last executing test programs: 1.429712625s ago: executing program 2 (id=144): r0 = socket$inet_sctp(0x2, 0x1, 0x84) getsockopt$inet_sctp_SCTP_HMAC_IDENT(r0, 0x84, 0x16, &(0x7f0000000000)={0x6, [0x1ab, 0x1, 0x80, 0x9, 0x1, 0x4]}, &(0x7f0000000040)=0x10) (async, rerun: 64) getsockopt$inet_pktinfo(r0, 0x0, 0x8, &(0x7f0000000080)={0x0, @initdev, @multicast2}, &(0x7f00000000c0)=0xc) (async, rerun: 64) r1 = geteuid() quotactl_fd$Q_QUOTAOFF(r0, 0xffffffff80000300, r1, 0x0) (async) getsockopt$inet_sctp_SCTP_PR_SUPPORTED(r0, 0x84, 0x71, &(0x7f0000000100)={0x0, 0xff}, &(0x7f0000000140)=0x8) r2 = socket$inet6_icmp(0xa, 0x2, 0x3a) setsockopt$inet6_IPV6_RTHDR(r2, 0x29, 0x39, &(0x7f0000000180)={0x3b, 0x10, 0x0, 0x3, 0x0, [@local, @remote, @ipv4={'\x00', '\xff\xff', @empty}, @empty, @rand_addr=' \x01\x00', @remote, @private2, @remote]}, 0x88) (async, rerun: 32) r3 = gettid() (rerun: 32) sched_setscheduler(r3, 0xe702fea272cc2ed5, &(0x7f0000000240)=0x3) (async, rerun: 32) socket$nl_xfrm(0x10, 0x3, 0x6) (rerun: 32) ioctl$sock_inet_SIOCDELRT(r0, 0x890c, &(0x7f00000002c0)={0x0, {0x2, 0x4e20, @multicast2}, {0x2, 0x4e24, @remote}, {0x2, 0x4e21, @empty}, 0x20, 0x0, 0x0, 0x0, 0x0, &(0x7f0000000280)='pimreg0\x00', 0x2a1, 0xff, 0x1}) (async) r4 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000340)='./cgroup.net/syz0\x00', 0x200002, 0x0) r5 = openat$cgroup_subtree(r4, &(0x7f0000000380), 0x2, 0x0) (async) r6 = fsmount(0xffffffffffffffff, 0x0, 0x0) write$cgroup_subtree(r6, &(0x7f00000003c0)={[{0x2d, 'net_cls'}, {0x2d, 'net_cls'}, {0x2d, 'memory'}, {0x2d, 'net_cls'}, {0x2d, 'perf_event'}]}, 0x2f) (async) ioctl$BTRFS_IOC_SET_RECEIVED_SUBVOL(r6, 0xc0c89425, &(0x7f0000000400)={"a3ab4760597a5b21fb6401f736c5cad3", 0x0, 0x0, {0x5, 0x2}, {0xffffffffffffffff, 0x65d}, 0x8, [0x5, 0xfffffffffffffff7, 0xdfca, 0x9348, 0x4, 0x1000, 0x80000000000000, 0x4, 0x384f, 0x12000000000000, 0x7fffffffffffffff, 0x80000000, 0x8, 0x81, 0x0, 0x6]}) ioctl$BTRFS_IOC_SNAP_DESTROY_V2(r4, 0x5000943f, &(0x7f0000000580)={{r5}, r7, 0x10, @inherit={0x58, &(0x7f0000000500)={0x0, 0x2, 0x0, 0x0, {0x10, 0x2, 0x9, 0x8, 0x8}, [0x800000000, 0x5]}}, @devid}) (async) r8 = socket$l2tp6(0xa, 0x2, 0x73) getsockopt$inet6_int(r8, 0x29, 0x4b, &(0x7f0000001580), &(0x7f00000015c0)=0x4) setsockopt$inet6_mtu(r8, 0x29, 0x17, &(0x7f0000001600)=0x2, 0x4) (async) openat$cgroup_type(r4, &(0x7f0000001640), 0x2, 0x0) (async) ioctl$sock_netdev_private(r0, 0x89f3, &(0x7f0000001680)="02c518082dd1b95a0c6ca78a073fd1328093d1138978ec8bef88e6664273a9fe0ca279a035a84aeffe1f5520be01c737baaf3966099ee45d9585ab89ff72ef7b3895206612b9") (async) sched_setaffinity(r3, 0x8, &(0x7f0000001700)=0x7aef) (async) openat$cgroup_subtree(r4, &(0x7f0000001740), 0x2, 0x0) (async) r9 = mmap$IORING_OFF_SQ_RING(&(0x7f0000ffe000/0x1000)=nil, 0x1000, 0x1000000, 0x10, r6, 0x0) (async, rerun: 64) r10 = mmap$IORING_OFF_SQES(&(0x7f0000ffb000/0x4000)=nil, 0x4000, 0x200000a, 0x10, r6, 0x10000000) (rerun: 64) syz_io_uring_submit(r9, r10, &(0x7f0000001780)=@IORING_OP_WRITE_FIXED={0x5, 0x40, 0x0, @fd_index=0x7, 0x0, 0x380000000000, 0x3, 0x4, 0x1, {0x3}}) connect$inet(r6, &(0x7f00000017c0)={0x2, 0x4e24, @remote}, 0x10) (async, rerun: 32) ioctl$FS_IOC_FSGETXATTR(r5, 0x801c581f, &(0x7f0000001800)={0x81, 0x10000, 0x8, 0x4, 0x10000}) (rerun: 32) 1.358285326s ago: executing program 2 (id=148): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = syz_genetlink_get_family_id$mptcp(&(0x7f0000000000), 0xffffffffffffffff) r2 = memfd_create(&(0x7f0000000340)='/dev/loop#\x00\xee\b\xce\xde\xe9\x8d\xd3\xd4\xe2\xfd\x7f\xf5R%\xe8]l\xa1s\b\xa5\xd2\xd59\xc8\xda\b\xd6\xb2\x15\xf6F\xb8\xb4{r.\xd2\xea\x16\x82\xe8=\xa3\x88sN\x83N`\xf9\xec\xe1\xbb\x05vH\xdd\x01?k\x97\xa5\xbf\xba\x89#=2G0xffffffffffffffff}) ioctl$NBD_SET_SOCK(r3, 0xab00, r4) ioctl$NBD_SET_FLAGS(r3, 0xab0a, 0x5) ioctl$NBD_DO_IT(r3, 0xab03) sendmsg$MPTCP_PM_CMD_ADD_ADDR(r0, &(0x7f0000000400)={0x0, 0x0, &(0x7f00000003c0)={&(0x7f0000000300)={0x30, r1, 0x1, 0x0, 0x0, {}, [@MPTCP_PM_ATTR_ADDR={0x1c, 0x1, 0x0, 0x1, [@MPTCP_PM_ADDR_ATTR_PORT={0x6, 0x5, 0x4e23}, @MPTCP_PM_ADDR_ATTR_FAMILY={0x6, 0x1, 0x2}, @MPTCP_PM_ADDR_ATTR_ADDR4={0x8, 0x3, @multicast1=0xac1414aa}]}]}, 0x30}}, 0x0) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000140)={&(0x7f0000000080)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x0, 0x0, 0x6}, {0x0, [0x2e, 0x0, 0x0, 0x61]}}, 0x0, 0x1e, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x28) socket$nl_generic(0x10, 0x3, 0x10) (async) syz_genetlink_get_family_id$mptcp(&(0x7f0000000000), 0xffffffffffffffff) (async) memfd_create(&(0x7f0000000340)='/dev/loop#\x00\xee\b\xce\xde\xe9\x8d\xd3\xd4\xe2\xfd\x7f\xf5R%\xe8]l\xa1s\b\xa5\xd2\xd59\xc8\xda\b\xd6\xb2\x15\xf6F\xb8\xb4{r.\xd2\xea\x16\x82\xe8=\xa3\x88sN\x83N`\xf9\xec\xe1\xbb\x05vH\xdd\x01?k\x97\xa5\xbf\xba\x89#=2G0xffffffffffffffff}, 0x106, 0x2}}, 0x20) write$RDMA_USER_CM_CMD_RESOLVE_IP(r4, &(0x7f0000000100)={0x3, 0x40, 0xfa00, {{0xa, 0x4e21, 0x0, @loopback}, {0xa, 0x0, 0xfffffffe, @empty}, r5}}, 0x48) write$RDMA_USER_CM_CMD_QUERY(r4, &(0x7f0000000040)={0x13, 0x10, 0xfa00, {&(0x7f0000000580), r5, 0x2}}, 0x18) r6 = openat$cdrom(0xffffffffffffff9c, &(0x7f0000000080), 0x107200, 0x0) ioctl$CDROMRESET(r6, 0x5312) readlink(&(0x7f0000000240)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', &(0x7f0000001200)=""/4096, 0xffffffffffffffa1) socket$nl_rdma(0x10, 0x3, 0x14) socket$nl_rdma(0x10, 0x3, 0x14) r7 = socket$kcm(0x11, 0x3, 0x0) getsockopt$sock_cred(r7, 0x1, 0x11, &(0x7f0000000340), &(0x7f0000000540)=0xc) r8 = socket$nl_generic(0x10, 0x3, 0x10) r9 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000800), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(r8, 0x8933, &(0x7f0000000640)={'wlan0\x00', 0x0}) sendmsg$NL80211_CMD_CONNECT(r8, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000200)={0x64, r9, 0x8, 0x70bd28, 0x25dfdbfd, {{}, {@val={0x8, 0x3, r10}, @void}}, [@NL80211_ATTR_WIPHY_EDMG_BW_CONFIG={0x5, 0x119, 0xf}, @NL80211_ATTR_HT_CAPABILITY={0x1e, 0x1f, {0x1000, 0x2, 0x0, 0x0, {0x2, 0x6, 0x0, 0x1, 0x0, 0x1, 0x0, 0x3}, 0x800, 0x0, 0x4}}, @NL80211_ATTR_HT_CAPABILITY_MASK={0x1e, 0x94, {0x4000, 0x3, 0x0, 0x0, {0x0, 0x80, 0x0, 0x3, 0x0, 0x0, 0x0, 0x0, 0x1}, 0x8, 0x9, 0x9e}}]}, 0x64}}, 0x0) 1.171133357s ago: executing program 1 (id=152): r0 = openat$vhost_vsock(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) ioctl$VHOST_VSOCK_SET_GUEST_CID(r0, 0x4008af60, &(0x7f0000000400)={@my=0x0}) r1 = socket(0x28, 0x5, 0x0) connect$vsock_stream(r1, &(0x7f0000000080)={0x28, 0x0, 0x0, @my=0x0}, 0x10) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) r3 = socket$netlink(0x10, 0x3, 0xc) bind$netlink(r3, &(0x7f0000514ff4)={0x10, 0x0, 0x0, 0x2ffffffff}, 0xc) sendmsg$NFT_BATCH(r2, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f00000006c0)=ANY=[@ANYBLOB="140000001000010000000000000000000100000a20000000000a01040000000000000000010080030900010073797a30000000002c000000030a01010000000000000000010000000900010073797a30000000000900030073797a3200000000a4000000060a010400000000000000000100000008001040000000007c000480340001800b000100657874686472000024000280080001400000000c080003400000000008000440000000220500020007000000440001a3070000006269747769736500340002800800034000000002080001400000001408000240000000120c000580060001008fb100000c000480060001008a9500000900010073797a3000000000140000001100010000000000000000000700000adbf10ec3fede6ddc01e02f7358a216d207eccedd6878af1be5f9146c8bd6dd98fd1a339eb856e0774b9af356d397103e3610713f620af72c909136e786cf8f3484e8e7839b7605a36ed25d65954a7375e549dbda13fedf25e81a8da40ec282e3a4c957d460a7f02b54f87a490a9985a032af16164683a07c9a637f711bdf0a3f95b08b17ba26d363de41972e46d8921cb4958cea8a60007f7b04a701fb57c74b3103c511e0e9e9bd4b7cbc88f5978cad30fde6244fabc46b235540ed916f633c296c851430b680cf378171904aa87e2bfddb2c0244b3a0c186f0f4b60154c7dac50e608481be2072c0367bc138f232676cc11d"], 0x118}}, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000240)='./file0\x00', &(0x7f0000000280)='hugetlbfs\x00', 0x0, 0x0) mount$tmpfs(0x0, &(0x7f0000000000)='./file0\x00', 0x0, 0x1230023, &(0x7f0000000680)={[{@nr_inodes={'nr_inodes', 0x3d, [0x38]}}]}) 1.170314866s ago: executing program 1 (id=153): mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x0) getxattr(&(0x7f0000000000)='./file0\x00', &(0x7f0000000040)=@known='trusted.overlay.origin\x00', &(0x7f0000000080)=""/21, 0x15) setsockopt$IPT_SO_SET_REPLACE(0xffffffffffffffff, 0x4000000000000, 0x40, &(0x7f0000000100)=@raw={'raw\x00', 0xc01, 0x3, 0x1230, 0x10e8, 0x5002004a, 0xa, 0x10e8, 0x0, 0x1208, 0x3c8, 0x3c8, 0x1208, 0x3c8, 0x3, 0x0, {[{{@ip={@private, @loopback, 0x0, 0x0, 'syzkaller0\x00', 'syzkaller0\x00'}, 0x60, 0x10a0, 0x10e8, 0x0, {}, [@common=@unspec=@cgroup1={{0x1030}, {0x0, 0x0, 0x0, 0x0, './cgroup.cpu/syz1\x00'}}]}, @common=@inet=@TEE={0x48, 'TEE\x00', 0x0, {@ipv6=@private0, 'wg2\x00'}}}, {{@uncond, 0x0, 0x70, 0xb0}, @common=@inet=@LOG={0x40, 'LOG\x00', 0x0, {0x0, 0x0, "53f99237f41c832fc8969da1f2b7a86ddedeb7587f1590839a7a3acebc0f"}}}], {{'\x00', 0x0, 0x70, 0x98}, {0x28, '\x00', 0x4}}}}, 0x1290) bpf$MAP_CREATE(0x100000000000000, &(0x7f0000000140)=@base={0xa, 0x16, 0x8, 0x7f, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r0 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000000040)='fdinfo/3\x00') read$FUSE(r0, &(0x7f00000020c0)={0x2020}, 0x2020) r1 = syz_open_dev$video(&(0x7f0000000440), 0x8, 0x0) ioctl$VIDIOC_S_SELECTION(r1, 0xc040565f, &(0x7f0000000940)={0xa, 0x0, 0x7, {0x8000, 0x1000, 0x4, 0x86c}}) mount$overlay(0x0, &(0x7f0000000140)='./file0\x00', &(0x7f0000003440), 0x0, &(0x7f00000001c0)={[{@lowerdir={'lowerdir', 0x3d, './file0'}, 0x3a}], [], 0x3a}) 1.091865213s ago: executing program 2 (id=154): r0 = openat$drirender128(0xffffffffffffff9c, &(0x7f00000000c0), 0x404c2, 0x0) ioctl$DRM_IOCTL_MODESET_CTL(r0, 0x40086408, &(0x7f0000000040)={0x7ff, 0xa}) sendmsg$nl_route(0xffffffffffffffff, &(0x7f00000000c0)={0x0, 0x509, &(0x7f0000000040)={&(0x7f00000001c0)=@RTM_NEWMDB={0x38, 0x55, 0x1e5, 0x0, 0x0, {}, [@MDBA_SET_ENTRY={0x20, 0x1, {0x0, 0x0, 0x0, 0x0, {@ip4=@broadcast, 0x86dd}}}]}, 0x38}}, 0x0) syz_emit_vhci(&(0x7f00000001c0)=ANY=[@ANYBLOB="040e0443050c"], 0x7) mlockall(0x1) r1 = socket$nl_generic(0x10, 0x3, 0x10) r2 = syz_genetlink_get_family_id$nl80211(&(0x7f0000007400), 0xffffffffffffffff) sendmsg$NL80211_CMD_SET_REG(r1, &(0x7f0000007640)={0x0, 0x0, &(0x7f0000007600)={&(0x7f0000000000)=ANY=[@ANYBLOB='$\x00\x00\x00', @ANYRES16=r2, @ANYBLOB="01002dbd7000fbdbdf251a000000070021007d61000008002280040000801e3aaee4a14b78aeb9d95c17915ef848c069f5ce3cd3"], 0x24}, 0x1, 0x0, 0x0, 0x8000}, 0x0) r3 = syz_init_net_socket$ax25(0x3, 0x5, 0xc4) listen(r3, 0x8) accept$ax25(r3, 0x0, &(0x7f0000000080)) sendmsg$nl_generic(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000180)={&(0x7f00000002c0)=ANY=[], 0x30}, 0x1, 0x0, 0x0, 0x488c0}, 0xc000) 1.089094308s ago: executing program 1 (id=155): r0 = openat$zero(0xffffffffffffff9c, &(0x7f0000000000), 0x101000, 0x0) ioctl$SW_SYNC_IOC_CREATE_FENCE(0xffffffffffffffff, 0xc0285700, &(0x7f0000000040)={0x6, "de92222be3449bb93785d48454f40f244fb057524a177510a391ef9ef84ec381", 0xffffffffffffffff}) ioctl$AUTOFS_DEV_IOCTL_CATATONIC(r0, 0xc0189379, &(0x7f0000000080)={{0x1, 0x1, 0x18, r1}, './file0\x00'}) ioctl$FBIOPAN_DISPLAY(r0, 0x4606, &(0x7f00000000c0)={0x400, 0x1000, 0x500, 0x40, 0x3, 0x9, 0x8, 0x1, {0xd9, 0x1}, {0x37188c8e, 0x5, 0x1}, {0xd914, 0xfffffffb, 0x1}, {0xfffffffc, 0x200, 0x1}, 0x2, 0x2, 0x0, 0xdea, 0x0, 0x5af5, 0xcc, 0x7, 0x1, 0x50, 0xffffadbd, 0x7, 0x1, 0x4, 0x1, 0xc}) r3 = shmget$private(0x0, 0x2000, 0x1000, &(0x7f0000ffc000/0x2000)=nil) ioctl$PAGEMAP_SCAN(r0, 0xc0606610, &(0x7f0000000200)={0x60, 0x3, &(0x7f0000ffc000/0x1000)=nil, &(0x7f0000ffa000/0x3000)=nil, 0x1, &(0x7f0000000180)=[{0x800000000000, 0x6, 0x2}, {0x0, 0x5, 0x800}, {0x2, 0x0, 0x8}, {0x7, 0x0, 0x6}], 0x4, 0x9, 0x2, 0x34, 0x4, 0x22}) ioctl$sock_bt_bnep_BNEPGETCONNLIST(r2, 0x800442d2, &(0x7f0000000380)={0x8, &(0x7f0000000280)=[{0x0, 0x0, 0x0, @local}, {0x0, 0x0, 0x0, @broadcast}, {0x0, 0x0, 0x0, @local}, {0x0, 0x0, 0x0, @broadcast}, {0x0, 0x0, 0x0, @dev}, {0x0, 0x0, 0x0, @link_local}, {0x0, 0x0, 0x0, @multicast}, {0x0, 0x0, 0x0, @link_local}]}) shmctl$SHM_UNLOCK(r3, 0xc) ioctl$EVIOCGABS20(r0, 0x80184560, &(0x7f00000003c0)=""/152) mremap(&(0x7f0000ffb000/0x3000)=nil, 0x3000, 0x2000, 0x3, &(0x7f0000ffd000/0x2000)=nil) mincore(&(0x7f0000ffe000/0x1000)=nil, 0x1000, &(0x7f0000000480)=""/24) shmctl$SHM_UNLOCK(r3, 0xc) shmctl$SHM_LOCK(r3, 0xb) r4 = openat$uinput(0xffffffffffffff9c, &(0x7f00000004c0), 0x802, 0x0) fcntl$setflags(r4, 0x2, 0x1) r5 = openat$sw_sync_info(0xffffffffffffff9c, &(0x7f0000000500), 0x600000, 0x0) ioctl$IOMMU_VFIO_IOAS$GET(r2, 0x3b88, &(0x7f0000000540)={0xc, 0x0}) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN(r5, 0x3ba0, &(0x7f0000000580)={0x48, 0x2, r6}) ioctl$IOMMU_VFIO_IOAS$GET(r5, 0x3b88, &(0x7f0000000600)={0xc, 0x0}) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN(r5, 0x3ba0, &(0x7f0000000640)={0x48, 0x2, r7}) ioctl$VT_GETMODE(r5, 0x5601, &(0x7f00000006c0)) fcntl$F_SET_FILE_RW_HINT(r2, 0x40e, &(0x7f0000000700)=0x1) syz_kvm_setup_cpu$x86(r0, r0, &(0x7f0000fe8000/0x18000)=nil, &(0x7f00000007c0)=[@text32={0x20, &(0x7f0000000740)="0f20c035020000000f22c0b9b20300000f320f08c7442400071f0000c7442402ce000000c7442406000000000f011c24b805000000b9730c00000f01d9660f71e51166b862008ec00f01ca66baf80cb84e34148eef66bafc0cecc4c26139c5", 