last executing test programs: 10.745166221s ago: executing program 3 (id=1697): mmap$auto(0x0, 0x20009, 0x4000000000df, 0xeb1, 0x401, 0x8000) r0 = socket(0x10, 0x2, 0x0) syz_genetlink_get_family_id$auto_mac80211_hwsim(&(0x7f0000000040), 0xffffffffffffffff) mmap$auto(0x0, 0x9, 0x800000000df, 0x9b72, 0xea8a, 0x8000) r1 = socket(0xa, 0x3, 0x3a) close$auto(r1) r2 = socket$nl_generic(0x10, 0x3, 0x10) r3 = syz_genetlink_get_family_id$auto_ipvs(&(0x7f0000000500), r2) sendmsg$auto_IPVS_CMD_SET_CONFIG(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000280)=ANY=[@ANYBLOB, @ANYRES16=r3, @ANYBLOB="010028bd7000ffdbdf250c0000000800060000000000"], 0x1c}, 0x1, 0x0, 0x0, 0x8010}, 0x0) capget$auto(&(0x7f0000000980)={0x1aa, 0x0}, &(0x7f00000009c0)={0x10, 0x9, 0xb1}) ioctl$auto_XFS_IOC_SWAPEXT(0xffffffffffffffff, 0xc0c0586d, &(0x7f0000000a00)={0x4, @raw, @inferred=r0, 0x7f, 0x29, '\x00', {0x0, 0x401, 0x9, 0xee01, 0x0, 0x8001, 0x4, 0xfff, {0x80, 0x9}, {0x8, 0x8}, {0x0, 0x7f}, 0x8, 0x1, 0x401, 0x6, 0xe, 0x7, 0x7, 0x5, 0x5ed, 0x7, '\x00', 0x5, 0x2, 0xb19, 0x1}}) sendmsg$auto_IPVS_CMD_SET_SERVICE(r0, &(0x7f0000001040)={&(0x7f0000000940)={0x10, 0x0, 0x0, 0x200}, 0xc, &(0x7f0000001000)={&(0x7f0000002e00)=ANY=[@ANYBLOB="781d0000", @ANYRES16=r3, @ANYBLOB="010026bd7000ffdbdf2502000000901a02807c1a288040183e8057cf14c2d46aa18459fb1b29342685cdee30fcfd8d2aaf51d0c819a34fb512372be99979fd10c89f0664efed5e0011ee6a2023a5a9f310bc6f830f7024180055a607fc4bc75acbacd482585d9f2e0392b8efa23d3a4993578574508e685a964babb6ce90525b5ec677b5a612dc4cd7f8a4593d4b05c15eba79539784ed4b45beb9864ff12672141b108e909db6e432ead74ce0895da6453dab7103043d3e614adeb40ed7daad9e42ada6c742902e6acbb65c85ba5804c503f503515161c5b989b03c474b05674471dacffb5ead74ac58168e2787ecd126a4e7de855561fee5f0a204dfdaba9b92dfe2a81a419b71d6d326edfa87d7e531ad1ea9d80ae92dfb5222830bc0177c8fd15725dcdbff4e43dcdb1f31d51799c0efc53ef98384d1e89f7ff5dde5c1cb5bad0fd67d590e7a72e0879743a8ddb57efdcc2b8e9fe7ac9c8b38bc33554a61e6cecd413f4f2c873278811e7e75e895423f431dace3cd91c48623e6d60a99f3b302598a42dfd15c27b074f99fb7bd06f9b364345da5d847b70063c7f214936e58750227cbf17e7879bccd8246dfe289c53b6d8920313ee670a350ac903b86e5cfd6bb7902243d14b4999a0f5981d7e9d27ccd1a16a96e2547420a0d57bce2e2548c5cd38483f7f64a6e1ffb95443728ba7ef293722e3261ba8e97fe2d079c8d7c6e06b4d84031b0ffdd3b53d30850af8f44b66caae602d5442c4cd7033069663ad07447485ff43f4f5e9ffc11d6ae514bccb1e6520562bee0417f970c71feed831e0cb0c487a50455d73f309e900225c607727e5a1fba736fca5df0d08c02bd838519dd2da9d13fdd5887675970dea962a253456077a87e4a894795e152e08a1a9b3a5f47e009535eb3b71fe46434484584cb732e9195e49352990e729cc886a600185321bba6e9352121876d9c08a42bc8f81198f00a7fcd1fc4cacd0e39ae3699bdc5e6c06042782992f3eaca851a3d554b0b086b7fd3605f4f689fabdc35af4931742df2f5461eeb9b48595d7e419dcedff35771ce3db503f46eedbcb64b43ca0c83312913644b91da77878baee1ca28df0ab9167e92fbde92492baeb6eff13deb7daf3b146ca0fa89d2925b352e6930d3c698a925aec9ff9be647173ef2c2269bad44007a0e16f6d0a71ff84225926afc920626868bf5f8db1e0a592b9405a9af8cc0f691914696b85778a771336aa22ff1e816d7cc9100db922871ed6e7ab9c8302160c5ec5a25a9796af8eca079e0da34e3cbb2f2f2dda99405a52f90f5555a48cd3d0b08c51aeaddb750524683722ba7f3086842756ede54dcb7fdee72f80a3860c4773cf74f3e423fb5a47ced7ab76aa8b35124c99c1068fd84be381c97df8debdac7a684d559ef1f5db1d6e9137d8e1a0539ac4682b28e5deccbd7b69ff5abe5d6ea47f982853b4ecf457c87b0542cb46f1084089c3e6ab20e707db885a1e22ff62b322b95edebcb0297886bbf5701261d615baeab07e08f743e8abac604584990a06f1ce8fb302a7f3ff870b5b90edb7761349daef4feafbb86bf94981fd5d237d68668304cae275b09bbd9bb165a72c2cbd6bd936ebb88e10dac04dfe97751dd55262b31fced69d6c2383a2c9f1a35841ea52ddabcb5eb69e66fbf86919fbb89d007c9320e482508cbf69768d3b46887b07bd2220bba6ab90ed5cc9d4f5850c548469bfcd637c5bb605f91c63e6baf0943c1c63fe420951f3fbe1828d9fe4bb206b0d880bcf4cd32cd03bce70a0e1f80bf5bf91ee4cc8be7e358d702679f4ac1ef6fcd67091f2a6591f7a0aeb18e9bf056b867be4c5349887d7c1544763aed14b288ad9a8f29353728aed20391aa4dafca8b927bfe8d97a83847d29d3484f31c637f464af3613d0eb5db5899ba5cc918cd55731157e8ece1ca83c37d38eb37efdcacc677257c895d9d50e774a3d9ec50c9d164fb7a775cdd4afbf9c439c595872f6bd046650116bd1077ddd8a58121768b1e26c6174405a7c9855fd6d9e31ab093359cfd82dbae2d8f78dabc1897c54214c500a45118a2519dd19f47f594abfa18f7128a7a8362dbed7977fb8f386e2891da46768ffea8b229db1959f75fcb74f59de76fb94e1882c0b99ef25cbcc9fda4f98e8215c199fdc2c3581630d84b2a888576e4fc9b1cdd2e67ca02a95ba8b20464deabbbe6d7285304f0aae71153132c4d07a5018c08ed046af6ccaf1fee3e397c25bd038dadf46f4445b2917c8515554e61eb6a1eea497f225b502c4f8a2dc8aa01f9d8504e09e56c7a4e44a032b460c7d7f94da6b8325d523417aaed5b4773e44905e2d88afadb56d68957d2cf1782f56751e74579f466b6bb50c560e3f6e3dd17d827f4765547ca3de130ef12c1e6a80721f742c3459f393b18e4b55b7be430e490fc319734ed2411fa91eacf9cc87df54c527874ab0d768db5a2685776d0d68a814602657088f2586072e015c44ebd0b4364f8d56bea6407b8732de3ea1a2378a424a4b8fff27f3f3092184599056d2b9ccb3bca65f35a2b2ccb9860fca65aa8819e66542ab3fa041a5afa20f1f99f61b4e381a23888e5ca2e16961b96d5f28debc596ac48ac1c93cfcbfbd1f5ef12fde1b1d0c07af82c2c50c0b0fd44714f6c45b7f605cda15624c3ef7610799c95110b1803b6df01851a2bdce090886cc785244c972e35ae7397aa5297010dd0217fd92e180fb2a8ad5a6833a4829aa3147165df7eeeb23b3853efd5b97c47762a280a3965032c30a064f83efa07df1659b95e0ae3248ec863b773031ca43728aba7090c858f3585d498b5d37d3a996e2d7870c3af56bfa6063bc67b37ef86e2a01def825dc075e765cafee29457a0e275832387699f9ef1493ae19c8ddd7620b620fa7fd3d24878cc3b57c8585a5a5f05127db56d8d673693a120c1769279f3b9e52205004142a32bf59352c922b2cb3f16f0b38c33cb13a23ec28de10b1033bc61463ade186d014b0fef8c94f975ee7d9512a34bce833d51435c280cdb85c9e73369e0d3d434356b58ce1e982914dd7a41cdf1f02c0ae3f130013d2ff3bcd6746c86b1558533a0a44046ca41d63a8af5de8267db0c7ff7ee60ebe5b8bad7e90400dc83c9c86dd497887f3e60e744f17724015b876fe898abeea99871ae67a6ee530704c21582e0fc7b61605e63171b71b08ae197806a8c5c5eef88a295bd8ed57e5fb53da3bd75615700275e2ed364f97945e4f9b208402547faedf4553d49ea977b664bae3fd82c621f96f709c1a604471d2c1707bf6c8ac6cd4197f523d7555264f629189addc349438819ed634f7d3a2b256b71c934fc8c6874678d716fd6837ae989f81e301b5ab1ef70cc2633ac6086ebf3dd0bec407ba207d22efee31a1a604e6db1c1dd697e0ef5890881e07269d1cf35fe872e3985b3c93e8922b33e2f254f9328b5efae1f479858c5c8af645f321d5e9d315033730b419b36c54d87d79053275505ab233e209be2fd2b26554ab7d2899769c3f95a78f64fd983da03833d051167706eb3d7ca8928fa1b2e2c13a09e33f8c4f677a7cdf8626c34399a4bdea2f1492918e6c491940a3d39d2003b5edea4f0dff5c9512dbaa4a5a5fe8c04b3aae725e2a8a51d85f4f4d46c970248a15e8ad976a38fa0663b3a2f316c4e0e54a3bb4d8d94053f994b7c3163504fc516144ce8bfa1188ac47b789fcf036d6dbd88e5e0582ffefa6efccb0870e7f3fa0ae48927e9686afcf73fcce7ecdc54a6e059bd3b56d7289843fa612c8e04f597cfcedbd4e8547f893f858802fb3ac6946fd21077a2b224cdd87decf05462ca2fe3b1825f3b572d70ad28a369f98511ab9a1036cb9f7c6022ff9f3a112542e29a7adc21aa9356ee80672c7668c7125abe2a8ba6beccd51cc778111f63b7fe1cd1742d311b4a629fb414fa7de5d08f9bb3c4f52366996836be710ece9cf62a181db2baaf70401778d1aa4a4fe1263ed2dcbf27a611c4767e49908da1e9961c228d5f3b1ad0bd8e964eb6f6a35c7b5aea094d64740db9731ef000c59e524aa31dd8f0eb2326d9e9f2f5c73ce13abf39cfaf7b53b80a5e21f819b222aa4c04c97db252b63aed217d76f9e7635208515a7e6e605692c9ff16cb8992ef498e8df12471d3f8617da8e09ef5d9dbef8403e3565a8df9e776b2ac9dc2125972eb527875f1bada43daab9e3e8c41400a5d602be544196caaa09056b2df5f1ef5c99da6e597968dee41b8dff8022ad2ce39f43f5c42e8e78ee388fcd5fd76f035f848397c2c8e5f892dec065bd091b79a4217f52e42200855e70af982e64d6dc0469435efcdd1229354b6cddc41ff0d4593ea7e01a971d90fb41c6456996c8c487a087b8889ae49be0fd5bed0f73fdf6625c49aa05f9370a28b3f706561d8def0bf8ba86d8ba8805d3803311bebe96232d38be5eefb7be1354c3ebfae848ad1791a0cc0752d8d1f4497ff287226d456c84f4a91cd305d39db1d96c69bfbeedc38bea054a320cdeb2f096c8fb632c4cd1e7afbdcff79148e45ee11ae1f3840560c53d552a86c6edae2a617cb37623e8bf942efc0e6327a9fbb9c09aa99ad890d487b455325ef28a2939408fa52aa1f2c05e2a6f14cc6f154c94419e0773bfc8bfe5c3eead72c10c4bc763807861582fef330320eceebff9ed72be011d3334d7da7efa4e12511f3a268903e38692f0ff1d7bacba5e08add07ee32d116efdce13a1e6bd6cc187b859284a30b0ae5bdc6e3f40f8d633ab31455078be5f18649085f431d24e06b158cc48cededde25795c55c3c14e265b3280cbe7f6a139ef8dfab7ff29fda402a0b52b527664b79158cfd9b39f58de9c34553330080e7e7202b3753f5f6c6c1f2c6b780a98ab2c1451f29238b3188b5ef18441f8e97d8a80b7f7631f691e18b5ef6438b51fd704a3e6752190cc8ca40124c026e440c710e4e984e8d7fd0b6c7338e8b58ddc1a7fa48011db169ad6c3c18645bb6c93aad484e59968ba93d3cb6320be52d17224b8d55117ec10014094456525f83a6e23d5ca986ef5ea45a9a80088c6427983ca1f9d157358db071b89263f7e9e43f8e7f118c94d04bb7460b13d7717cc49a612c91919aeb07413aa330f006314760ca0e0075baefbdb3d490a8fc9139e82f49140c21700a3a25b1352228c1de1ac96e670c572e71c9b58f73ef42c5514209dc37d7bef9a404be9a7ff4d737ac5e06edbba50fee41754bb1be1684a7e134306c6df75b2e21a9b04f90ccbb29d0e034909108eed30e351c35c86160671e17afc1b9876691a2a37ab4e0c1330d19a85f4df85882eb7ee3c9d8c02d28f4304bee4693a37b8404c37218ed99dd172c4d323a2b57b925d4999b6ee7ae38e7175c4d823610649b2b8e3b56fd34478ae0440e32043f016a8233fe654e901b340079e52395a3808236738da058fda7b2881df822d63cc2722bcd3205b41794fe112324cf33a9b37f552e76266ad772ecbe11063868a0516a5ac0db2fe825f20c51f8bae1326f58a5aa12b0e4c17f58e67eaca630565740f94a892463d3964162e8672eacf509fd464bed767fed8c8d2344347f1b4b3595c2ab9ab22b6bf7bd306fe68eb79c07816e1d927e21f56947da0859f29f84c287e112538bfe46521587729fbf1282e8aeb42f4a5a0eab7b897d159d81b360a2671211954354f51adc95b2310e9ab70de57076a8e957c283727c3740dcc63db3dea2e80aca48dad0509497c5d7f50b7076e2495fdb2414c6b68d0695f4263a318feadd22101cd24c3a9b0642318e7c42a663839efcc8a560dc2da254866631e43bcf0fa64444679c8c331a7028580c7bf0a4ea6dc20781f349fafe5bb2dc9cd35809d54341b5cdb1c02b643e78518ff8dae84ddbf648044e7d5b64da0bbd1e16d9482a27ae7676fb0aecf6378e3b4727f59dbe71aedd91f3237183b4fe09e7dea59bbcecd070d9ecc5655c5c0dee77d0a089b00da80233775f4150465d3f365283b08fc64c8e36625f2c83d57566ed0ab8a8c2142caa08b70780415623b05595ab4814c1207f13f3923c0e262eda17208de4c9ddedee40dabf2f79b99b1fac0b16d9cc5278e3b92eba3fc6ec26f5c26aa76e473b53b067ad4abd98d1f05ca84a5b05960a3174dc5668fdfa43752765959395853dd4a1400c700000000000000000000000000000000009e70f20014004600ff0200000000000000000000000000010900b20049505653000000005d009c800400d6808e72427c39c18175780c73833f419c023648f7288cb652c708bce6e2cbb91eed6491c9c83db0639bf74fc99ca43b900bef48b25af5e7be7394761e103fc08199e58f691bc2aee071e3c0e472b41a50cad8b5e585fe00000075c83dcb6488e13c8792e6860b01b4800800bb00", @ANYRES32=r5, @ANYBLOB="0800f100ac1414bb08004300", @ANYRES32=r2, @ANYBLOB="0800ef00", @ANYRES32=r2, @ANYBLOB="2bf8164311f1ef243622669c85014a2f4c7c1acdc1bcaab0b7541f04737cc8fa4ce30a52a40584a9c4d4656d8ddd850503b5cda9a123ed93b6e5832ab8b6ed89d7244f3092912f7ca294118a6d562470a40f853279511cf3e05dd96939a272abbc2f0e2759430bd24dd51db6e54c79d7dd30fe65662c55fa7f9ba9666ddb2dccd5fae57428b608bca89bc3dfebb3abbec0257baf62b2c5e9b816e3fccdbfdde6296267970dc03afd858c21affcee268dbab01282b1299d0d68007a092111c530688262ca21fe5bd3924505e9764dee9b2463175d86c4884f963b4c9f791cfa1bc246b3e57f7b8f0009001000495056530000000000b304308041026a80f522f5ff9b172dbeff4d7fc1fb9c50784f6a86e438ec4a40c200e23f3756738e803718bac0af3fa811461bfd8bcf885b7d0301c605e17c4c130a5ded3fff307e8888e56e79c7080eec637b894d55227f9313cfe56029396078d92c84c72093abdc843f93d26b5787be50bccf82fff9231b4ab067ddfe599c58e5d21c5469c3400b3bd4ee3c8ccf650105ae869941257b0a22a52fff5b0840431d28c5659de005e8c7b4d853296ce2d1f246d99e77147af2dabecc9c7158ebad6a6bf88d5113d45950ba51b89960955d2e5ba6fcfcedefdf4afd77ac30605d8faf3513118c9a64018dca744f2fb7993d0b63d818900c30a84664bd32a277f67dcf2c4e8410148e1bd797091c29a39c3cbdb20bc20a9dd30e508efbd90df25ba33b582c0a3400db1455ecde1432dcce94b98f8c992bf59be0b2cae59ebb42c959f06550b4d99318206ae22ed545193816748f7a770aa59c040039800c009d000400000000000000e209e858a6d1c5159bd6c2d338cca3c53f37441dc38284550fd25cf479b8f3d29c6b5090d19d59d3582a1e2ba8c757f55b3e98105c85a2c5fe7aec004c36ecbee1ebd7369dd28e3875e5baaf22443f04717667330a4c85b88264516cb6071b9101ec7e30a44d0c531d54d7555fafb2d99761e1737aef3d44b8119cab1f4cd4628619eb244c1edd26f8bb755bc9baaa3e1146dec654b43d27e6518e18a50f6f62ae1c9cf3927692376121c96949ce2522a58cdb9a5329ed7766820c1189b08f329b3a3008e30800ed000500000004001d800c004a000d060000000000000000005e012c8008006a00", @ANYRES32=r5, @ANYBLOB="925b934aa6c7063c269a10968eb2fd125c25f7417cb70be51799df89bd4ee177744e285a6bc4419fc249bdfd7cf182420d93f81370fd74bd428e2590dff54568baa8466089b50b4773ca12c018dd69da2146a45da88af6581dd1527f3652d3a6957805deb184d1ed3c7cbb335b6c7d763a8c24359c175e6c15902fefcf6dd159ed6f44ac84fcdde3501f3f61a793dfdfdf2b7a68bf1cffd5365328d4c193081ec55738ae701f1c380bfab1b99cac799398aceeb11cfd108a60bf7cf12c9c18a866cbde58867c1fdc4af1d6cdb2425d8d650af07d3936dd3c3665e355795a1654d7a96a93caa21cad67204db6eb03743077c0361a3e26803ee2ea52e811a712fdc838b6949265784919c9aaecdb2aeb4cf99a5ba09a554605f2c464f8164a729987bbf4c1b081453d73776bf9b742e43e69ab2844df540a8791f21e1854ed377948f50800d500", @ANYRES32, @ANYBLOB='\b\x00,\x00', @ANYRES32=r0, @ANYBLOB="0000a733a8a36a351b77fb6c39e9eda58b76e99ef2b1115e91d9b91dfb6411ed9da4f7e40ce54c96e7470b6aac9a307984607cf2156b5e7e74091246d10090b2fb38f571ae4925b2e581503835e935d67e9da2e9e712737220751c69cd5ae630fe2ffdb304d075337479522c56d3d0cfadf71bb79a23809da6ce8c38567db600910ec51c6d0f86b9274f69b679568921970b8c28a17dd1aa7778cdf73c0df12968acc0fbe47fe1ae5bfcfb74ba62094b0b7f0c03a8177e310c3407e284db742f86261541dd84a49a31df1eb0c84b16c64827f8969826e396b192447d64b4f75f6cc5174a7535d1f3d3a6fe20c31b8cdd095ca58e847474ce1accfe95834b1bb62e0c000c8008001d000500000008002500", @ANYRES32=r4, @ANYBLOB="00e0002d80da0088808353bb9617be3d0d6e2e9362ef2583b1d61a1d6896a2fec5056e6d10bb40ffe2b7ccfa1946b0ab056f60d79193e4b0a1addc396f2c2b0a24f882b8aebfb9e9d7d6543eab558e89b1b24aaa719600a732a7d86b67c703b7499d883729404ae49d88cfff4a171858e3ff365f025971e4eb9ed8353251f7996e2e61f9661afdef279b9fffa9ff3143947d3c1218b50dfc64d14c1d4431062e011831389fa896ee1b4c4525aaf5aecdc00958a04236c22e6c4f73405367c80d504112e348081dd2d6aaf0b57a395d7cbc546e701bc98ce0632ece5faa6ac00000e8c09e6a703c2c6066df5fe6b8d181015e8feef1ad8cb149e7fdd3f96a9736db6f2a3a463e3ee007d21cd213a30fc3329ce5e034027cd88c2d06787096b8525f4545f61ef6104bdc0dccb48870ea482505c41e388d3504d12269abbc514071305510a62252c0effe609d2185ab615b0e79e05c6f422559d74b51b0dc43d5112bb1e63f74e224fa87c95c0d00f102b47c024053a1c937ac947ec62ec1c9b9f8b9beb59a2e822cae2b09972275d764160979ebaefe1ccfa745a12caf68cc8faed85dd4d59f3ec0417f712fb7af08300c8647adc1c489d246acc531db43c4ebcea0b68da5027e634469540ab4cdca851c402dbf2019f87ae9e688719acbc29dc80760c746b106dad409c45a5d7ec9723d93cc2993866bc35f5580172b0cd0079d3e3f5af3fbd6e9d233b66a6e7581baec5b91ef20c865b449f604b9af36b22b915ad23322722bfa817581e9cb871f88961985e9bf1e083ca99af3f3dc65ef51b7da222fb0907c87b42c2542264bde4325ea9bd38e78bca4851d2c1bd6ac52078328f308b5ac250a1c8ae090f72e2104b00dc164ae4370544ea31fd823961ef90fdd97a3f3d2aa522ba09ea8e3e786497766e9ed52f03718381689f6518e3bce3d975fd4ed7fe5f6976a4c25cc15bb13a9bdcfe4b0196dc6e41d2b85ff79afeaf94275f6cb8eae3ebfa1b2ac65b708ee18f3130006004d414338303231315f485753494d00003805f981f0f26eba5ce042cb2b0cc53784b5b221dcf0f17a365ad6524f80176019e7a8a8586850722157eeeb57e74f73ab4e067008000200", @ANYRES32=r4, @ANYBLOB="0800ca00", @ANYRES32=r5, @ANYBLOB="d2020380d9535d0cde1884ec1c541e13d8e593eed64b94dc0058bb1dda132e43daba5dc96361e2cd677f0193f2b25353e7afd902a0b53eb47bf07407b52ead73f32a1d4881e3e43d1ca77dd245e562bd7e027babb6e349ad11180532fabda6640e5b49a2194994d07a5270729135db92baea4de20c3c5ba10476ed2102df0b7f80b8c3efb8c8fad6fcc9f16f0f9952e8c8bc5cbf90366d38c4d222de7b1318a325dd67822408cfa9a091b926e62d87fea10633a0bc79c7b07eec1ffaca9aae19cded4b7c1499e6e4ddf1815ee22182e44b2a57b949c9c719965f3e58e84a5df104b5718884e0099b15db58ae6bcfa6c252986759179e8127cf435fd0702b14289ceb670f5230b5014c83fff7b882111bc853d86cc7c2abbe06ca7890ed8207c9da49815a06e30c8e62612c7e3c68f6ee95cf5ce3d2c0d6395e74357e7e5fade75eb852d71aa56c6aab628b81fdf40b8a37810033801300ff00e412b15d379169a0a0bec6309b0029002c0010004db8f3f1b88d62a991e3060c0942cee374a0648a29c23ecf338ed9fa70779c56370b921bcf804b2508005000ff7fffff04009580957d1e9e9dd7cd51a2bdf9e712c9faf1c60f917a3e067256685763e016ea8a18c762c154c5554d41e5fd685a9dc119b207000000be05b5406a2bbdcd4f6b5a0e64b86d342c2429b0f94e9b794a511231a4b7f2bd10d2bc3fbb6219772b7876799dcee87396492a8a70f19682912ee7675cb9696f0205cd8e43f4cc19294de8e82cb49e559dbda8ffc56a6b296b2398d74768971648ae785afa8a2d770ec8c090f1625227527992a0a1308b7166d5445bfd8829917ece912138d776384f30a473000e24dd8b6d6fe12c9518d83f57fa37278a4fc659dd8031a69484b4954b58fcec22523981b8a333d4b345e23fe89fe015a1aa4762cdfabadb4e01f84ab1cf2976f4f4b2d68902cbc039d25579b11536e18e559fc7289e86ea5621634cda8ecbed39cf3ce08e2c2986bf91fda3bced3f290000"], 0x1d78}}, 0x4000000) io_uring_setup$auto(0x6, 0x0) io_uring_register$auto(r1, 0x8, &(0x7f0000000040), 0x2000) r6 = socket$nl_generic(0x10, 0x3, 0x10) shmctl$auto_SHM_STAT(0x8, 0xd, &(0x7f0000000180)={{0x8, 0xee00, 0xffffffffffffffff, 0x7, 0x7, 0xc, 0xe}, 0x200, 0x8000, 0xb, 0x9, @inferred=0xffffffffffffffff, @inferred, 0x10, 0x0, &(0x7f0000000300)="6ee101a1a180b63943f2ffadd44423f52f066f6c359fba3cd5319b9bdd1e29654453bc92ac17442500345603255dc524b8a86fbf881c12d9b048a7634f344bf1e50db36ec94e697b553b8da58569495ad8517349af4df39044723b6b25552b31bb9f46e09e12a3957cb03404fc5595b08ebd57386e06a1fcb0d8348bc671419c634552c91dd786f1", &(0x7f00000003c0)="f758fb0ff9ac2018da2fc1c56683d73809ab5d8351cab5320a03bfbe5cd66e097a0dc1743d6d5c6e3e86fbfbf5d4bf48effee42890ad7fa98c8d11cd9ee5a75d2a713f0b0bd0ef62daf10e1735aba759e1acdb2b13ca48031e1346a33b2034babff608fbbdcbb938832a91c00f2a664b92796537eaccce4af3b6aafbbddb652371b7c4911dd4fba9fc9d5d0636d5d649cf56b37ee4e9d12c476a0484d3c8044f87a096"}) sendmsg$auto_SEG6_CMD_SETHMAC(r6, &(0x7f0000000900)={&(0x7f0000000140)={0x10, 0x0, 0x0, 0x400000}, 0xc, &(0x7f00000008c0)={&(0x7f0000000480)=ANY=[@ANYBLOB="083cee0c", @ANYRES16=0x0, @ANYBLOB="000228bd7000fcdbdf250100000005000600ff000000dc030780b6992bf4a6c5f82cae3928a69ab615bb049c059dc1834c7c53aa75337ec8a64b8e1396e9993915e2757037ee7795ac45be193803a43f32756ab08c9ea6d637cdcfdff0903e203cbdc73497ce806b3ce5861364c960f45cb0288a755340230017ec70c791c25dc8e962b8f4e011db6d7fcf2f5d3f25e72b696f0cc14bc70a481eca3732689fe6e99150e7a6a905a497be304b0e62404a747bcba5b99df457e839498cfa0641f1a6523bb7c04b0d8118296a6cc693622d7e3b1c6af8d9fff7fa99ed1254f00231800400d880704cdb320a83e8abbda2351f9070008f6f70756d729f29a8c41c065577e112c0cdc4aa8f410df2ee5df7d6304df4f9691fa9a16fe41877865de03c7e438f43a5924350fe38ee62760a330e75463ea1870c2794a855bd484ea6b014070efdf1cd4a5776289e1fc7bb7917d5e7cfb087e3b0a369c9ab07c2ea3ffccba50b99d84731a066e7a6813adf2cf007c5ad31ec09d84daeb6ba00d600694b1fd13b8242152a490598648e1afc09c45bb6f5806afb5b5754bb004063c6f750c8e56589ab9c5b5ec48d86330b9461dfcedd8207027389da5e9ccbbce511fc452a3c20f6ad9f02d5b023ca9ebab80a3defbd33710695a4b1fc81948470c385338fcced414d1d21c0014f0a8f1249370c809cc00e9a48fe7407addebb03c34c17ab2f66992cf57e71ef03e109f3b446ebbf6514c1f840d3018e3513dc1152d280a10e93a3c9e795fe7785d29f4e068069b96ef1520000037f0684e8900f043a0ee45356f3088acf5d8b0130ff5c468b6f4d7b37b0d18ac0be0ac07eddd96f20ca78836bf1716a04c687805947009dbc3d3f7c318dc849faad3fb44e802d7f7e1b36122fe70c0608bdb2d9ed58c3b57d81415c4d2eed44cadaf9ca88a86a32eec25049ebeb9675f8be07975ec5d1ee003800365c9509b420f2de99f4733b1a9cbc65b51e9d06dc5605a99fc6dcfc41fb984f340dc77a5605fa06513c3dc80c51e26b25d457692f393464ab71992b84004cc4865bb803d500d885fa58274304b5f95331f6ba8397242c478f0499bb11d41c821c265dac1febb75faeaf0a952a83c0b43dae2273587084d79a86afbd381283c766109be2b2733c569d0f3f661c6fae7792ef76fa5502af2de3d3015aab6be99d902b50abc04069397acc445268fec6842addb462eec2f1e7a72859c0e93401aeaa58cad15880efff3247738ba6d407eb82ba6748f6d5eac7ccc1e62736f509f7d608094f16f7e27c39fb0000170028002f6465762f736e642f636f6e74726f6c4332000008005b00", @ANYRES32=r7, @ANYBLOB="75173d187d6a648f378a0937bd04004c80291269681d7f6036d9d3b2d2ccf84df49363476631691aeef00c00880000000100000000000800030008000000050006007f000000"], 0x408}, 0x1, 0x0, 0x0, 0x10}, 0x4040010) sendmsg$auto_NL80211_CMD_GET_REG(0xffffffffffffffff, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000040)=ANY=[@ANYBLOB="72010000", @ANYBLOB="1a00"], 0x1ac}}, 0x40000) sendmsg$auto_NL80211_CMD_GET_REG(0xffffffffffffffff, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000040)=ANY=[], 0x1ac}, 0x1, 0x0, 0x0, 0x4004810}, 0x20000800) sendmmsg$auto(0xffffffffffffffff, &(0x7f0000000080)={{0x0, 0x2, &(0x7f00000002c0)={0x0, 0xc4}, 0x2, 0x0, 0x3, 0x9}, 0x7}, 0x3, 0x400000) setfsuid$auto(0xffffffffffffffff) recvmmsg$auto(r0, &(0x7f0000000100)={{0x0, 0x4, &(0x7f0000000080)={&(0x7f0000000040), 0xcb}, 0x3, 0x0, 0x80000000, 0x6}, 0x9}, 0x7, 0x6, 0x0) sendmsg$auto_NL80211_CMD_GET_REG(0xffffffffffffffff, &(0x7f00000000c0)={0x0, 0x0, &(0x7f0000000200)={0x0, 0x1ac}, 0x1, 0x0, 0x0, 0x4004810}, 0x800) sendmsg$auto_NETDEV_CMD_QUEUE_GET(0xffffffffffffffff, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)={&(0x7f0000000040)=ANY=[@ANYBLOB="14000000", @ANYRES16=0x0, @ANYBLOB="01002cbd7000fbdbdf250a"], 0x14}, 0x1, 0x0, 0x0, 0x40000}, 0x20008810) sendmsg$auto_NL80211_CMD_GET_REG(0xffffffffffffffff, &(0x7f0000000240)={0x0, 0x0, &(0x7f0000000200)={&(0x7f0000000040)=ANY=[@ANYBLOB="72010000", @ANYBLOB="19"], 0x1ac}}, 0x40000) sendmmsg$auto(0x3, &(0x7f0000000080)={{0x0, 0x1c03, &(0x7f0000000000)={0x0, 0xc4}, 0x1, 0x0, 0x0, 0x9}, 0x1}, 0x2, 0x0) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) r8 = openat$auto_tty_fops_tty_io(0xffffffffffffff9c, &(0x7f0000000000)='/dev/ptybc\x00', 0x8000, 0x0) r9 = openat$auto_snd_ctl_f_ops_control(0xffffffffffffff9c, &(0x7f0000000280)='/dev/snd/controlC2\x00', 0x80, 0x0) ioctl$auto(r9, 0xc0045520, r8) 10.520258764s ago: executing program 0 (id=1698): mount$auto(0x0, &(0x7f00000000c0)='.