last executing test programs: 6m11.285451014s ago: executing program 4 (id=5): mmap(&(0x7f00009fd000/0x600000)=nil, 0x600000, 0x4, 0x6031, 0xffffffffffffffff, 0x0) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f0000000000)='./file1\x00', 0x3000046, &(0x7f00000006c0)={[{@delalloc}, {@data_err_abort}, {@barrier_val={'barrier', 0x3d, 0x2}}, {@dioread_lock}, {@data_err_ignore}, {@max_dir_size_kb={'max_dir_size_kb', 0x3d, 0x4007b1}}, {@dioread_lock}, {@acl}, {@max_batch_time={'max_batch_time', 0x3d, 0x7}}, {@user_xattr}, {@bh}, {@errors_remount}]}, 0x1, 0x555, &(0x7f0000002640)="$eJzs3d9rW1UcAPDvTdP91nUwhopIYQ9O5tK19ccEH+aj6HCg7zO0d2U0XUaTjrUO3B7ciy8yBBEH4ru++zj8B/wrBjoYMoo++FK56U2XtUmbtdnSmc8Hbjkn9ybnfnPv9/TcnBsSwMAazf4UIl6OiG+SiMMRkeTripGvHF3dbvnh9alsSWJl5dO/ksZ2Wb35Ws3nHcwrL0XEb19FnCxsbLe2uDRbrlTS+bw+Vp+7MlZbXDp1aa48k86klycmJ8+8PTnx3rvv9CzWN87/8/0ndz888/Xx5e9+uX/kdhJn41C+rjWOHbjRWhmN0fw9GY6z6zYc70Fju0nS7x1gW4byPB+OrA84HEN51gP/f19GxAowoBL5DwOqOQ5oXtv36Dr4ufHgg9ULoOWIdfEXVz8biX2Na6MDy8ljV0bZ9e5ID9rP2vj1zzu3syV69zkEwJZu3IyI08Xixv4/yfu/7TvdxTbr29D/wbNzNxv/vNlu/FdYG/9Em/HPwTa5ux1b53/hfg+a6Sgb/73fdvy7Nmk1MpTXXmiM+YaTi5cqada3vRgRJ2J4b1bfbD7nzPK9lU7rWsd/2ZK13xwL5vtxv7j38edMl+vlncTc6sHNiFeK7eJP1o5/0ub4Z+/H+S7bOJbeea3Tuq3jf7pWfop4ve3xfzSjlWw+PznWOB/GmmfFRn/fOvZ7p/b7HX92/A9sHv9I0jpfW3vyNn7c92/aad1j8Uf35/+e5LNGeU/+2LVyvT4/HrEn+Xjj4xOPntusN7fP4j9xfPP+r935vz8iPu8y/ltHf361q/j7dPynn+j4P3nh3kdf/NCp/e76v7capRP5I930f93u4E7eOwAAAAAAANhtChFxKJJCaa1cKJRKq/d3HI0DhUq1Vj95sbpweToa35UdieFCc6b7cMv9EOP5/bDN+sS6+mREHImIb4f2N+qlqWplut/BAwAAAAAAAAAAAAAAAAAAwC5xsMP3/zN/DPV774Cnzk9+w+DaMv978UtPwK7k/z8MLvkPg0v+w+CS/zC45D8MLvkPg0v+w+CS/wAAAAAAAAAAAAAAAAAAAAAAAAAAANBT58+dy5aV5YfXp7L69NXFhdnq1VPTaW22NLcwVZqqzl8pzVSrM5W0NFWd2+r1KtXqlfGJWLg2Vk9r9bHa4tKFuerC5fqFS3PlmfRCOvxMogIAAAAAAAAAAAAAAAAAAIDnS21xabZcqaTzCgrbKhR3x24o9LjQ754JAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB75LwAA//89ATZE") mount$tmpfs(0x0, &(0x7f00000003c0)='./file0\x00', &(0x7f0000000400), 0x0, &(0x7f0000000440)=ANY=[@ANYBLOB='huge=always']) chdir(&(0x7f0000000140)='./file0\x00') r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000040)='cgroup.controllers\x00', 0x275a, 0x0) write$binfmt_script(r0, &(0x7f0000000000), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x3000004, 0x28011, r0, 0x0) r1 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) ptrace(0x10, r1) mremap(&(0x7f0000097000/0x2000)=nil, 0x2000, 0x400000, 0x3, &(0x7f0000bff000/0x400000)=nil) madvise(&(0x7f0000000000/0x600000)=nil, 0x600000, 0x15) 6m9.092903274s ago: executing program 4 (id=13): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000040)='kmem_cache_free\x00', r0}, 0x10) r1 = socket(0x10, 0x3, 0x0) connect$netlink(r1, 0x0, 0x0) syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f0000000000)='./bus\x00', 0x88e, &(0x7f0000000080)={[{@errors_remount}, {@mblk_io_submit}, {@inlinecrypt}, {@test_dummy_encryption_v1}, {@barrier}, {@mblk_io_submit}, {@nogrpid}]}, 0x3, 0x445, &(0x7f0000000800)="$eJzs3M9rHFUcAPDv7CZt06YmlvqjadVoFYM/kiattQcvioIHBUEP9RiTtMRuG2ki2BI0itSjFLyLR8G/wJNeRD0JXvUuhSK5tIqHldmdSXY3u2k2blzNfj4wyXszb3nvuzNv9715mQTQs0bTH0nEYET8EhFD1Wx9gdHqr9uryzN/rC7PJFEuv/57Uil3a3V5Ji+av+5AnumLKHycxNEm9S5euXphulSau5zlJ5YuvjOxeOXq0/MXp8/PnZ+7NHXmzKmTk8+ennqmI3Gmcd0aeX/h2JGX37z+6szZ62/98FWSx98QR4eMbnbwsXK5w9V118GadNLXxYbQlmK1m0Z/pf8PRTHWT95QvPRRVxsH7KhyuVy+t/XhlTKwiyXR7RYA3ZF/0afz33zbfMDQ0eFH1918vjoBSuO+nW3VI31RyMr0N8xvO2k0Is6u/Pl5usXO3IcAAKjzTTr+earZ+K8QtfeF7srWUIYj4u6IOBQRpyPicETcE1Epe19E3N9m/Y2LJBvHP4Ub2wpsi9Lx33PZ2lb9+C8f/cVwMcsdrMTfn5ybL82dyN6Tsejfm+YnN6nj2xd//rTVsdrxX7ql9edjwawdN/r21r9mdnpp+p/EXOvmhxEjfc3iT9ZWApKIOBIRI9usY/6JL4+1Onbn+JurvCUdWGcqfxHxePX8r0RD/Llk8/XJiX1RmjsxkV8VG/3407XXWtW/3fg7JT3/+5te/2vxDye167WL7ddx7ddPWs5ptnv970neqNv33vTS0uXJiD3JK9VG1+6faig3tV4+jX/sePP+fyjW34mjEZFexA9ExIMR8VDW9ocj4pGIOL5J/N+/8OjbdTvGBtuIf2el8c+2df7XE3uicU/zRPHCd1/XVTocbcSfnv9TldRYtmcrn39badf2rmYAAAD4/ylExGAkhfG1dKEwPl79G/7Dsb9QWlhcevLcwruXZqvPCAxHfyG/0zVUcz90MpvW5/mphvzJ7L7xZ8WBSn58ZqE02+3goccdaNH/U78Vu906YMd5Xgt6l/4PvUv/h96l/0PvatL/Bzbu+qvhkUFgN2j2/f9BF9oB/Psa+r9lP+gh5v/Qu/R/6F36P/SkxYG480PyEhIbElH4TzRj5xP7tvhvLnZZotufTAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJ3xdwAAAP//FX7vJg==") link(0x0, 0x0) r2 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000100)='memory.stat\x00', 0x275a, 0x0) write$binfmt_script(r2, &(0x7f0000000040), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r2, 0x0) fdatasync(r2) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x15) sendmsg$key(0xffffffffffffffff, 0x0, 0x0) r3 = bpf$MAP_CREATE(0x0, &(0x7f0000000840)=@base={0xb, 0x5, 0x2002, 0x4, 0x5, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0x11, 0xc, &(0x7f00000002c0)=ANY=[@ANYBLOB="180000000000ff0300000000fcffffff18110000", @ANYRES32=r3, @ANYBLOB="0000000000000000b7080000840000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f0000000200)={0xc, 0xe, &(0x7f0000001a40)=ANY=[], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$MAP_CREATE_CONST_STR(0x0, 0x0, 0x0) getrandom(&(0x7f0000000240)=""/286, 0xffffff9a, 0x0) 6m8.451965922s ago: executing program 4 (id=15): r0 = openat$vhost_vsock(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) ioctl$VHOST_SET_OWNER(r0, 0xaf01, 0x0) ioctl$VHOST_SET_VRING_ADDR(r0, 0x4028af11, &(0x7f0000000300)={0x1, 0x0, 0x0, &(0x7f0000001600)=""/78, 0x0}) ioctl$VHOST_SET_MEM_TABLE(r0, 0x4008af03, &(0x7f0000001680)) r1 = eventfd2(0x1, 0x1) ioctl$VHOST_SET_VRING_ERR(r0, 0x4008af22, &(0x7f00000001c0)={0x0, r1}) ioctl$VHOST_SET_VRING_ADDR(r0, 0x4028af11, &(0x7f0000000240)={0x0, 0x0, 0x0, &(0x7f0000001d00)=""/176, 0x0, 0xffff1000}) ioctl$VHOST_SET_VRING_KICK(r0, 0x4008af20, &(0x7f0000000000)={0x0, r1}) ioctl$VHOST_VSOCK_SET_RUNNING(r0, 0x4004af61, &(0x7f00000000c0)=0x1) ioctl$VHOST_VSOCK_SET_GUEST_CID(r0, 0x4008af60, &(0x7f0000000140)={@my=0x1}) r2 = socket$vsock_stream(0x28, 0x1, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) ioctl$VHOST_SET_VRING_ADDR(r0, 0x4028af11, &(0x7f00000003c0)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000500)=""/4096}) connect$vsock_stream(r2, &(0x7f0000000200)={0x28, 0x0, 0x0, @my=0x1}, 0x10) 6m8.360580563s ago: executing program 32 (id=15): r0 = openat$vhost_vsock(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) ioctl$VHOST_SET_OWNER(r0, 0xaf01, 0x0) ioctl$VHOST_SET_VRING_ADDR(r0, 0x4028af11, &(0x7f0000000300)={0x1, 0x0, 0x0, &(0x7f0000001600)=""/78, 0x0}) ioctl$VHOST_SET_MEM_TABLE(r0, 0x4008af03, &(0x7f0000001680)) r1 = eventfd2(0x1, 0x1) ioctl$VHOST_SET_VRING_ERR(r0, 0x4008af22, &(0x7f00000001c0)={0x0, r1}) ioctl$VHOST_SET_VRING_ADDR(r0, 0x4028af11, &(0x7f0000000240)={0x0, 0x0, 0x0, &(0x7f0000001d00)=""/176, 0x0, 0xffff1000}) ioctl$VHOST_SET_VRING_KICK(r0, 0x4008af20, &(0x7f0000000000)={0x0, r1}) ioctl$VHOST_VSOCK_SET_RUNNING(r0, 0x4004af61, &(0x7f00000000c0)=0x1) ioctl$VHOST_VSOCK_SET_GUEST_CID(r0, 0x4008af60, &(0x7f0000000140)={@my=0x1}) r2 = socket$vsock_stream(0x28, 0x1, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) ioctl$VHOST_SET_VRING_ADDR(r0, 0x4028af11, &(0x7f00000003c0)={0x0, 0x0, 0x0, 0x0, &(0x7f0000000500)=""/4096}) connect$vsock_stream(r2, &(0x7f0000000200)={0x28, 0x0, 0x0, @my=0x1}, 0x10) 6m8.277215834s ago: executing program 1 (id=17): r0 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r0, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000880)=@newsa={0x238, 0x10, 0x633, 0x0, 0x0, {{@in=@dev={0xac, 0x14, 0x14, 0x25}, @in6=@initdev={0xfe, 0x88, '\x00', 0x0, 0x0}}, {@in6=@empty, 0x0, 0x32}, @in6=@empty, {0xfffffffffffffffd, 0x0, 0x0, 0x2dcd, 0x8}, {}, {0x0, 0x0, 0x4}, 0x0, 0x0, 0x2}, [@algo_crypt={0x48, 0x2, {{'ecb(cipher_null)\x00'}}}, @algo_auth={0x100, 0x1, {{'hmac(sha1)\x00'}, 0x5c0, "fd03480f2e2ebb04183ebca2d78f40b20e8473b935f6cf6f3d2c402e34b339e1b0cd2b29cd33e8f258cf85e6c1348f664a094fe82198b2247fe438734b6b8a3542814e750312a0ffb8d2a22897aa02b742120e6f30979c39395eff53127d75d756e6a5be009f9c5b73cc002ca5e0e93d1a1730a1593d11d326b04cf06a436e84581a4f7369563bd6ab49d5f5fd6114c1a68b7bd9c85dce5fe4b25231f54590dbd7156f55078a369d24a907824d1f331a6d7a31f0172f177c"}}]}, 0x238}}, 0x0) 6m8.025105178s ago: executing program 1 (id=19): mkdirat(0xffffffffffffff9c, &(0x7f0000000100)='./file0\x00', 0x100) mount(0x0, &(0x7f00000002c0)='./file0\x00', &(0x7f0000000400)='ramfs\x00', 0x2000000, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mkdir(&(0x7f0000000300)='./bus\x00', 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x2000000}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prlimit64(r0, 0x8, &(0x7f00000000c0)={0x4, 0x6}, 0x0) bind$inet6(0xffffffffffffffff, &(0x7f0000000100)={0xa, 0x4e22}, 0x1c) prctl$PR_GET_SPECULATION_CTRL(0x34, 0x0, 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000400)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) r3 = open(&(0x7f0000000140)='./file0\x00', 0x0, 0x0) mknodat$loop(r3, &(0x7f0000001600)='./file1\x00', 0x0, 0x0) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r4, 0x8947, &(0x7f0000000900)={'ip6tnl0\x00', @random="0600002000"}) chdir(&(0x7f0000000140)='./bus\x00') link(&(0x7f0000000000)='./file1\x00', &(0x7f00000001c0)='./file0\x00') 6m6.796453674s ago: executing program 1 (id=21): syz_mount_image$ext4(&(0x7f00000000c0)='ext4\x00', &(0x7f0000000640)='./file1\x00', 0x3000010, &(0x7f0000000000), 0x3e, 0x51b, &(0x7f0000001200)="$eJzs3c9vI1cdAPDvTOLd7G6KU0CoVKJUtGi3grU3DW0jhKBc4FQJKPclJE4UxY6j2CmbqKKp+A8QEkicOHFB4g9AQj3wB6BKleCCOCBAIARbOCABHTTjsZp17CTQrJ3Gn4/04vfm1/e9sfw8M36ZCWBqPRkRL0bETEQ8ExHVcnpaprt54bC33Nv3X13NUxJZ9vJfk0jKaf1t5eXZiLjRWyXmIuJrX474ZnI8bmf/YGul2WzsluV6t7VT7+wf3N5srWw0NhrbS0uLzy+/sPzc8p2s9J7audDP/PhLn//5p7/1u7t/vvXtvFqf+0hUYqAd56nX9EqxL/ryfbT7MIJNwEzZnsqkKwIAwJnkx/gfjIhPFMf/1ZgpjuYGzEyiZgAAAMB5yb4wH/9OIjIAAADg0kojYj6StFaOBZiPNL1SXhv4cFxPm+1O91Pr7b3ttXxexEJU0vXNZuNOOVZ4ISpJXl4sx9j2y88OlJci4tGI+F71WlGurbabaxO+9gEAAADT4sbA+f8/qmmRP92Q/xMAAAAALq6FkQUAAADgsnDKDwAAAJff4Pm/+/0DAADApfKVl17KU9Z//vXaK/t7W+1Xbq81Olu11t5qbbW9u1PbaLc3inv2tU7bXrPd3vlMbO/dq3cbnW69s39wt9Xe2+7e3XzgEdgAAADAGD368Td+nUTE4WevFSnK+wACPOAPk64AcJ4M9YPp5S7eML0qk64AMHHJKfMN3gEAgPe/mx89/vt///n/rg3A5WasDwBMH7//w/SqGAEIU2u2vAbwgV7x6qjlRv7+/8uzRsqyiDerR6e4vggAAOM1X6QkrZXnAfORprVaxCMR6UJUkvXNZuNOeX7wq2rlal5eLNZMTh0zDAAAAAAAAAAAAAAAAAAAAAAAAAD0ZFkSGQAAAHCpRaR/Soq7+UfcrD49P3h94Eryz2r8sSz88OXv31vpdncX8+l/K57ldSUiuj8opz878vFhAAAAwHlLDkfO6p2nl6+LY60VAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFPg7fuvrvbTOOP+5YsRsTAs/mzMFa9zUYmI639PYvbIeklEzJxD/MPXI+KxYfGTeCfLXouyFsPiX3vI8ReKXTM8fhoRN84hPkyzN/L+58Vhn780nixeh3/+Zsv0Xo3u/9Iy8mNFPzes/3nk2NZaQ2M8/tZP671c5Xj81yMenx3e//T732RE/KeObe1fWZYdj/+Nrx8cjGp/9qOIm0O/f5IHYtW7rZ16Z//g9mZrZaOx0dheWlp8fvmF5eeW79TXN5uN8u/QGN/92M/eGRU/b//1IfF/+5te/3tS+58etdEB/3nr3v0P9bLH3oA8/q2nhn7/zsWI+Gn53ffJMp/Pv9nPH/byRz3xkzefOKn9ayP2/2nv/60ztv+Zr37n92dcFAAYg87+wdZKs9nYPSEzd4Zl3o+ZX8xdiGr8j5nstd47d1Hq8/9m8qPVd6f0W3UBKnYkk40l1tXieP6sa10ZU9sn2i0BAAAPwbsH/ZOuCQAAAAAAAAAAAAAAAAAAAEyvcdxKbTDm4WSaCgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABwov8GAAD//3QT3Gw=") r0 = openat$dir(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x32d800, 0x0) renameat2(0xffffffffffffff9c, &(0x7f0000000080)='./file1\x00', r0, &(0x7f0000000980)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00', 0x0) unlink(&(0x7f0000000f40)='./file0aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x00') 6m4.85457981s ago: executing program 1 (id=25): preadv(0xffffffffffffffff, &(0x7f0000000280), 0x0, 0xfffffffb, 0x5) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000300)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e22}, 0x3f) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = add_key(&(0x7f0000000040)='dns_resolver\x00', &(0x7f00000000c0)={'syz', 0x3}, &(0x7f00000007c0)="0cf6652b5ec5714cb18f956f52a750f914598ed3e8d76ecd75cb0c7ed4edd0a745804d01756cbfe96f516081b504a040867caa5ff79f05e857000cabbac37160e5ca38aaf8ca77b21cdffd45892a733ca547c92b2902b917a23f2bbd91a898cb9725b6412c9fd4f79c3bcd143b5cf39bb1188a349530a344e8abbbcaca6f675eb3d6df3109cab0288048e34cffab4eca05245de8b81563a6fcf7cdce651b5f2ea8de0c26d6027ea2258ec0b364084c3da130f4534a5c2bf424cff8f6d2b215fc643b7f4432d63403f9ee0c5ad3403d8fcc6196d99308619fc0a0b321349fd0f18f4263622a177331ad5c6fd015c3e89d1df39a4735405425baf9b70655d49969e26ea2685e899a7447a2b6d4fa8f4ad5b6f9d844ee6d542d69ba78d06eaede18e5c2902368de7b260a3306d31fe30a3117be628096a7550b16f762ee79c273b0383647d6ec65d4fb2273cfec5236e36df1048845613ace5c7d0e35e7d3c4babfaf68a68ad137e5e4a3800dbd7cd1e40f133557425b08fe6944a91c9c5a1d6ac8727c2325e52f773d4e0379568896b0f9a29ac37496a7473ea4aa0345e0b82be89a632429f721d213ed7b2a034dea24ee32cda7a75fcaef1340600296ccfc6c5fdcbf0724bf3ba299aad99801cb190418d1583436e78af56b06f6b7f321013443ffb881a7eb4de5b74394a5dd0b521327cbfa3b96e23c7ddd239ddabd1e8a1b01c3f0a93eaa73aecd6cf52cde063ddb8b9c7f04d8ed6cbc6b42494d42503c540a3981113775974e9639cbf9f3c45f23f951989070e70a7199a778faab8d79a90c0c3fa9c34bbcf6e7d8d6a68071a26913a0a35483a0d30560755d7a575e6903ef635630e60ad38780eb137e888e23bece193d3b8f613f045ab0b0fee1aa4c78298f6137cdae1bf26ebaa42bd2a0fa5ef1441ddc1ac4ea17ce3e5bae341af9f795c4da45bc3e0e5a631ea2ef8d6f54f5d030638e4d2bb03975531939bcace5b6bc13e90fd34733c18c4f0e753ef3c0971d7866f39d5563808a4566a462703377b7eeb18a3d0197b276b3e942b79f70cc3a675ca039bc4ff3e1af11630af96a81bb06d821129960dea36be4513fc56bc8bc31b743f39ad567d29c64ecff911c3a40c71cc336af2170b65a4ea421838ecc206bd05aa53fd6360f37eced2e939450b33bb4faba875b3b1ff616490f6f7617c600a686de049fe1b0e090ddfb550b0c4b81420cb30c3b484d032b3174e6a83fbae83b9b1e535e01f03a64e4ed376d3ca390a961a46edd660f8db6831ec4b57d90e8f1e1cd75042708651c92a49513ab96278cf3c98099e639420e47016bfe67e89a4c1fa6f70d6ad8725489c3522913a439d6ed5f851095dcf560d6b68e91f5c9f16b2b6bdb469c05366baacf5c5e880a9a9b8bd9cccca0ce8ebfbd2cf9212c1952b22521e548d55620b72f2370ca58669d8b85985b8f63e15dd915b0f51d59b489ad7f80dd89741f046e7b1d3b32cba47c39dc022f3d6e12ac3465b71896350b99fc52aac1a58d76ac1242c622b8d1cbd9ed7745f3248d7aa3dccaf980a7bb1cae774bddf705385fbcd1d4679a8b77dab6a9e43052b36d4da60d6fe3393097a9ca861afa1fc9a78a97516e82b13bb2793bfa7210b6a2f53abc3458a84d5b668e3c201948afdf770d87876211986dc18ad091b52c896becffdf0c9d0447fe264b3a7b0f949c85fa5b96bd65a56b6eedca3eca322a7a7e8d56ebf1dc18e710f82de275664f9f896a458df442810206ba842a2839da86ceb457a9613e4acaba4fcd2777b650c4e39bdf2a3df3d726f0b6f0f4976f632f3facf4f910449f78659b89ca2bd9b1499504b6fa9795c295abda6d9d9880c7b39e15c32d79ac6eddd350430b70d63165b0c7b4795097d6ea8f4d24bd23395441731b4160efc9e136eff239287a273495e6063c8c06e6c3640263c2f4cf8ae43dd5a8a3440d119ad36248a992f99d7f05ba8509b2920c000074715fc58ebdca1b8f7f01d93b72f2107d5c1e4995a0b2e6edb22d27aa62ec3d9d0ea24237dba1a3eaff6d24d097d187af34c230566fb9cc6b1ccc90bc07f210534aa88d462e1ccfe5d3fd87c8324c4eaa29d606dae886897b6fc8bbd0df148524b488d6431ad42c0599f7fc101306378097a2760cf5aedfadd71a733c05d35e755176591b4036e9aa1cdeed713e5fd68dd8503d143e66719a171f4882d396c98c0ad45fb88b5ec1de72fa16d14d23538b74cbd9c8045c0d50a44c2fd74908cd66ddebde974aa3fe067f5673367d90f716a9a0d6e2441f9c17c93cf890133aac8f558fc4ae1282c4f8c76316a1b7dce1bdb6ec6f7450676db1f4ac12bf2b4dcd9e07c4e36efccdbc74cd323e17492497357f0a5b18397e6fa9062c131b0195aae149350cc1db93d774675609f1a3e393f9babc1a8d14d2a7db49bb3ff938325cff8aeb6c1586c26c39b9c2daffa04123a7fc152ea8404ee6766f6a4ff64ae488012364d179ea9f297eb52bfc13792c6fecb2f0a9f08bc9b4a313207f5e21ab74f90a67342c387f1acbadb62611404dd284c18bf268afddbbe306b39b5217a9cec458171b6f3eb8e4fef10311249bbba7c1b9ec4ac6072be82c24ffee5853502a0e0f9ff313a38a2ac2a74dad6d2213c31c33056294e70e8699e5a993670ea480ae079e384546735f490cc24c3c2f8c9f47181fbb9e5f5b18c8aec2fbac634d87bb2b5385f03b030683752225be2e09201de11234b9a0627e84294682d5ed33b4e4593d2d956c7af18aea671cddfd37849d1b72af33f5707addb0f45df0b407e5f6bbae8ba47252a84f7f8dc950930b95a4a91de50a958c7cf2436b55e600a0b59407c2a4eb725cdd657749a5c2e85a62e41f6cfa722bd18cdbabddd65f00b6c97d8ff52784922fb3b31138f1162fa95ba8bb3bbea3e505ea36983d722d0450a01d2d4fd221857fc28ee18d7bcd9f6553f79a5ef104f5c73354c6acd4f03821df5b49902f649b33318123200f025f8ad0c2b186abe9c1823802dc1b89b341808914938c20a3cad1b9a377d21bd1c7e43259ff45b276abb70e7769544520d3f818a91c77d747fd213a8ac3c59448d0b7d8fc86051c894c4954aacfa4fa6fc7fb70fe09bfa97e5d9e68fdda9d7c0065e54a5d85301f72b40992bbc6e3f73017a9c6da2de020c2b6ba684241c79514cc95c59be32a22db0cdf049cfc914df59d61a99c698c8be1d752004a2481839e0b97d5359f63dbdd69e206e4928b64a757933cab1a2b2dd5050245f431b5ce794293af833aa9833c57390afd6f503129498ca8e59427514566523fa4f9723d126f28f89d325bf7126f6bf532f93084c5b22766765b6cd8dca31e46e980c3c04d1ca80e914bf380bb2d50d744a2a27f31add483db2ae5b2e468dc4ee5b8022dca0013054a9f85f5d08186b5c0561325327a95a88a701ab4f12f90b6ff7a7a79e1db7abad196663edf72e64d5e89b21de798fac5e79b7a18bf14770bfcf77c121c828a17a3036b54918de4384da66d048aa4e59352fbbd7566e613539e7d132026bcb7f1def9e87e801dce8216053c73f9615451f0ef681b5edf126379bf22507bfebe7e8baf9d462c4355d62a90a75670d2bf7c2f72cdf848585a6cf14bae6861dedc30571eca5f234580e0f6e88fa58380288a6a32c64df58eff898a8b39a1c535de3152027931e7d1e345820f4e593eb325bdff60d6476a6f4dd16d7b9ff26c20140c86e355de03ad2ffaf2c75622c004e6259d86737713eae103e97c93b9aeda097c3e17e88998e95313e6232b30321aa130329971a67a4f4415964dd2e1c498cd8c43e9621eaab863e57dab4f6ab202bad50361c5cbd913a368707f99b47d7269bd766e4763d9424c79e7188130539d0c9fab30240f1f624787b020c23ecc6ed63e9397ae33211ef48bbcf2c334f31fd4610d56d1307ca1575846db998543b03950d7f50bf267a734bc321eb99118766ebc874b591ca3cbac53b1c70da7bb561d1c015f923fad51ea1533d443de7f0aa5b65e373e8c15ddadc221bd7ea3711945c36d9555a159d5929c861cd82e3e26df7a9ade8e5b0839d22d6a0492ec64d5895b5c633bb4b04c753163f8e0464a005cc026b2102be406f3242ca795cf6553b46960460aafcf4cf5df7339aebd023b83ef1165692defeb29f70c59613e9f5a133e638e918416e644760ec7d29793ecff44e8afc13ec1c9ff4d65416b9d865a104c21f7e280f829eae80a13ffca6151f645e85b202bccb6903232e9454b3067a3573f3125f490a61807dec446f4b9611761afad4c9f63b2d4f405366ca40f6ed9a5f77495b0a263efb6e2f8f9811e3e7621ec510dca06dfb330b4af31d614a38d12c0f39feaaa8803faf91ecc974ca1ea6f18bed5f825c1a4899347f4699a37fb84b046b6bfaae360c4c75d307805c66a36b3d6b1b3816c390c5ba86d532dfca56a293824bb9f5e10fcbe125a03bf2352b8cd2a5b830c0bb9667d116141252631b4def111347064e6e90cbb4d19508ddd1e9c2694ff3eced67f6aacda73f2e06dd5f28a9750ffd231ac075ab29ff1c517139e3ad5fcf463b7b2f2adba3fb7a8f885273e8dc5ecf1c3f214bb642ca16c80add3956ef56ada2dd3649ecdada46ace345cd0e4b81520c977555e197766d197d5f1b1d7a043d4bbaf55b1a50a8d87ed5a4a11cbf658c697529f55a01ea7ca44dd06bd3f6ec445cb60367cac76f387fcec8f33b5e70d53599a4935e0847420423942e403bf4df110b31bbb5d980622df7d07c6f2f7161a4c607c577be8896e9809db82773361023ca6a061e374293e16422cbec9185bb6286b2b153a85c99bb92cb68355c8864bb1c1c3cbba165adc405418606909d5f621ed3bc0f0e14ccbdd8fec1d7e26121e2708a68a5fbf3396514bb4f1c8edd5d16a5c9c43da1999d15b07b380e6a089d2009bb09a4717757a207476daee86486a951aabd2f4053f14681f37386972ccdf15ef99aa8ac97f55d6e0f4dd453d4260b9a10d135bd0e92859df9ac5fed4a43e18d5d1b69cb9d27a10fb638235ee86884bca76274839f78ccbd6090c508dbf5713fc930bf22678b71666d4e83d3898ae2dd67335460ec8eacde448b05e819e9e858c848e8110ec1778816a68d9936566f8ee7861b017f91e848e2a536655aaeb0e5296e8fc8b576214907e7033199650b91f9f99e201b29f6002933a89cff80ee7dc1b5cec4e2957ae7920556eff508946abe08f6306b7444c5812ee588ecb7a7fb534302a8a18484f8dd6a2dd280a72e3ef66d60364859dcc042165a5495a0edec6050a9607163e3c8540d83c85fe99cebead0b9d073ac733ed9ed25efa9102d1122c0c14192c70c94711496cdad6b3c821abe6c3db575d74720688dd840c18df234de8864db056fd4b6a3216fea7d5eb1f3084568e7ee98daf35397f2a513e3b3d78316600e1f012f21497d23d7e834a28b8f7379493f965eafb43dea812c582927441e3eb79961f2ab42d6873a16715dbea9e06e8e283ed693242081c6820154d9f1d6b3e9ee778cea0f64abe1c423dada83706a3559b3f1b4dbedff75f61b0ef9b4b10d689ae8bef364821962352a93012fbe0606f6b90f05d2314bcf0603d61673e276a2996c2531f05e56fa817dafc0cb018b3f9b1522a104dd63e2b46198350494b2ca29bdff9c3ea7e0000827a09dc3f9060a3cf6bf20895a0c2d0b05a928a6821f7e37a1b4b4d07db33f1b3ef0cd31cee60e409ffb5648f707ef9fdbb6fac0aa5f671a9a82964ce76b35577747c662801201f0c5eb0cc50d2", 0x1000, 0xfffffffffffffff8) r4 = add_key$keyring(&(0x7f0000000180), &(0x7f00000001c0)={'syz', 0x2}, 0x0, 0x0, 0xfffffffffffffffa) keyctl$instantiate(0xc, r3, &(0x7f0000000100)=@encrypted_update={'update ', 'ecryptfs', 0x20, 'user:', '/dev/ttyS3\x00'}, 0x21, r4) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r5 = openat$ttyS3(0xffffffffffffff9c, &(0x7f0000001840), 0x2982, 0x0) r6 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000000)='/proc/stat\x00', 0x3f00, 0x0) sendfile(r5, r6, 0x0, 0x20000023896) r7 = socket$inet_udp(0x2, 0x2, 0x0) syz_mount_image$ext4(&(0x7f0000000080)='ext4\x00', &(0x7f0000000040)='./file0\x00', 0x808003, &(0x7f0000000000), 0x3, 0x4ed, &(0x7f00000005c0)="$eJzs3d9rW28ZAPDnpM1st8526sUcuBVRtqFL2tVtxYttgujVQJ33XW3TUpo2pUm3tQzp8FoEERW90StvBP8AQfYniDDQ+yGiDNnmhRdq5CQnW79d0nYsafZtPx94+77nR87zvAk5yXvOaU4Ax9Z4RNyOiIGIuBwRo9n8XFZiu1nS9V6+eDSXliTq9bv/TCLJ5rW2lWT1qexhQxHxnW9GfC9JmjN2qG5uLc+Wy6X1bLpYW1krVje3riytzC6WFkurU1OT16dvTF+bnuhaX29+/W8//dFvvnHzD19+8GzmH5e+n+Y7ki3b2Y9uaj4n+cZz0TIYEeu9CNYHA1l/8gdZOel9PgAA7C39jv+piPh8RLz6Rb+zAQAAAHqhfmsk/pNE1AEAAIAjK9e4BjbJFbJrAUYilysUmtfwfiZuRblSrX1pobKxOt+8VnYs8rmFpXJpIrtWeCzySTo92Wi/mb66a3oqIs5ExE9GhxvThblKeb7fBz8AAADgmEjH+SO5Zjut/jXaHP8DAAAAR8xYvxMAAAAAes74HwAAAI6+t8f/480qGTz8ZAAAAIBu+9adO2mpt+5/PX9/c2O5cv/KfKm6XFjZmCvMVdbXCouVymLjN/tW9tteuVJZ+0qsbjws1krVWrG6uTWzUtlYrc007us9UzrQfaIBAACArjpz4clfkojY/upwo6ROZMuM1eFoy73b6kmv8gAO30C/EwD6xgW+cHwZ4wP7DeyHDikPAACgdy5+9vX5/+HYcf7/9DPHBuCoe8fz/8AR4vw/HF+7zv//ql95AIfPGB/Y7zhAx/P/f+x+LgAAQG+MNEqSK2RjgJHI5QqFiNON2wLkk4WlcmkiIj4ZEX8ezX8inZ7sd9IAAAAAAAAAAAAAAAAAAAAAAAAA8DFTrydRBwAAAI60iNzfk4hIYihi9Asju48PnEj+PdqoI+LBL+/+7OFsLSLupbNez6/9vDG/tn61DwcwAAAAgLe0xumN2o38AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOiyly8ezbXKYcZ9/rWIGGsXfzCGGvVQ5CPi5KskBnc8LomIgS7E334cEWfbxU/StGIsy2J3/FxEDPc5/qkuxIfj7Em6/7nd7v2Xi/FG3f79N5iV9/V8vNP+L/d6/zfQYf93ep9tn8jqc09/V+wY/3HEucH2+59W/OQ997/3vru11WlZ/dcRF9t+/iQfiVWsrawVq5tbV5ZWZhdLi6XVqanJ69M3pq9NTxQXlsql7G/bGD/+3O//t1f/T3aIP9ap/0kzp3q9/TYv7Jr+79OHLz7dbsUk4vkPs3ab1/9sp/jZc//F7HMgXX6x1d5utnc6/9s/nd+r//Md+r/f63+p00Z3ufztH/y12cof8BEAQC9VN7eWZ8vl0vpBG+mg98ArH2Ij7cwHkEYXG+MfRhoax7PR7z0TAADQbW++9Pc7EwAAAAAAAAAAAAAAAAAAADi+Wv//3/ot5178nNjOeEOtRpIcel8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPby/wAAAP//nXrOGw==") syz_open_procfs(r0, &(0x7f0000000540)='net/snmp6\x00') r8 = openat$fuse(0xffffffffffffff9c, &(0x7f0000002080), 0x2, 0x0) mount$fuse(0x0, &(0x7f00000020c0)='./file0\x00', &(0x7f0000002100), 0x0, &(0x7f0000002140)={{'fd', 0x3d, r8}, 0x2c, {'rootmode', 0x3d, 0x8000}}) write$FUSE_NOTIFY_RETRIEVE(r8, &(0x7f0000000100)={0x30, 0x5, 0x0, {0x0, 0x1000000000001}}, 0x30) unshare(0x40600) r9 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b000000070000000200"/20, @ANYRES32=0x1, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32], 0x50) ioctl$sock_SIOCGIFCONF(r2, 0x8912, &(0x7f0000000500)=@buf={0xe7, &(0x7f0000000340)="918657d862f27f51ec68308fa5b3eb8c74e85663ca69bd82dbf0830a16303fd1b99a5d7f5b6c0114048bf677a68d382425e259d8c05692d49f94cac034a8de2ebe940ccc78e8edfb5936b77922e94fb5c218552188ad25eca7855b905bb76a71e4083b6f160e41d09b43666c8ee466b81d334afdcb029e73334cba770fe75f9665c88eb9b852488c487795f14c165c3b22ee6ed93c30d32e39a696a6ad7168243cfea707a93497d55841b87af1dcec2246b06e2a943daeca8f0918d0c1333d7986fd30185f5c919e8909d5d1399f661ea7577fd6923b8cfcd6e81e50ca65f985f324866316de91"}) r10 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xd, &(0x7f0000000280)=ANY=[@ANYBLOB="18000000000000000000000000000000850000002a00000018", @ANYRES32=r9, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$PROG_BIND_MAP(0xa, &(0x7f00000004c0)={r10}, 0xc) accept4(r7, 0x0, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000440)={0x3, 0x6, &(0x7f0000000740)=ANY=[@ANYBLOB="b40000000600000063112e00000000008510000002000000850000000000000095000000000000009500000000000000152e3ccd1a14dce8122e4e3277131022e08b9b9c714f83ceb6f7f73ae7fa411f2f5514faef8d6db3ec4773adec9279"], &(0x7f0000000080)='GPL\x00', 0x4, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @sched_cls, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 6m3.493941218s ago: executing program 1 (id=29): socket$tipc(0x1e, 0x2, 0x0) recvmmsg(0xffffffffffffffff, 0x0, 0x0, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000180), 0x8040, 0x0) ioctl$TCSETS(r0, 0x40045431, &(0x7f0000000040)={0x0, 0x0, 0x4, 0x0, 0x0, "ff00f7000000000000000000af88008300"}) r1 = syz_open_pts(r0, 0x141601) r2 = gettid() timer_create(0x0, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004, @tid=r2}, &(0x7f0000bbdffc)) timer_settime(0x0, 0x0, &(0x7f0000000280)={{0x0, 0x3938700}, {0x0, 0x3938700}}, 0x0) ppoll(0x0, 0x0, 0x0, 0x0, 0x0) write(r1, &(0x7f0000000000)="d5", 0xfffffedf) ioctl$TCSETSF(r1, 0x5404, &(0x7f0000000080)={0x8, 0x20000000, 0xfffffffc, 0x7fffffd, 0x5, "682341f2fd71a6a76177920ea7e60c0ac7a4a5"}) 6m1.539836385s ago: executing program 1 (id=32): r0 = socket$inet_tcp(0x2, 0x1, 0x0) getsockopt$inet_tcp_int(r0, 0x6, 0x3, 0x0, 0x0) syz_mount_image$f2fs(&(0x7f0000000140), &(0x7f0000000080)='./file0\x00', 