last executing test programs: 1m27.6824215s ago: executing program 0 (id=248): r0 = shmget$private(0x0, 0x3000, 0x54001800, &(0x7f000010d000/0x3000)=nil) r1 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r1, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000100)={0x20, 0x44, 0x107, 0xfffffffc, 0x0, {0x1, 0x7c}, [@nested={0xc, 0x3, 0x0, 0x1, [@typed={0x2c, 0x6, 0x0, 0x0, @str='\x8e\n'}]}]}, 0x20}, 0x1, 0x0, 0x0, 0x488c0}, 0xc000) r2 = shmat(r0, &(0x7f0000000000/0x4000)=nil, 0xffffffffffffdfff) shmdt(r2) 1m27.678310169s ago: executing program 0 (id=251): r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) (async) ioctl$TCFLSH(r0, 0x400455c8, 0x400000009) ioctl$TIOCSTI(r0, 0x5412, &(0x7f0000000040)=0x31) (async) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000004c0)=ANY=[@ANYBLOB="01000000080000000400000008"], 0x48) mmap(&(0x7f0000ffb000/0x4000)=nil, 0x4000, 0x4, 0x13, r1, 0xaa05d000) (async, rerun: 64) bpf$MAP_CREATE(0x0, &(0x7f0000000040)=@base={0xc, 0x4, 0x4, 0xfffffc01, 0x0, r1, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) (rerun: 64) set_mempolicy(0x6, &(0x7f00000003c0)=0x8000000000000001, 0xe0) (async, rerun: 32) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000083850000007100000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x8, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) (rerun: 32) 1m25.540444439s ago: executing program 0 (id=300): r0 = syz_init_net_socket$ax25(0x3, 0x5, 0xca) r1 = syz_open_dev$tty1(0xc, 0x4, 0x1) dup(r0) ioctl$KDSETMODE(r1, 0x4b3a, 0x1) ioctl$TCXONC(r1, 0x4b3a, 0x2) ioctl$AUTOFS_IOC_EXPIRE_MULTI(r1, 0x40049366, &(0x7f0000000000)) r2 = socket$kcm(0x10, 0x7, 0x4) accept$ax25(r0, &(0x7f00000000c0)={{0x3, @netrom}, [@remote, @remote, @null, @default, @default, @netrom, @remote, @netrom]}, &(0x7f0000000040)=0x48) r3 = syz_init_net_socket$llc(0x1a, 0x1, 0x0) r4 = openat$selinux_create(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) write$selinux_create(r4, &(0x7f0000000040)=@access={'system_u:object_r:gpg_helper_exec_t:s0', 0x20, '/usr/sbin/cupsd', 0x20, 0x0, 0x2b}, 0x4c) setsockopt$llc_int(r3, 0x10c, 0x5, &(0x7f00000007c0)=0x9, 0x4) mmap(&(0x7f0000ffe000/0x1000)=nil, 0x1000, 0x2000000, 0x8010, r2, 0x9fc06000) sendmsg$kcm(r2, &(0x7f0000000240)={0x0, 0xf0ffffff, &(0x7f0000000140)=[{&(0x7f0000000280)="89000000120081ae08060cdc030000007f03e3f7000000006ee2ffca1b1f0000000004c00e72f750375ed08a56331dbf9ed7815e381ad6e747033a0093b837dc6cc01e32efaec8c7a6ec0012100001400a0c0c00bdad446b9bbc7a46e3988285dcdf12f21308f868fece01955fed0009d78f0a947ee2b49e33538afa8af92347514f0b56a20ff27fff", 0x89}], 0x1}, 0x0) shutdown(r2, 0x0) 1m25.461636834s ago: executing program 0 (id=301): r0 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000040), 0x84242, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000000)='./file0\x00', 0x0) mount(0x0, &(0x7f0000003c40)='./file0\x00', &(0x7f0000000080)='hugetlbfs\x00', 0x0, 0x0) open(&(0x7f0000000180)='./file0\x00', 0x4f0602, 0x0) r1 = syz_open_dev$loop(&(0x7f0000000080), 0x47ffffa, 0x122c42) r2 = syz_open_dev$sndctrl(&(0x7f0000000000), 0x1, 0x0) ioctl$SNDRV_CTL_IOCTL_ELEM_READ(r2, 0xc4c85512, &(0x7f0000000280)={{0x6, 0x0, 0x0, 0x0, 'syz0\x00'}, 0x0, [0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffc, 0x0, 0x0, 0x0, 0x4000000000000000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x400000000, 0x0, 0x0, 0x0, 0x8, 0x0, 0x0, 0x1dca, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1ff, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8, 0x0, 0x0, 0x0, 0xfffffffffffffffc, 0x0, 0x0, 0x0, 0x0, 0x8002, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1]}) r3 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) ptrace(0x10, r3) close_range(r1, r1, 0x0) ptrace$getenv(0x4201, r3, 0x0, 0x0) r4 = socket$inet_sctp(0x2, 0x1, 0x84) setsockopt$inet_pktinfo(r4, 0x0, 0x8, 0x0, 0x0) ppoll(&(0x7f0000000a00)=[{0xffffffffffffffff, 0x8010}], 0x1, &(0x7f0000000a80)={0x0, 0x3938700}, 0x0, 0x0) wait4(r3, &(0x7f00000000c0), 0x1, &(0x7f00000001c0)) ioctl$LOOP_CONFIGURE(r1, 0x4c0a, &(0x7f0000001ac0)={r0, 0x8004000, {0x0, 0x0, 0x0, 0x2ead, 0x7, 0x0, 0x0, 0x8000001d, 0xc, "339f020bbe82b398000000000000000000000d0ec0c1b4e9b1c4369d03740250ceaac594b1b3d741dd17c1c50d38ef2a565ef1e83323691c58d66500", "a9103939c787a16c1ca43f80026d1a8554fe581b59ded130e005520839f3d3289737f0374cda2f84112eb5c1f6f8a69ea917deb7ba193b3e7772fd29f35239d2", "24431a1e77a68e174ff10000000000000010e200", [0x0, 0x2500000000000000]}}) ioctl$LOOP_SET_CAPACITY(r1, 0x4c07) 1m25.353148958s ago: executing program 0 (id=303): r0 = accept4$packet(0xffffffffffffffff, &(0x7f0000000140)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @random}, &(0x7f0000000200)=0x14, 0x800) r1 = socket$nl_route(0x10, 0x3, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000000)='./file0\x00', &(0x7f0000000040)='devpts\x00', 0x0, 0x0) mount$bind(0x0, &(0x7f00000005c0)='./file0\x00', 0x0, 0x100000, 0x0) mount$bind(&(0x7f0000000140)='./file0\x00', &(0x7f0000000080)='./file0/../file0\x00', 0x0, 0x1adc51, 0x0) mount$bind(&(0x7f00000000c0)='./file0/../file0\x00', &(0x7f0000000100)='./file0\x00', 0x0, 0x510c0, 0x0) umount2(&(0x7f00000002c0)='./file0\x00', 0x0) sendmsg$nl_route_sched(r1, &(0x7f0000000280)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x80}, 0x800) r2 = socket$alg(0x26, 0x5, 0x0) syz_emit_vhci(&(0x7f0000000340)=ANY=[@ANYBLOB="041000"], 0xa) bind$alg(r2, &(0x7f0000000140)={0x26, 'rng\x00', 0x0, 0x0, 'drbg_nopr_sha512\x00'}, 0x19) ioctl$EXT4_IOC_MIGRATE(r0, 0x6609) creat(&(0x7f0000000040)='./file0\x00', 0x17) pipe2$9p(&(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}, 0x0) write$P9_RVERSION(r4, &(0x7f0000000280)=ANY=[@ANYRES32=r3], 0x1f) r5 = dup(r4) write$P9_RLERRORu(r5, &(0x7f0000000540)=ANY=[@ANYBLOB="8b"], 0x53) write$RDMA_USER_CM_CMD_SET_OPTION(r5, &(0x7f0000000100)={0xe, 0x18, 0xfa00, @id_afonly={0x0}}, 0x20) write$binfmt_elf64(r5, &(0x7f0000000340)=ANY=[@ANYBLOB="7f454c4600073f034b0b00000000000003003e00ffffffe935"], 0x7c8) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000380), 0xffffffffffffffff) syz_open_dev$char_usb(0xc, 0xb4, 0x5) syz_emit_vhci(&(0x7f00000003c0)=ANY=[@ANYBLOB="04100b05c87cd5aaaaaaaa120600bcf66ff1041eee921a0e141f380062b520fee5e78744d0a7efb5cfdee118cb81836284501eda9347a1499def3a0398268d73dd0a38f0229c8000a77adc66eb675053c98e3085da044875149d0661ebed6100595b6bd6d984c7b871ae77818c26b9251ed3c1077c1b9838d99bfaac550fc553d67ec64cccac990f01284fb9e0195e1876fc650b6513862696bf9a2b3ad7527ca560b4407dcda2e451f0e98b61df009b059c81dbea5ec2b223b54f11562c1e89c10fc54b19e4b1eaf19384b052d33bec93545666f6c35a061831a6ea8af612b49b2e0cb4a31eecaf99bc98c12487d50d49433727e14ee910"], 0xe) r8 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$sock_SIOCGIFINDEX_80211(r8, 0x8933, &(0x7f00000000c0)={'wlan1\x00', 0x0}) sendmsg$NL80211_CMD_SET_COALESCE(r6, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000180)={0x1c, r7, 0x1, 0x70bd2a, 0x25dfdbfe, {{}, {@val={0x8, 0x3, r9}, @void}}}, 0x1c}, 0x1, 0x0, 0x0, 0x408c1}, 0xc010) mincore(&(0x7f0000ffb000/0x3000)=nil, 0x3000, &(0x7f0000000240)=""/30) mount$9p_fd(0x0, &(0x7f00000000c0)='./file0\x00', &(0x7f00000001c0), 0x4, &(0x7f0000000080)=ANY=[@ANYRESDEC=r6, @ANYRES8, @ANYRES16=0x0, @ANYRESHEX]) 1m25.123276674s ago: executing program 0 (id=306): bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0xe, 0x4, 0x4, 0x4, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x400000, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r0 = creat(&(0x7f0000000280)='./file0\x00', 0xecf86c37d53049cc) r1 = socket$tipc(0x1e, 0x2, 0x0) setsockopt$TIPC_GROUP_JOIN(r1, 0x10f, 0x87, &(0x7f0000000000)={0x2001}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$tipc(&(0x7f00000003c0), 0xffffffffffffffff) sendmsg$TIPC_CMD_SHOW_NAME_TABLE(r2, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000280)={0x30, r3, 0x1, 0x0, 0x100000, {{}, {}, {0x14, 0x19, {0x2, 0x1, 0x0, 0x8}}}}, 0x30}, 0x1, 0x0, 0x0, 0x4008000}, 0x9004) write$binfmt_elf32(r0, &(0x7f0000000000)={{0x7f, 0x45, 0x4c, 0x46, 0x1, 0x3, 0x0, 0x3, 0x0, 0x2, 0x6, 0x10, 0x301, 0x38, 0xffffffff, 0xf, 0x0, 0x20, 0x3f, 0x4, 0x0, 0x4}}, 0x58) r4 = openat$tun(0xffffffffffffff9c, &(0x7f0000000080), 0x1c1341, 0x0) ioctl$TUNSETIFF(r4, 0x400454ca, &(0x7f00000000c0)={'syzkaller0\x00', 0x84aebfbd6349b7f2}) r5 = openat$tun(0xffffffffffffff9c, &(0x7f0000000500), 0x400, 0x0) close(r5) socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000340)) ioctl$SIOCSIFHWADDR(r5, 0x8914, &(0x7f0000002280)={'syzkaller0\x00', @link_local}) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = syz_genetlink_get_family_id$tipc(&(0x7f0000000200), 0xffffffffffffffff) sendmsg$TIPC_CMD_ENABLE_BEARER(r6, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000680)=ANY=[@ANYBLOB='8\x00\x00\x00', @ANYRES16=r7, @ANYBLOB="010000000d0000000000010000000000000001410000001c001700000000000000006574683a73797a6b616c6c657230"], 0x38}}, 0x0) writev(r4, &(0x7f0000000040)=[{&(0x7f0000000100)="89e7ee2c78dad9b4b473fec988cafbe863cac50580cd8b", 0x17}, {&(0x7f0000000440)="9c74dfbf77572856c809ff86bb648d", 0xf}], 0x2) ioctl$BTRFS_IOC_START_SYNC(r4, 0x80089418, &(0x7f0000000300)=0x0) r9 = openat$zero(0xffffffffffffff9c, &(0x7f0000000140), 0x2000, 0x0) ioctl$BTRFS_IOC_GET_SUBVOL_INFO(0xffffffffffffffff, 0x81f8943c, &(0x7f0000000380)={0x0, ""/256, 0x0, 0x0, 0x0, 0x0, ""/16, ""/16, ""/16, 0x0, 0x0, 0x0, 0x0}) ioctl$BTRFS_IOC_SNAP_CREATE_V2(0xffffffffffffffff, 0x50009417, &(0x7f0000000580)={{r9}, r10, 0x8, @unused=[0xbd, 0x80000001, 0x1, 0x5], @name="dc9edd9089cd1c765b0379ed41f340e310510ea884fef4fecbea81768bbb28f06301caf0d91807adac255fd6b0c1d9aca7945576c015d74b4112a41b8384fac3d749c5d21300ee572ef484151e92ed8453d95ad3b7acb809b0b63829af82915e93e29730d627d3143217397f9897662c2d49302143b248c02ffb49bdccc27f4769d8b2e57eae65a2720ecb46f430fd5535f0fae0b13e63ea5e82451ba55bf879aeff8370972da0f90c9db7484a95b2efb90741b4d9ba20a60a9da414ee025b38ca5b1f327767607d09f344d713efd3c9cd3758c4f1e25fea86157955768fcf2fe69fbae1d1737107e3e63b584914de142a4f9352ad77789d37e96ae5aa7d00260e38844920481f914a6c438ec7f3020714c3e2a20f60ccd67790bf7a21ce892a05c9c4cbf63b3097f2e49dfdbf007a984bc7df63ad56224666177df4f3dd4d8fdaa6956b331871ba1f42c9d92c559250078560522cb499d41ac02d2137964a3881bf865265ddec36226cd97433725cb67bbc3bc7fd44f10d828b8da4c32c77302451d3dc81d130af9ab07064ef58da053a70bf4bd513f4219572dd9176b0fa549cbea0acbaa580d000534d4ccfabd8d21b59a076ee60afd67b14ae171710f14f1db1104a8ce52c4b745075f3db4edf80d51687504e033ce5485c4273f2063b3ecfbdae38d9ba4851cfa2ce83c8bb1a8ca9ebf1fa4787f7140a3e44bf8e7fa83ab29d65551dbb73e55b4f65a7be25fd8dc655a06c62f0a613a04993bd4949eb2f3fd7fd365b9c6c2a9efeeb933b9659dffee27c7624ba6e74bb42c71d9086b73643a7fe2c8f11a0bebd083fe691bc7d061a95d960795639bee9375eae5a29d16eeee415ea20492af5d794ad6e1578795b8a8f680a5159dcb721a3e2652f5c62bfb845ac14df05f19e32e1613e659cd81fc57ac893f1581c72c23ecbf4e9e91bb14f0042d24bc36a22151988fc2463344e2df691585972ae3186387dfdce61096cb4b389779dc274e1eeb49347ae7e3c1f984dd353fcd4a65c46be0d42b55a95495887fc06ffb4a6aff313a337a4ef5c702fc99e5f763ca5a7d415bd74dec035c88b2d5b8927e88104b1c2868e55416e6141f3513e0f3d617d82ff6354aa195ec7e9e68718d3c36eaf06e420a6ad1d13b967979cef18bb86f23f185362220ac63f7eb9c34ee995c1525bf79a10326f9be186d6faaba408aed7a827ede96391e28c3e9edffaa898e7842b2cc625a25c30e532d086254aec1fa185970ecf3c9ea27f244e5b5e4682f1ce9cbea1a266aaf4ae8798a85a6b014b58b6b0d6541bb32cb2c65ae5fbac62123bb48b18f7497b392237b0526f87e59885e2423bc0926f9cb50db449f63546a8d09d60adb06f2a178528f07a87bc8fcff76c7b59577326ae61716c2a55252d84410cb622fd9a9060d0b917d3d119f3d53b21d1a519e89e43f82ecf765805f70ca6fb21618c1fb79351212ca34ae9d6bffd1860d99e9f47908c13523edd243c89d6cdf8f33fa28a9a33de7136d61b10a9b60c495812ade85ce27615cf75a9610d56950e9c1c1d3c966f2b70b30bd6e1aacc919fb62990dba94d7eeb2c176718ed09270ecfab0f611fa9e2de0a41eb4fab88cdbee9106f8d8c6fbd3006e2c1b716bea0712b4965967ea161a1c48018b5f6ad1063db31281de0375685c4386b0bc00960f596681099b94747a0ba5e51e621fb73123a72201ae928064c9a73b9b1da701990b150380cca264575bf9b5012fec97480c5dc0dd2e9d0cad505598cae2d02d9cdb9bff44c4573db39001bad429f4780d7ab0be6b641afd1fcea1e958416eb55aaceca7d1cec71efc027d0cab32893de781e30ed28234704aba3410c5eb7adb2aca8871cdb6628d9e7a63bb2cb98cf94db3ba99938d3f2bbda78368ac2bf9cc9af81fc020a588bac157545b24f09e16c52827adc5305229d86f9daf357e65b8e182e0c6afe3deb41cf2a3b55c89670088a627ac56d29088f69f6de055affb16dee65962d8246f306591f1f9e48a956d6f3d34e542bd6fc5a24efae16da0752a4ab740ea1c4fe660e5031694119e368314edffaf9f326f8e5279a63f7396b4c273a38ddcf51001cf88d72e55fd9526007285feeefdb8bee75a1d4051d41e09a8715232b8601807168732f705bd806e4b2af21d57321fe0ccdc135ac7ebf7d54d398cff48720d9785f236b71042d0af82e906a61391ad2fa2538b75d167384c6f48c288d5a05ae4b387e3260d0db5523290b041baecb3cd795033ccb69360ca586b7d8d539fa098c0a8eac922a60fde16e6ec9699b4502875b226d7a3cbff50402cedfa13270a4274e40d0e3b0b255ffbc68b6cd53fa8a513d80ad4e78de9e6469fcca050460a1077ac64012efae100bfbc501127f8a64bd08d6cfc881ab9e3f647310f18beb9b016d0d2fc58fc0a699f15ad504e94a117c513a6898812e220a7701faee5b199c08d6f06986b3a2c2380b114ba76a5bc0bd4cff6f349c7697f2d23271c5846d7dec8f3a21ecbb14eef1fe63474c486739d7f72cac9a7c1be267da4917326f2c6846ac882087939fbbf1670d0bf00f7049e0c5f9962522df9e2489dfe1a36d0340176fe5d4076f143df847b969356044d578213dd8bf0efedd2ff1e2cbf968f43e1811951fea0d087e8c7d31c3bf8c7aa9da88f5ad4116404b528b3c38468588b7f24782f3382e6553d47c21fecdca55b8a9d3f281dc42685f07ab64f0d3a8ba236438e4bc5f1911ae333fa4a5643dd7525ce2f2fdcbd4ae4bdaba7cc2031cd81510d27e1b82178a8c0a91e6edec44900d388766e7231d761c35b11f673f032636534c7c76bd61179f2b95d97bc05c84212c72cdcf6ee0b2542f2770a8792ab14ec7176b1f0e7c46cd6ee6a680c5f15a69d7117fe838c7c266929d7271e91047cd48272896edb45f8414b5b943112595254e6e47ec17c1feece32c9febda41108d416d37dff6fe7540a54ce9cdd07ff8f2b6b944ebf14850aec50e6ae5f037e1b63dec50ad339814e290df13b83e1a67000cda47429da98b5c51254c264ae066f208fef466b26f21397ae3f69d72605782dd2bfee009acb32b4760a5af59d278a1f027055252b8988c8813b0809e9ee591b96875af259626b635ea177ade5e47635deb8e84272bd28fb94983e65e491f5f703340f958410c8f8fd87188205de9b85c79584a98d57275d99e68edbb3a8e7773d4f9caee9cff7b082760df7f20fd8c9cf3b2e0be1cf0bd50f5288227038f6f579de734a0b91a8532e1f6970cb18d5bd6e4414478f86e5b58ed72775b3422c41f828fc1171cd76afb15b0a89f2ac29dfc3fd7cd9fba8437f7f47747553602ceda41dd6b7c6c966812d8bdae513dfce482f0db30a6063741ac2956b62e5770b8ad6a98eb294f7b7bbddaf645276b83aeac94fbced53d657dc45f303c36bb2946b802951989910d45c259c4990a75a16ff2c2ff064f1de9ac7201c9db0f9ea8f1c22d00c5615196c77d6bdea9e892dcfea34e875fbd2e14b23366add706580721ec5298d09b6777251bf582ca6ce60011a7f3267928bd94e00bb0d73e527515928b4ffb358c003579203e8e3b95755ef3b0579059e4004a32baadccc41d5673596e8ef07db46d67cb77ccb82b9fff18a042d6b9694b2b45251718cfe3dc9cbec5e33dcc6462ee14a30d7855b27a826a75109bf94d222fbb0200d5917004244cef0fc90f45ad510eb35e679cf0720785cae54560ebe8c23a054fb85983a0aca7d3f501d913f8696dcadf1f9a40c67525b8dfd600859f89d38f31761d086abd90d21cf4801390d32948a9634a0b7e47496bb4efe28b17ffd1b391ab2794180268582936adf14fa0ccaebbdce6b912f054e5dd13db335e753427a690241dc44f92e9d9ea902509488a66d8808df8b76d4b101fe0b94a40bca0f1091192f42ac469dd3ca6d33025dbe8db41b1603010ca1605ba91a24ded248cbe8dd1be2cd97b07185b2607b6ef0ab6801dd227ab2264bad045fd1217a987fd2114fbb31775be5f89d383d011aa58bbd5fe88a1ef40c5541b3f3b88653ad463ed42756510ed09f9de4a0a66e8e922aac42a60b4119001b0e8e2c2a9ce629e0e5ea987eac3f30177dd68cc7a01a503486ce6465065342d087eb83746510b66c5c6b85196f674e839443b6f9718a276f4cfa5e21fbd332d5a8c11f3c120cd140b203c20aba042811523ac925b5ef8ae68e48b4f5a79d215e7ea48046753f786e278d71193141082a8015076fe0582daf1f1019dd64c8848fe3f7dd4b966626ec64fc508bdc4b4e0b30412b4fa43dc4e01634bcdaa9d6acc335ca03bac234d0e875bdc0a8c70ceb8bcd933ba56039f84eb0a2a6b7aa7beb679aa66e386c4e404bdeae6cba92e042a85a623ddcdae7f21ac181697c51ffe75d0077cfafcf8cf3f39c786d5c6f3655657e06a3a7014666f4e842bd0b0fb864cfcaa36db634be834556571f724d167045b1f77d23f5e3bca6a862b61b289c30ba1b9b42135c62ceb285f85b62a2c02f3f3ebbc859ba840200ad23e0d031178de5e4ae035bcba475d79f5a4375223e1801c6a5620386f71dbc86987d8111da7c74bfb690c7e432032b3b79de4d3fa2579e8ddec21185fbc6551c19872515989353b88d751fb9e8e566923681fa64109191a1a33fee74a3a8bb66fb20f133c0bfd4b67f3f4401142ae01930f7362c3a0d2245d924d2cfcc41abd4238c3c39e60229e99ec0eeeb579d3ab929b4e883ff7519f5395f7088f0d6f6a956b74c4619b503aa487dc280e6a2012b629a98bf0e367530dad502b21d3b81a7a78e605d7be7c5b12710d885e39f32ddb56eafc8a778d6458d03d9153559fb4733899a2473522d4a01c8aeae9e539eb7e81de7928482295753c8433e01fe7c026e826a66bf1570f322744ebd57da40e4c47a41ef11b72bca854471da6ddf222a4565948e3249269fe2c00ee9b0e803a72f0719c041e1ea5b3c8e30e2346699e99feed4907272df8a114337324c5822b09122e69c642c37a76f76f6a9d1483250f0587dcd96e64a52b0df51fb45f45acf3905eaf55bd2020f7f94e5338bfab928ce369ec35d888bd6d61faa12483a6939554cbd7d4210924ef0fea13718f6ac4ac2f719a1187f5911d274e5e6afed3be2f9e293878414e544d59811f055c6c835e83d447f6bc17c4f3485a7378305b13f7850456d3907a558ecdc81027e225fd5747d092bb40f138cb3b56027558138a9b3ee2c7a771bbc8f77eea38690a9251021647fe779d1829116f387c021f58ae47fbaf190bc14937796d97595145cb293a1cf8a0a43d171df283b89206db3358949b7b2ab0e780b1e0d16c5e2a65780666d4a3fb6010bfd859d5fea93b0f6ec8235028194cfb1b19b427b0dbb444cf546a171640e1a4a10d5babb429b1fb8e78ca4758aabe598acefc4c4665909027ae34cca17c571d081b89047792736b72623071b66412afc165aa8f7a5a5e8ad4672b08a625610a5d92fb400b88a2c7f98e2dccd5b2a42aa10fc51c0e9898f6b543713fb16543758db64742999362b35dff93d1e698e7c9e174574175563893ee9e4cbb49a3b7f62f13429dbb7d89fb8db799a6d0108a0ce044cdc343e610e4c3a9f60f024363f7ac6050d4a7f9a28a1d497baba237e1def126d7619b5a50bb3ad3272d0186d7881d5ba887f6f5924572a77f2518821731a270ee30150ce7a690a6902d"}) ioctl$BTRFS_IOC_SET_RECEIVED_SUBVOL(r4, 0xc0c89425, &(0x7f0000000540)={"cd69c5a38b908007ee67d4021784f149", r8, r10, {0xc5, 0x3}, {0x101, 0x2}, 0x3, [0x2000000, 0x2, 0x4, 0x7fffffffffffffff, 0x5, 0x4000000000000, 0xfffffffffffffff7, 0x7, 0x7, 0x4, 0x6, 0x0, 0x6, 0x80, 0x4, 0x1]}) close(r0) execve(&(0x7f0000000140)='./file0\x00', 0x0, 0x0) r11 = openat$vimc0(0xffffffffffffff9c, &(0x7f0000000180), 0x2, 0x0) ioctl$VIDIOC_G_STD(r11, 0x80085617, &(0x7f00000001c0)) 1m25.074982932s ago: executing program 32 (id=306): bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0xe, 0x4, 0x4, 0x4, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x400000, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r0 = creat(&(0x7f0000000280)='./file0\x00', 0xecf86c37d53049cc) r1 = socket$tipc(0x1e, 0x2, 0x0) setsockopt$TIPC_GROUP_JOIN(r1, 0x10f, 0x87, &(0x7f0000000000)={0x2001}, 0x10) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$tipc(&(0x7f00000003c0), 0xffffffffffffffff) sendmsg$TIPC_CMD_SHOW_NAME_TABLE(r2, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000280)={0x30, r3, 0x1, 0x0, 0x100000, {{}, {}, {0x14, 0x19, {0x2, 0x1, 0x0, 0x8}}}}, 0x30}, 0x1, 0x0, 0x0, 0x4008000}, 0x9004) write$binfmt_elf32(r0, &(0x7f0000000000)={{0x7f, 0x45, 0x4c, 0x46, 0x1, 0x3, 0x0, 0x3, 0x0, 0x2, 0x6, 0x10, 0x301, 0x38, 0xffffffff, 0xf, 0x0, 0x20, 0x3f, 0x4, 0x0, 0x4}}, 0x58) r4 = openat$tun(0xffffffffffffff9c, &(0x7f0000000080), 0x1c1341, 0x0) ioctl$TUNSETIFF(r4, 0x400454ca, &(0x7f00000000c0)={'syzkaller0\x00', 0x84aebfbd6349b7f2}) r5 = openat$tun(0xffffffffffffff9c, &(0x7f0000000500), 0x400, 0x0) close(r5) socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000340)) ioctl$SIOCSIFHWADDR(r5, 0x8914, &(0x7f0000002280)={'syzkaller0\x00', @link_local}) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = syz_genetlink_get_family_id$tipc(&(0x7f0000000200), 0xffffffffffffffff) sendmsg$TIPC_CMD_ENABLE_BEARER(r6, &(0x7f00000002c0)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000680)=ANY=[@ANYBLOB='8\x00\x00\x00', @ANYRES16=r7, @ANYBLOB="010000000d0000000000010000000000000001410000001c001700000000000000006574683a73797a6b616c6c657230"], 0x38}}, 0x0) writev(r4, &(0x7f0000000040)=[{&(0x7f0000000100)="89e7ee2c78dad9b4b473fec988cafbe863cac50580cd8b", 0x17}, {&(0x7f0000000440)="9c74dfbf77572856c809ff86bb648d", 0xf}], 0x2) ioctl$BTRFS_IOC_START_SYNC(r4, 0x80089418, &(0x7f0000000300)=0x0) r9 = openat$zero(0xffffffffffffff9c, &(0x7f0000000140), 0x2000, 0x0) ioctl$BTRFS_IOC_GET_SUBVOL_INFO(0xffffffffffffffff, 0x81f8943c, &(0x7f0000000380)={0x0, ""/256, 0x0, 0x0, 0x0, 0x0, ""/16, ""/16, ""/16, 0x0, 0x0, 0x0, 0x0}) ioctl$BTRFS_IOC_SNAP_CREATE_V2(0xffffffffffffffff, 0x50009417, &(0x7f0000000580)={{r9}, r10, 0x8, @unused=[0xbd, 0x80000001, 0x1, 0x5], @name="dc9edd9089cd1c765b0379ed41f340e310510ea884fef4fecbea81768bbb28f06301caf0d91807adac255fd6b0c1d9aca7945576c015d74b4112a41b8384fac3d749c5d21300ee572ef484151e92ed8453d95ad3b7acb809b0b63829af82915e93e29730d627d3143217397f9897662c2d49302143b248c02ffb49bdccc27f4769d8b2e57eae65a2720ecb46f430fd5535f0fae0b13e63ea5e82451ba55bf879aeff8370972da0f90c9db7484a95b2efb90741b4d9ba20a60a9da414ee025b38ca5b1f327767607d09f344d713efd3c9cd3758c4f1e25fea86157955768fcf2fe69fbae1d1737107e3e63b584914de142a4f9352ad77789d37e96ae5aa7d00260e38844920481f914a6c438ec7f3020714c3e2a20f60ccd67790bf7a21ce892a05c9c4cbf63b3097f2e49dfdbf007a984bc7df63ad56224666177df4f3dd4d8fdaa6956b331871ba1f42c9d92c559250078560522cb499d41ac02d2137964a3881bf865265ddec36226cd97433725cb67bbc3bc7fd44f10d828b8da4c32c77302451d3dc81d130af9ab07064ef58da053a70bf4bd513f4219572dd9176b0fa549cbea0acbaa580d000534d4ccfabd8d21b59a076ee60afd67b14ae171710f14f1db1104a8ce52c4b745075f3db4edf80d51687504e033ce5485c4273f2063b3ecfbdae38d9ba4851cfa2ce83c8bb1a8ca9ebf1fa4787f7140a3e44bf8e7fa83ab29d65551dbb73e55b4f65a7be25fd8dc655a06c62f0a613a04993bd4949eb2f3fd7fd365b9c6c2a9efeeb933b9659dffee27c7624ba6e74bb42c71d9086b73643a7fe2c8f11a0bebd083fe691bc7d061a95d960795639bee9375eae5a29d16eeee415ea20492af5d794ad6e1578795b8a8f680a5159dcb721a3e2652f5c62bfb845ac14df05f19e32e1613e659cd81fc57ac893f1581c72c23ecbf4e9e91bb14f0042d24bc36a22151988fc2463344e2df691585972ae3186387dfdce61096cb4b389779dc274e1eeb49347ae7e3c1f984dd353fcd4a65c46be0d42b55a95495887fc06ffb4a6aff313a337a4ef5c702fc99e5f763ca5a7d415bd74dec035c88b2d5b8927e88104b1c2868e55416e6141f3513e0f3d617d82ff6354aa195ec7e9e68718d3c36eaf06e420a6ad1d13b967979cef18bb86f23f185362220ac63f7eb9c34ee995c1525bf79a10326f9be186d6faaba408aed7a827ede96391e28c3e9edffaa898e7842b2cc625a25c30e532d086254aec1fa185970ecf3c9ea27f244e5b5e4682f1ce9cbea1a266aaf4ae8798a85a6b014b58b6b0d6541bb32cb2c65ae5fbac62123bb48b18f7497b392237b0526f87e59885e2423bc0926f9cb50db449f63546a8d09d60adb06f2a178528f07a87bc8fcff76c7b59577326ae61716c2a55252d84410cb622fd9a9060d0b917d3d119f3d53b21d1a519e89e43f82ecf765805f70ca6fb21618c1fb79351212ca34ae9d6bffd1860d99e9f47908c13523edd243c89d6cdf8f33fa28a9a33de7136d61b10a9b60c495812ade85ce27615cf75a9610d56950e9c1c1d3c966f2b70b30bd6e1aacc919fb62990dba94d7eeb2c176718ed09270ecfab0f611fa9e2de0a41eb4fab88cdbee9106f8d8c6fbd3006e2c1b716bea0712b4965967ea161a1c48018b5f6ad1063db31281de0375685c4386b0bc00960f596681099b94747a0ba5e51e621fb73123a72201ae928064c9a73b9b1da701990b150380cca264575bf9b5012fec97480c5dc0dd2e9d0cad505598cae2d02d9cdb9bff44c4573db39001bad429f4780d7ab0be6b641afd1fcea1e958416eb55aaceca7d1cec71efc027d0cab32893de781e30ed28234704aba3410c5eb7adb2aca8871cdb6628d9e7a63bb2cb98cf94db3ba99938d3f2bbda78368ac2bf9cc9af81fc020a588bac157545b24f09e16c52827adc5305229d86f9daf357e65b8e182e0c6afe3deb41cf2a3b55c89670088a627ac56d29088f69f6de055affb16dee65962d8246f306591f1f9e48a956d6f3d34e542bd6fc5a24efae16da0752a4ab740ea1c4fe660e5031694119e368314edffaf9f326f8e5279a63f7396b4c273a38ddcf51001cf88d72e55fd9526007285feeefdb8bee75a1d4051d41e09a8715232b8601807168732f705bd806e4b2af21d57321fe0ccdc135ac7ebf7d54d398cff48720d9785f236b71042d0af82e906a61391ad2fa2538b75d167384c6f48c288d5a05ae4b387e3260d0db5523290b041baecb3cd795033ccb69360ca586b7d8d539fa098c0a8eac922a60fde16e6ec9699b4502875b226d7a3cbff50402cedfa13270a4274e40d0e3b0b255ffbc68b6cd53fa8a513d80ad4e78de9e6469fcca050460a1077ac64012efae100bfbc501127f8a64bd08d6cfc881ab9e3f647310f18beb9b016d0d2fc58fc0a699f15ad504e94a117c513a6898812e220a7701faee5b199c08d6f06986b3a2c2380b114ba76a5bc0bd4cff6f349c7697f2d23271c5846d7dec8f3a21ecbb14eef1fe63474c486739d7f72cac9a7c1be267da4917326f2c6846ac882087939fbbf1670d0bf00f7049e0c5f9962522df9e2489dfe1a36d0340176fe5d4076f143df847b969356044d578213dd8bf0efedd2ff1e2cbf968f43e1811951fea0d087e8c7d31c3bf8c7aa9da88f5ad4116404b528b3c38468588b7f24782f3382e6553d47c21fecdca55b8a9d3f281dc42685f07ab64f0d3a8ba236438e4bc5f1911ae333fa4a5643dd7525ce2f2fdcbd4ae4bdaba7cc2031cd81510d27e1b82178a8c0a91e6edec44900d388766e7231d761c35b11f673f032636534c7c76bd61179f2b95d97bc05c84212c72cdcf6ee0b2542f2770a8792ab14ec7176b1f0e7c46cd6ee6a680c5f15a69d7117fe838c7c266929d7271e91047cd48272896edb45f8414b5b943112595254e6e47ec17c1feece32c9febda41108d416d37dff6fe7540a54ce9cdd07ff8f2b6b944ebf14850aec50e6ae5f037e1b63dec50ad339814e290df13b83e1a67000cda47429da98b5c51254c264ae066f208fef466b26f21397ae3f69d72605782dd2bfee009acb32b4760a5af59d278a1f027055252b8988c8813b0809e9ee591b96875af259626b635ea177ade5e47635deb8e84272bd28fb94983e65e491f5f703340f958410c8f8fd87188205de9b85c79584a98d57275d99e68edbb3a8e7773d4f9caee9cff7b082760df7f20fd8c9cf3b2e0be1cf0bd50f5288227038f6f579de734a0b91a8532e1f6970cb18d5bd6e4414478f86e5b58ed72775b3422c41f828fc1171cd76afb15b0a89f2ac29dfc3fd7cd9fba8437f7f47747553602ceda41dd6b7c6c966812d8bdae513dfce482f0db30a6063741ac2956b62e5770b8ad6a98eb294f7b7bbddaf645276b83aeac94fbced53d657dc45f303c36bb2946b802951989910d45c259c4990a75a16ff2c2ff064f1de9ac7201c9db0f9ea8f1c22d00c5615196c77d6bdea9e892dcfea34e875fbd2e14b23366add706580721ec5298d09b6777251bf582ca6ce60011a7f3267928bd94e00bb0d73e527515928b4ffb358c003579203e8e3b95755ef3b0579059e4004a32baadccc41d5673596e8ef07db46d67cb77ccb82b9fff18a042d6b9694b2b45251718cfe3dc9cbec5e33dcc6462ee14a30d7855b27a826a75109bf94d222fbb0200d5917004244cef0fc90f45ad510eb35e679cf0720785cae54560ebe8c23a054fb85983a0aca7d3f501d913f8696dcadf1f9a40c67525b8dfd600859f89d38f31761d086abd90d21cf4801390d32948a9634a0b7e47496bb4efe28b17ffd1b391ab2794180268582936adf14fa0ccaebbdce6b912f054e5dd13db335e753427a690241dc44f92e9d9ea902509488a66d8808df8b76d4b101fe0b94a40bca0f1091192f42ac469dd3ca6d33025dbe8db41b1603010ca1605ba91a24ded248cbe8dd1be2cd97b07185b2607b6ef0ab6801dd227ab2264bad045fd1217a987fd2114fbb31775be5f89d383d011aa58bbd5fe88a1ef40c5541b3f3b88653ad463ed42756510ed09f9de4a0a66e8e922aac42a60b4119001b0e8e2c2a9ce629e0e5ea987eac3f30177dd68cc7a01a503486ce6465065342d087eb83746510b66c5c6b85196f674e839443b6f9718a276f4cfa5e21fbd332d5a8c11f3c120cd140b203c20aba042811523ac925b5ef8ae68e48b4f5a79d215e7ea48046753f786e278d71193141082a8015076fe0582daf1f1019dd64c8848fe3f7dd4b966626ec64fc508bdc4b4e0b30412b4fa43dc4e01634bcdaa9d6acc335ca03bac234d0e875bdc0a8c70ceb8bcd933ba56039f84eb0a2a6b7aa7beb679aa66e386c4e404bdeae6cba92e042a85a623ddcdae7f21ac181697c51ffe75d0077cfafcf8cf3f39c786d5c6f3655657e06a3a7014666f4e842bd0b0fb864cfcaa36db634be834556571f724d167045b1f77d23f5e3bca6a862b61b289c30ba1b9b42135c62ceb285f85b62a2c02f3f3ebbc859ba840200ad23e0d031178de5e4ae035bcba475d79f5a4375223e1801c6a5620386f71dbc86987d8111da7c74bfb690c7e432032b3b79de4d3fa2579e8ddec21185fbc6551c19872515989353b88d751fb9e8e566923681fa64109191a1a33fee74a3a8bb66fb20f133c0bfd4b67f3f4401142ae01930f7362c3a0d2245d924d2cfcc41abd4238c3c39e60229e99ec0eeeb579d3ab929b4e883ff7519f5395f7088f0d6f6a956b74c4619b503aa487dc280e6a2012b629a98bf0e367530dad502b21d3b81a7a78e605d7be7c5b12710d885e39f32ddb56eafc8a778d6458d03d9153559fb4733899a2473522d4a01c8aeae9e539eb7e81de7928482295753c8433e01fe7c026e826a66bf1570f322744ebd57da40e4c47a41ef11b72bca854471da6ddf222a4565948e3249269fe2c00ee9b0e803a72f0719c041e1ea5b3c8e30e2346699e99feed4907272df8a114337324c5822b09122e69c642c37a76f76f6a9d1483250f0587dcd96e64a52b0df51fb45f45acf3905eaf55bd2020f7f94e5338bfab928ce369ec35d888bd6d61faa12483a6939554cbd7d4210924ef0fea13718f6ac4ac2f719a1187f5911d274e5e6afed3be2f9e293878414e544d59811f055c6c835e83d447f6bc17c4f3485a7378305b13f7850456d3907a558ecdc81027e225fd5747d092bb40f138cb3b56027558138a9b3ee2c7a771bbc8f77eea38690a9251021647fe779d1829116f387c021f58ae47fbaf190bc14937796d97595145cb293a1cf8a0a43d171df283b89206db3358949b7b2ab0e780b1e0d16c5e2a65780666d4a3fb6010bfd859d5fea93b0f6ec8235028194cfb1b19b427b0dbb444cf546a171640e1a4a10d5babb429b1fb8e78ca4758aabe598acefc4c4665909027ae34cca17c571d081b89047792736b72623071b66412afc165aa8f7a5a5e8ad4672b08a625610a5d92fb400b88a2c7f98e2dccd5b2a42aa10fc51c0e9898f6b543713fb16543758db64742999362b35dff93d1e698e7c9e174574175563893ee9e4cbb49a3b7f62f13429dbb7d89fb8db799a6d0108a0ce044cdc343e610e4c3a9f60f024363f7ac6050d4a7f9a28a1d497baba237e1def126d7619b5a50bb3ad3272d0186d7881d5ba887f6f5924572a77f2518821731a270ee30150ce7a690a6902d"}) ioctl$BTRFS_IOC_SET_RECEIVED_SUBVOL(r4, 