last executing test programs: 2m10.682430281s ago: executing program 0 (id=80): close(0xffffffffffffffff) perf_event_open(&(0x7f0000000380)={0x0, 0x80, 0x0, 0x7, 0x0, 0x0, 0x0, 0x0, 0x2, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, @perf_bp={0x0, 0x1}, 0x80000, 0xca, 0x0, 0x0, 0x0, 0x720b, 0x0, 0x0, 0xe, 0x0, 0x8000008}, 0xffffffffffffffff, 0x0, 0xffffffffffffffff, 0x0) recvmsg$unix(0xffffffffffffffff, &(0x7f00000013c0)={0x0, 0x0, 0x0, 0x0, &(0x7f00000003c0)=[@rights={{0x14, 0x1, 0x1, [0xffffffffffffffff]}}], 0x18}, 0x101c0) write$cgroup_subtree(r0, &(0x7f0000000180)=ANY=[@ANYRES8, @ANYBLOB="01"], 0x9a) 2m10.33374727s ago: executing program 0 (id=84): bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000200)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb01001800000000000000240000002400000002000000000000000000000400000003000000000000001301000000000000000000000d0200"], 0xffffffffffffffff, 0x3e, 0x0, 0x2, 0x0, 0x0, @void, @value}, 0x28) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fedcb7907001175f37538e486dd637f4b22667f2f00db5b686158bbcfe8875a65969ff57b00000000000000000000000000ac1414aa"], 0xfdef) r0 = openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000140)='cgroup.stat\x00', 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(r0, 0x40082404, &(0x7f0000000300)=0xe69a) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000200)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fff, 0x80000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0x3, 0x8}, 0x8080, 0x2, 0x0, 0x0, 0x7fffffff}, 0x0, 0xafffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xa, 0xffffffffffffffff, 0x9) ioctl$TUNSETCARRIER(0xffffffffffffffff, 0x400454e2, &(0x7f0000000080)=0x1) socket$kcm(0x10, 0x5, 0x0) r2 = getpid() r3 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fee, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407ffc, 0xaea}, 0x14105, 0x2e, 0xff7ffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x2a9e6}, r2, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000700000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x0, 0x0, 0x0, 0x0, 0x1}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) ioctl$PERF_EVENT_IOC_SET_BPF(r3, 0x40042408, r4) bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000001280)={0x11, 0x3, &(0x7f0000000940)=ANY=[@ANYBLOB="1800000008000000000000000000000095"], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000007c0)={&(0x7f0000000780)='contention_end\x00', r5}, 0x10) r6 = socket$kcm(0xf, 0x3, 0x2) sendmsg$inet(r6, &(0x7f0000003780)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f00000000c0)="020a000202000000e4a17c45c8d260c9", 0x10}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xcfa4) r7 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0f00000004000000040000000300000000000000", @ANYRES32, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="000000000000000000000000000000000000000000000000000000008add802748732a5b324fe95fc1f76ebd7d6028a9fa30c70f7b2f16a835f11b826ce9ee9580c2fc8cef0dcbf866557c8d933293b211f24b7d466e2b8310b8e9f022efe438a05e08cfd5ec290e39ded6c7005fb46ecdfdbbd4cfb8f245e20df0430b4b919d8088f71adbd15755de4b3bbdb6d4ab54d2f045ae5f9e75ad4b370273894346ef3070b95d8000a03a0aed627889efd675d3447beed86d6b38ffda71db234739dadc62d4f5955b6905f5df52e71073ad42a04eae15829ba04c8729713180643798519347d30ecaa0e591c6a75160c8089c1459c33107736d7449b016993fa223394c2635349fd222311892e1d0d0cc38d1445500258d37bade50428818ea58808ee986900f222c3cec901828ce55653ab74e407ba04381c841a860c51d65"], 0x50) r8 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000240)={0x2, 0x4, 0x8, 0x1, 0x80, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000840)={0x8, 0x1c, &(0x7f0000000d40)=ANY=[@ANYBLOB="18080000c000000000000000000000001811000048b98d9afbfc34ee442e632143f3fd67d38c0b8766cde49377bef55ec0e1e979c9e6bffb9715efbde48742", @ANYRES32=r7, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000005000000bc0908000000000035090100000000009500000000070000b7020000000000007b9a00fe000000006609000000000000dbaaf0ff50000000bf8620000000000007080000f8ffffffbfa400000000000007040000f0ffffff770000000800000018220000", @ANYRES32=r8, @ANYBLOB="0000000000000000b7050000080000004608f0ff76000000bf9800000000000056080000030000008500000007000000b7000000000000009500000000000000"], &(0x7f0000000980)='GPL\x00', 0x1, 0x0, 0x0, 0x0, 0x25, '\x00', 0x0, @cgroup_skb, 0x0, 0xf00, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x4e) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fed007907001175f37538e486dd6317ce2200"], 0xcfa4) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x0, &(0x7f0000000000)='%', 0x0, 0xd01, 0x88be, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) bpf$OBJ_GET_PROG(0x7, &(0x7f00000000c0)=@generic={&(0x7f0000000080)='./file0\x00', 0x0, 0x10}, 0x18) 1m44.032661511s ago: executing program 0 (id=84): bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000200)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb01001800000000000000240000002400000002000000000000000000000400000003000000000000001301000000000000000000000d0200"], 0xffffffffffffffff, 0x3e, 0x0, 0x2, 0x0, 0x0, @void, @value}, 0x28) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fedcb7907001175f37538e486dd637f4b22667f2f00db5b686158bbcfe8875a65969ff57b00000000000000000000000000ac1414aa"], 0xfdef) r0 = openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000140)='cgroup.stat\x00', 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(r0, 0x40082404, &(0x7f0000000300)=0xe69a) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000200)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fff, 0x80000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0x3, 0x8}, 0x8080, 0x2, 0x0, 0x0, 0x7fffffff}, 0x0, 0xafffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xa, 0xffffffffffffffff, 0x9) ioctl$TUNSETCARRIER(0xffffffffffffffff, 0x400454e2, &(0x7f0000000080)=0x1) socket$kcm(0x10, 0x5, 0x0) r2 = getpid() r3 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fee, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407ffc, 0xaea}, 0x14105, 0x2e, 0xff7ffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x2a9e6}, r2, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000700000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x0, 0x0, 0x0, 0x0, 0x1}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) ioctl$PERF_EVENT_IOC_SET_BPF(r3, 0x40042408, r4) bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000001280)={0x11, 0x3, &(0x7f0000000940)=ANY=[@ANYBLOB="1800000008000000000000000000000095"], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000007c0)={&(0x7f0000000780)='contention_end\x00', r5}, 0x10) r6 = socket$kcm(0xf, 0x3, 0x2) sendmsg$inet(r6, &(0x7f0000003780)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f00000000c0)="020a000202000000e4a17c45c8d260c9", 0x10}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xcfa4) r7 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0f00000004000000040000000300000000000000", @ANYRES32, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="000000000000000000000000000000000000000000000000000000008add802748732a5b324fe95fc1f76ebd7d6028a9fa30c70f7b2f16a835f11b826ce9ee9580c2fc8cef0dcbf866557c8d933293b211f24b7d466e2b8310b8e9f022efe438a05e08cfd5ec290e39ded6c7005fb46ecdfdbbd4cfb8f245e20df0430b4b919d8088f71adbd15755de4b3bbdb6d4ab54d2f045ae5f9e75ad4b370273894346ef3070b95d8000a03a0aed627889efd675d3447beed86d6b38ffda71db234739dadc62d4f5955b6905f5df52e71073ad42a04eae15829ba04c8729713180643798519347d30ecaa0e591c6a75160c8089c1459c33107736d7449b016993fa223394c2635349fd222311892e1d0d0cc38d1445500258d37bade50428818ea58808ee986900f222c3cec901828ce55653ab74e407ba04381c841a860c51d65"], 0x50) r8 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000240)={0x2, 0x4, 0x8, 0x1, 0x80, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000840)={0x8, 0x1c, &(0x7f0000000d40)=ANY=[@ANYBLOB="18080000c000000000000000000000001811000048b98d9afbfc34ee442e632143f3fd67d38c0b8766cde49377bef55ec0e1e979c9e6bffb9715efbde48742", @ANYRES32=r7, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000005000000bc0908000000000035090100000000009500000000070000b7020000000000007b9a00fe000000006609000000000000dbaaf0ff50000000bf8620000000000007080000f8ffffffbfa400000000000007040000f0ffffff770000000800000018220000", @ANYRES32=r8, @ANYBLOB="0000000000000000b7050000080000004608f0ff76000000bf9800000000000056080000030000008500000007000000b7000000000000009500000000000000"], &(0x7f0000000980)='GPL\x00', 0x1, 0x0, 0x0, 0x0, 0x25, '\x00', 0x0, @cgroup_skb, 0x0, 0xf00, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x4e) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fed007907001175f37538e486dd6317ce2200"], 0xcfa4) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x0, &(0x7f0000000000)='%', 0x0, 0xd01, 0x88be, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) bpf$OBJ_GET_PROG(0x7, &(0x7f00000000c0)=@generic={&(0x7f0000000080)='./file0\x00', 0x0, 0x10}, 0x18) 1m12.913946452s ago: executing program 0 (id=84): bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000200)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb01001800000000000000240000002400000002000000000000000000000400000003000000000000001301000000000000000000000d0200"], 0xffffffffffffffff, 0x3e, 0x0, 0x2, 0x0, 0x0, @void, @value}, 0x28) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fedcb7907001175f37538e486dd637f4b22667f2f00db5b686158bbcfe8875a65969ff57b00000000000000000000000000ac1414aa"], 0xfdef) r0 = openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000140)='cgroup.stat\x00', 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(r0, 0x40082404, &(0x7f0000000300)=0xe69a) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000200)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fff, 0x80000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0x3, 0x8}, 0x8080, 0x2, 0x0, 0x0, 0x7fffffff}, 0x0, 0xafffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xa, 0xffffffffffffffff, 0x9) ioctl$TUNSETCARRIER(0xffffffffffffffff, 0x400454e2, &(0x7f0000000080)=0x1) socket$kcm(0x10, 0x5, 0x0) r2 = getpid() r3 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fee, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407ffc, 0xaea}, 0x14105, 0x2e, 0xff7ffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x2a9e6}, r2, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000700000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x0, 0x0, 0x0, 0x0, 0x1}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) ioctl$PERF_EVENT_IOC_SET_BPF(r3, 0x40042408, r4) bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000001280)={0x11, 0x3, &(0x7f0000000940)=ANY=[@ANYBLOB="1800000008000000000000000000000095"], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000007c0)={&(0x7f0000000780)='contention_end\x00', r5}, 0x10) r6 = socket$kcm(0xf, 0x3, 0x2) sendmsg$inet(r6, &(0x7f0000003780)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f00000000c0)="020a000202000000e4a17c45c8d260c9", 0x10}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xcfa4) r7 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0f00000004000000040000000300000000000000", @ANYRES32, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="000000000000000000000000000000000000000000000000000000008add802748732a5b324fe95fc1f76ebd7d6028a9fa30c70f7b2f16a835f11b826ce9ee9580c2fc8cef0dcbf866557c8d933293b211f24b7d466e2b8310b8e9f022efe438a05e08cfd5ec290e39ded6c7005fb46ecdfdbbd4cfb8f245e20df0430b4b919d8088f71adbd15755de4b3bbdb6d4ab54d2f045ae5f9e75ad4b370273894346ef3070b95d8000a03a0aed627889efd675d3447beed86d6b38ffda71db234739dadc62d4f5955b6905f5df52e71073ad42a04eae15829ba04c8729713180643798519347d30ecaa0e591c6a75160c8089c1459c33107736d7449b016993fa223394c2635349fd222311892e1d0d0cc38d1445500258d37bade50428818ea58808ee986900f222c3cec901828ce55653ab74e407ba04381c841a860c51d65"], 0x50) r8 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000240)={0x2, 0x4, 0x8, 0x1, 0x80, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000840)={0x8, 0x1c, &(0x7f0000000d40)=ANY=[@ANYBLOB="18080000c000000000000000000000001811000048b98d9afbfc34ee442e632143f3fd67d38c0b8766cde49377bef55ec0e1e979c9e6bffb9715efbde48742", @ANYRES32=r7, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000005000000bc0908000000000035090100000000009500000000070000b7020000000000007b9a00fe000000006609000000000000dbaaf0ff50000000bf8620000000000007080000f8ffffffbfa400000000000007040000f0ffffff770000000800000018220000", @ANYRES32=r8, @ANYBLOB="0000000000000000b7050000080000004608f0ff76000000bf9800000000000056080000030000008500000007000000b7000000000000009500000000000000"], &(0x7f0000000980)='GPL\x00', 0x1, 0x0, 0x0, 0x0, 0x25, '\x00', 0x0, @cgroup_skb, 0x0, 0xf00, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x4e) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fed007907001175f37538e486dd6317ce2200"], 0xcfa4) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x0, &(0x7f0000000000)='%', 0x0, 0xd01, 0x88be, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) bpf$OBJ_GET_PROG(0x7, &(0x7f00000000c0)=@generic={&(0x7f0000000080)='./file0\x00', 0x0, 0x10}, 0x18) 37.500865672s ago: executing program 0 (id=84): bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000200)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb01001800000000000000240000002400000002000000000000000000000400000003000000000000001301000000000000000000000d0200"], 0xffffffffffffffff, 0x3e, 0x0, 0x2, 0x0, 0x0, @void, @value}, 0x28) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fedcb7907001175f37538e486dd637f4b22667f2f00db5b686158bbcfe8875a65969ff57b00000000000000000000000000ac1414aa"], 0xfdef) r0 = openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000140)='cgroup.stat\x00', 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(r0, 0x40082404, &(0x7f0000000300)=0xe69a) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000200)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fff, 0x80000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0x3, 0x8}, 0x8080, 0x2, 0x0, 0x0, 0x7fffffff}, 0x0, 0xafffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xa, 0xffffffffffffffff, 0x9) ioctl$TUNSETCARRIER(0xffffffffffffffff, 0x400454e2, &(0x7f0000000080)=0x1) socket$kcm(0x10, 0x5, 0x0) r2 = getpid() r3 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fee, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407ffc, 0xaea}, 0x14105, 0x2e, 0xff7ffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x2a9e6}, r2, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000700000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x0, 0x0, 0x0, 0x0, 0x1}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) ioctl$PERF_EVENT_IOC_SET_BPF(r3, 0x40042408, r4) bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000001280)={0x11, 0x3, &(0x7f0000000940)=ANY=[@ANYBLOB="1800000008000000000000000000000095"], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000007c0)={&(0x7f0000000780)='contention_end\x00', r5}, 0x10) r6 = socket$kcm(0xf, 0x3, 0x2) sendmsg$inet(r6, &(0x7f0000003780)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f00000000c0)="020a000202000000e4a17c45c8d260c9", 0x10}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xcfa4) r7 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0f00000004000000040000000300000000000000", @ANYRES32, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="000000000000000000000000000000000000000000000000000000008add802748732a5b324fe95fc1f76ebd7d6028a9fa30c70f7b2f16a835f11b826ce9ee9580c2fc8cef0dcbf866557c8d933293b211f24b7d466e2b8310b8e9f022efe438a05e08cfd5ec290e39ded6c7005fb46ecdfdbbd4cfb8f245e20df0430b4b919d8088f71adbd15755de4b3bbdb6d4ab54d2f045ae5f9e75ad4b370273894346ef3070b95d8000a03a0aed627889efd675d3447beed86d6b38ffda71db234739dadc62d4f5955b6905f5df52e71073ad42a04eae15829ba04c8729713180643798519347d30ecaa0e591c6a75160c8089c1459c33107736d7449b016993fa223394c2635349fd222311892e1d0d0cc38d1445500258d37bade50428818ea58808ee986900f222c3cec901828ce55653ab74e407ba04381c841a860c51d65"], 0x50) r8 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000240)={0x2, 0x4, 0x8, 0x1, 0x80, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000840)={0x8, 0x1c, &(0x7f0000000d40)=ANY=[@ANYBLOB="18080000c000000000000000000000001811000048b98d9afbfc34ee442e632143f3fd67d38c0b8766cde49377bef55ec0e1e979c9e6bffb9715efbde48742", @ANYRES32=r7, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000005000000bc0908000000000035090100000000009500000000070000b7020000000000007b9a00fe000000006609000000000000dbaaf0ff50000000bf8620000000000007080000f8ffffffbfa400000000000007040000f0ffffff770000000800000018220000", @ANYRES32=r8, @ANYBLOB="0000000000000000b7050000080000004608f0ff76000000bf9800000000000056080000030000008500000007000000b7000000000000009500000000000000"], &(0x7f0000000980)='GPL\x00', 0x1, 0x0, 0x0, 0x0, 0x25, '\x00', 0x0, @cgroup_skb, 0x0, 0xf00, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x4e) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fed007907001175f37538e486dd6317ce2200"], 0xcfa4) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x0, &(0x7f0000000000)='%', 0x0, 0xd01, 0x88be, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) bpf$OBJ_GET_PROG(0x7, &(0x7f00000000c0)=@generic={&(0x7f0000000080)='./file0\x00', 0x0, 0x10}, 0x18) 9.67798724s ago: executing program 4 (id=536): bpf$PROG_LOAD(0x5, &(0x7f000000e000)={0x1, 0x4, &(0x7f0000000040)=@framed={{0xffffffb4, 0x5, 0x0, 0x0, 0x0, 0x79, 0x10, 0x8e}, [@ldst={0x5}]}, &(0x7f0000003ff6)='GPL\x00', 0x5, 0xfd90, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x22e, 0x10, &(0x7f0000000000), 0x1dd, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000200)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb01001800000000000000240000002400000002000000000000000000000400000003000000000000001301000000000000000000000d0200"], 0xffffffffffffffff, 0x3e, 0x0, 0x2, 0x0, 0x0, @void, @value}, 0x28) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fedcb7907001175f37538e486dd637f4b22667f2f00db5b686158bbcfe8875a65969ff57b00000000000000000000000000ac1414aa"], 0xfdef) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0xf1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1a089, 0x6, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7, 0x0, @perf_bp={0x0}, 0x2018, 0x0, 0x0, 0x8, 0x1000, 0x0, 0x7, 0x0, 0x0, 0x0, 0x6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x3) bpf$PROG_LOAD(0x5, 0x0, 0x0) r0 = socket$kcm(0x23, 0x2, 0x0) sendmsg$kcm(r0, &(0x7f0000000140)={&(0x7f0000000000)=@phonet, 0x80, 0x0}, 0x0) setsockopt$sock_attach_bpf(0xffffffffffffffff, 0x1, 0x34, 0x0, 0x0) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000200)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fed007907001175f37538e486dd6317ce2200"], 0xcfa4) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x0, &(0x7f0000000000)='%', 0x0, 0xd01, 0x88be, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) 8.452027323s ago: executing program 3 (id=540): perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) bpf$PROG_LOAD(0x5, 0x0, 0x0) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0xa, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0xf, 0x5}, 0x100e64, 0xc78, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x200000000}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x8) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4, @perf_config_ext={0x200000000000000}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10000000, 0x1}, 0x0, 0x0, 0xffffffffffffffff, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000440)={0xf, 0x9, &(0x7f0000000680)=@framed={{0x18, 0x8}, [@func={0x85, 0x0, 0x1, 0x0, 0x5}, @call={0x85, 0x0, 0x0, 0xbb}, @generic={0xa7}, @initr0, @exit]}, &(0x7f00000003c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x1e, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000005c0)='cpuacct.usage_percpu\x00', 0x26e1, 0x0) ioctl$PERF_EVENT_IOC_SET_FILTER(0xffffffffffffffff, 0x40082406, &(0x7f0000000140)='\x00') bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000600)={0xb, 0x3, &(0x7f0000000180)=ANY=[], &(0x7f0000000480)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000340)={0xe, 0x4, &(0x7f0000000400)=ANY=[@ANYBLOB="18020000801000000000000004000000850000000e00000095"], &(0x7f0000000000)='syzkaller\x00', 0x1, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) ioctl$TUNSETOFFLOAD(0xffffffffffffffff, 0x400454d0, 0x2) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000380)={&(0x7f0000000080)=ANY=[@ANYBLOB="9feb010018000000000000001c0000001c00000003000000010000000000000e0200000000000000000000000000000404000000002e"], 0x0, 0x37, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x20) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000100)='memory.current\x00', 0x275a, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x1d, 0x0, 0x0, &(0x7f0000000000)='GPL\x00', 0x4, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) ioctl$TUNSETIFF(0xffffffffffffffff, 0x400454ca, &(0x7f0000000080)={'wlan0\x00', 0x200}) socketpair(0x1, 