0x5f}], 0x1, 0x50, &(0x7f0000000800), 0x0) ioctl$F2FS_IOC_RESERVE_COMPRESS_BLOCKS(r1, 0x8008f513, &(0x7f0000000840)) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN(r0, 0x3ba0, &(0x7f0000000880)={0x48, 0x2, r7}) read$FUSE(r5, &(0x7f0000000900)={0x2020}, 0x2020) ioctl$IOMMU_IOAS_MAP(r5, 0x3b85, &(0x7f0000002a40)={0x28, 0x1, r6, 0x0, &(0x7f0000002940)="985178c12a7f28ecdb3f67c6501da27b455bba9e2a9daadfab52a34b63f262db0c0903335a5ecba4186c5e28503a2e69764e9a2e2f0756e41976dbdff6bb02a96556bf383065d6e3ffae50e5750e6f633cd063d2a1211979567b766374c77510ad542554eb03ab26662f610a5376c74165786dea2909722ff6cf543baed4df291219ed1f6ec1b788322f904372ac86b914a94d074c0fa3433a8cf15feefc548c6e116a1423eb2301488d69ca351973e20a0c965a516aec5eb4fceab0f0ad0c9f3a", 0xc1, 0x900}) openat$vicodec0(0xffffffffffffff9c, &(0x7f0000002a80), 0x2, 0x0) r8 = syz_open_dev$rtc(&(0x7f0000002ac0), 0x7, 0x400002) fadvise64(r8, 0x6, 0x8000, 0x2) 1.088759049s ago: executing program 1 (id=156): pipe2(&(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}, 0x4800) mmap(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xb, 0xc3072, 0xffffffffffffffff, 0x0) vmsplice(r0, &(0x7f0000000140)=[{&(0x7f0000000100)="eb", 0x20000101}], 0x1, 0x0) move_pages(0x0, 0x10, &(0x7f0000000140)=[&(0x7f0000000000/0x1000)=nil], &(0x7f0000000040)=[0x1], 0x0, 0x0) r1 = syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) r2 = syz_open_dev$dri(&(0x7f0000000280), 0x1, 0x0) ioctl$DRM_IOCTL_MODE_GET_LEASE(r2, 0xc01064c8, &(0x7f0000000200)={0x4000, 0x0, 0x0}) syz_open_dev$usbmon(&(0x7f00000002c0), 0x5, 0x36802) mremap(&(0x7f0000a96000/0x1000)=nil, 0x1000, 0x400000, 0x3, &(0x7f0000000000/0x400000)=nil) mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x1) openat$nullb(0xffffffffffffff9c, &(0x7f0000000040), 0x147c40, 0x0) r3 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) ptrace$poke(0x5, r3, &(0x7f0000000080), 0x1000000000000000) r4 = socket$inet6_tcp(0xa, 0x1, 0x0) r5 = syz_open_pts(0xffffffffffffffff, 0x400200) ioctl$TIOCGPTPEER(r5, 0x5441, 0x1) bind$inet6(r4, &(0x7f0000d84000)={0xa, 0x0, 0x0, @loopback, 0x9}, 0x1c) r6 = socket(0x10, 0x2, 0x0) ioctl$sock_ipv6_tunnel_SIOCADDTUNNEL(r6, 0x89f1, &(0x7f0000000180)={'ip6tnl0\x00', &(0x7f0000000000)={'syztnl1\x00', 0x0, 0x0, 0xf9, 0xfd, 0x0, 0x0, @empty, @private2={0xfc, 0x2, '\x00', 0x1}, 0x0, 0x80, 0xfffffffc, 0xdc67}}) ioctl$sock_ipv6_tunnel_SIOCADDTUNNEL(r6, 0x89f1, &(0x7f0000000140)={'syztnl1\x00', &(0x7f0000000240)={'syztnl0\x00', r7, 0x29, 0x0, 0x6, 0x7f, 0x5, @ipv4={'\x00', '\xff\xff', @multicast1}, @mcast1, 0x0, 0x40, 0x6, 0x41}}) tee(r4, 0xffffffffffffffff, 0x100, 0xa) ioctl$sock_ipv6_tunnel_SIOCCHGTUNNEL(r6, 0x89f3, &(0x7f0000000080)={'syztnl1\x00', &(0x7f00000000c0)={'syztnl1\x00', r7, 0x0, 0x0, 0x0, 0x0, 0x1c, @dev={0xfe, 0x80, '\x00', 0x8}, @private0={0xfc, 0x0, '\x00', 0x1}, 0x700, 0x0, 0xfffffffc}}) syz_genetlink_get_family_id$nfc(&(0x7f00000001c0), r1) socket$nl_route(0x10, 0x3, 0x0) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFINDEX(r8, 0x8933, &(0x7f0000000080)={'bridge_slave_1\x00'}) socket$netlink(0x10, 0x3, 0x0) r9 = openat$vmci(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) ioctl$IOCTL_VMCI_VERSION2(r9, 0x7a7, &(0x7f00000000c0)=0x80000) ioctl$IOCTL_VMCI_INIT_CONTEXT(r9, 0x7a0, &(0x7f0000000100)={@host}) 771.744671ms ago: executing program 1 (id=159): pwritev(0xffffffffffffffff, &(0x7f0000000340)=[{&(0x7f0000000000)="caa0353ff1ac4b11a6023d0a026daee85e1b23160ed65f7f5052e63f97811a52443aec84e0dc82a9061bd3ac6987ad4c87a143ea68416c0537f6233f49633e5307d7014d76c99fef48d9050585e7719fd8834c02b7fc56a194c0066ce03906fad6cc347ba056af911276661b3e965810596e3875ae2c5cf2459fd2fd1bda99dc27cc52a226de2de8e97a04a0b7372640684b7e6415f1612a490d86f146943af7c583fb48b28d7e0fe6e0f4091f2c9ec42ffe1469d312902070415c4770c32fbbb49e7813c33d9f70dcd061084af86dd3b1f858bd3e9219d1adc23b4147f4354885fdd95c158d8b64b2a0221e29a63d58f11d194f8c1b274f6b3b3ab1de", 0xfd}, {&(0x7f0000000100)="a173f1a4202ef4854cffd5bff51cf414f75025213d0ecd46c55760c918c73633db6676968f2f38bfb5bbefb04c675f19d67c5bc9e59e1e37670b72601a5b44569ce3b7906c", 0x45}, {&(0x7f0000000180)="ae3480d8ae2f7f258345c123722e6ea6b80706136dc48c2008dfe106c582605639b9387e4df615bc6cb42450cb53f006f5195e1fba7d1aad653321866bba940a6f647b09233dd80abba6c61bddc2744f61d23656835a355122c0e7dd785f72ef868c3b6e7206eab663c9db63aa26ead56e393bd10f473cf8391094d3ff5f9b967e90e6b11450f8f8154deec5a7e2a293aaf2f26918b77a73e57f16de4bc7201eb90b409123c1fd1aacef6e", 0xab}, {&(0x7f0000000240)="8f7f84ca48189ce199f28f81e67d98ad5d1ca5bb51e2c7eecc1026a9b04a137f89af4394cf2e76df642a778018c3bb6ffb0c8f43e83f12b858af5c5a29bc3ec0cd4bce05eb", 0x45}, {&(0x7f00000002c0)="9670d81fc12869ba78954f161c5f6630462a505f0a60fed6fd8d6a41c3", 0x1d}, {&(0x7f0000000300)="2d4ac6b885b3cfbe3f15a9f51208801badeb3b2bf5f0dc2502b1a920f8cf", 0x1e}], 0x6, 0x8, 0x3730) r0 = accept4$tipc(0xffffffffffffffff, &(0x7f00000003c0), &(0x7f0000000400)=0x10, 0x80800) ioctl$INCFS_IOC_FILL_BLOCKS(r0, 0x80106720, &(0x7f0000001540)={0x3, &(0x7f00000014c0)=[{0x8, 0x29, &(0x7f0000000440)="66d8bc3ef4f90dd46fc29ed9cf0107af8cf81ba87801c18297447cb959b8fd4cd4557a676757956671", 0x1}, {0x9000, 0x1000, &(0x7f0000000480)="255eb8c39ea7382011fe54766078d368453aa5c9f0a4ebba8f28cdcd5d0202c1a5f6a980af9fbd7488b2ef6580a49c1927e3b21522d03d5656d441a8ceca8530344801deac35b63f49ca247febf02314528b75878df26f4e43910ae4d189c7fa01eb76e89d41032b8ff35b498c3f01b823ce33249aebd9c3c19d04056c0abf2acfb74f8851b1c2852015e4b76d98d144365f821ed752211ea44b8564039529e024ecbe668606398b4a33836d00816c52f4ec881425a3e0666b53236bc42f794581ca1402edb67688203a253bc0e70b4611be356d75a7e710d0aa60ae16abf40ff78214bdc988f7f1fd9465c244b05ab13f63b8e9c58b83cdd619242c5e44051604d6901ba3a6415d8b439c78f568ae6f8d10141b8c790ae247fbd4c3af9c49e2af8133ded98577ea192abf4b5d44b317129defbece9d6565562a459a58720db4d1a156989438ae891e76f2fab40f5ba8f13263adcd1ab93684d849a8493309c0f6eb7d0509746f07fca0adafa0226b8ee8cdfc9d924e8c17ab19a29edd5c6e779887f9aaa5b3ae9433bda993485549d2e32866abe27b6e0045ed60b3bc58451e62cdcf5b3e997a8ad81ce0d57a1ff490116a160ec59067386147c0eeafc388467021364eccaa57af24ab68cd61d637fa602eb5502ee3a752ad22ecce5bb8b70cae5a182cc6aeac145ecda18278dd739c77c1256366e811bfc9bc606656e875c714d1439aa6b9c8694a88d64d933600430bfee4648a66451b2c8d4a4c05ee8356e88ed296b3d1f5c43b00f820980416b14a0717994f5fc878466c0bf49ceb453ec53fbcb426bdb1093a22b65349ec1cadf3ca8516fc79647f3610e01f3ab1958107aaf50155063bcb35d94faa211d9b4efb9bb56ea9f42eff30c96d0ab1a3e41085924eab3c4fc215ca9b7f22427a75965a4b9d1b7ae30905697465785dcd857d1ae40613e199bab8ca6a6c4ca4e06d97a9d8555d4dade8bd1ce201b15e421af67b8853b450c9bcf62bbc914d2db17cac15a346d13aa66e184d29b0d5d7200107b2b0b70702f068c76892da59672cfdee6c3179f07fe7cd505fe432a517a1be97883528ab69a0735cf34c2a60e8c23a6ab39ce5683e862033bd6ef49a7d0d7c810d1f00d11b00ee665551c80b34113495151efc483e9be1c66e9cae0fcc8c140e345fc5e1214750c50dab2e50a5f79c85a27d29823fa98b87235f4e15974f02208484e528bc3dd6efc3d389d587e82123921bc6827b60e883c6099cfe476aff4bd02e7a8ef421df482aef15cb4e65baf6ad75501c48a2b4193f0f36d7954f2f4737b1e33254296c277b5b6f1a87b97677af7e91d42e9bd03e911412b680aea1638327de5ed1bdb5e45ec992a1d4c9d103c37725e502dce16810ce5a6fa99c2814340e4eeb84e93ba1d6f6bcf92b21f2e430185b998270f1aeb4c94697b2ac4b5fbb3c8cb789f972a66d40b9adc40c32cf029e44ee3cd1d9d4a3b43bd9247108ab8beaebb213953645de263b5571b508dcb0c36f2eb4c2539c88422024c3eb1de3f02d4bc2f7eaaf3f93101f26ec3f288cd059c22cc9330719826d1284381bbeb156e518cf3c0813d510f9ade14b98920e1f68e8708e0158027d0e208ec40b3f0ab264b2795371242483bf2a34035d1c4a52e8c8caedbc9925b435e4b1b694a380366a2976daf9abee3bf66380c4b2fd2311bcc7dfabb8a9a3385b7ba9cb1c3b7d22a57fe7da69660617e0be33d31bfd9cff38968853ffbde6adccd34444b8da569512226234c5f1ab038ff09de91f328360d129c9ce8deea4153b6e1ac6b19e0dc8362b3c333c28bb182116eb772043f5371099da6571b68e896ef217efdf02ad57555394b8f8c704903401688ba11d1d4fd2bb255981ae836e8efb137572bcba8c67ca721f1d89bc2f639c8750c0d98914691ecaaac43b0f24c6b536c8aad7b0c1f8052ccc3c8ffa66accefb477385724d3c4e56555c3bd04304942aeec71aa02d1f3903717c67ae54451954a0f8a05428aeacf015353793c032cff6c1186c51a918c9ea113e82a7d1e38589a8531a46fe60ec69206581cf4e890bfbcfc7d381a7f6e5841d81a86d76c1310291ed3fcd99e827fa47c3ed2d10b3df069ed366cdcb79c78aa93347e7d6c39722a9ffaf88cce62e6b04e9de31bb396786ec18676a3543037df33ab569008556f5d43d284e8b5a0b59d8047ab9d02bd796991984c71c156f6a981a5515581b10c6e1c0e2c6257d3a55719961d8d3eba4ab05b4b6512b9dbd3f0e942384792b8727346857ecd3e8014ce210cb3d8675fa4e339c2095c5a120a7c31d6aa850dd737a43fb7ada4f05e641fda61033aea186f36c4f1e115c39ee62eb8ba119f67f5a05dff7a4ca639d4deec6c419f0f1746add40bddc91827471a4dbc575cba3df59bb36eaa43cab6b44921e18570414e468bea56704712c162f2871333a92c8fb6b579361d5f2e9906674867583257b9750f50ed1f7f2324b627b6b6ce770ed3ae8e264bb1db9b69344b5464359fc1dba744eb74d7fe6f2f65c0965b0d819271eb92b38ea3b7827fd23ae369ddeedc47b2e221210bb4af30b42e6c33e0a929a8f5fabb196b583ffb29dc369550103e12b60557ebb1778d848df6f1a62446468c3888dca3837162355678bcdfc3939c0e8454ed8d3752023ff2534890bcce45e9c61726f779158a65e7c85197aacf31742f5635946a9d22fa2999e3ac5aba168b00a11948a6d6de3185f47e49a0f0fa8f293cf789bb131312e0f6c0b4f8148538dfcbb9e1a47f1faa03f1c6816d59991581622660d9b6635b09811cfad13beb1e3dfaf312ad952ad7b6d8485ad047e975d255a1fad0202112394d7f0ed24d86b95ecf0eeae2520a0df3b77b0a300a8a3bc31a9fbd00cc6d17f7d56f3c9ea2ae0a2441da2d2937d46df607d6fe67f26a2331988f20b6ce36f0d824030de0a55aff67ec00f52dd54331b068aa9b06b1a457995fd7f186480fdc63d47f7b13cd7c7784e0a542e44e35e07b3e358f894ff9dcf4974a631a36d5a27d35ac683663abe16dd1a8c0022017a2e58fd3904c59c0f3632fb8bf33eae6e15c914a06e8f040f2808d6233c0dce4f6af80a389b9e7e8c0c5b10c54adb990ba0576ddc071e893a3019c838d088841a337bf27dd78d08be4edc3057beaf0c931a470239d3be257605d25a1de1e7ea6b1bf196b7dfe1c15f37d64bff503b368c9cdd591026c6fafef1630451c37866a05f125a9c0ade154cd5732caeca40a8941283173c266ea388fc7868939f0db83215129b6f4acdff0f4861e985a643bf947508d1b1a97948210d8aadeac7fd5673d68108b6b40486ecffeb8c910644109f959772f6912158552e5cf9b99dd21a14427c838b50ae59913bc70658d41537d9bb1118933112bc1d57fb815fe2aaca6b7dd609f7a4712bb6ec38f02a474b160cbc151c3c43965f2b6ee2e49140763e610bd9336aa2727030707d87923bb4e5162eda136d7cff064214992548fd61ffef722c256a1540df71807ef19badf0ab833f6804fd49bbeca41fc04ba7e817556b0fa0617de6c6d6676c682ca1c6b3178d05ba2b5c628149716a486bd56dbd1f4eebe3c2f320356eed91c1dba002f5aa94afcc1ea91e5232a249901146f5bc3a48d32eeb2d11bf00fb9f1ede752e054268cb27e14982097ee2eef892135ff9f13a01fa8d7fb52811a54668a95becca0e7907ae72f6db8c6f1bd8f0d93bb726e4efdb0d4815f63ac41587d857c9c664a49a92986f4d757b8efcd65969d8ec525b16393880ff1357b4ef37e0ee8dcbc51ad7edbe06e802f9202134ad4742089b7e311247bfcda75ddcd8c06c62fdf6c174059e53d1e4a67939e97f7bd2b6d71e12edca12330c027b9dd58c894057eb6abb26c2ccf3a9d150fff54f9b0bf2beaf6adadc3da108c2e5cb23d71a4b3ee697856b352441d00dead6fe70438b68ae9502828610f3c7fae00d55cd7a0eb6b107c8c0a659c0ca11a9709f0659f9ab298710dd10a149f5362610807e79e8d0f6024f5590d668beec373605cef93cc05d19715e5a61dec12b4468b6b93af8e24f95858d185a0bb345b02603084bb96dd3526b6e8c614b7cd4f1d9458f049ea47b5fbaf773f24a6e849ac2c08def6bf7d77e97baac2e07ba1a748ad65ebfdf101cace6d11f0bea2a795b78c279e4cab68a2138f058f575baec88e6200cc13f4e86193b14c9843d50ee00b30a34ba25ffd010d6b68122de2192000b75b085d3a6cb0ef8cefee2a5641ebe99f5d10de82202b6d639fcccc4971afc06ec2e3fc5523ed4bc27f0f979e49f22113905bcac8cb525f89145688ee3427e1b467cf7d5c71d94ac315d9a7e6fc6002321eff2c20b17b0f63becccc4d50bf01af11df8f5a79bd50a4f45149f92b123cb3041ca21d0e74b6e5ff6f1544f85c29ea26dfa9a037375a7771986be414274b6d2ff250f65a06fe47071db4d2be9b49db8c4e4ecbb637ee71a3aaa0b69ce079322d6a04b9361b6a88e255e205b2e849661df6b659afc19e762e18e788ac3995778cff0d33e090de7e8ccad8a9f528a00bf2a2340b780999b3f9ecaec50475ca4be10e6fdf6746b081721119a348bb3153ae28c84eb6374aa684ff16f549d21fde1cf1a5ebff8262532077ee2b8bbd3add1d5bf9bb4e71c8ec3f702b5c6913b1d3b997682ceedbd06ce6eafc621427bfbd2a567baa24e2a2a96e4164d355d7c679ac14eadade53082764390a680eb64d6afab2f4aae76d2d7b908e07595250ae66a8c28ebb35606b0e78de71d62787c46a34b8d0808676cb7a38337c1613a5bc10ee5f962489876f82e880c4db82250ca834c0ddbc16c692f8bca31a55fd45a53a412be901543735bf7bc83a04290df88129cbe704195b00b38648e1d0c926489645b1c2bc2b46e7741c4bf4fa3cf2b5011b2c7d323d38f9a0043d761d050798d090ae391130aeb0727a1ea47c14120a233c3ae8a79562f627b096b801ecf4e74a2294e835b6afb2e579657ab8ac827f75ba1ae2a7a6cdff8443df1a95b14349527b6a07525d6200ce7b96dbda24f775b2afcd8c408e729d1cf53ac00b522f5852f8cca678ab324e0acb8c337e03668f2182095f579bbdefe8059e8f4c53f8559a7bd94524c644c0bd385cc7890912cf615a9517b2988122ea0e006cbbc8489b54b60f81abd2d60fdfc0c111b04df55a23d06bbc07fdd44a755c8077b14b94571ba760f19f27262a41c578e07b150ef4b719c07662bea4dc3a10c5c1652655c10cadcbd8f588d040f0229b8dda3cf3107f65ef51f9f385ce690c78200921885fe4f36c22c7492b8000cdb90024a85ed3152edf69ff492f20641d2ac5315c8d54378d30e42eb2ffebe88da2ac7aea265af540e8ee97f74515d0fe50ee16e2320a0c74c74ec348753c7c4f1c891fbe515f3c04bf657f6be7160abb2a5be05fef3356c10facf3974f040f3e0ede18b69382f68bc10b6cbff5e8c309d2717d501334ac1337e55eda0e01005ff3ba1b098ed562e6658483a68f21003d63b9309cbaf67908b2b2069e78ee19d4fa7280e37805b5bb31b9a68e858f6e2135946788047f0648cb468a6af5fbaeae56e8767798ff41de9c0bd8fc5491bacfccc242dbb3759d79a88bbbc329b3550882abe8fceab005b57e5c5f7c445a79339eb1a17ff9040ecefc13eb715308a6e9d153a22e2e2094b5c118499ddc243ca3d81f0d7a5d99143107d0ce267eee9c3c572eee4f551e8df364450d89c3b372217f8365a122bc90b703a519eeeec9222cf34b1b09a7332538e2097c0c32253", 