last executing test programs: 4m26.15300082s ago: executing program 2 (id=803): r0 = open_tree(0xffffffffffffffff, &(0x7f0000000000)='./file0\x00', 0x100) setsockopt$netrom_NETROM_T4(r0, 0x103, 0x6, &(0x7f0000000040)=0x4c, 0x4) ioctl$VIDIOC_SUBDEV_ENUM_MBUS_CODE(r0, 0xc0305602, &(0x7f0000000080)={0x0, 0x4, 0x2003, 0x1}) splice(r0, &(0x7f00000000c0)=0x2, r0, &(0x7f0000000100)=0x8, 0x9, 0x7) mlock2(&(0x7f0000ffc000/0x1000)=nil, 0x1000, 0x0) mmap$dsp(&(0x7f0000ffc000/0x2000)=nil, 0x2000, 0x3000000, 0x40010, r0, 0x0) ioctl$VIDIOC_G_MODULATOR(r0, 0xc0445636, &(0x7f0000000140)={0x401, "dabce57bc5ce14d2faf94bbffdd2aa73ae7d224494922a6c56d4520b4646ba35", 0x800, 0x8000, 0x3, 0x10, 0x5}) syz_open_dev$video4linux(&(0x7f00000001c0), 0x800, 0x0) r1 = openat$sequencer(0xffffffffffffff9c, &(0x7f0000000200), 0x40002, 0x0) write$6lowpan_enable(r0, &(0x7f0000000240)='0', 0x1) ioctl$SNDCTL_TMR_START(r0, 0x5402) r2 = syz_open_dev$vcsn(&(0x7f0000000280), 0x100000000, 0x2000) r3 = syz_open_dev$ttys(0xc, 0x2, 0x1) fcntl$getownex(r0, 0x10, &(0x7f00000002c0)={0x0, 0x0}) ioctl$TIOCSPGRP(r3, 0x5410, &(0x7f0000000300)=r4) prlimit64(r4, 0xc, &(0x7f0000000340)={0x1, 0x8868}, &(0x7f0000000380)) ioctl$VHOST_VSOCK_SET_RUNNING(r0, 0x4004af61, &(0x7f00000003c0)) io_setup(0x1, &(0x7f0000000400)=0x0) r6 = eventfd2(0x2, 0x80000) r7 = openat$incfs(r0, &(0x7f0000000880)='.log\x00', 0x241, 0x14) r8 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000900)={0x2, 0x4, 0x8, 0x1, 0x80, r2, 0x9, '\x00', 0x0, r0, 0x4, 0x0, 0x2, 0x0, @void, @value, @void, @value}, 0x50) io_submit(r5, 0x5, &(0x7f0000000a40)=[&(0x7f0000000540)={0x0, 0x0, 0x0, 0x5, 0x40, r1, &(0x7f0000000440)="b00ed0a5dcdc241d074b4f583c1a58194b66b17a2ed2502579ba12f24b3a999386afd6859eed9273dd5eb5ce93d180d8b0b21deb7907531616eb7189ede144dfaea1eebbfeaad93b1d322fc2272dca75c4ed3c9e4568835a7f2bb99ab790d905c72634f4b848c9b176fbfde3c46e29bff9fb151c81ca0f17e3c1b569011da0fc0a5ca7aac955330c4125f251c73229291753c0f86da3f364d328ec1574cffa265f86f92dabc1583b561764442526ff61b62133aad64bfe415e38a4e3786b8cc92ec47bc4197b76c320d7", 0xca, 0xcb, 0x0, 0x1, r0}, &(0x7f0000000600)={0x0, 0x0, 0x0, 0x7, 0x47b, r1, &(0x7f0000000580)="dc2fbe8e364fbbf4a74e660eefc09a6c05dc332122b53d751297bdb2568cb770619ba0d899aa6c24eaa73bb4e8ca0c7661cafc2ec740dda14088981a9291a9ff87761126e18c", 0x46, 0x9, 0x0, 0x3, r6}, &(0x7f0000000740)={0x0, 0x0, 0x0, 0x2, 0xde1, r2, &(0x7f0000000640)="959c09112f80b23cab914f792ca13b3cf3c189e1943139988168ce9643c14eea078550dafb1300ab021dd1c5ce430843f9566b77088df2f1b761a3bfb0e71c072c840bea2fe5bb87a8173f2befa9c21a3f76ef81719df359b4ae56a1a13d6a27b51416f7cc9e0ac9d8383a8f999f85feab78aa05fcaf031b3aa14a976d21be38bbb21a29d0d7418ddda8e06eb0105aa45e7b9ec07b1a476b72b5c264c6b4f794baba0cced7d4b673bb7ce9e5e79f8558564345f852d3d2f80e37536952f5defb3f7814e5468ef85c00b915f82cca2900a2ec2f02c0966230d359c9e120839fd923fc59cec71384eef4470c", 0xeb, 0x9, 0x0, 0x2}, &(0x7f00000008c0)={0x0, 0x0, 0x0, 0x8, 0x0, r3, &(0x7f0000000780)="33ecf47ceeb798cbf0e23eacb3f583b96e94808b3ff068e7a0e6152fdfbb1057586663f72cbcd2e106b76d61047b9396cb908407e4f8f9c2fb510dabcd6675ec52601b765b9fd4cc68e6174368cd9f99e6d827a4219cd39973174e4cb71473c3652682ddc5a9629aab0d1b19e83fe3e212d9c4fe98c188c64a4756e6cec26a41d42a1b9b576bcb17f70937fc1153cdb450ac19a7d6a4ea742ad61b229c761245c7762bf36d565eea4c9cd052a036c323ff34776c28c4f1d0d11432bb7b52867967dbe21b6704a631bf6244", 0xcb, 0x8, 0x0, 0x2, r7}, &(0x7f0000000a00)={0x0, 0x0, 0x0, 0x2, 0x3d, r8, &(0x7f0000000980)="d59269771e4d3e0ed566d9d72d4c45ad5be68f5174086bb184b3926bf4e352e48d14f796c36604910a449ec15ed74f5c338b8cbf5b0752e71f248e42e64138883bf8c359d2c64eac8e694c0aa40d14069e7b", 0x52, 0x1, 0x0, 0x3, r2}]) r9 = mq_open(&(0x7f0000000a80)='/dev/sequencer\x00', 0x40, 0x10, &(0x7f0000000ac0)={0x949, 0x40000000, 0x10, 0x6}) mq_notify(r9, &(0x7f0000001b80)={0x0, 0x1d, 0x0, @thr={&(0x7f0000000b00)="35cebaf2cf8e3fd66010acfc2feba78aa52c9a2b577535fba1523d0b7b92676ead88d3e6ce34e3d8b684f06f7754eaa44619a1382df1a4cf67428e8ab9b1708d94397d55728ed88a060690f6aa3615d851bce6561da9688635dff4eb96b8", &(0x7f0000000b80)="9d13bfddbc0d47ea7268f11597e7887a1d75121cdc8ebc2900e217ef6b28d4c3a1bc4f02e75e2fd4bbcd3668f70f86da1f61639de5f6a65fc1c3ddb6041e18d0792d2159ea2bf8a83fd62d1b98262d4fe6a7b0d504738589aebe25635a9f2bb8d6b4b03dd4997eeb1d6fa07627b2a6431902aaa2ae3015d3f878525b2fd60f19179c8a1ea8ffd47fdd0d434350a86c678e545214c446362367b4104823dafa8ca8930273da3c0b206831278cbe59cf6353fd66ae7d4c866a39286e388820867e5cb2803c2552aed9d748a3e6e84dd1d699a66b473a2bfe5dede833eb39c0d0cb8e568734caa595b605c9e160d15846eb864ef69b1d23bf365f4a4c9c7445de41a9b993aaf8c71beb1c5e2d843e52972295243b2f6cf017bfea9eb1c08fc28c859450f34f9cbfdd8987a1752731352e6523975b6ff32374de8cba5056bd8f5dd8afb1cbdabb3234b435289db5e45064c52c5fbc72cdf397aa2df36999107c7812ddfa9e46996a781693f25ce7c231ef87ec62406f99dcec650a41fee35d68eb2e7f11c60475747fc16262c55dff3dea15b793c10cb4b6939d92dfbd2a8dbd7c3a5366c0051086aaadf2e440ee099adc84214a102f26ae627189e24787664d2225f54ed5f2d9db1a29a172bcce355c6facdd86ed29b2bae21f4bc8f815902cdcf1b14142ee8c8dc19e3b7a8fbb5f4c0088eae5c9bf99b84f6499e2c8481c308d15a5781d85dbf483d0e35b7a3743ffea0bdbd51109dff3686d2927dabfecacff20f67cf2701345a69bb0591605ab3408a627cd7ee5f46b261f17115a2797beca68e3780ae9487e297a6f8364876c95e019bf06ce7443426813a921bf554922f302d9eb3d788015de09121e08008098f79688ef167ad5559479f9aae2c81096f590443b6428cec8b1a73341aaf5f3e3420b90e2afabfa1bd441853f19c97c170e6343d9ecac37ac5fd374bffb5651bb0c62e1043cc578960f586c18479b8d3553b338d287e5c8a49a7fe12a596e3a0c913b28a0f08323eeae13a1f4cdeca44575874967a49528873abf2c8f0b48bdfc936b4504550634c3b129534cc2b2965ad8a81cec58a3fba4d9b895c16f87a1eb94e0130b279ad1625ebdf851940258ca7d46bd5c12365b8ecc40b6cc0ec20dbe8399c762c32c9b12a29383e4454fc67bff97fcae01488a89222be9f8722c7fdea950b6d914280d07b589c5bb1fd9cc4bd78ad352b0c63c5e2e8472d6a5fda8e0458926141baa6998d5c8a8c4df97c30d1e8be67b3eb33ab2df1b1a6fd213fd3ffb1828a0aa584b42a73d618497678450bcf2bc5bbd6bde2ecf096922f4fd1ae0dc3ac3ff4cbaa0ce568cc6dd590bd3c9cde95d804bd52ff1ada24bc8000acd7cbd3f15794121c1b40aa5c1df0db6d6253b104deea465f8a2b010756651cc298f5b2d1a0a73594cbc25cc9eeab999053937e6d10609668cdf70a30d933acc4d73defaf22d1c7e525d16639adc49d5d4c411892ee8fd0076ec8bff2fb520ca5fc7775acdaa85c4f13dae1808aee19eeee9af35da095050ba5db1dd0e139fa59cc704ea7dc56e9a01daedbc0eb1418e5c0df34ec9d45ff01c90d898e53ff363d8b756b35fe45c90baa5cc57ac4c9692aaa7013b0518852fef10338621beca8accccb345596461321e61d2f72d759769d2c7a8de91338af2d674bd16c1c60b04fd656a7bf88bcf00ae4642792a28783d200de2b5260178cccf7ed869abcededaa3ca5f55d874fb212ac46aa64d2e9111a0c20d017a7aa110e9725c3de66bd5019a1830cbf3fd999e81cce3364f8e30cde337f39e0606b7ab05ac8f9a8c99410a54129c19eb0ecb82fc9c38ddbc552fc801a12617cc7a12e523ecddf78df44a83e166ff39291f6b20ef24ff2df4fca1c40fd44fc0c27240ae4c2cfddba713f69e9b8255f539300f84136b86042ad1c636ff756f20d7d569693fda92827e7d39e37af1ed0659f16e31527a4ed1ea79424b2e55fe130f711bb71f86e58223ba0fa3502d41c89dc945204191a4b76a670e9005cb63b0f45aacecbb418dbbf09fa117477b185eb8a65b97fa8bfe82d2e19fd84fd5ef3ecea9520c5fdccbb450d025201e659709ca42abe164a446802d8a66a1e7c15645d1172836d30adf84161f428e519cdb36a225d2ed5290b0bec27ed35a51560aed26b06878cd51d54d59448c4aaec072b79d52c1587a5c385678e5a515d421fbfa9936e3fb73a93e84a6bd5ffc45bee13c900e9bd49a2d929ed69baa21a81d774d27ce8564c2a035759345c9ca546a0269cb36cb8c6a71f89cc561acfbd8d26927fc43969c64840f9498649d14a9dd6f624ef354bbc7553d2d5fc7520da78b7a1cef57f2e51edd797d860b44a113a5b0cbbe95360df5cd9eed310559fe8d00621bd1ed19007ef26fb2ca0a0caa5709b5e17662f5adc6a9fd9b6d312efe243bcae23318967728d224e3c1c544778fa6884f222a390cb12c347701e662d0c81fa19d224f719bf2982a683ff815326e9b07afaa32494797a6010cfaad891456f97b6d692c18a8620fa77284ce82d0bfbcd20378f6b016be10caff75d181ac58917599b8161f91d652c6e42456bf49df3477d46f95580dbfde508cb237ce00bf52c05cb6311e8547f66b780aac9c4539d9e96a4ac16c0630a6d68503c413ac024708087082e1d138fa0b8536076c010d74eb5435c7c593389c61cceac72c9fb5cff43cdd60d978a8a54dcb21aa4a3474a7c5a43b5b77e10a1d0a6d7a27d054756265733efe448339f3a8450127a4f480e2f59c4be1722d6b05f7998391400b20c72a8cb6dfcc3587582c7b18a615a8ef114224d3a249e9f177a40f5d031072cd8dba98c13ee2599397af5832108ab2fd09e73f666770b32d964f95cf4e891afed24cfc0a561e05882462f1ac9bc4d1906f583413c5c413346091795324a6d2a5affaa0accb0210f389c41ad09bf19f11ef9a3fdb64f884361dd3f46e8bf8a70a367a48eb97cb2b189f6366acf5c51f9c9a886281881e7016f8b52ef6dd06ee9b44c60f1ab3393a5705f32fc98f0ec26c75fea65b31da5c2e7150836adb1c4022096e858b18c2393d772007894ac3715e960c854a793573a63a442466cccbf251ebf5ed72c0bf3a813f939eb344f224be78cb30a90a8baef5328f6ea6ae237cc6e90af1dfe27dd6b17b998ffe21a5e9e98f2a78800b9b948bc5858b426ab4bd346a2d317bc58767c66bf42a1aa1a524187e59782ef84bd7263185e05d8b0e17b36025b82c8067eea69d491a9fdbf8e024b3b3c25e0004e5af85bfd023da9ae80c5a518b4caa3cede65943533e989c36782eff1dcbe6d7b43c2700c501326bbabeb38dbc8f4d00ea1c618612ec84be664212e5247b35de63d219ac5d1435091c181707f28f9a318080be6a39fc79adc5aa6e473f06cbcaf84a210569004b3c6753e20eb7bc7ac3b1aef45575da2a24fc759adede1be32682178d03d33e584b82c41ef2c2b669ff7c6a11b34ed0021105cc3a553fafdec7efe158c59763c7f1f46cc7803bb38bdbc4a901b7c57512b031f1b23e40b9a575b572124784562ac05ab9decb08d959834439d890a7368c9e2965fa0e698df3a79185d1d96f51eaf51b867df29777727b85cacf778707017f8ffaa8fd71999fadd3f39d36cdabe0e718a84f4069a12b358b3ddb01d876398289fa4f7e242d96932e648a68a0564f0b6ac332c7c05cad3f6a4beb7f33d68be569c3a5f2f424ff002d816cf65660759fbc388e0ef07b9a3b6687340b58f8d906998b714b1bb753ad66e11137bd5ea34b5375a50ef40b09dbbd810f3cd505f2ea4e57ee22ea1cb5fff9cf81e8c401d2d12f32efe3ca75e70f3e217bf4afc80477e71d4d81744bd5da16741f40aa2bd6f1ad49924a6ff2e9191ef5d4878f26728a5e696a6edc6d8ee80935f98522a09253d33a6038c9587cdeb22d931ad1cf1a9c1ff1c56316810ecc297f7dfdf673027ff0145ae7802a4c2d28d118708db4440eb49352ad9ca1032171b7593d1e362b7e4678059adc5417755e4f8d2d35ef50c9d0a8d3c7c1753dc0c051c36743422bf6b7f32881faeab5fd5a9959b48241fb7323e91dabf5b9a784669cd0cbddbee5a398cae95e1f748ceda6cacb8796325956c370ec516df07f7feaec47042e3293c213f4dcfc98c5f44094bf24657656fad9c48274c2d9dae3bd17e582d53d0870aca901e4abb1381c9f1c5b5694d448bf39144218135eff534ae158cdd809e4d12090ff243f100f7d565ad4df593d23d99c9c1c91d2503abce16340fa3e88da63d9de4078222b57313f97fe8a6e5f4cc58ec86d193e53ad7ffef640306659291a9d603de488197f818b373b32cccdf985074b2a6a99965ff13c0e8097afd355a5387b7b148e61287dc7ca726f1fb331e65c6ff9b6455482cacde87197118460afab82ae74dca11af981f998e16b9dd0e1545bb102910eed9146832c72c9066d3717faa0dbb42267342d4f351358d3df3e749d41c75af8be2160e044019832761972ff13b156f399250bbdc5ed1f7b67b51cbc6273012a2e5922a51f27c5bbc561649df649351e861a4d090265b5abc9edda704ff4d8cfb03849218851acf44ae77c72a350098ff93bbad1166326d1e2eb6bac014b40f764bde3376c0b9db7e06f2d11412a86dd59157a62737dd0437ac5b131cc63633ee0562b0f19e64f6f321df4c0b850e3b33abcbd207135e02e5da101baadbe59d3ef5a9700567cdcf8a4ea3351de74d98c7f781031e30826d645df03a2e5eaf0fcef1087fcc3f791c04684b997d031809dd0617dfa7b8c68e09efcce9d48118a5db0e723007795d8dfa04fd169b69882bc5b1aba189c9cff7d4a7cebaa4c4e78562589a5e5a973318efe5d85eca3dca4ae0f3480af6d713687833fea1ad3db72cb3059e65c812d3162a75e6c10e5e36eebdf2cb3bbfed3aa07b739844dbaa13eeec60b81eadacd4274906c85a459ad134d5c9edf14ec0fe8df4da0abec5ef4bef90e7825a6191b915864a4fe6088fee306eba451a35cd181f3b1ba33af85040461c0172c60e548bad8b4276eb21577149b5b80728665adbb972f6c3236d9ccafe307849e15ee4a3ec5007e3201deedcf685145b46bdfafb900d140874fe3b1c5144961dc512c219000391fbd441b0815472d2fa785873256dd85d44d26b00e852d1dcf57bd2be1e592fb3b5c0c81d02b0adf3c1e5f334463d264a79bfbd3502fe1ad97293baf4c70542283f767bedbafa0d4ec531854c82762745bcd7ea3e8302678dd1df2477ff596372fc2998eaf7c8dc4b2537e3deccb0143fbba1d1277f25b7c26afdf2ec7da173ece3425296fc4a623f45bb6fd32a121b2040ac76cb4a6d26fbc7f241585425ef9bf9fbe9eb5e7581f1936eb933996f90d816161d48a29115f0e4a70ca218d4754155729f8ba238b7b0e212fc59af483c58e97bea6ee47c5d4a5a1fbd812a2057fabdfd587e25ba81ec156b579141b20b06b2b344c1fe53325357d21777d66996fff51c87a698e1f2ac4c34fcefc640ac6eb5089a77e47f69e583ec06bd6a289fb7a95057793c2c0eadaf0c9f20b104333fdf50acbdaa41b64763c75db0f3c07bd98f97970adddaf5abec90c43d523b5342626dd51aed79fb05be9160fe5886de72df29db023850187f5d7997fb060949206cc0bab190d2d75e8b3cb1416cc6b51156570b595334d76363f4c7c2e4425942a798174a1c5e92fc9d9042a2fc09f7f37f1ada31063b606f06ced964c0dc69ee3da7299118018b10575b818c49b3d5779924644427508"}}) syz_open_dev$I2C(&(0x7f0000001bc0), 0x3, 0x200) syz_io_uring_setup(0x2b4c, &(0x7f0000001c00)={0x0, 0x3e7d, 0x20, 0x2, 0x2e, 0x0, r7}, &(0x7f0000001c80)=0x0, &(0x7f0000001cc0)) syz_memcpy_off$IO_URING_METADATA_GENERIC(r10, 0x110, &(0x7f0000001d00)=0x3a, 0x0, 0x4) socket$inet6_udplite(0xa, 0x2, 0x88) r11 = socket$igmp6(0xa, 0x3, 0x2) ioctl$BTRFS_IOC_QGROUP_CREATE(r11, 0x4010942a, &(0x7f0000001d40)={0x1, 0x4515}) 4m25.413278141s ago: executing program 2 (id=806): r0 = openat$selinux_member(0xffffffffffffff9c, &(0x7f00000001c0), 0x2, 0x0) write$selinux_access(r0, 0x0, 0x0) (fail_nth: 1) 4m24.314324622s ago: executing program 2 (id=811): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0200000004000000050000000200000000"], 0x50) r4 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000180)=ANY=[@ANYBLOB="1800"/15, @ANYRES32=r3, @ANYBLOB="0000000000000000b7080000000010007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000100000095"], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffc, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) r5 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r5, &(0x7f000000c2c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000140)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a28000000000a0101000000005e1affd5020000000900010073797a300000000008000240000000032c000000030a01030000e6ff00000000020000000900010073797a30000000000900030073797a320000000014000000110001"], 0x7c}}, 0xc048) sendmsg$NFT_BATCH(r5, &(0x7f0000000080)={0x0, 0x0, &(0x7f00000003c0)={&(0x7f0000000580)=ANY=[@ANYBLOB="140000001000010000000000000000000000000a78000000060a0b0400000000000000000200000038000480340001800b00010074617267657400002400028010000100434f4e4e5345434d41524b0005000300ef00000008000240000000000900010073797a30000000000900020073797a3200000000140005800800024000000000080001", @ANYRES8=0x0, @ANYRES8], 0xa0}, 0x1, 0x0, 0x0, 0x40000}, 0x44110) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000002c0)={&(0x7f0000000080)='sched_switch\x00', r4, 0x0, 0x7}, 0x18) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000100)={&(0x7f0000000040)='kmem_cache_free\x00', 0xffffffffffffffff, 0x0, 0x5}, 0x18) 4m22.937923589s ago: executing program 2 (id=812): sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000680)=@newtaction={0xd4, 0x30, 0x1, 0x0, 0x0, {}, [{0xc0, 0x1, [@m_ct={0x44, 0x3, 0x0, 0x0, {{0x7}, {0x1c, 0x2, 0x0, 0x1, [@TCA_CT_PARMS={0x18, 0x1, {0x9d, 0x11e41e7a, 0x20000000, 0x0, 0xf}}]}, {0x4}, {0xc, 0x7, {0x0, 0x1}}, {0xc}}}, @m_ife={0x78, 0xb, 0x0, 0x0, {{0x8}, {0x20, 0x2, 0x0, 0x1, [@TCA_IFE_PARMS={0x1c, 0x1, {{0x0, 0x400}}}]}, {0x32, 0x6, "2a1e065d53f9a12a6f0643881fd179759c537f545a6e3aacbb00372cba1068b1e5e61188f48471457bbe706e8044"}, {0xc}, {0xc}}}]}]}, 0xd4}, 0x1, 0x0, 0x0, 0x804}, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, 0x0, 0x0) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) sched_setaffinity(r0, 0x8, &(0x7f0000000240)=0x2) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) syz_io_uring_submit(0x0, 0x0, 0x0) syz_io_uring_setup(0x10d, &(0x7f0000000300)={0x0, 0xce5d, 0x80, 0x0, 0x89}, &(0x7f0000000240)=0x0, &(0x7f0000000280)) r4 = fsopen(&(0x7f0000000380)='btrfs\x00', 0x1) fsconfig$FSCONFIG_CMD_CREATE(r4, 0x6, 0x0, 0x0, 0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r3, 0x110, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) r5 = syz_open_procfs(0x0, &(0x7f00000001c0)='net/ptype\x00') read$msr(r5, &(0x7f0000000040)=""/59, 0xffb5) r6 = socket$inet6(0xa, 0x1, 0x0) bind$inet6(r6, &(0x7f0000000100)={0xa, 0x4e20, 0x0, @loopback}, 0x1c) sendmsg$RDMA_NLDEV_CMD_DELLINK(r5, &(0x7f00000005c0)={&(0x7f00000003c0)={0x10, 0x0, 0x0, 0x400}, 0xc, &(0x7f0000000580)={&(0x7f0000000500)={0x20, 0x1404, 0x20, 0x70bd2d, 0x25dfdbfb, "", [@RDMA_NLDEV_ATTR_DEV_INDEX={0x8, 0x1, 0x2}, @RDMA_NLDEV_ATTR_DEV_INDEX={0x8, 0x1, 0x1}]}, 0x20}, 0x1, 0x0, 0x0, 0x20008080}, 0x20000000) mmap(&(0x7f00009ff000/0x600000)=nil, 0x600000, 0x0, 0x11, r6, 0x0) setsockopt$SO_TIMESTAMP(0xffffffffffffffff, 0x1, 0x41, &(0x7f0000000000)=0xff, 0x4) sendmmsg$inet6(r6, &(0x7f0000000d40)=[{{0x0, 0x0, 0x0}}], 0x1, 0x4008800) getsockopt$inet6_tcp_TCP_ZEROCOPY_RECEIVE(r6, 0x6, 0x23, &(0x7f0000000400)={&(0x7f0000f59000/0x2000)=nil, 0x4000, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffff81, 0x1, 0x0, 0xfffffffffffffe27}, &(0x7f0000000800)=0x40) socket$netlink(0x10, 0x3, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000440)={0x1f, 0x9, &(0x7f0000000000)=@raw=[@printk={@lu, {}, {}, {}, {}, {}, {0x85, 0x0, 0x0, 0x96}}, @exit], &(0x7f0000000200)='syzkaller\x00', 0x80000000, 0x0, 0x0, 0x0, 0x10, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 4m21.085916899s ago: executing program 2 (id=819): sendmsg$key(0xffffffffffffffff, &(0x7f0000000100)={0x3, 0x0, &(0x7f0000000080)={&(0x7f0000000600)=ANY=[@ANYBLOB="0203c9181000000000000000000000000200080008000000660000000000000005000600000000000a000000000000000000000000000000000000000000000100000000000000000200010000000000000000fd0000000005000500000000000a00000000000000fe8000000000000000000000000000aa0000000000000000"], 0x80}, 0x1, 0x7}, 0x0) 4m20.944079913s ago: executing program 2 (id=821): r0 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x0) readv(r0, &(0x7f00000002c0)=[{&(0x7f00000000c0)=""/79, 0x4f}], 0x1) mkdir(&(0x7f0000000000)='./file0\x00', 0x0) openat$vimc0(0xffffffffffffff9c, &(0x7f00000003c0), 0x2, 0x0) openat$cuse(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) r1 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r1, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r2 = syz_io_uring_setup(0x497, &(0x7f0000000400)={0x0, 0x707b, 0x800, 0x4, 0x8}, &(0x7f0000000340)=0x0, &(0x7f0000000140)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r3, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r3, r4, &(0x7f00000002c0)=@IORING_OP_WRITEV={0x2, 0x0, 0x0, @fd_index=0x4, 0x0, 0x0}) io_uring_enter(r2, 0x3516, 0x0, 0x4, 0x0, 0x0) r5 = socket$inet6_sctp(0xa, 0x1, 0x84) bind$inet6(r5, &(0x7f00004b8fe4)={0xa, 0x4e23, 0x0, @empty}, 0x1c) sendto$inet6(r5, &(0x7f0000847fff)='X', 0x34000, 0x0, &(0x7f000005ffe4)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) setsockopt$inet_sctp6_SCTP_PEER_ADDR_PARAMS(r5, 0x84, 0x9, &(0x7f0000000380)={0x0, @in={{0x2, 0x4e23, @empty}}, 0x9, 0x3, 0x0, 0x6, 0x55, 0x0, 0x7c}, 0x9c) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mkdir(&(0x7f00000004c0)='./bus\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000400)={[{@uuid_off}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) r6 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000440), 0x0, 0x0) r7 = ioctl$KVM_CREATE_VM(r6, 0xae01, 0x0) r8 = ioctl$KVM_CREATE_VCPU(r7, 0xae41, 0x0) mmap(&(0x7f0000000000/0x3000)=nil, 0x3000, 0x7, 0x13, r8, 0x0) ioctl$KVM_SET_REGS(r8, 0x4090ae82, &(0x7f00000000c0)={[0x78, 0xfffffffffffffffd, 0x3, 0xffffffffffffffff, 0x1, 0xfffffffffffffffe, 0x2, 0x5, 0x40007fffffff, 0x6, 0x7, 0x80000001, 0x24e, 0x3, 0xffffffffffffffff], 0x0, 0x98302}) ioctl$KVM_SET_GUEST_DEBUG(0xffffffffffffffff, 0x4048ae9b, &(0x7f0000000000)={0x0, 0x0, [0x10001, 0xe5, 0x3, 0x2, 0x4, 0xca9, 0x3b, 0xf9d1]}) ioctl$KVM_RUN(r8, 0xae80, 0x0) openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file1\x00', 0x0, 0xd) 4m5.676235769s ago: executing program 32 (id=821): r0 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x0) readv(r0, &(0x7f00000002c0)=[{&(0x7f00000000c0)=""/79, 0x4f}], 0x1) mkdir(&(0x7f0000000000)='./file0\x00', 0x0) openat$vimc0(0xffffffffffffff9c, &(0x7f00000003c0), 0x2, 0x0) openat$cuse(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) openat$sequencer(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) r1 = syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) writev(r1, &(0x7f0000000840)=[{&(0x7f00000002c0)="94", 0xf000}, {0x0}], 0x2) r2 = syz_io_uring_setup(0x497, &(0x7f0000000400)={0x0, 0x707b, 0x800, 0x4, 0x8}, &(0x7f0000000340)=0x0, &(0x7f0000000140)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r3, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r3, r4, &(0x7f00000002c0)=@IORING_OP_WRITEV={0x2, 0x0, 0x0, @fd_index=0x4, 0x0, 0x0}) io_uring_enter(r2, 0x3516, 0x0, 0x4, 0x0, 0x0) r5 = socket$inet6_sctp(0xa, 0x1, 0x84) bind$inet6(r5, &(0x7f00004b8fe4)={0xa, 0x4e23, 0x0, @empty}, 0x1c) sendto$inet6(r5, &(0x7f0000847fff)='X', 0x34000, 0x0, &(0x7f000005ffe4)={0xa, 0x4e23, 0x0, @loopback}, 0x1c) setsockopt$inet_sctp6_SCTP_PEER_ADDR_PARAMS(r5, 0x84, 0x9, &(0x7f0000000380)={0x0, @in={{0x2, 0x4e23, @empty}}, 0x9, 0x3, 0x0, 0x6, 0x55, 0x0, 0x7c}, 0x9c) mkdirat(0xffffffffffffff9c, &(0x7f0000000340)='./file1\x00', 0x0) mkdir(&(0x7f00000004c0)='./bus\x00', 0x0) mount$overlay(0x0, &(0x7f00000000c0)='./bus\x00', &(0x7f0000000080), 0x0, &(0x7f0000000400)={[{@uuid_off}, {@lowerdir={'lowerdir', 0x3d, './file0'}}, {@upperdir={'upperdir', 0x3d, './file1'}}]}) r6 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000440), 0x0, 0x0) r7 = ioctl$KVM_CREATE_VM(r6, 0xae01, 0x0) r8 = ioctl$KVM_CREATE_VCPU(r7, 0xae41, 0x0) mmap(&(0x7f0000000000/0x3000)=nil, 0x3000, 0x7, 0x13, r8, 0x0) ioctl$KVM_SET_REGS(r8, 0x4090ae82, &(0x7f00000000c0)={[0x78, 0xfffffffffffffffd, 0x3, 0xffffffffffffffff, 0x1, 0xfffffffffffffffe, 0x2, 0x5, 0x40007fffffff, 0x6, 0x7, 0x80000001, 0x24e, 0x3, 0xffffffffffffffff], 0x0, 0x98302}) ioctl$KVM_SET_GUEST_DEBUG(0xffffffffffffffff, 0x4048ae9b, &(0x7f0000000000)={0x0, 0x0, [0x10001, 0xe5, 0x3, 0x2, 0x4, 0xca9, 0x3b, 0xf9d1]}) ioctl$KVM_RUN(r8, 0xae80, 0x0) openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file1\x00', 0x0, 0xd) 10.92644516s ago: executing program 1 (id=1514): openat$sndseq(0xffffffffffffff9c, &(0x7f0000000300), 0x480) prlimit64(0x0, 0xe, &(0x7f00000003c0)={0x8, 0xab}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f0000000040)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) r0 = syz_open_dev$MSR(&(0x7f0000000000), 0x0, 0x0) r1 = add_key$user(&(0x7f0000000000), &(0x7f0000000040)={'syz', 0x0}, &(0x7f00000000c0)="ff", 0x1, 0xffffffffffffffff) keyctl$KEYCTL_MOVE(0x1e, r1, 0xffffffffffffffff, 0x0, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$inet_tcp_int(r2, 0x6, 0x210000000013, &(0x7f00000000c0)=0x100000001, 0x4) bind$inet(r2, &(0x7f0000000080)={0x2, 0x4e21, @multicast1}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r2, 0x6, 0xd, &(0x7f0000000040)='htcp\x00', 0x5) connect$inet(r2, &(0x7f0000000180)={0x2, 0x4e21, @local}, 0x10) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r2, 0x6, 0x16, &(0x7f0000000000)=[@sack_perm, @window={0x3, 0x7}, @mss={0x2, 0xfff}, @window={0x3, 0x0, 0x401}, @window], 0x5) setsockopt$inet_tcp_TCP_REPAIR(r2, 0x6, 0x13, &(0x7f00000001c0), 0x4) sendto$inet(r2, &(0x7f0000000340)='\x00', 0x1, 0x0, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000000), 0xffffffffffffff94, 0xb, 0x0, 0x0) recvfrom$inet(r2, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0xc9100120, 0x0, 0xfffffffffffffd25) close(0x3) r3 = socket$netlink(0x10, 0x3, 0x15) ioctl$sock_SIOCSIFBR(r3, 0x8941, &(0x7f00000005c0)=@get={0x1, &(0x7f00000018c0)=""/4096, 0x3d}) openat$ttyS3(0xffffffffffffff9c, 0x0, 0x0, 0x0) r4 = syz_open_procfs(0x0, &(0x7f00000003c0)='net/mcfilter6\x00') preadv(r4, &(0x7f0000002740)=[{&(0x7f0000000600)=""/4096, 0x1000}], 0x1, 0x6, 0x6) 10.533257472s ago: executing program 3 (id=1515): socket$nl_route(0x10, 0x3, 0x0) socket$inet(0x10, 0x3, 0xc) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000180)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x24000815}, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) ioctl$DRM_IOCTL_MODE_GETRESOURCES(0xffffffffffffffff, 0xc04064a0, &(0x7f00000001c0)={0x0, &(0x7f0000000040), 0x0, 