0x400, &(0x7f00000004c0)=ANY=[@ANYBLOB="6e6f626172726965722c6e6f657874656e745f63616368652c6673796e635f6d6f64653d7374726963742c696e6c696e655f78617474720000693a653d3078303030303030303030303030303766662c736d61636b6673726f6f080000006673f52b00e58abba2d0cc27be339f6f4fe5ad35a724e1531a622f050000008586eb5ba3614d2c24abf5a2614c0f111e057112dafd66336a5e3b6512b81cda80be6e9a34ccc2b88c0100008000000000e3f5def862b95c20ee847008000b0c22653d2ff39b36732e46b56357afe57094f42ba61c5e8b4e184d7dd50000000000000000c0469264c247cd3c7fcb39043dda97538456bc294ae31e525d3b664cf8e83b52b1885b866b58698b3f132aced62a4fc7c8c400b805173d7488a35708d2523190c0014689f57be6ee3f5d28935a0000000000000000000000000000000000000059c1403d010001008ab61fa90695a8b268c277645c1e357ec9316354f659d4244fe126a8364eaa0de6bf4ba21c767782a04bdbb8c86d0cc7e3f03f8ef15c0ee311768cccb8affb0ae5d7cd0000000097676c046a6c754c98dd5f400ad99a588d983ae6e07b4e0e0907266aca53b30a815a84295fb5eab2f263613d36994dc15562892c33ed149270907e9c2e4d0cac7dd9735621a0c6768d4f70c664699157854bb1b85ce3f6ea44456e4f1ae1575315d77f2b995ce4d6ce21b17ca891c155ddd9916e997c32e78231e8d54675e4edf480980023b9736180ff98cf93f888eb70abb728b7e91a5d75b7e43e54f92b6e679249576f12533bef1c93aa993977f15c0a7b595423444db6e87480c46c408f6d48afa1ba"], 0x1, 0x5514, &(0x7f0000005d80)="$eJzs3M1rI2UYAPAn7Xa/XYt48LYDi9DCJmy67aK3qrv4gV3KqgdPmiZpyG6SKU2a1p48eBQPnv0nRMGTR/8GD569iQfFm6BkZqpbP8ClSWPb3w8mz7xv3jzzvGFZeGZKAjiz5pNffirFtbgUEbMRcTUiOy8VR2Y1D89FxPWImHnsKBXzf0ycj4jLEXFtlDzPWSre+vTm8MbKj2/8/PW3F85d+fyr76a3a2Dano+I7lZ+vtvNY9rK48NivjZsZ7G7PCxi/kb3UTFO87jb3Mgy7NYO1tWyeLuVr0+3dvqjuNmp1Uex1d7M5rd6+QX7w9ZBnuwDD2vb2bjR3Mhiu59msbWf17W3n//ftt8f5HkaRb4PsvQxGBzEfL6518z3s/Uoi/XeoJjP86aN5t4oDotYXC7qaaeR1bFxlG/6/+3Ndm9nLxk2t/vttJesVKovVKp3ytXttNEcNJfLtW7jznKy0OqMlpUHzVp3tZWmrU6zUk+7i8lCq14vV6vJwt3mRrvWS6rVyu3KrfLKYnF2M3n1/jtJp5EsjOLL7d7OoN3pJ5vpdpJ/YjFZqtx+cTG5UU3eWltP1h/cu7e2/vZ7d9+9/9La668Ui/5WVrKwdGtpqVy9VV6qLp6h/X9UFD3G/cORlJ5s+YVJ1QFwguj/gWmYXP+//SBi8v1/6P/H4kT1vxPr/z87s/uHI3nC/h8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgNPj+7kvXstO5vPxlWL+qWLqmWJcioiZiPjtH8zG+UM5Z4s8c/+yfu4vNXxTiizD6BoXiuNyRKwWx69PT/pbAAAAgNPryw+vf5J36/nL/LQL4jjlN21mrr4/pnyliJib/2FM2WZGL8+OKVn27/tc7I0pW3YD6+KYkuW33M6NK9t/MnsoXHwslPIwc6zlAAAAx+JwJ3C8XQgAAADH6eNpF8B0lOLgUebBs+DsL+//fCB46dAIAAAAOIFK0y4AAAAAmLis//f7fwAAAHC65b//BwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAv7NzP7lpA1EcgJ8NLvSfiqru26N0B8foEbrssuIAvQRHoFfIBTgD2eUIEUR4HBSiJIrisa2Q75PMMBb8/IzwYmakAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALp0Wa0X//9+/9c2Z7dv54WX/dG2bgAAAHgLttV6Ub+Zpf7H5vzn5tTXpl9ERBkRD43dR/HuJHPU5FSPfL66V8NFRJ1wuMakOT5ExM/muP7S9a8AAAAA52uzXM3TaD29zIYuiD6lSZvy069MeUVEVLOrTGnlIe9bprD6/z2OP5nS6gmsaaawNOU2zpX2LPXjfpy1m95pitSUT38/270DAAA9Gp00/Y5CAAAA6NPvoQtgGEXcLmUelwInqWmW996f9AAAAIBXqBi6AAAAAKBz9fjf/n8AAABw3tL+fwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHRpW60Xm+Vq3jZnt28nz90AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADADfvzjgIhEAZhsHd9ZzL3P6w0aGpqUgXCx98YDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAvPndX/5PTI0zydxrY+l5JFk7NbZOjb1z4+gP4+vXAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABc7M9tCoAgEIbBrezrX3j/w8YLeoYIZkB42EVBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOBH7hnLOLXO2BJPVbVME3vGvaqOrBJnVokrF/p4sPUPfwQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwMvO/bzGUcUBAH8zs7NJq+IaZQ8RseBBLzbd1tbexIMSPPgnCCHd1titP9ocbClCLt4k515EjyKCEm/9H3puoZd662EPFTxX5lcy+XFYhZ3ZZD8fePO+Mwzzvm8WQr77XgIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADsM/5wL06yQ6+I4/Law2d317P+0YE+c3/78XLWsjhqMunj4Y36SdSvnSw2nwwAAADzIanq+xDCk3RnNevjXl7/p9U9Wc3/00tFXNXzB+v+qq9q/6z9+cfT13YH6hXjZA+9ujEanjucSmd6s5xhz1+e4KZO/ubz716S/AOJP9l6dZzm7zP64cGDj7p5uDD9dAGA/+ds1ZdB9ftQ1g/aTAyAudGpFd5V/Z/02s0JAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoAnjrfBCFUchhOXOXpx59Ozu+lH9/e3Hy1W7dO/edv2Z2SPSEMLVjdHwXFhscDaz7dbtO9fXRqPhzeaDN0MIbY3+QTn9659NcHMIU0rjTEtvfs6CuPywZyWf4xG0+EMJAIATKS1bVtc/SXdWs2vRUgjPf95f/79di8OE9f/Tzy89rI9Vr/8Hjc1w9q1s3vh65dbtO+9u3Fi7Nrw2/PK984P3BxcuX7x4eSX/rqQ4tp0mAAAAx1i3bPX6P146vP5/uhaHCev/b34cfFcfK1H/H2lv0a/tTAAAAObbK2f++Ts64nrU7YZv1zY3bw6K4+75+eLYQqr/2ULZ6vV/stR2VgAAAEATxlvRvvX/K7U4TLj+/+Ivr/9Wf2YSQjhVrv+fXf9qdKW56cy0qfzx8EL5cDsLAAAAKOvxUwfW/9N8/3+8u+UhDiG881YRl/8GcKL6P/n4+1/rY9X3/19oboozKe4X7yPv+yF0+m1nBAAAwEm2mLdeXv//le6sfvH76U+79v8DAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANO3fAAAA///FdTwZ") bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b00000005000000000400000900000001000000", @ANYRES32, @ANYBLOB="0000000000000000000100000000000080000000", @ANYRES32=0x0, @ANYRES32, @ANYBLOB='\x00'/14], 0x48) epoll_ctl$EPOLL_CTL_ADD(0xffffffffffffffff, 0x1, 0xffffffffffffffff, 0x0) r1 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000240)='cpuset.effective_mems\x00', 0x275a, 0x0) write$binfmt_script(r1, &(0x7f0000000040), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r1, 0x0) r2 = dup(0xffffffffffffffff) write$uinput_user_dev(r2, &(0x7f00000000c0)={'syz0\x00', {0xfff7, 0xc, 0x100, 0x81}, 0x1d, [0x7b, 0xb7e2, 0x3, 0x9, 0x100, 0x3, 0x1, 0x7, 0x9, 0x2, 0x7, 0xa, 0x3, 0x0, 0x7f, 0xd, 0x7fff, 0x6, 0x6, 0x5, 0x6, 0x6, 0x7, 0x6, 0xff, 0x2, 0xa5f2b87a, 0x401, 0x0, 0xfc75, 0x8, 0x9, 0x4, 0x2, 0xffffffff, 0x83, 0xfffff765, 0x2, 0x3, 0x6, 0xa, 0x2, 0x5, 0x0, 0x3ff, 0x6, 0x7, 0x4c, 0xfffffffd, 0x80, 0x80000008, 0x8, 0x9, 0x7, 0x101, 0xc3c, 0x1733, 0x7fff, 0x7ffc, 0x1, 0x6, 0x5, 0x1, 0x4], [0x1, 0x3, 0x8, 0x8, 0x0, 0x8, 0x4, 0x0, 0x25, 0x10, 0x6, 0x7, 0x8, 0xe62, 0xffffff73, 0x1000, 0x6, 0x13e5, 0x3, 0x3, 0x1000, 0x7, 0x1, 0x3b40, 0x4, 0x1000, 0x5, 0x7fff, 0x8, 0x5a, 0xffff2503, 0x7fffffff, 0x6995, 0x1, 0x80000000, 0x8, 0xdab, 0x9, 0x2, 0x76c4, 0xfffffffd, 0x4, 0x401, 0x10000, 0xd, 0x2, 0x9, 0x20010, 0x4000e, 0x9, 0x7, 0xa, 0x9, 0x3, 0x8, 0x3, 0x2, 0x3a6, 0x0, 0xc0d, 0xfffffffd, 0x9, 0xc, 0xfffffffb], [0xcdc, 0x6, 0x6, 0x9, 0x1000, 0x0, 0x80000000, 0x5, 0x7f, 0xa, 0x100, 0x1000, 0xf1, 0x6, 0xc, 0x10000, 0x72, 0xc, 0x633, 0xd, 0x7, 0x6, 0x80000000, 0x6, 0x0, 0x7, 0x8, 0x2ef3adcb, 0x10, 0x2, 0x8, 0x8, 0x74, 0x4, 0x7, 0x7ff, 0xfffffff2, 0x63, 0x7, 0x2, 0x3, 0x3, 0x20a7fd9e, 0xfffffffd, 0x2, 0xa1, 0x0, 0x9d, 0x7, 0xa8a, 0x2, 0x6, 0x77, 0x8, 0x1ff, 0x7, 0x7, 0x2, 0x0, 0x2, 0x8, 0x2, 0x3, 0x5], [0x4, 0x4, 0x5, 0x8000, 0x493e, 0x3, 0x35ff4447, 0x7, 0x5, 0x4, 0x5d3a, 0x5, 0x5, 0x3ff, 0xb88f, 0xffff0000, 0x9, 0xf7df, 0x2, 0x10, 0x8, 0x4000002, 0xff, 0x9, 0x4, 0x4, 0x0, 0x0, 0x7, 0x4e6, 0x8, 0x40000000, 0x5ef, 0x8000, 0xc, 0x41, 0x400, 0x1, 0x5, 0x0, 0x9a8, 0x0, 0x231, 0x400, 0x8, 0x1, 0xffff0001, 0x1, 0x1, 0x10, 0x8, 0x5396, 0x6161, 0x9, 0x101, 0x1ff, 0x8, 0x431, 0x6, 0x5, 0x4, 0x7b, 0x7fc, 0x9]}, 0x45c) read$FUSE(r2, &(0x7f0000002c40)={0x2020}, 0x2020) fdatasync(r1) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x15) ftruncate(r1, 0x81ff) 6m1.425623926s ago: executing program 33 (id=32): r0 = socket$inet_tcp(0x2, 0x1, 0x0) getsockopt$inet_tcp_int(r0, 0x6, 0x3, 0x0, 0x0) syz_mount_image$f2fs(&(0x7f0000000140), &(0x7f0000000080)='./file0\x00', 0x400, &(0x7f00000004c0)=ANY=[@ANYBLOB="6e6f626172726965722c6e6f657874656e745f63616368652c6673796e635f6d6f64653d7374726963742c696e6c696e655f78617474720000693a653d3078303030303030303030303030303766662c736d61636b6673726f6f080000006673f52b00e58abba2d0cc27be339f6f4fe5ad35a724e1531a622f050000008586eb5ba3614d2c24abf5a2614c0f111e057112dafd66336a5e3b6512b81cda80be6e9a34ccc2b88c0100008000000000e3f5def862b95c20ee847008000b0c22653d2ff39b36732e46b56357afe57094f42ba61c5e8b4e184d7dd50000000000000000c0469264c247cd3c7fcb39043dda97538456bc294ae31e525d3b664cf8e83b52b1885b866b58698b3f132aced62a4fc7c8c400b805173d7488a35708d2523190c0014689f57be6ee3f5d28935a0000000000000000000000000000000000000059c1403d010001008ab61fa90695a8b268c277645c1e357ec9316354f659d4244fe126a8364eaa0de6bf4ba21c767782a04bdbb8c86d0cc7e3f03f8ef15c0ee311768cccb8affb0ae5d7cd0000000097676c046a6c754c98dd5f400ad99a588d983ae6e07b4e0e0907266aca53b30a815a84295fb5eab2f263613d36994dc15562892c33ed149270907e9c2e4d0cac7dd9735621a0c6768d4f70c664699157854bb1b85ce3f6ea44456e4f1ae1575315d77f2b995ce4d6ce21b17ca891c155ddd9916e997c32e78231e8d54675e4edf480980023b9736180ff98cf93f888eb70abb728b7e91a5d75b7e43e54f92b6e679249576f12533bef1c93aa993977f15c0a7b595423444db6e87480c46c408f6d48afa1ba"], 0x1, 0x5514, &(0x7f0000005d80)="$eJzs3M1rI2UYAPAn7Xa/XYt48LYDi9DCJmy67aK3qrv4gV3KqgdPmiZpyG6SKU2a1p48eBQPnv0nRMGTR/8GD569iQfFm6BkZqpbP8ClSWPb3w8mz7xv3jzzvGFZeGZKAjiz5pNffirFtbgUEbMRcTUiOy8VR2Y1D89FxPWImHnsKBXzf0ycj4jLEXFtlDzPWSre+vTm8MbKj2/8/PW3F85d+fyr76a3a2Dano+I7lZ+vtvNY9rK48NivjZsZ7G7PCxi/kb3UTFO87jb3Mgy7NYO1tWyeLuVr0+3dvqjuNmp1Uex1d7M5rd6+QX7w9ZBnuwDD2vb2bjR3Mhiu59msbWf17W3n//ftt8f5HkaRb4PsvQxGBzEfL6518z3s/Uoi/XeoJjP86aN5t4oDotYXC7qaaeR1bFxlG/6/+3Ndm9nLxk2t/vttJesVKovVKp3ytXttNEcNJfLtW7jznKy0OqMlpUHzVp3tZWmrU6zUk+7i8lCq14vV6vJwt3mRrvWS6rVyu3KrfLKYnF2M3n1/jtJp5EsjOLL7d7OoN3pJ5vpdpJ/YjFZqtx+cTG5UU3eWltP1h/cu7e2/vZ7d9+9/9La668Ui/5WVrKwdGtpqVy9VV6qLp6h/X9UFD3G/cORlJ5s+YVJ1QFwguj/gWmYXP+//SBi8v1/6P/H4kT1vxPr/z87s/uHI3nC/h8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgNPj+7kvXstO5vPxlWL+qWLqmWJcioiZiPjtH8zG+UM5Z4s8c/+yfu4vNXxTiizD6BoXiuNyRKwWx69PT/pbAAAAgNPryw+vf5J36/nL/LQL4jjlN21mrr4/pnyliJib/2FM2WZGL8+OKVn27/tc7I0pW3YD6+KYkuW33M6NK9t/MnsoXHwslPIwc6zlAAAAx+JwJ3C8XQgAAADH6eNpF8B0lOLgUebBs+DsL+//fCB46dAIAAAAOIFK0y4AAAAAmLis//f7fwAAAHC65b//BwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAv7NzP7lpA1EcgJ8NLvSfiqru26N0B8foEbrssuIAvQRHoFfIBTgD2eUIEUR4HBSiJIrisa2Q75PMMBb8/IzwYmakAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALp0Wa0X//9+/9c2Z7dv54WX/dG2bgAAAHgLttV6Ub+Zpf7H5vzn5tTXpl9ERBkRD43dR/HuJHPU5FSPfL66V8NFRJ1wuMakOT5ExM/muP7S9a8AAAAA52uzXM3TaD29zIYuiD6lSZvy069MeUVEVLOrTGnlIe9bprD6/z2OP5nS6gmsaaawNOU2zpX2LPXjfpy1m95pitSUT38/270DAAA9Gp00/Y5CAAAA6NPvoQtgGEXcLmUelwInqWmW996f9AAAAIBXqBi6AAAAAKBz9fjf/n8AAABw3tL+fwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHRpW60Xm+Vq3jZnt28nz90AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADADfvzjgIhEAZhsHd9ZzL3P6w0aGpqUgXCx98YDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAvPndX/5PTI0zydxrY+l5JFk7NbZOjb1z4+gP4+vXAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABc7M9tCoAgEIbBrezrX3j/w8YLeoYIZkB42EVBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOBH7hnLOLXO2BJPVbVME3vGvaqOrBJnVokrF/p4sPUPfwQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwMvO/bzGUcUBAH8zs7NJq+IaZQ8RseBBLzbd1tbexIMSPPgnCCHd1titP9ocbClCLt4k515EjyKCEm/9H3puoZd662EPFTxX5lcy+XFYhZ3ZZD8fePO+Mwzzvm8WQr77XgIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADsM/5wL06yQ6+I4/Law2d317P+0YE+c3/78XLWsjhqMunj4Y36SdSvnSw2nwwAAADzIanq+xDCk3RnNevjXl7/p9U9Wc3/00tFXNXzB+v+qq9q/6z9+cfT13YH6hXjZA+9ujEanjucSmd6s5xhz1+e4KZO/ubz716S/AOJP9l6dZzm7zP64cGDj7p5uDD9dAGA/+ds1ZdB9ftQ1g/aTAyAudGpFd5V/Z/02s0JAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAoAnjrfBCFUchhOXOXpx59Ozu+lH9/e3Hy1W7dO/edv2Z2SPSEMLVjdHwXFhscDaz7dbtO9fXRqPhzeaDN0MIbY3+QTn9659NcHMIU0rjTEtvfs6CuPywZyWf4xG0+EMJAIATKS1bVtc/SXdWs2vRUgjPf95f/79di8OE9f/Tzy89rI9Vr/8Hjc1w9q1s3vh65dbtO+9u3Fi7Nrw2/PK984P3BxcuX7x4eSX/rqQ4tp0mAAAAx1i3bPX6P146vP5/uhaHCev/b34cfFcfK1H/H2lv0a/tTAAAAObbK2f++Ts64nrU7YZv1zY3bw6K4+75+eLYQqr/2ULZ6vV/stR2VgAAAEATxlvRvvX/K7U4TLj+/+Ivr/9Wf2YSQjhVrv+fXf9qdKW56cy0qfzx8EL5cDsLAAAAKOvxUwfW/9N8/3+8u+UhDiG881YRl/8GcKL6P/n4+1/rY9X3/19oboozKe4X7yPv+yF0+m1nBAAAwEm2mLdeXv//le6sfvH76U+79v8DAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANO3fAAAA///FdTwZ") bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b00000005000000000400000900000001000000", @ANYRES32, @ANYBLOB="0000000000000000000100000000000080000000", @ANYRES32=0x0, @ANYRES32, @ANYBLOB='\x00'/14], 0x48) epoll_ctl$EPOLL_CTL_ADD(0xffffffffffffffff, 0x1, 0xffffffffffffffff, 0x0) r1 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000240)='cpuset.effective_mems\x00', 0x275a, 0x0) write$binfmt_script(r1, &(0x7f0000000040), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r1, 0x0) r2 = dup(0xffffffffffffffff) write$uinput_user_dev(r2, &(0x7f00000000c0)={'syz0\x00', {0xfff7, 0xc, 0x100, 0x81}, 0x1d, [0x7b, 0xb7e2, 0x3, 0x9, 0x100, 0x3, 0x1, 0x7, 0x9, 0x2, 0x7, 0xa, 0x3, 0x0, 0x7f, 0xd, 0x7fff, 0x6, 0x6, 0x5, 0x6, 0x6, 0x7, 0x6, 0xff, 0x2, 0xa5f2b87a, 0x401, 0x0, 0xfc75, 0x8, 0x9, 0x4, 0x2, 0xffffffff, 0x83, 0xfffff765, 0x2, 0x3, 0x6, 0xa, 0x2, 0x5, 0x0, 0x3ff, 0x6, 0x7, 0x4c, 0xfffffffd, 0x80, 0x80000008, 0x8, 0x9, 0x7, 0x101, 0xc3c, 0x1733, 0x7fff, 0x7ffc, 0x1, 0x6, 0x5, 0x1, 0x4], [0x1, 0x3, 0x8, 0x8, 0x0, 0x8, 0x4, 0x0, 0x25, 0x10, 0x6, 0x7, 0x8, 0xe62, 0xffffff73, 0x1000, 0x6, 0x13e5, 0x3, 0x3, 0x1000, 0x7, 0x1, 0x3b40, 0x4, 0x1000, 0x5, 0x7fff, 0x8, 0x5a, 0xffff2503, 0x7fffffff, 0x6995, 0x1, 0x80000000, 0x8, 0xdab, 0x9, 0x2, 0x76c4, 0xfffffffd, 0x4, 0x401, 0x10000, 0xd, 0x2, 0x9, 0x20010, 0x4000e, 0x9, 0x7, 0xa, 0x9, 0x3, 0x8, 0x3, 0x2, 0x3a6, 0x0, 0xc0d, 0xfffffffd, 0x9, 0xc, 0xfffffffb], [0xcdc, 0x6, 0x6, 0x9, 0x1000, 0x0, 0x80000000, 0x5, 0x7f, 0xa, 0x100, 0x1000, 0xf1, 0x6, 0xc, 0x10000, 0x72, 0xc, 0x633, 0xd, 0x7, 0x6, 0x80000000, 0x6, 0x0, 0x7, 0x8, 0x2ef3adcb, 0x10, 0x2, 0x8, 0x8, 0x74, 0x4, 0x7, 0x7ff, 0xfffffff2, 0x63, 0x7, 0x2, 0x3, 0x3, 0x20a7fd9e, 0xfffffffd, 0x2, 0xa1, 0x0, 0x9d, 0x7, 0xa8a, 0x2, 0x6, 0x77, 0x8, 0x1ff, 0x7, 0x7, 0x2, 0x0, 0x2, 0x8, 0x2, 0x3, 0x5], [0x4, 0x4, 0x5, 0x8000, 0x493e, 0x3, 0x35ff4447, 0x7, 0x5, 0x4, 0x5d3a, 0x5, 0x5, 0x3ff, 0xb88f, 0xffff0000, 0x9, 0xf7df, 0x2, 0x10, 0x8, 0x4000002, 0xff, 0x9, 0x4, 0x4, 0x0, 0x0, 0x7, 0x4e6, 0x8, 0x40000000, 0x5ef, 0x8000, 0xc, 0x41, 0x400, 0x1, 0x5, 0x0, 0x9a8, 0x0, 0x231, 0x400, 0x8, 0x1, 0xffff0001, 0x1, 0x1, 0x10, 0x8, 0x5396, 0x6161, 0x9, 0x101, 0x1ff, 0x8, 0x431, 0x6, 0x5, 0x4, 0x7b, 0x7fc, 0x9]}, 0x45c) read$FUSE(r2, &(0x7f0000002c40)={0x2020}, 0x2020) fdatasync(r1) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x15) ftruncate(r1, 0x81ff) 5m36.44699405s ago: executing program 6 (id=96): syz_usb_connect$uac1(0x0, 0xa5, &(0x7f0000000400)={{0x12, 0x1, 0x310, 0x0, 0x0, 0x0, 0x10, 0x1d6b, 0x101, 0x40, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x93, 0x3, 0x1, 0x3, 0xf0, 0x7, {{0x9, 0x4, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, {{0xa, 0x24, 0x1, 0x40, 0x92}, [@feature_unit={0xd, 0x24, 0x6, 0x5, 0x6, 0x3, [0x5, 0x5, 0x7], 0xff}, @processing_unit={0xc, 0x24, 0x7, 0x6, 0x3, 0x0, "4917fcb22d"}, @input_terminal={0xc, 0x24, 0x2, 0x5, 0x201, 0x1, 0x0, 0x1, 0x0, 0x6}, @output_terminal={0x9, 0x24, 0x3, 0x4, 0x302, 0x3, 0x1, 0xf7}, @selector_unit={0x6, 0x24, 0x5, 0x1, 0x0, "80"}]}}, {}, {0x9, 0x4, 0x1, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {}, {{0x9, 0x5, 0x1, 0x9, 0x40, 0x8, 0x0, 0x7, {0x7, 0x25, 0x1, 0x80, 0x0, 0x4}}}}, {}, {0x9, 0x4, 0x2, 0x1, 0x1, 0x1, 0x2, 0x0, 0x0, {}, {{0x9, 0x5, 0x82, 0x9, 0x10, 0x5, 0x5, 0x0, {0x7, 0x25, 0x1, 0xc1, 0xa, 0x7}}}}}}}]}}, &(0x7f0000000540)={0x0, 0x0, 0x0, 0x0}) 5m33.856791135s ago: executing program 6 (id=107): r0 = socket$nl_route(0x10, 0x3, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) r1 = socket$packet(0x11, 0x3, 0x300) ioctl$ifreq_SIOCGIFINDEX_wireguard(r1, 0x8933, &(0x7f00000001c0)={'wg1\x00', 0x0}) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000280)={0x1a, 0x0, 0x0, 0x0, 0x1, 0xc5, &(0x7f0000000180)=""/197, 0x0, 0x0, '\x00', 0x0, 0x19, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x2600, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) socket$inet(0x2, 0x1, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0xa, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, 0x0) r3 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f0000000180)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xb, &(0x7f0000000ac0)=ANY=[@ANYBLOB="1800000000000000000000000000000018010000786c6c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b7030000fdff"], 0x0, 0x0, 0x0, 0x0, 0x0, 0xa, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r6 = socket$inet6(0xa, 0x1, 0x0) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r6, 0x8933, &(0x7f0000000080)={'batadv_slave_1\x00'}) sendmsg$nl_route(r0, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000340)={&(0x7f0000000200)=@newlink={0xc0, 0x10, 0x1, 0x70bd29, 0x25dfdbfe, {0x0, 0x0, 0x0, r2, 0x0, 0x21001}, [@IFLA_PORT_SELF={0xa0, 0x19, 0x0, 0x1, [@IFLA_PORT_PROFILE={0x9c, 0x2, '\xff\xffO\x18\x81\xfbb;\xb5\x13f*F\xfa\xf2\xca\x976\xaaK\xdb3\xab\x8fo\xf3q?F\xf0E?\xc7\x82(.\xcd\xcaH\xd3\x0e\xd3K\xdcy\xe7\x99`\xad_\xaa\x03\xfc\x85?\xc3\xd6\x1b\x11f\r*\xcd<\xca\x80\x1aCx\xf9\xbaE\xea=\xb8|\x05\xdd7\xbd\x9d\xd8W\x01\xfb\f\xbc\"\x0f\xba\xd1\xaf\x16`\xf0=z\x99\xc4\x05\xd2\x92\xa1\xab\xd9\xbc6y\x8d\x95\x10Y5T\x96\xb3\xdaADI\x89\xcc\xcb\xb31?X\xaa\\>\r$t2\x9c\xa7W\x9e\xb3St\x11\xf6\xea\xd6\xc9\xb9\x9f\xdaYDk'}]}]}, 0xc0}, 0x1, 0x0, 0x0, 0x1}, 0x0) 5m29.529167873s ago: executing program 6 (id=120): r0 = syz_init_net_socket$nl_generic(0x10, 0x3, 0x10) r1 = syz_genetlink_get_family_id$nl802154(&(0x7f0000000300), 0xffffffffffffffff) sendmsg$NL802154_CMD_GET_WPAN_PHY(r0, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000080)={0x28, r1, 0x1, 0x70bd29, 0x25dfdbfc, {}, [@NL802154_ATTR_WPAN_PHY={0x8}, @NL802154_ATTR_WPAN_DEV={0xc, 0x6, 0x300000003}]}, 0x28}, 0x1, 0x0, 0x0, 0x4c040}, 0x2) 5m28.691236674s ago: executing program 6 (id=121): syz_mount_image$ext4(&(0x7f0000000040)='ext4\x00', &(0x7f0000000200)='./file1\x00', 0x200000, &(0x7f0000000240)={[{@noinit_itable}, {@usrquota}, {@dioread_lock}, {@norecovery}, {@debug_want_extra_isize={'debug_want_extra_isize', 0x3d, 0x32}}, {@lazytime}, {@nodelalloc}, {@usrquota}, {@nombcache}]}, 0xfe, 0x54c, &(0x7f0000000400)="$eJzs3d9rW1UcAPDvTdv91nUwhvoghT04mUvX1h8TfJiPosOBvs/Q3pXRZBlNOtY6cHtwL77IEEQciH+A7z4O/wH/ioEOhoyiD75EbnrTZWvSZm22Zubzgduec+9Nzz0593t6Tk5CAhhaE9mPQsSrEfFtEnG47dho5Acn1s5bfXh9NtuSaDQ++yuJJN/XOj/Jfx/MM69ExG9fR5wsbCy3tryyUCqX08U8P1mvXJmsLa+culQpzafz6eXpmZkz78xMv//eu32r65vn//nh07sfnfnm+Or3v9w/cjuJs3EoP9Zejx240Z6ZiIn8ORmLs0+cONWHwgZJstsXwLaM5HE+FlkfcDhG8qgH/v++iogGMKQS8Q9DqjUOaM3t+zQPfmE8+HBtArSx/qNrr43Evubc6MBq8tjMKJvvjveh/KyMX/+8czvbon+vQwBs6cbNiDg9Orqx/0vy/m/7TvdwzpNl6P/g+bmbjX/e6jT+KayPf6LD+Odgh9jdjq3jv3C/D8V0lY3/Pug4/l1ftBofyXMvNcd8Y8nFS+U069tejogTMbY3y2+2nnNm9V6j27H28V+2ZeW3xoL5ddwf3fv4Y+ZK9dJO6tzuwc2I1zqOf5P19k86tH/2fJzvsYxj6Z3Xux3buv7PVuPniDc6tv+jFa1k8/XJyeb9MNm6Kzb6+9ax37uVv9v1z9r/wOb1H0/a12trT1/GT/v+Tbsd2+79vyf5vJnek++7VqrXF6ci9iSfbNw//eixrXzr/Kz+J45v3v91uv/3R8QXPdb/1tFbXU8dhPafe6r2f/rEvY+//LFb+b21/9vN1Il8Ty/9X68XuJPnDgAAAAAAAAZNISIORVIorqcLhWJx7f0dR+NAoVyt1U9erC5dnovmZ2XHY6zQWuk+3PZ+iKn8/bCt/PQT+ZmIOBIR343sb+aLs9Xy3G5XHgAAAAAAAAAAAAAAAAAAAAbEwS6f/8/8MbLbVwc8c77yG4bXlvHfj296AgaS//8wvMQ/DC/xD8NL/MPwEv8wvMQ/DC/xD8NL/AMAAAAAAAAAAAAAAAAAAAAAAAAAAEBfnT93Ltsaqw+vz2b5uavLSwvVq6fm0tpCsbI0W5ytLl4pzler8+W0OFutbPX3ytXqlanpWLo2WU9r9cna8sqFSnXpcv3CpUppPr2Qjj2XWgEAAAAAAAAAAAAAAAAAAMCLpba8slAql9NFCYltJUYH4zIk+pzY7Z4JAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB75LwAA///MUDi3") syz_mount_image$vfat(&(0x7f00000002c0), &(0x7f0000000100)='./bus\x00', 0x2129c1b, 0x0, 0x4, 0x0, &(0x7f0000000100)) mount$overlay(0x0, &(0x7f0000000080)='./file0\x00', &(0x7f0000000000), 0x10000, &(0x7f00000002c0)={[{@workdir={'workdir', 0x3d, './file0'}}, {@lowerdir={'lowerdir', 0x3d, '.'}}, {@upperdir={'upperdir', 0x3d, './bus'}}], [], 0x2c}) r0 = open(&(0x7f0000000980)='./bus\x00', 0x30000, 0x1b0) ioctl$FS_IOC_REMOVE_ENCRYPTION_KEY(r0, 0x8004587d, &(0x7f00000009c0)={@desc={0x1, 0x0, @desc2}}) utime(&(0x7f0000000a00)='./file0\x00', 0x0) 5m27.262817023s ago: executing program 6 (id=125): bpf$PROG_LOAD_XDP(0x5, &(0x7f00000001c0)={0x12, 0x0, 0x0, &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0xe, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 5m26.616519762s ago: executing program 6 (id=129): r0 = syz_open_dev$tty1(0xc, 0x4, 0x1) r1 = dup(r0) write$UHID_INPUT(r1, 0x0, 0x0) 5m25.405634748s ago: executing program 34 (id=129): r0 = syz_open_dev$tty1(0xc, 0x4, 0x1) r1 = dup(r0) write$UHID_INPUT(r1, 0x0, 0x0) 7.961079674s ago: executing program 5 (id=1313): r0 = socket$netlink(0x10, 0x3, 0x0) r1 = socket(0x200000000000011, 0x2, 0x0) ioctl$sock_SIOCGIFINDEX(r1, 0x8933, &(0x7f0000000080)={'team0\x00', 0x0}) sendmsg$nl_route(r0, &(0x7f0000000200)={0x0, 0xfff0, &(0x7f0000000540)={&(0x7f0000000240)=@newlink={0x48, 0x10, 0xff05, 0x0, 0x0, {0x0, 0x0, 0x4a00}, [@IFLA_LINKINFO={0x14, 0x12, 0x0, 0x1, @batadv={{0xb}, {0x4}}}, @IFLA_MASTER={0x8, 0xa, r2}, @IFLA_ADDRESS={0xa, 0x1, @multicast}]}, 0x48}}, 0x0) 7.755370047s ago: executing program 5 (id=1315): r0 = socket$inet6(0xa, 0x806, 0x0) listen(r0, 0x3) shutdown(r0, 0x0) 7.679511448s ago: executing program 5 (id=1316): r0 = syz_usb_connect(0x0, 0x2d, &(0x7f00000003c0)=ANY=[@ANYBLOB="120100009ac0b620110f211066865578ac0109029c000100000400090400bf900b64ea00090587033b"], 0x0) syz_usb_control_io(r0, 0x0, 0x0) syz_usb_disconnect(r0) r1 = syz_open_dev$char_usb(0xc, 0xb4, 0x0) writev(r1, &(0x7f0000002580)=[{&(0x7f0000000400)="b4", 0x1}], 0x1) r2 = syz_io_uring_setup(0x10d, &(0x7f0000000140)={0x0, 0x5885}, &(0x7f0000000340)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r3, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r3, r4, &(0x7f00000002c0)=@IORING_OP_WRITEV={0x2, 0x0, 0x4004, @fd_index=0x3, 0x0, 0x0}) io_uring_enter(r2, 0x3516, 0x0, 0x0, 0x0, 0x0) 6.878962699s ago: executing program 7 (id=1318): socket$nl_generic(0x10, 0x3, 0x10) openat$vga_arbiter(0xffffffffffffff9c, &(0x7f0000000000), 0x80082, 0x0) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x2) ioctl$KVM_SET_MSRS(r2, 0x4008ae89, &(0x7f0000000440)=ANY=[@ANYBLOB="01000000000000002201"]) 6.730021041s ago: executing program 7 (id=1320): syz_usb_connect(0x0, 0x24, &(0x7f0000000000)=ANY=[@ANYBLOB="1201000075f84c1071042703a461000000010902"], 0x0) openat$kvm(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) r1 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000100), 0x41, 0x0) ioctl$TCSETS(r1, 0x40045431, &(0x7f0000000dc0)={0x0, 0x0, 0x0, 0x800, 0x0, "00629a7d82000000000000000000f7ffffff00"}) r2 = ioctl$TIOCGPTPEER(r1, 0x5441, 0x0) dup3(r2, r1, 0x0) ioctl$int_in(r2, 0x5452, &(0x7f00000003c0)=0x1) ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000040)={0x2, &(0x7f0000000000)=[{0x54}, {0x6, 0xfd, 0x0, 0x7ffffcb9}]}) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) write$binfmt_misc(0xffffffffffffffff, 0x0, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) sched_setaffinity(0x0, 0x8, &(0x7f0000000280)=0x2) connect$unix(r3, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) ptrace(0x10, 0x1) 6.152138948s ago: executing program 2 (id=1326): r0 = socket$inet6(0xa, 0x806, 0x0) shutdown(r0, 0x0) 6.127616169s ago: executing program 2 (id=1327): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000040), 0x8000, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) sendmsg$nl_xfrm(0xffffffffffffffff, &(0x7f0000000180)={0x0, 0x0, &(0x7f00000000c0)={0x0, 0xb8}}, 0x0) r2 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000001c0)='cpuacct.usage_percpu_user\x00', 0x275a, 0x0) write$binfmt_script(r2, &(0x7f0000000000), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x1000003, 0x28011, r2, 0x0) preadv(r2, &(0x7f00000015c0)=[{&(0x7f0000000080)=""/124, 0xffffff23}], 0x1, 0x0, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r1, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x20002000, &(0x7f0000000000/0x2000)=nil}) r3 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r3, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000140)=[@text64={0x40, 0x0}], 0x1, 0x44, 0x0, 0x0) ioctl$KVM_SET_FPU(r2, 0x41a0ae8d, &(0x7f0000000240)={'\x00', 0x4, 0x9, 0x99, 0x0, 0x0, 0x10000, 0x2, '\x00', 0xc94}) ioctl$KVM_RUN(r3, 0xae80, 0x0) 5.599641096s ago: executing program 2 (id=1329): add_key$keyring(&(0x7f0000000000), &(0x7f00000004c0)={'syz', 0x2}, 0x0, 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000340)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000000c0)=@newtaction={0xa4, 0x30, 0x1, 0x0, 0x25dfdbfb, {}, [{0x90, 0x1, [@m_ct={0x44, 0x2, 0x0, 0x0, {{0x7}, {0x1c, 0x2, 0x0, 0x1, [@TCA_CT_PARMS={0x18, 0x1, {0x9d, 0x11e41e7a, 0x8, 0x0, 0xf}}]}, {0x4}, {0xc, 0x7, {0x0, 0x1}}, {0xc, 0x8, {0x3, 0x1}}}}, @m_ife={0x48, 0x3, 0x0, 0x0, {{0x8}, {0x20, 0x2, 0x0, 0x1, [@TCA_IFE_PARMS={0x1c}]}, {0x4}, {0xc}, {0xc, 0x8, {0x1}}}}]}]}, 0xa4}, 0x1, 0x0, 0x0, 0x804}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) openat$sysfs(0xffffffffffffff9c, &(0x7f0000000400)='/sys/power/resume', 0x149a82, 0x0) r0 = socket$inet(0xa, 0x801, 0x84) connect$inet(r0, &(0x7f0000004cc0)={0x2, 0x0, @remote={0xac, 0x14, 0xffffffffffffffff}}, 0x10) listen(r0, 0xfffffffd) r1 = syz_open_dev$sndmidi(&(0x7f0000000100), 0x2, 0x141121) r2 = dup(r1) write$6lowpan_enable(r2, &(0x7f0000000000)='0', 0xfffffd2c) syz_io_uring_setup(0x38fe, &(0x7f0000000300)={0x0, 0x2355, 0x10100}, &(0x7f0000000180)=0x0, &(0x7f00000001c0)=0x0) syz_io_uring_submit(r3, r4, &(0x7f0000000140)=@IORING_OP_POLL_ADD={0x6, 0x0, 0x0, @fd=r1}) r5 = accept4(r0, 0x0, 0x0, 0x0) recvmmsg(r5, &(0x7f0000001000), 0x581, 0x40000000, 0x0) setsockopt$inet_sctp6_SCTP_EVENTS(r5, 0x84, 0xb, &(0x7f00000002c0)={0x3, 0x1, 0x2, 0xff, 0xa4, 0x0, 0x1, 0x0, 0x5, 0x8, 0x0, 0x0, 0x2, 0x20}, 0xe) 4.931719835s ago: executing program 5 (id=1332): socket$nl_generic(0x10, 0x3, 0x10) r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f00000002c0), 0x48401, 0x0) r1 = socket$inet6_tcp(0xa, 0x1, 0x0) r2 = syz_open_dev$loop(&(0x7f0000000140), 0x75f, 0xa382) r3 = memfd_create(&(0x7f0000000880)='C\x13\xfc2\x95WD\xaa\xba^\x90\xfd\x8d\xc2\xb1[\x81\xda\xda\xd6\x8c\xc99\xec\x0e*||\xe4\xb3\xc4\xb6\v\xaa\x15\x86,\xac\x8d\x89cu\x10\xdc\x93\x9b\xb4\x93\xafE*:\xe4\xdd\xa5\xa75\xb8\x1e;7\xb7.V\xdcrw[\r\x98\x93j\x9c\xf6\xf8\x99\xefF_\xcd\xdf!b\xc5\xec\ntb\xff\b\xaaF?!