last executing test programs: 4m6.429614052s ago: executing program 4 (id=1092): r0 = openat$sndtimer(0xffffffffffffff9c, &(0x7f0000000040), 0x8000) dup(0xffffffffffffffff) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000080)={0x5, 0x1000086}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x43, &(0x7f0000000040)=0x2) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) socket$nl_generic(0x10, 0x3, 0x10) ftruncate(0xffffffffffffffff, 0x200000000000) r2 = socket$rds(0x15, 0x5, 0x0) bind$rds(r2, 0x0, 0x0) sendmsg$rds(r2, &(0x7f0000000000)={0x0, 0x0, 0x0}, 0x0) setsockopt$inet6_IPV6_FLOWLABEL_MGR(0xffffffffffffffff, 0x29, 0x20, &(0x7f0000000280)={@mcast1, 0x800, 0x0, 0x103, 0x1}, 0x20) socket$nl_netfilter(0x10, 0x3, 0xc) ioctl$SNDRV_TIMER_IOCTL_GPARAMS(r0, 0x40345410, &(0x7f00000004c0)={{0x3}}) ioctl$SNDRV_TIMER_IOCTL_PARAMS(r0, 0x80605414, 0xffffffffffffffff) 4m4.488249114s ago: executing program 4 (id=1097): socket$nl_generic(0x10, 0x3, 0x10) r0 = openat$tun(0xffffffffffffff9c, &(0x7f0000000140), 0x0, 0x0) ioctl$TUNSETIFF(r0, 0x400454ca, &(0x7f00000000c0)={'syzkaller1\x00', 0x2}) sendmmsg$unix(0xffffffffffffffff, &(0x7f00000001c0)=[{{0x0, 0x0, &(0x7f0000000100)=[{0x0}], 0x1, 0x0, 0x0, 0x408c4}}], 0x1, 0x6001090) readv(r0, &(0x7f00000001c0)=[{&(0x7f0000001400)=""/227, 0x10}], 0x4) bpf$MAP_CREATE(0x1900000000000000, 0x0, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000300)={0x11, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="1805000000000000000000004b64ffec850000007d000000850000000700000095"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000000080)=ANY=[@ANYBLOB="18000025e9000000000000c10000002e"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000080)={0xffffffffffffffff}) r2 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) r3 = bpf$MAP_CREATE(0x0, &(0x7f00000002c0)=ANY=[@ANYRES32=r2, @ANYRES32, @ANYRES32=r1, @ANYRES32, @ANYBLOB="713cb1c1006e683e6d98b4f5ffffff0030be85b767d24fde0000000045cdf3e8eccde36236e5e50c31d966fce89cbcd4efb10b283468e60073b18048a3040f99beaf9dc0c84ebecc5ae659c9b7ca5c180be74b7fc3c3c474f30c84febcfb428e53667d705272a4"], 0x50) r4 = gettid() timer_create(0x0, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004, @tid=r4}, &(0x7f0000bbdffc)) timer_settime(0x0, 0x0, &(0x7f0000000280)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) pipe2(&(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}, 0x0) write$FUSE_INIT(r5, &(0x7f0000000400)={0x6f, 0x0, 0x0, {0x7, 0x28, 0x80000001, 0x0, 0x0, 0x0, 0x2, 0x1}}, 0xfffffede) vmsplice(r5, &(0x7f0000000140)=[{&(0x7f0000000100)="eb", 0x20000101}], 0x1, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x5, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x1) sched_setaffinity(0x0, 0x8, &(0x7f0000000380)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r6 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r6, &(0x7f0000034000)=""/102400, 0x19000) mmap$binder(&(0x7f0000bdf000/0x1000)=nil, 0x1000, 0x1, 0x11, 0xffffffffffffffff, 0x2000004) bind$inet6(0xffffffffffffffff, 0x0, 0x0) sendto$inet6(0xffffffffffffffff, 0x0, 0x0, 0x20000080, 0x0, 0x0) r7 = socket$nl_generic(0x10, 0x3, 0x10) r8 = syz_genetlink_get_family_id$ethtool(&(0x7f0000000000), 0xffffffffffffffff) sendmsg$ETHTOOL_MSG_LINKMODES_SET(r7, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000180)={&(0x7f0000000480)=ANY=[@ANYRES64=r3, @ANYRES16=r8, @ANYBLOB], 0x1490}}, 0x0) fcntl$notify(r2, 0x402, 0x4) 4m2.246245875s ago: executing program 4 (id=1103): r0 = socket$alg(0x26, 0x5, 0x0) bind$alg(r0, &(0x7f00000004c0)={0x26, 'skcipher\x00', 0x0, 0x0, 'cbc-twofish-3way\x00'}, 0x58) setsockopt$ALG_SET_KEY(r0, 0x117, 0x1, &(0x7f0000c18000)="ad56b6c5820fae9d6dcd3292ea54c7beef915d564c", 0x15) mkdirat(0xffffffffffffff9c, &(0x7f0000002040)='./file0\x00', 0x0) mkdir(0x0, 0x0) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000100)={[{@workdir={'workdir', 0x3d, './bus'}}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) r1 = open(&(0x7f0000000140)='./file0\x00', 0x800, 0x70) r2 = socket$nl_generic(0x10, 0x3, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) r3 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r3, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) sendmsg$nl_generic(r2, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000001ac0)={&(0x7f0000001b00)={0x1c, 0x2d, 0x1, 0x70bd26, 0x25dfdbfc, {0x4}, [@typed={0x8, 0xc, 0x0, 0x0, @fd=r2}]}, 0x1c}, 0x1, 0x0, 0x0, 0x4000d}, 0x20000000) r4 = syz_init_net_socket$llc(0x1a, 0x1, 0x0) connect$llc(r4, &(0x7f0000000180)={0x1a, 0x0, 0x0, 0x8, 0x0, 0x0, @multicast}, 0x10) mknodat$loop(r1, &(0x7f0000001600)='./file1\x00', 0x0, 0x0) chdir(&(0x7f0000000140)='./bus\x00') link(&(0x7f0000000200)='./file1\x00', &(0x7f0000000300)='./bus\x00') unlinkat(r1, 0x0, 0x200) unlink(&(0x7f0000000040)='./file1\x00') bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000100)={&(0x7f0000000400)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x31, 0x31, 0x3, [@type_tag={0xf, 0x0, 0x0, 0x12, 0x3}, @datasec={0x3, 0x2, 0x0, 0xf, 0x1, [{0x3, 0x1, 0x7}, {0x2, 0x2}], '\\'}]}, {0x0, [0x30]}}, &(0x7f0000000340)=""/142, 0x4f, 0x8e, 0x1, 0x0, 0x0, @void, @value}, 0x28) open(&(0x7f00000005c0)='./bus\x00', 0x66842, 0x0) r5 = openat$vhost_vsock(0xffffffffffffff9c, &(0x7f00000000c0), 0x2, 0x0) pwritev(r5, &(0x7f0000000080)=[{&(0x7f0000000240)="020000", 0x3}, {&(0x7f0000000000)='\x00', 0x1}], 0x2, 0x0, 0x0) r6 = accept4(r0, 0x0, 0x0, 0x80800) sendmmsg$alg(r6, &(0x7f0000000040)=[{0x0, 0x0, 0x0}], 0x1, 0x40800) 3m59.442731013s ago: executing program 4 (id=1110): ioprio_set$pid(0x2, 0x0, 0x2007) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x0, 0x0) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000380)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) timerfd_settime(0xffffffffffffffff, 0x2, &(0x7f0000007000)={{0x0, 0x3938700}, {0x0, 0x989680}}, 0x0) r3 = syz_open_dev$tty1(0xc, 0x4, 0x1) ioctl$KDFONTOP_SET(r3, 0x4b72, &(0x7f0000000040)={0x4, 0x0, 0x3, 0x1d, 0x100, &(0x7f00000000c0)="387ed7626d850509a2d6c1aa38f15cd00f85c263cb226db671261fff7ce9c555f18dafae3530db6dd493f2a3cc88721b9ae21b3e3b4523ae2594f47d8f62b480c4160b1f90ac9c41fae6ab12ac4c113fef588684ef494c89092883b902a41cd75387ef6f7bc7d460d5e665f398ff95596dc94ec97003c7e6f3c82fbd8de6e11aa4031a61c51caf7a65a2b613bda33f3eaeae635d7cd81761e74c38a7695800a15516eb337056e02335f9a7d10aa2eaf7beb7e1aed6e850ecb3421143c5c4ded0f06affc524dcf3208272619b6a952db5bc96141b26c54d13c7a5416287a3b6f7aadf50bc549974b6401a19cdb130282b955592efa94242065a4c8d695a2cdd9ada350defd58c775b92d348305774d3a256c7520b285d8da0dbf5e20d604413ed2ddf9bcbf881caf811852806175d63892a15234fbcd7a88a2a0aea45d19148f0e7dada7d6d0d77881387fdeaa0284abe90b88dfff412bff40c31c6415c54ae3335e54a49d315851feffe30d999c36def4df7df747695efbd649f42f310859122c0d2c1e558dc6586958a283762386ecf369274e43003a0fdff59ea515eb44504901ef0d00baa91c10a8e44a76aac3468a15bd3d45ad389977467f306f9bcde071b30769795eed2f1580414d168f557cd90040c4bd2a3d6bc5092548feaef7204a12cece59181fcb5bad8c24bd9f8f78d17ab82831325501e80d899e9252f99d3a2666343392fda11504800f4dd9f45657f8224fc78eb1168fe0527fac33466aadf48f16994d29a47778566e0f3945b2bf36b6eecc7fa18914beb66ac9e519bd333b30d3ce2f50dddeea3447aebbe3bed781e39d5a0fb0cdc60e196f2261305feb596b68986af3eee7b199fefb5f79ffb2d1050e46982af1c14a88dd9000400002f56a8404755c73e74bb90e64bab9647c70ed5afca1c3d87907d01000100df6f40a80ace2bb8a2aad3b0c66915927db4233181943d88c0c76d5969e2043db5bd77fd60ba0f013139929ccfec965c0c769785a4d23332ba1f0875e3146afef5b20cc306d3ecee65944fe9829e0ad0c3f6bb2fd81bc31152538db50f47dc38ba908a0d808687e478a609fe0daa02d4e9c618b99266e7f2e98597e2813e1dba9c3c16e9fab3bda6ed33cb1c75513e2264b69d472dd0e1338688ba782b41bde141f99c4894ded98eff9aa53d22eb77c9d93169c04ab2490bf28106f770e07eb7a9e87dde71929f918b98c4cbfcb11a90139264a9ee8081973167f493760278df0cc34be9e8f86f948d9a62e63ad6ca9d2195ff9c6320c85bddc42915e4f3a5db642447bc2195a3d64e04c9ecd1c313c08e29b814bd8fed1ab6d2846c73345962895d289ac77152cac2e0e32b75ce814731c542091f218dd1e68a15f8226577bf9481ae0555db64a717eb23a811356d00"}) bpf$MAP_UPDATE_CONST_STR(0x2, 0x0, 0x0) bpf$MAP_UPDATE_CONST_STR(0x2, &(0x7f0000001300)={{0xffffffffffffffff, 0xffffffffffffffff}, &(0x7f0000001280), 0x0}, 0x20) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, 0x0, 0x0) ioctl$sock_ipv4_tunnel_SIOCGETTUNNEL(0xffffffffffffffff, 0x89f0, &(0x7f00000000c0)={'syztnl2\x00', &(0x7f0000000040)={'gretap0\x00', 0x0, 0x700, 0x7800, 0x1, 0x2, {{0x6, 0x4, 0x2, 0xb, 0x18, 0x66, 0x0, 0x6, 0x4, 0x0, @loopback, @loopback, {[@end]}}}}}) bpf$BPF_GET_BTF_INFO(0xf, &(0x7f0000000780)={0xffffffffffffffff, 0x20, &(0x7f00000004c0)={&(0x7f0000000600)=""/162, 0xa2, 0x0, &(0x7f00000006c0)=""/189, 0xbd}}, 0x10) pipe(&(0x7f0000000040)) socket$nl_route(0x10, 0x3, 0x0) r6 = bpf$PROG_LOAD(0x5, &(0x7f00000007c0)={0x11, 0x10, &(0x7f0000000500)=ANY=[@ANYRES32=r4, @ANYBLOB="0000000000000000b70500000800000085000000a500000095000000000000006633c1ba041c9cdc25bf88851e95a66b602fa04191a7c6a064d8fe88ea45592f90d46913f2a0227ac841489db0f40a00000000000000cab5c74070a5b509ca8b777a0f1c8400b89cf579fba49887744aa93003f7defab3520b65b96a569bd65b93b761538924d3202ab3daa7c1d8748c8e1e42e8169e33b3a707ead7ac352c617dc8109eb709c2feac3f2bb2368b5f72a9f4917b8a940d4d8dfa7bb7b035f6f22aa64db342d870da0134f9ac9b90250dd77a38e9422f694773c5a5"], &(0x7f0000000000)='GPL\x00', 0x1a8289bf, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1b, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r5, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='signal_generate\x00', r6}, 0x18) r7 = socket$phonet(0x23, 0x2, 0x1) sendto$phonet(r7, 0x0, 0x0, 0x0, &(0x7f0000000300)={0x23, 0x0, 0x2}, 0x10) shmctl$IPC_RMID(0x0, 0x0) r8 = socket(0x2000000000000021, 0x2, 0x10000000000002) connect$rxrpc(r8, &(0x7f0000000140)=@in4={0x21, 0x4, 0x2, 0x10, {0x2, 0x4e24, @multicast2}}, 0x24) sendmmsg(r8, &(0x7f0000005c00)=[{{0x0, 0x0, 0x0, 0x0, &(0x7f0000000040)=ANY=[@ANYBLOB="18000000000000001001000001"], 0x18}}], 0x1, 0x0) 3m57.943930507s ago: executing program 4 (id=1113): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPSET_CMD_CREATE(r0, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000044c0)={&(0x7f0000000480)={0x14, 0x2, 0x6, 0x801, 0x0, 0x0, {0x0, 0x0, 0xfffc}}, 0x14}}, 0x0) 3m57.440793174s ago: executing program 4 (id=1117): setsockopt$netlink_NETLINK_ADD_MEMBERSHIP(0xffffffffffffffff, 0x10e, 0x1, &(0x7f0000000300)=0x800005, 0x4) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r0 = syz_open_dev$MSR(&(0x7f00000001c0), 0x8000002000000, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) sendmsg$NL80211_CMD_RELOAD_REGDB(0xffffffffffffffff, &(0x7f0000000380)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x20000000}, 0x8000) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="180100001c0000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000100)={&(0x7f00000000c0)='sys_enter\x00', r1}, 0x10) rt_sigprocmask(0x0, &(0x7f0000000000)={[0xfffffffffffffffd]}, 0x0, 0x8) rt_sigtimedwait(&(0x7f00000001c0)={[0xfffffffffffffffe]}, 0x0, 0x0, 0x8) 3m42.262198419s ago: executing program 32 (id=1117): setsockopt$netlink_NETLINK_ADD_MEMBERSHIP(0xffffffffffffffff, 0x10e, 0x1, &(0x7f0000000300)=0x800005, 0x4) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r0 = syz_open_dev$MSR(&(0x7f00000001c0), 0x8000002000000, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) sendmsg$NL80211_CMD_RELOAD_REGDB(0xffffffffffffffff, &(0x7f0000000380)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x20000000}, 0x8000) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="180100001c0000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000100)={&(0x7f00000000c0)='sys_enter\x00', r1}, 0x10) rt_sigprocmask(0x0, &(0x7f0000000000)={[0xfffffffffffffffd]}, 0x0, 0x8) rt_sigtimedwait(&(0x7f00000001c0)={[0xfffffffffffffffe]}, 0x0, 0x0, 0x8) 2m1.825676463s ago: executing program 3 (id=1362): r0 = memfd_create(&(0x7f00000000c0)='y\x105\xfb\xf7u\x83%:r\xc2\xb9x\xa4q\xc1\xea\x7f\x8cZ7`_4t\xcda\xa11\x11\x0e\xa1\xcf\x00\x00\x00\x00o~\x16\v\x03\n)\nL\x00'/60, 0x2) sendmsg$nl_route_sched(0xffffffffffffffff, 0x0, 0x0) getsockname$packet(0xffffffffffffffff, &(0x7f0000000200)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, 0x0) sendmmsg(0xffffffffffffffff, &(0x7f00000002c0), 0x40000000000009f, 0x0) sendmsg$nl_generic(0xffffffffffffffff, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, 0x0, 0x0) fcntl$addseals(r0, 0x409, 0x7) r2 = syz_io_uring_setup(0xbdc, &(0x7f0000000640)={0x0, 0xec25, 0x8, 0x4, 0x40000133}, &(0x7f00000006c0), &(0x7f00000001c0)) io_uring_enter(r2, 0x847ba, 0x0, 0xe, 0x0, 0x0) stat(&(0x7f0000000ac0)='./file0\x00', &(0x7f0000000340)) socket$nl_generic(0x10, 0x3, 0x10) 2m1.263575848s ago: executing program 3 (id=1363): syz_usb_control_io$cdc_ecm(0xffffffffffffffff, &(0x7f0000000040)={0x14, 0x0, &(0x7f0000000e00)={0x0, 0x3, 0x1a, {0x1a}}}, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) mkdir(&(0x7f0000000400)='./file0\x00', 0x0) sendmsg$SOCK_DIAG_BY_FAMILY(0xffffffffffffffff, 0x0, 0x48c0) chdir(&(0x7f0000000100)='./file0\x00') sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000840)={&(0x7f0000000400)=@pppol2tpv3in6={0x18, 0x1, {0x0, 0xffffffffffffffff, 0x0, 0x12, 0x0, 0x0, {0xa, 0x0, 0x0, @local}}}, 0x80, 0x0}, 0x0) r3 = socket$kcm(0x2, 0x1, 0x84) setsockopt$sock_attach_bpf(r3, 0x84, 0x9, &(0x7f0000000380), 0x98) sendmsg$inet(r3, &(0x7f00000006c0)={&(0x7f00000000c0)={0x2, 0x0, @remote}, 0x10, &(0x7f0000000100)=[{&(0x7f0000000000)="93", 0x34000}], 0x1}, 0x4040) 1m59.511642092s ago: executing program 3 (id=1368): socket$phonet_pipe(0x23, 0x5, 0x2) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x1) sched_setaffinity(0x0, 0x8, &(0x7f0000000200)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r0 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r0, &(0x7f0000002000)=""/102400, 0x19000) ioctl$UI_SET_LEDBIT(0xffffffffffffffff, 0x40045569, 0x7) userfaultfd(0x801) munmap(&(0x7f00003fe000/0xc00000)=nil, 0xc00000) r1 = socket(0x10, 0x3, 0x0) sendmsg$nl_route(r1, &(0x7f0000000080)={0xffffffffffffffff, 0x0, &(0x7f0000000680)={&(0x7f0000000180)=@ipv6_newnexthop={0x1c, 0x68, 0x5, 0x70bd2a, 0x0, {0x2}, [@NHA_FDB={0x4}]}, 0x1c}}, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) 1m57.562257488s ago: executing program 3 (id=1372): r0 = socket$nl_route(0x10, 0x3, 0x0) bpf$MAP_CREATE(0x0, &(0x7f0000000100)=ANY=[@ANYBLOB="0400000004000000e27f0000010000", @ANYRES32], 0x50) syz_emit_ethernet(0x1e, &(0x7f0000000100)=ANY=[], 0x0) socketpair$tipc(0x1e, 0x2, 0x0, &(0x7f0000000100)) r1 = socket(0x1, 0x803, 0x0) getsockname$packet(r1, &(0x7f0000000100)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f00000001c0)=0x14) sendmsg$nl_route(r0, &(0x7f0000000280)={0x0, 0x0, &(0x7f0000000140)={&(0x7f00000002c0)=@newlink={0x58, 0x10, 0x403, 0x0, 0x0, {0x0, 0x0, 0x0, 0x0, 0x90646}, [@IFLA_LINKINFO={0x28, 0x12, 0x0, 0x1, @vlan={{0x9}, {0x18, 0x2, 0x0, 0x1, [@IFLA_VLAN_FLAGS={0xc, 0x2, {0x1f, 0x1f}}, @IFLA_VLAN_ID={0x6, 0x1, 0x1}]}}}, @IFLA_LINK={0x8, 0x5, r2}, @IFLA_MASTER={0x8, 0xa, r2}]}, 0x58}, 0x1, 0x0, 0x0, 0x600}, 0x0) r3 = socket$netlink(0x10, 0x3, 0x0) sendmsg$nl_route(r3, &(0x7f0000000740)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000000c0)=@setlink={0x3c, 0x10, 0x401, 0x0, 0x0, {0x0, 0x0, 0x0, 0x0, 0x4280}, [@IFLA_LINKINFO={0x14, 0x12, 0x0, 0x1, @bond={{0x9}, {0x4}}}, @IFLA_MASTER={0x8, 0x3a}]}, 0x3c}}, 0x0) r4 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r4, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000240)=ANY=[@ANYBLOB="140000001000040000000000000000000000000a20000000000a01020000000000000000070000000900010073797a30000000003c000000090a010400000000000000000700000008000a40000000000900020073797a31000000000900010073797a300000000008000540000000218c0000000c0a01030000000000000000070000090900020073797a31000000000900010073797a3000000000600003805c000080080003400000000250000b80200001800a00010071756f7461000000100002800c00014000000000000000002c0001800a0001006c696d69740000001c0002800c00024000000000000000000c0001400000000000000003140000001000010000000000000000000084000a0142ffc0679d5b709bb2cb926ff0952917d416e32c0904ea4f9281cc8afa0581be6f43b12873ae477c33e0ed74214d0e", @ANYRES64], 0x110}, 0x1, 0x0, 0x0, 0x4004c40}, 0x4) 1m55.197993934s ago: executing program 3 (id=1378): prctl$PR_SET_SYSCALL_USER_DISPATCH_ON(0x3b, 0x1, 0x0, 0x0, &(0x7f0000006680)) r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) socket$kcm(0x2d, 0x2, 0x0) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000400)={0x11, 0x0, 0x0, &(0x7f0000000280)='syzkaller\x00', 0xea, 0x0, 0x0, 0x41100, 0x4, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x3b, 0x0, 0x0, 0x10, 0x20000, @void, @value}, 0x94) r2 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r2, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000180)={&(0x7f00000004c0)=ANY=[@ANYBLOB="240000001e0001000000000000000000020000000100000000000000"], 0x24}, 0x1, 0x0, 0x0, 0x2}, 0x4044040) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000000)='sched_switch\x00', r1, 0x0, 0x400}, 0x18) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r3 = getpid() sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) setsockopt$IP_VS_SO_SET_ADD(0xffffffffffffffff, 0x0, 0x482, &(0x7f0000000080)={0x11, @rand_addr, 0x0, 0x4, 'lblcr\x00', 0x0, 0xfffffff8}, 0x2c) 1m51.180063266s ago: executing program 3 (id=1384): bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x3, 0x4, &(0x7f0000000040)=@framed={{0xffffffb4, 0x5, 0x0, 0x0, 0x0, 0x61, 0x10, 0xa0}, [@ldst={0x3, 0x0, 0x3, 0x1c10a1, 0x0, 0x48}], {0x95, 0x0, 0x9}}, &(0x7f0000000080)='syzkaller\x00', 0x5, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @sched_cls, 0xffffffffffffffff, 0x8, &(0x7f0000000000)={0x4}, 0x8, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet_sctp6_SCTP_SOCKOPT_BINDX_ADD(0xffffffffffffffff, 0x84, 0x64, &(0x7f0000000300)=[@in={0x2, 0x4e23, @dev={0xac, 0x14, 0x14, 0x19}}, @in={0x2, 0x4e20, @initdev={0xac, 0x1e, 0x0, 0x0}}, @in={0x2, 0x4e22, @multicast1}, @in={0x2, 0x4e20, @remote}], 0x40) socket$inet6_udp(0xa, 0x2, 0x0) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000000)=@base={0x12, 0xb, 0x8, 0x22, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, 0x0, 0x0) syz_open_dev$tty20(0xc, 0x4, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000200)=0x3) sched_setaffinity(0x0, 0x8, &(0x7f0000000680)=0x400000bce) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x140, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r2, &(0x7f0000000100)={0x3, 0x0, &(0x7f0000000000)={&(0x7f0000000500)=ANY=[@ANYBLOB="020300020c00000000000000000000000200080008000000d700000000000000030006003c00000002004e20ac141400000000000000000002000100000000000000090000000080030005000000000002"], 0x60}, 0x1, 0x7}, 0x0) r3 = bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0x4, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="1802000000020000000000000000000085"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x3, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r4 = socket$nl_rdma(0x10, 0x3, 0x14) sendmsg$RDMA_NLDEV_CMD_RES_GET(r4, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000180)=ANY=[@ANYBLOB="50000000091405002cbd7000fbdbdf25080001"], 0x50}, 0x1, 0x0, 0x0, 0x440008c0}, 0x4804) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r3, 0x0, 0xe, 0x0, &(0x7f0000000900)="e02742e8680d85ff9782762f0800", 0x0, 0x1302, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) setsockopt$inet_sctp_SCTP_EVENTS(0xffffffffffffffff, 0x84, 0xb, 0x0, 0x0) bpf$MAP_UPDATE_ELEM(0x2, &(0x7f0000000340)={r0, &(0x7f0000000240), &(0x7f0000000180)=@tcp}, 0x20) bpf$MAP_UPDATE_ELEM(0x2, &(0x7f0000000300)={r0, &(0x7f0000000440), &(0x7f0000000380)=@udp, 0x1}, 0x20) 1m35.509777559s ago: executing program 33 (id=1384): bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x3, 0x4, &(0x7f0000000040)=@framed={{0xffffffb4, 0x5, 0x0, 0x0, 0x0, 0x61, 0x10, 0xa0}, [@ldst={0x3, 0x0, 0x3, 0x1c10a1, 0x0, 0x48}], {0x95, 0x0, 0x9}}, &(0x7f0000000080)='syzkaller\x00', 0x5, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @sched_cls, 0xffffffffffffffff, 0x8, &(0x7f0000000000)={0x4}, 0x8, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet_sctp6_SCTP_SOCKOPT_BINDX_ADD(0xffffffffffffffff, 0x84, 0x64, &(0x7f0000000300)=[@in={0x2, 0x4e23, @dev={0xac, 0x14, 0x14, 0x19}}, @in={0x2, 0x4e20, @initdev={0xac, 0x1e, 0x0, 0x0}}, @in={0x2, 0x4e22, @multicast1}, @in={0x2, 0x4e20, @remote}], 0x40) socket$inet6_udp(0xa, 0x2, 0x0) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000000)=@base={0x12, 0xb, 0x8, 0x22, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, 0x0, 0x0) syz_open_dev$tty20(0xc, 0x4, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000200)=0x3) sched_setaffinity(0x0, 0x8, &(0x7f0000000680)=0x400000bce) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x140, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r2, &(0x7f0000000100)={0x3, 0x0, &(0x7f0000000000)={&(0x7f0000000500)=ANY=[@ANYBLOB="020300020c00000000000000000000000200080008000000d700000000000000030006003c00000002004e20ac141400000000000000000002000100000000000000090000000080030005000000000002"], 0x60}, 0x1, 0x7}, 0x0) r3 = bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0x4, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="1802000000020000000000000000000085"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x3, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r4 = socket$nl_rdma(0x10, 0x3, 0x14) sendmsg$RDMA_NLDEV_CMD_RES_GET(r4, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000100)={&(0x7f0000000180)=ANY=[@ANYBLOB="50000000091405002cbd7000fbdbdf25080001"], 0x50}, 0x1, 0x0, 0x0, 0x440008c0}, 0x4804) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r3, 0x0, 0xe, 0x0, &(0x7f0000000900)="e02742e8680d85ff9782762f0800", 0x0, 0x1302, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) setsockopt$inet_sctp_SCTP_EVENTS(0xffffffffffffffff, 0x84, 0xb, 0x0, 0x0) bpf$MAP_UPDATE_ELEM(0x2, &(0x7f0000000340)={r0, &(0x7f0000000240), &(0x7f0000000180)=@tcp}, 0x20) bpf$MAP_UPDATE_ELEM(0x2, &(0x7f0000000300)={r0, &(0x7f0000000440), &(0x7f0000000380)=@udp, 0x1}, 0x20) 57.861651593s ago: executing program 0 (id=1483): r0 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000001c0)='memory.events\x00', 0x275a, 0x0) write$cgroup_subtree(r0, &(0x7f0000000100)=ANY=[], 0x32600) mmap(&(0x7f0000000000/0x3000)=nil, 0x3000, 0x2000001, 0x12, r0, 0x0) r1 = socket(0xa, 0x80805, 0x0) setsockopt$inet_sctp6_SCTP_PEER_ADDR_THLDS(r1, 0x84, 0x25, &(0x7f00000000c0)={0x0, @in={{0x2, 0x4e1b, @broadcast}}, 0xfff9, 0x4}, 0x90) 56.254452558s ago: executing program 0 (id=1485): syz_open_dev$media(&(0x7f0000000040), 0x4c6c, 0x200) io_uring_setup(0x177d, &(0x7f00000002c0)={0x0, 0x698c, 0x40, 0x2, 0xfffffffe}) r0 = socket$can_bcm(0x1d, 0x2, 0x2) connect$can_bcm(r0, &(0x7f00000000c0), 0x10) r1 = syz_open_dev$sg(&(0x7f00000000c0), 0x0, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) socket$nl_generic(0x10, 0x3, 0x10) sched_setscheduler(0x0, 0x2, &(0x7f0000000200)=0x7) bpf$MAP_CREATE(0x0, &(0x7f0000000280)=ANY=[], 0x50) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f0000000380)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) socket(0x27, 0x3, 0x80000000) ioctl$SG_IO(r1, 0x2285, &(0x7f0000000140)={0x0, 0xfffffffc, 0x0, 0x8, @buffer={0x0, 0x7a, &(0x7f0000000480)=""/122}, 0x0, 0x0, 0xfffffffb, 0x1c4ba80ff697ec1, 0x3, 0x0}) sendmsg$NL80211_CMD_FRAME(0xffffffffffffffff, 0x0, 0x0) sendmsg$can_bcm(r0, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000200)=ANY=[@ANYBLOB], 0x80}}, 0x0) r4 = socket(0x10, 0x803, 0x0) sendmsg$nl_route(r4, &(0x7f0000000040)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x4008000}, 0x0) sendmmsg$inet(r0, &(0x7f0000001b00), 0x0, 0x0) setsockopt$MRT6_ADD_MIF(0xffffffffffffffff, 0x29, 0xca, 0x0, 0x0) mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x5) 54.534406969s ago: executing program 0 (id=1489): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000280)=0x8) socket$nl_xfrm(0x10, 0x3, 0x6) openat$sndseq(0xffffffffffffff9c, &(0x7f0000000100), 0x300) openat$vmci(0xffffffffffffff9c, 0x0, 0x2, 0x0) setsockopt$TIPC_GROUP_JOIN(0xffffffffffffffff, 0x10f, 0x87, 0x0, 0x0) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={0x0, r0, 0x0, 0xffffffffffffffff}, 0x18) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, 0x0) r4 = openat$nullb(0xffffffffffffff9c, &(0x7f0000000040), 0x4000, 0x0) preadv2(r4, &(0x7f0000000080)=[{&(0x7f0000001200)=""/4096, 0xffe00}], 0x5, 0x0, 0x0, 0x1f) 53.083763722s ago: executing program 0 (id=1493): syz_emit_vhci(&(0x7f0000000ec0)=ANY=[@ANYBLOB="041c261c19110600c30a14ed3db9083c92149031a1dbb24ea329b303f51fe1d6d19ca633e434649958c63f4f9d01dbb55023b0b5473e30b509b7a949f9107b8aa2"], 0x8) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) bpf$BPF_BTF_LOAD(0x12, 0x0, 0x0) syz_open_procfs$userns(0xffffffffffffffff, &(0x7f0000000700)) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r3, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000300)=ANY=[@ANYBLOB="180000002400010300000000000000000100000004"], 0x18}, 0x1, 0x0, 0x0, 0x8001}, 0x4820) syz_genetlink_get_family_id$tipc(&(0x7f0000001780), r3) recvmmsg(r3, &(0x7f0000000540)=[{{0x0, 0x0, 0x0}, 0x101}, {{0x0, 0x0, &(0x7f0000000500)=[{&(0x7f0000001c40)=""/4096, 0x1000}, {&(0x7f0000000340)=""/196, 0xc4}], 0x2}, 0x7}, {{0x0, 0x0, 0x0}, 0x2}, {{0x0, 0x0, &(0x7f0000000240)=[{0x0}, {&(0x7f0000000440)=""/160, 0xa0}, {&(0x7f0000000100)=""/119, 0x77}, {&(0x7f00000018c0)=""/147, 0x93}, {0x0}], 0x5}, 0x80000000}], 0x4, 0x40008062, 0x0) 50.576162317s ago: executing program 0 (id=1501): bpf$MAP_CREATE(0x0, &(0x7f0000000000)=ANY=[@ANYBLOB, @ANYRES32=0x0, @ANYRES32, @ANYBLOB], 0x50) socket(0x1, 0x2, 0x0) prlimit64(0x0, 0xe, 0x0, 0x0) openat$btrfs_control(0xffffffffffffff9c, &(0x7f0000000040), 0x100, 0x0) socket$packet(0x11, 0x2, 0x300) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = openat$ttyS3(0xffffffffffffff9c, &(0x7f00000003c0), 0x8000, 0x0) ioctl$TCSBRKP(r2, 0x5425, 0x0) r3 = openat$ttyS3(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) gettid() timer_settime(0x0, 0x0, &(0x7f0000000280)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) ioctl$TCSETSW2(r3, 0x5408, &(0x7f0000000300)={0xff, 0x3eb, 0xfffffffe, 0x7fffffef, 0x0, "23f555d9adb42d4408020e90d1beaa82dc1ecf", 0x1002, 0xfffffffc}) sched_setaffinity(0x0, 0x8, &(0x7f0000000240)=0x400000bd1) read$msr(0xffffffffffffffff, &(0x7f0000019680)=""/102392, 0x18ff8) 39.684935792s ago: executing program 0 (id=1518): ioctl$BTRFS_IOC_ADD_DEV(0xffffffffffffffff, 