0x1, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$PERF_EVENT_IOC_SET_FILTER(r0, 0x8946, &(0x7f0000000080)) 7.809554822s ago: executing program 2 (id=542): r0 = socket$kcm(0x11, 0xa, 0x300) bpf$PROG_LOAD(0x5, &(0x7f0000000240)={0x0, 0x4, &(0x7f0000000000)=ANY=[@ANYBLOB="1800000000000000000000000000000081"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0xf1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5, 0x6, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xb8, 0x4, @perf_bp={0x0, 0x2}, 0x104141, 0x0, 0x0, 0x8, 0x0, 0xfffffffc, 0x2, 0x0, 0x0, 0x0, 0x3}, 0x0, 0x0, 0xffffffffffffffff, 0x0) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x5, 0x5, &(0x7f0000000180)=ANY=[@ANYBLOB="180800000000000000000000000000001800000000000000000000000000000095"], &(0x7f0000000980)='GPL\x00', 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, @fallback=0x28, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r3 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f00000001c0)='./cgroup.net/syz0\x00', 0x200002, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000140)={0x9, 0x4, &(0x7f0000000800)=ANY=[@ANYBLOB="1800000000008802000000000000000071722500000000009500000000000000a9db9b74b075eafb73bbb7c32f96d9e616cfb6ab1decab44509d636349305194d7327cbc8c84d7ee675a7c285dd3bfc125cd"], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0xd, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) openat$cgroup_int(r3, &(0x7f0000000200)='memory.low\x00', 0x2, 0x0) ioctl$PERF_EVENT_IOC_SET_BPF(r1, 0x40042408, r2) sendmsg$inet(0xffffffffffffffff, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000011c0)=[{0x0}], 0x1, 0x0, 0x0, 0x1f00c00e}, 0x0) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f0000000040)="e03f03002f000b08d25a80648c7494f90424fc600b0002", 0x17}], 0x1}, 0x0) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000340)={0x1, 0xffffffffffffffff}, 0x4) bpf$PROG_LOAD(0x5, &(0x7f0000000440)={0x9, 0x1e, &(0x7f00000006c0)=@raw=[@map_idx={0x18, 0x7, 0x5, 0x0, 0xb}, @exit, @printk={@i, {}, {}, {}, {}, {0x7, 0x0, 0xb, 0x3, 0x0, 0x0, 0x101}}, @exit, @snprintf={{}, {}, {0x7, 0x0, 0xb, 0x8, 0x0, 0x0, 0x43e0}, {}, {}, {}, {}, {}, {}, {0x18, 0x3, 0x2, 0x0, r4}}, @map_idx={0x18, 0x8, 0x5, 0x0, 0xa}, @initr0={0x18, 0x0, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0xffff}, @call={0x85, 0x0, 0x0, 0x5a}], &(0x7f0000000080)='GPL\x00', 0x4, 0xc3, &(0x7f000000cf3d)=""/195, 0x20800, 0x0, '\x00', 0x0, @cgroup_sock, 0xffffffffffffffff, 0x8, &(0x7f0000000000)={0x7}, 0x8, 0x10, &(0x7f0000000000)={0x0, 0x5}, 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0xf1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1a089, 0x6, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7, 0x0, @perf_bp={0x0}, 0x2018, 0x0, 0x0, 0x8, 0x1003, 0x0, 0x7, 0x0, 0x0, 0x0, 0x6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x2) ioctl$TUNSETIFF(0xffffffffffffffff, 0x400454ca, &(0x7f0000000080)={'bridge0\x00', 0x1e}) socketpair(0x1, 0x5, 0x0, &(0x7f0000000100)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$PERF_EVENT_IOC_SET_FILTER(r5, 0x89a2, &(0x7f0000000080)) close(r0) r6 = socket$kcm(0x10, 0x400000002, 0x0) write$cgroup_subtree(r6, &(0x7f0000000540)=ANY=[@ANYBLOB="924300005a726465c1b3fb048c9779050000010000000000988f4101cdd282b443f583c8eaf975d35bdabba51dbbae8ca69d07308fa10ccad7adef72e2e35b01425daec270dca028d9a7f239d85f8e21ea61ea3a76cfbe14eb16080f691c8962bba6f8325e12755a3cef1e938f7e1d2406b549701862a47458a9d3e07598401e5ad0"], 0xfe33) socket$kcm(0x29, 0x2, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000017c0)={0x1, 0xe, &(0x7f0000001880)=ANY=[@ANYBLOB="b700000081140000bfa30000000000000703000000feffff720af0fff8ffffff71a4f0ff000000007110bc00000000001d300500000000004704000001ed00000f030000000000001d44020000000000620a00fe040400007203000000000000b500f7ff000000009500000000000000023bc065b58111c6dfa041b63af4a3912435f1a8641aa05a1336b3b4c4becea710aad58db6a693002e7f3be361917adef6ee1c8a2a4f8ef1e50becb19bc461e91a7168c50000000190f32050e436fe275daf51efd601b6bf01c8e8b1b526375ec4dd6fcd82e4fe51bef7af9aa0d7d600c095199fe3380d28e599b0eaebbdbd732c9cc00eec363e4a8f6456e2cc21557c0afc646cb7798b3e6440c2fbdb00a3e35208b0bb0d2cd829e654400e2438ec649dc74a28610643a98d9ec21ead2ed51bf900000000000000d8a7925c3109b151b8b9f75dd08d123deda88c658d42ecbf28bf7076c15b463bebc72f526d8e8afcb913466aaa7f6df70252e79166d858fcd0e06dd31af9612f2460d0b11008e59a5923906f88b53987ad1714e72ba7a54f0c33d39000d06a59ff616236fd9aa58f2477184b6a89adaf17b0a6041bdef728d236619074d6ebdfd1f5089048ddff6da40f9411fe722631cb467600ade70063e5291569b33d21dae356e1c51f03a801be8189679a16da18ec0ae564162a27afea62d84f3a10746443d6438e959532e0617d419c6bc6ea9f2bca4464f56e24e6d2105bd901204a1deeed4155617572652d950ad31928b0b0c3dc2869f478341d02d0f5ad94b081fcd507acb4b9c65fee9d5a17f48a7382f13d000000225d85ae49cee383dc5049076b989b40000000000000da60d2ae20cfb91d6a49964757cdf538f9ce2bdb1ab062cd54e67011d355d84ce97bb0c6b4a595e487efbb2d71cde2c140952f9a0f0bc6980fe78683ac5c0c31032599ddd71063be9261b2e1aab1675b34a22048ef8c126aeef5f510a8f1aded94a129e4aec6f8d9ab06faffc3a15d96c2ea3e2e04cfe031b2875353193f82ade69d0540059fe6c7fe7cd8697502c7596566d674e425da5e87e59602a9f6590521d31d3804b3e0a1053abdc31282dfb15eb6841bb64a1b304502dda787343cccc953992e4a982f3c48153baae244e7bf37548c7f1a4cad2422ee965a38f7defbd2160242b104e20dc2d9b0c35608d402ccdd9069bd50b994fda7a9de44028d6112a0c2d21b2dc98816106dec28eaeb883418f562ae00003ea96d10f172c0374d6eed826416050000000bfe9b4a9c5a90ff59d54d1f92ecc4e95dd2d18383117c039862198899b212c55318294270a1ad10c80fef7c24d47afce829ba0f85da6d888f18ea40ab959f6074ab2a40d85d15017ab513cdc6c0e57fb1c1ca571380d7b4ead35a385e0b4a26b702396df7e0c1e02b6e4114f244a9bf93020000000000000080e69db384ac7eeedcf2ba3a9508f9d6aba582a896a9f1e096df6ecea75caf822a7a63ba34015ea5aacb1188883ad2a3b1832371fe5bc621426d1ed0a4a99702cc1b6912a1e717d29135753208165b9cdbae2ed9dc7358f0ebadde0b727f27feeb744ddcc536cbae315c7d1fe1399562ba6824840bd2951680f6f2f9a6a8346962a350845ffa0d829e4f79adc287906943408e6df3c391e97ba48db0a5adbfd03aac93df8866fb010aec0e92bed1fe39af169d2a466f0db6f3d9436a7d55fc30511d00e10000c95265b2bd83d64a532869d701723fedcbada1ee7baa5b6a686b50f0937f778af083e055f6138a757ebd0ed91124a6b244f9acf41ac5d73a008364e0606a594817031fc2f52c8785fe0721719b3d654026c6ea08b83b123145ab5703dad844ceb201ddeb6dc5f6a903792283c42efc54fa84323afc4c10eff462c8843187f1dd48ef3fa293774d582956ff0f40b10ca94f6feeb2893c17888e1cdba94a6ea80c33ead5722c3293a493f1479531dd88261458f40d31fe8df15efaaeea831555877f9538d6ee6ba65893ff1f908ba7554ba583fef3ec7932f5954f31a878e2fae6691d1aee1da02ba516467df3e7d1daac43738012e4fee18a22da19fcdb4c2890cda1f96b952511e3a69d694d625e0b2f808890205f3a6da2819d2f9e77c7c64affa54fec0136cbafa5f6f096753b639a924599c1f69219927ea5301fff0a6063d427f0688430754c02180d61542c2571f983e9673560000000000000000005a7b57f03ca91a01ba2e30ca99e8ebc15ecb4d91675767999d146aef7799738b292fd640dfef6b04d086f737a159d7e0c6e4d81ad64a8bbca48568325b2969e2b15f36b788bce5ccdbaf75c94cb93499f6947a967a7bce14c6de4e7c0660d80010f5c653d22d490cba8c2a4ab595bf4238f18ca428dafc7ac96d404607a0000000051a2104f22e6db5a62b5089c1b45282d38864daa3ae81d6b0968d1d2867b91b7d120617d12d91db2633d6864da40b54783a17aaeb6737c323f9f98e354cc98dcfe23ad01bd1c61563e69ffe1c2c73e16e1461173f359e93d2c5e424c17998809ec8f0232b3955e052a4cecd89008f70314a0bdd491ec86a4555d89fe0120f64c62e8e3ed8bcb45202c3d4bbec8d722824c0ebca8db1ea4a003d2fbdc1f9be78537756ab5bbe4fe9af5d785d0128171c90d9900ce2532b0f9d01c4b45294fbba468df3e1b583cb4e62e754598e47df6bd06431c94bc5d047899fd219f448bf9189c65c9d91eda6b52a373803a9efe44f86909bc90addb7b9aee813df534aac4b3093c91b8068cd84990453f006694d461b76a58d88cf0f520310a1e80dc18cde98d662eee077515d0a8811922929e085392ab3d1311b8243266d87047f601fa88a0da36b9f302e8262395174328f2482d14008de83070744f143fdec90ba5a82668d5fac114c13955ad6dca5db2231d8ba14c54c47ed04a4b4ace17e357e1d6032399f87a7a14245bbd796a09313b247b95d37ff40a404bdad74bd20000000000000000000099fef7cd7af3ce64a92f95d89d125b1e641240d7e5e27a3d1f7684448c3e3822d617e205061298b939a191be4b48e169bde2cae3accc5bd40a2968b59c93d35f8e42366fdef9a2abae1cf01ce68abff28861aac8302d268569dd42e194e330c7aaa54ebbcefd23f21ce8153b9926e12e925cb56119df72c7533a48d028ad0c74e2a9478fa3be18a1a2b65079cc1c00000000000000f59dd19e8d525206c0a728cfd42193abe8130bc01a2d69841f3d7799ac04bdc590bb1c89b9c695f163e57343c9bfb59909433c9001c5f8b23e38534a538fc933cac6c2a92d038df638a0f226df9fb857bd414c2cd69985e8053e3dfa41614d7c74d04d8c2471041d17c730fad28395f8d4688898cd58b9d600c851626529bb58aa364b55e73f053450665e7b94ed1012fd7a8139166fd5e59c84f4ab279b1b99c028db4cb9680c8035f967db18de738844da7e260a830c1ffa49f5af3c15423a0e315acb82a3e89218cb314e68fda4d94aa1d815babc13b9fd336d205c5913ef67cf0216e2d81e6127bd9d7fab28800eaab2355992f8ce4cd38add4b272c0bee4076ca4847ffa691cf78fb7ec212bad3bef29f577ea7159b7f3025b3d977ff7c9102"], &(0x7f00000001c0)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x0, 0x10, &(0x7f0000000000), 0xfffffffffffffd00, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) r7 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000480)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="18000000020000000000000000ee000095"], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x80) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r7, 0x5, 0xb68, 0x560b0007, &(0x7f0000000000)="259a53f271a76d2688634c6588a8", 0x0, 0xd01, 0x2a0, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="18090000000000000000000000000000850000006d0000001801000020696c2500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000007100000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0x4, &(0x7f0000000480)=ANY=[@ANYBLOB="1800000000000000000000000000000085000000d0"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x12, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xf, @void, @value}, 0x94) r8 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f00000007c0)='syzkaller\x00', 0xfffffffe, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000300)={&(0x7f0000000180)='workqueue_activate_work\x00', r8}, 0x10) r9 = bpf$PROG_LOAD(0x5, &(0x7f0000000380)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000300)={&(0x7f0000000180)='workqueue_activate_work\x00', r9}, 0x10) bpf$MAP_CREATE(0x0, &(0x7f0000000980)=@base={0x4, 0x4, 0x4, 0x4, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) 7.534370655s ago: executing program 4 (id=543): bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x0, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00'}, 0x10) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000940)={0x0, 0x0, &(0x7f00000001c0)=[{&(0x7f0000000000)="d8000000210081044e81f7d28344b904020000", 0x2}], 0x1}, 0x0) perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x4, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) perf_event_open(0x0, 0x0, 0xaffffff7ffffffff, 0xffffffffffffffff, 0x1) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000800)={&(0x7f0000000780)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x0, 0x0, 0x3}, {0x0, [0x1e]}}, &(0x7f00000007c0)=""/11, 0x1b, 0xb, 0x0, 0x0, 0x0, @void, @value}, 0x28) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b000000000100000811000009000000"], 0x50) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, &(0x7f00000006c0)=[{0x0}, {&(0x7f0000001540)}], 0x2}, 0x4004840) socket$kcm(0x11, 0x200000000000002, 0x300) bpf$MAP_UPDATE_BATCH(0x1a, &(0x7f0000000640)={0x0, 0x0, &(0x7f0000000000), 0x0, 0xb, r0}, 0x38) bpf$MAP_LOOKUP_BATCH(0x18, 0x0, 0x0) r1 = socket$kcm(0x2, 0x3, 0x2) sendmsg$inet(r1, &(0x7f0000000100)={&(0x7f00000004c0)={0x2, 0x0, @broadcast}, 0x10, 0x0, 0x0, &(0x7f0000003a00)=[@ip_pktinfo={{0x1c, 0x0, 0x8, {0x0, @dev={0xac, 0x14, 0x14, 0x2a}, @multicast1}}}], 0x20}, 0x4008804) bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f0000000000), 0x4) perf_event_open(&(0x7f0000000240)={0x5, 0x80, 0x0, 0x0, 0x9, 0x0, 0x0, 0x8020, 0x40, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, 0x2, @perf_config_ext={0x4a, 0x13}, 0x3386, 0x400000006, 0x800, 0x0, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x4}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) socketpair$tipc(0x1e, 0x5, 0x0, &(0x7f0000000340)) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000003c0)={0x0, 0x6, &(0x7f0000000080)=ANY=[@ANYBLOB="18080000000000000000000000000000851000001800000000000000", @ANYRES32], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000003c0)={0x3, 0x0, 0x0, &(0x7f0000000080)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x23, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0xffff7fff, @void, @value}, 0x94) r2 = socket$kcm(0x10, 0x400000002, 0x0) write$cgroup_subtree(r2, &(0x7f0000000080)=ANY=[@ANYBLOB="33fe0000240013"], 0xfe33) 7.281926605s ago: executing program 3 (id=544): r0 = perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0xf0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x9, 0x5, @perf_config_ext={0xffffffffffffffff, 0x8}, 0x9000, 0x0, 0x0, 0x1, 0x3, 0x0, 0x2}, 0x0, 0x0, 0xffffffffffffffff, 0x0) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0x5, &(0x7f0000000180)=ANY=[], &(0x7f0000000980)='GPL\x00', 0x0, 0x0, 0x0, 0x41100, 0x0, '\x00', 0x0, @fallback=0x24, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) ioctl$PERF_EVENT_IOC_SET_BPF(r0, 0x40042408, r1) r2 = socket$kcm(0x10, 0x2, 0x4) sendmsg$kcm(r2, &(0x7f0000000040)={0x0, 0x0, &(0x7f00000013c0)=[{&(0x7f0000000280)="39000000140081ae0000dc676f97daf01effffff0521018701546fabca1b4e8a06a6580e88370200c5090000009c40ebb3734b49bbc51245e7", 0x39}], 0x1}, 0x0) recvmsg$kcm(r2, &(0x7f00000005c0)={0x0, 0x0, 0x0}, 0x40010220) 5.14788724s ago: executing program 2 (id=546): openat$tun(0xffffffffffffff9c, 0x0, 0x280000, 0x0) mkdirat$cgroup_root(0xffffffffffffff9c, 0x0, 0x1ff) openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0x31) sendmsg$sock(0xffffffffffffffff, 0x0, 0x4000) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000caefb8)={0x8, 0x3, &(0x7f0000000100)=ANY=[@ANYBLOB="850000006100000054000000000000009500000000000000b4a8b1541206000000e9c79077fa15ba36eca61299de54cf77c9062c30bc068829afff36b31fa7e358e95cfa"], &(0x7f0000281ffc)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @cgroup_skb, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) bpf$BPF_PROG_TEST_RUN(0x1c, &(0x7f0000000180)={r0, 0x2000000, 0x8, 0x0, &(0x7f00000000c0)="13435cb8b9f6ff00", 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) perf_event_open(&(0x7f00000003c0)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4d31, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x9, 0x2, @perf_config_ext={0x5d, 0x200}, 0xf242, 0x2, 0x0, 0x0, 0x0, 0xfffffffe}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0xa) r1 = bpf$ITER_CREATE(0xb, &(0x7f0000000100), 0x0) close(r1) write$cgroup_int(r1, &(0x7f00000000c0)=0x9, 0x12) r2 = perf_event_open(&(0x7f0000000580)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x210e, 0x8000, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x30, 0x2, @perf_config_ext={0x407fff, 0xaea}, 0x14905, 0x32, 0xfffffbff, 0x3, 0x2, 0x0, 0xfffa, 0x0, 0x0, 0x0, 0x2008}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r3 = socket$kcm(0xa, 0x5, 0x0) sendmsg$kcm(r3, &(0x7f00000017c0)={&(0x7f0000000040)=@l2tp6={0xa, 0x0, 0x7, @dev={0xfe, 0x80, '\x00', 0x3e}, 0xa, 0x2}, 0x80, &(0x7f00000003c0)=[{&(0x7f00000004c0)="7f", 0x1}], 0x1, &(0x7f0000000600)=ANY=[@ANYBLOB="180000000000000084000000070000007ffffffff5000000b8"], 0xd0}, 0x480c4) ioctl$TUNATTACHFILTER(0xffffffffffffffff, 0x401054d5, &(0x7f0000000040)={0x4, &(0x7f0000000000)=[{0x4d, 0x0, 0x3}, {0x35}, {0x0, 0x0, 0x4}, {0x6}]}) r4 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="0200000004000000080000000100000080"], 0x48) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000480)={r4}, 0x4) r5 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x18, &(0x7f00000001c0)=ANY=[@ANYBLOB="18000000000000000000000000000000b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb70200000000000018230000", @ANYRES32=r4, @ANYBLOB="0000000000000000b70500000000000085000000a5000000180100002020640500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000a50000000800000095"], &(0x7f0000000600)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1f, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000180)={&(0x7f0000000000)='percpu_alloc_percpu\x00', r5}, 0x10) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000080)={0x1e, 0x6, &(0x7f00000002c0)=@framed={{0x18, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4}, [@map_fd={0x18, 0xf}, @call={0x85, 0x0, 0x0, 0x8c}]}, &(0x7f0000000100)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x24, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) sendmsg$kcm(r3, 0x0, 0x0) socket$kcm(0x1e, 0x5, 0x0) r6 = socket$kcm(0x10, 0x400000002, 0x0) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000100)=[{&(0x7f0000000040)}], 0x1}, 0x0) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r7, 0x89ff, &(0x7f0000000900)={'wg1\x00', @random="0600002000"}) socketpair$unix(0x1, 0xd, 0x0, &(0x7f0000000140)) write$cgroup_subtree(r6, &(0x7f0000000040)=ANY=[], 0xfe33) ioctl$PERF_EVENT_IOC_SET_BPF(r2, 0x40042408, 0xffffffffffffffff) 5.067993424s ago: executing program 3 (id=547): r0 = getpid() r1 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x1, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, r0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r2 = bpf$PROG_LOAD(0x5, &(0x7f0000000400)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa1000000000000070100"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) ioctl$PERF_EVENT_IOC_SET_BPF(r1, 0x40042408, r2) socketpair$unix(0x1, 0x1, 0x0, &(0x7f00000000c0)) socketpair$unix(0x1, 0x1, 0x0, 0x0) socketpair$tipc(0x1e, 0x2, 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(0xffffffffffffffff, 0x4020940d, 0x0) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0xb, 0x8000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x8}, 0x1400, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4}, 0x0, 0xaffffff7ffffffff, 0xffffffffffffffff, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) r3 = bpf$PROG_LOAD(0x5, &(0x7f0000000200)={0xc, 