\x9f\a\x1a\x03\f\xe94\x1deU\x06zS\xc90\xb9voI\xa5/\xb4\xa7@\xa1\\B\xc2@\r_b\x9a\xeb\b\x81\x00V\xd6/N\xc5\xc6f\xb1\x95Z\xe5w^\xd8\xe7J\x80\xf7\xae\xafuv\x84\x9eG\xd1\xe7\x9b\xf0_9\xc2\x9b\xfd\xc3\xf3\xe4\x95P\xf1m\xcf\xc2\xe1\xe6\xa6\x8c\x11\xfb\xb8S\x8b\x92\\\asW-Ee\x02\x00\x00\x00\xd0;Q\xc1~\x89\xec\xc8\x9b\x88\a\xf2\x93\x82(\x8b\x00\xd8\xb4T\x80\x95\x93\x9c5\xcf\t\x04\x00\x00\x00\x00\x00\x00v\xef\xee+\xab\x9c\x00^R\xb2n?i=\xbe\x16\x8a\xbf\xe3\xcdB\xed\xe14\xe8\xd0\xb7\xff\xfeQ\x1c\x85n8\x1b\xc1\b\x00\x00\x00\x00\x00\x00\x00\x17\x94\xdfW\x92z\xbe\xb2R)\xf1K\xd7\xaf\x99\xf6d\xe8\xec\xb7\xbd+T3\xa6\xa9\xfaY-1qs\x82\xefn*\x96\xc9\x1e\xf4\xd1\x02Dt\xc0\x19\xf7\x89\x96.D [F\xeeYW\x95\x13\xc7;\x94\x13^\x13\xaf\xf0C\x9c\xabf\x1daCS2\x02\xb0\xef\xc7\x8c\x9e\xed\a\nr3, {0xee00, 0xffffffffffffffff}}, './file1\x00'}) write$sndseq(r4, &(0x7f0000000040)=[{0x41, 0xb2, 0xb, 0x2a, @tick=0x4, {0x3, 0x3}, {0x0, 0x9}, @note={0x9, 0x1, 0x1, 0x9, 0x120000}}], 0x1c) ioctl$LOOP_CHANGE_FD(r2, 0x4c06, r1) ioctl$TCSETS(r0, 0x40045431, &(0x7f0000000dc0)={0x0, 0x3, 0x1000002, 0x0, 0x5, "d4e9002b2c00000000008000"}) r5 = syz_open_pts(r0, 0x0) r6 = dup(r5) ioctl$TIOCSETD(r6, 0x5423, &(0x7f00000000c0)=0x3) bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x78) r7 = openat$ppp(0xffffffffffffff9c, &(0x7f0000000840), 0x1a01, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000140)='./file1\x00', 0x1c0) r8 = syz_open_dev$swradio(&(0x7f0000000700), 0x0, 0x2) ioctl$VIDIOC_G_FMT(r8, 0xc0cc5604, 0x0) r9 = landlock_create_ruleset(&(0x7f0000000180)={0x100}, 0x18, 0x0) r10 = openat$dir(0xffffffffffffff9c, &(0x7f0000000240)='./file1\x00', 0x0, 0x0) landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r9, 0x1, &(0x7f0000000280)={0x100, r10}, 0x0) openat$dir(0xffffffffffffff9c, &(0x7f0000000300)='./file1\x00', 0x80400, 0x0) landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r9, 0x1, &(0x7f0000000080)={0x890c, r9}, 0x0) ioctl$EVIOCGPROP(r7, 0x40047438, &(0x7f0000000180)=""/246) 4.55310633s ago: executing program 2 (id=1335): syz_memcpy_off$IO_URING_METADATA_GENERIC(0x0, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) openat$cuse(0xffffffffffffff9c, 0x0, 0x2, 0x0) ioctl$AUTOFS_DEV_IOCTL_REQUESTER(0xffffffffffffffff, 0xc018937b, 0x0) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x80800, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) r3 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000080), 0x4000000004002, 0x0) r4 = dup(r3) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2000007, 0x38011, r4, 0x0) madvise(&(0x7f0000000000/0xc00000)=nil, 0xc00000, 0x1) madvise(&(0x7f0000000000/0xc00000)=nil, 0xc00000, 0x17) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r2, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000140)=[@text64={0x40, 0x0}], 0x1, 0xe8, 0x0, 0x0) write$vhost_msg_v2(r1, &(0x7f0000000240)={0x2, 0x0, {0x0, 0x0, &(0x7f00000001c0)=""/83, 0x3, 0x1}}, 0x48) ioctl$KVM_RUN(r2, 0xae80, 0x0) 2.845220512s ago: executing program 0 (id=1340): creat(0x0, 0xd931d3864d39ddd8) r0 = socket(0x10, 0x803, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, 0x0) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket$vsock_stream(0x28, 0x1, 0x0) connect$vsock_stream(r4, &(0x7f0000000140)={0x28, 0x0, 0x0, @my=0x1}, 0x10) pread64(0xffffffffffffffff, &(0x7f0000032140)=""/102344, 0x18fc8, 0x4000c2a) r5 = openat$tun(0xffffffffffffff9c, &(0x7f0000000340), 0x302, 0x0) ioctl$TUNSETIFF(r5, 0x400454ca, 0x0) r6 = socket(0x400000000010, 0x3, 0x0) r7 = socket$unix(0x1, 0x5, 0x0) ioctl$sock_SIOCGIFINDEX(r7, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r6, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000000640)=@newqdisc={0x48, 0x24, 0x4ee4e6a52ff56541, 0x70bd26, 0xffffffff, {0x0, 0x0, 0x0, r8, {0x0, 0xfff1}, {0xffff, 0xffff}, {0xffff, 0xf}}, [@qdisc_kind_options=@q_htb={{0x8}, {0x1c, 0x2, [@TCA_HTB_INIT={0x18, 0x2, {0x3, 0x4, 0x6}}]}}]}, 0x48}, 0x1, 0x0, 0x0, 0x40000}, 0x0) sendmsg$nl_route_sched(r0, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000480)=@newtfilter={0x30, 0x2c, 0xd27, 0x0, 0x0, {0x0, 0x0, 0x0, r8, {0xe, 0xfff1}, {}, {0xb, 0xb}}, [@filter_kind_options=@f_u32={{0x8}, {0x4}}]}, 0x30}, 0x1, 0x0, 0x0, 0x80}, 0x40) 2.760343813s ago: executing program 5 (id=1341): r0 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp_SCTP_SOCKOPT_BINDX_ADD(r0, 0x84, 0x64, &(0x7f0000000000)=[@in6={0xa, 0x4e23, 0x401, @loopback}], 0x1c) sendto$inet6(r0, &(0x7f0000000080)="b1", 0x1, 0x400c0d4, &(0x7f0000000140)={0xa, 0x4e23, 0x0, @loopback, 0xffffffff}, 0x1c) r1 = socket$inet6_sctp(0xa, 0x5, 0x84) dup2(r0, r1) setsockopt$inet_sctp6_SCTP_DELAYED_SACK(r1, 0x84, 0x10, &(0x7f0000000080)=@assoc_value={0x0, 0x3}, 0x8) 2.644541855s ago: executing program 5 (id=1342): syz_usb_connect(0x0, 0x3f, &(0x7f00000000c0)=ANY=[@ANYBLOB="11010000733336088dee1adb23610000000109022d0001100000000904000003fe03010009cd8d1f00020000000905050200de7e"], 0x0) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000000)={0x1, &(0x7f0000000100)=[{0x6, 0x0, 0x0, 0x7fff0000}]}) ioprio_get$pid(0x0, 0x0) r0 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r0, 0x0, 0x0) connect$inet(r0, 0x0, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e20}, 0x6e) sendmmsg$unix(r2, &(0x7f00000bd000), 0x318, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r3 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r3, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000480)=ANY=[@ANYBLOB="fc0000001900674c0000000000000000e0000001000000000000000000000000e000000200000000000000000000000000000000000000000a00000000000000", @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="0000000000000000000000000000400000000000000000000000000000000000000000000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000044000500000000000000000000000000000000000000000033"], 0xfc}}, 0x0) r4 = socket$inet6(0xa, 0x2, 0x0) connect$inet6(r4, &(0x7f00000002c0)={0xa, 0x4e24}, 0x1c) sendmmsg(r4, &(0x7f00000092c0), 0x4ff, 0xfdff) 2.643811145s ago: executing program 2 (id=1343): r0 = openat$fuse(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) read$FUSE(r0, &(0x7f00000021c0)={0x2020}, 0x2020) syz_fuse_handle_req(r0, 0x0, 0x0, 0x0) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000300)={0xffffffffffffffff}) ioctl$sock_SIOCGIFVLAN_DEL_VLAN_CMD(r1, 0x8982, &(0x7f0000002800)={0x1, 'vlan0\x00'}) socket(0x10, 0x80002, 0x0) socket$inet_udplite(0x2, 0x2, 0x88) r2 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r2, &(0x7f0000000080)={0x2, 0x4e21, @broadcast}, 0x10) connect$inet(r2, 0x0, 0x0) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r2, 0x6, 0x16, 0x0, 0x0) setsockopt$inet_tcp_TCP_CONGESTION(r2, 0x6, 0xd, &(0x7f0000000240)='yeah\x00', 0x5) setsockopt$inet_tcp_TCP_REPAIR(r2, 0x6, 0x13, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000000), 0xffffffffffffff94, 0x0, 0x0, 0x0) recvfrom$inet(r2, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0x700, 0x0, 0xfffffffffffffd25) r3 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_CREATE(r3, &(0x7f0000000100)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000140)={0x50, 0x2, 0x6, 0x5, 0x0, 0x0, {}, [@IPSET_ATTR_PROTOCOL={0x5}, @IPSET_ATTR_SETNAME={0x9, 0x2, 'syz1\x00'}, @IPSET_ATTR_DATA={0xc, 0x7, 0x0, 0x1, [@IPSET_ATTR_HASHSIZE={0x8}]}, @IPSET_ATTR_TYPENAME={0xc, 0x3, 'hash:ip\x00'}, @IPSET_ATTR_FAMILY={0x5, 0x5, 0xa}, @IPSET_ATTR_REVISION={0x5, 0x4, 0x1}]}, 0x50}, 0x1, 0x0, 0x0, 0x4004000}, 0x40080) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_CREATE(r4, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000001c0)={0x48, 0x2, 0x6, 0x5, 0x0, 0x0, {}, [@IPSET_ATTR_SETNAME={0x9, 0x2, 'syz2\x00'}, @IPSET_ATTR_REVISION={0x5, 0x4, 0x1}, @IPSET_ATTR_PROTOCOL={0x5, 0x1, 0x6}, @IPSET_ATTR_FAMILY={0x5, 0x5, 0xa}, @IPSET_ATTR_TYPENAME={0x10, 0x3, 'hash:ip,mac\x00'}]}, 0x48}}, 0x0) r5 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_FLUSH(r5, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000100)=ANY=[@ANYBLOB="1c000000040601010000000000000000000000000500010007"], 0x1c}}, 0x0) 2.362272389s ago: executing program 2 (id=1344): r0 = socket(0x10, 0x3, 0x0) sendmsg$nl_route(r0, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000240)=ANY=[@ANYBLOB="170000001a0001000000000000000000"], 0x24}}, 0x0) r1 = syz_usb_connect_ath9k(0x3, 0x5a, &(0x7f0000000480)={{0x12, 0x1, 0x200, 0xff, 0xff, 0xff, 0x40, 0xcf3, 0x9271, 0x108, 0x1, 0x2, 0x3, 0x38e38e38e38e6ef, [{{0x9, 0x2, 0x48}}]}}, 0x0) syz_usb_ep_write$ath9k_ep2(r1, 0x83, 0x10, &(0x7f0000000040)=@conn_svc_rsp={0x0, 0x0, 0x0, "5da08b79", {0x3, 0x102, 0x0, 0x0, 0x9, 0x2, 0x3}}) mmap(&(0x7f0000000000/0x400000)=nil, 0x400000, 0x2, 0xc3072, 0xffffffffffffffff, 0x200000) socketpair$tipc(0x1e, 0x2, 0x0, &(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}) setsockopt$TIPC_DEST_DROPPABLE(r2, 0x10f, 0x81, &(0x7f0000000080), 0x4) sendmmsg$inet(r2, &(0x7f0000001540)=[{{0x0, 0xfffffffffffffda1, 0x0}}], 0x40001b6, 0x0) close(r3) migrate_pages(0x0, 0x5, &(0x7f0000000040)=0x9, &(0x7f0000000080)=0x272) preadv(0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0) ioctl$DRM_IOCTL_WAIT_VBLANK(0xffffffffffffffff, 0xc018643a, &(0x7f0000000080)={0x4000000, 0x0, 0x3}) connect$inet6(0xffffffffffffffff, &(0x7f0000000080)={0xa, 0x0, 0x7, @loopback}, 0x1c) r4 = syz_open_dev$usbmon(&(0x7f0000000fc0), 0xff, 0x20000) ioctl$MON_IOCG_STATS(r4, 0x80089203, 0x0) r5 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) ptrace(0x10, r5) ptrace$poke(0x5, r5, &(0x7f0000000080), 0x200000000000000) 1.846296895s ago: executing program 7 (id=1345): add_key$keyring(&(0x7f0000000000), &(0x7f00000004c0)={'syz', 0x2}, 0x0, 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) openat$sysfs(0xffffffffffffff9c, &(0x7f0000000400)='/sys/power/resume', 0x149a82, 0x0) r0 = socket$inet(0xa, 0x801, 0x84) connect$inet(r0, &(0x7f0000004cc0)={0x2, 0x0, @remote={0xac, 0x14, 0xffffffffffffffff}}, 0x10) listen(r0, 0xfffffffd) r1 = syz_open_dev$sndmidi(&(0x7f0000000100), 0x2, 0x141121) r2 = dup(r1) write$6lowpan_enable(r2, &(0x7f0000000000)='0', 0xfffffd2c) syz_io_uring_setup(0x38fe, &(0x7f0000000300)={0x0, 0x2355, 0x10100}, &(0x7f0000000180)=0x0, &(0x7f00000001c0)=0x0) syz_io_uring_submit(r3, r4, &(0x7f0000000140)=@IORING_OP_POLL_ADD={0x6, 0x0, 0x0, @fd=r1}) r5 = accept4(r0, 0x0, 0x0, 0x0) recvmmsg(r5, &(0x7f0000001000), 0x581, 0x40000000, 0x0) setsockopt$inet_sctp6_SCTP_EVENTS(r5, 0x84, 0xb, &(0x7f00000002c0)={0x3, 0x1, 0x2, 0xff, 0xa4, 0x0, 0x1, 0x0, 0x5, 0x8, 0x0, 0x0, 0x2, 0x20}, 0xe) 1.53103539s ago: executing program 0 (id=1346): r0 = openat$tun(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) ioctl$TUNSETIFF(r0, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) r1 = socket(0x400000000010, 0x3, 0x0) r2 = socket$unix(0x1, 0x1, 0x0) ioctl$sock_SIOCGIFINDEX(r2, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r1, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2d, 0xffffffff, {0x0, 0x0, 0x0, r3, {0x0, 0xfff1}, {0xffff, 0xffff}, {0x1, 0x10}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8, 0x2, {0x28}}}]}, 0x38}}, 0x0) sendmsg$nl_route_sched(r1, &(0x7f0000006040)={0x0, 0x0, &(0x7f0000000440)={&(0x7f0000006080)=@newtfilter={0x3c, 0x2c, 0xd27, 0x70bd28, 0x8000, {0x0, 0x0, 0x0, r3, {0x0, 0x7}, {}, {0xa}}, [@filter_kind_options=@f_flow={{0x9}, {0xc, 0x2, [@TCA_FLOW_KEYS={0x8, 0x1, 0x2009200}]}}]}, 0x3c}, 0x1, 0x0, 0x0, 0x80}, 0x20000000) 1.271990693s ago: executing program 3 (id=1347): r0 = socket$inet_udp(0x2, 0x2, 0x0) bind$inet(r0, &(0x7f00000001c0)={0x2, 0x0, @local}, 0x10) connect$inet(r0, &(0x7f0000000480)={0x2, 0x0, @multicast2}, 0x10) sendmmsg(r0, &(0x7f0000007fc0), 0x800001d, 0x0) setsockopt$IP_VS_SO_SET_ADD(r0, 0x0, 0x482, &(0x7f0000000040)={0x100000011, @multicast2, 0x0, 0x0, 'sh\x00', 0x32, 0x85, 0x76}, 0x2c) 1.187722114s ago: executing program 0 (id=1348): r0 = openat$sequencer(0xffffffffffffff9c, &(0x7f0000000040), 0x8002, 0x0) r1 = syz_io_uring_setup(0x88c, &(0x7f0000000140)={0x0, 0x35a, 0x0, 0x20000002, 0xbfdffffc}, &(0x7f0000000100)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r2, r3, &(0x7f00000002c0)=@IORING_OP_POLL_ADD={0x6, 0x10, 0x0, @fd_index=0x3, 0x0, 0x0, 0x0, {0x1}}) io_uring_enter(r1, 0x47f6, 0x0, 0x2, 0x0, 0x0) syz_fuse_handle_req(0xffffffffffffffff, 0x0, 0x0, &(0x7f0000003540)={&(0x7f0000000140)={0x50, 0x0, 0x9, {0x7, 0x2b, 0x8, 0x100140, 0x0, 0x9, 0x6, 0x10002, 0x0, 0x0, 0x8, 0x6}}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) write$P9_RSTATu(r0, &(0x7f00000000c0)=ANY=[@ANYBLOB="320200007d00000005f100000000000005"], 0x232) 1.187396094s ago: executing program 7 (id=1349): r0 = socket$inet6(0xa, 0x806, 0x0) shutdown(r0, 0x0) 1.097041975s ago: executing program 7 (id=1350): r0 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000040), 0x0) ioctl$SNDRV_SEQ_IOCTL_CREATE_QUEUE(r0, 0xc08c5332, &(0x7f00000001c0)={0x4, 0x0, 0x0, 'queue0\x00'}) r1 = openat$sndseq(0xffffffffffffff9c, &(0x7f0000000000), 0x8882) ioctl$SNDRV_SEQ_IOCTL_SET_QUEUE_TIMER(r1, 0x40605346, &(0x7f0000000400)={0x0, 0x0, {0x3}, 0x8}) write$sndseq(r1, &(0x7f0000000140), 0x0) 1.096220196s ago: executing program 0 (id=1351): openat$sw_sync(0xffffffffffffff9c, &(0x7f0000000640), 0x0, 0x0) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, &(0x7f0000000000)={0x0, &(0x7f0000000100)}) ioprio_get$pid(0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r0 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r0, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000480)=ANY=[@ANYBLOB="fc0000001900674c0000000000000000e0000001000000000000000000000000e000000200000000000000000000000000000000000000000a00000000000000", @ANYRES32=0x0, @ANYRES32=0x0, @ANYBLOB="0000000000000000000000000000400000000000000000000000000000000000000000000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000044000500000000000000000000000000000000000000000033"], 0xfc}}, 0x0) r1 = socket$inet6(0xa, 0x2, 0x0) connect$inet6(r1, &(0x7f00000002c0)={0xa, 0x4e24}, 0x1c) sendmmsg(r1, &(0x7f00000092c0), 0x4ff, 0xfdff) 1.031971786s ago: executing program 7 (id=1352): r0 = syz_usb_connect(0x2, 0x36, &(0x7f0000000040)=ANY=[@ANYBLOB="120100001a77aa4094225b4210a20102030109022400010000000009040000029233500009050602ff030000000905"], 0x0) mlockall(0x2) r1 = shmget$private(0x0, 0x400000, 0x8, &(0x7f000000e000/0x400000)=nil) shmctl$SHM_LOCK(r1, 0xb) shmat(r1, &(0x7f0000ffd000/0x1000)=nil, 0x7000) shmctl$SHM_UNLOCK(r1, 0xc) unshare(0x20000400) r2 = openat$rtc(0xffffffffffffff9c, &(0x7f0000002600), 0x101840, 0x0) ioctl$RTC_AIE_ON(r2, 0x7001) r3 = syz_open_dev$vim2m(&(0x7f0000000000), 0x7f, 0x2) ioctl$vim2m_VIDIOC_S_FMT(r3, 0xc0d05605, &(0x7f0000000040)={0x1, @raw_data="dfab4d85d47fab3f5852323481422e0f382a7fff4f2f6544e6018dbd8ab7448ced0cb6d971aa93e8b234fd2ceb6c160545bc47d95cb6f68a98ee9ea4686093a60d1e90430c08857fd0c428cdd40ea133631f9993733758d144b78ac24b59a54138ada8c18089c1250c7de9ef6ad3b2f7f28322211b5313b263f34c07a174f7d1d0f000f2bd2a60f9e4f18a82318f990d85778a2b77c73764d2d187c87800f0905ca84dbdd9002b572b0928a92da591fbaa566464e5cb6dbaf6a6945d91b66259944c62c5090ca50c"}) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFULNL_MSG_CONFIG(r4, &(0x7f00000030c0)={0x0, 0x0, &(0x7f0000003080)={&(0x7f0000003040)={0x2c, 0x1, 0x4, 0x201, 0x0, 0x0, {0xa, 0x0, 0x2}, [@NFULA_CFG_FLAGS={0x6, 0x6, 0x1, 0x0, 0x4}, @NFULA_CFG_QTHRESH={0x8, 0x5, 0x1, 0x0, 0x8}, @NFULA_CFG_CMD={0x5, 0x1, 0x1}]}, 0x2c}, 0x1, 0x0, 0x0, 0x40084}, 0x0) connect$packet(0xffffffffffffffff, &(0x7f0000000100)={0x28, 0xf5, 0x0, 0x1, 0x2, 0x6, @link_local}, 0x14) ioctl$RTC_ALM_SET(r2, 0x40247007, &(0x7f00000000c0)={0x33, 0x1a, 0xe, 0x1, 0x3, 0x2, 0x2, 0x70}) r5 = openat$vmci(0xffffffffffffff9c, 0x0, 0x2, 0x0) ioctl$IOCTL_VMCI_VERSION2(r5, 0x7a7, &(0x7f0000000040)=0x90000) ioctl$IOCTL_VMCI_INIT_CONTEXT(r5, 0x7a0, &(0x7f0000000240)={@local}) ioctl$IOCTL_VMCI_QUEUEPAIR_ALLOC(r5, 0x7a8, &(0x7f0000000540)={{@any, 0xc25}, @my=0x1, 0x0, 0x0, 0x9, 0x0, 0x0, 0xfffffffd}) bpf$PROG_LOAD(0x5, &(0x7f0000000100)={0x12, 0x0, 0x0, 0x0, 0x4, 0x0, 0x0, 0x41000, 0x2a, '\x00', 0x0, @cgroup_sock_addr=0x13, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) syz_usb_control_io$cdc_ncm(r0, 0x0, &(0x7f0000000440)={0x44, &(0x7f0000000240)=ANY=[@ANYBLOB="40010400000003"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) 1.020407197s ago: executing program 0 (id=1353): r0 = socket$inet_udplite(0x2, 0x2, 0x88) sendmmsg$inet(r0, &(0x7f0000005b40)=[{{&(0x7f0000000000)={0x2, 0x4e20, @multicast2}, 0x10, 0x0, 0x0, &(0x7f0000000240)=[@ip_pktinfo={{0x1c, 0x0, 0x8, {0x0, @local, @multicast2}}}], 0x20}}], 0x1, 0x4000044) 1.012597537s ago: executing program 3 (id=1354): r0 = openat$fuse(0xffffffffffffff9c, &(0x7f0000000080), 0x2, 0x0) read$FUSE(r0, &(0x7f00000021c0)={0x2020}, 0x2020) syz_fuse_handle_req(r0, 0x0, 0x0, 0x0) socket$igmp(0x2, 0x3, 0x2) ioctl$sock_SIOCGIFVLAN_DEL_VLAN_CMD(0xffffffffffffffff, 0x8982, &(0x7f0000002800)={0x1, 'vlan0\x00'}) socket(0x10, 0x80002, 0x0) socket$inet_udplite(0x2, 0x2, 0x88) r1 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r1, &(0x7f0000000080)={0x2, 0x4e21, @broadcast}, 0x10) connect$inet(r1, 0x0, 0x0) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r1, 0x6, 0x16, 0x0, 0x0) setsockopt$inet_tcp_TCP_CONGESTION(r1, 0x6, 0xd, &(0x7f0000000240)='yeah\x00', 0x5) setsockopt$inet_tcp_TCP_REPAIR(r1, 0x6, 0x13, 0x0, 0x0) sendto$inet(r1, &(0x7f0000000000), 0xffffffffffffff94, 0x0, 0x0, 0x0) recvfrom$inet(r1, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0x700, 0x0, 0xfffffffffffffd25) r2 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_CREATE(r2, &(0x7f0000000100)={0x0, 0x0, &(0x7f00000000c0)={&(0x7f0000000140)={0x50, 0x2, 0x6, 0x5, 0x0, 0x0, {}, [@IPSET_ATTR_PROTOCOL={0x5}, @IPSET_ATTR_SETNAME={0x9, 0x2, 'syz1\x00'}, @IPSET_ATTR_DATA={0xc, 0x7, 0x0, 0x1, [@IPSET_ATTR_HASHSIZE={0x8}]}, @IPSET_ATTR_TYPENAME={0xc, 0x3, 'hash:ip\x00'}, @IPSET_ATTR_FAMILY={0x5, 0x5, 0xa}, @IPSET_ATTR_REVISION={0x5, 0x4, 0x1}]}, 0x50}, 0x1, 0x0, 0x0, 0x4004000}, 0x40080) r3 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_CREATE(r3, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000001c0)={0x48, 0x2, 0x6, 0x5, 0x0, 0x0, {}, [@IPSET_ATTR_SETNAME={0x9, 0x2, 'syz2\x00'}, @IPSET_ATTR_REVISION={0x5, 0x4, 0x1}, @IPSET_ATTR_PROTOCOL={0x5, 0x1, 0x6}, @IPSET_ATTR_FAMILY={0x5, 0x5, 0xa}, @IPSET_ATTR_TYPENAME={0x10, 0x3, 'hash:ip,mac\x00'}]}, 0x48}}, 0x0) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_FLUSH(r4, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000100)=ANY=[@ANYBLOB="1c000000040601010000000000000000000000000500010007"], 0x1c}}, 0x0) 944.900778ms ago: executing program 0 (id=1355): syz_usb_connect(0x5, 0x36, &(0x7f0000000040)=ANY=[@ANYBLOB="1a010c005c6b4408070a64006e40010203030902240001a82300000904000002ca744d00090503034d00ff99080805", @ANYRES16], &(0x7f0000000100)={0x0, 0x0, 0x0, 0x0, 0x1, [{0x0, 0x0}]}) syz_usb_control_io(0xffffffffffffffff, 0x0, 0x0) close(0x3) syz_open_dev$char_usb(0xc, 0xb4, 0x0) 944.268358ms ago: executing program 3 (id=1356): creat(0x0, 0xd931d3864d39ddd8) r0 = socket(0x10, 0x803, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, 0x0) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket$vsock_stream(0x28, 0x1, 0x0) connect$vsock_stream(r4, &(0x7f0000000140)={0x28, 0x0, 0x0, @my=0x1}, 0x10) pread64(0xffffffffffffffff, &(0x7f0000032140)=""/102344, 0x18fc8, 0x4000c2a) r5 = openat$tun(0xffffffffffffff9c, &(0x7f0000000340), 0x302, 0x0) ioctl$TUNSETIFF(r5, 0x400454ca, 0x0) r6 = socket(0x400000000010, 0x3, 0x0) r7 = socket$unix(0x1, 0x5, 0x0) ioctl$sock_SIOCGIFINDEX(r7, 0x8933, &(0x7f0000000100)={'syzkaller0\x00', 0x0}) sendmsg$nl_route_sched(r6, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f0000000640)=@newqdisc={0x48, 0x24, 0x4ee4e6a52ff56541, 0x70bd26, 0xffffffff, {0x0, 0x0, 0x0, r8, {0x0, 0xfff1}, {0xffff, 0xffff}, {0xffff, 0xf}}, [@qdisc_kind_options=@q_htb={{0x8}, {0x1c, 0x2, [@TCA_HTB_INIT={0x18, 0x2, {0x3, 0x4, 0x6}}]}}]}, 0x48}, 0x1, 0x0, 0x0, 0x40000}, 0x0) sendmsg$nl_route_sched(r0, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000480)=@newtfilter={0x30, 0x2c, 0xd27, 0x0, 0x0, {0x0, 0x0, 0x0, r8, {0xe, 0xfff1}, {}, {0xb, 0xb}}, [@filter_kind_options=@f_u32={{0x8}, {0x4}}]}, 0x30}, 0x1, 0x0, 0x0, 0x80}, 0x40) 340.356666ms ago: executing program 3 (id=1357): bind$inet6(0xffffffffffffffff, &(0x7f0000000040)={0xa, 0x10010000004e20}, 0x1c) r0 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000100), 0x1c3902, 0x0) sendfile(r0, r0, 0x0, 0x200000) getsockopt$IP_VS_SO_GET_SERVICE(0xffffffffffffffff, 0x0, 0x483, 0x0, 0x0) ioprio_set$pid(0x2, 0x0, 0x6000) r1 = socket(0x400000000010, 0x3, 0x0) socket$nl_crypto(0x10, 0x3, 0x15) r2 = socket$unix(0x1, 0x1, 0x0) ioctl$sock_SIOCGIFINDEX(r2, 0x8933, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, 0x0, 0x0) ioctl$sock_SIOCGIFINDEX(0xffffffffffffffff, 0x8933, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000900)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000180)=@newtfilter={0x24, 0x2c, 0xd27, 0x70bd28, 0x0, {0x0, 0x0, 0x0, 0x0, {0xf000, 0xffff}, {}, {0x7}}}, 0x24}, 0x1, 0x0, 0x0, 0x80}, 0x20000800) sendmsg$nl_route_sched(r1, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000280)=@delchain={0x2c, 0x66, 0x1, 0x70bd2c, 0x25dfdbff, {0x0, 0x0, 0x0, 0x0, {0x0, 0xfff3}, {}, {0xe, 0xd}}, [@TCA_CHAIN={0x8, 0xb, 0x3}]}, 0x2c}, 0x1, 0x0, 0x0, 0x8848}, 0x20004804) ioctl$sock_SIOCINQ(0xffffffffffffffff, 0x541b, &(0x7f0000000180)) 134.641859ms ago: executing program 3 (id=1358): socketpair$unix(0x1, 0x3, 0x0, 0x0) recvmmsg(0xffffffffffffffff, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r0 = socket(0x28, 0x800, 0x0) syz_open_procfs(0xffffffffffffffff, &(0x7f000001b1c0)='timerslack_ns\x00') sendmsg$nl_route(r0, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000100)={&(0x7f00000002c0)=ANY=[@ANYBLOB="1c0000001a0069ae00000000000000001c000000fe0000"], 0x1c}}, 0x0) socket$nl_xfrm(0x10, 0x3, 0x6) setsockopt$inet6_IPV6_RTHDR(0xffffffffffffffff, 0x29, 0x39, &(0x7f0000000080)=ANY=[@ANYRES16=r0], 0x18) r1 = syz_open_procfs(0x0, &(0x7f0000019080)='net/vlan/vlan0\x00') r2 = socket$pppl2tp(0x18, 0x1, 0x1) ioctl$SIOCSIFMTU(r2, 0x8923, &(0x7f0000000040)={'vlan0\x00', 0x40}) mmap$IORING_OFF_SQ_RING(&(0x7f00009d8000/0x2000)=nil, 0x2000, 0x200000b, 0x4010, r1, 0x0) 0s ago: executing program 3 (id=1359): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r1, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x20002000, &(0x7f0000000000/0x2000)=nil}) r2 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r2, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000040)=[@text64={0x40, 0x0}], 0x1, 0x74, 0x0, 0x0) ioctl$KVM_RUN(r2, 0xae80, 0x0) ioctl$KVM_SET_REGS(r2, 0x4090ae82, &(0x7f0000000140)={[0x10, 0x80, 0xffffffffffffffff, 0x800002, 0xfffffffffffffffd, 0x7, 0x0, 0xfffffffffffffffd, 0x0, 0x40000, 0x7, 0x7f, 0x9, 0x1000000000400001, 0xfffffffffffffffd, 0x1002], 0x1, 0x3e0602}) ioctl$KVM_SET_VCPU_EVENTS(r2, 0x4040aea0, &(0x7f0000000080)=@x86={0x0, 0xf, 0x0, 0x0, 0x3, 0x3, 0x0, 0x6, 0x1, 0x8, 0x8, 0x9, 0x0, 0x2, 0xf, 0xc9, 0x46, 0x4, 0xb, '\x00', 0x4, 0x7}) ioctl$KVM_RUN(r2, 0xae80, 0x0) kernel console output (not intermixed with test programs): ing: No such file or directory [ 205.441290][ T6505] 8021q: adding VLAN 0 to HW filter on device bond2 [ 205.472217][ T4315] usbhid 4-1:1.0: can't add hid device: -71 [ 205.478240][ T4315] usbhid: probe of 4-1:1.0 failed with error -71 [ 205.523204][ T4315] usb 4-1: USB disconnect, device number 7 [ 205.778600][ T6457] ptrace attach of "./syz-executor exec"[4918] was attempted by " Àÿ Ðÿ ð¥ Àÿ Àÿ Ðÿ àÿ ðÿ °ÿ Àÿ ÿÿÿÿ    €½@‚ » \x09$ \x1b \x09 *>t \x09 8  þÿÿÿÿÿÿÿ [ 205.806428][ T6457] udc-core: couldn't find an available UDC or it's busy [ 205.911483][ T6457] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 205.969793][ T6457] udc-core: couldn't find an available UDC or it's busy [ 205.978856][ T6457] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 206.153091][ T6518] KVM: KVM_SET_CPUID{,2} after KVM_RUN may cause guest instability [ 206.181516][ T6518] KVM: KVM_SET_CPUID{,2} will fail after KVM_RUN starting with Linux 5.16 [ 206.695958][ T6532] binder: BINDER_SET_CONTEXT_MGR already set [ 206.702193][ T6532] binder: 6526:6532 ioctl 4018620d 200000000040 returned -16 [ 206.710196][ T6532] binder: 6526:6532 unknown command 0 [ 206.715733][ T6532] binder: 6526:6532 ioctl c0306201 2000000002c0 returned -22 [ 206.724165][ T6532] netlink: 8 bytes leftover after parsing attributes in process `syz.2.464'. [ 207.890969][ T6551] binder: BINDER_SET_CONTEXT_MGR already set [ 207.897250][ T6551] binder: 6528:6551 ioctl 4018620d 200000000040 returned -16 [ 207.905866][ T6551] binder: 6528:6551 unknown command 0 [ 207.911243][ T6551] binder: 6528:6551 ioctl c0306201 2000000002c0 returned -22 [ 208.783828][ T6551] netlink: 8 bytes leftover after parsing attributes in process `syz.5.465'. [ 209.104459][ T4212] usb 8-1: USB disconnect, device number 3 [ 209.282204][ T13] usb 4-1: new high-speed USB device number 8 using dummy_hcd [ 209.300147][ T4315] usb 1-1: USB disconnect, device number 7 [ 209.534605][ T13] usb 4-1: Using ep0 maxpacket: 16 [ 209.652223][ T13] usb 4-1: config 2 has an invalid interface number: 32 but max is 0 [ 209.676677][ T13] usb 4-1: config 2 has no interface number 0 [ 209.692032][ T4212] usb 8-1: new high-speed USB device number 4 using dummy_hcd [ 209.718974][ T13] usb 4-1: config 2 interface 32 has no altsetting 0 [ 209.972367][ T13] usb 4-1: New USB device found, idVendor=1604, idProduct=8007, bcdDevice=65.11 [ 210.000780][ T13] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 210.034233][ T13] usb 4-1: Product: syz [ 210.070328][ T13] usb 4-1: Manufacturer: syz [ 210.091137][ T13] usb 4-1: SerialNumber: syz [ 210.182183][ T4212] usb 8-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 210.207506][ T4212] usb 8-1: config 0 has no interfaces? [ 210.223966][ T4212] usb 8-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 210.252047][ T4212] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 210.332995][ T4212] usb 8-1: config 0 descriptor?? [ 210.588872][ T13] usb 4-1: USB disconnect, device number 8 [ 210.944217][ T4789] udevd[4789]: error opening ATTR{/sys/devices/platform/dummy_hcd.3/usb4/4-1/4-1:2.32/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 211.920796][ T6616] netlink: 'syz.3.477': attribute type 4 has an invalid length. [ 212.108357][ T6620] xt_CT: No such helper "snmp" [ 212.824136][ T6632] binder: BINDER_SET_CONTEXT_MGR already set [ 212.830163][ T6632] binder: 6628:6632 ioctl 4018620d 200000000040 returned -16 [ 212.838265][ T6632] binder: 6628:6632 unknown command 0 [ 212.843726][ T6632] binder: 6628:6632 ioctl c0306201 2000000002c0 returned -22 [ 212.852282][ T6632] netlink: 8 bytes leftover after parsing attributes in process `syz.3.480'. [ 213.522381][ T13] usb 8-1: USB disconnect, device number 4 [ 213.904922][ T6647] binder: BINDER_SET_CONTEXT_MGR already set [ 213.910932][ T6647] binder: 6645:6647 ioctl 4018620d 200000000040 returned -16 [ 213.919060][ T6647] binder: 6645:6647 unknown command 0 [ 213.924529][ T6647] binder: 6645:6647 ioctl c0306201 2000000002c0 returned -22 [ 214.046961][ T6651] loop3: detected capacity change from 0 to 256 [ 214.154263][ T6651] FAT-fs (loop3): Directory bread(block 64) failed [ 214.177364][ T6651] FAT-fs (loop3): Directory bread(block 65) failed [ 214.200141][ T6651] FAT-fs (loop3): Directory bread(block 66) failed [ 214.235812][ T6651] FAT-fs (loop3): Directory bread(block 67) failed [ 214.256304][ T6651] FAT-fs (loop3): Directory bread(block 68) failed [ 214.292026][ T6651] FAT-fs (loop3): Directory bread(block 69) failed [ 214.312223][ T6651] FAT-fs (loop3): Directory bread(block 70) failed [ 214.348172][ T6651] FAT-fs (loop3): Directory bread(block 71) failed [ 214.366705][ T6651] FAT-fs (loop3): Directory bread(block 72) failed [ 214.389092][ T6651] FAT-fs (loop3): Directory bread(block 73) failed [ 215.152656][ T154] attempt to access beyond end of device [ 215.152656][ T154] loop3: rw=1, want=1236, limit=256 [ 216.106424][ T6670] netlink: 88 bytes leftover after parsing attributes in process `syz.5.490'. [ 216.559716][ T6676] binder: BINDER_SET_CONTEXT_MGR already set [ 216.565823][ T6676] binder: 6673:6676 ioctl 4018620d 200000000040 returned -16 [ 216.574048][ T6676] binder: 6673:6676 unknown command 0 [ 216.579442][ T6676] binder: 6673:6676 ioctl c0306201 2000000002c0 returned -22 [ 216.587733][ T6676] netlink: 8 bytes leftover after parsing attributes in process `syz.5.492'. [ 216.983523][ T6678] mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium [ 217.197814][ T6678] mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium [ 217.517942][ T6691] loop2: detected capacity change from 0 to 256 [ 217.572907][ T6691] FAT-fs (loop2): Directory bread(block 64) failed [ 217.592455][ T6691] FAT-fs (loop2): Directory bread(block 65) failed [ 217.606822][ T6691] FAT-fs (loop2): Directory bread(block 66) failed [ 217.643186][ T6691] FAT-fs (loop2): Directory bread(block 67) failed [ 217.675326][ T6694] kvm: vcpu 0: requested 1792 ns lapic timer period limited to 200000 ns [ 217.677138][ T6691] FAT-fs (loop2): Directory bread(block 68) failed [ 217.713221][ T6691] FAT-fs (loop2): Directory bread(block 69) failed [ 217.720560][ T6691] FAT-fs (loop2): Directory bread(block 70) failed [ 217.760143][ T6691] FAT-fs (loop2): Directory bread(block 71) failed [ 217.778425][ T6691] FAT-fs (loop2): Directory bread(block 72) failed [ 217.798479][ T6691] FAT-fs (loop2): Directory bread(block 73) failed [ 218.430040][ T6703] loop7: detected capacity change from 0 to 1024 [ 218.690957][ T4988] attempt to access beyond end of device [ 218.690957][ T4988] loop2: rw=1, want=1236, limit=256 [ 218.825452][ T6703] EXT4-fs (loop7): couldn't mount as ext2 due to feature incompatibilities [ 219.601866][ T6717] binder: BINDER_SET_CONTEXT_MGR already set [ 219.607990][ T6717] binder: 6711:6717 ioctl 4018620d 200000000040 returned -16 [ 219.616037][ T6717] binder: 6711:6717 unknown command 0 [ 219.621430][ T6717] binder: 6711:6717 ioctl c0306201 2000000002c0 returned -22 [ 219.653265][ T6718] binder: BINDER_SET_CONTEXT_MGR already set [ 219.659321][ T6718] binder: 6713:6718 ioctl 4018620d 200000000040 returned -16 [ 219.667975][ T6718] binder: 6713:6718 unknown command 0 [ 219.673437][ T6718] binder: 6713:6718 ioctl c0306201 2000000002c0 returned -22 [ 219.681827][ T6718] netlink: 8 bytes leftover after parsing attributes in process `syz.0.505'. [ 220.371419][ T6728] nf_conntrack: default automatic helper assignment has been turned off for security reasons and CT-based firewall rule not found. Use the iptables CT target to attach helpers instead. [ 220.690009][ T6741] netlink: 4 bytes leftover after parsing attributes in process `syz.7.512'. [ 220.794956][ T6743] loop3: detected capacity change from 0 to 256 [ 220.878737][ T6743] FAT-fs (loop3): Directory bread(block 64) failed [ 220.901044][ T6743] FAT-fs (loop3): Directory bread(block 65) failed [ 220.927561][ T6743] FAT-fs (loop3): Directory bread(block 66) failed [ 220.957813][ T6743] FAT-fs (loop3): Directory bread(block 67) failed [ 220.988399][ T6743] FAT-fs (loop3): Directory bread(block 68) failed [ 220.996894][ T6743] FAT-fs (loop3): Directory bread(block 69) failed [ 221.010490][ T6743] FAT-fs (loop3): Directory bread(block 70) failed [ 221.018347][ T6743] FAT-fs (loop3): Directory bread(block 71) failed [ 221.033476][ T6743] FAT-fs (loop3): Directory bread(block 72) failed [ 221.042015][ T6743] FAT-fs (loop3): Directory bread(block 73) failed [ 221.338971][ T6746] loop5: detected capacity change from 0 to 1024 [ 221.690674][ T6741] team0 (unregistering): Port device team_slave_0 removed [ 221.715649][ T6746] EXT4-fs (loop5): couldn't mount as ext2 due to feature incompatibilities [ 221.949475][ T6741] team0 (unregistering): Port device team_slave_1 removed [ 222.198062][ T5877] attempt to access beyond end of device [ 222.198062][ T5877] loop3: rw=1, want=1236, limit=256 [ 222.688685][ T6761] binder: BINDER_SET_CONTEXT_MGR already set [ 222.694796][ T6761] binder: 6757:6761 ioctl 4018620d 200000000040 returned -16 [ 222.702851][ T6761] binder: 6757:6761 unknown command 0 [ 222.708248][ T6761] binder: 6757:6761 ioctl c0306201 2000000002c0 returned -22 [ 223.613986][ T6771] binder: 6769:6771 unknown command 0 [ 223.619415][ T6771] binder: 6769:6771 ioctl c0306201 2000000002c0 returned -22 [ 223.628093][ T6771] netlink: 8 bytes leftover after parsing attributes in process `syz.2.521'. [ 223.712371][ T5174] usb 6-1: new full-speed USB device number 3 using dummy_hcd [ 223.751551][ T6775] netlink: 12 bytes leftover after parsing attributes in process `syz.0.523'. [ 223.813472][ T6778] netlink: 4 bytes leftover after parsing attributes in process `syz.0.523'. [ 224.072334][ T5174] usb 6-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 224.088160][ T5174] usb 6-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 224.101474][ T5174] usb 6-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 224.110701][ T5174] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 224.263214][ T6781] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 224.283688][ T6781] IPv6: ADDRCONF(NETDEV_CHANGE): dummy0: link becomes ready [ 224.359040][ T6781] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 224.382230][ T5174] usb 6-1: usb_control_msg returned -32 [ 224.388291][ T5174] usbtmc 6-1:16.0: can't read capabilities [ 224.413463][ T6781] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 224.436050][ T6781] A link change request failed with some changes committed already. Interface bridge_slave_0 may have been left with an inconsistent configuration, please check. [ 224.518794][ T26] audit: type=1326 audit(1746664814.209:40): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=6785 comm="syz.7.526" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7fba3aaf7969 code=0x0 [ 224.852252][ T4212] usb 3-1: new high-speed USB device number 7 using dummy_hcd [ 225.266134][ T4212] usb 3-1: config 27 has an invalid descriptor of length 0, skipping remainder of the config [ 225.285404][ T4212] usb 3-1: config 27 has 0 interfaces, different from the descriptor's value: 1 [ 225.324816][ T4212] usb 3-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 225.352047][ T4212] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 225.607095][ T6801] binder: BINDER_SET_CONTEXT_MGR already set [ 225.613195][ T6801] binder: 6799:6801 ioctl 4018620d 200000000040 returned -16 [ 225.621546][ T6801] binder: 6799:6801 unknown command 0 [ 225.627219][ T6801] binder: 6799:6801 ioctl c0306201 2000000002c0 returned -22 [ 225.635344][ T6801] netlink: 8 bytes leftover after parsing attributes in process `syz.3.532'. [ 225.857806][ T6809] binder: BINDER_SET_CONTEXT_MGR already set [ 225.863953][ T6809] binder: 6800:6809 ioctl 4018620d 200000000040 returned -16 [ 225.872001][ T6809] binder: 6800:6809 unknown command 0 [ 225.877397][ T6809] binder: 6800:6809 ioctl c0306201 2000000002c0 returned -22 [ 226.087203][ T6787] udc-core: couldn't find an available UDC or it's busy [ 226.109071][ T6787] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 226.128437][ T6787] udc-core: couldn't find an available UDC or it's busy [ 226.136006][ T6787] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 226.373746][ T5174] usb 4-1: new full-speed USB device number 9 using dummy_hcd [ 226.410794][ T4210] usb 6-1: USB disconnect, device number 3 [ 226.549880][ T4212] usb 3-1: USB disconnect, device number 7 [ 226.842125][ T5174] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 226.862297][ T5174] usb 4-1: config 0 has no interfaces? [ 226.870439][ T6823] binder: BINDER_SET_CONTEXT_MGR already set [ 226.876490][ T6823] binder: 6820:6823 ioctl 4018620d 200000000040 returned -16 [ 226.884561][ T6823] binder: 6820:6823 unknown command 0 [ 226.889957][ T6823] binder: 6820:6823 ioctl c0306201 2000000002c0 returned -22 [ 226.898585][ T6823] netlink: 8 bytes leftover after parsing attributes in process `syz.0.536'. [ 227.002159][ T5174] usb 4-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 227.035477][ T5174] usb 4-1: New USB device strings: Mfr=145, Product=0, SerialNumber=0 [ 227.056263][ T5174] usb 4-1: Manufacturer: syz [ 227.090651][ T5174] usb 4-1: config 0 descriptor?? [ 227.368885][ T6808] netlink: 8 bytes leftover after parsing attributes in process `syz.3.533'. [ 227.392100][ T6808] netlink: 16 bytes leftover after parsing attributes in process `syz.3.533'. [ 227.648442][ T6828] netlink: 4 bytes leftover after parsing attributes in process `syz.0.538'. [ 227.680407][ T6830] loop5: detected capacity change from 0 to 256 [ 227.815320][ T6830] FAT-fs (loop5): Directory bread(block 64) failed [ 227.831426][ T6830] FAT-fs (loop5): Directory bread(block 65) failed [ 227.839819][ T6830] FAT-fs (loop5): Directory bread(block 66) failed [ 227.848410][ T6830] FAT-fs (loop5): Directory bread(block 67) failed [ 227.856707][ T6830] FAT-fs (loop5): Directory bread(block 68) failed [ 227.863819][ T6830] FAT-fs (loop5): Directory bread(block 69) failed [ 227.870523][ T6830] FAT-fs (loop5): Directory bread(block 70) failed [ 227.877718][ T6830] FAT-fs (loop5): Directory bread(block 71) failed [ 227.885025][ T6830] FAT-fs (loop5): Directory bread(block 72) failed [ 227.891822][ T6830] FAT-fs (loop5): Directory bread(block 73) failed [ 227.983936][ T4171] usb 4-1: USB disconnect, device number 9 [ 228.122633][ T4212] usb 1-1: new high-speed USB device number 8 using dummy_hcd [ 228.422188][ T4212] usb 1-1: Using ep0 maxpacket: 8 [ 228.738640][ T5881] attempt to access beyond end of device [ 228.738640][ T5881] loop5: rw=1, want=1236, limit=256 [ 228.956479][ T4212] usb 1-1: New USB device found, idVendor=0ccd, idProduct=10a3, bcdDevice=23.a2 [ 228.986150][ T4212] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 229.019783][ T4212] usb 1-1: Product: syz [ 229.033113][ T4212] usb 1-1: Manufacturer: syz [ 229.045193][ T4212] usb 1-1: SerialNumber: syz [ 229.067375][ T4212] usb 1-1: config 0 descriptor?? [ 229.130092][ T6839] loop5: detected capacity change from 0 to 1024 [ 229.199834][ T6839] EXT4-fs (loop5): couldn't mount as ext2 due to feature incompatibilities [ 229.282106][ T5174] usb 3-1: new high-speed USB device number 8 using dummy_hcd [ 229.352155][ T4212] usb 1-1: dvb_usb_v2: found a 'Terratec H7' in warm state [ 229.792125][ T13] usb 6-1: new high-speed USB device number 4 using dummy_hcd [ 229.912852][ T5174] usb 3-1: Using ep0 maxpacket: 8 [ 229.988035][ T6827] netlink: 4 bytes leftover after parsing attributes in process `syz.0.538'. [ 230.044262][ T6855] pit: kvm: requested 5028 ns i8254 timer period limited to 200000 ns [ 230.072160][ T13] usb 6-1: Using ep0 maxpacket: 16 [ 230.160916][ T6855] set kvm_intel.dump_invalid_vmcs=1 to dump internal KVM state. [ 230.202139][ T4212] usb write operation failed. (-71) [ 230.225852][ T4212] usb 1-1: dvb_usb_v2: will pass the complete MPEG2 transport stream to the software demuxer [ 230.241486][ T4212] dvbdev: DVB: registering new adapter (Terratec H7) [ 230.252359][ T5174] usb 3-1: New USB device found, idVendor=1660, idProduct=0932, bcdDevice=80.ea [ 230.268658][ T4212] usb 1-1: media controller created [ 230.280555][ T5174] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 230.302859][ T4212] usb read operation failed. (-71) [ 230.322221][ T4212] usb write operation failed. (-71) [ 230.328553][ T5174] usb 3-1: Product: syz [ 230.339353][ T5174] usb 3-1: Manufacturer: syz [ 230.347470][ T4212] dvb_usb_az6007: probe of 1-1:0.0 failed with error -5 [ 230.355076][ T13] usb 6-1: New USB device found, idVendor=054c, idProduct=0038, bcdDevice=16.f5 [ 230.367943][ T5174] usb 3-1: SerialNumber: syz [ 230.367953][ T13] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 230.367977][ T13] usb 6-1: Product: syz [ 230.386193][ T5174] usb 3-1: config 0 descriptor?? [ 230.423474][ T4212] usb 1-1: USB disconnect, device number 8 [ 230.449349][ T5174] dvb-usb: found a 'Medion MD95700 (MDUSBTV-HYBRID)' in warm state. [ 230.466529][ T13] usb 6-1: Manufacturer: syz [ 230.467933][ T5174] usb 3-1: setting power ON [ 230.471534][ T13] usb 6-1: SerialNumber: syz [ 230.510002][ T13] usb 6-1: config 0 descriptor?? [ 230.545534][ T5174] dvb-usb: bulk message failed: -22 (2/0) [ 230.553867][ T13] visor 6-1:0.0: Sony Clie 3.5 converter detected [ 230.579053][ T5174] dvb-usb: will pass the complete MPEG2 transport stream to the software demuxer. [ 230.619506][ T5174] dvbdev: DVB: registering new adapter (Medion MD95700 (MDUSBTV-HYBRID)) [ 230.648592][ T6842] dvb-usb: bulk message failed: -22 (3/0) [ 230.656344][ T5174] usb 3-1: media controller created [ 230.670886][ T6842] usb 3-1: gpio_write failed. [ 230.689008][ T6842] dvb-usb: bulk message failed: -22 (4/0) [ 230.699376][ T5174] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 230.709044][ T6865] dvb-usb: bulk message failed: -22 (4/0) [ 230.722122][ T6865] cxusb: i2c read failed [ 230.753493][ T5174] usb 3-1: selecting invalid altsetting 6 [ 230.761192][ T5174] usb 3-1: digital interface selection failed (-22) [ 230.771295][ T5174] dvb-usb: no frontend was attached by 'Medion MD95700 (MDUSBTV-HYBRID)' [ 230.772169][ T13] usb 6-1: clie_3_5_startup: get config number failed: -71 [ 230.842529][ T5174] usb 3-1: setting power OFF [ 230.849263][ T5174] dvb-usb: bulk message failed: -22 (2/0) [ 230.860348][ T13] visor: probe of 6-1:0.0 failed with error -71 [ 230.880738][ T5174] dvb-usb: Medion MD95700 (MDUSBTV-HYBRID) successfully initialized and connected. [ 230.921342][ T5174] (NULL device *): no alternate interface [ 230.921596][ T13] usb 6-1: USB disconnect, device number 4 [ 231.119542][ T6868] binder: 6866:6868 unknown command 0 [ 231.125693][ T6868] binder: 6866:6868 ioctl c0306201 2000000002c0 returned -22 [ 231.134818][ T6868] netlink: 8 bytes leftover after parsing attributes in process `syz.0.548'. [ 231.176185][ T5174] dvb-usb: Medion MD95700 (MDUSBTV-HYBRID) successfully deinitialized and disconnected. [ 231.212435][ T5174] usb 3-1: USB disconnect, device number 8 [ 231.723069][ T6879] loop7: detected capacity change from 0 to 256 [ 231.819239][ T5174] usb 3-1: new high-speed USB device number 9 using dummy_hcd [ 231.882725][ T6879] FAT-fs (loop7): Directory bread(block 64) failed [ 231.892343][ T4211] usb 6-1: new full-speed USB device number 5 using dummy_hcd [ 231.905212][ T6879] FAT-fs (loop7): Directory bread(block 65) failed [ 231.982551][ T6879] FAT-fs (loop7): Directory bread(block 66) failed [ 232.066402][ T6879] FAT-fs (loop7): Directory bread(block 67) failed [ 232.088657][ T6879] FAT-fs (loop7): Directory bread(block 68) failed [ 232.102445][ T6879] FAT-fs (loop7): Directory bread(block 69) failed [ 232.115009][ T6879] FAT-fs (loop7): Directory bread(block 70) failed [ 232.121600][ T6879] FAT-fs (loop7): Directory bread(block 71) failed [ 232.129775][ T6879] FAT-fs (loop7): Directory bread(block 72) failed [ 232.137090][ T6879] FAT-fs (loop7): Directory bread(block 73) failed [ 232.352684][ T5174] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 232.372295][ T5174] usb 3-1: config 0 has no interfaces? [ 232.379450][ T5174] usb 3-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 232.388938][ T5174] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 232.866968][ T4211] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 232.880218][ T5174] usb 3-1: config 0 descriptor?? [ 232.885300][ T4211] usb 6-1: config 0 has no interfaces? [ 232.921374][ T1237] attempt to access beyond end of device [ 232.921374][ T1237] loop7: rw=1, want=1236, limit=256 [ 232.962249][ T4211] usb 6-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 232.989077][ T4211] usb 6-1: New USB device strings: Mfr=145, Product=0, SerialNumber=0 [ 233.000109][ T4211] usb 6-1: Manufacturer: syz [ 233.011525][ T4211] usb 6-1: config 0 descriptor?? [ 233.260984][ T6875] netlink: 8 bytes leftover after parsing attributes in process `syz.5.550'. [ 233.284278][ T6875] netlink: 16 bytes leftover after parsing attributes in process `syz.5.550'. [ 233.452915][ T13] usb 8-1: new high-speed USB device number 5 using dummy_hcd [ 234.055149][ T4211] usb 6-1: USB disconnect, device number 5 [ 234.123891][ T13] usb 8-1: config 0 has no interfaces? [ 234.317641][ T13] usb 8-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 234.368462][ T13] usb 8-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 234.422226][ T13] usb 8-1: Product: syz [ 234.426432][ T13] usb 8-1: Manufacturer: syz [ 234.447338][ T13] usb 8-1: SerialNumber: syz [ 234.470500][ T13] usb 8-1: config 0 descriptor?? [ 235.419315][ T5174] usb 3-1: USB disconnect, device number 9 [ 235.690517][ T6915] binder: 6913:6915 unknown command 0 [ 235.696087][ T6915] binder: 6913:6915 ioctl c0306201 2000000002c0 returned -22 [ 235.704589][ T6915] netlink: 8 bytes leftover after parsing attributes in process `syz.2.562'. [ 236.488577][ T6926] program syz.2.565 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 236.811041][ T4212] usb 8-1: USB disconnect, device number 5 [ 237.044614][ T6941] vivid-001: disconnect [ 237.055217][ T6935] vivid-001: reconnect [ 237.236799][ T6945] loop3: detected capacity change from 0 to 512 [ 237.546626][ T6960] binder: 6946:6960 ioctl 4018620d 0 returned -22 [ 237.565254][ T6960] binder: 6946:6960 unknown command 0 [ 237.570761][ T6960] binder: 6946:6960 ioctl c0306201 2000000002c0 returned -22 [ 237.583261][ T6960] netlink: 8 bytes leftover after parsing attributes in process `syz.2.574'. [ 237.762053][ T5174] usb 6-1: new high-speed USB device number 6 using dummy_hcd [ 238.012289][ T5174] usb 6-1: device descriptor read/64, error -71 [ 238.332271][ T5174] usb 6-1: new high-speed USB device number 7 using dummy_hcd [ 238.363809][ T6945] EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 238.386958][ T6945] ext4 filesystem being mounted at /140/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 238.408627][ T26] audit: type=1800 audit(1746664828.099:41): pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.572" name="file2" dev="loop3" ino=16 res=0 errno=0 [ 238.532131][ T5174] usb 6-1: device descriptor read/64, error -71 [ 238.663316][ T5174] usb usb6-port1: attempt power cycle [ 238.866975][ T6973] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 239.072082][ T5174] usb 6-1: new high-speed USB device number 8 using dummy_hcd [ 239.162189][ T5174] usb 6-1: device descriptor read/8, error -71 [ 239.432078][ T5174] usb 6-1: new high-speed USB device number 9 using dummy_hcd [ 239.522420][ T5174] usb 6-1: device descriptor read/8, error -71 [ 239.652340][ T5174] usb usb6-port1: unable to enumerate USB device [ 240.331351][ T6997] binder: 6995:6997 unknown command 0 [ 240.336909][ T6997] binder: 6995:6997 ioctl c0306201 2000000002c0 returned -22 [ 240.928823][ T7005] binder: 7000:7005 ioctl 4018620d 0 returned -22 [ 240.949440][ T7005] binder: 7000:7005 unknown command 0 [ 240.955065][ T7005] binder: 7000:7005 ioctl c0306201 2000000002c0 returned -22 [ 240.967563][ T7005] netlink: 8 bytes leftover after parsing attributes in process `syz.5.587'. [ 242.091422][ T7024] device syz_tun left promiscuous mode [ 242.292180][ T4211] usb 6-1: new high-speed USB device number 10 using dummy_hcd [ 242.822020][ T7024] bridge0: port 3(syz_tun) entered disabled state [ 242.844239][ T7024] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 242.875120][ T7030] netlink: set zone limit has 8 unknown bytes [ 242.890403][ T7024] batman_adv: batadv0: Interface deactivated: dummy0 [ 242.918397][ T7024] batman_adv: batadv0: Removing interface: dummy0 [ 242.939281][ T7024] IPv6: ADDRCONF(NETDEV_CHANGE): dummy0: link becomes ready [ 242.983815][ T7024] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 243.002815][ T7024] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 243.013096][ T7024] device bridge_slave_0 left promiscuous mode [ 243.020588][ T7024] bridge0: port 1(bridge_slave_0) entered disabled state [ 243.045376][ T7024] device bridge_slave_1 left promiscuous mode [ 243.053059][ T7024] bridge0: port 2(bridge_slave_1) entered disabled state [ 243.083456][ T4211] usb 6-1: Using ep0 maxpacket: 16 [ 243.133256][ T7024] bond0: (slave bond_slave_0): Releasing backup interface [ 243.222428][ T7024] bond0: (slave bond_slave_1): Releasing backup interface [ 243.232291][ T4211] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x84 has invalid wMaxPacketSize 0 [ 243.317031][ T7024] team0: Port device team_slave_0 removed [ 243.442615][ T7024] team0: Port device team_slave_1 removed [ 243.453254][ T7024] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 243.462618][ T4211] usb 6-1: New USB device found, idVendor=2040, idProduct=0264, bcdDevice=4e.d1 [ 243.475781][ T4211] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 243.498115][ T7024] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 243.512108][ T4211] usb 6-1: Product: syz [ 243.518405][ T4211] usb 6-1: Manufacturer: syz [ 243.542327][ T4211] usb 6-1: SerialNumber: syz [ 243.562522][ T4211] usb 6-1: config 0 descriptor?? [ 243.594143][ T7024] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 243.608566][ T7024] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 