last executing test programs: 6m50.093797626s ago: executing program 2 (id=153): fsopen(&(0x7f0000000300)='befs\x00', 0x1) socketpair$unix(0x1, 0x2, 0x0, &(0x7f00000000c0)={0xffffffffffffffff}) r1 = syz_io_uring_setup(0x8d0, 0x0, &(0x7f0000000000)=0x0, &(0x7f0000000080)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000180)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r2, r3, &(0x7f0000000200)=@IORING_OP_WRITEV={0x2, 0x0, 0x0, @fd_index=0x4, 0x0, 0x0}) io_uring_enter(r1, 0x47ba, 0x3e80, 0x2, 0x0, 0x0) ioctl$int_in(r0, 0x5452, &(0x7f0000000040)=0x5) 6m49.972575669s ago: executing program 2 (id=155): timer_create(0x3, 0x0, &(0x7f0000000300)) prctl$PR_SET_SECCOMP(0x16, 0x1, 0x0) timer_settime(0x0, 0x0, &(0x7f000006b000)={{0x0, 0x8}, {0x0, 0x9}}, 0x0) syz_emit_ethernet(0x51, &(0x7f0000000300)={@local, @random="ea6ea66e83a6", @void, {@ipv6={0x86dd, @icmpv6={0xa, 0x6, "50b0ef", 0x1b, 0x3a, 0xff, @empty, @local, {[], @ndisc_ns={0x87, 0x0, 0x0, @remote, [{0x5, 0x0, "d20f652b2b"}]}}}}}}, 0x0) 6m48.915784266s ago: executing program 2 (id=161): r0 = syz_usb_connect$hid(0x5, 0x36, &(0x7f0000000240)=ANY=[@ANYBLOB="12010000000000404c05f20dafd60000000109022400010000000009040000010300010009210101000122050009058103"], 0x0) syz_usb_connect$uac1(0x3, 0xc0, &(0x7f0000000080)={{0x12, 0x1, 0x300, 0x0, 0x0, 0x0, 0x40, 0x1d6b, 0x101, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0xae, 0x3, 0x1, 0x6, 0x0, 0xfc, {{0x9, 0x4, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, {{0xa, 0x24, 0x1, 0xb, 0x7}, [@processing_unit={0xc, 0x24, 0x7, 0x5, 0x4, 0x4, "4dc5b69f09"}, @mixer_unit={0x8, 0x24, 0x4, 0x5, 0x8, "f1b72c"}]}}, {}, {0x9, 0x4, 0x1, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {[@format_type_i_discrete={0x9, 0x24, 0x2, 0x1, 0x5, 0x3, 0xd, 0x31, "97"}, @format_type_i_continuous={0x9, 0x24, 0x2, 0x1, 0xa1, 0x2, 0x0, 0x7, "", "89"}, @as_header={0x7, 0x24, 0x1, 0xdc, 0x6}, @as_header={0x7, 0x24, 0x1, 0x3, 0x1, 0x2}, @format_type_i_discrete={0xa, 0x24, 0x2, 0x1, 0xff, 0x1, 0x5, 0x7, "ecf3"}, @format_type_i_continuous={0xa, 0x24, 0x2, 0x1, 0x3, 0x2, 0x5, 0x0, 'm-'}]}, {{0x9, 0x5, 0x1, 0x9, 0x400, 0x7d, 0x7, 0xd4, {0x7, 0x25, 0x1, 0x2, 0x7a, 0x800}}}}, {}, {0x9, 0x4, 0x2, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {[@as_header={0x7, 0x24, 0x1, 0x6, 0x2b, 0x1}]}, {{0x9, 0x5, 0x82, 0x9, 0x200, 0x4f, 0x1, 0x1, {0x7, 0x25, 0x1, 0x86, 0x4, 0x8001}}}}}}}]}}, &(0x7f0000000280)={0xa, &(0x7f0000000140)={0xa, 0x6, 0x250, 0x3, 0xf, 0x9, 0x40, 0x9}, 0x1d, &(0x7f0000000180)={0x5, 0xf, 0x1d, 0x1, [@ssp_cap={0x18, 0x10, 0xa, 0x4, 0x3, 0x8, 0x1100, 0x1, [0xff0000, 0x0, 0xff0000]}]}, 0x1, [{0x59, &(0x7f00000001c0)=@string={0x59, 0x3, "e79045ac8fc2e4dad9e3ac19deb2401748236b1bc898444badb4e15fc259fe99b2cfaa88420bad07e57e5d63390a0ce02678d82b9a02ba128e30ba3b752f8a68f1548b2709ddbf3752ab6d902e5bd32a1b4f8b9099464b"}}]}) syz_usb_control_io(r0, 0x0, 0x0) syz_usb_control_io(r0, &(0x7f00000003c0)={0x2c, &(0x7f0000000040)=ANY=[@ANYBLOB="000657"], 0x0, 0x0, 0x0, 0x0}, 0x0) syz_usb_control_io(r0, 0x0, &(0x7f0000000e40)={0x84, &(0x7f0000000000)=ANY=[@ANYBLOB="001e14"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) 6m47.053055137s ago: executing program 2 (id=163): mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x0) r0 = syz_usb_connect$hid(0x0, 0x36, &(0x7f0000000000)=ANY=[@ANYBLOB="12013f00000000407f04ffff000000000001090224000100000000090400001503000000092140000001220f00090581d7"], 0x0) syz_usb_control_io$hid(r0, 0x0, 0x0) syz_usb_control_io$hid(r0, &(0x7f0000000080)={0x24, 0x0, 0x0, &(0x7f00000000c0)={0x0, 0x22, 0xf, {[@main=@item_4={0x3, 0x0, 0x8, '\t\x00'}, @local=@item_4={0x3, 0x2, 0x0, "93bf0280"}, @main=@item_4={0x3, 0x0, 0x6, "00008000"}]}}, 0x0}, 0x0) r1 = syz_open_dev$hiddev(&(0x7f0000000540), 0x0, 0x0) ioctl$HIDIOCGREPORT(r1, 0x400c4807, &(0x7f0000000280)={0x3, 0x200, 0xfffffffe}) r2 = open_tree(0xffffffffffffff9c, &(0x7f0000000000)='./file0\x00', 0x89901) move_mount(r2, &(0x7f0000000140)='.\x00', 0xffffffffffffff9c, &(0x7f0000000180)='./file0\x00', 0x0) chroot(&(0x7f0000000300)='./file0/../file0/../file0/../file0\x00') syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) r3 = open_tree(0xffffffffffffff9c, &(0x7f0000000640)='\x00', 0x89901) move_mount(r3, &(0x7f0000000140)='.\x00', 0xffffffffffffff9c, &(0x7f0000000300)='./file0\x00', 0x0) pivot_root(&(0x7f0000000080)='./file0\x00', &(0x7f0000000200)='./file0/../file0/../file0/../file0\x00') syz_usb_connect$uac1(0x0, 0xa6, &(0x7f00000000c0)={{0x12, 0x1, 0x300, 0x0, 0x0, 0x0, 0x40, 0x1d6b, 0x101, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x94, 0x3, 0x1, 0x10, 0x10, 0x6, {{0x9, 0x4, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, {{0xa, 0x24, 0x1, 0x8001}, [@extension_unit={0x7, 0x24, 0x8, 0x4, 0x1, 0x5}, @processing_unit={0xc, 0x24, 0x7, 0x3, 0x0, 0x0, "d885700585"}]}}, {}, {0x9, 0x4, 0x1, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {[@format_type_i_continuous={0xc, 0x24, 0x2, 0x1, 0x2, 0x3, 0x3, 0x1, 'b', 'Qq\t'}]}, {{0x9, 0x5, 0x1, 0x9, 0x10, 0x14, 0x4, 0xcc, {0x7, 0x25, 0x1, 0x1, 0x7f, 0x4}}}}, {}, {0x9, 0x4, 0x2, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {[@as_header={0x7, 0x24, 0x1, 0x1, 0x5, 0x1002}, @format_type_ii_discrete={0xf, 0x24, 0x2, 0x2, 0x6896, 0x2, 0x0, "78f4cd9535ca"}]}, {{0x9, 0x5, 0x82, 0x9, 0x8, 0x7, 0x4, 0x3, {0x7, 0x25, 0x1, 0x2, 0xf4}}}}}}}]}}, &(0x7f0000000480)={0x0, 0x0, 0x0, 0x0}) 6m45.102807445s ago: executing program 2 (id=172): r0 = openat$khugepaged_scan(0xffffffffffffff9c, &(0x7f0000000000), 0x1, 0x0) readv(r0, &(0x7f0000001080)=[{&(0x7f0000000080)=""/4096, 0x1000}], 0x1) r1 = socket$nl_generic(0x10, 0x3, 0x10) r2 = msgget$private(0x0, 0x272) msgsnd(r2, &(0x7f00000010c0)={0x0, "cec9a359c2c59624e9dbbebd392368b9cc1d149b40f3c36d610119da354ead56c465dcb43aec5e830342e9971d28e10fd6db13e89317b612f719c67882fe14c8350ad21f96050d6c9310981c01ca69dd3a2f7a5dcd"}, 0x5d, 0x800) getuid() syz_genetlink_get_family_id$nl80211(&(0x7f0000001140), r1) socket$nl_netfilter(0x10, 0x3, 0xc) msgctl$IPC_INFO(r2, 0x3, &(0x7f0000001180)=""/240) r3 = openat(0xffffffffffffff9c, &(0x7f0000001280)='./file0\x00', 0x2, 0x14) ioctl$LOOP_CTL_REMOVE(r3, 0x4c81, 0xb) r4 = syz_genetlink_get_family_id$ethtool(&(0x7f0000001300), r1) sendmsg$ETHTOOL_MSG_FEATURES_SET(r1, &(0x7f0000001680)={&(0x7f00000012c0)={0x10, 0x0, 0x0, 0x80}, 0xc, &(0x7f0000001640)={&(0x7f0000001340)={0x2d0, r4, 0x20, 0x70bd27, 0x25dfdbfe, {}, [@ETHTOOL_A_FEATURES_WANTED={0x1c, 0x3, 0x0, 0x1, [@ETHTOOL_A_BITSET_SIZE={0x8, 0x2, 0x5}, @ETHTOOL_A_BITSET_BITS={0x10, 0x3, 0x0, 0x1, [{0xc, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x9}]}]}]}, @ETHTOOL_A_FEATURES_WANTED={0x1c4, 0x3, 0x0, 0x1, [@ETHTOOL_A_BITSET_BITS={0x1c0, 0x3, 0x0, 0x1, [{0x10, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_NAME={0x6, 0x2, '{\x00'}]}, {0x10, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x1bba00c8}]}, {0x38, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x1}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0xfffff9a2}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0xff}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0xfffffffe}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}]}, {0x14, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x8}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8}]}, {0x28, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_NAME={0x6, 0x2, '\\\x00'}, @ETHTOOL_A_BITSET_BIT_NAME={0x6, 0x2, '&\x00'}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x47e}, @ETHTOOL_A_BITSET_BIT_NAME={0xc, 0x2, 'nl80211\x00'}]}, {0x4c, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x400}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x6}, @ETHTOOL_A_BITSET_BIT_NAME={0x6, 0x2, '[\x00'}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x2}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_NAME={0xb, 0x2, '\\&{*&$\x00'}, @ETHTOOL_A_BITSET_BIT_NAME={0x6, 0x2, ')\x00'}, @ETHTOOL_A_BITSET_BIT_NAME={0xc, 0x2, 'nl80211\x00'}]}, {0x38, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x2}, @ETHTOOL_A_BITSET_BIT_NAME={0xc, 0x2, 'nl80211\x00'}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x7}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_NAME={0x6, 0x2, '-\x00'}, @ETHTOOL_A_BITSET_BIT_NAME={0x7, 0x2, ',.\x00'}]}, {0x20, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x8}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x6}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}]}, {0x74, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_NAME={0x48, 0x2, '/sys/kernel/mm/transparent_hugepage/khugepaged/scan_sleep_millisecs\x00'}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_NAME={0xc, 0x2, 'nl80211\x00'}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x2}, @ETHTOOL_A_BITSET_BIT_VALUE={0x4}, @ETHTOOL_A_BITSET_BIT_INDEX={0x8, 0x1, 0x7}]}, {0x10, 0x1, 0x0, 0x1, [@ETHTOOL_A_BITSET_BIT_NAME={0xc, 0x2, 'nl80211\x00'}]}]}]}, @ETHTOOL_A_FEATURES_HEADER={0x4}, @ETHTOOL_A_FEATURES_WANTED={0x4}, @ETHTOOL_A_FEATURES_WANTED={0xd4, 0x3, 0x0, 0x1, [@ETHTOOL_A_BITSET_MASK={0xcd, 0x5, "e288b975e82b7494810bb948d40212b37baa7b42f8f940a2d6ff7a049dcb3aa073de0a5634b6a2373534b200d2614edc0a1268981a2e5876732de66c7bb640e3d2b78ebfae2d8b3868d203f2d4fab57df2e642e8e43ed2aacb761cc6299669d228a11c1be5b35b0f545e86956b841f075f8ed626d52e46d37cf2d9ae468d00f636013b83fe24a4c45bbb5201e8498ac43bf91dea71dcb4d715b495ff8ab12567bad8adaf6cbd3760cc5897335610a8e4979100e346643ede3ac457ac90a21cab48062bee4578dce2ef"}]}]}, 0x2d0}, 0x1, 0x0, 0x0, 0x40}, 0x8805) bpf$BPF_GET_PROG_INFO(0xf, &(0x7f0000001980)={0xffffffffffffffff, 0xe0, &(0x7f0000001880)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x6, &(0x7f00000016c0)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0], ""/16, 0x0, 0x0, 0x0, 0x0, 0x2, 0x7, &(0x7f0000001700)=[0x0, 0x0], &(0x7f0000001740)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0], 0x0, 0x3a, &(0x7f0000001780)=[{}, {}, {}, {}, {}, {}, {}], 0x38, 0x10, &(0x7f00000017c0), &(0x7f0000001800), 0x8, 0xd6, 0x8, 0x8, &(0x7f0000001840)}}, 0x10) r7 = bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f00000019c0)={r3, 0x0, 0x25, 0x0, @val=@tracing={r6, 0xfff}}, 0x20) r8 = openat$nvram(0xffffffffffffff9c, &(0x7f0000001a00), 0x199040, 0x0) listen(r8, 0x1) openat$random(0xffffffffffffff9c, &(0x7f0000001a40), 0x82000, 0x0) mlockall(0x2) msgget(0x1, 0x0) r9 = bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f0000001a80)={r8, r5, 0x25, 0xa, @val=@netkit={@void, @value=r8}}, 0x1c) r10 = bpf$ITER_CREATE(0x21, &(0x7f0000001ac0)={r9}, 0x8) ioctl$KVM_CREATE_PIT2(0xffffffffffffffff, 0x4040ae77, &(0x7f0000001b00)={0x8000}) ioctl$KDFONTOP_GET(r3, 0x4b72, &(0x7f0000001f40)={0x1, 0x1, 0x8, 0x19, 0x7d, &(0x7f0000001b40)}) r11 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$devlink(&(0x7f0000001f80), r11) sendmsg$ETHTOOL_MSG_EEE_GET(0xffffffffffffffff, &(0x7f00000020c0)={&(0x7f0000001fc0)={0x10, 0x0, 0x0, 0x40}, 0xc, &(0x7f0000002080)={&(0x7f0000002000)={0x50, r4, 0x4, 0x70bd2a, 0x25dfdbfd, {}, [@HEADER={0x1c, 0x1, 0x0, 0x1, [@ETHTOOL_A_HEADER_FLAGS={0x8}, @ETHTOOL_A_HEADER_FLAGS={0x8, 0x3, 0x1}, @ETHTOOL_A_HEADER_FLAGS={0x8, 0x3, 0x3}]}, @HEADER={0x20, 0x1, 0x0, 0x1, [@ETHTOOL_A_HEADER_DEV_INDEX={0x8}, @ETHTOOL_A_HEADER_DEV_NAME={0x14, 0x2, 'caif0\x00'}]}]}, 0x50}, 0x1, 0x0, 0x0, 0x4}, 0x40) ioctl$FIONREAD(r8, 0x541b, &(0x7f0000002100)) write$6lowpan_enable(r10, &(0x7f0000002140)='1', 0x1) ioctl$BTRFS_IOC_SNAP_DESTROY_V2(r11, 0x5000943f, &(0x7f0000002800)={{r7}, 0x0, 0x14, @inherit={0x80, &(0x7f0000002380)={0x1, 0x7, 0xb, 0x43, {0x8, 0x4, 0x0, 0x6beb7288, 0x2}, [0x2, 0xecd, 0x400, 0x3, 0x365d, 0x6, 0x5]}}, @devid}) 6m44.843589239s ago: executing program 2 (id=174): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = socket$nl_generic(0x10, 0x3, 0x10) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f00000000c0)) r2 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000000), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(r1, 0x8933, &(0x7f0000000040)={'wlan1\x00', 0x0}) sendmsg$NL80211_CMD_JOIN_IBSS(r1, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000580)={&(0x7f0000000080)=ANY=[@ANYBLOB='4\x00\x00\x00', @ANYRES16=r2, @ANYBLOB="010100000000000000002b00000008000300", @ANYRES32=r3], 0x34}}, 0x40080) syz_open_dev$evdev(0x0, 0x7, 0x0) sendmsg$IPCTNL_MSG_CT_NEW(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000280)={0x9c, 0x0, 0x1, 0x401, 0x0, 0x0, {0x2, 0x0, 0x5}, [@CTA_TUPLE_ORIG={0x2c, 0x1, 0x0, 0x1, [@CTA_TUPLE_IP={0x14, 0x1, 0x0, 0x1, @ipv4={{0x8, 0x1, @empty}, {0x8, 0x2, @dev}}}, @CTA_TUPLE_IP={0x14, 0x1, 0x0, 0x1, @ipv4={{0x8, 0x1, @dev={0xac, 0x14, 0x14, 0x2a}}, {0x8, 0x2, @local}}}]}, @CTA_TUPLE_REPLY={0x24, 0x2, 0x0, 0x1, [@CTA_TUPLE_PROTO={0xc, 0x2, 0x0, 0x1, {0x5}}, @CTA_TUPLE_IP={0x14, 0x1, 0x0, 0x1, @ipv4={{0x8, 0x1, @multicast2}, {0x8, 0x2, @multicast2}}}]}, @CTA_LABELS_MASK={0x20, 0x17, [0x80000001, 0xffffffff, 0x9, 0xd190, 0x6, 0x9, 0xa]}, @CTA_NAT_SRC={0x18, 0x6, 0x0, 0x1, [@CTA_NAT_V4_MAXIP={0x8, 0x2, @dev}, @CTA_NAT_PROTO={0xc, 0x3, 0x0, 0x1, [@CTA_PROTONAT_PORT_MAX={0x6, 0x2, 0x4e22}]}]}]}, 0x9c}}, 0x0) sendmsg$nl_generic(r0, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000400)=ANY=[@ANYBLOB="340000003e0007010000000000000000017c00000400fc800c000180060006006558000008000280040011"], 0x34}, 0x1, 0x0, 0x0, 0xc000}, 0xc010) 6m44.110170315s ago: executing program 32 (id=174): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = socket$nl_generic(0x10, 0x3, 0x10) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f00000000c0)) r2 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000000), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(r1, 0x8933, &(0x7f0000000040)={'wlan1\x00', 0x0}) sendmsg$NL80211_CMD_JOIN_IBSS(r1, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000580)={&(0x7f0000000080)=ANY=[@ANYBLOB='4\x00\x00\x00', @ANYRES16=r2, @ANYBLOB="010100000000000000002b00000008000300", @ANYRES32=r3], 0x34}}, 0x40080) syz_open_dev$evdev(0x0, 0x7, 0x0) sendmsg$IPCTNL_MSG_CT_NEW(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000280)={0x9c, 0x0, 0x1, 0x401, 0x0, 0x0, {0x2, 0x0, 0x5}, [@CTA_TUPLE_ORIG={0x2c, 0x1, 0x0, 0x1, [@CTA_TUPLE_IP={0x14, 0x1, 0x0, 0x1, @ipv4={{0x8, 0x1, @empty}, {0x8, 0x2, @dev}}}, @CTA_TUPLE_IP={0x14, 0x1, 0x0, 0x1, @ipv4={{0x8, 0x1, @dev={0xac, 0x14, 0x14, 0x2a}}, {0x8, 0x2, @local}}}]}, @CTA_TUPLE_REPLY={0x24, 0x2, 0x0, 0x1, [@CTA_TUPLE_PROTO={0xc, 0x2, 0x0, 0x1, {0x5}}, @CTA_TUPLE_IP={0x14, 0x1, 0x0, 0x1, @ipv4={{0x8, 0x1, @multicast2}, {0x8, 0x2, @multicast2}}}]}, @CTA_LABELS_MASK={0x20, 0x17, [0x80000001, 0xffffffff, 0x9, 0xd190, 0x6, 0x9, 0xa]}, @CTA_NAT_SRC={0x18, 0x6, 0x0, 0x1, [@CTA_NAT_V4_MAXIP={0x8, 0x2, @dev}, @CTA_NAT_PROTO={0xc, 0x3, 0x0, 0x1, [@CTA_PROTONAT_PORT_MAX={0x6, 0x2, 0x4e22}]}]}]}, 0x9c}}, 0x0) sendmsg$nl_generic(r0, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000400)=ANY=[@ANYBLOB="340000003e0007010000000000000000017c00000400fc800c000180060006006558000008000280040011"], 0x34}, 0x1, 0x0, 0x0, 0xc000}, 0xc010) 3m8.591601177s ago: executing program 0 (id=1101): r0 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r0, &(0x7f0000000140)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000280)=ANY=[@ANYBLOB="170000001400010000000000fcdbdf2502"], 0x34}, 0x1, 0x0, 0x0, 0x20008814}, 0x0) (async) openat$tun(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) (async) r1 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) (async) r2 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000140), 0x101000, 0x0) r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0) r4 = ioctl$KVM_CREATE_VCPU(r3, 0xae41, 0x0) ioctl$KVM_SET_MSRS(r4, 0xc008ae88, &(0x7f0000000040)=ANY=[@ANYBLOB="01000000000000ec8502"]) (async) futex(&(0x7f000000cffc)=0x1, 0xd, 0x0, 0x0, 0x0, 0x0) (async) r5 = socket$inet_udplite(0x2, 0x2, 0x88) sendmmsg$inet(r5, &(0x7f0000005b40)=[{{0x0, 0x0, &(0x7f0000000400)=[{&(0x7f0000000380)="c1ad061c5d914eadd95de7fb63eb7b0306d91c25f3fba6c97eda8ade2420dfe1fe0f5c7a01d724be33a44f1cd52028110d8f7dd4b3421a3fe4b2066d179f938ba15c3956e1aaad35035bcde7b90ed59ee2de06c8a4af3de95bda", 0x5a}], 0x1}}, {{0x0, 0x0, &(0x7f0000001780)=[{&(0x7f0000000480)="f41fa963edcd5e2a5d", 0x9}, {&(0x7f00000004c0)="0c71e8d7705b19c24e8c3ec98b4243ae0be48cd79f024361b8082d328363e63e360e122e7ec929c89aea0b338987609655fb5f5f91cd457584f30946f63e00fd0e8c536ae0106beb7d02fb4eb35db10c37c4bf3f2c6df9254d540598ae9b7098b74908c7da448e8891bc1b46f58553776f43370d090df693f3a4e4a724dbb498e51860bd766e36c41c0a0ee41019a0b05b519107c1fbb944f26f16f9fc127f3cd86c3fdbcf169912fc1c42a4a7051d3e85591ccd24b19681da775dc34c98ad24ab07c6feab583ba1f5efb430a06d66c039dbf40a84f04cfdfca240676e96579502925e57864815d3fe17edaf5cdbc3a4b48843c22372f9f1cf363d8428fe6341fb474ba53db6be689703ce5f7b6639b3493a5aca4c9316df8b4600d73533021932eb359ce7c1f00a54cb1318076ccb00e27ba0934db1867e078ee47b86d3e367b96ba948c3aa029c365eb0dc99685c5fd7bfbd1916b889da42d6ad1ab2466e989b5c8304b1e2190d4efeb9ccbd3a7a48c3b393470fc215e164cb91e238c5a28c4f40b4b99ee8f9481fe62e0bcf0a9831e491dc1150ad9c023217df6432487219a3083b310958cdbc217f99d02a19414987ff1bc176e3267c205827f466ea1912cbc0e304faf034602b85db010d8796d2ab18c2c4badf39db5312ad908d8555c30d0cc7d3bce8b4fcfc5764ed6e8bf4e8e4af6bbb3f82ac014f021dc6cb81cebe4b7d071e4d019719d1b0354ce0a2ff3b66ba7bf0f4598bde90a9115ddc4f197bcd881e0cd0baabb57316e75d108b14acc668ee906acf7bffdff3aef11ecf107b3eccd67a56c6b26e0a9a72d404a7a2dd3da8759e676c0eef6a95890d4f647269d1bf972d75307bd867819f385df6f57a7c28332307f444d1157c303c30a478b056d6e11111398aafcb6fff1b6a985cf888afa04586e35e7d3b292d254acf08a6bd38fbbd22bc9919052e6693c1e454aade6348679e027d1b102618476c9ab1f9928fc7f505046cb8383b9e1d79b961895502cded12f1842705102dffddc11f7bea0bd53833f1a455e661f6bda92d35b1159e1489cf762da76c125060ffedc7cc54238b3bd2d894a91d92a6c5cce9bf5417674a2bd0e38271912f7481e58ec7ab422db826482ffb80ce45dab2cb43105356c292a2fd1db8a758b37d56f46721163f24c075d980a37917cca20acce274c404828efaed50b881a5481f9ad268e99e25884db25426d5a5f338f405748817bba32b89e4c18b0f061e6758d46b5f0f2865b1c41be4f7ff999d289538a8fca45b2cf76a2fc3", 0x395}], 0x2}}, {{0x0, 0x0, &(0x7f0000005ac0)=[{&(0x7f0000005980)="278fb09c2d1b28d358c37163cdbcea0d3723d2f440dae37ff1e9f214207c3f6aff47eb2913dd9b48cb5b253ba36515ef2d4b8682394c2ff478fe859129215c9f1a7e036340f082e2776b3055f5937046f4558f3de7beeeed07920aa523a3c6ccf5a9ef0eaf7fe98b8fe5404899bf5d3e8b83c82bbf1b733310bbb138", 0x7c}, {&(0x7f0000005a00)="e38e548b32c2e89c36ec6cbecb4361663bdb865da192ece8e480b2278fd82f8500c00cbe6fc87ea1f8b4f0de6e3966f90c8b54558118e5f17cce6dd68ede66e146e23413e9a099461e465bade37a82aea19493d79e1940ff39c6ddbb9cf3c7f279ff94da9a08a480c1458960e694ce16adc1795c3e533ddfc6ba1a7a94c6d95065f7ed321a3c02570af9fbade5fe0ebec78f88e0cc5b9b746eb6d72b2a4db65e6f6a8f7a9aecf4ab05b081caf31e7c124907eb41a29a87b15c7cad28", 0xbc}, {&(0x7f0000005c40)="1268d79933925249a8f49eeb663bc87186869bbbf4e6bc9132220ec1bbfbf15decd45eaf8fcfa39f27e2e5abab556ae3a759134dd3f6973f415be87c4cea23104c5fabf3f84c29fce9e4bac27e20fb021b60e6342ce36775d7dca5b573c331e834032b458910e5d382106c90d1ab0e7062a8690c8fd26eaaa24ff60393bfe0fbe4d96a30b59b04ebaa3101f8c3572cdf6e77813090ae053b2edc4319cd9ecae65e3704d79808085c1e8626de58acd2f23a3c1edf2db92498f1e929b3c637f0746d4dcd9a24195a0082", 0xc9}, {&(0x7f0000005d40)="8ef0e964a69f2aa2d96d1605302a119b3bbe6f743dc0813e052ee83f5d8fced21fe7924cae0dedeff228c6b2cc6316a1a06ca064a3ce587c458fc0d3508f6f62e9274f77b3ab8c9736c64c51cb6bb12d00ba7984eead164b582102e5658ae57f2489b7dc6b24f830a3d0aa861e19cbd8c0cbd1a94da7a0ff76e6d333880cb60eb8f05038ff7aaa3276329958f061e24053a74157a235dfea976dd4ea584e48d50a6857a12e2859bb8370cfd4c18aa37736f54fd53c5852591b3e5158353134364b2c7e3d", 0xc4}, {&(0x7f0000001c40)}], 0x5}}], 0x3, 0xc080) (async) recvmmsg(r5, &(0x7f0000005500)=[{{&(0x7f00000000c0)=@nfc_llcp, 0x80, &(0x7f0000000580)=[{&(0x7f0000000040)=""/36, 0x24}, {&(0x7f0000000200)=""/17, 0x11}, {&(0x7f0000000180)=""/46, 0x2e}, {&(0x7f00000056c0)=""/200, 0xc8}, {&(0x7f00000002c0)=""/229, 0xe5}, {&(0x7f0000000880)=""/121, 0x79}, {&(0x7f0000000540)=""/35, 0x23}], 0x7, &(0x7f0000000680)=""/253, 0xfd}, 0x100}, {{0x0, 0x0, &(0x7f0000000ac0)=[{&(0x7f0000000780)=""/132, 0x84}, {&(0x7f0000000600)=""/15, 0xf}], 0x2, &(0x7f0000000a00)=""/149, 0x95}, 0x6}, {{0x0, 0x0, &(0x7f0000000b00)=[{&(0x7f0000000440)=""/7, 0x7}], 0x1, &(0x7f0000005e40)=""/128, 0x80}, 0xfffffff9}, {{0x0, 0x0, &(0x7f0000002140)=[{&(0x7f0000000c40)=""/4096, 0x1000}, {&(0x7f00000009c0)=""/28, 0x1c}, {&(0x7f0000001c80)=""/5, 0x5}, {&(0x7f0000001cc0)=""/21, 0x15}, {&(0x7f0000001dc0)=""/120, 0x78}, {&(0x7f0000001e40)=""/126, 0x7e}, {&(0x7f0000001f00)=""/186, 0xba}, {&(0x7f0000001fc0)=""/221, 0xdd}, {&(0x7f00000020c0)=""/128, 0x80}], 0x9}, 0x2}, {{&(0x7f0000002280)=@generic, 0x80, &(0x7f0000004480)=[{&(0x7f0000002300)=""/189, 0xbd}, {&(0x7f0000002400)=""/4096, 0x1000}, {&(0x7f0000003400)=""/30, 0x1e}, {&(0x7f0000003440)=""/4096, 0x1000}, {&(0x7f0000004440)=""/59, 0x3b}], 0x5, &(0x7f0000004500)=""/4096, 0x1000}, 0xb}], 0x5, 0x10000, &(0x7f0000005640)={0x0, 0x3938700}) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)) (async) r6 = socket$packet(0x11, 0x2, 0x300) (async) r7 = socket$packet(0x11, 0x2, 0x300) ioctl$sock_SIOCGIFINDEX(r7, 0x8933, &(0x7f0000000000)={'syz_tun\x00', 0x0}) r9 = socket$packet(0x11, 0x2, 0x300) getsockopt$packet_int(r9, 0x107, 0x17, 0x0, &(0x7f00000001c0)) (async) bind$packet(r6, &(0x7f00000000c0)={0x11, 0x1b, r8, 0x1, 0x0, 0x6, @local}, 0x14) (async) bind$packet(r6, &(0x7f0000000100)={0x11, 0x4, r8}, 0x14) (async) syz_emit_ethernet(0x82, &(0x7f00000057c0)=ANY=[@ANYBLOB="aaaaaaaaaaaa0180c20097020000000470768d056d677583fd3ccd7187b1c36ec28f32a303a5d75835b2ee406ec9060565a4d29cf06a02b34341962887101f847f973222694b8213ffe123aefd4ea3e071c17edf5ea5614683d2c43f852955819d0007963b4e5b9a1b9b949624d371f1e66cdb89634204316a42"], 0x0) (async) r10 = ioctl$KVM_CREATE_VM(r1, 0xae01, 0x0) ioctl$KVM_CREATE_IRQCHIP(r10, 0xae60) (async) ioctl$KVM_SET_USER_MEMORY_REGION(r10, 0x4020ae46, &(0x7f0000000400)={0x1ff, 0x1, 0x0, 0x1000, &(0x7f0000001000/0x1000)=nil}) (async) r11 = ioctl$KVM_CREATE_VCPU(r10, 0xae41, 0x0) ioctl$KVM_SET_VAPIC_ADDR(r11, 0x4008ae93, &(0x7f0000000040)=0x4) (async) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) (async) socket$nl_netfilter(0x10, 0x3, 0xc) linkat(0xffffffffffffffff, 0x0, 0xffffffffffffffff, 0x0, 0x2800) ioctl$KVM_RUN(r11, 0xae80, 0x0) 3m8.338645182s ago: executing program 0 (id=1103): socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000000)) r0 = gettid() timer_create(0x0, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004, @tid=r0}, &(0x7f0000bbdffc)) timer_settime(0x0, 0x0, &(0x7f0000000000)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) r1 = socket$can_j1939(0x1d, 0x2, 0x7) ioctl$ifreq_SIOCGIFINDEX_vcan(r1, 0x8933, &(0x7f0000000000)={'vcan0\x00'}) socket$nl_route(0x10, 0x3, 0x0) setsockopt$XDP_UMEM_FILL_RING(0xffffffffffffffff, 0x11b, 0x5, &(0x7f0000000440)=0x100040, 0x4) r2 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000380)='./binderfs/binder0\x00', 0x0, 0x0) ioctl$BINDER_SET_CONTEXT_MGR_EXT(r2, 0x4018620d, &(0x7f00000000c0)={0x73622a85, 0x1000, 0x800000000002}) r3 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000200)='./binderfs/binder0\x00', 0x0, 0x0) ioctl$BINDER_WRITE_READ(r3, 0xc0306201, &(0x7f0000000080)={0x8, 0x0, &(0x7f0000000400)=[@increfs], 0x0, 0x0, 0x0}) r4 = openat$binderfs(0xffffffffffffff9c, &(0x7f0000000000)='./binderfs/binder0\x00', 0x802, 0x0) mmap$binder(&(0x7f0000ffd000/0x3000)=nil, 0x3000, 0x1, 0x11, r4, 0x0) ioctl$BINDER_SET_CONTEXT_MGR_EXT(r4, 0x4018620d, &(0x7f0000000040)={0x73622a85, 0x10a, 0x80000}) ioctl$BINDER_WRITE_READ(0xffffffffffffffff, 0xc0306201, &(0x7f00000003c0)={0x8, 0x0, &(0x7f0000000340)=[@acquire], 0x0, 0x0, 0x0}) pselect6(0x40, &(0x7f00000001c0)={0x0, 0x0, 0x3, 0xfffffffffffffffd, 0xfffffffffffffffc, 0x4}, 0x0, &(0x7f00000002c0)={0x3ff, 0x0, 0x3, 0x9, 0x0, 0x0, 0x7fffffff}, 0x0, 0x0) ioctl$BINDER_WRITE_READ(r2, 0xc0306201, &(0x7f0000000180)={0x4c, 0x0, &(0x7f0000000100)=[@transaction_sg={0x40486311, {0x1, 0x0, 0x0, 0x0, 0x30, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x2ff8}], 0x0, 0x0, 0x0}) 3m7.335098103s ago: executing program 0 (id=1107): socket$nl_netfilter(0x10, 0x3, 0xc) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f0000000840)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sched_setattr(0x0, &(0x7f0000000100)={0x38, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffe, 0x80000}, 0x0) syz_genetlink_get_family_id$l2tp(0x0, 0xffffffffffffffff) sendmsg$L2TP_CMD_SESSION_GET(0xffffffffffffffff, 0x0, 0x10) r2 = socket(0x2, 0x80805, 0x0) getsockopt$bt_hci(r2, 0x84, 0x6d, 0x0, &(0x7f0000001040)) getrusage(0xffffffffffffffff, &(0x7f0000000680)) r3 = openat$sequencer(0xffffffffffffff9c, &(0x7f0000000000), 0x1, 0x0) ioctl$SNDCTL_SEQ_TESTMIDI(r3, 0x40045108, 0x0) socket$can_raw(0x1d, 0x3, 0x1) r4 = openat$sequencer2(0xffffffffffffff9c, &(0x7f0000000980), 0x0, 0x0) ioctl$SNDCTL_SEQ_RESET(r4, 0x5100) ioctl$SNDCTL_SEQ_RESET(r4, 0x5100) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xa, &(0x7f00000001c0)={0x0, 0x0}) r5 = openat$iommufd(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) getsockopt$inet_sctp6_SCTP_GET_ASSOC_NUMBER(r2, 0x84, 0x1c, &(0x7f0000001080), &(0x7f00000010c0)=0x4) ioctl$IOMMU_IOAS_ALLOC(r5, 0x3b81, &(0x7f0000000400)={0xc, 0x0, 0x0}) ioctl$IOMMU_IOAS_MAP$PAGES(r5, 0x3b85, &(0x7f0000000140)={0x28, 0x2, r6, 0x0, &(0x7f0000ffc000/0x4000)=nil, 0x4000, 0x800}) ioctl$IOMMU_IOAS_MAP$PAGES(r5, 0x3b85, &(0x7f0000000000)={0x28, 0x4, r6, 0x0, &(0x7f00004f9000/0x3000)=nil, 0x3000}) ioctl$IOMMU_IOAS_COPY(r5, 0x3b83, &(0x7f0000000040)={0x28, 0x5, r6, r6, 0x3, 0xfffffffffffffffa, 0x3fff}) bpf$PROG_LOAD(0x5, 0x0, 0x0) add_key$user(&(0x7f00000003c0), &(0x7f0000000440), &(0x7f00000000c0), 0xc9, 0xfffffffffffffffd) bpf$BPF_PROG_TEST_RUN(0xa, 0x0, 0x0) syz_usb_connect(0x2, 0x4a, &(0x7f00000015c0)=ANY=[@ANYBLOB="12010000958c834099043f4d2ad201020301090238000100fd20000904270001ff40d300052402000105240009000d240f01030000000d0010006306241a7d000209050b02"], 