last executing test programs: 2m55.405702251s ago: executing program 1 (id=1783): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) mmap(&(0x7f0000000000/0xfbe000)=nil, 0xfbe000, 0x300000a, 0x4031, 0xffffffffffffffff, 0x0) openat$drirender128(0xffffffffffffff9c, &(0x7f0000000300), 0x280, 0x0) madvise(&(0x7f0000000000/0x600000)=nil, 0x600722, 0x19) r1 = userfaultfd(0x80001) ioctl$UFFDIO_API(r1, 0xc018aa3f, &(0x7f00000000c0)) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x15) ioctl$UFFDIO_REGISTER(r1, 0xc020aa00, &(0x7f0000000100)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x5}) ioctl$UFFDIO_REGISTER(r1, 0xc020aa07, &(0x7f0000000080)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x1, 0x2}) ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) 2m53.988209162s ago: executing program 1 (id=1792): r0 = socket$inet6_mptcp(0xa, 0x1, 0x106) r1 = socket$nl_route(0x10, 0x3, 0x0) r2 = socket$packet(0x11, 0x3, 0x300) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r2, 0x8933, &(0x7f0000000000)={'batadv_slave_0\x00'}) sendmsg$nl_route(r1, &(0x7f0000004380)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000100)=@ipv6_newrule={0x1c, 0x18, 0x409, 0x0, 0x0, {0xa, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3}}, 0x1c}}, 0x0) ioctl$sock_SIOCGIFINDEX(r0, 0x8933, &(0x7f0000000040)={'veth1_to_bridge\x00', 0x0}) r4 = socket$inet6_udplite(0xa, 0x2, 0x88) ioctl$sock_inet6_SIOCADDRT(r4, 0x890b, &(0x7f0000000140)={@rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01', @mcast1, @private2, 0x0, 0x0, 0x0, 0x0, 0x0, 0xa0022}) ioctl$sock_inet6_SIOCADDRT(r0, 0x890b, &(0x7f0000000540)={@rand_addr=' \x01\x00', @rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02', @private1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4400046, r3}) 2m53.811980288s ago: executing program 1 (id=1794): socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) r1 = openat$sysfs(0xffffffffffffff9c, &(0x7f0000000400)='/sys/power/resume', 0x149a82, 0x0) r2 = socket$nl_xfrm(0x10, 0x3, 0x6) accept4(0xffffffffffffffff, 0x0, 0x0, 0x80800) bpf$BPF_GET_PROG_INFO(0xf, &(0x7f0000000100)={r1, 0xe0, &(0x7f00000008c0)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, ""/16, 0x0, 0x0, 0x0, 0x0, 0x3, 0x0, &(0x7f0000000180)=[0x0, 0x0, 0x0], 0x0, 0x0, 0x6d, 0x0, 0x0, 0x0, 0x0, &(0x7f0000000580), 0x8, 0x3f, 0x8, 0x8, &(0x7f0000000200)}}, 0x10) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x7, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x80000100008b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000300)=0x7) sched_setscheduler(0x0, 0x2, &(0x7f00000000c0)=0xa) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) r3 = syz_clone(0x600, 0x0, 0x33, 0x0, 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x400000bce) r4 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r4, &(0x7f0000019680)=""/102392, 0x18ff8) socket$inet6_tcp(0xa, 0x1, 0x0) r5 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$mptcp(&(0x7f0000000280), 0xffffffffffffffff) sendmsg$MPTCP_PM_CMD_REMOVE(r5, &(0x7f0000000500)={0x0, 0x0, &(0x7f00000004c0)={&(0x7f0000000240)=ANY=[], 0x1c}, 0x1, 0x0, 0x0, 0x4004090}, 0x40000) msgget(0x3, 0x486) r6 = getgid() rseq(0x0, 0x0, 0x0, 0x0) msgctl$IPC_SET(0x0, 0x1, &(0x7f0000258f88)={{0x0, 0x0, r6, 0x0, r6, 0x1a, 0xfffc}, 0x0, 0x0, 0xd, 0x3, 0x4, 0xff, 0xfffffffffffffffe, 0x0, 0x4, 0x0, 0x0, r3}) msgsnd(0x0, &(0x7f0000000340)=ANY=[], 0x0, 0xe00) msgctl$MSG_INFO(0x0, 0xc, &(0x7f0000000340)=""/180) sendmsg$nl_xfrm(r2, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000500)=ANY=[], 0x138}, 0x1, 0x0, 0x0, 0x811}, 0x0) ioctl$SIOCSIFHWADDR(r0, 0x8937, &(0x7f0000000000)={'batadv_slave_1\x00', @random="0100002010ff"}) ioctl$KVM_SET_VCPU_EVENTS(r1, 0x4040aea0, &(0x7f0000000080)=@arm64={0xfc, 0x4, 0xfe, '\x00', 0x49b}) 2m52.209036571s ago: executing program 1 (id=1798): bpf$BPF_TASK_FD_QUERY(0x14, &(0x7f0000000180)={0x0, 0xffffffffffffffff, 0x0, 0x7, &(0x7f0000000000)='cgroup\x00'}, 0x30) mkdirat(0xffffffffffffff9c, &(0x7f0000000080)='./file1\x00', 0x0) mount$fuse(0x0, 0x0, 0x0, 0x2b38094, &(0x7f0000000400)=ANY=[@ANYBLOB='fd=', @ANYRESHEX=0x0]) mount(0x0, &(0x7f0000000380)='./file1\x00', &(0x7f0000000040)='autofs\x00', 0x0, &(0x7f0000000400)) chdir(&(0x7f0000000080)='./file1\x00') r0 = open(&(0x7f0000000000)='.\x00', 0x0, 0x0) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) chdir(&(0x7f0000000140)='./bus\x00') mkdirat(0xffffffffffffff9c, &(0x7f0000000000)='./file0\x00', 0x0) mount$tmpfs(0x0, &(0x7f0000000180)='./file0\x00', &(0x7f0000000300), 0x2008000, 0x0) ioctl$AUTOFS_IOC_PROTOSUBVER(r0, 0x40049366, &(0x7f0000000180)) syz_init_net_socket$bt_rfcomm(0x1f, 0x1, 0x3) r1 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) r2 = openat$cgroup_procs(r1, &(0x7f0000000040)='cgroup.threads\x00', 0x2, 0x0) sendfile(r2, r2, 0x0, 0x1) r3 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000080)='./cgroup.net/syz0\x00', 0x200002, 0x0) r4 = openat$cgroup_procs(r3, &(0x7f0000000480)='cgroup.procs\x00', 0x2, 0x0) write$cgroup_pid(r4, &(0x7f00000001c0), 0x12) 2m50.733129378s ago: executing program 1 (id=1801): r0 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r0, &(0x7f0000000440)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000200)=@updpolicy={0xb8, 0x13, 0xcb23c9c9931e99e9, 0x1, 0x0, {{@in6=@private0, @in=@initdev={0xac, 0x1e, 0x0, 0x0}, 0x0, 0x0, 0x0, 0x0, 0xa, 0x40, 0x0, 0x0, 0x0, 0xee01}, {0x0, 0x0, 0x9}}}, 0xb8}}, 0x4000) 2m50.049266437s ago: executing program 1 (id=1804): r0 = socket$inet(0x2, 0x4000000000000001, 0x0) setsockopt$inet_tcp_int(r0, 0x6, 0x80000000000002, &(0x7f00000000c0)=0x7a, 0x4) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e23, @local}, 0x10) setsockopt$SO_ATTACH_FILTER(r0, 0x1, 0x1a, &(0x7f0000000140)={0x1, &(0x7f0000000280)=[{0x6, 0x0, 0x0, 0xe4}]}, 0x10) sendto$inet(r0, 0x0, 0x0, 0x200007fd, &(0x7f0000e68000)={0x2, 0x4e23, @local}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r0, 0x6, 0xd, &(0x7f0000000100)='bbr\x00', 0x4) sendmmsg$inet(r0, &(0x7f00000010c0)=[{{0x0, 0x0, &(0x7f0000000580)=[{&(0x7f00000011c0)="93bffce623851797a8dc79018d7716840ffc6941c667f6d345b18bc896d8f016f5f206bb2b0eb2fe32d2f0048678cd35ef833c35225ff95a94770a6845b091e69f243dea0d601c54e9c93ee3568b89a3427c84262ff67b679ccac305b5cea1dcd151d7bb5754603b6b0e362d8041bdc61529260e6c4046d55927c96dcce1609b9c4f8424b9da760270a470f95b99ebb6", 0x90}, {&(0x7f00000007c0)="02999344565d9c61d3bb8cf353fd63c588ffa39f0ff0fced20927ea4b2a247d082247558bef6b2b2cd6a0dffece1b36526e9388c344fb7ac429e432bcb0330483c0604aaf296d8218e240055cb92f17b1b47fd7b1b178ca0d1c470154ed985a179f87c9bc402189195e92dc1d73fce0d96439a53073df328509806e960c2", 0x7e}, {&(0x7f00000002c0)="ec75d081fcb7e79634ec1a1abfdebb6a38b0c57cc77b83d2eea81aad8f73b36abc2019cb08fcaaec9647a07d0a0965f0f1e39afd84e7e2523aaded5e09aa1e36fcc90c269ad6d38d57619127cee4253655c33b71054226c3b00b9ee6ae29f0b07bc6fe7981126ca804c1f64e6c19ba36b2778c5f4a1c58625fe19516af43c9870c5b8191e23778abe7df2280d459b1651686a53ca52dce9570444c153f9c2903ae4c868074e89477bf6ed2ab648b0498ac8c0f90844ed9a26675199d5ff9b391c1dec077b5099cf9aecd1a9d94e235", 0xcf}, {&(0x7f00000003c0)="9059c5aee5eca0529f3f91", 0xb}], 0x4}}, {{0x0, 0x0, &(0x7f0000000c40)=[{&(0x7f0000000840)="3f1c4a04940ee0b20aec8b4090986a3bff84255d40657e7ee0d40a25584e869ef417cfb843df9bab6a733f72f13c385945fbe4f6592503b0013edc972aa7f382cfe6f924e9b3058c5dc3a39af5f6868c9031d7f0fba663fed16b868a4e53436b1be7a082f826014791", 0x69}, {&(0x7f00000008c0)="ab802595e16402267afad4132bae032aeebc5d3df8873915f385de7623fdcdbb497d2913cabe2bd146dee84fdcbeaa251db4f747090dc6c625ed3b915aae8dda1394c0d541055b3e89cab518a941", 0x4e}, {&(0x7f0000000940)="2c5e42e310fe2f095389d5264f44036f83f52415194225b1d75664af0bb8c7db4032895089bf7ed9c49da28ec002a2250c905af982041e9c842ea9dab20db6473e1556aca64e9c40548f5b0381db15e028b2a4f9983a447bb0aacb1b0267c1f54c88d99ea07b387d4be282d5d56e7acb15ebce07ad8846bcbbb754e3cee15d0455ceb58e34bd0c398ab501a6044e76a05692", 0x92}, {&(0x7f0000000b80)="5e93f51c80552080613760264b6008795ee1e8b68965025b8a5b43529d3a64b1947ab79563d895ac06f8e1df8ce3befc5707528570ed617ff1c87305dad0d429bb7245f67ac66435bd28dd2989c1a8a9dffb197f60548f295c14a8a9bdaa0691fe451b9b026a6ca951ad2dd50d8a2fab7a2c88ca6cbda171642082e6a1f24ae56a85b1ca9402e1f325ef41aab6a21391e7c10fdaa6201a9a61b609f40b1088c5b4504de74fd3f911c3218cb4fc8c14d201ba11305762", 0xb6}, {&(0x7f0000000ac0)="678c0bd2b658f8193777c8045e9dbac93340b02936a765993f548aae17", 0x1d}, {&(0x7f0000000d40)="ae6e06ff2c78f503a3e8140a4b5cf5fc573e93e3a03f36939389b5457bf672fb023da089c8c8d9b0cd7201e46415290be357067d58a5ddcacc7a8cba44b07d0515b7782843c5c90bbaceaa278c2b2ab600104ef2f60dace42501651170ca9e2c5929068ea5b40e237eb489f150859727071f9a78ea4011733928cdb9626f74b91f95eb6df84e717dc701cd791bbd688033af5b37f70e", 0x96}, {&(0x7f0000000e00)="7214e4ca106060b5952179f26f250a1e4a8ba22415db09cf6f9b26d3bc2679fbfbbc913ae8b5802936e2e34bb1ba5aab617987ac8c6ea13deb20577836d96115252a", 0x42}], 0x7}}], 0x2, 0xc0) setsockopt$sock_int(r0, 0x1, 0x8, &(0x7f0000000600)=0xdfa, 0x4) sendto$inet(r0, &(0x7f00000012c0)="09268a927f1f6588b967481241ba7860fcfaf65ac618ded8974895abeaf4b4834ff922b3f1e0b02bd67aa03059bcecc7a95425a3a07e758044ab4ea6f7ae55d88fecf90b1a7511bf746bec66ba", 0x20c8, 0x11, 0x0, 0x27) 2m49.664401977s ago: executing program 32 (id=1804): r0 = socket$inet(0x2, 0x4000000000000001, 0x0) setsockopt$inet_tcp_int(r0, 0x6, 0x80000000000002, &(0x7f00000000c0)=0x7a, 0x4) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e23, @local}, 0x10) setsockopt$SO_ATTACH_FILTER(r0, 0x1, 0x1a, &(0x7f0000000140)={0x1, &(0x7f0000000280)=[{0x6, 0x0, 0x0, 0xe4}]}, 0x10) sendto$inet(r0, 0x0, 0x0, 0x200007fd, &(0x7f0000e68000)={0x2, 0x4e23, @local}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r0, 0x6, 0xd, &(0x7f0000000100)='bbr\x00', 0x4) sendmmsg$inet(r0, &(0x7f00000010c0)=[{{0x0, 0x0, &(0x7f0000000580)=[{&(0x7f00000011c0)="93bffce623851797a8dc79018d7716840ffc6941c667f6d345b18bc896d8f016f5f206bb2b0eb2fe32d2f0048678cd35ef833c35225ff95a94770a6845b091e69f243dea0d601c54e9c93ee3568b89a3427c84262ff67b679ccac305b5cea1dcd151d7bb5754603b6b0e362d8041bdc61529260e6c4046d55927c96dcce1609b9c4f8424b9da760270a470f95b99ebb6", 0x90}, {&(0x7f00000007c0)="02999344565d9c61d3bb8cf353fd63c588ffa39f0ff0fced20927ea4b2a247d082247558bef6b2b2cd6a0dffece1b36526e9388c344fb7ac429e432bcb0330483c0604aaf296d8218e240055cb92f17b1b47fd7b1b178ca0d1c470154ed985a179f87c9bc402189195e92dc1d73fce0d96439a53073df328509806e960c2", 0x7e}, {&(0x7f00000002c0)="ec75d081fcb7e79634ec1a1abfdebb6a38b0c57cc77b83d2eea81aad8f73b36abc2019cb08fcaaec9647a07d0a0965f0f1e39afd84e7e2523aaded5e09aa1e36fcc90c269ad6d38d57619127cee4253655c33b71054226c3b00b9ee6ae29f0b07bc6fe7981126ca804c1f64e6c19ba36b2778c5f4a1c58625fe19516af43c9870c5b8191e23778abe7df2280d459b1651686a53ca52dce9570444c153f9c2903ae4c868074e89477bf6ed2ab648b0498ac8c0f90844ed9a26675199d5ff9b391c1dec077b5099cf9aecd1a9d94e235", 0xcf}, {&(0x7f00000003c0)="9059c5aee5eca0529f3f91", 0xb}], 0x4}}, {{0x0, 0x0, &(0x7f0000000c40)=[{&(0x7f0000000840)="3f1c4a04940ee0b20aec8b4090986a3bff84255d40657e7ee0d40a25584e869ef417cfb843df9bab6a733f72f13c385945fbe4f6592503b0013edc972aa7f382cfe6f924e9b3058c5dc3a39af5f6868c9031d7f0fba663fed16b868a4e53436b1be7a082f826014791", 0x69}, {&(0x7f00000008c0)="ab802595e16402267afad4132bae032aeebc5d3df8873915f385de7623fdcdbb497d2913cabe2bd146dee84fdcbeaa251db4f747090dc6c625ed3b915aae8dda1394c0d541055b3e89cab518a941", 0x4e}, {&(0x7f0000000940)="2c5e42e310fe2f095389d5264f44036f83f52415194225b1d75664af0bb8c7db4032895089bf7ed9c49da28ec002a2250c905af982041e9c842ea9dab20db6473e1556aca64e9c40548f5b0381db15e028b2a4f9983a447bb0aacb1b0267c1f54c88d99ea07b387d4be282d5d56e7acb15ebce07ad8846bcbbb754e3cee15d0455ceb58e34bd0c398ab501a6044e76a05692", 0x92}, {&(0x7f0000000b80)="5e93f51c80552080613760264b6008795ee1e8b68965025b8a5b43529d3a64b1947ab79563d895ac06f8e1df8ce3befc5707528570ed617ff1c87305dad0d429bb7245f67ac66435bd28dd2989c1a8a9dffb197f60548f295c14a8a9bdaa0691fe451b9b026a6ca951ad2dd50d8a2fab7a2c88ca6cbda171642082e6a1f24ae56a85b1ca9402e1f325ef41aab6a21391e7c10fdaa6201a9a61b609f40b1088c5b4504de74fd3f911c3218cb4fc8c14d201ba11305762", 0xb6}, {&(0x7f0000000ac0)="678c0bd2b658f8193777c8045e9dbac93340b02936a765993f548aae17", 0x1d}, {&(0x7f0000000d40)="ae6e06ff2c78f503a3e8140a4b5cf5fc573e93e3a03f36939389b5457bf672fb023da089c8c8d9b0cd7201e46415290be357067d58a5ddcacc7a8cba44b07d0515b7782843c5c90bbaceaa278c2b2ab600104ef2f60dace42501651170ca9e2c5929068ea5b40e237eb489f150859727071f9a78ea4011733928cdb9626f74b91f95eb6df84e717dc701cd791bbd688033af5b37f70e", 0x96}, {&(0x7f0000000e00)="7214e4ca106060b5952179f26f250a1e4a8ba22415db09cf6f9b26d3bc2679fbfbbc913ae8b5802936e2e34bb1ba5aab617987ac8c6ea13deb20577836d96115252a", 0x42}], 0x7}}], 0x2, 0xc0) setsockopt$sock_int(r0, 0x1, 0x8, &(0x7f0000000600)=0xdfa, 0x4) sendto$inet(r0, &(0x7f00000012c0)="09268a927f1f6588b967481241ba7860fcfaf65ac618ded8974895abeaf4b4834ff922b3f1e0b02bd67aa03059bcecc7a95425a3a07e758044ab4ea6f7ae55d88fecf90b1a7511bf746bec66ba", 0x20c8, 0x11, 0x0, 0x27) 2m37.161516659s ago: executing program 5 (id=1870): r0 = syz_usb_connect$hid(0x3, 0x0, 0x0, 0x0) syz_usb_control_io(r0, 0x0, 0x0) syz_usb_control_io(r0, &(0x7f0000000340)={0x2c, &(0x7f0000000040)={0x20, 0xa, 0x3, {0x3, 0x35, '\x00'}}, 0x0, 0x0, 0x0, 0x0}, 0x0) 2m35.479271012s ago: executing program 5 (id=1875): sendmsg$NL80211_CMD_FRAME(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000640)={0x50, 0x0, 0x1, 0x70bd26, 0x0, {{}, {@val={0x8}, @void}}, [@NL80211_ATTR_FRAME={0x29, 0x33, @auth={{{0x0, 0x0, 0xb, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, 0x1}, {0x3}, @broadcast, @device_a, @random="24644af037e4", {0x7, 0xf95}, @value=@ver_80211n={0x0, 0x59cf, 0x0, 0x1, 0x0, 0x3, 0x1}}, 0x1, 0x3, 0x25c, @val={0x10, 0x1, 0x42}}}, @NL80211_ATTR_CSA_C_OFFSETS_TX={0x6, 0xcd, [0x4]}]}, 0x50}, 0x1, 0x0, 0x0, 0xc0}, 0x0) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000140), 0x101100, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x1) ioctl$KVM_SET_USER_MEMORY_REGION(r1, 0x4020ae46, &(0x7f0000000080)={0x0, 0x2, 0x0, 0x2000, &(0x7f0000000000/0x2000)=nil}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0xfffffffffffffdc5, &(0x7f00000002c0)=0x800002) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r3 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r3, &(0x7f0000019680)=""/102392, 0x18ff8) r4 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xa, &(0x7f0000000000)={0x1, &(0x7f0000000100)=[{0x6, 0x0, 0x0, 0x7fff0000}]}) signalfd4(0xffffffffffffffff, &(0x7f0000000880), 0x8, 0x0) bpf$MAP_CREATE_TAIL_CALL(0x0, 0x0, 0x48) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000001c0)={0x18, 0xc, &(0x7f0000000040)=ANY=[@ANYBLOB="0000000000000000b703000000000000850000000c"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) write(r4, &(0x7f0000000340)="458d9a1a8323828ec3b3a84b9f8f16b5abfafe2aa5fca45e0d76c10ed55f4acc7c6253653918a33878ec3f32834bc8b2c7be8eb6cbd8f474541679a4e16ad1c247473c99baf96d9a165a2cf562e956ca1171667522d5d15377e31338316b98f2c0ad22c20599cea91191179b963efff3c0f74174", 0x74) io_uring_register$IORING_UNREGISTER_PERSONALITY(0xffffffffffffffff, 0x19, 0x2000000, 0x0) r5 = syz_open_dev$sg(&(0x7f00000060c0), 0x0, 0x8002) keyctl$set_timeout(0xf, 0x0, 0x100) fcntl$dupfd(r5, 0x0, r5) r6 = syz_open_dev$sndpcmc(&(0x7f0000000480), 0x1, 0x0) ioctl$SNDRV_PCM_IOCTL_HW_REFINE_OLD(r6, 0xc1004110, &(0x7f0000000000)={0x0, [0x6, 0xffff1337, 0x3], [{0x0, 0x0, 0x0, 0x1}, {0x35, 0x39}, {0x0, 0x8}, {0x800000, 0x800001}, {}, {0x1ff}, {0x0, 0xffe}, {}, {}, {}, {}, {0x0, 0xe68b}], 0xc, 0x0, 0x0, 0x0, 0x0, 0x500}) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r2, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000300)=[@textreal={0x8, 0x0}], 0x1, 0xa, 0x0, 0x0) ioctl$KVM_REGISTER_COALESCED_MMIO(r1, 0x4010ae67, &(0x7f0000000180)={0x0, 0xd000}) syz_emit_ethernet(0x3e, &(0x7f0000000000)=ANY=[@ANYBLOB="aaaaaaaaaaaa0f7f"], 0x0) ioctl$KVM_RUN(r2, 0xae80, 0x0) 2m33.875994399s ago: executing program 5 (id=1885): r0 = socket$inet6_mptcp(0xa, 0x1, 0x106) r1 = socket$nl_route(0x10, 0x3, 0x0) r2 = socket$packet(0x11, 0x3, 0x300) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r2, 0x8933, &(0x7f0000000000)={'batadv_slave_0\x00'}) sendmsg$nl_route(r1, &(0x7f0000004380)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000100)=@ipv6_newrule={0x24, 0x18, 0x409, 0x0, 0x0, {0xa, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3}, [@FIB_RULE_POLICY=@FRA_GOTO={0x8, 0x1e, 0x1}]}, 0x24}}, 0x0) ioctl$sock_SIOCGIFINDEX(r0, 0x8933, &(0x7f0000000040)={'veth1_to_bridge\x00'}) r3 = socket$inet6_udplite(0xa, 0x2, 0x88) ioctl$sock_inet6_SIOCADDRT(r3, 0x890b, &(0x7f0000000140)={@rand_addr=' \x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01', @mcast1, @private2, 0x0, 0x0, 0x0, 0x0, 0x0, 0xa0022}) ioctl$sock_inet6_SIOCADDRT(r0, 0x890b, 0x0) 2m32.165066734s ago: executing program 5 (id=1890): bpf$BPF_TASK_FD_QUERY(0x14, &(0x7f0000000180)={0x0, 0xffffffffffffffff, 0x0, 0x7, &(0x7f0000000000)='cgroup\x00'}, 0x30) mkdirat(0xffffffffffffff9c, &(0x7f0000000080)='./file1\x00', 0x0) mount$fuse(0x0, 0x0, 0x0, 0x2b38094, &(0x7f0000000400)=ANY=[@ANYBLOB='fd=', @ANYRESHEX=0x0]) mount(0x0, &(0x7f0000000380)='./file1\x00', &(0x7f0000000040)='autofs\x00', 0x0, &(0x7f0000000400)) chdir(&(0x7f0000000080)='./file1\x00') open(&(0x7f0000000000)='.\x00', 0x0, 0x0) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) chdir(&(0x7f0000000140)='./bus\x00') mkdirat(0xffffffffffffff9c, &(0x7f0000000000)='./file0\x00', 0x0) mount$tmpfs(0x0, &(0x7f0000000180)='./file0\x00', &(0x7f0000000300), 0x2008000, 0x0) r0 = syz_init_net_socket$bt_rfcomm(0x1f, 0x1, 0x3) setsockopt$bt_rfcomm_RFCOMM_LM(r0, 0x12, 0x3, 0x0, 0x0) r1 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) r2 = openat$cgroup_procs(r1, &(0x7f0000000040)='cgroup.threads\x00', 0x2, 0x0) sendfile(r2, r2, 0x0, 0x1) r3 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000080)='./cgroup.net/syz0\x00', 0x200002, 0x0) r4 = openat$cgroup_procs(r3, &(0x7f0000000480)='cgroup.procs\x00', 0x2, 0x0) write$cgroup_pid(r4, &(0x7f00000001c0), 0x12) 2m31.623055858s ago: executing program 5 (id=1893): r0 = socket$netlink(0x10, 0x3, 0x0) r1 = socket$netlink(0x10, 0x3, 0x0) r2 = socket(0x10, 0x803, 0x8) sendmsg$IPVS_CMD_SET_INFO(r2, &(0x7f0000000b00)={0x0, 0x0, &(0x7f0000000ac0)={0x0, 0x14}}, 0x0) getsockname$packet(r2, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000000200)=0x14) sendmsg$nl_route(r1, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000380)=ANY=[@ANYBLOB="3c0000001000850600"/20, @ANYRES32=r3, @ANYBLOB], 0x3c}}, 0x0) sendmsg$nl_route(r0, &(0x7f00000000c0)={0x0, 0x60, &(0x7f0000000300)={&(0x7f0000000900)=ANY=[@ANYBLOB="5c00000010001ffffcffffff0000000000000000", @ANYRES32=0x0, @ANYBLOB="0000000000000000340012800b0001006772657461700000240002800800070064010100060003001008000008001500700f0d0008000700ac1414bb08000a00", @ANYRES32=r3], 0x5c}}, 0x40) 2m31.276013436s ago: executing program 5 (id=1894): r0 = socket$inet6(0xa, 0x1, 0x0) r1 = dup2(r0, r0) ioctl$sock_inet6_SIOCDELRT(r1, 0x890c, &(0x7f0000000640)={@remote, @initdev={0xfe, 0x88, '\x00', 0x1, 0x0}, @dev={0xfe, 0x80, '\x00', 0x21}, 0x40000, 0x40, 0xd, 0x0, 0xfffffffffffffffe, 0x4080048}) 2m31.045249663s ago: executing program 33 (id=1894): r0 = socket$inet6(0xa, 0x1, 0x0) r1 = dup2(r0, r0) ioctl$sock_inet6_SIOCDELRT(r1, 0x890c, &(0x7f0000000640)={@remote, @initdev={0xfe, 0x88, '\x00', 0x1, 0x0}, @dev={0xfe, 0x80, '\x00', 0x21}, 0x40000, 0x40, 0xd, 0x0, 0xfffffffffffffffe, 0x4080048}) 10.446700839s ago: executing program 0 (id=2433): socket$nl_generic(0x10, 0x3, 0x10) socket$nl_generic(0x10, 0x3, 0x10) r0 = io_uring_setup(0x420c, &(0x7f0000000240)={0x0, 0x49d2, 0x2, 0x0, 0x402f}) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x11, 0x8, &(0x7f0000003900)=ANY=[], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) timer_create(0x0, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f0000000680)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$alg(0x26, 0x5, 0x0) bind$alg(r2, &(0x7f0000000000)={0x26, 'aead\x00', 0x0, 0x0, 'aegis128-generic\x00'}, 0x58) setsockopt$ALG_SET_KEY(r2, 0x117, 0x1, &(0x7f0000000080)="ab553fec94248c32e27d04000000288a", 0x10) r3 = accept$alg(r2, 0x0, 0x0) write$binfmt_script(r3, 0x0, 0x0) recvmmsg(r3, &(0x7f00000008c0)=[{{&(0x7f00000000c0)=@pptp={0x18, 0x2, {0x0, @initdev}}, 0x80, &(0x7f00000005c0)=[{0x0}, {&(0x7f0000000140)=""/9, 0x9}, {0x0}, {&(0x7f0000000400)=""/41, 0x29}, {&(0x7f0000000440)=""/123, 0x7b}, {0x0}], 0x6, &(0x7f0000000640)=""/123, 0x7b, 0x2000000}}], 0x1, 0xcb, &(0x7f0000008000)={0x0, 0x989680}) socket$inet_tcp(0x2, 0x1, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) io_uring_register$IORING_UNREGISTER_IOWQ_AFF(r0, 0x12, 0x0, 0x0) 8.283225539s ago: executing program 3 (id=2438): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) r0 = syz_open_dev$ndb(&(0x7f0000000040), 0x0, 0x0) socketpair(0x1e, 0x80805, 0x0, &(0x7f0000000180)={0xffffffffffffffff}) ioctl$NBD_SET_SOCK(r0, 0xab00, r1) ioctl$NBD_DO_IT(r0, 0xab03) ioctl$NBD_CLEAR_SOCK(r0, 0xab04) 7.764780941s ago: executing program 2 (id=2441): r0 = socket$inet_mptcp(0x2, 0x1, 0x106) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e24, @multicast2}, 0x10) r1 = userfaultfd(0x801) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) r2 = getpid() sched_setscheduler(r2, 0x2, &(0x7f0000000200)=0x5) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x400000bce) r3 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r3, &(0x7f0000019680)=""/102392, 0x18ff8) sched_setaffinity(0x0, 0xfffffef7, &(0x7f0000000740)=0x410000002) add_key(&(0x7f0000000140)='cifs.spnego\x00', &(0x7f0000000180)={'syz', 0x2}, 0x0, 0x0, 0xfffffffffffffffc) r4 = openat$vimc1(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) ioctl$VIDIOC_SUBSCRIBE_EVENT(r4, 0x4020565a, &(0x7f0000000080)={0x5, 0x9, 0x3}) ioctl$VIDIOC_UNSUBSCRIBE_EVENT(r4, 0x4020565b, &(0x7f0000000140)={0x6, 0x1, 0x7}) mmap$IORING_OFF_SQ_RING(&(0x7f0000400000/0xc00000)=nil, 0xc00000, 0x3000002, 0x5d031, 0xffffffffffffffff, 0x0) remap_file_pages(&(0x7f0000800000/0x800000)=nil, 0x800000, 0x0, 0x0, 0xf0ffffff) ioctl$UFFDIO_API(0xffffffffffffffff, 0xc018aa3f, &(0x7f0000000600)={0xaa, 0x4b4}) ioctl$UFFDIO_REGISTER(r1, 0xc020aa00, &(0x7f0000000040)={{&(0x7f0000400000/0xc00000)=nil, 0xc00000}, 0x4}) r5 = openat$full(0xffffffffffffff9c, &(0x7f0000000000), 0x8c0, 0x0) setsockopt$sock_int(r5, 0x1, 0x13, &(0x7f0000000100)=0xd89, 0x4) writev(r0, &(0x7f0000000200)=[{&(0x7f00000000c0)='X', 0x8030000}], 0x1) recvfrom$inet(r0, &(0x7f00000002c0)=""/231, 0xfffffffffffffee2, 0x40000102, 0x0, 0x0) 7.53200006s ago: executing program 0 (id=2443): r0 = fsopen(&(0x7f0000000300)='jfs\x00', 0x0) r1 = socket$inet_mptcp(0x2, 0x1, 0x106) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r2 = getpid() sched_setscheduler(r2, 0x2, &(0x7f0000000200)=0x6) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) bind$inet(r1, &(0x7f0000000080)={0x2, 0x4e24, @multicast2}, 0x10) connect$inet(r1, 0x0, 0x0) writev(r1, &(0x7f0000000200)=[{&(0x7f00000000c0)='X', 0x8030000}], 0x1) shutdown(r1, 0x1) close_range(r0, 0xffffffffffffffff, 0x0) 6.707038654s ago: executing program 0 (id=2445): sendmsg$NL80211_CMD_FRAME(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000640)={0x50, 0x0, 0x1, 0x70bd26, 0x0, {{}, {@val={0x8}, @void}}, [@NL80211_ATTR_FRAME={0x29, 0x33, @auth={{{0x0, 0x0, 0xb, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, 0x1}, {0x3}, @broadcast, @device_a, @random="24644af037e4", {0x7, 0xf95}, @value=@ver_80211n={0x0, 0x59cf, 0x0, 0x1, 0x0, 0x3, 0x1}}, 0x1, 0x3, 0x25c, @val={0x10, 0x1, 0x42}}}, @NL80211_ATTR_CSA_C_OFFSETS_TX={0x6, 0xcd, [0x4]}]}, 0x50}, 0x1, 0x0, 0x0, 0xc0}, 0x0) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000140), 0x101100, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x1) ioctl$KVM_SET_USER_MEMORY_REGION(r1, 0x4020ae46, &(0x7f0000000080)={0x0, 0x2, 0x0, 0x2000, &(0x7f0000000000/0x2000)=nil}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0xfffffffffffffdc5, &(0x7f00000002c0)=0x800002) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r3 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r3, &(0x7f0000019680)=""/102392, 0x18ff8) r4 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xa, &(0x7f0000000000)={0x1, &(0x7f0000000100)=[{0x6, 0x0, 0x0, 0x7fff0000}]}) signalfd4(0xffffffffffffffff, &(0x7f0000000880), 0x8, 0x0) bpf$MAP_CREATE_TAIL_CALL(0x0, 0x0, 0x48) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000001c0)={0x18, 0xc, &(0x7f0000000040)=ANY=[@ANYBLOB="0000000000000000b703000000000000850000000c"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) write(r4, &(0x7f0000000340)="458d9a1a8323828ec3b3a84b9f8f16b5abfafe2aa5fca45e0d76c10ed55f4acc7c6253653918a33878ec3f32834bc8b2c7be8eb6cbd8f474541679a4e16ad1c247473c99baf96d9a165a2cf562e956ca1171667522d5d15377e31338316b98f2c0ad22c20599cea91191179b963efff3c0f741745588f512a5c1ad", 