last executing test programs: 3m5.796042455s ago: executing program 4 (id=1855): r0 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000)='./cgroup.cpu/syz1\x00', 0x200002, 0x0) r1 = openat$cgroup_ro(r0, &(0x7f0000000040)='cgroup.controllers\x00', 0x0, 0x0) socket$nl_netfilter(0x10, 0x3, 0xc) r2 = socket$inet_sctp(0x2, 0x1, 0x84) ioctl$DRM_IOCTL_MODE_CREATE_DUMB(r1, 0xc02064b2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r3 = getpid() sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) openat$vim2m(0xffffffffffffff9c, 0x0, 0x2, 0x0) r6 = bpf$PROG_LOAD(0x5, &(0x7f0000000280)={0x3, 0x5, &(0x7f00000008c0)=ANY=[@ANYBLOB="180000000000000000000000000000008500000061000000850000000e00000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x41000, 0x1, '\x00', 0x0, @sched_cls, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4, @void, @value}, 0x94) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000180)={r6, 0x18000000000002a0, 0xe, 0x0, &(0x7f0000000500)="b90a00000044268cb89e14f086dd", 0x0, 0x9, 0x60000000, 0x0, 0x0, 0x0, 0x0}, 0x50) getsockopt$inet_sctp_SCTP_MAX_BURST(r2, 0x84, 0xc, &(0x7f0000000240)=@assoc_value={0x0}, &(0x7f0000000080)=0x8) r8 = openat$rdma_cm(0xffffffffffffff9c, &(0x7f0000000540), 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r8, &(0x7f0000000480)={0x0, 0x18, 0xfa00, {0x3, &(0x7f0000000f00), 0x13f}}, 0x20) r9 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$nl80211(&(0x7f0000000040), r9) ioctl$sock_SIOCGIFINDEX_80211(r9, 0x8933, &(0x7f0000000200)={'wlan1\x00'}) sendmsg$NL80211_CMD_TRIGGER_SCAN(r9, 0x0, 0x0) getsockopt$inet_sctp6_SCTP_CONTEXT(r1, 0x84, 0x11, &(0x7f00000000c0)={r7, 0x8326}, &(0x7f0000000100)=0x8) setsockopt$WPAN_SECURITY(r1, 0x0, 0x1, &(0x7f0000000180)=0x2, 0x4) r10 = socket$inet6(0xa, 0x2, 0x0) setsockopt$sock_int(r10, 0x1, 0x3c, &(0x7f0000000240)=0x9, 0x4) 3m4.298654684s ago: executing program 4 (id=1857): r0 = socket$nl_route(0x10, 0x3, 0x0) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r0, 0x8933, &(0x7f0000000200)={'batadv_slave_0\x00', 0x0}) ioctl$sock_SIOCGIFINDEX(r0, 0x8933, &(0x7f0000000180)={'hsr0\x00', 0x0}) sendmsg$nl_route(r0, &(0x7f0000000080)={0x0, 0x0, &(0x7f00000002c0)={&(0x7f0000000000)=ANY=[@ANYBLOB="680000001000030500000000fcdbdf2500000000", @ANYRES32=0x0, @ANYBLOB="00000000008000004800128008000100687372003c00d780060005000180000008000100", @ANYRES32=r2, @ANYBLOB="0500060001000000050007000000000005000300df00000008000200", @ANYRES32=r0, @ANYRES64=r1, @ANYRES32=r1], 0x68}}, 0x0) 3m3.709072582s ago: executing program 4 (id=1860): r0 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000000)='./binderfs/binder0\x00', 0x802, 0x0) mmap$binder(&(0x7f0000ffd000/0x3000)=nil, 0x3000, 0x1, 0x11, r0, 0x0) madvise(&(0x7f0000c00000/0x400000)=nil, 0x400000, 0xe) r1 = fsmount(0xffffffffffffffff, 0x1, 0x3) r2 = socket$can_raw(0x1d, 0x3, 0x1) setsockopt$CAN_RAW_FD_FRAMES(r2, 0x65, 0x5, 0x0, 0x0) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18020000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb703000008000000b703000000000020850000007300000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000040)={&(0x7f0000000080)='sched_switch\x00', r3}, 0x10) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x804}, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r4 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r5, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r6, &(0x7f0000000000), 0x400000000000041, 0x0) sched_setaffinity(r4, 0x8, &(0x7f0000000240)=0x2) recvmmsg(r5, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r7 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000900)=ANY=[@ANYBLOB="1b00000000000000000000000000040000000000", @ANYRES32=0x0, @ANYBLOB="0100"/20, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="000000000000000000000000ffffffdf0000000000000000000000003c5131c243bcb89ce602fe9667544bbf789e8e0b53e13338da4264b7b3a9c94a240276def7d2a0a282e026fc34b269ae1a72fb77ed65dddde553ea08bce2c63b8221ec6d47680a55460b749d09006b09f1eefe69f9275bc10604ea31951279d921e3c3"], 0x50) bpf$PROG_LOAD(0x5, &(0x7f0000002c40)={0x7, 0x17, &(0x7f0000000100)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r7, @ANYBLOB="00000000000000000000850031bfbedfd92423e5770347b840000008000000bc09080000000000b60a0100000000000f000000000000001801000020756c2500000000002020207b9af8ff000000002d9100000000000037010000f8ffffffb702000008000000b70300000000000015000000060000003f930000000000008500000076000000b7000000000000009500000000000000"], &(0x7f0000000080)='syzkaller\x00', 0x3, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) socket$kcm(0x2, 0x2, 0x73) socket$inet6_udp(0xa, 0x2, 0x0) sendmsg$can_raw(r2, &(0x7f0000000000)={&(0x7f0000000580), 0xcaf36ef73a8657ed, &(0x7f0000000280)={&(0x7f0000000880)=@canfd={{0x2, 0x0, 0x1, 0x1}, 0x1, 0x2, 0x0, 0x0, "cf38754f0ab1ccb3c81eaf46d625305c648951243e2eb7e9937a6d036cb38730281493579ce68208c6c5c4271fd8087c73b46aa97e3ef66f5526ed8ab41d787e"}, 0xfffffffffffffed2}, 0x2, 0x0, 0x0, 0x4024195}, 0x2400c080) r8 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$TIOCSETD(r8, 0x5423, &(0x7f0000000040)=0x1) ioctl$sock_ipv6_tunnel_SIOCCHGTUNNEL(r8, 0x89f3, 0x0) sendmsg$xdp(r1, &(0x7f0000000840)={&(0x7f0000000180)={0x2c, 0x4, 0x0, 0xac}, 0x10, &(0x7f00000007c0)=[{&(0x7f00000001c0)="31bf2eb202a1ef53f886bb33b63210fdcee9b175cadcf2e13532ba76a90bedf1bebda9fbffd7f970539119ee3480d9dcaa666804a1f8f172cc87071348", 0x3d}, {&(0x7f00000002c0)="8a16db0a99b741f9f343e9f0dc7672f1c18f49527edee9b64b00927b6ba64d5a096cc8d822135e51a8dd2db2026ac97d037153abcaef1bba3d7c2d844676731d7b915f73c876a4db13fd56c7f53d834430e24e95355ebc1ec197726c26efbc0691a60628546ec07fed631fa441f3a83f994f0b5f910e2f34929f0b9135a4954c3c276941d7539e641a8477c567b61ef81eb42887edda582581f4a1636d0bb7d8f521703299ea5751585de8939f968e09dad66a17f4e9b0f3ac22f1654b7d", 0xbe}, {&(0x7f0000000380)="c4d18a5235acf8461e3f4bffcc35097ebf2f78f6b064430eb44523c4c5931d2d724de774623601dc5847c817a0d7766a942dc5b00bce5d57fd20fb421cc1329679068366e1b7dbd7ba6fa25f6843605467bbb49ff412add12891d791287ffa48cbc2783c729c8bb38b9324a47b2aa5128232f8b99ee6b3ede3b6aa05c329e9e536329662ad3ec189850da5e0a8bee7fa282958d7eb83eb75a7f8f9", 0x9b}, {&(0x7f0000000440)="165990937f5f3247cdc1ab350fe62ea5e4cf98663d2e7558b296a96cbff7c4ec548c816679fda3c1522300d6c2443c75c923916cb9a8cf1bc5005358d4ae63f2b88bb237657c5af980", 0x49}, {&(0x7f0000000500)="273c474f89331ec92fdd49bd69e7515ce7e8358139dd1ad013b766f4cf517b832794bcd18222c928f3caa5751f831abe568e480a348d5c470aa1264de4f9418c552f53d2be6e013c30916ce962bc7e31cfb20e3a4407d1ea2adfa0d34f4d3bd48e531f0a49909855f8366649fed633c21019e4762e5f97d56f8a4854a5a2e3125d49e892cd5326a0b53488ae51987188518dc60190c35b6f2ac042efc5e02c3169185efece50851d38b859f15b830435304dab2ec3561a4d1131a8239ada486cc43979bb187d290cfa8597ac9758d9d013a440", 0xd3}, {&(0x7f0000000600)="74220455dfad45003f1a0de81ea713d9d04bbf712990e261e870837378474737188c6213ecbe9b7ffd59d2c458a5216f0f76d68cf3c8fc76b262bd7f8e9fad72c6be5fbee72393d3fe454598dbe2a42b42664df17502b9a1dccdb8d38c03f0c16ec9f428d424", 0x66}, {&(0x7f0000000700)="fad49b1e6178cb1bdfd99b3183912a263741b4e4466d613353a92826f8778edea7dae884dcf565c5f79f531a84dbdc20b33821d6bc4f31a4a44801b42e59a79e0b063a664d8d103b9f696745fd9607456c57d6ed31466be7f0a96b2fab793cbecf3b41a8ea9c1587353b4d214f1b90409f39789b9f0bc6ef55cc7771d2e47ab3cc456463", 0x84}], 0x7, 0x0, 0x0, 0x200000c0}, 0x0) ioctl$VIDIOC_S_INPUT(0xffffffffffffffff, 0xc0045627, &(0x7f0000000100)=0x3) 2m57.909576538s ago: executing program 4 (id=1874): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x0, 0x0) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = io_uring_setup(0x51d0, &(0x7f0000000140)={0x0, 0x3957, 0x40, 0x2000002, 0x402d7}) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000140)={0x1e, 0x4, &(0x7f0000000300)=ANY=[@ANYRESOCT=r3], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x24, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffeec, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) io_uring_register$IORING_REGISTER_BUFFERS2(r3, 0xf, &(0x7f0000002700)={0x119f, 0x0, 0x0, &(0x7f0000000200)=[{&(0x7f0000000480)=""/264, 0xf9}, {&(0x7f00000015c0)=""/4096, 0xd8da7}, {&(0x7f0000002a00)=""/88, 0x8}], 0x0}, 0x20) socket$nl_route(0x10, 0x3, 0x0) socket$inet_udp(0x2, 0x2, 0x0) r4 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x7, &(0x7f0000000240)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32, @ANYBLOB="0000000000000000b702000002000000850000008600000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f00000006c0)='sched_switch\x00', r4}, 0x18) r5 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_mreq(r5, 0x29, 0x1b, &(0x7f0000000200)={@dev}, 0x14) r6 = syz_open_procfs(0x0, &(0x7f0000000080)='net/anycast6\x00') preadv(r6, &(0x7f0000000040)=[{&(0x7f0000000380)=""/80, 0x50}], 0x1, 0x3, 0x3) sendmsg$IEEE802154_LLSEC_SETPARAMS(0xffffffffffffffff, &(0x7f0000000b00)={0x0, 0x0, 0x0}, 0x2000c094) 2m56.846999579s ago: executing program 4 (id=1881): r0 = socket(0x2, 0x2, 0x1) (async) r1 = openat$vcsa(0xffffffffffffff9c, &(0x7f0000000280), 0x10040, 0x0) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN(0xffffffffffffffff, 0x3ba0, &(0x7f0000000300)={0x48, 0x2, 0x0, 0x0, 0x0}) (async) ioctl$IOMMU_VFIO_IOAS$GET(0xffffffffffffffff, 0x3b88, &(0x7f0000000380)={0xc, 0x0}) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN_REPLACE(r1, 0x3ba0, &(0x7f00000003c0)={0x48, 0xa, r2, 0x0, r3}) (async) ioctl$SNDCTL_DSP_GETTRIGGER(0xffffffffffffffff, 0x80045010, 0x0) (async) mkdirat(0xffffffffffffff9c, &(0x7f0000000080)='./file1\x00', 0x0) (async) mount$fuse(0x0, 0x0, 0x0, 0xfc5cd7921c2c19c4, &(0x7f0000000400)=ANY=[@ANYBLOB='fd=', @ANYRESHEX=0x0]) (async) mount(0x0, &(0x7f0000000380)='./file1\x00', &(0x7f0000000040)='autofs\x00', 0x0, &(0x7f0000000400)) (async) chdir(&(0x7f0000000080)='./file1\x00') (async) r4 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) (async) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) chdir(&(0x7f00000003c0)='./bus\x00') (async) setpgid(r4, 0x0) (async) r5 = getpid() sched_setscheduler(r5, 0x1, &(0x7f0000000100)=0x5) (async) setpgid(r5, r4) (async) mount$afs(0x0, &(0x7f00000000c0)='./file1\x00', 0x0, 0x20, 0x0) (async) socket$inet6(0xa, 0x5, 0x0) setsockopt$inet6_int(r1, 0x29, 0xcf, &(0x7f0000000180)=0xffffffff, 0x4) (async) bind$unix(r0, &(0x7f0000000100)=@file={0x1, './file0\x00'}, 0x6e) r6 = openat$ptp0(0xffffffffffffff9c, &(0x7f0000000040), 0x60442, 0x0) sendmsg$NL802154_CMD_SET_SEC_PARAMS(0xffffffffffffffff, &(0x7f00000001c0)={&(0x7f0000000000)={0x10, 0x0, 0x0, 0x40000}, 0xc, &(0x7f00000000c0)={&(0x7f0000000080)={0x1c, 0x0, 0x400, 0x70bd2d, 0x25dfdbfe, {}, [@NL802154_ATTR_SEC_FRAME_COUNTER={0x8}]}, 0x1c}, 0x1, 0x0, 0x0, 0x600400c0}, 0x4000811) (async) r7 = dup(r6) ioctl$PTP_PEROUT_REQUEST2(r7, 0x40383d0c, &(0x7f00000002c0)={{0x4, 0xe}, {0xffffffffffffffff, 0xfd2}, 0x8, 0x2}) (async) setsockopt$SO_BINDTODEVICE(r7, 0x1, 0x19, &(0x7f0000000440)='team0\x00', 0x10) (async) r8 = socket$nl_audit(0x10, 0x3, 0x9) getpeername$netlink(r8, &(0x7f0000000480), &(0x7f00000004c0)=0xc) (async) mount_setattr(r7, &(0x7f0000000200)='./file0\x00', 0x9100, &(0x7f0000000240)={0x100001, 0x2, 0x100000, {r7}}, 0x20) socket$nl_route(0x10, 0x3, 0x0) 2m56.134776023s ago: executing program 4 (id=1886): bpf$PROG_LOAD(0x5, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8e}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0/file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000380)='/proc/stat\x00', 0x0, 0x0) preadv(r3, &(0x7f0000001240)=[{&(0x7f00000012c0)=""/90, 0x5a}], 0x1, 0xf, 0x8000) bpf$MAP_CREATE(0x0, 0x0, 0xfff8) 2m40.446791282s ago: executing program 32 (id=1886): bpf$PROG_LOAD(0x5, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8e}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0/file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000380)='/proc/stat\x00', 0x0, 0x0) preadv(r3, &(0x7f0000001240)=[{&(0x7f00000012c0)=""/90, 0x5a}], 0x1, 0xf, 0x8000) bpf$MAP_CREATE(0x0, 0x0, 0xfff8) 32.396251116s ago: executing program 3 (id=2500): r0 = socket$inet_udp(0x2, 0x2, 0x0) setsockopt$inet_MCAST_MSFILTER(r0, 0x0, 0x30, 0x0, 0x0) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000100)={0x18, 0x3, &(0x7f00000001c0)=ANY=[@ANYBLOB="18000000fdffffff0000000000000000950000000000000027a791d16d97b58209509e84d601d448a52d15575c5149572ab76d5d237ca66f8c5ae760954550b527f24c5c3b651fa87a19cea43e382b8a08329d8a51dedb028155b05c2e3feefe31997f9af137fb8dbb84a3747e79474bce45f096ddf7f7c4c0d6bb98c179"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000040)='contention_end\x00', r1}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$tipc(&(0x7f0000000480), 0xffffffffffffffff) sendmsg$TIPC_CMD_RESET_LINK_STATS(r2, &(0x7f0000000540)={0x0, 0x0, &(0x7f0000000500)={&(0x7f0000000600)=ANY=[@ANYBLOB='0\x00\x00\x00', @ANYRES16=r3, @ANYBLOB="0100000000000000000001000000007887000c41000000030014"], 0x30}}, 0x0) syz_usb_connect(0x0, 0x14, &(0x7f0000000300)=ANY=[@ANYBLOB="120986970600000000000000160f4086801001adbf000080010902120001000000000904000000a0122400"], 0x0) syz_usb_connect$hid(0x5, 0x0, 0x0, &(0x7f0000000440)={0xa, &(0x7f00000000c0)={0xa, 0x6, 0x300, 0x8, 0x7, 0x41, 0x10, 0x96}, 0x0, 0x0, 0x1, [{0x4, &(0x7f0000000280)=@lang_id={0x4, 0x3, 0xf8ff}}]}) ioctl$NBD_DISCONNECT(0xffffffffffffffff, 0xab08) r4 = socket$inet6_icmp_raw(0xa, 0x3, 0x3a) ioctl$sock_SIOCGIFINDEX_80211(r4, 0x8933, &(0x7f0000000240)={'wlan1\x00'}) r5 = syz_genetlink_get_family_id$nl80211(&(0x7f00000002c0), 0xffffffffffffffff) r6 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL80211_CMD_FRAME(r6, &(0x7f0000001280)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000580)=ANY=[@ANYRESOCT=r6, @ANYRES16=r5, @ANYBLOB="01e5c300000000fb04003b1c210008000300", @ANYRES32, @ANYBLOB="2c0433005000de295b3acba52ee4080211000001505050505050"], 0x448}}, 0x0) r7 = socket$packet(0x11, 0x2, 0x300) r8 = socket$inet6(0xa, 0x2, 0x0) ioctl$sock_SIOCETHTOOL(r8, 0x8946, &(0x7f0000000100)={'batadv0\x00', &(0x7f0000000080)=@ethtool_gstrings={0x1b, 0x1}}) ioctl$ifreq_SIOCGIFINDEX_team(r2, 0x8933, &(0x7f0000001500)) r9 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) r10 = ioctl$KVM_CREATE_VM(r9, 0xae01, 0x0) ioctl$KVM_CREATE_IRQCHIP(r10, 0xae60) r11 = ioctl$KVM_CREATE_VCPU(r10, 0xae41, 0x0) syz_kvm_setup_cpu$x86(r10, 0xffffffffffffffff, &(0x7f0000003000/0x18000)=nil, &(0x7f0000000300)=[@text64={0x40, 0x0}], 0x1, 0x43, 0x0, 0x0) ioctl$KVM_SET_REGS(r11, 0x4090ae82, &(0x7f0000000340)={[0x3ffffd, 0x3, 0x0, 0x0, 0x0, 0xfffffffffffffffb, 0x200000000, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7, 0x7, 0x100000000], 0x8080000, 0x280384}) mmap(&(0x7f0000000000/0x400000)=nil, 0x400000, 0x1, 0x10012, r11, 0x0) ioctl$KVM_RUN(r11, 0xae80, 0x0) sendmmsg$inet6(r8, &(0x7f0000002680), 0x0, 0x24000040) setsockopt$packet_tx_ring(r7, 0x107, 0x5, &(0x7f00000000c0)=@req3={0x8000, 0x6, 0x8000, 0x6}, 0x1c) mmap(&(0x7f0000000000/0x2000)=nil, 0x30000, 0x2, 0x11, r7, 0x0) 31.506382803s ago: executing program 3 (id=2503): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x0, 0x0) prlimit64(r0, 0x0, &(0x7f0000000000)={0xdf46, 0x1}, &(0x7f00000002c0)) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0e000000040000000800000005"], 0x48) bpf$MAP_CREATE(0x0, 0x0, 0x0) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x6, 0xc, &(0x7f00000001c0)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bc82000000000000a6020000f8ffffffb703000008000000b703000000000000850000003300000095"], &(0x7f0000000180)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @xdp, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000300)={r2, 0x18000000000002a0, 0xe, 0x0, &(0x7f0000000280)="b9ff03076804268c989e14f088a8", 0x0, 0x3f, 0x60000000, 0x0, 0x0, 0x0, 0x0, 0x2, 0x0, 0x21}, 0x50) acct(0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r4, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r5 = io_uring_setup(0x51d0, &(0x7f0000000140)={0x0, 0x3957, 0x40, 0x2000002, 0x402d7}) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000140)={0x1e, 0x4, &(0x7f0000000300)=ANY=[@ANYRES64=r0], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x24, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r6 = openat$mice(0xffffffffffffff9c, &(0x7f0000000040), 0x80082) poll(&(0x7f0000000080)=[{r6, 0x6002}], 0x1, 0xfffffffe) write$cgroup_type(r6, 0x0, 0x0) io_uring_register$IORING_REGISTER_BUFFERS2(r5, 0xf, &(0x7f0000002700)={0x119f, 0x0, 0x0, &(0x7f0000000200)=[{&(0x7f0000000480)=""/264, 0xf9}, {&(0x7f00000015c0)=""/4096, 0xd8da7}, {&(0x7f0000002a00)=""/88, 0x8}], 0x0}, 0x20) socket$nl_route(0x10, 0x3, 0x0) socket$inet_udp(0x2, 0x2, 0x0) r7 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x7, &(0x7f0000000240)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32, @ANYBLOB="0000000000000000b702000002000000850000008600000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f0000000400)='sched_switch\x00', r7}, 0x18) r8 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_mreq(r8, 0x29, 0x1b, &(0x7f0000000200)={@dev}, 0x14) r9 = syz_open_procfs(0x0, &(0x7f0000000080)='net/anycast6\x00') preadv(r9, &(0x7f0000000040)=[{&(0x7f0000000380)=""/80, 0x50}], 0x1, 0x3, 0x3) 30.502687138s ago: executing program 3 (id=2513): sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() sched_yield() 30.13808566s ago: executing program 3 (id=2517): syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x2) syz_io_uring_setup(0x1e21, 0x0, &(0x7f0000002000)=0x0, &(0x7f0000000180)=0x0) r2 = openat$sw_sync(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) openat$sw_sync(0xffffffffffffff9c, &(0x7f0000000ac0), 0x0, 0x0) ioctl$SW_SYNC_IOC_CREATE_FENCE(r2, 0xc0285700, &(0x7f0000000200)={0x8e, "00005c02ac56f967e45706449300004ed82ff400"}) ioctl$SW_SYNC_IOC_CREATE_FENCE(r2, 0xc0285700, &(0x7f0000000f40)={0x101, "7bb9595931028deda525e19bdeffafde2500f6d15c9e31df9454310ad7c18e65", 0xffffffffffffffff}) prlimit64(0x0, 0xe, &(0x7f00000007c0)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) openat$ipvs(0xffffffffffffff9c, &(0x7f00000003c0)='/proc/sys/net/ipv4/vs/sync_retries\x00', 0x2, 0x0) r4 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r4, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) openat$rtc(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) pselect6(0x40, &(0x7f00000001c0)={0x0, 0x1, 0x3}, 0x0, &(0x7f00000002c0)={0x3ff, 0x0, 0x0, 0x4, 0x400000000, 0x4, 0x7fffffff}, 0x0, 0x0) close_range(r2, 0xffffffffffffffff, 0x0) syz_io_uring_submit(r0, r1, &(0x7f00000001c0)=@IORING_OP_READ=@pass_buffer={0x16, 0x0, 0x0, @fd_index=0x3, 0xffffffffffffffff, 0x0, 0x0, 0x22}) openat$sequencer2(0xffffffffffffff9c, &(0x7f0000000040), 0x1e4011, 0x0) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000140)={&(0x7f0000000440)=@rxrpc=@in4={0x21, 0x1, 0x2, 0x10, {0x2, 0x4e24, @loopback}}, 0x80, 0x0, 0x0, &(0x7f0000000600)=ANY=[], 0x10b8}, 0x200008c0) r5 = creat(&(0x7f0000000000)='./file0\x00', 0xecf86c37d53049cc) write$binfmt_elf32(r5, &(0x7f0000000740)=ANY=[@ANYBLOB="7f454c4604030003000000000000000002003e00000000000103000038000000000000000f000000000020000100040000000000000000000300000008000000"], 0x58) close(r5) r6 = socket$nl_route(0x10, 0x3, 0x0) r7 = socket$inet_udp(0x2, 0x2, 0x0) sendmsg$nl_route(r6, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000240)=ANY=[@ANYBLOB="400000001000010429bd70000000000000000000", @ANYRES32=0x0, @ANYBLOB="2b030000004000002000128008000100677470001400028008000100", @ANYRES32=r7, @ANYBLOB="08000200", @ANYRES32=r7, @ANYBLOB="35ec224abca6c8e0c54d4965d4dc46a50efac31a46f15029e36aed35b71a5cbfac454e51b4a33869"], 0x40}}, 0x0) execve(&(0x7f0000000400)='./file0\x00', 0x0, 0x0) mmap(&(0x7f0000ff9000/0x4000)=nil, 0x4000, 0x200000a, 0x40010, r3, 0xab233000) fcntl$getownex(r3, 0x10, &(0x7f00000000c0)) add_key(&(0x7f0000000340)='id_legacy\x00', &(0x7f0000000380)={'syz', 0x1}, 0x0, 0x0, 0x0) 30.097119282s ago: executing program 3 (id=2518): getpid() bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000380)={0x8, 0x100008b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000000)=0x7) gettid() openat$sequencer(0xffffffffffffff9c, &(0x7f0000000280), 0x0, 0x0) r0 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r0, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r1 = socket$inet6(0xa, 0x5, 0x8010000000000084) r2 = openat$cgroup_devices(0xffffffffffffffff, 0x0, 0x2, 0x0) write$cgroup_devices(r2, &(0x7f0000000140)=ANY=[@ANYBLOB], 0xa) bind$inet6(r1, &(0x7f00000000c0)={0xa, 0x4e21, 0x0, @empty}, 0x1c) connect$inet6(r1, &(0x7f0000000000)={0xa, 0x4e21, 0x0, @ipv4={'\x00', '\xff\xff', @dev={0xac, 0x14, 0x14, 0x14}}}, 0x1c) socket$unix(0x1, 0x1, 0x0) r3 = openat$vim2m(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) ioctl$vim2m_VIDIOC_REQBUFS(r3, 0xc0145608, &(0x7f0000000100)={0x3, 0x2, 0x1}) mmap(&(0x7f0000fed000/0x12000)=nil, 0x12000, 0x2, 0x11, 0xffffffffffffffff, 0x0) r4 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$BTRFS_IOC_SET_RECEIVED_SUBVOL(0xffffffffffffffff, 0xc0c89425, &(0x7f0000000740)={"8c3ef01be86258108b331b07f91efab2", 0x0, 0x0, {0x6, 0x40}, {0x3, 0x1}, 0x6, [0x3, 0x5, 0x9, 0x7, 0x7, 0x5, 0x10, 0x953, 0x1, 0x4, 0x8, 0x9000000000000000, 0x2, 0x4, 0x2, 0x5]}) sendmsg$nl_generic(r4, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000440)={&(0x7f00000007c0)=ANY=[@ANYBLOB="280300002d00090027bd70000000000004000000130317"], 0x328}}, 0x84) r5 = syz_init_net_socket$nfc_raw(0x27, 0x5, 0x0) r6 = socket$nl_netfilter(0x10, 0x3, 0xc) r7 = dup3(r5, r6, 0x80000) syz_genetlink_get_family_id$nl80211(&(0x7f0000000e40), r7) sendmsg$IPCTNL_MSG_TIMEOUT_NEW(0xffffffffffffffff, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000300)=ANY=[@ANYBLOB="3c000000000801010000000000000000010000010900010073797a310000000006000240883e000005000300010000000c00048008"], 0x3c}}, 0x40040000) sysfs$1(0x1, &(0x7f00000001c0)='sysfs\x00') r8 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="180100"/12], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000003c0)={&(0x7f0000000000)='sched_switch\x00', r8}, 0xfffffffffffffd43) 8.774199729s ago: executing program 5 (id=2591): r0 = syz_open_procfs(0x0, &(0x7f00000001c0)='net/snmp6\x00') r1 = socket$inet_icmp_raw(0x2, 0x3, 0x1) setsockopt$IPT_SO_SET_REPLACE(r1, 0x0, 0x40, &(0x7f0000000800)=@raw={'raw\x00', 0x8, 0x3, 0x3b0, 0x280, 0x1000000, 0xffffffff, 0x0, 0xffffffff, 0x318, 0xffffffff, 0xffffffff, 0x318, 0xffffffff, 0x3, 0x0, {[{{@ip={@rand_addr=0x64010101, @private=0xa010100, 0x0, 0x0, 'bond_slave_1\x00', 'geneve1\x00', {}, {}, 0x4, 0x0, 0x28}, 0x0, 0x220, 0x280, 0x0, {0x0, 0x1c8}, [@common=@inet=@hashlimit3={{0x158}, {'veth0_to_batadv\x00', {0x6, 0x0, 0x39, 0x0, 0x0, 0x80000000, 0x3, 0x3}, {0x3}}}, @common=@inet=@hashlimit1={{0x58}, {'veth0_to_batadv\x00', {0x0, 0x0, 0x8, 0x0, 0x0, 0x5, 0x23}}}]}, @common=@SET={0x60, 'SET\x00', 0x0, {{0xffffffffffffffff, [0x2, 0x0, 0x8, 0x7, 0x4, 0xd], 0x3, 0xdab9f66e79d89cfe}, {0x1, [0x0, 0x4, 0x2, 0x0, 0x5, 0x2], 0x1}}}}, {{@ip={@remote, @rand_addr=0x64010101, 0xff, 0xffffff, 'veth0_vlan\x00', 'vcan0\x00', {}, {0xff}}, 0x0, 0x70, 0x98}, @common=@unspec=@CLASSIFY={0x28, 'CLASSIFY\x00', 0x0, {0x8}}}], {{'\x00', 0x0, 0x70, 0x98}, {0x28, '\x00', 0x64}}}}, 0x410) mmap(&(0x7f0000003000/0x2000)=nil, 0x2000, 0x0, 0x31, 0xffffffffffffffff, 0xf983e000) r2 = openat$cuse(0xffffffffffffff9c, &(0x7f0000000540), 0x2, 0x0) read$FUSE(r2, &(0x7f0000000580)={0x2020, 0x0, 0x0, 0x0, 0x0}, 0x2020) write$FUSE_DIRENTPLUS(r2, &(0x7f00000029c0)={0x658, 0x0, r3, [{{0x0, 0x2, 0x8001, 0x46, 0xff, 0x2, {0x6, 0xfa9, 0xfffffffffffffff9, 0xfff, 0x2, 0x3, 0x4, 0x0, 0xed07, 0xa000, 0x8, r4, 0x0, 0x55fd, 0x80000001}}, {0x0, 0x3, 0x6, 0x5, 'vcan0\x00'}}, {{0x6, 0x0, 0x5, 0xffffffffffffffc0, 0x3, 0x200, {0x3, 0x2, 0x5, 0xffffffffffffff01, 0xf, 0x7, 0xffff, 0x2, 0xfffffe01, 0x3000, 0x2, r4, r5, 0x5, 0x4c18}}, {0x0, 0x10001, 0x8, 0xb, '%pB \x00'}}, {{0x1, 0x0, 0xffffffff, 0x7, 0xf425, 0x2, {0x6, 0x7, 0x2, 0xf, 0xffffffffffffffff, 0x1, 0x2, 0x8, 0x9461, 0xe000, 0x7, r4, r5, 0x8000, 0x1ff8000}}, {0x1, 0xd0a9, 0xa, 0x9a5e, '/dev/cuse\x00'}}, {{0x6, 0x2, 0x5f, 0x4, 0x4, 0x1, {0x0, 0x7, 0x1000, 0xfffffffffffffff9, 0x8001, 0x0, 0x800, 0x80000000, 0xb83, 0xc000, 0x80000001, r4, r5, 0x28a, 0x7}}, {0x5, 0x4, 0x1, 0xa, '\x00'}}, {{0x5, 0x2, 0x8, 0x8001, 0xd, 0x6, {0x6, 0x184, 0x587, 0x8000, 0x8, 0x0, 0xffffffff, 0x6, 0x10, 0x2000, 0xb, r4, r5, 0x80000000, 0xb}}, {0x2, 0x8, 0x1, 0xa2, '('}}, {{0x2, 0x1, 0x9, 0x6, 0xfffffff8, 0x7fff, {0x5, 0x1, 0xc, 0xa, 0x6, 0x6, 0x3, 0x6, 0x7, 0x8000, 0x8, r4, r5, 0x5, 0x3}}, {0x3, 0x2, 0x1, 0x9, ','}}, {{0x6, 0x0, 0x5dd5, 0x3, 0x5, 0x81, {0x3, 0x100000001, 0x5, 0x2, 0x1, 0x2, 0x6, 0x69504f9e, 0x80000000, 0x2000, 0x6, r4, r5, 0x6, 0x5}}, {0x0, 0xfffffffffffffffc, 0x6, 0x4, '&\'.:&('}}, {{0x2, 0x1, 0x401, 0x5, 0x80, 0x4, {0x5, 0x404, 0x5, 0x4, 0x801, 0xff, 0x6, 0xd7a2, 0x7fff, 0x4000, 0x7f, 0x0, 0x0, 0x7fffffff, 0xc6}}, {0x4, 0x100000001, 0x4, 0xf4f, '\\--,'}}, {{0x5, 0x1, 0x7ff, 0x4, 0x3d, 0x7f, {0x6, 0x7, 0x5, 0x3, 0x59ec, 0x5, 0x4, 0xf6c, 0x80000000, 0x4000, 0x80, r4, r5, 0x6, 0x6a4a}}, {0x2, 