0x1}, {0x71, 0x2, &(0x7f0000001480)="95f9", 0x1, 0x1}]}) r1 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000001580)='./binderfs2/binder1\x00', 0x800, 0x0) (async) r2 = open(&(0x7f00000015c0)='./file0\x00', 0x2, 0x99) ioctl$TCSETA(r2, 0x5406, &(0x7f0000001600)={0x40, 0x0, 0xb, 0x9, 0x8, "4b397ce1736010f9"}) (async) r3 = syz_open_dev$ptys(0xc, 0x3, 0x0) ioctl$TCSETS(r3, 0x5402, &(0x7f0000001640)={0x9, 0xfffffffe, 0x200000, 0x4, 0x5, "431884f6605371a3f257c242b3a455eff96da2"}) ioctl$TCSBRKP(r2, 0x5425, 0x10) ioctl$sock_SIOCGIFVLAN_SET_VLAN_INGRESS_PRIORITY_CMD(r0, 0x8982, &(0x7f0000001680)={0x2, 'ip6_vti0\x00', {0x10000}, 0x5}) (async) ioctl$TIOCSTI(r3, 0x5412, &(0x7f00000016c0)=0xb) (async) fcntl$getflags(r1, 0x40a) (async, rerun: 32) ioctl$TCSETSW2(r3, 0x402c542c, &(0x7f0000001700)={0x5209, 0x2, 0xffff, 0x1, 0xb0, "0cf443d09c54e8076baee90e2ed56919fa075d", 0x93, 0x6}) (async, rerun: 32) ioctl$TIOCSTI(r3, 0x5412, &(0x7f0000001740)=0x8) (async) ioctl$DRM_IOCTL_MODE_GETENCODER(0xffffffffffffffff, 0xc01464a6, &(0x7f0000001780)={0x0, 0x0, 0x0}) ioctl$DRM_IOCTL_MODE_CREATE_LEASE(r2, 0xc01864c6, &(0x7f0000001800)={&(0x7f00000017c0)=[0x0, r4], 0x2, 0x80800, 0x0, 0xffffffffffffffff}) r6 = syz_open_dev$loop(&(0x7f0000001840), 0x5, 0x11100) (async) r7 = socket$inet6_icmp(0xa, 0x2, 0x3a) ioctl$LOOP_CHANGE_FD(r6, 0x4c06, r7) (async) readv(r6, &(0x7f0000001a40)=[{&(0x7f0000001880)=""/209, 0xd1}, {&(0x7f0000001980)=""/138, 0x8a}], 0x2) (async) r8 = syz_open_dev$loop(&(0x7f0000001a80), 0x0, 0xc0e01) ioctl$BLKIOOPT(r8, 0x1279, &(0x7f0000001ac0)) (async, rerun: 32) writev(r5, &(0x7f0000001d00)=[{&(0x7f0000001b00)="7d72ee7820c7e5b70733dc92657b1820dd6b93fe416172aa62bd6224843f774bf50c9b96cc0612e93f47f0ba84431a70dff3a9ac3fe41f7a9a5471edbc8e6db08c7643f861ead6890126388a3eacccdd9dce047fbe49503f583524de5c4a773fab8121dadf94a2", 0x67}, {&(0x7f0000001b80)="adcd04460dcfe319514932f04efbf71e55a467a0f86aaf6919f0e9d5913b0e89b40129bdb784d42ebe7dfcb0ae85d15ef380631d0b9f2fdcb4a45d8dddab", 0x3e}, {&(0x7f0000001bc0)="d2613c80eb879c1d333f16a5f088103c652be3a988e62b6efbc850d0798719d1eceeb54487b9eeff4f3f25ab28635111522fe649d91aca67dc735c06c5213c665450fc49a04667aee3a16d00dc2736db9e5bca7c45f5c46c75ba0d23c24d3ae19a5db9a851c433cca1c524f0fb694a033dcd7bd36d08218317f5a2b5e44d5514246637e4cc3bef7a3d6512afc2295c43ad40d6b8339ad35bfd48be3f957f9050f3cc57e7b2e2ce3d334390364c", 0xad}, {&(0x7f0000001c80)="631a35cba8a2f10f0a9b83e616dd3611d01bbd256ddbb10e3bfc069532fec338824a5febdd95ac4feb0c9b060990229718d3963c9608ce38c0b5f5cad50caadd9d08946ca09303042896f6b70b0d74841ae0aa9132aede", 0x57}], 0x4) (rerun: 32) r9 = openat$ttynull(0xffffffffffffff9c, &(0x7f0000001d40), 0x40, 0x0) ioctl$TCSETS(r9, 0x5402, &(0x7f0000001d80)={0x2, 0x5, 0x80, 0x6, 0xd, "e32983e4b20c48e4ff6d0a74b4e04c9b03df55"}) (async, rerun: 32) openat$nullb(0xffffffffffffff9c, &(0x7f0000001dc0), 0x8400, 0x0) (async, rerun: 32) getsockopt$inet_pktinfo(r5, 0x0, 0x8, &(0x7f0000001e40)={0x0, @multicast1}, &(0x7f0000001e80)=0xc) sendmsg$nl_route(r1, &(0x7f0000001fc0)={&(0x7f0000001e00)={0x10, 0x0, 0x0, 0x80}, 0xc, &(0x7f0000001f80)={&(0x7f0000001ec0)=@delneigh={0x84, 0x1d, 0x400, 0x70bd25, 0x25dfdbfe, {0x0, 0x0, 0x0, r10, 0x0, 0x40}, [@NDA_MASTER={0x8, 0x9, 0x9}, @NDA_VNI={0x8, 0x7, 0x4}, @NDA_PORT={0x6, 0x6, 0x4e20}, @NDA_FDB_EXT_ATTRS={0x28, 0xe, 0x0, 0x1, [@NFEA_ACTIVITY_NOTIFY={0x5, 0x1, 0x5}, @NFEA_ACTIVITY_NOTIFY={0x5, 0x1, 0x8}, @NFEA_DONT_REFRESH={0x4}, @NFEA_DONT_REFRESH={0x4}, @NFEA_DONT_REFRESH={0x4}, @NFEA_ACTIVITY_NOTIFY={0x5, 0x1, 0xe}]}, @NDA_LLADDR={0xa, 0x2, @broadcast}, @NDA_DST_MAC={0xa, 0x1, @local}, @NDA_PROBES={0x8, 0x4, 0x3}, @NDA_FLAGS_EXT={0x8, 0xf, 0x1}]}, 0x84}, 0x1, 0x0, 0x0, 0xc000}, 0x10) ioctl$SECCOMP_IOCTL_NOTIF_SEND(r7, 0xc0182101, &(0x7f0000002000)={0x0, 0x6, 0x2}) (async) ioctl$BLKIOMIN(0xffffffffffffffff, 0x1278, &(0x7f0000002040)) 771.355851ms ago: executing program 1 (id=160): ioctl$BTRFS_IOC_SET_RECEIVED_SUBVOL(0xffffffffffffffff, 0xc0c89425, &(0x7f0000000100)={'\x00', 0x0, 0x0, {0xfffffffffffffff8, 0x10000}, {0x6, 0x6}, 0xab4, [0x5, 0x7a, 0x1, 0x4000000005, 0x40, 0x66, 0x1, 0x5f, 0x2, 0x1, 0x10, 0x4, 0x6, 0xffdffffffffffff7, 0x621, 0xa]}) syz_open_dev$cec(&(0x7f0000000000), 0x0, 0x180) (async) r0 = syz_open_dev$cec(&(0x7f0000000000), 0x0, 0x180) ioctl$CEC_ADAP_S_LOG_ADDRS(r0, 0xc05c6104, &(0x7f00000000c0)={"0e00", 0x0, 0x6, 0x2, 0x0, 0x3b, "f7000000000041942f7500", '\x00\x00\a\x00', "0300", "fcffffff", ["50d5c2a7c5ae5cace40000b6", "808e88e2e9ffffffffff00", "0c436d743c97c443084000", "ff81000000008000"]}) ioctl$CEC_TRANSMIT(r0, 0xc0386105, &(0x7f0000000040)={0x2, 0x1, 0x5, 0x3ae9, 0xc6, 0x4, "02f8ffff070000fbb4883d45f400", 0x8, 0xae, 0x6, 0x8, 0x2, 0x0, 0x40}) (async) ioctl$CEC_TRANSMIT(r0, 0xc0386105, &(0x7f0000000040)={0x2, 0x1, 0x5, 0x3ae9, 0xc6, 0x4, "02f8ffff070000fbb4883d45f400", 0x8, 0xae, 0x6, 0x8, 0x2, 0x0, 0x40}) r1 = openat$ndctl0(0xffffffffffffff9c, &(0x7f0000000000), 0x169101, 0x0) ioctl$DRM_IOCTL_GEM_FLINK(r1, 0xc008640a, &(0x7f0000000180)) r2 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r2, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000001480)={&(0x7f0000000000)=@newtaction={0x60, 0x30, 0x36eac49ec043b62f, 0x0, 0x25dfdbc3, {}, [{0x4c, 0x1, [@m_gact={0x48, 0x1, 0x0, 0x0, {{0x9}, {0x1c, 0x2, 0x0, 0x1, [@TCA_GACT_PARMS={0x18, 0x2, {0x2, 0x8, 0x20000000, 0xd, 0xe}}]}, {0x4}, {0xc}, {0xc}}}]}]}, 0x60}}, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f0000000240)='gfs2\x00', 0x0, 0x0) (async) mount(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f0000000240)='gfs2\x00', 0x0, 0x0) ioctl$F2FS_IOC_MOVE_RANGE(r1, 0xc020f509, &(0x7f0000000380)={r2, 0x7, 0xffffffffffffffff, 0x8}) (async) ioctl$F2FS_IOC_MOVE_RANGE(r1, 0xc020f509, &(0x7f0000000380)={r2, 0x7, 0xffffffffffffffff, 0x8}) symlinkat(&(0x7f0000000340)='./file0/file0\x00', r3, &(0x7f00000003c0)='./file0/file0\x00') mount$tmpfs(0x0, &(0x7f0000000000)='./file0\x00', 0x0, 0x20, &(0x7f0000000200)={[{}]}) r4 = openat$cuse(0xffffffffffffff9c, &(0x7f0000000040), 0x2, 0x0) read$FUSE(r4, &(0x7f00000022c0)={0x2020}, 0x2020) (async) read$FUSE(r4, &(0x7f00000022c0)={0x2020, 0x0, 0x0, 0x0}, 0x2020) ioctl$AUTOFS_DEV_IOCTL_REQUESTER(0xffffffffffffffff, 0xc018937b, &(0x7f0000000180)={{0x1, 0x1, 0x18, 0xffffffffffffffff, {r5, 0xee01}}, './file0\x00'}) mount$overlay(0x0, &(0x7f00000000c0)='./file0\x00', &(0x7f0000000140), 0x28, &(0x7f0000000280)={[{@default_permissions}, {@nfs_export_on}, {@verity_off}, {@upperdir={'upperdir', 0x3d, './file0/file0'}}], [{@flag='silent'}, {@fsuuid={'fsuuid', 0x3d, {[0x31, 0x66, 0x62, 0x33, 0x33, 0x31, 0x32, 0x33], 0x2d, [0x61, 0x64, 0x36, 0x32], 0x2d, [0x34, 0x39, 0x62, 0x56], 0x2d, [0x36, 0x32, 0x62, 0x33], 0x2d, [0x37, 0x62, 0x65, 0x34, 0x64, 0x34, 0x63, 0x84935c262caf0919]}}}, {@uid_gt={'uid>', r6}}]}) 468.990674ms ago: executing program 3 (id=165): r0 = syz_open_dev$vim2m(&(0x7f0000000000), 0x3, 0x2) ioctl$vim2m_VIDIOC_REQBUFS(r0, 0xc0145608, &(0x7f00000000c0)={0x1, 0x2, 0x1}) ioctl$HIDIOCGFIELDINFO(0xffffffffffffffff, 0xc038480a, &(0x7f0000000040)={0x3, 0x200, 0x6cb0, 0x9, 0x1, 0x6, 0x9e2, 0x7, 0x5, 0x11, 0x7, 0x8, 0x1, 0x7}) ioctl$vim2m_VIDIOC_QBUF(r0, 0xc058560f, &(0x7f0000000340)=@mmap={0x0, 0x2, 0xfffffffffffffeff, 0x100, 0x0, {0x77359400}, {0x0, 0x0, 0x0, 0x0, 0x0, 0x0, "186856f3"}}) 391.605945ms ago: executing program 3 (id=166): r0 = socket(0x28, 0x5, 0x0) r1 = socket(0x28, 0x5, 0x0) bind$vsock_stream(r1, &(0x7f0000000040)={0x28, 0x0, 0x0, @local}, 0x10) listen(r1, 0x4) connect$vsock_stream(r0, &(0x7f0000000080)={0x28, 0x0, 0x0, @local}, 0x10) sendmmsg(r0, &(0x7f0000000100)=[{{0x0, 0x2d, &(0x7f00000000c0)=[{&(0x7f0000000000)="1b", 0x40000}], 0x1}}], 0x51, 0x0) r2 = socket(0x10, 0x3, 0x0) connect$inet(r0, &(0x7f0000000140)={0x2, 0x4e23, @dev={0xac, 0x14, 0x14, 0x3e}}, 0x10) socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFINDEX(r3, 0x8933, &(0x7f0000000000)={'lo\x00', 0x0}) sendmsg$nl_route_sched(r2, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000780)={&(0x7f0000000240)=@newqdisc={0x38, 0x24, 0xf0b, 0x70bd26, 0x0, {0x60, 0x0, 0x0, r4, {0x0, 0xfff1}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_fq={{0x7}, {0x4}}, @TCA_EGRESS_BLOCK={0x8}]}, 0x38}, 0x1, 0x0, 0x0, 0x4000}, 0x0) write$uinput_user_dev(0xffffffffffffffff, &(0x7f0000000400)={'syz1\x00', {0x3, 0x2, 0x6, 0xfffa}, 0x3a, [0x8000, 0xc95a, 0xf, 0x8, 0x80, 0x2, 0x3, 0x7f, 0x20000006, 0x4d, 0x6, 0x5f, 0x9, 0x4, 0xffff2d37, 0xff7fff01, 0x6, 0x3, 0x7, 0x5, 0x4, 0x0, 0x7, 0x3c5b, 0x1, 0x24, 0xd, 0x1, 0x0, 0xffffffff, 0xe661, 0x4, 0x7, 0x3, 0x8, 0x4c34, 0x10000, 0x242, 0x3, 0xe, 0x0, 0x80008071, 0x7, 0x17, 0x1, 0x7, 0x5, 0x3e, 0x8e, 0x6, 0x6, 0x0, 0x5, 0x4, 0x8, 0x3ff, 0x80, 0x0, 0x5, 0x6, 0x8, 0x4, 0x1, 0x40], [0x10000007, 0x9, 0x8000012f, 0x8004, 0x5, 0x8, 0x129432e6, 0xc8, 0xf9, 0xe, 0x2bf, 0x6c7, 0x9, 0xfffffffc, 0x3, 0x0, 0x0, 0x5, 0x2f, 0xe, 0x312, 0x78, 0xea4, 0x0, 0x4, 0x7, 0x7fff, 0x6, 0x400, 0x401, 0x6, 0x1, 0xff, 0x5, 0x1000005, 0x5f31, 0xd, 0x4e0, 0x2, 0x4, 0xb, 0x4, 0x9, 0x8, 0x9, 0x6, 0x47, 0x8000, 0x1, 0xfe000000, 0xffff, 0x2, 0x4, 0x9, 0x3, 0x3, 0x9, 0x1, 0x3, 0x3, 0xbc45, 0x48c93690, 0x42, 0x3], [0x7, 0x408, 0x4, 0x5, 0xfffffffe, 0x100, 0x4, 0x9, 0x5, 0x7fff, 0x0, 0x5, 0xb, 0x4, 0x5, 0x5, 0x0, 0x1ef, 0x5, 0x8, 0x86, 0x3, 0x303c, 0x3e7, 0xb, 0x5, 0x2, 0x2, 0x3, 0x20000008, 0x4, 0x6d01, 0x6, 0x38, 0x800003, 0x200, 0x80, 0x3, 0x4, 0x2950bfaf, 0x1000, 0xa2, 0x7, 0xa9, 0x5, 0x6, 0xac8, 0xbf, 0x2, 0x3, 0x7ff, 0x12b, 0x4, 0x1, 0xa, 0x0, 0x5, 0x1c, 0x120000, 0x3, 0x2006, 0x80a2ed, 0x4, 0x25], [0x9, 0xbb33, 0x7, 0xb, 0x5, 0x938, 0x6, 0x6, 0x0, 0xb9, 0xce4, 0x1ff, 0x2, 0x57, 0x5, 0x3, 0x101, 0x10000, 0x4, 0x7fff, 0xffff, 0xa620, 0x1, 0x5, 0x1, 0x2000002, 0x14c, 0x60a7, 0x6, 0x16, 0xffffffff, 0x80000000, 0x5, 0x4, 0xc8, 0x1, 0xfffff000, 0x10000, 0x3, 0x7e, 0x100, 0x9622, 0x7, 0xaf, 0x8, 0x6, 0x226, 0x5, 0x5, 0x0, 0x30b1d693, 0xa1f, 0xf40, 0x7, 0x1, 0x6c1b, 0x0, 0x4, 0x5, 0xb1e, 0xd7, 0x200, 0xffff3441, 0xfff]}, 0x45c) ppoll(&(0x7f00000000c0)=[{}, {}], 0x20000000000000dc, 0x0, 0x0, 0x0) 391.44214ms ago: executing program 3 (id=167): r0 = syz_init_net_socket$nl_rdma(0x10, 0x3, 0x10) readv(r0, &(0x7f0000000040)=[{&(0x7f00000000c0)=""/214, 0xd6}], 0x1) sendmsg$netlink(r0, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000000)=[{&(0x7f0000000200)=ANY=[@ANYBLOB="140100001e0001eb25bd7000000000000117731e0664ebd3d82663bc5e186fc3f109d06b5732493414e886d7ef66c1fbfdb4c0abe1097bef015c99aea82d37bbd93a6fe9dc635a348b805ca5c1f186a3404c7378e4d90206e88a7628a06110c880435143842fc7544c61237f5e4926d0c81a812af97cccaff88d778eb861f7aa440df25bc875f6b1c6c86d12ec5dcced63fdbdc6ef4806b47a6de8cd"], 0x114}], 0x1}, 0x0) 271.963189ms ago: executing program 0 (id=168): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f000000c2c0)={0x0, 0xfffffffffffffe01, &(0x7f0000000200)={&(0x7f0000000340)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101000000005e1affd5020000000900010073797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a30000000000900030073797a320000000014000000110001"], 0x7c}}, 0x0) sendmsg$NFT_BATCH(r0, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000240)=ANY=[@ANYBLOB="140000001000010000000000000000000a00000a64000000060a0b0400000000000000000200008738000480340001800a0001006c696d6974000000240002800c000240000000000000000308000440000000010c00014000000000000000020908000000797a30000000000900020073797a3200000000140000001100010000000000000000000200000a"], 0x8c}}, 0x14b6deac033214c2) 271.794679ms ago: executing program 3 (id=169): r0 = socket(0x10, 0x3, 0x0) setsockopt$netlink_NETLINK_TX_RING(r0, 0x10e, 0xc, &(0x7f0000000180)={0x80000000}, 0x19a) (async) setsockopt$netlink_NETLINK_TX_RING(r0, 0x10e, 0xc, &(0x7f0000000180)={0x80000000}, 0x19a) sendmsg$nl_route(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000000380)=@mpls_getroute={0x24, 0x1a, 0x1, 0x0, 0x0, {0x1c, 0x14}, [@RTA_DST={0x8, 0x13, {0x7}}]}, 0x24}, 0x1, 0x0, 0x0, 0x40000c0}, 0x80) 271.417591ms ago: executing program 0 (id=170): r0 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$IPSET_CMD_CREATE(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000001c0)=ANY=[@ANYBLOB="24720000020605000000000000400000000000000900020073797a3200000000040006"], 0x24}, 0x1, 0x0, 0x0, 0x20040004}, 0x80) mkdirat(0xffffffffffffff9c, &(0x7f0000000240)='./file0\x00', 0x0) mount$9p_virtio(&(0x7f00000001c0), &(0x7f0000000480)='./file0\x00', &(0x7f00000004c0), 0x0, &(0x7f0000000c00)=ANY=[@ANYBLOB="56c78e3c733d76697274696f2c6e6f657874656e642c6163638173733d616e792c63616368653d667363616368652c76657273696f6e3d3970323030302e75"]) chdir(&(0x7f0000000300)='./file0\x00') r1 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000000c0)='blkio.throttle.io_service_bytes_recursive\x00', 0x275a, 0x0) write$binfmt_script(r1, &(0x7f0000000640)={'#! ', './file0', [], 0xa, "7bad65c4da5338577feb172ca63250224c76e2027f000000000000007e2ac7fe2e31a2"}, 0x2e) userfaultfd(0x1) sendmsg$nl_generic(r0, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000180)={&(0x7f00000001c0)=ANY=[@ANYBLOB="340000003e000900000000000008000003000000040004001c000180180010"], 0x34}}, 0x84) 211.621553ms ago: executing program 3 (id=171): getsockopt$EBT_SO_GET_INIT_ENTRIES(0xffffffffffffffff, 0x0, 0x83, &(0x7f0000000100)={'nat\x00', 0x0, 0x4, 0x6c, [0x2, 0x7, 0x4, 0x6, 0xffffffffffffd9ca, 0x2], 0x4, &(0x7f0000000040)=[{}, {}, {}, {}], &(0x7f0000000080)=""/108}, &(0x7f0000000180)=0x78) r0 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r0, &(0x7f00000014c0)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000000)={0x2, 0xd, 0x0, 0x0, 0x18, 0x0, 0x70bd2c, 0x0, [@sadb_x_policy={0x8, 0x12, 0x0, 0x2, 0x0, 0x0, 0x0, {0x6, 0x0, 0x0, 0x0, 0x0, 0xfffffffd, 0x0, @in=@initdev={0xac, 0x1e, 0xfa, 0x0}, @in=@broadcast}}, @sadb_address={0x5, 0x5, 0x0, 0x0, 0x0, @in6={0xa, 0x0, 0x0, @local}}, @sadb_address={0x5, 0x6, 0x0, 0x0, 0x0, @in6={0xa, 0x0, 0x0, @private2}}, @sadb_lifetime={0x4, 0x3, 0x2f}]}, 0xc0}}, 0x0) (async) r1 = bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000340)={&(0x7f0000000280)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0xc, 0xc, 0x9, [@ptr={0x7, 0x0, 0x0, 0x2, 0x2}]}, {0x0, [0x0, 0x30, 0x5f, 0x61, 0x0, 0x5f, 0x61]}}, &(0x7f00000002c0)=""/91, 0x2d, 0x5b, 0x0, 0x2, 0x10000, @value}, 0x28) (async) r2 = syz_open_dev$sndpcmc(&(0x7f0000000400), 0x0, 0x0) ioctl$SNDRV_PCM_IOCTL_STATUS32(r2, 0x80984120, &(0x7f0000000080)) (async) bpf$PROG_LOAD_XDP(0x5, &(0x7f00000001c0)={0x12, 0x1b6, &(0x7f0000000000)=@framed={{}, [@call={0x85, 0x0, 0x0, 0x19}]}, &(0x7f0000000480)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0xa, r1, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 210.86161ms ago: executing program 0 (id=172): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) r1 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000600), 0x0) ioctl$SNDRV_SEQ_IOCTL_CREATE_QUEUE(r1, 0xc08c5332, &(0x7f00000003c0)={0x9c9, 0x0, 0x0, 'queue1\x00', 0x200000}) (async) fspick(0xffffffffffffff9c, &(0x7f0000000000)='.