0x7b) io_uring_register$IORING_UNREGISTER_PERSONALITY(0xffffffffffffffff, 0x19, 0x2000000, 0x0) r5 = syz_open_dev$sg(&(0x7f00000060c0), 0x0, 0x8002) keyctl$set_timeout(0xf, 0x0, 0x100) fcntl$dupfd(r5, 0x0, r5) r6 = syz_open_dev$sndpcmc(&(0x7f0000000480), 0x1, 0x0) ioctl$SNDRV_PCM_IOCTL_HW_REFINE_OLD(r6, 0xc1004110, &(0x7f0000000000)={0x0, [0x6, 0xffff1337, 0x3], [{0x0, 0x0, 0x0, 0x1}, {0x35, 0x39}, {0x0, 0x8}, {0x800000, 0x800001}, {}, {0x1ff}, {0x0, 0xffe}, {}, {}, {}, {}, {0x0, 0xe68b}], 0xc, 0x0, 0x0, 0x0, 0x0, 0x500}) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r2, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000300)=[@textreal={0x8, 0x0}], 0x1, 0xa, 0x0, 0x0) ioctl$KVM_REGISTER_COALESCED_MMIO(r1, 0x4010ae67, &(0x7f0000000180)={0x0, 0xd000}) syz_emit_ethernet(0x3e, &(0x7f0000000000)=ANY=[@ANYBLOB], 0x0) ioctl$KVM_RUN(r2, 0xae80, 0x0) 6.369312098s ago: executing program 2 (id=2449): socket$nl_xfrm(0x10, 0x3, 0x6) socket$inet6_tcp(0xa, 0x1, 0x0) socket$nl_route(0x10, 0x3, 0x0) socket$igmp(0x2, 0x3, 0x2) socket$netlink(0x10, 0x3, 0x0) socket$netlink(0x10, 0x3, 0x0) socket(0x10, 0x803, 0x0) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000780)=ANY=[@ANYBLOB="19000000040000000800000008"], 0x50) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x6, 0xd, &(0x7f0000000200)=ANY=[@ANYBLOB="1800000000000000000000000000000085000000bc00000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bca2000000000000a6020000f8ffffffb703000008000000b704000000000400850000003300000095"], &(0x7f0000000180)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @xdp, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000380)={{r0}, &(0x7f0000000080), &(0x7f0000000340)=r1}, 0x20) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000280)={r1, 0x5, 0x0, 0x0, &(0x7f0000000000), 0x0, 0x29d, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2, 0x0, 0x2}, 0x50) 5.988747539s ago: executing program 3 (id=2450): openat$cgroup_ro(0xffffffffffffff9c, 0x0, 0x275a, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r3, 0x3b81, &(0x7f0000000080)={0x19}) r4 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r4, 0x3b81, &(0x7f00000003c0)={0xc, 0x0, 0x0}) ioctl$IOMMU_IOAS_MAP$PAGES(r3, 0x3b85, &(0x7f00000000c0)={0x28, 0x7, r5, 0x0, &(0x7f0000800000/0x800000)=nil, 0x800000}) ioctl$IOMMU_TEST_OP_CREATE_ACCESS(r3, 0x3ba0, &(0x7f0000000340)={0x48, 0x5, r5, 0x0, 0xffffffffffffffff, 0x1}) ioctl$IOMMU_TEST_OP_ACCESS_PAGES$syz(r3, 0x3ba0, &(0x7f0000001480)={0x48, 0x7, r6, 0x0, 0x10000, 0x0, 0x8, 0x2a7345, 0x21316f}) ioctl$IOMMU_TEST_OP_ACCESS_PAGES$syz(r3, 0x3ba0, &(0x7f0000000100)={0x48, 0x7, r6, 0x0, 0x0, 0x0, 0x0, 0x0, 0x334e8b}) 5.267858303s ago: executing program 2 (id=2451): r0 = syz_usb_connect(0x5, 0x36, 0x0, 0x0) r1 = getpid() prlimit64(r1, 0xe, &(0x7f0000000000)={0xa, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000640)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f0000000280)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) bpf$PROG_LOAD_XDP(0x5, &(0x7f00000001c0)={0xd, 0x3, &(0x7f0000000040)=@framed, &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x20, '\x00', 0x0, 0xf, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x4, @void, @value}, 0x94) r2 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r2, &(0x7f0000019680)=""/102392, 0x18ff8) socket$inet6_tcp(0xa, 0x1, 0x0) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$L2TP_CMD_TUNNEL_CREATE(r3, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000380)={&(0x7f0000000280)={0x34, 0x0, 0x917, 0x0, 0x0, {}, [@L2TP_ATTR_PROTO_VERSION={0x5, 0x7, 0x2}, @L2TP_ATTR_PEER_CONN_ID={0x8}, @L2TP_ATTR_ENCAP_TYPE={0x6, 0x2, 0x1}, @L2TP_ATTR_FD={0x8}]}, 0x34}}, 0x0) socket$nl_generic(0x10, 0x3, 0x10) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000000080)=@framed, &(0x7f0000000100)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) syz_usb_control_io$printer(r0, &(0x7f0000000140)={0x14, 0x0, &(0x7f0000000540)={0x0, 0x3, 0x2, @string={0x2}}}, &(0x7f0000000800)={0x34, &(0x7f0000000680)={0x20, 0x31, 0xb9, "e3db4fb5aa8773666679868ee6efebebe7d9c923da47b99c392ec9d65b37eea38b71885c3ac4d8ab826f85623a05823acaa6cd3dcc199da40b163b31f299c923526be81342b8d3294b48283a27fa5f0f2e3206f7ef78f462d63d479313f68a8877b76991f930984a6a240d64246c7650ec42e205559cb84c13f433c70eff00f663e91ef00277f72db2ed08f98aa0c0d46f3dc8238c34caf91a93940ad0c1d8cbc9be500526524ac377b2b4f7976146abd42a709eea857bc1a4"}, 0x0, 0x0, &(0x7f0000000780)={0x20, 0x0, 0x2}, &(0x7f0000000440)={0x20, 0x1, 0x1, 0xfa}, &(0x7f00000004c0)={0x20, 0x0, 0x1, 0x1}}) r4 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r4, 0x0, 0x0) syz_usb_control_io(0xffffffffffffffff, 0x0, 0x0) r5 = socket(0xa, 0x3, 0x3a) ioctl$sock_SIOCGIFINDEX(r5, 0x8933, &(0x7f0000000240)={'vxcan1\x00', 0x0}) setsockopt$MRT6_DEL_MIF(r5, 0x29, 0xcb, &(0x7f0000000500)={0x1, 0x1, 0x5, r6, 0x6}, 0xc) syz_usb_control_io$hid(0xffffffffffffffff, 0x0, 0x0) 4.746783013s ago: executing program 3 (id=2452): r0 = openat$iommufd(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r0, 0x3b81, &(0x7f0000000400)={0xc, 0x0, 0x0}) r2 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000100), 0x400841, 0x0) ioctl$IOMMU_IOAS_ALLOW_IOVAS(r2, 0x3b82, &(0x7f0000000080)={0x18, r1, 0x0, 0x0, 0x0}) r3 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r3, 0x3b81, 0x0) ioctl$IOMMU_TEST_OP_CREATE_ACCESS(r3, 0x3ba0, &(0x7f0000000980)={0x48, 0x5, 0x0, 0x0, 0x0, 0x1}) ioctl$IOMMU_IOAS_MAP(r3, 0x3b85, &(0x7f0000000a00)={0x28, 0x7, 0x0, 0x0, &(0x7f00000a0000)='LLLLLLLLLLLLLLLLLLLLLLLLLLLL', 0x1000}) ioctl$IOMMU_TEST_OP_CREATE_ACCESS(r3, 0x3ba0, &(0x7f0000000180)={0x48, 0x5, 0x0, 0x0, 0xffffffffffffffff, 0x1}) ioctl$IOMMU_TEST_OP_ACCESS_PAGES(r3, 0x3ba0, &(0x7f0000000100)={0x48, 0x7, r4, 0x0, 0x0, 0x0, 0x0, 0x1000}) ioctl$IOMMU_IOAS_UNMAP$ALL(r3, 0x3b86, &(0x7f0000000c00)={0x18}) r5 = socket$nl_route(0x10, 0x3, 0x0) syz_emit_ethernet(0x76, &(0x7f00000004c0)=ANY=[@ANYBLOB="0180c2000000aaaaaaaaaaaa88a840008100000086dd60b33c8300383a0000000000000000000000000000000000fe8000000000000000000000000000aa0200907800009b5e6e90f26f00052f01fe800000000000000000000000000000000000000000000001320004000d680700983d4668"], 0x0) r6 = socket$nl_xfrm(0x10, 0x3, 0x6) r7 = openat$sequencer(0xffffffffffffff9c, &(0x7f0000000040), 0x8002, 0x0) write$P9_RSTATu(r7, &(0x7f0000000c40)=ANY=[@ANYBLOB="d90200000200000005cd000005c20000000000000000000000000000000000000000000000000000000000000000000000001b00046e6f6465767b65766f6f7e0539c60005000037d93a8b92000000280070673effeb09b5351f5bde05400000000018789ba916638814e5708103b494e10000000000000000020008005500f8f669fb716dcf315ecaf385409ac65b9408678c2c3b9e1d52c36cde7ba4a400b4b0b4f174a666a8529a451b3407dbdab2884baf050000000000000047ec21cabff20f9c1cbe36f4fd1a4cc280e8e289da649a3700f7016f6465762f6eb17b2300f9daa5ee23266ecf85fea65e42d979a3fde5f475daf03b1172d97badc7095afd76fe4f0441f7f7741eac030000ecff0000dba0c2f7f09ff53c7e4d1ad66e2df506ae894806878267d5a1298d792c4a37f2e1cbbd2482929a0d8972b5cf732ea5b0d723859dba3f93aed3b42ee7cac07de09d1d68a60333a882467d2b31aaddf9188549b1125d6c4c9b18c2fb56c57d7dc626e4390796a1c60f508eedc544bbb11d146059f310e2634d593fec65d529f382066664df244e4c90570a70049f399f061f75b7797ce1fe11ea919609d51a41dd3de304bd7c7ed0a456f0ae12516105c9ce887df5a6e0b6a77d596cf88ba6e5c6397c7d5021d7989528fd1739e1c2d87fff000000000000000000000000000000000066b63457b586d62877ba3c97954861e6aa12d4dfa9ce55b107b34de09bbc93dd82d4ae06808943608c40879a6e81eab951c7fcbff4348262d7f5047e3e50ed54fde86ab07d1aeaeaa5f05b79c00196ec190a296298bfe23b8d24458126ea1ce13329c79af5c86d131248752be4512fcbd5177499217a9877f8811f134a03c86ad36ff7487fd6da3e79eb2f2f82f6767b5a1933d42a72e05520249e4154c142ea9f284be40fc019f104ab65ab7ea101b5b6f44859ce8094fbd6f479a536bfd25fb7d1195a107e4fc089cb654dd7f90ecc2238f98e771ade97ec00"/731, @ANYRES32=0x0, @ANYRES32=0x0, @ANYRESHEX], 0x2d9) sendmsg$nl_xfrm(r6, &(0x7f0000000440)={0x0, 0x0, &(0x7f0000000400)={&(0x7f0000000800)=ANY=[@ANYBLOB="28010000170001000010000000000000ff0200000000000000000000000000010000000000000000fe880000000000000000000000000001fe8000000000000000000000000000bb00"/104, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="ac1414aa0ade7e4f5d00000000000100000000000000000000000000020080a03c00f4db47e40fa8fae0d9ffe9f44c455f30546a48b2228e31e8cc664175d38c54f1", @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000500000000000000"], 0x128}}, 0x0) mmap(&(0x7f0000000000/0xfbe000)=nil, 0xfbe000, 0x300000a, 0x4031, 0xffffffffffffffff, 0x0) r8 = bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f0000000200), 0x4) bpf$PROG_LOAD(0x5, &(0x7f0000000040)={0x11, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, '\x00', 0x0, @fallback, r8, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) madvise(&(0x7f0000000000/0x600000)=nil, 0x600722, 0x19) r9 = userfaultfd(0x80001) ioctl$UFFDIO_API(r9, 0xc018aa3f, &(0x7f00000000c0)) r10 = syz_open_dev$I2C(&(0x7f0000000480), 0x0, 0x0) ioctl$I2C_RDWR(r10, 0x707, &(0x7f00000001c0)={&(0x7f0000000a00)}) ioctl$UFFDIO_REGISTER(r9, 0xc020aa00, &(0x7f0000000100)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x1}) ioctl$UFFDIO_REGISTER(r9, 0xc020aa07, &(0x7f0000000080)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x1, 0x2}) sendmsg$nl_route(r5, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000340)=@newlink={0x3c, 0x10, 0x44b, 0x0, 0x0, {0x7a}, [@IFLA_LINKINFO={0x1c, 0x12, 0x0, 0x1, @bridge={{0xb}, {0xc, 0x2, 0x0, 0x1, [@IFLA_BR_MCAST_ROUTER={0x5, 0x16, 0x2}]}}}]}, 0x3c}}, 0x4) r11 = creat(&(0x7f0000000100)='./file0\x00', 0xd931d3864d39dcca) write$binfmt_elf32(r11, &(0x7f0000000280)=ANY=[@ANYBLOB="7f454c460508800bf006000000000000020006000f000000b800000038000000b8030000050000000104200005000473080003000000000004000000050000000400000008000000ffff0000a40000000c00000058000000"], 0x58) 4.742693046s ago: executing program 4 (id=2453): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000000080)=@framed, 0x0, 0x2, 0x0, 0x0, 0x0, 0x43, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0xa5, @void, @value}, 0x94) bpf$TOKEN_CREATE(0x24, &(0x7f0000000100)={0x0, r0}, 0x8) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000140)={&(0x7f0000000200)=ANY=[], 0x0, 0x6a, 0x0, 0x1, 0x0, 0x0, @void, @value}, 0x28) openat$vhost_vsock(0xffffffffffffff9c, 0x0, 0x2, 0x0) pipe2(&(0x7f0000000340), 0x0) close(0xffffffffffffffff) socket$inet6_mptcp(0xa, 0x1, 0x106) bind$inet6(0xffffffffffffffff, &(0x7f0000000040)={0xa, 0x4e22, 0x800000, @loopback, 0x1000000}, 0x1c) socket$inet_mptcp(0x2, 0x1, 0x106) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000000)={0x8, 0x100008b}, 0x0) sched_setaffinity(0x0, 0x11, &(0x7f0000000180)=0x1400200bce) sched_setscheduler(0x0, 0x1, &(0x7f0000002200)=0x1) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000002700)=""/102392, 0x18ff8) close(0x4) mount(&(0x7f00000000c0)=@nbd={'/dev/nbd', 0x0}, &(0x7f0000000000)='./cgroup\x00', &(0x7f0000000080)='hfs\x00', 0x8000, 0x0) 4.083987546s ago: executing program 0 (id=2454): r0 = socket$nl_generic(0x10, 0x3, 0x10) r1 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000080), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(r0, 0x8933, &(0x7f00000000c0)={'wlan1\x00', 0x0}) sendmsg$NL80211_CMD_CONNECT(r0, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000300)=ANY=[@ANYBLOB='0\x00\x00', @ANYRES16=r1, @ANYBLOB="0500003f0000000000002e00000008000300", @ANYRES32=r2, @ANYBLOB="0a003400020202020202000008003500060000"], 0x30}}, 0x0) 4.060967957s ago: executing program 3 (id=2455): bpf$PROG_LOAD(0x5, 0x0, 0x0) bpf$MAP_CREATE(0x0, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x20000008b}, 0x0) sendmsg$inet(0xffffffffffffffff, 0x0, 0x800) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x11, 0x8, &(0x7f0000003900)=ANY=[@ANYBLOB="620af8ff0c200021bfa100000000000007010000f8ffffffb702000003000000bd120000000000008500000006000000b70000000000000095000000000000003faf4f1e7f2aa3d9b18ed81c0c869b51ec6c0af4e0e4a9446c7670568982b4e020f698393aa0f3881f9c24aa56f15199fad0093c59d66b5ece9f36c70d0f13905ea23c22624c9f87f9793f50bb546040677b0c5077da80fb982c1e9400e693146cea484a415b76966118b64f751a0f241b07080008002d75593a286cecc93e64c227c95aa0b784625704f07a72c234664c0af9360a1f7a5e6b607130c89f18c0c1089d8b853289e01aa27ae8b09e00e79ab20b0b8e1148f49faf2ad0000000000000006fa03c6468972089b302d7bf6023cdcedb5e0125ebbc08dee510cb2364149215108333719acd97cfa107d40224edc5465a932b77e74e802a0d42bc6099ad2300000080006ef6c1ff0900000000000010c63a949e8b7955394ffa82b8e942c89112f4ab87b1bfeda7be586602d985430cea0162ab3fcf4591c926abfb0767192302000000b0eea24492a660583eecb42cbcd3de3a83209da17a0faf60fd6ad9b97aa5fa68480366c9c6fd6fa5043aa3926b81e3b59c95c25a573dc2edcaea2b1a52496dfcaf99431412fd134a996382a1a04d5bb924cfe5f3185418d605ffff9c4d2ec7c32f2095e63c80aff9fa740b5b7632f32030916f89c6dad7603f2ba2a790d62d6faec2fed44da4928b30142ba11de6c5d50b83bae613402216b5054d1e7c13b1355d6f4a8245ffa4997da9c77af4c0eb97fca585ec6bf5af51d564beb6d952aab9c70764b0a8a7583c90b3433b809bdb9fbd48bc873495cbff8a326eea31ae4e0f7505ebf6c9d13330ca005ace1a84521f14518c9b476fccbd6c712016219848624b87cec2dbe98223a0eb4fa39f6b5c02e6d6d90756ff57902a8f57000000009700cf0b4b8bc2294133000000000000000000030000000000000000000000000010008bc0d9559711e6e8861c46495ba585a4b2d02edc3e28dd271c896249ed85b980680b00002b435ac15fc0288d9b2a169cdcacc413038dafb7a2c8cb482bac0ac502d9ba96ffffff7f0000100000000000007d5ad897ef3b7cda42013d53046da21b40216e14ba2d6ad5656bfff17addaedab25b30002abbba7fa725f38400be7c1f001b2cd317902f19e385be9e48dccff729433282830689da6b53b263339863297771429d120000003341bf4abacac95900fca0493cf29b33dcc9ffffffffffffffd39fec2271ff01589646efd1cf870cd7bb2366fde41f94290c2a5ff870ce41fd3467decb05cfd9fcb32c8ed1dbd9d10a64c1083d5e71b5565b1768ee58969c41595229df17bcad70fb4021428ce970275d13b78100788f11f76161d46ea3abe0fa4d30dc94ef241875f3b4ce0232fcea69c271d7fa29822aea68a660e717a04becff0f719197724f4fce1093b62d7e8c7123d8ec571be54c72d978cf906df0042e36acd37d7f9e119f2c06f815312e0cfe222a06f56dd022c074eb8a322fb0bf47c0a8d154b405c37feaf3dd95f6ef2ae582786105c7df8be5877050c91301bb997316dbf17866fb84d4173731efe895ff2e1c5560926e90109b598502d3e959efc71f665c4d75cf2458e3546c1c776da64fb5abee0acfd235f2f4632c9062ece84c99a061887a20639b41c8c12ee86c50804042b3fb5aac518a75f9e7d7101d5e186c489b3a06fb99e0aa7f23a054de2f4d92d6bd72ee2c9fdc75aaaf1e3e483b4ad05573af40326993947d9a631bcbf3583784acbda216550d7aec6b79e30cbd128f54c2d3335457acf37331766e472391e358c3b377327ac9ecc34f24c9ae153ec60ac0694dc55bff9f5f45f90400000000000000d6b2c5ea1393fdf24285bf16b99c9cc0ad1857216f1a985f369191ae954febb3df464bfe0f7f3ee9afe7befb89d2777399f5874c553aeb3729cffe86e66964ae09bb6d163118e4cbe024fd4500f8ff0700000000cc9d8046c216c1f895778cb25122a2a9f9b444aeadea2a40da8daccf080842a486721737390cbf3a74cb2003016f1514216bdf57d2a40d40b51ab63e96ec8485b3b8a8c9ae3d14f93100c2e0893862eef552fcde2981f48c482bde8a168c3f5db2fea6f26e4a4304e50c349f4f9ecee27defc93871c5f99b355b72d538ba4958ea8e4aa37094191e10096e7e60fc3541a2c905a1a95e9571bf38ae1981c4238ecaee6f75cd0a6881bd1517a8250ddc8674152f94e3a409e2a3bce109b60000000000000000d6d5210d7503000000a87a27602b81f76386f1535bef1497f92186086e29c6bc5a1fad6ec9a31137abf9a404abde7750898b1bd627e873f8703be8672d70d1ab57075228a9f46ed9bd1f08fb8191bbab2dc51de3a61f0868afc4294859323e6c257a45319f18101288d139bd3da20fed05a8fe64680b0a3fc22dd70400000000946912d6c98cd1a9fbe1e7d58c08acaf30235b918a31d2eca55f74a23641f61f2d5b308cf0d031b0c7f0ced69993e9960ff5f76015e6009556237badf4e7965bbe2777e808fcba821aa8e8c5c39609ff854352cb4900000000000000000000000000c1fee30a3f7a85d1b29e58c77685efc0ceb1c8e5729c66418d169fc03aa188546b3ad2a182068e1e3a0e2505bc7f41019645466a53f1c96e0d4b3bc19faa5449209b083dbd334b47f067bbab40743b2a42010082008df75cf43f8ecc8d3726602111b40e761fd21081920382f14d12ca3c3431ee97471c7868dcda7eaa69eb7f7f80572fdd11bb1d0d1280fbc22bf73468788df51710d7d31c632fc5ed1762eb0b428ee751c47d8e894f745a868404a0bf35f0121008b722b1eaa6aedfa1bf2e7ccb2d61d5d76331945ecefa26b8471d42645288d7226bbd9ccd628ab84875f2c50ba891cea592b0430a537a395dc73bda367bf12cb7d81691a5fe8c47be395656a297e9df0e71f96756ea5cce7daac4be290159f6bcd75f0dda9de5532e71ae9e48b0ed0254a83100000000f6fbb869604d51a36a54c832e45b2569dc0d90b075225fde44c4e0973171ad47d6b0fdf9743af932cd6db49a47613808bad959710300000000000000832d0a45fa4242e24c7e800003c9e8095e02985f28e678f66422436f949e2ab8f162d7e3f855e378f4a1f40b0c6fb2d4b205a800b6d713acebc5b014e61a543a5a194f9ac18d76b5440e3b1a569e7397f6cafa86966d7ba19e720413267a6ccea9c439671d2c680f2753ca184eeeb843450368acb4383a01d25eb3d1e23e0f2645d1cdfa9fa410632f95a5f622f851c66ee7e30393cd7a4d67ff2a49c4f93c0984b5c2d4523497e4d64f95f08493564a1df87111c9bf3194fef97dcecc467ace45feeb685c5870d05f88a0f463db88d377442e1349acaf766218b54a9d624778e1c4e064c98e494198276eb2df7766411bef0ebb5000000000006065d635b0b7a00ee767221d8af9753387e0cd8d718f54a29df6eba3bd4c440e6e2172e3fcc01b8babb757b5c59217b80d0db3ba582814a604e4ef7a803e9ca7c85b35c9b93a9e0885e238b44ae1c2e64cce3b27083b8246829e64056000302bffff15405bd5f2eba20000000000000000000000000000000000009a9823fd8fbc5aa16509945ed032b48ea12d8e0588dc52702e4084913a06d468d0928bad76d697e1f85ab030e788d38788ee5b5428d4a971cc97db9fd231088e570735ce129e7e77fc2777692664a1488fd8d6dff4dad618fd54f529d4555c6507009ee69dd1bc55258789b24052137e9637f3efbab71720f88c3c44b3b7486f979e8a3174b531f573fe0e5239c000be2733c49546f6e8a9175ec6f14dbf72cac91643b2fd99c29eca28a3c2e60d5e5b8795fae16a7c3ea57e728eca35eaf0155a39f97580e079175426c088a0208040982a0000000000000000000000000051ceaaf0159fe61f2eade7603d0a7a56fb09cd119ac06adb6597155ae47846892bb423c024d8cbe9240b71ec6dc2124d3a19e2d714b273d95d1d3aa737cb04a33615ff2a730e51067d5d675d7122361c37c61a43b5afd865b60d4cae891b73220f17d25985a7f76834995e53a93a1c7b9eef267df691ca983a0b15bda7f6c5c1ca7aa50261a3089a1ebf0734c9b07e8951ff023263ad5aed8cfb49b49e128c697724c057d22c5df5aef27ce3db11d5ad5527d149d076e1a87e2df27c0cb8a67ad026bf953e88f10447e125c2c0f1aebee1f3390a9e3ddad4e2a6e0f6e4569fdefa19e870e04acf9493b963f98e23cfc665e4f465fa3f801e1957c399e45f61d3459b1c606204368bb931345af2823c487d2fd99db6ea6e008e7ffa06ca861551189d155bd077a79fe2c7e961352e56824f727d21d41eae78bfec4a2d7a7edbc8ef958c5ea599f7c25bf71c2340558aa12fdd24a88aaad5921aee7dae6a2f3009d9cb43ab4898d0f0aa565431b6abe585d75db04d1c9ba0b9de4ae8b0d3132bc6810cc9a693979f55174a72e1df9fdef35bc470f9e6e591982757f45c52c645d891bf63bb21fb66926ebe1a8525611fc3e8bb8795c36dc2a86b5ab46ff33cc74f61751b2dae92676db85c8d0c721b7ea4544bf51c95c86fcac1f434d09d1ee4928aafe23de66fed972e0dddfb33f64e48701b049239e7f552d816441d11c4c2647c014462344359198d97c4b6e9ed31ca18987b64de079b2bed641e8a92f13ca70844c65cb423d01950b0ebf44bd28e09c05d9ae5dd689fb880fb18d042219f5ac60c3a03b085abf3e8e3efc842a8d328733461f04c99607061c65ed14c61322a5ac2d371a95b8ad867ec92d13a4fa4ae033a09673866cd77f4bcdaaa05207166b19a8758d8855400d8c6a7242dc207251e8797eca24ea4f487663e60f2f5e1f1424958fd148f846830e88a42d93e1fe9c0b4a4a268921738938aa9f3cb3811ac87c54c8ebc8bcfb4613cc3a997ff1579edbd4ade8020e3ad001b072b1a751b588ac4639f35a58e00a50c0270608c7a7f10132b1c25b9ea81232fbef665f6212f875b2a0000000000000000000000000000cf7b6c4ba9bec153d6834bfef080df374703a8ff56a63ec1fe5f2e05a79e3cace7283dd68d41e94420c325fe4dae144fde5ec25a87d625cab20753a77b323fa3783c8b675859b9012647885a242adfee2fe812ecbe5191e0a15142f7349e7627cc39d724e2e34e7a24154f26ae3125b36d0504965295d0453902ac7079b11a3a1e655e482331e3dc35b2e7e4e3ea99064fe5b9c8ae0ca3e5fd653f3286a99d81ce4eba765c38d097391ad4babac38ce5b4344e24a361cd54e5"], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x2e) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000180)={&(0x7f0000000540)='rcu_utilization\x00', r0}, 0x10) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x6) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x0, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e24}, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000054c0)={0xe, 0x16, &(0x7f0000000940)=ANY=[@ANYBLOB="611570000000000061136c0000000000bfa000000000000007000000ee0016055e03010000000000160500000000000069163e0000000000bf070000000000002605fefffcffffff6706000020000000140600000ee6ff80bf500000000000002f650000000000006507f9ff0100000007070000cddfffff1e75000000000000bf54000000000000070400000400f9ffad4301000000000095000000000000001500000000000000950000000000000032ed3c12dc8c27df8ecf264e0f84f9f17d3c30e32f1754558f2278af6d71d79a5e12814cb1d8a5d4601d295c45a6a0b9bdb7dd3997f9c9c4f6f3be4b369289aa6812b8e007e733a9a4f1b0af3dda82ee45a010fb94fe9de57b9d8a814261bdb94a05002000c6c60bf70d742a81762bab8395fa64810b5b40d893ea8fe0185473d51b546cad3f1d5ace0600006e7c955ccefa1f6ab689b555202da2e0ec2871b4a7e65836429a527dc47ebe84a423b6c8d345dc0da3085b0ab71ca1b901627b562ed04ae76002d4519af619e3cca4d69e0dee5eb106774a8f3e6916dfec88158f0200000000c8fb730a5c1bf2b2bb71a629361997a75fd552bdc206438b8ef4901fd03c16dfda44e2a2235c8ac86d8a297dff0445a15f21dce431e56723888fb126a163f16f920ae2fb494059bba8e3b680324a188076eb685d00c4e9b2ad9bc1172ba7cbebe174aba210d739a018f9bbec63222d20cecac4d03723f1c932fb3bba54b3a6aa57f1ad2e99e0e67ab9ff16d20000009f0f53acbb40b4f8e2738270001562ed834f2af97787f696649a462e7ee4bcf8b07a10d6735154beb4000000000000000000000000004000bc00f679629709e7e78f4ddc211bc3ebe6bd9d42ca0140a7afaab43176e65ec1118d50d1e827f3472f4445d253880800000000000000690884f800031e03a651bb96589a7e2e509bcc1d161347623cb5e7ac4629c8ab04871bc47287cd31cc43010000007b40407d000000210000000000000000005f37d83f84e98a523d80bd970d703f37ca364a601ae899a56715a0a62a34c6c94cce6994521629ab028acfc1d926a0f6a5489af8dc2f17923f3c40dfd1970a55c22fe3a5ac000000000000000000000000000000c1eb2d91fb79ea00000000815266b2c9e1bfadc7498e9dda5d000000bb0d00000000000000000000e4007be511fe32fbc90e2364a55e9bb66ac64423d2d00fea2594e190deae46e26c596f84eba9000000000000003cc3aa39ee4b1386bab561cda886fa642994cacd473b543ccb5f0d7b63924f17c67b13631822a11dc3c693962895496d4f6e9cc54db6c7205a6b26f92121ef53e553acdf42068fff496d2da7d6327f31d7c8cc5d325c5379b0363ce8bd1f61b007e1ff5f1be1969a1ba791ad46d800000000c7f26a0337302f3b41eae59809fd05d12f6186f117b062df67d3a63f3265dd1410eea68208a3f26b2989b832d8b34a34a4f08b34b3042065acaa10856e858d27adee7daf32903d3fc78700d429a2d4c8b6d803eb83eecfe4c7ff9e6ab5a52e83d089dad7a8710eec53f1b11cced7bc3c8da0c44d2fbf9f6f3ff3be4d1458077c2253b0c7c7a0a9fdd63bf910dc20e5cb2a88e59febc47f1212a21f631dbaa74f22bad050e9856b48ae3a03a497c37758537650fe6db80300c41fdc3d78e046f6160e1741299e8dc29906870e6431ed1eab5d067a183f064b060a8ec12725d42e3a74863d66bee966b1574f8e01b3f34a267ff0afa1e1c758a0079b747067312e9815a21cb3f1f8150d999d788535a4d3114dbc7e2bf2402a75fd7a55733360040855ed5d1c0d634fc5fb38f8709d87b27f8a5d9121fdc058447b728f134f72062fc4b1ca0780b1a7af137ff7b4ff139604faf0453b65586f65c7943d56b52f06c870edf0c5d744b5272b44c23480b2bdbff947c4dfa108cbb88202eeb81f428a5b3c299848649e1a6bff52f657a67463d7dbf85ae9321fc2cc17dc4a29b9cba8ded5de8206c812439ab129ae818837ee1562078fc524b3baf49a0be9bb7d958d5e87c6c09bf71a894bad62934782cc308e936d7637e07c4a2a3bc87b0da20000d9ef418cf19e7a8c4c328be0ce91798adc2dca871073f6bd61940aabc86b94f8cbde4d47060400e722a6a2af483ad0d3415ed0f9db009acaba9eaea93f811d434e00000000000000000000d154672fea96aedf346279ec00000000000000000000d535d41b0067f01e2e54b9154d876020b669640ead4ca44631fadf7c4ac39a1b331dbdcd52b36df021b731ef1f92330d347f88ced5c1aaadbcdd8d2257e3a9a7c7494fadf9be36f7a2334ee6e9446fa1fd486f85d672a77dc5bd21463994d49f12016305a1e394d292b66840fe32b40ad665d241a8b8a32b3100450c32832789aa8a096f41201b585cd76631c88cf958e9e9047f5af1730c5e83db12460a0768fd4b62be6c41eed307048bac8d1f7f164574241e06027654b248dcc38749eee0c1ee7c61b3f6411a559c3d45637b11e440ed5a99109b8e71d28c3d677af5f0499c6d3fc6a129775056958c9df824ebe5fa9fb306b24a8a8334910627d03efe69d4b61c4345f048c5da8aca16cea848fa77d2507c920a6bd654b00e07789382ed902c80deeff2fd5c78f42e4353e5360c3e55962efd1331e6736eaf4ee27736fa54803ee8ec1a15266ffcd8b30368740b584c2559e691e542cab3d49db327db62328f159d1e0900b3e23e84dedcd1377aa15dbeab7db181bd66980c3557c7d9f7377fcb6023accb5c368a121acf70e5f4c3f2a0ea07011c7149ea979cab2ee65cf7ffa29152b7a8fed89575e6e6fd77d4d9463d21775abac886ee6a1f2d7d8523840438a73d6307a87e2f525867fc3af7ab74520a773ae26bae74cdd405a211e8833e1ba523cde51d04a7ca6732"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @sk_skb, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0xffffffffffffffd2, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) 3.980607057s ago: executing program 4 (id=2457): r0 = syz_io_uring_setup(0x7a6e, &(0x7f0000000040)={0x0, 0x80000000}, &(0x7f00000000c0), &(0x7f0000000100)) io_uring_register$IORING_REGISTER_BUFFERS2(r0, 0x2, &(0x7f0000000900)={0x0, 0x0, 0x0, 0x0, 0x0}, 0x20) io_uring_register$IORING_REGISTER_FILES_UPDATE(r0, 0x6, &(0x7f00000013c0)={0x0, 0x0, 0x0}, 0x0) 3.834830195s ago: executing program 0 (id=2458): socket$nl_generic(0x10, 0x3, 0x10) socket$nl_generic(0x10, 0x3, 0x10) r0 = io_uring_setup(0x420c, &(0x7f0000000240)={0x0, 0x49d2, 0x2, 0x0, 0x402f}) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x11, 0x8, &(0x7f0000003900)=ANY=[], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) timer_create(0x0, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f0000000680)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$alg(0x26, 