last executing test programs: 1m9.393986654s ago: executing program 0 (id=3217): r0 = syz_open_procfs(0x0, &(0x7f0000000380)='attr/exec\x00') mount$9p_fd(0x0, &(0x7f0000000100)='.\x00', 0x0, 0x0, &(0x7f0000000880)=ANY=[@ANYRESHEX=r0, @ANYBLOB=',wfdno=', @ANYRESHEX=r0]) r1 = syz_io_uring_setup(0x2e3b, &(0x7f0000000240)={0x0, 0x492b, 0x10100, 0x400}, &(0x7f00000003c0)=0x0, &(0x7f0000000300)=0x0) lseek(r0, 0xfffffffffffffffe, 0x1) syz_io_uring_submit(r2, r3, &(0x7f0000000180)=@IORING_OP_READV=@pass_iovec={0x1, 0x0, 0x0, @fd=r0, 0x0, &(0x7f00000004c0)=[{&(0x7f0000000000)=""/4, 0x4}], 0x1}) io_uring_enter(r1, 0x567, 0xa1ff, 0x0, 0x0, 0x0) r4 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0600000004000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x5, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r4, @ANYBLOB="0000000000000000b7080000b2e900007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, '\x00', 0x0, @fallback=0x2e, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00'}, 0x10) r5 = socket$inet6_tcp(0xa, 0x1, 0x0) bind$inet6(r5, &(0x7f0000000100)={0xa, 0x4e22}, 0x1c) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x14, &(0x7f0000000280)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020646c2100000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000000008500", @ANYRES32, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b70400000000000085000000c30000"], &(0x7f0000000340)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x4, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffc, @void, @value}, 0x94) r6 = inotify_init1(0x0) r7 = inotify_add_watch(r6, &(0x7f0000000200)='.\x00', 0x400) inotify_rm_watch(0xffffffffffffffff, r7) socket$nl_route(0x10, 0x3, 0x0) open(&(0x7f0000000200)='./file0\x00', 0x808360, 0x20) bpf$BPF_PROG_TEST_RUN(0x1c, &(0x7f00000002c0)={0xffffffffffffffff, 0x4, 0x29, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) r8 = syz_open_dev$usbfs(&(0x7f0000000080), 0x74, 0x101301) ioctl$USBDEVFS_IOCTL(r8, 0xc0105512, &(0x7f0000000200)) ioctl$USBDEVFS_IOCTL(r8, 0xc0105512, &(0x7f0000000040)=@usbdevfs_connect) 1m9.271708584s ago: executing program 0 (id=3223): r0 = bpf$MAP_CREATE(0x0, 0x0, 0x48) r1 = socket(0x2, 0x80805, 0x0) getsockopt$inet_sctp6_SCTP_SOCKOPT_CONNECTX3(r1, 0x84, 0x6f, &(0x7f0000000000)={0x0, 0x10, &(0x7f0000000380)=[@in={0x2, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}}]}, &(0x7f0000000180)=0x10) getsockopt$inet_sctp_SCTP_MAX_BURST(r1, 0x84, 0x14, &(0x7f0000000000)=@assoc_value={0x0}, 0x0) getsockopt$inet_sctp_SCTP_SOCKOPT_PEELOFF(r1, 0x84, 0x66, &(0x7f0000000040)={r2, 0x10000}, &(0x7f00000010c0)=0x8) r3 = bpf$PROG_LOAD(0x5, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r3}, 0x10) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000180)={{r0}, 0x0, &(0x7f0000000080)}, 0x20) r4 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000540)=ANY=[], &(0x7f0000000180)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000bc0)={&(0x7f0000000a80)='kfree\x00', r4}, 0x10) r5 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$IP6T_SO_SET_REPLACE(r5, 0x29, 0x40, &(0x7f0000000c80)=@raw={'raw\x00', 0x3c1, 0x3, 0x4c0, 0x2e0, 0x940c, 0x3002, 0x2e0, 0x2c0, 0x3f0, 0x3d8, 0x3d8, 0x3f0, 0x3d8, 0x3, 0x0, {[{{@uncond, 0x0, 0x298, 0x2e0, 0x4001, {}, [@common=@inet=@recent0={{0xf8}, {0x0, 0x4001, 0x1, 0x3, 'syz0\x00'}}, @common=@inet=@recent0={{0xf8}, {0x0, 0x0, 0x2, 0x0, 'syz0\x00'}}]}, @common=@inet=@TEE={0x48, 'TEE\x00', 0x1, {@ipv4=@loopback, 'virt_wifi0\x00'}}}, {{@uncond, 0x0, 0xd0, 0x110, 0x0, {}, [@inet=@rpfilter={{0x28}}]}, @common=@unspec=@RATEEST={0x40, 'RATEEST\x00', 0x0, {'syz1\x00', 0x1, 0xbe, {0x565159d7}}}}], {{'\x00', 0x0, 0xa8, 0xd0}, {0x28}}}}, 0x565) ioctl$AUTOFS_DEV_IOCTL_CATATONIC(0xffffffffffffffff, 0xc018937e, 0x0) r6 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18020000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb703000008000000b703000000000020850000007200000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) timer_create(0x0, &(0x7f0000066000)={0x0, 0x12}, &(0x7f00009b1ffc)) timer_settime(0x0, 0x0, &(0x7f00000008c0)={{0x0, 0x3938700}, {0x0, 0x3938700}}, 0x0) timer_settime(0x0, 0x0, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000300)={&(0x7f00000002c0)='sched_switch\x00', r6}, 0x18) io_setup(0x4, &(0x7f0000000140)=0x0) io_pgetevents(r7, 0x1, 0x1, &(0x7f00000001c0)=[{}], &(0x7f0000000300)={0x0, 0x3938700}, 0x0) ioprio_set$pid(0x1, 0x0, 0x6000) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="18000000000000000000000000000000181200", @ANYRES32, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000002010000850000004300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r8 = bpf$PROG_LOAD(0x5, &(0x7f00000007c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000880)='GPL\x00', 0x0, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00', r8}, 0x10) getsockname$packet(0xffffffffffffffff, 0x0, 0x0) socket$nl_generic(0x10, 0x3, 0x10) 1m8.973797632s ago: executing program 0 (id=3227): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r0, 0x84, 0x72, &(0x7f0000000240)={0x0, 0x0, 0x20}, 0xc) bind$inet6(r0, &(0x7f0000000000)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendto$inet6(r0, &(0x7f0000000180)="1a", 0x1, 0x0, 0x0, 0x0) sendmmsg$sock(r0, &(0x7f0000000300)=[{{0x0, 0x0, &(0x7f0000000200)=[{&(0x7f00000000c0)="073c4a3715599c23307584e021db102efa0221b7935a2d2447da0792affa48ca0a59768965ce5d6d11aa2928e6e72e7093706a08a910", 0x36}], 0x1}}, {{0x0, 0x0, &(0x7f0000000040)=[{&(0x7f0000000280)="8b32d1", 0x3}], 0x1}}, {{0x0, 0x0, &(0x7f0000001800)=[{&(0x7f0000001e00)="02", 0x1}], 0x1}}], 0x3, 0x8040) shutdown(r0, 0x1) 1m8.861302192s ago: executing program 0 (id=3228): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00'}, 0x18) r0 = perf_event_open(&(0x7f0000000380)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x4}}, 0x0, 0x0, 0xffffffffffffffff, 0x8) mmap$perf(&(0x7f0000ffd000/0x1000)=nil, 0x1000, 0x0, 0x11, r0, 0x0) r1 = socket(0x10, 0x3, 0x0) getsockopt$sock_cred(r1, 0x1, 0x11, &(0x7f0000caaffb)={0x0, 0x0, 0x0}, &(0x7f0000cab000)=0xc) setregid(0xffffffffffffffff, r2) setgroups(0x1, &(0x7f0000000000)=[r2]) setgid(r2) r3 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$VT_RESIZEX(r3, 0x560a, &(0x7f0000000280)={0x6, 0x0, 0x1, 0x0, 0x83, 0x7}) perf_event_open(&(0x7f0000000040)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x200, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff}, 0x0, 0x0, r0, 0x3) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc9ffb}]}) r4 = syz_io_uring_setup(0x5bbd, &(0x7f00000002c0), &(0x7f0000000180), &(0x7f00000001c0)) syz_io_uring_setup(0x10278f, &(0x7f0000000240)={0x0, 0x0, 0x10}, &(0x7f0000000200), &(0x7f00000000c0)) io_uring_enter(r4, 0x1413, 0x0, 0x0, 0x0, 0x0) r5 = syz_open_procfs(0x0, &(0x7f0000000100)='fdinfo/3\x00') preadv(r5, &(0x7f0000000000)=[{&(0x7f0000000640)=""/147, 0x93}], 0x1, 0x0, 0xfff) bpf$MAP_CREATE(0x0, 0x0, 0x50) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./file2\x00', 0x404, &(0x7f0000000780)={[{@errors_remount}, {@resuid}, {@debug_want_extra_isize={'debug_want_extra_isize', 0x3d, 0x68}}, {@resgid}, {@block_validity}, {@quota}]}, 0x3, 0x42f, &(0x7f0000000940)="$eJzs289rHFUcAPDvzCat/WViqT+aVo1WMfgjadJae/CiKHhQEPRQjzFJS+y2kSaCLUGjSD1Kwbt4FPwLPOlF1JPgVe9SKJJLq6eV2Z1Jdje7aZJustX9fGCS92be8t53Z97ue/N2AuhZw9mfJGJ/RPweEQO1bGOB4dq/W8uLU38vL04lUam89VdSLXdzeXGqKFq8bl+R6YtIP0viSIt65y9fOT9ZLs9cyvNjCxfeH5u/fOW52QuT52bOzVycOH365InxF05NPN+ROLO4bg59NHf08GvvXHtj6sy1d3/+Ninib4qjQ4bXO/hkpdLh6rrrQF066etiQ9iUUq2bRn+1/w9EKVZP3kC8+mlXGwdsq0qlUnmg/eGlCvA/lkS3WwB0R/FFn81/i22Hhh53hRsv1SZAWdy38q12pC/SvEx/0/y2k4Yj4szSP19lW2zPfQgAgAbfZ+OfZ1uN/9Kovy90b76GMhgR90XEwYg4FRGHIuL+iGrZByPioU3W37xIsnb8k17fUmAblI3/XszXthrHf8XoLwZLee5ANf7+5OxseeZ4/p6MRP/uLD++Th0/vPLbF+2O1Y//si2rvxgL5u243re78TXTkwuTdxJzvRufRAz1tYo/WVkJSCLicEQMbbGO2ae/Odru2O3jX0cH1pkqX0c8VTv/S9EUfyFZf31y7J4ozxwfK66KtX759eqb7eq/o/g7IDv/e1te/yvxDyb167Xzm6/j6h+ft53TbPX635W83bDvw8mFhUvjEbuS12uNrt8/0VRuYrV8Fv/Isdb9/2CsvhNHIiK7iB+OiEci4tG87Y9FxOMRcWyd+H96+Yn3th7/9srin97U+V9N7IrmPa0TpfM/ftdQ6eBm4s/O/8lqaiTfs5HPv420a2tXMwAAAPz3pBGxP5J0dCWdpqOjtd/wH4q9aXlufuGZs3MfXJyuPSMwGP1pcadroO5+6Hg+rS/yE035E/l94y9Le6r50am58nS3g4cet69N/8/8Wep264Bt53kt6F36P/Qu/R96l/4PvatF/9/TjXYAO6/V9//HXWgHsPOa+r9lP+gh5v/Qu/R/6F36P/Sk+T1x+4fkJSTWJCK9K5ohsU2Jbn8yAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAdMa/AQAA//9QOObV") creat(&(0x7f0000000140)='./file2\x00', 0x1ad) r6 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r6, 0x0, 0x0) r7 = open(&(0x7f00000000c0)='./bus\x00', 0x66842, 0x0) pwritev2(r7, &(0x7f0000000240)=[{&(0x7f0000000000)="85", 0xffffffe4}], 0x1, 0x1400, 0x0, 0x0) quotactl$Q_GETINFO(0xffffffff80000502, &(0x7f0000000140)=@loop={'/dev/loop', 0x0}, 0x0, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0600000004000000cf00"], 0x50) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x16, 0x4, &(0x7f0000000040)=ANY=[@ANYBLOB="b4000000000000000700000000000000850000005d0000009500000000000000"], &(0x7f0000000080)='syzkaller\x00', 0x5, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) 1m8.687080991s ago: executing program 0 (id=3229): syz_mount_image$ext4(&(0x7f0000000180)='ext4\x00', &(0x7f00000001c0)='./file1\x00', 0x21885e, &(0x7f0000000440)={[{@grpquota}, {@min_batch_time={'min_batch_time', 0x3d, 0x2f}}, {@dioread_lock}]}, 0x5, 0x504, &(0x7f0000001480)="$eJzs3c9vG1kdAPCvnThx0uwmu+wBEOyW3YWCqjqJuxut9sCWE0KoEqJHkNqQuFEUO45ipzShh/TMFYlKnODIH8C5J+5cENy4lAMSPyJQg8TBaMaT1E3tJtokdhR/PtJo3ps3nu97cea9+Dn2C2BoXY2I3YgYi4h7ETGdHc9lW9xqb8l5z/ceLe3vPVrKRat155+5tDw5Fh2PSVzJrlmMiB9+N+InuVfjNrZ31har1cpmlp9t1jZmG9s7N1ZriyuVlcp6ubwwvzD3yc2Py2fW1vdqY1nqq8/+sPutnyXVmsqOdLbjLLWbXjiMkxiNiO+fR7ABGMnaMzboivC55CPi7Yh4P73/p2MkfTYBgMus1ZqO1nRnHgC47PLpHFguX8rmAqYiny+V2nN478RkvlpvNK/fr2+tL7fnymaikL+/Wq3MZXOFM1HIJfn5NP0iXz6SvxkRb0XEL8Yn0nxpqV5dHuQfPgAwxK4cGf//M94e/wGAS6446AoAAH1n/AeA4WP8B4DhY/wHgOHTHv8nBl0NAKCPvP4HgOFj/AeAofKD27eTrbWfff/18oPtrbX6gxvLlcZaqba1VFqqb26UVur1lfQ7e2rHXa9ar2/MfxRbD2e+vdFozja2d+7W6lvrzbvp93rfrRTSs3b70DIAoJe33nv651wyIn86kW7RsZZDYaA1A85bftAVAAZmZNAVAAbGal8wvE7xGt/0AFwSXZbofUmx2weEWq1W6/yqBJyza18y/w/DqmP+338Bw5Ax/w/Dy/w/DK9WK3fSNf/jpCcCABebOX6gx/v/b2f732ZvDvx4+egZT7o+bjfrXs6uggAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHABHaz/W8rWAp+KfL5UingjImaikLu/Wq3MRcSbEfGn8cJ4kp8fcJ0BgNPK/y2Xrf91bfrDqZeK3r1ymByLiJ/+6s4vHy42m5t/jBjL/Wv84HjzSXa83P/aAwDHOxin033HC/nne4+WDrZ+1ufv34mIYjv+/t5Y7B/GH43RdF+MQkRM/juX5dtyHXMXp7H7OCK+2K39uZhK50DaK58ejZ/EfqOv8fMvxc+nZe198rP4whnUBYbN06T/udXt/svH1XTf/f4vpj3U6WX9X3Kppf20D3wR/6D/G+nR/109aYyPfv+9dmri1bLHEV8ejTiIvd/R/xzEz/WI/+EJ4//lK+++36us9euIa9E9fmes2WZtY7axvXNjtba4UlmprJfLC/MLc5/c/Lg8m85Rz/YeDf7x6fU3e5Ul7Z/sEb94TPu/fsL2/+Z/9370tdfE/+YH3eLn453XxE/GxG+cMP7i5O+KvcqS+Ms92n/c83/9hPGf/XXnlWXDAYDBaWzvrC1Wq5VNCYmLn0h+ZS9ANbomPutXrLHoXvTzD9r39JGiVuv1F/yse1GvHuMsZt2Ai+Dwpo+I/w66MgAAAAAAAAAAAAAAQFf9+MTSoNsIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADA5fX/AAAA//+YXdZi") acct(0x0) r0 = fspick(0xffffffffffffff9c, &(0x7f0000000000)='.\x00', 0x0) syz_mount_image$vfat(&(0x7f00000000c0), &(0x7f0000000040)='./file2\x00', 0x10502, &(0x7f0000001b80)=ANY=[], 0x1, 0x11f3, &(0x7f0000000980)="$eJzs3E+LW1UYB+C3cWrHqfNHrdV2oQfduLo0s3AlSJApyASU2gitINw6NxpyTUJuGIiI1ZVbP4e4dCeIX2A2fgZ3s3HZhXiFpLVNTdUuOpH6PJv7kvf8cu8hEDjhnBy/8c2n/W6VdfNJNE6disYoIt1KkaIRd7y0P79eu77farf3rqR0uXW1+XpKaevlHz/4/LtXfpqcff/7rR/OxNHOh8e/7v5ydP7owvHvVz/pValXpcFwkvJ0Yzic5DfKIh30qn6W0rtlkVdF6g2qYrzQ75bD0Wia8sHB5sZoXFRVygfT1C+maTJMk/E05R/nvUHKsixtbgQPdPqfh3S+vVXXdURdn44no67r+qnYiLPxdGzGVnwZEc/Es/FcnIvn43y8EC/Ghdmok3h8AAAAAAAAAAAAAAAAAAAA+P/4u/P/27Hj/D8AAAAAAAAAAAAAAAAAAACcgPeuXd9vtdt7V1Jajyi/PuwcdubXeb/VjV6UUcSl2I7fYnb6f25eX367vXcpzezEV+XN2/mbh50nFvPN2d8J3M6vzXp38s15Pi3mz8TGvfnd2I5zy++/uzS/Hq+9ek8+i+34+aMYRhkHs3vfzX/RTOmtd9r35S/OxgEAAMDjIEt/Wrp+z7IH9ef5h/h94L719VpcXFvt3Imopp/187IsxovF+l9eUfz7ovGI3rkR/5EJKh7/YtXfTJyEux/6qp8EAAAAAAAAAACAh/GIdxGuxZKdZW+uZqoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB/sAPHAgAAAADC/K3T6NgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABgqAAD//99CzUo=") r1 = creat(&(0x7f00000000c0)='./bus\x00', 0x0) mount(&(0x7f0000000380)=@loop={'/dev/loop', 0x0}, &(0x7f0000000140)='./bus\x00', 0x0, 0x201000, 0x0) ioctl$sock_SIOCETHTOOL(r1, 0x8946, &(0x7f0000000100)={'team_slave_1\x00', &(0x7f0000000080)=@ethtool_test={0x1a, 0x1, 0x3, 0x6, [0x3e, 0x80000000, 0xf, 0x89d, 0x4, 0x3]}}) mkdir(0x0, 0x0) bpf$MAP_CREATE(0x0, 0x0, 0x48) bpf$PROG_LOAD(0x5, 0x0, 0x0) open(0x0, 0x8002, 0xa1) prlimit64(0x0, 0xe, 0x0, 0x0) sched_setscheduler(0x0, 0x1, 0x0) getpid() openat$loop_ctrl(0xffffffffffffff9c, 0x0, 0x0, 0x0) r2 = open(&(0x7f0000000540)='./bus\x00', 0x4000, 0x0) preadv2(r2, &(0x7f00000000c0)=[{&(0x7f0000001200)=""/4096, 0x1000}], 0x1, 0x0, 0x0, 0x1a) fsconfig$FSCONFIG_CMD_RECONFIGURE(r0, 0x7, 0x0, 0x0, 0x0) 1m8.33228239s ago: executing program 0 (id=3233): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r0, 0x84, 0x72, &(0x7f0000000240)={0x0, 0x0, 0x20}, 0xc) bind$inet6(r0, &(0x7f0000000000)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendto$inet6(r0, &(0x7f0000000180)="1a", 0x1, 0x0, 0x0, 0x0) 53.230316838s ago: executing program 32 (id=3233): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp6_SCTP_DEFAULT_PRINFO(r0, 0x84, 0x72, &(0x7f0000000240)={0x0, 0x0, 0x20}, 0xc) bind$inet6(r0, &(0x7f0000000000)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) sendto$inet6(r0, &(0x7f0000000180)="1a", 0x1, 0x0, 0x0, 0x0) 39.421426661s ago: executing program 3 (id=3613): socket$nl_route(0x10, 0x3, 0x0) bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="1b0000000000000000000000000004"], 0x48) syz_emit_ethernet(0x7e, &(0x7f0000000800)={@broadcast, @random="1704b45adbde", @void, {@ipv4={0x800, @icmp={{0x5, 0x4, 0x0, 0x0, 0x70, 0x0, 0x0, 0x0, 0x1, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}, @local}, @dest_unreach={0x3, 0x0, 0x0, 0x0, 0x8, 0x0, {0x15, 0x4, 0x0, 0x0, 0x0, 0x0, 0x9, 0x0, 0x89, 0x0, @loopback, @initdev={0xac, 0x1e, 0x1, 0x0}, {[@timestamp_addr={0x44, 0x3c, 0x0, 0x1, 0x0, [{@empty}, {@broadcast}, {@broadcast}, {@private}, {@multicast1}, {@multicast1}, {@dev}]}, @lsrr={0x83, 0x3}]}}}}}}}, 0x0) r0 = socket$nl_route(0x10, 0x3, 0x0) ioctl$sock_SIOCGIFINDEX(r0, 0x8933, &(0x7f0000000200)={'dummy0\x00', 0x0}) r2 = bpf$PROG_LOAD(0x5, &(0x7f0000000480)={0x11, 0xf, &(0x7f00000000c0)=ANY=[@ANYBLOB="1800000000000016000000000000000018110000", @ANYRES64=r1, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000083000000bf0900000000000055090100000000009500000000000000bf91000000000000b7020000000000008500000085000000b70000000000000095"], &(0x7f0000000080)='syzkaller\x00', 0xfffffffe, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x28, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f0000000040)='kmem_cache_free\x00', r2}, 0x10) r3 = fcntl$dupfd(0xffffffffffffffff, 0x0, 0xffffffffffffffff) ioctl$SG_GET_REQUEST_TABLE(r3, 0x2286, 0x0) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000180)={0x1, &(0x7f0000000080)=[{0x200000000006, 0x0, 0x0, 0x7ffc0002}]}) r4 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="1801000000000000000000000000ea04850000007b00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x78) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000040)='kmem_cache_free\x00', r4}, 0x10) r5 = socket(0x10, 0x3, 0x0) connect$netlink(r5, &(0x7f0000000280)=@proc={0x10, 0x0, 0x1}, 0xc) sendmsg$nl_route_sched(r5, &(0x7f0000000080)={&(0x7f0000000000), 0xc, &(0x7f0000000040)={&(0x7f0000001500)=@newtaction={0x18, 0x31, 0x829, 0x0, 0x0, {0x0, 0x0, 0x2}, [{0x4}]}, 0x18}}, 0x0) syz_open_procfs(0x0, &(0x7f0000000400)='ns\x00') socket$netlink(0x10, 0x3, 0x0) inotify_add_watch(0xffffffffffffffff, &(0x7f0000000a40)='./file0/file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa/file0\x00', 0x200) 39.285750521s ago: executing program 3 (id=3617): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0x6, 0x4, 0xffc, 0xa, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000b2e900007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x48, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000007c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000880)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00', r2}, 0x10) sendmsg$NFT_BATCH(r0, &(0x7f000000c2c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000340)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101000000005e1affd5020000000900010073797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a30000000000900030073797a320000000014"], 0x7c}}, 0x0) sendmsg$NFT_BATCH(r0, &(0x7f0000000840)={0x0, 0x0, &(0x7f0000000000)={&(0x7f000000c300)={{0x14}, [@NFT_MSG_NEWSET={0x3c, 0x12, 0xa, 0x9, 0x0, 0x0, {0x2}, [@NFTA_SET_NAME={0x9, 0x2, 'syz0\x00'}, @NFTA_SET_KEY_TYPE={0x8}, @NFTA_SET_TABLE={0x9, 0x1, 'syz0\x00'}, @NFTA_SET_FLAGS={0x8, 0x3, 0x1, 0x0, 0x4}]}], {0x14}}, 0x64}}, 0x0) 39.11391599s ago: executing program 3 (id=3622): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="170000000000000004000000ff"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x40, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r1}, 0x10) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r2, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={0x0, 0xf8}}, 0x0) 38.987975159s ago: executing program 3 (id=3623): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="18000000008000000000000001000000940000000fad413ec50000000f00000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000000)=ANY=[@ANYBLOB="240000002100010000000000000000000a0000200000000000000000050019"], 0x24}, 0x1, 0x0, 0x0, 0x4008000}, 0x20000000) sendto$inet6(0xffffffffffffffff, &(0x7f0000000000)="9000000020", 0x5, 0x0, 0x0, 0x0) syz_mount_image$vfat(&(0x7f0000000000), &(0x7f0000002240)='./file0\x00', 0x0, &(0x7f0000000b00)=ANY=[@ANYBLOB="73686f72746e616d653d77696e6e742c666c7573682c646d61736b3d30303030303030303030303030303030303137373737372c73686f72746e616d653d77696e39352c636865636b3d7374726963742c73686f72746e616d653d6d697865642c6e6f6e756d7461696c3d302c757466383d312c73686f72746e616d653d77696e6e742c756e695f786c6174653d312c756e695f786c6174653d312c726f6469722c696f636861727365743d757466382c666d61736b3d30303030303030303030303030303030303030303030342c646d61736b3d30303030303030303030303030303030303030303030372c757466383d312c726f6469722c73686f72746e616d653d77696e39352c726f6469722c00743ccfec81d6c7d05b0f2a54ddce151ec4cbbaacb9552647fd950fedfdc024b3953e7669bc9d4f66e3beaecb80fe73633280b1d3e82023d4f5c7f5a4989406c0f0d0cf537f132dc1e63d84a17532cb78ae7a368bc0029207b9b166705972f4e8dad041e6be170bf43057b456d43f100c53b471aa6c8e3751", @ANYRES16], 0x1, 0x2b8, &(0x7f0000001080)="$eJzs3T2LY1UYAOD3JpkkuxZJYSWCF7SwWna2tckgWVhMpaRQCx3cXZAkCLsw4CgGK1sbS3+BINj5J2wEf4DgD7BzioEjN7mXZGbyMUEz48fzFJl37jnvPe85OcwHwz3z4cuT0eM8nn75+a/RbmdR60UvzrLoRi0qKaUUC72vAwD4NztLKX5Pc9dM6RUvWUS091saALAnO3///2HvJQEAe/bOu++9dTQY9N/O83Y8nHx1Mix+sy8+ztuPnsbHMY4ncT86cT7/W0D100Lx+jClNG3khW68NpmeDIvMyQc/lfc/qgY6jE50Z9HF/EeD/mE+t5Q/Leq4W47fK8Z/EJ14ccX4jwb9ByvyY9iM119dqv9edOLnj+KTGMfjWRGL/C8O8/zN9M0fn71flFfkZ9OTYWvWbyHVb+5dAQAAAAAAAAAAAAAAAAAAAADgv+5eeXZOK2bn9xSXyvN36ufFJweRV7oXz+eZ52fVjS6dDzRN8W1KrUbEoH8/z/NUdlzkN+KlRjRuZ9YAAAAAAAAAAAAAAAAAAADwz/L809PR8Xj85NmK4Je7EWua1gTVaQDVY/1bsurrmnpLV16J09Fxa/0Nl5pqZbhh0KhXfbKIjdMpJrHL3P9CcGddzd99v+sN29v7HGxan78nqHbX6DhbvYatqK60q/f0x+U+zbjmWM11TWn79lsKmiubOjvPvfnCLJhu6BPZpsLe+G2+cuWV7PIsmrNVXZl+UAZL6Zf2xk77+erXisxpHQAAAAAAAAAAAAAAAAAAsFeLh36vNN3ZklpLrb2VBQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA3avH//3cIpmXyNTo349nzW54iAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/wN/BgAA//+kKlw+") mkdirat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x0) mount$bind(&(0x7f0000000180)='.\x00', &(0x7f0000001cc0)='./file0/../file0\x00', 0x0, 0x1101088, 0x0) r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='cgroup.controllers\x00', 0x275a, 0x0) r1 = socket$xdp(0x2c, 0x3, 0x0) setsockopt$XDP_UMEM_REG(r1, 0x11b, 0x4, &(0x7f00000000c0)={0x0, 0x328000, 0x1000}, 0x20) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(0xffffffffffffffff, 0x8933, 0x0) syz_mount_image$ext4(&(0x7f0000000580)='ext4\x00', &(0x7f00000005c0)='./file0\x00', 0x1008002, &(0x7f0000000700)={[{@grpquota}, {@noload}, {@resuid}, {@max_batch_time={'max_batch_time', 0x3d, 0x3}}, {@resgid}, {@usrquota}, {@data_err_abort}, {@errors_remount}]}, 0x1, 0x5d8, &(0x7f0000001200)="$eJzs3c9vFFUcAPDvbH/QUrSFGBUP0sQYSJSWFjDEeICrIQ3+iBcvVloQKdDQGi2aUBK8mBgvxph48iD+F0rkyklPHrx4MiREDUcT18x2pnTb2ZYubacyn0+y9M17O7w33X773r6+NxtAZQ2m/9Qi9kbEdBLRn8wvlnVGVji48Lx7f39yOn0kUa+/8WcSSZaXPz/JvvZlJ/dExM8/JbGnY2W9M3NXzo9PTU1ezo6HZy9MD8/MXTl47sL42cmzkxdHXxo9dvTI0WMjh9q6rqsFeSevv/9h/2djb3/3zT/JyPe/jSVxPF7Nnrj0OjbKYAw2vifJyqK+YxtdWUk6sp+TpS9x0llig1iX/PXrioinoj864v6L1x+fvlZq44BNVU8i6kBFJeIfKiofB+Tv7Ze/D66VMioBtsLdEwsTACvjv3NhbjB6GnMDO+8lsXRaJ4mI9mbmmu2KiNu3xq6fuTV2PTZpHg4oNn8tIp4uiv+kEf8D0RMDjfivNcV/Oi44lX1N819vs/7lU8XiH7bOQvz3rBr/0SL+31kS/++2Wf/g/eR7vU3x39vuJQEAAAAAAEBl3TwRES8W/f2/trj+JwrW//RFxPENqH9w2fHKv//X7mxANUCBuyciXilc/1vLV/8OdGSpxxrrAbqSM+emJg9FxOMRcSC6dqTHI6vUcfDzPV+3KhvM1v/lj7T+29lawKwddzp3NJ8zMT47/rDXDUTcvRbxTOH632Sx/08K+v/098H0A9ax5/kbp1qVrR3/wGapfxuxv7D/v3/XimT1+3MMN8YDw/moYKVnP/7ih1b1txv/bjEBDy/t/3euHv8DydL79cysv47Dc531VmXtjv+7kzcbt5zpzvI+Gp+dvTwS0Z2c7Ehzm/JH199meBTl8ZDHSxr/B55bff6vaPzfGxHzy/7v5K/mPcW5J//t+71Ve4z/oTxp/E+sq/9ff2L0xsCPrep/sP7/SKOvP5DlmP+DBV/lYdrdnF8Qjp1FRVvdXgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4FNQiYlcktaHFdK02NBTRFxFPxM7a1KWZ2RfOXPrg4kRa1vj8/1r+Sb/9C8dJ/vn/A0uOR5cdH46I3RHxZUdv43jo9KWpibIvHgAAAAAAAAAAAAAAAAAAALaJvhb7/1N/dJTdOmDTdZbdAKA0BfH/SxntALae/h+qS/xDdYl/qC7xD9Ul/qG6xD9Ul/iH6hL/AAAAAADwSNm97+avSUTMv9zbeKS6s7KuUlsGbLZa2Q0ASuMWP1Bdlv5AdXmPDyRrlPe0PGmtM1czffohTgYAAAAAAAAAAACAytm/1/5/qCr7/6G67P+H6sr3/+8ruR3A1vMeH4g1dvIX7v9f8ywAAAAAAAAAAAAAYCPNzF05Pz41NXlZ4q3t0YytTNTr9avpT8F2ac//PJEvhd8u7VmWyPf6PdhZ5f1OAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAmv0XAAD//xYSJMU=") quotactl$Q_SETQUOTA(0xffffffff80000800, &(0x7f0000000040)=@loop={'/dev/loop', 0x0}, 0x0, &(0x7f0000000240)={0xffffffffffffffff, 0x1, 0x0, 0x0, 0x5, 0x62f, 0x5, 0xfffffffffffffff7, 0x25}) mmap(&(0x7f0000000000/0x4000)=nil, 0x4000, 0x2000002, 0x10011, r0, 0x0) ioperm(0x0, 0x8, 0x400) modify_ldt$write(0x1, &(0x7f0000000000)={0x80, 0x0, 0x400}, 0x10) r2 = socket$inet6(0x10, 0x3, 0x0) futex(0x0, 0x4, 0x80000002, 0x0, 0x0, 0x0) sendto$inet6(r2, &(0x7f0000000000)='.', 0x10a73, 0x800, 0x0, 0x22e2e083fa2f5a1) getsockopt$inet6_IPV6_XFRM_POLICY(r0, 0x29, 0x23, &(0x7f00000002c0)={{{@in6=@initdev, @in=@broadcast}}, {{@in6=@mcast1}, 0x0, @in=@loopback}}, &(0x7f0000000100)=0xe8) 38.433260547s ago: executing program 3 (id=3628): r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000480)=ANY=[@ANYBLOB="1b0000000000000000000000000004"], 0x3a) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000b00)={0x11, 0xf, &(0x7f00000004c0)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000083000000bf0900000000000055090100000000009500000000000000bf91000000000000b7020000000000008500000085000000b70000000000000095"], &(0x7f0000000080)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000340)='kfree\x00', r1}, 0x10) r2 = socket(0x2, 0x5, 0x0) sendmmsg$inet_sctp(r2, 0x0, 0x0, 0x880) sendmmsg$inet_sctp(r2, &(0x7f0000000bc0)=[{&(0x7f00000000c0)=@in={0x2, 0x0, @initdev={0xac, 0x1e, 0x0, 0x0}}, 0x10, &(0x7f00000001c0)=[{0x0, 0x2}], 0x1, &(0x7f0000000140)=ANY=[@ANYBLOB="30000000000000008400000001000000000000000c0000000000000002002b0388edb6556900"/51, @ANYRES32=0x0], 0x30}], 0x1, 0x0) 38.101786786s ago: executing program 3 (id=3639): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00'}, 0x18) r0 = perf_event_open(&(0x7f0000000380)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x4}}, 0x0, 0x0, 0xffffffffffffffff, 0x8) mmap$perf(&(0x7f0000ffd000/0x1000)=nil, 0x1000, 0x0, 0x11, r0, 0x0) r1 = socket(0x10, 0x3, 0x0) getsockopt$sock_cred(r1, 0x1, 0x11, &(0x7f0000caaffb)={0x0, 0x0, 0x0}, &(0x7f0000cab000)=0xc) setregid(0xffffffffffffffff, r2) setgroups(0x1, &(0x7f0000000000)=[r2]) setgid(r2) r3 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$VT_RESIZEX(r3, 0x560a, &(0x7f0000000280)={0x6, 0x0, 0x1, 0x0, 0x83, 0x7}) perf_event_open(&(0x7f0000000040)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x200, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff}, 0x0, 0x0, r0, 0x3) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc9ffb}]}) r4 = syz_io_uring_setup(0x5bbd, &(0x7f00000002c0), &(0x7f0000000180), &(0x7f00000001c0)) syz_io_uring_setup(0x10278f, &(0x7f0000000240)={0x0, 0x0, 0x10}, &(0x7f0000000200), &(0x7f00000000c0)) io_uring_enter(r4, 0x1413, 0x0, 0x0, 0x0, 0x0) r5 = syz_open_procfs(0x0, &(0x7f0000000100)='fdinfo/3\x00') preadv(r5, &(0x7f0000000000)=[{&(0x7f0000000640)=""/147, 0x93}], 0x1, 0x0, 0xfff) bpf$MAP_CREATE(0x0, 0x0, 0x50) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./file2\x00', 0x404, &(0x7f0000000780)={[{@errors_remount}, {@resuid}, {@debug_want_extra_isize={'debug_want_extra_isize', 0x3d, 0x68}}, {@resgid}, {@block_validity}, {@quota}]}, 0x3, 0x42f, &(0x7f0000000940)="$eJzs289rHFUcAPDvzCat/WViqT+aVo1WMfgjadJae/CiKHhQEPRQjzFJS+y2kSaCLUGjSD1Kwbt4FPwLPOlF1JPgVe9SKJJLq6eV2Z1Jdje7aZJustX9fGCS92be8t53Z97ue/N2AuhZw9mfJGJ/RPweEQO1bGOB4dq/W8uLU38vL04lUam89VdSLXdzeXGqKFq8bl+R6YtIP0viSIt65y9fOT9ZLs9cyvNjCxfeH5u/fOW52QuT52bOzVycOH365InxF05NPN+ROLO4bg59NHf08GvvXHtj6sy1d3/+Ninib4qjQ4bXO/hkpdLh6rrrQF066etiQ9iUUq2bRn+1/w9EKVZP3kC8+mlXGwdsq0qlUnmg/eGlCvA/lkS3WwB0R/FFn81/i22Hhh53hRsv1SZAWdy38q12pC/SvEx/0/y2k4Yj4szSP19lW2zPfQgAgAbfZ+OfZ1uN/9Kovy90b76GMhgR90XEwYg4FRGHIuL+iGrZByPioU3W37xIsnb8k17fUmAblI3/XszXthrHf8XoLwZLee5ANf7+5OxseeZ4/p6MRP/uLD++Th0/vPLbF+2O1Y//si2rvxgL5u243re78TXTkwuTdxJzvRufRAz1tYo/WVkJSCLicEQMbbGO2ae/Odru2O3jX0cH1pkqX0c8VTv/S9EUfyFZf31y7J4ozxwfK66KtX759eqb7eq/o/g7IDv/e1te/yvxDyb167Xzm6/j6h+ft53TbPX635W83bDvw8mFhUvjEbuS12uNrt8/0VRuYrV8Fv/Isdb9/2CsvhNHIiK7iB+OiEci4tG87Y9FxOMRcWyd+H96+Yn3th7/9srin97U+V9N7IrmPa0TpfM/ftdQ6eBm4s/O/8lqaiTfs5HPv420a2tXMwAAAPz3pBGxP5J0dCWdpqOjtd/wH4q9aXlufuGZs3MfXJyuPSMwGP1pcadroO5+6Hg+rS/yE035E/l94y9Le6r50am58nS3g4cet69N/8/8Wep264Bt53kt6F36P/Qu/R96l/4PvatF/9/TjXYAO6/V9//HXWgHsPOa+r9lP+gh5v/Qu/R/6F36P/Sk+T1x+4fkJSTWJCK9K5ohsU2Jbn8yAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAdMa/AQAA//9QOObV") creat(&(0x7f0000000140)='./file2\x00', 0x1ad) r6 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r6, 0x0, 0x0) r7 = open(&(0x7f00000000c0)='./bus\x00', 0x66842, 0x0) pwritev2(r7, &(0x7f0000000240)=[{&(0x7f0000000000)="85", 0xffffffe4}], 0x1, 0x1400, 0x0, 0x0) quotactl$Q_GETINFO(0xffffffff80000502, &(0x7f0000000140)=@loop={'/dev/loop', 0x0}, 0x0, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0600000004000000cf00000007"], 0x50) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x16, 0x4, &(0x7f0000000040)=ANY=[@ANYBLOB="b4000000000000000700000000000000850000005d0000009500000000000000"], 0x0, 0x5, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 38.063062686s ago: executing program 33 (id=3639): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00'}, 0x18) r0 = perf_event_open(&(0x7f0000000380)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x4}}, 0x0, 0x0, 0xffffffffffffffff, 0x8) mmap$perf(&(0x7f0000ffd000/0x1000)=nil, 