0xc0c89425, &(0x7f0000000540)={"cd69c5a38b908007ee67d4021784f149", r8, r10, {0xc5, 0x3}, {0x101, 0x2}, 0x3, [0x2000000, 0x2, 0x4, 0x7fffffffffffffff, 0x5, 0x4000000000000, 0xfffffffffffffff7, 0x7, 0x7, 0x4, 0x6, 0x0, 0x6, 0x80, 0x4, 0x1]}) close(r0) execve(&(0x7f0000000140)='./file0\x00', 0x0, 0x0) r11 = openat$vimc0(0xffffffffffffff9c, &(0x7f0000000180), 0x2, 0x0) ioctl$VIDIOC_G_STD(r11, 0x80085617, &(0x7f00000001c0)) 1m7.241093896s ago: executing program 2 (id=475): socket$nl_generic(0x10, 0x3, 0x10) r0 = openat$sw_sync(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$SW_SYNC_IOC_CREATE_FENCE(r0, 0xc0285700, &(0x7f0000000100)={0x1, "ff0f000000000000f5a72d866b0000000000f0ffdefe00"}) r1 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000400)={0x1, &(0x7f0000000380)=[{0x6, 0x0, 0x0, 0x7fffffff}]}) r2 = openat$dma_heap(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$DMA_HEAP_IOCTL_ALLOC(r2, 0xc0184800, &(0x7f0000000100)={0x4, r1}) (async) ioctl$DMA_HEAP_IOCTL_ALLOC(r2, 0xc0184800, &(0x7f0000000100)={0x4, r1}) ioctl$DMA_BUF_SET_NAME_A(r3, 0x40086203, &(0x7f00000001c0)='\x02\x00\x00\x00\x05\x00\x00\x00-control\x00') write$uinput_user_dev(0xffffffffffffffff, &(0x7f0000000400)={'syz0\x00', {0x3, 0x2, 0x6, 0xfffa}, 0x3a, [0x3, 0x401, 0xf, 0x8, 0x80, 0x2, 0x7, 0x7f, 0xa9, 0x4d, 0x6, 0x5f, 0x9, 0x15, 0xffff2d37, 0xff7fff01, 0x6, 0x5, 0x7, 0x5, 0x6, 0x0, 0x7, 0x3c5b, 0x1, 0x24, 0xd, 0x1, 0x0, 0xffffffff, 0xe661, 0x4, 0x7, 0x5, 0x8, 0x4c74, 0x10000, 0x246, 0x3, 0xe, 0x0, 0x80008071, 0x7, 0x17, 0x1, 0x7, 0x5, 0x3e, 0x18e, 0x6, 0x6, 0x0, 0x8, 0x4, 0x8, 0x3ff, 0x80, 0x0, 0x5, 0x6, 0x8, 0x4, 0x1, 0x40], [0x10000007, 0x9, 0x8000012f, 0x8004, 0x5, 0xfffffff3, 0x129432f6, 0xc8, 0xf1, 0xe, 0x2bf, 0x6c7, 0x9, 0xfffffffc, 0x3, 0x0, 0x0, 0x5, 0x2f, 0xe, 0x312, 0x66abcbd2, 0xea4, 0x0, 0x4, 0x1007, 0x7fff, 0x6, 0x400, 0x401, 0x6, 0x1, 0xff, 0x5, 0x1000005, 0x5f31, 0xd, 0x4e0, 0x381, 0x4, 0xb, 0x4, 0x9, 0x8, 0x40, 0x6, 0x47, 0x8000, 0x1, 0xfe000000, 0xffff, 0x2, 0x4, 0x9, 0x3, 0x3, 0x4000009, 0x6, 0x0, 0x3, 0xbc45, 0x48c93690, 0x42, 0x3], [0x7, 0xffff, 0x3ff, 0x5, 0xfffffffd, 0x100, 0x4, 0x9, 0x5, 0x7fff, 0x0, 0x5, 0xb, 0x4, 0x5, 0x5, 0x0, 0x1ef, 0x5, 0x808, 0x86, 0x3, 0x303c, 0x3e7, 0xb, 0x5, 0x2, 0x2, 0x3, 0x20000008, 0x4, 0x6d01, 0x6, 0x38, 0x200, 0x1fd, 0x80, 0x3, 0x4, 0x2950bfaf, 0x1000, 0xa2, 0x4, 0xa9, 0x5, 0x6, 0xac8, 0xbf, 0x2, 0x3, 0x7ff, 0x12b, 0x4, 0x1, 0xa, 0xffffffff, 0x5, 0x1c, 0x120000, 0x7ff, 0x2006, 0x80a2ed, 0x4, 0x25], [0x9, 0xbb33, 0x7, 0xb, 0x5, 0x938, 0x6, 0x6, 0x0, 0xb9, 0xce4, 0x1ff, 0x2, 0x57, 0x5, 0x3, 0x2, 0x10000, 0x4, 0x7fff, 0xffff, 0xa620, 0x1, 0x5, 0x1, 0x2000002, 0x150, 0x60a7, 0x6, 0x16, 0xffffffff, 0x80000000, 0x5, 0x5, 0xc4, 0x1, 0xfffff000, 0x10000, 0x3, 0x7e, 0x9, 0x9622, 0x7, 0xaf, 0x20000008, 0x5, 0x226, 0x2, 0x5, 0x0, 0x30b1d693, 0xa1f, 0xf40, 0x7, 0x530e, 0x6c1b, 0xfffffffd, 0x4, 0x5, 0x7ff, 0xd7, 0x200, 0xb, 0xfff]}, 0x45c) (async) write$uinput_user_dev(0xffffffffffffffff, &(0x7f0000000400)={'syz0\x00', {0x3, 0x2, 0x6, 0xfffa}, 0x3a, [0x3, 0x401, 0xf, 0x8, 0x80, 0x2, 0x7, 0x7f, 0xa9, 0x4d, 0x6, 0x5f, 0x9, 0x15, 0xffff2d37, 0xff7fff01, 0x6, 0x5, 0x7, 0x5, 0x6, 0x0, 0x7, 0x3c5b, 0x1, 0x24, 0xd, 0x1, 0x0, 0xffffffff, 0xe661, 0x4, 0x7, 0x5, 0x8, 0x4c74, 0x10000, 0x246, 0x3, 0xe, 0x0, 0x80008071, 0x7, 0x17, 0x1, 0x7, 0x5, 0x3e, 0x18e, 0x6, 0x6, 0x0, 0x8, 0x4, 0x8, 0x3ff, 0x80, 0x0, 0x5, 0x6, 0x8, 0x4, 0x1, 0x40], [0x10000007, 0x9, 0x8000012f, 0x8004, 0x5, 0xfffffff3, 0x129432f6, 0xc8, 0xf1, 0xe, 0x2bf, 0x6c7, 0x9, 0xfffffffc, 0x3, 0x0, 0x0, 0x5, 0x2f, 0xe, 0x312, 0x66abcbd2, 0xea4, 0x0, 0x4, 0x1007, 0x7fff, 0x6, 0x400, 0x401, 0x6, 0x1, 0xff, 0x5, 0x1000005, 0x5f31, 0xd, 0x4e0, 0x381, 0x4, 0xb, 0x4, 0x9, 0x8, 0x40, 0x6, 0x47, 0x8000, 0x1, 0xfe000000, 0xffff, 0x2, 0x4, 0x9, 0x3, 0x3, 0x4000009, 0x6, 0x0, 0x3, 0xbc45, 0x48c93690, 0x42, 0x3], [0x7, 0xffff, 0x3ff, 0x5, 0xfffffffd, 0x100, 0x4, 0x9, 0x5, 0x7fff, 0x0, 0x5, 0xb, 0x4, 0x5, 0x5, 0x0, 0x1ef, 0x5, 0x808, 0x86, 0x3, 0x303c, 0x3e7, 0xb, 0x5, 0x2, 0x2, 0x3, 0x20000008, 0x4, 0x6d01, 0x6, 0x38, 0x200, 0x1fd, 0x80, 0x3, 0x4, 0x2950bfaf, 0x1000, 0xa2, 0x4, 0xa9, 0x5, 0x6, 0xac8, 0xbf, 0x2, 0x3, 0x7ff, 0x12b, 0x4, 0x1, 0xa, 0xffffffff, 0x5, 0x1c, 0x120000, 0x7ff, 0x2006, 0x80a2ed, 0x4, 0x25], [0x9, 0xbb33, 0x7, 0xb, 0x5, 0x938, 0x6, 0x6, 0x0, 0xb9, 0xce4, 0x1ff, 0x2, 0x57, 0x5, 0x3, 0x2, 0x10000, 0x4, 0x7fff, 0xffff, 0xa620, 0x1, 0x5, 0x1, 0x2000002, 0x150, 0x60a7, 0x6, 0x16, 0xffffffff, 0x80000000, 0x5, 0x5, 0xc4, 0x1, 0xfffff000, 0x10000, 0x3, 0x7e, 0x9, 0x9622, 0x7, 0xaf, 0x20000008, 0x5, 0x226, 0x2, 0x5, 0x0, 0x30b1d693, 0xa1f, 0xf40, 0x7, 0x530e, 0x6c1b, 0xfffffffd, 0x4, 0x5, 0x7ff, 0xd7, 0x200, 0xb, 0xfff]}, 0x45c) ppoll(&(0x7f00000000c0)=[{}, {}], 0x20000000000000dc, 0x0, 0x0, 0x0) r4 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f00000000c0)={0x1, &(0x7f0000000100)=[{0x6, 0x0, 0x0, 0x7fff0006}]}) close_range(r4, 0xffffffffffffffff, 0x0) (async) close_range(r4, 0xffffffffffffffff, 0x0) 1m7.145132834s ago: executing program 2 (id=477): r0 = openat$incfs(0xffffffffffffff9c, &(0x7f0000000000)='.pending_reads\x00', 0x143100, 0x2a) ioctl$SG_BLKTRACETEARDOWN(r0, 0x1276, 0x0) r1 = socket$nl_generic(0x10, 0x3, 0x10) r2 = openat$sw_sync(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) newfstatat(0xffffffffffffff9c, &(0x7f0000000080)='./file0\x00', &(0x7f00000000c0)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x2000) quotactl_fd$Q_GETFMT(r2, 0xffffffff80000401, r3, &(0x7f0000000140)) ioctl$SYNC_IOC_MERGE(r0, 0xc0303e03, &(0x7f0000000180)={"cf744542c7021a8adbcf77e3c3082bdd3c3ea613aa9234e481f48e1daf79d118", r0, 0xffffffffffffffff}) fsetxattr$trusted_overlay_redirect(r2, &(0x7f00000001c0), &(0x7f0000000200)='./file0\x00', 0x8, 0x1) ioctl$ifreq_SIOCGIFINDEX_vcan(r1, 0x8933, &(0x7f0000000280)={'vxcan1\x00', 0x0}) sendmsg$nl_route(r0, &(0x7f0000000340)={&(0x7f0000000240)={0x10, 0x0, 0x0, 0x400000}, 0xc, &(0x7f0000000300)={&(0x7f00000002c0)=@ipv4_deladdr={0x40, 0x15, 0x400, 0x70bd25, 0x25dfdbfd, {0x2, 0x0, 0x180, 0xc8, r6}, [@IFA_LOCAL={0x8, 0x2, @multicast2}, @IFA_BROADCAST={0x8, 0x4, @private=0xa010100}, @IFA_LOCAL={0x8, 0x2, @empty}, @IFA_FLAGS={0x8, 0x8, 0x421}, @IFA_LOCAL={0x8, 0x2, @local}]}, 0x40}, 0x1, 0x0, 0x0, 0x4080}, 0x80) quotactl_fd$Q_GETNEXTQUOTA(r1, 0x0, r3, &(0x7f0000000380)) r7 = openat$selinux_policy(0xffffffffffffff9c, &(0x7f0000000400), 0x0, 0x0) ioctl$BLKRAGET(r7, 0x1263, &(0x7f0000000440)) ioctl$DRM_IOCTL_AGP_ENABLE(r0, 0x40086432, &(0x7f0000000480)=0x4) write$P9_RGETATTR(r7, &(0x7f00000004c0)={0xa0, 0x19, 0x1, {0x10a0, {0x40, 0x3, 0x4}, 0x80, r3, r4, 0xa, 0xffffffff, 0x4, 0x401, 0xd463, 0x10001, 0xc72, 0x0, 0x3, 0x100, 0xfbc, 0xfffffffffffffff1, 0x44, 0x8, 0x8000}}, 0xa0) splice(r5, &(0x7f0000000580)=0xf, r0, &(0x7f00000005c0)=0x6, 0x6, 0x1) write$P9_RSTATFS(r0, &(0x7f0000000600)={0x43, 0x9, 0x1, {0xffffffff, 0x2, 0x4, 0x80000001, 0xd, 0x100000001, 0x0, 0x7b8a3641, 0x80}}, 0x43) ioctl$PPPIOCGFLAGS(r0, 0x8004745a, &(0x7f0000000680)) ioctl$PPPIOCSMRRU(r7, 0x4004743b, &(0x7f00000006c0)=0x3) r8 = socket$netlink(0x10, 0x3, 0x8) socket$nl_generic(0x10, 0x3, 0x10) ioctl$BTRFS_IOC_SCRUB(r7, 0xc400941b, &(0x7f0000000700)={0x0, 0x8, 0x6, 0x1}) ioctl$BTRFS_IOC_DEV_INFO(r8, 0xd000941e, &(0x7f0000000b00)={r9, "f49d0822826d0b6709605933239cd7ea"}) r10 = syz_init_net_socket$x25(0x9, 0x5, 0x0) ioctl$INCFS_IOC_READ_FILE_SIGNATURE(r10, 0x8010671f, &(0x7f0000001b80)={&(0x7f0000001b00)=""/71, 0x47}) r11 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) ioctl$KVM_CREATE_VCPU(r11, 0xae41, 0x2) setsockopt$CAN_RAW_FILTER(r7, 0x65, 0x1, &(0x7f0000001bc0)=[{{0x2, 0x0, 0x0, 0x1}, {0x3, 0x1, 0x1, 0x1}}, {{0x1, 0x0, 0x0, 0x1}, {0x4, 0x0, 0x0, 0x1}}, {{}, {0x4, 0x0, 0x0, 0x1}}, {{0x3, 0x1, 0x1, 0x1}, {0x3, 0x0, 0x1, 0x1}}, {{0x1, 0x1, 0x1, 0x1}, {0x3, 0x0, 0x1}}, {{0x0, 0x1, 0x1}, {0x2, 0x0, 0x0, 0x1}}, {{0x2, 0x1, 0x1, 0x1}, {0x4, 0x1}}, {{0x0, 0x1, 0x0, 0x1}, {0x1}}], 0x40) syz_init_net_socket$llc(0x1a, 0x2, 0x0) io_uring_register$IORING_REGISTER_SYNC_CANCEL(r0, 0x18, &(0x7f0000001cc0)={0x8, 0xffffffffffffffff, 0x20, {0x8, 0x533c}, 0xcc}, 0x1) 1m7.144951922s ago: executing program 2 (id=478): bind$can_j1939(0xffffffffffffffff, &(0x7f0000000500)={0x1d, 0x0, 0x5, {0x1, 0xff, 0x3}, 0x1}, 0x18) r0 = syz_open_dev$char_usb(0xc, 0xb4, 0x0) preadv(r0, &(0x7f0000001280)=[{&(0x7f00000000c0)=""/170, 0xaa}], 0x1, 0xfffffff5, 0x2) syz_usb_disconnect(0xffffffffffffffff) syz_usb_connect$cdc_ncm(0x2, 0x9b, &(0x7f00000001c0)={{0x12, 0x1, 0x201, 0x2, 0x0, 0x0, 0x40, 0x525, 0xa4a1, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x89, 0x2, 0x1, 0xdf, 0x70, 0x8, {{0x9, 0x4, 0x0, 0x0, 0x1, 0x2, 0xd, 0x0, 0x0, {{0x5}, {0x5, 0x24, 0x0, 0x2}, {0xd, 0x24, 0xf, 0x1, 0x2, 0x8, 0x3ff, 0x1}, {0x6, 0x24, 0x1a, 0x7, 0x46}, [@dmm={0x7, 0x24, 0x14, 0x9, 0x4}, @country_functional={0x6, 0x24, 0x7, 0x10, 0x43}, @network_terminal={0x7, 0x24, 0xa, 0x2, 0x4, 0xe, 0x7}, @acm={0x4, 0x24, 0x2, 0x6}, @mdlm={0x15, 0x24, 0x12, 0x400}]}, {{0x9, 0x5, 0x81, 0x3, 0x400, 0xff, 0xd, 0x9}}}, {}, {0x9, 0x4, 0x1, 0x1, 0x2, 0x2, 0xd, 0x0, 0x0, "", {{{0x9, 0x5, 0x82, 0x2, 0x40, 0x7, 0x81, 0xfa}}, {{0x9, 0x5, 0x3, 0x2, 0x8, 0x5, 0x3, 0x5}}}}}}}]}}, 0x0) 1m5.955627661s ago: executing program 2 (id=490): getpid() mkdirat(0xffffffffffffff9c, &(0x7f0000000080)='./file1\x00', 0x0) mount$fuse(0x0, 0x0, 0x0, 0xfc5cd7921c2c19c4, &(0x7f0000000400)=ANY=[@ANYBLOB='fd=', @ANYRESHEX=0x0]) mount(0x0, &(0x7f0000000380)='./file1\x00', &(0x7f0000000040)='autofs\x00', 0x0, &(0x7f0000000400)) r0 = syz_open_dev$video4linux(&(0x7f0000000040), 0x955a, 0x0) ioctl$VIDIOC_SUBDEV_G_FRAME_INTERVAL(r0, 0xc0305615, &(0x7f0000000080)={0x0, {0x4, 0x200}}) r1 = socket$inet6(0xa, 0x800000000000002, 0x0) sendto$inet6(r1, 0x0, 0x0, 0x2004c880, &(0x7f0000000540)={0xa, 0x4e20, 0x8000002, @ipv4={'\x00', '\xff\xff', @local}}, 0x1c) r2 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000040)={0x1, &(0x7f0000000000)=[{0x6, 0x0, 0x0, 0x7fff7ffc}]}) close_range(r2, 0xffffffffffffffff, 0x0) chdir(&(0x7f0000000080)='./file1\x00') r3 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) setpgid(r3, 0x0) chdir(&(0x7f00000000c0)='./file1\x00') r4 = syz_io_uring_setup(0x407f72, &(0x7f00000004c0)={0x0, 0x4d5a, 0x800, 0x2, 0x309}, &(0x7f0000000bc0), &(0x7f0000000c00)) r5 = syz_io_uring_setup(0x3fec, &(0x7f0000000000)={0x0, 0x8d69, 0x0, 0x10000, 0x0, 0x0, r4}, &(0x7f00000003c0), &(0x7f00000000c0)=0x0) io_uring_register$IORING_REGISTER_FILES2(r5, 0xd, &(0x7f0000000280)={0x9, 0x0, 0x0, &(0x7f00000010c0)=[{&(0x7f0000000c40)=""/85, 0x55}, {&(0x7f0000001a40)=""/4096, 0x1000}, {&(0x7f0000000cc0)=""/7, 0x7}, {&(0x7f0000000d00)=""/188, 0xbc}, {&(0x7f0000000dc0)=""/22, 0x16}, {&(0x7f0000000e00)=""/213, 0xd5}, {&(0x7f0000000f00)=""/192, 0xc0}, {&(0x7f0000000fc0)=""/188, 0xbc}, {&(0x7f0000001080)=""/10, 0xa}], 0x0}, 0x20) io_uring_register$IORING_UNREGISTER_FILES(r5, 0x3, 0x0, 0x0) r7 = socket(0x400000000010, 0x3, 0x0) sendmsg$nl_route_sched(r7, 0x0, 0x20044000) sendmsg$NFT_BATCH(r7, &(0x7f0000000580)={&(0x7f0000000200)={0x10, 0x0, 0x0, 0x400}, 0xc, &(0x7f0000000240)={&(0x7f0000001180)=ANY=[@ANYRESDEC=r6], 0x2c8}, 0x1, 0x0, 0x0, 0x1}, 0x40001) r8 = syz_open_dev$dri(&(0x7f00000000c0), 0x1ff, 0x0) r9 = syz_open_dev$dri(&(0x7f0000000080), 0x40100001, 0x0) ioctl$DRM_IOCTL_SET_CLIENT_CAP(r9, 0x4010640d, &(0x7f0000000000)={0x3, 0x2}) ioctl$DRM_IOCTL_MODE_GETPLANERESOURCES(r9, 0xc01064b5, &(0x7f0000000140)={&(0x7f0000000100)=[0x0], 0x1}) ioctl$DRM_IOCTL_MODE_GETPLANE(r8, 0xc02064b6, &(0x7f0000000180)={r10, 0x0, 0x0, 0x0, 0x0, 0x6, &(0x7f0000000040)=[0x0, 0x0, 0x0, 0x0, 0x0, 0x0]}) mount$9p_fd(0x0, &(0x7f00000001c0)='./file1\x00', 0x0, 0x10000, 0x0) r11 = socket$kcm(0x21, 0x2, 0x2) sendmsg$kcm(r11, &(0x7f0000000140)={&(0x7f0000000440)=@rxrpc=@in4={0x21, 0x0, 0x2, 0x10, {0x2, 0x0, @loopback}}, 0x80, &(0x7f0000000980)=[{&(0x7f0000000a00)="00149088015a873f73b78508ac3cb20ce356b2432cff9fe78d7c8ace6773ef3c56d4134faf6710e7e496e4ac0400000077ba9821b2dec33454ecd2ff939e1d7c14782117b4334d47b5b60c15da0b31cf96850aaf36ba50cb9b96743d63c7395b48c5988542ca5a859ef5cc6beba68d8564f4f843d46cc355e82424576925944b8cd6d51fd96870ba9cae7b0526b880be66a442fa6ef3ef46f8d59987d1f558a9204a71682d0f135d082e463237efeba1c053d8b702552d435aa16b5a5e17a6db396397f01e30cbbf260ecfda140230b6a9b56e58e421ea624d4d40fc07b947a59e41106003602e53322ac9f0447f22ba6e36e3ccfcc527ff000000002ddee37dc0f1a122a00fd1db6b9827e66c070f4f0620f6da88e7490f69146bc1a7003b0c232dc0bcabd88d632cd3313d96d7a00ede907a38877a2b9e91c5fc09555d802500006801f66d48f70e70bf6fd7403182c18d3ed1645421c9a5e952af87ab0683e6a1fff5e9f4dd6046fc3d1481c63732d0dc0a5d97d5effd67f5015a8b8e0ab0fba7f8e464d4c95c683b1bf39332a282cc2cdb58cb4e97b84d48482033d1eaea345b898027aa2f4cacfd6685c5b264c803441dbfa74db87668", 0x1b9}, {0x0}, {&(0x7f0000000880)="67bcbd8b268b074d2e6b336de74169ab09ac165a09e4b2868cefb37a505672da3c9fa1dc5bd733c01f9c7043cbd92aa46c53db708c9118477754384b5f3042bf5c74da89c55c0cd52056f2fb6bbf4102a17c85502c27b773c5b0d5c741a9b783995e706788a57525c14aaa3c8e6688e68d8114b084e83ea8d081740dba27e0923cc63eda3964270a7731f6f2a85d27f0598f29a18d1701683b29600309287e0837d3c098491b3df2ca4c7af4e6393f6cca691b682b856cb4a23f410b4a695eae10dca9d576b198df5458da3afb50626265313a5d1b42e2b210c9bec4874d", 0xde}, {&(0x7f00000002c0)="5d58fa07803a3db415019fe542ad87a5f89995f9f0d68f226981cff5e8140c4755faf31eba336a09bc77960ec0fad8c73337c98f4b9b1ebbbaf149b529cba23cc0e433368f42ecf012b83cc46c9fff301630cc44e44d71837f0898f0be13293ec1", 0x61}, {&(0x7f0000000340)="7ba5b7af87c2783805d62da5c227b5f4ba8adb723059cef75856823cd720e43dbdf33202f4e58c5a22", 0x29}], 0x5, &(0x7f0000001a00)=ANY=[@ANYRES64=r2], 0x10b8}, 0x0) mkdir(&(0x7f0000000000)='./file0/file0\x00', 0x130) 1m5.829595109s ago: executing program 2 (id=491): r0 = socket$inet_udp(0x2, 0x2, 0x0) getrandom(&(0x7f0000000240)=""/286, 0xffffff9a, 0x0) r1 = syz_open_dev$sg(&(0x7f0000000440), 0xa, 0x8000) ioctl$SG_SET_TIMEOUT(r1, 0x2201, &(0x7f00000001c0)=0xffffff37) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x66) r2 = openat$uhid(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) write$UHID_CREATE(r2, &(0x7f00000000c0)={0x0, {'syz0\x00', 'syz0\x00', 'syz1\x00', &(0x7f00000006c0)=""/83, 0x53}}, 0x120) writev(r2, &(0x7f00000002c0)=[{&(0x7f00000003c0)="0e000000", 0x4}, {&(0x7f0000000040)="4010bac4", 0x4}], 0x2) ioctl$sock_ipv4_tunnel_SIOCGETTUNNEL(r0, 0x89f0, 0x0) 1m5.593021475s ago: executing program 2 (id=492): mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x4) ioctl$sock_FIOGETOWN(0xffffffffffffffff, 0x8903, &(0x7f0000000000)=0x0) r1 = openat$uinput(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) write$uinput_user_dev(r1, &(0x7f0000000100)={'syz0\x00', {0x0, 0x0, 0x80, 0xfffc}, 0x7, [0x0, 0x80000000, 0x0, 0x0, 0x8, 0x0, 0x0, 0x77, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, 0xffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffd, 0x0, 0x0, 0x0, 0x0, 0x20000, 0x0, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2], [0xffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8, 0x0, 0x0, 0x0, 0x0, 0x3d, 0xffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x80, 0x1, 0x200, 0x0, 0x0, 0x20000, 0x0, 0x0, 0x0, 0x400000, 0x0, 0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x800000, 0x0, 0x0, 0x0, 0x4, 0x0, 0x9, 0xfffffffd], [0x0, 0x401, 0xfffffffc, 0x0, 0x0, 0x0, 0x0, 0x800, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffff8, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, 0x1, 0x0, 0x0, 0x20, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4000000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1], [0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8001, 0x0, 0x0, 0x0, 0x0, 0x3, 0x100000, 0x0, 0x0, 0x0, 0x101, 0x0, 0x0, 0x0, 0x8000, 0x0, 0x0, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1000]}, 0x45c) ioctl$UI_DEV_SETUP(r1, 0x5501, 0x0) readv(r1, &(0x7f0000000080)=[{&(0x7f0000001340)=""/104, 0x68}], 0x1) write$input_event(r1, &(0x7f0000000000)={{0x77359400}, 0x15}, 0xfe4f) r2 = syz_open_procfs(r0, &(0x7f0000000080)='task\x00') mkdir(&(0x7f0000000000)='./file0\x00', 0x0) r3 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000000), 0x8000, 0x0) ioctl$IOMMU_TEST_OP_MD_CHECK_MAP(r3, 0x3ba0, &(0x7f0000000280)={0x48, 0x3, 0x0, 0x0, 0x100000000, 0x0, 0x0}) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mkdir(&(0x7f00000004c0)='./bus\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000000), 0x10000, &(0x7f0000000400)) chdir(&(0x7f00000000c0)='./bus\x00') r4 = openat$dir(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) r5 = socket(0x15, 0x5, 0x0) getsockopt(r5, 0x200000000114, 0x2711, &(0x7f0000c35fff)=""/1, &(0x7f0000000000)=0xf002) socket$packet(0x11, 0x3, 0x300) getsockname$packet(0xffffffffffffffff, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f00000000c0)=0x14) getuid() getdents64(r4, 0x0, 0x0) iopl(0x3) getitimer(0x1, 0x0) getdents(r4, 0x0, 0x58) r6 = syz_io_uring_setup(0x239, &(0x7f0000000380)={0x0, 0x154, 0x8000, 0xfffffffe, 0x4}, &(0x7f0000000180)=0x0, &(0x7f00000001c0)=0x0) syz_io_uring_submit(r7, r8, &(0x7f0000000040)=@IORING_OP_TEE={0x21, 0x40, 0x0, @fd_index=0x2, 0x0, 0x0, 0x8, 0x62ca00576f1a33c5, 0x1, {0x0, 0x0, r6}}) io_uring_enter(r6, 0x2ded, 0x4000, 0x0, 0x0, 0x0) lseek(r2, 0xfffffffffffffffe, 0x2) 1m5.568903767s ago: executing program 33 (id=492): mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x4) ioctl$sock_FIOGETOWN(0xffffffffffffffff, 0x8903, &(0x7f0000000000)=0x0) r1 = openat$uinput(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) write$uinput_user_dev(r1, &(0x7f0000000100)={'syz0\x00', {0x0, 0x0, 0x80, 0xfffc}, 0x7, [0x0, 0x80000000, 0x0, 0x0, 0x8, 0x0, 0x0, 0x77, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, 0xffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffd, 0x0, 0x0, 0x0, 0x0, 0x20000, 0x0, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2], [0xffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8, 0x0, 0x0, 0x0, 0x0, 0x3d, 0xffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x80, 0x1, 0x200, 0x0, 0x0, 0x20000, 0x0, 0x0, 0x0, 0x400000, 0x0, 0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x800000, 0x0, 0x0, 0x0, 0x4, 0x0, 0x9, 0xfffffffd], [0x0, 0x401, 0xfffffffc, 0x0, 0x0, 0x0, 0x0, 0x800, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffff8, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, 0x1, 0x0, 0x0, 0x20, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4000000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1], [0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8001, 0x0, 0x0, 0x0, 0x0, 0x3, 0x100000, 0x0, 0x0, 0x0, 0x101, 0x0, 0x0, 0x0, 0x8000, 0x0, 0x0, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1000]}, 0x45c) ioctl$UI_DEV_SETUP(r1, 0x5501, 0x0) readv(r1, &(0x7f0000000080)=[{&(0x7f0000001340)=""/104, 0x68}], 0x1) write$input_event(r1, &(0x7f0000000000)={{0x77359400}, 0x15}, 0xfe4f) r2 = syz_open_procfs(r0, &(0x7f0000000080)='task\x00') mkdir(&(0x7f0000000000)='./file0\x00', 0x0) r3 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000000), 0x8000, 0x0) ioctl$IOMMU_TEST_OP_MD_CHECK_MAP(r3, 0x3ba0, &(0x7f0000000280)={0x48, 0x3, 0x0, 0x0, 0x100000000, 0x0, 0x0}) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mkdir(&(0x7f00000004c0)='./bus\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000000), 0x10000, &(0x7f0000000400)) chdir(&(0x7f00000000c0)='./bus\x00') r4 = openat$dir(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) r5 = socket(0x15, 0x5, 0x0) getsockopt(r5, 0x200000000114, 0x2711, &(0x7f0000c35fff)=""/1, &(0x7f0000000000)=0xf002) socket$packet(0x11, 0x3, 0x300) getsockname$packet(0xffffffffffffffff, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f00000000c0)=0x14) getuid() getdents64(r4, 0x0, 0x0) iopl(0x3) getitimer(0x1, 0x0) getdents(r4, 0x0, 0x58) r6 = syz_io_uring_setup(0x239, &(0x7f0000000380)={0x0, 0x154, 0x8000, 0xfffffffe, 0x4}, &(0x7f0000000180)=0x0, &(0x7f00000001c0)=0x0) syz_io_uring_submit(r7, r8, &(0x7f0000000040)=@IORING_OP_TEE={0x21, 0x40, 0x0, @fd_index=0x2, 0x0, 0x0, 0x8, 0x62ca00576f1a33c5, 0x1, {0x0, 0x0, r6}}) io_uring_enter(r6, 0x2ded, 0x4000, 0x0, 0x0, 0x0) lseek(r2, 0xfffffffffffffffe, 0x2) 46.760630592s ago: executing program 3 (id=292): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000140)={0x6, 0x10, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000000000000000000000181100009607325919177b407b8a6e34695caa595b7ff3e4b1dedd64ddc691e689779c84d2ec034bd7c28cc0d38d5b6578830eabf5019bcc674ab3dff49604ca2661641b6ad4303d4521deb9fb5b655f113240fff66bb004418f2156df30ea2b7b68ae7c37659a36c2db52cd96d8dba9a3c5170084b9dd8c8d15b4d6ff29052cdf8e33ca986115aca19df1a48e963d", @ANYRES32=r0, @ANYRES32=r0], &(0x7f0000000100)='GPL\x00', 0x7, 0x108, &(0x7f00000002c0)=""/264, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 44.522507386s ago: executing program 1 (id=674): r0 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$USBDEVFS_DISCONNECT_CLAIM(0xffffffffffffffff, 0x8108551b, &(0x7f0000000000)={0x0, 0x0, "ec9fe44d4dbe56a60274fcffffffffffffff14e315eeb406bfdd73835e57efa94b1a0275781c647aa7e3470c6028643b17832b10b386a6f73791011c26a9aa141f406e312295ee620a9a46577b9249b738fe7750bec83bf6ed5b67213fa7d6c0823fd154ed29ede1ff379742c3f0b46caa357d70ee438f901d7645c3f87e4b21482b76f2ad8eaac090272081f98fd2e3e5a63e006204df635e731a5bfcf142f4529517454618de595cd179445b4bdbf698b9986356f0ebf7d25a57774ef474f86a3ad24ae9f0bf94b99e6b87de5f79d383d05bb32701daed400785a49788f08caecc9e0c48a3740bbe6e1c1fd400cfdfe756bc00d08e36655c00"}) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x18, 0x4, &(0x7f00000003c0)=ANY=[@ANYBLOB="b4000000000b00007910000000000000c310000401000000950074000000000031fb0d3a42319fa204399d17d34e075fdcda533ab1aa71ab1d764152e63925789381db3fe455e8dadc7dcf81189517730bed5d8036168bd2e27cc611027d29066927603deb92de3141e8ed7ac5b8902070213cdfdc506c4890cdeb50347c32060581172b94c6ba22a2b58eb6cbad46ed6e7964a2ba103b0b36f790bb41931f9a3d4dd127c1b4e49f7468f5e623950c4f67581c92ef9e7e8ece17d566c93a114d68c577d694b9844e0d9e306404cfc3bfbead9e1b96c6a6cb639bca6d"], &(0x7f0000003ff6)='GPL\x00', 0x2, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) ioctl$SCSI_IOCTL_SEND_COMMAND(r0, 0x1, &(0x7f0000000080)=ANY=[@ANYBLOB="000000001f0000001a"]) 39.522033133s ago: executing program 3 (id=292): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000140)={0x6, 0x10, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000000000000000000000181100009607325919177b407b8a6e34695caa595b7ff3e4b1dedd64ddc691e689779c84d2ec034bd7c28cc0d38d5b6578830eabf5019bcc674ab3dff49604ca2661641b6ad4303d4521deb9fb5b655f113240fff66bb004418f2156df30ea2b7b68ae7c37659a36c2db52cd96d8dba9a3c5170084b9dd8c8d15b4d6ff29052cdf8e33ca986115aca19df1a48e963d", @ANYRES32=r0, @ANYRES32=r0], &(0x7f0000000100)='GPL\x00', 0x7, 0x108, &(0x7f00000002c0)=""/264, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 38.749905419s ago: executing program 1 (id=674): r0 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$USBDEVFS_DISCONNECT_CLAIM(0xffffffffffffffff, 0x8108551b, &(0x7f0000000000)={0x0, 0x0, "ec9fe44d4dbe56a60274fcffffffffffffff14e315eeb406bfdd73835e57efa94b1a0275781c647aa7e3470c6028643b17832b10b386a6f73791011c26a9aa141f406e312295ee620a9a46577b9249b738fe7750bec83bf6ed5b67213fa7d6c0823fd154ed29ede1ff379742c3f0b46caa357d70ee438f901d7645c3f87e4b21482b76f2ad8eaac090272081f98fd2e3e5a63e006204df635e731a5bfcf142f4529517454618de595cd179445b4bdbf698b9986356f0ebf7d25a57774ef474f86a3ad24ae9f0bf94b99e6b87de5f79d383d05bb32701daed400785a49788f08caecc9e0c48a3740bbe6e1c1fd400cfdfe756bc00d08e36655c00"}) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x18, 0x4, &(0x7f00000003c0)=ANY=[@ANYBLOB="b4000000000b00007910000000000000c310000401000000950074000000000031fb0d3a42319fa204399d17d34e075fdcda533ab1aa71ab1d764152e63925789381db3fe455e8dadc7dcf81189517730bed5d8036168bd2e27cc611027d29066927603deb92de3141e8ed7ac5b8902070213cdfdc506c4890cdeb50347c32060581172b94c6ba22a2b58eb6cbad46ed6e7964a2ba103b0b36f790bb41931f9a3d4dd127c1b4e49f7468f5e623950c4f67581c92ef9e7e8ece17d566c93a114d68c577d694b9844e0d9e306404cfc3bfbead9e1b96c6a6cb639bca6d"], &(0x7f0000003ff6)='GPL\x00', 0x2, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) ioctl$SCSI_IOCTL_SEND_COMMAND(r0, 0x1, &(0x7f0000000080)=ANY=[@ANYBLOB="000000001f0000001a"]) 29.10164429s ago: executing program 1 (id=674): r0 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$USBDEVFS_DISCONNECT_CLAIM(0xffffffffffffffff, 0x8108551b, &(0x7f0000000000)={0x0, 0x0, "ec9fe44d4dbe56a60274fcffffffffffffff14e315eeb406bfdd73835e57efa94b1a0275781c647aa7e3470c6028643b17832b10b386a6f73791011c26a9aa141f406e312295ee620a9a46577b9249b738fe7750bec83bf6ed5b67213fa7d6c0823fd154ed29ede1ff379742c3f0b46caa357d70ee438f901d7645c3f87e4b21482b76f2ad8eaac090272081f98fd2e3e5a63e006204df635e731a5bfcf142f4529517454618de595cd179445b4bdbf698b9986356f0ebf7d25a57774ef474f86a3ad24ae9f0bf94b99e6b87de5f79d383d05bb32701daed400785a49788f08caecc9e0c48a3740bbe6e1c1fd400cfdfe756bc00d08e36655c00"}) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x18, 