243.634465][ T4211] em28xx 6-1:0.0: New device syz syz @ 480 Mbps (2040:0264, interface 0, class 0) [ 243.684684][ T4211] em28xx 6-1:0.0: DVB interface 0 found: bulk [ 244.142261][ T4210] usb 4-1: new full-speed USB device number 10 using dummy_hcd [ 244.282174][ T4211] em28xx 6-1:0.0: unknown em28xx chip ID (0) [ 244.392111][ T5174] usb 8-1: new full-speed USB device number 6 using dummy_hcd [ 244.522184][ T4210] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 244.569054][ T4210] usb 4-1: config 0 has no interfaces? [ 244.604050][ T7049] binder: 7047:7049 unknown command 0 [ 244.609455][ T7049] binder: 7047:7049 ioctl c0306201 2000000002c0 returned -22 [ 244.662250][ T4210] usb 4-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 244.672122][ T4210] usb 4-1: New USB device strings: Mfr=145, Product=0, SerialNumber=0 [ 244.682293][ T4210] usb 4-1: Manufacturer: syz [ 244.706927][ T4210] usb 4-1: config 0 descriptor?? [ 244.812780][ T4211] em28xx 6-1:0.0: reading from i2c device at 0xa0 failed (error=-5) [ 244.826035][ T4211] em28xx 6-1:0.0: board has no eeprom [ 244.882209][ T5174] usb 8-1: config 0 has no interfaces? [ 244.957630][ T7039] netlink: 8 bytes leftover after parsing attributes in process `syz.3.596'. [ 244.972537][ T7039] netlink: 16 bytes leftover after parsing attributes in process `syz.3.596'. [ 245.052179][ T5174] usb 8-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 245.062292][ T5174] usb 8-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 245.087247][ T5174] usb 8-1: Product: syz [ 245.091973][ T5174] usb 8-1: Manufacturer: syz [ 245.112095][ T5174] usb 8-1: SerialNumber: syz [ 245.132498][ T5174] usb 8-1: config 0 descriptor?? [ 245.572485][ T7056] binder: BINDER_SET_CONTEXT_MGR already set [ 245.578650][ T7056] binder: 7051:7056 ioctl 4018620d 200000000040 returned -16 [ 245.591826][ T7056] netlink: 8 bytes leftover after parsing attributes in process `syz.0.600'. [ 246.364768][ T5174] usb 4-1: USB disconnect, device number 10 [ 246.372941][ T7020] em28xx 6-1:0.0: failed to get i2c transfer status from bridge register (error=-5) [ 246.462181][ T4211] em28xx 6-1:0.0: Identified as PCTV tripleStick (292e) (card=94) [ 246.478559][ T4211] em28xx 6-1:0.0: dvb set to bulk mode. [ 246.534009][ T4211] usb 6-1: USB disconnect, device number 10 [ 246.580147][ T4211] em28xx 6-1:0.0: Disconnecting em28xx [ 246.596681][ T5174] em28xx 6-1:0.0: Binding DVB extension [ 246.680724][ T5174] em28xx 6-1:0.0: Registering input extension [ 246.696966][ T4211] em28xx 6-1:0.0: Closing input extension [ 246.787256][ T4211] em28xx 6-1:0.0: Freeing device [ 247.452177][ T4211] usb 6-1: new full-speed USB device number 11 using dummy_hcd [ 247.647512][ T13] usb 8-1: USB disconnect, device number 6 [ 247.832086][ T4211] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x6 has invalid maxpacket 1023, setting to 64 [ 247.847788][ T4211] usb 6-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 248.091127][ T7078] IPv6: ADDRCONF(NETDEV_CHANGE): syz_tun: link becomes ready [ 248.127031][ T7078] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 248.208784][ T7078] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 248.262990][ T7078] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 248.292175][ T7078] device bridge_slave_0 left promiscuous mode [ 248.303378][ T7078] bridge0: port 1(bridge_slave_0) entered disabled state [ 248.334317][ T7078] device bridge_slave_1 left promiscuous mode [ 248.351346][ T7078] bridge0: port 2(bridge_slave_1) entered disabled state [ 248.379808][ T7078] bond0: (slave bond_slave_0): Releasing backup interface [ 248.408933][ T4211] usb 6-1: New USB device found, idVendor=2294, idProduct=425b, bcdDevice=a2.10 [ 248.448122][ T7078] bond0: (slave bond_slave_1): Releasing backup interface [ 248.461693][ T7089] binder: BINDER_SET_CONTEXT_MGR already set [ 248.467828][ T7089] binder: 7085:7089 ioctl 4018620d 200000000040 returned -16 [ 248.476008][ T7089] binder: 7085:7089 unknown command 0 [ 248.481411][ T7089] binder: 7085:7089 ioctl c0306201 2000000002c0 returned -22 [ 248.530766][ T7078] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 248.548484][ T7078] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 248.564955][ T7078] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 248.583810][ T7078] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 248.597690][ T4211] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 248.605959][ T4211] usb 6-1: Product: syz [ 248.610285][ T4211] usb 6-1: Manufacturer: syz [ 248.616141][ T4211] usb 6-1: SerialNumber: syz [ 248.632241][ T4211] usb 6-1: config 0 descriptor?? [ 248.650520][ T7078] bond1: (slave vlan2): Releasing backup interface [ 248.652757][ T7073] raw-gadget.0 gadget: fail, usb_ep_enable returned -22 [ 248.736790][ T7094] binder: BINDER_SET_CONTEXT_MGR already set [ 248.743037][ T7094] binder: 7087:7094 ioctl 4018620d 200000000040 returned -16 [ 248.771293][ T4211] usb 6-1: ucan: probing device on interface #0 [ 248.946159][ T4211] usb 6-1: ucan: invalid EP count (1) [ 248.958284][ T4211] usb 6-1: ucan: probe failed; try to update the device firmware [ 249.228010][ T7094] netlink: 8 bytes leftover after parsing attributes in process `syz.0.612'. [ 249.483085][ T7111] netlink: 4 bytes leftover after parsing attributes in process `syz.2.618'. [ 249.525451][ T7116] loop8: detected capacity change from 0 to 7 [ 249.586897][ T7116] Dev loop8: unable to read RDB block 7 [ 249.618019][ T7116] loop8: unable to read partition table [ 249.645583][ T7116] loop8: partition table beyond EOD, truncated [ 249.696251][ T7116] loop_reread_partitions: partition scan of loop8 (þ被xüŸÑø éÚ¬§½dƤ´à–ƒÝ¡¯¨â·û [ 249.696251][ T7116] ) failed (rc=-5) [ 250.323613][ T7131] netlink: 'syz.2.624': attribute type 1 has an invalid length. [ 250.379720][ T7131] 8021q: adding VLAN 0 to HW filter on device bond3 [ 250.681360][ T7141] binder: BINDER_SET_CONTEXT_MGR already set [ 250.687698][ T7141] binder: 7133:7141 ioctl 4018620d 200000000040 returned -16 [ 250.699367][ T7141] binder: 7133:7141 unknown command 0 [ 250.704971][ T7141] binder: 7133:7141 ioctl c0306201 2000000002c0 returned -22 [ 251.514273][ T4212] usb 6-1: USB disconnect, device number 11 [ 251.817687][ T7148] binder: BINDER_SET_CONTEXT_MGR already set [ 251.823940][ T7148] binder: 7145:7148 ioctl 4018620d 200000000040 returned -16 [ 251.837240][ T7148] netlink: 8 bytes leftover after parsing attributes in process `syz.2.627'. [ 254.105443][ T7167] binder: 7163:7167 unknown command 0 [ 254.110874][ T7167] binder: 7163:7167 ioctl c0306201 2000000002c0 returned -22 [ 254.119372][ T7167] netlink: 8 bytes leftover after parsing attributes in process `syz.2.634'. [ 254.227960][ T7169] device syzkaller1 entered promiscuous mode [ 254.497198][ T7172] netlink: 'syz.3.638': attribute type 1 has an invalid length. [ 255.287221][ T7178] binder: BINDER_SET_CONTEXT_MGR already set [ 255.293283][ T7178] binder: 7170:7178 ioctl 4018620d 200000000040 returned -16 [ 255.301450][ T7178] binder: 7170:7178 unknown command 0 [ 255.306889][ T7178] binder: 7170:7178 ioctl c0306201 2000000002c0 returned -22 [ 255.715390][ T1422] ieee802154 phy0 wpan0: encryption failed: -22 [ 255.722046][ T1422] ieee802154 phy1 wpan1: encryption failed: -22 [ 255.866640][ T7172] 8021q: adding VLAN 0 to HW filter on device bond1 [ 255.925917][ T7186] loop7: detected capacity change from 0 to 1024 [ 255.949285][ T7172] bond1: (slave vlan0): Enslaving as an active interface with an up link [ 255.964088][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): bond1: link becomes ready [ 255.976337][ T7186] EXT4-fs (loop7): couldn't mount as ext2 due to feature incompatibilities [ 256.612321][ T4211] usb 1-1: new high-speed USB device number 9 using dummy_hcd [ 257.073289][ T7200] loop7: detected capacity change from 0 to 512 [ 257.202925][ T4211] usb 1-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0xFF, skipping [ 257.323463][ T4211] usb 1-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 257.384422][ T4211] usb 1-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 257.408394][ T4211] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 257.434260][ T7200] EXT4-fs (loop7): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 257.436270][ T4211] usb 1-1: config 0 descriptor?? [ 257.492944][ T7200] ext4 filesystem being mounted at /89/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 257.538617][ T4211] usbhid 1-1:0.0: couldn't find an input interrupt endpoint [ 257.647261][ T26] audit: type=1800 audit(1746664847.339:42): pid=7202 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.7.647" name="file2" dev="loop7" ino=16 res=0 errno=0 [ 257.922763][ T7217] loop2: detected capacity change from 0 to 256 [ 258.181485][ T7217] FAT-fs (loop2): Directory bread(block 64) failed [ 258.199090][ T7217] FAT-fs (loop2): Directory bread(block 65) failed [ 258.239578][ T7217] FAT-fs (loop2): Directory bread(block 66) failed [ 258.249461][ T7217] FAT-fs (loop2): Directory bread(block 67) failed [ 258.267992][ T7217] FAT-fs (loop2): Directory bread(block 68) failed [ 258.294852][ T7217] FAT-fs (loop2): Directory bread(block 69) failed [ 258.301634][ T7217] FAT-fs (loop2): Directory bread(block 70) failed [ 258.339877][ T7217] FAT-fs (loop2): Directory bread(block 71) failed [ 258.360120][ T7217] FAT-fs (loop2): Directory bread(block 72) failed [ 258.371772][ T7217] FAT-fs (loop2): Directory bread(block 73) failed [ 258.452062][ T7228] loop7: detected capacity change from 0 to 1024 [ 258.648961][ T7228] EXT4-fs (loop7): couldn't mount as ext2 due to feature incompatibilities [ 259.126396][ T4554] attempt to access beyond end of device [ 259.126396][ T4554] loop2: rw=1, want=1236, limit=256 [ 259.447816][ T4212] usb 4-1: new high-speed USB device number 11 using dummy_hcd [ 259.655770][ T13] usb 1-1: USB disconnect, device number 9 [ 259.692032][ T4212] usb 4-1: Using ep0 maxpacket: 32 [ 259.857021][ T4212] usb 4-1: unable to get BOS descriptor or descriptor too short [ 259.962090][ T4212] usb 4-1: config 7 has an invalid descriptor of length 0, skipping remainder of the config [ 259.993015][ T4212] usb 4-1: config 7 has 0 interfaces, different from the descriptor's value: 1 [ 260.006992][ T7255] netlink: 199836 bytes leftover after parsing attributes in process `syz.0.662'. [ 260.054058][ T7256] netlink: 'syz.0.662': attribute type 10 has an invalid length. [ 260.502446][ T4212] usb 4-1: New USB device found, idVendor=18d1, idProduct=1eaf, bcdDevice=5a.bb [ 260.548001][ T4212] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 260.680569][ T4212] usb 4-1: Product: syz [ 260.707075][ T4212] usb 4-1: Manufacturer: syz [ 260.717450][ T4212] usb 4-1: SerialNumber: syz [ 260.781221][ T7256] wlan1: mtu greater than device maximum [ 261.272515][ T7265] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 261.619416][ T7271] loop5: detected capacity change from 0 to 256 [ 261.802091][ T7271] FAT-fs (loop5): Directory bread(block 64) failed [ 261.812515][ T7271] FAT-fs (loop5): Directory bread(block 65) failed [ 261.820857][ T7271] FAT-fs (loop5): Directory bread(block 66) failed [ 261.836734][ T7271] FAT-fs (loop5): Directory bread(block 67) failed [ 261.845994][ T7271] FAT-fs (loop5): Directory bread(block 68) failed [ 261.853347][ T7271] FAT-fs (loop5): Directory bread(block 69) failed [ 261.860275][ T7271] FAT-fs (loop5): Directory bread(block 70) failed [ 261.867667][ T7271] FAT-fs (loop5): Directory bread(block 71) failed [ 261.879011][ T7277] netlink: 8 bytes leftover after parsing attributes in process `syz.2.667'. [ 261.889684][ T7271] FAT-fs (loop5): Directory bread(block 72) failed [ 261.897838][ T7271] FAT-fs (loop5): Directory bread(block 73) failed [ 263.334831][ T154] attempt to access beyond end of device [ 263.334831][ T154] loop5: rw=1, want=1236, limit=256 [ 263.908782][ T23] usb 4-1: USB disconnect, device number 11 [ 265.836807][ T7314] loop3: detected capacity change from 0 to 512 [ 266.009788][ T7314] EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 266.098530][ T7314] ext4 filesystem being mounted at /165/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 266.225260][ T26] audit: type=1800 audit(1746664855.919:43): pid=7314 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.678" name="file2" dev="loop3" ino=16 res=0 errno=0 [ 266.362094][ T4212] usb 1-1: new high-speed USB device number 10 using dummy_hcd [ 266.993710][ T4212] usb 1-1: Using ep0 maxpacket: 8 [ 267.112429][ T4212] usb 1-1: config 0 has an invalid interface number: 31 but max is 0 [ 267.128910][ T4212] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 267.208112][ T4212] usb 1-1: config 0 has no interface number 0 [ 267.281384][ T7328] netlink: 16 bytes leftover after parsing attributes in process `syz.3.682'. [ 267.392218][ T4212] usb 1-1: New USB device found, idVendor=046d, idProduct=08c3, bcdDevice=6b.16 [ 267.402149][ T4212] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 267.411590][ T4212] usb 1-1: Product: syz [ 267.416181][ T13] usb 6-1: new high-speed USB device number 12 using dummy_hcd [ 267.445555][ T4212] usb 1-1: Manufacturer: syz [ 267.470608][ T4212] usb 1-1: SerialNumber: syz [ 267.511992][ T4212] usb 1-1: config 0 descriptor?? [ 267.670140][ T4212] usb 1-1: Found UVC 0.04 device syz (046d:08c3) [ 267.702072][ T4212] usb 1-1: No valid video chain found. [ 268.772214][ T13] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 268.790560][ T7320] ODEBUG: Out of memory. ODEBUG disabled [ 268.816791][ T13] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 268.845442][ T13] usb 6-1: New USB device found, idVendor=0926, idProduct=3333, bcdDevice= 0.40 [ 268.869498][ T13] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 268.913636][ T13] usb 6-1: config 0 descriptor?? [ 269.589353][ T23] usb 1-1: USB disconnect, device number 10 [ 269.992199][ T13] usbhid 6-1:0.0: can't add hid device: -71 [ 270.002210][ T13] usbhid: probe of 6-1:0.0 failed with error -71 [ 270.038661][ T13] usb 6-1: USB disconnect, device number 12 [ 270.087673][ T7359] loop7: detected capacity change from 0 to 512 [ 270.226927][ T7359] EXT4-fs (loop7): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 270.248713][ T7359] ext4 filesystem being mounted at /96/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 270.277900][ T26] audit: type=1800 audit(1746664859.969:44): pid=7359 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.7.692" name="file2" dev="loop7" ino=16 res=0 errno=0 [ 270.532282][ T23] usb 3-1: new high-speed USB device number 10 using dummy_hcd [ 270.801964][ T23] usb 3-1: Using ep0 maxpacket: 8 [ 270.922271][ T23] usb 3-1: config 150 has an invalid interface number: 204 but max is 0 [ 270.936326][ T23] usb 3-1: config 150 has no interface number 0 [ 270.949929][ T23] usb 3-1: config 150 interface 204 has no altsetting 0 [ 271.242370][ T7378] netlink: 28 bytes leftover after parsing attributes in process `syz.7.696'. [ 271.276273][ T23] usb 3-1: New USB device found, idVendor=04e2, idProduct=1424, bcdDevice=c7.eb [ 271.449482][ T23] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 271.643220][ T23] usb 3-1: Product: syz [ 271.770326][ T23] usb 3-1: Manufacturer: syz [ 272.001458][ T23] usb 3-1: SerialNumber: syz [ 272.783383][ T23] usb 3-1: USB disconnect, device number 10 [ 272.984775][ T7400] loop3: detected capacity change from 0 to 512 [ 273.111486][ T7400] EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 273.125985][ T7400] ext4 filesystem being mounted at /171/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 273.149999][ T26] audit: type=1800 audit(1746664862.839:45): pid=7400 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.706" name="file2" dev="loop3" ino=16 res=0 errno=0 [ 274.676483][ T13] hid-generic 0000:0000:0000.0005: unknown main item tag 0x0 [ 274.744901][ T13] hid-generic 0000:0000:0000.0005: hidraw0: HID v0.00 Device [syz1] on syz0 [ 274.985250][ T7434] binder: BINDER_SET_CONTEXT_MGR already set [ 274.991326][ T7434] binder: 7425:7434 ioctl 4018620d 200000000040 returned -16 [ 275.002318][ T7434] binder: 7425:7434 unknown command 0 [ 275.007849][ T7434] binder: 7425:7434 ioctl c0306201 2000000002c0 returned -22 [ 275.020369][ T7434] netlink: 8 bytes leftover after parsing attributes in process `syz.2.714'. [ 277.215566][ T7455] binder: BINDER_SET_CONTEXT_MGR already set [ 277.221692][ T7455] binder: 7447:7455 ioctl 4018620d 200000000040 returned -16 [ 277.230251][ T7455] netlink: 8 bytes leftover after parsing attributes in process `syz.7.720'. [ 278.365705][ T7462] bond1: (slave vlan0): Releasing backup interface [ 278.480608][ T7467] loop5: detected capacity change from 0 to 512 [ 278.525929][ T13] usb 8-1: new high-speed USB device number 7 using dummy_hcd [ 278.974681][ T7475] binder: 7463:7475 ioctl 4018620d 0 returned -22 [ 278.983443][ T7475] binder: 7463:7475 unknown command 0 [ 278.988859][ T7475] binder: 7463:7475 ioctl c0306201 2000000002c0 returned -22 [ 280.322100][ T7480] binder: BINDER_SET_CONTEXT_MGR already set [ 280.328136][ T7480] binder: 7470:7480 ioctl 4018620d 200000000040 returned -16 [ 280.432074][ T7480] binder: 7470:7480 unknown command 0 [ 280.437492][ T7480] binder: 7470:7480 ioctl c0306201 2000000002c0 returned -22 [ 280.742104][ T7480] netlink: 8 bytes leftover after parsing attributes in process `syz.3.728'. [ 280.935468][ T7467] EXT4-fs (loop5): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 280.992147][ T7467] ext4 filesystem being mounted at /122/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 281.068978][ T26] audit: type=1800 audit(1746664870.759:46): pid=7467 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.5.726" name="file2" dev="loop5" ino=16 res=0 errno=0 [ 281.197536][ T13] usb 8-1: Using ep0 maxpacket: 8 [ 282.252113][ T13] usb 8-1: device descriptor read/all, error -71 [ 282.439342][ T7504] netlink: 'syz.3.736': attribute type 10 has an invalid length. [ 284.239782][ T7530] binder: 7518:7530 ioctl 4018620d 0 returned -22 [ 284.259458][ T7530] binder: 7518:7530 unknown command 0 [ 284.265135][ T7530] binder: 7518:7530 ioctl c0306201 2000000002c0 returned -22 [ 287.054022][ T7547] binder: BINDER_SET_CONTEXT_MGR already set [ 287.060232][ T7547] binder: 7543:7547 ioctl 4018620d 200000000040 returned -16 [ 287.238440][ T23] usb 3-1: new high-speed USB device number 11 using dummy_hcd [ 287.474423][ T7547] netlink: 8 bytes leftover after parsing attributes in process `syz.7.751'. [ 287.523655][ T26] audit: type=1800 audit(1746664877.209:47): pid=7545 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.3.747" name="/" dev="fuse" ino=0 res=0 errno=0 [ 288.022269][ T23] usb 3-1: config 0 has an invalid interface number: 109 but max is 0 [ 288.296117][ T23] usb 3-1: config 0 has no interface number 0 [ 288.379560][ T23] usb 3-1: New USB device found, idVendor=0db0, idProduct=6899, bcdDevice=5b.fe [ 288.580731][ T7557] loop3: detected capacity change from 0 to 512 [ 288.593331][ T23] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 288.644785][ T7557] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 288.647888][ T23] usb 3-1: config 0 descriptor?? [ 288.734400][ T7557] EXT4-fs warning (device loop3): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 290.561157][ T4315] usb 3-1: USB disconnect, device number 11 [ 291.123016][ T7592] binder: BINDER_SET_CONTEXT_MGR already set [ 291.129089][ T7592] binder: 7580:7592 ioctl 4018620d 200000000040 returned -16 [ 291.948475][ T7594] binder: 7590:7594 ioctl 4018620d 0 returned -22 [ 291.956835][ T7594] binder: 7590:7594 unknown command 0 [ 291.962926][ T7594] binder: 7590:7594 ioctl c0306201 2000000002c0 returned -22 [ 291.971072][ T7594] netlink: 8 bytes leftover after parsing attributes in process `syz.0.764'. [ 293.332065][ T7596] binder: 7588:7596 unknown command 0 [ 293.337492][ T7596] binder: 7588:7596 ioctl c0306201 2000000002c0 returned -22 [ 293.642099][ T7596] netlink: 8 bytes leftover after parsing attributes in process `syz.3.763'. [ 295.136089][ T7611] loop3: detected capacity change from 0 to 512 [ 295.190540][ T7611] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 295.240228][ T7611] EXT4-fs warning (device loop3): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 296.123770][ T7624] IPVS: Error connecting to the multicast addr [ 296.370579][ T26] audit: type=1326 audit(1746664886.059:48): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 296.407588][ T26] audit: type=1326 audit(1746664886.059:49): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=257 compat=0 ip=0x7fbaa7af82d0 code=0x7ffc0000 [ 296.512999][ T26] audit: type=1326 audit(1746664886.059:50): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 296.746543][ T26] audit: type=1326 audit(1746664886.059:51): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=186 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 296.823972][ T7644] binder: 7637:7644 unknown command 0 [ 296.829429][ T7644] binder: 7637:7644 ioctl c0306201 2000000002c0 returned -22 [ 296.837934][ T7644] netlink: 8 bytes leftover after parsing attributes in process `syz.5.778'. [ 296.882466][ T26] audit: type=1326 audit(1746664886.059:52): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 296.930719][ T26] audit: type=1326 audit(1746664886.059:53): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=222 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 297.700385][ T26] audit: type=1326 audit(1746664886.059:54): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 297.722592][ C0] vkms_vblank_simulate: vblank timer overrun [ 297.812946][ T26] audit: type=1326 audit(1746664886.059:55): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=223 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 297.853306][ T7653] netlink: 100 bytes leftover after parsing attributes in process `syz.7.781'. [ 297.863156][ T26] audit: type=1326 audit(1746664886.059:56): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7fbaa7af0927 code=0x7ffc0000 [ 297.886905][ T26] audit: type=1326 audit(1746664886.059:57): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7626 comm="syz.3.774" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fbaa7a95b39 code=0x7ffc0000 [ 298.181005][ T7655] loop7: detected capacity change from 0 to 256 [ 298.382355][ T7660] loop3: detected capacity change from 0 to 512 [ 298.454686][ T7655] FAT-fs (loop7): Directory bread(block 64) failed [ 298.462212][ T7655] FAT-fs (loop7): Directory bread(block 65) failed [ 298.471561][ T7655] FAT-fs (loop7): Directory bread(block 66) failed [ 298.520041][ T7660] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 298.574416][ T7655] FAT-fs (loop7): Directory bread(block 67) failed [ 298.581402][ T7655] FAT-fs (loop7): Directory bread(block 68) failed [ 298.633356][ T7660] EXT4-fs warning (device loop3): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 298.662214][ T4212] Bluetooth: hci1: command 0x0406 tx timeout [ 298.730359][ T7655] FAT-fs (loop7): Directory bread(block 69) failed [ 298.772019][ T7655] FAT-fs (loop7): Directory bread(block 70) failed [ 298.778608][ T7655] FAT-fs (loop7): Directory bread(block 71) failed [ 298.785829][ T7655] FAT-fs (loop7): Directory bread(block 72) failed [ 298.810586][ T7655] FAT-fs (loop7): Directory bread(block 73) failed [ 299.892792][ T5875] attempt to access beyond end of device [ 299.892792][ T5875] loop7: rw=1, want=1236, limit=256 [ 300.247207][ T7690] delete_channel: no stack [ 301.564460][ T7708] loop3: detected capacity change from 0 to 512 [ 301.709979][ T7708] EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 302.057292][ T7708] ext4 filesystem being mounted at /191/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 302.421400][ T7719] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 302.428980][ T7719] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 302.698839][ T26] kauditd_printk_skb: 59 callbacks suppressed [ 302.698855][ T26] audit: type=1800 audit(1746664892.389:117): pid=7708 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.798" name="file2" dev="loop3" ino=16 res=0 errno=0 [ 303.875937][ T7731] binder: BINDER_SET_CONTEXT_MGR already set [ 303.882070][ T7731] binder: 7728:7731 ioctl 4018620d 200000000040 returned -16 [ 306.334807][ T7758] loop3: detected capacity change from 0 to 512 [ 306.379594][ T26] audit: type=1326 audit(1746664896.069:118): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=7763 comm="syz.5.817" exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f65669ea969 code=0x0 [ 306.486698][ T7758] EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 306.514512][ T7758] ext4 filesystem being mounted at /193/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 306.546190][ T26] audit: type=1800 audit(1746664896.239:119): pid=7758 