last executing test programs: 10.615588579s ago: executing program 1 (id=2962): r0 = socket(0x10, 0x3, 0x0) r1 = openat$ppp(0xffffffffffffff9c, &(0x7f00000000c0), 0x20002, 0x0) sendmsg$nl_route(r0, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000100)=ANY=[@ANYBLOB="400000001000030400"/20, @ANYRES32=0x0, @ANYBLOB="00000000000000001800128008000100707070000c00028008000100", @ANYRES32=r1, @ANYBLOB='\b\x00\n\x00', @ANYRES32], 0x40}}, 0x0) r2 = socket(0x2, 0x80805, 0x0) getsockopt$inet_sctp_SCTP_MAX_BURST(r2, 0x84, 0xc, &(0x7f0000000040)=@assoc_value={0x0}, &(0x7f0000000000)=0x8) setsockopt$inet_sctp_SCTP_DEFAULT_SNDINFO(r2, 0x84, 0x22, &(0x7f0000000100)={0xa, 0x3, 0x80000001, 0x4, r3}, 0x10) getsockopt$inet_sctp6_SCTP_SOCKOPT_CONNECTX3(r0, 0x84, 0x6f, &(0x7f0000000180)={r3, 0x1c, &(0x7f0000000140)=[@in6={0xa, 0x1, 0xa, @loopback, 0x40}]}, &(0x7f00000001c0)=0x10) r4 = syz_open_procfs(0x0, &(0x7f0000000000)='net/rt_acct\x00') r5 = socket(0x18, 0x3, 0x0) r6 = socket$inet6(0xa, 0x2, 0x0) bind$inet6(r6, &(0x7f0000000040)={0xa, 0xe22}, 0x1c) connect$inet6(r6, &(0x7f0000000600)={0x2, 0x4e21, 0x0, @dev}, 0x1c) connect$inet6(r6, 0x0, 0x0) r7 = socket$netlink(0x10, 0x3, 0x8000000004) writev(r7, &(0x7f0000001200)=[{&(0x7f0000000080)="580000001400add427323b472545b45602117fffffff81004e230e227f000001925aa80020007b00090080007f000001e809000000ff0000f03ac71002000000ffffffffffffffffffe7ee00000000000000000200000000", 0x58}], 0x1) connect$pppoe(r5, &(0x7f0000000100)={0x18, 0x0, {0x2, @broadcast, 'vxcan1\x00'}}, 0x1e) sendfile(r5, r4, 0x0, 0x8) 10.468797093s ago: executing program 1 (id=2963): syz_usb_connect(0x3, 0x8c6, &(0x7f00000000c0)=ANY=[@ANYBLOB="1201500236e47e2082055c2955d4010203010902b408048006a00309047f0e01ff2dde700a24010100800201020824050503"], &(0x7f0000000080)={0x0, 0x0, 0x0, 0x0, 0x1, [{0x2f, &(0x7f0000000100)=ANY=[@ANYBLOB="2f03bac6c75bef54b57901ce9c63dae3933f2b25"]}]}) syz_usb_connect$cdc_ncm(0x2, 0x95, &(0x7f0000000140)={{0x12, 0x1, 0x250, 0x2, 0x0, 0x0, 0x20, 0x525, 0xa4a1, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x83, 0x2, 0x1, 0x8, 0x0, 0xf7, {{0x9, 0x4, 0x0, 0x0, 0x1, 0x2, 0xd, 0x0, 0x0, {{0xb, 0x24, 0x6, 0x0, 0x1, "56255581b573"}, {0x5, 0x24, 0x0, 0x3}, {0xd, 0x24, 0xf, 0x1, 0x7, 0x5, 0x7, 0x4}, {0x6, 0x24, 0x1a, 0x644, 0xd}, [@mbim={0xc, 0x24, 0x1b, 0x1, 0x4, 0xb2, 0x81, 0x1ff, 0x5}, @acm={0x4, 0x24, 0x2, 0xa}, @call_mgmt={0x5, 0x24, 0x1, 0x1, 0x99}, @obex={0x5, 0x24, 0x15, 0x6}, @dmm={0x7, 0x24, 0x14, 0x5, 0xd}]}, {{0x9, 0x5, 0x81, 0x3, 0x20, 0x8, 0xf7, 0x9}}}, {}, {0x9, 0x4, 0x1, 0x1, 0x2, 0x2, 0xd, 0x0, 0x0, "", {{{0x9, 0x5, 0x82, 0x2, 0x400, 0x90, 0x2, 0x5}}, {{0x9, 0x5, 0x3, 0x2, 0x40, 0x40, 0x5, 0x3}}}}}}}]}}, &(0x7f0000000040)={0xa, &(0x7f0000000000)={0xa, 0x6, 0x310, 0xbf, 0x2c, 0x0, 0x8, 0x2}, 0xef, &(0x7f0000000200)={0x5, 0xf, 0xef, 0x3, [@ptm_cap={0x3}, @ptm_cap={0x3}, @generic={0xe4, 0x10, 0x2, "883d2f28d13ea4bbc5b7f79e3679d9a29c7f7f364fbfcd9e0ec1eb211ac7e1607a099969acced777240c6bd62406b82ebe49330512731599f84d8e03d43cc789d967dfc9dc5a3b414bb5ca829e34e4150d5e1eae71760492167dad39d8fc181426eefa249ba473a4161dbfdf204ebb7c4e115fb92c52f5683121b0a26402436ebf687e4eb9b24a0a71de580f9221aba0bf10e1e906663880344968c2db75af2f07407a0c222dd5b17ab0d818b98b28bbc8fb7aa4b391954343c37e14ec400540698ab17d150eabf86bba4bde4f864ee3cd4bf51860f198b2fc42defb81cc52b582"}]}, 0x1, [{0x93, &(0x7f0000000300)=@string={0x93, 0x3, "f31220e368ab41f9ec7d1f19273c34ff7d6f429b61ffaefcd52a8c7dcf8a9e9d29557b909ab67f813c8fce0598e81d99cb3b3040776eba99089b78ea06a31d91b5650b5ee4db797875470c42d9b158af3fa663e8e727bd9e1a9fd474dfdd1104f226ffb226dd913939e6c873351af68f8ac87dd04447f45a3997c2d2d5edf297cd298d8d588d8f64348f9029a34555b00c"}}]}) 9.6679196s ago: executing program 2 (id=2967): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000000)={0x26, 'skcipher\x00', 0x0, 0x0, 'ecb(serpent)\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, 0x0, 0x0) r1 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$alg(r1, &(0x7f0000000200)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000300)=[@op={0x18, 0x117, 0x3, 0x1}], 0x18}, 0x0) sendmsg$inet6(r1, &(0x7f0000000900)={0x0, 0x0, &(0x7f0000000880)=[{&(0x7f0000000080)="abf63fa63be2057e6eb311864b862f44687c12bc9818a7859baa745aff3f92ef76bdf77e7b5d02d91fc1523771c95efb", 0x30}, {&(0x7f0000000480)="52d2ea933609eb07c6d2847054a95df72d8e98717a68c12027034ea2cfe9dfff638298030651a2552405127ab1f7367c6befdcf20f700dcb39e7b9df0edc9269ab3c24d49de362841a9cd7af799cd57f26705d6d6f840b720f5c1fec2275e81fe37b609b8a0309a9918d2621e4ff4084240a16e4d47d78aa427b547d7965db06b164d307465c77df9c1e24328d2a333ad21affbe312fc9eeb453040efedc9bdfb00d138f8b862f393d2d46336dfcaa1e1548c69347803a16c74b964a857bed00d8871d6f679b861c1def970838b2d5314e43ca06b900aa8059d40d756882c3929803e9d98545ac5a2d067813fb171aed7715ad5e5e0e731e953a0d70a6", 0xfd}, {&(0x7f0000000240)="48edc487717a690680dd1b477b1b66f6ea0142bd8ca00f8a7e3a3e520f8adcbe6dab37ba403c2e9923da1833dd11ca383a6d15e18b86b27175a14a8670146d37ce7e8d726d66bfb76649432d82c990712c96ac8e7ffe131637f081b5299f1cd4d210d282c5de16089e6b5ae996836a1c8b2a475048eaf9e1710cdd5c390be553caf0c8c2ef7046bc", 0x88}, {&(0x7f0000000940)="4da1537e1aa8ee68c744c5a486e7b2393712688bdffa4e960c7629be4054a649249ce75863e4b6189990e87e8ade0e7abd7c19e524fb3270ee17563373cb5cef0600000062298a6e00"/85, 0x55}, {&(0x7f0000000580)="ff41c07b3bc0bb61c722d3d67c9e883fbcbb907958a2d3b5f478d9f0afe2a0a587dc0d3e7a7011ded58cee584dafbadfdbd560cff25414fe5e5c0adc1c425dfb9c273feb9cbd03d513b68b29527e13c9396ffe05ca82fa4fb0", 0x59}, {&(0x7f0000000b80)="141deb00cedbccb636a9ab53213ea1f1c1986285e42936fad54f7abb5d", 0x1d}], 0x6}, 0x91) recvmsg$unix(r1, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)=[{&(0x7f0000001f00)=""/4096, 0x1000}], 0x1}, 0x12060) bpf$BPF_GET_PROG_INFO(0xf, &(0x7f0000000800)={0xffffffffffffffff, 0xe0, &(0x7f00000009c0)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3, &(0x7f0000001d00)=[0x0, 0x0, 0x0], ""/16, 0x0, 0x0, 0x0, 0x0, 0x9, 0x5, &(0x7f0000001d40)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0], &(0x7f0000000440)=[0x0, 0x0, 0x0, 0x0, 0x0], 0x0, 0x32, &(0x7f0000000700)=[{}, {}, {}, {}, {}], 0x28, 0x10, &(0x7f0000000740), &(0x7f0000000780), 0x8, 0x9a, 0x8, 0x8, &(0x7f00000007c0)}}, 0x10) r3 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='memory.events\x00', 0x275a, 0x0) r4 = syz_open_dev$radio(&(0x7f0000000000), 0xffffffffffffffff, 0x2) ioctl$VIDIOC_S_EXT_CTRLS(r4, 0xc0205647, &(0x7f0000000100)={0xf000000, 0x1, 0xffffffff, 0xffffffffffffffff, 0x0, &(0x7f0000000140)={0x98f910, 0x797, '\x00', @value64=0x1}}) mmap(&(0x7f0000002000/0x3000)=nil, 0x3000, 0x0, 0x12, r3, 0x0) r5 = syz_genetlink_get_family_id$nl80211(&(0x7f0000001c00), r1) sendmsg$NL80211_CMD_SET_NOACK_MAP(r3, &(0x7f0000001cc0)={&(0x7f0000001bc0)={0x10, 0x0, 0x0, 0x200000}, 0xc, &(0x7f0000001c80)={&(0x7f0000001c40)={0x28, r5, 0x400, 0x70bd25, 0xcf, {{}, {@void, @val={0xc, 0x99, {0x800, 0x14}}}}, [@NL80211_ATTR_NOACK_MAP={0x6, 0x95, 0x4}]}, 0x28}, 0x1, 0x0, 0x0, 0x20000000}, 0x4000000) r6 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$SO_BINDTODEVICE(r6, 0x1, 0x19, &(0x7f0000000180)='syz_tun\x00', 0x10) r7 = socket$packet(0x11, 0x2, 0x300) setsockopt$packet_fanout(r7, 0x107, 0x12, &(0x7f0000000140)={0x0, 0xa003}, 0x4) connect$inet(r6, &(0x7f0000000040)={0x2, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10) r8 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r8, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000001340)={&(0x7f0000000400)=@ipv6_delrule={0x24, 0x21, 0x1, 0x0, 0x0, {}, [@FIB_RULE_POLICY=@FRA_SUPPRESS_PREFIXLEN={0x8}]}, 0x24}}, 0x0) sendmsg$inet6(r1, &(0x7f0000000840)={&(0x7f00000000c0)={0xa, 0x8, 0x1, @private2={0xfc, 0x2, '\x00', 0x1}, 0x8001}, 0x1c, &(0x7f00000001c0)=[{&(0x7f0000000100)="5bfb3052c546fe5cd38d47f023015640494a584b1da76c2dd55cdc3959fd0599a1cc9502d9", 0x25}, {&(0x7f0000000340)="467c3973a62d261e91b6eefbab995f6260aa1ab37f15134da170c394c6beb36dff298d786950d92269d634dcd4505a6fe40e4d42f7bed66327e39d6d5fe7481d0c89b6fa", 0x44}, {&(0x7f0000000600)="e92462a434128265eb5ea5b29338f3405b990c8fd74b3c522ba12e6416a13dd68876f609c1b96bec696bb3c9d4aa2363aecea479a084db27c34540e9247042b406fde3c3befa2df9c137ddc5a93f36fea2095cf5022fe136dc2020cf8bab0dd7942e4a9f78660b298173bda0847191ad6e7df3560be9a5da3af4e4543170bac83a42d0e062eec47a0cb0f93155289a967c24aa72813a701240e829ad856ac261cfd043d8fb15d4df067724cf9ecdf7af1605768b4a902831fc3248826f26e947568e28b8f6b553c3b8034537bad41b3e74a9f188f0ce4d9e39", 0xd9}, {&(0x7f0000000bc0)="0fda13c83c2e82ce630bdc665a6e725987d61566b44ddb2e3e0500d3e5b916bd2cbfe094b04a623298065ef5f72eec2727724abe8a2c92697b301eb9fb4eb9ba900884049eb4ddc2e2d8a5b1ecd293de90f18ec809e74b044d546987bb4b5ac9d2fbf381b606bd598723af183f0db81de78e4b08bf37cc0f4430e8390e209e8d8157e9104200bb0bd54ecfbb50ce9f029a447cc87518c57e00924019ef668e88cadad9e9bd3d772c40d73d1d3c54c05eb16d7367c16e9b3c847b43e9508f7655bd669a3a1a7e738e13157216a981435d250b17f7ef09c87521a797c8e57ff05829ed4ba8ce2c093444dbef6544f0b92c62dc611c6703ee8ce3b9fa2480301b329778761aee1c0c2fa480d1e18b76e28c4f6c2d3924375fd593aa0a393ae7b6637d882c55b0fea5274ce5722da8419550162ac579367ce0650c347ca23b74675fcd5598694f401a8d14148f811aa5686c3aa61bd1a50e777289a08c12b1155f0c47e0cbb132e01b28d89eafd86bca989cc190d157a89aa32ab96e6ccd24c8c4b22db568342c22dc0021c795d498b4d232c5759745a94f90935711a1fa5d7f32b5a3d71a053f6b2286376c7eaa85a22f6233ee3d87b862b618b01bff01627c3de4cef4217965a4325937b17505202e542094f3643c44767475bef44c4f36ca50ce0933e3ab2539a941dc2cd1193ba32075c9bb9bba26c282141eeab5295a2845ea9c1da59c5f37e3517aa73406d47961705a310ff23e998f8e6a149211cab52467f712cefc0967105bea688a10b05fb754317437435a268aefb874176e5ff1c4047600711c075f34d71b5ff735a681ab2233e9930d1240c90b5c61b2c8e8c06478474e6f580028ddda7d6507e681246ee6e25d477ffe0e0f5a2ed97294918187c55ca12582a20bcc3c31176363fb11f0ec247873f261be8b57313f819122516e633b497936f98712726bfcc38dcdf05dc2a732a024ec8b6f70dba0f33af5e06c015e266ff48e75bb3e3c60333f0f1a9a247319fce1b131b3768a20eb8325bfbbd5777e04a73dff824ac48db09c1dd5ccea1385fc58c4eab7aad31d46c07fca2bea4fa3a458f89eeec2ec5c07f27e1b86f7570f85660afb7467ccbe9185964bcf1ed7f56c2971b228a2a3dd2b3c920d124a730e09bd06d1dd310282306f90a1b7e0427c1c066f635bcecba7da5b5f191d26e1d81cd91ff6eb189015847765c1b3429baa0382291e706e8b2d433e3fca4cb4e57487938f5ffd7185879e42ce3788eb6f0eb2f77da4355b40a0061bd626d29eef221b5bfe8271d870aeba9fd76370bd41bde1c2327c4ca06cc0c09b368bbea909571b1f4570f99b13f80f74a32cfca5a372e4d20508b3480e8a795f048e7d2e922f7d188e32a075aca82e5807d4cdc7dadb4e28038e32d53e20f48338f8f2804a0fc3aef7cd92d95c65880d1b508b70c22d8a3bc4e671ef1752c7cc63ae2d5ed88d2b5dbaaeb69fdeec5d6a6fbb0055eb7989ea0a3c55ab1941c3b2b3ea6c63123b32b0a0e528e696ef2c6106e3dc1b7e56b92ff7b012ba5dd49b6c13b016819cdd3743c8f2787ab880d13584a503ba4487747c11024765c0c51c59f1c7320e74aa9c421cb8acda831d3f0df3643243c7b37190fb9fbae8da0f984fa1858cb960a7510c1e0894edcf570f660c9a2b489e613e23ba33598c3868e360208386a4a7d5caf403fc87a9011e89a95c9b0305f778af1b47224b77011ade90981113df02ebf1e3e01462e121801f0be18c53dad0b7b21f245a6ed28c100c2969f7c0f2404ecdb0e78ee56415bfb117d5a75b2dc9c445bd36093ffed61ff355fe791332a2625277c734564c900b8cbdacd0b08b854881b9d376ecf300122b6c8509e0736fe75b3a1cbeb3dfcc04c5e8726ec0e4e217e36fb0222fec73468c4a37d3cdefa17aaf7d19af5ae6d7a3951a363f9b652441362fe1b7b564d7c0724f500b9c5bcac9ed7e77856a1423514ab2a5c0e60903e0d40df4445b50b8ae5ad21b05aea552d1707862d8d1bd6a0a7f28f05866ce357cadc0707ad76095aab26e7f29c10d20bb3a5d19a64ceaa1bce04922d4c5214eaa58f413736a12d6455dc973a94fe87a7f0c3e7b4593d1ffa05dadc821fd83edb4e36f87166fa282289cf532b32a43fcec13b0a29533df8047afe48ddab502af2211002c342e5224d65be8a393506485e4e38a2e30a553f6e5949681fb1eb6a48634577f7a7d65d7096a914b29ff43bb026010eb73eb999b2e6a334053d1ba4fbe105fc84f93f100c087fde064ee0bf3a6c6da3c42fc8b52fb54a89ac3438f1d2cb674648b9e71399f6ff9c9649d74f24f9ef0de97579351342be10b506087d553b3f7bbcc318356e603fd9c1124f845359174f21d2bf140e51060b5f7212cfc0c00682875922e92067792d907da02ac6dc075b2e9f590e066df361383e4069494374b60610c0cb0bd15d11154e239ccebed74adc04eed301653502da5ed179beb0f07de362d6de097effe3255da5d2a3fc101771c033ffa918fa8905efbc8a43b0fcee4fc216b4764a7cf67137f5cd87a1614fdb4dd3071ae7fb784a79948dd34002bad79a8a66dd5762da895da21a19669156be25c9ee6f6154b1d9e03cffb6d22846a5a4678a9a858d32b014511081d6ef8eeaeb3a9b1b2d85ca43c92b7cf3963fde47c41d2ab45515221adf5e6f16fa37da8bbd82f7cc55c1cc97aef22bc74087166ca8b57a57ca1b1ebebc4d06e318ed0b66eacfd871ccf756c5df5071028a54197220a9e38cc2f473382e7c3a6ac8a1917835c6ad22721aed1756dfe43e29ca12c674ecc5153b63042b0dfaecf8213afd1ca75305dfb70bb92f75ee61aa0f8e2b80810069b8ae86e56dc4b3fe80c6472dfaff3977860c0e057992310dad7ff327c4f7c99e9acff0ed1526c1c84df99287530e7c32727aecaa32c35cd07306e2a8867c7b476ce78f261d48f13c7e9737b70414aa746cb823f4ea618c8d68505f12bdb84dec782eb47ff48e200bb0e1ec51a9e39c7bf588ce6aee004f5331a1d9b2c1d00d87f0c9b7bf0f5a1179cb3c4912d89cf37b83fdcd34e40649a6d26c722f72520af38e757a745c8bdab251d84f4e5526326860fafe204bda5138e7f90571f4a60adbe0f1ab0d95a68e9add603e18494ae5c9a8d74ca0a771204ef5d20eea5b6f595094221eb126fe95f4ee2d37a3983fb9f017c35c180a237b5018279ce7b034dcc1761f80dccb7f0a31cab15ebffe4fa50ebabeb9d667808484be8758de872de869ef0f39ae7319bd07d9a4db21b71df5dffc9e31392b65801b1bb2bfa89813d97813df9bf1e866601b9f4a41cead755f8cbc91ea6984eeb2bffd7f052b19daf2b3e36c9b4942804430797867d0e2f1a7e6f562a7ca5fa11863ccbdd03c13b09802b6628f3fa2d3ddc6f4a2f1a4f0a4d7287fec41f22893e7e4b9ddf710bd52f3d0c2f6c846829610630d73b320454c406a64d3375464998b81947a2ef4e2bca0dcedee3dae449cfae30fc777e05d3f3115f966cbfec6c12382311d4e85dc56659a2ece09578005d047492dac9a97de5725b655eea650292a6d457533945c4dba01ba32d21ac4572a6e79053303d2801d5e8e6d6656ac2bf00ccc1ecad0e0982331d1bf31f204d3baff4d5028c1044dcb1adbf9ec50f5430dfb31a3c7a1a693e30b0b6f925c372642783c46bfcc4ffb19a92f1f88bb77c6d80a1b2d65d25fbddf182b3387582e48dd338644ad001a535278bff16214eb838de1a06ca03cc8ac8042b6f65fcce11179566d6f35234a8fe31a8da31cc202ffb450cde74b78217bfc440fff125f3b29d0668bf184fb2567d76088f6eba2a81f1378b36c8670d89328c88929532bd284a54c7370cbc8d87f289655bc592bbe83e02c94e97a49b06ab731efb125cb58e83afece7a301722cfd1f987ebf2ed6dc9bcb2a3bb5d2eeca2c1e59b20da4b322adb7c3584b398ba9eb61b0ca8631de5259012577e7727b9dd5c0e40397b0bfd3ac6cd7d0a37041bc661dc091e5fe9632522b0c15c3a74306d9e6f3ceaab134f9b47ec1869575fe150940ace6777ac8fb2766aafd93e70012cbc8fb8bfec543a7208a2cb79dd5411f4cc99d6e519fed8b2cd8bbadf13242e02bd4187f9afe52e988b57968b9e675abe8c8cd0f83f8b22612c85191d07dd371407f6fa19a4f528630b439b1fb5f8ed70f8a8e5fa58974dede9cde5911caed6182bcacd14302e22fc4f8cf12b3d6962808a2e2b30e3a2dcfaf871fa53acef796081ef08d4ebfbff9c5ae4df869e7afe9793271e31a35e6f30dcf4ccb58afd7a269094e0503275737e3cca2666eba26b3d0d26c8c2753ee4cdbc6ff6547996456b6ba4094a56a7bad018afd9df6ed456eae355750c2831cd20bcf7eabb80036a8160809a0275dfff436c6bde7de6d242878344b52b910b3c7a088d515bfda39d9b624e3da0723bf3ba10ff6fd2dd00f02e8b4afd2f0698702a8ec4b1864acdfc45369e5908d72ec283a21aebd3a02771f91d994b644a95382c83bcfb6e2d350b3db997ec635466a164e958dbc8e947d850cd371672d51ccc007d2660f0f205a6cc9913ec7d4276e01b216012829137023890dbbc2f391ba1b0edfff9a157f615f2c331148b0dc4c4464155d12f76e77f6c8b0f921596eeeba3ed28dc2afecfe6eaeb93262090ee783f9758e641b0b0554187198bcc02ea9486f6f026acd7c43583f596501bee57c38a0a3fe0c22d52157df1b1505266053bab0cad9954292f3f1e1cd3069ad7712a081f8b621ad2b2d33c7ae86c8cffd3a9abf610273b9cd375147d1e758f76d33617f63e1204e4b83253b66ef690ce676193cc786dd70a86ee5c2ccb74682b03c336f80bdee89a56845e213faca8f24a43f54473772657e08500585a83f6779a307018ac1642be0e959f3887ff541fd41927cf89220a38fa7494e085f6f2d70f9ed4a338904e55140a73666ff8f66c1b29bda6dc4f25a6cf39bf7a18d55c1457b43d18747b8808b2b4a27fa43944062035f0cb6a72d90cbe0b77637519371acf51f6f778388213ec40df93c18d7ec7dedc520d7cfa02f086d8710c543dcbfa25d6e413f81b64164a54bfb220d733cecb42cc0bf4839da196c2976cfa963c5e55a1869fdc2427cf17c6d2353b04b9e936a1f70cdc30fd085cd963d16b48af026351e6761c7712ddf800824b35d0eace6b90f287ec929bab3a23adf7cfb94d4879377a33a657dcab6171d1a1a1d7aca9f824803ed2c75efbf4d7e4decb422288e18db06112f16df89a7808551d8614f1b404390d69f813f65b99f7dd76287190039e3a172f5c0f1b3918ffdfeda4fd9b472a1da964ceeb1c51593101bf78d0253eaedbd882bfff4d28c85758b58d1ff14c8447fa03e298cd13f06e3a5c178dbab7951f59a7235c20d50ec8ae79f7ee53d6dfcf1d68793a87cab8d9f3703ecff5b7f9fdc21fff9b39f2bf695cc88366e7abe6b4e40da9736a3c3d27f0c6abd50883018421dd23fa8511034da6ff103d1b3a098eaf6c0722f7b602a2655b6ba5a86176495fe32de1bd6d9e508d6d374b89a6fa58d69cc95ee7038bf6289b41cf3281f59b2268becfedc0a8156f48121f5274243427cd0a70fbea7f9ea4b84caf1dc3f0340ba0fdaa01cf3152dd4b583206329d83d0984e8e317daee516ca9d0cf827cbfa771f7edcdc38af5066d416e6d8f1a75aa285066695f98545cb5445d0015e8e2229785d694190bf8a60be686b1a7923e35f4fa907dfd22910b1dcabf4aa31cc9ce4005690a752a338f629b02751d3ef64a88", 0x1000}], 0x4, &(0x7f0000000ac0)=[@rthdr_2292={{0x58, 0x29, 0x39, {0x3c, 0x8, 0x0, 0x2, 0x0, [@private1, @mcast1, @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}, @ipv4={'\x00', '\xff\xff', @remote}]}}}, @pktinfo={{0x24, 0x29, 0x32, {@rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02', r2}}}, @hoplimit_2292={{0x14, 0x29, 0x8, 0xfffffffa}}], 0x98}, 0x1) 8.78572398s ago: executing program 2 (id=2968): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000000)={0x26, 'skcipher\x00', 0x0, 0x0, 'ecb(serpent)\x00'}, 0x58) r1 = socket$rds(0x15, 0x5, 0x0) ioctl$sock_proto_private(r1, 0x89e1, 0x0) r2 = socket$inet_udp(0x2, 0x2, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sched_setattr(0x0, &(0x7f0000000100)={0x38, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffe, 0x0, 0xffffffff}, 0x0) syz_usb_connect(0x0, 0x5f, &(0x7f0000000000)=ANY=[@ANYBLOB="12010000b1f203401e0903003bd7010203010902"], 0x0) r5 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$ethtool(0x0, r5) sendmsg$ETHTOOL_MSG_STRSET_GET(r5, 0x0, 0x0) sendmsg$NFT_BATCH(0xffffffffffffffff, 0x0, 0x0) socket$nl_route(0x10, 0x3, 0x0) bind$inet(r2, &(0x7f0000000040)={0x2, 0x4e20, @empty}, 0x10) mknodat$null(0xffffffffffffff9c, &(0x7f0000000180)='./file0\x00', 0x0, 0x103) r6 = openat$fuse(0xffffffffffffff9c, &(0x7f00000001c0), 0x2, 0x0) r7 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp6_SCTP_AUTH_KEY(r7, 0x84, 0x17, 0x0, 0x9) mount$fuse(0x0, &(0x7f0000000100)='./file0\x00', &(0x7f0000000140), 0x0, &(0x7f0000000540)={{'fd', 0x3d, r6}, 0x2c, {'rootmode', 0x3d, 0x1000}}) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, 0x0, 0x0) r8 = io_uring_setup(0xc68, &(0x7f0000000340)={0x0, 0x8992, 0x2, 0x2, 0x175}) io_uring_register$IORING_UNREGISTER_IOWQ_AFF(r8, 0x12, 0x0, 0x0) r9 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$inet6(r9, &(0x7f0000000900)={0x0, 0x0, &(0x7f0000000880)=[{&(0x7f0000000080)="abf63fa63be2057e6eb311864b862f44687c12bc9818a7859baa745aff3f92ef76bdf77e7b5d02d91fc1523771c95efb", 0x30}, {&(0x7f0000000480)="52d2ea933609eb07c6d2847054a95df72d8e98717a68c12027034ea2cfe9dfff638298030651a2552405127ab1f7367c6befdcf20f700dcb39e7b9df0edc9269ab3c24d49de362841a9cd7af799cd57f26705d6d6f840b720f5c1fec2275e81fe37b609b8a0309a9918d2621e4ff4084240a16e4d47d78aa427b547d7965db06b164d307465c77df9c1e24328d2a333ad21affbe312fc9eeb453040efedc9bdfb00d138f8b862f393d2d46336dfcaa1e1548c69347803a16c74b964a857bed00d8871d6f679b861c1def970838b2d5314e43ca06b900aa8059d40d756882c3929803e9d98545ac5a2d067813fb171aed7715ad5e5e0e731e953a0d70a6", 0xfd}, {&(0x7f0000000240)="48edc487717a690680dd1b477b1b66f6ea0142bd8ca00f8a7e3a3e520f8adcbe6dab37ba403c2e9923da1833dd11ca383a6d15e18b86b27175a14a8670146d37ce7e8d726d66bfb76649432d82c990712c96ac8e7ffe131637f081b5299f1cd4d210d282c5de16089e6b5ae996836a1c8b2a475048eaf9e1710cdd5c390be553caf0c8c2ef7046bc", 0x88}, {&(0x7f0000000940)="4da1537e1aa8ee68c744c5a486e7b2393712688bdffa4e960c7629be4054a649249ce75863e4b6189990e87e8ade0e7abd7c19e524fb3270ee17563373cb5cef0600000062298a6e00"/85, 0x55}, {&(0x7f0000000580)="ff41c07b3bc0bb61c722d3d67c9e883fbcbb907958a2d3b5f478d9f0afe2a0a587dc0d3e7a7011ded58cee584dafbadfdbd560cff25414fe5e5c0adc1c425dfb9c273feb9cbd03d513b68b29527e13c9396ffe05ca82fa4fb0", 0x59}, {&(0x7f0000000600)="4db4e4aa095c9b5a2387d052149b7c35fa0d70b53339fc2d0bebb32c8067922fb8f7282fa73ef579c6e344162ae2976b06dae8bb60d55f87974a636a824cea86fe3e0bed0e29d37683ce9e232e4da2eb401ee683868f5470885043a7e2d832fd3c80a32d365b2a33bd295610f808d6b7ca42e590b9d6345f2815d824b234409259c29656ff8a00c71a2c9ffc830267ed5faa27b60962891f939fc893fe", 0x9d}], 0x6}, 0x91) r10 = socket$rds(0x15, 0x5, 0x0) ioctl$sock_proto_private(r10, 0x89e1, &(0x7f0000001080)) 7.661552786s ago: executing program 3 (id=2973): openat(0xffffffffffffff9c, &(0x7f0000000140)='./cgroup.cpu/cgroup.procs\x00', 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) r2 = socket$nl_rdma(0x10, 0x3, 0x14) sendmsg$RDMA_NLDEV_CMD_PORT_GET(r2, &(0x7f0000000480)={0x0, 0x0, &(0x7f0000000100)={&(0x7f00000000c0)={0x20, 0x1405, 0x621, 0x0, 0x25dfdbfe, "", [{{0x8}, {0x8}}]}, 0x20}, 0x1, 0x0, 0x0, 0x40080}, 0x0) syz_emit_ethernet(0x56, &(0x7f0000000100)={@local, @dev, @void, {@ipv4={0x800, @tcp={{0xd, 0x4, 0x0, 0x0, 0x48, 0x0, 0x0, 0x0, 0x6, 0x0, @private=0xa210104, @local, {[@timestamp_addr={0x44, 0x1c, 0xa, 0x1, 0x0, [{@broadcast, 0xffffaa7e}, {@local, 0x8001}, {@initdev={0xac, 0x1e, 0x0, 0x0}, 0x8}]}, @generic={0x7, 0x4, "0990"}]}}, {{0x0, 0x0, 0x41424344, 0x41424344, 0x0, 0x6, 0x5}}}}}}, 0x0) r3 = socket$nl_generic(0x10, 0x3, 0x10) r4 = syz_genetlink_get_family_id$batadv(&(0x7f0000000080), 0xffffffffffffffff) ioctl$ifreq_SIOCGIFINDEX_batadv_mesh(r3, 0x8933, &(0x7f0000000140)={'batadv0\x00', 0x0}) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r3, 0x8933, &(0x7f0000000040)={'batadv_slave_0\x00', 0x0}) sendmsg$BATADV_CMD_GET_NEIGHBORS(r3, &(0x7f0000004340)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000180)={0x24, r4, 0x331, 0x70bd28, 0x0, {0x8}, [@BATADV_ATTR_MESH_IFINDEX={0x8, 0x3, r5}, @BATADV_ATTR_HARD_IFINDEX={0x8, 0x6, r6}]}, 0x24}}, 0x0) sendmmsg$unix(r1, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r7 = syz_io_uring_setup(0x88f, &(0x7f0000000140)={0x0, 0xaee2, 0x0, 0xffffffff, 0xffdffffe}, &(0x7f0000000000)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r8, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r8, r9, &(0x7f00000002c0)=@IORING_OP_POLL_ADD={0x6, 0x0, 0x0, @fd_index=0x3}) io_uring_enter(r7, 0x47f6, 0x0, 0x0, 0x0, 0x0) 7.366389397s ago: executing program 1 (id=2974): openat$binder_debug(0xffffffffffffff9c, &(0x7f0000000040)='/sys/kernel/debug/binder/stats\x00', 0x0, 0x0) r0 = syz_open_dev$loop(&(0x7f00000000c0), 0x1054c3b7, 0x40801) ioctl$BLKTRACESETUP(r0, 0xc0481273, &(0x7f0000000140)={'\x00', 0xfff8, 0x7f, 0x10000, 0x0, 0x6}) r1 = dup(0xffffffffffffffff) write$6lowpan_enable(r1, 0x0, 0x0) r2 = syz_io_uring_setup(0x238, 0x0, &(0x7f0000000180)=0x0, 0x0) syz_io_uring_submit(r3, 0x0, &(0x7f0000000040)=@IORING_OP_POLL_ADD={0x6, 0x2, 0x0, @fd_index=0x4, 0x0, 0x0, 0x0, {0x48}, 0x1}) io_uring_enter(r2, 0x2ded, 0x4000, 0x0, 0x0, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x3, 0x8031, 0xffffffffffffffff, 0x0) unshare(0x1c040880) socket$nl_route(0x10, 0x3, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r6 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r6, &(0x7f0000000380)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x4000008}, 0x8010) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) listen(0xffffffffffffffff, 0x0) accept(0xffffffffffffffff, 0x0, 0x0) madvise(&(0x7f0000000000/0x600000)=nil, 0x600000, 0x15) openat$audio1(0xffffffffffffff9c, 0x0, 0x68000, 0x0) syz_open_procfs(0x0, &(0x7f0000000000)='net/anycast6\x00') remap_file_pages(&(0x7f00002ec000/0x200000)=nil, 0x200000, 0x0, 0x1, 0x2000) ioctl$VIDIOC_REQBUFS(0xffffffffffffffff, 0xc0145608, &(0x7f0000000000)={0xfffffffa, 0xb, 0x4}) r7 = msgget$private(0x0, 0x100) msgsnd(r7, &(0x7f00000003c0)=ANY=[@ANYBLOB="03000000000000002c5b92fe53d0a8d45c8df77b3a5b24f5b5f47fb21e984f7cd98be58672f21c05d89a28dd30d16695fd88872467e730c5c5b07c0baad7f374dbe55481983863b91989f7f9e702207af9ed03c1ce4f6eb9b24a840cf9e71f78cba191462144280a2866a9e564cdf705a0dcf7833ebd4d2f23d396cbe8ffa41ecb67a470e3bb3037a146b21a2af740178582259f87014c3647901b3c888b71cb87bcb145a83f4429394c319164566ac0c8821c5827f7c81d9a289c18b0808e9046145a3890f5273bab59211376b73224dc2cfc9a99c36c8266430e1877aa8fb26ccbdee4c77a0de31deb8729c07d000f3714455c7db1999b623eee354be50ae48db0bc57b0d663aeabe13198305efa3c242b6b17458cf3aaf07f57727548163f83393600bc81201c2792b82cc5cdaa5ba4ae7ecdb2db7defa75da39bfbcdc1c139ac6f015758e6f536796ee758ebc486b289244942a2db4721deede70ef5b975e2ef6f72e7530e2a48d4cbb74ce7a376939ddd77cdc6aab076c17bba11ad81fb16f55aec0a603d71da0c53bb4b10c369308e8d397bd797b54a9fbb2f8b96b982a5775124bd1a73d659d8ec88148e5c9ee4f6156071adb66ee79e19cc753724cc31b5883b7a8c0d2921aff7103de65c90b97e4acd5e18bb3f373b9cd32f6a03476d6324645fcc44adad16f2bf3935232b2d33e68f16882e264d01064d9d74bdd36d1a43a6157875309e8ca7d23e87d44ae57f8db8a005f6833f75016ee942f226686cd342e11cc3b035d815c3935d0304783cb3d4bc70c2f1a377ef865b1ae7f1f8da4bd85a748b24a592b020891acd6f1bd1f6462e0fa5bd704dd94e254a60f7da2794abd16fa208a2b3dd40b8b6c91502da6aa9ce0b49c30dc886e94f9c637d0279234f69e9cc824a9f9eab8b78437f839d19c2d33b26f3a4aee997de0a3a9f4e850f2672de91b03e4199a231ac11b370a8381f742bd42521dde5e5703306273f763c36a499b7dfd591847d9a037761fb6b5fe63259896d3cc5a92839c7f8c7bc30fdb87bdf10e20528f85eee2e898e505d85ea55c7ca6f8188c99203ac65ab028c3ec8537a4bab01abe8df789fce5bb267737e936ba40834855589736b9ddd9610593ba55853cc171a5f40b81dadc741a2dd608977251c67cf5265066c064d9f29f444f08d6e220f930856207a4fc954dfdc2aa0af045c2a1e053e37c88af310ed6394c7fb0593ff5b20d729a71c91bd509ea2e50aad1f878523463eda57c4199287f9265289cef64c4e38da47adee287055d8f54bb6f9f7082b8046d62be6d974dfee3b99784d3a7c2bf332711bba305d6d13954282a390ec2872ce52c84d25b38f2c29a797eb21f3a2df1b207382561df9ec9432cc14a99ac51ded0afd4e4a2ea0500e23546da7490c46aaa7d6c86d4871d5a172c6179171195c5eeaad08bd38f7bbd0a7704bed147e6c3ad11cedc3406990af4365b56614ffd2f12b1f3bdd363b8a1e70e9b0148eec8ed052ce0c5db4a4bb126da0f9bb78fd05f054e418a595e370a5c4e74fc8c8b6e26097ad8a4318a4e7678869116ca608e1b58f86"], 0x3e4, 0x0) ioctl$BLKTRACETEARDOWN(r0, 0x1276, 0x0) 5.892318489s ago: executing program 3 (id=2979): openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='cpu.stat\x00', 0x275a, 0x0) r0 = creat(&(0x7f0000000040)='./file0\x00', 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SET_SECCOMP(0x16, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sendmsg(r1, &(0x7f0000001480)={0x0, 0x0, &(0x7f0000001400)=[{&(0x7f0000000140)="ac5f61acdbad9cbe4a7c312fb71a20b4a65627e3c3c39cac2c7058a25d472fb39ed2e031d22a57ecd39e204222a9cdbb99ff00a23224e9f59865c4e8505642b013b66317dfaa7c8fb2a50c10", 