0x0}) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000380)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e23}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) sched_setaffinity(r0, 0x8, &(0x7f0000000240)=0x2) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = socket$inet_udp(0x2, 0x2, 0x0) getsockopt$IP_VS_SO_GET_TIMEOUT(r3, 0x0, 0xf, 0x0, &(0x7f0000000640)) socket$inet6_tcp(0xa, 0x1, 0x0) r4 = socket$qrtr(0x2a, 0x2, 0x0) sendmsg$NL80211_CMD_JOIN_MESH(0xffffffffffffffff, &(0x7f00000003c0)={0x0, 0x0, &(0x7f0000000380)={&(0x7f0000000300)=ANY=[@ANYBLOB="3be20b00", @ANYBLOB="00082dbd7000fcdf12ec0300caea10d6109858fcf7707600000004005a80", @ANYRESDEC, @ANYRESDEC=r4], 0x24}}, 0x4000) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="180000000004000000000000000000008500000050000000850000005000000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x78) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000080)='sched_switch\x00', r5}, 0x18) r6 = socket(0x10, 0x3, 0x0) sendmsg$nl_route(r6, &(0x7f00000000c0)={0x0, 0x0, &(0x7f00000006c0)={&(0x7f00000004c0)=ANY=[@ANYBLOB="440000001000010400"/20, @ANYRES32=0x0, @ANYBLOB="0000000000a10000240012800b0001006272696467650000140002800800040000000000050017"], 0x44}}, 0x0) 9.594988273s ago: executing program 4 (id=1516): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00000095"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) r1 = getpid() sched_setscheduler(r1, 0x2, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = inotify_init() inotify_rm_watch(r4, 0x0) 9.494799949s ago: executing program 1 (id=1517): syz_usbip_server_init(0x5) 9.412528627s ago: executing program 3 (id=1518): socket$nl_route(0x10, 0x3, 0x0) socket$inet(0x10, 0x3, 0xc) sendmsg$nl_route_sched(0xffffffffffffffff, &(0x7f0000000180)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x24000815}, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x6) ioctl$DRM_IOCTL_MODE_GETRESOURCES(0xffffffffffffffff, 0xc04064a0, &(0x7f00000001c0)={0x0, &(0x7f0000000040), 0x0, 0x0}) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000380)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e23}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) sched_setaffinity(r0, 0x8, &(0x7f0000000240)=0x2) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = socket$inet_udp(0x2, 0x2, 0x0) getsockopt$IP_VS_SO_GET_TIMEOUT(r3, 0x0, 0xf, 0x0, &(0x7f0000000640)) socket$inet6_tcp(0xa, 0x1, 0x0) r4 = socket$qrtr(0x2a, 0x2, 0x0) sendmsg$NL80211_CMD_JOIN_MESH(0xffffffffffffffff, &(0x7f00000003c0)={0x0, 0x0, &(0x7f0000000380)={&(0x7f0000000300)=ANY=[@ANYBLOB="3be20b00", @ANYBLOB="00082dbd7000fcdf12ec0300caea10d6109858fcf7707600000004005a80", @ANYRESDEC, @ANYRESDEC=r4], 0x24}}, 0x4000) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x5, &(0x7f00000002c0)=ANY=[@ANYBLOB="180000000004000000000000000000008500000050000000850000005000000095"], &(0x7f0000000040)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x78) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000080)='sched_switch\x00', r5}, 0x18) r6 = socket(0x10, 0x3, 0x0) sendmsg$nl_route(r6, &(0x7f00000000c0)={0x0, 0x0, &(0x7f00000006c0)={&(0x7f00000004c0)=ANY=[@ANYBLOB="440000001000010400"/20, @ANYRES32=0x0, @ANYBLOB="00000000a1ffffff240012800b0001006272696467650000140002800800040000000000050017"], 0x44}}, 0x0) 8.654490477s ago: executing program 5 (id=1519): ioperm(0x0, 0x401, 0xfffffffffffffffc) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x40, 0x7ffc1ffb}]}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) socketpair$tipc(0x1e, 0x2, 0x0, 0x0) sendmmsg$inet(0xffffffffffffffff, &(0x7f0000001540)=[{{0x0, 0xfffffffffffffda1, 0x0}}], 0x40001b6, 0x0) syz_usbip_server_init(0x5) 8.414324511s ago: executing program 3 (id=1520): socket$nl_generic(0x10, 0x3, 0x10) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00'}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x85}, 0x0) r0 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000080)='/proc/vmallocinfo\x00', 0x0, 0x0) fsconfig$FSCONFIG_SET_BINARY(r0, 0x2, 0x0, 0x0, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e20}, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) r5 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r5, &(0x7f0000000100)={0x3, 0x0, &(0x7f0000000080)={&(0x7f0000000500)={0x2, 0x3, 0x0, 0x2, 0x1a, 0x0, 0x0, 0x0, [@sadb_key={0x2, 0x8, 0x8, 0x0, 'f'}, @sadb_x_sec_ctx={0xf, 0x18, 0x2, 0x11, 0x6c, "e45a6927de470f48b98cb616f766e2bf25e109700bc58c625ea2192f4a606f8d2e5f932dd03a69c02606a807f0c560aecc8385aa4a7111039c0d1b72484029784b68874abecb18c08e421a5eea0726a6e1c11f1f0bc87c3cadc39039b4f8f1c18ca87cd2c06e6175f85b5b9b"}, @sadb_sa={0x2, 0x1, 0x0, 0x0, 0x0, 0x0, 0xfd}, @sadb_address={0x5, 0x5, 0x0, 0x0, 0x0, @in6={0xa, 0x0, 0x0, @local}}]}, 0xd0}, 0x1, 0x7}, 0x0) r6 = syz_open_dev$admmidi(&(0x7f0000000280), 0x2, 0x0) ioctl$SNDRV_RAWMIDI_IOCTL_STATUS64(r6, 0xc0385720, &(0x7f00000001c0)={0x1}) lseek(r4, 0x81, 0x0) mkdir(&(0x7f00000003c0)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000200)='./file0\x00', &(0x7f00000004c0)='cgroup2\x00', 0x0, 0x0) io_uring_register$IORING_REGISTER_BUFFERS(0xffffffffffffffff, 0xf0, 0x0, 0x0) chroot(&(0x7f0000000000)='./file0/../file0\x00') mount$bind(&(0x7f00000002c0)='.\x00', &(0x7f0000000200)='./file0\x00', 0x0, 0x101091, 0x0) r7 = socket$inet6(0xa, 0x80001, 0x0) setsockopt$inet6_MCAST_JOIN_GROUP(r7, 0x29, 0x2a, &(0x7f0000fca000)={0x100000001, {{0xa, 0x0, 0x0, @mcast1}}}, 0x88) syz_usb_connect(0x3, 0x99, &(0x7f00000009c0)={{0x12, 0x1, 0x310, 0x8a, 0x7d, 0x53, 0x8, 0xa5c, 0x2033, 0x73e4, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x87, 0x1, 0x5, 0xaa, 0x20, 0xfa, [{{0x9, 0x4, 0xee, 0x0, 0x1, 0x58, 0xfa, 0x42, 0x5, [], [{{0x9, 0x5, 0xe, 0x1, 0x200, 0x0, 0x1, 0x1, [@generic={0x6c, 0x8, "41e0f1a32183c629d51fd060ca7d36639d76ec09c57056cd91a71c4e078e5d34d4a5f012730bf2d3b43b045915368f85deebf713d3ceadfec132553cee5253f1401a1ceae66046eca95764ddfa346cb43824097dac838f3b0b946f7e6b7cc512e3067c4a92e521385bb1"}]}}]}}]}}]}}, 0x0) setsockopt$inet6_group_source_req(r7, 0x29, 0x2c, &(0x7f00000005c0)={0x1, {{0xa, 0x0, 0x0, @mcast1}}, {{0xa, 0x0, 0x0, @empty}}}, 0x108) 7.376837351s ago: executing program 1 (id=1521): socket$nl_generic(0x10, 0x3, 0x10) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00'}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x85}, 0x0) r0 = openat$procfs(0xffffffffffffff9c, &(0x7f0000000080)='/proc/vmallocinfo\x00', 0x0, 0x0) fsconfig$FSCONFIG_SET_BINARY(r0, 0x2, 0x0, 0x0, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e20}, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = openat(0xffffffffffffff9c, &(0x7f0000000040)='.\x00', 0x0, 0x0) r5 = socket$key(0xf, 0x3, 0x2) sendmsg$key(r5, &(0x7f0000000100)={0x3, 0x0, &(0x7f0000000080)={&(0x7f0000000500)={0x2, 0x3, 0x0, 0x2, 0x1a, 0x0, 0x0, 0x0, [@sadb_key={0x2, 0x8, 0x8, 0x0, 'f'}, @sadb_x_sec_ctx={0xf, 0x18, 0x2, 0x11, 0x6c, "e45a6927de470f48b98cb616f766e2bf25e109700bc58c625ea2192f4a606f8d2e5f932dd03a69c02606a807f0c560aecc8385aa4a7111039c0d1b72484029784b68874abecb18c08e421a5eea0726a6e1c11f1f0bc87c3cadc39039b4f8f1c18ca87cd2c06e6175f85b5b9b"}, @sadb_sa={0x2, 0x1, 0x0, 0x0, 0x0, 0x0, 0xfd}, @sadb_address={0x5, 0x5, 0x0, 0x0, 0x0, @in6={0xa, 0x0, 0x0, @local}}]}, 0xd0}, 0x1, 0x7}, 0x0) r6 = syz_open_dev$admmidi(&(0x7f0000000280), 0x2, 0x0) ioctl$SNDRV_RAWMIDI_IOCTL_STATUS64(r6, 0xc0385720, &(0x7f00000001c0)={0x1}) lseek(r4, 0x81, 0x0) mkdir(&(0x7f00000003c0)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000200)='./file0\x00', &(0x7f00000004c0)='cgroup2\x00', 0x0, 0x0) io_uring_register$IORING_REGISTER_BUFFERS(0xffffffffffffffff, 0xf0, 0x0, 0x0) chroot(&(0x7f0000000000)='./file0/../file0\x00') mount$bind(&(0x7f00000002c0)='.\x00', &(0x7f0000000200)='./file0\x00', 0x0, 0x101091, 0x0) r7 = socket$inet6(0xa, 0x80001, 0x0) setsockopt$inet6_MCAST_JOIN_GROUP(r7, 0x29, 0x2a, &(0x7f0000fca000)={0x100000001, {{0xa, 0x0, 0x0, @mcast1}}}, 0x88) syz_usb_connect(0x3, 0x99, &(0x7f00000009c0)={{0x12, 0x1, 0x310, 0x8a, 0x7d, 0x53, 0x8, 0xa5c, 0x2033, 0x73e4, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x87, 0x1, 0x5, 0xaa, 0x20, 0xfa, [{{0x9, 0x4, 0xee, 0x0, 0x1, 0x58, 0xfa, 0x42, 0x5, [], [{{0x9, 0x5, 0xe, 0x1, 0x200, 0x0, 0x1, 0x1, [@generic={0x6c, 0x8, "41e0f1a32183c629d51fd060ca7d36639d76ec09c57056cd91a71c4e078e5d34d4a5f012730bf2d3b43b045915368f85deebf713d3ceadfec132553cee5253f1401a1ceae66046eca95764ddfa346cb43824097dac838f3b0b946f7e6b7cc512e3067c4a92e521385bb1"}]}}]}}]}}]}}, 0x0) setsockopt$inet6_MCAST_MSFILTER(r7, 0x29, 0x30, &(0x7f00000007c0)=ANY=[@ANYBLOB="01000000000000000a0000000000ff00ff010000000000000000000000000001000001000000000000000000ffff00000000000000bd0000000000000000000000e4ec01000000004000000000fc00000000000000000000000000013da51fd47aa2e2f700000000000000000000000000000000000000000000000000000000000000060000000000000000050000000a004e200e8a34c38f36f0c7eb2700d609bcf41076d88144448ebe7994dd1b33d7c8787734cc315672f62261ceeede940774fd94d2767288cfb3a20882449d601ff878eedd3d57c9eb3a723b62102bd534c8a304a975d752e82cc8d5f969771c94a1d69cfd8694e29b9468fca5df65ece31ed7c209325604001fcd06adc3ac391f60a3523d6d0b4a8a"], 0x310) 7.164341513s ago: executing program 5 (id=1523): mkdir(&(0x7f0000002200)='./file0\x00', 0x0) mount(0x0, &(0x7f0000000980)='./file0\x00', &(0x7f0000000000)='proc\x00', 0x0, 0x0) chroot(&(0x7f0000000180)='./file0\x00') r0 = socket$inet6_udplite(0xa, 0x2, 0x88) ioctl$sock_ipv4_tunnel_SIOCADDTUNNEL(0xffffffffffffffff, 0x89f1, &(0x7f0000000040)={'gretap0\x00', &(0x7f00000000c0)={'tunl0\x00', 0x0, 0x80, 0x700, 0x9, 0x4, {{0x1e, 0x4, 0x0, 0x38, 0x78, 0x64, 0x0, 0x49, 0x2f, 0x0, @loopback, @empty, {[@noop, @timestamp_prespec={0x44, 0x1c, 0xbe, 0x3, 0x7, [{@initdev={0xac, 0x1e, 0x0, 0x0}, 0x5}, {@empty, 0x67e}, {@dev={0xac, 0x14, 0x14, 0x13}, 0xa}]}, @lsrr={0x83, 0xf, 0x4a, [@remote, @broadcast, @broadcast]}, @ssrr={0x89, 0x7, 0xaa, [@empty]}, @timestamp={0x44, 0x1c, 0xe0, 0x0, 0x9, [0x4, 0x7, 0x5, 0x101, 0xfffffff8, 0xc2]}, @generic={0x82, 0x7, "9a24f5075c"}, @generic={0x44, 0xd, "b5095f63495a8e4cf67b2b"}]}}}}}) ioctl$sock_ipv6_tunnel_SIOCGETTUNNEL(r0, 0x89f0, &(0x7f0000000280)={'ip6gre0\x00', &(0x7f00000001c0)={'syztnl1\x00', r1, 0x2f, 0x6, 0x8, 0x1ff, 0x4, @remote, @remote, 0x700, 0x7800, 0x9, 0x800}}) r2 = socket$nl_route(0x10, 0x3, 0x0) ioctl$ifreq_SIOCGIFINDEX_wireguard(r2, 0x8933, &(0x7f0000000240)={'wg0\x00', 0x0}) r4 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r4, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000440)=ANY=[@ANYBLOB="2c0000001800835e09000000000000000210000200fe020000008008000400", @ANYRES32=r3, @ANYBLOB="08000700ffffffff"], 0x2c}, 0x1, 0xffffff7f, 0x0, 0x20000800}, 0x4040000) openat$sysfs(0xffffffffffffff9c, &(0x7f0000000180)='/sys/kernel/address_bits', 0x20040, 0x84) mkdir(&(0x7f0000002200)='./file0\x00', 0x0) (async) mount(0x0, &(0x7f0000000980)='./file0\x00', &(0x7f0000000000)='proc\x00', 0x0, 0x0) (async) chroot(&(0x7f0000000180)='./file0\x00') (async) socket$inet6_udplite(0xa, 0x2, 0x88) (async) ioctl$sock_ipv4_tunnel_SIOCADDTUNNEL(0xffffffffffffffff, 0x89f1, &(0x7f0000000040)={'gretap0\x00', &(0x7f00000000c0)={'tunl0\x00', 0x0, 0x80, 0x700, 0x9, 0x4, {{0x1e, 0x4, 0x0, 0x38, 0x78, 0x64, 0x0, 0x49, 0x2f, 0x0, @loopback, @empty, {[@noop, @timestamp_prespec={0x44, 0x1c, 0xbe, 0x3, 0x7, [{@initdev={0xac, 0x1e, 0x0, 0x0}, 0x5}, {@empty, 0x67e}, {@dev={0xac, 0x14, 0x14, 0x13}, 0xa}]}, @lsrr={0x83, 0xf, 0x4a, [@remote, @broadcast, @broadcast]}, @ssrr={0x89, 0x7, 0xaa, [@empty]}, @timestamp={0x44, 0x1c, 0xe0, 0x0, 0x9, [0x4, 0x7, 0x5, 0x101, 0xfffffff8, 0xc2]}, @generic={0x82, 0x7, "9a24f5075c"}, @generic={0x44, 0xd, "b5095f63495a8e4cf67b2b"}]}}}}}) (async) ioctl$sock_ipv6_tunnel_SIOCGETTUNNEL(r0, 0x89f0, &(0x7f0000000280)={'ip6gre0\x00', &(0x7f00000001c0)={'syztnl1\x00', r1, 0x2f, 0x6, 0x8, 0x1ff, 0x4, @remote, @remote, 0x700, 0x7800, 0x9, 0x800}}) (async) socket$nl_route(0x10, 0x3, 0x0) (async) ioctl$ifreq_SIOCGIFINDEX_wireguard(r2, 0x8933, &(0x7f0000000240)={'wg0\x00'}) (async) socket$nl_route(0x10, 0x3, 0x0) (async) sendmsg$nl_route(r4, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000440)=ANY=[@ANYBLOB="2c0000001800835e09000000000000000210000200fe020000008008000400", @ANYRES32=r3, @ANYBLOB="08000700ffffffff"], 0x2c}, 0x1, 0xffffff7f, 0x0, 0x20000800}, 0x4040000) (async) openat$sysfs(0xffffffffffffff9c, &(0x7f0000000180)='/sys/kernel/address_bits', 0x20040, 0x84) (async) 6.262537524s ago: executing program 5 (id=1524): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x200, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = socket$inet6_tcp(0xa, 0x1, 0x0) bind$inet6(r2, &(0x7f0000000040)={0xa, 0x4e22, 0x0, @empty}, 0x1c) listen(r2, 0x0) r3 = socket$inet6_tcp(0xa, 0x1, 0x0) r4 = pidfd_getfd(0xffffffffffffffff, 0xffffffffffffffff, 0x0) connect$inet6(r3, &(0x7f0000000080)={0xa, 0x4e22, 0x4, @loopback, 0x7}, 0x1c) syz_emit_ethernet(0x52, &(0x7f0000000200)={@local, @broadcast, @val={@val={0x88a8, 0x3, 0x1}, {0x8100, 0x4}}, {@ipv6={0x86dd, @tcp={0x0, 0x6, '\f\n5', 0x14, 0x6, 0x0, @local, @local, {[], {{0x0, 0x4e22, 0x41424344, 0x41424344, 0x0, 0x0, 0x5, 0x2, 0x0, 0x0, 0x4}}}}}}}, 0x0) r5 = openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000001c0)='blkio.bfq.io_wait_time_recursive\x00', 0x275a, 0x0) write$binfmt_script(r5, &(0x7f0000000000), 0x208e24b) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x28011, r5, 0x0) preadv(r5, &(0x7f00000015c0)=[{&(0x7f0000000080)=""/124, 0xffffff23}], 0x1, 0x0, 0x0) r6 = ioctl$KVM_CREATE_VCPU(r1, 0xae41, 0x0) r7 = syz_genetlink_get_family_id$devlink(&(0x7f0000000280), r4) r8 = ioctl$TUNGETDEVNETNS(r5, 0x54e3, 0x0) ioctl$TIOCGPGRP(r5, 0x540f, &(0x7f00000002c0)=0x0) r10 = getpid() sched_setscheduler(r10, 0x2, &(0x7f0000000200)=0x7) eventfd2(0x3, 0x1) sendmsg$DEVLINK_CMD_RELOAD(r5, &(0x7f0000000400)={&(0x7f0000000180)={0x10, 0x0, 0x0, 0x8}, 0xc, &(0x7f00000003c0)={&(0x7f0000000300)={0xa4, r7, 0x1, 0x70bd2c, 0x25dfdbff, {}, [{@pci={{0x8}, {0x11}}, @DEVLINK_ATTR_NETNS_FD={0x8, 0x8a, r5}}, {@pci={{0x8}, {0x11}}, @DEVLINK_ATTR_NETNS_FD={0x8, 0x8a, r8}}, {@pci={{0x8}, {0x11}}, @DEVLINK_ATTR_NETNS_PID={0x8, 0x8b, r9}}, {@pci={{0x8}, {0x11}}, @DEVLINK_ATTR_NETNS_PID={0x8, 0x8b, r10}}]}, 0xa4}, 0x1, 0x0, 0x0, 0x20000000}, 0x10) socket$inet6_sctp(0xa, 0x1, 0x84) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r6, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000140)=[@text64={0x40, 0x0}], 0x1, 0x64, 0x0, 0x0) ioctl$KVM_GET_NESTED_STATE(r6, 0xc080aebe, &(0x7f000000a100)={{0x0, 0x0, 0x80}}) 5.978035s ago: executing program 4 (id=1526): r0 = openat$rfkill(0xffffffffffffff9c, &(0x7f0000000040), 0x0, 0x0) r1 = dup(r0) r2 = syz_open_procfs(0x0, &(0x7f00000000c0)='fd/3\x00') mount$9p_fd(0x0, &(0x7f00000001c0)='.\x00', &(0x7f0000000180), 0x0, &(0x7f0000000200)={'trans=fd,', {'rfdno', 0x3d, r1}, 0x2c, {'wfdno', 0x3d, r2}}) (async) openat$drirender128(0xffffffffffffff9c, 0x0, 0x2000, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) (async) close_range(0xffffffffffffffff, 0xffffffffffffffff, 0x2) (async) syz_init_net_socket$rose(0xb, 0x5, 0x0) (async) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) (async) socket$inet6(0xa, 0x200000000003, 0x87) (async) syz_emit_ethernet(0x36, &(0x7f0000000080)={@broadcast, @random="00005403cb00", @void, {@ipv6={0x86dd, @generic={0x0, 0x6, "03136c", 0x0, 0x87, 0x0, @private2, @mcast2}}}}, 0x0) io_setup(0x3, &(0x7f00000003c0)=0x0) io_submit(r3, 0x1, &(0x7f00000006c0)=[&(0x7f00000000c0)={0x0, 0x0, 0x0, 0x5, 0x0, r2, 0x0, 0x0, 0x0, 0x0, 0x2}]) (async) openat$nci(0xffffffffffffff9c, &(0x7f0000000080), 0x5400, 0x0) 5.878392282s ago: executing program 4 (id=1527): openat$sndseq(0xffffffffffffff9c, &(0x7f0000000300), 0x480) prlimit64(0x0, 0xe, &(0x7f00000003c0)={0x8, 0xab}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f0000000040)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) r0 = syz_open_dev$MSR(&(0x7f0000000000), 0x0, 0x0) r1 = add_key$user(&(0x7f0000000000), &(0x7f0000000040)={'syz', 0x0}, &(0x7f00000000c0)="ff", 0x1, 0xffffffffffffffff) keyctl$KEYCTL_MOVE(0x1e, r1, 0xffffffffffffffff, 0x0, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$inet_tcp_int(r2, 0x6, 0x210000000013, &(0x7f00000000c0)=0x100000001, 0x4) bind$inet(r2, &(0x7f0000000080)={0x2, 0x4e21, @multicast1}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r2, 0x6, 0xd, &(0x7f0000000040)='htcp\x00', 0x5) connect$inet(r2, &(0x7f0000000180)={0x2, 0x4e21, @local}, 0x10) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r2, 0x6, 0x16, &(0x7f0000000000)=[@mss, @sack_perm, @window={0x3, 0x7}, @mss={0x2, 0xfff}, @window={0x3, 0x0, 0x401}, @window], 0x20000000000000e4) setsockopt$inet_tcp_TCP_REPAIR(r2, 0x6, 0x13, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000340)='\x00', 0x1, 0x0, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000000), 0xffffffffffffff94, 0xb, 0x0, 0x0) recvfrom$inet(r2, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0xc9100120, 0x0, 0xfffffffffffffd25) close(0x3) r3 = socket$netlink(0x10, 0x3, 0x15) ioctl$sock_SIOCSIFBR(r3, 0x8941, &(0x7f00000005c0)=@get={0x1, &(0x7f00000018c0)=""/4096, 0x3d}) openat$ttyS3(0xffffffffffffff9c, 0x0, 0x0, 0x0) r4 = syz_open_procfs(0x0, &(0x7f00000003c0)='net/mcfilter6\x00') preadv(r4, &(0x7f0000002740)=[{&(0x7f0000000600)=""/4096, 0x1000}], 0x1, 0x6, 0x6) 5.409350929s ago: executing program 4 (id=1528): r0 = socket$nl_xfrm(0x10, 0x3, 0x6) sendmsg$nl_xfrm(r0, &(0x7f0000000180)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f00000002c0)=@updpolicy={0xb8, 0x19, 0x1, 0x0, 0xffffffff, {{@in=@multicast2, @in6=@local, 0x4e21, 0x0, 0x3, 0x0, 0xa, 0x0, 0xa0}, {0x0, 0xe9, 0x0, 0x0, 0x200}, {0x0, 0x0, 0x0, 0x1000}, 0x0, 0x200}}, 0xb8}}, 0x0) socket$inet6(0xa, 0x400000000001, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, 0x0, 0x0) ioctl$TUNSETIFF(0xffffffffffffffff, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x7101}) socket$unix(0x1, 0x1, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) syz_usb_connect(0x0, 0x24, &(0x7f0000000040)=ANY=[@ANYBLOB="12010000e5cf01406e0510401c20000000010902120001000000000904"], 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) r4 = socket$inet_udplite(0x2, 0x2, 0x88) ioctl$sock_ipv4_tunnel_SIOCCHGTUNNEL(r4, 0x89f3, &(0x7f0000000280)={'tunl0\x00', &(0x7f0000000080)={'tunl0\x00', 0x0, 0x10, 0x8, 0x9, 0xf8f8, {{0x15, 0x4, 0x1, 0x7, 0x54, 0x66, 0x0, 0xe8, 0x29, 0x0, @loopback, @private=0xa010100, {[@end, @timestamp_addr={0x44, 0x3c, 0x75, 0x1, 0xb, [{@remote, 0xff}, {@loopback, 0x7ff}, {@multicast2, 0xaf2}, {@local, 0x81}, {@local, 0x3}, {@multicast1, 0x401}, {@empty, 0x55}]}]}}}}}) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r5 = syz_io_uring_setup(0x7b, &(0x7f0000000540)={0x0, 0x3bca, 0x10100, 0x0, 0x313}, &(0x7f00000005c0)=0x0, &(0x7f0000000100)=0x0) socketpair$tipc(0x1e, 0x5, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) syz_io_uring_submit(r6, r7, &(0x7f0000000600)=@IORING_OP_RECVMSG={0xa, 0x40, 0x0, r9, 0x0, &(0x7f00000001c0)={0x0, 0x0, &(0x7f00000019c0)=[{&(0x7f00000002c0)=""/183, 0xb7}], 0x1}, 0x0, 0x40000103}) io_uring_enter(r5, 0x46f3, 0x0, 0x0, 0x0, 0x0) write(r8, &(0x7f0000000200)='~', 0x1) 5.319338112s ago: executing program 5 (id=1529): openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x0, 0x0) r0 = socket$can_j1939(0x1d, 0x2, 0x7) ioctl$ifreq_SIOCGIFINDEX_vcan(r0, 0x8933, 0x0) bind$can_j1939(r0, &(0x7f0000001080)={0x1d, 0x0, 0x2, {0x1, 0xf0, 0x3}, 0x1}, 0x18) r1 = socket$inet6_tcp(0xa, 0x1, 0x0) listen(r1, 0x0) bpf$TOKEN_CREATE(0x24, &(0x7f00000001c0), 0x8) r2 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000540)={0x10, 0x4, 0x0, &(0x7f00000000c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x3, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) open_tree(0xffffffffffffff9c, 0x0, 0x89901) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000240)=0x7) r3 = getpid() sched_setscheduler(r3, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r4, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r5, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r4, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r6 = bpf$MAP_CREATE(0x0, &(0x7f00000023c0)=@base={0x12, 0x4, 0x8, 0xb, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$BPF_PROG_DETACH(0x8, &(0x7f0000000140)=ANY=[@ANYRES32=r6, @ANYRES32=r2, @ANYBLOB='\a'], 0x10) bpf$MAP_UPDATE_ELEM(0x2, &(0x7f0000000500)={r6, &(0x7f0000000240), &(0x7f00000004c0)=@tcp6=r1}, 0x20) sendmmsg$inet6(r1, &(0x7f0000000480)=[{{0x0, 0x0, &(0x7f0000000440)=[{&(0x7f0000000200)="bd", 0x1}], 0x14}}], 0x1, 0x41) syz_usb_connect(0x3, 0x1b, &(0x7f0000000000)={{0x12, 0x1, 0x0, 0x10, 0x81, 0x72, 0x20, 0x2040, 0x8268, 0x76d1, 0x1, 0x2, 0x3, 0x1, [{{0x9, 0x2, 0x9, 0x0, 0x5, 0xfb, 0xb0}}]}}, 0x0) 5.299881018s ago: executing program 3 (id=1530): r0 = syz_open_dev$loop(&(0x7f0000000040), 0x0, 0xa4201) r1 = syz_init_net_socket$bt_l2cap(0x1f, 0x3, 0x0) getsockopt$bt_BT_DEFER_SETUP(r1, 0x112, 0xf, &(0x7f0000000040), &(0x7f0000000080)=0x4) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000080)='memory.events.local\x00', 0x275a, 0x0) r2 = syz_open_dev$loop(&(0x7f0000000000), 0x4, 0x26040) ioctl$LOOP_CONFIGURE(r0, 0x4c0a, &(0x7f00000002c0)={r2, 0x0, {0x2a00, 0x80010000, 0x0, 0x55, 0x0, 0x0, 0x6, 0x17, 0x8, "15e9a2ab7af4fadf0d9e8293c3af1e299de2b7f90a0900e6083e9e930000061fd90000e2ffffffffff0b000000000000000000000200", "2809e8dbe108598b5b6c0dd54afac11d09000000000000008dd4992861ac1000000093c9fd5700", "90be601400000000000029f07a9ef9b486b0a4711de1b81e8c7b00", [0x10000000000, 0x8]}}) ioctl$LOOP_SET_CAPACITY(r0, 0x4c07) 5.156370307s ago: executing program 3 (id=1532): ioperm(0x0, 0x401, 0xfffffffffffffffc) prctl$PR_SET_SECCOMP(0x16, 0x2, &(0x7f0000000000)={0x1, &(0x7f00000000c0)=[{0x200000000006, 0x0, 0x40, 0x7ffc1ffb}]}) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000080)=0x8) r0 = getpid() sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) socketpair$tipc(0x1e, 0x2, 0x0, 0x0) sendmmsg$inet(0xffffffffffffffff, &(0x7f0000001540)=[{{0x0, 0xfffffffffffffda1, 0x0}}], 0x40001b6, 0x0) syz_usbip_server_init(0x5) r3 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000480)={0x11, 0x3, &(0x7f0000000780)=ANY=[@ANYBLOB="1800000000000000000000000040000095"], &(0x7f0000000340)='GPL\x00', 0x1, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r3, 0x406, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x0, &(0x7f00000000c0)="a0", 0x0}, 0x31) r4 = syz_usb_connect$hid(0x5, 0x3f, &(0x7f00000000c0)=ANY=[@ANYBLOB="12011801000000405804155000000000000109022d00010000000909040004010300000009210400040122070009058103"], 0x0) r5 = syz_io_uring_setup(0x10e, &(0x7f0000000140)={0x0, 0xd6ab, 0x100, 0x1}, &(0x7f0000000240)=0x0, &(0x7f0000000280)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r6, 0x4, &(0x7f0000000080)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r6, r7, &(0x7f00000001c0)=@IORING_OP_POLL_REMOVE={0x7, 0x40, 0x0, 0x0, 0x0, 0x1}) io_uring_enter(r5, 0x7ffe, 0x184c, 0x2, 0x0, 0x0) r8 = openat$tun(0xffffffffffffff9c, &(0x7f0000000000), 0x48241, 0x0) ioctl$TUNSETIFF(r8, 0x400454ca, &(0x7f00000000c0)={'syzkaller1\x00', 0x6bf1c2d5adba8c32}) syz_usb_control_io$hid(r4, 0x0, 0x0) socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$ethtool(&(0x7f0000000000), 0xffffffffffffffff) sendmsg$inet(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000140)=[{0x0}], 0x1}, 0x48d0) r9 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$nl_generic(r9, &(0x7f0000000180)={0x0, 0x0, &(0x7f0000000300)={&(0x7f0000000080)=ANY=[@ANYBLOB="1c00000015000100000000000000000005000000080001"], 0x1c}, 0x1, 0x0, 0x0, 0x4000810}, 0x0) 5.08484639s ago: executing program 0 (id=1533): r0 = socket(0xa, 0x2, 0x0) getsockopt$sock_cred(r0, 0x1, 0x11, &(0x7f0000caaffb)={0x0, 0x0, 0x0}, &(0x7f0000cab000)=0xa) r3 = open(&(0x7f00009e1000)='./file0\x00', 0x60840, 0x0) r4 = openat$cachefiles(0xffffffffffffff9c, &(0x7f0000000000), 0x4401, 0x0) getpeername$llc(r4, &(0x7f0000000080)={0x1a, 0x0, 0x0, 0x0, 0x0, 0x0, @dev}, &(0x7f0000000140)=0x10) fcntl$setlease(0xffffffffffffffff, 0x400, 0x2) fcntl$setown(r3, 0x8, 0x0) fcntl$setlease(r3, 0x400, 0x2) prlimit64(0x0, 0xe, &(0x7f00000007c0)={0x8, 0x88}, 0x0) sched_setscheduler(r1, 0x1, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000000c0)=0xfffffffffffffffe) socket(0x2, 0x80805, 0x0) openat$vim2m(0xffffffffffffff9c, &(0x7f0000000100), 0x2, 0x0) sendmsg$IPSET_CMD_CREATE(0xffffffffffffffff, 0x0, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r5 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r5, &(0x7f0000019680)=""/102392, 0x18ff8) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000000)={0xffffffffffffffff, 0xffffffffffffffff}) setsockopt$SO_ATTACH_FILTER(r6, 0x1, 0x1a, 0x0, 0x0) openat$sequencer(0xffffffffffffff9c, 0x0, 0x0, 0x0) syz_open_dev$sndmidi(&(0x7f00000004c0), 0x2, 0x141102) setfsgid(r2) setresgid(0x0, 0x0, r2) syz_open_procfs(0x0, &(0x7f0000000740)='net/netstat\x00') socket$netlink(0x10, 0x3, 0x0) r7 = socket$nl_route(0x10, 0x3, 0x0) ioctl$sock_SIOCGIFINDEX(r7, 0x8933, &(0x7f00000000c0)={'bridge0\x00'}) 4.161312984s ago: executing program 1 (id=1534): r0 = socket$key(0xf, 0x3, 0x2) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000400)=0x6) r1 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) fsconfig$FSCONFIG_SET_PATH_EMPTY(0xffffffffffffffff, 0x4, &(0x7f0000000240)='\x00', 0x0, 0xffffffffffffffff) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) sched_setattr(0x0, &(0x7f0000000100)={0x38, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffe, 0x0, 0xffffffff}, 0x0) r4 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000400), 0x0, 0x0) ioctl$TIOCSETD(r4, 0x5423, &(0x7f0000000040)=0x14) ioctl$TIOCSETD(r4, 0x5423, &(0x7f0000000000)=0x5) ioctl$TIOCVHANGUP(r4, 0x5437, 0x0) r5 = socket$inet6(0xa, 0x80002, 0x0) connect$inet6(r5, &(0x7f0000000040)={0xa, 0x4e23, 0x0, @private0={0xfc, 0x0, '\x00', 0x1}, 0xfffffffc}, 0x1c) sendmmsg$inet6(r5, &(0x7f0000003cc0)=[{{0x0, 0x0, &(0x7f0000003980), 0x171}}], 0x400000000000172, 0x0) symlink(&(0x7f0000000580)='.