0x1000, 0x0, 0x11, r0, 0x0) r1 = socket(0x10, 0x3, 0x0) getsockopt$sock_cred(r1, 0x1, 0x11, &(0x7f0000caaffb)={0x0, 0x0, 0x0}, &(0x7f0000cab000)=0xc) setregid(0xffffffffffffffff, r2) setgroups(0x1, &(0x7f0000000000)=[r2]) setgid(r2) r3 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$VT_RESIZEX(r3, 0x560a, &(0x7f0000000280)={0x6, 0x0, 0x1, 0x0, 0x83, 0x7}) perf_event_open(&(0x7f0000000040)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x200, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff}, 0x0, 0x0, r0, 0x3) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc9ffb}]}) r4 = syz_io_uring_setup(0x5bbd, &(0x7f00000002c0), &(0x7f0000000180), &(0x7f00000001c0)) syz_io_uring_setup(0x10278f, &(0x7f0000000240)={0x0, 0x0, 0x10}, &(0x7f0000000200), &(0x7f00000000c0)) io_uring_enter(r4, 0x1413, 0x0, 0x0, 0x0, 0x0) r5 = syz_open_procfs(0x0, &(0x7f0000000100)='fdinfo/3\x00') preadv(r5, &(0x7f0000000000)=[{&(0x7f0000000640)=""/147, 0x93}], 0x1, 0x0, 0xfff) bpf$MAP_CREATE(0x0, 0x0, 0x50) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./file2\x00', 0x404, &(0x7f0000000780)={[{@errors_remount}, {@resuid}, {@debug_want_extra_isize={'debug_want_extra_isize', 0x3d, 0x68}}, {@resgid}, {@block_validity}, {@quota}]}, 0x3, 0x42f, &(0x7f0000000940)="$eJzs289rHFUcAPDvzCat/WViqT+aVo1WMfgjadJae/CiKHhQEPRQjzFJS+y2kSaCLUGjSD1Kwbt4FPwLPOlF1JPgVe9SKJJLq6eV2Z1Jdje7aZJustX9fGCS92be8t53Z97ue/N2AuhZw9mfJGJ/RPweEQO1bGOB4dq/W8uLU38vL04lUam89VdSLXdzeXGqKFq8bl+R6YtIP0viSIt65y9fOT9ZLs9cyvNjCxfeH5u/fOW52QuT52bOzVycOH365InxF05NPN+ROLO4bg59NHf08GvvXHtj6sy1d3/+Ninib4qjQ4bXO/hkpdLh6rrrQF066etiQ9iUUq2bRn+1/w9EKVZP3kC8+mlXGwdsq0qlUnmg/eGlCvA/lkS3WwB0R/FFn81/i22Hhh53hRsv1SZAWdy38q12pC/SvEx/0/y2k4Yj4szSP19lW2zPfQgAgAbfZ+OfZ1uN/9Kovy90b76GMhgR90XEwYg4FRGHIuL+iGrZByPioU3W37xIsnb8k17fUmAblI3/XszXthrHf8XoLwZLee5ANf7+5OxseeZ4/p6MRP/uLD++Th0/vPLbF+2O1Y//si2rvxgL5u243re78TXTkwuTdxJzvRufRAz1tYo/WVkJSCLicEQMbbGO2ae/Odru2O3jX0cH1pkqX0c8VTv/S9EUfyFZf31y7J4ozxwfK66KtX759eqb7eq/o/g7IDv/e1te/yvxDyb167Xzm6/j6h+ft53TbPX635W83bDvw8mFhUvjEbuS12uNrt8/0VRuYrV8Fv/Isdb9/2CsvhNHIiK7iB+OiEci4tG87Y9FxOMRcWyd+H96+Yn3th7/9srin97U+V9N7IrmPa0TpfM/ftdQ6eBm4s/O/8lqaiTfs5HPv420a2tXMwAAAPz3pBGxP5J0dCWdpqOjtd/wH4q9aXlufuGZs3MfXJyuPSMwGP1pcadroO5+6Hg+rS/yE035E/l94y9Le6r50am58nS3g4cet69N/8/8Wep264Bt53kt6F36P/Qu/R96l/4PvatF/9/TjXYAO6/V9//HXWgHsPOa+r9lP+gh5v/Qu/R/6F36P/Sk+T1x+4fkJSTWJCK9K5ohsU2Jbn8yAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAdMa/AQAA//9QOObV") creat(&(0x7f0000000140)='./file2\x00', 0x1ad) r6 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r6, 0x0, 0x0) r7 = open(&(0x7f00000000c0)='./bus\x00', 0x66842, 0x0) pwritev2(r7, &(0x7f0000000240)=[{&(0x7f0000000000)="85", 0xffffffe4}], 0x1, 0x1400, 0x0, 0x0) quotactl$Q_GETINFO(0xffffffff80000502, &(0x7f0000000140)=@loop={'/dev/loop', 0x0}, 0x0, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0600000004000000cf00000007"], 0x50) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x16, 0x4, &(0x7f0000000040)=ANY=[@ANYBLOB="b4000000000000000700000000000000850000005d0000009500000000000000"], 0x0, 0x5, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 35.216935804s ago: executing program 5 (id=3685): r0 = socket$tipc(0x1e, 0x5, 0x0) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0a00000004000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000080)={{r1}, &(0x7f0000000000), &(0x7f0000000040)}, 0x20) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x48, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r2}, 0x10) mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000050b6850000002d00000095"], &(0x7f0000000200)='GPL\x00', 0x9, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00', r3}, 0x10) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000040)={0x2, 0x4, &(0x7f0000000200)=ANY=[@ANYBLOB="180000000300000000000000feffff10850000000700000095"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x100, 0x70, '\x00', 0x0, @fallback=0x30, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f00000012c0)={r4, 0x0, 0x30, 0xe1515f8735398fb, @val=@uprobe_multi={&(0x7f0000000140)='./file0\x00', &(0x7f00000002c0)=[0x8fff5], 0x0, 0x0, 0x1f, 0x1}}, 0x3c) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./bus\x00', 0x0, &(0x7f0000000180)={[{@nodiscard}, {@acl}, {@commit={'commit', 0x3d, 0x4486}}, {@discard}, {@discard}]}, 0x64, 0x53f, &(0x7f0000000a00)="$eJzs3c9vHFcdAPDvrHcTO3FqFzhAJUqhRUkE2Y1r2lgcSpEQnCoB5R6MvbEsr72Rd93Gq4o44g9AQgiQOMGFCxJ/ABKqxIUjQqoEZxAgEIIUDhxKB83u2PWPWXsTtl7j/Xyk8bz3Zt5+37M143k7TzMBjK1nIuLliHg3TdPrETGTl5fyJXZ6S7bf2w/fWMqWJNL01b8nkeRlu5+V5OvLebXJiPjqlyK+kRyN29rurC02GvXNPF9rr9+ttbY7N1bXF1fqK/WN+fm5FxduLbywcPPkTlSOFl08lL8SES994c/f+/ZPvvjSLz79+h9u//XaN7NmTefb9/fjEZWP25jkDZw8VGHzMYOdReX9f4Kpoj0mjpQ8eJ/bBABAsewa/wMR8YmIuB4zMXH85eyewfYCAAAAzoL0c9PxThKRFrvQpxwAAAD4PxLdObBJqZrPBZiOUqla7c3h/VBcKjWarfan7jS3NpZ7c2Vno1K6s9qo38znCs9GJcnyc930e/nnD+XnI+LJiPjuzFQ3X11qNpZH/eUHAAAAjInLh8b//5rpjf8BAACAc2Z21A0AAAAA3nfG/wAAAHD+Gf8DAADAufblV17JlnT3/dfLr21vrTVfu7Fcb61V17eWqkvNzbvVlWZzpfvMvvWTPq/RbN79TGxs3au16612rbXdub3e3Npo31498ApsAAAA4BQ9+bE3f5dExM5np7pL5sJgVQfcDTirynupJF8XHNa/f6K3/tMpNQo4FROjbgAwMuVRNwAYmcqoGwCMXHIwe2RY0Hfyzq/z9ceH3yYAAGC4rn6k//3/0rE1d47fDJx5DmIYX+7/w/jq3v8fdCaviwU4VyquAGDs7bv/n94v2H7i/f8TpemjtwoAABim6e6SlKr513vTUSpVqxFXuq8FqCR3Vhv1mxHxRET8dqZyMcvPdWsmh+cMAwAAAAAAAAAAAAAAAAAAAAAAAAB9pGkSKQAAAHCuRZT+kvyy9yz/qzPPTR/+fuBC8u+ZyF8R+voPX/3+vcV2e3MuK//HXnn7B3n586P4BgMAAADGwiO9wP/eYqk7Tt8dxwMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADAML398I2l3eU04/7t8xExWxS/HJPd9WRUIuLSP5Mo76uXRMTEEOJPZT8+fKsgfpI1ay9kUfypIcTfeZDFL+p/N37M5r+FoviXhxAfxtmb2fnn5aLjrxTPdNfFx1854kD+cfU//8Xe+W8ij1/ZVy87/q8MGOOpt35W6xv/QcRT5eLzz278pM/559kB43/9a51Ov23pjyKuFv7/SQ7EqrXX79Za250bq+uLK/WV+sb8/NyLC7cWXli4Wbuz2qjnP+NiQYzvfPTn7x7X/0t94s+e0P/nBuz/f9669/CDvWSlKP61Zwvi/+rH+R5H45fy/32fzNPZ9qu76Z1eer+nf/qbp4/r/3Kf/hf//e/v9f/agP2//pVv/XHAXQGAU9Da7qwtNhr1zXObyEbpZ6AZ45R4Jz0TzTg5cb+ztpjeH9ZRkKZpmh1T/8PnJHEWfi3dxKjPTAAAwLC9d9H/WNUnh94gAAAAAAAAAAAAAAAAAAAAGEOn8TixwzF39lLJMB6hDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwFP8NAAD//7/83DY=") bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) llistxattr(&(0x7f0000000140)='./file1\x00', 0x0, 0x0) bind$tipc(r0, &(0x7f0000000040)=@name={0x1e, 0x2, 0x3, {{0x42, 0x2}, 0x3}}, 0x10) r5 = socket$tipc(0x1e, 0x2, 0x0) r6 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000fbff000000000000061d8500000007000000a50000002a00000095"], &(0x7f0000000400)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000580)={&(0x7f0000000640)='mm_page_free\x00', r6, 0x0, 0x2}, 0x18) r7 = syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x0) r8 = fcntl$dupfd(r7, 0x0, r7) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) perf_event_open(&(0x7f00000003c0)={0x2, 0x80, 0x3c, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3, 0x0, @perf_bp={0x0, 0x4}, 0x0, 0x3, 0xffff, 0x0, 0x0, 0xfffffffa, 0x3}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) r9 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_int(r9, 0x6, 0x17, &(0x7f0000000540)=0x400000001, 0x4) ioctl$SG_IO(r8, 0x2285, &(0x7f0000000040)={0x53, 0x0, 0xd, 0x0, @buffer={0x2, 0x51, &(0x7f00000000c0)=""/81}, &(0x7f0000000300)="259374c96ee387b7ef452c9737", 0x0, 0x0, 0x10004, 0x4, 0x0}) bind$tipc(r5, &(0x7f0000000080)=@nameseq={0x1e, 0x1, 0x1, {0x0, 0x4, 0x4}}, 0x10) r10 = socket$tipc(0x1e, 0x2, 0x0) bind$tipc(r10, &(0x7f0000000340)=@nameseq={0x1e, 0x1, 0x3, {0x43}}, 0x10) setsockopt$TIPC_GROUP_JOIN(r10, 0x10f, 0x87, &(0x7f0000000100)={0x43, 0x0, 0x3, 0x3}, 0x10) 35.112671423s ago: executing program 5 (id=3686): r0 = openat$autofs(0xffffffffffffff9c, 0x0, 0x0, 0x0) ioctl$AUTOFS_DEV_IOCTL_ISMOUNTPOINT(r0, 0xc0189374, &(0x7f0000000240)={{0x1, 0x1, 0x5f, 0xffffffffffffffff, {0x29}}, './file0\x00'}) 35.060724993s ago: executing program 5 (id=3687): socket$nl_netfilter(0x10, 0x3, 0xc) creat(&(0x7f0000000100)='./file0\x00', 0x0) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000000000000b703000000000000850000007000000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000080)='sys_enter\x00', r0}, 0x10) munlockall() r1 = openat$autofs(0xffffffffffffff9c, &(0x7f0000000080), 0x20280, 0x0) r2 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="16000000000000000400000001"], 0x48) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000280)={0x0, 0x0, 0x78, 0x0, 0x1, 0x5, 0x0, @void, @value}, 0x28) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r2, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f00000003c0)={{r2}, 0x0, &(0x7f0000000040)}, 0x20) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000280)='kmem_cache_free\x00', r3}, 0x10) ioctl$AUTOFS_DEV_IOCTL_ISMOUNTPOINT(r1, 0xc0189374, &(0x7f0000000240)={{0x1, 0x1, 0x1018, 0xffffffffffffffff, {0x2}}, './file0\x00'}) r4 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="1b0000000000000000000000000004"], 0x48) r5 = bpf$PROG_LOAD(0x5, &(0x7f0000000b00)={0x11, 0xf, &(0x7f0000000000)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r4, @ANYBLOB="0000000000000000b702000014fa0000b7030000000008008500000083000000bf0900000000000055090100000000009500000000000000bf91000000000000b7020000000000008500000084000000b70000000020000095"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00', r5}, 0x10) socket$nl_route(0x10, 0x3, 0x0) r6 = socket(0x22, 0x803, 0x0) r7 = socket$inet6_tcp(0xa, 0x1, 0x0) getsockname$packet(r6, &(0x7f0000000200), &(0x7f0000000240)=0x14) r8 = dup(r7) setsockopt$IPT_SO_SET_REPLACE(r8, 0x4000000000000, 0x4, 0x0, 0x0) openat2(r8, &(0x7f00000000c0)='./file0\x00', &(0x7f0000000140)={0x53a6c0dd0491a5f3, 0x102, 0x4}, 0x18) r9 = socket$inet6(0xa, 0x1, 0x0) setsockopt$inet6_int(r9, 0x29, 0xb, &(0x7f0000000040)=0x9eb9, 0x4) bind$inet6(r9, &(0x7f0000f65000)={0xa, 0x4e20, 0xfffffffc, @empty, 0x3}, 0x1c) sendto$inet6(r9, 0x0, 0x0, 0xfffffefffbfbbfbe, &(0x7f0000000100)={0xa, 0x4e20, 0x0, @empty, 0x6}, 0x1c) getsockopt$inet6_buf(r9, 0x29, 0x6, 0x0, &(0x7f0000000080)) r10 = openat$ttyS3(0xffffffffffffff9c, &(0x7f0000001600), 0x0, 0x0) ioctl$TCSBRKP(r10, 0x5425, 0x0) 34.412772001s ago: executing program 5 (id=3694): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="18000000008000000000000001000000940000000fad413ec50000000f00000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) sendmsg$nl_route(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000280)={&(0x7f0000000000)=ANY=[@ANYBLOB="240000002100010000000000000000000a0000200000000000000000050019"], 0x24}, 0x1, 0x0, 0x0, 0x4008000}, 0x20000000) sendto$inet6(0xffffffffffffffff, &(0x7f0000000000)="9000000020", 0x5, 0x0, 0x0, 0x0) syz_mount_image$vfat(&(0x7f0000000000), &(0x7f0000002240)='./file0\x00', 0x0, &(0x7f0000000b00)=ANY=[@ANYBLOB="73686f72746e616d653d77696e6e742c666c7573682c646d61736b3d30303030303030303030303030303030303137373737372c73686f72746e616d653d77696e39352c636865636b3d7374726963742c73686f72746e616d653d6d697865642c6e6f6e756d7461696c3d302c757466383d312c73686f72746e616d653d77696e6e742c756e695f786c6174653d312c756e695f786c6174653d312c726f6469722c696f636861727365743d757466382c666d61736b3d30303030303030303030303030303030303030303030342c646d61736b3d30303030303030303030303030303030303030303030372c757466383d312c726f6469722c73686f72746e616d653d77696e39352c726f6469722c00743ccfec81d6c7d05b0f2a54ddce151ec4cbbaacb9552647fd950fedfdc024b3953e7669bc9d4f66e3beaecb80fe73633280b1d3e82023d4f5c7f5a4989406c0f0d0cf537f132dc1e63d84a17532cb78ae7a368bc0029207b9b166705972f4e8dad041e6be170bf43057b456d43f100c53b471aa6c8e3751", @ANYRES16], 0x1, 0x2b8, &(0x7f0000001080)="$eJzs3T2LY1UYAOD3JpkkuxZJYSWCF7SwWna2tckgWVhMpaRQCx3cXZAkCLsw4CgGK1sbS3+BINj5J2wEf4DgD7BzioEjN7mXZGbyMUEz48fzFJl37jnvPe85OcwHwz3z4cuT0eM8nn75+a/RbmdR60UvzrLoRi0qKaUUC72vAwD4NztLKX5Pc9dM6RUvWUS091saALAnO3///2HvJQEAe/bOu++9dTQY9N/O83Y8nHx1Mix+sy8+ztuPnsbHMY4ncT86cT7/W0D100Lx+jClNG3khW68NpmeDIvMyQc/lfc/qgY6jE50Z9HF/EeD/mE+t5Q/Leq4W47fK8Z/EJ14ccX4jwb9ByvyY9iM119dqv9edOLnj+KTGMfjWRGL/C8O8/zN9M0fn71flFfkZ9OTYWvWbyHVb+5dAQAAAAAAAAAAAAAAAAAAAADgv+5eeXZOK2bn9xSXyvN36ufFJweRV7oXz+eZ52fVjS6dDzRN8W1KrUbEoH8/z/NUdlzkN+KlRjRuZ9YAAAAAAAAAAAAAAAAAAADwz/L809PR8Xj85NmK4Je7EWua1gTVaQDVY/1bsurrmnpLV16J09Fxa/0Nl5pqZbhh0KhXfbKIjdMpJrHL3P9CcGddzd99v+sN29v7HGxan78nqHbX6DhbvYatqK60q/f0x+U+zbjmWM11TWn79lsKmiubOjvPvfnCLJhu6BPZpsLe+G2+cuWV7PIsmrNVXZl+UAZL6Zf2xk77+erXisxpHQAAAAAAAAAAAAAAAAAAsFeLh36vNN3ZklpLrb2VBQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA3avH//3cIpmXyNTo349nzW54iAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/wN/BgAA//+kKlw+") mkdirat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x0) mount$bind(&(0x7f0000000180)='.\x00', &(0x7f0000001cc0)='./file0/../file0\x00', 0x0, 0x1101088, 0x0) r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='cgroup.controllers\x00', 0x275a, 0x0) r1 = socket$xdp(0x2c, 0x3, 0x0) setsockopt$XDP_UMEM_REG(r1, 0x11b, 0x4, &(0x7f00000000c0)={0x0, 0x328000, 0x1000}, 0x20) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(0xffffffffffffffff, 0x8933, 0x0) syz_mount_image$ext4(&(0x7f0000000580)='ext4\x00', &(0x7f00000005c0)='./file0\x00', 0x1008002, &(0x7f0000000700)={[{@grpquota}, {@noload}, {@resuid}, {@max_batch_time={'max_batch_time', 0x3d, 0x3}}, {@resgid}, {@usrquota}, {@data_err_abort}, {@errors_remount}]}, 0x1, 0x5d8, &(0x7f0000001200)="$eJzs3c9vFFUcAPDvbH/QUrSFGBUP0sQYSJSWFjDEeICrIQ3+iBcvVloQKdDQGi2aUBK8mBgvxph48iD+F0rkyklPHrx4MiREDUcT18x2pnTb2ZYubacyn0+y9M17O7w33X773r6+NxtAZQ2m/9Qi9kbEdBLRn8wvlnVGVji48Lx7f39yOn0kUa+/8WcSSZaXPz/JvvZlJ/dExM8/JbGnY2W9M3NXzo9PTU1ezo6HZy9MD8/MXTl47sL42cmzkxdHXxo9dvTI0WMjh9q6rqsFeSevv/9h/2djb3/3zT/JyPe/jSVxPF7Nnrj0OjbKYAw2vifJyqK+YxtdWUk6sp+TpS9x0llig1iX/PXrioinoj864v6L1x+fvlZq44BNVU8i6kBFJeIfKiofB+Tv7Ze/D66VMioBtsLdEwsTACvjv3NhbjB6GnMDO+8lsXRaJ4mI9mbmmu2KiNu3xq6fuTV2PTZpHg4oNn8tIp4uiv+kEf8D0RMDjfivNcV/Oi44lX1N819vs/7lU8XiH7bOQvz3rBr/0SL+31kS/++2Wf/g/eR7vU3x39vuJQEAAAAAAEBl3TwRES8W/f2/trj+JwrW//RFxPENqH9w2fHKv//X7mxANUCBuyciXilc/1vLV/8OdGSpxxrrAbqSM+emJg9FxOMRcSC6dqTHI6vUcfDzPV+3KhvM1v/lj7T+29lawKwddzp3NJ8zMT47/rDXDUTcvRbxTOH632Sx/08K+v/098H0A9ax5/kbp1qVrR3/wGapfxuxv7D/v3/XimT1+3MMN8YDw/moYKVnP/7ih1b1txv/bjEBDy/t/3euHv8DydL79cysv47Dc531VmXtjv+7kzcbt5zpzvI+Gp+dvTwS0Z2c7Ehzm/JH199meBTl8ZDHSxr/B55bff6vaPzfGxHzy/7v5K/mPcW5J//t+71Ve4z/oTxp/E+sq/9ff2L0xsCPrep/sP7/SKOvP5DlmP+DBV/lYdrdnF8Qjp1FRVvdXgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4FNQiYlcktaHFdK02NBTRFxFPxM7a1KWZ2RfOXPrg4kRa1vj8/1r+Sb/9C8dJ/vn/A0uOR5cdH46I3RHxZUdv43jo9KWpibIvHgAAAAAAAAAAAAAAAAAAALaJvhb7/1N/dJTdOmDTdZbdAKA0BfH/SxntALae/h+qS/xDdYl/qC7xD9Ul/qG6xD9Ul/iH6hL/AAAAAADwSNm97+avSUTMv9zbeKS6s7KuUlsGbLZa2Q0ASuMWP1Bdlv5AdXmPDyRrlPe0PGmtM1czffohTgYAAAAAAAAAAACAytm/1/5/qCr7/6G67P+H6sr3/+8ruR3A1vMeH4g1dvIX7v9f8ywAAAAAAAAAAAAAYCPNzF05Pz41NXlZ4q3t0YytTNTr9avpT8F2ac//PJEvhd8u7VmWyPf6PdhZ5f1OAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAmv0XAAD//xYSJMU=") quotactl$Q_SETQUOTA(0xffffffff80000800, &(0x7f0000000040)=@loop={'/dev/loop', 0x0}, 0x0, &(0x7f0000000240)={0xffffffffffffffff, 0x1, 0x0, 0x0, 0x5, 0x62f, 0x5, 0xfffffffffffffff7, 0x25}) mmap(&(0x7f0000000000/0x4000)=nil, 0x4000, 0x2000002, 0x10011, r0, 0x0) ioperm(0x0, 0x8, 0x400) modify_ldt$write(0x1, &(0x7f0000000000)={0x80, 0x0, 0x400}, 0x10) r2 = socket$inet6(0x10, 0x3, 0x0) futex(0x0, 0x4, 0x80000002, 0x0, 0x0, 0x0) sendto$inet6(r2, &(0x7f0000000000)='.', 0x10a73, 0x800, 0x0, 0x22e2e083fa2f5a1) getsockopt$inet6_IPV6_XFRM_POLICY(r0, 0x29, 0x23, &(0x7f00000002c0)={{{@in6=@initdev, @in=@broadcast}}, {{@in6=@mcast1}, 0x0, @in=@loopback}}, &(0x7f0000000100)=0xe8) 34.15637173s ago: executing program 5 (id=3696): r0 = socket$tipc(0x1e, 0x5, 0x0) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0a00000004000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000080)={{r1}, &(0x7f0000000000), &(0x7f0000000040)}, 0x20) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x48, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r2}, 0x10) mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000050b6850000002d00000095"], &(0x7f0000000200)='GPL\x00', 0x9, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00', r3}, 0x10) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000040)={0x2, 0x4, &(0x7f0000000200)=ANY=[@ANYBLOB="180000000300000000000000feffff10850000000700000095"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x100, 0x70, '\x00', 0x0, @fallback=0x30, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f00000012c0)={r4, 0x0, 0x30, 0xe1515f8735398fb, @val=@uprobe_multi={&(0x7f0000000140)='./file0\x00', &(0x7f00000002c0)=[0x8fff5], 0x0, 0x0, 0x1f, 0x1}}, 0x3c) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./bus\x00', 0x0, &(0x7f0000000180)={[{@nodiscard}, {@acl}, {@commit={'commit', 0x3d, 0x4486}}, {@discard}, {@discard}]}, 0x64, 0x53f, &(0x7f0000000a00)="$eJzs3c9vHFcdAPDvrHcTO3FqFzhAJUqhRUkE2Y1r2lgcSpEQnCoB5R6MvbEsr72Rd93Gq4o44g9AQgiQOMGFCxJ/ABKqxIUjQqoEZxAgEIIUDhxKB83u2PWPWXsTtl7j/Xyk8bz3Zt5+37M143k7TzMBjK1nIuLliHg3TdPrETGTl5fyJXZ6S7bf2w/fWMqWJNL01b8nkeRlu5+V5OvLebXJiPjqlyK+kRyN29rurC02GvXNPF9rr9+ttbY7N1bXF1fqK/WN+fm5FxduLbywcPPkTlSOFl08lL8SES994c/f+/ZPvvjSLz79+h9u//XaN7NmTefb9/fjEZWP25jkDZw8VGHzMYOdReX9f4Kpoj0mjpQ8eJ/bBABAsewa/wMR8YmIuB4zMXH85eyewfYCAAAAzoL0c9PxThKRFrvQpxwAAAD4PxLdObBJqZrPBZiOUqla7c3h/VBcKjWarfan7jS3NpZ7c2Vno1K6s9qo38znCs9GJcnyc930e/nnD+XnI+LJiPjuzFQ3X11qNpZH/eUHAAAAjInLh8b//5rpjf8BAACAc2Z21A0AAAAA3nfG/wAAAHD+Gf8DAADAufblV17JlnT3/dfLr21vrTVfu7Fcb61V17eWqkvNzbvVlWZzpfvMvvWTPq/RbN79TGxs3au16612rbXdub3e3Npo31498ApsAAAA4BQ9+bE3f5dExM5np7pL5sJgVQfcDTirynupJF8XHNa/f6K3/tMpNQo4FROjbgAwMuVRNwAYmcqoGwCMXHIwe2RY0Hfyzq/z9ceH3yYAAGC4rn6k//3/0rE1d47fDJx5DmIYX+7/w/jq3v8fdCaviwU4VyquAGDs7bv/n94v2H7i/f8TpemjtwoAABim6e6SlKr513vTUSpVqxFXuq8FqCR3Vhv1mxHxRET8dqZyMcvPdWsmh+cMAwAAAAAAAAAAAAAAAAAAAAAAAAB9pGkSKQAAAHCuRZT+kvyy9yz/qzPPTR/+fuBC8u+ZyF8R+voPX/3+vcV2e3MuK//HXnn7B3n586P4BgMAAADGwiO9wP/eYqk7Tt8dxwMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADAML398I2l3eU04/7t8xExWxS/HJPd9WRUIuLSP5Mo76uXRMTEEOJPZT8+fKsgfpI1ay9kUfypIcTfeZDFL+p/N37M5r+FoviXhxAfxtmb2fnn5aLjrxTPdNfFx1854kD+cfU//8Xe+W8ij1/ZVy87/q8MGOOpt35W6xv/QcRT5eLzz278pM/559kB43/9a51Ov23pjyKuFv7/SQ7EqrXX79Za250bq+uLK/WV+sb8/NyLC7cWXli4Wbuz2qjnP+NiQYzvfPTn7x7X/0t94s+e0P/nBuz/f9669/CDvWSlKP61Zwvi/+rH+R5H45fy/32fzNPZ9qu76Z1eer+nf/qbp4/r/3Kf/hf//e/v9f/agP2//pVv/XHAXQGAU9Da7qwtNhr1zXObyEbpZ6AZ45R4Jz0TzTg5cb+ztpjeH9ZRkKZpmh1T/8PnJHEWfi3dxKjPTAAAwLC9d9H/WNUnh94gAAAAAAAAAAAAAAAAAAAAGEOn8TixwzF39lLJMB6hDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwFP8NAAD//7/83DY=") bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) llistxattr(&(0x7f0000000140)='./file1\x00', 0x0, 0x0) bind$tipc(r0, &(0x7f0000000040)=@name={0x1e, 0x2, 0x3, {{0x42, 0x2}, 0x3}}, 0x10) r5 = socket$tipc(0x1e, 0x2, 0x0) r6 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000fbff000000000000061d8500000007000000a50000002a00000095"], &(0x7f0000000400)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000580)={&(0x7f0000000640)='mm_page_free\x00', r6, 0x0, 0x2}, 0x18) r7 = syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x0) r8 = fcntl$dupfd(r7, 0x0, r7) bind$bt_hci(0xffffffffffffffff, 0x0, 0x0) perf_event_open(&(0x7f00000003c0)={0x2, 0x80, 0x3c, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3, 0x0, @perf_bp={0x0, 0x4}, 0x0, 0x3, 0xffff, 0x0, 0x0, 0xfffffffa, 0x3}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) r9 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_int(r9, 0x6, 0x17, &(0x7f0000000540)=0x400000001, 0x4) ioctl$SG_IO(r8, 0x2285, &(0x7f0000000040)={0x53, 0x0, 0xd, 0x0, @buffer={0x2, 0x51, &(0x7f00000000c0)=""/81}, &(0x7f0000000300)="259374c96ee387b7ef452c9737", 0x0, 0x0, 0x10004, 0x4, 0x0}) bind$tipc(r5, &(0x7f0000000080)=@nameseq={0x1e, 0x1, 0x1, {0x0, 0x4, 0x4}}, 0x10) r10 = socket$tipc(0x1e, 0x2, 0x0) bind$tipc(r10, &(0x7f0000000340)=@nameseq={0x1e, 0x1, 0x3, {0x43}}, 0x10) setsockopt$TIPC_GROUP_JOIN(r10, 0x10f, 0x87, &(0x7f0000000100)={0x43, 0x0, 0x3, 0x3}, 0x10) 33.632929267s ago: executing program 5 (id=3701): mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) r0 = creat(&(0x7f00000000c0)='./file0\x00', 0xd4) r1 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=@base={0xb, 0x8, 0x10001, 0x9, 0x1, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) r2 = openat$selinux_attr(0xffffffffffffff9c, &(0x7f00000002c0)='/proc/thread-self/attr/sockcreate\x00', 0x2, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0xb, 0x7, 0x8, 0x8, 0x5, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x17, &(0x7f0000000300)=@ringbuf={{0x18, 0x0, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0x6}, {{0x18, 0x1, 0x1, 0x0, r0}}, {}, [@tail_call={{0x18, 0x2, 0x1, 0x0, r1}}, @btf_id={0x18, 0x0, 0x3, 0x0, 0x4}, @func={0x85, 0x0, 0x1, 0x0, 0xffffffffffffffff}], {{}, {}, {0x85, 0x0, 0x0, 0x84}}}, &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, r0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000180)='kfree\x00', r3}, 0x10) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYRESDEC, @ANYRES32, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) write$selinux_attr(r2, &(0x7f0000000100)='system_u:object_r:hugetlbfs_t:s0\x00', 0x1d) r4 = socket$inet_udp(0x2, 0x2, 0x0) r5 = syz_genetlink_get_family_id$devlink(&(0x7f0000000580), 0xffffffffffffffff) r6 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$DEVLINK_CMD_TRAP_GROUP_SET(r6, &(0x7f0000000400)={0x0, 0x0, &(0x7f00000003c0)={&(0x7f0000000300)=ANY=[@ANYBLOB='L\x00\x00\x00', @ANYRES16=r5, @ANYBLOB="011f00000089bd0000000000420000000e0001006e657464657673696d0000000f0002006e657464657673696d3000000d0087006c325f64726f70730000000008008e000000"], 0x4c}}, 0x0) bind$inet(r4, &(0x7f0000000100)={0x2, 0x0, @dev={0xac, 0x14, 0x14, 0x2a}}, 0x10) setsockopt$sock_int(r4, 0x1, 0x6, &(0x7f0000000140)=0x32, 0x4) connect$inet(r4, &(0x7f0000000280)={0x2, 0x0, @broadcast}, 0x10) sendmmsg$inet(r4, &(0x7f0000008c80)=[{{0x0, 0x0, 0x0}}], 0x1, 0x840) 33.582488587s ago: executing program 34 (id=3701): mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) r0 = creat(&(0x7f00000000c0)='./file0\x00', 0xd4) r1 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=@base={0xb, 0x8, 0x10001, 0x9, 0x1, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) r2 = openat$selinux_attr(0xffffffffffffff9c, &(0x7f00000002c0)='/proc/thread-self/attr/sockcreate\x00', 0x2, 0x0) bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0xb, 0x7, 0x8, 0x8, 0x5, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x17, &(0x7f0000000300)=@ringbuf={{0x18, 0x0, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0x6}, {{0x18, 0x1, 0x1, 0x0, r0}}, {}, [@tail_call={{0x18, 0x2, 0x1, 0x0, r1}}, @btf_id={0x18, 0x0, 0x3, 0x0, 0x4}, @func={0x85, 0x0, 0x1, 0x0, 0xffffffffffffffff}], {{}, {}, {0x85, 0x0, 0x0, 0x84}}}, &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, r0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000180)='kfree\x00', r3}, 0x10) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYRESDEC, @ANYRES32, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) write$selinux_attr(r2, &(0x7f0000000100)='system_u:object_r:hugetlbfs_t:s0\x00', 0x1d) r4 = socket$inet_udp(0x2, 0x2, 0x0) r5 = syz_genetlink_get_family_id$devlink(&(0x7f0000000580), 0xffffffffffffffff) r6 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$DEVLINK_CMD_TRAP_GROUP_SET(r6, &(0x7f0000000400)={0x0, 0x0, &(0x7f00000003c0)={&(0x7f0000000300)=ANY=[@ANYBLOB='L\x00\x00\x00', @ANYRES16=r5, @ANYBLOB="011f00000089bd0000000000420000000e0001006e657464657673696d0000000f0002006e657464657673696d3000000d0087006c325f64726f70730000000008008e000000"], 0x4c}}, 0x0) bind$inet(r4, &(0x7f0000000100)={0x2, 0x0, @dev={0xac, 0x14, 0x14, 0x2a}}, 0x10) setsockopt$sock_int(r4, 0x1, 0x6, &(0x7f0000000140)=0x32, 0x4) connect$inet(r4, &(0x7f0000000280)={0x2, 0x0, @broadcast}, 0x10) sendmmsg$inet(r4, &(0x7f0000008c80)=[{{0x0, 0x0, 0x0}}], 0x1, 0x840) 33.245373186s ago: executing program 1 (id=3709): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="170000000000000004000000ff"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x40, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r1}, 0x10) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r2, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000005c0)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a03000000000000000100070000000900010073797a300000000068000000090a010400000000000000000700000008000a40000000000900020073797a31000000000900010073797a300000000008000540"], 0xf8}}, 0x0) 33.126652275s ago: executing program 1 (id=3712): r0 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000340)={0x2, 0x4, 0x8, 0x1, 0x80, 0xffffffffffffffff, 0x7, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000480)={r0, 0xffffffffffffffff}, 0x4) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x10, &(0x7f0000000a40)=ANY=[@ANYBLOB="18000000000000000000000000000000b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb7", @ANYRES32=r1, @ANYBLOB="0000000000000000b70500000800000085000000b600000095"], &(0x7f00000007c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f0000000000)='kmem_cache_free\x00', r2}, 0x10) r3 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000240)=[{&(0x7f00000000c0)="d800000018008103e00312ba0d8105040a600300ff0f040b067c55a1bc000900b80006990700000015000500fef32702d3001500030001400200000901ac040098007f6f94007100a007a290457f0189b316277ce06bbace8017cbec4c2ee5a7cef4090000001fb791643a5ee4b11602b2a10c11ce1b14d6d930dfe1d9d322fe04000000730d7a5025ccca262f3d40fad95667e04adcdf634c1f215ce3bb9ad809d5e1cace81ed0b66bce0b42a9ecbee5de6ccd40dd6e4edef3d93452a92307f00000e970300"/216, 0xd8}], 0x1}, 0x880) 33.047136835s ago: executing program 1 (id=3713): r0 = getuid() bpf$PROG_LOAD(0x5, &(0x7f0000000200)={0x4, 0xe, &(0x7f00000014c0)=ANY=[@ANYBLOB="b702000000000000bfa30000000000000702000000feffff7a0af0fff8ffffff79a4f0ff00000000b7060000ffffffff6d6405000000000065040400010000000404000001000000b7050000400000006a0a80fe000000008500000053000000b7000000000000009500001000000000a80501363034fdb117168bd07ba00af739d1a1ee35fe163a255c33282044b32495ef8ab9adc67ccc945f105d802f5132143c0a9fc7a84452569957c1002ed7d4d8e17f791f4798c8eb483e9973320d046c3126c6afcfd84de03352c69b3edff5be26f8ffa5f8f2879021c2ea53ea79acd7fb38dd1abb75aa393cea26d465637d11f705000000473e7b7c4ae7dd5e4dee88518ddf12dddd4bfc6a4dd3b6beba51074229b0d4b504516c4c3e5d1aa044d8d00728141cd67bcd68f253288e655c6b34e02e90637ef2912ba7de26ff2357ef17f95a25780c3a057844f226ef4e912f01a201e694e3806e8c70e8b69524cd19f7525d8d66bb766f7f3f918c86a70252236800001897133af94a5a4cfc794d8b9d7c33632152c48eaf302f0b2e0c252b00000000000000006f1bbefbe08de65e3762e194ba4cae8b13535d7d11ee917bca4885bbf597a14ab2458efce78510d86272d88e0c8088f404f011289ebc5623faa1182632161e073af1d69a2e36bed435000025ecd201d2ffb0a7fa4f5d11060cdcf071defd0a8be3b69ce3e4f361aca75827426dde87fdf4617222674280f55e98107450c19b9d86329bd5b4697336112b0b8754ce3574046bf6114d1a88597850b77378fa8edfff8faf8b8ec039bab385cac0535373bb8fab90539b1a65ddff841eb671f3faf37ebdfccea0c002ad2b42047c9ec43193ccf617dbf8a12b4f189edbf9fb7c42b1f435ccd4d96822e6b70100912c92e3943e9c4f45d8bcd528fa8a3ea847f10e9b2506f3bb506f1d7fbde8010000000000a073d0de5538ab42e170b3baae34c35987b0dda497ac3f5e97e6e6aeea15c6d5ed24310100000003bb6030f84b63aaf8690db0221b1705c501f802ff59b4e683efa4b6e77e042072bd2ac37d413008ec9eb8166f6e28b49a77ed91befc65315896f88a8fb1dd679fb4c515f8b7a5b7aca6a251a89d47b728502f7e621cc0e3ba04000000c149ee6601728c750d304197c22da8650579475afd96187d881e93b42a5fdfd686d8900c44c67133dad58037fda65885a15a429edfe3027a5ebf95254744f10fd607bc3300b94932b8d944e0b083bbd86b19cb074577a25ff581d92af08a06f857310a2f14326b0b290205e91a682e00c8762cbc6b904c980eef6e6a1def886c95676dce6a8194479700a02b92bdc8d05eae1f24fdd7b80d1bb404c22f681594de2ebb9687219de8d73ac83823feb402a2415a9850d5f0183ec67be96dc0e4c2d7acf1dfe79d6771903b76e21190c22d641030e1ddacf006c3116e1803af20a5f2b5f7ba58aca5bcabbbab24414a3810788e5503e4be66d683daac5f0001000077339b4200000000108a3c87b19d5b9a00c75d84a92d6dcf00ba96edf35ede0e2b57c26e94801b498924166bde57d5f24258d9fd028096cc15a8b912b494d4bbe609031ea1ca65a548971d5d16296dd08e020000007a27310d5d01f8a8a0f5212d7f628f554afea715ccbc66cbb1016490f5d579308cb3188cf2fcaf67e0c16443d526ba4b968f07ae362c2133c168313e84beb871203880dd453c45d0a137d7f5a8b039dbfa62fb2b4214f8e69f967bf1fbd89e77fcca110000000800000000000000f8877994ebdc35f7efd41e3babd9b3782edd6776d5b6cb4ecd72c9de9b5503747d71440378cf2c2c7ea2dc5febb654a867f853713cf4c0bb322fbbe446d18dee4c821275ef18259cafc346c8b3b9fb0f3adcf6ea310a6b9a3f59e29a5909ea047fb61affb4bc8bbea1fb761b8933795b1a91358a7791aa843d07020e8bb6fc18458c49ac6313e7165b7d9f65e94a62b69f1011b94340cdb7303f01e5cdb5682ddf73d65c3de1d88dd7496d6345d5b9de0223988056a53e19a8b96b9640bc6c09d3c2ff894d626b57c776ed53f94d5e22ff148061b37f72bd92924cb1d0a725e19b264346b7cae0251a850de78316503f3c3d395c7e3f04fc8d52583327cd2341ce4b2d092815376299686f41353b2823814563011a2223b9dd00000000000000000000003a131374a3371cb3e2a9bb4d798b91cefa444501f40b7c9589e8c0bb6c82123d2b45ce905d0903b32ecf30e828c71a07a83f3275f3d661d1af0ffbd5d7f0"], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) syz_genetlink_get_family_id$ethtool(&(0x7f00000004c0), 0xffffffffffffffff) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0a00000002000000ff0f000007"], 0x48) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000400)={{r1}, &(0x7f0000000000), &(0x7f00000003c0)}, 0x20) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x7, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x41000, 0x2, '\x00', 0x0, @fallback=0xd1170707f0656889, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r2}, 0x10) syz_mount_image$msdos(&(0x7f0000000140), &(0x7f0000000040)='./file0\x00', 0x200012, &(0x7f0000000100)=ANY=[@ANYRES8=r0, @ANYRESDEC, @ANYRES32=r0], 0x1, 0x52b, &(0x7f0000001600)="$eJzs1bGKE1EUBuCz2bhGq63F4oKN1bLaWRmRLCwOCEoErQxsbDIiZJpJqn0EH8AHs/AhJNV2kWUS466WzkxIvq/J4f6ZOfdchpmPDz9PLr4Un75//Ra9/kF0+nGvc3UQx9GJtcsAAHbJ1XIZP5eVtvcCADTD9x8A9s/b9x9evciywZuUehGLy3JYDqvfKj87zwan6drRH1ctynJ4+Dt/kio38ztxf5U//Wd+FI8fVfl19vJ1diu/Gxe1Tw8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPvtJKVuRKSU0vFmdVGWw8MqP0lrt/KqOjvPBqerP9zMu/Gg29gYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwH9QzOaTUZ6PpztWRPyIhpv2Vkdae693EbFZ6a/absvJ11k8r+POzyJiWwZsuli/BjYP718RAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwb4rZfDLK8/G0aHsnAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMC2KGbzySjPx9Mai7ZnBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANrxKwAA//9LaiYQ") pwrite64(0xffffffffffffffff, &(0x7f00000000c0)='a', 0x200000c1, 0x9000) 32.919050945s ago: executing program 1 (id=3714): mkdirat(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\x00', 0x0) mount$bind(&(0x7f00000002c0)='.