0x54f, 0x8, 0x3ff, 'nl80211\x00'}}, {{0x5, 0x2, 0x2, 0x49f, 0x7fff, 0x65, {0x5, 0xbe4a, 0x707, 0x4b3, 0x0, 0x3, 0x10001, 0xfffff800, 0x6, 0x4000, 0x4b4cca3e, 0xee00, r5, 0x1, 0x62e2}}, {0x2, 0x101, 0x1, 0x3, '\xad'}}]}, 0x658) preadv(r0, &(0x7f00000005c0)=[{&(0x7f00000024c0)=""/4096, 0x1000}], 0x1, 0xffffffff, 0x2) openat$binderfs(0xffffffffffffff9c, &(0x7f00000000c0)='./binderfs/binder0\x00', 0x0, 0x0) r6 = openat$dsp(0xffffffffffffff9c, &(0x7f0000000000), 0xa0842, 0x0) write$dsp(r6, 0x0, 0xffda) r7 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPCTNL_MSG_CT_NEW(r7, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000100)=ANY=[@ANYBLOB="640000000001010400000000141a000002000000240001801400018008000100e000000108000200e00000010c00028005000100000000002400028014000180080001000000000008000200ac1e00010c00028005000100000000000800074000000001"], 0x64}}, 0x0) r8 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPCTNL_MSG_CT_NEW(r8, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000080)=ANY=[@ANYBLOB="5c00000000010104000000000000000002000000240002801400018008000100e000000108000200e00000010c0002800500010000000000080008400000000014000580"], 0x5c}}, 0x0) 7.992441002s ago: executing program 3 (id=2519): bpf$BPF_BTF_LOAD(0x12, &(0x7f00000000c0)={&(0x7f0000000440)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x7c, 0x7c, 0x2, [@var, @func_proto={0x0, 0x6, 0x0, 0xd, 0x0, [{}, {}, {}, {}, {}, {}]}, @func={0x0, 0x0, 0x0, 0xc, 0x20}, @volatile, @volatile, @volatile={0x0, 0x0, 0x0, 0x9, 0x1}]}}, 0x0, 0x96, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x28) (async) r0 = bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000140)={&(0x7f0000000000)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0xc, 0xc, 0x2, [@struct]}}, 0x0, 0x26, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x20) (async) r1 = openat$vim2m(0xffffffffffffff9c, &(0x7f0000000040), 0x2, 0x0) (async) pipe2$watch_queue(&(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}, 0x80) ioctl$IOC_WATCH_QUEUE_SET_FILTER(r2, 0x5761, &(0x7f0000000040)=ANY=[@ANYBLOB="01"]) (async) ioctl$vim2m_VIDIOC_DQBUF(r1, 0xc0585611, &(0x7f0000000180)=@fd={0x2, 0x3, 0x4, 0x1000, 0x6875, {0x77359400}, {0x3, 0xe, 0x6, 0x2, 0xc, 0x5, "2e3596a2"}, 0xb, 0x4, {}, 0x7fffffff, 0x0, r2}) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000500)={0x6, 0x3, &(0x7f0000000200)=@framed, &(0x7f0000000280)='GPL\x00', 0x5, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, r0, 0x8, 0x0, 0x0, 0x10, &(0x7f00000004c0), 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 5.737266774s ago: executing program 5 (id=2606): syz_open_dev$loop(&(0x7f0000000100), 0xf01c, 0x0) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000140)='cgroup.stat\x00', 0x275a, 0x0) io_setup(0x3ff, &(0x7f0000000000)) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000300)={0x11, 0xc, &(0x7f0000000080)=ANY=[@ANYBLOB, @ANYRES32, @ANYBLOB="000000000087fb00b70800000000396f7b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000002400000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x34, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$ENABLE_STATS(0x20, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000680)={&(0x7f0000000000)='tlb_flush\x00', r0}, 0x18) syz_open_dev$sg(0x0, 0x0, 0x200) syz_io_uring_setup(0x2b9, 0x0, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x9}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f0000000240), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) syz_init_net_socket$ax25(0x3, 0x3, 0x8) sched_setattr(0x0, &(0x7f00000003c0)={0x38, 0x0, 0x40, 0x7, 0x81, 0x200, 0x8000000000000000, 0x7291, 0x9, 0xffffff00}, 0x0) r2 = syz_open_dev$dri(&(0x7f0000000080), 0x1, 0x1) ioctl$DRM_IOCTL_SET_CLIENT_CAP(r2, 0x4010640d, &(0x7f0000000000)={0x3, 0x2}) ioctl$DRM_IOCTL_MODE_GETPLANERESOURCES(r2, 0xc01064b5, &(0x7f0000000140)={&(0x7f0000000100)=[0x0], 0x1}) ioctl$DRM_IOCTL_MODE_GETPLANE(r2, 0xc02064b6, &(0x7f00000001c0)={r3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) ioctl$DRM_IOCTL_MODE_GET_LEASE(r2, 0xc01064c8, &(0x7f0000000280)={0x1, 0x0, &(0x7f0000000200)=[0x0]}) ioctl$DRM_IOCTL_MODE_OBJ_GETPROPERTIES(r2, 0xc02064b9, 0x0) io_setup(0x5, &(0x7f0000000640)=0x0) r5 = syz_open_procfs(0x0, &(0x7f00000006c0)='net/nfsfs\x00') io_getevents(r4, 0x1, 0x1, &(0x7f00000000c0)=[{}], 0x0) io_submit(r4, 0x1, &(0x7f0000000540)=[&(0x7f0000000500)={0x0, 0x0, 0x0, 0x0, 0x6020, r5, 0x0, 0x0, 0x3, 0x0, 0x2, r5}]) r6 = socket$inet_tcp(0x2, 0x1, 0x0) r7 = bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x1, 0x5, &(0x7f0000000c00)=ANY=[@ANYBLOB="bf16000000000000b70700000100000048700000e4ff0000bc700000000000009500faff000000008aa1210b29017b83c8e96e6405f798585fb5030b3388b0409a814343f1ae341b74efa745a12f5c0685e5261482e31e0cacc902c97e6145ef48004d26342c94f56a39359ba56724e4535d80ffbd6848d53382c26211a2b975eb4a9d08501c000c00000000000097e50f118c4a3b05489d1d1245cb774879b0871dd61703eefe87ff070000000000008cca1a363b2b28add613658171122dc01e0a77d7c44b009fdac91fc827f5797532750d4d4639f11089feb3f25b4695c6dac2cabfa04e2c16fa741b0665bb33be6f0e742213d0bf5528a601b5934b867f39f7d776ac00a434949b4455b7c6c678de4d9740d8dff6169c664b55ce550fb4e686ae169d9f7abbeb08e02799374ae0081858bdf144d8c7fb67dcec5e43a0e8099e543116b1b7d144b5613845cca4388344d82de45f0c1b7d041db040fd777791232d5db32d14bc1c3d000000000000000000000016a1049b6f094e504c28d7daa2f61b2a7c14d2343b4308b36e6b141371c958406e212b3accb45f87aef8bd5e2181fd7826b9e5cb2f6a63f113491239dca17e4fb33e670daf1cd7a99015ae9e1ca32b4e64dc38b55d525bd10971b0898be9d6e6154dfc99b20622b604b87ba03524c2fed51056d672b1b966657de5c86ab09195fba55af17663fecf1b5c5a76cf07615c7ee54c361449e275371a8c4243b9060ecdeecfb1603b061a8a62159830049061800953f7d00c43c95068c62c2ca1ad7fea9de97216dbc9c8e36a5607608e77d1d7d72b78b4f1eab8e40000000000000000adc90eb850f42f44e4b48c9cc39412c0ce6c9f4b95936ec36efc8dfbc54eb44affe1cd0f14d124df0c29c51b5628646b8155a1859358aa08f71fd2d9b2c4288a0d8870e8767173c65476e1a4f000c580f61d73f5be35ca1aa1235cf309650cdf8c6cd950c477890089be400b26dedec1199479b1b5adfaf2b6e05b7f90c9098ed4accddabd802ac5dc1b436e"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) setsockopt$IPT_SO_SET_REPLACE(r6, 0x4000000000000, 0x40, &(0x7f0000000180)=@raw={'raw\x00', 0xc01, 0x3, 0x460, 0x0, 0x5002004a, 0x6, 0x2c8, 0x3, 0x3c8, 0x3c8, 0x3c8, 0x3c8, 0x3c8, 0x7fffffe, 0x0, {[{{@ip={@dev, @broadcast=0xfeffffff, 0x0, 0x0, 'sit0\x00', 'bridge0\x00'}, 0x0, 0x2a0, 0x2c8, 0x0, {0x0, 0x3fa}, [@common=@unspec=@bpf1={{0x230}, @fd={0x2, 0x0, r7}}]}, @common=@unspec=@NFQUEUE3={0x28, 'NFQUEUE\x00', 0x3, {0xe, 0x100, 0x1}}}, {{@uncond, 0x0, 0xa0, 0x100, 0x0, {}, [@common=@inet=@udp={{0x30}}]}, @common=@CLUSTERIP={0x60, 'CLUSTERIP\x00', 0x0, {0x0, @link_local, 0x0, 0x0, [0x0, 0x0, 0x21, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xe13], 0x0, 0x0, 0xfffffffffffffffc}}}], {{'\x00', 0x0, 0x70, 0x98}, {0x28, '\x00', 0x4}}}}, 0x4c0) ioctl$sock_SIOCGPGRP(r5, 0x8904, &(0x7f0000000400)) 5.699326898s ago: executing program 0 (id=2607): r0 = socket$inet6_tcp(0xa, 0x1, 0x0) sendmmsg$unix(0xffffffffffffffff, 0x0, 0x0, 0x0) mount(0x0, 0x0, 0x0, 0x8000, 0x0) setsockopt$IP6T_SO_SET_REPLACE(r0, 0x29, 0x40, &(0x7f0000000000)=@raw={'raw\x00', 0x3c1, 0x3, 0x1468, 0x1170, 0x1170, 0x1398, 0x1170, 0x1170, 0x1398, 0x1398, 0x1398, 0x1398, 0x1398, 0x3, 0x0, {[{{@uncond, 0x0, 0x1128, 0x1170, 0x0, {}, [@common=@inet=@multiport={{0x50}}, @common=@unspec=@cgroup1={{0x1030}, {0x0, 0x2, 0x0, 0x0, './cgroup.net/syz0\x00'}}]}, @common=@inet=@TEE={0x48, 'TEE\x00', 0x1, {@ipv4=@multicast2, 'netpci0\x00'}}}, {{@uncond, 0x0, 0x1e0, 0x228, 0x0, {}, [@common=@rt={{0x138}, {0x0, [0x88], 0x0, 0x23, 0x0, [@empty, @local, @remote, @mcast2, @loopback, @rand_addr=' \x01\x00', @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}, @ipv4={'\x00', '\xff\xff', @local}, @mcast1, @loopback, @remote, @mcast2, @empty, @rand_addr=' \x01\x00', @mcast1, @remote]}}]}, @unspec=@CT0={0x48, 'CT\x00', 0x0, {0x0, 0x0, 0x0, 0x0, 'snmp_trap\x00'}}}], {{'\x00', 0x0, 0xa8, 0xd0}, {0x28}}}}, 0x14c8) 5.251258976s ago: executing program 0 (id=2608): r0 = syz_usb_connect(0x2, 0x24, &(0x7f0000000040)=ANY=[@ANYBLOB="1201000073864020720c1400ac39013b4fa9380dfdf189d87f5f875eca72e6"], 0x0) socket$nl_netfilter(0x10, 0x3, 0xc) syz_open_dev$vbi(&(0x7f0000000040), 0x0, 0x2) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) r1 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r1, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r2 = socket$inet6_sctp(0xa, 0x1, 0x84) openat$userio(0xffffffffffffff9c, 0x0, 0x2002, 0x0) r3 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000500), 0x28002) dup(r3) syz_open_procfs(0x0, &(0x7f0000000380)='autogroup\x00') mount$9p_fd(0x0, &(0x7f00000001c0)='.\x00', &(0x7f0000000180), 0x0, &(0x7f00000003c0)=ANY=[]) setsockopt$inet_sctp6_SCTP_RECONFIG_SUPPORTED(r2, 0x84, 0x75, &(0x7f0000000000)={0x0, 0xca}, 0x8) r4 = socket(0x10, 0x803, 0x0) sendmsg$IPVS_CMD_SET_INFO(r4, 0x0, 0x0) r5 = socket$alg(0x26, 0x5, 0x0) bind$alg(r5, &(0x7f00000000c0)={0x26, 'rng\x00', 0x0, 0x0, 'drbg_pr_sha512\x00'}, 0x58) setsockopt$ALG_SET_KEY(r5, 0x117, 0x1, 0x0, 0x0) r6 = accept4(r5, 0x0, 0x0, 0x80000) sendmsg$nl_netfilter(r6, &(0x7f00000003c0)={0x0, 0x0, &(0x7f00000006c0)={0x0, 0xffffff70}, 0x1, 0x0, 0x0, 0x200050c0}, 0x4000000) r7 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r7, &(0x7f0000000100)={0x3, 0x0, &(0x7f0000000000)={&(0x7f0000000040)={0x2, 0x5, 0xfc, 0x2, 0x4, 0x0, 0x0, 0x4, [@sadb_sa={0x2, 0x1, 0x4d2, 0x0, 0x0, 0x9, 0x0, 0xc0000001}]}, 0x20}, 0x1, 0x7}, 0x0) recvmmsg(r6, &(0x7f0000000240)=[{{0x0, 0x0, &(0x7f0000000900), 0x3}, 0x17ba}], 0x1e, 0x2000, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000340)={&(0x7f0000000300)='sched_switch\x00'}, 0x10) mremap(&(0x7f000054e000/0x1000)=nil, 0x1000, 0x2000, 0x4, &(0x7f000022d000/0x2000)=nil) sendmsg$nl_route(0xffffffffffffffff, 0x0, 0x40000) syz_usb_control_io(r0, 0x0, &(0x7f0000000600)={0x84, &(0x7f0000000200)=ANY=[@ANYBLOB='@1\x00@\x00\x00'], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) 4.372803278s ago: executing program 2 (id=2611): r0 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL80211_CMD_SET_INTERFACE(r0, &(0x7f00000001c0)={0x0, 0x0, 0x0}, 0x0) socket$kcm(0x10, 0x2, 0x0) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x5, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000100)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f0000000200)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) read$msr(r1, &(0x7f0000002000)=""/102400, 0x19000) mkdir(&(0x7f0000000100)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000200)='./file0\x00', &(0x7f00000004c0)='cgroup2\x00', 0x0, 0x0) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', &(0x7f0000000240), 0x0, &(0x7f00000001c0)={[{@lowerdir={'lowerdir', 0x3d, './file0'}, 0x3a}], [], 0x2f}) faccessat2(0xffffffffffffff9c, 0x0, 0x3, 0x300) sendfile(0xffffffffffffffff, 0xffffffffffffffff, 0x0, 0x20000023896) r2 = bpf$MAP_CREATE(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="19000000040000000400", @ANYRES32=0x1, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="0000000000000000004d8a025b0000000000000000000000000000002e90fac9aff48d6e00d4a8ddc945a5ae4087bc7e20dd45d1455fa08883960f0c09cb304e60c14dff48fc8104521c48e82421b2c911dc3f5512131a989d8c4bd128cc0ac668eb537b5ff5a4e7760dbe266c7715a150cc3761d9f82fce03c49bd95acb561b100c0fe19eba3bbbe3d1c76a950073ca6be0118b8c01471ec63ccfcbffab64d5dab667ceead0e42bd18a51bc34f9967300006bb4a1e9a2b3eb7b2f240000000029072d3a844d02e88d78deddab6a7c7d506b99feff8a3bf038bfa1d3f5b3d3aa11ddf8e45b3e0a312d43cab398e2f7838a915e000f360200"], 0x48) bpf$MAP_GET_NEXT_KEY(0x2, &(0x7f0000000240)={r2, &(0x7f0000000140), &(0x7f0000000000)=""/6, 0x2}, 0x20) mlock(&(0x7f0000ffb000/0x3000)=nil, 0x3000) mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x0) mount(0x0, &(0x7f00000000c0)='./file0\x00', &(0x7f0000000040)='cgroup2\x00', 0x0, 0x0) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', &(0x7f0000000000), 0x0, &(0x7f00000001c0)={[{@lowerdir={'lowerdir', 0x3d, './file0'}, 0x3a}], [], 0x2f}) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', 0x0, 0x22806d, 0x0) r3 = openat$sysctl(0xffffffffffffff9c, &(0x7f0000000000)='/proc/sys/net/ipv4/tcp_rfc1337\x00', 0x2, 0x0) sendfile(r3, r3, 0x0, 0x1) move_pages(0x0, 0x2, &(0x7f0000000180)=[&(0x7f0000ffb000/0x2000)=nil, &(0x7f0000ffb000/0x2000)=nil], &(0x7f0000000240)=[0x1, 0x1], &(0x7f0000000540), 0x0) 4.343538099s ago: executing program 5 (id=2612): r0 = openat$binderfs(0xffffff9c, 0x0, 0x806, 0x0) ioctl$BINDER_GET_NODE_INFO_FOR_REF(r0, 0xc018620c, 0x0) r1 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000001140)='net\x00') r2 = openat$kvm(0xffffffffffffff9c, &(0x7f00000001c0), 0x0, 0x0) ioctl$SNDCTL_DSP_GETTRIGGER(r1, 0x80045010, &(0x7f0000000000)) r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0) r4 = syz_init_net_socket$bt_l2cap(0x1f, 0x2, 0x0) connect$bt_l2cap(r4, &(0x7f0000000080)={0x1f, 0x0, @fixed={'\xaa\xaa\xaa\xaa\xaa', 0x10}, 0x7ff}, 0xe) r5 = syz_init_net_socket$bt_hidp(0x1f, 0x3, 0x6) connect$inet6(r1, &(0x7f0000000040)={0xa, 0x4e24, 0x5c, @private1={0xfc, 0x1, '\x00', 0x1}, 0x1b57}, 0x1c) ioctl$sock_bt_hidp_HIDPCONNADD(r5, 0x400448c8, &(0x7f00000001c0)={r4, r4, 0x8, 0x0, 0x0, 0x1, 0xb, 0x7, 0x7, 0x0, 0x1, 0x0, 'syz0\x00'}) r6 = eventfd2(0x0, 0x0) ioctl$KVM_IOEVENTFD(r3, 0x4040ae79, &(0x7f0000000300)={0x7, 0xeeee0000, 0x0, r6}) close_range(r1, 0xffffffffffffffff, 0x0) 3.537990528s ago: executing program 2 (id=2615): r0 = socket$inet6(0xa, 0x2, 0x0) (async, rerun: 64) r1 = socket$nl_route(0x10, 0x3, 0x0) (async, rerun: 64) r2 = socket(0x10, 0x803, 0x0) (async) socket$nl_route(0x10, 0x3, 0x0) (async) syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) (async) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) (async) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) (async, rerun: 32) r3 = getpid() (rerun: 32) sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) (async, rerun: 64) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000080)) (async, rerun: 64) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) (async, rerun: 32) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) (rerun: 32) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) (async, rerun: 32) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) (async, rerun: 32) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) (async) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) (async, rerun: 64) r6 = socket$nl_route(0x10, 0x3, 0x0) (rerun: 64) sendmsg$nl_route(r6, &(0x7f0000000100)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000140)=@ipv6_newnexthop={0x1c, 0x68, 0x5fb9a818fb7378e9, 0x0, 0x0, {}, [@NHA_BLACKHOLE={0x4}]}, 0x1c}}, 0x0) (async) r7 = socket$inet6_icmp(0xa, 0x2, 0x3a) sendmsg$inet6(r7, &(0x7f0000000040)={0x0, 0x0, 0x0}, 0x4040080) (async) r8 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r8, &(0x7f0000000000)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000300)=@newnexthop={0x24, 0x68, 0x1, 0x2, 0x7ffffffc, {}, [@NHA_GROUP={0xc, 0x2, [{0x1, 0x4}]}]}, 0x24}, 0x1, 0x0, 0x0, 0x24008000}, 0x4000) (async) r9 = syz_genetlink_get_family_id$nl80211(&(0x7f00000019c0), 0xffffffffffffffff) sendmsg$NL80211_CMD_CHANNEL_SWITCH(0xffffffffffffffff, &(0x7f0000001ac0)={&(0x7f00000002c0)={0x10, 0x0, 0x0, 0x2000000}, 0xc, &(0x7f0000001a80)={&(0x7f0000001a40)={0x30, r9, 0x4, 0x70bd2a, 0x25dfdbfb, {{}, {@val={0x8}, @val={0xc, 0x99, {0xfff, 0x1b}}}}, [@NL80211_ATTR_CH_SWITCH_COUNT={0x8, 0xb7, 0x12}]}, 0x30}, 0x1, 0x0, 0x0, 0x1}, 0x4004080) r10 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r10, &(0x7f0000000280)={0x0, 0xfffffffffffffda3, &(0x7f0000000180)={&(0x7f0000000200)=@delnexthop={0x20, 0x69, 0xb, 0x0, 0x0, {}, [{0x8, 0x1, 0x1}]}, 0x20}}, 0x4000000) (async) sendmsg$SMC_PNETID_GET(r2, &(0x7f0000000300)={0x0, 0x0, &(0x7f00000001c0)={0x0}, 0x1, 0x0, 0x0, 0x24000080}, 0x0) (async) getsockname$packet(r2, &(0x7f0000000280)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000900)=0x14) sendmsg$nl_route(r1, &(0x7f0000000380)={0x0, 0x0, &(0x7f00000002c0)={&(0x7f00000000c0)=@newlink={0x40, 0x10, 0x437, 0x10, 0x25dfdbff, {0x0, 0x0, 0x0, r11, 0x54583, 0x1}, [@IFLA_LINKINFO={0x20, 0x12, 0x0, 0x1, @gre={{0x8}, {0x14, 0x2, 0x0, 0x1, [@IFLA_GRE_IKEY={0x8, 0x4, 0xffffffff}, @IFLA_GRE_OFLAGS={0x6, 0x3, 0x23}]}}}]}, 0x40}, 0x1, 0x0, 0x0, 0x1}, 0x0) sendmmsg$inet(r0, &(0x7f0000000640)=[{{&(0x7f0000000040)={0x2, 0x4e1c, @multicast1}, 0x10, 0x0, 0x0, &(0x7f0000000000)=[@ip_pktinfo={{0x1c, 0x0, 0x8, {r11, @empty}}}], 0x20}}], 0x1, 0x80) 3.40657771s ago: executing program 5 (id=2616): unshare(0x6a040000) mmap(&(0x7f0000609000/0x4000)=nil, 0x4000, 0x3, 0x8031, 0xffffffffffffffff, 0x0) unshare(0x0) r0 = socket$inet_smc(0x2b, 0x1, 0x0) mprotect(&(0x7f0000000000/0x4000)=nil, 0x4000, 0x1) sendmsg(r0, &(0x7f0000000500)={&(0x7f00000000c0)=@pppol2tpin6={0x18, 0x1, {0x0, r0, 0x4, 0x0, 0x4, 0x3, {0xa, 0x4e24, 0x79a, @local, 0x19200000}}}, 0x80, &(0x7f0000000200)=[{&(0x7f0000000140)="c374b1326ceef87f100166c99895f68327c4fd072be48c70aa3189f6a2194acea1bdb53fd1799ab954e133a7bdbfae4e3e95f45bf91f6a82cb017b441ef4392906c76b38d205fbe2120e48307b8b8cea2a13db099aa59715ad9b00458fa82809843f41100b4f333cdee50c156e95fb765520aa765a1c5ea55b205404fbc4d8e03c03f77c2e4f3f4c42fd07606f3698b062231a652df3a2edf999dbcc6092c65cbbea75c7184b010c795ba8c0d10218398c2fad8ff183cd83", 0xb8}], 0x1, &(0x7f0000000240)=[{0xb8, 0x11, 0x3, "692d008924bb331af71b2fa2a8f675aff6cfbb115ca148701a52eb62dca628184017e4caa853f9de157992d8e5f2a5c4e6f58334a006357f9735f059dfae247ea6130509c5e3d2da78485c67c664a79e008201f722b2d7e1ef6c086f0154a0f48a5fed223ce3dda5187e64b7f9d5d66465d070084e815d527d26c8b9bf6ed0f31e6026850b3f2794016669b0cdc355faff2016f101decd6be1a02e7f78d2780a44524dcb"}, {0xb0, 0x111, 0xf3f7, "21d5f30f86ed1dc0b229a7924aae46011bb1294a3a17a8b591b2fc5a4edec8c1cbd4cf39e55df3e6baa1392aac2949e087554e4b3e640b21efdfa6b6c3dc8689d6ddc78971a0390660d266b42c275885fe3220bef6349484ebefbb6cdbb379a74ec864ff9249449007104306c6542467c5d21dbd1cb318ed97ef3bb04ece995ccf0d23a030ad4c5a69f65d7cef4cad63832d4c45d2cd0ae94bf5012c5aec"}, {0xd0, 0x0, 0x9, "cd937de9c7c806818b8cd483af91e643a85a70a3d8109733fbbc8a853a4ad3574a69e8918d2904c3f3ded68570485e3a28e81179aeafa1467fab3bba196938ba29dd61002f43f27e301858cb76636264c8f37d80fd5c96b5fc7e554b85a87c2d62b380138010bc53f303099bcc459b6cff481e028b6a18c9cc1c2d6e692e51d2bc591d342d53daabd3da1dffb571eadd11ce7c42c452c05f8e235693dae68c15a62f21b7c2130fc268bceadcf8079baf5b817ddd0e4986fde01e8625b9ba0d75"}, {0x60, 0x103, 0x2, "d0c46fc9e2f4f22a2ba834baf612615faee91dae7974a9826503c999d0a6d62bb6e37132c586e799a3ec6d721930fb36f6430810bc1335a81910d0c41a8ca7188045c6e6f72162768af398be"}], 0x298}, 0x4000) getsockopt$EBT_SO_GET_INFO(r0, 0x0, 0x80, &(0x7f0000000000)={'nat\x00', 0x0, 0x0, 0x0, [0x4, 0x5, 0xff, 0x7, 0x97d4, 0x1000000073]}, &(0x7f0000000080)=0x78) 3.406318339s ago: executing program 1 (id=2617): socket$nl_route(0x10, 0x3, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000400)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) pipe(&(0x7f0000000280)={0xffffffffffffffff, 0xffffffffffffffff}) r4 = socket$inet(0x2b, 0x801, 0x0) splice(r4, 0x0, r3, 0x0, 0x5, 0x9) 3.264873819s ago: executing program 2 (id=2618): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = io_uring_setup(0x51d0, &(0x7f0000000140)={0x0, 0x3957, 0x40, 0x2000002, 0x402d7}) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000140)={0x1e, 0x4, &(0x7f0000000300)=ANY=[@ANYRESOCT=r3], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x24, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffeec, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) io_uring_register$IORING_REGISTER_BUFFERS2(r3, 0xf, &(0x7f0000002700)={0x119f, 0x0, 0x0, &(0x7f0000000200)=[{&(0x7f0000000480)=""/264, 0xf9}, {&(0x7f00000015c0)=""/4096, 0xd8da7}, {&(0x7f0000002a00)=""/88, 0x8}], 0x0}, 0x20) socket$nl_route(0x10, 0x3, 0x0) r4 = socket$inet_udp(0x2, 0x2, 0x0) r5 = bpf$MAP_CREATE(0x0, &(0x7f0000000ac0)=ANY=[@ANYBLOB], 0x48) r6 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x7, &(0x7f0000000240)=ANY=[@ANYBLOB="180000000000000000000000000000001811", @ANYRES32=r5, @ANYBLOB="0000000000000000b702000002000000850000008600000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f00000006c0)='sched_switch\x00', r6}, 0x18) socket$inet_tcp(0x2, 0x1, 0x0) r7 = syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$ieee802154(&(0x7f0000000ac0), r7) r8 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_mreq(r8, 0x29, 0x1b, &(0x7f0000000200)={@dev}, 0x14) r9 = syz_open_procfs(0x0, &(0x7f0000000080)='net/anycast6\x00') preadv(r9, &(0x7f0000000040)=[{&(0x7f0000000380)=""/80, 0x50}], 0x1, 0x3, 0x3) r10 = socket(0x25, 0x801, 0x0) recvfrom$l2tp6(r10, 0x0, 0x0, 0x2000, 0x0, 0x0) ioctl$sock_inet_SIOCGARP(r4, 0x8954, &(0x7f0000000040)={{0x2, 0x4e23, @remote}, {0x1, @multicast}, 0x38, {0x2, 0x4e20, @broadcast}, 'gre0\x00'}) 2.289336154s ago: executing program 1 (id=2619): r0 = socket$inet6_tcp(0xa, 0x1, 0x0) sendmmsg$unix(0xffffffffffffffff, 0x0, 0x0, 0x0) mount(0x0, 0x0, 0x0, 0x8000, 0x0) setsockopt$IP6T_SO_SET_REPLACE(r0, 0x29, 0x40, &(0x7f0000000000)=@raw={'raw\x00', 0x3c1, 0x3, 0x1468, 0x1170, 0x1170, 0x1398, 0x1170, 0x1170, 0x1398, 0x1398, 0x1398, 0x1398, 0x1398, 0x3, 0x0, {[{{@uncond, 0x0, 0x1128, 0x1170, 0x0, {}, [@common=@inet=@multiport={{0x50}}, @common=@unspec=@cgroup1={{0x1030}, {0x0, 0x2, 0x0, 0x0, './cgroup.net/syz0\x00'}}]}, @common=@inet=@TEE={0x48, 'TEE\x00', 0x1, {@ipv4=@multicast2, 'netpci0\x00'}}}, {{@uncond, 0x0, 0x1e0, 0x228, 0x0, {}, [@common=@rt={{0x138}, {0x0, [0x600], 0x0, 0x23, 0x0, [@empty, @local, @remote, @mcast2, @loopback, @rand_addr=' \x01\x00', @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}, @ipv4={'\x00', '\xff\xff', @local}, @mcast1, @loopback, @remote, @mcast2, @empty, @rand_addr=' \x01\x00', @mcast1, @remote]}}]}, @unspec=@CT0={0x48, 'CT\x00', 0x0, {0x0, 0x0, 0x0, 0x0, 'snmp_trap\x00'}}}], {{'\x00', 0x0, 0xa8, 0xd0}, {0x28}}}}, 0x14c8) 2.183992139s ago: executing program 5 (id=2620): openat$sysfs(0xffffffffffffff9c, &(0x7f0000000000)='/sys/kernel/cpu_byteorder', 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000240)=0x7) r0 = getpid() r1 = socket$nl_generic(0x10, 0x3, 0x10) r2 = syz_genetlink_get_family_id$SEG6(&(0x7f0000000080), 0xffffffffffffffff) sendmsg$SEG6_CMD_SETHMAC(r1, &(0x7f00000004c0)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000500)=ANY=[@ANYBLOB='0\x00\x00\x00', @ANYRES16=r2, @ANYBLOB="01000000000000000000010000000500050001000000040004000500060000000000080003000100000087a6ef99b1c653fc5f714725dcb3b0488f9fdfdb1b5fea9dc9103250d17aec179494e92837b045445fa4430b6701554783b1e31e272bd01a90b2b3e92e149de0eaf362592956132d3fdf0d0507e48aef2058f73b1b19127bfa730cb821ea0b0b6589d13c6a9910716c628d09f683af57c23e74417cd8c8ebc5d7ebcbf476f9771d8e68432fd96f2538c7058686b047257f29e08dea9e4c9963e39460"], 0x30}}, 0x0) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbee2, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e21}, 0x6e) sendmmsg$unix(r4, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000100)=0x6) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000000)={0xffffffffffffffff}) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = socket$kcm(0xa, 0x922000000003, 0x11) setsockopt$sock_attach_bpf(r7, 0x29, 0x24, &(0x7f00000000c0), 0x4) sendmsg$kcm(r7, &(0x7f0000000000)={&(0x7f00000002c0)=@l2tp6={0xa, 0x0, 0x0, @mcast1, 0x9}, 0x80, 0x0}, 0x0) dup2(r7, r5) ioctl$ifreq_SIOCGIFINDEX_batadv_mesh(r5, 0x8933, &(0x7f0000003040)={'batadv0\x00', 0x0}) sendmsg$BATADV_CMD_TP_METER(r6, &(0x7f0000003140)={0x0, 0x0, &(0x7f0000003100)={&(0x7f0000000340)=ANY=[@ANYBLOB="1c000000", @ANYRES16=0x0, @ANYBLOB="01002bbd7000fbdbdf250200000008000300", @ANYRES32=r8, @ANYBLOB="38bbc11fb0fe3e3edbcea66fcf6cb7cbc7c5ce645e94cee363a50800000000000000d40571786278534ce6cfcca3355ff969e8625d8a64232a87ee5b16e1200043a8f0fd6b1c337072ec4ada5b2413ce0d1855806786391de5caadc26e7e53ccaac4fa390dcd7285cb2264334f6a7d90ff3c538bf1668be5bf1993deeb6872355fff3a3f12f3c314ad820bf498e9de9cd6b4fcbdd2b0f311a22b2a46ec6d1b35dfc2ccf9a3b90309c84f4cd2054be1fd17f0badd9a19acbd0743b8d5d0f5a5e9210b4e96cd539233087ecbb881ca8b830dfd92d0f97f1bbe59d11e9963ad109ebd184361d53c7bac0e00"/248], 0x1c}, 0x1, 0x0, 0x0, 0x20000050}, 0x20040084) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000240)={&(0x7f0000000280)='mmap_lock_acquire_returned\x00'}, 0x18) r9 = syz_open_procfs(0x0, &(0x7f00000001c0)='pagemap\x00') pread64(r9, &(0x7f0000001240)=""/102400, 0x19000, 0x1000000000) r10 = socket$inet_smc(0x2b, 0x1, 0x0) getsockopt$IP_VS_SO_GET_TIMEOUT(r10, 0x0, 0x486, &(0x7f0000000000), &(0x7f0000000040)=0xc) write$RDMA_USER_CM_CMD_RESOLVE_IP(0xffffffffffffffff, 0x0, 0x0) openat$kvm(0xffffffffffffff9c, &(0x7f0000000200), 0x0, 0x0) openat$procfs(0xffffffffffffff9c, &(0x7f0000000000)='/proc/bus/input/devices\x00', 0x0, 0x0) 2.17236698s ago: executing program 2 (id=2621): r0 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) r1 = dup(r0) write$6lowpan_enable(r1, &(0x7f0000000000)='0', 