0x0) 3m4.120521013s ago: executing program 0 (id=1127): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) getsockopt$inet_sctp6_SCTP_STATUS(0xffffffffffffffff, 0x84, 0xe, &(0x7f0000000000)={0x0, 0xcd74, 0x8, 0x200, 0xa, 0x4, 0x1000, 0x7fffffff, {0x0, @in6={{0xa, 0x4e22, 0x7, @empty, 0x6}}, 0x10001, 0x8, 0x3, 0x88, 0x1}}, &(0x7f00000000c0)=0xb0) setsockopt$inet_sctp6_SCTP_MAX_BURST(r0, 0x84, 0x14, &(0x7f0000000100)=@assoc_value={r1, 0x80}, 0x8) ioctl$FIONCLEX(r0, 0x5450) ioctl$sock_ipv6_tunnel_SIOCGET6RD(0xffffffffffffffff, 0x89f8, &(0x7f0000000200)={'sit0\x00', &(0x7f0000000180)={'ip_vti0\x00', 0x0, 0x10, 0x10, 0x6, 0x4, {{0x18, 0x4, 0x1, 0x7, 0x60, 0x67, 0x0, 0xfa, 0x4, 0x0, @empty, @broadcast, {[@noop, @rr={0x7, 0x13, 0xa8, [@multicast2, @multicast1, @remote, @local]}, @timestamp_addr={0x44, 0xc, 0x9, 0x1, 0x7, [{@loopback, 0x2}]}, @rr={0x7, 0x23, 0x4c, [@multicast1, @broadcast, @broadcast, @empty, @rand_addr=0x64010100, @empty, @rand_addr=0x64010101, @dev={0xac, 0x14, 0x14, 0x1c}]}, @rr={0x7, 0x7, 0x6e, [@rand_addr=0x64010101]}, @generic={0x89, 0x2}]}}}}}) sendmsg$nl_route(0xffffffffffffffff, &(0x7f00000002c0)={&(0x7f0000000140)={0x10, 0x0, 0x0, 0x80000}, 0xc, &(0x7f0000000280)={&(0x7f0000000240)=@ipv4_delroute={0x24, 0x19, 0x4, 0x70bd25, 0x25dfdbff, {0x2, 0x14, 0x50db97a9ae531162, 0x6, 0x1, 0x1, 0x67, 0x0, 0x2600}, [@RTA_IIF={0x8, 0x3, r3}]}, 0x24}, 0x1, 0x0, 0x0, 0x20000840}, 0x5c0c27499f9e19fe) r4 = socket$nl_sock_diag(0x10, 0x3, 0x4) setsockopt$netlink_NETLINK_TX_RING(r4, 0x10e, 0x7, &(0x7f0000000300)={0x2, 0x4, 0x81, 0x9}, 0x10) ioctl$sock_ipv6_tunnel_SIOCGETTUNNEL(0xffffffffffffffff, 0x89f0, &(0x7f0000000400)={'ip6_vti0\x00', &(0x7f0000000380)={'ip6gre0\x00', r3, 0x4, 0x20, 0x8, 0x2a, 0x13, @ipv4={'\x00', '\xff\xff', @remote}, @rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02', 0x1, 0x8020, 0xc6, 0x5}}) sendmsg$TCPDIAG_GETSOCK(r4, &(0x7f0000000500)={&(0x7f0000000340)={0x10, 0x0, 0x0, 0x10000}, 0xc, &(0x7f00000004c0)={&(0x7f0000000440)={0x80, 0x12, 0x100, 0x70bd2c, 0x25dfdbff, {0x15, 0xb, 0x9, 0x9, {0x4e21, 0x4e22, [0xb, 0x59711e06, 0x3, 0x3], [0x5, 0x193a, 0x2, 0x4], r5, [0xc, 0x100]}, 0x9, 0x55f}, [@INET_DIAG_REQ_BYTECODE={0x33, 0x1, "78cbecd6f41c58ef6f474cbd3ac44444173d748616186cf0eeaaf38ccbc161f8da93cb003ddcb26f11bfa5a7df18b0"}]}, 0x80}, 0x1, 0x0, 0x0, 0x24008000}, 0x844) r6 = socket$inet_sctp(0x2, 0x5, 0x84) sendmmsg$inet_sctp(r6, &(0x7f0000001ac0)=[{&(0x7f0000000540)=@in={0x2, 0x4e23, @empty}, 0x10, &(0x7f0000000600)=[{&(0x7f0000000580)="3ca6cdbaed3bd5020b3d08547f29a7d3f9290ed26cb7fa3df41b52ef0af373d506b7ea71baef4f549dac292f90f45510bf65ca1644956770fbff1f19eab38ff8cbdf27bd08a904ed7e49906b4deaced407aef88340", 0x55}], 0x1, &(0x7f0000000640)=[@dstaddrv6={0x20, 0x84, 0x8, @mcast2}, @init={0x18, 0x84, 0x0, {0x3ff, 0x1, 0x77, 0x2}}, @prinfo={0x18, 0x84, 0x5, {0x0, 0x9}}, @sndinfo={0x20, 0x84, 0x2, {0x3ff, 0x20e, 0xf9db, 0x2, r1}}, @init={0x18, 0x84, 0x0, {0xc541, 0x8, 0x6, 0x5}}, @dstaddrv4={0x18, 0x84, 0x7, @loopback}, @dstaddrv4={0x18, 0x84, 0x7, @rand_addr=0x64010102}, @sndrcv={0x30, 0x84, 0x1, {0x2, 0x2, 0x8, 0x78, 0x9, 0xff, 0x10001, 0xff, r1}}, @init={0x18, 0x84, 0x0, {0x1ff, 0xfff9, 0xbe20, 0x5}}], 0x100, 0x4000000}, {&(0x7f0000000740)=@in6={0xa, 0x4e20, 0x800, @mcast1, 0xcb}, 0x1c, &(0x7f0000000a00)=[{&(0x7f0000000780)="34e20be949ebf4263a7244ea00e3b92e0023ebdf73de6f20ea04d27763b83f5c6a5f83faeadc374481cc8f2a1c31298e057b645604d17b37906eaf9570c88dd4bd1e3543dcd0105bf08c97f9c8193d69c46acbd1b0f753912e8fd3202cf704811931179c2f667ce30dcbcabd067d472faf2356396206797c72640720df01fe565d0d7e4a22d61af7afd443374965b2b4f811b17d4722ac7e13585aaa2fdc72c9b18a2b9232d316dbf4945213918069b1fe5411798c6662be1e48e689a9bf49218bf7643642c169f051beee3251c2734c977ced", 0xd3}, {&(0x7f0000000880)="1331f61cf7c3bdb5f8894dae8005cf7222ba96712875b97cf1ab28940b6f330c15ee8f51a140a9670da1d24480a87da444c726762f6b9f27b61fb889d139666304e1e82a9dccca6b9228dd61acc6586cb5693af2f5ae9a16c41d9bbf9b2ac7a4c9731983d7cd3271b05335d9758d65d73e3232ce62cbe760d381489324ec2e4e8bffaa45294323f7a931bed429309cc73ce9f89f8ad34045e2b81012fcf7c3ec6e25e8fb49144d71ca32fd842b0531e6471207ee641f9f19cf27b05434e42edfc8c25a1e6d463e5a5bd24fa3342eaba58a58c7569866a433600f1684f5708786088d1ae2ec97c3412bf9c8d2d5b175a8d27698d176d5604ac7258ab7", 0xfc}, {&(0x7f0000000980)="c4ba9d58e823984dcc1503029eb01bf4ffbf7c360a855484fa7dd8175a8134a1357c4f3fdd29effb8357303fb2658db03be52c4c32deb3145f29dad0d423028a3e7d36c983d2d485fc4feac0cbee09085342e36426d03a5963ca96b456655c861a2893c6af6f96eed52e998362148f8fd78306097dead11c7bb1", 0x7a}], 0x3, &(0x7f0000000a40)=[@dstaddrv4={0x18, 0x84, 0x7, @multicast1}, @sndinfo={0x20, 0x84, 0x2, {0x9, 0x8203, 0x4e, 0x7, r2}}, @authinfo={0x18, 0x84, 0x6, {0xfff}}, @dstaddrv4={0x18, 0x84, 0x7, @loopback}, @sndinfo={0x20, 0x84, 0x2, {0x0, 0x208, 0x101, 0xe, r1}}, @authinfo={0x18, 0x84, 0x6, {0x2}}, @sndinfo={0x20, 0x84, 0x2, {0x7f, 0x6, 0x200, 0x2, r1}}], 0xc0, 0x200080c0}, {&(0x7f0000000b00)=@in6={0xa, 0x4e21, 0x8001, @loopback, 0x1}, 0x1c, &(0x7f0000000f80)=[{&(0x7f0000000b40)="800d14b31bf83da07dd2d490b5b531f7c32f6342edb407b71171e391f0bb6f64345585502cf2f413fa047433bc88725e81b5d2340a66c3f32fcff4b7b52496f948e767ad9c8e051c8439ff5ce98eef52ed1844355b35cfa8d5bf05ef252813df81562d8ed1489ba4c51358aabd94382a1d83b399fe488765d7c2bba6c5905238a1eb90358de4d1dc035ef00fbbfa95b905020c01700b09c4752219e37ab104509d3d0cb3bed48b9c6f4a74c94559d7f6ca35a823ef400715df4fa6e2826a35bbae36216bd2c55f403ee5ff77353b2c09ad82f3654b11ad61e82f59726fb70a4162c58d3d25e51145295212a3f9ed64df3d6f5f48243d1eff012d3340bf916f", 0xff}, {&(0x7f0000000c40)="7967ee30d191571688dfe25dc859d1cfb149e2c79dc8f845296df75ae89207d9b458b3743a10452c53d029b4fd9b5efd285a02a19bc68992d5eb091cd33a830b6ca127842a7e9088b7185002f0acfc4b85", 0x51}, {&(0x7f0000000cc0)="8ec499ba4385b06e886c2b0573c56afd6a4bf8149c2fde20ac6b10c009931c828481d01246375dd2f46205ed58d79b8887059ca0468e7b4b8ca22361b77f3e963714c06884c149155e604fb959725ef62632583bd28879688732e9209f21424dab0fa378c85e9b61d58964e48b74071150a35b57a9960d04ec69c312899edaaae7d506b0d32fa15c1752b3022ba7035a", 0x90}, {&(0x7f0000000d80)="d5fa7060fa37ac8e795a9924f8e042351aca38093e6463afebd13a78fcea3bd782e4b615a8be5d34cd371078a36f0c4ba507a01442d98c780eea272f07c6d481e0e0a03256039d0d4807d57c8a77a5269e11f2c33ebf6f767b1c3492bb91c10c6433c640e07a745fb6156e93f019e6e80225d6854e0271ba11fea11006300b976e4bf83ae2664c", 0x87}, {&(0x7f0000000e40)="607972b47cbcdba68deb4e84e1c19510358610957e85454602bfd0307517d722623d5f7cb7d49057fbb31244d5898a0f530e43b3bb4dc0c46e4f38684c7894efb5a72d9ffbf25e", 0x47}, {&(0x7f0000000ec0)="8d47088917af7169def27122fb2286f2d38cf20d187d8abc8e76276617fe6e27603d8d5553471783ac87eb33f7bf8f2a37161d55bf049bb30d1f92b6a0b97521654ad5e99b2d186eaf954f8ca9e40f91e0342f99580ec17a8011ca8b7d6467214b646c93563809d5d8e4adf14a1d3cdb414b870e6c743538dc69ae04db534f573d9865639a862cba8ecfa0f738410be0271dfcded6c44172b0bb92ee3fa5f358af8700c5d81e039f658170fc70e108344d", 0xb1}], 0x6, &(0x7f0000001000)=[@init={0x18, 0x84, 0x0, {0xfffa, 0x91, 0x4, 0x2}}, @prinfo={0x18, 0x84, 0x5, {0x0, 0x85f2}}], 0x30, 0x4040840}, {&(0x7f0000001040)=@in6={0xa, 0x4e20, 0x4, @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}, 0x6}, 0x1c, &(0x7f00000014c0)=[{&(0x7f0000001080)="eb5959b2117898108e8e09175df858c892abcbf4ee60c28468328058e63691e065ef1913449312c8aca679bab40260ee0cd385adbac04753b8b808a4889766d6ae326292d93f77ce892933dda99734f589", 0x51}, {&(0x7f0000001100)="19be38c855087f716669991424cc15d2cb236d223414726c0db4277f1df412b3bcadeb5dc57abf98f393ff8a3a14778f5671f084ff4bb34a8fe926dfbd34ab259bd005bbc1714a49458bcde7af103d3d5dec9214d3f6ba9b160dbccefde997a60f71cd1604", 0x65}, {&(0x7f0000001180)="0eda20e22b938ae82f82500a31610e9956c082b72d2564854c5aa897b9036f0e0058605ffb1d81ce68e3e3844421712f99076a6b96f20d3a004fc50f64622ef6011579531fb0b2df15a7", 0x4a}, {&(0x7f0000001200)="8a7f5844244123984bd3cb668d3573b71c79589c3ebaedd9c831dc896ce608ca6bf251895b4d6803c82d788ffb67a320a8598cfe8a8beafe60e1c960760e08182707410cd40ffac663d98f32d431d6f980dac025b1214ca5fb264e578be134eadbfa53fd5977b291ae89a449f28a8420a33bd2a99b0a7bc63577be3aa7e1e21c54a4f6ae10e9bf8fd5c784aee828913d746d189564d3c10cd6a25abaeb5cafa0d1032b7e752425f6708bbd4f277810793a1805ff83a0120606be6f8bbc63183341", 0xc1}, {&(0x7f0000001300)="95e88d5661cb6651de862b5d81b84c31bc241c3e5ae0f255ed51e1d9c4e3962cfd3737243c903289fbd12329377a21b79acd4389999272bc714c36f16c967c9ed456e5ae001960ae3ff8619704dda2cdb24a910b941f884d60354620875e63427f1da3dceca053b3a97d41391989855c3ddcd1e24db096569c3bf34cc8a7fd4b40aa9b8cd6457ed2adec9f4d8e04e0e6a125fa531f16", 0x96}, {&(0x7f00000013c0)="e5c064039737b97d7ab4f771ef14af1a0f4a666b34e18a8e3adca2aac2cd375bbb362a9a5df0d5098a164e4ce2327f82fb999a25f92c8d15e798f1f168a1c426b7b1bb715116b0ca595d7d7c3cbc19f3b3b1b720426a95188948f20c4356e1bc4aad24eca726ba2702be0719b97b1d761a2892f2d9dfcb962022a1cef022d74263857711cb4735589be251e9807cc35aa91352240e2821f9e4e748617aed1f1b10a419e4d3902e7368ca2c2040a1e389875047e8b7a456bfb6827938e848e2ff4a29c2a69e33624f6a77", 0xca}], 0x6, &(0x7f0000001540)=[@prinfo={0x18, 0x84, 0x5, {0x30, 0x7}}, @sndinfo={0x20, 0x84, 0x2, {0x4, 0x4, 0x8, 0x1, r1}}, @prinfo={0x18, 0x84, 0x5, {0x0, 0x3}}], 0x50, 0x80}, {&(0x7f00000015c0)=@in6={0xa, 0x4e24, 0x4, @loopback, 0x80}, 0x1c, &(0x7f0000001880)=[{&(0x7f0000001600)="d9b559bdbd3cd7f73da5cf2351c99fffdbdf83265c7a61f48877301643a88d8a14c0a2", 0x23}, {&(0x7f0000001640)="9c", 0x1}, {&(0x7f0000001680)="ca819a76f6fcb131953176c8d216ff58a4cb9447fb279e8db27440c30cca1af77bb08c496b406a5060bf50c1c4a2c9f37fd7f423fe59377d36e988f0b455aff869529f0bffd3a1fae42a61ab0919a8b8f4443a671f0a49e5554f8d9d461fdb58d31fc915972b8adf32e9d314cf866ed0eb90cc5d46a1bb91341f4e3a3e4d0de3449f3927692ba8aa7bf2cfef876ca8d298636e5933d8d1b42c25c15cf3da03555191430408ba57faddcc00bc5a0a320c5562442233529e0decf75e7d69aa41ca659f639a1ed401b3066fb3fb4eb9d05265af38dcae845e233b419eb49317473f1d7c0122ffd75cf33edf19fa19a8da8a556679ee04934ba4868171", 0xfb}, {&(0x7f0000001780)="815fbdaee8f1952dd8a2c5824ca7279763cd12b589655bb661b4c9cdebf442860d7047b87aaf57458e09c193fecffde96cc5b949e8e805a26a04ae51945a4bdbf115d6b157761f98f35c7663769dd74d47a1600a17c6c2b08e124bfbdb2b05669724f5b05d2e1ad1c26a28c0e4a6268f11e79b2a01855f4450768658a4fa178d8d878a67ae43786f34ae6b14ebe45b61efdbd467767c8aefa2b976c328278b69bd91521426c902472bf5c35447bb40da2264cf3eb05f15acd43bcd6efa73252536534df645cda9849a86c4914d1d34ec247ab3ae8262e44796a7513ad20365c670406cd1912fd49ecdedb99afd4193acd9a6f925b2984fc13b073c61", 0xfc}], 0x4, 0x0, 0x0, 0x80}, {&(0x7f00000018c0)=@in6={0xa, 0x4e23, 0x4, @rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02', 0xddd}, 0x1c, &(0x7f00000019c0)=[{&(0x7f0000001900)="746ce6dd8ab88e2ec8a3f7943f10fd445f5e950336bdc03910d230fae7c77ed0d6c63b8f3ce90b1288e7e081ee2b0acbf54ed353222b195ae401335896c37d6513ad85491222fb800dc374e22443c2c3ad4105bf3bf089f85955b85f74de6884f17141868c9827746dc5c995b135d719689de0810c5f7f8bac9cb0ed6a97f404a03a0b59582e73", 0x87}], 0x1, &(0x7f0000001a00)=[@dstaddrv6={0x20, 0x84, 0x8, @empty}, @init={0x18, 0x84, 0x0, {0x7, 0x6, 0x0, 0x8}}, @dstaddrv6={0x20, 0x84, 0x8, @empty}, @sndrcv={0x30, 0x84, 0x1, {0x8, 0x7, 0x8008, 0x5, 0x5, 0x5, 0x7, 0x7ff, r1}}], 0x88, 0x1}], 0x6, 0x40000) r7 = socket$nl_sock_diag(0x10, 0x3, 0x4) ioctl$ifreq_SIOCGIFINDEX_batadv_mesh(r4, 0x8933, &(0x7f0000001c80)={'batadv0\x00', 0x0}) sendmsg$DCCPDIAG_GETSOCK(r7, &(0x7f00000020c0)={&(0x7f0000001c40)={0x10, 0x0, 0x0, 0x100000}, 0xc, &(0x7f0000002080)={&(0x7f0000001cc0)={0x3a0, 0x13, 0x100, 0x70bd29, 0x25dfdbfe, {0x8, 0x28, 0x2, 0x94, {0x4e24, 0x4e23, [0x401, 0x1ff, 0x620e07c6, 0x3a4f], [0x2, 0x80, 0x3, 0x1], r8, [0xb, 0x9]}, 0x9, 0x9}, [@INET_DIAG_REQ_BYTECODE={0xfa, 0x1, "aa44900d64ce0d92dced81acba63453a3427de3d3582bf037598d858166333bb951896b655412af6191ceb03ce21851eb38cdb15125fc99a9a57871b8089925ccdfca31281e291f627ed5a1ca4cf906960dc304669d5c348b5c22d9feb1ccaa32c0d339c154e5b3637cb3efbd069e89c3f6728e28987ceb043ec2129e6b97224d30483bf76660cdfe0ea06eb6e5de2db963ac5034898e7406f9c9e7ca413cb20407c19efd46a7ff04484504ccf46655833fa2337609b33c11d77ea6ad8ebf0f993bc04fae83703d4d6e03b904728a66f6535697f5f2ba0849072879a0ae9f77404d3586439a8368e159b388633c72e7b0b8099cb899f"}, @INET_DIAG_REQ_BYTECODE={0x1e, 0x1, "f04be808f75a911ef94ecdbf803997b12170189bf7de9d27d0e1"}, @INET_DIAG_REQ_BYTECODE={0x98, 0x1, "cfb5e452fda8090381f8456c457a581448a05c8c104e770b95bdc51b675aa3789bf596f3e47c218d4be97932387ad8937b00143ef97dea0eaa76e731313247b34a184207b98bc6b72a4144f58ae9e4e07479981077783ab4e16640e81053fe347f69be3027def32f072a0a98a9d7e2430d000eff94371a52658932984a21ba6f045b33ce69232dd79e69c240b07d35a7207f3e91"}, @INET_DIAG_REQ_BYTECODE={0x53, 0x1, "60700bda857b830c7120abdab63c0c9dbafaabf211ad972f1571e2cc6ed9b9a9e301b6479be9f0c0db999ec02cc7939d3576b2cdabcad4fb54d5c006ee28e5e8590d04bc715938f2ab67643ba5d292"}, @INET_DIAG_REQ_BYTECODE={0x87, 0x1, "4ebe534500242bdf998e96f6beb2506ca783357b09aed1b4ba40e006c0cb4fb3915c7b16c01621d1b4f5b0af4ba194ef5f09b3d9ab2bf410981472f547f64561e44e1c050f02144b658f151bde76c7702f5132f6be83898b4eddb708c31eb3df01179052762e98c9fb39e944b98e6241fb43a7342d280e2f8ff50b5d5905fb56cc5605"}, @INET_DIAG_REQ_BYTECODE={0x9, 0x1, "8ed0c5a5ef"}, @INET_DIAG_REQ_BYTECODE={0x60, 0x1, "dbfb384a9c35f7805986a43e5e3f94c594aa9a6996ac61b27703dd1c21c4ea236b9f5b82e4625e86983c4ad556e56ca9b088d4bc40c4da4dfee7cc1bf7660953e875668ce53fc588c3ebbc330947d29c72d464c4755f7bdda4135149"}, @INET_DIAG_REQ_BYTECODE={0x55, 0x1, "daf6c39265d89d92540840a09e4bde628873056ec52b363b1d0a5b3aaf4cd9bd2826c7d0916acc9fede0b3d029a4e03e175014e6e064973353eabe7a54f01b946f860b5c2b3ec5e7d91a2227382fe42cc4"}]}, 0x3a0}, 0x1, 0x0, 0x0, 0x840}, 0x1) sendmsg$nl_route_sched(r6, &(0x7f0000002200)={&(0x7f0000002100)={0x10, 0x0, 0x0, 0x10000000}, 0xc, &(0x7f00000021c0)={&(0x7f0000002140)=@deltclass={0x60, 0x29, 0x100, 0x70bd28, 0x25dfdbfe, {0x0, 0x0, 0x0, r8, {0xe}, {0x8, 0x8008}, {0xe, 0xf}}, [@TCA_RATE={0x6, 0x5, {0x0, 0x81}}, @tclass_kind_options=@c_taprio={0xb}, @tclass_kind_options=@c_red={0x8}, @TCA_RATE={0x6, 0x5, {0x3, 0x1}}, @TCA_RATE={0x6, 0x5, {0x93, 0x25}}, @TCA_RATE={0x6, 0x5, {0x5, 0x5}}, @TCA_RATE={0x6, 0x5, {0x1, 0x1}}]}, 0x60}, 0x1, 0x0, 0x0, 0x40081}, 0x95075a18f8cc5f88) r9 = dup2(r7, 0xffffffffffffffff) r10 = openat$zero(0xffffffffffffff9c, &(0x7f0000002240), 0x40, 0x0) bpf$BPF_PROG_QUERY(0x10, &(0x7f0000002380)={@map=0x1, 0xa, 0x0, 0x77, &(0x7f0000002280)=[0x0], 0x1, 0x0, &(0x7f00000022c0)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0], &(0x7f0000002300)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0], &(0x7f0000002340)=[0x0, 0x0, 0x0, 0x0], 0x0}, 0x40) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000002480)={{0xffffffffffffffff, 0xffffffffffffffff}, &(0x7f0000002400), &(0x7f0000002440)}, 0x20) bpf$BPF_PROG_ATTACH(0x8, &(0x7f00000023c0)={@map=r12, r9, 0x14, 0x2001, r10, @value, @void, @void, @void, r11}, 0x20) connect$pppl2tp(r9, &(0x7f00000024c0)=@pppol2tpv3={0x18, 0x1, {0x0, r0, {0x2, 0x4e21, @remote}, 0x4, 0x1, 0x4}}, 0x2e) connect$inet6(r0, &(0x7f0000002500)={0xa, 0x4e23, 0x1, @mcast1, 0xc}, 0x1c) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r4, 0x8933, &(0x7f0000002540)={'batadv_slave_1\x00', 0x0}) bind$packet(r9, &(0x7f0000002580)={0x11, 0x8, r13, 0x1, 0x1, 0x6, @random="4430aade3895"}, 0x14) close(0xffffffffffffffff) socket$inet6_sctp(0xa, 0x1, 0x84) openat$sysctl(0xffffffffffffff9c, &(0x7f00000025c0)='/proc/sys/vm/compact_memory\x00', 0x1, 0x0) getsockopt$TIPC_DEST_DROPPABLE(r10, 0x10f, 0x81, &(0x7f0000002600), &(0x7f0000002640)=0x4) mount$fuse(0x0, &(0x7f0000002680)='./file0\x00', &(0x7f00000026c0), 0x1000, &(0x7f00000048c0)={{'fd', 0x3d, r9}, 0x2c, {'rootmode', 0x3d, 0x4000}, 0x2c, {}, 0x2c, {}, 0x2c, {[{@default_permissions}, {}, {@blksize={'blksize', 0x3d, 0x1200}}, {@blksize={'blksize', 0x3d, 0x1000}}, {@max_read={'max_read', 0x3d, 0x3}}, {@blksize}, {@blksize={'blksize', 0x3d, 0x1400}}], [{@smackfstransmute={'smackfstransmute', 0x3d, '##],'}}, {@euid_gt}, {@uid_eq={'uid', 0x3d, 0xee01}}, {@uid_gt}, {@rootcontext={'rootcontext', 0x3d, 'unconfined_u'}}, {@smackfsfloor={'smackfsfloor', 0x3d, 'ip6_vti0\x00'}}, {@subj_type={'subj_type', 0x3d, '{:\\[,%!!{'}}, {@dont_hash}]}}) 3m3.995723233s ago: executing program 0 (id=1128): bpf$MAP_CREATE(0x2000000000000020, &(0x7f0000000140)=@base={0x0, 0x4, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r0 = openat$pfkey(0xffffffffffffff9c, &(0x7f0000001580), 0x0, 0x0) pread64(r0, &(0x7f0000000100)=""/29, 0x1d, 0x2b) socket(0x10, 0x3, 0x0) r1 = openat$ppp(0xffffffffffffff9c, &(0x7f0000000040), 0x161042, 0x0) ioctl$PPPIOCNEWUNIT(r1, 0xc004743e, &(0x7f0000000000)=0x3) r2 = syz_io_uring_setup(0x25e3, &(0x7f0000000480)={0x0, 0xdff9, 0x800, 0x200003, 0x136}, &(0x7f0000000000)=0x0, &(0x7f0000000080)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r3, 0x4, &(0x7f0000000180)=0xfffffffc, 0x0, 0x4) r5 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$TIOCGSOFTCAR(r5, 0x5414, &(0x7f0000000000)) r6 = syz_open_dev$audion(&(0x7f0000000140), 0x100, 0x2400) ioctl$AUTOFS_IOC_EXPIRE(r6, 0x810c9365, &(0x7f0000000240)={{0xffffffff, 0x7ff}, 0x100, './file0\x00'}) unshare(0x4040600) pipe(&(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) getpeername$packet(r7, 0x0, 0x0) syz_io_uring_submit(r3, r4, &(0x7f0000000200)=@IORING_OP_WRITEV={0x2, 0x0, 0x0, @fd_index=0x4, 0x0, 0x0}) io_uring_enter(r2, 0x47ba, 0x0, 0x0, 0x0, 0x0) 3m2.572243108s ago: executing program 0 (id=1134): syz_usb_connect$cdc_ncm(0x0, 0x72, &(0x7f0000000080)=ANY=[@ANYBLOB="1201000002000040257d15a4400001040001090260004201000000090400000102090000052406000105240000000d240f01000004eaffffff1e0006031a00000804800200090581", @ANYBLOB="f7", @ANYRESOCT], 0x0) r0 = io_uring_setup(0x194e, &(0x7f0000000a80)={0x0, 0xd3d5, 0x40, 0x2, 0x2b1}) close_range(r0, 0xffffffffffffffff, 0x0) r1 = syz_open_dev$char_usb(0xc, 0xb4, 0x0) write$char_usb(r1, 0x0, 0x0) r2 = syz_open_dev$char_usb(0xc, 0xb4, 0x0) dup3(r1, r2, 0x80000) r3 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r3, &(0x7f00005f5000)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000600)=ANY=[@ANYBLOB="02030000140000000000000000000000040003000000000000001000000000000000000000000000000000000000000003000600ff00000002004e20ac1e0001000000000000000004000400000000000000000000000000ffffffffffffffff00000000000000000200010000000000000108fd010000c0030005000000000002004e22e00000020000000000000000020013"], 0xa0}}, 0x0) r4 = syz_open_dev$radio(&(0x7f00000000c0), 0x2, 0x2) ioctl$VIDIOC_S_TUNER(r4, 0x4054561e, &(0x7f0000000100)={0x2, "02c0cf0c629c527e5162bf1cab3223b02749791e5c7465e0caa7b1214ac1efe3", 0x5, 0x100, 0x1aa35bb2, 0x4b70, 0x4, 0x2, 0x80000001, 0x401}) socketpair(0x1d, 0x2, 0x5, &(0x7f0000000300)) 2m47.470637952s ago: executing program 33 (id=1134): syz_usb_connect$cdc_ncm(0x0, 0x72, &(0x7f0000000080)=ANY=[@ANYBLOB="1201000002000040257d15a4400001040001090260004201000000090400000102090000052406000105240000000d240f01000004eaffffff1e0006031a00000804800200090581", @ANYBLOB="f7", @ANYRESOCT], 0x0) r0 = io_uring_setup(0x194e, &(0x7f0000000a80)={0x0, 0xd3d5, 0x40, 0x2, 0x2b1}) close_range(r0, 0xffffffffffffffff, 0x0) r1 = syz_open_dev$char_usb(0xc, 0xb4, 0x0) write$char_usb(r1, 0x0, 0x0) r2 = syz_open_dev$char_usb(0xc, 0xb4, 0x0) dup3(r1, r2, 0x80000) r3 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r3, &(0x7f00005f5000)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000600)=ANY=[@ANYBLOB="02030000140000000000000000000000040003000000000000001000000000000000000000000000000000000000000003000600ff00000002004e20ac1e0001000000000000000004000400000000000000000000000000ffffffffffffffff00000000000000000200010000000000000108fd010000c0030005000000000002004e22e00000020000000000000000020013"], 0xa0}}, 0x0) r4 = syz_open_dev$radio(&(0x7f00000000c0), 0x2, 0x2) ioctl$VIDIOC_S_TUNER(r4, 0x4054561e, &(0x7f0000000100)={0x2, "02c0cf0c629c527e5162bf1cab3223b02749791e5c7465e0caa7b1214ac1efe3", 0x5, 0x100, 0x1aa35bb2, 0x4b70, 0x4, 0x2, 0x80000001, 0x401}) socketpair(0x1d, 0x2, 0x5, &(0x7f0000000300)) 2.904284874s ago: executing program 5 (id=1773): r0 = socket$inet_mptcp(0x2, 0x1, 0x106) connect$inet(r0, &(0x7f0000000000)={0x2, 0x4e22, @empty}, 0x10) recvfrom(r0, &(0x7f0000000180)=""/60, 0xfffffffffffffecb, 0x4100, 0x0, 0x0) 2.040420629s ago: executing program 6 (id=1785): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="04000000040000000400000005"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x1b, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b70800000000e7057b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000001600000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x9, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xe8c, @void, @value}, 0x94) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000023c0)={0x0, 0x4, &(0x7f0000000480)=ANY=[@ANYBLOB="18020000000000000000"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x3, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r1}, 0x10) r2 = io_uring_setup(0x5f41, &(0x7f00000001c0)={0x0, 0x0, 0x800}) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) close(r3) r4 = socket$inet6_mptcp(0xa, 0x1, 0x106) bind$inet6(r3, &(0x7f0000000040)={0xa, 0x4e22, 0x0, @ipv4={'\x00', '\xff\xff', @empty}, 0xf}, 0x1c) listen(r4, 0x0) r5 = socket$inet_mptcp(0x2, 0x1, 0x106) connect$inet(r5, &(0x7f0000000140)={0x2, 0x4e22, @local}, 0x10) close_range(r2, 0xffffffffffffffff, 0x0) 1.91031578s ago: executing program 5 (id=1788): process_madvise(0xffffffffffffffff, 0x0, 0x0, 0x11, 0x0) 1.865467584s ago: executing program 6 (id=1789): r0 = syz_open_procfs(0x0, &(0x7f0000000180)='net/kcm\x00') faccessat2(r0, &(0x7f0000000040)='\x00', 0x1, 0x1300) 1.767204595s ago: executing program 1 (id=1791): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000004c0)={0x18, 0x5, &(0x7f0000000280)=ANY=[@ANYBLOB="1801000000dd0000000000003b810000850000006d000000a50000005000000095"], &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0xa, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x5, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000340)='kfree\x00', r0, 0x0, 0x3e}, 0x18) r1 = openat(0xffffffffffffff9c, &(0x7f0000000100)='./file1\x00', 0x42, 0x1ff) write$binfmt_elf64(r1, &(0x7f0000000980)=ANY=[@ANYBLOB="7f454c4600000006010000000000000003003e000000000003000000000000004000000000000000980100000000000002000000000038000200000002000000000000600300000008000000000000000d00000000000000ed08000000000000f0ffffffffffffff0000000000000000080000000000000003"], 0x5b0) close(r1) execveat(0xffffffffffffff9c, &(0x7f0000000140)='./file1\x00', 0x0, 0x0, 0x0) 1.766884915s ago: executing program 5 (id=1792): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000000c0)=@base={0x1b, 0x0, 0x0, 0x8000, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000640)={0x11, 0x7, &(0x7f0000000400)=ANY=[@ANYBLOB="18000000f7ffffff000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b702000000000000850000008600000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x41000, 0x8, '\x00', 0x0, @fallback=0x2b, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000600)={&(0x7f00000005c0)='sys_enter\x00', r1}, 0x10) lsm_get_self_attr(0x69, &(0x7f0000000740)={0x0, 0x0, 0xad, 0x8d, ""/148}, &(0x7f00000002c0)=0xffffffffffffffe7, 0x0) 1.753040042s ago: executing program 4 (id=1793): r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f00000004c0)=ANY=[@ANYBLOB], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000180)='kfree\x00', r0}, 0x10) socket$nl_netfilter(0x10, 0x3, 0xc) r1 = syz_open_procfs(0x0, &(0x7f0000000000)='ns\x00') renameat(r1, &(0x7f0000000080)='./mnt\x00', r1, &(0x7f0000000100)='./mnt\x00') unlinkat(r1, 0x0, 0x200) r2 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$IP6T_SO_SET_REPLACE(r2, 0x29, 0x40, &(0x7f0000000c80)=@raw={'raw\x00', 0x3c1, 0x3, 0x4c0, 0x2e0, 0x940c, 0x3002, 0x2e0, 0x2c0, 0x3f0, 0x3d8, 0x3d8, 0x3f0, 0x3d8, 0x3, 0x0, {[{{@uncond, 0x0, 0x298, 0x2e0, 0x4001, {}, [@common=@inet=@recent0={{0xf8}, {0x0, 0x4001, 0x1, 0x3, 'syz0\x00'}}, @common=@inet=@recent0={{0xf8}, {0x0, 0x0, 0x2, 0x0, 'syz0\x00'}}]}, @common=@inet=@TEE={0x48, 'TEE\x00', 0x1, {@ipv4=@loopback, 'virt_wifi0\x00'}}}, {{@uncond, 0x0, 0xd0, 0x110, 0x0, {}, [@inet=@rpfilter={{0x28}}]}, @common=@unspec=@RATEEST={0x40, 'RATEEST\x00', 0x0, {'syz1\x00', 0x1, 0xbe, {0x565159d7}}}}], {{'\x00', 0x0, 0xa8, 0xd0}, {0x28}}}}, 0x520) sendmsg$SEG6_CMD_DUMPHMAC(r1, &(0x7f0000000600)={&(0x7f0000000380)={0x10, 0x0, 0x0, 0x4}, 0xc, &(0x7f00000005c0)={&(0x7f00000002c0)=ANY=[@ANYBLOB="1c000000", @ANYRES16, @ANYBLOB="0000229ac9d99901d7d8b38bfa2abd7000fedbc9250200000002ade7c550b604dd93ab69a1fb7c852d795258aab01ee15cc329cc07030d507ee56a68f8a8c4cb8e5c46"], 0x1c}, 0x1, 0x0, 0x0, 0x10d0}, 0x20010) r3 = socket$netlink(0x10, 0x3, 0x0) sendmsg$netlink(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000640)=[{&(0x7f0000000340)=ANY=[@ANYBLOB="2c00000010008100000000000080000000000000", @ANYRES32=0x0, @ANYBLOB="0a043cbf", @ANYRES32, @ANYBLOB="0a001b"], 0x2c}, {&(0x7f0000000400)={0x10, 0x3f, 0x200, 0x70bd29, 0x25dfdbff}, 0x10}, {0x0}], 0x3}, 0x0) 1.70011754s ago: executing program 6 (id=1794): r0 = socket(0x10, 0x803, 0x0) getsockname$packet(r0, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000200)=0x14) sendmsg$nl_route(r0, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000500)={&(0x7f00000002c0)=ANY=[@ANYBLOB="60000000100039042cbd7000eaffffff000003e4", @ANYRES32=r1, @ANYBLOB="001100000000000040001280080001007369740034000280050009002900000008000200ac1414bb08000c000000010006000d"], 0x60}, 0x1, 0x0, 0x0, 0x8000}, 0x4040) 1.54388369s ago: executing program 5 (id=1796): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000001e80)=ANY=[@ANYBLOB="0b000000080000000c000000ffffffff01"], 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xd, &(0x7f0000000240)=ANY=[@ANYBLOB="18000000000000000000000000000000850000006d00000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000010b704000000000000850000000100000095"], &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000180)='kfree\x00', r1, 