\x00', &(0x7f0000000180)='nfsd\x00', 0x8, 0x0) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) timer_create$auto(0x8, 0x0, 0x0) timer_settime$auto(0x0, 0x9, &(0x7f00000000c0)={{0x7fff, 0x30d}, {0x7, 0x4}}, 0x0) statmount$auto(0x0, &(0x7f0000000180)={0x8000008, 0x4, 0x389d, 0x3, 0x26, 0x940, 0x1ffde, 0x3, 0x4, 0x902a, 0x29, 0x400005, 0x3, 0x4, 0xb0, 0x8, 0x9, 0x3, 0x5, 0x6, 0x80000000, 0xffffffff, 0x4, 0x0, 0x0, 0x0, [0x3, 0x3, 0x200000000, 0x400000000, 0x0, 0x3903, 0x0, 0x8, 0xd, 0x7, 0x9, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffa, 0x0, 0x0, 0x0, 0x0, 0xffffffeffffffffe, 0xffffffff80000001, 0x0, 0xceb, 0xfffffffffffffffe, 0xfffffffffffffffc, 0xe539, 0x1, 0x96f, 0xffffffffffffffff, 0x1, 0x4001, 0x3, 0x0, 0x5, 0x8, 0x54c3, 0xfffffffffffffffd, 0x0, 0x0, 0x0, 0x4, 0x0, 0xfffffffffffffffb, 0x3]}, 0xfffff7fffffffffa, 0x81) r0 = openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000080)='/sys/devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A03:00/device:08/adr\x00', 0x0, 0x0) read$auto(r0, 0x0, 0x20) r1 = socket(0x28, 0x5, 0x0) sendmmsg$auto(0xffffffffffffffff, &(0x7f0000000080)={{0x0, 0x1, 0x0, 0x1, 0x0, 0x0, 0x9}, 0x7}, 0x3, 0x2) bind$auto(r1, &(0x7f0000000080)=@ethernet={0x306, @random="8c63feb39f3c"}, 0x3) mlockall$auto(0x7) adjtimex$auto(&(0x7f00000004c0)={0xf332b6e, 0x0, 0xfffffffffffffffc, 0xfffffffffffffffd, 0xd4, 0x1, 0x6, 0x0, 0x1, 0x368e, 0x2, {0x100000000, 0x10000}, 0x5, 0x6, 0xfffffffffffffffd, 0x1008000, 0x0, 0x9, 0x81, 0xffffffffffff628e, 0xa747, 0xdeb1, 0x804}) openat$auto_seq_oss_f_ops_seq_oss(0xffffffffffffff9c, &(0x7f0000000040)='/dev/sequencer2\x00', 0x2, 0x0) r2 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/midiC2D0\x00', 0x1, 0x0) write$auto(r2, &(0x7f0000000400)='/dev/audio1\x00', 0xa3d9) mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, r1, 0x80000000) r3 = socket$nl_generic(0x10, 0x3, 0x10) r4 = syz_genetlink_get_family_id$auto_l2tp(&(0x7f0000000100), 0xffffffffffffffff) openat$auto_iommufd_fops_main(0xffffffffffffff9c, 0x0, 0x80001, 0x0) sendmsg$auto_L2TP_CMD_TUNNEL_CREATE(r3, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000280)={&(0x7f00000002c0)=ANY=[@ANYBLOB='x\x00', @ANYRES16=r4, @ANYBLOB="01002dbd7000f9dbdf250100000005000d00100000000500070010000000080009009c781e2108000a000800000014001f000000000000000000c0feffff0000000014002000ff01fafffffd00000000"], 0x78}, 0x1, 0x0, 0x0, 0x40000}, 0x400c004) r5 = openat$auto_fuse_dev_operations_fuse_i(0xffffffffffffff9c, &(0x7f0000000140)='/dev/cuse\x00', 0x1c1041, 0x0) write$auto_fuse_dev_operations_fuse_i(r5, &(0x7f00000005c0)="1100000005000000000000000001000000", 0x11) r6 = openat$auto_proc_fail_nth_operations_base(0xffffffffffffff9c, &(0x7f0000000000)='/proc/thread-self/fail-nth\x00', 0x802, 0x0) writev$auto(r6, &(0x7f0000000200)={0x0, 0x7}, 0x3) timerfd_create$auto(0x8, 0x0) openat$auto_sg_fops_sg(0xffffffffffffff9c, 0x0, 0x82802, 0x0) timer_gettime$auto(0x0, 0x0) adjtimex$auto(&(0x7f0000000380)={0x8, 0x0, 0x2, 0xd, 0x5, 0x3, 0xd, 0x0, 0x4, 0x7, 0x800, {0x5, 0x2}, 0x2, 0x100000001, 0x8, 0x9, 0x0, 0x0, 0x7f, 0x3, 0x1, 0x40, 0x5}) pivot_root$auto(&(0x7f0000000600)='P\b\x04/u\xf34e', &(0x7f0000000480)='.\x00') 9.745519349s ago: executing program 3 (id=1700): mount$auto(0x0, &(0x7f00000000c0)='.\x00', &(0x7f0000000180)='nfsd\x00', 0x8, 0x0) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) timer_create$auto(0x8, 0x0, 0x0) timer_settime$auto(0x0, 0x9, &(0x7f00000000c0)={{0x7fff, 0x30d}, {0x7, 0x4}}, 0x0) mmap$auto(0x0, 0x400005, 0xffffffffffffffde, 0x14, 0x2, 0x8000) statmount$auto(0x0, &(0x7f0000000180)={0x8000008, 0x4, 0x389d, 0x3, 0x26, 0x940, 0x1ffde, 0x3, 0x4, 0x902a, 0x29, 0x400005, 0x3, 0x4, 0xb0, 0x8, 0x9, 0x3, 0x5, 0x6, 0x80000000, 0xffffffff, 0x4, 0x0, 0x0, 0x0, [0x3, 0x3, 0x200000000, 0x400000000, 0x0, 0x3903, 0x0, 0x8, 0xd, 0x7, 0x9, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffa, 0x0, 0x0, 0x0, 0x0, 0xffffffeffffffffe, 0xffffffff80000001, 0x0, 0xceb, 0xfffffffffffffffe, 0xfffffffffffffffc, 0xe539, 0x1, 0x96f, 0xffffffffffffffff, 0x1, 0x4001, 0x3, 0x0, 0x5, 0x8, 0x54c3, 0xfffffffffffffffd, 0x0, 0x0, 0x0, 0x4, 0x0, 0xfffffffffffffffb, 0x3]}, 0xfffff7fffffffffa, 0x81) r0 = openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000080)='/sys/devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A03:00/device:08/adr\x00', 0x0, 0x0) read$auto(r0, 0x0, 0x20) r1 = socket(0x28, 0x5, 0x0) bind$auto(r1, 0x0, 0x3) mlockall$auto(0x7) adjtimex$auto(&(0x7f00000004c0)={0xf332b6e, 0x0, 0xfffffffffffffffc, 0xfffffffffffffffd, 0xd4, 0x1, 0x6, 0x0, 0x1, 0x368e, 0x2, {0x100000000, 0x10000}, 0x5, 0x6, 0xfffffffffffffffd, 0x1008000, 0x0, 0x9, 0x81, 0xffffffffffff628e, 0xa747, 0xdeb1, 0x804}) openat$auto_seq_oss_f_ops_seq_oss(0xffffffffffffff9c, &(0x7f0000000040)='/dev/sequencer2\x00', 0x2, 0x0) r2 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/midiC2D0\x00', 0x1, 0x0) write$auto(r2, &(0x7f0000000400)='/dev/audio1\x00', 0xa3d9) mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, r1, 0x80000000) r3 = socket$nl_generic(0x10, 0x3, 0x10) r4 = syz_genetlink_get_family_id$auto_l2tp(&(0x7f0000000100), 0xffffffffffffffff) openat$auto_iommufd_fops_main(0xffffffffffffff9c, 0x0, 0x80001, 0x0) sendmsg$auto_L2TP_CMD_TUNNEL_CREATE(r3, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000280)={&(0x7f00000002c0)=ANY=[@ANYBLOB='x\x00\x00\x00', @ANYRES16=r4, @ANYBLOB="01002dbd7000f9dbdf250100000005000d00100000000500070010000000080009009c781e2108000a0008000000"], 0x78}, 0x1, 0x0, 0x0, 0x40000}, 0x400c004) r5 = openat$auto_fuse_dev_operations_fuse_i(0xffffffffffffff9c, &(0x7f0000000140)='/dev/cuse\x00', 0x1c1041, 0x0) write$auto_fuse_dev_operations_fuse_i(r5, &(0x7f00000005c0)="1100000005000000000000000001000000", 0x11) r6 = openat$auto_proc_fail_nth_operations_base(0xffffffffffffff9c, &(0x7f0000000000)='/proc/thread-self/fail-nth\x00', 0x802, 0x0) writev$auto(r6, &(0x7f0000000200)={0x0, 0x7}, 0x3) timerfd_create$auto(0x8, 0x0) openat$auto_sg_fops_sg(0xffffffffffffff9c, 0x0, 0x82802, 0x0) timer_gettime$auto(0x0, 0x0) adjtimex$auto(&(0x7f0000000380)={0x8, 0x0, 0x2, 0xd, 0x5, 0x3, 0xd, 0x0, 0x4, 0x7, 0x800, {0x5, 0x2}, 0x2, 0x100000001, 0x8, 0x9, 0x0, 0x0, 0x7f, 0x3, 0x1, 0x40, 0x5}) pivot_root$auto(&(0x7f0000000600)='P\b\x04/u\xf34e', &(0x7f0000000480)='.\x00') 9.688282442s ago: executing program 0 (id=1701): mount$auto(0x0, &(0x7f00000000c0)='.\x00', &(0x7f0000000180)='nfsd\x00', 0x8, 0x0) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) timer_create$auto(0x8, 0x0, 0x0) timer_settime$auto(0x0, 0x9, &(0x7f00000000c0)={{0x7fff, 0x30d}, {0x7, 0x4}}, 0x0) mmap$auto(0x0, 0x400005, 0xffffffffffffffde, 0x14, 0x2, 0x8000) statmount$auto(0x0, &(0x7f0000000180)={0x8000008, 0x4, 0x389d, 0x3, 0x26, 0x940, 0x1ffde, 0x3, 0x4, 0x902a, 0x29, 0x400005, 0x3, 0x4, 0xb0, 0x8, 0x9, 0x3, 0x5, 0x6, 0x80000000, 0xffffffff, 0x4, 0x0, 0x0, 0x0, [0x3, 0x3, 0x200000000, 0x400000000, 0x0, 0x3903, 0x0, 0x8, 0xd, 0x7, 0x9, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffa, 0x0, 0x0, 0x0, 0x0, 0xffffffeffffffffe, 0xffffffff80000001, 0x0, 0xceb, 0xfffffffffffffffe, 0xfffffffffffffffc, 0xe539, 0x1, 0x96f, 0xffffffffffffffff, 0x1, 0x4001, 0x3, 0x0, 0x5, 0x8, 0x54c3, 0xfffffffffffffffd, 0x0, 0x0, 0x0, 0x4, 0x0, 0xfffffffffffffffb, 0x3]}, 0xfffff7fffffffffa, 0x81) r0 = openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000080)='/sys/devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A03:00/device:08/adr\x00', 0x0, 0x0) read$auto(r0, 0x0, 0x20) r1 = socket(0x28, 0x5, 0x0) bind$auto(r1, 0x0, 0x3) mlockall$auto(0x7) adjtimex$auto(&(0x7f00000004c0)={0xf332b6e, 0x0, 0xfffffffffffffffc, 0xfffffffffffffffd, 0xd4, 0x1, 0x6, 0x0, 0x1, 0x368e, 0x2, {0x100000000, 0x10000}, 0x5, 0x6, 0xfffffffffffffffd, 0x1008000, 0x0, 0x9, 0x81, 0xffffffffffff628e, 0xa747, 0xdeb1, 0x804}) openat$auto_seq_oss_f_ops_seq_oss(0xffffffffffffff9c, &(0x7f0000000040)='/dev/sequencer2\x00', 0x2, 0x0) r2 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/midiC2D0\x00', 0x1, 0x0) write$auto(r2, &(0x7f0000000400)='/dev/audio1\x00', 0xa3d9) mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, r1, 0x80000000) r3 = socket$nl_generic(0x10, 0x3, 0x10) r4 = syz_genetlink_get_family_id$auto_l2tp(&(0x7f0000000100), 0xffffffffffffffff) openat$auto_iommufd_fops_main(0xffffffffffffff9c, 0x0, 0x80001, 0x0) sendmsg$auto_L2TP_CMD_TUNNEL_CREATE(r3, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000280)={&(0x7f00000002c0)=ANY=[@ANYBLOB='x\x00\x00\x00', @ANYRES16=r4, @ANYBLOB="01002dbd7000f9dbdf250100000005000d00100000000500070010000000080009009c781e2108000a000800000014001f000000000000000000c0feffff00000000140020"], 0x78}, 0x1, 0x0, 0x0, 0x40000}, 0x400c004) r5 = openat$auto_fuse_dev_operations_fuse_i(0xffffffffffffff9c, &(0x7f0000000140)='/dev/cuse\x00', 0x1c1041, 0x0) write$auto_fuse_dev_operations_fuse_i(r5, &(0x7f00000005c0)="1100000005000000000000000001000000", 0x11) r6 = openat$auto_proc_fail_nth_operations_base(0xffffffffffffff9c, &(0x7f0000000000)='/proc/thread-self/fail-nth\x00', 0x802, 0x0) writev$auto(r6, &(0x7f0000000200)={0x0, 0x7}, 0x3) timerfd_create$auto(0x8, 0x0) openat$auto_sg_fops_sg(0xffffffffffffff9c, 0x0, 0x82802, 0x0) timer_gettime$auto(0x0, 0x0) adjtimex$auto(&(0x7f0000000380)={0x8, 0x0, 0x2, 0xd, 0x5, 0x3, 0xd, 0x0, 0x4, 0x7, 0x800, {0x5, 0x2}, 0x2, 0x100000001, 0x8, 0x9, 0x0, 0x0, 0x7f, 0x3, 0x1, 0x40, 0x5}) pivot_root$auto(&(0x7f0000000600)='P\b\x04/u\xf34e', &(0x7f0000000480)='.\x00') 8.764669837s ago: executing program 0 (id=1706): sendmsg$auto_NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL(0xffffffffffffffff, 0x0, 0x20040045) pwrite64$auto(0xc8, 0x0, 0x6, 0x7a) mmap$auto(0x0, 0x400008, 0xdf, 0x9b7a, 0x2, 0x8000) madvise$auto(0x3, 0x6, 0x8) mlock$auto(0x1000, 0x6) mlockall$auto(0x800000000000005) pselect6$auto(0x8000, &(0x7f0000000080)={[0x800, 0x3, 0xb, 0xb9, 0x7, 0x7, 0x28, 0x4, 0x100, 0x8024, 0x3, 0xffffffffffff6ee4, 0x80, 0x47, 0x3, 0x40]}, &(0x7f0000000100)={[0xfffffffffffffffc, 0x8, 0x101, 0x4, 0xb, 0x0, 0x3f8b, 0xc, 0x2, 0x2, 0x7, 0x7f, 0x0, 0x800, 0x7fffffffffffffff, 0x6]}, &(0x7f0000000180)={[0x5d58, 0x7, 0xa5, 0x7f, 0xffffffffffffff63, 0x6, 0xfffffffffffffffa, 0x2001, 0x4, 0x7, 0x6, 0x8000, 0xc, 0x101, 0x4, 0x9]}, &(0x7f0000000200)={0x6, 0xac}, &(0x7f0000000240)="84564c8c26b8144fd4d3e1ecb7942bbed10faff85baff45164fe66cd970aa99ce6e0b82e3f049231ba73698898fcd2a65389893a8ce8b267d7aa4f5258122e0b18ac67ffde635cac8164af89d15c5b3222a32a0e03b46c0b57abb954eb9a7ba2e851d345c9e7319f0334e91d93a1a639c9a157cbd953f98a055c6326e49c3691aa27e73928cfc94b6ca85e02c62ac8fc9925f5c6481c62e36169492d6741aa7e32fbc03e9391f9b9b275e7e9551b938d5b80bafbdc1dd37bfb2772dbc29cf87b41fa609e535de02906ee62739ad3f141062547") madvise$auto(0x0, 0x200007, 0x19) mbind$auto(0x0, 0x2, 0x2, 0x0, 0x7, 0x0) write$auto(0x1, &(0x7f0000000000)='//\xf2\x00', 0x80000000) r0 = semctl$auto_IPC_RMID(0xf, 0x9, 0x0, 0xe2d0) process_vm_readv$auto(r0, &(0x7f0000000840)={&(0x7f0000000340)="06256a32415daf13edbdbd0b27f0fb57db0b503de2ee2338275ebffe51e681f9f8891ddaec874efde7fc91b28327ac21fd1230ab174ca619968f015fee9486a2c38050883ab722b93e236fe1beda4602253f1a6ffc5f280caccf0669ac8109710b23b843b1eaf1082dc322f5737c9d1c51c4e940012ebc9010b9cd5b3a828aa1dee58ba6a81d348144e9a5cef32434ef012b00953c5f7606feda1d73eac4a5a76860cd87ccbd3aff6fcb408e9d3dac9f23233a8564564142c36f21e9", 0x8001}, 0x3, &(0x7f0000000580)={&(0x7f0000000480)="3a9371856a0fe2d687c96782e1476ef6ad3e145f06fe222588077d601e36f5e89468704e08b6afa3dd979358134bef39e9dc013001b0c99781d1184f1346cfc935f785b8f59a181ae9c6e677be87d6a07045ef3577e3b3227fbd957d9c0ae56fc012267f9c05a01cc9eee7f4aa5ba889c375bf4db8498d16c0c5217b46d1bb099c448326a8051c8ae637b54d42aa751c4651cbb0e44570ef625431bdc08397b999b0dc33d2ba5ee883890a3b09003d0941fd4604f10157d4dea7bfa9efc4b789e445a7fd2512d47be9b8915b024f5dea0a81fcb6550dd8ff3eee9d04c1ca4b4f7045ad7ecea22c3826134eecabfc5e", 0xb3c}, 0x3, 0x40) ioperm$auto(0x7, 0x6, 0x1) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) openat$auto_snd_pcm_f_ops_pcm(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/pcmC1D1p\x00', 0x80, 0x0) socket(0x2b, 0x1, 0x0) open(&(0x7f0000000000)='./file0\x00', 0x261c2, 0x84) r1 = socket$nl_generic(0x10, 0x3, 0x10) ioctl$sock_SIOCGIFINDEX(r1, 0x8933, &(0x7f0000000000)={'syz_tun\x00'}) close_range$auto(0x0, 0xfffffffffffff000, 0x4000000000002) socket$nl_generic(0x10, 0x3, 0x10) socket(0x26, 0x80805, 0x0) clone$auto(0x20003b46, 0x2, 0x0, 0x0, 0x2) pidfd_getfd$auto(0x3, 0x1, 0x100000000) 7.585752726s ago: executing program 1 (id=1707): mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, 0x2, 0x800008000) madvise$auto(0x0, 0xffffffffffff0001, 0x15) openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, 0x0, 0x80002, 0x0) read$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffffff, 0x0, 0x0) prctl$auto(0x7fff, 0x1, 0x4, 0x5, 0x80000000000000a) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) r0 = openat$auto_vhost_vsock_fops_vsock(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) poll$auto(&(0x7f0000000180)={r0, 0xfff7, 0x9816}, 0x7f, 0x9) ioctl$auto_VHOST_SET_OWNER(r1, 0xaf01, 0x0) ioctl$auto(r1, 0x9, r0) ioctl$auto_VHOST_VSOCK_SET_RUNNING(r0, 0x4004af61, 0x0) openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000000)='/sys/devices/virtual/net/bond0/bonding/lacp_active\x00', 0x80, 0x0) ioctl$auto(0xffffffffffffffff, 0x4bfa, 0xffffffffffffffff) r2 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$auto_ovs_ct_limit(&(0x7f0000000840), r2) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) madvise$auto(0x0, 0xffffffffffff0005, 0x17) setgroups$auto(0xe32, 0x0) madvise$auto(0x0, 0x200007, 0x19) r3 = openat$auto_def_blk_fops_fs(0xffffffffffffff9c, &(0x7f0000000100)='/dev/loop6\x00', 0x8081, 0x0) close_range$auto(0x0, 0xfffffffffffff000, 0x2) openat$auto_userio_fops_userio(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) r4 = openat$auto_snd_pcm_f_ops_pcm(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/pcmC1D1p\x00', 0x0, 0x0) ioctl$auto_SNDRV_PCM_IOCTL_LINK(r4, 0x40044160, 0x0) ioctl$auto_SG_GET_RESERVED_SIZE(r3, 0x4c04, 0x0) mmap$auto(0x0, 0x128009, 0xdf, 0xeb1, 0x401, 0x8000) capget$auto(0x0, 0xfffffffffffffffe) remap_file_pages$auto(0x6a27, 0x1000, 0x0, 0xb74, 0x66a) madvise$auto(0x0, 0xffffffffffff0001, 0x15) 7.519264536s ago: executing program 0 (id=1708): mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, 0x2, 0x800008000) madvise$auto(0x0, 0xffffffffffff0001, 0x15) openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, 0x0, 0x80002, 0x0) read$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffffff, 0x0, 0x0) prctl$auto(0x7fff, 0x1, 0x4, 0x5, 0x80000000000000a) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) r0 = openat$auto_vhost_vsock_fops_vsock(0xffffffffffffff9c, &(0x7f0000000300), 0x0, 0x0) poll$auto(&(0x7f0000000180)={r0, 0xfff7, 0x9816}, 0x7f, 0x9) ioctl$auto_VHOST_SET_OWNER(r1, 0xaf01, 0x0) capset$auto(0x0, 0x0) ioctl$auto_VHOST_VSOCK_SET_RUNNING(r0, 0x4004af61, 0x0) openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000000)='/sys/devices/virtual/net/bond0/bonding/lacp_active\x00', 0x80, 0x0) ioctl$auto(0xffffffffffffffff, 0x4bfa, 0xffffffffffffffff) r2 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$auto_ovs_ct_limit(&(0x7f0000000840), r2) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) madvise$auto(0x0, 0xffffffffffff0005, 0x17) setgroups$auto(0xe32, 0x0) madvise$auto(0x0, 0x200007, 0x19) r3 = openat$auto_def_blk_fops_fs(0xffffffffffffff9c, &(0x7f0000000100)='/dev/loop6\x00', 0x8081, 0x0) close_range$auto(0x0, 0xfffffffffffff000, 0x2) openat$auto_userio_fops_userio(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) r4 = openat$auto_snd_pcm_f_ops_pcm(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/pcmC1D1p\x00', 0x0, 0x0) ioctl$auto_SNDRV_PCM_IOCTL_LINK(r4, 0x40044160, 0x0) ioctl$auto_SG_GET_RESERVED_SIZE(r3, 0x4c04, 0x0) mmap$auto(0x0, 0x128009, 0xdf, 0xeb1, 0x401, 0x8000) capget$auto(0x0, 0xfffffffffffffffe) remap_file_pages$auto(0x6a27, 0x1000, 0x0, 0xb74, 0x66a) madvise$auto(0x0, 0xffffffffffff0001, 0x15) 7.347009327s ago: executing program 3 (id=1709): mmap$auto(0x0, 0x2, 0xdf, 0x9b72, 0x2, 0x8000) io_uring_setup$auto(0x4, 0x0) close_range$auto(0x2, 0x8, 0x0) mmap$auto(0x0, 0x20009, 0xdf, 0xeb1, 0x40000000000a5, 0x8000) mmap$auto(0x0, 0x2020009, 0xa, 0xeb1, 0xfffffffffffffffa, 0x8000) sysfs$auto(0x2, 0x10000000000048, 0x0) r0 = openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000000)='/sys/devices/virtual/block/nbd5/queue/optimal_io_size\x00', 0x800, 0x0) read$auto_kernfs_file_fops_kernfs_internal(r0, &(0x7f0000000380)=""/172, 0xac) io_uring_setup$auto(0x6, 0x0) close_range$auto(0x2, 0x8, 0x0) r1 = openat$auto_kvm_chardev_ops_kvm_main(0xffffffffffffff9c, &(0x7f00000011c0), 0xe0180, 0x0) ioctl$auto_KVM_CREATE_VM(r1, 0xae01, 0x0) close_range$auto(0x0, 0xfffffffffffff000, 0x4000000000002) r2 = openat$auto_proc_reg_file_ops_compat_inode(0xffffffffffffff9c, &(0x7f00000000c0)='/proc/self/net/vlan/config\x00', 0xc0000, 0x0) pread64$auto(r2, &(0x7f0000000300)='K\x1da\"\x1eH\xcc4\xeb\x01\n\xe5\x01\xc19\x80\xbd\xd3\xf2\xdfz\xc9gy\xd9\xf4\xbb\xdc\xb5\x7f\xb6\x19q\xe2\xc8d\xd6@\xdb\x9bs\x19\xab\x03>YV\xe7\x93\xce\xf4\xd4k\xa4\x9d\xe9\'?\x16y4lX\xb9\xa6=Yo\x9f%\xb1\'%\x86\x8f\x93\xb7l\x15\x9c\x1b\xaf\x9f\x13\x01\xe9y\xa8\x92Y\x1c>\xd2\xf6\x81\xf8\xd4\x8d\xb6*\xa17j\xd5\xdah\xc7\x13\x16o\x18\xdcPD\x8f\x8e1\xac\x82HH\xee\fd\xf9E\xdeBy\x128\xba\x8f\xf9w\x95\xa0*[\a\x8ed\x02', 0x6d, 0x7) r3 = socket$nl_generic(0x10, 0x3, 0x10) mmap$auto(0x0, 0x400005, 0xdf, 0x9b72, 0x2, 0x8000) io_uring_setup$auto(0x6, 0x0) writev$auto(0xffffffffffffffff, 0x0, 0x3) syz_clone(0x11, 0x0, 0x0, 0x0, 0x0, 0x0) r4 = openat$auto_snd_pcm_oss_f_reg_pcm_oss(0xffffffffffffff9c, &(0x7f0000000100)='/dev/dsp\x00', 0x20342, 0x0) ppoll$auto(&(0x7f0000000000)={r4, 0x3f, 0x2}, 0x4, 0x0, 0x0, 0x8) read$auto_nsim_dev_trap_fa_cookie_fops_dev(r5, &(0x7f0000000300)=""/243, 0xf3) close_range$auto(0x2, 0xa, 0x0) r6 = mq_open$auto(0x0, 0xdd1, 0x8, 0x0) mq_notify$auto(r6, &(0x7f0000000200)={@sival_ptr=0x0, @inferred=r3, 0x2, @_tid}) futex_wait$auto(0x0, 0x0, 0x7f, 0x2, 0x0, 0x1) futex_wake$auto(0x0, 0x8, 0x7, 0x2) mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, 0x2, 0x8000) setsockopt$auto(0x5, 0x104000000000010e, 0x1, 0x0, 0x16) 5.148717209s ago: executing program 2 (id=1712): close_range$auto(0xffffffffffffffff, 0x8, 0x0) socket(0x2b, 0x1, 0x0) r0 = socket(0x2c, 0x3, 0x0) r1 = syz_genetlink_get_family_id$auto_gtp(0x0, 0xffffffffffffffff) sendmsg$auto_GTP_CMD_DELPDP(r0, &(0x7f0000000200)={&(0x7f0000000100)={0x10, 0x0, 0x0, 0x40000}, 0xc, &(0x7f00000001c0)={&(0x7f0000000140)={0x64, r1, 0x200, 0x70bd2c, 0x25dfdbfd, {}, [@GTPA_TID={0xc, 0x3, 0x7}, @GTPA_PEER_ADDRESS={0x8, 0x4, @multicast2}, @GTPA_MS_ADDR6={0x14, 0xc, @mcast2}, @GTPA_MS_ADDR6={0x14, 0xc, @ipv4={'\x00', '\xff\xff', @rand_addr=0x64010100}}, @GTPA_TID={0xc, 0x3, 0x5}, @GTPA_FAMILY={0x5, 0xd, 0x81}]}, 0x64}, 0x1, 0x0, 0x0, 0x24040080}, 0x20000004) mmap$auto(0x0, 0x20009, 0x4000000000df, 0xeb1, 0x401, 0x8000) r2 = openat$auto_proc_oom_adj_operations_base(0xffffffffffffff9c, &(0x7f0000000000)='/proc/self/oom_adj\x00', 0x48402, 0x0) read$auto(r2, 0x0, 0x1f40) sendmsg$auto_NET_SHAPER_CMD_GET2(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, &(0x7f00000001c0)={&(0x7f0000000280)=ANY=[@ANYBLOB="14000000", @ANYRES16=0x0, @ANYBLOB="010029bd7000fcdbdf2501000000fc7cf35bc52af9139e22f6d7902f6a276987314199fa1d82c2c5f8ea46a480cea76f72186cd0dbe3ff7a663dce"], 0x14}, 0x1, 0x0, 0x0, 0x60040010}, 0x10) writev$auto(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x7}, 0x3) bpf$auto(0x0, &(0x7f00000001c0)=@task_fd_query={0x9, 0x21eb, 0x7ff, 0x6, 0xa, 0x1000009, 0x5f, 0x0, 0x3}, 0x6f3) openat$auto_snd_pcm_oss_f_reg_pcm_oss(0xffffffffffffff9c, &(0x7f00000000c0)='/dev/audio1\x00', 0x40000, 0x0) set_mempolicy$auto(0x9, &(0x7f00000000c0)=0x800, 0x7) socket(0xa, 0x2, 0x73) setsockopt$auto(0x4, 0x29, 0x1, 0x0, 0x8) mmap$auto(0x0, 0x20009, 0xdf, 0xeb1, 0x40000000000a5, 0x8000) adjtimex$auto(&(0x7f00000004c0)={0xf332b6e, 0x0, 0x0, 0xfffffffffffffffd, 0xd4, 0x7fffffff, 0x8000006, 0x0, 0xa89e, 0x3690, 0x2, {0xfffffffc, 0x10000}, 0x5, 0x6, 0xffffffffffffffff, 0x1008000, 0x0, 0x80000080000004, 0x84, 0xffffffffffff6291, 0xffff, 0xdeb1, 0x806}) r3 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/midiC2D0\x00', 0x1, 0x0) write$auto(r3, &(0x7f0000000400)='/dev/audio1\x00', 0xa3d9) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) getrandom$auto(0x0, 0x6000000, 0x3) keyctl$auto(0x1d, 0x725fffffffb, 0x69c9, 0x2, 0x6) bind$auto(0x3, &(0x7f0000000040)=@in={0x2, 0x3, @empty}, 0x6a) connect$auto(0x3, &(0x7f0000000080)=@in={0x2, 0x3, @dev={0xac, 0x14, 0x14, 0x14}}, 0x54) recvmmsg$auto(0x3, 0x0, 0x10810, 0x0, 0x0) 4.220436144s ago: executing program 1 (id=1713): close_range$auto(0x0, 0xfffffffffffff000, 0x4000000000002) r0 = openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000480)='/sys/module/zswap/parameters/compressor\x00', 0x80002, 0x0) openat$auto_proc_pagemap_operations_internal(0xffffffffffffff9c, &(0x7f0000000100)='/proc/self/pagemap\x00', 0x900, 0x0) r1 = openat$auto_drm_crtc_crc_data_fops_drm_debugfs_crc(0xffffffffffffff9c, &(0x7f0000000200), 0x8000, 0x0) read$auto_drm_crtc_crc_data_fops_drm_debugfs_crc(r1, 0x0, 0x0) write$auto_ocfs2_control_fops_stack_user(r0, &(0x7f0000003900)='\t', 0x1) r2 = socket(0x10, 0x2, 0x6) r3 = syz_genetlink_get_family_id$auto_nl802154(&(0x7f0000000040), 0xffffffffffffffff) adjtimex$auto(&(0x7f00000004c0)={0xf332b6d, 0x0, 0x0, 0xfffffffffffffffd, 0xd4, 0x1, 0x6, 0x0, 0x1, 0x5b8f5189, 0xc, {0x100000000, 0x10000}, 0x5, 0x6, 0xfffffffffffffffd, 0x1008000, 0x0, 0x80000004, 0x81, 0xffffffffffff628e, 0xa747, 0xdeb1, 0x804}) openat$auto_seq_oss_f_ops_seq_oss(0xffffffffffffff9c, &(0x7f0000000080)='/dev/sequencer2\x00', 0x2, 0x0) r4 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/midiC2D0\x00', 0x1, 0x0) write$auto(r4, &(0x7f0000000400)='/dev/audio1\x00', 0xa3d9) r5 = mq_open$auto(&(0x7f00000005c0)='\x12\xe6D\b\x9e\x00\x80\x8d\f\xb9w-\xbd!\x9eb\xed\xfb\x0f\xe5\x9dZ\xc2\xd1\x01wBV\x91\x8f_\xc0.\x84\xfe\x84\xd1se\x01\x06\x00\xb3\x13_Y&\xa9\x88\xe4\xa2\xb0V\x85\x92<\xb6\xdcT \\\xf2\v\xb1\xe2\xd8\xfa\xd8V\xe5\x00\xfa\xe9!