0x5000940a, &(0x7f0000000100)={{}, "176914d2ab253215d746e4694d57dfa31a0abb28f4f3e94f8e778117e2fbd456d41e3fdc5404e9413897c73a82945c61fb5c26be446ae725b697cb11162ccd7876ba4fde227f063e7c01a59aba6ce813aaf5611c68381b0ccd406757d7b435d80bdafc62b3d81be88cdcb107313cc5d2803e9811c0f447804f3db53281770b2d3cd4f87acb36e69cb0a6abd417acd41cafb5f10c738e09cc2608fb257cde7c8230d6a930ecb83fed0ae2f646d89bc47f962c1960bde5daa84722bcf066ed893a3ab7d398b4958f07d97ce8b93b8ee0920276215a55298f70556e73e75d60851e23fd4ad54fa5b07b7bfa0669a41c9ae2cd6fedc2e8c60af48b087a1faf74e16a9f815879fe5830c960e6e5da21cb01060d775336a81a8465c3c0c46ddd37848aaf77d7b11d6939dd2c59914b04b99138da4ed3b31f064044422e65f2860be605f0782c2ad6597d1a8d8cd71d5f90e4a17296b832ffa4334616f359d54248a9544cac61019a31f9115fdd0717819edf241a9372ead1ad3370a9da7072a1df64bc772b007f77b078a4b2ea29906288c99b1d53beabd765bb9a09cf9d2156d37b9dda0b4dfb40d31cdc56dcd097b6e7634bfbaa3d7b50056d3b7f3b8d2bfd488e6c9fe599b201964b69fb12aa6815f8018b45839cd006ebe00d5e5a1cd6eaa4dc51c1ed104ccd9160e135250f4a1f12580eeaa47ccf375cda55a5f202759e1cd556281e5bc0ce2ecd31d74674ffe2e7acee85f8f58512eef0ad11bfa91e466361e62b1c8766021966834a2d211ce88f42e8f6fa2d1f375fb49d3e12a25bb76b7696e5b822a3286cbfa5e669b751220b223274bda0776463c5eb0605d7ef3beb22fb0b8768645831b90a8dfb5ca62d22ebc45e08d455f484818789e0f4e91355f4b4425a70c6eebbef6c087014f306fd415f199dea44ea5fd52e3c7efb40bd2f0040566c31e12bdea4389baf6a588d3ee726933b27b6335bdfe91cbd34a84cebc06f25f80df1546ceefa173143be67c21b0eaa37f759a648169aa7b0452be021263e5f3dfd6706ed8890b4092e3482bfc08b07b3fa83dad65d86e9314a8c299b9488e493d469887649e4389b38db10629c6c83427f19a5a9d714549336daed6c22e6a65891aa1ba2f6ca29f978e5ac26f6645d4d77dd90928abbf1be157e7d6eae65e640cf7dc5e7da2f97447c4677514e4406d27a0b6933604bae608867c50376c2b3cc379fcf942c25d2ebe0f8bb3df130735ebe117edc977dcb51683addb2ac9a3c36b9f2be2d62aee01a2cf8a3a58ecf02150e8fcd2e00319b6d639bfeed0331d846c7c09e677963bb149b5ad0a1d173d60e9f31865f25ba2bf485ada0379334d3f53dc2e82c6d3fc623d5b5462b10db0298e2df9f87dc98d488a3e49ecb7e923aaab66f091eedc985d141a7b3aabc43911ee9d5cdc1889160522a8507fe5c9a9654af3b57f7b2b462b9c901738de69033220e256ef5b1c920c6c635249fce3b521cf481b0f113d227fefc4cd3eff7676a42289895fcb0542445cf63898878b8516d99446ef073c0e100093491d67c9809621006d9a03d80229ab91a634da87763619349393764379123606b4e72f2fbbaa9524a8dbf413de47b09265b1d231d4dfac5c12be460e1aaec6e50ca1f9aa3956955f15173cba0c08376e4641a3b738725b936fc8cd4e69a53bf86a6212077ef78bd2b2363537f699204d746f39ddcfb3e73f763406ab2b6889bb2cf8cfbf23ca84b314669b4f61fbb0de90a3be05335735ed19b8ef4e408e87baae2df2b972f24efa1cedf4d2a478111fed7b4ea12b0c30015b472fa2340cbaab8c3ef25f0d6be0be29736e0cf72976115ed33fc0c88411363915cefc9fa63852ef83fae797349759bcac68cba836d2adc6dfa2d57a467aa2f851d8c645e537a52224a137f6c4cf1741bcc765cf22c8d32d0255f602bdecb987d2384761b5a75ca7cffba2cb9e37b38f3104cb8cbc8fe4ed7705998544b536dec838a6a365d61b64d5281816ac4d85653b5a051a0c06becbe788581e464e71ad92ca362e43ccaee36b35f4146023023695cd7834723ba858a1de4d34426188cc05088256b498abf143723103bb950f2d4fabd35041ec278647b263728f69a0a5fa81795114cb4b18e990ae26943032c009bc08f526c837a97e61103def6e48e084743083fe3dbe2a0a927c0214ff58774d92d2518c6784bef5623f8e51380f30f0476a7f3484ca841fe0efea46b20b2eb6ef5c4529e4823fa77d1e8242ab87fb9b88f118bc415de872a3ebf768d3d77f10eafedb689d881517fe4aad41b87496bce80d915bb2d00bfb6b693833a033a8d2feda53ce290996a4b3b0c48ad642b2a06e374b7c714d13dcfd7c3db7de3e86a9dd8afb006c0eb3ec50ad3ef04084746c6758152aaf4fcc23a108fe4f46bc1bb17acc5fc9e562d3bdf2bc2a2d94c6a5acd9469a6a88f08f77c199e7c9671a54c028e6da0756fe6dc3854700b017a7bd734dc6822736f8c98ff1ebba17de7ec7d2a49d818873119cbc90d9208227affb9d5825be311f22a9bb85d017c9b2208f15bc7ac9a43ba22d53d8622ff954659c7de8ce3adb37847d7eb495fa13045c75dc4fa9562013157e321514472033dbb41df53feaccd482b03260f000d13cb875f07e2d7929cc3ed92713cee8277a3f1eaeb31efb860419c70766fbb68dffd1e804c9df37077d11b34bbc23ed4969d95977df8e708c11188d818c4ae56be482ef1b6c166e1e1a482cc6a277c2b85ad6906f60136032a58e3355245761fe1782414bd2267addfddc522219b3c6eb08ce8e43f8dc81f7169d32cf50be4a51e123f7ba7865f31a5f6677851156dead0045d29d66cc5ca022bbd385eb9bf35e357cd3178867d288d5f2d041e8002208998c118208d2d15e27567cc2a0b53953945e35c9158ca7e9d967c487f8ba2279427e2597a8132f52502ce5af94ec2dc4f871b5384139101702cddc3fd2271553b3aa57074590be216b2c0f1ee04ba88752f3d57016fa56a3047e0111529edf7f2a1d4cea21022ba6e7f6496b9315e3d78fe17ca17104ab630ac30f3946f54cfe9d20d23f6f3913bbd1f131943ba66aaf54988048c414a8651e50bffaa01e9d80f3e02e681c84c2bf7bf2bac0a299e0969fd9e77b5e3b7bfdbaca9621afc1991a72ae4f295973823dbe09d7bd8b41e7771ea1a17d1e5caabb00bd31f670254920a493c465e1b3d27467633365015f0ebceb96efa01861dcc8aed6a834232a9c33e2b9e94a6fad9271d89216815ad65f78c4a53d8c5e689cc6b10b147f7edae2de1a3a0b1f1faff720ea68ef9611e0838993a73e5e8e722a8650bdf07ae6a59c356cb5f4f30ed360470fcc5dde1b9c4ee3d27b7d0b94d7293132f7e8afe800cdc0275e813d95c52b75c5be3986f16a68819fb9330954eaa65749055a21cdc31f384d1c5f557fabefe2e77831b3cf3108415b12fd11d8c56926c1503346a882d6ae7b18a68578aee18cf7ce9310eab0ffda4969d0ac9585ae9efe4519de8f8ac15ad5ae789a9a59c1800781d20d1d565f88fc6aa30908808aff4f615593e1789b51407829710b9ee8cbc38e4ece4165813db383af307c5fd1ecbc8439d5ecc41769837bf64fc378947246e23bcc8b9528a3c623f5cb70da8b904e2ab4304521b1583742f93668d06fb353f3ca752dc93cc3f211e4738512ca469751fdf0ecf09d83cf6634a51adb224d323433ec06e9f3d1b24fcd8d6ad16c3649e01e35de4da4d87fe40d85ee76255087bfca99551154522e6d27a6ba4dbf04dd9a36324113e3aaffc540db1c844cf6843ea4ef0deb8817b9f244a09e8fc2e2a0c3b813ead494cbfbb21a42a296e6d442d06f1392410a39924088cd7fdf51f60b08dfe5bfca2019f7865401aeb13c969537b0bce47352413c425ff9af35bccc4316bb18f25a54fcb9de9a02421c3c5cf070f5813a5c17efe9d0b0ed95b3f3f71c8388eeecdef6751de1fbcbb54f1f5def7744dc7fcd6aa7437af7548b4f764f4ced03db9e14bf9b52055d4f3ef318499a15e84f823c98dff9e8c00783038b607095ea4a9a76f9d157c677d637578721b9cac6ff5ffbbd791aaf164d06f793c123da686706a32de69bab8a3d2afd5334c85071791c2db6698dbd705bfe8b3ce65bac2f496437ef7e9c298c3746b16e996dcd205822d49d77523e13cf5d370aadb474a99b94aa20f4cdbef553740ed6d2bf0e91c3a039c8674778cdaf29dbd829dc2b70471460113198237e2e92ab4517a4448fd140184bcfc32a8fb8ec550885abef597e7003abaf5d9ba7dfa59f28a44474da7a49faabb00fb6e062c7ab430dad23c7ae1410fa82f89056299c7740ebb5bfa4739fdca93feeee9e915163ee0d92f945d45731283055bc0591ae5ccf7dd11eea2131fdadabf5f51e65cfc9f257aaffa9d9b81d8dd9582359dba66bcf4eeecf642bb02ba4ad5506f6f436194443a5e3a0a3b3675530f510fee9c59b79eab35fa6e40c2f56e41a81670b17b69d916f8c90b69acd85fdbc76e3d93c5e3e90ea26115d0290fbe18080ad114a0107f5fb6bbe0d48b0686ced86e33eaa7f744cd1e850b075988be3349b3c6024d03510b2dd3470115512485b44feac154f2c6fd996b4c56878b24faebfca386c51b012b1ea86d0e523c34b9514059c3d395b8cb450de676a081b6591a23c465f6871d967fc98b55eeec697622a099309be7f85de0c3759ef1e4a9cd3715dd5f8ee7d4be49595543dcfe690b632e03d428e0a734543b63a47b9726472a5b5b4d75b1912948c27ec7b86fa578a800750720c16e2d8a070e435cffd77ba0910ff9faa62ebd267ae410aa6a0b29f50c2bc43456733cafac010711e0e98abec657a293beab6d7b72b34f8bbbaa8f967d0a5fe2ff027b757cc12f323ad7fd67c8e76ecb7bebf36c470bbc40c6253a80856e478d132c1c0b25b1df90629830bf3d3fa364e40a8173a5f5763a37f178ecec8576d78150d71344640add7be9ff5dba0ed275235880c08e0290d57f75e793af700f9daeb2ddfd242a9b582ab1589a8e362c347d700016dec63118afce91496f5b045363b30d7f9c048ff17460e002fd9237ed1d85bb14e535bba005fd2b051aff0814e0611907466e57c898fb9cb45ebdc825b13a662aec2364df358dff02a755b43f00f6d976f0671e727370a1e6af2df0bc509c416905e85052052f6081032ad66d096289b76eb4e2da3e68fa12de224202152fa3d00cf2741995e6454b17e13d6e8b9cbc5b1d85d229667b0ae07cd906ff0779b2761217430710cf593305834e2ac069d7e9af020d768b9c75aaf0c9cfdcd14e8b561561e755e372e93faeda995a038f3f7ce1e5b86ba8789a8f5c9d01dfb19848a01fad11e23c57b16e9a4dd3b65f31fae1d55f2ba093987df164c311201d0e6899def8b6a1def88ac7ce79dd24784a8e8621e61fbad6e218440f71a907a46fe0e0c69e19e015fa1430ecbfe729b31b1e27613bbd47c400e927a8a1c423150b80c17555c193fc514cdc0d22915dde7c7f731062c3e6958fa722c60d4b3c5c9676a20245550adcea924180e0c8d8b4ad7d04dfa4da34fcd267765e63b9bd42c8abe20cb191e04449cb2916b34b22aa4984de34b16d0c3fdd10a1a66457ef00b4e47fdae53e42cfde240a5684fac86e3404b985557443de8b70eb42fe7df5597d9052cdc0ad7781b49282d5b4fe254f0dfd37581c73c83f6e30b097506d5805700bb12f31707315370f179abc7f00e12d0dc5624ee04cba3abe795509184fa1"}) r0 = openat$ttyS3(0xffffffffffffff9c, 0x0, 0x2, 0x0) ioctl$TCSETA(r0, 0x5406, &(0x7f0000000080)={0xa2, 0xcff, 0x8, 0x7, 0x1, "4462811f5249ceec"}) prlimit64(0x0, 0xe, 0x0, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$inet_tcp(0x2, 0x1, 0x0) ioctl$sock_inet_SIOCSIFADDR(r2, 0x8916, &(0x7f0000000000)={'veth1_to_team\x00', {0x2, 0x4e24, @loopback=0x7f000000}}) ioctl$sock_inet_SIOCSIFADDR(r2, 0x8916, &(0x7f0000000180)={'lo\x00', {0x2, 0x4e23, @multicast2}}) write$uinput_user_dev(0xffffffffffffffff, 0x0, 0x0) r3 = socket$inet6_icmp_raw(0xa, 0x3, 0x3a) setsockopt$inet6_IPV6_HOPOPTS(r3, 0x29, 0x36, 0x0, 0x8) r4 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp6_SCTP_EVENTS(r4, 0x84, 0xb, &(0x7f0000000180)={0x4, 0xfd, 0x1, 0x6, 0x0, 0xfd, 0x0, 0x0, 0x0, 0x0, 0x0, 0x58, 0x0, 0x96}, 0xe) sendto$inet6(r4, 0x0, 0x0, 0x0, &(0x7f0000000000)={0xa, 0x0, 0x0, @private1}, 0x1c) shutdown(r4, 0x1) read(r4, &(0x7f0000000340)=""/165, 0xa5) ioctl$SNDRV_SEQ_IOCTL_GET_QUEUE_INFO(0xffffffffffffffff, 0xc08c5334, &(0x7f0000001100)={0x8, 0xc, 0x0, 'queue0\x00', 0x9}) r5 = fsopen(&(0x7f0000000100)='ecryptfs\x00', 0x0) close_range(r5, 0xffffffffffffffff, 0x0) mount(&(0x7f0000000100)=@md0, &(0x7f0000000040)='.\x00', &(0x7f0000000000)='virtiofs\x00', 0x3010005, 0x0) r6 = socket$inet_udp(0x2, 0x2, 0x0) setsockopt$inet_int(r6, 0x0, 0x21, &(0x7f0000000000)=0xffffffff, 0x4) syz_genetlink_get_family_id$nl80211(&(0x7f0000000280), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(0xffffffffffffffff, 0x8933, &(0x7f00000002c0)={'wlan0\x00'}) sendmsg$NL80211_CMD_FRAME(0xffffffffffffffff, 0x0, 0x100000c4) 24.463905879s ago: executing program 34 (id=1518): ioctl$BTRFS_IOC_ADD_DEV(0xffffffffffffffff, 0x5000940a, &(0x7f0000000100)={{}, "176914d2ab253215d746e4694d57dfa31a0abb28f4f3e94f8e778117e2fbd456d41e3fdc5404e9413897c73a82945c61fb5c26be446ae725b697cb11162ccd7876ba4fde227f063e7c01a59aba6ce813aaf5611c68381b0ccd406757d7b435d80bdafc62b3d81be88cdcb107313cc5d2803e9811c0f447804f3db53281770b2d3cd4f87acb36e69cb0a6abd417acd41cafb5f10c738e09cc2608fb257cde7c8230d6a930ecb83fed0ae2f646d89bc47f962c1960bde5daa84722bcf066ed893a3ab7d398b4958f07d97ce8b93b8ee0920276215a55298f70556e73e75d60851e23fd4ad54fa5b07b7bfa0669a41c9ae2cd6fedc2e8c60af48b087a1faf74e16a9f815879fe5830c960e6e5da21cb01060d775336a81a8465c3c0c46ddd37848aaf77d7b11d6939dd2c59914b04b99138da4ed3b31f064044422e65f2860be605f0782c2ad6597d1a8d8cd71d5f90e4a17296b832ffa4334616f359d54248a9544cac61019a31f9115fdd0717819edf241a9372ead1ad3370a9da7072a1df64bc772b007f77b078a4b2ea29906288c99b1d53beabd765bb9a09cf9d2156d37b9dda0b4dfb40d31cdc56dcd097b6e7634bfbaa3d7b50056d3b7f3b8d2bfd488e6c9fe599b201964b69fb12aa6815f8018b45839cd006ebe00d5e5a1cd6eaa4dc51c1ed104ccd9160e135250f4a1f12580eeaa47ccf375cda55a5f202759e1cd556281e5bc0ce2ecd31d74674ffe2e7acee85f8f58512eef0ad11bfa91e466361e62b1c8766021966834a2d211ce88f42e8f6fa2d1f375fb49d3e12a25bb76b7696e5b822a3286cbfa5e669b751220b223274bda0776463c5eb0605d7ef3beb22fb0b8768645831b90a8dfb5ca62d22ebc45e08d455f484818789e0f4e91355f4b4425a70c6eebbef6c087014f306fd415f199dea44ea5fd52e3c7efb40bd2f0040566c31e12bdea4389baf6a588d3ee726933b27b6335bdfe91cbd34a84cebc06f25f80df1546ceefa173143be67c21b0eaa37f759a648169aa7b0452be021263e5f3dfd6706ed8890b4092e3482bfc08b07b3fa83dad65d86e9314a8c299b9488e493d469887649e4389b38db10629c6c83427f19a5a9d714549336daed6c22e6a65891aa1ba2f6ca29f978e5ac26f6645d4d77dd90928abbf1be157e7d6eae65e640cf7dc5e7da2f97447c4677514e4406d27a0b6933604bae608867c50376c2b3cc379fcf942c25d2ebe0f8bb3df130735ebe117edc977dcb51683addb2ac9a3c36b9f2be2d62aee01a2cf8a3a58ecf02150e8fcd2e00319b6d639bfeed0331d846c7c09e677963bb149b5ad0a1d173d60e9f31865f25ba2bf485ada0379334d3f53dc2e82c6d3fc623d5b5462b10db0298e2df9f87dc98d488a3e49ecb7e923aaab66f091eedc985d141a7b3aabc43911ee9d5cdc1889160522a8507fe5c9a9654af3b57f7b2b462b9c901738de69033220e256ef5b1c920c6c635249fce3b521cf481b0f113d227fefc4cd3eff7676a42289895fcb0542445cf63898878b8516d99446ef073c0e100093491d67c9809621006d9a03d80229ab91a634da87763619349393764379123606b4e72f2fbbaa9524a8dbf413de47b09265b1d231d4dfac5c12be460e1aaec6e50ca1f9aa3956955f15173cba0c08376e4641a3b738725b936fc8cd4e69a53bf86a6212077ef78bd2b2363537f699204d746f39ddcfb3e73f763406ab2b6889bb2cf8cfbf23ca84b314669b4f61fbb0de90a3be05335735ed19b8ef4e408e87baae2df2b972f24efa1cedf4d2a478111fed7b4ea12b0c30015b472fa2340cbaab8c3ef25f0d6be0be29736e0cf72976115ed33fc0c88411363915cefc9fa63852ef83fae797349759bcac68cba836d2adc6dfa2d57a467aa2f851d8c645e537a52224a137f6c4cf1741bcc765cf22c8d32d0255f602bdecb987d2384761b5a75ca7cffba2cb9e37b38f3104cb8cbc8fe4ed7705998544b536dec838a6a365d61b64d5281816ac4d85653b5a051a0c06becbe788581e464e71ad92ca362e43ccaee36b35f4146023023695cd7834723ba858a1de4d34426188cc05088256b498abf143723103bb950f2d4fabd35041ec278647b263728f69a0a5fa81795114cb4b18e990ae26943032c009bc08f526c837a97e61103def6e48e084743083fe3dbe2a0a927c0214ff58774d92d2518c6784bef5623f8e51380f30f0476a7f3484ca841fe0efea46b20b2eb6ef5c4529e4823fa77d1e8242ab87fb9b88f118bc415de872a3ebf768d3d77f10eafedb689d881517fe4aad41b87496bce80d915bb2d00bfb6b693833a033a8d2feda53ce290996a4b3b0c48ad642b2a06e374b7c714d13dcfd7c3db7de3e86a9dd8afb006c0eb3ec50ad3ef04084746c6758152aaf4fcc23a108fe4f46bc1bb17acc5fc9e562d3bdf2bc2a2d94c6a5acd9469a6a88f08f77c199e7c9671a54c028e6da0756fe6dc3854700b017a7bd734dc6822736f8c98ff1ebba17de7ec7d2a49d818873119cbc90d9208227affb9d5825be311f22a9bb85d017c9b2208f15bc7ac9a43ba22d53d8622ff954659c7de8ce3adb37847d7eb495fa13045c75dc4fa9562013157e321514472033dbb41df53feaccd482b03260f000d13cb875f07e2d7929cc3ed92713cee8277a3f1eaeb31efb860419c70766fbb68dffd1e804c9df37077d11b34bbc23ed4969d95977df8e708c11188d818c4ae56be482ef1b6c166e1e1a482cc6a277c2b85ad6906f60136032a58e3355245761fe1782414bd2267addfddc522219b3c6eb08ce8e43f8dc81f7169d32cf50be4a51e123f7ba7865f31a5f6677851156dead0045d29d66cc5ca022bbd385eb9bf35e357cd3178867d288d5f2d041e8002208998c118208d2d15e27567cc2a0b53953945e35c9158ca7e9d967c487f8ba2279427e2597a8132f52502ce5af94ec2dc4f871b5384139101702cddc3fd2271553b3aa57074590be216b2c0f1ee04ba88752f3d57016fa56a3047e0111529edf7f2a1d4cea21022ba6e7f6496b9315e3d78fe17ca17104ab630ac30f3946f54cfe9d20d23f6f3913bbd1f131943ba66aaf54988048c414a8651e50bffaa01e9d80f3e02e681c84c2bf7bf2bac0a299e0969fd9e77b5e3b7bfdbaca9621afc1991a72ae4f295973823dbe09d7bd8b41e7771ea1a17d1e5caabb00bd31f670254920a493c465e1b3d27467633365015f0ebceb96efa01861dcc8aed6a834232a9c33e2b9e94a6fad9271d89216815ad65f78c4a53d8c5e689cc6b10b147f7edae2de1a3a0b1f1faff720ea68ef9611e0838993a73e5e8e722a8650bdf07ae6a59c356cb5f4f30ed360470fcc5dde1b9c4ee3d27b7d0b94d7293132f7e8afe800cdc0275e813d95c52b75c5be3986f16a68819fb9330954eaa65749055a21cdc31f384d1c5f557fabefe2e77831b3cf3108415b12fd11d8c56926c1503346a882d6ae7b18a68578aee18cf7ce9310eab0ffda4969d0ac9585ae9efe4519de8f8ac15ad5ae789a9a59c1800781d20d1d565f88fc6aa30908808aff4f615593e1789b51407829710b9ee8cbc38e4ece4165813db383af307c5fd1ecbc8439d5ecc41769837bf64fc378947246e23bcc8b9528a3c623f5cb70da8b904e2ab4304521b1583742f93668d06fb353f3ca752dc93cc3f211e4738512ca469751fdf0ecf09d83cf6634a51adb224d323433ec06e9f3d1b24fcd8d6ad16c3649e01e35de4da4d87fe40d85ee76255087bfca99551154522e6d27a6ba4dbf04dd9a36324113e3aaffc540db1c844cf6843ea4ef0deb8817b9f244a09e8fc2e2a0c3b813ead494cbfbb21a42a296e6d442d06f1392410a39924088cd7fdf51f60b08dfe5bfca2019f7865401aeb13c969537b0bce47352413c425ff9af35bccc4316bb18f25a54fcb9de9a02421c3c5cf070f5813a5c17efe9d0b0ed95b3f3f71c8388eeecdef6751de1fbcbb54f1f5def7744dc7fcd6aa7437af7548b4f764f4ced03db9e14bf9b52055d4f3ef318499a15e84f823c98dff9e8c00783038b607095ea4a9a76f9d157c677d637578721b9cac6ff5ffbbd791aaf164d06f793c123da686706a32de69bab8a3d2afd5334c85071791c2db6698dbd705bfe8b3ce65bac2f496437ef7e9c298c3746b16e996dcd205822d49d77523e13cf5d370aadb474a99b94aa20f4cdbef553740ed6d2bf0e91c3a039c8674778cdaf29dbd829dc2b70471460113198237e2e92ab4517a4448fd140184bcfc32a8fb8ec550885abef597e7003abaf5d9ba7dfa59f28a44474da7a49faabb00fb6e062c7ab430dad23c7ae1410fa82f89056299c7740ebb5bfa4739fdca93feeee9e915163ee0d92f945d45731283055bc0591ae5ccf7dd11eea2131fdadabf5f51e65cfc9f257aaffa9d9b81d8dd9582359dba66bcf4eeecf642bb02ba4ad5506f6f436194443a5e3a0a3b3675530f510fee9c59b79eab35fa6e40c2f56e41a81670b17b69d916f8c90b69acd85fdbc76e3d93c5e3e90ea26115d0290fbe18080ad114a0107f5fb6bbe0d48b0686ced86e33eaa7f744cd1e850b075988be3349b3c6024d03510b2dd3470115512485b44feac154f2c6fd996b4c56878b24faebfca386c51b012b1ea86d0e523c34b9514059c3d395b8cb450de676a081b6591a23c465f6871d967fc98b55eeec697622a099309be7f85de0c3759ef1e4a9cd3715dd5f8ee7d4be49595543dcfe690b632e03d428e0a734543b63a47b9726472a5b5b4d75b1912948c27ec7b86fa578a800750720c16e2d8a070e435cffd77ba0910ff9faa62ebd267ae410aa6a0b29f50c2bc43456733cafac010711e0e98abec657a293beab6d7b72b34f8bbbaa8f967d0a5fe2ff027b757cc12f323ad7fd67c8e76ecb7bebf36c470bbc40c6253a80856e478d132c1c0b25b1df90629830bf3d3fa364e40a8173a5f5763a37f178ecec8576d78150d71344640add7be9ff5dba0ed275235880c08e0290d57f75e793af700f9daeb2ddfd242a9b582ab1589a8e362c347d700016dec63118afce91496f5b045363b30d7f9c048ff17460e002fd9237ed1d85bb14e535bba005fd2b051aff0814e0611907466e57c898fb9cb45ebdc825b13a662aec2364df358dff02a755b43f00f6d976f0671e727370a1e6af2df0bc509c416905e85052052f6081032ad66d096289b76eb4e2da3e68fa12de224202152fa3d00cf2741995e6454b17e13d6e8b9cbc5b1d85d229667b0ae07cd906ff0779b2761217430710cf593305834e2ac069d7e9af020d768b9c75aaf0c9cfdcd14e8b561561e755e372e93faeda995a038f3f7ce1e5b86ba8789a8f5c9d01dfb19848a01fad11e23c57b16e9a4dd3b65f31fae1d55f2ba093987df164c311201d0e6899def8b6a1def88ac7ce79dd24784a8e8621e61fbad6e218440f71a907a46fe0e0c69e19e015fa1430ecbfe729b31b1e27613bbd47c400e927a8a1c423150b80c17555c193fc514cdc0d22915dde7c7f731062c3e6958fa722c60d4b3c5c9676a20245550adcea924180e0c8d8b4ad7d04dfa4da34fcd267765e63b9bd42c8abe20cb191e04449cb2916b34b22aa4984de34b16d0c3fdd10a1a66457ef00b4e47fdae53e42cfde240a5684fac86e3404b985557443de8b70eb42fe7df5597d9052cdc0ad7781b49282d5b4fe254f0dfd37581c73c83f6e30b097506d5805700bb12f31707315370f179abc7f00e12d0dc5624ee04cba3abe795509184fa1"}) r0 = openat$ttyS3(0xffffffffffffff9c, 0x0, 0x2, 0x0) ioctl$TCSETA(r0, 0x5406, &(0x7f0000000080)={0xa2, 0xcff, 0x8, 0x7, 0x1, "4462811f5249ceec"}) prlimit64(0x0, 0xe, 0x0, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$inet_tcp(0x2, 0x1, 0x0) ioctl$sock_inet_SIOCSIFADDR(r2, 0x8916, &(0x7f0000000000)={'veth1_to_team\x00', {0x2, 0x4e24, @loopback=0x7f000000}}) ioctl$sock_inet_SIOCSIFADDR(r2, 0x8916, &(0x7f0000000180)={'lo\x00', {0x2, 0x4e23, @multicast2}}) write$uinput_user_dev(0xffffffffffffffff, 0x0, 0x0) r3 = socket$inet6_icmp_raw(0xa, 0x3, 0x3a) setsockopt$inet6_IPV6_HOPOPTS(r3, 0x29, 0x36, 0x0, 0x8) r4 = socket$inet6_sctp(0xa, 0x1, 0x84) setsockopt$inet_sctp6_SCTP_EVENTS(r4, 0x84, 0xb, &(0x7f0000000180)={0x4, 0xfd, 0x1, 0x6, 0x0, 0xfd, 0x0, 0x0, 0x0, 0x0, 0x0, 0x58, 0x0, 0x96}, 0xe) sendto$inet6(r4, 0x0, 0x0, 0x0, &(0x7f0000000000)={0xa, 0x0, 0x0, @private1}, 0x1c) shutdown(r4, 0x1) read(r4, &(0x7f0000000340)=""/165, 0xa5) ioctl$SNDRV_SEQ_IOCTL_GET_QUEUE_INFO(0xffffffffffffffff, 0xc08c5334, &(0x7f0000001100)={0x8, 0xc, 0x0, 'queue0\x00', 0x9}) r5 = fsopen(&(0x7f0000000100)='ecryptfs\x00', 0x0) close_range(r5, 0xffffffffffffffff, 0x0) mount(&(0x7f0000000100)=@md0, &(0x7f0000000040)='.\x00', &(0x7f0000000000)='virtiofs\x00', 0x3010005, 0x0) r6 = socket$inet_udp(0x2, 0x2, 0x0) setsockopt$inet_int(r6, 0x0, 0x21, &(0x7f0000000000)=0xffffffff, 0x4) syz_genetlink_get_family_id$nl80211(&(0x7f0000000280), 0xffffffffffffffff) ioctl$sock_SIOCGIFINDEX_80211(0xffffffffffffffff, 0x8933, &(0x7f00000002c0)={'wlan0\x00'}) sendmsg$NL80211_CMD_FRAME(0xffffffffffffffff, 0x0, 0x100000c4) 22.724452264s ago: executing program 6 (id=1541): r0 = syz_usb_connect$cdc_ncm(0x0, 0x72, &(0x7f00000000c0)=ANY=[@ANYBLOB="1201000002000040257d15a4400001040001090260004201000000090400000102090000052406000105240000000d240f01000004eaffffff1e0006031a00000804800200090581", @ANYBLOB="f7", @ANYRESDEC], 0x0) syz_open_dev$char_usb(0xc, 0xb4, 0x0) syz_usb_ep_write(r0, 0x81, 0x6, &(0x7f0000000080)="00012c615bc2") 20.179221895s ago: executing program 6 (id=1545): socket$inet6(0xa, 0x80002, 0x0) setsockopt$inet_sctp_SCTP_AUTO_ASCONF(0xffffffffffffffff, 0x84, 0x1e, 0x0, 0x0) socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$devlink(&(0x7f0000000140), 0xffffffffffffffff) r0 = openat$sysfs(0xffffffffffffff9c, &(0x7f00000000c0)='/sys/power/pm_test', 0x141a82, 0x0) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000180)={0x18, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="180000001800ff0f0000000000000000850000006d0000008500000008"], &(0x7f0000000080)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000540)={&(0x7f0000000080)='sched_switch\x00', r1}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0xa, 0xe1}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000640)=0x6) r2 = getpid() sched_setscheduler(r2, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r0, 0x0, 0x40884) r5 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$IPCTNL_MSG_CT_GET_CTRZERO(r5, 0x0, 0x0) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, 0x0, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) sendfile(r0, r0, &(0x7f0000000000)=0x7, 0x4) 17.87038573s ago: executing program 6 (id=1548): r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000040)={&(0x7f00000005c0)={{0x14}, [], {0x14}}, 0x28}}, 0x0) 16.610805639s ago: executing program 2 (id=1549): r0 = syz_open_dev$dri(&(0x7f00000000c0), 0x1ff, 0x0) ioctl$DRM_IOCTL_MODE_GETRESOURCES(r0, 0xc04064a0, &(0x7f00000003c0)={0x0, 0x0, &(0x7f0000000340)=[0x0], 0x0, 0x0, 0x0, 0x1}) ioctl$DRM_IOCTL_MODE_CREATE_LEASE(r0, 0xc01864c6, &(0x7f0000000040)={&(0x7f0000000640)=[r1, 0x0], 0x2, 0x0, 0x0, 0xffffffffffffffff}) ioctl$DRM_IOCTL_MODE_GETCONNECTOR(r0, 0xc05064a7, &(0x7f0000000500)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3000000}) ioctl$DRM_IOCTL_MODE_GETENCODER(r2, 0xc01464a6, &(0x7f0000000180)={r3}) 16.454118768s ago: executing program 6 (id=1550): syz_emit_vhci(&(0x7f0000000ec0)=ANY=[@ANYBLOB="041c261c19110600c30a14ed3db9083c92149031a1dbb24ea329b303f51fe1d6d19ca633e434649958c63f4f9d01dbb55023b0b5473e30b509b7a949f9107b8aa2"], 0x8) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) bpf$BPF_BTF_LOAD(0x12, 0x0, 0x0) syz_open_procfs$userns(0xffffffffffffffff, &(0x7f0000000700)) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r3, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000300)=ANY=[@ANYBLOB="18000000240001030000000000000000010000000400"], 0x18}, 0x1, 0x0, 0x0, 0x8001}, 0x4820) syz_genetlink_get_family_id$tipc(&(0x7f0000001780), r3) recvmmsg(r3, &(0x7f0000000540)=[{{0x0, 0x0, 0x0}, 0x101}, {{0x0, 0x0, &(0x7f0000000500)=[{&(0x7f0000001c40)=""/4096, 0x1000}, {&(0x7f0000000340)=""/196, 0xc4}], 0x2}, 0x7}, {{0x0, 0x0, 0x0}, 0x2}, {{0x0, 0x0, &(0x7f0000000240)=[{0x0}, {&(0x7f0000000440)=""/160, 0xa0}, {&(0x7f0000000100)=""/119, 0x77}, {&(0x7f00000018c0)=""/147, 0x93}, {0x0}], 0x5}, 0x80000000}], 0x4, 0x40008062, 0x0) 16.179933042s ago: executing program 2 (id=1552): io_uring_register$IORING_REGISTER_PERSONALITY(0xffffffffffffffff, 0x9, 0x0, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000100)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) r0 = getpgrp(0xffffffffffffffff) prctl$PR_SCHED_CORE(0x3e, 0x1, r0, 0x1, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) socket$inet6_mptcp(0xa, 0x1, 0x106) r2 = openat$vicodec0(0xffffffffffffff9c, &(0x7f0000000240), 0x2, 0x0) ioctl$VIDIOC_S_FMT(r2, 0xc0d05605, 0x0) r3 = syz_init_net_socket$bt_l2cap(0x1f, 0x3, 0x3) r4 = dup(r3) syz_emit_ethernet(0xe2f, &(0x7f0000001540)={@random="cebf901584bc", @random="6a177a00", @void, {@x25={0x805, {0x3, 0x6, 0xff, "3cc2cf9cf258fc60ac5471863cf8b24d9b27d4ca85c99d06f224f11d7b012645cb9e98a4fa8cd538193c47527256f8cd50b0ba8084979e2c835ff1b163c44dd8a66a5b8f4c550c94e434840efb1f51e7ca106bdb43dd9d7a2bebe70f8c773761f78485101c785ebfeacbb541c517818800d95d252717eb649cb32da44d2ab02230b3f5329e480a5a88a4733aca11daa8ae84507906dce585c1411a918580bec2dbe0ca0407387dd118772e70a3e068f975e92688393bda5f985507ddc9e7077e5f4cd0ac323d6d959f2633f7731c976f350535de4062cf334afc9182ffda77c5000552cafcd5fa1a84fd5e18e5dc04404a8f3d818c966819cb4a1ca4ad13c82410234172bb3d395814821a49b313a94d163e2fc5a4dfc657fb34ca9580c66ce81cc88a8e9a8847ddbaf527a88efe9b281192f33b9480e98b8d9b8829be6727d21996c581f950a881f64f55c82c23368884ac4f8a70dac647ad12485dc5685b1f8519ebcedeaa7c54615bce25ccd2aa9f47df03addc7f1505d1e8c62ca1f9fe05193f5cc58195c05e9d1511ead462de2e888b0bbe4e27167063c6f749094ac5c81c354cc91f9cb6eb35c7084e62849c8101f0b5bddca4244451236540dd86799d0d3da8cf1be1f0cfaf52d905649e942203b60a0e84760df492c0095abcd725eea03377382ea50a417626c7d4c9993830a7485622c0a4821a1dc72ce45624a4c4fc588d3013e4f7cda7a2c32785c06d3e4cf5249356c1bcd8ca2d8fdfd8fd6c898978f1fec18ebfb0ff1c0b790631d9053be15286f3d0346993b1c8df85599ab545bf9fa5caa3add99f729ac161d0794c36ea6908ab01fc14b752107295ff1d734a534842e36d3b729b1e99855577b6f6475ae371977cb16e7852784926f218753de083fe3ab2b82f42193b39839ac64eb6d3c0e15d1fc243bd8fc775ae213b8498e31b58145abcfaa5e8d5f2695b3290d888108fa6bc17e2d61cd695c69ae693058700d2363b630f0f07642a585e0e79766b62d0e606468d82ddf6263014c1c5d5f9e8a9568ed0959905fad36b9780d472f0ac7e14132bcb8290b84c54875c1411724d5d5b3d759b914b37d0c4be1e19ad23e1c76ced438f22af808c0f8d3fcc8b1ca157d1c4575cfffd2402fb706da18ebe56316090c10aac919f0b547ef6da0b8dac4f5ceeebb966f2c9adbb8999e44483402b3b32bc7924bc1648d52af5896f775c2446e5591096d19cc4863f4d33b17a18ec21a9c437a765b4194bc260d3bfd1e87ef9de5a6b63a0fb0748c21b2908301c187e243d45cbca42f9a0aa6ddfe47b55ba3105a1b8931357f498e5a9bf30e76d8b33daa1690dee459a5bc47ab7a9c457ef3a2211793da442a26770392d730835dc524c4135f8d5330623566427b9d330e465a765e4a393c8cb880e424950e0b836d06cff345c904f041d315f9d09beb9cc1bcafe61928adf1bd1f0085e04c7302a028081c7bef68c15563d5b2b5756f3fca95cbcf2e2fcb4e42ba4af4283962a26cddeb9e91c0857e1da215e0dd406f684d76bd23730746568a58dae9d2361b06cf3df08088093d61fd2604d963dd2b4540f3300631ce7e49c094268417e930bb3e502be243e25b174c2f2c8d6aba378da7ae159c353b2dfbb4a25c89bb51158dc4f2e48ed1c2b7f8060e27860e9a7d6e6bb2cfdddb7668ca4ca19f7a3ca4d8401bb2d19580ba485edf3b658f413782a50f86e4d3c88a7739b1212bac1128d36ee6ceb9089cbb6ee699580e5770df6076f8f0b7c834e330fb7a0eaa51bfb7ab48d0427ea22736a0877ecc392da2c6b38cd918c67a41c3282b85f50c137261a4e5f8832add57d691fa5b5b8840ee604996665668f91ce2220e57464b6d297b926da03efea3ecfd922e5f8ec69843c6c3f81b49e7452ef16dbc2785af5d1fd81840a98023754c8e9c1b9f001a1c01070bf0baa697a9954b8639adef079fbba1e99204253c223129c74f329480ff45e20ebdc783c5ebd226328ade52f93579502d4d96a3beb0654f3be33394000d3296260b4ca3ae8aedfe6d93b0af9c7bce42ad3111977a62199ceae61cec0a3661b2772cae7153eb029a7680b2d41e90a6e2b654bf9bda5f4a23cc1bf5d73e67992fa0b2fcdc656f32ac7bd362bb0a9eea8290e8693cc50474e912cb0610dc98a975134e693a5e07e35cb5fa15c9682c3c299f76ba732f6759361ccde7dd9086bfc7d0988829aabea79c00b8715efe5f7161be1ecb3a69b87670228443cd98c70a5c79e8c8168d38dd298a4abf33b35ba64f4a30feeb3d2d0e23f1af8f3d7f8fe8fb74da0d59763c9dfa70493aaf960a587409ac18c2c30388fe1ceb9d73a1cd052ad1b427dff45a51fc7819f98d88b928a8946b9bb31267ac5794403ce443d685e8b87ab443c731c7aba5c63c0e8de2335dacf5394d2426841b505ab9b578f048f987fe34519dac2097d6ab8a3370121fa27da58cca5397dd6db1c2bfdf51895ade606df2d5381f9a781f70be4250f9b8bead65a5e15b3721fa9481d19a31193967e0fc9b291a908adda35f7c958b193d81c52f014acfdeb22bbb85357b48a963bece9efdaf56f7e1c06fcdff0379a1af8326c7573122377a06829a007fb66f3ee1e8b70f72f2aeaba76b9c92ee1f588ea5a55a2b46c8b47f7da0f916e861561269dc1349c5658ee0265f87948b50f1e18de17d6d2836ce133ff4cba4b2f0746aa21a700281bbeff5bb0c6421e8e0db38a79881f32673e157e41ac798b015dc7ffc90afb572f831691a03cbc5dc3153beae3961fae7b913b053b744c6462a8ee94f4e679bd0e6b9721a550e49c15534a2328b9c136073ced5f7d719400b22b6041e50352942b625be1fe88015a914dad9882c0701b1859d5ed65b5314ce5f939feec9fa09447c49359f9e55216e060f5bd6990284158b343d75b3b03b76dbfccbb4ae63a05535c27938bc7e69440bff8c1a138e3ad80e912bbdec65a53d6b12d140362393bca064d3f5d9e5450b1e90e1cfda41e3d4876787be7261bd7f86c8cd91e40e84794eac113567b6b27f149d8fa1d08696792ccec50cf43755350200b9b226799707e6de6a13e8761a931271e618c0d5aa7c4a3250283f4021cabfeb37b2905098806f410ad22eca0b5c0bcc2bca2d9f8af2aff6656ab99309455c1a5f237836cb7124570e209ce1e46c507302e2fb672a6ed46fb78ef5e271fb8e6a6f73e6b36c17cac5bb5e01c096d8b45b5e9879ebe84bba627d52502564598f9ac391f2e04ad8f34d39049c8761a2b082e13cd403373d7b006495ea580aaa6e5ef8d3c4cd5411c1bbcc04214df3bb98eb9f395a2b3e03ed03302afb6c4dcacd66cdfc88165362e7a9194b2e9ab8062723c18eb5dc14eef3d26f7877bb8f861447f8c2cc757b0e7502353b0dff074888c44a82c0e549545800c7cccaad320b18785c4e40de35ed710e9f24daf33aded6b183e0797dbac94f60e4ecbde8e5c0f24153cecfd048ad1ae5d9bbc4d23e41133e80dd0cbba76134eecebbcb35b26ca21e25f7ed6754f071901cb4f25e1e6a474da83090e56ef23f478702ec41a4e4d0bb251d62fdf8d64eda2ab3f327db52c6b711f7f5d9e9dff922b9c615aa70bca53447ff483f6ee07d237c812e25f195ad3e38fcf3fdc803eca390f04962dd8c21a9c23f947fd41df6fd1ab99434196fef0081846fe83dd7d097a3a31d614926619cf9ff7e837df4299b1318ab1115629596eee9f389c7d8f0467f649e43690799b7028b78cf2081383961fdcda9198585702e91d5408af632b287f8fb4965d3355478e8f6614a7f26c139743b23e13dfa94926fdc7ba6348e9cbc7b8a8020a5e1b801ca040d3a5b2e2366ced1f2f40461e4013e00b3b4c014a2a45c2d7241b509e0c074eb9134e60d461436728da4d70a31c0068e73e071bf369d10ec5783206b00ffceaa37fd55d0a96b6f78f6d4b756b6d3e5e30d7a33089ef25a0414e28b3e0e69a2589e5a492103f4e89020f68c78c10e658ed3220ed6d29e3614277b5dbffc51b123cf6efc5afac43de23ddf2e0f348ccda6cedea88dae7c109c063f97ca4e847847dbfff8ad9be5a573a44a0d71c03573eb66cf3856a6fd733e0f6a950d5928e1ca4e62cb26394b1bebffe6298a8af3e68ea00cab819ccf5c45c84387e48e53e36f29624cb20eb6a946fef50ebed49dd3143465278256fc34e088eeaea4c8911a862fee8ddd97d7eb06328647d9a336b7a628fc3e2d8d9bee7a5189084c6ab6cda37bc239d259eda25b24cada795473816a34e58cf6d512ded3a498cd5f667000e4b46151704e6b7804272659e1fee1794c54f13cc6b58619586ec7d6f8ba85a3c63bba8518e25ab73c326605b9cedb765dffff9f27efbfc01e528da89aaeb8ebdcd3c3a39ef39780842281b29b683cf2a682c1ae33e1fdb07f8712afd92441efbb9fa52d82a8626f387768f65edc368a5221bbf91b57620b5ff450ef41c9bf7da34a474c5bd3281ba93fa517c336562cdf92425f6ec729848ec97c07c35cca985652cdf398ac4663906f2822886612b3db9cf142e455b1d41a801566abb8d41c5682289ec2a57f9745f5eb844583b294a44e08ded45d0c662e7f4a200eec3eaf86c6aa34679f8b598783e70e786afc8c1e2e7204ec5a52d8fbb108003ef24d69f2a4b41c5e20594df2b4e29351f1c65c8c9af8ffee3cb9f5f824dd0811e3b8f57686b01f502d74581c4c6329bb09f896677afbcf37bd4e88397df76fe68a33c71792e60ce53c26225dc32997da6aa5476fbd4572da3c0483d80752fcb39b26e72a93e89247af5176b7544e7966bd1a34fd25c2adcc750266842af296f4b87e9f18ac6adcfd103ff22c4670d9b0403f3e50d5592e1efa093c43149d651424f779fc4e9ead4a33050bb25de77b4c501a6157350b5b9204bce269cff6f2611cee5a9fcb95aededa0b2588549d9726d13cbf8325ca7f45b018bda6b08ae8ed7e658cd307093f081f78f8660498d4baf2c2cd5f83623bc136ebd121cb1bcb9ccc5e6bb5807b3403930399c7f0cfc6d4dcc5519e67dc36635a6539d6e163875bf30c4c7c6b28d687b617c0387e7ca6bb48ab5f1e72b4edacfc0beea99554af8"}}}}, 