0xe, &(0x7f0000002e00)=ANY=[@ANYBLOB="b702000003000000bfa30000000000000703000000feffff7a0af0fff8ffffff79a4f0ff00000000b7060000ffffffff2d6405000000000065040400010000000404000001007d60b7030000000000006a0a00fe00000000850000000d000000b7000000000008009500f10100000000487591731cba12c07d57d995b61e89a4530f92344f242b416ae9eeefc0e9c6f203cb1276bfdbb4ddffffff7f82dc2b938189a7ca02f732e4c2eab72bf40c0682fd0a0c4ac106b29e220dc2880072599456d4c4e6f3fe684ab8373bb4df9d72876ef3834293812e927c01c7da1322da44c7f2ed1084a12f56d1cb39df9858037458a4ca037604007600b6be484e4c9517af216bd8ed42f7dd01008e49f4a94608c9a20819e02fc22e6be45574d4ed88b37ab8d7674c644dca2f1b4d745fd95c41f9dfc1adafd1e5a3e7f2e898961cb43e438c4e41ae43ea118e14ffffffffe4b8a80366ce5401ec61921a1b529cc8b99bffffb1ac006c67767b03b95151aeb89e6d4a43c625aa228504e4afd8c1cc3eb215ba22f43115f4d39dc7beedb130d9f2be90133a4500000058b8c9370634060105baa664953514605fba3973aa021945b985a8a66e0200000057033815717b4fdbe55b37cb8d7f41aacfbd4089ea1bd22440f64909a09b5a759a703e71f358e11ac8e13db15d792e604a4f279b3bd6621bdf2c17bc0400001000000000ff8d81006200607a9a76e5d9656a7154c75773902a1bdf399df3925130312d095e9c1f973d091c198c1a11edb6b3cc425fe203d2f2655a76865c2c34e2470fcfb1248c0add5431a7fbcb0ef4f66a09af93a09fab1daae4b518d7a5d95a017864010067d6bab101446ebfe3fdeed7ee7bb0749cacf56cf27409c60fca2e0004000000000000a9cb6f4a78444986f9b1ab61f9dab53038010000004abbfc59d6d1b18fe380df4bf024f120bd755d82033f2fb7d8fc9e0de834f7646c8dd27da1297d0c77b294e097e293db7f002c0024ab2fb4d32972cba6f49051cec1ff5d16231bbb90a2d201a500000000000000007700b06fa191ebd3a0c2ef0058ffebd7cc4cf80f74a7cdac01d998c24f34a5ba9a4a2039d0416e3f8107671141ffffffe0c7d8e94a27a06a4e3d9acee835fd0571e5bbb3e6d2b5eba505000000968983811f832dc5390f83e817c602c4f1f0d0504255c22ee8674053d0e160e5255366139bbe5863e23c3dd42d21f542816edf56a93d0a7e6f08f9ffffff64875fea6ff57ba6ae25c5e8ca4f78d5a01308243b08f1caa46be5244d64f8e875857f083144c642f71cdc8e5634c1360c056430fe77ee7ed7ac1f9743786b2fb8e0fcfcc3d36c93230b7b1da97c971c8c84a427edc3492b97e73d2060acfd8145e4a5851bc4d6fdc5ad939d7795f3879baa88bd194d48e50c84892c97c800d156b059a718f6b10274b077a710f27ab8ee953de70ea860b74a0f3c3dc11177b11cc2e62a95f1ecf607a8dc38e525f415a1bd46b38845ebca04061bacbf627f7975fe599678fee48f83b5989543729e3600000000bc86cd51704f309130f534741377ea7b7bea3c46c0c4c4b7c27c5d057d95ac85a41cdcee8e6fa31f7d2137ed1fb4b21c13b9a2c5e3f7c9ef9e45a35adbf0b9312be929863f000000000000004a82bc080de1f87808d0711dd76f2977ca7f2684bfa5c14a0cd6f1f561e34e4e8e51e81d4a355a7d00d917c16a2bb0cfb2b5f59dfead7ac6e7fa84746e2e425769b9ee2c8ff10e934847604d930f62924d0562ce17f6dadf5053ed8f33092a41bb46e1878c5295fecc27f9c6d1f62da58c0002ea00000000009aa38a05e70591d5cdab1c488ef3c1984c7c0a566cfc2a080000009ec206a54fb49056a555414178ef00d8b8f3c59f01eb5d83415994efcc6ec4b3c275cd6b1b5ff82ef7d7abb1d218e7a1d0afa285706841aac9ccc89df41c39dd58dd70569dde45f8adeaad7d3328fbb6e279f745d2872f0208635e465ca443c3a64c7803760880af23fb3f430a0311fffc96dd13b951642f1433f65b4e170a62a5f7b7d0f9d5cef0d17289c43d4aee0001f7a343899434594cc23e1c864164e130754b337e560f285dc670a31241bf657babf0615b85dc200a10294b7d5885b43ac62fc7f97a85586168483427072a535f2c7481ec261c00f725de74e48d9a86f7d4a5d28da3f099ca3e6472b9d7c86d961f525f799b4517141f018af0673b8296f867eca1ec07be11bc497a6f7d2b752bcf77c2908b64630e7fa0c2261bc2d5de32ab6bbcf296d36807544aa7c3d3301fe227b713a371414c98695e559f9cbf6b046184064a5f24a4cc6f41f21fc24a3ad7d20a89e00a9dc99a40f890869d35fba3ce6f297661d3f8ba21c65badf55d1859581f9e7ef3e2693b46a8fc85be061ce79a08002c04dc04de8b6536123b24be2ef80eb06b2db900fb30596c1574b2a31f81d61ccfd58080d2330b9c7b87b5d17d48c32daffead3414b91603e250eeedc7d601000000037426f643797be3e93da96b5643d3feed0b7c885d06006b830d7cbf3152f27522f5142dcc84a9e48a07518f0142167abf5d6685d09945cbc778bcc3e7dcfaee5d9c1689a3bafc0d3b51b5a3bfd6007954c36d532960964183842601e5364ecb6ad9168040388c7640bfa2f88643de7eebf4da8d1c3e76daace5217761d933d06bbe9609fcf5971aa1e77c3123910e63daaadd8878ad468eabaf78a96012a4ada1a9cd217fb2a0da2d521454ea9e8fcd3b5badfd6f00003a73345b841d04a02bf441955b932c59608a555bc44873272812e0fb874618a0b56b4cf44990f60000000000000000000000b20000da0ca6797590ed13b0bccf71a39e05e877893646d185a77882f866785af6b0149e336c31fb177e3e85f4c60cd4de4ce6ea73a95f434328620fa493937386ad2e2a0d60eb815aa05c33e02c32276dab36d14c63af66a31409ab2a403ec3c7a4e07bd745efa2835a8c932f22aa6da40af9bcdf808b916bc8deb37d5b8c422b65c42d17e61751c561ce775a31b52703d398d52694cfbb7d2b3791b030093b321d9f16b2f06676cf94d75cbba6491ae0b5a16ce92320321314d8d2e88d1cd7e7b1216bdaecba309a38e107103e649d46958cc6ba2d660dd41b78d832beb7206ae01508377273ea96e40760410aeed1866971e04f578e9d856d01000000045aea928f5f669be0636dc3f34f90c34531735f271527412d1ae755a9243da523d713071f9370b509a34eeb46415b2f0d271a7072cbd17e293f20132e6c15756e92776c6a0d7c3a9f512ce17edf3f1ea190853bbf93e220a6ce968b79d504c057000e7d8f8249a8158e68a90bbea8bfab2bd3c067c28e185fe62ce7020f5282cf045b9c790984c6fb65fd3187bd8bfcbe663df6b7770000f58fbad41e6eee5c9595950c4172b9c925403b2f99bbf3cb1981bb0d14bded8eae35e08278020a1ec7f508628056fd3d408a02a1cf8594bcbb21a88f477673442804f714212d000045b9f563b5352fe460a30489b1b6a6d37daead86151492f7fd4b5c64007b68a1b04027eac124478a2ef7f59fe472795785de83578cb96334e0f7c1370dc397d3aa42d937b5718b7610cdcdfe104db7801ec74980b8b111a2748321f81512e4204eb2b024b9fc9e0f257f8c6037b93b2caa236d4354b32434d5a6b01e00000000ee2ea723ea2e1accb97a200609c77e0000000000000000d3a54ccd6e13a966801e9341260d6cbce5fe03999214462cbaa297448677ab659102d0f430fbeae119a7ef2e962d2829d4dd2201c4b30d491269594c88252fbd09aced90609851bd9e5c307e7e0d39e73579c1f3563eff1a6237d3699d61acdc8e36010d76093ddd237df1c4181b0a0c4543b4249e9ff2f5e8b5e0ba2048d542de40f643fda4036124b8feb2dd45d0fa52300518c8052cc09ad73f89734fce82cc627356aa2c651ed2644f34cfbc32e8b29cf29e895e43b473ddb9a43421b4b25f8bbce8e2d7cb8547d156d5972021ae4c9e30f85413276ddebde55999d2ec3c524632b74d703147ba09e0dcb26c4b89636d28428b67e955f53bfd0c9eeb7a9d17000000000096cd8ecf1c511eea07aefa1c5cae1841efa9329d80eafefe00000000000000009111274a44c722ff9f5151aa7cb99ea3e8b2c51eadbd2d0ba1a25b08cc3e67cd186c12ea62a55ff905388bb30d1a63d42593c9aea3a84f5a6fc470d8aaaafeccb373ca26c3685679e6a048af19fca3fc5315a3"], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000080)={r3, 0x18000000000002a0, 0xe28, 0xfffffffffffffff5, &(0x7f0000000980)="b0ff04c66b0d698cb89e2fe086dd1f74ffff06000000fe80000000000000ac14140746647b7954c4c06b580febc28eb143d0f6c0bad62c67a04402ba4125c7024f63fdb0b6c8ee826b4dfe6042a2f057c66cad677d850ea9928bcfcb47e585e427746ed3b27c40060cbd030a6d675c9926af53cd3085b24f9b7a486775c4f284f8c5a572ca115bce90c0ee9d4e7a07f5f1518092cb1f156694036f6618a59196631e6303fd5307d1112601d3641c9492f7dc3503416836b14590c53b1fc1ac149b70cc1142d6bc57fc3a76839fa2f96878b520fedfb9f64d81584a2e85ab4f6ec718b02d78f2ebf04e6b3b94610a21616181629a03c3dc0bf05e0a71f887833b81db7a10bc53259cb80716f6804934a411d424c1db98d454be1adb2776fdbb92b299d3b80af6987a871b4549fdb4c8297ee31ad925c8b0fb1a9d2589b08ed52602cbc26b56df71201bc4ea8621c56f33d251c1d4589af2dcd78fbb4e34bde02cb3920a30cee9489ee72c3e19304c16c2110e1839712d484b80abe77786a7e2ba834874a4e16b93dd07297554a06c2ad2c906f8ebb1db8730df096709184728d48f0a806696bd0d4b12d0064b933d9675353dae77fe8419451f85da63be78b70ca2a84a77f572d9f289d4313e6f6039fe756ac13a5d08838315dff44cda433cc7bc6b77449f8c", 0x0, 0x2f, 0xe8034000, 0xf000, 0xfffffffffffffe2a, &(0x7f0000000000), &(0x7f00000000c0)="c6769e45b7c61302926682c7f9e9bb5ba2b3cdf023e8da0392a4cd62e2370f25ae5ba0dab896bcf5b774cd28bebbde39f796ae27d04582bb7c03e9fe830ea22c9fd03f6d2779515fdad3f5d0de07b7b70996102fdb67b1e77a34a5b7136a212fa2c0ea502588309dc3e42c55a6f93e6ba5e1b492f9db48f0fdd2f9fb937b3e8a63dcf9dd855837433998ba579da27559", 0x5dc}, 0x28) 4.963135442s ago: executing program 4 (id=548): r0 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r0, &(0x7f0000000600)={0x0, 0x0, &(0x7f0000000340)=[{&(0x7f0000000940)="2e00000010008188e6b62aa73772cc9f1ba1f848310000005e140602000000000e000a001000000002800000128c", 0x2e}], 0x1}, 0x0) 4.943228274s ago: executing program 0 (id=84): bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000200)={&(0x7f0000000000)=ANY=[@ANYBLOB="9feb01001800000000000000240000002400000002000000000000000000000400000003000000000000001301000000000000000000000d0200"], 0xffffffffffffffff, 0x3e, 0x0, 0x2, 0x0, 0x0, @void, @value}, 0x28) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fedcb7907001175f37538e486dd637f4b22667f2f00db5b686158bbcfe8875a65969ff57b00000000000000000000000000ac1414aa"], 0xfdef) r0 = openat$cgroup_ro(0xffffffffffffffff, &(0x7f0000000140)='cgroup.stat\x00', 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(r0, 0x40082404, &(0x7f0000000300)=0xe69a) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, &(0x7f0000000680)=ANY=[@ANYBLOB="1800000002000000000000000000000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r1 = bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000200)={0x6, 0x3, &(0x7f0000000680)=ANY=[], &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fff, 0x80000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0x3, 0x8}, 0x8080, 0x2, 0x0, 0x0, 0x7fffffff}, 0x0, 0xafffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xa, 0xffffffffffffffff, 0x9) ioctl$TUNSETCARRIER(0xffffffffffffffff, 0x400454e2, &(0x7f0000000080)=0x1) socket$kcm(0x10, 0x5, 0x0) r2 = getpid() r3 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fee, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407ffc, 0xaea}, 0x14105, 0x2e, 0xff7ffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x2a9e6}, r2, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r4 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000700000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0xe, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}, 0x0, 0x0, 0x0, 0x0, 0x1}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x1) ioctl$PERF_EVENT_IOC_SET_BPF(r3, 0x40042408, r4) bpf$BPF_GET_PROG_INFO(0xf, 0x0, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xfdef) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000380)={0x6, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r5 = bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000001280)={0x11, 0x3, &(0x7f0000000940)=ANY=[@ANYBLOB="1800000008000000000000000000000095"], &(0x7f0000000380)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000007c0)={&(0x7f0000000780)='contention_end\x00', r5}, 0x10) r6 = socket$kcm(0xf, 0x3, 0x2) sendmsg$inet(r6, &(0x7f0000003780)={0x0, 0x0, &(0x7f0000000080)=[{&(0x7f00000000c0)="020a000202000000e4a17c45c8d260c9", 0x10}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0xcfa4) r7 = bpf$MAP_CREATE(0x0, &(0x7f00000009c0)=ANY=[@ANYBLOB="0f00000004000000040000000300000000000000", @ANYRES32, @ANYBLOB='\x00'/20, @ANYRES32=0x0, @ANYRES32, @ANYBLOB="000000000000000000000000000000000000000000000000000000008add802748732a5b324fe95fc1f76ebd7d6028a9fa30c70f7b2f16a835f11b826ce9ee9580c2fc8cef0dcbf866557c8d933293b211f24b7d466e2b8310b8e9f022efe438a05e08cfd5ec290e39ded6c7005fb46ecdfdbbd4cfb8f245e20df0430b4b919d8088f71adbd15755de4b3bbdb6d4ab54d2f045ae5f9e75ad4b370273894346ef3070b95d8000a03a0aed627889efd675d3447beed86d6b38ffda71db234739dadc62d4f5955b6905f5df52e71073ad42a04eae15829ba04c8729713180643798519347d30ecaa0e591c6a75160c8089c1459c33107736d7449b016993fa223394c2635349fd222311892e1d0d0cc38d1445500258d37bade50428818ea58808ee986900f222c3cec901828ce55653ab74e407ba04381c841a860c51d65"], 0x50) r8 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000240)={0x2, 0x4, 0x8, 0x1, 0x80, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$PROG_LOAD(0x5, &(0x7f0000000840)={0x8, 0x1c, &(0x7f0000000d40)=ANY=[@ANYBLOB="18080000c000000000000000000000001811000048b98d9afbfc34ee442e632143f3fd67d38c0b8766cde49377bef55ec0e1e979c9e6bffb9715efbde48742", @ANYRES32=r7, @ANYBLOB="0000000000000000b702000014000000b7030000000000008500000005000000bc0908000000000035090100000000009500000000070000b7020000000000007b9a00fe000000006609000000000000dbaaf0ff50000000bf8620000000000007080000f8ffffffbfa400000000000007040000f0ffffff770000000800000018220000", @ANYRES32=r8, @ANYBLOB="0000000000000000b7050000080000004608f0ff76000000bf9800000000000056080000030000008500000007000000b7000000000000009500000000000000"], &(0x7f0000000980)='GPL\x00', 0x1, 0x0, 0x0, 0x0, 0x25, '\x00', 0x0, @cgroup_skb, 0x0, 0xf00, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x4e) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[@ANYBLOB="8fed007907001175f37538e486dd6317ce2200"], 0xcfa4) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r1, 0x5, 0xb68, 0x0, &(0x7f0000000000)='%', 0x0, 0xd01, 0x88be, 0x0, 0x0, 0x0, 0x0, 0x2}, 0x48) bpf$OBJ_GET_PROG(0x7, &(0x7f00000000c0)=@generic={&(0x7f0000000080)='./file0\x00', 0x0, 0x10}, 0x18) 3.574929095s ago: executing program 1 (id=549): r0 = socket$kcm(0x10, 0x2, 0x0) sendmsg$kcm(r0, &(0x7f0000000600)={0x0, 0x0, &(0x7f0000000340)=[{&(0x7f0000000940)="2e00000010008188e6b62aa73772cc9f1ba1f848310000005e140602000000000e000a001000000002800000128c", 0x2e}], 0x1}, 0x0) (fail_nth: 1) 3.573704554s ago: executing program 2 (id=550): setsockopt$sock_attach_bpf(0xffffffffffffffff, 0x29, 0x2a, 0x0, 0x0) mkdirat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000)='./cgroup/syz0\x00', 0x1ff) r0 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) openat$cgroup_type(r0, 0x0, 0x2, 0x0) r1 = openat$cgroup_procs(r0, &(0x7f00000002c0)='cgroup.threads\x00', 0x2, 0x0) write$cgroup_pid(r1, 0x0, 0x0) r2 = openat$cgroup_ro(r0, &(0x7f0000000040)='cgroup.freeze\x00', 0x275a, 0x0) write$cgroup_int(r2, &(0x7f0000000200)=0x1, 0x12) write$cgroup_pid(r2, &(0x7f0000000340), 0x12) 3.573112481s ago: executing program 3 (id=551): recvmsg$unix(0xffffffffffffffff, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x0, &(0x7f00000003c0)}, 0x120) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000000)=ANY=[], 0xfdef) perf_event_open(0x0, 0x0, 0x1, 0xffffffffffffffff, 0x0) bpf$BPF_BTF_LOAD(0x12, 0x0, 0x0) sendmsg$kcm(0xffffffffffffffff, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000400)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYRES32], &(0x7f0000000100)='GPL\x00', 0x0, 0x0, 0x0, 0x41000, 0x22, '\x00', 0x0, @fallback=0x17, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0xb1, 0x82, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x3, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x1, 0xfffffbff, 0x3, 0x802, 0x0, 0x4, 0x0, 0x0, 0x0, 0x5}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) perf_event_open(0x0, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) bpf$BPF_BTF_LOAD(0x12, 0x0, 0x0) r0 = socket$kcm(0x2b, 0x1, 0x0) sendmsg$sock(r0, 0x0, 0x241) recvmsg(r0, &(0x7f00000004c0)={0x0, 0x0, 0x0}, 0x40002020) 3.572028791s ago: executing program 4 (id=552): perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0xb1, 0x0, 0x0, 0x210b, 0xb1061, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7e, 0x2, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x32, 0x10000, 0x7, 0x3, 0x0, 0xfffa, 0x0, 0x0, 0x0, 0x8000000000000000}, 0x0, 0x4, 0xffffffffffffffff, 0xb) openat$tun(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) perf_event_open(&(0x7f0000000100)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, @perf_bp={0x0}}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) bpf$MAP_CREATE_TAIL_CALL(0x0, &(0x7f0000000580)=ANY=[], 0x50) openat$cgroup_devices(0xffffffffffffffff, 0x0, 0x2, 0x0) r0 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000300)='./cgroup.cpu/syz0\x00', 0x200002, 0x0) r1 = socket$kcm(0xa, 0x2, 0x0) setsockopt$sock_attach_bpf(r1, 0x29, 0x2a, &(0x7f0000000040), 0xcf) mkdirat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000)='./cgroup/syz1\x00', 0x1ff) r2 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000280)={0x12, 0x4, 0x0, &(0x7f0000000040)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0xf, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) r3 = openat$cgroup_type(r2, &(0x7f00000001c0), 0x2, 0x0) write$cgroup_type(r3, &(0x7f0000000280), 0x9) r4 = openat$cgroup_procs(r2, &(0x7f00000002c0)='cgroup.threads\x00', 0x2, 0x0) write$cgroup_pid(r4, &(0x7f0000000c40), 0x12) r5 = openat$cgroup_ro(r2, &(0x7f0000000040)='cgroup.freeze\x00', 0x275a, 0x0) openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000180)='./cgroup/syz0\x00', 0x200002, 0x0) openat$cgroup_procs(r0, &(0x7f0000000040)='cgroup.procs\x00', 0x2, 0x0) mkdirat$cgroup(r0, &(0x7f0000000240)='syz0\x00', 0x1ff) write$cgroup_pid(r5, &(0x7f0000000080), 0x12) bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f00000001c0), 0x4) openat$cgroup_root(0xffffffffffffff9c, &(0x7f00000006c0)='./cgroup.cpu/syz0\x00', 0x200002, 0x0) 3.403451995s ago: executing program 2 (id=553): perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x0, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0xa, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0xf, 0x8}, 0x100e64, 0xc78, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x7fffffffffffffff}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x8) r0 = bpf$MAP_CREATE_RINGBUF(0x0, &(0x7f0000000600)={0x1b, 0x0, 0x0, 0x40000, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x10000000, 0x0, @void, @value, @void, @value}, 0x50) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a00)={0x6, 0x28, &(0x7f0000000e00)=@ringbuf={{0x18, 0x0, 0x0, 0x0, 0xfffffffb, 0x0, 0x0, 0x0, 0x252}, {{0x18, 0x1, 0x1, 0x0, r0}}, {}, [@map_idx={0x18, 0x7, 0x5, 0x0, 0x7}, @tail_call, @cb_func={0x18, 0x9, 0x4, 0x0, 0x3}, @ringbuf_query, @ringbuf_output={{}, {0x7, 0x0, 0xb, 0x8, 0x0, 0x0, 0x8}}, @map_idx={0x18, 0x4, 0x5, 0x0, 0xa}, @jmp={0x5, 0x0, 0xc, 0x7, 0x2, 0xffffffffffffffff, 0xfffffffffffffffc}], {{}, {}, {0x85, 0x0, 0x0, 0x85}}}, &(0x7f00000002c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x20, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, &(0x7f00000000c0)=[r0, r0], 0x0, 0x10, 0x0, @void, @value}, 0x94) socket$kcm(0x10, 0x400000002, 0x0) bpf$BPF_GET_PROG_INFO(0xf, &(0x7f0000000300)={0xffffffffffffffff, 0x0, 0x0}, 0x10) bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f0000000c40)=0xffffffffffffffff, 0x4) bpf$BPF_PROG_GET_FD_BY_ID(0xd, &(0x7f00000000c0), 0x4) bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f0000000140)=0xffffffffffffffff, 0x4) bpf$BPF_BTF_GET_NEXT_ID(0x17, 0x0, 0x0) bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f00000001c0), 0x4) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000100)=[{&(0x7f0000000040)="2e00000012002f", 0x7}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, &(0x7f00000003c0)=ANY=[@ANYBLOB='\x00\x00'], 0xfe33) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000180)) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x3, 0xc, &(0x7f0000000700)=@framed={{}, [@call={0x85, 0x0, 0x0, 0x2f}, @printk={@lli}]}, &(0x7f0000000200)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @sched_cls, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r1 = socket$kcm(0xa, 0x1, 0x0) sendmsg$kcm(r1, &(0x7f0000000140)={&(0x7f0000000180)=@l2tp6={0xa, 0x0, 0x0, @initdev={0xfe, 0x88, '\x00', 0x0, 0x0}, 0x5}, 0x80, 0x0}, 0x20000000) sendmsg$kcm(r1, &(0x7f0000002ec0)={&(0x7f0000000580)=@l2tp6={0xa, 0x0, 0x0, @remote, 0x101, 0x4000}, 0x80, 0x0}, 0x20000000) 2.994795022s ago: executing program 1 (id=554): perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) bpf$PROG_LOAD(0x5, 0x0, 0x0) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0xa, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext={0xf, 0x5}, 0x100e64, 0xc78, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x200000000}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x8) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4, @perf_config_ext={0x200000000000000}, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10000000, 0x1}, 0x0, 0x0, 0xffffffffffffffff, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000440)={0xf, 0x9, &(0x7f0000000680)=@framed={{0x18, 0x8}, [@func={0x85, 0x0, 0x1, 0x0, 0x5}, @call={0x85, 0x0, 0x0, 0xbb}, @generic={0xa7}, @initr0, @exit]}, &(0x7f00000003c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x1e, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f00000005c0)='cpuacct.usage_percpu\x00', 0x26e1, 0x0) ioctl$PERF_EVENT_IOC_SET_FILTER(0xffffffffffffffff, 0x40082406, &(0x7f0000000140)='\x00') bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000600)={0xb, 0x3, &(0x7f0000000180)=ANY=[], &(0x7f0000000480)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000340)={0xe, 0x4, &(0x7f0000000400)=ANY=[@ANYBLOB="18020000801000000000000004000000850000000e00000095"], &(0x7f0000000000)='syzkaller\x00', 0x1, 0x0, 0x0, 0x40f00, 0x0, '\x00', 0x0, 0x25, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) ioctl$TUNSETOFFLOAD(0xffffffffffffffff, 0x400454d0, 0x2) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000380)={&(0x7f0000000080)=ANY=[@ANYBLOB="9feb010018000000000000001c0000001c00000003000000010000000000000e0200000000000000000000000000000404000000002e"], 0x0, 0x37, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x20) openat$cgroup_ro(0xffffffffffffff9c, &(0x7f0000000100)='memory.current\x00', 0x275a, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000080)={0x1d, 0x0, 0x0, &(0x7f0000000000)='GPL\x00', 0x4, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) ioctl$TUNSETIFF(0xffffffffffffffff, 0x400454ca, &(0x7f0000000080)={'wlan0\x00', 0x200}) socketpair(0x1, 0x1, 0x0, &(0x7f0000000200)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$PERF_EVENT_IOC_SET_FILTER(r0, 0x8946, &(0x7f0000000080)) 2.245998471s ago: executing program 3 (id=555): r0 = openat$tun(0xffffffffffffff9c, &(0x7f00000000c0), 0x0, 0x0) ioctl$TUNSETIFF(r0, 0x400454ca, &(0x7f0000000040)={'syzkaller0\x00', 0x4801}) r1 = openat$tun(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) close(r1) socketpair$unix(0x1, 0x5, 0x0, &(0x7f00000002c0)) ioctl$SIOCSIFHWADDR(r1, 0x8914, &(0x7f0000002280)={'syzkaller0\x00', @multicast}) r2 = openat$tun(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) close(r2) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000000)) ioctl$SIOCSIFHWADDR(r2, 0x8943, &(0x7f0000002280)={'syzkaller0\x00', @random="0100"}) r3 = openat$tun(0xffffffffffffff9c, &(0x7f0000000080), 0x0, 0x0) close(r3) bpf$BPF_PROG_WITH_BTFID_LOAD(0x5, &(0x7f0000000400)=@bpf_lsm={0x6, 0x5, &(0x7f0000000000)=ANY=[], &(0x7f0000000580)='syzkaller\x00', 0x4, 0xd2, &(0x7f00000002c0)=""/210, 0x0, 0x8, '\x00', 0x0, 0x1b, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) socketpair$unix(0x1, 0x5, 0x0, &(0x7f00000029c0)={0xffffffffffffffff, 0xffffffffffffffff}) close(r5) r6 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0x5, &(0x7f0000000180)=ANY=[@ANYBLOB="180800000000000000000000000000001800000000000000000000000000000095"], &(0x7f0000000980)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x19, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r7 = perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0xf1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1a089, 0x6, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x2, 0x0, @perf_bp={0x0}, 0x2019, 0x0, 0x0, 0x8, 0x1000, 0x0, 0x7, 0x0, 0x0, 0x0, 0x8}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x3) ioctl$PERF_EVENT_IOC_SET_BPF(r7, 0x40042408, r6) recvmsg$unix(r4, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x0, &(0x7f00000003c0)=[@rights={{0x14, 0x1, 0x1, [0xffffffffffffffff]}}], 0x18}, 0x0) write$cgroup_subtree(r8, &(0x7f0000000300)=ANY=[@ANYBLOB="8fedcb7910009875f37538e486dd6317ce8102032b00fe08000e40000200875a65969ff57b00ff0200000000000000000001ffaaaaaa"], 0xfdef) 2.195627851s ago: executing program 2 (id=556): openat$tun(0xffffffffffffff9c, 0x0, 0x280000, 0x0) mkdirat$cgroup_root(0xffffffffffffff9c, 0x0, 0x1ff) openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0x31) sendmsg$sock(0xffffffffffffffff, 0x0, 0x4000) r0 = bpf$PROG_LOAD(0x5, &(0x7f0000caefb8)={0x8, 0x3, &(0x7f0000000100)=ANY=[@ANYBLOB="850000006100000054000000000000009500000000000000b4a8b1541206000000e9c79077fa15ba36eca61299de54cf77c9062c30bc068829afff36b31fa7e358e95cfa"], &(0x7f0000281ffc)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @cgroup_skb, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x48) bpf$BPF_PROG_TEST_RUN(0x1c, &(0x7f0000000180)={r0, 