0x5, 0x0) bind$alg(r2, &(0x7f0000000000)={0x26, 'aead\x00', 0x0, 0x0, 'aegis128-generic\x00'}, 0x58) setsockopt$ALG_SET_KEY(r2, 0x117, 0x1, &(0x7f0000000080)="ab553fec94248c32e27d04000000288a", 0x10) r3 = accept$alg(r2, 0x0, 0x0) recvmmsg(r3, &(0x7f00000008c0)=[{{&(0x7f00000000c0)=@pptp={0x18, 0x2, {0x0, @initdev}}, 0x80, &(0x7f00000005c0)=[{0x0}, {&(0x7f0000000140)=""/9, 0x9}, {0x0}, {&(0x7f0000000400)=""/41, 0x29}, {&(0x7f0000000440)=""/123, 0x7b}, {0x0}], 0x6, &(0x7f0000000640)=""/123, 0x7b, 0x2000000}}], 0x1, 0xcb, &(0x7f0000008000)={0x0, 0x989680}) socket$inet_tcp(0x2, 0x1, 0x0) getsockopt$rose(0xffffffffffffffff, 0x104, 0x5, 0x0, &(0x7f0000002180)) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) io_uring_register$IORING_UNREGISTER_IOWQ_AFF(r0, 0x12, 0x0, 0x0) 2.950162335s ago: executing program 3 (id=2459): r0 = socket$inet(0x2, 0x4000000000000001, 0x0) setsockopt$inet_tcp_int(r0, 0x6, 0x80000000000002, &(0x7f00000000c0)=0x7a, 0x4) bind$inet(r0, &(0x7f0000000080)={0x2, 0x4e23, @local}, 0x10) setsockopt$SO_ATTACH_FILTER(r0, 0x1, 0x1a, &(0x7f0000000140)={0x1, &(0x7f0000000280)=[{0x6, 0x0, 0x0, 0xe4}]}, 0x10) sendto$inet(r0, 0x0, 0x0, 0x200007fd, &(0x7f0000e68000)={0x2, 0x4e23, @local}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r0, 0x6, 0xd, &(0x7f0000000100)='bbr\x00', 0x4) sendmmsg$inet(r0, &(0x7f00000010c0)=[{{0x0, 0x0, &(0x7f0000000580)=[{&(0x7f00000011c0)="93bffce623851797a8dc79018d7716840ffc6941c667f6d345b18bc896d8f016f5f206bb2b0eb2fe32d2f0048678cd35ef833c35225ff95a94770a6845b091e69f243dea0d601c54e9c93ee3568b89a3427c84262ff67b679ccac305b5cea1dcd151d7bb5754603b6b0e362d8041bdc61529260e6c4046d55927c96dcce1609b9c4f8424b9da760270a470f9", 0x8c}, {&(0x7f00000007c0)="02999344565d9c61d3bb8cf353fd63c588ffa39f0ff0fced20927ea4b2a247d082247558bef6b2b2cd6a0dffece1b36526e9388c344fb7ac429e43", 0x3b}, {&(0x7f00000002c0)="ec75d081fcb7e79634ec1a1abfdebb6a38b0c57cc77b83d2eea81aad8f73b36abc2019cb08fcaaec9647a07d0a0965f0f1e39afd84e7e2523aaded5e09aa1e36fcc90c269ad6d38d57619127cee4253655c33b71054226c3b00b9ee6ae29f0b07bc6fe7981126ca804c1f64e6c19ba36b2778c5f4a1c58625fe19516af43c9870c5b8191e23778abe7df2280d459b1651686a53ca52dce9570444c153f9c2903ae4c868074e89477bf6ed2ab648b0498", 0xb0}], 0x3}}, {{0x0, 0x0, &(0x7f0000000c40)=[{&(0x7f0000000840)="3f1c4a04940ee0b20aec8b4090986a3bff84255d40657e7ee0d40a25584e869ef417cfb843df9bab6a733f72f13c385945fbe4f6592503b0013edc972aa7f382cfe6f924e9b3058c5dc3a39af5f6868c9031d7f0fba663fed16b868a4e53436b1be7a082f826014791", 0x69}, {&(0x7f00000008c0)="ab802595e16402267afad4132bae032aeebc5d3df8873915f385de7623fdcdbb497d2913cabe2bd146dee84fdcbeaa251db4f747090dc6c625ed3b915aae8dda1394c0d541055b3e89cab518a94118", 0x4f}, {&(0x7f0000000940)="2c5e42e310fe2f095389d5264f44036f83f52415194225b1d75664af0bb8c7db4032895089bf7ed9c49da28ec002a2250c905af982041e9c842ea9dab20db6473e1556aca64e9c40548f5b0381db15e028b2a4f9983a447bb0aacb1b0267c1f54c88d99ea07b387d4be282d5d56e7acb15ebce07ad8846bcbbb754e3cee15d0455ceb58e34bd0c398ab501a6044e76a05692", 0x92}, {&(0x7f0000000b80)="5e93f51c80552080613760264b6008795ee1e8b68965025b8a5b43529d3a64b1947ab79563d895ac06f8e1df8ce3befc5707528570ed617ff1c87305dad0d429bb7245f67ac66435bd28dd2989c1a8a9dffb197f60548f295c14a8a9bdaa0691fe451b9b026a6ca951ad2dd50d8a2fab7a2c88ca6cbda171642082e6a1f24ae56a85b1ca9402e1f325ef41aab6a21391e7c10fdaa6201a9a61b609f40b1088c5b4504de74fd3f911c3218cb4fc8c14d201ba113057620b4b", 0xb8}, {&(0x7f0000000ac0)="678c0bd2b658f8193777c8045e9dbac93340b02936a765993f548aae1735", 0x1e}, {&(0x7f0000000d40)="ae6e06ff2c78f503a3e8140a4b5cf5fc573e93e3a03f36939389b5457bf672fb023da089c8c8d9b0cd7201e46415290be357067d58a5ddcacc7a8cba44b07d0515b7782843c5c90bbaceaa278c2b2ab600104ef2f60dace42501651170ca9e2c5929068ea5b40e237eb489f150859727071f9a78ea4011733928cdb9626f74b91f95eb6df84e717dc701cd791bbd688033af5b37f70e4f4a9a52", 0x9a}, {&(0x7f0000000e00)="7214e4ca106060b5952179f26f250a1e4a8ba22415db09cf6f9b26d3bc2679fbfbbc913ae8b5802936e2e34bb1ba5aab617987ac8c6ea13deb20577836d96115252a006f88ba0aaecce5f2a01cd82f7cbd5331dcdc749e58f71ea23bef8882ae78c6d97dee03a4f290f1dcd49af3c1198fb61cb8d4a2b2b70e9277b1829c3ae8623f43793903ab85b73e468e173e79075f09457bcdd1e4", 0x97}], 0x7}}], 0x2, 0xc0) setsockopt$sock_int(r0, 0x1, 0x8, &(0x7f0000000600)=0xdfa, 0x4) sendto$inet(r0, &(0x7f00000012c0)="09268a927f1f6588b967481241ba7860fcfaf65ac618ded8974895abeaf4b4834ff922b3f1e0b02bd67aa03059bcecc7a95425a3a07e758044ab4ea6f7ae55d88fecf90b1a7511bf746bec66ba", 0x20c8, 0x11, 0x0, 0x27) 2.94664071s ago: executing program 6 (id=2460): r0 = socket$pppl2tp(0x18, 0x1, 0x1) r1 = socket$inet6_udp(0xa, 0x2, 0x0) connect$pppl2tp(r0, &(0x7f0000000000)=@pppol2tpv3={0x18, 0x1, {0x3, r1, {0x2, 0x0, @dev}, 0x2}}, 0x2e) r2 = syz_genetlink_get_family_id$l2tp(&(0x7f0000000040), 0xffffffffffffffff) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$L2TP_CMD_SESSION_DELETE(r3, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000200)={0x2c, r2, 0x1, 0x1070bd2c, 0x4, {0x5}, [@L2TP_ATTR_CONN_ID={0x8, 0x9, 0x2}, @L2TP_ATTR_PEER_SESSION_ID={0x8, 0xc, 0xaa8}, @L2TP_ATTR_SESSION_ID={0x8}]}, 0x2c}}, 0x20) 2.860036922s ago: executing program 4 (id=2461): socket$nl_xfrm(0x10, 0x3, 0x6) socket$inet6_tcp(0xa, 0x1, 0x0) socket$nl_route(0x10, 0x3, 0x0) socket$igmp(0x2, 0x3, 0x2) socket$netlink(0x10, 0x3, 0x0) socket$netlink(0x10, 0x3, 0x0) socket(0x10, 0x803, 0x0) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000780)=ANY=[@ANYBLOB="19000000040000000800000008"], 0x50) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x6, 0xd, &(0x7f0000000200)=ANY=[@ANYBLOB="1800000000000000000000000000000085000000bc00000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bca2000000000000a6020000f8ffffffb703000008000000b704000000000400850000003300000095"], &(0x7f0000000180)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @xdp, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000380)={{r0}, &(0x7f0000000080), &(0x7f0000000340)=r1}, 0x20) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000280)={r1, 0x5, 0x0, 0x0, &(0x7f0000000000), 0x0, 0x29d, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2, 0x0, 0x2}, 0x50) 2.557708238s ago: executing program 6 (id=2462): openat$sequencer2(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) openat$random(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) r0 = openat$audio(0xffffffffffffff9c, &(0x7f0000000400), 0x0, 0x0) openat$nvram(0xffffffffffffff9c, &(0x7f00000014c0), 0x40280, 0x0) fanotify_init(0x0, 0x80000) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000380)={0x8, 0x100008b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000000)=0x7) r1 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r1, &(0x7f0000000840)=[{0x0}], 0x1) pselect6(0x40, &(0x7f0000000000)={0x0, 0x0, 0x8000000000000000, 0x0, 0x0, 0x0, 0x0, 0x10000000}, 0x0, 0x0, 0x0, 0x0) socket$inet6_sctp(0xa, 0x1, 0x84) r2 = syz_init_net_socket$netrom(0x6, 0x5, 0x0) getsockopt$netrom_NETROM_T1(r2, 0x103, 0x1, 0x0, &(0x7f0000000140)) close_range(r0, 0xffffffffffffffff, 0x0) socket$inet_mptcp(0x2, 0x1, 0x106) sendmmsg$inet_sctp(0xffffffffffffffff, &(0x7f00000032c0)=[{&(0x7f00000000c0)=@in={0x2, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10, 0x0}], 0x1, 0x0) r3 = syz_io_uring_setup(0x1f87, &(0x7f0000000080)={0x0, 0x0, 0x13580}, &(0x7f0000000100)=0x0, &(0x7f0000000280)=0x0) syz_io_uring_submit(r4, r5, &(0x7f0000000140)=@IORING_OP_MSG_RING={0x28, 0x0, 0x0, r3, 0x0, 0x0}) io_uring_enter(r3, 0x14, 0xb9c, 0x3, 0x0, 0xffffffd5) 2.515353591s ago: executing program 4 (id=2463): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) sched_setaffinity(r0, 0x8, &(0x7f0000000240)=0x2) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) r4 = syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) sendmsg$NL802154_CMD_SET_LBT_MODE(r4, 0x0, 0x0) syz_genetlink_get_family_id$nfc(0x0, r4) r5 = syz_genetlink_get_family_id$netlbl_mgmt(&(0x7f0000000580), r4) sendmsg$NLBL_MGMT_C_VERSION(r4, &(0x7f0000000600)={0x0, 0x0, &(0x7f0000001340)={&(0x7f00000001c0)={0x30, r5, 0xf03, 0x70bd2d, 0xfffffffe, {}, [@NLBL_MGMT_A_DOMAIN={0x1a, 0x1, 'cpuset.effective_mems\x00'}]}, 0x30}, 0x1, 0x0, 0x0, 0x2400c800}, 0x0) listen(r3, 0x2) accept(r3, 0x0, 0x0) r6 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000180)={0x11, 0x5, &(0x7f0000000280)=ANY=[@ANYBLOB="1801000021000000000000004bc311ec8500000075000000a70000000800000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f00000000c0)='percpu_alloc_percpu\x00', r6}, 0x10) syz_io_uring_setup(0x10d, &(0x7f00000003c0)={0x0, 0x0, 0x2, 0x4, 0xfffe}, 0x0, 0x0) 2.503760261s ago: executing program 2 (id=2464): sendmsg$NL80211_CMD_FRAME(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000640)={0x50, 0x0, 0x1, 0x70bd26, 0x0, {{}, {@val={0x8}, @void}}, [@NL80211_ATTR_FRAME={0x29, 0x33, @auth={{{0x0, 0x0, 0xb, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, 0x1}, {0x3}, @broadcast, @device_a, @random="24644af037e4", {0x7, 0xf95}, @value=@ver_80211n={0x0, 0x59cf, 0x0, 0x1, 0x0, 0x3, 0x1}}, 0x1, 0x3, 0x25c, @val={0x10, 0x1, 0x42}}}, @NL80211_ATTR_CSA_C_OFFSETS_TX={0x6, 0xcd, [0x4]}]}, 0x50}, 0x1, 0x0, 0x0, 0xc0}, 0x0) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000140), 0x101100, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x1) ioctl$KVM_SET_USER_MEMORY_REGION(r1, 0x4020ae46, &(0x7f0000000080)={0x0, 0x2, 0x0, 0x2000, &(0x7f0000000000/0x2000)=nil}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0xfffffffffffffdc5, &(0x7f00000002c0)=0x800002) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r3 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r3, &(0x7f0000019680)=""/102392, 0x18ff8) r4 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xa, &(0x7f0000000000)={0x1, &(0x7f0000000100)=[{0x6, 0x0, 0x0, 0x7fff0000}]}) signalfd4(0xffffffffffffffff, &(0x7f0000000880), 0x8, 0x0) bpf$MAP_CREATE_TAIL_CALL(0x0, 0x0, 0x48) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000001c0)={0x18, 0xc, &(0x7f0000000040)=ANY=[@ANYBLOB="0000000000000000b703000000000000850000000c"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) write(r4, &(0x7f0000000340)="458d9a1a8323828ec3b3a84b9f8f16b5abfafe2aa5fca45e0d76c10ed55f4acc7c6253653918a33878ec3f32834bc8b2c7be8eb6cbd8f474541679a4e16ad1c247473c99baf96d9a165a2cf562e956ca1171667522d5d15377e31338316b98f2c0ad22c20599cea91191179b963efff3c0f741745588f512a5c1ad", 0x7b) io_uring_register$IORING_UNREGISTER_PERSONALITY(0xffffffffffffffff, 0x19, 0x2000000, 0x0) r5 = syz_open_dev$sg(&(0x7f00000060c0), 0x0, 0x8002) keyctl$set_timeout(0xf, 0x0, 0x100) fcntl$dupfd(r5, 0x0, r5) r6 = syz_open_dev$sndpcmc(&(0x7f0000000480), 0x1, 0x0) ioctl$SNDRV_PCM_IOCTL_HW_REFINE_OLD(r6, 0xc1004110, &(0x7f0000000000)={0x0, [0x6, 0xffff1337, 0x3], [{0x0, 0x0, 0x0, 0x1}, {0x35, 0x39}, {0x0, 0x8}, {0x800000, 0x800001}, {}, {0x1ff}, {0x0, 0xffe}, {}, {}, {}, {}, {0x0, 0xe68b}], 0xc, 0x0, 0x0, 0x0, 0x0, 0x500}) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r2, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000300)=[@textreal={0x8, 0x0}], 0x1, 0xa, 0x0, 0x0) ioctl$KVM_REGISTER_COALESCED_MMIO(r1, 0x4010ae67, &(0x7f0000000180)={0x0, 0xd000}) syz_emit_ethernet(0x3e, &(0x7f0000000000)=ANY=[@ANYBLOB="aaaaaaaa"], 0x0) ioctl$KVM_RUN(r2, 0xae80, 0x0) 2.335462524s ago: executing program 3 (id=2465): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x102}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) getpid() mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs={0x0, 0x0, 0xfffffffe}, 0x6e) sendmmsg$unix(r1, 0x0, 0x0, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r2 = openat$rdma_cm(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r2, &(0x7f0000000040)={0x0, 0x1, 0xfa00, {0x0, &(0x7f0000000380)={0xffffffffffffffff}, 0x2}}, 0x20) write$RDMA_USER_CM_CMD_QUERY(0xffffffffffffffff, &(0x7f0000000080)={0x13, 0x10, 0xfa00, {&(0x7f00000009c0), r3, 0x1}}, 0x18) writev(r2, 0x0, 0x0) 1.347377012s ago: executing program 4 (id=2466): r0 = openat$iommufd(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r0, 0x3b81, &(0x7f0000000400)={0xc, 0x0, 0x0}) r2 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000100), 0x400841, 0x0) ioctl$IOMMU_IOAS_ALLOW_IOVAS(r2, 0x3b82, &(0x7f0000000080)={0x18, r1, 0x0, 0x0, 0x0}) r3 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r3, 0x3b81, &(0x7f00000000c0)={0xc, 0x0, 0x0}) ioctl$IOMMU_TEST_OP_CREATE_ACCESS(r3, 0x3ba0, 0x0) ioctl$IOMMU_IOAS_MAP(r3, 0x3b85, &(0x7f0000000a00)={0x28, 0x7, r4, 0x0, &(0x7f00000a0000)='LLLLLLLLLLLLLLLLLLLLLLLLLLLL', 0x1000}) ioctl$IOMMU_TEST_OP_CREATE_ACCESS(r3, 0x3ba0, &(0x7f0000000180)={0x48, 0x5, r4, 0x0, 0xffffffffffffffff, 0x1}) ioctl$IOMMU_TEST_OP_ACCESS_PAGES(r3, 0x3ba0, &(0x7f0000000100)={0x48, 0x7, r5, 0x0, 0x0, 0x0, 0x0, 0x1000}) ioctl$IOMMU_IOAS_UNMAP$ALL(r3, 0x3b86, &(0x7f0000000c00)={0x18, r4}) r6 = socket$nl_route(0x10, 0x3, 0x0) syz_emit_ethernet(0x76, &(0x7f00000004c0)=ANY=[@ANYBLOB="0180c2000000aaaaaaaaaaaa88a840008100000086dd60b33c8300383a0000000000000000000000000000000000fe8000000000000000000000000000aa0200907800009b5e6e90f26f00052f01fe800000000000000000000000000000000000000000000001320004000d680700983d4668"], 0x0) r7 = socket$nl_xfrm(0x10, 0x3, 0x6) r8 = openat$sequencer(0xffffffffffffff9c, &(0x7f0000000040), 0x8002, 0x0) write$P9_RSTATu(r8, &(0x7f0000000c40)=ANY=[@ANYBLOB="d90200000200000005cd000005c20000000000000000000000000000000000000000000000000000000000000000000000001b00046e6f6465767b65766f6f7e0539c60005000037d93a8b92000000280070673effeb09b5351f5bde05400000000018789ba916638814e5708103b494e10000000000000000020008005500f8f669fb716dcf315ecaf385409ac65b9408678c2c3b9e1d52c36cde7ba4a400b4b0b4f174a666a8529a451b3407dbdab2884baf050000000000000047ec21cabff20f9c1cbe36f4fd1a4cc280e8e289da649a3700f7016f6465762f6eb17b2300f9daa5ee23266ecf85fea65e42d979a3fde5f475daf03b1172d97badc7095afd76fe4f0441f7f7741eac030000ecff0000dba0c2f7f09ff53c7e4d1ad66e2df506ae894806878267d5a1298d792c4a37f2e1cbbd2482929a0d8972b5cf732ea5b0d723859dba3f93aed3b42ee7cac07de09d1d68a60333a882467d2b31aaddf9188549b1125d6c4c9b18c2fb56c57d7dc626e4390796a1c60f508eedc544bbb11d146059f310e2634d593fec65d529f382066664df244e4c90570a70049f399f061f75b7797ce1fe11ea919609d51a41dd3de304bd7c7ed0a456f0ae12516105c9ce887df5a6e0b6a77d596cf88ba6e5c6397c7d5021d7989528fd1739e1c2d87fff000000000000000000000000000000000066b63457b586d62877ba3c97954861e6aa12d4dfa9ce55b107b34de09bbc93dd82d4ae06808943608c40879a6e81eab951c7fcbff4348262d7f5047e3e50ed54fde86ab07d1aeaeaa5f05b79c00196ec190a296298bfe23b8d24458126ea1ce13329c79af5c86d131248752be4512fcbd5177499217a9877f8811f134a03c86ad36ff7487fd6da3e79eb2f2f82f6767b5a1933d42a72e05520249e4154c142ea9f284be40fc019f104ab65ab7ea101b5b6f44859ce8094fbd6f479a536bfd25fb7d1195a107e4fc089cb654dd7f90ecc2238f98e771ade97ec00"/731, @ANYRES32=0x0, @ANYRES32=0x0, @ANYRESHEX], 0x2d9) sendmsg$nl_xfrm(r7, &(0x7f0000000440)={0x0, 0x0, &(0x7f0000000400)={&(0x7f0000000800)=ANY=[@ANYBLOB="28010000170001000010000000000000ff0200000000000000000000000000010000000000000000fe880000000000000000000000000001fe8000000000000000000000000000bb00"/104, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="ac1414aa0ade7e4f5d00000000000100000000000000000000000000020080a03c00f4db47e40fa8fae0d9ffe9f44c455f30546a48b2228e31e8cc664175d38c54f1", @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000500000000000000"], 0x128}}, 0x0) mmap(&(0x7f0000000000/0xfbe000)=nil, 0xfbe000, 0x300000a, 0x4031, 0xffffffffffffffff, 0x0) r9 = bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f0000000200), 0x4) bpf$PROG_LOAD(0x5, &(0x7f0000000040)={0x11, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, '\x00', 0x0, @fallback, r9, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) madvise(&(0x7f0000000000/0x600000)=nil, 0x600722, 0x19) r10 = userfaultfd(0x80001) ioctl$UFFDIO_API(r10, 0xc018aa3f, &(0x7f00000000c0)) r11 = syz_open_dev$I2C(&(0x7f0000000480), 0x0, 0x0) ioctl$I2C_RDWR(r11, 0x707, &(0x7f00000001c0)={&(0x7f0000000a00)}) ioctl$UFFDIO_REGISTER(r10, 0xc020aa00, &(0x7f0000000100)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x1}) ioctl$UFFDIO_REGISTER(r10, 0xc020aa07, &(0x7f0000000080)={{&(0x7f00000e2000/0xc00000)=nil, 0xc00000}, 0x1, 0x2}) sendmsg$nl_route(r6, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000340)=@newlink={0x3c, 0x10, 0x44b, 0x0, 0x0, {0x7a}, [@IFLA_LINKINFO={0x1c, 0x12, 0x0, 0x1, @bridge={{0xb}, {0xc, 0x2, 0x0, 0x1, [@IFLA_BR_MCAST_ROUTER={0x5, 0x16, 0x2}]}}}]}, 0x3c}}, 0x4) r12 = creat(&(0x7f0000000100)='./file0\x00', 0xd931d3864d39dcca) write$binfmt_elf32(r12, &(0x7f0000000280)=ANY=[@ANYBLOB="7f454c460508800bf006000000000000020006000f000000b800000038000000b8030000050000000104200005000473080003000000000004000000050000000400000008000000ffff0000a40000000c00000058000000"], 0x58) 1.135931544s ago: executing program 6 (id=2467): r0 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r0, 0x3b81, &(0x7f0000000080)={0x19}) r1 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r1, 0x3b81, &(0x7f00000003c0)={0xc, 0x0, 0x0}) ioctl$IOMMU_IOAS_MAP$PAGES(r0, 0x3b85, &(0x7f00000000c0)={0x28, 0x7, r2, 0x0, &(0x7f0000800000/0x800000)=nil, 0x800000}) ioctl$IOMMU_TEST_OP_CREATE_ACCESS(r0, 0x3ba0, &(0x7f0000000340)={0x48, 0x5, r2, 0x0, 0xffffffffffffffff, 0x1}) ioctl$IOMMU_TEST_OP_ACCESS_PAGES$syz(r0, 0x3ba0, &(0x7f0000001480)={0x48, 0x7, r3, 0x0, 0x10000, 0x0, 0x8, 0x2a7345, 0x21316f}) ioctl$IOMMU_TEST_OP_ACCESS_PAGES$syz(r0, 0x3ba0, &(0x7f0000000100)={0x48, 0x7, r3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x334e8b}) 841.093859ms ago: executing program 4 (id=2468): mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) mremap(&(0x7f00004fd000/0x2000)=nil, 0x2000, 0x2000, 0x3, &(0x7f000015a000/0x2000)=nil) madvise(&(0x7f0000000000/0x600000)=nil, 0x600000, 0x9) r0 = socket$inet6(0xa, 0x3, 0x8000000003c) connect$inet6(r0, &(0x7f0000000040)={0xa, 0x0, 0x0, @mcast1, 0x5}, 0x1c) sendmsg(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000100)=[{0x0}], 0x1, 0x0, 0x0, 0x2c}, 0x4) 695.386815ms ago: executing program 0 (id=2469): r0 = syz_usb_connect(0x5, 0x36, 0x0, 0x0) r1 = getpid() prlimit64(r1, 0xe, &(0x7f0000000000)={0xa, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000640)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f0000000280)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) bpf$PROG_LOAD_XDP(0x5, &(0x7f00000001c0)={0xd, 0x3, &(0x7f0000000040)=@framed, &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x20, '\x00', 0x0, 0xf, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x4, @void, @value}, 0x94) r2 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r2, &(0x7f0000019680)=""/102392, 0x18ff8) socket$inet6_tcp(0xa, 0x1, 0x0) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$L2TP_CMD_TUNNEL_CREATE(r3, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000380)={&(0x7f0000000280)={0x34, 0x0, 0x917, 0x0, 0x0, {}, [@L2TP_ATTR_PROTO_VERSION={0x5, 0x7, 0x2}, @L2TP_ATTR_PEER_CONN_ID={0x8}, @L2TP_ATTR_ENCAP_TYPE={0x6, 0x2, 0x1}, @L2TP_ATTR_FD={0x8}]}, 0x34}}, 0x0) socket$nl_generic(0x10, 0x3, 0x10) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000000080)=@framed, &(0x7f0000000100)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) syz_usb_control_io$printer(r0, &(0x7f0000000140)={0x14, 0x0, &(0x7f0000000540)={0x0, 0x3, 0x2, @string={0x2}}}, &(0x7f0000000800)={0x34, &(0x7f0000000680)={0x20, 0x31, 0xb9, "e3db4fb5aa8773666679868ee6efebebe7d9c923da47b99c392ec9d65b37eea38b71885c3ac4d8ab826f85623a05823acaa6cd3dcc199da40b163b31f299c923526be81342b8d3294b48283a27fa5f0f2e3206f7ef78f462d63d479313f68a8877b76991f930984a6a240d64246c7650ec42e205559cb84c13f433c70eff00f663e91ef00277f72db2ed08f98aa0c0d46f3dc8238c34caf91a93940ad0c1d8cbc9be500526524ac377b2b4f7976146abd42a709eea857bc1a4"}, 0x0, 0x0, &(0x7f0000000780)={0x20, 0x0, 0x2}, &(0x7f0000000440)={0x20, 0x1, 0x1, 0xfa}, &(0x7f00000004c0)={0x20, 0x0, 0x1, 0x1}}) r4 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route_sched(r4, 0x0, 0x0) syz_usb_control_io(0xffffffffffffffff, 0x0, 0x0) r5 = socket(0xa, 0x3, 0x3a) ioctl$sock_SIOCGIFINDEX(r5, 0x8933, &(0x7f0000000240)={'vxcan1\x00', 0x0}) setsockopt$MRT6_DEL_MIF(r5, 0x29, 0xcb, &(0x7f0000000500)={0x1, 0x1, 0x5, r6, 0x6}, 0xc) syz_usb_control_io$hid(0xffffffffffffffff, 0x0, 0x0) 636.775036ms ago: executing program 6 (id=2470): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) r0 = syz_open_dev$ndb(&(0x7f0000000040), 0x0, 0x0) socketpair(0x1e, 0x80805, 0x0, &(0x7f0000000180)={0xffffffffffffffff}) ioctl$NBD_SET_SOCK(r0, 0xab00, r1) ioctl$NBD_DO_IT(r0, 0xab03) ioctl$NBD_CLEAR_SOCK(r0, 0xab04) 617.57882ms ago: executing program 2 (id=2471): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x40000, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) ioctl$KVM_SET_CPUID2(r2, 0x4008ae90, &(0x7f0000000000)=ANY=[@ANYBLOB="01"]) ioctl$KVM_RUN(r2, 0xae80, 0x0) ioctl$KVM_SET_CPUID(r2, 0x4008ae8a, &(0x7f0000000340)=ANY=[@ANYBLOB]) 94.195336ms ago: executing program 6 (id=2472): r0 = socket$pppl2tp(0x18, 0x1, 0x1) r1 = socket$inet6_udp(0xa, 0x2, 0x0) connect$pppl2tp(r0, &(0x7f0000000000)=@pppol2tpv3={0x18, 0x1, {0x3, r1, {0x2, 0x0, @dev}, 0x2}}, 0x2e) r2 = syz_genetlink_get_family_id$l2tp(&(0x7f0000000040), 0xffffffffffffffff) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$L2TP_CMD_SESSION_DELETE(r3, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000200)={0x2c, r2, 0x1, 0x1070bd2c, 0x4, {0x5}, [@L2TP_ATTR_CONN_ID={0x8, 0x9, 0x2}, @L2TP_ATTR_PEER_SESSION_ID={0x8, 0xc, 0xaa8}, @L2TP_ATTR_SESSION_ID={0x8}]}, 0x2c}}, 0x20) 54.868795ms ago: executing program 2 (id=2473): socket$nl_xfrm(0x10, 0x3, 0x6) socket$inet6_tcp(0xa, 0x1, 0x0) socket$nl_route(0x10, 0x3, 0x0) socket$igmp(0x2, 0x3, 0x2) socket$netlink(0x10, 0x3, 0x0) socket$netlink(0x10, 0x3, 0x0) socket(0x10, 0x803, 0x0) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000780)=ANY=[@ANYBLOB="19000000040000000800000008"], 0x50) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x6, 0xd, &(0x7f0000000200)=ANY=[@ANYBLOB="1800000000000000000000000000000085000000bc00000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bca2000000000000a6020000f8ffffffb703000008000000b704000000000400850000003300000095"], &(0x7f0000000180)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @xdp, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000380)={{r0}, &(0x7f0000000080), &(0x7f0000000340)=r1}, 0x20) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000280)={r1, 0x5, 0x7, 0x0, &(0x7f0000000000)="6121eed4cd50bb", 0x0, 0x29d, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2, 0x0, 0x2}, 0x50) 0s ago: executing program 6 (id=2474): openat$udambuf(0xffffffffffffff9c, 0x0, 0x2) memfd_create(&(0x7f0000000340)='y\x105\xfb\xf7u\x83%:r\xc2\xb9x\xa4q\xc1\xea_\x8cZ7\xe7a\x9b\x11x\x0e\xa1\xcf\x1a\x98S7\xc9\x00\x00\x00\x00\x00\x00\a\x00\x00\x00\x00\x00\x00\x04\x879\xa24\xa9am\xde\xb2\xd3\xcbZJoa\xc4\x1acB\xaa\xc1\xfb Q\xd4\xf4\x01\xa52\xe2DG\xd4\xbd{\x9f\xa9\x97\x9b@\xdb\x00b\xe1br\xb6\x008\xe3\x10\xff\xc2\x9d\r2\x9e\x8e\x04sW\x1b\xb7\xb3\xa2\xc9&@\xca\xda\xdc\xe2/\x97X\xac\b\xb0\xc2<\x80E\x1a\xbc\xc7W\xda9VsA\xaf\xc6\xcf\xe1\xa1\xb5M\xa2\x85\xa6y\xc4J\xf1\xf7\xfcD\x95\xe3\xeb\xc7\xbc\x91\xb0\xa8\x9eo\xebF(\x9dL\x01vRk\xaacB\x04\xa7I\v\x86EZ\x96\xd5\x14OD\\\xe8R\xe4\xcd\xec\xcc\xd1\x0fre\xe86\xcd\xeb\xc4$\x98\x06J\xd6dD\x8d_U`ji{\xab\x97\xaf;l\x1f\xaf\xb38U\xcb\xfa\xb3j\x92\f\x81\xa0\xa2-g\b\x99\x0e\x8d\x8d\x16\xd9w\\\xf8\xce\xb0j\x9d\'\x93\xef\x1d\xa0H\xd9\xbd\xd9\xaf\x12$\x8d\x16%\x8b\x00', 0x3) io_submit(0x0, 0x0, 0x0) syz_open_dev$vim2m(&(0x7f0000000000), 0x7, 0x2) sendmsg$key(0xffffffffffffffff, 0x0, 0x18) r0 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$PIO_SCRNMAP(r0, 0x4b41, &(0x7f00000016c0)) r1 = syz_init_net_socket$netrom(0x6, 0x5, 0x0) socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$sock_SIOCGIFINDEX(r2, 0x8933, &(0x7f0000000000)={'batadv_slave_0\x00'}) syz_init_net_socket$bt_sco(0x1f, 0x5, 0x2) setsockopt$ax25_SO_BINDTODEVICE(0xffffffffffffffff, 0x101, 0x19, &(0x7f0000000000)=@bpq0, 0xfffffffffffffe1d) ioctl$sock_netrom_SIOCADDRT(r1, 0x890b, &(0x7f0000000280)={0x1, @bcast, @bpq0, 0xfff4, 'syz0\x00', @netrom={0xbb, 0xbb, 0xbb, 0xbb, 0xbb, 0x0, 0x0}, 0x3ff, 0x2, [@null, @netrom={0xbb, 0xbb, 0xbb, 0xbb, 0xbb, 0x0, 0x0}, @null, @rose={0xbb, 0xbb, 0xbb, 0x1, 0x0}, @default, @default, @rose={0xbb, 0xbb, 0xbb, 0x1, 0x0}, @bcast]}) kernel console output (not intermixed with test programs): ysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 228.126916][ T8824] process 'syz.4.949' launched '/dev/fd/7' with NULL argv: empty string added [ 228.331310][ T30] audit: type=1400 audit(1743729635.637:371): avc: denied { execute_no_trans } for pid=8821 comm="syz.4.949" path=2F6D656D66643A2D42D54E49C56A9A707070F00884A26D202864656C6574656429 dev="tmpfs" ino=128 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 229.441579][ T8841] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 229.488035][ T8841] UDF-fs: Scanning with blocksize 512 failed [ 229.489512][ T5825] usb 