0x4, &(0x7f00000003c0)=ANY=[@ANYBLOB="b4000000000b00007910000000000000c310000401000000950074000000000031fb0d3a42319fa204399d17d34e075fdcda533ab1aa71ab1d764152e63925789381db3fe455e8dadc7dcf81189517730bed5d8036168bd2e27cc611027d29066927603deb92de3141e8ed7ac5b8902070213cdfdc506c4890cdeb50347c32060581172b94c6ba22a2b58eb6cbad46ed6e7964a2ba103b0b36f790bb41931f9a3d4dd127c1b4e49f7468f5e623950c4f67581c92ef9e7e8ece17d566c93a114d68c577d694b9844e0d9e306404cfc3bfbead9e1b96c6a6cb639bca6d"], &(0x7f0000003ff6)='GPL\x00', 0x2, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) ioctl$SCSI_IOCTL_SEND_COMMAND(r0, 0x1, &(0x7f0000000080)=ANY=[@ANYBLOB="000000001f0000001a"]) 28.942082623s ago: executing program 3 (id=292): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000140)={0x6, 0x10, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000000000000000000000181100009607325919177b407b8a6e34695caa595b7ff3e4b1dedd64ddc691e689779c84d2ec034bd7c28cc0d38d5b6578830eabf5019bcc674ab3dff49604ca2661641b6ad4303d4521deb9fb5b655f113240fff66bb004418f2156df30ea2b7b68ae7c37659a36c2db52cd96d8dba9a3c5170084b9dd8c8d15b4d6ff29052cdf8e33ca986115aca19df1a48e963d", @ANYRES32=r0, @ANYRES32=r0], &(0x7f0000000100)='GPL\x00', 0x7, 0x108, &(0x7f00000002c0)=""/264, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 21.901558681s ago: executing program 3 (id=292): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000140)={0x6, 0x10, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000000000000000000000181100009607325919177b407b8a6e34695caa595b7ff3e4b1dedd64ddc691e689779c84d2ec034bd7c28cc0d38d5b6578830eabf5019bcc674ab3dff49604ca2661641b6ad4303d4521deb9fb5b655f113240fff66bb004418f2156df30ea2b7b68ae7c37659a36c2db52cd96d8dba9a3c5170084b9dd8c8d15b4d6ff29052cdf8e33ca986115aca19df1a48e963d", @ANYRES32=r0, @ANYRES32=r0], &(0x7f0000000100)='GPL\x00', 0x7, 0x108, &(0x7f00000002c0)=""/264, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 21.640352955s ago: executing program 1 (id=674): r0 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$USBDEVFS_DISCONNECT_CLAIM(0xffffffffffffffff, 0x8108551b, &(0x7f0000000000)={0x0, 0x0, "ec9fe44d4dbe56a60274fcffffffffffffff14e315eeb406bfdd73835e57efa94b1a0275781c647aa7e3470c6028643b17832b10b386a6f73791011c26a9aa141f406e312295ee620a9a46577b9249b738fe7750bec83bf6ed5b67213fa7d6c0823fd154ed29ede1ff379742c3f0b46caa357d70ee438f901d7645c3f87e4b21482b76f2ad8eaac090272081f98fd2e3e5a63e006204df635e731a5bfcf142f4529517454618de595cd179445b4bdbf698b9986356f0ebf7d25a57774ef474f86a3ad24ae9f0bf94b99e6b87de5f79d383d05bb32701daed400785a49788f08caecc9e0c48a3740bbe6e1c1fd400cfdfe756bc00d08e36655c00"}) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x18, 0x4, &(0x7f00000003c0)=ANY=[@ANYBLOB="b4000000000b00007910000000000000c310000401000000950074000000000031fb0d3a42319fa204399d17d34e075fdcda533ab1aa71ab1d764152e63925789381db3fe455e8dadc7dcf81189517730bed5d8036168bd2e27cc611027d29066927603deb92de3141e8ed7ac5b8902070213cdfdc506c4890cdeb50347c32060581172b94c6ba22a2b58eb6cbad46ed6e7964a2ba103b0b36f790bb41931f9a3d4dd127c1b4e49f7468f5e623950c4f67581c92ef9e7e8ece17d566c93a114d68c577d694b9844e0d9e306404cfc3bfbead9e1b96c6a6cb639bca6d"], &(0x7f0000003ff6)='GPL\x00', 0x2, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) ioctl$SCSI_IOCTL_SEND_COMMAND(r0, 0x1, &(0x7f0000000080)=ANY=[@ANYBLOB="000000001f0000001a"]) 14.54127452s ago: executing program 1 (id=674): r0 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$USBDEVFS_DISCONNECT_CLAIM(0xffffffffffffffff, 0x8108551b, &(0x7f0000000000)={0x0, 0x0, "ec9fe44d4dbe56a60274fcffffffffffffff14e315eeb406bfdd73835e57efa94b1a0275781c647aa7e3470c6028643b17832b10b386a6f73791011c26a9aa141f406e312295ee620a9a46577b9249b738fe7750bec83bf6ed5b67213fa7d6c0823fd154ed29ede1ff379742c3f0b46caa357d70ee438f901d7645c3f87e4b21482b76f2ad8eaac090272081f98fd2e3e5a63e006204df635e731a5bfcf142f4529517454618de595cd179445b4bdbf698b9986356f0ebf7d25a57774ef474f86a3ad24ae9f0bf94b99e6b87de5f79d383d05bb32701daed400785a49788f08caecc9e0c48a3740bbe6e1c1fd400cfdfe756bc00d08e36655c00"}) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x18, 0x4, &(0x7f00000003c0)=ANY=[@ANYBLOB="b4000000000b00007910000000000000c310000401000000950074000000000031fb0d3a42319fa204399d17d34e075fdcda533ab1aa71ab1d764152e63925789381db3fe455e8dadc7dcf81189517730bed5d8036168bd2e27cc611027d29066927603deb92de3141e8ed7ac5b8902070213cdfdc506c4890cdeb50347c32060581172b94c6ba22a2b58eb6cbad46ed6e7964a2ba103b0b36f790bb41931f9a3d4dd127c1b4e49f7468f5e623950c4f67581c92ef9e7e8ece17d566c93a114d68c577d694b9844e0d9e306404cfc3bfbead9e1b96c6a6cb639bca6d"], &(0x7f0000003ff6)='GPL\x00', 0x2, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) ioctl$SCSI_IOCTL_SEND_COMMAND(r0, 0x1, &(0x7f0000000080)=ANY=[@ANYBLOB="000000001f0000001a"]) 14.382049147s ago: executing program 3 (id=292): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000140)={0x6, 0x10, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000000000000000000000181100009607325919177b407b8a6e34695caa595b7ff3e4b1dedd64ddc691e689779c84d2ec034bd7c28cc0d38d5b6578830eabf5019bcc674ab3dff49604ca2661641b6ad4303d4521deb9fb5b655f113240fff66bb004418f2156df30ea2b7b68ae7c37659a36c2db52cd96d8dba9a3c5170084b9dd8c8d15b4d6ff29052cdf8e33ca986115aca19df1a48e963d", @ANYRES32=r0, @ANYRES32=r0], &(0x7f0000000100)='GPL\x00', 0x7, 0x108, &(0x7f00000002c0)=""/264, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 6.999328575s ago: executing program 3 (id=292): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000140)={0x6, 0x10, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000000000000000000000181100009607325919177b407b8a6e34695caa595b7ff3e4b1dedd64ddc691e689779c84d2ec034bd7c28cc0d38d5b6578830eabf5019bcc674ab3dff49604ca2661641b6ad4303d4521deb9fb5b655f113240fff66bb004418f2156df30ea2b7b68ae7c37659a36c2db52cd96d8dba9a3c5170084b9dd8c8d15b4d6ff29052cdf8e33ca986115aca19df1a48e963d", @ANYRES32=r0, @ANYRES32=r0], &(0x7f0000000100)='GPL\x00', 0x7, 0x108, &(0x7f00000002c0)=""/264, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 6.813058428s ago: executing program 1 (id=674): r0 = syz_open_dev$sg(&(0x7f0000000040), 0x0, 0x0) ioctl$USBDEVFS_DISCONNECT_CLAIM(0xffffffffffffffff, 0x8108551b, &(0x7f0000000000)={0x0, 0x0, "ec9fe44d4dbe56a60274fcffffffffffffff14e315eeb406bfdd73835e57efa94b1a0275781c647aa7e3470c6028643b17832b10b386a6f73791011c26a9aa141f406e312295ee620a9a46577b9249b738fe7750bec83bf6ed5b67213fa7d6c0823fd154ed29ede1ff379742c3f0b46caa357d70ee438f901d7645c3f87e4b21482b76f2ad8eaac090272081f98fd2e3e5a63e006204df635e731a5bfcf142f4529517454618de595cd179445b4bdbf698b9986356f0ebf7d25a57774ef474f86a3ad24ae9f0bf94b99e6b87de5f79d383d05bb32701daed400785a49788f08caecc9e0c48a3740bbe6e1c1fd400cfdfe756bc00d08e36655c00"}) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x18, 0x4, &(0x7f00000003c0)=ANY=[@ANYBLOB="b4000000000b00007910000000000000c310000401000000950074000000000031fb0d3a42319fa204399d17d34e075fdcda533ab1aa71ab1d764152e63925789381db3fe455e8dadc7dcf81189517730bed5d8036168bd2e27cc611027d29066927603deb92de3141e8ed7ac5b8902070213cdfdc506c4890cdeb50347c32060581172b94c6ba22a2b58eb6cbad46ed6e7964a2ba103b0b36f790bb41931f9a3d4dd127c1b4e49f7468f5e623950c4f67581c92ef9e7e8ece17d566c93a114d68c577d694b9844e0d9e306404cfc3bfbead9e1b96c6a6cb639bca6d"], &(0x7f0000003ff6)='GPL\x00', 0x2, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) ioctl$SCSI_IOCTL_SEND_COMMAND(r0, 0x1, &(0x7f0000000080)=ANY=[@ANYBLOB="000000001f0000001a"]) 2.522636964s ago: executing program 5 (id=996): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000140), 0x101100, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r1, 0x4020ae46, &(0x7f0000000080)={0x4, 0x2, 0x0, 0x2000, &(0x7f0000000000/0x2000)=nil}) mknod$loop(&(0x7f0000000140)='./file0\x00', 0xfff, 0x0) execve(&(0x7f0000000040)='./file0\x00', 0x0, 0x0) mount(0x0, &(0x7f00000000c0)='./file0\x00', 0x0, 0x21052, 0x0) execve(&(0x7f0000000000)='./file0\x00', 0x0, 0x0) execve(&(0x7f0000000080)='./file0\x00', 0x0, &(0x7f0000000240)={[&(0x7f0000000100)='#)[)\\-@\x00']}) syz_kvm_setup_cpu$x86(r1, r2, &(0x7f0000000000/0x18000)=nil, &(0x7f00000000c0)=[@textreal={0x8, &(0x7f0000000200)="83f100660f017e0bf3670f22c2dbf566b91008000066b8db91000066ba000000000f09d9be0100c4c3b5cea4013200f0f7122e0f0fbd3ddbb4", 0x39}], 0x1, 0x2, 0x0, 0x0) ioctl$KVM_RUN(r2, 0xae80, 0x0) symlink(&(0x7f0000000440)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', &(0x7f0000000340)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00') openat2$dir(0xffffffffffffff9c, &(0x7f0000000640)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', &(0x7f00000000c0)={0x40040, 0x10a, 0xa}, 0x18) 2.342164358s ago: executing program 5 (id=997): r0 = syz_open_dev$dri(&(0x7f0000000040), 0x20, 0x0) ioctl$DRM_IOCTL_SYNCOBJ_CREATE(r0, 0xc00864bf, &(0x7f0000000140)={0x0, 0x1}) ioctl$DRM_IOCTL_SYNCOBJ_TIMELINE_SIGNAL(r0, 0xc01864cd, &(0x7f0000000340)={&(0x7f00000001c0)=[r1, r1], 0x0, 0x2}) r2 = seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xa, &(0x7f0000000100)={0x17, &(0x7f0000000200)}) (async) r3 = syz_open_dev$dri(&(0x7f0000000080), 0x1, 0x0) ioctl$DRM_IOCTL_SET_CLIENT_CAP(r3, 0x4010640d, &(0x7f0000000000)={0x3, 0x2}) (async) ioctl$DRM_IOCTL_MODE_GETPLANERESOURCES(r3, 0xc01064b5, &(0x7f0000000180)={&(0x7f00000000c0)=[0x0], 0x1}) ioctl$DRM_IOCTL_MODE_SETPLANE(r3, 0xc03064b7, &(0x7f0000000040)={r4, 0x0, r4, 0x3, 0x4000000, 0xff, 0x2, 0x851, 0x400001, 0x0, 0xfffbff7f, 0x400}) (async) ioctl$DRM_IOCTL_SYNCOBJ_QUERY(r3, 0xc01864cb, &(0x7f0000000280)={&(0x7f0000000200)=[r1, r1, r1, r1, r1, r1, r1, r1, r1], &(0x7f0000000240)=[0x3, 0xb6, 0xfffffffffffffff6, 0xe95, 0x1, 0x9, 0x5, 0xfffffffffffffffe], 0x9}) close_range(r2, 0xffffffffffffffff, 0x0) 2.341138055s ago: executing program 5 (id=998): syz_emit_ethernet(0x52, &(0x7f0000000100)=ANY=[@ANYBLOB="aaaaaaaaaaaaaaaaaaaaaabb08004c0000", @ANYRES32=0x41424344], 0x0) openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) r0 = add_key$user(&(0x7f00000002c0), &(0x7f0000000300)={'syz', 0x0}, &(0x7f0000000280)="d25a9850", 0x4, 0xfffffffffffffffe) sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f00000018c0)={&(0x7f00000000c0)=ANY=[@ANYBLOB="48000000100005040000000000000000", @ANYBLOB="ebffffffffffffff280012800b00010065"], 0x48}, 0x1, 0x0, 0x0, 0x4000011}, 0x0) r1 = add_key$user(&(0x7f00000003c0), &(0x7f0000000440), &(0x7f00000000c0), 0xc9, 0xfffffffffffffffd) keyctl$dh_compute(0x17, &(0x7f0000000140)={r0, r1, r0}, &(0x7f00000000c0)=""/83, 0xfffffffffffffe4f, 0x0) r2 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x20042, 0x0) add_key$user(&(0x7f0000000080), 0x0, 0x0, 0x0, 0x0) r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0) r4 = dup(r3) ioctl$KVM_SET_USER_MEMORY_REGION(r3, 0x4020ae46, &(0x7f0000000840)={0x1fe, 0x2, 0x2000, 0x1000, &(0x7f0000003000/0x1000)=nil}) r5 = ioctl$KVM_CREATE_VCPU(r4, 0xae41, 0x2) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r5, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000040)=[@text64={0x40, 0x0}], 0x1, 0x11, 0x0, 0x0) syz_kvm_setup_cpu$x86(r3, r5, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000200)=[@text64={0x40, 0x0}], 0x1, 0x0, 0x0, 0x0) socket$nl_generic(0x10, 0x3, 0x10) ioctl$KVM_RUN(r5, 0xae80, 0x0) 2.148993976s ago: executing program 5 (id=999): r0 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000240)=ANY=[@ANYBLOB="0200000004000000080000000100000080000000", @ANYRES32=0x0, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="000000000000000000000000000000000000000000001b0000000000"], 0x48) r1 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000007c0)=ANY=[@ANYBLOB="1b0000000000000000000000000004"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x12, 0x1c, &(0x7f0000000d80)=@ringbuf={{0x18, 0x8}, {{0x18, 0x1, 0x1, 0x0, r1}, {}, {}, {0x85, 0x0, 0x0, 0x5}}, {}, [@snprintf={{0x7, 0x0, 0xb, 0x2}, {0x3, 0x3, 0x3, 0xa, 0x9, 0xfe00}, {0x6, 0x0, 0xb, 0x9, 0x0, 0x8}, {0x3, 0x3, 0x3, 0xa, 0x9}, {0x7, 0x1, 0xb, 0x6, 0x8, 0x10}, {0x7, 0x0, 0x0, 0x8}, {}, {}, {}, {0x18, 0x8, 0x2, 0x0, r0}, {}, {0x15, 0x0, 0x0, 0x76}}], {{0x7, 0x1, 0xb, 0x8}, {0x6, 0x0, 0x5, 0x8}, {0x85, 0x0, 0x0, 0x7}}}, &(0x7f0000000980)='GPL\x00', 0x2, 0x0, 0x0, 0x40f00, 0x2c, '\x00', 0x0, @cgroup_sock_addr=0xa, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r2 = openat$vnet(0xffffffffffffff9c, &(0x7f0000000180), 0x2, 0x0) ioctl$int_in(r2, 0x40000000af01, 0x0) ioctl$VHOST_SET_VRING_ADDR(r2, 0x4028af11, &(0x7f0000000200)={0x1, 0x1, 0x0, &(0x7f0000000740)=""/51, 0x0}) r3 = socket$packet(0x11, 0x3, 0x300) r4 = syz_open_dev$I2C(&(0x7f0000000000), 0x1, 0x0) ioctl$I2C_SMBUS(r4, 0x720, &(0x7f0000000080)={0x0, 0x0, 0x3, &(0x7f0000000040)={0x0, "0a0dffbf000000005c0ecd551ee7b16eab615e6234c7dece48bacf6f78c7da6647"}}) ioctl$VHOST_SET_MEM_TABLE(r2, 0x4008af03, &(0x7f0000000340)) r5 = socket$kcm(0x2, 0x3, 0x84) sendmsg$inet(r5, &(0x7f00000004c0)={&(0x7f0000000140)={0x2, 0x0, @local}, 0x10, 0x0}, 0x4008804) r6 = socket(0x22, 0x2, 0x24) bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000300)=@bpf_lsm={0xd, 0x5, &(0x7f0000000040)=ANY=[@ANYBLOB="450a000000ff03ffc311a400100100001800000000000000000000000000000095"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) setsockopt$ALG_SET_KEY(r6, 0x117, 0x1, &(0x7f0000000080)="20c13d101b", 0x5) sendmsg$inet(r5, &(0x7f0000000a00)={&(0x7f0000000040)={0x2, 0x0, @dev}, 0x10, &(0x7f0000000280)=[{&(0x7f0000000340)="c109", 0x2}, {&(0x7f00000005c0)="19cd6df62e722d40185166", 0xb}], 0x2}, 0x0) r7 = dup(r3) ioctl$VHOST_NET_SET_BACKEND(r2, 0x4008af30, &(0x7f0000000000)={0x1, r7}) r8 = bpf$BPF_BTF_LOAD(0x12, &(0x7f00000003c0)={&(0x7f0000000000)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0xc, 0xc, 0x2, [@struct={0x0, 0x0, 0x0, 0x4, 0x0, 0x180000}]}}, 0x0, 0x26, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x28) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x1a, 0x3, &(0x7f0000000040)=@framed={{0x18, 0x0, 0x0, 0x300, 0xed}}, &(0x7f0000000080)='GPL\x00', 0x5, 0x1f6, &(0x7f00000002c0)=""/168, 0x0, 0x0, '\x00', 0x0, @tracing, r8, 0x8, 0x0, 0x0, 0x10, &(0x7f0000000200)={0x0, 0x0, 0xfff9}, 0x92f5e, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x6d) r9 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f00000006c0)=ANY=[@ANYBLOB="18000000000000000000000095980000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f0ffffffb702000005000000b703000000000000850000007300000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x23, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000002c0)={&(0x7f0000000280)='page_pool_release\x00', r9, 0x0, 0x7fff}, 0x18) r10 = bpf$MAP_CREATE(0x0, &(0x7f0000000440)=ANY=[@ANYBLOB="1b00000000000000000000000080"], 0x50) r11 = bpf$PROG_LOAD(0x5, &(0x7f0000000140)={0x6, 0x17, &(0x7f0000000800)=ANY=[@ANYBLOB="1800000000000000000000000000000218110000", @ANYRES32=r10, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000083000000bf090000000000005509010000000000950000000000000018110000", @ANYRES32=r10, @ANYBLOB="0000000000000000b702000000000000850000008600000018110000", @ANYRES32=r10, @ANYBLOB="0000000000000000b7020000000000008500000017000000bf91000000000000b7020000000000008500000084000000b70000000000000095"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, @fallback=0x35, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r11, 0xfca804a0, 0xe, 0x0, &(0x7f0000000580)="b80022ab98d1db1b883e04000000", 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x50) r12 = syz_open_dev$dri(&(0x7f0000000000), 0x1ff, 0x0) ioctl$DRM_IOCTL_MODE_GETRESOURCES(r12, 0xc04064a0, &(0x7f0000000140)={0x0, &(0x7f0000000080)=[0x0], 0x0, 0x0, 0x0, 0x1}) ioctl$DRM_IOCTL_MODE_CURSOR2(r12, 0xc02464bb, &(0x7f0000000040)={0x2, r13, 0x4, 0x7, 0x5b45, 0xbb, 0x823, 0x8ae, 0xf81e}) ioctl$VHOST_NET_SET_BACKEND(r2, 0x4008af30, &(0x7f00000003c0)={0x1}) 2.010254518s ago: executing program 5 (id=1001): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) socket$inet_smc(0x2b, 0x1, 0x0) r1 = semget$private(0x0, 0x3, 0x0) semtimedop(r1, 0x0, 0x0, 0x0) keyctl$setperm(0x5, 0x0, 0x21081c22) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000c40)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a05000000000000000000010000000900010073797a300000000040000000030a01010000000000000000010000000900030073797a310000000014000480080002400000000008000140000000000900010073797a3000000000a0010000060a010400000000000000000100000224000480200001800700010072740000140002800800024000000000080002400000000208000b40000000000900010073797a3000000000d8000480300001800a0001006d6174636800000020000280080002400000000008000240000000020c0001007564706c69746500400001800a0001006c696d6974000000300002800c00024000000000000000010c000140000000000000000708000440000000000c0001400000000000000008100001800c000100636f7558f9657200540001800b0001006e756d67656e0000440002800800034000000001080001400000001408000340000000010800034000000000080001400000000108000440000000880800044000000004080001400000000c69000740f955b43db806fb2e909d660d9742ed78ef38d4a064ae28f0a24a4fcb6ba7fb91a67a0b9c35f8bb32a27408d0cdbd8076d83b9a3ff272f3f5441e1e6674d6e828ad1ba8e0e71db13bafd95ee8f4b6cdb7d01535d839e3937ccc668d484baaf77f7a56377446000000080009400000000108000a"], 0x2f4}}, 0x0) socket$nl_netfilter(0x10, 0x3, 0xc) (async) socket$inet_smc(0x2b, 0x1, 0x0) (async) semget$private(0x0, 0x3, 0x0) (async) semtimedop(r1, 0x0, 0x0, 0x0) (async) keyctl$setperm(0x5, 0x0, 0x21081c22) (async) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000c40)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a05000000000000000000010000000900010073797a300000000040000000030a01010000000000000000010000000900030073797a310000000014000480080002400000000008000140000000000900010073797a3000000000a0010000060a010400000000000000000100000224000480200001800700010072740000140002800800024000000000080002400000000208000b40000000000900010073797a3000000000d8000480300001800a0001006d6174636800000020000280080002400000000008000240000000020c0001007564706c69746500400001800a0001006c696d6974000000300002800c00024000000000000000010c000140000000000000000708000440000000000c0001400000000000000008100001800c000100636f7558f9657200540001800b0001006e756d67656e0000440002800800034000000001080001400000001408000340000000010800034000000000080001400000000108000440000000880800044000000004080001400000000c69000740f955b43db806fb2e909d660d9742ed78ef38d4a064ae28f0a24a4fcb6ba7fb91a67a0b9c35f8bb32a27408d0cdbd8076d83b9a3ff272f3f5441e1e6674d6e828ad1ba8e0e71db13bafd95ee8f4b6cdb7d01535d839e3937ccc668d484baaf77f7a56377446000000080009400000000108000a"], 0x2f4}}, 0x0) (async) 1.932113286s ago: executing program 5 (id=1002): r0 = socket$nl_route(0x10, 0x3, 0x0) mkdir(&(0x7f0000000000)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000180)='./bus\x00', &(0x7f0000000200)='f2fs\x00', 0x40020, 0x0) chdir(&(0x7f0000000640)='./file0\x00') mknod(&(0x7f00000000c0)='./bus\x00', 0x8000, 0xd02) r1 = openat$rdma_cm(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(r1, &(0x7f0000000240)={0x0, 0x18, 0xfa00, {0x0, &(0x7f0000000040)={0xffffffffffffffff}, 0x2}}, 0x20) write$RDMA_USER_CM_CMD_LISTEN(r1, &(0x7f00000001c0)={0x7, 0x8, 0xfa00, {r2}}, 0x10) syz_usb_connect(0x5, 0x2d, &(0x7f0000000080)=ANY=[@ANYBLOB="120100000cb768405e0483020b9901e4020109021b000100000000090400fb015c291d00090509"], 0x0) syz_open_dev$sndpcmp(&(0x7f0000000080), 0x3, 0x84940) r3 = socket(0x2, 0x80805, 0x0) sendmmsg$inet(r3, &(0x7f0000000340)=[{{&(0x7f0000000280)={0x2, 0x4e22, @private=0xa010101}, 0x10, &(0x7f0000000600)=[{&(0x7f0000000380)="ef", 0x1}], 0x1}}], 0x1, 0x8081) openat$dsp(0xffffffffffffff9c, &(0x7f0000000000), 0x42f82, 0x0) r4 = syz_io_uring_setup(0x22f, &(0x7f0000000080)={0x0, 0xabd6, 0x2, 0x0, 0x100002cd}, &(0x7f0000000000)=0x0, &(0x7f0000000040)=0x0) syz_io_uring_submit(r5, r6, &(0x7f00000009c0)=@IORING_OP_WRITE={0x17, 0x0, 0x0, @fd_index=0x3, 0x0, 0x0, 0xffffffffffffff31}) io_uring_enter(r4, 0x7a98, 0x0, 0x0, 0x0, 0x0) r7 = socket$inet_sctp(0x2, 0x5, 0x84) getsockopt$inet_sctp_SCTP_MAX_BURST(r7, 0x84, 0xc, &(0x7f0000000240)=@assoc_value={0x0}, &(0x7f0000000080)=0x8) setsockopt$inet_sctp6_SCTP_AUTH_DEACTIVATE_KEY(r3, 0x84, 0x23, &(0x7f0000000300)={r8, 0x6dce}, 0x8) mq_timedsend(0xffffffffffffffff, 0x0, 0x0, 0x6, &(0x7f0000000280)={0x0, 0x3938700}) madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) r9 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000380), 0x4000000004882, 0x0) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) mremap(&(0x7f00005ab000/0x1000)=nil, 0x1000, 0x1000, 0x7, &(0x7f0000ffe000/0x1000)=nil) io_setup(0x1, &(0x7f00000004c0)=0x0) r11 = eventfd(0x6) io_submit(r10, 0x2, &(0x7f00000003c0)=[&(0x7f0000000140)={0x3a0012fb, 0x2759, 0x7, 0x1, 0x0, r9, &(0x7f00000002c0), 0x3d, 0x1000000, 0x0, 0x10, r11}, &(0x7f0000000440)={0x0, 0x0, 0x0, 0x1, 0x2, r7, &(0x7f0000000680)="89c80920fc4b0f041fc689a3c2642e202abe756e85039b8c0c94f937f9eb732e5a2a2903d7942fd9f7407c6070f3e595fd9f942be99e75c079f24a19f95d7a91f585ee97d665ae59e46a8e10daa12d719387db23845c07db34ff67d27bb90b9d350f4eb86d52e704878120f526eebacc1ac1c9f0aa06444cc9db452f29a2d24d2caba81b0689ecc223673120c0e1aa1cbcdb0799657d865da11326c08888e9519957d11e806d37002c0aba12d4f7703c08fe8960a40b1380c2a12f7a676cbcb527c0db7aed404e755923fdab52d1a9c284b87fbca09e2f99fc212d3434c57270b3a1400bb43771c108a5cf39332ae30d361ddfb04431ba88452be864e1d3d74ad2ac921b95ce229c1a8f40f0a9338f70a3aa3ddddc4c04516a3811e44e111901a367870d23d3e10f8674fc91ff8e0eb04a285c204bbc166e6f5e06d8081681ccde75b43eb172f01d87d1ba7d3502138f20c5284787890a30e87396fdb86f4ada8b2cfd5c0fd87e35e7b66de7c1cf0d1fe37f45c9bdbc2299bf364acc6c1193946fbc3e03a80fc790a28b", 0x3f, 0xff, 0x0, 0x2}]) acct(&(0x7f0000000000)='./bus\x00') sendmsg$nl_route(r0, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000080)=ANY=[@ANYBLOB="5000000020000103feffffff000000000a000000000000000400010008000a000008000005001e"], 0x50}, 0x1, 0x0, 0x0, 0x2000c018}, 0x4000850) openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x400, 0x0) 458.065015ms ago: executing program 4 (id=1012): r0 = syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x0) r1 = openat$sequencer2(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$SNDCTL_SEQ_NRSYNTHS(r1, 0x40045109, &(0x7f0000001280)) r2 = syz_open_procfs$namespace(0x0, &(0x7f0000000040)='ns/ipc\x00') ioctl$BTRFS_IOC_ADD_DEV(r2, 0xb701, 0x0) r3 = openat$vnet(0xffffffffffffff9c, &(0x7f0000000180), 0x2, 0x0) r4 = socket$inet_tcp(0x2, 0x1, 0x0) getsockopt$sock_buf(r4, 0x1, 0x19, 0x0, &(0x7f0000000280)) ioctl$int_in(r3, 0x40000000af01, 0x0) ioctl$SG_IO(r0, 0x2285, &(0x7f00000005c0)={0x53, 0x6, 0x6, 0xfa, @scatter={0x0, 0x0, 0x0}, &(0x7f00000002c0)="9eb07acda001", 0x0, 0x4, 0x6, 0x0, 0x0}) 392.565187ms ago: executing program 4 (id=1013): bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x0, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) creat(&(0x7f00000002c0)='./file0\x00', 0x6) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000040)={0x2, 0x4, &(0x7f0000000200)=ANY=[@ANYBLOB="180000000300000000000000fe020010850000000700000095"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x100, 0x70, '\x00', 0x0, @fallback=0x30, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r1 = socket$inet6_sctp(0xa, 0x801, 0x84) sendto$inet6(r1, &(0x7f00000002c0)="f9", 0x1, 0x0, &(0x7f0000000040)={0xa, 0x0, 0x0, @private2}, 0x1c) sendto$inet6(r1, &(0x7f0000000300)='H', 0x1, 0x0, &(0x7f0000000000)={0xa, 0x0, 0x0, @local, 0x9}, 0x1c) shutdown(r1, 0x1) getsockopt$inet_sctp6_SCTP_PR_ASSOC_STATUS(r1, 0x84, 0x74, &(0x7f0000000200)={0x0, 0x0, 0x10}, &(0x7f0000000240)=0x18) r2 = fsopen(&(0x7f0000000480)='autofs\x00', 0x0) fsconfig$FSCONFIG_SET_STRING(r2, 0x1, &(0x7f0000000240)='uid', &(0x7f00000008c0)='0\x00#\x00\xd0\x00 \x00\x00qS\x00\x00\x00\x00\x00\x00\x00\x00$\xf6_\xbdI\x1c\xf2\xa9]\xcc\xe0*\xef\x01\x8d\x15\xd2h\x93\xc9\xb57\xc3\xea\\Eb\xf8\xe6,\xdf\xd4\xfae\x84\xcc\xd5\"d\xf0D-\x98\x9f\x81{\xfc$\xc4\xbcF\xf8\xc8\x8d\xcb\xb8\xf2\x1e\xe4\'U\xb3\xb8\xd3\xe6\xd7\x80=\x8a\xeb\n\xb8_\xe8\x96YY\xe3\xc7\xe6\xf28\x19\xa6\xa7\xfa\xdb\x1ce\xc1\x03\x86J\xb2fh\x19\xee#\xcc\x0f\xed\xfea\xdc\x88\xcb%bW\xd35\xda=\xac\x1d\xae\x93\xfd\'T6\x94\n\xa4\x9cU\xc4\fA~[\xbf\x8b\x90\xfe\x04\xe7U\xf3h\x81\x14l7u\x95\x96t\\\x0f\xef;\x03\xa4C\xbc(Vc!a\xc1\xe39\xc6b\x905\x1f\x03\x00\x00\x00\x00\x00\x00\xdf9\xaf5\xc8a:z\xe4\xcbag&67\x814\xf6}\xe10v6l\xd6,\x1e\xa0\xcc\xbf\xfdkm\b?