\x00', &(0x7f00000001c0)='./file0/../file0\x00', 0x0, 0x101091, 0x0) openat2$dir(0xffffffffffffff9c, &(0x7f0000000000)='./file0/file0\x00', &(0x7f0000000100)={0x42a00, 0x46be879dc61b3ceb, 0x5}, 0x18) r0 = openat$rtc(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) ioctl$RTC_UIE_ON(r0, 0x7003) ioctl$RTC_AIE_ON(r0, 0x7001) ioctl$RTC_SET_TIME(r0, 0x4024700a, &(0x7f0000000040)={0x0, 0x0, 0x0, 0x16, 0x0, 0xa9, 0x0, 0xf1, 0x1}) mount$bind(0x0, &(0x7f00000005c0)='./file0\x00', 0x0, 0x100000, 0x0) mount$bind(&(0x7f0000000040)='./file0/../file0\x00', &(0x7f0000000340)='./file0/file0\x00', 0x0, 0x89101a, 0x0) mount$bind(0x0, &(0x7f0000000240)='./file0/file0\x00', 0x0, 0x80000, 0x0) mount$bind(&(0x7f0000000280)='./file0\x00', &(0x7f0000000480)='./file0/../file0\x00', 0x0, 0x21adc51, 0x0) open_tree(0xffffffffffffff9c, &(0x7f0000000080)='.\x00', 0x89901) syz_mount_image$ext4(&(0x7f0000000b80)='ext4\x00', &(0x7f0000000bc0)='./file0\x00', 0x484, &(0x7f0000000480), 0x1, 0xb95, &(0x7f00000017c0)="$eJzs3M1vVFUbAPDn3n7TvrS8efO+L8TEJgYxGodCiSbEGHBt0EQXLKntlDQdPmxrYiuLgnt1YYwLEsOfYOJeXLgycYELhb+AGIkhugEXNXc+yqSdKaWd9iD8fsmZe849wzzPw4Xec5K5DeCpNVq85BH7I+JMFjFcP59HRG+11x+xXHvf/buXJouWxcrKO79nkUXEvbuXJhufldWPg/VBf0TceCOLf3+8Pu784tLsRKVSnquPDy+cu3h4fnHp5ZlzE2fLZ8vnj42/emz8lfHxDtZ6++J7Xz7z06nnr1z7ZOytL/b+kMWJGKrPNdfRKaMxuvp30qw7IiY6HSyRrno9zXVm3QkTAgBgQ3nTGu6/MRxd8WDxNhzf/5w0OQAAAKAjVroiVgAAAIAnXGb/DwAAAE+4xvcA7t29NNloab+RsLvunIyIkVr9jeebazPdsVw99kdPROz5I4vmx1qz2h/bttEi0jc/losWj/Ac8kd7b73WgfCxfDki/t/q+mfV+keqT3Gvrz+PiLEOxB9dM97tf3/bqf9EB+Knrh+Ap9P1k7Ub2fr7X766/okW97/uFveurUh9/2us/+6vW/89qL+rzfrv7U3GOPDXizfazTWv/05/emuqiF8ct1XUI7hzOeJAd6v6s9X6szb1n9lkjMHJ21fbzRX1F/U22m7Xv3It4vVTretvyDb6/USHp2cq5bHaa5sYB787fahd/ObrX7QifmMvsMbytottobj+e2Jr1//iJmOM/O+3/e3mHl5//mtv9m6111s/8+HEwsLckYje7M31549unEvjPY3PKOp/4bmN//+3qr+rdkH6or4XuFw/Fu+9sibm4MGjX2+9/p1V1D+1xev/2SZjfPXt1ffbzaWuHwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIB/hjwihiLLS6v9PC+VIgYj4j+xJ69cmF94afrCB+enirmIkejJp2cq5bGIGK6Ns2J8pNp/MD66ZjweEfsi4vPhgeq4NHmhMpW6eAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFYNRsRQZHkpIvKI+HM4z0ul1FkBAAAAHTeSOgEAAABgx9n/AwAAwJPP/h8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAdtu/Z6zeziFg+PlBthd76XE/SzICdlqdOAEimK3UCQDLdqRMAkrHHB7KHzPe3nenreC4AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPL4O7b9+M4uI5eMD1Vborc/1JM0M2Gl56gSAZLpSJwAk093m/MAu5wHsPnt8IHvIfH/bmb6O5wIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADA42uo2rK8FBF5tZ/npVLEvyJiJHqy6ZlKeSwi9kbEL8M9fcX4SOqkAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA6Lj5xaXZiUqlPKejo6Oz2kn9kwkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgBTmF5dmJyqV8tx86kwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACA1OYXl2YnKpXy3A52UtcIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEA6fwcAAP//184Irg==") 32.777206134s ago: executing program 1 (id=3719): syz_mount_image$msdos(&(0x7f0000000140), &(0x7f0000000040)='./file0\x00', 0x200012, &(0x7f0000000100)=ANY=[@ANYRES8, @ANYRESDEC, @ANYRES32], 0x1, 0x52b, &(0x7f0000001600)="$eJzs1bGKE1EUBuCz2bhGq63F4oKN1bLaWRmRLCwOCEoErQxsbDIiZJpJqn0EH8AHs/AhJNV2kWUS466WzkxIvq/J4f6ZOfdchpmPDz9PLr4Un75//Ra9/kF0+nGvc3UQx9GJtcsAAHbJ1XIZP5eVtvcCADTD9x8A9s/b9x9evciywZuUehGLy3JYDqvfKj87zwan6drRH1ctynJ4+Dt/kio38ztxf5U//Wd+FI8fVfl19vJ1diu/Gxe1Tw8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPvtJKVuRKSU0vFmdVGWw8MqP0lrt/KqOjvPBqerP9zMu/Gg29gYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwH9QzOaTUZ6PpztWRPyIhpv2Vkdae693EbFZ6a/absvJ11k8r+POzyJiWwZsuli/BjYP718RAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwb4rZfDLK8/G0aHsnAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMC2KGbzySjPx9Mai7ZnBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANrxKwAA//9LaiYQ") r0 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file1\x00', 0x42, 0x0) pwrite64(r0, &(0x7f00000000c0)='a', 0x200000c1, 0x9000) r1 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file1\x00', 0x107842, 0x42) sendfile(r1, r1, 0x0, 0x80000000) 32.546251963s ago: executing program 1 (id=3722): r0 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000340)={0x2, 0x4, 0x8, 0x1, 0x80, 0xffffffffffffffff, 0x7, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000480)={r0, 0xffffffffffffffff}, 0x4) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x10, &(0x7f0000000a40)=ANY=[@ANYBLOB="18000000000000000000000000000000b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb7020000080000", @ANYRES32=r1, @ANYBLOB="0000000000000000b70500000800000085000000b600000095"], &(0x7f00000007c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f0000000000)='kmem_cache_free\x00', r2}, 0x10) r3 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000240)=[{&(0x7f00000000c0)="d800000018008103e00312ba0d8105040a600300ff0f040b067c55a1bc000900b80006990700000015000500fef32702d3001500030001400200000901ac040098007f6f94007100a007a290457f0189b316277ce06bbace8017cbec4c2ee5a7cef4090000001fb791643a5ee4b11602b2a10c11ce1b14d6d930dfe1d9d322fe04000000730d7a5025ccca262f3d40fad95667e04adcdf634c1f215ce3bb9ad809d5e1cace81ed0b66bce0b42a9ecbee5de6ccd40dd6e4edef3d93452a92307f00000e970300"/216, 0xd8}], 0x1}, 0x880) 32.484391873s ago: executing program 35 (id=3722): r0 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000340)={0x2, 0x4, 0x8, 0x1, 0x80, 0xffffffffffffffff, 0x7, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000480)={r0, 0xffffffffffffffff}, 0x4) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x10, &(0x7f0000000a40)=ANY=[@ANYBLOB="18000000000000000000000000000000b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb7020000080000", @ANYRES32=r1, @ANYBLOB="0000000000000000b70500000800000085000000b600000095"], &(0x7f00000007c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f0000000000)='kmem_cache_free\x00', r2}, 0x10) r3 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000240)=[{&(0x7f00000000c0)="d800000018008103e00312ba0d8105040a600300ff0f040b067c55a1bc000900b80006990700000015000500fef32702d3001500030001400200000901ac040098007f6f94007100a007a290457f0189b316277ce06bbace8017cbec4c2ee5a7cef4090000001fb791643a5ee4b11602b2a10c11ce1b14d6d930dfe1d9d322fe04000000730d7a5025ccca262f3d40fad95667e04adcdf634c1f215ce3bb9ad809d5e1cace81ed0b66bce0b42a9ecbee5de6ccd40dd6e4edef3d93452a92307f00000e970300"/216, 0xd8}], 0x1}, 0x880) 2.947100422s ago: executing program 2 (id=4092): bpf$BPF_BTF_GET_NEXT_ID(0x17, &(0x7f0000000080)={0x81, 0x0}, 0x8) r1 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000200)='/proc/keys\x00', 0x0, 0x0) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0xc, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="1800000000000000000000000000000018010000", @ANYRES32, @ANYBLOB="0000000000000000b70800000000396f7b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000002400000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1a, r1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000040)='kmem_cache_free\x00', r2}, 0x10) r3 = socket$inet6(0xa, 0x3, 0xff) connect$inet6(r3, &(0x7f0000000000)={0xa, 0x0, 0x0, @mcast1, 0x5}, 0x1c) r4 = bpf$MAP_CREATE(0x0, &(0x7f0000001e80)=ANY=[@ANYBLOB="0b000000080000000c000000ffffffff01"], 0x48) bpf$MAP_UPDATE_BATCH(0x1a, &(0x7f0000000340)={0x0, 0x0, &(0x7f00000000c0), &(0x7f0000000140), 0x5, r4}, 0x38) bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xd, &(0x7f0000000240)=ANY=[@ANYBLOB="18000000000000000000000000000000850000006d00000018110000", @ANYRES32=r4, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000010b704000000000000850000000100000095"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) socket$nl_audit(0x10, 0x3, 0x9) write$binfmt_aout(r3, 0x0, 0x28) 2.862162642s ago: executing program 2 (id=4094): r0 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000340)={0x2, 0x4, 0x8, 0x1, 0x80, 0xffffffffffffffff, 0x7, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000480)={r0, 0xffffffffffffffff}, 0x4) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x10, &(0x7f0000000a40)=ANY=[@ANYRES32=r1, @ANYBLOB="0000000000000000b70500000800000085000000b600000095"], &(0x7f00000007c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000280)={&(0x7f0000000000)='kmem_cache_free\x00', r2}, 0x10) unshare(0x20020000) mkdirat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x1c0) mount$tmpfs(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f00000000c0), 0x0, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000280)='./file0/file1\x00', 0x1c0) open_tree(0xffffffffffffff9c, &(0x7f0000000100)='\x00', 0x89901) r3 = open(&(0x7f0000000000)='.\x00', 0x800, 0x0) prctl$PR_SET_SECCOMP(0x16, 0x1, 0x0) unlinkat(r3, &(0x7f0000000140)='./file0\x00', 0x200) 1.989844758s ago: executing program 2 (id=4106): bpf$BPF_BTF_GET_NEXT_ID(0x17, &(0x7f0000000080)={0x81, 0x0}, 0x8) r1 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000200)='/proc/keys\x00', 0x0, 0x0) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0xc, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="1800000000000000000000000000000018010000", @ANYRES32, @ANYBLOB="0000000000000000b70800000000396f7b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000002400000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1a, r1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000040)='kmem_cache_free\x00', r2}, 0x10) r3 = socket$inet6(0xa, 0x3, 0xff) connect$inet6(r3, &(0x7f0000000000)={0xa, 0x0, 0x0, @mcast1, 0x5}, 0x1c) r4 = bpf$MAP_CREATE(0x0, &(0x7f0000001e80)=ANY=[@ANYBLOB="0b000000080000000c000000ffffffff01"], 0x48) bpf$MAP_UPDATE_BATCH(0x1a, &(0x7f0000000340)={0x0, 0x0, &(0x7f00000000c0), &(0x7f0000000140), 0x5, r4}, 0x38) bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0xd, &(0x7f0000000240)=ANY=[@ANYBLOB="18000000000000000000000000000000850000006d00000018110000", @ANYRES32=r4, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000010b704000000000000850000000100000095"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) socket$nl_audit(0x10, 0x3, 0x9) write$binfmt_aout(r3, 0x0, 0x28) 1.958311498s ago: executing program 2 (id=4107): unshare(0x20020000) mkdirat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x1c0) mount$tmpfs(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f00000000c0), 0x0, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000280)='./file0/file1\x00', 0x1c0) open_tree(0xffffffffffffff9c, &(0x7f0000000100)='\x00', 0x89901) r0 = open(&(0x7f0000000000)='.\x00', 0x800, 0x0) prctl$PR_SET_SECCOMP(0x16, 0x1, 0x0) unlinkat(r0, 0x0, 0x200) 1.459760346s ago: executing program 6 (id=4120): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x1, 0x0, 0x7ffc1ffb}]}) bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="170000000000000004000000ff"], 0x48) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="16000000000000000400000001"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b704000000000000850000005700000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000580)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) socket$inet_sctp(0x2, 0x5, 0x84) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000000)='sched_switch\x00', r1, 0x0, 0xe}, 0x18) bpf$MAP_CREATE(0x0, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000040)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r2 = getpid() sched_setscheduler(r2, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f0000000000), 0x651, 0x0) bpf$MAP_CREATE(0x0, &(0x7f0000000300)=ANY=[@ANYBLOB="0b00000007000000010001000900000001000000", @ANYBLOB, @ANYRES32=0x0, @ANYBLOB="00000000000000000000000000000000000000000000000000000000b6f1e3c57c48e6300e2190b39cfae50783a4976751d346aa3e82b0fcce38070000008a9dfdf5d6fe2514"], 0x48) msync(&(0x7f0000952000/0x2000)=nil, 0x87abbe8d1cc6ad9, 0x6) 1.074242284s ago: executing program 2 (id=4127): bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0x11, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000006000000000000000018"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) syz_usbip_server_init(0x1) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) syz_open_dev$usbfs(&(0x7f0000000100), 0x76, 0x301) r0 = socket$inet6_tcp(0xa, 0x1, 0x0) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000008c0)=ANY=[@ANYBLOB="0a00000002000000ff0f000007"], 0x48) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) bpf$PROG_LOAD(0x5, &(0x7f00000007c0)={0x14, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @lirc_mode2=0x10, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000080)={{r1}, &(0x7f0000000000), &(0x7f0000000040)}, 0x20) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r2}, 0x10) personality(0x4100001) setsockopt$inet6_tcp_int(r0, 0x6, 0x13, &(0x7f0000000000)=0x100000001, 0x4) ppoll(&(0x7f00000001c0)=[{r0, 0x218}], 0x1, 0x0, 0x0, 0x0) 1.073720905s ago: executing program 4 (id=4128): creat(&(0x7f0000000100)='./file0\x00', 0x0) r0 = openat$autofs(0xffffffffffffff9c, &(0x7f0000000080), 0x20280, 0x0) r1 = bpf$MAP_CREATE(0x0, 0x0, 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f00000003c0)={{r1}, 0x0, &(0x7f0000000040)}, 0x20) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000280)='kmem_cache_free\x00', r2}, 0x10) ioctl$AUTOFS_DEV_IOCTL_ISMOUNTPOINT(r0, 0xc0189374, &(0x7f0000000240)={{0x1, 0x1, 0x1018, 0xffffffffffffffff, {0x2}}, './file0\x00'}) 1.021919144s ago: executing program 7 (id=4129): syz_mount_image$ext4(&(0x7f0000000200)='ext4\x00', &(0x7f0000000740)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', 0xc000, &(0x7f00000006c0), 0x2, 0x246, &(0x7f0000000ac0)="$eJzs3T9oM2UcB/DvXRJf+75BXnURxD8gIloor5vg8rooFKQUEUGFioiL0gq1xa1xcnHQWaWTSxE3q6N0KS6K4FS1Q10ELQ4WBx0iybVS24ja1Jz0Ph+43l3vee73HLnvkyyXBGisq0muJ2klmU7SSVIcb3B3tVw93F2f2l5I+v0nfiqG7ar9ylG/K0l6SR5KslUWeamdrG4+s/fLzmP3vbnSuff9zaenJnqRh/b3dh8/eG/ujY9mH1z94qsf5opcT/dP13X+ihH/axfJLf9Fsf+Jol33CPgn5l/78OtB7m9Ncs8w/52UqV68t5Zv2OrkgXf/qu/bP355+yTHCpy/fr8zeA/s9YHGKZN0U5QzSartspyZqT7Df9O6XL68tPzq9ItLK4sv1D1TAeelm+w++smlj6+cyP/3rSr/wMU1yP+T8xvfDrYPWnWPBpiIO6rVIP/Tz63dH/mHxpF/aC75h+aSf2gu+Yfmkn9oLvmHC6xztNEbeVj+obnkH5pL/qG5jucfAGiW/qW6n0AG6lL3/AMAAAAAAAAAAAAAAAAAAJy2PrW9cLRMquZn7yT7jyRpj6rfGv4ecXLj8O/ln4tBsz8UVbexPHvXmCcY0wc1P31903f11v/8znrrry0mvdeTXGu3T99/xeH9d3Y3/83xzvNjFviXihP7Dz812fon/bZRb/3ZneTTwfxzbdT8U+a24Xr0/NM9/hXLZ/TKr2OeAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgIn5PQAA//8PK23M") mmap(&(0x7f0000001000/0xc00000)=nil, 0xc00000, 0x0, 0x3032, 0xffffffffffffffff, 0x0) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000000000000b703000000000000850000007300000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000bc0)={&(0x7f0000000a80)='kfree\x00', r0}, 0x10) r1 = openat$selinux_load(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) write$selinux_load(r1, &(0x7f0000000100)={0xf97cff8c, 0x8}, 0x10) ioctl$FS_IOC_GETFSMAP(0xffffffffffffffff, 0xc0c0583b, &(0x7f0000000240)=ANY=[@ANYBLOB="000000004c90020052feffff0300010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ffffffff000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000d63a4c758775a1ee6e7f2952515a1d5d7032377a9980f0554a348501849d4cb4096524a3acb80db295966ecc19f46ae70f57b7c2d609e783930c78b0d027042271145d0b8c67852b24e084aff1775ae163ee32b3f8013b895191d9a89407b0bc248a976c7380c0f75901f0359718212a64c7304227c8c05b31df8ff69131e2ea0ba8c30adea4df216e1d1454aea9f1dc3c6696627d70e4cd34954589137655bb80fb5afbe0033d1f567ea749"]) 1.020730044s ago: executing program 4 (id=4130): socketpair(0x1, 0x1, 0x0, &(0x7f0000000000)) bpf$MAP_CREATE(0x0, &(0x7f0000000200)=@base={0x12, 0xd, 0x4, 0x2, 0x0, 0xffffffffffffffff, 0x4, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0x5d, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x0, 0x0, 0x0, 0x8}, 0x0, 0x0, 0xffffffffffffffff, 0x0) bpf$MAP_GET_NEXT_KEY(0x2, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0x11, 0xc, 0x0, &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) syz_mount_image$ext4(&(0x7f0000000000)='ext4\x00', &(0x7f00000001c0)='./bus\x00', 0x41, &(0x7f00000008c0)={[{@bsdgroups}, {@nodiscard}, {@noblock_validity}, {@grpjquota}, {@grpjquota}, {@orlov}, {@abort}, {@nombcache}, {@stripe={'stripe', 0x3d, 0x10}}]}, 0x64, 0x50a, &(0x7f0000000200)="$eJzs3VFrHFsdAPD/bHZr06Y3ueqDXvB6tZW0aHeTxrbBh1pB9Kmg1vcak00I2WRDdtM2oWiKH0AQUcEnffFF8AMIUvDFRxEK+qyoKKKtPvigncvuTtI03U227TabZn8/mMw5Z2b2f86GmZ0zc5gJYGC9FxHXI+JJmqYXImI0K89lU2y1psZ6jx/dm21MSaTpzX8mkWRl25+VZPPT2WYnI+JrX474ZvJ83NrG5tJMpVJey/Kl+vJqqbaxeXFxeWahvFBemZqavDJ9dfry9ERP2nkmIq598a8/+O7PvnTtV5+586dbfz//rUa1RrLlu9vxgvL7LWw1vdD8LnZvsPaSwY6ifLOFmeF2aww9V3L/NdcJAID2Guf4H4yIT0bEhRiNof1PZwEAAIA3UPr5kfhfEpG2d6JDOQAAAPAGyTXHwCa5YjYWYCRyuWKxNYb3w3EqV6nW6p+er66vzLXGyo5FITe/WClPZGOFx6KQNPKTzfTT/KU9+amIeDsivj863MwXZ6uVuX5f/AAAAIABcXpP//8/o63+PwAAAHDMjPW7AgAAAMBrp/8PAAAAx5/+PwAAABxrX7lxozGl2++/nru9sb5UvX1xrlxbKi6vzxZnq2urxYVqdaH5zL7lgz6vUq2ufjZW1u+W6uVavVTb2Ly1XF1fqd9afOYV2AAAAMAhevvjD/6QRMTW54abU8OJ7jbtcjXgqMrvpJJs3ma3/uNbrflfDqlSwKEY6ncFgL7J97sCQN8U+l0BoO+SA5Z3HLzz22z+id7WBwAA6L3xj3a+/5/bd8ut/RcDR56dGAaX+/8wuJr3/7sdyetkAY6VgjMAGHivfP//QGn6QhUCAAB6bqQ5JblidnlvJHK5YjHiTPO1AIVkfrFSnoiItyLi96OFDzTyk80tkwP7DAAAAAAAAAAAAAAAAAAAAAAAAABAS5omkQIAAADHWkTub8mvW8/yHx89N7L3+sCJ5L+jkb0i9M6Pb/7w7ky9vjbZKP/XTnn9R1n5pX5cwQAAAICB8EIv8N/up2/34wEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACglx4/uje7PR1m3H98ISLG2sXPx8nm/GQUIuLUv5PI79ouiYihHsQfbvz5SLv4SaNaOyHbxR/uQfyt+/vGj7HsW2gX/3QP4sMge9A4/lxvt//l4r3mvP3+l494Jv+yOh//Yuf4N9Rh/z/TZYx3Hv6i1DH+/Yh38u2PP9vxkw7xz3YZ/xtf39zstCz9ScR429+f5JlYpfryaqm2sXlxcXlmobxQXpmamrwyfXX68vREaX6xUs7+to3xvY/98sl+7T/VIf7YAe0/12X7///w7qMPtZKFdvHPn20T/zc/zdZ4Pn4u++37VJZuLB/fTm+10ru9+/Pfvbtf++c6tP+g///5Ltt/4avf+XOXqwIAh6C2sbk0U6mU145totFLPwLVkDiCiW/39APTNE0b+9QrfE4SR+FraSb6fWQCAAB67elJf79rAgAAAAAAAAAAAAAAAAAAAIPrMB4ntjfm1k4q6cUjtAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAeuL9AAAA//+GAdlV") prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f00000001c0)={0x1, &(0x7f0000000200)=[{0x200000000006, 0x0, 0x0, 0x7ffc0001}]}) epoll_create1(0x0) 989.505434ms ago: executing program 7 (id=4131): bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0900000004000000ff0f000007"], 0x48) r0 = syz_open_procfs(0x0, &(0x7f0000000080)='fdinfo/3\x00') read$eventfd(r0, &(0x7f0000000100), 0xfffffd79) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f00000001c0)={0x1, &(0x7f0000000200)=[{0x200000000006, 0x0, 0x0, 0x7ffc0001}]}) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) r1 = creat(&(0x7f0000000040)='./file0\x00', 0x81) socket$inet6_sctp(0xa, 0x5, 0x84) close(r1) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020786c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000000008500000010000000850000000700000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x38, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000600)={&(0x7f00000005c0)='sys_enter\x00', r2}, 0x10) waitid(0x0, 0x0, 0x0, 0x20000000, 0x0) socket$tipc(0x1e, 0x2, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x10, &(0x7f0000000580)=ANY=[@ANYBLOB="18000000030000000000000000000400b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb70200000800000018230000", @ANYRES32, @ANYBLOB="0000000000000000b705000008000000850000006900000095"], &(0x7f0000000600)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r3 = syz_open_procfs(0x0, &(0x7f0000000340)='attr/sockcreate\x00') pread64(r3, 0x0, 0x0, 0x73) 914.261054ms ago: executing program 7 (id=4132): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="170000000000000004000000"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x40, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r1}, 0x10) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r2, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000005c0)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a03000000000000000100070000000900010073797a300000000068000000090a010400000000000000000700000008000a40000000000900020073797a31000000000900010073797a300000000008000540000000212c0011800a0001006c696d69740000001c0002800c0002"], 0xf8}}, 0x0) 878.271274ms ago: executing program 7 (id=4133): socket$nl_netfilter(0x10, 0x3, 0xc) creat(&(0x7f0000000100)='./file0\x00', 0x0) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000000000000b703000000000000850000007000000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000200)={&(0x7f0000000080)='sys_enter\x00', r0}, 0x10) munlockall() r1 = openat$autofs(0xffffffffffffff9c, &(0x7f0000000080), 0x20280, 0x0) r2 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="16000000000000000400000001"], 0x48) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000280)={0x0, 0x0, 0x78, 0x0, 0x1, 0x5, 0x0, @void, @value}, 0x28) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r2, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f00000003c0)={{r2}, 0x0, &(0x7f0000000040)}, 0x20) r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000280)='kmem_cache_free\x00', r3}, 0x10) ioctl$AUTOFS_DEV_IOCTL_ISMOUNTPOINT(r1, 0xc0189374, &(0x7f0000000240)={{0x1, 0x1, 0x1018, 0xffffffffffffffff, {0x2}}, './file0\x00'}) r4 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="1b0000000000000000000000000004"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000b00)={0x11, 0xf, &(0x7f0000000000)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r4, @ANYBLOB="0000000000000000b702000014fa0000b7030000000008008500000083000000bf0900000000000055090100000000009500000000000000bf91000000000000b7020000000000008500000084000000b70000000020000095"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) r5 = socket(0x22, 0x803, 0x0) getsockname$packet(r5, &(0x7f0000000200), &(0x7f0000000240)=0x14) dup(0xffffffffffffffff) r6 = socket$inet6(0xa, 0x1, 0x0) setsockopt$inet6_int(r6, 0x29, 0xb, &(0x7f0000000040)=0x9eb9, 0x4) bind$inet6(r6, &(0x7f0000f65000)={0xa, 0x4e20, 0xfffffffc, @empty, 0x3}, 0x1c) sendto$inet6(r6, 0x0, 0x0, 0xfffffefffbfbbfbe, &(0x7f0000000100)={0xa, 0x4e20, 0x0, @empty, 0x6}, 0x1c) 850.420503ms ago: executing program 7 (id=4134): r0 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$ifreq_SIOCGIFINDEX_vcan(r0, 0x8933, 0x0) r1 = socket$can_j1939(0x1d, 0x2, 0x7) bind$can_j1939(r1, &(0x7f0000000080), 0x18) sendmsg$can_j1939(r1, &(0x7f00000001c0)={&(0x7f0000000040)={0x1d, 0x0, 0xfbfffffffffffffc, {0x0, 0x0, 0x1}, 0xff}, 0x18, &(0x7f0000000180)={0x0, 0xf0}, 0x1, 0x0, 0x0, 0x8000}, 0x200000ee) 823.295943ms ago: executing program 7 (id=4135): sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) r0 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) sched_setaffinity(0x0, 0x0, 0x0) r1 = bpf$MAP_CREATE(0x0, 0x0, 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB, @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000002010000850000004300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000040)='sched_switch\x00', r2}, 0x10) open(&(0x7f0000000080)='./bus\x00', 0x143862, 0x0) mount(&(0x7f0000000100), &(0x7f0000000280)='./bus\x00', &(0x7f00000002c0)='9p\x00', 0x0, &(0x7f0000000300)='trans=rdma,') r3 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000640)=ANY=[@ANYBLOB="18060000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000003000000b703000000000000850000007300000095"], &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000600)={&(0x7f0000000080)='sys_enter\x00', r3}, 0x10) perf_event_open(&(0x7f0000000200)={0x2, 0x80, 0x3d, 0x1, 0x0, 0x0, 0x0, 0x5, 0x62000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x100000, 0x0, 0x0, 0x6, 0x3, 0x0, 0x4}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x8) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) 822.886963ms ago: executing program 4 (id=4136): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000180)={0x1, &(0x7f0000000080)=[{0x200000000006, 0x0, 0x0, 0x7ffc0002}]}) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) inotify_add_watch(0xffffffffffffffff, 0x0, 0x200) 