4-1: new high-speed USB device number 5 using dummy_hcd [ 229.506925][ T8841] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 229.518076][ T8841] UDF-fs: Scanning with blocksize 1024 failed [ 229.541900][ T8841] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 229.550152][ T8841] UDF-fs: Scanning with blocksize 2048 failed [ 229.564860][ T8841] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 229.599739][ T8841] UDF-fs: Scanning with blocksize 4096 failed [ 229.704927][ T5825] usb 4-1: Using ep0 maxpacket: 32 [ 229.765438][ T5825] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 229.785347][ T5825] usb 4-1: config 0 interface 0 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 229.819132][ T5825] usb 4-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 3 [ 229.866995][ T5825] usb 4-1: New USB device found, idVendor=072f, idProduct=2200, bcdDevice=3f.bf [ 229.884549][ T5825] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 229.927650][ T5825] usb 4-1: Product: syz [ 229.938197][ T5825] usb 4-1: Manufacturer: syz [ 229.965945][ T5825] usb 4-1: SerialNumber: syz [ 230.028635][ T5825] usb 4-1: config 0 descriptor?? [ 230.043101][ T5825] pn533_usb 4-1:0.0: NFC: Could not find bulk-in or bulk-out endpoint [ 230.248036][ T5825] usb 4-1: USB disconnect, device number 5 [ 230.749814][ T8865] trusted_key: encrypted_key: insufficient parameters specified [ 230.789606][ T974] usb 2-1: new high-speed USB device number 7 using dummy_hcd [ 231.019356][ T974] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 231.096840][ T974] usb 2-1: New USB device found, idVendor=0471, idProduct=0304, bcdDevice=e4.df [ 231.125492][ T974] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 231.151501][ T974] usb 2-1: config 0 descriptor?? [ 231.166409][ T974] pwc: Askey VC010 type 2 USB webcam detected. [ 231.390956][ T8869] block nbd4: shutting down sockets [ 232.128434][ T974] pwc: recv_control_msg error -71 req 02 val 2700 [ 232.143388][ T974] pwc: recv_control_msg error -71 req 02 val 2c00 [ 232.194010][ T974] pwc: recv_control_msg error -71 req 04 val 1000 [ 232.227919][ T974] pwc: recv_control_msg error -71 req 04 val 1300 [ 232.287582][ T974] pwc: recv_control_msg error -71 req 04 val 1400 [ 232.326174][ T974] pwc: recv_control_msg error -71 req 02 val 2000 [ 232.376058][ T974] pwc: recv_control_msg error -71 req 02 val 2100 [ 232.493054][ T974] pwc: recv_control_msg error -71 req 04 val 1500 [ 232.920903][ T8889] overlayfs: "xino" feature enabled using 2 upper inode bits. [ 232.923465][ T974] pwc: recv_control_msg error -71 req 02 val 2500 [ 233.046120][ T974] pwc: recv_control_msg error -71 req 02 val 2400 [ 233.059961][ T974] pwc: recv_control_msg error -71 req 02 val 2600 [ 233.139546][ T974] pwc: recv_control_msg error -71 req 02 val 2900 [ 233.192547][ T974] pwc: recv_control_msg error -71 req 02 val 2800 [ 233.396321][ T974] pwc: recv_control_msg error -71 req 04 val 1100 [ 233.527190][ T974] pwc: recv_control_msg error -71 req 04 val 1200 [ 233.566336][ T974] pwc: Registered as video103. [ 233.586723][ T974] input: PWC snapshot button as /devices/platform/dummy_hcd.1/usb2/2-1/input/input6 [ 233.604373][ T974] usb 2-1: USB disconnect, device number 7 [ 233.609686][ T30] audit: type=1400 audit(1743729641.087:372): avc: denied { read } for pid=5182 comm="acpid" name="event4" dev="devtmpfs" ino=2795 scontext=system_u:system_r:acpid_t tcontext=system_u:object_r:device_t tclass=chr_file permissive=1 [ 233.657297][ T30] audit: type=1400 audit(1743729641.087:373): avc: denied { open } for pid=5182 comm="acpid" path="/dev/input/event4" dev="devtmpfs" ino=2795 scontext=system_u:system_r:acpid_t tcontext=system_u:object_r:device_t tclass=chr_file permissive=1 [ 233.686497][ T30] audit: type=1400 audit(1743729641.087:374): avc: denied { ioctl } for pid=5182 comm="acpid" path="/dev/input/event4" dev="devtmpfs" ino=2795 ioctlcmd=0x4520 scontext=system_u:system_r:acpid_t tcontext=system_u:object_r:device_t tclass=chr_file permissive=1 [ 233.812054][ T5908] usb 3-1: new high-speed USB device number 3 using dummy_hcd [ 233.969570][ T5908] usb 3-1: Using ep0 maxpacket: 32 [ 233.991066][ T5908] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 234.005906][ T5908] usb 3-1: config 0 interface 0 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 234.026824][ T5908] usb 3-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xE3, changing to 0x83 [ 234.041618][ T5908] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x83 has invalid wMaxPacketSize 0 [ 234.051696][ T5908] usb 3-1: config 0 interface 0 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 0 [ 234.061913][ T5908] usb 3-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 234.077030][ T5908] usb 3-1: New USB device found, idVendor=072f, idProduct=2200, bcdDevice=3f.bf [ 234.096654][ T5908] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 234.114867][ T5908] usb 3-1: Product: syz [ 234.124734][ T5908] usb 3-1: Manufacturer: syz [ 234.138835][ T5908] usb 3-1: SerialNumber: syz [ 234.193840][ T5908] usb 3-1: config 0 descriptor?? [ 234.203696][ T5908] pn533_usb 3-1:0.0: NFC: Could not find bulk-in or bulk-out endpoint [ 235.191585][ T30] audit: type=1400 audit(1743729641.877:375): avc: denied { connect } for pid=8908 comm="syz.1.978" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 235.226596][ T5908] usb 3-1: USB disconnect, device number 3 [ 237.073418][ T8929] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 238.363362][ T30] audit: type=1400 audit(1743729645.847:376): avc: denied { accept } for pid=8951 comm="syz.3.994" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 238.951201][ T30] audit: type=1400 audit(1743729646.437:377): avc: denied { ioctl } for pid=8961 comm="syz.2.997" path="socket:[21091]" dev="sockfs" ino=21091 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 239.584971][ T8966] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 239.685596][ T30] audit: type=1400 audit(1743729646.457:378): avc: denied { bind } for pid=8961 comm="syz.2.997" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 242.384044][ T9007] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 243.554372][ T9036] netlink: 12 bytes leftover after parsing attributes in process `syz.1.1024'. [ 243.568377][ T9036] vlan2: entered promiscuous mode [ 244.172466][ T9047] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 244.450869][ T9058] vhci_hcd vhci_hcd.0: pdev(4) rhport(0) sockfd(3) [ 244.457416][ T9058] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 245.048710][ T9058] vhci_hcd vhci_hcd.0: Device attached [ 245.296312][ T9059] vhci_hcd: connection closed [ 245.296652][ T6169] vhci_hcd: stop threads [ 245.315147][ T6169] vhci_hcd: release socket [ 245.329859][ T6169] vhci_hcd: disconnect device [ 245.339508][ T974] usb 41-1: new high-speed USB device number 2 using vhci_hcd [ 245.355113][ T974] usb 41-1: enqueue for inactive port 0 [ 245.541826][ T974] vhci_hcd: vhci_device speed not set [ 245.569703][ T9084] netlink: 12 bytes leftover after parsing attributes in process `syz.1.1041'. [ 245.773424][ T9084] vlan2: entered promiscuous mode [ 247.649827][ T9118] netlink: 908 bytes leftover after parsing attributes in process `syz.2.1054'. [ 248.367110][ T9123] fuse: Bad value for 'rootmode' [ 249.951705][ T5825] usb 2-1: new high-speed USB device number 8 using dummy_hcd [ 250.629582][ T5825] usb 2-1: Using ep0 maxpacket: 32 [ 250.642203][ T5825] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 250.695677][ T5825] usb 2-1: config 0 interface 0 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 250.714375][ T5825] usb 2-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xE3, changing to 0x83 [ 250.730343][ T5825] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x83 has invalid maxpacket 33307, setting to 1024 [ 250.742438][ T5825] usb 2-1: config 0 interface 0 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 1024 [ 250.752872][ T5825] usb 2-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 250.768349][ T5825] usb 2-1: New USB device found, idVendor=072f, idProduct=2200, bcdDevice=3f.bf [ 250.778329][ T5825] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 250.795548][ T5825] usb 2-1: Product: syz [ 250.800085][ T5825] usb 2-1: Manufacturer: syz [ 250.804681][ T5825] usb 2-1: SerialNumber: syz [ 250.990607][ T5825] usb 2-1: config 0 descriptor?? [ 250.996287][ T9147] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 251.044463][ T5825] pn533_usb 2-1:0.0: NFC: Could not find bulk-in or bulk-out endpoint [ 251.509976][ T9176] fuse: Unknown parameter 'user_i00000000000000000000' [ 251.559319][ T5825] usb 2-1: USB disconnect, device number 8 [ 252.868921][ T9209] ecryptfs_validate_options: You must supply at least one valid auth tok signature as a mount parameter; see the eCryptfs README [ 252.882485][ T9209] Error validating options; rc = [-22] [ 253.651479][ T971] IPVS: starting estimator thread 0... [ 253.820461][ T9223] IPVS: using max 40 ests per chain, 96000 per kthread [ 254.009692][ T5825] usb 3-1: new high-speed USB device number 4 using dummy_hcd [ 254.299533][ T5825] usb 3-1: Using ep0 maxpacket: 32 [ 254.307097][ T5825] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 254.634358][ T5825] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 254.653114][ T5825] usb 3-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 254.663427][ T5825] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 254.675479][ T5825] usb 3-1: config 0 descriptor?? [ 254.692232][ T5825] hub 3-1:0.0: USB hub found [ 255.103645][ T9246] vimc link validate: Scaler:src:640x480 (0x33424752, 8, 0, 0, 0) RGB/YUV Capture:snk:640x480 (0x33424752, 8, 0, 0, 0) [ 255.262982][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 255.269501][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 255.542213][ T9249] autofs: Unknown parameter './file1' [ 256.508673][ T5825] hub 3-1:0.0: config failed, can't read hub descriptor (err -22) [ 256.535509][ T5825] usbhid 3-1:0.0: can't add hid device: -71 [ 256.551673][ T5825] usbhid 3-1:0.0: probe with driver usbhid failed with error -71 [ 256.606245][ T5825] usb 3-1: USB disconnect, device number 4 [ 256.999460][ T9278] overlayfs: option "workdir=./bus" is useless in a non-upper mount, ignore [ 257.008384][ T9278] overlayfs: at least 2 lowerdir are needed while upperdir nonexistent [ 258.049750][ T974] usb 5-1: new high-speed USB device number 7 using dummy_hcd [ 258.216597][ T9300] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 258.282241][ T974] usb 5-1: Using ep0 maxpacket: 8 [ 258.296699][ T974] usb 5-1: config 1 interface 0 has no altsetting 0 [ 258.307597][ T974] usb 5-1: language id specifier not provided by device, defaulting to English [ 258.342725][ T974] usb 5-1: New USB device found, idVendor=046d, idProduct=c71f, bcdDevice= 0.40 [ 258.369715][ T974] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 258.380951][ T974] usb 5-1: Manufacturer: ᐉ [ 259.040388][ T974] usbhid 5-1:1.0: can't add hid device: -71 [ 259.056856][ T974] usbhid 5-1:1.0: probe with driver usbhid failed with error -71 [ 259.088236][ T974] usb 5-1: USB disconnect, device number 7 [ 259.319528][ T48] usb 4-1: new high-speed USB device number 6 using dummy_hcd [ 259.659555][ T24] usb 2-1: new high-speed USB device number 9 using dummy_hcd [ 259.692449][ T48] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 259.778663][ T48] usb 4-1: New USB device found, idVendor=0471, idProduct=0304, bcdDevice=e4.df [ 259.839552][ T24] usb 2-1: Using ep0 maxpacket: 32 [ 259.872805][ T48] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 259.909098][ T24] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 259.992111][ T48] usb 4-1: config 0 descriptor?? [ 260.004129][ T24] usb 2-1: config 0 interface 0 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 260.033638][ T48] pwc: Askey VC010 type 2 USB webcam detected. [ 260.057975][ T24] usb 2-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xE3, changing to 0x83 [ 260.070245][ T24] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x83 has invalid maxpacket 33307, setting to 1024 [ 260.084848][ T24] usb 2-1: config 0 interface 0 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 1024 [ 260.095069][ T24] usb 2-1: config 0 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 260.114579][ T24] usb 2-1: New USB device found, idVendor=072f, idProduct=2200, bcdDevice=3f.bf [ 260.138807][ T24] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 260.159192][ T24] usb 2-1: Product: syz [ 260.165225][ T24] usb 2-1: Manufacturer: syz [ 260.170378][ T24] usb 2-1: SerialNumber: syz [ 260.178507][ T24] usb 2-1: config 0 descriptor?? [ 260.185912][ T9322] raw-gadget.1 gadget.1: fail, usb_ep_enable returned -22 [ 260.194731][ T24] pn533_usb 2-1:0.0: NFC: Could not find bulk-in or bulk-out endpoint [ 260.247551][ T9339] wg1 speed is unknown, defaulting to 1000 [ 260.303342][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 260.425582][ T24] usb 2-1: USB disconnect, device number 9 [ 260.470164][ T48] pwc: recv_control_msg error -71 req 02 val 2b00 [ 260.483608][ T48] pwc: recv_control_msg error -71 req 02 val 2700 [ 260.510563][ T48] pwc: recv_control_msg error -71 req 02 val 2c00 [ 260.520710][ T48] pwc: recv_control_msg error -71 req 04 val 1000 [ 260.541940][ T48] pwc: recv_control_msg error -71 req 04 val 1300 [ 260.569502][ T48] pwc: recv_control_msg error -71 req 04 val 1400 [ 260.587419][ T48] pwc: recv_control_msg error -71 req 02 val 2000 [ 260.593812][ T56] Bluetooth: hci4: SCO packet for unknown connection handle 200 [ 260.600417][ T48] pwc: recv_control_msg error -71 req 02 val 2100 [ 260.728874][ T48] pwc: recv_control_msg error -71 req 04 val 1500 [ 260.739780][ T48] pwc: recv_control_msg error -71 req 02 val 2500 [ 260.759829][ T48] pwc: recv_control_msg error -71 req 02 val 2400 [ 260.797662][ T48] pwc: recv_control_msg error -71 req 02 val 2600 [ 260.831688][ T48] pwc: recv_control_msg error -71 req 02 val 2900 [ 261.356806][ T48] pwc: recv_control_msg error -71 req 02 val 2800 [ 261.479267][ T48] pwc: recv_control_msg error -71 req 04 val 1100 [ 261.574238][ T48] pwc: recv_control_msg error -71 req 04 val 1200 [ 261.679022][ T48] pwc: Registered as video103. [ 261.807332][ T48] input: PWC snapshot button as /devices/platform/dummy_hcd.3/usb4/4-1/input/input7 [ 262.148409][ T48] usb 4-1: USB disconnect, device number 6 [ 262.813578][ T9373] netlink: 16 bytes leftover after parsing attributes in process `syz.3.1140'. [ 263.059723][ T9376] netlink: 28 bytes leftover after parsing attributes in process `syz.0.1143'. [ 263.080503][ T9376] netlink: 28 bytes leftover after parsing attributes in process `syz.0.1143'. [ 263.221497][ T9376] netdevsim netdevsim0 netdevsim0: entered promiscuous mode [ 263.260921][ T9376] bridge0: entered promiscuous mode [ 266.799589][ T48] usb 5-1: new high-speed USB device number 8 using dummy_hcd [ 267.149478][ T48] usb 5-1: Using ep0 maxpacket: 32 [ 267.162447][ T48] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 267.174116][ T48] usb 5-1: config 0 interface 0 altsetting 0 has an invalid descriptor for endpoint zero, skipping [ 267.187059][ T48] usb 5-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xE3, changing to 0x83 [ 267.199248][ T48] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x83 has invalid maxpacket 33307, setting to 1024 [ 267.210688][ T48] usb 5-1: config 0 interface 0 altsetting 0 bulk endpoint 0x83 has invalid maxpacket 1024 [ 267.220992][ T48] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0xB has invalid wMaxPacketSize 0 [ 267.233196][ T48] usb 5-1: New USB device found, idVendor=072f, idProduct=2200, bcdDevice=3f.bf [ 267.242588][ T48] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 267.250879][ T48] usb 5-1: Product: syz [ 267.255107][ T48] usb 5-1: Manufacturer: syz [ 267.260081][ T48] usb 5-1: SerialNumber: syz [ 267.266803][ T48] usb 5-1: config 0 descriptor?? [ 267.274187][ T9404] raw-gadget.0 gadget.4: fail, usb_ep_enable returned -22 [ 267.283303][ T48] pn533_usb 5-1:0.0: NFC: Could not find bulk-in or bulk-out endpoint [ 267.397299][ T5908] usb 3-1: new high-speed USB device number 5 using dummy_hcd [ 268.455793][ T974] usb 5-1: USB disconnect, device number 8 [ 268.529536][ T5908] usb 3-1: Using ep0 maxpacket: 32 [ 268.536709][ T5908] usb 3-1: config 0 has an invalid interface number: 12 but max is 0 [ 268.549481][ T5908] usb 3-1: config 0 has no interface number 0 [ 268.569537][ T5908] usb 3-1: config 0 interface 12 has no altsetting 0 [ 268.593818][ T5908] usb 3-1: New USB device found, idVendor=2c42, idProduct=1202, bcdDevice=85.40 [ 268.617488][ T5908] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 268.639907][ T5908] usb 3-1: Product: syz [ 268.644101][ T5908] usb 3-1: Manufacturer: syz [ 268.650086][ T5908] usb 3-1: SerialNumber: syz [ 268.690910][ T5908] usb 3-1: config 0 descriptor?? [ 268.734049][ T9437] bridge_slave_0: left allmulticast mode [ 268.751458][ T9437] bridge_slave_0: left promiscuous mode [ 268.771404][ T9437] bridge0: port 1(bridge_slave_0) entered disabled state [ 268.783410][ T30] audit: type=1400 audit(1743729676.257:379): avc: denied { read } for pid=9436 comm="syz.0.1161" path="socket:[22077]" dev="sockfs" ino=22077 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rawip_socket permissive=1 [ 268.886395][ T9437] bridge_slave_1: left allmulticast mode [ 268.897806][ T9437] bridge_slave_1: left promiscuous mode [ 268.948371][ T9437] bridge0: port 2(bridge_slave_1) entered disabled state [ 268.969091][ T9437] bond0: (slave bond_slave_0): Releasing backup interface [ 268.988294][ T9437] bond0: (slave bond_slave_1): Releasing backup interface [ 269.019114][ T9437] team0: Port device team_slave_0 removed [ 269.032298][ T9437] team0: Port device team_slave_1 removed [ 269.042320][ T9437] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 269.052930][ T9437] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 269.063125][ T9437] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 269.074704][ T9437] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 269.112558][ T971] wg1 speed is unknown, defaulting to 1000 [ 269.470793][ T9440] Bluetooth: hci0: Opcode 0x0c03 failed: -4 [ 270.586859][ T9459] vimc link validate: Scaler:src:640x480 (0x33424752, 8, 0, 0, 0) RGB/YUV Capture:snk:640x480 (0x33424752, 8, 0, 0, 0) [ 270.633550][ T5908] f81534 3-1:0.12: f81534_get_register: reg: 1003 failed: -71 [ 270.746408][ T5908] f81534 3-1:0.12: f81534_find_config_idx: read failed: -71 [ 270.759733][ T5908] f81534 3-1:0.12: f81534_calc_num_ports: find idx failed: -71 [ 270.769619][ T5908] f81534 3-1:0.12: probe with driver f81534 failed with error -71 [ 270.790871][ T5908] usb 3-1: USB disconnect, device number 5 [ 270.892219][ T30] audit: type=1400 audit(1743729678.367:380): avc: denied { listen } for pid=9462 comm="syz.2.1169" lport=20003 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=dccp_socket permissive=1 [ 271.267592][ T9462] dccp_close: ABORT with 32 bytes unread [ 271.314933][ T30] audit: type=1400 audit(1743729678.377:381): avc: denied { accept } for pid=9462 comm="syz.2.1169" lport=20003 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=dccp_socket permissive=1 [ 271.422569][ T30] audit: type=1400 audit(1743729678.377:382): avc: denied { write } for pid=9462 comm="syz.2.1169" laddr=::ffff:127.0.0.1 lport=20003 faddr=::ffff:127.0.0.1 fport=37398 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=dccp_socket permissive=1 [ 271.448098][ T30] audit: type=1400 audit(1743729678.377:383): avc: denied { read } for pid=9462 comm="syz.2.1169" laddr=::ffff:127.0.0.1 lport=20003 faddr=::ffff:127.0.0.1 fport=37398 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=dccp_socket permissive=1 [ 271.624473][ T9483] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 272.382145][ T9501] vimc link validate: Scaler:src:640x480 (0x33424752, 8, 0, 0, 0) RGB/YUV Capture:snk:640x480 (0x33424752, 8, 0, 0, 0) [ 272.859126][ T9498] Bluetooth: hci0: Opcode 0x0c03 failed: -4 [ 275.116723][ T9558] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 277.259166][ T9589] Unsupported ieee802154 address type: 0 [ 277.609492][ T30] audit: type=1400 audit(1743729684.737:384): avc: denied { bind } for pid=9583 comm="syz.1.1213" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 278.257066][ T9613] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 278.264754][ T9613] UDF-fs: Scanning with blocksize 512 failed [ 278.273509][ T9613] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 278.281163][ T9613] UDF-fs: Scanning with blocksize 1024 failed [ 278.338535][ T9613] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 278.353324][ T9613] UDF-fs: Scanning with blocksize 2048 failed [ 278.373253][ T9613] UDF-fs: warning (device nullb0): udf_load_vrs: No VRS found [ 278.381082][ T9613] UDF-fs: Scanning with blocksize 4096 failed [ 283.134318][ T9683] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1244'. [ 283.169218][ T9683] vlan2: entered promiscuous mode [ 283.800080][ T30] audit: type=1326 audit(1743729691.127:385): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9694 comm="syz.2.1247" exe="/root/syz-executor" sig=31 arch=c000003e syscall=202 compat=0 ip=0x7f6013d8d169 code=0x0 [ 285.045104][ T30] audit: type=1400 audit(1743729692.087:386): avc: denied { shutdown } for pid=9710 comm="syz.1.1256" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 286.659503][ T974] usb 5-1: new high-speed USB device number 9 using dummy_hcd [ 286.678066][ T9744] syz.3.1266: attempt to access beyond end of device [ 286.678066][ T9744] nbd3: rw=0, sector=2, nr_sectors = 2 limit=0 [ 286.829566][ T974] usb 5-1: Using ep0 maxpacket: 16 [ 286.848100][ T974] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 286.874302][ T974] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 286.892996][ T974] usb 5-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 286.904948][ T974] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 286.941837][ T974] usb 5-1: config 0 descriptor?? [ 286.989104][ T9] hid-generic 0000:0000:0000.0005: unknown main item tag 0x0 [ 287.149547][ T9] hid-generic 0000:0000:0000.0005: hidraw0: HID v0.00 Device [syz1] on syz0 [ 287.275136][ T30] audit: type=1400 audit(1743729694.757:387): avc: denied { name_connect } for pid=9749 comm="syz.3.1269" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:port_t tclass=sctp_socket permissive=1 [ 287.540267][ T974] konepure 0003:1E7D:2DB4.0006: unknown main item tag 0x0 [ 287.547961][ T974] konepure 0003:1E7D:2DB4.0006: unknown main item tag 0x0 [ 287.559831][ T974] konepure 0003:1E7D:2DB4.0006: unknown main item tag 0x0 [ 287.569243][ T974] konepure 0003:1E7D:2DB4.0006: unknown main item tag 0x0 [ 287.702145][ T974] konepure 0003:1E7D:2DB4.0006: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.4-1/input0 [ 287.752525][ T9737] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 287.771350][ T9737] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 288.426641][ T9] usb 5-1: USB disconnect, device number 9 [ 289.310349][ T30] audit: type=1400 audit(1743729696.547:388): avc: denied { write } for pid=9774 comm="syz.1.1276" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 290.939006][ T30] audit: type=1400 audit(1743729698.417:389): avc: denied { setopt } for pid=9821 comm="syz.0.1293" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=dccp_socket permissive=1 [ 291.412986][ T9833] vlan2: entered promiscuous mode [ 291.418188][ T9833] bond0: entered promiscuous mode [ 291.518098][ T9838] fuse: Unknown parameter 'fd0x0000000000000004' [ 291.646818][ T9840] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 292.503662][ T30] audit: type=1400 audit(1743729699.987:390): avc: denied { create } for pid=9852 comm="syz.2.1303" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_iscsi_socket permissive=1 [ 292.560964][ T30] audit: type=1400 audit(1743729700.007:391): avc: denied { write } for pid=9852 comm="syz.2.1303" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_iscsi_socket permissive=1 [ 292.790890][ T6813] bridge0: port 2(bridge_slave_1) entered disabled state [ 293.072220][ T9864] program syz.4.1307 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 293.104501][ T30] audit: type=1400 audit(1743729700.557:392): avc: denied { append } for pid=9862 comm="syz.4.1307" name="sg0" dev="devtmpfs" ino=749 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 293.130820][ T9867] fuse: Unknown parameter 'fd0x0000000000000004' [ 293.345287][ T9873] syz.4.1310: attempt to access beyond end of device [ 293.345287][ T9873] nbd4: rw=0, sector=2, nr_sectors = 2 limit=0 [ 293.557979][ T9883] netlink: 'syz.1.1315': attribute type 1 has an invalid length. [ 293.605987][ T9886] netlink: 8 bytes leftover after parsing