\xc5<\xce\x18=\x06\xdagq\xb5\r\t\xb2\xde\x99\xd50\xbb\x192\x1c4\x86\xc0\xc1-\xd5\x10\xc3\xfc*[8\x89h\xc5\xba\xff\xc8u50xffffffffffffffff, 0xfff7, 0x9816}, 0x7f, 0x9) ioctl$auto_VHOST_SET_OWNER(r0, 0xaf01, 0x0) ioctl$auto(r0, 0x9, 0xffffffffffffffff) capset$auto(0x0, 0x0) ioctl$auto_VHOST_VSOCK_SET_RUNNING(0xffffffffffffffff, 0x4004af61, 0x0) openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000000)='/sys/devices/virtual/net/bond0/bonding/lacp_active\x00', 0x80, 0x0) ioctl$auto(0xffffffffffffffff, 0x4bfa, 0xffffffffffffffff) r1 = socket$nl_generic(0x10, 0x3, 0x10) syz_genetlink_get_family_id$auto_ovs_ct_limit(&(0x7f0000000840), r1) mmap$auto(0x0, 0x2020009, 0x3, 0xeb1, 0xfffffffffffffffa, 0x8000) madvise$auto(0x0, 0xffffffffffff0005, 0x17) setgroups$auto(0xe32, 0x0) madvise$auto(0x0, 0x200007, 0x19) r2 = openat$auto_def_blk_fops_fs(0xffffffffffffff9c, &(0x7f0000000100)='/dev/loop6\x00', 0x8081, 0x0) close_range$auto(0x0, 0xfffffffffffff000, 0x2) openat$auto_userio_fops_userio(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) r3 = openat$auto_snd_pcm_f_ops_pcm(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/pcmC1D1p\x00', 0x0, 0x0) ioctl$auto_SNDRV_PCM_IOCTL_LINK(r3, 0x40044160, 0x0) ioctl$auto_SG_GET_RESERVED_SIZE(r2, 0x4c04, 0x0) mmap$auto(0x0, 0x128009, 0xdf, 0xeb1, 0x401, 0x8000) capget$auto(0x0, 0xfffffffffffffffe) remap_file_pages$auto(0x6a27, 0x1000, 0x0, 0xb74, 0x66a) madvise$auto(0x0, 0xffffffffffff0001, 0x15) 379.788601ms ago: executing program 2 (id=1725): clock_getres$auto(0x8, 0x0) close_range$auto(0x2, 0x8, 0x0) openat$auto_proc_loginuid_operations_base(0xffffffffffffff9c, &(0x7f00000001c0)='/proc/thread-self/loginuid\x00', 0x3c8082, 0x0) socket$nl_generic(0x10, 0x3, 0x10) socket(0x2b, 0x1, 0x0) socket(0xa, 0x801, 0x84) socket(0x15, 0x3, 0x106) mmap$auto(0x0, 0x6, 0x2, 0x9b72, 0x2, 0x8000) futex$auto(0x0, 0x6, 0x47, 0x0, 0x0, 0x0) setsockopt$auto(0x3, 0x1, 0x3e, 0x0, 0x9) socket(0x2c, 0x3, 0x0) adjtimex$auto(&(0x7f00000004c0)={0x5, 0x0, 0x0, 0xfffffffffffffffd, 0xd4, 0x7fffffff, 0x6, 0x0, 0xa89e, 0x3690, 0x2, {0xfffffffc, 0x10000}, 0x5, 0x2, 0xffffffffffffffff, 0x1008000, 0x0, 0x4, 0x84, 0xffffffffffff6291, 0x10001, 0xdeb1, 0x806}) mmap$auto(0x0, 0x9, 0xdf, 0xeb1, 0x401, 0x7ffc) close_range$auto(0x2, 0x8, 0x0) r0 = eventfd$auto(0x3) sendmsg$auto_THERMAL_GENL_CMD_THRESHOLD_ADD(r0, &(0x7f0000000200)={&(0x7f00000000c0)={0x10, 0x0, 0x0, 0x800}, 0xc, &(0x7f0000000180)={&(0x7f0000000240)=ANY=[], 0x24}, 0x1, 0x0, 0x0, 0x22000}, 0xf0e07cce7780fd87) socketpair$auto(0x9, 0x2, 0xb, 0x0) openat$auto_tty_fops_tty_io(0xffffffffffffff9c, &(0x7f0000000080)='/dev/ptyw6\x00', 0x0, 0x0) ioctl$auto(0x3, 0x5401, 0x1) openat$auto_seq_oss_f_ops_seq_oss(0xffffffffffffff9c, &(0x7f0000000080)='/dev/sequencer2\x00', 0x2, 0x0) r1 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000100)='/dev/snd/midiC2D0\x00', 0x40401, 0x0) write$auto(r1, &(0x7f0000000400)='/dev/audio1\x00', 0xa3d9) bind$auto(0x3, &(0x7f0000000040)=@in={0x2, 0x3, @empty}, 0x6a) mmap$auto(0x0, 0x20009, 0xdf, 0xeb1, 0x401, 0x8000) close_range$auto(0x2, 0x8, 0x0) socket$nl_generic(0x10, 0x3, 0x10) io_uring_setup$auto(0x1, 0x0) openat$auto_kernfs_file_fops_kernfs_internal(0xffffffffffffff9c, &(0x7f0000000000)='/sys/devices/system/memory/memory12/power/control\x00', 0x100, 0x0) r2 = openat$auto_proc_reg_file_ops_compat_inode(0xffffffffffffff9c, &(0x7f0000000080)='/proc/fs/jbd2/sda1-8/info\x00', 0x2, 0x0) read$auto_proc_reg_file_ops_compat_inode(r2, &(0x7f00000000c0)=""/10, 0xa) 136.695942ms ago: executing program 2 (id=1726): openat$auto_posix_clock_file_operations_posix_clock(0xffffffffffffff9c, 0x0, 0x0, 0x0) openat$auto_drm_edid_fops_drm_debugfs(0xffffffffffffff9c, 0x0, 0x40901, 0x0) adjtimex$auto(&(0x7f00000004c0)={0xf332b6e, 0x0, 0x0, 0xfffffffffffffffd, 0xd4, 0x1, 0x6, 0x0, 0x1, 0x368e, 0x2, {0x100000000, 0x10000}, 0x5, 0x6, 0xfffffffffffffffd, 0x1008000, 0x0, 0x9, 0x81, 0xdfffffffffff628e, 0x6, 0xdeb1, 0x808}) socket(0x2b, 0x1, 0x1) openat$auto_seq_oss_f_ops_seq_oss(0xffffffffffffff9c, &(0x7f0000000080)='/dev/sequencer2\x00', 0x2, 0x0) r0 = openat$auto_snd_rawmidi_f_ops_rawmidi(0xffffffffffffff9c, &(0x7f0000000000)='/dev/snd/midiC2D1\x00', 0x1, 0x0) write$auto(r0, &(0x7f0000000400)='/dev/audio1\x00', 0xa3db) openat$auto_proc_reg_file_ops_compat_inode(0xffffffffffffff9c, 0x0, 0x4a801, 0x0) openat$auto_uprobe_events_ops_trace_uprobe(0xffffffffffffff9c, 0x0, 0x12000, 0x0) socket(0x3, 0x5, 0x5) r1 = openat$auto_mtd_fops_mtdchar(0xffffffffffffff9c, &(0x7f00000000c0)='/dev/mtd0ro\x00', 0x2000, 0x0) sendmsg$auto_SMC_NETLINK_DISABLE_SEID(0xffffffffffffffff, &(0x7f0000000140)={0x0, 0x0, &(0x7f0000000100)={&(0x7f00000001c0)=ANY=[@ANYBLOB="b30000c4acc64e6db6d344dafa772e702fbb1dd5276186c557bb1869f6a7a444861ed9130000995aecaec6fb535f6b7124c15f5573c3529dd7549e7f1b3706dc2eee524c6e554298bff456895cbd0ef84796eec97de123d41f7ffc", @ANYRES16=0x0, @ANYBLOB="010026bd7000080000000f000000"], 0x14}, 0x1, 0x0, 0x0, 0x880}, 0x810) r2 = syz_genetlink_get_family_id$auto_ovs_flow(&(0x7f0000000180), 0xffffffffffffffff) r3 = socket$nl_generic(0x10, 0x3, 0x10) sendmsg$auto_OVS_FLOW_CMD_GET(r3, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000040)={&(0x7f0000000000)=ANY=[@ANYBLOB='$\x00\x00\x00', @ANYRES16=r2, @ANYBLOB="010029bd700001dcdf2503000000040006000c000180080010000400"], 0x24}, 0x1, 0x0, 0x0, 0x40010}, 0x800) ioctl$auto_MTDFILEMODE(r1, 0x4d13, 0x0) ioctl$auto_SNDCTL_DSP_SPEED(0xffffffffffffffff, 0xc0045002, &(0x7f00000002c0)="3098412d1d2a21f9821bbb6575682f4fa969d6d8f51ad133eb2fb3cd698bac435177fc1942f009b507130df5d599f4ff6031c5518c8e660d59059846f0326039e724f62ba81e019302f5") sendmsg$auto_OVS_PACKET_CMD_EXECUTE(0xffffffffffffffff, &(0x7f0000000000)={0x0, 0x0, 0x0, 0x1, 0x0, 0x0, 0x4004040}, 0xc800) r4 = eventfd$auto(0x34b) readv$auto(r4, &(0x7f0000000380)={0x0, 0x8}, 0x4) read$auto(r4, 0x0, 0xcc9c) write$auto(r4, &(0x7f0000000400)='\'\x00', 0x8) r5 = socket(0xa, 0x5, 0x84) sendto$auto(r5, 0x0, 0x401, 0x7f, &(0x7f0000000000)=@generic={0xa, "e2e18340cba8fe80fffe00000010"}, 0x1c) 0s ago: executing program 1 (id=1727): getpgid$auto(0xffffffffffffffff) fcntl$getown(0xffffffffffffffff, 0x9) r0 = socket(0x2, 0x801, 0x100) connect$auto(0x3, &(0x7f00000000c0), 0x55) connect$auto(0x3, &(0x7f00000000c0), 0x55) ioctl$sock_SIOCGIFINDEX(0xffffffffffffffff, 0x8933, &(0x7f0000000000)={'wlan1\x00', 0x0}) r2 = prctl$auto_PR_GET_TSC(0x19, 0xfff, 0x0, 0x0, 0x10000) read$auto_proc_mountinfo_operations_mnt_namespace(r2, &(0x7f0000000280)=""/28, 0x1c) r3 = socket(0x11, 0x3, 0x9) r4 = prctl$auto_PR_SET_MM_START_BRK(0x90e6, 0x6, 0x0, 0x8, 0x9) syz_genetlink_get_family_id$auto_nfsd(&(0x7f0000000040), r4) r5 = syz_genetlink_get_family_id$auto_hsr(&(0x7f0000000140), r0) mmap$auto(0x0, 0x20009, 0x20000000000000e2, 0xeb1, 0x405, 0x8000) r6 = openat$auto_snd_mixer_oss_f_ops_mixer_oss(0xffffffffffffff9c, &(0x7f00000004c0)='/dev/mixer\x00', 0x40000, 0x0) ioctl$auto_SOUND_MIXER_WRITE_RECSRC(r6, 0xc0044dff, 0x0) sendmsg$auto_HSR_C_GET_NODE_STATUS(r0, &(0x7f0000000240)={&(0x7f0000000080)={0x10, 0x0, 0x0, 0x8000000}, 0xc, &(0x7f0000000200)={&(0x7f0000000180)={0x6c, r5, 0x100, 0x70bd26, 0x25dfdbfb, {}, [@HSR_A_IF2_AGE={0x8}, @HSR_A_NODE_ADDR={0xa, 0x1, @local}, @HSR_A_NODE_ADDR_B={0xa, 0x5, @link_local}, @HSR_A_IF2_SEQ={0x6}, @HSR_A_NODE_ADDR={0xa, 0x1, @multicast}, @HSR_A_IF1_SEQ={0x6, 0x6, 0x4}, @HSR_A_IFINDEX={0x8, 0x2, r1}, @HSR_A_IF2_AGE={0x8, 0x4, 0x5}, @HSR_A_NODE_ADDR_B={0xa, 0x5, @multicast}]}, 0x6c}, 0x1, 0x0, 0x0, 0x800}, 0x40) sendmmsg$auto(r3, &(0x7f0000000400)={{&(0x7f0000000000), 0x5aa, &(0x7f0000000100)={&(0x7f0000000440), 0x49}, 0x1, &(0x7f0000000200), 0x5, 0x3}, 0x5}, 0x2, 0x100) sendmsg$auto_TIPC_NL_UDP_GET_REMOTEIP(0xffffffffffffffff, 0x0, 0x24048000) mlockall$auto(0x7) mmap$auto(0x0, 0x400008, 0xdf, 0x9b72, 0x2, 0x8000) move_pages$auto(0x0, 0xd0, 0x0, 0x0, 0x0, 0x2) r7 = openat$auto_vhci_fops_hci_vhci(0xffffffffffffff9c, &(0x7f0000000000), 0x2, 0x0) bpf$auto(0x8, &(0x7f00000001c0)=@link_detach={r7}, 0x10) r8 = openat$auto_usbdev_file_operations_usb(0xffffffffffffff9c, &(0x7f0000000040)='/dev/bus/usb/038/001\x00', 0xa821, 0x0) ioctl$auto_USBDEVFS_SUBMITURB32(r8, 0x802c550a, &(0x7f00000001c0)=ANY=[@ANYBLOB="028006000000000005"]) kernel console output (not intermixed with test programs): x2a0 [ 292.120701][ T8597] ? __split_page_owner+0xdd/0x120 [ 292.120747][ T8597] alloc_pages_noprof+0x131/0x390 [ 292.120796][ T8597] alloc_pages_exact_noprof+0x31/0x90 [ 292.120832][ T8597] snd_pcm_attach_substream+0x4bb/0xd60 [ 292.120890][ T8597] snd_pcm_open_substream+0x8d/0x17f0 [ 292.120938][ T8597] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 292.120996][ T8597] snd_pcm_oss_open+0x735/0x1400 [ 292.121051][ T8597] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 292.121088][ T8597] ? __lock_acquire+0xaa4/0x1ba0 [ 292.121121][ T8597] ? __pfx_default_wake_function+0x10/0x10 [ 292.121170][ T8597] ? __lock_acquire+0xaa4/0x1ba0 [ 292.121211][ T8597] ? do_raw_spin_lock+0x12c/0x2b0 [ 292.121255][ T8597] ? soundcore_open+0x35a/0x580 [ 292.121309][ T8597] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 292.121348][ T8597] soundcore_open+0x409/0x580 [ 292.121403][ T8597] ? __pfx_soundcore_open+0x10/0x10 [ 292.121455][ T8597] chrdev_open+0x231/0x6a0 [ 292.121495][ T8597] ? __pfx_apparmor_file_open+0x10/0x10 [ 292.121548][ T8597] ? __pfx_chrdev_open+0x10/0x10 [ 292.121594][ T8597] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 292.121641][ T8597] do_dentry_open+0x741/0x1c10 [ 292.121679][ T8597] ? __pfx_chrdev_open+0x10/0x10 [ 292.121730][ T8597] vfs_open+0x82/0x3f0 [ 292.121781][ T8597] path_openat+0x1e5e/0x2d40 [ 292.121838][ T8597] ? __pfx_path_openat+0x10/0x10 [ 292.121889][ T8597] do_filp_open+0x20b/0x470 [ 292.121930][ T8597] ? __pfx_do_filp_open+0x10/0x10 [ 292.122002][ T8597] ? alloc_fd+0x471/0x7d0 [ 292.122052][ T8597] do_sys_openat2+0x11b/0x1d0 [ 292.122099][ T8597] ? __pfx_do_sys_openat2+0x10/0x10 [ 292.122165][ T8597] __x64_sys_openat+0x174/0x210 [ 292.122214][ T8597] ? __pfx___x64_sys_openat+0x10/0x10 [ 292.122266][ T8597] ? rcu_is_watching+0x12/0xc0 [ 292.122321][ T8597] do_syscall_64+0xcd/0x260 [ 292.122379][ T8597] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 292.122413][ T8597] RIP: 0033:0x7fb6b3d8d169 [ 292.122440][ T8597] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 292.122474][ T8597] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 292.122507][ T8597] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 292.122534][ T8597] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 292.122556][ T8597] RBP: 00007fb6b3e0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 292.122577][ T8597] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 292.122596][ T8597] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 292.122639][ T8597] [ 292.500858][ C1] vkms_vblank_simulate: vblank timer overrun [ 293.364381][ T8608] netlink: 20 bytes leftover after parsing attributes in process `syz.0.686'. [ 294.599888][ T8626] netlink: 20 bytes leftover after parsing attributes in process `syz.2.690'. [ 295.154841][ T8637] netlink: 20 bytes leftover after parsing attributes in process `syz.0.692'. [ 296.092116][ T8651] netlink: 4 bytes leftover after parsing attributes in process `syz.0.695'. [ 296.321582][ T8657] netlink: 20 bytes leftover after parsing attributes in process `syz.2.704'. [ 297.397248][ T30] audit: type=1800 audit(6038434231.367:9): pid=8667 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.3.696" name="SYSV00000400" dev="tmpfs" ino=0 res=0 errno=0 [ 299.429387][ T8696] netlink: 20 bytes leftover after parsing attributes in process `syz.3.702'. [ 299.553590][ T8699] FAULT_INJECTION: forcing a failure. [ 299.553590][ T8699] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 299.600962][ T8699] CPU: 1 UID: 0 PID: 8699 Comm: syz.0.707 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 299.601011][ T8699] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 299.601031][ T8699] Call Trace: [ 299.601042][ T8699] [ 299.601056][ T8699] dump_stack_lvl+0x16c/0x1f0 [ 299.601117][ T8699] should_fail_ex+0x512/0x640 [ 299.601168][ T8699] should_fail_alloc_page+0xe7/0x130 [ 299.601220][ T8699] prepare_alloc_pages+0x3c2/0x610 [ 299.601260][ T8699] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 299.601309][ T8699] ? stack_trace_save+0x8e/0xc0 [ 299.601354][ T8699] ? __pfx_stack_trace_save+0x10/0x10 [ 299.601400][ T8699] ? stack_depot_save_flags+0x28/0xa50 [ 299.601446][ T8699] ? __kernel_text_address+0xd/0x40 [ 299.601495][ T8699] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 299.601538][ T8699] ? kasan_save_track+0x14/0x30 [ 299.601577][ T8699] ? snd_pcm_attach_substream+0x441/0xd60 [ 299.601622][ T8699] ? snd_pcm_oss_open+0x735/0x1400 [ 299.601655][ T8699] ? soundcore_open+0x409/0x580 [ 299.601703][ T8699] ? chrdev_open+0x231/0x6a0 [ 299.601740][ T8699] ? do_dentry_open+0x741/0x1c10 [ 299.601782][ T8699] ? vfs_open+0x82/0x3f0 [ 299.601824][ T8699] ? path_openat+0x1e5e/0x2d40 [ 299.601864][ T8699] ? do_filp_open+0x20b/0x470 [ 299.601918][ T8699] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 299.601958][ T8699] ? policy_nodemask+0xea/0x4e0 [ 299.602008][ T8699] alloc_pages_mpol+0x1fb/0x550 [ 299.602057][ T8699] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 299.602116][ T8699] alloc_pages_noprof+0x131/0x390 [ 299.602165][ T8699] alloc_pages_exact_noprof+0x31/0x90 [ 299.602200][ T8699] snd_pcm_attach_substream+0x468/0xd60 [ 299.602258][ T8699] snd_pcm_open_substream+0x8d/0x17f0 [ 299.602305][ T8699] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 299.602363][ T8699] snd_pcm_oss_open+0x735/0x1400 [ 299.602417][ T8699] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 299.602453][ T8699] ? __lock_acquire+0xaa4/0x1ba0 [ 299.602487][ T8699] ? __pfx_default_wake_function+0x10/0x10 [ 299.602535][ T8699] ? __lock_acquire+0xaa4/0x1ba0 [ 299.602577][ T8699] ? do_raw_spin_lock+0x12c/0x2b0 [ 299.602620][ T8699] ? soundcore_open+0x35a/0x580 [ 299.602673][ T8699] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 299.602712][ T8699] soundcore_open+0x409/0x580 [ 299.602775][ T8699] ? __pfx_soundcore_open+0x10/0x10 [ 299.602827][ T8699] chrdev_open+0x231/0x6a0 [ 299.602867][ T8699] ? __pfx_apparmor_file_open+0x10/0x10 [ 299.602917][ T8699] ? __pfx_chrdev_open+0x10/0x10 [ 299.602962][ T8699] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 299.603008][ T8699] do_dentry_open+0x741/0x1c10 [ 299.603046][ T8699] ? __pfx_chrdev_open+0x10/0x10 [ 299.603097][ T8699] vfs_open+0x82/0x3f0 [ 299.603149][ T8699] path_openat+0x1e5e/0x2d40 [ 299.603205][ T8699] ? __pfx_path_openat+0x10/0x10 [ 299.603256][ T8699] do_filp_open+0x20b/0x470 [ 299.603296][ T8699] ? __pfx_do_filp_open+0x10/0x10 [ 299.603368][ T8699] ? alloc_fd+0x471/0x7d0 [ 299.603418][ T8699] do_sys_openat2+0x11b/0x1d0 [ 299.603467][ T8699] ? __pfx_do_sys_openat2+0x10/0x10 [ 299.603532][ T8699] __x64_sys_openat+0x174/0x210 [ 299.603582][ T8699] ? __pfx___x64_sys_openat+0x10/0x10 [ 299.603634][ T8699] ? rcu_is_watching+0x12/0xc0 [ 299.603689][ T8699] do_syscall_64+0xcd/0x260 [ 299.603746][ T8699] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 299.603786][ T8699] RIP: 0033:0x7f7cadd8d169 [ 299.603814][ T8699] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 299.603847][ T8699] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 299.603879][ T8699] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 299.603899][ T8699] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 299.603920][ T8699] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 299.603939][ T8699] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 299.603958][ T8699] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 299.604000][ T8699] [ 300.000739][ C1] vkms_vblank_simulate: vblank timer overrun [ 300.261710][ T8704] FAULT_INJECTION: forcing a failure. [ 300.261710][ T8704] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 300.350902][ T8704] CPU: 0 UID: 0 PID: 8704 Comm: syz.2.708 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 300.350958][ T8704] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 300.350978][ T8704] Call Trace: [ 300.350990][ T8704] [ 300.351003][ T8704] dump_stack_lvl+0x16c/0x1f0 [ 300.351062][ T8704] should_fail_ex+0x512/0x640 [ 300.351112][ T8704] should_fail_alloc_page+0xe7/0x130 [ 300.351163][ T8704] prepare_alloc_pages+0x3c2/0x610 [ 300.351203][ T8704] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 300.351250][ T8704] ? stack_trace_save+0x8e/0xc0 [ 300.351295][ T8704] ? __pfx_stack_trace_save+0x10/0x10 [ 300.351340][ T8704] ? stack_depot_save_flags+0x28/0xa50 [ 300.351387][ T8704] ? __kernel_text_address+0xd/0x40 [ 300.351435][ T8704] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 300.351478][ T8704] ? kasan_save_track+0x14/0x30 [ 300.351517][ T8704] ? snd_pcm_attach_substream+0x441/0xd60 [ 300.351562][ T8704] ? snd_pcm_oss_open+0x735/0x1400 [ 300.351601][ T8704] ? soundcore_open+0x409/0x580 [ 300.351650][ T8704] ? chrdev_open+0x231/0x6a0 [ 300.351687][ T8704] ? do_dentry_open+0x741/0x1c10 [ 300.351723][ T8704] ? vfs_open+0x82/0x3f0 [ 300.351765][ T8704] ? path_openat+0x1e5e/0x2d40 [ 300.351800][ T8704] ? do_filp_open+0x20b/0x470 [ 300.351854][ T8704] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 300.351894][ T8704] ? policy_nodemask+0xea/0x4e0 [ 300.351953][ T8704] alloc_pages_mpol+0x1fb/0x550 [ 300.352002][ T8704] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 300.352063][ T8704] alloc_pages_noprof+0x131/0x390 [ 300.352112][ T8704] alloc_pages_exact_noprof+0x31/0x90 [ 300.352147][ T8704] snd_pcm_attach_substream+0x468/0xd60 [ 300.352205][ T8704] snd_pcm_open_substream+0x8d/0x17f0 [ 300.352253][ T8704] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 300.352311][ T8704] snd_pcm_oss_open+0x735/0x1400 [ 300.352364][ T8704] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 300.352402][ T8704] ? __lock_acquire+0xaa4/0x1ba0 [ 300.352435][ T8704] ? __pfx_default_wake_function+0x10/0x10 [ 300.352484][ T8704] ? __lock_acquire+0xaa4/0x1ba0 [ 300.352526][ T8704] ? do_raw_spin_lock+0x12c/0x2b0 [ 300.352569][ T8704] ? soundcore_open+0x35a/0x580 [ 300.352622][ T8704] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 300.352661][ T8704] soundcore_open+0x409/0x580 [ 300.352717][ T8704] ? __pfx_soundcore_open+0x10/0x10 [ 300.352769][ T8704] chrdev_open+0x231/0x6a0 [ 300.352809][ T8704] ? __pfx_apparmor_file_open+0x10/0x10 [ 300.352858][ T8704] ? __pfx_chrdev_open+0x10/0x10 [ 300.352903][ T8704] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 300.352955][ T8704] do_dentry_open+0x741/0x1c10 [ 300.352994][ T8704] ? __pfx_chrdev_open+0x10/0x10 [ 300.353045][ T8704] vfs_open+0x82/0x3f0 [ 300.353097][ T8704] path_openat+0x1e5e/0x2d40 [ 300.353154][ T8704] ? __pfx_path_openat+0x10/0x10 [ 300.353206][ T8704] do_filp_open+0x20b/0x470 [ 300.353245][ T8704] ? __pfx_do_filp_open+0x10/0x10 [ 300.353317][ T8704] ? alloc_fd+0x471/0x7d0 [ 300.353367][ T8704] do_sys_openat2+0x11b/0x1d0 [ 300.353415][ T8704] ? __pfx_do_sys_openat2+0x10/0x10 [ 300.353481][ T8704] __x64_sys_openat+0x174/0x210 [ 300.353531][ T8704] ? __pfx___x64_sys_openat+0x10/0x10 [ 300.353583][ T8704] ? rcu_is_watching+0x12/0xc0 [ 300.353638][ T8704] do_syscall_64+0xcd/0x260 [ 300.353696][ T8704] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 300.353730][ T8704] RIP: 0033:0x7fa48d58d169 [ 300.353758][ T8704] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 300.353792][ T8704] RSP: 002b:00007fa48e33f038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 300.353825][ T8704] RAX: ffffffffffffffda RBX: 00007fa48d7a5fa0 RCX: 00007fa48d58d169 [ 300.353847][ T8704] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 300.353869][ T8704] RBP: 00007fa48d60e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 300.353889][ T8704] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 300.353909][ T8704] R13: 0000000000000000 R14: 00007fa48d7a5fa0 R15: 00007fff90313ae8 [ 300.353960][ T8704] [ 300.945714][ T8699] Process accounting resumed [ 301.158989][ T8710] netlink: 20 bytes leftover after parsing attributes in process `syz.1.711'. [ 302.244469][ T8738] netlink: 4 bytes leftover after parsing attributes in process `syz.3.719'. [ 303.018286][ T8748] netlink: 20 bytes leftover after parsing attributes in process `syz.3.721'. [ 306.232752][ T8797] FAULT_INJECTION: forcing a failure. [ 306.232752][ T8797] name failslab, interval 1, probability 0, space 0, times 0 [ 306.278226][ T8797] CPU: 0 UID: 0 PID: 8797 Comm: syz.0.735 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 306.278270][ T8797] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 306.278289][ T8797] Call Trace: [ 306.278299][ T8797] [ 306.278311][ T8797] dump_stack_lvl+0x16c/0x1f0 [ 306.278368][ T8797] should_fail_ex+0x512/0x640 [ 306.278410][ T8797] ? __kmalloc_node_track_caller_noprof+0xc3/0x510 [ 306.278461][ T8797] should_failslab+0xc2/0x120 [ 306.278508][ T8797] __kmalloc_node_track_caller_noprof+0xd6/0x510 [ 306.278555][ T8797] ? snd_pcm_hw_rule_add+0x414/0x5a0 [ 306.278615][ T8797] krealloc_noprof+0x1fb/0x380 [ 306.278662][ T8797] snd_pcm_hw_rule_add+0x414/0x5a0 [ 306.278717][ T8797] ? __pfx_snd_pcm_hw_rule_format+0x10/0x10 [ 306.278759][ T8797] ? __pfx_snd_pcm_hw_rule_add+0x10/0x10 [ 306.278809][ T8797] ? lockdep_init_map_type+0x5c/0x280 [ 306.278838][ T8797] ? debug_mutex_init+0x37/0x70 [ 306.278874][ T8797] ? snd_pcm_attach_substream+0x89d/0xd60 [ 306.278926][ T8797] snd_pcm_open_substream+0x534/0x17f0 [ 306.278974][ T8797] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 306.279028][ T8797] snd_pcm_oss_open+0x735/0x1400 [ 306.279082][ T8797] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 306.279119][ T8797] ? __lock_acquire+0xaa4/0x1ba0 [ 306.279163][ T8797] ? __pfx_default_wake_function+0x10/0x10 [ 306.279211][ T8797] ? __lock_acquire+0xaa4/0x1ba0 [ 306.279253][ T8797] ? do_raw_spin_lock+0x12c/0x2b0 [ 306.279296][ T8797] ? soundcore_open+0x35a/0x580 [ 306.279350][ T8797] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 306.279388][ T8797] soundcore_open+0x409/0x580 [ 306.279444][ T8797] ? __pfx_soundcore_open+0x10/0x10 [ 306.279496][ T8797] chrdev_open+0x231/0x6a0 [ 306.279537][ T8797] ? __pfx_apparmor_file_open+0x10/0x10 [ 306.279586][ T8797] ? __pfx_chrdev_open+0x10/0x10 [ 306.279631][ T8797] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 306.279677][ T8797] do_dentry_open+0x741/0x1c10 [ 306.279716][ T8797] ? __pfx_chrdev_open+0x10/0x10 [ 306.279766][ T8797] vfs_open+0x82/0x3f0 [ 306.279817][ T8797] path_openat+0x1e5e/0x2d40 [ 306.279874][ T8797] ? __pfx_path_openat+0x10/0x10 [ 306.279925][ T8797] do_filp_open+0x20b/0x470 [ 306.279965][ T8797] ? __pfx_do_filp_open+0x10/0x10 [ 306.280036][ T8797] ? alloc_fd+0x471/0x7d0 [ 306.280086][ T8797] do_sys_openat2+0x11b/0x1d0 [ 306.280141][ T8797] ? __pfx_do_sys_openat2+0x10/0x10 [ 306.280206][ T8797] __x64_sys_openat+0x174/0x210 [ 306.280256][ T8797] ? __pfx___x64_sys_openat+0x10/0x10 [ 306.280308][ T8797] ? rcu_is_watching+0x12/0xc0 [ 306.280363][ T8797] do_syscall_64+0xcd/0x260 [ 306.280420][ T8797] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 306.280454][ T8797] RIP: 0033:0x7f7cadd8d169 [ 306.280481][ T8797] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 306.280514][ T8797] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 306.280545][ T8797] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 306.280566][ T8797] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 306.280585][ T8797] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 306.280605][ T8797] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 306.280623][ T8797] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 306.280665][ T8797] [ 306.615478][ C0] vkms_vblank_simulate: vblank timer overrun [ 306.701797][ T8802] netlink: 20 bytes leftover after parsing attributes in process `syz.3.736'. [ 307.722744][ T8811] netlink: 20 bytes leftover after parsing attributes in process `syz.3.738'. [ 309.801553][ T8847] netlink: 20 bytes leftover after parsing attributes in process `syz.2.747'. [ 309.879502][ T8846] netlink: 20 bytes leftover after parsing