0x2000000, 0x8, 0x0, &(0x7f00000000c0)="13435cb8b9f6ff00", 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) perf_event_open(&(0x7f00000003c0)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4d31, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x9, 0x2, @perf_config_ext={0x5d, 0x200}, 0xf242, 0x2, 0x0, 0x0, 0x0, 0xfffffffe}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0xa) r1 = bpf$ITER_CREATE(0xb, &(0x7f0000000100), 0x0) close(r1) write$cgroup_int(r1, &(0x7f00000000c0)=0x9, 0x12) r2 = perf_event_open(&(0x7f0000000580)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x210e, 0x8000, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x30, 0x2, @perf_config_ext={0x407fff, 0xaea}, 0x14905, 0x32, 0xfffffbff, 0x3, 0x2, 0x0, 0xfffa, 0x0, 0x0, 0x0, 0x2008}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r3 = socket$kcm(0xa, 0x5, 0x0) sendmsg$kcm(r3, &(0x7f00000017c0)={&(0x7f0000000040)=@l2tp6={0xa, 0x0, 0x7, @dev={0xfe, 0x80, '\x00', 0x3e}, 0xa, 0x2}, 0x80, &(0x7f00000003c0)=[{&(0x7f00000004c0)="7f", 0x1}], 0x1, &(0x7f0000000600)=ANY=[@ANYBLOB="180000000000000084000000070000007ffffffff5000000b8"], 0xd0}, 0x480c4) ioctl$TUNATTACHFILTER(0xffffffffffffffff, 0x401054d5, &(0x7f0000000040)={0x4, &(0x7f0000000000)=[{0x4d, 0x0, 0x3}, {0x35}, {0x0, 0x0, 0x4}, {0x6}]}) r4 = bpf$MAP_CREATE_CONST_STR(0x0, &(0x7f0000000280)=ANY=[@ANYBLOB="0200000004000000080000000100000080"], 0x48) bpf$BPF_MAP_CONST_STR_FREEZE(0x16, &(0x7f0000000480)={r4}, 0x4) r5 = bpf$PROG_LOAD(0x5, &(0x7f00000004c0)={0x11, 0x18, &(0x7f00000001c0)=ANY=[@ANYBLOB="18000000000000000000000000000000b7080000000000007b8af8ff00000000b7080000000000007b8af0ff00000000bfa100000000000007010000f8ffffffbfa400000000000007040000f0ffffffb70200000000000018230000", @ANYRES32=r4, @ANYBLOB="0000000000000000b70500000000000085000000a5000000180100002020640500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000a50000000800000095"], &(0x7f0000000600)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x1f, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000180)={&(0x7f0000000000)='percpu_alloc_percpu\x00', r5}, 0x10) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000080)={0x1e, 0x6, &(0x7f00000002c0)=@framed={{0x18, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4}, [@map_fd={0x18, 0xf}, @call={0x85, 0x0, 0x0, 0x8c}]}, &(0x7f0000000100)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x24, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) sendmsg$kcm(r3, 0x0, 0x0) socket$kcm(0x1e, 0x5, 0x0) r6 = socket$kcm(0x10, 0x400000002, 0x0) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, &(0x7f0000000100)=[{&(0x7f0000000040)}], 0x1}, 0x0) socketpair$nbd(0x1, 0x1, 0x0, &(0x7f0000000180)={0xffffffffffffffff, 0xffffffffffffffff}) ioctl$SIOCSIFHWADDR(r7, 0x89ff, &(0x7f0000000900)={'wg1\x00', @random="0600002000"}) socketpair$unix(0x1, 0xd, 0x0, &(0x7f0000000140)) write$cgroup_subtree(r6, &(0x7f0000000040)=ANY=[], 0xfe33) ioctl$PERF_EVENT_IOC_SET_BPF(r2, 0x40042408, 0xffffffffffffffff) 792.649878ms ago: executing program 1 (id=557): perf_event_open(&(0x7f00000000c0)={0x0, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffffffffffc, 0x16023, 0x1, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext, 0xa24, 0x0, 0x1000, 0x0, 0x0, 0x0, 0x4}, 0x0, 0x0, 0xffffffffffffffff, 0x0) perf_event_open(&(0x7f0000000000)={0x3, 0x80, 0x0, 0x0, 0x0, 0xfd, 0x0, 0xb0, 0x25108, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x8, 0x0, @perf_bp={0x0, 0x2}, 0x102, 0xffffffffffbfffff, 0x2, 0x0, 0x400da4f, 0x2000a, 0x0, 0x0, 0xfffffff8}, 0x0, 0x4, 0xffffffffffffffff, 0x0) perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14125, 0x2e, 0xfffffbff, 0x3, 0x3, 0x0, 0x6, 0x0, 0x0, 0x0, 0x3}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0xf, 0x18002, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xe, 0x0, @perf_config_ext={0x1, 0x5}, 0x10580, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4}, 0x0, 0xaffffff7ffffffff, 0xffffffffffffffff, 0x0) perf_event_open(&(0x7f0000000200)={0x2, 0x80, 0x3d, 0x1, 0x0, 0x0, 0x0, 0x5, 0x62000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x0, @perf_bp={0x0, 0xd}, 0x100000, 0x0, 0x0, 0x6, 0x3, 0x0, 0x4}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x2) bpf$ENABLE_STATS(0x20, 0x0, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000440)={0xf, 0x9, &(0x7f0000000680)=ANY=[@ANYBLOB="180800000000000000000000000000008510000005000000850000000f0000005f000000000000001800"/54], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) 723.901782ms ago: executing program 4 (id=558): bpf$PROG_LOAD(0x5, &(0x7f0000000680)={0x0, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f00000001c0)={&(0x7f0000000080)='kfree\x00'}, 0x10) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000940)={0x0, 0x0, &(0x7f00000001c0)=[{&(0x7f0000000000)="d8000000210081044e81f7d28344b904020000", 0x2}], 0x1}, 0x0) perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x4, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) perf_event_open(0x0, 0x0, 0xaffffff7ffffffff, 0xffffffffffffffff, 0x1) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000800)={&(0x7f0000000780)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0x0, 0x0, 0x3}, {0x0, [0x1e]}}, &(0x7f00000007c0)=""/11, 0x1b, 0xb, 0x0, 0x0, 0x0, @void, @value}, 0x28) r0 = bpf$MAP_CREATE(0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="0b000000000100000811000009000000"], 0x50) sendmsg$kcm(0xffffffffffffffff, &(0x7f0000000200)={0x0, 0x0, &(0x7f00000006c0)=[{0x0}, {&(0x7f0000001540)}], 0x2}, 0x4004840) socket$kcm(0x11, 0x200000000000002, 0x300) bpf$MAP_UPDATE_BATCH(0x1a, &(0x7f0000000640)={0x0, 0x0, &(0x7f0000000000), 0x0, 0xb, r0}, 0x38) bpf$MAP_LOOKUP_BATCH(0x18, 0x0, 0x0) r1 = socket$kcm(0x2, 0x3, 0x2) sendmsg$inet(r1, &(0x7f0000000100)={&(0x7f00000004c0)={0x2, 0x0, @broadcast}, 0x10, 0x0, 0x0, &(0x7f0000003a00)=[@ip_pktinfo={{0x1c, 0x0, 0x8, {0x0, @dev={0xac, 0x14, 0x14, 0x2a}, @multicast1}}}], 0x20}, 0x4008804) bpf$BPF_BTF_GET_FD_BY_ID(0x13, &(0x7f0000000000), 0x4) perf_event_open(&(0x7f0000000240)={0x5, 0x80, 0x0, 0x0, 0x9, 0x0, 0x0, 0x8020, 0x40, 0x4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, 0x1, 0x0, 0x0, 0x2, @perf_config_ext={0x4a, 0x13}, 0x3386, 0x400000006, 0x800, 0x0, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0x4}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) perf_event_open(0x0, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) socketpair$tipc(0x1e, 0x5, 0x0, &(0x7f0000000340)) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000003c0)={0x0, 0x6, &(0x7f0000000080)=ANY=[@ANYBLOB="18080000000000000000000000000000851000001800000000000000", @ANYRES32], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f00000003c0)={0x3, 0x0, 0x0, &(0x7f0000000080)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x23, '\x00', 0x0, 0x0, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0xffff7fff, @void, @value}, 0x94) r2 = socket$kcm(0x10, 0x400000002, 0x0) write$cgroup_subtree(r2, &(0x7f0000000080)=ANY=[@ANYBLOB="33fe0000240013"], 0xfe33) 686.638808ms ago: executing program 2 (id=559): bpf$PROG_LOAD(0x5, &(0x7f0000000580)={0x1a, 0x4, &(0x7f0000000b80)=ANY=[@ANYBLOB="b40000000000000061119400000000000600000000000000000000000000000098e294193d156252c25ef327a2ff93cc2ae4ec77e01d6c654b6f7cb046c26ef15e5e980b4393369c6c0afb0ea4ede839e550a220d02f786744bc7d17fcc59dd1e654894a1872ad4f1f6d6767be63a5c5b9ffaf941d83313060c85dac5f31c2bcb9f682cd042764a4eb3a7fff88a7d870cdbd8039a4bfef90b3cb5ad3a06f3dc1b5471d029256e0804eb73fce54df3bf7fc4856b6f7ccaac3cbac2d2e51c2ea3a2a63724f71eaae1ffb411853ff4aaf1c070c7d724020f3bc2006160431e65eece775988a5468474f0100000001000000d4d361ba9a99e675430e4bbb02f5a7d9a8780784c9beac8b8ffe3e726f07c00b1d953ee5383b06b924b5483cc1b77dd5692ea9aa89f40ba095256eca"], &(0x7f0000000080)='GPL\x00', 0x4, 0xc3, &(0x7f000000cf3d)=""/195, 0x0, 0x0, '\x00', 0x0, @fallback=0x12, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$PROG_LOAD(0x5, &(0x7f00000054c0)={0x3, 0x16, &(0x7f0000000f40)=ANY=[@ANYBLOB="61122f76880c040061134c0000deffffff1b004007000000080000002d0301"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @sched_cls, 0xffffffffffffffff, 0x8, 0x0, 0x0, 0x10, 0x0, 0x0, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) openat$tun(0xffffffffffffff9c, &(0x7f0000000080), 0x280000, 0x0) r0 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x40000, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x408001}, 0x114905, 0x4, 0xfffffbff, 0x3, 0x82, 0x0, 0x0, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x3) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b703000000000000850000000700000095"], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r2 = socket$kcm(0xa, 0x3, 0x3a) sendmsg$kcm(r2, &(0x7f00000031c0)={&(0x7f00000006c0)=@l2tp6={0xa, 0x0, 0x0, @mcast1}, 0x80, 0x0, 0x0, &(0x7f0000000d80)}, 0x0) ioctl$PERF_EVENT_IOC_SET_BPF(r0, 0x40042408, r1) perf_event_open(&(0x7f0000001200)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x2}, 0x0, 0x7fffffff, 0xfffffffd, 0x0, 0x2, 0x0, 0x0, 0x0, 0x0, 0x0, 0x3}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) r3 = socket$kcm(0x10, 0x2, 0x4) sendmsg$inet(r3, &(0x7f0000003540)={0x0, 0x0, &(0x7f0000000000)=[{&(0x7f0000000100)}], 0x1, 0x0, 0x0, 0x1f00c00e}, 0x0) perf_event_open(&(0x7f0000000000)={0x2, 0x80, 0x0, 0x0, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x1, @perf_config_ext={0x3, 0x900000000}, 0x5081, 0x0, 0x0, 0x0, 0x0, 0x44000002, 0x3, 0x0, 0x6}, 0xffffffffffffffff, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) r4 = socket$kcm(0xa, 0x2, 0x0) setsockopt$sock_attach_bpf(r4, 0x29, 0x23, &(0x7f00000002c0), 0xfffffffffffffe50) r5 = socket$kcm(0xa, 0x2, 0x0) sendmsg$kcm(r5, &(0x7f00000003c0)={&(0x7f0000000040)=@un=@file={0x0, './file0\x00'}, 0x80, 0x0}, 0x0) setsockopt$sock_attach_bpf(r5, 0x1, 0x32, &(0x7f0000000080)=r1, 0x4) bpf$MAP_CREATE(0x0, 0x0, 0x48) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, 0x0, 0x0, 0x0, 0x0, 0x0, 0x41100, 0x6, '\x00', 0x0, @fallback=0x34, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xffffffff, @void, @value}, 0x94) r6 = bpf$PROG_LOAD(0x5, &(0x7f00000007c0)={0x5, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x21, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffe, @void, @value}, 0x94) r7 = bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000140)={&(0x7f0000000040)=ANY=[@ANYBLOB="9feb01001800000000000000180000001800000004000000020000000100000c02000000000000000000000d0000000000005f"], 0x0, 0x34, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x20) bpf$BPF_PROG_RAW_TRACEPOINT_LOAD(0x5, &(0x7f0000000200)={0x11, 0x3, &(0x7f0000000100)=ANY=[@ANYBLOB="1800000000000000000000000000000095000000fcbbd784"], &(0x7f0000000000)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, r7, 0x8, &(0x7f00000000c0)={0x0, 0x1}, 0x1, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000180)={r6, 0x2000000, 0xe, 0x0, &(0x7f0000000300)="860000800000004753b89a20ef0b", 0x0, 0x5, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x50) sendmsg(0xffffffffffffffff, 0x0, 0x11) setsockopt$sock_attach_bpf(0xffffffffffffffff, 0x84, 0x75, 0x0, 0x0) socket$kcm(0x11, 0xa, 0x300) socketpair$tipc(0x1e, 0x2, 0x0, &(0x7f0000000200)={0xffffffffffffffff}) sendmsg$tipc(r8, &(0x7f0000003a00)={&(0x7f0000000080)=@id={0x1e, 0x3, 0x2, {0x4e22, 0x3}}, 0x10, &(0x7f0000000b40)=[{0x0}, {0x0}, {0x0}, {&(0x7f0000001a00)}], 0x4, 0x0, 0x0, 0x4040000}, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x3, 0x10, &(0x7f00000009c0)=ANY=[@ANYBLOB="18080000000000120000b3b50600000000000000e576749d4cc56ff788d57a715b237ed41086e9dc8b6c1ee1cc67cebcfaa3000000000000000000004d58b8942eb5e3a69e5b6ff97b601482dd972cd3c01b0200c70cecdbb5b0db045193070b008142f0b6806a01ffd7325d5dc99b38cddf44db5ba9c8eaba1e98d0d83303e9452a093bbc4b172f65e93d5e224d010011eea91e9cf0bbe770ae3296a0", @ANYRES32, @ANYBLOB="0000000000000000b7030000ffffffc0850000000c000000b707000000000000180100002020702500000000002020207b1af8ff00000000bfa100000000000007010000f8ffffffb702000008000000b70300000000000085000000060000009500000000000000"], &(0x7f0000000980)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @sched_cls, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) 513.330949ms ago: executing program 3 (id=560): bpf$MAP_CREATE(0x0, &(0x7f0000000000)=ANY=[@ANYBLOB="0a0000000100000044000000200000", @ANYRES32], 0x50) r0 = openat$cgroup_ro(0xffffffffffffff9c, 0x0, 0x26e1, 0x0) close(r0) r1 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14125, 0x2e, 0xfffffbff, 0x3, 0x3, 0x0, 0x6, 0x0, 0x0, 0x0, 0x3}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r2 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB], &(0x7f00000000c0)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) ioctl$PERF_EVENT_IOC_SET_BPF(r1, 0x40042408, r2) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0xf, 0x8000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xe, 0x0, @perf_bp={0x0, 0x8}, 0x1400, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4}, 0x0, 0xaffffff7ffffffff, 0xffffffffffffffff, 0x0) bpf$MAP_UPDATE_BATCH(0x1a, 0x0, 0x0) write$cgroup_subtree(0xffffffffffffffff, &(0x7f0000000140)=ANY=[@ANYBLOB="0bf60000"], 0xfe33) ioctl$SIOCSIFHWADDR(r0, 0x8b29, &(0x7f0000000000)={'wlan1\x00', @random="010000000700"}) r3 = socket$kcm(0x10, 0x2, 0x0) sendmsg$inet(r3, &(0x7f0000000080)={0x0, 0x9, &(0x7f0000000100)=[{&(0x7f00000001c0)="5c00000026006bab9a3fe3d86e17aa31106b876c1d0000007ea60864160af36504001a0038001d004231a0e69ee517d34460bc06000000a705251e6182949a3651f60a84c9f4d4938037e70e4509c5bb5b64f69853362ac3407173ec", 0x5c}], 0x1, 0x0, 0x0, 0x1f00c00e}, 0x0) r4 = bpf$PROG_LOAD(0x5, 0x0, 0x0) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000600)={r4, 0x0, 0x0, 0x0, 0x0, 0x0, 0x500, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x9}, 0x50) recvmsg(r3, &(0x7f0000000000)={0x0, 0x0, &(0x7f0000001140)=[{&(0x7f0000001ac0)=""/4081, 0xff1}], 0x1}, 0x0) r5 = bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000140)={&(0x7f0000000040)={{0xeb9f, 0x1, 0x0, 0x18, 0x0, 0xc, 0xc, 0x2, [@ptr]}}, 0x0, 0x26, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x20) bpf$PROG_LOAD_XDP(0x5, &(0x7f0000000a00)={0x6, 0xd, &(0x7f0000000bc0)=@framed={{}, [@exit, @exit, @cb_func={0x18, 0x0, 0x4, 0x0, 0xffffffffffffffff}, @map_fd, @map_idx, @cb_func={0x18, 0x0, 0x4, 0x0, 0xfffffffffffffff8}]}, &(0x7f0000000740)='GPL\x00', 0x6, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, 0x25, r5, 0x8, 0x0, 0x0, 0x2, &(0x7f0000000940), 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x90) bpf$MAP_CREATE_TAIL_CALL(0x0, &(0x7f0000000740)={0x3, 0x4, 0x4, 0xa, 0x0, 0x0, 0x0, '\x00', 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x50) perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r6 = socket$kcm(0x10, 0x3, 0x10) sendmsg$kcm(r6, &(0x7f0000000000)={0x0, 0xd18c9b25, &(0x7f0000000080)=[{&(0x7f0000000040)="e03f030033000b35d25a806c8c6f94f90424fc60040207000a000200053582c137153e37000c0980fc0b10000300", 0x33fe0}], 0x1}, 0x0) 324.910925ms ago: executing program 4 (id=561): r0 = bpf$PROG_LOAD(0x5, &(0x7f0000000180)={0xe, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800"/20, @ANYRES32=0x0, @ANYBLOB="0000000000000000b7080000002000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b704000000000000850000000f00000095"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r1 = bpf$MAP_CREATE(0x0, &(0x7f00000000c0)=@base={0x1b, 0x0, 0x0, 0x8000, 0x0, 0xffffffffffffffff, 0x0, '\x00', 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, @void, @value, @void, @value}, 0x48) bpf$TOKEN_CREATE(0x24, 0x0, 0x0) bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x0, 0xc, &(0x7f0000000440)=ANY=[@ANYBLOB="1800000000000000000000000000000018110000", @ANYRES32=r1, @ANYBLOB="0000000000000000b7080000000000007b8af8ff00000000bfa200000000000007020000f8ffffffb703000008000000b7040000020000008500000082"], 0x0, 0x3, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x37, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, r0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) r2 = bpf$PROG_LOAD(0x5, &(0x7f00000000c0)={0x11, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000300)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x32, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, &(0x7f0000000000)={&(0x7f0000000080)='sched_switch\x00', r2}, 0x10) bpf$PROG_LOAD(0x5, &(0x7f00000005c0)={0x18, 0xc, &(0x7f0000000440)=ANY=[], &(0x7f0000000240)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x90) bpf$MAP_CREATE(0x2000000000000000, 0x0, 0x0) bpf$BPF_RAW_TRACEPOINT_OPEN(0x11, 0x0, 0x0) perf_event_open(&(0x7f00000002c0)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x200, 0x20, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0}}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) mkdirat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000)='./cgroup/syz0\x00', 0x1ff) openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) socketpair(0xa, 0x1, 0x0, 0x0) socketpair$unix(0x1, 0x5, 0x0, &(0x7f0000000480)={0xffffffffffffffff, 0xffffffffffffffff}) mkdir(&(0x7f0000000280)='./file0\x00', 0x1) sendmsg$inet(r3, &(0x7f0000001780)={0x0, 0x0, 0x0}, 0x4000840) r4 = openat$tun(0xffffffffffffff9c, &(0x7f0000000340), 0xc0000, 0x0) ioctl$TUNSETQUEUE(r4, 0x400454d9, &(0x7f0000000380)={'ip6erspan0\x00', 0x25c}) bpf$BPF_BTF_LOAD(0x12, &(0x7f0000000040)={0x0, &(0x7f00000000c0)=""/76, 0xbe, 0x4c, 0x0, 0x1ff, 0x10000, @value}, 0x28) 268.342149ms ago: executing program 1 (id=562): r0 = getpid() r1 = perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x1, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, r0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r2 = bpf$PROG_LOAD(0x5, &(0x7f0000000400)={0x5, 0xb, &(0x7f0000000180)=ANY=[@ANYBLOB="18080000000000000000000000000000180100002020702500000000002020207b1af8ff00000000bfa1000000000000070100"], 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) ioctl$PERF_EVENT_IOC_SET_BPF(r1, 0x40042408, r2) socketpair$unix(0x1, 0x1, 0x0, &(0x7f00000000c0)) socketpair$unix(0x1, 0x1, 0x0, 0x0) socketpair$tipc(0x1e, 0x2, 0x0, 0x0) ioctl$PERF_EVENT_IOC_PERIOD(0xffffffffffffffff, 0x4020940d, 0x0) perf_event_open(&(0x7f0000000180)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0xb, 0x8000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x8}, 0x1400, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x4}, 0x0, 0xaffffff7ffffffff, 0xffffffffffffffff, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) r3 = bpf$PROG_LOAD(0x5, &(0x7f0000000200)={0xc, 