attributes in process `syz.4.1316'. [ 293.619214][ T9879] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 293.661383][ T971] IPVS: starting estimator thread 0... [ 293.759907][ T9889] IPVS: using max 46 ests per chain, 110400 per kthread [ 295.689585][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 296.557803][ T9938] syz.4.1334: attempt to access beyond end of device [ 296.557803][ T9938] nbd4: rw=0, sector=2, nr_sectors = 2 limit=0 [ 297.292015][ T9952] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 297.825029][ T9955] wg1 speed is unknown, defaulting to 1000 [ 297.829773][ T56] Bluetooth: hci3: command 0x0406 tx timeout [ 298.139506][ T30] audit: type=1400 audit(1743729705.547:393): avc: denied { mounton } for pid=9956 comm="syz.2.1341" path="/281/file0" dev="fuse" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fusefs_t tclass=file permissive=1 [ 298.176284][ T30] audit: type=1400 audit(1743729705.657:394): avc: denied { mount } for pid=9956 comm="syz.2.1341" name="/" dev="9p" ino=2 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 298.555534][ T30] audit: type=1400 audit(1743729706.037:395): avc: denied { unmount } for pid=5821 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 301.110416][T10003] netlink: 16 bytes leftover after parsing attributes in process `syz.4.1355'. [ 301.472741][T10015] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 302.081868][ T30] audit: type=1400 audit(1743729709.547:396): avc: denied { write } for pid=10027 comm="syz.4.1360" name="001" dev="devtmpfs" ino=745 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usb_device_t tclass=chr_file permissive=1 [ 302.254713][T10033] netlink: 'syz.4.1360': attribute type 10 has an invalid length. [ 302.262713][T10033] netlink: 40 bytes leftover after parsing attributes in process `syz.4.1360'. [ 302.321319][T10033] team0: Port device geneve0 added [ 303.361744][ T5825] usb 4-1: new high-speed USB device number 7 using dummy_hcd [ 303.377473][ T30] audit: type=1400 audit(1743729710.857:397): avc: denied { ioctl } for pid=10056 comm="syz.0.1369" path="/dev/vhost-net" dev="devtmpfs" ino=1274 ioctlcmd=0xaf01 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:vhost_device_t tclass=chr_file permissive=1 [ 303.504007][T10064] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 303.549597][ T5825] usb 4-1: Using ep0 maxpacket: 16 [ 303.557977][ T5825] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 303.576014][ T5825] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 303.591648][ T5825] usb 4-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 303.601371][ T5825] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 303.607759][T10066] batman_adv: Cannot find parent device. Skipping batadv-on-batadv check for ip6gretap1 [ 303.631115][ T5825] usb 4-1: config 0 descriptor?? [ 303.632998][T10066] batman_adv: batadv0: Adding interface: ip6gretap1 [ 303.643196][T10066] batman_adv: batadv0: The MTU of interface ip6gretap1 is too small (1434) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 303.668881][T10066] batman_adv: batadv0: Interface activated: ip6gretap1 [ 304.437320][ T5825] konepure 0003:1E7D:2DB4.0007: unknown main item tag 0x0 [ 304.466154][ T5825] konepure 0003:1E7D:2DB4.0007: unknown main item tag 0x0 [ 304.478108][ T5825] konepure 0003:1E7D:2DB4.0007: unknown main item tag 0x0 [ 304.488696][ T5825] konepure 0003:1E7D:2DB4.0007: unknown main item tag 0x0 [ 304.510310][ T5825] konepure 0003:1E7D:2DB4.0007: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.3-1/input0 [ 304.650282][T10068] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 304.694737][T10068] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 306.161154][ T9] usb 4-1: USB disconnect, device number 7 [ 306.533849][T10109] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1383'. [ 307.054395][T10118] 9pnet_fd: Insufficient options for proto=fd [ 307.326991][ T30] audit: type=1400 audit(1743729714.527:398): avc: denied { read write } for pid=10112 comm="syz.1.1387" name="cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 307.497534][ T30] audit: type=1400 audit(1743729714.527:399): avc: denied { open } for pid=10112 comm="syz.1.1387" path="/dev/cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 307.642909][T10126] No control pipe specified [ 310.539177][T10171] netlink: 16 bytes leftover after parsing attributes in process `syz.4.1407'. [ 311.045025][T10191] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 311.336823][T10194] wg1 speed is unknown, defaulting to 1000 [ 311.593271][T10183] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 313.912952][T10228] program syz.0.1424 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 314.034742][T10239] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 315.039154][T10259] netlink: 16 bytes leftover after parsing attributes in process `syz.0.1433'. [ 315.557815][T10269] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1439'. [ 315.635635][T10273] program syz.0.1438 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 315.791096][T10269] syz.3.1439: attempt to access beyond end of device [ 315.791096][T10269] nbd3: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 315.805042][T10269] SQUASHFS error: Failed to read block 0x0: -5 [ 315.811226][T10269] unable to read squashfs_super_block [ 315.821884][ T30] audit: type=1400 audit(1743729723.267:400): avc: denied { view } for pid=10268 comm="syz.3.1439" scontext=root:sysadm_r:sysadm_t tcontext=system_u:system_r:kernel_t tclass=key permissive=1 [ 316.659961][T10290] netlink: 16 bytes leftover after parsing attributes in process `syz.3.1445'. [ 316.709293][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 316.716011][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 316.736242][T10292] netlink: 'syz.2.1446': attribute type 1 has an invalid length. [ 316.767273][T10292] 8021q: adding VLAN 0 to HW filter on device bond1 [ 316.824989][T10292] bond1: (slave gretap1): making interface the new active one [ 317.011160][T10292] bond1: (slave gretap1): Enslaving as an active interface with an up link [ 318.056225][T10323] netlink: 16 bytes leftover after parsing attributes in process `syz.1.1457'. [ 318.180410][T10327] siw: device registration error -23 [ 318.266282][T10331] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 318.300723][ T5839] Bluetooth: hci4: command 0x0406 tx timeout [ 320.728292][T10365] netlink: 16 bytes leftover after parsing attributes in process `syz.1.1469'. [ 321.964889][ T6799] bridge0: port 2(bridge_slave_1) entered disabled state [ 322.300093][ T971] usb 4-1: new high-speed USB device number 8 using dummy_hcd [ 322.679549][ T971] usb 4-1: Using ep0 maxpacket: 16 [ 322.734123][ T971] usb 4-1: config 0 has 0 interfaces, different from the descriptor's value: 1 [ 322.826348][ T971] usb 4-1: New USB device found, idVendor=0471, idProduct=0327, bcdDevice=61.a4 [ 322.858409][ T971] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 322.937629][ T971] usb 4-1: config 0 descriptor?? [ 323.616434][ T30] audit: type=1400 audit(1743729731.097:401): avc: denied { map } for pid=10412 comm="syz.1.1485" path="socket:[26205]" dev="sockfs" ino=26205 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 323.723198][ T30] audit: type=1400 audit(1743729731.097:402): avc: denied { read } for pid=10412 comm="syz.1.1485" path="socket:[26205]" dev="sockfs" ino=26205 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 324.808290][ T971] usb 4-1: USB disconnect, device number 8 [ 325.545820][T10442] autofs: Unknown parameter '0x0000000000000000' [ 325.649514][ T5875] usb 4-1: new high-speed USB device number 9 using dummy_hcd [ 325.789766][T10444] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 326.349440][ T5875] usb 4-1: Using ep0 maxpacket: 32 [ 326.367405][ T5875] usb 4-1: New USB device found, idVendor=0e41, idProduct=414d, bcdDevice=82.8d [ 326.387913][ T5875] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 326.408143][ T5875] usb 4-1: Product: syz [ 326.422292][ T5875] usb 4-1: Manufacturer: syz [ 326.434218][ T5875] usb 4-1: SerialNumber: syz [ 326.645918][T10460] netlink: 'syz.2.1497': attribute type 1 has an invalid length. [ 326.649622][ T5875] usb 4-1: config 0 descriptor?? [ 326.675575][T10460] 8021q: adding VLAN 0 to HW filter on device bond2 [ 326.699196][ T5875] snd_usb_podhd 4-1:0.0: Line 6 POD HD500 found [ 326.744942][ T5875] usb 4-1: selecting invalid altsetting 1 [ 326.773652][ T5875] snd_usb_podhd 4-1:0.0: set_interface failed [ 326.873839][ T5875] snd_usb_podhd 4-1:0.0: Line 6 POD HD500 now disconnected [ 326.886924][ T5875] snd_usb_podhd 4-1:0.0: probe with driver snd_usb_podhd failed with error -22 [ 326.966653][ T5875] usb 4-1: USB disconnect, device number 9 [ 328.059684][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 328.350872][T10491] netlink: 16 bytes leftover after parsing attributes in process `syz.3.1507'. [ 328.529961][T10494] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 328.650764][T10493] siw: device registration error -23 [ 330.065670][ T6174] bridge0: port 2(bridge_slave_1) entered disabled state [ 330.629484][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 330.893328][T10526] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 331.967176][T10536] overlayfs: missing 'lowerdir' [ 332.850119][T10544] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1522'. [ 336.711718][T10594] netlink: 16 bytes leftover after parsing attributes in process `syz.0.1536'. [ 337.429640][ T5825] usb 5-1: new high-speed USB device number 10 using dummy_hcd [ 337.589555][ T5825] usb 5-1: Using ep0 maxpacket: 32 [ 337.600404][ T5825] usb 5-1: config 127 has an invalid interface number: 36 but max is 1 [ 337.628926][ T5825] usb 5-1: config 127 has an invalid interface number: 51 but max is 1 [ 337.657817][ T5825] usb 5-1: config 127 has an invalid descriptor of length 133, skipping remainder of the config [ 337.678668][ T5825] usb 5-1: config 127 has 3 interfaces, different from the descriptor's value: 2 [ 337.698075][ T5825] usb 5-1: config 127 has no interface number 0 [ 337.722449][ T5825] usb 5-1: config 127 has no interface number 2 [ 337.758271][ T5825] usb 5-1: config 127 interface 36 altsetting 250 endpoint 0x86 has invalid maxpacket 512, setting to 64 [ 337.782445][ T5825] usb 5-1: config 127 interface 36 altsetting 250 has an endpoint descriptor with address 0xD2, changing to 0x82 [ 337.807967][ T5825] usb 5-1: config 127 interface 36 altsetting 250 endpoint 0x82 has invalid maxpacket 4552, setting to 64 [ 337.828668][ T5825] usb 5-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 337.840192][ T5825] usb 5-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 337.851595][ T5825] usb 5-1: config 127 interface 36 altsetting 250 has 9 endpoint descriptors, different from the interface descriptor's value: 8 [ 337.865472][ T5825] usb 5-1: config 127 interface 51 altsetting 2 has 0 endpoint descriptors, different from the interface descriptor's value: 8 [ 337.897832][ T5825] usb 5-1: too many endpoints for config 127 interface 1 altsetting 249: 97, using maximum allowed: 30 [ 337.910077][ T5825] usb 5-1: config 127 interface 1 altsetting 249 has 0 endpoint descriptors, different from the interface descriptor's value: 97 [ 337.923898][ T5825] usb 5-1: config 127 interface 36 has no altsetting 0 [ 337.931055][ T5825] usb 5-1: config 127 interface 51 has no altsetting 0 [ 337.938091][ T5825] usb 5-1: config 127 interface 1 has no altsetting 0 [ 337.964226][ T5825] usb 5-1: New USB device found, idVendor=1410, idProduct=a005, bcdDevice=53.d4 [ 337.983614][ T5825] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 338.172534][T10610] siw: device registration error -23 [ 338.954522][ T5825] usb 5-1: Product: syz [ 338.958712][ T5825] usb 5-1: Manufacturer: syz [ 338.963372][ T5825] usb 5-1: SerialNumber: syz [ 339.511852][ T5825] usb 5-1: USB disconnect, device number 10 [ 339.648372][T10629] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 340.055171][T10634] wg1 speed is unknown, defaulting to 1000 [ 340.644805][T10640] netlink: 28 bytes leftover after parsing attributes in process `syz.3.1549'. [ 342.223595][ T30] audit: type=1400 audit(1743729749.707:403): avc: denied { execute } for pid=10668 comm="syz.4.1558" path="/dev/dsp" dev="devtmpfs" ino=1285 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:sound_device_t tclass=chr_file permissive=1 [ 342.387606][ T30] audit: type=1400 audit(1743729749.867:404): avc: denied { read write } for pid=10668 comm="syz.4.1558" name="mouse0" dev="devtmpfs" ino=1000 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:mouse_device_t tclass=chr_file permissive=1 [ 342.885471][ T30] audit: type=1400 audit(1743729749.907:405): avc: denied { open } for pid=10668 comm="syz.4.1558" path="/dev/input/mouse0" dev="devtmpfs" ino=1000 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:mouse_device_t tclass=chr_file permissive=1 [ 342.909635][ C0] vkms_vblank_simulate: vblank timer overrun [ 342.931596][T10673] siw: device registration error -23 [ 343.156580][T10684] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1559'. [ 343.420715][T10689] netlink: 'syz.4.1562': attribute type 1 has an invalid length. [ 343.689217][T10689] 8021q: adding VLAN 0 to HW filter on device bond1 [ 343.972072][T10702] netlink: 'syz.0.1565': attribute type 10 has an invalid length. [ 343.980101][T10702] netlink: 40 bytes leftover after parsing attributes in process `syz.0.1565'. [ 344.077408][T10702] team0: Port device geneve0 added [ 344.192084][T10708] batman_adv: Cannot find parent device. Skipping batadv-on-batadv check for ip6gretap1 [ 344.311221][T10708] batman_adv: batadv0: Adding interface: ip6gretap1 [ 344.319288][T10708] batman_adv: batadv0: The MTU of interface ip6gretap1 is too small (1434) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 344.784079][T10708] batman_adv: batadv0: Interface activated: ip6gretap1 [ 346.326078][T10728] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1572'. [ 346.758534][T10740] netlink: 'syz.0.1578': attribute type 1 has an invalid length. [ 346.914814][T10740] 8021q: adding VLAN 0 to HW filter on device bond1 [ 348.705894][T10772] syz.3.1586: attempt to access beyond end of device [ 348.705894][T10772] nbd3: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 348.718914][T10772] SQUASHFS error: Failed to read block 0x0: -5 [ 348.725289][T10772] unable to read squashfs_super_block [ 349.719580][ T24] usb 3-1: new high-speed USB device number 6 using dummy_hcd [ 349.850516][T10789] netlink: 'syz.4.1589': attribute type 10 has an invalid length. [ 349.858463][T10789] netlink: 40 bytes leftover after parsing attributes in process `syz.4.1589'. [ 349.909447][ T24] usb 3-1: Using ep0 maxpacket: 16 [ 349.936664][ T24] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 349.976127][ T24] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 350.129655][ T24] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 350.264076][ T24] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 350.305416][ T24] usb 3-1: config 0 descriptor?? [ 351.109569][ T24] konepure 0003:1E7D:2DB4.0008: unknown main item tag 0x0 [ 351.122414][ T24] konepure 0003:1E7D:2DB4.0008: unknown main item tag 0x0 [ 351.135299][ T24] konepure 0003:1E7D:2DB4.0008: unknown main item tag 0x0 [ 351.143732][ T24] konepure 0003:1E7D:2DB4.0008: unknown main item tag 0x0 [ 351.179294][ T24] konepure 0003:1E7D:2DB4.0008: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.2-1/input0 [ 351.269289][T10814] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 351.369960][T10814] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 351.649802][ T30] audit: type=1400 audit(1743729759.127:406): avc: denied { setopt } for pid=10802 comm="syz.1.1599" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 351.974902][T10821] syz.4.1603: attempt to access beyond end of device [ 351.974902][T10821] nbd4: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 351.987973][T10821] SQUASHFS error: Failed to read block 0x0: -5 [ 351.994287][T10821] unable to read squashfs_super_block [ 352.563904][ T971] usb 3-1: USB disconnect, device number 6 [ 354.657368][T10869] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 354.669391][T10869] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 354.679302][T10869] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 354.689972][T10869] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 354.700007][T10869] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 354.710588][T10869] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 355.792932][T10885] Unsupported ieee802154 address type: 0 [ 356.457848][ T30] audit: type=1400 audit(1743729763.917:407): avc: denied { ioctl } for pid=10891 comm="syz.3.1626" path="/dev/input/mouse0" dev="devtmpfs" ino=1000 ioctlcmd=0x3b81 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:mouse_device_t tclass=chr_file permissive=1 [ 358.814432][T10931] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1637'. [ 358.828794][T10931] vlan2: entered promiscuous mode [ 358.835349][T10931] team0: entered promiscuous mode [ 358.840850][T10931] team_slave_0: entered promiscuous mode [ 358.848002][T10931] team_slave_1: entered promiscuous mode [ 359.390174][T10943] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 360.239842][T10950] netlink: 'syz.1.1643': attribute type 13 has an invalid length. [ 360.376161][T10953] ======================================================= [ 360.376161][T10953] WARNING: The mand mount option has been deprecated and [ 360.376161][T10953] and is ignored by this kernel. Remove the mand [ 360.376161][T10953] option from the mount to silence this warning. [ 360.376161][T10953] ======================================================= [ 360.411762][T10953] MTD: Attempt to mount non-MTD device "/dev/nullb0" [ 360.422756][T10953] VFS: Can't find a romfs filesystem on dev nullb0. [ 360.422756][T10953] [ 360.445195][ T5902] usb 3-1: new high-speed USB device number 7 using dummy_hcd [ 360.609512][ T5902] usb 3-1: Using ep0 maxpacket: 16 [ 360.645511][ T5902] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 360.684776][ T5902] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 360.716597][T10950] bridge0: port 1(bridge_slave_0) entered disabled state [ 360.725546][ T5902] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 360.743283][ T5902] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 360.764807][ T5902] usb 3-1: config 0 descriptor?? [ 360.877254][ T30] audit: type=1400 audit(1743729768.357:408): avc: denied { write } for pid=10954 comm="syz.3.1644" name="random" dev="devtmpfs" ino=8 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:random_device_t tclass=chr_file permissive=1 [ 360.949147][ T30] audit: type=1400 audit(1743729768.427:409): avc: denied { create } for pid=10956 comm="syz.3.1645" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 360.978045][ T30] audit: type=1400 audit(1743729768.457:410): avc: denied { connect } for pid=10956 comm="syz.3.1645" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 361.003133][ T30] audit: type=1400 audit(1743729768.457:411): avc: denied { setopt } for pid=10956 comm="syz.3.1645" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 361.025271][T10950] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 361.275024][T10950] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 361.841880][T10959] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 361.913430][T10959] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 362.456895][T10950] netdevsim netdevsim1 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 362.485235][T10950] netdevsim netdevsim1 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 362.525029][T10950] netdevsim netdevsim1 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 362.566406][T10950] netdevsim netdevsim1 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 362.678283][ T30] audit: type=1400 audit(1743729770.137:412): avc: denied { read } for pid=10956 comm="syz.3.1645" scontext=root:sysadm_r:sysadm_t tcontext=system_u:system_r:kernel_t tclass=key permissive=1 [ 362.679476][ T5902] usbhid 3-1:0.0: can't add hid device: -71 [ 362.705561][ T5902] usbhid 3-1:0.0: probe with driver usbhid failed with error -71 [ 362.721841][ T5902] usb 3-1: USB disconnect, device number 7 [ 362.753135][T10950] batman_adv: batadv0: Interface deactivated: ip6gretap1 [ 363.237462][ T30] audit: type=1400 audit(1743729770.717:413): avc: denied { ioctl } for pid=10969 comm="syz.2.1648" path="socket:[27491]" dev="sockfs" ino=27491 ioctlcmd=0x8949 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 363.262857][T10972] sctp: [Deprecated]: syz.2.1648 (pid 10972) Use of int in max_burst socket option deprecated. [ 363.262857][T10972] Use struct sctp_assoc_value instead [ 363.710031][T10904] Set syz1 is full, maxelem 65536 reached [ 364.318635][T10994] netlink: 'syz.2.1657': attribute type 13 has an invalid length. [ 364.416656][T10994] bridge0: port 1(bridge_slave_0) entered disabled state [ 364.513766][T10994] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 364.539022][T10994] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 364.682071][T10994] netdevsim netdevsim2 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 364.692826][T10994] netdevsim netdevsim2 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 364.708646][T10994] netdevsim netdevsim2 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 364.736392][T10994] netdevsim netdevsim2 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 364.791904][T10994] batman_adv: batadv0: Interface deactivated: ip6gretap1 [ 365.593399][T11002] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 365.932337][ T5902] usb 5-1: new high-speed USB device number 11 using dummy_hcd [ 365.966588][T11002] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 366.639784][ T5902] usb 5-1: Using ep0 maxpacket: 16 [ 366.770864][T11010] netlink: 12 bytes leftover after parsing attributes in process `syz.1.1661'. [ 366.787582][ T5902] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 366.800116][ T5902] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 366.812179][T11010] netlink: 12 bytes leftover after parsing attributes in process `syz.1.1661'. [ 366.822168][ T5902] usb 5-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 366.839556][ T5902] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 367.330257][ T5902] usb 5-1: config 0 descriptor?? [ 367.821872][T11021] wg1 speed is unknown, defaulting to 1000 [ 368.632090][T11000] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 368.656886][T11000] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 368.687218][ T5902] usbhid 5-1:0.0: can't add hid device: -71 [ 368.697722][ T5902] usbhid 5-1:0.0: probe with driver usbhid failed with error -71 [ 368.992352][ T5902] usb 5-1: USB disconnect, device number 11 [ 370.042772][T11042] netlink: 'syz.2.1670': attribute type 13 has an invalid length. [ 370.798714][T11052] siw: device registration error -23 [ 372.054067][T11077] netlink: 'syz.2.1683': attribute type 13 has an invalid length. [ 372.488764][T11020] Set syz1 is full, maxelem 65536 reached [ 373.676282][T11098] netlink: 'syz.0.1691': attribute type 1 has an invalid length. [ 374.247454][ T5825] usb 4-1: new full-speed USB device number 10 using dummy_hcd [ 374.441682][ T5825] usb 4-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 374.485309][ T5825] usb 4-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 374.534683][ T5825] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 374.575594][ T5825] usb 4-1: Product: syz [ 374.591855][ T5825] usb 4-1: Manufacturer: syz [ 374.607387][ T5825] usb 4-1: SerialNumber: syz [ 375.764657][T11120] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 375.904141][T11119] wg1 speed is unknown, defaulting to 1000 [ 377.800537][ T5825] usb 4-1: selecting invalid altsetting 1 [ 377.848359][ T5825] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 377.848451][ T5825] dvb_usb_lmedm04 4-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 377.929686][ T5825] usb 4-1: USB disconnect, device number 10 [ 378.143538][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 378.150073][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 380.099507][ T5825] usb 3-1: new high-speed USB device number 8 using dummy_hcd [ 380.269463][ T5825] usb 3-1: Using ep0 maxpacket: 16 [ 380.281654][ T5825] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 380.309514][ T5825] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 380.320033][ T5825] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 380.332819][ T5825] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 380.349714][ T5825] usb 3-1: config 0 descriptor?? [ 380.437816][T11177] netlink: 