attributes in process `syz.0.746'. [ 310.586452][ T8849] random: crng reseeded on system resumption [ 310.823105][ T8858] netlink: 20 bytes leftover after parsing attributes in process `syz.0.751'. [ 313.920421][ T8893] netlink: 20 bytes leftover after parsing attributes in process `syz.2.759'. [ 315.882546][ T8902] netlink: 20 bytes leftover after parsing attributes in process `syz.0.761'. [ 320.041439][ T8946] netlink: 20 bytes leftover after parsing attributes in process `syz.0.774'. [ 321.541297][ T8959] FAULT_INJECTION: forcing a failure. [ 321.541297][ T8959] name failslab, interval 1, probability 0, space 0, times 0 [ 321.554264][ T8959] CPU: 1 UID: 0 PID: 8959 Comm: syz.0.777 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 321.554309][ T8959] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 321.554331][ T8959] Call Trace: [ 321.554341][ T8959] [ 321.554354][ T8959] dump_stack_lvl+0x16c/0x1f0 [ 321.554412][ T8959] should_fail_ex+0x512/0x640 [ 321.554454][ T8959] ? __kmalloc_node_track_caller_noprof+0xc3/0x510 [ 321.554506][ T8959] should_failslab+0xc2/0x120 [ 321.554560][ T8959] __kmalloc_node_track_caller_noprof+0xd6/0x510 [ 321.554610][ T8959] ? snd_pcm_hw_rule_add+0x414/0x5a0 [ 321.554670][ T8959] krealloc_noprof+0x1fb/0x380 [ 321.554718][ T8959] snd_pcm_hw_rule_add+0x414/0x5a0 [ 321.554772][ T8959] ? __pfx_snd_pcm_hw_rule_format+0x10/0x10 [ 321.554815][ T8959] ? __pfx_snd_pcm_hw_rule_add+0x10/0x10 [ 321.554872][ T8959] ? lockdep_init_map_type+0x5c/0x280 [ 321.554907][ T8959] ? debug_mutex_init+0x37/0x70 [ 321.554951][ T8959] ? snd_pcm_attach_substream+0x89d/0xd60 [ 321.555006][ T8959] snd_pcm_open_substream+0x534/0x17f0 [ 321.555054][ T8959] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 321.555112][ T8959] snd_pcm_oss_open+0x735/0x1400 [ 321.555165][ T8959] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 321.555203][ T8959] ? __lock_acquire+0xaa4/0x1ba0 [ 321.555235][ T8959] ? __pfx_default_wake_function+0x10/0x10 [ 321.555283][ T8959] ? __lock_acquire+0xaa4/0x1ba0 [ 321.555325][ T8959] ? do_raw_spin_lock+0x12c/0x2b0 [ 321.555367][ T8959] ? soundcore_open+0x35a/0x580 [ 321.555421][ T8959] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 321.555459][ T8959] soundcore_open+0x409/0x580 [ 321.555514][ T8959] ? __pfx_soundcore_open+0x10/0x10 [ 321.555591][ T8959] chrdev_open+0x231/0x6a0 [ 321.555632][ T8959] ? __pfx_apparmor_file_open+0x10/0x10 [ 321.555681][ T8959] ? __pfx_chrdev_open+0x10/0x10 [ 321.555725][ T8959] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 321.555772][ T8959] do_dentry_open+0x741/0x1c10 [ 321.555810][ T8959] ? __pfx_chrdev_open+0x10/0x10 [ 321.555860][ T8959] vfs_open+0x82/0x3f0 [ 321.555911][ T8959] path_openat+0x1e5e/0x2d40 [ 321.555966][ T8959] ? __pfx_path_openat+0x10/0x10 [ 321.556018][ T8959] do_filp_open+0x20b/0x470 [ 321.556061][ T8959] ? __pfx_do_filp_open+0x10/0x10 [ 321.556129][ T8959] ? alloc_fd+0x471/0x7d0 [ 321.556179][ T8959] do_sys_openat2+0x11b/0x1d0 [ 321.556224][ T8959] ? __pfx_do_sys_openat2+0x10/0x10 [ 321.556286][ T8959] __x64_sys_openat+0x174/0x210 [ 321.556334][ T8959] ? __pfx___x64_sys_openat+0x10/0x10 [ 321.556381][ T8959] ? rcu_is_watching+0x12/0xc0 [ 321.556429][ T8959] do_syscall_64+0xcd/0x260 [ 321.556476][ T8959] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 321.556506][ T8959] RIP: 0033:0x7f7cadd8d169 [ 321.556530][ T8959] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 321.556574][ T8959] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 321.556610][ T8959] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 321.556634][ T8959] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 321.556658][ T8959] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 321.556679][ T8959] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 321.556700][ T8959] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 321.556744][ T8959] [ 322.453836][ T1298] ieee802154 phy0 wpan0: encryption failed: -22 [ 322.477245][ T8964] netlink: 20 bytes leftover after parsing attributes in process `syz.1.778'. [ 322.479966][ T1298] ieee802154 phy1 wpan1: encryption failed: -22 [ 322.561194][ C1] vkms_vblank_simulate: vblank timer overrun [ 322.840711][ T8968] Invalid ELF header magic: != ELF [ 325.499536][ T8988] netlink: 20 bytes leftover after parsing attributes in process `syz.2.786'. [ 326.037342][ T9004] netlink: 20 bytes leftover after parsing attributes in process `syz.2.791'. [ 326.286993][ T9011] netlink: 20 bytes leftover after parsing attributes in process `syz.3.793'. [ 328.652641][ T9063] HfR: entered promiscuous mode [ 328.700460][ T9063] netlink: 12 bytes leftover after parsing attributes in process `syz.3.807'. [ 328.719711][ T9063] HfR: left promiscuous mode [ 328.890772][ T9063] HfR: entered promiscuous mode [ 329.401521][ T9079] netlink: 20 bytes leftover after parsing attributes in process `syz.3.812'. [ 331.058430][ T9094] Process accounting paused [ 332.847834][ T9132] netlink: 44 bytes leftover after parsing attributes in process `syz.0.830'. [ 332.952243][ T9133] netlink: 20 bytes leftover after parsing attributes in process `syz.1.829'. [ 334.009854][ T9144] netlink: 20 bytes leftover after parsing attributes in process `syz.1.833'. [ 336.225927][ T9171] netlink: 20 bytes leftover after parsing attributes in process `syz.0.842'. [ 338.527546][ T9205] netlink: 20 bytes leftover after parsing attributes in process `syz.1.851'. [ 339.574448][ T9212] FAULT_INJECTION: forcing a failure. [ 339.574448][ T9212] name failslab, interval 1, probability 0, space 0, times 0 [ 339.587696][ T9212] CPU: 0 UID: 0 PID: 9212 Comm: syz.1.853 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 339.587744][ T9212] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 339.587763][ T9212] Call Trace: [ 339.587773][ T9212] [ 339.587786][ T9212] dump_stack_lvl+0x16c/0x1f0 [ 339.587846][ T9212] should_fail_ex+0x512/0x640 [ 339.587887][ T9212] ? __kmalloc_cache_noprof+0x57/0x3e0 [ 339.587929][ T9212] should_failslab+0xc2/0x120 [ 339.587975][ T9212] __kmalloc_cache_noprof+0x6a/0x3e0 [ 339.588012][ T9212] ? snd_ctl_get_preferred_subdevice+0x16c/0x1f0 [ 339.588057][ T9212] ? snd_pcm_attach_substream+0x441/0xd60 [ 339.588111][ T9212] snd_pcm_attach_substream+0x441/0xd60 [ 339.588178][ T9212] snd_pcm_open_substream+0x8d/0x17f0 [ 339.588225][ T9212] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 339.588282][ T9212] snd_pcm_oss_open+0x735/0x1400 [ 339.588336][ T9212] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 339.588373][ T9212] ? __lock_acquire+0xaa4/0x1ba0 [ 339.588407][ T9212] ? __pfx_default_wake_function+0x10/0x10 [ 339.588455][ T9212] ? __lock_acquire+0xaa4/0x1ba0 [ 339.588497][ T9212] ? do_raw_spin_lock+0x12c/0x2b0 [ 339.588539][ T9212] ? soundcore_open+0x35a/0x580 [ 339.588592][ T9212] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 339.588630][ T9212] soundcore_open+0x409/0x580 [ 339.588684][ T9212] ? __pfx_soundcore_open+0x10/0x10 [ 339.588736][ T9212] chrdev_open+0x231/0x6a0 [ 339.588774][ T9212] ? __pfx_apparmor_file_open+0x10/0x10 [ 339.588822][ T9212] ? __pfx_chrdev_open+0x10/0x10 [ 339.588867][ T9212] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 339.588913][ T9212] do_dentry_open+0x741/0x1c10 [ 339.588951][ T9212] ? __pfx_chrdev_open+0x10/0x10 [ 339.589000][ T9212] vfs_open+0x82/0x3f0 [ 339.589051][ T9212] path_openat+0x1e5e/0x2d40 [ 339.589107][ T9212] ? __pfx_path_openat+0x10/0x10 [ 339.589165][ T9212] do_filp_open+0x20b/0x470 [ 339.589205][ T9212] ? __pfx_do_filp_open+0x10/0x10 [ 339.589273][ T9212] ? alloc_fd+0x471/0x7d0 [ 339.589321][ T9212] do_sys_openat2+0x11b/0x1d0 [ 339.589368][ T9212] ? __pfx_do_sys_openat2+0x10/0x10 [ 339.589431][ T9212] __x64_sys_openat+0x174/0x210 [ 339.589480][ T9212] ? __pfx___x64_sys_openat+0x10/0x10 [ 339.589530][ T9212] ? rcu_is_watching+0x12/0xc0 [ 339.589584][ T9212] do_syscall_64+0xcd/0x260 [ 339.589638][ T9212] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 339.589671][ T9212] RIP: 0033:0x7fb6b3d8d169 [ 339.589697][ T9212] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 339.589729][ T9212] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 339.589760][ T9212] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 339.589781][ T9212] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 339.589802][ T9212] RBP: 00007fb6b3e0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 339.589823][ T9212] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 339.589842][ T9212] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 339.589884][ T9212] [ 339.898257][ C0] vkms_vblank_simulate: vblank timer overrun [ 340.791436][ T9232] svc: failed to register nfsdv3 RPC service (errno 111). [ 340.809343][ T9232] svc: failed to register nfsaclv3 RPC service (errno 111). [ 342.037675][ T9245] netlink: 20 bytes leftover after parsing attributes in process `syz.3.863'. [ 342.103566][ T9249] FAULT_INJECTION: forcing a failure. [ 342.103566][ T9249] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 342.135347][ T9249] CPU: 0 UID: 0 PID: 9249 Comm: syz.1.864 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 342.135392][ T9249] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 342.135411][ T9249] Call Trace: [ 342.135422][ T9249] [ 342.135433][ T9249] dump_stack_lvl+0x16c/0x1f0 [ 342.135489][ T9249] should_fail_ex+0x512/0x640 [ 342.135535][ T9249] should_fail_alloc_page+0xe7/0x130 [ 342.135664][ T9249] prepare_alloc_pages+0x3c2/0x610 [ 342.135698][ T9249] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 342.135746][ T9249] ? stack_trace_save+0x8e/0xc0 [ 342.135790][ T9249] ? __pfx_stack_trace_save+0x10/0x10 [ 342.135835][ T9249] ? stack_depot_save_flags+0x28/0xa50 [ 342.135888][ T9249] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 342.135930][ T9249] ? kasan_save_stack+0x33/0x60 [ 342.135969][ T9249] ? __kasan_kmalloc+0xaa/0xb0 [ 342.136005][ T9249] ? copy_splice_read+0x1a8/0xba0 [ 342.136040][ T9249] ? do_splice_read+0x282/0x370 [ 342.136067][ T9249] ? splice_direct_to_actor+0x2a1/0xa30 [ 342.136098][ T9249] ? do_splice_direct+0x174/0x240 [ 342.136128][ T9249] ? do_sendfile+0xafd/0xe50 [ 342.136157][ T9249] ? __x64_sys_sendfile64+0x1d8/0x220 [ 342.136197][ T9249] ? do_syscall_64+0xcd/0x260 [ 342.136276][ T9249] alloc_pages_bulk_noprof+0x703/0x13b0 [ 342.136327][ T9249] ? __pfx_alloc_pages_bulk_noprof+0x10/0x10 [ 342.136380][ T9249] ? trace_kmalloc+0x2b/0xd0 [ 342.136422][ T9249] ? __kmalloc_noprof+0x242/0x510 [ 342.136470][ T9249] copy_splice_read+0x1e1/0xba0 [ 342.136512][ T9249] ? __pfx_copy_splice_read+0x10/0x10 [ 342.136561][ T9249] ? find_held_lock+0x2b/0x80 [ 342.136612][ T9249] ? __pfx_copy_splice_read+0x10/0x10 [ 342.136656][ T9249] do_splice_read+0x282/0x370 [ 342.136692][ T9249] splice_direct_to_actor+0x2a1/0xa30 [ 342.136728][ T9249] ? __pfx_direct_splice_actor+0x10/0x10 [ 342.136774][ T9249] ? __pfx_splice_direct_to_actor+0x10/0x10 [ 342.136809][ T9249] ? get_pid_task+0xfc/0x250 [ 342.136853][ T9249] do_splice_direct+0x174/0x240 [ 342.136888][ T9249] ? __pfx_do_splice_direct+0x10/0x10 [ 342.136925][ T9249] ? __pfx_direct_file_splice_eof+0x10/0x10 [ 342.136966][ T9249] ? rw_verify_area+0xcf/0x680 [ 342.137030][ T9249] do_sendfile+0xafd/0xe50 [ 342.137072][ T9249] ? __pfx_do_sendfile+0x10/0x10 [ 342.137106][ T9249] ? __fget_files+0x20e/0x3c0 [ 342.137153][ T9249] __x64_sys_sendfile64+0x1d8/0x220 [ 342.137195][ T9249] ? ksys_write+0x1b9/0x240 [ 342.137228][ T9249] ? __pfx___x64_sys_sendfile64+0x10/0x10 [ 342.137268][ T9249] ? rcu_is_watching+0x12/0xc0 [ 342.137320][ T9249] do_syscall_64+0xcd/0x260 [ 342.137376][ T9249] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 342.137408][ T9249] RIP: 0033:0x7fb6b3d8d169 [ 342.137434][ T9249] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 342.137466][ T9249] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000028 [ 342.137497][ T9249] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 342.137518][ T9249] RDX: 0000000000000000 RSI: 0000000000000003 RDI: 0000000000000003 [ 342.137538][ T9249] RBP: 00007fb6b4b46090 R08: 0000000000000000 R09: 0000000000000000 [ 342.137557][ T9249] R10: 0000000000000003 R11: 0000000000000246 R12: 0000000000000001 [ 342.137576][ T9249] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 342.137616][ T9249] [ 342.465934][ C0] vkms_vblank_simulate: vblank timer overrun [ 342.911865][ T9256] FAULT_INJECTION: forcing a failure. [ 342.911865][ T9256] name failslab, interval 1, probability 0, space 0, times 0 [ 342.924867][ T9256] CPU: 0 UID: 0 PID: 9256 Comm: syz.0.867 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 342.924916][ T9256] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 342.924937][ T9256] Call Trace: [ 342.924949][ T9256] [ 342.924962][ T9256] dump_stack_lvl+0x16c/0x1f0 [ 342.925022][ T9256] should_fail_ex+0x512/0x640 [ 342.925064][ T9256] ? __kmalloc_node_track_caller_noprof+0xc3/0x510 [ 342.925117][ T9256] should_failslab+0xc2/0x120 [ 342.925163][ T9256] __kmalloc_node_track_caller_noprof+0xd6/0x510 [ 342.925212][ T9256] ? snd_pcm_hw_rule_add+0x414/0x5a0 [ 342.925272][ T9256] krealloc_noprof+0x1fb/0x380 [ 342.925319][ T9256] snd_pcm_hw_rule_add+0x414/0x5a0 [ 342.925373][ T9256] ? __pfx_snd_pcm_hw_rule_format+0x10/0x10 [ 342.925415][ T9256] ? __pfx_snd_pcm_hw_rule_add+0x10/0x10 [ 342.925482][ T9256] ? lockdep_init_map_type+0x5c/0x280 [ 342.925517][ T9256] ? debug_mutex_init+0x37/0x70 [ 342.925561][ T9256] ? snd_pcm_attach_substream+0x89d/0xd60 [ 342.925617][ T9256] snd_pcm_open_substream+0x534/0x17f0 [ 342.925665][ T9256] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 342.925723][ T9256] snd_pcm_oss_open+0x735/0x1400 [ 342.925776][ T9256] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 342.925814][ T9256] ? __lock_acquire+0xaa4/0x1ba0 [ 342.925845][ T9256] ? __pfx_default_wake_function+0x10/0x10 [ 342.925894][ T9256] ? __lock_acquire+0xaa4/0x1ba0 [ 342.925936][ T9256] ? do_raw_spin_lock+0x12c/0x2b0 [ 342.925979][ T9256] ? soundcore_open+0x35a/0x580 [ 342.926035][ T9256] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 342.926071][ T9256] soundcore_open+0x409/0x580 [ 342.926123][ T9256] ? __pfx_soundcore_open+0x10/0x10 [ 342.926169][ T9256] chrdev_open+0x231/0x6a0 [ 342.926203][ T9256] ? __pfx_apparmor_file_open+0x10/0x10 [ 342.926247][ T9256] ? __pfx_chrdev_open+0x10/0x10 [ 342.926292][ T9256] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 342.926338][ T9256] do_dentry_open+0x741/0x1c10 [ 342.926376][ T9256] ? __pfx_chrdev_open+0x10/0x10 [ 342.926426][ T9256] vfs_open+0x82/0x3f0 [ 342.926482][ T9256] path_openat+0x1e5e/0x2d40 [ 342.926532][ T9256] ? __pfx_path_openat+0x10/0x10 [ 342.926578][ T9256] do_filp_open+0x20b/0x470 [ 342.926616][ T9256] ? __pfx_do_filp_open+0x10/0x10 [ 342.926681][ T9256] ? alloc_fd+0x471/0x7d0 [ 342.926731][ T9256] do_sys_openat2+0x11b/0x1d0 [ 342.926777][ T9256] ? __pfx_do_sys_openat2+0x10/0x10 [ 342.926838][ T9256] __x64_sys_openat+0x174/0x210 [ 342.926888][ T9256] ? __pfx___x64_sys_openat+0x10/0x10 [ 342.926939][ T9256] ? rcu_is_watching+0x12/0xc0 [ 342.927000][ T9256] do_syscall_64+0xcd/0x260 [ 342.927057][ T9256] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 342.927089][ T9256] RIP: 0033:0x7f7cadd8d169 [ 342.927115][ T9256] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 342.927148][ T9256] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 342.927179][ T9256] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 342.927199][ T9256] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 342.927219][ T9256] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 342.927239][ T9256] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 342.927257][ T9256] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 342.927300][ T9256] [ 343.258039][ C0] vkms_vblank_simulate: vblank timer overrun [ 343.988842][ T9267] netlink: 20 bytes leftover after parsing attributes in process `syz.3.866'. [ 344.601102][ T9270] netlink: 36 bytes leftover after parsing attributes in process `syz.0.870'. [ 344.646764][ T9275] netlink: 28 bytes leftover after parsing attributes in process `syz.2.871'. [ 344.655944][ T9275] bridge_slave_1: left allmulticast mode [ 344.677975][ T9275] bridge_slave_1: left promiscuous mode [ 344.685289][ T9275] bridge0: port 2(bridge_slave_1) entered disabled state [ 344.773920][ T9275] bridge_slave_0: left allmulticast mode [ 344.779999][ T9275] bridge_slave_0: left promiscuous mode [ 344.792756][ T9275] bridge0: port 1(bridge_slave_0) entered disabled state [ 345.449510][ T9296] netlink: 20 bytes leftover after parsing attributes in process `syz.0.875'. [ 345.459523][ T9283] netlink: 28 bytes leftover after parsing attributes in process `syz.3.873'. [ 346.452722][ T9305] usb usb38: Requested nonsensical USBDEVFS_URB_SHORT_NOT_OK. [ 346.472121][ T9305] vhci_hcd: default hub control req: 0000 v0000 i0000 l0 [ 347.597912][ T9327] netlink: 20 bytes leftover after parsing attributes in process `syz.0.883'. [ 348.032898][ T9333] netlink: 20 bytes leftover after parsing attributes in process `syz.3.884'. [ 348.864181][ T9348] netlink: 20 bytes leftover after parsing attributes in process `syz.0.886'. [ 349.762997][ T9360] netlink: 20 bytes leftover after parsing attributes in process `syz.3.893'. [ 349.994492][ T9364] FAULT_INJECTION: forcing a failure. [ 349.994492][ T9364] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 350.061032][ T9364] CPU: 1 UID: 0 PID: 9364 Comm: syz.0.895 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 350.061082][ T9364] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 350.061104][ T9364] Call Trace: [ 350.061117][ T9364] [ 350.061130][ T9364] dump_stack_lvl+0x16c/0x1f0 [ 350.061192][ T9364] should_fail_ex+0x512/0x640 [ 350.061242][ T9364] should_fail_alloc_page+0xe7/0x130 [ 350.061293][ T9364] prepare_alloc_pages+0x3c2/0x610 [ 350.061334][ T9364] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 350.061381][ T9364] ? stack_trace_save+0x8e/0xc0 [ 350.061463][ T9364] ? __pfx_stack_trace_save+0x10/0x10 [ 350.061508][ T9364] ? stack_depot_save_flags+0x28/0xa50 [ 350.061565][ T9364] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 350.061609][ T9364] ? kasan_save_track+0x14/0x30 [ 350.061650][ T9364] ? snd_pcm_attach_substream+0x441/0xd60 [ 350.061695][ T9364] ? snd_pcm_oss_open+0x735/0x1400 [ 350.061737][ T9364] ? soundcore_open+0x409/0x580 [ 350.061785][ T9364] ? chrdev_open+0x231/0x6a0 [ 350.061823][ T9364] ? do_dentry_open+0x741/0x1c10 [ 350.061858][ T9364] ? vfs_open+0x82/0x3f0 [ 350.061900][ T9364] ? path_openat+0x1e5e/0x2d40 [ 350.061939][ T9364] ? do_filp_open+0x20b/0x470 [ 350.061993][ T9364] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 350.062034][ T9364] ? policy_nodemask+0xea/0x4e0 [ 350.062084][ T9364] alloc_pages_mpol+0x1fb/0x550 [ 350.062134][ T9364] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 350.062193][ T9364] alloc_pages_noprof+0x131/0x390 [ 350.062242][ T9364] alloc_pages_exact_noprof+0x31/0x90 [ 350.062278][ T9364] snd_pcm_attach_substream+0x468/0xd60 [ 350.062336][ T9364] snd_pcm_open_substream+0x8d/0x17f0 [ 350.062384][ T9364] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 350.062442][ T9364] snd_pcm_oss_open+0x735/0x1400 [ 350.062496][ T9364] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 350.062533][ T9364] ? __lock_acquire+0xaa4/0x1ba0 [ 350.062567][ T9364] ? __pfx_default_wake_function+0x10/0x10 [ 350.062615][ T9364] ? __lock_acquire+0xaa4/0x1ba0 [ 350.062658][ T9364] ? do_raw_spin_lock+0x12c/0x2b0 [ 350.062701][ T9364] ? soundcore_open+0x35a/0x580 [ 350.062773][ T9364] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 350.062813][ T9364] soundcore_open+0x409/0x580 [ 350.062869][ T9364] ? __pfx_soundcore_open+0x10/0x10 [ 350.062922][ T9364] chrdev_open+0x231/0x6a0 [ 350.062962][ T9364] ? __pfx_apparmor_file_open+0x10/0x10 [ 350.063011][ T9364] ? __pfx_chrdev_open+0x10/0x10 [ 350.063057][ T9364] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 350.063104][ T9364] do_dentry_open+0x741/0x1c10 [ 350.063143][ T9364] ? __pfx_chrdev_open+0x10/0x10 [ 350.063194][ T9364] vfs_open+0x82/0x3f0 [ 350.063247][ T9364] path_openat+0x1e5e/0x2d40 [ 350.063303][ T9364] ? __pfx_path_openat+0x10/0x10 [ 350.063354][ T9364] do_filp_open+0x20b/0x470 [ 350.063395][ T9364] ? __pfx_do_filp_open+0x10/0x10 [ 350.063466][ T9364] ? alloc_fd+0x471/0x7d0 [ 350.063516][ T9364] do_sys_openat2+0x11b/0x1d0 [ 350.063564][ T9364] ? __pfx_do_sys_openat2+0x10/0x10 [ 350.063630][ T9364] __x64_sys_openat+0x174/0x210 [ 350.063680][ T9364] ? __pfx___x64_sys_openat+0x10/0x10 [ 350.063739][ T9364] ? rcu_is_watching+0x12/0xc0 [ 350.063795][ T9364] do_syscall_64+0xcd/0x260 [ 350.063851][ T9364] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 350.063886][ T9364] RIP: 0033:0x7f7cadd8d169 [ 350.063913][ T9364] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 350.063947][ T9364] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 350.063980][ T9364] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 350.064002][ T9364] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 350.064022][ T9364] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 350.064041][ T9364] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 350.064060][ T9364] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 350.064103][ T9364] [ 351.827336][ T9403] FAULT_INJECTION: forcing a failure. [ 351.827336][ T9403] name failslab, interval 1, probability 0, space 0, times 0 [ 351.863655][ T9403] CPU: 1 UID: 0 PID: 9403 Comm: syz.3.904 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 351.863706][ T9403] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 351.863727][ T9403] Call Trace: [ 351.863739][ T9403] [ 351.863751][ T9403] dump_stack_lvl+0x16c/0x1f0 [ 351.863811][ T9403] should_fail_ex+0x512/0x640 [ 351.863856][ T9403] ? __kmalloc_node_track_caller_noprof+0xc3/0x510 [ 351.863909][ T9403] should_failslab+0xc2/0x120 [ 351.863955][ T9403] __kmalloc_node_track_caller_noprof+0xd6/0x510 [ 351.864004][ T9403] ? snd_pcm_hw_rule_add+0x414/0x5a0 [ 351.864064][ T9403] krealloc_noprof+0x1fb/0x380 [ 351.864110][ T9403] snd_pcm_hw_rule_add+0x414/0x5a0 [ 351.864161][ T9403] ? __pfx_snd_pcm_hw_rule_format+0x10/0x10 [ 351.864198][ T9403] ? __pfx_snd_pcm_hw_rule_add+0x10/0x10 [ 351.864255][ T9403] ? lockdep_init_map_type+0x5c/0x280 [ 351.864293][ T9403] ? debug_mutex_init+0x37/0x70 [ 351.864338][ T9403] ? snd_pcm_attach_substream+0x89d/0xd60 [ 351.864395][ T9403] snd_pcm_open_substream+0x534/0x17f0 [ 351.864444][ T9403] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 351.864503][ T9403] snd_pcm_oss_open+0x735/0x1400 [ 351.864566][ T9403] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 351.864604][ T9403] ? __lock_acquire+0xaa4/0x1ba0 [ 351.864638][ T9403] ? __pfx_default_wake_function+0x10/0x10 [ 351.864688][ T9403] ? __lock_acquire+0xaa4/0x1ba0 [ 351.864730][ T9403] ? do_raw_spin_lock+0x12c/0x2b0 [ 351.864773][ T9403] ? soundcore_open+0x35a/0x580 [ 351.864827][ T9403] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 351.864865][ T9403] soundcore_open+0x409/0x580 [ 351.864920][ T9403] ? __pfx_soundcore_open+0x10/0x10 [ 351.864968][ T9403] chrdev_open+0x231/0x6a0 [ 351.865006][ T9403] ? __pfx_apparmor_file_open+0x10/0x10 [ 351.865051][ T9403] ? __pfx_chrdev_open+0x10/0x10 [ 351.865093][ T9403] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 351.865138][ T9403] do_dentry_open+0x741/0x1c10 [ 351.865174][ T9403] ? __pfx_chrdev_open+0x10/0x10 [ 351.865221][ T9403] vfs_open+0x82/0x3f0 [ 351.865270][ T9403] path_openat+0x1e5e/0x2d40 [ 351.865326][ T9403] ? __pfx_path_openat+0x10/0x10 [ 351.865376][ T9403] do_filp_open+0x20b/0x470 [ 351.865416][ T9403] ? __pfx_do_filp_open+0x10/0x10 [ 351.865487][ T9403] ? alloc_fd+0x471/0x7d0 [ 351.865532][ T9403] do_sys_openat2+0x11b/0x1d0 [ 351.865590][ T9403] ? __pfx_do_sys_openat2+0x10/0x10 [ 351.865653][ T9403] __x64_sys_openat+0x174/0x210 [ 351.865702][ T9403] ? __pfx___x64_sys_openat+0x10/0x10 [ 351.865752][ T9403] ? rcu_is_watching+0x12/0xc0 [ 351.865805][ T9403] do_syscall_64+0xcd/0x260 [ 351.865859][ T9403] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 351.865890][ T9403] RIP: 0033:0x7fe21cd8d169 [ 351.865916][ T9403] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 351.865947][ T9403] RSP: 002b:00007fe21dcc2038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 351.865980][ T9403] RAX: ffffffffffffffda RBX: 00007fe21cfa5fa0 RCX: 00007fe21cd8d169 [ 351.866002][ T9403] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 351.866028][ T9403] RBP: 00007fe21ce0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 351.866046][ T9403] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 351.866064][ T9403] R13: 0000000000000000 R14: 00007fe21cfa5fa0 R15: 00007ffd12fa0298 [ 351.866103][ T9403] [ 353.223963][ T9428] FAULT_INJECTION: forcing a failure. [ 353.223963][ T9428] name failslab, interval 1, probability 0, space 0, times 0 [ 353.277714][ T9428] CPU: 0 UID: 0 PID: 9428 Comm: syz.0.910 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 353.277755][ T9428] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 353.277771][ T9428] Call Trace: [ 353.277780][ T9428] [ 353.277790][ T9428] dump_stack_lvl+0x16c/0x1f0 [ 353.277838][ T9428] should_fail_ex+0x512/0x640 [ 353.277876][ T9428] ? fs_reclaim_acquire+0xae/0x150 [ 353.277904][ T9428] ? tomoyo_encode2+0x100/0x3e0 [ 353.277943][ T9428] should_failslab+0xc2/0x120 [ 353.277979][ T9428] __kmalloc_noprof+0xd2/0x510 [ 353.278011][ T9428] ? d_absolute_path+0x136/0x1a0 [ 353.278056][ T9428] tomoyo_encode2+0x100/0x3e0 [ 353.278101][ T9428] tomoyo_encode+0x29/0x50 [ 353.278139][ T9428] tomoyo_realpath_from_path+0x18f/0x6e0 [ 353.278189][ T9428] tomoyo_path_number_perm+0x245/0x580 [ 353.278223][ T9428] ? tomoyo_path_number_perm+0x237/0x580 [ 353.278261][ T9428] ? __pfx_tomoyo_path_number_perm+0x10/0x10 [ 353.278298][ T9428] ? find_held_lock+0x2b/0x80 [ 353.278362][ T9428] ? find_held_lock+0x2b/0x80 [ 353.278395][ T9428] ? hook_file_ioctl_common+0x145/0x410 [ 353.278450][ T9428] ? __fget_files+0x20e/0x3c0 [ 353.278493][ T9428] security_file_ioctl+0x9b/0x240 [ 353.278539][ T9428] __x64_sys_ioctl+0xb7/0x200 [ 353.278592][ T9428] do_syscall_64+0xcd/0x260 [ 353.278645][ T9428] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 353.278676][ T9428] RIP: 0033:0x7f7cadd8d169 [ 353.278699][ T9428] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 353.278728][ T9428] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 353.278756][ T9428] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 353.278776][ T9428] RDX: 0000200000000040 RSI: 0000000040095505 RDI: 0000000000000003 [ 353.278794][ T9428] RBP: 00007f7caeb58090 R08: 0000000000000000 R09: 0000000000000000 [ 353.278813][ T9428] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 353.278831][ T9428] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 353.278872][ T9428] [ 353.304993][ T9428] ERROR: Out of memory at tomoyo_realpath_from_path. [ 353.307770][ C0] vkms_vblank_simulate: vblank timer overrun [ 353.507451][ C0] vkms_vblank_simulate: vblank timer overrun [ 353.760600][ T9436] netlink: 4 bytes leftover after parsing attributes in process `syz.1.905'. [ 354.632204][ T9449] netlink: 20 bytes leftover after parsing attributes in process `syz.3.913'. [ 359.066731][ T9498] zswap: compressor not available [ 359.427130][ T9497] netlink: 20 bytes leftover after parsing attributes in process `syz.2.928'. [ 359.717633][ T9510] netlink: 20 bytes leftover after parsing attributes in process `syz.0.932'. [ 360.808927][ T9519] zswap: compressor not available [ 361.592508][ T9518] Process accounting resumed [ 362.138816][ T9548] netlink: 20 bytes leftover after parsing attributes in process `syz.0.943'. [ 363.759974][ T9565] netlink: 20 bytes leftover after parsing attributes in process `syz.0.946'. [ 364.612672][ T9566] netlink: 20 bytes leftover after parsing attributes in process `syz.3.948'. [ 365.043853][ T9579] netlink: 20 bytes leftover after parsing attributes in process `syz.0.954'. [ 365.632445][ T9586] FAULT_INJECTION: forcing a failure. [ 365.632445][ T9586] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 365.646508][ T9586] CPU: 1 UID: 0 PID: 9586 Comm: syz.1.956 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 365.646552][ T9586] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 365.646571][ T9586] Call Trace: [ 365.646581][ T9586] [ 365.646592][ T9586] dump_stack_lvl+0x16c/0x1f0 [ 365.646645][ T9586] should_fail_ex+0x512/0x640 [ 365.646688][ T9586] _copy_to_user+0x32/0xd0 [ 365.646735][ T9586] io_uring_setup+0x14d1/0x2090 [ 365.646776][ T9586] ? __pfx_io_uring_setup+0x10/0x10 [ 365.646810][ T9586] ? __mutex_unlock_slowpath+0x161/0x6a0 [ 365.646873][ T9586] ? __fget_files+0x20e/0x3c0 [ 365.646921][ T9586] ? ksys_write+0x1b9/0x240 [ 365.646954][ T9586] ? __pfx_ksys_write+0x10/0x10 [ 365.646985][ T9586] ? rcu_is_watching+0x12/0xc0 [ 365.647035][ T9586] __x64_sys_io_uring_setup+0xc2/0x170 [ 365.647074][ T9586] do_syscall_64+0xcd/0x260 [ 365.647128][ T9586] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 365.647160][ T9586] RIP: 0033:0x7fb6b3d8d169 [ 365.647184][ T9586] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 365.647216][ T9586] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 00000000000001a9 [ 365.647253][ T9586] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 365.647274][ T9586] RDX: 0000000000000000 RSI: 0000200000000000 RDI: 000000000000d364 [ 365.647294][ T9586] RBP: 00007fb6b4b46090 R08: 0000000000000000 R09: 0000000000000000 [ 365.647314][ T9586] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000002 [ 365.647333][ T9586] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 365.647374][ T9586] [ 366.306455][ T9593] netlink: 20 bytes leftover after parsing attributes in process `syz.1.958'. [ 368.860316][ T9620] FAULT_INJECTION: forcing a failure. [ 368.860316][ T9620] name failslab, interval 1, probability 0, space 0, times 0 [ 368.914824][ T9622] netlink: 20 bytes leftover after parsing attributes in process `syz.2.965'. [ 368.940411][ T9620] CPU: 0 UID: 0 PID: 9620 Comm: syz.1.963 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 368.940461][ T9620] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 368.940483][ T9620] Call Trace: [ 368.940494][ T9620] [ 368.940506][ T9620] dump_stack_lvl+0x16c/0x1f0 [ 368.940566][ T9620] should_fail_ex+0x512/0x640 [ 368.940607][ T9620] ? fs_reclaim_acquire+0xae/0x150 [ 368.940643][ T9620] should_failslab+0xc2/0x120 [ 368.940690][ T9620] kmem_cache_alloc_noprof+0x6d/0x3b0 [ 368.940734][ T9620] ? security_inode_alloc+0x3b/0x2b0 [ 368.940783][ T9620] security_inode_alloc+0x3b/0x2b0 [ 368.940826][ T9620] inode_init_always_gfp+0xce4/0x1030 [ 368.940874][ T9620] alloc_inode+0x86/0x240 [ 368.940932][ T9620] new_inode+0x22/0x1c0 [ 368.940987][ T9620] __rpc_create_common+0x57/0x2f0 [ 368.941028][ T9620] rpc_populate.constprop.0+0x153/0x5d0 [ 368.941075][ T9620] rpc_fill_super+0x2bc/0x840 [ 368.941110][ T9620] ? sget_fc+0x808/0xc20 [ 368.941145][ T9620] ? __pfx_set_anon_super_fc+0x10/0x10 [ 368.941179][ T9620] ? __pfx_rpc_fill_super+0x10/0x10 [ 368.941215][ T9620] get_tree_keyed+0x10b/0x1d0 [ 368.941252][ T9620] vfs_get_tree+0x8b/0x340 [ 368.941304][ T9620] vfs_cmd_create+0xd7/0x2a0 [ 368.941354][ T9620] __do_sys_fsconfig+0x7b8/0xbe0 [ 368.941407][ T9620] ? __pfx___do_sys_fsconfig+0x10/0x10 [ 368.941455][ T9620] ? xfd_validate_state+0x5d/0x180 [ 368.941496][ T9620] ? rcu_is_watching+0x12/0xc0 [ 368.941552][ T9620] do_syscall_64+0xcd/0x260 [ 368.941607][ T9620] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 368.941641][ T9620] RIP: 0033:0x7fb6b3d8d169 [ 368.941668][ T9620] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 368.941700][ T9620] RSP: 002b:00007fb6b4b25038 EFLAGS: 00000246 ORIG_RAX: 00000000000001af [ 368.941732][ T9620] RAX: ffffffffffffffda RBX: 00007fb6b3fa6080 RCX: 00007fb6b3d8d169 [ 368.941754][ T9620] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 000000000000000b [ 368.941773][ T9620] RBP: 00007fb6b3e0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 368.941793][ T9620] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 368.941813][ T9620] R13: 0000000000000000 R14: 00007fb6b3fa6080 R15: 00007ffd1f7a1268 [ 368.941857][ T9620] [ 368.941926][ T9620] net/sunrpc/rpc_pipe.c: __rpc_create_common failed to allocate inode for dentry gssd [ 369.336249][ T9620] net/sunrpc/rpc_pipe.c: rpc_populate failed to populate directory / [ 372.279941][ T9647] netlink: 12 bytes leftover after parsing attributes in process `syz.0.972'. [ 372.923954][ T9657] netlink: 20 bytes leftover after parsing attributes in process `syz.1.975'. [ 373.451138][ T9662] FAULT_INJECTION: forcing a failure. [ 373.451138][ T9662] name failslab, interval 1, probability 0, space 0, times 0 [ 373.546149][ T9662] CPU: 1 UID: 0 PID: 9662 Comm: syz.3.977 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 373.546198][ T9662] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 373.546218][ T9662] Call Trace: [ 373.546229][ T9662] [ 373.546242][ T9662] dump_stack_lvl+0x16c/0x1f0 [ 373.546301][ T9662] should_fail_ex+0x512/0x640 [ 373.546343][ T9662] ? __kmalloc_node_track_caller_noprof+0xc3/0x510 [ 373.546396][ T9662] should_failslab+0xc2/0x120 [ 373.546441][ T9662] __kmalloc_node_track_caller_noprof+0xd6/0x510 [ 373.546496][ T9662] ? snd_pcm_hw_rule_add+0x414/0x5a0 [ 373.546558][ T9662] krealloc_noprof+0x1fb/0x380 [ 373.546606][ T9662] snd_pcm_hw_rule_add+0x414/0x5a0 [ 373.546661][ T9662] ? __pfx_snd_pcm_hw_rule_format+0x10/0x10 [ 373.546706][ T9662] ? __pfx_snd_pcm_hw_rule_add+0x10/0x10 [ 373.546763][ T9662] ? lockdep_init_map_type+0x5c/0x280 [ 373.546800][ T9662] ? debug_mutex_init+0x37/0x70 [ 373.546844][ T9662] ? snd_pcm_attach_substream+0x89d/0xd60 [ 373.546900][ T9662] snd_pcm_open_substream+0x534/0x17f0 [ 373.546948][ T9662] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 373.547010][ T9662] snd_pcm_oss_open+0x735/0x1400 [ 373.547064][ T9662] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 373.547101][ T9662] ? __lock_acquire+0xaa4/0x1ba0 [ 373.547133][ T9662] ? __pfx_default_wake_function+0x10/0x10 [ 373.547181][ T9662] ? __lock_acquire+0xaa4/0x1ba0 [ 373.547222][ T9662] ? do_raw_spin_lock+0x12c/0x2b0 [ 373.547266][ T9662] ? soundcore_open+0x35a/0x580 [ 373.547319][ T9662] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 373.547357][ T9662] soundcore_open+0x409/0x580 [ 373.547412][ T9662] ? __pfx_soundcore_open+0x10/0x10 [ 373.547470][ T9662] chrdev_open+0x231/0x6a0 [ 373.547511][ T9662] ? __pfx_apparmor_file_open+0x10/0x10 [ 373.547560][ T9662] ? __pfx_chrdev_open+0x10/0x10 [ 373.547605][ T9662] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 373.547652][ T9662] do_dentry_open+0x741/0x1c10 [ 373.547690][ T9662] ? __pfx_chrdev_open+0x10/0x10 [ 373.547741][ T9662] vfs_open+0x82/0x3f0 [ 373.547792][ T9662] path_openat+0x1e5e/0x2d40 [ 373.547848][ T9662] ? __pfx_path_openat+0x10/0x10 [ 373.547899][ T9662] do_filp_open+0x20b/0x470 [ 373.547939][ T9662] ? __pfx_do_filp_open+0x10/0x10 [ 373.548009][ T9662] ? alloc_fd+0x471/0x7d0 [ 373.548059][ T9662] do_sys_openat2+0x11b/0x1d0 [ 373.548107][ T9662] ? __pfx_do_sys_openat2+0x10/0x10 [ 373.548172][ T9662] __x64_sys_openat+0x174/0x210 [ 373.548221][ T9662] ? __pfx___x64_sys_openat+0x10/0x10 [ 373.548272][ T9662] ? rcu_is_watching+0x12/0xc0 [ 373.548327][ T9662] do_syscall_64+0xcd/0x260 [ 373.548381][ T9662] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 373.548415][ T9662] RIP: 0033:0x7fe21cd8d169 [ 373.548442][ T9662] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 373.548483][ T9662] RSP: 002b:00007fe21dcc2038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 373.548516][ T9662] RAX: ffffffffffffffda RBX: 00007fe21cfa5fa0 RCX: 00007fe21cd8d169 [ 373.548538][ T9662] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 373.548560][ T9662] RBP: 00007fe21ce0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 373.548581][ T9662] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 373.548601][ T9662] R13: 0000000000000000 R14: 00007fe21cfa5fa0 R15: 00007ffd12fa0298 [ 373.548645][ T9662] [ 373.885608][ C1] vkms_vblank_simulate: vblank timer overrun [ 374.298719][ T9668] FAULT_INJECTION: forcing a failure. [ 374.298719][ T9668] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 374.331907][ T9668] CPU: 0 UID: 0 PID: 9668 Comm: syz.1.978 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 374.331954][ T9668] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 374.331974][ T9668] Call Trace: [ 374.331985][ T9668] [ 374.331997][ T9668] dump_stack_lvl+0x16c/0x1f0 [ 374.332054][ T9668] should_fail_ex+0x512/0x640 [ 374.332103][ T9668] should_fail_alloc_page+0xe7/0x130 [ 374.332153][ T9668] prepare_alloc_pages+0x3c2/0x610 [ 374.332194][ T9668] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 374.332241][ T9668] ? stack_trace_save+0x8e/0xc0 [ 374.332286][ T9668] ? __pfx_stack_trace_save+0x10/0x10 [ 374.332331][ T9668] ? stack_depot_save_flags+0x28/0xa50 [ 374.332400][ T9668] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 374.332444][ T9668] ? kasan_save_track+0x14/0x30 [ 374.332484][ T9668] ? snd_pcm_attach_substream+0x441/0xd60 [ 374.332530][ T9668] ? snd_pcm_oss_open+0x735/0x1400 [ 374.332563][ T9668] ? soundcore_open+0x409/0x580 [ 374.332611][ T9668] ? chrdev_open+0x231/0x6a0 [ 374.332649][ T9668] ? do_dentry_open+0x741/0x1c10 [ 374.332682][ T9668] ? vfs_open+0x82/0x3f0 [ 374.332723][ T9668] ? path_openat+0x1e5e/0x2d40 [ 374.332758][ T9668] ? do_filp_open+0x20b/0x470 [ 374.332811][ T9668] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 374.332851][ T9668] ? policy_nodemask+0xea/0x4e0 [ 374.332901][ T9668] alloc_pages_mpol+0x1fb/0x550 [ 374.332949][ T9668] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 374.333008][ T9668] alloc_pages_noprof+0x131/0x390 [ 374.333056][ T9668] alloc_pages_exact_noprof+0x31/0x90 [ 374.333092][ T9668] snd_pcm_attach_substream+0x468/0xd60 [ 374.333149][ T9668] snd_pcm_open_substream+0x8d/0x17f0 [ 374.333196][ T9668] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 374.333253][ T9668] snd_pcm_oss_open+0x735/0x1400 [ 374.333306][ T9668] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 374.333343][ T9668] ? __lock_acquire+0xaa4/0x1ba0 [ 374.333383][ T9668] ? __pfx_default_wake_function+0x10/0x10 [ 374.333432][ T9668] ? __lock_acquire+0xaa4/0x1ba0 [ 374.333474][ T9668] ? do_raw_spin_lock+0x12c/0x2b0 [ 374.333516][ T9668] ? soundcore_open+0x35a/0x580 [ 374.333570][ T9668] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 374.333609][ T9668] soundcore_open+0x409/0x580 [ 374.333663][ T9668] ? __pfx_soundcore_open+0x10/0x10 [ 374.333713][ T9668] chrdev_open+0x231/0x6a0 [ 374.333753][ T9668] ? __pfx_apparmor_file_open+0x10/0x10 [ 374.333801][ T9668] ? __pfx_chrdev_open+0x10/0x10 [ 374.333846][ T9668] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 374.333892][ T9668] do_dentry_open+0x741/0x1c10 [ 374.333931][ T9668] ? __pfx_chrdev_open+0x10/0x10 [ 374.333981][ T9668] vfs_open+0x82/0x3f0 [ 374.334032][ T9668] path_openat+0x1e5e/0x2d40 [ 374.334087][ T9668] ? __pfx_path_openat+0x10/0x10 [ 374.334137][ T9668] do_filp_open+0x20b/0x470 [ 374.334177][ T9668] ? __pfx_do_filp_open+0x10/0x10 [ 374.334248][ T9668] ? alloc_fd+0x471/0x7d0 [ 374.334298][ T9668] do_sys_openat2+0x11b/0x1d0 [ 374.334346][ T9668] ? __pfx_do_sys_openat2+0x10/0x10 [ 374.334419][ T9668] __x64_sys_openat+0x174/0x210 [ 374.334469][ T9668] ? __pfx___x64_sys_openat+0x10/0x10 [ 374.334520][ T9668] ? rcu_is_watching+0x12/0xc0 [ 374.334575][ T9668] do_syscall_64+0xcd/0x260 [ 374.334630][ T9668] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 374.334664][ T9668] RIP: 0033:0x7fb6b3d8d169 [ 374.334690][ T9668] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 374.334723][ T9668] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 374.334755][ T9668] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 374.334776][ T9668] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 374.334798][ T9668] RBP: 00007fb6b3e0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 374.334818][ T9668] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 374.334838][ T9668] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 374.334880][ T9668] [ 375.385734][ T9672] netlink: 24 bytes leftover after parsing attributes in process `syz.1.980'. [ 375.405666][ T9672] netlink: 23 bytes leftover after parsing attributes in process `syz.1.980'. [ 378.594012][ T9707] netlink: 20 bytes leftover after parsing attributes in process `syz.2.988'. [ 379.906908][ T9727] netlink: 20 bytes leftover after parsing attributes in process `syz.2.992'. [ 381.086929][ T9737] zswap: compressor not available [ 383.270962][ T9771] vhci_hcd: invalid port number 242 [ 383.286220][ T9771] vhci_hcd: default hub control req: f2ff vffff i00f2 l65535 [ 383.585607][ T9778] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1007'. [ 383.897404][ T1298] ieee802154 phy0 wpan0: encryption failed: -22 [ 383.905348][ T1298] ieee802154 phy1 wpan1: encryption failed: -22 [ 385.252790][ T9801] netlink: 146 bytes leftover after parsing attributes in process `syz.2.1014'. [ 385.262421][ T9793] zswap: compressor not available [ 385.850153][ T9808] vhci_hcd: invalid port number 242 [ 385.868069][ T9808] vhci_hcd: default hub control req: f2ff vffff i00f2 l65535 [ 386.957763][ T9819] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1020'. [ 387.388557][ T9830] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1023'. [ 388.330082][ T9845] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1030'. [ 389.346879][ T9863] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1035'. [ 390.393712][ T9893] FAULT_INJECTION: forcing a failure. [ 390.393712][ T9893] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 390.408019][ T9893] CPU: 1 UID: 0 PID: 9893 Comm: syz.1.1046 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 390.408066][ T9893] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 390.408086][ T9893] Call Trace: [ 390.408097][ T9893] [ 390.408109][ T9893] dump_stack_lvl+0x16c/0x1f0 [ 390.408169][ T9893] should_fail_ex+0x512/0x640 [ 390.408220][ T9893] should_fail_alloc_page+0xe7/0x130 [ 390.408269][ T9893] prepare_alloc_pages+0x3c2/0x610 [ 390.408309][ T9893] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 390.408356][ T9893] ? stack_trace_save+0x8e/0xc0 [ 390.408402][ T9893] ? __pfx_stack_trace_save+0x10/0x10 [ 390.408447][ T9893] ? stack_depot_save_flags+0x28/0xa50 [ 390.408493][ T9893] ? __kernel_text_address+0xd/0x40 [ 390.408542][ T9893] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 390.408583][ T9893] ? kasan_save_track+0x14/0x30 [ 390.408623][ T9893] ? snd_pcm_attach_substream+0x441/0xd60 [ 390.408668][ T9893] ? snd_pcm_oss_open+0x735/0x1400 [ 390.408701][ T9893] ? soundcore_open+0x409/0x580 [ 390.408767][ T9893] ? chrdev_open+0x231/0x6a0 [ 390.408806][ T9893] ? do_dentry_open+0x741/0x1c10 [ 390.408850][ T9893] ? vfs_open+0x82/0x3f0 [ 390.408892][ T9893] ? path_openat+0x1e5e/0x2d40 [ 390.408928][ T9893] ? do_filp_open+0x20b/0x470 [ 390.408982][ T9893] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 390.409023][ T9893] ? policy_nodemask+0xea/0x4e0 [ 390.409073][ T9893] alloc_pages_mpol+0x1fb/0x550 [ 390.409122][ T9893] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 390.409182][ T9893] alloc_pages_noprof+0x131/0x390 [ 390.409230][ T9893] alloc_pages_exact_noprof+0x31/0x90 [ 390.409265][ T9893] snd_pcm_attach_substream+0x468/0xd60 [ 390.409322][ T9893] snd_pcm_open_substream+0x8d/0x17f0 [ 390.409369][ T9893] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 390.409427][ T9893] snd_pcm_oss_open+0x735/0x1400 [ 390.409479][ T9893] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 390.409517][ T9893] ? __lock_acquire+0xaa4/0x1ba0 [ 390.409549][ T9893] ? __pfx_default_wake_function+0x10/0x10 [ 390.409597][ T9893] ? __lock_acquire+0xaa4/0x1ba0 [ 390.409639][ T9893] ? do_raw_spin_lock+0x12c/0x2b0 [ 390.409681][ T9893] ? soundcore_open+0x35a/0x580 [ 390.409734][ T9893] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 390.409772][ T9893] soundcore_open+0x409/0x580 [ 390.409827][ T9893] ? __pfx_soundcore_open+0x10/0x10 [ 390.409884][ T9893] chrdev_open+0x231/0x6a0 [ 390.409923][ T9893] ? __pfx_apparmor_file_open+0x10/0x10 [ 390.409971][ T9893] ? __pfx_chrdev_open+0x10/0x10 [ 390.410015][ T9893] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 390.410062][ T9893] do_dentry_open+0x741/0x1c10 [ 390.410100][ T9893] ? __pfx_chrdev_open+0x10/0x10 [ 390.410149][ T9893] vfs_open+0x82/0x3f0 [ 390.410197][ T9893] path_openat+0x1e5e/0x2d40 [ 390.410247][ T9893] ? __pfx_path_openat+0x10/0x10 [ 390.410294][ T9893] do_filp_open+0x20b/0x470 [ 390.410331][ T9893] ? __pfx_do_filp_open+0x10/0x10 [ 390.410398][ T9893] ? alloc_fd+0x471/0x7d0 [ 390.410447][ T9893] do_sys_openat2+0x11b/0x1d0 [ 390.410496][ T9893] ? __pfx_do_sys_openat2+0x10/0x10 [ 390.410561][ T9893] __x64_sys_openat+0x174/0x210 [ 390.410610][ T9893] ? __pfx___x64_sys_openat+0x10/0x10 [ 390.410661][ T9893] ? rcu_is_watching+0x12/0xc0 [ 390.410715][ T9893] do_syscall_64+0xcd/0x260 [ 390.410768][ T9893] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 390.410801][ T9893] RIP: 