0x0) sendmsg$nl_route_sched(r4, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000040)={0x0}}, 0x0) sendmsg$NFNL_MSG_ACCT_GET(r4, &(0x7f00000001c0)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x44801}, 0x40) ioctl$vim2m_VIDIOC_S_CTRL(r4, 0xc008561c, 0x0) add_key(0x0, 0x0, 0x0, 0x0, 0x0) creat(&(0x7f0000000000)='./file0\x00', 0xd931d3864d39dcdb) timer_settime(0x0, 0x0, &(0x7f0000000280)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) r5 = open(&(0x7f0000000000)='./file0\x00', 0x0, 0x1a1) fcntl$setlease(r5, 0x400, 0x1) execve(&(0x7f00000000c0)='./file0\x00', 0x0, 0x0) 14.698568176s ago: executing program 1 (id=1553): syz_open_procfs(0x0, &(0x7f00000000c0)='task\x00') socket$inet6_tcp(0xa, 0x1, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000340), 0x0, 0x0) r0 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r0, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r1 = syz_io_uring_setup(0x5ce, &(0x7f0000000240)={0x0, 0x6734, 0x80, 0x40000, 0x34f}, &(0x7f00000000c0)=0x0, &(0x7f00000001c0)) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000180)=0xfffffffc, 0x0, 0x4) setsockopt$SO_ATTACH_FILTER(0xffffffffffffffff, 0x1, 0x1a, &(0x7f0000000400)={0x1, &(0x7f0000000200)=[{0x2e, 0x0, 0x0, 0x4}]}, 0x10) syz_open_dev$dri(&(0x7f0000000040), 0xd21, 0x0) mprotect(&(0x7f0000000000/0x800000)=nil, 0x800000, 0x5) io_uring_enter(r1, 0x57de, 0x0, 0x0, 0x0, 0x0) 14.676086975s ago: executing program 2 (id=1555): openat$binderfs(0xffffffffffffff9c, &(0x7f0000000300)='./binderfs/binder0\x00', 0x0, 0x0) get_mempolicy(&(0x7f0000000040), 0x0, 0xa, &(0x7f0000ffc000/0x1000)=nil, 0x4) 13.603788991s ago: executing program 2 (id=1556): socket$qrtr(0x2a, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) r0 = syz_usb_connect(0x0, 0x24, &(0x7f0000004200)={{0x12, 0x1, 0x0, 0xe2, 0x79, 0x3b, 0x10, 0x5d1, 0x2001, 0x900, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x12, 0x1, 0x0, 0x0, 0x0, 0x0, [{{0x9, 0x4, 0x0, 0x0, 0x0, 0x4d, 0x2f, 0x9c}}]}}]}}, 0x0) syz_usb_control_io(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, 0x0) syz_usb_control_io$cdc_ncm(r0, 0x0, &(0x7f0000000600)={0x44, &(0x7f0000000300)={0x20, 0x16, 0x2, "fcca"}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}) syz_usb_control_io$printer(r0, 0x0, &(0x7f0000000740)={0x34, &(0x7f0000000580)={0x0, 0x15}, 0x0, 0x0, 0x0, 0x0, 0x0}) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x0, 0x0) sched_setaffinity(0x0, 0x8, &(0x7f0000000680)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) openat$fb0(0xffffffffffffff9c, 0x0, 0x0, 0x0) r2 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r2, &(0x7f00000002c0)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x44010}, 0x8000) r3 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000140), 0x0, 0x0) readv(r3, &(0x7f0000000000)=[{&(0x7f0000001300)=""/244, 0xfdef}], 0x1) ioctl$TCSETS(r3, 0x40045431, &(0x7f00000000c0)={0x0, 0x0, 0x0, 0x0, 0x0, "000080f100df00000000000000000009f600"}) r4 = syz_open_pts(r3, 0xa001) r5 = dup3(r4, r3, 0x0) ioctl$TIOCSETD(r5, 0x5423, &(0x7f0000000100)=0x15) write$UHID_INPUT(r5, &(0x7f00000001c0)={0xa, {"08c39ee52f329f1698b1c4865f8b540a5eee9f496a0809c3d20325867b6edda88489ab4c09fe0a7f1e8640aa8e344f412df0d69475a5d6570e21f31fac7dfb4aa7ade0e851582d5c1abdd809580cb34c9e48576b1c73ed76023256fca058ada3db47d86cc75b33cf762b67fe61f152618c49a40858f68794a4fc484ab73ccd254ba3d147f5feddaf91dacc238c0a8096f79597ca1e6da781fcf37a0141a335c6a7577d2d53c6e552a7be208381bb31d1d3e0e92ea651655217535734b286d3f19780a4c720075a36a734151f8c00e651cb3a6bbe30e3f6aee48750436da6471e965e81f38134674fcb697108fb7345010bb8fa15fba9b33355d7858327171ab9c68f6c21b2ffbff4eb061dab80bc77a4a7769e7ff73bcd98790e09415bfc5978cf5af45c3ec9ef9c1a39f766c59d59590281038dbcb765580ba2b3f141d5bbfc40910a0894cd1f22d2a8b6d4e4778debef99438b54d44b4b7568de2777431a5b2f3e8d1a45a60a468f5e33e8ef534f803dfb6798c270f52edf031ecd996bb78c4e92961c63c079676d77412ebc6074e5f235417785e7a14b14ce7626b015071c154cc2bf8f4499b93293e9997c23df4c7a1498cf12414fb31eb873728e4f613b540d22e7ca718f18da5b82ed24995e4309c3af4a2e1097465bf09728082d09e71ea365522035eb9772b8e072f8454777ee304dacd59d3eb9f933f151fa14f8c38eadbeba04810a2dea7a66824f09235c13a45f07870210d0d310ce3ae6284577bd4e65f32700f6723727926cb52e4f27776a1dab0f6668327ab5cf1893879a635261f2e0d9923ccecbf5b80f10a8275c1515f47930d614e787f14c105d3a4f8faf8e7f738cf4eae4fc39ef3db3cb87794ace87f7239b69dc4ab4e5ae57cdfbd309e847d99600ef14b51faead01e8ade57d24270bc13a1787896096eeacb8ab1c93d31d93cfb244bb09ecfecf336362a5656db7df327cbb9aeb898f8af229c7bb9452805f2b4510c5df86b6d564e01f000000167ade5205331523a6392af2bea9e6db0ba5480cbf1b202714233289c4017cb66e83c0c8b6e88bedb922162d0ceecf6c5da173bbefe6781ab7720d2be6cca378db650c69d4228141ae190922fbbaddb86c7f0fe138b704e8305b3bcc7910b2280d96d71dafdbfa876b0013fc4de586f85d9ee077b6349becbdca8bd989a51c4c76ed8a8cc691a65078e0272a62edec8236a779f0cbffeda49dcdccd4def7064e0d77ae5a8c64f3057b4a3a0d4457d33f2bc6c112378315411baa4bb126fe540d750491fc58fbb66911ef82bce5ed76872dbcd8e05dea2f3f347a653aa39ab5d75e71671bfeb924e71476134dbf91e3f287fd853cc34bf81e717edd41aa04b6fbeb43cf2074f0c8fe5350401b6cff801c147a3b58b972aa5652629a9fd8b1df2852708ce958d4e9974ec4383aa5da4e3f75fdc85981e97b75863546f67a8703673b6fe2c26f0e9eeb8c45c26f673adac55fa5d69b82ae7d032fd3b26866047e8c029b90a62794a89c11398944b398b4177b2dcc5a743c16d4a5333b1e30af678d3db8df849c1753db067a6f94bab00c0dd3c7e94a8675924c89bda98ac09e10bcdf83f5114b9b466c413477a5cdc48c857230798934bcc1f0eb3a2d2944b139e459af32e515785f46ed4e97cdcb23c7e4dc7c4f91b5b5ca5228344aeb6652fffaf31325c7429bc70a5f6beaaa98ef190dffdeccc94bd814b3edfdd48243bf34291076ab5438ee00e924a827d5b453df42d24144fe1a45bb6c84fcbb2143d0a561c1e867c1279bdf0a47061ea77a84f36c720aff785f0db10eda84c767b5f3874f9455c0f026735ded32f0403ef7dbcf97d2233d59c670114ddf89314ba74fc248bcbdbf43c24e46304e229b3cf583aa410f4dfd119152495da8737518ee2a05a8ca1f004be3c551408f2e4013e444b63bf2bb26ddeae505642dffcc989ee241c48741181b506e22fdc4530319522780c74bf786852dc66ebbb51f8ecbb1e35de09ef7afe589bb8a31c5d63477db5d5e7174694ea04cfa98057d39127a4e5eedb4897a491c6693acd0a036abf846f3b6f3006e5e5fd586f29a4a8a31abbccf732e4f1b88187a72d669c16302657e9cbbeb9322662e111edc7771526400b6123d0f8207bcaa38bee07043e36e223d418ac948d65e7acfe72cc3fdcf03a3e43ecfec8ae489ddba09126709c5c7968829e3504de8a5010c9372de09476a7b96b04d7aed2486d8f89f21f075321abe350024abe00a81f87df3dc372fc3206496776c26b6958243070bda4cace3e358da5d39a3945765c2ba4b002b06efd416af66f3343f218ed84550ea83f02f9a5c3fc677ea60987aa25f0406d6154081cfdc074814a2465accdfa102858f5a52c9eae293c56ddcaf8f6926d3dd0ccb51a30c960d6b7e473038ebd3702b5106f6bc040efdfd7169fd3f2dc42ff23de26a239e13b74278729fd7e843b38a35c55fd50181ac13a9cbbbfd8feb36afaeb1993349c0ac5a0c44ffd92919dfe272b0f8ed7df7198cd299715f021109a58dced4753d3c7ddd6e9ea01596f18b2fe7000000004ccfca57aed5b5cebdff65de480a56bd53f4c7f83ddef00d7c9686311d1fce76f320bb3222a11db30ba6ed31535d8fda61e694478ca9935d72719b8d6b9be88ae3df30b60ee251b919b4d1734b994c62accdf855488b351738331b462eccf27efdc5577d7a5548579dc90d227a42ac010f33a720dc3cf0a63454f8b07c775287495761a058ec1e28e6aaf8057241f4ef8b5de56e279355bb66630c4ddf35e7c2cfff26a4241b1df0379d2a1e9f959e46d3843f89844ead50aff44640fcbc4a1edb033afff7cc9e57c4f8d31900764233e11fa4c28e547788c1b00de4268df692ba3415a9ad90fa712f9618f5ecff57da32809380eeff040cd3b23f508614c72b303cec3bcd732708303b166193366a062b9cea536f28478c387e626744c6a611a8e7162d274efccc84eee8eb31d3310c86752777dd5b5ffe234e895c54909f19a4aabcf3c15b90c02170409e314fd90e766ec4ba93c8ec6321237a980ad3c32fb2fab69e57541ea7f5427a85c2c57d40f9ebe9de5572f46a4713fb28e0af42d0adef3e29195aa41a3ba318181512eebfadffede4e35ff7f975928edc5d4d9f2d931fb44b30e1df55e66c52e1648e9cdaf71221b57c6a6b087428ccc57ade5b1531341cba2be452b426c434c70fd8c493337d4995cbd76ea1dd545226e3eb59d5f94ffb5352f87a4a66cd7c5e88322404fd397c46e198646a9c819d0eb1f10e54d8a3ea912f1cb134ff1095aa7325287f6ea9af8c13b67d6abcbb70dbc06838ecb33e45b60f6cb832c3e72d1401770f66bd02f35a2d007815ab676099e31f5102000000c0e83d5e7107c8dc5830c9cddb9781185b94d7f2814c5058ba3ac54c268741c5728f4997a9628602c2a36090162379f3f37c47619b3e7c7397a5913b7060b51e0c7f7226ff1135444f866f89a4b74136cbd3acb7178bd63183b3fd9cd19fdeb6fcc6341910ad4605da76a9af4bfb8b75fcd666f8188902b380ae560d9aa04f8f9b0ac5c109d1824a470726e06a49d955f8f71c8a86081e75b13f62600deb941da181eaff544cd559c467d8dae432debd22e7a7b3e1ad731a5b9470f5f60423dda061ff899c07c79f3da34f38e1d8182d6ee0c36c602945509167be440382a8a8a759b20e41638fd57152029b190b5701d30a86f579e2d0cc53a2f809ca9bd3aba1eb2772a7acc35c4d983afa83a9baea35c0ed4931234719636cf8f5fe1884bde6cebbdf23bd62b1ebf0a5cb78c27295349bd7d5cf28c4ee4689497238fd3aa71a417914e6892667a56bd69dc2e5882cfb67df71494e9a9199e025892e4e7435f727636cd988cc7563d28db5133f649849c5b3973a3428de10ad39d96146b22acc50f50eee5a038876452b960686892de40efe30081ccdaa2bf64af78d5988026e529b36c62a21378ac42d220d0dd878010178e374e6dbb2b61206066d04e729ed03c6fd9a4e00547fe9304aec0925d85a0acd07fdc5d48c1a1cff656916f5d25952327792255e0d606a32517781cc3d737ec753eb95b5b5b95dabd8946907ab54cc85d05b475e2e5486c6fc070417198d3a50910e2949d20d3fa68fd327934cff5171224942b8f18d88947763a7c710d09c4b269bdf2d3e715329917fb70728a4a0530999b755ba8fc04deabf4bc4bcffc4d62d491538c65078122bf2c263ae0020af67cfc9cf19e5b929e086af281fb43d5504d728935c5cfac136eb81703d50fddb39a5a713b2914c6acd9b2d07819cf7bba495ac5734fe423e611d309b80eeafcf9053d51b0ab3c29d5ca5eb8861ffc1ebc4d53f361b8991baecb52860c15202f979e34054fcde869d018103ccd6d914a70f1840fc6aaf426beec975ddb980b19b0f4cc2ca393c0b9e6ebe5e7d1c9fc1ef7a1c91378f0b73262993fb80667ecf62bac3c47cbd002ae1b87b8dc3ec99d5c987765d778868eb55022cc3bed14b8f934a584bcc98fa0b4f6e6982ab8d8a2bb49f9074ef429dd7b8db332a96ccec6983a97be7c8634c02e7937ffc8d613b83aa375886bf40a87ec062090382f874bf2c8e5fbb58ac18a46c4d9e85af3ca21bdacb7755f49776b0eb3972ff682c84beb07d74cbe2764e378253e72128991b73d2730704a5448280e8a0fd8cc87d4cddcffbfe5525ae3d2304877a3988e33c8e12bf77793e753f25840e9af2ce56bdb999fc62623a2298b4244534f662eb398a2577c72f6cfd5174697dcee151d4f3a7293b11de3889c43744da4165aca4e4a1e926d37ae4d7471584a06f3641f2037a74a58c2397a594f29d142d59f91bb57e24e1a3f30f68c626033cc34895c1b16d62e3a375c3e09f5dbd9338cd3a500643143cd404b57019c648c3ec31d696233fe16efc3c4c84aca0830ca8b9fbf1144b98d82f41e4cf67631c74cdcf8d9c8b8556b876ff1592683ccac0b47a26cb3a2cb1b917f433bb54e0b53deae9ac4b1cd0594c1fa0e6744e7ed88fdac60901e3da989f3b0d7c12b140cc576fa1b0e8e705321d37c303691aafc9fed9c3dc419078d0925ead56455ea5f3cd57941e410c1c14c2e8972d7cca44fcaca1f64fc817f4a41b6d9fb237fed159cb09e788ae560726537f49cb64b9f60915d402e0931355c55ad792cde758548b1af54b196e414046d4af3579a6c30ceac3d68bbfd2adef309c064e759a9f0dd69d682a3880b8ff27b69abffaa45ee7e65d8f1f6e40c188f6249fdf72220b4c87243217ba0292b9e9b67ebeda4fb83406216a4d765812bafeff34cc57f7d2cd1608282079c076055b9cabffe5fa491b970291bc2672540ccc15ed877d7dbe3ef683724c715ace770905e48c2dc6a44e1fc095773676d070eac00ee3834b07590cba7093f56b678313870471c81599d34c53fc03ec6c913d8ba3f604ace8da12d2025cbb5000bc062f4db65a6feacaf3915206d1c15ce7e78c17dc2ea32cb57d6fab0a22d487c77118e75016006f812541ec8180a321287a2d57248d4ee4a19706a19d802c70e250c3b0fc400a0b5cdc06537d2f55fd5300be4eeeaab8cc481a84b6a5e17d8c47ec92fe40710d4ec3530a94ca16710ade2ec7562398106e0ddbb6c8af6412166afd99d45d29a3a967e58decd0d6fc5bebb98d639b5606efd358a43d635d50f0ccb8472197da604994e7fb700243d5f7e45700", 0x1000}}, 0xffffff5c) ioctl$SNDRV_SEQ_IOCTL_SET_QUEUE_TIMER(r5, 0x40605346, &(0x7f0000000400)={0xfffffffc, 0x0, {0x3, 0x0, 0x0, 0x1, 0x596}, 0x80}) write$sndseq(0xffffffffffffffff, &(0x7f0000000140), 0x0) dup2(0xffffffffffffffff, 0xffffffffffffffff) syz_usb_connect$hid(0x2, 0x36, 0x0, 0x0) syz_open_pts(r4, 0x880) 12.998491456s ago: executing program 1 (id=1557): prctl$PR_SET_SYSCALL_USER_DISPATCH_ON(0x3b, 0x1, 0x0, 0x0, &(0x7f0000006680)) r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) socket$kcm(0x2d, 0x2, 0x0) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000400)={0x11, 0x0, 0x0, &(0x7f0000000280)='syzkaller\x00', 0xea, 0x0, 0x0, 0x41100, 0x4, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x3b, 0x0, 0x0, 0x10, 0x20000, @void, @value}, 0x94) r2 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r2, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000180)={&(0x7f00000004c0)=ANY=[@ANYBLOB="240000001e0001000000000000000000020000000100000000000000"], 0x24}, 0x1, 0x0, 0x0, 0x2}, 0x4044040) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000000)='sched_switch\x00', r1, 0x0, 0x400}, 0x18) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r3 = getpid() sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r6 = socket$inet_icmp_raw(0x2, 0x3, 0x1) setsockopt$IP_VS_SO_SET_ADD(r6, 0x0, 0x482, &(0x7f0000000080)={0x11, @rand_addr, 0x0, 0x4, 'lblcr\x00', 0x0, 0xfffffff8}, 0x2c) fcntl$dupfd(r0, 0x0, r0) ioctl$TCFLSH(r0, 0x400455c8, 0x8000000001) ioctl$TIOCSETD(r0, 0x5412, &(0x7f0000000200)=0x1011) timer_create(0x2, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004}, &(0x7f0000bbdffc)) mount(&(0x7f00000000c0)=@nullb, &(0x7f0000000000)='./cgroup\x00', &(0x7f0000000040)='hfsplus\x00', 0x2000010, &(0x7f0000000100)='barrier') ioctl$TCSETS(r0, 0x5402, &(0x7f0000000080)={0x6, 0x3, 0x1, 0x0, 0x1b, "b3d3c8d5dd41c7b2c462285cb5a05d1baeefbd"}) 11.604548249s ago: executing program 6 (id=1558): sendmsg$kcm(0xffffffffffffffff, 0x0, 0x0) r0 = socket$kcm(0x2, 0x1, 0x84) setsockopt$sock_attach_bpf(r0, 0x84, 0x9, &(0x7f0000000380), 0x98) sendmsg$inet(r0, &(0x7f00000006c0)={&(0x7f00000000c0)={0x2, 0x0, @remote}, 0x10, &(0x7f0000000100)=[{&(0x7f0000000000)="93", 0x34000}], 0x1}, 0x4040) 11.416250105s ago: executing program 6 (id=1559): r0 = socket$nl_route(0x10, 0x3, 0x0) mmap(&(0x7f0000000000/0xff5000)=nil, 0xff5000, 0x2, 0x4c831, 0xffffffffffffffff, 0x0) io_uring_register$IORING_REGISTER_BUFFERS2(0xffffffffffffffff, 0xf, &(0x7f0000001580)={0x0, 0x0, 0x0, 0x0, 0x0}, 0x20) r1 = creat(0x0, 0x0) syz_emit_vhci(&(0x7f0000000240)=ANY=[@ANYBLOB="041c0500c80001015c2899025116bee1", @ANYRES8=r1, @ANYRESHEX=r1, @ANYRES32=r1], 0x8) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) write$RDMA_USER_CM_CMD_CREATE_ID(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x18, 0xfa00, {0x0, &(0x7f0000000080)={0xffffffffffffffff}, 0x13f, 0x9}}, 0x20) write$RDMA_USER_CM_CMD_SET_OPTION(0xffffffffffffffff, &(0x7f00000000c0)={0xe, 0x18, 0xfa00, @id_tos={&(0x7f0000000400), r2, 0x0, 0x3, 0x1}}, 0x20) sched_setaffinity(0x0, 0x8, &(0x7f00000000c0)=0xa) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r3 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r3, &(0x7f0000032680)=""/102400, 0x19000) r4 = syz_open_dev$cec(&(0x7f0000000040), 0x0, 0x0) r5 = socket$nl_generic(0x10, 0x3, 0x10) r6 = syz_genetlink_get_family_id$tipc2(&(0x7f0000000200), 0xffffffffffffffff) sendmsg$TIPC_NL_MON_PEER_GET(r5, &(0x7f0000000500)={0x0, 0x0, &(0x7f00000004c0)={&(0x7f0000000180)=ANY=[@ANYBLOB='0\x00\x00\x00', @ANYRES16=r6, @ANYBLOB="0d030000000000000000130000001c000980080002"], 0x30}}, 0x0) ioctl$CEC_S_MODE(r4, 0x40046109, &(0x7f0000000100)=0xd0) r7 = semget$private(0x0, 0x207, 0x53) write$RDMA_USER_CM_CMD_LISTEN(r1, &(0x7f0000000280)={0x7, 0x8, 0xfa00, {r2, 0x5}}, 0x10) semctl$GETALL(r7, 0x0, 0xd, &(0x7f0000000040)=""/119) r8 = userfaultfd(0x80001) ioctl$UFFDIO_API(r8, 0xc018aa3f, &(0x7f0000000080)={0xaa, 0x1}) ioctl$UFFDIO_REGISTER(r8, 0xc020aa00, &(0x7f0000000040)={{&(0x7f0000ff2000/0xe000)=nil, 0xe000}, 0x3}) ioctl$UFFDIO_WRITEPROTECT(r8, 0xc020aa08, 0x0) ioctl$UFFDIO_COPY(r8, 0xc028aa05, &(0x7f00000000c0)={&(0x7f0000ffc000/0x2000)=nil, &(0x7f0000ffb000/0x2000)=nil, 0x2000, 0x3}) clock_settime(0x0, &(0x7f0000000040)={0x77359400}) sendmsg$nl_route(r0, &(0x7f0000000380)={0x0, 0x0, &(0x7f00000002c0)={&(0x7f0000001280)=ANY=[@ANYBLOB="4400000010003704b176332e6596c1c8e7359b43", @ANYRES32=0x0], 0x44}}, 0x0) 9.218574591s ago: executing program 1 (id=1562): syz_emit_ethernet(0x0, 0x0, 0x0) getpid() r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000400)={0x11, 0x5, &(0x7f0000000000)=ANY=[@ANYBLOB="18000000006900000000000001000000940000000fad413e850000000700000095"], &(0x7f0000000180)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000040)='sched_switch\x00', r0}, 0x10) r1 = openat$iommufd(0xffffffffffffff9c, 0x0, 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000380)={0x8, 0x100008b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000000)=0x7) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000280), 0x0, 0x0) r2 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r2, 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r1, 0x3b81, 0x0) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN(r1, 0x3ba0, 0x0) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) r4 = socket$netlink(0x10, 0x3, 0x0) openat$procfs(0xffffffffffffff9c, &(0x7f0000000000)='/proc/bus/input/devices\x00', 0x0, 0x0) io_setup(0x3, &(0x7f0000000140)) r5 = openat$uinput(0xffffffffffffff9c, &(0x7f0000000040), 0x802, 0x0) write$uinput_user_dev(r5, 0x0, 0x0) sendmsg$netlink(r4, 0x0, 0x0) setsockopt$inet6_tcp_int(r3, 0x6, 0x13, &(0x7f0000000000)=0x100000001, 0x4) setsockopt$IPT_SO_SET_REPLACE(0xffffffffffffffff, 0x0, 0x40, 0x0, 0x0) connect$inet6(r3, &(0x7f0000000200)={0xa, 0x0, 0x0, @loopback}, 0x1c) setsockopt$inet6_tcp_TCP_ULP(r3, 0x6, 0x1f, &(0x7f00000000c0), 0x4) setsockopt$inet6_tcp_TCP_REPAIR_QUEUE(r3, 0x6, 0x14, &(0x7f0000000600)=0x1, 0x4) setsockopt$inet6_tcp_TLS_TX(r3, 0x11a, 0x1, &(0x7f0000000100)=@gcm_256={{0x303}, "0f78fbc54b6c106c", "75fd7583f127c5c356354c80ea765edaa15f377fb214e20fda1b0241bed67dc4", "b1726789", "fb442565fb00"}, 0x38) sendto$inet6(r3, &(0x7f00000001c0), 0xffffffffffffff13, 0x0, 0x0, 0x3000137) 8.985915108s ago: executing program 2 (id=1563): r0 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000600), 0x22042, 0x0) ioctl$IOMMU_IOAS_ALLOC(r0, 0x3b81, &(0x7f0000000080)={0xc, 0x0, 0x0}) ioctl$IOMMU_TEST_OP_ADD_RESERVED(r0, 0x3ba0, &(0x7f00000003c0)={0x48, 0x1, r1}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x3) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r2, &(0x7f0000019680)=""/102392, 0x18ff8) r3 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$EBT_SO_SET_ENTRIES(r3, 0x0, 0x80, &(0x7f0000000100)=@nat={'nat\x00', 0x19, 0x0, 0x90, [0x200000000040, 0x0, 0x0, 0x200000000070, 0x2000000000a0], 0x0, 0x0, &(0x7f0000000040)=ANY=[@ANYBLOB="00000000000000000000000000000000000000000000000000000000000000000000000000000000fcffffff0000000000000000010000000000000000000000000000000000000000000000000000000000000000000000feffffff0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000feffffff00000000"]}, 0x108) setsockopt$kcm_KCM_RECV_DISABLE(0xffffffffffffffff, 0x119, 0x1, 0x0, 0x0) bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="1b00"/14], 0x48) ioctl$IOMMU_VFIO_IOAS$SET(r0, 0x3b88, &(0x7f00000000c0)={0xc, r1}) r4 = openat$procfs(0xffffffffffffff9c, &(0x7f00000003c0)='/proc/diskstats\x00', 0x0, 0x0) read$char_usb(r4, &(0x7f0000002840)=""/4103, 0x1007) 8.535723222s ago: executing program 1 (id=1564): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0xb058}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@file={0x0, './file0\x00'}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000180), 0x0, 0x0) ioctl$TIOCSETD(r3, 0x5423, 0x0) ioctl$TCFLSH(r3, 0x80047456, 0xffefff1f00000000) 8.494758892s ago: executing program 5 (id=1565): io_uring_register$IORING_REGISTER_PERSONALITY(0xffffffffffffffff, 0x9, 0x0, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000100)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) r0 = getpgrp(0xffffffffffffffff) prctl$PR_SCHED_CORE(0x3e, 0x1, r0, 0x1, 0x0) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) socket$inet6_mptcp(0xa, 0x1, 0x106) r2 = openat$vicodec0(0xffffffffffffff9c, &(0x7f0000000240), 0x2, 0x0) ioctl$VIDIOC_S_FMT(r2, 0xc0d05605, 0x0) r3 = syz_init_net_socket$bt_l2cap(0x1f, 0x3, 0x3) r4 = dup(r3) syz_emit_ethernet(0xe2f, &(0x7f0000001540)={@random="cebf901584bc", @random="6a177a00", @void, {@x25={0x805, {0x3, 0x6, 0xff, "3cc2cf9cf258fc60ac5471863cf8b24d9b27d4ca85c99d06f224f11d7b012645cb9e98a4fa8cd538193c47527256f8cd50b0ba8084979e2c835ff1b163c44dd8a66a5b8f4c550c94e434840efb1f51e7ca106bdb43dd9d7a2bebe70f8c773761f78485101c785ebfeacbb541c517818800d95d252717eb649cb32da44d2ab02230b3f5329e480a5a88a4733aca11daa8ae84507906dce585c1411a918580bec2dbe0ca0407387dd118772e70a3e068f975e92688393bda5f985507ddc9e7077e5f4cd0ac323d6d959f2633f7731c976f350535de4062cf334afc9182ffda77c5000552cafcd5fa1a84fd5e18e5dc04404a8f3d818c966819cb4a1ca4ad13c82410234172bb3d395814821a49b313a94d163e2fc5a4dfc657fb34ca9580c66ce81cc88a8e9a8847ddbaf527a88efe9b281192f33b9480e98b8d9b8829be6727d21996c581f950a881f64f55c82c23368884ac4f8a70dac647ad12485dc5685b1f8519ebcedeaa7c54615bce25ccd2aa9f47df03addc7f1505d1e8c62ca1f9fe05193f5cc58195c05e9d1511ead462de2e888b0bbe4e27167063c6f749094ac5c81c354cc91f9cb6eb35c7084e62849c8101f0b5bddca4244451236540dd86799d0d3da8cf1be1f0cfaf52d905649e942203b60a0e84760df492c0095abcd725eea03377382ea50a417626c7d4c9993830a7485622c0a4821a1dc72ce45624a4c4fc588d3013e4f7cda7a2c32785c06d3e4cf5249356c1bcd8ca2d8fdfd8fd6c898978f1fec18ebfb0ff1c0b790631d9053be15286f3d0346993b1c8df85599ab545bf9fa5caa3add99f729ac161d0794c36ea6908ab01fc14b752107295ff1d734a534842e36d3b729b1e99855577b6f6475ae371977cb16e7852784926f218753de083fe3ab2b82f42193b39839ac64eb6d3c0e15d1fc243bd8fc775ae213b8498e31b58145abcfaa5e8d5f2695b3290d888108fa6bc17e2d61cd695c69ae693058700d2363b630f0f07642a585e0e79766b62d0e606468d82ddf6263014c1c5d5f9e8a9568ed0959905fad36b9780d472f0ac7e14132bcb8290b84c54875c1411724d5d5b3d759b914b37d0c4be1e19ad23e1c76ced438f22af808c0f8d3fcc8b1ca157d1c4575cfffd2402fb706da18ebe56316090c10aac919f0b547ef6da0b8dac4f5ceeebb966f2c9adbb8999e44483402b3b32bc7924bc1648d52af5896f775c2446e5591096d19cc4863f4d33b17a18ec21a9c437a765b4194bc260d3bfd1e87ef9de5a6b63a0fb0748c21b2908301c187e243d45cbca42f9a0aa6ddfe47b55ba3105a1b8931357f498e5a9bf30e76d8b33daa1690dee459a5bc47ab7a9c457ef3a2211793da442a26770392d730835dc524c4135f8d5330623566427b9d330e465a765e4a393c8cb880e424950e0b836d06cff345c904f041d315f9d09beb9cc1bcafe61928adf1bd1f0085e04c7302a028081c7bef68c15563d5b2b5756f3fca95cbcf2e2fcb4e42ba4af4283962a26cddeb9e91c0857e1da215e0dd406f684d76bd23730746568a58dae9d2361b06cf3df08088093d61fd2604d963dd2b4540f3300631ce7e49c094268417e930bb3e502be243e25b174c2f2c8d6aba378da7ae159c353b2dfbb4a25c89bb51158dc4f2e48ed1c2b7f8060e27860e9a7d6e6bb2cfdddb7668ca4ca19f7a3ca4d8401bb2d19580ba485edf3b658f413782a50f86e4d3c88a7739b1212bac1128d36ee6ceb9089cbb6ee699580e5770df6076f8f0b7c834e330fb7a0eaa51bfb7ab48d0427ea22736a0877ecc392da2c6b38cd918c67a41c3282b85f50c137261a4e5f8832add57d691fa5b5b8840ee604996665668f91ce2220e57464b6d297b926da03efea3ecfd922e5f8ec69843c6c3f81b49e7452ef16dbc2785af5d1fd81840a98023754c8e9c1b9f001a1c01070bf0baa697a9954b8639adef079fbba1e99204253c223129c74f329480ff45e20ebdc783c5ebd226328ade52f93579502d4d96a3beb0654f3be33394000d3296260b4ca3ae8aedfe6d93b0af9c7bce42ad3111977a62199ceae61cec0a3661b2772cae7153eb029a7680b2d41e90a6e2b654bf9bda5f4a23cc1bf5d73e67992fa0b2fcdc656f32ac7bd362bb0a9eea8290e8693cc50474e912cb0610dc98a975134e693a5e07e35cb5fa15c9682c3c299f76ba732f6759361ccde7dd9086bfc7d0988829aabea79c00b8715efe5f7161be1ecb3a69b87670228443cd98c70a5c79e8c8168d38dd298a4abf33b35ba64f4a30feeb3d2d0e23f1af8f3d7f8fe8fb74da0d59763c9dfa70493aaf960a587409ac18c2c30388fe1ceb9d73a1cd052ad1b427dff45a51fc7819f98d88b928a8946b9bb31267ac5794403ce443d685e8b87ab443c731c7aba5c63c0e8de2335dacf5394d2426841b505ab9b578f048f987fe34519dac2097d6ab8a3370121fa27da58cca5397dd6db1c2bfdf51895ade606df2d5381f9a781f70be4250f9b8bead65a5e15b3721fa9481d19a31193967e0fc9b291a908adda35f7c958b193d81c52f014acfdeb22bbb85357b48a963bece9efdaf56f7e1c06fcdff0379a1af8326c7573122377a06829a007fb66f3ee1e8b70f72f2aeaba76b9c92ee1f588ea5a55a2b46c8b47f7da0f916e861561269dc1349c5658ee0265f87948b50f1e18de17d6d2836ce133ff4cba4b2f0746aa21a700281bbeff5bb0c6421e8e0db38a79881f32673e157e41ac798b015dc7ffc90afb572f831691a03cbc5dc3153beae3961fae7b913b053b744c6462a8ee94f4e679bd0e6b9721a550e49c15534a2328b9c136073ced5f7d719400b22b6041e50352942b625be1fe88015a914dad9882c0701b1859d5ed65b5314ce5f939feec9fa09447c49359f9e55216e060f5bd6990284158b343d75b3b03b76dbfccbb4ae63a05535c27938bc7e69440bff8c1a138e3ad80e912bbdec65a53d6b12d140362393bca064d3f5d9e5450b1e90e1cfda41e3d4876787be7261bd7f86c8cd91e40e84794eac113567b6b27f149d8fa1d08696792ccec50cf43755350200b9b226799707e6de6a13e8761a931271e618c0d5aa7c4a3250283f4021cabfeb37b2905098806f410ad22eca0b5c0bcc2bca2d9f8af2aff6656ab99309455c1a5f237836cb7124570e209ce1e46c507302e2fb672a6ed46fb78ef5e271fb8e6a6f73e6b36c17cac5bb5e01c096d8b45b5e9879ebe84bba627d52502564598f9ac391f2e04ad8f34d39049c8761a2b082e13cd403373d7b006495ea580aaa6e5ef8d3c4cd5411c1bbcc04214df3bb98eb9f395a2b3e03ed03302afb6c4dcacd66cdfc88165362e7a9194b2e9ab8062723c18eb5dc14eef3d26f7877bb8f861447f8c2cc757b0e7502353b0dff074888c44a82c0e549545800c7cccaad320b18785c4e40de35ed710e9f24daf33aded6b183e0797dbac94f60e4ecbde8e5c0f24153cecfd048ad1ae5d9bbc4d23e41133e80dd0cbba76134eecebbcb35b26ca21e25f7ed6754f071901cb4f25e1e6a474da83090e56ef23f478702ec41a4e4d0bb251d62fdf8d64eda2ab3f327db52c6b711f7f5d9e9dff922b9c615aa70bca53447ff483f6ee07d237c812e25f195ad3e38fcf3fdc803eca390f04962dd8c21a9c23f947fd41df6fd1ab99434196fef0081846fe83dd7d097a3a31d614926619cf9ff7e837df4299b1318ab1115629596eee9f389c7d8f0467f649e43690799b7028b78cf2081383961fdcda9198585702e91d5408af632b287f8fb4965d3355478e8f6614a7f26c139743b23e13dfa94926fdc7ba6348e9cbc7b8a8020a5e1b801ca040d3a5b2e2366ced1f2f40461e4013e00b3b4c014a2a45c2d7241b509e0c074eb9134e60d461436728da4d70a31c0068e73e071bf369d10ec5783206b00ffceaa37fd55d0a96b6f78f6d4b756b6d3e5e30d7a33089ef25a0414e28b3e0e69a2589e5a492103f4e89020f68c78c10e658ed3220ed6d29e3614277b5dbffc51b123cf6efc5afac43de23ddf2e0f348ccda6cedea88dae7c109c063f97ca4e847847dbfff8ad9be5a573a44a0d71c03573eb66cf3856a6fd733e0f6a950d5928e1ca4e62cb26394b1bebffe6298a8af3e68ea00cab819ccf5c45c84387e48e53e36f29624cb20eb6a946fef50ebed49dd3143465278256fc34e088eeaea4c8911a862fee8ddd97d7eb06328647d9a336b7a628fc3e2d8d9bee7a5189084c6ab6cda37bc239d259eda25b24cada795473816a34e58cf6d512ded3a498cd5f667000e4b46151704e6b7804272659e1fee1794c54f13cc6b58619586ec7d6f8ba85a3c63bba8518e25ab73c326605b9cedb765dffff9f27efbfc01e528da89aaeb8ebdcd3c3a39ef39780842281b29b683cf2a682c1ae33e1fdb07f8712afd92441efbb9fa52d82a8626f387768f65edc368a5221bbf91b57620b5ff450ef41c9bf7da34a474c5bd3281ba93fa517c336562cdf92425f6ec729848ec97c07c35cca985652cdf398ac4663906f2822886612b3db9cf142e455b1d41a801566abb8d41c5682289ec2a57f9745f5eb844583b294a44e08ded45d0c662e7f4a200eec3eaf86c6aa34679f8b598783e70e786afc8c1e2e7204ec5a52d8fbb108003ef24d69f2a4b41c5e20594df2b4e29351f1c65c8c9af8ffee3cb9f5f824dd0811e3b8f57686b01f502d74581c4c6329bb09f896677afbcf37bd4e88397df76fe68a33c71792e60ce53c26225dc32997da6aa5476fbd4572da3c0483d80752fcb39b26e72a93e89247af5176b7544e7966bd1a34fd25c2adcc750266842af296f4b87e9f18ac6adcfd103ff22c4670d9b0403f3e50d5592e1efa093c43149d651424f779fc4e9ead4a33050bb25de77b4c501a6157350b5b9204bce269cff6f2611cee5a9fcb95aededa0b2588549d9726d13cbf8325ca7f45b018bda6b08ae8ed7e658cd307093f081f78f8660498d4baf2c2cd5f83623bc136ebd121cb1bcb9ccc5e6bb5807b3403930399c7f0cfc6d4dcc5519e67dc36635a6539d6e163875bf30c4c7c6b28d687b617c0387e7ca6bb48ab5f1e72b4edacfc0beea99554af8"}}}}, 