0x4c}, {&(0x7f0000000300)="f3e00b16b521d5ab5caf842e16096eebf5c72dd9a710ffd9c12c9ddff0c706ae2b17f077dd35fd44d4dcd4c03cf5d97e8415b0c36f055801c8e5cf9cc141ac7ddc5bc99d1e3276f5a94a0ea8232ce20feeccb5b70be8565795f7580b8170419d91e5f64f1063901c3b21a56c7661946c749b05ebbb37ab991acf19fafb50f0792a84d4e1786bb7f809ce29bd78f87c69ef7683deb5e8b55dfcaa1f18c324fc90c70046d30e2a63aa7eaa4b83499ed7295a14d7deb70f01d36f5946cb4ad2ad89fdce6b284ceafaeddfd7de2048d984e6b1d62105406e135fb5985c92be291e7de38d7a98f8673d09028b10b35eb68bc09b82cc3e7cbf1e8029439bfa7a448019bce2ad823d0806f428566a103d1181912f0f271456759b3793d969e81ba13f59f23ffd507651cea52c48980a0cd20eafaf9b5c16e8149dce96266a45de9e96b12fd7da168b589c53371b14eac36723c48ab5a3ec5233817bd7c928bed5324fc16653352952279d31f77737bc9130b406b76cc2f311ff7c7f8ad2b22901a2ab70b638c67ce225075a3320aad607f77cc32a46f5aa8dc4a8281e2109c3829f6285f39a6e020cbc9c2d8e901d7ebdbd6e5c635cb22f68cdb45cc63c34155ff3304c00fc830d03b7eeedddcad1be146eabae773d4cc0eaf664843eddb6745dfb2dd959fc23321e5d7b808ee883ef589a79e59207178b4f42fe5a28bed6a56ce3ab85b9d852c73367c1a9dfdae325f6210ecdc51c43595eeaa5c53fa58799c85831363886360ad71911486303310b4562d0f3f8c51f2e22a0a8bb79ca68da2cb6a0ca49af9cfe490cfd9266fceb539535e047c4e53af1f636d42b05dc27240b966d17a596cb580e27dedd2a5bf83ec7431e4588942cdc3a51005e5d9557288397dedf1da7e49f290e44515c5f92ee1fda202f8566fb36823b27d03f02bd6b18b375581ef4e314dc03ba52722dca2df064af5052a8517aea62133224e69c9eefff5aff4159acc292f8eaef7e6ba9aa76f460a4e706e83f44af5008bcf6c4cd0f04e7d5334c1fc42ca2ef6d53679b2e6cda641d50dddbd81bd4ba772aae004614552a40e5d9da25b6b2ec7c0573412043430d069991b709d7353a300225a52ef7a4aa0b9c3144904459d7859d1dc6cf724c3ee30c598b7778eb78c7e0c096ef3464e0b381725e179660aaaa47897dc790b7763c4c15ed19bd678d27d501f66598164e9d2a716878fafc2bfd8270ed65368d279c26ccaa22ceaa5f71b6934413e0079c118585e4a32e09f62ca6f59f64fa92478d7b7abecdb3c6dcdb78c6a4718db68b4f075f7c878e1e8f5eec53ed80d33c78ff0dc1e136475d7f911b9beb9f60402616a487d2a3a187930baa5ba32dcea405126c034cbdc20f7875c23195aa4d226416ddae82cb644c09842967cdcbc48bc7121c29f6ac89d4cb0d8f5c2b1dcecf5f58b7bee0e795b7014808482dbd0382b28d9d980843f36a0eb3b93a89a114748f0e021d9ebac0c52317fad4e4b99ca3532249e8f22f86a8dd1662539123cba02698e02f8ca9d4f36c07af64afee8aae4972bb98fead5a94bbd2691d2eeaaa3c3c30149edd21807f116c01b927ed87a6e314b96ecac6629fc26aa20909b5be68c360235dd7823be0f2c274e89f8976b0fa94d7a4b40743d6c470f70fd0cc1a9b5c903d187807d9b15943d7631a39a76efe4f34425173be6349943b1478f91641541d95d81af05e263baaed13dab3e27e85aeaad0640df5a1e6f1a0018327c5ad8423b950a376cc0661d4d4551fb5846d52e97dd8e505068c1c4887e6d3e67f3ae3e507003dd3b044263d3a5a891c827e20b1010838cb4aa8ea252fa4e61cbd5e82f3e64a5a9b3cde5a8d1f63e4009574187714eb5ce26911cee00dbfa1f3bd8478876e69ac1ed27516317efe82fefd2fbd7676bb08a87e8e6b96b6b0aac344b4ef2f4c95beb55f4711c046aa3d722eb842d6c2cba8b457bab01492a6e81f9131b27f45fdfe0e1f3a255f8769d97c02fc4cd0baaed4506eb4a7d3830ad7d4ee57647b0735bc4a67ed810bfa75d6608391d7a9a62a31366e67d82f45cdc9b24ff60b28c19dba4b70e960cb052879af863ede7aea3ffae89abd97f23e3127baba7f900b348f739216ecce8de740667eb90c3bff9d781d573ca9e1d99b79c6ad6c0fbd5949fa60742395ea089c7567a623f839f0a7e93685312fd641d826f9e95ca894c438d4acda52ddb39480d2d2b5c0c270eff733081cabb4541cbeb50d3222f98bf52697b6c12f7296f847da8b667f859794b0651536f29d83a68daa1b50ce5d88743556a29d607fd773dee36eae46f6428cc754d9b11f6efbcbfbcf4b51e6bec645f36185697a7ad2abe8776084c2e554fb68372d85b7fd5087b3198da41c29952c004758a844dabc563733f9618237ca201306e316df22c0ea29285f819dc0c2eb47834cb1b67fd4dae86cba5058330ac5978b631ceb325303d50ede38184a9f01d8c2c236c88d800cdaddbb9d6bb51468afe997b769db5cc69db70c8119169d78171680f70996edb93cb5b26e1b6a5ff29b9a6d1ed76d2a251d156e7ee77716cec9c1d994ab6dd9c355b3dadc68e2573f959ce1a17c39cf549604f9976245e62a3f9baad4230c882971de6b919f74e308ce0b9cbd4d4bba1ddf1ac10ba0626b9f94ee39c67a18dabe0017c69ecfef0f897d6d21ed464aa40618c5ff2b0dc9ea29d722f015907afb1a2edfcfe1c6fe35db304f43ee7a495bdf6b896a1d093a6cc3651455fffbcd2fce8635178bd4daa00be809efd637af707207e2f73e16716716b6d2bb425ef0e30795669b8d3adf9684b6ef38a46c66936780d18b4c820ab250c2959a83561092da6daf8be034641a5aafac1230eb6f600317b2b1a9f5d0311c9e6b33ffa5ebe7563b74178f12f0c043a3484cef5fe2c53286056702642793208f55e5dd0738392f4e97c4f4bdc6f2000ec3a97351435f18f57c6d945bf9ed8ccf092ff88e4ac6b694fc83b3a49e4483a35df2e67e05e523a2388cd7a15dce2c032e80c0523754569247c1e403d9531288cb736bf6505ab3e5f901224764b4485e2a4774cbfade25d9ea7ac0ed7db8e25ddf3e9bc9e597bad03b12f2db52f45c73e71173611041a2baf6efeaa3a1cf1c297b4b489c7e73bd79a185e6e85d4fd5618ba750560f234f5575903d3459fd2f6a8f84dbb059bbded7e1b8814b00258ae53c59b21f3e127cdee0564d31d6061a88f01a5181a79845f3fa54a80aca901ba10855560aa7c69836111333e1bff045228182132266d5107f9af5b550d5dc07c6f0fa036f33bcae9f4155bf356fec2aacf372d10f5a3c0f3e2ccfdc3f5dc7cac2d1fa7201d14f39f5b01ad84a70619d7566c198d3ea10646da07d9cca41175c992354fc7d6bbe22d855a7a841004f69c7704c572d7d5d716c00c6a95b19a81cd4615f1fd8cf14b066bfd66a059ea349e540ccc3ad9a4e742ad382dd05d3a8f77d07b462a7510e09983bcdb167be5bc3680fa55ebe1b2e21bd7b028f4c0e40640b6341c561773d73d43f4055d5f7e7cd438378ed9afb163b1455a09d071f82d4515ba41455ac74eabea7c27f8081db56da292bd3fb7a1e7d0649fe5f889d9a6b2fdeef151fb0761e7a0b852982aad5782491df8d057b19cd7a2d4f2aa549d5a617dec3e003066d6b771a282f95e65a92f7fe956669039a3d7f2b8dd8cae8bfafbf4777c9e1a234a9bec90d034059b77777d501e5e161d567eba75a0fa87b8c0009a9656683ba414cd88530908d8a84bba5e612b3de429e45283f570bcfd421debfad4d539066adab0830f5846f4d1ab6e07dd5b16237e7092cd4533264f32a725314385a0e7450e371ad86267c4a574c5570ee32678d74b14124136e0e35eb5ef1e8d0f8961372c0687f6005699f21c82f7ece3716bc2b226dd66287b9894045f78bf743e77921ef258f168e1bbf01dfb490f66dfaed664425d0999ed175dd4f3eeb9c8ce43d1dd874f533a10158bac4e67a268c94936defc000f16e86d2803703cbe2359c28cb6f420b6b8483a37840359bb97439bfe4444c2f9c7430ba7040cf50b1b4a47c7f791ed579beaed003489fda99f9707ae728a3137217ced175597fcc2b0c8da8fa0b78ffdb3bce98c0af818bbc87cc59cac1e7cd3a816569924baba0e981e79af13d877dff8d7bbcfecdd2327e5daecc75ebd8d70d34e13618dd88daefd683b171ddba47ac9da2c690a0d914ac0b451fd8be84ee4a516793a7f06fa96c6b9d26b04d06e8cc546f5e9fb2cf3e40fd75f385dec12f28bb1e11bcf52a8f9da7072a6c92e1434068265cd32585c34ea5dd36ee4bc2a76c1c62c4b77ee768f39ebf08f6ff80f382015d2d38465ee3495ba8135fdb54768580b041bcc52727408803d107422f0055c6666d9fc3ba7bb87c30b264dfc4e3a972a30577ca9bdaaf0f21ada9a3ec0faf1cf50c114a6afa24ad2fc2f985c21c35015c493b32268ff0b8a9e7986233283cf4c2a34a99eb5e5a3188a6757439c82a8084a33fd78e446cc08d3ac441db0ffdcf67c0fc8a4a4006538482d770681455c9753b6cbe1549fb60ffe37534b5e5db4d8e99ad8fb289c0d13858195d85145755192fc699493f7a30c5866bb043b57ed7dbec4e4dd7825d4aae3b6cd88d5ef49c29913c5f5f1c92d064229f8e0fb6b3980939c89c72ff40ffdeef3499663575a55b51cf2639be1e5d192e1a5ff949cee867b9100cefd59a5a2c34ba382493629136488c2a2e2fdbdf6f1bd3c85ab47bef20d10aeb44f55f57442ef3741991880e4fa6b2964eb2bfa0f651a2896eda71c532a4e52c5a9147aafc88f2cf7485ad8191d35b4f36078709ea4d9b6d7bf6be3659160d22ad4d1b854c17d659622597c2c642db4d64cd94f65a5316b87fa54cad23fde3747247b9a57f727e117178832d8ad800ccdafbf5abcf04fbf546e1d3049978830c99ae426bdae70b194727fcaa1f03f32d5cdd964d793264915d605025eed9df472406c747899047527e7e36e4416d38faedc00445e59f79f3568cec6f59285f0f91de7a409dd90e77661cea94ce2116507762d6c3b150cceee013d2186bebf1a83ae6c9637df2ec9e4d439a357b0eaa80b65b403881dc81c121f0e8d1efd6fb5b686f2c51d3f4fa94f783709a01dcc6347ae29c6681b0c1d4b85af9ae6b23cb385a9d579cd7e49d6431dbf6d389ea23cc944e3007b2f38772c2f6860aaeca19ba327f632f1c4a28f0e301766e7816dc3449eed51e57535a0659b8ecfd30660595c91d4ac4a9be32da9c2917efb39bc77f4e2257da5329166b212094793a9b236ac6ffa8246ec889be127be32f4ed5abaa9b8a67ec5373493f41831cbe4d699cde8cb60e1ef4efa79d5987e0d5c92db16d8c91c655814ed223627c4d9ea43ef7823af41389c7bc10e107ac5662aac5e674588c3e7a23130ec45d416a782e7cb1c8da37340e1ccbae51033768ec4831853be8b5168fe9e8a33054cc1b7622ca5c810214a6ef74edb50e20158d11632c355b77fb4090747382094aaa1b79d3c9783933bbe17b55b54a27092eff54ff3b4905f678fa71cbf24396aeffc35d8d9af612a12fa85c3b6d2bab062588bd533af448e90e5fd24bf01283a55ff0963f8202202aa9451a4d4ac87397e2c73ba3e2fc534788be40164b47a1b50dee4a9499c7221096cc546345f88af0cfa2264d95ea59714e0993720a3605b4d0b23d465cf759f7b60fb3042accac65d946e30029b701ac20ad68710aa82642a63504d2ada223b5453646c70060439be6aad776a40ad2", 0x1000}, {&(0x7f0000000200)="e38dc3b256c3dbb1f0db2ed180229bf819612f2c55ec5aec897c21aa0ea57085ae40805c0bb2545d56c52778aa41affca01f313b22ae8ab05ce35ac44a4207598b8fede00b9b0c85e639c23bc739f23bdd6a82ebe826353fea9be91aef9b097f93cc22a42b3bdc466a40f0e484ebc0db7763b79191d948353f6c381aad6ee2672a39bd2e4c9ceef777944f955db7155f32c74585090615f9f17205b67c02c70f", 0xa0}, {&(0x7f00000000c0)="1f80cd9190325e6f1b57f09f259625", 0xf}, {&(0x7f0000001300)="7cabe17734b8655c70419e7f47eab8bb8177da50f0664f1dd9d47d26dd9afa1a062a3f2a5323914148cdd567065e30266451d6764906bf801ef7e55626a4e444505a96e89f9a2cf1460d208a6fde6b81643060e4729a0ed0d227550eac1781c4d2a70bffc586d86c0b89884b8daa6f6ed9081939f3180036c4", 0x79}, {&(0x7f0000001380)="9ee81db693932927847694043b08047eeff1549e9efb28549adbddff3f569021489fcfe8b7f16e30ab20369453786c5ff07847482a90ae6d674cb1f427d0189b5f7a74a762a3c98e9cc52ccc39024fc56007e8e55df4be5809c9b91dc115d1db17eecc4e622aff5aa4caaa0d58f8a6d3a5494fd0b3228ecdbb", 0x79}], 0x6}, 0x10) sched_setattr(0x0, &(0x7f0000000100)={0x38, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffe, 0x0, 0xffffffff}, 0x0) mmap(&(0x7f00009fd000/0x600000)=nil, 0x600000, 0x2000003, 0x6031, 0xffffffffffffffff, 0x0) move_pages(0x0, 0x1, &(0x7f0000002600)=[&(0x7f0000ffc000/0x1000)=nil], &(0x7f0000002640)=[0x1], &(0x7f0000000000), 0x0) r3 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r3, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000000)=ANY=[@ANYBLOB="ec0000002100390d0000000000000000ff02000000000000000000000000000100"/64, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="000000000a0000009c001100ff010000000000000000000000000001ffffffff0000000000000000000000002001000000000000000028a46861bed7b4a114bb000000000000000000000000000400000000000000000a00ff010000000000000000000000000001ffffffff000000000000000000000000e0000002000000000000000000000000ac1e000100000000000000000000000006"], 0xec}}, 0x0) syz_usb_connect$hid(0x0, 0x36, &(0x7f00000002c0)=ANY=[@ANYBLOB], 0x0) mkdirat(r0, &(0x7f00000023c0)='./file0\x00', 0x18c) r4 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) r5 = ioctl$KVM_CREATE_VM(r4, 0xae01, 0x0) r6 = ioctl$KVM_CREATE_GUEST_MEMFD(r5, 0xc040aed4, &(0x7f00000001c0)={0x1fe0000}) r7 = socket$rds(0x15, 0x5, 0x0) setsockopt$RDS_CANCEL_SENT_TO(r7, 0x114, 0x7, 0x0, 0xa0) fstat(r6, &(0x7f0000005b00)) fanotify_init(0x0, 0x8000) mremap(&(0x7f0000fff000/0x1000)=nil, 0x1000, 0x1000, 0x2, &(0x7f0000ffe000/0x1000)=nil) socket$nl_route(0x10, 0x3, 0x0) r8 = add_key$user(&(0x7f0000000000), &(0x7f0000000100)={'syz', 0x2}, &(0x7f0000000080)="01", 0x1, 0xffffffffffffffff) r9 = add_key$user(&(0x7f0000000140), &(0x7f0000002840)={'syz', 0x0}, &(0x7f0000002880)="f40fc24077021c9b084c60ffc26f26db12b9e78d629870bb26edb4a5e1cc0942ed8c58ca4fe84b94a0e31ea64089ee9ca1efb52945ffebbfea11dd3d0df936a10285eccab940ab5c96cb5d81dac1ad2243d878dde6cfd6ea08d5abcb00bb35436929ddabce530b63fab525337057438cf64a506d54d5c83e3e593d1d53ad0e6a44168fe8cfc6ad98b653d80636e4ddc1f2ab58762b3494250b9557f5b606a43e50874c90143034142cd5f7bd9b4dd876b97b7feb75b9138dde818a3c6b96dd80", 0xc0, 0xfffffffffffffffb) keyctl$dh_compute(0x17, &(0x7f0000000300)={r8, r9, r9}, &(0x7f0000001380)=""/4098, 0x1002, 0x0) syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x0) mount$fuse(0x0, &(0x7f0000000000)='./file0\x00', &(0x7f0000002100), 0x0, &(0x7f0000002140)={{}, 0x2c, {'rootmode', 0x3d, 0x4000}}) 5.302138352s ago: executing program 2 (id=2980): r0 = openat$cuse(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) (async) lstat(&(0x7f00000000c0)='./file0\x00', &(0x7f0000000100)={0x0, 0x0, 0x0, 0x0, 0x0}) (async, rerun: 32) ioctl$DRM_IOCTL_GET_CLIENT(0xffffffffffffffff, 0xc0286405, &(0x7f0000000180)={0x5, 0x561, {}, {0xee00}, 0x5, 0xffffffffffffff00}) (async, rerun: 32) statx(0xffffffffffffff9c, &(0x7f00000001c0)='./file0\x00', 0x100, 0x0, &(0x7f0000000200)={0x0, 0x0, 0x0, 0x0, 0x0}) r4 = syz_mount_image$fuse(&(0x7f0000000000), &(0x7f0000000040)='./file0\x00', 0xc04, &(0x7f0000000300)={{'fd', 0x3d, r0}, 0x2c, {'rootmode', 0x3d, 0x2000}, 0x2c, {'user_id', 0x3d, r1}, 0x2c, {'group_id', 0x3d, 0xffffffffffffffff}, 0x2c, {[{@blksize}, {@allow_other}, {@max_read={'max_read', 0x3d, 0xfffffffffffff800}}, {}], [{@rootcontext={'rootcontext', 0x3d, 'user_u'}}, {@uid_gt={'uid>', r2}}, {@rootcontext={'rootcontext', 0x3d, 'user_u'}}, {@euid_lt={'euid<', r3}}, {@smackfsfloor}]}}, 0x1, 0x0, &(0x7f0000000440)="60e5184b6f79b3990078fc015dd00064e45ad690c72c9ad3ed3f8304e5f8bccc425096c8d7d8cd1b98b3da0f2726b322237223d1435d6104c492") (async, rerun: 64) r5 = openat$uhid(0xffffffffffffff9c, &(0x7f0000000480), 0x2, 0x0) (rerun: 64) write$UHID_CREATE2(r5, &(0x7f00000004c0)={0xb, {'syz0\x00', 'syz1\x00', 'syz0\x00', 0x95, 0x2e4, 0x5, 0xc6, 0x0, 0x9, "2b46a8ce33471d4eb88a7557b197fab875b8ed160b251bf9509827559aefbdbdb0bf856dc2a0d02f0af7d68cd8b7f40b8c59bc5ebf48bb5eba225662b11819a86073482e0ccbf93f76ee2c8cb913229339663f07ba675d6a526e188dca34432981c739afb005d27954ce94c8470c82b543ef6414e6152d7b6ada42c8383ec4508dbd1109bd712f94adf1e67c29c5a1cadf17e17173"}}, 0x1ad) (async) r6 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$ARPT_SO_SET_REPLACE(r6, 0x0, 0x60, &(0x7f00000006c0)={'filter\x00', 0x7, 0x4, 0x3e0, 0x0, 0x0, 0x210, 0x2f8, 0x2f8, 0x2f8, 0x4, &(0x7f0000000680), {[{{@arp={@rand_addr=0x64010101, @remote, 0xffffff00, 0x0, 0x3, 0xb, {@mac=@broadcast, {[0x0, 0x0, 0x0, 0xff]}}, {@mac, {[0x0, 0x0, 0x0, 0xff, 0xff, 0xff]}}, 0x87a, 0x4, 0x200, 0x53c, 0x3, 0x5, 'vlan1\x00', 'rose0\x00', {}, {0xff}, 0x0, 0x8}, 0xc0, 0x110}, @mangle={0x50, 'mangle\x00', 0x0, {@empty, @empty, @rand_addr=0x64010102, @initdev={0xac, 0x1e, 0x0, 0x0}, 0xf}}}, {{@uncond, 0xc0, 0x100}, @unspec=@ERROR={0x40, 'ERROR\x00', 0x0, "42fb63ba6dd623b4eadcdfff25768d419c0cbf599bb6d00cf09323d590ed"}}, {{@uncond, 0xc0, 0xe8}, @unspec=@NFQUEUE0={0x28, 'NFQUEUE\x00', 0x0, {0x5}}}], {{'\x00', 0xc0, 0xe8}, {0x28}}}}, 0x430) (async) socket$nl_route(0x10, 0x3, 0x0) (async) fcntl$setpipe(r0, 0x407, 0x7dc) (async) r7 = openat$vcsu(0xffffffffffffff9c, &(0x7f0000000b00), 0x8000, 0x0) sendmsg$nl_xfrm(r7, &(0x7f0000000cc0)={&(0x7f0000000b40)={0x10, 0x0, 0x0, 0x100}, 0xc, &(0x7f0000000c80)={&(0x7f0000000b80)=@delsa={0xfc, 0x11, 0x300, 0x70bd27, 0x25dfdbfb, {@in=@private=0xa010101, 0x4d4, 0xa, 0x32}, [@algo_auth={0x61, 0x1, {{'digest_null-generic\x00'}, 0xc8, "95c3db62549cddeaff72e63cc45702240bd63496b98ea81244"}}, @sec_ctx={0x70, 0x8, {0x6c, 0x8, 0x0, 0x6, 0x64, "0a84a1e1ebbb8d4820c552ef775af6b0526c081940066baf847ef34d3a685521f25ef5c63c87434fafdd7a65e63d9e951d1af5f3964d391265a8809d4691a532273b1bb357c5fa2fdf13a9249b5ddf99e4a44e24d901fc2a193afc5e1c1407db40d60bd8"}}]}, 0xfc}, 0x1, 0x0, 0x0, 0x8001}, 0x8001) (async, rerun: 32) ioctl$PTP_SYS_OFFSET(r7, 0x43403d05, &(0x7f0000000d00)={0x5}) (async, rerun: 32) getgid() statx(r4, &(0x7f0000001040)='./file1\x00', 0x1000, 0x200, &(0x7f0000001080)) (async) write$UHID_CREATE2(r7, &(0x7f0000001180)={0xb, {'syz0\x00', 'syz0\x00', 'syz0\x00', 0xb2, 0x4, 0x2, 0x80, 0x1, 0x81, "bfbd61e574730652eaae7e8b5f4b56fdc8e970c00364dc5225255c5ce0f0ba32f437b3a75fea84e4143366813b959836a85d2651542f7be50eec7dbf0ecb64cbe00d42161c02f68450a252f7fc8f4d62d22588124576417b8eb062808412082c850dfe942581f1c5b20392c7ec57bfa546ef818c087baeb79636055d7ef350a1baddab54d514b4bea8cbbdbf6441deabeb1f5816fbb4920e206f18daa653958ac36cd753d7c66cf819e63b0762dc923acf95"}}, 0x1ca) (async) r8 = socket$inet6_dccp(0xa, 0x6, 0x0) ioctl$sock_SIOCGIFINDEX(r8, 0x8933, &(0x7f0000001380)={'vxcan1\x00'}) (async, rerun: 32) r9 = socket$inet_dccp(0x2, 0x6, 0x0) (async, rerun: 32) setsockopt$sock_int(0xffffffffffffffff, 0x1, 0x1, &(0x7f00000013c0)=0x81, 0x4) (async) setxattr$security_ima(&(0x7f0000001400)='./file0\x00', &(0x7f0000001440), &(0x7f0000001480)=@v1={0x2, "b9"}, 0x2, 0x0) (async) setsockopt$inet6_int(r4, 0x29, 0x3e, &(0x7f00000014c0)=0x1, 0x4) setsockopt$sock_linger(r9, 0x1, 0xd, &(0x7f0000001500)={0x1, 0x5}, 0x8) (async) r10 = syz_genetlink_get_family_id$nl80211(&(0x7f0000001580), r7) (async) ioctl$sock_SIOCGIFINDEX_80211(r9, 0x8933, &(0x7f00000015c0)={'wlan1\x00', 0x0}) sendmsg$NL80211_CMD_SET_INTERFACE(r7, &(0x7f0000001700)={&(0x7f0000001540)={0x10, 0x0, 0x0, 0x400000}, 0xc, &(0x7f00000016c0)={&(0x7f0000001600)={0x98, r10, 0x100, 0x70bd27, 0x25dfdbfe, {{}, {@val={0x8, 0x3, r11}, @val={0xc, 0x99, {0x4, 0x64}}}}, [@NL80211_ATTR_IFTYPE={0x8, 0x5, 0x6}, @NL80211_ATTR_IFTYPE={0x8, 0x5, 0x6}, @NL80211_ATTR_MESH_ID={0xa}, @NL80211_ATTR_IFTYPE={0x8, 0x5, 0x8}, @mon_options=[@NL80211_ATTR_MU_MIMO_GROUP_DATA={0x1c, 0xe7, "765b89120ed9d1549ceef8e25032f17f83a1fe279eaf43bc"}, @NL80211_ATTR_MNTR_FLAGS={0x10, 0x17, 0x0, 0x1, [@NL80211_MNTR_FLAG_PLCPFAIL={0x4}, @NL80211_MNTR_FLAG_COOK_FRAMES={0x4}, @NL80211_MNTR_FLAG_ACTIVE={0x4}]}, @NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR={0xa}], @NL80211_ATTR_MESH_ID={0xa}, @NL80211_ATTR_4ADDR={0x5}]}, 0x98}, 0x1, 0x0, 0x0, 0x400c840}, 0x4015) (async) fsetxattr$trusted_overlay_redirect(r9, &(0x7f0000001740), &(0x7f0000001780)='./file2\x00', 0x8, 0x1) ioctl$SNDRV_CTL_IOCTL_ELEM_WRITE(r7, 0xc4c85513, &(0x7f00000017c0)={{0x5, 0x3, 0x800, 0x9, 'syz1\x00', 0x1a}, 0x0, [0x7, 0x7, 0x2, 0x5, 0x1, 0xbae, 0x0, 0x172c000000000, 0x4, 0x7, 0x3, 0xfff, 0x100, 0xfffffffffffffff9, 0xfffffffffffffffc, 0x8, 0x6, 0x4, 0x5, 0x1, 0x6, 0x10000, 0x5, 0xe, 0x2, 0x5, 0x5, 0x1000, 0x4, 0xfffffffffffffffd, 0x0, 0x9, 0x401, 0x1, 0x6, 0x8001, 0x2, 0x3, 0x1, 0x1ff, 0x88a2, 0x0, 0xc4, 0x8, 0xfc, 0x8, 0x7, 0x2909, 0x7, 0x2, 0x8, 0x8, 0x2, 0x5, 0x734, 0x29, 0x2, 0x5, 0x6, 0xffffffffffffffff, 0x28, 0x76, 0x6, 0x7, 0x1, 0x4, 0xfffffffffffffffc, 0x8, 0x0, 0x341, 0xff, 0x0, 0x2, 0x3, 0x1, 0x1, 0x8, 0xb, 0x0, 0x0, 0x6, 0x0, 0xfffffffffffff384, 0x5, 0x5f, 0x100000000, 0x2, 0xd, 0x7ff, 0x9, 0x1000, 0x4800000000000000, 0xfffffffffffffffb, 0x491, 0x0, 0x2, 0xfffffffffffffff8, 0x7, 0x80000000, 0x4, 0xfffffffffffffff7, 0x6, 0x100000001, 0x2bd787d0, 0x6, 0xb8, 0x7, 0xfffffffffffffffc, 0x9, 0x0, 0x9, 0x4, 0xfffffffffffffffd, 0x8000000000000000, 0xe1, 0x1, 0x9, 0x4, 0x49, 0x0, 0x1ff, 0x8cb, 0x8, 0x0, 0x5, 0x9, 0x3, 0x1ff]}) (async, rerun: 32) ioctl$NS_GET_OWNER_UID(0xffffffffffffffff, 0xb704, &(0x7f0000001cc0)) (rerun: 32) 4.769883972s ago: executing program 2 (id=2981): r0 = fsopen(&(0x7f0000000000)='cgroup\x00', 0x0) fsconfig$FSCONFIG_SET_STRING(r0, 0x1, &(0x7f0000000340)='name', &(0x7f00000000c0)='ccnA\xf6gro_p\x00', 0x0) bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000000)=ANY=[@ANYBLOB="0200000064000000080000000100000080000000c7e3deaa"], 0x48) r1 = openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) r2 = ioctl$KVM_CREATE_VM(r1, 0xae01, 0x0) r3 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000001c0)='blkio.bfq.io_wait_time_recursive\x00', 0x275a, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r3, 0x0) preadv(r3, 0x0, 0x0, 0x0, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r2, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x20002000, &(0x7f0000000000/0x2000)=nil}) socket(0x1f, 0x80801, 0x1) r4 = openat$fuse(0xffffffffffffff9c, &(0x7f00000001c0), 0x42, 0x0) read$FUSE(r4, &(0x7f0000006300)={0x2020}, 0x2020) syz_fuse_handle_req(r4, &(0x7f00000021c0)="0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000e00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000800000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000dc4e00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ba045abcd5dfc67d00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000081000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000230000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000050000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000a0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000dc000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000008000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000209bfd66eea210560000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003dc150f4000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000030000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000f50000000000000000000000000000000000000000000000000000000000000000000000000000000000c6d90000000000001354c4b6000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000f8000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001a00", 0x2000, &(0x7f00000062c0)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, &(0x7f0000000300)={0x20}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) r5 = socket$packet(0x11, 0xa, 0x300) setsockopt$SO_ATTACH_FILTER(r5, 0x1, 0x1a, &(0x7f0000fbe000)={0x1, &(0x7f0000000100)=[{0x80000006}]}, 0x10) fsconfig$FSCONFIG_CMD_CREATE(r0, 0x6, 0x0, 0x0, 0x0) 4.428202936s ago: executing program 2 (id=2982): r0 = syz_usb_connect(0x0, 0x36, &(0x7f0000000040)={{0x12, 0x1, 0x0, 0x75, 0x1c, 0x1, 0x10, 0xfe6, 0x9800, 0xd19a, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x24, 0x1, 0x0, 0x0, 0x0, 0x0, [{{0x9, 0x4, 0x29, 0x2, 0x2, 0xb4, 0x8c, 0xbb, 0x0, [], [{{0x9, 0x5, 0x4, 0x2, 0x10, 0x0, 0xfa}}, {{0x9, 0x5, 0x82, 0x2, 0x40}}]}}]}}]}}, 0x0) r1 = socket(0x15, 0x5, 0x0) connect$unix(r1, &(0x7f0000000080)=@abs={0xa}, 0x6e) r2 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000c40), 0xffffffffffffffff) sendmsg$NL80211_CMD_SET_REKEY_OFFLOAD(r1, &(0x7f0000000d00)={&(0x7f0000000c00)={0x10, 0x0, 0x0, 0x2000}, 0xc, &(0x7f0000000cc0)={&(0x7f0000000c80)={0x40, r2, 0x802, 0x70bd28, 0x25dfdbff, {{}, {@void, @val={0xc, 0x99, {0x3, 0x48}}}}, [@NL80211_ATTR_REKEY_DATA={0x20, 0x7a, 0x0, 0x1, [@NL80211_REKEY_DATA_AKM={0x8, 0x4, 0x7}, @NL80211_REKEY_DATA_KEK={0x14, 0x1, @kek="e4b4d18785ae9146a8704cd423a46182"}]}]}, 0x40}, 0x1, 0x0, 0x0, 0xc004}, 0x8000) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, &(0x7f0000000580)={0x44, &(0x7f0000000340)={0x20, 0x24, 0x6, "24461d208426"}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) syz_usb_control_io$printer(r0, 0x0, 0x0) syz_usb_control_io$cdc_ecm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, &(0x7f0000000100)={0x14, &(0x7f0000000080)={0x40, 0x4, 0x6c, {0x6c, 0xd, "2c64bf910da3b6c7a01777e843c3c8f75ebf1fda1d69007b76d9b26d49b5c7adfa34954d72aaec058d333239b3fa17b070916e7f33fe532fe6c2b5ab48b6a622bfd5df6263b691a131bcf8f13d0462d8ab1f817f1a8c553f0675b425ab1dbbea818f2b53d68d45faad1d"}}, &(0x7f0000000000)={0x0, 0x3, 0x1a, {0x1a}}}, &(0x7f0000000400)={0x44, &(0x7f0000000140)={0x0, 0xf, 0x8e, "cd8c479d637e450d80e972ef03ea6f630b47457d15c2ab363603b9cf33ea1589345bbc0ac26dfe3b081437aa322ba098254467ecf3e60de794ea6cba8e3919975af102564bb1fccf5ab2d789c086d284ac74dab26a5ba0d78e63618aceec95a05a19a3d99e204d3acbc262f753caa487d263f57cc32f9d0ee2287f149e21412b9686f02382a5a217ecf1d9b338d4"}, &(0x7f0000000200)={0x0, 0xa, 0x1, 0xfc}, &(0x7f0000000240)={0x0, 0x8, 0x1, 0x7}, &(0x7f0000000280)={0x20, 0x80, 0x1c, {0xc14c, 0xff, 0x99, 0x9, 0x6, 0xe, 0x7, 0x8, 0x3, 0x7, 0x1000, 0xfffa}}, &(0x7f00000002c0)={0x20, 0x85, 0x4, 0x400}, &(0x7f0000000300)={0x20, 0x83, 0x2, 0x1}, &(0x7f0000000380)={0x20, 0x87, 0x2, 0x9}, &(0x7f00000003c0)={0x20, 0x89, 0x2}}) r3 = syz_usb_connect$cdc_ecm(0x6, 0x60, &(0x7f0000000480)={{0x12, 0x1, 0x201, 0x2, 0x0, 0x0, 0x8, 0x525, 0xa4a1, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x4e, 0x1, 0x1, 0x8, 0x0, 0xa, [{{0x9, 0x4, 0x0, 0x4, 0x28, 0x2, 0x6, 0x0, 0x2, {{0xa, 0x24, 0x6, 0x0, 0x0, "089bd4cf4a"}, {0x5, 0x24, 0x0, 0x7a0a}, {0xd, 0x24, 0xf, 0x1, 0x8000, 0x6, 0x1, 0xb2}, [@call_mgmt={0x5, 0x24, 0x1, 0x2, 0x3}]}, {[{{0x9, 0x5, 0x81, 0x3, 0x8, 0xff, 0x1, 0x3}}], {{0x9, 0x5, 0x82, 0x2, 0x3ff, 0x1, 0x5, 0x5}}, {{0x9, 0x5, 0x3, 0x2, 0x400, 0x9, 0x6, 0x5}}}}}]}}]}}, &(0x7f00000008c0)={0xa, &(0x7f0000000500)={0xa, 0x6, 0x310, 0x3a, 0xf5, 0x0, 0x40, 0x2}, 0x54, &(0x7f0000000600)={0x5, 0xf, 0x54, 0x6, [@ss_container_id={0x14, 0x10, 0x4, 0x4, "b7872a1e67dcdab9c02eec2f5d6fabb6"}, @ss_container_id={0x14, 0x10, 0x4, 0x8, "bec586bd1e839d391742c397c132429b"}, @wireless={0xb, 0x10, 0x1, 0x4, 0x12, 0x4, 0x7, 0xffff, 0x6}, @wireless={0xb, 0x10, 0x1, 0x2, 0x58, 0x7, 0x40, 0x2, 0xfa}, @ss_cap={0xa, 0x10, 0x3, 0x0, 0x8, 0x83, 0x2, 0x5}, @ext_cap={0x7, 0x10, 0x2, 0x0, 0x9, 0x2, 0x8}]}, 0x9, [{0x6, &(0x7f0000000540)=@string={0x6, 0x3, "fa88b0c2"}}, {0x4, &(0x7f0000000680)=@lang_id={0x4, 0x3, 0x404}}, {0x4, &(0x7f00000006c0)=@lang_id={0x4, 0x3, 0x870}}, {0x4, &(0x7f0000000700)=@lang_id={0x4, 0x3, 0x806}}, {0x4, &(0x7f0000000740)=@lang_id={0x4, 0x3, 0x40e}}, {0x5b, &(0x7f0000000780)=@string={0x5b, 0x3, "8237bcd377509d48ac1c50df07791ff95fe35aeec7c75d516e4dde87aac46c06a263a59a79a8c21faeb80c3cf62a7df6671a9a2fdc314e0e1a42ea817cd1ad20c5e2954325ee0b6541ee50004e0f1754db6f66a8be2b7ef782"}}, {0x23, &(0x7f0000000800)=@string={0x23, 0x3, "7369e2e72717d67ca1e4686e7aa439da46534aadebdbf14c68c0881ac41a1fa6e7"}}, {0x4, &(0x7f0000000840)=@lang_id={0x4, 0x3, 0xc09}}, {0x1e, &(0x7f0000000880)=@string={0x1e, 0x3, "38c1a334763a51d653ee2f188b593dd74b190558af7e4ab967c1f803"}}]}) syz_usb_control_io$cdc_ecm(r3, &(0x7f0000000a40)={0x14, &(0x7f0000000980)={0xbd24dedfac03de89, 0x11, 0x44, {0x44, 0x2, "126705f2c89beab750c042ee408c387e5c7b9847f8e60ae907d6c55a6501eb316c6bb90f98a8de4d5b3b32b299a5be400a484553ab60448af5160de4283ff748b28f"}}, &(0x7f0000000a00)={0x0, 0x3, 0x1a, {0x1a}}}, &(0x7f0000000bc0)={0x1c, &(0x7f0000000a80)={0x0, 0x31, 0x85, "b8afdc1bd05345dee05895778dc52b05daa1768b4cd6375e97ff490089ef2a86920382db21177d5713b630e54cdf7634a64d08b3d70e200c48f55a9014423174d4e39814be56732b4e947b5b1c13876135f9c0754bc656f291e30d70e1dda18dabf7f7f237ea6655553cb4d533b6fb38c6385a20b17cd3c0d3a92f5945bb86e1a8d492def0"}, &(0x7f0000000b40)={0x0, 0xa, 0x1, 0xdc}, &(0x7f0000000b80)={0x0, 0x8, 0x1, 0x10}}) 4.234580758s ago: executing program 4 (id=2984): r0 = add_key(&(0x7f0000000040)='cifs.spnego\x00', &(0x7f0000000140)={'syz', 0x2}, &(0x7f0000000180)="1214753f8060c9e4608b01d54971180b2680694070a8361174981c16a35e5d44362da12d16b0cb297e88c83bcf1ddaf838d40eeaa16afacc748f63fb354bee0691ae1fafe8ebffbfa83c80afa869a82e24717f1becb5c1b519e2a905b9fdd288a22ac1bfee888086ca830285be45d94f95f1ae759f7cad4118b9df8b79e71a7678604204928722bc6b9ea2efca3ba31c6f188231061ce966f80dfc47", 0x9c, 0xfffffffffffffffb) keyctl$revoke(0x3, r0) r1 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file1\x00', 0x8042, 0x0) r2 = socket$netlink(0x10, 0x3, 0x0) sendmsg$netlink(r2, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000000)=[{&(0x7f0000000580)=ANY=[@ANYBLOB="340000002e0001002ab77d343a634091ed700000", @ANYRES32, @ANYBLOB="1c0000801800318011001d"], 0x34}], 0x1}, 0x0) fcntl$setlease(r1, 0x400, 0x1) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) close(r3) r4 = socket$inet6_mptcp(0xa, 0x1, 0x106) setsockopt$sock_int(r4, 0x1, 0xf, &(0x7f0000000040)=0xcc, 0x4) listen(r4, 0x0) fcntl$getflags(r1, 0x401) mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) r5 = creat(&(0x7f00000000c0)='./file0\x00', 0xd4) r6 = bpf$MAP_CREATE(0x0, &(0x7f0000000300)=@bloom_filter={0x1e, 0x4, 0x100, 0x5, 0x1002, r5, 0x80002, '\x00', 0x0, r5, 0x3, 0x2, 0x3, 0x8, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018120000", @ANYRES32=r6, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7040000f6000000850000004300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) setsockopt$inet6_tcp_int(0xffffffffffffffff, 0x6, 0x13, 0x0, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0x19, 0x4, 0x4, 0x5, 0x0, 0xffffffffffffffff, 0x80000000, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x17, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=0x0, @ANYBLOB="0000000000000000b70800000000e7057b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1d, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r7 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r7, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000740)=ANY=[@ANYBLOB="140000001000010000000000000100000000000a20000000000a01010000000000000000010000000900010073797a300000000068000000090a010400000000000000000100000008000a4000000000200011800e000100636f6e6e6c696d69740000000c00028008000140000000000900010073797a30000000000900020073797a3200000000080005400000001f0c000980080001400037"], 0xb0}}, 0x0) 3.771788714s ago: executing program 1 (id=2985): bind$vsock_stream(0xffffffffffffffff, &(0x7f0000000040)={0x28, 0x0, 0x2710, @local}, 0x10) connect$vsock_stream(0xffffffffffffffff, &(0x7f0000000640)={0x28, 0x0, 0x2710}, 0x10) socket(0x2, 0x80805, 0x0) r0 = userfaultfd(0x801) ioctl$UFFDIO_API(r0, 0xc018aa3f, &(0x7f00000001c0)={0xaa, 0x1c0}) ioctl$UFFDIO_REGISTER(r0, 0xc020aa00, &(0x7f0000000080)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x2}) ioctl$UFFDIO_COPY(r0, 0xc028aa03, &(0x7f0000000000)={&(0x7f00002b9000/0x400000)=nil, &(0x7f0000779000/0x1000)=nil, 0x400000, 0x3, 0x2}) madvise(&(0x7f0000000000/0x600000)=nil, 0x600000, 0x4) r1 = socket$xdp(0x2c, 0x3, 0x0) setsockopt$XDP_UMEM_REG(r1, 0x11b, 0x4, &(0x7f0000000040)={0x0, 0x108000, 0x800, 0x80000000, 0x2}, 0x20) syz_usb_connect$cdc_ncm(0x0, 0x0, 0x0, 0x0) syz_usb_connect$uac1(0x0, 0xa5, &(0x7f0000000600)={{0x12, 0x1, 0x0, 0x0, 0x0, 0x0, 0x10, 0x1d6b, 0x101, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x93, 0x3, 0x1, 0x0, 0x0, 0x0, {{0x9, 0x4, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, {{0xa, 0x24, 0x1, 0x8000}, [@feature_unit={0x13, 0x24, 0x6, 0x0, 0x0, 0x6, [0x0, 0x0, 0x0, 0x0, 0x0, 0x0]}, @output_terminal={0x9}, @selector_unit={0x9, 0x24, 0x5, 0x0, 0x0, "f8431cfd"}, @output_terminal={0x9, 0x24, 0x3, 0x0, 0x305, 0x0, 0x4, 0x3}, @selector_unit={0x6, 0x24, 0x5, 0x4, 0x0, "dd"}]}}, {}, {0x9, 0x4, 0x1, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {}, {{0x9, 0x5, 0x1, 0x9, 0x0, 0x0, 0x0, 0x0, {0x7}}}}, {}, {0x9, 0x4, 0x2, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {}, {{0x9, 0x5, 0x82, 0x9, 0x0, 0x0, 0x0, 0x0, {0x7}}}}}}}]}}, 0x0) write$uinput_user_dev(0xffffffffffffffff, 0x0, 0x0) syz_clone(0x2ba90480, 0x0, 0x0, 0x0, 0x0, 0x0) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) ioctl$sock_SIOCGPGRP(0xffffffffffffffff, 0x8904, 0x0) 3.364208772s ago: executing program 0 (id=2986): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = openat$sysfs(0xffffffffffffff9c, &(0x7f0000000100)='/sys/kernel/debug', 0x0, 0x0) getsockopt$inet_sctp_SCTP_PEER_ADDR_PARAMS(r1, 0x84, 0x9, &(0x7f00000001c0)={0x0, @in={{0x2, 0x4e24, @initdev={0xac, 0x1e, 0x0, 0x0}}}, 0x6, 0x9d, 0xfffffffb, 0xfff, 0x2, 0x1, 0x7}, &(0x7f0000000280)=0x9c) setsockopt$inet_sctp_SCTP_ASSOCINFO(r1, 0x84, 0x1, &(0x7f00000002c0)={r2, 0x7, 0x1, 0x8, 0x4, 0x6}, 0x14) fcntl$notify(r1, 0x402, 0x8) sendmsg$nl_generic(r0, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000001ac0)={&(0x7f0000001b00)={0x14, 0x2c, 0x1, 0x70bd26, 0x25ffdbfc, {0x4}}, 0x14}, 0x1, 0x0, 0x0, 0x200480cd}, 0x20008000) (async) r3 = socket$nl_generic(0x10, 0x3, 0x10) r4 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000080), 0xffffffffffffffff) (async) ioctl$sock_SIOCGIFINDEX_80211(r3, 0x8933, &(0x7f00000000c0)={'wlan0\x00', 0x0}) sendmsg$NL80211_CMD_SET_INTERFACE(r3, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000180)={0x24, r4, 0x5, 0x0, 0x0, {{}, {@val={0x8, 0x3, r5}, @void}}, [@NL80211_ATTR_IFTYPE={0x8, 0x5, 0x3}]}, 0x24}}, 0x0) (async) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000240), 0xffffffffffffffff) (async) ioctl$sock_SIOCGIFINDEX_80211(r6, 0x8933, &(0x7f0000000100)={'wlan1\x00', 0x0}) r9 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL80211_CMD_REGISTER_FRAME(r9, &(0x7f0000000340)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000400)={0x94, r7, 0x1, 0x0, 0x0, {{}, {@val={0x8, 0x3, r8}, @void}}, [@NL80211_ATTR_FRAME_MATCH={0x4}, @NL80211_ATTR_FRAME_MATCH={0x73, 0x5b, "e1d57afe938d650c30f1c8fccecc7aaa6eee0de884000b9e550c62191bb6b5c0c6fcafce64c107c81f789caab48e9af42897f40161295dd81c74ed11c3612a0f5a2e77c84f43afc8fa20fc2a7103fb6a26fc80ce982550bb43cdbd9a5e1927435adbebf2530ee3583d84a67dd091c7"}]}, 0x94}}, 0x0) r10 = socket$nl_generic(0x10, 0x3, 0x10) (async) r11 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000040), 