0xe, &(0x7f0000002e00)=ANY=[@ANYBLOB="b702000003000000bfa30000000000000703000000feffff7a0af0fff8ffffff79a4f0ff00000000b7060000ffffffff2d6405000000000065040400010000000404000001007d60b7030000000000006a0a00fe00000000850000000d000000b7000000000008009500f10100000000487591731cba12c07d57d995b61e89a4530f92344f242b416ae9eeefc0e9c6f203cb1276bfdbb4ddffffff7f82dc2b938189a7ca02f732e4c2eab72bf40c0682fd0a0c4ac106b29e220dc2880072599456d4c4e6f3fe684ab8373bb4df9d72876ef3834293812e927c01c7da1322da44c7f2ed1084a12f56d1cb39df9858037458a4ca037604007600b6be484e4c9517af216bd8ed42f7dd01008e49f4a94608c9a20819e02fc22e6be45574d4ed88b37ab8d7674c644dca2f1b4d745fd95c41f9dfc1adafd1e5a3e7f2e898961cb43e438c4e41ae43ea118e14ffffffffe4b8a80366ce5401ec61921a1b529cc8b99bffffb1ac006c67767b03b95151aeb89e6d4a43c625aa228504e4afd8c1cc3eb215ba22f43115f4d39dc7beedb130d9f2be90133a4500000058b8c9370634060105baa664953514605fba3973aa021945b985a8a66e0200000057033815717b4fdbe55b37cb8d7f41aacfbd4089ea1bd22440f64909a09b5a759a703e71f358e11ac8e13db15d792e604a4f279b3bd6621bdf2c17bc0400001000000000ff8d81006200607a9a76e5d9656a7154c75773902a1bdf399df3925130312d095e9c1f973d091c198c1a11edb6b3cc425fe203d2f2655a76865c2c34e2470fcfb1248c0add5431a7fbcb0ef4f66a09af93a09fab1daae4b518d7a5d95a017864010067d6bab101446ebfe3fdeed7ee7bb0749cacf56cf27409c60fca2e0004000000000000a9cb6f4a78444986f9b1ab61f9dab53038010000004abbfc59d6d1b18fe380df4bf024f120bd755d82033f2fb7d8fc9e0de834f7646c8dd27da1297d0c77b294e097e293db7f002c0024ab2fb4d32972cba6f49051cec1ff5d16231bbb90a2d201a500000000000000007700b06fa191ebd3a0c2ef0058ffebd7cc4cf80f74a7cdac01d998c24f34a5ba9a4a2039d0416e3f8107671141ffffffe0c7d8e94a27a06a4e3d9acee835fd0571e5bbb3e6d2b5eba505000000968983811f832dc5390f83e817c602c4f1f0d0504255c22ee8674053d0e160e5255366139bbe5863e23c3dd42d21f542816edf56a93d0a7e6f08f9ffffff64875fea6ff57ba6ae25c5e8ca4f78d5a01308243b08f1caa46be5244d64f8e875857f083144c642f71cdc8e5634c1360c056430fe77ee7ed7ac1f9743786b2fb8e0fcfcc3d36c93230b7b1da97c971c8c84a427edc3492b97e73d2060acfd8145e4a5851bc4d6fdc5ad939d7795f3879baa88bd194d48e50c84892c97c800d156b059a718f6b10274b077a710f27ab8ee953de70ea860b74a0f3c3dc11177b11cc2e62a95f1ecf607a8dc38e525f415a1bd46b38845ebca04061bacbf627f7975fe599678fee48f83b5989543729e3600000000bc86cd51704f309130f534741377ea7b7bea3c46c0c4c4b7c27c5d057d95ac85a41cdcee8e6fa31f7d2137ed1fb4b21c13b9a2c5e3f7c9ef9e45a35adbf0b9312be929863f000000000000004a82bc080de1f87808d0711dd76f2977ca7f2684bfa5c14a0cd6f1f561e34e4e8e51e81d4a355a7d00d917c16a2bb0cfb2b5f59dfead7ac6e7fa84746e2e425769b9ee2c8ff10e934847604d930f62924d0562ce17f6dadf5053ed8f33092a41bb46e1878c5295fecc27f9c6d1f62da58c0002ea00000000009aa38a05e70591d5cdab1c488ef3c1984c7c0a566cfc2a080000009ec206a54fb49056a555414178ef00d8b8f3c59f01eb5d83415994efcc6ec4b3c275cd6b1b5ff82ef7d7abb1d218e7a1d0afa285706841aac9ccc89df41c39dd58dd70569dde45f8adeaad7d3328fbb6e279f745d2872f0208635e465ca443c3a64c7803760880af23fb3f430a0311fffc96dd13b951642f1433f65b4e170a62a5f7b7d0f9d5cef0d17289c43d4aee0001f7a343899434594cc23e1c864164e130754b337e560f285dc670a31241bf657babf0615b85dc200a10294b7d5885b43ac62fc7f97a85586168483427072a535f2c7481ec261c00f725de74e48d9a86f7d4a5d28da3f099ca3e6472b9d7c86d961f525f799b4517141f018af0673b8296f867eca1ec07be11bc497a6f7d2b752bcf77c2908b64630e7fa0c2261bc2d5de32ab6bbcf296d36807544aa7c3d3301fe227b713a371414c98695e559f9cbf6b046184064a5f24a4cc6f41f21fc24a3ad7d20a89e00a9dc99a40f890869d35fba3ce6f297661d3f8ba21c65badf55d1859581f9e7ef3e2693b46a8fc85be061ce79a08002c04dc04de8b6536123b24be2ef80eb06b2db900fb30596c1574b2a31f81d61ccfd58080d2330b9c7b87b5d17d48c32daffead3414b91603e250eeedc7d601000000037426f643797be3e93da96b5643d3feed0b7c885d06006b830d7cbf3152f27522f5142dcc84a9e48a07518f0142167abf5d6685d09945cbc778bcc3e7dcfaee5d9c1689a3bafc0d3b51b5a3bfd6007954c36d532960964183842601e5364ecb6ad9168040388c7640bfa2f88643de7eebf4da8d1c3e76daace5217761d933d06bbe9609fcf5971aa1e77c3123910e63daaadd8878ad468eabaf78a96012a4ada1a9cd217fb2a0da2d521454ea9e8fcd3b5badfd6f00003a73345b841d04a02bf441955b932c59608a555bc44873272812e0fb874618a0b56b4cf44990f60000000000000000000000b20000da0ca6797590ed13b0bccf71a39e05e877893646d185a77882f866785af6b0149e336c31fb177e3e85f4c60cd4de4ce6ea73a95f434328620fa493937386ad2e2a0d60eb815aa05c33e02c32276dab36d14c63af66a31409ab2a403ec3c7a4e07bd745efa2835a8c932f22aa6da40af9bcdf808b916bc8deb37d5b8c422b65c42d17e61751c561ce775a31b52703d398d52694cfbb7d2b3791b030093b321d9f16b2f06676cf94d75cbba6491ae0b5a16ce92320321314d8d2e88d1cd7e7b1216bdaecba309a38e107103e649d46958cc6ba2d660dd41b78d832beb7206ae01508377273ea96e40760410aeed1866971e04f578e9d856d01000000045aea928f5f669be0636dc3f34f90c34531735f271527412d1ae755a9243da523d713071f9370b509a34eeb46415b2f0d271a7072cbd17e293f20132e6c15756e92776c6a0d7c3a9f512ce17edf3f1ea190853bbf93e220a6ce968b79d504c057000e7d8f8249a8158e68a90bbea8bfab2bd3c067c28e185fe62ce7020f5282cf045b9c790984c6fb65fd3187bd8bfcbe663df6b7770000f58fbad41e6eee5c9595950c4172b9c925403b2f99bbf3cb1981bb0d14bded8eae35e08278020a1ec7f508628056fd3d408a02a1cf8594bcbb21a88f477673442804f714212d000045b9f563b5352fe460a30489b1b6a6d37daead86151492f7fd4b5c64007b68a1b04027eac124478a2ef7f59fe472795785de83578cb96334e0f7c1370dc397d3aa42d937b5718b7610cdcdfe104db7801ec74980b8b111a2748321f81512e4204eb2b024b9fc9e0f257f8c6037b93b2caa236d4354b32434d5a6b01e00000000ee2ea723ea2e1accb97a200609c77e0000000000000000d3a54ccd6e13a966801e9341260d6cbce5fe03999214462cbaa297448677ab659102d0f430fbeae119a7ef2e962d2829d4dd2201c4b30d491269594c88252fbd09aced90609851bd9e5c307e7e0d39e73579c1f3563eff1a6237d3699d61acdc8e36010d76093ddd237df1c4181b0a0c4543b4249e9ff2f5e8b5e0ba2048d542de40f643fda4036124b8feb2dd45d0fa52300518c8052cc09ad73f89734fce82cc627356aa2c651ed2644f34cfbc32e8b29cf29e895e43b473ddb9a43421b4b25f8bbce8e2d7cb8547d156d5972021ae4c9e30f85413276ddebde55999d2ec3c524632b74d703147ba09e0dcb26c4b89636d28428b67e955f53bfd0c9eeb7a9d17000000000096cd8ecf1c511eea07aefa1c5cae1841efa9329d80eafefe00000000000000009111274a44c722ff9f5151aa7cb99ea3e8b2c51eadbd2d0ba1a25b08cc3e67cd186c12ea62a55ff905388bb30d1a63d42593c9aea3a84f5a6fc470d8aaaafeccb373ca26c3685679e6a048af19fca3fc5315a3"], &(0x7f0000000340)='syzkaller\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x8, &(0x7f0000000000), 0x8, 0x10, &(0x7f0000000000), 0x10, 0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94) bpf$BPF_PROG_TEST_RUN(0xa, &(0x7f0000000080)={r3, 0x18000000000002a0, 0xe28, 0xfffffffffffffff5, &(0x7f0000000980)="b0ff04c66b0d698cb89e2fe086dd1f74ffff06000000fe80000000000000ac14140746647b7954c4c06b580febc28eb143d0f6c0bad62c67a04402ba4125c7024f63fdb0b6c8ee826b4dfe6042a2f057c66cad677d850ea9928bcfcb47e585e427746ed3b27c40060cbd030a6d675c9926af53cd3085b24f9b7a486775c4f284f8c5a572ca115bce90c0ee9d4e7a07f5f1518092cb1f156694036f6618a59196631e6303fd5307d1112601d3641c9492f7dc3503416836b14590c53b1fc1ac149b70cc1142d6bc57fc3a76839fa2f96878b520fedfb9f64d81584a2e85ab4f6ec718b02d78f2ebf04e6b3b94610a21616181629a03c3dc0bf05e0a71f887833b81db7a10bc53259cb80716f6804934a411d424c1db98d454be1adb2776fdbb92b299d3b80af6987a871b4549fdb4c8297ee31ad925c8b0fb1a9d2589b08ed52602cbc26b56df71201bc4ea8621c56f33d251c1d4589af2dcd78fbb4e34bde02cb3920a30cee9489ee72c3e19304c16c2110e1839712d484b80abe77786a7e2ba834874a4e16b93dd07297554a06c2ad2c906f8ebb1db8730df096709184728d48f0a806696bd0d4b12d0064b933d9675353dae77fe8419451f85da63be78b70ca2a84a77f572d9f289d4313e6f6039fe756ac13a5d08838315dff44cda433cc7bc6b77449f8c", 0x0, 0x2f, 0xe8034000, 0xf000, 0xfffffffffffffe2a, &(0x7f0000000000), &(0x7f00000000c0)="c6769e45b7c61302926682c7f9e9bb5ba2b3cdf023e8da0392a4cd62e2370f25ae5ba0dab896bcf5b774cd28bebbde39f796ae27d04582bb7c03e9fe830ea22c9fd03f6d2779515fdad3f5d0de07b7b70996102fdb67b1e77a34a5b7136a212fa2c0ea502588309dc3e42c55a6f93e6ba5e1b492f9db48f0fdd2f9fb937b3e8a63dcf9dd855837433998ba579da27559", 0x5dc}, 0x28) 69.972521ms ago: executing program 1 (id=563): setsockopt$sock_attach_bpf(0xffffffffffffffff, 0x29, 0x2a, 0x0, 0x0) mkdirat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000)='./cgroup/syz0\x00', 0x1ff) r0 = openat$cgroup_root(0xffffffffffffff9c, &(0x7f0000000000), 0x200002, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) openat$cgroup_type(r0, 0x0, 0x2, 0x0) r1 = openat$cgroup_procs(r0, &(0x7f00000002c0)='cgroup.threads\x00', 0x2, 0x0) write$cgroup_pid(r1, &(0x7f0000000c40), 0x12) r2 = openat$cgroup_ro(r0, 0x0, 0x275a, 0x0) write$cgroup_int(r2, &(0x7f0000000200)=0x1, 0x12) write$cgroup_pid(r2, &(0x7f0000000340), 0x12) 0s ago: executing program 1 (id=564): r0 = perf_event_open(0x0, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r1 = bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback=0x16, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) ioctl$PERF_EVENT_IOC_SET_BPF(r0, 0x40042408, r1) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d31, 0x208, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_bp={0x0, 0x2}, 0x0, 0x0, 0x0, 0x7, 0x0, 0x4}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x0) bpf$PROG_LOAD_XDP(0x5, 0x0, 0x0) perf_event_open(&(0x7f0000000500)={0x2, 0x80, 0x56, 0x1, 0x0, 0x0, 0x0, 0x7fef, 0x82, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x107b7b, 0x1, @perf_config_ext={0x407fff, 0xaea}, 0x14105, 0x2e, 0xfffffbff, 0x3, 0x2, 0x0, 0x6, 0x0, 0x0, 0x0, 0xa9e6}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x9) r2 = socket$kcm(0x2, 0x922000000001, 0x106) perf_event_open(&(0x7f0000000040)={0x2, 0x80, 0xf0, 0x0, 0x0, 0x0, 0x0, 0xb, 0x1509, 0x3, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0xfffffffd, 0x1, @perf_bp={0x0, 0xe}, 0x0, 0x4, 0x4000, 0x5, 0x67}, 0x0, 0x0, 0xffffffffffffffff, 0x0) bpf$PROG_LOAD(0x5, &(0x7f0000000880)={0x5, 0x5, &(0x7f00000005c0)=ANY=[@ANYBLOB="1808000000000000000000000000000018000000e5020000000000000000000095"], &(0x7f0000000980)='GPL\x00', 0x0, 0x0, 0x0, 0x0, 0x0, '\x00', 0x0, @fallback, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @void, @value}, 0x94) socket$kcm(0x10, 0x2, 0x10) r3 = socket$kcm(0x10, 0x3, 0x10) sendmsg$kcm(r3, &(0x7f0000000080)={0x0, 0x0, &(0x7f0000000000)=[{&(0x7f0000000540)="1400000024000b47564cb6288200eb141fb220cf", 0x14}], 0x1}, 0x0) write$cgroup_subtree(0xffffffffffffffff, 0x0, 0x4) setsockopt$sock_attach_bpf(r2, 0x1, 0x19, 0x0, 0x0) bpf$PROG_LOAD(0x5, 0x0, 0x0) bpf$BPF_TASK_FD_QUERY(0x14, &(0x7f0000000040)={0x0, 0xffffffffffffffff, 0x0, 0x0, 0x0}, 0x30) r4 = bpf$OBJ_GET_MAP(0x7, &(0x7f0000000180), 0x10) r5 = socket$kcm(0x10, 0x2, 0x10) perf_event_open(&(0x7f0000000480)={0x1, 0x80, 0x0, 0x0, 0x0, 0x0, 0x0, 0x5d34, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, @perf_config_ext, 0x10, 0x0, 0x0, 0x0, 0x0, 0x0, 0x80}, 0x0, 0xffffffffffffffff, 0xffffffffffffffff, 0x8) r6 = socket$kcm(0x10, 0x3, 0x0) write$cgroup_subtree(r6, &(0x7f0000000000)=ANY=[@ANYBLOB='$\x00\x00\x00-\x00Y'], 0xfe33) socketpair$unix(0x1, 0x2, 0x0, 0x0) setsockopt$sock_attach_bpf(0xffffffffffffffff, 0x1, 0x4c, 0x0, 0x0) bpf$BPF_MAP_LOOKUP_AND_DELETE_ELEM(0x15, &(0x7f0000000100)={r4, &(0x7f0000000300)="da869ae61106817a900b8768eef5cf898281ee5ba5f63f6f433895fd5a5b31569bb8521777df4badbdcb40d252ff8b9eecdb3d5e67e22cb3770f2b69dc8c6c3ccaed062a9011ea9b03adb4cab1175d38be1ab6cf0292b8f8e085b5866642f12bcf6510c3402c206099e00bd414dd2ea7ab7688c34e770a2ec7bc271e9a21075639c4f6eafeba0c6317b405be81f9141b88bf1f5178b07a62945b21cf5fb45bc919841d4ca7991a5f25d3fd5d997d76f5882364b65e06e0249e904e4a6379f8cebef2e3f64f89a40694db87b941054f3ca836bb8369d368508cf30d72507f98444d1c5286ad51d627299cf3f52d5a6e832492d8f5a3e2a0bb2822fdac4ec251", &(0x7f00000000c0)=""/30}, 0x20) r7 = bpf$MAP_CREATE(0x0, &(0x7f0000000400)=ANY=[@ANYBLOB="12000000040000000400000012"], 0x48) bpf$BPF_PROG_QUERY(0x10, &(0x7f00000002c0)={@map=r7, 0x4, 0x0, 0x9, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, 0x40) sendmsg$kcm(r5, 0x0, 0x0) kernel console output (not intermixed with test programs): Warning: Permanently added '10.128.1.112' (ED25519) to the list of known hosts. [ 81.353774][ T5819] cgroup: Unknown subsys name 'net' [ 81.492509][ T5819] cgroup: Unknown subsys name 'cpuset' [ 81.501480][ T5819] cgroup: Unknown subsys name 'rlimit' Setting up swapspace version 1, size = 127995904 bytes [ 83.150164][ T5819] Adding 124996k swap on ./swap-file. Priority:0 extents:1 across:124996k [ 85.794941][ T5834] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 85.817032][ T5846] Bluetooth: hci2: unexpected cc 0x0c03 length: 249 > 1 [ 85.825155][ T5846] Bluetooth: hci3: unexpected cc 0x0c03 length: 249 > 1 [ 85.833297][ T5846] Bluetooth: hci4: unexpected cc 0x0c03 length: 249 > 1 [ 85.840592][ T5840] Bluetooth: hci1: unexpected cc 0x0c03 length: 249 > 1 [ 85.850088][ T5840] Bluetooth: hci3: unexpected cc 0x1003 length: 249 > 9 [ 85.857539][ T5840] Bluetooth: hci1: unexpected cc 0x1003 length: 249 > 9 [ 85.859342][ T5848] Bluetooth: hci4: unexpected cc 0x1003 length: 249 > 9 [ 85.866343][ T5840] Bluetooth: hci1: unexpected cc 0x1001 length: 249 > 9 [ 85.878958][ T5846] Bluetooth: hci4: unexpected cc 0x1001 length: 249 > 9 [ 85.879930][ T5840] Bluetooth: hci2: unexpected cc 0x1003 length: 249 > 9 [ 85.886210][ T5848] Bluetooth: hci3: unexpected cc 0x1001 length: 249 > 9 [ 85.908114][ T5846] Bluetooth: hci2: unexpected cc 0x1001 length: 249 > 9 [ 85.931643][ T5847] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 85.940523][ T5847] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 85.947651][ T5848] Bluetooth: hci4: unexpected cc 0x0c23 length: 249 > 4 [ 85.955916][ T5846] Bluetooth: hci3: unexpected cc 0x0c23 length: 249 > 4 [ 85.964374][ T5846] Bluetooth: hci4: unexpected cc 0x0c38 length: 249 > 2 [ 85.972290][ T5846] Bluetooth: hci3: unexpected cc 0x0c38 length: 249 > 2 [ 85.972773][ T5850] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 85.988697][ T5850] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 85.996850][ T5850] Bluetooth: hci1: unexpected cc 0x0c23 length: 249 > 4 [ 86.006655][ T5850] Bluetooth: hci1: unexpected cc 0x0c38 length: 249 > 2 [ 86.016441][ T5840] Bluetooth: hci2: unexpected cc 0x0c23 length: 249 > 4 [ 86.027714][ T5840] Bluetooth: hci2: unexpected cc 0x0c38 length: 249 > 2 [ 86.624953][ T5837] chnl_net:caif_netlink_parms(): no params data found [ 86.785798][ T5832] chnl_net:caif_netlink_parms(): no params data found [ 86.812741][ T5836] chnl_net:caif_netlink_parms(): no params data found [ 87.030839][ T5833] chnl_net:caif_netlink_parms(): no params data found [ 87.221345][ T5829] chnl_net:caif_netlink_parms(): no params data found [ 87.233737][ T5837] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.242070][ T5837] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.249838][ T5837] bridge_slave_0: entered allmulticast mode [ 87.258020][ T5837] bridge_slave_0: entered promiscuous mode [ 87.320299][ T5837] bridge0: port 2(bridge_slave_1) entered blocking state [ 87.327696][ T5837] bridge0: port 2(bridge_slave_1) entered disabled state [ 87.336479][ T5837] bridge_slave_1: entered allmulticast mode [ 87.343909][ T5837] bridge_slave_1: entered promiscuous mode [ 87.371745][ T5832] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.379037][ T5832] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.386403][ T5832] bridge_slave_0: entered allmulticast mode [ 87.394811][ T5832] bridge_slave_0: entered promiscuous mode [ 87.424956][ T5836] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.432379][ T5836] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.439679][ T5836] bridge_slave_0: entered allmulticast mode [ 87.446949][ T5836] bridge_slave_0: entered promiscuous mode [ 87.474548][ T5832] bridge0: port 2(bridge_slave_1) entered blocking state [ 87.482327][ T5832] bridge0: port 2(bridge_slave_1) entered disabled state [ 87.489814][ T5832] bridge_slave_1: entered allmulticast mode [ 87.497092][ T5832] bridge_slave_1: entered promiscuous mode [ 87.533046][ T5836] bridge0: port 2(bridge_slave_1) entered blocking state [ 87.540382][ T5836] bridge0: port 2(bridge_slave_1) entered disabled state [ 87.547553][ T5836] bridge_slave_1: entered allmulticast mode [ 87.555220][ T5836] bridge_slave_1: entered promiscuous mode [ 87.613480][ T5832] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 87.645980][ T5837] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 87.671562][ T5832] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 87.706223][ T5836] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 87.719727][ T5837] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 87.764750][ T5836] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 87.816319][ T5833] bridge0: port 1(bridge_slave_0) entered blocking state [ 87.824007][ T5833] bridge0: port 1(bridge_slave_0) entered disabled state [ 87.832180][ T5833] bridge_slave_0: entered allmulticast mode [ 87.839861][ T5833] bridge_slave_0: entered promiscuous mode [ 87.847809][ T5833] bridge0: port 2(bridge_slave_1) entered blocking state [ 87.859475][ T5833] bridge0: port 2(bridge_slave_1) entered disabled state [ 87.866653][ T5833] bridge_slave_1: entered allmulticast mode [ 87.874840][ T5833] bridge_slave_1: entered promiscuous mode [ 87.884921][ T5832] team0: Port device team_slave_0 added [ 87.922533][ T5837] team0: Port device team_slave_0 added [ 87.933247][ T5837] team0: Port device team_slave_1 added [ 87.954656][ T5832] team0: Port device team_slave_1 added [ 87.992194][ T5836] team0: Port device team_slave_0 added [ 88.039156][ T5832] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.046155][ T5832] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.072211][ T5832] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.084857][ T5829] bridge0: port 1(bridge_slave_0) entered blocking state [ 88.092433][ T5829] bridge0: port 1(bridge_slave_0) entered disabled state [ 88.092754][ T5839] Bluetooth: hci1: command tx timeout [ 88.099755][ T5850] Bluetooth: hci4: command tx timeout [ 88.100052][ T5850] Bluetooth: hci3: command tx timeout [ 88.105667][ T5840] Bluetooth: hci2: command tx timeout [ 88.111056][ T56] Bluetooth: hci0: command tx timeout [ 88.117659][ T5829] bridge_slave_0: entered allmulticast mode [ 88.134777][ T5829] bridge_slave_0: entered promiscuous mode [ 88.145305][ T5836] team0: Port device team_slave_1 added [ 88.167365][ T5833] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 88.178286][ T5832] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.185311][ T5832] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.211540][ T5832] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.222806][ T5829] bridge0: port 2(bridge_slave_1) entered blocking state [ 88.230402][ T5829] bridge0: port 2(bridge_slave_1) entered disabled state [ 88.237615][ T5829] bridge_slave_1: entered allmulticast mode [ 88.245225][ T5829] bridge_slave_1: entered promiscuous mode [ 88.266793][ T5837] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.273954][ T5837] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.300106][ T5837] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.314248][ T5833] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 88.386206][ T5837] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.393565][ T5837] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.419776][ T5837] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.457215][ T5833] team0: Port device team_slave_0 added [ 88.466491][ T5833] team0: Port device team_slave_1 added [ 88.485363][ T5836] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.492642][ T5836] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.519283][ T5836] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.532216][ T5836] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.539246][ T5836] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.565177][ T5836] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.612735][ T5829] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 88.625639][ T5829] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 88.669584][ T5832] hsr_slave_0: entered promiscuous mode [ 88.676223][ T5832] hsr_slave_1: entered promiscuous mode [ 88.742069][ T5837] hsr_slave_0: entered promiscuous mode [ 88.749991][ T5837] hsr_slave_1: entered promiscuous mode [ 88.756348][ T5837] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 88.764180][ T5837] Cannot create hsr debugfs directory [ 88.787152][ T5833] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 88.794343][ T5833] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.821781][ T5833] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 88.837011][ T5829] team0: Port device team_slave_0 added [ 88.875809][ T5833] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 88.883089][ T5833] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 88.909593][ T5833] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 88.928462][ T5829] team0: Port device team_slave_1 added [ 88.953672][ T5836] hsr_slave_0: entered promiscuous mode [ 88.960373][ T5836] hsr_slave_1: entered promiscuous mode [ 88.966770][ T5836] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 88.974654][ T5836] Cannot create hsr debugfs directory [ 89.140419][ T5833] hsr_slave_0: entered promiscuous mode [ 89.146877][ T5833] hsr_slave_1: entered promiscuous mode [ 89.153641][ T5833] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 89.161988][ T5833] Cannot create hsr debugfs directory [ 89.171726][ T5829] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 89.179119][ T5829] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 89.208053][ T5829] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 89.225291][ T5829] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 89.232586][ T5829] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 89.258923][ T5829] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 89.532641][ T5829] hsr_slave_0: entered promiscuous mode [ 89.539405][ T5829] hsr_slave_1: entered promiscuous mode [ 89.545630][ T5829] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 89.553383][ T5829] Cannot create hsr debugfs directory [ 89.774078][ T5832] netdevsim netdevsim4 netdevsim0: renamed from eth0 [ 89.810914][ T5832] netdevsim netdevsim4 netdevsim1: renamed from eth1 [ 89.841426][ T5832] netdevsim netdevsim4 netdevsim2: renamed from eth2 [ 89.867058][ T5832] netdevsim netdevsim4 netdevsim3: renamed from eth3 [ 89.960798][ T5837] netdevsim netdevsim1 netdevsim0: renamed from eth0 [ 89.998049][ T5837] netdevsim netdevsim1 netdevsim1: renamed from eth1 [ 90.024653][ T5837] netdevsim netdevsim1 netdevsim2: renamed from eth2 [ 90.036976][ T5837] netdevsim netdevsim1 netdevsim3: renamed from eth3 [ 90.126114][ T5833] netdevsim netdevsim2 netdevsim0: renamed from eth0 [ 90.141587][ T5833] netdevsim netdevsim2 netdevsim1: renamed from eth1 [ 90.153396][ T5833] netdevsim netdevsim2 netdevsim2: renamed from eth2 [ 90.168275][ T5141] Bluetooth: hci0: command tx timeout [ 90.173761][ T5141] Bluetooth: hci2: command tx timeout [ 90.179432][ T56] Bluetooth: hci3: command tx timeout [ 90.184899][ T5850] Bluetooth: hci1: command tx timeout [ 90.184921][ T5840] Bluetooth: hci4: command tx timeout [ 90.203419][ T5833] netdevsim netdevsim2 netdevsim3: renamed from eth3 [ 90.326863][ T5836] netdevsim netdevsim3 netdevsim0: renamed from eth0 [ 90.357399][ T5836] netdevsim netdevsim3 netdevsim1: renamed from eth1 [ 90.381048][ T5836] netdevsim netdevsim3 netdevsim2: renamed from eth2 [ 90.420475][ T5836] netdevsim netdevsim3 netdevsim3: renamed from