\x839\x85N\x1c\xc1\xcb\xfc\x85\xd2\n\x02\"\xf2\x81g\x90\x01n%\x7f_\xe1.f>>\xa5\xfb\"\xab\xdb\x06\x12e\x14\x11~\x9a\bR-\x85\xc3\xa9\xe6\xf6R\x11\"\xc3\xc9\xfc\x14s X\xec\xdd\xc2qB\x85\xf0\xd7\x04\xdd<\x9ak\x00\x00\x00\x00\x00\x00\x00\n\xa72\xa3\xef^\xe7\x8f', 0x0) bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f00000005c0)={r0, 0x0, 0x30, 0x1, @val=@uprobe_multi={&(0x7f0000000140)='./file0\x00', &(0x7f00000004c0)=[0x7], &(0x7f0000000500), 0x0, 0xff8e}}, 0x3c) 288.204929ms ago: executing program 4 (id=1014): r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000001700), 0x0, 0x0) (async) r1 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000040), 0x20040, 0x0) r2 = ioctl$KVM_CREATE_VM(r1, 0xae01, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r2, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x20002000, &(0x7f0000000000/0x2000)=nil}) r3 = ioctl$KVM_CREATE_VCPU(r2, 0xae41, 0x3) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r3, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000600)=[@text64={0x40, &(0x7f0000000640)="430fc73f0f2390b9800000c00f3235010000000f300f20d835080000000f22d8c4e18173f53866baf80cb83879e487ef66bafc0cec66b88e008ec02d1aa80000460f1c460041ae", 0x47}], 0x1, 0x76, 0x0, 0x0) syz_emit_ethernet(0x7e, &(0x7f0000000080)=ANY=[@ANYBLOB="0f539af210"], 0x0) (async) ioctl$KVM_RUN(r3, 0xae80, 0x0) (async) r4 = socket$nl_generic(0x10, 0x3, 0x10) r5 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000080), r4) (async) r6 = socket$packet(0x11, 0x2, 0x300) syz_io_uring_setup(0x238, &(0x7f0000000740)={0x0, 0x1c2a, 0x10100, 0x0, 0xfffffffe, 0x0, r0}, &(0x7f00000003c0)=0x0, &(0x7f00000001c0)=0x0) syz_io_uring_submit(r7, r8, &(0x7f0000000200)=@IORING_OP_SEND={0x1a, 0x20, 0x0, r6, 0x0, &(0x7f0000000280)="9df0dbcc02a4", 0x6, 0x4000800}) io_uring_enter(0xffffffffffffffff, 0x2ded, 0x2b38, 0x0, 0x0, 0xffffffffffffff82) ioctl$sock_SIOCGIFINDEX_80211(r4, 0x8933, &(0x7f00000000c0)={'wlan1\x00'}) (async) sendmsg$NL80211_CMD_STOP_P2P_DEVICE(r4, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000140)={&(0x7f00000002c0)=ANY=[@ANYBLOB="1c0000001f07ba8a8e00cc99a503da9734e53d373589bfbc9839755f68405ad85931377076e737cf2c4bc498a8b28300b2e27af87cf00aa929a0111d0e53614d89640f8f57186189422e74920375245f55dd7ad15131b4231e7754d1e5d3abae11283ef537d9a5018027760c60e4450525ffa74bc3af76f03f8400c8a8f2837d27b0925e0c75b460d14e350c9756aeeb3b883d2d951a1e810b6d56a3f160fa8d94422dde94f0cd2463ce30e4f484abab21e9981d71a6a490a65dbd86c06adcf5908abc5f1f9baec2507ac4f03f808c39b39e9e", @ANYRES16=r5, @ANYBLOB="010027bd7000fedbdf255a00000008000300", @ANYRES32=r2, @ANYBLOB], 0x1c}, 0x1, 0x0, 0x0, 0x104}, 0x4) (async) ioctl$TIOCGSID(r0, 0x5429, 0x0) (async) socketpair$unix(0x1, 0x1, 0x0, &(0x7f0000000240)={0xffffffffffffffff, 0xffffffffffffffff}) (async) syz_emit_ethernet(0x66, &(0x7f00000000c0)=ANY=[@ANYBLOB="ffffffffffffaaaaaaaaaabb86dd683a16ff20010000000000000000000000000001ff010000000000000000000000000001030090781000000067"], 0x0) (async) r10 = openat$ttyprintk(0xffffffffffffff9c, &(0x7f0000002780), 0x202, 0x0) ioctl$TIOCVHANGUP(r10, 0x5437, 0x0) (async) ioctl$sock_SIOCGIFINDEX(r9, 0x8933, &(0x7f0000000000)={'lo\x00'}) r11 = socket$inet(0x2, 0x1, 0x0) setsockopt$inet_mreqn(r11, 0x0, 0x27, &(0x7f0000000200)={@multicast1, @local}, 0xc) (async) ioctl$TIOCSETD(r10, 0x5423, &(0x7f00000001c0)=0x1a) (async) r12 = syz_open_dev$video(&(0x7f0000000000), 0x3, 0x0) ioctl$VIDIOC_DQEVENT(r12, 0x80885659, 0x0) openat$iommufd(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) (async) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x0, 0x8031, 0xffffffffffffffff, 0x40ead000) madvise(&(0x7f0000130000/0xd000)=nil, 0xd000, 0x66) 159.076037ms ago: executing program 4 (id=1015): madvise(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xe) mlock(&(0x7f0000000000/0x800000)=nil, 0x800000) munlockall() syz_clone(0x1000, 0x0, 0x0, 0x0, 0x0, 0x0) mlock2(&(0x7f0000381000/0x4000)=nil, 0x4000, 0x0) pipe2(&(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}, 0x4800) mmap(&(0x7f0000000000/0x800000)=nil, 0x800000, 0xb, 0xc3072, 0xffffffffffffffff, 0x0) vmsplice(r1, &(0x7f0000000140)=[{&(0x7f0000000100)="eb", 0x20000101}], 0x1, 0x0) keyctl$link(0x8, 0x0, 0x0) move_pages(0x0, 0x10, &(0x7f0000000140)=[&(0x7f0000000000/0x1000)=nil], &(0x7f0000000040)=[0x1], 0x0, 0x0) r2 = openat$ptmx(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) r3 = openat$sysfs(0xffffffffffffff9c, &(0x7f0000000080)='/sys/kernel/kexec_loaded', 0x0, 0x4) r4 = socket(0x400000000010, 0x3, 0x0) r5 = socket$unix(0x1, 0x1, 0x0) ioctl$sock_SIOCGIFINDEX(r5, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r4, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000001c0)=@newqdisc={0x2c, 0x24, 0x4ee4e6a52ff56541, 0x70bd2a, 0xffffffff, {0x0, 0x0, 0x0, r6, {0x0, 0xfff1}, {0xffff, 0xffff}, {0xc, 0xf}}, [@qdisc_kind_options=@q_drr={0x8}]}, 0x2c}, 0x1, 0x0, 0x0, 0x8001}, 0x20008850) r7 = openat$selinux_checkreqprot(0xffffffffffffff9c, &(0x7f0000000300), 0x1, 0x0) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f00000003c0)={{r0, 0xffffffffffffffff}, &(0x7f0000000340), &(0x7f0000000380)=r1}, 0x20) bpf$PROG_LOAD(0x5, &(0x7f0000000500)={0x14, 0x14, &(0x7f0000000180)=@raw=[@func={0x85, 0x0, 0x1, 0x0, 0xfffffffffffffffc}, @snprintf={{}, {}, {0x7, 0x0, 0xb, 0x8, 0x0, 0x0, 0x22}, {}, {}, {}, {}, {}, {}, {0x18, 0x3, 0x2, 0x0, r0}}, @btf_id={0x18, 0xb, 0x3, 0x0, 0x2}, @func, @map_val={0x18, 0x5, 0x2, 0x0, r3, 0x0, 0x0, 0x0, 0x5}, @alu={0x9a46252be3482323, 0x0, 0xd, 0x8, 0x0, 0xc, 0x1}], &(0x7f0000000240)='GPL\x00', 0xd97, 0x0, &(0x7f0000000280), 0x40f00, 0x68, '\x00', r6, @fallback=0x10, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, &(0x7f00000002c0)={0x0, 0x9, 0x1000, 0x7}, 0x10, 0xffffffffffffffff, r7, 0xa, &(0x7f0000000400)=[r8, r1], &(0x7f0000000440)=[{0x1, 0x5, 0xe, 0xa}, {0x2, 0x3, 0xa, 0x4}, {0x1, 0x4, 0xd, 0x9}, {0x2, 0x2, 0xb, 0x2}, {0x2, 0x4, 0xd, 0x2}, {0x5, 0x1, 0xc, 0x9}, {0x4, 0x1, 0x9, 0x1}, {0x3, 0x2, 0x2, 0x4}, {0x0, 0x3, 0x2, 0x9}, {0x2, 0x1, 0xf, 0xb}], 0x10, 0x6, @void, @value}, 0x94) syz_open_pts(r2, 0x0) 819.528µs ago: executing program 4 (id=1016): r0 = socket$nl_route(0x10, 0x3, 0x0) r1 = openat$tun(0xffffffffffffff9c, &(0x7f0000000040), 0x200, 0x0) ioctl$TUNSETIFF(r1, 0x400454ca, &(0x7f0000000080)={'xfrm0\x00', 0x400}) sendmsg$nl_route(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000000)=ANY=[@ANYBLOB="3c0000001000030428bd70000400000000000000", @ANYRES32=0x0, @ANYBLOB="00000000000000001c0075dae2cc6ac137128009000100626f6e64000000000c00028008"], 0x3c}, 0x1, 0x2000000000000000}, 0x0) 0s ago: executing program 4 (id=1017): r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) (async) r1 = fcntl$dupfd(r0, 0x0, r0) ioctl$TCFLSH(r1, 0x400455c8, 0x8000000001) (async) ioctl$TIOCSETD(r1, 0x5412, &(0x7f0000000140)=0xffffffc0) (async) ioctl$TIOCSTI(r1, 0x5412, &(0x7f0000000040)=0xfc) (async) r2 = openat$udambuf(0xffffffffffffff9c, &(0x7f0000000080), 0x2) ioctl$EXT4_IOC_PRECACHE_EXTENTS(r2, 0x6612) mmap(&(0x7f0000000000/0xfbe000)=nil, 0xfbe000, 0x2, 0x31, 0xffffffffffffffff, 0x0) (async) r3 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r3, &(0x7f0000000400)={0x0, 0x0, &(0x7f00000003c0)={&(0x7f0000000180)=ANY=[@ANYBLOB="6800000015000100000000000000ff00fe8800000000000000000000800000010000000000000000000000000000000000040000000000000000b10000000000", @ANYRES32, @ANYRES32, @ANYBLOB='\x00\x00\x00\x00\x00\x00\x00\x00\f\x00\b'], 0x68}}, 0x0) (async) set_mempolicy(0x6, &(0x7f00000003c0)=0x8000000000000001, 0xe0) madvise(&(0x7f00008d1000/0x2000)=nil, 0x2000, 0x9) (async) r4 = syz_open_dev$dri(&(0x7f0000002500), 0x2, 0x0) ioctl$DRM_IOCTL_AUTH_MAGIC(r4, 0x400464d1, &(0x7f0000000400)=0x8) ioctl$DRM_IOCTL_MODESET_CTL(r4, 0x40086408, &(0x7f0000000000)={0xc, 0x4}) (async) r5 = socket$nl_route(0x10, 0x3, 0x0) pidfd_getfd(0xffffffffffffffff, r5, 0x0) (async) r6 = syz_open_dev$loop(&(0x7f0000000100), 0x2000000, 0xe2001) (async) r7 = openat$sysfs(0xffffffffffffff9c, &(0x7f0000000000)='/sys/power/pm_test', 0x41e43, 0x8) ioctl$LOOP_CONFIGURE(r6, 0x4c0a, &(0x7f00000002c0)={r7, 0x0, {0x2a00, 0x80010000, 0x0, 0x1, 0x0, 0x0, 0x0, 0x0, 0x1c, "fee8a2ab78fc979fd1e00d96072000001ea89de2b7fb0000e60080b8785d96000100", "2809e8dbe108598948224ad54afac11d875397bdb22d0000b420a1a93c5240f45f819e01177d3d458dd4992861ac00", "90be8b1c551265406c7f306003d8a0f4bd00", [0x0, 0xfffffffffffffff8]}}) sendmsg$nl_route(r7, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000100)={&(0x7f00000002c0)=ANY=[], 0x24}}, 0x0) (async) unshare(0x68060200) (async) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x3, 0x8031, 0xffffffffffffffff, 0x0) (async) syz_genetlink_get_family_id$devlink(0x0, 0xffffffffffffffff) (async) r8 = socket$inet_udp(0x2, 0x2, 0x0) setsockopt$ARPT_SO_SET_REPLACE(r8, 0x0, 0x60, &(0x7f0000000940)={'filter\x00', 0x104, 0x4, 0x3f0, 0x220, 0x220, 0x0, 0x308, 0x308, 0x308, 0x4, 0x0, {[{{@uncond, 0xc0, 0x110}, @mangle={0x50, 'mangle\x00', 0x0, {@empty, @empty, @multicast2, @empty, 0x1, 0xffffffff}}}, {{@uncond, 0xc0, 0x110, 0x0, {0xb000000}}, @mangle={0x50, 'mangle\x00', 0x0, {@mac=@multicast, @mac=@random="cab170e97230", @multicast1, @remote, 0x8}}}, {{@arp={@rand_addr, @initdev={0xac, 0x1e, 0x0, 0x0}, 0xffffffff, 0xff000000, 0x0, 0x0, {@mac=@remote, {[0x0, 0x0, 0xff]}}, {}, 0x0, 0x0, 0x0, 0x3ff, 0x0, 0x0, 'xfrm0\x00', 'ipvlan1\x00', {}, {0xff}}, 0xc0, 0xe8}, @unspec=@AUDIT={0x28}}], {{'\x00', 0xc0, 0xe8}, {0x28}}}}, 0x440) (async) madvise(&(0x7f0000000000/0x600000)=nil, 0x60005f, 0x3) kernel console output (not intermixed with test programs): 1][ T8432] veth1_macvtap: entered promiscuous mode [ 126.146962][ T8432] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 126.153148][ T8432] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 126.157887][ T8432] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 126.160749][ T8432] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 126.163962][ T8432] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 126.166950][ T8432] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 126.207443][ T13] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 126.210105][ T13] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 126.222554][ T837] usb usb10-port1: attempt power cycle [ 126.227010][ T1146] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 126.230038][ T1146] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 126.288644][ T1146] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 126.591130][ T837] usb 10-1: new high-speed USB device number 8 using dummy_hcd [ 126.611875][ T837] usb 10-1: device descriptor read/8, error -71 [ 126.861234][ T837] usb 10-1: new high-speed USB device number 9 using dummy_hcd [ 126.881930][ T837] usb 10-1: device descriptor read/8, error -71 [ 127.001490][ T837] usb usb10-port1: unable to enumerate USB device [ 127.172802][ T5955] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 127.176301][ T5955] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 127.180662][ T5955] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 127.185665][ T5955] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 127.188455][ T5955] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 127.210529][ T8484] lo speed is unknown, defaulting to 1000 [ 127.311935][ T8484] chnl_net:caif_netlink_parms(): no params data found [ 127.324797][ T40] kauditd_printk_skb: 7 callbacks suppressed [ 127.324806][ T40] audit: type=1400 audit(2000000050.525:537): avc: denied { accept } for pid=8488 comm="syz.4.690" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 127.384475][ T40] audit: type=1400 audit(2000000050.585:538): avc: denied { getopt } for pid=8488 comm="syz.4.690" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 127.392456][ T8484] bridge0: port 1(bridge_slave_0) entered blocking state [ 127.394866][ T8484] bridge0: port 1(bridge_slave_0) entered disabled state [ 127.397233][ T8484] bridge_slave_0: entered allmulticast mode [ 127.400174][ T8484] bridge_slave_0: entered promiscuous mode [ 127.405591][ T8484] bridge0: port 2(bridge_slave_1) entered blocking state [ 127.407926][ T8484] bridge0: port 2(bridge_slave_1) entered disabled state [ 127.410259][ T8484] bridge_slave_1: entered allmulticast mode [ 127.414448][ T8484] bridge_slave_1: entered promiscuous mode [ 127.422178][ T40] audit: type=1400 audit(2000000050.625:539): avc: denied { setattr } for pid=8495 comm="syz.4.691" name="sg0" dev="devtmpfs" ino=721 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 127.464949][ T8484] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 127.468007][ T8498] netlink: 'syz.4.692': attribute type 12 has an invalid length. [ 127.471901][ T8499] IPv6: NLM_F_CREATE should be specified when creating new route [ 127.474537][ T8499] netlink: 4 bytes leftover after parsing attributes in process `syz.4.692'. [ 127.483778][ T8484] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 127.526863][ T8484] team0: Port device team_slave_0 added [ 127.531304][ T8484] team0: Port device team_slave_1 added [ 127.547775][ T8503] x_tables: ip_tables: icmp.0 match: invalid size 8 (kernel) != (user) 56 [ 127.551773][ T8503] netlink: 'syz.4.694': attribute type 1 has an invalid length. [ 127.576217][ T8484] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 127.578523][ T8484] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 127.587890][ T8484] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 127.599202][ T8484] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 127.601596][ T8484] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 127.609877][ T8484] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 127.660402][ T8484] hsr_slave_0: entered promiscuous mode [ 127.663147][ T8484] hsr_slave_1: entered promiscuous mode [ 127.665380][ T8484] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 127.667999][ T8484] Cannot create hsr debugfs directory [ 128.012483][ T8521] netlink: 'syz.4.701': attribute type 6 has an invalid length. [ 128.068538][ T8525] netlink: 'syz.4.703': attribute type 11 has an invalid length. [ 128.093724][ T8525] netlink: 12 bytes leftover after parsing attributes in process `syz.4.703'. [ 128.155340][ T1146] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 128.193034][ T8527] random: crng reseeded on system resumption [ 128.216303][ T1146] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 128.303891][ T40] audit: type=1400 audit(2000000051.505:540): avc: denied { read write open } for pid=8526 comm="syz.4.704" path="/147/bus/file1" dev="9p" ino=35913925 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 128.324601][ T1146] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 128.462921][ T1146] bridge_slave_1: left allmulticast mode [ 128.464793][ T1146] bridge_slave_1: left promiscuous mode [ 128.466799][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 128.471273][ T1146] bridge_slave_0: left allmulticast mode [ 128.473303][ T1146] bridge_slave_0: left promiscuous mode [ 128.475365][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 128.545656][ T40] audit: type=1400 audit(2000000051.745:541): avc: denied { getopt } for pid=8541 comm="syz.4.707" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 128.650729][ T40] audit: type=1400 audit(2000000051.845:542): avc: denied { ioctl } for pid=8544 comm="syz.5.708" path="/dev/nullb0" dev="devtmpfs" ino=707 ioctlcmd=0x127c scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:device_t tclass=blk_file permissive=1 [ 128.678082][ T5955] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 128.682336][ T5955] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 128.688098][ T5955] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 128.698807][ T5955] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 128.706624][ T5955] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 128.839770][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 128.846281][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 128.850110][ T1146] bond0 (unregistering): Released all slaves [ 128.885913][ T8546] lo speed is unknown, defaulting to 1000 [ 128.919974][ T8559] netlink: 4 bytes leftover after parsing attributes in process `syz.4.711'. [ 128.971018][ T40] audit: type=1400 audit(2000000052.165:543): avc: denied { append } for pid=8556 comm="syz.4.711" name="pfkey" dev="proc" ino=4026534097 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:proc_net_t tclass=file permissive=1 [ 128.978663][ T40] audit: type=1400 audit(2000000052.175:544): avc: denied { map } for pid=8556 comm="syz.4.711" path="/proc/457/net/pfkey" dev="proc" ino=4026534097 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:proc_net_t tclass=file permissive=1 [ 129.021296][ T8546] chnl_net:caif_netlink_parms(): no params data found [ 129.054967][ T8565] hpfs: hpfs_map_sector(): read error [ 129.064410][ T8565] hpfs: hpfs_map_sector(): read error [ 129.109749][ T8546] bridge0: port 1(bridge_slave_0) entered blocking state [ 129.112852][ T8546] bridge0: port 1(bridge_slave_0) entered disabled state [ 129.116096][ T8546] bridge_slave_0: entered allmulticast mode [ 129.118895][ T8546] bridge_slave_0: entered promiscuous mode [ 129.146034][ T8546] bridge0: port 2(bridge_slave_1) entered blocking state [ 129.148441][ T8546] bridge0: port 2(bridge_slave_1) entered disabled state [ 129.150848][ T8546] bridge_slave_1: entered allmulticast mode [ 129.155139][ T8546] bridge_slave_1: entered promiscuous mode [ 129.187660][ T8546] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 129.197027][ T8546] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 129.229212][ T8546] team0: Port device team_slave_0 added [ 129.234399][ T8546] team0: Port device team_slave_1 added [ 129.251175][ T5955] Bluetooth: hci0: command tx timeout [ 129.283856][ T1146] hsr_slave_0: left promiscuous mode [ 129.286024][ T1146] hsr_slave_1: left promiscuous mode [ 129.288077][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 129.290509][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 129.293664][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 129.296107][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 129.323914][ T1146] veth1_macvtap: left promiscuous mode [ 129.325777][ T1146] veth0_macvtap: left promiscuous mode [ 129.327662][ T1146] veth1_vlan: left promiscuous mode [ 129.329385][ T1146] veth0_vlan: left promiscuous mode [ 129.561317][ T10] usb 9-1: new high-speed USB device number 9 using dummy_hcd [ 129.703185][ T10] usb 9-1: device descriptor read/64, error -71 [ 129.943612][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 129.971293][ T10] usb 9-1: new high-speed USB device number 10 using dummy_hcd [ 130.012160][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 130.101170][ T10] usb 9-1: device descriptor read/64, error -71 [ 130.222187][ T10] usb usb9-port1: attempt power cycle [ 130.463379][ T8546] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 130.465689][ T8546] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 130.474082][ T8546] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 130.479299][ T8546] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 130.482713][ T8546] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 130.491215][ T8546] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 130.554412][ T8546] hsr_slave_0: entered promiscuous mode [ 130.556716][ T8546] hsr_slave_1: entered promiscuous mode [ 130.558888][ T8546] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 130.561462][ T8546] Cannot create hsr debugfs directory [ 130.571216][ T10] usb 9-1: new high-speed USB device number 11 using dummy_hcd [ 130.592504][ T10] usb 9-1: device descriptor read/8, error -71 [ 130.608742][ T8484] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 130.616738][ T8484] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 130.630578][ T8484] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 130.637605][ T8484] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 130.710548][ T8546] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 130.720486][ T8583] netlink: 8 bytes leftover after parsing attributes in process `syz.5.719'. [ 130.723606][ T8583] netlink: 'syz.5.719': attribute type 30 has an invalid length. [ 130.730045][ T8583] netdevsim netdevsim5 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 130.733224][ T8583] netdevsim netdevsim5 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 130.736101][ T8583] netdevsim netdevsim5 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 130.738950][ T8583] netdevsim netdevsim5 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 130.761292][ T5955] Bluetooth: hci2: command tx timeout [ 130.761886][ T8484] 8021q: adding VLAN 0 to HW filter on device bond0 [ 130.775990][ T8484] 8021q: adding VLAN 0 to HW filter on device team0 [ 130.782927][ T6966] bridge0: port 1(bridge_slave_0) entered blocking state [ 130.785356][ T6966] bridge0: port 1(bridge_slave_0) entered forwarding state [ 130.792716][ T6966] bridge0: port 2(bridge_slave_1) entered blocking state [ 130.795118][ T6966] bridge0: port 2(bridge_slave_1) entered forwarding state [ 130.841227][ T10] usb 9-1: new high-speed USB device number 12 using dummy_hcd [ 130.872253][ T10] usb 9-1: device descriptor read/8, error -71 [ 130.895708][ T8546] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 130.971433][ T8546] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 130.990344][ T8484] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 131.000909][ T10] usb usb9-port1: unable to enumerate USB device [ 131.027184][ T8484] veth0_vlan: entered promiscuous mode [ 131.032206][ T8484] veth1_vlan: entered promiscuous mode [ 131.046018][ T8484] veth0_macvtap: entered promiscuous mode [ 131.049947][ T8484] veth1_macvtap: entered promiscuous mode [ 131.060960][ T8484] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 131.076105][ T8546] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 131.083228][ T8484] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 131.088392][ T8484] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 131.091888][ T8484] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 131.094753][ T8484] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 131.097622][ T8484] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 131.132372][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 131.135006][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 131.148024][ T6967] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 131.150643][ T6967] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 131.181463][ T1146] bridge_slave_1: left allmulticast mode [ 131.184076][ T1146] bridge_slave_1: left promiscuous mode [ 131.187144][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 131.194093][ T1146] bridge_slave_0: left allmulticast mode [ 131.195993][ T1146] bridge_slave_0: left promiscuous mode [ 131.197910][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 131.451285][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 131.455053][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 131.458430][ T1146] bond0 (unregistering): Released all slaves [ 131.518714][ T8546] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 131.523184][ T8546] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 131.534839][ T8546] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 131.548938][ T8546] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 131.599054][ T8546] 8021q: adding VLAN 0 to HW filter on device bond0 [ 131.608295][ T8546] 8021q: adding VLAN 0 to HW filter on device team0 [ 131.613848][ T6962] bridge0: port 1(bridge_slave_0) entered blocking state [ 131.616224][ T6962] bridge0: port 1(bridge_slave_0) entered forwarding state [ 131.621656][ T6966] bridge0: port 2(bridge_slave_1) entered blocking state [ 131.624099][ T6966] bridge0: port 2(bridge_slave_1) entered forwarding state [ 131.667011][ T8622] netlink: 'syz.5.729': attribute type 10 has an invalid length. [ 131.673885][ T8622] batman_adv: batadv0: Adding interface: team0 [ 131.676309][ T8622] batman_adv: batadv0: The MTU of interface team0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 131.687789][ T8622] batman_adv: batadv0: Not using interface team0 (retrying later): interface not active [ 131.693709][ T8622] netlink: 'syz.5.729': attribute type 10 has an invalid length. [ 131.696280][ T8622] netlink: 2 bytes leftover after parsing attributes in process `syz.5.729'. [ 131.699210][ T8622] team0: entered promiscuous mode [ 131.703506][ T8622] team_slave_0: entered promiscuous mode [ 131.705453][ T8622] team_slave_1: entered promiscuous mode [ 131.708259][ T8622] 8021q: adding VLAN 0 to HW filter on device team0 [ 131.710613][ T8622] batman_adv: batadv0: Interface activated: team0 [ 131.713064][ T8622] batman_adv: batadv0: Interface deactivated: team0 [ 131.715241][ T8622] batman_adv: batadv0: Removing interface: team0 [ 131.718060][ T8622] bridge0: port 3(team0) entered blocking state [ 131.720156][ T8622] bridge0: port 3(team0) entered disabled state [ 131.722784][ T8622] team0: entered allmulticast mode [ 131.724629][ T8622] team_slave_0: entered allmulticast mode [ 131.726598][ T8622] team_slave_1: entered allmulticast mode [ 131.729697][ T8622] bridge0: port 3(team0) entered blocking state [ 131.732087][ T8622] bridge0: port 3(team0) entered forwarding state [ 131.761256][ T8546] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 131.784025][ T8546] veth0_vlan: entered promiscuous mode [ 131.788824][ T8546] veth1_vlan: entered promiscuous mode [ 131.800538][ T8629] netlink: 700 bytes leftover after parsing attributes in process `syz.5.731'. [ 131.820666][ T1146] hsr_slave_0: left promiscuous mode [ 131.823425][ T1146] hsr_slave_1: left promiscuous mode [ 131.825522][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 131.827976][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 131.830744][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 131.833887][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 131.858099][ T1146] veth1_macvtap: left promiscuous mode [ 131.859963][ T1146] veth0_macvtap: left promiscuous mode [ 131.862778][ T1146] veth1_vlan: left promiscuous mode [ 131.864612][ T1146] veth0_vlan: left promiscuous mode [ 132.343177][ T40] audit: type=1400 audit(2000000055.545:545): avc: denied { mounton } for pid=8635 comm="+}[@" path="/157/file0" dev="tmpfs" ino=848 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=chr_file permissive=1 [ 132.355860][ T40] audit: type=1400 audit(2000000055.545:546): avc: denied { setattr } for pid=8635 comm="syz.4.733" name="/" dev="9p" ino=2 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 132.443300][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 132.510489][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 132.604046][ T1420] ieee802154 phy1 wpan1: encryption failed: -22 [ 132.841293][ T5955] Bluetooth: hci2: command tx timeout [ 132.982599][ T8546] veth0_macvtap: entered promiscuous mode [ 132.990550][ T8633] bond0: option active_slave: mode dependency failed, not supported in mode balance-rr(0) [ 132.996417][ T8546] veth1_macvtap: entered promiscuous mode [ 133.005618][ T8546] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 133.012069][ T8546] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 133.018260][ T8546] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 133.021205][ T8546] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 133.024026][ T8546] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 133.027013][ T8546] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 133.106302][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 133.108856][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 133.126053][ T102] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 133.128649][ T102] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 133.258166][ T8646] netlink: 8 bytes leftover after parsing attributes in process `syz.4.735'. [ 133.282879][ T8651] nbd: must specify an index to disconnect [ 133.287267][ T8653] nbd: must specify an index to disconnect [ 133.478029][ T8662] lo speed is unknown, defaulting to 1000 [ 133.596017][ T1146] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 134.328591][ T5951] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 134.333048][ T5951] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 134.336023][ T5951] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 134.341194][ T5951] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 134.344203][ T5951] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 134.357059][ T68] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 134.361259][ T68] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 134.364211][ T40] audit: type=1400 audit(2000000057.555:547): avc: denied { setattr } for pid=8685 comm="syz.5.748" name="NFC_LLCP" dev="sockfs" ino=31969 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 134.365119][ T68] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 134.376210][ T68] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 134.376992][ T8678] lo speed is unknown, defaulting to 1000 [ 134.383322][ T6956] Bluetooth: Error in BCSP hdr checksum [ 134.383617][ T5955] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 