0x0) sendmsg$nl_route_sched(r4, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000040)={0x0}}, 0x0) sendmsg$NFNL_MSG_ACCT_GET(r4, &(0x7f00000001c0)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x44801}, 0x40) ioctl$vim2m_VIDIOC_S_CTRL(r4, 0xc008561c, 0x0) add_key(0x0, 0x0, 0x0, 0x0, 0x0) creat(&(0x7f0000000000)='./file0\x00', 0xd931d3864d39dcdb) timer_settime(0x0, 0x0, &(0x7f0000000280)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) r5 = open(&(0x7f0000000000)='./file0\x00', 0x0, 0x1a1) fcntl$setlease(r5, 0x400, 0x1) execve(&(0x7f00000000c0)='./file0\x00', 0x0, 0x0) 7.025845478s ago: executing program 1 (id=1566): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000600)={0x11, 0x3, &(0x7f0000000200)=@framed, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r0 = openat$udambuf(0xffffffffffffff9c, 0x0, 0x2) r1 = memfd_create(&(0x7f00000000c0)='y\x105\xfb\xf7u\x83%:r\xc2\xb9x\xa4q\xc1\xea\x7f\x8cZ7`_4t\xcda\xa11\x11\x0e\xa1\xcf\x00\x00\x00\x00o~\x16\v\x03\n)\nL\x00'/60, 0x2) ftruncate(r1, 0x1000006) r2 = fsopen(0x0, 0x0) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000300)={0x0, 0x0, &(0x7f0000000240)={&(0x7f00000005c0)=@newqdisc={0x24}, 0x24}}, 0x0) r3 = socket(0x2a, 0x2, 0x0) getsockname$packet(r3, &(0x7f0000000200)={0x11, 0x0, 0x0, 0x1, 0x0, 0x6, @broadcast}, &(0x7f0000001480)=0x14) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f00000002c0)={0x0, 0x0, 0x0}, 0x0) r4 = socket$netlink(0x10, 0x3, 0x0) sendmmsg(r4, &(0x7f00000002c0), 0x40000000000009f, 0x0) sendmsg$nl_generic(0xffffffffffffffff, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x2) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r5 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r5, &(0x7f0000019680)=""/102392, 0x18ff8) fcntl$addseals(r1, 0x409, 0x7) ioctl$IOCTL_VMCI_CTX_SET_CPT_STATE(0xffffffffffffffff, 0x7b2, 0x0) r6 = syz_io_uring_setup(0xbdc, &(0x7f0000000640)={0x0, 0xec25, 0x8, 0x4, 0x40000133}, &(0x7f00000006c0), &(0x7f00000001c0)) io_uring_enter(r6, 0x847ba, 0x0, 0xe, 0x0, 0x0) stat(&(0x7f0000000ac0)='./file0\x00', &(0x7f0000000340)={0x0, 0x0, 0x0, 0x0, 0x0}) newfstatat(0xffffffffffffff9c, &(0x7f0000000fc0)='./file0\x00', &(0x7f0000001000)={0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x2000) sendmsg$netlink(r4, &(0x7f0000001100)={&(0x7f0000000080)=@kern={0x10, 0x0, 0x0, 0x4000000}, 0xc, 0x0, 0x0, &(0x7f0000001080)=[@rights={{0x18, 0x1, 0x1, [r3, r2]}}, @cred={{0x1c, 0x1, 0x2, {0x0, r7, r8}}}, @rights={{0x1c, 0x1, 0x1, [0xffffffffffffffff, r0, r4]}}], 0x58, 0x24000010}, 0x8004) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) openat$sndtimer(0xffffffffffffff9c, &(0x7f0000000000), 0x0) socket$nl_generic(0x10, 0x3, 0x10) 6.475570019s ago: executing program 2 (id=1567): bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, 0x0, &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) ioctl$TUNSETIFF(0xffffffffffffffff, 0x400454ca, 0x0) r0 = socket(0x400000000010, 0x3, 0x0) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000040)={0x11, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000820004000000000000000c00850000000f00000095"], &(0x7f0000000180)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000080)='sched_switch\x00', r1}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0xa, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r2 = getpid() sched_setscheduler(r2, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r3, &(0x7f0000000180)=@abs, 0x6e) sendmmsg$unix(r4, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r3, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r5 = add_key(&(0x7f0000000080)='user\x00', &(0x7f0000000000)={'syz', 0x2}, &(0x7f0000000040)='9', 0x1, 0xfffffffffffffffc) keyctl$chown(0x4, r5, 0xee00, 0xffffffffffffffff) socket$unix(0x1, 0x1, 0x0) sendmsg$nl_route_sched(r0, &(0x7f00000012c0)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000005c0)=@newqdisc={0x38, 0x24, 0x4ee4e6a52ff56541, 0x70bd2a, 0xffffffff, {0x0, 0x0, 0x0, 0x0, {0x0, 0xfff1}, {0xffff, 0xffff}}, [@qdisc_kind_options=@q_multiq={{0xb}, {0x8, 0x2, {0x0, 0x400}}}]}, 0x38}}, 0x0) 6.41328311s ago: executing program 5 (id=1568): openat$dma_heap(0xffffffffffffff9c, 0x0, 0x100, 0x0) ioctl$DMA_BUF_IOCTL_SYNC(0xffffffffffffffff, 0x40086200, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x10) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket$alg(0x26, 0x5, 0x0) bind$alg(r4, &(0x7f0000000080)={0x26, 'skcipher\x00', 0x0, 0x0, 'adiantum(xchacha20-simd,anubis-generic,nhpoly1305-sse2)\x00'}, 0x58) setsockopt$ALG_SET_KEY(r4, 0x117, 0x1, &(0x7f0000000300)="c99b57381801238c09d0ff0f1d0dbd301e5a47b2f3caa73dcd2a6a370554375a", 0x20) r5 = accept4(r4, 0x0, 0x0, 0x0) recvmmsg$unix(r5, &(0x7f0000001540)=[{{0x0, 0x0, &(0x7f0000000100)=[{&(0x7f0000000000)=""/44, 0x10b8c}], 0x1}}], 0x1, 0x2001, 0x0) sendmsg$nl_route_sched(r5, &(0x7f0000013a40)={0x0, 0x0, &(0x7f0000013a00)={&(0x7f00000158c0), 0x10b8c}}, 0x0) lseek(0xffffffffffffffff, 0x10000000005, 0x0) socket$can_bcm(0x1d, 0x2, 0x2) r6 = socket$inet6_sctp(0xa, 0x5, 0x84) syz_open_dev$video4linux(&(0x7f0000000400), 0x40, 0x1a1240) getsockopt$inet_sctp6_SCTP_SOCKOPT_CONNECTX3(r6, 0x84, 0x6f, 0x0, 0x0) 3.758543783s ago: executing program 1 (id=1569): syz_emit_vhci(&(0x7f0000000ec0)=ANY=[@ANYBLOB="041c261c19110600c30a14ed3db9083c92149031a1dbb24ea329b303f51fe1d6d19ca633e434649958c63f4f9d01dbb55023b0b5473e30b509b7a949f9107b8aa2"], 0x8) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) bpf$BPF_BTF_LOAD(0x12, 0x0, 0x0) syz_open_procfs$userns(0xffffffffffffffff, &(0x7f0000000700)) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r3, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000300)=ANY=[@ANYBLOB="18000000240001030000000000000000010000000400ae"], 0x18}, 0x1, 0x0, 0x0, 0x8001}, 0x4820) syz_genetlink_get_family_id$tipc(0x0, r3) recvmmsg(r3, &(0x7f0000000540)=[{{0x0, 0x0, 0x0}, 0x101}, {{0x0, 0x0, &(0x7f0000000500)=[{&(0x7f0000001c40)=""/4096, 0x1000}, {&(0x7f0000000340)=""/196, 0xc4}], 0x2}, 0x7}, {{0x0, 0x0, 0x0}, 0x2}, {{0x0, 0x0, &(0x7f0000000240)=[{0x0}, {&(0x7f0000000440)=""/160, 0xa0}, {&(0x7f0000000100)=""/119, 0x77}, {&(0x7f00000018c0)=""/147, 0x93}, {0x0}], 0x5}, 0x80000000}], 0x4, 0x40008062, 0x0) 3.58402687s ago: executing program 5 (id=1570): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0xfffffdca, &(0x7f0000000200)=0x400000bce) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) r0 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) r1 = syz_init_net_socket$nl_rdma(0x10, 0x3, 0x10) sendmsg$netlink(r1, 0x0, 0x0) 2.092620441s ago: executing program 5 (id=1571): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f00000001c0)=0x8) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x6770c000) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000100)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000440)={0x11, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r3 = getpgrp(0x0) r4 = syz_clone(0x0, 0x0, 0x0, 0x0, 0x0, 0x0) kcmp(r3, r4, 0x0, 0xffffffffffffffff, 0xffffffffffffffff) setsockopt$inet6_group_source_req(0xffffffffffffffff, 0x29, 0x2e, 0x0, 0x0) 864.586871ms ago: executing program 5 (id=1572): write$uinput_user_dev(0xffffffffffffffff, &(0x7f0000000400)={'syz1\x00', {0x3, 0x2, 0x6, 0xfffa}, 0x7, [0x8000, 0xc95a, 0xf, 0x8, 0x80, 0x5, 0x3, 0x7f, 0x20000006, 0x4d, 0x808, 0x5f, 0x9, 0x5, 0xffff2d37, 0xffffff01, 0x0, 0x3, 0x0, 0x5, 0x4, 0x0, 0x800, 0x3c5b, 0x1, 0x24, 0xd, 0x1, 0x0, 0xffffffff, 0xe661, 0x4, 0x7, 0x3, 0xc, 0x3, 0xfffffff9, 0x242, 0x3, 0xe, 0x0, 0x8b, 0x7, 0x17, 0x1, 0x7, 0x805, 0x3c, 0x8f, 0x6, 0x6, 0xc57, 0x5, 0x14, 0x8, 0x3ff, 0x6, 0x0, 0x5, 0x6, 0x1, 0x4, 0x10001, 0x40], [0x10000009, 0x9, 0x8000012f, 0x8000, 0x5, 0xfffffff5, 0x129432e6, 0xc8, 0xf9, 0xe, 0x2c3, 0x6ca, 0x9, 0xfffffffc, 0x3, 0x0, 0x0, 0x5, 0x2f, 0xe, 0x312, 0x7c, 0x2, 0x0, 0x4, 0x7, 0x7fff, 0x6, 0x400, 0x401, 0x6, 0x1, 0x1, 0x5, 0x1000005, 0x5f31, 0xd, 0x4e0, 0x2, 0x4, 0xb, 0x4, 0x9, 0x9, 0x9, 0x6, 0x47, 0x8000, 0x1, 0xfe000000, 0x7e78, 0x2, 0x4, 0x9, 0x3, 0x5, 0x2, 0x2, 0x3, 0x3, 0xbc45, 0x48c93690, 0x42, 0x3], [0x7, 0x408, 0x4, 0x5, 0xfffffffe, 0x100, 0x8d2, 0x9, 0x5, 0x6, 0x0, 0x5, 0x600b, 0xfffffff7, 0x4, 0x5, 0x0, 0x1ef, 0x5, 0x8, 0x86, 0x3, 0x303c, 0x1, 0xb, 0x7ff, 0xa, 0x2, 0x3, 0x20000008, 0x7fffffff, 0x2, 0x5, 0x38, 0x7, 0x200, 0x80, 0x3, 0x4, 0x2950bfaf, 0x1000, 0xa2, 0x7, 0xa9, 0x1, 0x6, 0x542c5705, 0xbf, 0xb, 0x803, 0x7ff, 0x12b, 0x4, 0x1, 0xa, 0x0, 0x5, 0x1c, 0x120000, 0x3, 0x2006, 0x80a2ed, 0x4, 0x25], [0x8, 0xbb33, 0x7, 0xb, 0x5, 0x938, 0x6, 0xb, 0x4, 0x1b9, 0xce7, 0x1a, 0x2, 0x56, 0xfffffff2, 0x6bd8490e, 0x1, 0x10000, 0x80000001, 0x7fff, 0xffff, 0xa61e, 0x80000000, 0x5, 0x1, 0xfffffffe, 0x14c, 0x60a7, 0x6, 0x16, 0x9, 0x80000000, 0x5, 0x4, 0xc8, 0x1, 0x5, 0x10000, 0x3, 0x7e, 0x100, 0x9602, 0x7, 0xaf, 0x8, 0x3, 0x226, 0x5, 0xfffffeff, 0x7, 0x30b1d693, 0xa1f, 0x40000f40, 0x7, 0x1, 0x6c1b, 0x0, 0x4, 0x5, 0xb1e, 0xd7, 0x200, 0xffff3441, 0xfff]}, 0x45c) socket$nl_generic(0x10, 0x3, 0x10) bpf$MAP_CREATE_RINGBUF(0x0, 0x0, 0x0) quotactl_fd$Q_SYNC(0xffffffffffffffff, 0xffffffff80000100, 0x0, 0x0) socket$can_bcm(0x1d, 0x2, 0x2) r0 = socket$kcm(0x2, 0x200000000000001, 0x0) sendmsg$inet(r0, &(0x7f0000000080)={&(0x7f0000000140)={0x2, 0x4001, @remote}, 0x10, 0x0}, 0x300048c1) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x7, 0x80000008a}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000200)=0x3) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x400010bce) r1 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r1, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='blkio.throttle.io_serviced_recursive\x00', 0x26e1, 0x0) setsockopt$sock_attach_bpf(r0, 0x1, 0x3e, &(0x7f0000000100)=r2, 0x4) r3 = syz_open_procfs(0x0, &(0x7f0000000240)='net/ip_tables_targets\x00') ioctl$IOC_PR_RESERVE(r3, 0x401070c9, 0x0) ioctl$BTRFS_IOC_SNAP_CREATE_V2(0xffffffffffffffff, 0x50009417, 0x0) sendmsg$inet(r0, &(0x7f0000000040)={0x0, 0xeafbff3, &(0x7f0000000000)=[{&(0x7f0000000300)="b8", 0xfffffdef}], 0x1, 0x0, 0x0, 0x10000000}, 0x52cc) 0s ago: executing program 5 (id=1573): prctl$PR_SET_SYSCALL_USER_DISPATCH_ON(0x3b, 0x1, 0x0, 0x0, &(0x7f0000006680)) r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) socket$kcm(0x2d, 0x2, 0x0) r1 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000400)={0x11, 0x0, 0x0, &(0x7f0000000280)='syzkaller\x00', 0xea, 0x0, 0x0, 0x41100, 0x4, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x3b, 0x0, 0x0, 0x10, 0x20000, @void, @value}, 0x94) r2 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r2, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000180)={&(0x7f00000004c0)=ANY=[@ANYBLOB="240000001e0001000000000000000000020000000100000000000000"], 0x24}, 0x1, 0x0, 0x0, 0x2}, 0x4044040) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={&(0x7f0000000000)='sched_switch\x00', r1, 0x0, 0x400}, 0x18) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r3 = getpid() sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r6 = socket$inet_icmp_raw(0x2, 0x3, 0x1) setsockopt$IP_VS_SO_SET_ADD(r6, 0x0, 0x482, &(0x7f0000000080)={0x11, @rand_addr, 0x0, 0x4, 'lblcr\x00', 0x0, 0xfffffff8}, 0x2c) fcntl$dupfd(r0, 0x0, r0) ioctl$TCFLSH(r0, 0x400455c8, 0x8000000001) ioctl$TIOCSETD(r0, 0x5412, &(0x7f0000000200)=0x1011) timer_create(0x2, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004}, &(0x7f0000bbdffc)) mount(&(0x7f00000000c0)=@nullb, &(0x7f0000000000)='./cgroup\x00', &(0x7f0000000040)='hfsplus\x00', 0x2000010, &(0x7f0000000100)='barrier') ioctl$TCSETS(r0, 0x5402, &(0x7f0000000080)={0x6, 0x3, 0x1, 0x0, 0x1b, "b3d3c8d5dd41c7b2c462285cb5a05d1baeefbd"}) kernel console output (not intermixed with test programs): rol pipe specified [ 306.714450][ T5896] usb 6-1: new full-speed USB device number 14 using dummy_hcd [ 306.775982][ T5896] usb 6-1: no configurations [ 306.798010][ T5896] usb 6-1: can't read configurations, error -22 [ 306.820770][ T5896] usb usb6-port1: unable to enumerate USB device [ 307.791276][ T9519] 9pnet_fd: Insufficient options for proto=fd [ 308.584245][ T9526] netlink: 'syz.0.478': attribute type 2 has an invalid length. [ 308.744841][ C0] vkms_vblank_simulate: vblank timer overrun [ 308.806482][ C0] vkms_vblank_simulate: vblank timer overrun [ 308.908860][ C0] vkms_vblank_simulate: vblank timer overrun [ 309.008868][ C0] vkms_vblank_simulate: vblank timer overrun [ 309.074479][ C0] vkms_vblank_simulate: vblank timer overrun [ 309.110682][ C0] vkms_vblank_simulate: vblank timer overrun [ 313.683704][ T2142] usb 4-1: new full-speed USB device number 6 using dummy_hcd [ 313.936650][ T2142] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 314.024010][ T2142] usb 4-1: config 0 has no interfaces? [ 314.072407][ T2142] usb 4-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 314.476355][ T2142] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 314.546163][ T9568] No control pipe specified [ 314.551948][ T2142] usb 4-1: config 0 descriptor?? [ 314.809287][ T5896] usb 4-1: USB disconnect, device number 6 [ 315.804156][ T9578] 9pnet_fd: Insufficient options for proto=fd [ 320.641066][ T9606] No control pipe specified [ 321.189404][ T9616] 9pnet_fd: Insufficient options for proto=fd [ 322.568197][ T5895] usb 5-1: new full-speed USB device number 4 using dummy_hcd [ 322.927399][ T5895] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 323.165427][ T5895] usb 5-1: config 0 has no interfaces? [ 323.193566][ T5895] usb 5-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 323.339853][ T5895] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 323.856731][ T5895] usb 5-1: config 0 descriptor?? [ 323.939069][ T5895] usb 5-1: can't set config #0, error -71 [ 323.979411][ T5895] usb 5-1: USB disconnect, device number 4 [ 324.103757][ T5894] usb 1-1: new high-speed USB device number 9 using dummy_hcd [ 324.293589][ T5894] usb 1-1: Using ep0 maxpacket: 16 [ 324.302251][ T5894] usb 1-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 324.322519][ T5894] usb 1-1: config 0 interface 0 has no altsetting 0 [ 324.350802][ T5894] usb 1-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 324.406202][ T5894] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 324.483185][ T5894] usb 1-1: config 0 descriptor?? [ 324.536731][ T5894] usbhid 1-1:0.0: couldn't find an input interrupt endpoint [ 326.759525][ T1290] ieee802154 phy0 wpan0: encryption failed: -22 [ 326.766310][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 327.770874][ T5895] usb 1-1: USB disconnect, device number 9 [ 329.132199][ T9675] No control pipe specified [ 330.562256][ T5895] usb 6-1: new full-speed USB device number 15 using dummy_hcd [ 330.828930][ T5895] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 331.075108][ T5895] usb 6-1: config 0 has no interfaces? [ 331.143675][ T5895] usb 6-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 331.224026][ T5895] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 331.305037][ T5895] usb 6-1: config 0 descriptor?? [ 331.597072][ T2142] usb 6-1: USB disconnect, device number 15 [ 333.330611][ T9723] virtio-fs: tag not found [ 334.910558][ T9736] No control pipe specified [ 337.663733][ T5999] usb 6-1: new full-speed USB device number 16 using dummy_hcd [ 338.430631][ T5999] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 338.463764][ T5999] usb 6-1: config 0 has 0 interfaces, different from the descriptor's value: 2 [ 338.472869][ T5999] usb 6-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 338.482840][ T5999] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 338.542621][ T5999] usb 6-1: config 0 descriptor?? [ 339.894289][ T5999] usb 6-1: USB disconnect, device number 16 [ 340.035584][ T9774] autofs: Unknown parameter '0x0000000000000000' [ 340.189229][ T9778] siw: device registration error -23 [ 340.394653][ T9778] netlink: 8 bytes leftover after parsing attributes in process `syz.1.553'. [ 341.338539][ T9778] nbd: socks must be embedded in a SOCK_ITEM attr [ 342.487759][ T5896] usb 6-1: new high-speed USB device number 17 using dummy_hcd [ 342.645908][ T5896] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 342.663927][ T5896] usb 6-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 342.696093][ T5896] usb 6-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 342.710431][ T5896] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 342.752156][ T5896] usb 6-1: Product: syz [ 342.799808][ T5896] usb 6-1: Manufacturer: syz [ 342.819236][ T5896] usb 6-1: SerialNumber: syz [ 342.850200][ T5896] usb 6-1: config 0 descriptor?? [ 343.209493][ T10] usb 6-1: USB disconnect, device number 17 [ 347.861935][ T9830] autofs: Unknown parameter 'fd0x0000000000000000' [ 348.923929][ T5999] usb 5-1: new full-speed USB device number 5 using dummy_hcd [ 349.397361][ T5999] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 349.407841][ T5999] usb 5-1: config 0 has 0 interfaces, different from the descriptor's value: 2 [ 349.418181][ T5999] usb 5-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 349.428391][ T5999] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 349.503811][ T5999] usb 5-1: config 0 descriptor?? [ 350.216899][ T5895] usb 5-1: USB disconnect, device number 5 [ 354.048859][ T9881] autofs: Unknown parameter 'fd0x0000000000000000' [ 356.133555][ T5894] usb 4-1: new high-speed USB device number 7 using dummy_hcd [ 356.605211][ T5894] usb 4-1: config 0 has no interfaces? [ 356.803667][ T5894] usb 4-1: New USB device found, idVendor=1908, idProduct=1315, bcdDevice= 0.00 [ 356.813007][ T5894] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 356.880394][ T5894] usb 4-1: config 0 descriptor?? [ 357.161272][ T9895] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 357.251499][ T9895] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 357.749393][ T5134] Bluetooth: hci5: adv larger than maximum supported [ 357.749429][ T5134] Bluetooth: hci5: Malformed LE Event: 0x0d [ 357.769149][ T5896] usb 4-1: USB disconnect, device number 7 [ 357.834040][ T5895] usb 3-1: new full-speed USB device number 11 using dummy_hcd [ 358.020886][ T5895] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 358.072960][ T5895] usb 3-1: config 0 has 0 interfaces, different from the descriptor's value: 2 [ 358.174395][ T5895] usb 3-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 358.203537][ T5895] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 358.234751][ T5895] usb 3-1: config 0 descriptor?? [ 358.365069][ T9915] autofs: Unknown parameter 'fd0x0000000000000000' [ 358.562851][ T5894] usb 3-1: USB disconnect, device number 11 [ 366.171826][ T5894] usb 6-1: new high-speed USB device number 18 using dummy_hcd [ 366.319154][ T5895] usb 2-1: new full-speed USB device number 2 using dummy_hcd [ 366.349057][ T5894] usb 6-1: device descriptor read/64, error -71 [ 366.875942][ T5895] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 366.923719][ T5894] usb 6-1: new high-speed USB device number 19 using dummy_hcd [ 366.924299][ T5895] usb 2-1: config 0 has 0 interfaces, different from the descriptor's value: 2 [ 366.993527][ T5895] usb 2-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 367.043822][ T5895] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 367.084865][ T5894] usb 6-1: device descriptor read/64, error -71 [ 367.095756][ T5895] usb 2-1: config 0 descriptor?? [ 367.214246][ T5894] usb usb6-port1: attempt power cycle [ 367.311313][ T5895] usb 2-1: USB disconnect, device number 2 [ 367.589181][ T5894] usb 6-1: new high-speed USB device number 20 using dummy_hcd [ 367.694751][ T5894] usb 6-1: device descriptor read/8, error -71 [ 367.963841][ T5894] usb 6-1: new high-speed USB device number 21 using dummy_hcd [ 368.030331][ T5894] usb 6-1: device descriptor read/8, error -71 [ 368.443870][ T5894] usb usb6-port1: unable to enumerate USB device [ 369.362896][T10000] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(13) [ 369.369548][T10000] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 369.388227][T10000] vhci_hcd vhci_hcd.0: Device attached [ 369.502419][T10000] vhci_hcd vhci_hcd.0: pdev(1) rhport(1) sockfd(15) [ 369.509095][T10000] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 369.583813][ T5894] vhci_hcd: vhci_device speed not set [ 369.618189][T10000] vhci_hcd vhci_hcd.0: Device attached [ 369.643661][ T5894] usb 35-1: new full-speed USB device number 2 using vhci_hcd [ 369.713210][T10002] vhci_hcd vhci_hcd.0: pdev(1) rhport(2) sockfd(17) [ 369.719865][T10002] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 369.789744][T10012] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(20) [ 369.796413][T10012] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 369.813095][T10012] vhci_hcd vhci_hcd.0: Device attached [ 369.840442][T10002] vhci_hcd vhci_hcd.0: Device attached [ 369.848495][T10000] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 370.000918][T10000] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 370.058092][T10002] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 370.099554][T10000] vhci_hcd vhci_hcd.0: pdev(1) rhport(6) sockfd(28) [ 370.106204][T10000] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 370.217271][T10000] vhci_hcd vhci_hcd.0: Device attached [ 370.300491][T10019] vhci_hcd: connection closed [ 370.302714][T10013] vhci_hcd: connection closed [ 370.304847][T10015] vhci_hcd: connection closed [ 370.307843][ T76] vhci_hcd: stop threads [ 370.321453][T10005] vhci_hcd: connection reset by peer [ 370.326800][T10009] vhci_hcd: connection closed [ 370.357627][ T76] vhci_hcd: release socket [ 370.921350][ T76] vhci_hcd: disconnect device [ 370.960436][ T76] vhci_hcd: stop threads [ 371.038345][ T76] vhci_hcd: release socket [ 371.087599][ T76] vhci_hcd: disconnect device [ 371.137307][ T76] vhci_hcd: stop threads [ 371.173299][ T76] vhci_hcd: release socket [ 371.186038][ T76] vhci_hcd: disconnect device [ 371.221630][ T76] vhci_hcd: stop threads [ 371.267809][ T76] vhci_hcd: release socket [ 371.307668][ T76] vhci_hcd: disconnect device [ 371.364167][ T76] vhci_hcd: stop threads [ 371.368475][ T76] vhci_hcd: release socket [ 371.384034][ T76] vhci_hcd: disconnect device [ 374.213552][ T5895] usb 3-1: new full-speed USB device number 12 using dummy_hcd [ 374.409599][ T5895] usb 3-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 374.455543][ T5895] usb 3-1: config 0 has 0 interfaces, different from the descriptor's value: 2 [ 374.463607][ T5999] usb 4-1: new high-speed USB device number 8 using dummy_hcd [ 374.483160][ T5895] usb 3-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 374.611602][ T5895] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 374.764703][ T5895] usb 3-1: config 0 descriptor?? [ 374.793740][ T5999] usb 4-1: device descriptor read/64, error -71 [ 374.815081][ T5894] vhci_hcd: vhci_device speed not set [ 375.301451][ T5895] usb 3-1: USB disconnect, device number 12 [ 375.343556][ T5999] usb 4-1: new high-speed USB device number 9 using dummy_hcd [ 375.513536][ T5999] usb 4-1: device descriptor read/64, error -71 [ 375.624167][ T5999] usb usb4-port1: attempt power cycle [ 376.033608][ T5999] usb 4-1: new high-speed USB device number 10 using dummy_hcd [ 376.143668][ T5999] usb 4-1: device descriptor read/8, error -71 [ 376.574322][ T5999] usb 4-1: new high-speed USB device number 11 using dummy_hcd [ 376.810349][ T5999] usb 4-1: device descriptor read/8, error -71 [ 377.003803][ T5896] usb usb36-port1: attempt power cycle [ 377.524452][ T5999] usb usb4-port1: unable to enumerate USB device [ 378.246342][ T5896] usb usb36-port1: unable to enumerate USB device [ 378.271290][ T30] audit: type=1800 audit(2000000187.220:2): pid=10078 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.0.645" name="bus" dev="overlay" ino=592 res=0 errno=0 [ 379.570757][T10087] netlink: 'syz.3.648': attribute type 1 has an invalid length. [ 379.578740][T10087] netlink: 224 bytes leftover after parsing attributes in process `syz.3.648'. [ 381.943677][ T48] usb 2-1: new full-speed USB device number 3 using dummy_hcd [ 382.196295][ T48] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 382.267742][ T48] usb 2-1: config 0 has 0 interfaces, different from the descriptor's value: 2 [ 382.869492][ T48] usb 2-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 382.907844][ T48] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 382.968642][ T48] usb 2-1: config 0 descriptor?? [ 383.283379][ T48] usb 2-1: USB disconnect, device number 3 [ 388.257440][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 393.221856][ T30] audit: type=1800 audit(2000000202.550:3): pid=10150 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.4.665" name="bus" dev="overlay" ino=577 res=0 errno=0 [ 393.441432][T10160] virtio-fs: tag not found [ 398.364411][T10196] siw: device registration error -23 [ 398.410490][T10196] netlink: 8 bytes leftover after parsing attributes in process `syz.2.680'. [ 398.419667][T10196] nbd: socks must be embedded in a SOCK_ITEM attr [ 400.625000][ T30] audit: type=1800 audit(2000000209.950:4): pid=10211 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.2.685" name="bus" dev="overlay" ino=608 res=0 errno=0 [ 401.544316][T10225] netlink: 'syz.0.691': attribute type 1 has an invalid length. [ 401.566232][T10225] netlink: 224 bytes leftover after parsing attributes in process `syz.0.691'. [ 403.504420][T10247] bridge3: entered promiscuous mode [ 403.567751][T10213] befs: (nbd4): No write support. Marking filesystem read-only [ 403.638915][T10213] syz.4.686: attempt to access beyond end of device [ 403.638915][T10213] nbd4: rw=0, sector=0, nr_sectors = 2 limit=0 [ 403.713823][ T969] usb 1-1: new full-speed USB device number 10 using dummy_hcd [ 403.764400][T10213] befs: (nbd4): unable to read superblock [ 403.897551][ T969] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 403.908073][ T969] usb 1-1: config 0 has 1 interface, different from the descriptor's value: 2 [ 403.975759][ T969] usb 1-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 404.022774][ T969] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 404.158586][ T969] usb 1-1: config 0 descriptor?? [ 404.239111][ T969] dvb-usb: found a 'Artec T1 USB2.0' in warm state. [ 404.304808][ T969] dvb-usb: bulk message failed: -22 (3/0) [ 404.376294][ T969] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 404.435850][ T969] dvbdev: DVB: registering new adapter (Artec T1 USB2.0) [ 404.515682][ T969] usb 1-1: media controller created [ 404.625158][ T969] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 404.802136][ T30] audit: type=1800 audit(2000000214.030:5): pid=10256 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.5.700" name="bus" dev="overlay" ino=662 res=0 errno=0 [ 404.822646][ C0] vkms_vblank_simulate: vblank timer overrun [ 405.048496][ T969] dvb-usb: bulk message failed: -22 (6/0) [ 405.135319][ T969] dvb-usb: no frontend was attached by 'Artec T1 USB2.0' [ 405.394677][ T969] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.0/usb1/1-1/input/input15 [ 405.522074][ T969] dvb-usb: schedule remote query interval to 150 msecs. [ 405.633576][ T969] dvb-usb: Artec T1 USB2.0 successfully initialized and connected. [ 405.742564][ T969] usb 1-1: USB disconnect, device number 10 [ 406.287912][ T969] dvb-usb: Artec T1 USB2.0 successfully deinitialized and disconnected. [ 408.653537][ T5999] usb 6-1: new high-speed USB device number 22 using dummy_hcd [ 408.858512][ T5999] usb 6-1: config 0 has no interfaces? [ 408.876309][ T5999] usb 6-1: New USB device found, idVendor=1908, idProduct=1315, bcdDevice= 0.00 [ 409.292079][ T5999] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 409.349132][ T5999] usb 6-1: config 0 descriptor?? [ 409.588706][T10281] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 409.614371][T10281] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 409.648904][ T969] usb 6-1: USB disconnect, device number 22 [ 409.763780][ T5999] usb 2-1: new high-speed USB device number 4 using dummy_hcd [ 409.943642][ T5999] usb 2-1: Using ep0 maxpacket: 16 [ 409.951010][ T5999] usb 2-1: config 0 interface 0 altsetting 2 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 409.993697][ T5999] usb 2-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 410.003641][ T5999] usb 2-1: config 0 interface 0 has no altsetting 0 [ 410.010292][ T5999] usb 2-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 410.019639][ T5999] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 410.034883][ T5999] usb 2-1: config 0 descriptor?? [ 411.075973][ T5999] usb 2-1: USB disconnect, device number 4 [ 411.278610][T10296] netlink: 8 bytes leftover after parsing attributes in process `syz.3.713'. [ 411.433612][T10302] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(13) [ 411.440302][T10302] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 411.458073][T10302] vhci_hcd vhci_hcd.0: Device attached [ 411.503545][T10302] vhci_hcd vhci_hcd.0: pdev(5) rhport(1) sockfd(15) [ 411.510208][T10302] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 411.567117][T10302] vhci_hcd vhci_hcd.0: Device attached [ 411.610546][T10307] vhci_hcd vhci_hcd.0: pdev(5) rhport(2) sockfd(17) [ 411.617213][T10307] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 411.653645][ T5842] vhci_hcd: vhci_device speed not set [ 411.677970][T10307] vhci_hcd vhci_hcd.0: Device attached [ 411.686774][T10316] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 411.721823][T10302] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(20) [ 411.728465][T10302] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 411.745505][T10302] vhci_hcd vhci_hcd.0: Device attached [ 411.745880][ T5842] usb 43-1: new full-speed USB device number 2 using vhci_hcd [ 411.823559][T10311] netlink: 36 bytes leftover after parsing attributes in process `syz.1.716'. [ 411.837088][T10307] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 412.538727][T10327] bridge2: entered promiscuous mode [ 412.846316][T10328] befs: (nbd0): No write support. Marking filesystem read-only [ 412.856268][T10328] syz.0.718: attempt to access beyond end of device [ 412.856268][T10328] nbd0: rw=0, sector=0, nr_sectors = 2 limit=0 [ 412.869571][T10328] befs: (nbd0): unable to read superblock [ 413.274538][T10316] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 413.506849][T10316] vhci_hcd vhci_hcd.0: pdev(5) rhport(6) sockfd(29) [ 413.513523][T10316] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 413.823565][T10316] vhci_hcd vhci_hcd.0: Device attached [ 413.928230][T10329] vhci_hcd: connection closed [ 413.928920][ T1028] vhci_hcd: stop threads [ 413.938306][T10314] vhci_hcd: connection closed [ 413.948832][T10303] vhci_hcd: connection reset by peer [ 413.959096][T10308] vhci_hcd: connection closed [ 413.959372][T10305] vhci_hcd: connection closed [ 413.963411][ T1028] vhci_hcd: release socket [ 414.032739][ T1028] vhci_hcd: disconnect device [ 414.051669][ T1028] vhci_hcd: stop threads [ 414.103043][ T1028] vhci_hcd: release socket [ 414.111632][ T1028] vhci_hcd: disconnect device [ 414.123273][ T1028] vhci_hcd: stop threads [ 414.135911][ T1028] vhci_hcd: release socket [ 414.145130][ T1028] vhci_hcd: disconnect device [ 414.152001][ T1028] vhci_hcd: stop threads [ 414.171658][ T1028] vhci_hcd: release socket [ 414.294161][ T1028] vhci_hcd: disconnect device [ 414.339098][ T1028] vhci_hcd: stop threads [ 414.766136][ T1028] vhci_hcd: release socket [ 414.778792][ T1028] vhci_hcd: disconnect device [ 415.084350][ T969] usb 5-1: new high-speed USB device number 6 using dummy_hcd [ 415.435642][ T969] usb 5-1: config 0 has no interfaces? [ 415.442970][ T969] usb 5-1: New USB device found, idVendor=1908, idProduct=1315, bcdDevice= 0.00 [ 415.583654][ T969] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 415.641116][ T969] usb 5-1: config 0 descriptor?? [ 415.694078][ T48] usb 6-1: new high-speed USB device number 23 using dummy_hcd [ 415.893754][ T48] usb 6-1: Using ep0 maxpacket: 16 [ 415.920346][ T48] usb 6-1: config 0 interface 0 altsetting 2 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 415.931868][T10346] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 415.954121][T10346] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 415.956460][ T48] usb 6-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 415.972566][ T48] usb 6-1: config 0 interface 0 has no altsetting 0 [ 415.980164][ T48] usb 6-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 415.992744][ T48] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 416.033727][ T5894] usb 5-1: USB disconnect, device number 6 [ 416.091123][ T48] usb 6-1: config 0 descriptor?? [ 416.731932][T10366] x_tables: ip_tables: rpfilter match: used from hooks OUTPUT, but only valid from PREROUTING [ 417.104523][ T969] usb 6-1: USB disconnect, device number 23 [ 417.163620][ T5842] vhci_hcd: vhci_device speed not set [ 417.759445][ T30] audit: type=1800 audit(2000000005.910:6): pid=10377 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.1.735" name="bus" dev="overlay" ino=627 res=0 errno=0 [ 419.378289][ T5999] usb usb44-port1: attempt power cycle [ 421.315353][ T5999] usb usb44-port1: unable to enumerate USB device [ 422.438406][T10402] netlink: 36 bytes leftover after parsing attributes in process `syz.0.741'. [ 423.848293][T10420] openvswitch: netlink: Either Ethernet header or EtherType is required. [ 426.591486][T10446] netlink: 36 bytes leftover after parsing attributes in process `syz.5.760'. [ 427.446706][ T30] audit: type=1800 audit(2000000000.420:7): pid=10449 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.4.756" name="bus" dev="overlay" ino=670 res=0 errno=0 [ 428.682938][T10466] trusted_key: encrypted_key: keylen parameter is missing [ 433.415100][T10492] netlink: 36 bytes leftover after parsing attributes in process `syz.5.773'. [ 438.014237][T10541] netlink: 36 bytes leftover after parsing attributes in process `syz.4.791'. [ 439.043295][T10560] netlink: 24 bytes leftover after parsing attributes in process `syz.3.797'. [ 440.519814][T10578] No control pipe specified [ 441.342126][T10595] netlink: 36 bytes leftover after parsing attributes in process `syz.3.807'. [ 441.618009][T10593] netlink: 8 bytes leftover after parsing attributes in process `syz.0.809'. [ 444.162045][T10639] netlink: 'syz.3.820': attribute type 2 has an invalid length. [ 444.468941][T10604] bridge3: entered promiscuous mode [ 444.674664][T10604] befs: (nbd0): No write support. Marking filesystem read-only [ 444.683640][T10604] syz.0.813: attempt to access beyond end of device [ 444.683640][T10604] nbd0: rw=0, sector=0, nr_sectors = 2 limit=0 [ 444.698888][T10604] befs: (nbd0): unable to read superblock [ 445.449783][T10651] netlink: 16 bytes leftover after parsing attributes in process `syz.3.823'. [ 445.524839][T10651] netlink: 36 bytes leftover after parsing attributes in process `syz.3.823'. [ 446.575821][T10656] netlink: 60 bytes leftover after parsing attributes in process `syz.1.825'. [ 446.586067][T10656] unsupported nlmsg_type 40 [ 449.639316][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 449.695659][T10693] netlink: 'syz.4.836': attribute type 2 has an invalid length. [ 449.862307][T10687] netlink: 16 bytes leftover after parsing attributes in process `syz.3.838'. [ 449.888689][T10687] netlink: 36 bytes leftover after parsing attributes in process `syz.3.838'. [ 452.795633][T10713] bridge0: port 2(bridge_slave_1) entered disabled state [ 452.803289][T10713] bridge0: port 1(bridge_slave_0) entered disabled state [ 453.679551][T10713] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 453.730173][T10713] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 454.043171][T10713] netdevsim netdevsim3 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 454.059300][T10713] netdevsim netdevsim3 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 454.089141][T10713] netdevsim netdevsim3 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 454.122003][T10713] netdevsim netdevsim3 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 454.239858][T10713] bridge1: left promiscuous mode [ 454.248620][T10713] bridge2: left promiscuous mode [ 454.405099][T10705] lo speed is unknown, defaulting to 1000 [ 454.598266][T10733] befs: (nbd2): No write support. Marking filesystem read-only [ 454.760630][T10733] syz.2.846: attempt to access beyond end of device [ 454.760630][T10733] nbd2: rw=0, sector=0, nr_sectors = 2 limit=0 [ 454.850783][T10731] bridge2: entered promiscuous mode [ 454.856611][T10733] befs: (nbd2): unable to read superblock [ 456.041663][ T5999] usb 1-1: new full-speed USB device number 11 using dummy_hcd [ 456.380016][ T5999] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 456.403817][ T5999] usb 1-1: config 0 has 1 interface, different from the descriptor's value: 2 [ 456.412914][ T5999] usb 1-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 456.452827][ T5999] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 456.529675][ T5999] usb 1-1: config 0 descriptor?? [ 456.618162][ T5999] dvb-usb: found a 'Artec T1 USB2.0' in warm state. [ 456.668704][ T5999] dvb-usb: bulk message failed: -22 (3/0) [ 456.728579][ T5999] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 456.881393][ T5999] dvbdev: DVB: registering new adapter (Artec T1 USB2.0) [ 456.898691][ T5999] usb 1-1: media controller created [ 456.963915][ T5999] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 457.100612][ T5999] dvb-usb: bulk message failed: -22 (6/0) [ 457.126125][ T5999] dvb-usb: no frontend was attached by 'Artec T1 USB2.0' [ 457.330748][T10755] netlink: 16 bytes leftover after parsing attributes in process `syz.5.856'. [ 457.387567][T10755] netlink: 36 bytes leftover after parsing attributes in process `syz.5.856'. [ 457.869659][ T5999] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.0/usb1/1-1/input/input18 [ 458.047670][ T5999] dvb-usb: schedule remote query interval to 150 msecs. [ 458.363583][ T5999] dvb-usb: Artec T1 USB2.0 successfully initialized and connected. [ 458.424909][ T5999] usb 1-1: USB disconnect, device number 11 [ 459.257745][ T30] audit: type=1800 audit(2000000001.260:8): pid=10770 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.0.858" name="bus" dev="overlay" ino=768 res=0 errno=0 [ 459.647657][ T5999] dvb-usb: Artec T1 USB2.0 successfully deinitialized and disconnected. [ 460.432400][T10784] siw: device registration error -23 [ 460.754513][T10784] netlink: 8 bytes leftover after parsing attributes in process `syz.3.863'. [ 460.930562][T10784] nbd: socks must be embedded in a SOCK_ITEM attr [ 461.988245][T10794] netlink: 'syz.4.864': attribute type 1 has an invalid length. [ 461.996330][T10794] netlink: 224 bytes leftover after parsing attributes in process `syz.4.864'. [ 463.948929][T10822] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(13) [ 463.955612][T10822] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 463.970058][T10822] vhci_hcd vhci_hcd.0: Device attached [ 464.003994][ T5999] usb 6-1: new full-speed USB device number 24 using dummy_hcd [ 464.014451][T10822] vhci_hcd vhci_hcd.0: pdev(2) rhport(1) sockfd(15) [ 464.021093][T10822] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 464.030020][T10822] vhci_hcd vhci_hcd.0: Device attached [ 464.071418][T10827] vhci_hcd vhci_hcd.0: pdev(2) rhport(2) sockfd(17) [ 464.078094][T10827] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 464.089049][T10827] vhci_hcd vhci_hcd.0: Device attached [ 464.145275][T10822] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(19) [ 464.151959][T10822] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 464.161168][T10042] vhci_hcd: vhci_device speed not set [ 464.173979][T10822] vhci_hcd vhci_hcd.0: Device attached [ 464.206274][ T5999] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 464.224006][ T5999] usb 6-1: config 0 has 1 interface, different from the descriptor's value: 2 [ 464.240686][T10822] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 464.253055][T10042] usb 37-1: new full-speed USB device number 2 using vhci_hcd [ 464.274972][T10822] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 464.286558][ T5999] usb 6-1: New USB device found, idVendor=05d8, idProduct=810a, bcdDevice=92.b8 [ 464.319411][ T5999] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 464.329820][T10822] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 464.370465][T10827] vhci_hcd vhci_hcd.0: pdev(2) rhport(6) sockfd(28) [ 464.377154][T10827] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 464.392090][ T5999] usb 6-1: config 0 descriptor?? [ 464.425165][ T5999] dvb-usb: found a 'Artec T1 USB2.0' in warm state. [ 464.448212][T10827] vhci_hcd vhci_hcd.0: Device attached [ 464.470971][ T5999] dvb-usb: bulk message failed: -22 (3/0) [ 464.549820][ T5999] dvb-usb: will use the device's hardware PID filter (table count: 16). [ 464.605922][ T5999] dvbdev: DVB: registering new adapter (Artec T1 USB2.0) [ 464.647249][ T5999] usb 6-1: media controller created [ 464.671126][ T5999] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 464.702569][T10830] vhci_hcd: connection closed [ 464.713723][ T5951] vhci_hcd: stop threads [ 464.733071][T10823] vhci_hcd: connection reset by peer [ 464.738702][T10825] vhci_hcd: connection closed [ 464.739382][ T5951] vhci_hcd: release socket [ 464.753919][T10828] vhci_hcd: connection closed [ 464.756354][ T5999] dvb-usb: bulk message failed: -22 (6/0) [ 464.801007][ T5951] vhci_hcd: disconnect device [ 464.803631][ T5999] dvb-usb: no frontend was attached by 'Artec T1 USB2.0' [ 464.807971][T10832] vhci_hcd: connection closed [ 464.850430][ T5951] vhci_hcd: stop threads [ 464.877510][ T5951] vhci_hcd: release socket [ 464.888209][ T5999] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.5/usb6/6-1/input/input19 [ 464.889926][ T5951] vhci_hcd: disconnect device [ 465.283419][ T5999] dvb-usb: schedule remote query interval to 150 msecs. [ 465.290740][ T5999] dvb-usb: Artec T1 USB2.0 successfully initialized and connected. [ 465.445294][ T48] dvb-usb: bulk message failed: -22 (1/0) [ 465.488899][ T30] audit: type=1800 audit(2000000008.040:9): pid=10841 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.1.874" name="bus" dev="overlay" ino=764 res=0 errno=0 [ 465.509383][ C1] vkms_vblank_simulate: vblank timer overrun [ 465.516460][T10807] ptm ptm0: ldisc open failed (-12), clearing slot 0 [ 465.532318][ T48] dvb-usb: error while querying for an remote control event. [ 465.709476][ T5999] usb 6-1: USB disconnect, device number 24 [ 465.975882][ T5951] vhci_hcd: stop threads [ 466.042808][ T5951] vhci_hcd: release socket [ 466.108409][ T5951] vhci_hcd: disconnect device [ 466.464629][ T5951] vhci_hcd: stop threads [ 466.468917][ T5951] vhci_hcd: release socket [ 466.510856][ T5951] vhci_hcd: disconnect device [ 466.544011][ T5951] vhci_hcd: stop threads [ 466.544037][ T5951] vhci_hcd: release socket [ 466.544094][ T5951] vhci_hcd: disconnect device [ 466.911932][T10848] netlink: 56 bytes leftover after parsing attributes in process `syz.4.875'. [ 467.343889][ T5999] dvb-usb: Artec T1 USB2.0 successfully deinitialized and disconnected. [ 469.489559][T10042] vhci_hcd: vhci_device speed not set [ 470.826833][T10886] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(13) [ 470.833523][T10886] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 470.907790][T10886] vhci_hcd vhci_hcd.0: Device attached [ 470.935353][T10886] vhci_hcd vhci_hcd.0: pdev(1) rhport(1) sockfd(15) [ 470.942023][T10886] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 470.945022][ T5842] usb usb38-port1: attempt power cycle [ 470.977425][T10886] vhci_hcd vhci_hcd.0: Device attached [ 471.024511][ T48] usb 6-1: new high-speed USB device number 25 using dummy_hcd [ 471.040851][T10895] vhci_hcd vhci_hcd.0: pdev(1) rhport(2) sockfd(17) [ 471.047501][T10895] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 471.091511][T10895] vhci_hcd vhci_hcd.0: Device attached [ 471.097252][ T5999] vhci_hcd: vhci_device speed not set [ 471.105374][T10886] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(20) [ 471.112018][T10886] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 471.123545][T10886] vhci_hcd vhci_hcd.0: Device attached [ 471.129305][T10895] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 471.139450][T10886] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 471.152691][T10886] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 471.164887][ T5999] usb 35-1: new full-speed USB device number 3 using vhci_hcd [ 471.173088][T10886] vhci_hcd vhci_hcd.0: pdev(1) rhport(6) sockfd(27) [ 471.179726][T10886] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 471.260275][ T48] usb 6-1: Using ep0 maxpacket: 8 [ 471.274695][T10886] vhci_hcd vhci_hcd.0: Device attached [ 471.332603][ T48] usb 6-1: config 0 has an invalid interface number: 33 but max is 1 [ 471.530959][ T48] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 471.547923][ T48] usb 6-1: config 0 has 1 interface, different from the descriptor's value: 2 [ 471.582440][ T48] usb 6-1: config 0 has no interface number 0 [ 471.609549][ T48] usb 6-1: config 0 interface 33 altsetting 0 endpoint 0x6 has an invalid bInterval 0, changing to 7 [ 471.612509][T10904] vhci_hcd: connection closed [ 471.868474][ T5842] usb usb38-port1: unable to enumerate USB device [ 471.970023][T10897] vhci_hcd: connection closed [ 471.972985][ T48] usb 6-1: New USB device found, idVendor=2040, idProduct=2950, bcdDevice=85.f1 [ 471.980723][T10889] vhci_hcd: connection reset by peer [ 471.987072][T10893] vhci_hcd: connection closed [ 471.987745][T10901] vhci_hcd: connection closed [ 472.002700][ T5951] vhci_hcd: stop threads [ 472.034416][ T5951] vhci_hcd: release socket [ 472.035409][ T48] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 472.047252][ T5951] vhci_hcd: disconnect device [ 472.055888][ T5951] vhci_hcd: stop threads [ 472.060242][ T5951] vhci_hcd: release socket [ 472.084940][ T48] usb 6-1: Product: syz [ 472.089172][ T48] usb 6-1: Manufacturer: syz [ 472.123525][ T48] usb 6-1: SerialNumber: syz [ 472.124851][ T5951] vhci_hcd: disconnect device [ 472.147411][ T5951] vhci_hcd: stop threads [ 472.151990][ T5951] vhci_hcd: release socket [ 472.167658][ T5951] vhci_hcd: disconnect device [ 472.176050][ T48] usb 6-1: config 0 descriptor?? [ 472.208149][ T5951] vhci_hcd: stop threads [ 472.212481][ T5951] vhci_hcd: release socket [ 472.238201][ T48] pvrusb2: Hardware description: WinTV PVR USB2 Model 29xxx [ 472.255217][ T5951] vhci_hcd: disconnect device [ 472.279401][ T5951] vhci_hcd: stop threads [ 472.303887][ T5951] vhci_hcd: release socket [ 472.308457][ T5951] vhci_hcd: disconnect device [ 472.530609][ T2334] pvrusb2: Invalid write control endpoint [ 472.592441][ T2334] usb 6-1: Direct firmware load for v4l-pvrusb2-29xxx-01.fw failed with error -2 [ 472.624651][ T2334] usb 6-1: Falling back to sysfs fallback for: v4l-pvrusb2-29xxx-01.fw [ 473.089319][ T48] usb 6-1: USB disconnect, device number 25 [ 474.668545][T10937] netlink: 56 bytes leftover after parsing attributes in process `syz.5.899'. [ 476.233560][ T2142] usb 3-1: new high-speed USB device number 13 using dummy_hcd [ 476.353710][ T5999] vhci_hcd: vhci_device speed not set [ 476.451794][ T2142] usb 3-1: config 0 has no interfaces? [ 476.460316][ T2142] usb 3-1: New USB device found, idVendor=1908, idProduct=1315, bcdDevice= 0.00 [ 476.502094][ T2142] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 476.622943][ T2142] usb 3-1: config 0 descriptor?? [ 476.892532][T10949] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 476.909164][T10949] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 476.952311][ T2142] usb 3-1: USB disconnect, device number 13 [ 477.784943][T10972] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(12) [ 477.791619][T10972] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 477.804626][ T5894] usb usb36-port1: attempt power cycle [ 477.881438][T10972] vhci_hcd vhci_hcd.0: Device attached [ 477.937952][T10980] vhci_hcd vhci_hcd.0: pdev(1) rhport(1) sockfd(16) [ 477.944628][T10980] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 478.027516][T10980] vhci_hcd vhci_hcd.0: Device attached [ 478.060299][T10967] vhci_hcd vhci_hcd.0: pdev(1) rhport(2) sockfd(14) [ 478.066961][T10967] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 478.143920][T10967] vhci_hcd vhci_hcd.0: Device attached [ 478.174768][T10972] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(18) [ 478.181443][T10972] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 478.242906][T10967] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 478.263594][ T5894] usb 36-1: SetAddress Request (9) to port 0 [ 478.288098][ T5894] usb 36-1: new SuperSpeed USB device number 9 using vhci_hcd [ 478.297901][T10972] vhci_hcd vhci_hcd.0: Device attached [ 478.325781][T10980] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 478.374513][T10967] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 478.427151][T10967] vhci_hcd vhci_hcd.0: pdev(1) rhport(6) sockfd(27) [ 478.433827][T10967] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 478.520358][T10967] vhci_hcd vhci_hcd.0: Device attached [ 478.654256][T10992] vhci_hcd: connection reset by peer [ 478.659815][T10981] vhci_hcd: connection closed [ 478.660108][T10996] vhci_hcd: connection closed [ 478.665042][T10985] vhci_hcd: connection closed [ 478.669855][T10974] vhci_hcd: connection closed [ 478.684864][ T36] vhci_hcd: stop threads [ 478.721891][ T36] vhci_hcd: release socket [ 478.786104][ T36] vhci_hcd: disconnect device [ 478.825528][ T36] vhci_hcd: stop threads [ 478.841683][ T36] vhci_hcd: release socket [ 478.858382][ T36] vhci_hcd: disconnect device [ 478.891551][ T36] vhci_hcd: stop threads [ 478.915914][ T36] vhci_hcd: release socket [ 478.928422][ T36] vhci_hcd: disconnect device [ 478.948887][ T36] vhci_hcd: stop threads [ 478.960187][ T36] vhci_hcd: release socket [ 478.994919][ T36] vhci_hcd: disconnect device [ 479.342892][ T36] vhci_hcd: stop threads [ 479.397122][ T36] vhci_hcd: release socket [ 479.427797][ T36] vhci_hcd: disconnect device [ 483.393629][ T5894] usb 36-1: device descriptor read/8, error -110 [ 483.490743][T11042] netlink: 8 bytes leftover after parsing attributes in process `syz.4.924'. [ 483.517149][ T5894] usb usb36-port1: unable to enumerate USB device [ 483.542159][T11042] nbd: socks must be embedded in a SOCK_ITEM attr [ 483.593734][ T5999] vhci_hcd: vhci_device speed not set [ 483.648909][T11047] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(13) [ 483.655579][T11047] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 483.695448][T11047] vhci_hcd vhci_hcd.0: Device attached [ 483.786083][T11054] vhci_hcd vhci_hcd.0: pdev(5) rhport(1) sockfd(15) [ 483.792764][T11054] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 483.849330][T11047] vhci_hcd vhci_hcd.0: pdev(5) rhport(2) sockfd(18) [ 483.856009][T11047] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 483.877620][ T5814] vhci_hcd: vhci_device speed not set [ 483.919389][T11047] vhci_hcd vhci_hcd.0: Device attached [ 483.929648][T11054] vhci_hcd vhci_hcd.0: Device attached [ 483.948443][ T2142] usb 1-1: new high-speed USB device number 12 using