eth3 [ 90.481840][ T5832] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.526345][ T5829] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 90.542713][ T5829] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 90.574371][ T5829] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 90.584610][ T5829] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 90.602206][ T5832] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.634636][ T5837] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.665800][ T1158] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.673142][ T1158] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.717499][ T1158] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.724680][ T1158] bridge0: port 2(bridge_slave_1) entered forwarding state [ 90.747392][ T5833] 8021q: adding VLAN 0 to HW filter on device bond0 [ 90.770384][ T5837] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.789856][ T1158] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.797043][ T1158] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.832190][ T1158] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.839362][ T1158] bridge0: port 2(bridge_slave_1) entered forwarding state [ 90.872391][ T5833] 8021q: adding VLAN 0 to HW filter on device team0 [ 90.917728][ T194] bridge0: port 1(bridge_slave_0) entered blocking state [ 90.924907][ T194] bridge0: port 1(bridge_slave_0) entered forwarding state [ 90.969204][ T194] bridge0: port 2(bridge_slave_1) entered blocking state [ 90.976334][ T194] bridge0: port 2(bridge_slave_1) entered forwarding state [ 91.074600][ T5836] 8021q: adding VLAN 0 to HW filter on device bond0 [ 91.164795][ T5836] 8021q: adding VLAN 0 to HW filter on device team0 [ 91.220322][ T5829] 8021q: adding VLAN 0 to HW filter on device bond0 [ 91.232327][ T63] bridge0: port 1(bridge_slave_0) entered blocking state [ 91.240548][ T63] bridge0: port 1(bridge_slave_0) entered forwarding state [ 91.293241][ T63] bridge0: port 2(bridge_slave_1) entered blocking state [ 91.300554][ T63] bridge0: port 2(bridge_slave_1) entered forwarding state [ 91.361359][ T5829] 8021q: adding VLAN 0 to HW filter on device team0 [ 91.404965][ T63] bridge0: port 1(bridge_slave_0) entered blocking state [ 91.412219][ T63] bridge0: port 1(bridge_slave_0) entered forwarding state [ 91.472602][ T63] bridge0: port 2(bridge_slave_1) entered blocking state [ 91.479860][ T63] bridge0: port 2(bridge_slave_1) entered forwarding state [ 91.711258][ T5837] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.743615][ T5832] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.834243][ T5833] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 91.941501][ T1868] cfg80211: failed to load regulatory.db [ 92.114855][ T5837] veth0_vlan: entered promiscuous mode [ 92.134935][ T5836] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 92.167483][ T5837] veth1_vlan: entered promiscuous mode [ 92.193013][ T5833] veth0_vlan: entered promiscuous mode [ 92.225874][ T5833] veth1_vlan: entered promiscuous mode [ 92.251753][ T5840] Bluetooth: hci4: command tx timeout [ 92.257331][ T5840] Bluetooth: hci1: command tx timeout [ 92.263285][ T5839] Bluetooth: hci2: command tx timeout [ 92.263699][ T5850] Bluetooth: hci3: command tx timeout [ 92.270799][ T5839] Bluetooth: hci0: command tx timeout [ 92.325835][ T5829] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 92.425533][ T5836] veth0_vlan: entered promiscuous mode [ 92.444625][ T5833] veth0_macvtap: entered promiscuous mode [ 92.466351][ T5833] veth1_macvtap: entered promiscuous mode [ 92.476160][ T5837] veth0_macvtap: entered promiscuous mode [ 92.485396][ T5836] veth1_vlan: entered promiscuous mode [ 92.523265][ T5837] veth1_macvtap: entered promiscuous mode [ 92.547521][ T5832] veth0_vlan: entered promiscuous mode [ 92.563016][ T5833] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 92.590657][ T5837] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 92.601659][ T5837] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 92.613834][ T5837] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 92.624689][ T5832] veth1_vlan: entered promiscuous mode [ 92.647230][ T5837] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 92.656324][ T5833] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 92.667887][ T5833] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 92.680831][ T5833] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 92.702869][ T5829] veth0_vlan: entered promiscuous mode [ 92.724943][ T5836] veth0_macvtap: entered promiscuous mode [ 92.737728][ T5837] netdevsim netdevsim1 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.749972][ T5837] netdevsim netdevsim1 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.760080][ T5837] netdevsim netdevsim1 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.769181][ T5837] netdevsim netdevsim1 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.783206][ T5833] netdevsim netdevsim2 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.793623][ T5833] netdevsim netdevsim2 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.802613][ T5833] netdevsim netdevsim2 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.813364][ T5833] netdevsim netdevsim2 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 92.826326][ T5836] veth1_macvtap: entered promiscuous mode [ 92.846105][ T5829] veth1_vlan: entered promiscuous mode [ 92.905693][ T5832] veth0_macvtap: entered promiscuous mode [ 92.943444][ T5836] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 92.956914][ T5836] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 92.971066][ T5836] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 92.983561][ T5836] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 92.994930][ T5836] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 93.010912][ T5836] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.022017][ T5836] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.032083][ T5836] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.044557][ T5836] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.055999][ T5836] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 93.096323][ T5832] veth1_macvtap: entered promiscuous mode [ 93.136226][ T5836] netdevsim netdevsim3 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.145581][ T5836] netdevsim netdevsim3 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.154698][ T5836] netdevsim netdevsim3 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.163482][ T5836] netdevsim netdevsim3 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.174786][ T5829] veth0_macvtap: entered promiscuous mode [ 93.199140][ T1111] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.209772][ T1111] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.235670][ T5829] veth1_macvtap: entered promiscuous mode [ 93.277969][ T1111] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.285851][ T1111] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.317443][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.329428][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.339826][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.350650][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.360701][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.373203][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.386072][ T5832] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 93.403436][ T1143] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.416553][ T1143] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.433858][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.446860][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.458163][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.468676][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.478897][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.489534][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.499495][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 93.510133][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.522060][ T5829] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 93.537398][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.549643][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.559994][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.571108][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.581441][ T5829] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.592345][ T5829] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.604388][ T5829] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 93.627231][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.643544][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.654930][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.665949][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.681050][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.684764][ T5837] soft_limit_in_bytes is deprecated and will be removed. Please report your usecase to linux-mm@kvack.org if you depend on this functionality. [ 93.707332][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.717988][ T5832] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 93.729488][ T5832] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 93.740902][ T5832] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 93.762833][ T12] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.774851][ T12] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 93.786500][ T5832] netdevsim netdevsim4 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.797339][ T5832] netdevsim netdevsim4 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.810473][ T5832] netdevsim netdevsim4 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.828434][ T5832] netdevsim netdevsim4 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.859972][ T5829] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.871209][ T5829] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.882031][ T5829] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.890930][ T5829] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 93.989210][ T13] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 93.997115][ T13] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 94.206293][ T1158] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 94.237987][ T1158] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 94.302623][ T12] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 94.311818][ T12] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 94.328274][ T5839] Bluetooth: hci0: command tx timeout [ 94.334803][ T5840] Bluetooth: hci1: command tx timeout [ 94.334843][ T56] Bluetooth: hci2: command tx timeout [ 94.343005][ T5840] Bluetooth: hci4: command tx timeout [ 94.346810][ T5850] Bluetooth: hci3: command tx timeout [ 94.469966][ T5934] FAULT_INJECTION: forcing a failure. [ 94.469966][ T5934] name fail_usercopy, interval 1, probability 0, space 0, times 1 [ 94.549816][ T1158] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 94.557682][ T1158] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 94.565592][ T5934] CPU: 1 UID: 0 PID: 5934 Comm: syz.2.8 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 94.565620][ T5934] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 94.565638][ T5934] Call Trace: [ 94.565649][ T5934] [ 94.565658][ T5934] dump_stack_lvl+0x189/0x250 [ 94.565697][ T5934] ? __lock_acquire+0xaac/0xd20 [ 94.565728][ T5934] ? __pfx_dump_stack_lvl+0x10/0x10 [ 94.565756][ T5934] ? __pfx__printk+0x10/0x10 [ 94.565776][ T5934] ? __might_fault+0xb0/0x130 [ 94.565815][ T5934] should_fail_ex+0x414/0x560 [ 94.565842][ T5934] _copy_from_user+0x2d/0xb0 [ 94.565871][ T5934] __sys_bpf+0x1ed/0x860 [ 94.565899][ T5934] ? __pfx___sys_bpf+0x10/0x10 [ 94.565937][ T5934] ? ksys_write+0x1f0/0x250 [ 94.565974][ T5934] __x64_sys_bpf+0x7c/0x90 [ 94.565997][ T5934] do_syscall_64+0xf6/0x210 [ 94.566025][ T5934] ? clear_bhb_loop+0x45/0xa0 [ 94.566050][ T5934] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 94.566068][ T5934] RIP: 0033:0x7f002b18e969 [ 94.566091][ T5934] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 94.566108][ T5934] RSP: 002b:00007f002c056038 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 [ 94.566129][ T5934] RAX: ffffffffffffffda RBX: 00007f002b3b5fa0 RCX: 00007f002b18e969 [ 94.566144][ T5934] RDX: 0000000000000023 RSI: 00002000002a0fb8 RDI: 0000000000000005 [ 94.566165][ T5934] RBP: 00007f002c056090 R08: 0000000000000000 R09: 0000000000000000 [ 94.566177][ T5934] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 94.566188][ T5934] R13: 0000000000000001 R14: 00007f002b3b5fa0 R15: 00007fff602e2fc8 [ 94.566218][ T5934] [ 94.755026][ T63] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 94.769632][ C0] hrtimer: interrupt took 28349 ns [ 94.776025][ T63] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 94.906241][ T63] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 94.914841][ T63] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 96.235356][ T5950] netlink: 132 bytes leftover after parsing attributes in process `syz.3.11'. [ 96.829848][ T5957] netlink: 60 bytes leftover after parsing attributes in process `syz.0.1'. [ 97.031570][ T5963] syzkaller0: tun_chr_ioctl cmd 1074025678 [ 97.058091][ T5963] syzkaller0: group set to 0 [ 97.092161][ T5963] netlink: 'syz.4.14': attribute type 2 has an invalid length. [ 97.107535][ T5963] netlink: 'syz.4.14': attribute type 3 has an invalid length. [ 97.218846][ T5963] netlink: 132 bytes leftover after parsing attributes in process `syz.4.14'. [ 97.456005][ T5976] Zero length message leads to an empty skb [ 99.190682][ T5995] netlink: 60 bytes leftover after parsing attributes in process `syz.3.22'. [ 100.455457][ T6006] netlink: 'syz.3.26': attribute type 21 has an invalid length. [ 100.598904][ T6006] netlink: 132 bytes leftover after parsing attributes in process `syz.3.26'. [ 100.614715][ T6006] netlink: 'syz.3.26': attribute type 1 has an invalid length. [ 101.394941][ T6035] netlink: 127868 bytes leftover after parsing attributes in process `syz.2.36'. [ 102.285499][ T6049] FAULT_INJECTION: forcing a failure. [ 102.285499][ T6049] name failslab, interval 1, probability 0, space 0, times 1 [ 102.389239][ T6049] CPU: 1 UID: 0 PID: 6049 Comm: syz.0.41 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 102.389277][ T6049] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 102.389290][ T6049] Call Trace: [ 102.389298][ T6049] [ 102.389307][ T6049] dump_stack_lvl+0x189/0x250 [ 102.389345][ T6049] ? __pfx_dump_stack_lvl+0x10/0x10 [ 102.389375][ T6049] ? __pfx__printk+0x10/0x10 [ 102.389402][ T6049] ? __pfx___might_resched+0x10/0x10 [ 102.389419][ T6049] ? fs_reclaim_acquire+0x7d/0x100 [ 102.389443][ T6049] should_fail_ex+0x414/0x560 [ 102.389472][ T6049] should_failslab+0xa8/0x100 [ 102.389502][ T6049] __kmalloc_noprof+0xcb/0x4f0 [ 102.389527][ T6049] ? kfree+0x4d/0x440 [ 102.389548][ T6049] ? tomoyo_realpath_from_path+0xe3/0x5d0 [ 102.389581][ T6049] tomoyo_realpath_from_path+0xe3/0x5d0 [ 102.389610][ T6049] ? tomoyo_domain+0xda/0x130 [ 102.389642][ T6049] ? tomoyo_path_number_perm+0x1bc/0x5a0 [ 102.389663][ T6049] tomoyo_path_number_perm+0x1e8/0x5a0 [ 102.389693][ T6049] ? __pfx_tomoyo_path_number_perm+0x10/0x10 [ 102.389733][ T6049] ? __lock_acquire+0xaac/0xd20 [ 102.389781][ T6049] ? __fget_files+0x2a/0x420 [ 102.389814][ T6049] ? __fget_files+0x3a0/0x420 [ 102.389840][ T6049] ? __fget_files+0x2a/0x420 [ 102.389873][ T6049] security_file_ioctl+0xcb/0x2d0 [ 102.389907][ T6049] __se_sys_ioctl+0x47/0x170 [ 102.389933][ T6049] do_syscall_64+0xf6/0x210 [ 102.389960][ T6049] ? clear_bhb_loop+0x45/0xa0 [ 102.389986][ T6049] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 102.390005][ T6049] RIP: 0033:0x7fcd08f8e969 [ 102.390023][ T6049] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 102.390040][ T6049] RSP: 002b:00007fcd09d41038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 [ 102.390061][ T6049] RAX: ffffffffffffffda RBX: 00007fcd091b5fa0 RCX: 00007fcd08f8e969 [ 102.390075][ T6049] RDX: 0000000000000000 RSI: 0000000080108907 RDI: 0000000000000004 [ 102.390087][ T6049] RBP: 00007fcd09d41090 R08: 0000000000000000 R09: 0000000000000000 [ 102.390099][ T6049] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 102.390110][ T6049] R13: 0000000000000000 R14: 00007fcd091b5fa0 R15: 00007ffe01aac628 [ 102.390141][ T6049] [ 102.390150][ T6049] ERROR: Out of memory at tomoyo_realpath_from_path. [ 102.957069][ T6062] netlink: 'syz.1.46': attribute type 21 has an invalid length. [ 103.105193][ T6062] netlink: 128 bytes leftover after parsing attributes in process `syz.1.46'. [ 104.388910][ T6087] netlink: 60 bytes leftover after parsing attributes in process `syz.3.52'. [ 104.583082][ T5850] Bluetooth: hci0: unexpected event 0x01 length: 151 > 1 [ 104.716663][ T6102] syz.0.58 uses obsolete (PF_INET,SOCK_PACKET) [ 104.771591][ T6103] netlink: 202920 bytes leftover after parsing attributes in process `syz.0.58'. [ 104.929957][ T6107] netlink: 60 bytes leftover after parsing attributes in process `syz.1.60'. [ 105.122188][ T6112] netlink: 'syz.2.62': attribute type 12 has an invalid length. [ 105.158343][ T6112] netlink: 132 bytes leftover after parsing attributes in process `syz.2.62'. [ 105.501062][ T5850] Bluetooth: hci2: unexpected event 0x01 length: 151 > 1 [ 105.514096][ T6125] netlink: 'syz.3.67': attribute type 2 has an invalid length. [ 105.568059][ T6125] netlink: 'syz.3.67': attribute type 8 has an invalid length. [ 105.594751][ T6125] netlink: 132 bytes leftover after parsing attributes in process `syz.3.67'. [ 105.633219][ T6125] FAULT_INJECTION: forcing a failure. [ 105.633219][ T6125] name failslab, interval 1, probability 0, space 0, times 0 [ 105.655108][ T6125] CPU: 0 UID: 0 PID: 6125 Comm: syz.3.67 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 105.655137][ T6125] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 105.655150][ T6125] Call Trace: [ 105.655159][ T6125] [ 105.655169][ T6125] dump_stack_lvl+0x189/0x250 [ 105.655276][ T6125] ? __pfx_dump_stack_lvl+0x10/0x10 [ 105.655309][ T6125] ? __pfx__printk+0x10/0x10 [ 105.655338][ T6125] ? __pfx___might_resched+0x10/0x10 [ 105.655365][ T6125] should_fail_ex+0x414/0x560 [ 105.655396][ T6125] should_failslab+0xa8/0x100 [ 105.655429][ T6125] kmem_cache_alloc_node_noprof+0x76/0x3c0 [ 105.655460][ T6125] ? __alloc_skb+0x112/0x2d0 [ 105.655491][ T6125] __alloc_skb+0x112/0x2d0 [ 105.655521][ T6125] inet_ifmcaddr_notify+0x7e/0x150 [ 105.655552][ T6125] ____ip_mc_inc_group+0x9b8/0xde0 [ 105.655586][ T6125] __ip_mc_join_group+0x431/0x510 [ 105.655619][ T6125] ip_mc_autojoin_config+0x16a/0x230 [ 105.655653][ T6125] ? __pfx_ip_mc_autojoin_config+0x10/0x10 [ 105.655695][ T6125] inet_rtm_newaddr+0xeec/0x18b0 [ 105.655735][ T6125] ? __pfx_inet_rtm_newaddr+0x10/0x10 [ 105.655783][ T6125] ? __pfx_inet_rtm_newaddr+0x10/0x10 [ 105.655810][ T6125] rtnetlink_rcv_msg+0x7cc/0xb70 [ 105.655837][ T6125] ? rtnetlink_rcv_msg+0x1ab/0xb70 [ 105.655859][ T6125] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 105.655886][ T6125] ? ref_tracker_free+0x63a/0x7d0 [ 105.655906][ T6125] ? __copy_skb_header+0xa7/0x550 [ 105.655945][ T6125] netlink_rcv_skb+0x219/0x490 [ 105.655970][ T6125] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 105.655995][ T6125] ? __pfx_netlink_rcv_skb+0x10/0x10 [ 105.656057][ T6125] ? netlink_deliver_tap+0x2e/0x1b0 [ 105.656080][ T6125] ? netlink_deliver_tap+0x2e/0x1b0 [ 105.656109][ T6125] netlink_unicast+0x758/0x8d0 [ 105.656150][ T6125] netlink_sendmsg+0x805/0xb30 [ 105.656186][ T6125] ? __pfx_netlink_sendmsg+0x10/0x10 [ 105.656213][ T6125] ? aa_sock_msg_perm+0x94/0x160 [ 105.656240][ T6125] ? bpf_lsm_socket_sendmsg+0x9/0x20 [ 105.656267][ T6125] ? __pfx_netlink_sendmsg+0x10/0x10 [ 105.656291][ T6125] __sock_sendmsg+0x219/0x270 [ 105.656316][ T6125] ____sys_sendmsg+0x505/0x830 [ 105.656351][ T6125] ? __pfx_____sys_sendmsg+0x10/0x10 [ 105.656390][ T6125] ? import_iovec+0x74/0xa0 [ 105.656424][ T6125] ___sys_sendmsg+0x21f/0x2a0 [ 105.656459][ T6125] ? __pfx____sys_sendmsg+0x10/0x10 [ 105.656530][ T6125] ? __fget_files+0x2a/0x420 [ 105.656559][ T6125] ? __fget_files+0x3a0/0x420 [ 105.656599][ T6125] __x64_sys_sendmsg+0x19b/0x260 [ 105.656632][ T6125] ? __pfx___x64_sys_sendmsg+0x10/0x10 [ 105.656657][ T6125] ? perf_trace_preemptirq_template+0xa3/0x340 [ 105.656704][ T6125] ? do_syscall_64+0xba/0x210 [ 105.656736][ T6125] do_syscall_64+0xf6/0x210 [ 105.656766][ T6125] ? clear_bhb_loop+0x45/0xa0 [ 105.656792][ T6125] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 105.656813][ T6125] RIP: 0033:0x7f0e1458e969 [ 105.656832][ T6125] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 105.656849][ T6125] RSP: 002b:00007f0e1547c038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 105.656870][ T6125] RAX: ffffffffffffffda RBX: 00007f0e147b5fa0 RCX: 00007f0e1458e969 [ 105.656884][ T6125] RDX: 