0x1) r2 = openat$fuse(0xffffffffffffff9c, &(0x7f0000000040), 0x2, 0x0) read$FUSE(r2, &(0x7f0000003780)={0x2020}, 0x2020) 2.114572369s ago: executing program 0 (id=2622): openat$vhost_vsock(0xffffffffffffff9c, 0x0, 0x2, 0x0) (async) r0 = inotify_init1(0x0) ioctl$INOTIFY_IOC_SETNEXTWD(r0, 0x40044900, 0x7) (async) openat$ipvs(0xffffffffffffff9c, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) (async) r1 = socket$can_bcm(0x1d, 0x2, 0x2) (async) capset(&(0x7f0000000080)={0x20071026}, &(0x7f0000000040)={0x200000, 0x200000}) (async) r2 = syz_open_dev$sg(&(0x7f00000002c0), 0x0, 0x2000) r3 = fcntl$dupfd(r2, 0x0, r2) ioctl$SG_IO(r3, 0x2285, &(0x7f0000000040)={0x53, 0xfffffffe, 0x6, 0x0, @buffer={0x2, 0x0, 0x0}, &(0x7f0000000380)="159374c96ee3", 0x0, 0x300, 0x0, 0x0, 0x0}) (async) connect$can_bcm(r1, 0x0, 0x0) (async) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) (async) r4 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000180)=0x2) (async) sched_setaffinity(0x0, 0x0, 0x0) (async) read$msr(r4, &(0x7f0000019680)=""/102384, 0x18ff0) (async) syslog(0x4, &(0x7f0000000b00)=""/4096, 0x1000) (async) syz_usb_connect(0x1, 0x24, &(0x7f0000000200)=ANY=[@ANYBLOB="1201000046365608b40413068f9501020301090258320c1200010000000009efffffffd06fe1372a3bfa9f5d8ae86399f6cd35c5f4a686c9870e9fa5e0a2a6cb7b2bf9bf9319ca541cc430b83607033fa996c773193fa7be437db0023d2fd202c7df7d84df5e5bf5445ed309f02970db39b24355a7ef8b5917f7481c32f6fd3e59fc849f39c968656a014b31930f01a40f719430cba3047a3dba1ac47c23d69223ecd8d4eeb7814f"], &(0x7f0000000bc0)={0x0, 0x0, 0x0, 0x0, 0x1, [{0x0, 0x0}]}) 2.068098865s ago: executing program 2 (id=2623): prctl$PR_SET_SYSCALL_USER_DISPATCH_ON(0x3b, 0x1, 0x0, 0x0, &(0x7f0000006680)) r0 = landlock_create_ruleset(&(0x7f0000000040)={0x8201, 0x3}, 0x4e, 0x0) r1 = openat$vhost_vsock(0xffffffffffffff9c, &(0x7f00000015c0), 0x2, 0x0) ioctl$VHOST_SET_VRING_BASE(r1, 0xaf01, 0x0) ioctl$VHOST_SET_LOG_FD(r1, 0x4004af07, 0xfffffffffffffffc) landlock_restrict_self(r0, 0x0) r2 = fsopen(&(0x7f0000000080)='tmpfs\x00', 0x0) fsconfig$FSCONFIG_CMD_CREATE(r2, 0x6, 0x0, 0x0, 0x0) r3 = fsmount(r2, 0x0, 0xf) capset(&(0x7f0000000000)={0x20080522}, &(0x7f0000000280)={0x0, 0x0, 0x0, 0x81, 0xffffffff}) ioctl$sock_ipv6_tunnel_SIOCGETTUNNEL(r3, 0x89f0, &(0x7f0000000180)={'syztnl1\x00', &(0x7f0000000200)={'ip6_vti0\x00', 0x0, 0x4, 0xe9, 0xfc, 0xa, 0x8, @rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01', @empty, 0x7800, 0x1, 0xe, 0x6}}) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0xf, 0xe, &(0x7f0000001880)=ANY=[@ANYBLOB="b700000081000000bfa30000000000000703000003feffff720a00fef8ffffff71a400fe0000000071302000000000001d400500000000004704000001ed00000f030000000000001d44000000000000620af8fe040400007203f80000000000b500f7ff000000009500000000000000023bc065b58111c6dfa041b63af4a3912435f1a864a710aad58db6a693002e7f3be361917adef6ee1c8a2a4f8ef1e50becb19bc461e91a7168c50000000190f32050e436fe275daf51efd601b6bf01c8e8b1b526375ec4dd6fcd82e4fe51bef7af9aa0d7d600c095199fe3380d28e599b0eaebbdbd732c9cc00eec363e4a8f6456e2cc21557c0afc646cb7798b3e6440c2fbdb00a3e35208b0bb0d2cd829e654400e2438ec649dc74a28610643a98d9ec21ead2ed51bf900000000000000d8a7925c3109b151b8b9f75dd08d123deda88c658d42ecbf28bf7076c15b463bebc72f526d8e8afcb913466aaa7f6df70252e79166d858fcd0e06dd31af9612f2460d0b11008e59a5923906f88b53987ad1714e72ba7a54f0c33d39000d06a59ff616236fd9aa58f2477184b6a89adaf17b0a6041bdef728d236619074d6ebdfd1f5089048ddff6da40f9411fe722631cb467600ade70063e5291569b33d21dae356e1c51f03a801be8189679a16da18ec0ae564162a27afea62d84f3a10746443d6438e959532e0617d419c6bc6ea9f2bca4464f56e24e6d2105bd901204a1deeed4155617572652d950ad31928b0b0c3dc2869f478341d02d0f5ad94b081fcd507acb4b9c65fee9d5a17f48a7382f13d000000225d85ae49cee383dc5049076b989b40000000000000da60d2ae20cfb91d6a49964757cdf538f9ce2bdb1ab062cd54e67011d355d84ce97bb0c6b4a595e487efbb2d71cde2c140952f9a0f0bc6980fe78683ac5c0c31032599ddd71063be9261b2e1aab1675b34a22048ef8c126aeef5f510a8f1aded94a129e4aec6f8d9ab06faffc3a15d96c2ea3e2e04cfe031b2875353193f82ade69d0540059fe6c7fe7cd8697502c7596566d674e425da5e87e59602a9f6590521d31d3804b3e0a1053abdc31282dfb15eb6841bb64a1b304502dda787343ce3c953992e4a982f3c48153baae244e7bf37548c7f1a4cad2422ee965a38f7defbd2160242b104e20dc2d9b0c35608d402ccdd9069bd50b994fda7a9de44028d6112a0c2d21b2dc98816106dec28eaeb883418f562ae00003ea96d10f172c0374d6eed826416050000000bfe9b4a9c5a90ff59d54d1f92ecc4e95dd2d18383117c039862198899b212c55318294270a1ad10c80fef7c24d47afce829ba0f85da6d888f18ea40ab959f6074ab2a40d85d15017ab513cdc6c0e57fb1c1ca571380d7b4ead35a385e0b4a26b702396df7e0c1e02b6e4114f244a9bf93020000000000000080e69db384ac7eeedcf2ba3a9508f9d6aba582a896a9f1e096df6ecea75caf822a7a63ba34015ea5aacb1188883ad2a3b1832371fe5bc621426d1ed0a4a99702cc1b6912a1e717d29135753208165b9cdbae2ed9dc7358f0ebadde0b727f27feeb744ddcc536cbae315c7d1fe1399562ba6824840bd2951680f6f2f9a6a8346962a350845ffa0d829e4f79adc287906943408e6df3c391e97ba48db0a5adbfd03aac93df8866fb010aec0e92bed1fe39af169d2a466f0db6f3d9436a7d55fc30511d00e10000c95265b2bd83d64a532869d701723fedcbada1ee7baa5b6a686b50f0937f778af083e055f6138a757ebd0ed91124a6b244f9acf41ac5d73a008364e0606a594817031fc2f52c8785fe0721719b3d654026c6ea08b83b123145ab5703dad844ceb201ddeb6dc5f6a903792283c42efc54fa84323afc4c10eff462c8843187f1dd48ef3fa293774d582956ff0f40b10ca94f6feeb2893c17888e1cdba94a6ea80c33ead5722c3293a493f1479531dd88261458f40d31fe8df15efaaeea831555877f9538d6ee6ba65893ff1f908ba7554ba583fef3ec7932f5954f31a878e2fae6691d1aee1da02ba516467df3e7d1daac43738012e4fee18a22da19fcdb4c2890cda1f96b952511e3a69d694d625e0b2f808890205f3a6da2819d2f9e77c7c64affa54fec0136cbafa5f6f096753b639a924599c1f69219927ea5301fff0a6063d427f0688430754c02180d61542c2571f983e9673560000000000000000005a7b57f03ca91a01ba2e30ca99e8ebc15ecb4d91675767999d146aef7799738b292fd640dfef6b04d086f737a159d7e0c6e4d81ad64a8bbca48568325b2969e2b15f36b788bce5ccdbaf75c94cb93499f6947a967a7bce14c6de4e7c0660d80010f5c653d22d490cba8c2a4ab595bf4238f18ca428dafc7ac96d404607a0000000051a2104f22e6db5a62b5089c1b45282d38864daa3ae81d6b0968d1d2867b91b7d120617d12d91db2633d6864da40b54783a17aaeb6737c323f9f98e354cc98dcfe23ad01bd1c61563e69ffe1c2c73e16e1461173f359e93d2c5e424c17998809ec8f0232b3955e052a4cecd89008f70314a0bdd491ec86a4555d89fe0120f64c62e8e3ed8bcb45202c3d4bbec8d722824c0ebca8db1ea4a003d2fbdc1f9be78537756ab5bbe4fe9af5d785d0128171c90d9900ce2532b0f9d01c4b45294fbba468df3e1b583cb4e62e754598e47df6bd06431c94bc5d047899fd219f448bf9189c65c9d91eda6b52a373803a9efe44f86909bc90addb7b9aee813df534aac4b3093c91b8068cd84990453f006694d461b76a58d88cf0f520310a1e80dc18cde98d662eee077515d0a8811922929e085392ab3d1311b8243266d87047f601fa88a0da36b9f302e8262395174328f2482d14008de83070744f143fdec90ba5a82668d5fac114c13955ad6dca5db2231d8ba14c54c47ed04a4b4ace17e357e1d6032399f87a7a14245bbd796a09313b247b95d37ff40a404bdad74bd20000000000000000000099fef7cd7af3ce64a92f95d89d125b1e641240d7e5e27a3d1f7684448c3e3822d617e205061298b939a191be4b48e169bde2cae3accc5bd40a2968b59c93d35f8e42366fdef9a2abae1cf01ce68abff28861aac8302d268569dd42e194e330c7aaa54ebbcefd23f21ce8153b9926e12e925cb56119df72c7533a48d028ad0c74e2a9478fa3be18a1a2b65079cc1c00000000000000f59dd19e8d525206c0a728cfd42193abe8130bc01a2d69841f3d7799ac04bdc590bb1c89b9c695f163e57343c9bfb59909433c9001c5f8b23e38534a538fc933cac6c2a92d038df638a0f226df9fb857bd414c2cd69985e8053e3dfa41614d7c74d04d8c2471041d17c730fad28395f8d4688898cd58b9d600c851626529bb58aa364b55e73f053450665e7b94ed1012fd7a8139166fd5e59c84f4ab279b1b99c028db4cb9680c8035f967db18de738844da7e260a830c1ffa49f5af3c15423a0e315acb82a3e89218cb314e68fda4d94aa1d815babc13b9fd336d205c5913ef67cf0216e2d81e6127bd9d7fab28800eaab2355992f8ce4cd38add4b272c0bee4076ca4847ffa691cf78fb7ec212bad3bef29f577ea7159b7f3025b3d977ff7c91024cf71126233cb8791c3c"], &(0x7f00000001c0)='GPL\x00', 0x5, 0x0, 0x0, 0x0, 0x0, '\x00', r4, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000)={0x0, 0x0, 0x0, 0x6}, 0x10, 0x0, r3, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) setpriority(0x1, 0x0, 0x3) fsconfig$FSCONFIG_CMD_RECONFIGURE(r2, 0x7, 0x0, 0x0, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x8031, 0xffffffffffffffff, 0x0) madvise(&(0x7f0000000000/0x600000)=nil, 0x600002, 0x9) semget(0x2, 0x4, 0x200) ioctl$AUTOFS_DEV_IOCTL_EXPIRE(0xffffffffffffffff, 0xc018937c, &(0x7f0000000000)={{0x1, 0x1, 0x18, 0xffffffffffffffff, {0x2}}, './file0\x00'}) ioctl$DRM_IOCTL_ADD_MAP(r5, 0xc0286415, &(0x7f0000000040)={&(0x7f00000d6000/0x4000)=nil, 0x5, 0x0, 0x2}) 1.990655539s ago: executing program 0 (id=2624): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) ioctl$KVM_SET_CLOCK(r1, 0x4030ae7b, &(0x7f0000000500)={0x2, 0x2, 0x7, 0xb, 0x7ff}) r2 = socket(0x10, 0x803, 0x0) socket$inet_udp(0x2, 0x2, 0x0) sendmsg$nl_route(r2, &(0x7f00000002c0)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f00000003c0)=@newlink={0x40, 0x10, 0x503, 0x20000000, 0x0, {0x0, 0x0, 0x0, 0x0, 0x0, 0x880}, [@IFLA_LINKINFO={0x20, 0x12, 0x0, 0x1, @vti={{0x8}, {0x14, 0x2, 0x0, 0x1, [@IFLA_VTI_LOCAL={0x8, 0x4, @dev={0xac, 0x14, 0x14, 0x27}}, @IFLA_VTI_REMOTE={0x8, 0x5, @multicast1}]}}}]}, 0x40}, 0x1, 0x0, 0x0, 0x800}, 0x4000) 1.92228118s ago: executing program 1 (id=2625): r0 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL80211_CMD_SET_INTERFACE(r0, &(0x7f00000001c0)={0x0, 0x0, 0x0}, 0x0) socket$kcm(0x10, 0x2, 0x0) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x5, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000100)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f0000000200)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) read$msr(r1, &(0x7f0000002000)=""/102400, 0x19000) mkdir(&(0x7f0000000100)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000200)='./file0\x00', &(0x7f00000004c0)='cgroup2\x00', 0x0, 0x0) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', &(0x7f0000000240), 0x0, &(0x7f00000001c0)={[{@lowerdir={'lowerdir', 0x3d, './file0'}, 0x3a}], [], 0x2f}) faccessat2(0xffffffffffffff9c, 0x0, 0x3, 0x300) sendfile(0xffffffffffffffff, 0xffffffffffffffff, 0x0, 0x20000023896) r2 = bpf$MAP_CREATE(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="19000000040000000400", @ANYRES32=0x1, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="0000000000000000004d8a025b0000000000000000000000000000002e90fac9aff48d6e00d4a8ddc945a5ae4087bc7e20dd45d1455fa08883960f0c09cb304e60c14dff48fc8104521c48e82421b2c911dc3f5512131a989d8c4bd128cc0ac668eb537b5ff5a4e7760dbe266c7715a150cc3761d9f82fce03c49bd95acb561b100c0fe19eba3bbbe3d1c76a950073ca6be0118b8c01471ec63ccfcbffab64d5dab667ceead0e42bd18a51bc34f9967300006bb4a1e9a2b3eb7b2f240000000029072d3a844d02e88d78deddab6a7c7d506b99feff8a3bf038bfa1d3f5b3d3aa11ddf8e45b3e0a312d43cab398e2f7838a915e000f360200"], 0x48) bpf$MAP_GET_NEXT_KEY(0x2, &(0x7f0000000240)={r2, &(0x7f0000000140), &(0x7f0000000000)=""/6, 0x2}, 0x20) mlock(&(0x7f0000ffb000/0x3000)=nil, 0x3000) mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x0) mount(0x0, &(0x7f00000000c0)='./file0\x00', &(0x7f0000000040)='cgroup2\x00', 0x0, 0x0) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', &(0x7f0000000000), 0x0, &(0x7f00000001c0)={[{@lowerdir={'lowerdir', 0x3d, './file0'}, 0x3a}], [], 0x2f}) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', 0x0, 0x22806d, 0x0) r3 = openat$sysctl(0xffffffffffffff9c, &(0x7f0000000000)='/proc/sys/net/ipv4/tcp_rfc1337\x00', 0x2, 0x0) sendfile(r3, r3, 0x0, 0x1) move_pages(0x0, 0x2, &(0x7f0000000180)=[&(0x7f0000ffb000/0x2000)=nil, &(0x7f0000ffb000/0x2000)=nil], &(0x7f0000000240)=[0x1, 0x1], &(0x7f0000000540), 0x0) 1.34474496s ago: executing program 1 (id=2626): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, &(0x7f00000009c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000540)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x44, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_TCP_REPAIR_WINDOW(r1, 0x6, 0x2c, &(0x7f0000000340), 0x6a) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000000)='sched_switch\x00', r0, 0x0, 0xfff7fffffffffff5}, 0x18) r2 = syz_open_dev$video4linux(&(0x7f0000000080), 0x0, 0x0) ioctl$VIDIOC_SUBSCRIBE_EVENT(r2, 0x4020565a, &(0x7f00000000c0)={0x3, 0x980900}) ioctl$VIDIOC_QUERYMENU(r2, 0xc008561c, &(0x7f0000000400)={0x980902, 0x4003, @value}) r3 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r3, 0x0, 0x0) sendmsg$NFT_BATCH(r3, &(0x7f00000000c0)={0x0, 0x0, 0x0}, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) symlinkat(0x0, 0xffffffffffffffff, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) r4 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141182) writev(r4, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r5 = openat$audio(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) socket$nl_generic(0x10, 0x3, 0x10) ioctl$SNDCTL_DSP_CHANNELS(r5, 0xc0045006, &(0x7f0000000080)=0x7f) ioctl$SNDCTL_DSP_SPEED(r5, 0xc0045002, &(0x7f00000000c0)=0x6) pselect6(0x40, &(0x7f0000000340)={0x9, 0x4, 0x7, 0x1, 0x200, 0x8, 0xb, 0x8001}, &(0x7f0000000380)={0x5, 0xd1b7, 0xfffffffffffff801, 0x2, 0x7fffffff, 0x8, 0x3, 0x4}, &(0x7f00000003c0)={0x0, 0x1, 0x2118, 0x7e, 0x4, 0x4, 0x0, 0x1}, 0x0, 0x0) r6 = openat$selinux_load(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) r7 = openat$selinux_policy(0xffffff9c, &(0x7f0000001040), 0x0, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x100000a, 0x12, r7, 0x0) sendmsg$NL80211_CMD_JOIN_MESH(0xffffffffffffffff, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000000)={0x20, 0x0, 0x200, 0x70bd2d, 0x25dfdbfb, {{}, {@val={0x8}, @void}}, [@NL80211_ATTR_MESH_CONFIG={0x4}]}, 0x20}, 0x1, 0x0, 0x0, 0x20008000}, 0x200480c0) write$selinux_load(r6, &(0x7f0000000000)=ANY=[], 0x2000) read$dsp(r5, &(0x7f00000011c0)=""/4117, 0x200021d5) 1.232882016s ago: executing program 0 (id=2627): r0 = openat$adsp1(0xffffffffffffff9c, &(0x7f0000000100), 0x200, 0x0) readv(r0, &(0x7f0000000140)=[{&(0x7f0000000080)=""/94, 0x5e}], 0x1) (async) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000280)={0x18, 0x5, &(0x7f0000000180)=ANY=[@ANYBLOB="180100002100000000000000000000108500000075000000a50000002300000095637da4659bd7874a09eaaa97f64e79edf0d0804eaad2c4f1ccb134e39196cdcf3ef10618742bd8bd5901721a7a55c4c9d0fd647d4d6d4273ddcb73f3fb0b1ed2efb57a8a67c4a6969cce11e4cafcbba327605f0c875268f16b72d53228be4e3d570e459ef1ec9cb033973df1184ec252d1561efd19944eff1b33aa92fcba4aa8b09bc5d5a04f62b60ebff12ce7913e0718ff904472462cb77d345e7c849fa93a"], &(0x7f0000000000)='syzkaller\x00', 0x2, 0x0, 0x0, 0x0, 0x4, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) (async) move_pages(0x0, 0x1, &(0x7f0000000140)=[&(0x7f0000064000/0x1000)=nil], &(0x7f0000000240), 0x0, 0x0) 1.230161105s ago: executing program 5 (id=2628): r0 = socket$inet6_tcp(0xa, 0x1, 0x0) bind$inet6(r0, &(0x7f0000d84000)={0xa, 0x2, 0x3, @loopback, 0x7}, 0x1c) setsockopt$inet6_tcp_int(r0, 0x6, 0x2000000000000022, &(0x7f0000000200)=0x1, 0x4) sendto$inet6(r0, &(0x7f0000000240)=':', 0x1, 0x8000, &(0x7f00000001c0)={0xa, 0x2, 0x398, @empty, 0x2000000}, 0x61) syz_usb_connect(0x5, 0x24, &(0x7f0000000380)={{0x12, 0x1, 0x250, 0x4, 0xda, 0xb0, 0x10, 0xccd, 0x39, 0x4499, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x12, 0x1, 0x4, 0xf8, 0x90, 0x1, [{{0x9, 0x4, 0x6f, 0x8, 0x0, 0x37, 0x6d, 0xbe, 0x9}}]}}]}}, 0x0) getsockopt$EBT_SO_GET_INIT_ENTRIES(0xffffffffffffffff, 0x0, 0x83, &(0x7f0000000200)={'broute\x00', 0x0, 0x3, 0x0, [0x9, 0xa6e, 0x400000000000003, 0xf, 0x8, 0xfffffffffffffffb], 0x0, 0x0, 0x0}, 0x0) bind$netlink(0xffffffffffffffff, &(0x7f0000177ff4)={0x10, 0x0, 0x1}, 0xc) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) r1 = add_key$keyring(&(0x7f0000000100), &(0x7f0000000180)={'syz', 0x1}, 0x0, 0x0, 0xfffffffffffffffe) add_key(&(0x7f00000003c0)='ceph\x00', 0x0, &(0x7f0000000400)="010000000037a788a11d1f000000000000006923c63a4541062101a59ea9cba39a989ca8c70b3692930208", 0x2b, r1) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x4) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) r2 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r2, &(0x7f0000019680)=""/102392, 0x18ff8) r3 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) r4 = ioctl$KVM_CREATE_VM(r3, 0xae01, 0x0) ioctl$KVM_SET_CLOCK(r4, 0x4188aec6, &(0x7f0000000040)) ioctl$KVM_SET_CLOCK(r4, 0x4188aec6, &(0x7f0000000040)={0x0, 0x8, 0x0, 0x95d}) r5 = syz_open_procfs(0x0, &(0x7f00000000c0)='loginuid\x00') r6 = socket$pppl2tp(0x18, 0x1, 0x1) ioctl$SIOCSIFMTU(r6, 0x8923, &(0x7f0000000040)={'vlan0\x00', 0x40}) read$midi(0xffffffffffffffff, 0x0, 0x43) r7 = openat$rdma_cm(0xffffffffffffff9c, 0x0, 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r7, 0x0, 0x0) r8 = syz_open_dev$rtc(&(0x7f0000000140), 0x0, 0x0) openat$nullb(0xffffffffffffff9c, 0x0, 0x121441, 0x0) ioctl$BLKDISCARD(r5, 0x125f, 0x0) ioctl$RTC_SET_TIME(r8, 0x40187013, 0x0) set_mempolicy(0x8006, &(0x7f0000000040)=0xfff, 0x5) 1.122353317s ago: executing program 1 (id=2629): socket$nl_route(0x10, 0x3, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000400)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) pipe(&(0x7f0000000280)={0xffffffffffffffff, 0xffffffffffffffff}) r4 = socket$inet(0x2b, 0x801, 0x0) splice(r4, 0x0, r3, 0x0, 0x5, 0x9) 286.350185ms ago: executing program 0 (id=2630): r0 = openat$ptp0(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) r1 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000000000)='net/snmp6\x00') getsockopt$inet_IP_IPSEC_POLICY(0xffffffffffffffff, 0x0, 0x10, 0x0, 0x0) read$FUSE(r1, &(0x7f0000006780)={0x2020}, 0x2020) r2 = getpid() prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) r3 = gettid() getpriority(0x1, r3) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r4 = getpid() sched_setscheduler(r4, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f000097f000/0x4000)=nil, 0x4000, 0xb635773f06ebbeee, 0x20010, 0xffffffffffffffff, 0x6b042000) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000340)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r5, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r6, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r5, &(0x7f00000000c0), 0x10106, 0x2, 0x0) mkdirat(0xffffffffffffff9c, 0x0, 0x0) geteuid() r7 = open_tree(0xffffffffffffff9c, &(0x7f0000000640)='\x00', 0x89901) fsconfig$FSCONFIG_SET_PATH(r7, 0x3, &(0x7f0000000100)='macvtap0\x00', &(0x7f0000000180)='./file0\x00', 0xffffffffffffff9c) connect$inet(0xffffffffffffffff, 0x0, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0xffffffba) r8 = socket$kcm(0x29, 0x5, 0x0) sendmsg$rds(r8, &(0x7f0000002940)={0x0, 0x0, &(0x7f0000002800)=[{&(0x7f0000002980)=""/4112, 0xfffffe09}], 0x1}, 0x0) bpf$ENABLE_STATS(0x20, 0x0, 0x0) sched_setscheduler(r2, 0x3, &(0x7f0000000200)=0x7) io_uring_register$IORING_REGISTER_SYNC_CANCEL(r7, 0x18, &(0x7f00000001c0)={0x2, r7, 0x0, {0xf, 0x101}, 0x68}, 0x1) prlimit64(0x0, 0x6, &(0x7f0000000040)={0x401, 0xdf}, &(0x7f0000000080)) ioctl$sock_inet_SIOCSIFADDR(r6, 0x8916, &(0x7f00000000c0)={'macvtap0\x00', {0x2, 0x4e22, @local}}) ioctl$PTP_SYS_OFFSET(r0, 0x40043d0d, 0xffffffffffffffff) 149.256916ms ago: executing program 1 (id=2631): syz_init_net_socket$bt_hci(0x1f, 0x3, 0x1) vmsplice(0xffffffffffffffff, 0x0, 0x0, 0x1) sched_setaffinity(0x0, 0x0, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f0000000300)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sendmsg(r1, &(0x7f0000000180)={0x0, 0x0, 0x0}, 0x0) sched_setattr(0x0, &(0x7f0000000100)={0x38, 0x5, 0x0, 0x0, 0x0, 0xb47, 0x9, 0x8, 0x80000001, 0x3}, 0x0) r2 = openat$ttyS3(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) r3 = socket$alg(0x26, 0x5, 0x0) bind$alg(r3, &(0x7f0000000200)={0x26, 'aead\x00', 0x0, 0x0, 'rfc7539esp(adiantum(lrw(serpent),aes-asm,ghash-ce-sync),sha512_m'}, 0x58) ioctl$TIOCMGET(r2, 0x541e, &(0x7f0000000040)) r4 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000040), 0x60240) ioctl$SNDRV_SEQ_IOCTL_SET_PORT_INFO(r4, 0xc0a85320, &(0x7f0000000180)={{0x80}, 'port0\x00', 0x7e, 0xa1c07, 0x6, 0x0, 0x100000}) r5 = epoll_create(0x101) epoll_ctl$EPOLL_CTL_ADD(r5, 0x1, r4, &(0x7f0000000080)={0x40000014}) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000ed07449e0000000000000000180100", @ANYRES32], 0x0, 0x0, 0x0, 0x0, 0x0, 0x45, '\x00', 0x0, @fallback=0x2b, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r6 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r6, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000080)=ANY=[@ANYBLOB="20010000120013070000000000000000e0000001000000000000000000000000fc00"/64, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="fc020000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000072c42572f64a264410b000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000fbc18c8582fc7800000000000000000000000050019000000000028001a"], 0x120}}, 0x0) openat$sequencer2(0xffffffffffffff9c, &(0x7f0000000140), 0x8417f, 0x0) socket$inet(0x2, 0x2, 0x0) rt_sigqueueinfo(0x0, 0xe, &(0x7f00000004c0)={0x22, 0x6, 0x7}) mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x0) mount$fuse(0x0, &(0x7f00000000c0)='./file0\x00', &(0x7f0000002100), 0x0, &(0x7f00000003c0)=ANY=[@ANYBLOB, @ANYRESOCT, @ANYRESDEC=0x0]) fsopen(&(0x7f0000000000)='autofs\x00', 0x0) r7 = socket$alg(0x26, 0x5, 0x0) bind$alg(r7, &(0x7f0000000000)={0x26, 'aead\x00', 0x0, 0x0, 'aegis128-generic\x00'}, 0x58) clock_settime(0x0, &(0x7f0000000000)={0x77359400}) 0s ago: executing program 2 (id=2632): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="1b00000000000000000000000000040000000000", @ANYRES32=0x0, @ANYBLOB="0000000000000500"/20, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB='\x00'/28], 0x48) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="040000000400000004"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000340)={0x11, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b70800000000e7057b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000001600000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000023c0)={0x0, 0x4, &(0x7f0000000480)=ANY=[@ANYBLOB="18020000660000000000"], 0x0, 0x7ff, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYRES64=r0, @ANYRESDEC=r2], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x40f00, 0x4, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000040)={&(0x7f0000000000)='sys_enter\x00', r3}, 0x18) io_setup(0x8, &(0x7f0000002740)=0x0) io_getevents(r4, 0x4, 0x13, &(0x7f0000000000), 0x0) r5 = socket$nl_generic(0x10, 0x3, 0x10) io_submit(r4, 0x1, &(0x7f0000000480)=[&(0x7f0000000880)={0x0, 0x0, 0x0, 0x7, 0x8, r5, 0x0, 0x0, 0x6}]) io_destroy(r4) r6 = socket$nl_netfilter(0x10, 0x3, 0xc) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x8, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="b40000000000000061104c000000000005000000000000009500000c000000000dee"], 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @cgroup_skb, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r7 = socket$netlink(0x10, 0x3, 0x0) ioctl$sock_SIOCGIFINDEX(r7, 0x8933, &(0x7f00000003c0)={'bridge0\x00', 0x0}) sendmsg$nl_route(r7, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000100)={&(0x7f00000002c0)=ANY=[@ANYBLOB="240000001d00070f000000000000000007000000", @ANYRES32=r8, @ANYBLOB='\x00\x00r\a\b\x00\b'], 0x24}, 0x1, 0x0, 0x0, 0x4000001}, 0x0) r9 = socket(0x2b, 0x80801, 0x1) shutdown(r9, 0xfffffffffffffffd) setsockopt$IPT_SO_SET_REPLACE(r9, 0x0, 0x40, &(0x7f0000000580)=@raw={'raw\x00', 0x8, 0x3, 0x3b0, 0x0, 0x43, 0xa0, 0x1d0, 0x98, 0x318, 0x178, 0x178, 0x318, 0x178, 0x49, 0x0, {[{{@ip={@loopback, @local, 0x0, 0x0, 'veth0_to_bond\x00', 'ip6erspan0\x00'}, 0x12a, 0x1b0, 0x1d0, 0x0, {0x0, 0x7a010000}, [@common=@inet=@recent0={{0xf8}, {0x0, 0x0, 0x8, 0x0, 'syz0\x00'}}, @common=@unspec=@helper={{0x48}, {0x0, 'ftp-20000\x00'}}]}, @unspec=@TRACE={0x20}}, {{@uncond, 0x0, 0xe8, 0x148, 0x0, {}, [@common=@unspec=@connbytes={{0x38}, {[{0xb}]}}, @common=@set={{0x40}, {{0x0, [0x0, 0x0, 0x0, 0x0, 0x0, 0x300]}}}]}, @common=@inet=@HMARK={0x60, 'HMARK\x00', 0x0, {@ipv4=@multicast1}}}], {{'\x00', 0x0, 0x70, 0x98}, {0x28, '\x00', 0x4}}}}, 0x410) r10 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='cpu.stat\x00', 0x275a, 0x0) write$UHID_CREATE2(r10, &(0x7f0000000180)=ANY=[], 0x118) mmap(&(0x7f0000000000/0x3000)=nil, 0x3000, 0x5, 0x12, r10, 0x0) r11 = socket(0x40000000015, 0x5, 0x0) sendto$inet(r11, 0x0, 0x0, 0x4000000, &(0x7f0000000200)={0x2, 0x0, @loopback}, 0x10) bind$bt_hci(r9, &(0x7f0000000080)={0x1f, 0x3, 0x2}, 0x6) sendmsg$NFT_BATCH(r6, &(0x7f000000c2c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000340)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101000000005e1affd5020000000900010073797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a30000000000900030073797a320000000014000000110001"], 0x7c}}, 0x0) sendmsg$NFT_BATCH(r6, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000007c0)=ANY=[@ANYBLOB="140000001000010000000000000000000a00000a70000000060a0b0400000000000000000200000244000480400001800b00010074617267657400003000028014000300e1a0b063bae294fe8f45a9b02fdf068408000240000000010d000100434f4e4e4d41524b000000000900010073797a30000000000900020073797a32"], 0x98}}, 0x0) kernel console output (not intermixed with test programs): socket [ 519.638820][ T6608] vhci_hcd: disconnect device [ 520.372916][T12930] (unnamed net_device) (uninitialized): option all_slaves_active: invalid value (220) [ 521.035060][T12934] overlayfs: failed to clone lowerpath [ 521.049059][T12936] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1822'. [ 521.080802][T12934] overlayfs: failed to clone lowerpath [ 521.348606][T12941] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 521.387833][T12941] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 521.563949][T12951] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1825'. [ 522.051619][ T30] audit: type=1400 audit(1748352403.652:1131): avc: denied { map } for pid=12949 comm="syz.4.1828" path="socket:[36403]" dev="sockfs" ino=36403 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_dgram_socket permissive=1 [ 522.432645][ T30] audit: type=1400 audit(1748352403.652:1132): avc: denied { accept } for pid=12949 comm="syz.4.1828" path="socket:[36403]" dev="sockfs" ino=36403 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_dgram_socket permissive=1 [ 522.529800][ T5918] usb 3-1: new high-speed USB device number 67 using dummy_hcd [ 522.868231][ T5918] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 523.060552][ T5918] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 523.259118][ T5918] usb 3-1: New USB device found, idVendor=046d, idProduct=c222, bcdDevice= 0.00 [ 523.436276][ T5918] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 524.370638][ T5918] usb 3-1: config 0 descriptor?? [ 524.430223][ T9] vhci_hcd: vhci_device speed not set [ 524.828954][T12976] overlayfs: failed to clone lowerpath [ 524.866307][T12976] overlayfs: failed to clone lowerpath [ 524.882978][ T5918] usbhid 3-1:0.0: can't add hid device: -71 [ 524.889117][ T5918] usbhid 3-1:0.0: probe with driver usbhid failed with error -71 [ 525.229887][ T5918] usb 3-1: USB disconnect, device number 67 [ 525.262770][T12987] 9pnet_fd: Insufficient options for proto=fd [ 525.349913][T12994] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1839'. [ 525.484670][T13001] netlink: 52 bytes leftover after parsing attributes in process `syz.1.1842'. [ 525.495399][T13001] netlink: 52 bytes leftover after parsing attributes in process `syz.1.1842'. [ 525.538852][ T30] audit: type=1804 audit(1748352407.502:1133): pid=13004 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=invalid_pcr cause=open_writers comm="syz.0.1841" name="/newroot/365/file0" dev="tmpfs" ino=1951 res=1 errno=0 [ 525.647527][T13011] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1843'. [ 525.669370][T13011] netdevsim netdevsim3 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 525.679069][T13011] netdevsim netdevsim3 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 525.688171][T13011] netdevsim netdevsim3 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 525.697015][T13011] netdevsim netdevsim3 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 525.709019][T13011] vxlan1: entered promiscuous mode [ 525.759644][ T5918] usb 5-1: new full-speed USB device number 75 using dummy_hcd [ 525.922814][ T5918] usb 5-1: config 0 has an invalid interface number: 8 but max is 0 [ 525.931447][ T5918] usb 5-1: config 0 has no interface number 0 [ 525.937875][ T5918] usb 5-1: config 0 interface 8 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 525.950085][ T5918] usb 5-1: config 0 interface 8 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 10 [ 525.961849][ T5918] usb 5-1: config 0 interface 8 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 525.973997][ T5918] usb 5-1: New USB device found, idVendor=0d8c, idProduct=000e, bcdDevice=8e.04 [ 525.984772][ T5918] usb 5-1: New USB device strings: Mfr=0, Product=24, SerialNumber=3 [ 525.993065][ T5918] usb 5-1: Product: syz [ 525.997587][ T5918] usb 5-1: SerialNumber: syz [ 526.010197][ T5918] usb 5-1: config 0 descriptor?? [ 526.023173][ T5918] cm109 5-1:0.8: invalid payload size 0, expected 4 [ 526.041094][ T5918] input: CM109 USB driver as /devices/platform/dummy_hcd.4/usb5/5-1/5-1:0.8/input/input23 [ 526.266878][T13002] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 526.276776][T13002] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 526.354047][ C0] cm109_urb_ctl_callback: 175 callbacks suppressed [ 526.354071][ C0] cm109 5-1:0.8: cm109_urb_ctl_callback: urb status -71 [ 526.354305][ T5894] usb 5-1: USB disconnect, device number 75 [ 526.360601][ C0] cm109 5-1:0.8: cm109_submit_buzz_toggle: usb_submit_urb (urb_ctl) failed -19 [ 526.485918][ T30] audit: type=1400 audit(1748352408.452:1134): avc: denied { ioctl } for pid=13013 comm="syz.2.1844" path="socket:[35801]" dev="sockfs" ino=35801 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 527.005699][ T5894] cm109 5-1:0.8: cm109_toggle_buzzer_sync: usb_control_msg() failed -19 [ 527.106517][T13028] netlink: 40 bytes leftover after parsing attributes in process `syz.0.1847'. [ 527.406953][T13033] tipc: Started in network mode [ 527.430824][T13033] tipc: Node identity ac141413, cluster identity 4711 [ 527.557288][T13033] tipc: Enabled bearer , priority 10 [ 527.887552][T13045] can0: slcan on ttyS3. [ 528.272195][T13040] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 528.339901][T13045] can0 (unregistered): slcan off ttyS3. [ 528.486703][T13040] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 528.549968][T13035] hsr0 speed is unknown, defaulting to 1000 [ 528.679654][ T5948] tipc: Node number set to 2886997011 [ 528.893844][T13035] lo speed is unknown, defaulting to 1000 [ 529.715773][T13056] SET target dimension over the limit! [ 530.338383][T13069] netlink: 48 bytes leftover after parsing attributes in process `syz.0.1856'. [ 530.609932][ T5948] usb 3-1: new high-speed USB device number 68 using dummy_hcd [ 530.929739][ T5948] usb 3-1: Using ep0 maxpacket: 16 [ 530.947716][ T5948] usb 3-1: config 1 interface 1 altsetting 1 endpoint 0x1 has an invalid bInterval 0, changing to 7 [ 530.963424][ T5948] usb 3-1: config 1 interface 1 altsetting 1 endpoint 0x1 has invalid wMaxPacketSize 0 [ 530.982115][ T5948] usb 3-1: config 1 interface 2 altsetting 1 endpoint 0x82 has an invalid bInterval 0, changing to 7 [ 531.570267][ T5948] usb 3-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 531.579344][ T5948] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 532.388680][ T5948] usb 3-1: Product: syz [ 532.399683][ T5948] usb 3-1: Manufacturer: syz [ 533.287425][T13089] hsr0 speed is unknown, defaulting to 1000 [ 533.541115][ T5948] usb 3-1: SerialNumber: syz [ 533.562872][T13097] overlayfs: overlapping lowerdir path [ 533.748151][T13089] lo speed is unknown, defaulting to 1000 [ 533.997487][ T5948] usb 3-1: can't set config #1, error -71 [ 534.879273][ T5948] usb 3-1: USB disconnect, device number 68 [ 535.583255][ T13] Bluetooth: hci5: Frame reassembly failed (-84) [ 537.287926][T13146] overlayfs: failed to clone lowerpath [ 537.295867][T13146] overlayfs: failed to clone lowerpath [ 537.640081][T12557] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 537.647976][ T5126] Bluetooth: hci5: command 0x1003 tx timeout [ 538.400929][T13182] netlink: 40 bytes leftover after parsing attributes in process `syz.0.1883'. [ 540.324132][T13198] overlayfs: failed to clone lowerpath [ 540.476875][T13198] overlayfs: failed to clone lowerpath [ 541.725144][ T30] audit: type=1804 audit(1748352423.232:1135): pid=13217 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=invalid_pcr cause=open_writers comm="syz.3.1893" name="file0" dev="tmpfs" ino=2353 res=1 errno=0 [ 541.969729][ C1] ip6_tunnel: ip6gre1 xmit: Local address not yet configured! [ 542.078263][T13230] SELinux: Context system_u:object_r:fsadm_ex is not valid (left unmapped). [ 542.184257][ T30] audit: type=1400 audit(1748352424.152:1136): avc: denied { relabelto } for pid=13228 comm="syz.1.1898" name="385" dev="tmpfs" ino=2085 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=dir permissive=1 trawcon="system_u:object_r:fsadm_ex" [ 542.204698][T13232] hsr0 speed is unknown, defaulting to 1000 [ 542.209980][ C1] vkms_vblank_simulate: vblank timer overrun [ 542.214605][ T30] audit: type=1400 audit(1748352424.152:1137): avc: denied { associate } for pid=13228 comm="syz.1.1898" name="385" dev="tmpfs" ino=2085 scontext=system_u:object_r:unlabeled_t tcontext=system_u:object_r:tmpfs_t tclass=filesystem permissive=1 srawcon="system_u:object_r:fsadm_ex" [ 542.248722][ C1] vkms_vblank_simulate: vblank timer overrun [ 542.808857][T13232] lo speed is unknown, defaulting to 1000 [ 545.480187][ T5894] usb 3-1: new full-speed USB device number 69 using dummy_hcd [ 545.943615][ T5894] usb 3-1: config 0 has an invalid interface number: 33 but max is 0 [ 545.956105][ T5894] usb 3-1: config 0 has no interface number 0 [ 546.018730][ T5894] usb 3-1: New USB device found, idVendor=2eca, idProduct=c101, bcdDevice=f6.9e [ 546.049905][ T30] audit: type=1400 audit(1748352427.992:1138): avc: denied { mount } for pid=13270 comm="syz.3.1908" name="/" dev="hugetlbfs" ino=38026 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=filesystem permissive=1 [ 546.122960][ T5894] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 546.147029][ T5894] usb 3-1: Product: syz [ 546.177784][ T5894] usb 3-1: Manufacturer: syz [ 546.188860][ T5894] usb 3-1: SerialNumber: syz [ 546.317538][ T5894] usb 3-1: config 0 descriptor?? [ 546.318218][ T30] audit: type=1400 audit(1748352428.282:1139): avc: denied { write } for pid=5808 comm="syz-executor" name="385" dev="tmpfs" ino=2085 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=dir permissive=1 trawcon="system_u:object_r:fsadm_ex" [ 546.365846][ T30] audit: type=1400 audit(1748352428.282:1140): avc: denied { remove_name } for pid=5808 comm="syz-executor" name="binderfs" dev="tmpfs" ino=2089 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=dir permissive=1 trawcon="system_u:object_r:fsadm_ex" [ 546.799176][ T30] audit: type=1400 audit(1748352428.292:1141): avc: denied { rmdir } for pid=5808 comm="syz-executor" name="385" dev="tmpfs" ino=2085 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=dir permissive=1 trawcon="system_u:object_r:fsadm_ex" [ 546.826875][ T5948] usb 3-1: USB disconnect, device number 69 [ 548.317548][T13302] overlayfs: failed to clone lowerpath [ 548.325520][T13302] overlayfs: failed to clone lowerpath [ 548.387723][T13310] xt_recent: hitcount (2147483647) is larger than allowed maximum (65535) [ 548.522936][ T30] audit: type=1326 audit(1748352430.482:1142): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f937678e969 code=0x7ffc0000 [ 548.548551][ T30] audit: type=1400 audit(1748352430.482:1143): avc: denied { getopt } for pid=13314 comm="syz.2.1922" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=llc_socket permissive=1 [ 548.581750][ T30] audit: type=1326 audit(1748352430.482:1144): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f937678e969 code=0x7ffc0000 [ 549.005013][ T30] audit: type=1326 audit(1748352430.512:1145): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f9376785927 code=0x7ffc0000 [ 549.040996][T13320] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1923'. [ 549.053156][ T30] audit: type=1326 audit(1748352430.512:1146): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f937672ab39 code=0x7ffc0000 [ 549.077171][ T30] audit: type=1326 audit(1748352430.512:1147): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=266 compat=0 ip=0x7f937678e969 code=0x7ffc0000 [ 549.101339][ T30] audit: type=1326 audit(1748352430.512:1148): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f937678e969 code=0x7ffc0000 [ 549.313016][ T30] audit: type=1326 audit(1748352430.512:1149): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f937678e969 code=0x7ffc0000 [ 549.341403][ T30] audit: type=1326 audit(1748352430.512:1150): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13311 comm="syz.3.1923" exe="/root/syz-executor" sig=0 arch=c000003e syscall=278 compat=0 ip=0x7f937678e969 code=0x7ffc0000 [ 549.524486][ T8214] Bluetooth: hci5: Frame reassembly failed (-84) [ 549.628981][T13328] xt_addrtype: ipv6 does not support BROADCAST matching [ 550.891729][T13350] overlayfs: failed to clone lowerpath [ 550.970527][T13348] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1928'. [ 550.981498][T13352] overlayfs: failed to clone lowerpath [ 551.023745][T13354] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1932'. [ 551.301897][T13364] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 551.314946][T13363] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1936'. [ 551.327561][T12557] Bluetooth: hci5: command 0x1003 tx timeout [ 551.334309][ T5126] Bluetooth: hci5: Opcode 0x1003 failed: -110 [ 551.574999][T13363] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1936'. [ 551.980841][T13385] overlayfs: failed to clone lowerpath [ 551.988445][T13385] overlayfs: failed to clone lowerpath [ 552.830095][ T30] kauditd_printk_skb: 92 callbacks suppressed [ 552.830113][ T30] audit: type=1800 audit(1748352434.792:1243): pid=13412 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=collect_data cause=failed(directio) comm="syz.3.1951" name="nullb0" dev="tmpfs" ino=1029 res=0 errno=0 [ 554.121561][T13423] overlayfs: failed to clone lowerpath [ 554.162082][T13423] overlayfs: failed to clone lowerpath [ 554.248186][ T30] audit: type=1326 audit(1748352436.212:1244): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13427 comm="syz.1.1959" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f2d14f8e969 code=0x0 [ 554.413678][T10659] netdevsim netdevsim4 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 554.516437][T12557] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 554.526291][T12557] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 554.534803][T12557] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 554.548643][T12557] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 554.558711][T12557] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 554.619768][T10659] netdevsim netdevsim4 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 554.660889][T13439] hsr0 speed is unknown, defaulting to 1000 [ 554.698537][T10659] netdevsim netdevsim4 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 554.794551][T10659] netdevsim netdevsim4 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 554.831634][T13439] lo speed is unknown, defaulting to 1000 [ 555.032242][T10659] bridge_slave_1: left allmulticast mode [ 555.052271][T10659] bridge_slave_1: left promiscuous mode [ 555.103294][T10659] bridge0: port 2(bridge_slave_1) entered disabled state [ 555.433463][T13449] overlayfs: failed to clone lowerpath [ 555.894353][T13452] overlayfs: failed to clone upperpath [ 555.908529][ T30] audit: type=1400 audit(1748352437.482:1245): avc: denied { prog_load } for pid=13445 comm="syz.1.1963" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bpf permissive=1 [ 555.912742][ T30] audit: type=1400 audit(1748352437.502:1246): avc: denied { map_create } for pid=13445 comm="syz.1.1963" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bpf permissive=1 [ 556.187812][T10659] bridge_slave_0: left allmulticast mode [ 556.187847][T10659] bridge_slave_0: left promiscuous mode [ 556.188013][T10659] bridge0: port 1(bridge_slave_0) entered disabled state [ 556.340447][ T30] audit: type=1400 audit(1748352438.302:1247): avc: denied { map_read map_write } for pid=13455 comm="syz.3.1965" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bpf permissive=1 [ 556.342935][ T30] audit: type=1400 audit(1748352438.312:1248): avc: denied { prog_run } for pid=13455 comm="syz.3.1965" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bpf permissive=1 [ 556.600037][T12557] Bluetooth: hci2: command tx timeout [ 557.742737][T10659] bond0 (unregistering): Released all slaves [ 557.833752][T10659] bond1 (unregistering): Released all slaves [ 557.851998][T13460] 8021q: adding VLAN 0 to HW filter on device ipvlan2 [ 557.859362][T13460] team0: Device ipvlan2 is already an upper device of the team interface [ 558.194232][T13485] xt_addrtype: ipv6 does not support BROADCAST matching [ 558.680151][T12557] Bluetooth: hci2: command tx timeout [ 558.761759][ T5948] usb 3-1: new low-speed USB device number 70 using dummy_hcd [ 559.307337][T13439] chnl_net:caif_netlink_parms(): no params data found [ 559.411709][T13511] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1974'. [ 559.437732][ T5948] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 10 [ 559.466604][ T5948] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 559.479811][ T5948] usb 3-1: New USB device found, idVendor=1038, idProduct=1410, bcdDevice= 0.00 [ 559.488874][ T5948] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 559.554092][ T5948] usb 3-1: config 0 descriptor?? [ 559.716042][T13511] geneve3: entered promiscuous mode [ 559.724817][T13511] geneve3: entered allmulticast mode [ 560.006718][ T5948] steelseries 0003:1038:1410.0019: unbalanced collection at end of report description [ 560.104850][T13439] bridge0: port 1(bridge_slave_0) entered blocking state [ 560.146661][T13439] bridge0: port 1(bridge_slave_0) entered disabled state [ 560.156013][T13439] bridge_slave_0: entered allmulticast mode [ 560.175720][T13439] bridge_slave_0: entered promiscuous mode [ 560.183706][ T5948] steelseries 0003:1038:1410.0019: parse failed [ 560.200688][T13486] ubi: mtd0 is already attached to ubi31 [ 560.207714][ T5948] steelseries 0003:1038:1410.0019: probe with driver steelseries failed with error -22 [ 560.750092][T10659] hsr_slave_0: left promiscuous mode [ 560.759697][T12557] Bluetooth: hci2: command tx timeout [ 560.765362][ T5948] usb 3-1: USB disconnect, device number 70 [ 560.782818][T10659] hsr_slave_1: left promiscuous mode [ 560.830236][T10659] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 560.837729][T10659] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 560.861212][T10659] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 560.879617][T10659] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 560.960393][T13538] xt_addrtype: ipv6 does not support BROADCAST matching [ 560.977570][T10659] veth1_macvtap: left promiscuous mode [ 561.257537][T10659] veth0_macvtap: left promiscuous mode [ 561.263556][T10659] veth1_vlan: left promiscuous mode [ 561.268990][T10659] veth0_vlan: left promiscuous mode [ 561.408939][T13547] netlink: 28 bytes leftover after parsing attributes in process `syz.0.1983'. [ 561.428247][ T30] audit: type=1400 audit(1748352443.392:1249): avc: denied { map } for pid=13546 comm="syz.0.1983" path="/dev/bus/usb/006/001" dev="devtmpfs" ino=736 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usb_device_t tclass=chr_file permissive=1 [ 561.485048][ T30] audit: type=1400 audit(1748352443.422:1250): avc: denied { connect } for pid=13546 comm="syz.0.1983" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 562.160244][T10659] team0 (unregistering): Port device team_slave_1 removed [ 562.250407][T10659] team0 (unregistering): Port device team_slave_0 removed [ 562.447654][ T1294] ieee802154 phy0 wpan0: encryption failed: -22 [ 562.650754][T10656] smc: removing ib device syz0 [ 562.656884][T13439] bridge0: port 2(bridge_slave_1) entered blocking state [ 562.665679][T13439] bridge0: port 2(bridge_slave_1) entered disabled state [ 562.676350][T13439] bridge_slave_1: entered allmulticast mode [ 562.688749][T13439] bridge_slave_1: entered promiscuous mode [ 562.764030][T13543] 8021q: adding VLAN 0 to HW filter on device ipvlan0 [ 562.787080][T13543] team0: Device ipvlan0 is already an upper device of the team interface [ 562.834084][ T9] lo speed is unknown, defaulting to 1000 [ 562.839807][T12557] Bluetooth: hci2: command tx timeout [ 562.851153][T13553] batadv1: entered promiscuous mode [ 562.852227][ T9] syz0: Port: 1 Link DOWN [ 563.311773][T13564] bond0: (slave team0): Releasing backup interface [ 563.602539][T13583] xt_addrtype: ipv6 does not support BROADCAST matching [ 564.057827][T13589] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=13529 sclass=netlink_route_socket pid=13589 comm=syz.2.1993 [ 564.076318][T13588] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=13529 sclass=netlink_route_socket pid=13588 comm=syz.2.1993 [ 564.627052][T13580] pim6reg: entered allmulticast mode [ 564.634483][T13584] pim6reg: left allmulticast mode [ 564.662806][T13439] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 564.684344][T13439] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 564.808575][T13439] team0: Port device team_slave_0 added [ 564.817593][T13439] team0: Port device team_slave_1 added [ 564.885380][T13601] team0: Device is already in use. [ 564.897612][T13439] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 564.919496][T13439] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 565.028257][T13439] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 565.073732][ T9] usb 3-1: new high-speed USB device number 71 using dummy_hcd [ 565.095438][T13439] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 565.114653][T13439] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 565.141185][T13439] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 565.233925][T13439] hsr_slave_0: entered promiscuous mode [ 565.247423][ T9] usb 3-1: device descriptor read/64, error -71 [ 565.254532][T13439] hsr_slave_1: entered promiscuous mode [ 565.284451][T13611] batadv_slave_1: entered promiscuous mode [ 565.473941][ T30] audit: type=1400 audit(1748352447.442:1251): avc: denied { map } for pid=13618 comm="syz.1.1999" path="socket:[37803]" dev="sockfs" ino=37803 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 565.507053][ T30] audit: type=1400 audit(1748352447.442:1252): avc: denied { read accept } for pid=13618 comm="syz.1.1999" path="socket:[37803]" dev="sockfs" ino=37803 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 565.536407][T13607] batadv_slave_1: left promiscuous mode [ 565.567414][ T9] usb 3-1: new high-speed USB device number 72 using dummy_hcd [ 565.570822][T13622] rdma_op ffff88804fcc09f0 conn xmit_rdma 0000000000000000 [ 565.604344][ T30] audit: type=1400 audit(1748352447.572:1253): avc: denied { node_bind } for pid=13625 comm="syz.3.2000" src=20002 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=sctp_socket permissive=1 [ 565.650815][ T30] audit: type=1400 audit(1748352447.612:1254): avc: denied { create } for pid=13625 comm="syz.3.2000" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_iscsi_socket permissive=1 [ 565.676728][ T30] audit: type=1400 audit(1748352447.612:1255): avc: denied { ioctl } for pid=13625 comm="syz.3.2000" path="socket:[37812]" dev="sockfs" ino=37812 ioctlcmd=0x8940 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_iscsi_socket permissive=1 [ 565.710224][ T9] usb 3-1: device descriptor read/64, error -71 [ 565.819249][T13439] netdevsim netdevsim5 netdevsim0: renamed from eth0 [ 565.833047][ T9] usb usb3-port1: attempt power cycle [ 565.835697][T13439] netdevsim netdevsim5 netdevsim1: renamed from eth1 [ 565.851245][T13633] xt_addrtype: ipv6 does not support BROADCAST matching [ 565.875608][T13439] netdevsim netdevsim5 netdevsim2: renamed from eth2 [ 565.899735][T13439] netdevsim netdevsim5 netdevsim3: renamed from eth3 [ 566.016717][T13439] 8021q: adding VLAN 0 to HW filter on device bond0 [ 566.048075][T13439] 8021q: adding VLAN 0 to HW filter on device team0 [ 566.064564][ T7256] bridge0: port 1(bridge_slave_0) entered blocking state [ 566.071715][ T7256] bridge0: port 1(bridge_slave_0) entered forwarding state [ 566.104113][ T7256] bridge0: port 2(bridge_slave_1) entered blocking state [ 566.111266][ T7256] bridge0: port 2(bridge_slave_1) entered forwarding state [ 566.193193][ T9] usb 3-1: new high-speed USB device number 73 using dummy_hcd [ 566.223875][ T9] usb 3-1: device descriptor read/8, error -71 [ 566.380577][T13439] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 566.486175][ T9] usb 3-1: new high-speed USB device number 74 using dummy_hcd [ 566.520280][ T9] usb 3-1: device descriptor read/8, error -71 [ 566.631990][ T9] usb usb3-port1: unable to enumerate USB device [ 566.689673][T13586] Bluetooth: hci0: Opcode 0x0c03 failed: -110 [ 566.762886][T13439] veth0_vlan: entered promiscuous mode [ 566.800760][T13439] veth1_vlan: entered promiscuous mode [ 566.840862][T13439] veth0_macvtap: entered promiscuous mode [ 566.916860][T13673] overlayfs: failed to clone lowerpath [ 567.336269][T13439] veth1_macvtap: entered promiscuous mode [ 567.366993][T13439] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 567.394430][T13439] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 567.414411][T13439] netdevsim netdevsim5 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 567.436404][T13439] netdevsim netdevsim5 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 567.445660][T13439] netdevsim netdevsim5 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 567.455667][T13439] netdevsim netdevsim5 