\x00', 0x0) ioctl$SNDRV_SEQ_IOCTL_SET_QUEUE_TIMER(r1, 0x40605346, &(0x7f00000004c0)={0x3, 0x0, {0xffffffffffffffff, 0x2, 0x20000000, 0x0, 0x2}, 0x2}) r2 = memfd_create(&(0x7f00000011c0)='\x9d#\x00\xe6Z\x00\xafq%\xa5\x83\xa6\xb5\x00\x83y\xf3\xb2\xe6b\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x17?&^\xe1Ob\xe1Y\xd6\xeb\x91\x83;\xeb\xf1\xd0\xe3\xe5\x19T\xff\x01\x00\x00\xe2\x9f\xd9\xae\xcf>/\x05V%$6\x9fU\x86\xbe\xcbx\x00\x00\x00\x15\x00\x00\x00\xa1\xa2\xe0g\x98\xbf*\xa2c\x12.\xb7\xbe`\'\xcb\xb6\xaf\xdc\xa0D\x93.\xf25\x957\xec\xfb\xe6|\\\xe4h\xfc\x14\x06\xb5\xaa\xe6\x05\xe4\xc3\x90\x91\x98\x15\xec\xdb\xaa\t9\x11\xb4\x84$&0\xdd\x19\x86\x90\xbe\xd7\xdc\n\xcbC\x15\xfcp\x11\xdai\f{a?\xd0\xe1{\x84\xb5\x82q\x19\xacS\x88|\x99\xfd\x9eS\x80\xcb\x14G\xfa\xff\xff\xff\xff\xff\xff\xff\xcd\xf0%\x97!\xba\xe3J\xc2t\x96\xf8\xb1\xd2\x168\xbf`$\xbf\xca\xea\xa3\x83\x8e-k\x12\xdf\xb9q\xb6Pr\xd4\xb5X\\\xdbD\n\x03G\x00\x04\x00\x00\xbc\xac\x18\xba\xce\xb3%QF\x03\b\x9dh\xcb)\xf4f\x12[\xf9\r\t\xef{h\xb0\xc0:\x8f|\x8f\x06\xf8\x83\x87+nM\x11\x1c\xb0*8\v\x1e\xcf\x03\xd3\xe8,?\x87\x84\\/y\xed\x01#?\xab\x1c\x11\x00\xc5\x8d\x82\x9c\xd6B[\xc9\x00\xf5]\x81\xf3\xfd\x06M\xbe\xf9\xba\x9em\xe9\"\x03\x933P\xa3\xcc\x9b\f\xa7\x8f\x91O\xc9\xb9\x10M\x8b\xd0\xc0\xb8L\xbd\x1c4\xb59\x988\tgC\xbc\xe0\xc5\xf4\xe0E%\xd9\xd8w\x00k\x042Y\xdc\xc5\xe59\xa95\xd1m\xd8hCuZYi\x10D\xb9\xe6\xff\x04K%yH\xe5W\xfb\x82\xac\x19,\\D\x91T\xfd\x9c\xb8\x8b\x88\xa5\xcc\x8fI\x00\xf0\xc9%\n\xa7\xd6\x0f:\xb0\xf5?\xc3\x88\x1e\xbb-\xa6\xecA\x92\xaf\xa4Xl\v\xa5\xca\v|\xe2L\xac\x80\xc7\x15\x96fh\x83\x15\xc7\xea\xd5\xe8\x89W\x11\xd7oC\xe4\x06\xa8[O\xe6\x1d=\x87\x93\x0f\x87I\xdf\xb1\xeb\x89\x11.\x01\x00\r`\x1e8\x94\v)\x06B\xf0\xed\x91 )y\xb4\xba\xba\xb7\xbc\xc3\xad\xf1\x92/(A=A\x8b\xa5\xb0\x89\x9e5\x12\xa4\x9a\va\xdf\xf4\xea\xc6\xc7\x10g\x1d\xd5\xb0\xbb\xd2\xfc]fC\x8d\x0f\xa6q\x0f\xef\x90\xfe\x94k\xf1\xb8\xfa\xbbb\xb1\x03\x99\xf7\xfd\'\xae\x906\xe0\xaa\xdbtWWH\xa4L\xb5pe,\xdfN\x0f8\t\xe7X_H\xd4\xe3\xb2,oj\xac\xd7\xbd\xd0\xadW\x1f<\xd0\b\x00\x00\x00\x00/ \xe4]@\xf7mA\xe8\xd1\xf4:\xb3\xeb\x81\xb9\x018\x1c\x95%o\x05x\x1a\x90\xf4\x03\xe7\xe9\xa9', 0x7) fallocate(r2, 0x0, 0x0, 0x400001) (async) r3 = syz_open_dev$evdev(&(0x7f0000000000), 0x100, 0x402000) (async, rerun: 32) readv(r2, &(0x7f0000000b40)=[{&(0x7f0000000700)=""/217, 0xd9}, {&(0x7f00000000c0)}, {&(0x7f0000000580)=""/80, 0x50}, {&(0x7f0000000800)=""/140, 0x8c}, {&(0x7f0000000100)=""/29, 0x1d}, {&(0x7f00000008c0)=""/183, 0xb7}, {&(0x7f0000000480)=""/43, 0x2b}, {&(0x7f0000000980)=""/247, 0xf7}, {&(0x7f0000000a80)=""/67, 0x43}, {&(0x7f0000000b00)}], 0xa) (rerun: 32) r4 = openat$rdma_cm(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r4, &(0x7f0000000040)={0x0, 0x18, 0xfa00, {0x1, &(0x7f0000000300)={0xffffffffffffffff}, 0x106, 0x8}}, 0x20) ioctl$EVIOCGBITSW(r3, 0x80404525, &(0x7f0000000640)=""/177) (async) write$RDMA_USER_CM_CMD_RESOLVE_ADDR(r4, &(0x7f0000000140)={0x15, 0x110, 0xfa00, {r5, 0x0, 0x30, 0x30, 0x0, @in6={0x1b, 0x0, 0x0, @loopback, 0x3ff}, @ib={0x1b, 0xffff, 0x0, {'\x00\a\x00'}, 0x0, 0x40000000, 0x7ffd}}}, 0x118) close_range(r3, r4, 0x2) ioctl$FS_IOC_RESVSP(r2, 0x4030582b, &(0x7f0000000080)={0x0, 0x0, 0x9, 0x100000001}) (async) r6 = socket$inet6(0xa, 0x4, 0x5) (async) setsockopt$sock_linger(0xffffffffffffffff, 0x1, 0x3c, &(0x7f0000000280)={0x1}, 0x8) (async, rerun: 32) r7 = syz_open_dev$dri(&(0x7f0000000180), 0x1, 0x0) (async, rerun: 32) r8 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000000), 0x101002, 0x0) ioctl$IOMMU_IOAS_ALLOC(r8, 0x3b81, &(0x7f00000003c0)={0xc, 0x0, 0x0}) ioctl$IOMMU_IOAS_MAP$PAGES(r8, 0x3b85, &(0x7f00000000c0)={0x28, 0x7, r9, 0x0, &(0x7f0000800000/0x800000)=nil, 0x800000}) (async, rerun: 32) close_range(r7, 0xffffffffffffffff, 0x0) (async, rerun: 32) sendto$inet6(r6, 0x0, 0x0, 0x4000000, &(0x7f0000000140)={0xa, 0x4e20, 0x3, @local, 0x6}, 0x1c) r10 = socket(0x2, 0x80805, 0x0) (async, rerun: 64) r11 = socket(0x2, 0x80805, 0x0) (rerun: 64) getsockopt$inet_sctp6_SCTP_SOCKOPT_CONNECTX3(r11, 0x84, 0x6f, &(0x7f0000000000)={0x0, 0x10, &(0x7f0000001100)=[@in={0x2, 0x0, @rand_addr=0x64010101}]}, &(0x7f0000000180)=0x10) getsockopt$inet_sctp_SCTP_MAX_BURST(0xffffffffffffffff, 0x84, 0x14, &(0x7f0000000540)=@assoc_value={0x0}, &(0x7f0000001080)=0xffffff40) getsockopt$inet_sctp_SCTP_PR_SUPPORTED(r10, 0x84, 0x71, &(0x7f0000000080)={r12, 0x7}, &(0x7f00000002c0)=0x8) (async) setsockopt$inet_sctp6_SCTP_PR_SUPPORTED(r6, 0x84, 0x71, &(0x7f00000000c0)={r13, 0x1}, 0x8) (async) sendmsg$NFT_BATCH(r0, &(0x7f000000c2c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000340)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101000000005e1affd5020000000900010073797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a30000000000900030073797a320000000014000000110001"], 0x7c}}, 0x0) 210.598604ms ago: executing program 3 (id=173): r0 = socket$nl_xfrm(0x10, 0x3, 0x6) r1 = syz_io_uring_setup(0x10e, &(0x7f0000000140)={0x0, 0xd6ab, 0x100, 0x1}, &(0x7f0000000240)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r2, r3, &(0x7f00000002c0)=@IORING_OP_SHUTDOWN={0x22, 0x13}) io_uring_enter(r1, 0x7ffe, 0x184c, 0x2, 0x0, 0x0) futex(&(0x7f000000cffc)=0x4, 0x0, 0x4, &(0x7f000000b000)={0x77359400}, 0x0, 0x0) sendmsg$nl_xfrm(r0, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000880)=@newsa={0x138, 0x1a, 0x713, 0x0, 0x10, {{@in6=@loopback, @in6=@initdev={0xfe, 0x88, '\x00', 0x1, 0x0}, 0x6e21}, {@in6=@initdev={0xfe, 0x88, '\x00', 0x8, 0x0}, 0x0, 0x32}, @in=@broadcast, {0x0, 0xfffffffffffffffc, 0x0, 0x0, 0x8000000000002000}, {}, {0x2}, 0x0, 0x4, 0xa, 0x5}, [@algo_crypt={0x48, 0x2, {{'ecb(cipher_null)\x00'}}}]}, 0x138}}, 0x0) sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000000)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f00000000c0)=@newlink={0x58, 0x10, 0x601, 0x0, 0x0, {0x0, 0x0, 0x0, 0x0, 0x4000}, [@IFLA_LINKINFO={0x1c, 0x12, 0x0, 0x1, @geneve={{0xb}, {0xc, 0x2, 0x0, 0x1, [@IFLA_GENEVE_ID={0x8, 0x1, 0x1}]}}}, @IFLA_IFNAME={0x14, 0x3, 'geneve1\x00'}, @IFLA_CARRIER_CHANGES={0x8, 0x23, 0x3}]}, 0x58}, 0x1, 0x0, 0x0, 0x4000}, 0x2040000) 71.718738ms ago: executing program 2 (id=174): r0 = socket(0x10, 0x3, 0x0) setsockopt$netlink_NETLINK_TX_RING(r0, 0x10e, 0xc, &(0x7f0000000100)={0x80000000, 0x0, 0xfffffffc}, 0x10) (async) write(r0, &(0x7f0000000000)="240000001a005f0214f9f407000904001f000000fe0000000000000008000f00fd000000", 0x24) (async) r1 = openat$adsp1(0xffffffffffffff9c, &(0x7f0000000180), 0x2, 0x0) ioctl$SNDCTL_DSP_SETFRAGMENT(r1, 0xc004500a, &(0x7f0000000080)) (async) r2 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000000), 0xa4242, 0x0) sendfile(r2, r2, 0x0, 0x40008) ioctl$SNDCTL_DSP_CHANNELS(r1, 0xc0045006, &(0x7f0000000000)=0x2b) (async) ioctl$SNDCTL_DSP_SPEED(r1, 0xc0045002, &(0x7f00000001c0)) 70.097192ms ago: executing program 0 (id=175): mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f0000000040)='devpts\x00', 0x0, 0x0) umount2(&(0x7f00000002c0)='./file0\x00', 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x0) (async) mount(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f0000000040)='devpts\x00', 0x0, 0x0) (async) umount2(&(0x7f00000002c0)='./file0\x00', 0x0) (async) 67.290926ms ago: executing program 2 (id=176): r0 = socket(0x28, 0x5, 0x0) r1 = socket(0x28, 0x5, 0x0) bind$vsock_stream(r1, &(0x7f0000000040)={0x28, 0x0, 0x0, @local}, 0x10) r2 = openat$sndtimer(0xffffffffffffff9c, &(0x7f0000000000), 0x0) read$proc_mixer(r2, 0x0, 0x0) listen(r1, 0x4) connect$vsock_stream(r0, &(0x7f0000000080)={0x28, 0x0, 0x0, @local}, 0x10) sendmmsg(r0, &(0x7f0000000100)=[{{0x0, 0x2d, &(0x7f00000000c0)=[{&(0x7f0000000000)="1b", 0x40000}], 0x1}}], 0x51, 0x0) write$uinput_user_dev(0xffffffffffffffff, &(0x7f0000000400)={'syz1\x00', {0x3, 0x2, 0x6, 0xfffa}, 0x3a, [0x8000, 0xc95a, 0xf, 0x8, 0x80, 0x2, 0x3, 0x7f, 0x20000006, 0x4d, 0x6, 0x5f, 0x9, 0x4, 0xffff2d37, 0xff7fff01, 0x6, 0x3, 0x7, 0x5, 0x4, 0x0, 0x8001, 0x3c5b, 0x1, 0x24, 0xd, 0x1, 0x0, 0xffffffff, 0xe661, 0x4, 0x7, 0x3, 0x8, 0x4c34, 0x10000, 0x242, 0x3, 0xe, 0x0, 0x80008071, 0x7, 0x17, 0x5, 0x7, 0x5, 0x3e, 0x8e, 0x6, 0x6, 0x0, 0x5, 0x4, 0x8, 0x3ff, 0x80, 0x0, 0x5, 0x6, 0x8, 0x4, 0x1, 0x40], [0x10000007, 0x9, 0x8000012f, 0x8004, 0x5, 0x8, 0x129432e6, 0xc8, 0xf9, 0xe, 0x2bf, 0x6c7, 0x9, 0xfffffffc, 0x3, 0x0, 0x0, 0x5, 0x2f, 0xe, 0x312, 0x78, 0xea4, 0x0, 0x4, 0x7, 0x7fff, 0x6, 0x400, 0x401, 0x6, 0x1, 0xff, 0x5, 0x1000005, 0x5f31, 0xd, 0x4e0, 0x2, 0x4, 0xb, 0x4, 0x9, 0x8, 0x9, 0x6, 0x47, 0x8000, 0x1, 0xfe000000, 0xffff, 0x2, 0x4, 0x9, 0x3, 0x3, 0x9, 0x1, 0x3, 0x3, 0xbc45, 0x48c93690, 0x42, 0x3], [0x7, 0x408, 0x4, 0x5, 0xfffffffe, 0x100, 0x4, 0x9, 0x5, 0x7fff, 0x0, 0x5, 0xb, 0x4, 0x5, 0x5, 0x0, 0x1ef, 0x5, 0x8, 0x86, 0x3, 0x303c, 0x3e7, 0xb, 0x5, 0x2, 0x2, 0x3, 0x20000008, 0x4, 0x6d01, 0x6, 0x38, 0x800003, 0x200, 0x80, 0x3, 0x4, 0x2950bfaf, 0x1000, 0xa2, 0x7, 0xa9, 0x5, 0x6, 0xac8, 0xbf, 0x2, 0x3, 0x7ff, 0x12b, 0x4, 0x1, 0xa, 0x0, 0x5, 0x1c, 0x120000, 0x3, 0x2006, 0x80a2ed, 0x4, 0x25], [0x9, 0xbb33, 0x7, 0xb, 0x5, 0x938, 0x6, 0x6, 0x0, 0xb9, 0xce4, 0x1ff, 0x2, 0x57, 0x5, 0x3, 0x101, 0x10000, 0x4, 0x7fff, 0xffff, 0xa620, 0x1, 0x5, 0x1, 0x2000002, 0x14c, 0x60a7, 0x6, 0x16, 0xffffffff, 0x80000000, 0x5, 0x4, 0xc8, 0x1, 0xfffff000, 0x10000, 0x3, 0x7e, 0x100, 0x9622, 0x7, 0xaf, 0x8, 0x6, 0x226, 0x5, 0x5, 0x0, 0x30b1d693, 0xa1f, 0xf40, 0x7, 0x1, 0x6c1b, 0x0, 0x4, 0x5, 0xb1e, 0xd7, 0x200, 0xffff3441, 0xfff]}, 0x45c) ppoll(&(0x7f00000000c0)=[{}, {}], 0x20000000000000dc, 0x0, 0x0, 0x0) socket$inet6_icmp_raw(0xa, 0x3, 0x3a) 1.4099ms ago: executing program 0 (id=177): r0 = socket$pptp(0x18, 0x1, 0x2) bind$pptp(r0, &(0x7f0000000000)={0x18, 0x2, {0x0, @local}}, 0x1e) (async) bind$pptp(r0, &(0x7f0000000000)={0x18, 0x2, {0x0, @local}}, 0x1e) socket$pptp(0x18, 0x1, 0x2) (async) r1 = socket$pptp(0x18, 0x1, 0x2) bind$pptp(r1, &(0x7f0000000040)={0x18, 0x2, {0x85e0, @private=0xa010101}}, 0x1e) sched_yield() socket$pptp(0x18, 0x1, 0x2) (async) socket$pptp(0x18, 0x1, 0x2) sched_yield() bind$pptp(r0, &(0x7f0000000080)={0x18, 0x2, {0x2, @remote}}, 0x1e) bind$pptp(r0, &(0x7f00000000c0)={0x18, 0x2, {0x2, @empty}}, 0x1e) ioctl$AUTOFS_DEV_IOCTL_VERSION(0xffffffffffffffff, 0xc0189371, &(0x7f0000000100)={{0x1, 0x1, 0x18, r1}, './file0\x00'}) bind$pptp(r2, &(0x7f0000000140)={0x18, 0x2, {0x0, @local}}, 0x1e) (async) bind$pptp(r2, &(0x7f0000000140)={0x18, 0x2, {0x0, @local}}, 0x1e) sched_yield() (async) sched_yield() ioctl$PPPIOCGMRU(r0, 0x80047453, &(0x7f0000000180)) (async) ioctl$PPPIOCGMRU(r0, 0x80047453, &(0x7f0000000180)) connect$pptp(r2, &(0x7f00000001c0)={0x18, 0x2, {0x1, @remote}}, 0x1e) (async) connect$pptp(r2, &(0x7f00000001c0)={0x18, 0x2, {0x1, @remote}}, 0x1e) sched_yield() sched_yield() ioctl$AUTOFS_DEV_IOCTL_ISMOUNTPOINT(r2, 0xc018937e, &(0x7f0000000200)={{0x1, 0x1, 0x18, r1, {0x4}}, './file0\x00'}) sched_yield() syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) (async) r3 = syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) r4 = syz_genetlink_get_family_id$ieee802154(&(0x7f0000000280), 0xffffffffffffffff) sendmsg$IEEE802154_LLSEC_LIST_DEV(r3, &(0x7f0000000340)={&(0x7f0000000240)={0x10, 0x0, 0x0, 0x48000000}, 0xc, &(0x7f0000000300)={&(0x7f00000002c0)={0x14, r4, 0x20, 0x70bd25, 0x25dfdbfe, {}, [""]}, 0x14}, 0x1, 0x0, 0x0, 0x4830}, 0x0) sched_yield() (async) sched_yield() ioctl$BTRFS_IOC_SEND(r0, 0x40489426, &(0x7f00000003c0)={{r0}, 0x4, &(0x7f0000000380)=[0x7ab, 0xbc02, 0x2, 0x800], 0x4, 0x7, 0x1}) (async) ioctl$BTRFS_IOC_SEND(r0, 0x40489426, &(0x7f00000003c0)={{r0}, 0x4, &(0x7f0000000380)=[0x7ab, 0xbc02, 0x2, 0x800], 0x4, 0x7, 