0x0, 0x2}, 0x18) r2 = openat$tun(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) ioctl$TUNSETIFF(r2, 0x400454da, &(0x7f00000001c0)={'bond_slave_0\x00'}) ioctl$TUNSETIFF(r2, 0x400454ca, &(0x7f0000000000)={'dvmrp1\x00', 0x1}) r3 = openat$tun(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) ioctl$TUNSETIFF(r3, 0x400454da, &(0x7f0000000140)={'bond0\x00'}) ioctl$TUNSETIFF(r3, 0x400454ca, &(0x7f0000000100)={'nicvf0\x00', 0x1432}) 1.543600054s ago: executing program 1 (id=1797): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000b00)=ANY=[@ANYBLOB="1e0000000000000005000000ff"], 0x50) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005700000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r1}, 0x10) syz_emit_ethernet(0x4c, &(0x7f0000000280)=ANY=[@ANYBLOB="aaaaaaaaaaaa0180c200000086dd60000000001611fffe8100000000000000000000000000bbfe8000000000000000000000000000aa"], 0x0) 1.505090172s ago: executing program 3 (id=1798): r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000700)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000002d00000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x15, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00', r0}, 0x10) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000001c0)={0x18, 0x4, &(0x7f0000000040)=ANY=[@ANYBLOB="18070000000000000000000000000000950000000000010095"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 1.43229198s ago: executing program 1 (id=1799): r0 = openat$nvram(0xffffffffffffff9c, &(0x7f00000002c0), 0x88002, 0x0) pwritev(r0, 0x0, 0x0, 0x0, 0x0) 1.363901813s ago: executing program 3 (id=1800): sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000140)={0x0, 0x0, &(0x7f00000000c0)={0x0, 0x18}}, 0x4000) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000240)={0x11, 0x4, &(0x7f0000000180)=ANY=[@ANYBLOB="18010000010000000000000000030000850000007b00000095"], &(0x7f0000000100)='GPL\x00', 0x3, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0xffffffff, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000340)='kfree\x00', r0}, 0x10) r1 = syz_open_dev$sg(&(0x7f00000002c0), 0x0, 0x2000) r2 = fcntl$dupfd(r1, 0x0, r1) ioctl$SG_IO(r2, 0x2285, &(0x7f0000000040)={0x53, 0xfffffffe, 0x6, 0x0, @buffer={0x2, 0x41001, &(0x7f00000000c0)=""/81}, &(0x7f0000000380)="259374c96ee3", 0x0, 0x300, 0x0, 0x0, 0x0}) 1.310165546s ago: executing program 1 (id=1801): open$dir(&(0x7f0000000080)='./file0\x00', 0x204180, 0x180) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000240)=ANY=[], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bind$rds(0xffffffffffffffff, &(0x7f0000000040)={0x2, 0x0, @loopback}, 0x10) ioctl$sock_ipv6_tunnel_SIOCGETTUNNEL(0xffffffffffffffff, 0x89f0, 0x0) r0 = socket$inet6_sctp(0xa, 0x5, 0x84) getsockopt$inet_sctp6_SCTP_SOCKOPT_CONNECTX3(r0, 0x84, 0x6f, &(0x7f0000000040)={0x0, 0x10, &(0x7f0000000000)=[@in={0x2, 0x300, @private=0xa010101}]}, &(0x7f0000000080)=0x10) bind$inet(0xffffffffffffffff, 0x0, 0x0) r1 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPCTNL_MSG_TIMEOUT_NEW(r1, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000740)=ANY=[@ANYBLOB="440000000008010400000000000000000700000806000240600200001400048008000a400000000908"], 0x44}}, 0x4000000) r2 = socket$inet6_tcp(0xa, 0x1, 0x0) connect$inet6(r2, &(0x7f0000000180)={0xa, 0x4001, 0x0, @dev={0xfe, 0x80, '\x00', 0x1b}, 0xd}, 0x1c) write$binfmt_script(r2, &(0x7f0000000200), 0xfffffd9d) sendmsg$L2TP_CMD_SESSION_GET(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000004c0)={&(0x7f0000000640)=ANY=[], 0x28}}, 0x0) 1.252709207s ago: executing program 3 (id=1802): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="04000000040000000400000005"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x8, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b70800000000e7057b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000001600000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x9, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xe8c, @void, @value}, 0x94) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000380)={0x0, 0x4, &(0x7f0000000480)=ANY=[@ANYBLOB="18020000000000000000"], 0x0, 0x0, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000300)='fib_table_lookup\x00', r1}, 0x10) r2 = socket$netlink(0x10, 0x3, 0x0) sendmsg(r2, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000300)=[{&(0x7f0000000140)="5500000018007f5f00fe01b2a4a2809302060000ff41fd01020400000a00120002002800000019002d007fffffff0022de1330d54400009b84136ef75afb83de066a5900e1baac968300000000f2ff000001000000", 0x55}], 0x1, 0x0, 0x0, 0x7a000000}, 0x4000884) 883.721019ms ago: executing program 4 (id=1803): r0 = bpf$BPF_BTF_LOAD(0x12, 0x0, 0x0) r1 = socket(0x10, 0x803, 0x0) ioctl$sock_SIOCETHTOOL(r1, 0x8946, 0x0) r2 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000004c0)={0x18, 0x5, &(0x7f0000000280)=ANY=[@ANYBLOB="1801000000dd0000000000003b810000850000006d000000a50000005000000095"], &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0xa, '\x00', 0x0, 0x2, r0, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x5, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000340)='kfree\x00', r2, 0x0, 0x3e}, 0x18) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="02000000040000"], 0x48) uname(&(0x7f0000000300)=""/10) r3 = openat(0xffffffffffffff9c, &(0x7f0000000100)='./file1\x00', 0x42, 0x1ff) write$binfmt_elf64(r3, 0x0, 0x5b0) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_MSG_GETOBJ_RESET(r4, &(0x7f00000003c0)={0x0, 0x0, &(0x7f0000000380)={&(0x7f0000000840)=ANY=[], 0x164}, 0x1, 0x0, 0x0, 0x4000800}, 0x4008804) r5 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_CREATE(r5, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000440)=ANY=[@ANYBLOB="4c00000002060108000034e40000000000000000050001000600000005000400000000000900020073797a3100000080050005000200000011000300686173683a69702c706f7274"], 0x4c}, 0x1, 0x0, 0x0, 0x4000}, 0x0) sendmsg$IPSET_CMD_ADD(r4, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000300)=ANY=[@ANYBLOB="50000000090601020000000000000000020000840900020073797a31000000000500010007000000280007800c00018008000140fffffff70500070084000000060004404e22000006000540"], 0x50}, 0x1, 0x0, 0x0, 0x10000082}, 0x90) 856.461237ms ago: executing program 3 (id=1804): r0 = syz_open_procfs(0x0, 0x0) faccessat2(r0, &(0x7f0000000040)='\x00', 0x1, 0x1300) 826.784453ms ago: executing program 6 (id=1805): bpf$PROG_LOAD(0x5, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) bpf$MAP_CREATE(0x0, 0x0, 0x48) socket$packet(0x11, 0x2, 0x300) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xb, &(0x7f00000006c0)=ANY=[@ANYBLOB="18000000000000000000000095980000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f0ffffffb702000005000000b703000000000000850000007300000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x1, '\x00', 0x0, @fallback=0x20, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000140)='kmem_cache_free\x00', r0}, 0x10) syz_emit_ethernet(0x6e, &(0x7f0000000440)={@link_local={0x1, 0x80, 0xc2, 0x0, 0x0, 0x3}, @empty, @void, {@ipv6={0x86dd, @icmpv6={0x0, 0x6, '\x00', 0x38, 0x3a, 0x0, @initdev={0xfe, 0x88, '\x00', 0x1, 0x0}, @mcast2, {[], @pkt_toobig={0x2, 0x0, 0x0, 0x5dc, {0x0, 0x6, "8cb02b", 0x9, 0x2f, 0x0, @loopback, @local, [@srh={0x2b, 0x0, 0x4, 0x0, 0x0, 0x10}]}}}}}}}, 0x0) 775.307245ms ago: executing program 4 (id=1806): r0 = socket$inet6_udp(0xa, 0x2, 0x0) bind$inet6(r0, &(0x7f0000000000)={0xa, 0xe22, 0x2, @empty, 0xfff}, 0x1c) connect$inet6(r0, &(0x7f0000000140)={0xa, 0x4e20, 0x4, @remote, 0xb}, 0x1c) syz_emit_ethernet(0xd2, &(0x7f0000000540)=ANY=[@ANYBLOB="aaaaaaaaaaaaaaaaaaaaaaaa86dd60010100009c1100fe8000000002000000000000000000bbfe8000000000000000000000000000aa4e200e22"], 0x0) 768.483574ms ago: executing program 5 (id=1807): socket$nl_generic(0x10, 0x3, 0x10) r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="020000000400000008000000060000000010"], 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000006c0)={0x11, 0xd, &(0x7f0000000780)=ANY=[@ANYBLOB="18000000000000000000000000000000850000000700000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000001b80)='GPL\x00', 0x0, 0x0, 0x0, 0x100, 0x0, '\x00', 0x0, @fallback=0x36e084fcb6392193, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000005c0)={&(0x7f0000000080)='kfree\x00', r1}, 0x10) r2 = socket$packet(0x11, 0x3, 0x300) ioctl$sock_SIOCGIFINDEX(r2, 0x8933, &(0x7f0000000340)={'geneve0\x00', 0x0}) bind$packet(r2, &(0x7f0000000000)={0x11, 0x3, r3, 0x1, 0x0, 0x6, @local}, 0x14) r4 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r4, &(0x7f00000003c0)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000280)=@getchain={0x24, 0x11, 0x839, 0x70bd2d, 0x25dfdbff, {0x0, 0x0, 0x0, r3, {0xc}, {0xfff3, 0x8}}}, 0x24}}, 0x20040000) 729.816615ms ago: executing program 3 (id=1808): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0b00000007000000080000000800000005"], 0x48) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="1800"/15, @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000027b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x4, '\x00', 0x0, @fallback=0x13, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000040)='kmem_cache_free\x00', r1}, 0x10) r2 = bpf$MAP_CREATE(0x0, &(0x7f0000000280)=@base={0x7, 0x4, 0x208, 0x21, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x11, 0x8, &(0x7f0000000740)=ANY=[@ANYBLOB="1800000000000000000000000000000018120000", @ANYRES32=r2, @ANYBLOB="0000000000000000b703000000000001850000001b000000b700000000000700"], &(0x7f0000000780)='GPL\x00', 0x0, 0x0, 0x0, 0x41000, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r3 = socket$nl_route(0x10, 0x3, 0x0) ioctl$sock_SIOCGIFINDEX(r3, 0x8933, &(0x7f0000000000)={'veth0_vlan\x00', 0x0}) sendmsg$nl_route_sched(r3, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000180)=@getchain={0x24, 0x11, 0x43d, 0x0, 0x0, {0x0, 0x0, 0x0, r4}}, 0x24}, 0x1, 0x0, 0x0, 0x8080}, 0x0) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000180)={&(0x7f0000000200)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0xc, 0xc, 0x3, [@fwd={0x1}]}, {0x0, [0x2e]}}, 0x0, 0x27, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x28) bpf$MAP_CREATE(0x0, &(0x7f0000001380)=ANY=[@ANYBLOB="0e000000040000000800000008"], 0x50) bpf$PROG_LOAD(0x5, &(0x7f0000000c00)={0x11, 0xc, &(0x7f0000000340)=ANY=[], 0x0, 0x0, 0x0, 0x0, 0x41000, 0x41, '\x00', 0x0, @fallback=0x1e, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffd, @void, @value}, 0x94) r5 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r5, &(0x7f0000000300)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x20048840}, 0x4001000) r6 = socket$inet6_sctp(0xa, 0x801, 0x84) r7 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_TCP_CONGESTION(r7, 0x6, 0xd, &(0x7f00000004c0)='dctcp\x00', 0x6) bind$inet6(r7, &(0x7f0000d84000)={0xa, 0x2, 0x0, @loopback, 0x7}, 0x1c) setsockopt$inet6_tcp_int(r7, 0x6, 0x2000000000000022, &(0x7f0000000200)=0x1, 0x4) sendto$inet6(r7, &(0x7f0000000240)=':', 0x1, 0x20000045, &(0x7f00000001c0)={0xa, 0x2, 0x398, @empty}, 0x1c) shutdown(r7, 0x1) openat$rfkill(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) syz_open_procfs(0x0, 0x0) openat$nci(0xffffffffffffff9c, &(0x7f0000000040), 0x2, 0x0) sendmmsg$inet6(r6, &(0x7f00000006c0)=[{{&(0x7f0000000000)={0xa, 0x40, 0x6, @private0={0xfc, 0x0, '\x00', 0xfe}, 0x3}, 0x1c, &(0x7f0000000300)=[{&(0x7f0000000080)="18", 0x1}], 0x1}}, {{&(0x7f0000000040)={0xa, 0x4e23, 0xfffffffb, @remote, 0x5}, 0x1c, &(0x7f0000000500)=[{&(0x7f00000002c0)="b71b0000000000000000755f92f38428b4da87fc1b5d7b4375", 0x19}], 0x1}}], 0x2, 0x0) 619.615705ms ago: executing program 6 (id=1809): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000380)=@base={0x1, 0x7, 0xc, 0x38a0, 0x1, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f0000000580)={0x0, 0xc, &(0x7f0000000440)=@framed={{}, [@ringbuf_output={{0x18, 0x1, 0x1, 0x0, r0}, {}, {}, {}, {}, {}, {}, {0x85, 0x0, 0x0, 0x3}}]}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffd, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000040)='sched_switch\x00', r1}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$tipc2(&(0x7f0000000040), 0xffffffffffffffff) sendmsg$TIPC_NL_MEDIA_SET(r2, &(0x7f0000000440)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000c00)=ANY=[@ANYBLOB="ac020000", @ANYRES16=r3, @ANYBLOB="bf4400000000000000000c"], 0x2ac}}, 0x0) 551.728176ms ago: executing program 4 (id=1810): r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000300)={0x11, 0x13, &(0x7f0000000240)=ANY=[@ANYBLOB="180300000005000000000000000000001801000011af000000000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000020000838500000070000000180100002020752500000000806020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000400000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000500)={&(0x7f00000005c0)='sys_exit\x00', r0, 0x0, 0x8}, 0x18) 499.422821ms ago: executing program 4 (id=1811): r0 = openat$rtc(0xffffffffffffff9c, &(0x7f0000000000), 0x40, 0x0) ioctl$RTC_AIE_ON(r0, 0x7001) ioctl$RTC_ALM_SET(r0, 0x40247007, &(0x7f0000000080)={0x36, 0xb, 0x2, 0x1d, 0x0, 0x0, 0x2, 0x89}) 390.722492ms ago: executing program 4 (id=1812): r0 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000001140)={&(0x7f0000000300)=ANY=[@ANYBLOB="400000001000030500"/20, @ANYRES32=0x0, @ANYBLOB="0019000000000000140012800b0001006970366772650000040002800a000100aaaaaaaaa12800e08a21b2000c74e1d7fa6ee06b8ffeffb3ee63e709233d2b4369c6ca8ec3c35b3861cea9ed2823ee0e5e575c"], 0x40}}, 0x0) r1 = bpf$MAP_CREATE(0x0, &(0x7f0000000100)=ANY=[@ANYBLOB="0100000004000000e27f000001"], 0x50) r2 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="02000000040000000600000005"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000001070000000000000000000018110000", @ANYRES32=r2, @ANYBLOB="0000000000000000b7080000001900007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000005c0)={0x18, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000140)={&(0x7f0000000040)='mm_page_alloc\x00', r3}, 0x10) bpf$BPF_MAP_LOOKUP_AND_DELETE_ELEM(0x15, &(0x7f00000004c0)={r1, &(0x7f0000000340), 0x0}, 0x20) socket$netlink(0x10, 0x3, 0x13) r4 = socket$netlink(0x10, 0x3, 0x10) bind$netlink(r4, &(0x7f0000514ff4)={0x10, 0x0, 0x0, 0x2ffffffff}, 0xc) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) r5 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) ptrace(0x10, r5) ptrace$setregs(0x1a, r5, 0xc, &(0x7f0000000040)) r6 = fsopen(&(0x7f00000000c0)='cgroup2\x00', 0x0) fsconfig$FSCONFIG_SET_BINARY(r6, 0x6, 0x0, 0x0, 0x0) r7 = fsmount(r6, 0x0, 0x0) openat$cgroup_subtree(r7, &(0x7f0000000100), 0x2, 0x0) setsockopt$sock_int(r4, 0x1, 0x2d, &(0x7f00000002c0), 0x4) r8 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r8, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000500)=@newtaction={0x70, 0x30, 0xffff, 0x0, 0x0, {}, [{0x5c, 0x1, [@m_ife={0x58, 0x1, 0x0, 0x0, {{0x8}, {0x30, 0x2, 0x0, 0x1, [@TCA_IFE_METALST={0x4}, @TCA_IFE_PARMS={0x1c, 0x1, {{0x5, 0xc6a, 0x4, 0x200, 0x3}, 0x1}}, @TCA_IFE_SMAC={0xa}]}, {0x4}, {0xc}, {0xc}}}]}]}, 0x70}}, 0x0) setsockopt$netlink_NETLINK_BROADCAST_ERROR(r4, 0x10e, 0x4, &(0x7f0000000640)=0x1800, 0x4) r9 = socket$kcm(0x10, 0x2, 0x0) r10 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r10, &(0x7f0000000600)={0x0, 0x0, &(0x7f00000005c0)=[{&(0x7f0000000380)="2e00000010008188e6b62aa73772cc9f1ba1f848110000005e140602000000000e000a001000000002900000121f", 0x2e}], 0x1}, 0x0) sendmsg$kcm(r9, &(0x7f0000000600)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f0000000040)="2e00000010008188040f80ec59acbc0413a1f848110000005e140602000000000e000a000f00000002800000121f", 0x2e}], 0x1}, 0x0) 291.777984ms ago: executing program 1 (id=1813): r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x11, 0x8, &(0x7f00000009c0)=ANY=[@ANYBLOB="620af8ffa1dc0021bfa100000000000007010000f8ffffffb702000007000000bd120000000000008500000010000000b70000000000000095000000000000003faf4f2aa3d9b18ed812a2e2c49e8020a6f4e0e4a9446c7670568982b4e020f698393aa0f3881f9c24561f1b2607995daa56f151905ea23c22624c9f87f9793f3bbb546040677b0c5077da80fb982c1e9400e693146cea484a415b76966118b64b751a0f241b072e90080008002d75593a286cecc93e64c227c95aa0b784625704f07372c29184ff7f4a7c0000070000006056feb4cc664c0af9360a1f7a5e6b607130c89f18c0c1089d8b8588d72ec29c48b45e0000000000000401d01aa27ae8b09e00e79ab20b0b8ed8fb7a68000000000000000000006fa03c6468978089b302d7ff6023cdcedb5e0125ebbcebdde510cb2364149215108337719acd97cfa107d40224edc5465a932b77a74e802a0dc6bf25d8a242bc6099ad2300000480006ef6c1ff0900ff0000000010c63a949e8b7955394ffaff03000000000000ab87b1bfeda7be586602d985430cea080000000000000026abfb0767192361448279b05d96a703a660581eecdbf5bcd3de227a167ca17a0faf60fd6ad9b97aa5fa68480366c9c6fd6fa5043aa3926b81e3b59c9b081d6a08000000ea2b1a52496dfcaf99431412fd134a996382a1a04d5bb924cfe5f3185418d605ffff9c4d2ec7c32f2095e63c80af740b5b7632d5933a1c1fa5605bd7603f2ba2a790d62d6faec2fed44da4928b30142ba1fde5c5d50b83bae616b5054d1e7c13b1355d6f4a8245ffa4997da9c77af4c0cb97fca585ec6bf58351d578be00d952aab9c71764b0a8a7583c90b3433b809bdb9fbd48bc877505ebf6c9d13330ca006bce1a84521f14518c9b476fccbd6c712016219848624b87cec2dbe98223d8d9e86c5ea06d108d8f80a0eb4fa39f6b5c02e6d6d90756ff578f57000000009700cf0b4b8bc229413300000000000000000003000000000000000000000000001000000000559711e6e8fcffffffffffffffb2d02edc3e01dd271c896249ed85b980680b09000000000f0000169cdcacc413b48dafb7a2c8cb482bac0ac502d9ba96ffffffd897ef3b7cda42f93d53046da21b40216e14ba2d6af8656b01e17addaedab25b30002abbba7fa725f38400be7c1f001b2cd3170400000085be9e48dccf1f9f3282830689da6b53b263339863297771d74732d400003341bf4a00fc9fec2271ff01589646efd1cf870cd7bb2366fde4a594290c405ff870ce5dfd3467decb05cfd9fcb32c8ed1dbd9d30a64c108285e71b5565b1768ee58969c41595229df17bcad70fb4021428ce970275d13b78249788f11f761038b75d4fe32b561d46ea3abe0fa4d30dc94ef241875f3b4b6ab7929a57affe760e717a04becff0f719197724f4fce1093b62d7e8c7123d890cec55bf404e4e1f74b7eed82571be54c72d978cf906df08f11f1c4042e36acd37d7f9e109f2c06f815312e0cfe222a06f56dd022c074eb8a322fb0bf47c0a8d154b405c37feaf3dd95f6ef2acd1fe582786105c70600000000000000b7561301bb997316dbf17866fb84d4173731efe895ff2e1c5560926e90109b598502d3e959efc71f665c542c9062ece84c99a061887a20639b41c8c12ee86c50804042b3eac1f871b136345cf67ca3fb5aac518a75f9e7d7101da841735e186c489b3a06fb99e0347f23a054de2f4d92d6bd72ee2c9f0390a6f01e3e483b4ad05573af403269b4a39ce40293947d9a631bcbf3583784acbda216550d7aec6b79e30cbd128f91e358c3b377327ac9ecc34f24c9ae153ec60ac0694da85bff9f5f4df90400000000000000d6b2c5eaff07000000000000b99c9cc0ad1857216f000000009191ae954febb3df464bfe0f7f3ee9afe7befb89d2777399f5874c553aeb3729cffe86e669261192899d4562db0e22d564ae09bb6d163118e401e024fd452277c3887d6116c6cc9d8046c216c1f895778cb26e22a2a798de44aeadea2a40da8daccf080842a486721737390cbf3a74cb2003016f1514216bdf57d2a40d40b51ab63e96ec8485b3b8a8c9ae3d14f93100c2e0893862eef552fcde2981f48c482bde8a168c3f5db2fea6f26e4a4304e50c349f4f9ecee27defc93871c5f99a3594191e104d417e60fc3541a2c905a1a95e9571bf38ae1981c4238ecaee6f75cd0a6881bd1517a8250df98674152f94e32409e2a3bce109b6000000000000a1fec9000000d694210d7560eb92d6a97a27602b81f76386f1535bef1497f92186086e29c6bc5a1fad6ec9a31137ab79a404abde7750898b59270b939b81367ac91bd627e87306703be8672d70d1ab57075228a9f46ed9bd1f00fb8191bbab2dc591dda61f0868afc4294859323e7a45319f18101288a0268893373750d1a8fe64680b0a3fc22dd704e4214de5946912d6c98cd1a9fbe1e7d58c08acaf30065b928a31d2eca55f74a23641f61f2d5b308cf01cfaed9ef0ce21d69993e9960ff5f76015e6009756237badf4e7965bbe2777e808fcba821a00e8c5c39609ff854356cb490000000000c1fee30a3f7a85d1b29e58c77685efc0ceb1c8e5729c66018d169fc03aa188546bb2e51935ab9067ec3ad2a182068e1e3a0e2505bc7f41019645466ac96e0d0b3bc19faa5449209b085f3c334b47f067bbab40743b2a428f1da1f626602111b40e761fd21081920382f14d12ca3c471c7868e7da7eaa69eb7f7f80572fdd11bb1d070080fbc22bf73468788df51710eb0b428ee751c47d8e894f745a868404a0bf35f0121008b722b1eaa6aedfa1bf2e7ccb2d61d5d76331ff5e20fa26b8471d9e1cc9eb3d541e407cc2dae5e690cd628ab84875f2c50ba830d3f474b079b407000000deff000040430a537a395dc73bda367bf12cb7d81691a5fe8c47be395656a297e9df902aeec50e71b967ce7daac4be290159f6bcd75f0dda9de5532e66ae9e48b0ed1254a81faae79b6af6fbb869604d51de44c4e0973171ad47d6c00ebc7603093f000000fdec743af930cd6db49a47613808bad959719c0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000f15d6533f78a1f4e2df4ca23d867693fd42de9b49a1b36d48a44ba6a4530e59bec53e876dc660dd6d89f80a4377b1b1292a893a516dab183ee65744fb8fc4f9ce2242e0f000000000100000000d77480e0345effff6413258d1f6eb190aa28cbb4bafe3436b176c7ed4b132fb805d5edd9d188daf28d89c014c3ecca10ae55704544673e1fb03b84f63e022fe755f4007a4a899eaf52c4f491f1e97c862e29e4570600000091c691faee1e0c8fe056a07474e6e5490a7d3c3402000000b60600d837c6befc63ddf2f594ad7cbc56a1e44d218c956a5392a995f1fae8e9f206efbb33854dc70104d74dc07748f9745cb796da2dfb714a0500000000000000faed94fc39acfb3fd25dfa8116a154cd1226e1bb72b59fed817072a0da60160761fd3dffda0f7c592eabd8ab68334d2a1693cb187539049e331272bf5135044df8161400211b8012b6eb1ed5656e83f65509bb4b323c5bd61bff949d3bade2f6ffda1360c2786e16937ab61d6dcafed319c7167d0885f9c6d1f442954c167dd9b4acd9468ce3674c82bbb2e31389179b025dbe063b7f906217b2cf8410c7023aa3e5cc3ba1000000000000000000000000000000006ae6301a2da44394275c582a6516bb92ea1980a0a659f2f1811c8b281c209647c4241f292b20508b215dde27bb2487a6e2b5e4a8ccfab90c23827ef06cbe364073005f8a6d1456aaeb85ffb7858f24eced67a67ab825e863928ed64c83f62ffdaa997657335b63c6b4163aff094059e626766845fd779c9e6cdbbd64c2499ce3ffe2fef03f7cdd0d90f3a7579579a142c0f7b318264d5c13c31cf475829528267ead38523cab7e1664e8426cfce471fef821c8a02a7e7d954d05b68a9c28f79429b09e2bb3681ae2b831e27c735123361c193d66ed4d71f19b199d371ec6bfada7cd370e3fdd3cd980fa1e145fd3f3e96b1feb53c865e1ada08f5d16ed652ee0c7f45352222692fbd679212c225d097aa90f7e1fb1f983415f43e75a19ecf7fd21bfa150ef563aa72ba3c43c5f3d9be128ec26b691f31f9cab931631606a81622f120675c962be2d3b5e95f74f0b209e42e6bdd76e6e725295b1d78d928f6f63e4581d5cc41cbde2ba66adc1168070c8c6e18a6a234f5f9311ef0f78924b68dbb4712efdb6974667bdb54f16fd2061b9ba93638dd177227e94e4ebd0ec1d437db948062bf41742000000000000000000305f70dd02fa0c61d5fe6d8ff35389246037e18d34c1375ae04f44f0c2543c772c5ccb137be7dc1874c514b37c668554d77d4ea5ed144a648257f4a0301067bbcd9b91072659d872f26b796e2b81025edb5f45f785e2c2602b248ecdd80f019ca659be7e8ae953325a27564f33c9d458a60be3dab38baab7eb1a66ab1ffd6308f7fd51beb356fe75eb985b7581bb5584c53984ba9c3340f97e8d3825681c53de5f554e595b00000000000000006a8fa9f05d64c4be42f981f00051a39938613067dbd1427e01bfec016e51844cefa8a855bf23ac887b4a88eed6d9443857242f28e31a41d20105fbf3394ff910e734b4d9101265ff729c426e01c1ab13dda8c388b909006f19eecb87e39175e85e17000000000000000000009431807e43886903526074e6b40244c938a4c68a38c25ddd7c143b3f1400010000ec66815cf8d1f56aa1424bc9b5d58790298e5b310969e50c222563b54e60854e1b0100448aca8c5ccbf5546ce4c3cd5a733fec25fb94e1e0f966bcbd28a4d8fe4f556eaa1104a793006619700798354c6ae05025040965e3083562bfa20968c04007d21dc02c9fd1f75e1ff40f439bdde4e784012e52049b483d02f81b88f5f57816b3fecec79cfca8d37203e769759d6b6a56b7605ced8ee18475a77ff0963a565fb6021d216c01b1098e40550a1cfd80e918d685a7b099a4f8ed654cd76ca61fe5ad8a31ec558fdbfa706d5e738bceae81fe777c307d5bc72183a4c2d35732ab916a781b9912160a3fd2a2e74dd690c57bdfdc1f069f949170ef8cb9c13c12138116bca7a8c59363799be7005c51bc25a8bbe2cf5ddf6aa161693782b0e7feb8a768f391b49d4c978c96dbb52f21c122eba9f17c8bed10591958cf06321a248b5f76ceedfe0d080d6aeadc11b237b3326dd04b86ac37c0d131544888db9e128d059761ad9a393e96c3b41c13c5a381bff187a75de560ba6eb3faa5ff8d2bb3c88f8de5efc2fb2200cfda6d07ceae22577064334fbf76a23e62e6059211d995b879f6b7d3f7fcf03652b81e6b7cdeff947ad185d3c6269ca247b429c3b872a8f1ef60407d29a874f4ec31c9effed55543a65a6b4d778cebcd43b7905f3960140bd783540a7353014bda8e9c7a34a5f428fd1f8eb11e837dd9d586487fdebcb1ecd3a003ff0fda4be617fecf1ff0ef2c74664d60a4b9423f3297bc8eb91b4ee1d73272abbef3e7a828a7d7ab055a8eb58fe379de85338304e26e3620941b463e9049fd105c74c91cc4d71b0f76e2c2e4825106aa7ce2a3adbbc7a0443ece58e752b47e6f677eff7c5c568a89d6e36b165c39132a0f27080ece2a94c320b002c77f82662675a7713c7067081cac15994698c41ff4754268ae1676384ff799783f55d7e5a1a0920300000000000000d98440c355927629f2bcf9dc405a18ca0264400abf38e90000000000000000008faf2cddffbfa69bf32eb718e88ec75603ed7c7a8825ce0f27a114bd7a4ab74d0c7b8d90ccc1c3ca6620def782e24d75aed70eb676437f62677a69e0994cd82d72e95493c830fe9515329f40b7025326dec33a527c5d999298eaa3690fd0d38a02fc6e0bc16dbe19f353027edc014411e1138087221492f5d5e5cc9d0a1acd3f581eda9a807aa0e609f935f626d96351e0ff116686cbeb8939feecd5dac8cf45101942cc7cec21b7f337df5431bcf7e504b7c427f70a10e1cb8993a661306a0576b638a0171e6800b5b35589d676eb30ed1a72e8f7b057eb281c4504195635b6b285ebaba019913a2520e43ed790231f047f7d3789c10ae7d724929f77aec1d33d9587580268ee14396f71e7ef588cb2560d6bd0795a9b97281229eb16de086553469fad7214ffc3e416f8b8e442dce1d37f9b1c88a5d8a8d9f2fe45bd8df213ecb4194c8554aea13cadcd502e51f6fec80418e772b5bd8d0228949058038b185909ee542848680f9ad43f4057d676d5e21ae3d7e0e4a28c04f112a94707f032b35915e42993ff148291b8babe026646ee41905992db217561b90811c4702a14f312fe5d2ae7257db6be1034cc1c346b76a853ce274bf0435e18f7e86c660c18c80f30505dd4cf2ae2a1893b83c62d61bfeadc1f913e4cab2b897e096dd3fe3525090410cb23bab36cdf200a36014032cf6e5121803c5a0c4a273a19f340163fc6265425d513a1294b8439276394945d94a589708e32a1cb30f1fa4b2f08e01dc5e8c6732e6dc59b5c8cb400000000000000592c9b68f09c8f5ddb20b4ae08b4d9df548e5ed6cd47b91a4bea8b6aa52edf64576aef1e43f2958437fdc20fbbd0d4e13d8cce1193b2f9b4f107e25af178d056e1b1e40bd75b013f7484fae0bc447b1ffaf34819fe3ad1a634c94345e26e1e68dec08723a37b05d1594a66a4718a51d4d67fc880c9d640f4eacc509873f1a103c87f69"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x41) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000340)='kfree\x00', r0}, 0x10) prctl$PR_SET_NAME(0xf, &(0x7f0000000140)='+}[@\x00') r1 = open(&(0x7f0000000300)='.