134.422766][ T8683] lo speed is unknown, defaulting to 1000 [ 134.546967][ T8678] chnl_net:caif_netlink_parms(): no params data found [ 134.580217][ T8683] chnl_net:caif_netlink_parms(): no params data found [ 134.640497][ T8678] bridge0: port 1(bridge_slave_0) entered blocking state [ 134.643213][ T8678] bridge0: port 1(bridge_slave_0) entered disabled state [ 134.646314][ T8678] bridge_slave_0: entered allmulticast mode [ 134.649042][ T8678] bridge_slave_0: entered promiscuous mode [ 134.652596][ T8678] bridge0: port 2(bridge_slave_1) entered blocking state [ 134.655006][ T8678] bridge0: port 2(bridge_slave_1) entered disabled state [ 134.657444][ T8678] bridge_slave_1: entered allmulticast mode [ 134.660187][ T8678] bridge_slave_1: entered promiscuous mode [ 134.735745][ T8678] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 134.738918][ T8683] bridge0: port 1(bridge_slave_0) entered blocking state [ 134.742282][ T8683] bridge0: port 1(bridge_slave_0) entered disabled state [ 134.745464][ T8683] bridge_slave_0: entered allmulticast mode [ 134.749704][ T8683] bridge_slave_0: entered promiscuous mode [ 134.755679][ T8678] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 134.774869][ T8683] bridge0: port 2(bridge_slave_1) entered blocking state [ 134.778044][ T8683] bridge0: port 2(bridge_slave_1) entered disabled state [ 134.781345][ T8683] bridge_slave_1: entered allmulticast mode [ 134.785398][ T8683] bridge_slave_1: entered promiscuous mode [ 134.854311][ T8683] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 134.861609][ T8678] team0: Port device team_slave_0 added [ 134.866198][ T8683] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 134.890566][ T8678] team0: Port device team_slave_1 added [ 134.931958][ T8683] team0: Port device team_slave_0 added [ 134.959153][ T1146] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 134.968695][ T8683] team0: Port device team_slave_1 added [ 134.971529][ T8678] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 134.973825][ T8678] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 134.983036][ T8678] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 135.002847][ T8678] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 135.005149][ T8678] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 135.013405][ T8678] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 135.034699][ T8683] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 135.037034][ T8683] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 135.045422][ T8683] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 135.050408][ T8683] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 135.052817][ T8683] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 135.061133][ T8683] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 135.076854][ T1146] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 135.133761][ T8678] hsr_slave_0: entered promiscuous mode [ 135.136138][ T8678] hsr_slave_1: entered promiscuous mode [ 135.138270][ T8678] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 135.140747][ T8678] Cannot create hsr debugfs directory [ 135.189455][ T1146] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 135.198679][ T8683] hsr_slave_0: entered promiscuous mode [ 135.201369][ T8683] hsr_slave_1: entered promiscuous mode [ 135.211127][ T8683] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 135.213778][ T8683] Cannot create hsr debugfs directory [ 135.243119][ T40] audit: type=1400 audit(2000000058.445:548): avc: denied { write } for pid=8705 comm="syz.4.751" name="fb0" dev="devtmpfs" ino=637 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:framebuf_device_t tclass=chr_file permissive=1 [ 135.354230][ T40] audit: type=1400 audit(2000000058.555:549): avc: denied { read } for pid=8710 comm="syz.4.752" name="cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 135.363050][ T40] audit: type=1400 audit(2000000058.555:550): avc: denied { open } for pid=8710 comm="syz.4.752" path="/dev/cachefiles" dev="devtmpfs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cachefiles_device_t tclass=chr_file permissive=1 [ 135.448024][ T8678] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 135.459145][ T1146] bridge_slave_1: left allmulticast mode [ 135.461102][ T1146] bridge_slave_1: left promiscuous mode [ 135.463047][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 135.466879][ T1146] bridge_slave_0: left allmulticast mode [ 135.468757][ T1146] bridge_slave_0: left promiscuous mode [ 135.470877][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 135.475684][ T1146] team0: left allmulticast mode [ 135.477339][ T1146] team_slave_0: left allmulticast mode [ 135.479321][ T1146] team_slave_1: left allmulticast mode [ 135.481481][ T1146] bridge0: port 3(team0) entered disabled state [ 135.487744][ T1146] bridge_slave_1: left allmulticast mode [ 135.489611][ T1146] bridge_slave_1: left promiscuous mode [ 135.492497][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 135.495887][ T1146] bridge_slave_0: left allmulticast mode [ 135.497782][ T1146] bridge_slave_0: left promiscuous mode [ 135.499697][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 135.504018][ T1146] bridge_slave_1: left allmulticast mode [ 135.505941][ T1146] bridge_slave_1: left promiscuous mode [ 135.507829][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 135.512548][ T1146] bridge_slave_0: left allmulticast mode [ 135.514442][ T1146] bridge_slave_0: left promiscuous mode [ 135.516370][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 135.789092][ T1146] dvmrp1 (unregistering): left allmulticast mode [ 136.123091][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 136.128089][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 136.133438][ T1146] bond0 (unregistering): Released all slaves [ 136.211443][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 136.216414][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 136.219585][ T1146] bond0 (unregistering): Released all slaves [ 136.296114][ T1146] bond1 (unregistering): Released all slaves [ 136.361542][ T5955] Bluetooth: hci0: command tx timeout [ 136.364880][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 136.368646][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 136.373395][ T1146] bond0 (unregistering): Released all slaves [ 136.393934][ T8678] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.441228][ T68] Bluetooth: hci4: Opcode 0x1003 failed: -110 [ 136.444584][ T5955] Bluetooth: hci2: command tx timeout [ 136.477306][ T1146] tipc: Left network mode [ 136.504115][ T1146] IPVS: stopping backup sync thread 7894 ... [ 136.525739][ T8678] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.542350][ T8735] pty pty30: ldisc open failed (-12), clearing slot 30 [ 136.556869][ T8733] macvlan0: entered promiscuous mode [ 136.563641][ T8733] netlink: 64 bytes leftover after parsing attributes in process `syz.4.759'. [ 136.608685][ T8678] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.961155][ T29] usb 9-1: new high-speed USB device number 13 using dummy_hcd [ 137.079827][ T40] audit: type=1400 audit(2000000060.275:551): avc: denied { ioctl } for pid=8752 comm="syz.5.765" path="socket:[31360]" dev="sockfs" ino=31360 ioctlcmd=0x4508 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=smc_socket permissive=1 [ 137.115046][ T29] usb 9-1: Using ep0 maxpacket: 32 [ 137.122117][ T29] usb 9-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 137.127471][ T29] usb 9-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 137.137019][ T29] usb 9-1: New USB device found, idVendor=12d8, idProduct=0001, bcdDevice=de.79 [ 137.141194][ T29] usb 9-1: New USB device strings: Mfr=1, Product=236, SerialNumber=2 [ 137.144770][ T29] usb 9-1: Product: syz [ 137.146701][ T29] usb 9-1: Manufacturer: syz [ 137.148720][ T29] usb 9-1: SerialNumber: syz [ 137.154789][ T29] usb 9-1: config 0 descriptor?? [ 137.158495][ T29] hub 9-1:0.0: bad descriptor, ignoring hub [ 137.161831][ T29] hub 9-1:0.0: probe with driver hub failed with error -5 [ 137.192278][ T8761] binder: 8760:8761 ioctl c0306201 2000000003c0 returned -14 [ 137.192927][ T40] audit: type=1400 audit(2000000060.385:552): avc: denied { map } for pid=8760 comm="syz.5.768" path="/dev/binderfs/binder0" dev="binder" ino=7 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 137.222320][ T8683] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 137.227488][ T8683] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 137.231566][ T8683] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 137.235723][ T8683] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 137.260043][ T40] audit: type=1400 audit(2000000060.455:553): avc: denied { call } for pid=8760 comm="syz.5.768" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=binder permissive=1 [ 137.292252][ T8678] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 137.298600][ T1146] hsr_slave_0: left promiscuous mode [ 137.300749][ T1146] hsr_slave_1: left promiscuous mode [ 137.303820][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 137.306290][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 137.309134][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 137.312263][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 137.319332][ T1146] hsr_slave_0: left promiscuous mode [ 137.322447][ T1146] hsr_slave_1: left promiscuous mode [ 137.324527][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 137.327385][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 137.335362][ T1146] hsr_slave_0: left promiscuous mode [ 137.337648][ T1146] hsr_slave_1: left promiscuous mode [ 137.381823][ T1146] veth1_macvtap: left promiscuous mode [ 137.384367][ T1146] veth0_macvtap: left promiscuous mode [ 137.386932][ T1146] veth1_vlan: left promiscuous mode [ 137.389374][ T1146] veth0_vlan: left promiscuous mode [ 137.463387][ T29] usb 9-1: USB disconnect, device number 13 [ 137.802953][ T29] usb 9-1: new full-speed USB device number 14 using dummy_hcd [ 137.952442][ T29] usb 9-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 137.955883][ T29] usb 9-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 137.961876][ T29] usb 9-1: New USB device found, idVendor=12d8, idProduct=0001, bcdDevice=de.79 [ 137.964949][ T29] usb 9-1: New USB device strings: Mfr=1, Product=236, SerialNumber=2 [ 137.967946][ T29] usb 9-1: Product: syz [ 137.968378][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 137.969379][ T29] usb 9-1: Manufacturer: syz [ 137.973316][ T29] usb 9-1: SerialNumber: syz [ 137.977249][ T29] usb 9-1: config 0 descriptor?? [ 137.980325][ T29] hub 9-1:0.0: bad descriptor, ignoring hub [ 137.982425][ T29] hub 9-1:0.0: probe with driver hub failed with error -5 [ 138.043021][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 138.074542][ T8764] netlink: 8 bytes leftover after parsing attributes in process `syz.5.769'. [ 138.291205][ T29] usb 9-1: USB disconnect, device number 14 [ 138.441264][ T68] Bluetooth: hci0: command tx timeout [ 138.521188][ T68] Bluetooth: hci2: command tx timeout [ 138.601101][ T5955] Bluetooth: hci3: Opcode 0x206a failed: -110 [ 138.601146][ T68] Bluetooth: hci3: command 0x0406 tx timeout [ 139.082578][ T1146] team_slave_1 (unregistering): left promiscuous mode [ 139.089429][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 139.175091][ T1146] team_slave_0 (unregistering): left promiscuous mode [ 139.179623][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 140.180361][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 140.521592][ T5955] Bluetooth: hci0: command tx timeout [ 140.602411][ T5955] Bluetooth: hci2: command tx timeout [ 140.657824][ T8678] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 140.662492][ T8678] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 140.667065][ T8678] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 140.672266][ T8770] tc_dump_action: action bad kind [ 140.713833][ T8683] 8021q: adding VLAN 0 to HW filter on device bond0 [ 140.723975][ T40] audit: type=1400 audit(2000000063.925:554): avc: denied { map } for pid=8773 comm="syz.4.773" path="/dev/video7" dev="devtmpfs" ino=974 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:v4l_device_t tclass=chr_file permissive=1 [ 140.733328][ T40] audit: type=1400 audit(2000000063.925:555): avc: denied { execute } for pid=8773 comm="syz.4.773" path="/dev/video7" dev="devtmpfs" ino=974 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:v4l_device_t tclass=chr_file permissive=1 [ 140.740270][ T8683] 8021q: adding VLAN 0 to HW filter on device team0 [ 140.755322][ T13] bridge0: port 1(bridge_slave_0) entered blocking state [ 140.757694][ T13] bridge0: port 1(bridge_slave_0) entered forwarding state [ 140.765126][ T102] bridge0: port 2(bridge_slave_1) entered blocking state [ 140.767497][ T102] bridge0: port 2(bridge_slave_1) entered forwarding state [ 140.800927][ T8678] 8021q: adding VLAN 0 to HW filter on device bond0 [ 140.801790][ T8777] kvm_intel: set kvm_intel.dump_invalid_vmcs=1 to dump internal KVM state. [ 140.820551][ T8678] 8021q: adding VLAN 0 to HW filter on device team0 [ 140.835358][ T102] bridge0: port 1(bridge_slave_0) entered blocking state [ 140.837757][ T102] bridge0: port 1(bridge_slave_0) entered forwarding state [ 140.857702][ T1182] bridge0: port 2(bridge_slave_1) entered blocking state [ 140.860089][ T1182] bridge0: port 2(bridge_slave_1) entered forwarding state [ 140.945576][ T8683] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 140.970080][ T8683] veth0_vlan: entered promiscuous mode [ 140.977286][ T8683] veth1_vlan: entered promiscuous mode [ 140.995401][ T8683] veth0_macvtap: entered promiscuous mode [ 140.999152][ T8683] veth1_macvtap: entered promiscuous mode [ 141.012564][ T8683] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 141.018959][ T8683] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 141.025354][ T8683] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.028226][ T8683] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.037421][ T8683] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.040329][ T8683] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.100335][ T8678] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 141.131592][ T1182] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 141.134558][ T1182] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 141.137895][ T8798] netlink: 20 bytes leftover after parsing attributes in process `syz.4.778'. [ 141.161353][ T1182] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 141.163931][ T1182] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 141.176630][ T8678] veth0_vlan: entered promiscuous mode [ 141.189180][ T8678] veth1_vlan: entered promiscuous mode [ 141.221428][ T8678] veth0_macvtap: entered promiscuous mode [ 141.230956][ T8678] veth1_macvtap: entered promiscuous mode [ 141.248336][ T8678] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 141.267638][ T8678] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 141.285440][ T8678] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.288386][ T8678] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.292686][ T8678] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.295588][ T8678] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 141.313433][ T8804] netlink: 2028 bytes leftover after parsing attributes in process `syz.4.779'. [ 141.330779][ T8804] netlink: 24 bytes leftover after parsing attributes in process `syz.4.779'. [ 141.346007][ T8804] netlink: 60 bytes leftover after parsing attributes in process `syz.4.779'. [ 141.353389][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 141.356015][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 141.375103][ T6967] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 141.377793][ T6967] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 141.597756][ T1146] IPVS: stop unused estimator thread 0... [ 141.693524][ T1146] bridge_slave_1: left allmulticast mode [ 141.695479][ T1146] bridge_slave_1: left promiscuous mode [ 141.697405][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 141.701088][ T1146] bridge_slave_0: left allmulticast mode [ 141.702933][ T1146] bridge_slave_0: left promiscuous mode [ 141.704840][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 141.762076][ T66] usb 10-1: new high-speed USB device number 10 using dummy_hcd [ 141.911318][ T66] usb 10-1: Using ep0 maxpacket: 32 [ 141.914335][ T66] usb 10-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 141.918608][ T66] usb 10-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 141.922121][ T66] usb 10-1: New USB device found, idVendor=1e7d, idProduct=2d5a, bcdDevice= 0.00 [ 141.925315][ T66] usb 10-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 141.929250][ T66] usb 10-1: config 0 descriptor?? [ 141.982143][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 141.986644][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 141.990304][ T1146] bond0 (unregistering): Released all slaves [ 142.300852][ T8814] netlink: 8 bytes leftover after parsing attributes in process `syz.4.783'. [ 142.323933][ T1146] hsr_slave_0: left promiscuous mode [ 142.326148][ T1146] hsr_slave_1: left promiscuous mode [ 142.328201][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 142.330602][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 142.333878][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 142.336330][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 142.348941][ T66] savu 0003:1E7D:2D5A.0007: hiddev0,hidraw1: USB HID v0.00 Device [HID 1e7d:2d5a] on usb-dummy_hcd.5-1/input0 [ 142.358829][ T1146] veth1_macvtap: left promiscuous mode [ 142.360676][ T1146] veth0_macvtap: left promiscuous mode [ 142.363796][ T1146] veth1_vlan: left promiscuous mode [ 142.365538][ T1146] veth0_vlan: left promiscuous mode [ 142.435503][ T8817] netlink: 'syz.4.784': attribute type 1 has an invalid length. [ 142.609068][ T836] usb 10-1: USB disconnect, device number 10 [ 142.930699][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 142.993142][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 143.607522][ T40] audit: type=1400 audit(2000000066.805:556): avc: denied { setattr } for pid=8825 comm="syz.4.786" name="/" dev="configfs" ino=3110 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:configfs_t tclass=dir permissive=1 [ 143.911103][ T837] usb 9-1: new high-speed USB device number 15 using dummy_hcd [ 143.988624][ T1146] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 144.111128][ T837] usb 9-1: Using ep0 maxpacket: 16 [ 144.114140][ T837] usb 9-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 0 [ 144.118582][ T837] usb 9-1: New USB device found, idVendor=05ac, idProduct=0244, bcdDevice= 0.00 [ 144.121654][ T837] usb 9-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 144.126109][ T837] usb 9-1: config 0 descriptor?? [ 144.133921][ T837] input: bcm5974 as /devices/platform/dummy_hcd.4/usb9/9-1/9-1:0.0/input/input12 [ 144.198678][ T68] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 144.203606][ T68] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 144.207003][ T68] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 144.210716][ T68] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 144.213784][ T68] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 144.311448][ T8842] chnl_net:caif_netlink_parms(): no params data found [ 144.378515][ T8842] bridge0: port 1(bridge_slave_0) entered blocking state [ 144.380701][ T8842] bridge0: port 1(bridge_slave_0) entered disabled state [ 144.383251][ T8842] bridge_slave_0: entered allmulticast mode [ 144.385718][ T8842] bridge_slave_0: entered promiscuous mode [ 144.388624][ T8842] bridge0: port 2(bridge_slave_1) entered blocking state [ 144.390754][ T8842] bridge0: port 2(bridge_slave_1) entered disabled state [ 144.393212][ T8842] bridge_slave_1: entered allmulticast mode [ 144.395675][ T8842] bridge_slave_1: entered promiscuous mode [ 144.426704][ T8842] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 144.432112][ T8842] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 144.466576][ T8842] team0: Port device team_slave_0 added [ 144.469895][ T8842] team0: Port device team_slave_1 added [ 144.515671][ T8842] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 144.518866][ T8842] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 144.530302][ T8842] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 144.544068][ T8842] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 144.546980][ T8842] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 144.556936][ T8842] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 144.617142][ T8842] hsr_slave_0: entered promiscuous mode [ 144.620204][ T8842] hsr_slave_1: entered promiscuous mode [ 144.850938][ T5332] bcm5974 9-1:0.0: could not read from device [ 144.852617][ T837] usb 9-1: USB disconnect, device number 15 [ 144.858713][ T8007] bcm5974 9-1:0.0: could not read from device [ 145.007237][ T8857] sctp: [Deprecated]: syz.4.791 (pid 8857) Use of int in max_burst socket option deprecated. [ 145.007237][ T8857] Use struct sctp_assoc_value instead [ 145.070723][ T40] audit: type=1400 audit(2000000068.265:557): avc: denied { map } for pid=8868 comm="syz.4.796" path="/dev/usbmon0" dev="devtmpfs" ino=737 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usbmon_device_t tclass=chr_file permissive=1 [ 145.114808][ T68] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 145.120740][ T68] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 145.124718][ T68] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 145.128719][ T68] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 145.132389][ T68] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 145.155475][ T8876] netlink: 'syz.5.797': attribute type 1 has an invalid length. [ 145.250533][ T8876] veth3: entered promiscuous mode [ 145.273738][ T1146] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 145.287969][ T40] audit: type=1400 audit(2000000068.485:558): avc: denied { write } for pid=8889 comm="syz.4.800" path="socket:[34051]" dev="sockfs" ino=34051 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 145.292230][ T8871] chnl_net:caif_netlink_parms(): no params data found [ 145.363804][ T40] audit: type=1400 audit(2000000068.565:559): avc: denied { bind } for pid=8903 comm="syz.5.803" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 145.418155][ T8909] ieee802154 phy1 wpan1: encryption failed: -22 [ 145.421972][ T40] audit: type=1400 audit(2000000068.615:560): avc: denied { connect } for pid=8903 comm="syz.5.803" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ieee802154_socket permissive=1 [ 145.431792][ T1146] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 145.475806][ T40] audit: type=1400 audit(2000000068.675:561): avc: denied { ioctl } for pid=8912 comm="syz.5.804" path="socket:[34873]" dev="sockfs" ino=34873 ioctlcmd=0x4944 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=isdn_socket permissive=1 [ 145.509904][ T1146] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 145.528677][ T8871] bridge0: port 1(bridge_slave_0) entered blocking state [ 145.530795][ T8871] bridge0: port 1(bridge_slave_0) entered disabled state [ 145.533436][ T8871] bridge_slave_0: entered allmulticast mode [ 145.537160][ T8871] bridge_slave_0: entered promiscuous mode [ 145.540068][ T8871] bridge0: port 2(bridge_slave_1) entered blocking state [ 145.544136][ T8871] bridge0: port 2(bridge_slave_1) entered disabled state [ 145.546337][ T8871] bridge_slave_1: entered allmulticast mode [ 145.548811][ T8871] bridge_slave_1: entered promiscuous mode [ 145.652715][ T8871] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 145.657533][ T8871] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 145.709935][ T8871] team0: Port device team_slave_0 added [ 145.714708][ T8871] team0: Port device team_slave_1 added [ 145.748237][ T8871] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 145.750539][ T8871] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 145.759716][ T8871] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 145.766771][ T8871] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 145.769057][ T8871] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 145.778094][ T8871] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 145.912540][ T1146] bridge_slave_1: left allmulticast mode [ 145.914360][ T1146] bridge_slave_1: left promiscuous mode [ 145.916350][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 145.928926][ T1146] bridge_slave_0: left allmulticast mode [ 145.930871][ T1146] bridge_slave_0: left promiscuous mode [ 145.933433][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 146.282314][ T5955] Bluetooth: hci0: command tx timeout [ 146.291217][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 146.301094][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 146.304906][ T1146] bond0 (unregistering): Released all slaves [ 146.313147][ T8871] hsr_slave_0: entered promiscuous mode [ 146.316131][ T8871] hsr_slave_1: entered promiscuous mode [ 146.318302][ T8871] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 146.320999][ T8871] Cannot create hsr debugfs directory [ 146.351323][ T7920] IPVS: starting estimator thread 0... [ 146.395111][ T8930] netlink: 'syz.5.809': attribute type 5 has an invalid length. [ 146.441616][ T8931] IPVS: using max 43 ests per chain, 103200 per kthread [ 146.522900][ T8937] netlink: 12 bytes leftover after parsing attributes in process `syz.5.811'. [ 146.547248][ T8902] Set syz1 is full, maxelem 65536 reached [ 146.613080][ T1146] hsr_slave_0: left promiscuous mode [ 146.615681][ T1146] hsr_slave_1: left promiscuous mode [ 146.618148][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 146.623441][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 146.627119][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 146.629754][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 146.649317][ T1146] veth1_macvtap: left promiscuous mode [ 146.651701][ T1146] veth0_macvtap: left promiscuous mode [ 146.653642][ T1146] veth1_vlan: left promiscuous mode [ 146.655492][ T1146] veth0_vlan: left promiscuous mode [ 146.694365][ T40] audit: type=1400 audit(2000000069.895:562): avc: denied { ioctl } for pid=8940 comm="syz.4.813" path="socket:[33521]" dev="sockfs" ino=33521 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 147.163371][ T5955] Bluetooth: hci2: command tx timeout [ 147.258746][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 147.323200][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 147.839359][ T8871] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 147.929632][ T8871] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 148.014271][ T8871] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 148.115002][ T8871] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 148.251203][ T8871] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 148.258432][ T8871] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 148.274144][ T8871] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 148.279149][ T8956] netlink: 'syz.4.820': attribute type 21 has an invalid length. [ 148.292482][ T8956] netlink: 'syz.4.820': attribute type 1 has an invalid length. [ 148.295172][ T8871] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 148.326424][ T8842] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 148.334139][ T8842] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 148.339391][ T8842] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 148.343654][ T8842] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 148.361204][ T5955] Bluetooth: hci0: command tx timeout [ 148.365134][ T1146] bridge_slave_1: left allmulticast mode [ 148.367192][ T1146] bridge_slave_1: left promiscuous mode [ 148.369676][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 148.375733][ T1146] bridge_slave_0: left allmulticast mode [ 148.377706][ T1146] bridge_slave_0: left promiscuous mode [ 148.379718][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 148.448658][ T8966] netlink: 8 bytes leftover after parsing attributes in process `syz.4.823'. [ 148.619323][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 148.624102][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 148.627725][ T1146] bond0 (unregistering): Released all slaves [ 148.648738][ T8871] 8021q: adding VLAN 0 to HW filter on device bond0 [ 148.666890][ T8871] 8021q: adding VLAN 0 to HW filter on device team0 [ 148.682248][ T6967] bridge0: port 1(bridge_slave_0) entered blocking state [ 148.684670][ T6967] bridge0: port 1(bridge_slave_0) entered forwarding state [ 148.695896][ T6967] bridge0: port 2(bridge_slave_1) entered blocking state [ 148.698149][ T6967] bridge0: port 2(bridge_slave_1) entered forwarding state [ 148.739170][ T8842] 8021q: adding VLAN 0 to HW filter on device bond0 [ 148.750841][ T8842] 8021q: adding VLAN 0 to HW filter on device team0 [ 148.756218][ T6967] bridge0: port 1(bridge_slave_0) entered blocking state [ 148.758584][ T6967] bridge0: port 1(bridge_slave_0) entered forwarding state [ 148.789056][ T6966] bridge0: port 2(bridge_slave_1) entered blocking state [ 148.791673][ T6966] bridge0: port 2(bridge_slave_1) entered forwarding state [ 148.832901][ T8979] netlink: 'syz.5.827': attribute type 2 has an invalid length. [ 148.897082][ T8871] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 148.914504][ T8991] bond0: entered promiscuous mode [ 148.914519][ T8991] bond_slave_0: entered promiscuous mode [ 148.914605][ T8991] bond_slave_1: entered promiscuous mode [ 148.922437][ T8987] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=1539 sclass=netlink_route_socket pid=8987 comm=syz.5.829 [ 148.928879][ T8871] veth0_vlan: entered promiscuous mode [ 148.944510][ T8871] veth1_vlan: entered promiscuous mode [ 148.958677][ T8842] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 148.989678][ T1146] hsr_slave_0: left promiscuous mode [ 148.989887][ T8997] libceph: resolve ' [ 148.989887][ T8997] -&őĚ×fÍYąÇť˛a×ďĹ2i [ 148.989887][ T8997] .