\x02/file1\x00', &(0x7f00000002c0)='.\x02\x00') rmdir(0x0) sendmmsg$unix(0xffffffffffffffff, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r0, &(0x7f0000000440), 0x0, 0x2100, &(0x7f0000000480)={0x77359400}) r6 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$ifreq_SIOCGIFINDEX_batadv_hard(r6, 0x8933, &(0x7f0000000000)={'batadv_slave_1\x00', 0x0}) sendmsg$ETHTOOL_MSG_LINKMODES_GET(r6, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000580)={&(0x7f0000000300)=ANY=[@ANYBLOB="200000008b772df4468cab3d0cd905d3d3dcd06e52540f9e69c054ba85683bc0beba4e72c44cac34aec27572cc70872cabd7136fc147ce07fb3c9ae494e820d7df2499d7bb8379ee66621d85dea272a4f658275a8947382e19", @ANYRES16=0x0, @ANYBLOB="010328bd7000fedbdf251c0000000c00018008000100", @ANYRES32=r7, @ANYBLOB], 0x20}}, 0x10) sendmsg$key(r0, &(0x7f0000000180)={0x0, 0x0, 0x0}, 0x4007) socket$nl_route(0x10, 0x3, 0x0) 2.966368211s ago: executing program 0 (id=1535): syz_usb_connect(0x0, 0x24, &(0x7f0000000980)=ANY=[@ANYBLOB="12010000b1bd2f087d0403508c2f010203010902120001000000000904"], 0x0) (async) socket$inet6_udp(0xa, 0x2, 0x0) (async) r0 = socket$nl_netfilter(0x10, 0x3, 0xc) sendmsg$NFT_BATCH(r0, &(0x7f00000003c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000340)=ANY=[], 0x7c}, 0x1, 0x0, 0x0, 0x844}, 0x0) (async, rerun: 32) r1 = socket$nl_rdma(0x10, 0x3, 0x14) (rerun: 32) sendmsg$RDMA_NLDEV_CMD_SET(r1, &(0x7f0000000340)={0x0, 0x0, &(0x7f0000000240)={&(0x7f0000000140)=ANY=[@ANYBLOB], 0x18}}, 0x0) (async) sendmmsg$inet6(0xffffffffffffffff, 0x0, 0x0, 0x4000001) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0x8, 0x0) (async) r2 = bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000280)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb010018000000000000003c0000003c00000002000000000000000200000408000000000000000300000000000000000000000200000000000000000000000000000200"/78], 0x0, 0x56, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x28) unshare(0x60600) (async, rerun: 64) setreuid(0x0, 0x0) (rerun: 64) stat(&(0x7f0000000300)='./file0\x00', &(0x7f0000000a80)) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000040)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r3, 0x8937, &(0x7f0000000000)={'batadv_slave_1\x00', @random="0100002010ff"}) (async) accept(r1, 0x0, 0x0) (async, rerun: 64) sendmsg$netlink(r1, &(0x7f0000000bc0)={&(0x7f0000000200)=@proc={0x10, 0x0, 0x25dfdbfb}, 0xc, &(0x7f00000002c0)=[{&(0x7f00000004c0)=ANY=[], 0x63c}], 0x1, &(0x7f0000000740), 0x0, 0x2400c850}, 0x0) (async, rerun: 64) bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000440)=ANY=[@ANYRES32=0x1, @ANYBLOB='7\a\x00'/19, @ANYRES32=0x0, @ANYRES32=r2], 0x50) (async, rerun: 64) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) (async, rerun: 64) sched_setscheduler(0x0, 0x2, &(0x7f00000004c0)=0x2) (async, rerun: 32) sched_setaffinity(0x0, 0x8, &(0x7f00000000c0)=0xa) (rerun: 32) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) (async) r4 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r4, &(0x7f0000019680)=""/102392, 0x18ff8) (async, rerun: 64) keyctl$instantiate(0xc, 0x0, 0x0, 0x0, 0xfffffffffffffffc) (async, rerun: 64) keyctl$dh_compute(0x17, 0x0, 0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000080)={'poly1305-generic\x00'}}) (async, rerun: 32) r5 = syz_init_net_socket$llc(0x1a, 0x2, 0x0) (rerun: 32) getsockopt$llc_int(r5, 0x10c, 0x0, 0x0, 0x0) (async) getsockname$llc(r5, &(0x7f0000000000), &(0x7f0000000040)=0x10) (async, rerun: 64) prlimit64(0x0, 0x2, &(0x7f0000000080)={0x3ff, 0x5}, &(0x7f0000000100)) (async, rerun: 64) sendmsg$NFT_BATCH(0xffffffffffffffff, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000380)={&(0x7f00000008c0)=ANY=[@ANYBLOB], 0x294}, 0x1, 0x0, 0x0, 0x80}, 0x20050800) 2.888913933s ago: executing program 1 (id=1536): openat$sndseq(0xffffffffffffff9c, &(0x7f0000000300), 0x480) prlimit64(0x0, 0xe, &(0x7f00000003c0)={0x8, 0xab}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f0000000040)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) r0 = syz_open_dev$MSR(&(0x7f0000000000), 0x0, 0x0) r1 = add_key$user(&(0x7f0000000000), &(0x7f0000000040)={'syz', 0x0}, &(0x7f00000000c0), 0x0, 0xffffffffffffffff) keyctl$KEYCTL_MOVE(0x1e, r1, 0xffffffffffffffff, 0x0, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$inet_tcp_int(r2, 0x6, 0x210000000013, &(0x7f00000000c0)=0x100000001, 0x4) bind$inet(r2, &(0x7f0000000080)={0x2, 0x4e21, @multicast1}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r2, 0x6, 0xd, &(0x7f0000000040)='htcp\x00', 0x5) connect$inet(r2, &(0x7f0000000180)={0x2, 0x4e21, @local}, 0x10) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r2, 0x6, 0x16, &(0x7f0000000000)=[@mss, @sack_perm, @window={0x3, 0x7}, @mss={0x2, 0xfff}, @window={0x3, 0x0, 0x401}, @window], 0x20000000000000e4) setsockopt$inet_tcp_TCP_REPAIR(r2, 0x6, 0x13, &(0x7f00000001c0), 0x4) sendto$inet(r2, &(0x7f0000000340)='\x00', 0x1, 0x0, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000000), 0xffffffffffffff94, 0xb, 0x0, 0x0) recvfrom$inet(r2, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0xc9100120, 0x0, 0xfffffffffffffd25) r3 = socket$netlink(0x10, 0x3, 0x15) ioctl$sock_SIOCSIFBR(r3, 0x8941, &(0x7f00000005c0)=@get={0x1, &(0x7f00000018c0)=""/4096, 0x3d}) openat$ttyS3(0xffffffffffffff9c, 0x0, 0x0, 0x0) r4 = syz_open_procfs(0x0, &(0x7f00000003c0)='net/mcfilter6\x00') preadv(r4, &(0x7f0000002740)=[{&(0x7f0000000600)=""/4096, 0x1000}], 0x1, 0x6, 0x6) 2.8684634s ago: executing program 0 (id=1537): syz_genetlink_get_family_id$batadv(&(0x7f0000000040), 0xffffffffffffffff) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) socket$nl_xfrm(0x10, 0x3, 0x6) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x4, 0x0, &(0x7f0000000300)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, &(0x7f0000000200)=0x7) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbee2, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000340)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e21}, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) r4 = socket(0x10, 0x3, 0x0) sendmsg$nl_route(r4, &(0x7f0000000040)={0x0, 0x0, &(0x7f0000000080)={&(0x7f00000002c0)=ANY=[@ANYBLOB="240000006800019f00000000000000000a000000000000000800010001000000040004"], 0x24}, 0x1, 0x0, 0x0, 0x20000004}, 0x4000) r5 = syz_init_net_socket$bt_l2cap(0x1f, 0x5, 0x0) bind$bt_l2cap(r5, &(0x7f0000000000)={0x1f, 0x0, @fixed={'\xaa\xaa\xaa\xaa\xaa', 0x10}, 0x804}, 0xe) listen(r5, 0x3) syz_emit_vhci(&(0x7f0000000100)=ANY=[@ANYBLOB="043e130100c900"], 0x16) ioctl$sock_bt_bnep_BNEPGETCONNLIST(0xffffffffffffffff, 0x800442d2, 0x0) socket$can_bcm(0x1d, 0x2, 0x2) setsockopt$XDP_UMEM_REG(0xffffffffffffffff, 0x11b, 0x4, 0x0, 0x0) r6 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000013c0)={0x18, 0x3, &(0x7f0000000380)=ANY=[@ANYRES32=r2, @ANYRES64=r0, @ANYRES8=r3, @ANYRES8=r3], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0xfffffffd, @void, @value}, 0x94) r7 = bpf$MAP_CREATE(0x0, &(0x7f0000000140)=ANY=[@ANYBLOB="1e00000001fcffff01000000ffffffff08000000", @ANYRES32, @ANYBLOB="07b3ffff00"/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="030000000000000004000000010000000085afd4cb54d9dd1120ed"], 0x50) bpf$MAP_GET_NEXT_KEY(0x4, &(0x7f0000000280)={r7, &(0x7f00000001c0)="1ac45103e80c53575c815e56c6589fe515a90f868c7a0ba5bf9daf77ae4b8f5a97cbe7", &(0x7f0000000200)=""/17}, 0x20) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000000c0)={0x0, r6}, 0x18) bpf$MAP_CREATE(0x0, &(0x7f0000000240)=ANY=[@ANYBLOB="0100000005001000050000000500", @ANYBLOB], 0x50) bpf$MAP_UPDATE_BATCH(0x1a, 0x0, 0x0) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, 0x0, 0x0) 2.193650505s ago: executing program 5 (id=1538): openat$sndseq(0xffffffffffffff9c, &(0x7f0000000300), 0x480) prlimit64(0x0, 0xe, &(0x7f00000003c0)={0x8, 0xab}, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f0000000040)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x1, 0x0) r0 = syz_open_dev$MSR(&(0x7f0000000000), 0x0, 0x0) r1 = add_key$user(&(0x7f0000000000), &(0x7f0000000040)={'syz', 0x0}, &(0x7f00000000c0)="ff", 0x1, 0xffffffffffffffff) keyctl$KEYCTL_MOVE(0x1e, r1, 0xffffffffffffffff, 0x0, 0x0) read$msr(r0, &(0x7f0000019680)=""/102392, 0x18ff8) r2 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$inet_tcp_int(r2, 0x6, 0x210000000013, &(0x7f00000000c0)=0x100000001, 0x4) bind$inet(r2, &(0x7f0000000080)={0x2, 0x4e21, @multicast1}, 0x10) setsockopt$inet_tcp_TCP_CONGESTION(r2, 0x6, 0xd, &(0x7f0000000040)='htcp\x00', 0x5) connect$inet(r2, &(0x7f0000000180)={0x2, 0x4e21, @local}, 0x10) setsockopt$inet_tcp_TCP_REPAIR_OPTIONS(r2, 0x6, 0x16, &(0x7f0000000000)=[@mss, @sack_perm, @window={0x3, 0x7}, @mss={0x2, 0xfff}, @window={0x3, 0x0, 0x401}, @window], 0x20000000000000e4) setsockopt$inet_tcp_TCP_REPAIR(r2, 0x6, 0x13, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000340)='\x00', 0x1, 0x0, 0x0, 0x0) sendto$inet(r2, &(0x7f0000000000), 0xffffffffffffff94, 0xb, 0x0, 0x0) recvfrom$inet(r2, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0xc9100120, 0x0, 0xfffffffffffffd25) close(0x3) r3 = socket$netlink(0x10, 0x3, 0x15) ioctl$sock_SIOCSIFBR(r3, 0x8941, &(0x7f00000005c0)=@get={0x1, &(0x7f00000018c0)=""/4096, 0x3d}) openat$ttyS3(0xffffffffffffff9c, 0x0, 0x0, 0x0) r4 = syz_open_procfs(0x0, &(0x7f00000003c0)='net/mcfilter6\x00') preadv(r4, &(0x7f0000002740)=[{&(0x7f0000000600)=""/4096, 0x1000}], 0x1, 0x6, 0x6) 1.986953406s ago: executing program 4 (id=1539): r0 = openat$kvm(0xffffffffffffff9c, &(0x7f00000012c0), 0xa0400, 0x0) ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r1 = openat$iommufd(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) ioctl$IOMMU_IOAS_ALLOC(r1, 0x3b81, &(0x7f00000000c0)={0xc, 0x0, 0x0}) ioctl$IOMMU_TEST_OP_MOCK_DOMAIN(r1, 0x3ba0, &(0x7f0000000100)={0x48, 0x2, r2, 0x0, 0x0, 0x0, 0x0}) ioctl$IOMMU_HWPT_ALLOC$NONE(r1, 0x3b89, &(0x7f0000000180)={0x28, 0x1, r3, r2, 0x0, 0x0, 0x0, 0x0, 0x0}) ioctl$IOMMU_IOAS_MAP$PAGES(r1, 0x3b85, &(0x7f0000000280)={0x28, 0x4, r2, 0x0, &(0x7f0000ffc000/0x2000)=nil, 0x2000, 0x1}) ioctl$IOMMU_IOAS_MAP$PAGES(r1, 0x3b85, &(0x7f0000000000)={0x28, 0x4, r2, 0x0, &(0x7f0000ffd000/0x1000)=nil, 0x1000, 0x8}) ioctl$IOMMU_DESTROY$hwpt(r1, 0x3b80, &(0x7f0000000340)={0x8, r4}) 1.906918971s ago: executing program 0 (id=1540): r0 = syz_init_net_socket$nfc_llcp(0x27, 0x2, 0x1) listen(r0, 0x8001) r1 = bpf$MAP_CREATE(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="0500000004000000080000000a"], 0x48) close(0x3) bpf$MAP_CREATE(0x0, &(0x7f0000000000)=ANY=[@ANYBLOB="0b00000008000000080000000600000001"], 0x50) bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="18090000000000000000000000000000850000006d0000001801000020696c2500000000002020207b1af8ff00000000bfa10000000000000701"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x14, &(0x7f0000000400)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7040000000000008500000001"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000023c0)={0x0, 0x4, &(0x7f0000000480)=ANY=[@ANYBLOB="18020000000500000000000000000000850000007b00000095"], 0x0, 0x0, 0x0, 0x0, 0x41000, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0x14, &(0x7f0000000400)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000bc0)={&(0x7f0000000940)='percpu_alloc_percpu\x00', r2}, 0x10) ioctl$AUTOFS_DEV_IOCTL_VERSION(0xffffffffffffffff, 0xc0189371, &(0x7f0000000000)={{0x1, 0x1, 0x18}, './file0\x00'}) socket$nl_route(0x10, 0x3, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$ENABLE_STATS(0x20, 0x0, 0x0) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) bpf$ENABLE_STATS(0x20, 0x0, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000180)=0x4) sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r3 = syz_open_dev$MSR(&(0x7f00000001c0), 0x0, 0x0) read$msr(r3, &(0x7f0000001a40)=""/102392, 0x18ff8) r4 = socket$igmp(0x2, 0x3, 0x2) setsockopt$MRT_ADD_VIF(r4, 0x0, 0xca, 0x0, 0x0) r5 = openat$rfkill(0xffffffffffffff9c, &(0x7f00000000c0), 0x80201, 0x0) write$rfkill(r5, &(0x7f0000000000)={0x0, 0x8, 0x2, 0x1}, 0x8) openat$ttyS3(0xffffffffffffff9c, &(0x7f0000001840), 0x2982, 0x0) seccomp$SECCOMP_SET_MODE_FILTER_LISTENER(0x1, 0xc, &(0x7f00000000c0)={0x1, &(0x7f0000000100)=[{0x6, 0x6, 0x0, 0x7fff0006}]}) writev(0xffffffffffffffff, 0x0, 0x0) syz_clone3(&(0x7f0000000140)={0x0, 0x0, 0x0, 0x0, {}, 0x0, 0x700, 0x0, 0x0}, 0x58) socket$kcm(0x11, 0xa, 0x300) 1.207248333s ago: executing program 1 (id=1541): r0 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x18, 0x4, &(0x7f00000002c0)=ANY=[@ANYBLOB="18010000000000000000000000000000850000006d00"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x2, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000080)={&(0x7f0000000000)='sched_switch\x00', r0}, 0x10) prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x88}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000240)=0x7) r1 = getpid() sched_setscheduler(r1, 0x2, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeee, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r2, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r3, &(0x7f0000000000), 0x651, 0x0) recvmmsg(r2, &(0x7f00000000c0), 0x10106, 0x2, 0x0) sched_setscheduler(0x0, 0x2, &(0x7f0000000000)=0x6) openat$procfs(0xffffffffffffff9c, 0x0, 0x0, 0x0) sendmsg$IPSET_CMD_CREATE(0xffffffffffffffff, &(0x7f0000000340)={0x0, 0x0, &(0x7f0000000300)={&(0x7f0000000080)={0x14, 0x2, 0x6, 0x801}, 0x14}, 0x1, 0x0, 0x0, 0x2002c0c4}, 0x0) unshare(0x22020400) munmap(&(0x7f0000002000/0x1000)=nil, 0x1000) r4 = syz_open_dev$usbmon(&(0x7f0000000080), 0x0, 0x0) r5 = syz_open_dev$usbfs(&(0x7f0000000040), 0x20000007d, 0x0) r6 = dup3(r4, r5, 0x0) ioctl$MON_IOCX_GETX(r6, 0x4018920a, &(0x7f0000000d80)={&(0x7f0000000000), &(0x7f0000002240)=""/4124, 0x101c}) 1.105991326s ago: executing program 3 (id=1542): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) (async) sendmmsg$unix(r1, &(0x7f00000bd000), 0x318, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) r2 = open(&(0x7f0000000280)='.\x00', 0x0, 0x0) r3 = openat$rdma_cm(0xffffff9c, &(0x7f00000006c0), 0x2, 0x0) write$RDMA_USER_CM_CMD_GET_EVENT(r3, 0x0, 0x0) (async) mmap(&(0x7f0000000000/0xfbe000)=nil, 0xfbe000, 0x2, 0x31, 0xffffffffffffffff, 0x0) (async) write$RDMA_USER_CM_CMD_CREATE_ID(r3, &(0x7f0000000540)={0x0, 0x18, 0xfa00, {0x1, &(0x7f0000000500)={0xffffffffffffffff}, 0x106}}, 0x20) write$RDMA_USER_CM_CMD_RESOLVE_IP(r3, &(0x7f0000000600)={0x3, 0x40, 0xfa00, {{0xa, 0x4e20, 0x3, @loopback, 0x1}, {0xa, 0x0, 0x9, @mcast1}, r4}}, 0x48) fcntl$notify(r2, 0x402, 0x8000003d) (async) r5 = io_uring_setup(0x3454, &(0x7f0000000080)={0x0, 0xffffafff, 0x1000, 0x2, 0x33d}) io_uring_register$IORING_REGISTER_BUFFERS(r5, 0x0, &(0x7f00000002c0)=[{&(0x7f0000001700)=""/4095, 0x440000}], 0x100000000000011a) (async) madvise(&(0x7f0000000000/0x600000)=nil, 0x600003, 0x8) (async) r6 = socket$l2tp(0x2, 0x2, 0x73) bind$l2tp(0xffffffffffffffff, &(0x7f00000000c0)={0x2, 0x0, @dev={0xac, 0x14, 0x14, 0x12}}, 0x10) (async) bind$inet(r6, &(0x7f0000000000)={0x2, 0x0, @multicast1}, 0x10) (async) syz_emit_ethernet(0x74, &(0x7f0000000000)={@link_local, @empty, @void, {@ipv4={0x800, @udp={{0x5, 0x4, 0x0, 0x0, 0x24, 0x0, 0x0, 0x0, 0x73, 0x0, @private=0x300, @multicast1=0xac141412}, {0x0, 0x0, 0xfffffe9a, 0x0, @gue={{0x2}}}}}}}, 0x0) (async) r7 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000100), 0x0, 0x0) r8 = ioctl$KVM_CREATE_VM(r7, 0xae01, 0x0) ioctl$KVM_SET_USER_MEMORY_REGION(r8, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x20002000, &(0x7f0000000000/0x2000)=nil}) r9 = ioctl$KVM_CREATE_VCPU(r8, 0xae41, 0x0) (async) r10 = socket$inet6_tcp(0xa, 0x1, 0x0) setsockopt$inet6_buf(r10, 0x29, 0x20, &(0x7f00000000c0)="0bbb268dd6ffa80800000000000000000000210d0000aaa8fa017242ba9380d412000000000000002900000036000000", 0xfe60) syz_kvm_setup_cpu$x86(0xffffffffffffffff, r9, &(0x7f0000000000/0x18000)=nil, &(0x7f0000000140)=[@text64={0x40, 0x0}], 0x1, 0x0, 0x0, 0x0) ioctl$KVM_SET_REGS(r9, 0x4090ae82, &(0x7f0000000240)={[0x583a, 0x5, 0x9, 0xe55, 0x6, 0x2, 0x1040, 0x4, 0x0, 0x32a, 0xfffffffffffffffe, 0xffffffff, 0x1, 0x9, 0x5, 0x6a], 0x1, 0x1000d6}) (async) ioctl$KVM_RUN(r9, 0xae80, 0x0) (async) r11 = syz_open_procfs(0x0, &(0x7f0000000040)='smaps_rollup\x00') preadv(r11, &(0x7f0000000140)=[{0x0}], 0x1, 0x0, 0x0) 1.054735425s ago: executing program 5 (id=1543): socketpair$unix(0x1, 0x3, 0x0, &(0x7f0000000080)={0xffffffffffffffff}) connect$unix(r0, &(0x7f000057eff8)=@abs, 0x6e) sendmmsg$unix(r0, &(0x7f00000bd000), 0x0, 0x0) recvmmsg(r0, &(0x7f00000000c0), 0x10106, 0x2, 0x0) prctl$PR_SCHED_CORE(0x3e, 0x1, 0x0, 0x2, 0x0) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0x2, 0x8031, 0xffffffffffffffff, 0x9a974000) mremap(&(0x7f000040b000/0x1000)=nil, 0x1000, 0x4000, 0x3, &(0x7f00004b3000/0x4000)=nil) mremap(&(0x7f00003ef000/0x3000)=nil, 0x3000, 0x400000, 0x3, &(0x7f000082a000/0x400000)=nil) madvise(&(0x7f000042f000/0x800000)=nil, 0x800000, 0x15) 973.517531ms ago: executing program 0 (id=1544): prlimit64(0x0, 0xe, &(0x7f0000000140)={0x8, 0x8b}, 0x0) sched_setscheduler(0x0, 0x1, &(0x7f0000000080)=0x7) syz_open_procfs(0x0, &(0x7f0000000000)='map_files\x00') r0 = getpid() sched_setaffinity(0x0, 0x8, &(0x7f00000002c0)=0x2) sched_setscheduler(r0, 0x2, &(0x7f0000000200)=0x4) mmap(&(0x7f0000000000/0xb36000)=nil, 0xb36000, 0xb635773f06ebbeef, 0x8031, 0xffffffffffffffff, 0x0) socketpair$unix(0x1, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) connect$unix(r1, &(0x7f000057eff8)=@abs={0x0, 0x0, 0x4e22}, 0x6e) sendmmsg$unix(r2, &(0x7f0000000000), 0x400000000000041, 0x0) recvmmsg(r1, &(0x7f00000000c0), 0x10106, 0x2, 0x0) r3 = socket$inet_tcp(0x2, 0x1, 0x0) r4 = syz_genetlink_get_family_id$ethtool(&(0x7f0000000300), 0xffffffffffffffff) r5 = socket$nl_generic(0x10, 0x3, 0x10) recvmmsg(r5, &(0x7f0000001640)=[{{0x0, 0x0, &(0x7f0000000040)=[{&(0x7f00000004c0)=""/4096, 0x1e1c}, {&(0x7f00000000c0)=""/250, 0x4}], 0x2, 0x0, 0xd64}}], 0x300, 0x34000, 0x0) sendmsg$ETHTOOL_MSG_TSINFO_GET(r5, &(0x7f0000000480)={0x0, 0x0, &(0x7f0000000440)={&(0x7f0000000280)=ANY=[@ANYBLOB="18000000", @ANYRES16=r4, @ANYBLOB="a787000000ff000000000b00000404000180"], 0x18}}, 0x0) socket$inet6_sctp(0xa, 0x5, 0x84) recvfrom$inet(r3, &(0x7f0000000080)=""/8, 0xfffffffffffffd0b, 0x720, 0x0, 0xfffffffffffffd25) set_mempolicy(0x8004, &(0x7f0000003ac0)=0x9, 0x5) r6 = socket$inet_mptcp(0x2, 0x1, 0x106) r7 = syz_open_dev$vim2m(&(0x7f0000000000), 0x3, 0x2) ioctl$vim2m_VIDIOC_S_FMT(r7, 0xc0d05605, &(0x7f0000008b40)={0x2, @pix={0x4, 0xdf, 0x34324d59, 0x4, 0x9, 0xff000000, 0xb, 0x6, 0x0, 0x7}}) syz_genetlink_get_family_id$nl80211(&(0x7f0000000040), 0xffffffffffffffff) ioctl$sock_SIOCETHTOOL(r6, 0x89f1, &(0x7f00000002c0)={'ip6gre0\x00', &(0x7f0000000000)=@ethtool_cmd={0x0, 0x0, 0x0, 0x200, 0x2, 0x0, 0x0, 0x0, 0x0, 0x4, 0x0, 0xfffff7fc, 0x4, 0x0, 0x0, 0x47, [0xfffffffc, 0x80]}}) 772.084182ms ago: executing program 4 (id=1545): syz_usb_connect(0x0, 0x36, &(0x7f00000000c0)=ANY=[@ANYBLOB="120100008010bd40820514009dbb0000000109022400011b00000009040000022a3e740009058bff7f0000100109050b362f"], 0x0) r0 = syz_open_dev$midi(&(0x7f0000000000), 0x3, 0x88c02) r1 = syz_io_uring_setup(0x9e, &(0x7f0000000640)={0x0, 0xec25, 0x0, 0x0, 0x40000333}, &(0x7f00000006c0)=0x0, &(0x7f00000001c0)=0x0) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000180)=0xfffffffc, 0x0, 0x4) syz_io_uring_submit(r2, r3, &(0x7f0000000200)=@IORING_OP_READV=@pass_iovec={0x1, 0x4, 0x0, @fd_index=0x4, 0x0, &(0x7f0000000600)=[{&(0x7f0000000400)=""/202, 0xca}], 0x1}) io_uring_enter(r1, 0x847ba, 0x0, 0xe, 0x0, 0x0) ioctl$SNDRV_RAWMIDI_IOCTL_STATUS64(r0, 0xc0385720, &(0x7f0000000040)={0x1}) syz_usb_connect(0x0, 0x36, &(0x7f00000000c0)=ANY=[@ANYBLOB="120100008010bd40820514009dbb0000000109022400011b00000009040000022a3e740009058bff7f0000100109050b362f"], 0x0) (async) syz_open_dev$midi(&(0x7f0000000000), 0x3, 0x88c02) (async) syz_io_uring_setup(0x9e, &(0x7f0000000640)={0x0, 0xec25, 0x0, 0x0, 0x40000333}, &(0x7f00000006c0), &(0x7f00000001c0)) (async) syz_memcpy_off$IO_URING_METADATA_GENERIC(r2, 0x4, &(0x7f0000000180)=0xfffffffc, 0x0, 0x4) (async) syz_io_uring_submit(r2, r3, &(0x7f0000000200)=@IORING_OP_READV=@pass_iovec={0x1, 0x4, 0x0, @fd_index=0x4, 0x0, &(0x7f0000000600)=[{&(0x7f0000000400)=""/202, 0xca}], 0x1}) (async) io_uring_enter(r1, 0x847ba, 0x0, 0xe, 0x0, 0x0) (async) ioctl$SNDRV_RAWMIDI_IOCTL_STATUS64(r0, 0xc0385720, &(0x7f0000000040)={0x1}) (async) 0s ago: executing program 0 (id=1546): prctl$PR_SET_SYSCALL_USER_DISPATCH_ON(0x3b, 0x1, 0x0, 0x0, &(0x7f0000006680)) (async) r0 = openat$ptmx(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) ioctl$TIOCSETD(r0, 0x5423, &(0x7f00000000c0)=0xf) (async) r1 = fcntl$dupfd(r0, 0x0, r0) ioctl$TCFLSH(r0, 0x400455c8, 0x8000000001) (async) ioctl$TIOCSETD(r1, 0x5412, &(0x7f0000000140)=0xffffffc0) (async) r2 = gettid() timer_create(0x2, &(0x7f0000533fa0)={0x0, 0x21, 0x800000000004, @tid=r2}, &(0x7f0000000340)) (async) timer_settime(0x0, 0x0, &(0x7f0000000000)={{0x0, 0x989680}, {0x0, 0x989680}}, 0x0) clock_nanosleep(0x2, 0x0, &(0x7f0000000040)={0x0, 0x989680}, 0x0) (async) ioctl$TIOCSTI(r1, 0x5412, 0x0) (async, rerun: 32) prctl$PR_SET_SYSCALL_USER_DISPATCH_ON(0x3b, 0x1, 0xfff, 0x7, &(0x7f0000000000)) (async, rerun: 32) syz_usb_connect(0x0, 0x36, &(0x7f0000000640)=ANY=[@ANYBLOB="120100030f9be020b113410069b00102030109022400010000800409048f4d01ff429600092105000301225b03090505000004030c0350666f616819250c6f89b0b34f077112cb95737b8e46d67734b1a4a67e31eee6c07dba57b7a6c3da85309ee1220dd44fb8400774edcc5747abdb6901b7915a0f0c818704451c9db15b65d0ffd010ac97"], &(0x7f0000003980)={0x0, 0x0, 0x0, 0x0}) (async) r3 = socket$nl_route(0x10, 0x3, 0x0) sendmsg$nl_route(r3, &(0x7f0000000480)={0x0, 0x0, &(0x7f0000000980)={&(0x7f00000004c0)=ANY=[@ANYBLOB="240000001900010028bd7000fedbdf251d01000008000a00", @ANYRES32=0x0, @ANYBLOB='\b\x00\t\x00', @ANYRES32=0x0, @ANYBLOB="030000000000000700000000000292b98af17c5dbe56873456d49b0d3aaa69cfffc477e745aa5746f2b8cd0a40fbfddeb96f87010100000000000071ee074cce4a755fd5757eaa020467f381f3049df859d060bb3fe517b486524acaa99d27ee91fe21ec8bbc014283881b7e9c10bb1abcba2fcfd0246f8974f7bd0a9206cbe5057f"], 