'syz.4.1714': attribute type 10 has an invalid length. [ 380.446183][T11177] netlink: 40 bytes leftover after parsing attributes in process `syz.4.1714'. [ 380.866451][T11179] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 380.875090][T11179] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 383.388243][ T5825] usbhid 3-1:0.0: can't add hid device: -71 [ 383.616879][ T5825] usbhid 3-1:0.0: probe with driver usbhid failed with error -71 [ 383.676746][ T5825] usb 3-1: USB disconnect, device number 8 [ 386.794557][ T30] audit: type=1400 audit(1743729793.817:414): avc: denied { write } for pid=11246 comm="syz.1.1734" path="socket:[28980]" dev="sockfs" ino=28980 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 387.495852][ T9] IPVS: starting estimator thread 0... [ 387.599565][T11265] IPVS: using max 42 ests per chain, 100800 per kthread [ 391.943022][T11331] netlink: 12 bytes leftover after parsing attributes in process `syz.2.1758'. [ 391.952235][T11331] netlink: 12 bytes leftover after parsing attributes in process `syz.2.1758'. [ 394.371758][T11358] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 394.382503][T11358] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 395.249585][ T48] usb 4-1: new high-speed USB device number 11 using dummy_hcd [ 395.504603][ T48] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 395.518193][ T48] usb 4-1: New USB device found, idVendor=0471, idProduct=0304, bcdDevice=e4.df [ 395.527334][ T48] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 395.990184][ T48] usb 4-1: config 0 descriptor?? [ 395.998034][ T48] pwc: Askey VC010 type 2 USB webcam detected. [ 396.436081][ T48] pwc: recv_control_msg error -32 req 02 val 2b00 [ 396.986865][ T48] pwc: recv_control_msg error -71 req 02 val 2700 [ 397.086141][ T48] pwc: recv_control_msg error -71 req 02 val 2c00 [ 397.286599][ T48] pwc: recv_control_msg error -71 req 04 val 1000 [ 397.960648][ T48] pwc: recv_control_msg error -71 req 04 val 1300 [ 397.968239][ T48] pwc: recv_control_msg error -71 req 04 val 1400 [ 397.976183][ T48] pwc: recv_control_msg error -71 req 02 val 2000 [ 397.983910][ T48] pwc: recv_control_msg error -71 req 02 val 2100 [ 397.991608][ T48] pwc: recv_control_msg error -71 req 04 val 1500 [ 397.998325][ T48] pwc: recv_control_msg error -71 req 02 val 2500 [ 398.005977][ T48] pwc: recv_control_msg error -71 req 02 val 2400 [ 398.013522][ T48] pwc: recv_control_msg error -71 req 02 val 2600 [ 398.021147][ T48] pwc: recv_control_msg error -71 req 02 val 2900 [ 398.027847][ T48] pwc: recv_control_msg error -71 req 02 val 2800 [ 398.036310][ T48] pwc: recv_control_msg error -71 req 04 val 1100 [ 398.043986][ T48] pwc: recv_control_msg error -71 req 04 val 1200 [ 398.059645][ T48] pwc: Registered as video103. [ 398.072652][ T48] input: PWC snapshot button as /devices/platform/dummy_hcd.3/usb4/4-1/input/input8 [ 398.121962][ T48] usb 4-1: USB disconnect, device number 11 [ 399.646898][T11418] netlink: 12 bytes leftover after parsing attributes in process `syz.4.1784'. [ 399.658900][T11418] vlan2: entered promiscuous mode [ 399.664113][T11418] team0: entered promiscuous mode [ 399.678421][T11418] team_slave_0: entered promiscuous mode [ 399.684610][T11418] team_slave_1: entered promiscuous mode [ 399.690511][T11418] geneve0: entered promiscuous mode [ 400.504199][T11430] netlink: 28 bytes leftover after parsing attributes in process `syz.2.1788'. [ 400.537312][ T30] audit: type=1400 audit(1743729808.017:415): avc: denied { bind } for pid=11431 comm="syz.2.1790" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 400.590221][ T30] audit: type=1400 audit(1743729808.077:416): avc: denied { read } for pid=11431 comm="syz.2.1790" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 400.650432][ T30] audit: type=1400 audit(1743729808.137:417): avc: denied { write } for pid=11431 comm="syz.2.1790" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 400.744185][T11432] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 402.102349][T11453] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 402.112917][T11453] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 402.122882][T11453] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 402.133395][T11453] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 402.510141][T11456] batman_adv: Cannot find parent device. Skipping batadv-on-batadv check for ip6gretap1 [ 402.544315][T11456] batman_adv: batadv0: Adding interface: ip6gretap1 [ 402.560834][T11456] batman_adv: batadv0: The MTU of interface ip6gretap1 is too small (1434) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 402.654390][T11456] batman_adv: batadv0: Interface activated: ip6gretap1 [ 402.940082][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 402.980570][ T30] audit: type=1400 audit(1743729810.467:418): avc: denied { mounton } for pid=11460 comm="syz.1.1798" path="/381/file1/bus/file0" dev="autofs" ino=30118 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:autofs_t tclass=dir permissive=1 [ 406.445991][ T5839] Bluetooth: hci1: unexpected cc 0x0c03 length: 249 > 1 [ 406.455402][ T5839] Bluetooth: hci1: unexpected cc 0x1003 length: 249 > 9 [ 406.464224][ T5839] Bluetooth: hci1: unexpected cc 0x1001 length: 249 > 9 [ 406.477770][ T5839] Bluetooth: hci1: unexpected cc 0x0c23 length: 249 > 4 [ 406.488563][ T5839] Bluetooth: hci1: unexpected cc 0x0c38 length: 249 > 2 [ 406.521097][ T30] audit: type=1400 audit(1743729813.987:419): avc: denied { mounton } for pid=11505 comm="syz-executor" path="/" dev="sda1" ino=2 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:root_t tclass=dir permissive=1 [ 406.699487][T11505] wg1 speed is unknown, defaulting to 1000 [ 407.232077][T11505] chnl_net:caif_netlink_parms(): no params data found [ 407.288923][T11508] Bluetooth: hci0: Opcode 0x0c03 failed: -4 [ 407.789263][T11505] bridge0: port 1(bridge_slave_0) entered blocking state [ 407.796637][T11505] bridge0: port 1(bridge_slave_0) entered disabled state [ 407.804944][T11505] bridge_slave_0: entered allmulticast mode [ 407.814834][T11505] bridge_slave_0: entered promiscuous mode [ 407.825923][T11505] bridge0: port 2(bridge_slave_1) entered blocking state [ 407.857187][T11505] bridge0: port 2(bridge_slave_1) entered disabled state [ 407.867528][T11505] bridge_slave_1: entered allmulticast mode [ 407.883105][T11505] bridge_slave_1: entered promiscuous mode [ 407.910644][T11546] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(13) [ 407.917278][T11546] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 407.932484][T11546] vhci_hcd vhci_hcd.0: Device attached [ 407.950170][T11546] vhci_hcd vhci_hcd.0: pdev(0) rhport(1) sockfd(15) [ 407.956788][T11546] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 407.973545][T11505] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 408.003619][T11505] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 408.035460][T11546] vhci_hcd vhci_hcd.0: Device attached [ 408.036678][T11556] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 408.080500][T11505] team0: Port device team_slave_0 added [ 408.091748][T11505] team0: Port device team_slave_1 added [ 408.097451][T11546] vhci_hcd vhci_hcd.0: pdev(0) rhport(3) sockfd(17) [ 408.104062][T11546] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 408.112273][T11560] netlink: 20 bytes leftover after parsing attributes in process `syz.4.1832'. [ 408.119823][ T48] vhci_hcd: vhci_device speed not set [ 408.127777][T11546] vhci_hcd vhci_hcd.0: Device attached [ 408.146092][T11546] vhci_hcd vhci_hcd.0: pdev(0) rhport(4) sockfd(22) [ 408.152712][T11546] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 408.179506][T11505] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 408.182106][T11546] vhci_hcd vhci_hcd.0: Device attached [ 408.186460][T11505] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 408.186485][T11505] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 408.187917][T11505] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 408.216248][T11556] vhci_hcd vhci_hcd.0: pdev(0) rhport(5) sockfd(24) [ 408.218043][ T48] usb 33-1: new full-speed USB device number 2 using vhci_hcd [ 408.228337][T11556] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 408.237450][T11556] vhci_hcd vhci_hcd.0: Device attached [ 408.252040][T11505] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 408.289657][T11505] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 408.347137][T11546] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 408.358414][T11546] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 408.416759][T11546] vhci_hcd vhci_hcd.0: port 0 already used [ 408.539831][ T56] Bluetooth: hci1: command tx timeout [ 408.551765][T11565] vhci_hcd: connection closed [ 408.551948][T11561] vhci_hcd: connection closed [ 408.552893][T11554] vhci_hcd: connection closed [ 408.556677][T11550] vhci_hcd: connection reset by peer [ 408.564630][T11557] vhci_hcd: connection closed [ 408.567142][T11505] hsr_slave_0: entered promiscuous mode [ 408.583849][ T6163] vhci_hcd: stop threads [ 408.586784][T11505] hsr_slave_1: entered promiscuous mode [ 408.595037][T11579] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 408.604652][T11505] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 408.612423][ T6163] vhci_hcd: release socket [ 408.613045][T11505] Cannot create hsr debugfs directory [ 408.622879][ T6163] vhci_hcd: disconnect device [ 408.638630][ T6163] vhci_hcd: stop threads [ 408.655858][ T6163] vhci_hcd: release socket [ 408.682571][ T6163] vhci_hcd: disconnect device [ 408.705496][ T6163] vhci_hcd: stop threads [ 408.722080][ T6163] vhci_hcd: release socket [ 408.746143][ T6163] vhci_hcd: disconnect device [ 408.775257][ T6163] vhci_hcd: stop threads [ 408.799764][ T6163] vhci_hcd: release socket [ 408.804492][ T6163] vhci_hcd: disconnect device [ 408.809751][ T6163] vhci_hcd: stop threads [ 408.813993][ T6163] vhci_hcd: release socket [ 408.818688][ T6163] vhci_hcd: disconnect device [ 408.902554][T11586] MTD: Attempt to mount non-MTD device "/dev/nullb0" [ 408.909921][T11586] /dev/nullb0: Can't open blockdev [ 409.339504][ T5839] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 409.632803][T11505] netdevsim netdevsim5 netdevsim0: renamed from eth0 [ 409.763944][T11505] netdevsim netdevsim5 netdevsim1: renamed from eth1 [ 409.948041][T11505] netdevsim netdevsim5 netdevsim2: renamed from eth2 [ 410.207849][T11505] netdevsim netdevsim5 netdevsim3: renamed from eth3 [ 410.346456][T11505] 8021q: adding VLAN 0 to HW filter on device bond0 [ 410.368291][T11505] 8021q: adding VLAN 0 to HW filter on device team0 [ 410.408472][T11505] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 410.421323][T11505] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 410.518746][ T6174] bridge0: port 1(bridge_slave_0) entered blocking state [ 410.525943][ T6174] bridge0: port 1(bridge_slave_0) entered forwarding state [ 410.551946][ T6174] bridge0: port 2(bridge_slave_1) entered blocking state [ 410.559111][ T6174] bridge0: port 2(bridge_slave_1) entered forwarding state [ 410.636266][ T5839] Bluetooth: hci1: command tx timeout [ 411.684672][T11505] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 411.809437][ T5875] usb 4-1: new high-speed USB device number 12 using dummy_hcd [ 412.469615][ T5875] usb 4-1: Using ep0 maxpacket: 32 [ 412.476300][ T5875] usb 4-1: config 0 interface 0 altsetting 253 has 1 endpoint descriptor, different from the interface descriptor's value: 2 [ 412.489488][ T5875] usb 4-1: config 0 interface 0 has no altsetting 0 [ 412.496103][ T5875] usb 4-1: New USB device found, idVendor=0b05, idProduct=1a30, bcdDevice= 0.00 [ 412.505590][ T5875] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 412.522114][ T5875] usb 4-1: config 0 descriptor?? [ 412.647573][T11505] veth0_vlan: entered promiscuous mode [ 412.678117][T11505] veth1_vlan: entered promiscuous mode [ 412.735022][ T5839] Bluetooth: hci1: command tx timeout [ 412.833384][T11505] veth0_macvtap: entered promiscuous mode [ 412.853366][T11505] veth1_macvtap: entered promiscuous mode [ 412.877249][T11505] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 412.891421][T11505] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 412.903492][T11505] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 412.915747][T11505] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 412.941837][T11505] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 413.016987][T11505] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 413.047304][T11505] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 413.070586][T11505] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 413.092943][T11505] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 413.167845][T11505] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 413.289954][ T5875] asus 0003:0B05:1A30.0009: item fetching failed at offset 0/3 [ 413.291302][T11505] netdevsim netdevsim5 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 413.297964][ T5875] asus 0003:0B05:1A30.0009: Asus hid parse failed: -22 [ 413.310322][T11505] netdevsim netdevsim5 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 413.313214][ T5875] asus 0003:0B05:1A30.0009: probe with driver asus failed with error -22 [ 413.324595][T11505] netdevsim netdevsim5 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 413.342163][ T48] vhci_hcd: vhci_device speed not set [ 413.347860][T11505] netdevsim netdevsim5 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 413.409236][ T5902] usb 4-1: USB disconnect, device number 12 [ 413.457510][ T6163] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 413.466740][ T6163] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 413.583431][ T6163] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 413.592193][ T6163] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 413.624030][ T30] audit: type=1400 audit(1743729821.087:420): avc: denied { mounton } for pid=11505 comm="syz-executor" path="/root/syzkaller.mrlY59/syz-tmp/newroot/sys/kernel/debug" dev="debugfs" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:debugfs_t tclass=dir permissive=1 [ 413.652051][ T30] audit: type=1400 audit(1743729821.097:421): avc: denied { mount } for pid=11505 comm="syz-executor" name="/" dev="gadgetfs" ino=6681 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nfs_t tclass=filesystem permissive=1 [ 414.779435][ T5839] Bluetooth: hci1: command tx timeout [ 415.179092][T11673] overlayfs: failed to resolve './file1': -2 [ 416.004557][T11685] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1864'. [ 417.112409][T11698] syz.5.1868: attempt to access beyond end of device [ 417.112409][T11698] nbd5: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 417.139387][T11698] SQUASHFS error: Failed to read block 0x0: -5 [ 417.157127][T11698] unable to read squashfs_super_block [ 419.712326][T11728] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1878'. [ 421.747208][T11745] Bluetooth: hci0: Opcode 0x0c03 failed: -4 [ 421.859837][T11755] netlink: 28 bytes leftover after parsing attributes in process `syz.4.1886'. [ 423.011502][ T30] audit: type=1400 audit(1743729830.477:422): avc: denied { setopt } for pid=11762 comm="syz.5.1890" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 423.526785][ T5929] netdevsim netdevsim5 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 423.622710][ T5929] netdevsim netdevsim5 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 423.727110][ T5929] netdevsim netdevsim5 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 423.820133][ T5839] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 423.940420][ T5929] netdevsim netdevsim5 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 424.285980][ T56] Bluetooth: hci1: unexpected cc 0x0c03 length: 249 > 1 [ 424.297671][ T56] Bluetooth: hci1: unexpected cc 0x1003 length: 249 > 9 [ 424.911920][T11791] syz.3.1900: attempt to access beyond end of device [ 424.911920][T11791] nbd3: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 424.924949][T11791] SQUASHFS error: Failed to read block 0x0: -5 [ 424.931975][T11791] unable to read squashfs_super_block [ 424.973688][ T56] Bluetooth: hci1: unexpected cc 0x1001 length: 249 > 9 [ 424.986423][ T56] Bluetooth: hci1: unexpected cc 0x0c23 length: 249 > 4 [ 424.997458][ T56] Bluetooth: hci1: unexpected cc 0x0c38 length: 249 > 2 [ 425.275424][T11785] wg1 speed is unknown, defaulting to 1000 [ 425.275931][ T5929] bridge_slave_1: left allmulticast mode [ 425.639434][ T5929] bridge_slave_1: left promiscuous mode [ 425.647083][ T5929] bridge0: port 2(bridge_slave_1) entered disabled state [ 425.663285][ T5929] bridge_slave_0: left allmulticast mode [ 425.668952][ T5929] bridge_slave_0: left promiscuous mode [ 425.722051][ T5929] bridge0: port 1(bridge_slave_0) entered disabled state [ 427.100959][ T56] Bluetooth: hci1: command tx timeout [ 427.149515][ T5875] usb 3-1: new full-speed USB device number 9 using dummy_hcd [ 427.335089][ T5875] usb 3-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 427.355019][ T5875] usb 3-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 427.401358][ T5875] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 427.419839][ T5875] usb 3-1: Product: syz [ 427.424028][ T5875] usb 3-1: Manufacturer: syz [ 427.428617][ T5875] usb 3-1: SerialNumber: syz [ 427.939195][ T5875] usb 3-1: selecting invalid altsetting 1 [ 428.155226][ T5875] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 428.158392][ T5875] dvb_usb_lmedm04 3-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 428.517321][ T974] usb 4-1: new full-speed USB device number 13 using dummy_hcd [ 428.590046][ T5929] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 428.602710][ T5929] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 428.614230][ T5929] bond0 (unregistering): Released all slaves [ 428.784623][ T974] usb 4-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 428.828080][ T974] usb 4-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 429.179450][ T56] Bluetooth: hci1: command tx timeout [ 429.302082][ T48] usb 3-1: USB disconnect, device number 9 [ 429.371410][ T974] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 429.460464][ T974] usb 4-1: Product: syz [ 429.544403][ T974] usb 4-1: Manufacturer: syz [ 429.564015][ T974] usb 4-1: SerialNumber: syz [ 430.239511][ T974] usb 4-1: selecting invalid altsetting 1 [ 430.791347][ T974] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 430.812359][ T974] dvb_usb_lmedm04 4-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 431.119221][T11785] chnl_net:caif_netlink_parms(): no params data found [ 431.357430][ T56] Bluetooth: hci1: command tx timeout [ 431.382158][ T974] usb 4-1: USB disconnect, device number 13 [ 431.601563][ T30] audit: type=1400 audit(1743729839.087:423): avc: denied { ioctl } for pid=11882 comm="syz.3.1917" path="/dev/nullb0" dev="devtmpfs" ino=696 ioctlcmd=0x127f scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:device_t tclass=blk_file permissive=1 [ 432.233527][T11785] bridge0: port 1(bridge_slave_0) entered blocking state [ 432.250350][T11785] bridge0: port 1(bridge_slave_0) entered disabled state [ 432.267726][T11785] bridge_slave_0: entered allmulticast mode [ 432.278970][T11785] bridge_slave_0: entered promiscuous mode [ 432.348719][ T5929] hsr_slave_0: left promiscuous mode [ 432.357342][ T5929] hsr_slave_1: left promiscuous mode [ 432.364145][ T5929] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 432.373733][ T5929] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 432.390002][ T5929] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 432.397505][ T5929] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 432.541385][ T5929] veth1_macvtap: left promiscuous mode [ 432.557979][ T5929] veth0_macvtap: left promiscuous mode [ 432.567623][ T5929] veth1_vlan: left promiscuous mode [ 432.579616][ T5929] veth0_vlan: left promiscuous mode [ 433.699451][ T56] Bluetooth: hci1: command tx timeout [ 433.849096][ T30] audit: type=1400 audit(1743729841.327:424): avc: denied { create } for pid=11916 comm="syz.3.1926" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=mctp_socket permissive=1 [ 433.879458][ T9] usb 5-1: new full-speed USB device number 12 using dummy_hcd [ 434.311248][ T9] usb 5-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 434.328958][ T9] usb 5-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 434.348874][ T9] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 434.357523][ T9] usb 5-1: Product: syz [ 434.365524][ T9] usb 5-1: Manufacturer: syz [ 434.370482][ T9] usb 5-1: SerialNumber: syz [ 434.595190][T11928] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1930'. [ 435.029927][ T9] usb 5-1: selecting invalid altsetting 1 [ 435.094122][ T5929] team0 (unregistering): Port device team_slave_1 removed [ 435.124467][ T5929] team0 (unregistering): Port device team_slave_0 removed [ 435.242012][ T9] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 435.242068][ T9] dvb_usb_lmedm04 5-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 435.850457][T11785] bridge0: port 2(bridge_slave_1) entered blocking state [ 435.857943][T11785] bridge0: port 2(bridge_slave_1) entered disabled state [ 435.867152][T11785] bridge_slave_1: entered allmulticast mode [ 435.877000][T11785] bridge_slave_1: entered promiscuous mode [ 436.010727][T11785] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 436.201981][ T48] usb 5-1: USB disconnect, device number 12 [ 436.681445][ T30] audit: type=1400 audit(1743729843.817:425): avc: denied { nlmsg_write } for pid=11939 comm="syz.3.1932" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_tcpdiag_socket permissive=1 [ 437.032970][T11785] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 437.686472][T11785] team0: Port device team_slave_0 added [ 438.001987][T11785] team0: Port device team_slave_1 added [ 439.280033][T11785] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 439.287005][T11785] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 439.320944][T11785] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 439.366555][T11785] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 439.395890][T11785] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 439.441220][T11989] netlink: 20 bytes leftover after parsing attributes in process `syz.4.1942'. [ 439.486152][T11785] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 439.584220][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 439.593082][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 440.294081][T11785] hsr_slave_0: entered promiscuous mode [ 440.305850][T11785] hsr_slave_1: entered promiscuous mode [ 440.320517][T11785] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 440.328982][T11785] Cannot create hsr debugfs directory [ 440.828312][T11785] netdevsim netdevsim6 netdevsim0: renamed from eth0 [ 440.963974][T11785] netdevsim netdevsim6 netdevsim1: renamed from eth1 [ 441.880400][T11785] netdevsim netdevsim6 netdevsim2: renamed from eth2 [ 441.985964][T11785] netdevsim netdevsim6 netdevsim3: renamed from eth3 [ 442.645177][T11785] 8021q: adding VLAN 0 to HW filter on device bond0 [ 442.693711][T11785] 8021q: adding VLAN 0 to HW filter on device team0 [ 442.776095][ T6799] bridge0: port 1(bridge_slave_0) entered blocking state [ 442.783255][ T6799] bridge0: port 1(bridge_slave_0) entered forwarding state [ 442.860542][ T6838] bridge0: port 2(bridge_slave_1) entered blocking state [ 442.867715][ T6838] bridge0: port 2(bridge_slave_1) entered forwarding state [ 443.595700][T11785] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 443.647821][T12068] netlink: 20 bytes leftover after parsing attributes in process `syz.4.1960'. [ 445.694108][T12095] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 445.806994][T11785] veth0_vlan: entered promiscuous mode [ 446.443771][T12104] wg1 speed is unknown, defaulting to 1000 [ 446.503546][T11785] veth1_vlan: entered promiscuous mode [ 446.600542][T11785] veth0_macvtap: entered promiscuous mode [ 446.719226][T11785] veth1_macvtap: entered promiscuous mode [ 446.787907][T11785] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 446.816216][T11785] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 446.839530][T11785] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 446.860326][T11785] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 446.886586][T11785] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 447.015479][T11785] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 447.084572][T11785] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 447.197120][T11785] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 447.283111][T11785] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 447.372778][T11785] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 447.483387][T11785] netdevsim