dummy_hcd [ 483.968663][T11061] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(21) [ 483.975358][T11061] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 483.983138][ T5814] usb 43-1: new full-speed USB device number 3 using vhci_hcd [ 484.165288][T11061] vhci_hcd vhci_hcd.0: Device attached [ 484.173283][ T2142] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x7 has invalid wMaxPacketSize 0 [ 484.248699][T11047] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 484.447514][ T2142] usb 1-1: config 0 interface 0 altsetting 0 bulk endpoint 0x7 has invalid maxpacket 0 [ 484.462083][ T2142] usb 1-1: config 0 interface 0 altsetting 0 endpoint 0x89 has invalid wMaxPacketSize 0 [ 484.471800][T11047] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 484.472671][ T2142] usb 1-1: config 0 interface 0 altsetting 0 bulk endpoint 0x89 has invalid maxpacket 0 [ 484.877274][T11047] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 485.080637][T11047] vhci_hcd vhci_hcd.0: pdev(5) rhport(6) sockfd(27) [ 485.083550][ T2142] usb 1-1: New USB device found, idVendor=2040, idProduct=4900, bcdDevice=4d.8b [ 485.087285][T11047] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 485.134323][ T2142] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 485.158139][T11047] vhci_hcd vhci_hcd.0: Device attached [ 485.181984][ T2142] usb 1-1: config 0 descriptor?? [ 485.791980][ T2142] hdpvr 1-1:0.0: firmware version 0x0 dated [ 485.809944][T11063] vhci_hcd: connection closed [ 485.810191][T11058] vhci_hcd: connection closed [ 485.815233][ T37] vhci_hcd: stop threads [ 485.815477][T11055] vhci_hcd: connection closed [ 485.819921][ T37] vhci_hcd: release socket [ 485.853673][ T2142] hdpvr 1-1:0.0: untested firmware, the driver might not work. [ 485.860925][T11049] vhci_hcd: connection reset by peer [ 485.862708][ T37] vhci_hcd: disconnect device [ 485.876810][ T37] vhci_hcd: stop threads [ 485.899298][ T37] vhci_hcd: release socket [ 485.925200][ T37] vhci_hcd: disconnect device [ 485.943849][ T37] vhci_hcd: stop threads [ 485.968626][ T37] vhci_hcd: release socket [ 485.975982][T11074] vhci_hcd: connection closed [ 486.006321][ T37] vhci_hcd: disconnect device [ 486.038505][ T37] vhci_hcd: stop threads [ 486.042961][ T37] vhci_hcd: release socket [ 486.050300][ T37] vhci_hcd: disconnect device [ 486.070688][ T37] vhci_hcd: stop threads [ 486.078479][ T37] vhci_hcd: release socket [ 486.083290][ T37] vhci_hcd: disconnect device [ 486.453959][ T2142] hdpvr 1-1:0.0: Could not setup controls [ 486.482051][ T2142] hdpvr 1-1:0.0: registering videodev failed [ 486.490255][T11084] binder_alloc: 11083: binder_alloc_buf, no vma [ 486.692941][ T2142] hdpvr 1-1:0.0: probe with driver hdpvr failed with error -71 [ 486.963955][ T2142] usb 1-1: USB disconnect, device number 12 [ 487.043110][T11091] netlink: 56 bytes leftover after parsing attributes in process `syz.1.936'. [ 489.225079][ T5814] vhci_hcd: vhci_device speed not set [ 489.346720][T11111] siw: device registration error -23 [ 489.386006][T11111] netlink: 8 bytes leftover after parsing attributes in process `syz.1.943'. [ 489.404376][T11111] nbd: socks must be embedded in a SOCK_ITEM attr [ 491.268210][ T24] usb usb44-port1: attempt power cycle [ 491.365581][T11132] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(13) [ 491.372255][T11132] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 491.457196][T11132] vhci_hcd vhci_hcd.0: Device attached [ 491.464739][ T5999] usb 1-1: new high-speed USB device number 13 using dummy_hcd [ 491.531275][T11135] vhci_hcd vhci_hcd.0: pdev(5) rhport(1) sockfd(16) [ 491.537951][T11135] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 491.873959][T11135] vhci_hcd vhci_hcd.0: Device attached [ 491.881548][ T5999] usb 1-1: device descriptor read/64, error -71 [ 492.445754][ T24] usb usb44-port1: unable to enumerate USB device [ 492.496636][T11132] vhci_hcd vhci_hcd.0: pdev(5) rhport(2) sockfd(15) [ 492.503307][T11132] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 492.514587][T11132] vhci_hcd vhci_hcd.0: Device attached [ 492.532072][ T5814] vhci_hcd: vhci_device speed not set [ 492.576931][T11149] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 492.655060][ T5814] usb 43-1: new full-speed USB device number 4 using vhci_hcd [ 492.682245][T11135] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(20) [ 492.688973][T11135] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 492.731357][ T5999] usb 1-1: new high-speed USB device number 14 using dummy_hcd [ 492.753894][T11135] vhci_hcd vhci_hcd.0: Device attached [ 492.809466][T11135] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 492.857636][T11132] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 492.883555][ T5999] usb 1-1: device descriptor read/64, error -71 [ 492.912304][T11135] vhci_hcd vhci_hcd.0: pdev(5) rhport(6) sockfd(28) [ 492.918957][T11135] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 492.963721][T11135] vhci_hcd vhci_hcd.0: Device attached [ 492.973314][T11147] vhci_hcd: connection closed [ 492.973852][ T12] vhci_hcd: stop threads [ 492.986421][T11137] vhci_hcd: connection closed [ 492.987623][T11145] vhci_hcd: connection closed [ 493.003195][T11133] vhci_hcd: connection reset by peer [ 493.014112][T11154] vhci_hcd: connection closed [ 493.032856][ T5999] usb usb1-port1: attempt power cycle [ 493.101940][ T12] vhci_hcd: release socket [ 493.180829][ T12] vhci_hcd: disconnect device [ 493.223282][ T12] vhci_hcd: stop threads [ 493.234946][ T12] vhci_hcd: release socket [ 493.242902][ T12] vhci_hcd: disconnect device [ 493.249732][ T12] vhci_hcd: stop threads [ 493.256069][ T12] vhci_hcd: release socket [ 493.324858][ T12] vhci_hcd: disconnect device [ 493.348276][ T12] vhci_hcd: stop threads [ 493.363617][ T12] vhci_hcd: release socket [ 493.384076][ T12] vhci_hcd: disconnect device [ 493.389870][ T12] vhci_hcd: stop threads [ 493.401305][ T12] vhci_hcd: release socket [ 493.412735][ T12] vhci_hcd: disconnect device [ 493.634644][ T5999] usb 1-1: new high-speed USB device number 15 using dummy_hcd [ 494.553035][T11162] netlink: 56 bytes leftover after parsing attributes in process `syz.4.956'. [ 495.033515][ T5999] usb 1-1: device descriptor read/8, error -71 [ 495.618269][T11173] netlink: 8 bytes leftover after parsing attributes in process `syz.4.960'. [ 495.627358][T11173] nbd: socks must be embedded in a SOCK_ITEM attr [ 497.793581][ T5814] vhci_hcd: vhci_device speed not set [ 499.795756][ T5895] usb usb44-port1: attempt power cycle [ 499.808494][T11208] netlink: 8 bytes leftover after parsing attributes in process `syz.4.971'. [ 499.925619][T11213] netlink: 56 bytes leftover after parsing attributes in process `syz.0.972'. [ 500.185322][T11208] nbd: socks must be embedded in a SOCK_ITEM attr [ 500.617951][ T5895] usb usb44-port1: unable to enumerate USB device [ 501.379016][T11226] siw: device registration error -23 [ 501.556751][T11226] netlink: 8 bytes leftover after parsing attributes in process `syz.1.977'. [ 501.583911][T11226] nbd: socks must be embedded in a SOCK_ITEM attr [ 506.778020][ T30] audit: type=1326 audit(2000000048.880:10): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 506.779663][T11258] netlink: 56 bytes leftover after parsing attributes in process `syz.5.986'. [ 506.802129][T11259] siw: device registration error -23 [ 506.817868][T11262] macvtap1: entered allmulticast mode [ 506.823273][T11262] veth0_macvtap: entered allmulticast mode [ 507.284408][ T30] audit: type=1326 audit(2000000048.880:11): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.311033][ T30] audit: type=1326 audit(2000000048.880:12): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.340621][ T30] audit: type=1326 audit(2000000048.880:13): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.370373][ T30] audit: type=1326 audit(2000000048.880:14): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.392971][ T30] audit: type=1326 audit(2000000048.890:15): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=294 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.416457][ T30] audit: type=1326 audit(2000000048.890:16): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.457615][T11259] netlink: 8 bytes leftover after parsing attributes in process `syz.3.988'. [ 507.503656][T11259] nbd: socks must be embedded in a SOCK_ITEM attr [ 507.555129][ T30] audit: type=1326 audit(2000000048.890:17): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.599366][ T30] audit: type=1326 audit(2000000048.890:18): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=72 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 507.629655][ T30] audit: type=1326 audit(2000000048.890:19): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11257 comm="syz.4.987" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f2ab3d8e969 code=0x7ffc0000 [ 508.126739][T11268] overlayfs: failed to decode file handle (len=5, type=0, flags=0, err=-22) [ 508.402383][T11277] siw: device registration error -23 [ 508.659842][T11277] netlink: 8 bytes leftover after parsing attributes in process `syz.3.993'. [ 508.702861][T11277] nbd: socks must be embedded in a SOCK_ITEM attr [ 511.078269][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 516.453107][T11324] overlayfs: failed to decode file handle (len=5, type=0, flags=0, err=-22) [ 517.313653][T11335] siw: device registration error -23 [ 517.801457][T11335] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1010'. [ 517.811457][T11335] nbd: socks must be embedded in a SOCK_ITEM attr [ 522.283769][ T5814] usb 4-1: new high-speed USB device number 12 using dummy_hcd [ 522.292610][ T30] kauditd_printk_skb: 7 callbacks suppressed [ 522.292632][ T30] audit: type=1326 audit(2000000064.900:27): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 522.581778][ T5814] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 522.644900][ T30] audit: type=1326 audit(2000000064.900:28): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 522.668009][ T30] audit: type=1326 audit(2000000064.990:29): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=41 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 522.692377][ T30] audit: type=1326 audit(2000000064.990:30): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 522.714655][ C0] vkms_vblank_simulate: vblank timer overrun [ 523.375992][T11368] overlayfs: fs on './file0' does not support file handles, falling back to index=off,nfs_export=off. [ 523.387305][T11368] overlayfs: "xino" feature enabled using 2 upper inode bits. [ 523.514126][ T5814] usb 4-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 524.312356][ T30] audit: type=1326 audit(2000000065.010:31): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 524.443618][ T5814] usb 4-1: string descriptor 0 read error: -71 [ 524.481840][ T5814] usb 4-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 524.483510][ T30] audit: type=1326 audit(2000000065.010:32): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=44 compat=0 ip=0x7f409c3907fc code=0x7ffc0000 [ 524.513085][ C0] vkms_vblank_simulate: vblank timer overrun [ 524.543544][ T5814] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 524.633296][ T5814] usb 4-1: config 0 descriptor?? [ 524.674745][ T5814] usb 4-1: can't set config #0, error -71 [ 524.737812][ T30] audit: type=1326 audit(2000000065.100:33): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=45 compat=0 ip=0x7f409c390734 code=0x7ffc0000 [ 524.749940][ T5814] usb 4-1: USB disconnect, device number 12 [ 524.994017][ T30] audit: type=1326 audit(2000000065.170:34): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=45 compat=0 ip=0x7f409c390734 code=0x7ffc0000 [ 525.016324][ C0] vkms_vblank_simulate: vblank timer overrun [ 525.096268][ T30] audit: type=1326 audit(2000000065.190:35): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 525.148542][ T30] audit: type=1326 audit(2000000065.190:36): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11364 comm="syz.1.1020" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f409c38e969 code=0x7ffc0000 [ 525.601940][T11412] netlink: 'syz.1.1031': attribute type 1 has an invalid length. [ 525.609831][T11412] netlink: 224 bytes leftover after parsing attributes in process `syz.1.1031'. [ 530.323754][T11453] siw: device registration error -23 [ 530.543941][T11453] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1045'. [ 530.563601][T11453] nbd: socks must be embedded in a SOCK_ITEM attr [ 530.765732][T11460] netlink: 'syz.3.1046': attribute type 1 has an invalid length. [ 530.773606][T11460] netlink: 224 bytes leftover after parsing attributes in process `syz.3.1046'. [ 536.696006][ T2334] pvrusb2: request_firmware fatal error with code=-110 [ 536.705830][ T2334] pvrusb2: Failure uploading firmware1 [ 536.711484][ T2334] pvrusb2: Device initialization was not successful. [ 536.725145][ T2334] pvrusb2: ***WARNING*** pvrusb2 device hardware appears to be jammed and I can't clear it. [ 536.745527][ T2334] pvrusb2: You might need to power cycle the pvrusb2 device in order to recover. [ 536.756005][ T48] pvrusb2: Device being rendered inoperable [ 537.413063][T11505] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1060'. [ 537.582448][T11507] netlink: 'syz.2.1061': attribute type 1 has an invalid length. [ 537.650121][T11507] netlink: 224 bytes leftover after parsing attributes in process `syz.2.1061'. [ 539.872599][T11528] overlayfs: failed to resolve './file0': -2 [ 541.555358][T11538] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1071'. [ 543.772818][T11554] siw: device registration error -23 [ 543.844941][T11557] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1076'. [ 543.854023][T11557] nbd: socks must be embedded in a SOCK_ITEM attr [ 544.363832][T11558] netlink: 'syz.3.1078': attribute type 1 has an invalid length. [ 544.371682][T11558] netlink: 224 bytes leftover after parsing attributes in process `syz.3.1078'. [ 546.702227][T11582] netlink: 56 bytes leftover after parsing attributes in process `syz.1.1083'. [ 547.065870][T11580] overlayfs: failed to resolve './file0': -2 [ 548.243842][ T30] kauditd_printk_skb: 57 callbacks suppressed [ 548.243880][ T30] audit: type=1326 audit(2000000090.070:94): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 548.278081][ T5896] usb 3-1: new high-speed USB device number 14 using dummy_hcd [ 551.120886][ T30] audit: type=1326 audit(2000000090.070:95): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 551.143753][ T30] audit: type=1326 audit(2000000090.080:96): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=3 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 551.166273][ T30] audit: type=1326 audit(2000000090.080:97): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 551.289299][ T30] audit: type=1326 audit(2000000090.080:98): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 551.543651][ T30] audit: type=1326 audit(2000000090.080:99): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=294 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 552.057567][ T30] audit: type=1326 audit(2000000090.090:100): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 552.216237][ T30] audit: type=1326 audit(2000000090.090:101): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=unconfined pid=11577 comm="syz.0.1084" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7fe62358e969 code=0x7ffc0000 [ 554.369682][ T24] usb 4-1: new high-speed USB device number 13 using dummy_hcd [ 554.715792][ T24] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 555.946950][ T24] usb 4-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 556.001282][ T24] usb 4-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 556.094186][ T24] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 556.122855][ T24] usb 4-1: Product: syz [ 556.160943][ T24] usb 4-1: Manufacturer: syz [ 556.222441][ T24] usb 4-1: SerialNumber: syz [ 556.296741][ T24] usb 4-1: config 0 descriptor?? [ 556.519843][ T5895] usb 4-1: USB disconnect, device number 13 [ 557.493583][ T24] usb 6-1: new high-speed USB device number 26 using dummy_hcd [ 558.210912][ T24] usb 6-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 558.237377][ T24] usb 6-1: config 1 descriptor has 1 excess byte, ignoring [ 559.184542][ T24] usb 6-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 559.266064][ T24] usb 6-1: config 1 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 559.339696][ T24] usb 6-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 559.373006][ T24] usb 6-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 559.392377][ T24] usb 6-1: Product: syz [ 559.403746][ T24] usb 6-1: Manufacturer: syz [ 559.634657][ T24] cdc_wdm 6-1:1.0: skipping garbage [ 559.639937][ T24] cdc_wdm 6-1:1.0: probe with driver cdc_wdm failed with error -22 [ 560.910430][ T5895] usb 6-1: USB disconnect, device number 26 [ 562.935822][T11685] bridge3: entered promiscuous mode [ 563.006191][T11687] befs: (nbd2): No write support. Marking filesystem read-only [ 563.016329][T11687] syz.2.1119: attempt to access beyond end of device [ 563.016329][T11687] nbd2: rw=0, sector=0, nr_sectors = 2 limit=0 [ 563.029826][T11687] befs: (nbd2): unable to read superblock [ 565.073591][ T5814] usb 6-1: new high-speed USB device number 27 using dummy_hcd [ 565.094542][T11692] netlink: 'syz.3.1122': attribute type 1 has an invalid length. [ 565.102312][T11692] netlink: 224 bytes leftover after parsing attributes in process `syz.3.1122'. [ 568.043601][ T969] usb 4-1: new high-speed USB device number 14 using dummy_hcd [ 569.897903][T11710] tmpfs: Bad value for 'mpol' [ 569.998233][ T5814] usb 6-1: device descriptor read/all, error -71 [ 570.000343][ T969] usb 4-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 570.071639][ T969] usb 4-1: config 1 descriptor has 1 excess byte, ignoring [ 570.153613][ T969] usb 4-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 570.162676][ T969] usb 4-1: config 1 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 570.274175][ T969] usb 4-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 570.295521][ T969] usb 4-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 570.330548][ T969] usb 4-1: Product: syz [ 572.041936][ T969] usb 4-1: Manufacturer: syz [ 572.255137][ T969] usb 4-1: can't set config #1, error -71 [ 572.304024][ T969] usb 4-1: USB disconnect, device number 14 [ 572.585055][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 573.115792][ T48] usb 3-1: new high-speed USB device number 15 using dummy_hcd [ 575.133989][ T48] usb 3-1: New USB device found, idVendor=046d, idProduct=0870, bcdDevice=61.47 [ 575.143097][ T48] usb 3-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 575.672434][ T48] usb 3-1: config 0 descriptor?? [ 575.760304][ T48] usb 3-1: can't set config #0, error -71 [ 575.823106][ T48] usb 3-1: USB disconnect, device number 15 [ 577.159513][ T5842] usb 2-1: new high-speed USB device number 5 using dummy_hcd [ 577.350969][ T5842] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 577.412092][ T5842] usb 2-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 577.466743][ T5842] usb 2-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 577.483630][ T5842] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 577.512806][ T5842] usb 2-1: Product: syz [ 577.522963][ T5842] usb 2-1: Manufacturer: syz [ 577.527998][ T5842] usb 2-1: SerialNumber: syz [ 577.671171][ T5842] usb 2-1: config 0 descriptor?? [ 578.553058][ T5842] usb 2-1: USB disconnect, device number 5 [ 579.982398][ T5134] Bluetooth: hci6: unexpected cc 0x0c03 length: 249 > 1 [ 579.995150][ T5134] Bluetooth: hci6: unexpected cc 0x1003 length: 249 > 9 [ 580.004902][ T5134] Bluetooth: hci6: unexpected cc 0x1001 length: 249 > 9 [ 580.013218][ T5134] Bluetooth: hci6: unexpected cc 0x0c23 length: 249 > 4 [ 580.033835][ T5134] Bluetooth: hci6: unexpected cc 0x0c38 length: 249 > 2 [ 580.288530][T11773] lo speed is unknown, defaulting to 1000 [ 580.645029][ T5896] usb 6-1: new high-speed USB device number 29 using dummy_hcd [ 581.000387][ T5896] usb 6-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 581.132783][ T5896] usb 6-1: config 1 has an invalid descriptor of length 56, skipping remainder of the config [ 581.283667][ T5896] usb 6-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 581.355533][ T5896] usb 6-1: config 1 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 581.484472][ T5896] usb 6-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 581.524800][ T5896] usb 6-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 581.773646][ T5896] usb 6-1: Product: syz [ 581.777891][ T5896] usb 6-1: Manufacturer: syz [ 582.122196][ T5134] Bluetooth: hci6: command tx timeout [ 582.595163][ T5896] cdc_wdm 6-1:1.0: skipping garbage [ 582.603960][ T5896] cdc_wdm 6-1:1.0: probe with driver cdc_wdm failed with error -22 [ 582.887964][ T24] usb 6-1: USB disconnect, device number 29 [ 584.193580][ T5134] Bluetooth: hci6: command tx timeout [ 586.873770][ T5134] Bluetooth: hci6: command tx timeout [ 587.523308][ T5973] netdevsim netdevsim4 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 588.788929][ T5973] netdevsim netdevsim4 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 588.936678][ T5848] Bluetooth: hci6: command tx timeout [ 589.530515][T11773] chnl_net:caif_netlink_parms(): no params data found [ 590.673962][ T5973] netdevsim netdevsim4 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 591.415618][T11875] siw: device registration error -23 [ 592.285389][ T5973] netdevsim netdevsim4 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 592.344360][T11875] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1173'. [ 592.384516][T11875] nbd: socks must be embedded in a SOCK_ITEM attr [ 593.522368][T11773] bridge0: port 1(bridge_slave_0) entered blocking state [ 593.575219][T11773] bridge0: port 1(bridge_slave_0) entered disabled state [ 594.026358][T11773] bridge_slave_0: entered allmulticast mode [ 594.094522][T11773] bridge_slave_0: entered promiscuous mode [ 594.374553][T11773] bridge0: port 2(bridge_slave_1) entered blocking state [ 594.390252][T11773] bridge0: port 2(bridge_slave_1) entered disabled state [ 594.397667][T11773] bridge_slave_1: entered allmulticast mode [ 595.096892][T11773] bridge_slave_1: entered promiscuous mode [ 595.108777][T11899] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1179'. [ 595.557948][T11773] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 595.570137][T11773] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 596.578661][T11911] overlayfs: failed to resolve './file1': -2 [ 599.028408][T11773] team0: Port device team_slave_0 added [ 599.186332][T11773] team0: Port device team_slave_1 added [ 599.333599][ T5896] usb 4-1: new high-speed USB device number 15 using dummy_hcd [ 599.708955][ T5896] usb 4-1: Using ep0 maxpacket: 32 [ 599.939491][ T5896] usb 4-1: New USB device found, idVendor=05a9, idProduct=1550, bcdDevice=e4.bb [ 599.955398][T11773] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 599.958965][ T5896] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 599.962354][T11773] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 600.036419][ T5896] usb 4-1: Product: syz [ 600.040614][ T5896] usb 4-1: Manufacturer: syz [ 600.053574][ T5896] usb 4-1: SerialNumber: syz [ 600.107312][ T5896] usb 4-1: config 0 descriptor?? [ 600.122876][T11773] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 600.231041][T11773] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 600.256086][ T5896] gspca_main: ov534_9-2.14.0 probing 05a9:1550 [ 600.277255][T11773] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 600.439123][ T5896] gspca_ov534_9: reg_w failed -71 [ 600.459573][T11773] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 600.623849][ T5973] bridge_slave_1: left allmulticast mode [ 600.632886][ T5973] bridge_slave_1: left promiscuous mode [ 600.675382][ T5973] bridge0: port 2(bridge_slave_1) entered disabled state [ 600.923929][ T5896] gspca_ov534_9: Unknown sensor 0000 [ 600.924047][ T5896] ov534_9 4-1:0.0: probe with driver ov534_9 failed with error -22 [ 600.927150][ T5973] bridge_slave_0: left allmulticast mode [ 601.194156][ T5896] usb 4-1: USB disconnect, device number 15 [ 601.217075][ T5973] bridge_slave_0: left promiscuous mode [ 602.176973][ T5973] bridge0: port 1(bridge_slave_0) entered disabled state [ 602.303865][T11946] siw: device registration error -23 [ 602.331845][T11938] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(13) [ 602.338504][T11938] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 602.414438][T11946] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1192'. [ 602.432417][T11938] vhci_hcd vhci_hcd.0: Device attached [ 602.434211][T11939] vhci_hcd vhci_hcd.0: pdev(1) rhport(1) sockfd(16) [ 602.444509][T11939] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 602.471583][T11946] nbd: socks must be embedded in a SOCK_ITEM attr [ 602.523599][T11955] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(19) [ 602.530268][T11955] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 602.575609][T11939] vhci_hcd vhci_hcd.0: Device attached [ 602.619882][T11938] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 602.701282][ T24] vhci_hcd: vhci_device speed not set [ 602.720359][T11955] vhci_hcd vhci_hcd.0: Device attached [ 602.744217][T11939] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 602.782650][ T24] usb 35-1: new full-speed USB device number 5 using vhci_hcd [ 603.180341][T11964] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 603.283787][T11938] vhci_hcd vhci_hcd.0: pdev(1) rhport(5) sockfd(25) [ 603.290441][T11938] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 603.331413][T11938] vhci_hcd vhci_hcd.0: Device attached [ 603.730858][T11971] netlink: 'syz.0.1194': attribute type 2 has an invalid length. [ 603.895319][T11965] vhci_hcd: connection closed [ 603.900808][T11956] vhci_hcd: connection closed [ 603.906698][T11948] vhci_hcd: connection closed [ 603.908890][ T5950] vhci_hcd: stop threads [ 603.920448][T11944] vhci_hcd: connection reset by peer [ 603.980381][ T5950] vhci_hcd: release socket [ 604.009320][ T5950] vhci_hcd: disconnect device [ 604.017987][ T5950] vhci_hcd: stop threads [ 604.053546][ T5950] vhci_hcd: release socket [ 604.063056][ T5950] vhci_hcd: disconnect device [ 604.088943][ T5950] vhci_hcd: stop threads [ 604.103831][ T5950] vhci_hcd: release socket [ 604.113139][ T5950] vhci_hcd: disconnect device [ 604.122661][ T5950] vhci_hcd: stop threads [ 604.296709][ T5950] vhci_hcd: release socket [ 604.483684][ T5950] vhci_hcd: disconnect device [ 606.466428][T11989] siw: device registration error -23 [ 608.403715][ T24] vhci_hcd: vhci_device speed not set [ 609.237541][ T5973] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 609.304274][ T5973] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 609.321357][T12015] netlink: 12 bytes leftover after parsing attributes in process `syz.2.1204'. [ 609.338379][ T5973] bond0 (unregistering): Released all slaves [ 609.353157][T12015] openvswitch: netlink: Flow get message