ÖúŐ?Çý&Ť*»§&' (ret=-3): failed [ 148.998343][ T1146] hsr_slave_1: left promiscuous mode [ 149.000451][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 149.003774][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 149.006627][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 149.009209][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 149.022348][ T40] audit: type=1400 audit(2000000072.225:563): avc: denied { append } for pid=9001 comm="syz.5.833" name="video7" dev="devtmpfs" ino=974 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:v4l_device_t tclass=chr_file permissive=1 [ 149.027650][ T1146] veth1_macvtap: left promiscuous mode [ 149.031734][ T1146] veth0_macvtap: left promiscuous mode [ 149.033843][ T1146] veth1_vlan: left promiscuous mode [ 149.035690][ T1146] veth0_vlan: left promiscuous mode [ 149.251177][ T5955] Bluetooth: hci2: command tx timeout [ 149.618267][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 149.689689][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 149.932609][ T9007] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=9007 comm=syz.5.834 [ 149.940547][ T9007] openvswitch: netlink: IP tunnel dst address not specified [ 150.169714][ T9004] netlink: 104 bytes leftover after parsing attributes in process `syz.4.831'. [ 150.176403][ T8871] veth0_macvtap: entered promiscuous mode [ 150.180257][ T8871] veth1_macvtap: entered promiscuous mode [ 150.201513][ T8871] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 150.213021][ T8842] veth0_vlan: entered promiscuous mode [ 150.222927][ T8871] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 150.230215][ T8842] veth1_vlan: entered promiscuous mode [ 150.235705][ T8871] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.238562][ T8871] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.242165][ T8871] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.245003][ T8871] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.268587][ T9020] syz.5.838: attempt to access beyond end of device [ 150.268587][ T9020] loop5: rw=0, sector=64, nr_sectors = 1 limit=0 [ 150.279338][ T9020] syz.5.838: attempt to access beyond end of device [ 150.279338][ T9020] loop5: rw=0, sector=256, nr_sectors = 1 limit=0 [ 150.285997][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=256, location=256 [ 150.289273][ T9020] syz.5.838: attempt to access beyond end of device [ 150.289273][ T9020] loop5: rw=0, sector=512, nr_sectors = 1 limit=0 [ 150.294417][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=512, location=512 [ 150.299891][ T9020] UDF-fs: warning (device loop5): udf_load_vrs: No anchor found [ 150.307112][ T9020] UDF-fs: Scanning with blocksize 512 failed [ 150.309816][ T9020] syz.5.838: attempt to access beyond end of device [ 150.309816][ T9020] loop5: rw=0, sector=64, nr_sectors = 2 limit=0 [ 150.314553][ T9020] syz.5.838: attempt to access beyond end of device [ 150.314553][ T9020] loop5: rw=0, sector=512, nr_sectors = 2 limit=0 [ 150.317291][ T8842] veth0_macvtap: entered promiscuous mode [ 150.318744][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=256, location=256 [ 150.327148][ T9020] syz.5.838: attempt to access beyond end of device [ 150.327148][ T9020] loop5: rw=0, sector=1024, nr_sectors = 2 limit=0 [ 150.331639][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=512, location=512 [ 150.334818][ T9020] UDF-fs: warning (device loop5): udf_load_vrs: No anchor found [ 150.337396][ T9020] UDF-fs: Scanning with blocksize 1024 failed [ 150.340645][ T9020] syz.5.838: attempt to access beyond end of device [ 150.340645][ T9020] loop5: rw=0, sector=64, nr_sectors = 4 limit=0 [ 150.344957][ T9020] syz.5.838: attempt to access beyond end of device [ 150.344957][ T9020] loop5: rw=0, sector=1024, nr_sectors = 4 limit=0 [ 150.345566][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 150.345975][ T8842] veth1_macvtap: entered promiscuous mode [ 150.349175][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=256, location=256 [ 150.353866][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 150.356918][ T9020] syz.5.838: attempt to access beyond end of device [ 150.356918][ T9020] loop5: rw=0, sector=2048, nr_sectors = 4 limit=0 [ 150.364480][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=512, location=512 [ 150.373519][ T9020] UDF-fs: warning (device loop5): udf_load_vrs: No anchor found [ 150.376178][ T6967] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 150.377929][ T9020] UDF-fs: Scanning with blocksize 2048 failed [ 150.378199][ T8842] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 150.378736][ T6967] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 150.380009][ T8842] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 150.382389][ T9020] syz.5.838: attempt to access beyond end of device [ 150.382389][ T9020] loop5: rw=0, sector=64, nr_sectors = 8 limit=0 [ 150.391589][ T8842] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.392668][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=256, location=256 [ 150.395384][ T8842] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.398564][ T9020] UDF-fs: error (device loop5): udf_read_tagged: read failed, block=512, location=512 [ 150.402721][ T8842] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.404593][ T9020] UDF-fs: warning (device loop5): udf_load_vrs: No anchor found [ 150.407330][ T8842] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 150.410101][ T9020] UDF-fs: Scanning with blocksize 4096 failed [ 150.415183][ T9018] tipc: Started in network mode [ 150.417581][ T9018] tipc: Node identity ac141417, cluster identity 5 [ 150.420415][ T9018] tipc: Enabled bearer , priority 10 [ 150.422557][ T9020] UDF-fs: warning (device loop5): udf_fill_super: No partition found (1) [ 150.445452][ T40] audit: type=1400 audit(2000000073.655:564): avc: denied { unlink } for pid=9017 comm="syz.4.837" name="file0" dev="9p" ino=35913943 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 150.452010][ T5955] Bluetooth: hci0: command tx timeout [ 150.453028][ T9018] netfs: Duplicate cookie detected [ 150.456883][ T9018] netfs: O-cookie c=00000005 [fl=4008 na=0 nA=0 s=-] [ 150.459880][ T9018] netfs: O-cookie V=00000003 [9p,syz,] [ 150.462837][ T9018] netfs: O-key=[8] 'd500240200000000' [ 150.465228][ T9018] netfs: N-cookie c=00000006 [fl=8 na=0 nA=0 s=-] [ 150.465267][ T9024] netlink: 8 bytes leftover after parsing attributes in process `syz.5.839'. [ 150.468084][ T9018] netfs: N-cookie V=00000003 [9p,syz,] [ 150.470975][ T9024] nbd: socks must be embedded in a SOCK_ITEM attr [ 150.473825][ T9018] netfs: N-key=[8] 'd500240200000000' [ 150.484724][ T9024] loop6: detected capacity change from 0 to 63 [ 150.501751][ T8005] Buffer I/O error on dev loop6, logical block 0, async page read [ 150.507321][ T8005] Buffer I/O error on dev loop6, logical block 0, async page read [ 150.510150][ T8005] Buffer I/O error on dev loop6, logical block 0, async page read [ 150.513885][ T8005] Buffer I/O error on dev loop6, logical block 0, async page read [ 150.517199][ T8005] Buffer I/O error on dev loop6, logical block 0, async page read [ 150.558713][ T1182] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 150.561600][ T1182] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 150.582874][ T1182] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 150.585220][ T1182] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 150.665859][ T9037] openvswitch: netlink: Unknown VXLAN extension attribute 0 [ 150.668962][ T9037] overlayfs: failed to resolve './file1': -2 [ 150.716835][ T40] audit: type=1400 audit(2000000073.915:565): avc: denied { watch } for pid=9046 comm="syz.4.846" path=2F6D656D66643A2D42D54E49C56A9A707070F00884A26D202864656C6574656429 dev="tmpfs" ino=3086 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 150.785444][ T9056] xt_l2tp: missing protocol rule (udp|l2tpip) [ 150.814156][ T40] audit: type=1400 audit(2000000074.015:566): avc: denied { lock } for pid=9057 comm="syz.5.851" path="socket:[36970]" dev="sockfs" ino=36970 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_stream_socket permissive=1 [ 151.146397][ T1146] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 151.281746][ T1146] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 151.432902][ T6013] tipc: Node number set to 2886997015 [ 151.492263][ T68] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 151.496815][ T68] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 151.499822][ T68] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 151.504765][ T68] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 151.507683][ T68] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 151.614766][ T9068] chnl_net:caif_netlink_parms(): no params data found [ 151.690070][ T9068] bridge0: port 1(bridge_slave_0) entered blocking state [ 151.692548][ T9068] bridge0: port 1(bridge_slave_0) entered disabled state [ 151.694897][ T9068] bridge_slave_0: entered allmulticast mode [ 151.697541][ T9068] bridge_slave_0: entered promiscuous mode [ 151.700741][ T9068] bridge0: port 2(bridge_slave_1) entered blocking state [ 151.703212][ T9068] bridge0: port 2(bridge_slave_1) entered disabled state [ 151.705567][ T9068] bridge_slave_1: entered allmulticast mode [ 151.708233][ T9068] bridge_slave_1: entered promiscuous mode [ 151.740227][ T9068] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 151.744984][ T9068] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 151.780033][ T9068] team0: Port device team_slave_0 added [ 151.784197][ T9068] team0: Port device team_slave_1 added [ 151.813037][ T9068] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 151.815366][ T9068] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 151.823667][ T9068] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 151.828102][ T9068] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 151.830365][ T9068] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 151.838676][ T9068] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 151.877051][ T9068] hsr_slave_0: entered promiscuous mode [ 151.879434][ T9068] hsr_slave_1: entered promiscuous mode [ 151.881950][ T9068] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 151.884614][ T9068] Cannot create hsr debugfs directory [ 151.989269][ T9078] netlink: 'syz.5.855': attribute type 6 has an invalid length. [ 151.992036][ T9078] netlink: 199836 bytes leftover after parsing attributes in process `syz.5.855'. [ 151.999205][ T9078] netlink: 4 bytes leftover after parsing attributes in process `syz.5.855'. [ 152.002965][ T68] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 152.006646][ T68] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 152.009629][ T68] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 152.014016][ T68] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 152.017560][ T68] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 152.057063][ T9078] kvm: vcpu 0: requested 1664 ns lapic timer period limited to 200000 ns [ 152.131803][ T9090] chnl_net:caif_netlink_parms(): no params data found [ 152.187783][ T1146] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 152.243394][ T9090] bridge0: port 1(bridge_slave_0) entered blocking state [ 152.245787][ T9090] bridge0: port 1(bridge_slave_0) entered disabled state [ 152.248256][ T9090] bridge_slave_0: entered allmulticast mode [ 152.250970][ T9090] bridge_slave_0: entered promiscuous mode [ 152.255268][ T9090] bridge0: port 2(bridge_slave_1) entered blocking state [ 152.257672][ T9090] bridge0: port 2(bridge_slave_1) entered disabled state [ 152.260165][ T9090] bridge_slave_1: entered allmulticast mode [ 152.263613][ T9090] bridge_slave_1: entered promiscuous mode [ 152.279657][ T9104] misc userio: Begin command sent, but we're already running [ 152.309496][ T9090] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 152.314629][ T9090] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 152.349004][ T9090] team0: Port device team_slave_0 added [ 152.353672][ T9090] team0: Port device team_slave_1 added [ 152.383629][ T9090] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 152.386038][ T9090] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 152.394411][ T9090] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 152.398840][ T9090] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 152.401198][ T9090] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 152.409519][ T9090] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 152.447561][ T9090] hsr_slave_0: entered promiscuous mode [ 152.449907][ T9090] hsr_slave_1: entered promiscuous mode [ 152.452657][ T9090] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 152.455160][ T9090] Cannot create hsr debugfs directory [ 152.621575][ T1146] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 152.703479][ T1146] bridge_slave_1: left allmulticast mode [ 152.705437][ T1146] bridge_slave_1: left promiscuous mode [ 152.707417][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 152.712375][ T1146] bridge_slave_0: left allmulticast mode [ 152.714263][ T1146] bridge_slave_0: left promiscuous mode [ 152.717111][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 152.730654][ T9106] openvswitch: netlink: ct_state flags 0000ee01 unsupported [ 152.760756][ T40] audit: type=1400 audit(2000000075.955:567): avc: denied { mount } for pid=9107 comm="syz.5.860" name="/" dev="devpts" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:devpts_t tclass=filesystem permissive=1 [ 152.774921][ T40] audit: type=1400 audit(2000000075.975:568): avc: denied { unmount } for pid=9107 comm="syz.5.860" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:devpts_t tclass=filesystem permissive=1 [ 152.786772][ T9108] binder: 9107:9108 ioctl c0306201 2000000003c0 returned -14 [ 152.962366][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 152.967288][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 152.972515][ T1146] bond0 (unregistering): Released all slaves [ 152.993763][ T9108] @: renamed from vlan0 (while UP) [ 153.190838][ T9128] netlink: 48 bytes leftover after parsing attributes in process `syz.4.866'. [ 153.195588][ T9128] netlink: 'syz.4.866': attribute type 4 has an invalid length. [ 153.204648][ T9128] netlink: 'syz.4.866': attribute type 4 has an invalid length. [ 153.226760][ T40] audit: type=1400 audit(2000000076.425:569): avc: denied { watch } for pid=9127 comm="syz.4.866" path="/225/file0/file0" dev="afs" ino=4 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:nfs_t tclass=dir permissive=1 [ 153.320036][ T40] audit: type=1400 audit(2000000076.515:570): avc: denied { ioctl } for pid=9122 comm="syz.5.865" path="socket:[35512]" dev="sockfs" ino=35512 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_crypto_socket permissive=1 [ 153.374617][ T1146] hsr_slave_0: left promiscuous mode [ 153.376789][ T1146] hsr_slave_1: left promiscuous mode [ 153.378857][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 153.381466][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 153.384711][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 153.387242][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 153.407112][ T1146] veth1_macvtap: left promiscuous mode [ 153.409008][ T1146] veth0_macvtap: left promiscuous mode [ 153.410904][ T1146] veth1_vlan: left promiscuous mode [ 153.412959][ T1146] veth0_vlan: left promiscuous mode [ 153.571128][ T5955] Bluetooth: hci0: command tx timeout [ 153.593106][ T29] usb 9-1: new high-speed USB device number 16 using dummy_hcd [ 153.742320][ T29] usb 9-1: config 0 interface 0 altsetting 251 endpoint 0x9 has invalid wMaxPacketSize 0 [ 153.745527][ T29] usb 9-1: config 0 interface 0 has no altsetting 0 [ 153.752970][ T29] usb 9-1: New USB device found, idVendor=045e, idProduct=0283, bcdDevice=99.0b [ 153.755999][ T29] usb 9-1: New USB device strings: Mfr=1, Product=228, SerialNumber=2 [ 153.758651][ T29] usb 9-1: Product: syz [ 153.760009][ T29] usb 9-1: Manufacturer: syz [ 153.761911][ T29] usb 9-1: SerialNumber: syz [ 153.764662][ T29] usb 9-1: config 0 descriptor?? [ 153.775320][ T29] usb 9-1: selecting invalid altsetting 0 [ 153.973303][ T9] usb 9-1: USB disconnect, device number 16 [ 154.042022][ T5955] Bluetooth: hci2: command tx timeout [ 154.073742][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 154.154314][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 154.735998][ T9090] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 154.774490][ T9] usb 9-1: new high-speed USB device number 17 using dummy_hcd [ 154.914709][ T9168] netlink: 8 bytes leftover after parsing attributes in process `syz.5.881'. [ 154.917471][ T9170] tmpfs: Bad value for 'mpol' [ 154.920012][ T9170] tmpfs: Bad value for 'mpol' [ 154.921532][ T9] usb 9-1: Using ep0 maxpacket: 32 [ 154.922671][ T9170] tmpfs: Bad value for 'mpol' [ 154.925463][ T9] usb 9-1: config 0 interface 0 altsetting 0 endpoint 0x85 has invalid wMaxPacketSize 0 [ 154.929183][ T9] usb 9-1: config 0 interface 0 altsetting 0 bulk endpoint 0x85 has invalid maxpacket 0 [ 154.931378][ T9170] tmpfs: Bad value for 'mpol' [ 154.934393][ T9] usb 9-1: New USB device found, idVendor=12d8, idProduct=0001, bcdDevice=de.79 [ 154.934633][ T9170] tmpfs: Bad value for 'mpol' [ 154.937484][ T9] usb 9-1: New USB device strings: Mfr=1, Product=236, SerialNumber=2 [ 154.937504][ T9] usb 9-1: Product: syz [ 154.937517][ T9] usb 9-1: Manufacturer: syz [ 154.939857][ T9170] tmpfs: Bad value for 'mpol' [ 154.942416][ T9] usb 9-1: SerialNumber: syz [ 154.951493][ T9170] tmpfs: Bad value for 'mpol' [ 154.953857][ T9] usb 9-1: config 0 descriptor?? [ 154.956991][ T9] hub 9-1:0.0: bad descriptor, ignoring hub [ 154.958845][ T9090] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 154.958948][ T9] hub 9-1:0.0: probe with driver hub failed with error -5 [ 154.961420][ T9170] tmpfs: Bad value for 'mpol' [ 154.961661][ T9170] tmpfs: Bad value for 'mpol' [ 154.961862][ T9170] tmpfs: Bad value for 'mpol' [ 154.962058][ T9170] tmpfs: Bad value for 'mpol' [ 154.962260][ T9170] tmpfs: Bad value for 'mpol' [ 154.962453][ T9170] tmpfs: Bad value for 'mpol' [ 154.962672][ T9170] tmpfs: Bad value for 'mpol' [ 155.018523][ T9173] xt_l2tp: invalid flags combination: c [ 155.023391][ T9173] netlink: 'syz.5.882': attribute type 11 has an invalid length. [ 155.036999][ T9090] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 155.173045][ T9090] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 155.212534][ T40] audit: type=1400 audit(2000000078.415:571): avc: denied { listen } for pid=9176 comm="syz.5.884" path=000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=unix_dgram_socket permissive=1 [ 155.281347][ T7920] usb 9-1: USB disconnect, device number 17 [ 155.298759][ T1146] bridge_slave_1: left allmulticast mode [ 155.301401][ T1146] bridge_slave_1: left promiscuous mode [ 155.303607][ T1146] bridge0: port 2(bridge_slave_1) entered disabled state [ 155.307985][ T1146] bridge_slave_0: left allmulticast mode [ 155.309905][ T1146] bridge_slave_0: left promiscuous mode [ 155.312729][ T1146] bridge0: port 1(bridge_slave_0) entered disabled state [ 155.355237][ T9179] binder: 9178:9179 ioctl 4018620d 0 returned -22 [ 155.412007][ T9181] binder: 9178:9181 ioctl 4018620d 0 returned -22 [ 155.442609][ T40] audit: type=1400 audit(2000000078.645:572): avc: denied { getopt } for pid=9183 comm="syz.5.886" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 155.449692][ T40] audit: type=1400 audit(2000000078.645:573): avc: denied { write } for pid=9183 comm="syz.5.886" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 155.467545][ T9186] mmap: syz.5.887 (9186) uses deprecated remap_file_pages() syscall. See Documentation/mm/remap_file_pages.rst. [ 155.475612][ T9186] vivid-001: disconnect [ 155.478248][ T9185] vivid-001: reconnect [ 155.560896][ T1146] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 155.566288][ T1146] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 155.570101][ T1146] bond0 (unregistering): Released all slaves [ 155.582069][ T9068] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 155.589542][ T9068] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 155.593462][ T9068] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 155.605279][ T9068] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 155.611189][ T6032] usb 9-1: new full-speed USB device number 18 using dummy_hcd [ 155.629977][ T9090] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 155.635055][ T9090] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 155.645078][ T5955] Bluetooth: hci0: command tx timeout [ 155.646536][ T9090] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 155.660681][ T9090] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 155.731799][ T9068] 8021q: adding VLAN 0 to HW filter on device bond0 [ 155.739486][ T9090] 8021q: adding VLAN 0 to HW filter on device bond0 [ 155.754323][ T9068] 8021q: adding VLAN 0 to HW filter on device team0 [ 155.762668][ T6032] usb 9-1: config 0 interface 0 altsetting 0 endpoint 0x85 has invalid wMaxPacketSize 0 [ 155.765915][ T13] bridge0: port 1(bridge_slave_0) entered blocking state [ 155.765960][ T13] bridge0: port 1(bridge_slave_0) entered forwarding state [ 155.770116][ T6032] usb 9-1: New USB device found, idVendor=12d8, idProduct=0001, bcdDevice=de.79 [ 155.773789][ T6032] usb 9-1: New USB device strings: Mfr=1, Product=236, SerialNumber=2 [ 155.776466][ T6032] usb 9-1: Product: syz [ 155.777852][ T6032] usb 9-1: Manufacturer: syz [ 155.779394][ T6032] usb 9-1: SerialNumber: syz [ 155.779662][ T9090] 8021q: adding VLAN 0 to HW filter on device team0 [ 155.782211][ T6032] usb 9-1: config 0 descriptor?? [ 155.785894][ T13] bridge0: port 2(bridge_slave_1) entered blocking state [ 155.786941][ T6032] hub 9-1:0.0: bad descriptor, ignoring hub [ 155.788173][ T13] bridge0: port 2(bridge_slave_1) entered forwarding state [ 155.790075][ T6032] hub 9-1:0.0: probe with driver hub failed with error -5 [ 155.806858][ T9198] netlink: 'syz.5.892': attribute type 62 has an invalid length. [ 155.812642][ T6966] bridge0: port 1(bridge_slave_0) entered blocking state [ 155.815010][ T6966] bridge0: port 1(bridge_slave_0) entered forwarding state [ 155.823636][ T6966] bridge0: port 2(bridge_slave_1) entered blocking state [ 155.826027][ T6966] bridge0: port 2(bridge_slave_1) entered forwarding state [ 155.840232][ T9068] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 155.843962][ T9068] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 155.875097][ T1146] hsr_slave_0: left promiscuous mode [ 155.877614][ T1146] hsr_slave_1: left promiscuous mode [ 155.879647][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 155.882311][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 155.885141][ T1146] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 155.887581][ T1146] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 155.907011][ T1146] veth1_macvtap: left promiscuous mode [ 155.908864][ T1146] veth0_macvtap: left promiscuous mode [ 155.910713][ T1146] veth1_vlan: left promiscuous mode [ 155.912597][ T1146] veth0_vlan: left promiscuous mode [ 156.091253][ T6032] usb 9-1: USB disconnect, device number 18 [ 156.121114][ T5955] Bluetooth: hci2: command tx timeout [ 156.493480][ T1146] team0 (unregistering): Port device team_slave_1 removed [ 156.566477][ T1146] team0 (unregistering): Port device team_slave_0 removed [ 156.610562][ T9208] netlink: 'syz.5.896': attribute type 1 has an invalid length. [ 157.122747][ T9208] 8021q: adding VLAN 0 to HW filter on device bond1 [ 157.132383][ T9209] 8021q: adding VLAN 0 to HW filter on device bond1 [ 157.134838][ T9209] bond1: (slave vxcan3): The slave device specified does not support setting the MAC address [ 157.138804][ T9209] bond1: (slave vxcan3): Error -95 calling set_mac_address [ 157.148685][ T9210] erspan0: entered allmulticast mode [ 157.153603][ T9210] bond1: (slave erspan0): making interface the new active one [ 157.156614][ T9210] bond1: (slave erspan0): Enslaving as an active interface with an up link [ 157.186231][ T9068] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 157.244189][ T9068] veth0_vlan: entered promiscuous mode [ 157.265831][ T40] audit: type=1400 audit(2000000080.465:574): avc: denied { append } for pid=9232 comm="syz.4.902" name="001" dev="devtmpfs" ino=767 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usb_device_t tclass=chr_file permissive=1 [ 157.271506][ T9068] veth1_vlan: entered promiscuous mode [ 157.290479][ T9068] veth0_macvtap: entered promiscuous mode [ 157.302736][ T9068] veth1_macvtap: entered promiscuous mode [ 157.317229][ T9068] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 157.323379][ T9090] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 157.333134][ T9068] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 157.339735][ T9068] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.343393][ T9068] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.347083][ T9068] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.350802][ T9068] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.395031][ T9090] veth0_vlan: entered promiscuous mode [ 157.419368][ T1182] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 157.420865][ T9090] veth1_vlan: entered promiscuous mode [ 157.424363][ T1182] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 157.433792][ T9247] syzkaller1: entered promiscuous mode [ 157.436446][ T9] hid-generic 0005:10CF:0009.0008: unknown main item tag 0x0 [ 157.437823][ T9247] syzkaller1: entered allmulticast mode [ 157.447411][ T9] hid-generic 0005:10CF:0009.0008: hidraw1: BLUETOOTH HID v0.09 Device [syz1] on aa:aa:aa:aa:aa:aa [ 157.458598][ T40] audit: type=1400 audit(2000000080.655:575): avc: denied { append } for pid=9246 comm="syz.4.906" name="card2" dev="devtmpfs" ino=639 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:dri_device_t tclass=chr_file permissive=1 [ 157.482842][ T6966] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 157.487814][ T9090] veth0_macvtap: entered promiscuous mode [ 157.488794][ T6966] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 157.491737][ T9090] veth1_macvtap: entered promiscuous mode [ 157.512554][ T9090] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 157.516862][ T9090] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 157.524146][ T9090] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.527074][ T9090] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.530715][ T9090] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.534707][ T9090] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 157.625220][ T1146] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 157.628432][ T1146] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 157.644667][ T13] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 157.648068][ T13] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 157.974547][ T9277] xt_hashlimit: size too large, truncated to 1048576 [ 158.032302][ T9278] program syz.5.915 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 158.032302][ T9277] program syz.5.915 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 158.150327][ T9286] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(10) [ 158.152664][ T9286] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 158.155693][ T9286] vhci_hcd vhci_hcd.0: Device attached [ 158.401339][ T9] usb 47-1: new low-speed USB device number 2 using vhci_hcd [ 158.406266][ T10] usb 10-1: new high-speed USB device number 11 using dummy_hcd [ 158.437121][ T9290] netlink: 4768 bytes leftover after parsing attributes in process `syz.4.919'. [ 158.441967][ T9290] dns_resolver: Unsupported server list version (0) [ 158.459302][ T6967] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 158.573332][ T10] usb 10-1: config 0 has no interfaces? [ 158.576004][ T10] usb 10-1: New USB device found, idVendor=0de5, idProduct=0056, bcdDevice= 5.b5 [ 158.580035][ T10] usb 10-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 158.593600][ T10] usb 10-1: config 0 descriptor?? [ 158.697725][ T68] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 158.700920][ T68] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 158.703880][ T68] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 158.707121][ T68] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 158.710365][ T68] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 158.797906][ T9287] usbip_core: unknown command [ 158.799508][ T9287] vhci_hcd: unknown pdu 1207959552 [ 158.801629][ T9287] usbip_core: unknown command [ 158.804101][ T1182] vhci_hcd: stop threads [ 158.805539][ T1182] vhci_hcd: release socket [ 158.808040][ T1182] vhci_hcd: disconnect device [ 158.808254][ T6013] usb 10-1: USB disconnect, device number 11 [ 158.819386][ T9294] chnl_net:caif_netlink_parms(): no params data found [ 158.886918][ T9294] bridge0: port 1(bridge_slave_0) entered blocking state [ 158.889428][ T9294] bridge0: port 1(bridge_slave_0) entered disabled state [ 158.892911][ T9294] bridge_slave_0: entered allmulticast mode [ 158.895646][ T9294] bridge_slave_0: entered promiscuous mode [ 158.899699][ T9294] bridge0: port 2(bridge_slave_1) entered blocking state [ 158.902348][ T9294] bridge0: port 2(bridge_slave_1) entered disabled state [ 158.904685][ T9294] bridge_slave_1: entered allmulticast mode [ 158.907358][ T9294] bridge_slave_1: entered promiscuous mode [ 158.938814][ T9294] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 158.944728][ T9294] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 158.975548][ T9294] team0: Port device team_slave_0 added [ 158.980170][ T9294] team0: Port device team_slave_1 added [ 159.021756][ T6967] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 159.029894][ T9294] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 159.033780][ T9294] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 159.042209][ T9294] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 159.046563][ T9294] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 159.048842][ T9294] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 159.058503][ T9294] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 159.095029][ T9294] hsr_slave_0: entered promiscuous mode [ 159.097366][ T9294] hsr_slave_1: entered promiscuous mode [ 159.634647][ T6967] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 159.765932][ T9311] SELinux: unrecognized netlink message: protocol=4 nlmsg_type=0 sclass=netlink_tcpdiag_socket pid=9311 comm=syz.5.923 [ 159.817624][ T5955] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 159.823214][ T5955] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 159.828928][ T5955] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 159.833410][ T5955] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 159.837126][ T5955] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 159.885384][ T9316] netlink: 'syz.5.923': attribute type 4 has an invalid length. [ 159.984391][ T9314] chnl_net:caif_netlink_parms(): no params data found [ 160.084252][ T6967] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 160.089996][ T9314] bridge0: port 1(bridge_slave_0) entered blocking state [ 160.093333][ T9314] bridge0: port 1(bridge_slave_0) entered disabled state [ 160.095770][ T9314] bridge_slave_0: entered allmulticast mode [ 160.099105][ T9314] bridge_slave_0: entered promiscuous mode [ 160.102967][ T9314] bridge0: port 2(bridge_slave_1) entered blocking state [ 160.105397][ T9314] bridge0: port 2(bridge_slave_1) entered disabled state [ 160.108435][ T9314] bridge_slave_1: entered allmulticast mode [ 160.111858][ T9314] bridge_slave_1: entered promiscuous mode [ 160.152561][ T9314] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 160.158159][ T9314] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 160.205619][ T9314] team0: Port device team_slave_0 added [ 160.212340][ T9314] team0: Port device team_slave_1 added [ 160.254575][ T9314] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 160.257133][ T9314] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 160.266720][ T9314] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 160.272034][ T9314] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 160.274386][ T9314] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 160.284527][ T9314] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 160.352251][ T9314] hsr_slave_0: entered promiscuous mode [ 160.354858][ T9314] hsr_slave_1: entered promiscuous mode [ 160.357243][ T9314] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 160.359889][ T9314] Cannot create hsr debugfs directory [ 160.364657][ T6967] bridge_slave_1: left allmulticast mode [ 160.366568][ T6967] bridge_slave_1: left promiscuous mode [ 160.368484][ T6967] bridge0: port 2(bridge_slave_1) entered disabled state [ 160.373322][ T6967] bridge_slave_0: left allmulticast mode [ 160.375221][ T6967] bridge_slave_0: left promiscuous mode [ 160.377186][ T6967] bridge0: port 1(bridge_slave_0) entered disabled state [ 160.652499][ T6967] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 160.657924][ T6967] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 160.666842][ T6967] bond0 (unregistering): Released all slaves [ 160.676942][ T40] audit: type=1400 audit(2000000083.875:576): avc: denied { create } for pid=9323 comm="syz.5.924" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rose_socket permissive=1 [ 160.685554][ T40] audit: type=1400 audit(2000000083.875:577): avc: denied { ioctl } for pid=9323 comm="syz.5.924" path="socket:[39113]" dev="sockfs" ino=39113 ioctlcmd=0x89e0 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rose_socket permissive=1 [ 160.764830][ T68] Bluetooth: hci0: command tx timeout [ 160.782420][ T9324] netlink: 8 bytes leftover after parsing attributes in process `syz.5.924'. [ 160.785403][ T9324] netlink: 'syz.5.924': attribute type 30 has an invalid length. [ 161.126415][ T6967] hsr_slave_0: left promiscuous mode [ 161.128901][ T6967] hsr_slave_1: left promiscuous mode [ 161.131494][ T6967] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 161.134522][ T6967] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 161.139032][ T6967] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 161.142263][ T6967] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 161.149929][ T9345] SELinux: security_context_str_to_sid (Eá…) failed with errno=-22 [ 161.159548][ T40] audit: type=1400 audit(2000000084.355:578): avc: denied { mount } for pid=9344 comm="syz.5.930" name="/" dev="debugfs" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:debugfs_t tclass=filesystem permissive=1 [ 161.178092][ T6967] veth1_macvtap: left promiscuous mode [ 161.180580][ T6967] veth0_macvtap: left promiscuous mode [ 161.184100][ T6967] veth1_vlan: left promiscuous mode [ 161.186447][ T6967] veth0_vlan: left promiscuous mode [ 161.894637][ T68] Bluetooth: hci2: command tx timeout [ 161.964109][ T6967] team0 (unregistering): Port device team_slave_1 removed [ 162.043302][ T6967] team0 (unregistering): Port device team_slave_0 removed [ 162.654388][ T9314] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 162.716348][ T9365] bridge0: port 2(bridge_slave_1) entered disabled state [ 162.731660][ T9365] bridge0: port 2(bridge_slave_1) entered disabled state [ 162.750486][ T9314] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 162.841580][ T68] Bluetooth: hci0: command tx timeout [ 162.844810][ T9314] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 162.923482][ T9382] netlink: 12 bytes leftover after parsing attributes in process `syz.4.942'. [ 162.928229][ T9382] netlink: 31 bytes leftover after parsing attributes in process `syz.4.942'. [ 162.929132][ T9314] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 162.934070][ T9382] netlink: 'syz.4.942': attribute type 3 has an invalid length. [ 162.939691][ T9382] netlink: 'syz.4.942': attribute type 2 has an invalid length. [ 162.946034][ T9382] netlink: 31 bytes leftover after parsing attributes in process `syz.4.942'. [ 163.015393][ T9386] bridge0: port 2(bridge_slave_1) entered disabled state [ 163.079796][ T9314] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 163.087222][ T9314] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 163.091382][ T9314] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 163.109965][ T9314] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 163.139305][ T9294] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 163.146184][ T9294] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 163.152785][ T9294] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 163.155155][ T9294] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 163.173075][ T40] audit: type=1400 audit(2000000086.365:579): avc: denied { append } for pid=9400 comm="syz.4.944" name="ppp" dev="devtmpfs" ino=730 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ppp_device_t tclass=chr_file permissive=1 [ 163.173125][ T40] audit: type=1400 audit(2000000086.365:580): avc: denied { getopt } for pid=9400 comm="syz.4.944" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 163.173162][ T40] audit: type=1400 audit(2000000086.375:581): avc: denied { read } for pid=9400 comm="syz.4.944" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 163.174204][ T6967] bridge_slave_1: left allmulticast mode [ 163.174219][ T6967] bridge_slave_1: left promiscuous mode [ 163.174310][ T6967] bridge0: port 2(bridge_slave_1) entered disabled state [ 163.187204][ T6967] bridge_slave_0: left allmulticast mode [ 163.210462][ T6967] bridge_slave_0: left promiscuous mode [ 163.213272][ T6967] bridge0: port 1(bridge_slave_0) entered disabled state [ 163.224869][ T40] audit: type=1400 audit(2000000086.425:582): avc: denied { setopt } for pid=9400 comm="syz.4.944" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 163.447040][ T6967] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 163.451930][ T6967] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 163.455756][ T6967] bond0 (unregistering): Released all slaves [ 163.485683][ T9314] 8021q: adding VLAN 0 to HW filter on device bond0 [ 163.504795][ T9314] 8021q: adding VLAN 0 to HW filter on device team0 [ 163.512519][ T1182] bridge0: port 1(bridge_slave_0) entered blocking state [ 163.515451][ T1182] bridge0: port 1(bridge_slave_0) entered forwarding state [ 163.528710][ T9294] 8021q: adding VLAN 0 to HW filter on device bond0 [ 163.534379][ T1182] bridge0: port 2(bridge_slave_1) entered blocking state [ 163.536825][ T1182] bridge0: port 2(bridge_slave_1) entered forwarding state [ 163.551637][ T9] vhci_hcd: vhci_device speed not set [ 163.554120][ T9294] 8021q: adding VLAN 0 to HW filter on device team0 [ 163.562042][ T1182] bridge0: port 1(bridge_slave_0) entered blocking state [ 163.564454][ T1182] bridge0: port 1(bridge_slave_0) entered forwarding state [ 163.574629][ T1182] bridge0: port 2(bridge_slave_1) entered blocking state [ 163.577006][ T1182] bridge0: port 2(bridge_slave_1) entered forwarding state [ 163.718378][ T9314] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 163.732891][ T9294] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 163.759251][ T6967] hsr_slave_0: left promiscuous mode [ 163.761526][ T6967] hsr_slave_1: left promiscuous mode [ 163.763568][ T6967] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 163.766089][ T6967] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 163.769423][ T6967] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 163.773926][ T6967] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 163.793354][ T6967] veth1_macvtap: left promiscuous mode [ 163.795231][ T6967] veth0_macvtap: left promiscuous mode [ 163.797113][ T6967] veth1_vlan: left promiscuous mode [ 163.799020][ T6967] veth0_vlan: left promiscuous mode [ 163.961461][ T68] Bluetooth: hci2: command tx timeout [ 164.461960][ T6967] team0 (unregistering): Port device team_slave_1 removed [ 164.529103][ T6967] team0 (unregistering): Port device team_slave_0 removed [ 164.921274][ T68] Bluetooth: hci0: command tx timeout [ 165.039976][ T9294] veth0_vlan: entered promiscuous mode [ 165.042935][ T9413] (unnamed net_device) (uninitialized): Removing last ns target with arp_interval on [ 165.046366][ T9413] workqueue: Failed to create a rescuer kthread for wq "bond2": -EINTR [ 165.065098][ T9294] veth1_vlan: entered promiscuous mode [ 165.080057][ T9314] veth0_vlan: entered promiscuous mode [ 165.089137][ T9314] veth1_vlan: entered promiscuous mode [ 165.096687][ T9294] veth0_macvtap: entered promiscuous mode [ 165.102638][ T9294] veth1_macvtap: entered promiscuous mode [ 165.147086][ T9294] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 165.152003][ T9314] veth0_macvtap: entered promiscuous mode [ 165.161998][ T9294] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 165.168407][ T9294] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.172652][ T9294] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.176290][ T9294] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.179868][ T9294] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.187867][ T9314] veth1_macvtap: entered promiscuous mode [ 165.246220][ T9314] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 165.251887][ T9432] sg_read: process 583 (syz.5.952) changed security contexts after opening file descriptor, this is not allowed. [ 165.267321][ T9314] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 165.273317][ T9314] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.276638][ T9314] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.280330][ T9314] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.280510][ T9434] Bluetooth: MGMT ver 1.23 [ 165.284631][ T9314] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 165.287320][ T9434] netlink: 'syz.4.954': attribute type 1 has an invalid length. [ 165.291678][ T9434] netlink: 44 bytes leftover after parsing attributes in process `syz.4.954'. [ 165.307904][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 165.323683][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 165.394442][ T102] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 165.397661][ T102] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 165.426240][ T9438] netlink: 32 bytes leftover after parsing attributes in process `syz.4.956'. [ 165.426961][ T102] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 165.447570][ T102] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 165.474122][ T6962] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 165.478984][ T6962] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 165.619481][ T9449] x_tables: ip6_tables: SYNPROXY target: used from hooks PREROUTING, but only usable from INPUT/FORWARD [ 165.635039][ T9440] syz.5.957 (9440): drop_caches: 2 [ 165.639746][ T9440] syz.5.957 (9440): drop_caches: 2 [ 165.786599][ T9463] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=42 sclass=netlink_xfrm_socket pid=9463 comm=syz.5.963 [ 165.790725][ T9463] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=44 sclass=netlink_xfrm_socket pid=9463 comm=syz.5.963 [ 165.790756][ T40] audit: type=1400 audit(2000000088.985:583): avc: denied { nlmsg_read } for pid=9462 comm="syz.5.963" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 165.795846][ T9463] SELinux: unrecognized netlink message: protocol=6 nlmsg_type=47 sclass=netlink_xfrm_socket pid=9463 comm=syz.5.963 [ 165.833891][ T40] audit: type=1400 audit(2000000089.035:584): avc: denied { bind } for pid=9464 comm="syz.5.964" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 166.056498][ T6962] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 166.135699][ T6962] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 166.227285][ T9494] netlink: 132 bytes leftover after parsing attributes in process `syz.4.972'. [ 166.315206][ T5955] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 166.318710][ T5955] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 166.323320][ T5955] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 166.326763][ T5955] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 166.329522][ T5955] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 166.433204][ T9497] chnl_net:caif_netlink_parms(): no params data found [ 166.526418][ T9497] bridge0: port 1(bridge_slave_0) entered blocking state [ 166.528947][ T9497] bridge0: port 1(bridge_slave_0) entered disabled state [ 166.531851][ T9497] bridge_slave_0: entered allmulticast mode [ 166.534633][ T9497] bridge_slave_0: entered promiscuous mode [ 166.538166][ T9497] bridge0: port 2(bridge_slave_1) entered blocking state [ 166.540862][ T9497] bridge0: port 2(bridge_slave_1) entered disabled state [ 166.543689][ T9497] bridge_slave_1: entered allmulticast mode [ 166.546900][ T9497] bridge_slave_1: entered promiscuous mode [ 166.559016][ T6962] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 166.595190][ T9497] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 166.599973][ T9497] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 166.636640][ T9497] team0: Port device team_slave_0 added [ 166.640300][ T9497] team0: Port device team_slave_1 added [ 166.676382][ T9497] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 166.679209][ T9497] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 166.689723][ T9497] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 166.696258][ T9497] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 166.699760][ T9497] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 166.711185][ T9497] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 166.767952][ T9497] hsr_slave_0: entered promiscuous mode [ 166.770523][ T9497] hsr_slave_1: entered promiscuous mode [ 166.772735][ T9497] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 166.775192][ T9497] Cannot create hsr debugfs directory [ 166.938094][ T68] Bluetooth: hci3: unexpected event for opcode 0x204e [ 166.990833][ T9516] openvswitch: netlink: Flow actions may not be safe on all matching packets. [ 167.020472][ T5955] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 167.024280][ T5955] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 167.027248][ T5955] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 167.033112][ T5955] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 167.036246][ T5955] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 167.123524][ T9511] bridge0: port 3(team0) entered disabled state [ 167.129025][ T9511] bridge0: port 1(bridge_slave_0) entered disabled state [ 167.197188][ T9520] chnl_net:caif_netlink_parms(): no params data found [ 167.224930][ T9511] bridge0: entered promiscuous mode [ 167.227041][ T9511] macvlan2: entered promiscuous mode [ 167.287632][ T6962] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 167.296403][ T9520] bridge0: port 1(bridge_slave_0) entered blocking state [ 167.299205][ T9520] bridge0: port 1(bridge_slave_0) entered disabled state [ 167.301749][ T9520] bridge_slave_0: entered allmulticast mode [ 167.304650][ T9520] bridge_slave_0: entered promiscuous mode [ 167.307884][ T9520] bridge0: port 2(bridge_slave_1) entered blocking state [ 167.310347][ T9520] bridge0: port 2(bridge_slave_1) entered disabled state [ 167.313830][ T9520] bridge_slave_1: entered allmulticast mode [ 167.316673][ T9520] bridge_slave_1: entered promiscuous mode [ 167.348823][ T9520] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 167.355533][ T9520] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 167.393254][ T9520] team0: Port device team_slave_0 added [ 167.396737][ T9520] team0: Port device team_slave_1 added [ 167.428221][ T9520] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 167.432312][ T9520] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 167.436955][ T9511] vivid-000: ================= START STATUS ================= [ 167.442005][ T9520] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 167.443565][ T9520] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 167.446026][ T9511] vivid-000: Test Pattern: [ 167.448269][ T9520] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 167.448301][ T9520] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 167.450853][ T9511] 75% Colorbar [ 167.467644][ T9511] vivid-000: Fill Percentage of Frame: 100 [ 167.469633][ T9511] vivid-000: Horizontal Movement: No Movement [ 167.472005][ T9511] vivid-000: Vertical Movement: No Movement [ 167.474453][ T9511] vivid-000: OSD Text Mode: All [ 167.476180][ T9511] vivid-000: Show Border: false [ 167.477801][ T9511] vivid-000: Show Square: false [ 167.479419][ T9511] vivid-000: Sensor Flipped Horizontally: false [ 167.483176][ T9511] vivid-000: Sensor Flipped Vertically: false [ 167.485333][ T9511] vivid-000: Insert SAV Code in Image: false [ 167.487332][ T9511] vivid-000: Insert EAV Code in Image: false [ 167.489344][ T9511] vivid-000: Insert Video Guard Band: false [ 167.491687][ T9511] vivid-000: Reduced Framerate: false [ 167.493498][ T9511] vivid-000: HDMI 000-0 Is Connected To: Test Pattern Generator [ 167.496456][ T9511] vivid-000: S-Video 000-0 Is Connected To: Output S-Video 001-0 [ 167.496799][ T9520] hsr_slave_0: entered promiscuous mode [ 167.499220][ T9511] vivid-000: Enable Capture Cropping: false grabbed [ 167.501784][ T9520] hsr_slave_1: entered promiscuous mode [ 167.503815][ T9511] vivid-000: Enable Capture Composing: true grabbed [ 167.505949][ T9520] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 167.507821][ T9511] vivid-000: Enable Capture Scaler: [ 167.510269][ T9520] Cannot create hsr debugfs directory [ 167.512482][ T9511] true grabbed [ 167.515148][ T9511] vivid-000: Timestamp Source: End of Frame [ 167.517971][ T9511] vivid-000: Colorspace: sRGB [ 167.519558][ T9511] vivid-000: Transfer Function: sRGB [ 167.521954][ T9511] vivid-000: Y'CbCr Encoding: Default [ 167.523767][ T9511] vivid-000: HSV Encoding: Hue 0-179 [ 