netdevsim6 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 447.556760][T11785] netdevsim netdevsim6 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 447.685285][T11785] netdevsim netdevsim6 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 447.695528][T11785] netdevsim netdevsim6 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 448.231525][ T6169] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 448.497002][ T6169] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 448.660681][ T6169] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 448.668529][ T6169] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 448.832481][ T971] usb 3-1: new high-speed USB device number 10 using dummy_hcd [ 449.152506][ T971] usb 3-1: device descriptor read/64, error -71 [ 450.806113][ T971] usb 3-1: new high-speed USB device number 11 using dummy_hcd [ 451.036996][ T971] usb 3-1: device descriptor read/64, error -71 [ 451.229699][ T971] usb usb3-port1: attempt power cycle [ 452.191213][ T971] usb 3-1: new high-speed USB device number 12 using dummy_hcd [ 452.549423][ T971] usb 3-1: device not accepting address 12, error -71 [ 455.149610][ T24] usb 7-1: new high-speed USB device number 2 using dummy_hcd [ 455.447793][ T24] usb 7-1: device descriptor read/64, error -71 [ 455.859772][ T971] usb 4-1: new full-speed USB device number 14 using dummy_hcd [ 455.952531][ T30] audit: type=1400 audit(1743729863.427:426): avc: denied { setrlimit } for pid=12258 comm="dhcpcd" scontext=system_u:system_r:dhcpc_t tcontext=system_u:system_r:dhcpc_t tclass=process permissive=1 [ 456.047797][ T24] usb 7-1: new high-speed USB device number 3 using dummy_hcd [ 456.057618][T12264] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2003'. [ 456.070255][ T971] usb 4-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 456.094649][T12264] vlan2: entered promiscuous mode [ 456.101840][ T971] usb 4-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 456.115472][ T971] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 456.123922][ T971] usb 4-1: Product: syz [ 456.134515][ T971] usb 4-1: Manufacturer: syz [ 456.145668][ T971] usb 4-1: SerialNumber: syz [ 456.193757][ T24] usb 7-1: device descriptor read/64, error -71 [ 456.586855][ T24] usb usb7-port1: attempt power cycle [ 456.969479][ T24] usb 7-1: new high-speed USB device number 4 using dummy_hcd [ 457.073974][ T24] usb 7-1: device descriptor read/8, error -71 [ 457.419552][ T24] usb 7-1: new high-speed USB device number 5 using dummy_hcd [ 457.450544][ T24] usb 7-1: device descriptor read/8, error -71 [ 457.611156][T12291] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 457.617571][ T24] usb usb7-port1: unable to enumerate USB device [ 458.574232][ T971] usb 4-1: selecting invalid altsetting 1 [ 458.587989][ T971] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 458.588079][ T971] dvb_usb_lmedm04 4-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 458.649472][ T971] usb 4-1: USB disconnect, device number 14 [ 459.759581][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 461.102893][ T5874] usb 7-1: new high-speed USB device number 6 using dummy_hcd [ 461.409513][ T5872] usb 3-1: new high-speed USB device number 14 using dummy_hcd [ 461.449547][ T5874] usb 7-1: Using ep0 maxpacket: 32 [ 461.469753][ T5874] usb 7-1: config 127 has an invalid interface number: 36 but max is 1 [ 461.506915][ T5874] usb 7-1: config 127 has an invalid interface number: 51 but max is 1 [ 461.517288][ T5874] usb 7-1: config 127 has an invalid descriptor of length 133, skipping remainder of the config [ 461.544698][ T5874] usb 7-1: config 127 has 3 interfaces, different from the descriptor's value: 2 [ 461.563465][ T5874] usb 7-1: config 127 has no interface number 0 [ 461.581944][ T5874] usb 7-1: config 127 has no interface number 2 [ 461.591978][ T5874] usb 7-1: config 127 interface 36 altsetting 250 endpoint 0x86 has invalid maxpacket 512, setting to 64 [ 461.605479][ T5874] usb 7-1: config 127 interface 36 altsetting 250 has an endpoint descriptor with address 0xD2, changing to 0x82 [ 461.623539][ T5874] usb 7-1: config 127 interface 36 altsetting 250 endpoint 0x82 has invalid maxpacket 4552, setting to 64 [ 461.639520][ T5872] usb 3-1: device descriptor read/64, error -71 [ 461.656350][ T5874] usb 7-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 461.674406][ T5874] usb 7-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 461.688634][ T5874] usb 7-1: config 127 interface 36 altsetting 250 has 9 endpoint descriptors, different from the interface descriptor's value: 8 [ 461.702499][ T5874] usb 7-1: config 127 interface 51 altsetting 2 has 0 endpoint descriptors, different from the interface descriptor's value: 8 [ 461.716075][ T5874] usb 7-1: too many endpoints for config 127 interface 1 altsetting 249: 97, using maximum allowed: 30 [ 461.730128][ T5874] usb 7-1: config 127 interface 1 altsetting 249 has 0 endpoint descriptors, different from the interface descriptor's value: 97 [ 461.745499][ T5874] usb 7-1: config 127 interface 36 has no altsetting 0 [ 461.757138][ T5874] usb 7-1: config 127 interface 51 has no altsetting 0 [ 461.765590][ T5874] usb 7-1: config 127 interface 1 has no altsetting 0 [ 461.775361][ T5874] usb 7-1: New USB device found, idVendor=1410, idProduct=a005, bcdDevice=53.d4 [ 461.785181][ T5874] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 461.793671][ T5874] usb 7-1: Product: syz [ 461.798053][ T5874] usb 7-1: Manufacturer: syz [ 461.803184][ T5874] usb 7-1: SerialNumber: syz [ 461.931833][ T5872] usb 3-1: new high-speed USB device number 15 using dummy_hcd [ 462.201414][ T5872] usb 3-1: device descriptor read/64, error -71 [ 462.401287][ T5872] usb usb3-port1: attempt power cycle [ 463.171460][ T5872] usb 3-1: new high-speed USB device number 16 using dummy_hcd [ 463.193981][ T5874] usb 7-1: USB disconnect, device number 6 [ 463.330702][ T5872] usb 3-1: device descriptor read/8, error -71 [ 463.599913][ T5872] usb 3-1: new high-speed USB device number 17 using dummy_hcd [ 463.762227][ T5872] usb 3-1: device descriptor read/8, error -71 [ 463.946978][ T5872] usb usb3-port1: unable to enumerate USB device [ 464.285121][T12389] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 464.299863][T12389] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 464.310464][T12389] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 464.398535][T12389] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 470.397611][T12465] vxcan1: entered allmulticast mode [ 470.622797][T12472] Unsupported ieee802154 address type: 0 [ 471.549627][T12463] vxcan1: left allmulticast mode [ 474.125629][T12524] netlink: 'syz.3.2074': attribute type 13 has an invalid length. [ 474.144389][T12524] netlink: 28 bytes leftover after parsing attributes in process `syz.3.2074'. [ 474.312145][T12530] netlink: 'syz.0.2064': attribute type 10 has an invalid length. [ 474.360231][T12530] 8021q: adding VLAN 0 to HW filter on device team0 [ 475.292877][T12530] team0: entered promiscuous mode [ 475.297907][T12530] geneve0: entered promiscuous mode [ 475.451966][T12530] bond0: (slave team0): Enslaving as an active interface with an up link [ 475.474682][ T54] kworker/u8:3 (54) used greatest stack depth: 21400 bytes left [ 476.119492][ T974] usb 3-1: new high-speed USB device number 18 using dummy_hcd [ 476.329576][ T974] usb 3-1: Using ep0 maxpacket: 16 [ 476.445433][ T974] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 476.584188][T12546] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 476.595347][T12546] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 476.607422][T12546] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 476.609553][ T974] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 476.693607][T12546] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 476.710430][ T974] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 476.719821][ T974] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 476.773092][ T974] usb 3-1: config 0 descriptor?? [ 476.951933][T12549] Bluetooth: hci0: Opcode 0x0c03 failed: -112 [ 477.603843][T12563] siw: device registration error -23 [ 477.842860][T12559] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 477.866720][ T974] konepure 0003:1E7D:2DB4.000A: unknown main item tag 0x0 [ 477.879795][T12559] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 477.912169][ T974] konepure 0003:1E7D:2DB4.000A: unknown main item tag 0x0 [ 477.954174][ T974] konepure 0003:1E7D:2DB4.000A: unknown main item tag 0x0 [ 477.995011][ T974] konepure 0003:1E7D:2DB4.000A: unknown main item tag 0x0 [ 478.052356][ T974] konepure 0003:1E7D:2DB4.000A: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.2-1/input0 [ 478.864386][T12587] netlink: 'syz.0.2086': attribute type 13 has an invalid length. [ 478.897368][T12587] netlink: 28 bytes leftover after parsing attributes in process `syz.0.2086'. [ 478.971540][ T974] usb 3-1: USB disconnect, device number 18 [ 479.024462][ T56] Bluetooth: hci0: Opcode 0x0c1a failed: -110 [ 483.472374][T12643] virtio-fs: tag <(null)> not found [ 485.239613][T12674] overlayfs: "xino" feature enabled using 2 upper inode bits. [ 485.309509][ T974] usb 4-1: new high-speed USB device number 15 using dummy_hcd [ 485.795890][ T974] usb 4-1: Using ep0 maxpacket: 16 [ 485.803482][ T974] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 485.814930][ T974] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 485.826722][ T974] usb 4-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 485.849433][ T974] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 485.874553][ T974] usb 4-1: config 0 descriptor?? [ 485.951683][T12685] siw: device registration error -23 [ 487.188453][ T974] konepure 0003:1E7D:2DB4.000B: unknown main item tag 0x0 [ 487.323617][ T974] konepure 0003:1E7D:2DB4.000B: unknown main item tag 0x0 [ 487.528502][ T974] konepure 0003:1E7D:2DB4.000B: unknown main item tag 0x0 [ 487.560079][T12666] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 487.606485][ T974] konepure 0003:1E7D:2DB4.000B: unknown main item tag 0x0 [ 487.638232][T12666] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 487.740612][ T974] konepure 0003:1E7D:2DB4.000B: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.3-1/input0 [ 488.269612][ T30] audit: type=1400 audit(1743729895.747:427): avc: denied { write } for pid=5179 comm="syslogd" name="/" dev="tmpfs" ino=1 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 488.317309][ T974] usb 4-1: USB disconnect, device number 15 [ 488.346906][ T30] audit: type=1400 audit(1743729895.747:428): avc: denied { remove_name } for pid=5179 comm="syslogd" name="messages" dev="tmpfs" ino=7 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 488.355744][T12720] netlink: 4 bytes leftover after parsing attributes in process `syz.0.2112'. [ 488.486936][ T30] audit: type=1400 audit(1743729895.747:429): avc: denied { add_name } for pid=5179 comm="syslogd" name="messages.0" dev="tmpfs" ino=3 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 490.117876][T12742] syz.6.2109: attempt to access beyond end of device [ 490.117876][T12742] nbd6: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 490.131061][ T9] usb 4-1: new high-speed USB device number 16 using dummy_hcd [ 490.335389][ T9] usb 4-1: Using ep0 maxpacket: 32 [ 490.459790][T12742] SQUASHFS error: Failed to read block 0x0: -5 [ 490.534154][ T9] usb 4-1: config 127 has an invalid interface number: 36 but max is 0 [ 490.543006][ T9] usb 4-1: config 127 has no interface number 0 [ 490.549315][ T9] usb 4-1: config 127 interface 36 altsetting 250 endpoint 0x86 has invalid maxpacket 512, setting to 64 [ 490.561137][ T9] usb 4-1: config 127 interface 36 altsetting 250 has an endpoint descriptor with address 0xD2, changing to 0x82 [ 490.575162][T12742] unable to read squashfs_super_block [ 490.587811][ T9] usb 4-1: config 127 interface 36 altsetting 250 endpoint 0x82 has invalid maxpacket 4552, setting to 64 [ 491.249755][ T9] usb 4-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 491.274630][ T9] usb 4-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 491.327388][ T9] usb 4-1: config 127 interface 36 altsetting 250 has 9 endpoint descriptors, different from the interface descriptor's value: 8 [ 491.342849][T12763] virtio-fs: tag <(null)> not found [ 491.809018][ T9] usb 4-1: config 127 interface 36 has no altsetting 0 [ 491.817904][ T9] usb 4-1: New USB device found, idVendor=1410, idProduct=a005, bcdDevice=53.d4 [ 491.841086][ T9] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 491.863856][ T9] usb 4-1: Product: syz [ 491.876832][ T9] usb 4-1: Manufacturer: syz [ 491.894480][ T9] usb 4-1: SerialNumber: syz [ 491.939424][T12771] netlink: 12 bytes leftover after parsing attributes in process `syz.0.2122'. [ 491.948536][T12771] netlink: 12 bytes leftover after parsing attributes in process `syz.0.2122'. [ 492.717041][ T9] usb 4-1: USB disconnect, device number 16 [ 493.242051][T12791] netlink: 28 bytes leftover after parsing attributes in process `syz.3.2126'. [ 495.341171][ T5825] usb 7-1: new high-speed USB device number 7 using dummy_hcd [ 495.581958][ T5825] usb 7-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 495.599007][ T5825] usb 7-1: config 0 has no interfaces? [ 495.623782][ T5825] usb 7-1: New USB device found, idVendor=04fc, idProduct=504a, bcdDevice=43.02 [ 495.633358][ T5825] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 495.646838][ T5825] usb 7-1: Product: syz [ 495.658145][ T5825] usb 7-1: Manufacturer: syz [ 495.673695][ T5825] usb 7-1: SerialNumber: syz [ 495.697036][ T5825] usb 7-1: config 0 descriptor?? [ 495.910439][ T5825] usb 7-1: USB disconnect, device number 7 [ 497.460626][T12851] siw: device registration error -23 [ 499.429757][T12875] siw: device registration error -23 [ 500.969533][T12896] MTD: Attempt to mount non-MTD device "/dev/nullb0" [ 500.976491][T12896] VFS: Can't find a romfs filesystem on dev nullb0. [ 500.976491][T12896] [ 500.999438][T12883] Bluetooth: hci0: Opcode 0x0c03 failed: -4 [ 501.047738][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 501.055969][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 501.301365][T12904] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(13) [ 501.308003][T12904] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 501.332600][T12904] vhci_hcd vhci_hcd.0: Device attached [ 501.348303][T12910] vhci_hcd vhci_hcd.0: pdev(0) rhport(1) sockfd(16) [ 501.354929][T12910] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 501.379805][T12910] vhci_hcd vhci_hcd.0: Device attached [ 501.391353][T12905] netlink: 28 bytes leftover after parsing attributes in process `syz.6.2160'. [ 501.579444][ T48] vhci_hcd: vhci_device speed not set [ 501.639417][ T48] usb 33-1: new full-speed USB device number 3 using vhci_hcd [ 501.902674][T12904] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 501.987413][T12904] vhci_hcd vhci_hcd.0: pdev(0) rhport(3) sockfd(19) [ 501.994053][T12904] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 502.002253][T12904] vhci_hcd vhci_hcd.0: Device attached [ 502.028796][T12904] vhci_hcd vhci_hcd.0: pdev(0) rhport(4) sockfd(22) [ 502.035438][T12904] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 502.046716][T12904] vhci_hcd vhci_hcd.0: Device attached [ 502.056807][T12904] vhci_hcd vhci_hcd.0: pdev(0) rhport(5) sockfd(24) [ 502.063444][T12904] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 502.073297][T12904] vhci_hcd vhci_hcd.0: Device attached [ 502.103329][T12904] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 502.125008][T12904] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 502.162866][T12904] vhci_hcd vhci_hcd.0: port 0 already used [ 502.202070][T12924] vhci_hcd: connection closed [ 502.202273][T12911] vhci_hcd: connection closed [ 502.202972][T12907] vhci_hcd: connection reset by peer [ 502.217113][ T6838] vhci_hcd: stop threads [ 502.221515][T12930] vhci_hcd: connection closed [ 502.221699][T12928] vhci_hcd: connection closed [ 502.226622][ T6838] vhci_hcd: release socket [ 502.236575][ T6838] vhci_hcd: disconnect device [ 502.242113][ T6838] vhci_hcd: stop threads [ 502.259594][ T6838] vhci_hcd: release socket [ 502.264402][ T6838] vhci_hcd: disconnect device [ 502.269721][ T6838] vhci_hcd: stop threads [ 502.274181][ T6838] vhci_hcd: release socket [ 502.278757][ T6838] vhci_hcd: disconnect device [ 502.328548][ T6838] vhci_hcd: stop threads [ 502.338276][ T6838] vhci_hcd: release socket [ 502.351288][ T6838] vhci_hcd: disconnect device [ 502.367598][ T6838] vhci_hcd: stop threads [ 502.415997][ T6838] vhci_hcd: release socket [ 502.427006][ T6838] vhci_hcd: disconnect device [ 502.598345][T12951] syz.6.2168: attempt to access beyond end of device [ 502.598345][T12951] nbd6: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 502.611628][T12951] SQUASHFS error: Failed to read block 0x0: -5 [ 502.617853][T12951] unable to read squashfs_super_block [ 503.361908][T12962] netlink: 'syz.4.2179': attribute type 72 has an invalid length. [ 503.449518][T12962] netlink: 20 bytes leftover after parsing attributes in process `syz.4.2179'. [ 503.774420][T12971] siw: device registration error -23 [ 505.544924][T12983] netlink: 28 bytes leftover after parsing attributes in process `syz.2.2186'. [ 506.774692][ T48] vhci_hcd: vhci_device speed not set [ 506.801185][T13009] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(12) [ 506.807812][T13009] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 506.855134][T13009] vhci_hcd vhci_hcd.0: Device attached [ 506.880917][T13006] vhci_hcd vhci_hcd.0: pdev(0) rhport(1) sockfd(15) [ 506.887636][T13006] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 507.036892][T13006] vhci_hcd vhci_hcd.0: Device attached [ 507.043186][T13009] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 507.439858][T13026] siw: device registration error -23 [ 507.519692][ T48] vhci_hcd: vhci_device speed not set [ 507.935383][T13006] vhci_hcd vhci_hcd.0: pdev(0) rhport(3) sockfd(18) [ 507.942012][T13006] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 508.060710][ T48] usb 33-1: device descriptor read/64, error -110 [ 508.069066][T13006] vhci_hcd vhci_hcd.0: Device attached [ 508.254647][ T48] vhci_hcd: vhci_device speed not set [ 508.274248][T13006] vhci_hcd vhci_hcd.0: pdev(0) rhport(5) sockfd(25) [ 508.280905][T13006] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 508.779599][T13006] vhci_hcd vhci_hcd.0: Device attached [ 508.783638][ T48] usb 33-1: new full-speed USB device number 4 using vhci_hcd [ 508.793014][T13034] vhci_hcd vhci_hcd.0: pdev(0) rhport(4) sockfd(21) [ 508.799634][T13034] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 509.193704][T13032] netlink: 28 bytes leftover after parsing attributes in process `syz.3.2200'. [ 509.235239][T13033] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 509.247234][T13033] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 509.257068][T13033] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 509.267552][T13033] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 509.310765][T13006] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 509.327507][T13034] vhci_hcd vhci_hcd.0: Device attached [ 509.349014][T13006] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 509.378629][T13006] vhci_hcd vhci_hcd.0: port 0 already used [ 509.429473][ T5874] usb 3-1: new high-speed USB device number 19 using dummy_hcd [ 509.597437][ T5874] usb 3-1: device descriptor read/64, error -71 [ 509.649736][T13038] vhci_hcd: connection closed [ 509.650060][T13024] vhci_hcd: connection closed [ 509.650975][T13014] vhci_hcd: connection closed [ 509.654811][T13010] vhci_hcd: connection reset by peer [ 509.669465][T13036] vhci_hcd: connection closed [ 510.081920][ T6145] vhci_hcd: stop threads [ 510.112048][ T6145] vhci_hcd: release socket [ 510.127772][ T6145] vhci_hcd: disconnect device [ 510.138527][ T6145] vhci_hcd: stop threads [ 510.149429][ T5874] usb 3-1: new high-speed USB device number 20 using dummy_hcd [ 510.152839][ T6145] vhci_hcd: release socket [ 510.171870][ T6145] vhci_hcd: disconnect device [ 510.184140][ T6145] vhci_hcd: stop threads [ 510.189362][ T6145] vhci_hcd: release socket [ 510.194832][ T6145] vhci_hcd: disconnect device [ 510.201331][ T6145] vhci_hcd: stop threads [ 510.205780][ T6145] vhci_hcd: release socket [ 510.210701][ T6145] vhci_hcd: disconnect device [ 510.217115][ T6145] vhci_hcd: stop threads [ 510.221905][ T6145] vhci_hcd: release socket [ 510.226613][ T6145] vhci_hcd: disconnect device [ 510.309640][ T5874] usb 3-1: device descriptor read/64, error -71 [ 510.432906][ T5874] usb usb3-port1: attempt power cycle [ 510.478900][T13060] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2205'. [ 510.488280][T13060] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2205'. [ 510.769413][ T5874] usb 3-1: new high-speed USB device number 21 using dummy_hcd [ 510.815066][ T5874] usb 3-1: device descriptor read/8, error -71 [ 511.132401][ T5874] usb 3-1: new high-speed USB device number 22 using dummy_hcd [ 511.193910][ T5874] usb 3-1: device descriptor read/8, error -71 [ 511.722811][ T5874] usb usb3-port1: unable to enumerate USB device [ 514.369508][ T48] vhci_hcd: vhci_device speed not set [ 514.571380][T13112] trusted_key: encrypted_key: key user:syz not found [ 515.869516][ T5902] usb 3-1: new full-speed USB device number 23 using dummy_hcd [ 516.186151][T13133] Unsupported ieee802154 address type: 0 [ 516.368513][ T5902] usb 3-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 517.182166][ T5902] usb 3-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 517.191278][ T5902] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 517.199284][ T5902] usb 3-1: Product: syz [ 517.219765][ T5902] usb 3-1: Manufacturer: syz [ 517.224688][ T5902] usb 3-1: SerialNumber: syz [ 517.413602][T13138] block nbd0: shutting down sockets [ 518.382921][ T5874] usb 7-1: new high-speed USB device number 8 using dummy_hcd [ 518.560429][ T5902] usb 3-1: selecting invalid altsetting 1 [ 518.580161][ T5874] usb 7-1: Using ep0 maxpacket: 16 [ 518.614443][ T5902] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 518.614504][ T5902] dvb_usb_lmedm04 3-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 518.645394][ T5874] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 518.656685][ T5874] usb 7-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 518.681478][ T5902] usb 3-1: USB disconnect, device number 23 [ 518.727075][ T5874] usb 7-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 518.916880][ T5874] usb 7-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 518.997416][T13158] batman_adv: Cannot find parent device. Skipping batadv-on-batadv check for ip6gretap1 [ 519.032256][ T5874] usb 7-1: config 0 descriptor?? [ 519.063352][T13158] batman_adv: batadv0: Adding interface: ip6gretap1 [ 519.098691][T13158] batman_adv: batadv0: The MTU of interface ip6gretap1 is too small (1434) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 519.387602][T13158] batman_adv: batadv0: Interface activated: ip6gretap1 [ 519.965857][ T5874] konepure 0003:1E7D:2DB4.000C: unknown main item tag 0x0 [ 519.973723][ T5874] konepure 0003:1E7D:2DB4.000C: unknown main item tag 0x0 [ 519.985480][ T5874] konepure 0003:1E7D:2DB4.000C: unknown main item tag 0x0 [ 519.993743][ T5874] konepure 0003:1E7D:2DB4.000C: unknown main item tag 0x0 [ 520.014748][ T5874] konepure 0003:1E7D:2DB4.000C: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.6-1/input0 [ 520.104918][T13141] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 520.125384][T13141] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 520.353866][ T5874] usb 7-1: USB disconnect, device number 8 [ 520.842245][T13177] trusted_key: encrypted_key: key user:syz not found [ 520.880599][T13180] Unsupported ieee802154 address type: 0 [ 523.053415][T13210] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 524.125262][T13220] siw: device registration error -23 [ 524.400400][ T5874] usb 5-1: new full-speed USB device number 13 using dummy_hcd [ 525.050745][ T5874] usb 5-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 525.099569][ T971] usb 3-1: new high-speed USB device number 24 using dummy_hcd [ 525.443398][ T5874] usb 5-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 525.452528][ T5874] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 525.460917][ T5874] usb 5-1: Product: syz [ 525.465096][ T5874] usb 5-1: Manufacturer: syz [ 525.469735][ T5874] usb 5-1: SerialNumber: syz [ 525.472336][ T971] usb 3-1: Using ep0 maxpacket: 16 [ 525.484043][ T971] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 525.501612][ T971] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 525.513461][ T971] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 