] 1 lock held by syz.0.307/6639: [ 116.042836][ T6639] #0: ffffffff8df3dec0 (rcu_read_lock_trace){....}-{0:0}, at: rcu_read_lock_trace+0x38/0x80 [ 116.053297][ T6639] [ 116.053297][ T6639] stack backtrace: [ 116.059266][ T6639] CPU: 1 UID: 0 PID: 6639 Comm: syz.0.307 Not tainted 6.15.0-rc6-syzkaller-00207-g3fab2d2d901a #0 PREEMPT(full) [ 116.059296][ T6639] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 116.059314][ T6639] Call Trace: [ 116.059331][ T6639] [ 116.059342][ T6639] dump_stack_lvl+0x189/0x250 [ 116.059383][ T6639] ? __pfx_dump_stack_lvl+0x10/0x10 [ 116.059414][ T6639] ? __pfx__printk+0x10/0x10 [ 116.059452][ T6639] lockdep_rcu_suspicious+0x140/0x1d0 [ 116.059492][ T6639] get_callchain_entry+0x2b6/0x3c0 [ 116.059530][ T6639] get_perf_callchain+0xa1/0x6b0 [ 116.059570][ T6639] ? __pfx_get_perf_callchain+0x10/0x10 [ 116.059608][ T6639] ? schedule+0x16f/0x360 [ 116.059638][ T6639] __bpf_get_stack+0x3fc/0xa60 [ 116.059677][ T6639] ? __pfx___bpf_get_stack+0x10/0x10 [ 116.059709][ T6639] ? __lock_acquire+0xaac/0xd20 [ 116.059745][ T6639] bpf_get_stack+0x33/0x50 [ 116.059772][ T6639] ? bpf_prog_d43750871481577d+0x46/0x4e [ 116.059798][ T6639] bpf_get_stack_raw_tp+0x195/0x220 [ 116.059827][ T6639] bpf_prog_d43750871481577d+0x46/0x4e [ 116.059848][ T6639] bpf_prog_run_pin_on_cpu+0x67/0x150 [ 116.059880][ T6639] bpf_prog_test_run_syscall+0x312/0x4b0 [ 116.059912][ T6639] ? __pfx_bpf_prog_test_run_syscall+0x10/0x10 [ 116.059937][ T6639] ? __fget_files+0x2a/0x420 [ 116.059973][ T6639] ? __pfx_bpf_prog_test_run_syscall+0x10/0x10 [ 116.060002][ T6639] bpf_prog_test_run+0x2ac/0x340 [ 116.060036][ T6639] __sys_bpf+0x4a4/0x860 [ 116.060075][ T6639] ? __pfx___sys_bpf+0x10/0x10 [ 116.060121][ T6639] ? __pfx___se_sys_futex+0x10/0x10 [ 116.060156][ T6639] __x64_sys_bpf+0x7c/0x90 [ 116.060182][ T6639] do_syscall_64+0xf6/0x210 [ 116.060212][ T6639] ? clear_bhb_loop+0x60/0xb0 [ 116.060238][ T6639] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 116.060259][ T6639] RIP: 0033:0x7fd272b8e969 [ 116.060278][ T6639] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 116.060296][ T6639] RSP: 002b:00007fd273a4a038 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 [ 116.060317][ T6639] RAX: ffffffffffffffda RBX: 00007fd272db5fa0 RCX: 00007fd272b8e969 [ 116.060332][ T6639] RDX: 000000000000000c RSI: 00002000000004c0 RDI: 000000000000000a [ 116.060345][ T6639] RBP: 00007fd272c10ab1 R08: 0000000000000000 R09: 0000000000000000 [ 116.060358][ T6639] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 116.060370][ T6639] R13: 0000000000000000 R14: 00007fd272db5fa0 R15: 00007ffd6fc3b478 [ 116.060403][ T6639]