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.814" name="file2" dev="loop3" ino=16 res=0 errno=0 [ 307.662251][ T13] usb 6-1: new high-speed USB device number 13 using dummy_hcd [ 308.054087][ T13] usb 6-1: config 0 has no interfaces? [ 308.222550][ T13] usb 6-1: New USB device found, idVendor=045e, idProduct=0283, bcdDevice=99.0b [ 308.377721][ T13] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 308.402617][ T7788] input: syz1 as /devices/virtual/input/input27 [ 308.412107][ T13] usb 6-1: Product: syz [ 308.416402][ T13] usb 6-1: Manufacturer: syz [ 308.421029][ T13] usb 6-1: SerialNumber: syz [ 308.497623][ T13] usb 6-1: config 0 descriptor?? [ 309.281954][ T13] usb 8-1: new high-speed USB device number 9 using dummy_hcd [ 309.522034][ T13] usb 8-1: Using ep0 maxpacket: 8 [ 309.678656][ T7817] binder: BINDER_SET_CONTEXT_MGR already set [ 309.684809][ T7817] binder: 7813:7817 ioctl 4018620d 200000000040 returned -16 [ 309.696702][ T7817] netlink: 8 bytes leftover after parsing attributes in process `syz.3.831'. [ 310.421970][ T13] usb 8-1: config 0 has no interfaces? [ 310.427845][ T13] usb 8-1: New USB device found, idVendor=12ab, idProduct=90a3, bcdDevice=1e.eb [ 310.439047][ T13] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 310.459266][ T13] usb 8-1: config 0 descriptor?? [ 310.465326][ T4212] usb 6-1: USB disconnect, device number 13 [ 310.711358][ T4212] usb 8-1: USB disconnect, device number 9 [ 312.177277][ T7841] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 312.225558][ T7841] A link change request failed with some changes committed already. Interface hsr_slave_0 may have been left with an inconsistent configuration, please check. [ 313.206769][ T7856] binder: BINDER_SET_CONTEXT_MGR already set [ 313.213118][ T7856] binder: 7848:7856 ioctl 4018620d 200000000040 returned -16 [ 313.225471][ T7856] netlink: 8 bytes leftover after parsing attributes in process `syz.2.842'. [ 313.989310][ T7863] binder: 7857:7863 ioctl 4018620d 0 returned -22 [ 314.008009][ T7863] binder: 7857:7863 unknown command 0 [ 314.013542][ T7863] binder: 7857:7863 ioctl c0306201 2000000002c0 returned -22 [ 314.026858][ T7863] netlink: 8 bytes leftover after parsing attributes in process `syz.3.845'. [ 315.582689][ T4315] usb 1-1: new high-speed USB device number 11 using dummy_hcd [ 315.982206][ T4315] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 316.021940][ T4315] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 316.062388][ T4315] usb 1-1: New USB device found, idVendor=27b8, idProduct=01ed, bcdDevice= 0.00 [ 316.091991][ T4315] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 316.112680][ T4315] usb 1-1: config 0 descriptor?? [ 316.641994][ T4210] usb 3-1: new high-speed USB device number 12 using dummy_hcd [ 316.682584][ T4315] usbhid 1-1:0.0: can't add hid device: -71 [ 316.692170][ T4315] usbhid: probe of 1-1:0.0 failed with error -71 [ 316.759767][ T4315] usb 1-1: USB disconnect, device number 11 [ 317.012114][ T4210] usb 3-1: config 0 has no interfaces? [ 317.064744][ T1422] ieee802154 phy0 wpan0: encryption failed: -22 [ 317.071239][ T1422] ieee802154 phy1 wpan1: encryption failed: -22 [ 317.232132][ T4210] usb 3-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 317.245244][ T4210] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 317.254174][ T4210] usb 3-1: Product: syz [ 317.258415][ T4210] usb 3-1: Manufacturer: syz [ 317.263540][ T4210] usb 3-1: SerialNumber: syz [ 317.301320][ T4210] usb 3-1: config 0 descriptor?? [ 317.651083][ T7906] binder: BINDER_SET_CONTEXT_MGR already set [ 317.657477][ T7906] binder: 7901:7906 ioctl 4018620d 200000000040 returned -16 [ 317.666478][ T7906] netlink: 8 bytes leftover after parsing attributes in process `syz.7.858'. [ 318.822065][ T7908] binder: 7904:7908 ioctl 4018620d 0 returned -22 [ 319.522704][ T7908] binder: 7904:7908 unknown command 0 [ 319.528275][ T7908] binder: 7904:7908 ioctl c0306201 2000000002c0 returned -22 [ 319.832091][ T7908] netlink: 8 bytes leftover after parsing attributes in process `syz.3.859'. [ 322.965006][ T7953] binder: 7947:7953 ioctl 4018620d 0 returned -22 [ 322.982990][ T7953] binder: 7947:7953 unknown command 0 [ 322.988843][ T7953] binder: 7947:7953 ioctl c0306201 2000000002c0 returned -22 [ 323.330108][ T7953] netlink: 8 bytes leftover after parsing attributes in process `syz.5.872'. [ 323.424713][ T7955] nf_conntrack: default automatic helper assignment has been turned off for security reasons and CT-based firewall rule not found. Use the iptables CT target to attach helpers instead. [ 323.708574][ T4212] usb 3-1: USB disconnect, device number 12 [ 323.722057][ T4315] usb 6-1: new high-speed USB device number 14 using dummy_hcd [ 324.012219][ T4315] usb 6-1: Using ep0 maxpacket: 32 [ 324.528003][ T4315] usb 6-1: config 0 interface 0 has no altsetting 0 [ 324.535663][ T4315] usb 6-1: New USB device found, idVendor=1e71, idProduct=2011, bcdDevice= 0.00 [ 324.566594][ T4315] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 324.608808][ T4315] usb 6-1: config 0 descriptor?? [ 325.282925][ T7957] udc-core: couldn't find an available UDC or it's busy [ 325.289923][ T7957] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 325.330046][ T7957] netlink: 'syz.5.874': attribute type 1 has an invalid length. [ 325.376418][ T7957] program syz.5.874 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 325.484944][ T4315] hid-generic 0003:1E71:2011.0006: collection stack underflow [ 325.503735][ T4315] hid-generic 0003:1E71:2011.0006: item 0 0 0 12 parsing failed [ 325.514930][ T4315] hid-generic: probe of 0003:1E71:2011.0006 failed with error -22 [ 325.737336][ T7989] netlink: 'syz.2.884': attribute type 10 has an invalid length. [ 325.805658][ T7990] netlink: 'syz.2.884': attribute type 72 has an invalid length. [ 325.845966][ T7990] netlink: 52 bytes leftover after parsing attributes in process `syz.2.884'. [ 326.058921][ T7995] netlink: 'syz.3.886': attribute type 1 has an invalid length. [ 326.153552][ T7995] 8021q: adding VLAN 0 to HW filter on device bond2 [ 326.162963][ T7988] mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium [ 326.179996][ T7998] bond2: (slave vlan0): Enslaving as an active interface with an up link [ 326.221770][ T4554] IPv6: ADDRCONF(NETDEV_CHANGE): bond2: link becomes ready [ 326.919863][ T23] usb 6-1: USB disconnect, device number 14 [ 327.362056][ T4210] usb 1-1: new full-speed USB device number 12 using dummy_hcd [ 327.485856][ T8031] bond2: (slave vlan0): Releasing backup interface [ 327.762051][ T4210] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 327.792987][ T4210] usb 1-1: config 0 has no interfaces? [ 327.872180][ T4210] usb 1-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 327.903955][ T4210] usb 1-1: New USB device strings: Mfr=145, Product=0, SerialNumber=0 [ 327.964027][ T4210] usb 1-1: Manufacturer: syz [ 327.997447][ T4210] usb 1-1: config 0 descriptor?? [ 328.163484][ T8042] loop3: detected capacity change from 0 to 512 [ 328.267941][ T8042] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 328.280833][ T8024] netlink: 8 bytes leftover after parsing attributes in process `syz.0.895'. [ 328.295794][ T8024] netlink: 16 bytes leftover after parsing attributes in process `syz.0.895'. [ 328.305379][ T8042] EXT4-fs warning (device loop3): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 328.337236][ T4210] usb 1-1: USB disconnect, device number 12 [ 328.540445][ T4554] netdevsim netdevsim2 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 328.708141][ T4554] netdevsim netdevsim2 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 329.428288][ T4554] netdevsim netdevsim2 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 329.709280][ T8051] loop5: detected capacity change from 0 to 1024 [ 329.837714][ T4554] netdevsim netdevsim2 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 329.893185][ T8051] EXT4-fs (loop5): couldn't mount as ext2 due to feature incompatibilities [ 330.508079][ T8067] chnl_net:caif_netlink_parms(): no params data found [ 330.552058][ T13] usb 6-1: new high-speed USB device number 15 using dummy_hcd [ 330.662965][ T8096] loop3: detected capacity change from 0 to 512 [ 330.687998][ T8094] device bridge0 entered promiscuous mode [ 330.702950][ T8094] device bridge0 left promiscuous mode [ 330.747886][ T8096] EXT4-fs (loop3): encrypted files will use data=ordered instead of data journaling mode [ 330.780828][ T8096] EXT4-fs warning (device loop3): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 330.912195][ T13] usb 6-1: config 1 interface 0 altsetting 0 endpoint 0x1 has invalid wMaxPacketSize 0 [ 330.960311][ T13] usb 6-1: config 1 interface 0 altsetting 0 bulk endpoint 0x1 has invalid maxpacket 0 [ 330.981588][ T13] usb 6-1: config 1 interface 0 altsetting 0 bulk endpoint 0x82 has invalid maxpacket 72 [ 331.026089][ T8096] set kvm_intel.dump_invalid_vmcs=1 to dump internal KVM state. [ 331.039831][ T8067] bridge0: port 1(bridge_slave_0) entered blocking state [ 331.049899][ T8067] bridge0: port 1(bridge_slave_0) entered disabled state [ 331.058750][ T8067] device bridge_slave_0 entered promiscuous mode [ 331.068184][ T8067] bridge0: port 2(bridge_slave_1) entered blocking state [ 331.076950][ T8067] bridge0: port 2(bridge_slave_1) entered disabled state [ 331.085882][ T8067] device bridge_slave_1 entered promiscuous mode [ 331.162318][ T13] usb 6-1: New USB device found, idVendor=0525, idProduct=a4a8, bcdDevice= 0.40 [ 331.180430][ T8067] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 331.201545][ T13] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 331.211327][ T8067] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 331.246692][ T13] usb 6-1: Product: syz [ 331.250910][ T13] usb 6-1: Manufacturer: syz [ 331.256110][ T13] usb 6-1: SerialNumber: syz [ 331.291048][ T8077] raw-gadget.0 gadget: fail, usb_ep_enable returned -22 [ 331.298162][ T4315] usb 8-1: new full-speed USB device number 10 using dummy_hcd [ 331.509137][ T8067] team0: Port device team_slave_0 added [ 331.553226][ T13] usblp 6-1:1.0: usblp0: USB Bidirectional printer dev 15 if 0 alt 0 proto 3 vid 0x0525 pid 0xA4A8 [ 331.651291][ T13] usb 6-1: USB disconnect, device number 15 [ 331.672618][ T4315] usb 8-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 331.705016][ T4315] usb 8-1: config 0 has no interfaces? [ 331.723525][ T13] usblp0: removed [ 331.782520][ T4315] usb 8-1: New USB device found, idVendor=046d, idProduct=c31c, bcdDevice= 0.40 [ 331.784021][ T8067] team0: Port device team_slave_1 added [ 331.812112][ T4315] usb 8-1: New USB device strings: Mfr=145, Product=0, SerialNumber=0 [ 331.820449][ T4315] usb 8-1: Manufacturer: syz [ 331.867015][ T4315] usb 8-1: config 0 descriptor?? [ 331.928816][ T8067] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 331.937922][ T8067] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 331.986901][ T8067] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 332.021469][ T13] Bluetooth: hci3: command 0x0409 tx timeout [ 332.044497][ T8067] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 332.051597][ T8067] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 332.072656][ T8126] loop3: detected capacity change from 0 to 512 [ 332.115750][ T8108] netlink: 8 bytes leftover after parsing attributes in process `syz.7.915'. [ 332.129097][ T8108] netlink: 16 bytes leftover after parsing attributes in process `syz.7.915'. [ 332.157734][ T4315] usb 8-1: USB disconnect, device number 10 [ 332.170771][ T8067] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 332.198909][ T8126] EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 332.239201][ T8131] loop5: detected capacity change from 0 to 256 [ 332.278771][ T8126] ext4 filesystem being mounted at /225/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 332.375992][ T8131] FAT-fs (loop5): Directory bread(block 64) failed [ 332.404512][ T26] audit: type=1800 audit(1746664922.099:120): pid=8126 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.3.919" name="file2" dev="loop3" ino=16 res=0 errno=0 [ 332.432108][ T8131] FAT-fs (loop5): Directory bread(block 65) failed [ 332.439303][ T8131] FAT-fs (loop5): Directory bread(block 66) failed [ 332.507472][ T8131] FAT-fs (loop5): Directory bread(block 67) failed [ 332.568524][ T8131] FAT-fs (loop5): Directory bread(block 68) failed [ 332.575940][ T4554] device hsr_slave_0 left promiscuous mode [ 332.580683][ T8131] FAT-fs (loop5): Directory bread(block 69) failed [ 332.592099][ T4554] device hsr_slave_1 left promiscuous mode [ 332.613039][ T8131] FAT-fs (loop5): Directory bread(block 70) failed [ 332.661416][ T8131] FAT-fs (loop5): Directory bread(block 71) failed [ 332.748866][ T8131] FAT-fs (loop5): Directory bread(block 72) failed [ 332.789290][ T4554] device veth1_macvtap left promiscuous mode [ 332.821066][ T8131] FAT-fs (loop5): Directory bread(block 73) failed [ 332.832365][ T4554] device veth0_macvtap left promiscuous mode [ 332.840862][ T4554] device veth1_vlan left promiscuous mode [ 332.872632][ T4554] device veth0_vlan left promiscuous mode [ 333.177083][ T8144] loop7: detected capacity change from 0 to 1024 [ 333.228752][ T4554] bond3 (unregistering): Released all slaves [ 333.309520][ T4554] bond2 (unregistering): Released all slaves [ 333.322053][ T8144] EXT4-fs (loop7): couldn't mount as ext2 due to feature incompatibilities [ 333.473187][ T4554] bond1 (unregistering): Released all slaves [ 333.788074][ T4688] attempt to access beyond end of device [ 333.788074][ T4688] loop5: rw=1, want=1236, limit=256 [ 334.092123][ T4315] Bluetooth: hci3: command 0x041b tx timeout [ 334.099135][ T4554] bond0 (unregistering): Released all slaves [ 334.120967][ T8067] device hsr_slave_0 entered promiscuous mode [ 334.129063][ T8067] device hsr_slave_1 entered promiscuous mode [ 334.183620][ T8157] device syzkaller1 entered promiscuous mode [ 334.516516][ T8174] Cannot find add_set index 2 as target [ 335.803175][ T8067] netdevsim netdevsim2 netdevsim0: renamed from eth0 [ 335.832874][ T8067] netdevsim netdevsim2 netdevsim1: renamed from eth1 [ 335.851610][ T8067] netdevsim netdevsim2 netdevsim2: renamed from eth2 [ 335.903654][ T8067] netdevsim netdevsim2 netdevsim3: renamed from eth3 [ 336.172147][ T4212] Bluetooth: hci3: command 0x040f tx timeout [ 336.173919][ T8067] 8021q: adding VLAN 0 to HW filter on device bond0 [ 336.246138][ T4688] IPv6: ADDRCONF(NETDEV_CHANGE): veth1: link becomes ready [ 336.279804][ T4688] IPv6: ADDRCONF(NETDEV_CHANGE): veth0: link becomes ready [ 336.329778][ T8067] 8021q: adding VLAN 0 to HW filter on device team0 [ 336.389240][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_to_bridge: link becomes ready [ 336.425297][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): bridge_slave_0: link becomes ready [ 336.450190][ T5881] bridge0: port 1(bridge_slave_0) entered blocking state [ 336.457378][ T5881] bridge0: port 1(bridge_slave_0) entered forwarding state [ 336.523529][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): bridge0: link becomes ready [ 336.552472][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_bridge: link becomes ready [ 336.592341][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): bridge_slave_1: link becomes ready [ 336.621644][ T5881] bridge0: port 2(bridge_slave_1) entered blocking state [ 336.628989][ T5881] bridge0: port 2(bridge_slave_1) entered forwarding state [ 336.677442][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_to_bond: link becomes ready [ 336.703645][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_bond: link becomes ready [ 336.757788][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_to_team: link becomes ready [ 336.810417][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): team_slave_0: link becomes ready [ 336.862907][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_team: link becomes ready [ 336.882675][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): team_slave_1: link becomes ready [ 336.912757][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_to_hsr: link becomes ready [ 336.942851][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): hsr_slave_0: link becomes ready [ 336.971656][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): team0: link becomes ready [ 337.012416][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_hsr: link becomes ready [ 337.062430][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): hsr_slave_1: link becomes ready [ 337.104370][ T8067] IPv6: ADDRCONF(NETDEV_CHANGE): hsr0: link becomes ready [ 337.479832][ T154] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 337.498321][ T154] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 337.550818][ T8067] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 337.731396][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_virt_wifi: link becomes ready [ 337.746533][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_virt_wifi: link becomes ready [ 337.840777][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_vlan: link becomes ready [ 337.852946][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_vlan: link becomes ready [ 337.879967][ T8067] device veth0_vlan entered promiscuous mode [ 337.891809][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): vlan0: link becomes ready [ 337.920372][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): vlan1: link becomes ready [ 337.968711][ T8067] device veth1_vlan entered promiscuous mode [ 338.084906][ T5877] IPv6: ADDRCONF(NETDEV_CHANGE): macvlan0: link becomes ready [ 338.103133][ T5877] IPv6: ADDRCONF(NETDEV_CHANGE): macvlan1: link becomes ready [ 338.162698][ T5877] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_macvtap: link becomes ready [ 338.218258][ T5877] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_macvtap: link becomes ready [ 338.242146][ T8067] device veth0_macvtap entered promiscuous mode [ 338.258059][ T4315] Bluetooth: hci3: command 0x0419 tx timeout [ 338.296806][ T8067] device veth1_macvtap entered promiscuous mode [ 338.382340][ T8067] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 338.389785][ T4688] IPv6: ADDRCONF(NETDEV_CHANGE): macvtap0: link becomes ready [ 338.452832][ T4688] IPv6: ADDRCONF(NETDEV_CHANGE): macsec0: link becomes ready [ 338.491415][ T4688] IPv6: ADDRCONF(NETDEV_CHANGE): batadv_slave_0: link becomes ready [ 338.656993][ T4688] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_to_batadv: link becomes ready [ 338.727164][ T8067] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 338.812540][ T8251] binder: BINDER_SET_CONTEXT_MGR already set [ 338.818956][ T8251] binder: 8241:8251 ioctl 4018620d 200000000040 returned -16 [ 338.829821][ T8251] binder: 8241:8251 unknown command 0 [ 338.835455][ T8251] binder: 8241:8251 ioctl c0306201 2000000002c0 returned -22 [ 339.194507][ T5875] IPv6: ADDRCONF(NETDEV_CHANGE): batadv_slave_1: link becomes ready [ 339.209815][ T5875] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_batadv: link becomes ready [ 339.358159][ T8251] netlink: 8 bytes leftover after parsing attributes in process `syz.3.936'. [ 340.541682][ T8247] device syzkaller1 entered promiscuous mode [ 341.134391][ T8067] netdevsim netdevsim2 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 341.176831][ T8067] netdevsim netdevsim2 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 341.312060][ T8067] netdevsim netdevsim2 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 341.358686][ T8067] netdevsim netdevsim2 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 341.815287][ T154] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 341.864698][ T154] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 342.261620][ T154] IPv6: ADDRCONF(NETDEV_CHANGE): wlan0: link becomes ready [ 342.514845][ T154] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 342.692727][ T154] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 342.800453][ T8288] binder: BINDER_SET_CONTEXT_MGR already set [ 342.806585][ T8288] binder: 8282:8288 ioctl 4018620d 200000000040 returned -16 [ 342.824854][ T8288] netlink: 8 bytes leftover after parsing attributes in process `syz.7.942'. [ 342.962883][ T154] IPv6: ADDRCONF(NETDEV_CHANGE): wlan1: link becomes ready [ 344.569390][ T8307] device syzkaller1 entered promiscuous mode [ 345.304024][ T8343] device syzkaller1 entered promiscuous mode [ 345.951960][ T4212] usb 4-1: new high-speed USB device number 12 using dummy_hcd [ 346.222144][ T4212] usb 4-1: Using ep0 maxpacket: 8 [ 346.531422][ T8369] binder: BINDER_SET_CONTEXT_MGR already set [ 346.538044][ T8369] binder: 8362:8369 ioctl 4018620d 200000000040 returned -16 [ 346.550153][ T8369] netlink: 8 bytes leftover after parsing attributes in process `syz.5.954'. [ 346.612169][ T4212] usb 4-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 346.739037][ T4212] usb 4-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 0 [ 346.953916][ T4212] usb 4-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 347.343051][ T4212] usb 4-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 347.357511][ T4212] usb 4-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 347.367604][ T4212] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 347.491409][ T8380] binder: BINDER_SET_CONTEXT_MGR already set [ 347.497804][ T8380] binder: 8370:8380 ioctl 4018620d 200000000040 returned -16 [ 347.508291][ T8380] binder: 8370:8380 unknown command 0 [ 347.513799][ T8380] binder: 8370:8380 ioctl c0306201 2000000002c0 returned -22 [ 347.526418][ T8380] netlink: 8 bytes leftover after parsing attributes in process `syz.7.957'. [ 347.732326][ T4212] usb 4-1: GET_CAPABILITIES returned 0 [ 347.756223][ T4212] usbtmc 4-1:16.0: can't read capabilities [ 348.223003][ T4212] usb 4-1: USB disconnect, device number 12 [ 348.423798][ T8389] loop7: detected capacity change from 0 to 1024 [ 348.522545][ T8389] EXT4-fs (loop7): couldn't mount as ext2 due to feature incompatibilities [ 349.005152][ T4212] usb 3-1: new high-speed USB device number 13 using dummy_hcd [ 349.187087][ T8405] netdevsim netdevsim5 eth0: unset [0, 0] type 1 family 0 port 8472 - 0 [ 349.195707][ T8405] netdevsim netdevsim5 eth1: unset [0, 0] type 1 family 0 port 8472 - 0 [ 349.204541][ T8405] netdevsim netdevsim5 eth2: unset [0, 0] type 1 family 0 port 8472 - 0 [ 349.213213][ T8405] netdevsim netdevsim5 eth3: unset [0, 0] type 1 family 0 port 8472 - 0 [ 349.254921][ T8405] team0: Port device vxlan0 removed [ 349.423401][ T4212] usb 3-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 349.447442][ T4212] usb 3-1: config 27 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 349.477469][ T4212] usb 3-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 349.503123][ T4212] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 350.427677][ T8410] binder: BINDER_SET_CONTEXT_MGR already set [ 350.433778][ T8410] binder: 8406:8410 ioctl 4018620d 200000000040 returned -16 [ 350.442462][ T8410] netlink: 8 bytes leftover after parsing attributes in process `syz.5.970'. [ 350.715210][ T4212] usb 3-1: invalid MIDI out EP 0 [ 350.734848][ T8394] fuse: Unknown parameter '0x000000000000000a' [ 350.977128][ T4212] snd-usb-audio: probe of 3-1:27.0 failed with error -22 [ 350.999822][ T4306] udevd[4306]: error opening ATTR{/sys/devices/platform/dummy_hcd.2/usb3/3-1/3-1:27.