0033:0x7fb6b3d8d169 [ 390.410826][ T9893] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 390.410869][ T9893] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 390.410902][ T9893] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 390.410922][ T9893] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 390.410941][ T9893] RBP: 00007fb6b3e0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 390.410958][ T9893] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 390.410976][ T9893] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 390.411015][ T9893] [ 390.451824][ T9891] FAULT_INJECTION: forcing a failure. [ 390.451824][ T9891] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 390.453501][ C1] vkms_vblank_simulate: vblank timer overrun [ 390.502706][ T9891] CPU: 0 UID: 0 PID: 9891 Comm: syz.0.1045 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 390.502759][ T9891] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 390.502781][ T9891] Call Trace: [ 390.502793][ T9891] [ 390.502807][ T9891] dump_stack_lvl+0x16c/0x1f0 [ 390.502872][ T9891] should_fail_ex+0x512/0x640 [ 390.502925][ T9891] should_fail_alloc_page+0xe7/0x130 [ 390.502978][ T9891] prepare_alloc_pages+0x3c2/0x610 [ 390.503020][ T9891] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 390.503069][ T9891] ? stack_trace_save+0x8e/0xc0 [ 390.503127][ T9891] ? __pfx_stack_trace_save+0x10/0x10 [ 390.503174][ T9891] ? stack_depot_save_flags+0x28/0xa50 [ 390.503234][ T9891] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 390.503279][ T9891] ? kasan_save_track+0x14/0x30 [ 390.503320][ T9891] ? snd_pcm_attach_substream+0x441/0xd60 [ 390.503370][ T9891] ? snd_pcm_oss_open+0x735/0x1400 [ 390.503404][ T9891] ? soundcore_open+0x409/0x580 [ 390.503456][ T9891] ? chrdev_open+0x231/0x6a0 [ 390.503495][ T9891] ? do_dentry_open+0x741/0x1c10 [ 390.503530][ T9891] ? vfs_open+0x82/0x3f0 [ 390.503574][ T9891] ? path_openat+0x1e5e/0x2d40 [ 390.503609][ T9891] ? do_filp_open+0x20b/0x470 [ 390.503664][ T9891] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 390.503706][ T9891] ? policy_nodemask+0xea/0x4e0 [ 390.503758][ T9891] alloc_pages_mpol+0x1fb/0x550 [ 390.503808][ T9891] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 390.503869][ T9891] alloc_pages_noprof+0x131/0x390 [ 390.503918][ T9891] alloc_pages_exact_noprof+0x31/0x90 [ 390.503955][ T9891] snd_pcm_attach_substream+0x468/0xd60 [ 390.504013][ T9891] snd_pcm_open_substream+0x8d/0x17f0 [ 390.504062][ T9891] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 390.504129][ T9891] snd_pcm_oss_open+0x735/0x1400 [ 390.504184][ T9891] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 390.504222][ T9891] ? __lock_acquire+0xaa4/0x1ba0 [ 390.504256][ T9891] ? __pfx_default_wake_function+0x10/0x10 [ 390.504308][ T9891] ? __lock_acquire+0xaa4/0x1ba0 [ 390.504351][ T9891] ? do_raw_spin_lock+0x12c/0x2b0 [ 390.504395][ T9891] ? soundcore_open+0x35a/0x580 [ 390.504450][ T9891] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 390.504490][ T9891] soundcore_open+0x409/0x580 [ 390.504546][ T9891] ? __pfx_soundcore_open+0x10/0x10 [ 390.504600][ T9891] chrdev_open+0x231/0x6a0 [ 390.504640][ T9891] ? __pfx_apparmor_file_open+0x10/0x10 [ 390.504691][ T9891] ? __pfx_chrdev_open+0x10/0x10 [ 390.504736][ T9891] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 390.504786][ T9891] do_dentry_open+0x741/0x1c10 [ 390.504826][ T9891] ? __pfx_chrdev_open+0x10/0x10 [ 390.504877][ T9891] vfs_open+0x82/0x3f0 [ 390.504930][ T9891] path_openat+0x1e5e/0x2d40 [ 390.504987][ T9891] ? __pfx_path_openat+0x10/0x10 [ 390.505039][ T9891] do_filp_open+0x20b/0x470 [ 390.505086][ T9891] ? __pfx_do_filp_open+0x10/0x10 [ 390.505159][ T9891] ? alloc_fd+0x471/0x7d0 [ 390.505210][ T9891] do_sys_openat2+0x11b/0x1d0 [ 390.505261][ T9891] ? __pfx_do_sys_openat2+0x10/0x10 [ 390.505329][ T9891] __x64_sys_openat+0x174/0x210 [ 390.505380][ T9891] ? __pfx___x64_sys_openat+0x10/0x10 [ 390.505433][ T9891] ? rcu_is_watching+0x12/0xc0 [ 390.505490][ T9891] do_syscall_64+0xcd/0x260 [ 390.505559][ T9891] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 390.505596][ T9891] RIP: 0033:0x7f7cadd8d169 [ 390.505623][ T9891] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 390.505659][ T9891] RSP: 002b:00007f7caeb58038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 390.505692][ T9891] RAX: ffffffffffffffda RBX: 00007f7cadfa5fa0 RCX: 00007f7cadd8d169 [ 390.505715][ T9891] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 390.505737][ T9891] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 390.505759][ T9891] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 390.505778][ T9891] R13: 0000000000000000 R14: 00007f7cadfa5fa0 R15: 00007ffda25118b8 [ 390.505831][ T9891] [ 391.217322][ C1] vkms_vblank_simulate: vblank timer overrun [ 391.832731][ T9889] Process accounting paused [ 394.182197][ T9932] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1056'. [ 394.280893][ T9930] netlink: 338 bytes leftover after parsing attributes in process `syz.0.1055'. [ 394.291708][ T9930] mac80211_hwsim hwsim6 wlan0: entered promiscuous mode [ 394.388934][ T9937] FAULT_INJECTION: forcing a failure. [ 394.388934][ T9937] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 394.413622][ T9937] CPU: 0 UID: 0 PID: 9937 Comm: syz.3.1057 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 394.413679][ T9937] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 394.413697][ T9937] Call Trace: [ 394.413707][ T9937] [ 394.413720][ T9937] dump_stack_lvl+0x16c/0x1f0 [ 394.413777][ T9937] should_fail_ex+0x512/0x640 [ 394.413825][ T9937] _copy_from_user+0x2e/0xd0 [ 394.413871][ T9937] __x64_sys_epoll_ctl+0x131/0x1e0 [ 394.413910][ T9937] ? __pfx___x64_sys_epoll_ctl+0x10/0x10 [ 394.413945][ T9937] ? rcu_is_watching+0x12/0xc0 [ 394.413997][ T9937] do_syscall_64+0xcd/0x260 [ 394.414047][ T9937] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 394.414080][ T9937] RIP: 0033:0x7fe21cd8d169 [ 394.414106][ T9937] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 394.414138][ T9937] RSP: 002b:00007fe21dcc2038 EFLAGS: 00000246 ORIG_RAX: 00000000000000e9 [ 394.414167][ T9937] RAX: ffffffffffffffda RBX: 00007fe21cfa5fa0 RCX: 00007fe21cd8d169 [ 394.414188][ T9937] RDX: 8000000000000000 RSI: 0000000000000001 RDI: 0000000000000001 [ 394.414207][ T9937] RBP: 00007fe21dcc2090 R08: 0000000000000000 R09: 0000000000000000 [ 394.414227][ T9937] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 394.414245][ T9937] R13: 0000000000000000 R14: 00007fe21cfa5fa0 R15: 00007ffd12fa0298 [ 394.414286][ T9937] [ 395.153399][ T9951] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1063'. [ 395.370239][ T9961] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1065'. [ 398.397262][T10018] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1084'. [ 398.700753][T10023] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1085'. [ 400.103819][T10042] FAULT_INJECTION: forcing a failure. [ 400.103819][T10042] name failslab, interval 1, probability 0, space 0, times 0 [ 400.166883][T10042] CPU: 1 UID: 0 PID: 10042 Comm: syz.3.1092 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 400.166931][T10042] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 400.166952][T10042] Call Trace: [ 400.166963][T10042] [ 400.166975][T10042] dump_stack_lvl+0x16c/0x1f0 [ 400.167034][T10042] should_fail_ex+0x512/0x640 [ 400.167077][T10042] ? kmem_cache_alloc_noprof+0x5a/0x3b0 [ 400.167125][T10042] should_failslab+0xc2/0x120 [ 400.167171][T10042] kmem_cache_alloc_noprof+0x6d/0x3b0 [ 400.167212][T10042] ? __proc_create+0xc3/0x8c0 [ 400.167258][T10042] ? __proc_create+0x2ce/0x8c0 [ 400.167311][T10042] __proc_create+0x2ce/0x8c0 [ 400.167361][T10042] ? __pfx___proc_create+0x10/0x10 [ 400.167420][T10042] ? _raw_write_unlock+0x28/0x50 [ 400.167473][T10042] proc_create_reg+0x7d/0x180 [ 400.167528][T10042] proc_create_data+0x86/0x110 [ 400.167579][T10042] ? __pfx_proc_create_data+0x10/0x10 [ 400.167634][T10042] ? cache_register_net+0x137/0x5e0 [ 400.167688][T10042] cache_register_net+0x1e0/0x5e0 [ 400.167739][T10042] gss_svc_init_net+0x151/0x660 [ 400.167791][T10042] ? __pfx_canbcm_pernet_init+0x10/0x10 [ 400.167851][T10042] ? __pfx_rpcsec_gss_init_net+0x10/0x10 [ 400.167892][T10042] ops_init+0x1df/0x5f0 [ 400.167950][T10042] setup_net+0x21e/0x850 [ 400.168007][T10042] ? __pfx_setup_net+0x10/0x10 [ 400.168056][T10042] ? lockdep_init_map_type+0x5c/0x280 [ 400.168090][T10042] ? __pfx_down_read_killable+0x10/0x10 [ 400.168130][T10042] ? debug_mutex_init+0x37/0x70 [ 400.168178][T10042] copy_net_ns+0x2a6/0x5f0 [ 400.168216][T10042] create_new_namespaces+0x3ea/0xad0 [ 400.168275][T10042] unshare_nsproxy_namespaces+0xc0/0x1f0 [ 400.168330][T10042] ksys_unshare+0x45b/0xa40 [ 400.168360][T10042] ? __pfx_ksys_unshare+0x10/0x10 [ 400.168385][T10042] ? xfd_validate_state+0x5d/0x180 [ 400.168423][T10042] ? rcu_is_watching+0x12/0xc0 [ 400.168460][T10042] __x64_sys_unshare+0x31/0x40 [ 400.168480][T10042] do_syscall_64+0xcd/0x260 [ 400.168519][T10042] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 400.168543][T10042] RIP: 0033:0x7fe21cd8d169 [ 400.168561][T10042] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 400.168584][T10042] RSP: 002b:00007fe21dca1038 EFLAGS: 00000246 ORIG_RAX: 0000000000000110 [ 400.168606][T10042] RAX: ffffffffffffffda RBX: 00007fe21cfa6080 RCX: 00007fe21cd8d169 [ 400.168622][T10042] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000040000080 [ 400.168635][T10042] RBP: 00007fe21ce0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 400.168650][T10042] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 400.168663][T10042] R13: 0000000000000000 R14: 00007fe21cfa6080 R15: 00007ffd12fa0298 [ 400.168692][T10042] [ 400.448539][ C1] vkms_vblank_simulate: vblank timer overrun [ 401.290112][T10048] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1093'. [ 401.651692][T10061] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1095'. [ 401.914676][T10062] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1098'. [ 402.871611][T10069] netlink: 28 bytes leftover after parsing attributes in process `syz.3.1099'. [ 404.485329][T10092] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1106'. [ 406.195674][T10112] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1111'. [ 406.651996][T10126] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1115'. [ 407.672996][T10133] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1117'. [ 407.863026][T10137] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1119'. [ 408.165518][T10146] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1123'. [ 408.661897][T10159] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1128'. [ 410.007964][T10179] netlink: 36 bytes leftover after parsing attributes in process `syz.2.1136'. [ 411.514608][T10200] FAULT_INJECTION: forcing a failure. [ 411.514608][T10200] name failslab, interval 1, probability 0, space 0, times 0 [ 411.549776][T10200] CPU: 0 UID: 0 PID: 10200 Comm: syz.3.1141 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 411.549819][T10200] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 411.549836][T10200] Call Trace: [ 411.549847][T10200] [ 411.549858][T10200] dump_stack_lvl+0x16c/0x1f0 [ 411.549910][T10200] should_fail_ex+0x512/0x640 [ 411.549948][T10200] ? __kmalloc_node_track_caller_noprof+0xc3/0x510 [ 411.550001][T10200] should_failslab+0xc2/0x120 [ 411.550047][T10200] __kmalloc_node_track_caller_noprof+0xd6/0x510 [ 411.550095][T10200] ? snd_pcm_hw_rule_add+0x414/0x5a0 [ 411.550155][T10200] krealloc_noprof+0x1fb/0x380 [ 411.550201][T10200] snd_pcm_hw_rule_add+0x414/0x5a0 [ 411.550255][T10200] ? __pfx_snd_pcm_hw_rule_format+0x10/0x10 [ 411.550296][T10200] ? __pfx_snd_pcm_hw_rule_add+0x10/0x10 [ 411.550351][T10200] ? lockdep_init_map_type+0x5c/0x280 [ 411.550388][T10200] ? debug_mutex_init+0x37/0x70 [ 411.550425][T10200] ? snd_pcm_attach_substream+0x89d/0xd60 [ 411.550472][T10200] snd_pcm_open_substream+0x534/0x17f0 [ 411.550512][T10200] ? __pfx_snd_pcm_open_substream+0x10/0x10 [ 411.550559][T10200] snd_pcm_oss_open+0x735/0x1400 [ 411.550602][T10200] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 411.550633][T10200] ? __lock_acquire+0xaa4/0x1ba0 [ 411.550662][T10200] ? __pfx_default_wake_function+0x10/0x10 [ 411.550717][T10200] ? __lock_acquire+0xaa4/0x1ba0 [ 411.550759][T10200] ? do_raw_spin_lock+0x12c/0x2b0 [ 411.550801][T10200] ? soundcore_open+0x35a/0x580 [ 411.550853][T10200] ? __pfx_snd_pcm_oss_open+0x10/0x10 [ 411.550891][T10200] soundcore_open+0x409/0x580 [ 411.550944][T10200] ? __pfx_soundcore_open+0x10/0x10 [ 411.550995][T10200] chrdev_open+0x231/0x6a0 [ 411.551035][T10200] ? __pfx_apparmor_file_open+0x10/0x10 [ 411.551082][T10200] ? __pfx_chrdev_open+0x10/0x10 [ 411.551126][T10200] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 411.551171][T10200] do_dentry_open+0x741/0x1c10 [ 411.551209][T10200] ? __pfx_chrdev_open+0x10/0x10 [ 411.551260][T10200] vfs_open+0x82/0x3f0 [ 411.551309][T10200] path_openat+0x1e5e/0x2d40 [ 411.551364][T10200] ? __pfx_path_openat+0x10/0x10 [ 411.551409][T10200] do_filp_open+0x20b/0x470 [ 411.551446][T10200] ? __pfx_do_filp_open+0x10/0x10 [ 411.551515][T10200] ? alloc_fd+0x471/0x7d0 [ 411.551565][T10200] do_sys_openat2+0x11b/0x1d0 [ 411.551612][T10200] ? __pfx_do_sys_openat2+0x10/0x10 [ 411.551673][T10200] __x64_sys_openat+0x174/0x210 [ 411.551731][T10200] ? __pfx___x64_sys_openat+0x10/0x10 [ 411.551779][T10200] ? rcu_is_watching+0x12/0xc0 [ 411.551833][T10200] do_syscall_64+0xcd/0x260 [ 411.551889][T10200] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 411.551923][T10200] RIP: 0033:0x7fe21cd8d169 [ 411.551949][T10200] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 411.551983][T10200] RSP: 002b:00007fe21dcc2038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 411.552014][T10200] RAX: ffffffffffffffda RBX: 00007fe21cfa5fa0 RCX: 00007fe21cd8d169 [ 411.552036][T10200] RDX: 0000000000040000 RSI: 00002000000000c0 RDI: ffffffffffffff9c [ 411.552056][T10200] RBP: 00007fe21ce0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 411.552075][T10200] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 411.552095][T10200] R13: 0000000000000000 R14: 00007fe21cfa5fa0 R15: 00007ffd12fa0298 [ 411.552137][T10200] [ 412.579857][T10213] i2c i2c-0: dtv_property_process_set: SET cmd 0x00000000 undefined [ 412.768295][T10219] netlink: 36 bytes leftover after parsing attributes in process `syz.0.1147'. [ 412.989649][T10227] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 413.252558][T10223] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1149'. [ 413.507476][T10230] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1150'. [ 414.671209][T10245] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1157'. [ 414.828313][T10252] zswap: compressor not available [ 415.179896][T10268] [U] [ 415.182710][T10268] [U] [ 415.185472][T10268] [U] [ 415.188237][T10268] [U] [ 415.271316][T10268] [U] [ 415.274119][T10268] [U] [ 415.276886][T10268] [U] [ 415.279647][T10268] [U] [ 415.304741][T10268] [U] [ 415.307548][T10268] [U] [ 415.310305][T10268] [U] [ 415.313061][T10268] [U] [ 415.369369][T10268] [U] [ 415.372176][T10268] [U] [ 415.374932][T10268] [U] [ 415.377687][T10268] [U] [ 415.424120][T10268] [U] [ 415.426934][T10268] [U] [ 415.429692][T10268] [U] [ 415.432441][T10268] [U] [ 415.519216][T10268] [U] [ 415.522039][T10268] [U] [ 415.524788][T10268] [U] [ 415.527521][T10268] [U] [ 415.609279][T10268] [U] [ 415.612084][T10268] [U] [ 415.614840][T10268] [U] [ 415.617596][T10268] [U] [ 415.630994][T10268] [U] [ 415.633791][T10268] [U] [ 415.636558][T10268] [U] [ 415.639320][T10268] [U] [ 415.656533][T10268] [U] [ 415.659319][T10268] [U] [ 415.662063][T10268] [U] [ 415.664817][T10268] [U] [ 415.668326][ T30] audit: type=1800 audit(6038434349.627:10): pid=10273 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.1.1164" name="dummy_udc" dev="gadgetfs" ino=5825 res=0 errno=0 [ 415.797221][T10268] [U] [ 415.800038][T10268] [U] [ 415.802796][T10268] [U] [ 415.805549][T10268] [U] [ 415.861264][T10268] [U] [ 416.029753][ T30] audit: type=1800 audit(6038434349.997:11): pid=10281 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.3.1166" name="discovery_nqn" dev="configfs" ino=24078 res=0 errno=0 [ 416.312778][T10286] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1167'. [ 417.090153][T10303] netlink: 36 bytes leftover after parsing attributes in process `syz.3.1173'. [ 420.063694][T10328] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1180'. [ 420.730928][T10337] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1183'. [ 421.125477][T10341] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1185'. [ 422.473387][T10358] Process accounting resumed [ 422.663236][T10369] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1193'. [ 422.997150][T10370] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1194'. [ 423.765527][T10381] netlink: 28 bytes leftover after parsing attributes in process `syz.0.1195'. [ 425.791253][T10399] netlink: 334 bytes leftover after parsing attributes in process `syz.3.1201'. [ 426.354951][T10408] netlink: 12 bytes leftover after parsing attributes in process `syz.0.1205'. [ 428.355382][T10427] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 428.465566][T10430] netlink: 4 bytes leftover after parsing attributes in process `syz.2.1212'. [ 428.567416][T10430] netlink: 4 bytes leftover after parsing attributes in process `syz.2.1212'. [ 428.979689][T10438] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1214'. [ 429.183108][T10440] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1215'. [ 429.635665][T10443] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1216'. [ 430.494281][T10447] [U] [ 430.497092][T10447] [U] [ 430.499843][T10447] [U] [ 430.502579][T10447] [U] [ 430.555684][T10447] [U] [ 430.558489][T10447] [U] [ 430.561256][T10447] [U] [ 430.564015][T10447] [U] [ 430.604664][T10447] [U] [ 430.607489][T10447] [U] [ 430.610245][T10447] [U] [ 430.612999][T10447] [U] [ 430.656440][T10447] [U] [ 430.659243][T10447] [U] [ 430.662002][T10447] [U] [ 430.664798][T10447] [U] [ 430.668609][T10448] [U] [ 431.238890][T10459] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 432.941274][T10474] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1223'. [ 433.006361][T10477] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1224'. [ 433.092991][T10480] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1226'. [ 433.118398][T10480] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1226'. [ 433.156716][T10482] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 433.304654][T10487] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1228'. [ 433.529138][T10491] netlink: 36 bytes leftover after parsing attributes in process `syz.2.1229'. [ 433.780939][T10497] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1230'. [ 433.856757][T10496] netlink: 16 bytes leftover after parsing attributes in process `syz.2.1231'. [ 434.692253][T10506] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1232'. [ 435.485753][T10510] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1236'. [ 437.996675][T10549] vxcan1: tx drop: invalid sa for name 0x00000000000000fd [ 438.095367][T10552] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 438.945200][T10560] __nla_validate_parse: 3 callbacks suppressed [ 438.945233][T10560] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1250'. [ 439.841924][T10573] netlink: 4 bytes leftover after parsing attributes in process `syz.3.1256'. [ 439.902318][T10575] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1257'. [ 440.967961][T10593] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1261'. [ 441.913217][T10603] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 442.747977][T10609] netlink: 36 bytes leftover after parsing attributes in process `syz.0.1268'. [ 444.539610][T10635] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 445.333141][ T1298] ieee802154 phy0 wpan0: encryption failed: -22 [ 445.339618][ T1298] ieee802154 phy1 wpan1: encryption failed: -22 syzkaller syzkaller login: [ 445.702950][T10647] netlink: 4 bytes leftover after parsing attributes in process `syz.0.1278'. [ 446.187757][T10654] netlink: 146 bytes leftover after parsing attributes in process `syz.0.1281'. [ 446.356358][T10656] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1279'. [ 447.795578][T10675] netlink: 36 bytes leftover after parsing attributes in process `syz.2.1287'. [ 447.992708][T10679] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1288'. [ 448.009771][T10658] sd 0:0:1:0: PR command failed: 1026 [ 448.031890][T10658] sd 0:0:1:0: Sense Key : Illegal Request [current] [ 448.063671][T10658] sd 0:0:1:0: Add. Sense: Invalid command operation code [ 450.385466][T10717] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1297'. [ 450.399839][T10714] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x79000 [ 450.487910][T10714] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 450.615437][T10714] flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff) [ 450.778704][T10714] page_type: f5(slab) [ 450.815343][T10714] raw: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 450.873029][T10714] raw: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 450.881828][T10714] head: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 450.891192][T10714] head: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 450.900231][T10714] head: 00fff00000000002 ffffea0001e40001 ffffffffffffffff 0000000000000000 [ 450.909041][T10714] head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000 [ 450.918177][T10714] page dumped because: unmovable page [ 450.923606][T10714] page_owner tracks the page as allocated [ 450.929826][T10714] page last allocated via order 2, migratetype Reclaimable, gfp_mask 0xd20d0(__GFP_RECLAIMABLE|__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5838, tgid 5838 (syz-executor), ts 97491221650, free_ts 35045899222 [ 450.953232][T10714] post_alloc_hook+0x181/0x1b0 [ 450.958162][T10714] get_page_from_freelist+0x10fc/0x35c0 [ 450.963791][T10714] __alloc_frozen_pages_noprof+0x223/0x2370 [ 450.969841][T10714] alloc_pages_mpol+0x1fb/0x550 [ 450.974776][T10714] new_slab+0x23c/0x330 [ 450.979103][T10714] ___slab_alloc+0xd9c/0x1940 [ 450.983854][T10714] __slab_alloc.constprop.0+0x56/0xb0 [ 450.989403][T10714] kmem_cache_alloc_lru_noprof+0xf4/0x3b0 [ 450.995212][T10714] alloc_inode+0x61/0x240 [ 450.999706][T10714] new_inode+0x22/0x1c0 [ 451.003939][T10714] __debugfs_create_file+0x11c/0x6b0 [ 451.010932][T10714] debugfs_create_file_unsafe+0x3c/0x50 [ 