\x00', 0x0, 0x0) r2 = socket(0x40000000015, 0x5, 0x0) connect$inet(r2, &(0x7f0000000040)={0x2, 0x4e20, @loopback}, 0x10) bind$inet(r2, &(0x7f0000000340)={0x2, 0x4e20, @loopback}, 0x57) sendmsg$xdp(r2, &(0x7f0000000100)={0x0, 0x0, 0x0}, 0x0) sendmsg$NL80211_CMD_JOIN_MESH(r2, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000240)=ANY=[], 0x30}, 0x1, 0x0, 0x0, 0x40000}, 0x40) close_range(r1, 0xffffffffffffffff, 0x0) 151.126833ms ago: executing program 6 (id=1814): r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000240)={0x11, 0xb, &(0x7f00000009c0)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000093850000007100000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00', r0, 0x0, 0x6}, 0x18) r1 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000100), 0x0) ioctl$SNDRV_SEQ_IOCTL_SET_PORT_INFO(r1, 0xc0a85320, &(0x7f00000003c0)={{0x80}, 'port0\x00', 0x511e36599023629, 0x100000, 0x0, 0x4000000, 0xffffffff, 0x1, 0x0, 0x0, 0x5, 0x4}) ioctl$SNDRV_SEQ_IOCTL_DELETE_PORT(r1, 0x40a85321, &(0x7f00000004c0)={{0x80}, 'port0\x00', 0x8, 0x100075, 0xffefffff, 0x4, 0x1ff, 0x0, 0x0, 0x0, 0x6}) 116.492061ms ago: executing program 1 (id=1815): r0 = bpf$MAP_CREATE(0x0, &(0x7f00000008c0)=ANY=[@ANYBLOB="0a00000002000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000980)={0x17, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x7a, 0x0, 0x0, 0x41000, 0x44, '\x00', 0x0, @cgroup_sysctl=0x12, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x7, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x27, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000400)={&(0x7f00000001c0)='mm_page_free\x00', r1, 0x0, 0x6}, 0x18) r2 = io_uring_setup(0x6c4, &(0x7f0000000080)={0x0, 0x4075, 0x18, 0x2}) io_uring_register$IORING_REGISTER_BUFFERS(r2, 0x0, &(0x7f00000002c0)=[{&(0x7f0000001700)=""/4095, 0x440000}], 0x100000000000011a) 73.116838ms ago: executing program 5 (id=1816): r0 = socket$kcm(0x22, 0x2, 0x21) r1 = openat$autofs(0xffffffffffffff9c, &(0x7f00000000c0), 0x109000, 0x0) ioctl$AUTOFS_DEV_IOCTL_CLOSEMOUNT(r1, 0xc0189375, &(0x7f0000000100)={{0x1, 0x1, 0x18, r0}, './file0\x00'}) 0s ago: executing program 3 (id=1817): r0 = socket$inet_udp(0x2, 0x2, 0x0) connect$inet(r0, &(0x7f0000000040)={0x2, 0x4e1f, @remote}, 0x10) setsockopt$sock_linger(r0, 0x1, 0x3d, &(0x7f0000000080), 0x8) sendmmsg$sock(r0, &(0x7f0000000000)=[{{0x0, 0x0, 0x0, 0x0, &(0x7f0000000140)=[@txtime={{0x18, 0x1, 0x3d, 0x1}}, @mark={{0x14, 0x1, 0x24, 0x3}}], 0x30}}], 0x1, 0x4000000) kernel console output (not intermixed with test programs): ch=c000003e syscall=202 compat=0 ip=0x7f1141b8e929 code=0x7ffc0000 [ 433.511261][ T30] audit: type=1326 audit(1749416692.136:1747): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11270 comm="syz.6.1369" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f1141b8e929 code=0x7ffc0000 [ 433.666330][ T30] audit: type=1326 audit(1749416692.136:1748): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11270 comm="syz.6.1369" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f1141b8e929 code=0x7ffc0000 [ 433.689583][ T24] usb 6-1: new low-speed USB device number 107 using dummy_hcd [ 433.703545][T11297] netlink: 24 bytes leftover after parsing attributes in process `syz.1.1374'. [ 433.883570][ T24] usb 6-1: string descriptor 0 read error: -22 [ 433.891013][ T24] usb 6-1: New USB device found, idVendor=1415, idProduct=0003, bcdDevice=65.5d [ 433.953581][ T5897] usbhid 5-1:1.0: couldn't find an input interrupt endpoint [ 433.968865][ T24] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 434.026346][ T5897] usb 5-1: USB disconnect, device number 3 [ 434.053369][ T24] usb 6-1: config 0 descriptor?? [ 434.295141][ T24] dvb-usb: found a 'Sony PlayTV' in cold state, will try to load a firmware [ 434.314192][T11284] netlink: 'syz.3.1371': attribute type 21 has an invalid length. [ 434.347664][ T24] dvb-usb: downloading firmware from file 'dvb-usb-dib0700-1.20.fw' [ 434.390597][ T5919] usb 2-1: new full-speed USB device number 101 using dummy_hcd [ 434.419704][ T24] dib0700: firmware download failed at 7 with -22 [ 434.464432][ T24] usb 6-1: USB disconnect, device number 107 [ 434.488008][ T7012] usb 7-1: new full-speed USB device number 11 using dummy_hcd [ 434.495705][ T5844] Bluetooth: hci0: command 0x0405 tx timeout [ 434.580210][ T5919] usb 2-1: config 0 has an invalid interface number: 65 but max is 3 [ 434.601182][ T5919] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 434.619277][ T5919] usb 2-1: config 0 has 1 interface, different from the descriptor's value: 4 [ 434.653511][ T7012] usb 7-1: config index 0 descriptor too short (expected 51137, got 36) [ 434.678022][ T5919] usb 2-1: config 0 has no interface number 0 [ 434.703406][ T7012] usb 7-1: config 3 has too many interfaces: 208, using maximum allowed: 32 [ 434.725802][ T5919] usb 2-1: New USB device found, idVendor=0af7, idProduct=0101, bcdDevice=91.34 [ 434.747967][ T7012] usb 7-1: config 3 has an invalid descriptor of length 251, skipping remainder of the config [ 434.760078][ T5919] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 434.790076][ T5919] usb 2-1: Product: syz [ 434.794310][ T7012] usb 7-1: config 3 has 0 interfaces, different from the descriptor's value: 208 [ 434.807917][ T5919] usb 2-1: Manufacturer: syz [ 434.824291][ T5919] usb 2-1: SerialNumber: syz [ 434.831815][ T7012] usb 7-1: New USB device found, idVendor=10c4, idProduct=8acf, bcdDevice= 0.00 [ 434.862863][ T5919] usb 2-1: config 0 descriptor?? [ 434.877360][ T7012] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 435.212567][ T7012] usb 7-1: string descriptor 0 read error: -71 [ 435.275797][ T7012] usb 7-1: USB disconnect, device number 11 [ 435.281889][ T24] usb 5-1: new high-speed USB device number 4 using dummy_hcd [ 435.297959][ T5890] usb 6-1: new high-speed USB device number 108 using dummy_hcd [ 435.472879][ T24] usb 5-1: Using ep0 maxpacket: 8 [ 435.509625][ T24] usb 5-1: config 0 has no interfaces? [ 435.515707][ T5890] usb 6-1: Using ep0 maxpacket: 16 [ 435.521329][ T24] usb 5-1: New USB device found, idVendor=1de1, idProduct=c102, bcdDevice=4d.89 [ 435.539666][ T5890] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 435.551198][ T24] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 435.576396][ T5890] usb 6-1: config 0 has 0 interfaces, different from the descriptor's value: 1 [ 435.587144][ T5919] flexcop_usb: set interface failed. [ 435.600431][ T24] usb 5-1: config 0 descriptor?? [ 435.605625][ T5919] b2c2_flexcop_usb 2-1:0.65: probe with driver b2c2_flexcop_usb failed with error -22 [ 435.618571][ T5890] usb 6-1: New USB device found, idVendor=0699, idProduct=8206, bcdDevice=f4.55 [ 435.665325][ T5890] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 435.678183][ T5919] usb 2-1: USB disconnect, device number 101 [ 435.706007][ T5890] usb 6-1: config 0 descriptor?? [ 435.826624][ T24] usb 5-1: USB disconnect, device number 4 [ 435.937939][ T5890] usb 6-1: string descriptor 0 read error: -71 [ 435.968411][ T5890] usb 6-1: USB disconnect, device number 108 [ 436.810411][T11368] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 436.830952][T11368] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1388'. [ 436.842463][T11368] netlink: 'syz.3.1388': attribute type 10 has an invalid length. [ 436.945848][T11371] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1388'. [ 436.969677][T11368] 8021q: adding VLAN 0 to HW filter on device bond0 [ 436.989631][T11368] team0: Port device bond0 added [ 437.007906][ T5890] usb 2-1: new high-speed USB device number 102 using dummy_hcd [ 437.192200][ T5890] usb 2-1: New USB device found, idVendor=0471, idProduct=0329, bcdDevice=db.da [ 437.281122][ T5890] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 437.448842][ T917] usb 5-1: new high-speed USB device number 5 using dummy_hcd [ 437.450372][ T5890] usb 2-1: config 0 descriptor?? [ 437.619748][ T5890] pwc: Philips SPC 900NC USB webcam detected. [ 437.620785][ T917] usb 5-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 437.655656][ T917] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 437.711714][T11371] team0 (unregistering): Port device team_slave_0 removed [ 437.737888][ T917] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 437.773106][T11371] team0 (unregistering): Port device team_slave_1 removed [ 437.857934][ T917] usb 5-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 437.878068][ T917] usb 5-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 437.900902][T11371] team0 (unregistering): Port device bond0 removed [ 437.909128][ T917] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 437.980504][ T917] usb 5-1: config 0 descriptor?? [ 438.052075][ T5890] pwc: send_video_command error -71 [ 438.057551][ T5890] pwc: Failed to set video mode VGA@30 fps; return code = -71 [ 438.065773][ T5890] Philips webcam 2-1:0.0: probe with driver Philips webcam failed with error -71 [ 438.211375][ T5890] usb 2-1: USB disconnect, device number 102 [ 438.896257][T11385] netlink: 1 bytes leftover after parsing attributes in process `syz.5.1394'. [ 438.923158][T11385] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1394'. [ 438.937968][T11385] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1394'. [ 438.985704][T11387] xt_addrtype: input interface limitation not valid in POSTROUTING and OUTPUT [ 439.017924][T11385] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1394'. [ 439.336947][T11391] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 439.623769][T11368] syz.3.1388 (11368) used greatest stack depth: 20008 bytes left [ 439.852721][ T1305] ieee802154 phy0 wpan0: encryption failed: -22 [ 439.858047][ T917] usbhid 5-1:0.0: can't add hid device: -71 [ 439.866116][ T1305] ieee802154 phy1 wpan1: encryption failed: -22 [ 439.966781][ T917] usbhid 5-1:0.0: probe with driver usbhid failed with error -71 [ 440.072664][ T917] usb 5-1: USB disconnect, device number 5 [ 440.398688][ T5890] usb 7-1: new high-speed USB device number 12 using dummy_hcd [ 440.418129][ T917] usb 5-1: new high-speed USB device number 6 using dummy_hcd [ 440.604645][ T917] usb 5-1: Using ep0 maxpacket: 8 [ 440.621489][ T5890] usb 7-1: Using ep0 maxpacket: 16 [ 440.634199][ T917] usb 5-1: config 0 has no interfaces? [ 440.649309][ T5890] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x83 has invalid maxpacket 62320, setting to 1024 [ 440.658269][ T917] usb 5-1: New USB device found, idVendor=1de1, idProduct=c102, bcdDevice=4d.89 [ 440.670509][ T5890] usb 7-1: config 0 interface 0 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 1024 [ 440.702505][ T917] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 440.704102][ T5890] usb 7-1: New USB device found, idVendor=134c, idProduct=0002, bcdDevice=ec.7e [ 440.728856][ T917] usb 5-1: config 0 descriptor?? [ 440.757911][ T5890] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 440.771035][T11430] binder: BINDER_SET_CONTEXT_MGR already set [ 440.777064][T11430] binder: 11429:11430 ioctl 4018620d 200000000040 returned -16 [ 440.782009][ T5890] usb 7-1: Product: syz [ 440.799059][T11430] binder: 11429:11430 ioctl c018620c 200000000100 returned -1 [ 440.808445][ T24] usb 4-1: new high-speed USB device number 104 using dummy_hcd [ 440.817905][ T5890] usb 7-1: Manufacturer: syz [ 440.822518][ T5890] usb 7-1: SerialNumber: syz [ 440.870525][ T5890] usb 7-1: config 0 descriptor?? [ 440.876940][T11417] raw-gadget.1 gadget.6: fail, usb_ep_enable returned -22 [ 440.910086][ T5890] hub 7-1:0.0: bad descriptor, ignoring hub [ 440.929084][ T5890] hub 7-1:0.0: probe with driver hub failed with error -5 [ 440.962578][T11433] loop7: detected capacity change from 0 to 6 [ 440.989649][ T917] usb 5-1: USB disconnect, device number 6 [ 441.011578][ T5890] input: syz syz as /devices/platform/dummy_hcd.6/usb7/7-1/7-1:0.0/input/input42 [ 441.020976][ T24] usb 4-1: Using ep0 maxpacket: 32 [ 441.061663][ T24] usb 4-1: config index 0 descriptor too short (expected 156, got 27) [ 441.099673][ T24] usb 4-1: too many endpoints for config 0 interface 0 altsetting 191: 144, using maximum allowed: 30 [ 441.123077][T11433] Dev loop7: unable to read RDB block 6 [ 441.136076][ T24] usb 4-1: config 0 interface 0 altsetting 191 endpoint 0x87 has an invalid bInterval 0, changing to 7 [ 441.172593][T11433] loop7: unable to read partition table [ 441.183522][ T24] usb 4-1: config 0 interface 0 altsetting 191 has 1 endpoint descriptor, different from the interface descriptor's value: 144 [ 441.196471][T11433] loop7: partition table beyond EOD, truncated [ 441.229631][T11433] loop_reread_partitions: partition scan of loop7 (ݷU@:B${Wɴ) failed (rc=-5) [ 441.258777][ T24] usb 4-1: config 0 interface 0 has no altsetting 0 [ 441.278858][ T24] usb 4-1: New USB device found, idVendor=0f11, idProduct=1021, bcdDevice=86.66 [ 441.329535][ T24] usb 4-1: New USB device strings: Mfr=85, Product=120, SerialNumber=172 [ 441.383160][ T24] usb 4-1: Product: syz [ 441.405829][ T24] usb 4-1: Manufacturer: syz [ 441.450894][ T24] usb 4-1: SerialNumber: syz [ 441.536658][ T24] usb 4-1: config 0 descriptor?? [ 441.577657][ T24] ldusb 4-1:0.0: Interrupt out endpoint not found (using control endpoint instead) [ 441.621776][ T24] ldusb 4-1:0.0: LD USB Device #0 now attached to major 180 minor 0 [ 443.049662][ T24] usb 7-1: USB disconnect, device number 12 [ 443.591290][ T917] usb 4-1: USB disconnect, device number 104 [ 443.647934][ T917] ldusb 4-1:0.0: LD USB Device #0 now disconnected [ 443.823301][T11487] x_tables: ip6_tables: rpfilter match: used from hooks OUTPUT, but only valid from PREROUTING [ 443.933616][T11493] input: syz1 as /devices/virtual/input/input43 [ 443.987973][ T24] usb 7-1: new high-speed USB device number 13 using dummy_hcd [ 444.050150][T11494] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1416'. [ 444.102574][T11493] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1416'. [ 444.128067][ T5890] usb 5-1: new high-speed USB device number 7 using dummy_hcd [ 444.148144][ T24] usb 7-1: Using ep0 maxpacket: 16 [ 444.161159][ T24] usb 7-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 444.196029][ T24] usb 7-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 444.220664][ T24] usb 7-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 444.232552][ T24] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 444.264469][ T24] usb 7-1: Product: syz [ 444.278102][ T24] usb 7-1: Manufacturer: syz [ 444.302227][ T5890] usb 5-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 444.318288][ T24] usb 7-1: SerialNumber: syz [ 444.345674][ T5890] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 444.397564][ T5890] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 444.447464][ T5890] usb 5-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 444.506827][ T5890] usb 5-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 444.536679][ T5890] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 444.572888][ T24] usb 7-1: 0:2 : does not exist [ 444.608163][ T917] usb 2-1: new high-speed USB device number 103 using dummy_hcd [ 444.621673][ T5890] usb 5-1: config 0 descriptor?? [ 444.629233][ T24] usb 7-1: 5:0: failed to get current value for ch 0 (-22) [ 444.728295][ T24] usb 7-1: USB disconnect, device number 13 [ 444.778142][ T917] usb 2-1: Using ep0 maxpacket: 8 [ 444.803024][ T917] usb 2-1: config 0 has no interfaces? [ 444.832190][ T917] usb 2-1: New USB device found, idVendor=1de1, idProduct=c102, bcdDevice=4d.89 [ 444.857600][ T6163] udevd[6163]: error opening ATTR{/sys/devices/platform/dummy_hcd.6/usb7/7-1/7-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 444.883879][ T917] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 444.908990][T11510] netlink: 'syz.5.1418': attribute type 1 has an invalid length. [ 444.922251][ T917] usb 2-1: config 0 descriptor?? [ 444.932285][T11510] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1418'. [ 444.991487][T11510] netlink: 'syz.5.1418': attribute type 1 has an invalid length. [ 445.183388][ T5905] usb 2-1: USB disconnect, device number 103 [ 445.470582][T11522] syzkaller1: entered promiscuous mode [ 445.476276][T11522] syzkaller1: entered allmulticast mode [ 445.536967][T11522] tipc: Can't bind to reserved service type 1 [ 445.556619][T11522] kvm_intel: set kvm_intel.dump_invalid_vmcs=1 to dump internal KVM state. [ 445.728003][ T24] usb 7-1: new high-speed USB device number 14 using dummy_hcd [ 445.900294][ T24] usb 7-1: config 0 has no interfaces? [ 445.929187][ T24] usb 7-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 445.957906][ T24] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 445.965989][ T24] usb 7-1: Product: syz [ 445.998513][ T24] usb 7-1: Manufacturer: syz [ 446.003233][ T24] usb 7-1: SerialNumber: syz [ 446.028916][ T30] kauditd_printk_skb: 1 callbacks suppressed [ 446.028932][ T30] audit: type=1326 audit(1749416705.856:1750): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11534 comm="syz.5.1422" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f24f0d8e929 code=0x0 [ 446.072112][ T24] usb 7-1: config 0 descriptor?? [ 446.397160][ T5890] usbhid 5-1:0.0: can't add hid device: -71 [ 446.434292][ T5890] usbhid 5-1:0.0: probe with driver usbhid failed with error -71 [ 446.502440][ T5890] usb 5-1: USB disconnect, device number 7 [ 447.507953][ T24] usb 5-1: new high-speed USB device number 8 using dummy_hcd [ 447.578429][ T917] usb 6-1: new high-speed USB device number 109 using dummy_hcd [ 447.601866][T11569] netlink: 'syz.3.1430': attribute type 1 has an invalid length. [ 447.663129][ T24] usb 5-1: config 0 has no interfaces? [ 447.675625][ T24] usb 5-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 447.685960][ T24] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 447.696473][ T24] usb 5-1: Product: syz [ 447.705466][ T24] usb 5-1: Manufacturer: syz [ 447.714828][ T24] usb 5-1: SerialNumber: syz [ 447.733197][ T24] usb 5-1: config 0 descriptor?? [ 447.752807][ T917] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 447.793256][ T917] usb 6-1: New USB device found, idVendor=0926, idProduct=3333, bcdDevice= 0.40 [ 447.852368][ T917] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 447.903837][ T917] usb 6-1: config 0 descriptor?? [ 448.053205][T11560] wireguard2: entered promiscuous mode [ 448.067947][ T24] usb 4-1: new high-speed USB device number 105 using dummy_hcd [ 448.075779][T11560] wireguard2: entered allmulticast mode [ 448.144321][ T917] usbhid 6-1:0.0: can't add hid device: -71 [ 448.163724][ T917] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 448.245924][ T917] usb 6-1: USB disconnect, device number 109 [ 448.308371][ T24] usb 4-1: Using ep0 maxpacket: 8 [ 448.315167][ T24] usb 4-1: config 0 has no interfaces? [ 448.323758][ T24] usb 4-1: New USB device found, idVendor=1de1, idProduct=c102, bcdDevice=4d.89 [ 448.335380][ T24] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 448.444388][ T24] usb 4-1: config 0 descriptor?? [ 448.470372][ T5905] usb 7-1: USB disconnect, device number 14 [ 448.635300][T11584] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 448.676248][ T24] usb 4-1: USB disconnect, device number 105 [ 448.930440][T11590] team0: entered promiscuous mode [ 448.945665][T11590] team_slave_0: entered promiscuous mode [ 448.952240][T11590] team_slave_1: entered promiscuous mode [ 449.326451][T11598] netlink: 104 bytes leftover after parsing attributes in process `syz.1.1437'. [ 449.416281][T11601] netlink: 104 bytes leftover after parsing attributes in process `syz.1.1437'. [ 449.553209][T11605] binder: 11603:11605 ioctl c00c6211 0 returned -14 [ 449.786416][T11583] team0: left promiscuous mode [ 449.808156][T11583] team_slave_0: left promiscuous mode [ 449.825065][T11583] team_slave_1: left promiscuous mode [ 450.132779][ T5905] usb 5-1: USB disconnect, device number 8 [ 450.518225][ T5905] usb 5-1: new high-speed USB device number 9 using dummy_hcd [ 450.779121][ T5905] usb 5-1: config 0 has an invalid interface number: 46 but max is 0 [ 450.787309][ T5905] usb 5-1: config 0 has no interface number 0 [ 450.866135][ T5905] usb 5-1: New USB device found, idVendor=04e2, idProduct=1420, bcdDevice=9e.b9 [ 450.914872][ T5905] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 450.958027][ T5905] usb 5-1: Product: syz [ 450.962219][ T5905] usb 5-1: Manufacturer: syz [ 451.014583][ T5905] usb 5-1: SerialNumber: syz [ 451.088871][ T5905] usb 5-1: config 0 descriptor?? [ 451.130960][ T5905] xr_serial 5-1:0.46: More than one union descriptor, skipping ... [ 451.570581][T11657] netlink: 'syz.6.1447': attribute type 13 has an invalid length. [ 452.170983][T11657] A link change request failed with some changes committed already. Interface caif0 may have been left with an inconsistent configuration, please check. [ 452.311380][T11629] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 452.435542][T11629] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 452.669957][T11675] ptrace attach of "./syz-executor exec"[5839] was attempted by "./syz-executor exec"[11675] [ 452.701843][T11675] netlink: 'syz.1.1445': attribute type 21 has an invalid length. [ 452.726493][T11675] netlink: 128 bytes leftover after parsing attributes in process `syz.1.1445'. [ 452.954622][T11675] netlink: 'syz.1.1445': attribute type 4 has an invalid length. [ 452.963040][T11675] netlink: 3 bytes leftover after parsing attributes in process `syz.1.1445'. [ 453.105094][ T5890] usb 5-1: USB disconnect, device number 9 [ 454.087985][ T5890] usb 4-1: new high-speed USB device number 106 using dummy_hcd [ 454.438006][ T9] usb 5-1: new high-speed USB device number 10 using dummy_hcd [ 454.487945][ T5890] usb 4-1: Using ep0 maxpacket: 32 [ 454.503517][ T5890] usb 4-1: New USB device found, idVendor=0ac8, idProduct=0321, bcdDevice=6f.be [ 454.517394][ T5890] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 454.600871][ T5890] usb 4-1: config 0 descriptor?? [ 454.623029][ T9] usb 5-1: config 0 has no interfaces? [ 454.625596][ T5890] gspca_main: vc032x-2.14.0 probing 0ac8:0321 [ 454.698372][ T9] usb 5-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 454.772406][ T9] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 454.816094][ T5890] gspca_vc032x: reg_r err -71 [ 454.821346][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.826647][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.842431][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.851932][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.857917][ T9] usb 5-1: Product: syz [ 454.862122][ T9] usb 5-1: Manufacturer: syz [ 454.892136][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.908096][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.925635][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.952274][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.957590][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.975152][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 454.993879][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.003860][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.009659][ T9] usb 5-1: SerialNumber: syz [ 455.017470][ T9] usb 5-1: config 0 descriptor?? [ 455.028620][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.033943][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.048623][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.060974][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.124625][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.145632][ T5890] gspca_vc032x: I2c Bus Busy Wait 00 [ 455.160650][ T5890] gspca_vc032x: Unknown sensor... [ 455.199966][ T5890] vc032x 4-1:0.0: probe with driver vc032x failed with error -22 [ 455.233489][ T5890] usb 4-1: USB disconnect, device number 106 [ 455.336144][T11710] snd_dummy snd_dummy.0: control 0:0:0:syz0:0 is already present [ 455.616235][T11694] wireguard3: entered promiscuous mode [ 455.636364][T11694] wireguard3: entered allmulticast mode [ 455.807937][ T24] usb 2-1: new full-speed USB device number 104 using dummy_hcd [ 456.094332][ T24] usb 2-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 456.132447][ T24] usb 2-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 10 [ 456.304510][ T24] usb 2-1: New USB device found, idVendor=0525, idProduct=a4a1, bcdDevice= 0.40 [ 456.383287][ T24] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 456.411761][ T24] usb 2-1: Product: syz [ 456.517383][ T24] usb 2-1: Manufacturer: syz [ 456.540582][ T24] usb 2-1: SerialNumber: syz [ 456.677025][ T24] usb 2-1: selecting invalid altsetting 1 [ 457.514142][T11748] xt_TPROXY: Can be used only with -p tcp or -p udp [ 457.572176][T11752] netdevsim netdevsim5 netdevsim0: entered promiscuous mode [ 457.582970][T11752] netdevsim netdevsim5 netdevsim0: entered allmulticast mode [ 458.105858][T11767] netlink: 60 bytes leftover after parsing attributes in process `syz.3.1467'. [ 458.636693][ T5905] usb 5-1: USB disconnect, device number 10 [ 459.379419][T11784] binder: BINDER_SET_CONTEXT_MGR already set [ 459.431351][T11784] binder: 11783:11784 ioctl 4018620d 200000000040 returned -16 [ 459.697898][ T5890] usb 6-1: new full-speed USB device number 110 using dummy_hcd [ 459.704484][T11796] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 459.830470][T11796] binder: 11795:11796 ioctl c0306201 200000000640 returned -22 [ 459.851194][ T5890] usb 6-1: unable to get BOS descriptor or descriptor too short [ 459.863437][ T5890] usb 6-1: not running at top speed; connect to a high speed hub [ 459.891572][ T5890] usb 6-1: config 17 has an invalid interface number: 8 but max is 1 [ 459.925877][T11801] binder: 11795:11801 ioctl c0306201 200000000640 returned -22 [ 459.942637][ T24] cdc_ncm 2-1:1.0: bind() failure [ 459.981510][ T5890] usb 6-1: config 17 has 1 interface, different from the descriptor's value: 2 [ 460.009222][ T24] usb 2-1: USB disconnect, device number 104 [ 460.017582][ T5890] usb 6-1: config 17 has no interface number 0 [ 460.026857][ T5890] usb 6-1: config 17 interface 8 altsetting 6 endpoint 0x3 has an invalid bInterval 0, changing to 4 [ 460.071220][ T5890] usb 6-1: config 