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 567.720195][ T30] audit: type=1400 audit(1748352449.632:1256): avc: denied { setopt } for pid=13682 comm="syz.3.2005" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=qipcrtr_socket permissive=1 [ 568.377797][ T13] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 568.408533][ T13] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 568.483919][ T6608] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 568.510343][ T6608] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 568.537672][ T30] audit: type=1400 audit(1748352450.502:1257): avc: denied { mounton } for pid=13439 comm="syz-executor" path="/root/syzkaller.8tM6R0/syz-tmp/newroot/sys/kernel/debug" dev="debugfs" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:debugfs_t tclass=dir permissive=1 [ 568.699013][ T30] audit: type=1400 audit(1748352450.552:1258): avc: denied { mounton } for pid=13439 comm="syz-executor" path="/root/syzkaller.8tM6R0/syz-tmp/newroot/proc/sys/fs/binfmt_misc" dev="proc" ino=40252 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:sysctl_fs_t tclass=dir permissive=1 [ 568.814313][ T30] audit: type=1400 audit(1748352450.612:1259): avc: denied { mounton } for pid=13439 comm="syz-executor" path="/sys/fs/fuse/connections" dev="fusectl" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fusefs_t tclass=dir permissive=1 [ 569.118024][T13723] xt_addrtype: ipv6 does not support BROADCAST matching [ 569.880393][ T5948] usb 3-1: new high-speed USB device number 75 using dummy_hcd [ 570.405649][T13733] netlink: 'syz.1.2014': attribute type 1 has an invalid length. [ 570.420321][ T5948] usb 3-1: Using ep0 maxpacket: 32 [ 570.438138][ T5948] usb 3-1: config 0 has an invalid interface number: 1 but max is 0 [ 570.450334][ T5948] usb 3-1: config 0 has no interface number 0 [ 570.459215][ T5948] usb 3-1: New USB device found, idVendor=8086, idProduct=9500, bcdDevice=b6.d8 [ 570.516639][ T5948] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 570.527083][ T5948] usb 3-1: Product: syz [ 570.531500][ T5948] usb 3-1: Manufacturer: syz [ 570.536069][ T5948] usb 3-1: SerialNumber: syz [ 570.541891][ T5948] usb 3-1: config 0 descriptor?? [ 570.548460][ T5948] usb 3-1: dvb_usb_v2: found a 'Intel CE9500 reference design' in warm state [ 570.557296][ T5948] usb 3-1: selecting invalid altsetting 1 [ 570.563186][ T5948] usb 3-1: dvb_usb_ce6230: usb_set_interface() failed=-22 [ 570.573378][ T5948] usb 3-1: dvb_usb_v2: will pass the complete MPEG2 transport stream to the software demuxer [ 570.583674][ T5948] dvbdev: DVB: registering new adapter (Intel CE9500 reference design) [ 570.592144][ T5948] usb 3-1: media controller created [ 570.645716][T13736] hsr0 speed is unknown, defaulting to 1000 [ 570.687675][ T5948] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 570.787438][ T30] audit: type=1400 audit(1748352452.752:1260): avc: denied { append } for pid=13747 comm="syz.0.2017" name="sg0" dev="devtmpfs" ino=749 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 570.883258][ T30] audit: type=1400 audit(1748352452.752:1261): avc: denied { open } for pid=13747 comm="syz.0.2017" path="/dev/sg0" dev="devtmpfs" ino=749 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 570.919083][T13700] kvm: pic: single mode not supported [ 570.919271][T13700] kvm: pic: level sensitive irq not supported [ 570.945783][ T30] audit: type=1400 audit(1748352452.752:1262): avc: denied { ioctl } for pid=13747 comm="syz.0.2017" path="/dev/sg0" dev="devtmpfs" ino=749 ioctlcmd=0x227a scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 571.160928][T13755] hsr0 speed is unknown, defaulting to 1000 [ 572.118946][ T30] audit: type=1326 audit(1748352453.632:1263): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13763 comm="syz.1.2020" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f2d14f8e969 code=0x0 [ 572.149256][ T5948] usb 3-1: dvb_usb_ce6230: usb_control_msg() failed=-110 [ 572.150027][ T5948] zl10353_read_register: readreg error (reg=127, ret==-110) [ 572.226892][T13700] usb 3-1: dvb_usb_ce6230: usb_control_msg() failed=-32 [ 572.698110][T13775] fuse: Bad value for 'fd' [ 572.822737][ T5948] usb 3-1: USB disconnect, device number 75 [ 572.869099][ T30] audit: type=1400 audit(1748352454.822:1264): avc: denied { map } for pid=13771 comm="syz.0.2021" path="/dev/dri/card0" dev="devtmpfs" ino=627 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:dri_device_t tclass=chr_file permissive=1 [ 572.913623][T13775] fuse: Bad value for 'fd' [ 572.932903][ T30] audit: type=1400 audit(1748352454.822:1265): avc: denied { execute } for pid=13771 comm="syz.0.2021" path="/dev/dri/card0" dev="devtmpfs" ino=627 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:dri_device_t tclass=chr_file permissive=1 [ 574.057532][ T30] audit: type=1326 audit(1748352456.022:1266): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13803 comm="syz.1.2027" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f2d14f8e969 code=0x0 [ 574.089096][T13804] netlink: 8 bytes leftover after parsing attributes in process `syz.0.2026'. [ 574.098375][ T5948] usb 3-1: new high-speed USB device number 76 using dummy_hcd [ 574.260460][ T5948] usb 3-1: device descriptor read/64, error -71 [ 574.465357][T13823] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 574.530082][ T5948] usb 3-1: new high-speed USB device number 77 using dummy_hcd [ 574.690450][ T5948] usb 3-1: device descriptor read/64, error -71 [ 574.843512][ T5948] usb usb3-port1: attempt power cycle [ 575.296565][ T5948] usb 3-1: new high-speed USB device number 78 using dummy_hcd [ 575.341867][ T5948] usb 3-1: device descriptor read/8, error -71 [ 575.610076][ T5948] usb 3-1: new high-speed USB device number 79 using dummy_hcd [ 575.682451][ T5948] usb 3-1: device descriptor read/8, error -71 [ 575.799978][ T5948] usb usb3-port1: unable to enumerate USB device [ 576.521658][T13850] PKCS7: Unknown OID: [4] 0.0 [ 576.542361][T13850] PKCS7: Only support pkcs7_signedData type [ 578.049001][ T30] audit: type=1400 audit(1748352460.001:1267): avc: denied { getopt } for pid=13877 comm="syz.2.2041" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_netfilter_socket permissive=1 [ 578.224635][T13891] netlink: 10 bytes leftover after parsing attributes in process `syz.2.2045'. [ 578.539665][ T10] usb 6-1: new high-speed USB device number 2 using dummy_hcd [ 578.699915][ T10] usb 6-1: Using ep0 maxpacket: 32 [ 578.748588][ T10] usb 6-1: New USB device found, idVendor=0ac8, idProduct=0321, bcdDevice=6f.be [ 578.875951][ T10] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 578.945312][ T10] usb 6-1: config 0 descriptor?? [ 578.962757][ T10] gspca_main: vc032x-2.14.0 probing 0ac8:0321 [ 579.010803][T13910] netlink: 32 bytes leftover after parsing attributes in process `syz.1.2050'. [ 579.333016][T13923] IPVS: set_ctl: invalid protocol: 51 172.20.20.170:20004 [ 580.064441][ T30] audit: type=1400 audit(1748352462.021:1268): avc: denied { write } for pid=13937 comm="syz.3.2056" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 580.662446][T13957] netlink: 'syz.2.2058': attribute type 28 has an invalid length. [ 580.671154][T13957] netlink: 'syz.2.2058': attribute type 3 has an invalid length. [ 580.678899][T13957] netlink: 132 bytes leftover after parsing attributes in process `syz.2.2058'. [ 580.919902][ T10] gspca_vc032x: reg_w err -110 [ 581.156939][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.173818][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.181778][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.188182][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.199109][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.204792][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.211722][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.217175][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.226799][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.236923][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.255392][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.262444][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.267782][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.278134][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.287323][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.296423][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.302201][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.307588][ T10] gspca_vc032x: I2c Bus Busy Wait 00 [ 581.338250][ T10] gspca_vc032x: Unknown sensor... [ 581.384309][ T10] vc032x 6-1:0.0: probe with driver vc032x failed with error -22 [ 581.414756][ T30] audit: type=1400 audit(1748352463.361:1269): avc: denied { connect } for pid=13962 comm="syz.3.2059" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 581.904505][T13974] --map-set only usable from mangle table [ 582.353957][ T30] audit: type=1400 audit(1748352464.321:1270): avc: denied { connect } for pid=13985 comm="syz.2.2064" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 582.432163][T13986] XFS (nullb0): Invalid superblock magic number [ 583.496566][ T5948] usb 6-1: USB disconnect, device number 2 [ 584.304752][T14035] geneve4: entered promiscuous mode [ 584.310087][T14035] geneve4: entered allmulticast mode [ 584.325085][ T30] audit: type=1400 audit(1748352465.831:1271): avc: denied { listen } for pid=14029 comm="syz.1.2071" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_dgram_socket permissive=1 [ 585.419477][T14059] netlink: 88 bytes leftover after parsing attributes in process `syz.5.2078'. [ 585.891574][T14063] overlayfs: failed to clone lowerpath [ 585.908924][T14063] overlayfs: failed to clone lowerpath [ 586.115988][T14079] netlink: 40 bytes leftover after parsing attributes in process `syz.3.2082'. [ 588.596750][T14107] overlayfs: failed to clone upperpath [ 590.886182][T14137] 8021q: adding VLAN 0 to HW filter on device ipvlan2 [ 590.901221][T14137] team0: Device ipvlan2 is already an upper device of the team interface [ 592.733355][T14171] netlink: 24 bytes leftover after parsing attributes in process `syz.2.2100'. [ 593.826296][T14183] batadv1: entered promiscuous mode [ 594.135090][ T5948] usb 3-1: new high-speed USB device number 80 using dummy_hcd [ 594.296098][T14162] Bluetooth: hci1: Opcode 0x0c1a failed: -4 [ 594.302920][T14162] Bluetooth: hci1: Error when powering off device on rfkill (-4) [ 594.313090][T14162] Bluetooth: hci3: Opcode 0x0c1a failed: -4 [ 594.319061][T14162] Bluetooth: hci3: Error when powering off device on rfkill (-4) [ 594.328260][T14162] Bluetooth: hci4: Opcode 0x0c1a failed: -4 [ 594.334227][T14162] Bluetooth: hci4: Error when powering off device on rfkill (-4) [ 594.377369][ T5948] usb 3-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 594.435492][ T5948] usb 3-1: config 1 has an invalid descriptor of length 55, skipping remainder of the config [ 594.447754][ T5948] usb 3-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 594.457880][ T5948] usb 3-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 52, changing to 9 [ 594.469002][ T5948] usb 3-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 8241, setting to 1024 [ 594.481925][ T5948] usb 3-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 594.548138][T14162] Bluetooth: hci2: Opcode 0x0c1a failed: -4 [ 594.554324][T14162] Bluetooth: hci2: Error when powering off device on rfkill (-4) [ 594.581156][ T5948] usb 3-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 594.613312][T14200] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 594.622314][T14200] SELinux: failed to load policy [ 595.118592][ T5948] usb 3-1: Product: syz [ 595.123157][ T5948] usb 3-1: Manufacturer: syz [ 595.131997][ T5948] cdc_wdm 3-1:1.0: skipping garbage [ 595.137220][ T5948] cdc_wdm 3-1:1.0: skipping garbage [ 595.194387][ T5948] cdc_wdm 3-1:1.0: cdc-wdm0: USB WDM device [ 595.200388][ T5948] cdc_wdm 3-1:1.0: Unknown control protocol [ 595.286911][T14205] netlink: 'syz.1.2107': attribute type 2 has an invalid length. [ 595.359484][ T30] audit: type=1400 audit(1748352477.321:1272): avc: denied { read write } for pid=14187 comm="syz.2.2103" name="cdc-wdm0" dev="devtmpfs" ino=3310 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:modem_device_t tclass=chr_file permissive=1 [ 595.403556][T14188] netlink: 'syz.2.2103': attribute type 64 has an invalid length. [ 595.431301][T14188] netlink: 44 bytes leftover after parsing attributes in process `syz.2.2103'. [ 595.437222][ T30] audit: type=1400 audit(1748352477.321:1273): avc: denied { open } for pid=14187 comm="syz.2.2103" path="/dev/cdc-wdm0" dev="devtmpfs" ino=3310 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:modem_device_t tclass=chr_file permissive=1 [ 595.556432][T14222] netlink: 12 bytes leftover after parsing attributes in process `syz.0.2109'. [ 595.569939][T14222] netlink: 112 bytes leftover after parsing attributes in process `syz.0.2109'. [ 595.583044][ T30] audit: type=1400 audit(1748352477.451:1274): avc: denied { shutdown } for pid=14187 comm="syz.2.2103" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=isdn_socket permissive=1 [ 595.909606][ T5948] usb 6-1: new high-speed USB device number 4 using dummy_hcd [ 596.040635][ T5948] usb 6-1: device descriptor read/64, error -71 [ 596.114256][T14237] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 596.138414][T14239] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 596.441389][ T5948] usb 6-1: new high-speed USB device number 5 using dummy_hcd [ 596.619892][ T5948] usb 6-1: device descriptor read/64, error -71 [ 596.742279][ T5948] usb usb6-port1: attempt power cycle [ 596.904271][T13454] usb 3-1: USB disconnect, device number 80 [ 597.079795][ T5948] usb 6-1: new high-speed USB device number 6 using dummy_hcd [ 597.082644][T14273] SELinux: policydb string length -16777208 does not match expected length 8 [ 597.097121][T14273] SELinux: failed to load policy [ 597.121913][ T5948] usb 6-1: device descriptor read/8, error -71 [ 597.372366][T14278] overlayfs: failed to clone upperpath [ 597.380451][ T5948] usb 6-1: new high-speed USB device number 7 using dummy_hcd [ 597.383783][T14278] overlayfs: failed to clone upperpath [ 597.400500][T14278] /dev/nullb0: Can't lookup blockdev [ 597.430352][ T5948] usb 6-1: device descriptor read/8, error -71 [ 597.550243][ T5948] usb usb6-port1: unable to enumerate USB device [ 597.629006][T14283] overlayfs: failed to clone lowerpath [ 597.649272][T14283] overlayfs: failed to clone lowerpath [ 597.679825][ T10] usb 3-1: new high-speed USB device number 81 using dummy_hcd [ 598.253131][ T10] usb 3-1: config 0 has an invalid interface number: 132 but max is 3 [ 598.261566][ T10] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 598.272513][ T10] usb 3-1: config 0 has 1 interface, different from the descriptor's value: 4 [ 598.282932][ T10] usb 3-1: config 0 has no interface number 0 [ 598.289093][ T10] usb 3-1: config 0 interface 132 altsetting 181 has 0 endpoint descriptors, different from the interface descriptor's value: 11 [ 598.303652][ T10] usb 3-1: config 0 interface 132 has no altsetting 0 [ 598.318049][ T10] usb 3-1: New USB device found, idVendor=0fe9, idProduct=db71, bcdDevice=df.d9 [ 598.335167][ T10] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 598.343692][ T10] usb 3-1: Product: ъ [ 598.347817][ T10] usb 3-1: Manufacturer: ᡬ䂮৓䃱칽㯁痛갹숱꽉ڂ쟩⏋ꛬ㊤釤⨹盱읰ꨃ田퍲삝菐齊ⳏ㙓尵￀ﳚ▘隁﷤ꢬ稑鵰ﶔ簭⪩鑟⩐鳙䠮ண렟䙜 [ 598.373088][ T10] usb 3-1: SerialNumber: syz [ 598.384877][ T10] usb 3-1: config 0 descriptor?? [ 598.722627][ T10] dvb-usb: found a 'DViCO FusionHDTV DVB-T NANO2 w/o firmware' in warm state. [ 598.739871][ T10] usb 3-1: setting power ON [ 598.746755][ T10] dvb-usb: bulk message failed: -22 (2/0) [ 599.261196][ T10] dvb-usb: will pass the complete MPEG2 transport stream to the software demuxer. [ 599.284581][ T10] dvbdev: DVB: registering new adapter (DViCO FusionHDTV DVB-T NANO2 w/o firmware) [ 599.298841][ T10] usb 3-1: media controller created [ 599.323412][ T10] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 600.229856][ T10] cxusb: set interface failed [ 600.234929][ T10] dvb-usb: bulk message failed: -22 (1/0) [ 600.268161][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 600.287859][ T10] usb 3-1: bluebird_gpio_write failed. [ 600.299957][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 600.311994][ T10] usb 3-1: bluebird_gpio_write failed. [ 600.406686][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 600.929900][ T10] usb 3-1: bluebird_gpio_write failed. [ 600.938270][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 600.948132][ T10] usb 3-1: bluebird_gpio_write failed. [ 601.006159][ T5862] usb 6-1: new high-speed USB device number 8 using dummy_hcd [ 601.289876][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 601.380229][ T10] usb 3-1: bluebird_gpio_write failed. [ 601.410184][ T10] dvb-usb: bulk message failed: -22 (5/0) [ 601.439174][ T10] zl10353_read_register: readreg error (reg=127, ret==-121) [ 602.696941][ T5862] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x8E has invalid wMaxPacketSize 0 [ 602.949864][ T5862] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0xB has invalid wMaxPacketSize 0 [ 602.997447][ T10] DVB: Unable to find symbol mt352_attach() [ 603.009835][ T10] dvb-usb: no frontend was attached by 'DViCO FusionHDTV DVB-T NANO2 w/o firmware' [ 603.031165][ T5862] usb 6-1: New USB device found, idVendor=045e, idProduct=0283, bcdDevice=99.0b [ 603.104207][ T5862] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 603.112690][ T5862] usb 6-1: Product: syz [ 603.116870][ T5862] usb 6-1: Manufacturer: syz [ 603.122675][T14356] netlink: 12 bytes leftover after parsing attributes in process `syz.3.2137'. [ 603.128010][ T5862] usb 6-1: SerialNumber: syz [ 603.145746][ T5862] usb 6-1: config 0 descriptor?? [ 603.220204][ T10] rc_core: IR keymap rc-dvico-portable not found [ 603.237271][T14356] bridge0: port 4(batadv1) entered blocking state [ 603.245836][T14356] bridge0: port 4(batadv1) entered disabled state [ 603.254697][T14356] batadv1: entered allmulticast mode [ 603.255309][ T10] Registered IR keymap rc-empty [ 603.296522][T14356] batadv1: entered promiscuous mode [ 603.383746][T14373] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 603.441057][ T10] rc rc0: DViCO FusionHDTV DVB-T NANO2 w/o firmware as /devices/platform/dummy_hcd.2/usb3/3-1/rc/rc0 [ 603.514029][ T10] input: DViCO FusionHDTV DVB-T NANO2 w/o firmware as /devices/platform/dummy_hcd.2/usb3/3-1/rc/rc0/input24 [ 603.553648][ T5862] usb 6-1: USB disconnect, device number 8 [ 603.598441][ T10] dvb-usb: schedule remote query interval to 100 msecs. [ 603.637096][T10850] udevd[10850]: error opening ATTR{/sys/devices/platform/dummy_hcd.5/usb6/6-1/6-1:0.0/sound/card4/controlC4/../uevent} for writing: No such file or directory [ 603.652982][ T10] usb 3-1: setting power OFF [ 603.653003][ T10] dvb-usb: bulk message failed: -22 (2/0) [ 603.653033][ T10] dvb-usb: bulk message failed: -22 (3/0) [ 603.653047][ T10] usb 3-1: bluebird_gpio_write failed. [ 603.653057][ T10] dvb-usb: DViCO FusionHDTV DVB-T NANO2 w/o firmware successfully initialized and connected. [ 603.673494][ T10] usb 3-1: USB disconnect, device number 81 [ 603.686533][T14389] netlink: 20 bytes leftover after parsing attributes in process `syz.1.2142'. [ 603.725478][ T8214] batman_adv: batadv1: No IGMP Querier present - multicast optimizations disabled [ 603.734740][ T8214] batman_adv: batadv1: No MLD Querier present - multicast optimizations disabled [ 603.765872][ T5866] dvb-usb: bulk message failed: -22 (1/0) [ 603.887855][T14396] Failed to initialize the IGMP autojoin socket (err -2) [ 603.983897][ T5866] dvb-usb: bulk message failed: -22 (1/0) [ 604.589408][ T10] dvb-usb: DViCO FusionHDTV DVB-T NANO2 w/o firmwa successfully deinitialized and disconnected. [ 605.479693][ T10] usb 3-1: new high-speed USB device number 82 using dummy_hcd [ 605.639599][ T10] usb 3-1: device descriptor read/64, error -71 [ 605.901276][ T10] usb 3-1: new high-speed USB device number 83 using dummy_hcd [ 606.129957][ T10] usb 3-1: device descriptor read/64, error -71 [ 606.260296][ T10] usb usb3-port1: attempt power cycle [ 606.774578][ T10] usb usb3-port1: Cannot enable. Maybe the USB cable is bad? [ 606.953472][ T10] usb 3-1: new high-speed USB device number 85 using dummy_hcd [ 607.054615][ T10] usb 3-1: config 0 has an invalid interface number: 160 but max is 0 [ 607.078852][ T10] usb 3-1: config 0 has no interface number 0 [ 607.186783][T14488] Failed to initialize the IGMP autojoin socket (err -2) [ 607.194990][ T30] audit: type=1400 audit(1748352489.131:1275): avc: denied { sys_admin } for pid=14481 comm="syz.1.2161" capability=21 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=cap_userns permissive=1 [ 607.513496][ T10] usb 3-1: config 0 interface 160 altsetting 0 endpoint 0x5 has an invalid bInterval 0, changing to 7 [ 607.526628][ T10] usb 3-1: New USB device found, idVendor=05ac, idProduct=8501, bcdDevice=9e.4e [ 607.560848][ T10] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 607.568906][ T10] usb 3-1: Product: syz [ 607.573393][ T10] usb 3-1: Manufacturer: syz [ 607.577972][ T10] usb 3-1: SerialNumber: syz [ 607.584144][ T10] usb 3-1: config 0 descriptor?? [ 607.592698][ T10] usb 3-1: Found UVC 0.00 device syz (05ac:8501) [ 607.606114][ T10] usb 3-1: No valid video chain found. [ 607.966196][T14499] Failed to initialize the IGMP autojoin socket (err -2) [ 608.499848][ T30] audit: type=1400 audit(1748352490.431:1276): avc: denied { map } for pid=14470 comm="syz.2.2158" path="socket:[42295]" dev="sockfs" ino=42295 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 609.565127][T14516] netlink: 'syz.1.2166': attribute type 6 has an invalid length. [ 609.725494][T14514] overlayfs: failed to clone upperpath [ 609.798030][T14522] netlink: 8 bytes leftover after parsing attributes in process `syz.5.2167'. [ 610.365723][ T60] usb 3-1: USB disconnect, device number 85 [ 610.889889][ T5866] usb 6-1: new high-speed USB device number 9 using dummy_hcd [ 611.062925][ T5866] usb 6-1: Using ep0 maxpacket: 32 [ 611.076387][ T5866] usb 6-1: config 0 interface 0 has no altsetting 0 [ 611.106416][ T5866] usb 6-1: New USB device found, idVendor=16d0, idProduct=10b8, bcdDevice=de.8e [ 611.118752][ T5866] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 611.142484][ T5866] usb 6-1: Product: syz [ 611.146708][ T5866] usb 6-1: Manufacturer: syz [ 611.165809][ T5866] usb 6-1: SerialNumber: syz [ 611.214613][ T5866] usb 6-1: config 0 descriptor?? [ 611.223374][T14549] netlink: 220 bytes leftover after parsing attributes in process `syz.2.2174'. [ 611.707560][T14573] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(3) [ 611.714114][T14573] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 611.747898][ T5866] gs_usb 6-1:0.0: Configuring for 1 interfaces [ 611.774737][T14573] vhci_hcd vhci_hcd.0: Device attached [ 611.949128][T14538] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 611.979257][T14538] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 611.999835][ T30] audit: type=1326 audit(1748352493.971:1277): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14536 comm="syz.5.2172" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7fb9acd8e969 code=0x0 [ 612.029866][ T5862] usb 3-1: new high-speed USB device number 86 using dummy_hcd [ 612.051182][ T60] usb 37-1: new low-speed USB device number 4 using vhci_hcd [ 612.059184][ T30] audit: type=1400 audit(1748352494.021:1278): avc: denied { read } for pid=14536 comm="syz.5.2172" name="sg0" dev="devtmpfs" ino=749 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 612.060356][T14583] sd 0:0:1:0: device reset [ 612.269857][ T5862] usb 3-1: Using ep0 maxpacket: 16 [ 612.278781][ T5862] usb 3-1: New USB device found, idVendor=05d1, idProduct=2001, bcdDevice= 9.00 [ 612.290054][ T5862] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 612.298078][ T5862] usb 3-1: Product: syz [ 612.303079][ T5862] usb 3-1: Manufacturer: syz [ 612.307684][ T5862] usb 3-1: SerialNumber: syz [ 612.330436][ T5862] usb 3-1: config 0 descriptor?? [ 612.340800][ T5862] ftdi_sio 3-1:0.0: FTDI USB Serial Device converter detected [ 612.354542][ T5862] usb 3-1: Detected FT232H [ 612.758762][T14576] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 613.063183][T14576] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 613.080771][T14573] vhci_hcd vhci_hcd.0: pdev(2) rhport(1) sockfd(5) [ 613.087324][T14573] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 613.095792][T14573] vhci_hcd vhci_hcd.0: Device attached [ 613.155569][T14604] vhci_hcd: connection closed [ 613.156273][ T13] vhci_hcd: stop threads [ 613.170488][ T5862] ftdi_sio ttyUSB0: Unable to read latency timer: -71 [ 613.178177][T14574] vhci_hcd: connection reset by peer [ 613.189898][ T13] vhci_hcd: release socket [ 613.201069][ T5862] ftdi_sio ttyUSB0: Unable to write latency timer: -71 [ 613.213159][ T13] vhci_hcd: disconnect device [ 613.398797][ T5862] ftdi_sio 3-1:0.0: GPIO initialisation failed: -71 [ 613.406294][ T13] vhci_hcd: stop threads [ 613.416099][ T13] vhci_hcd: release socket [ 613.428841][ T13] vhci_hcd: disconnect device [ 613.434767][ T5862] usb 3-1: FTDI USB Serial Device converter now attached to ttyUSB0 [ 614.021318][ T5866] gs_usb 6-1:0.0: Couldn't get extended bit timing const for channel 0 (-ETIMEDOUT) [ 614.038433][ T5866] gs_usb 6-1:0.0: probe with driver gs_usb failed with error -110 [ 614.080113][ T5862] usb 3-1: USB disconnect, device number 86 [ 614.121444][T14618] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 614.131584][T14618] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 614.194545][ T5862] ftdi_sio ttyUSB0: FTDI USB Serial Device converter now disconnected from ttyUSB0 [ 614.223618][ T5948] usb 6-1: USB disconnect, device number 9 [ 614.230337][ T5862] ftdi_sio 3-1:0.0: device disconnected [ 614.618273][T14630] SELinux: ebitmap: truncated map [ 615.117444][ T30] audit: type=1400 audit(1748352496.651:1279): avc: denied { write } for pid=14634 comm="syz.5.2188" name="001" dev="devtmpfs" ino=721 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usb_device_t tclass=chr_file permissive=1 [ 615.156307][T14630] SELinux: failed to load policy [ 615.161676][ T30] audit: type=1400 audit(1748352497.111:1280): avc: denied { create } for pid=14643 comm="syz.2.2189" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 615.275686][T14657] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=38 sclass=netlink_audit_socket pid=14657 comm=syz.2.2191 [ 615.291864][T14657] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=28 sclass=netlink_audit_socket pid=14657 comm=syz.2.2191 [ 615.305051][T14657] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=51 sclass=netlink_audit_socket pid=14657 comm=syz.2.2191 [ 615.317985][T14657] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=256 sclass=netlink_audit_socket pid=14657 comm=syz.2.2191 [ 615.781578][ T30] audit: type=1400 audit(1748352497.751:1281): avc: denied { read write } for pid=14668 comm="syz.5.2195" name="fuse" dev="devtmpfs" ino=99 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fuse_device_t tclass=chr_file permissive=1 [ 616.083172][T14676] netlink: 8 bytes leftover after parsing attributes in process `syz.0.2193'. [ 616.092203][T14676] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2193'. [ 616.179423][ T30] audit: type=1400 audit(1748352497.771:1282): avc: denied { open } for pid=14668 comm="syz.5.2195" path="/dev/fuse" dev="devtmpfs" ino=99 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fuse_device_t tclass=chr_file permissive=1 [ 616.665890][ T13] tipc: Subscription rejected, illegal request [ 616.718879][ T30] audit: type=1400 audit(1748352498.661:1283): avc: denied { getopt } for pid=14681 comm="syz.2.2198" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 616.878141][T14695] netlink: 20 bytes leftover after parsing attributes in process `syz.0.2199'. [ 616.922839][T14696] netlink: 20 bytes leftover after parsing attributes in process `syz.0.2199'. [ 617.161529][T14705] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 617.171876][T14705] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 617.261167][ T60] vhci_hcd: vhci_device speed not set [ 618.183634][T14735] netlink: 8 bytes leftover after parsing attributes in process `syz.2.2207'. [ 618.229692][T14734] netlink: 12 bytes leftover after parsing attributes in process `syz.5.2208'. [ 619.025801][T14755] Failed to initialize the IGMP autojoin socket (err -2) [ 619.128091][ T30] audit: type=1400 audit(1748352501.091:1284): avc: denied { setattr } for pid=14751 comm="syz.2.2211" name="video0" dev="devtmpfs" ino=930 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:v4l_device_t tclass=chr_file permissive=1 [ 619.751235][ T30] audit: type=1400 audit(1748352501.711:1285): avc: denied { bind } for pid=14761 comm="syz.2.2213" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 619.791080][T14763] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2213'. [ 620.339220][T14768] openvswitch: netlink: IP tunnel attribute has 16 unknown bytes. [ 620.384355][T14771] netlink: 'syz.5.2215': attribute type 10 has an invalid length. [ 620.424372][T14768] /dev/nullb0: Can't lookup blockdev [ 620.685456][T14780] ubi: mtd0 is already attached to ubi31 [ 621.579576][ T9] usb 6-1: new high-speed USB device number 10 using dummy_hcd [ 621.803544][ T9] usb 6-1: Using ep0 maxpacket: 32 [ 621.845655][ T9] usb 6-1: config 1 interface 0 altsetting 3 endpoint 0x2 has an invalid bInterval 77, changing to 10 [ 621.871425][ T9] usb 6-1: config 1 interface 0 has no altsetting 0 [ 621.901608][ T9] usb 6-1: New USB device found, idVendor=1e7d, idProduct=2c24, bcdDevice= 0.40 [ 621.913025][ T9] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 621.947696][ T9] usb 6-1: Product: syz [ 621.963710][ T9] usb 6-1: Manufacturer: 닰䃦镫뼨殃䀢滛⚨퟇韎ꚸ墈♹䫲겎埣 ͘⿍㗌ᕼ굚ѓ㲘椸歨㴎⍷ק쫌瀨ᔋ䠛賠軞ൈDZ喴矋늗♨Ʉ틁׍孕ᣤ㣴䀔ᕤ﬛䦽淟刊碏̢ᆶ䦽ﺿ瞤㓆営タꁄ৑Ӟ떡焯ጂ䨠᱕狑⏗煞쑉ꞛꢁ霓篶়锯丱㠴喹ᵝ㔠衹蘣抪뷇韅△㗆䵠늂쿝⳺ [ 622.066721][ T9] usb 6-1: SerialNumber: syz [ 622.561124][T14788] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 622.602581][T14788] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 622.736568][ T9] usbhid 6-1:1.0: can't add hid device: -71 [ 622.817912][ T9] usbhid 6-1:1.0: probe with driver usbhid failed with error -71 [ 622.877366][ T9] usb 6-1: USB disconnect, device number 10 [ 623.896511][ T1294] ieee802154 phy0 wpan0: encryption failed: -22 [ 624.455960][ T30] audit: type=1400 audit(1748352506.421:1286): avc: denied { read append } for pid=14852 comm="syz.5.2235" name="ptp0" dev="devtmpfs" ino=1265 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 624.479706][ C0] vkms_vblank_simulate: vblank timer overrun [ 624.506318][T14853] block device autoloading is deprecated and will be removed. [ 624.546980][T14862] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2233'. [ 624.568576][T14865] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 624.744177][ T30] audit: type=1400 audit(1748352506.421:1287): avc: denied { open } for pid=14852 comm="syz.5.2235" path="/dev/ptp0" dev="devtmpfs" ino=1265 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 627.486492][T14910] netlink: 10 bytes leftover after parsing attributes in process `syz.2.2249'. [ 627.826914][ T30] audit: type=1400 audit(1748352509.791:1288): avc: denied { read write } for pid=14909 comm="syz.2.2249" name="uinput" dev="devtmpfs" ino=920 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 627.841734][T14912] mkiss: ax0: crc mode is auto. [ 627.917873][ T30] audit: type=1400 audit(1748352509.871:1289): avc: denied { open } for pid=14909 comm="syz.2.2249" path="/dev/uinput" dev="devtmpfs" ino=920 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 627.955681][ T30] audit: type=1400 audit(1748352509.911:1290): avc: denied { ioctl } for pid=14909 comm="syz.2.2249" path="/dev/uinput" dev="devtmpfs" ino=920 ioctlcmd=0x5501 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 628.193312][ T60] usb 3-1: new high-speed USB device number 87 using dummy_hcd [ 628.290755][T14928] 8021q: adding VLAN 0 to HW filter on device ipvlan2 [ 628.298126][T14928] team0: Device ipvlan2 is already an upper device of the team interface [ 628.352156][ T60] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 628.439085][T14932] A link change request failed with some changes committed already. Interface geneve0 may have been left with an inconsistent configuration, please check. [ 628.472958][ T60] usb 3-1: New USB device found, idVendor=045e, idProduct=0283, bcdDevice=99.0b [ 628.488229][ T60] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 628.498319][ T60] usb 3-1: Product: syz [ 628.506438][ T60] usb 3-1: Manufacturer: syz [ 628.513400][ T60] usb 3-1: SerialNumber: syz [ 628.524696][ T60] usb 3-1: config 0 descriptor?? [ 628.575644][ T60] snd-usb-audio 3-1:0.0: probe with driver snd-usb-audio failed with error -22 [ 628.661330][T14808] udevd[14808]: error opening ATTR{/sys/devices/platform/dummy_hcd.2/usb3/3-1/3-1:0.0/sound/card4/controlC4/../uevent} for writing: No such file or directory [ 628.779702][T14941] SELinux: policydb magic number 0x20 does not match expected magic number 0xf97cff8c [ 628.789663][T14941] SELinux: failed to load policy [ 629.943708][ T60] usb 3-1: USB disconnect, device number 87 [ 629.980343][ T30] audit: type=1400 audit(1748352511.941:1291): avc: denied { append } for pid=14951 comm="syz.5.2261" name="card1" dev="devtmpfs" ino=628 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:dri_device_t tclass=chr_file permissive=1 [ 630.019143][T14957] serio: Serial port ttyS3 [ 632.285754][T14994] netlink: 'syz.2.2272': attribute type 1 has an invalid length. [ 632.339862][ T5948] usb 6-1: new high-speed USB device number 11 using dummy_hcd [ 632.501293][ T5948] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 632.519935][ T5948] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 632.539562][ T5948] usb 6-1: New USB device found, idVendor=17ef, idProduct=6047, bcdDevice= 0.00 [ 632.551084][T15008] netlink: 4 bytes leftover after parsing attributes in process `syz.3.2277'. [ 632.559034][ T5948] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 632.580651][ T5948] usb 6-1: config 0 descriptor?? [ 632.831092][ T5948] usbhid 6-1:0.0: can't add hid device: -71 [ 632.848918][ T5948] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 632.909933][ T5948] usb 6-1: USB disconnect, device number 11 [ 633.628164][ T30] audit: type=1326 audit(1748352515.531:1292): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 633.940203][ T9] usb 3-1: new high-speed USB device number 88 using dummy_hcd [ 634.013021][ T30] audit: type=1326 audit(1748352515.531:1293): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.055969][ T30] audit: type=1326 audit(1748352515.541:1294): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=113 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.083898][T15050] Failed to initialize the IGMP autojoin socket (err -2) [ 634.103751][ T9] usb 3-1: config 1 interface 0 altsetting 44 endpoint 0x81 has an invalid bInterval 127, changing to 10 [ 634.113479][ T30] audit: type=1326 audit(1748352515.541:1295): auid=4294967295 uid=60929 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.146411][ T9] usb 3-1: config 1 interface 0 altsetting 44 bulk endpoint 0x82 has invalid maxpacket 8 [ 634.170369][ T9] usb 3-1: config 1 interface 0 altsetting 44 bulk endpoint 0x3 has invalid maxpacket 32 [ 634.213067][ T9] usb 3-1: config 1 interface 0 has no altsetting 0 [ 634.219440][ T30] audit: type=1326 audit(1748352515.541:1296): auid=4294967295 uid=60929 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.245062][ T30] audit: type=1326 audit(1748352515.541:1297): auid=4294967295 uid=60929 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=252 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.270114][ T30] audit: type=1326 audit(1748352515.541:1298): auid=4294967295 uid=60929 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.294256][ T30] audit: type=1326 audit(1748352515.541:1299): auid=4294967295 uid=60929 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.320349][ T9] usb 3-1: New USB device found, idVendor=0525, idProduct=a4a1, bcdDevice= 0.40 [ 634.348332][ T9] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 634.373661][ T9] usb 3-1: Product: syz [ 634.385137][ T9] usb 3-1: Manufacturer: syz [ 634.394167][ T9] usb 3-1: SerialNumber: syz [ 634.403020][ T30] audit: type=1326 audit(1748352515.541:1300): auid=4294967295 uid=60929 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15036 comm="syz.5.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=55 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 634.429191][T15040] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 634.452074][T15040] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 634.605965][T15072] netlink: 'syz.5.2294': attribute type 6 has an invalid length. [ 635.351636][ T9] usb 3-1: bad CDC descriptors [ 635.361075][ T9] usb 3-1: USB disconnect, device number 88 [ 635.810463][T15090] bridge2: entered promiscuous mode [ 636.436343][T15099] team0: Device is already in use. [ 637.557748][T15127] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 637.568071][T15127] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 638.213699][ T30] kauditd_printk_skb: 8 callbacks suppressed [ 638.213715][ T30] audit: type=1400 audit(1748352520.181:1309): avc: denied { bind } for pid=15138 comm="syz.5.2316" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=qipcrtr_socket permissive=1 [ 638.225547][T15142] Failed to initialize the IGMP autojoin socket (err -2) [ 639.264612][T15161] team0: Device is already in use. [ 639.281237][T15162] Failed to initialize the IGMP autojoin socket (err -2) [ 640.099882][ T5948] usb 3-1: new high-speed USB device number 89 using dummy_hcd [ 640.188148][T15190] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 640.198396][T15190] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 640.339554][ T5948] usb 3-1: Using ep0 maxpacket: 32 [ 640.352384][ T5948] usb 3-1: config 0 has an invalid interface number: 67 but max is 0 [ 640.361520][ T5948] usb 3-1: config 0 has no interface number 0 [ 640.382969][ T5948] usb 3-1: New USB device found, idVendor=0424, idProduct=9901, bcdDevice=c2.57 [ 640.431791][T15192] Failed to initialize the IGMP autojoin socket (err -2) [ 640.515781][ T5948] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 640.557611][ T5948] usb 3-1: Product: syz [ 640.588596][ T5948] usb 3-1: Manufacturer: syz [ 640.677291][ T5948] usb 3-1: SerialNumber: syz [ 640.761348][ T5948] usb 3-1: config 0 descriptor?? [ 640.768654][ T5948] smsc95xx v2.0.0 [ 640.816965][T15196] overlayfs: failed to clone lowerpath [ 640.837236][T15196] overlayfs: failed to clone lowerpath [ 640.895174][ T30] audit: type=1400 audit(1748352522.861:1310): avc: denied { write } for pid=15198 comm="syz.5.2335" name="sg0" dev="devtmpfs" ino=749 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 640.918815][ C0] vkms_vblank_simulate: vblank timer overrun [ 641.430152][ T30] audit: type=1326 audit(1748352523.391:1311): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15205 comm="syz.1.2337" exe="/root/syz-executor" sig=0 arch=c000003e syscall=157 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 641.478838][ T30] audit: type=1326 audit(1748352523.391:1312): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15205 comm="syz.1.2337" exe="/root/syz-executor" sig=0 arch=c000003e syscall=157 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 641.502340][ C0] vkms_vblank_simulate: vblank timer overrun [ 641.928238][ T30] audit: type=1326 audit(1748352523.391:1313): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15205 comm="syz.1.2337" exe="/root/syz-executor" sig=0 arch=c000003e syscall=157 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 641.951725][ C0] vkms_vblank_simulate: vblank timer overrun [ 641.995134][ T30] audit: type=1326 audit(1748352523.391:1314): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15205 comm="syz.1.2337" exe="/root/syz-executor" sig=0 arch=c000003e syscall=157 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 642.018601][ C0] vkms_vblank_simulate: vblank timer overrun [ 642.023884][T15174] CIFS mount error: No usable UNC path provided in device string! [ 642.023884][T15174] [ 642.040415][T15174] CIFS: VFS: CIFS mount error: No usable UNC path provided in device string! [ 642.133193][T15235] sp0: Synchronizing with TNC [ 642.256866][ T30] audit: type=1326 audit(1748352523.391:1315): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15205 comm="syz.1.2337" exe="/root/syz-executor" sig=0 arch=c000003e syscall=157 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 642.280370][ C0] vkms_vblank_simulate: vblank timer overrun [ 642.685430][T15243] workqueue: Failed to create a rescuer kthread for wq "ceph-completion": -EINTR [ 642.743251][ T5948] smsc95xx 3-1:0.67 (unnamed net_device) (uninitialized): Failed to read reg index 0x00000034: -71 [ 642.835072][ T5948] smsc95xx 3-1:0.67 (unnamed net_device) (uninitialized): Error reading E2P_DATA [ 642.877641][ T5948] smsc95xx 3-1:0.67 (unnamed net_device) (uninitialized): Failed to write reg index 0x00000014: -71 [ 642.894344][ T5948] smsc95xx 3-1:0.67: probe with driver smsc95xx failed with error -71 [ 643.077457][ T5948] usb 3-1: USB disconnect, device number 89 [ 643.519564][ T5862] usb 6-1: new high-speed USB device number 12 using dummy_hcd [ 643.689579][ T5862] usb 6-1: device descriptor read/64, error -71 [ 643.811672][T15271] bridge3: entered promiscuous mode [ 643.816900][T15271] bridge3: entered allmulticast mode [ 643.880514][ T30] audit: type=1400 audit(1748352525.851:1316): avc: denied { create } for pid=15275 comm="syz.2.2354" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=appletalk_socket permissive=1 [ 644.011582][ T30] audit: type=1400 audit(1748352525.921:1317): avc: denied { ioctl } for pid=15275 comm="syz.2.2354" path="/dev/cpu/0/msr" dev="devtmpfs" ino=87 ioctlcmd=0xff scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cpu_device_t tclass=chr_file permissive=1 [ 644.036536][ C0] vkms_vblank_simulate: vblank timer overrun [ 644.055668][ T5862] usb 6-1: new high-speed USB device number 13 using dummy_hcd [ 644.118960][T15282] netlink: 'syz.0.2355': attribute type 10 has an invalid length. [ 644.144919][T15282] bridge0: port 3(batadv0) entered disabled state [ 644.155957][T15282] batadv0: left allmulticast mode [ 644.161126][T15282] batadv0: left promiscuous mode [ 644.167002][T15282] bridge0: port 3(batadv0) entered disabled state [ 644.317638][T15282] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 644.331663][T15282] batadv0: entered allmulticast mode [ 644.338822][T15282] bond0: (slave batadv0): Enslaving as an active interface with an up link [ 644.541129][T15285] 9pnet: Found fid 0 not clunked [ 645.309642][ T5862] usb 6-1: device descriptor read/64, error -71 [ 646.068199][ T5862] usb usb6-port1: attempt power cycle [ 646.196086][T15300] netlink: 20 bytes leftover after parsing attributes in process `syz.5.2361'. [ 646.703227][T15310] netlink: 4 bytes leftover after parsing attributes in process `syz.3.2356'. [ 647.837338][T15316] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 648.823129][T15327] netlink: 32 bytes leftover after parsing attributes in process `syz.5.2366'. [ 649.051701][T15321] syz.5.2366 (15321): drop_caches: 2 [ 649.139855][T15321] syz.5.2366 (15321): drop_caches: 2 [ 650.171808][ T9] usb 6-1: new high-speed USB device number 15 using dummy_hcd [ 650.205835][T15348] netlink: 56 bytes leftover after parsing attributes in process `syz.5.2371'. [ 650.671549][T15369] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 650.681725][T15369] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 651.629798][T15391] netlink: 44 bytes leftover after parsing attributes in process `syz.1.2380'. [ 651.673758][T15393] netlink: 'syz.5.2379': attribute type 58 has an invalid length. [ 651.697487][T15393] netlink: 20 bytes leftover after parsing attributes in process `syz.5.2379'. [ 651.874334][T15393] PKCS8: Unsupported PKCS#8 version [ 652.095779][T15411] SELinux: security_context_str_to_sid (5] S9q#) failed with errno=-22 [ 652.427504][T15412] SELinux: policydb magic number 0x20 does not match expected magic number 0xf97cff8c [ 652.438127][T15412] SELinux: failed to load policy [ 654.142421][T15426] binder: 15423:15426 ioctl c0306201 200000000480 returned -14 [ 654.150359][ T30] audit: type=1400 audit(1748352536.111:1318): avc: denied { set_context_mgr } for pid=15423 comm="syz.2.2386" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=binder permissive=1 [ 654.679187][ T30] audit: type=1400 audit(1748352536.641:1319): avc: denied { call } for pid=15423 comm="syz.2.2386" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=binder permissive=1 [ 654.707663][ T30] audit: type=1400 audit(1748352536.671:1320): avc: denied { transfer } for pid=15423 comm="syz.2.2386" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=binder permissive=1 [ 656.798011][T15432] ALSA: mixer_oss: invalid index 40000 [ 657.207472][T15448] Failed to initialize the IGMP autojoin socket (err -2) [ 657.588068][T15455] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 657.598094][T15455] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 658.272727][T15463] netlink: 'syz.0.2396': attribute type 1 has an invalid length. [ 658.849721][T15469] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 658.873493][T15472] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 658.882879][T15463] bond1: entered promiscuous mode [ 658.903301][T15472] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 658.925361][T15463] 8021q: adding VLAN 0 to HW filter on device bond1 [ 659.109666][ T5862] usb 6-1: new high-speed USB device number 16 using dummy_hcd [ 659.152636][T15468] 8021q: adding VLAN 0 to HW filter on device bond1 [ 659.170424][T15468] bond1: (slave wireguard0): The slave device specified does not support setting the MAC address [ 659.188563][T15468] bond1: (slave wireguard0): Setting fail_over_mac to active for active-backup mode [ 659.289655][ T5862] usb 6-1: Using ep0 maxpacket: 32 [ 659.347445][ T5862] usb 6-1: config 0 has an invalid interface number: 184 but max is 0 [ 659.659791][T15468] wireguard: wireguard0: Could not create IPv4 socket [ 659.667203][T15468] bond1: (slave wireguard0): Opening slave failed [ 659.716896][ T5862] usb 6-1: config 0 has no interface number 0 [ 659.733216][ T5862] usb 6-1: config 0 interface 184 has no altsetting 0 [ 659.769764][ T5862] usb 6-1: New USB device found, idVendor=0424, idProduct=7500, bcdDevice=69.ee [ 659.779812][ T5862] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 659.788084][ T5862] usb 6-1: Product: syz [ 659.796665][ T5862] usb 6-1: Manufacturer: syz [ 659.863480][ T5862] usb 6-1: SerialNumber: syz [ 659.908543][ T5862] usb 6-1: config 0 descriptor?? [ 659.958256][ T5862] smsc75xx v1.0.0 [ 660.046990][T15481] A link change request failed with some changes committed already. Interface bond0 may have been left with an inconsistent configuration, please check. [ 660.213947][ T5862] smsc75xx 6-1:0.184 (unnamed net_device) (uninitialized): usbnet_get_endpoints failed: -71 [ 660.231872][ T5862] smsc75xx 6-1:0.184: probe with driver smsc75xx failed with error -71 [ 660.309219][T15487] netlink: 8 bytes leftover after parsing attributes in process `syz.3.2402'. [ 660.748458][ T5862] usb 6-1: USB disconnect, device number 16 [ 661.236387][T15501] Failed to initialize the IGMP autojoin socket (err -2) [ 663.563516][T15515] netlink: 8 bytes leftover after parsing attributes in process `syz.1.2410'. [ 663.638814][T15518] netlink: 80 bytes leftover after parsing attributes in process `syz.0.2409'. [ 663.648681][T15515] netlink: 12 bytes leftover after parsing attributes in process `syz.1.2410'. [ 663.648715][T15515] netlink: 'syz.1.2410': attribute type 13 has an invalid length. [ 663.838319][T15524] (unnamed net_device) (uninitialized): invalid ARP target 0.0.0.0 specified for addition [ 663.848799][T15524] (unnamed net_device) (uninitialized): option arp_ip_target: invalid value (0) [ 664.839721][ C1] ip6_tunnel: ip6gre1 xmit: Local address not yet configured! [ 665.724654][T15550] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=16 sclass=netlink_audit_socket pid=15550 comm=syz.5.2418 [ 665.737543][T15550] SELinux: unrecognized netlink message: protocol=9 nlmsg_type=17 sclass=netlink_audit_socket pid=15550 comm=syz.5.2418 [ 667.238475][T15553] Falling back ldisc for ttyprintk. [ 667.859863][ T10] usb 6-1: new high-speed USB device number 17 using dummy_hcd [ 668.557254][ T10] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 668.632665][ T10] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 668.669884][ T10] usb 6-1: New USB device found, idVendor=054c, idProduct=024b, bcdDevice= 0.00 [ 668.688659][ T10] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 668.940918][ T10] usb 6-1: config 0 descriptor?? [ 669.098766][T15577] binder: BINDER_SET_CONTEXT_MGR already set [ 669.106405][T15577] binder: 15575:15577 ioctl 4018620d 200000000040 returned -16 [ 669.510111][T15591] netlink: 'syz.1.2428': attribute type 21 has an invalid length. [ 669.517992][T15591] netlink: 'syz.1.2428': attribute type 20 has an invalid length. [ 669.526177][T15591] IPv6: NLM_F_CREATE should be specified when creating new route [ 669.591767][ T10] usbhid 6-1:0.0: can't add hid device: -71 [ 669.779273][T15592] binder: 15583:15592 ioctl c0306201 0 returned -14 [ 669.897075][ T10] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 669.908419][ T10] usb 6-1: USB disconnect, device number 17 [ 670.323948][ T30] audit: type=1400 