781.790733ms ago: executing program 4 (id=4137): syz_mount_image$ext4(&(0x7f0000000700)='ext4\x00', &(0x7f0000000080)='./file0\x00', 0x8002, &(0x7f00000000c0), 0x7, 0x4a9, &(0x7f0000000b40)="$eJzs3E9sFFUYAPBvtru0gEhFREHUIhobjS0UFA5eMJp40MSIBz02bSFIoYbWRAjRkhg8GhLvxqNXD17Vm/Fk4hUPHkwMCTFcAE9jZnem3e6flrbbLri/X7L0vZk3+963b97s23m7BNCzhrJ/koiHIuJ6ROysZZcWGKr9uXPr8sTdW5cnYj5NT/6TVMvdzvK54rjteWa4FFH6Iml4wprZi5fOjk9PT13I86Nz5z4enb146eUz58ZPT52eOj92/PjRI4ePvTr2yuqDalFfFtftfZ/N7N/71ofX3pkoF9sH8r/1cXTKUAy1akrV852urMt21KWTchcbwqpk53/WXZXq+N8ZfaHzoFekaZr2t989nza60rQFeGAl0e0WAN1RvNFnn3+LxyZNPe4LN0/UPgBlcd/JH7U95SjlZSoNn287aSgiPpj/95vsEcvdh/hzgxoAAPScn04UM8HG+V8p9tSVezhfQxmMiEciYldEPBoRuyPisYhq2ccj4onGCpKIdJn6dzfkm+c/pRvriW8l2fzvtXxta+n8r5j9xWBfntsRUUyYpw7lr8lwVPpPnZmeOrxMHT+/8ftX7fbVz/+yR1Z/MRfM23Gj3HCDbnJ8bnzNATe4eSViX7kx/qScdVyxEpBExN6I2LeK5x2sS5958bv9C5nK0nIrx1+VtlxH68BSRfptxAu1/p+PJf2/WGOy/Prk6EBMTx0azc6CQy3r+PW3q++2q3/F+H/4q/GQN4/9eHK9YS/I+n9b3fkfxfrtYvyDSUSysF47u/o6rv7xZfV5hw4271vr+b8leb+a3pJv+3R8bu7C4YgtydvN28cWjy3yRfks/uGDrcf/rvyY7JV4MiKyk/ipiHg6Ip7J234gIp6NiBahLfjl9ec+arfvHs//DZPFP9ny+rek/xfX69eQ6Dt74PrdNhePe+v/o9XUcL6l9fUvWXKJuNcGduAlBAAAgPteKarf/S+NLKRLpZGR2j2g3bGtND0zO/fSqZlPzk/WfiMwGJVScaerdj+4khT3Pwfr8mMN+SP5feOv+7ZW8yMTM9OT3Q4eetz26phPmsZ/5u++brcO2HB+8gO9a6Xxv+faJjUE2HTe/6F31Y3/+TZF5n1TBv6fvP9D72o1/j9fwzHAgyU1lqGnGf/Qu8rx3kK61NWWAJvN+z/0pPX8rn/lRNrfetdANBeOgY1pxtYWdXUlkc2sulL71rUcVfxvCm3LRGl1T9gfzbv6otMhVyJixcKn93T85E/z78p3uge/35Rx2irRlcsRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAx/0XAAD//8p53a4=") r0 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=@base={0x5, 0x1, 0xfff, 0x7, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c3000000"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r1}, 0x10) r2 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) getdents64(r2, 0x0, 0x0) lseek(r2, 0x3, 0x1) getdents64(r2, 0x0, 0x0) 708.657803ms ago: executing program 4 (id=4138): syz_read_part_table(0x5c9, &(0x7f0000000880)="$eJzs0jFoW0cYAOD/vaKoHYJFCLjQpRCTSUmKOiRQiVKMIrzYIaQhQ+dCMhQSyODBSFUyp8nULSGJDcaL6dBOhi7GMhgb5MnIq+dCvWkwr8h6XmxTCsZ13XzfoNP999/9d/wvONfS+CPLsiQisuJB7Md8JeLxF3+/+9uF+u2Jz+98c/deRBKPImLy2qPfBitJnnFw6i/5fCqfTxQr3bdr47sLpfUrm52x92lEYRC/EBGtwf7W7MjRekl8dfIn8z+yWFsZefb8SePFdO3hVmNmp5DHX918V23eH60+SIfzpfS43dkx39jJ6u+N3prbyKb+fH3xeqHT7VdW87xyctJK/Bct7mUDn2aD/n89s/PmcrvX7k9enX96o3ypt9x8ud/338/6mgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwAdgsbYy8uz5k8aL6drDrcbMzpffX6t/9lP9h1c331Wb90erD9Jh3lL679Qf696a28g+jtcXrxc6F/qV1TyvnJxOfc7W4f6/udzutfuTV+ef3ihf6i03XyY/Pz7rOwIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA50v99nZE3L0XkcR3ETGelmYH8awYUdo+mj9VHI4TxUr37dr47kJp/cpmZ+z9nTy+lEa04pP9/7/u/04fOuGj4dCKiPT03sU/81cAAAD//xmKiIU=") 623.371533ms ago: executing program 4 (id=4139): syz_mount_image$vfat(&(0x7f0000000400), &(0x7f0000000280)='./file0\x00', 0x800414, &(0x7f0000000000)=ANY=[@ANYBLOB="6e6f6e756d7461696c2c6e66732c73686f72746e616d653d6c6f7765722c757466383d312c64656275672c696f636861727365743d757466382c73686f72746e616d653d6d697865642c757466383d312c004845160000000000"], 0x1, 0x2c2, &(0x7f0000000c40)="$eJzs3dFLU28cx/GPzp+bE91+EEFB9VA3dTN0/QE1QiEaFOakugiOeVZjp03OGcYicjfRbX9EV1J33QXVZTfeRDfddydB0I0X0Yl2Nt102nQ6l75fIOe7830+nEc9yneC28qtFw/zWS+RtUrqjxj1SxWtSvE/VU1f7dhfrQfVqKILwz++nLp5+861VDo9MWXMZGr6YtIYM3rm3aMnr85+KA3PvBl9G9Zy/O7K9+TX5ePLJ1Z+TT/IeSbnmUKxZCwzWyyWrFnHNnM5L58w5oZjW55tcgXPdpv6Wac4P182VmFuJDrv2p5nrELZ5O2yKRVNyS0b676VK5hYImFGojraBtpYk1mamrJSW7b9UKuzLU+iJwy1Oum6qUrrZmapC3sCAAA9Zvv5P5j1t57/0zPBcdv5P1Sb/1+/lNqb/6XO5v9E0/zf19UvaI+rND36y/yPQ8F1U1a09vPbjPkfAAAAAAAAAAAAAAAAAAAAAIB/warvx3zfj9WP9Y+wpIik+uOD3if2xy6//5cOaLvYYw3/uBeRnOcLmYVMcAz6qaxycmRrTDH9rN4PNUE9eTU9MWaq4nrvLNbyiwuZkML1fF28Vf70/+NB3jTn/1O08fpJxXSs9fWTLfODOn+uIZ9QTJ/uqShHc9X7ej3/dNyYK9fTG/JD1XUAAAAAABwGCbNm0/P3ar+6IKLN/SC/g78PbHh+PaCT7bxEJQAAAAAA6JhXfpy3HMd2d1GEJXUQ30Hh9+37JfauCKkntrGhuCypB7bRrSIiKThjdhP/thZvK+W3sWZAUqefV6SLt9ZB/2YCAAAAsNfWh/4dhD4/28cdAQAAAAAAAAAAAAAAAAAAAAAAAAAAAABw9LT7emD19Zta9cY28YbLhfRx7e0BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgCPndwAAAP//6bYmHA==") write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000a00)=@bpf_lsm={0x1d, 0x11, &(0x7f0000000300)=@ringbuf={{0x18, 0x0, 0x0, 0x0, 0x4, 0x0, 0x0, 0x0, 0x2}, {}, {}, [@map_fd={0x18, 0x2}], {{}, {}, {0x85, 0x0, 0x0, 0x84}}}, &(0x7f0000000080)='GPL\x00', 0x1b1, 0x1000, &(0x7f00000022c0)=""/4096, 0x40f00, 0x1, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, &(0x7f00000003c0)={0x1, 0x1, 0x3, 0xc}, 0x10, 0x0, 0x0, 0x1, &(0x7f0000000540)=[0xffffffffffffffff], &(0x7f0000000700)=[{0x1, 0x3, 0x3, 0x7}], 0x10, 0xa, @void, @value}, 0x94) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000b80)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r0 = socket$inet6(0xa, 0x3, 0x8000000003c) setsockopt$IP6T_SO_SET_REPLACE(r0, 0x29, 0x40, &(0x7f00000014c0)=@raw={'raw\x00', 0x8, 0x3, 0x528, 0x0, 0xffffffff, 0xffffffff, 0xd0, 0xffffffff, 0x458, 0xffffffff, 0xffffffff, 0x458, 0xffffffff, 0x3, 0x0, {[{{@ipv6={@private0, @mcast2, [], [], 'veth0_macvtap\x00', 'dvmrp1\x00'}, 0x0, 0xa8, 0xd0}, @common=@unspec=@NFQUEUE0={0x28}}, {{@ipv6={@empty, @ipv4={'\x00', '\xff\xff', @dev}, [], [], 'wg1\x00', 'gre0\x00', {}, {}, 0x62}, 0x0, 0x358, 0x388, 0x0, {}, [@common=@inet=@hashlimit3={{0x158}, {'veth0_to_hsr\x00', {0x4, 0x8, 0x20, 0x5e1b2d47, 0xf91, 0x5, 0x4, 0x9f7, 0x18}, {0x8}}}, @common=@inet=@hashlimit3={{0x158}, {'wg1\x00', {0x3, 0x0, 0x41, 0x0, 0x0, 0x1000, 0x6, 0x3}}}]}, @common=@unspec=@CONNMARK={0x30}}], {{'\x00', 0x0, 0xa8, 0xd0}, {0x28, '\x00', 0x7}}}}, 0x588) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000480)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x1300, &(0x7f0000000000)='%', 0x0, 0xd01, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) 551.722072ms ago: executing program 6 (id=4141): syz_mount_image$ext4(&(0x7f0000000200)='ext4\x00', &(0x7f0000000740)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', 0xc000, &(0x7f00000006c0), 0x2, 0x246, &(0x7f0000000ac0)="$eJzs3T9oM2UcB/DvXRJf+75BXnURxD8gIloor5vg8rooFKQUEUGFioiL0gq1xa1xcnHQWaWTSxE3q6N0KS6K4FS1Q10ELQ4WBx0iybVS24ja1Jz0Ph+43l3vee73HLnvkyyXBGisq0muJ2klmU7SSVIcb3B3tVw93F2f2l5I+v0nfiqG7ar9ylG/K0l6SR5KslUWeamdrG4+s/fLzmP3vbnSuff9zaenJnqRh/b3dh8/eG/ujY9mH1z94qsf5opcT/dP13X+ihH/axfJLf9Fsf+Jol33CPgn5l/78OtB7m9Ncs8w/52UqV68t5Zv2OrkgXf/qu/bP355+yTHCpy/fr8zeA/s9YHGKZN0U5QzSartspyZqT7Df9O6XL68tPzq9ItLK4sv1D1TAeelm+w++smlj6+cyP/3rSr/wMU1yP+T8xvfDrYPWnWPBpiIO6rVIP/Tz63dH/mHxpF/aC75h+aSf2gu+Yfmkn9oLvmHC6xztNEbeVj+obnkH5pL/qG5jucfAGiW/qW6n0AG6lL3/AMAAAAAAAAAAAAAAAAAAJy2PrW9cLRMquZn7yT7jyRpj6rfGv4ecXLj8O/ln4tBsz8UVbexPHvXmCcY0wc1P31903f11v/8znrrry0mvdeTXGu3T99/xeH9d3Y3/83xzvNjFviXihP7Dz812fon/bZRb/3ZneTTwfxzbdT8U+a24Xr0/NM9/hXLZ/TKr2OeAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgIn5PQAA//8PK23M") mmap(&(0x7f0000001000/0xc00000)=nil, 0xc00000, 0x0, 0x3032, 0xffffffffffffffff, 0x0) r0 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000000000000b703000000000000850000007300000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000bc0)={&(0x7f0000000a80)='kfree\x00', r0}, 0x10) r1 = openat$selinux_load(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) write$selinux_load(r1, &(0x7f0000000100)={0xf97cff8c, 0x8}, 0x10) ioctl$FS_IOC_GETFSMAP(0xffffffffffffffff, 0xc0c0583b, &(0x7f0000000240)=ANY=[@ANYBLOB="000000004c90020052feffff0300010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ffffffff000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000d63a4c758775a1ee6e7f2952515a1d5d7032377a9980f0554a348501849d4cb4096524a3acb80db295966ecc19f46ae70f57b7c2d609e783930c78b0d027042271145d0b8c67852b24e084aff1775ae163ee32b3f8013b895191d9a89407b0bc248a976c7380c0f75901f0359718212a64c7304227c8c05b31df8ff69131e2ea0ba8c30adea4df216e1d1454aea9f1dc3c6696627d70e4cd34954589137655bb80fb5afbe0033d1f567ea749"]) 440.458702ms ago: executing program 8 (id=4142): bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0900000004000000ff0f000007"], 0x48) r0 = syz_open_procfs(0x0, &(0x7f0000000080)='fdinfo/3\x00') read$eventfd(r0, &(0x7f0000000100), 0xfffffd79) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f00000001c0)={0x1, &(0x7f0000000200)=[{0x200000000006, 0x0, 0x0, 0x7ffc0001}]}) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) socket$inet6_sctp(0xa, 0x5, 0x84) close(0xffffffffffffffff) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020786c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000000008500000010000000850000000700000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x38, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000600)={&(0x7f00000005c0)='sys_enter\x00', r1}, 0x10) waitid(0x0, 0x0, 0x0, 0x20000000, 0x0) r2 = socket$tipc(0x1e, 0x2, 0x0) r3 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f00000007c0)=ANY=[@ANYBLOB="02000000040000000800000001"], 0x48) r4 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x10, &(0x7f0000000580)=ANY=[@ANYBLOB="18000000030000000000000000000400b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb70200000800000018230000", @ANYRES32=r3, @ANYBLOB="0000000000000000b705000008000000850000006900000095"], &(0x7f0000000600)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00', r4}, 0x18) r5 = syz_open_procfs(0x0, &(0x7f0000000340)='attr/sockcreate\x00') pread64(r5, 0x0, 0x0, 0x73) mount$9p_fd(0x0, &(0x7f0000000180)='./file0\x00', &(0x7f00000002c0), 0x0, &(0x7f0000001540)={'trans=fd,', {}, 0x2c, {'wfdno', 0x3d, r2}}) 439.735592ms ago: executing program 2 (id=4143): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc1ffb}]}) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000000)='kfree\x00'}, 0x18) r0 = perf_event_open(&(0x7f0000000380)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x4}}, 0x0, 0x0, 0xffffffffffffffff, 0x8) mmap$perf(&(0x7f0000ffd000/0x1000)=nil, 0x1000, 0x0, 0x11, r0, 0x0) r1 = socket(0x10, 0x3, 0x0) getsockopt$sock_cred(r1, 0x1, 0x11, &(0x7f0000caaffb)={0x0, 0x0, 0x0}, &(0x7f0000cab000)=0xc) setregid(0xffffffffffffffff, r2) setgroups(0x0, &(0x7f0000000000)) setgid(r2) r3 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$VT_RESIZEX(r3, 0x560a, 0x0) perf_event_open(&(0x7f0000000040)={0x6, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x200, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff}, 0x0, 0x0, r0, 0x3) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x0, 0x7ffc9ffb}]}) r4 = syz_io_uring_setup(0x5bbd, &(0x7f00000002c0), &(0x7f0000000180), &(0x7f00000001c0)) syz_io_uring_setup(0x10278f, &(0x7f0000000240)={0x0, 0x0, 0x10}, &(0x7f0000000200), &(0x7f00000000c0)) io_uring_enter(r4, 0x1413, 0x0, 0x0, 0x0, 0x0) r5 = syz_open_procfs(0x0, &(0x7f0000000100)='fdinfo/3\x00') preadv(r5, &(0x7f0000000000)=[{&(0x7f0000000640)=""/147, 0x93}], 0x1, 0x0, 0xfff) bpf$MAP_CREATE(0x0, 0x0, 0x50) sendmsg$NFT_BATCH(0xffffffffffffffff, 0x0, 0x0) r6 = open(&(0x7f00000000c0)='./bus\x00', 0x66842, 0x0) pwritev2(r6, &(0x7f0000000240)=[{&(0x7f0000000000)="85", 0xffffffe4}], 0x1, 0x1400, 0x0, 0x0) quotactl$Q_GETINFO(0xffffffff80000502, &(0x7f0000000140)=@loop={'/dev/loop', 0x0}, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x16, 0x4, &(0x7f0000000040)=ANY=[@ANYBLOB="b4000000000000000700000000000000850000005d0000009500000000000000"], &(0x7f0000000080)='syzkaller\x00', 0x5, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @flow_dissector, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) 366.302041ms ago: executing program 8 (id=4144): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000580)=ANY=[@ANYBLOB="1600000000000000040085225cec12c69eefc765aa61", @ANYRES32, @ANYRES8, @ANYRES16=0x0, @ANYBLOB="da43e96476ba27e2712f55d34d21ed2483f3a99ef2a8b1d648311e317239856d84e8dbb8de013995df4d3d43c159b3a327223d233db5cc4fb74941f4405dce338219760eb57fa52e5ffbd4d6f27ea96e2fd9e5d89a8965d9f5adcc3ab7dbda99d9e8d3fbcec7209511852fb99cff4f168f9f3ec213033869982fed49b6283dbcd31dd6c1975d41c7384a2e726aae666e268e8dda19c2cae906ee8a5984ba71b584b5b474217b62dcbbe873a5cdc6b4d8c231619d9837ff5129df71c65b", @ANYBLOB="00000000000000000000000000000000000200000000000000000a79fa5d16160000"], 0x48) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000800)={0x18, 0x4, &(0x7f00000008c0)=ANY=[@ANYRES8=r0], &(0x7f0000000100)='GPL\x00', 0xd05, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r3 = bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000007c0)={&(0x7f0000000780)='netlink_extack\x00', r1}, 0x10) r4 = socket$netlink(0x10, 0x3, 0x0) sendmsg$nl_route(r4, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000100)=ANY=[@ANYBLOB="340000001c00070cfcffffff0000000007"], 0x34}, 0x1, 0x0, 0x0, 0xc800}, 0x0) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000300)=ANY=[@ANYRESHEX=r3, @ANYRES32=r2, @ANYBLOB="0000000000002e0e2acb4d0000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000570000009500000000000000"], 0x0, 0x0, 0xfffffffffffffe83, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000008000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) syz_mount_image$ext4(0x0, &(0x7f0000000080)='./file0\x00', 0x140020, 0x0, 0x1, 0x0, &(0x7f0000000080)) r5 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x3b, &(0x7f0000000440)=ANY=[], &(0x7f0000000280)='GPL\x00', 0x2, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x35, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000003c0)={&(0x7f0000000140)='kmem_cache_free\x00', r5}, 0x10) perf_event_open(&(0x7f0000000400)={0x8, 0x80, 0x0, 0x0, 0x0, 0x0, 0x82, 0x0, 0x0, 0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fffffff, 0x0, @perf_bp={&(0x7f0000000080)}, 0xa031, 0x0, 0x0, 0x0, 0x3}, 0x0, 0x0, 0xffffffffffffffff, 0x0) socket$nl_rdma(0x10, 0x3, 0x14) r6 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x78) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000040)={&(0x7f0000000180)='sys_enter\x00', r6}, 0x10) r7 = openat(0xffffffffffffff9c, &(0x7f0000000100)='./file1\x00', 0x40042, 0x1ff) write$binfmt_elf32(r7, &(0x7f0000000040)=ANY=[], 0x158) close(r7) execveat(0xffffffffffffff9c, &(0x7f0000000140)='./file1\x00', 0x0, 0x0, 0x0) 309.972451ms ago: executing program 6 (id=4145): r0 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$ifreq_SIOCGIFINDEX_vcan(r0, 0x8933, 0x0) r1 = socket$can_j1939(0x1d, 0x2, 0x7) bind$can_j1939(r1, &(0x7f0000000080), 0x18) sendmsg$can_j1939(r1, &(0x7f00000001c0)={&(0x7f0000000040)={0x1d, 0x0, 0xfbfffffffffffffc, {0x0, 0x0, 0x1}, 0xff}, 0x18, &(0x7f0000000180)={0x0, 0xf0}, 0x1, 0x0, 0x0, 0x8000}, 0x200000ee) 254.363921ms ago: executing program 6 (id=4146): unlinkat(0xffffffffffffffff, 0x0, 0x200) 239.352691ms ago: executing program 8 (id=4147): prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000180)={0x1, &(0x7f0000000080)=[{0x200000000006, 0x0, 0x0, 0x7ffc0002}]}) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, &(0x7f00000002c0)=ANY=[], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={0x0, r0}, 0x18) inotify_init() 155.332831ms ago: executing program 8 (id=4148): sendmmsg$sock(0xffffffffffffffff, &(0x7f0000000640)=[{{0x0, 0x0, &(0x7f0000000500)=[{&(0x7f00000001c0)="89df24f340e8e049266970a7268ed62f366b750c2a5895e2e75e5ad14002e6fedf5b1174e9aaeded262f1c83b0d4e5c77d2d8dfef2fc4357e030610a30a56b28f6", 0x41}], 0x1}}], 0x1, 0xc040091) r0 = syz_io_uring_setup(0x4300, &(0x7f0000000380)={0x0, 0x0, 0x10100, 0x0, 0xd0}, &(0x7f0000000040)=0x0, &(0x7f00000002c0)=0x0) r3 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='cpu.stat\x00', 0x275a, 0x0) syz_io_uring_submit(0x0, 0x0, 0x0) write$UHID_CREATE2(r3, &(0x7f00000001c0)=ANY=[@ANYBLOB='*'], 0x118) mmap(&(0x7f0000000000/0x3000)=nil, 0x3000, 0x5, 0x12, r3, 0x0) syz_io_uring_submit(r1, r2, &(0x7f0000000000)=@IORING_OP_RECVMSG={0xa, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0}) io_uring_enter(r0, 0x2d3e, 0x4000000, 0x0, 0x0, 0x0) 154.849211ms ago: executing program 6 (id=4149): r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000640)=ANY=[@ANYBLOB="170000000000000004000000"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r0, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x40, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r1}, 0x10) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r2, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000005c0)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a20000000000a03000000000000000100070000000900010073797a300000000068000000090a010400000000000000000700000008000a40000000000900020073797a31000000000900010073797a300000000008000540000000212c0011800a0001006c696d69740000001c0002800c0002"], 0xf8}}, 0x0) 78.90119ms ago: executing program 8 (id=4150): bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0900000004000000ff0f000007"], 0x48) r0 = syz_open_procfs(0x0, &(0x7f0000000080)='fdinfo/3\x00') read$eventfd(r0, &(0x7f0000000100), 0xfffffd79) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f00000001c0)={0x1, &(0x7f0000000200)=[{0x200000000006, 0x0, 0x0, 0x7ffc0001}]}) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) r1 = creat(&(0x7f0000000040)='./file0\x00', 0x81) socket$inet6_sctp(0xa, 0x5, 0x84) close(r1) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000000000000000000000001801000020786c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000000008500000010000000850000000700000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x38, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000600)={&(0x7f00000005c0)='sys_enter\x00', r2}, 0x10) waitid(0x0, 0x0, 0x0, 0x20000000, 0x0) r3 = syz_open_procfs(0x0, &(0x7f0000000340)='attr/sockcreate\x00') pread64(r3, 0x0, 0x0, 0x73) 77.91385ms ago: executing program 6 (id=4151): r0 = socket$tipc(0x1e, 0x5, 0x0) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0a00000004000000ff0f000007"], 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000000000000b70400000000000085000000c300000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_UPDATE_ELEM_TAIL_CALL(0x2, &(0x7f0000000080)={{r1}, &(0x7f0000000000), &(0x7f0000000040)}, 0x20) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x48, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000100)='kmem_cache_free\x00', r2}, 0x10) mknod$loop(&(0x7f0000000080)='./file0\x00', 0x100000000000600d, 0x1) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18000000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000000050b6850000002d00000095"], &(0x7f0000000200)='GPL\x00', 0x9, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r3 = bpf$PROG_LOAD(0x5, &(0x7f0000000040)={0x2, 0x4, &(0x7f0000000200)=ANY=[@ANYBLOB="180000000300000000000000feffff10850000000700000095"], &(0x7f0000000000)='GPL\x00', 0x0, 0x0, 0x0, 0x100, 0x70, '\x00', 0x0, @fallback=0x30, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f00000012c0)={r3, 0x0, 0x30, 0xe1515f8735398fb, @val=@uprobe_multi={&(0x7f0000000140)='./file0\x00', &(0x7f00000002c0)=[0x8fff5], 0x0, 0x0, 0x1f, 0x1}}, 0x3c) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f00000001c0)='./bus\x00', 0x0, &(0x7f0000000180)={[{@nodiscard}, {@acl}, {@commit={'commit', 0x3d, 0x4486}}, {@discard}, {@discard}]}, 0x64, 0x53f, &(0x7f0000000a00)="$eJzs3c9vHFcdAPDvrHcTO3FqFzhAJUqhRUkE2Y1r2lgcSpEQnCoB5R6MvbEsr72Rd93Gq4o44g9AQgiQOMGFCxJ/ABKqxIUjQqoEZxAgEIIUDhxKB83u2PWPWXsTtl7j/Xyk8bz3Zt5+37M143k7TzMBjK1nIuLliHg3TdPrETGTl5fyJXZ6S7bf2w/fWMqWJNL01b8nkeRlu5+V5OvLebXJiPjqlyK+kRyN29rurC02GvXNPF9rr9+ttbY7N1bXF1fqK/WN+fm5FxduLbywcPPkTlSOFl08lL8SES994c/f+/ZPvvjSLz79+h9u//XaN7NmTefb9/fjEZWP25jkDZw8VGHzMYOdReX9f4Kpoj0mjpQ8eJ/bBABAsewa/wMR8YmIuB4zMXH85eyewfYCAAAAzoL0c9PxThKRFrvQpxwAAAD4PxLdObBJqZrPBZiOUqla7c3h/VBcKjWarfan7jS3NpZ7c2Vno1K6s9qo38znCs9GJcnyc930e/nnD+XnI+LJiPjuzFQ3X11qNpZH/eUHAAAAjInLh8b//5rpjf8BAACAc2Z21A0AAAAA3nfG/wAAAHD+Gf8DAADAufblV17JlnT3/dfLr21vrTVfu7Fcb61V17eWqkvNzbvVlWZzpfvMvvWTPq/RbN79TGxs3au16612rbXdub3e3Npo31498ApsAAAA4BQ9+bE3f5dExM5np7pL5sJgVQfcDTirynupJF8XHNa/f6K3/tMpNQo4FROjbgAwMuVRNwAYmcqoGwCMXHIwe2RY0Hfyzq/z9ceH3yYAAGC4rn6k//3/0rE1d47fDJx5DmIYX+7/w/jq3v8fdCaviwU4VyquAGDs7bv/n94v2H7i/f8TpemjtwoAABim6e6SlKr513vTUSpVqxFXuq8FqCR3Vhv1mxHxRET8dqZyMcvPdWsmh+cMAwAAAAAAAAAAAAAAAAAAAAAAAAB9pGkSKQAAAHCuRZT+kvyy9yz/qzPPTR/+fuBC8u+ZyF8R+voPX/3+vcV2e3MuK//HXnn7B3n586P4BgMAAADGwiO9wP/eYqk7Tt8dxwMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADAML398I2l3eU04/7t8xExWxS/HJPd9WRUIuLSP5Mo76uXRMTEEOJPZT8+fKsgfpI1ay9kUfypIcTfeZDFL+p/N37M5r+FoviXhxAfxtmb2fnn5aLjrxTPdNfFx1854kD+cfU//8Xe+W8ij1/ZVy87/q8MGOOpt35W6xv/QcRT5eLzz278pM/559kB43/9a51Ov23pjyKuFv7/SQ7EqrXX79Za250bq+uLK/WV+sb8/NyLC7cWXli4Wbuz2qjnP+NiQYzvfPTn7x7X/0t94s+e0P/nBuz/f9669/CDvWSlKP61Zwvi/+rH+R5H45fy/32fzNPZ9qu76Z1eer+nf/qbp4/r/3Kf/hf//e/v9f/agP2//pVv/XHAXQGAU9Da7qwtNhr1zXObyEbpZ6AZ45R4Jz0TzTg5cb+ztpjeH9ZRkKZpmh1T/8PnJHEWfi3dxKjPTAAAwLC9d9H/WNUnh94gAAAAAAAAAAAAAAAAAAAAGEOn8TixwzF39lLJMB6hDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwFP8NAAD//7/83DY=") bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) llistxattr(&(0x7f0000000140)='./file1\x00', 0x0, 0x0) bind$tipc(r0, &(0x7f0000000040)=@name={0x1e, 0x2, 0x3, {{0x42, 0x2}, 0x3}}, 0x10) r4 = socket$tipc(0x1e, 0x2, 0x0) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="180000000000fbff000000000000061d8500000007000000a50000002a00000095"], &(0x7f0000000400)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000580)={&(0x7f0000000640)='mm_page_free\x00', r5, 0x0, 0x2}, 0x18) r6 = fcntl$dupfd(0xffffffffffffffff, 0x0, 0xffffffffffffffff) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) bind$bt_hci(0xffffffffffffffff, 0x0, 0x0) perf_event_open(&(0x7f00000003c0)={0x2, 0x80, 0x3c, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3, 0x0, @perf_bp={0x0, 0x4}, 0x0, 0x3, 0xffff, 0x0, 0x0, 0xfffffffa, 0x3}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) r7 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_tcp_int(r7, 0x6, 0x17, &(0x7f0000000540)=0x400000001, 0x4) ioctl$SG_IO(r6, 0x2285, &(0x7f0000000040)={0x53, 0x0, 0xd, 0x0, @buffer={0x2, 0x51, &(0x7f00000000c0)=""/81}, &(0x7f0000000300)="259374c96ee387b7ef452c9737", 0x0, 0x0, 0x10004, 0x4, 0x0}) bind$tipc(r4, &(0x7f0000000080)=@nameseq={0x1e, 0x1, 0x1, {0x0, 0x4, 0x4}}, 0x10) r8 = socket$tipc(0x1e, 0x2, 0x0) bind$tipc(r8, &(0x7f0000000340)=@nameseq={0x1e, 0x1, 0x3, {0x43}}, 0x10) setsockopt$TIPC_GROUP_JOIN(r8, 0x10f, 0x87, &(0x7f0000000100)={0x43, 0x0, 0x3, 0x3}, 0x10) 0s ago: executing program 8 (id=4152): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000005c0)={0x0, 0xc, &(0x7f0000000300)=ANY=[@ANYBLOB="18000000000000000000000000000000850000002a000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b70300000000000085000000b000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x4, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000500)={0x11, 0xc, &(0x7f0000000300)=ANY=[], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x41000, 0x62, '\x00', 0x0, @fallback=0x26, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000180)='kfree\x00', r0}, 0x10) r1 = bpf$MAP_CREATE(0x0, &(0x7f0000000380)=ANY=[@ANYBLOB="160000000000000004000000ff"], 0x48) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a40)={0x3, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000005900000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x42, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) r2 = bpf$PROG_LOAD(0x5, &(0x7f0000000280)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000f40)={&(0x7f0000000f00)='kfree\x00', r2}, 0x10) r3 = openat$sndseq(0xffffffffffffff9c, &(0x7f00000004c0), 0x0) ioctl$SNDRV_SEQ_IOCTL_CREATE_QUEUE(r3, 0xc08c5332, &(0x7f0000000340)={0x0, 0x0, 0x0, 'queue0\x00'}) ioctl$SNDRV_SEQ_IOCTL_SET_QUEUE_TIMER(r3, 0x40605346, &(0x7f0000000280)={0x0, 0x0, {0x2}}) r4 = fspick(0xffffffffffffff9c, &(0x7f0000000000)='.