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 351.166973][ T4210] usb 3-1: USB disconnect, device number 13 [ 351.312013][ T13] usb 6-1: new full-speed USB device number 16 using dummy_hcd [ 351.762022][ T13] usb 6-1: config 0 interface 0 altsetting 0 endpoint 0x6 has invalid maxpacket 1023, setting to 64 [ 351.798072][ T13] usb 6-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 351.839733][ T8445] netlink: 132 bytes leftover after parsing attributes in process `syz.7.977'. [ 352.032212][ T13] usb 6-1: New USB device found, idVendor=2294, idProduct=425b, bcdDevice=a2.10 [ 352.049625][ T13] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 352.077623][ T13] usb 6-1: Product: syz [ 352.094577][ T13] usb 6-1: Manufacturer: syz [ 352.141280][ T13] usb 6-1: SerialNumber: syz [ 352.157392][ T8454] netlink: 28 bytes leftover after parsing attributes in process `syz.7.979'. [ 352.175254][ T13] usb 6-1: config 0 descriptor?? [ 352.202230][ T8416] raw-gadget.1 gadget: fail, usb_ep_enable returned -22 [ 352.221481][ T8454] netlink: 28 bytes leftover after parsing attributes in process `syz.7.979'. [ 352.223138][ T8461] syz.2.980 sent an empty control message without MSG_MORE. [ 352.231951][ T13] usb 6-1: ucan: probing device on interface #0 [ 352.252269][ T8454] netlink: 52 bytes leftover after parsing attributes in process `syz.7.979'. [ 352.272620][ T13] usb 6-1: ucan: invalid EP count (1) [ 352.289556][ T13] usb 6-1: ucan: probe failed; try to update the device firmware [ 352.778347][ T8470] binder: BINDER_SET_CONTEXT_MGR already set [ 352.784781][ T8470] binder: 8465:8470 ioctl 4018620d 200000000040 returned -16 [ 352.793104][ T8470] binder: 8465:8470 unknown command 0 [ 352.798510][ T8470] binder: 8465:8470 ioctl c0306201 2000000002c0 returned -22 [ 352.807012][ T8470] netlink: 8 bytes leftover after parsing attributes in process `syz.7.981'. [ 353.890937][ T8479] netlink: 8 bytes leftover after parsing attributes in process `syz.7.982'. [ 355.109566][ T8489] binder: 8485:8489 unknown command 0 [ 355.115235][ T8489] binder: 8485:8489 ioctl c0306201 2000000002c0 returned -22 [ 355.123771][ T8489] netlink: 8 bytes leftover after parsing attributes in process `syz.7.987'. [ 355.962008][ T13] usb 4-1: new high-speed USB device number 13 using dummy_hcd [ 356.022508][ T4210] usb 6-1: USB disconnect, device number 16 [ 356.044818][ T8495] netlink: 12 bytes leftover after parsing attributes in process `syz.0.989'. [ 356.086480][ T8495] netdevsim netdevsim0 netdevsim0: set [0, 0] type 1 family 0 port 8472 - 0 [ 356.095875][ T8495] netdevsim netdevsim0 netdevsim1: set [0, 0] type 1 family 0 port 8472 - 0 [ 356.104661][ T8495] netdevsim netdevsim0 netdevsim2: set [0, 0] type 1 family 0 port 8472 - 0 [ 356.113468][ T8495] netdevsim netdevsim0 netdevsim3: set [0, 0] type 1 family 0 port 8472 - 0 [ 356.196117][ T8495] netdevsim netdevsim0 netdevsim0: unset [0, 0] type 1 family 0 port 8472 - 0 [ 356.205337][ T8495] netdevsim netdevsim0 netdevsim1: unset [0, 0] type 1 family 0 port 8472 - 0 [ 356.214403][ T8495] netdevsim netdevsim0 netdevsim2: unset [0, 0] type 1 family 0 port 8472 - 0 [ 356.224006][ T8495] netdevsim netdevsim0 netdevsim3: unset [0, 0] type 1 family 0 port 8472 - 0 [ 356.261952][ T13] usb 4-1: Using ep0 maxpacket: 8 [ 356.706822][ T8505] binder: BINDER_SET_CONTEXT_MGR already set [ 356.713167][ T8505] binder: 8500:8505 ioctl 4018620d 200000000040 returned -16 [ 356.721461][ T8505] binder: 8500:8505 unknown command 0 [ 356.727041][ T8505] binder: 8500:8505 ioctl c0306201 2000000002c0 returned -22 [ 356.735721][ T8505] netlink: 8 bytes leftover after parsing attributes in process `syz.2.992'. [ 357.431991][ T13] usb 4-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 357.443170][ T13] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 2 [ 357.461157][ T13] usb 4-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 100, changing to 10 [ 357.489380][ T13] usb 4-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 24936, setting to 1024 [ 357.511034][ T13] usb 4-1: New USB device found, idVendor=0225, idProduct=0000, bcdDevice= 0.00 [ 357.522046][ T13] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 357.733081][ T13] hub 4-1:1.0: bad descriptor, ignoring hub [ 357.740020][ T13] hub: probe of 4-1:1.0 failed with error -5 [ 357.746887][ T13] cdc_wdm 4-1:1.0: skipping garbage [ 357.752490][ T13] cdc_wdm 4-1:1.0: skipping garbage [ 357.786715][ T13] cdc_wdm 4-1:1.0: cdc-wdm0: USB WDM device [ 357.792994][ T13] cdc_wdm 4-1:1.0: Unknown control protocol [ 357.821484][ T8519] netlink: 8 bytes leftover after parsing attributes in process `syz.7.995'. [ 358.042079][ T4315] usb 6-1: new high-speed USB device number 17 using dummy_hcd [ 358.411451][ T4315] usb 6-1: Using ep0 maxpacket: 8 [ 358.442010][ T13] usb 4-1: USB disconnect, device number 13 [ 358.532332][ T4315] usb 6-1: config 0 has an invalid interface number: 143 but max is 0 [ 358.540583][ T4315] usb 6-1: config 0 has no interface number 0 [ 358.731796][ T4315] usb 6-1: New USB device found, idVendor=2058, idProduct=1005, bcdDevice=c1.9b [ 358.741426][ T4315] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 358.752905][ T4315] usb 6-1: config 0 descriptor?? [ 358.770595][ T8525] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 358.781937][ T8525] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 358.789609][ T8525] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 358.800897][ T8525] A link change request failed with some changes committed already. Interface bridge_slave_0 may have been left with an inconsistent configuration, please check. [ 358.921922][ T8529] binder: 8520:8529 unknown command 0 [ 358.927399][ T8529] binder: 8520:8529 ioctl c0306201 2000000002c0 returned -22 [ 358.939632][ T8529] netlink: 8 bytes leftover after parsing attributes in process `syz.3.998'. [ 358.992866][ T4315] viperboard 6-1:0.143: version 0.00 found at bus 006 address 017 [ 359.112334][ T4171] usb 8-1: new full-speed USB device number 11 using dummy_hcd [ 359.440853][ T4315] viperboard-i2c viperboard-i2c.2.auto: failure setting i2c_bus_freq to 100 [ 359.477442][ T4315] viperboard-i2c: probe of viperboard-i2c.2.auto failed with error -5 [ 359.508763][ T8533] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 359.548447][ T4315] usb 6-1: USB disconnect, device number 17 [ 359.582095][ T4171] usb 8-1: config 0 interface 0 altsetting 0 endpoint 0x6 has invalid maxpacket 1023, setting to 64 [ 359.622808][ T8533] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 359.632283][ T4171] usb 8-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 359.842326][ T4171] usb 8-1: New USB device found, idVendor=2294, idProduct=425b, bcdDevice=a2.10 [ 359.871050][ T4171] usb 8-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 359.896055][ T4171] usb 8-1: Product: syz [ 359.911742][ T4171] usb 8-1: Manufacturer: syz [ 359.918144][ T4171] usb 8-1: SerialNumber: syz [ 359.930317][ T4171] usb 8-1: config 0 descriptor?? [ 359.983075][ T8528] raw-gadget.0 gadget: fail, usb_ep_enable returned -22 [ 360.115106][ T4171] usb 8-1: ucan: probing device on interface #0 [ 360.121532][ T4171] usb 8-1: ucan: invalid EP count (1) [ 360.127229][ T4171] usb 8-1: ucan: probe failed; try to update the device firmware [ 360.250743][ T8549] binder: BINDER_SET_CONTEXT_MGR already set [ 360.256866][ T8549] binder: 8543:8549 ioctl 4018620d 200000000040 returned -16 [ 360.267711][ T8549] binder: 8543:8549 unknown command 0 [ 360.273267][ T8549] binder: 8543:8549 ioctl c0306201 2000000002c0 returned -22 [ 360.286643][ T8549] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1005'. [ 361.617652][ T4171] usb 1-1: new high-speed USB device number 13 using dummy_hcd [ 361.872940][ T8565] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1009'. [ 362.562909][ T5174] usb 8-1: USB disconnect, device number 11 [ 362.950766][ T8578] binder: 8572:8578 unknown command 0 [ 362.956433][ T8578] binder: 8572:8578 ioctl c0306201 2000000002c0 returned -22 [ 362.967970][ T8578] netlink: 8 bytes leftover after parsing attributes in process `syz.7.1012'. [ 362.980723][ T4171] usb 1-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 363.050855][ T4171] usb 1-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 363.051486][ T4171] usb 1-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 363.192400][ T4171] usb 1-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 363.192483][ T4171] usb 1-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 363.192559][ T4171] usb 1-1: Product: syz [ 363.192618][ T4171] usb 1-1: Manufacturer: syz [ 364.037961][ T8585] binder: 8584:8585 ioctl c0306201 200000000480 returned -14 [ 364.140788][ T8586] binder: BINDER_SET_CONTEXT_MGR already set [ 364.147100][ T8586] binder: 8581:8586 ioctl 4018620d 200000000040 returned -16 [ 364.158120][ T8586] binder: 8581:8586 unknown command 0 [ 364.163682][ T8586] binder: 8581:8586 ioctl c0306201 2000000002c0 returned -22 [ 364.176830][ T8586] netlink: 8 bytes leftover after parsing attributes in process `syz.7.1016'. [ 364.856938][ T13] usb 1-1: USB disconnect, device number 13 [ 366.217519][ T8610] binder: 8603:8610 ioctl 4018620d 0 returned -22 [ 366.227598][ T8610] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1023'. [ 366.239963][ T13] usb 1-1: new full-speed USB device number 14 using dummy_hcd [ 367.063020][ T13] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x6 has invalid maxpacket 1023, setting to 64 [ 367.127644][ T13] usb 1-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 367.392170][ T13] usb 1-1: New USB device found, idVendor=2294, idProduct=425b, bcdDevice=a2.10 [ 367.431188][ T13] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 367.456311][ T13] usb 1-1: Product: syz [ 367.472175][ T13] usb 1-1: Manufacturer: syz [ 367.483679][ T13] usb 1-1: SerialNumber: syz [ 367.500514][ T13] usb 1-1: config 0 descriptor?? [ 367.522632][ T8596] raw-gadget.0 gadget: fail, usb_ep_enable returned -22 [ 367.542763][ T13] usb 1-1: ucan: probing device on interface #0 [ 367.566700][ T13] usb 1-1: ucan: invalid EP count (1) [ 367.588409][ T13] usb 1-1: ucan: probe failed; try to update the device firmware [ 367.922022][ T23] usb 4-1: new high-speed USB device number 14 using dummy_hcd [ 369.255456][ T23] usb 4-1: config 0 has no interfaces? [ 369.388064][ T8653] binder: BINDER_SET_CONTEXT_MGR already set [ 369.394242][ T8653] binder: 8647:8653 ioctl 4018620d 200000000040 returned -16 [ 369.405229][ T8653] binder: 8647:8653 unknown command 0 [ 369.410712][ T8653] binder: 8647:8653 ioctl c0306201 2000000002c0 returned -22 [ 369.423334][ T8653] netlink: 8 bytes leftover after parsing attributes in process `syz.7.1030'. [ 370.252017][ T23] usb 4-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 370.267120][ T4674] usb 1-1: USB disconnect, device number 14 [ 370.541951][ T23] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 370.550080][ T23] usb 4-1: Product: syz [ 371.461956][ T23] usb 4-1: Manufacturer: syz [ 371.472581][ T23] usb 4-1: SerialNumber: syz [ 371.512776][ T23] usb 4-1: config 0 descriptor?? [ 371.732010][ T4674] usb 1-1: new high-speed USB device number 15 using dummy_hcd [ 371.942575][ T8650] ALSA: mixer_oss: invalid OSS volume '' [ 372.092501][ T4674] usb 1-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 372.147417][ T4674] usb 1-1: config 27 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 372.188710][ T4674] usb 1-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 372.229193][ T4674] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 372.294333][ T4674] usb 1-1: invalid MIDI out EP 0 [ 372.368353][ T4674] snd-usb-audio: probe of 1-1:27.0 failed with error -22 [ 372.429419][ T4158] udevd[4158]: error opening ATTR{/sys/devices/platform/dummy_hcd.0/usb1/1-1/1-1:27.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 372.497565][ T8670] fuse: Unknown parameter '0x000000000000000a' [ 372.547634][ T4674] usb 1-1: USB disconnect, device number 15 [ 372.762019][ T23] usb 4-1: can't set config #0, error -71 [ 372.779754][ T23] usb 4-1: USB disconnect, device number 14 [ 373.209831][ T8719] netlink: 20 bytes leftover after parsing attributes in process `syz.5.1042'. [ 373.232211][ T8719] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1042'. [ 373.398190][ T8724] tipc: Started in network mode [ 374.173119][ T8724] tipc: Node identity ac1414aa, cluster identity 4711 [ 374.214452][ T8724] tipc: Enabled bearer , priority 10 [ 375.486624][ T4674] tipc: Node number set to 2886997162 [ 376.029615][ T8768] netlink: 'syz.3.1050': attribute type 1 has an invalid length. [ 376.409201][ T8777] mmap: syz.7.1048 (8777) uses deprecated remap_file_pages() syscall. See Documentation/vm/remap_file_pages.rst. [ 378.564242][ T1422] ieee802154 phy0 wpan0: encryption failed: -22 [ 378.573517][ T1422] ieee802154 phy1 wpan1: encryption failed: -22 [ 379.275329][ T8812] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1058'. [ 381.363643][ T8851] loop2: detected capacity change from 0 to 512 [ 381.408223][ T8851] EXT4-fs (loop2): encrypted files will use data=ordered instead of data journaling mode [ 381.435620][ T8855] program syz.3.1069 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 381.465191][ T8851] EXT4-fs warning (device loop2): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 385.422200][ T8907] netlink: 12 bytes leftover after parsing attributes in process `syz.0.1085'. [ 385.467959][ T8907] device vlan2 entered promiscuous mode [ 385.486631][ T8907] device team0 entered promiscuous mode [ 386.041938][ T4211] usb 1-1: new high-speed USB device number 16 using dummy_hcd [ 386.302648][ T4211] usb 1-1: Using ep0 maxpacket: 32 [ 386.422974][ T4211] usb 1-1: config 0 interface 0 has no altsetting 0 [ 386.429694][ T4211] usb 1-1: New USB device found, idVendor=1e71, idProduct=2011, bcdDevice= 0.00 [ 386.484697][ T4211] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 386.531126][ T4211] usb 1-1: config 0 descriptor?? [ 386.578636][ T8930] netlink: 4 bytes leftover after parsing attributes in process `syz.7.1092'. [ 386.952136][ T4674] usb 8-1: new full-speed USB device number 12 using dummy_hcd [ 387.214019][ T8916] udc-core: couldn't find an available UDC or it's busy [ 387.221149][ T8916] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 387.243544][ T8916] netlink: 'syz.0.1088': attribute type 1 has an invalid length. [ 387.282700][ T8916] program syz.0.1088 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 387.392542][ T4674] usb 8-1: config 0 interface 0 altsetting 0 endpoint 0x6 has invalid maxpacket 1023, setting to 64 [ 387.413763][ T4674] usb 8-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 387.471987][ T4315] usb 3-1: new high-speed USB device number 14 using dummy_hcd [ 387.582095][ T4674] usb 8-1: New USB device found, idVendor=2294, idProduct=425b, bcdDevice=a2.10 [ 387.599520][ T4674] usb 8-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 387.608482][ T4674] usb 8-1: Product: syz [ 387.617672][ T4674] usb 8-1: Manufacturer: syz [ 387.626692][ T4674] usb 8-1: SerialNumber: syz [ 387.638333][ T4674] usb 8-1: config 0 descriptor?? [ 387.662210][ T8933] raw-gadget.1 gadget: fail, usb_ep_enable returned -22 [ 387.683043][ T4674] usb 8-1: ucan: probing device on interface #0 [ 387.698135][ T4674] usb 8-1: ucan: invalid EP count (1) [ 387.705138][ T4674] usb 8-1: ucan: probe failed; try to update the device firmware [ 387.842200][ T4315] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 387.861254][ T4315] usb 3-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 387.877765][ T4315] usb 3-1: config 0 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 21 [ 387.933713][ T4315] usb 3-1: New USB device found, idVendor=047f, idProduct=ffff, bcdDevice= 0.00 [ 387.971107][ T4315] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 387.995579][ T4315] usb 3-1: config 0 descriptor?? [ 388.270941][ T8953] device syzkaller1 entered promiscuous mode [ 388.484415][ T4315] plantronics 0003:047F:FFFF.0007: No inputs registered, leaving [ 388.500500][ T4315] plantronics 0003:047F:FFFF.0007: hiddev0,hidraw0: USB HID v0.40 Device [HID 047f:ffff] on usb-dummy_hcd.2-1/input0 [ 388.887704][ T4211] usbhid 1-1:0.0: can't add hid device: -71 [ 388.894146][ T4211] usbhid: probe of 1-1:0.0 failed with error -71 [ 388.918739][ T4211] usb 1-1: USB disconnect, device number 16 [ 389.780781][ T5174] usb 8-1: USB disconnect, device number 12 [ 389.836804][ T4315] usb 3-1: USB disconnect, device number 14 [ 390.559911][ T8970] syz.5.1103 (8970): drop_caches: 2 [ 390.755160][ T8971] syz.5.1103 (8971): drop_caches: 2 [ 390.881098][ T8985] netlink: 'syz.5.1107': attribute type 4 has an invalid length. [ 391.425036][ T9001] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1113'. [ 391.541932][ T5174] usb 6-1: new high-speed USB device number 18 using dummy_hcd [ 391.792015][ T5174] usb 6-1: Using ep0 maxpacket: 32 [ 391.928072][ T9019] binder: BINDER_SET_CONTEXT_MGR already set [ 391.934611][ T9019] binder: 9010:9019 ioctl 4018620d 200000000040 returned -16 [ 391.948912][ T9019] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1117'. [ 392.616251][ T26] audit: type=1326 audit(1746664982.309:121): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9020 comm=0AA126F20A6C01D33335A4B93E4CD6 exe="/root/syz-executor" sig=9 arch=c000003e syscall=231 compat=0 ip=0x7f87bca3d969 code=0x0 [ 392.702134][ T5174] usb 6-1: config 0 interface 0 has no altsetting 0 [ 392.710758][ T5174] usb 6-1: New USB device found, idVendor=1e71, idProduct=2011, bcdDevice= 0.00 [ 392.730288][ T5174] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 392.752128][ T5174] usb 6-1: config 0 descriptor?? [ 392.938617][ T9034] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1125'. [ 393.395274][ T9043] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 393.416063][ T8997] udc-core: couldn't find an available UDC or it's busy [ 393.423424][ T8997] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 393.432778][ T8997] netlink: 'syz.5.1111': attribute type 1 has an invalid length. [ 393.439659][ T9043] IPv6: ADDRCONF(NETDEV_CHANGE): dummy0: link becomes ready [ 393.474615][ T9043] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 393.496940][ T9043] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 393.533088][ T9049] program syz.5.1111 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 394.978532][ T9058] af_packet: tpacket_rcv: packet too big, clamped from 4 to 4294967272. macoff=96 [ 395.067830][ T5174] usbhid 6-1:0.0: can't add hid device: -71 [ 395.083260][ T5174] usbhid: probe of 6-1:0.0 failed with error -71 [ 395.120418][ T5174] usb 6-1: USB disconnect, device number 18 [ 395.350466][ T9068] binder: BINDER_SET_CONTEXT_MGR already set [ 395.356683][ T9068] binder: 9059:9068 ioctl 4018620d 200000000040 returned -16 [ 395.369688][ T9068] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1132'. [ 396.428991][ T9071] device syzkaller1 entered promiscuous mode [ 396.625173][ T9084] device syzkaller1 entered promiscuous mode [ 396.812403][ T4315] usb 3-1: new high-speed USB device number 15 using dummy_hcd [ 397.162059][ T4315] usb 3-1: Using ep0 maxpacket: 32 [ 397.201012][ T9101] loop7: detected capacity change from 0 to 512 [ 397.323249][ T4315] usb 3-1: config 0 interface 0 has no altsetting 0 [ 397.331194][ T4315] usb 3-1: New USB device found, idVendor=1e71, idProduct=2011, bcdDevice= 0.00 [ 397.369192][ T9101] EXT4-fs (loop7): encrypted files will use data=ordered instead of data journaling mode [ 397.405258][ T4315] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 397.431179][ T9101] EXT4-fs warning (device loop7): ext4_multi_mount_protect:300: Invalid MMP block in superblock [ 397.480813][ T4315] usb 3-1: config 0 descriptor?? [ 397.666031][ T9109] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1145'. [ 398.084007][ T9120] binder: BINDER_SET_CONTEXT_MGR already set [ 398.090114][ T9120] binder: 9110:9120 ioctl 4018620d 200000000040 returned -16 [ 398.282505][ T9095] udc-core: couldn't find an available UDC or it's busy [ 398.300211][ T9095] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 398.313016][ T9095] netlink: 'syz.2.1142': attribute type 1 has an invalid length. [ 398.391626][ T9123] program syz.2.1142 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 398.496185][ T9120] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1146'. [ 398.577114][ T4315] hid-generic 0003:1E71:2011.0008: collection stack underflow [ 398.601264][ T4315] hid-generic 0003:1E71:2011.0008: item 0 0 0 12 parsing failed [ 398.612001][ T4315] hid-generic: probe of 0003:1E71:2011.0008 failed with error -22 [ 398.857308][ T9140] loop7: detected capacity change from 0 to 256 [ 398.874896][ T9135] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(7) [ 398.882013][ T9135] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 398.892385][ T9145] usb usb8: usbfs: process 9145 (syz.3.1157) did not claim interface 7 before use [ 398.905506][ T9135] vhci_hcd vhci_hcd.0: Device attached [ 398.982106][ T9140] FAT-fs (loop7): Directory bread(block 64) failed [ 399.007128][ T9140] FAT-fs (loop7): Directory bread(block 65) failed [ 399.014343][ T9140] FAT-fs (loop7): Directory bread(block 66) failed [ 399.039095][ T9140] FAT-fs (loop7): Directory bread(block 67) failed [ 399.046957][ T9140] FAT-fs (loop7): Directory bread(block 68) failed [ 399.053817][ T9140] FAT-fs (loop7): Directory bread(block 69) failed [ 399.062240][ T9140] FAT-fs (loop7): Directory bread(block 70) failed [ 399.069141][ T9140] FAT-fs (loop7): Directory bread(block 71) failed [ 399.081608][ T9142] vhci_hcd: connection closed [ 399.090618][ T9140] FAT-fs (loop7): Directory bread(block 72) failed [ 399.095354][ T5875] vhci_hcd: stop threads [ 399.102463][ T9140] FAT-fs (loop7): Directory bread(block 73) failed [ 399.120369][ T5875] vhci_hcd: release socket [ 399.128098][ T5875] vhci_hcd: disconnect device [ 399.171972][ T5174] usb 33-1: new low-speed USB device number 2 using vhci_hcd [ 399.199328][ T5174] usb 33-1: enqueue for inactive port 0 [ 399.355607][ T5174] vhci_hcd: vhci_device speed not set [ 399.442994][ T26] audit: type=1326 audit(1746664989.139:122): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fbaa7a95b39 code=0x7ffc0000 [ 399.529907][ T26] audit: type=1326 audit(1746664989.179:123): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fbaa7a95b39 code=0x7ffc0000 [ 399.582222][ T26] audit: type=1326 audit(1746664989.179:124): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 399.612566][ T26] audit: type=1326 audit(1746664989.179:125): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fbaa7a95b39 code=0x7ffc0000 [ 399.742993][ T26] audit: type=1326 audit(1746664989.179:126): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 399.765352][ C0] vkms_vblank_simulate: vblank timer overrun [ 399.841328][ T26] audit: type=1326 audit(1746664989.179:127): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fbaa7a95b39 code=0x7ffc0000 [ 399.864782][ C0] vkms_vblank_simulate: vblank timer overrun [ 399.918004][ T26] audit: type=1326 audit(1746664989.179:128): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 399.992568][ T4211] usb 3-1: USB disconnect, device number 15 [ 400.047253][ T26] audit: type=1326 audit(1746664989.179:129): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 400.102774][ T9159] device syzkaller1 entered promiscuous mode [ 400.189721][ T26] audit: type=1326 audit(1746664989.179:130): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fbaa7af9969 code=0x7ffc0000 [ 400.212983][ C0] vkms_vblank_simulate: vblank timer overrun [ 400.306590][ T26] audit: type=1326 audit(1746664989.179:131): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=9154 comm="syz.3.1160" exe="/root/syz-executor" sig=0 arch=c000003e syscall=15 compat=0 ip=0x7fbaa7a95b39 code=0x7ffc0000 [ 400.329404][ C0] vkms_vblank_simulate: vblank timer overrun [ 400.504453][ T9163] device syzkaller1 entered promiscuous mode [ 401.881954][ T9186] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 401.890943][ T9186] IPv6: ADDRCONF(NETDEV_CHANGE): dummy0: link becomes ready [ 401.900297][ T9186] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 401.908299][ T9186] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 401.922414][ T9186] A link change request failed with some changes committed already. Interface hsr_slave_0 may have been left with an inconsistent configuration, please check. [ 402.592187][ T4315] usb 8-1: new high-speed USB device number 13 using dummy_hcd [ 402.942344][ T4315] usb 8-1: Using ep0 maxpacket: 32 [ 403.074119][ T4315] usb 8-1: config 0 interface 0 has no altsetting 0 [ 403.201987][ T4315] usb 8-1: New USB device found, idVendor=1e71, idProduct=2011, bcdDevice= 0.00 [ 403.252122][ T4315] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 403.342253][ T4315] usb 8-1: config 0 descriptor?? [ 404.062568][ T9199] udc-core: couldn't find an available UDC or it's busy [ 404.069854][ T9199] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 404.082166][ T9199] netlink: 'syz.7.1172': attribute type 1 has an invalid length. [ 404.115709][ T9199] program syz.7.1172 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 404.224443][ T4315] hid-generic 0003:1E71:2011.0009: collection stack underflow [ 404.248780][ T4315] hid-generic 0003:1E71:2011.0009: item 0 0 0 12 parsing failed [ 404.300596][ T4315] hid-generic: probe of 0003:1E71:2011.0009 failed with error -22 [ 404.532010][ T4315] usb 4-1: new full-speed USB device number 15 using dummy_hcd [ 404.962010][ T4315] usb 4-1: config 0 has no interfaces? [ 405.122012][ T4315] usb 4-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 405.147080][ T4315] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 405.189106][ T4315] usb 4-1: Product: syz [ 405.207144][ T4315] usb 4-1: Manufacturer: syz [ 405.236181][ T4315] usb 4-1: SerialNumber: syz [ 405.270643][ T4315] usb 4-1: config 0 descriptor?? [ 405.550388][ T4315] usb 8-1: USB disconnect, device number 13 [ 407.114419][ T13] usb 1-1: new high-speed USB device number 17 using dummy_hcd [ 407.152078][ T9265] vhci_hcd vhci_hcd.0: pdev(7) rhport(0) sockfd(6) [ 407.158756][ T9265] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 407.234489][ T9265] vhci_hcd vhci_hcd.0: Device attached [ 407.266307][ T9266] vhci_hcd: connection closed [ 