rejected, Key attribute missing. [ 609.425936][T12015] netlink: 4 bytes leftover after parsing attributes in process `syz.2.1204'. [ 609.753962][T12020] siw: device registration error -23 [ 609.825226][ T48] usb usb36-port1: attempt power cycle [ 609.839202][T12020] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1205'. [ 609.880887][T12020] nbd: socks must be embedded in a SOCK_ITEM attr [ 610.273364][T12027] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1207'. [ 610.397460][ T48] usb usb36-port1: unable to enumerate USB device [ 610.599976][T11773] hsr_slave_0: entered promiscuous mode [ 610.661266][T11773] hsr_slave_1: entered promiscuous mode [ 610.749012][T11773] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 610.776895][T11773] Cannot create hsr debugfs directory [ 610.835192][T12035] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(13) [ 610.841857][T12035] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 610.915268][T12035] vhci_hcd vhci_hcd.0: Device attached [ 610.985735][T12042] vhci_hcd vhci_hcd.0: pdev(5) rhport(1) sockfd(16) [ 610.992406][T12042] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 611.043705][T12035] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(15) [ 611.050386][T12035] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 611.153737][T12042] vhci_hcd vhci_hcd.0: Device attached [ 611.286096][ T48] vhci_hcd: vhci_device speed not set [ 611.354473][ T48] usb 43-1: new full-speed USB device number 5 using vhci_hcd [ 611.514442][T12050] input: syz0 as /devices/virtual/input/input20 [ 612.255419][T12042] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 612.497388][T12051] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 612.534050][T12035] vhci_hcd vhci_hcd.0: Device attached [ 612.562299][T12053] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 612.761869][T12035] vhci_hcd vhci_hcd.0: pdev(5) rhport(5) sockfd(20) [ 612.768549][T12035] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 613.873651][T12035] vhci_hcd vhci_hcd.0: Device attached [ 613.893776][T12058] vhci_hcd: connection closed [ 613.900320][ T5951] vhci_hcd: stop threads [ 613.904774][T12045] vhci_hcd: connection closed [ 613.905096][T12037] vhci_hcd: connection reset by peer [ 613.913560][T12043] vhci_hcd: connection closed [ 613.919471][ T5951] vhci_hcd: release socket [ 613.951520][ T5951] vhci_hcd: disconnect device [ 613.972807][ T5951] vhci_hcd: stop threads [ 613.989154][ T5951] vhci_hcd: release socket [ 614.003397][ T5951] vhci_hcd: disconnect device [ 614.035096][ T5951] vhci_hcd: stop threads [ 614.063717][ T5951] vhci_hcd: release socket [ 614.084218][ T5951] vhci_hcd: disconnect device [ 614.190498][ T5951] vhci_hcd: stop threads [ 614.554611][ T5951] vhci_hcd: release socket [ 614.565326][ T5951] vhci_hcd: disconnect device [ 614.675102][ T5973] hsr_slave_0: left promiscuous mode [ 614.757413][ T5973] hsr_slave_1: left promiscuous mode [ 614.813931][ T5973] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 614.821518][ T5973] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 615.102022][ T5973] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 615.319816][ T5973] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 615.709910][T12081] siw: device registration error -23 [ 616.229279][T12081] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1218'. [ 616.238392][T12081] nbd: socks must be embedded in a SOCK_ITEM attr [ 616.260505][ T5973] veth0_macvtap: left allmulticast mode [ 616.266492][ T5973] veth1_macvtap: left promiscuous mode [ 616.290383][ T5973] veth0_macvtap: left promiscuous mode [ 616.296939][ T5973] veth1_vlan: left promiscuous mode [ 616.534740][ T5973] veth0_vlan: left promiscuous mode [ 616.588605][ T48] vhci_hcd: vhci_device speed not set [ 617.170784][T12102] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1221'. [ 619.165464][ T5999] usb usb44-port1: attempt power cycle [ 619.792992][T12129] netlink: 56 bytes leftover after parsing attributes in process `syz.3.1227'. [ 619.935122][ T5999] usb usb44-port1: unable to enumerate USB device [ 620.478286][T12131] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(13) [ 620.484951][T12131] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 620.681836][T12131] vhci_hcd vhci_hcd.0: Device attached [ 620.975203][ T969] vhci_hcd: vhci_device speed not set [ 621.063176][T12139] vhci_hcd vhci_hcd.0: pdev(0) rhport(1) sockfd(16) [ 621.069835][T12139] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 621.090385][T12139] vhci_hcd vhci_hcd.0: Device attached [ 621.106236][ T969] usb 33-1: new full-speed USB device number 2 using vhci_hcd [ 621.122080][T12131] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(15) [ 621.128713][T12131] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 622.224527][T12131] vhci_hcd vhci_hcd.0: Device attached [ 622.228404][T12139] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 622.320479][T12131] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 622.353837][T12131] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 622.393596][T12131] vhci_hcd vhci_hcd.0: pdev(0) rhport(5) sockfd(25) [ 622.400231][T12131] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 622.447061][T12131] vhci_hcd vhci_hcd.0: Device attached [ 622.459066][T12155] siw: device registration error -23 [ 622.476071][T12151] vhci_hcd: connection closed [ 622.476961][T12143] vhci_hcd: connection closed [ 622.479031][ T5972] vhci_hcd: stop threads [ 622.481689][T12140] vhci_hcd: connection closed [ 622.486391][T12135] vhci_hcd: connection reset by peer [ 622.487285][ T5972] vhci_hcd: release socket [ 622.514252][ T5972] vhci_hcd: disconnect device [ 622.519927][ T5972] vhci_hcd: stop threads [ 622.527948][ T5972] vhci_hcd: release socket [ 622.533206][ T5972] vhci_hcd: disconnect device [ 622.546460][ T5972] vhci_hcd: stop threads [ 622.550797][ T5972] vhci_hcd: release socket [ 622.569374][ T5972] vhci_hcd: disconnect device [ 622.580030][ T5972] vhci_hcd: stop threads [ 622.587970][ T5972] vhci_hcd: release socket [ 622.598628][ T5972] vhci_hcd: disconnect device [ 622.682008][T12157] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1231'. [ 622.755125][T12157] nbd: socks must be embedded in a SOCK_ITEM attr [ 622.776819][T12159] netlink: 'syz.2.1232': attribute type 2 has an invalid length. [ 623.415852][T12164] loop7: detected capacity change from 0 to 16384 [ 623.672299][ T5973] team0 (unregistering): Port device team_slave_1 removed [ 623.762391][T12172] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1235'. [ 623.900617][ T5973] team0 (unregistering): Port device team_slave_0 removed [ 625.949080][ T5895] lo speed is unknown, defaulting to 1000 [ 625.957756][ T5895] infiniband syz2: ib_query_port failed (-19) [ 625.985665][T12179] platform regulatory.0: loading /lib/firmware/regulatory.db failed with error -12 [ 625.993611][ T30] audit: type=1800 audit(2000000168.600:102): pid=12179 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.3.1237" name="regulatory.db" dev="sda1" ino=448 res=0 errno=0 [ 625.995314][T12179] platform regulatory.0: Direct firmware load for regulatory.db failed with error -12 [ 626.024980][T12179] platform regulatory.0: Falling back to sysfs fallback for: regulatory.db [ 626.549147][ T969] vhci_hcd: vhci_device speed not set [ 627.396341][T12194] netlink: 56 bytes leftover after parsing attributes in process `syz.1.1241'. [ 628.475034][ T5999] usb usb34-port1: attempt power cycle [ 629.187013][ T5999] usb usb34-port1: unable to enumerate USB device [ 629.261339][T11773] netdevsim netdevsim6 netdevsim0: renamed from eth0 [ 629.299149][ T5973] IPVS: stop unused estimator thread 0... [ 629.335437][T12209] lo speed is unknown, defaulting to 1000 [ 629.336321][T11773] netdevsim netdevsim6 netdevsim1: renamed from eth1 [ 629.391904][T11773] netdevsim netdevsim6 netdevsim2: renamed from eth2 [ 629.401094][T12211] vhci_hcd vhci_hcd.0: pdev(3) rhport(0) sockfd(13) [ 629.407741][T12211] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 629.458394][T12213] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1245'. [ 629.464699][T12211] vhci_hcd vhci_hcd.0: Device attached [ 629.507188][T12209] lo speed is unknown, defaulting to 1000 [ 629.507221][T11773] netdevsim netdevsim6 netdevsim3: renamed from eth3 [ 629.533717][T12213] nbd: socks must be embedded in a SOCK_ITEM attr [ 629.553588][T12217] vhci_hcd vhci_hcd.0: pdev(3) rhport(1) sockfd(16) [ 629.560231][T12217] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 629.585279][T12217] vhci_hcd vhci_hcd.0: Device attached [ 629.606871][T12209] lo speed is unknown, defaulting to 1000 [ 629.633027][T12209] infiniband syz2: RDMA CMA: cma_listen_on_dev, error -98 [ 629.668233][T12217] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 629.724616][T12217] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 629.776640][T12211] vhci_hcd vhci_hcd.0: pdev(3) rhport(0) sockfd(19) [ 629.783307][T12211] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 629.823585][ T48] usb 39-1: new low-speed USB device number 2 using vhci_hcd [ 629.832749][T12225] vhci_hcd vhci_hcd.0: pdev(3) rhport(4) sockfd(24) [ 629.839401][T12225] vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed) [ 629.894347][T12217] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 629.913360][T12209] lo speed is unknown, defaulting to 1000 [ 629.922422][T12209] lo speed is unknown, defaulting to 1000 [ 629.966186][T12209] lo speed is unknown, defaulting to 1000 [ 629.976441][T12225] vhci_hcd vhci_hcd.0: Device attached [ 629.982319][T12209] lo speed is unknown, defaulting to 1000 [ 630.017535][T12211] vhci_hcd vhci_hcd.0: Device attached [ 630.033099][T12209] lo speed is unknown, defaulting to 1000 [ 630.062011][T12209] lo speed is unknown, defaulting to 1000 [ 630.174800][T12219] vhci_hcd: connection closed [ 630.174955][T12222] vhci_hcd: connection closed [ 630.175321][T12226] vhci_hcd: connection closed [ 630.179769][ T5973] vhci_hcd: stop threads [ 630.196081][T12214] vhci_hcd: connection reset by peer [ 630.208278][T11773] 8021q: adding VLAN 0 to HW filter on device bond0 [ 630.237028][ T5973] vhci_hcd: release socket [ 630.252218][ T5973] vhci_hcd: disconnect device [ 630.269701][T11773] 8021q: adding VLAN 0 to HW filter on device team0 [ 630.273885][ T5973] vhci_hcd: stop threads [ 630.293901][ T5973] vhci_hcd: release socket [ 630.319447][ T5973] vhci_hcd: disconnect device [ 630.350739][ T5973] vhci_hcd: stop threads [ 630.355621][ T12] bridge0: port 1(bridge_slave_0) entered blocking state [ 630.362793][ T12] bridge0: port 1(bridge_slave_0) entered forwarding state [ 630.366320][ T5973] vhci_hcd: release socket [ 630.395488][ T12] bridge0: port 2(bridge_slave_1) entered blocking state [ 630.402635][ T12] bridge0: port 2(bridge_slave_1) entered forwarding state [ 630.404350][ T5973] vhci_hcd: disconnect device [ 630.828458][ T5973] vhci_hcd: stop threads [ 630.860902][ T5973] vhci_hcd: release socket [ 630.924436][ T5973] vhci_hcd: disconnect device [ 631.530120][T11773] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 632.131220][T12251] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1252'. [ 632.282109][T12255] netlink: 'syz.2.1251': attribute type 2 has an invalid length. [ 632.928971][T12265] netlink: 56 bytes leftover after parsing attributes in process `syz.0.1254'. [ 633.978717][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 634.763000][T11773] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 635.003689][ T48] vhci_hcd: vhci_device speed not set [ 635.066100][T12289] siw: device registration error -23 [ 635.184635][T12288] siw: device registration error -23 [ 635.260401][T12288] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1261'. [ 635.287953][T12288] nbd: socks must be embedded in a SOCK_ITEM attr [ 636.083961][T12304] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1264'. [ 636.866821][ T5999] usb usb40-port1: attempt power cycle [ 636.885058][ T24] usb 1-1: new high-speed USB device number 17 using dummy_hcd [ 637.147364][ T24] usb 1-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 637.209323][ T24] usb 1-1: config 1 has an invalid descriptor of length 49, skipping remainder of the config [ 637.379435][ T24] usb 1-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 637.520858][ T24] usb 1-1: config 1 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 637.545325][ T5999] usb usb40-port1: unable to enumerate USB device [ 637.620899][T12321] netlink: 56 bytes leftover after parsing attributes in process `syz.5.1267'. [ 638.026451][ T24] usb 1-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 638.093563][ T24] usb 1-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 638.173033][ T24] usb 1-1: Product: syz [ 638.184115][ T24] usb 1-1: Manufacturer: syz [ 638.226068][ T24] cdc_wdm 1-1:1.0: skipping garbage [ 638.232294][ T24] cdc_wdm 1-1:1.0: skipping garbage [ 638.282995][ T24] cdc_wdm 1-1:1.0: probe with driver cdc_wdm failed with error -22 [ 638.539348][ T24] usb 1-1: USB disconnect, device number 17 [ 638.701883][T12333] siw: device registration error -23 [ 638.763816][T12333] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1271'. [ 638.772786][T12333] nbd: socks must be embedded in a SOCK_ITEM attr [ 640.705058][T12346] siw: device registration error -23 [ 640.824813][T12350] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1275'. [ 640.853654][T12350] nbd: socks must be embedded in a SOCK_ITEM attr [ 641.053686][ T969] usb 6-1: new high-speed USB device number 30 using dummy_hcd [ 641.143569][T12356] hfsplus: unable to find HFS+ superblock [ 641.163873][ T5134] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 641.177124][ T5134] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 641.187359][ T5134] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 641.208141][ T5134] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 641.220303][ T5134] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 641.336728][ T10] IPVS: starting estimator thread 0... [ 641.502050][T12343] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1274'. [ 641.543414][ T969] usb 6-1: Using ep0 maxpacket: 16 [ 641.572599][ T969] usb 6-1: config 0 interface 0 altsetting 2 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 641.613678][T12357] IPVS: using max 28 ests per chain, 67200 per kthread [ 641.628439][ T969] usb 6-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 641.653770][ T969] usb 6-1: config 0 interface 0 has no altsetting 0 [ 641.672307][ T969] usb 6-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 641.683055][ T969] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 641.722342][ T969] usb 6-1: config 0 descriptor?? [ 641.785406][T12353] lo speed is unknown, defaulting to 1000 [ 642.154333][ T969] usbhid 6-1:0.0: can't add hid device: -71 [ 642.258476][T12366] befs: (nbd2): No write support. Marking filesystem read-only [ 642.266376][T12366] syz.2.1277: attempt to access beyond end of device [ 642.266376][T12366] nbd2: rw=0, sector=0, nr_sectors = 2 limit=0 [ 642.279199][T12366] befs: (nbd2): unable to read superblock [ 642.954300][ T969] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 643.028199][ T969] usb 6-1: USB disconnect, device number 30 [ 643.161665][T12361] bridge4: entered promiscuous mode [ 643.314004][T12358] Bluetooth: hci2: command tx timeout [ 643.476917][ T5848] Bluetooth: hci6: Opcode 0x1003 failed: -110 [ 643.486019][T12358] Bluetooth: hci6: command 0x1003 tx timeout [ 643.794654][T12373] netlink: 'syz.1.1279': attribute type 2 has an invalid length. [ 645.027116][T12384] netlink: 56 bytes leftover after parsing attributes in process `syz.5.1281'. [ 645.414416][ T5848] Bluetooth: hci2: command tx timeout [ 647.493822][ T5848] Bluetooth: hci2: command tx timeout [ 648.619529][T12416] siw: device registration error -23 [ 648.759888][T12416] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1288'. [ 648.811966][T12416] nbd: socks must be embedded in a SOCK_ITEM attr [ 649.533421][ T5973] bridge_slave_1: left allmulticast mode [ 649.554072][ T5848] Bluetooth: hci2: command tx timeout [ 649.570623][ T5973] bridge_slave_1: left promiscuous mode [ 649.592601][ T5973] bridge0: port 2(bridge_slave_1) entered disabled state [ 649.664447][ T5973] bridge_slave_0: left allmulticast mode [ 649.677614][ T5842] usb 6-1: new high-speed USB device number 31 using dummy_hcd [ 649.689740][ T5973] bridge_slave_0: left promiscuous mode [ 649.728170][ T5973] bridge0: port 1(bridge_slave_0) entered disabled state [ 649.883824][ T5842] usb 6-1: Using ep0 maxpacket: 16 [ 649.904911][ T5842] usb 6-1: config 0 interface 0 altsetting 2 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 649.947533][ T5842] usb 6-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 650.017161][ T5842] usb 6-1: config 0 interface 0 has no altsetting 0 [ 650.089281][ T5842] usb 6-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 651.237689][ T5842] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 651.300798][T12442] netlink: 56 bytes leftover after parsing attributes in process `syz.0.1295'. [ 651.671260][ T5842] usb 6-1: config 0 descriptor?? [ 652.093167][ C0] raw-gadget.0 gadget.5: ignoring, device is not running [ 652.101051][ C0] raw-gadget.0 gadget.5: ignoring, device is not running [ 652.108679][ C0] raw-gadget.0 gadget.5: ignoring, device is not running [ 652.116080][ T5842] usbhid 6-1:0.0: can't add hid device: -32 [ 652.122095][ T5842] usbhid 6-1:0.0: probe with driver usbhid failed with error -32 [ 652.166232][ T5842] usb 6-1: USB disconnect, device number 31 [ 652.348419][T12448] siw: device registration error -23 [ 652.625868][T12454] fuse: Bad value for 'fd' [ 653.423720][T12459] siw: device registration error -23 [ 653.732266][T12459] netlink: 8 bytes leftover after parsing attributes in process `syz.0.1302'. [ 653.772375][T12459] nbd: socks must be embedded in a SOCK_ITEM attr [ 654.643552][ T5896] usb 1-1: new high-speed USB device number 18 using dummy_hcd [ 654.682296][ T5973] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 654.702999][ T5973] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 654.734675][ T5973] bond0 (unregistering): Released all slaves [ 654.846967][ T5896] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 654.877683][ T5896] usb 1-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 654.913759][T12353] chnl_net:caif_netlink_parms(): no params data found [ 654.991128][ T5896] usb 1-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 655.013493][ T5896] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 655.043496][ T5896] usb 1-1: Product: syz [ 655.068048][ T5896] usb 1-1: Manufacturer: syz [ 655.072686][ T5896] usb 1-1: SerialNumber: syz [ 655.142383][ T5896] usb 1-1: config 0 descriptor?? [ 655.337310][T12484] block device autoloading is deprecated and will be removed. [ 656.015840][ T2142] usb 1-1: USB disconnect, device number 18 [ 657.059000][T12494] netlink: 56 bytes leftover after parsing attributes in process `syz.5.1308'. [ 657.721425][ T5973] hsr_slave_0: left promiscuous mode [ 657.762026][ T5973] hsr_slave_1: left promiscuous mode [ 657.784855][ T5973] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 657.881325][ T5973] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 657.915145][T12509] siw: device registration error -23 [ 657.989848][T12511] netlink: 'syz.2.1310': attribute type 2 has an invalid length. [ 658.063674][ T24] usb 2-1: new high-speed USB device number 6 using dummy_hcd [ 658.435145][ T24] usb 2-1: Using ep0 maxpacket: 16 [ 658.703365][ T24] usb 2-1: config 0 interface 0 altsetting 2 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 658.729425][ T24] usb 2-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 658.792844][ T24] usb 2-1: config 0 interface 0 has no altsetting 0 [ 658.817696][ T24] usb 2-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 658.950224][ T24] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 659.100053][ T24] usb 2-1: config 0 descriptor?? [ 660.307924][T12522] sctp: failed to load transform for md5: -2 [ 660.395924][ T24] usbhid 2-1:0.0: can't add hid device: -71 [ 660.401983][ T24] usbhid 2-1:0.0: probe with driver usbhid failed with error -71 [ 660.583793][ T24] usb 2-1: USB disconnect, device number 6 [ 660.896693][ T5973] team0 (unregistering): Port device team_slave_1 removed [ 661.528859][ T5973] team0 (unregistering): Port device team_slave_0 removed [ 662.003731][ T10] usb 2-1: new high-speed USB device number 7 using dummy_hcd [ 662.180978][ T10] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 662.220405][ T10] usb 2-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 662.243350][ T10] usb 2-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 662.262054][ T10] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 662.272525][ T10] usb 2-1: Product: syz [ 662.282609][ T10] usb 2-1: Manufacturer: syz [ 662.289350][ T10] usb 2-1: SerialNumber: syz [ 662.306215][ T10] usb 2-1: config 0 descriptor?? [ 662.562173][ T5999] usb 2-1: USB disconnect, device number 7 [ 662.795770][T12557] netlink: 56 bytes leftover after parsing attributes in process `syz.2.1324'. [ 663.068554][T12353] bridge0: port 1(bridge_slave_0) entered blocking state [ 663.083667][T12353] bridge0: port 1(bridge_slave_0) entered disabled state [ 663.157773][T12353] bridge_slave_0: entered allmulticast mode [ 663.224048][T12353] bridge_slave_0: entered promiscuous mode [ 663.276718][T12565] siw: device registration error -23 [ 663.286782][T12353] bridge0: port 2(bridge_slave_1) entered blocking state [ 663.320864][T12353] bridge0: port 2(bridge_slave_1) entered disabled state [ 663.349173][T12353] bridge_slave_1: entered allmulticast mode [ 663.906701][T12571] sg_write: data in/out 209152/1 bytes for SCSI command 0xf2-- guessing data in; [ 663.906701][T12571] program syz.5.1329 not setting count and/or reply_len properly [ 664.575324][T12353] bridge_slave_1: entered promiscuous mode [ 666.294927][T12353] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 667.362588][T12353] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 667.472627][T12588] netlink: 'syz.3.1335': attribute type 2 has an invalid length. [ 667.748295][T12353] team0: Port device team_slave_0 added [ 667.760221][T12353] team0: Port device team_slave_1 added [ 668.160106][T12353] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 668.211996][T12353] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 668.330056][T12353] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 668.391301][T12353] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 668.413515][T12353] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 668.520724][T12353] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 669.236587][T12353] hsr_slave_0: entered promiscuous mode [ 669.273165][T12353] hsr_slave_1: entered promiscuous mode [ 669.291118][T12353] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 669.306379][T12353] Cannot create hsr debugfs directory [ 670.133708][ T10] usb 1-1: new high-speed USB device number 19 using dummy_hcd [ 670.522988][ T10] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 670.540930][ T10] usb 1-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 670.557353][ T10] usb 1-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 670.574356][ T10] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 670.592988][ T10] usb 1-1: Product: syz [ 670.597920][ T10] usb 1-1: Manufacturer: syz [ 670.602546][ T10] usb 1-1: SerialNumber: syz [ 670.623178][ T10] usb 1-1: config 0 descriptor?? [ 670.854678][ T10] usb 1-1: USB disconnect, device number 19 [ 671.071689][T12634] netlink: 108 bytes leftover after parsing attributes in process `syz.2.1345'. [ 672.232457][T12353] netdevsim netdevsim6 netdevsim0: renamed from eth0 [ 672.309668][T12648] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 672.314372][T12353] netdevsim netdevsim6 netdevsim1: renamed from eth1 [ 672.645865][T12353] netdevsim netdevsim6 netdevsim2: renamed from eth2 [ 672.829804][T12353] netdevsim netdevsim6 netdevsim3: renamed from eth3 [ 673.201301][T12353] 8021q: adding VLAN 0 to HW filter on device bond0 [ 673.439872][T12670] netlink: 56 bytes leftover after parsing attributes in process `syz.5.1356'. [ 673.519257][T12353] 8021q: adding VLAN 0 to HW filter on device team0 [ 674.239626][ T5972] bridge0: port 1(bridge_slave_0) entered blocking state [ 674.246892][ T5972] bridge0: port 1(bridge_slave_0) entered forwarding state [ 674.465867][ T5972] bridge0: port 2(bridge_slave_1) entered blocking state [ 674.473139][ T5972] bridge0: port 2(bridge_slave_1) entered forwarding state [ 676.016702][T12699] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1360'. [ 676.112932][T12700] siw: device registration error -23 [ 677.318917][T12353] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 680.079419][T12736] bridge4: entered promiscuous mode [ 680.144143][T12736] befs: (nbd0): No write support. Marking filesystem read-only [ 680.151891][T12736] syz.0.1369: attempt to access beyond end of device [ 680.151891][T12736] nbd0: rw=0, sector=0, nr_sectors = 2 limit=0 [ 680.164736][T12736] befs: (nbd0): unable to read superblock [ 680.831975][T12740] overlayfs: missing 'lowerdir' [ 682.102288][T12750] vlan2: entered allmulticast mode [ 682.169576][T12750] erspan0: entered allmulticast mode [ 683.306732][T12753] bond1: entered allmulticast mode [ 683.839908][T12772] siw: device registration error -23 [ 684.124194][T12353] veth0_vlan: entered promiscuous mode [ 684.202942][T12353] veth1_vlan: entered promiscuous mode [ 685.289166][T12778] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1378'. [ 685.816916][T12353] veth0_macvtap: entered promiscuous mode [ 685.892125][T12353] veth1_macvtap: entered promiscuous mode [ 686.830556][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 687.037259][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.047265][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 687.125111][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.168158][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 687.192225][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.204525][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 687.247434][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.280102][T12353] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 687.421909][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 687.470637][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.510588][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 687.794778][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.823648][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 687.859258][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 687.966458][T12809] befs: (nbd1): No write support. Marking filesystem read-only [ 687.974907][T12809] syz.1.1383: attempt to access beyond end of device [ 687.974907][T12809] nbd1: rw=0, sector=0, nr_sectors = 2 limit=0 [ 687.988108][T12809] befs: (nbd1): unable to read superblock [ 