0x1}) sched_yield() rename(&(0x7f0000000440)='./file0\x00', &(0x7f0000000480)='./file0/file0\x00') sched_yield() sched_yield() sched_yield() sched_yield() getsockopt$inet_sctp_SCTP_HMAC_IDENT(r2, 0x84, 0x16, &(0x7f00000004c0)={0x4, [0x82, 0x7, 0xffff, 0x4]}, &(0x7f0000000500)=0xc) 0s ago: executing program 2 (id=178): openat$kvm(0xffffffffffffff9c, &(0x7f0000000040), 0x22042, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)) socket$kcm(0x2, 0x3, 0x2) (async) r0 = socket$kcm(0x2, 0x3, 0x2) ioctl$sock_SIOCETHTOOL(r0, 0x8946, 0x0) socket$kcm(0x10, 0x2, 0x0) (async) socket$kcm(0x10, 0x2, 0x0) socket$netlink(0x10, 0x3, 0x0) (async) r1 = socket$netlink(0x10, 0x3, 0x0) r2 = socket(0x10, 0x803, 0x0) sendmsg$nl_route_sched(r2, &(0x7f00000003c0)={0x0, 0x0, &(0x7f0000000380)={0x0, 0x24}}, 0x0) getsockname$packet(r2, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000200)=0x2ba) sendmsg$nl_route(r1, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000400)=ANY=[], 0x3c}, 0x1, 0x0, 0x0, 0x240408c4}, 0x0) (async) sendmsg$nl_route(r1, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000400)=ANY=[], 0x3c}, 0x1, 0x0, 0x0, 0x240408c4}, 0x0) r4 = socket(0x10, 0x3, 0x0) sendmsg$nl_route(r4, &(0x7f0000000840)={0x0, 0x0, &(0x7f0000000000)={&(0x7f00000000c0)=ANY=[@ANYBLOB="280000001000030412c3c1824c32d28400000000fcffffff00000000", @ANYRES32=r3, @ANYBLOB="7fff00000000000008000500", @ANYRES32=0x0, @ANYBLOB], 0x28}}, 0x0) r5 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r5, &(0x7f0000000280)={&(0x7f0000000180)={0x10, 0x0, 0x0, 0x200000}, 0xc, &(0x7f0000000240)={&(0x7f00000001c0)=@ipv6_newnexthop={0x1c, 0x68, 0x8, 0x70bd2d, 0x25dfdbfd, {0xa, 0x0, 0x4, 0x0, 0xd}, [@NHA_GROUP={0x4}]}, 0x1c}, 0x1, 0x0, 0x0, 0x20048880}, 0x800) (async) sendmsg$nl_route(r5, &(0x7f0000000280)={&(0x7f0000000180)={0x10, 0x0, 0x0, 0x200000}, 0xc, &(0x7f0000000240)={&(0x7f00000001c0)=@ipv6_newnexthop={0x1c, 0x68, 0x8, 0x70bd2d, 0x25dfdbfd, {0xa, 0x0, 0x4, 0x0, 0xd}, [@NHA_GROUP={0x4}]}, 0x1c}, 0x1, 0x0, 0x0, 0x20048880}, 0x800) r6 = socket$nl_route(0x10, 0x3, 0x0) socket(0x1, 0x803, 0x0) (async) r7 = socket(0x1, 0x803, 0x0) getsockname$packet(r7, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f00000002c0)=0x14) sendmsg$nl_route(r6, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000700)=@newlink={0x54, 0x10, 0x401, 0x0, 0x0, {0x0, 0x0, 0x0, 0x0, 0x0, 0x12}, [@IFLA_LINKINFO={0x2c, 0x12, 0x0, 0x1, @ip6gretap={{0xe}, {0x18, 0x2, 0x0, 0x1, [@IFLA_GRE_REMOTE={0x14, 0x7, @private0}]}}}, @IFLA_MASTER={0x8, 0xa, r8}]}, 0x54}}, 0x0) 0s ago: executing program 0 (id=179): r0 = socket(0x22, 0xa, 0xfffffffe) bpf$PROG_LOAD(0x5, &(0x7f00000006c0)={0x15, 0xe, &(0x7f0000000a40)=ANY=[@ANYBLOB="b7020000380d0000bfa30000000000000703000000feffff720af0fff8ffff1989a4f0ff00000000b7060000080000001e640000000000004504040001000000170400000c000a00b7040000ff0100006a0af2fe00000000850000001a000000b70000003f00000095000000000000009e17f199a68b06d83298a8cdc21ce784909b849d5550ad857d0454d8877a6db61d69f2ffcaa10350e11cb97c8adf1bc9a0c4eeceb9971e43405d621ffbc9ce000000d8ca56b50d0c010d631f6dde53a9a53608c10556e5734eb84049761451ce540c772e2d9f8004e26f7fcc059c062234d5595f6fbaa187b81d1106000000000f0000fd9ac3d09e29a9d542ca9d85a5c9c88474895d679838def0a83a733dc6a39b63a5ed69d32394c53361d7e43c5cbd8000000000000080231c61ccd106cb937b450f859ce8122a79c3e40000b59b0fc46d6cec3c0802882add4e1179bd4a44f231b6d753a7be428ba953df4aece69311687f4122073a236c3a32efa04137d4524847d2638da3261c8162bb7c7824be6195a66d2e17e122040e1100000000928612a29fc691e4f1f7bd053abb885f39381f1759410b1059f05684261f332d606834669b49ec99320ca7712d7e79bd5bf5ed818ecc7640917f6a559a47db608fcf9f6c131b84e41c354c66838f72b9e12d36e996f316f0812ca83efb30c7f6c6d57c4a64590401eec22523dd712c680013e87f649a1ede7142ca9d5d8a8c9f9b440fe4331ad5532c74d9a31a5d737537f7a2caa30581253d14dd3e92af7dc836686365ae01bdec561c0402b67801267a8df97d2f85426a5963d4fa3e26cc05972c162f223f000000d999e80de00fcbcc02d0aed7bb8f7ba337d59c14f39dcd4aad4139ef6425a9367f1bd1467fc6b95a4df7669839771ce9d5788029901e5a79d8b9990ace8f74087f25ad50c4608800000000000000005cbb5a2600"], &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @sk_reuseport, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000340), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000240)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFINDEX(r1, 0x8933, &(0x7f0000000000)={'lo\x00'}) mkdir(&(0x7f0000000040)='./file1\x00', 0x0) r2 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) ioctl$TIOCSETD(r2, 0x5423, &(0x7f00000000c0)=0xf) (async) r3 = fcntl$dupfd(r2, 0x0, r2) (async) r4 = syz_open_dev$vim2m(&(0x7f0000000040), 0x7, 0x2) ioctl$vim2m_VIDIOC_S_FMT(r4, 0xc0d05605, &(0x7f00000000c0)={0x1, @pix={0x5, 0x4, 0x32315852, 0x2, 0x6, 0x46, 0x2, 0x3, 0x1, 0x7, 0x0, 0x7}}) (async) getpgid(0x0) (async) ioctl$TCFLSH(r3, 0x400455c8, 0x8000000001) (async) ioctl$TIOCSETD(r3, 0x5412, &(0x7f0000000140)=0xffffffc0) (async) ioctl$TIOCSTI(r3, 0x5412, &(0x7f0000000040)=0xfc) (async, rerun: 64) mount$fuse(0x0, 0x0, 0x0, 0x100801b, &(0x7f0000000180)=ANY=[@ANYRESHEX=0x0]) (async, rerun: 64) setsockopt$inet_sctp_SCTP_NODELAY(r0, 0x84, 0x3, &(0x7f0000000100)=0x8001, 0x4) r5 = getpid() r6 = syz_pidfd_open(r5, 0x0) setns(r6, 0x24020000) (async) madvise(&(0x7f0000bdc000/0x4000)=nil, 0x86ac726dff2f4713, 0xa) syz_clone(0xf5982500, 0x0, 0x0, 0x0, 0x0, 0x0) (async, rerun: 64) mount(0x0, &(0x7f0000000140)='./file1\x00', &(0x7f0000000040)='autofs\x00', 0x0, &(0x7f0000000400)) (rerun: 64) chdir(&(0x7f0000000080)='./file1\x00') (async) r7 = socket$netlink(0x10, 0x3, 0xa) sendmsg$nl_xfrm(r7, &(0x7f0000004840)={0x0, 0x0, &(0x7f0000004800)={&(0x7f0000004540)=@polexpire={0xc0, 0x1b, 0x2, 0x70bd2c, 0x25dfdbff, {{{@in=@remote, @in6=@empty, 0x4e22, 0x7, 0x4e24, 0x5, 0x2, 0x180, 0x0, 0x3a}, {0x7, 0x100000001, 0x4, 0x0, 0x1, 0xffffffffffffff8b, 0x7, 0x5}, {0x9, 0x2, 0x1, 0x8}, 0x2, 0x6e6bbd, 0x2, 0x1, 0x2}, 0xa}}, 0xc0}, 0x1, 0x0, 0x0, 0x80}, 0x20008000) r8 = syz_init_net_socket$bt_hci(0x1f, 0x3, 0x1) bind$bt_hci(r8, &(0x7f0000000080)={0x1f, 0xffff, 0x3}, 0x6) (async) write(r8, &(0x7f0000000000)="0c000000010001", 0x7) (async, rerun: 32) mkdir(&(0x7f0000000040)='./bus\x00', 0x100) (async, rerun: 32) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000a00)={[{@workdir={'workdir', 0x3d, './bus'}}]}) kernel console output (not intermixed with test programs): [ 43.592277][ T40] audit: type=1400 audit(1748418874.133:63): avc: denied { rlimitinh } for pid=5859 comm="sh" scontext=system_u:system_r:sshd_t tcontext=root:sysadm_r:sysadm_t tclass=process permissive=1 [ 43.598295][ T40] audit: type=1400 audit(1748418874.133:64): avc: denied { siginh } for pid=5859 comm="sh" scontext=system_u:system_r:sshd_t tcontext=root:sysadm_r:sysadm_t tclass=process permissive=1 Warning: Permanently added '[localhost]:39664' (ED25519) to the list of known hosts. [ 44.812135][ T40] audit: type=1400 audit(1748418875.373:65): avc: denied { name_bind } for pid=5903 comm="sshd-session" src=30000 scontext=system_u:system_r:sshd_t tcontext=system_u:object_r:unreserved_port_t tclass=tcp_socket permissive=1 [ 44.836194][ T40] audit: type=1400 audit(1748418875.393:66): avc: denied { write } for pid=5904 comm="sh" path="pipe:[4941]" dev="pipefs" ino=4941 scontext=root:sysadm_r:sysadm_t tcontext=system_u:system_r:sshd_t tclass=fifo_file permissive=1 [ 44.856032][ T40] audit: type=1400 audit(1748418875.413:67): avc: denied { execute } for pid=5904 comm="sh" name="syz-executor" dev="sda1" ino=2020 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:etc_runtime_t tclass=file permissive=1 [ 44.863091][ T40] audit: type=1400 audit(1748418875.413:68): avc: denied { execute_no_trans } for pid=5904 comm="sh" path="/syz-executor" dev="sda1" ino=2020 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:etc_runtime_t tclass=file permissive=1 [ 46.894877][ T40] audit: type=1400 audit(1748418877.453:69): avc: denied { mounton } for pid=5904 comm="syz-executor" path="/syzcgroup/unified" dev="sda1" ino=2022 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:root_t tclass=dir permissive=1 [ 46.897983][ T5904] cgroup: Unknown subsys name 'net' [ 47.034696][ T5904] cgroup: Unknown subsys name 'cpuset' [ 47.039298][ T5904] cgroup: Unknown subsys name 'rlimit' [ 47.303517][ T5925] SELinux: Context root:object_r:swapfile_t is not valid (left unmapped). Setting up swapspace version 1, size = 127995904 bytes [ 48.025790][ T5904] Adding 124996k swap on ./swap-file. Priority:0 extents:1 across:124996k [ 51.161735][ T40] kauditd_printk_skb: 13 callbacks suppressed [ 51.161746][ T40] audit: type=1400 audit(1748418881.723:83): avc: denied { execmem } for pid=5929 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=process permissive=1 [ 51.357651][ T40] audit: type=1400 audit(1748418881.913:84): avc: denied { create } for pid=5933 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 51.365092][ T40] audit: type=1400 audit(1748418881.913:85): avc: denied { read write } for pid=5933 comm="syz-executor" name="vhci" dev="devtmpfs" ino=1291 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:vhost_device_t tclass=chr_file permissive=1 [ 51.372607][ T40] audit: type=1400 audit(1748418881.913:86): avc: denied { open } for pid=5933 comm="syz-executor" path="/dev/vhci" dev="devtmpfs" ino=1291 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:vhost_device_t tclass=chr_file permissive=1 [ 51.379963][ T40] audit: type=1400 audit(1748418881.933:87): avc: denied { ioctl } for pid=5934 comm="syz-executor" path="socket:[7207]" dev="sockfs" ino=7207 ioctlcmd=0x48c9 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 51.398601][ T5936] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 51.401420][ T5936] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 51.404611][ T5949] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 51.407201][ T5949] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 51.410194][ T5949] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 51.411865][ T5944] Bluetooth: hci1: unexpected cc 0x0c03 length: 249 > 1 [ 51.412811][ T5949] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 51.415841][ T5944] Bluetooth: hci1: unexpected cc 0x1003 length: 249 > 9 [ 51.421449][ T40] audit: type=1400 audit(1748418881.983:88): avc: denied { read } for pid=5940 comm="syz-executor" dev="nsfs" ino=4026531840 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nsfs_t tclass=file permissive=1 [ 51.422535][ T5944] Bluetooth: hci1: unexpected cc 0x1001 length: 249 > 9 [ 51.422679][ T5948] Bluetooth: hci3: unexpected cc 0x0c03 length: 249 > 1 [ 51.427268][ T5947] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 51.428257][ T5939] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 51.428630][ T5947] Bluetooth: hci3: unexpected cc 0x1003 length: 249 > 9 [ 51.428986][ T5947] Bluetooth: hci3: unexpected cc 0x1001 length: 249 > 9 [ 51.429449][ T5947] Bluetooth: hci3: unexpected cc 0x0c23 length: 249 > 4 [ 51.429707][ T5947] Bluetooth: hci3: unexpected cc 0x0c38 length: 249 > 2 [ 51.431680][ T5947] Bluetooth: hci1: unexpected cc 0x0c23 length: 249 > 4 [ 51.433554][ T5939] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 51.435263][ T5947] Bluetooth: hci1: unexpected cc 0x0c38 length: 249 > 2 [ 51.436852][ T5939] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 51.445003][ T40] audit: type=1400 audit(1748418881.983:89): avc: denied { open } for pid=5940 comm="syz-executor" path="net:[4026531840]" dev="nsfs" ino=4026531840 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nsfs_t tclass=file permissive=1 [ 51.461013][ T40] audit: type=1400 audit(1748418881.983:90): avc: denied { mounton } for pid=5940 comm="syz-executor" path="/" dev="sda1" ino=2 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:root_t tclass=dir permissive=1 [ 51.644539][ T40] audit: type=1400 audit(1748418882.203:91): avc: denied { module_request } for pid=5940 comm="syz-executor" kmod="rtnl-link-nicvf" scontext=root:sysadm_r:sysadm_t tcontext=system_u:system_r:kernel_t tclass=system permissive=1 [ 51.726959][ T5940] chnl_net:caif_netlink_parms(): no params data found [ 51.755770][ T5942] chnl_net:caif_netlink_parms(): no params data found [ 51.887021][ T5933] chnl_net:caif_netlink_parms(): no params data found [ 51.891928][ T5940] bridge0: port 1(bridge_slave_0) entered blocking state [ 51.894184][ T5940] bridge0: port 1(bridge_slave_0) entered disabled state [ 51.896563][ T5940] bridge_slave_0: entered allmulticast mode [ 51.900123][ T5940] bridge_slave_0: entered promiscuous mode [ 51.927244][ T5940] bridge0: port 2(bridge_slave_1) entered blocking state [ 51.930400][ T5940] bridge0: port 2(bridge_slave_1) entered disabled state [ 51.932761][ T5940] bridge_slave_1: entered allmulticast mode [ 51.935349][ T5940] bridge_slave_1: entered promiscuous mode [ 52.023425][ T5940] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 52.026446][ T5942] bridge0: port 1(bridge_slave_0) entered blocking state [ 52.030912][ T5942] bridge0: port 1(bridge_slave_0) entered disabled state [ 52.033364][ T5942] bridge_slave_0: entered allmulticast mode [ 52.036741][ T5942] bridge_slave_0: entered promiscuous mode [ 52.043380][ T5942] bridge0: port 2(bridge_slave_1) entered blocking state [ 52.045689][ T5942] bridge0: port 2(bridge_slave_1) entered disabled state [ 