0xffffffffffffffff) (async) r12 = openat$fb0(0xffffffffffffff9c, &(0x7f0000000200), 0x20000, 0x0) ioctl$FBIOPAN_DISPLAY(r12, 0x4606, &(0x7f0000000580)={0x550, 0x80, 0x550, 0x280, 0x0, 0x4, 0x18, 0x0, {0x8}, {0x1ff}, {0x10000, 0x9}, {0xd46, 0xffffffff}, 0x2, 0x1, 0x401, 0x6, 0x1, 0x1, 0x8, 0x5e, 0x3, 0x5, 0xffff7fff, 0x6, 0x0, 0x100, 0x0, 0x9}) (async) ioctl$sock_SIOCGIFINDEX_80211(r10, 0x8933, &(0x7f0000000740)={'wlan1\x00', 0x0}) (async) r14 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL80211_CMD_REGISTER_FRAME(r14, &(0x7f00000005c0)={0x0, 0x0, &(0x7f0000000580)={&(0x7f0000000380)={0x20, r11, 0x1, 0x0, 0x0, {{}, {@val={0x8, 0x3, r13}, @void}}, [@NL80211_ATTR_FRAME_MATCH={0x4}]}, 0x20}}, 0x0) 3.305647089s ago: executing program 0 (id=2987): r0 = socket$nl_route(0x10, 0x3, 0x0) r1 = socket(0x10, 0x803, 0x0) sendmsg$nl_route(r1, &(0x7f0000000380)={0x0, 0x4076cbba9945d516, &(0x7f0000000340)={0x0, 0x14}}, 0x0) getsockname$packet(r1, &(0x7f0000000140)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000200)=0x28a) r3 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r3, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000500)={&(0x7f00000003c0)=ANY=[@ANYBLOB="34000000100039042cbd70000000000000000000", @ANYRES32=r2, @ANYBLOB="059800000020000014001280080001006772650008000280"], 0x34}}, 0x0) sendmsg$nl_route(r0, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f00000000c0)=@newlink={0x44, 0x10, 0x439, 0x70bd2b, 0x25dfdbfd, {0x0, 0x0, 0x0, r2}, [@IFLA_LINKINFO={0x24, 0x12, 0x0, 0x1, @gre={{0x8}, {0x18, 0x2, 0x0, 0x1, [@IFLA_GRE_FWMARK={0x8, 0x14, 0x2}, @IFLA_GRE_ENCAP_SPORT={0x6, 0x10, 0x4e22}, @IFLA_GRE_COLLECT_METADATA={0x4}]}}}]}, 0x44}}, 0x0) 3.177150077s ago: executing program 0 (id=2988): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000000)={0x26, 'skcipher\x00', 0x0, 0x0, 'ecb(serpent)\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, 0x0, 0x0) r1 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$inet6(r1, &(0x7f0000000900)={0x0, 0x0, &(0x7f0000000880)=[{&(0x7f0000000080)="abf63fa63be2057e6eb311864b862f44687c12bc9818a7859baa745aff3f92ef76bdf77e7b5d02d91fc1523771c95efb", 0x30}, {&(0x7f0000000480)="52d2ea933609eb07c6d2847054a95df72d8e98717a68c12027034ea2cfe9dfff638298030651a2552405127ab1f7367c6befdcf20f700dcb39e7b9df0edc9269ab3c24d49de362841a9cd7af799cd57f26705d6d6f840b720f5c1fec2275e81fe37b609b8a0309a9918d2621e4ff4084240a16e4d47d78aa427b547d7965db", 0x7f}, {&(0x7f0000000940)="4da1537e1aa8ee68c744c5a486e7b2393712688bdffa4e960c7629be4054a649249ce75863e4b6189990e87e8ade0e7abd7c19e524fb3270ee17563373cb5cef0600000062298a6e00"/83, 0x53}], 0x3}, 0x91) recvmsg$unix(r1, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)=[{&(0x7f0000001f00)=""/4096, 0x1000}], 0x1}, 0x12060) 3.040555341s ago: executing program 0 (id=2989): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000000)=ANY=[@ANYBLOB="050000001e0000004000000040"], 0x48) bpf$MAP_UPDATE_BATCH(0x1a, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000080), &(0x7f0000000180), 0x1003, r0}, 0x38) bpf$MAP_LOOKUP_ELEM(0x15, &(0x7f0000000b80)={r0, &(0x7f0000000a80), &(0x7f0000000b40)=""/31}, 0x20) r1 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt(r1, 0x84, 0x81, &(0x7f0000000280)="1a00000002000000", 0x8) setsockopt$inet_sctp6_SCTP_AUTH_CHUNK(r1, 0x84, 0x15, &(0x7f00000000c0), 0x1) setsockopt$inet_sctp_SCTP_SOCKOPT_BINDX_ADD(r1, 0x84, 0x64, &(0x7f0000000000)=[@in6={0xa, 0x4e23, 0x401, @loopback}], 0x1c) setsockopt$inet_sctp6_SCTP_AUTH_CHUNK(r1, 0x84, 0x15, &(0x7f0000000040)={0x5}, 0x1) unshare(0x18000080) r2 = socket$tipc(0x1e, 0x5, 0x0) setsockopt$TIPC_GROUP_JOIN(r2, 0x10f, 0x87, &(0x7f0000000100)={0x43, 0x0, 0x3, 0x3}, 0x10) r3 = socket$tipc(0x1e, 0x5, 0x0) setsockopt$TIPC_GROUP_JOIN(r3, 0x10f, 0x87, &(0x7f0000000100)={0x43, 0x0, 0x3, 0x3}, 0x10) sendmsg$tipc(r3, &(0x7f0000000280)={&(0x7f0000000040), 0x10, 0x0}, 0x0) sendto$inet6(r1, &(0x7f0000000780)="d2", 0x1, 0x400c0d4, &(0x7f0000000140)={0xa, 0x4e23, 0x0, @loopback, 0xfffffffc}, 0x1c) 2.804188939s ago: executing program 0 (id=2990): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000740)=ANY=[@ANYBLOB="140000001000010000000000000100000000000a20000000000a01010000000000000000010000000900010073797a300000000068000000090a010400000000000000000100000008000a4000000000200011800e000100636f6e6e6c696d69740000000c00028008000140000000000900010073797a30000000000900020073797a3200000000080005400000001f0c0009800800014000"], 0xb0}}, 0x0) 2.729164829s ago: executing program 0 (id=2991): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) r2 = openat$vicodec1(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) r3 = socket$inet(0x2, 0x3, 0x8) setsockopt$inet_int(r3, 0x0, 0x5, &(0x7f0000000080)=0x7, 0x4) r4 = socket$inet(0x2, 0x3, 0x6) r5 = dup3(r3, r4, 0x0) setsockopt$inet_int(r5, 0x0, 0x5, &(0x7f0000000080)=0x7, 0x4) write$binfmt_aout(r2, 0x0, 0x6b1) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) connect$inet6(0xffffffffffffffff, 0x0, 0x0) pread64(0xffffffffffffffff, 0x0, 0x0, 0xc2a) socket$netlink(0x10, 0x3, 0x0) syz_usb_connect(0x0, 0x36, &(0x7f0000000040)=ANY=[@ANYBLOB="130100002add1e20ef050a023691010203010902240001000000000904000002ea1998000905a6a700000000000905", @ANYRES32], 0x0) r6 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000100), 0x1c3902, 0x0) sendfile(r6, r6, 0x0, 0x200000) 2.518638372s ago: executing program 4 (id=2992): r0 = socket$nl_route(0x10, 0x3, 0x0) ioctl$ifreq_SIOCGIFINDEX_vcan(r0, 0x8933, &(0x7f0000000380)={'vcan0\x00', 0x0}) r2 = socket$can_j1939(0x1d, 0x2, 0x7) bind$can_j1939(r2, &(0x7f0000000080)={0x1d, r1, 0x0, {0x0, 0x0, 0x4}}, 0x18) sendmsg$can_j1939(r2, &(0x7f00000001c0)={&(0x7f0000000040), 0x18, &(0x7f0000000180)={0x0}, 0x1, 0xee00}, 0xee) 2.178393323s ago: executing program 4 (id=2993): r0 = socket$inet_icmp_raw(0x2, 0x3, 0x1) sendmsg$NFT_BATCH(0xffffffffffffffff, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f00000004c0)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a01080000000000000000010000000900010073797a300000000078000000090a010400000000000000000100000008000a40000000000900020073797a30000000000900010073797a300000000008000540000000213c0011800a0001006c696d6974"], 0xc0}}, 0x0) setsockopt$inet_int(r0, 0x0, 0xb, &(0x7f0000000040)=0x3, 0x4) setsockopt$IP_VS_SO_SET_STARTDAEMON(r0, 0x0, 0x1a, &(0x7f0000000240)={0x1, 'veth0_to_team\x00'}, 0x18) syz_emit_ethernet(0xbe, &(0x7f0000000480)={@broadcast, @empty, @void, {@ipv4={0x800, @icmp={{0x5, 0x4, 0x0, 0x0, 0xb0, 0x0, 0x0, 0x0, 0x1, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}, @local}, @time_exceeded={0x3, 0x0, 0x0, 0x3, 0x24, 0x0, {0x25, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x0, @local, @dev, {[@cipso={0x86, 0x71, 0x0, [{0x0, 0xc, "e256b28c59881681fb52"}, {0x0, 0x9, "020007651442eb"}, {0x5, 0xe, "7434954373561de584b703c8"}, {0x0, 0x9, "e706d30bd224f8"}, {0x0, 0x7, "cfa11cab1a"}, {0x2, 0x10, "8475be675de6a70a05a0dc91e5c6"}, {0x0, 0xa, "6580a5e97612fe86"}, {0x0, 0x12, "73bc2300ad9d19a30000050000000000"}, {0x0, 0xc, "c8f46976e79e56c7a95e"}]}, @cipso={0x86, 0xc, 0x0, [{0x0, 0x6, "7f36c525"}]}]}}}}}}}, 0x0) 1.968848855s ago: executing program 4 (id=2994): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000000)={0x26, 'skcipher\x00', 0x0, 0x0, 'ecb(serpent)\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, 0x0, 0x0) r1 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$alg(r1, &(0x7f0000000200)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000300)=[@op={0x18, 0x117, 0x3, 0x1}], 0x18}, 0x0) openat$fuse(0xffffffffffffff9c, &(0x7f0000000040), 0x42, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)) socket$nl_route(0x10, 0x3, 0x0) syz_io_uring_setup(0x4b6, &(0x7f0000000100)={0x0, 0xde23, 0x1, 0x0, 0x1a9}, 0x0, 0x0) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000140)='cpuset.effective_mems\x00', 0x275a, 0x0) socket$inet_mptcp(0x2, 0x1, 0x106) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = socket(0x10, 0x2, 0x0) sendmsg$nl_generic(r2, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000280)=ANY=[@ANYBLOB="1c00000015000103000000000000e7ff0b00000008000100", @ANYRES8=r3], 0x1c}, 0x1, 0x0, 0x0, 0xc001}, 0x4000000) r4 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) ioctl$TUNSETIFF(r4, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) r5 = socket(0x10, 0x803, 0x0) r6 = socket$unix(0x1, 0x1, 0x0) r7 = socket(0x1e, 0x4, 0x0) setsockopt$packet_tx_ring(r7, 0x10f, 0x87, &(0x7f0000000080)=@req3={0x54c, 0x4, 0x3, 0x3, 0xc, 0x6, 0x7}, 0x1c) recvfrom(r7, &(0x7f0000000040)=""/18, 0x12, 0x6667b9fe4a5fca3, 0x0, 0x0) ioctl$sock_SIOCGIFINDEX(r6, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r5, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2b, 0xffffffff, {0x0, 0x0, 0x0, r8, {0x0, 0x7}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8}}]}, 0x38}}, 0x0) sendmsg$nl_route_sched(r5, &(0x7f0000006040)={0x0, 0x0, &(0x7f0000000300)={&(0x7f0000000140)=@newtfilter={0x5c, 0x2c, 0xd27, 0x30bd29, 0x2, {0x0, 0x0, 0x0, r8, {0x0, 0xc}, {}, {0x7, 0xa}}, [@filter_kind_options=@f_basic={{0xa}, {0x2c, 0x2, [@TCA_BASIC_EMATCHES={0x28, 0x2, 0x0, 0x1, [@TCA_EMATCH_TREE_HDR={0x8, 0x1, {0x1}}, @TCA_EMATCH_TREE_LIST={0x1c, 0x2, 0x0, 0x1, [@TCF_EM_META={0x18, 0x1, 0x0, 0x0, {{0x7, 0x4, 0x4}, [@TCA_EM_META_HDR={0x4, 0x1, {{0x4, 0x81, 0x1}, {0x2, 0xa5, 0x2}}}]}}]}]}]}}]}, 0x5c}}, 0x0) sendmsg$inet6(r1, &(0x7f0000000900)={0x0, 0x0, &(0x7f0000000880)=[{&(0x7f0000000080)="abf63fa63be2057e6eb311864b862f44687c12bc9818a7859baa745aff3f92ef76bdf77e7b5d02d91fc1523771c95efb", 0x30}, {&(0x7f0000000940)="4da1537e1aa8ee68c744c5a486e7b2393712688bdffa4e960c7629be4054a649249ce75863e4b6189990e87e8ade0e7abd7c19e524fb3270ee17563373cb5cef0600000062298a6e0000000000000000", 0x50}], 0x2}, 0x91) recvmsg$unix(r1, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)=[{&(0x7f0000001f00)=""/4096, 0x1000}], 0x1}, 0x12060) 1.659581305s ago: executing program 4 (id=2995): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000580)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101000000005e1affd5020000000900010073797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a30000000000900030073797a320000000014000000110001"], 0x7c}}, 0x0) r1 = syz_clone(0x400, 0x0, 0x0, 0x0, 0x0, 0x0) wait4(r1, &(0x7f0000000000), 0x80000000, 0x0) process_vm_writev(r1, 0x0, 0x0, &(0x7f00000002c0)=[{0x0}], 0x1, 0x0) sendmsg$NFT_BATCH(r0, &(0x7f000000c2c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000240)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101804bc9555e1affd5020000000900010001797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a300000000009000300737975320000000014000000110001"], 0x7c}, 0x1, 0x0, 0x0, 0x24040010}, 0x0) close(r0) r2 = socket$alg(0x26, 0x5, 0x0) bind$alg(r2, &(0x7f0000000000)={0x26, 'skcipher\x00', 0x0, 0x0, 'ecb(serpent)\x00'}, 0x58) r3 = openat$ttyS3(0xffffffffffffff9c, &(0x7f0000000280), 0x0, 0x0) ioctl$TIOCSETD(r3, 0x5423, &(0x7f00000000c0)=0xe) ioctl$TCFLSH(r3, 0x540b, 0xfffffffffffffffe) setsockopt$ALG_SET_KEY(r2, 0x117, 0x1, 0x0, 0x0) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f0000000080)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) r4 = syz_open_dev$loop(&(0x7f0000000140), 0x75f, 0xa382) sendfile(r4, r4, 0x0, 0x24002de8) sendmsg$alg(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000300)=[@op={0x18, 0x117, 0x3, 0x1}], 0x18}, 0x0) sendmsg$inet6(0xffffffffffffffff, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000240), 0x6}, 0xc1) recvmsg$unix(0xffffffffffffffff, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)=[{&(0x7f0000001f00)=""/4096, 0x1000}], 0x1}, 0x12060) 1.348065249s ago: executing program 2 (id=2996): arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000000)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000040)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000080)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f00000000c0)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000100)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000140)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000180)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f00000001c0)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000200)) r0 = socket$inet6_sctp(0xa, 0x1, 0x84) newfstatat(0xffffffffffffff9c, &(0x7f0000000240)='./file0\x00', &(0x7f0000000280)={0x0, 0x0, 0x0, 0x0, 0x0}, 0x4000) setsockopt$inet6_IPV6_IPSEC_POLICY(r0, 0x29, 0x22, &(0x7f0000000300)={{{@in6=@mcast2, @in6=@loopback, 0x4e22, 0x0, 0x4e23, 0x14, 0x0, 0x20, 0x20, 0x67, 0x0, r1}, {0xffffffffffffffff, 0xfffffffffffffeff, 0x9, 0x7, 0xab8, 0x4, 0x100000000, 0xf}, {0xfffffffffffffffc, 0x8, 0x4, 0x5}, 0x2, 0x0, 0x1, 0x1, 0x2}, {{@in6=@loopback, 0x4d5}, 0xa, @in6=@private0={0xfc, 0x0, '\x00', 0x1}, 0x0, 0x756d32857b3a6404, 0x3, 0x7, 0x2, 0xa04, 0xd}}, 0xe8) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000400)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000440)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000000480)) syz_usb_connect(0x5, 0x9a5, &(0x7f00000004c0)={{0x12, 0x1, 0x310, 0xb3, 0xde, 0x30, 0x10, 0x499, 0x1043, 0x4334, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x993, 0x3, 0x5, 0x1, 0x30, 0xf6, [{{0x9, 0x4, 0x21, 0x8, 0x4, 0x32, 0x3a, 0x66, 0x1, [@uac_as={[@as_header={0x7, 0x24, 0x1, 0x4c, 0x4, 0x1001}, @as_header={0x7, 0x24, 0x1, 0x0, 0x0, 0x1002}]}], [{{0x9, 0x5, 0x6, 0x0, 0x400, 0xf1, 0xd, 0xc, [@generic={0x57, 0x0, "a6d2566b7af490a7f8572f47e818a9a029b086ff9a30d8643f0925e91545dc491e5876d0467de75bcdd20d7d21b30f7451ef09b550bea36a13abe5e4758f4522411e423f03a70e13107e37f0ec41230c69bfcec9b4"}]}}, {{0x9, 0x5, 0x7, 0x0, 0x903a7db9dce05459, 0x1, 0x98, 0x1, [@generic={0xe7, 0x9, "8f80e0786a8e0ba90a697571c13a981a495198818791eaf76f36370f3bb907dec0ca74914970ba9fdf0bbadff3cb73be527e54d57b01a804ebcb2fa711b6c68b2f09def0eda7908e955f240ce185fa6f624bdf55eaf1ff01abffc7503e536d3dd5c84f05a671adce6b608aeaba847aa89803d1b8dda262cd0788d76646cd0b0415070fc44dc0299f4be1c05f1060731e7d6c1921cbb2d376930a8014db9d34bec92c8e7cbc23555dd1fea6a5a44c25dcee7259aa10c9420874e6f4f6abc6acb3bc6fa8ddd55257542ea9163eae552459a10f7a4ae701069b07933c007a4c9bfba2c7433aff"}]}}, {{0x9, 0x5, 0x2, 0xc, 0x410, 0x0, 0x8, 0x0, [@uac_iso={0x7, 0x25, 0x1, 0xc0, 0xef, 0x4}, @uac_iso={0x7, 0x25, 0x1, 0x0, 0x6, 0x8}]}}, {{0x9, 0x5, 0x9, 0x8, 0x20, 0x2, 0x81, 0x3, [@generic={0x9, 0x10, "fda3a291c15e49"}]}}]}}, {{0x9, 0x4, 0xb4, 0x89, 0xa, 0xf5, 0x92, 0x77, 0x2, [@generic={0x58, 0xf, "23b4205fcaac019b042f406ca8c1358977e180c99603dc1fda94474d0f747b88e4e9bcc86407122cbfd5126363aaf937dbfb65fdc522daffa0af3bcaf49855a56a9dad8a02c8faaa76a677d1da0abaa7fdb17bfced0d"}], [{{0x9, 0x5, 0xc, 0x2, 0x40, 0xff, 0x3, 0x5}}, {{0x9, 0x5, 0x80, 0x2, 0x400, 0xfe, 0x4, 0x9, [@uac_iso={0x7, 0x25, 0x1, 0x1, 0x7, 0x9}]}}, {{0x9, 0x5, 0x3, 0x8, 0x8, 0x45, 0x7, 0x0, [@generic={0x78, 0x30, "3e7e3925b1a547980ffb2c69aaf89f84d63a250aa447860262bcf9ed01cc22000582625c36f0921317f999a535bfdd48743fa8b4cd7ac1d7ed3ec4a7bfc6b374c61753bdfe4fb8549129998e657989472ff9d92d5f1e80f4dc2085940e9d4dc7e8c5b9b10bcd0b79c0fa2a359d4d1e2e73e074fe37b5"}]}}, {{0x9, 0x5, 0xa, 0xc, 0x200, 0x8, 0xde, 0x3, [@generic={0x4f, 0xc, "834dc2eec645af2da66f8376b2ae78762251e7e98daafe26aa6e64e9af8b51c9e299f741afa7874ec8302201b35342d4374b5eb34a64151b1f40c0c97081d4b3afece8a0a865fe0377c8126dae"}, @generic={0xb1, 0xb, "30a021cefa485e0054ebfdcb67ce27ab3a79e61e00a9e27fb2fac0d0bb20264f68527051ddc1092eaace797c17430958667294ef9d18f2a2821bc1d930725574910c184eca310573b12c5711319930d28ddf1490e365d7841c2da6e51a81cd64241e6be7819b08540a76915e206caeb7aa24e905a02cd096457f93e9427b559bf16a7a8717fbad2b64335a750a1e1a4e9e84a95919440dfadc9d195cc7dad131c78914c9df6f6a4fea8c538a2e2ff9"}]}}, {{0x9, 0x5, 0x1, 0x0, 0x58, 0xe3, 0x7, 0xfc}}, {{0x9, 0x5, 0x2, 0x4, 0x10, 0x8, 0x1, 0x5}}, {{0x9, 0x5, 0xf, 0x10, 0x3ff, 0x1, 0x6, 0x6a}}, {{0x9, 0x5, 0xc, 0x10, 0x200, 0x7, 0x1, 0x6b, [@uac_iso={0x7, 0x25, 0x1, 0x80, 0x8e, 0xa11f}, @uac_iso={0x7, 0x25, 0x1, 0x81, 0x4, 0x400}]}}, {{0x9, 0x5, 0x3, 0x3, 0x10, 0x7f, 0x8, 0xe6}}, {{0x9, 0x5, 0xe, 0x3, 0x200, 0x81, 0xf4}}]}}, {{0x9, 0x4, 0xb, 0xc, 0x10, 0xc2, 0x84, 0x84, 0x8, [@cdc_ncm={{0x6, 0x24, 0x6, 0x0, 0x1, "8e"}, {0x5, 0x24, 0x0, 0x298a}, {0xd, 0x24, 0xf, 0x1, 0x401, 0x2, 0x4, 0x4}, {0x6, 0x24, 0x1a, 0x4, 0x11}, [@country_functional={0xe, 0x24, 0x7, 0x5, 0x4, [0x0, 0xfa37, 0xa, 0x8000]}, @mbim={0xc, 0x24, 0x1b, 0x24e, 0xa9a6, 0xfc, 0x9, 0xe4c1, 0xbc}, @obex={0x5, 0x24, 0x15, 0x1}, @dmm={0x7, 0x24, 0x14, 0x7, 0x9}]}], [{{0x9, 0x5, 0x5, 0x1, 0x400, 0x80, 0x81, 0x7, [@uac_iso={0x7, 0x25, 0x1, 0x80, 0x9, 0x449}, @generic={0xd5, 0x8, "e4cc6be9bef27910e38b16d29f0f37118e91b578ab12f43552a2558d6fdd82b93e127073a423d3e70d9d8a36eebbdba9f440832f61b8c19707c37b3fed9b6ffd99db9c8942d66e10c4fd1822128fff7c42e9f1b26364c75e6dd08332357272464e9e5f63657f745c6a75f97a0d6ae362e53f0a9c68cc9bfa45a2674337a450a3a24021714400ff133dd058b2e91bd89c13ea118f7e0cc8723923f26bff7233baa07e9f86b6adfd2098c635c0284dfec6c2efe1ebff622e5783067151ba57c6a0436dc3c6b4ef1c3d3d18bbf8c1c19053c587ef"}]}}, {{0x9, 0x5, 0x3, 0x0, 0x400, 0x65, 0x5}}, {{0x9, 0x5, 0x1, 0xa, 0x8, 0xf, 0x6, 0x9, [@generic={0x51, 0xe, "3b177d68bea8c75f2ec8c49d93799cde95039dfe9a7fd1af1886f73324cac9d92f4593dfb5a04d5aef4074e6fc4a06c9f2b114bd4820a8e4521017a7e3a2678968fd6be252429454bbf560855071e7"}, @generic={0xb9, 0x10, "48af741f441d48f27c86ecce708395aa0f36a25901d363aba103a4fb6d9ea3e34f725e26a743b540cd4adbf42aa22f0a6e5cde90a261e3d37f265423635abf35f472eba282cd540cba49b7e9356ced33ffe1ad2293620abb2c52daec73162e196caee8df9b1464bd7496fba9328e7de76efb784b051edf5f97546aa53420a2034ad1d7f25cd8d2498a2a28a8008676a049ec5bd60d6e602bfecfe7c32d3c63bf5073a5aafd6b6f409bb14980c3f3ea58474163d5007e8b"}]}}, {{0x9, 0x5, 0x5, 0x0, 0x8, 0x3, 0xd, 0x1, [@generic={0x93, 0xb, "6734a69f38547711863545be8f1e5f95e12832de9b5e62f3a2bdb64176c17a8cfd98cbeda648f14702dbdde0c4bb90ab8dd0ce76111b9681bcce5437ae5730e10ff4b3f763d1cdaa1c7d13514610013dd70927e5babd832224c066c8cfcdc71edd1c54936e35ba4c6026941845f26da3c2c3be25b469ce55177c4762779dab9c28400856ff9adcf2c5fba6415f7cf57d2d"}, @generic={0xd8, 0x11, "f3c74dd84c330e93431dfbf4366eb16ff78adfd2cb0f0b23d3a658b047f26fb99199fb9689f1ea97e17276037744dfdc7fc01a82c56f2b31f00217ae6cb1e3c2b96431022c040f08b3625306d8a400413f6d54630c7c324cdb9c46c8ba87e28230dc8ae8876892b32fef609791885111aaf0953ca37c352b31f4843b515b99eb064650cf178a3729b0da63d7ee1a5081fbd3447d8d3ee24aa6602b1b6f0d8eda7c78bb76c8598f450da17e8e9712caa587982d67f4ea0f96af410ee6a446b3a66783dc43f725be86f8b20c37cbd42a06c627ef31cd39"}]}}, {{0x9, 0x5, 0x1, 0x10, 0x200, 0x81, 0x74, 0xef}}, {{0x9, 0x5, 0xa, 0x1, 0x8, 0x8, 0x0, 0xc, [@uac_iso={0x7, 0x25, 0x1, 0x83, 0xa4}, @uac_iso={0x7, 0x25, 0x1, 0x81, 0x81, 0x19a0}]}}, {{0x9, 0x5, 0x4, 0x1b, 0x20, 0x4, 0x7, 0x5, [@generic={0x2, 0x1}]}}, {{0x9, 0x5, 0xb, 0x4, 0x10, 0xfc, 0x7f, 0xc7}}, {{0x9, 0x5, 0x1, 0x10, 0x200, 0x0, 0x1, 0x56, [@generic={0x24, 0xf, "cde8eb2512fba38d07e7b8d64d6a99bf77e7bc089db1ab5936423b0d57f240ab981b"}, @uac_iso={0x7, 0x25, 0x1, 0x1, 0x7}]}}, {{0x9, 0x5, 0x0, 0x8, 0x20, 0xa2, 0x30, 0x0, [@uac_iso={0x7, 0x25, 0x1, 0x103, 0xf9, 0x7}]}}, {{0x9, 0x5, 0xd, 0x10, 0x20, 0x4, 0x9, 0xd, [@generic={0x16, 0xc, "b7dad585f9478f2d0a0f667654500ff0a5fbc74b"}]}}, {{0x9, 0x5, 0x5, 0x0, 0x400, 0xf8, 0x6, 0x0, [@uac_iso={0x7, 0x25, 0x1, 0x81, 0x5, 0x7d}, @generic={0x81, 0x23, "309ce1bb8a9704b18ee16a0290686a36a645e91ca9f7d996168339c18accbdf6a1d32f3cf52a85dbb7b8c21bad3c84ea4072ba01852bf08ea4dda26628c600cf86159335299be110a3083e4c985a343550cc7af5fe110629db2952e19bf4310df478deb6bee57e04c7471f50eefe6992a07c51bf5fd09a09423d2aafa61f58"}]}}, {{0x9, 0x5, 0x80, 0x0, 0x10, 0x0, 0x0, 0x40}}, {{0x9, 0x5, 0x5, 0x0, 0x40, 0x0, 0x1, 0x6f, [@generic={0x60, 0x1, "cd43e56cb30697c02a40b88e94112b16804c7514a8945e63cc514d60fcf7844a69152c4f6df9b666b692f7a5e46d36fef7bce688435446e43cc7259c5eb58f1ef25a26f84209987cf427456f6ffbe2bcfcaa851548709bc76dcab8b1a350"}]}}, {{0x9, 0x5, 0x8, 0x0, 0x8, 0x8, 0x5, 0x2, [@generic={0x3d, 0xd, "ff9fb84ed879c72636a47a4058f7f735746cd3b7b7a3d04876938a4502152e7cefcf2fd739ce525ffc586d1879cc43f8aafef6e09ef1b1617386ec"}]}}, {{0x9, 0x5, 0x5, 0x4, 0x40, 0xc, 0x0, 0x1, [@uac_iso={0x7, 0x25, 0x1, 0x2, 0x7, 0x79}]}}]}}]}}]}}, &(0x7f00000011c0)={0xa, &(0x7f0000000e80)={0xa, 0x6, 0x250, 0x0, 0x0, 0x75, 0x8, 0x2}, 0x21c, &(0x7f0000000ec0)={0x5, 0xf, 0x21c, 0x6, [@ss_container_id={0x14, 0x10, 0x4, 0x2, "91452d5bc9c9c0f6f2fb377a5bd7694f"}, @generic={0xb0, 0x10, 0xa, "c0b19303276913c1725179208cff9c06f22272ffd5253915968fb955578453e257161577a3748d561df61f7e4b142f643086296588641f443863d49331d2df082304f9f5afa2430afb8d3403239c070f24a409b473423ad4f90475f447927e98b3951518f4e2c62bf512dca6da039801ef4bd1251d941b373d2a3fae9bcba93f71fe53345e0a1b6099ceaeeee57347a1b65106036ad7b2dfebc56d1be5e704817ee29e0721f78f6b9c99006ebf"}, @generic={0xbb, 0x10, 0x1, "c24c08b8a578518a54209db2d6a070b4f1484f7618c3fc712aa463403ef24960aa4118ba2cb8478f9e342556807ad21a3fa3f59054568629922e093d9033b52fc186b62188f51cfb81642dea185fabcd69dbd0a7107c7fcb808f363f049600b62e01d4ebb20907b49e2ab3863e9786a86a839ce2e8dc1a514f099d4b6d4265e59d2af40cafedc463b84a2d5bec6cb2a8dcab0481008871f2e662fdfb7d2bf237b93abffe22d2a3721f7fc30ccf291efde3de0142c4bd2697"}, @ptm_cap={0x3}, @generic={0x8e, 0x10, 0x2, "af24afffb75124956f6018eb47ec365ba3de0a43f501925bb4a8de2a4c2bad25315104130e07e6dca9bb0e8a08bea63b202972760a6f311364f451adb9d7d673578cc30ab2793b03a14092c7db293caa24c08ea42596be45dcdd7d2c33256025fc7220c2970e7d13126f54af74a0605e85637c97c507f2dbe6c6f6e4ac73507eb261ccac3264288c56341b"}, @ext_cap={0x7, 0x10, 0x2, 0x10, 0x9, 0x2, 0x1}]}, 0x3, [{0x3e, &(0x7f0000001100)=@string={0x3e, 0x3, "a864464b16cb544d4946cbf80f7db041eecc9a169a06905a7b3047876c974ebbf9bb393a0bb78e23af3d289367c88a122cfe5338832f9d595922af8e"}}, {0x4, &(0x7f0000001140)=@lang_id={0x4, 0x3, 0xf4ff}}, {0x10, &(0x7f0000001180)=@string={0x10, 0x3, "0f2671e67ecfff4436f97491fb19"}}]}) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001200)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001240)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001280)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f00000012c0)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001300)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001340)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001380)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f00000013c0)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001400)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001440)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001480)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f00000014c0)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001500)) arch_prctl$ARCH_GET_UNTAG_MASK(0x4001, &(0x7f0000001540)) 1.24584738s ago: executing program 4 (id=2997): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = openat$uinput(0xffffffffffffff9c, &(0x7f0000000340), 0x802, 0x0) ioctl$UI_SET_EVBIT(r2, 0x40045564, 0x3) ioctl$UI_DEV_SETUP(r2, 0x405c5503, &(0x7f0000000000)={{0x10, 0xbfd2, 0x100, 0x9}, 'syz0\x00', 0x38}) syz_usb_connect(0x2, 0x36, &(0x7f0000000300)=ANY=[@ANYBLOB="12010000022fb040d80408fdb159000000010902240001080000000904b109020a5f92400905e80aff03f70709090587"], 0x0) ioctl$UI_DEV_CREATE(r2, 0x5501) r3 = syz_open_procfs$userns(0x0, &(0x7f0000000140)) ioctl$NS_GET_PARENT(r3, 0xb702, 0x0) r4 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r4, &(0x7f0000000100)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000200)=@ipv6_newnexthop={0x1c, 0x68, 0x5fb9a818fb7378e9, 0x70bd28, 0x0, {0xa, 0x0, 0x3}, [@NHA_BLACKHOLE={0x4}]}, 0x1c}, 0x1, 0xffffffffffffff9f}, 0x4090) r5 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r5, &(0x7f0000000000)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000300)=ANY=[@ANYBLOB="240000006800010002000000fcffff7f0000000000000c00173eaf92d00200010000"], 0x24}, 0x1, 0x0, 0x0, 0x24008000}, 0x4000) r6 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r6, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000000c0)=ANY=[@ANYBLOB="240000006800010009000000000000000a00000000000000080001000200000004000b"], 0x24}}, 0x0) r7 = openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) ioctl$KVM_CREATE_VM(r7, 0xae01, 0x0) r8 = ioctl$KVM_CREATE_VCPU(0xffffffffffffffff, 0xae41, 0x2) ioctl$KVM_KVMCLOCK_CTRL(r8, 0xaead) r9 = socket$inet6_sctp(0xa, 0x1, 0x84) getsockopt$inet_sctp6_SCTP_SOCKOPT_CONNECTX3(r9, 0x84, 0x6f, &(0x7f0000000100)={0x0, 0x1c, &(0x7f00000000c0)=[@in6={0xa, 0x4e21, 0xf, @ipv4={'\x00', '\xff\xff', @private=0xa010101}, 0x4}]}, &(0x7f0000000140)=0x10) listen(r9, 0xfff) accept$inet6(r9, &(0x7f0000000180)={0xa, 0x0, 0x0, @initdev}, &(0x7f00000001c0)=0x1c) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='cpu.stat\x00', 0x275a, 0x0) madvise(&(0x7f0000bc0000/0x400000)=nil, 0x400000, 0x9) 1.105154599s ago: executing program 3 (id=2998): r0 = socket$nl_route(0x10, 0x3, 0x0) r1 = socket(0x10, 0x803, 0x0) sendmsg$nl_route(r1, &(0x7f0000000380)={0x0, 0x4076cbba9945d516, &(0x7f0000000340)={0x0, 0x14}}, 0x0) getsockname$packet(r1, &(0x7f0000000140)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000200)=0x28a) r3 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r3, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000500)={&(0x7f00000003c0)=ANY=[@ANYBLOB="34000000100039042cbd70000000000000000000", @ANYRES32=r2, @ANYBLOB="0598000000200000140012800800010067726500080002800400"], 0x34}}, 0x0) sendmsg$nl_route(r0, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f00000000c0)=@newlink={0x44, 0x10, 0x439, 0x70bd2b, 0x25dfdbfd, {0x0, 0x0, 0x0, r2}, [@IFLA_LINKINFO={0x24, 0x12, 0x0, 0x1, @gre={{0x8}, {0x18, 0x2, 0x0, 0x1, [@IFLA_GRE_FWMARK={0x8, 0x14, 0x2}, @IFLA_GRE_ENCAP_SPORT={0x6, 0x10, 0x4e22}, @IFLA_GRE_COLLECT_METADATA={0x4}]}}}]}, 0x44}}, 0x0) 798.749013ms ago: executing program 3 (id=2999): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f0000000000)={0x26, 'skcipher\x00', 0x0, 0x0, 'ecb(serpent)\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, 0x0, 0x0) r1 = accept4(r0, 0x0, 0x0, 0x0) sendmsg$inet6(r1, &(0x7f0000000900)={0x0, 0x0, &(0x7f0000000880)=[{&(0x7f0000000080)="abf63fa63be2057e6eb311864b862f44687c12bc9818a7859baa745aff3f92ef76bdf77e7b5d02d91fc1523771c95efb", 0x30}, {&(0x7f0000000480)="52d2ea933609eb07c6d2847054a95df72d8e98717a68c12027034ea2cfe9dfff638298030651a2552405127ab1f7367c6befdcf20f700dcb39e7b9df0edc9269ab3c24d49de362841a9cd7af799cd57f26705d6d6f840b720f5c1fec2275e81fe37b609b8a0309a9918d2621e4ff4084240a16e4d47d78aa427b547d7965db", 0x7f}, {&(0x7f0000000940)="4da1537e1aa8ee68c744c5a486e7b2393712688bdffa4e960c7629be4054a649249ce75863e4b6189990e87e8ade0e7abd7c19e524fb3270ee17563373cb5cef0600000062298a6e00"/83, 0x53}], 0x3}, 0x91) recvmsg$unix(r1, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)=[{&(0x7f0000001f00)=""/4096, 0x1000}], 0x1}, 0x12060) 580.867834ms ago: executing program 1 (id=3000): socket$alg(0x26, 0x5, 0x0) r0 = socket$tipc(0x1e, 0x5, 0x0) bind$tipc(r0, &(0x7f0000000200)=@name={0x1e, 0x2, 0x1, {{0x2, 0x1}, 0x3}}, 0x10) bind$tipc(r0, &(0x7f0000000000)=@nameseq={0x1e, 0x1, 0x0, {0x42, 0x0, 0x2}}, 0x10) r1 = socket$tipc(0x1e, 0x5, 0x0) bind$tipc(r1, &(0x7f00000000c0)=@nameseq={0x1e, 0x1, 0x0, {0x42}}, 0x10) bind$tipc(r1, &(0x7f0000000140)=@name={0x1e, 0x2, 0x0, {{0x42, 0x2}}}, 0x10) bind$tipc(r0, 0x0, 0x0) r2 = syz_genetlink_get_family_id$ethtool(&(0x7f00000005c0), 0xffffffffffffffff) r3 = syz_open_procfs$namespace(0xffffffffffffffff, &(0x7f0000000040)='ns/mnt\x00') ioctl$BTRFS_IOC_BALANCE(r3, 0x5000940c, 0x0) bpf$MAP_UPDATE_CONST_STR(0x2, &(0x7f0000000080)={{0xffffffffffffffff, 0xffffffffffffffff}, &(0x7f0000000000), &(0x7f0000000040)='%ps \x00'}, 0x20) syz_open_dev$tty1(0xc, 0x4, 0x1) r5 = bpf$BPF_BTF_LOAD(0x12, &(0x7f00000000c0)={&(0x7f0000000180)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x98, 0x98, 0x3, [@array={0x0, 0x0, 0x0, 0x3, 0x0, {0x80, 0x1, 0x19}}, @array={0x0, 0x0, 0x0, 0x3, 0x0, {0x1, 0x5, 0x8}}, @ptr={0x2, 0x0, 0x0, 0x2, 0x3}, @ptr={0xf}, @var={0xc, 0x0, 0x0, 0xe, 0x1, 0x1}, @volatile={0x1, 0x0, 0x0, 0x9, 0x1}, @array={0x0, 0x0, 0x0, 0x3, 0x0, {0x3, 0x1, 0x2}}, @volatile={0x3, 0x0, 0x0, 0x9, 0x1}, @decl_tag={0x9, 0x0, 0x0, 0x11, 0x1, 0x8}]}, {0x0, [0x5f]}}, &(0x7f00000002c0)=""/255, 0xb3, 0xff, 0x1, 0x8000, 0x0, @void, @value}, 0x28) bpf$MAP_CREATE(0x0, &(0x7f0000000600)=ANY=[@ANYBLOB="0700000002000000000000000500000000040000", @ANYRES32=r4, @ANYBLOB="ffffffff00000000000000000000000000000000f4fae9a0dc330c847297f9479e9300f2d68c70bdbe65ca94d3e9bfd742d66a8ef183d41f2054c988ae187248a6c529e052a22eeb0058a16a700b468f01dbc73eb2be00e8a8697704540689e9b5c0f6c066c7ca3221a86fb83c87cdc99a88b639dc4971f9c02ad9bd5a54a27053f8f85c82697b799abd82edca27bdfa27d61e8d567dab7d1e081ac2912cc35629fe997f71a3f2b624005afffa0fd4b7dd612c91f169ec9c9b38632fd10e5a2c37b5be0622b95aef0fa125", @ANYRES32=0x0, @ANYRES32=r5, @ANYBLOB="01000000020000000300"/28], 0x50) r6 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r6, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000400)=ANY=[@ANYBLOB="440000001000210400"/20, @ANYRES32=0x0, @ANYBLOB="00000000000000001c0012800b00010067726574617000000c00028008000100", @ANYRES64=r2], 0x44}}, 0x0) 411.713713ms ago: executing program 3 (id=3001): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000740)=ANY=[@ANYBLOB="140000001000010000000000000100000000000a20000000000a01010000000000000000010000000900010073797a300000000068000000090a010400000000000000000100000008000a4000000000200011800e000100636f6e6e6c696d69740000000c00028008000140000000000900010073797a30000000000900020073797a3200000000080005400000001f0c0009800800014000"], 0xb0}}, 0x0) 195.45503ms ago: executing program 1 (id=3002): r0 = add_key(&(0x7f0000000040)='cifs.spnego\x00', &(0x7f0000000140)={'syz', 0x2}, &(0x7f0000000180)="1214753f8060c9e4608b01d54971180b2680694070a8361174981c16a35e5d44362da12d16b0cb297e88c83bcf1ddaf838d40eeaa16afacc748f63fb354bee0691ae1fafe8ebffbfa83c80afa869a82e24717f1becb5c1b519e2a905b9fdd288a22ac1bfee888086ca830285be45d94f95f1ae759f7cad4118b9df8b79e71a7678604204928722bc6b9ea2efca3ba31c6f188231061ce966f80dfc47", 0x9c, 0xfffffffffffffffb) keyctl$revoke(0x3, r0) r1 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file1\x00', 0x8042, 0x0) r2 = socket$netlink(0x10, 0x3, 0x0) sendmsg$netlink(r2, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000000)=[{&(0x7f0000000580)=ANY=[@ANYBLOB="340000002e0001002ab77d343a634091ed700000", @ANYRES32, @ANYBLOB="1c0000801800318011001d"], 0x34}], 0x1}, 0x0) fcntl$setlease(r1, 0x400, 0x1) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) close(r3) r4 = socket$inet6_mptcp(0xa, 0x1, 0x106) setsockopt$sock_int(r4, 0x1, 0xf, &(0x7f0000000040)=0xcc, 0x4) listen(r4, 0x0) fcntl$getflags(r1, 0x401) mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) r5 = creat(&(0x7f00000000c0)='./file0\x00', 0xd4) r6 = bpf$MAP_CREATE(0x0, &(0x7f0000000300)=@bloom_filter={0x1e, 0x4, 0x100, 0x5, 0x1002, r5, 0x80002, '\x00', 0x0, r5, 0x3, 0x2, 0x3, 0x8, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018120000", @ANYRES32=r6, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7040000f6000000850000004300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) setsockopt$inet6_tcp_int(0xffffffffffffffff, 0x6, 0x13, 0x0, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0x19, 0x4, 0x4, 0x5, 0x0, 0xffffffffffffffff, 0x80000000, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x17, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=0x0, @ANYBLOB="0000000000000000b70800000000e7057b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1d, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r7 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r7, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000740)=ANY=[@ANYBLOB="140000001000010000000000000100000000000a20000000000a01010000000000000000010000000900010073797a300000000068000000090a010400000000000000000100000008000a4000000000200011800e000100636f6e6e6c696d69740000000c00028008000140000000000900010073797a30000000000900020073797a3200000000080005400000001f0c000980080001400037"], 0xb0}}, 0x0) 0s ago: executing program 3 (id=3003): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPCTNL_MSG_CT_NEW(r0, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000100)=ANY=[@ANYBLOB="640000000001010400000000141a000002000000240001801400018008000100e000000108000200e00000010c00028005000100000000002400028014000180080001000000000008000200ac1e00010c00028005000100000000000800074000000001"], 0x64}}, 0x0) r1 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xc, &(0x7f0000000040)={0xd}) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPCTNL_MSG_CT_NEW(r2, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000036c0)=ANY=[@ANYBLOB="44001100000000000000020000002400018014000180080001006a7e7c46d49415d7b49149e000000108000200e00000010c000280050001000000400000000004000f800000000000000000000000df586519bc846ea6fa3f900e7f5b43d327ab37b6d920991e1a026645c6cc458964e899a09f8ebbd6ebf0622ce64234e16990415e9709df8b3f"], 0x44}}, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r5 = syz_io_uring_setup(0x88f, &(0x7f0000000140)={0x0, 0xaee2, 0x0, 0x2, 0xbfdffffc}, &(0x7f0000000100)=0x0, &(0x7f0000000000)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r6, 0x4, &(0x7f0000000400)=0xfffffffc, 0x0, 0x4) r8 = eventfd2(0x7fff, 0x80001) io_submit(0x0, 0x1, &(0x7f0000003680)=[&(0x7f0000003640)={0x0, 0x0, 0x0, 0x7, 0x1, r1, &(0x7f0000003600)="3764772638392e85eb6f8214d803679c848d1d42a5543ebcd9c277e665821eb73fc5d74cba98c7db709ecfdf4478440c035f9d8d213f339453ac156318e2", 0x3e, 0x9, 0x0, 0x2, r8}]) syz_io_uring_submit(r6, r7, &(0x7f00000002c0)=@IORING_OP_FILES_UPDATE={0x14, 0x40, 0x0, 0x0, 0xffffffffffff8000, &(0x7f00000001c0)=[0xffffffffffffffff], 0x1}) io_uring_enter(r5, 0x47f6, 0x0, 0x0, 0x0, 0x0) write$UHID_INPUT(0xffffffffffffffff, &(0x7f0000000080)={0x8, {"70ca253e230ef7cea884834d6c465f42def02f94c45b1f01cfd13fd2861758c6a3f127481e685c30df940fabe7e21f351b0c7c1b8de44552a95e7bc2997931185cdd971d5e6eb64794c87e1fec87a1a270a7bbbab5be8c0815954251fc2e177c022a16298decd4a2566ade604f962c561b894cdd8c8cf2a10c9da36d16647cdcbf6e575406baf4b5730e3e7e57622384fb84a0e9cd2b8ad525a43aebfbccad8e0e39512d2daeafc434c2f2234c59fa4ddb14477949df126432e20d94eac5ea6b880dbb7862010f40482da409cef850a503d0d8eba1d9b0de9c4fe0c1aa8af96afa487c89608b76c9791ae6bd00939d567acb5b11d54398aa649c9f60131e2ce92df810af5dd279c14f70a97c4735249817a2bf26af0fb9befc6be91ee11e10efaeb20bf2e58e4698b820bc7493d7cb4cd9a67b4517c589ef0bbd2f0deb3f8df2701a65c9cffa95e9d91fec02ad09a5822c683e346bc75160941a0e85ddf2485ee64ac7320e72767a0ed3a0788435f6a137773a9327450b780de47ad36a45a2431f4cec1ba7a1c63676f21456878798e8881ac7d692c182893bbb158790c8b30ae773a4c487bd6c5248d0ac861160f114f2fb0bf313f3eed9040d7ddbca03d2fcf6450b658209e4976ce602d5e976de5b17550fdd711206c667e644e5c58732549a1d9ea03ef6a4b96b9342851bbd4d9d31965ff1a5c96ff57f2af85b15519b08641eb6c3451167a28954ab9c713ce8c9890165717d52ef0557dd5c79d861deb2c66fb1a40b4f4c850970a74b5154b1120222a0b5bf5a1935623cb37042a9e98026b8800c53a187a532d759187da97f679e9525d79db3d253ab8622bca7357d164c51a762426296f9e518687bcc3d34264e16de8c8e2d74454c4ea5278fdcfc9a935fc059fb8476eb0c1d8f61b58a7bbe509b687a00ecf37095f2b4aed0b9a0f4c61f38254448081651bada010e316a23b1a22e598314c581e88a21a8b428ddf33e082499e0e8964543e36ecc72f759ee86432298f175aaf1350f54193965539dca6eaa159765c87ad5a6649b47e80b2dd93b076cccc9cbc95da67f3d52c94c5cd683c38c9f548da3b8714d44b5109f761dab9800a258759a8597e995615ba771d74479c8728d933733fbe62a722807e1839f5a537ebb2ee9d5e93252d64abfab5a7eac00413623924f48f9b304df00634b82c95650eb4bec42d1386c37a993ad5fae4483a9177421c454026af1ccce94b80b785671fc209264ce374a9add2ce2d95a08c31ad5c62d6608c338ff5a28d5400ea4d71f847381a83c2a7ba1437cebd9b665377595d5cd8f82f462b7763bcc5d0453a3ed95a99d316040b8f3578f516e79d53cccf98fd4548902a5deaaca146b799b4cdeeb60a429beb6d912153b793b725eca39b8ab21e34966dca1d24edbb891443cd619ef0435ea2ef563fbf3f3a07dff8f29381b13990a2d909e43dd3f57e176d7808e2d91b1364c1748880d96bc29101b0987f0e280886dd20c40b6bec7e721ebda7954fb1e77e1abb1a47da1ff213f994a22759a7d186f4d0f23e7f042b97051c9b12ca3bd47a30f05a0e8648201450f68b78ed541ed6ea9a920731caec520c2d6991ccbff20cedacbd07e94046ab083a6be822a020c19889f4bef2e057910c81e340a2869197906e2e9da4f8dc11bf778a72aa5590254a72520aa1a80ff8d02eb47e98053b23e9c98358c871e04669606838f8eb599dc0df5287dde674c05636a403fdb22f9b19182db445d732bd397d154d66dc1b9206b638ed38b15a3ed5eb72d28401398f7379541c715faf1b78985df2f41be10ec3c27ce1ea495cfd682a3efb9049ebab3e2b97b371b487c7a56bf16d371742002be0fa27693dadfc10290b37825f2d4a1a7385fdd812d71fcb951a3f329a183132894bdd256dc078e0b6216ebd341fc56c1175c80bd74064610a65655e4140a8c5920a516060f1a02e867de51136d2a82cf0450914a61288d92506ad04fc7e54a4003d3b102345fbe2e3fd5a75714345eefd25ef74aadb17a52ff41c7597163cd7de6e24c26d157176be3c3936c77916f8b51b9cd0ac9c583371a5f68add5561c306867ca4592965bd8932716f45dece476ea210a56386f102039316da5e3e632b0ebaab0856c1803f21c44d67fa9ec35c1aedf79ac427adb62f48cfab8c308faafadd00d24194e95a51f2f7c60a2fec8e094b71f8c1e6b0ba27c32c30e8da05f928d848fa295e3c9594220bafd302bf915d34a1bb20638aafaba3bd55b6f58b0427a863a961372add3d240a72913cf78772487b073d3db96b7447e2a85de6e8df404f49cd79feaddc69ed4e8061a6122d4e12d3cd32f20360b6f57c0d29cdbfd8f0fbb0f58328213680ca465efc7a891fce48174b12473f90850b56f246f83826e13ba4f39041d0344032be484a11473d31dce46cf28166680237199d55ae53b18acc4d67cd0ea8859d0362b68cda330e801e7fcceb0421a029615511900777583c2da500fd048382e54435ad7be5cec1499c6fa3e4688107b9946ea2f81fe935be159fafaacd07dc6a9de0d4d6a02a493e53a572c2880e59b29aebd31fa7e0bbd08119586d923cf76e3bb0ee5083e31e26dd2e103ce687b9aad198d7cb650965ca3a7d63155f4976127e37ce8f4668f4583419b3587cafb33b202816539000c9f45422c4642aa5e3aa6fe82c83f9151476f3c10e4531a419cdd72455c271d20317658c116b3f122c6bfe87db2a63d8235eeed3d3dc92e3b640cffcd0672dad125b9b7d850b8b27f5c1e3c89b121c5449acb9377c33f4a2ea99a580ff98e2d6e937834d556ea2afece5e75850600ddb540693d0f37a45e7cd9c4a186f34e18e334bbb2e9302e6e7159d73e6c654e5e6748e1ba24fec14a9a37701b9dcb3b8cdad2f6e6edcb955ef3f33f2db362c1f08ae514af64c4c02f079726128be3a487320dfaaf7feac2845878c23fa21b1edff5f5df1268cef6e94308a75161f1cb3aee1d8c1d574e1bd15a97df84983768ec12453c1d5418ab30568cee229c3ff0ee163d159165b5841c701a622e63236301e0a05764cf4ab14e4ddb6d6a0c10689f23decbffdfa5c71c7384bd986f76872033f47b920ac84f5decdd029444ec0b5780fcbc298350af77020ea5b328e1d6ea51f5ad6a2aac2c4e6ac3da48c1671fafba498e676b16ae1d11cc7d835f2a5ab0014fc1b408057620356e261e4721e1fd6cc4fb789641bab7c7897d29904d9bdf14c8b62f640da42776c10f4763dce9d0cd7b0231f4281cc48e9e6255a03ee0ae5ff7a13db515e2fcde1664d8030d48fd0936a9eb2b35ae4989d8ce527a5987d46f34f5f67e302ddc86ef8d1358a3929462b8cf302238172f18984c0129204eb84f88e4875c9ed62c4df4dec9b31a35fc47f49f371800e929f6ff6afb7006419581fb776dbd8e3669b799c920605ea26fbfe8b2eceba96e80c430967b4f154f9a8191b0ad02ad0e43b7219d4a1426c71e7dd69b52c35fbce6be14c07f7c38539a9c043e585f0b1baaaab411271962e1e28a9638dab16c568b8911c25d1100f970f629869f4bbe30efbaee3ec3e086477be178a882cbbbf698e6f456a3d0ee5f64325bb238b55f70f51cd4884b3002276c05ce7f8e801cc0238395fd98f884a12e6a980e79f434734a6d29f6724e2e6b4e41d72c7694a03fe1ca3d8ce9df03eafe3d7273b922cf942b224d795445c8716b092be6de27ac9e9e365d2dfa79a702fadc4472f42fe383b16688b4e9cd64ac288a466ed152f1fcc91f8d22912c750bbfe15ca304fcd82ff1c11c12f5df148d74a27caaf75780128fe17ad86c3b7f3d97659ffa1abbe292b2896c82f76d1b503eb80eae07fb1e7f68da96a536817c12d964b9f4ef6b6f901373ac365cbf6d276ad8b295a30de3288bc50ce3744b7d63c183e1fb072463baa366f67bcf6e7aa01c4fc129654413dba4747786ae3967a77a6f5d0bb24b1a18e276e9899a8fdc45df61ef84368964d77204c187b12d06ed7961b239aa3aad6b2ae75edebe0018335b77f9ff7a90a3518417ebad569ca9df6d9d028c347b0bc0754ff05bd30bc10057c339eb09fbdd875cb4a0760aa2e0a88633bf5b4beccbd3146046a490d66278cf75de76671c4ba8124fc9de5427ad120b202b8424e734eddbe08466259e757214f58b47cf3aaa21b8c98f6e8d4f66e9fda897732827855d987e6f8e310fce14a05034cf1d53d211aa4ad56eab17bbd39fc69d950ba5d14bcd5db8605950b6785acd04f00cf054998613dda8a6630102a86550205331444ce0248f2c44d3edec23a935cee7b093e47fd4fd72cae4bd1421adff6f2c13525692c511c19bd4008624510aafcf120801d7f6366806d3e377e2e39f47e341a40f812715e8a1130ee9770f998cea169038f43ba9bbefbff9882a85fe984a39c1930b7255ae8ddce424c1e5468557f072a3a76aa6932cc16a2633b27572a0696bd2a3303deba70cca4cad54b34ddb67acee56a95dde9c157890e36784576a9b8f96163c463c2c8392fb54e34da218c42616b8186c6e45298973af8769446a9fced6440543e4b355c0d1f2288f769ad5c62394f5ac6907d811c9f0e5c228ff01d7837833ffbe3b0fc4e45ee6356fe8fca29b6a5a7f498cce5c765ab77108ede41f455aa325d387bbf175a525104878d344d32e5afdfb68c4108551c2a45089c943456deb57f5dfe634fbcd305c076a4b93bb30286b474317e7daeadd45fa1a3fa21b74832c932773fa4d4f95794355c7692fd58e0b8a331e77d06d590ba1b14ed1349febb6782a695f16d8ebae63dd5e14650783f904e8f4835f941ff1f9d07208541a90f3412308074a882236abfb0540ded765b8ee18aef943ae608d5d8889d3d7d6b4871cdfb548d408dc67fee80ded13ad01e99cd9d6630099566f811d23859c65a87440790729e136e972734047262a8be47c4d8794fd4605b284db6365a8da83da9a3c3f6951e13ece5b2a454aa9e9d3421153e6e822cf05896a59561cea7d7ceec0a5e80141706ce6ff41429806d80fea11b222eda4ee1e3d983970fd31dc529de82e0b37d8b1d58692c1a45bdaee904359020d9bbad4c16ac667ad3c966019e988c498fa9041a7eece51ea6fd9292e522bd3f62876a3b29fb5cc759913495364bb505d200b9a7aa327f252453251099d5d815de77e81c4d75ada7630b4a72b184594d8e97ba8b09fcec10bd873e04b50f9f914067fe92d28691aec9f15c205ec4d59022798715348ed787418c2c7127f7077dbd83e72590675b237a9a0f88603b07679bdfb24e6dfdbc7718fc72d060c3ca002e42d5d93ab5b13ddab1aca5ac8cf245951e0ab9bb80060421053ff84e1b83751b7fa3449c326c5c5d5e0c0261a7e3ed779e376b3522b831e7d33a296e95d06ce7275f1f7d52b69e0116e4ade52cfc508e3bf9717aeb3320e3621c5d2fe06ef071d00c89698af91c37bdf52228f029412d18018baf7daae644fd700ba99331593f470ebf919f7bb360ab433cc5425b38ee89e1bc8c3e82da0b96c41a4506023146da65d5c1ef3b1bc968aa03c60933d6792e34bb221dec52509ece5d0976088acc0c36685f599e900aef4e86377e4206d0e54cf7fa76bbee156ceea501176807879f705ca5fea9ec6464d61b3c8f89ae03bef165e086a53104c0fa87c8007996bfd1c8f43d7d8ac3a7ae4e1bdf94d5fa9092eb580ca5756181d89f22f12b7e8d253958f0b281688e915e729b40cfe98ec9a8c0211b0c10ed3b2e88dc210b757153a797ccc22d349a7a419", 0x1000}}, 0x1006) r9 = socket$inet6(0xa, 0x1, 0x100) r10 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL80211_CMD_START_SCHED_SCAN(r10, &(0x7f0000003580)={&(0x7f0000003340)={0x10, 0x0, 0x0, 0x80000}, 0xc, &(0x7f0000003540)={&(0x7f0000003780)=ANY=[@ANYBLOB="8c010000", @ANYRES16=0x0, @ANYBLOB="20002cbd7000fedbdf254b0000006c012a008c1049040da90d074c74a73671e07beb56bc7107000001ffff0140828804c2000d000000080211000001783100002e000000020000000a01080211088c7ef70d00000008021100000100fe000004ffffffffffff090000000408021100000106000000050802110000000900000004ffffffffff0bcfd26f5eb2b8a38b094ae79cdfc936ff010400000008021100000019d8ffff000802110000010000000001ffffffffffffc70c000000080211000001c3000000bd060802110031b095acd4713c42711df56d7900001001372606086c01b1cc5c0301a504a0bfc955d2afa4984d8dd296541a6ae39116c8111a95399dfc8286d63e9d31896e9194fd80d8b1e24fb4149a105c9059b83aad81c61af35ea983f3d61d70910e6172373c6a9615084cb054dcd58a601848233333c95658a835ca6fc2d7090d792ee118b9d2b9bfb720901cb81aeab255502274fa70789e672adcdb11e2da1bd4194e024bd5f45932929e4d56e11c6b47c37545f3d5ca6082179a9f29c5a50a997c3e010272060303030303030400ff000800770008000000"], 0x18c}, 0x1, 0x0, 0x0, 0x24000005}, 0x40) setsockopt$inet6_mreq(r9, 0x29, 0x1b, &(0x7f0000000100)={@remote}, 0x14) ioctl$sock_SIOCGIFINDEX(r9, 0x8933, &(0x7f0000000300)={'virt_wifi0\x00', 0x0}) setsockopt$inet6_mreq(r9, 0x29, 0x1b, &(0x7f0000000000)={@remote, r11}, 0x14) syz_usb_connect(0x0, 0x36, &(0x7f00000033c0)=ANY=[@ANYRESHEX=r1], 0x0) syz_emit_vhci(&(0x7f0000003040)=ANY=[@ANYBLOB="043e0c0406c9002c9e1a4bf74f1d08"], 0xf) r12 = socket$xdp(0x2c, 0x3, 0x0) r13 = openat$dsp(0xffffffffffffff9c, &(0x7f0000000200), 0x40281, 0x0) ioctl$SNDCTL_DSP_SUBDIVIDE(r13, 0xc0045009, &(0x7f0000000000)=0x1) ioctl$SNDCTL_DSP_SPEED(r13, 0xc0045002, &(0x7f0000000500)=0x42268597) recvmmsg(r12, &(0x7f00000031c0)=[{{&(0x7f0000000000)=@l2tp6, 0x80, &(0x7f00000020c0)=[{&(0x7f00000010c0)=""/4096, 0x1000}], 0x1, &(0x7f0000002100)=""/147, 0x93}, 0x4}, {{&(0x7f00000021c0)=@pppol2tpv3={0x18, 0x1, {0x0, 0xffffffffffffffff, {0x2, 0x0, @loopback}}}, 0x80, &(0x7f0000002340)=[{&(0x7f0000003400)=""/246, 0xf6}], 0x1, &(0x7f0000002380)=""/143, 0x8f}, 0x401}, {{&(0x7f0000002440)=@generic, 0x80, &(0x7f0000002b80)=[{&(0x7f00000024c0)=""/24, 0x18}, {&(0x7f0000002500)=""/171, 0xab}, {&(0x7f00000025c0)=""/198, 0xc6}, {&(0x7f00000026c0)=""/144, 0x90}, {&(0x7f0000002780)=""/240, 0xf0}, {&(0x7f0000002880)=""/139, 0x8b}, {&(0x7f0000002940)=""/36, 0x24}, {&(0x7f0000002980)=""/216, 0xd8}, {&(0x7f0000002a80)=""/40, 0x28}, {&(0x7f0000002ac0)=""/163, 0xa3}], 0xa, &(0x7f0000002c40)=""/141, 0x8d}, 0x7}, {{0x0, 0x0, &(0x7f0000002e80)=[{&(0x7f0000002d00)=""/240, 0xf0}, {&(0x7f0000002e00)=""/91, 0x5b}], 0x2, &(0x7f0000002ec0)=""/38, 0x26}, 0xffffff2d}, {{&(0x7f0000002f00)=@caif=@dgm, 0x80, &(0x7f0000003000)=[{&(0x7f0000002f80)=""/96, 0x60}, {&(0x7f0000003080)=""/168, 0xa8}, {&(0x7f0000003140)=""/72, 0x48}], 0x3}, 0x7}], 0x5, 0x0, &(0x7f0000003300)={0x77359400}) kernel console output (not intermixed with test programs): 8d169 code=0x7ffc0000 [ 535.715441][T11575] netlink: 40 bytes leftover after parsing attributes in process `syz.4.2139'. [ 535.925388][ T5854] Bluetooth: hci0: command 0x0c1a tx timeout [ 536.030717][ T30] audit: type=1326 audit(1743764705.017:1520): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11587 comm="syz.2.2145" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 536.129525][ T30] audit: type=1326 audit(1743764705.017:1521): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11587 comm="syz.2.2145" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 536.195291][ T30] audit: type=1326 audit(1743764705.017:1522): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11587 comm="syz.2.2145" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 536.257706][ T30] audit: type=1326 audit(1743764705.017:1523): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11587 comm="syz.2.2145" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 536.353776][ T30] audit: type=1326 audit(1743764705.017:1524): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11587 comm="syz.2.2145" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 536.735377][ T5854] Bluetooth: hci1: command 0x0c1a tx timeout [ 536.815653][ T5854] Bluetooth: hci4: command 0x0c1a tx timeout [ 536.819447][ T5843] Bluetooth: hci3: command 0x0c1a tx timeout [ 536.885530][ T5843] Bluetooth: hci2: command 0x0405 tx timeout [ 537.005586][T11638] netlink: 14 bytes leftover after parsing attributes in process `syz.4.2167'. [ 537.479922][T11652] netlink: 32 bytes leftover after parsing attributes in process `syz.0.2175'. [ 537.668297][T11658] netlink: 4 bytes leftover after parsing attributes in process `syz.4.2176'. [ 537.705373][T11658] bridge_slave_1: left allmulticast mode [ 537.718056][T11658] bridge_slave_1: left promiscuous mode [ 537.735128][T11658] bridge0: port 2(bridge_slave_1) entered disabled state [ 537.756982][T11658] bridge_slave_0: left allmulticast mode [ 537.762688][T11658] bridge_slave_0: left promiscuous mode [ 537.772411][T11658] bridge0: port 1(bridge_slave_0) entered disabled state [ 537.909403][T11669] netlink: 100 bytes leftover after parsing attributes in process `syz.3.2182'. [ 538.706763][T11699] bridge0: port 3(vlan2) entered blocking state [ 538.725741][T11699] bridge0: port 3(vlan2) entered disabled state [ 538.742456][T11699] vlan2: entered allmulticast mode [ 538.755843][T11699] bridge0: entered allmulticast mode [ 538.773394][T11699] vlan2: left allmulticast mode [ 538.785285][T11699] bridge0: left allmulticast mode [ 538.960910][T11645] warn_alloc: 7 callbacks suppressed [ 538.960932][T11645] syz.1.2174: vmalloc error: size 2101248, failed to allocated page array size 4104, mode:0xdc2(GFP_KERNEL|__GFP_HIGHMEM|__GFP_ZERO), nodemask=(null),cpuset=/,mems_allowed=0-1 [ 539.017498][T11645] CPU: 0 UID: 0 PID: 11645 Comm: syz.1.2174 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 539.017534][T11645] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 539.017550][T11645] Call Trace: [ 539.017558][T11645] [ 539.017568][T11645] dump_stack_lvl+0x241/0x360 [ 539.017609][T11645] ? __pfx_dump_stack_lvl+0x10/0x10 [ 539.017642][T11645] ? __pfx__printk+0x10/0x10 [ 539.017671][T11645] ? cpuset_print_current_mems_allowed+0x1f/0x350 [ 539.017707][T11645] ? cpuset_print_current_mems_allowed+0x1f/0x350 [ 539.017739][T11645] ? cpuset_print_current_mems_allowed+0x31e/0x350 [ 539.017774][T11645] warn_alloc+0x27c/0x410 [ 539.017809][T11645] ? __pfx_warn_alloc+0x10/0x10 [ 539.017839][T11645] ? hash_netiface_create+0x356/0x1040 [ 539.017871][T11645] ? __get_vm_area_node+0x1c8/0x2d0 [ 539.017902][T11645] ? __get_vm_area_node+0x25c/0x2d0 [ 539.017941][T11645] __vmalloc_node_range_noprof+0x634/0x1390 [ 539.017992][T11645] ? __kmalloc_cache_node_noprof+0x26a/0x3c0 [ 539.018026][T11645] ? __pfx___vmalloc_node_range_noprof+0x10/0x10 [ 539.018050][T11645] ? hash_netiface_create+0x356/0x1040 [ 539.018079][T11645] ? __get_vm_area_node+0x1c8/0x2d0 [ 539.018104][T11645] ? __get_vm_area_node+0x25c/0x2d0 [ 539.018133][T11645] __vmalloc_node_range_noprof+0x53f/0x1390 [ 539.018150][T11645] ? hash_netiface_create+0x356/0x1040 [ 539.018203][T11645] ? __pfx___vmalloc_node_range_noprof+0x10/0x10 [ 539.018221][T11645] ? __kasan_kmalloc_large+0x1a/0xa0 [ 539.018248][T11645] ? hash_netiface_create+0x356/0x1040 [ 539.018275][T11645] __kvmalloc_node_noprof+0x3b2/0x5a0 [ 539.018301][T11645] ? hash_netiface_create+0x356/0x1040 [ 539.018326][T11645] ? hash_netiface_create+0x356/0x1040 [ 539.018351][T11645] ? hash_netiface_create+0x2fa/0x1040 [ 539.018381][T11645] hash_netiface_create+0x356/0x1040 [ 539.018506][T11645] ? __pfx_hash_netiface_create+0x10/0x10 [ 539.018552][T11645] ip_set_create+0xa7d/0x1960 [ 539.018576][T11645] ? ip_set_create+0x48c/0x1960 [ 539.018598][T11645] ? __pfx_ip_set_create+0x10/0x10 [ 539.018643][T11645] ? nfnetlink_rcv_msg+0x227/0x1190 [ 539.018662][T11645] nfnetlink_rcv_msg+0xbf7/0x1190 [ 539.018680][T11645] ? nfnetlink_rcv_msg+0x227/0x1190 [ 539.018717][T11645] ? __pfx_nfnetlink_rcv_msg+0x10/0x10 [ 539.018732][T11645] ? stack_trace_save+0x11a/0x1d0 [ 539.018778][T11645] ? dev_hard_start_xmit+0x2d4/0x840 [ 539.018796][T11645] ? __dev_queue_xmit+0x1b80/0x3f60 [ 539.018813][T11645] ? __netlink_deliver_tap+0x561/0x7f0 [ 539.018837][T11645] ? netlink_deliver_tap+0x19d/0x1b0 [ 539.018859][T11645] ? netlink_unicast+0x7c6/0x9a0 [ 539.018877][T11645] ? netlink_sendmsg+0x8c3/0xcd0 [ 539.018899][T11645] ? __sock_sendmsg+0x221/0x270 [ 539.018919][T11645] ? ____sys_sendmsg+0x523/0x860 [ 539.018935][T11645] ? __sys_sendmsg+0x271/0x360 [ 539.018964][T11645] netlink_rcv_skb+0x208/0x480 [ 539.018989][T11645] ? __pfx_nfnetlink_rcv_msg+0x10/0x10 [ 539.019009][T11645] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 539.019051][T11645] ? apparmor_capable+0x13b/0x1b0 [ 539.019071][T11645] ? bpf_lsm_capable+0x9/0x10 [ 539.019091][T11645] ? security_capable+0x7e/0x2d0 [ 539.019121][T11645] nfnetlink_rcv+0x296/0x28f0 [ 539.019140][T11645] ? __dev_queue_xmit+0x2f9/0x3f60 [ 539.019161][T11645] ? __pfx___local_bh_enable_ip+0x10/0x10 [ 539.019183][T11645] ? __dev_queue_xmit+0x2f9/0x3f60 [ 539.019201][T11645] ? __dev_queue_xmit+0x2f9/0x3f60 [ 539.019221][T11645] ? __dev_queue_xmit+0x1780/0x3f60 [ 539.019238][T11645] ? kasan_save_track+0x3f/0x80 [ 539.019258][T11645] ? __kasan_slab_alloc+0x66/0x80 [ 539.019283][T11645] ? do_syscall_64+0xf3/0x230 [ 539.019306][T11645] ? __pfx_nfnetlink_rcv+0x10/0x10 [ 539.019322][T11645] ? __dev_queue_xmit+0x2f9/0x3f60 [ 539.019343][T11645] ? __pfx___dev_queue_xmit+0x10/0x10 [ 539.019376][T11645] ? ref_tracker_free+0x63e/0x7e0 [ 539.019396][T11645] ? __asan_memcpy+0x40/0x70 [ 539.019427][T11645] ? __pfx_ref_tracker_free+0x10/0x10 [ 539.019444][T11645] ? __skb_clone+0x5c/0x6d0 [ 539.019476][T11645] ? skb_clone+0x240/0x390 [ 539.019506][T11645] ? netlink_deliver_tap+0x2e/0x1b0 [ 539.019532][T11645] ? netlink_deliver_tap+0x2e/0x1b0 [ 539.019556][T11645] netlink_unicast+0x7f8/0x9a0 [ 539.019584][T11645] ? __pfx_netlink_unicast+0x10/0x10 [ 539.019606][T11645] ? skb_put+0x114/0x1f0 [ 539.019628][T11645] netlink_sendmsg+0x8c3/0xcd0 [ 539.019669][T11645] ? __pfx_netlink_sendmsg+0x10/0x10 [ 539.019696][T11645] ? aa_sock_msg_perm+0x91/0x160 [ 539.019725][T11645] ? __pfx_netlink_sendmsg+0x10/0x10 [ 539.019747][T11645] __sock_sendmsg+0x221/0x270 [ 539.019772][T11645] ____sys_sendmsg+0x523/0x860 [ 539.019797][T11645] ? __pfx_____sys_sendmsg+0x10/0x10 [ 539.019812][T11645] ? __fget_files+0x2a/0x420 [ 539.019831][T11645] ? __fget_files+0x2a/0x420 [ 539.019855][T11645] __sys_sendmsg+0x271/0x360 [ 539.019878][T11645] ? __pfx___sys_sendmsg+0x10/0x10 [ 539.019941][T11645] ? do_syscall_64+0xb6/0x230 [ 539.019963][T11645] do_syscall_64+0xf3/0x230 [ 539.019984][T11645] ? clear_bhb_loop+0x45/0xa0 [ 539.020005][T11645] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 539.020022][T11645] RIP: 0033:0x7fb1ce58d169 [ 539.020039][T11645] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 539.020054][T11645] RSP: 002b:00007fb1cf4cc038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 539.020074][T11645] RAX: ffffffffffffffda RBX: 00007fb1ce7a5fa0 RCX: 00007fb1ce58d169 [ 539.020087][T11645] RDX: 0000000000000800 RSI: 0000200000000040 RDI: 0000000000000003 [ 539.020098][T11645] RBP: 00007fb1ce60e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 539.020109][T11645] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 539.020119][T11645] R13: 0000000000000000 R14: 00007fb1ce7a5fa0 R15: 00007fb1ce8cfa28 [ 539.020145][T11645] [ 539.021016][T11645] Mem-Info: [ 539.681777][T11645] active_anon:5363 inactive_anon:0 isolated_anon:0 [ 539.681777][T11645] active_file:7821 inactive_file:38509 isolated_file:0 [ 539.681777][T11645] unevictable:780 dirty:28 writeback:0 [ 539.681777][T11645] slab_reclaimable:10094 slab_unreclaimable:99435 [ 539.681777][T11645] mapped:29402 shmem:1417 pagetables:916 [ 539.681777][T11645] sec_pagetables:0 bounce:0 [ 539.681777][T11645] kernel_misc_reclaimable:0 [ 539.681777][T11645] free:1293964 free_pcp:2189 free_cma:0 [ 539.762569][T11645] Node 0 active_anon:21552kB inactive_anon:0kB active_file:31284kB inactive_file:153964kB unevictable:1584kB isolated(anon):0kB isolated(file):0kB mapped:117608kB dirty:112kB writeback:0kB shmem:4132kB shmem_thp:0kB shmem_pmdmapped:0kB anon_thp:0kB writeback_tmp:0kB kernel_stack:10532kB pagetables:3664kB sec_pagetables:0kB all_unreclaimable? no Balloon:0kB [ 539.845271][T11645] Node 1 active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:72kB unevictable:1536kB isolated(anon):0kB isolated(file):0kB mapped:0kB dirty:0kB writeback:0kB shmem:1536kB shmem_thp:0kB shmem_pmdmapped:0kB anon_thp:0kB writeback_tmp:0kB kernel_stack:48kB pagetables:0kB sec_pagetables:0kB all_unreclaimable? no Balloon:0kB [ 539.954656][T11645] Node 0 DMA free:15360kB boost:0kB min:208kB low:260kB high:312kB reserved_highatomic:0KB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15360kB mlocked:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB [ 540.018428][T11645] lowmem_reserve[]: 0 2487 2487 2487 2487 [ 540.032361][T11645] Node 0 DMA32 free:1241068kB boost:0kB min:34152kB low:42688kB high:51224kB reserved_highatomic:0KB active_anon:21784kB inactive_anon:0kB active_file:31284kB inactive_file:153872kB unevictable:1584kB writepending:112kB present:3129332kB managed:2547264kB mlocked:0kB bounce:0kB free_pcp:8432kB local_pcp:7668kB free_cma:0kB [ 540.143989][T11645] lowmem_reserve[]: 0 0 0 0 0 [ 540.164404][T11645] Node 0 Normal free:0kB boost:0kB min:0kB low:0kB high:0kB reserved_highatomic:0KB active_anon:8kB inactive_anon:0kB active_file:0kB inactive_file:92kB unevictable:0kB writepending:0kB present:1048580kB managed:108kB mlocked:0kB bounce:0kB free_pcp:8kB local_pcp:8kB free_cma:0kB [ 540.207229][T11645] lowmem_reserve[]: 0 0 0 0 0 [ 540.223712][T11645] Node 1 Normal free:3912440kB boost:0kB min:55748kB low:69684kB high:83620kB reserved_highatomic:0KB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:72kB unevictable:1536kB writepending:0kB present:4194300kB managed:4111164kB mlocked:0kB bounce:0kB free_pcp:4kB local_pcp:0kB free_cma:0kB [ 540.271795][T11645] lowmem_reserve[]: 0 0 0 0 0 [ 540.279061][T11645] Node 0 DMA: 0*4kB 0*8kB 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB 0*512kB 1*1024kB (U) 1*2048kB (M) 3*4096kB (M) = 15360kB [ 540.292146][T11645] Node 0 DMA32: 634*4kB (UME) 814*8kB (UME) 156*16kB (UME) 232*32kB (UM) 119*64kB (UME) 24*128kB (UME) 81*256kB (UM) 70*512kB (UM) 39*1024kB (UME) 20*2048kB (UE) 262*4096kB (UM) = 1240280kB [ 540.312606][T11645] Node 0 Normal: 0*4kB 0*8kB 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 0kB [ 540.328246][T11645] Node 1 Normal: 192*4kB (UE) 47*8kB (UME) 32*16kB (UME) 160*32kB (UME) 86*64kB (UME) 28*128kB [ 540.328751][T11749] pim6reg1: entered promiscuous mode [ 540.348923][T11749] pim6reg1: entered allmulticast mode [ 540.357078][T11645] (UME) 15*256kB (UME) 5*512kB (UM) 3*1024kB (UME) 4*2048kB (UME) 947*4096kB (M) = 3912440kB [ 540.392071][T11645] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 540.402335][T11645] Node 0 hugepages_total=4 hugepages_free=3 hugepages_surp=0 hugepages_size=2048kB [ 540.411791][T11645] Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 540.424755][T11645] Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB [ 540.434261][T11645] 47750 total pagecache pages [ 540.450500][ T30] kauditd_printk_skb: 60 callbacks suppressed [ 540.450520][ T30] audit: type=1326 audit(1743764709.437:1585): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.454515][T11645] 0 pages in swap cache [ 540.462911][ T30] audit: type=1326 audit(1743764709.437:1586): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.489029][T11645] Free swap = 124996kB [ 540.511849][T11645] Total swap = 124996kB [ 540.516088][T11645] 2097051 pages RAM [ 540.529710][T11645] 0 pages HighMem/MovableOnly [ 540.556121][ T30] audit: type=1326 audit(1743764709.477:1587): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.565566][T11645] 428577 pages reserved [ 540.589462][T11759] tipc: Started in network mode [ 540.594368][T11759] tipc: Node identity 52, cluster identity 4711 [ 540.612028][ T30] audit: type=1326 audit(1743764709.477:1588): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.627752][T11759] tipc: Node number set to 82 [ 540.648967][T11645] 0 pages cma reserved [ 540.659146][ T30] audit: type=1326 audit(1743764709.477:1589): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.733263][ T30] audit: type=1326 