688.043968][T12353] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 688.474953][T12353] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 688.486623][T12353] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 688.521461][T12806] bridge2: entered promiscuous mode [ 688.671944][T12353] netdevsim netdevsim6 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 688.732135][T12353] netdevsim netdevsim6 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 688.768682][T12353] netdevsim netdevsim6 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 688.803600][T12353] netdevsim netdevsim6 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 688.831447][T12815] netlink: 56 bytes leftover after parsing attributes in process `syz.3.1384'. [ 690.299851][ T2976] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 690.343605][ T2976] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 690.519598][T12832] gtp0: entered promiscuous mode [ 690.663238][ T12] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 691.649798][ T12] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 693.378951][T12855] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1395'. [ 695.501521][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 697.039502][T12880] bridge3: entered promiscuous mode [ 697.114919][T12884] befs: (nbd1): No write support. Marking filesystem read-only [ 697.123022][T12884] syz.1.1398: attempt to access beyond end of device [ 697.123022][T12884] nbd1: rw=0, sector=0, nr_sectors = 2 limit=0 [ 697.136148][T12884] befs: (nbd1): unable to read superblock [ 700.906533][T12910] virtio-fs: tag not found [ 701.432581][T12916] netlink: 8 bytes leftover after parsing attributes in process `syz.6.1409'. [ 701.796933][T12919] hfsplus: unable to find HFS+ superblock [ 702.604388][ T2142] IPVS: starting estimator thread 0... [ 702.653977][ T5896] usb 2-1: new high-speed USB device number 8 using dummy_hcd [ 702.774297][T12920] IPVS: using max 23 ests per chain, 55200 per kthread [ 703.283895][ T5896] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 703.363556][ T5896] usb 2-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 703.404868][ T5896] usb 2-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 703.414227][ T5896] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 703.441509][ T5896] usb 2-1: Product: syz [ 703.453527][ T5896] usb 2-1: Manufacturer: syz [ 703.485299][ T5896] usb 2-1: SerialNumber: syz [ 703.625130][ T5896] usb 2-1: config 0 descriptor?? [ 703.913324][ T5896] usb 2-1: USB disconnect, device number 8 [ 703.967009][ T5848] Bluetooth: hci6: Opcode 0x1003 failed: -110 [ 704.526939][T12924] netlink: 44 bytes leftover after parsing attributes in process `syz.5.1407'. [ 704.537398][T12924] overlayfs: option "workdir=./bus" is useless in a non-upper mount, ignore [ 704.546823][T12924] overlayfs: missing 'lowerdir' [ 706.274460][T12952] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1417'. [ 707.814002][T12956] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(12) [ 707.820679][T12956] vhci_hcd vhci_hcd.0: devid(0) speed(4) speed_str(wireless) [ 707.969386][T12961] vhci_hcd vhci_hcd.0: pdev(2) rhport(2) sockfd(15) [ 707.976085][T12961] vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed) [ 708.073787][T12956] vhci_hcd vhci_hcd.0: Device attached [ 708.263580][ T2142] vhci_hcd: vhci_device speed not set [ 708.381466][ T2142] usb 37-1: new full-speed USB device number 3 using vhci_hcd [ 708.395699][T12962] vhci_hcd vhci_hcd.0: pdev(2) rhport(1) sockfd(17) [ 708.402391][T12962] vhci_hcd vhci_hcd.0: devid(0) speed(2) speed_str(full-speed) [ 708.692296][T12972] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 709.675470][T12984] trusted_key: encrypted_key: keyword 'new' not allowed when called from .update method [ 710.326452][T12969] vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(14) [ 710.333126][T12969] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 710.704200][T12962] vhci_hcd vhci_hcd.0: Device attached [ 710.729426][T12956] vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN [ 710.795370][ T5848] Bluetooth: hci6: unexpected cc 0x0c03 length: 249 > 1 [ 710.804090][ T5848] Bluetooth: hci6: unexpected cc 0x1003 length: 249 > 9 [ 710.812998][ T5848] Bluetooth: hci6: unexpected cc 0x1001 length: 249 > 9 [ 710.821284][ T5848] Bluetooth: hci6: unexpected cc 0x0c23 length: 249 > 4 [ 710.831169][ T5848] Bluetooth: hci6: unexpected cc 0x0c38 length: 249 > 2 [ 711.096395][T12961] vhci_hcd vhci_hcd.0: Device attached [ 711.102292][T12969] vhci_hcd vhci_hcd.0: Device attached [ 711.246423][T12996] virtio-fs: tag not found [ 711.671460][T12988] lo speed is unknown, defaulting to 1000 [ 712.008404][T12980] vhci_hcd: connection closed [ 712.019575][T12963] vhci_hcd: connection closed [ 712.037362][ T2993] vhci_hcd: stop threads [ 712.054482][T12964] vhci_hcd: connection closed [ 712.054760][T12960] vhci_hcd: connection reset by peer [ 712.090802][ T2993] vhci_hcd: release socket [ 712.156622][ T5999] usb 6-1: new high-speed USB device number 32 using dummy_hcd [ 712.392111][ T2993] vhci_hcd: disconnect device [ 712.920006][T12358] Bluetooth: hci6: command tx timeout [ 712.925764][ T2993] vhci_hcd: stop threads [ 712.926593][ T48] usb 1-1: new high-speed USB device number 20 using dummy_hcd [ 712.938424][ T2993] vhci_hcd: release socket [ 712.948578][ T5999] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 712.950571][ T2993] vhci_hcd: disconnect device [ 712.970702][ T5999] usb 6-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 713.054674][ T2993] vhci_hcd: stop threads [ 713.055175][ T5999] usb 6-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 713.058960][ T2993] vhci_hcd: release socket [ 713.083485][ T5999] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 713.091548][ T5999] usb 6-1: Product: syz [ 713.117402][ T5999] usb 6-1: Manufacturer: syz [ 713.122046][ T5999] usb 6-1: SerialNumber: syz [ 713.140686][T13017] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1426'. [ 713.159169][ T2993] vhci_hcd: disconnect device [ 713.203876][ T2993] vhci_hcd: stop threads [ 713.208169][ T2993] vhci_hcd: release socket [ 713.263616][ T2993] vhci_hcd: disconnect device [ 713.311283][ T5999] usb 6-1: config 0 descriptor?? [ 713.317005][ T48] usb 1-1: Using ep0 maxpacket: 16 [ 713.334754][ T48] usb 1-1: config 0 interface 0 altsetting 2 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 713.423842][ T48] usb 1-1: config 0 interface 0 altsetting 2 endpoint 0x81 has invalid wMaxPacketSize 0 [ 713.484747][ T48] usb 1-1: config 0 interface 0 has no altsetting 0 [ 713.492439][ T48] usb 1-1: New USB device found, idVendor=056a, idProduct=0331, bcdDevice= 0.00 [ 713.544996][ T2142] vhci_hcd: vhci_device speed not set [ 713.577226][ T48] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 714.749189][ T5842] usb 6-1: USB disconnect, device number 32 [ 714.805652][ T48] usb 1-1: config 0 descriptor?? [ 714.921521][T13027] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1430'. [ 714.994111][T12358] Bluetooth: hci6: command tx timeout [ 715.267338][ T48] usbhid 1-1:0.0: can't add hid device: -71 [ 715.273423][ T48] usbhid 1-1:0.0: probe with driver usbhid failed with error -71 [ 715.314517][ T48] usb 1-1: USB disconnect, device number 20 [ 715.703544][ T24] usb usb38-port1: attempt power cycle [ 716.365148][T13045] siw: device registration error -23 [ 716.527291][ T24] usb usb38-port1: unable to enumerate USB device [ 717.083669][T12358] Bluetooth: hci6: command tx timeout [ 717.162869][T13053] siw: device registration error -23 [ 717.616304][T12988] chnl_net:caif_netlink_parms(): no params data found [ 717.851766][ T5950] bridge_slave_1: left allmulticast mode [ 717.870226][ T5950] bridge_slave_1: left promiscuous mode [ 717.886661][ T5950] bridge0: port 2(bridge_slave_1) entered disabled state [ 717.969918][ T5950] bridge_slave_0: left allmulticast mode [ 718.200951][ T5950] bridge_slave_0: left promiscuous mode [ 718.319568][T13068] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 719.207480][T12358] Bluetooth: hci6: command tx timeout [ 719.216343][ T5950] bridge0: port 1(bridge_slave_0) entered disabled state [ 719.773160][ C0] vkms_vblank_simulate: vblank timer overrun [ 719.834059][ C0] vkms_vblank_simulate: vblank timer overrun [ 720.155214][T13080] virtio-fs: tag not found [ 720.427399][T13079] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1440'. [ 720.489774][T13079] nbd: socks must be embedded in a SOCK_ITEM attr [ 720.973552][ T24] usb 7-1: new high-speed USB device number 2 using dummy_hcd [ 721.815658][ T24] usb 7-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 721.847075][ T24] usb 7-1: config 0 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 2 [ 721.864702][ T24] usb 7-1: New USB device found, idVendor=1781, idProduct=0938, bcdDevice=9b.49 [ 721.874594][ T24] usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 721.901744][ T24] usb 7-1: Product: syz [ 721.910826][ T24] usb 7-1: Manufacturer: syz [ 721.917554][ T24] usb 7-1: SerialNumber: syz [ 721.932503][ T24] usb 7-1: config 0 descriptor?? [ 722.317526][ T5896] usb 7-1: USB disconnect, device number 2 [ 723.211519][ T5950] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 723.230412][ T5950] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 723.240938][ T5950] bond0 (unregistering): Released all slaves [ 723.263059][ T5950] bond1 (unregistering): Released all slaves [ 723.325105][ T5842] usb 6-1: new high-speed USB device number 33 using dummy_hcd [ 723.435218][T13093] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1441'. [ 723.444490][T13102] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1445'. [ 723.515700][ T5842] usb 6-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 723.656000][ T5842] usb 6-1: config 1 has an invalid descriptor of length 55, skipping remainder of the config [ 723.667306][ T5842] usb 6-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 723.676496][ T5842] usb 6-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 52, changing to 9 [ 723.687645][ T5842] usb 6-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 8241, setting to 1024 [ 723.701281][ T5842] usb 6-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 723.839486][ T5842] usb 6-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 723.968638][ T5842] usb 6-1: Product: syz [ 724.150525][ T5842] usb 6-1: Manufacturer: syz [ 724.429363][ T5842] cdc_wdm 6-1:1.0: skipping garbage [ 724.454421][ T5842] cdc_wdm 6-1:1.0: skipping garbage [ 724.477703][ T5842] cdc_wdm 6-1:1.0: cdc-wdm0: USB WDM device [ 724.517166][ T5842] cdc_wdm 6-1:1.0: Unknown control protocol [ 724.640501][T13127] siw: device registration error -23 [ 724.744860][T13128] siw: device registration error -23 [ 725.358343][ T10] usb 6-1: USB disconnect, device number 33 [ 725.625629][T12988] bridge0: port 1(bridge_slave_0) entered blocking state [ 725.759418][T12988] bridge0: port 1(bridge_slave_0) entered disabled state [ 725.809759][T12988] bridge_slave_0: entered allmulticast mode [ 725.865837][T12988] bridge_slave_0: entered promiscuous mode [ 726.347239][ C0] vkms_vblank_simulate: vblank timer overrun [ 726.922143][T12988] bridge0: port 2(bridge_slave_1) entered blocking state [ 727.765096][T12988] bridge0: port 2(bridge_slave_1) entered disabled state [ 727.822310][T12988] bridge_slave_1: entered allmulticast mode [ 727.833169][T12988] bridge_slave_1: entered promiscuous mode [ 728.147736][ T5950] hsr_slave_0: left promiscuous mode [ 729.153730][ T5950] hsr_slave_1: left promiscuous mode [ 729.300353][ T5950] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 730.318633][T13168] ptrace attach of "./syz-executor exec"[5835] was attempted by "./syz-executor exec"[13168] [ 730.721187][ T5950] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 730.862345][T13164] syz.0.1458 (13164): /proc/13164/oom_adj is deprecated, please use /proc/13164/oom_score_adj instead. [ 732.605345][T13182] virtio-fs: tag not found [ 734.633789][ T24] usb 3-1: new high-speed USB device number 16 using dummy_hcd [ 735.954834][ T24] usb 3-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 736.020371][ T24] usb 3-1: config 1 has an invalid descriptor of length 55, skipping remainder of the config [ 736.043228][ T24] usb 3-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 736.062670][ T24] usb 3-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 52, changing to 9 [ 736.093648][ T24] usb 3-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 8241, setting to 1024 [ 736.110662][ T24] usb 3-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 736.124490][ T24] usb 3-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 736.132654][ T24] usb 3-1: Product: syz [ 736.153026][ T24] usb 3-1: Manufacturer: syz [ 736.184424][ T24] cdc_wdm 3-1:1.0: skipping garbage [ 736.189696][ T24] cdc_wdm 3-1:1.0: skipping garbage [ 736.216218][ T24] cdc_wdm 3-1:1.0: cdc-wdm0: USB WDM device [ 736.222642][ T24] cdc_wdm 3-1:1.0: Unknown control protocol [ 736.432358][ C0] cdc_wdm 3-1:1.0: wdm_int_callback - 0 bytes [ 736.953732][ T10] usb 3-1: USB disconnect, device number 16 [ 737.199663][ T5950] team0 (unregistering): Port device team_slave_1 removed [ 737.315876][ T5950] team0 (unregistering): Port device team_slave_0 removed [ 739.690330][T12988] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 739.760531][T12988] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 740.328754][T13246] siw: device registration error -23 [ 740.897118][T12988] team0: Port device team_slave_0 added [ 740.939366][T12988] team0: Port device team_slave_1 added [ 742.463137][T12988] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 742.547400][T12988] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 742.573433][ C1] vkms_vblank_simulate: vblank timer overrun [ 742.743627][T12988] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 742.856402][T12988] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 742.863415][T12988] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 743.143502][T12988] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 743.466935][ T5950] IPVS: stop unused estimator thread 0... [ 743.578470][T12988] hsr_slave_0: entered promiscuous mode [ 743.606669][T12988] hsr_slave_1: entered promiscuous mode [ 743.647162][T12988] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 743.684107][T12988] Cannot create hsr debugfs directory [ 746.008113][T13297] virtio-fs: tag not found [ 747.060833][T12988] netdevsim netdevsim7 netdevsim0: renamed from eth0 [ 747.978050][T12988] netdevsim netdevsim7 netdevsim1: renamed from eth1 [ 748.031692][T12988] netdevsim netdevsim7 netdevsim2: renamed from eth2 [ 748.127956][T12988] netdevsim netdevsim7 netdevsim3: renamed from eth3 [ 751.040762][T12988] 8021q: adding VLAN 0 to HW filter on device bond0 [ 751.717351][T12988] 8021q: adding VLAN 0 to HW filter on device team0 [ 751.800249][T13347] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1504'. [ 751.814745][T13347] nbd: socks must be embedded in a SOCK_ITEM attr [ 751.903121][ T5951] bridge0: port 1(bridge_slave_0) entered blocking state [ 751.910370][ T5951] bridge0: port 1(bridge_slave_0) entered forwarding state [ 752.016891][ T5951] bridge0: port 2(bridge_slave_1) entered blocking state [ 752.024187][ T5951] bridge0: port 2(bridge_slave_1) entered forwarding state [ 752.184231][T13352] siw: device registration error -23 [ 753.918836][T13359] overlayfs: missing 'workdir' [ 754.326001][T13366] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1509'. [ 757.008020][ T1290] ieee802154 phy1 wpan1: encryption failed: -22 [ 757.338792][T12988] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 760.225212][T13413] tmpfs: Bad value for 'mpol' [ 762.988492][T13427] virtio-fs: tag not found [ 764.543685][ T5848] Bluetooth: hci2: command 0x0406 tx timeout [ 764.600495][T13448] netlink: 8 bytes leftover after parsing attributes in process `syz.2.1526'. [ 766.811567][ T30] audit: type=1800 audit(2000000308.700:103): pid=13473 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed(directio) comm="syz.5.1530" name="bus" dev="overlay" ino=1353 res=0 errno=0 [ 768.964190][T11774] Bluetooth: hci5: unexpected cc 0x0c03 length: 249 > 1 [ 768.974422][T11774] Bluetooth: hci5: unexpected cc 0x1003 length: 249 > 9 [ 768.982448][T11774] Bluetooth: hci5: unexpected cc 0x1001 length: 249 > 9 [ 768.990922][T11774] Bluetooth: hci5: unexpected cc 0x0c23 length: 249 > 4 [ 769.001331][ T5848] Bluetooth: hci5: unexpected cc 0x0c38 length: 249 > 2 [ 770.449644][T13471] lo speed is unknown, defaulting to 1000 [ 771.073689][ T5848] Bluetooth: hci5: command tx timeout [ 772.051693][T13494] xt_hashlimit: size too large, truncated to 1048576 [ 773.153877][ T5848] Bluetooth: hci5: command tx timeout [ 775.724748][ T5848] Bluetooth: hci5: command tx timeout [ 776.257877][T13471] chnl_net:caif_netlink_parms(): no params data found [ 776.504051][ T48] usb 7-1: new high-speed USB device number 3 using dummy_hcd [ 776.687003][ T48] usb 7-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 776.700791][T12358] Bluetooth: hci6: unexpected cc 0x0c03 length: 249 > 1 [ 776.710110][T12358] Bluetooth: hci6: unexpected cc 0x1003 length: 249 > 9 [ 776.718411][T12358] Bluetooth: hci6: unexpected cc 0x1001 length: 249 > 9 [ 776.728856][T12358] Bluetooth: hci6: unexpected cc 0x0c23 length: 249 > 4 [ 776.739791][T12358] Bluetooth: hci6: unexpected cc 0x0c38 length: 249 > 2 [ 776.966041][ T48] usb 7-1: config 1 has an invalid descriptor of length 55, skipping remainder of the config [ 776.978294][ T48] usb 7-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 777.040286][ T48] usb 7-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 52, changing to 9 [ 777.178711][ T48] usb 7-1: config 1 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 8241, setting to 1024 [ 777.224272][ T48] usb 7-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 777.238350][T13536] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1542'. [ 777.252838][ T48] usb 7-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 777.263578][ T48] usb 7-1: Product: syz [ 777.267987][ T48] usb 7-1: Manufacturer: syz [ 777.348925][ T48] cdc_wdm 7-1:1.0: skipping garbage [ 777.357137][ T48] cdc_wdm 7-1:1.0: skipping garbage [ 777.380073][ T48] cdc_wdm 7-1:1.0: cdc-wdm0: USB WDM device [ 777.424144][ T48] cdc_wdm 7-1:1.0: Unknown control protocol [ 777.591679][ C1] cdc_wdm 7-1:1.0: wdm_int_callback - 6 bytes [ 777.617691][T13471] bridge0: port 1(bridge_slave_0) entered blocking state [ 777.661974][T13471] bridge0: port 1(bridge_slave_0) entered disabled state [ 777.692427][T13471] bridge_slave_0: entered allmulticast mode [ 777.716212][T13471] bridge_slave_0: entered promiscuous mode [ 777.790780][T13471] bridge0: port 2(bridge_slave_1) entered blocking state [ 777.803880][T12358] Bluetooth: hci5: command tx timeout [ 777.805737][ T5895] usb 7-1: USB disconnect, device number 3 [ 778.045550][T13471] bridge0: port 2(bridge_slave_1) entered disabled state [ 778.319123][T13471] bridge_slave_1: entered allmulticast mode [ 778.400412][T13471] bridge_slave_1: entered promiscuous mode [ 778.914792][T12358] Bluetooth: hci6: command tx timeout [ 780.335240][T13471] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 780.698812][T13471] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 780.922225][T13537] lo speed is unknown, defaulting to 1000 [ 781.008470][T12358] Bluetooth: hci6: command tx timeout [ 781.312374][ T5972] bridge_slave_1: left allmulticast mode [ 781.318383][ T5972] bridge_slave_1: left promiscuous mode [ 781.335287][ T5972] bridge0: port 2(bridge_slave_1) entered disabled state [ 782.238672][ T5972] bridge_slave_0: left allmulticast mode [ 782.253627][ T5972] bridge_slave_0: left promiscuous mode [ 782.259412][ T5972] bridge0: port 1(bridge_slave_0) entered disabled state [ 782.642464][T13582] netlink: 'syz.1.1551': attribute type 1 has an invalid length. [ 782.803894][T13582] netlink: 224 bytes leftover after parsing attributes in process `syz.1.1551'. [ 783.434059][T12358] Bluetooth: hci6: command tx timeout [ 785.482182][T12358] Bluetooth: hci6: command tx timeout [ 785.696382][ T48] IPVS: starting estimator thread 0... [ 785.793641][ T5895] usb 3-1: new high-speed USB device number 17 using dummy_hcd [ 785.794526][T13605] IPVS: using max 28 ests per chain, 67200 per kthread [ 785.983828][ T5895] usb 3-1: Using ep0 maxpacket: 16 [ 786.021850][ T5895] usb 3-1: New USB device found, idVendor=05d1, idProduct=2001, bcdDevice= 9.00 [ 786.041583][ T5895] usb 3-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 786.055445][ T5895] usb 3-1: Product: syz [ 786.070629][ T5895] usb 3-1: Manufacturer: syz [ 786.075736][ T5895] usb 3-1: SerialNumber: syz [ 786.104371][ T5895] usb 3-1: config 0 descriptor?? [ 786.123284][ T5895] ftdi_sio 3-1:0.0: FTDI USB Serial Device converter detected [ 786.172266][ T5895] usb 3-1: Detected FT232H [ 786.301180][ T5972] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 786.314124][ T5972] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 786.426551][T13612] hfsplus: unable to find HFS+ superblock [ 786.573910][ T5895] ftdi_sio ttyUSB0: Unable to read latency timer: -32 [ 786.889284][ T5972] bond0 (unregistering): Released all slaves [ 786.973287][T13598] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1554'. [ 786.982632][T13609] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1557'. [ 787.009004][ T5895] ftdi_sio 3-1:0.0: GPIO initialisation failed: -5 [ 787.065364][ T5895] usb 3-1: FTDI USB Serial Device converter now attached to ttyUSB0 [ 787.084250][ T5972] hsr_slave_0: left promiscuous mode [ 787.113604][ T5972] hsr_slave_1: left promiscuous mode [ 787.132041][ T5972] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 787.248843][ T5972] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 788.130387][T13620] netlink: 16 bytes leftover after parsing attributes in process `syz.6.1559'. [ 788.385051][ T24] usb 3-1: USB disconnect, device number 17 [ 788.596162][ T5848] Bluetooth: hci4: command 0x1003 tx timeout [ 788.604033][T12358] Bluetooth: hci4: Opcode 0x1003 failed: -110 [ 789.511988][ T24] ftdi_sio ttyUSB0: FTDI USB Serial Device converter now disconnected from ttyUSB0 [ 789.538933][T13624] netlink: 36 bytes leftover after parsing attributes in process `syz.6.1559'. [ 789.540358][ T24] ftdi_sio 3-1:0.0: device disconnected [ 795.489235][ T5972] team0 (unregistering): Port device team_slave_1 removed [ 796.717476][ T5972] team0 (unregistering): Port device team_slave_0 removed [ 798.930544][T13471] team0: Port device team_slave_0 added [ 798.949250][T13471] team0: Port device team_slave_1 added [ 799.358674][T13676] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000021: 0000 [#1] SMP KASAN NOPTI [ 799.370813][T13676] KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] [ 799.379247][T13676] CPU: 1 UID: 0 PID: 13676 Comm: syz.5.1573 Not tainted 6.15.0-rc6-syzkaller-00093-g546bce579204 #0 PREEMPT(full) [ 799.391351][T13676] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 799.401430][T13676] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 799.406577][T13676] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 2a 8a 5f f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 799.426229][T13676] RSP: 0018:ffffc90004b27bf0 EFLAGS: 00010283 [ 799.432328][T13676] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffc90012576000 [ 799.440331][T13676] RDX: 0000000000080000 RSI: ffffffff885bbb66 RDI: 0000000000000005 [ 799.448336][T13676] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 799.456338][T13676] R10: 0000000000000001 R11: 0000000000000000 R12: ffffc90004b27d88 [ 799.464336][T13676] R13: ffffc90004b27d88 R14: 0000000000000001 R15: ffff888024d79000 [ 799.472339][T13676] FS: 00007f133fb5e6c0(0000) GS:ffff888124ae3000(0000) knlGS:0000000000000000 [ 799.481313][T13676] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 799.487926][T13676] CR2: 00007f133fb5df98 CR3: 000000003213a000 CR4: 0000000000350ef0 [ 799.495924][T13676] Call Trace: [ 799.499214][T13676] [ 799.502159][T13676] ? srso_alias_return_thunk+0x5/0xfbef5 [ 799.507838][T13676] ? __pfx_bcsp_recv+0x10/0x10 [ 799.512637][T13676] ? srso_alias_return_thunk+0x5/0xfbef5 [ 799.518313][T13676] ? srso_alias_return_thunk+0x5/0xfbef5 [ 799.523998][T13676] hci_uart_tty_receive+0x254/0x7e0 [ 799.529252][T13676] ? __pfx_hci_uart_tty_receive+0x10/0x10 [ 799.535032][T13676] tty_ioctl+0x580/0x1610 [ 799.539405][T13676] ? __pfx_tty_ioctl+0x10/0x10 [ 799.544218][T13676] ? srso_alias_return_thunk+0x5/0xfbef5 [ 799.549888][T13676] ? find_held_lock+0x2b/0x80 [ 799.554609][T13676] ? srso_alias_return_thunk+0x5/0xfbef5 [ 799.560275][T13676] ? hook_file_ioctl_common+0x145/0x410 [ 799.565859][T13676] ? srso_alias_return_thunk+0x5/0xfbef5 [ 799.571532][T13676] ? __fget_files+0x20e/0x3c0 [ 799.576260][T13676] ? __pfx_tty_ioctl+0x10/0x10 [ 799.581058][T13676] __x64_sys_ioctl+0x193/0x200 [ 799.585861][T13676] do_syscall_64+0xcd/0x260 [ 799.590415][T13676] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 799.596331][T13676] RIP: 0033:0x7f133ed8e969 [ 799.600785][T13676] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 799.620436][T13676] RSP: 002b:00007f133fb5e038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 799.628868][T13676] RAX: ffffffffffffffda RBX: 00007f133efb6320 RCX: 00007f133ed8e969 [ 799.636850][T13676] RDX: 0000200000000200 RSI: 0000000000005412 RDI: 0000000000000003 [ 799.644834][T13676] RBP: 00007f133ee10ab1 R08: 0000000000000000 R09: 0000000000000000 [ 799.652811][T13676] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 799.660797][T13676] R13: 0000000000000001 R14: 00007f133efb6320 R15: 00007ffe36c32658 [ 799.668790][T13676] [ 799.671822][T13676] Modules linked in: [ 799.677301][T13676] ---[ end trace 0000000000000000 ]--- [ 799.681455][T13674] hfsplus: unable to find HFS+ superblock [ 799.682768][T13676] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 799.693701][T13676] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 2a 8a 5f f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 799.713743][T13676] RSP: 0018:ffffc90004b27bf0 EFLAGS: 00010283 [ 799.720149][T13676] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffc90012576000 [ 799.728234][T13676] RDX: 0000000000080000 RSI: ffffffff885bbb66 RDI: 0000000000000005 [ 799.736303][T13676] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 799.744369][T13676] R10: 0000000000000001 R11: 0000000000000000 R12: ffffc90004b27d88 [ 799.752410][T13676] R13: ffffc90004b27d88 R14: 0000000000000001 R15: ffff888024d79000 [ 799.760486][T13676] FS: 00007f133fb5e6c0(0000) GS:ffff888124ae3000(0000) knlGS:0000000000000000 [ 799.769473][T13676] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 799.776105][T13676] CR2: 00007f133fb5df98 CR3: 000000003213a000 CR4: 0000000000350ef0 [ 799.777758][T13672] netlink: 8 bytes leftover after parsing attributes in process `syz.5.1573'. [ 799.784110][T13676] Kernel panic - not syncing: Fatal exception [ 799.784392][T13676] Kernel Offset: disabled