52.048294][ T5942] bridge_slave_1: entered allmulticast mode [ 52.050931][ T5942] bridge_slave_1: entered promiscuous mode [ 52.054959][ T5940] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 52.069380][ T5934] chnl_net:caif_netlink_parms(): no params data found [ 52.175761][ T5942] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 52.198718][ T5940] team0: Port device team_slave_0 added [ 52.235441][ T5942] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 52.239899][ T5940] team0: Port device team_slave_1 added [ 52.242002][ T5933] bridge0: port 1(bridge_slave_0) entered blocking state [ 52.244547][ T5933] bridge0: port 1(bridge_slave_0) entered disabled state [ 52.246843][ T5933] bridge_slave_0: entered allmulticast mode [ 52.250041][ T5933] bridge_slave_0: entered promiscuous mode [ 52.296243][ T5933] bridge0: port 2(bridge_slave_1) entered blocking state [ 52.298552][ T5933] bridge0: port 2(bridge_slave_1) entered disabled state [ 52.300794][ T5933] bridge_slave_1: entered allmulticast mode [ 52.303431][ T5933] bridge_slave_1: entered promiscuous mode [ 52.341791][ T5942] team0: Port device team_slave_0 added [ 52.379710][ T5933] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 52.396842][ T5942] team0: Port device team_slave_1 added [ 52.399584][ T5940] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 52.401756][ T5940] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.410249][ T5940] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 52.416805][ T5933] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 52.446401][ T5934] bridge0: port 1(bridge_slave_0) entered blocking state [ 52.448853][ T5934] bridge0: port 1(bridge_slave_0) entered disabled state [ 52.451103][ T5934] bridge_slave_0: entered allmulticast mode [ 52.453780][ T5934] bridge_slave_0: entered promiscuous mode [ 52.472861][ T5940] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 52.475037][ T5940] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.483365][ T5940] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 52.500340][ T5934] bridge0: port 2(bridge_slave_1) entered blocking state [ 52.502686][ T5934] bridge0: port 2(bridge_slave_1) entered disabled state [ 52.505110][ T5934] bridge_slave_1: entered allmulticast mode [ 52.509174][ T5934] bridge_slave_1: entered promiscuous mode [ 52.542523][ T5942] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 52.544935][ T5942] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.554616][ T5942] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 52.564321][ T5933] team0: Port device team_slave_0 added [ 52.587943][ T5942] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 52.592567][ T5942] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.601968][ T5942] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 52.612220][ T5933] team0: Port device team_slave_1 added [ 52.616680][ T5934] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 52.623237][ T5934] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 52.701618][ T5940] hsr_slave_0: entered promiscuous mode [ 52.703920][ T5940] hsr_slave_1: entered promiscuous mode [ 52.785413][ T5933] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 52.788254][ T5933] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.798534][ T5933] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 52.805722][ T5934] team0: Port device team_slave_0 added [ 52.813444][ T5942] hsr_slave_0: entered promiscuous mode [ 52.816530][ T5942] hsr_slave_1: entered promiscuous mode [ 52.820377][ T5942] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 52.823745][ T5942] Cannot create hsr debugfs directory [ 52.826704][ T5933] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 52.829749][ T5933] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.840505][ T5933] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 52.862367][ T5934] team0: Port device team_slave_1 added [ 52.943180][ T5934] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 52.946144][ T5934] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 52.956965][ T5934] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 52.992534][ T5934] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 52.995242][ T5934] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 53.005524][ T5934] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 53.038299][ T5933] hsr_slave_0: entered promiscuous mode [ 53.040584][ T5933] hsr_slave_1: entered promiscuous mode [ 53.042693][ T5933] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 53.045057][ T5933] Cannot create hsr debugfs directory [ 53.143953][ T5934] hsr_slave_0: entered promiscuous mode [ 53.146257][ T5934] hsr_slave_1: entered promiscuous mode [ 53.150776][ T5934] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 53.153239][ T5934] Cannot create hsr debugfs directory [ 53.373529][ T5940] netdevsim netdevsim2 netdevsim0: renamed from eth0 [ 53.379767][ T5940] netdevsim netdevsim2 netdevsim1: renamed from eth1 [ 53.384378][ T5940] netdevsim netdevsim2 netdevsim2: renamed from eth2 [ 53.388917][ T5940] netdevsim netdevsim2 netdevsim3: renamed from eth3 [ 53.419849][ T5942] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 53.424911][ T5942] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 53.430093][ T5939] Bluetooth: hci2: command tx timeout [ 53.430146][ T5942] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 53.436527][ T5942] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 53.481450][ T5933] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 53.486854][ T5933] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 53.491667][ T5933] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 53.495702][ T5933] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 53.508286][ T5297] Bluetooth: hci0: command tx timeout [ 53.510150][ T5297] Bluetooth: hci1: command tx timeout [ 53.511565][ T5939] Bluetooth: hci3: command tx timeout [ 53.555499][ T5934] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 53.565808][ T5940] 8021q: adding VLAN 0 to HW filter on device bond0 [ 53.568845][ T5934] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 53.576800][ T5934] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 53.582735][ T5934] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 53.610371][ T5940] 8021q: adding VLAN 0 to HW filter on device team0 [ 53.621063][ T1206] bridge0: port 1(bridge_slave_0) entered blocking state [ 53.623302][ T1206] bridge0: port 1(bridge_slave_0) entered forwarding state [ 53.636256][ T5942] 8021q: adding VLAN 0 to HW filter on device bond0 [ 53.643452][ T96] bridge0: port 2(bridge_slave_1) entered blocking state [ 53.645746][ T96] bridge0: port 2(bridge_slave_1) entered forwarding state [ 53.670265][ T5942] 8021q: adding VLAN 0 to HW filter on device team0 [ 53.682216][ T46] bridge0: port 1(bridge_slave_0) entered blocking state [ 53.684602][ T46] bridge0: port 1(bridge_slave_0) entered forwarding state [ 53.705167][ T1206] bridge0: port 2(bridge_slave_1) entered blocking state [ 53.707390][ T1206] bridge0: port 2(bridge_slave_1) entered forwarding state [ 53.728816][ T5933] 8021q: adding VLAN 0 to HW filter on device bond0 [ 53.750569][ T5934] 8021q: adding VLAN 0 to HW filter on device bond0 [ 53.764684][ T40] audit: type=1400 audit(1748418884.323:92): avc: denied { sys_module } for pid=5940 comm="syz-executor" capability=16 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=capability permissive=1 [ 53.769055][ T5933] 8021q: adding VLAN 0 to HW filter on device team0 [ 53.781660][ T5934] 8021q: adding VLAN 0 to HW filter on device team0 [ 53.794982][ T95] bridge0: port 1(bridge_slave_0) entered blocking state [ 53.797960][ T95] bridge0: port 1(bridge_slave_0) entered forwarding state [ 53.803631][ T95] bridge0: port 1(bridge_slave_0) entered blocking state [ 53.806597][ T95] bridge0: port 1(bridge_slave_0) entered forwarding state [ 53.811904][ T95] bridge0: port 2(bridge_slave_1) entered blocking state [ 53.814885][ T95] bridge0: port 2(bridge_slave_1) entered forwarding state [ 53.841960][ T96] bridge0: port 2(bridge_slave_1) entered blocking state [ 53.844268][ T96] bridge0: port 2(bridge_slave_1) entered forwarding state [ 53.897101][ T5940] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 53.948144][ T5942] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 53.955665][ T5940] veth0_vlan: entered promiscuous mode [ 53.967549][ T5940] veth1_vlan: entered promiscuous mode [ 53.996031][ T5942] veth0_vlan: entered promiscuous mode [ 54.000982][ T5942] veth1_vlan: entered promiscuous mode [ 54.026717][ T5940] veth0_macvtap: entered promiscuous mode [ 54.033911][ T5940] veth1_macvtap: entered promiscuous mode [ 54.036641][ T5942] veth0_macvtap: entered promiscuous mode [ 54.042099][ T5942] veth1_macvtap: entered promiscuous mode [ 54.047683][ T5933] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 54.062402][ T5934] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 54.068559][ T5940] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 54.074003][ T5942] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 54.082526][ T5942] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 54.089967][ T5940] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 54.095660][ T5942] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.100251][ T5942] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.103103][ T5942] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.105834][ T5942] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.112306][ T5940] netdevsim netdevsim2 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.115016][ T5940] netdevsim netdevsim2 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.117707][ T5940] netdevsim netdevsim2 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.121138][ T5940] netdevsim netdevsim2 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.167709][ T5933] veth0_vlan: entered promiscuous mode [ 54.192960][ T5933] veth1_vlan: entered promiscuous mode [ 54.195700][ T5934] veth0_vlan: entered promiscuous mode [ 54.196306][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.204683][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.217533][ T1146] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.218498][ T5934] veth1_vlan: entered promiscuous mode [ 54.220423][ T1146] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.250699][ T1146] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.253639][ T1146] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.261349][ T5933] veth0_macvtap: entered promiscuous mode [ 54.265306][ T5933] veth1_macvtap: entered promiscuous mode [ 54.268786][ T102] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.271265][ T102] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.290492][ T5933] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 54.300751][ T5933] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 54.305788][ T5934] veth0_macvtap: entered promiscuous mode [ 54.309870][ T5942] soft_limit_in_bytes is deprecated and will be removed. Please report your usecase to linux-mm@kvack.org if you depend on this functionality. [ 54.312680][ T5933] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.317317][ T5933] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.320410][ T5933] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.323065][ T5933] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.336627][ T5934] veth1_macvtap: entered promiscuous mode [ 54.365495][ T5934] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 54.389754][ T5934] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 54.396493][ T96] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.398758][ T5934] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.401331][ T96] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.402873][ T5934] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.410154][ T5934] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.413467][ T5934] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 54.443660][ T6003] netlink: 'syz.2.5': attribute type 2 has an invalid length. [ 54.447554][ T6003] netlink: 46 bytes leftover after parsing attributes in process `syz.2.5'. [ 54.448835][ T6005] ICMPv6: Received fragmented ndisc packet. Carefully consider disabling suppress_frag_ndisc. [ 54.470092][ T46] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.473443][ T46] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.503519][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.505995][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.542785][ T46] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 54.545262][ T46] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 54.550550][ T6009] netlink: 'syz.3.4': attribute type 1 has an invalid length. [ 54.637934][ T6022] netlink: 'syz.2.10': attribute type 32 has an invalid length. [ 54.662866][ T5939] Bluetooth: hci0: Malformed Event: 0x13 [ 54.696876][ T6024] tmpfs: Bad value for 'mpol' [ 54.870867][ T6040] netlink: 'syz.3.16': attribute type 2 has an invalid length. [ 54.873314][ T6040] netlink: 46 bytes leftover after parsing attributes in process `syz.3.16'. [ 55.052379][ T6055] netlink: 'syz.1.21': attribute type 1 has an invalid length. [ 55.173907][ T6064] dlm: plock device version mismatch: kernel (1.2.0), user (4207687471.1574799195.3139252685) [ 55.177738][ T6064] netlink: 4 bytes leftover after parsing attributes in process `syz.1.26'. [ 55.197751][ T6066] UDPLite: UDP-Lite is deprecated and scheduled to be removed in 2025, please contact the netdev mailing list [ 55.223334][ T6070] UDPLite6: UDP-Lite is deprecated and scheduled to be removed in 2025, please contact the netdev mailing list [ 55.280786][ T6072] kAFS: Can only specify source 'none' with -o dyn [ 55.443176][ T6089] Zero length message leads to an empty skb [ 55.451159][ T6092] futex_wake_op: syz.1.36 tries to shift op by -1; fix this program [ 55.454342][ T6092] netlink: 'syz.1.36': attribute type 1 has an invalid length. [ 55.475880][ T6092] Bluetooth: (null): Out-of-order packet arrived (4 != 0) [ 55.486965][ T95] Bluetooth: (null): Invalid header checksum [ 55.508569][ T5939] Bluetooth: hci2: command tx timeout [ 55.588332][ T5939] Bluetooth: hci0: command tx timeout [ 55.588336][ T5297] Bluetooth: hci1: command tx timeout [ 55.598556][ T5939] Bluetooth: hci3: command tx timeout [ 55.671271][ T6102] dummy0: entered promiscuous mode [ 55.738902][ T5996] usb 7-1: new high-speed USB device number 2 using dummy_hcd [ 55.756597][ T29] usb 5-1: new high-speed USB device number 2 using dummy_hcd [ 55.758133][ T5976] usb 8-1: new high-speed USB device number 2 using dummy_hcd [ 55.765664][ T6107] netlink: 'syz.1.43': attribute type 1 has an invalid length. [ 55.771021][ T6107] netlink: 8 bytes leftover after parsing attributes in process `syz.1.43'. [ 55.773835][ T6107] netlink: 16 bytes leftover after parsing attributes in process `syz.1.43'. [ 55.833086][ T6112] vlan2: entered promiscuous mode [ 55.835023][ T6112] vlan2: entered allmulticast mode [ 55.836646][ T6112] hsr_slave_1: entered allmulticast mode [ 55.848174][ T6112] netlink: 4 bytes leftover after parsing attributes in process `syz.1.44'. [ 55.888219][ T5996] usb 7-1: Using ep0 maxpacket: 32 [ 55.893322][ T5996] usb 7-1: config 0 interface 0 altsetting 0 bulk endpoint 0x85 has invalid maxpacket 1024 [ 55.899658][ T29] usb 5-1: device descriptor read/64, error -71 [ 55.901814][ T5996] usb 7-1: New USB device found, idVendor=12d8, idProduct=0001, bcdDevice=de.79 [ 55.905335][ T5996] usb 7-1: New USB device strings: Mfr=1, Product=236, SerialNumber=2 [ 55.908445][ T5996] usb 7-1: Product: syz [ 55.909801][ T5996] usb 7-1: Manufacturer: syz [ 55.911294][ T5996] usb 7-1: SerialNumber: syz [ 55.917557][ T5996] usb 7-1: config 0 descriptor?? [ 55.921457][ T6094] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 55.926249][ T5976] usb 8-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 55.931473][ T5996] hub 7-1:0.0: bad descriptor, ignoring hub [ 55.933622][ T5976] usb 8-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 7 [ 55.937035][ T5996] hub 7-1:0.0: probe with driver hub failed with error -5 [ 55.939483][ T5976] usb 8-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 55.942523][ T5976] usb 8-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 55.946502][ T5976] usb 8-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 55.954903][ T5976] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 55.960314][ T5976] usb 8-1: config 0 descriptor?? [ 56.158568][ T29] usb 5-1: new high-speed USB device number 3 using dummy_hcd [ 56.238635][ T60] usb 7-1: USB disconnect, device number 2 [ 56.289826][ T29] usb 5-1: device descriptor read/64, error -71 [ 56.367469][ T40] kauditd_printk_skb: 96 callbacks suppressed [ 56.367485][ T40] audit: type=1400 audit(1748418886.923:189): avc: denied { lock } for pid=6097 comm="syz.3.39" path="socket:[6889]" dev="sockfs" ino=6889 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 56.398818][ T29] usb usb5-port1: attempt power cycle [ 56.568911][ T40] audit: type=1400 audit(1748418887.133:190): avc: denied { create } for pid=6097 comm="syz.3.39" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 56.575149][ T40] audit: type=1400 audit(1748418887.133:191): avc: denied { read } for pid=6097 comm="syz.3.39" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 56.624090][ T6116] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 56.628175][ T6116] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 56.738192][ T29] usb 5-1: new high-speed USB device number 4 using dummy_hcd [ 56.759876][ T29] usb 5-1: device descriptor read/8, error -71 [ 56.867027][ T40] audit: type=1400 audit(1748418887.423:192): avc: denied { read } for pid=6117 comm="syz.2.45" name="binder0" dev="binder" ino=7 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 56.876086][ T40] audit: type=1400 audit(1748418887.423:193): avc: denied { open } for pid=6117 comm="syz.2.45" path="/dev/binderfs/binder0" dev="binder" ino=7 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 56.883460][ T40] audit: type=1400 audit(1748418887.423:194): avc: denied { ioctl } for pid=6117 comm="syz.2.45" path="/dev/binderfs/binder0" dev="binder" ino=7 ioctlcmd=0x620d scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 56.891764][ T40] audit: type=1400 audit(1748418887.433:195): avc: denied { set_context_mgr } for pid=6117 comm="syz.2.45" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=binder permissive=1 [ 56.931304][ T40] audit: type=1400 audit(1748418887.493:196): avc: denied { bind } for pid=6121 comm="syz.2.46" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 56.937366][ T40] audit: type=1400 audit(1748418887.493:197): avc: denied { node_bind } for pid=6121 comm="syz.2.46" saddr=172.20.20.35 src=52768 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=sctp_socket permissive=1 [ 56.945480][ T40] audit: type=1400 audit(1748418887.493:198): avc: denied { write } for pid=6121 comm="syz.2.46" name="route" dev="proc" ino=4026532898 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:proc_net_t tclass=file permissive=1 [ 57.018647][ T29] usb 5-1: new high-speed USB device number 5 using dummy_hcd [ 57.039128][ T29] usb 5-1: device descriptor read/8, error -71 [ 57.148374][ T29] usb usb5-port1: unable to enumerate USB device [ 57.239106][ T6140] netlink: 4 bytes leftover after parsing attributes in process `syz.2.49'. [ 57.285548][ T6144] netlink: 12 bytes leftover after parsing attributes in process `syz.1.53'. [ 57.295819][ T6144] netlink: 8 bytes leftover after parsing attributes in process `syz.1.53'. [ 57.588762][ T5939] Bluetooth: hci2: command tx timeout [ 57.668515][ T5939] Bluetooth: hci1: command tx timeout [ 57.668619][ T5947] Bluetooth: hci0: command tx timeout [ 57.668666][ T5297] Bluetooth: hci3: command tx timeout [ 57.747341][ T6001] libceph: connect (1)[c::]:6789 error -101 [ 57.751077][ T6001] libceph: mon0 (1)[c::]:6789 connect error [ 58.009040][ T840] libceph: connect (1)[c::]:6789 error -101 [ 58.011578][ T840] libceph: mon0 (1)[c::]:6789 connect error [ 58.519121][ T6001] libceph: connect (1)[c::]:6789 error -101 [ 58.522121][ T6001] libceph: mon0 (1)[c::]:6789 connect error [ 58.567974][ T6157] ceph: No mds server is up or the cluster is laggy [ 58.596058][ T5976] usbhid 8-1:0.0: can't add hid device: -71 [ 58.601009][ T5976] usbhid 8-1:0.0: probe with driver usbhid failed with error -71 [ 58.606310][ T5976] usb 8-1: USB disconnect, device number 2 [ 58.636408][ T6175] netlink: 36 bytes leftover after parsing attributes in process `syz.3.61'. [ 58.842675][ T6198] capability: warning: `syz.1.69' uses 32-bit capabilities (legacy support in use) [ 58.922641][ T6205] gfs2: gfs2 mount does not exist [ 58.969127][ T6213] fuse: Unknown parameter '' [ 58.969477][ T6212] fuse: Unknown parameter '' [ 58.972132][ T6213] netlink: 'syz.0.75': attribute type 2 has an invalid length. [ 58.973623][ T6209] 9p: Unknown uid 00000000004294967295 [ 59.083699][ T6226] capability: warning: `syz.1.79' uses deprecated v2 capabilities in a way that may be insecure [ 59.097438][ T6228] overlayfs: failed to resolve './file0': -2 [ 59.453184][ T6265] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(5) [ 59.455956][ T6265] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 59.461324][ T6265] vhci_hcd vhci_hcd.0: Device attached [ 59.537368][ T6266] vhci_hcd: connection closed [ 59.538687][ T6278] __nla_validate_parse: 6 callbacks suppressed [ 59.538701][ T6278] netlink: 60 bytes leftover after parsing attributes in process `syz.0.93'. [ 59.539827][ T1146] vhci_hcd: stop threads [ 59.547625][ T1146] vhci_hcd: release socket [ 59.550621][ T1146] vhci_hcd: disconnect device [ 59.669854][ T5947] Bluetooth: hci2: command tx timeout [ 59.691593][ T6289] syz.0.98 uses obsolete (PF_INET,SOCK_PACKET) [ 59.694751][ T6289] syzkaller1: entered allmulticast mode [ 59.748714][ T5939] Bluetooth: hci0: command tx timeout [ 59.748746][ T5297] Bluetooth: hci1: command tx timeout [ 59.750464][ T5947] Bluetooth: hci3: command tx timeout [ 59.859772][ T6298] overlayfs: option "volatile" is meaningless in a non-upper mount, ignoring it. [ 59.863341][ T6298] overlayfs: missing 'lowerdir' [ 59.906549][ T6302] netlink: 8 bytes leftover after parsing attributes in process `syz.3.104'. [ 59.911505][ T6302] netlink: 8 bytes leftover after parsing attributes in process `syz.3.104'. [ 59.915358][ T6302] nfs4: Unknown parameter '00000000000000000035' [ 59.972134][ T6312] netlink: 16 bytes leftover after parsing attributes in process `syz.3.106'. [ 60.022352][ T6317] xt_cgroup: xt_cgroup: no path or classid specified [ 60.093654][ T6328] netlink: 36 bytes leftover after parsing attributes in process `syz.2.111'. [ 60.215016][ T6328] kvm: pic: non byte write [ 60.315062][ T6350] netlink: 32 bytes leftover after parsing attributes in process `syz.3.119'. [ 60.320046][ T6350] netlink: 32 bytes leftover after parsing attributes in process `syz.3.119'. [ 60.326323][ T6350] netlink: 'syz.3.119': attribute type 8 has an invalid length. [ 60.339793][ T6352] batman_adv: batadv0: Adding interface: dummy0 [ 60.342437][ T6352] batman_adv: batadv0: The MTU of interface dummy0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 60.354124][ T6352] batman_adv: batadv0: Interface activated: dummy0 [ 60.364272][ T6352] batadv0: mtu less than device minimum [ 60.366681][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.370596][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.374431][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.378207][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.382123][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.386104][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.390016][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.393756][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.397488][ T6352] batman_adv: batadv0: Forced to purge local tt entries to fit new maximum fragment MTU (-320) [ 60.421981][ T6355] x_tables: duplicate underflow at hook 2 [ 60.449607][ T6355] syz.2.121: attempt to access beyond end of device [ 60.449607][ T6355] nbd2: rw=4096, sector=2, nr_sectors = 2 limit=0 [ 60.456269][ T6355] EXT4-fs (nbd2): unable to read superblock [ 60.529482][ T6375] Mount JFS Failure: -22 [ 60.594326][ T5297] Bluetooth: hci3: ACL packet for unknown connection handle 0 [ 60.688371][ T6389] netlink: 'syz.3.126': attribute type 13 has an invalid length. [ 60.814341][ T6401] netlink: 146840 bytes leftover after parsing attributes in process `syz.0.133'. [ 60.842283][ T6403] netlink: 8 bytes leftover after parsing attributes in process `syz.2.134'. [ 60.863956][ T6403] (unnamed net_device) (uninitialized): Unable to set up delay as MII monitoring is disabled [ 60.913603][ T6411] mmap: syz.2.137 (6411) uses deprecated remap_file_pages() syscall. See Documentation/mm/remap_file_pages.rst. [ 60.969844][ T6413] netlink: 'syz.2.138': attribute type 1 has an invalid length. [ 61.430113][ T6441] binder: 6440:6441 ioctl 400c620e 200000001580 returned -22 [ 61.524441][ T40] kauditd_printk_skb: 126 callbacks suppressed [ 61.524452][ T40] audit: type=1400 audit(1748418892.083:325): avc: denied { bind } for pid=6445 comm="syz.3.150" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 61.527102][ T6450] vlan2: entered allmulticast mode [ 61.531962][ T6447] usb 2-1: USB disconnect, device number 2 [ 61.537297][ T40] audit: type=1400 audit(1748418892.083:326): avc: denied { listen } for pid=6445 comm="syz.3.150" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 61.541099][ T6450] bridge0: entered allmulticast mode [ 61.544070][ T40] audit: type=1400 audit(1748418892.083:327): avc: denied { connect } for pid=6445 comm="syz.3.150" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 61.576449][ T40] audit: type=1400 audit(1748418892.133:328): avc: denied { read } for pid=6445 comm="syz.3.150" dev="sockfs" ino=11488 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 61.588198][ T6457] netlink: 56 bytes leftover after parsing attributes in process `syz.1.152'. [ 61.592472][ T6444] block nbd2: shutting down sockets [ 61.595954][ T40] audit: type=1400 audit(1748418892.153:329): avc: denied { mount } for pid=6456 comm="syz.1.152" name="/" dev="hugetlbfs" ino=11103 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=filesystem permissive=1 [ 61.604299][ T40] audit: type=1400 audit(1748418892.153:330): avc: denied { remount } for pid=6456 