\x00', 0x0) fsconfig$FSCONFIG_CMD_RECONFIGURE(r4, 0x7, 0x0, 0x0, 0x0) kernel console output (not intermixed with test programs): [T13437] EXT4-fs error (device loop1): ext4_orphan_get:1394: comm syz.1.3550: couldn't read orphan inode 15 (err -117) [ 227.858451][T13437] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 227.869292][T13443] loop4: detected capacity change from 0 to 128 [ 227.874523][T13437] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 227.944725][T13445] loop4: detected capacity change from 0 to 2048 [ 227.974676][T13445] syz.4.3559: attempt to access beyond end of device [ 227.974676][T13445] loop4: rw=0, sector=1936, nr_sectors = 128 limit=2048 [ 228.066042][T13451] loop4: detected capacity change from 0 to 2048 [ 228.129371][T13455] loop4: detected capacity change from 0 to 512 [ 228.137746][T13455] EXT4-fs error (device loop4): ext4_free_branches:1023: inode #11: comm syz.4.3564: invalid indirect mapped block 256 (level 2) [ 228.152292][T13455] EXT4-fs (loop4): 2 truncates cleaned up [ 228.158547][T13455] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 228.186931][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 228.233302][T13461] loop4: detected capacity change from 0 to 512 [ 228.240704][T13461] EXT4-fs (loop4): encrypted files will use data=ordered instead of data journaling mode [ 228.254154][T13461] EXT4-fs (loop4): 1 truncate cleaned up [ 228.262737][T13461] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 228.303480][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 228.332179][T13469] IPv6: Can't replace route, no match found [ 228.349010][T13471] loop4: detected capacity change from 0 to 128 [ 228.402752][T13475] loop1: detected capacity change from 0 to 512 [ 228.410075][T13475] EXT4-fs (loop1): encrypted files will use data=ordered instead of data journaling mode [ 228.424375][T13475] EXT4-fs (loop1): 1 truncate cleaned up [ 228.431016][T13475] EXT4-fs (loop1): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 228.498585][T13482] loop4: detected capacity change from 0 to 2048 [ 228.527065][T11477] EXT4-fs (loop1): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 228.581350][T13489] loop1: detected capacity change from 0 to 128 [ 228.639210][T13495] IPv6: Can't replace route, no match found [ 228.719095][T13502] loop5: detected capacity change from 0 to 512 [ 228.727060][T13502] EXT4-fs error (device loop5): ext4_free_branches:1023: inode #11: comm syz.5.3584: invalid indirect mapped block 256 (level 2) [ 228.742387][T13502] EXT4-fs (loop5): 2 truncates cleaned up [ 228.748540][T13502] EXT4-fs (loop5): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 228.789016][T13505] loop5: detected capacity change from 0 to 128 [ 228.844982][T13507] loop5: detected capacity change from 0 to 256 [ 228.851759][T13507] FAT-fs (loop5): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 228.901221][T13509] loop5: detected capacity change from 0 to 512 [ 228.908517][T13509] EXT4-fs (loop5): encrypted files will use data=ordered instead of data journaling mode [ 228.920421][T13509] EXT4-fs (loop5): 1 truncate cleaned up [ 228.999036][T13514] loop5: detected capacity change from 0 to 2048 [ 229.664835][T13534] loop3: detected capacity change from 0 to 512 [ 229.682543][T13538] loop2: detected capacity change from 0 to 2048 [ 229.687896][T13539] loop1: detected capacity change from 0 to 256 [ 229.712849][T13539] FAT-fs (loop1): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 229.715886][T13536] lo speed is unknown, defaulting to 1000 [ 229.734101][T13534] EXT4-fs error (device loop3): ext4_free_branches:1023: inode #11: comm syz.3.3596: invalid indirect mapped block 256 (level 2) [ 229.755804][T13534] EXT4-fs (loop3): 2 truncates cleaned up [ 229.793802][T13536] loop4: detected capacity change from 0 to 512 [ 229.801059][T13536] EXT4-fs: Ignoring removed mblk_io_submit option [ 229.822048][T13536] EXT4-fs (loop4): couldn't mount as ext3 due to feature incompatibilities [ 229.859655][T13541] syz.2.3598: attempt to access beyond end of device [ 229.859655][T13541] loop2: rw=0, sector=1936, nr_sectors = 128 limit=2048 [ 229.928460][T13548] loop3: detected capacity change from 0 to 128 [ 230.015592][T13552] loop2: detected capacity change from 0 to 2048 [ 230.021789][T13554] loop1: detected capacity change from 0 to 8192 [ 230.073000][T13554] loop1: p1 < > p2 p3 < p5 p6 > p4 [ 230.078266][T13554] loop1: partition table partially beyond EOD, truncated [ 230.086390][T13554] loop1: p1 start 277760 is beyond EOD, truncated [ 230.093081][T13554] loop1: p2 start 6684676 is beyond EOD, truncated [ 230.098251][T13552] syz.2.3603: attempt to access beyond end of device [ 230.098251][T13552] loop2: rw=0, sector=1936, nr_sectors = 128 limit=2048 [ 230.105373][T13554] loop1: p5 start 6684676 is beyond EOD, truncated [ 230.136751][T13558] lo speed is unknown, defaulting to 1000 [ 230.163065][ T2999] loop1: p1 < > p2 p3 < p5 p6 > p4 [ 230.168438][ T2999] loop1: partition table partially beyond EOD, truncated [ 230.177971][ T2999] loop1: p1 start 277760 is beyond EOD, truncated [ 230.184623][ T2999] loop1: p2 start 6684676 is beyond EOD, truncated [ 230.188281][ T2999] loop1: p5 start 6684676 is beyond EOD, truncated [ 230.208204][T13562] FAULT_INJECTION: forcing a failure. [ 230.208204][T13562] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 230.211068][T13567] loop5: detected capacity change from 0 to 512 [ 230.221457][T13562] CPU: 1 UID: 0 PID: 13562 Comm: syz.3.3609 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 230.238334][T13562] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 230.239820][T13564] loop4: detected capacity change from 0 to 512 [ 230.248398][T13562] Call Trace: [ 230.248413][T13562] [ 230.248424][T13562] dump_stack_lvl+0xf2/0x150 [ 230.255529][T13567] EXT4-fs: Ignoring removed mblk_io_submit option [ 230.257949][T13562] dump_stack+0x15/0x1a [ 230.263915][T13567] EXT4-fs (loop5): couldn't mount as ext3 due to feature incompatibilities [ 230.265469][T13562] should_fail_ex+0x223/0x230 [ 230.289387][T13562] should_fail+0xb/0x10 [ 230.293624][T13562] should_fail_usercopy+0x1a/0x20 [ 230.298671][T13562] _copy_from_user+0x1e/0xb0 [ 230.303426][T13562] kvmemdup_bpfptr_noprof+0x7d/0xf0 [ 230.308648][T13562] map_update_elem+0x195/0x470 [ 230.313428][T13562] __sys_bpf+0x713/0x7a0 [ 230.317719][T13562] __x64_sys_bpf+0x43/0x50 [ 230.322253][T13562] x64_sys_call+0x2914/0x2dc0 [ 230.326986][T13562] do_syscall_64+0xc9/0x1c0 [ 230.331585][T13562] ? clear_bhb_loop+0x55/0xb0 [ 230.336275][T13562] ? clear_bhb_loop+0x55/0xb0 [ 230.340964][T13562] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 230.346943][T13562] RIP: 0033:0x7fd8f4745d29 [ 230.351370][T13562] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 230.370995][T13562] RSP: 002b:00007fd8f2db7038 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 [ 230.379418][T13562] RAX: ffffffffffffffda RBX: 00007fd8f4935fa0 RCX: 00007fd8f4745d29 [ 230.387527][T13562] RDX: 0000000000000020 RSI: 00000000200024c0 RDI: 0000000000000002 [ 230.395681][T13562] RBP: 00007fd8f2db7090 R08: 0000000000000000 R09: 0000000000000000 [ 230.403663][T13562] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 230.411666][T13562] R13: 0000000000000000 R14: 00007fd8f4935fa0 R15: 00007fff3ed81bc8 [ 230.419655][T13562] [ 230.426661][T13564] EXT4-fs (loop4): encrypted files will use data=ordered instead of data journaling mode [ 230.456283][ T3527] udevd[3527]: inotify_add_watch(7, /dev/loop1p3, 10) failed: No such file or directory [ 230.465483][T13569] loop1: detected capacity change from 0 to 1024 [ 230.474315][ T9633] udevd[9633]: inotify_add_watch(7, /dev/loop1p4, 10) failed: No such file or directory [ 230.476059][ T3528] udevd[3528]: inotify_add_watch(7, /dev/loop1p6, 10) failed: No such file or directory [ 230.499258][T13569] ext4: Unknown parameter 'permit_directio' [ 230.534187][T13564] EXT4-fs (loop4): 1 truncate cleaned up [ 230.674143][T10525] udevd[10525]: inotify_add_watch(7, /dev/loop1p6, 10) failed: No such file or directory [ 230.679396][ T9633] udevd[9633]: inotify_add_watch(7, /dev/loop1p3, 10) failed: No such file or directory [ 230.718869][ T3528] udevd[3528]: inotify_add_watch(7, /dev/loop1p4, 10) failed: No such file or directory [ 230.942963][T13598] loop1: detected capacity change from 0 to 8192 [ 230.970969][ T3527] loop1: p1 < > p2 p3 < p5 p6 > p4 [ 230.976274][ T3527] loop1: partition table partially beyond EOD, truncated [ 231.106165][ T3527] loop1: p1 start 277760 is beyond EOD, truncated [ 231.112816][ T3527] loop1: p2 start 6684676 is beyond EOD, truncated [ 231.199509][T13611] loop3: detected capacity change from 0 to 256 [ 231.261817][T13611] FAT-fs (loop3): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 231.283979][ T3527] loop1: p5 start 6684676 is beyond EOD, truncated [ 231.317097][T13598] loop1: p1 < > p2 p3 < p5 p6 > p4 [ 231.322591][T13598] loop1: partition table partially beyond EOD, truncated [ 231.336543][T13598] loop1: p1 start 277760 is beyond EOD, truncated [ 231.343073][T13598] loop1: p2 start 6684676 is beyond EOD, truncated [ 231.361448][T13598] loop1: p5 start 6684676 is beyond EOD, truncated [ 231.368471][T13611] FAT-fs (loop3): Volume was not properly unmounted. Some data may be corrupt. Please run fsck. [ 231.451290][ T3528] udevd[3528]: inotify_add_watch(7, /dev/loop1p6, 10) failed: No such file or directory [ 231.457363][ T9633] udevd[9633]: inotify_add_watch(7, /dev/loop1p4, 10) failed: No such file or directory [ 231.465921][ T3527] udevd[3527]: inotify_add_watch(7, /dev/loop1p3, 10) failed: No such file or directory [ 231.499255][ T3528] udevd[3528]: inotify_add_watch(7, /dev/loop1p6, 10) failed: No such file or directory [ 231.514133][T13632] loop2: detected capacity change from 0 to 256 [ 231.523344][T13628] loop1: detected capacity change from 0 to 512 [ 231.527666][T13632] FAT-fs (loop2): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 231.543819][T13628] EXT4-fs (loop1): encrypted files will use data=ordered instead of data journaling mode [ 231.572919][T13628] EXT4-fs (loop1): 1 truncate cleaned up [ 231.591360][T11715] FAT-fs (loop3): error, corrupted directory (invalid entries) [ 231.598970][T11715] FAT-fs (loop3): Filesystem has been set read-only [ 231.628348][T11715] FAT-fs (loop3): error, corrupted directory (invalid entries) [ 231.764969][T13653] IPv6: Can't replace route, no match found [ 231.887271][T13668] loop4: detected capacity change from 0 to 512 [ 231.910923][T13668] EXT4-fs (loop4): can't mount with commit=17542, fs mounted w/o journal [ 231.931314][T13670] lo speed is unknown, defaulting to 1000 [ 231.999700][T13677] loop1: detected capacity change from 0 to 512 [ 232.015930][T13677] EXT4-fs: Ignoring removed mblk_io_submit option [ 232.025913][T13677] EXT4-fs (loop1): couldn't mount as ext3 due to feature incompatibilities [ 232.045852][ T3386] netdevsim netdevsim3 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 232.083407][T13684] loop4: detected capacity change from 0 to 128 [ 232.114991][ T3386] netdevsim netdevsim3 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 232.149349][T13686] loop2: detected capacity change from 0 to 2048 [ 232.188702][ T3386] netdevsim netdevsim3 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 232.255086][ T3386] netdevsim netdevsim3 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 232.300152][T13699] IPv6: Can't replace route, no match found [ 232.389642][ T3386] bridge_slave_1: left allmulticast mode [ 232.395427][ T3386] bridge_slave_1: left promiscuous mode [ 232.396468][T13705] loop4: detected capacity change from 0 to 1024 [ 232.401287][ T3386] bridge0: port 2(bridge_slave_1) entered disabled state [ 232.415465][ T29] kauditd_printk_skb: 929 callbacks suppressed [ 232.415481][ T29] audit: type=1400 audit(232.453:42633): avc: denied { create } for pid=13706 comm="syz.2.3650" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=udp_socket permissive=1 [ 232.441491][ T29] audit: type=1400 audit(232.453:42634): avc: denied { create } for pid=13706 comm="syz.2.3650" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=netlink_generic_socket permissive=1 [ 232.447027][T13710] loop1: detected capacity change from 0 to 512 [ 232.462206][ T29] audit: type=1400 audit(232.453:42635): avc: denied { write } for pid=13706 comm="syz.2.3650" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=netlink_generic_socket permissive=1 [ 232.489149][ T29] audit: type=1400 audit(232.453:42636): avc: denied { read } for pid=13706 comm="syz.2.3650" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=netlink_generic_socket permissive=1 [ 232.496800][T13705] ext4: Unknown parameter 'permit_directio' [ 232.515776][ T29] audit: type=1400 audit(232.553:42637): avc: denied { bind } for pid=13706 comm="syz.2.3650" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=udp_socket permissive=1 [ 232.535441][ T29] audit: type=1400 audit(232.553:42638): avc: denied { node_bind } for pid=13706 comm="syz.2.3650" saddr=172.20.20.42 scontext=system_u:object_r:hugetlbfs_t tcontext=system_u:object_r:node_t tclass=udp_socket permissive=1 [ 232.557413][ T3386] bridge_slave_0: left allmulticast mode [ 232.561943][ T29] audit: type=1400 audit(232.583:42639): avc: denied { setopt } for pid=13706 comm="syz.2.3650" laddr=172.20.20.42 lport=60275 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=udp_socket permissive=1 [ 232.563347][ T3386] bridge_slave_0: left promiscuous mode [ 232.585436][ T29] audit: type=1400 audit(232.583:42640): avc: denied { connect } for pid=13706 comm="syz.2.3650" laddr=172.20.20.42 lport=60275 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=udp_socket permissive=1 [ 232.591218][ T3386] bridge0: port 1(bridge_slave_0) entered disabled state [ 232.613330][ T29] audit: type=1400 audit(232.583:42641): avc: denied { write } for pid=13706 comm="syz.2.3650" laddr=172.20.20.42 lport=60275 faddr=255.255.255.255 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:hugetlbfs_t tclass=udp_socket permissive=1 [ 232.636427][T13710] EXT4-fs (loop1): can't mount with commit=17542, fs mounted w/o journal [ 232.712733][ T29] audit: type=1326 audit(232.753:42642): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=13716 comm="syz.1.3653" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f67e6785d29 code=0x7ffc0000 [ 232.799024][T13722] loop2: detected capacity change from 0 to 2048 [ 232.848061][ T3386] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 232.862809][ T3386] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 232.879471][ T3386] bond0 (unregistering): Released all slaves [ 232.910884][T13687] lo speed is unknown, defaulting to 1000 [ 232.953089][ T3386] hsr_slave_0: left promiscuous mode [ 232.981625][ T3386] hsr_slave_1: left promiscuous mode [ 232.996917][ T3386] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 233.004567][ T3386] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 233.023659][T13727] loop1: detected capacity change from 0 to 2048 [ 233.036696][ T3386] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 233.044359][ T3386] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 233.052682][T13734] loop2: detected capacity change from 0 to 512 [ 233.073916][T13734] EXT4-fs: Ignoring removed mblk_io_submit option [ 233.093788][T13734] EXT4-fs (loop2): couldn't mount as ext3 due to feature incompatibilities [ 233.102980][ T3386] veth1_macvtap: left promiscuous mode [ 233.108504][ T3386] veth0_macvtap: left promiscuous mode [ 233.114272][ T3386] veth1_vlan: left promiscuous mode [ 233.116540][T13727] syz.1.3657: attempt to access beyond end of device [ 233.116540][T13727] loop1: rw=0, sector=1936, nr_sectors = 128 limit=2048 [ 233.119551][ T3386] veth0_vlan: left promiscuous mode [ 233.321202][ T3386] team0 (unregistering): Port device team_slave_1 removed [ 233.335417][T13755] loop5: detected capacity change from 0 to 512 [ 233.348974][ T3386] team0 (unregistering): Port device team_slave_0 removed [ 233.351728][T13755] EXT4-fs (loop5): can't mount with commit=17542, fs mounted w/o journal [ 233.425055][T13729] lo speed is unknown, defaulting to 1000 [ 233.433639][T13748] IPv6: Can't replace route, no match found [ 233.464893][T13759] loop5: detected capacity change from 0 to 128 [ 233.652148][T13774] loop1: detected capacity change from 0 to 2048 [ 233.663955][T13687] chnl_net:caif_netlink_parms(): no params data found [ 233.734997][T13768] loop5: detected capacity change from 0 to 2048 [ 233.736548][T13687] bridge0: port 1(bridge_slave_0) entered blocking state [ 233.748484][T13687] bridge0: port 1(bridge_slave_0) entered disabled state [ 233.755730][T13687] bridge_slave_0: entered allmulticast mode [ 233.758429][T13789] loop4: detected capacity change from 0 to 512 [ 233.762416][T13687] bridge_slave_0: entered promiscuous mode [ 233.774720][T13687] bridge0: port 2(bridge_slave_1) entered blocking state [ 233.781896][T13687] bridge0: port 2(bridge_slave_1) entered disabled state [ 233.789086][T13687] bridge_slave_1: entered allmulticast mode [ 233.798752][T13789] ext4: Unknown parameter 'fsuuid' [ 233.814427][T13687] bridge_slave_1: entered promiscuous mode [ 233.819456][T13789] FAULT_INJECTION: forcing a failure. [ 233.819456][T13789] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 233.833458][T13789] CPU: 1 UID: 0 PID: 13789 Comm: syz.4.3670 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 233.843373][T13787] syz.1.3669: attempt to access beyond end of device [ 233.843373][T13787] loop1: rw=0, sector=1936, nr_sectors = 128 limit=2048 [ 233.844227][T13789] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 233.867820][T13789] Call Trace: [ 233.871110][T13789] [ 233.874162][T13789] dump_stack_lvl+0xf2/0x150 [ 233.878788][T13789] dump_stack+0x15/0x1a [ 233.883075][T13789] should_fail_ex+0x223/0x230 [ 233.887790][T13789] should_fail+0xb/0x10 [ 233.891968][T13789] should_fail_usercopy+0x1a/0x20 [ 233.897085][T13789] _copy_from_user+0x1e/0xb0 [ 233.901711][T13789] copy_msghdr_from_user+0x54/0x2a0 [ 233.906970][T13789] ? __fget_files+0x17c/0x1c0 [ 233.911678][T13789] __sys_sendmsg+0x13e/0x230 [ 233.916301][T13789] __x64_sys_sendmsg+0x46/0x50 [ 233.921154][T13789] x64_sys_call+0x2734/0x2dc0 [ 233.925891][T13789] do_syscall_64+0xc9/0x1c0 [ 233.930461][T13789] ? clear_bhb_loop+0x55/0xb0 [ 233.935237][T13789] ? clear_bhb_loop+0x55/0xb0 [ 233.939929][T13789] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 233.945930][T13789] RIP: 0033:0x7f94fe055d29 [ 233.950370][T13789] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 233.970048][T13789] RSP: 002b:00007f94fc6c7038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 233.978499][T13789] RAX: ffffffffffffffda RBX: 00007f94fe245fa0 RCX: 00007f94fe055d29 [ 233.986482][T13789] RDX: 0000000000000000 RSI: 0000000020000240 RDI: 0000000000000007 [ 233.994479][T13789] RBP: 00007f94fc6c7090 R08: 0000000000000000 R09: 0000000000000000 [ 234.002456][T13789] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 234.010483][T13789] R13: 0000000000000000 R14: 00007f94fe245fa0 R15: 00007ffcc562f188 [ 234.018590][T13789] [ 234.084326][T13797] loop4: detected capacity change from 0 to 512 [ 234.094319][T13795] team0 (unregistering): Port device team_slave_0 removed [ 234.104418][T13797] EXT4-fs (loop4): can't mount with commit=17542, fs mounted w/o journal [ 234.115731][T13795] team0 (unregistering): Port device team_slave_1 removed [ 234.147263][T13687] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 234.172508][T13804] loop5: detected capacity change from 0 to 512 [ 234.181605][T13801] IPv6: Can't replace route, no match found [ 234.219074][T13804] EXT4-fs error (device loop5): ext4_free_branches:1023: inode #11: comm syz.5.3675: invalid indirect mapped block 256 (level 2) [ 234.220245][T13687] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 234.260280][T13804] EXT4-fs (loop5): 2 truncates cleaned up [ 234.314733][T13811] loop1: detected capacity change from 0 to 512 [ 234.342405][T13811] EXT4-fs (loop1): encrypted files will use data=ordered instead of data journaling mode [ 234.371328][T13687] team0: Port device team_slave_0 added [ 234.399518][T13821] 9pnet_fd: Insufficient options for proto=fd [ 234.409335][T13687] team0: Port device team_slave_1 added [ 234.411200][T13811] EXT4-fs (loop1): 1 truncate cleaned up [ 234.430953][T13821] program syz.2.3680 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 234.462402][T13687] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 234.469535][T13687] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 234.495530][T13687] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 234.526166][T13687] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 234.533242][T13687] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 234.559357][T13687] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 234.606491][T13833] loop2: detected capacity change from 0 to 2048 [ 234.641370][T13833] msdos: Unknown parameter 'ÿ18446744073709551615ÿÿÿÿ' [ 234.697065][T13687] hsr_slave_0: entered promiscuous mode [ 234.709645][T13687] hsr_slave_1: entered promiscuous mode [ 234.726688][T13687] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 234.738659][T13687] Cannot create hsr debugfs directory [ 234.747115][T13838] lo speed is unknown, defaulting to 1000 [ 234.797062][T13843] loop1: detected capacity change from 0 to 512 [ 234.825817][T13847] loop4: detected capacity change from 0 to 512 [ 234.841057][T13849] loop5: detected capacity change from 0 to 512 [ 234.843742][T13843] EXT4-fs: Ignoring removed mblk_io_submit option [ 234.870481][T13849] EXT4-fs (loop5): can't mount with commit=17542, fs mounted w/o journal [ 234.910436][T13843] EXT4-fs (loop1): couldn't mount as ext3 due to feature incompatibilities [ 234.921772][T13847] EXT4-fs (loop4): re-mounted 00000000-0000-0000-0000-000000000000 ro. Quota mode: writeback. [ 234.998043][T13847] EXT4-fs (loop4): re-mounted 00000000-0000-0000-0000-000000000000 r/w. Quota mode: writeback. [ 235.033430][T13687] netdevsim netdevsim6 netdevsim0: renamed from eth0 [ 235.056380][T13687] netdevsim netdevsim6 netdevsim1: renamed from eth1 [ 235.067124][T13687] netdevsim netdevsim6 netdevsim2: renamed from eth2 [ 235.090674][T13687] netdevsim netdevsim6 netdevsim3: renamed from eth3 [ 235.193691][T13687] 8021q: adding VLAN 0 to HW filter on device bond0 [ 235.200978][T13874] IPv6: Can't replace route, no match found [ 235.213285][T13687] 8021q: adding VLAN 0 to HW filter on device team0 [ 235.235588][T13687] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 235.246060][T13687] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 235.266964][ T3386] bridge0: port 1(bridge_slave_0) entered blocking state [ 235.274125][ T3386] bridge0: port 1(bridge_slave_0) entered forwarding state [ 235.294872][T13881] FAULT_INJECTION: forcing a failure. [ 235.294872][T13881] name failslab, interval 1, probability 0, space 0, times 0 [ 235.307630][T13881] CPU: 0 UID: 0 PID: 13881 Comm: syz.1.3691 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 235.318425][T13881] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 235.328577][T13881] Call Trace: [ 235.331886][T13881] [ 235.334842][T13881] dump_stack_lvl+0xf2/0x150 [ 235.339584][T13881] dump_stack+0x15/0x1a [ 235.343789][T13881] should_fail_ex+0x223/0x230 [ 235.348509][T13881] should_failslab+0x8f/0xb0 [ 235.351041][ T3386] bridge0: port 2(bridge_slave_1) entered blocking state [ 235.353136][T13881] kmem_cache_alloc_noprof+0x52/0x320 [ 235.353209][T13881] ? audit_log_start+0x34c/0x6b0 [ 235.353237][T13881] audit_log_start+0x34c/0x6b0 [ 235.360301][ T3386] bridge0: port 2(bridge_slave_1) entered forwarding state [ 235.365614][T13881] audit_seccomp+0x4b/0x130 [ 235.387057][T13881] __seccomp_filter+0x6fa/0x1180 [ 235.392032][T13881] ? __pfx_proc_fail_nth_write+0x10/0x10 [ 235.397809][T13881] ? vfs_write+0x596/0x920 [ 235.402255][T13881] __secure_computing+0x9f/0x1c0 [ 235.407270][T13881] syscall_trace_enter+0xd1/0x1f0 [ 235.412372][T13881] ? fpregs_assert_state_consistent+0x83/0xa0 [ 235.418593][T13881] do_syscall_64+0xaa/0x1c0 [ 235.423244][T13881] ? clear_bhb_loop+0x55/0xb0 [ 235.427942][T13881] ? clear_bhb_loop+0x55/0xb0 [ 235.432630][T13881] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 235.438619][T13881] RIP: 0033:0x7f67e6785d29 [ 235.443057][T13881] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 235.462762][T13881] RSP: 002b:00007f67e4df7038 EFLAGS: 00000246 ORIG_RAX: 0000000000000071 [ 235.471231][T13881] RAX: ffffffffffffffda RBX: 00007f67e6975fa0 RCX: 00007f67e6785d29 [ 235.479222][T13881] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 235.487201][T13881] RBP: 00007f67e4df7090 R08: 0000000000000000 R09: 0000000000000000 [ 235.495242][T13881] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 235.503242][T13881] R13: 0000000000000000 R14: 00007f67e6975fa0 R15: 00007ffc07fdffc8 [ 235.511239][T13881] [ 235.619171][T13687] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 235.641749][T13890] loop2: detected capacity change from 0 to 512 [ 235.694581][T13903] loop5: detected capacity change from 0 to 256 [ 235.702497][T13890] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 235.709350][T13903] FAT-fs (loop5): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 235.735217][T13890] EXT4-fs (loop2): 1 truncate cleaned up [ 235.745081][T13903] FAT-fs (loop5): Volume was not properly unmounted. Some data may be corrupt. Please run fsck. [ 235.912797][T12874] FAT-fs (loop5): error, corrupted directory (invalid entries) [ 235.920534][T12874] FAT-fs (loop5): Filesystem has been set read-only [ 235.927786][T12874] FAT-fs (loop5): error, corrupted directory (invalid entries) [ 236.013523][T13933] loop2: detected capacity change from 0 to 512 [ 236.036372][T13687] veth0_vlan: entered promiscuous mode [ 236.068882][T13933] EXT4-fs (loop2): re-mounted 00000000-0000-0000-0000-000000000000 ro. Quota mode: writeback. [ 236.105393][T13687] veth1_vlan: entered promiscuous mode [ 236.129980][T13941] loop4: detected capacity change from 0 to 2048 [ 236.136791][T13941] msdos: Unknown parameter 'ÿ18446744073709551615ÿÿÿÿ' [ 236.155716][T13687] veth0_macvtap: entered promiscuous mode [ 236.163894][T13687] veth1_macvtap: entered promiscuous mode [ 236.171183][T13942] EXT4-fs (loop2): re-mounted 00000000-0000-0000-0000-000000000000 r/w. Quota mode: writeback. [ 236.178604][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.192514][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.202395][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.212930][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.222779][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.233232][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.243069][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.253524][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.263353][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.273881][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.283725][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.294297][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.304213][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.314753][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.324769][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 236.335364][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.347451][T13687] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 236.369035][T13950] IPv6: Can't replace route, no match found [ 236.379858][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.390623][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.400509][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.411007][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.420847][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.431327][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.441236][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.451690][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.461617][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.472069][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.481919][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.492634][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.502704][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.513183][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.523074][T13687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 236.533651][T13687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 236.537603][T13953] loop1: detected capacity change from 0 to 2048 [ 236.546034][T13687] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 236.559014][T13687] netdevsim netdevsim6 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 236.567792][T13687] netdevsim netdevsim6 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 236.576616][T13687] netdevsim netdevsim6 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 236.585392][T13687] netdevsim netdevsim6 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 236.652482][ T3410] netdevsim netdevsim5 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 236.680901][T13959] @: renamed from vlan0 (while UP) [ 236.735566][ T3410] netdevsim netdevsim5 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 236.811058][ T3410] netdevsim netdevsim5 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 236.880456][T13981] netlink: 44 bytes leftover after parsing attributes in process `syz.1.3709'. [ 236.907265][ T3410] netdevsim netdevsim5 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 236.972951][T13990] IPv6: Can't replace route, no match found [ 236.979473][T13955] lo speed is unknown, defaulting to 1000 [ 237.024081][T13994] loop4: detected capacity change from 0 to 512 [ 237.060325][ T3410] bridge_slave_1: left allmulticast mode [ 237.060721][T13994] EXT4-fs (loop4): can't mount with commit=17542, fs mounted w/o journal [ 237.066069][ T3410] bridge_slave_1: left promiscuous mode [ 237.080296][ T3410] bridge0: port 2(bridge_slave_1) entered disabled state [ 237.105391][T13999] loop1: detected capacity change from 0 to 2048 [ 237.112556][ T3410] bridge_slave_0: left allmulticast mode [ 237.118306][ T3410] bridge_slave_0: left promiscuous mode [ 237.124025][ T3410] bridge0: port 1(bridge_slave_0) entered disabled state [ 237.227892][T14004] loop1: detected capacity change from 0 to 4096 [ 237.316080][ T3410] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 237.339691][ T3410] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 