167.526980][ T9511] vivid-000: Quantization: Default [ 167.529044][ T9511] vivid-000: Apply Alpha To Red Only: false [ 167.532703][ T9511] vivid-000: Standard Aspect Ratio: 4x3 [ 167.535127][ T9511] vivid-000: DV Timings Signal Mode: Current DV Timings inactive [ 167.538527][ T9511] vivid-000: DV Timings: 640x480p59 inactive [ 167.541684][ T9511] vivid-000: DV Timings Aspect Ratio: 4x3 [ 167.544045][ T9511] vivid-000: Maximum EDID Blocks: 1 [ 167.545980][ T9511] vivid-000: Limited RGB Range (16-235): false [ 167.548545][ T9511] vivid-000: Rx RGB Quantization Range: Automatic [ 167.551387][ T9511] vivid-000: Power Present: 0x00000001 [ 167.553850][ T9511] tpg source WxH: 320x180 (R'G'B) [ 167.556024][ T9511] tpg field: 1 [ 167.557514][ T9511] tpg crop: (0,0)/320x180 [ 167.559394][ T9511] tpg compose: (0,0)/320x180 [ 167.561314][ T9511] tpg colorspace: 8 [ 167.562629][ T9511] tpg transfer function: 2/2 [ 167.565344][ T9511] tpg quantization: 0/1 [ 167.567322][ T9511] tpg RGB range: 0/2 [ 167.568758][ T9511] vivid-000: ================== END STATUS ================== [ 167.811672][ T6962] bridge_slave_1: left allmulticast mode [ 167.813569][ T6962] bridge_slave_1: left promiscuous mode [ 167.815514][ T6962] bridge0: port 2(bridge_slave_1) entered disabled state [ 167.821830][ T6962] bridge_slave_0: left allmulticast mode [ 167.824187][ T6962] bridge_slave_0: left promiscuous mode [ 167.826219][ T6962] bridge0: port 1(bridge_slave_0) entered disabled state [ 167.933650][ T40] audit: type=1400 audit(2000000091.135:585): avc: denied { append } for pid=9538 comm="syz.5.979" path="/211/bus/blkio.bfq.io_merged_recursive" dev="9p" ino=35913965 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 167.963379][ T40] audit: type=1400 audit(2000000091.165:586): avc: denied { map } for pid=9538 comm="syz.5.979" path="/211/bus/cpu.stat" dev="9p" ino=35913966 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 167.971238][ T40] audit: type=1400 audit(2000000091.165:587): avc: denied { execute } for pid=9538 comm="syz.5.979" path="/211/bus/cpu.stat" dev="9p" ino=35913966 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=file permissive=1 [ 168.148672][ T9545] netlink: 8 bytes leftover after parsing attributes in process `syz.5.980'. [ 168.152730][ T9545] netlink: 4 bytes leftover after parsing attributes in process `syz.5.980'. [ 168.159438][ T6962] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 168.165523][ T6962] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 168.170388][ T6962] bond0 (unregistering): Released all slaves [ 168.361500][ T68] Bluetooth: hci0: command tx timeout [ 168.402993][ T40] audit: type=1400 audit(2000000091.605:588): avc: denied { recv } for pid=28 comm="ksoftirqd/1" saddr=127.0.0.1 src=30000 daddr=127.0.0.1 dest=37728 netif=lo scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=peer permissive=1 [ 168.411564][ T40] audit: type=1400 audit(2000000091.605:589): avc: denied { recv } for pid=28 comm="ksoftirqd/1" saddr=127.0.0.1 src=37728 daddr=127.0.0.1 dest=30000 netif=lo scontext=system_u:system_r:sshd_t tcontext=system_u:object_r:unlabeled_t tclass=peer permissive=1 [ 168.470602][ T9553] netlink: 168 bytes leftover after parsing attributes in process `syz.5.983'. [ 168.541401][ T6962] hsr_slave_0: left promiscuous mode [ 168.544976][ T6962] hsr_slave_1: left promiscuous mode [ 168.547230][ T6962] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 168.550370][ T6962] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 168.553710][ T6962] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 168.556238][ T6962] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 168.582934][ T6962] veth1_macvtap: left promiscuous mode [ 168.584815][ T6962] veth0_macvtap: left promiscuous mode [ 168.587355][ T6962] veth1_vlan: left promiscuous mode [ 168.589151][ T6962] veth0_vlan: left promiscuous mode [ 168.599227][ T9555] bio_check_eod: 2 callbacks suppressed [ 168.599239][ T9555] syz.5.984: attempt to access beyond end of device [ 168.599239][ T9555] nbd5: rw=4096, sector=0, nr_sectors = 1 limit=0 [ 168.606124][ T9555] XFS (nbd5): SB validate failed with error -5. [ 168.643867][ T40] audit: type=1804 audit(2000000091.835:590): pid=9565 uid=0 auid=4294967295 ses=4294967295 subj=root:sysadm_r:sysadm_t op=invalid_pcr cause=open_writers comm="syz.4.985" name="/newroot/276/file0" dev="tmpfs" ino=1469 res=1 errno=0 [ 168.670282][ T9565] ref_ctr_offset mismatch. inode: 0x5bd offset: 0x0 ref_ctr_offset(old): 0x0 ref_ctr_offset(new): 0x6 [ 168.778549][ T40] audit: type=1400 audit(2000000091.975:591): avc: denied { listen } for pid=9570 comm="syz.4.987" lport=56180 faddr=::ffff:172.20.255.187 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 168.788219][ T40] audit: type=1400 audit(2000000091.975:592): avc: denied { accept } for pid=9570 comm="syz.4.987" lport=56180 faddr=::ffff:172.20.255.187 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 169.082643][ T68] Bluetooth: hci2: command tx timeout [ 169.311873][ T6962] team0 (unregistering): Port device team_slave_1 removed [ 169.403261][ T6962] team0 (unregistering): Port device team_slave_0 removed [ 170.040162][ T68] Bluetooth: hci3: unexpected event for opcode 0x2010 [ 170.092826][ T9520] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 170.102991][ T9497] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 170.107770][ T9497] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 170.118430][ T9497] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 170.129405][ T9497] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 170.154184][ T9520] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 170.164600][ T9585] xt_cluster: you have exceeded the maximum number of cluster nodes (4095 > 32) [ 170.187141][ T9497] 8021q: adding VLAN 0 to HW filter on device bond0 [ 170.196044][ T9497] 8021q: adding VLAN 0 to HW filter on device team0 [ 170.202618][ T13] bridge0: port 1(bridge_slave_0) entered blocking state [ 170.205499][ T13] bridge0: port 1(bridge_slave_0) entered forwarding state [ 170.211542][ T6967] bridge0: port 2(bridge_slave_1) entered blocking state [ 170.213906][ T6967] bridge0: port 2(bridge_slave_1) entered forwarding state [ 170.242769][ T9497] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 170.284700][ T9520] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 170.291649][ T9592] block device autoloading is deprecated and will be removed. [ 170.358722][ T9497] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 170.392803][ T9520] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 170.440312][ T9497] veth0_vlan: entered promiscuous mode [ 170.442302][ T68] Bluetooth: hci0: command tx timeout [ 170.448615][ T9497] veth1_vlan: entered promiscuous mode [ 170.466217][ T9497] veth0_macvtap: entered promiscuous mode [ 170.473672][ T9497] veth1_macvtap: entered promiscuous mode [ 170.494291][ T9497] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 170.503252][ T9497] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 170.511580][ T9497] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 170.514389][ T9497] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 170.517522][ T9497] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 170.520847][ T9497] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 170.576539][ T9520] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 170.581871][ T6962] bridge_slave_1: left allmulticast mode [ 170.583846][ T6962] bridge_slave_1: left promiscuous mode [ 170.585868][ T6962] bridge0: port 2(bridge_slave_1) entered disabled state [ 170.590143][ T6962] bridge_slave_0: left allmulticast mode [ 170.592511][ T6962] bridge_slave_0: left promiscuous mode [ 170.594583][ T6962] bridge0: port 1(bridge_slave_0) entered disabled state [ 170.907935][ T9613] Driver unsupported XDP return value 0 on prog (id 130) dev N/A, expect packet loss! [ 170.939758][ T6962] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 170.951623][ T6962] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 170.955588][ T9612] delete_channel: no stack [ 170.956755][ T6962] bond0 (unregistering): Released all slaves [ 170.992802][ T9520] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 171.007660][ T40] kauditd_printk_skb: 7 callbacks suppressed [ 171.007676][ T40] audit: type=1400 audit(2000000094.205:600): avc: denied { mount } for pid=9615 comm="syz.4.1000" name="/" dev="bpf" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:bpf_t tclass=filesystem permissive=1 [ 171.016148][ T9520] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 171.040226][ T40] audit: type=1400 audit(2000000094.235:601): avc: denied { unmount } for pid=7054 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:bpf_t tclass=filesystem permissive=1 [ 171.054966][ T9520] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 171.066639][ T6966] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 171.070291][ T6966] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 171.125652][ T1146] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 171.129193][ T1146] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 171.146377][ T40] audit: type=1400 audit(2000000094.345:602): avc: denied { mounton } for pid=9497 comm="syz-executor" path="/syzkaller.ZZT8H5/syz-tmp/newroot/proc/sys/fs/binfmt_misc" dev="proc" ino=43267 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:sysctl_fs_t tclass=dir permissive=1 [ 171.163905][ T40] audit: type=1400 audit(2000000094.365:603): avc: denied { mount } for pid=9497 comm="syz-executor" name="/" dev="binder" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=filesystem permissive=1 [ 171.171570][ T68] Bluetooth: hci2: command tx timeout [ 171.252924][ T9520] 8021q: adding VLAN 0 to HW filter on device bond0 [ 171.300435][ T9520] 8021q: adding VLAN 0 to HW filter on device team0 [ 171.310578][ T6962] hsr_slave_0: left promiscuous mode [ 171.311184][ T9] usb 10-1: new high-speed USB device number 12 using dummy_hcd [ 171.316744][ T6962] hsr_slave_1: left promiscuous mode [ 171.319712][ T6962] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 171.324435][ T6962] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 171.328337][ T6962] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 171.332068][ T6962] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 171.353179][ T6962] veth1_macvtap: left promiscuous mode [ 171.355126][ T6962] veth0_macvtap: left promiscuous mode [ 171.357188][ T6962] veth1_vlan: left promiscuous mode [ 171.359343][ T6962] veth0_vlan: left promiscuous mode [ 171.462958][ T9] usb 10-1: config 0 interface 0 altsetting 251 endpoint 0x9 has invalid wMaxPacketSize 0 [ 171.467534][ T9] usb 10-1: config 0 interface 0 has no altsetting 0 [ 171.484630][ T9] usb 10-1: New USB device found, idVendor=045e, idProduct=0283, bcdDevice=99.0b [ 171.488801][ T9] usb 10-1: New USB device strings: Mfr=1, Product=228, SerialNumber=2 [ 171.493023][ T9] usb 10-1: Product: syz [ 171.494998][ T9] usb 10-1: Manufacturer: syz [ 171.497143][ T9] usb 10-1: SerialNumber: syz [ 171.502559][ T9] usb 10-1: config 0 descriptor?? [ 171.510371][ T9] usb 10-1: selecting invalid altsetting 0 [ 171.732991][ T40] audit: type=1400 audit(2000000094.925:604): avc: denied { create } for pid=9625 comm="syz.5.1002" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 171.739475][ T40] audit: type=1400 audit(2000000094.925:605): avc: denied { getopt } for pid=9625 comm="syz.5.1002" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 171.777446][ T9626] netlink: 16 bytes leftover after parsing attributes in process `syz.5.1002'. [ 172.107502][ T6962] team0 (unregistering): Port device team_slave_1 removed [ 172.193033][ T6962] team0 (unregistering): Port device team_slave_0 removed [ 172.602232][ T40] audit: type=1400 audit(2000000095.805:606): avc: denied { write } for pid=9669 comm="syz.4.1013" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 172.609802][ T40] audit: type=1400 audit(2000000095.805:607): avc: denied { connect } for pid=9669 comm="syz.4.1013" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 172.624933][ T40] audit: type=1400 audit(2000000095.825:608): avc: denied { shutdown } for pid=9669 comm="syz.4.1013" laddr=fe80::13 lport=34829 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 172.863718][ T102] bridge0: port 1(bridge_slave_0) entered blocking state [ 172.866895][ T102] bridge0: port 1(bridge_slave_0) entered forwarding state [ 172.872459][ T7920] usb 10-1: USB disconnect, device number 12 [ 172.879745][ T102] bridge0: port 2(bridge_slave_1) entered blocking state [ 172.882229][ T102] bridge0: port 2(bridge_slave_1) entered forwarding state [ 172.900149][ T40] audit: type=1400 audit(2000000096.095:609): avc: denied { sendto } for pid=6966 comm="kworker/u32:15" saddr=fe80::1b daddr=ff02::16 netif=wpan1 scontext=system_u:object_r:unlabeled_t tcontext=system_u:object_r:node_t tclass=node permissive=1 [ 173.030543][ T9691] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000021: 0000 [#1] SMP KASAN NOPTI [ 173.032455][ T9520] 8021q: adding VLAN 0 to HW filter on device batadv0 SYZFAIL: failed to recv rpc fd=3 want=4 recv=0 n=0 (errno 9: Bad file descriptor) [ 173.035232][ T9691] KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] [ 173.042511][ T9691] CPU: 0 UID: 0 PID: 9691 Comm: syz.4.1017 Not tainted 6.15.0-rc6-syzkaller-00278-g172a9d94339c #0 PREEMPT(full) [ 173.046380][ T9691] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 [ 173.049898][ T9691] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 173.051617][ T9691] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 ca 2c 5d f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 173.056175][ T9520] veth0_vlan: entered promiscuous mode [ 173.057997][ T9691] RSP: 0018:ffffc900038d7bf0 EFLAGS: 00010293 [ 173.061712][ T9520] veth1_vlan: entered promiscuous mode [ 173.061792][ T9691] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffffff885e192a [ 173.066187][ T9691] RDX: ffff888026a74880 RSI: ffffffff885e1976 RDI: 0000000000000005 [ 173.068804][ T9691] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 173.070748][ T9520] veth0_macvtap: entered promiscuous mode [ 173.071419][ T9691] R10: 0000000000000001 R11: 0000000000000000 R12: ffffc900038d7d88 [ 173.071428][ T9691] R13: ffffc900038d7d88 R14: 0000000000000001 R15: ffff88802e7d9c00 [ 173.071435][ T9691] FS: 00007fd9cf81f6c0(0000) GS:ffff8880d69da000(0000) knlGS:0000000000000000 [ 173.071458][ T9691] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 173.071467][ T9691] CR2: 00007fd9cf81ef98 CR3: 0000000062d2e000 CR4: 0000000000352ef0 [ 173.071474][ T9691] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 173.071481][ T9691] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 173.075061][ T9520] veth1_macvtap: entered promiscuous mode [ 173.075940][ T9691] Call Trace: [ 173.082866][ T9520] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 173.083624][ T9691] [ 173.088402][ T9520] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 173.088800][ T9691] ? __pfx_bcsp_recv+0x10/0x10 [ 173.093322][ T9520] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 173.094359][ T9691] hci_uart_tty_receive+0x251/0x7e0 [ 173.096767][ T9520] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 173.097806][ T9691] ? __pfx_hci_uart_tty_receive+0x10/0x10 [ 173.100134][ T9520] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 173.101747][ T9691] tty_ioctl+0x580/0x1610 [ 173.101775][ T9691] ? __pfx_tty_ioctl+0x10/0x10 [ 173.101787][ T9691] ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 [ 173.101809][ T9691] ? hook_file_ioctl_common+0x145/0x410 [ 173.104946][ T9520] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 173.106331][ T9691] ? selinux_file_ioctl+0x180/0x270 [ 173.125506][ T9691] ? selinux_file_ioctl+0xb4/0x270 [ 173.127224][ T9691] ? __pfx_tty_ioctl+0x10/0x10 [ 173.128932][ T9691] __x64_sys_ioctl+0x193/0x200 [ 173.130752][ T9691] do_syscall_64+0xcd/0x260 [ 173.132474][ T9691] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 173.134482][ T9691] RIP: 0033:0x7fd9ce98e969 [ 173.136398][ T9691] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 173.142958][ T9691] RSP: 002b:00007fd9cf81f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 173.145726][ T9691] RAX: ffffffffffffffda RBX: 00007fd9cebb6160 RCX: 00007fd9ce98e969 [ 173.148324][ T9691] RDX: 0000200000000040 RSI: 0000000000005412 RDI: 0000000000000004 [ 173.150985][ T9691] RBP: 00007fd9cea10ab1 R08: 0000000000000000 R09: 0000000000000000 [ 173.153598][ T9691] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 173.156193][ T9691] R13: 0000000000000001 R14: 00007fd9cebb6160 R15: 00007ffe2302fe98 [ 173.158814][ T9691] [ 173.159895][ T9691] Modules linked in: [ 173.161676][ T9691] ---[ end trace 0000000000000000 ]--- [ 173.163798][ T9691] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 173.167415][ T9691] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 ca 2c 5d f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 173.195360][ T9691] RSP: 0018:ffffc900038d7bf0 EFLAGS: 00010293 [ 173.198185][ T9691] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffffff885e192a [ 173.202700][ T9691] RDX: ffff888026a74880 RSI: ffffffff885e1976 RDI: 0000000000000005 [ 173.204596][ T7770] Process accounting resumed [ 173.205956][ T9691] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 173.205973][ T9691] R10: 0000000000000001 R11: 0000000000000000 R12: ffffc900038d7d88 [ 173.214289][ T9691] R13: ffffc900038d7d88 R14: 0000000000000001 R15: ffff88802e7d9c00 [ 173.217796][ T9691] FS: 00007fd9cf81f6c0(0000) GS:ffff8880d6cda000(0000) knlGS:0000000000000000 [ 173.225240][ T9691] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 173.228244][ T9691] CR2: 0000555ee44cfb08 CR3: 0000000062d2e000 CR4: 0000000000352ef0 [ 173.232125][ T9691] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 173.235537][ T9691] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 173.238146][ T9691] Kernel panic - not syncing: Fatal exception [ 173.241078][ T9691] Kernel Offset: disabled [ 173.242994][ T9691] Rebooting in 86400 seconds.. VM DIAGNOSIS: 18:30:16 Registers: info registers vcpu 0 CPU#0 RAX=0000000000000000 RBX=0000000000000046 RCX=ffffffff819b27e2 RDX=ffff888026a74880 RSI=ffffffff819b27d0 RDI=0000000000000001 RBP=0000000000000001 RSP=ffffc900038d7908 R8 =0000000000000001 R9 =0000000000000000 R10=0000000000000001 R11=6567203a73706f4f R12=1ffff9200071af23 R13=0000000000000000 R14=ffff88802a0c8000 R15=ffffc900038d79d0 RIP=ffffffff819b27d2 RFL=00000093 [--S-A-C] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 00007fd9cf81f6c0 ffffffff 00c00000 GS =0000 ffff8880d69da000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe0000003000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe0000001000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007fd9cf81ef98 CR3=0000000062d2e000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000000008001 Opmask01=0000000000000000 Opmask02=000000000000003f Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11a8a ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11a97 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11a91 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11aa5 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11b2b ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11c09 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9ceb83488 00007fd9ceb83480 00007fd9ceb83478 00007fd9ceb83450 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cf6ed100 00007fd9ceb83440 00007fd9ceb83458 00007fd9ceb834a0 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9ceb83498 00007fd9ceb83490 00007fd9ceb83488 00007fd9ceb83480 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 1 CPU#1 RAX=0000000000000061 RBX=00000000000003f8 RCX=0000000000000000 RDX=00000000000003f8 RSI=ffffffff854f9af5 RDI=ffffffff9adfe5a0 RBP=ffffffff9adfe560 RSP=ffffc90003716ba8 R8 =0000000000000001 R9 =000000000000001f R10=0000000000000000 R11=61203a7131323038 R12=0000000000000000 R13=0000000000000061 R14=ffffffff9adfe560 R15=ffffffff854f9a90 RIP=ffffffff854f9b1f RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 000055558e13b500 ffffffff 00c00000 GS =0000 ffff8880d6ada000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe000004a000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe0000048000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=00007f8998848e9c CR3=000000004685a000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000040102080 Opmask01=0000000000000fff Opmask02=00000000ffffffef Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000100000001 0000001400000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11a5f ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11a57 ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11a8a ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11a97 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11a91 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11aa5 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11b2b ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007f5783c11c09 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2525252525252525 2525252525252525 2525252525252525 2525252525252525 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 706900306974765f 706900306c6e7574 0030746973003267 7700316777003067 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 7700647261756765 72697700316e6163 7876006e61637876 0030766461746162 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 2 CPU#2 RAX=00000000000ef2d4 RBX=0000000000000002 RCX=ffffffff8b6d3419 RDX=ffffed100d4c65be RSI=ffffffff8bf4a120 RDI=ffffffff8191ae41 RBP=ffffed1003ad9910 RSP=ffffc90000187df8 R8 =0000000000000000 R9 =ffffed100d4c65bd R10=ffff88806a632deb R11=0000000000005bdf R12=0000000000000002 R13=ffff88801d6cc880 R14=ffffffff90852d10 R15=0000000000000000 RIP=ffffffff8b6d1caf RFL=00000286 [--S--P-] CPL=0 II=0 A20=1 SMM=0 HLT=1 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 0000000000000000 ffffffff 00c00000 GS =0000 ffff8880d6bda000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe0000091000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe000008f000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=0000200000000400 CR3=0000000062d2e000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=0000000000008001 Opmask01=0000000000000000 Opmask02=000000000000003f Opmask03=0000000000000000 Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 000001a0000000d0 00000000ffffffff ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11a8a ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11a97 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11a91 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11aa5 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11b2b ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cea11c09 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9ceb83488 00007fd9ceb83480 00007fd9ceb83478 00007fd9ceb83450 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9cf6ed100 00007fd9ceb83440 00007fd9ceb83458 00007fd9ceb834a0 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fd9ceb83498 00007fd9ceb83490 00007fd9ceb83488 00007fd9ceb83480 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6161616161616161 6161616161616161 6161616161616161 6161616161616161 ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 info registers vcpu 3 CPU#3 RAX=dffffc0000000000 RBX=ffff8880236628f0 RCX=ffffffff894aae44 RDX=1ffff110040d9176 RSI=ffffffff894ab872 RDI=ffff8880206c8bb0 RBP=ffff8880206c8000 RSP=ffffc90004017600 R8 =0000000000000005 R9 =0000000000000000 R10=0000000000000000 R11=0000000000000000 R12=ffff888023662980 R13=0000000000000000 R14=ffff88803094d000 R15=ffff8880206c8000 RIP=ffffffff894ab8ad RFL=00000246 [---Z-P-] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0000 0000000000000000 ffffffff 00c00000 CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA] SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA] DS =0000 0000000000000000 ffffffff 00c00000 FS =0000 00007f8697059300 ffffffff 00c00000 GS =0000 ffff8880d6cda000 ffffffff 00c00000 LDT=0000 0000000000000000 ffffffff 00c00000 TR =0040 fffffe00000d8000 00000067 00008b00 DPL=0 TSS64-busy GDT= fffffe00000d6000 0000007f IDT= fffffe0000000000 0000ffff CR0=80050033 CR2=0000000000000000 CR3=0000000024d69000 CR4=00352ef0 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000fffe0ff0 DR7=0000000000000400 EFER=0000000000000d01 FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80 FPR0=0000000000000000 0000 FPR1=0000000000000000 0000 FPR2=0000000000000000 0000 FPR3=0000000000000000 0000 FPR4=0000000000000000 0000 FPR5=0000000000000000 0000 FPR6=0000000000000000 0000 FPR7=0000000000000000 0000 Opmask00=00000000fcffc200 Opmask01=000000000000ffff Opmask02=00000000ffffffff Opmask03=0000000010000000 Opmask04=0000000000000000 Opmask05=00000000004007ff Opmask06=0000000007ffe7ff Opmask07=0000000000000000 ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 000000000001df8a 0000002c00000012 0004000000080024 0000000000280030 ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000401 0000001000000000 0000000000000000 0000000000000015 ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 1000058004040171 b00001fe08090606 0e0412080580033c 000009b700000000 ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00000001ffffffff ffffffffa7080da0 030008000d980300 ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 08000d9003000800 0d88030008000d80 0300080002100004 100006026fd40ca0 ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 a088801000020175 ca04100002f4ec10 000004060074aa00 236f656469762f76 ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 65642f01ffffffff ffffffffe7080003 0010000fffffffff ffff04040156a012 ZMM24=708dea7f708dea7f 708dea7f708dea7f 708dea7f708dea7f 708dea7f708dea7f 708dea7f708dea7f 708dea7f708dea7f 708dea7f708dea7f 708dea7f708dea7f ZMM25=dedb6b2bdedb6b2b dedb6b2bdedb6b2b dedb6b2bdedb6b2b dedb6b2bdedb6b2b dedb6b2bdedb6b2b dedb6b2bdedb6b2b dedb6b2bdedb6b2b dedb6b2bdedb6b2b ZMM26=9fe3de9c9fe3de9c 9fe3de9c9fe3de9c 9fe3de9c9fe3de9c 9fe3de9c9fe3de9c 9fe3de9c9fe3de9c 9fe3de9c9fe3de9c 9fe3de9c9fe3de9c 9fe3de9c9fe3de9c ZMM27=e1a81048e1a81048 e1a81048e1a81048 e1a81048e1a81048 e1a81048e1a81048 e1a81048e1a81048 e1a81048e1a81048 e1a81048e1a81048 e1a81048e1a81048 ZMM28=000000300000002f 0000002e0000002d 0000002c0000002b 0000002a00000029 0000002800000027 0000002600000025 0000002400000023 0000002200000021 ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ZMM31=4905000049050000 4905000049050000 4905000049050000 4905000049050000 4905000049050000 4905000049050000 4905000049050000 4905000049050000