comm="syz.1.152" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=filesystem permissive=1 [ 61.610865][ T40] audit: type=1400 audit(1748418892.163:331): avc: denied { unmount } for pid=5934 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=filesystem permissive=1 [ 61.626674][ T6462] overlayfs: lower data-only dirs require metacopy support. [ 61.674956][ T40] audit: type=1400 audit(1748418892.233:332): avc: denied { write } for pid=6465 comm="syz.1.155" name="uinput" dev="devtmpfs" ino=943 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:event_device_t tclass=chr_file permissive=1 [ 61.687912][ T40] audit: type=1400 audit(1748418892.243:333): avc: denied { getopt } for pid=6453 comm="syz.0.151" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 61.731975][ T40] audit: type=1400 audit(1748418892.293:334): avc: denied { listen } for pid=6463 comm="syz.2.154" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 62.052284][ T6494] overlay: ./file0 is not a directory [ 62.064037][ T6495] ip6t_REJECT: ECHOREPLY is not supported [ 62.148480][ T6499] input: syz0 as /devices/virtual/input/input5 [ 62.226341][ T6505] trusted_key: syz.3.163 sent an empty control message without MSG_MORE. [ 62.810545][ T6576] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000021: 0000 [#1] SMP KASAN NOPTI [ 62.814289][ T6576] KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] [ 62.818327][ T6576] CPU: 2 UID: 0 PID: 6576 Comm: syz.0.179 Not tainted 6.15.0-syzkaller-03478-gc89756bcf406 #0 PREEMPT(full) [ 62.822249][ T6576] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 [ 62.825560][ T6576] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 62.827153][ T6576] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 da be 55 f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 62.833112][ T6576] RSP: 0018:ffffc9000ce37bf0 EFLAGS: 00010293 [ 62.835005][ T6576] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffffff8865af1a [ 62.837456][ T6576] RDX: ffff888027bcc880 RSI: ffffffff8865af66 RDI: 0000000000000005 [ 62.839913][ T6576] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 62.842427][ T6576] R10: 0000000000000001 R11: 0000000000000001 R12: ffffc9000ce37d88 [ 62.844883][ T6576] R13: ffffc9000ce37d88 R14: 0000000000000001 R15: ffff8880463b5000 [ 62.847346][ T6576] FS: 00007f10c75826c0(0000) GS:ffff8880d6ba1000(0000) knlGS:0000000000000000 [ 62.850271][ T6576] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 62.852412][ T6576] CR2: 00007f10c7581f98 CR3: 00000000531a8000 CR4: 0000000000352ef0 [ 62.855002][ T6576] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 62.857684][ T6576] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 62.860147][ T6576] Call Trace: [ 62.861165][ T6576] [ 62.862061][ T6576] ? __pfx_bcsp_recv+0x10/0x10 [ 62.863515][ T6576] hci_uart_tty_receive+0x254/0x7e0 [ 62.865094][ T6576] ? __pfx_hci_uart_tty_receive+0x10/0x10 [ 62.866876][ T6576] tty_ioctl+0x57d/0x1610 [ 62.868262][ T6576] ? __pfx_tty_ioctl+0x10/0x10 [ 62.869764][ T6576] ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 [ 62.871911][ T6576] ? hook_file_ioctl_common+0x145/0x410 [ 62.873677][ T6576] ? selinux_file_ioctl+0x180/0x270 [ 62.875318][ T6576] ? selinux_file_ioctl+0xb4/0x270 [ 62.876971][ T6576] ? __pfx_tty_ioctl+0x10/0x10 [ 62.878527][ T6576] __x64_sys_ioctl+0x18e/0x210 [ 62.880079][ T6576] do_syscall_64+0xcd/0x4c0 [ 62.881514][ T6576] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 62.883392][ T6576] RIP: 0033:0x7f10c678e969 [ 62.884825][ T6576] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 62.890682][ T6576] RSP: 002b:00007f10c7582038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 62.893264][ T6576] RAX: ffffffffffffffda RBX: 00007f10c69b6080 RCX: 00007f10c678e969 [ 62.895712][ T6576] RDX: 0000200000000040 RSI: 0000000000005412 RDI: 0000000000000007 [ 62.898144][ T6576] RBP: 00007f10c6810ab1 R08: 0000000000000000 R09: 0000000000000000 [ 62.900593][ T6576] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 62.903066][ T6576] R13: 0000000000000000 R14: 00007f10c69b6080 R15: 00007ffda3f495a8 [ 62.905510][ T6576] [ 62.906490][ T6576] Modules linked in: [ 62.908360][ T6576] ---[ end trace 0000000000000000 ]--- [ 62.915030][ T6576] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 62.916691][ T6576] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 da be 55 f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 62.923231][ T6576] RSP: 0018:ffffc9000ce37bf0 EFLAGS: 00010293 [ 62.925391][ T6576] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffffff8865af1a [ 62.927978][ T6576] RDX: ffff888027bcc880 RSI: ffffffff8865af66 RDI: 0000000000000005 [ 62.931336][ T6576] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 62.933810][ T6576] R10: 0000000000000001 R11: 0000000000000001 R12: ffffc9000ce37d88 [ 62.936309][ T6576] R13: ffffc9000ce37d88 R14: 0000000000000001 R15: ffff8880463b5000 [ 62.938869][ T6576] FS: 00007f10c75826c0(0000) GS:ffff8880d6ba1000(0000) knlGS:0000000000000000 [ 62.941593][ T6576] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 62.943674][ T6576] CR2: 00007ff9a2b80178 CR3: 00000000531a8000 CR4: 0000000000352ef0 [ 62.946307][ T6576] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 62.948930][ T6576] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 62.951449][ T6576] Kernel panic - not syncing: Fatal exception [ 62.954115][ T6576] Kernel Offset: disabled [ 62.955490][ T6576] Rebooting in 86400 seconds.. VM DIAGNOSIS: 07:54:53 Registers: info registers vcpu 0 CPU#0 RAX=0000000000000000 RBX=0000000000000000 RCX=ffffffff8b6eb3b6 RDX=ffff888034c88000 RSI=0000000000000000 RDI=0000000000000000 RBP=ffff888050d05800 RSP=ffffc9000c6e7748 R8 =0000000000000000 R9 =0000000000000000 R10=0000000000000009 R11=0000000000000001 R12=0000000000000009 R13=ffffc9000c6e79c8 R14=ffffffffffffffff R15=ffffc9000c6e7a05 RIP=ffffffff81bb6802 RFL=00000246 [---Z-P-] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 0000000000000000 ffffffff 00c00000 GS =0000 ffff8880d69a1000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe0000003000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe0000001000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=000055ff3eecd300 CR3=0000000057424000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000000008001 Opmask01=0000000000000054 Opmask02=00000000000003ff Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00316576656e6567 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75211a8a ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75211a97 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75211a91 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75211aa5 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75211b2b ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75211c09 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75eed100 00007f6e75383440 00007f6e75380004 0008000f0010000a ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f6e75383498 00007f6e75383490 00007f6e75383488 00007f6e75383480 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000000524f525245 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00524f5252450040 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00e800a800000000 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 1 CPU#1 RAX=000000273dfa8d3c RBX=ffff88806a5239c0 RCX=00000000000006e0 RDX=0000000000000027 RSI=ffff88806a5239c0 RDI=0000000000054218 RBP=0000000000054218 RSP=ffffc900006a0ec8 R8 =0000000000000005 R9 =000000000000003f R10=0000000000000019 R11=ffffffff9ad37f90 R12=0000000000000000 R13=0000000000000000 R14=0000000000000019 R15=ffff88806a527c40 RIP=ffffffff8167d485 RFL=00000006 [-----P-] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 0000000000000000 ffffffff 00c00000 GS =0000 ffff8880d6aa1000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe000004a000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe0000048000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007f7b897c1286 CR3=0000000029de3000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000ffff0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=00000000c0fffc00 Opmask01=00000000000000ff Opmask02=00000000000000ff Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000001 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000555576f54d10 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000555576f1ff46 0000555576f1f560 ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000555576f1b4a8 ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000555576f2c3bd 0000555576f2ba70 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000000000001df8a ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 90031c08001b8803 2a08001b80031fff fffffc0800141000 44100006006fa03c ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 fe00000003070000 00000000a3bf0000 0d38000002b70ada 082980032980041b ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 10b08084001cee03 0401e0808084001c ec033004001ce803 00080007000c0008 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 1cfa0303f802001c f8030e04001cf403 2804001cf0030210 b88084001cee0300 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 9603000000000000 0000000000000001 ffffffffffffffff e5081cfc03000200 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 010010000c800401 00000c0806060167 b40008000ce00300 10000cd003001000 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0cc0030210000cb0 0301a81000100300 00001008061da003 1404001d9c031004 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 001d98030002001d 9603000000000000 0000000000000001 ffffffffffffffff ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 e5081cfc03000200 1cfa0303f802001c f8030e04001cf403 2804001cf0030210 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 2 CPU#2 RAX=0000000000000031 RBX=00000000000003f8 RCX=0000000000000000 RDX=00000000000003f8 RSI=ffffffff85563fc5 RDI=ffffffff9ae385a0 RBP=ffffffff9ae38560 RSP=ffffc9000ce375f0 R8 =0000000000000001 R9 =000000000000001f R10=0000000000000000 R11=000000004153414b R12=0000000000000000 R13=0000000000000031 R14=ffffffff9ae38560 R15=ffffffff85563f60 RIP=ffffffff85563fef RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 00007f10c75826c0 ffffffff 00c00000 GS =0000 ffff8880d6ba1000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe0000091000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe000008f000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007f10c7581f98 CR3=00000000531a8000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000000008001 Opmask01=0000000000000000 Opmask02=000000000000003f Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811a8a ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811a97 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811a91 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811aa5 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811b2b ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811c09 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6983488 00007f10c6983480 00007f10c6983478 00007f10c6983450 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c74ed100 00007f10c6983440 00007f10c6983458 00007f10c69834a0 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6983498 00007f10c6983490 00007f10c6983488 00007f10c6983480 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 8860c450ad257f08 748fce0a99b9d879 5a1e90298078d5e9 1c77399866f74d5a ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00265abb5c000000 00000000008860c4 50ad257f08748fce 0a99b9d8795a1e90 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 298078d5e91c7739 9866f74d5ab9c67f 46d11b7f36a92564 ef3941ad4acd9df3 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 149cd537a37b8fbb d7aed002cccb0fe0 0de899d90000003f 222f162c9705cc26 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 3efad463596a4285 2f7df98d7a260178 b602041c56ecbd01 ae65636836c87daf ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 3 CPU#3 RAX=0000000000000000 RBX=0000000000000000 RCX=ffffffff816c2bae RDX=ffff888027fca440 RSI=ffffffff816c2bb8 RDI=0000000000000007 RBP=0000000034ce03f0 RSP=ffffc9000c45faf0 R8 =0000000000000007 R9 =0000000000000000 R10=0000000000000000 R11=0000000000002be0 R12=0000000000000000 R13=0000000000000009 R14=ffff88803352d2e0 R15=ffff888034ce03f8 RIP=ffffffff816c2bb8 RFL=00000293 [--S-A-C] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 0000000000000000 ffffffff 00c00000 GS =0000 ffff8880d6ca1000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe00000d8000 00004087 00008b00 DPL=0 TSS64-busy GDT= fffffe00000d6000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=0000555558030808 CR3=000000004e27c000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000040000400 Opmask01=0000000000000000 Opmask02=00000000ffffffef Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007ffda3f49930 0000003000000018 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811a8a ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811a97 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811a91 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811aa5 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811b2b ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f10c6811c09 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000