17 interface 8 has no altsetting 0 [ 460.094175][ T5890] usb 6-1: New USB device found, idVendor=0763, idProduct=2001, bcdDevice=2c.ff [ 460.113831][ T5890] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 460.136226][ T5890] usb 6-1: Product: syz [ 460.166506][ T5890] usb 6-1: Manufacturer: syz [ 460.187907][ T5890] usb 6-1: SerialNumber: syz [ 460.205037][T11806] loop0: detected capacity change from 0 to 7 [ 460.233440][T11806] Dev loop0: unable to read RDB block 7 [ 460.259854][T11806] loop0: AHDI p1 p3 p4 [ 460.264119][T11806] loop0: partition table partially beyond EOD, truncated [ 460.324710][T11806] loop0: p1 start 975770946 is beyond EOD, truncated [ 460.363293][T11806] loop0: p3 start 6514546 is beyond EOD, truncated [ 460.426071][ T5890] usb 6-1: selecting invalid altsetting 0 [ 460.460399][ T5890] usb 6-1: 8:6 : no UAC_FORMAT_TYPE desc [ 460.476691][ T5890] usb 6-1: selecting invalid altsetting 0 [ 460.499783][T11819] input: syz1 as /devices/virtual/input/input46 [ 460.586851][ T5890] usb 6-1: USB disconnect, device number 110 [ 460.739229][ T6163] udevd[6163]: error opening ATTR{/sys/devices/platform/dummy_hcd.5/usb6/6-1/6-1:17.8/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 460.873648][T11829] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1482'. [ 460.886222][T11829] netlink: 24 bytes leftover after parsing attributes in process `syz.1.1482'. [ 461.038170][ T7012] usb 4-1: new full-speed USB device number 107 using dummy_hcd [ 461.213861][ T7012] usb 4-1: config 1 has an invalid descriptor of length 170, skipping remainder of the config [ 461.235155][ T7012] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 461.274147][ T7012] usb 4-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 461.293410][ T7012] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 461.318289][ T7012] usb 4-1: Product: syz [ 461.350447][ T7012] usb 4-1: Manufacturer: syz [ 461.389128][ T7012] usb 4-1: SerialNumber: syz [ 461.664049][ T7012] usb 4-1: 0:2 : does not exist [ 461.686286][ T7012] usb 4-1: USB disconnect, device number 107 [ 461.774867][ T5890] usb 7-1: new low-speed USB device number 15 using dummy_hcd [ 462.063923][ T6163] udevd[6163]: error opening ATTR{/sys/devices/platform/dummy_hcd.3/usb4/4-1/4-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 462.157952][ T5890] usb 7-1: device descriptor read/64, error -71 [ 462.507891][ T5890] usb 7-1: new low-speed USB device number 16 using dummy_hcd [ 462.660411][ T5890] usb 7-1: device descriptor read/64, error -71 [ 462.768266][ T5890] usb usb7-port1: attempt power cycle [ 462.784034][T11879] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1492'. [ 462.793253][ T5905] usb 6-1: new high-speed USB device number 111 using dummy_hcd [ 462.958606][ T5905] usb 6-1: Using ep0 maxpacket: 8 [ 462.965943][ T5905] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x8D has an invalid bInterval 42, changing to 9 [ 463.018419][ T5905] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 463.061547][ T5905] usb 6-1: config 0 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 0 [ 463.107993][ T5890] usb 7-1: new low-speed USB device number 17 using dummy_hcd [ 463.129156][ T5905] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x8B has invalid maxpacket 12336, setting to 1024 [ 463.145980][ T5890] usb 7-1: device descriptor read/8, error -71 [ 463.194680][ T5905] usb 6-1: config 0 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 1024 [ 463.233530][ T5905] usb 6-1: New USB device found, idVendor=05ac, idProduct=8215, bcdDevice=8f.58 [ 463.262882][ T5905] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 463.305057][ T5905] usb 6-1: config 0 descriptor?? [ 463.321844][T11868] raw-gadget.0 gadget.5: fail, usb_ep_enable returned -22 [ 463.388594][ T5890] usb 7-1: new low-speed USB device number 18 using dummy_hcd [ 463.433115][ T5890] usb 7-1: device descriptor read/8, error -71 [ 463.655513][ T5890] usb usb7-port1: unable to enumerate USB device [ 463.673834][ T5905] usb 6-1: USB disconnect, device number 111 [ 463.683837][ T5844] Bluetooth: hci5: Opcode 0x0c03 failed: -71 [ 465.090809][ T5890] usb 6-1: new high-speed USB device number 112 using dummy_hcd [ 465.300669][ T5890] usb 6-1: too many endpoints for config 0 interface 0 altsetting 0: 196, using maximum allowed: 30 [ 465.336076][ T5890] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 465.356603][ T5890] usb 6-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 196 [ 465.382756][ T5890] usb 6-1: New USB device found, idVendor=04d9, idProduct=a055, bcdDevice= 0.00 [ 465.407713][ T5890] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 465.418444][ T917] usb 2-1: new high-speed USB device number 105 using dummy_hcd [ 465.436305][ T5890] usb 6-1: config 0 descriptor?? [ 465.609608][ T917] usb 2-1: device descriptor read/64, error -71 [ 465.848518][ T917] usb 2-1: new high-speed USB device number 106 using dummy_hcd [ 465.929127][ T5905] usb 7-1: new high-speed USB device number 19 using dummy_hcd [ 465.932119][ T5890] holtek_kbd 0003:04D9:A055.0010: unbalanced delimiter at end of report description [ 465.981697][ T5890] holtek_kbd 0003:04D9:A055.0010: probe with driver holtek_kbd failed with error -22 [ 466.018587][ T917] usb 2-1: device descriptor read/64, error -71 [ 466.118264][ T5905] usb 7-1: Using ep0 maxpacket: 32 [ 466.134558][ T5905] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 466.153790][ T917] usb usb2-port1: attempt power cycle [ 466.162885][ T5905] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 466.174051][ T5905] usb 7-1: New USB device found, idVendor=0403, idProduct=6030, bcdDevice= 0.00 [ 466.182456][T11933] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1497'. [ 466.184925][ T5905] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 466.216526][T11933] netdevsim netdevsim5 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 466.225613][T11933] netdevsim netdevsim5 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 466.234831][T11933] netdevsim netdevsim5 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 466.241116][ T5905] usb 7-1: config 0 descriptor?? [ 466.244064][T11933] netdevsim netdevsim5 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 466.254819][T11948] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 466.291494][T11933] vxlan0: entered promiscuous mode [ 466.341670][ T5890] usb 5-1: new high-speed USB device number 11 using dummy_hcd [ 466.510148][ T5890] usb 5-1: Using ep0 maxpacket: 16 [ 466.519369][ T5890] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 466.533931][ T5890] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 466.538677][ T917] usb 2-1: new high-speed USB device number 107 using dummy_hcd [ 466.552809][ T5890] usb 5-1: New USB device found, idVendor=1b1c, idProduct=1b02, bcdDevice= 0.00 [ 466.565033][ T5890] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 466.598097][ T30] audit: type=1326 audit(1749416726.426:1751): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 466.633972][ T30] audit: type=1326 audit(1749416726.426:1752): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=118 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 466.637913][ T917] usb 2-1: device descriptor read/8, error -71 [ 466.658092][ T5890] usb 5-1: config 0 descriptor?? [ 466.677331][ T30] audit: type=1326 audit(1749416726.426:1753): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 466.740326][ T5905] ft260 0003:0403:6030.0011: unknown main item tag 0x0 [ 466.770185][ T30] audit: type=1326 audit(1749416726.426:1754): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=46 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 466.798428][ T30] audit: type=1326 audit(1749416726.426:1755): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 467.085188][T11944] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 467.094341][ T30] audit: type=1326 audit(1749416726.426:1756): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=272 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 467.119065][T11944] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 467.155704][ T30] audit: type=1326 audit(1749416726.926:1757): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 467.178217][ C1] vkms_vblank_simulate: vblank timer overrun [ 467.196149][ T5905] ft260 0003:0403:6030.0011: failed to retrieve chip version [ 467.205929][ T5905] ft260 0003:0403:6030.0011: probe with driver ft260 failed with error -71 [ 467.215285][ T917] usb 2-1: new high-speed USB device number 108 using dummy_hcd [ 467.277918][ T917] usb 2-1: device descriptor read/8, error -71 [ 467.321576][ T5905] usb 7-1: USB disconnect, device number 19 [ 467.325985][ T30] audit: type=1326 audit(1749416726.926:1758): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11951 comm="syz.3.1508" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7ff5e418e929 code=0x7ffc0000 [ 467.360035][ T5890] corsair 0003:1B1C:1B02.0012: hidraw0: USB HID v0.00 Device [HID 1b1c:1b02] on usb-dummy_hcd.4-1/input0 [ 467.401238][ T917] usb usb2-port1: unable to enumerate USB device [ 467.762239][ T5890] usb 5-1: USB disconnect, device number 11 [ 467.884190][ T7012] usb 6-1: USB disconnect, device number 112 [ 468.558134][ T5905] usb 7-1: new high-speed USB device number 20 using dummy_hcd [ 468.568060][ T5890] usb 6-1: new high-speed USB device number 113 using dummy_hcd [ 468.580155][ T7012] usb 2-1: new high-speed USB device number 109 using dummy_hcd [ 468.768463][ T5890] usb 6-1: device descriptor read/64, error -71 [ 468.794410][ T7012] usb 2-1: New USB device found, idVendor=1604, idProduct=8001, bcdDevice=44.1f [ 468.808520][ T5905] usb 7-1: Using ep0 maxpacket: 32 [ 468.812178][ T7012] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 468.820131][ T5905] usb 7-1: config 1 has an invalid interface number: 242 but max is 0 [ 468.833602][ T7012] usb 2-1: Product: syz [ 468.837945][ T7012] usb 2-1: Manufacturer: syz [ 468.843448][ T7012] usb 2-1: SerialNumber: syz [ 468.858795][ T7012] usb 2-1: config 0 descriptor?? [ 468.864621][ T5905] usb 7-1: config 1 has no interface number 0 [ 468.888682][ T24] usb 5-1: new low-speed USB device number 12 using dummy_hcd [ 468.946023][ T5905] usb 7-1: config 1 interface 242 has no altsetting 0 [ 468.984583][ T5905] usb 7-1: New USB device found, idVendor=2ec8, idProduct=c101, bcdDevice= 7.df [ 469.009253][ T5905] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 469.018048][ T5890] usb 6-1: new high-speed USB device number 114 using dummy_hcd [ 469.032144][ T917] usb 4-1: new high-speed USB device number 108 using dummy_hcd [ 469.058442][ T24] usb 5-1: config index 0 descriptor too short (expected 6427, got 27) [ 469.079629][ T5905] usb 7-1: Product: syz [ 469.092832][ T5905] usb 7-1: Manufacturer: syz [ 469.101659][ T24] usb 5-1: config 0 has an invalid interface number: 21 but max is 0 [ 469.113087][ T5905] usb 7-1: SerialNumber: syz [ 469.118435][ T7012] usb 2-1: USB disconnect, device number 109 [ 469.133400][ T24] usb 5-1: config 0 has no interface number 0 [ 469.163362][ T5890] usb 6-1: device descriptor read/64, error -71 [ 469.177655][ T24] usb 5-1: config 0 interface 21 altsetting 0 has an endpoint descriptor with address 0x61, changing to 0x1 [ 469.228630][ T24] usb 5-1: config 0 interface 21 altsetting 0 endpoint 0x1 is Bulk; changing to Interrupt [ 469.241933][ T24] usb 5-1: config 0 interface 21 altsetting 0 endpoint 0x1 has invalid wMaxPacketSize 0 [ 469.258818][ T24] usb 5-1: New USB device found, idVendor=06cd, idProduct=0202, bcdDevice=92.d4 [ 469.268488][ T24] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 469.279219][ T917] usb 4-1: Using ep0 maxpacket: 16 [ 469.298702][ T24] usb 5-1: config 0 descriptor?? [ 469.319696][ T5890] usb usb6-port1: attempt power cycle [ 469.387243][ T917] usb 4-1: unable to get BOS descriptor or descriptor too short [ 469.466115][ T917] usb 4-1: config 1 has an invalid descriptor of length 255, skipping remainder of the config [ 469.503909][ T917] usb 4-1: config 1 interface 0 altsetting 8 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 469.551412][T11982] fuse: Unknown parameter '0x0000000000000004`}KrB%P3lp`ku"@CbފEҕbjR;m}ݏ<' [ 469.566178][T11982] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 469.576420][T11982] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 469.613933][ T917] usb 4-1: config 1 interface 0 has no altsetting 0 [ 469.646373][ T917] usb 4-1: New USB device found, idVendor=04f3, idProduct=074d, bcdDevice= 0.40 [ 469.682025][ T917] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 469.698155][ T5890] usb 6-1: new high-speed USB device number 115 using dummy_hcd [ 469.717059][ T917] usb 4-1: Product: syz [ 469.729550][ T5890] usb 6-1: device descriptor read/8, error -71 [ 469.732702][ T917] usb 4-1: Manufacturer: syz [ 469.763898][ T917] usb 4-1: SerialNumber: syz [ 470.057903][ T5890] usb 6-1: new high-speed USB device number 116 using dummy_hcd [ 470.078656][ T5890] usb 6-1: device descriptor read/8, error -71 [ 470.188375][ T5890] usb usb6-port1: unable to enumerate USB device [ 471.145872][ T5905] usb 2-1: new high-speed USB device number 110 using dummy_hcd [ 471.330224][ T5918] usb 7-1: USB disconnect, device number 20 [ 471.359511][ T5905] usb 2-1: Using ep0 maxpacket: 32 [ 471.396381][ T5905] usb 2-1: config 0 has an invalid interface number: 51 but max is 0 [ 471.408815][ T5905] usb 2-1: config 0 has no interface number 0 [ 471.446838][ T5905] usb 2-1: New USB device found, idVendor=061d, idProduct=c150, bcdDevice=1f.6f [ 471.578114][ T5905] usb 2-1: New USB device strings: Mfr=42, Product=168, SerialNumber=181 [ 471.622470][ T5905] usb 2-1: Product: syz [ 471.681836][ T5905] usb 2-1: Manufacturer: syz [ 471.698290][ T5905] usb 2-1: SerialNumber: syz [ 471.707630][ T7012] usb 5-1: USB disconnect, device number 12 [ 471.784047][ T5905] usb 2-1: config 0 descriptor?? [ 471.914499][T12035] bridge1: entered promiscuous mode [ 472.586004][ T5905] quatech2 2-1:0.51: Quatech 2nd gen USB to Serial Driver converter detected [ 473.246986][ T917] usbhid 4-1:1.0: couldn't find an input interrupt endpoint [ 473.290412][ T917] usb 4-1: USB disconnect, device number 108 [ 474.348060][ T917] usb 4-1: new high-speed USB device number 109 using dummy_hcd [ 474.510559][ T917] usb 4-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 474.523893][ T917] usb 4-1: config 1 has an invalid descriptor of length 55, skipping remainder of the config [ 474.535312][ T917] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 474.576548][ T917] usb 4-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 55, changing to 9 [ 474.624210][ T917] usb 4-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 8496, setting to 1024 [ 474.680170][ T917] usb 4-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 474.690003][ T917] usb 4-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 474.698074][ T917] usb 4-1: Product: syz [ 474.704463][ T917] usb 4-1: Manufacturer: syz [ 474.732964][ T917] cdc_wdm 4-1:1.0: skipping garbage [ 474.761421][ T917] cdc_wdm 4-1:1.0: skipping garbage [ 474.787410][ T917] cdc_wdm 4-1:1.0: cdc-wdm0: USB WDM device [ 474.818867][ T917] cdc_wdm 4-1:1.0: Unknown control protocol [ 474.956038][ C0] wdm_int_callback: 15 callbacks suppressed [ 474.956056][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 474.968631][ C0] wdm_int_callback: 15 callbacks suppressed [ 474.968644][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 474.981430][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 474.988093][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 474.994568][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 475.001187][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 475.007470][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 475.014093][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 475.020700][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 475.027343][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 475.037924][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 475.044541][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 475.054193][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 475.060802][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 475.067781][ C0] cdc_wdm 4-1:1.0: nonzero urb status received: -71 [ 475.069758][ T7012] usb 4-1: USB disconnect, device number 109 [ 475.074400][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - 0 bytes [ 475.074421][ C0] cdc_wdm 4-1:1.0: wdm_int_callback - usb_submit_urb failed with result -19 [ 475.203834][ T5905] usb 2-1: qt2_attach - failed to power on unit: -71 [ 475.210766][ T5905] quatech2 2-1:0.51: probe with driver quatech2 failed with error -71 [ 475.249444][ T5905] usb 2-1: USB disconnect, device number 110 [ 476.050852][ T7012] usb 2-1: new high-speed USB device number 111 using dummy_hcd [ 476.234543][ T7012] usb 2-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 476.288165][ T7012] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 476.308328][ T5905] usb 4-1: new high-speed USB device number 110 using dummy_hcd [ 476.317883][ T7012] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 476.334224][ T7012] usb 2-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 476.367938][ T7012] usb 2-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 476.377088][ T7012] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 476.401821][ T7012] usb 2-1: config 0 descriptor?? [ 476.407944][ T917] usb 6-1: new high-speed USB device number 117 using dummy_hcd [ 476.475595][T12072] binder: 12071:12072 ioctl c0306201 0 returned -14 [ 476.484609][ T5905] usb 4-1: Using ep0 maxpacket: 8 [ 476.495043][ T5905] usb 4-1: New USB device found, idVendor=0ccd, idProduct=00b3, bcdDevice=2d.ea [ 476.512048][ T5905] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 476.530089][ T5905] usb 4-1: Product: syz [ 476.537973][ T917] usb 6-1: device descriptor read/64, error -71 [ 476.545430][ T5905] usb 4-1: Manufacturer: syz [ 476.558003][ T5905] usb 4-1: SerialNumber: syz [ 476.576946][ T5905] usb 4-1: config 0 descriptor?? [ 476.788319][ T917] usb 6-1: new high-speed USB device number 118 using dummy_hcd [ 476.803007][ T5905] usb 4-1: dvb_usb_v2: found a 'TerraTec NOXON DAB Stick' in warm state [ 476.918219][ T917] usb 6-1: device descriptor read/64, error -71 [ 477.042321][ T917] usb usb6-port1: attempt power cycle [ 477.448269][ T917] usb 6-1: new high-speed USB device number 119 using dummy_hcd [ 477.479286][ T917] usb 6-1: device descriptor read/8, error -71 [ 477.552641][T12093] mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium [ 477.738563][ T917] usb 6-1: new high-speed USB device number 120 using dummy_hcd [ 477.758679][ T917] usb 6-1: device descriptor read/8, error -71 [ 477.826430][ T5905] dvb_usb_rtl28xxu 4-1:0.0: probe with driver dvb_usb_rtl28xxu failed with error -32 [ 477.897742][ T917] usb usb6-port1: unable to enumerate USB device [ 478.281449][T12098] netlink: 96 bytes leftover after parsing attributes in process `syz.4.1537'. [ 478.719117][ T7012] usbhid 2-1:0.0: can't add hid device: -71 [ 478.725247][ T7012] usbhid 2-1:0.0: probe with driver usbhid failed with error -71 [ 478.749475][ T7012] usb 2-1: USB disconnect, device number 111 [ 479.091663][ T7012] usb 4-1: USB disconnect, device number 110 [ 479.738256][ T917] usb 7-1: new high-speed USB device number 21 using dummy_hcd [ 479.899678][ T917] usb 7-1: Using ep0 maxpacket: 16 [ 479.906881][ T917] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 479.918787][ T917] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 479.948535][ T917] usb 7-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 9 [ 480.008345][ T917] usb 7-1: New USB device found, idVendor=0457, idProduct=07da, bcdDevice= 0.00 [ 480.017640][ T917] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 480.038535][ T917] usb 7-1: config 0 descriptor?? [ 480.352957][ T5905] usb 4-1: new high-speed USB device number 111 using dummy_hcd [ 480.449010][ T917] hid (null): unknown global tag 0xc [ 480.459796][ T917] hid (null): unknown global tag 0xd [ 480.465388][T12132] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 480.475871][ T917] hid-multitouch 0003:0457:07DA.0013: unknown main item tag 0x2 [ 480.503128][ T917] hid-multitouch 0003:0457:07DA.0013: unknown global tag 0xc [ 480.507672][T12132] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 480.527433][ T917] hid-multitouch 0003:0457:07DA.0013: item 0 2 1 12 parsing failed [ 480.539025][ T5905] usb 4-1: Using ep0 maxpacket: 32 [ 480.591131][ T5905] usb 4-1: config 0 has an invalid interface number: 85 but max is 0 [ 480.609271][ T917] hid-multitouch 0003:0457:07DA.0013: probe with driver hid-multitouch failed with error -22 [ 480.625790][ T5905] usb 4-1: config 0 has no interface number 0 [ 480.644903][ T5905] usb 4-1: config 0 interface 85 altsetting 7 endpoint 0x82 has an invalid bInterval 0, changing to 7 [ 480.701827][ T917] usb 7-1: USB disconnect, device number 21 [ 480.723622][ T5905] usb 4-1: config 0 interface 85 has no altsetting 0 [ 480.734758][ T5905] usb 4-1: New USB device found, idVendor=05ac, idProduct=0219, bcdDevice=f0.72 [ 480.743721][T12135] netlink: 4 bytes leftover after parsing attributes in process `syz.4.1547'. [ 480.790223][ T5905] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 480.813156][ T5905] usb 4-1: Product: syz [ 480.813178][ T5905] usb 4-1: Manufacturer: syz [ 480.813195][ T5905] usb 4-1: SerialNumber: syz [ 480.833183][ T5905] usb 4-1: config 0 descriptor?? [ 480.881826][T12141] tty tty32: ldisc open failed (-12), clearing slot 31 [ 480.978627][T12148] netlink: 'syz.5.1550': attribute type 5 has an invalid length. [ 481.021804][T12148] ip6erspan0: entered promiscuous mode [ 481.099368][T12156] netlink: 88 bytes leftover after parsing attributes in process `syz.4.1552'. [ 481.319139][T12162] netlink: 28 bytes leftover after parsing attributes in process `syz.6.1554'. [ 481.616288][ T5905] appletouch 4-1:0.85: Geyser mode initialized. [ 481.655698][ T5905] input: appletouch as /devices/platform/dummy_hcd.3/usb4/4-1/4-1:0.85/input/input47 [ 481.747711][ T7012] usb 6-1: new full-speed USB device number 121 using dummy_hcd [ 481.828609][ T5905] usb 4-1: USB disconnect, device number 111 [ 481.876555][ T5905] appletouch 4-1:0.85: input: appletouch disconnected [ 481.942258][ T7012] usb 6-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 481.983846][ T7012] usb 6-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 482.011337][ T7012] usb 6-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 482.023745][ T7012] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 482.037441][ T7012] usb 6-1: Product: syz [ 482.050973][ T7012] usb 6-1: Manufacturer: syz [ 482.061284][ T7012] usb 6-1: SerialNumber: syz [ 482.310583][ T7012] usb 6-1: 0:2 : does not exist [ 482.315772][ T7012] usb 6-1: unit 9 not found! [ 482.346349][ T7012] usb 6-1: 4:0: cannot get min/max values for control 1 (id 4) [ 482.472944][ T7012] usb 6-1: USB disconnect, device number 121 [ 483.298039][ T5905] usb 6-1: new high-speed USB device number 122 using dummy_hcd [ 483.382927][T12197] netlink: 88 bytes leftover after parsing attributes in process `syz.4.1564'. [ 483.458563][ T5905] usb 6-1: Using ep0 maxpacket: 8 [ 483.470743][ T5905] usb 6-1: New USB device found, idVendor=0ccd, idProduct=00b3, bcdDevice=2d.ea [ 483.487916][ T7012] usb 7-1: new high-speed USB device number 22 using dummy_hcd [ 483.491431][ T5905] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 483.582133][ T5905] usb 6-1: Product: syz [ 483.610507][ T5905] usb 6-1: Manufacturer: syz [ 483.628237][ T5905] usb 6-1: SerialNumber: syz [ 483.641106][ T5905] usb 6-1: config 0 descriptor?? [ 483.686118][ T7012] usb 7-1: config 0 has no interfaces? [ 483.784560][ T7012] usb 7-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 483.823896][ T7012] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 483.873153][ T5905] usb 6-1: dvb_usb_v2: found a 'TerraTec NOXON DAB Stick' in warm state [ 483.907617][ T7012] usb 7-1: Product: syz [ 483.938255][ T7012] usb 7-1: Manufacturer: syz [ 483.953899][ T7012] usb 7-1: SerialNumber: syz [ 483.999260][ T7012] usb 7-1: config 0 descriptor?? [ 484.067953][ T5918] usb 2-1: new high-speed USB device number 112 using dummy_hcd [ 484.294668][T12193] Invalid logical block size (-1) [ 484.305496][ T5918] usb 2-1: Using ep0 maxpacket: 8 [ 484.385794][T12209] netlink: 4 bytes leftover after parsing attributes in process `syz.4.1569'. [ 484.399726][T12209] netlink: 4 bytes leftover after parsing attributes in process `syz.4.1569'. [ 484.586570][ T5918] usb 2-1: config 179 has an invalid interface number: 65 but max is 0 [ 484.721831][ T5918] usb 2-1: config 179 has no interface number 0 [ 484.921000][ T5918] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0xF has an invalid bInterval 0, changing to 7 [ 484.957214][ T5918] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0xF has invalid maxpacket 1025, setting to 1024 [ 484.992813][ T5918] usb 2-1: config 179 interface 65 altsetting 0 endpoint 0x83 has invalid wMaxPacketSize 0 [ 485.013137][ T5918] usb 2-1: config 179 interface 65 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 23 [ 485.080080][T12216] binder: BINDER_SET_CONTEXT_MGR already set [ 485.086439][T12216] binder: 12215:12216 ioctl 4018620d 200000000040 returned -16 [ 485.121103][ T5918] usb 2-1: New USB device found, idVendor=12ab, idProduct=90a3, bcdDevice=1e.eb [ 485.166929][ T5918] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 485.211791][T12204] raw-gadget.2 gadget.1: fail, usb_ep_enable returned -22 [ 485.430837][ T5918] usb 2-1: USB disconnect, device number 112 [ 485.775314][T12190] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1562'. [ 485.855056][ T5905] dvb_usb_rtl28xxu 