451.016678][T10714] debugfs_create_u32+0x70/0xa0 [ 451.021923][T10714] nsim_ethtool_init+0x3a5/0x5c0 [ 451.027040][T10714] nsim_create+0x247/0xb00 [ 451.031520][T10714] __nsim_dev_port_add+0x42b/0x7d0 [ 451.036796][T10714] page last free pid 1 tgid 1 stack trace: [ 451.042657][T10714] __free_frozen_pages+0x69d/0xf90 [ 451.047951][T10714] free_contig_range+0x135/0x3f0 [ 451.052965][T10714] destroy_args+0x66f/0x830 [ 451.057605][T10714] debug_vm_pgtable+0x130e/0x2d50 [ 451.065963][T10714] do_one_initcall+0x120/0x6e0 [ 451.082551][T10714] kernel_init_freeable+0x5c2/0x900 [ 451.106041][T10714] kernel_init+0x1c/0x2b0 [ 451.110476][T10714] ret_from_fork+0x45/0x80 [ 451.114960][T10714] ret_from_fork_asm+0x1a/0x30 [ 453.442134][T10755] netlink: 36 bytes leftover after parsing attributes in process `syz.2.1309'. [ 453.729604][T10762] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1310'. [ 455.033044][ T48] Process accounting resumed [ 455.063777][T10723] Process accounting paused [ 455.431172][T10781] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1317'. [ 456.943225][T10800] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 458.033186][T10824] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1332'. [ 459.092762][T10837] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 459.972835][T10844] FAULT_INJECTION: forcing a failure. [ 459.972835][T10844] name failslab, interval 1, probability 0, space 0, times 0 [ 459.989297][T10844] CPU: 1 UID: 0 PID: 10844 Comm: syz.3.1340 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 459.989347][T10844] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 459.989367][T10844] Call Trace: [ 459.989378][T10844] [ 459.989391][T10844] dump_stack_lvl+0x16c/0x1f0 [ 459.989450][T10844] should_fail_ex+0x512/0x640 [ 459.989492][T10844] ? fs_reclaim_acquire+0xae/0x150 [ 459.989526][T10844] ? tomoyo_encode2+0x100/0x3e0 [ 459.989575][T10844] should_failslab+0xc2/0x120 [ 459.989620][T10844] __kmalloc_noprof+0xd2/0x510 [ 459.989660][T10844] ? d_absolute_path+0x136/0x1a0 [ 459.989716][T10844] tomoyo_encode2+0x100/0x3e0 [ 459.989772][T10844] tomoyo_encode+0x29/0x50 [ 459.989820][T10844] tomoyo_realpath_from_path+0x18f/0x6e0 [ 459.989891][T10844] tomoyo_check_open_permission+0x2ab/0x3c0 [ 459.989940][T10844] ? __pfx_tomoyo_check_open_permission+0x10/0x10 [ 459.990029][T10844] ? do_raw_spin_lock+0x12c/0x2b0 [ 459.990081][T10844] tomoyo_file_open+0x6b/0x90 [ 459.990119][T10844] security_file_open+0x84/0x1e0 [ 459.990169][T10844] do_dentry_open+0x596/0x1c10 [ 459.990219][T10844] vfs_open+0x82/0x3f0 [ 459.990270][T10844] path_openat+0x1e5e/0x2d40 [ 459.990325][T10844] ? __pfx_path_openat+0x10/0x10 [ 459.990377][T10844] do_filp_open+0x20b/0x470 [ 459.990417][T10844] ? __pfx_do_filp_open+0x10/0x10 [ 459.990487][T10844] ? alloc_fd+0x471/0x7d0 [ 459.990536][T10844] do_sys_openat2+0x11b/0x1d0 [ 459.990586][T10844] ? __pfx_do_sys_openat2+0x10/0x10 [ 459.990649][T10844] __x64_sys_openat+0x174/0x210 [ 459.990698][T10844] ? __pfx___x64_sys_openat+0x10/0x10 [ 459.990749][T10844] ? rcu_is_watching+0x12/0xc0 [ 459.990804][T10844] do_syscall_64+0xcd/0x260 [ 459.990860][T10844] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 459.990900][T10844] RIP: 0033:0x7fe21cd8d169 [ 459.990927][T10844] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 459.990960][T10844] RSP: 002b:00007fe21dcc2038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 459.990994][T10844] RAX: ffffffffffffffda RBX: 00007fe21cfa5fa0 RCX: 00007fe21cd8d169 [ 459.991015][T10844] RDX: 0000000000080000 RSI: 0000200000000080 RDI: ffffffffffffff9c [ 459.991037][T10844] RBP: 00007fe21ce0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 459.991057][T10844] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 459.991077][T10844] R13: 0000000000000000 R14: 00007fe21cfa5fa0 R15: 00007ffd12fa0298 [ 459.991121][T10844] [ 459.991155][T10844] ERROR: Out of memory at tomoyo_realpath_from_path. [ 460.648138][ T30] audit: type=1800 audit(6038434394.607:12): pid=10856 uid=0 auid=4294967295 ses=4294967295 subj=unconfined op=collect_data cause=failed comm="syz.3.1344" name="lu_gp_id" dev="configfs" ino=27221 res=0 errno=0 [ 461.531648][T10870] capability: warning: `syz.2.1347' uses deprecated v2 capabilities in a way that may be insecure [ 462.921331][T10885] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 463.174110][T10888] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1352'. [ 463.589108][T10900] usb usb38: Requested nonsensical USBDEVFS_URB_SHORT_NOT_OK. [ 463.606216][T10900] vhci_hcd: default hub control req: 0000 v0000 i0000 l0 [ 465.207347][T10922] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 465.403916][T10924] netlink: 8 bytes leftover after parsing attributes in process `syz.3.1363'. [ 465.562412][T10924] mkiss: ax0: crc mode is auto. [ 466.653541][T10939] netlink: 36 bytes leftover after parsing attributes in process `syz.3.1367'. [ 467.061118][T10945] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1369'. [ 467.377827][T10952] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1371'. [ 468.216631][T10964] zswap: compressor not available [ 470.207499][T10993] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1384'. [ 470.377718][T10997] netlink: 342 bytes leftover after parsing attributes in process `syz.2.1386'. [ 470.517107][T11003] FAULT_INJECTION: forcing a failure. [ 470.517107][T11003] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 470.542457][T11003] CPU: 0 UID: 0 PID: 11003 Comm: syz.1.1389 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 470.542504][T11003] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 470.542523][T11003] Call Trace: [ 470.542534][T11003] [ 470.542545][T11003] dump_stack_lvl+0x16c/0x1f0 [ 470.542602][T11003] should_fail_ex+0x512/0x640 [ 470.542650][T11003] _copy_from_user+0x2e/0xd0 [ 470.542697][T11003] memdup_user+0x6b/0xe0 [ 470.542728][T11003] raw_ioctl+0xc1f/0x2c30 [ 470.542787][T11003] ? __pfx_raw_ioctl+0x10/0x10 [ 470.542844][T11003] ? __pfx_raw_ioctl+0x10/0x10 [ 470.542903][T11003] __x64_sys_ioctl+0x190/0x200 [ 470.542959][T11003] do_syscall_64+0xcd/0x260 [ 470.543013][T11003] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 470.543046][T11003] RIP: 0033:0x7fb6b3d8d169 [ 470.543072][T11003] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 470.543103][T11003] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 470.543132][T11003] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 470.543153][T11003] RDX: 0000200000000040 RSI: 0000000040095505 RDI: 0000000000000003 [ 470.543173][T11003] RBP: 00007fb6b4b46090 R08: 0000000000000000 R09: 0000000000000000 [ 470.543193][T11003] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 470.543213][T11003] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 470.543254][T11003] [ 470.700353][ C0] vkms_vblank_simulate: vblank timer overrun [ 472.280143][T11021] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1395'. [ 472.373386][T11024] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1396'. [ 472.567172][T11028] netlink: 36 bytes leftover after parsing attributes in process `syz.3.1398'. [ 474.051494][T11048] zswap: compressor not available [ 475.521192][T11063] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 476.093991][T11066] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1409'. [ 477.958194][T11094] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 478.593383][T11101] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 479.872480][T11121] program syz.0.1426 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 480.331161][T11132] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1429'. [ 480.391013][T11133] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x79000 [ 480.426891][T11133] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 480.436234][T11133] flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff) [ 480.482926][T11133] page_type: f5(slab) [ 480.493943][T11133] raw: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 480.534927][T11133] raw: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 480.564936][T11133] head: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 480.594718][T11133] head: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 480.624901][T11133] head: 00fff00000000002 ffffea0001e40001 ffffffffffffffff 0000000000000000 [ 480.646320][T11133] head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000 [ 480.677846][T11133] page dumped because: unmovable page [ 480.683975][T11142] hub 8-0:1.0: USB hub found [ 480.707446][T11133] page_owner tracks the page as allocated [ 480.717898][T11142] hub 8-0:1.0: 1 port detected [ 480.720176][T11133] page last allocated via order 2, migratetype Reclaimable, gfp_mask 0xd20d0(__GFP_RECLAIMABLE|__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5838, tgid 5838 (syz-executor), ts 97491221650, free_ts 35045899222 [ 480.806197][T11133] post_alloc_hook+0x181/0x1b0 [ 480.823508][T11133] get_page_from_freelist+0x10fc/0x35c0 [ 480.841724][T11133] __alloc_frozen_pages_noprof+0x223/0x2370 [ 480.886656][T11133] alloc_pages_mpol+0x1fb/0x550 [ 480.891979][T11133] new_slab+0x23c/0x330 [ 480.916527][T11133] ___slab_alloc+0xd9c/0x1940 [ 480.921631][T11133] __slab_alloc.constprop.0+0x56/0xb0 [ 480.936047][T11133] kmem_cache_alloc_lru_noprof+0xf4/0x3b0 [ 480.941882][T11133] alloc_inode+0x61/0x240 [ 480.993204][T11133] new_inode+0x22/0x1c0 [ 481.003775][T11133] __debugfs_create_file+0x11c/0x6b0 [ 481.026094][T11133] debugfs_create_file_unsafe+0x3c/0x50 [ 481.031847][T11133] debugfs_create_u32+0x70/0xa0 [ 481.046794][T11133] nsim_ethtool_init+0x3a5/0x5c0 [ 481.051851][T11133] nsim_create+0x247/0xb00 [ 481.216323][T11133] __nsim_dev_port_add+0x42b/0x7d0 [ 481.229777][T11133] page last free pid 1 tgid 1 stack trace: [ 481.239867][T11133] __free_frozen_pages+0x69d/0xf90 [ 481.245093][T11133] free_contig_range+0x135/0x3f0 [ 481.266323][T11133] destroy_args+0x66f/0x830 [ 481.286583][T11133] debug_vm_pgtable+0x130e/0x2d50 [ 481.310569][T11133] do_one_initcall+0x120/0x6e0 [ 481.330338][T11133] kernel_init_freeable+0x5c2/0x900 [ 481.335703][T11133] kernel_init+0x1c/0x2b0 [ 481.376119][T11133] ret_from_fork+0x45/0x80 [ 481.389863][T11133] ret_from_fork_asm+0x1a/0x30 [ 481.483393][T11150] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1432'. [ 481.861176][T11166] FAULT_INJECTION: forcing a failure. [ 481.861176][T11166] name failslab, interval 1, probability 0, space 0, times 0 [ 481.888812][T11166] CPU: 0 UID: 0 PID: 11166 Comm: syz.1.1435 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 481.888863][T11166] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 481.888882][T11166] Call Trace: [ 481.888892][T11166] [ 481.888904][T11166] dump_stack_lvl+0x16c/0x1f0 [ 481.888959][T11166] should_fail_ex+0x512/0x640 [ 481.889000][T11166] ? kmem_cache_alloc_noprof+0x5a/0x3b0 [ 481.889046][T11166] should_failslab+0xc2/0x120 [ 481.889090][T11166] kmem_cache_alloc_noprof+0x6d/0x3b0 [ 481.889129][T11166] ? __proc_create+0xc3/0x8c0 [ 481.889175][T11166] ? __proc_create+0x2ce/0x8c0 [ 481.889228][T11166] __proc_create+0x2ce/0x8c0 [ 481.889274][T11166] ? __pfx___proc_create+0x10/0x10 [ 481.889331][T11166] ? _raw_write_unlock+0x28/0x50 [ 481.889383][T11166] proc_create_reg+0x7d/0x180 [ 481.889438][T11166] proc_create_net_data+0x8e/0x1b0 [ 481.889490][T11166] ? __pfx_proc_create_net_data+0x10/0x10 [ 481.889541][T11166] ? __pfx_uevent_net_rcv+0x10/0x10 [ 481.889584][T11166] ? __pfx_dev_proc_net_init+0x10/0x10 [ 481.889626][T11166] dev_proc_net_init+0x5a/0x220 [ 481.889667][T11166] ops_init+0x1df/0x5f0 [ 481.889733][T11166] setup_net+0x21e/0x850 [ 481.889790][T11166] ? __pfx_setup_net+0x10/0x10 [ 481.889839][T11166] ? lockdep_init_map_type+0x5c/0x280 [ 481.889873][T11166] ? __pfx_down_read_killable+0x10/0x10 [ 481.889912][T11166] ? debug_mutex_init+0x37/0x70 [ 481.889959][T11166] copy_net_ns+0x2a6/0x5f0 [ 481.889997][T11166] create_new_namespaces+0x3ea/0xad0 [ 481.890057][T11166] unshare_nsproxy_namespaces+0xc0/0x1f0 [ 481.890107][T11166] ksys_unshare+0x45b/0xa40 [ 481.890138][T11166] ? __pfx_ksys_unshare+0x10/0x10 [ 481.890166][T11166] ? xfd_validate_state+0x5d/0x180 [ 481.890206][T11166] ? rcu_is_watching+0x12/0xc0 [ 481.890260][T11166] __x64_sys_unshare+0x31/0x40 [ 481.890289][T11166] do_syscall_64+0xcd/0x260 [ 481.890345][T11166] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 481.890378][T11166] RIP: 0033:0x7fb6b3d8d169 [ 481.890404][T11166] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 481.890438][T11166] RSP: 002b:00007fb6b4b46038 EFLAGS: 00000246 ORIG_RAX: 0000000000000110 [ 481.890469][T11166] RAX: ffffffffffffffda RBX: 00007fb6b3fa5fa0 RCX: 00007fb6b3d8d169 [ 481.890491][T11166] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000040000080 [ 481.890511][T11166] RBP: 00007fb6b3e0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 481.890532][T11166] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 481.890552][T11166] R13: 0000000000000000 R14: 00007fb6b3fa5fa0 R15: 00007ffd1f7a1268 [ 481.890594][T11166] [ 483.271302][T11184] netlink: 36 bytes leftover after parsing attributes in process `syz.1.1439'. [ 483.583316][T11191] page: refcount:2 mapcount:1 mapping:0000000000000000 index:0x381 pfn:0x78416 [ 483.619422][T11191] memcg:ffff888028c18000 [ 483.630317][T11191] anon flags: 0xfff00000020808(uptodate|owner_2|swapbacked|node=0|zone=1|lastcpupid=0x7ff) [ 483.657870][T11191] raw: 00fff00000020808 ffffea0001e18948 ffffea0001e21dc8 ffff88803354e661 [ 483.684640][T11191] raw: 0000000000000381 0000000000000000 0000000200000000 ffff888028c18000 [ 483.726068][T11191] page dumped because: unmovable page [ 483.732403][T11191] page_owner tracks the page as freed [ 483.768885][T11191] page last allocated via order 0, migratetype Movable, gfp_mask 0x140dca(GFP_HIGHUSER_MOVABLE|__GFP_ZERO|__GFP_COMP), pid 11182, tgid 11180 (syz.2.1436), ts 483253986571, free_ts 483606791607 [ 483.835490][T11191] post_alloc_hook+0x181/0x1b0 [ 483.859820][T11191] get_page_from_freelist+0x10fc/0x35c0 [ 483.876536][T11191] __alloc_frozen_pages_noprof+0x223/0x2370 [ 483.903534][T11191] alloc_pages_mpol+0x1fb/0x550 [ 483.909205][T11191] folio_alloc_mpol_noprof+0x36/0x2f0 [ 483.934167][T11191] vma_alloc_folio_noprof+0xed/0x1e0 [ 483.942834][T11191] do_pte_missing+0x2049/0x3ea0 [ 483.966200][T11191] __handle_mm_fault+0x1043/0x2a50 [ 483.972657][T11191] handle_mm_fault+0x404/0xae0 [ 484.000554][T11191] __get_user_pages+0x771/0x36f0 [ 484.005618][T11191] populate_vma_page_range+0x278/0x3a0 [ 484.059331][T11191] __mm_populate+0x1d8/0x380 [ 484.074308][T11191] vm_mmap_pgoff+0x362/0x450 [ 484.093472][T11191] ksys_mmap_pgoff+0x7d/0x5c0 [ 484.112809][T11191] __x64_sys_mmap+0x125/0x190 [ 484.128120][T11191] do_syscall_64+0xcd/0x260 [ 484.132879][T11191] page last free pid 11185 tgid 11180 stack trace: [ 484.206390][T11191] free_unref_folios+0x999/0x15e0 [ 484.226207][T11191] shrink_folio_list+0x327d/0x40a0 [ 484.246162][T11191] reclaim_folio_list+0xd7/0x5d0 [ 484.251270][T11191] reclaim_pages+0x47b/0x650 [ 484.321053][T11191] madvise_cold_or_pageout_pte_range+0x13b2/0x2100 [ 484.356366][T11191] walk_pgd_range+0xba7/0x1a90 [ 484.376142][T11191] __walk_page_range+0x163/0x830 [ 484.381307][T11191] walk_page_range_mm+0x558/0x940 [ 484.439438][T11191] walk_page_range+0x63/0x90 [ 484.469433][T11191] madvise_pageout+0x31c/0x810 [ 484.498957][T11191] madvise_vma_behavior+0x44f/0x1de0 [ 484.504669][T11191] madvise_walk_vmas+0x1ce/0x2c0 [ 484.546093][T11191] do_madvise+0x364/0x7c0 [ 484.550544][T11191] __x64_sys_madvise+0xa9/0x110 [ 484.599150][T11191] do_syscall_64+0xcd/0x260 [ 484.603787][T11191] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 485.286427][T11204] netlink: 68 bytes leftover after parsing attributes in process `syz.3.1445'. [ 486.074935][T11179] Process accounting resumed [ 486.363263][T11217] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 488.167760][T11232] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 488.666462][T11234] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1453'. [ 489.314199][T11243] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1457'. [ 489.917704][T11238] netlink: 68 bytes leftover after parsing attributes in process `syz.1.1455'. [ 490.103723][T11249] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1459'. [ 493.396418][T11282] vxcan1: tx drop: invalid sa for name 0x00000000000000fd [ 493.498878][T11280] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1468'. [ 493.656388][T11285] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 495.616273][T11320] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1481'. [ 497.374665][T11346] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x79000 [ 497.422557][T11346] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 497.453933][T11346] flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff) [ 497.476353][T11346] page_type: f5(slab) [ 497.484117][T11346] raw: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 497.494596][T11346] raw: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 497.521676][T11346] head: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 497.544358][T11346] head: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 497.557784][T11346] head: 00fff00000000002 ffffea0001e40001 ffffffffffffffff 0000000000000000 [ 497.579708][T11346] head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000 [ 497.607180][T11346] page dumped because: unmovable page [ 497.614372][T11346] page_owner tracks the page as allocated [ 497.634285][T11346] page last allocated via order 2, migratetype Reclaimable, gfp_mask 0xd20d0(__GFP_RECLAIMABLE|__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5838, tgid 5838 (syz-executor), ts 97491221650, free_ts 35045899222 [ 497.697158][T11346] post_alloc_hook+0x181/0x1b0 [ 497.702075][T11346] get_page_from_freelist+0x10fc/0x35c0 [ 497.728268][T11346] __alloc_frozen_pages_noprof+0x223/0x2370 [ 497.734308][T11346] alloc_pages_mpol+0x1fb/0x550 [ 497.769051][T11346] new_slab+0x23c/0x330 [ 497.773311][T11346] ___slab_alloc+0xd9c/0x1940 [ 497.789933][T11346] __slab_alloc.constprop.0+0x56/0xb0 [ 497.795416][T11346] kmem_cache_alloc_lru_noprof+0xf4/0x3b0 [ 497.816109][T11346] alloc_inode+0x61/0x240 [ 497.820567][T11346] new_inode+0x22/0x1c0 [ 497.824826][T11346] __debugfs_create_file+0x11c/0x6b0 [ 497.866052][T11346] debugfs_create_file_unsafe+0x3c/0x50 [ 497.871728][T11346] debugfs_create_u32+0x70/0xa0 [ 497.880100][T11346] nsim_ethtool_init+0x3a5/0x5c0 [ 497.885190][T11346] nsim_create+0x247/0xb00 [ 497.901499][T11346] __nsim_dev_port_add+0x42b/0x7d0 [ 497.919705][T11346] page last free pid 1 tgid 1 stack trace: [ 497.925600][T11346] __free_frozen_pages+0x69d/0xf90 [ 497.950648][T11346] free_contig_range+0x135/0x3f0 [ 497.955870][T11346] destroy_args+0x66f/0x830 [ 497.986026][T11346] debug_vm_pgtable+0x130e/0x2d50 [ 497.991264][T11346] do_one_initcall+0x120/0x6e0 [ 498.006065][T11346] kernel_init_freeable+0x5c2/0x900 [ 498.011399][T11346] kernel_init+0x1c/0x2b0 [ 498.015827][T11346] ret_from_fork+0x45/0x80 [ 498.054147][T11346] ret_from_fork_asm+0x1a/0x30 [ 499.159257][T11366] netlink: 4 bytes leftover after parsing attributes in process `syz.2.1494'. [ 499.461871][T11369] netlink: 28 bytes leftover after parsing attributes in process `syz.1.1495'. [ 500.033695][T11381] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x79000 [ 500.045284][T11381] head: order:2 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 500.056977][T11381] flags: 0xfff00000000040(head|node=0|zone=1|lastcpupid=0x7ff) [ 500.064917][T11381] page_type: f5(slab) [ 500.071955][T11381] raw: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 500.081251][T11381] raw: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 500.092611][T11381] head: 00fff00000000040 ffff88801eade640 dead000000000122 0000000000000000 [ 500.137186][T11381] head: 0000000000000000 00000000000c000c 00000000f5000000 0000000000000000 [ 500.148370][T11381] head: 00fff00000000002 ffffea0001e40001 ffffffffffffffff 0000000000000000 [ 500.158527][T11381] head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000 [ 500.170217][T11381] page dumped because: unmovable page [ 500.193550][T11381] page_owner tracks the page as allocated [ 500.199865][T11381] page last allocated via order 2, migratetype Reclaimable, gfp_mask 0xd20d0(__GFP_RECLAIMABLE|__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5838, tgid 5838 (syz-executor), ts 97491221650, free_ts 35045899222 [ 500.278546][T11381] post_alloc_hook+0x181/0x1b0 [ 500.304019][T11381] get_page_from_freelist+0x10fc/0x35c0 [ 500.320334][T11383] netlink: 28 bytes leftover after parsing attributes in process `syz.1.1502'. [ 500.333047][T11381] __alloc_frozen_pages_noprof+0x223/0x2370 [ 500.348136][T11381] alloc_pages_mpol+0x1fb/0x550 [ 500.361825][T11381] new_slab+0x23c/0x330 [ 500.385013][T11381] ___slab_alloc+0xd9c/0x1940 [ 500.405327][T11381] __slab_alloc.constprop.0+0x56/0xb0 [ 500.428600][T11381] kmem_cache_alloc_lru_noprof+0xf4/0x3b0 [ 500.459743][T11381] alloc_inode+0x61/0x240 [ 500.487333][T11381] new_inode+0x22/0x1c0 [ 500.496673][T11381] __debugfs_create_file+0x11c/0x6b0 [ 500.515093][T11381] debugfs_create_file_unsafe+0x3c/0x50 [ 500.536749][T11381] debugfs_create_u32+0x70/0xa0 [ 500.566206][T11381] nsim_ethtool_init+0x3a5/0x5c0 [ 500.583940][T11381] nsim_create+0x247/0xb00 [ 500.602380][T11381] __nsim_dev_port_add+0x42b/0x7d0 [ 500.630245][T11381] page last free pid 1 tgid 1 stack trace: [ 500.653839][T11381] __free_frozen_pages+0x69d/0xf90 [ 500.675748][T11381] free_contig_range+0x135/0x3f0 [ 500.696284][T11381] destroy_args+0x66f/0x830 [ 500.719485][T11381] debug_vm_pgtable+0x130e/0x2d50 [ 500.756221][T11381] do_one_initcall+0x120/0x6e0 [ 500.776634][T11381] kernel_init_freeable+0x5c2/0x900 [ 500.796190][T11381] kernel_init+0x1c/0x2b0 [ 500.811517][T11381] ret_from_fork+0x45/0x80 [ 500.816319][T11381] ret_from_fork_asm+0x1a/0x30 [ 501.130383][T11397] netlink: 36 bytes leftover after parsing attributes in process `syz.2.1508'. [ 501.956190][T11407] netlink: 28 bytes leftover after parsing attributes in process `syz.2.1510'. [ 502.300859][T11413] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1511'. [ 503.180099][T11425] page: refcount:3 mapcount:1 mapping:ffff88806244ec20 index:0x4a1 pfn:0x7887e [ 503.199356][T11425] memcg:ffff88802a18c000 [ 503.203964][T11425] aops:shmem_aops ino:31e dentry name(?):"dev/zero" [ 503.226645][T11425] flags: 0xfff00000020018(uptodate|dirty|swapbacked|node=0|zone=1|lastcpupid=0x7ff) [ 503.240242][T11425] raw: 00fff00000020018 ffffea0001dd56c8 ffffea000103b808 