audit(1748352552.291:1321): avc: denied { lock } for pid=15611 comm="syz.0.2434" path="socket:[45117]" dev="sockfs" ino=45117 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_stream_socket permissive=1 [ 670.347887][ C0] vkms_vblank_simulate: vblank timer overrun [ 670.824617][T15621] netlink: 4 bytes leftover after parsing attributes in process `syz.3.2435'. [ 670.836997][T15624] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(3) [ 670.839656][T15621] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 670.843513][T15624] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 670.874887][T15621] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 670.891158][T15621] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 670.899247][T15624] vhci_hcd vhci_hcd.0: Device attached [ 670.899254][T15627] vhci_hcd vhci_hcd.0: pdev(5) rhport(1) sockfd(6) [ 670.899275][T15627] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 670.910314][T15621] bridge0: port 3(batadv0) entered disabled state [ 670.926013][T15627] vhci_hcd vhci_hcd.0: Device attached [ 670.941808][T15621] bridge0: port 3(batadv0) entered disabled state [ 671.069603][ T5862] vhci_hcd: vhci_device speed not set [ 671.143307][ T5862] usb 43-1: new full-speed USB device number 2 using vhci_hcd [ 671.219675][ T10] usb 6-1: new high-speed USB device number 18 using dummy_hcd [ 671.477279][ T30] audit: type=1400 audit(1748352553.441:1322): avc: denied { read } for pid=15639 comm="syz.0.2441" name="file2" dev="tmpfs" ino=2502 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=blk_file permissive=1 [ 671.499829][ C0] vkms_vblank_simulate: vblank timer overrun [ 671.512958][ T10] usb 6-1: device descriptor read/64, error -71 [ 671.569769][ T5894] usb 3-1: new high-speed USB device number 90 using dummy_hcd [ 671.749900][ T5894] usb 3-1: Using ep0 maxpacket: 16 [ 671.814821][ T5894] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 671.846949][ T5894] usb 3-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 2 [ 671.903755][ T5894] usb 3-1: New USB device found, idVendor=1781, idProduct=0898, bcdDevice= 0.00 [ 671.945339][ T10] usb 6-1: new high-speed USB device number 19 using dummy_hcd [ 671.950535][ T5894] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 671.991850][ T5894] usb 3-1: config 0 descriptor?? [ 672.009659][ T5894] input: PXRC Flight Controller Adapter as /devices/platform/dummy_hcd.2/usb3/3-1/3-1:0.0/input/input26 [ 672.113372][ T10] usb 6-1: device descriptor read/64, error -71 [ 672.226660][T15634] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 672.245804][ T10] usb usb6-port1: attempt power cycle [ 672.266123][T15634] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 672.311903][ T5894] usb 3-1: USB disconnect, device number 90 [ 672.377758][T15666] Failed to initialize the IGMP autojoin socket (err -2) [ 672.609844][ T10] usb 6-1: new high-speed USB device number 20 using dummy_hcd [ 672.659138][ T10] usb 6-1: device descriptor read/8, error -71 [ 672.919615][ T10] usb 6-1: new high-speed USB device number 21 using dummy_hcd [ 672.977544][ T10] usb 6-1: device descriptor read/8, error -71 [ 673.109815][ T10] usb usb6-port1: unable to enumerate USB device [ 673.229348][T15682] netlink: 8 bytes leftover after parsing attributes in process `syz.2.2451'. [ 673.238671][T15682] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2451'. [ 673.414001][T15685] kAFS: No cell specified [ 673.479684][ T30] audit: type=1400 audit(1748352555.441:1323): avc: denied { create } for pid=15686 comm="syz.2.2453" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_connector_socket permissive=1 [ 673.653422][ T30] audit: type=1400 audit(1748352555.441:1324): avc: denied { bind } for pid=15686 comm="syz.2.2453" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_connector_socket permissive=1 [ 673.917790][ T30] audit: type=1400 audit(1748352555.771:1325): avc: denied { write } for pid=15686 comm="syz.2.2453" name="usbmon7" dev="devtmpfs" ino=737 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usbmon_device_t tclass=chr_file permissive=1 [ 673.972530][T15628] vhci_hcd: connection closed [ 673.974089][ T6608] vhci_hcd: stop threads [ 673.987078][T15625] vhci_hcd: connection reset by peer [ 674.007344][ T6608] vhci_hcd: release socket [ 674.019413][ T30] audit: type=1400 audit(1748352555.771:1326): avc: denied { open } for pid=15686 comm="syz.2.2453" path="/dev/usbmon7" dev="devtmpfs" ino=737 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usbmon_device_t tclass=chr_file permissive=1 [ 674.059692][ T6608] vhci_hcd: disconnect device [ 674.084862][ T6608] vhci_hcd: stop threads [ 674.089224][ T6608] vhci_hcd: release socket [ 674.095461][ T6608] vhci_hcd: disconnect device [ 674.102904][ T30] audit: type=1400 audit(1748352555.781:1327): avc: denied { ioctl } for pid=15686 comm="syz.2.2453" path="/dev/usbmon7" dev="devtmpfs" ino=737 ioctlcmd=0x940a scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usbmon_device_t tclass=chr_file permissive=1 [ 674.128215][ C0] vkms_vblank_simulate: vblank timer overrun [ 674.570134][T15706] netlink: 4 bytes leftover after parsing attributes in process `syz.1.2454'. [ 674.719658][ T10] usb 3-1: new high-speed USB device number 91 using dummy_hcd [ 674.883938][ T10] usb 3-1: New USB device found, idVendor=0cf3, idProduct=9271, bcdDevice= 1.08 [ 674.895573][ T10] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 674.905238][ T10] usb 3-1: Product: syz [ 674.910348][ T5894] usb 6-1: new high-speed USB device number 22 using dummy_hcd [ 674.912198][ T10] usb 3-1: Manufacturer: syz [ 674.926270][ T10] usb 3-1: SerialNumber: syz [ 674.941255][ T10] usb 3-1: ath9k_htc: Firmware ath9k_htc/htc_9271-1.4.0.fw requested [ 674.966096][ T5866] usb 3-1: ath9k_htc: Transferred FW: ath9k_htc/htc_9271-1.4.0.fw, size: 51008 [ 675.069567][ T5894] usb 6-1: Using ep0 maxpacket: 16 [ 675.077319][ T5894] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 675.094628][ T5894] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 675.119632][ T5894] usb 6-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 9 [ 675.140753][ T5894] usb 6-1: New USB device found, idVendor=045e, idProduct=07da, bcdDevice= 0.00 [ 675.151548][ T5894] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 675.162909][ T5894] usb 6-1: config 0 descriptor?? [ 675.551446][T15716] netlink: 'syz.0.2459': attribute type 3 has an invalid length. [ 675.584436][T15716] netlink: 'syz.0.2459': attribute type 1 has an invalid length. [ 675.599863][T15716] netlink: 224 bytes leftover after parsing attributes in process `syz.0.2459'. [ 675.602492][ T5894] microsoft 0003:045E:07DA.001A: unknown main item tag 0x0 [ 675.623731][T15716] NCSI netlink: No device for ifindex 0 [ 675.630058][ T5894] microsoft 0003:045E:07DA.001A: unknown main item tag 0x0 [ 675.665110][T15718] netlink: 'syz.1.2461': attribute type 9 has an invalid length. [ 675.685603][T15718] macvlan0: entered promiscuous mode [ 675.706894][ T5894] input: HID 045e:07da as /devices/platform/dummy_hcd.5/usb6/6-1/6-1:0.0/0003:045E:07DA.001A/input/input27 [ 675.728137][T15718] bond0: entered promiscuous mode [ 675.749288][T15718] 8021q: adding VLAN 0 to HW filter on device macvlan0 [ 675.775519][ T5894] microsoft 0003:045E:07DA.001A: input,hidraw0: USB HID v0.00 Device [HID 045e:07da] on usb-dummy_hcd.5-1/input0 [ 676.145423][ T5866] ath9k_htc 3-1:1.0: ath9k_htc: Target is unresponsive [ 676.163391][ T5894] usb 6-1: USB disconnect, device number 22 [ 676.175198][ T5866] ath9k_htc: Failed to initialize the device [ 676.201909][T15720] @: renamed from vlan0 (while UP) [ 676.245343][ T5866] usb 3-1: ath9k_htc: USB layer deinitialized [ 676.269852][ T5862] vhci_hcd: vhci_device speed not set [ 676.307890][T15722] fido_id[15722]: Failed to open report descriptor at '/sys/devices/platform/dummy_hcd.5/usb6/6-1/report_descriptor': No such file or directory [ 676.533510][ T5894] usb 3-1: USB disconnect, device number 91 [ 676.865941][T15742] netlink: 288 bytes leftover after parsing attributes in process `syz.3.2467'. [ 677.072615][T15746] kAFS: No cell specified [ 677.303127][T15758] loop6: detected capacity change from 0 to 7 [ 677.312077][T15758] buffer_io_error: 8 callbacks suppressed [ 677.312104][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.326976][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.335276][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.343960][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.352342][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.360565][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.369184][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.377282][T15758] ldm_validate_partition_table(): Disk read failed. [ 677.384120][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.392366][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.400699][T15758] Buffer I/O error on dev loop6, logical block 0, async page read [ 677.409073][T15758] Dev loop6: unable to read RDB block 0 [ 677.415959][T15758] loop6: unable to read partition table [ 677.422442][T15758] loop6: partition table beyond EOD, truncated [ 677.428660][T15758] loop_reread_partitions: partition scan of loop6 (被xڬdƤݡ [ 677.428660][T15758] ) failed (rc=-5) [ 677.444646][ T30] audit: type=1326 audit(1748352559.171:1328): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 677.484019][T15748] Failed to initialize the IGMP autojoin socket (err -2) [ 677.491673][ T30] audit: type=1326 audit(1748352559.171:1329): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 677.514672][T15759] openvswitch: netlink: IP tunnel attribute has 20 unknown bytes. [ 677.657926][ T30] audit: type=1326 audit(1748352559.181:1330): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=22 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.205806][ T30] audit: type=1326 audit(1748352559.181:1331): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.267990][ T30] audit: type=1326 audit(1748352559.181:1332): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.304412][ T30] audit: type=1326 audit(1748352559.181:1333): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=278 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.328089][ T30] audit: type=1326 audit(1748352559.181:1334): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.354834][ T30] audit: type=1326 audit(1748352559.181:1335): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.552857][ T30] audit: type=1326 audit(1748352559.191:1336): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=64 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 678.577173][ T30] audit: type=1326 audit(1748352559.191:1337): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15743 comm="syz.5.2469" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fb9acd8e969 code=0x7ffc0000 [ 679.711199][T15773] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 679.720654][T15773] SELinux: failed to load policy [ 680.034649][T15782] netdevsim netdevsim1 netdevsim0: entered promiscuous mode [ 680.042296][T15782] netdevsim netdevsim1 netdevsim0: entered allmulticast mode [ 680.285168][T15793] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2484'. [ 680.305082][T15793] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2484'. [ 680.741615][T15808] Invalid logical block size (1025) [ 680.789644][ T5862] usb 3-1: new high-speed USB device number 92 using dummy_hcd [ 681.179090][ T5862] usb 3-1: config 0 interface 0 has no altsetting 0 [ 681.236763][ T5862] usb 3-1: New USB device found, idVendor=0403, idProduct=bdc8, bcdDevice=a9.d7 [ 681.288212][ T5862] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 681.300199][ T5862] usb 3-1: config 0 descriptor?? [ 681.318529][ T5862] ftdi_sio 3-1:0.0: Ignoring interface reserved for JTAG [ 681.397074][T15821] netlink: 44 bytes leftover after parsing attributes in process `syz.3.2492'. [ 681.577564][T15825] No control pipe specified [ 681.664462][T15829] netlink: 48 bytes leftover after parsing attributes in process `syz.1.2494'. [ 681.674996][T15829] tmpfs: Bad value for 'mpol' [ 683.089100][ T30] kauditd_printk_skb: 2 callbacks suppressed [ 683.089116][ T30] audit: type=1400 audit(1748352565.051:1340): avc: denied { read } for pid=15863 comm="syz.1.2506" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_crypto_socket permissive=1 [ 683.629851][ T60] usb 3-1: USB disconnect, device number 92 [ 683.738958][T15877] netlink: 'syz.1.2509': attribute type 1 has an invalid length. [ 683.883763][T15882] mkiss: ax0: crc mode is auto. [ 684.259244][T15899] SELinux: policydb magic number 0x6c65732f does not match expected magic number 0xf97cff8c [ 684.291634][ T30] audit: type=1326 audit(1748352566.221:1341): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.315004][ C0] vkms_vblank_simulate: vblank timer overrun [ 684.321870][ T30] audit: type=1326 audit(1748352566.221:1342): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.444229][ T30] audit: type=1326 audit(1748352566.221:1343): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.452360][T15899] SELinux: failed to load policy [ 684.483994][ T30] audit: type=1326 audit(1748352566.221:1344): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.511075][ T30] audit: type=1326 audit(1748352566.221:1345): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.547858][T15906] netlink: 'syz.3.2518': attribute type 23 has an invalid length. [ 684.596423][ T30] audit: type=1326 audit(1748352566.221:1346): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.642836][T15893] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 684.651592][T15893] SELinux: failed to load policy [ 684.698740][ T30] audit: type=1326 audit(1748352566.251:1347): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 684.729974][ T30] audit: type=1326 audit(1748352566.251:1348): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7f489ef2ab39 code=0x7ffc0000 [ 684.779978][ T30] audit: type=1326 audit(1748352566.251:1349): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15890 comm="syz.0.2512" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 684.883720][T15911] fuse: Unknown parameter 'U' [ 685.110733][ T5866] usb 6-1: new high-speed USB device number 23 using dummy_hcd [ 685.202751][T15916] overlayfs: failed to resolve './bus': -2 [ 685.335300][ T1294] ieee802154 phy0 wpan0: encryption failed: -22 [ 685.340600][ T5866] usb 6-1: Using ep0 maxpacket: 8 [ 685.380970][ T5866] usb 6-1: config 0 has an invalid interface number: 122 but max is 0 [ 685.403987][ T5866] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 685.555473][ T5866] usb 6-1: config 0 has no interface number 0 [ 685.585500][ T5866] usb 6-1: config 0 interface 122 altsetting 0 endpoint 0xA has invalid maxpacket 512, setting to 64 [ 685.597474][ T5126] Bluetooth: hci5: unexpected cc 0x0c03 length: 249 > 1 [ 685.624751][ T5126] Bluetooth: hci5: unexpected cc 0x1003 length: 249 > 9 [ 685.637141][ T5126] Bluetooth: hci5: unexpected cc 0x1001 length: 249 > 9 [ 685.645938][ T5126] Bluetooth: hci5: unexpected cc 0x0c23 length: 249 > 4 [ 685.653832][ T5126] Bluetooth: hci5: unexpected cc 0x0c38 length: 249 > 2 [ 685.670619][T12557] Bluetooth: hci5: unexpected cc 0x0c03 length: 249 > 1 [ 685.677779][T12557] Bluetooth: hci5: unexpected cc 0x1003 length: 249 > 9 [ 685.688509][T12557] Bluetooth: hci5: unexpected cc 0x1001 length: 249 > 9 [ 685.696849][T12557] Bluetooth: hci5: unexpected cc 0x0c23 length: 249 > 4 [ 685.704973][T12557] Bluetooth: hci5: unexpected cc 0x0c38 length: 249 > 2 [ 685.722340][ T5866] usb 6-1: config 0 interface 122 altsetting 0 bulk endpoint 0x8 has invalid maxpacket 8 [ 685.759933][ T5866] usb 6-1: config 0 interface 122 altsetting 0 endpoint 0x88 has invalid wMaxPacketSize 0 [ 685.783230][ T5866] usb 6-1: config 0 interface 122 altsetting 0 bulk endpoint 0x88 has invalid maxpacket 0 [ 685.785241][T15919] Failed to initialize the IGMP autojoin socket (err -2) [ 685.793325][ T5866] usb 6-1: config 0 interface 122 altsetting 0 has 4 endpoint descriptors, different from the interface descriptor's value: 8 [ 685.817106][ T5866] usb 6-1: New USB device found, idVendor=1286, idProduct=2046, bcdDevice= 5.b7 [ 685.826461][ T5866] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 685.835252][ T5866] usb 6-1: Product: syz [ 685.839690][ T5866] usb 6-1: Manufacturer: syz [ 685.848141][ T5866] usb 6-1: SerialNumber: syz [ 685.862951][ T5866] usb 6-1: config 0 descriptor?? [ 685.869311][T15910] raw-gadget.1 gadget.5: fail, usb_ep_enable returned -22 [ 686.464179][T15910] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 686.679794][T15910] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 686.758171][ T5866] usb 6-1: NFC: intf ffff88806f4d9000 id ffffffff8f3442e0 [ 686.999340][ T5866] nfcmrvl 6-1:0.122: NFC: registered with nci successfully [ 687.076498][ T5866] usb 6-1: USB disconnect, device number 23 [ 687.114121][ T5866] usb 6-1: NFC: intf ffff88806f4d9000 [ 687.164995][T15944] netlink: 'syz.1.2527': attribute type 1 has an invalid length. [ 687.272126][T15944] 8021q: adding VLAN 0 to HW filter on device bond2 [ 687.462527][ T5862] usb 3-1: new high-speed USB device number 93 using dummy_hcd [ 687.472905][T10656] netdevsim netdevsim3 netdevsim3 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 687.485116][T10656] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 687.511876][T15947] vlan0: entered allmulticast mode [ 687.521637][T15947] bond2: (slave vlan0): making interface the new active one [ 687.530597][T15947] bond2: (slave vlan0): Enslaving as an active interface with an up link [ 687.534164][T15952] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 687.548025][T15952] SELinux: failed to load policy [ 687.673715][ T5862] usb 3-1: config index 0 descriptor too short (expected 45, got 36) [ 687.724914][ T5862] usb 3-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 687.799913][T12557] Bluetooth: hci5: command tx timeout [ 687.865070][ T5862] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 687.974031][ T5862] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 688.106004][ T5862] usb 3-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 688.124354][T10656] netdevsim netdevsim3 netdevsim2 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 688.227654][T10656] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 688.266842][ T5862] usb 3-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 688.313785][T15919] chnl_net:caif_netlink_parms(): no params data found [ 688.343124][ T5862] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 688.369416][ T5862] usb 3-1: config 0 descriptor?? [ 688.430168][T10656] netdevsim netdevsim3 netdevsim1 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 688.490250][T15975] netlink: 8 bytes leftover after parsing attributes in process `syz.5.2535'. [ 688.562712][T15975] openvswitch: netlink: nsh attr 0 has unexpected len 32764 expected 0 [ 688.634968][T15975] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 688.738949][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 688.800408][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 688.807678][T10656] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 688.828737][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 688.859917][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 688.888116][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 688.914769][T15977] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 688.924050][T15977] SELinux: failed to load policy [ 688.969138][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 689.068304][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 689.148686][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 689.222682][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 689.285673][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 689.309033][T10656] netdevsim netdevsim3 netdevsim0 (unregistering): left promiscuous mode [ 689.348679][ T5862] plantronics 0003:047F:FFFF.001B: unknown main item tag 0x0 [ 689.431940][ T5862] plantronics 0003:047F:FFFF.001B: No inputs registered, leaving [ 689.613967][ T5862] plantronics 0003:047F:FFFF.001B: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.2-1/input0 [ 689.879901][T12557] Bluetooth: hci5: command tx timeout [ 689.995927][ T5862] usb 3-1: USB disconnect, device number 93 [ 690.005583][T10656] netdevsim netdevsim3 netdevsim0 (unregistering): unset [0, 0] type 1 family 0 port 8472 - 0 [ 690.393607][T10656] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 690.399274][T15998] fido_id[15998]: Failed to open report descriptor at '/sys/devices/platform/dummy_hcd.2/usb3/3-1/report_descriptor': No such file or directory [ 690.670373][ T5948] usb 6-1: new full-speed USB device number 24 using dummy_hcd [ 690.739544][ T5862] usb 3-1: new high-speed USB device number 94 using dummy_hcd [ 690.851120][ T5948] usb 6-1: config 7 has an invalid interface number: 101 but max is 0 [ 690.859477][ T5948] usb 6-1: config 7 has no interface number 0 [ 690.884114][ T5948] usb 6-1: New USB device found, idVendor=0fd9, idProduct=002c, bcdDevice= 6.6b [ 690.893379][ T5862] usb 3-1: Using ep0 maxpacket: 32 [ 690.898845][ T5948] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 690.927535][ T5862] usb 3-1: config 0 has an invalid interface number: 184 but max is 0 [ 690.935409][T15919] bridge0: port 1(bridge_slave_0) entered blocking state [ 690.940219][ T5862] usb 3-1: config 0 has no interface number 0 [ 690.948982][ T5862] usb 3-1: config 0 interface 184 has no altsetting 0 [ 690.953598][T15919] bridge0: port 1(bridge_slave_0) entered disabled state [ 690.967400][T15919] bridge_slave_0: entered allmulticast mode [ 690.968629][ T5948] usb 6-1: Product: syz [ 690.979594][ T5948] usb 6-1: Manufacturer: syz [ 690.986382][T15919] bridge_slave_0: entered promiscuous mode [ 690.987943][ T5948] usb 6-1: SerialNumber: syz [ 691.001104][ T5862] usb 3-1: New USB device found, idVendor=0424, idProduct=7500, bcdDevice=69.ee [ 691.021015][ T5862] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 691.039676][ T5862] usb 3-1: Product: syz [ 691.045692][T15919] bridge0: port 2(bridge_slave_1) entered blocking state [ 691.049828][ T5862] usb 3-1: Manufacturer: syz [ 691.089661][ T5862] usb 3-1: SerialNumber: syz [ 691.096056][T15919] bridge0: port 2(bridge_slave_1) entered disabled state [ 691.116836][T15919] bridge_slave_1: entered allmulticast mode [ 691.119274][ T5862] usb 3-1: config 0 descriptor?? [ 691.134539][T15919] bridge_slave_1: entered promiscuous mode [ 691.178978][ T5862] smsc75xx v1.0.0 [ 691.353410][T15919] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 691.364336][T10656] batadv1: left allmulticast mode [ 691.369426][T10656] batadv1: left promiscuous mode [ 691.376378][T10656] bridge0: port 4(batadv1) entered disabled state [ 691.390595][T10656] bridge_slave_1: left allmulticast mode [ 691.396291][T10656] bridge_slave_1: left promiscuous mode [ 691.402365][T10656] bridge0: port 2(bridge_slave_1) entered disabled state [ 691.413924][T10656] bridge0: port 1(bridge_slave_0) entered disabled state [ 691.663864][T10656] dvmrp0 (unregistering): left allmulticast mode [ 691.701319][T16025] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 691.717197][T16025] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 691.925460][T10656] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 691.938973][T10656] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 691.953283][T10656] bond0 (unregistering): (slave team0): Releasing backup interface [ 691.959660][T12557] Bluetooth: hci5: command tx timeout [ 691.968054][T10656] bond0 (unregistering): Released all slaves [ 691.997108][ T5862] smsc75xx 3-1:0.184 (unnamed net_device) (uninitialized): Failed to read reg index 0x00000040: -32 [ 692.035124][ T5862] smsc75xx 3-1:0.184 (unnamed net_device) (uninitialized): Error reading E2P_CMD [ 692.046351][T15919] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 692.126115][T10656] tipc: Disabling bearer [ 692.138767][T10656] tipc: Left network mode [ 692.243682][T15919] team0: Port device team_slave_0 added [ 692.280156][T15919] team0: Port device team_slave_1 added [ 692.344168][T15919] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 692.354087][T15919] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 692.382972][T15919] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 692.395627][T15919] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 692.403418][T15919] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 692.429985][T15919] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 692.491890][ T5862] smsc75xx 3-1:0.184 (unnamed net_device) (uninitialized): Failed to write reg index 0x00000010: -71 [ 692.508352][ T5862] smsc75xx 3-1:0.184 (unnamed net_device) (uninitialized): Failed to write HW_CFG: -71 [ 692.519220][ T5862] smsc75xx 3-1:0.184 (unnamed net_device) (uninitialized): smsc75xx_reset