0x24}, 0x1, 0x0, 0x0, 0x10}, 0x0) (async) mlock2(&(0x7f0000076000/0x2000)=nil, 0x2000, 0x1) r4 = socket$inet(0x2, 0x2, 0x0) (async) r5 = socket$inet_tcp(0x2, 0x1, 0x0) setsockopt$inet_mreqn(r5, 0x0, 0x23, &(0x7f0000000740)={@loopback, @loopback}, 0xc) r6 = socket$nl_generic(0x10, 0x3, 0x10) r7 = syz_genetlink_get_family_id$nl80211(&(0x7f0000000080), 0xffffffffffffffff) (async) ioctl$sock_SIOCGIFINDEX_80211(r6, 0x8933, &(0x7f00000000c0)={'wlan1\x00', 0x0}) (async, rerun: 64) r9 = socket$inet(0x2, 0x1, 0x0) (rerun: 64) setsockopt$inet_int(r9, 0x0, 0x4, &(0x7f0000000000)=0x3, 0x4) (async) sendmsg$NL80211_CMD_SET_INTERFACE(r6, &(0x7f0000000100)={0x0, 0x0, &(0x7f0000000140)={&(0x7f0000000580)=ANY=[@ANYBLOB='$\x00\x00\x00', @ANYRES16=r7, @ANYBLOB="050000000000000000000600000008000300154ff1182f4da12edc630099e3ce6ef14e41bf2043fb15035644371bfa08064da743fc063471cccac6f710773c3b30b846afa09cd45892034cb4be30289d6e04672bb9cf1e82c5060dbf0bd50ef92681629253fd9960885743776b6dbe3c1f077800895a0a856e981c07", @ANYRES32=r8, @ANYBLOB="0800050003000000"], 0x24}}, 0x0) (async) sendmsg$NL80211_CMD_START_AP(r6, &(0x7f00000001c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f00000009c0)={0xc0, r7, 0x8, 0x0, 0x0, {{}, {@void, @void}}, [@beacon=[@NL80211_ATTR_IE={0x73, 0x2a, [@sec_chan_ofs={0x3e, 0x1, 0x3}, @sec_chan_ofs={0x3e, 0x1, 0x3}, @preq={0x82, 0x2b, {{0x0, 0x0, 0x0, 0x0, 0x1}, 0x4, 0x3, 0x6, @device_a, 0xc77, @value, 0x6, 0x4, 0x1, [{{0x1, 0x0, 0x1}, @device_a, 0x8}]}}, @peer_mgmt={0x75, 0x16, {0x0, 0x8, @void, @val=0x28, @val="696b5d05f5d21208cb7f32a55cffff39"}}, @ht={0x2d, 0x1a, {0x800, 0x1, 0x7, 0x0, {0x1, 0x4, 0x0, 0x199, 0x0, 0x0, 0x0, 0x2, 0x1}, 0x800, 0xd9, 0x77}}, @gcr_ga={0xbd, 0x6}]}], @chandef_params=[@NL80211_ATTR_WIPHY_FREQ={0x8}, @NL80211_ATTR_WIPHY_EDMG_CHANNELS={0x5, 0x118, 0x38}, @NL80211_ATTR_WIPHY_EDMG_CHANNELS={0x5, 0x118, 0x31}, @NL80211_ATTR_CENTER_FREQ1={0x8, 0xa0, 0x2}, @NL80211_ATTR_WIPHY_EDMG_BW_CONFIG={0x5, 0x119, 0x6}], @NL80211_ATTR_BEACON_INTERVAL={0x8}, @NL80211_ATTR_DTIM_PERIOD={0x8, 0xd, 0x1}]}, 0xc0}}, 0x0) (async) setsockopt$inet_msfilter(r4, 0x0, 0x29, &(0x7f0000000000)=ANY=[@ANYBLOB="e00000027fa80a010100000004"], 0x57) (async) r10 = socket$netlink(0x10, 0x3, 0x0) writev(r10, &(0x7f00000003c0)=[{&(0x7f0000000180)="200000001300034700bb65e1c3e4ffff01000000010000005600000025000000", 0x20}], 0x1) (async) socket$inet6_icmp_raw(0xa, 0x3, 0x3a) kernel console output (not intermixed with test programs): file permissive=1 [ 403.133491][ T5861] usb 4-1: config 5 has no interfaces? [ 403.233049][ T9] IPVS: starting estimator thread 0... [ 403.251161][ T9528] lo speed is unknown, defaulting to 1000 [ 403.261814][ T5861] usb 4-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 403.276385][ T5861] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 403.284442][ T5861] usb 4-1: Product: syz [ 403.288599][ T5861] usb 4-1: Manufacturer: syz [ 403.324423][ T9536] IPVS: using max 38 ests per chain, 91200 per kthread [ 403.540414][ T5861] usb 4-1: SerialNumber: syz [ 403.546578][ T30] audit: type=1400 audit(1746633995.075:1261): avc: denied { mount } for pid=9529 comm="syz.1.935" name="/" dev="overlay" ino=979 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fs_t tclass=filesystem permissive=1 [ 403.616431][ T9528] lo speed is unknown, defaulting to 1000 [ 403.659669][ T9528] lo speed is unknown, defaulting to 1000 [ 403.670198][ T9528] lo speed is unknown, defaulting to 1000 [ 403.681169][ T9528] lo speed is unknown, defaulting to 1000 [ 403.995611][ T9528] lo speed is unknown, defaulting to 1000 [ 405.238962][ T5861] usb 4-1: USB disconnect, device number 20 [ 405.776538][ T5891] usb 1-1: new full-speed USB device number 24 using dummy_hcd [ 406.129327][ T30] audit: type=1326 audit(1746633998.075:1262): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 406.196537][ T5891] usb 1-1: New USB device found, idVendor=09c0, idProduct=0203, bcdDevice=d3.43 [ 406.223972][ T5891] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 406.393210][ C1] IPVS: rr: UDP 224.0.0.2:0 - no destination available [ 406.410637][ T30] audit: type=1326 audit(1746633998.075:1263): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 406.436381][ T5891] usb 1-1: config 0 descriptor?? [ 406.446827][ T30] audit: type=1326 audit(1746633998.075:1264): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 406.454919][ T5891] dvb-usb: found a 'Genpix SkyWalker-1 DVB-S receiver' in warm state. [ 406.470530][ T30] audit: type=1326 audit(1746633998.075:1265): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 406.503288][ T30] audit: type=1326 audit(1746633998.075:1266): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 406.601154][ T30] audit: type=1326 audit(1746633998.355:1267): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 406.935111][ T9556] process 'syz.0.940' launched '/dev/fd/7' with NULL argv: empty string added [ 406.973100][ T30] audit: type=1326 audit(1746633998.355:1268): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.052719][ T30] audit: type=1326 audit(1746633998.355:1269): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.159621][ T30] audit: type=1326 audit(1746633998.355:1270): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.199538][ T30] audit: type=1326 audit(1746633998.355:1271): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.248458][ T30] audit: type=1326 audit(1746633998.355:1272): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.594859][ T30] audit: type=1326 audit(1746633998.355:1273): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.854532][ T30] audit: type=1326 audit(1746633998.355:1274): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 407.881137][ T30] audit: type=1326 audit(1746633998.355:1275): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9568 comm="syz.3.945" exe="/root/syz-executor" sig=0 arch=c000003e syscall=9 compat=0 ip=0x7f7763b8e969 code=0x7ffc0000 [ 408.540427][ T5891] gp8psk: usb out operation failed. [ 408.553148][ T30] audit: type=1400 audit(1746633998.895:1276): avc: denied { execute_no_trans } for pid=9555 comm="syz.0.940" path=2F6D656D66643A5B0BDB58AE5B1AA9FDFAAED16D64C885202864656C6574656429 dev="hugetlbfs" ino=20163 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:hugetlbfs_t tclass=file permissive=1 [ 408.632867][ T5891] dvb-usb: This USB2.0 device cannot be run on a USB1.1 port. (it lacks a hardware PID filter) [ 408.666595][ T5891] dvb-usb: Genpix SkyWalker-1 DVB-S receiver error while loading driver (-19) [ 409.173338][ T9596] vhci_hcd vhci_hcd.0: pdev(3) rhport(0) sockfd(7) [ 409.179888][ T9596] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 409.187639][ T9596] vhci_hcd vhci_hcd.0: Device attached [ 409.510603][ T9] usb 4-1: new high-speed USB device number 21 using dummy_hcd [ 409.553072][ T5891] usb 1-1: USB disconnect, device number 24 [ 409.583073][ T972] usb 40-1: SetAddress Request (10) to port 0 [ 409.590237][ T9606] sch_tbf: burst 4398 is lower than device lo mtu (65550) ! [ 409.699736][ T972] usb 40-1: new SuperSpeed USB device number 10 using vhci_hcd [ 410.224614][ T9614] siw: device registration error -23 [ 410.381118][ T9] usb 4-1: device descriptor read/all, error -71 [ 410.390770][ T9598] vhci_hcd: connection reset by peer [ 410.536848][ T1146] vhci_hcd: stop threads [ 410.541224][ T1146] vhci_hcd: release socket [ 410.641076][ T1146] vhci_hcd: disconnect device [ 411.844153][ T5816] Bluetooth: hci4: command 0x0406 tx timeout [ 413.640408][ T30] kauditd_printk_skb: 8 callbacks suppressed [ 413.640423][ T30] audit: type=1400 audit(1746634005.585:1285): avc: denied { read append } for pid=9642 comm="syz.3.963" name="fb0" dev="devtmpfs" ino=629 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:framebuf_device_t tclass=chr_file permissive=1 [ 413.706945][ T9649] netlink: 209852 bytes leftover after parsing attributes in process `syz.5.962'. [ 413.711156][ T9645] infiniband syz1: RDMA CMA: cma_listen_on_dev, error -98 [ 413.824583][ T9649] openvswitch: netlink: ufid size 3068 bytes exceeds the range (1, 16) [ 413.833839][ T9649] openvswitch: netlink: Flow get message rejected, Key attribute missing. [ 413.842829][ T30] audit: type=1400 audit(1746634005.585:1286): avc: denied { open } for pid=9642 comm="syz.3.963" path="/dev/fb0" dev="devtmpfs" ino=629 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:framebuf_device_t tclass=chr_file permissive=1 [ 413.866347][ C0] vkms_vblank_simulate: vblank timer overrun [ 414.813038][ T972] usb 40-1: device descriptor read/8, error -110 [ 415.285591][ T972] usb usb40-port1: attempt power cycle [ 416.118461][ T9655] netlink: 4 bytes leftover after parsing attributes in process `syz.3.963'. [ 416.212335][ T30] audit: type=1326 audit(1746634008.155:1287): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 416.238231][ T972] usb usb40-port1: unable to enumerate USB device [ 416.376028][ T30] audit: type=1326 audit(1746634008.155:1288): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 416.415647][ T30] audit: type=1326 audit(1746634008.195:1289): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 416.473075][ T5912] usb 5-1: new full-speed USB device number 19 using dummy_hcd [ 416.566745][ T30] audit: type=1326 audit(1746634008.195:1290): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 417.023113][ T9681] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(7) [ 417.029639][ T9681] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 417.153668][ T30] audit: type=1326 audit(1746634008.195:1291): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 417.177300][ T30] audit: type=1326 audit(1746634008.195:1292): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 417.200872][ T30] audit: type=1326 audit(1746634008.195:1293): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 417.203135][ T9681] vhci_hcd vhci_hcd.0: Device attached [ 417.224776][ T30] audit: type=1326 audit(1746634008.195:1294): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=9670 comm="syz.1.969" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 417.313451][ T5912] usb 5-1: config index 0 descriptor too short (expected 1051, got 27) [ 417.321763][ T5912] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x88 has invalid wMaxPacketSize 0 [ 417.336697][ T5912] usb 5-1: New USB device found, idVendor=06f8, idProduct=b000, bcdDevice=7d.f9 [ 417.349724][ T5912] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 417.357837][ T5912] usb 5-1: Product: syz [ 417.362027][ T5912] usb 5-1: Manufacturer: syz [ 417.367163][ T5912] usb 5-1: SerialNumber: syz [ 417.493280][ T5891] usb 36-1: SetAddress Request (18) to port 0 [ 417.583596][ T5891] usb 36-1: new SuperSpeed USB device number 18 using vhci_hcd [ 417.659011][ T5912] usb 5-1: config 0 descriptor?? [ 417.742879][ T972] usb 2-1: new high-speed USB device number 25 using dummy_hcd [ 417.985158][ T9690] siw: device registration error -23 [ 418.104217][ T9669] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 418.123867][ T9669] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 418.159585][ T5862] usb 5-1: USB disconnect, device number 19 [ 418.220640][ T972] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 418.247764][ T972] usb 2-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 418.303551][ T972] usb 2-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 418.327767][ T972] usb 2-1: config 0 interface 0 has no altsetting 0 [ 418.337636][ T972] usb 2-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 418.487938][ T972] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 418.528716][ T972] usb 2-1: config 0 descriptor?? [ 421.081308][ T5816] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 421.524938][ T30] kauditd_printk_skb: 17 callbacks suppressed [ 421.524953][ T30] audit: type=1400 audit(1746634013.475:1312): avc: denied { append } for pid=9730 comm="syz.5.982" name="random" dev="devtmpfs" ino=8 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:random_device_t tclass=chr_file permissive=1 [ 421.647032][ T9732] 9pnet_fd: Insufficient options for proto=fd [ 421.672857][ T30] audit: type=1400 audit(1746634013.475:1313): avc: denied { setopt } for pid=9730 comm="syz.5.982" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 421.702593][ T30] audit: type=1400 audit(1746634013.565:1314): avc: denied { read } for pid=9730 comm="syz.5.982" name="ppp" dev="devtmpfs" ino=709 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ppp_device_t tclass=chr_file permissive=1 [ 421.725676][ T30] audit: type=1400 audit(1746634013.565:1315): avc: denied { open } for pid=9730 comm="syz.5.982" path="/dev/ppp" dev="devtmpfs" ino=709 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ppp_device_t tclass=chr_file permissive=1 [ 421.750166][ T30] audit: type=1400 audit(1746634013.565:1316): avc: denied { ioctl } for pid=9730 comm="syz.5.982" path="/dev/ppp" dev="devtmpfs" ino=709 ioctlcmd=0x743e scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ppp_device_t tclass=chr_file permissive=1 [ 421.778763][ T30] audit: type=1400 audit(1746634013.595:1317): avc: denied { mounton } for pid=9730 comm="syz.5.982" path="/12/file1" dev="tmpfs" ino=79 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 421.802064][ T30] audit: type=1400 audit(1746634013.605:1318): avc: denied { ioctl } for pid=9730 comm="syz.5.982" path="/dev/fuse" dev="devtmpfs" ino=99 ioctlcmd=0xe500 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:fuse_device_t tclass=chr_file permissive=1 [ 422.816883][ T30] audit: type=1400 audit(1746634014.765:1319): avc: denied { connect } for pid=9734 comm="syz.3.983" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netrom_socket permissive=1 [ 423.161798][ T9739] siw: device registration error -23 [ 423.226725][ T30] audit: type=1400 audit(1746634014.765:1320): avc: denied { bind } for pid=9734 comm="syz.3.983" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netrom_socket permissive=1 [ 423.866142][ T5912] usb 6-1: new high-speed USB device number 2 using dummy_hcd [ 424.393045][ T5912] usb 6-1: Using ep0 maxpacket: 8 [ 424.406605][ T5912] usb 6-1: config index 0 descriptor too short (expected 301, got 45) [ 424.421127][ T5912] usb 6-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid wMaxPacketSize 0 [ 424.447755][ T5912] usb 6-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 0 [ 424.649389][ T5912] usb 6-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 424.673472][ T972] usbhid 2-1:0.0: can't add hid device: -32 [ 424.688936][ T972] usbhid 2-1:0.0: probe with driver usbhid failed with error -32 [ 424.699082][ T5912] usb 6-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 424.731065][ T5912] usb 6-1: New USB device found, idVendor=ee8d, idProduct=db1e, bcdDevice=61.23 [ 424.748238][ T5912] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 424.856552][ T972] usb 2-1: USB disconnect, device number 25 [ 424.892529][ T9682] vhci_hcd: connection reset by peer [ 424.917871][ T81] vhci_hcd: stop threads [ 424.922149][ T81] vhci_hcd: release socket [ 424.957466][ T81] vhci_hcd: disconnect device [ 424.960032][ T5891] usb 36-1: device descriptor read/8, error -110 [ 424.970123][ T5912] usb 6-1: usb_control_msg returned -32 [ 424.981624][ T5912] usbtmc 6-1:16.0: can't read capabilities [ 425.325666][ T9777] usbtmc 6-1:16.0: usb_control_msg returned -32 [ 425.441579][ T5891] usb usb36-port1: attempt power cycle [ 426.034140][ T30] audit: type=1400 audit(1746634017.985:1321): avc: denied { append } for pid=9779 comm="syz.3.995" name="sg0" dev="devtmpfs" ino=743 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:scsi_generic_device_t tclass=chr_file permissive=1 [ 426.333732][ T5816] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 426.376220][ T9788] SELinux: unrecognized netlink message: protocol=0 nlmsg_type=0 sclass=netlink_route_socket pid=9788 comm=syz.1.999 [ 426.439925][ T5891] usb usb36-port1: unable to enumerate USB device [ 427.109945][ T5863] usb 6-1: USB disconnect, device number 2 [ 427.729813][ T9805] misc userio: Invalid payload size [ 429.078502][ T9814] IPVS: Error connecting to the multicast addr [ 429.130142][ T5824] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 430.663296][ T9868] IPVS: sync thread started: state = MASTER, mcast_ifn = veth0_virt_wifi, syncid = 33554432, id = 0 [ 431.207995][ T9874] siw: device registration error -23 [ 432.136386][ T9890] (unnamed net_device) (uninitialized): option primary: mode dependency failed, not supported in mode balance-rr(0) [ 432.156381][ T30] kauditd_printk_skb: 1 callbacks suppressed [ 432.162465][ T30] audit: type=1400 audit(1746634024.105:1323): avc: denied { ioctl } for pid=9887 comm="syz.4.1032" path="/dev/vhost-net" dev="devtmpfs" ino=1274 ioctlcmd=0xaf00 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:vhost_device_t tclass=chr_file permissive=1 [ 432.887233][ T9898] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1033'. [ 434.286000][ T5824] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 434.815805][ T9926] siw: device registration error -23 [ 437.353202][ T30] audit: type=1400 audit(1746634029.285:1324): avc: denied { ioctl } for pid=9954 comm="syz.5.1049" path="socket:[22607]" dev="sockfs" ino=22607 ioctlcmd=0x89e3 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=ax25_socket permissive=1 [ 437.927265][ T5824] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 438.053622][ T30] audit: type=1400 audit(1746634029.995:1325): avc: denied { setopt } for pid=9974 comm="syz.0.1055" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=alg_socket permissive=1 [ 438.093672][ T30] audit: type=1400 audit(1746634030.025:1326): avc: denied { ioctl } for pid=9974 comm="syz.0.1055" path="socket:[21824]" dev="sockfs" ino=21824 ioctlcmd=0x8922 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=pppox_socket permissive=1 [ 438.130175][ T30] audit: type=1400 audit(1746634030.075:1327): avc: denied { create } for pid=9974 comm="syz.0.1055" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=phonet_socket permissive=1 [ 438.183953][ T30] audit: type=1400 audit(1746634030.075:1328): avc: denied { getopt } for pid=9974 comm="syz.0.1055" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=phonet_socket permissive=1 [ 438.698177][ T9989] netlink: 24 bytes leftover after parsing attributes in process `syz.5.1060'. [ 439.283206][ T5816] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 439.362236][ T30] audit: type=1400 audit(1746634031.305:1329): avc: denied { mounton } for pid=10003 comm="syz.5.1063" path=2F32362FE91F7189591E9233614B dev="tmpfs" ino=161 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=sock_file permissive=1 [ 439.390206][T10004] overlayfs: workdir and upperdir must reside under the same mount [ 439.478329][ T5824] Bluetooth: hci0: Ignoring HCI_Connection_Complete for existing connection [ 439.663480][ T30] audit: type=1400 audit(1746634031.605:1330): avc: denied { unmount } for pid=9225 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:tmpfs_t tclass=filesystem permissive=1 [ 439.705461][ T1296] ieee802154 phy0 wpan0: encryption failed: -22 [ 439.711752][ T1296] ieee802154 phy1 wpan1: encryption failed: -22 [ 439.986654][ T972] usb 5-1: new high-speed USB device number 20 using dummy_hcd [ 440.715951][ T972] usb 5-1: Using ep0 maxpacket: 32 [ 440.744971][ T972] usb 5-1: config 0 has an invalid interface number: 51 but max is 0 [ 440.810955][ T972] usb 5-1: config 0 has no interface number 0 [ 441.323607][ T972] usb 5-1: New USB device found, idVendor=061d, idProduct=c150, bcdDevice=ce.6f [ 441.332686][ T972] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 441.356668][ T972] usb 5-1: Product: syz [ 441.361062][ T972] usb 5-1: Manufacturer: syz [ 441.365858][ T972] usb 5-1: SerialNumber: syz [ 441.390370][ T972] usb 5-1: config 0 descriptor?? [ 441.497506][T10027] ubi31: attaching mtd0 [ 441.503493][T10027] ubi31: scanning is finished [ 441.509164][ T972] quatech2 5-1:0.51: Quatech 2nd gen USB to Serial Driver converter detected [ 441.610541][T10027] ubi31: attached mtd0 (name "mtdram test device", size 0 MiB) [ 441.619819][T10027] ubi31: PEB size: 4096 bytes (4 KiB), LEB size: 3968 bytes [ 441.627131][T10027] ubi31: min./max. I/O unit sizes: 1/64, sub-page size 1 [ 441.634161][T10027] ubi31: VID header offset: 64 (aligned 64), data offset: 128 [ 441.641605][T10027] ubi31: good PEBs: 32, bad PEBs: 0, corrupted PEBs: 0 [ 441.648443][T10027] ubi31: user volume: 0, internal volumes: 1, max. volumes count: 23 [ 441.656538][T10027] ubi31: max/mean erase counter: 1/1, WL threshold: 4096, image sequence number: 565999716 [ 441.666520][T10027] ubi31: available PEBs: 28, total reserved PEBs: 4, PEBs reserved for bad PEB handling: 0 [ 441.677575][T10031] ubi31: background thread "ubi_bgt31d" started, PID 10031 [ 441.691421][T10029] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1070'. [ 441.729956][ T972] usb 5-1: Quatech 2nd gen USB to Serial Driver converter now attached to ttyUSB0 [ 441.753404][ T972] usb 5-1: Quatech 2nd gen USB to Serial Driver converter now attached to ttyUSB1 [ 441.845772][ T5183] udevd[5183]: worker [5827] terminated by signal 33 (Unknown signal 33) [ 441.864615][ T5183] udevd[5183]: worker [5827] failed while handling '/devices/platform/dummy_hcd.4/usb5/5-1/5-1:0.51/ttyUSB1/tty/ttyUSB1' [ 442.189029][T10009] syz_tun: entered allmulticast mode [ 442.196470][T10009] netlink: 8 bytes leftover after parsing attributes in process `syz.4.1064'. [ 442.207538][T10009] netlink: 8 bytes leftover after parsing attributes in process `syz.4.1064'. [ 442.226529][T10008] syz_tun: left allmulticast mode [ 442.401699][ T30] audit: type=1400 audit(1746634034.345:1331): avc: denied { execute } for pid=10041 comm="syz.1.1075" path="/220/cpu.stat" dev="tmpfs" ino=1156 scontext=root:sysadm_r:sysadm_t tcontext=root:object_r:user_tmpfs_t tclass=file permissive=1 [ 442.425640][ T972] usb 1-1: new high-speed USB device number 25 using dummy_hcd [ 442.733108][ T972] usb 1-1: device descriptor read/64, error -71 [ 443.013204][ T5824] Bluetooth: hci0: Ignoring HCI_Connection_Complete for existing connection [ 443.309155][ T972] usb 1-1: new high-speed USB device number 26 using dummy_hcd [ 443.623194][ T972] usb 1-1: device descriptor read/64, error -71 [ 444.724805][ T972] usb usb1-port1: attempt power cycle [ 444.917173][T10061] lo speed is unknown, defaulting to 1000 [ 445.251533][ C0] usb 5-1: qt2_read_bulk_callback - non-zero urb status: -71 [ 445.253536][ T5863] usb 5-1: USB disconnect, device number 20 [ 445.295056][ T5816] Bluetooth: hci1: Ignoring HCI_Connection_Complete for existing connection [ 445.488170][ T5863] quatech-serial ttyUSB0: Quatech 2nd gen USB to Serial Driver converter now disconnected from ttyUSB0 [ 446.290826][ T5863] quatech-serial ttyUSB1: Quatech 2nd gen USB to Serial Driver converter now disconnected from ttyUSB1 [ 446.353780][ T5863] quatech2 5-1:0.51: device disconnected [ 447.662433][ T5816] sysfs: cannot create duplicate filename '/devices/virtual/bluetooth/hci5/hci5:201' [ 447.672540][ T5816] CPU: 1 UID: 0 PID: 5816 Comm: kworker/u9:4 Not tainted 6.15.0-rc5-syzkaller-00032-g0d8d44db295c #0 PREEMPT(full) [ 447.672568][ T5816] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/29/2025 [ 447.672581][ T5816] Workqueue: hci5 hci_rx_work [ 447.672613][ T5816] Call Trace: [ 447.672619][ T5816] [ 447.672626][ T5816] dump_stack_lvl+0x16c/0x1f0 [ 447.672652][ T5816] sysfs_warn_dup+0x7f/0xa0 [ 447.672680][ T5816] sysfs_create_dir_ns+0x24b/0x2b0 [ 447.672707][ T5816] ? __pfx_sysfs_create_dir_ns+0x10/0x10 [ 447.672733][ T5816] ? find_held_lock+0x2b/0x80 [ 447.672759][ T5816] ? do_raw_spin_unlock+0x172/0x230 [ 447.672780][ T5816] kobject_add_internal+0x2c4/0x9b0 [ 447.672810][ T5816] kobject_add+0x16e/0x240 [ 447.672833][ T5816] ? __pfx_kobject_add+0x10/0x10 [ 447.672859][ T5816] ? do_raw_spin_unlock+0x172/0x230 [ 447.672878][ T5816] ? kobject_put+0xab/0x5a0 [ 447.672909][ T5816] device_add+0x288/0x1a70 [ 447.672940][ T5816] ? __pfx_dev_set_name+0x10/0x10 [ 447.672965][ T5816] ? __pfx_device_add+0x10/0x10 [ 447.672984][ T5816] ? mgmt_send_event_skb+0x2fb/0x460 [ 447.673010][ T5816] hci_conn_add_sysfs+0x17e/0x230 [ 447.673036][ T5816] le_conn_complete_evt+0x1075/0x1d70 [ 447.673063][ T5816] ? rcu_is_watching+0x12/0xc0 [ 447.673083][ T5816] ? __pfx_le_conn_complete_evt+0x10/0x10 [ 447.673105][ T5816] ? hci_event_packet+0x43c/0x1190 [ 447.673134][ T5816] hci_le_conn_complete_evt+0x23c/0x370 [ 447.673164][ T5816] hci_le_meta_evt+0x2f3/0x5e0 [ 447.673188][ T5816] ? __pfx_hci_le_conn_complete_evt+0x10/0x10 [ 447.673216][ T5816] hci_event_packet+0x669/0x1190 [ 447.673240][ T5816] ? __pfx_hci_le_meta_evt+0x10/0x10 [ 447.673267][ T5816] ? __pfx_hci_event_packet+0x10/0x10 [ 447.673294][ T5816] ? kcov_remote_start+0x3c9/0x6d0 [ 447.673310][ T5816] ? lockdep_hardirqs_on+0x7c/0x110 [ 447.673337][ T5816] hci_rx_work+0x2c5/0x16b0 [ 447.673364][ T5816] ? rcu_is_watching+0x12/0xc0 [ 447.673387][ T5816] process_one_work+0x9cc/0x1b70 [ 447.673417][ T5816] ? __pfx_process_one_work+0x10/0x10 [ 447.673443][ T5816] ? assign_work+0x1a0/0x250 [ 447.673462][ T5816] worker_thread+0x6c8/0xf10 [ 447.673492][ T5816] ? __pfx_worker_thread+0x10/0x10 [ 447.673511][ T5816] kthread+0x3c2/0x780 [ 447.673528][ T5816] ? __pfx_kthread+0x10/0x10 [ 447.673541][ T5816] ? __pfx_kthread+0x10/0x10 [ 447.673556][ T5816] ? __pfx_kthread+0x10/0x10 [ 447.673570][ T5816] ? __pfx_kthread+0x10/0x10 [ 447.673585][ T5816] ? rcu_is_watching+0x12/0xc0 [ 447.673605][ T5816] ? __pfx_kthread+0x10/0x10 [ 447.673619][ T5816] ret_from_fork+0x45/0x80 [ 447.673634][ T5816] ? __pfx_kthread+0x10/0x10 [ 447.673659][ T5816] ret_from_fork_asm+0x1a/0x30 [ 447.673699][ T5816] [ 447.985985][T10090] FAULT_INJECTION: forcing a failure. [ 447.985985][T10090] name failslab, interval 1, probability 0, space 0, times 0 [ 447.998729][T10090] CPU: 1 UID: 0 PID: 10090 Comm: syz.0.1086 Not tainted 6.15.0-rc5-syzkaller-00032-g0d8d44db295c #0 PREEMPT(full) [ 447.998753][T10090] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/29/2025 [ 447.998763][T10090] Call Trace: [ 447.998769][T10090] [ 447.998776][T10090] dump_stack_lvl+0x16c/0x1f0 [ 447.998801][T10090] should_fail_ex+0x512/0x640 [ 447.998826][T10090] should_failslab+0xc2/0x120 [ 447.998843][T10090] kmem_cache_alloc_node_noprof+0x71/0x3b0 [ 447.998869][T10090] ? __alloc_skb+0x2b2/0x380 [ 447.998889][T10090] __alloc_skb+0x2b2/0x380 [ 447.998903][T10090] ? __pfx___alloc_skb+0x10/0x10 [ 447.998918][T10090] ? __pfx_tomoyo_socket_sendmsg_permission+0x10/0x10 [ 447.998957][T10090] pfkey_sendmsg+0x16e/0x850 [ 447.998987][T10090] ____sys_sendmsg+0xa95/0xc70 [ 447.999010][T10090] ? copy_msghdr_from_user+0x10a/0x160 [ 447.999027][T10090] ? __pfx_____sys_sendmsg+0x10/0x10 [ 447.999052][T10090] ? lock_acquire+0x179/0x350 [ 447.999075][T10090] ? find_held_lock+0x2b/0x80 [ 447.999097][T10090] ___sys_sendmsg+0x134/0x1d0 [ 447.999115][T10090] ? __pfx____sys_sendmsg+0x10/0x10 [ 447.999161][T10090] __sys_sendmsg+0x16d/0x220 [ 447.999178][T10090] ? __pfx___sys_sendmsg+0x10/0x10 [ 447.999193][T10090] ? rcu_is_watching+0x12/0xc0 [ 447.999221][T10090] ? trace_irq_enable.constprop.0+0x2f/0x120 [ 447.999242][T10090] do_syscall_64+0xcd/0x260 [ 447.999265][T10090] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 447.999282][T10090] RIP: 0033:0x7f6589b8e969 [ 447.999295][T10090] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 447.999311][T10090] RSP: 002b:00007f658a981038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 447.999327][T10090] RAX: ffffffffffffffda RBX: 00007f6589db6160 RCX: 00007f6589b8e969 [ 447.999337][T10090] RDX: 0000000000000000 RSI: 0000200000000100 RDI: 0000000000000007 [ 447.999347][T10090] RBP: 00007f658a981090 R08: 0000000000000000 R09: 0000000000000000 [ 447.999356][T10090] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 447.999366][T10090] R13: 0000000000000000 R14: 00007f6589db6160 R15: 00007ffc3abb4c68 [ 447.999388][T10090] [ 448.139793][ T5816] kobject: kobject_add_internal failed for hci5:201 with -EEXIST, don't try to register things with the same name in the same directory. [ 448.243210][ T5816] Bluetooth: hci5: failed to register connection device [ 450.313796][ T5816] Bluetooth: hci5: command tx timeout [ 450.653110][ T30] audit: type=1400 audit(1746634042.565:1332): avc: denied { read } for pid=10109 comm="syz.3.1092" name="binder0" dev="binder" ino=10 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 450.809418][ T30] audit: type=1400 audit(1746634042.565:1333): avc: denied { open } for pid=10109 comm="syz.3.1092" path="/dev/binderfs/binder0" dev="binder" ino=10 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 451.089463][ T30] audit: type=1400 audit(1746634042.585:1334): avc: denied { nlmsg_write } for pid=10109 comm="syz.3.1092" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_xfrm_socket permissive=1 [ 451.314228][ T30] audit: type=1400 audit(1746634042.595:1335): avc: denied { ioctl } for pid=10109 comm="syz.3.1092" path="/dev/binderfs/binder0" dev="binder" ino=10 ioctlcmd=0x620d scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 451.341558][ T30] audit: type=1400 audit(1746634042.595:1336): avc: denied { set_context_mgr } for pid=10109 comm="syz.3.1092" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=binder permissive=1 [ 451.485155][ T5912] usb 2-1: new high-speed USB device number 26 using dummy_hcd [ 452.008056][T10134] syzkaller0: entered promiscuous mode [ 452.013638][T10134] syzkaller0: entered allmulticast mode [ 452.073270][ T5912] usb 2-1: Using ep0 maxpacket: 32 [ 452.083618][ T5912] usb 2-1: config 5 has no interfaces? [ 452.099338][ T5912] usb 2-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 452.118736][ T5912] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 452.141956][ T5912] usb 2-1: Product: syz [ 452.146247][ T5912] usb 2-1: Manufacturer: syz [ 452.151936][ T5912] usb 2-1: SerialNumber: syz [ 453.099236][ T30] audit: type=1400 audit(1746634045.045:1337): avc: denied { write } for pid=10157 comm="syz.5.1104" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=pppox_socket permissive=1 [ 453.143339][ T5862] usb 5-1: new high-speed USB device number 21 using dummy_hcd [ 453.396756][ T5862] usb 5-1: New USB device found, idVendor=2c42, idProduct=1709, bcdDevice=ca.b7 [ 453.406849][ T5862] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 453.463873][ T5862] usb 5-1: Product: syz [ 453.468576][ T5862] usb 5-1: Manufacturer: syz [ 453.473456][ T5862] usb 5-1: SerialNumber: syz [ 453.543705][ T5862] usb 5-1: config 0 descriptor?? [ 453.693273][ T5912] usb 2-1: USB disconnect, device number 26 [ 454.676926][ T5862] usb 5-1: f81604_write: reg: 105 data: 65 failed: -EPROTO [ 454.714752][ T5862] f81604 5-1:0.0: Setting termination of CH#1 failed: -EPROTO [ 454.764272][ T5862] f81604 5-1:0.0: probe with driver f81604 failed with error -71 [ 454.787142][ T5862] usb 5-1: USB disconnect, device number 21 [ 456.812409][T10205] FAULT_INJECTION: forcing a failure. [ 456.812409][T10205] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 456.825574][T10205] CPU: 0 UID: 0 PID: 10205 Comm: syz.3.1116 Not tainted 6.15.0-rc5-syzkaller-00032-g0d8d44db295c #0 PREEMPT(full) [ 456.825598][T10205] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/29/2025 [ 456.825607][T10205] Call Trace: [ 456.825613][T10205] [ 456.825619][T10205] dump_stack_lvl+0x16c/0x1f0 [ 456.825645][T10205] should_fail_ex+0x512/0x640 [ 456.825669][T10205] _copy_from_iter+0x2a4/0x15b0 [ 456.825693][T10205] ? __build_skb_around+0x278/0x3b0 [ 456.825718][T10205] ? __pfx__copy_from_iter+0x10/0x10 [ 456.825740][T10205] ? __pfx___alloc_skb+0x10/0x10 [ 456.825754][T10205] ? __pfx_tomoyo_socket_sendmsg_permission+0x10/0x10 [ 456.825788][T10205] pfkey_sendmsg+0x1da/0x850 [ 456.825817][T10205] ____sys_sendmsg+0xa95/0xc70 [ 456.825839][T10205] ? copy_msghdr_from_user+0x10a/0x160 [ 456.825855][T10205] ? __pfx_____sys_sendmsg+0x10/0x10 [ 456.825880][T10205] ? __pfx___schedule+0x10/0x10 [ 456.825904][T10205] ___sys_sendmsg+0x134/0x1d0 [ 456.825922][T10205] ? __pfx____sys_sendmsg+0x10/0x10 [ 456.825968][T10205] __sys_sendmsg+0x16d/0x220 [ 456.825984][T10205] ? __pfx___sys_sendmsg+0x10/0x10 [ 456.826017][T10205] do_syscall_64+0xcd/0x260 [ 456.826039][T10205] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 456.826056][T10205] RIP: 0033:0x7f7763b8e969 [ 456.826069][T10205] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 456.826085][T10205] RSP: 002b:00007f77619b4038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 456.826100][T10205] RAX: ffffffffffffffda RBX: 00007f7763db6160 RCX: 00007f7763b8e969 [ 456.826111][T10205] RDX: 0000000000000000 RSI: 0000200000000100 RDI: 0000000000000007 [ 456.826120][T10205] RBP: 00007f77619b4090 R08: 0000000000000000 R09: 0000000000000000 [ 456.826130][T10205] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 456.826140][T10205] R13: 0000000000000000 R14: 00007f7763db6160 R15: 00007ffdc95bb1f8 [ 456.826161][T10205] [ 457.083298][ T5891] usb 6-1: new high-speed USB device number 3 using dummy_hcd [ 457.510481][T10212] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1117'. [ 457.519498][ T5891] usb 6-1: Using ep0 maxpacket: 32 [ 457.520941][ T5891] usb 6-1: config 5 has no interfaces? [ 457.538038][ T5891] usb 6-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 457.661432][ T5891] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 457.690416][ T5891] usb 6-1: Product: syz [ 457.704061][ T5891] usb 6-1: Manufacturer: syz [ 458.130534][ T5891] usb 6-1: SerialNumber: syz [ 458.786495][ T30] audit: type=1400 audit(1746634050.735:1338): avc: denied { name_connect } for pid=10226 comm="syz.1.1122" dest=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:reserved_port_t tclass=sctp_socket permissive=1 [ 458.943069][ T5912] usb 5-1: new high-speed USB device number 22 using dummy_hcd [ 459.125300][ T5912] usb 5-1: New USB device found, idVendor=0bed, idProduct=1100, bcdDevice=ec.c3 [ 459.155939][ T5912] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 459.180153][ T5912] usb 5-1: config 0 descriptor?? [ 459.204841][ T5912] cp210x 5-1:0.0: cp210x converter detected [ 459.435806][ T5891] usb 6-1: USB disconnect, device number 3 [ 459.957568][ T30] audit: type=1400 audit(1746634051.905:1339): avc: denied { ioctl } for pid=10234 comm="syz.0.1125" path="socket:[23156]" dev="sockfs" ino=23156 ioctlcmd=0x9411 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 460.026736][ T5912] usb 5-1: cp210x converter now attached to ttyUSB0 [ 460.049910][ T30] audit: type=1400 audit(1746634051.905:1340): avc: denied { setopt } for pid=10234 comm="syz.0.1125" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rds_socket permissive=1 [ 460.218951][ T5912] usb 5-1: USB disconnect, device number 22 [ 460.247044][ T5912] cp210x ttyUSB0: cp210x converter now disconnected from ttyUSB0 [ 460.268401][ T5912] cp210x 5-1:0.0: device disconnected [ 460.390602][T10248] FAULT_INJECTION: forcing a failure. [ 460.390602][T10248] name failslab, interval 1, probability 0, space 0, times 0 [ 460.403440][T10248] CPU: 0 UID: 0 PID: 10248 Comm: syz.0.1127 Not tainted 6.15.0-rc5-syzkaller-00032-g0d8d44db295c #0 PREEMPT(full) [ 460.403463][T10248] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/29/2025 [ 460.403473][T10248] Call Trace: [ 460.403479][T10248] [ 460.403485][T10248] dump_stack_lvl+0x16c/0x1f0 [ 460.403512][T10248] should_fail_ex+0x512/0x640 [ 460.403532][T10248] ? kmem_cache_alloc_noprof+0x5a/0x3b0 [ 460.403561][T10248] should_failslab+0xc2/0x120 [ 460.403578][T10248] kmem_cache_alloc_noprof+0x6d/0x3b0 [ 460.403603][T10248] ? skb_clone+0x154/0x3f0 [ 460.403619][T10248] ? skb_clone+0x190/0x3f0 [ 460.403639][T10248] skb_clone+0x190/0x3f0 [ 460.403657][T10248] pfkey_process+0xc6/0x840 [ 460.403681][T10248] ? __pfx___might_resched+0x10/0x10 [ 460.403705][T10248] ? __pfx_pfkey_process+0x10/0x10 [ 460.403728][T10248] ? trace_contention_end+0xdd/0x130 [ 460.403779][T10248] pfkey_sendmsg+0x435/0x850 [ 460.403808][T10248] ____sys_sendmsg+0xa95/0xc70 [ 460.403829][T10248] ? copy_msghdr_from_user+0x10a/0x160 [ 460.403845][T10248] ? __pfx_____sys_sendmsg+0x10/0x10 [ 460.403873][T10248] ? plist_check_prev_next+0x12a/0x1a0 [ 460.403893][T10248] ___sys_sendmsg+0x134/0x1d0 [ 460.403911][T10248] ? __pfx____sys_sendmsg+0x10/0x10 [ 460.403958][T10248] __sys_sendmsg+0x16d/0x220 [ 460.403975][T10248] ? __pfx___sys_sendmsg+0x10/0x10 [ 460.404008][T10248] do_syscall_64+0xcd/0x260 [ 460.404030][T10248] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 460.404047][T10248] RIP: 0033:0x7f6589b8e969 [ 460.404061][T10248] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 460.404076][T10248] RSP: 002b:00007f658a981038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 460.404092][T10248] RAX: ffffffffffffffda RBX: 00007f6589db6160 RCX: 00007f6589b8e969 [ 460.404103][T10248] RDX: 0000000000000000 RSI: 0000200000000100 RDI: 0000000000000007 [ 460.404113][T10248] RBP: 00007f658a981090 R08: 0000000000000000 R09: 0000000000000000 [ 460.404122][T10248] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 460.404132][T10248] R13: 0000000000000000 R14: 00007f6589db6160 R15: 00007ffc3abb4c68 [ 460.404154][T10248] [ 460.739406][T10239] qrtr: Invalid version 254 [ 460.777819][ T30] audit: type=1400 audit(1746634052.585:1341): avc: denied { write } for pid=10246 comm="syz.3.1128" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=can_socket permissive=1 [ 462.183284][ T5891] usb 2-1: new high-speed USB device number 27 using dummy_hcd [ 462.288216][T10266] netlink: 4 bytes leftover after parsing attributes in process `syz.4.1133'. [ 462.465967][ T5891] usb 2-1: config 1 has too many interfaces: 66, using maximum allowed: 32 [ 462.506034][ T5891] usb 2-1: config 1 has an invalid descriptor of length 54, skipping remainder of the config [ 462.517625][ T5891] usb 2-1: config 1 has 1 interface, different from the descriptor's value: 66 [ 462.526909][ T5891] usb 2-1: config 1 interface 0 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 462.542047][ T5891] usb 2-1: New USB device found, idVendor=7d25, idProduct=a415, bcdDevice= 0.40 [ 462.551187][ T5891] usb 2-1: New USB device strings: Mfr=1, Product=4, SerialNumber=0 [ 462.559806][ T5891] usb 2-1: Product: syz [ 462.589855][ T5891] usb 2-1: Manufacturer: syz [ 462.660189][ T5891] cdc_wdm 2-1:1.0: skipping garbage [ 462.674687][ T5891] cdc_wdm 2-1:1.0: probe with driver cdc_wdm failed with error -22 [ 462.878602][T10254] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 462.889426][T10254] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 463.234867][ T972] usb 2-1: USB disconnect, device number 27 [ 463.820092][ T5816] Bluetooth: hci5: Ignoring HCI_Connection_Complete for existing connection [ 465.087081][ T5816] Bluetooth: hci0: Ignoring HCI_Connection_Complete for existing connection [ 465.873668][T10303] FAULT_INJECTION: forcing a failure. [ 465.873668][T10303] name failslab, interval 1, probability 0, space 0, times 0 [ 465.886636][T10303] CPU: 1 UID: 0 PID: 10303 Comm: syz.5.1143 Not tainted 6.15.0-rc5-syzkaller-00032-g0d8d44db295c #0 PREEMPT(full) [ 465.886661][T10303] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/29/2025 [ 465.886671][T10303] Call Trace: [ 465.886676][T10303] [ 465.886683][T10303] dump_stack_lvl+0x16c/0x1f0 [ 465.886709][T10303] should_fail_ex+0x512/0x640 [ 465.886734][T10303] should_failslab+0xc2/0x120 [ 465.886751][T10303] kmem_cache_alloc_noprof+0x6d/0x3b0 [ 465.886779][T10303] ? xfrm_state_alloc+0x23/0x5c0 [ 465.886799][T10303] xfrm_state_alloc+0x23/0x5c0 [ 465.886814][T10303] pfkey_add+0x5fe/0x2ec0 [ 465.886846][T10303] ? __pfx_pfkey_add+0x10/0x10 [ 465.886868][T10303] ? kfree_skbmem+0x1a4/0x1f0 [ 465.886891][T10303] ? sk_skb_reason_drop+0x136/0x1a0 [ 465.886911][T10303] ? pfkey_broadcast+0x2af/0x460 [ 465.886936][T10303] ? __pfx_pfkey_add+0x10/0x10 [ 465.886959][T10303] pfkey_process+0x6d9/0x840 [ 465.886986][T10303] ? __pfx_pfkey_process+0x10/0x10 [ 465.887009][T10303] ? trace_contention_end+0xdd/0x130 [ 465.887061][T10303] pfkey_sendmsg+0x435/0x850 [ 465.887096][T10303] ____sys_sendmsg+0xa95/0xc70 [ 465.887118][T10303] ? copy_msghdr_from_user+0x10a/0x160 [ 465.887135][T10303] ? __pfx_____sys_sendmsg+0x10/0x10 [ 465.887162][T10303] ? __pfx___pv_queued_spin_lock_slowpath+0x10/0x10 [ 465.887188][T10303] ___sys_sendmsg+0x134/0x1d0 [ 465.887206][T10303] ? __pfx____sys_sendmsg+0x10/0x10 [ 465.887254][T10303] __sys_sendmsg+0x16d/0x220 [ 465.887271][T10303] ? __pfx___sys_sendmsg+0x10/0x10 [ 465.887304][T10303] do_syscall_64+0xcd/0x260 [ 465.887327][T10303] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 465.887343][T10303] RIP: 0033:0x7f17add8e969 [ 465.887357][T10303] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 465.887373][T10303] RSP: 002b:00007f17aec63038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 465.887389][T10303] RAX: ffffffffffffffda RBX: 00007f17adfb6160 RCX: 00007f17add8e969 [ 465.887400][T10303] RDX: 0000000000000000 RSI: 0000200000000100 RDI: 0000000000000007 [ 465.887409][T10303] RBP: 00007f17aec63090 R08: 0000000000000000 R09: 0000000000000000 [ 465.887419][T10303] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 465.887428][T10303] R13: 0000000000000000 R14: 00007f17adfb6160 R15: 00007ffe05eea598 [ 465.887450][T10303] [ 467.092332][T10314] lo speed is unknown, defaulting to 1000 [ 468.773029][ T5891] usb 1-1: new high-speed USB device number 28 using dummy_hcd [ 469.313695][ T5891] usb 1-1: Using ep0 maxpacket: 32 [ 469.325241][ T5891] usb 1-1: New USB device found, idVendor=0ac8, idProduct=0321, bcdDevice=6f.be [ 469.372962][ T5891] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 469.424632][ T5891] usb 1-1: config 0 descriptor?? [ 469.439586][ T30] audit: type=1400 audit(1746634061.385:1342): avc: denied { append } for pid=10340 comm="syz.5.1152" name="kvm" dev="devtmpfs" ino=84 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:kvm_device_t tclass=chr_file permissive=1 [ 469.507331][ T5891] gspca_main: vc032x-2.14.0 probing 0ac8:0321 [ 470.269041][ T5912] usb 5-1: new high-speed USB device number 23 using dummy_hcd [ 470.477698][T10352] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1156'. [ 470.783122][ T5912] usb 5-1: Using ep0 maxpacket: 32 [ 470.790061][ T5912] usb 5-1: config 5 has no interfaces? [ 470.797759][ T5912] usb 5-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 470.813069][ T5912] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 470.823048][ T5912] usb 5-1: Product: syz [ 470.827220][ T5912] usb 5-1: Manufacturer: syz [ 470.842032][ T5912] usb 5-1: SerialNumber: syz [ 471.323217][ T5860] usb 4-1: new high-speed USB device number 23 using dummy_hcd [ 471.417176][ T5891] gspca_vc032x: reg_w err -110 [ 471.421985][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.429323][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.435498][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.440862][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.446238][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.451560][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.458151][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.463507][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.468832][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.474492][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.479822][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.485235][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.490670][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.534669][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.544372][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.549771][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.579292][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.584821][ T5891] gspca_vc032x: I2c Bus Busy Wait 00 [ 471.590320][ T5891] gspca_vc032x: Unknown sensor... [ 471.596804][ T5891] vc032x 1-1:0.0: probe with driver vc032x failed with error -22 [ 471.712982][ T5860] usb 4-1: Using ep0 maxpacket: 32 [ 471.721603][ T5860] usb 4-1: config 5 has no interfaces? [ 471.757998][ T5860] usb 4-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 471.767370][ T5860] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 471.775499][ T5860] usb 4-1: Product: syz [ 471.779848][ T5860] usb 4-1: Manufacturer: syz [ 471.784897][ T5860] usb 4-1: SerialNumber: syz [ 471.846933][T10367] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 471.876462][ T972] lo speed is unknown, defaulting to 1000 [ 471.883768][ T972] syz2: Port: 1 Link DOWN [ 472.486064][ T5891] usb 1-1: USB disconnect, device number 28 [ 472.613123][ T972] usb 2-1: new high-speed USB device number 28 using dummy_hcd [ 472.625902][ T5912] usb 5-1: USB disconnect, device number 23 [ 472.879474][ T972] usb 2-1: New USB device found, idVendor=0471, idProduct=0329, bcdDevice=db.da [ 472.896343][ T972] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 473.017958][ T972] usb 2-1: config 0 descriptor?? [ 473.037826][ T972] pwc: Philips SPC 900NC USB webcam detected. [ 473.204465][T10382] vivid-004: disconnect [ 473.216712][T10378] ip6tnl1: entered promiscuous mode [ 473.225078][T10377] vivid-004: reconnect [ 473.240317][T10369] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 473.266138][T10369] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 473.558649][ T972] pwc: send_video_command error -71 [ 473.576434][ T972] pwc: Failed to set video mode VGA@30 fps; return code = -71 [ 473.615393][ T30] audit: type=1400 audit(1746634065.565:1343): avc: denied { create } for pid=10386 comm="syz.5.1166" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=x25_socket permissive=1 [ 473.778065][ T972] Philips webcam 2-1:0.0: probe with driver Philips webcam failed with error -71 [ 473.794704][ T5860] usb 4-1: USB disconnect, device number 23 [ 473.816537][ T972] usb 2-1: USB disconnect, device number 28 [ 474.750149][ T30] audit: type=1400 audit(1746634066.255:1344): avc: denied { create } for pid=10393 comm="syz.3.1168" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=mctp_socket permissive=1 [ 474.976796][ T30] audit: type=1400 audit(1746634066.265:1345): avc: denied { ioctl } for pid=10393 comm="syz.3.1168" path="socket:[23652]" dev="sockfs" ino=23652 ioctlcmd=0x89e2 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=mctp_socket permissive=1 [ 475.165088][ T30] audit: type=1400 audit(1746634066.275:1346): avc: denied { listen } for pid=10393 comm="syz.3.1168" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=vsock_socket permissive=1 [ 475.385225][T10402] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1171'. [ 476.204743][ T5860] usb 2-1: new high-speed USB device number 29 using dummy_hcd [ 476.657444][ T5860] usb 2-1: Using ep0 maxpacket: 32 [ 476.726843][ T5860] usb 2-1: config 5 has no interfaces? [ 476.734642][ T5860] usb 2-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 477.805255][ T5860] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 477.936151][ T30] audit: type=1400 audit(1746634069.685:1347): avc: denied { ioctl } for pid=10422 comm="syz.4.1176" path="socket:[23767]" dev="sockfs" ino=23767 ioctlcmd=0x8933 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=sctp_socket permissive=1 [ 477.964649][ T5824] Bluetooth: hci1: unexpected cc 0x2007 length: 100 > 2 [ 477.972595][ T5824] Bluetooth: hci1: unexpected event for opcode 0x2007 [ 478.748879][T10413] syz.5.1173 (10413): drop_caches: 2 [ 478.960090][ T5860] usb 2-1: Product: syz [ 478.997272][ T5860] usb 2-1: Manufacturer: syz [ 479.001948][ T5860] usb 2-1: SerialNumber: syz [ 479.528702][T10413] syz.5.1173 (10413): drop_caches: 2 [ 479.537389][ T5860] usb 2-1: can't set config #5, error -71 [ 479.546126][ T5860] usb 2-1: USB disconnect, device number 29 [ 481.994562][ T5824] Bluetooth: hci1: Controller not accepting commands anymore: ncmd = 0 [ 482.004521][ T5824] Bluetooth: hci1: Injecting HCI hardware error event [ 482.017313][ T5824] Bluetooth: hci1: hardware error 0x00 [ 482.241918][T10459] Device name cannot be null; rc = [-22] [ 484.458860][ T5824] Bluetooth: hci1: Opcode 0x0c03 failed: -110 [ 485.137379][ T5891] usb 2-1: new high-speed USB device number 30 using dummy_hcd [ 485.481937][ T5891] usb 2-1: Using ep0 maxpacket: 32 [ 485.527395][ T5891] usb 2-1: config 5 has no interfaces? [ 485.622737][ T5891] usb 2-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 485.747254][ T5891] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 485.849687][ T972] usb 6-1: new high-speed USB device number 4 using dummy_hcd [ 485.937128][ T5891] usb 2-1: Product: syz [ 485.976656][ T5891] usb 2-1: Manufacturer: syz [ 485.981382][ T5891] usb 2-1: SerialNumber: syz [ 486.963134][T10501] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 487.758004][ T5891] usb 2-1: USB disconnect, device number 30 [ 487.912476][T10509] netlink: 32 bytes leftover after parsing attributes in process `syz.3.1202'. [ 487.962352][T10514] siw: device registration error -23 [ 490.888500][ T5824] Bluetooth: hci3: Ignoring HCI_Connection_Complete for existing connection [ 490.977439][T10545] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 492.382070][ T30] audit: type=1400 audit(1746634084.325:1348): avc: denied { connect } for pid=10552 comm="syz.0.1215" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rxrpc_socket permissive=1 [ 492.685564][ T30] audit: type=1400 audit(1746634084.635:1349): avc: denied { sqpoll } for pid=10552 comm="syz.0.1215" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=io_uring permissive=1 [ 492.750469][T10564] bridge0: port 2(bridge_slave_1) entered disabled state [ 492.759010][T10564] bridge0: port 1(bridge_slave_0) entered disabled state [ 492.803065][ T5891] usb 4-1: new high-speed USB device number 24 using dummy_hcd [ 492.978322][T10564] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 492.990122][T10564] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 493.046586][T10564] netdevsim netdevsim1 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 493.055639][T10564] netdevsim netdevsim1 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 493.065011][T10564] netdevsim netdevsim1 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 493.073996][T10564] netdevsim netdevsim1 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 493.107504][ T5891] usb 4-1: Using ep0 maxpacket: 32 [ 493.189477][ T5891] usb 4-1: config 5 has no interfaces? [ 493.337739][ T5891] usb 4-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 493.467620][ T5891] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 493.494543][T10579] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 493.506592][ T5891] usb 4-1: Product: syz [ 493.593507][ T5891] usb 4-1: Manufacturer: syz [ 493.598216][ T5891] usb 4-1: SerialNumber: syz [ 493.799992][ T30] audit: type=1400 audit(1746634085.745:1350): avc: denied { listen } for pid=10583 comm="syz.0.1221" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=x25_socket permissive=1 [ 493.829951][T10585] IPVS: rr: UDP 224.0.0.2:0 - no destination available [ 493.850306][ T30] audit: type=1400 audit(1746634085.775:1351): avc: denied { connect } for pid=10583 comm="syz.0.1221" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=x25_socket permissive=1 [ 494.283034][ T972] usb 1-1: new high-speed USB device number 29 using dummy_hcd [ 494.612821][ T972] usb 1-1: unable to get BOS descriptor or descriptor too short [ 494.727349][ T972] usb 1-1: config 6 has an invalid interface number: 200 but max is 0 [ 494.743161][ T972] usb 1-1: config 6 has no interface number 0 [ 494.765105][ T972] usb 1-1: config 6 interface 200 has no altsetting 0 [ 494.790880][ T972] usb 1-1: New USB device found, idVendor=05d8, idProduct=810c, bcdDevice=18.5f [ 494.809030][ T972] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 494.879452][ T5891] usb 4-1: USB disconnect, device number 24 [ 494.885555][ T972] usb 1-1: Product: syz [ 494.913029][ T972] usb 1-1: Manufacturer: syz [ 494.955256][ T972] usb 1-1: SerialNumber: syz [ 496.292209][ T972] dvb-usb: found a 'Artec T14 - USB2.0 DVB-T' in warm state. [ 496.512685][ T30] audit: type=1400 audit(1746634088.435:1352): avc: denied { write } for pid=10589 comm="syz.0.1223" path="socket:[24925]" dev="sockfs" ino=24925 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 496.537136][T10614] Bluetooth: MGMT ver 1.23 [ 496.588780][ T972] dvb-usb: will pass the complete MPEG2 transport stream to the software demuxer. [ 496.599890][ T972] dvbdev: DVB: registering new adapter (Artec T14 - USB2.0 DVB-T) [ 496.609211][ T972] usb 1-1: media controller created [ 496.843219][ T972] dvbdev: dvb_create_media_entity: media entity 'dvb-demux' registered. [ 496.917705][ T972] dvb-usb: bulk message failed: -71 (6/0) [ 496.944535][ T972] dvb-usb: bulk message failed: -71 (6/0) [ 496.950519][ T972] dvb-usb: no frontend was attached by 'Artec T14 - USB2.0 DVB-T' [ 496.988506][ T972] input: IR-receiver inside an USB DVB receiver as /devices/platform/dummy_hcd.0/usb1/1-1/input/input12 [ 497.103786][ T972] dvb-usb: schedule remote query interval to 150 msecs. [ 497.121184][ T972] dvb-usb: Artec T14 - USB2.0 DVB-T successfully initialized and connected. [ 497.305903][ T5860] dvb-usb: bulk message failed: -71 (1/0) [ 497.333998][ T5860] dvb-usb: error while querying for an remote control event. [ 497.524100][ T5860] dvb-usb: bulk message failed: -71 (1/0) [ 497.543495][ T972] usb 1-1: USB disconnect, device number 29 [ 497.564052][ T5860] dvb-usb: error while querying for an remote control event. [ 497.632039][ T30] audit: type=1400 audit(1746634089.575:1353): avc: denied { read } for pid=5165 comm="syslogd" name="log" dev="sda1" ino=1915 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:var_t tclass=lnk_file permissive=1 [ 497.721141][ T30] audit: type=1400 audit(1746634089.575:1354): avc: denied { search } for pid=5165 comm="syslogd" name="/" dev="tmpfs" ino=1 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1 [ 497.772293][ T30] audit: type=1400 audit(1746634089.575:1355): avc: denied { append } for pid=5165 comm="syslogd" name="messages" dev="tmpfs" ino=7 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1 [ 497.798197][ T30] audit: type=1400 audit(1746634089.575:1356): avc: denied { open } for pid=5165 comm="syslogd" path="/tmp/messages" dev="tmpfs" ino=7 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1 [ 498.051169][ T972] dvb-usb: Artec T14 - USB2.0 DVB-T successfully deinitialized and disconnected. [ 498.066435][ T30] audit: type=1400 audit(1746634089.575:1357): avc: denied { getattr } for pid=5165 comm="syslogd" path="/tmp/messages" dev="tmpfs" ino=7 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1 [ 498.093004][ T5816] Bluetooth: hci5: command 0x0406 tx timeout [ 498.113181][ T73] usb 2-1: new high-speed USB device number 31 using dummy_hcd [ 498.273296][ T73] usb 2-1: Using ep0 maxpacket: 32 [ 498.296157][ T73] usb 2-1: config 0 has an invalid interface number: 219 but max is 0 [ 498.405372][ T73] usb 2-1: config 0 has no interface number 0 [ 498.413260][ T73] usb 2-1: config 0 interface 219 altsetting 0 has an endpoint descriptor with address 0xDB, changing to 0x8B [ 498.425821][ T30] audit: type=1400 audit(1746634090.365:1358): avc: denied { setopt } for pid=10628 comm="syz.5.1234" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rxrpc_socket permissive=1 [ 498.492980][ T73] usb 2-1: config 0 interface 219 altsetting 0 endpoint 0x8B has invalid maxpacket 28739, setting to 1024 [ 498.713056][ T73] usb 2-1: config 0 interface 219 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 1024 [ 498.723411][ T73] usb 2-1: config 0 interface 219 altsetting 0 endpoint 0xB has invalid maxpacket 32802, setting to 1024 [ 498.734671][ T73] usb 2-1: config 0 interface 219 altsetting 0 bulk endpoint 0xB has invalid maxpacket 1024 [ 499.337616][ T73] usb 2-1: New USB device found, idVendor=108c, idProduct=0169, bcdDevice=75.b9 [ 499.375681][ T73] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 499.390893][ T73] usb 2-1: Product: syz [ 499.395178][ T5862] usb 6-1: new high-speed USB device number 5 using dummy_hcd [ 499.443369][ T73] usb 2-1: Manufacturer: syz [ 499.589971][ T73] usb 2-1: SerialNumber: syz [ 499.969451][ T73] usb 2-1: config 0 descriptor?? [ 499.979346][T10625] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 499.992665][T10625] raw-gadget.0 gadget.1: fail, usb_ep_enable returned -22 [ 499.993127][ T5862] usb 6-1: Using ep0 maxpacket: 8 [ 500.612696][ T30] audit: type=1400 audit(1746634092.025:1359): avc: denied { create } for pid=10640 comm="syz.4.1237" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 500.658658][ T30] audit: type=1400 audit(1746634092.025:1360): avc: denied { bind } for pid=10640 comm="syz.4.1237" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 500.806600][ T30] audit: type=1400 audit(1746634092.035:1361): avc: denied { node_bind } for pid=10640 comm="syz.4.1237" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:node_t tclass=icmp_socket permissive=1 [ 500.948087][ T5862] usb 6-1: New USB device found, idVendor=13d8, idProduct=0001, bcdDevice=30.62 [ 500.977572][ T73] etas_es58x 2-1:0.219: Starting syz syz (Serial Number syz) [ 500.988459][ T5862] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 500.999911][ T73] etas_es58x 2-1:0.219: could not retrieve the product info string [ 501.025461][ T5862] usb 6-1: Product: syz [ 501.029705][ T5862] usb 6-1: Manufacturer: syz [ 501.056169][ T5862] usb 6-1: SerialNumber: syz [ 501.117128][ T1296] ieee802154 phy0 wpan0: encryption failed: -22 [ 501.127832][ T1296] ieee802154 phy1 wpan1: encryption failed: -22 [ 501.128417][ T5862] usb 6-1: config 0 descriptor?? [ 501.170435][ T73] usb 2-1: USB disconnect, device number 31 [ 501.200420][ T73] etas_es58x 2-1:0.219: Disconnecting syz syz [ 501.232681][T10650] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 501.333025][ T5863] usb 4-1: new high-speed USB device number 25 using dummy_hcd [ 502.825125][ T5863] usb 4-1: Using ep0 maxpacket: 16 [ 502.839587][ T5863] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 255, changing to 11 [ 502.860594][ T5863] usb 4-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid maxpacket 59391, setting to 1024 [ 503.610983][ T5863] usb 4-1: New USB device found, idVendor=04d8, idProduct=f002, bcdDevice= 0.00 [ 503.631546][ T5863] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 503.710822][ T5863] usb 4-1: config 0 descriptor?? [ 503.800181][ T5862] usb 6-1: can't set config #0, error -71 [ 503.806681][T10651] raw-gadget.0 gadget.3: fail, usb_ep_enable returned -22 [ 503.863374][ T5862] usb 6-1: USB disconnect, device number 5 [ 504.323318][ T30] audit: type=1400 audit(1746634096.265:1362): avc: denied { read } for pid=10670 comm="syz.5.1244" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=packet_socket permissive=1 [ 504.437910][ T5863] usbhid 4-1:0.0: can't add hid device: -71 [ 504.466902][ T5863] usbhid 4-1:0.0: probe with driver usbhid failed with error -71 [ 504.505488][ T5863] usb 4-1: USB disconnect, device number 25 [ 506.553640][T10704] lo speed is unknown, defaulting to 1000 [ 507.563127][T10711] netlink: 12 bytes leftover after parsing attributes in process `syz.3.1254'. [ 508.651122][ T5891] usb 6-1: new high-speed USB device number 6 using dummy_hcd [ 509.271082][T10730] siw: device registration error -23 [ 509.725701][ T5824] Bluetooth: hci5: Ignoring HCI_Connection_Complete for existing connection [ 510.208511][T10738] netlink: 28 bytes leftover after parsing attributes in process `syz.5.1261'. [ 510.243400][T10738] netlink: 'syz.5.1261': attribute type 7 has an invalid length. [ 510.277372][T10738] netlink: 'syz.5.1261': attribute type 8 has an invalid length. [ 510.337963][T10738] netlink: 4 bytes leftover after parsing attributes in process `syz.5.1261'. [ 510.483289][ T73] usb 2-1: new high-speed USB device number 32 using dummy_hcd [ 510.580167][T10752] 8021q: adding VLAN 0 to HW filter on device bond1 [ 510.634859][ T30] audit: type=1400 audit(1746634102.585:1363): avc: denied { create } for pid=10756 comm="syz.0.1268" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_nflog_socket permissive=1 [ 510.715043][ T73] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 511.181110][ T73] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 511.207986][ T73] usb 2-1: New USB device found, idVendor=0926, idProduct=3333, bcdDevice= 0.40 [ 511.241115][ T73] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 511.273800][ T73] usb 2-1: config 0 descriptor?? [ 511.720975][ T73] keytouch 0003:0926:3333.0001: fixing up Keytouch IEC report descriptor [ 511.774478][ T73] input: HID 0926:3333 as /devices/platform/dummy_hcd.1/usb2/2-1/2-1:0.0/0003:0926:3333.0001/input/input13 [ 512.496802][ T73] keytouch 0003:0926:3333.0001: input,hidraw0: USB HID v0.00 Keyboard [HID 0926:3333] on usb-dummy_hcd.1-1/input0 [ 512.536054][ T73] usb 2-1: USB disconnect, device number 32 [ 513.370853][ T5824] Bluetooth: hci0: Ignoring HCI_Connection_Complete for existing connection [ 513.399121][T10784] siw: device registration error -23 [ 514.013746][ T972] usb 2-1: new high-speed USB device number 33 using dummy_hcd [ 514.129908][T10792] siw: device registration error -23 [ 514.238647][ T972] usb 2-1: device descriptor read/64, error -71 [ 514.533282][ T972] usb 2-1: new high-speed USB device number 34 using dummy_hcd [ 514.734439][ T972] usb 2-1: device descriptor read/64, error -71 [ 515.190187][ T972] usb usb2-port1: attempt power cycle [ 515.861089][T10804] lo speed is unknown, defaulting to 1000 [ 515.933234][ T972] usb 2-1: new high-speed USB device number 35 using dummy_hcd [ 515.973874][ T972] usb 2-1: device descriptor read/8, error -71 [ 516.670232][ T972] usb 2-1: new high-speed USB device number 36 using dummy_hcd [ 516.695220][ T972] usb 2-1: device descriptor read/8, error -71 [ 516.735323][ T5860] usb 4-1: new high-speed USB device number 26 using dummy_hcd [ 516.813456][ T972] usb usb2-port1: unable to enumerate USB device [ 516.876535][ T5860] usb 4-1: device descriptor read/64, error -71 [ 517.628697][ T5860] usb 4-1: new high-speed USB device number 27 using dummy_hcd [ 517.656462][T10829] netlink: 'syz.1.1287': attribute type 2 has an invalid length. [ 517.667542][T10829] 9p: Unknown Cache mode or invalid value f [ 517.803397][ T5860] usb 4-1: device descriptor read/64, error -71 [ 517.933716][ T5860] usb usb4-port1: attempt power cycle [ 518.593161][ T5860] usb 4-1: new high-speed USB device number 28 using dummy_hcd [ 518.624090][ T5860] usb 4-1: device descriptor read/8, error -71 [ 518.873669][ T5860] usb 4-1: new high-speed USB device number 29 using dummy_hcd [ 518.914302][ T5860] usb 4-1: device descriptor read/8, error -71 [ 519.033793][ T5860] usb usb4-port1: unable to enumerate USB device [ 519.180126][T10847] netlink: 64 bytes leftover after parsing attributes in process `syz.1.1290'. [ 520.945089][ T30] audit: type=1400 audit(1746634112.883:1364): avc: denied { mounton } for pid=10868 comm="syz.0.1295" path="/" dev="cgroup2" ino=1 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cgroup_t tclass=dir permissive=1 [ 522.068790][T10882] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1298'. [ 523.212991][ T5824] Bluetooth: hci5: Ignoring HCI_Connection_Complete for existing connection [ 524.573094][ T30] audit: type=1400 audit(1746634116.493:1365): avc: denied { unmount } for pid=5819 comm="syz-executor" scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:cgroup_t tclass=filesystem permissive=1 [ 526.183439][ T972] usb 1-1: new high-speed USB device number 30 using dummy_hcd [ 527.011646][ T5824] Bluetooth: hci0: Ignoring HCI_Connection_Complete for existing connection [ 527.073569][ T30] audit: type=1400 audit(1746634119.023:1366): avc: denied { write } for pid=10933 comm="syz.3.1311" name="card1" dev="devtmpfs" ino=628 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:dri_device_t tclass=chr_file permissive=1 [ 527.143491][ T972] usb 1-1: Using ep0 maxpacket: 32 [ 527.153692][ T972] usb 1-1: config 5 has no interfaces? [ 527.176339][ T972] usb 1-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 527.348257][ T972] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 527.360627][ T972] usb 1-1: Product: syz [ 527.364918][ T972] usb 1-1: Manufacturer: syz [ 527.369597][ T972] usb 1-1: SerialNumber: syz [ 527.630295][ T972] usb 1-1: USB disconnect, device number 30 [ 527.819911][ T30] audit: type=1400 audit(1746634119.753:1367): avc: denied { bind } for pid=10945 comm="syz.5.1313" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_netfilter_socket permissive=1 [ 529.920979][T10988] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 534.143149][ T30] audit: type=1326 audit(1746634125.933:1368): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 534.595107][T11033] vhci_hcd vhci_hcd.0: pdev(4) rhport(0) sockfd(7) [ 534.601657][T11033] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 534.609708][T11033] vhci_hcd vhci_hcd.0: Device attached [ 534.616692][ T5863] usb 2-1: new high-speed USB device number 37 using dummy_hcd [ 534.886668][ T30] audit: type=1326 audit(1746634125.933:1369): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 534.915141][ T73] usb 42-1: SetAddress Request (6) to port 0 [ 534.921193][ T73] usb 42-1: new SuperSpeed USB device number 6 using vhci_hcd [ 534.928867][ T5862] usb 5-1: new high-speed USB device number 24 using dummy_hcd [ 535.033197][ T30] audit: type=1326 audit(1746634125.933:1370): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 535.088963][ T5863] usb 2-1: Using ep0 maxpacket: 32 [ 535.103309][ T30] audit: type=1326 audit(1746634125.933:1371): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 535.127894][ T5863] usb 2-1: config 5 has no interfaces? [ 535.133452][ T30] audit: type=1326 audit(1746634125.933:1372): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 535.248577][ T5824] Bluetooth: hci5: ACL packet for unknown connection handle 200 [ 535.934052][ T5863] usb 2-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 535.943466][ T5863] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 535.951486][ T5863] usb 2-1: Product: syz [ 535.955844][ T30] audit: type=1326 audit(1746634125.933:1373): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 535.979479][ T5863] usb 2-1: Manufacturer: syz [ 535.984180][ T5863] usb 2-1: SerialNumber: syz [ 535.997151][ T30] audit: type=1326 audit(1746634125.933:1374): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 536.033244][ T30] audit: type=1326 audit(1746634125.933:1375): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 536.066404][ T5862] usb 5-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 536.070997][ T30] audit: type=1326 audit(1746634125.933:1376): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 536.095619][ T5862] usb 5-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 536.106271][ T30] audit: type=1326 audit(1746634125.933:1377): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11030 comm="syz.4.1333" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 536.329664][ T5862] usb 5-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 536.341160][ T5862] usb 5-1: config 0 interface 0 has no altsetting 0 [ 536.349848][ T5862] usb 5-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 536.360187][ T5862] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 536.434335][T11057] netlink: 12 bytes leftover after parsing attributes in process `syz.0.1339'. [ 537.097912][T11038] vhci_hcd: connection reset by peer [ 537.290368][ T1146] vhci_hcd: stop threads [ 537.407625][ T5863] usb 2-1: USB disconnect, device number 37 [ 537.430422][ T1146] vhci_hcd: release socket [ 537.473227][ T1146] vhci_hcd: disconnect device [ 537.658647][ T5862] usb 5-1: config 0 descriptor?? [ 537.958493][ T5862] usb 5-1: can't set config #0, error -71 [ 538.826194][T11075] omfs: Invalid superblock (0) [ 538.957373][ T5862] usb 5-1: USB disconnect, device number 24 [ 540.169728][ T73] usb 42-1: device descriptor read/8, error -110 [ 540.314626][T11093] netlink: 16 bytes leftover after parsing attributes in process `syz.0.1347'. [ 540.347682][ T30] kauditd_printk_skb: 16 callbacks suppressed [ 540.347695][ T30] audit: type=1400 audit(1746634132.233:1394): avc: denied { getopt } for pid=11087 comm="syz.0.1347" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=smc_socket permissive=1 [ 540.400003][T11096] netlink: 4 bytes leftover after parsing attributes in process `syz.4.1348'. [ 540.650179][ T30] audit: type=1400 audit(1746634132.593:1395): avc: denied { map } for pid=11087 comm="syz.0.1347" path="socket:[26114]" dev="sockfs" ino=26114 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=netlink_route_socket permissive=1 [ 540.673817][ T73] usb usb42-port1: attempt power cycle [ 541.095642][ T30] audit: type=1326 audit(1746634133.043:1396): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.210586][ T30] audit: type=1326 audit(1746634133.043:1397): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.235427][ T30] audit: type=1326 audit(1746634133.063:1398): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.261477][ T30] audit: type=1326 audit(1746634133.063:1399): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.770607][ T73] usb usb42-port1: unable to enumerate USB device [ 541.793567][ T30] audit: type=1326 audit(1746634133.063:1400): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.820424][ T30] audit: type=1326 audit(1746634133.063:1401): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.823018][T11106] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(5) [ 541.844871][ T30] audit: type=1326 audit(1746634133.063:1402): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 541.850483][T11106] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 541.850653][T11106] vhci_hcd vhci_hcd.0: Device attached [ 541.938416][ T30] audit: type=1326 audit(1746634133.063:1403): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11103 comm="syz.5.1350" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 542.104513][ T5860] usb 6-1: new high-speed USB device number 7 using dummy_hcd [ 542.305097][T11115] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 542.560396][T11062] usb 44-1: SetAddress Request (2) to port 0 [ 542.600468][T11062] usb 44-1: new SuperSpeed USB device number 2 using vhci_hcd [ 542.668987][ T5860] usb 6-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 543.020809][ T5860] usb 6-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 543.032481][ T5860] usb 6-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 543.048457][ T5860] usb 6-1: config 0 interface 0 has no altsetting 0 [ 543.055550][ T5860] usb 6-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 543.076840][ T5860] usb 6-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 543.124720][ T5860] usb 6-1: config 0 descriptor?? [ 545.333014][T11108] vhci_hcd: connection reset by peer [ 545.338891][ T5860] usbhid 6-1:0.0: can't add hid device: -71 [ 545.364551][ T1087] vhci_hcd: stop threads [ 545.368911][ T1087] vhci_hcd: release socket [ 545.377283][ T5860] usbhid 6-1:0.0: probe with driver usbhid failed with error -71 [ 545.451295][ T1087] vhci_hcd: disconnect device [ 545.573669][ T5860] usb 6-1: USB disconnect, device number 7 [ 546.140910][T11151] siw: device registration error -23 [ 546.230316][ T30] kauditd_printk_skb: 