525.525762][ T971] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 525.559526][ T5875] usb 7-1: new full-speed USB device number 9 using dummy_hcd [ 525.567862][ T971] usb 3-1: config 0 descriptor?? [ 525.642076][T13237] trusted_key: encrypted_key: key user:syz not found [ 525.790928][ T5875] usb 7-1: config 2 has an invalid descriptor of length 0, skipping remainder of the config [ 525.854839][ T5875] usb 7-1: New USB device found, idVendor=3344, idProduct=22f0, bcdDevice=ef.4d [ 525.864141][ T5875] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 525.887116][ T5875] usb 7-1: Product: syz [ 525.899815][ T5875] usb 7-1: Manufacturer: syz [ 525.915977][ T5875] usb 7-1: SerialNumber: syz [ 526.051602][ T971] konepure 0003:1E7D:2DB4.000D: unknown main item tag 0x0 [ 526.065003][ T971] konepure 0003:1E7D:2DB4.000D: unknown main item tag 0x0 [ 526.072767][ T971] konepure 0003:1E7D:2DB4.000D: unknown main item tag 0x0 [ 526.084929][ T971] konepure 0003:1E7D:2DB4.000D: unknown main item tag 0x0 [ 526.109823][ T971] konepure 0003:1E7D:2DB4.000D: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.2-1/input0 [ 526.241556][T13247] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 526.283621][T13241] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 526.304008][T13241] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 526.923587][ T5874] usb 5-1: selecting invalid altsetting 1 [ 526.936038][ T5874] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 526.936131][ T5874] dvb_usb_lmedm04 5-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 526.954129][ T5874] usb 5-1: USB disconnect, device number 13 [ 527.973066][T13261] overlayfs: "xino" feature enabled using 2 upper inode bits. [ 528.248898][ T5875] usb 7-1: selecting invalid altsetting 1 [ 528.258878][ T5875] LME2510(C): Firmware Status: 00 00 00 00 00 00 [ 528.258974][ T5875] dvb_usb_lmedm04 7-1:2.0: probe with driver dvb_usb_lmedm04 failed with error -22 [ 528.273317][ T5874] usb 3-1: USB disconnect, device number 24 [ 528.288024][ T5875] usb 7-1: USB disconnect, device number 9 [ 528.698541][T13269] syz.4.2268: attempt to access beyond end of device [ 528.698541][T13269] nbd4: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 528.711826][T13269] SQUASHFS error: Failed to read block 0x0: -5 [ 528.718023][T13269] unable to read squashfs_super_block [ 528.861976][T13276] No control pipe specified [ 528.994824][T13283] netlink: 28 bytes leftover after parsing attributes in process `syz.6.2273'. [ 530.265208][T13313] netlink: 'syz.3.2280': attribute type 10 has an invalid length. [ 530.273384][T13313] netlink: 40 bytes leftover after parsing attributes in process `syz.3.2280'. [ 530.700063][T13316] syz.4.2281: attempt to access beyond end of device [ 530.700063][T13316] nbd4: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 530.713161][T13316] SQUASHFS error: Failed to read block 0x0: -5 [ 530.719687][T13316] unable to read squashfs_super_block [ 530.753913][T13320] No control pipe specified [ 530.931181][T13313] geneve0: entered promiscuous mode [ 530.958664][T13313] team0: Port device geneve0 added [ 532.271743][T13361] No control pipe specified [ 538.060655][ T30] audit: type=1400 audit(1743729945.237:430): avc: denied { getopt } for pid=13417 comm="syz.0.2310" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 538.394016][T13430] netlink: 'syz.3.2314': attribute type 10 has an invalid length. [ 538.402008][T13430] netlink: 40 bytes leftover after parsing attributes in process `syz.3.2314'. [ 540.446492][T13459] overlayfs: "xino" feature enabled using 2 upper inode bits. [ 541.620690][T13472] netlink: 8 bytes leftover after parsing attributes in process `syz.6.2326'. [ 542.856297][T13494] netlink: 'syz.3.2331': attribute type 10 has an invalid length. [ 542.864591][T13494] netlink: 40 bytes leftover after parsing attributes in process `syz.3.2331'. [ 543.583325][T13502] block nbd0: shutting down sockets [ 544.190265][T13515] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 545.383717][T13532] block nbd4: shutting down sockets [ 545.992729][T13552] netlink: 'syz.6.2350': attribute type 13 has an invalid length. [ 546.284817][T13561] MTD: Attempt to mount non-MTD device "/dev/nullb0" [ 546.313958][T13561] VFS: Can't find a romfs filesystem on dev nullb0. [ 546.313958][T13561] [ 546.340097][T13552] bridge0: port 2(bridge_slave_1) entered disabled state [ 546.347654][T13552] bridge0: port 1(bridge_slave_0) entered disabled state [ 547.051571][T13552] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 547.106101][T13552] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 547.408751][T13552] netdevsim netdevsim6 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 547.437294][T13552] netdevsim netdevsim6 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 547.459380][T13570] usb 3-1: new high-speed USB device number 25 using dummy_hcd [ 547.467062][T13552] netdevsim netdevsim6 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 547.493393][T13552] netdevsim netdevsim6 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 547.639479][T13570] usb 3-1: Using ep0 maxpacket: 16 [ 547.655195][T13570] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 547.688815][T13570] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 547.719001][T13570] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 547.738460][T13570] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 547.784407][T13570] usb 3-1: config 0 descriptor?? [ 548.021213][T13590] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2356'. [ 548.038307][T13590] netlink: 12 bytes leftover after parsing attributes in process `syz.4.2356'. [ 548.421468][T13570] konepure 0003:1E7D:2DB4.000E: unknown main item tag 0x0 [ 548.429416][T13570] konepure 0003:1E7D:2DB4.000E: unknown main item tag 0x0 [ 548.436609][T13570] konepure 0003:1E7D:2DB4.000E: unknown main item tag 0x0 [ 548.453037][T13570] konepure 0003:1E7D:2DB4.000E: unknown main item tag 0x0 [ 548.486570][T13594] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 548.612113][T13570] konepure 0003:1E7D:2DB4.000E: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.2-1/input0 [ 548.629037][T13594] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 549.181759][T13580] Bluetooth: hci1: command 0x0406 tx timeout [ 550.218991][ T974] usb 3-1: USB disconnect, device number 25 [ 550.422601][T13628] block nbd2: shutting down sockets [ 550.430450][T13627] block nbd3: shutting down sockets [ 550.445277][T13633] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 551.431086][ T974] usb 5-1: new high-speed USB device number 14 using dummy_hcd [ 551.572106][T13657] netlink: 12 bytes leftover after parsing attributes in process `syz.0.2378'. [ 551.600398][ T974] usb 5-1: Using ep0 maxpacket: 32 [ 551.614409][T13657] netlink: 12 bytes leftover after parsing attributes in process `syz.0.2378'. [ 551.635229][ T974] usb 5-1: config 127 has an invalid interface number: 36 but max is 1 [ 551.649095][ T974] usb 5-1: config 127 has an invalid interface number: 51 but max is 1 [ 551.657909][ T974] usb 5-1: config 127 contains an unexpected descriptor of type 0x1, skipping [ 551.667621][ T974] usb 5-1: config 127 has an invalid descriptor of length 254, skipping remainder of the config [ 551.681789][ T974] usb 5-1: config 127 has 3 interfaces, different from the descriptor's value: 2 [ 551.691741][ T974] usb 5-1: config 127 has no interface number 0 [ 551.699111][ T974] usb 5-1: config 127 has no interface number 2 [ 551.706162][ T974] usb 5-1: config 127 interface 36 altsetting 250 endpoint 0x86 has invalid maxpacket 512, setting to 64 [ 551.742065][ T974] usb 5-1: config 127 interface 36 altsetting 250 has an endpoint descriptor with address 0xD2, changing to 0x82 [ 551.769446][ T974] usb 5-1: config 127 interface 36 altsetting 250 endpoint 0x82 has invalid maxpacket 4552, setting to 64 [ 551.804487][ T974] usb 5-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 551.838817][ T974] usb 5-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 551.868986][ T974] usb 5-1: config 127 interface 36 altsetting 250 has 9 endpoint descriptors, different from the interface descriptor's value: 8 [ 551.889589][T13570] usb 3-1: new high-speed USB device number 26 using dummy_hcd [ 551.897221][ T974] usb 5-1: config 127 interface 51 altsetting 2 has 0 endpoint descriptors, different from the interface descriptor's value: 8 [ 551.932216][ T974] usb 5-1: too many endpoints for config 127 interface 1 altsetting 249: 97, using maximum allowed: 30 [ 551.964666][ T974] usb 5-1: config 127 interface 1 altsetting 249 has an endpoint descriptor with address 0x54, changing to 0x4 [ 552.003483][ T974] usb 5-1: config 127 interface 1 altsetting 249 endpoint 0x4 has invalid maxpacket 50668, setting to 64 [ 552.015106][ T974] usb 5-1: config 127 interface 1 altsetting 249 has 1 endpoint descriptor, different from the interface descriptor's value: 97 [ 552.029073][ T974] usb 5-1: config 127 interface 36 has no altsetting 0 [ 552.036284][ T974] usb 5-1: config 127 interface 51 has no altsetting 0 [ 552.044764][ T974] usb 5-1: config 127 interface 1 has no altsetting 0 [ 552.094836][ T974] usb 5-1: New USB device found, idVendor=1410, idProduct=a005, bcdDevice=53.d4 [ 552.105443][ T974] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 552.119503][T13570] usb 3-1: Using ep0 maxpacket: 16 [ 552.122814][ T974] usb 5-1: Product: syz [ 552.128894][ T974] usb 5-1: Manufacturer: syz [ 552.134084][ T974] usb 5-1: SerialNumber: syz [ 552.136876][T13570] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 552.177938][T13570] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 552.192112][T13570] usb 3-1: New USB device found, idVendor=1e7d, idProduct=2db4, bcdDevice= 0.00 [ 552.205151][T13570] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 552.234784][T13570] usb 3-1: config 0 descriptor?? [ 552.620755][ T974] usb 5-1: USB disconnect, device number 14 [ 552.726224][T13570] konepure 0003:1E7D:2DB4.000F: unknown main item tag 0x0 [ 552.734039][T13570] konepure 0003:1E7D:2DB4.000F: unknown main item tag 0x0 [ 552.743225][T13570] konepure 0003:1E7D:2DB4.000F: unknown main item tag 0x0 [ 552.753805][T13570] konepure 0003:1E7D:2DB4.000F: unknown main item tag 0x0 [ 552.773049][T13570] konepure 0003:1E7D:2DB4.000F: hidraw0: USB HID v0.00 Device [HID 1e7d:2db4] on usb-dummy_hcd.2-1/input0 [ 552.937244][T13674] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 552.965061][T13674] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 553.465355][T13693] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 555.034986][T13563] usb 3-1: USB disconnect, device number 26 [ 555.552831][T13723] netlink: 12 bytes leftover after parsing attributes in process `syz.6.2397'. [ 555.561902][T13723] netlink: 12 bytes leftover after parsing attributes in process `syz.6.2397'. [ 556.354691][T13729] syz.2.2396: attempt to access beyond end of device [ 556.354691][T13729] nbd2: rw=0, sector=2, nr_sectors = 2 limit=0 [ 556.677057][T13722] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 556.688125][T13722] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 556.769848][T13571] usb 5-1: new high-speed USB device number 15 using dummy_hcd [ 557.059455][T13571] usb 5-1: Using ep0 maxpacket: 32 [ 557.361398][T13571] usb 5-1: config 127 has an invalid interface number: 36 but max is 1 [ 557.379909][T13571] usb 5-1: config 127 has an invalid interface number: 51 but max is 1 [ 557.388184][T13571] usb 5-1: config 127 contains an unexpected descriptor of type 0x1, skipping [ 557.418311][T13571] usb 5-1: config 127 has an invalid descriptor of length 254, skipping remainder of the config [ 557.490765][T13741] syz.0.2405: attempt to access beyond end of device [ 557.490765][T13741] nbd0: rw=0, sector=2, nr_sectors = 2 limit=0 [ 557.737855][T13571] usb 5-1: config 127 has 3 interfaces, different from the descriptor's value: 2 [ 557.747902][T13571] usb 5-1: config 127 has no interface number 0 [ 557.764380][T13571] usb 5-1: config 127 has no interface number 2 [ 557.789854][T13571] usb 5-1: config 127 interface 36 altsetting 250 endpoint 0x86 has invalid maxpacket 512, setting to 64 [ 557.850596][T13571] usb 5-1: config 127 interface 36 altsetting 250 has an endpoint descriptor with address 0xD2, changing to 0x82 [ 557.872749][T13571] usb 5-1: config 127 interface 36 altsetting 250 endpoint 0x82 has invalid maxpacket 4552, setting to 64 [ 557.885616][T13571] usb 5-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 557.982762][T13571] usb 5-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 558.075819][T13571] usb 5-1: config 127 interface 36 altsetting 250 has 9 endpoint descriptors, different from the interface descriptor's value: 8 [ 558.196790][T13571] usb 5-1: config 127 interface 51 altsetting 2 has 0 endpoint descriptors, different from the interface descriptor's value: 8 [ 558.489750][T13571] usb 5-1: too many endpoints for config 127 interface 1 altsetting 249: 97, using maximum allowed: 30 [ 558.523069][T13571] usb 5-1: config 127 interface 1 altsetting 249 has an endpoint descriptor with address 0x54, changing to 0x4 [ 559.098369][T13571] usb 5-1: config 127 interface 1 altsetting 249 endpoint 0x4 has invalid maxpacket 50668, setting to 64 [ 559.374136][T13571] usb 5-1: config 127 interface 1 altsetting 249 has 1 endpoint descriptor, different from the interface descriptor's value: 97 [ 559.711314][T13571] usb 5-1: config 127 interface 36 has no altsetting 0 [ 559.718204][T13571] usb 5-1: config 127 interface 51 has no altsetting 0 [ 559.725147][T13571] usb 5-1: config 127 interface 1 has no altsetting 0 [ 559.737518][T13571] usb 5-1: string descriptor 0 read error: -71 [ 559.744010][T13571] usb 5-1: New USB device found, idVendor=1410, idProduct=a005, bcdDevice=53.d4 [ 559.753105][T13571] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 559.768210][T13571] usb 5-1: can't set config #127, error -71 [ 559.776199][T13571] usb 5-1: USB disconnect, device number 15 [ 559.882442][T13766] block nbd2: shutting down sockets [ 560.271472][T13777] syz.4.2415: attempt to access beyond end of device [ 560.271472][T13777] nbd4: rw=2048, sector=0, nr_sectors = 8 limit=0 [ 560.284579][T13777] SQUASHFS error: Failed to read block 0x0: -5 [ 560.290847][T13777] unable to read squashfs_super_block [ 561.588350][T13792] infiniband syz1: RDMA CMA: cma_listen_on_dev, error -98 [ 562.493588][ T1295] ieee802154 phy0 wpan0: encryption failed: -22 [ 562.799914][ T1295] ieee802154 phy1 wpan1: encryption failed: -22 [ 563.102650][T13568] usb 3-1: new high-speed USB device number 27 using dummy_hcd [ 563.382723][T13568] usb 3-1: Using ep0 maxpacket: 32 [ 563.398464][T13568] usb 3-1: config 127 has an invalid interface number: 36 but max is 1 [ 563.407435][T13568] usb 3-1: config 127 has an invalid interface number: 51 but max is 1 [ 563.428489][T13568] usb 3-1: config 127 contains an unexpected descriptor of type 0x1, skipping [ 563.441201][T13568] usb 3-1: config 127 has an invalid descriptor of length 254, skipping remainder of the config [ 563.452089][T13568] usb 3-1: config 127 has 3 interfaces, different from the descriptor's value: 2 [ 563.469914][T13568] usb 3-1: config 127 has no interface number 0 [ 563.493163][T13568] usb 3-1: config 127 has no interface number 2 [ 563.512351][T13568] usb 3-1: config 127 interface 36 altsetting 250 endpoint 0x86 has invalid maxpacket 512, setting to 64 [ 563.546272][T13568] usb 3-1: config 127 interface 36 altsetting 250 has an endpoint descriptor with address 0xD2, changing to 0x82 [ 563.569416][T13568] usb 3-1: config 127 interface 36 altsetting 250 endpoint 0x82 has invalid maxpacket 4552, setting to 64 [ 563.647641][T13568] usb 3-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 563.669570][T13568] usb 3-1: config 127 interface 36 altsetting 250 has a duplicate endpoint with address 0x2, skipping [ 563.684416][T13568] usb 3-1: config 127 interface 36 altsetting 250 has 9 endpoint descriptors, different from the interface descriptor's value: 8 [ 564.149482][T13568] usb 3-1: config 127 interface 51 altsetting 2 has 0 endpoint descriptors, different from the interface descriptor's value: 8 [ 564.268052][T13568] usb 3-1: too many endpoints for config 127 interface 1 altsetting 249: 97, using maximum allowed: 30 [ 564.286321][T13568] usb 3-1: config 127 interface 1 altsetting 249 has an endpoint descriptor with address 0x54, changing to 0x4 [ 564.298135][T13568] usb 3-1: config 127 interface 1 altsetting 249 endpoint 0x4 has invalid maxpacket 50668, setting to 64 [ 564.309890][T13568] usb 3-1: config 127 interface 1 altsetting 249 has 1 endpoint descriptor, different from the interface descriptor's value: 97 [ 564.323377][T13568] usb 3-1: config 127 interface 36 has no altsetting 0 [ 564.502195][T13568] usb 3-1: config 127 interface 51 has no altsetting 0 [ 564.509098][T13568] usb 3-1: config 127 interface 1 has no altsetting 0 [ 564.517909][T13568] usb 3-1: New USB device found, idVendor=1410, idProduct=a005, bcdDevice=53.d4 [ 564.527169][T13568] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 564.535193][T13568] usb 3-1: Product: syz [ 564.539396][T13568] usb 3-1: Manufacturer: syz [ 564.543984][T13568] usb 3-1: SerialNumber: syz [ 565.251447][T13833] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 565.375545][T13833] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 565.531213][T13568] usb 3-1: can't set config #127, error -71 [ 565.980669][T13839] siw: device registration error -23 [ 566.346103][T13568] usb 3-1: USB disconnect, device number 27 [ 566.562799][T13846] block nbd4: shutting down sockets [ 568.371556][T13873] block nbd3: shutting down sockets [ 570.337032][T13903] syz.4.2453: attempt to access beyond end of device [ 570.337032][T13903] nbd4: rw=0, sector=2, nr_sectors = 2 limit=0 [ 574.251106][T13964] block nbd6: shutting down sockets [ 574.785112][T13980] [ 574.787462][T13980] ====================================================== [ 574.794476][T13980] WARNING: possible circular locking dependency detected [ 574.801493][T13980] 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 Not tainted [ 574.808252][T13980] ------------------------------------------------------ [ 574.815262][T13980] syz.6.2474/13980 is trying to acquire lock: [ 574.821306][T13980] ffffffff9037d578 (nr_neigh_list_lock){+...}-{3:3}, at: nr_remove_neigh+0x1a/0x290 [ 574.830688][T13980] [ 574.830688][T13980] but task is already holding lock: [ 574.838026][T13980] ffff88807bc6c770 (&nr_node->node_lock){+...}-{3:3}, at: nr_add_node+0x60b/0x2c00 [ 574.847314][T13980] [ 574.847314][T13980] which lock already depends on the new lock. [ 574.847314][T13980] [ 574.857692][T13980] [ 574.857692][T13980] the existing dependency chain (in reverse order) is: [ 574.866678][T13980] [ 574.866678][T13980] -> #2 (&nr_node->node_lock){+...}-{3:3}: [ 574.874649][T13980] _raw_spin_lock_bh+0x33/0x40 [ 574.879915][T13980] nr_rt_device_down+0x18e/0x810 [ 574.885374][T13980] nr_device_event+0x126/0x170 [ 574.890656][T13980] notifier_call_chain+0xb9/0x410 [ 574.896200][T13980] call_netdevice_notifiers_info+0xbe/0x140 [ 574.902609][T13980] __dev_notify_flags+0x1f7/0x2e0 [ 574.908155][T13980] netif_change_flags+0x108/0x160 [ 574.913679][T13980] dev_change_flags+0xba/0x250 [ 574.918944][T13980] dev_ifsioc+0x1498/0x1f70 [ 574.923947][T13980] dev_ioctl+0x223/0x10e0 [ 574.928773][T13980] sock_do_ioctl+0x19d/0x280 [ 574.933872][T13980] sock_ioctl+0x227/0x6b0 [ 574.938706][T13980] __x64_sys_ioctl+0x190/0x200 [ 574.943975][T13980] do_syscall_64+0xcd/0x260 [ 574.948979][T13980] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 574.955368][T13980] [ 574.955368][T13980] -> #1 (nr_node_list_lock){+...}-{3:3}: [ 574.963162][T13980] _raw_spin_lock_bh+0x33/0x40 [ 574.968425][T13980] nr_rt_device_down+0xd3/0x810 [ 574.973779][T13980] nr_device_event+0x126/0x170 [ 574.979045][T13980] notifier_call_chain+0xb9/0x410 [ 574.984574][T13980] call_netdevice_notifiers_info+0xbe/0x140 [ 574.990971][T13980] __dev_notify_flags+0x1f7/0x2e0 [ 574.996493][T13980] netif_change_flags+0x108/0x160 [ 575.002014][T13980] dev_change_flags+0xba/0x250 [ 575.007277][T13980] dev_ifsioc+0x1498/0x1f70 [ 575.012279][T13980] dev_ioctl+0x223/0x10e0 [ 575.017105][T13980] sock_do_ioctl+0x19d/0x280 [ 575.022220][T13980] sock_ioctl+0x227/0x6b0 [ 575.027053][T13980] __x64_sys_ioctl+0x190/0x200 [ 575.032333][T13980] do_syscall_64+0xcd/0x260 [ 575.037337][T13980] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 575.043732][T13980] [ 575.043732][T13980] -> #0 (nr_neigh_list_lock){+...}-{3:3}: [ 575.051612][T13980] __lock_acquire+0x1173/0x1ba0 [ 575.056960][T13980] lock_acquire+0x179/0x350 [ 575.061960][T13980] _raw_spin_lock_bh+0x33/0x40 [ 575.067222][T13980] nr_remove_neigh+0x1a/0x290 [ 575.072402][T13980] nr_add_node+0x2408/0x2c00 [ 575.077494][T13980] nr_rt_ioctl+0x11b7/0x29b0 [ 575.082584][T13980] nr_ioctl+0x19a/0x2e0 [ 575.087240][T13980] sock_do_ioctl+0x115/0x280 [ 575.092334][T13980] sock_ioctl+0x227/0x6b0 [ 575.097173][T13980] __x64_sys_ioctl+0x190/0x200 [ 575.102439][T13980] do_syscall_64+0xcd/0x260 [ 575.107445][T13980] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 575.113837][T13980] [ 575.113837][T13980] other info that might help us debug this: [ 575.113837][T13980] [ 575.124061][T13980] Chain exists of: [ 575.124061][T13980] nr_neigh_list_lock --> nr_node_list_lock --> &nr_node->node_lock [ 575.124061][T13980] [ 575.137851][T13980] Possible unsafe locking scenario: [ 575.137851][T13980] [ 575.145277][T13980] CPU0 CPU1 [ 575.150617][T13980] ---- ---- [ 575.155955][T13980] lock(&nr_node->node_lock); [ 575.160694][T13980] lock(nr_node_list_lock); [ 575.167780][T13980] lock(&nr_node->node_lock); [ 575.175041][T13980] lock(nr_neigh_list_lock); [ 575.179693][T13980] [ 575.179693][T13980] *** DEADLOCK *** [ 575.179693][T13980] [ 575.187830][T13980] 1 lock held by syz.6.2474/13980: [ 575.192920][T13980] #0: ffff88807bc6c770 (&nr_node->node_lock){+...}-{3:3}, at: nr_add_node+0x60b/0x2c00 [ 575.202643][T13980] [ 575.202643][T13980] stack backtrace: [ 575.208508][T13980] CPU: 0 UID: 0 PID: 13980 Comm: syz.6.2474 Not tainted 6.14.0-syzkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) [ 575.208525][T13980] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 575.208532][T13980] Call Trace: [ 575.208537][T13980] [ 575.208542][T13980] dump_stack_lvl+0x116/0x1f0 [ 575.208558][T13980] print_circular_bug+0x275/0x350 [ 575.208578][T13980] check_noncircular+0x14c/0x170 [ 575.208599][T13980] __lock_acquire+0x1173/0x1ba0 [ 575.208613][T13980] lock_acquire+0x179/0x350 [ 575.208624][T13980] ? nr_remove_neigh+0x1a/0x290 [ 575.208642][T13980] ? do_raw_spin_lock+0x12c/0x2b0 [ 575.208657][T13980] _raw_spin_lock_bh+0x33/0x40 [ 575.208669][T13980] ? nr_remove_neigh+0x1a/0x290 [ 575.208686][T13980] nr_remove_neigh+0x1a/0x290 [ 575.208704][T13980] nr_add_node+0x2408/0x2c00 [ 575.208725][T13980] nr_rt_ioctl+0x11b7/0x29b0 [ 575.208745][T13980] ? __pfx_nr_rt_ioctl+0x10/0x10 [ 575.208768][T13980] ? bpf_lsm_capable+0x9/0x10 [ 575.208781][T13980] ? security_capable+0x7e/0x260 [ 575.208796][T13980] nr_ioctl+0x19a/0x2e0 [ 575.208810][T13980] sock_do_ioctl+0x115/0x280 [ 575.208827][T13980] ? __pfx_sock_do_ioctl+0x10/0x10 [ 575.208846][T13980] ? ioctl_has_perm.constprop.0.isra.0+0x2f4/0x450 [ 575.208872][T13980] ? ioctl_has_perm.constprop.0.isra.0+0x2fe/0x450 [ 575.208892][T13980] ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 [ 575.208912][T13980] sock_ioctl+0x227/0x6b0 [ 575.208930][T13980] ? __pfx_sock_ioctl+0x10/0x10 [ 575.208947][T13980] ? hook_file_ioctl_common+0x145/0x410 [ 575.208961][T13980] ? selinux_file_ioctl+0x180/0x270 [ 575.208979][T13980] ? selinux_file_ioctl+0xb4/0x270 [ 575.208997][T13980] ? __pfx_sock_ioctl+0x10/0x10 [ 575.209015][T13980] __x64_sys_ioctl+0x190/0x200 [ 575.209033][T13980] do_syscall_64+0xcd/0x260 [ 575.209048][T13980] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 575.209060][T13980] RIP: 0033:0x7fb7cad8d169 [ 575.209071][T13980] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 575.209083][T13980] RSP: 002b:00007fb7c8bf6038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 575.209095][T13980] RAX: ffffffffffffffda RBX: 00007fb7cafa5fa0 RCX: 00007fb7cad8d169 [ 575.209103][T13980] RDX: 0000200000000280 RSI: 000000000000890b RDI: 0000000000000007 [ 575.209112][T13980] RBP: 00007fb7cae0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 575.209119][T13980] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 575.209127][T13980] R13: 0000000000000000 R14: 00007fb7cafa5fa0 R15: 00007ffe92fb2f38 [ 575.209138][T13980] [ 575.748997][T13986] fuse: Unknown parameter 'fd0xffffffffffffffff00000000000000000000' [ 578.139465][ T5929] unregister_netdevice: waiting for batadv0 to become free. Usage count = 3