ffff88806244ec20 [ 503.265930][T11425] raw: 00000000000004a1 0000000000000000 0000000300000000 ffff88802a18c000 [ 503.288545][T11425] page dumped because: unmovable page [ 503.294393][T11425] page_owner tracks the page as allocated [ 503.300954][T11425] page last allocated via order 0, migratetype Movable, gfp_mask 0x140cca(GFP_HIGHUSER_MOVABLE|__GFP_COMP), pid 11398, tgid 11396 (syz.3.1507), ts 502166350844, free_ts 502120281981 [ 503.340611][T11425] post_alloc_hook+0x181/0x1b0 [ 503.346770][T11425] get_page_from_freelist+0x10fc/0x35c0 [ 503.359812][T11425] __alloc_frozen_pages_noprof+0x223/0x2370 [ 503.365940][T11425] alloc_pages_mpol+0x1fb/0x550 [ 503.379331][T11425] folio_alloc_mpol_noprof+0x36/0x2f0 [ 503.385654][T11425] shmem_alloc_folio+0x135/0x160 [ 503.395885][T11425] shmem_alloc_and_add_folio+0x499/0xc20 [ 503.419938][T11425] shmem_get_folio_gfp+0x687/0x1530 [ 503.425458][T11425] shmem_fault+0x204/0xb10 [ 503.433239][T11425] __do_fault+0x10a/0x490 [ 503.441668][T11425] do_pte_missing+0x1a6/0x3ea0 [ 503.450786][T11425] __handle_mm_fault+0x1043/0x2a50 [ 503.459931][T11425] handle_mm_fault+0x404/0xae0 [ 503.469683][T11425] __get_user_pages+0x771/0x36f0 [ 503.485506][T11425] faultin_page_range+0x249/0x980 [ 503.495661][T11425] do_madvise+0x551/0x7c0 [ 503.503068][T11425] page last free pid 11399 tgid 11393 stack trace: [ 503.520551][T11425] free_unref_folios+0x999/0x15e0 [ 503.530914][T11425] folios_put_refs+0x5af/0x800 [ 503.540805][T11425] shmem_undo_range+0x58f/0x1150 [ 503.551027][T11425] shmem_evict_inode+0x3a1/0xbe0 [ 503.560595][T11425] evict+0x3e3/0x920 [ 503.564923][T11425] iput+0x521/0x880 [ 503.586273][T11425] dentry_unlink_inode+0x29c/0x480 [ 503.604318][T11425] __dentry_kill+0x1d0/0x600 [ 503.612969][T11425] dput.part.0+0x4b1/0x9b0 [ 503.618310][T11425] dput+0x1f/0x30 [ 503.626479][T11425] __fput+0x51c/0xb70 [ 503.632612][T11425] task_work_run+0x14d/0x240 [ 503.647018][T11425] do_exit+0xafe/0x2d90 [ 503.656303][T11425] do_group_exit+0xd3/0x2a0 [ 503.676150][T11425] get_signal+0x2673/0x26d0 [ 503.686364][T11425] arch_do_signal_or_restart+0x8f/0x7d0 [ 504.053560][T11434] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1518'. [ 504.953709][T11447] netlink: 28 bytes leftover after parsing attributes in process `syz.3.1520'. [ 506.772386][ T1298] ieee802154 phy0 wpan0: encryption failed: -22 [ 506.778896][ T1298] ieee802154 phy1 wpan1: encryption failed: -22 [ 507.380535][T11485] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1531'. [ 509.236497][T11491] FAULT_INJECTION: forcing a failure. [ 509.236497][T11491] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 509.305959][T11491] CPU: 0 UID: 0 PID: 11491 Comm: syz.3.1532 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 509.306017][T11491] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 509.306039][T11491] Call Trace: [ 509.306050][T11491] [ 509.306063][T11491] dump_stack_lvl+0x16c/0x1f0 [ 509.306121][T11491] should_fail_ex+0x512/0x640 [ 509.306169][T11491] should_fail_alloc_page+0xe7/0x130 [ 509.306220][T11491] prepare_alloc_pages+0x3c2/0x610 [ 509.306252][T11491] ? rcu_is_watching+0x12/0xc0 [ 509.306298][T11491] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 509.306352][T11491] ? stack_trace_save+0x8e/0xc0 [ 509.306397][T11491] ? __pfx_stack_trace_save+0x10/0x10 [ 509.306442][T11491] ? stack_depot_save_flags+0x28/0xa50 [ 509.306491][T11491] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 509.306538][T11491] ? kasan_save_stack+0x42/0x60 [ 509.306575][T11491] ? kasan_save_stack+0x33/0x60 [ 509.306610][T11491] ? kasan_save_track+0x14/0x30 [ 509.306647][T11491] ? __kasan_kmalloc+0xaa/0xb0 [ 509.306682][T11491] ? mon_bin_open+0x1a8/0x4a0 [ 509.306729][T11491] ? chrdev_open+0x231/0x6a0 [ 509.306772][T11491] ? __x64_sys_openat+0x174/0x210 [ 509.306818][T11491] ? do_syscall_64+0xcd/0x260 [ 509.306868][T11491] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 509.306911][T11491] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 509.306950][T11491] ? policy_nodemask+0xea/0x4e0 [ 509.307008][T11491] alloc_pages_mpol+0x1fb/0x550 [ 509.307063][T11491] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 509.307124][T11491] alloc_pages_noprof+0x131/0x390 [ 509.307171][T11491] get_zeroed_page_noprof+0x14/0x50 [ 509.307224][T11491] mon_alloc_buff+0xbc/0x180 [ 509.307271][T11491] ? kasan_save_track+0x14/0x30 [ 509.307314][T11491] mon_bin_open+0x207/0x4a0 [ 509.307364][T11491] ? __pfx_mon_bin_open+0x10/0x10 [ 509.307413][T11491] chrdev_open+0x231/0x6a0 [ 509.307452][T11491] ? __pfx_apparmor_file_open+0x10/0x10 [ 509.307500][T11491] ? __pfx_chrdev_open+0x10/0x10 [ 509.307545][T11491] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 509.307593][T11491] do_dentry_open+0x741/0x1c10 [ 509.307631][T11491] ? __pfx_chrdev_open+0x10/0x10 [ 509.307681][T11491] vfs_open+0x82/0x3f0 [ 509.307732][T11491] path_openat+0x1e5e/0x2d40 [ 509.307788][T11491] ? __pfx_path_openat+0x10/0x10 [ 509.307839][T11491] do_filp_open+0x20b/0x470 [ 509.307879][T11491] ? __pfx_do_filp_open+0x10/0x10 [ 509.307950][T11491] ? alloc_fd+0x471/0x7d0 [ 509.308008][T11491] do_sys_openat2+0x11b/0x1d0 [ 509.308057][T11491] ? __pfx_do_sys_openat2+0x10/0x10 [ 509.308123][T11491] __x64_sys_openat+0x174/0x210 [ 509.308172][T11491] ? __pfx___x64_sys_openat+0x10/0x10 [ 509.308221][T11491] ? rcu_is_watching+0x12/0xc0 [ 509.308276][T11491] do_syscall_64+0xcd/0x260 [ 509.308332][T11491] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 509.308365][T11491] RIP: 0033:0x7fe21cd8d169 [ 509.308391][T11491] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 509.308425][T11491] RSP: 002b:00007fe21dcc2038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 509.308457][T11491] RAX: ffffffffffffffda RBX: 00007fe21cfa5fa0 RCX: 00007fe21cd8d169 [ 509.308479][T11491] RDX: 0000000000080000 RSI: 0000200000000080 RDI: ffffffffffffff9c [ 509.308500][T11491] RBP: 00007fe21ce0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 509.308520][T11491] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 509.308539][T11491] R13: 0000000000000000 R14: 00007fe21cfa5fa0 R15: 00007ffd12fa0298 [ 509.308582][T11491] [ 511.642468][T11535] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1543'. [ 513.404741][T11566] netlink: 8 bytes leftover after parsing attributes in process `syz.1.1551'. [ 513.515557][ T48] smpboot: CPU 0 is now offline [ 514.307396][T11564] FAULT_INJECTION: forcing a failure. [ 514.307396][T11564] name failslab, interval 1, probability 0, space 0, times 0 [ 514.682011][T11564] CPU: 1 UID: 0 PID: 11564 Comm: syz.0.1546 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 514.682050][T11564] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 514.682066][T11564] Call Trace: [ 514.682075][T11564] [ 514.682085][T11564] dump_stack_lvl+0x16c/0x1f0 [ 514.682133][T11564] should_fail_ex+0x512/0x640 [ 514.682165][T11564] ? __kmalloc_cache_noprof+0x57/0x3e0 [ 514.682195][T11564] ? __pfx_cec_config_thread_func+0x10/0x10 [ 514.682219][T11564] should_failslab+0xc2/0x120 [ 514.682252][T11564] __kmalloc_cache_noprof+0x6a/0x3e0 [ 514.682279][T11564] ? lockdep_init_map_type+0x5c/0x280 [ 514.682303][T11564] ? __kthread_create_on_node+0xce/0x3f0 [ 514.682343][T11564] ? __init_swait_queue_head+0xca/0x150 [ 514.682375][T11564] ? __pfx_cec_config_thread_func+0x10/0x10 [ 514.682397][T11564] __kthread_create_on_node+0xce/0x3f0 [ 514.682438][T11564] ? __pfx___kthread_create_on_node+0x10/0x10 [ 514.682485][T11564] ? cec_adap_enable+0x77c/0xc30 [ 514.682512][T11564] ? __pfx_cec_config_thread_func+0x10/0x10 [ 514.682535][T11564] kthread_create_on_node+0xc7/0x100 [ 514.682557][T11564] ? __pfx_kthread_create_on_node+0x10/0x10 [ 514.682595][T11564] ? __pfx___mutex_unlock_slowpath+0x10/0x10 [ 514.682648][T11564] ? lockdep_init_map_type+0x5c/0x280 [ 514.682692][T11564] ? lockdep_init_map_type+0x5c/0x280 [ 514.682721][T11564] cec_claim_log_addrs+0x13e/0x2e0 [ 514.682765][T11564] __cec_s_log_addrs+0xdc9/0x1670 [ 514.682797][T11564] cec_ioctl+0x4b8/0x2970 [ 514.682825][T11564] ? __pfx_cec_ioctl+0x10/0x10 [ 514.682851][T11564] ? __pfx_tomoyo_path_number_perm+0x10/0x10 [ 514.682883][T11564] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 514.682914][T11564] ? do_vfs_ioctl+0x512/0x1990 [ 514.682953][T11564] ? __pfx_do_vfs_ioctl+0x10/0x10 [ 514.683017][T11564] ? find_held_lock+0x2b/0x80 [ 514.683050][T11564] ? hook_file_ioctl_common+0x145/0x410 [ 514.683093][T11564] ? __pfx_cec_ioctl+0x10/0x10 [ 514.683120][T11564] __x64_sys_ioctl+0x190/0x200 [ 514.683161][T11564] do_syscall_64+0xcd/0x260 [ 514.683202][T11564] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 514.683228][T11564] RIP: 0033:0x7f7cadd8d169 [ 514.683249][T11564] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 514.683273][T11564] RSP: 002b:00007f7cab7f4038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 514.683297][T11564] RAX: ffffffffffffffda RBX: 00007f7cadfa6240 RCX: 00007f7cadd8d169 [ 514.683315][T11564] RDX: 00002000000000c0 RSI: 00000000c05c6104 RDI: 0000000000000005 [ 514.683333][T11564] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 514.683349][T11564] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 514.683365][T11564] R13: 0000000000000000 R14: 00007f7cadfa6240 R15: 00007ffda25118b8 [ 514.683395][T11564] [ 514.970035][ C1] vkms_vblank_simulate: vblank timer overrun [ 515.424286][T11588] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 515.435174][T11582] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1557'. [ 515.554499][T11590] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1558'. [ 516.278439][T11586] Process accounting paused [ 517.613400][T11607] openvswitch: netlink: nsh attribute has unmatched MD type 0. [ 518.787465][T11622] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1568'. [ 521.410397][T11662] netlink: 28 bytes leftover after parsing attributes in process `syz.2.1580'. [ 522.576330][T11675] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1581'. [ 522.955121][T11678] openvswitch: netlink: ct_state flags aa1414ac unsupported [ 524.152076][T11680] netlink: 28 bytes leftover after parsing attributes in process `syz.0.1585'. [ 527.945815][T11716] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1594'. [ 532.124854][T11753] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1604'. [ 532.753603][T11761] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 533.028301][T11758] netlink: 28 bytes leftover after parsing attributes in process `syz.2.1606'. [ 534.086494][T11780] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 534.398704][T11777] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1611'. [ 536.568489][T11806] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 539.306319][T11825] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 540.002981][T11831] netlink: 20 bytes leftover after parsing attributes in process `syz.1.1625'. [ 540.599319][T11843] netlink: 'syz.3.1628': attribute type 4 has an invalid length. [ 542.716724][T11860] netlink: 20 bytes leftover after parsing attributes in process `syz.3.1632'. [ 544.386806][T11877] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1635'. [ 546.440365][T11899] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 546.826766][T11800] Process accounting resumed [ 548.674689][T11918] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1647'. [ 550.136429][T11934] netlink: 68 bytes leftover after parsing attributes in process `syz.0.1650'. [ 550.966763][T11935] netlink: 68 bytes leftover after parsing attributes in process `syz.3.1651'. [ 551.549034][T11938] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1652'. syzkaller syzkaller login: [ 555.702782][T11970] netlink: 4 bytes leftover after parsing attributes in process `syz.1.1661'. [ 556.554988][T11981] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1665'. [ 558.123996][T11996] netlink: 36 bytes leftover after parsing attributes in process `syz.3.1670'. [ 558.148062][T11995] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 558.700024][T12001] netlink: 20 bytes leftover after parsing attributes in process `syz.0.1669'. [ 559.434025][T12010] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1675'. [ 560.445358][T12013] Invalid ELF header magic: != ELF [ 562.382573][T12052] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 562.920225][T12057] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 564.599399][T12061] netlink: 28 bytes leftover after parsing attributes in process `syz.2.1688'. [ 568.212205][ T1298] ieee802154 phy0 wpan0: encryption failed: -22 [ 568.220985][ T1298] ieee802154 phy1 wpan1: encryption failed: -22 [ 570.349738][T12109] netlink: 342 bytes leftover after parsing attributes in process `syz.3.1697'. [ 571.577016][T12125] netlink: 28 bytes leftover after parsing attributes in process `syz.0.1701'. [ 578.270383][T12184] zswap: compressor not available [ 578.317244][T12187] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1716'. [ 578.652502][T12184] Process accounting paused [ 580.267155][T12213] netlink: 20 bytes leftover after parsing attributes in process `syz.2.1723'. [ 580.856522][T12222] openvswitch: netlink: Tunnel attr 0 has unexpected len 0 expected 8 [ 580.985137][ T5898] [ 580.987631][ T5898] ====================================================== [ 580.994755][ T5898] WARNING: possible circular locking dependency detected [ 581.001824][ T5898] 6.14.0-syzkaller-11125-g609706855d90 #0 Not tainted [ 581.008698][ T5898] ------------------------------------------------------ [ 581.015847][ T5898] kworker/1:4/5898 is trying to acquire lock: [ 581.021948][ T5898] ffffffff90123d68 (rtnl_mutex){+.+.}-{4:4}, at: smc_vlan_by_tcpsk+0x251/0x620 [ 581.031088][ T5898] [ 581.031088][ T5898] but task is already holding lock: [ 581.038466][ T5898] ffff888029ba0258 (sk_lock-AF_INET){+.+.}-{0:0}, at: smc_connect_work+0x53a/0xae0 [ 581.047838][ T5898] [ 581.047838][ T5898] which lock already depends on the new lock. [ 581.047838][ T5898] [ 581.058440][ T5898] [ 581.058440][ T5898] the existing dependency chain (in reverse order) is: [ 581.067478][ T5898] [ 581.067478][ T5898] -> #1 (sk_lock-AF_INET){+.+.}-{0:0}: [ 581.075156][ T5898] lock_sock_nested+0x41/0xf0 [ 581.080380][ T5898] sockopt_lock_sock+0x54/0x70 [ 581.085698][ T5898] do_ip_setsockopt+0xfe/0x3240 [ 581.091115][ T5898] ip_setsockopt+0x59/0xf0 [ 581.096155][ T5898] raw_setsockopt+0xb7/0x2a0 [ 581.101284][ T5898] do_sock_setsockopt+0x221/0x470 [ 581.106885][ T5898] __sys_setsockopt+0x1a0/0x230 [ 581.112320][ T5898] __x64_sys_setsockopt+0xbd/0x160 [ 581.117981][ T5898] do_syscall_64+0xcd/0x260 [ 581.123032][ T5898] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 581.129472][ T5898] [ 581.129472][ T5898] -> #0 (rtnl_mutex){+.+.}-{4:4}: [ 581.136720][ T5898] __lock_acquire+0x1173/0x1ba0 [ 581.142111][ T5898] lock_acquire+0x179/0x350 [ 581.147144][ T5898] __mutex_lock+0x199/0xb90 [ 581.152218][ T5898] smc_vlan_by_tcpsk+0x251/0x620 [ 581.157698][ T5898] __smc_connect+0x44b/0x4880 [ 581.162913][ T5898] smc_connect_work+0x54c/0xae0 [ 581.168301][ T5898] process_one_work+0x9cc/0x1b70 [ 581.173774][ T5898] worker_thread+0x6c8/0xf10 [ 581.178904][ T5898] kthread+0x3c2/0x780 [ 581.183505][ T5898] ret_from_fork+0x45/0x80 [ 581.188451][ T5898] ret_from_fork_asm+0x1a/0x30 [ 581.193759][ T5898] [ 581.193759][ T5898] other info that might help us debug this: [ 581.193759][ T5898] [ 581.204085][ T5898] Possible unsafe locking scenario: [ 581.204085][ T5898] [ 581.211551][ T5898] CPU0 CPU1 [ 581.217014][ T5898] ---- ---- [ 581.222385][ T5898] lock(sk_lock-AF_INET); [ 581.226912][ T5898] lock(rtnl_mutex); [ 581.233436][ T5898] lock(sk_lock-AF_INET); [ 581.240394][ T5898] lock(rtnl_mutex); [ 581.244385][ T5898] [ 581.244385][ T5898] *** DEADLOCK *** [ 581.244385][ T5898] [ 581.252569][ T5898] 3 locks held by kworker/1:4/5898: [ 581.257815][ T5898] #0: ffff888032296548 ((wq_completion)smc_hs_wq){+.+.}-{0:0}, at: process_one_work+0x12a2/0x1b70 [ 581.268573][ T5898] #1: ffffc900042ffd18 ((work_completion)(&smc->connect_work)){+.+.}-{0:0}, at: process_one_work+0x929/0x1b70 [ 581.280436][ T5898] #2: ffff888029ba0258 (sk_lock-AF_INET){+.+.}-{0:0}, at: smc_connect_work+0x53a/0xae0 [ 581.290241][ T5898] [ 581.290241][ T5898] stack backtrace: [ 581.296138][ T5898] CPU: 1 UID: 0 PID: 5898 Comm: kworker/1:4 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 581.296173][ T5898] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 581.296190][ T5898] Workqueue: smc_hs_wq smc_connect_work [ 581.296223][ T5898] Call Trace: [ 581.296232][ T5898] [ 581.296242][ T5898] dump_stack_lvl+0x116/0x1f0 [ 581.296277][ T5898] print_circular_bug+0x275/0x350 [ 581.296316][ T5898] check_noncircular+0x14c/0x170 [ 581.296355][ T5898] __lock_acquire+0x1173/0x1ba0 [ 581.296380][ T5898] lock_acquire+0x179/0x350 [ 581.296400][ T5898] ? smc_vlan_by_tcpsk+0x251/0x620 [ 581.296432][ T5898] ? __pfx___might_resched+0x10/0x10 [ 581.296463][ T5898] ? kasan_save_stack+0x42/0x60 [ 581.296490][ T5898] ? kasan_save_stack+0x33/0x60 [ 581.296514][ T5898] ? kasan_save_track+0x14/0x30 [ 581.296541][ T5898] __mutex_lock+0x199/0xb90 [ 581.296576][ T5898] ? smc_vlan_by_tcpsk+0x251/0x620 [ 581.296607][ T5898] ? smc_vlan_by_tcpsk+0x251/0x620 [ 581.296703][ T5898] ? __pfx___mutex_lock+0x10/0x10 [ 581.296741][ T5898] ? find_held_lock+0x2b/0x80 [ 581.296773][ T5898] ? smc_vlan_by_tcpsk+0x251/0x620 [ 581.296803][ T5898] ? rtnl_lock+0x9/0x20 [ 581.296826][ T5898] smc_vlan_by_tcpsk+0x251/0x620 [ 581.296857][ T5898] ? __pfx_smc_vlan_by_tcpsk+0x10/0x10 [ 581.296900][ T5898] __smc_connect+0x44b/0x4880 [ 581.296933][ T5898] ? __pfx___smc_connect+0x10/0x10 [ 581.296961][ T5898] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 581.296991][ T5898] ? __local_bh_enable_ip+0xa4/0x120 [ 581.297024][ T5898] smc_connect_work+0x54c/0xae0 [ 581.297052][ T5898] ? __pfx_smc_connect_work+0x10/0x10 [ 581.297082][ T5898] ? rcu_is_watching+0x12/0xc0 [ 581.297116][ T5898] process_one_work+0x9cc/0x1b70 [ 581.297149][ T5898] ? __pfx_process_one_work+0x10/0x10 [ 581.297179][ T5898] ? assign_work+0x1a0/0x250 [ 581.297203][ T5898] worker_thread+0x6c8/0xf10 [ 581.297235][ T5898] ? __pfx_worker_thread+0x10/0x10 [ 581.297261][ T5898] kthread+0x3c2/0x780 [ 581.297285][ T5898] ? __pfx_kthread+0x10/0x10 [ 581.297306][ T5898] ? __pfx_kthread+0x10/0x10 [ 581.297328][ T5898] ? __pfx_kthread+0x10/0x10 [ 581.297351][ T5898] ? __pfx_kthread+0x10/0x10 [ 581.297373][ T5898] ? rcu_is_watching+0x12/0xc0 [ 581.297401][ T5898] ? __pfx_kthread+0x10/0x10 [ 581.297424][ T5898] ret_from_fork+0x45/0x80 [ 581.297448][ T5898] ? __pfx_kthread+0x10/0x10 [ 581.297472][ T5898] ret_from_fork_asm+0x1a/0x30 [ 581.297514][ T5898] [ 581.533249][ C1] vkms_vblank_simulate: vblank timer overrun [ 581.569702][T12216] FAULT_INJECTION: forcing a failure. [ 581.569702][T12216] name fail_page_alloc, interval 1, probability 0, space 0, times 0 [ 581.583332][T12216] CPU: 1 UID: 0 PID: 12216 Comm: syz.0.1720 Not tainted 6.14.0-syzkaller-11125-g609706855d90 #0 PREEMPT(full) [ 581.583365][T12216] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 [ 581.583379][T12216] Call Trace: [ 581.583386][T12216] [ 581.583394][T12216] dump_stack_lvl+0x16c/0x1f0 [ 581.583434][T12216] should_fail_ex+0x512/0x640 [ 581.583468][T12216] should_fail_alloc_page+0xe7/0x130 [ 581.583503][T12216] prepare_alloc_pages+0x3c2/0x610 [ 581.583524][T12216] ? rcu_is_watching+0x12/0xc0 [ 581.583556][T12216] __alloc_frozen_pages_noprof+0x18f/0x2370 [ 581.583589][T12216] ? stack_trace_save+0x8e/0xc0 [ 581.583620][T12216] ? __pfx_stack_trace_save+0x10/0x10 [ 581.583651][T12216] ? stack_depot_save_flags+0x28/0xa50 [ 581.583683][T12216] ? __pfx___alloc_frozen_pages_noprof+0x10/0x10 [ 581.583714][T12216] ? kasan_save_stack+0x42/0x60 [ 581.583741][T12216] ? kasan_save_stack+0x33/0x60 [ 581.583767][T12216] ? kasan_save_track+0x14/0x30 [ 581.583793][T12216] ? __kasan_kmalloc+0xaa/0xb0 [ 581.583818][T12216] ? mon_bin_open+0x1a8/0x4a0 [ 581.583862][T12216] ? chrdev_open+0x231/0x6a0 [ 581.583891][T12216] ? __x64_sys_openat+0x174/0x210 [ 581.583925][T12216] ? do_syscall_64+0xcd/0x260 [ 581.583960][T12216] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 581.583986][T12216] ? __sanitizer_cov_trace_switch+0x54/0x90 [ 581.584013][T12216] ? policy_nodemask+0xea/0x4e0 [ 581.584044][T12216] alloc_pages_mpol+0x1fb/0x550 [ 581.584076][T12216] ? __pfx_alloc_pages_mpol+0x10/0x10 [ 581.584112][T12216] alloc_pages_noprof+0x131/0x390 [ 581.584143][T12216] get_zeroed_page_noprof+0x14/0x50 [ 581.584181][T12216] mon_alloc_buff+0xbc/0x180 [ 581.584214][T12216] ? kasan_save_track+0x14/0x30 [ 581.584242][T12216] mon_bin_open+0x207/0x4a0 [ 581.584276][T12216] ? __pfx_mon_bin_open+0x10/0x10 [ 581.584309][T12216] chrdev_open+0x231/0x6a0 [ 581.584336][T12216] ? __pfx_apparmor_file_open+0x10/0x10 [ 581.584370][T12216] ? __pfx_chrdev_open+0x10/0x10 [ 581.584399][T12216] ? file_set_fsnotify_mode_from_watchers+0x163/0x640 [ 581.584428][T12216] do_dentry_open+0x741/0x1c10 [ 581.584453][T12216] ? __pfx_chrdev_open+0x10/0x10 [ 581.584484][T12216] vfs_open+0x82/0x3f0 [ 581.584516][T12216] path_openat+0x1e5e/0x2d40 [ 581.584547][T12216] ? __pfx_path_openat+0x10/0x10 [ 581.584576][T12216] do_filp_open+0x20b/0x470 [ 581.584602][T12216] ? __pfx_do_filp_open+0x10/0x10 [ 581.584638][T12216] ? alloc_fd+0x471/0x7d0 [ 581.584669][T12216] do_sys_openat2+0x11b/0x1d0 [ 581.584701][T12216] ? __pfx_do_sys_openat2+0x10/0x10 [ 581.584739][T12216] __x64_sys_openat+0x174/0x210 [ 581.584773][T12216] ? __pfx___x64_sys_openat+0x10/0x10 [ 581.584807][T12216] ? rcu_is_watching+0x12/0xc0 [ 581.584849][T12216] ? rcu_is_watching+0x12/0xc0 [ 581.584883][T12216] do_syscall_64+0xcd/0x260 [ 581.584921][T12216] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 581.584945][T12216] RIP: 0033:0x7f7cadd8d169 [ 581.584963][T12216] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 581.584985][T12216] RSP: 002b:00007f7caeb16038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 581.585007][T12216] RAX: ffffffffffffffda RBX: 00007f7cadfa6160 RCX: 00007f7cadd8d169 [ 581.585023][T12216] RDX: 0000000000080000 RSI: 0000200000000080 RDI: ffffffffffffff9c [ 581.585038][T12216] RBP: 00007f7cade0e2a0 R08: 0000000000000000 R09: 0000000000000000 [ 581.585052][T12216] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 581.585066][T12216] R13: 0000000000000000 R14: 00007f7cadfa6160 R15: 00007ffda25118b8 [ 581.585088][T12216] [ 581.939531][ C1] vkms_vblank_simulate: vblank timer overrun [ 582.523889][T12229] hsr_slave_0: hsr_addr_subst_dest: Unknown node [ 582.530583][T12229] hsr_slave_1: hsr_addr_subst_dest: Unknown node