237.352624][ T3410] bond0 (unregistering): Released all slaves [ 237.399872][T14018] loop4: detected capacity change from 0 to 1024 [ 237.414739][ T3410] hsr_slave_0: left promiscuous mode [ 237.422445][ T3410] hsr_slave_1: left promiscuous mode [ 237.428529][ T3410] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 237.436213][ T3410] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 237.444078][ T3410] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 237.451675][ T3410] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 237.461634][ T3410] veth1_macvtap: left promiscuous mode [ 237.467134][ T3410] veth0_macvtap: left promiscuous mode [ 237.472768][ T3410] veth1_vlan: left promiscuous mode [ 237.478004][ T3410] veth0_vlan: left promiscuous mode [ 237.654442][T14024] loop2: detected capacity change from 0 to 512 [ 237.721919][T14024] EXT4-fs (loop2): can't mount with commit=17542, fs mounted w/o journal [ 237.773230][T13955] chnl_net:caif_netlink_parms(): no params data found [ 237.988486][ T29] kauditd_printk_skb: 471 callbacks suppressed [ 237.988503][ T29] audit: type=1326 audit(238.023:43112): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.050573][T13955] bridge0: port 1(bridge_slave_0) entered blocking state [ 238.057793][T13955] bridge0: port 1(bridge_slave_0) entered disabled state [ 238.083561][ T29] audit: type=1326 audit(238.063:43113): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.106685][ T29] audit: type=1326 audit(238.063:43114): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.129806][ T29] audit: type=1326 audit(238.063:43115): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.140506][T13955] bridge_slave_0: entered allmulticast mode [ 238.152958][ T29] audit: type=1326 audit(238.063:43116): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.170569][T13955] bridge_slave_0: entered promiscuous mode [ 238.181825][ T29] audit: type=1326 audit(238.063:43117): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.210708][ T29] audit: type=1326 audit(238.063:43118): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.215083][T13955] bridge0: port 2(bridge_slave_1) entered blocking state [ 238.233777][ T29] audit: type=1326 audit(238.063:43119): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=298 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.240782][T13955] bridge0: port 2(bridge_slave_1) entered disabled state [ 238.242874][T14057] loop2: detected capacity change from 0 to 512 [ 238.263765][ T29] audit: type=1326 audit(238.063:43120): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.271262][T13955] bridge_slave_1: entered allmulticast mode [ 238.277048][ T29] audit: type=1326 audit(238.063:43121): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14055 comm="syz.2.3728" exe="/root/syz-executor" sig=0 arch=c000003e syscall=9 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 238.312695][T14057] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 238.331884][T13955] bridge_slave_1: entered promiscuous mode [ 238.364498][T14057] EXT4-fs (loop2): 1 truncate cleaned up [ 238.380434][T14021] netlink: 'syz.4.3721': attribute type 6 has an invalid length. [ 238.390001][T13955] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 238.401481][T14025] lo speed is unknown, defaulting to 1000 [ 238.419008][T13955] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 238.498360][T14066] loop6: detected capacity change from 0 to 1024 [ 238.523183][T14071] loop4: detected capacity change from 0 to 2048 [ 238.540626][ T3410] netdevsim netdevsim1 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 238.572681][T13955] team0: Port device team_slave_0 added [ 238.609763][T13955] team0: Port device team_slave_1 added [ 238.623766][T14083] FAULT_INJECTION: forcing a failure. [ 238.623766][T14083] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 238.624194][ T3410] netdevsim netdevsim1 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 238.636862][T14083] CPU: 1 UID: 0 PID: 14083 Comm: syz.4.3733 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 238.657915][T14083] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 238.668006][T14083] Call Trace: [ 238.671398][T14083] [ 238.674430][T14083] dump_stack_lvl+0xf2/0x150 [ 238.679095][T14083] dump_stack+0x15/0x1a [ 238.683293][T14083] should_fail_ex+0x223/0x230 [ 238.688041][T14083] should_fail+0xb/0x10 [ 238.692232][T14083] should_fail_usercopy+0x1a/0x20 [ 238.697284][T14083] _copy_from_user+0x1e/0xb0 [ 238.701967][T14083] move_addr_to_kernel+0x82/0x120 [ 238.707018][T14083] __sys_sendto+0x12e/0x230 [ 238.711549][T14083] __x64_sys_sendto+0x78/0x90 [ 238.716243][T14083] x64_sys_call+0x29fa/0x2dc0 [ 238.721005][T14083] do_syscall_64+0xc9/0x1c0 [ 238.725523][T14083] ? clear_bhb_loop+0x55/0xb0 [ 238.730223][T14083] ? clear_bhb_loop+0x55/0xb0 [ 238.735087][T14083] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 238.741076][T14083] RIP: 0033:0x7f94fe055d29 [ 238.745564][T14083] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 238.765358][T14083] RSP: 002b:00007f94fc6c7038 EFLAGS: 00000246 ORIG_RAX: 000000000000002c [ 238.773828][T14083] RAX: ffffffffffffffda RBX: 00007f94fe245fa0 RCX: 00007f94fe055d29 [ 238.781807][T14083] RDX: 0000000000000001 RSI: 0000000020000340 RDI: 0000000000000003 [ 238.789785][T14083] RBP: 00007f94fc6c7090 R08: 00000000200000c0 R09: 0000000000000014 [ 238.797780][T14083] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 238.805841][T14083] R13: 0000000000000000 R14: 00007f94fe245fa0 R15: 00007ffcc562f188 [ 238.813906][T14083] [ 238.887864][ T3410] netdevsim netdevsim1 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 238.914039][T13955] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 238.921120][T13955] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 238.947143][T13955] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 238.993642][T13955] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 239.000661][T13955] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 239.027224][T13955] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 239.063117][T14095] loop4: detected capacity change from 0 to 512 [ 239.099893][T14025] chnl_net:caif_netlink_parms(): no params data found [ 239.118020][ T3410] netdevsim netdevsim1 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 239.138619][T14095] EXT4-fs (loop4): can't mount with commit=17542, fs mounted w/o journal [ 239.225375][T13955] hsr_slave_0: entered promiscuous mode [ 239.238999][T13955] hsr_slave_1: entered promiscuous mode [ 239.261758][T13955] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 239.269628][T13955] Cannot create hsr debugfs directory [ 239.315336][T14076] loop2: detected capacity change from 0 to 512 [ 239.387579][T14076] bridge0: port 3(vlan0) entered blocking state [ 239.394005][T14076] bridge0: port 3(vlan0) entered disabled state [ 239.419782][T14076] vlan0: entered allmulticast mode [ 239.446557][T14076] vlan0: left allmulticast mode [ 239.482641][T14025] bridge0: port 1(bridge_slave_0) entered blocking state [ 239.489774][T14025] bridge0: port 1(bridge_slave_0) entered disabled state [ 239.517815][T14025] bridge_slave_0: entered allmulticast mode [ 239.534085][T14025] bridge_slave_0: entered promiscuous mode [ 239.564687][T14025] bridge0: port 2(bridge_slave_1) entered blocking state [ 239.571959][T14025] bridge0: port 2(bridge_slave_1) entered disabled state [ 239.599149][T14115] loop4: detected capacity change from 0 to 512 [ 239.599710][T14025] bridge_slave_1: entered allmulticast mode [ 239.608970][T14115] EXT4-fs (loop4): encrypted files will use data=ordered instead of data journaling mode [ 239.622414][T14025] bridge_slave_1: entered promiscuous mode [ 239.644360][ T3410] bridge_slave_1: left allmulticast mode [ 239.650088][ T3410] bridge_slave_1: left promiscuous mode [ 239.655845][ T3410] bridge0: port 2(bridge_slave_1) entered disabled state [ 239.663805][T14115] EXT4-fs (loop4): 1 truncate cleaned up [ 239.688058][ T3410] bridge_slave_0: left allmulticast mode [ 239.693932][ T3410] bridge_slave_0: left promiscuous mode [ 239.699680][ T3410] bridge0: port 1(bridge_slave_0) entered disabled state [ 239.794808][ T3410] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 239.804853][ T3410] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 239.817618][ T3410] bond0 (unregistering): Released all slaves [ 239.849059][T14066] netlink: 'syz.6.3730': attribute type 6 has an invalid length. [ 239.876364][T14025] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 239.893699][T14025] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 239.900500][ T3410] IPVS: stopping backup sync thread 11868 ... [ 239.942857][T14126] loop6: detected capacity change from 0 to 512 [ 239.956446][ T3410] hsr_slave_0: left promiscuous mode [ 239.966012][ T3410] hsr_slave_1: left promiscuous mode [ 239.972404][T14126] EXT4-fs (loop6): can't mount with commit=17542, fs mounted w/o journal [ 239.983262][ T3410] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 239.990878][ T3410] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 240.006303][ T3410] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 240.013911][ T3410] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 240.030584][ T3410] veth1_macvtap: left promiscuous mode [ 240.036221][ T3410] veth0_macvtap: left promiscuous mode [ 240.042119][ T3410] veth1_vlan: left promiscuous mode [ 240.047407][ T3410] veth0_vlan: left promiscuous mode [ 240.086993][T14132] loop2: detected capacity change from 0 to 512 [ 240.094627][T14132] EXT4-fs: Ignoring removed mblk_io_submit option [ 240.103426][T14132] EXT4-fs (loop2): couldn't mount as ext3 due to feature incompatibilities [ 240.142763][T14134] loop6: detected capacity change from 0 to 512 [ 240.150973][T14134] EXT4-fs (loop6): encrypted files will use data=ordered instead of data journaling mode [ 240.163657][T14134] EXT4-fs (loop6): 1 truncate cleaned up [ 240.214988][T14129] lo speed is unknown, defaulting to 1000 [ 240.229664][T14025] team0: Port device team_slave_0 added [ 240.254567][T14025] team0: Port device team_slave_1 added [ 240.298397][T13955] netdevsim netdevsim7 netdevsim0: renamed from eth0 [ 240.319049][T13955] netdevsim netdevsim7 netdevsim1: renamed from eth1 [ 240.332015][T14025] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 240.339368][T14025] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 240.365863][T14025] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 240.382042][T13955] netdevsim netdevsim7 netdevsim2: renamed from eth2 [ 240.390934][T13955] netdevsim netdevsim7 netdevsim3: renamed from eth3 [ 240.432661][T14025] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 240.439655][T14025] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 240.465701][T14025] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 240.477615][T14156] FAULT_INJECTION: forcing a failure. [ 240.477615][T14156] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 240.490906][T14156] CPU: 0 UID: 0 PID: 14156 Comm: syz.6.3750 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 240.501711][T14156] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 240.511881][T14156] Call Trace: [ 240.515200][T14156] [ 240.518180][T14156] dump_stack_lvl+0xf2/0x150 [ 240.522856][T14156] dump_stack+0x15/0x1a [ 240.527062][T14156] should_fail_ex+0x223/0x230 [ 240.531846][T14156] should_fail+0xb/0x10 [ 240.536067][T14156] should_fail_usercopy+0x1a/0x20 [ 240.541165][T14156] _copy_to_user+0x20/0xa0 [ 240.545642][T14156] simple_read_from_buffer+0xa0/0x110 [ 240.551108][T14156] proc_fail_nth_read+0xf9/0x140 [ 240.556115][T14156] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 240.561746][T14156] vfs_read+0x1a2/0x700 [ 240.566009][T14156] ? __rcu_read_unlock+0x4e/0x70 [ 240.571037][T14156] ? __fget_files+0x17c/0x1c0 [ 240.575754][T14156] ksys_read+0xe8/0x1b0 [ 240.579994][T14156] __x64_sys_read+0x42/0x50 [ 240.584589][T14156] x64_sys_call+0x2874/0x2dc0 [ 240.589340][T14156] do_syscall_64+0xc9/0x1c0 [ 240.593947][T14156] ? clear_bhb_loop+0x55/0xb0 [ 240.598655][T14156] ? clear_bhb_loop+0x55/0xb0 [ 240.603394][T14156] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 240.609396][T14156] RIP: 0033:0x7f64e3ba473c [ 240.613840][T14156] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 240.633468][T14156] RSP: 002b:00007f64e2217030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 240.641982][T14156] RAX: ffffffffffffffda RBX: 00007f64e3d95fa0 RCX: 00007f64e3ba473c [ 240.649964][T14156] RDX: 000000000000000f RSI: 00007f64e22170a0 RDI: 0000000000000007 [ 240.657955][T14156] RBP: 00007f64e2217090 R08: 0000000000000000 R09: 0000000000000000 [ 240.665984][T14156] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 240.673978][T14156] R13: 0000000000000000 R14: 00007f64e3d95fa0 R15: 00007ffc15b64ae8 [ 240.682030][T14156] [ 240.766463][T14025] hsr_slave_0: entered promiscuous mode [ 240.786738][T14025] hsr_slave_1: entered promiscuous mode [ 240.803828][T14025] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 240.814820][T14025] Cannot create hsr debugfs directory [ 240.859225][T14172] netlink: 12 bytes leftover after parsing attributes in process `syz.2.3755'. [ 240.963452][T14174] loop6: detected capacity change from 0 to 512 [ 240.973406][T14174] EXT4-fs (loop6): encrypted files will use data=ordered instead of data journaling mode [ 241.015425][T14174] EXT4-fs (loop6): 1 truncate cleaned up [ 241.067777][T13955] 8021q: adding VLAN 0 to HW filter on device bond0 [ 241.082953][T13955] 8021q: adding VLAN 0 to HW filter on device team0 [ 241.112112][T14025] netdevsim netdevsim8 netdevsim0: renamed from eth0 [ 241.125716][T14025] netdevsim netdevsim8 netdevsim1: renamed from eth1 [ 241.139229][T14025] netdevsim netdevsim8 netdevsim2: renamed from eth2 [ 241.161097][ T7727] bridge0: port 1(bridge_slave_0) entered blocking state [ 241.168393][ T7727] bridge0: port 1(bridge_slave_0) entered forwarding state [ 241.192365][T14025] netdevsim netdevsim8 netdevsim3: renamed from eth3 [ 241.213348][ T55] bridge0: port 2(bridge_slave_1) entered blocking state [ 241.213386][ T55] bridge0: port 2(bridge_slave_1) entered forwarding state [ 241.303520][T14205] loop4: detected capacity change from 0 to 1024 [ 241.326571][T14025] 8021q: adding VLAN 0 to HW filter on device bond0 [ 241.342340][T14025] 8021q: adding VLAN 0 to HW filter on device team0 [ 241.351492][ T55] bridge0: port 1(bridge_slave_0) entered blocking state [ 241.366533][ T55] bridge0: port 1(bridge_slave_0) entered forwarding state [ 241.400698][T14218] loop6: detected capacity change from 0 to 2048 [ 241.411855][T14025] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 241.422249][T14025] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 241.436372][ T55] bridge0: port 2(bridge_slave_1) entered blocking state [ 241.443489][ T55] bridge0: port 2(bridge_slave_1) entered forwarding state [ 241.465238][T13955] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 241.576770][T14227] vhci_hcd: invalid port number 61 [ 241.655980][T14025] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 241.797629][T13955] veth0_vlan: entered promiscuous mode [ 241.878246][T13955] veth1_vlan: entered promiscuous mode [ 241.948784][T13955] veth0_macvtap: entered promiscuous mode [ 241.976602][T13955] veth1_macvtap: entered promiscuous mode [ 242.027237][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.037794][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.047686][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.058257][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.068154][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.078672][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.088662][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.099302][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.109312][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.119850][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.129795][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.140321][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.150224][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.160796][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.188249][T13955] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 242.199054][T14196] netlink: 'syz.4.3761': attribute type 6 has an invalid length. [ 242.225613][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.236189][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.246094][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.256785][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.266825][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.277361][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.287635][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.298434][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.308585][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.319149][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.329143][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.339725][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.349731][T13955] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.360232][T13955] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.369437][T14218] EXT4-fs error (device loop6): ext4_mb_generate_buddy:1220: group 0, block bitmap and bg descriptor inconsistent: 25 vs 150994969 free clusters [ 242.371099][T13955] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 242.394427][T13955] netdevsim netdevsim7 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 242.403252][T13955] netdevsim netdevsim7 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 242.412160][T13955] netdevsim netdevsim7 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 242.421061][T13955] netdevsim netdevsim7 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 242.463218][T14218] EXT4-fs (loop6): Delayed block allocation failed for inode 18 at logical offset 0 with max blocks 2048 with error 28 [ 242.475796][T14218] EXT4-fs (loop6): This should not happen!! Data will be lost [ 242.475796][T14218] [ 242.485689][T14218] EXT4-fs (loop6): Total free blocks count 0 [ 242.491723][T14218] EXT4-fs (loop6): Free/Dirty block details [ 242.497640][T14218] EXT4-fs (loop6): free_blocks=2415919104 [ 242.503522][T14218] EXT4-fs (loop6): dirty_blocks=8192 [ 242.509024][T14218] EXT4-fs (loop6): Block reservation details [ 242.515069][T14218] EXT4-fs (loop6): i_reserved_data_blocks=512 [ 242.529429][T14286] lo speed is unknown, defaulting to 1000 [ 242.535820][T14286] lo speed is unknown, defaulting to 1000 [ 242.537407][T14025] veth0_vlan: entered promiscuous mode [ 242.574979][T14286] lo speed is unknown, defaulting to 1000 [ 242.584655][T14025] veth1_vlan: entered promiscuous mode [ 242.600847][T14025] veth0_macvtap: entered promiscuous mode [ 242.608778][T14025] veth1_macvtap: entered promiscuous mode [ 242.620387][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.630867][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.640709][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.641256][T14286] infiniband syz0: RDMA CMA: cma_listen_on_dev, error -98 [ 242.651207][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.651224][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.651243][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.651255][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.698985][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.708990][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.719485][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.728769][T14287] loop2: detected capacity change from 0 to 512 [ 242.729325][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.746079][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.755937][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.759403][T14287] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 242.766569][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.766594][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 242.781441][T14287] EXT4-fs (loop2): 1 truncate cleaned up [ 242.786340][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.812913][T14025] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 242.828945][ T7727] EXT4-fs (loop6): Delayed block allocation failed for inode 18 at logical offset 2050 with max blocks 2048 with error 28 [ 242.841929][ T7727] EXT4-fs (loop6): This should not happen!! Data will be lost [ 242.841929][ T7727] [ 242.900705][T14286] lo speed is unknown, defaulting to 1000 [ 242.907820][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.918401][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.928388][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.938892][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.948824][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.959291][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.969201][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 242.979749][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 242.989633][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 243.000158][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 243.010128][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 243.020889][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 243.030736][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 243.041254][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 243.051448][T14025] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 243.061910][T14025] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 243.077638][ T29] kauditd_printk_skb: 566 callbacks suppressed [ 243.077679][ T29] audit: type=1400 audit(243.113:43688): avc: denied { connect } for pid=14297 comm="syz.2.3771" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 243.095517][T14025] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 243.110249][T14302] program syz.7.3704 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 243.121515][T14302] FAULT_INJECTION: forcing a failure. [ 243.121515][T14302] name failslab, interval 1, probability 0, space 0, times 0 [ 243.123453][T14283] lo speed is unknown, defaulting to 1000 [ 243.134373][T14302] CPU: 1 UID: 0 PID: 14302 Comm: syz.7.3704 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 243.134408][T14302] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 243.134423][T14302] Call Trace: [ 243.134430][T14302] [ 243.134440][T14302] dump_stack_lvl+0xf2/0x150 [ 243.134481][T14302] dump_stack+0x15/0x1a [ 243.153012][T14286] lo speed is unknown, defaulting to 1000 [ 243.161015][T14302] should_fail_ex+0x223/0x230 [ 243.161056][T14302] should_failslab+0x8f/0xb0 [ 243.171617][T14025] netdevsim netdevsim8 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 243.171945][T14302] __kmalloc_noprof+0xab/0x3f0 [ 243.176122][T14025] netdevsim netdevsim8 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 243.181795][T14302] ? bio_kmalloc+0x43/0x50 [ 243.181925][T14302] bio_kmalloc+0x43/0x50 [ 243.181970][T14302] blk_rq_map_kern+0x2a0/0x760 [ 243.181997][T14302] scsi_ioctl+0x13d7/0x1540 [ 243.186669][T14025] netdevsim netdevsim8 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 243.191325][T14302] ? avc_has_perm+0xd4/0x160 [ 243.200032][T14025] netdevsim netdevsim8 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 243.204759][T14302] ? file_has_perm+0x329/0x370 [ 243.204796][T14302] ? do_vfs_ioctl+0x96e/0x1530 [ 243.204825][T14302] sg_ioctl+0xda4/0x1870 [ 243.228681][T14286] lo speed is unknown, defaulting to 1000 [ 243.231524][T14302] ? __fget_files+0x17c/0x1c0 [ 243.231572][T14302] ? __pfx_sg_ioctl+0x10/0x10 [ 243.249725][T14283] lo speed is unknown, defaulting to 1000 [ 243.253559][T14302] __se_sys_ioctl+0xc9/0x140 [ 243.259225][T14286] lo speed is unknown, defaulting to 1000 [ 243.263111][T14302] __x64_sys_ioctl+0x43/0x50 [ 243.303556][T14302] x64_sys_call+0x1690/0x2dc0 [ 243.303586][T14302] do_syscall_64+0xc9/0x1c0 [ 243.303607][T14302] ? clear_bhb_loop+0x55/0xb0 [ 243.303629][T14302] ? clear_bhb_loop+0x55/0xb0 [ 243.303650][T14302] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 243.303716][T14302] RIP: 0033:0x7f4669015d29 [ 243.303734][T14302] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 243.303812][T14302] RSP: 002b:00007f4667681038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 243.303833][T14302] RAX: ffffffffffffffda RBX: 00007f4669205fa0 RCX: 00007f4669015d29 [ 243.303847][T14302] RDX: 0000000020000180 RSI: 0000000000000001 RDI: 0000000000000004 [ 243.303861][T14302] RBP: 00007f4667681090 R08: 0000000000000000 R09: 0000000000000000 [ 243.303874][T14302] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 243.303888][T14302] R13: 0000000000000000 R14: 00007f4669205fa0 R15: 00007ffd3226b258 [ 243.303909][T14302] [ 243.304406][ T29] audit: type=1400 audit(243.143:43689): avc: denied { read } for pid=14301 comm="syz.7.3704" name="sg0" dev="devtmpfs" ino=135 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 243.304448][ T29] audit: type=1400 audit(243.143:43690): avc: denied { open } for pid=14301 comm="syz.7.3704" path="/dev/sg0" dev="devtmpfs" ino=135 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 243.304484][ T29] audit: type=1326 audit(243.273:43691): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 243.304570][ T29] audit: type=1326 audit(243.273:43692): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=425 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 243.342337][ T29] audit: type=1326 audit(243.363:43693): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 243.342381][ T29] audit: type=1326 audit(243.363:43694): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 243.447847][T14286] lo speed is unknown, defaulting to 1000 [ 243.449854][ T29] audit: type=1326 audit(243.483:43695): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=425 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 243.499706][T14300] loop6: detected capacity change from 0 to 512 [ 243.522841][ T29] audit: type=1326 audit(243.523:43696): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=9 compat=0 ip=0x7f64e3ba5d63 code=0x7ffc0000 [ 243.609237][T14315] netlink: 'syz.8.3723': attribute type 29 has an invalid length. [ 243.621592][ T29] audit: type=1326 audit(243.523:43697): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14299 comm="syz.6.3770" exe="/root/syz-executor" sig=0 arch=c000003e syscall=9 compat=0 ip=0x7f64e3ba5d63 code=0x7ffc0000 [ 243.630973][T14286] lo speed is unknown, defaulting to 1000 [ 243.680057][T14300] EXT4-fs (loop6): encrypted files will use data=ordered instead of data journaling mode [ 243.688305][T14286] lo speed is unknown, defaulting to 1000 [ 243.704857][T14286] lo speed is unknown, defaulting to 1000 [ 243.711946][T14286] lo speed is unknown, defaulting to 1000 [ 243.719116][T14300] EXT4-fs (loop6): 1 truncate cleaned up [ 243.726236][T14286] lo speed is unknown, defaulting to 1000 [ 243.824502][T14331] 