15 callbacks suppressed [ 546.230331][ T30] audit: type=1400 audit(1746634138.173:1419): avc: denied { setattr } for pid=11152 comm="syz.4.1363" name="video7" dev="devtmpfs" ino=949 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:v4l_device_t tclass=chr_file permissive=1 [ 547.491389][ T5824] Bluetooth: hci0: Ignoring HCI_Connection_Complete for existing connection [ 548.145949][ T9509] netdevsim netdevsim2 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 548.156713][T11062] usb 44-1: device descriptor read/8, error -110 [ 548.670171][T11192] siw: device registration error -23 [ 548.857819][ T5862] usb 1-1: new high-speed USB device number 31 using dummy_hcd [ 549.028879][T11062] usb usb44-port1: attempt power cycle [ 549.113047][ T5860] usb 6-1: new high-speed USB device number 8 using dummy_hcd [ 549.195641][ T30] audit: type=1326 audit(1746634141.033:1420): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 549.227717][ T9509] netdevsim netdevsim2 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 549.229432][ T30] audit: type=1326 audit(1746634141.033:1421): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 549.643337][ T73] usb 2-1: new high-speed USB device number 38 using dummy_hcd [ 549.681587][ T30] audit: type=1326 audit(1746634141.033:1422): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 549.693951][T11062] usb usb44-port1: unable to enumerate USB device [ 549.711891][T11199] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(5) [ 549.718420][T11199] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 549.722948][ T30] audit: type=1326 audit(1746634141.033:1423): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 549.726252][T11199] vhci_hcd vhci_hcd.0: Device attached [ 549.760028][ T5862] usb 1-1: unable to get BOS descriptor or descriptor too short [ 549.779586][ T5862] usb 1-1: unable to read config index 0 descriptor/start: -71 [ 549.790455][ T30] audit: type=1326 audit(1746634141.033:1424): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 549.798726][ T5862] usb 1-1: can't read configurations, error -71 [ 549.817399][ T30] audit: type=1326 audit(1746634141.033:1425): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 549.960572][ T73] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 549.971830][ T73] usb 2-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 549.981546][ T5860] usb 6-1: config 0 has no interfaces? [ 549.983336][ T73] usb 2-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 549.998030][ T73] usb 2-1: config 0 interface 0 has no altsetting 0 [ 550.004942][ T73] usb 2-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 550.014033][ T73] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 550.016721][ T5860] usb 6-1: New USB device found, idVendor=091e, idProduct=0003, bcdDevice=d7.3b [ 550.069750][ T73] usb 2-1: config 0 descriptor?? [ 550.093159][ T5863] usb 36-1: SetAddress Request (22) to port 0 [ 550.099406][ T5863] usb 36-1: new SuperSpeed USB device number 22 using vhci_hcd [ 550.438083][ T30] audit: type=1326 audit(1746634141.033:1426): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 550.462207][ T5860] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 550.470724][ T9509] netdevsim netdevsim2 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 550.485632][ T5860] usb 6-1: Product: syz [ 550.489852][ T5860] usb 6-1: Manufacturer: syz [ 550.490349][ T30] audit: type=1326 audit(1746634141.033:1427): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 550.510660][ T5860] usb 6-1: SerialNumber: syz [ 550.521458][ T30] audit: type=1326 audit(1746634141.033:1428): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11194 comm="syz.1.1371" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 550.562775][ T5860] usb 6-1: config 0 descriptor?? [ 550.594350][ T9509] netdevsim netdevsim2 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 551.358249][ T9509] bridge_slave_1: left allmulticast mode [ 551.380706][ T9509] bridge_slave_1: left promiscuous mode [ 551.442916][ T9509] bridge0: port 2(bridge_slave_1) entered disabled state [ 551.459040][ T9509] bridge_slave_0: left allmulticast mode [ 551.467417][ T9509] bridge_slave_0: left promiscuous mode [ 551.473674][ T9509] bridge0: port 1(bridge_slave_0) entered disabled state [ 552.336292][ T5862] usb 6-1: USB disconnect, device number 8 [ 554.014239][ T5860] usb 5-1: new high-speed USB device number 25 using dummy_hcd [ 554.109417][ T9509] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 554.174822][ T5860] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 554.191261][ T9509] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 554.205313][ T5860] usb 5-1: config 0 interface 0 altsetting 0 endpoint 0x81 has invalid wMaxPacketSize 0 [ 554.230922][ T9509] bond0 (unregistering): (slave wlan1): Releasing backup interface [ 554.244478][ T5860] usb 5-1: New USB device found, idVendor=1e7d, idProduct=2cf6, bcdDevice= 0.00 [ 554.256064][ T5860] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 554.280121][ T5860] usb 5-1: config 0 descriptor?? [ 554.343275][ T30] kauditd_printk_skb: 12 callbacks suppressed [ 554.343293][ T30] audit: type=1400 audit(1746634146.283:1441): avc: denied { shutdown } for pid=11263 comm="syz.5.1386" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=tipc_socket permissive=1 [ 554.370120][ C1] vkms_vblank_simulate: vblank timer overrun [ 554.389394][ T9509] bond0 (unregistering): Released all slaves [ 554.577212][T11245] lo speed is unknown, defaulting to 1000 [ 554.612968][T11200] vhci_hcd: connection reset by peer [ 554.630827][ T6229] vhci_hcd: stop threads [ 554.645964][ T73] usbhid 2-1:0.0: can't add hid device: -71 [ 554.659028][ T6229] vhci_hcd: release socket [ 554.670432][ T6229] vhci_hcd: disconnect device [ 554.675645][ T73] usbhid 2-1:0.0: probe with driver usbhid failed with error -71 [ 554.695119][ T73] usb 2-1: USB disconnect, device number 38 [ 554.732212][ T9509] IPVS: stopping master sync thread 6732 ... [ 554.761825][ T5860] pyra 0003:1E7D:2CF6.0002: hidraw0: USB HID v0.00 Device [HID 1e7d:2cf6] on usb-dummy_hcd.4-1/input0 [ 555.280796][ T5863] usb 36-1: device descriptor read/8, error -110 [ 555.834073][ T5863] usb usb36-port1: attempt power cycle [ 555.863241][ T5860] pyra 0003:1E7D:2CF6.0002: couldn't init struct pyra_device [ 555.883034][ T5860] pyra 0003:1E7D:2CF6.0002: couldn't install mouse [ 555.938197][ T5860] pyra 0003:1E7D:2CF6.0002: probe with driver pyra failed with error -71 [ 556.203314][ T5860] usb 5-1: USB disconnect, device number 25 [ 556.476279][ T5863] usb usb36-port1: unable to enumerate USB device [ 556.547432][ T30] audit: type=1400 audit(1746634148.493:1442): avc: denied { create } for pid=11282 comm="syz.5.1392" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rose_socket permissive=1 [ 556.567006][ C1] vkms_vblank_simulate: vblank timer overrun [ 557.464921][ T30] audit: type=1400 audit(1746634149.343:1443): avc: denied { connect } for pid=11282 comm="syz.5.1392" lport=1 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rawip_socket permissive=1 [ 557.601757][ T30] audit: type=1400 audit(1746634149.353:1444): avc: denied { ioctl } for pid=11282 comm="syz.5.1392" path="socket:[26475]" dev="sockfs" ino=26475 ioctlcmd=0x890b scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rose_socket permissive=1 [ 557.683804][ T30] audit: type=1400 audit(1746634149.463:1445): avc: denied { append } for pid=11290 comm="syz.3.1393" name="ppp" dev="devtmpfs" ino=709 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:ppp_device_t tclass=chr_file permissive=1 [ 557.923095][ T5863] usb 5-1: new full-speed USB device number 26 using dummy_hcd [ 558.002824][ T9509] hsr_slave_0: left promiscuous mode [ 558.543511][ T5912] usb 6-1: new high-speed USB device number 9 using dummy_hcd [ 558.579305][ T9509] hsr_slave_1: left promiscuous mode [ 558.597854][ T9509] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 558.605467][ T9509] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 558.664361][ T5863] usb 5-1: config 0 has an invalid interface number: 183 but max is 0 [ 558.672628][ T5863] usb 5-1: config 0 has no interface number 0 [ 558.683550][ T9509] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 558.690985][ T9509] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 558.710131][ T5863] usb 5-1: New USB device found, idVendor=06d0, idProduct=0622, bcdDevice=70.f8 [ 558.738687][ T5863] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 558.873263][ T5912] usb 6-1: Using ep0 maxpacket: 32 [ 558.886731][ T5863] usb 5-1: Product: syz [ 558.891200][ T5863] usb 5-1: Manufacturer: syz [ 558.895064][ T5912] usb 6-1: config 5 has no interfaces? [ 558.896131][ T5863] usb 5-1: SerialNumber: syz [ 558.927991][ T9509] veth1_macvtap: left promiscuous mode [ 558.937566][ T5912] usb 6-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 559.719152][ T5863] usb 5-1: config 0 descriptor?? [ 559.727849][ T5863] net1080 5-1:0.183: probe with driver net1080 failed with error -22 [ 559.788962][ T9509] veth0_macvtap: left promiscuous mode [ 559.794650][ T5912] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 559.824148][ T9509] veth1_vlan: left promiscuous mode [ 559.839465][ T9509] veth0_vlan: left promiscuous mode [ 559.977925][ T73] usb 5-1: USB disconnect, device number 26 [ 560.035332][ T5912] usb 6-1: Product: syz [ 560.039584][ T5912] usb 6-1: Manufacturer: syz [ 560.047979][ T5912] usb 6-1: SerialNumber: syz [ 560.093059][ T5863] usb 2-1: new high-speed USB device number 39 using dummy_hcd [ 560.253110][ T5863] usb 2-1: device descriptor read/64, error -71 [ 560.512985][ T5863] usb 2-1: new high-speed USB device number 40 using dummy_hcd [ 560.643379][ T5863] usb 2-1: device descriptor read/64, error -71 [ 560.793951][ T5863] usb usb2-port1: attempt power cycle [ 561.006725][ T9509] team0 (unregistering): Port device team_slave_1 removed [ 561.051551][ T9509] team0 (unregistering): Port device team_slave_0 removed [ 561.135892][ T5863] usb 2-1: new high-speed USB device number 41 using dummy_hcd [ 561.164640][ T5863] usb 2-1: device descriptor read/8, error -71 [ 561.333257][ T5912] usb 6-1: USB disconnect, device number 9 [ 562.013511][ T5863] usb 2-1: new high-speed USB device number 42 using dummy_hcd [ 562.075738][ T5863] usb 2-1: device descriptor read/8, error -71 [ 562.548712][ T5863] usb usb2-port1: unable to enumerate USB device [ 562.571113][ T1296] ieee802154 phy0 wpan0: encryption failed: -22 [ 562.577590][ T1296] ieee802154 phy1 wpan1: encryption failed: -22 [ 563.152286][T11336] lo speed is unknown, defaulting to 1000 [ 564.488503][ T30] audit: type=1400 audit(1746634156.233:1446): avc: denied { connect } for pid=11348 comm="syz.4.1406" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 564.869437][T11360] netlink: 68 bytes leftover after parsing attributes in process `syz.4.1406'. [ 565.078922][ T5863] libceph: connect (1)[c::]:6789 error -101 [ 565.088057][ T5863] libceph: mon0 (1)[c::]:6789 connect error [ 565.287471][ T30] audit: type=1400 audit(1746634156.613:1447): avc: denied { shutdown } for pid=11348 comm="syz.4.1406" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=bluetooth_socket permissive=1 [ 565.308706][T11354] ceph: No mds server is up or the cluster is laggy [ 565.420300][ T5863] usb 4-1: new high-speed USB device number 30 using dummy_hcd [ 565.637000][ T30] audit: type=1400 audit(1746634157.583:1448): avc: denied { bind } for pid=11364 comm="syz.1.1409" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=xdp_socket permissive=1 [ 566.053098][ T5863] usb 4-1: Using ep0 maxpacket: 8 [ 566.065663][T11377] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1410'. [ 566.074070][ T5863] usb 4-1: config 0 has an invalid interface number: 31 but max is 0 [ 566.079978][T11371] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1409'. [ 566.082578][ T5863] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 566.082600][ T5863] usb 4-1: config 0 has no interface number 0 [ 566.082633][ T5863] usb 4-1: config 0 interface 31 altsetting 0 has 0 endpoint descriptors, different from the interface descriptor's value: 1 [ 566.091726][ T30] audit: type=1326 audit(1746634157.713:1449): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.091770][ T30] audit: type=1326 audit(1746634157.713:1450): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.091807][ T30] audit: type=1326 audit(1746634157.713:1451): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=85 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.107133][ T9509] IPVS: stop unused estimator thread 0... [ 566.121896][ T30] audit: type=1326 audit(1746634157.723:1452): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.313143][ T5816] Bluetooth: hci5: command 0x0406 tx timeout [ 566.386677][ T30] audit: type=1326 audit(1746634157.723:1453): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.396261][ T5863] usb 4-1: New USB device found, idVendor=112a, idProduct=0005, bcdDevice=be.68 [ 566.410773][ T30] audit: type=1326 audit(1746634157.723:1454): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=198 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.778797][ T972] usb 5-1: new full-speed USB device number 27 using dummy_hcd [ 566.840250][T11371] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 566.892167][ T5863] usb 4-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 566.898741][ T30] audit: type=1326 audit(1746634157.733:1455): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11368 comm="syz.4.1412" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f8b7018e969 code=0x7ffc0000 [ 566.941748][T11383] ptm ptm0: ldisc open failed (-12), clearing slot 0 [ 566.943302][ T5863] usb 4-1: Product: syz [ 566.955475][ T5863] usb 4-1: Manufacturer: syz [ 566.973199][ T5863] usb 4-1: SerialNumber: syz [ 567.018819][ T5863] usb 4-1: config 0 descriptor?? [ 567.037506][ T5863] redrat3 4-1:0.31: Couldn't find all endpoints [ 567.167194][ T972] usb 5-1: New USB device found, idVendor=09c0, idProduct=0203, bcdDevice=d3.43 [ 567.179305][ T972] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 567.209378][ T972] usb 5-1: config 0 descriptor?? [ 567.823078][T10660] usb 6-1: new high-speed USB device number 10 using dummy_hcd [ 567.884304][ T972] dvb-usb: found a 'Genpix SkyWalker-1 DVB-S receiver' in warm state. [ 567.917654][T11363] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1408'. [ 568.146104][ T972] gp8psk: usb in 128 operation failed. [ 568.155036][T11380] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 568.183055][T10660] usb 6-1: Using ep0 maxpacket: 32 [ 568.341233][T10660] usb 6-1: config 5 has no interfaces? [ 568.367487][ T5912] usb 4-1: USB disconnect, device number 30 [ 568.388270][T11380] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 568.692191][T10660] usb 6-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 568.708155][T10660] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 568.756021][ T972] gp8psk: usb in 146 operation failed. [ 568.767546][ T972] gp8psk: failed to get FW version [ 568.769010][T10660] usb 6-1: Product: syz [ 568.801721][T10660] usb 6-1: Manufacturer: syz [ 568.824728][T10660] usb 6-1: SerialNumber: syz [ 568.912467][T11404] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 568.937313][T11404] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 569.559522][ T972] gp8psk: FPGA Version = 83 [ 570.715462][T10660] usb 6-1: USB disconnect, device number 10 [ 571.459003][ T30] kauditd_printk_skb: 32 callbacks suppressed [ 571.459037][ T30] audit: type=1400 audit(1746634163.403:1488): avc: denied { name_bind } for pid=11416 comm="syz.3.1420" src=20002 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:port_t tclass=icmp_socket permissive=1 [ 571.800415][T11174] Bluetooth: hci5: command 0x0406 tx timeout [ 571.800473][ T972] gp8psk: usb in 138 operation failed. [ 571.836024][ T972] dvb-usb: This USB2.0 device cannot be run on a USB1.1 port. (it lacks a hardware PID filter) [ 571.889557][ T972] dvb-usb: Genpix SkyWalker-1 DVB-S receiver error while loading driver (-19) [ 572.895835][ T972] usb 5-1: USB disconnect, device number 27 [ 573.012089][T11427] lo speed is unknown, defaulting to 1000 [ 573.075396][ T73] usb 4-1: new high-speed USB device number 31 using dummy_hcd [ 573.173763][T10660] usb 2-1: new high-speed USB device number 43 using dummy_hcd [ 573.398890][T11437] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 574.093044][T10660] usb 2-1: Using ep0 maxpacket: 32 [ 574.104400][ T73] usb 4-1: device descriptor read/all, error -71 [ 574.138092][T10660] usb 2-1: config 0 interface 0 altsetting 0 has an endpoint descriptor with address 0xA6, changing to 0x86 [ 574.153817][T10660] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x86 has an invalid bInterval 0, changing to 7 [ 574.257546][T10660] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x86 has invalid wMaxPacketSize 0 [ 574.273161][T10660] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x7 has an invalid bInterval 255, changing to 11 [ 574.293665][T10660] usb 2-1: config 0 interface 0 altsetting 0 endpoint 0x7 has invalid maxpacket 59391, setting to 1024 [ 574.741701][ T30] audit: type=1400 audit(1746634166.423:1489): avc: denied { map } for pid=11441 comm="syz.4.1427" path="/dev/bus/usb/006/001" dev="devtmpfs" ino=736 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:usb_device_t tclass=chr_file permissive=1 [ 574.790383][T10660] usb 2-1: New USB device found, idVendor=05ef, idProduct=020a, bcdDevice=91.36 [ 574.802166][T10660] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 574.810224][T10660] usb 2-1: Product: syz [ 574.817003][T10660] usb 2-1: Manufacturer: syz [ 574.821603][T10660] usb 2-1: SerialNumber: syz [ 574.835072][T10660] usb 2-1: config 0 descriptor?? [ 574.949385][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 574.968285][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 574.981603][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.046838][ T5862] usb 5-1: new high-speed USB device number 28 using dummy_hcd [ 575.075260][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.083796][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.091270][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.098758][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.116689][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.132690][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.144262][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.161734][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.288075][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.295799][ T5862] usb 5-1: config 1 interface 0 altsetting 0 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 575.309303][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.315641][ T5862] usb 5-1: config 1 interface 1 altsetting 1 has 1 endpoint descriptor, different from the interface descriptor's value: 2 [ 575.328931][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.337547][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.773927][ T5912] usb 1-1: new high-speed USB device number 33 using dummy_hcd [ 575.796747][ T5862] usb 5-1: New USB device found, idVendor=0525, idProduct=a4a1, bcdDevice= 0.40 [ 575.809580][T11462] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1432'. [ 575.820843][ T5862] usb 5-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 575.820988][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.835815][ T5862] usb 5-1: Product: syz [ 575.840042][ T5862] usb 5-1: Manufacturer: syz [ 575.844723][ T5862] usb 5-1: SerialNumber: syz [ 575.851234][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.861421][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.873486][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.884788][T10660] iforce 2-1:0.0: usb_submit_urb failed: -71 [ 575.892514][T10660] input input15: Timeout waiting for response from device. [ 575.932349][T10660] usb 2-1: USB disconnect, device number 43 [ 575.953274][ T5912] usb 1-1: Using ep0 maxpacket: 16 [ 575.960167][ T5912] usb 1-1: config 1 has an invalid interface number: 203 but max is 0 [ 575.970170][ T5912] usb 1-1: config 1 has no interface number 0 [ 575.987534][ T5912] usb 1-1: New USB device found, idVendor=0b95, idProduct=2790, bcdDevice=63.9c [ 576.090423][ T5912] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 576.111839][ T5912] usb 1-1: Product: syz [ 576.121710][ T5912] usb 1-1: Manufacturer: syz [ 576.136291][ T5912] usb 1-1: SerialNumber: syz [ 576.394713][ T5912] aqc111 1-1:1.203: probe with driver aqc111 failed with error -22 [ 576.511847][ T5862] cdc_ncm 5-1:1.0: failed GET_NTB_PARAMETERS [ 576.540716][ T5862] cdc_ncm 5-1:1.0: bind() failure [ 576.577237][ T5862] cdc_ncm 5-1:1.1: CDC Union missing and no IAD found [ 576.593285][ T5862] cdc_ncm 5-1:1.1: bind() failure [ 576.631369][ T5862] usb 5-1: USB disconnect, device number 28 [ 576.693637][ T30] audit: type=1400 audit(1746634168.633:1490): avc: denied { ioctl } for pid=11452 comm="syz.0.1430" path="/dev/nullb0" dev="devtmpfs" ino=696 ioctlcmd=0x5406 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:device_t tclass=blk_file permissive=1 [ 576.760140][ T5912] usb 1-1: USB disconnect, device number 33 [ 577.190934][T11477] IPVS: Error connecting to the multicast addr [ 578.509211][T11491] lo speed is unknown, defaulting to 1000 [ 578.923883][ T5912] usb 1-1: new high-speed USB device number 34 using dummy_hcd [ 579.033930][T11500] syzkaller0: entered promiscuous mode [ 579.039491][T11500] syzkaller0: entered allmulticast mode [ 579.193527][ T5912] usb 1-1: Using ep0 maxpacket: 32 [ 579.200611][ T5912] usb 1-1: unable to get BOS descriptor or descriptor too short [ 579.212260][ T5912] usb 1-1: config 69 has an invalid interface number: 11 but max is 3 [ 579.232046][ T5912] usb 1-1: config 69 contains an unexpected descriptor of type 0x2, skipping [ 579.269286][ T5912] usb 1-1: config 69 has an invalid descriptor of length 0, skipping remainder of the config [ 579.290642][ T5912] usb 1-1: config 69 has 2 interfaces, different from the descriptor's value: 4 [ 579.309125][ T972] usb 2-1: new high-speed USB device number 44 using dummy_hcd [ 579.318252][ T5912] usb 1-1: config 69 has no interface number 0 [ 579.325032][ T5912] usb 1-1: config 69 has no interface number 1 [ 579.332391][ T5912] usb 1-1: config 69 interface 11 altsetting 16 endpoint 0xD has invalid maxpacket 1023, setting to 64 [ 580.294213][ T5912] usb 1-1: config 69 interface 11 altsetting 16 bulk endpoint 0x1 has invalid maxpacket 32 [ 580.304729][ T5912] usb 1-1: config 69 interface 11 altsetting 16 has 3 endpoint descriptors, different from the interface descriptor's value: 12 [ 580.321103][ T5912] usb 1-1: config 69 interface 2 has no altsetting 0 [ 580.328149][ T5912] usb 1-1: config 69 interface 11 has no altsetting 0 [ 580.338269][ T5912] usb 1-1: New USB device found, idVendor=2001, idProduct=3311, bcdDevice=b6.aa [ 580.348088][ T5912] usb 1-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 580.356388][ T5912] usb 1-1: Product: syz [ 580.360617][ T5912] usb 1-1: Manufacturer: syz [ 580.365677][ T972] usb 2-1: Using ep0 maxpacket: 32 [ 580.370940][ T5912] usb 1-1: SerialNumber: syz [ 580.377194][ T972] usb 2-1: config 5 has no interfaces? [ 580.394375][ T972] usb 2-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 580.403803][ T972] usb 2-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 580.411874][ T972] usb 2-1: Product: syz [ 580.416116][ T972] usb 2-1: Manufacturer: syz [ 580.420757][ T972] usb 2-1: SerialNumber: syz [ 580.954968][T11496] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 580.967689][T11496] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 581.005370][ T5912] usb 1-1: USB disconnect, device number 34 [ 581.596222][T11522] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 