audit(1743764709.507:1590): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.785099][T11765] netlink: 40 bytes leftover after parsing attributes in process `syz.2.2222'. [ 540.797716][ T30] audit: type=1326 audit(1743764709.507:1591): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.885336][ T30] audit: type=1326 audit(1743764709.507:1592): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.933955][ T30] audit: type=1326 audit(1743764709.507:1593): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 540.993212][ T30] audit: type=1326 audit(1743764709.507:1594): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11753 comm="syz.3.2218" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 541.430820][T11792] IPVS: sync thread started: state = BACKUP, mcast_ifn = netdevsim0, syncid = 1, id = 0 [ 542.546731][T11822] netlink: 44 bytes leftover after parsing attributes in process `syz.4.2247'. [ 544.463031][T11878] veth0_macvtap: left promiscuous mode [ 544.492827][T11878] macvtap0: refused to change device tx_queue_len [ 545.457598][ T30] kauditd_printk_skb: 94 callbacks suppressed [ 545.457618][ T30] audit: type=1326 audit(1743764714.447:1689): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 545.563938][ T30] audit: type=1326 audit(1743764714.497:1690): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=13 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 545.661049][ T30] audit: type=1326 audit(1743764714.497:1691): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 545.719907][T11917] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2289'. [ 545.743474][ T30] audit: type=1326 audit(1743764714.497:1692): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 545.785431][T11917] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2289'. [ 545.819303][ T30] audit: type=1326 audit(1743764714.497:1693): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 545.945483][ T30] audit: type=1326 audit(1743764714.497:1694): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 546.041004][ T30] audit: type=1326 audit(1743764714.497:1695): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 546.126280][ T30] audit: type=1326 audit(1743764714.497:1696): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 546.231282][ T30] audit: type=1326 audit(1743764714.497:1697): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 546.325052][ T30] audit: type=1326 audit(1743764714.497:1698): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11905 comm="syz.2.2283" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 546.356034][T11942] netlink: 8 bytes leftover after parsing attributes in process `syz.3.2300'. [ 546.379637][T11943] netlink: 4 bytes leftover after parsing attributes in process `syz.4.2301'. [ 547.121062][T11970] netlink: 8 bytes leftover after parsing attributes in process `syz.2.2313'. [ 547.436639][T11983] netlink: 'syz.0.2320': attribute type 15 has an invalid length. [ 547.669563][T11996] netlink: 8 bytes leftover after parsing attributes in process `syz.4.2326'. [ 547.835600][T12007] netlink: 8 bytes leftover after parsing attributes in process `+}[@'. [ 547.973439][T12012] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2332'. [ 547.985463][T12012] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2332'. [ 548.002660][T12015] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2334'. [ 548.030571][T12012] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2332'. [ 548.322365][T12033] sch_tbf: burst 3298 is lower than device lo mtu (65550) ! [ 548.687920][T12052] netdevsim netdevsim0 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 548.697456][T12052] netdevsim netdevsim0 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 548.708378][T12052] netdevsim netdevsim0 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 548.718293][T12052] netdevsim netdevsim0 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 548.761227][T12052] netdevsim netdevsim0 netdevsim0: unset [0, 0] type 1 family 0 port 8472 - 0 [ 548.770574][T12052] netdevsim netdevsim0 netdevsim1: unset [0, 0] type 1 family 0 port 8472 - 0 [ 548.780063][T12052] netdevsim netdevsim0 netdevsim2: unset [0, 0] type 1 family 0 port 8472 - 0 [ 548.789324][T12052] netdevsim netdevsim0 netdevsim3: unset [0, 0] type 1 family 0 port 8472 - 0 [ 550.881620][ T30] kauditd_printk_skb: 79 callbacks suppressed [ 550.881640][ T30] audit: type=1326 audit(1743764719.867:1778): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 550.974983][ T30] audit: type=1326 audit(1743764719.867:1779): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.000761][ T30] audit: type=1326 audit(1743764719.907:1780): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.031967][ T30] audit: type=1326 audit(1743764719.907:1781): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.065047][ T30] audit: type=1326 audit(1743764719.907:1782): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.100092][ T30] audit: type=1326 audit(1743764719.927:1783): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.143529][T12153] __nla_validate_parse: 12 callbacks suppressed [ 551.143552][T12153] netlink: 28 bytes leftover after parsing attributes in process `syz.3.2390'. [ 551.163248][ T30] audit: type=1326 audit(1743764719.927:1784): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.224256][ T30] audit: type=1326 audit(1743764719.927:1785): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.294204][ T30] audit: type=1326 audit(1743764719.927:1786): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=149 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.380577][ T30] audit: type=1326 audit(1743764720.367:1787): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12144 comm="syz.2.2388" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f9cc998d169 code=0x7ffc0000 [ 551.628180][T12163] rdma_op ffff888032c409f0 conn xmit_rdma 0000000000000000 [ 552.625608][T12204] netlink: 12 bytes leftover after parsing attributes in process `syz.2.2412'. [ 554.454207][ T53] IPVS: starting estimator thread 0... [ 554.565494][T12276] IPVS: using max 28 ests per chain, 67200 per kthread [ 555.560248][T12302] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2454'. [ 555.683839][T12309] pimreg3: entered allmulticast mode [ 555.694878][T12308] pimreg3: left allmulticast mode [ 555.872140][ T53] hid-generic 0000:0000:20000000.0016: unknown main item tag 0x0 [ 555.890225][ T30] kauditd_printk_skb: 46 callbacks suppressed [ 555.890246][ T30] audit: type=1326 audit(1743764724.877:1834): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7fb1ce584127 code=0x7ffc0000 [ 555.901687][ T53] hid-generic 0000:0000:20000000.0016: item fetching failed at offset 8/43 [ 555.944448][ T30] audit: type=1326 audit(1743764724.917:1835): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fb1ce529359 code=0x7ffc0000 [ 556.004597][ T30] audit: type=1326 audit(1743764724.917:1836): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7fb1ce584127 code=0x7ffc0000 [ 556.008290][ T53] hid-generic 0000:0000:20000000.0016: probe with driver hid-generic failed with error -22 [ 556.101105][ T30] audit: type=1326 audit(1743764724.917:1837): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fb1ce529359 code=0x7ffc0000 [ 556.133403][ T30] audit: type=1326 audit(1743764724.917:1838): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=437 compat=0 ip=0x7fb1ce58d169 code=0x7ffc0000 [ 556.168844][ T30] audit: type=1326 audit(1743764724.917:1839): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7fb1ce584127 code=0x7ffc0000 [ 556.194846][ T30] audit: type=1326 audit(1743764724.917:1840): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fb1ce529359 code=0x7ffc0000 [ 556.254250][ T30] audit: type=1326 audit(1743764724.917:1841): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=437 compat=0 ip=0x7fb1ce58d169 code=0x7ffc0000 [ 556.302745][ T30] audit: type=1326 audit(1743764724.927:1842): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7fb1ce584127 code=0x7ffc0000 [ 556.372364][ T30] audit: type=1326 audit(1743764724.927:1843): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12312 comm="syz.1.2459" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fb1ce529359 code=0x7ffc0000 [ 556.876469][T12345] netlink: 4 bytes leftover after parsing attributes in process `syz.2.2473'. [ 556.940870][T12347] program syz.3.2474 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 557.745459][ T5897] usb 3-1: new full-speed USB device number 44 using dummy_hcd [ 557.876884][T12375] netlink: 16 bytes leftover after parsing attributes in process `syz.0.2485'. [ 557.925271][ T5897] usb 3-1: config 8 has an invalid interface number: 177 but max is 0 [ 558.018686][ T5897] usb 3-1: config 8 has no interface number 0 [ 558.082965][ T5897] usb 3-1: config 8 interface 177 altsetting 9 has an endpoint descriptor with address 0xE8, changing to 0x88 [ 558.193328][ T5897] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x88 has invalid maxpacket 1023, setting to 64 [ 558.249504][ T5897] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x87 has invalid wMaxPacketSize 0 [ 558.274253][ T5897] usb 3-1: config 8 interface 177 has no altsetting 0 [ 558.290591][ T5897] usb 3-1: New USB device found, idVendor=04d8, idProduct=fd08, bcdDevice=59.b1 [ 558.365279][ T3079] usb 4-1: new high-speed USB device number 49 using dummy_hcd [ 558.462590][ T5897] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 558.525329][ T3079] usb 4-1: device descriptor read/64, error -71 [ 558.713902][T12369] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 558.796716][ T3079] usb 4-1: new high-speed USB device number 50 using dummy_hcd [ 558.996739][ T3079] usb 4-1: device descriptor read/64, error -71 [ 559.007133][T12369] input: syz0 as /devices/virtual/input/input41 [ 559.109523][T12369] netlink: 12 bytes leftover after parsing attributes in process `syz.2.2482'. [ 559.145715][ T3079] usb usb4-port1: attempt power cycle [ 559.384719][T12383] Bluetooth: hci0: Opcode 0x0c1a failed: -4 [ 559.403584][T12383] Bluetooth: hci1: Opcode 0x0c1a failed: -4 [ 559.508308][T12383] Bluetooth: hci3: Opcode 0x0c1a failed: -4 [ 559.524641][T12383] Bluetooth: hci4: Opcode 0x0c1a failed: -4 [ 559.565294][ T3079] usb 4-1: new high-speed USB device number 51 using dummy_hcd [ 559.620572][T12383] Bluetooth: hci2: Opcode 0x0c1a failed: -4 [ 559.884068][ T3079] usb 4-1: device descriptor read/8, error -71 [ 560.155740][ T3079] usb 4-1: new high-speed USB device number 52 using dummy_hcd [ 560.421205][ T3079] usb 4-1: device descriptor read/8, error -71 [ 560.595543][ T3079] usb usb4-port1: unable to enumerate USB device [ 561.121098][ T5897] usb 3-1: string descriptor 0 read error: -71 [ 561.132685][ T5897] ir_toy 3-1:8.177: required endpoints not found [ 561.206666][ T5897] usb 3-1: USB disconnect, device number 44 [ 561.365707][ T5843] Bluetooth: hci0: command 0x0c1a tx timeout [ 561.445381][ T5843] Bluetooth: hci1: command 0x0c1a tx timeout [ 561.525595][ T5843] Bluetooth: hci4: command 0x0c1a tx timeout [ 561.526170][ T5854] Bluetooth: hci3: command 0x0c1a tx timeout [ 561.685489][ T5854] Bluetooth: hci2: command 0x0405 tx timeout [ 562.064796][T12435] netlink: 8 bytes leftover after parsing attributes in process `syz.0.2509'. [ 562.211583][T12430] Bluetooth: hci0: Opcode 0x0c1a failed: -4 [ 562.221057][T12445] fuse: Bad value for 'fd' [ 562.229980][T12430] Bluetooth: hci1: Opcode 0x0c1a failed: -4 [ 562.245737][T12430] Bluetooth: hci3: Opcode 0x0c1a failed: -4 [ 562.252884][T12430] Bluetooth: hci4: Opcode 0x0c1a failed: -4 [ 562.269061][T12430] Bluetooth: hci2: Opcode 0x0c1a failed: -4 [ 562.425035][T12449] loop8: detected capacity change from 0 to 7 [ 562.443917][T12449] Dev loop8: unable to read RDB block 7 [ 562.477131][T12449] loop8: unable to read partition table [ 562.494825][T12449] loop8: partition table beyond EOD, truncated [ 562.512389][T12449] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 562.512389][T12449] ) failed (rc=-5) [ 562.891341][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 562.898089][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 564.175459][ T5854] Bluetooth: hci0: command 0x0c1a tx timeout [ 564.245285][ T5854] Bluetooth: hci1: command 0x0c1a tx timeout [ 564.325526][ T5854] Bluetooth: hci2: command 0x0405 tx timeout [ 564.325794][ T5843] Bluetooth: hci4: command 0x0c1a tx timeout [ 564.331607][ T5840] Bluetooth: hci3: command 0x0c1a tx timeout [ 564.347883][T12502] netlink: 16 bytes leftover after parsing attributes in process `syz.1.2534'. [ 565.972733][ T5897] usb 3-1: new full-speed USB device number 45 using dummy_hcd [ 566.098691][T12543] netlink: 8 bytes leftover after parsing attributes in process `syz.4.2550'. [ 566.146943][ T3079] usb 4-1: new full-speed USB device number 53 using dummy_hcd [ 566.209151][ T5897] usb 3-1: config 8 has an invalid interface number: 177 but max is 0 [ 566.219580][ T5897] usb 3-1: config 8 has no interface number 0 [ 566.235553][ T5897] usb 3-1: config 8 interface 177 altsetting 9 has an endpoint descriptor with address 0xE8, changing to 0x88 [ 566.254338][ T5897] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x88 has invalid maxpacket 1023, setting to 64 [ 566.295332][ T5897] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x87 has invalid wMaxPacketSize 0 [ 566.322600][ T5897] usb 3-1: config 8 interface 177 has no altsetting 0 [ 566.339826][ T5897] usb 3-1: New USB device found, idVendor=04d8, idProduct=fd08, bcdDevice=59.b1 [ 566.359130][ T3079] usb 4-1: config 5 has an invalid interface number: 123 but max is 0 [ 566.368853][ T3079] usb 4-1: config 5 has no interface number 0 [ 566.375096][ T3079] usb 4-1: config 5 interface 123 altsetting 7 has an endpoint descriptor with address 0xEB, changing to 0x8B [ 566.387168][ T5897] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 566.388759][ T3079] usb 4-1: config 5 interface 123 altsetting 7 endpoint 0x4 has invalid maxpacket 12338, setting to 64 [ 566.407074][ T3079] usb 4-1: config 5 interface 123 has no altsetting 0 [ 566.434335][T12535] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 566.454657][ T3079] usb 4-1: New USB device found, idVendor=3923, idProduct=718a, bcdDevice=d8.d7 [ 566.509231][ T3079] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 566.536323][ T3079] usb 4-1: Product: syz [ 566.594178][ T3079] usb 4-1: Manufacturer: syz [ 566.603540][ T3079] usb 4-1: SerialNumber: syz [ 566.632447][T12542] raw-gadget.2 gadget.3: fail, usb_ep_enable returned -22 [ 566.663840][T12535] input: syz0 as /devices/virtual/input/input42 [ 566.711866][T12535] netlink: 12 bytes leftover after parsing attributes in process `syz.2.2546'. [ 566.908204][T12542] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 567.055726][T12542] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 567.201885][ T3079] comedi comedi0: driver 'ni6501' has successfully auto-configured 'ni6501'. [ 567.236150][ T3079] usb 4-1: USB disconnect, device number 53 [ 568.029873][T12559] bridge0: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 568.076418][T12559] bridge0: port 3(vlan3) entered disabled state [ 568.082864][T12559] bridge0: port 2(bridge_slave_1) entered disabled state [ 568.090227][T12559] bridge0: port 1(bridge_slave_0) entered disabled state [ 568.815582][T12569] netlink: 16 bytes leftover after parsing attributes in process `syz.0.2562'. [ 569.272726][ T5897] usb 3-1: string descriptor 0 read error: -71 [ 569.333576][ T5897] ir_toy 3-1:8.177: required endpoints not found [ 569.400723][ T5897] usb 3-1: USB disconnect, device number 45 [ 569.859060][T12596] cgroup: fork rejected by pids controller in /syz1 [ 569.881723][T12596] netlink: 20 bytes leftover after parsing attributes in process `syz.1.2574'. [ 570.023757][ T5854] Bluetooth: hci1: unexpected event for opcode 0x0c7a [ 570.392216][ T82] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 570.530531][ T82] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 570.650156][ T82] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 570.793272][ T82] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 571.476033][T12730] netlink: 8 bytes leftover after parsing attributes in process `syz.2.2583'. [ 571.496243][ T82] vlan3: left promiscuous mode [ 571.501360][ T82] bond0: left promiscuous mode [ 571.582072][ T82] bond_slave_0: left promiscuous mode [ 571.604836][ T82] bond_slave_1: left promiscuous mode [ 571.607286][ T5854] Bluetooth: hci2: command 0x0405 tx timeout [ 571.649604][ T82] bridge0: port 3(vlan3) entered disabled state [ 571.864927][ T82] bridge_slave_1: left allmulticast mode [ 571.884361][ T82] bridge_slave_1: left promiscuous mode [ 571.934627][ T82] bridge0: port 2(bridge_slave_1) entered disabled state [ 572.143994][ T5854] Bluetooth: hci3: unexpected cc 0x0c03 length: 249 > 1 [ 572.156244][ T5854] Bluetooth: hci3: unexpected cc 0x1003 length: 249 > 9 [ 572.164489][ T5854] Bluetooth: hci3: unexpected cc 0x1001 length: 249 > 9 [ 572.173329][ T5854] Bluetooth: hci3: unexpected cc 0x0c23 length: 249 > 4 [ 572.181264][ T5854] Bluetooth: hci3: unexpected cc 0x0c38 length: 249 > 2 [ 572.314020][ T82] bridge_slave_0: left allmulticast mode [ 572.325525][ T82] bridge_slave_0: left promiscuous mode [ 572.331494][ T82] bridge0: port 1(bridge_slave_0) entered disabled state [ 573.481719][T12763] vcan0: tx drop: invalid da for name 0x00000000fffffffe [ 573.557846][T12765] netlink: 16 bytes leftover after parsing attributes in process `syz.3.2592'. [ 573.981403][ T82] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 574.009367][ T82] bond_slave_0: left allmulticast mode [ 574.072771][ T82] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 574.099122][ T82] bond_slave_1: left allmulticast mode [ 574.142972][ T82] bond0 (unregistering): Released all slaves [ 574.245359][ T5854] Bluetooth: hci3: command tx timeout [ 574.365555][ T82] tipc: Left network mode [ 575.153682][ T82] hsr_slave_0: left promiscuous mode [ 575.178283][ T82] hsr_slave_1: left promiscuous mode [ 575.371511][ T82] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 575.403459][ T82] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 575.426886][ T82] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 575.437342][ T82] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 575.528280][ T82] veth1_macvtap: left promiscuous mode [ 575.549082][T12798] netlink: 8 bytes leftover after parsing attributes in process `syz.0.2600'. [ 575.562480][ T82] veth0_macvtap: left promiscuous mode [ 575.591021][ T82] veth1_vlan: left promiscuous mode [ 575.622552][ T82] veth0_vlan: left promiscuous mode [ 576.261202][ T9] usb 3-1: new full-speed USB device number 46 using dummy_hcd [ 576.325601][ T5854] Bluetooth: hci3: command tx timeout [ 576.497418][ T9] usb 3-1: config 8 has an invalid interface number: 177 but max is 0 [ 576.857879][ T9] usb 3-1: config 8 has no interface number 0 [ 576.877991][ T9] usb 3-1: config 8 interface 177 altsetting 9 has an endpoint descriptor with address 0xE8, changing to 0x88 [ 576.916455][ T9] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x88 has invalid maxpacket 1023, setting to 64 [ 576.936848][ T9] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x87 has invalid wMaxPacketSize 0 [ 576.965484][ T9] usb 3-1: config 8 interface 177 has no altsetting 0 [ 576.976239][ T9] usb 3-1: New USB device found, idVendor=04d8, idProduct=fd08, bcdDevice=59.b1 [ 577.026421][ T9] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 577.061116][T12820] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 577.279912][T12820] input: syz0 as /devices/virtual/input/input45 [ 577.370929][T12826] netlink: 12 bytes leftover after parsing attributes in process `syz.2.2604'. [ 578.405341][ T5854] Bluetooth: hci3: command tx timeout [ 578.532292][T12754] chnl_net:caif_netlink_parms(): no params data found [ 579.140109][T12754] bridge0: port 1(bridge_slave_0) entered blocking state [ 579.170700][T12754] bridge0: port 1(bridge_slave_0) entered disabled state [ 579.178337][T12754] bridge_slave_0: entered allmulticast mode [ 579.186962][T12754] bridge_slave_0: entered promiscuous mode [ 579.198480][T12754] bridge0: port 2(bridge_slave_1) entered blocking state [ 579.206083][T12754] bridge0: port 2(bridge_slave_1) entered disabled state [ 579.214634][T12754] bridge_slave_1: entered allmulticast mode [ 579.231779][T12754] bridge_slave_1: entered promiscuous mode [ 579.388062][T12754] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 579.419846][T12754] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 579.561412][T12754] team0: Port device team_slave_0 added [ 579.583658][T12754] team0: Port device team_slave_1 added [ 579.645349][ T47] usb 4-1: new high-speed USB device number 54 using dummy_hcd [ 579.678598][T12754] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 579.686917][T12754] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 579.750761][T12754] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 579.784051][T12754] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 579.791259][T12754] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 579.818711][T12754] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 579.831652][ T47] usb 4-1: Using ep0 maxpacket: 16 [ 579.850080][ T47] usb 4-1: config index 0 descriptor too short (expected 6180, got 36) [ 579.859334][ T47] usb 4-1: config 0 has an invalid interface number: 251 but max is 0 [ 579.872481][ T47] usb 4-1: config 0 has no interface number 0 [ 579.906483][ T47] usb 4-1: config 0 interface 251 altsetting 0 bulk endpoint 0x4 has invalid maxpacket 16 [ 579.953321][ T47] usb 4-1: config 0 interface 251 altsetting 0 bulk endpoint 0x82 has invalid maxpacket 64 [ 579.982469][ T47] usb 4-1: New USB device found, idVendor=0b95, idProduct=172a, bcdDevice=f7.f4 [ 580.043521][ T47] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 580.068002][ T47] usb 4-1: Product: syz [ 580.100086][T12754] hsr_slave_0: entered promiscuous mode [ 580.118297][ T47] usb 4-1: Manufacturer: syz [ 580.129370][ T47] usb 4-1: SerialNumber: syz [ 580.168503][T12754] hsr_slave_1: entered promiscuous mode [ 580.177934][ T47] usb 4-1: config 0 descriptor?? [ 580.246001][T12858] raw-gadget.1 gadget.3: fail, usb_ep_enable returned -22 [ 580.256747][T12754] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 580.302040][ T9] usb 3-1: string descriptor 0 read error: -71 [ 580.325628][T12858] raw-gadget.1 gadget.3: fail, usb_ep_enable returned -22 [ 580.349229][T12754] Cannot create hsr debugfs directory [ 580.369190][T12875] veth1_macvtap: left promiscuous mode [ 580.391486][T12875] macsec0: entered promiscuous mode [ 580.409044][ T9] ir_toy 3-1:8.177: required endpoints not found [ 580.478973][T12877] veth1_macvtap: entered promiscuous mode [ 580.485649][ T5854] Bluetooth: hci3: command tx timeout [ 580.491806][ T9] usb 3-1: USB disconnect, device number 46 [ 580.499410][T12877] macsec0: left promiscuous mode [ 580.601686][T12858] raw-gadget.1 gadget.3: fail, usb_ep_enable returned -22 [ 580.648264][T12858] raw-gadget.1 gadget.3: fail, usb_ep_enable returned -22 [ 581.089668][ T47] asix 4-1:0.251 (unnamed net_device) (uninitialized): Interface mode not supported by driver [ 581.166338][ T47] asix 4-1:0.251: probe with driver asix failed with error -524 [ 581.312307][ T47] usb 4-1: USB disconnect, device number 54 [ 581.893547][T12754] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 581.949579][T12754] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 581.982775][T12754] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 582.064757][T12754] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 582.218134][T12754] 8021q: adding VLAN 0 to HW filter on device bond0 [ 582.256876][T12754] 8021q: adding VLAN 0 to HW filter on device team0 [ 582.286236][ T13] bridge0: port 1(bridge_slave_0) entered blocking state [ 582.293399][ T13] bridge0: port 1(bridge_slave_0) entered forwarding state [ 582.343210][ T13] bridge0: port 2(bridge_slave_1) entered blocking state [ 582.350399][ T13] bridge0: port 2(bridge_slave_1) entered forwarding state [ 582.379475][ T3079] usb 4-1: new high-speed USB device number 55 using dummy_hcd [ 582.540074][ T3079] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 582.553150][T12754] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 582.581681][ T3079] usb 4-1: New USB device found, idVendor=8086, idProduct=0b63, bcdDevice=ca.f3 [ 582.596266][ T3079] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 582.623903][ T3079] usb 4-1: Product: syz [ 582.650432][ T3079] usb 4-1: Manufacturer: syz [ 582.673900][ T3079] usb 4-1: SerialNumber: syz [ 582.717542][ T3079] usb 4-1: config 0 descriptor?? [ 582.727968][T12754] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 582.744890][ T3079] ljca 4-1:0.0: bulk endpoints not found [ 582.847226][T12754] veth0_vlan: entered promiscuous mode [ 582.859178][T12754] veth1_vlan: entered promiscuous mode [ 582.907354][T12754] veth0_macvtap: entered promiscuous mode [ 582.922324][T12754] veth1_macvtap: entered promiscuous mode [ 582.949380][T12915] netlink: 8 bytes leftover after parsing attributes in process `syz.3.2622'. [ 582.968629][T12915] netlink: 24 bytes leftover after parsing attributes in process `syz.3.2622'. [ 582.986477][T12754] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 583.002723][T12754] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 583.012963][T12754] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 583.029666][T12754] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 583.042720][T12754] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 583.066166][T12754] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 583.083936][T12754] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 583.122560][T12754] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 583.142378][T12754] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 583.158290][T12754] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 583.173550][T12754] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 583.192993][T12754] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 583.227008][T12754] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 583.245797][T12754] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 583.269052][T12754] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 583.311513][T12754] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 583.585879][ T13] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 583.608444][ T13] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 583.711397][ T54] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 583.723839][ T54] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 584.056077][T12939] vcan0: tx drop: invalid da for name 0x00f0000000000000 [ 584.066476][T12938] bridge0: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 584.114151][T12938] bridge0: port 2(bridge_slave_1) entered disabled state [ 584.123071][T12938] bridge0: port 1(bridge_slave_0) entered disabled state [ 584.504846][T12952] loop8: detected capacity change from 0 to 7 [ 584.524292][T12952] Dev loop8: unable to read RDB block 7 [ 584.544771][T12952] loop8: unable to read partition table [ 584.560746][T12952] loop8: partition table beyond EOD, truncated [ 584.583730][T12952] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 584.583730][T12952] ) failed (rc=-5) [ 585.089806][ T5935] usb 4-1: USB disconnect, device number 55 [ 585.325510][T12980] netlink: 'syz.2.2637': attribute type 27 has an invalid length. [ 585.661366][T12995] bridge0: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 586.615423][ T5935] usb 5-1: new high-speed USB device number 51 using dummy_hcd [ 586.623326][ C1] raw-gadget.0 gadget.4: ignoring, device is not running [ 586.687659][T13021] netlink: 8 bytes leftover after parsing attributes in process `syz.2.2644'. [ 586.755527][ T5935] usb 5-1: device descriptor read/64, error -32 [ 586.996888][ T5935] usb 5-1: new high-speed USB device number 52 using dummy_hcd [ 587.017573][ C1] raw-gadget.0 gadget.4: ignoring, device is not running [ 587.155464][ T5935] usb 5-1: device descriptor read/64, error -32 [ 587.278901][ T5935] usb usb5-port1: attempt power cycle [ 587.665371][ T5935] usb 5-1: new high-speed USB device number 53 using dummy_hcd [ 587.694983][T13048] Cannot find map_set index 0 as target [ 587.778610][ T30] kauditd_printk_skb: 126 callbacks suppressed [ 587.778632][ T30] audit: type=1804 audit(1743764756.767:1970): pid=13052 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=invalid_pcr cause=ToMToU comm="syz.3.2651" name="/newroot/540/file1" dev="fuse" ino=1 res=1 errno=0 [ 588.016124][T13055] ip6t_srh: unknown srh match flags B153 [ 588.125032][T13058] netlink: 4 bytes leftover after parsing attributes in process `syz.1.2654'. [ 588.348036][ T5935] usb 5-1: config 0 has no interfaces? [ 588.357755][ T5935] usb 5-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 588.367303][ T5935] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 588.391874][ T5935] usb 5-1: Product: syz [ 588.396682][ T5935] usb 5-1: Manufacturer: syz [ 588.401626][ T5935] usb 5-1: SerialNumber: syz [ 588.447660][ T5935] usb 5-1: config 0 descriptor?? [ 589.452584][T13087] FAULT_INJECTION: forcing a failure. [ 589.452584][T13087] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 589.491181][T13087] CPU: 1 UID: 0 PID: 13087 Comm: syz.0.2660 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 589.491216][T13087] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 589.491231][T13087] Call Trace: [ 589.491240][T13087] [ 589.491250][T13087] dump_stack_lvl+0x241/0x360 [ 589.491291][T13087] ? __pfx_dump_stack_lvl+0x10/0x10 [ 589.491323][T13087] ? __pfx__printk+0x10/0x10 [ 589.491368][T13087] should_fail_ex+0x424/0x570 [ 589.491396][T13087] _copy_from_user+0x2d/0xb0 [ 589.491428][T13087] copy_msghdr_from_user+0xb3/0x580 [ 589.491463][T13087] ? __pfx_copy_msghdr_from_user+0x10/0x10 [ 589.491488][T13087] ? __fget_files+0x2a/0x420 [ 589.491516][T13087] ? __fget_files+0x2a/0x420 [ 589.491546][T13087] __sys_recvmsg+0x210/0x3a0 [ 589.491575][T13087] ? __pfx___sys_recvmsg+0x10/0x10 [ 589.491612][T13087] ? __fget_files+0x2a/0x420 [ 589.491659][T13087] ? do_syscall_64+0xb6/0x230 [ 589.491687][T13087] do_syscall_64+0xf3/0x230 [ 589.491712][T13087] ? clear_bhb_loop+0x45/0xa0 [ 589.491738][T13087] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 589.491759][T13087] RIP: 0033:0x7f7e8878d169 [ 589.491779][T13087] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 589.491797][T13087] RSP: 002b:00007f7e895ca038 EFLAGS: 00000246 ORIG_RAX: 000000000000002f [ 589.491821][T13087] RAX: ffffffffffffffda RBX: 00007f7e889a5fa0 RCX: 00007f7e8878d169 [ 589.491837][T13087] RDX: 0000000000012060 RSI: 0000200000000180 RDI: 0000000000000004 [ 589.491852][T13087] RBP: 00007f7e895ca090 R08: 0000000000000000 R09: 0000000000000000 [ 589.491866][T13087] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 589.491879][T13087] R13: 0000000000000000 R14: 00007f7e889a5fa0 R15: 00007f7e88acfa28 [ 589.491911][T13087] [ 589.676762][ C1] vkms_vblank_simulate: vblank timer overrun [ 590.130401][T13113] dvmrp0: entered allmulticast mode [ 590.140968][T13113] loop8: detected capacity change from 0 to 8 [ 590.153369][T13113] Dev loop8: unable to read RDB block 8 [ 590.167059][T13113] loop8: unable to read partition table [ 590.180208][T13113] loop8: partition table beyond EOD, truncated [ 590.187442][T13101] Bluetooth: hci0: Opcode 0x0c1a failed: -4 [ 590.195656][T13101] Bluetooth: hci1: Opcode 0x0c1a failed: -4 [ 590.207589][T13101] Bluetooth: hci4: Opcode 0x0c1a failed: -4 [ 590.213764][T13101] Bluetooth: hci2: Opcode 0x0c1a failed: -4 [ 590.220369][T13113] loop_reread_partitions: partition scan of loop8 (被x^>& 2t) failed (rc=-5) [ 590.324690][T13101] Bluetooth: hci3: Opcode 0x0c1a failed: -4 [ 590.333525][T13101] Bluetooth: hci3: Opcode 0x0406 failed: -4 [ 590.413288][T13101] Bluetooth: hci3: Opcode 0x0406 failed: -4 [ 590.702871][T13137] sctp: [Deprecated]: syz.3.2671 (pid 13137) Use of int in max_burst socket option deprecated. [ 590.702871][T13137] Use struct sctp_assoc_value instead [ 590.915299][ T5935] usb 3-1: new high-speed USB device number 47 using dummy_hcd [ 590.994933][ T53] usb 5-1: USB disconnect, device number 53 [ 591.077878][ T5935] usb 3-1: config 17 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 591.089835][ T5935] usb 3-1: config 17 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 255, changing to 11 [ 591.102360][ T5935] usb 3-1: config 17 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 591.114511][ T5935] usb 3-1: New USB device found, idVendor=0458, idProduct=5003, bcdDevice= 0.00 [ 591.123842][ T5935] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 591.145470][T13134] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 591.315297][T13163] loop8: detected capacity change from 0 to 7 [ 591.322609][T13163] Dev loop8: unable to read RDB block 7 [ 591.328992][T13163] loop8: unable to read partition table [ 591.335116][T13163] loop8: partition table beyond EOD, truncated [ 591.342132][T13163] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 591.342132][T13163] ) failed (rc=-5) [ 591.372694][ T5935] aiptek 3-1:17.0: Aiptek using 400 ms programming speed [ 591.400970][ T5935] input: Aiptek as /devices/platform/dummy_hcd.2/usb3/3-1/3-1:17.0/input/input46 [ 591.477841][ T5935] usb 3-1: USB disconnect, device number 47 [ 591.483861][ C1] aiptek 3-1:17.0: aiptek_irq - usb_submit_urb failed with result -19 [ 591.845682][ T9] usb 4-1: new high-speed USB device number 56 using dummy_hcd [ 591.992577][T13173] vlan2: entered promiscuous mode [ 592.017132][ T9] usb 4-1: config 0 has no interfaces? [ 592.029711][ T9] usb 4-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 592.061600][ T9] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 592.075483][ T9] usb 4-1: Product: syz [ 592.079690][ T9] usb 4-1: Manufacturer: syz [ 592.084313][ T9] usb 4-1: SerialNumber: syz [ 592.085731][ T5854] Bluetooth: hci0: command 0x0c1a tx timeout [ 592.115292][ T9] usb 4-1: config 0 descriptor?? [ 592.245545][ T5843] Bluetooth: hci4: command 0x0c1a tx timeout [ 592.251649][ T5840] Bluetooth: hci1: command 0x0c1a tx timeout [ 592.257903][ T5854] Bluetooth: hci2: command 0x0405 tx timeout [ 592.342165][T13184] netlink: 'syz.2.2688': attribute type 10 has an invalid length. [ 592.372289][T13184] netdevsim netdevsim2 netdevsim0: entered promiscuous mode [ 592.382466][T13184] bond0: (slave netdevsim0): Enslaving as an active interface with an up link [ 592.405411][ T5854] Bluetooth: hci3: command 0x0c1a tx timeout [ 592.417100][ T5935] usb 5-1: new high-speed USB device number 54 using dummy_hcd [ 592.575241][ T5935] usb 5-1: Using ep0 maxpacket: 16 [ 592.593323][ T5935] usb 5-1: config 0 has an invalid interface number: 251 but max is 0 [ 592.616979][ T5935] usb 5-1: config 0 has no interface number 0 [ 592.633206][ T5935] usb 5-1: config 0 interface 251 altsetting 0 bulk endpoint 0x4 has invalid maxpacket 16 [ 592.643703][ T5935] usb 5-1: config 0 interface 251 altsetting 0 bulk endpoint 0x82 has invalid maxpacket 64 [ 592.665307][ T5935] usb 5-1: New USB device found, idVendor=0b95, idProduct=172a, bcdDevice=f7.f4 [ 592.689383][ T5935] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 592.711787][ T5935] usb 5-1: Product: syz [ 592.716108][ T5935] usb 5-1: Manufacturer: syz [ 592.721923][ T5935] usb 5-1: SerialNumber: syz [ 592.732272][ T5935] usb 5-1: config 0 descriptor?? [ 592.738519][T13181] raw-gadget.3 gadget.4: fail, usb_ep_enable returned -22 [ 592.746386][T13181] raw-gadget.3 gadget.4: fail, usb_ep_enable returned -22 [ 592.954999][T13181] raw-gadget.3 gadget.4: fail, usb_ep_enable returned -22 [ 592.963128][T13181] raw-gadget.3 gadget.4: fail, usb_ep_enable returned -22 [ 593.399378][ T5935] asix 5-1:0.251 (unnamed net_device) (uninitialized): Interface mode not supported by driver [ 593.410476][ T5935] asix 5-1:0.251: probe with driver asix failed with error -524 [ 593.595434][ T5845] usb 3-1: new high-speed USB device number 48 using dummy_hcd [ 593.611880][ T9] usb 5-1: USB disconnect, device number 54 [ 593.750829][ T5845] usb 3-1: config 7 has an invalid interface number: 158 but max is 3 [ 593.759166][ T5845] usb 3-1: config 7 contains an unexpected descriptor of type 0x1, skipping [ 593.768652][ T5845] usb 3-1: config 7 contains an unexpected descriptor of type 0x1, skipping [ 593.777664][ T5845] usb 3-1: config 7 has 1 interface, different from the descriptor's value: 4 [ 593.787169][ T5845] usb 3-1: config 7 has no interface number 0 [ 593.793295][ T5845] usb 3-1: config 7 interface 158 altsetting 254 endpoint 0xE has an invalid bInterval 127, changing to 7 [ 593.804803][ T5845] usb 3-1: config 7 interface 158 altsetting 254 has an invalid descriptor for endpoint zero, skipping [ 593.816553][ T5845] usb 3-1: config 7 interface 158 altsetting 254 endpoint 0x5 has invalid maxpacket 2047, setting to 64 [ 593.827797][ T5845] usb 3-1: config 7 interface 158 altsetting 254 has a duplicate endpoint with address 0x5, skipping [ 593.839431][ T5845] usb 3-1: config 7 interface 158 altsetting 254 has an invalid descriptor for endpoint zero, skipping [ 593.850729][ T5845] usb 3-1: config 7 interface 158 altsetting 254 has an invalid descriptor for endpoint zero, skipping [ 593.862118][ T5845] usb 3-1: config 7 interface 158 altsetting 254 has an invalid descriptor for endpoint zero, skipping [ 593.873663][ T5845] usb 3-1: config 7 interface 158 altsetting 254 has 9 endpoint descriptors, different from the interface descriptor's value: 7 [ 593.887718][ T5845] usb 3-1: config 7 interface 158 has no altsetting 0 [ 593.900178][ T5845] usb 3-1: New USB device found, idVendor=8086, idProduct=0b07, bcdDevice=ca.41 [ 593.909415][ T5845] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 593.917867][ T5845] usb 3-1: Product: 䀁 [ 593.922062][ T5845] usb 3-1: Manufacturer: ᰁ [ 593.927338][ T5845] usb 3-1: SerialNumber: 㰘 [ 594.364574][ T5845] usb 3-1: Found UVC 58.d6 device 䀁 (8086:0b07) [ 594.386381][ T5845] usb 3-1: No valid video chain found. [ 594.446175][ T5845] usb 3-1: USB disconnect, device number 48 [ 594.485409][ T5854] Bluetooth: hci3: command 0x0c1a tx timeout [ 594.546440][ T5935] usb 4-1: USB disconnect, device number 56 [ 594.765651][T13218] fuse: Bad value for 'fd' [ 594.775862][T13216] netlink: 196 bytes leftover after parsing attributes in process `syz.1.2700'. [ 594.800258][ T30] audit: type=1326 audit(1743764763.787:1971): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 594.893209][ T30] audit: type=1326 audit(1743764763.787:1972): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 594.951274][ T30] audit: type=1326 audit(1743764763.787:1973): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=41 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.025082][ T30] audit: type=1326 audit(1743764763.787:1974): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.084811][ T30] audit: type=1326 audit(1743764763.787:1975): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.107526][ T30] audit: type=1326 audit(1743764763.787:1976): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=54 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.229926][ T30] audit: type=1326 audit(1743764763.817:1977): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.290240][ T30] audit: type=1326 audit(1743764763.817:1978): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.321203][ T30] audit: type=1326 audit(1743764763.817:1979): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=48 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.368080][ T30] audit: type=1326 audit(1743764763.817:1980): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13214 comm="syz.1.2700" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fcf1b18d169 code=0x7ffc0000 [ 595.561082][T13235] FAULT_INJECTION: forcing a failure. [ 595.561082][T13235] name failslab, interval 1, probability 0, space 0, times 0 [ 595.578626][T13235] CPU: 1 UID: 0 PID: 13235 Comm: syz.4.2707 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 595.578649][T13235] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 595.578659][T13235] Call Trace: [ 595.578665][T13235] [ 595.578672][T13235] dump_stack_lvl+0x241/0x360 [ 595.578701][T13235] ? __pfx_dump_stack_lvl+0x10/0x10 [ 595.578723][T13235] ? __pfx__printk+0x10/0x10 [ 595.578748][T13235] ? __pfx___might_resched+0x10/0x10 [ 595.578770][T13235] should_fail_ex+0x424/0x570 [ 595.578790][T13235] should_failslab+0xac/0x100 [ 595.578812][T13235] __kmalloc_cache_noprof+0x73/0x370 [ 595.578834][T13235] ? alloc_pipe_info+0xeb/0x4d0 [ 595.578857][T13235] alloc_pipe_info+0xeb/0x4d0 [ 595.578887][T13235] splice_direct_to_actor+0xac3/0xc90 [ 595.578910][T13235] ? aa_file_perm+0x3f1/0xf60 [ 595.578941][T13235] ? __pfx_aa_file_perm+0x10/0x10 [ 595.578963][T13235] ? __pfx_direct_splice_actor+0x10/0x10 [ 595.578985][T13235] ? __pfx_splice_direct_to_actor+0x10/0x10 [ 595.579015][T13235] do_splice_direct+0x281/0x3d0 [ 595.579040][T13235] ? __pfx_do_splice_direct+0x10/0x10 [ 595.579062][T13235] ? __pfx_direct_file_splice_eof+0x10/0x10 [ 595.579087][T13235] ? bpf_lsm_file_permission+0x9/0x10 [ 595.579105][T13235] ? rw_verify_area+0x246/0x630 [ 595.579124][T13235] do_sendfile+0x582/0x8c0 [ 595.579154][T13235] ? __pfx_do_sendfile+0x10/0x10 [ 595.579177][T13235] ? __fget_files+0x2a/0x420 [ 595.579198][T13235] __se_sys_sendfile64+0x17e/0x1e0 [ 595.579222][T13235] ? __pfx___se_sys_sendfile64+0x10/0x10 [ 595.579248][T13235] ? do_syscall_64+0xb6/0x230 [ 595.579269][T13235] do_syscall_64+0xf3/0x230 [ 595.579286][T13235] ? clear_bhb_loop+0x45/0xa0 [ 595.579304][T13235] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 595.579319][T13235] RIP: 0033:0x7fc745d8d169 [ 595.579333][T13235] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 595.579346][T13235] RSP: 002b:00007fc746b14038 EFLAGS: 00000246 ORIG_RAX: 0000000000000028 [ 595.579363][T13235] RAX: ffffffffffffffda RBX: 00007fc745fa5fa0 RCX: 00007fc745d8d169 [ 595.579374][T13235] RDX: 0000000000000000 RSI: 0000000000000003 RDI: 0000000000000004 [ 595.579384][T13235] RBP: 00007fc746b14090 R08: 0000000000000000 R09: 0000000000000000 [ 595.579393][T13235] R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000001 [ 595.579402][T13235] R13: 0000000000000000 R14: 00007fc745fa5fa0 R15: 00007fc7460cfa28 [ 595.579424][T13235] [ 595.835641][T13233] IPVS: sh: UDP 224.0.0.2:0 - no destination available [ 595.855850][ T10] IPVS: starting estimator thread 0... [ 595.955563][T13238] IPVS: using max 27 ests per chain, 64800 per kthread [ 596.565501][ T5854] Bluetooth: hci3: command 0x0c1a tx timeout [ 596.680226][T13254] netlink: 'syz.4.2713': attribute type 27 has an invalid length. [ 596.710111][T13254] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2713'. [ 596.730611][T13254] tipc: Cannot configure node identity twice [ 597.925348][ T5935] usb 5-1: new high-speed USB device number 55 using dummy_hcd [ 598.045552][ T9] usb 3-1: new high-speed USB device number 49 using dummy_hcd [ 598.102163][ T5935] usb 5-1: config 0 has no interfaces? [ 598.123891][ T5935] usb 5-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 598.145260][ T5935] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 598.165259][ T5935] usb 5-1: Product: syz [ 598.169487][ T5935] usb 5-1: Manufacturer: syz [ 598.174143][ T5935] usb 5-1: SerialNumber: syz [ 598.205990][ T5935] usb 5-1: config 0 descriptor?? [ 598.215344][ T9] usb 3-1: Using ep0 maxpacket: 16 [ 598.232314][ T9] usb 3-1: config 0 interface 0 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 598.264095][ T9] usb 3-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xD7, changing to 0x87 [ 598.281291][ T9] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x87 has an invalid bInterval 152, changing to 11 [ 598.309073][ T9] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x87 has invalid maxpacket 8285, setting to 1024 [ 598.323078][ T9] usb 3-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 1 [ 598.362358][ T9] usb 3-1: New USB device found, idVendor=05ac, idProduct=9226, bcdDevice=b2.89 [ 598.395557][ T9] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 598.403617][ T9] usb 3-1: Product: syz [ 598.407994][ T9] usb 3-1: Manufacturer: syz [ 598.413953][ T9] usb 3-1: SerialNumber: syz [ 598.453462][ T9] usb 3-1: config 0 descriptor?? [ 598.671617][ T9] appledisplay: Apple Cinema Display connected [ 599.592713][ T9] usb 3-1: USB disconnect, device number 49 [ 599.598815][ C0] usb 3-1: appledisplay_complete - usb_submit_urb failed with result -19 [ 599.612446][ T9] appledisplay: Apple Cinema Display disconnected [ 600.424025][ T5935] usb 5-1: USB disconnect, device number 55 [ 600.577961][ T53] usb 4-1: new high-speed USB device number 57 using dummy_hcd [ 600.750586][T13307] bridge0: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 600.762306][ T53] usb 4-1: Using ep0 maxpacket: 16 [ 600.770916][ T53] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x84 has invalid wMaxPacketSize 0 [ 600.780840][ T5845] usb 3-1: new high-speed USB device number 50 using dummy_hcd [ 600.808126][ T53] usb 4-1: New USB device found, idVendor=2040, idProduct=0264, bcdDevice=4e.d1 [ 600.825272][ T53] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 600.833319][ T53] usb 4-1: Product: syz [ 600.857845][ T53] usb 4-1: Manufacturer: syz [ 600.862510][ T53] usb 4-1: SerialNumber: syz [ 600.880844][ T53] usb 4-1: config 0 descriptor?? [ 600.895042][ T53] em28xx 4-1:0.0: New device syz syz @ 480 Mbps (2040:0264, interface 0, class 0) [ 600.913986][ T53] em28xx 4-1:0.0: DVB interface 0 found: bulk [ 600.915562][ T5845] usb 3-1: device descriptor read/64, error -71 [ 601.165493][ T5845] usb 3-1: new high-speed USB device number 51 using dummy_hcd [ 601.299824][T13297] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 601.319011][ T5845] usb 3-1: device descriptor read/64, error -71 [ 601.334893][T13297] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 601.435690][ T5845] usb usb3-port1: attempt power cycle [ 601.573696][ T53] em28xx 4-1:0.0: unknown em28xx chip ID (0) [ 601.785478][ T5845] usb 3-1: new high-speed USB device number 52 using dummy_hcd [ 601.820098][ T5845] usb 3-1: device descriptor read/8, error -71 [ 601.863234][T13318] loop8: detected capacity change from 0 to 7 [ 601.871066][T13318] Dev loop8: unable to read RDB block 7 [ 601.878377][T13318] loop8: unable to read partition table [ 601.884322][T13318] loop8: partition table beyond EOD, truncated [ 601.891405][T13318] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 601.891405][T13318] ) failed (rc=-5) [ 602.008301][ T53] em28xx 4-1:0.0: reading from i2c device at 0xa0 failed (error=-5) [ 602.027652][ T9] usb 5-1: new high-speed USB device number 56 using dummy_hcd [ 602.040299][ T53] em28xx 4-1:0.0: board has no eeprom [ 602.075582][ T5845] usb 3-1: new high-speed USB device number 53 using dummy_hcd [ 602.110127][ T5845] usb 3-1: device descriptor read/8, error -71 [ 602.195494][ T9] usb 5-1: device descriptor read/64, error -71 [ 602.226966][ T5845] usb usb3-port1: unable to enumerate USB device [ 602.318282][ T53] em28xx 4-1:0.0: Identified as PCTV tripleStick (292e) (card=94) [ 602.326509][ T53] em28xx 4-1:0.0: dvb set to bulk mode. [ 602.346855][ T10] em28xx 4-1:0.0: Binding DVB extension [ 602.367047][ T53] usb 4-1: USB disconnect, device number 57 [ 602.379955][ T53] em28xx 4-1:0.0: Disconnecting em28xx [ 602.428233][ T10] em28xx 4-1:0.0: Registering input extension [ 602.442656][ T53] em28xx 4-1:0.0: Closing input extension [ 602.456056][ T9] usb 5-1: new high-speed USB device number 57 using dummy_hcd [ 602.472566][T13335] bridge0: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 602.487927][ T53] em28xx 4-1:0.0: Freeing device [ 602.615253][ T9] usb 5-1: device descriptor read/64, error -71 [ 602.725700][ T9] usb usb5-port1: attempt power cycle [ 603.106206][ T9] usb 5-1: new high-speed USB device number 58 using dummy_hcd [ 603.155959][ T9] usb 5-1: device descriptor read/8, error -71 [ 603.395446][ T9] usb 5-1: new high-speed USB device number 59 using dummy_hcd [ 603.448757][ T9] usb 5-1: device descriptor read/8, error -71 [ 603.588291][ T9] usb usb5-port1: unable to enumerate USB device [ 603.981405][T13356] FAULT_INJECTION: forcing a failure. [ 603.981405][T13356] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 604.015507][T13356] CPU: 1 UID: 0 PID: 13356 Comm: syz.0.2755 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 604.015539][T13356] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 604.015554][T13356] Call Trace: [ 604.015563][T13356] [ 604.015572][T13356] dump_stack_lvl+0x241/0x360 [ 604.015610][T13356] ? __pfx_dump_stack_lvl+0x10/0x10 [ 604.015640][T13356] ? __pfx__printk+0x10/0x10 [ 604.015684][T13356] should_fail_ex+0x424/0x570 [ 604.015711][T13356] _copy_from_user+0x2d/0xb0 [ 604.015741][T13356] move_addr_to_kernel+0x7f/0x170 [ 604.015770][T13356] __sys_bind+0x12e/0x290 [ 604.015801][T13356] ? __pfx___sys_bind+0x10/0x10 [ 604.015868][T13356] __x64_sys_bind+0x7a/0x90 [ 604.015897][T13356] do_syscall_64+0xf3/0x230 [ 604.015921][T13356] ? clear_bhb_loop+0x45/0xa0 [ 604.015945][T13356] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 604.015965][T13356] RIP: 0033:0x7f7e8878d169 [ 604.015983][T13356] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 604.016000][T13356] RSP: 002b:00007f7e895ca038 EFLAGS: 00000246 ORIG_RAX: 0000000000000031 [ 604.016022][T13356] RAX: ffffffffffffffda RBX: 00007f7e889a5fa0 RCX: 00007f7e8878d169 [ 604.016038][T13356] RDX: 000000000000001c RSI: 0000200000000480 RDI: 0000000000000004 [ 604.016051][T13356] RBP: 00007f7e895ca090 R08: 0000000000000000 R09: 0000000000000000 [ 604.016064][T13356] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 604.016086][T13356] R13: 0000000000000000 R14: 00007f7e889a5fa0 R15: 00007f7e88acfa28 [ 604.016118][T13356] [ 604.196241][ T5935] usb 3-1: new high-speed USB device number 54 using dummy_hcd [ 604.271421][T13362] bridge0: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 604.355266][ T5935] usb 3-1: Using ep0 maxpacket: 16 [ 604.362690][ T5935] usb 3-1: config 0 has an invalid interface number: 122 but max is 0 [ 604.371426][ T5935] usb 3-1: config 0 has no interface number 0 [ 604.378451][ T5935] usb 3-1: config 0 interface 122 altsetting 0 endpoint 0xF has an invalid bInterval 89, changing to 7 [ 604.410010][ T5935] usb 3-1: config 0 interface 122 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 604.438273][ T5935] usb 3-1: New USB device found, idVendor=0403, idProduct=d012, bcdDevice=b1.90 [ 604.448420][ T5935] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 604.458533][ T5935] usb 3-1: Product: syz [ 604.462745][ T5935] usb 3-1: Manufacturer: syz [ 604.467507][ T5935] usb 3-1: SerialNumber: syz [ 604.476771][ T5935] usb 3-1: config 0 descriptor?? [ 604.487085][ T5935] ftdi_sio 3-1:0.122: FTDI USB Serial Device converter detected [ 604.497763][ T5935] ftdi_sio ttyUSB0: unknown device type: 0xb190 [ 604.622264][T13365] geneve2: entered promiscuous mode [ 604.632926][T13365] netlink: 156 bytes leftover after parsing attributes in process `syz.1.2759'. [ 604.687654][T13353] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 604.715556][T13353] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 604.756638][ T9] usb 3-1: USB disconnect, device number 54 [ 604.771225][ T9] ftdi_sio 3-1:0.122: device disconnected [ 606.178357][T13397] sctp: [Deprecated]: syz.2.2767 (pid 13397) Use of struct sctp_assoc_value in delayed_ack socket option. [ 606.178357][T13397] Use struct sctp_sack_info instead [ 606.672726][T13405] bridge2: trying to set multicast startup query interval below minimum, setting to 100 (1000ms) [ 607.294727][T13421] program syz.1.2777 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 607.314693][T13421] xt_cgroup: xt_cgroup: no path or classid specified [ 607.885022][T13437] loop8: detected capacity change from 0 to 7 [ 607.902198][T13437] Dev loop8: unable to read RDB block 7 [ 607.914402][T13437] loop8: unable to read partition table [ 607.927051][T13437] loop8: partition table beyond EOD, truncated [ 607.943650][T13437] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 607.943650][T13437] ) failed (rc=-5) [ 609.945311][ T5935] usb 5-1: new high-speed USB device number 60 using dummy_hcd [ 610.131212][ T5935] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 610.187806][ T5935] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 610.208970][T13469] loop8: detected capacity change from 0 to 7 [ 610.215433][ T5935] usb 5-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 610.215492][ T5935] usb 5-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 610.215519][ T5935] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 610.250605][ T5935] usb 5-1: config 0 descriptor?? [ 610.402760][T13469] Dev loop8: unable to read RDB block 7 [ 610.428881][T13469] loop8: unable to read partition table [ 610.434810][T13469] loop8: partition table beyond EOD, truncated [ 610.490099][T13469] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 610.490099][T13469] ) failed (rc=-5) [ 610.680762][ T5935] plantronics 0003:047F:FFFF.0017: No inputs registered, leaving [ 610.799897][ T5935] plantronics 0003:047F:FFFF.0017: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.4-1/input0 [ 610.929874][T13465] sctp: [Deprecated]: syz.4.2792 (pid 13465) Use of int in maxseg socket option. [ 610.929874][T13465] Use struct sctp_assoc_value instead [ 611.016519][ T9] usb 5-1: USB disconnect, device number 60 [ 611.667193][T13492] netlink: 72 bytes leftover after parsing attributes in process `syz.2.2804'. [ 611.722034][T13492] netlink: 12 bytes leftover after parsing attributes in process `syz.2.2804'. [ 612.034740][ T5935] usb 3-1: new high-speed USB device number 55 using dummy_hcd [ 612.205508][ T5935] usb 3-1: device descriptor read/64, error -71 [ 612.212396][ T3079] usb 5-1: new high-speed USB device number 61 using dummy_hcd [ 612.365758][ T3079] usb 5-1: Using ep0 maxpacket: 32 [ 612.390235][ T3079] usb 5-1: config 0 has an invalid interface number: 51 but max is 0 [ 612.400694][ T3079] usb 5-1: config 0 has no interface number 0 [ 612.422106][ T3079] usb 5-1: New USB device found, idVendor=061d, idProduct=c150, bcdDevice=ce.6f [ 612.433998][ T3079] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 612.455521][ T5935] usb 3-1: new high-speed USB device number 56 using dummy_hcd [ 612.486678][ T3079] usb 5-1: Product: syz [ 612.495905][ T3079] usb 5-1: Manufacturer: syz [ 612.511008][ T3079] usb 5-1: SerialNumber: syz [ 612.523823][ T3079] usb 5-1: config 0 descriptor?? [ 612.542221][ T3079] quatech2 5-1:0.51: Quatech 2nd gen USB to Serial Driver converter detected [ 612.625306][ T5935] usb 3-1: device descriptor read/64, error -71 [ 612.740635][T13509] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 612.755751][T13509] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 612.769319][ T5935] usb usb3-port1: attempt power cycle [ 612.787985][ T3079] usb 5-1: Quatech 2nd gen USB to Serial Driver converter now attached to ttyUSB0 [ 612.812082][ T3079] usb 5-1: Quatech 2nd gen USB to Serial Driver converter now attached to ttyUSB1 [ 613.142144][ T5935] usb 3-1: new high-speed USB device number 57 using dummy_hcd [ 613.166039][ T5935] usb 3-1: device descriptor read/8, error -71 [ 613.191718][ C1] usb 5-1: qt2_read_bulk_callback - non-zero urb status: -71 [ 613.204781][ T3079] usb 5-1: USB disconnect, device number 61 [ 613.219451][ T3079] quatech-serial ttyUSB0: Quatech 2nd gen USB to Serial Driver converter now disconnected from ttyUSB0 [ 613.242812][ T3079] quatech-serial ttyUSB1: Quatech 2nd gen USB to Serial Driver converter now disconnected from ttyUSB1 [ 613.289457][ T3079] quatech2 5-1:0.51: device disconnected [ 613.415348][ T5935] usb 3-1: new high-speed USB device number 58 using dummy_hcd [ 613.446799][ T5935] usb 3-1: device descriptor read/8, error -71 [ 613.555994][ T5935] usb usb3-port1: unable to enumerate USB device [ 615.053705][T13544] netlink: 'syz.2.2823': attribute type 4 has an invalid length. [ 615.065012][T13544] netlink: 52 bytes leftover after parsing attributes in process `syz.2.2823'. [ 615.107668][T13546] netlink: 'syz.1.2824': attribute type 21 has an invalid length. [ 615.121240][T13546] IPv6: NLM_F_CREATE should be specified when creating new route [ 615.140577][T13546] IPv6: RTM_NEWROUTE with no NLM_F_CREATE or NLM_F_REPLACE [ 615.147888][T13546] IPv6: NLM_F_CREATE should be set when creating new route [ 615.155227][T13546] IPv6: NLM_F_CREATE should be set when creating new route [ 615.162506][T13546] IPv6: NLM_F_CREATE should be set when creating new route [ 615.564082][T13561] netlink: 8 bytes leftover after parsing attributes in process `syz.4.2827'. [ 615.875246][ T47] usb 5-1: new high-speed USB device number 62 using dummy_hcd [ 616.092123][ T47] usb 5-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 616.112987][ T47] usb 5-1: config 0 interface 0 has no altsetting 0 [ 616.130931][ T47] usb 5-1: New USB device found, idVendor=044e, idProduct=1215, bcdDevice= 0.00 [ 616.190841][ T47] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 616.261040][ T47] usb 5-1: config 0 descriptor?? [ 617.042547][ T47] usbhid 5-1:0.0: can't add hid device: -71 [ 617.075821][ T47] usbhid 5-1:0.0: probe with driver usbhid failed with error -71 [ 617.144109][ T47] usb 5-1: USB disconnect, device number 62 [ 617.407057][T13575] netlink: 4 bytes leftover after parsing attributes in process `syz.1.2832'. [ 617.457512][T13575] netlink: 28 bytes leftover after parsing attributes in process `syz.1.2832'. [ 617.784946][ T5843] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 617.797001][ T5843] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 617.807120][ T5843] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 617.817032][ T5843] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 617.824889][ T5843] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 618.311996][T13582] chnl_net:caif_netlink_parms(): no params data found [ 618.500918][T13582] bridge0: port 1(bridge_slave_0) entered blocking state [ 618.525000][T13582] bridge0: port 1(bridge_slave_0) entered disabled state [ 