6-1:0.0: probe with driver dvb_usb_rtl28xxu failed with error -71 [ 485.872091][T12225] netlink: 'syz.3.1573': attribute type 2 has an invalid length. [ 485.879848][ T5905] usb 6-1: USB disconnect, device number 122 [ 486.356366][ T5905] usb 7-1: USB disconnect, device number 22 [ 486.428076][ T7012] usb 2-1: new high-speed USB device number 113 using dummy_hcd [ 486.515432][T12233] netlink: 16 bytes leftover after parsing attributes in process `syz.4.1576'. [ 486.619616][ T7012] usb 2-1: device descriptor read/64, error -71 [ 486.787901][ T5918] usb 6-1: new high-speed USB device number 123 using dummy_hcd [ 486.955733][ T5918] usb 6-1: Using ep0 maxpacket: 16 [ 486.963061][ T5918] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 486.975633][ T5918] usb 6-1: New USB device found, idVendor=054c, idProduct=024b, bcdDevice= 0.00 [ 486.978016][ T7012] usb 2-1: new high-speed USB device number 114 using dummy_hcd [ 487.010931][ T5918] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 487.113650][ T5918] usb 6-1: config 0 descriptor?? [ 487.148116][ T7012] usb 2-1: device descriptor read/64, error -71 [ 487.258503][ T7012] usb usb2-port1: attempt power cycle [ 487.530108][ T5918] sony 0003:054C:024B.0014: item fetching failed at offset 2/5 [ 487.538843][ T5918] sony 0003:054C:024B.0014: parse failed [ 487.544708][ T5918] sony 0003:054C:024B.0014: probe with driver sony failed with error -22 [ 487.608118][ T7012] usb 2-1: new high-speed USB device number 115 using dummy_hcd [ 487.639359][ T7012] usb 2-1: device descriptor read/8, error -71 [ 487.732780][ T5897] usb 6-1: USB disconnect, device number 123 [ 487.938235][ T7012] usb 2-1: new high-speed USB device number 116 using dummy_hcd [ 487.958923][ T7012] usb 2-1: device descriptor read/8, error -71 [ 487.992498][T12257] binder: BINDER_SET_CONTEXT_MGR already set [ 487.998646][T12257] binder: 12256:12257 ioctl 4018620d 200000000040 returned -16 [ 488.068362][ T7012] usb usb2-port1: unable to enumerate USB device [ 488.148223][ T5918] usb 5-1: new full-speed USB device number 13 using dummy_hcd [ 488.310029][ T5918] usb 5-1: config 150 has an invalid interface number: 204 but max is 1 [ 488.323417][ T5918] usb 5-1: config 150 has no interface number 0 [ 488.337946][ T5918] usb 5-1: config 150 interface 204 has no altsetting 0 [ 488.345047][ T5918] usb 5-1: config 150 interface 1 has no altsetting 0 [ 488.355172][ T5918] usb 5-1: New USB device found, idVendor=04e2, idProduct=1424, bcdDevice=c7.eb [ 488.364904][ T5918] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 488.373991][ T5918] usb 5-1: Product: syz [ 488.378427][ T5918] usb 5-1: Manufacturer: syz [ 488.384342][ T5918] usb 5-1: SerialNumber: syz [ 488.568307][T11206] Bluetooth: hci4: command 0x0c1a tx timeout [ 488.599773][ T5918] xr_serial 5-1:150.204: xr_serial converter detected [ 488.697908][ T7012] usb 6-1: new high-speed USB device number 124 using dummy_hcd [ 488.870260][ T7012] usb 6-1: config 0 has no interfaces? [ 488.878731][ T7012] usb 6-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 488.889253][ T7012] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 488.897303][ T7012] usb 6-1: Product: syz [ 488.901642][ T7012] usb 6-1: Manufacturer: syz [ 488.906553][ T7012] usb 6-1: SerialNumber: syz [ 488.914948][ T7012] usb 6-1: config 0 descriptor?? [ 488.999262][ T5918] xr_serial ttyUSB0: Failed to set reg 0x0c: -71 [ 489.012998][ T5918] xr_serial ttyUSB0: probe with driver xr_serial failed with error -71 [ 489.041544][ T5918] usb 5-1: USB disconnect, device number 13 [ 489.061686][ T5918] xr_serial 5-1:150.204: device disconnected [ 489.139186][T12263] netlink: 'syz.5.1586': attribute type 1 has an invalid length. [ 489.230920][ T7012] usb 4-1: new high-speed USB device number 112 using dummy_hcd [ 489.410315][ T7012] usb 4-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 489.442343][ T7012] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 489.466003][ T7012] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 489.496905][ T7012] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 489.530743][ T7012] usb 4-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 489.555555][ T7012] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 489.598517][ T7012] usb 4-1: config 0 descriptor?? [ 489.765964][T12274] netlink: 20 bytes leftover after parsing attributes in process `syz.4.1589'. [ 489.794930][T12274] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 489.820634][T12274] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 490.347899][ T5918] usb 7-1: new high-speed USB device number 23 using dummy_hcd [ 490.518414][ T5918] usb 7-1: Using ep0 maxpacket: 8 [ 490.528780][ T5918] usb 7-1: config 0 has no interfaces? [ 490.542341][ T5918] usb 7-1: New USB device found, idVendor=1de1, idProduct=c102, bcdDevice=4d.89 [ 490.565072][ T5918] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 490.592648][ T5918] usb 7-1: config 0 descriptor?? [ 490.814318][T12283] netlink: 28 bytes leftover after parsing attributes in process `syz.6.1592'. [ 490.826838][ T5905] usb 7-1: USB disconnect, device number 23 [ 491.008396][ T5918] usb 5-1: new high-speed USB device number 14 using dummy_hcd [ 491.170367][ T5918] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 491.181910][ T5918] usb 5-1: New USB device found, idVendor=046d, idProduct=c50c, bcdDevice= 0.00 [ 491.191486][ T5918] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 491.202974][ T5918] usb 5-1: config 0 descriptor?? [ 491.447514][ T5905] usb 6-1: USB disconnect, device number 124 [ 491.857909][ T917] usb 7-1: new high-speed USB device number 24 using dummy_hcd [ 491.915107][ T7012] usbhid 4-1:0.0: can't add hid device: -71 [ 491.921461][ T7012] usbhid 4-1:0.0: probe with driver usbhid failed with error -71 [ 491.946012][ T7012] usb 4-1: USB disconnect, device number 112 [ 492.008473][ T917] usb 7-1: Using ep0 maxpacket: 8 [ 492.025188][ T917] usb 7-1: config 179 has an invalid interface number: 65 but max is 0 [ 492.036550][ T917] usb 7-1: config 179 has no interface number 0 [ 492.046083][ T917] usb 7-1: config 179 interface 65 altsetting 12 endpoint 0xF has an invalid bInterval 63, changing to 9 [ 492.062527][ T917] usb 7-1: config 179 interface 65 altsetting 12 endpoint 0xF has invalid maxpacket 57605, setting to 1024 [ 492.074847][ T917] usb 7-1: config 179 interface 65 altsetting 12 endpoint 0x83 has an invalid bInterval 52, changing to 9 [ 492.086999][ T917] usb 7-1: config 179 interface 65 altsetting 12 endpoint 0x83 has invalid maxpacket 8241, setting to 1024 [ 492.099685][ T917] usb 7-1: config 179 interface 65 altsetting 12 has 2 endpoint descriptors, different from the interface descriptor's value: 23 [ 492.113592][ T917] usb 7-1: config 179 interface 65 has no altsetting 0 [ 492.121502][ T917] usb 7-1: New USB device found, idVendor=12ab, idProduct=0004, bcdDevice= 0.00 [ 492.131607][ T917] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 492.191909][ T917] input: Honey Bee Xbox360 dancepad as /devices/platform/dummy_hcd.6/usb7/7-1/7-1:179.65/input/input49 [ 492.269553][ T5189] input input49: unable to receive magic message: -110 [ 492.290684][ T5189] input input49: unable to receive magic message: -32 [ 492.342013][ T5189] input input49: unable to receive magic message: -32 [ 492.405423][ T5189] input input49: unable to receive magic message: -32 [ 492.436398][ T5189] input input49: unable to receive magic message: -32 [ 492.480556][ T5189] input input49: unable to receive magic message: -32 [ 492.675870][ T917] usb 7-1: USB disconnect, device number 24 [ 492.681996][ C0] xpad 7-1:179.65: xpad_irq_out - usb_submit_urb failed with result -19 [ 492.712261][ T917] xpad 7-1:179.65: xpad_try_sending_next_out_packet - usb_submit_urb failed with result -19 [ 492.829112][ T7012] usb 6-1: new full-speed USB device number 125 using dummy_hcd [ 493.000656][ T7012] usb 6-1: config index 0 descriptor too short (expected 9, got 0) [ 493.009132][ T7012] usb 6-1: can't read configurations, error -22 [ 493.337975][ T7012] usb 6-1: new full-speed USB device number 126 using dummy_hcd [ 493.511084][ T7012] usb 6-1: config index 0 descriptor too short (expected 9, got 0) [ 493.524412][ T7012] usb 6-1: can't read configurations, error -22 [ 493.536291][ T7012] usb usb6-port1: attempt power cycle [ 493.647880][ T5890] usb 2-1: new high-speed USB device number 117 using dummy_hcd [ 493.826794][ T5918] usbhid 5-1:0.0: can't add hid device: -71 [ 493.834258][ T5918] usbhid 5-1:0.0: probe with driver usbhid failed with error -71 [ 493.838846][ T5890] usb 2-1: Using ep0 maxpacket: 8 [ 493.887947][ T7012] usb 6-1: new full-speed USB device number 127 using dummy_hcd [ 493.953830][ T5890] usb 2-1: New USB device found, idVendor=0ccd, idProduct=00b3, bcdDevice=2d.ea [ 493.964543][ T5918] usb 5-1: USB disconnect, device number 14 [ 493.978845][ T5890] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 493.993811][ T7012] usb 6-1: config index 0 descriptor too short (expected 9, got 0) [ 494.016683][ T7012] usb 6-1: can't read configurations, error -22 [ 494.027937][ T5890] usb 2-1: Product: syz [ 494.043273][ T5890] usb 2-1: Manufacturer: syz [ 494.057976][ T5890] usb 2-1: SerialNumber: syz [ 494.075685][ T5890] usb 2-1: config 0 descriptor?? [ 494.228555][ T7012] usb 6-1: new full-speed USB device number 2 using dummy_hcd [ 494.316144][ T5890] usb 2-1: dvb_usb_v2: found a 'TerraTec NOXON DAB Stick' in warm state [ 494.371200][ T7012] usb 6-1: config index 0 descriptor too short (expected 9, got 0) [ 494.379397][ T7012] usb 6-1: can't read configurations, error -22 [ 494.386038][ T7012] usb usb6-port1: unable to enumerate USB device [ 494.448355][ T5918] usb 5-1: new high-speed USB device number 15 using dummy_hcd [ 494.498251][ T917] usb 7-1: new high-speed USB device number 25 using dummy_hcd [ 494.654551][ T5918] usb 5-1: Using ep0 maxpacket: 8 [ 494.666195][ T5918] usb 5-1: config 0 has no interfaces? [ 494.672564][ T5918] usb 5-1: New USB device found, idVendor=1de1, idProduct=c102, bcdDevice=4d.89 [ 494.685532][ T5918] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 494.721368][ T917] usb 7-1: Using ep0 maxpacket: 16 [ 494.748424][ T917] usb 7-1: unable to get BOS descriptor or descriptor too short [ 494.773929][ T917] usb 7-1: config 1 has an invalid descriptor of length 255, skipping remainder of the config [ 494.784534][ T917] usb 7-1: config 1 interface 0 altsetting 8 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 494.819698][ T5918] usb 5-1: config 0 descriptor?? [ 494.826797][ T917] usb 7-1: config 1 interface 0 has no altsetting 0 [ 494.864670][ T917] usb 7-1: New USB device found, idVendor=04f3, idProduct=074d, bcdDevice= 0.40 [ 494.875300][ T917] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 494.887100][ T917] usb 7-1: Product: syz [ 494.961228][ T917] usb 7-1: Manufacturer: syz [ 494.992962][ T917] usb 7-1: SerialNumber: syz [ 495.059480][T12328] netlink: 28 bytes leftover after parsing attributes in process `syz.4.1604'. [ 495.074480][ T5918] usb 5-1: USB disconnect, device number 15 [ 495.370071][T12332] (unnamed net_device) (uninitialized): peer notification delay (1164) is not a multiple of miimon (100), value rounded to 1100 ms [ 495.395502][ T7012] IPVS: starting estimator thread 0... [ 495.513457][T12332] bond1: entered promiscuous mode [ 495.518888][T12332] bond1: entered allmulticast mode [ 495.525956][T12332] 8021q: adding VLAN 0 to HW filter on device bond1 [ 495.596138][T12321] netlink: 40 bytes leftover after parsing attributes in process `syz.1.1603'. [ 495.647988][T12333] IPVS: using max 27 ests per chain, 64800 per kthread [ 495.786661][ T5890] dvb_usb_rtl28xxu 2-1:0.0: probe with driver dvb_usb_rtl28xxu failed with error -71 [ 495.833751][ T5890] usb 2-1: USB disconnect, device number 117 [ 495.855022][T12337] netlink: 'syz.5.1606': attribute type 15 has an invalid length. [ 495.876506][T12337] netlink: 24 bytes leftover after parsing attributes in process `syz.5.1606'. [ 496.108043][T12343] netlink: 268 bytes leftover after parsing attributes in process `syz.5.1608'. [ 496.127475][T12343] unsupported nla_type 65024 [ 496.136684][T12343] netlink: 16 bytes leftover after parsing attributes in process `syz.5.1608'. [ 496.151094][T12343] 8021q: VLANs not supported on gre0 [ 497.238329][ T5918] usb 5-1: new high-speed USB device number 16 using dummy_hcd [ 497.248784][ T917] usbhid 7-1:1.0: couldn't find an input interrupt endpoint [ 497.386492][ T917] usb 7-1: USB disconnect, device number 25 [ 497.499589][ T5918] usb 5-1: Using ep0 maxpacket: 32 [ 497.506974][T12360] netlink: 180 bytes leftover after parsing attributes in process `syz.3.1614'. [ 497.527987][ T5890] usb 6-1: new high-speed USB device number 3 using dummy_hcd [ 497.555129][ T5918] usb 5-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xFF, changing to 0x8F [ 497.617941][ T5918] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x8F has an invalid bInterval 255, changing to 11 [ 497.657885][ T5905] usb 2-1: new high-speed USB device number 118 using dummy_hcd [ 497.682487][ T5890] usb 6-1: config 3 has an invalid interface number: 192 but max is 3 [ 497.691907][ T5890] usb 6-1: config 3 has an invalid interface number: 97 but max is 3 [ 497.734401][ T5918] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x8F has invalid maxpacket 59391, setting to 1024 [ 497.758206][ T5918] usb 5-1: New USB device found, idVendor=046d, idProduct=c314, bcdDevice= 0.40 [ 497.768965][ T5890] usb 6-1: config 3 has an invalid interface number: 53 but max is 3 [ 497.774156][ T5918] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 497.787750][ T5890] usb 6-1: config 3 has an invalid interface number: 184 but max is 3 [ 497.788851][ T5918] usb 5-1: config 0 descriptor?? [ 497.796212][ T5890] usb 6-1: config 3 has an invalid interface number: 23 but max is 3 [ 497.796240][ T5890] usb 6-1: config 3 has 5 interfaces, different from the descriptor's value: 4 [ 497.796264][ T5890] usb 6-1: config 3 has no interface number 0 [ 497.825191][ T7012] usb 4-1: new high-speed USB device number 113 using dummy_hcd [ 497.826227][T12346] raw-gadget.0 gadget.4: fail, usb_ep_enable returned -22 [ 497.845397][ T5890] usb 6-1: config 3 has no interface number 1 [ 497.859027][ T5890] usb 6-1: config 3 has no interface number 2 [ 497.859252][ T917] usb 7-1: new high-speed USB device number 26 using dummy_hcd [ 497.865128][ T5890] usb 6-1: config 3 has no interface number 3 [ 497.865153][ T5890] usb 6-1: config 3 has no interface number 4 [ 497.885969][ T5890] usb 6-1: config 3 interface 192 altsetting 4 has an invalid descriptor for endpoint zero, skipping [ 497.896805][ T5918] hub 5-1:0.0: USB hub found [ 497.910736][ T5890] usb 6-1: config 3 interface 192 altsetting 4 endpoint 0x1 has an invalid bInterval 0, changing to 7 [ 497.917464][ T5905] usb 2-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 497.923405][ T5890] usb 6-1: config 3 interface 192 altsetting 4 endpoint 0xF has invalid wMaxPacketSize 0 [ 497.944132][ T5890] usb 6-1: config 3 interface 192 altsetting 4 endpoint 0x5 has invalid maxpacket 512, setting to 64 [ 497.948044][ T5905] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 497.956111][ T5890] usb 6-1: config 3 interface 192 altsetting 4 endpoint 0x7 has an invalid bInterval 129, changing to 7 [ 497.987185][ T5905] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 497.987616][ T5890] usb 6-1: config 3 interface 192 altsetting 4 has a duplicate endpoint with address 0x4, skipping [ 498.007672][ T5905] usb 2-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 498.007751][ T5905] usb 2-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 498.007903][ T5905] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 498.044133][ T7012] usb 4-1: Using ep0 maxpacket: 16 [ 498.050691][ T5890] usb 6-1: config 3 interface 192 altsetting 4 has a duplicate endpoint with address 0x1, skipping [ 498.051732][ T5905] usb 2-1: config 0 descriptor?? [ 498.076726][ T5890] usb 6-1: config 3 interface 192 altsetting 4 has an invalid descriptor for endpoint zero, skipping [ 498.094513][ T917] usb 7-1: config 0 has an invalid interface number: 64 but max is 0 [ 498.099572][ T7012] usb 4-1: New USB device found, idVendor=17ef, idProduct=721e, bcdDevice=de.06 [ 498.117949][ T7012] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 498.139212][ T7012] usb 4-1: Product: syz [ 498.143448][ T7012] usb 4-1: Manufacturer: syz [ 498.158004][ T917] usb 7-1: config 0 has no interface number 0 [ 498.158683][ T7012] usb 4-1: SerialNumber: syz [ 498.169254][ T5890] usb 6-1: config 3 interface 192 altsetting 4 has a duplicate endpoint with address 0x2, skipping [ 498.186754][ T917] usb 7-1: New USB device found, idVendor=046d, idProduct=0823, bcdDevice= 0.07 [ 498.188635][ T5890] usb 6-1: config 3 interface 192 altsetting 4 has a duplicate endpoint with address 0xF, skipping [ 498.216523][ T917] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 498.227234][ T7012] r8152-cfgselector 4-1: Unknown version 0x0000 [ 498.234859][ T7012] r8152-cfgselector 4-1: config 0 descriptor?? [ 498.245479][ T917] usb 7-1: Product: syz [ 498.245710][ T5918] hub 5-1:0.0: 10 ports detected [ 498.245778][ T5890] usb 6-1: config 3 interface 97 altsetting 13 has a duplicate endpoint with address 0xA, skipping [ 498.263263][ T5890] usb 6-1: config 3 interface 97 altsetting 13 has a duplicate endpoint with address 0x8, skipping [ 498.266305][ T5918] hub 5-1:0.0: insufficient power available to use all downstream ports [ 498.282198][ T5890] usb 6-1: config 3 interface 97 altsetting 13 has an invalid descriptor for endpoint zero, skipping [ 498.297001][ T5890] usb 6-1: config 3 interface 97 altsetting 13 has a duplicate endpoint with address 0x9, skipping [ 498.305504][ T917] usb 7-1: Manufacturer: syz [ 498.313082][ T917] usb 7-1: SerialNumber: syz [ 498.322872][ T917] usb 7-1: config 0 descriptor?? [ 498.334215][ T5890] usb 6-1: config 3 interface 53 altsetting 29 endpoint 0xD has invalid maxpacket 1023, setting to 64 [ 498.351565][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0xE, skipping [ 498.364665][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0xE, skipping [ 498.380601][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x2, skipping [ 498.393572][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0xC, skipping [ 498.407199][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x1, skipping [ 498.423230][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x7, skipping [ 498.450551][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x2, skipping [ 498.465697][ T5890] usb 6-1: config 3 interface 53 altsetting 29 endpoint 0x3 has invalid maxpacket 512, setting to 64 [ 498.480644][ T7012] r8152-cfgselector 4-1: Unknown version 0x08a0 [ 498.488931][ T7012] r8152-cfgselector 4-1: bad CDC descriptors [ 498.495021][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x8, skipping [ 498.520628][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x3, skipping [ 498.547733][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has a duplicate endpoint with address 0x1, skipping [ 498.567073][ T5890] usb 6-1: config 3 interface 53 altsetting 29 has 13 endpoint descriptors, different from the interface descriptor's value: 15 [ 498.585292][ T5890] usb 6-1: config 3 interface 184 altsetting 206 has an invalid descriptor for endpoint zero, skipping [ 498.603101][ T5890] usb 6-1: config 3 interface 184 altsetting 206 endpoint 0xB has invalid maxpacket 1023, setting to 64 [ 498.615093][ T5890] usb 6-1: config 3 interface 184 altsetting 206 has 2 endpoint descriptors, different from the interface descriptor's value: 16 [ 498.632023][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0xC, skipping [ 498.646860][T12358] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 498.656983][T12358] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 498.680533][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0xC, skipping [ 498.700540][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0xC, skipping [ 498.703433][ T9] r8152-cfgselector 4-1: USB disconnect, device number 113 [ 498.733249][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0xA, skipping [ 498.748821][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0xF, skipping [ 498.854981][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x7, skipping [ 498.870480][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x8, skipping [ 498.873022][ T917] usb 7-1: Found UVC 0.08 device syz (046d:0823) [ 498.883538][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x8, skipping [ 498.904913][ T917] usb 7-1: No valid video chain found. [ 498.917581][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x8, skipping [ 498.929282][ T917] usb 7-1: USB disconnect, device number 26 [ 498.937449][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x3, skipping [ 498.965885][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x7, skipping [ 498.984252][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has an invalid descriptor for endpoint zero, skipping [ 498.996357][ T5890] usb 6-1: config 3 interface 23 altsetting 7 has a duplicate endpoint with address 0x2, skipping [ 499.015330][ T5890] usb 6-1: config 3 interface 192 has no altsetting 0 [ 499.025402][ T5890] usb 6-1: config 3 interface 97 has no altsetting 0 [ 499.033465][ T5890] usb 6-1: config 3 interface 53 has no altsetting 0 [ 499.040526][ T5890] usb 6-1: config 3 interface 184 has no altsetting 0 [ 499.047734][ T5890] usb 6-1: config 3 interface 23 has no altsetting 0 [ 499.059787][ T5890] usb 6-1: Dual-Role OTG device on HNP port [ 499.066059][ T5890] usb 6-1: New USB device found, idVendor=0eb1, idProduct=7007, bcdDevice= 2.02 [ 499.075502][ T5890] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 499.087061][ T5890] usb 6-1: Product: syz [ 499.091403][ T5890] usb 6-1: Manufacturer: syz [ 499.096126][ T5890] usb 6-1: SerialNumber: syz [ 499.332883][ T5890] go7007 6-1:3.192: Direct firmware load for go7007/go7007fw.bin failed with error -2 [ 499.343150][ T5890] go7007 6-1:3.192: Falling back to sysfs fallback for: go7007/go7007fw.bin [ 499.386699][ T5918] hub 5-1:0.0: hub_hub_status failed (err = -32) [ 499.397229][ T5918] hub 5-1:0.0: config failed, can't get hub status (err -32) [ 499.426481][ T5918] usbhid 5-1:0.0: can't add hid device: -32 [ 499.436876][ T5918] usbhid 5-1:0.0: probe with driver usbhid failed with error -32 [ 499.461839][T12368] gretap0: entered promiscuous mode [ 499.497334][T12368] netlink: 31 bytes leftover after parsing attributes in process `syz.6.1616'. [ 499.538054][ T917] usb 4-1: new high-speed USB device number 114 using dummy_hcd [ 499.602177][T12371] openvswitch: netlink: IP tunnel dst address not specified [ 499.628576][ T7012] usb 5-1: USB disconnect, device number 16 [ 499.711145][ T917] usb 4-1: config 1 has an invalid descriptor of length 251, skipping remainder of the config [ 499.722501][ T917] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 499.739831][ T917] usb 4-1: New USB device found, idVendor=08b7, idProduct=0000, bcdDevice= 0.00 [ 499.769084][ T917] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=3 [ 499.786277][ T917] usb 4-1: SerialNumber: syz [ 500.000108][T12366] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 500.027028][T12366] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 500.051061][T12366] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 500.074892][T12366] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 500.083233][ T5918] usb 5-1: new high-speed USB device number 17 using dummy_hcd [ 500.120748][T12366] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 500.143588][T12366] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 500.169203][T12366] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 500.189261][ T5905] usbhid 2-1:0.0: can't add hid device: -71 [ 500.195357][ T5905] usbhid 2-1:0.0: probe with driver usbhid failed with error -71 [ 500.218616][T12366] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 500.243823][ T5905] usb 2-1: USB disconnect, device number 118 [ 500.270691][T12366] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 500.279636][ T5918] usb 5-1: Using ep0 maxpacket: 16 [ 500.307553][ T5918] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 500.308551][T12366] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 500.323816][ T5918] usb 5-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 2 [ 500.376547][ T5918] usb 5-1: New USB device found, idVendor=1781, idProduct=0898, bcdDevice= 0.00 [ 500.386353][ T5918] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 500.422415][ T917] usb 4-1: 0:2 : does not exist [ 500.435050][ T917] usb 4-1: unit 5: unexpected type 0x03 [ 500.442645][ T5918] usb 5-1: config 0 descriptor?? [ 500.457703][ T5918] input: PXRC Flight Controller Adapter as /devices/platform/dummy_hcd.4/usb5/5-1/5-1:0.0/input/input51 [ 500.488167][ T917] usb 4-1: USB disconnect, device number 114 [ 500.615358][ T6164] udevd[6164]: error opening ATTR{/sys/devices/platform/dummy_hcd.3/usb4/4-1/4-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 500.702940][ T5918] usb 5-1: USB disconnect, device number 17 [ 500.712022][ T5189] pxrc 5-1:0.0: pxrc_open - usb_submit_urb failed, error: -19 [ 500.760877][T12390] netlink: 60 bytes leftover after parsing attributes in process `syz.6.1622'. [ 501.298385][ T1305] ieee802154 phy0 wpan0: encryption failed: -22 [ 501.305114][ T1305] ieee802154 phy1 wpan1: encryption failed: -22 [ 501.320707][ T5918] usb 4-1: new high-speed USB device number 115 using dummy_hcd [ 501.421596][T12398] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1624'. [ 501.520925][T12400] IPVS: sync thread started: state = BACKUP, mcast_ifn = lo, syncid = 5, id = 0 [ 501.609441][ T5918] usb 4-1: Using