407.361920][ T13] usb 1-1: Using ep0 maxpacket: 8 [ 407.481920][ T4315] usb 47-1: new low-speed USB device number 2 using vhci_hcd [ 407.533637][ T4554] vhci_hcd: stop threads [ 407.547590][ T4554] vhci_hcd: release socket [ 407.589807][ T4554] vhci_hcd: disconnect device [ 407.682172][ T13] usb 1-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid maxpacket 56832, setting to 1024 [ 407.710451][ T13] usb 1-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 1024 [ 407.722383][ T13] usb 1-1: config 16 interface 0 altsetting 0 endpoint 0x8B has invalid maxpacket 1312, setting to 1024 [ 407.742073][ T13] usb 1-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 1024 [ 407.752889][ T13] usb 1-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 407.772093][ T13] usb 1-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 407.781323][ T13] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 408.030764][ T9274] loop2: detected capacity change from 0 to 256 [ 408.052194][ T13] usb 1-1: GET_CAPABILITIES returned 0 [ 408.057947][ T13] usbtmc 1-1:16.0: can't read capabilities [ 408.068752][ T5174] usb 4-1: USB disconnect, device number 15 [ 408.202493][ T9274] FAT-fs (loop2): Directory bread(block 64) failed [ 408.209138][ T9274] FAT-fs (loop2): Directory bread(block 65) failed [ 408.226198][ T9274] FAT-fs (loop2): Directory bread(block 66) failed [ 408.245112][ T9274] FAT-fs (loop2): Directory bread(block 67) failed [ 408.282623][ T9274] FAT-fs (loop2): Directory bread(block 68) failed [ 408.299505][ T9274] FAT-fs (loop2): Directory bread(block 69) failed [ 408.316868][ T9274] FAT-fs (loop2): Directory bread(block 70) failed [ 408.340987][ T9274] FAT-fs (loop2): Directory bread(block 71) failed [ 408.354206][ T9274] FAT-fs (loop2): Directory bread(block 72) failed [ 408.365638][ T9274] FAT-fs (loop2): Directory bread(block 73) failed [ 408.581956][ T5174] usb 4-1: new high-speed USB device number 16 using dummy_hcd [ 409.423078][ T4212] usb 1-1: USB disconnect, device number 17 [ 409.742030][ T5174] usb 4-1: Using ep0 maxpacket: 32 [ 409.862366][ T5174] usb 4-1: config 0 interface 0 has no altsetting 0 [ 409.869253][ T5174] usb 4-1: New USB device found, idVendor=1e71, idProduct=2011, bcdDevice= 0.00 [ 409.917605][ T5174] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 409.945626][ T5174] usb 4-1: config 0 descriptor?? [ 410.015328][ T9317] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(7) [ 410.021870][ T9317] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 410.050563][ T9317] vhci_hcd vhci_hcd.0: Device attached [ 410.063862][ T9318] vhci_hcd: connection closed [ 410.064181][ T5875] vhci_hcd: stop threads [ 410.087059][ T5875] vhci_hcd: release socket [ 410.097276][ T5875] vhci_hcd: disconnect device [ 410.428395][ T23] usb 8-1: new full-speed USB device number 14 using dummy_hcd [ 410.665047][ T9281] udc-core: couldn't find an available UDC or it's busy [ 410.676696][ T9281] misc raw-gadget: fail, usb_gadget_probe_driver returned -16 [ 410.702998][ T9281] netlink: 'syz.3.1197': attribute type 1 has an invalid length. [ 410.747308][ T9281] program syz.3.1197 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 410.801993][ T23] usb 8-1: config 0 has no interfaces? [ 410.858230][ T5174] hid-generic 0003:1E71:2011.000A: collection stack underflow [ 410.874813][ T5174] hid-generic 0003:1E71:2011.000A: item 0 0 0 12 parsing failed [ 410.895283][ T5174] hid-generic: probe of 0003:1E71:2011.000A failed with error -22 [ 411.062312][ T23] usb 8-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 411.081673][ T23] usb 8-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 411.104314][ T23] usb 8-1: Product: syz [ 411.121922][ T23] usb 8-1: Manufacturer: syz [ 411.126708][ T23] usb 8-1: SerialNumber: syz [ 411.288971][ T23] usb 8-1: config 0 descriptor?? [ 412.822083][ T9341] binder: BINDER_SET_CONTEXT_MGR already set [ 412.828117][ T9341] binder: 9337:9341 ioctl 4018620d 200000000040 returned -16 [ 413.956089][ T9347] loop5: detected capacity change from 0 to 256 [ 413.972122][ T4315] vhci_hcd: vhci_device speed not set [ 414.074178][ T9347] FAT-fs (loop5): Directory bread(block 64) failed [ 414.080868][ T9347] FAT-fs (loop5): Directory bread(block 65) failed [ 414.088277][ T4212] usb 4-1: USB disconnect, device number 16 [ 414.122258][ T9347] FAT-fs (loop5): Directory bread(block 66) failed [ 414.148530][ T9347] FAT-fs (loop5): Directory bread(block 67) failed [ 414.167993][ T9347] FAT-fs (loop5): Directory bread(block 68) failed [ 414.192013][ T9347] FAT-fs (loop5): Directory bread(block 69) failed [ 414.214780][ T9347] FAT-fs (loop5): Directory bread(block 70) failed [ 414.241990][ T9347] FAT-fs (loop5): Directory bread(block 71) failed [ 414.268099][ T9347] FAT-fs (loop5): Directory bread(block 72) failed [ 414.277224][ T13] usb 3-1: new high-speed USB device number 16 using dummy_hcd [ 414.295708][ T9347] FAT-fs (loop5): Directory bread(block 73) failed [ 414.633503][ T9359] vhci_hcd vhci_hcd.0: pdev(3) rhport(0) sockfd(7) [ 414.640044][ T9359] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 414.737829][ T9359] vhci_hcd vhci_hcd.0: Device attached [ 414.795958][ T13] usb 3-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 414.816331][ T9360] vhci_hcd: connection closed [ 414.822269][ T5881] vhci_hcd: stop threads [ 414.827453][ T13] usb 3-1: config 1 has an invalid descriptor of length 0, skipping remainder of the config [ 414.831246][ T5881] vhci_hcd: release socket [ 414.861892][ T13] usb 3-1: config 1 has 0 interfaces, different from the descriptor's value: 66 [ 414.937874][ T5881] vhci_hcd: disconnect device [ 415.012177][ T13] usb 3-1: string descriptor 0 read error: -71 [ 415.030984][ T13] usb 3-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 415.091877][ T13] usb 3-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 415.161977][ T13] usb 3-1: can't set config #1, error -71 [ 415.179316][ T13] usb 3-1: USB disconnect, device number 16 [ 415.481997][ T23] usb 8-1: can't set config #0, error -71 [ 415.499958][ T23] usb 8-1: USB disconnect, device number 14 [ 415.529013][ T9376] netlink: 'syz.3.1227': attribute type 9 has an invalid length. [ 416.118285][ T9383] binder: BINDER_SET_CONTEXT_MGR already set [ 416.124527][ T9383] binder: 9377:9383 ioctl 4018620d 200000000040 returned -16 [ 417.721899][ T23] usb 8-1: new high-speed USB device number 15 using dummy_hcd [ 417.741978][ T13] usb 4-1: new high-speed USB device number 17 using dummy_hcd [ 417.992039][ T13] usb 4-1: Using ep0 maxpacket: 16 [ 418.034688][ T9404] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(7) [ 418.041273][ T9404] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 418.051112][ T4620] attempt to access beyond end of device [ 418.051112][ T4620] loop5: rw=1, want=1236, limit=256 [ 418.062871][ T9404] vhci_hcd vhci_hcd.0: Device attached [ 418.085708][ T9405] vhci_hcd: connection closed [ 418.085980][ T5875] vhci_hcd: stop threads [ 418.097849][ T5875] vhci_hcd: release socket [ 418.107651][ T5875] vhci_hcd: disconnect device [ 418.108323][ T23] usb 8-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 418.152013][ T13] usb 4-1: config 0 has no interfaces? [ 418.157934][ T13] usb 4-1: New USB device found, idVendor=0471, idProduct=0327, bcdDevice=61.a4 [ 418.175606][ T13] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 418.194551][ T13] usb 4-1: config 0 descriptor?? [ 418.211945][ T23] usb 8-1: config 27 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 418.227235][ T23] usb 8-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 418.237939][ T23] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 418.325266][ T23] usb 8-1: invalid MIDI out EP 0 [ 418.404463][ T23] snd-usb-audio: probe of 8-1:27.0 failed with error -22 [ 418.453699][ T4158] udevd[4158]: error opening ATTR{/sys/devices/platform/dummy_hcd.7/usb8/8-1/8-1:27.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 418.526492][ T9398] fuse: Unknown parameter '0x000000000000000a' [ 418.545602][ T23] usb 8-1: USB disconnect, device number 15 [ 419.306195][ T9423] binder: BINDER_SET_CONTEXT_MGR already set [ 419.312330][ T9423] binder: 9420:9423 ioctl 4018620d 200000000040 returned -16 [ 420.451664][ T9436] kvm: vcpu 0: requested lapic timer restore with starting count register 0x390=4174057588 (33392460704 ns) > initial count (29138837416 ns). Using initial count to start timer. [ 420.547024][ T9437] ptrace attach of "./syz-executor exec"[4167] was attempted by "./syz-executor exec"[9437] [ 420.858594][ T9446] loop2: detected capacity change from 0 to 256 [ 420.950978][ T9446] FAT-fs (loop2): Directory bread(block 64) failed [ 420.968606][ T9446] FAT-fs (loop2): Directory bread(block 65) failed [ 420.999837][ T9446] FAT-fs (loop2): Directory bread(block 66) failed [ 421.073656][ T9446] FAT-fs (loop2): Directory bread(block 67) failed [ 421.108668][ T9446] FAT-fs (loop2): Directory bread(block 68) failed [ 421.161507][ T9446] FAT-fs (loop2): Directory bread(block 69) failed [ 421.182637][ T9446] FAT-fs (loop2): Directory bread(block 70) failed [ 421.189626][ T9446] FAT-fs (loop2): Directory bread(block 71) failed [ 421.196861][ T9446] FAT-fs (loop2): Directory bread(block 72) failed [ 421.204318][ T9446] FAT-fs (loop2): Directory bread(block 73) failed [ 421.648213][ T9458] sch_tbf: burst 32855 is lower than device lo mtu (39287) ! [ 421.661986][ T13] usb 8-1: new high-speed USB device number 16 using dummy_hcd [ 422.042041][ T13] usb 8-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 422.072041][ T13] usb 8-1: config 27 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 422.167157][ T13] usb 8-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 422.251500][ T13] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 422.334421][ T13] usb 8-1: invalid MIDI out EP 0 [ 422.646529][ T9455] fuse: Unknown parameter '0x000000000000000a' [ 422.689792][ T13] snd-usb-audio: probe of 8-1:27.0 failed with error -22 [ 422.749087][ T13] usb 4-1: USB disconnect, device number 17 [ 422.779525][ T4158] udevd[4158]: error opening ATTR{/sys/devices/platform/dummy_hcd.7/usb8/8-1/8-1:27.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 422.887377][ T4212] usb 8-1: USB disconnect, device number 16 [ 424.278277][ T5875] attempt to access beyond end of device [ 424.278277][ T5875] loop2: rw=1, want=1236, limit=256 [ 424.600830][ T9508] netlink: 12 bytes leftover after parsing attributes in process `syz.0.1267'. [ 426.561948][ T4212] usb 6-1: new high-speed USB device number 19 using dummy_hcd [ 427.028701][ T4212] usb 6-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 427.206343][ T4212] usb 6-1: config 27 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 427.217792][ T4212] usb 6-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 427.231910][ T4212] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 427.380169][ T4212] usb 6-1: invalid MIDI out EP 0 [ 427.644504][ T4212] snd-usb-audio: probe of 6-1:27.0 failed with error -22 [ 428.142138][ T4160] udevd[4160]: error opening ATTR{/sys/devices/platform/dummy_hcd.5/usb6/6-1/6-1:27.0/sound/card3/controlC3/../uevent} for writing: No such file or directory [ 428.163061][ T9530] fuse: Unknown parameter '0x000000000000000a' [ 428.224664][ T4211] usb 6-1: USB disconnect, device number 19 [ 430.040241][ T9576] device macvlan1 entered promiscuous mode [ 430.198333][ T9576] device batadv0 entered promiscuous mode [ 431.064129][ T5881] IPv6: ADDRCONF(NETDEV_CHANGE): hsr1: link becomes ready [ 431.584489][ T9597] loop2: detected capacity change from 0 to 512 [ 431.817521][ T9597] EXT4-fs (loop2): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback. [ 431.898730][ T9597] ext4 filesystem being mounted at /55/file1 supports timestamps until 2038-01-19 (0x7fffffff) [ 432.893449][ T9605] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 432.901311][ T9605] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 432.914127][ T9605] A link change request failed with some changes committed already. Interface hsr_slave_0 may have been left with an inconsistent configuration, please check. [ 433.432128][ T4315] usb 4-1: new high-speed USB device number 18 using dummy_hcd [ 433.742242][ T4315] usb 4-1: Using ep0 maxpacket: 16 [ 433.872160][ T4315] usb 4-1: config 0 has no interfaces? [ 433.877690][ T4315] usb 4-1: New USB device found, idVendor=0471, idProduct=0327, bcdDevice=61.a4 [ 433.966399][ T4315] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 434.033014][ T4315] usb 4-1: config 0 descriptor?? [ 434.228282][ T9621] device syzkaller1 entered promiscuous mode [ 436.616610][ T23] usb 3-1: new high-speed USB device number 17 using dummy_hcd [ 436.635296][ T13] usb 4-1: USB disconnect, device number 18 [ 436.934652][ T9659] tipc: Can't bind to reserved service type 0 [ 437.016902][ T23] usb 3-1: Using ep0 maxpacket: 8 [ 437.060002][ T9660] IPv6: ADDRCONF(NETDEV_CHANGE): vcan0: link becomes ready [ 437.069045][ T9660] IPv6: ADDRCONF(NETDEV_CHANGE): dummy0: link becomes ready [ 437.077667][ T9660] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready [ 437.085375][ T9660] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready [ 437.099138][ T9660] A link change request failed with some changes committed already. Interface hsr_slave_0 may have been left with an inconsistent configuration, please check. [ 437.193272][ T23] usb 3-1: config 0 has no interfaces? [ 437.198811][ T23] usb 3-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 437.225302][ T23] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 437.253276][ T23] usb 3-1: config 0 descriptor?? [ 437.781902][ T4315] usb 6-1: new high-speed USB device number 20 using dummy_hcd [ 437.896548][ T5174] usb 3-1: USB disconnect, device number 17 [ 438.061904][ T4315] usb 6-1: Using ep0 maxpacket: 32 [ 438.205870][ T4315] usb 6-1: config index 0 descriptor too short (expected 156, got 27) [ 438.214263][ T4315] usb 6-1: too many endpoints for config 0 interface 0 altsetting 191: 144, using maximum allowed: 30 [ 438.225411][ T4315] usb 6-1: config 0 interface 0 altsetting 191 endpoint 0x87 has an invalid bInterval 0, changing to 7 [ 438.251890][ T4315] usb 6-1: config 0 interface 0 altsetting 191 has 1 endpoint descriptor, different from the interface descriptor's value: 144 [ 438.279447][ T4315] usb 6-1: config 0 interface 0 has no altsetting 0 [ 438.492335][ T4315] usb 6-1: New USB device found, idVendor=0f11, idProduct=1021, bcdDevice=86.66 [ 438.529202][ T4315] usb 6-1: New USB device strings: Mfr=85, Product=120, SerialNumber=172 [ 438.565287][ T4315] usb 6-1: Product: syz [ 438.584850][ T4315] usb 6-1: Manufacturer: syz [ 438.629939][ T4315] usb 6-1: SerialNumber: syz [ 438.663989][ T4315] usb 6-1: config 0 descriptor?? [ 438.703727][ T4315] ldusb 6-1:0.0: Interrupt out endpoint not found (using control endpoint instead) [ 438.740905][ T4315] ldusb 6-1:0.0: LD USB Device #0 now attached to major 180 minor 0 [ 438.821925][ T13] usb 8-1: new high-speed USB device number 17 using dummy_hcd [ 439.061998][ T13] usb 8-1: Using ep0 maxpacket: 16 [ 439.136981][ T9708] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1328'. [ 439.206909][ T13] usb 8-1: config 0 has no interfaces? [ 439.217741][ T13] usb 8-1: New USB device found, idVendor=0471, idProduct=0327, bcdDevice=61.a4 [ 439.255882][ T13] usb 8-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 439.320484][ T13] usb 8-1: config 0 descriptor?? [ 439.531407][ T4315] usb 6-1: USB disconnect, device number 20 [ 439.542263][ C0] ldusb 6-1:0.0: usb_submit_urb failed (-19) [ 439.549627][ T9714] ldusb 6-1:0.0: Couldn't submit HID_REQ_SET_REPORT -71 [ 439.578588][ T4315] ldusb 6-1:0.0: LD USB Device #0 now disconnected [ 439.935669][ T1422] ieee802154 phy0 wpan0: encryption failed: -22 [ 439.948538][ T1422] ieee802154 phy1 wpan1: encryption failed: -22 [ 440.179295][ T9730] ptrace attach of "./syz-executor exec"[4918] was attempted by "./syz-executor exec"[9730] [ 440.385309][ T9734] loop7: detected capacity change from 0 to 16384 [ 440.595100][ T9734] loop_set_status: loop7 () has still dirty pages (nrpages=248) [ 442.386642][ T9758] sctp: [Deprecated]: syz.5.1341 (pid 9758) Use of struct sctp_assoc_value in delayed_ack socket option. [ 442.386642][ T9758] Use struct sctp_sack_info instead [ 442.812000][ T4211] usb 6-1: new high-speed USB device number 21 using dummy_hcd [ 442.937882][ T13] usb 8-1: USB disconnect, device number 17 [ 443.071922][ T4315] usb 3-1: new high-speed USB device number 18 using dummy_hcd [ 443.311941][ T4211] usb 6-1: Using ep0 maxpacket: 8 [ 443.432255][ T4211] usb 6-1: config 16 has an invalid descriptor of length 0, skipping remainder of the config [ 443.593282][ T4315] usb 3-1: too many configurations: 239, using maximum allowed: 8 [ 443.755440][ T4211] usb 6-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid maxpacket 56832, setting to 1024 [ 443.766731][ T4211] usb 6-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 1024 [ 443.776942][ T4211] usb 6-1: config 16 interface 0 altsetting 0 has 1 endpoint descriptor, different from the interface descriptor's value: 3 [ 443.794088][ T4211] usb 6-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 443.803251][ T4211] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 443.853129][ T4211] usbtmc 6-1:16.0: bulk endpoints not found [ 443.957938][ T9780] IPVS: sh: UDP 224.0.0.2:0 - no destination available [ 444.331933][ T4211] usb 8-1: new full-speed USB device number 18 using dummy_hcd [ 444.442037][ T13] usb 1-1: new high-speed USB device number 18 using dummy_hcd [ 444.742690][ T4315] usb 3-1: New USB device found, idVendor=0cf3, idProduct=9271, bcdDevice= 1.08 [ 444.758053][ T4315] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 444.766865][ T4315] usb 3-1: Product: syz [ 444.771159][ T4315] usb 3-1: Manufacturer: syz [ 444.782973][ T4315] usb 3-1: SerialNumber: syz [ 444.844944][ T4315] usb 3-1: ath9k_htc: Firmware ath9k_htc/htc_9271-1.4.0.fw requested [ 444.884481][ T13] usb 1-1: Using ep0 maxpacket: 8 [ 444.892392][ T4211] usb 8-1: config 0 interface 0 altsetting 0 endpoint 0x6 has invalid maxpacket 1023, setting to 64 [ 444.908009][ T4211] usb 8-1: config 0 interface 0 altsetting 0 has an invalid endpoint with address 0x0, skipping [ 445.032268][ T13] usb 1-1: config 168 descriptor has 1 excess byte, ignoring [ 445.040034][ T13] usb 1-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 445.052349][ T13] usb 1-1: config 168 interface 0 altsetting 0 has an invalid endpoint with address 0xFF, skipping [ 445.082262][ T4211] usb 8-1: New USB device found, idVendor=2294, idProduct=425b, bcdDevice=a2.10 [ 445.101125][ T4211] usb 8-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 445.109850][ T4211] usb 8-1: Product: syz [ 445.120380][ T4211] usb 8-1: Manufacturer: syz [ 445.125798][ T4211] usb 8-1: SerialNumber: syz [ 445.138841][ T4211] usb 8-1: config 0 descriptor?? [ 445.162406][ T9792] raw-gadget.1 gadget: fail, usb_ep_enable returned -22 [ 445.169910][ T13] usb 1-1: config 168 descriptor has 1 excess byte, ignoring [ 445.178212][ T13] usb 1-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 445.190131][ T13] usb 1-1: config 168 interface 0 altsetting 0 has an invalid endpoint with address 0xFF, skipping [ 445.200247][ T4211] usb 8-1: ucan: probing device on interface #0 [ 445.209425][ T4211] usb 8-1: ucan: invalid EP count (1) [ 445.221912][ T4211] usb 8-1: ucan: probe failed; try to update the device firmware [ 445.230775][ T9815] [ 445.234295][ T9815] ============================= [ 445.240679][ T9815] WARNING: suspicious RCU usage [ 445.246034][ T9815] 5.15.181-syzkaller #0 Not tainted [ 445.251268][ T9815] ----------------------------- [ 445.257294][ T9815] include/linux/kvm_host.h:889 suspicious rcu_dereference_check() usage! [ 445.266283][ T9815] [ 445.266283][ T9815] other info that might help us debug this: [ 445.266283][ T9815] [ 445.277151][ T9815] [ 445.277151][ T9815] rcu_scheduler_active = 2, debug_locks = 1 [ 445.285880][ T9815] 1 lock held by syz.3.1359/9815: [ 445.291218][ T9815] #0: ffff8880587480c8 (&vcpu->mutex){+.+.}-{3:3}, at: kvm_vcpu_ioctl+0x1c8/0xb80 [ 445.300702][ T9815] [ 445.300702][ T9815] stack backtrace: [ 445.302960][ T13] usb 1-1: config 168 descriptor has 1 excess byte, ignoring [ 445.308107][ T9815] CPU: 1 PID: 9815 Comm: syz.3.1359 Not tainted 5.15.181-syzkaller #0 [ 445.322335][ T9815] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/19/2025 [ 445.332494][ T9815] Call Trace: [ 445.335775][ T9815] [ 445.338727][ T9815] dump_stack_lvl+0x168/0x230 [ 445.343442][ T9815] ? load_image+0x3b0/0x3b0 [ 445.347958][ T9815] ? show_regs_print_info+0x20/0x20 [ 445.353164][ T9815] ? lockdep_rcu_suspicious+0x110/0x180 [ 445.358719][ T9815] kvm_vcpu_memslots+0x1b6/0x200 [ 445.363755][ T9815] kvm_vcpu_gfn_to_memslot+0x2b/0x3c0 [ 445.369133][ T9815] ? sync_vmcs02_to_vmcs12+0xd33/0x19a0 [ 445.374691][ T9815] kvm_vcpu_unmap+0x5b/0x80 [ 445.379485][ T9815] nested_vmx_vmexit+0x13f5/0x28d0 [ 445.384617][ T9815] ? nested_mark_vmcs12_pages_dirty+0x290/0x290 [ 445.390857][ T9815] ? __might_fault+0xb7/0x110 [ 445.395536][ T9815] ? __lock_acquire+0x7c60/0x7c60 [ 445.400569][ T9815] vmx_leave_nested+0x7e/0xc0 [ 445.405254][ T9815] kvm_vcpu_ioctl_x86_set_vcpu_events+0x95b/0x1190 [ 445.411775][ T9815] kvm_arch_vcpu_ioctl+0x1092/0x19d0 [ 445.417282][ T9815] ? kvm_arch_vcpu_put+0x840/0x840 [ 445.422401][ T9815] ? is_bpf_text_address+0x254/0x270 [ 445.427701][ T9815] ? __kernel_text_address+0x9a/0x100 [ 445.433086][ T9815] ? mark_lock+0x94/0x320 [ 445.437540][ T9815] ? __lock_acquire+0x13ad/0x7c60 [ 445.442667][ T9815] ? kfree+0xef/0x2a0 [ 445.446668][ T9815] ? __se_sys_ioctl+0x48/0x170 [ 445.451445][ T9815] ? kfree+0xef/0x2a0 [ 445.455465][ T9815] ? kasan_set_track+0x62/0x70 [ 445.460236][ T9815] ? kasan_set_track+0x4b/0x70 [ 445.465013][ T9815] ? kasan_set_free_info+0x1f/0x40 [ 445.470230][ T9815] ? verify_lock_unused+0x140/0x140 [ 445.475433][ T9815] ? tomoyo_path_number_perm+0x48f/0x5d0 [ 445.481102][ T9815] ? __mutex_trylock_common+0x14f/0x250 [ 445.490737][ T9815] ? rcu_lock_release+0x20/0x20 [ 445.495609][ T9815] ? __ia32_compat_sys_ioctl+0x850/0x850 [ 445.501247][ T9815] ? rcu_lock_release+0x5/0x20 [ 445.506011][ T9815] ? kvm_vcpu_ioctl+0x1c8/0xb80 [ 445.509993][ T13] usb 1-1: config 168 interface 0 altsetting 0 endpoint 0x3 has an invalid bInterval 255, changing to 11 [ 445.510866][ T9815] ? kvm_vcpu_ioctl+0x1c8/0xb80 [ 445.527128][ T9815] ? kvm_vcpu_ioctl+0x1c8/0xb80 [ 445.528351][ T13] usb 1-1: config 168 interface 0 altsetting 0 has an invalid endpoint with address 0xFF, skipping [ 445.532101][ T9815] ? __mutex_lock_common+0x431/0x2390 [ 445.532136][ T9815] ? kfree+0xef/0x2a0 [ 445.532164][ T9815] ? tomoyo_path_number_perm+0x4d4/0x5d0 [ 445.532191][ T9815] ? verify_lock_unused+0x140/0x140 [ 445.563150][ T9815] ? mutex_lock_io_nested+0x60/0x60 [ 445.568373][ T9815] kvm_vcpu_ioctl+0x6b1/0xb80 [ 445.573147][ T9815] ? kvm_clear_stat_per_vcpu+0x1f0/0x1f0 [ 445.578911][ T9815] ? bpf_lsm_file_ioctl+0x5/0x10 [ 445.583850][ T9815] ? security_file_ioctl+0x7c/0xa0 [ 445.588966][ T9815] ? kvm_clear_stat_per_vcpu+0x1f0/0x1f0 [ 445.594707][ T9815] __se_sys_ioctl+0xfa/0x170 [ 445.599304][ T9815] do_syscall_64+0x4c/0xa0 [ 445.603722][ T9815] ? clear_bhb_loop+0x15/0x70 [ 445.613001][ T9815] ? clear_bhb_loop+0x15/0x70 [ 445.617683][ T9815] entry_SYSCALL_64_after_hwframe+0x66/0xd0 [ 445.623603][ T9815] RIP: 0033:0x7fbaa7af9969 [ 445.628024][ T9815] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 445.647662][ T9815] RSP: 002b:00007fbaa5961038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 445.656093][ T9815] RAX: ffffffffffffffda RBX: 00007fbaa7d20fa0 RCX: 00007fbaa7af9969 [ 445.664071][ T9815] RDX: 0000200000000080 RSI: 000000004040aea0 RDI: 0000000000000005 [ 445.672043][ T9815] RBP: 00007fbaa7b7bab1 R08: 0000000000000000 R09: 0000000000000000 [ 445.680024][ T9815] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 445.688002][ T9815] R13: 0000000000000000 R14: 00007fbaa7d20fa0 R15: 00007ffd03b10618 [ 445.695996][ T9815] [ 445.718528][ T23] usb 6-1: USB disconnect, device number 21 [ 445.791672][ T4211] usb 3-1: USB disconnect, device number 18 [ 445.802140][ T4315] usb 3-1: ath9k_htc: Firmware - ath9k_htc/htc_9271-1.4.0.fw download failed [ 445.813802][ T4211] usb 3-1: ath9k_htc: USB layer deinitialized [ 445.922197][ T13] usb 1-1: string descriptor 0 read error: -22 [ 445.928899][ T13] usb 1-1: New USB device found, idVendor=0a07, idProduct=0064, bcdDevice=40.6e [ 445.939339][ T13] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 445.983681][ T13] adutux 1-1:168.0: interrupt endpoints not found [ 446.202647][ T4211] usb 1-1: USB disconnect, device number 18 [ 447.089881][ T5174] usb 8-1: USB disconnect, device number 18 [ 452.261940][ T13] Bluetooth: hci3: command 0x0406 tx timeout