618.546892][T13582] bridge_slave_0: entered allmulticast mode [ 618.574899][T13582] bridge_slave_0: entered promiscuous mode [ 618.664234][T13582] bridge0: port 2(bridge_slave_1) entered blocking state [ 618.697295][T13582] bridge0: port 2(bridge_slave_1) entered disabled state [ 618.704607][T13582] bridge_slave_1: entered allmulticast mode [ 618.745051][T13582] bridge_slave_1: entered promiscuous mode [ 618.884317][T13582] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 618.932817][T13582] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 619.058063][T13582] team0: Port device team_slave_0 added [ 619.067853][T13582] team0: Port device team_slave_1 added [ 619.180164][T13582] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 619.195376][T13582] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 619.261410][T13582] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 619.290388][T13582] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 619.305321][T13582] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 619.359054][T13582] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 619.387114][T13604] FAULT_INJECTION: forcing a failure. [ 619.387114][T13604] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 619.426918][T13604] CPU: 0 UID: 0 PID: 13604 Comm: syz.1.2840 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 619.426951][T13604] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 619.426966][T13604] Call Trace: [ 619.426975][T13604] [ 619.426984][T13604] dump_stack_lvl+0x241/0x360 [ 619.427025][T13604] ? __pfx_dump_stack_lvl+0x10/0x10 [ 619.427056][T13604] ? __pfx__printk+0x10/0x10 [ 619.427098][T13604] should_fail_ex+0x424/0x570 [ 619.427127][T13604] _copy_to_user+0x31/0xb0 [ 619.427159][T13604] simple_read_from_buffer+0xc4/0x170 [ 619.427194][T13604] proc_fail_nth_read+0x1ef/0x260 [ 619.427221][T13604] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 619.427247][T13604] ? rw_verify_area+0x246/0x630 [ 619.427271][T13604] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 619.427295][T13604] vfs_read+0x21f/0xb90 [ 619.427325][T13604] ? __pfx___mutex_lock+0x10/0x10 [ 619.427350][T13604] ? __pfx_vfs_read+0x10/0x10 [ 619.427384][T13604] ? __fget_files+0x2a/0x420 [ 619.427406][T13604] ? __fget_files+0x39d/0x420 [ 619.427424][T13604] ? __fget_files+0x2a/0x420 [ 619.427454][T13604] ksys_read+0x19d/0x2d0 [ 619.427481][T13604] ? __pfx_ksys_read+0x10/0x10 [ 619.427513][T13604] ? do_syscall_64+0xb6/0x230 [ 619.427541][T13604] do_syscall_64+0xf3/0x230 [ 619.427565][T13604] ? clear_bhb_loop+0x45/0xa0 [ 619.427591][T13604] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 619.427612][T13604] RIP: 0033:0x7fcf1b18bb7c [ 619.427632][T13604] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 619.427651][T13604] RSP: 002b:00007fcf1bfce030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 619.427674][T13604] RAX: ffffffffffffffda RBX: 00007fcf1b3a5fa0 RCX: 00007fcf1b18bb7c [ 619.427690][T13604] RDX: 000000000000000f RSI: 00007fcf1bfce0a0 RDI: 0000000000000005 [ 619.427704][T13604] RBP: 00007fcf1bfce090 R08: 0000000000000000 R09: 0000000000000000 [ 619.427717][T13604] R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002 [ 619.427730][T13604] R13: 0000000000000000 R14: 00007fcf1b3a5fa0 R15: 00007fcf1b4cfa28 [ 619.427763][T13604] [ 619.644567][ C0] vkms_vblank_simulate: vblank timer overrun [ 619.845936][ T5843] Bluetooth: hci2: command tx timeout [ 619.911577][T13582] hsr_slave_0: entered promiscuous mode [ 619.920527][T13582] hsr_slave_1: entered promiscuous mode [ 619.956195][T13582] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 619.984218][T13582] Cannot create hsr debugfs directory [ 620.522680][T13582] netdevsim netdevsim2 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 620.634829][T13582] netdevsim netdevsim2 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 620.787861][T13582] netdevsim netdevsim2 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 620.956725][T13582] bond0: (slave netdevsim0): Releasing backup interface [ 620.998187][T13582] netdevsim netdevsim2 netdevsim0 (unregistering): left promiscuous mode [ 621.031914][T13582] netdevsim netdevsim2 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 621.423946][T13582] netdevsim netdevsim2 netdevsim0: renamed from eth0 [ 621.440275][T13582] netdevsim netdevsim2 netdevsim1: renamed from eth1 [ 621.488990][T13582] netdevsim netdevsim2 netdevsim2: renamed from eth2 [ 621.544555][T13582] netdevsim netdevsim2 netdevsim3: renamed from eth3 [ 621.925816][ T5843] Bluetooth: hci2: command tx timeout [ 621.960870][T13582] 8021q: adding VLAN 0 to HW filter on device bond0 [ 621.998962][T13582] 8021q: adding VLAN 0 to HW filter on device team0 [ 622.037697][ T1139] bridge0: port 1(bridge_slave_0) entered blocking state [ 622.044925][ T1139] bridge0: port 1(bridge_slave_0) entered forwarding state [ 622.103475][T13644] netlink: 20 bytes leftover after parsing attributes in process `syz.3.2851'. [ 622.170915][ T13] bridge0: port 2(bridge_slave_1) entered blocking state [ 622.178294][ T13] bridge0: port 2(bridge_slave_1) entered forwarding state [ 622.454539][T13582] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 622.554421][T13582] veth0_vlan: entered promiscuous mode [ 622.574108][T13582] veth1_vlan: entered promiscuous mode [ 622.654476][T13582] veth0_macvtap: entered promiscuous mode [ 622.665640][T13582] veth1_macvtap: entered promiscuous mode [ 622.686028][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 622.697303][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.709777][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 622.720715][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.731028][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 622.741986][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.753087][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 622.771629][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.797300][T13582] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 622.841690][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 622.872908][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.883837][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 622.895275][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.905750][T13582] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 622.920087][T13582] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 622.938646][T13582] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 622.954747][T13582] netdevsim netdevsim2 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 622.957930][T13665] loop8: detected capacity change from 0 to 7 [ 622.964137][T13582] netdevsim netdevsim2 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 622.979576][T13582] netdevsim netdevsim2 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 622.993220][T13582] netdevsim netdevsim2 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 623.003358][T13665] Dev loop8: unable to read RDB block 7 [ 623.018948][T13665] loop8: unable to read partition table [ 623.031114][T13665] loop8: partition table beyond EOD, truncated [ 623.040583][T13665] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 623.040583][T13665] ) failed (rc=-5) [ 623.209013][T13672] FAULT_INJECTION: forcing a failure. [ 623.209013][T13672] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 623.242505][ T54] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 623.267618][T13672] CPU: 1 UID: 0 PID: 13672 Comm: syz.0.2861 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 623.267648][T13672] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 623.267662][T13672] Call Trace: [ 623.267671][T13672] [ 623.267680][T13672] dump_stack_lvl+0x241/0x360 [ 623.267719][T13672] ? __pfx_dump_stack_lvl+0x10/0x10 [ 623.267750][T13672] ? __pfx__printk+0x10/0x10 [ 623.267792][T13672] should_fail_ex+0x424/0x570 [ 623.267820][T13672] _copy_to_user+0x31/0xb0 [ 623.267853][T13672] simple_read_from_buffer+0xc4/0x170 [ 623.267889][T13672] proc_fail_nth_read+0x1ef/0x260 [ 623.267914][T13672] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 623.267939][T13672] ? rw_verify_area+0x246/0x630 [ 623.267962][T13672] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 623.267986][T13672] vfs_read+0x21f/0xb90 [ 623.268014][T13672] ? __pfx___mutex_lock+0x10/0x10 [ 623.268039][T13672] ? __pfx_vfs_read+0x10/0x10 [ 623.268066][T13672] ? __fget_files+0x2a/0x420 [ 623.268088][T13672] ? __fget_files+0x39d/0x420 [ 623.268113][T13672] ? __fget_files+0x2a/0x420 [ 623.268143][T13672] ksys_read+0x19d/0x2d0 [ 623.268170][T13672] ? __pfx_ksys_read+0x10/0x10 [ 623.268200][T13672] ? do_syscall_64+0xb6/0x230 [ 623.268228][T13672] do_syscall_64+0xf3/0x230 [ 623.268252][T13672] ? clear_bhb_loop+0x45/0xa0 [ 623.268278][T13672] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 623.268299][T13672] RIP: 0033:0x7f7e8878bb7c [ 623.268318][T13672] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 623.268335][T13672] RSP: 002b:00007f7e895ca030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 623.268358][T13672] RAX: ffffffffffffffda RBX: 00007f7e889a5fa0 RCX: 00007f7e8878bb7c [ 623.268374][T13672] RDX: 000000000000000f RSI: 00007f7e895ca0a0 RDI: 0000000000000005 [ 623.268388][T13672] RBP: 00007f7e895ca090 R08: 0000000000000000 R09: 0000000000000000 [ 623.268401][T13672] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 623.268415][T13672] R13: 0000000000000000 R14: 00007f7e889a5fa0 R15: 00007f7e88acfa28 [ 623.268447][T13672] [ 623.268710][ T54] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 623.642445][T13676] netlink: 60 bytes leftover after parsing attributes in process `syz.4.2863'. [ 623.659548][ T4542] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 623.675928][T13676] unsupported nlmsg_type 40 [ 623.695802][ T4542] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 623.733649][T13676] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 623.749204][T13676] batadv_slave_0: entered promiscuous mode [ 623.757067][T13676] batadv_slave_0: entered allmulticast mode [ 623.825703][ T47] usb 4-1: new high-speed USB device number 58 using dummy_hcd [ 623.844275][T13681] dccp_invalid_packet: P.type (RESET) not Data || [Data]Ack, while P.X == 0 [ 623.988196][ T47] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 624.001685][ T47] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 624.012443][ T5843] Bluetooth: hci2: command tx timeout [ 624.032421][ T47] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 624.053421][ T47] usb 4-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 624.064278][ T47] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 624.094245][ T47] usb 4-1: config 0 descriptor?? [ 624.301704][T13702] loop8: detected capacity change from 0 to 7 [ 624.319105][T13702] Dev loop8: unable to read RDB block 7 [ 624.324890][T13702] loop8: unable to read partition table [ 624.335394][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 624.335506][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 624.369639][T13702] loop8: partition table beyond EOD, truncated [ 624.388703][T13702] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 624.388703][T13702] ) failed (rc=-5) [ 624.515466][ T47] plantronics 0003:047F:FFFF.0018: No inputs registered, leaving [ 624.539864][ T47] plantronics 0003:047F:FFFF.0018: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.3-1/input0 [ 624.719553][T13679] sctp: [Deprecated]: syz.3.2864 (pid 13679) Use of int in maxseg socket option. [ 624.719553][T13679] Use struct sctp_assoc_value instead [ 624.771387][ T47] usb 4-1: USB disconnect, device number 58 [ 625.715250][ T47] usb 4-1: new high-speed USB device number 59 using dummy_hcd [ 625.895387][ T47] usb 4-1: Using ep0 maxpacket: 16 [ 625.918657][ T47] usb 4-1: config 0 has an invalid interface number: 11 but max is 0 [ 625.957784][ T47] usb 4-1: config 0 has no interface number 0 [ 625.982692][ T47] usb 4-1: too many endpoints for config 0 interface 11 altsetting 255: 255, using maximum allowed: 30 [ 626.023580][ T47] usb 4-1: config 0 interface 11 altsetting 255 has 0 endpoint descriptors, different from the interface descriptor's value: 255 [ 626.067906][ T47] usb 4-1: config 0 interface 11 has no altsetting 0 [ 626.085372][ T5843] Bluetooth: hci2: command tx timeout [ 626.100030][ T47] usb 4-1: New USB device found, idVendor=1199, idProduct=68a3, bcdDevice=d2.7b [ 626.119601][ T47] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 626.136764][ T47] usb 4-1: Product: syz [ 626.145428][ T47] usb 4-1: Manufacturer: syz [ 626.150087][ T47] usb 4-1: SerialNumber: syz [ 626.158105][ T47] usb 4-1: config 0 descriptor?? [ 626.416518][T13726] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 626.447436][T13726] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 626.478679][ T47] usb 4-1: Expected 3 endpoints, found: 0 [ 626.494311][ T47] usb 4-1: USB disconnect, device number 59 [ 626.558760][T13743] ptrace attach of "./syz-executor exec"[13582] was attempted by "./syz-executor exec"[13743] [ 626.867539][T13754] netlink: 60 bytes leftover after parsing attributes in process `syz.1.2887'. [ 626.945533][ T47] usb 3-1: new full-speed USB device number 59 using dummy_hcd [ 627.120866][ T47] usb 3-1: config 36 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 627.151368][ T47] usb 3-1: config 36 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 0, changing to 10 [ 627.181933][ T47] usb 3-1: config 36 interface 0 altsetting 0 endpoint 0x8F has invalid wMaxPacketSize 0 [ 627.204068][ T47] usb 3-1: New USB device found, idVendor=6993, idProduct=b001, bcdDevice=3d.29 [ 627.231609][ T47] usb 3-1: New USB device strings: Mfr=244, Product=0, SerialNumber=16 [ 627.249759][ T47] usb 3-1: Manufacturer: syz [ 627.266209][ T47] usb 3-1: SerialNumber: syz [ 627.345566][ T10] usb 4-1: new full-speed USB device number 60 using dummy_hcd [ 627.372439][T13767] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2892'. [ 627.499754][ T47] yealink 3-1:36.0: invalid payload size 0, expected 16 [ 627.530082][ T10] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 627.547712][ T47] input: Yealink usb-p1k as /devices/platform/dummy_hcd.2/usb3/3-1/3-1:36.0/input/input48 [ 627.561387][ T10] usb 4-1: config 0 interface 0 has no altsetting 0 [ 627.569076][ T10] usb 4-1: New USB device found, idVendor=054c, idProduct=0374, bcdDevice= 0.00 [ 627.582984][ T10] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 627.589418][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.598122][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.605149][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.612189][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.619649][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.631245][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.638938][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.646969][ C1] yealink 3-1:36.0: urb_ctl_callback - urb status -71 [ 627.653790][ C1] yealink 3-1:36.0: urb_ctl_callback - usb_submit_urb failed -90 [ 627.671608][ T10] usb 4-1: config 0 descriptor?? [ 627.681531][ T47] usb 3-1: USB disconnect, device number 59 [ 627.936359][T13760] fuse: Bad value for 'user_id' [ 627.941285][T13760] fuse: Bad value for 'user_id' [ 627.971616][ T10] usb 4-1: USB disconnect, device number 60 [ 628.235241][ T47] usb 5-1: new high-speed USB device number 63 using dummy_hcd [ 628.415739][ T47] usb 5-1: Using ep0 maxpacket: 8 [ 628.432209][ T47] usb 5-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0x73, changing to 0x3 [ 628.455266][ T47] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 0, changing to 7 [ 628.474542][ T47] usb 5-1: New USB device found, idVendor=0e9c, idProduct=0000, bcdDevice=5b.1e [ 628.484321][ T47] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 628.499818][ T47] usb 5-1: Product: syz [ 628.504046][ T47] usb 5-1: Manufacturer: syz [ 628.532730][ T47] usb 5-1: SerialNumber: syz [ 628.562575][ T47] usb 5-1: config 0 descriptor?? [ 628.592584][ T47] streamzap 5-1:0.0: streamzap_probe: endpoint doesn't match input device 0203 [ 628.791345][ T53] usb 5-1: USB disconnect, device number 63 [ 629.385238][ T53] usb 4-1: new high-speed USB device number 61 using dummy_hcd [ 629.545596][ T53] usb 4-1: device descriptor read/64, error -71 [ 629.560146][T13815] input: syz1 as /devices/virtual/input/input49 [ 629.795379][ T53] usb 4-1: new high-speed USB device number 62 using dummy_hcd [ 629.870014][T13819] futex_wake_op: syz.4.2905 tries to shift op by -33; fix this program [ 629.888502][T13819] netdevsim netdevsim4: Direct firmware load for . [ 629.888502][T13819] failed with error -2 [ 629.900315][T13819] netdevsim netdevsim4: Falling back to sysfs fallback for: . [ 629.900315][T13819] [ 629.935455][ T53] usb 4-1: device descriptor read/64, error -71 [ 630.045839][ T53] usb usb4-port1: attempt power cycle [ 630.187295][T13824] netlink: 'syz.2.2910': attribute type 21 has an invalid length. [ 630.233526][T13824] netlink: 128 bytes leftover after parsing attributes in process `syz.2.2910'. [ 630.265392][T13824] netlink: 'syz.2.2910': attribute type 5 has an invalid length. [ 630.287268][T13824] netlink: 3 bytes leftover after parsing attributes in process `syz.2.2910'. [ 630.416419][ T53] usb 4-1: new high-speed USB device number 63 using dummy_hcd [ 630.446470][ T53] usb 4-1: device descriptor read/8, error -71 [ 630.456712][ T5935] usb 3-1: new low-speed USB device number 60 using dummy_hcd [ 630.474928][T13830] netlink: 4 bytes leftover after parsing attributes in process `syz.1.2912'. [ 630.696358][ T53] usb 4-1: new high-speed USB device number 64 using dummy_hcd [ 630.727197][ T53] usb 4-1: device descriptor read/8, error -71 [ 630.845433][ T53] usb usb4-port1: unable to enumerate USB device [ 631.685469][ T5935] usb 3-1: new high-speed USB device number 61 using dummy_hcd [ 631.745609][ T10] usb 5-1: new high-speed USB device number 64 using dummy_hcd [ 631.835389][ T5935] usb 3-1: Using ep0 maxpacket: 32 [ 631.842487][ T5935] usb 3-1: config 0 interface 0 altsetting 0 bulk endpoint 0x85 has invalid maxpacket 1024 [ 631.856725][ T5935] usb 3-1: New USB device found, idVendor=12d8, idProduct=0001, bcdDevice=de.79 [ 631.866036][ T5935] usb 3-1: New USB device strings: Mfr=1, Product=236, SerialNumber=2 [ 631.874221][ T5935] usb 3-1: Product: syz [ 631.878547][ T5935] usb 3-1: Manufacturer: syz [ 631.883172][ T5935] usb 3-1: SerialNumber: syz [ 631.885592][ T10] usb 5-1: device descriptor read/64, error -71 [ 631.891322][ T5935] usb 3-1: config 0 descriptor?? [ 631.901143][T13852] raw-gadget.2 gadget.2: fail, usb_ep_enable returned -22 [ 631.910325][ T5935] hub 3-1:0.0: bad descriptor, ignoring hub [ 631.916347][ T5935] hub 3-1:0.0: probe with driver hub failed with error -5 [ 632.113249][T13852] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 632.122202][T13852] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 632.142686][ T10] usb 5-1: new high-speed USB device number 65 using dummy_hcd [ 632.171993][T13870] loop8: detected capacity change from 0 to 7 [ 632.179229][T13870] Dev loop8: unable to read RDB block 7 [ 632.184865][T13870] loop8: unable to read partition table [ 632.191528][T13870] loop8: partition table beyond EOD, truncated [ 632.198451][T13870] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 632.198451][T13870] ) failed (rc=-5) [ 632.255932][ T53] usb 3-1: USB disconnect, device number 61 [ 632.298984][ T10] usb 5-1: device descriptor read/64, error -71 [ 632.417043][ T10] usb usb5-port1: attempt power cycle [ 632.755450][ T10] usb 5-1: new high-speed USB device number 66 using dummy_hcd [ 632.805812][ T10] usb 5-1: device descriptor read/8, error -71 [ 632.820589][T13872] netdevsim netdevsim0 netdevsim0: entered promiscuous mode [ 633.065340][ T10] usb 5-1: new high-speed USB device number 67 using dummy_hcd [ 633.096782][ T10] usb 5-1: device descriptor read/8, error -71 [ 633.205733][ T10] usb usb5-port1: unable to enumerate USB device [ 633.395299][ T3079] usb 3-1: new high-speed USB device number 62 using dummy_hcd [ 633.395340][ T5897] usb 4-1: new high-speed USB device number 65 using dummy_hcd [ 633.545620][ T3079] usb 3-1: Using ep0 maxpacket: 16 [ 633.558537][ T3079] usb 3-1: config 0 has an invalid interface number: 2 but max is 0 [ 633.567632][ T3079] usb 3-1: config 0 has no interface number 0 [ 633.574483][ T3079] usb 3-1: config 0 interface 2 altsetting 0 has an endpoint descriptor with address 0x44, changing to 0x4 [ 633.575470][ T5897] usb 4-1: Using ep0 maxpacket: 16 [ 633.586490][ T3079] usb 3-1: config 0 interface 2 altsetting 0 endpoint 0x4 has an invalid bInterval 0, changing to 7 [ 633.602240][ T3079] usb 3-1: config 0 interface 2 altsetting 0 endpoint 0x4 has invalid maxpacket 16706, setting to 1024 [ 633.616323][ T5897] usb 4-1: config 1 interface 0 altsetting 1 endpoint 0x81 has an invalid bInterval 248, changing to 11 [ 633.616450][ T3079] usb 3-1: New USB device found, idVendor=0582, idProduct=0005, bcdDevice= 0.88 [ 633.636871][ T3079] usb 3-1: New USB device strings: Mfr=0, Product=2, SerialNumber=3 [ 633.638575][ T5897] usb 4-1: config 1 interface 0 has no altsetting 0 [ 633.644872][ T3079] usb 3-1: Product: syz [ 633.644894][ T3079] usb 3-1: SerialNumber: syz [ 633.650354][ T3079] usb 3-1: config 0 descriptor?? [ 633.659785][ T5897] usb 4-1: New USB device found, idVendor=0486, idProduct=0186, bcdDevice= 0.40 [ 633.681608][ T5897] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 633.689815][ T5897] usb 4-1: Product: о [ 633.693950][ T5897] usb 4-1: Manufacturer: П [ 633.699916][ T5897] usb 4-1: SerialNumber: ﹝✰珌ꂒ篣铉౳䵜ꡊ駻쥵뗮픿♪閏炏핟ꍀᅟɰ놓齋宁吣陑珠ꐄ苑뽅ꂗ幓櫜疰≋็䑜ϗ㊮ힶИĈ橼䦤櫱밾θ덫퀛ꧭⵃ䪤ﶉ쁍ꭄ斫䷓쫓⻟駫㛡ꔤᶞ耥暞擡䭙퐘倭濘唿춨퉏๲༏䨩潑୘쩱컇黉쁕᢭燏쌬ۧݶ嬝ᚸ怑溧ẋ栗䗶䵛諡蚞되筷斸윘憳頰문몒搎刏뒰냍鉡䍢 [ 633.884848][ T3079] usb 3-1: Quirk or no altset; falling back to MIDI 1.0 [ 633.906918][ T3079] usb 3-1: invalid MIDI in EP 0 [ 634.020664][ T5897] usbhid 4-1:1.0: can't add hid device: -71 [ 634.032227][T13904] vlan2: entered promiscuous mode [ 634.042438][ T5897] usbhid 4-1:1.0: probe with driver usbhid failed with error -71 [ 634.043449][ T3079] snd-usb-audio 3-1:0.2: probe with driver snd-usb-audio failed with error -22 [ 634.063829][T13905] netlink: 32 bytes leftover after parsing attributes in process `syz.0.2936'. [ 634.093716][ T5897] usb 4-1: USB disconnect, device number 65 [ 634.095944][ T3079] usb 3-1: USB disconnect, device number 62 [ 634.335706][T13906] udevd[13906]: error opening ATTR{/sys/devices/platform/dummy_hcd.2/usb3/3-1/3-1:0.2/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 634.885438][ T10] usb 3-1: new high-speed USB device number 63 using dummy_hcd [ 635.068833][ T10] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 635.095243][ T10] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 635.125756][ T10] usb 3-1: New USB device found, idVendor=0419, idProduct=0600, bcdDevice= 0.00 [ 635.135824][ T10] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 635.161444][ T10] usb 3-1: config 0 descriptor?? [ 635.499313][T13938] netlink: 'syz.3.2946': attribute type 1 has an invalid length. [ 635.579624][ T10] samsung 0003:0419:0600.0019: unknown main item tag 0x0 [ 635.591693][ T10] samsung 0003:0419:0600.0019: unknown main item tag 0x0 [ 635.599291][ T10] samsung 0003:0419:0600.0019: unknown main item tag 0x0 [ 635.614026][ T10] samsung 0003:0419:0600.0019: unknown main item tag 0x0 [ 635.632747][ T10] samsung 0003:0419:0600.0019: unknown main item tag 0x0 [ 635.642600][ T10] samsung 0003:0419:0600.0019: hidraw0: USB HID v0.00 Device [HID 0419:0600] on usb-dummy_hcd.2-1/input0 [ 635.754645][T13942] xt_hashlimit: size too large, truncated to 1048576 [ 635.784193][T13922] netlink: 20 bytes leftover after parsing attributes in process `syz.2.2941'. [ 635.825468][ T3079] usb 3-1: USB disconnect, device number 63 [ 636.759610][ T30] kauditd_printk_skb: 4 callbacks suppressed [ 636.759630][ T30] audit: type=1326 audit(1743764805.747:1985): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 636.825383][ T47] usb 3-1: new high-speed USB device number 64 using dummy_hcd [ 636.863618][ T30] audit: type=1326 audit(1743764805.777:1986): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 636.886410][ T53] usb 5-1: new high-speed USB device number 68 using dummy_hcd [ 636.894135][ T30] audit: type=1326 audit(1743764805.787:1987): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=194 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 636.923780][ T30] audit: type=1326 audit(1743764805.787:1988): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 636.953209][ T30] audit: type=1326 audit(1743764805.787:1989): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 636.984589][ T30] audit: type=1326 audit(1743764805.787:1990): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 637.012446][ T30] audit: type=1326 audit(1743764805.787:1991): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 637.039564][ T30] audit: type=1326 audit(1743764805.787:1992): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 637.045925][ T3079] usb 4-1: new high-speed USB device number 66 using dummy_hcd [ 637.072837][ T30] audit: type=1326 audit(1743764805.787:1993): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=16 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 637.085267][ T47] usb 3-1: Using ep0 maxpacket: 32 [ 637.102821][ T47] usb 3-1: config 0 has an invalid interface number: 146 but max is 0 [ 637.111451][ T47] usb 3-1: config 0 has no interface number 0 [ 637.126345][ T47] usb 3-1: config 0 interface 146 altsetting 0 has an endpoint descriptor with address 0xE3, changing to 0x83 [ 637.138277][ T53] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0xF has invalid wMaxPacketSize 0 [ 637.155253][ T47] usb 3-1: config 0 interface 146 altsetting 0 endpoint 0x83 has invalid maxpacket 33307, setting to 1024 [ 637.181261][ T47] usb 3-1: config 0 interface 146 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 1024 [ 637.186660][ T53] usb 5-1: New USB device found, idVendor=2058, idProduct=1005, bcdDevice= 9.75 [ 637.205330][ T47] usb 3-1: config 0 interface 146 altsetting 0 endpoint 0x9 has invalid maxpacket 19604, setting to 1024 [ 637.220258][ T53] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 637.229956][ T30] audit: type=1326 audit(1743764805.787:1994): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=13955 comm="syz.3.2951" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff43a78d169 code=0x7ffc0000 [ 637.264841][ T53] usb 5-1: Product: syz [ 637.269288][ T47] usb 3-1: config 0 interface 146 altsetting 0 bulk endpoint 0x9 has invalid maxpacket 1024 [ 637.295346][ T47] usb 3-1: config 0 interface 146 altsetting 0 endpoint 0x1 has invalid wMaxPacketSize 0 [ 637.305232][ T53] usb 5-1: Manufacturer: syz [ 637.305258][ T53] usb 5-1: SerialNumber: syz [ 637.318532][ T53] usb 5-1: config 0 descriptor?? [ 637.343913][ T47] usb 3-1: New USB device found, idVendor=05da, idProduct=009a, bcdDevice=62.95 [ 637.359205][ T47] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 637.387641][ T47] usb 3-1: Product: syz [ 637.404928][ T47] usb 3-1: Manufacturer: syz [ 637.416043][ T47] usb 3-1: SerialNumber: syz [ 637.437072][ T53] viperboard 5-1:0.0: version 0.00 found at bus 005 address 068 [ 637.439470][ T47] usb 3-1: config 0 descriptor?? [ 637.487808][T13951] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 637.495104][T13951] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 637.510273][ T47] microtek usb (rev 0.4.3): can only deal with bulk endpoints; endpoint 1 is not bulk. [ 637.530068][ T47] microtek usb (rev 0.4.3): couldn't find two input bulk endpoints. Bailing out. [ 637.651661][T13962] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 637.672569][T13962] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 637.741069][T13951] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 637.749576][ T3079] usb 4-1: Using ep0 maxpacket: 16 [ 637.764961][ T53] viperboard-i2c viperboard-i2c.2.auto: failure setting i2c_bus_freq to 100 [ 637.789502][T13951] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 637.811575][ T53] viperboard-i2c viperboard-i2c.2.auto: probe with driver viperboard-i2c failed with error -5 [ 637.857378][ T10] usb 3-1: USB disconnect, device number 64 [ 637.913103][ T3079] usb 4-1: unable to get BOS descriptor or descriptor too short [ 638.039080][ T53] usb 5-1: USB disconnect, device number 68 [ 638.081555][ T3079] usb 4-1: config 1 interface 0 has no altsetting 0 [ 638.475484][ T3079] usb 4-1: New USB device found, idVendor=04f3, idProduct=074d, bcdDevice= 0.40 [ 638.622489][ T3079] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 638.687544][ T3079] usb 4-1: Product: syz [ 638.706177][ T3079] usb 4-1: Manufacturer: syz [ 638.710831][ T3079] usb 4-1: SerialNumber: syz [ 639.216388][ T53] usb 3-1: new full-speed USB device number 65 using dummy_hcd [ 639.525235][ T53] usb 3-1: config 8 has an invalid interface number: 177 but max is 0 [ 639.545533][ T53] usb 3-1: config 8 has no interface number 0 [ 639.658172][ T53] usb 3-1: config 8 interface 177 altsetting 9 has an endpoint descriptor with address 0xE8, changing to 0x88 [ 639.717754][ T53] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x88 has invalid maxpacket 1023, setting to 64 [ 639.763035][ T53] usb 3-1: config 8 interface 177 altsetting 9 endpoint 0x87 has invalid wMaxPacketSize 0 [ 639.806658][ T53] usb 3-1: config 8 interface 177 has no altsetting 0 [ 639.855673][ T53] usb 3-1: New USB device found, idVendor=04d8, idProduct=fd08, bcdDevice=59.b1 [ 639.888749][ T53] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 640.006034][T13980] raw-gadget.1 gadget.2: fail, usb_ep_enable returned -22 [ 640.258111][T13980] input: syz0 as /devices/virtual/input/input50 [ 640.400536][T13980] netlink: 12 bytes leftover after parsing attributes in process `syz.2.2955'. [ 641.683554][ T3079] usbhid 4-1:1.0: can't add hid device: -71 [ 641.689956][ T3079] usbhid 4-1:1.0: probe with driver usbhid failed with error -71 [ 641.788597][T13996] netlink: 16 bytes leftover after parsing attributes in process `syz.1.2961'. [ 641.802550][T13996] netlink: 24 bytes leftover after parsing attributes in process `syz.1.2961'. [ 641.826394][ T3079] usb 4-1: USB disconnect, device number 66 [ 641.848432][T13996] veth3: entered promiscuous mode [ 641.883985][T13996] veth3: entered allmulticast mode [ 642.200169][ T3079] usb 4-1: new high-speed USB device number 67 using dummy_hcd [ 642.365080][ T3079] usb 4-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 642.372451][T14003] loop8: detected capacity change from 0 to 7 [ 642.385074][T14003] Dev loop8: unable to read RDB block 7 [ 642.400736][ T3079] usb 4-1: config 1 has an invalid descriptor of length 55, skipping remainder of the config [ 642.421332][T14003] loop8: unable to read partition table [ 642.446625][T14003] loop8: partition table beyond EOD, truncated [ 642.453130][ T3079] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 642.463066][T14003] loop_reread_partitions: partition scan of loop8 (被xڬdƤݡ [ 642.463066][T14003] ) failed (rc=-5) [ 642.481861][ T3079] usb 4-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 52, changing to 9 [ 642.494351][ T3079] usb 4-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 8241, setting to 1024 [ 642.508301][ T3079] usb 4-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 642.517881][ T3079] usb 4-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 642.535483][ T3079] usb 4-1: Product: syz [ 642.543174][ T3079] usb 4-1: Manufacturer: syz [ 642.582013][ T3079] cdc_wdm 4-1:1.0: skipping garbage [ 642.587425][ T3079] cdc_wdm 4-1:1.0: skipping garbage [ 642.610167][ T3079] cdc_wdm 4-1:1.0: cdc-wdm0: USB WDM device [ 642.629252][ T3079] cdc_wdm 4-1:1.0: Unknown control protocol [ 642.769482][ T53] usb 3-1: string descriptor 0 read error: -71 [ 642.798890][ T53] ir_toy 3-1:8.177: required endpoints not found [ 642.829061][ T53] usb 3-1: USB disconnect, device number 65 [ 643.065241][ T9] usb 5-1: new high-speed USB device number 69 using dummy_hcd [ 643.215321][ T9] usb 5-1: Using ep0 maxpacket: 8 [ 643.228491][ T9] usb 5-1: New USB device found, idVendor=0979, idProduct=0270, bcdDevice=a8.17 [ 643.237880][ T9] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 643.246299][ T9] usb 5-1: Product: syz [ 643.250956][ T9] usb 5-1: Manufacturer: syz [ 643.255967][ T9] usb 5-1: SerialNumber: syz [ 643.263785][ T9] usb 5-1: config 0 descriptor?? [ 643.273946][ T9] hub 5-1:0.0: bad descriptor, ignoring hub [ 643.280198][ T9] hub 5-1:0.0: probe with driver hub failed with error -5 [ 643.294343][ T9] gspca_main: jeilinj-2.14.0 probing 0979:0270 [ 643.481974][ T5845] usb 4-1: USB disconnect, device number 67 [ 644.155344][ T9] usb 3-1: new high-speed USB device number 66 using dummy_hcd [ 644.327967][ T9] usb 3-1: config 0 has no interfaces? [ 644.331221][T14028] ======================================================= [ 644.331221][T14028] WARNING: The mand mount option has been deprecated and [ 644.331221][T14028] and is ignored by this kernel. Remove the mand [ 644.331221][T14028] option from the mount to silence this warning. [ 644.331221][T14028] ======================================================= [ 644.392584][ T9] usb 3-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 644.413979][ T9] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 644.438131][ T9] usb 3-1: Product: syz [ 644.442912][ T9] usb 3-1: Manufacturer: syz [ 644.459242][ T9] usb 3-1: SerialNumber: syz [ 644.476049][ T9] usb 3-1: config 0 descriptor?? [ 645.706693][ T53] usb 5-1: USB disconnect, device number 69 [ 646.885845][ T5845] usb 5-1: new high-speed USB device number 70 using dummy_hcd [ 647.126542][ T5845] usb 5-1: New USB device found, idVendor=0856, idProduct=ac31, bcdDevice=93.1e [ 647.155316][ T5845] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 647.204315][ T5845] usb 5-1: Product: syz [ 647.209515][ T5845] usb 5-1: Manufacturer: syz [ 647.228829][ T5845] usb 5-1: SerialNumber: syz [ 647.254116][ T5845] usb 5-1: config 0 descriptor?? [ 647.315617][ T9] usb 3-1: USB disconnect, device number 66 [ 647.819020][ T5845] mos7840 5-1:0.0: required endpoints missing [ 647.876639][ T5845] usb 5-1: USB disconnect, device number 70 [ 648.480063][T14068] netlink: 16 bytes leftover after parsing attributes in process `syz.4.2984'. [ 648.645762][ T5845] usb 3-1: new high-speed USB device number 67 using dummy_hcd [ 648.815249][ T5845] usb 3-1: Using ep0 maxpacket: 16 [ 648.840819][ T5845] usb 3-1: config 0 has an invalid interface number: 41 but max is 0 [ 648.890594][ T5845] usb 3-1: config 0 has no interface number 0 [ 648.920951][ T5845] usb 3-1: config 0 interface 41 altsetting 2 bulk endpoint 0x4 has invalid maxpacket 16 [ 648.952113][ T5845] usb 3-1: config 0 interface 41 altsetting 2 bulk endpoint 0x82 has invalid maxpacket 64 [ 648.975596][ T5845] usb 3-1: config 0 interface 41 has no altsetting 0 [ 648.987623][ T5845] usb 3-1: New USB device found, idVendor=0fe6, idProduct=9800, bcdDevice=d1.9a [ 649.009423][ T5845] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 649.029321][ T5845] usb 3-1: Product: syz [ 649.033625][ T5845] usb 3-1: Manufacturer: syz [ 649.048274][ T5845] usb 3-1: SerialNumber: syz [ 649.090554][ T5845] usb 3-1: config 0 descriptor?? [ 649.106818][T14067] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 649.114714][T14067] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 649.326775][T14078] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2987'. [ 649.398113][T14067] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 649.415486][T14067] raw-gadget.0 gadget.2: fail, usb_ep_enable returned -22 [ 650.075399][ T5845] CoreChips 3-1:0.41 (unnamed net_device) (uninitialized): sr_get_phy_addr : Error reading PHYID register:ffffffe0 [ 650.558062][ T5845] CoreChips 3-1:0.41 (unnamed net_device) (uninitialized): Failed to send software reset:ffffffb9 [ 650.609057][ T5845] CoreChips 3-1:0.41 (unnamed net_device) (uninitialized): Failed to reset PHY: -71 [ 650.623285][ T5845] CoreChips 3-1:0.41: probe with driver CoreChips failed with error -71 [ 650.660066][ T5845] usb 3-1: USB disconnect, device number 67 [ 651.082946][ T30] kauditd_printk_skb: 56 callbacks suppressed [ 651.082960][ T30] audit: type=1326 audit(1743764820.067:2051): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.218236][ T30] audit: type=1326 audit(1743764820.117:2052): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.339999][ T30] audit: type=1326 audit(1743764820.117:2053): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7fc745d8bad0 code=0x7ffc0000 [ 651.399245][ T30] audit: type=1326 audit(1743764820.117:2054): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.487905][ T30] audit: type=1326 audit(1743764820.117:2055): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.551895][ T30] audit: type=1326 audit(1743764820.127:2056): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=40 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.614524][ T30] audit: type=1326 audit(1743764820.127:2057): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.672234][ T30] audit: type=1326 audit(1743764820.127:2058): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.741136][ T30] audit: type=1326 audit(1743764820.127:2059): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=46 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.787174][ T30] audit: type=1326 audit(1743764820.127:2060): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=14095 comm="syz.4.2995" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fc745d8d169 code=0x7ffc0000 [ 651.835470][ T5845] usb 3-1: new high-speed USB device number 68 using dummy_hcd [ 651.935252][ T53] usb 5-1: new full-speed USB device number 71 using dummy_hcd [ 652.015314][ T5845] usb 3-1: Using ep0 maxpacket: 16 [ 652.023260][ T5845] usb 3-1: config 5 has an invalid interface number: 33 but max is 2 [ 652.046020][ T5845] usb 3-1: config 5 has an invalid interface number: 180 but max is 2 [ 652.148354][T14111] tipc: Can't bind to reserved service type 2 [ 652.163633][ T5845] usb 3-1: config 5 has an invalid interface number: 11 but max is 2 [ 652.211219][ T5845] usb 3-1: config 5 contains an unexpected descriptor of type 0x1, skipping [ 652.227643][ T53] usb 5-1: config 8 has an invalid interface number: 177 but max is 0 [ 652.237807][T14111] netlink: 8 bytes leftover after parsing attributes in process `syz.1.3000'. [ 652.248807][ T5845] usb 3-1: config 5 contains an unexpected descriptor of type 0x1, skipping [ 652.253833][ T53] usb 5-1: config 8 has no interface number 0 [ 652.288557][ T53] usb 5-1: config 8 interface 177 altsetting 9 has an endpoint descriptor with address 0xE8, changing to 0x88 [ 652.307346][T14111] batman_adv: Cannot find parent device. Skipping batadv-on-batadv check for gretap1 [ 652.317471][ T5845] usb 3-1: config 5 has no interface number 0 [ 652.323740][ T5845] usb 3-1: config 5 has no interface number 1 [ 652.350796][ T5845] usb 3-1: config 5 has no interface number 2 [ 652.377137][ T5845] usb 3-1: config 5 interface 33 altsetting 8 endpoint 0x6 has invalid maxpacket 1024, setting to 64 [ 652.410830][ T5845] usb 3-1: config 5 interface 33 altsetting 8 endpoint 0x7 has invalid maxpacket 21593, setting to 64 [ 652.446374][ T5845] usb 3-1: config 5 interface 33 altsetting 8 endpoint 0x2 has invalid maxpacket 1040, setting to 64 [ 652.462755][T14115] netlink: 16 bytes leftover after parsing attributes in process `syz.1.3002'. [ 652.479065][ T5845] usb 3-1: config 5 interface 180 altsetting 137 bulk endpoint 0xC has invalid maxpacket 64 [ 652.518227][ T5845] usb 3-1: config 5 interface 180 altsetting 137 has an invalid descriptor for endpoint zero, skipping [ 652.565750][ T53] usb 5-1: config 8 interface 177 altsetting 9 endpoint 0x88 has invalid maxpacket 1023, setting to 64 [ 652.604434][ T53] usb 5-1: config 8 interface 177 altsetting 9 endpoint 0x87 has invalid wMaxPacketSize 0 [ 652.638414][ T5845] usb 3-1: config 5 interface 180 altsetting 137 endpoint 0xA has invalid maxpacket 512, setting to 64 [ 652.664414][ T53] usb 5-1: config 8 interface 177 has no altsetting 0 [ 652.679511][ T53] usb 5-1: New USB device found, idVendor=04d8, idProduct=fd08, bcdDevice=59.b1 [ 652.698613][ T53] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 652.746508][T14106] raw-gadget.3 gadget.4: fail, usb_ep_enable returned -22 [ 652.768419][ T5845] usb 3-1: config 5 interface 180 altsetting 137 endpoint 0x1 has invalid maxpacket 88, setting to 64 [ 652.845143][T14119] [ 652.847529][T14119] ====================================================== [ 652.854564][T14119] WARNING: possible circular locking dependency detected [ 652.861605][T14119] 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 Not tainted [ 652.868377][T14119] ------------------------------------------------------ [ 652.875388][T14119] syz.3.3003/14119 is trying to acquire lock: [ 652.881454][T14119] ffffffff900fc808 (rtnl_mutex){+.+.}-{4:4}, at: do_ipv6_setsockopt+0xa9a/0x3680 [ 652.890603][T14119] [ 652.890603][T14119] but task is already holding lock: [ 652.897957][T14119] ffff88804b970aa0 (&smc->clcsock_release_lock){+.+.}-{4:4}, at: smc_setsockopt+0x1b2/0xd50 [ 652.908053][T14119] [ 652.908053][T14119] which lock already depends on the new lock. [ 652.908053][T14119] [ 652.918451][T14119] [ 652.918451][T14119] the existing dependency chain (in reverse order) is: [ 652.927463][T14119] [ 652.927463][T14119] -> #2 (&smc->clcsock_release_lock){+.+.}-{4:4}: [ 652.936073][T14119] lock_acquire+0x116/0x2f0 [ 652.941114][T14119] __mutex_lock+0x1a5/0x10c0 [ 652.946237][T14119] smc_switch_to_fallback+0x35/0xda0 [ 652.952055][T14119] smc_sendmsg+0x11f/0x530 [ 652.957000][T14119] __sock_sendmsg+0x221/0x270 [ 652.962216][T14119] __sys_sendto+0x365/0x4c0 [ 652.967245][T14119] __x64_sys_sendto+0xde/0x100 [ 652.972557][T14119] do_syscall_64+0xf3/0x230 [ 652.977581][T14119] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 652.984016][T14119] [ 652.984016][T14119] -> #1 (sk_lock-AF_INET){+.+.}-{0:0}: [ 652.991668][T14119] lock_acquire+0x116/0x2f0 [ 652.996709][T14119] lock_sock_nested+0x48/0x100 [ 653.002073][T14119] do_ip_setsockopt+0x17e9/0x39c0 [ 653.007626][T14119] ip_setsockopt+0x63/0x100 [ 653.012647][T14119] do_sock_setsockopt+0x3b1/0x710 [ 653.018212][T14119] __x64_sys_setsockopt+0x1ee/0x280 [ 653.023929][T14119] do_syscall_64+0xf3/0x230 [ 653.028963][T14119] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 653.035417][T14119] [ 653.035417][T14119] -> #0 (rtnl_mutex){+.+.}-{4:4}: [ 653.042653][T14119] validate_chain+0xa69/0x24e0 [ 653.048060][T14119] __lock_acquire+0xad5/0xd80 [ 653.053254][T14119] lock_acquire+0x116/0x2f0 [ 653.058447][T14119] __mutex_lock+0x1a5/0x10c0 [ 653.063556][T14119] do_ipv6_setsockopt+0xa9a/0x3680 [ 653.069188][T14119] ipv6_setsockopt+0x5d/0x170 [ 653.074511][T14119] smc_setsockopt+0x25c/0xd50 [ 653.079715][T14119] do_sock_setsockopt+0x3b1/0x710 [ 653.085271][T14119] __x64_sys_setsockopt+0x1ee/0x280 [ 653.090991][T14119] do_syscall_64+0xf3/0x230 [ 653.096035][T14119] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 653.102449][T14119] [ 653.102449][T14119] other info that might help us debug this: [ 653.102449][T14119] [ 653.112677][T14119] Chain exists of: [ 653.112677][T14119] rtnl_mutex --> sk_lock-AF_INET --> &smc->clcsock_release_lock [ 653.112677][T14119] [ 653.126248][T14119] Possible unsafe locking scenario: [ 653.126248][T14119] [ 653.133693][T14119] CPU0 CPU1 [ 653.139050][T14119] ---- ---- [ 653.144407][T14119] lock(&smc->clcsock_release_lock); [ 653.149800][T14119] lock(sk_lock-AF_INET); [ 653.156736][T14119] lock(&smc->clcsock_release_lock); [ 653.164628][T14119] lock(rtnl_mutex); [ 653.168607][T14119] [ 653.168607][T14119] *** DEADLOCK *** [ 653.168607][T14119] [ 653.176745][T14119] 1 lock held by syz.3.3003/14119: [ 653.181851][T14119] #0: ffff88804b970aa0 (&smc->clcsock_release_lock){+.+.}-{4:4}, at: smc_setsockopt+0x1b2/0xd50 [ 653.192391][T14119] [ 653.192391][T14119] stack backtrace: [ 653.198273][T14119] CPU: 0 UID: 0 PID: 14119 Comm: syz.3.3003 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 653.198293][T14119] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 653.198303][T14119] Call Trace: [ 653.198311][T14119] [ 653.198319][T14119] dump_stack_lvl+0x241/0x360 [ 653.198344][T14119] ? __pfx_dump_stack_lvl+0x10/0x10 [ 653.198366][T14119] ? __pfx__printk+0x10/0x10 [ 653.198387][T14119] ? print_lock+0x171/0x1a0 [ 653.198407][T14119] print_circular_bug+0x2e1/0x300 [ 653.198429][T14119] check_noncircular+0x142/0x160 [ 653.198451][T14119] validate_chain+0xa69/0x24e0 [ 653.198473][T14119] ? __pfx___switch_to+0x10/0x10 [ 653.198500][T14119] __lock_acquire+0xad5/0xd80 [ 653.198519][T14119] lock_acquire+0x116/0x2f0 [ 653.198533][T14119] ? do_ipv6_setsockopt+0xa9a/0x3680 [ 653.198558][T14119] __mutex_lock+0x1a5/0x10c0 [ 653.198575][T14119] ? do_ipv6_setsockopt+0xa9a/0x3680 [ 653.198596][T14119] ? __lock_acquire+0xad5/0xd80 [ 653.198613][T14119] ? do_ipv6_setsockopt+0xa9a/0x3680 [ 653.198633][T14119] ? __pfx___mutex_lock+0x10/0x10 [ 653.198656][T14119] do_ipv6_setsockopt+0xa9a/0x3680 [ 653.198678][T14119] ? register_lock_class+0x54/0x330 [ 653.198694][T14119] ? __pfx_do_ipv6_setsockopt+0x10/0x10 [ 653.198714][T14119] ? __lock_acquire+0xad5/0xd80 [ 653.198730][T14119] ? __mutex_trylock_common+0x184/0x2e0 [ 653.198752][T14119] ? __pfx___mutex_trylock_common+0x10/0x10 [ 653.198774][T14119] ? rcu_is_watching+0x15/0xb0 [ 653.198793][T14119] ? trace_contention_end+0x3c/0x120 [ 653.198812][T14119] ? __mutex_lock+0x380/0x10c0 [ 653.198832][T14119] ? smc_setsockopt+0x1b2/0xd50 [ 653.198848][T14119] ? __pfx___mutex_lock+0x10/0x10 [ 653.198869][T14119] ipv6_setsockopt+0x5d/0x170 [ 653.198889][T14119] ? __pfx_sock_common_setsockopt+0x10/0x10 [ 653.198911][T14119] smc_setsockopt+0x25c/0xd50 [ 653.198927][T14119] ? __pfx_aa_sk_perm+0x10/0x10 [ 653.198946][T14119] ? __pfx_smc_setsockopt+0x10/0x10 [ 653.198961][T14119] ? aa_sock_opt_perm+0x79/0x120 [ 653.198984][T14119] ? __pfx_smc_setsockopt+0x10/0x10 [ 653.199003][T14119] do_sock_setsockopt+0x3b1/0x710 [ 653.199029][T14119] ? __pfx_do_sock_setsockopt+0x10/0x10 [ 653.199052][T14119] ? __fget_files+0x2a/0x420 [ 653.199066][T14119] ? __fget_files+0x39d/0x420 [ 653.199078][T14119] ? __fget_files+0x2a/0x420 [ 653.199094][T14119] __x64_sys_setsockopt+0x1ee/0x280 [ 653.199110][T14119] do_syscall_64+0xf3/0x230 [ 653.199128][T14119] ? clear_bhb_loop+0x45/0xa0 [ 653.199145][T14119] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 653.199160][T14119] RIP: 0033:0x7ff43a78d169 [ 653.199174][T14119] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 653.199188][T14119] RSP: 002b:00007ff438570038 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 [ 653.199205][T14119] RAX: ffffffffffffffda RBX: 00007ff43a9a6160 RCX: 00007ff43a78d169 [ 653.199217][T14119] RDX: 000000000000001b RSI: 0000000000000029 RDI: 0000000000000009 [ 653.199227][T14119] RBP: 00007ff43a80e2a0 R08: 0000000000000014 R09: 0000000000000000 [ 653.199237][T14119] R10: 0000200000000100 R11: 0000000000000246 R12: 0000000000000000 [ 653.199247][T14119] R13: 0000000000000000 R14: 00007ff43a9a6160 R15: 00007ff43aacfa28 [ 653.199264][T14119] [ 653.523621][T14106] input: syz0 as /devices/virtual/input/input52 [ 653.542680][ T5845] usb 3-1: config 5 interface 180 altsetting 137 has a duplicate endpoint with address 0x2, skipping [ 653.591710][T14106] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2997'. [ 653.612136][ T5845] usb 3-1: config 5 interface 180 altsetting 137 endpoint 0xF has invalid maxpacket 1023, setting to 64 [ 653.945558][ T5845] usb 3-1: config 5 interface 180 altsetting 137 has a duplicate endpoint with address 0xC, skipping [ 653.973428][ T5845] usb 3-1: config 5 interface 180 altsetting 137 has a duplicate endpoint with address 0x3, skipping [ 653.984672][ T5845] usb 3-1: config 5 interface 180 altsetting 137 endpoint 0xE has an invalid bInterval 129, changing to 11 [ 654.015529][ T5845] usb 3-1: config 5 interface 11 altsetting 12 endpoint 0x5 has an invalid bInterval 128, changing to 7 [ 654.029378][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x3, skipping [ 654.041011][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x1, skipping [ 654.052530][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x5, skipping [ 654.063701][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x1, skipping [ 654.074484][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0xA, skipping [ 654.086445][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x1, skipping [ 654.097839][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has an invalid descriptor for endpoint zero, skipping [ 654.109231][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x5, skipping [ 654.120206][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has an invalid descriptor for endpoint zero, skipping [ 654.131519][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x5, skipping [ 654.148036][ T5845] usb 3-1: config 5 interface 11 altsetting 12 has a duplicate endpoint with address 0x5, skipping [ 654.158863][ T3079] usb 4-1: new high-speed USB device number 68 using dummy_hcd [ 654.161532][T14115] warn_alloc: 3 callbacks suppressed [ 654.161552][T14115] syz.1.3002: vmalloc error: size 67112960, failed to allocated page array size 131080, mode:0x400dc2(GFP_KERNEL_ACCOUNT|__GFP_HIGHMEM|__GFP_ZERO), nodemask=(null) [ 654.167569][ T5845] usb 3-1: config 5 interface 33 has no altsetting 0 [ 654.180624][T14115] ,cpuset= [ 654.197617][ T5845] usb 3-1: config 5 interface 180 has no altsetting 0 [ 654.199638][T14115] / [ 654.200788][ T5845] usb 3-1: config 5 interface 11 has no altsetting 0 [ 654.217373][T14115] ,mems_allowed=0-1 [ 654.221348][T14115] CPU: 0 UID: 0 PID: 14115 Comm: syz.1.3002 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 654.221381][T14115] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 654.221396][T14115] Call Trace: [ 654.221404][T14115] [ 654.221413][T14115] dump_stack_lvl+0x241/0x360 [ 654.221450][T14115] ? __pfx_dump_stack_lvl+0x10/0x10 [ 654.221481][T14115] ? __pfx__printk+0x10/0x10 [ 654.221508][T14115] ? lock_release+0x4e/0x3e0 [ 654.221533][T14115] ? __rcu_read_unlock+0xa1/0x110 [ 654.221556][T14115] warn_alloc+0x27c/0x410 [ 654.221581][T14115] ? __pfx_warn_alloc+0x10/0x10 [ 654.221605][T14115] ? nf_tables_newset+0x188b/0x30e0 [ 654.221635][T14115] ? __get_vm_area_node+0x1c8/0x2d0 [ 654.221665][T14115] ? __get_vm_area_node+0x25c/0x2d0 [ 654.221699][T14115] __vmalloc_node_range_noprof+0x634/0x1390 [ 654.221732][T14115] ? __pfx___vmalloc_node_range_noprof+0x10/0x10 [ 654.221751][T14115] ? __kasan_kmalloc_large+0x1a/0xa0 [ 654.221779][T14115] ? nf_tables_newset+0x188b/0x30e0 [ 654.221808][T14115] __kvmalloc_node_noprof+0x3b2/0x5a0 [ 654.221841][T14115] ? nf_tables_newset+0x188b/0x30e0 [ 654.221869][T14115] ? nf_tables_newset+0x188b/0x30e0 [ 654.221901][T14115] nf_tables_newset+0x188b/0x30e0 [ 654.221948][T14115] ? __pfx_nf_tables_newset+0x10/0x10 [ 654.221987][T14115] ? __nla_parse+0x40/0x60 [ 654.222014][T14115] nfnetlink_rcv+0x12eb/0x28f0 [ 654.222049][T14115] ? __pfx_nfnetlink_rcv+0x10/0x10 [ 654.222091][T14115] ? skb_clone+0x240/0x390 [ 654.222119][T14115] ? netlink_deliver_tap+0x2e/0x1b0 [ 654.222148][T14115] ? netlink_deliver_tap+0x2e/0x1b0 [ 654.222177][T14115] netlink_unicast+0x7f8/0x9a0 [ 654.222205][T14115] ? __pfx_netlink_unicast+0x10/0x10 [ 654.222230][T14115] ? skb_put+0x114/0x1f0 [ 654.222251][T14115] netlink_sendmsg+0x8c3/0xcd0 [ 654.222284][T14115] ? __pfx_netlink_sendmsg+0x10/0x10 [ 654.222315][T14115] ? aa_sock_msg_perm+0x91/0x160 [ 654.222346][T14115] ? __pfx_netlink_sendmsg+0x10/0x10 [ 654.222373][T14115] __sock_sendmsg+0x221/0x270 [ 654.222401][T14115] ____sys_sendmsg+0x523/0x860 [ 654.222426][T14115] ? __pfx_____sys_sendmsg+0x10/0x10 [ 654.222446][T14115] ? __fget_files+0x2a/0x420 [ 654.222466][T14115] ? __fget_files+0x2a/0x420 [ 654.222489][T14115] __sys_sendmsg+0x271/0x360 [ 654.222512][T14115] ? __pfx___sys_sendmsg+0x10/0x10 [ 654.222557][T14115] ? do_syscall_64+0xb6/0x230 [ 654.222582][T14115] do_syscall_64+0xf3/0x230 [ 654.222605][T14115] ? clear_bhb_loop+0x45/0xa0 [ 654.222629][T14115] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 654.222650][T14115] RIP: 0033:0x7fcf1b18d169 [ 654.222668][T14115] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 654.222687][T14115] RSP: 002b:00007fcf1bfce038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 654.222711][T14115] RAX: ffffffffffffffda RBX: 00007fcf1b3a5fa0 RCX: 00007fcf1b18d169 [ 654.222727][T14115] RDX: 0000000000000000 RSI: 00002000000000c0 RDI: 0000000000000007 [ 654.222742][T14115] RBP: 00007fcf1b20e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 654.222756][T14115] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 654.222770][T14115] R13: 0000000000000000 R14: 00007fcf1b3a5fa0 R15: 00007fcf1b4cfa28 [ 654.222793][T14115] [ 654.222830][T14115] Mem-Info: [ 654.225641][ T5845] usb 3-1: Dual-Role OTG device on HNP port [ 654.238402][T14115] active_anon:25795 inactive_anon:0 isolated_anon:0 [ 654.238402][T14115] active_file:16178 inactive_file:38557 isolated_file:0 [ 654.238402][T14115] unevictable:780 dirty:86 writeback:25 [ 654.238402][T14115] slab_reclaimable:10452 slab_unreclaimable:106823 [ 654.238402][T14115] mapped:31345 shmem:20337 pagetables:978 [ 654.238402][T14115] sec_pagetables:0 bounce:0 [ 654.238402][T14115] kernel_misc_reclaimable:0 [ 654.238402][T14115] free:1286837 free_pcp:2776 free_cma:0 [ 654.375302][ T3079] usb 4-1: device descriptor read/64, error -71 [ 654.376451][T14115] Node 0 active_anon:103180kB inactive_anon:0kB active_file:64712kB inactive_file:154156kB unevictable:1584kB isolated(anon):0kB isolated(file):0kB mapped:125380kB dirty:344kB writeback:0kB shmem:79812kB shmem_thp:0kB shmem_pmdmapped:0kB anon_thp:0kB writeback_tmp:0kB kernel_stack:11224kB pagetables:3912kB sec_pagetables:0kB all_unreclaimable? no Balloon:0kB [ 654.615285][ T3079] usb 4-1: new high-speed USB device number 69 using dummy_hcd [ 654.650024][T14115] Node 1 active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:72kB unevictable:1536kB isolated(anon):0kB isolated(file):0kB mapped:0kB dirty:0kB writeback:0kB shmem:1536kB shmem_thp:0kB shmem_pmdmapped:0kB anon_thp:0kB writeback_tmp:0kB kernel_stack:48kB pagetables:0kB sec_pagetables:0kB all_unreclaimable? no Balloon:0kB [ 654.685103][ T5845] usb 3-1: New USB device found, idVendor=0499, idProduct=1043, bcdDevice=43.34 [ 654.694746][ T5845] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 654.702950][ T5845] usb 3-1: Product: ☏콾䓿虜酴᧻ [ 654.708756][T14115] Node 0 DMA free:15360kB boost:0kB min:208kB low:260kB high:312kB reserved_highatomic:0KB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15360kB mlocked:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB [ 654.736326][ T5845] usb 3-1: Manufacturer:  [ 654.741962][ T5845] usb 3-1: SerialNumber: syz [ 654.754725][T14115] lowmem_reserve[]: 0 2487 2487 2487 2487 [ 654.755885][ T5845] usb 3-1: can't set config #5, error -71 [ 654.770515][T14115] Node 0 DMA32 free:1219900kB boost:0kB min:34152kB low:42688kB high:51224kB reserved_highatomic:0KB active_anon:103172kB inactive_anon:0kB active_file:64712kB inactive_file:154064kB unevictable:1584kB writepending:340kB present:3129332kB managed:2547264kB mlocked:0kB bounce:0kB free_pcp:11236kB local_pcp:11172kB free_cma:0kB [ 654.777961][ T5845] usb 3-1: USB disconnect, device number 68 [ 654.808829][T14115] lowmem_reserve[]: 0 0 0 0 0 [ 654.813919][T14115] Node 0 Normal free:0kB boost:0kB min:0kB low:0kB high:0kB reserved_highatomic:0KB active_anon:8kB inactive_anon:0kB active_file:0kB inactive_file:92kB unevictable:0kB writepending:0kB present:1048580kB managed:108kB mlocked:0kB bounce:0kB free_pcp:8kB local_pcp:8kB free_cma:0kB [ 654.840817][T14115] lowmem_reserve[]: 0 0 0 0 0 [ 654.845743][T14115] Node 1 Normal free:3912484kB boost:0kB min:55748kB low:69684kB high:83620kB reserved_highatomic:0KB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:72kB unevictable:1536kB writepending:0kB present:4194300kB managed:4111164kB mlocked:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB [ 654.865375][ T3079] usb 4-1: device descriptor read/64, error -71 [ 654.876159][T14115] lowmem_reserve[]: 0 0 0 0 0 [ 654.890162][T14115] Node 0 DMA: 0*4kB 0*8kB 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB 0*512kB 1*1024kB (U) 1*2048kB (M) 3*4096kB (M) = 15360kB [ 654.904650][T14115] Node 0 DMA32: 29*4kB (UME) 468*8kB (UME) 245*16kB (UME) 211*32kB (UME) 340*64kB (UME) 461*128kB (UM) 209*256kB (UME) 155*512kB (UM) 92*1024kB (UME) 2*2048kB (M) 218*4096kB (UM) = 1219396kB [ 654.925638][T14115] Node 0 Normal: 0*4kB 0*8kB 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 0kB [ 654.938568][T14115] Node 1 Normal: 197*4kB (UE) 48*8kB (UME) 33*16kB (UME) 160*32kB (UME) 86*64kB (UME) 28*128kB (UME) 15*256kB (UME) 5*512kB (UM) 3*1024kB (UME) 4*2048kB (UME) 947*4096kB (M) = 3912484kB [ 654.959125][T14115] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 654.970766][T14115] Node 0 hugepages_total=4 hugepages_free=4 hugepages_surp=0 hugepages_size=2048kB [ 654.982214][T14115] Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=1048576kB [ 654.991874][T14115] Node 1 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB [ 654.995596][ T3079] usb usb4-port1: attempt power cycle [ 655.001519][T14115] 75056 total pagecache pages [ 655.011355][T14115] 0 pages in swap cache [ 655.015734][T14115] Free swap = 124996kB [ 655.019937][T14115] Total swap = 124996kB [ 655.024132][T14115] 2097051 pages RAM [ 655.028192][T14115] 0 pages HighMem/MovableOnly [ 655.032926][T14115] 428577 pages reserved [ 655.037248][T14115] 0 pages cma reserved [ 655.207590][ T53] usb 5-1: string descriptor 0 read error: -71 [ 655.226729][ T53] ir_toy 5-1:8.177: required endpoints not found [ 655.235940][ T53] usb 5-1: USB disconnect, device number 71 [ 655.355329][ T3079] usb 4-1: new high-speed USB device number 70 using dummy_hcd [ 655.376019][ T3079] usb 4-1: device descriptor read/8, error -71 [ 655.615664][ T3079] usb 4-1: new high-speed USB device number 71 using dummy_hcd [ 655.635943][ T3079] usb 4-1: device descriptor read/8, error -71 [ 655.749158][ T3079] usb usb4-port1: unable to enumerate USB device