ep0 maxpacket: 16 [ 501.623709][ T5918] usb 4-1: config 1 has an invalid descriptor of length 97, skipping remainder of the config [ 501.636837][ T5918] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 502.077541][ T5918] usb 4-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 502.099932][ T5918] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 502.108721][ T5918] usb 4-1: Product: syz [ 502.114257][ T5918] usb 4-1: Manufacturer: syz [ 502.127882][ T7012] usb 5-1: new high-speed USB device number 18 using dummy_hcd [ 502.197351][ T5918] usb 4-1: SerialNumber: syz [ 502.310077][ T7012] usb 5-1: Using ep0 maxpacket: 16 [ 502.360607][ T7012] usb 5-1: unable to get BOS descriptor or descriptor too short [ 502.443518][ T7012] usb 5-1: config 1 has an invalid descriptor of length 255, skipping remainder of the config [ 502.470313][ T5918] usb 4-1: 0:2 : does not exist [ 502.496013][ T5918] usb 4-1: 5:0: failed to get current value for ch 0 (-22) [ 502.522531][ T7012] usb 5-1: config 1 interface 0 altsetting 8 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 502.594511][ T7012] usb 5-1: config 1 interface 0 has no altsetting 0 [ 502.611864][ T5918] usb 4-1: USB disconnect, device number 115 [ 502.782132][ T6164] udevd[6164]: error opening ATTR{/sys/devices/platform/dummy_hcd.3/usb4/4-1/4-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 502.843118][ T7012] usb 5-1: New USB device found, idVendor=04f3, idProduct=074d, bcdDevice= 0.40 [ 502.858465][ T7012] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 502.899263][ T7012] usb 5-1: Product: syz [ 502.903479][ T7012] usb 5-1: Manufacturer: syz [ 502.968616][ T7012] usb 5-1: SerialNumber: syz [ 503.133424][T12416] netlink: 20 bytes leftover after parsing attributes in process `syz.5.1628'. [ 503.243634][T12418] x_tables: ip_tables: udp match: only valid for protocol 17 [ 503.550441][ T5918] usb 2-1: new high-speed USB device number 119 using dummy_hcd [ 503.718305][ T5918] usb 2-1: Using ep0 maxpacket: 16 [ 503.727724][ T5918] usb 2-1: config 0 has an invalid interface number: 105 but max is 0 [ 503.746097][ T5918] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 503.792765][ T5918] usb 2-1: config 0 has no interface number 0 [ 503.814327][ T5918] usb 2-1: New USB device found, idVendor=046d, idProduct=08d3, bcdDevice= b.28 [ 503.833433][ T5918] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 503.859461][ T5918] usb 2-1: Product: syz [ 503.884514][ T5918] usb 2-1: Manufacturer: syz [ 503.913415][ T5918] usb 2-1: SerialNumber: syz [ 504.203040][ T5918] usb 2-1: config 0 descriptor?? [ 504.457218][ T5918] usb 2-1: USB disconnect, device number 119 [ 504.468039][ T24] usb 4-1: new high-speed USB device number 116 using dummy_hcd [ 504.815679][ T24] usb 4-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 504.846930][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 504.879723][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 504.928569][ T24] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 504.978215][ T24] usb 4-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 505.028736][ T24] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 505.059169][ T24] usb 4-1: config 0 descriptor?? [ 505.264689][ T7012] usbhid 5-1:1.0: couldn't find an input interrupt endpoint [ 505.348093][ T7012] usb 5-1: USB disconnect, device number 18 [ 505.587894][ T5918] usb 7-1: new high-speed USB device number 27 using dummy_hcd [ 505.803977][T12451] netlink: 12 bytes leftover after parsing attributes in process `syz.4.1637'. [ 505.825318][T12451] bridge_slave_1: left allmulticast mode [ 505.831066][ T5918] usb 7-1: Using ep0 maxpacket: 16 [ 505.833472][ T5918] usb 7-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 505.846834][T12451] bridge_slave_1: left promiscuous mode [ 505.870737][T12451] bridge0: port 2(bridge_slave_1) entered disabled state [ 505.934853][T12451] bridge_slave_0: left allmulticast mode [ 505.942009][T12451] bridge_slave_0: left promiscuous mode [ 505.959826][T12451] bridge0: port 1(bridge_slave_0) entered disabled state [ 506.040736][ T5918] usb 7-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 506.134960][T12451] team0: Port device bridge0 removed [ 506.249517][ T5918] usb 7-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 506.260040][ T5918] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 506.271204][ T5918] usb 7-1: Product: syz [ 506.277726][ T5918] usb 7-1: Manufacturer: syz [ 506.285385][ T5918] usb 7-1: SerialNumber: syz [ 506.438543][ T7012] usb 2-1: new low-speed USB device number 120 using dummy_hcd [ 506.568099][ T7012] usb 2-1: device descriptor read/64, error -71 [ 506.705877][ T5918] usb 7-1: skipping empty audio interface (v1) [ 506.761914][ T5918] snd-usb-audio 7-1:1.0: probe with driver snd-usb-audio failed with error -22 [ 506.803796][ T5918] usb 7-1: USB disconnect, device number 27 [ 506.807937][ T7012] usb 2-1: new low-speed USB device number 121 using dummy_hcd [ 506.887319][ T6164] udevd[6164]: error opening ATTR{/sys/devices/platform/dummy_hcd.6/usb7/7-1/7-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 506.998373][ T7012] usb 2-1: device descriptor read/64, error -71 [ 507.120320][ T7012] usb usb2-port1: attempt power cycle [ 507.457929][ T7012] usb 2-1: new low-speed USB device number 122 using dummy_hcd [ 507.489661][ T7012] usb 2-1: device descriptor read/8, error -71 [ 507.512884][ T24] usbhid 4-1:0.0: can't add hid device: -71 [ 507.525111][ T24] usbhid 4-1:0.0: probe with driver usbhid failed with error -71 [ 507.550086][ T24] usb 4-1: USB disconnect, device number 116 [ 507.727924][ T7012] usb 2-1: new low-speed USB device number 123 using dummy_hcd [ 507.788266][ T7012] usb 2-1: device descriptor read/8, error -71 [ 507.912850][ T7012] usb usb2-port1: unable to enumerate USB device [ 508.237889][ T7012] usb 4-1: new high-speed USB device number 117 using dummy_hcd [ 508.400833][ T7012] usb 4-1: config 0 interface 0 altsetting 253 endpoint 0x81 has an invalid bInterval 36, changing to 9 [ 508.436053][ T7012] usb 4-1: config 0 interface 0 altsetting 253 endpoint 0x81 has invalid wMaxPacketSize 0 [ 508.446494][ T7012] usb 4-1: config 0 interface 0 has no altsetting 0 [ 508.453450][ T7012] usb 4-1: New USB device found, idVendor=0810, idProduct=0002, bcdDevice= 0.00 [ 508.462765][ T7012] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 508.481418][ T7012] usb 4-1: config 0 descriptor?? [ 508.959381][ T7012] pantherlord 0003:0810:0002.0015: unknown main item tag 0x0 [ 508.970254][ T7012] pantherlord 0003:0810:0002.0015: item fetching failed at offset 6/7 [ 508.981186][ T7012] pantherlord 0003:0810:0002.0015: parse failed [ 508.990140][ T7012] pantherlord 0003:0810:0002.0015: probe with driver pantherlord failed with error -22 [ 509.130368][ T5937] usb 4-1: USB disconnect, device number 117 [ 509.284011][T12476] xfrm1: entered allmulticast mode [ 509.704105][T12481] vivid-007: disconnect [ 509.714518][T12480] vivid-007: reconnect [ 509.995495][ T5937] usb 7-1: new high-speed USB device number 28 using dummy_hcd [ 510.023816][T12492] syzkaller1: entered promiscuous mode [ 510.029526][T12492] syzkaller1: entered allmulticast mode [ 510.159906][ T5937] usb 7-1: config 0 has an invalid interface number: 1 but max is 0 [ 510.178010][ T5937] usb 7-1: config 0 has no interface number 0 [ 510.188259][ T5937] usb 7-1: New USB device found, idVendor=18b4, idProduct=fffb, bcdDevice=dc.7b [ 510.215297][ T5937] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 510.264006][ T5937] usb 7-1: Product: syz [ 510.278534][ T5937] usb 7-1: Manufacturer: syz [ 510.288278][ T5937] usb 7-1: SerialNumber: syz [ 510.303868][ T5937] usb 7-1: config 0 descriptor?? [ 510.340379][ T30] audit: type=1326 audit(1749416770.176:1759): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12504 comm="syz.3.1653" exe="/root/syz-executor" sig=31 arch=c000003e syscall=317 compat=0 ip=0x7ff5e418e929 code=0x0 [ 510.348512][T12507] netdevsim netdevsim3 netdevsim3: entered allmulticast mode [ 510.434503][ T7012] usb 5-1: new high-speed USB device number 19 using dummy_hcd [ 510.512471][T12483] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 510.535800][T12483] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 510.576470][T12483] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 510.591440][T12483] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 510.613819][T12483] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 510.650269][ T5919] usb 2-1: new high-speed USB device number 124 using dummy_hcd [ 510.672974][T12483] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 510.709607][T12483] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 510.728974][T12483] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 510.751609][ T7012] usb 5-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 510.772764][T12483] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 510.783835][ T7012] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 510.805479][T12483] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 510.825256][ T7012] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 510.835688][ T5919] usb 2-1: Using ep0 maxpacket: 16 [ 510.841152][ T24] usb 4-1: new high-speed USB device number 118 using dummy_hcd [ 510.868368][ T5919] usb 2-1: unable to get BOS descriptor or descriptor too short [ 510.878284][ T5919] usb 2-1: config 1 has an invalid descriptor of length 255, skipping remainder of the config [ 510.898169][ T5919] usb 2-1: config 1 interface 0 altsetting 8 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 510.914658][ T7012] usb 5-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 510.934019][ T5919] usb 2-1: config 1 interface 0 has no altsetting 0 [ 510.936206][ T5937] usb 7-1: dvb_usb_v2: found a 'E3C EC168 reference design' in warm state [ 510.945616][ T7012] usb 5-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 510.958970][ T7012] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 510.970168][ T5919] usb 2-1: New USB device found, idVendor=04f3, idProduct=074d, bcdDevice= 0.40 [ 510.988005][ T5919] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 510.998831][ T5919] usb 2-1: Product: syz [ 511.006227][ T5919] usb 2-1: Manufacturer: syz [ 511.020264][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 511.032435][ T7012] usb 5-1: config 0 descriptor?? [ 511.046531][ T24] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 511.068115][ T5919] usb 2-1: SerialNumber: syz [ 511.071011][ T5937] usb 7-1: dvb_usb_v2: will pass the complete MPEG2 transport stream to the software demuxer [ 511.117373][ T24] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 2 [ 511.152833][ T5937] dvbdev: DVB: registering new adapter (E3C EC168 reference design) [ 511.184360][ T5937] usb 7-1: media controller created [ 511.230392][ T24] usb 4-1: New USB device found, idVendor=0079, idProduct=0011, bcdDevice= 0.00 [ 511.238992][ T5937] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 511.313861][ T24] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 511.364530][ T5937] i2c i2c-1: ec100: i2c rd failed=-71 reg=33 [ 511.368494][ T24] usb 4-1: config 0 descriptor?? [ 511.465591][ T5937] usb 7-1: USB disconnect, device number 28 [ 511.808530][ T5937] usb 7-1: new high-speed USB device number 29 using dummy_hcd [ 512.291132][ T24] dragonrise 0003:0079:0011.0016: unknown main item tag 0x1 [ 512.325264][ T24] dragonrise 0003:0079:0011.0016: reserved main item tag 0xe [ 512.369451][ T24] dragonrise 0003:0079:0011.0016: hidraw0: USB HID v0.00 Device [HID 0079:0011] on usb-dummy_hcd.3-1/input0 [ 512.425687][ T5937] usb 7-1: Using ep0 maxpacket: 32 [ 512.442757][ T5937] usb 7-1: config index 0 descriptor too short (expected 29220, got 36) [ 512.496103][ T5937] usb 7-1: config 0 has too many interfaces: 81, using maximum allowed: 32 [ 512.515875][ T5918] usb 4-1: USB disconnect, device number 118 [ 512.650516][ T5937] usb 7-1: config 0 has 1 interface, different from the descriptor's value: 81 [ 512.676009][ T5937] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x1 has invalid wMaxPacketSize 0 [ 512.690448][T12524] fido_id[12524]: Failed to open report descriptor at '/sys/devices/platform/dummy_hcd.3/usb4/report_descriptor': No such file or directory [ 512.705679][ T5937] usb 7-1: config 0 interface 0 altsetting 0 bulk endpoint 0x1 has invalid maxpacket 0 [ 512.715631][ T5937] usb 7-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 18 [ 512.749950][ T5937] usb 7-1: New USB device found, idVendor=03f0, idProduct=6c17, bcdDevice= 0.40 [ 512.763458][ T5937] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 512.794758][ T5937] usb 7-1: config 0 descriptor?? [ 513.017268][ T5937] usblp 7-1:0.0: usblp0: USB Bidirectional printer dev 29 if 0 alt 0 proto 3 vid 0x03F0 pid 0x6C17 [ 513.097314][ T5937] usb 7-1: USB disconnect, device number 29 [ 513.141858][ T5937] usblp0: removed [ 513.468388][ T7012] usbhid 5-1:0.0: can't add hid device: -71 [ 513.484364][ T7012] usbhid 5-1:0.0: probe with driver usbhid failed with error -71 [ 513.525282][ T7012] usb 5-1: USB disconnect, device number 19 [ 513.698435][ T5937] usb 7-1: new high-speed USB device number 30 using dummy_hcd [ 513.714940][ T5919] usbhid 2-1:1.0: couldn't find an input interrupt endpoint [ 513.736749][ T5919] usb 2-1: USB disconnect, device number 124 [ 513.758188][ T5918] usb 4-1: new high-speed USB device number 119 using dummy_hcd [ 513.917464][T12528] syz.1.1659(12528): Attempt to set a LOCK_MAND lock via flock(2). This support has been removed and the request ignored. [ 513.938642][ T5918] usb 4-1: Using ep0 maxpacket: 8 [ 513.947950][ T5937] usb 7-1: device descriptor read/64, error -71 [ 513.955612][ T5918] usb 4-1: config 2 has an invalid interface number: 157 but max is 1 [ 513.980572][ T5918] usb 4-1: config 2 has an invalid interface number: 193 but max is 1 [ 513.993013][ T5918] usb 4-1: config 2 has no interface number 0 [ 514.001496][ T5918] usb 4-1: config 2 has no interface number 1 [ 514.007677][ T5918] usb 4-1: config 2 interface 193 altsetting 3 endpoint 0x2 has an invalid bInterval 150, changing to 7 [ 514.023682][ T5918] usb 4-1: config 2 interface 193 altsetting 3 endpoint 0xE has invalid maxpacket 1023, setting to 64 [ 514.035254][ T5918] usb 4-1: config 2 interface 193 altsetting 3 endpoint 0xA has invalid maxpacket 512, setting to 64 [ 514.070824][ T5918] usb 4-1: config 2 interface 193 altsetting 3 has a duplicate endpoint with address 0xA, skipping [ 514.095186][ T5918] usb 4-1: config 2 interface 193 altsetting 3 has an invalid descriptor for endpoint zero, skipping [ 514.117220][ T5918] usb 4-1: config 2 interface 157 has no altsetting 0 [ 514.126821][ T5918] usb 4-1: config 2 interface 193 has no altsetting 0 [ 514.137745][T12530] netlink: 'syz.4.1661': attribute type 1 has an invalid length. [ 514.139636][ T5918] usb 4-1: New USB device found, idVendor=12d1, idProduct=14f0, bcdDevice=4f.2b [ 514.160986][ T5918] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 514.161012][ T5918] usb 4-1: Product: syz [ 514.161029][ T5918] usb 4-1: Manufacturer: syz [ 514.161046][ T5918] usb 4-1: SerialNumber: syz [ 514.228418][ T5937] usb 7-1: new high-speed USB device number 31 using dummy_hcd [ 514.374953][ T5918] usb 4-1: unknown number of interfaces: 2 [ 514.387930][ T5919] usb 2-1: new low-speed USB device number 125 using dummy_hcd [ 514.400014][ T5918] usb 4-1: USB disconnect, device number 119 [ 514.498076][ T5905] usb 5-1: new full-speed USB device number 20 using dummy_hcd [ 514.553614][ T5919] usb 2-1: config 1 interface 0 altsetting 81 endpoint 0x81 has invalid maxpacket 32, setting to 8 [ 514.564617][ T5919] usb 2-1: config 1 interface 0 altsetting 81 endpoint 0x82 is Bulk; changing to Interrupt [ 514.575094][ T5919] usb 2-1: config 1 interface 0 altsetting 81 has 3 endpoint descriptors, different from the interface descriptor's value: 2 [ 514.588629][ T5919] usb 2-1: config 1 interface 0 has no altsetting 0 [ 514.597635][ T5919] usb 2-1: New USB device found, idVendor=0525, idProduct=a4a1, bcdDevice= 0.40 [ 514.606784][ T5919] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 514.608634][ T5937] usb 7-1: device descriptor read/64, error -71 [ 514.615459][ T5919] usb 2-1: Product: ࠓ [ 514.625474][ T5919] usb 2-1: Manufacturer: 㰗 [ 514.630218][ T5919] usb 2-1: SerialNumber: 觙豹꿱仵涱ĥꂂ韥疬Ộ㯥찒ᶇ䂠ǐ뫣㮑餺齘쭉쾔쨽뭹侜誼㵋핕谵榨듪鎳졹쬞쳨箭즜꿭滬䜴̏撥ዙ䫜㗸⚞꼂᜙胳앿꼬䠒쪆襇澓땦扰榚넩捯ऒ뽪뱢锇속撖䝟썄䲑ሓơ歛⸋즽轰瓪ࢴ厢ܣॻ겞㨑㪎딧䊫䳻蚚欁輌є噘倱媓ꜻ갿ꕂ폓⍨Ζⷚ餣렐錄嶣绺͋橎畾힓밵֯缾먥 [ 514.649998][ T5905] usb 5-1: config 7 has an invalid interface number: 109 but max is 0 [ 514.677631][T12533] raw-gadget.3 gadget.1: fail, usb_ep_enable returned -22 [ 514.685255][T12533] raw-gadget.3 gadget.1: fail, usb_ep_enable returned -22 [ 514.692625][ T5905] usb 5-1: config 7 has no interface number 0 [ 514.696359][T12533] raw-gadget.3 gadget.1: fail, usb_ep_enable returned -22 [ 514.699326][ T5905] usb 5-1: config 7 interface 109 altsetting 4 endpoint 0x3 has an invalid bInterval 0, changing to 10 [ 514.717289][ T5905] usb 5-1: config 7 interface 109 altsetting 4 endpoint 0x3 has invalid maxpacket 512, setting to 64 [ 514.730142][ T5937] usb usb7-port1: attempt power cycle [ 514.736309][ T5905] usb 5-1: config 7 interface 109 altsetting 4 endpoint 0x2 has invalid maxpacket 512, setting to 64 [ 514.747546][ T5905] usb 5-1: config 7 interface 109 altsetting 4 endpoint 0x8 has invalid wMaxPacketSize 0 [ 514.757459][ T5905] usb 5-1: config 7 interface 109 altsetting 4 has 4 endpoint descriptors, different from the interface descriptor's value: 5 [ 514.794460][ T5905] usb 5-1: config 7 interface 109 has no altsetting 0 [ 514.805344][ T5905] usb 5-1: New USB device found, idVendor=1965, idProduct=0018, bcdDevice=d9.4d [ 514.815358][ T5905] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 514.831446][ T5905] usb 5-1: Product: syz [ 514.835640][ T5905] usb 5-1: Manufacturer: syz [ 514.841122][ T5905] usb 5-1: SerialNumber: syz [ 514.852932][T12534] raw-gadget.4 gadget.4: fail, usb_ep_enable returned -22 [ 514.921364][ T5919] cdc_ether 2-1:1.0: probe with driver cdc_ether failed with error -22 [ 514.992957][T12544] netlink: 'syz.3.1664': attribute type 58 has an invalid length. [ 514.999450][T12539] Bluetooth: hci1: Opcode 0x0c1a failed: -4 [ 515.001402][T12544] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1664'. [ 515.024168][T12539] Bluetooth: hci3: Opcode 0x0c1a failed: -4 [ 515.032285][T12539] Bluetooth: hci4: Opcode 0x0c1a failed: -4 [ 515.039940][T12539] Bluetooth: hci2: Opcode 0x0c1a failed: -4 [ 515.045308][T12545] netlink: 'syz.3.1664': attribute type 2 has an invalid length. [ 515.046368][T12539] Bluetooth: hci0: Opcode 0x0c1a failed: -4 [ 515.077969][ T5937] usb 7-1: new high-speed USB device number 32 using dummy_hcd [ 515.104879][T12545] : entered promiscuous mode [ 515.112314][ T5905] usbhid 5-1:7.109: couldn't find an input interrupt endpoint [ 515.124399][ T5919] usb 2-1: USB disconnect, device number 125 [ 515.146812][ T5937] usb 7-1: config 16 interface 0 has no altsetting 0 [ 515.170502][ T5905] usb 5-1: USB disconnect, device number 20 [ 515.182600][ T5937] usb 7-1: New USB device found, idVendor=046d, idProduct=0a0e, bcdDevice=94.75 [ 515.218813][ T5937] usb 7-1: New USB device strings: Mfr=1, Product=0, SerialNumber=0 [ 515.227169][ T5937] usb 7-1: Manufacturer: syz [ 515.525058][T12557] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 515.535266][T12557] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 515.802880][ T5937] (null): keene_cmd_main failed (-110) [ 515.838120][ T5937] video4linux radio48: keene_cmd_main failed (-32) [ 515.845805][ T5937] radio-keene 7-1:16.0: V4L2 device registered as radio48 [ 515.872632][T12563] input: syz0 as /devices/virtual/input/input52 [ 515.998422][ T5919] usb 2-1: new high-speed USB device number 126 using dummy_hcd [ 516.114647][T12566] netlink: 'syz.4.1670': attribute type 10 has an invalid length. [ 516.148437][ T5919] usb 2-1: device descriptor read/64, error -71 [ 516.388112][ T5919] usb 2-1: new high-speed USB device number 127 using dummy_hcd [ 516.614880][ T5919] usb 2-1: device descriptor read/64, error -71 [ 516.904683][ T5919] usb usb2-port1: attempt power cycle [ 517.038021][ T5937] usb 4-1: new high-speed USB device number 120 using dummy_hcd [ 517.048016][T11206] Bluetooth: hci2: command 0x0405 tx timeout [ 517.054167][ T5844] Bluetooth: hci4: command 0x0c1a tx timeout [ 517.060306][ T5844] Bluetooth: hci3: command 0x0c1a tx timeout [ 517.066403][T11206] Bluetooth: hci1: command 0x0c1a tx timeout [ 517.128664][T12580] Bluetooth: hci0: command 0x0405 tx timeout [ 517.201433][ T5937] usb 4-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 517.220558][ T5937] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 517.244066][ T5937] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 517.248166][ T5919] usb 2-1: new high-speed USB device number 2 using dummy_hcd [ 517.388266][ T5937] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 517.418284][ T5937] usb 4-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 517.427391][ T5937] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 517.438730][ T5919] usb 2-1: device descriptor read/8, error -71 [ 517.530970][ T5937] usb 4-1: config 0 descriptor?? [ 517.578406][ T5905] usb 7-1: USB disconnect, device number 32 [ 517.678222][ T5919] usb 2-1: new high-speed USB device number 3 using dummy_hcd [ 517.718639][ T5919] usb 2-1: device descriptor read/8, error -71 [ 517.828798][ T5919] usb usb2-port1: unable to enumerate USB device [ 517.948788][T12589] ipt_rpfilter: only valid in 'raw' or 'mangle' table, not '' [ 517.998034][ T24] usb 5-1: new high-speed USB device number 21 using dummy_hcd [ 518.035378][ T5937] usbhid 4-1:0.0: can't add hid device: -71 [ 518.045903][ T5937] usbhid 4-1:0.0: probe with driver usbhid failed with error -71 [ 518.058399][ T5937] usb 4-1: USB disconnect, device number 120 [ 518.157881][ T24] usb 5-1: Using ep0 maxpacket: 16 [ 518.164805][ T24] usb 5-1: config 1 has an invalid descriptor of length 97, skipping remainder of the config [ 518.175646][ T24] usb 5-1: config 1 has 1 interface, different from the descriptor's value: 3 [ 518.189738][ T24] usb 5-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 518.199539][ T24] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 518.207585][ T24] usb 5-1: Product: syz [ 518.212073][ T24] usb 5-1: Manufacturer: syz [ 518.216705][ T24] usb 5-1: SerialNumber: syz [ 518.437263][ T24] usb 5-1: 0:2 : does not exist [ 518.446330][ T24] usb 5-1: 5:0: failed to get current value for ch 0 (-22) [ 518.473265][ T24] usb 5-1: USB disconnect, device number 21 [ 518.621419][ T6164] udevd[6164]: error opening ATTR{/sys/devices/platform/dummy_hcd.4/usb5/5-1/5-1:1.