error -71 [ 692.534515][ T5862] smsc75xx 3-1:0.184: probe with driver smsc75xx failed with error -71 [ 692.550774][ T5862] usb 3-1: USB disconnect, device number 94 [ 692.644364][T15919] hsr_slave_0: entered promiscuous mode [ 692.655174][T15919] hsr_slave_1: entered promiscuous mode [ 692.662680][T15919] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 692.670748][T15919] Cannot create hsr debugfs directory [ 692.845782][ T30] kauditd_printk_skb: 1395 callbacks suppressed [ 692.845798][ T30] audit: type=1326 audit(1748352574.811:2745): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 692.851200][ T5948] as10x_usb: device has been detected [ 692.862623][ T30] audit: type=1326 audit(1748352574.821:2746): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 692.915045][ T5948] dvbdev: DVB: registering new adapter (Elgato EyeTV DTT Deluxe) [ 692.918253][ T30] audit: type=1326 audit(1748352574.881:2747): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=16 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 692.946387][ C0] vkms_vblank_simulate: vblank timer overrun [ 692.968103][ T30] audit: type=1326 audit(1748352574.881:2748): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 693.001045][ T30] audit: type=1326 audit(1748352574.881:2749): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 693.286267][ T5948] usb 6-1: DVB: registering adapter 1 frontend 0 (Elgato EyeTV DTT Deluxe)... [ 693.375045][ T30] audit: type=1326 audit(1748352574.881:2750): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 693.756584][ T30] audit: type=1326 audit(1748352574.881:2751): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 693.780328][ C0] vkms_vblank_simulate: vblank timer overrun [ 693.841127][ T5866] usb 3-1: new high-speed USB device number 95 using dummy_hcd [ 694.071964][T12557] Bluetooth: hci5: command tx timeout [ 694.177916][ T5866] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 694.221638][ T30] audit: type=1326 audit(1748352574.881:2752): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 694.245142][ C0] vkms_vblank_simulate: vblank timer overrun [ 694.354963][ T5866] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 694.474193][ T30] audit: type=1326 audit(1748352574.881:2753): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 694.479796][ T5866] usb 3-1: New USB device found, idVendor=054c, idProduct=024b, bcdDevice= 0.00 [ 694.497765][ T30] audit: type=1326 audit(1748352574.881:2754): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16032 comm="syz.1.2546" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f2d14f8e969 code=0x7ffc0000 [ 694.530734][ C0] vkms_vblank_simulate: vblank timer overrun [ 694.610475][ T5948] as10x_usb: error during firmware upload part1 [ 694.627060][ T5948] Registered device Elgato EyeTV DTT Deluxe [ 694.632120][T16044] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 694.646521][T16044] SELinux: failed to load policy [ 694.664185][ T5948] usb 6-1: USB disconnect, device number 24 [ 694.809034][ T5866] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 694.905602][ T5866] usb 3-1: config 0 descriptor?? [ 695.008855][ T5948] Unregistered device Elgato EyeTV DTT Deluxe [ 695.039198][ T5948] as10x_usb: device has been disconnected [ 695.134132][T10656] hsr_slave_0: left promiscuous mode [ 695.149727][T10656] hsr_slave_1: left promiscuous mode [ 695.161989][T10656] veth0_macvtap: left promiscuous mode [ 695.375484][ T5866] sony 0003:054C:024B.001C: unexpected long global item [ 695.386053][ T5866] sony 0003:054C:024B.001C: parse failed [ 695.428695][ T5866] sony 0003:054C:024B.001C: probe with driver sony failed with error -22 [ 695.465177][T16064] overlayfs: failed to clone lowerpath [ 695.493244][T16064] overlayfs: failed to clone lowerpath [ 695.711880][T16040] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 695.720641][T16040] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 695.955518][T10656] team0 (unregistering): Port device team_slave_1 removed [ 696.053876][T10656] team0 (unregistering): Port device team_slave_0 removed [ 696.064512][ T6608] smc: removing ib device syz! [ 697.024576][T16066] 8021q: adding VLAN 0 to HW filter on device ipvlan2 [ 697.032241][T16066] team0: Device ipvlan2 is already an upper device of the team interface [ 697.057393][T16040] bridge0: port 1(syz_tun) entered blocking state [ 697.065233][T16040] bridge0: port 1(syz_tun) entered disabled state [ 697.071925][T16040] syz_tun: entered allmulticast mode [ 697.079156][T16040] syz_tun: entered promiscuous mode [ 697.086834][T16040] bridge0: port 1(syz_tun) entered blocking state [ 697.093723][T16040] bridge0: port 1(syz_tun) entered forwarding state [ 697.130888][ T5862] usb 3-1: USB disconnect, device number 95 [ 697.773427][T16082] SELinux: policydb table sizes (8,-2145189879) do not match mine (8,9) [ 697.782442][T16082] SELinux: failed to load policy [ 699.570173][T16102] overlayfs: failed to clone lowerpath [ 699.773154][T16102] overlayfs: failed to clone lowerpath [ 700.179759][ T5862] usb 3-1: new high-speed USB device number 96 using dummy_hcd [ 700.198956][T15919] netdevsim netdevsim3 netdevsim0: renamed from eth5 [ 700.349948][ T5862] usb 3-1: Using ep0 maxpacket: 16 [ 700.392640][ T5862] usb 3-1: config 0 has an invalid interface number: 4 but max is 0 [ 700.405375][ T5862] usb 3-1: config 0 has no interface number 0 [ 700.431795][ T5862] usb 3-1: config 0 interface 4 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 700.454043][ T5862] usb 3-1: config 0 interface 4 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 700.475596][T15919] netdevsim netdevsim3 netdevsim1: renamed from eth6 [ 700.498070][ T5862] usb 3-1: New USB device found, idVendor=6161, idProduct=4d15, bcdDevice= 0.00 [ 700.549104][ T5862] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 700.586956][ T5862] usb 3-1: config 0 descriptor?? [ 700.625179][T15919] netdevsim netdevsim3 netdevsim2: renamed from eth7 [ 700.882562][T15919] netdevsim netdevsim3 netdevsim3: renamed from eth8 [ 701.478254][ T5862] usb 3-1: USB disconnect, device number 96 [ 701.873733][T15919] 8021q: adding VLAN 0 to HW filter on device team0 [ 701.913997][T10659] bridge0: port 1(bridge_slave_0) entered blocking state [ 701.921162][T10659] bridge0: port 1(bridge_slave_0) entered forwarding state [ 702.119121][T10659] bridge0: port 2(bridge_slave_1) entered blocking state [ 702.126302][T10659] bridge0: port 2(bridge_slave_1) entered forwarding state [ 702.134045][ T5862] usb 6-1: new full-speed USB device number 25 using dummy_hcd [ 702.243365][T16153] Failed to initialize the IGMP autojoin socket (err -2) [ 702.346243][ T5862] usb 6-1: New USB device found, idVendor=0a46, idProduct=9621, bcdDevice=4f.32 [ 702.425402][ T5862] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 702.512266][ T5862] usb 6-1: Product: syz [ 702.561419][ T5862] usb 6-1: Manufacturer: syz [ 702.609161][ T5862] usb 6-1: SerialNumber: syz [ 702.626295][ T5862] usb 6-1: config 0 descriptor?? [ 703.013690][T16165] netlink: 4 bytes leftover after parsing attributes in process `syz.5.2577'. [ 703.050960][T16165] netlink: 24 bytes leftover after parsing attributes in process `syz.5.2577'. [ 703.117642][ T30] kauditd_printk_skb: 22 callbacks suppressed [ 703.117659][ T30] audit: type=1400 audit(1748352585.081:2777): avc: denied { ioctl } for pid=16146 comm="syz.5.2577" path="socket:[47055]" dev="sockfs" ino=47055 ioctlcmd=0x89ef scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=phonet_socket permissive=1 [ 703.139795][ T5815] usb 3-1: new full-speed USB device number 97 using dummy_hcd [ 703.369683][ T5815] usb 3-1: device descriptor read/64, error -71 [ 703.513759][T15919] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 703.695065][ T5815] usb 3-1: new full-speed USB device number 98 using dummy_hcd [ 703.839611][ T5815] usb 3-1: device descriptor read/64, error -71 [ 704.440584][ T5815] usb usb3-port1: attempt power cycle [ 704.846013][T16187] 8021q: adding VLAN 0 to HW filter on device ipvlan2 [ 704.853164][T16187] team0: Device ipvlan2 is already an upper device of the team interface [ 704.863511][ T5815] usb 3-1: new full-speed USB device number 99 using dummy_hcd [ 704.895652][T15919] veth0_vlan: entered promiscuous mode [ 704.902854][ T5815] usb 3-1: device descriptor read/8, error -71 [ 705.033313][T15919] veth1_vlan: entered promiscuous mode [ 705.250085][ T5815] usb 3-1: new full-speed USB device number 100 using dummy_hcd [ 705.400959][ T5815] usb 3-1: device descriptor read/8, error -71 [ 705.428681][T16194] netlink: 4 bytes leftover after parsing attributes in process `syz.1.2588'. [ 705.530685][ T5815] usb usb3-port1: unable to enumerate USB device [ 705.558670][ T5862] dm9601 6-1:0.0: probe with driver dm9601 failed with error -71 [ 705.564096][T15919] veth0_macvtap: entered promiscuous mode [ 705.604523][ T5862] usb 6-1: USB disconnect, device number 25 [ 705.646017][T15919] veth1_macvtap: entered promiscuous mode [ 705.674906][T16201] netlink: 8 bytes leftover after parsing attributes in process `syz.5.2591'. [ 705.698023][T16201] netlink: 16 bytes leftover after parsing attributes in process `syz.5.2591'. [ 705.915797][T15919] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 705.968697][T15919] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 706.021034][T15919] A link change request failed with some changes committed already. Interface geneve0 may have been left with an inconsistent configuration, please check. [ 706.074318][T15919] A link change request failed with some changes committed already. Interface geneve1 may have been left with an inconsistent configuration, please check. [ 706.093207][T15919] wireguard: wg0: Could not create IPv4 socket [ 706.103323][T15919] wireguard: wg1: Could not create IPv4 socket [ 706.112658][T15919] wireguard: wg2: Could not create IPv4 socket [ 706.339687][ T5894] usb 3-1: new high-speed USB device number 101 using dummy_hcd [ 706.514292][ T5894] usb 3-1: Using ep0 maxpacket: 32 [ 706.532951][ T5894] usb 3-1: New USB device found, idVendor=0c72, idProduct=000d, bcdDevice=27.9b [ 706.563072][ T5894] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 706.586356][ T5894] usb 3-1: Product: syz [ 706.603226][ T5894] usb 3-1: Manufacturer: syz [ 706.607887][ T5894] usb 3-1: SerialNumber: syz [ 706.636031][ T5894] usb 3-1: config 0 descriptor?? [ 706.765707][T16220] overlayfs: failed to clone lowerpath [ 706.784266][T16220] overlayfs: failed to clone lowerpath [ 706.809967][ T30] audit: type=1326 audit(1748352588.771:2778): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16221 comm="syz.0.2598" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 706.883112][ T30] audit: type=1326 audit(1748352588.771:2779): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16221 comm="syz.0.2598" exe="/root/syz-executor" sig=0 arch=c000003e syscall=127 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 706.946651][ T30] audit: type=1326 audit(1748352588.771:2780): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16221 comm="syz.0.2598" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 707.042831][ T30] audit: type=1326 audit(1748352588.771:2781): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16221 comm="syz.0.2598" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 707.051332][ T5894] peak_usb 3-1:0.0 can0: unable to request usb[type=0 value=1] err=-32 [ 707.075533][ T5894] peak_usb 3-1:0.0: unable to read PCAN-USB Pro firmware info (err -32) [ 707.088441][ T30] audit: type=1326 audit(1748352588.771:2782): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16221 comm="syz.0.2598" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 707.559194][ T30] audit: type=1326 audit(1748352588.771:2783): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=16221 comm="syz.0.2598" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f489ef8e969 code=0x7ffc0000 [ 707.610581][ T5894] peak_usb 3-1:0.0: probe with driver peak_usb failed with error -32 [ 708.273321][T16240] netlink: 24 bytes leftover after parsing attributes in process `syz.1.2602'. [ 708.324668][ T5126] Bluetooth: hci3: unexpected cc 0x0c03 length: 249 > 1 [ 708.334111][ T5126] Bluetooth: hci3: unexpected cc 0x1003 length: 249 > 9 [ 708.346486][ T5126] Bluetooth: hci3: unexpected cc 0x1001 length: 249 > 9 [ 708.355781][ T5126] Bluetooth: hci3: unexpected cc 0x0c23 length: 249 > 4 [ 708.364145][ T5126] Bluetooth: hci3: unexpected cc 0x0c38 length: 249 > 2 [ 708.427885][T16241] Failed to initialize the IGMP autojoin socket (err -2) [ 709.075951][ T9] usb 3-1: USB disconnect, device number 101 [ 709.193155][T16257] netlink: 20 bytes leftover after parsing attributes in process `syz.2.2609'. [ 710.281897][T16271] input: Bluetooth HID Boot Protocol Device as /devices/virtual/bluetooth/hci3/hci3:200/input28 [ 710.443431][T12557] Bluetooth: hci3: command tx timeout [ 710.993362][T16298] Failed to initialize the IGMP autojoin socket (err -2) [ 711.088823][T16241] netdevsim netdevsim3 netdevsim0: renamed from eth5 [ 711.231400][T16241] netdevsim netdevsim3 netdevsim1: renamed from eth6 [ 711.533660][T16241] netdevsim netdevsim3 netdevsim2: renamed from eth7 [ 712.208057][T16241] netdevsim netdevsim3 netdevsim3: renamed from eth8 [ 712.520169][T12557] Bluetooth: hci3: command tx timeout [ 712.967459][T16329] overlayfs: failed to clone lowerpath [ 712.988268][T16329] overlayfs: failed to clone lowerpath [ 713.520087][ T5815] usb 6-1: new high-speed USB device number 26 using dummy_hcd [ 713.590168][T16241] A link change request failed with some changes committed already. Interface geneve0 may have been left with an inconsistent configuration, please check. [ 713.646140][T16241] A link change request failed with some changes committed already. Interface geneve1 may have been left with an inconsistent configuration, please check. [ 713.690137][ T5815] usb 6-1: Using ep0 maxpacket: 16 [ 713.701992][T16241] wireguard: wg0: Could not create IPv4 socket [ 713.966074][T16241] wireguard: wg1: Could not create IPv4 socket [ 713.987549][T16241] wireguard: wg2: Could not create IPv4 socket [ 714.093608][T16350] @: renamed from vlan0 (while UP) [ 714.359205][ T30] audit: type=1400 audit(1748352596.321:2784): avc: denied { ioctl } for pid=16353 comm="syz.0.2630" path="/dev/ptp0" dev="devtmpfs" ino=1265 ioctlcmd=0x3d0d scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:clock_device_t tclass=chr_file permissive=1 [ 714.431227][ T5815] usb 6-1: unable to get BOS descriptor or descriptor too short [ 714.466258][ T5815] usb 6-1: unable to read config index 0 descriptor/start: -71 [ 714.486993][ T5815] usb 6-1: can't read configurations, error -71 [ 714.512722][T16364] netlink: 8 bytes leftover after parsing attributes in process `syz.1.2631'. [ 714.524763][T16364] fuse: Unknown parameter '0177777777777777777777700000000000000000000' [ 714.609846][ T30] audit: type=1400 audit(1748352596.481:2785): avc: denied { nlmsg_read } for pid=16355 comm="syz.1.2631" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 819.649363][ C0] rcu: INFO: rcu_preempt detected stalls on CPUs/tasks: [ 819.656338][ C0] rcu: 1-...!: (1 GPs behind) idle=e714/1/0x4000000000000000 softirq=86403/86406 fqs=86 [ 819.667341][ C0] rcu: (detected by 0, t=10502 jiffies, g=64485, q=132 ncpus=2) [ 819.675055][ C0] Sending NMI from CPU 0 to CPUs 1: [ 819.675078][ C1] NMI backtrace for cpu 1 [ 819.675091][ C1] CPU: 1 UID: 0 PID: 16358 Comm: syz.1.2631 Not tainted 6.15.0-syzkaller #0 PREEMPT(full) [ 819.675107][ C1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 819.675115][ C1] RIP: 0010:rcu_is_watching+0x5c/0xc0 [ 819.675136][ C1] Code: 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 5c 48 03 1c ed 20 0d cf 8d 48 b8 00 00 00 00 00 fc ff df 48 89 da 48 c1 ea 03 <0f> b6 14 02 48 89 d8 83 e0 07 83 c0 03 38 d0 7c 04 84 d2 75 24 8b [ 819.675149][ C1] RSP: 0018:ffffc90000a08e28 EFLAGS: 00000806 [ 819.675160][ C1] RAX: dffffc0000000000 RBX: ffff8880b8532de8 RCX: ffffffff81a87276 [ 819.675169][ C1] RDX: 1ffff110170a65bd RSI: ffffffff8bf4a420 RDI: ffffffff8dcf0d28 [ 819.675177][ C1] RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000 [ 819.675185][ C1] R10: 0000000000000001 R11: 0000000000000000 R12: ffff8880b8527840 [ 819.675193][ C1] R13: 0000000000000001 R14: ffff88804e697340 R15: 0000000000000001 [ 819.675201][ C1] FS: 00007f2d12dd56c0(0000) GS:ffff888124ada000(0000) knlGS:0000000000000000 [ 819.675215][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 819.675223][ C1] CR2: 0000200000025030 CR3: 000000005fcf7000 CR4: 00000000003526f0 [ 819.675232][ C1] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 819.675239][ C1] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 819.675247][ C1] Call Trace: [ 819.675253][ C1] [ 819.675259][ C1] __hrtimer_run_queues+0x7fe/0xad0 [ 819.675277][ C1] ? __pfx___hrtimer_run_queues+0x10/0x10 [ 819.675291][ C1] ? read_tsc+0x9/0x20 [ 819.675311][ C1] hrtimer_interrupt+0x397/0x8e0 [ 819.675331][ C1] __sysvec_apic_timer_interrupt+0x108/0x3f0 [ 819.675348][ C1] sysvec_apic_timer_interrupt+0x9f/0xc0 [ 819.675367][ C1] [ 819.675371][ C1] [ 819.675376][ C1] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 819.675391][ C1] RIP: 0010:_raw_spin_unlock_irqrestore+0x31/0x80 [ 819.675409][ C1] Code: f5 53 48 8b 74 24 10 48 89 fb 48 83 c7 18 e8 b6 43 28 f6 48 89 df e8 5e 97 28 f6 f7 c5 00 02 00 00 75 23 9c 58 f6 c4 02 75 37 01 00 00 00 e8 b5 03 19 f6 65 8b 05 fe 83 34 08 85 c0 74 16 5b [ 819.675435][ C1] RSP: 0018:ffffc9000dc77818 EFLAGS: 00000246 [ 819.675445][ C1] RAX: 0000000000000006 RBX: ffff8880299a61c0 RCX: 0000000000000006 [ 819.675453][ C1] RDX: 0000000000000000 RSI: ffffffff8dbe444d RDI: ffffffff8bf4a4a0 [ 819.675461][ C1] RBP: 0000000000000286 R08: 0000000000000001 R09: 0000000000000001 [ 819.675469][ C1] R10: ffffffff90853117 R11: 0000000000000000 R12: 0000000000000002 [ 819.675476][ C1] R13: ffff8880299a6030 R14: ffff8880299a6200 R15: ffff8880299a5ba8 [ 819.675493][ C1] __unix_dgram_recvmsg+0x326/0xee0 [ 819.675517][ C1] ? __pfx___unix_dgram_recvmsg+0x10/0x10 [ 819.675536][ C1] ? do_user_addr_fault+0x843/0x1370 [ 819.675551][ C1] ? __lock_acquire+0xaa4/0x1ba0 [ 819.675571][ C1] ? lockdep_hardirqs_on+0x7c/0x110 [ 819.675590][ C1] ? iovec_from_user+0xbb/0x140 [ 819.675611][ C1] unix_dgram_recvmsg+0xd0/0x110 [ 819.675630][ C1] ____sys_recvmsg+0x5f9/0x6b0 [ 819.675651][ C1] ? __pfx_____sys_recvmsg+0x10/0x10 [ 819.675678][ C1] ? kfree+0x252/0x4d0 [ 819.675698][ C1] ___sys_recvmsg+0x114/0x1a0 [ 819.675713][ C1] ? __pfx____sys_recvmsg+0x10/0x10 [ 819.675734][ C1] ? __pfx___might_resched+0x10/0x10 [ 819.675753][ C1] do_recvmmsg+0x2fe/0x740 [ 819.675769][ C1] ? __pfx_do_recvmmsg+0x10/0x10 [ 819.675782][ C1] ? lock_vma_under_rcu+0x47d/0x970 [ 819.675801][ C1] ? cgroup_rstat_updated+0x2a/0xb20 [ 819.675823][ C1] ? find_held_lock+0x2b/0x80 [ 819.675839][ C1] __x64_sys_recvmmsg+0x22a/0x280 [ 819.675855][ C1] ? __pfx___x64_sys_recvmmsg+0x10/0x10 [ 819.675873][ C1] do_syscall_64+0xcd/0x260 [ 819.675892][ C1] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 819.675905][ C1] RIP: 0033:0x7f2d14f8e969 [ 819.675916][ C1] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 819.675928][ C1] RSP: 002b:00007f2d12dd5038 EFLAGS: 00000246 ORIG_RAX: 000000000000012b [ 819.675940][ C1] RAX: ffffffffffffffda RBX: 00007f2d151b6080 RCX: 00007f2d14f8e969 [ 819.675948][ C1] RDX: 0000000000010106 RSI: 00002000000000c0 RDI: 0000000000000003 [ 819.675956][ C1] RBP: 00007f2d15010ab1 R08: 0000000000000000 R09: 0000000000000000 [ 819.675964][ C1] R10: 0000000000000002 R11: 0000000000000246 R12: 0000000000000000 [ 819.675972][ C1] R13: 0000000000000001 R14: 00007f2d151b6080 R15: 00007ffdfde060d8 [ 819.675986][ C1] [ 819.676073][ C0] rcu: rcu_preempt kthread starved for 10330 jiffies! g64485 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0 [ 820.133180][ C0] rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior. [ 820.143143][ C0] rcu: RCU grace-period kthread stack dump: [ 820.149032][ C0] task:rcu_preempt state:R running task stack:27304 pid:16 tgid:16 ppid:2 task_flags:0x208040 flags:0x00004000 [ 820.162540][ C0] Call Trace: [ 820.165822][ C0] [ 820.168755][ C0] __schedule+0x116f/0x5de0 [ 820.173281][ C0] ? __pfx___schedule+0x10/0x10 [ 820.178139][ C0] ? find_held_lock+0x2b/0x80 [ 820.182816][ C0] ? schedule+0x2d7/0x3a0 [ 820.187147][ C0] schedule+0xe7/0x3a0 [ 820.191217][ C0] schedule_timeout+0x123/0x290 [ 820.196067][ C0] ? __pfx_schedule_timeout+0x10/0x10 [ 820.201434][ C0] ? __pfx_process_timeout+0x10/0x10 [ 820.206724][ C0] ? _raw_spin_unlock_irqrestore+0x3b/0x80 [ 820.212533][ C0] ? prepare_to_swait_event+0xf5/0x480 [ 820.217999][ C0] rcu_gp_fqs_loop+0x1ea/0xb00 [ 820.222769][ C0] ? __pfx_rcu_gp_fqs_loop+0x10/0x10 [ 820.228060][ C0] ? rcu_gp_cleanup+0x7c1/0xd90 [ 820.232924][ C0] rcu_gp_kthread+0x270/0x380 [ 820.237606][ C0] ? __pfx_rcu_gp_kthread+0x10/0x10 [ 820.242804][ C0] ? rcu_is_watching+0x12/0xc0 [ 820.247564][ C0] ? lockdep_hardirqs_on+0x7c/0x110 [ 820.252766][ C0] ? __kthread_parkme+0x19e/0x250 [ 820.257792][ C0] ? __pfx_rcu_gp_kthread+0x10/0x10 [ 820.262994][ C0] kthread+0x3c2/0x780 [ 820.267063][ C0] ? __pfx_kthread+0x10/0x10 [ 820.271646][ C0] ? __pfx_kthread+0x10/0x10 [ 820.276231][ C0] ? __pfx_kthread+0x10/0x10 [ 820.280813][ C0] ? __pfx_kthread+0x10/0x10 [ 820.285395][ C0] ? rcu_is_watching+0x12/0xc0 [ 820.290162][ C0] ? __pfx_kthread+0x10/0x10 [ 820.294750][ C0] ret_from_fork+0x45/0x80 [ 820.299160][ C0] ? __pfx_kthread+0x10/0x10 [ 820.303743][ C0] ret_from_fork_asm+0x1a/0x30 [ 820.308521][ C0] [ 820.311531][ C0] rcu: Stack dump where RCU GP kthread last ran: [ 820.317846][ C0] CPU: 0 UID: 0 PID: 13439 Comm: syz-executor Not tainted 6.15.0-syzkaller #0 PREEMPT(full) [ 820.327988][ C0] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 820.338033][ C0] RIP: 0010:smp_call_function_many_cond+0x4af/0x1290 [ 820.344706][ C0] Code: 48 48 8b 44 24 20 49 89 c4 83 e0 07 49 c1 ec 03 48 89 c5 4d 01 f4 83 c5 03 e8 7d 17 0c 00 f3 90 41 0f b6 04 24 40 38 c5 7c 08 <84> c0 0f 85 de 0b 00 00 8b 43 08 31 ff 83 e0 01 41 89 c5 89 c6 e8 [ 820.364307][ C0] RSP: 0000:ffffc9001cecf968 EFLAGS: 00000206 [ 820.370367][ C0] RAX: 0000000000000000 RBX: ffff8880b853f740 RCX: ffffffff81af2e99 [ 820.378346][ C0] RDX: ffff88807f422440 RSI: ffffffff81af2e73 RDI: 0000000000000005 [ 820.386326][ C0] RBP: 0000000000000003 R08: 0000000000000005 R09: 0000000000000000 [ 820.394308][ C0] R10: 0000000000000001 R11: 0000000000000000 R12: ffffed10170a7ee9 [ 820.402279][ C0] R13: 0000000000000001 R14: dffffc0000000000 R15: ffff8880b843b040 [ 820.410244][ C0] FS: 00005555925d5500(0000) GS:ffff8881249da000(0000) knlGS:0000000000000000 [ 820.419690][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 820.426270][ C0] CR2: 00005555925f05c8 CR3: 000000006a2a9000 CR4: 00000000003526f0 [ 820.434235][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 820.442196][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 820.450160][ C0] Call Trace: [ 820.453438][ C0] [ 820.456378][ C0] ? __pfx_flush_tlb_func+0x10/0x10 [ 820.461610][ C0] ? __pfx_should_flush_tlb+0x10/0x10 [ 820.466986][ C0] on_each_cpu_cond_mask+0x40/0x90 [ 820.472095][ C0] flush_tlb_mm_range+0x322/0x1780 [ 820.477211][ C0] ? page_table_check_clear+0x548/0xb30 [ 820.482758][ C0] ? __page_table_check_pte_clear+0xa9/0x100 [ 820.488732][ C0] ? __pfx_flush_tlb_mm_range+0x10/0x10 [ 820.494280][ C0] ? __pfx_pte_mkwrite+0x10/0x10 [ 820.499218][ C0] ptep_clear_flush+0x136/0x180 [ 820.504085][ C0] do_wp_page+0x17cb/0x5930 [ 820.508597][ C0] ? __pfx_do_wp_page+0x10/0x10 [ 820.513454][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 820.518819][ C0] ? ___pte_offset_map+0x1bc/0x540 [ 820.523932][ C0] __handle_mm_fault+0x1ada/0x2a40 [ 820.529053][ C0] ? __pfx___handle_mm_fault+0x10/0x10 [ 820.534520][ C0] ? lock_vma_under_rcu+0x47d/0x970 [ 820.539716][ C0] ? lock_vma_under_rcu+0x47d/0x970 [ 820.544934][ C0] handle_mm_fault+0x3fe/0xad0 [ 820.549705][ C0] do_user_addr_fault+0x60c/0x1370 [ 820.554823][ C0] exc_page_fault+0x5c/0xc0 [ 820.559327][ C0] asm_exc_page_fault+0x26/0x30 [ 820.564171][ C0] RIP: 0033:0x7fb9acd4cdbf [ 820.568582][ C0] Code: 8d 34 19 48 39 d5 48 89 75 60 0f 95 c2 48 29 d8 48 83 c1 10 0f b6 d2 48 83 c8 01 48 c1 e2 02 48 09 da 48 83 ca 01 48 89 51 f8 <48> 89 46 08 eb 80 48 8d 0d 01 d1 0e 00 48 8d 15 05 e3 0e 00 bf 01 [ 820.588182][ C0] RSP: 002b:00007ffc27414210 EFLAGS: 00010206 [ 820.594242][ C0] RAX: 0000000000018a41 RBX: 0000000000008040 RCX: 00005555925e8590 [ 820.602205][ C0] RDX: 0000000000008041 RSI: 00005555925f05c0 RDI: 0000000000000004 [ 820.610168][ C0] RBP: 00007fb9acf83ca0 R08: 0000000000000000 R09: 0000000000000000 [ 820.618130][ C0] R10: 0000000000001000 R11: 0000000000000802 R12: 0000000000008030 [ 820.626093][ C0] R13: 0000000000000076 R14: 00007fb9acf83d00 R15: 0000000000000000 [ 820.634068][ C0] [ 820.637226][ C0] vkms_vblank_simulate: vblank timer overrun