9pnet_fd: Insufficient options for proto=fd [ 244.150366][T14355] lo speed is unknown, defaulting to 1000 [ 244.160613][T14355] lo speed is unknown, defaulting to 1000 [ 244.190432][T14362] syz.4.3781[14362] is installing a program with bpf_probe_write_user helper that may corrupt user memory! [ 244.190531][T14362] syz.4.3781[14362] is installing a program with bpf_probe_write_user helper that may corrupt user memory! [ 244.214886][T14360] loop6: detected capacity change from 0 to 512 [ 244.240565][T14362] syz.4.3781[14362] is installing a program with bpf_probe_write_user helper that may corrupt user memory! [ 244.310720][T14360] EXT4-fs: Ignoring removed mblk_io_submit option [ 244.340279][T14360] EXT4-fs (loop6): couldn't mount as ext3 due to feature incompatibilities [ 244.381285][T14370] loop4: detected capacity change from 0 to 1024 [ 244.408308][T14370] EXT4-fs: Ignoring removed nobh option [ 244.414091][T14370] EXT4-fs: Ignoring removed nomblk_io_submit option [ 244.438531][T14370] ext4: Unknown parameter 'euid>00000000000000000000' [ 244.491497][T14379] 9pnet_fd: Insufficient options for proto=fd [ 244.532256][T14384] 9pnet_fd: Insufficient options for proto=fd [ 244.562919][T14388] loop6: detected capacity change from 0 to 2048 [ 244.636384][T14386] loop7: detected capacity change from 0 to 512 [ 244.644618][T14370] loop4: detected capacity change from 0 to 8192 [ 244.660158][T14386] EXT4-fs (loop7): encrypted files will use data=ordered instead of data journaling mode [ 244.702460][T14386] EXT4-fs (loop7): 1 truncate cleaned up [ 244.727673][T14400] 9pnet_fd: Insufficient options for proto=fd [ 244.898206][T14420] loop8: detected capacity change from 0 to 512 [ 244.904957][T14420] ext4: Unknown parameter 'fsuuid' [ 244.918608][T14420] netlink: 'syz.8.3793': attribute type 13 has an invalid length. [ 244.926550][T14420] netlink: 152 bytes leftover after parsing attributes in process `syz.8.3793'. [ 244.936262][T14420] syz_tun: refused to change device tx_queue_len [ 244.942762][T14420] A link change request failed with some changes committed already. Interface syz_tun may have been left with an inconsistent configuration, please check. [ 244.977798][T14419] loop6: detected capacity change from 0 to 512 [ 244.988295][T14420] hsr_slave_0 (unregistering): left promiscuous mode [ 245.008556][T14419] EXT4-fs (loop6): can't mount with commit=17542, fs mounted w/o journal [ 245.765470][T14487] lo speed is unknown, defaulting to 1000 [ 245.765718][T14487] lo speed is unknown, defaulting to 1000 [ 245.804519][T14492] loop7: detected capacity change from 0 to 512 [ 245.807321][T14492] EXT4-fs: Ignoring removed mblk_io_submit option [ 245.853486][T14492] EXT4-fs (loop7): couldn't mount as ext3 due to feature incompatibilities [ 245.991607][T14505] loop6: detected capacity change from 0 to 128 [ 245.996086][T14505] FAT-fs (loop6): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 246.032546][T14505] FAT-fs (loop6): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 246.073428][T14505] xt_hashlimit: size too large, truncated to 1048576 [ 246.160618][T14516] 9pnet_fd: Insufficient options for proto=fd [ 246.164524][T14514] loop7: detected capacity change from 0 to 1024 [ 246.427948][T14531] loop8: detected capacity change from 0 to 512 [ 246.512430][T14531] EXT4-fs (loop8): encrypted files will use data=ordered instead of data journaling mode [ 246.590422][T14531] EXT4-fs (loop8): 1 truncate cleaned up [ 246.727975][T14541] loop2: detected capacity change from 0 to 1024 [ 247.019292][T14568] netlink: 'syz.7.3801': attribute type 6 has an invalid length. [ 247.130424][T14572] lo speed is unknown, defaulting to 1000 [ 247.137342][T14575] loop7: detected capacity change from 0 to 512 [ 247.149802][T14572] lo speed is unknown, defaulting to 1000 [ 247.162629][T14575] EXT4-fs (loop7): can't mount with commit=17542, fs mounted w/o journal [ 247.201531][T14578] loop6: detected capacity change from 0 to 512 [ 247.232302][T14578] EXT4-fs: Ignoring removed mblk_io_submit option [ 247.270501][T14578] EXT4-fs (loop6): couldn't mount as ext3 due to feature incompatibilities [ 247.566024][T14603] loop6: detected capacity change from 0 to 128 [ 247.572892][T14603] FAT-fs (loop6): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 247.604112][T14603] FAT-fs (loop6): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 247.616603][T14603] xt_hashlimit: size too large, truncated to 1048576 [ 247.800805][T14541] netlink: 'syz.2.3807': attribute type 6 has an invalid length. [ 247.881978][T14625] loop8: detected capacity change from 0 to 512 [ 247.909636][T14632] loop2: detected capacity change from 0 to 512 [ 247.950382][T14625] EXT4-fs (loop8): encrypted files will use data=ordered instead of data journaling mode [ 247.976988][T14632] EXT4-fs error (device loop2): ext4_free_branches:1023: inode #11: comm syz.2.3818: invalid indirect mapped block 256 (level 2) [ 248.009887][T14625] EXT4-fs (loop8): 1 truncate cleaned up [ 248.052934][T14632] EXT4-fs (loop2): 2 truncates cleaned up [ 248.061346][T14625] EXT4-fs mount: 51 callbacks suppressed [ 248.061364][T14625] EXT4-fs (loop8): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 248.072064][T14632] EXT4-fs (loop2): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 248.089897][T14636] loop4: detected capacity change from 0 to 512 [ 248.092095][ T29] kauditd_printk_skb: 455 callbacks suppressed [ 248.092112][ T29] audit: type=1326 audit(248.123:44153): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14635 comm="syz.4.3819" exe="/root/syz-executor" sig=0 arch=c000003e syscall=16 compat=0 ip=0x7f94fe05592b code=0x7ffc0000 [ 248.154247][ T29] audit: type=1326 audit(248.153:44154): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14635 comm="syz.4.3819" exe="/root/syz-executor" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f94fe05498a code=0x7ffc0000 [ 248.178010][ T29] audit: type=1326 audit(248.153:44155): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14635 comm="syz.4.3819" exe="/root/syz-executor" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f94fe05498a code=0x7ffc0000 [ 248.201806][ T29] audit: type=1326 audit(248.153:44156): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14635 comm="syz.4.3819" exe="/root/syz-executor" sig=0 arch=c000003e syscall=258 compat=0 ip=0x7f94fe054597 code=0x7ffc0000 [ 248.226123][ T29] audit: type=1326 audit(248.153:44157): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14635 comm="syz.4.3819" exe="/root/syz-executor" sig=0 arch=c000003e syscall=165 compat=0 ip=0x7f94fe0574ca code=0x7ffc0000 [ 248.249988][ T29] audit: type=1326 audit(248.163:44158): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14624 comm="syz.8.3817" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7f3a159a4690 code=0x7ffc0000 [ 248.273792][ T29] audit: type=1326 audit(248.163:44159): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14624 comm="syz.8.3817" exe="/root/syz-executor" sig=0 arch=c000003e syscall=80 compat=0 ip=0x7f3a159a4a77 code=0x7ffc0000 [ 248.297764][ T29] audit: type=1326 audit(248.163:44160): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14624 comm="syz.8.3817" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7f3a159a4690 code=0x7ffc0000 [ 248.300072][T14636] EXT4-fs (loop4): encrypted files will use data=ordered instead of data journaling mode [ 248.321575][ T29] audit: type=1326 audit(248.163:44161): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14624 comm="syz.8.3817" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 248.355238][ T29] audit: type=1326 audit(248.163:44162): auid=4294967295 uid=0 gid=4294967040 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14624 comm="syz.8.3817" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 248.391541][T14646] Cannot find del_set index 0 as target [ 248.414932][T11848] EXT4-fs (loop2): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 248.426818][T14636] EXT4-fs (loop4): 1 truncate cleaned up [ 248.486957][T14636] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 248.543838][T14025] EXT4-fs (loop8): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 248.577607][T14667] loop7: detected capacity change from 0 to 1024 [ 248.586401][T14665] loop6: detected capacity change from 0 to 1024 [ 248.608829][T14667] EXT4-fs: dax option not supported [ 248.617924][T14665] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 248.640183][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 248.688048][T14677] vhci_hcd vhci_hcd.0: pdev(4) rhport(0) sockfd(3) [ 248.694610][T14677] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 248.702218][T14677] vhci_hcd vhci_hcd.0: Device attached [ 248.708905][T14675] lo speed is unknown, defaulting to 1000 [ 248.721787][T14675] lo speed is unknown, defaulting to 1000 [ 248.737305][T14681] loop8: detected capacity change from 0 to 512 [ 248.754842][T14681] EXT4-fs: Ignoring removed mblk_io_submit option [ 248.762866][T14681] EXT4-fs (loop8): couldn't mount as ext3 due to feature incompatibilities [ 248.817402][T14667] netlink: 96 bytes leftover after parsing attributes in process `syz.7.3824'. [ 248.978565][T14689] loop7: detected capacity change from 0 to 512 [ 249.030010][ T2962] usb 9-1: new low-speed USB device number 2 using vhci_hcd [ 249.045678][T14689] EXT4-fs (loop7): encrypted files will use data=ordered instead of data journaling mode [ 249.065973][T14689] EXT4-fs (loop7): 1 truncate cleaned up [ 249.086140][T14689] EXT4-fs (loop7): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 249.213331][T14705] loop8: detected capacity change from 0 to 512 [ 249.248243][T14705] EXT4-fs (loop8): encrypted files will use data=ordered instead of data journaling mode [ 249.271197][T14705] EXT4-fs (loop8): 1 truncate cleaned up [ 249.285547][T14705] EXT4-fs (loop8): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 249.307348][T13955] EXT4-fs (loop7): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 249.335066][T14658] netlink: 'syz.6.3821': attribute type 6 has an invalid length. [ 249.365130][T14025] EXT4-fs (loop8): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 249.386848][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 249.412297][T14717] vhci_hcd: invalid port number 61 [ 249.466551][T14721] netlink: 4 bytes leftover after parsing attributes in process `syz.2.3833'. [ 249.469212][T14724] loop6: detected capacity change from 0 to 128 [ 249.494690][T14721] netlink: 17 bytes leftover after parsing attributes in process `syz.2.3833'. [ 249.508529][T14678] vhci_hcd: connection reset by peer [ 249.511055][T14724] FAT-fs (loop6): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 249.530738][ T3386] vhci_hcd: stop threads [ 249.535024][ T3386] vhci_hcd: release socket [ 249.537123][T14724] FAT-fs (loop6): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 249.539474][ T3386] vhci_hcd: disconnect device [ 249.559539][T14724] xt_hashlimit: size too large, truncated to 1048576 [ 249.631491][T14732] lo speed is unknown, defaulting to 1000 [ 249.637651][T14732] lo speed is unknown, defaulting to 1000 [ 249.686471][T14739] loop7: detected capacity change from 0 to 512 [ 249.696542][T14739] EXT4-fs: Ignoring removed mblk_io_submit option [ 249.709538][T14736] lo speed is unknown, defaulting to 1000 [ 249.719305][T14736] lo speed is unknown, defaulting to 1000 [ 249.750273][T14739] EXT4-fs (loop7): couldn't mount as ext3 due to feature incompatibilities [ 249.811916][T14745] loop8: detected capacity change from 0 to 512 [ 249.825570][T14748] FAULT_INJECTION: forcing a failure. [ 249.825570][T14748] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 249.830357][T14745] EXT4-fs: Ignoring removed mblk_io_submit option [ 249.838679][T14748] CPU: 0 UID: 0 PID: 14748 Comm: syz.2.3839 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 249.855892][T14748] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 249.866015][T14748] Call Trace: [ 249.869381][T14748] [ 249.872375][T14748] dump_stack_lvl+0xf2/0x150 [ 249.877062][T14748] dump_stack+0x15/0x1a [ 249.881248][T14748] should_fail_ex+0x223/0x230 [ 249.886020][T14748] should_fail+0xb/0x10 [ 249.890214][T14748] should_fail_usercopy+0x1a/0x20 [ 249.895254][T14748] _copy_to_user+0x20/0xa0 [ 249.899751][T14748] simple_read_from_buffer+0xa0/0x110 [ 249.905288][T14748] proc_fail_nth_read+0xf9/0x140 [ 249.910382][T14748] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 249.915948][T14748] vfs_read+0x1a2/0x700 [ 249.920176][T14748] ? __rcu_read_unlock+0x4e/0x70 [ 249.925223][T14748] ? __fget_files+0x17c/0x1c0 [ 249.929989][T14748] ksys_read+0xe8/0x1b0 [ 249.934176][T14748] __x64_sys_read+0x42/0x50 [ 249.938712][T14748] x64_sys_call+0x2874/0x2dc0 [ 249.943491][T14748] do_syscall_64+0xc9/0x1c0 [ 249.948178][T14748] ? clear_bhb_loop+0x55/0xb0 [ 249.952937][T14748] ? clear_bhb_loop+0x55/0xb0 [ 249.957622][T14748] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 249.963664][T14748] RIP: 0033:0x7f26e97b473c [ 249.968142][T14748] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 249.987767][T14748] RSP: 002b:00007f26e7e27030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 249.996189][T14748] RAX: ffffffffffffffda RBX: 00007f26e99a5fa0 RCX: 00007f26e97b473c [ 250.004166][T14748] RDX: 000000000000000f RSI: 00007f26e7e270a0 RDI: 0000000000000005 [ 250.012152][T14748] RBP: 00007f26e7e27090 R08: 0000000000000000 R09: 0000000000000000 [ 250.020131][T14748] R10: 0000000000000042 R11: 0000000000000246 R12: 0000000000000001 [ 250.028128][T14748] R13: 0000000000000000 R14: 00007f26e99a5fa0 R15: 00007fff058eb878 [ 250.036116][T14748] [ 250.120812][T14745] EXT4-fs (loop8): couldn't mount as ext3 due to feature incompatibilities [ 250.327523][T14761] loop4: detected capacity change from 0 to 1024 [ 250.382003][T14761] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 250.467815][T14772] loop2: detected capacity change from 0 to 2048 [ 250.616254][T14783] team0 (unregistering): Port device team_slave_0 removed [ 250.638289][T14783] team0 (unregistering): Port device team_slave_1 removed [ 250.871134][T14790] loop8: detected capacity change from 0 to 1024 [ 250.889440][T14799] lo speed is unknown, defaulting to 1000 [ 250.905776][T14799] lo speed is unknown, defaulting to 1000 [ 250.913275][T14790] EXT4-fs (loop8): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 250.976978][T14804] loop2: detected capacity change from 0 to 512 [ 251.026608][T14804] EXT4-fs: Ignoring removed mblk_io_submit option [ 251.033724][T14761] netlink: 'syz.4.3842': attribute type 6 has an invalid length. [ 251.055122][T14804] EXT4-fs (loop2): couldn't mount as ext3 due to feature incompatibilities [ 251.057184][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 251.171507][T14822] netlink: 24 bytes leftover after parsing attributes in process `syz.4.3854'. [ 251.209203][T14822] loop4: detected capacity change from 0 to 128 [ 251.273312][T14825] loop6: detected capacity change from 0 to 2048 [ 251.578258][T14843] loop2: detected capacity change from 0 to 512 [ 251.600448][T14841] team0 (unregistering): Port device team_slave_0 removed [ 251.618878][T14841] team0 (unregistering): Port device team_slave_1 removed [ 251.633294][T14854] loop4: detected capacity change from 0 to 512 [ 251.643761][T14843] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 251.647833][T14855] loop6: detected capacity change from 0 to 1024 [ 251.672348][T14854] EXT4-fs error (device loop4): ext4_free_branches:1023: inode #11: comm syz.4.3866: invalid indirect mapped block 256 (level 2) [ 251.698586][T14843] EXT4-fs (loop2): 1 truncate cleaned up [ 251.727330][T14843] EXT4-fs (loop2): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 251.750145][T14790] netlink: 'syz.8.3848': attribute type 6 has an invalid length. [ 251.785228][T14025] EXT4-fs (loop8): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 251.798625][T14854] EXT4-fs (loop4): 2 truncates cleaned up [ 251.808558][T14854] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 251.865370][T14855] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 251.886463][T11848] EXT4-fs (loop2): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 251.901393][T14864] loop8: detected capacity change from 0 to 2048 [ 251.913924][T14864] msdos: Unknown parameter 'ÿ18446744073709551615ÿÿÿÿ' [ 251.921938][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 251.949871][T14870] FAULT_INJECTION: forcing a failure. [ 251.949871][T14870] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 251.963043][T14870] CPU: 0 UID: 0 PID: 14870 Comm: syz.2.3869 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 251.973832][T14870] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 251.984053][T14870] Call Trace: [ 251.987416][T14870] [ 251.990383][T14870] dump_stack_lvl+0xf2/0x150 [ 251.995110][T14870] dump_stack+0x15/0x1a [ 251.999383][T14870] should_fail_ex+0x223/0x230 [ 252.004109][T14870] should_fail+0xb/0x10 [ 252.008294][T14870] should_fail_usercopy+0x1a/0x20 [ 252.013388][T14870] _copy_to_user+0x20/0xa0 [ 252.017916][T14870] simple_read_from_buffer+0xa0/0x110 [ 252.023351][T14870] proc_fail_nth_read+0xf9/0x140 [ 252.028355][T14870] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 252.034018][T14870] vfs_read+0x1a2/0x700 [ 252.038226][T14870] ? __rcu_read_unlock+0x4e/0x70 [ 252.043222][T14870] ? __fget_files+0x17c/0x1c0 [ 252.048008][T14870] ksys_read+0xe8/0x1b0 [ 252.052328][T14870] __x64_sys_read+0x42/0x50 [ 252.056979][T14870] x64_sys_call+0x2874/0x2dc0 [ 252.061748][T14870] do_syscall_64+0xc9/0x1c0 [ 252.066367][T14870] ? clear_bhb_loop+0x55/0xb0 [ 252.071073][T14870] ? clear_bhb_loop+0x55/0xb0 [ 252.075783][T14870] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 252.081852][T14870] RIP: 0033:0x7f26e97b473c [ 252.086324][T14870] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 252.106139][T14870] RSP: 002b:00007f26e7e27030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 252.114599][T14870] RAX: ffffffffffffffda RBX: 00007f26e99a5fa0 RCX: 00007f26e97b473c [ 252.122672][T14870] RDX: 000000000000000f RSI: 00007f26e7e270a0 RDI: 0000000000000005 [ 252.130716][T14870] RBP: 00007f26e7e27090 R08: 0000000000000000 R09: 0000000000000000 [ 252.138756][T14870] R10: 0000000000000019 R11: 0000000000000246 R12: 0000000000000001 [ 252.146768][T14870] R13: 0000000000000000 R14: 00007f26e99a5fa0 R15: 00007fff058eb878 [ 252.154798][T14870] [ 252.330030][T14882] loop8: detected capacity change from 0 to 512 [ 252.345192][T14882] EXT4-fs: Ignoring removed mblk_io_submit option [ 252.349132][T14883] lo speed is unknown, defaulting to 1000 [ 252.357960][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 252.373470][T14886] loop2: detected capacity change from 0 to 512 [ 252.381023][T14882] EXT4-fs (loop8): couldn't mount as ext3 due to feature incompatibilities [ 252.394024][T14886] EXT4-fs: Ignoring removed mblk_io_submit option [ 252.402039][T14883] lo speed is unknown, defaulting to 1000 [ 252.419773][T14877] lo speed is unknown, defaulting to 1000 [ 252.435552][T14886] EXT4-fs (loop2): couldn't mount as ext3 due to feature incompatibilities [ 252.444738][T14877] lo speed is unknown, defaulting to 1000 [ 252.473508][T14892] loop6: detected capacity change from 0 to 512 [ 252.514673][T14892] EXT4-fs error (device loop6): ext4_free_branches:1023: inode #11: comm syz.6.3876: invalid indirect mapped block 256 (level 2) [ 252.549065][T14892] EXT4-fs (loop6): 2 truncates cleaned up [ 252.555510][T14890] veth0_vlan: entered allmulticast mode [ 252.555588][T14892] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 252.607262][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 252.646372][T14894] ÿÿÿÿÿÿ: renamed from vlan1 [ 252.754176][T14906] loop8: detected capacity change from 0 to 512 [ 252.781328][T14906] EXT4-fs (loop8): can't mount with commit=17542, fs mounted w/o journal [ 252.863780][T14909] loop6: detected capacity change from 0 to 2048 [ 252.889004][T14912] loop8: detected capacity change from 0 to 1764 [ 252.942801][T14921] netlink: 8 bytes leftover after parsing attributes in process `syz.2.3887'. [ 252.960974][T14912] netlink: 76 bytes leftover after parsing attributes in process `syz.8.3883'. [ 252.964642][T14919] lo speed is unknown, defaulting to 1000 [ 252.973799][T14912] netlink: 8 bytes leftover after parsing attributes in process `syz.8.3883'. [ 252.997113][T14919] lo speed is unknown, defaulting to 1000 [ 253.016592][T14924] loop2: detected capacity change from 0 to 512 [ 253.025214][T14923] loop6: detected capacity change from 0 to 512 [ 253.035275][T14924] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 253.044890][T14923] EXT4-fs: Ignoring removed mblk_io_submit option [ 253.059802][T14923] EXT4-fs (loop6): couldn't mount as ext3 due to feature incompatibilities [ 253.068032][T14924] EXT4-fs (loop2): 1 truncate cleaned up [ 253.088937][T14924] EXT4-fs (loop2): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 253.112311][ T29] kauditd_printk_skb: 725 callbacks suppressed [ 253.112328][ T29] audit: type=1326 audit(253.153:44888): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14918 comm="syz.6.3886" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 253.142295][ T29] audit: type=1326 audit(253.163:44889): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14929 comm="syz.8.3889" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f3a159a5d29 code=0x0 [ 253.165336][ T29] audit: type=1326 audit(253.183:44890): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14918 comm="syz.6.3886" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 253.345512][T11848] EXT4-fs (loop2): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 253.387492][ T29] audit: type=1400 audit(253.423:44891): avc: denied { create } for pid=14934 comm="syz.2.3891" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 253.408477][ T29] audit: type=1400 audit(253.443:44892): avc: denied { bind } for pid=14934 comm="syz.2.3891" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 253.427616][ T29] audit: type=1400 audit(253.443:44893): avc: denied { listen } for pid=14934 comm="syz.2.3891" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 253.427715][ T29] audit: type=1400 audit(253.443:44894): avc: denied { accept } for pid=14934 comm="syz.2.3891" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 253.428543][ T29] audit: type=1326 audit(253.453:44895): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14936 comm="syz.6.3892" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 253.489968][ T29] audit: type=1326 audit(253.453:44896): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14936 comm="syz.6.3892" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 253.513123][ T29] audit: type=1326 audit(253.453:44897): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=14936 comm="syz.6.3892" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 253.608802][T14941] loop7: detected capacity change from 0 to 512 [ 253.623923][T14941] EXT4-fs (loop7): can't mount with commit=17542, fs mounted w/o journal [ 253.698536][T14946] loop7: detected capacity change from 0 to 2048 [ 253.789884][T14956] netlink: 24 bytes leftover after parsing attributes in process `syz.6.3900'. [ 253.813406][T14958] FAULT_INJECTION: forcing a failure. [ 253.813406][T14958] name failslab, interval 1, probability 0, space 0, times 0 [ 253.826260][T14958] CPU: 0 UID: 0 PID: 14958 Comm: syz.7.3901 Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 253.837060][T14958] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 253.847171][T14958] Call Trace: [ 253.850462][T14958] [ 253.853400][T14958] dump_stack_lvl+0xf2/0x150 [ 253.858032][T14958] dump_stack+0x15/0x1a [ 253.862212][T14958] should_fail_ex+0x223/0x230 [ 253.866945][T14958] should_failslab+0x8f/0xb0 [ 253.871559][T14958] kmem_cache_alloc_noprof+0x52/0x320 [ 253.876977][T14958] ? audit_log_start+0x34c/0x6b0 [ 253.882011][T14958] audit_log_start+0x34c/0x6b0 [ 253.886927][T14958] audit_seccomp+0x4b/0x130 [ 253.891447][T14958] __seccomp_filter+0x6fa/0x1180 [ 253.896408][T14958] ? __pfx_proc_fail_nth_write+0x10/0x10 [ 253.902081][T14958] ? vfs_write+0x596/0x920 [ 253.906514][T14958] ? __schedule+0x6fa/0x930 [ 253.911052][T14958] __secure_computing+0x9f/0x1c0 [ 253.916075][T14958] syscall_trace_enter+0xd1/0x1f0 [ 253.921219][T14958] do_syscall_64+0xaa/0x1c0 [ 253.925732][T14958] ? clear_bhb_loop+0x55/0xb0 [ 253.930448][T14958] ? clear_bhb_loop+0x55/0xb0 [ 253.935196][T14958] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 253.941117][T14958] RIP: 0033:0x7f4669015d29 [ 253.945582][T14958] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 253.965331][T14958] RSP: 002b:00007f4667681038 EFLAGS: 00000246 ORIG_RAX: 0000000000000071 [ 253.973832][T14958] RAX: ffffffffffffffda RBX: 00007f4669205fa0 RCX: 00007f4669015d29 [ 253.981881][T14958] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 253.989955][T14958] RBP: 00007f4667681090 R08: 0000000000000000 R09: 0000000000000000 [ 253.997936][T14958] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 254.005915][T14958] R13: 0000000000000000 R14: 00007f4669205fa0 R15: 00007ffd3226b258 [ 254.013963][T14958] [ 254.090482][ T2962] usb 9-1: enqueue for inactive port 0 [ 254.100469][ T2962] usb 9-1: enqueue for inactive port 0 [ 254.115851][T14966] loop8: detected capacity change from 0 to 512 [ 254.161120][T14966] EXT4-fs (loop8): can't mount with commit=17542, fs mounted w/o journal [ 254.170062][ T2962] vhci_hcd: vhci_device speed not set [ 254.246014][T14973] netlink: 12 bytes leftover after parsing attributes in process `syz.6.3907'. [ 254.325443][T14982] netlink: 12 bytes leftover after parsing attributes in process `syz.6.3911'. [ 254.559826][T14998] lo speed is unknown, defaulting to 1000 [ 254.566541][T15002] loop4: detected capacity change from 0 to 512 [ 254.587904][T15005] loop2: detected capacity change from 0 to 512 [ 254.587947][T14998] lo speed is unknown, defaulting to 1000 [ 254.612509][T15005] EXT4-fs: Ignoring removed mblk_io_submit option [ 254.622137][T15002] EXT4-fs (loop4): can't mount with commit=17542, fs mounted w/o journal [ 254.650700][T15005] EXT4-fs (loop2): couldn't mount as ext3 due to feature incompatibilities [ 254.671280][T15011] netlink: 8 bytes leftover after parsing attributes in process `syz.8.3921'. [ 254.754547][T15011] netlink: 36 bytes leftover after parsing attributes in process `syz.8.3921'. [ 254.754903][T15014] lo speed is unknown, defaulting to 1000 [ 254.763709][T15011] netlink: 36 bytes leftover after parsing attributes in process `syz.8.3921'. [ 254.777025][T15014] lo speed is unknown, defaulting to 1000 [ 254.787099][T15017] loop4: detected capacity change from 0 to 512 [ 254.794786][T15017] EXT4-fs: Ignoring removed mblk_io_submit option [ 254.809572][T15017] EXT4-fs (loop4): couldn't mount as ext3 due to feature incompatibilities [ 255.924668][T15037] 9pnet_fd: Insufficient options for proto=fd [ 256.172814][T15049] loop6: detected capacity change from 0 to 