581.763799][ T972] usb 2-1: USB disconnect, device number 44 [ 583.021451][T11518] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 583.869512][T11174] Bluetooth: hci5: Ignoring HCI_Connection_Complete for existing connection [ 585.303361][T11566] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 585.433017][ T73] usb 6-1: new high-speed USB device number 11 using dummy_hcd [ 586.013041][ T73] usb 6-1: Using ep0 maxpacket: 32 [ 586.047623][ T73] usb 6-1: config 5 has no interfaces? [ 586.051416][T11574] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1457'. [ 586.076075][ T73] usb 6-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 586.253813][ T73] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 586.261896][ T73] usb 6-1: Product: syz [ 586.273929][T11578] Freezing with imperfect legacy cgroup freezer. See cgroup.freeze of cgroup v2 [ 586.287712][ T73] usb 6-1: Manufacturer: syz [ 586.292564][ T73] usb 6-1: SerialNumber: syz [ 586.385244][T11580] kvm: vcpu 2: requested 128 ns lapic timer period limited to 200000 ns [ 586.397188][T11580] kvm: vcpu 2: requested lapic timer restore with starting count register 0x390=1812281087 (231971979136 ns) > initial count (200000 ns). Using initial count to start timer. [ 586.471971][T11580] kvm: user requested TSC rate below hardware speed [ 587.680303][ T73] usb 6-1: USB disconnect, device number 11 [ 588.014034][ T30] audit: type=1400 audit(1746634179.963:1491): avc: denied { write } for pid=11591 comm="syz.5.1462" name="binder0" dev="binder" ino=7 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 588.057784][ T30] audit: type=1400 audit(1746634179.963:1492): avc: denied { map } for pid=11591 comm="syz.5.1462" path="/dev/binderfs/binder0" dev="binder" ino=7 scontext=root:sysadm_r:sysadm_t tcontext=system_u:object_r:unlabeled_t tclass=chr_file permissive=1 [ 588.619651][T11599] bridge0: port 2(bridge_slave_1) entered disabled state [ 588.627005][T11599] bridge0: port 1(bridge_slave_0) entered disabled state [ 588.692680][T11599] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 588.704726][T11599] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 589.939860][T11599] netdevsim netdevsim0 netdevsim0: unset [1, 0] type 2 family 0 port 6081 - 0 [ 589.948934][T11599] netdevsim netdevsim0 netdevsim1: unset [1, 0] type 2 family 0 port 6081 - 0 [ 589.958065][T11599] netdevsim netdevsim0 netdevsim2: unset [1, 0] type 2 family 0 port 6081 - 0 [ 589.966991][T11599] netdevsim netdevsim0 netdevsim3: unset [1, 0] type 2 family 0 port 6081 - 0 [ 590.203297][T11608] lo speed is unknown, defaulting to 1000 [ 591.811468][ T5860] libceph: connect (1)[c::]:6789 error -101 [ 591.825495][ T5860] libceph: mon0 (1)[c::]:6789 connect error [ 591.929787][T11625] ceph: No mds server is up or the cluster is laggy [ 592.884986][T11642] RDS: rds_bind could not find a transport for fc01::, load rds_tcp or rds_rdma? [ 593.276918][T11637] siw: device registration error -23 [ 593.924743][ T5816] Bluetooth: hci5: Ignoring HCI_Connection_Complete for existing connection [ 594.400906][T11652] siw: device registration error -23 [ 594.842311][T11658] xt_CT: No such helper "netbios-ns" [ 597.015704][T11676] ceph: No mds server is up or the cluster is laggy [ 597.023938][ T73] libceph: connect (1)[c::]:6789 error -13 [ 597.033803][ T73] libceph: mon0 (1)[c::]:6789 connect error [ 597.802982][ T30] audit: type=1326 audit(1746634189.653:1493): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.065482][T11689] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(7) [ 598.072040][T11689] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 598.080506][T11689] vhci_hcd vhci_hcd.0: Device attached [ 598.243207][ T5912] usb 2-1: new high-speed USB device number 45 using dummy_hcd [ 598.261823][ T30] audit: type=1326 audit(1746634189.653:1494): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.286044][ T30] audit: type=1326 audit(1746634189.653:1495): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.309753][ T30] audit: type=1326 audit(1746634189.653:1496): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.364955][ T5860] usb 36-1: SetAddress Request (26) to port 0 [ 598.640192][ T30] audit: type=1326 audit(1746634189.653:1497): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.665485][ T5912] usb 2-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 598.679372][ T5860] usb 36-1: new SuperSpeed USB device number 26 using vhci_hcd [ 598.727765][ T5912] usb 2-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 598.738707][ T30] audit: type=1326 audit(1746634189.653:1498): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.738752][ T30] audit: type=1326 audit(1746634189.653:1499): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.738786][ T30] audit: type=1326 audit(1746634189.653:1500): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.738821][ T30] audit: type=1326 audit(1746634189.653:1501): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.738858][ T30] audit: type=1326 audit(1746634189.653:1502): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11684 comm="syz.1.1485" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f7e98d8e969 code=0x7ffc0000 [ 598.889802][T11702] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1487'. [ 598.901986][ T5912] usb 2-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 598.912258][ T5912] usb 2-1: config 0 interface 0 has no altsetting 0 [ 598.920780][ T5912] usb 2-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 598.967255][T11703] misc userio: Can't change port type on an already running userio instance [ 599.240225][ T5912] usb 2-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 599.422806][ T5912] usb 2-1: config 0 descriptor?? [ 601.565755][T11690] vhci_hcd: connection reset by peer [ 601.593871][ T5912] usbhid 2-1:0.0: can't add hid device: -71 [ 601.601048][ T5912] usbhid 2-1:0.0: probe with driver usbhid failed with error -71 [ 601.615495][ T5912] usb 2-1: USB disconnect, device number 45 [ 601.639583][T11728] IPVS: sync thread started: state = BACKUP, mcast_ifn = sit0, syncid = 0, id = 0 [ 601.816738][ T6202] vhci_hcd: stop threads [ 601.821070][ T6202] vhci_hcd: release socket [ 601.828699][ T6202] vhci_hcd: disconnect device [ 603.195502][T11751] vhci_hcd vhci_hcd.0: pdev(3) rhport(0) sockfd(7) [ 603.202057][T11751] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 603.209818][T11751] vhci_hcd vhci_hcd.0: Device attached [ 603.881540][ T73] usb 4-1: new high-speed USB device number 33 using dummy_hcd [ 603.933858][ T5860] usb 36-1: device descriptor read/8, error -110 [ 603.942960][ T5862] usb 40-1: SetAddress Request (14) to port 0 [ 603.953147][ T5862] usb 40-1: new SuperSpeed USB device number 14 using vhci_hcd [ 604.246150][ T73] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 604.257992][ T73] usb 4-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 604.258021][ T73] usb 4-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 604.258038][ T73] usb 4-1: config 0 interface 0 has no altsetting 0 [ 604.258061][ T73] usb 4-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 604.258079][ T73] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 604.308207][ T73] usb 4-1: config 0 descriptor?? [ 604.329936][T11764] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1504'. [ 604.524146][ T5860] usb usb36-port1: attempt power cycle [ 604.821699][T11771] Invalid ELF header type: 3 != 1 [ 604.834709][ T30] kauditd_printk_skb: 34 callbacks suppressed [ 604.834738][ T30] audit: type=1400 audit(1746634196.763:1537): avc: denied { module_load } for pid=11767 comm="syz.4.1505" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=system permissive=1 [ 605.213829][ T5860] usb usb36-port1: unable to enumerate USB device [ 605.743355][ T972] usb 5-1: new high-speed USB device number 29 using dummy_hcd [ 605.902923][ T972] usb 5-1: Using ep0 maxpacket: 8 [ 605.914116][ T972] usb 5-1: config 16 interface 0 altsetting 0 endpoint 0x5 has invalid maxpacket 56832, setting to 1024 [ 605.952413][ T972] usb 5-1: config 16 interface 0 altsetting 0 bulk endpoint 0x5 has invalid maxpacket 1024 [ 605.995851][ T972] usb 5-1: config 16 interface 0 altsetting 0 bulk endpoint 0x8B has invalid maxpacket 32 [ 606.021299][ T972] usb 5-1: config 16 interface 0 altsetting 0 has 2 endpoint descriptors, different from the interface descriptor's value: 3 [ 606.034927][T11753] vhci_hcd: connection reset by peer [ 606.044450][ T73] usbhid 4-1:0.0: can't add hid device: -71 [ 606.056856][ T6202] vhci_hcd: stop threads [ 606.058518][ T73] usbhid 4-1:0.0: probe with driver usbhid failed with error -71 [ 606.092750][ T73] usb 4-1: USB disconnect, device number 33 [ 606.110633][ T972] usb 5-1: New USB device found, idVendor=ee8d, idProduct=db1a, bcdDevice=61.23 [ 606.136096][ T6202] vhci_hcd: release socket [ 606.149968][ T6202] vhci_hcd: disconnect device [ 606.156852][ T972] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 606.459947][ T972] usb 5-1: GET_CAPABILITIES returned 0 [ 606.469830][ T972] usbtmc 5-1:16.0: can't read capabilities [ 606.688199][ T30] audit: type=1400 audit(1746634198.623:1538): avc: denied { write } for pid=11775 comm="syz.4.1507" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=rxrpc_socket permissive=1 [ 606.932523][T11778] UDC core: USB Raw Gadget: couldn't find an available UDC or it's busy [ 606.973427][T11778] misc raw-gadget: fail, usb_gadget_register_driver returned -16 [ 607.054066][ T73] usb 5-1: USB disconnect, device number 29 [ 607.144522][ T30] audit: type=1400 audit(1746634199.083:1539): avc: denied { setopt } for pid=11793 comm="syz.4.1511" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 607.180244][ T30] audit: type=1400 audit(1746634199.083:1540): avc: denied { write } for pid=11793 comm="syz.4.1511" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 607.460861][ T30] audit: type=1400 audit(1746634199.123:1541): avc: denied { read } for pid=11793 comm="syz.4.1511" lport=2 scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=icmp_socket permissive=1 [ 607.784986][T11800] xt_time: invalid argument - start or stop time greater than 23:59:59 [ 607.844784][ T30] audit: type=1326 audit(1746634199.793:1542): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11801 comm="syz.0.1513" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f6589b8e969 code=0x7ffc0000 [ 608.095403][ T30] audit: type=1326 audit(1746634199.793:1543): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11801 comm="syz.0.1513" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f6589b8e969 code=0x7ffc0000 [ 608.199950][T11804] vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(7) [ 608.206499][T11804] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 608.214899][T11804] vhci_hcd vhci_hcd.0: Device attached [ 608.515733][ T5860] usb 1-1: new high-speed USB device number 35 using dummy_hcd [ 608.543137][ T972] usb 34-1: SetAddress Request (10) to port 0 [ 608.547751][ T30] audit: type=1326 audit(1746634199.833:1544): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11801 comm="syz.0.1513" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f6589b8e969 code=0x7ffc0000 [ 608.572906][ T30] audit: type=1326 audit(1746634199.833:1545): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11801 comm="syz.0.1513" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f6589b8e969 code=0x7ffc0000 [ 608.596615][ T30] audit: type=1326 audit(1746634199.833:1546): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11801 comm="syz.0.1513" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f6589b8e969 code=0x7ffc0000 [ 608.602970][ T972] usb 34-1: new SuperSpeed USB device number 10 using vhci_hcd [ 608.838225][ T5860] usb 1-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 608.851132][ T5860] usb 1-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 609.443553][ T5860] usb 1-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 609.449345][ T5862] usb 40-1: device descriptor read/8, error -110 [ 609.453423][ T5860] usb 1-1: config 0 interface 0 has no altsetting 0 [ 609.468739][ T5860] usb 1-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 609.478707][ T5860] usb 1-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 609.624829][ T5860] usb 1-1: config 0 descriptor?? [ 609.636035][T11818] vhci_hcd vhci_hcd.0: pdev(1) rhport(0) sockfd(3) [ 609.642578][T11818] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 609.736442][T11818] vhci_hcd vhci_hcd.0: Device attached [ 609.775978][T11819] vhci_hcd: connection closed [ 609.776434][ T6848] vhci_hcd: stop threads [ 609.816494][ T6848] vhci_hcd: release socket [ 609.821033][ T6848] vhci_hcd: disconnect device [ 610.362891][ T5862] usb usb40-port1: attempt power cycle [ 610.466888][ T30] kauditd_printk_skb: 17 callbacks suppressed [ 610.466904][ T30] audit: type=1326 audit(1746634202.413:1564): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 610.500333][ T30] audit: type=1326 audit(1746634202.413:1565): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 610.640480][ T30] audit: type=1326 audit(1746634202.413:1566): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=302 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 610.704235][ T30] audit: type=1326 audit(1746634202.413:1567): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 610.728297][ T30] audit: type=1326 audit(1746634202.413:1568): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=144 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 611.230122][ T30] audit: type=1326 audit(1746634202.413:1569): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 611.253943][ T30] audit: type=1326 audit(1746634202.413:1570): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 611.279488][T11831] vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(5) [ 611.286034][T11831] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 611.293901][T11831] vhci_hcd vhci_hcd.0: Device attached [ 611.341226][T11832] vhci_hcd: connection closed [ 611.351532][ T6229] vhci_hcd: stop threads [ 611.366999][ T30] audit: type=1326 audit(1746634202.413:1571): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=39 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 611.373159][ T6229] vhci_hcd: release socket [ 611.430135][ T6229] vhci_hcd: disconnect device [ 611.656836][T11805] vhci_hcd: connection reset by peer [ 611.678465][ T5860] usbhid 1-1:0.0: can't add hid device: -71 [ 611.719004][ T5862] usb usb40-port1: unable to enumerate USB device [ 611.739294][ T6848] vhci_hcd: stop threads [ 611.743033][ T30] audit: type=1326 audit(1746634202.413:1572): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 611.751920][ T5860] usbhid 1-1:0.0: probe with driver usbhid failed with error -71 [ 611.780544][ T6848] vhci_hcd: release socket [ 611.800821][ T6848] vhci_hcd: disconnect device [ 611.814788][ T30] audit: type=1326 audit(1746634202.413:1573): auid=4294967295 uid=0 gid=0 ses=4294967295 subj=root:sysadm_r:sysadm_t pid=11825 comm="syz.5.1519" exe="/root/syz-executor" sig=0 arch=c000003e syscall=202 compat=0 ip=0x7f17add8e969 code=0x7ffc0000 [ 611.947004][ T5860] usb 1-1: USB disconnect, device number 35 [ 612.050856][T11843] netlink: 16 bytes leftover after parsing attributes in process `syz.5.1523'. [ 613.942902][T11062] usb 5-1: new high-speed USB device number 30 using dummy_hcd [ 613.953477][ T972] usb 34-1: device descriptor read/8, error -110 [ 614.362240][T11880] vhci_hcd vhci_hcd.0: pdev(3) rhport(0) sockfd(5) [ 614.368788][T11880] vhci_hcd vhci_hcd.0: devid(0) speed(5) speed_str(super-speed) [ 614.376944][T11880] vhci_hcd vhci_hcd.0: Device attached [ 614.443400][ T5860] usb 6-1: new high-speed USB device number 12 using dummy_hcd [ 614.495959][ T972] usb usb34-port1: attempt power cycle [ 614.676795][ T9] usb 4-1: new high-speed USB device number 34 using dummy_hcd [ 614.692260][ T5912] usb 40-1: SetAddress Request (18) to port 0 [ 614.698911][ T5860] usb 6-1: Using ep0 maxpacket: 32 [ 614.712899][ T5912] usb 40-1: new SuperSpeed USB device number 18 using vhci_hcd [ 614.756914][T11062] usb 5-1: New USB device found, idVendor=056e, idProduct=4010, bcdDevice=20.1c [ 614.756976][ T5860] usb 6-1: config 5 has no interfaces? [ 614.812410][T11062] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 614.842332][T11062] usb 5-1: config 0 descriptor?? [ 614.855296][ T5860] usb 6-1: New USB device found, idVendor=2040, idProduct=8268, bcdDevice=76.d1 [ 614.904483][ T9] usb 4-1: config 0 has an invalid descriptor of length 0, skipping remainder of the config [ 614.948258][ T5860] usb 6-1: New USB device strings: Mfr=1, Product=2, SerialNumber=3 [ 614.960122][ T9] usb 4-1: config 0 interface 0 altsetting 4 endpoint 0x81 has an invalid bInterval 0, changing to 7 [ 614.984390][ T5860] usb 6-1: Product: syz [ 614.989116][ T5860] usb 6-1: Manufacturer: syz [ 614.995408][ T9] usb 4-1: config 0 interface 0 altsetting 4 endpoint 0x81 has invalid wMaxPacketSize 0 [ 615.010352][ T5860] usb 6-1: SerialNumber: syz [ 615.250304][ T972] usb usb34-port1: unable to enumerate USB device [ 615.281691][ T9] usb 4-1: config 0 interface 0 has no altsetting 0 [ 615.517849][T11893] mkiss: ax0: crc mode is auto. [ 615.688126][ T9] usb 4-1: New USB device found, idVendor=0458, idProduct=5015, bcdDevice= 0.00 [ 615.933072][ T9] usb 4-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 616.005343][T11062] pegasus 5-1:0.0: probe with driver pegasus failed with error -32 [ 616.051056][ T9] usb 4-1: config 0 descriptor?? [ 616.130645][T11901] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 616.147160][T11901] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 616.157641][T11901] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 616.170421][T11901] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 616.531395][T11174] Bluetooth: hci4: Ignoring HCI_Connection_Complete for existing connection [ 616.906282][ T5860] usb 6-1: USB disconnect, device number 12 [ 617.180012][T11062] usb 5-1: USB disconnect, device number 30 [ 617.541152][ T30] kauditd_printk_skb: 36 callbacks suppressed [ 617.541166][ T30] audit: type=1400 audit(1746634209.483:1610): avc: denied { listen } for pid=11915 comm="syz.0.1540" scontext=root:sysadm_r:sysadm_t tcontext=root:sysadm_r:sysadm_t tclass=nfc_socket permissive=1 [ 617.581567][T11918] iommufd_mock iommufd_mock0: Adding to iommu group 0 [ 617.982406][T11881] vhci_hcd: connection reset by peer [ 617.993223][ T9] usbhid 4-1:0.0: can't add hid device: -71 [ 617.999267][ T9] usbhid 4-1:0.0: probe with driver usbhid failed with error -71 [ 618.103070][ T6229] vhci_hcd: stop threads [ 618.108736][ T9] usb 4-1: USB disconnect, device number 34 [ 618.124364][ T6229] vhci_hcd: release socket [ 618.157931][ T6229] vhci_hcd: disconnect device [ 619.082977][T11062] usb 5-1: new high-speed USB device number 31 using dummy_hcd [ 619.132174][T11943] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000021: 0000 [#1] SMP KASAN NOPTI [ 619.144245][T11943] KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] [ 619.152658][T11943] CPU: 1 UID: 0 PID: 11943 Comm: syz.0.1546 Not tainted 6.15.0-rc5-syzkaller-00032-g0d8d44db295c #0 PREEMPT(full) [ 619.164723][T11943] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/29/2025 [ 619.174857][T11943] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 619.179971][T11943] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 3a 74 5d f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 619.199580][T11943] RSP: 0018:ffffc9001286fbf0 EFLAGS: 00010293 [ 619.205627][T11943] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffffff885dbe6a [ 619.213571][T11943] RDX: ffff8880255c0000 RSI: ffffffff885dbeb6 RDI: 0000000000000005 [ 619.221514][T11943] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 619.229457][T11943] R10: 0000000000000001 R11: 0000000000000001 R12: ffffc9001286fd88 [ 619.237400][T11943] R13: ffffc9001286fd88 R14: 0000000000000001 R15: ffff88807f303400 [ 619.245346][T11943] FS: 00007f658a9a26c0(0000) GS:ffff888124adf000(0000) knlGS:0000000000000000 [ 619.254252][T11943] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 619.260908][T11943] CR2: 00007f658a981d58 CR3: 0000000027c2f000 CR4: 00000000003526f0 [ 619.268853][T11943] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 619.276794][T11943] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 619.284737][T11943] Call Trace: [ 619.287994][T11943] [ 619.290901][T11943] ? __pfx_bcsp_recv+0x10/0x10 [ 619.295652][T11943] hci_uart_tty_receive+0x251/0x7e0 [ 619.300832][T11943] ? __pfx_hci_uart_tty_receive+0x10/0x10 [ 619.306528][T11943] tty_ioctl+0x57d/0x1610 [ 619.310828][T11943] ? __pfx_tty_ioctl+0x10/0x10 [ 619.315566][T11943] ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 [ 619.322395][T11943] ? hook_file_ioctl_common+0x145/0x410 [ 619.327912][T11943] ? selinux_file_ioctl+0x180/0x270 [ 619.333086][T11943] ? selinux_file_ioctl+0xb4/0x270 [ 619.338170][T11943] ? __pfx_tty_ioctl+0x10/0x10 [ 619.342904][T11943] __x64_sys_ioctl+0x190/0x200 [ 619.347641][T11943] do_syscall_64+0xcd/0x260 [ 619.352127][T11943] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 619.357999][T11943] RIP: 0033:0x7f6589b8e969 [ 619.362384][T11943] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 619.381962][T11943] RSP: 002b:00007f658a9a2038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 619.390346][T11943] RAX: ffffffffffffffda RBX: 00007f6589db6080 RCX: 00007f6589b8e969 [ 619.398289][T11943] RDX: 0000200000000140 RSI: 0000000000005412 RDI: 0000000000000004 [ 619.406232][T11943] RBP: 00007f6589c10ab1 R08: 0000000000000000 R09: 0000000000000000 [ 619.414174][T11943] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 619.422124][T11943] R13: 0000000000000000 R14: 00007f6589db6080 R15: 00007ffc3abb4c68 [ 619.430069][T11943] [ 619.433060][T11943] Modules linked in: [ 619.437269][T11943] ---[ end trace 0000000000000000 ]--- [ 619.514276][T11943] RIP: 0010:bcsp_recv+0x10a/0x17f0 [ 619.523081][T11943] Code: 18 48 c1 e8 03 48 01 e8 48 89 04 24 48 8d 83 78 01 00 00 48 89 44 24 28 48 c1 e8 03 48 89 44 24 08 e8 3a 74 5d f9 48 8b 04 24 <80> 38 00 0f 85 d1 12 00 00 4c 8b ab 08 01 00 00 31 ff 4c 89 ee e8 [ 619.562659][T11062] usb 5-1: config 27 interface 0 altsetting 0 endpoint 0x8B has an invalid bInterval 0, changing to 7 [ 619.568147][T11943] RSP: 0018:ffffc9001286fbf0 EFLAGS: 00010293 [ 619.589804][T11062] usb 5-1: config 27 interface 0 altsetting 0 bulk endpoint 0xB has invalid maxpacket 47 [ 619.598069][T11943] [ 619.606001][T11062] usb 5-1: New USB device found, idVendor=0582, idProduct=0014, bcdDevice=bb.9d [ 619.617377][T11062] usb 5-1: New USB device strings: Mfr=0, Product=0, SerialNumber=0 [ 619.628763][T11943] RAX: dffffc0000000021 RBX: 0000000000000000 RCX: ffffffff885dbe6a [ 619.641289][T11940] raw-gadget.0 gadget.4: fail, usb_ep_enable returned -22 [ 619.655981][T11062] usb 5-1: Quirk or no altset; falling back to MIDI 1.0 [ 619.661200][T11943] RDX: ffff8880255c0000 RSI: ffffffff885dbeb6 RDI: 0000000000000005 [ 619.680832][T11943] RBP: dffffc0000000000 R08: 0000000000000005 R09: 0000000000000000 [ 619.688971][T11943] R10: 0000000000000001 R11: 0000000000000001 R12: ffffc9001286fd88 [ 619.699385][T11943] R13: ffffc9001286fd88 R14: 0000000000000001 R15: ffff88807f303400 [ 619.707618][T11943] FS: 00007f658a9a26c0(0000) GS:ffff8881249df000(0000) knlGS:0000000000000000 [ 619.718491][T11943] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 619.736832][T11943] CR2: 00007f7e98f7d2d8 CR3: 0000000027c2f000 CR4: 00000000003526f0 [ 619.744948][T11943] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 619.755695][T11943] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 619.763980][T11943] Kernel panic - not syncing: Fatal exception [ 619.770248][T11943] Kernel Offset: disabled [ 619.774552][T11943] Rebooting in 86400 seconds..