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 518.737655][T12599] 8021q: adding VLAN 0 to HW filter on device batadv1 [ 518.772671][T12599] team0: Port device batadv1 added [ 519.208085][ T5905] usb 2-1: new low-speed USB device number 4 using dummy_hcd [ 519.240910][T12606] netlink: 28 bytes leftover after parsing attributes in process `syz.4.1679'. [ 519.366787][ T5905] usb 2-1: device descriptor read/64, error -71 [ 519.688153][ T5905] usb 2-1: new low-speed USB device number 5 using dummy_hcd [ 519.817922][ T5905] usb 2-1: device descriptor read/64, error -71 [ 519.938415][ T5905] usb usb2-port1: attempt power cycle [ 520.276963][T12622] netlink: 'syz.5.1682': attribute type 10 has an invalid length. [ 520.291795][T12622] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 520.301298][T12622] bond0: (slave batadv0): Enslaving as an active interface with an up link [ 520.316041][ T5905] usb 2-1: new low-speed USB device number 6 using dummy_hcd [ 520.341713][ T5905] usb 2-1: device descriptor read/8, error -71 [ 520.598334][ T5905] usb 2-1: new low-speed USB device number 7 using dummy_hcd [ 520.618640][ T5905] usb 2-1: device descriptor read/8, error -71 [ 520.738517][ T5905] usb usb2-port1: unable to enumerate USB device [ 520.998874][T12633] input: syz1 as /devices/virtual/input/input53 [ 521.317903][ T24] usb 5-1: new high-speed USB device number 22 using dummy_hcd [ 521.477937][ T24] usb 5-1: Using ep0 maxpacket: 8 [ 521.485493][ T24] usb 5-1: unable to read config index 0 descriptor/start: -61 [ 521.493498][ T24] usb 5-1: can't read configurations, error -61 [ 521.627948][ T24] usb 5-1: new high-speed USB device number 23 using dummy_hcd [ 521.797943][ T24] usb 5-1: Using ep0 maxpacket: 8 [ 521.806291][ T24] usb 5-1: unable to read config index 0 descriptor/start: -61 [ 521.814108][ T24] usb 5-1: can't read configurations, error -61 [ 521.820948][ T24] usb usb5-port1: attempt power cycle [ 521.858049][ T5919] usb 4-1: new high-speed USB device number 121 using dummy_hcd [ 522.018236][ T5919] usb 4-1: Using ep0 maxpacket: 32 [ 522.027384][ T5919] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 522.038653][ T5919] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 522.048733][ T5919] usb 4-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 522.061887][ T5919] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 522.074935][ T5919] usb 4-1: config 0 descriptor?? [ 522.098290][ T5919] hub 4-1:0.0: USB hub found [ 522.178043][ T24] usb 5-1: new high-speed USB device number 24 using dummy_hcd [ 522.210946][ T24] usb 5-1: Using ep0 maxpacket: 8 [ 522.221266][ T24] usb 5-1: unable to read config index 0 descriptor/start: -61 [ 522.230306][ T24] usb 5-1: can't read configurations, error -61 [ 522.290453][ T5919] hub 4-1:0.0: 1 port detected [ 522.337911][ T5905] usb 2-1: new high-speed USB device number 8 using dummy_hcd [ 522.368294][ T24] usb 5-1: new high-speed USB device number 25 using dummy_hcd [ 522.414172][ T24] usb 5-1: Using ep0 maxpacket: 8 [ 522.430483][ T24] usb 5-1: unable to read config index 0 descriptor/start: -61 [ 522.453575][ T24] usb 5-1: can't read configurations, error -61 [ 522.474251][ T24] usb usb5-port1: unable to enumerate USB device [ 522.672817][T12650] vhci_hcd vhci_hcd.0: pdev(6) rhport(0) sockfd(6) [ 522.679740][T12650] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 522.703487][T12650] vhci_hcd vhci_hcd.0: Device attached [ 522.717379][T12650] fuse: Bad value for 'rootmode' [ 522.731392][T12653] vhci_hcd vhci_hcd.0: pdev(6) rhport(1) sockfd(12) [ 522.738048][T12653] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 522.751784][T12653] vhci_hcd vhci_hcd.0: Device attached [ 522.816291][T12655] vhci_hcd: connection closed [ 522.820134][T10208] vhci_hcd: stop threads [ 522.837897][T12651] vhci_hcd: connection closed [ 522.858528][T10208] vhci_hcd: release socket [ 522.883916][ T24] vhci_hcd: vhci_device speed not set [ 522.948375][ T24] usb 45-1: new full-speed USB device number 2 using vhci_hcd [ 522.959527][T10208] vhci_hcd: disconnect device [ 522.965964][T10208] vhci_hcd: stop threads [ 522.972100][T10208] vhci_hcd: release socket [ 522.976629][T10208] vhci_hcd: disconnect device [ 522.981442][ T5905] usb 2-1: Using ep0 maxpacket: 16 [ 522.983953][ T5919] hub 4-1:0.0: activate --> -90 [ 522.989405][ T5905] usb 2-1: config 0 has no interfaces? [ 523.006717][ T5905] usb 2-1: New USB device found, idVendor=05d1, idProduct=2001, bcdDevice=10.00 [ 523.016744][ T5905] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 523.026668][T12659] openvswitch: netlink: Key type 98 is out of range max 32 [ 523.029849][ T5905] usb 2-1: Product: syz [ 523.043692][ T5905] usb 2-1: Manufacturer: syz [ 523.053000][ T5905] usb 2-1: SerialNumber: syz [ 523.068805][ T5905] usb 2-1: config 0 descriptor?? [ 523.226897][T12639] syzkaller1: entered promiscuous mode [ 523.237430][T12639] syzkaller1: entered allmulticast mode [ 523.284501][T12646] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 523.294872][T12646] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 523.317105][ T7012] usb 2-1: USB disconnect, device number 8 [ 523.543831][ T5919] usb 4-1-port1: cannot reset (err = -71) [ 523.550634][ T7012] usb 4-1: USB disconnect, device number 121 [ 523.563305][ T5919] usb 4-1-port1: attempt power cycle [ 523.748022][ T5905] usb 7-1: new high-speed USB device number 33 using dummy_hcd [ 523.946345][ T5905] usb 7-1: too many endpoints for config 0 interface 0 altsetting 0: 255, using maximum allowed: 30 [ 523.991224][ T5905] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 523.996133][T12672] tipc: Failed to remove unknown binding: 66,1,1/2886997007:2306124097/2306124099 [ 524.019037][ T5905] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 524.045819][ T5905] usb 7-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 255 [ 524.074873][T12672] tipc: Failed to remove unknown binding: 66,1,1/2886997007:2306124097/2306124099 [ 524.123710][ T5905] usb 7-1: New USB device found, idVendor=04d8, idProduct=c002, bcdDevice= 0.00 [ 524.188245][T12672] tipc: Failed to remove unknown binding: 66,1,1/2886997007:2306124097/2306124099 [ 524.215626][ T5905] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 524.326987][ T5905] usb 7-1: config 0 descriptor?? [ 524.796667][T12677] Bluetooth: hci1: Opcode 0x0c1a failed: -4 [ 524.806184][T12677] Bluetooth: hci3: Opcode 0x0c1a failed: -4 [ 524.814738][T12677] Bluetooth: hci4: Opcode 0x0c1a failed: -4 [ 524.821358][T12677] Bluetooth: hci2: Opcode 0x0c1a failed: -4 [ 524.827700][T12677] Bluetooth: hci0: Opcode 0x0c1a failed: -4 [ 525.443596][T12689] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 525.477711][T12689] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 525.680286][ T5937] usb 2-1: new high-speed USB device number 9 using dummy_hcd [ 525.734456][T12695] openvswitch: netlink: Either Ethernet header or EtherType is required. [ 525.838275][ T5937] usb 2-1: Using ep0 maxpacket: 16 [ 525.846684][ T5937] usb 2-1: config 1 contains an unexpected descriptor of type 0x2, skipping [ 525.857566][ T5937] usb 2-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 525.876390][ T5937] usb 2-1: config 1 interface 1 altsetting 1 endpoint 0x1 has an invalid bInterval 0, changing to 7 [ 525.913301][ T5937] usb 2-1: config 1 interface 1 altsetting 1 endpoint 0x1 has invalid wMaxPacketSize 0 [ 525.965164][ T5937] usb 2-1: New USB device found, idVendor=1d6b, idProduct=0101, bcdDevice= 0.40 [ 525.985384][ T5937] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 525.998071][ T5937] usb 2-1: Product: syz [ 526.018585][ T7012] usb 4-1: new high-speed USB device number 126 using dummy_hcd [ 526.075639][ T5937] usb 2-1: Manufacturer: syz [ 526.096326][ T5937] usb 2-1: SerialNumber: syz [ 526.178199][ T7012] usb 4-1: device descriptor read/64, error -71 [ 526.488542][ T7012] usb 4-1: new high-speed USB device number 127 using dummy_hcd [ 526.505614][ T5905] usbhid 7-1:0.0: can't add hid device: -71 [ 526.518628][ T5905] usbhid 7-1:0.0: probe with driver usbhid failed with error -71 [ 526.559176][ T5937] usb 2-1: USB disconnect, device number 9 [ 526.584973][ T5905] usb 7-1: USB disconnect, device number 33 [ 526.631661][ T7012] usb 4-1: device descriptor read/64, error -71 [ 526.763468][ T7012] usb usb4-port1: attempt power cycle [ 526.808041][T12580] Bluetooth: hci1: command 0x0c1a tx timeout [ 526.889599][T12580] Bluetooth: hci0: command 0x0405 tx timeout [ 526.889624][ T5154] Bluetooth: hci2: command 0x0405 tx timeout [ 526.895639][T12580] Bluetooth: hci4: command 0x0c1a tx timeout [ 526.902346][T11206] Bluetooth: hci3: command 0x0c1a tx timeout [ 527.117908][ T7012] usb 4-1: new high-speed USB device number 2 using dummy_hcd [ 527.151957][ T7012] usb 4-1: device descriptor read/8, error -71 [ 527.324839][ T5154] Bluetooth: hci1: SCO packet for unknown connection handle 200 [ 527.462070][ T7012] usb 4-1: new high-speed USB device number 3 using dummy_hcd [ 527.533093][ T7012] usb 4-1: device descriptor read/8, error -71 [ 527.578277][ T5937] usb 2-1: new high-speed USB device number 10 using dummy_hcd [ 527.648375][ T7012] usb usb4-port1: unable to enumerate USB device [ 527.728283][ T5937] usb 2-1: Using ep0 maxpacket: 16 [ 527.765578][ T5937] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x83 has invalid maxpacket 62320, setting to 1024 [ 527.826345][ T5937] usb 2-1: config 0 interface 0 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 1024 [ 527.870484][ T5937] usb 2-1: New USB device found, idVendor=134c, idProduct=0002, bcdDevice=ec.7e [ 527.884977][ T5937] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 527.940885][ T5937] usb 2-1: Product: syz [ 527.945093][ T5937] usb 2-1: Manufacturer: syz [ 527.987191][ T5937] usb 2-1: SerialNumber: syz [ 528.017168][ T5937] usb 2-1: config 0 descriptor?? [ 528.086251][T12699] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 528.100010][ T5937] hub 2-1:0.0: bad descriptor, ignoring hub [ 528.105239][ T24] vhci_hcd: vhci_device speed not set [ 528.105942][ T5937] hub 2-1:0.0: probe with driver hub failed with error -5 [ 528.145290][ T5937] input: syz syz as /devices/platform/dummy_hcd.1/usb2/2-1/2-1:0.0/input/input55 [ 528.377043][T12707] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1702'. [ 528.408921][T12707] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1702'. [ 528.708443][ T30] audit: type=1326 audit(1749416788.546:1760): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 528.897685][ T30] audit: type=1326 audit(1749416788.576:1761): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 529.297559][ T30] audit: type=1326 audit(1749416788.596:1762): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 529.414922][ T30] audit: type=1326 audit(1749416788.596:1763): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 529.630081][T12724] netlink: 'syz.5.1710': attribute type 13 has an invalid length. [ 529.641254][ T30] audit: type=1326 audit(1749416788.596:1764): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 529.800808][ T30] audit: type=1326 audit(1749416788.596:1765): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 529.950843][ T30] audit: type=1326 audit(1749416788.596:1766): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 530.053179][ T30] audit: type=1326 audit(1749416788.596:1767): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 530.143860][ T30] audit: type=1326 audit(1749416788.596:1768): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=450 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 530.237918][ T30] audit: type=1326 audit(1749416788.596:1769): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12710 comm="syz.5.1706" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x7ffc0000 [ 530.744312][ T5937] usb 2-1: USB disconnect, device number 10 [ 531.338078][T12763] netlink: 280 bytes leftover after parsing attributes in process `syz.1.1729'. [ 532.030806][T12781] netlink: 32 bytes leftover after parsing attributes in process `syz.6.1736'. [ 532.250437][T12789] batman_adv: batadv0: adding TT local entry aa:aa:aa:aa:aa:2a to non-existent VLAN 1 [ 532.646730][T12813] random: crng reseeded on system resumption [ 532.981290][T12828] netlink: 12 bytes leftover after parsing attributes in process `syz.6.1753'. [ 533.059572][T12828] hsr_slave_0: left promiscuous mode [ 533.071997][T12828] hsr_slave_1: left promiscuous mode [ 533.138818][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.147423][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.172258][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.183042][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.195622][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.205585][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.241755][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.250799][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.289444][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.321525][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.351342][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.387342][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.421523][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.474455][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.496852][T12845] sg_read: process 971 (syz.5.1763) changed security contexts after opening file descriptor, this is not allowed. [ 533.507115][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.554372][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.626261][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.691109][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.715172][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.736603][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.762424][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.784030][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.804452][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.813552][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.822623][ T30] kauditd_printk_skb: 108 callbacks suppressed [ 533.822639][ T30] audit: type=1326 audit(1749416793.656:1878): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12852 comm="syz.5.1766" exe="/root/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7f24f0d8e929 code=0x0 [ 533.826119][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.875810][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.897818][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.990257][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 533.999145][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.007485][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.015727][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.046055][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.064159][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.079665][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.092367][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.102847][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.137976][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.153761][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.162745][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.171848][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.181686][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.194268][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.212342][ T24] hid-generic 0000:007F:FFFFFFFE.0017: unknown main item tag 0x0 [ 534.252455][ T24] hid-generic 0000:007F:FFFFFFFE.0017: hidraw0: HID v0.00 Device [syz1] on syz0 [ 534.429477][ T30] audit: type=1326 audit(1749416794.266:1879): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.529633][ T30] audit: type=1326 audit(1749416794.326:1880): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=258 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.610572][ T30] audit: type=1326 audit(1749416794.326:1881): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.661577][ T30] audit: type=1326 audit(1749416794.326:1882): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.716673][T12863] fido_id[12863]: Failed to open report descriptor at '/sys/devices/virtual/misc/uhid/report_descriptor': No such file or directory [ 534.746854][ T30] audit: type=1326 audit(1749416794.326:1883): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=243 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.841551][ T30] audit: type=1326 audit(1749416794.326:1884): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.882913][ T30] audit: type=1326 audit(1749416794.326:1885): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=157 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.909769][ T30] audit: type=1326 audit(1749416794.326:1886): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 534.956846][ T30] audit: type=1326 audit(1749416794.326:1887): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=12866 comm="syz.4.1770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=54 compat=0 ip=0x7f411eb8e929 code=0x7ffc0000 [ 535.990121][T12914] netlink: 'syz.4.1793': attribute type 27 has an invalid length. [ 536.000202][T12917] netlink: 16 bytes leftover after parsing attributes in process `syz.6.1794'. [ 536.364459][T12914] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 536.383666][T12914] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 536.424766][T12937] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1801'. [ 536.464395][T12914] netdevsim netdevsim4 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 536.473936][T12914] netdevsim netdevsim4 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 536.484101][T12914] netdevsim netdevsim4 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 536.493213][T12914] netdevsim netdevsim4 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 536.518904][T12914] wireguard0: left promiscuous mode [ 536.524136][T12914] wireguard0: left allmulticast mode [ 536.530847][T12914] wireguard1: left promiscuous mode [ 536.536092][T12914] wireguard1: left allmulticast mode [ 536.545219][T12914] netdevsim netdevsim4 netdevsim0: unset [1, 1] type 2 family 0 port 42846 - 0 [ 536.554671][T12914] netdevsim netdevsim4 netdevsim1: unset [1, 1] type 2 family 0 port 42846 - 0 [ 536.563945][T12914] netdevsim netdevsim4 netdevsim2: unset [1, 1] type 2 family 0 port 42846 - 0 [ 536.573787][T12914] netdevsim netdevsim4 netdevsim3: unset [1, 1] type 2 family 0 port 42846 - 0 [ 536.583153][T12914] geneve2: left promiscuous mode [ 536.591118][T12914] bond0: left promiscuous mode [ 536.595987][T12914] ip6gre1: left promiscuous mode [ 536.605255][T12914] wireguard2: left promiscuous mode [ 536.610664][T12914] wireguard2: left allmulticast mode [ 536.617084][T12914] wireguard3: left promiscuous mode [ 536.622784][T12914] wireguard3: left allmulticast mode [ 536.924038][T12949] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1808'. [ 536.938827][T12948] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1807'. [ 537.078094][T12955] netlink: 664 bytes leftover after parsing attributes in process `syz.6.1809'. [ 537.500249][T12961] netlink: 'syz.4.1812': attribute type 10 has an invalid length. [ 537.515342][T12961] team0: Port device dummy0 added [ 537.563211][T12961] netlink: 'syz.4.1812': attribute type 10 has an invalid length. [ 537.582271][T12961] [ 537.584655][T12961] ====================================================== [ 537.591701][T12961] WARNING: possible circular locking dependency detected [ 537.598751][T12961] 6.15.0-syzkaller-13743-g8630c59e9936 #0 Not tainted [ 537.605542][T12961] ------------------------------------------------------ [ 537.612597][T12961] syz.4.1812/12961 is trying to acquire lock: [ 537.618686][T12961] ffff88803477ce00 (team->team_lock_key#5){+.+.}-{4:4}, at: team_device_event+0x182/0xa20 [ 537.628642][T12961] [ 537.628642][T12961] but task is already holding lock: [ 537.636004][T12961] ffff88807fe18d30 (&dev_instance_lock_key#3){+.+.}-{4:4}, at: do_setlink+0x388/0x41c0 [ 537.645679][T12961] [ 537.645679][T12961] which lock already depends on the new lock. [ 537.645679][T12961] [ 537.656083][T12961] [ 537.656083][T12961] the existing dependency chain (in reverse order) is: [ 537.665095][T12961] [ 537.665095][T12961] -> #1 (&dev_instance_lock_key#3){+.+.}-{4:4}: [ 537.673548][T12961] lock_acquire+0x120/0x360 [ 537.678589][T12961] __mutex_lock+0x182/0xe80 [ 537.683618][T12961] dev_set_mtu+0x10e/0x260 [ 537.688584][T12961] team_add_slave+0x8b8/0x2840 [ 537.693879][T12961] do_set_master+0x530/0x6d0 [ 537.698998][T12961] do_setlink+0xcf0/0x41c0 [ 537.703955][T12961] rtnl_newlink+0x160b/0x1c70 [ 537.709164][T12961] rtnetlink_rcv_msg+0x7cc/0xb70 [ 537.714656][T12961] netlink_rcv_skb+0x208/0x470 [ 537.719947][T12961] netlink_unicast+0x75b/0x8d0 [ 537.725239][T12961] netlink_sendmsg+0x805/0xb30 [ 537.730534][T12961] __sock_sendmsg+0x219/0x270 [ 537.735746][T12961] ____sys_sendmsg+0x505/0x830 [ 537.741079][T12961] ___sys_sendmsg+0x21f/0x2a0 [ 537.746287][T12961] __x64_sys_sendmsg+0x19b/0x260 [ 537.751762][T12961] do_syscall_64+0xfa/0x3b0 [ 537.756786][T12961] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 537.763205][T12961] [ 537.763205][T12961] -> #0 (team->team_lock_key#5){+.+.}-{4:4}: [ 537.771396][T12961] validate_chain+0xb9b/0x2140 [ 537.776693][T12961] __lock_acquire+0xab9/0xd20 [ 537.781901][T12961] lock_acquire+0x120/0x360 [ 537.786933][T12961] __mutex_lock+0x182/0xe80 [ 537.791972][T12961] team_device_event+0x182/0xa20 [ 537.797467][T12961] notifier_call_chain+0x1b3/0x3e0 [ 537.803117][T12961] __dev_notify_flags+0x18d/0x2e0 [ 537.808676][T12961] netif_change_flags+0xe8/0x1a0 [ 537.814139][T12961] do_setlink+0xc55/0x41c0 [ 537.819086][T12961] rtnl_newlink+0x160b/0x1c70 [ 537.824290][T12961] rtnetlink_rcv_msg+0x7cc/0xb70 [ 537.829752][T12961] netlink_rcv_skb+0x208/0x470 [ 537.835049][T12961] netlink_unicast+0x75b/0x8d0 [ 537.840341][T12961] netlink_sendmsg+0x805/0xb30 [ 537.845631][T12961] __sock_sendmsg+0x219/0x270 [ 537.850835][T12961] ____sys_sendmsg+0x505/0x830 [ 537.856127][T12961] ___sys_sendmsg+0x21f/0x2a0 [ 537.861341][T12961] __x64_sys_sendmsg+0x19b/0x260 [ 537.866815][T12961] do_syscall_64+0xfa/0x3b0 [ 537.871852][T12961] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 537.878274][T12961] [ 537.878274][T12961] other info that might help us debug this: [ 537.878274][T12961] [ 537.888513][T12961] Possible unsafe locking scenario: [ 537.888513][T12961] [ 537.895988][T12961] CPU0 CPU1 [ 537.901358][T12961] ---- ---- [ 537.906724][T12961] lock(&dev_instance_lock_key#3); [ 537.911943][T12961] lock(team->team_lock_key#5); [ 537.919424][T12961] lock(&dev_instance_lock_key#3); [ 537.927163][T12961] lock(team->team_lock_key#5); [ 537.932118][T12961] [ 537.932118][T12961] *** DEADLOCK *** [ 537.932118][T12961] [ 537.940267][T12961] 2 locks held by syz.4.1812/12961: [ 537.945470][T12961] #0: ffffffff8f510808 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8db/0x1c70 [ 537.954548][T12961] #1: ffff88807fe18d30 (&dev_instance_lock_key#3){+.+.}-{4:4}, at: do_setlink+0x388/0x41c0 [ 537.964678][T12961] [ 537.964678][T12961] stack backtrace: [ 537.970600][T12961] CPU: 0 UID: 0 PID: 12961 Comm: syz.4.1812 Not tainted 6.15.0-syzkaller-13743-g8630c59e9936 #0 PREEMPT(full) [ 537.970625][T12961] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 537.970640][T12961] Call Trace: [ 537.970648][T12961] [ 537.970657][T12961] dump_stack_lvl+0x189/0x250 [ 537.970690][T12961] ? __pfx_dump_stack_lvl+0x10/0x10 [ 537.970718][T12961] ? __pfx__printk+0x10/0x10 [ 537.970739][T12961] ? print_lock_name+0xde/0x100 [ 537.970759][T12961] print_circular_bug+0x2ee/0x310 [ 537.970779][T12961] check_noncircular+0x134/0x160 [ 537.970800][T12961] validate_chain+0xb9b/0x2140 [ 537.970820][T12961] ? __lock_acquire+0xab9/0xd20 [ 537.970850][T12961] __lock_acquire+0xab9/0xd20 [ 537.970877][T12961] ? team_device_event+0x182/0xa20 [ 537.970900][T12961] lock_acquire+0x120/0x360 [ 537.970924][T12961] ? team_device_event+0x182/0xa20 [ 537.970948][T12961] ? _raw_spin_unlock_irqrestore+0x85/0x110 [ 537.970978][T12961] __mutex_lock+0x182/0xe80 [ 537.970994][T12961] ? team_device_event+0x182/0xa20 [ 537.971019][T12961] ? __try_to_del_timer_sync+0x34a/0x3a0 [ 537.971041][T12961] ? team_device_event+0x182/0xa20 [ 537.971064][T12961] ? __pfx___mutex_lock+0x10/0x10 [ 537.971081][T12961] ? __timer_delete_sync+0x218/0x2d0 [ 537.971110][T12961] team_device_event+0x182/0xa20 [ 537.971134][T12961] notifier_call_chain+0x1b3/0x3e0 [ 537.971154][T12961] __dev_notify_flags+0x18d/0x2e0 [ 537.971179][T12961] ? __pfx___dev_notify_flags+0x10/0x10 [ 537.971201][T12961] ? __dev_change_flags+0x4cc/0x6d0 [ 537.971238][T12961] ? __pfx___dev_change_flags+0x10/0x10 [ 537.971260][T12961] ? __pfx_console_unlock+0x10/0x10 [ 537.971279][T12961] ? irq_work_queue+0xbc/0x140 [ 537.971304][T12961] netif_change_flags+0xe8/0x1a0 [ 537.971328][T12961] do_setlink+0xc55/0x41c0 [ 537.971356][T12961] ? __pfx_do_setlink+0x10/0x10 [ 537.971377][T12961] ? _printk+0xcf/0x120 [ 537.971393][T12961] ? __pfx____ratelimit+0x10/0x10 [ 537.971424][T12961] ? __lock_acquire+0xab9/0xd20 [ 537.971451][T12961] ? __mutex_trylock_common+0x153/0x260 [ 537.971469][T12961] ? __pfx___mutex_trylock_common+0x10/0x10 [ 537.971489][T12961] ? rcu_is_watching+0x15/0xb0 [ 537.971504][T12961] ? trace_contention_end+0x39/0x120 [ 537.971526][T12961] ? __mutex_lock+0x330/0xe80 [ 537.971544][T12961] ? __pfx_aa_get_newest_label+0x10/0x10 [ 537.971570][T12961] ? rtnl_newlink+0x8db/0x1c70 [ 537.971590][T12961] ? rcu_is_watching+0x15/0xb0 [ 537.971606][T12961] ? __pfx___mutex_lock+0x10/0x10 [ 537.971627][T12961] ? ns_capable+0x8a/0xf0 [ 537.971654][T12961] ? rtnl_link_get_net_capable+0x16a/0x350 [ 537.971678][T12961] rtnl_newlink+0x160b/0x1c70 [ 537.971702][T12961] ? __pfx_rtnl_newlink+0x10/0x10 [ 537.971722][T12961] ? is_bpf_text_address+0x26/0x2b0 [ 537.971739][T12961] ? __lock_acquire+0xab9/0xd20 [ 537.971768][T12961] ? __lock_acquire+0xab9/0xd20 [ 537.971819][T12961] ? is_bpf_text_address+0x26/0x2b0 [ 537.971851][T12961] ? is_bpf_text_address+0x292/0x2b0 [ 537.971867][T12961] ? is_bpf_text_address+0x26/0x2b0 [ 537.971883][T12961] ? kernel_text_address+0xa5/0xe0 [ 537.971911][T12961] ? __lock_acquire+0xab9/0xd20 [ 537.971944][T12961] ? __pfx_rtnl_newlink+0x10/0x10 [ 537.971963][T12961] rtnetlink_rcv_msg+0x7cc/0xb70 [ 537.971983][T12961] ? rtnetlink_rcv_msg+0x1ab/0xb70 [ 537.972002][T12961] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 537.972027][T12961] netlink_rcv_skb+0x208/0x470 [ 537.972049][T12961] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 537.972068][T12961] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 537.972094][T12961] ? netlink_deliver_tap+0x2e/0x1b0 [ 537.972115][T12961] ? netlink_deliver_tap+0x2e/0x1b0 [ 537.972138][T12961] netlink_unicast+0x75b/0x8d0 [ 537.972161][T12961] netlink_sendmsg+0x805/0xb30 [ 537.972187][T12961] ? __pfx_netlink_sendmsg+0x10/0x10 [ 537.972211][T12961] ? aa_sock_msg_perm+0x94/0x160 [ 537.972234][T12961] ? bpf_lsm_socket_sendmsg+0x9/0x20 [ 537.972258][T12961] ? __pfx_netlink_sendmsg+0x10/0x10 [ 537.972282][T12961] __sock_sendmsg+0x219/0x270 [ 537.972301][T12961] ____sys_sendmsg+0x505/0x830 [ 537.972326][T12961] ? __pfx_____sys_sendmsg+0x10/0x10 [ 537.972352][T12961] ? import_iovec+0x74/0xa0 [ 537.972372][T12961] ___sys_sendmsg+0x21f/0x2a0 [ 537.972396][T12961] ? __pfx____sys_sendmsg+0x10/0x10 [ 537.972432][T12961] ? __fget_files+0x2a/0x420 [ 537.972453][T12961] ? __fget_files+0x3a0/0x420 [ 537.972476][T12961] __x64_sys_sendmsg+0x19b/0x260 [ 537.972501][T12961] ? __pfx___x64_sys_sendmsg+0x10/0x10 [ 537.972536][T12961] ? __secure_computing+0xe2/0x2a0 [ 537.972555][T12961] do_syscall_64+0xfa/0x3b0 [ 537.972572][T12961] ? lockdep_hardirqs_on+0x9c/0x150 [ 537.972600][T12961] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 537.972617][T12961] ? clear_bhb_loop+0x60/0xb0 [ 537.972636][T12961] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 537.972657][T12961] RIP: 0033:0x7f411eb8e929 [ 537.972674][T12961] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 537.972690][T12961] RSP: 002b:00007f411f98b038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 537.972708][T12961] RAX: ffffffffffffffda RBX: 00007f411edb5fa0 RCX: 00007f411eb8e929 [ 537.972722][T12961] RDX: 0000000000000000 RSI: 0000200000000600 RDI: 000000000000000b [ 537.972734][T12961] RBP: 00007f411ec10b39 R08: 0000000000000000 R09: 0000000000000000 [ 537.972762][T12961] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 537.972774][T12961] R13: 0000000000000000 R14: 00007f411edb5fa0 R15: 00007f411eedfa28 [ 537.972793][T12961] [ 538.555067][T12972] delete_channel: no stack [ 538.576481][T12961] team0: Port device dummy0 removed [ 538.618314][T12974] IPVS: dh: FWM 3 0x00000003 - no destination available [ 542.248887][ T1214] kworker/1:2 (1214) used greatest stack depth: 19480 bytes left