128 [ 256.188126][T15049] FAT-fs (loop6): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 256.190627][T15051] __nla_validate_parse: 7 callbacks suppressed [ 256.190647][T15051] netlink: 44 bytes leftover after parsing attributes in process `syz.8.3935'. [ 256.242340][T15049] FAT-fs (loop6): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 256.272359][T15054] loop7: detected capacity change from 0 to 512 [ 256.278992][T15054] EXT4-fs: Ignoring removed orlov option [ 256.303865][T15049] xt_hashlimit: size too large, truncated to 1048576 [ 256.312772][T15054] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 256.440720][T15054] EXT4-fs (loop7): orphan cleanup on readonly fs [ 256.476928][T15054] EXT4-fs error (device loop7): ext4_validate_block_bitmap:441: comm syz.7.3937: bg 0: block 248: padding at end of block bitmap is not set [ 256.519486][T15054] EXT4-fs error (device loop7): ext4_acquire_dquot:6938: comm syz.7.3937: Failed to acquire dquot type 1 [ 256.635585][T15054] EXT4-fs (loop7): 1 truncate cleaned up [ 256.699690][T15070] loop4: detected capacity change from 0 to 512 [ 256.759536][T15070] EXT4-fs (loop4): encrypted files will use data=ordered instead of data journaling mode [ 256.842499][T15070] EXT4-fs (loop4): 1 truncate cleaned up [ 256.874639][T15070] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 256.994291][T15054] EXT4-fs (loop7): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 257.027160][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 257.056881][T15074] netlink: 12 bytes leftover after parsing attributes in process `syz.2.3943'. [ 257.096897][T15076] loop4: detected capacity change from 0 to 512 [ 257.112119][T13955] EXT4-fs (loop7): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 257.125621][T15076] [EXT4 FS bs=4096, gc=1, bpg=32768, ipg=32, mo=8856c01c, mo2=0002] [ 257.133867][T15076] EXT4-fs (loop4): orphan cleanup on readonly fs [ 257.170254][T15076] EXT4-fs warning (device loop4): ext4_enable_quotas:7156: Failed to enable quota tracking (type=2, err=-22, ino=15). Please run e2fsck to fix. [ 257.247485][T15076] EXT4-fs (loop4): Cannot turn on quotas: error -22 [ 257.273757][T15076] EXT4-fs error (device loop4): ext4_ext_check_inode:524: inode #13: comm syz.4.3944: pblk 0 bad header/extent: invalid extent entries - magic f30a, entries 1, max 4(4), depth 0(0) [ 257.328252][T15076] EXT4-fs error (device loop4): ext4_orphan_get:1394: comm syz.4.3944: couldn't read orphan inode 13 (err -117) [ 257.348056][T15076] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 257.370220][T15076] EXT4-fs (loop4): warning: mounting fs with errors, running e2fsck is recommended [ 257.393824][T15076] [EXT4 FS bs=4096, gc=1, bpg=32768, ipg=32, mo=8856c01c, mo2=0002] [ 257.419786][T15076] EXT4-fs warning (device loop4): ext4_enable_quotas:7156: Failed to enable quota tracking (type=2, err=-22, ino=15). Please run e2fsck to fix. [ 257.467012][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 257.548273][T15109] lo speed is unknown, defaulting to 1000 [ 257.554931][T15109] lo speed is unknown, defaulting to 1000 [ 257.598412][T15111] loop7: detected capacity change from 0 to 512 [ 257.606306][T15111] EXT4-fs: Ignoring removed mblk_io_submit option [ 257.617579][T15111] EXT4-fs (loop7): couldn't mount as ext3 due to feature incompatibilities [ 258.188967][T15117] netlink: 24 bytes leftover after parsing attributes in process `syz.8.3959'. [ 258.427433][T15124] loop4: detected capacity change from 0 to 128 [ 258.437284][ T29] kauditd_printk_skb: 719 callbacks suppressed [ 258.437302][ T29] audit: type=1326 audit(258.473:45613): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.466713][ T29] audit: type=1326 audit(258.473:45614): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=172 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.490101][ T29] audit: type=1326 audit(258.473:45615): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.490632][T15124] FAT-fs (loop4): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 258.513256][ T29] audit: type=1326 audit(258.473:45616): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.545384][T15130] lo speed is unknown, defaulting to 1000 [ 258.548081][ T29] audit: type=1326 audit(258.473:45617): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.554397][T15130] lo speed is unknown, defaulting to 1000 [ 258.576829][ T29] audit: type=1326 audit(258.473:45618): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.576868][ T29] audit: type=1326 audit(258.473:45619): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.593234][T15124] FAT-fs (loop4): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 258.605799][ T29] audit: type=1326 audit(258.473:45620): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=82 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.660951][ T29] audit: type=1326 audit(258.473:45621): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.684224][ T29] audit: type=1326 audit(258.473:45622): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15120 comm="syz.8.3961" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f3a159a5d29 code=0x7ffc0000 [ 258.708604][T15124] xt_hashlimit: size too large, truncated to 1048576 [ 258.718084][T15133] loop6: detected capacity change from 0 to 512 [ 258.728679][T15133] EXT4-fs: Ignoring removed mblk_io_submit option [ 258.739676][T15133] EXT4-fs (loop6): couldn't mount as ext3 due to feature incompatibilities [ 258.926690][T15139] sctp: [Deprecated]: syz.7.3966 (pid 15139) Use of struct sctp_assoc_value in delayed_ack socket option. [ 258.926690][T15139] Use struct sctp_sack_info instead [ 259.211102][T15151] netlink: 12 bytes leftover after parsing attributes in process `syz.6.3970'. [ 259.304496][T15154] loop8: detected capacity change from 0 to 128 [ 259.337902][T15154] FAT-fs (loop8): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 259.381610][T15154] FAT-fs (loop8): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 259.402240][T15154] xt_hashlimit: size too large, truncated to 1048576 [ 259.411640][T15160] netlink: 'syz.7.3969': attribute type 1 has an invalid length. [ 259.419411][T15160] netlink: 16166 bytes leftover after parsing attributes in process `syz.7.3969'. [ 259.741812][T15176] 9pnet_fd: Insufficient options for proto=fd [ 259.858403][T15183] loop6: detected capacity change from 0 to 512 [ 259.875708][T15183] [EXT4 FS bs=4096, gc=1, bpg=32768, ipg=32, mo=8856c01c, mo2=0002] [ 259.904067][T15183] EXT4-fs (loop6): orphan cleanup on readonly fs [ 259.926706][T15183] EXT4-fs warning (device loop6): ext4_enable_quotas:7156: Failed to enable quota tracking (type=2, err=-22, ino=15). Please run e2fsck to fix. [ 259.955517][T15183] EXT4-fs (loop6): Cannot turn on quotas: error -22 [ 259.971917][T15183] EXT4-fs error (device loop6): ext4_ext_check_inode:524: inode #13: comm syz.6.3982: pblk 0 bad header/extent: invalid extent entries - magic f30a, entries 1, max 4(4), depth 0(0) [ 260.005592][T15183] EXT4-fs error (device loop6): ext4_orphan_get:1394: comm syz.6.3982: couldn't read orphan inode 13 (err -117) [ 260.038516][T15183] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 260.068001][T15183] EXT4-fs (loop6): warning: mounting fs with errors, running e2fsck is recommended [ 260.084969][T15183] [EXT4 FS bs=4096, gc=1, bpg=32768, ipg=32, mo=8856c01c, mo2=0002] [ 260.100935][T15183] EXT4-fs warning (device loop6): ext4_enable_quotas:7156: Failed to enable quota tracking (type=2, err=-22, ino=15). Please run e2fsck to fix. [ 260.136839][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 260.439055][T15209] 9pnet_fd: Insufficient options for proto=fd [ 260.475494][T15211] netlink: 24 bytes leftover after parsing attributes in process `syz.2.3993'. [ 260.552026][T15219] loop6: detected capacity change from 0 to 764 [ 260.557577][T15217] loop2: detected capacity change from 0 to 512 [ 260.565722][T15219] rock: corrupted directory entry. extent=32, offset=2044, size=237 [ 260.566237][T15217] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 260.596660][T15217] EXT4-fs (loop2): 1 truncate cleaned up [ 260.605344][T15217] EXT4-fs (loop2): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 260.666530][T11848] EXT4-fs (loop2): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 260.715984][T15231] netlink: 12 bytes leftover after parsing attributes in process `syz.6.4000'. [ 260.930768][T15248] lo speed is unknown, defaulting to 1000 [ 260.936814][T15248] lo speed is unknown, defaulting to 1000 [ 260.980683][T15251] loop2: detected capacity change from 0 to 512 [ 261.000855][T15251] EXT4-fs: Ignoring removed mblk_io_submit option [ 261.028814][T15251] EXT4-fs (loop2): couldn't mount as ext3 due to feature incompatibilities [ 261.377892][T15259] loop7: detected capacity change from 0 to 128 [ 261.499734][T15259] FAT-fs (loop7): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 261.584150][T15259] FAT-fs (loop7): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 261.605913][T15259] xt_hashlimit: size too large, truncated to 1048576 [ 262.110673][T15268] tmpfs: Bad value for 'mpol' [ 262.365525][T15278] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(3) [ 262.372091][T15278] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 262.379778][T15278] vhci_hcd vhci_hcd.0: Device attached [ 262.388171][T15280] netlink: 64859 bytes leftover after parsing attributes in process `syz.6.4011'. [ 262.425335][T15283] loop8: detected capacity change from 0 to 2048 [ 262.493277][T15283] EXT4-fs (loop8): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none. [ 262.508157][T15283] vhci_hcd: invalid port number 61 [ 262.527765][T14025] EXT4-fs (loop8): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 262.619988][ T1033] usb 5-1: new low-speed USB device number 2 using vhci_hcd [ 262.721470][T15298] loop6: detected capacity change from 0 to 512 [ 262.741876][T15298] EXT4-fs (loop6): can't mount with commit=17542, fs mounted w/o journal [ 262.760222][T15300] xt_hashlimit: size too large, truncated to 1048576 [ 262.837422][T15307] netlink: 12 bytes leftover after parsing attributes in process `syz.7.4029'. [ 262.989825][T15319] loop7: detected capacity change from 0 to 512 [ 263.006289][T15319] EXT4-fs error (device loop7): ext4_free_branches:1023: inode #11: comm syz.7.4033: invalid indirect mapped block 256 (level 2) [ 263.026483][T15319] EXT4-fs (loop7): 2 truncates cleaned up [ 263.033025][T15319] EXT4-fs (loop7): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 263.066696][T13955] EXT4-fs (loop7): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 263.192889][T15279] vhci_hcd: connection reset by peer [ 263.198959][ T55] vhci_hcd: stop threads [ 263.203284][ T55] vhci_hcd: release socket [ 263.207717][ T55] vhci_hcd: disconnect device [ 263.210559][T15332] netlink: 24 bytes leftover after parsing attributes in process `syz.8.4038'. [ 263.615425][ T29] kauditd_printk_skb: 632 callbacks suppressed [ 263.615511][ T29] audit: type=1400 audit(263.633:46255): avc: denied { connect } for pid=15339 comm="syz.4.4040" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_netfilter_socket permissive=1 [ 263.905258][ T29] audit: type=1326 audit(263.933:46256): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 263.928535][ T29] audit: type=1326 audit(263.943:46257): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 263.951586][ T29] audit: type=1326 audit(263.943:46258): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 263.974661][ T29] audit: type=1326 audit(263.943:46259): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=85 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 263.980607][T15374] loop6: detected capacity change from 0 to 512 [ 263.997713][ T29] audit: type=1326 audit(263.943:46260): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 264.027152][ T29] audit: type=1326 audit(263.943:46261): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=41 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 264.029760][T15374] EXT4-fs error (device loop6): ext4_free_branches:1023: inode #11: comm syz.6.4044: invalid indirect mapped block 256 (level 2) [ 264.050529][ T29] audit: type=1326 audit(263.943:46262): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 264.076052][T15374] EXT4-fs (loop6): 2 truncates cleaned up [ 264.086808][ T29] audit: type=1326 audit(263.943:46263): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 264.095832][T15374] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 264.115351][ T29] audit: type=1326 audit(263.943:46264): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15370 comm="syz.2.4043" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f26e97b5d29 code=0x7ffc0000 [ 264.319149][T15387] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(3) [ 264.325719][T15387] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 264.333371][T15387] vhci_hcd vhci_hcd.0: Device attached [ 264.334729][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 264.394946][T15399] xt_hashlimit: size too large, truncated to 1048576 [ 264.974414][T15439] netlink: 24 bytes leftover after parsing attributes in process `syz.8.4052'. [ 265.080037][T15450] vhci_hcd vhci_hcd.0: pdev(8) rhport(0) sockfd(3) [ 265.086604][T15450] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 265.094186][T15450] vhci_hcd vhci_hcd.0: Device attached [ 265.137187][T15389] vhci_hcd: connection closed [ 265.137363][ T7727] vhci_hcd: stop threads [ 265.146406][ T7727] vhci_hcd: release socket [ 265.150970][ T7727] vhci_hcd: disconnect device [ 265.205096][T15466] loop6: detected capacity change from 0 to 128 [ 265.215300][T15466] EXT4-fs (loop6): mounted filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09 r/w without journal. Quota mode: none. [ 265.235737][T15466] SELinux: failed to load policy [ 265.256145][T13687] EXT4-fs (loop6): unmounting filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09. [ 265.339970][ T3373] usb 17-1: new low-speed USB device number 2 using vhci_hcd [ 265.477865][T15496] loop4: detected capacity change from 0 to 512 [ 265.501298][T15496] EXT4-fs (loop4): can't mount with commit=17542, fs mounted w/o journal [ 265.615545][T15514] loop4: detected capacity change from 0 to 512 [ 265.625145][T15514] EXT4-fs error (device loop4): ext4_free_branches:1023: inode #11: comm syz.4.4058: invalid indirect mapped block 256 (level 2) [ 265.640992][T15514] EXT4-fs (loop4): 2 truncates cleaned up [ 265.651339][T15514] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 265.683707][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 265.786472][T15532] loop4: detected capacity change from 0 to 512 [ 265.800492][T15532] EXT4-fs: Ignoring removed orlov option [ 265.814652][T15532] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 265.829311][T15532] EXT4-fs (loop4): orphan cleanup on readonly fs [ 265.846542][T15532] EXT4-fs error (device loop4): ext4_validate_block_bitmap:441: comm syz.4.4062: bg 0: block 248: padding at end of block bitmap is not set [ 265.877053][T15532] EXT4-fs error (device loop4): ext4_acquire_dquot:6938: comm syz.4.4062: Failed to acquire dquot type 1 [ 265.899426][T15453] vhci_hcd: connection reset by peer [ 265.905418][ T3410] vhci_hcd: stop threads [ 265.909793][ T3410] vhci_hcd: release socket [ 265.914275][ T3410] vhci_hcd: disconnect device [ 265.928999][T15532] EXT4-fs (loop4): 1 truncate cleaned up [ 265.938107][T15532] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 266.008317][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 266.087616][T15562] netlink: 12 bytes leftover after parsing attributes in process `syz.2.4066'. [ 266.161961][T15566] loop6: detected capacity change from 0 to 512 [ 266.181108][T15566] EXT4-fs (loop6): can't mount with commit=17542, fs mounted w/o journal [ 266.257292][T15573] loop6: detected capacity change from 0 to 512 [ 266.266259][T15573] EXT4-fs: Ignoring removed orlov option [ 266.274518][T15573] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 266.285182][T15573] EXT4-fs (loop6): orphan cleanup on readonly fs [ 266.294540][T15573] EXT4-fs error (device loop6): ext4_validate_block_bitmap:441: comm syz.6.4070: bg 0: block 248: padding at end of block bitmap is not set [ 266.309184][T15573] EXT4-fs error (device loop6): ext4_acquire_dquot:6938: comm syz.6.4070: Failed to acquire dquot type 1 [ 266.321770][T15573] EXT4-fs (loop6): 1 truncate cleaned up [ 266.329034][T15573] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 266.402580][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 266.565470][T15595] netlink: 32 bytes leftover after parsing attributes in process `syz.7.4078'. [ 266.713165][T15604] loop8: detected capacity change from 0 to 1024 [ 266.733474][T15609] pimreg: entered allmulticast mode [ 266.741396][T15604] EXT4-fs (loop8): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 266.772896][T15609] pimreg: left allmulticast mode [ 266.862525][T15617] loop7: detected capacity change from 0 to 512 [ 266.879323][T15617] EXT4-fs: Ignoring removed orlov option [ 266.889437][T15617] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 266.891544][T15617] EXT4-fs (loop7): orphan cleanup on readonly fs [ 266.893022][T15617] EXT4-fs error (device loop7): ext4_validate_block_bitmap:441: comm syz.7.4087: bg 0: block 248: padding at end of block bitmap is not set [ 266.893436][T15617] EXT4-fs error (device loop7): ext4_acquire_dquot:6938: comm syz.7.4087: Failed to acquire dquot type 1 [ 266.895163][T15617] EXT4-fs (loop7): 1 truncate cleaned up [ 266.896863][T15617] EXT4-fs (loop7): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 266.958955][T15622] loop4: detected capacity change from 0 to 1024 [ 267.022216][T13955] EXT4-fs (loop7): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 267.039262][T15622] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 267.079635][T15627] netlink: 12 bytes leftover after parsing attributes in process `syz.2.4091'. [ 267.347574][T15604] netlink: 'syz.8.4083': attribute type 6 has an invalid length. [ 267.378498][T14025] EXT4-fs (loop8): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 267.528712][T15652] loop6: detected capacity change from 0 to 512 [ 267.539759][T15652] EXT4-fs: Ignoring removed orlov option [ 267.548616][T15652] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 267.558484][T15652] EXT4-fs (loop6): orphan cleanup on readonly fs [ 267.567419][T15652] EXT4-fs error (device loop6): ext4_validate_block_bitmap:441: comm syz.6.4101: bg 0: block 248: padding at end of block bitmap is not set [ 267.584531][T15652] EXT4-fs error (device loop6): ext4_acquire_dquot:6938: comm syz.6.4101: Failed to acquire dquot type 1 [ 267.598531][T15652] EXT4-fs (loop6): 1 truncate cleaned up [ 267.607275][T15652] EXT4-fs (loop6): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 267.653327][T13687] EXT4-fs (loop6): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 267.675962][T15655] netlink: 12 bytes leftover after parsing attributes in process `syz.6.4102'. [ 267.690007][ T1033] usb 5-1: enqueue for inactive port 0 [ 267.696015][ T1033] usb 5-1: enqueue for inactive port 0 [ 267.772573][ T1033] vhci_hcd: vhci_device speed not set [ 267.778943][T15619] netlink: 'syz.4.4089': attribute type 6 has an invalid length. [ 267.800579][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 267.857382][T15662] loop4: detected capacity change from 0 to 1024 [ 267.868080][T15662] EXT4-fs (loop4): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback. [ 268.250682][T15662] netlink: 'syz.4.4105': attribute type 6 has an invalid length. [ 268.274672][T11178] EXT4-fs (loop4): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 268.387932][T15680] loop7: detected capacity change from 0 to 512 [ 268.405161][T15680] EXT4-fs: Ignoring removed orlov option [ 268.421567][T15680] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 268.432803][T15680] EXT4-fs (loop7): orphan cleanup on readonly fs [ 268.445497][T15680] EXT4-fs error (device loop7): ext4_validate_block_bitmap:441: comm syz.7.4112: bg 0: block 248: padding at end of block bitmap is not set [ 268.461736][T15683] vhci_hcd: invalid port number 61 [ 268.463017][T15680] EXT4-fs error (device loop7): ext4_acquire_dquot:6938: comm syz.7.4112: Failed to acquire dquot type 1 [ 268.497656][T15680] EXT4-fs (loop7): 1 truncate cleaned up [ 268.516786][T15692] loop4: detected capacity change from 0 to 128 [ 268.518594][T15680] EXT4-fs (loop7): mounted filesystem 00000000-0000-0000-0000-000000000000 ro without journal. Quota mode: writeback. [ 268.537051][T15692] EXT4-fs (loop4): mounted filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09 r/w without journal. Quota mode: none. [ 268.554841][T15692] SELinux: failed to load policy [ 268.576576][T11178] EXT4-fs (loop4): unmounting filesystem 76b65be2-f6da-4727-8c75-0525a5b65a09. [ 268.589494][T13955] EXT4-fs (loop7): unmounting filesystem 00000000-0000-0000-0000-000000000000. [ 268.621242][ T29] kauditd_printk_skb: 636 callbacks suppressed [ 268.621262][ T29] audit: type=1326 audit(268.663:46891): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.650595][ T29] audit: type=1326 audit(268.663:46892): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=321 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.673778][ T29] audit: type=1326 audit(268.663:46893): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.697023][ T29] audit: type=1326 audit(268.663:46894): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.720056][ T29] audit: type=1326 audit(268.663:46895): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.743170][ T29] audit: type=1326 audit(268.663:46896): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.766307][ T29] audit: type=1326 audit(268.663:46897): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.789622][ T29] audit: type=1326 audit(268.663:46898): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.812632][ T29] audit: type=1326 audit(268.663:46899): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.835670][ T29] audit: type=1326 audit(268.663:46900): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=15698 comm="syz.6.4120" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f64e3ba5d29 code=0x7ffc0000 [ 268.971658][T15717] vhci_hcd: invalid port number 61 [ 269.015291][T15724] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(3) [ 269.021149][T15728] loop7: detected capacity change from 0 to 128 [ 269.021854][T15724] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 269.035739][T15724] vhci_hcd vhci_hcd.0: Device attached [ 269.058291][T15728] SELinux: failed to load policy [ 269.067922][T15731] loop4: detected capacity change from 0 to 512 [ 269.075706][T15731] EXT4-fs: Ignoring removed orlov option [ 269.088816][T15731] EXT4-fs: Journaled quota options ignored when QUOTA feature is enabled [ 269.092744][T15725] vhci_hcd: connection closed [ 269.097743][ T7404] vhci_hcd: stop threads [ 269.106878][ T7404] vhci_hcd: release socket [ 269.111547][ T7404] vhci_hcd: disconnect device [ 269.117217][T15731] EXT4-fs (loop4): orphan cleanup on readonly fs [ 269.137161][T15731] EXT4-fs error (device loop4): ext4_validate_block_bitmap:441: comm syz.4.4130: bg 0: block 248: padding at end of block bitmap is not set [ 269.153942][T15736] netlink: 12 bytes leftover after parsing attributes in process `syz.7.4132'. [ 269.154594][T15731] EXT4-fs error (device loop4): ext4_acquire_dquot:6938: comm syz.4.4130: Failed to acquire dquot type 1 [ 269.177348][T15731] EXT4-fs (loop4): 1 truncate cleaned up [ 269.298076][T15746] loop4: detected capacity change from 0 to 512 [ 269.310975][T15746] EXT4-fs error (device loop4): ext4_free_branches:1023: inode #11: comm syz.4.4137: invalid indirect mapped block 256 (level 2) [ 269.325146][T15746] EXT4-fs (loop4): 2 truncates cleaned up [ 269.394427][T15750] loop4: detected capacity change from 0 to 2048 [ 269.529551][T15753] loop6: detected capacity change from 0 to 128 [ 269.529581][T15754] loop4: detected capacity change from 0 to 128 [ 269.551930][T15754] FAT-fs (loop4): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive! [ 269.576211][T15754] FAT-fs (loop4): Invalid FSINFO signature: 0x41615252, 0x80417272 (sector = 1) [ 269.610324][T15754] xt_hashlimit: size too large, truncated to 1048576 [ 269.618862][T15753] SELinux: failed to load policy [ 269.704652][T15764] netlink: 24 bytes leftover after parsing attributes in process `syz.8.4144'. [ 269.951684][T15777] netlink: 12 bytes leftover after parsing attributes in process `syz.6.4149'. [ 270.049164][T15782] loop6: detected capacity change from 0 to 512 [ 270.070851][T15782] EXT4-fs (loop6): can't mount with commit=17542, fs mounted w/o journal [ 270.081128][ T2999] ================================================================== [ 270.089337][ T2999] BUG: KCSAN: data-race in block_uevent / inc_diskseq [ 270.096125][ T2999] [ 270.098473][ T2999] write to 0xffff888101072620 of 8 bytes by task 15782 on cpu 1: [ 270.106214][ T2999] inc_diskseq+0x2c/0x40 [ 270.110475][ T2999] disk_force_media_change+0x9f/0xf0 [ 270.115805][ T2999] lo_release+0x2ca/0x400 [ 270.120155][ T2999] bdev_release+0x3c6/0x420 [ 270.124681][ T2999] blkdev_release+0x15/0x20 [ 270.129202][ T2999] __fput+0x17a/0x6d0 [ 270.133196][ T2999] __fput_sync+0x96/0xc0 [ 270.137492][ T2999] __se_sys_close+0x109/0x1b0 [ 270.142269][ T2999] __x64_sys_close+0x1f/0x30 [ 270.146880][ T2999] x64_sys_call+0x266c/0x2dc0 [ 270.151577][ T2999] do_syscall_64+0xc9/0x1c0 [ 270.156098][ T2999] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 270.162047][ T2999] [ 270.164376][ T2999] read to 0xffff888101072620 of 8 bytes by task 2999 on cpu 0: [ 270.171926][ T2999] block_uevent+0x31/0x50 [ 270.176267][ T2999] dev_uevent+0x2f3/0x380 [ 270.180619][ T2999] uevent_show+0x11e/0x210 [ 270.185052][ T2999] dev_attr_show+0x3a/0xa0 [ 270.189481][ T2999] sysfs_kf_seq_show+0x17c/0x250 [ 270.194434][ T2999] kernfs_seq_show+0x7c/0x90 [ 270.199046][ T2999] seq_read_iter+0x2d1/0x930 [ 270.203649][ T2999] kernfs_fop_read_iter+0xc0/0x310 [ 270.208804][ T2999] vfs_read+0x5dc/0x700 [ 270.213003][ T2999] ksys_read+0xe8/0x1b0 [ 270.217216][ T2999] __x64_sys_read+0x42/0x50 [ 270.221742][ T2999] x64_sys_call+0x2874/0x2dc0 [ 270.226466][ T2999] do_syscall_64+0xc9/0x1c0 [ 270.230980][ T2999] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 270.236899][ T2999] [ 270.239266][ T2999] value changed: 0x00000000000009e7 -> 0x00000000000009e8 [ 270.246379][ T2999] [ 270.248707][ T2999] Reported by Kernel Concurrency Sanitizer on: [ 270.254859][ T2999] CPU: 0 UID: 0 PID: 2999 Comm: udevd Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 [ 270.265135][ T2999] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 [ 270.275236][ T2999] ================================================================== [ 270.410557][ T3373] usb 17-1: enqueue for inactive port 0 [ 270.417142][ T3373] usb 17-1: enqueue for inactive port 0 [ 270.490414][ T3373] vhci_hcd: vhci_device speed not set