0000000000000000 RSI: 0000200000000080 RDI: 0000000000000003 [ 105.656895][ T6125] RBP: 00007f0e1547c090 R08: 0000000000000000 R09: 0000000000000000 [ 105.656905][ T6125] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 105.656970][ T6125] R13: 0000000000000000 R14: 00007f0e147b5fa0 R15: 00007fff010d84a8 [ 105.657017][ T6125] [ 106.357395][ T6147] netlink: 60 bytes leftover after parsing attributes in process `syz.0.76'. [ 106.878874][ T6161] netlink: 'syz.2.78': attribute type 21 has an invalid length. [ 106.891730][ T6161] netlink: 132 bytes leftover after parsing attributes in process `syz.2.78'. [ 106.909439][ T6161] netlink: 'syz.2.78': attribute type 1 has an invalid length. [ 107.141392][ T1158] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 107.180131][ T6171] sctp: [Deprecated]: syz.1.83 (pid 6171) Use of struct sctp_assoc_value in delayed_ack socket option. [ 107.180131][ T6171] Use struct sctp_sack_info instead [ 107.233863][ T6174] C: renamed from team_slave_0 (while UP) [ 107.294751][ T6174] netlink: 'syz.1.83': attribute type 3 has an invalid length. [ 107.302700][ T6174] netlink: 152 bytes leftover after parsing attributes in process `syz.1.83'. [ 107.313076][ T6174] A link change request failed with some changes committed already. Interface C may have been left with an inconsistent configuration, please check. [ 107.409710][ T1158] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 107.447245][ T6171] netlink: 'syz.1.83': attribute type 10 has an invalid length. [ 107.603616][ T1158] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 107.945843][ T1158] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 108.276063][ T6185] netlink: 10 bytes leftover after parsing attributes in process `syz.2.89'. [ 108.767417][ T1158] bridge_slave_1: left allmulticast mode [ 108.799317][ T1158] bridge_slave_1: left promiscuous mode [ 108.834705][ T1158] bridge0: port 2(bridge_slave_1) entered disabled state [ 108.903892][ T56] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 108.921785][ T56] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 108.927933][ T1158] bridge_slave_0: left allmulticast mode [ 108.936293][ T56] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 108.941837][ T1158] bridge_slave_0: left promiscuous mode [ 108.952922][ T56] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 108.970032][ T56] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 109.039123][ T1158] bridge0: port 1(bridge_slave_0) entered disabled state [ 110.210954][ T1158] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 110.241155][ T1158] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 110.253234][ T1158] bond0 (unregistering): Released all slaves [ 110.270918][ T6198] netlink: 10 bytes leftover after parsing attributes in process `syz.1.90'. [ 110.712908][ T6230] UDPLite6: UDP-Lite is deprecated and scheduled to be removed in 2025, please contact the netdev mailing list [ 110.755580][ T6233] netlink: 'syz.1.96': attribute type 2 has an invalid length. [ 110.981072][ T6233] netlink: 199836 bytes leftover after parsing attributes in process `syz.1.96'. [ 110.990581][ T6233] nbd: must specify a device to reconfigure [ 111.049339][ T5850] Bluetooth: hci0: command tx timeout [ 111.726546][ T6261] netlink: 65039 bytes leftover after parsing attributes in process `syz.2.104'. [ 112.812112][ T1158] hsr_slave_0: left promiscuous mode [ 112.974459][ T1158] hsr_slave_1: left promiscuous mode [ 113.055960][ T1158] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 113.095941][ T1158] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 113.131911][ T5850] Bluetooth: hci0: command tx timeout [ 113.199753][ T1158] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 113.219564][ T1158] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 113.255672][ T1158] veth1_macvtap: left promiscuous mode [ 113.261626][ T1158] veth0_macvtap: left promiscuous mode [ 113.267543][ T1158] veth1_vlan: left promiscuous mode [ 113.273184][ T1158] veth0_vlan: left promiscuous mode [ 115.147770][ T1158] team0 (unregistering): Port device team_slave_1 removed [ 115.192380][ T1158] team0 (unregistering): Port device team_slave_0 removed [ 115.208353][ T5850] Bluetooth: hci0: command tx timeout [ 115.704313][ T6272] netlink: 10 bytes leftover after parsing attributes in process `syz.2.106'. [ 116.224725][ T6311] netlink: 'syz.2.115': attribute type 29 has an invalid length. [ 116.545795][ T6193] chnl_net:caif_netlink_parms(): no params data found [ 116.939583][ T6330] netlink: 60 bytes leftover after parsing attributes in process `syz.3.119'. [ 117.292386][ T5850] Bluetooth: hci0: command tx timeout [ 117.793337][ T6193] bridge0: port 1(bridge_slave_0) entered blocking state [ 117.804894][ T6193] bridge0: port 1(bridge_slave_0) entered disabled state [ 117.832512][ T6349] netlink: 176 bytes leftover after parsing attributes in process `syz.3.125'. [ 117.875873][ T6193] bridge_slave_0: entered allmulticast mode [ 117.944934][ T6193] bridge_slave_0: entered promiscuous mode [ 118.213675][ T6358] netlink: 'syz.1.126': attribute type 21 has an invalid length. [ 118.278251][ T6358] netlink: 132 bytes leftover after parsing attributes in process `syz.1.126'. [ 118.333360][ T6358] netlink: 'syz.1.126': attribute type 1 has an invalid length. [ 118.375082][ T6193] bridge0: port 2(bridge_slave_1) entered blocking state [ 118.428003][ T6193] bridge0: port 2(bridge_slave_1) entered disabled state [ 118.435431][ T6193] bridge_slave_1: entered allmulticast mode [ 118.483763][ T6193] bridge_slave_1: entered promiscuous mode [ 118.733488][ T6193] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 118.794703][ T6372] syzkaller0: entered promiscuous mode [ 118.808597][ T6372] syzkaller0: entered allmulticast mode [ 118.846954][ T6193] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 119.436127][ T6193] team0: Port device team_slave_0 added [ 119.891034][ T6193] team0: Port device team_slave_1 added [ 120.438772][ T6193] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 120.488451][ T6193] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 120.573940][ T6193] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 120.635327][ T6193] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 120.667932][ T6193] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 120.689873][ T6407] netlink: 'syz.3.138': attribute type 33 has an invalid length. [ 120.703471][ T6407] netlink: 152 bytes leftover after parsing attributes in process `syz.3.138'. [ 120.744725][ T6193] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 121.128786][ T6417] netlink: 'syz.4.140': attribute type 21 has an invalid length. [ 121.390404][ T6417] netlink: 132 bytes leftover after parsing attributes in process `syz.4.140'. [ 121.439240][ T6417] netlink: 'syz.4.140': attribute type 1 has an invalid length. [ 121.544913][ T6193] hsr_slave_0: entered promiscuous mode [ 121.600722][ T6193] hsr_slave_1: entered promiscuous mode [ 121.642908][ T6193] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 121.670109][ T6193] Cannot create hsr debugfs directory [ 121.692680][ T6423] sit0: entered allmulticast mode [ 121.818507][ T6425] sit0: entered promiscuous mode [ 122.635797][ T6439] netlink: 132 bytes leftover after parsing attributes in process `syz.3.144'. [ 123.507483][ T6457] netlink: 'syz.4.149': attribute type 3 has an invalid length. [ 123.584299][ T6457] netlink: 199836 bytes leftover after parsing attributes in process `syz.4.149'. [ 123.873655][ T6471] netlink: 60 bytes leftover after parsing attributes in process `syz.4.151'. [ 124.801662][ T6488] netlink: 'syz.1.155': attribute type 21 has an invalid length. [ 125.674948][ T6488] netlink: 132 bytes leftover after parsing attributes in process `syz.1.155'. [ 125.689151][ T6488] netlink: 'syz.1.155': attribute type 1 has an invalid length. [ 125.716150][ T6495] netlink: 10 bytes leftover after parsing attributes in process `syz.4.157'. [ 125.978764][ T6193] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 126.005391][ T6193] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 126.044256][ T6193] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 126.067712][ T6503] netlink: 'syz.4.160': attribute type 10 has an invalid length. [ 126.069729][ T6193] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 126.094960][ T6503] netlink: 40 bytes leftover after parsing attributes in process `syz.4.160'. [ 126.161014][ T6503] dummy0: entered promiscuous mode [ 126.167027][ T6503] dummy0: entered allmulticast mode [ 126.218862][ T6503] A link change request failed with some changes committed already. Interface dummy0 may have been left with an inconsistent configuration, please check. [ 126.646698][ T6193] 8021q: adding VLAN 0 to HW filter on device bond0 [ 126.744651][ T6193] 8021q: adding VLAN 0 to HW filter on device team0 [ 126.811443][ T12] bridge0: port 1(bridge_slave_0) entered blocking state [ 126.818679][ T12] bridge0: port 1(bridge_slave_0) entered forwarding state [ 126.873456][ T12] bridge0: port 2(bridge_slave_1) entered blocking state [ 126.880745][ T12] bridge0: port 2(bridge_slave_1) entered forwarding state [ 127.582341][ T6538] netlink: 'syz.4.169': attribute type 21 has an invalid length. [ 127.658055][ T6538] netlink: 132 bytes leftover after parsing attributes in process `syz.4.169'. [ 127.698576][ T6538] netlink: 'syz.4.169': attribute type 1 has an invalid length. [ 128.053768][ T6554] netlink: 60 bytes leftover after parsing attributes in process `syz.1.174'. [ 128.216166][ T6193] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 128.278002][ T6561] netlink: 'syz.4.175': attribute type 10 has an invalid length. [ 128.302450][ T6561] netlink: 40 bytes leftover after parsing attributes in process `syz.4.175'. [ 128.391258][ T6561] A link change request failed with some changes committed already. Interface dummy0 may have been left with an inconsistent configuration, please check. [ 128.594666][ T6193] veth0_vlan: entered promiscuous mode [ 128.671138][ T6193] veth1_vlan: entered promiscuous mode [ 128.879128][ T6193] veth0_macvtap: entered promiscuous mode [ 129.162113][ T6575] netlink: 'syz.4.177': attribute type 21 has an invalid length. [ 129.307498][ T6193] veth1_macvtap: entered promiscuous mode [ 129.411266][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 129.467041][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.507023][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 129.556998][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.575842][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 129.589285][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.599672][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 129.628007][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.661670][ T6193] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 129.705431][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 129.797951][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.828672][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 129.886325][ T6597] netlink: 127868 bytes leftover after parsing attributes in process `syz.2.183'. [ 129.896337][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.933094][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 129.944571][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 129.954546][ T6193] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 129.987301][ T6193] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 130.245250][ T6193] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 130.492264][ T6193] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 130.552248][ T6193] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 130.645587][ T6193] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 130.734599][ T6193] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 131.040685][ T6610] netlink: 'syz.4.185': attribute type 21 has an invalid length. [ 131.197080][ T6610] netlink: 132 bytes leftover after parsing attributes in process `syz.4.185'. [ 131.320329][ T6610] netlink: 'syz.4.185': attribute type 1 has an invalid length. [ 132.116830][ T1143] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 132.157228][ T1143] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 132.312996][ T54] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 132.347869][ T54] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 132.566682][ T6643] netlink: 'syz.2.190': attribute type 10 has an invalid length. [ 132.575505][ T6643] netlink: 2 bytes leftover after parsing attributes in process `syz.2.190'. [ 132.672730][ T6643] batadv_slave_1: entered promiscuous mode [ 132.703271][ T6643] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 132.768022][ T6643] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 132.861071][ T6643] bridge0: port 3(batadv_slave_1) entered blocking state [ 132.893309][ T1302] ieee802154 phy0 wpan0: encryption failed: -22 [ 132.900071][ T1302] ieee802154 phy1 wpan1: encryption failed: -22 [ 132.908146][ T6643] bridge0: port 3(batadv_slave_1) entered disabled state [ 132.978104][ T6643] batadv_slave_1: entered allmulticast mode [ 133.029607][ T6643] bridge0: port 3(batadv_slave_1) entered blocking state [ 133.037040][ T6643] bridge0: port 3(batadv_slave_1) entered forwarding state [ 134.412601][ T1143] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 134.863951][ T6672] netlink: 'syz.4.198': attribute type 21 has an invalid length. [ 136.021662][ T1143] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 136.070122][ T56] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 136.085863][ T56] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 136.096837][ T56] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 136.118213][ T56] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 136.128712][ T56] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 136.241016][ T6672] netlink: 132 bytes leftover after parsing attributes in process `syz.4.198'. [ 136.292745][ T6672] netlink: 'syz.4.198': attribute type 1 has an invalid length. [ 136.350588][ T6689] netlink: 2 bytes leftover after parsing attributes in process `syz.2.199'. [ 136.389250][ T6695] netlink: 127868 bytes leftover after parsing attributes in process `syz.3.200'. [ 136.923804][ T1143] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 137.193904][ T1143] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 137.384824][ T6717] netlink: 'syz.2.203': attribute type 10 has an invalid length. [ 137.677141][ T6717] bond0: (slave bond_slave_0): Releasing backup interface [ 138.060880][ T1143] bridge_slave_1: left allmulticast mode [ 138.066747][ T1143] bridge_slave_1: left promiscuous mode [ 138.099018][ T1143] bridge0: port 2(bridge_slave_1) entered disabled state [ 138.198902][ T56] Bluetooth: hci0: command tx timeout [ 138.207782][ T1143] bridge_slave_0: left allmulticast mode [ 138.270856][ T6736] netlink: 127868 bytes leftover after parsing attributes in process `syz.3.209'. [ 138.280244][ T1143] bridge_slave_0: left promiscuous mode [ 138.280493][ T1143] bridge0: port 1(bridge_slave_0) entered disabled state [ 138.488826][ T6739] netlink: 'syz.2.210': attribute type 2 has an invalid length. [ 138.496897][ T6739] netlink: 'syz.2.210': attribute type 1 has an invalid length. [ 138.879278][ T6746] netlink: 'syz.2.212': attribute type 21 has an invalid length. [ 139.925486][ T1143] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 140.003461][ T1143] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 140.020516][ T1143] bond0 (unregistering): Released all slaves [ 140.248319][ T56] Bluetooth: hci0: command tx timeout [ 140.382987][ T6746] netlink: 132 bytes leftover after parsing attributes in process `syz.2.212'. [ 140.408592][ T6746] netlink: 'syz.2.212': attribute type 1 has an invalid length. [ 140.956676][ T6756] netlink: 10 bytes leftover after parsing attributes in process `syz.2.216'. [ 141.191570][ T6763] netlink: 127868 bytes leftover after parsing attributes in process `syz.4.215'. [ 141.612743][ T6687] chnl_net:caif_netlink_parms(): no params data found [ 142.127731][ T6772] netlink: 'syz.1.218': attribute type 39 has an invalid length. [ 142.527958][ T56] Bluetooth: hci0: command tx timeout [ 142.782623][ T6792] FAULT_INJECTION: forcing a failure. [ 142.782623][ T6792] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 142.858099][ T1143] hsr_slave_0: left promiscuous mode [ 142.956000][ T6792] CPU: 0 UID: 0 PID: 6792 Comm: syz.2.224 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 142.956030][ T6792] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 142.956042][ T6792] Call Trace: [ 142.956050][ T6792] [ 142.956061][ T6792] dump_stack_lvl+0x189/0x250 [ 142.956134][ T6792] ? __pfx_dump_stack_lvl+0x10/0x10 [ 142.956164][ T6792] ? __pfx__printk+0x10/0x10 [ 142.956198][ T6792] should_fail_ex+0x414/0x560 [ 142.956226][ T6792] _copy_to_user+0x31/0xb0 [ 142.956258][ T6792] simple_read_from_buffer+0xe1/0x170 [ 142.956289][ T6792] proc_fail_nth_read+0x1df/0x250 [ 142.956324][ T6792] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 142.956357][ T6792] ? rw_verify_area+0x258/0x650 [ 142.956381][ T6792] ? __pfx_proc_fail_nth_read+0x10/0x10 [ 142.956412][ T6792] vfs_read+0x1fd/0x980 [ 142.956442][ T6792] ? __pfx___mutex_lock+0x10/0x10 [ 142.956469][ T6792] ? __pfx_vfs_read+0x10/0x10 [ 142.956495][ T6792] ? __fget_files+0x2a/0x420 [ 142.956534][ T6792] ? __fget_files+0x3a0/0x420 [ 142.956562][ T6792] ? __fget_files+0x2a/0x420 [ 142.956599][ T6792] ksys_read+0x145/0x250 [ 142.956622][ T6792] ? __fget_files+0x2a/0x420 [ 142.956650][ T6792] ? __pfx_ksys_read+0x10/0x10 [ 142.956679][ T6792] ? do_syscall_64+0xba/0x210 [ 142.956710][ T6792] do_syscall_64+0xf6/0x210 [ 142.956737][ T6792] ? clear_bhb_loop+0x45/0xa0 [ 142.956762][ T6792] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 142.956781][ T6792] RIP: 0033:0x7f002b18d37c [ 142.956805][ T6792] Code: ec 28 48 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 99 93 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 34 44 89 c7 48 89 44 24 08 e8 ef 93 02 00 48 [ 142.956822][ T6792] RSP: 002b:00007f002c056030 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [ 142.956847][ T6792] RAX: ffffffffffffffda RBX: 00007f002b3b5fa0 RCX: 00007f002b18d37c [ 142.956861][ T6792] RDX: 000000000000000f RSI: 00007f002c0560a0 RDI: 0000000000000005 [ 142.956873][ T6792] RBP: 00007f002c056090 R08: 0000000000000000 R09: 0000000000000000 [ 142.956885][ T6792] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 142.956896][ T6792] R13: 0000000000000000 R14: 00007f002b3b5fa0 R15: 00007fff602e2fc8 [ 142.956932][ T6792] [ 143.176305][ T1143] hsr_slave_1: left promiscuous mode [ 143.183001][ T1143] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 143.190530][ T1143] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 143.217004][ T1143] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 143.225298][ T1143] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 143.294886][ T1143] veth1_macvtap: left promiscuous mode [ 143.316022][ T1143] veth0_macvtap: left promiscuous mode [ 143.342844][ T1143] veth1_vlan: left promiscuous mode [ 143.355858][ T1143] veth0_vlan: left promiscuous mode [ 143.513280][ T6799] netlink: 'syz.4.226': attribute type 21 has an invalid length. [ 144.570378][ T56] Bluetooth: hci0: command tx timeout [ 144.689978][ T1143] team0 (unregistering): Port device team_slave_1 removed [ 144.725251][ T1143] team0 (unregistering): Port device team_slave_0 removed [ 145.075001][ T6799] netlink: 132 bytes leftover after parsing attributes in process `syz.4.226'. [ 145.087573][ T6799] netlink: 'syz.4.226': attribute type 1 has an invalid length. [ 145.387216][ T6816] netlink: 'syz.2.229': attribute type 1 has an invalid length. [ 145.409827][ T6821] netlink: 127868 bytes leftover after parsing attributes in process `syz.3.230'. [ 145.453356][ T6687] bridge0: port 1(bridge_slave_0) entered blocking state [ 145.496450][ T6687] bridge0: port 1(bridge_slave_0) entered disabled state [ 145.544962][ T6687] bridge_slave_0: entered allmulticast mode [ 145.572775][ T6687] bridge_slave_0: entered promiscuous mode [ 145.638058][ T6687] bridge0: port 2(bridge_slave_1) entered blocking state [ 145.908285][ T6687] bridge0: port 2(bridge_slave_1) entered disabled state [ 145.915620][ T6687] bridge_slave_1: entered allmulticast mode [ 145.932508][ T6687] bridge_slave_1: entered promiscuous mode [ 146.033671][ T6687] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 146.073839][ T6687] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 146.353001][ T6687] team0: Port device team_slave_0 added [ 146.374801][ T6687] team0: Port device team_slave_1 added [ 146.392013][ T6843] netlink: 10 bytes leftover after parsing attributes in process `syz.3.236'. [ 146.585942][ T6845] openvswitch: netlink: Flow key attr not present in new flow. [ 146.708932][ T6687] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 146.737164][ T6687] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 146.822880][ T6687] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 146.872293][ T6687] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 146.887184][ T6687] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 147.031718][ T6687] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 147.143946][ T6861] netlink: 'syz.1.241': attribute type 21 has an invalid length. [ 147.524182][ T6861] netlink: 132 bytes leftover after parsing attributes in process `syz.1.241'. [ 147.581572][ T6861] netlink: 'syz.1.241': attribute type 1 has an invalid length. [ 147.767104][ T6687] hsr_slave_0: entered promiscuous mode [ 147.792527][ T6687] hsr_slave_1: entered promiscuous mode [ 147.802851][ T6687] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 147.813160][ T6687] Cannot create hsr debugfs directory [ 149.559725][ T6886] warning: `syz.3.248' uses wireless extensions which will stop working for Wi-Fi 7 hardware; use nl80211 [ 149.614962][ T6894] A link change request failed with some changes committed already. Interface lo may have been left with an inconsistent configuration, please check. [ 150.520444][ T6918] netlink: 61244 bytes leftover after parsing attributes in process `syz.2.254'. [ 150.893494][ T6923] netlink: 'syz.1.255': attribute type 21 has an invalid length. [ 150.998526][ T6923] netlink: 132 bytes leftover after parsing attributes in process `syz.1.255'. [ 151.038156][ T6923] netlink: 'syz.1.255': attribute type 1 has an invalid length. [ 153.257412][ T6687] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 153.510335][ T6687] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 154.189935][ T6687] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 154.360160][ T6687] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 155.781045][ T6687] 8021q: adding VLAN 0 to HW filter on device bond0 [ 155.949175][ T6687] 8021q: adding VLAN 0 to HW filter on device team0 [ 156.098276][ T7014] netlink: 65039 bytes leftover after parsing attributes in process `syz.1.278'. [ 156.143849][ T54] bridge0: port 1(bridge_slave_0) entered blocking state [ 156.151135][ T54] bridge0: port 1(bridge_slave_0) entered forwarding state [ 156.196460][ T54] bridge0: port 2(bridge_slave_1) entered blocking state [ 156.203744][ T54] bridge0: port 2(bridge_slave_1) entered forwarding state [ 157.164324][ T7035] netlink: 'syz.3.283': attribute type 10 has an invalid length. [ 157.391706][ T7035] bond0: (slave bond_slave_0): Releasing backup interface [ 157.691801][ T6687] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 158.443368][ T6687] veth0_vlan: entered promiscuous mode [ 158.954520][ T6687] veth1_vlan: entered promiscuous mode [ 159.174560][ T6687] veth0_macvtap: entered promiscuous mode [ 159.249514][ T6687] veth1_macvtap: entered promiscuous mode [ 159.296343][ T7080] netlink: 65039 bytes leftover after parsing attributes in process `syz.3.292'. [ 159.369454][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 159.433489][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 159.481278][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 159.523635][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 159.584874][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 159.632860][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 159.670987][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 159.719262][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 159.808075][ T6687] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 159.887185][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 159.986079][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 160.055130][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 160.086559][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 160.137730][ T6687] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 160.161287][ T6687] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 160.189457][ T6687] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 160.491218][ T6687] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 160.630544][ T6687] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 160.649232][ T6687] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 160.659132][ T6687] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 161.345886][ T7109] FAULT_INJECTION: forcing a failure. [ 161.345886][ T7109] name failslab, interval 1, probability 0, space 0, times 0 [ 161.429236][ T7109] CPU: 0 UID: 0 PID: 7109 Comm: syz.1.299 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 161.429267][ T7109] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 161.429279][ T7109] Call Trace: [ 161.429288][ T7109] [ 161.429297][ T7109] dump_stack_lvl+0x189/0x250 [ 161.429335][ T7109] ? __pfx_dump_stack_lvl+0x10/0x10 [ 161.429365][ T7109] ? __pfx__printk+0x10/0x10 [ 161.429389][ T7109] ? __pfx___might_resched+0x10/0x10 [ 161.429408][ T7109] ? fs_reclaim_acquire+0x7d/0x100 [ 161.429432][ T7109] should_fail_ex+0x414/0x560 [ 161.429460][ T7109] should_failslab+0xa8/0x100 [ 161.429498][ T7109] __kmalloc_node_noprof+0xd1/0x4e0 [ 161.429526][ T7109] ? alloc_slab_obj_exts+0x39/0xa0 [ 161.429557][ T7109] alloc_slab_obj_exts+0x39/0xa0 [ 161.429582][ T7109] __memcg_slab_post_alloc_hook+0x332/0x820 [ 161.429624][ T7109] kmem_cache_alloc_noprof+0x2bf/0x3c0 [ 161.429650][ T7109] ? seq_open+0x5f/0x140 [ 161.429676][ T7109] seq_open+0x5f/0x140 [ 161.429707][ T7109] kernfs_fop_open+0x542/0xca0 [ 161.429733][ T7109] ? file_set_fsnotify_mode_from_watchers+0x127/0x660 [ 161.429766][ T7109] ? __pfx_kernfs_fop_open+0x10/0x10 [ 161.429788][ T7109] do_dentry_open+0xdf0/0x1970 [ 161.429839][ T7109] vfs_open+0x3b/0x340 [ 161.429867][ T7109] ? path_openat+0x2ecd/0x3830 [ 161.429892][ T7109] path_openat+0x2ee5/0x3830 [ 161.429911][ T7109] ? arch_stack_walk+0xfc/0x150 [ 161.429976][ T7109] ? __pfx_path_openat+0x10/0x10 [ 161.429995][ T7109] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 161.430038][ T7109] do_filp_open+0x1fa/0x410 [ 161.430064][ T7109] ? __pfx_do_filp_open+0x10/0x10 [ 161.430111][ T7109] ? _raw_spin_unlock+0x28/0x50 [ 161.430131][ T7109] ? alloc_fd+0x64c/0x6c0 [ 161.430170][ T7109] do_sys_openat2+0x121/0x1c0 [ 161.430193][ T7109] ? __pfx_do_sys_openat2+0x10/0x10 [ 161.430210][ T7109] ? perf_trace_preemptirq_template+0xa3/0x340 [ 161.430238][ T7109] ? __pfx_perf_trace_preemptirq_template+0x10/0x10 [ 161.430264][ T7109] ? ksys_write+0x1f0/0x250 [ 161.430287][ T7109] ? rcu_is_watching+0x15/0xb0 [ 161.430325][ T7109] __x64_sys_openat+0x138/0x170 [ 161.430351][ T7109] do_syscall_64+0xf6/0x210 [ 161.430378][ T7109] ? clear_bhb_loop+0x45/0xa0 [ 161.430403][ T7109] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 161.430422][ T7109] RIP: 0033:0x7f8832d8e969 [ 161.430440][ T7109] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 161.430457][ T7109] RSP: 002b:00007f8833bcd038 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 [ 161.430485][ T7109] RAX: ffffffffffffffda RBX: 00007f8832fb5fa0 RCX: 00007f8832d8e969 [ 161.430499][ T7109] RDX: 0000000000000020 RSI: 00002000000001c0 RDI: 0000000000000003 [ 161.430512][ T7109] RBP: 00007f8833bcd090 R08: 0000000000000000 R09: 0000000000000000 [ 161.430524][ T7109] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 161.430536][ T7109] R13: 0000000000000000 R14: 00007f8832fb5fa0 R15: 00007ffc850862d8 [ 161.430568][ T7109] [ 161.910002][ T7111] netlink: 60 bytes leftover after parsing attributes in process `syz.4.298'. [ 161.963780][ T13] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 162.031816][ T13] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 163.130713][ T63] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 163.148584][ T63] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 163.314815][ T7131] netlink: 65039 bytes leftover after parsing attributes in process `syz.3.306'. [ 163.357452][ T7134] netlink: 'syz.2.305': attribute type 21 has an invalid length. [ 163.538810][ T7138] netlink: 'syz.4.307': attribute type 10 has an invalid length. [ 163.709132][ T7138] bond0: (slave bond_slave_0): Releasing backup interface [ 163.773158][ T7137] netlink: 144 bytes leftover after parsing attributes in process `syz.1.304'. [ 164.874198][ T36] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 165.173171][ T36] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 165.254429][ T7169] netlink: 'syz.4.319': attribute type 20 has an invalid length. [ 165.386897][ T36] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 165.460800][ T7170] netlink: 65039 bytes leftover after parsing attributes in process `syz.3.318'. [ 165.895333][ T36] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 166.134244][ T5850] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 166.144327][ T5850] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 166.153274][ T5850] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 166.172503][ T5850] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 166.181536][ T5850] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 166.748437][ T7191] netlink: 'syz.4.323': attribute type 10 has an invalid length. [ 166.948582][ T36] bridge_slave_1: left allmulticast mode [ 166.972957][ T36] bridge_slave_1: left promiscuous mode [ 166.992944][ T36] bridge0: port 2(bridge_slave_1) entered disabled state [ 167.474186][ T36] bridge_slave_0: left allmulticast mode [ 167.512412][ T36] bridge_slave_0: left promiscuous mode [ 167.554110][ T36] bridge0: port 1(bridge_slave_0) entered disabled state [ 168.248144][ T5850] Bluetooth: hci0: command tx timeout [ 169.386447][ T36] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 169.399926][ T36] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 169.410479][ T36] bond0 (unregistering): Released all slaves [ 170.099412][ T7224] netlink: 127868 bytes leftover after parsing attributes in process `syz.4.332'. [ 170.154851][ T7184] chnl_net:caif_netlink_parms(): no params data found [ 170.330534][ T5850] Bluetooth: hci0: command tx timeout [ 171.104157][ T36] hsr_slave_0: left promiscuous mode [ 171.115479][ T36] hsr_slave_1: left promiscuous mode [ 171.149587][ T36] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 171.205272][ T36] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 171.273055][ T36] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 171.320966][ T36] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 171.499110][ T36] veth1_macvtap: left promiscuous mode [ 171.517945][ T36] veth0_macvtap: left promiscuous mode [ 171.523776][ T36] veth1_vlan: left promiscuous mode [ 171.696286][ T36] veth0_vlan: left promiscuous mode [ 172.408572][ T5850] Bluetooth: hci0: command tx timeout [ 172.886920][ T36] team0 (unregistering): Port device team_slave_1 removed [ 172.933106][ T36] team0 (unregistering): Port device team_slave_0 removed [ 173.324175][ T7184] bridge0: port 1(bridge_slave_0) entered blocking state [ 173.332147][ T7184] bridge0: port 1(bridge_slave_0) entered disabled state [ 173.345265][ T7184] bridge_slave_0: entered allmulticast mode [ 173.354991][ T7184] bridge_slave_0: entered promiscuous mode [ 173.372844][ T7184] bridge0: port 2(bridge_slave_1) entered blocking state [ 173.399579][ T7184] bridge0: port 2(bridge_slave_1) entered disabled state [ 173.407071][ T7184] bridge_slave_1: entered allmulticast mode [ 173.433300][ T7184] bridge_slave_1: entered promiscuous mode [ 173.930416][ T7271] netlink: 'syz.1.342': attribute type 10 has an invalid length. [ 174.648151][ T5850] Bluetooth: hci0: command tx timeout [ 175.278799][ T7271] bond0: (slave bond_slave_0): Releasing backup interface [ 175.334591][ T7184] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 175.402263][ T7184] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 176.058062][ T7184] team0: Port device team_slave_0 added [ 176.074755][ T7184] team0: Port device team_slave_1 added [ 177.555753][ T7314] syzkaller0: entered promiscuous mode [ 177.567983][ T7314] syzkaller0: entered allmulticast mode [ 177.598698][ T7184] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 177.630487][ T7184] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 177.706208][ T7184] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 178.134214][ T7336] netlink: 'syz.3.357': attribute type 2 has an invalid length. [ 178.228156][ T7336] netlink: 'syz.3.357': attribute type 1 has an invalid length. [ 178.268871][ T7184] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 178.348024][ T7184] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 178.467874][ T7184] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 178.843557][ T7354] netlink: 'syz.1.360': attribute type 10 has an invalid length. [ 181.804509][ T7184] hsr_slave_0: entered promiscuous mode [ 181.824408][ T7184] hsr_slave_1: entered promiscuous mode [ 181.831564][ T7184] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 181.841911][ T7184] Cannot create hsr debugfs directory [ 182.111717][ T7365] syzkaller0: entered promiscuous mode [ 182.140448][ T7365] syzkaller0: entered allmulticast mode [ 182.354114][ T7377] netlink: 212424 bytes leftover after parsing attributes in process `syz.3.366'. [ 183.540684][ T7397] netlink: 132 bytes leftover after parsing attributes in process `syz.4.369'. [ 183.793123][ T7402] netlink: 212424 bytes leftover after parsing attributes in process `syz.3.372'. [ 184.801675][ T7403] syzkaller0: entered promiscuous mode [ 184.815668][ T7403] syzkaller0: entered allmulticast mode [ 185.510335][ T7438] netlink: 'syz.4.379': attribute type 29 has an invalid length. [ 185.539427][ T7435] netlink: 14 bytes leftover after parsing attributes in process `syz.2.381'. [ 185.564908][ T7435] openvswitch: netlink: Message has 4 unknown bytes. [ 185.845247][ T7440] netlink: 212424 bytes leftover after parsing attributes in process `syz.3.382'. [ 187.158567][ T7184] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 187.266746][ T7184] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 188.009855][ T7184] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 188.591415][ T7184] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 189.318173][ T7484] syzkaller0: entered promiscuous mode [ 189.339481][ T7484] syzkaller0: entered allmulticast mode [ 191.692494][ T7184] 8021q: adding VLAN 0 to HW filter on device bond0 [ 191.930946][ T7510] netlink: 212424 bytes leftover after parsing attributes in process `syz.4.396'. [ 192.129181][ T7184] 8021q: adding VLAN 0 to HW filter on device team0 [ 192.299549][ T54] bridge0: port 1(bridge_slave_0) entered blocking state [ 192.306785][ T54] bridge0: port 1(bridge_slave_0) entered forwarding state [ 192.540526][ T54] bridge0: port 2(bridge_slave_1) entered blocking state [ 192.547872][ T54] bridge0: port 2(bridge_slave_1) entered forwarding state [ 192.891538][ T7530] netlink: 65039 bytes leftover after parsing attributes in process `syz.1.402'. [ 193.640582][ T7184] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 194.207658][ T7184] veth0_vlan: entered promiscuous mode [ 194.303095][ T7184] veth1_vlan: entered promiscuous mode [ 194.429851][ T7184] veth0_macvtap: entered promiscuous mode [ 194.452224][ T7184] veth1_macvtap: entered promiscuous mode [ 194.563045][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 194.581967][ T1302] ieee802154 phy0 wpan0: encryption failed: -22 [ 194.588448][ T1302] ieee802154 phy1 wpan1: encryption failed: -22 [ 194.631945][ T7564] netlink: 'syz.2.409': attribute type 2 has an invalid length. [ 194.666287][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 194.684159][ T7564] netlink: 'syz.2.409': attribute type 1 has an invalid length. [ 194.717108][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 194.771945][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 194.828043][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 194.880226][ T7569] netlink: 212424 bytes leftover after parsing attributes in process `syz.1.410'. [ 194.917951][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 194.981683][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 195.033338][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 195.132416][ T7184] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 195.206588][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 195.248130][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 195.281490][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 195.298301][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 195.337974][ T7184] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 195.360715][ T7184] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 195.435175][ T7184] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 195.518619][ T7578] netlink: 'syz.3.414': attribute type 2 has an invalid length. [ 195.538112][ T7184] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 195.558296][ T7578] netlink: 'syz.3.414': attribute type 1 has an invalid length. [ 195.582238][ T7184] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 195.605134][ T7184] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 195.631001][ T7184] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 195.651650][ T7583] netlink: 65039 bytes leftover after parsing attributes in process `syz.2.416'. [ 195.702496][ T7587] netlink: 156 bytes leftover after parsing attributes in process `syz.4.415'. [ 196.058947][ T7595] netlink: 127868 bytes leftover after parsing attributes in process `syz.2.420'. [ 196.817555][ T1158] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 196.977342][ T1158] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 197.113487][ T194] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 197.140450][ T194] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 198.048885][ T7639] netlink: 'syz.3.428': attribute type 2 has an invalid length. [ 198.093741][ T7639] netlink: 'syz.3.428': attribute type 1 has an invalid length. [ 198.234725][ T7645] netlink: 212424 bytes leftover after parsing attributes in process `syz.1.427'. [ 198.344103][ T7646] netlink: 65039 bytes leftover after parsing attributes in process `syz.2.430'. [ 200.281799][ T5953] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 200.683178][ T5953] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 200.825139][ T5953] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 201.324759][ T5953] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 201.735753][ T7704] netlink: 'syz.1.441': attribute type 2 has an invalid length. [ 201.772162][ T7704] netlink: 'syz.1.441': attribute type 1 has an invalid length. [ 202.136363][ T7712] netlink: 65039 bytes leftover after parsing attributes in process `syz.1.444'. [ 202.656666][ T7713] netlink: 212424 bytes leftover after parsing attributes in process `syz.3.443'. [ 202.736145][ T5953] bridge_slave_1: left allmulticast mode [ 202.736176][ T5953] bridge_slave_1: left promiscuous mode [ 202.736418][ T5953] bridge0: port 2(bridge_slave_1) entered disabled state [ 202.952138][ T56] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 202.953160][ T56] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 202.980685][ T56] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 202.988226][ T56] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 202.989774][ T56] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 203.208679][ T5953] bridge_slave_0: left allmulticast mode [ 203.241318][ T5953] bridge_slave_0: left promiscuous mode [ 203.276291][ T5953] bridge0: port 1(bridge_slave_0) entered disabled state [ 205.047938][ T56] Bluetooth: hci0: command tx timeout [ 206.222450][ T7765] netlink: 'syz.4.454': attribute type 2 has an invalid length. [ 206.267587][ T7765] netlink: 'syz.4.454': attribute type 1 has an invalid length. [ 206.547562][ T5953] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 206.618187][ T5953] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 206.632197][ T5953] bond0 (unregistering): Released all slaves [ 207.153697][ T56] Bluetooth: hci0: command tx timeout [ 207.434023][ T7778] netlink: 65039 bytes leftover after parsing attributes in process `syz.1.457'. [ 208.047444][ T5953] hsr_slave_0: left promiscuous mode [ 208.077706][ T5953] hsr_slave_1: left promiscuous mode [ 208.101973][ T5953] batman_adv: batadv0: Interface deactivated: batadv_slave_0 [ 208.109870][ T5953] batman_adv: batadv0: Removing interface: batadv_slave_0 [ 208.170239][ T5953] batman_adv: batadv0: Interface deactivated: batadv_slave_1 [ 208.208425][ T5953] batman_adv: batadv0: Removing interface: batadv_slave_1 [ 208.373808][ T5953] veth1_macvtap: left promiscuous mode [ 208.409266][ T5953] veth0_macvtap: left promiscuous mode [ 208.415198][ T5953] veth1_vlan: left promiscuous mode [ 208.441994][ T7816] netlink: 'syz.2.466': attribute type 2 has an invalid length. [ 208.468865][ T5953] veth0_vlan: left promiscuous mode [ 208.475438][ T7816] netlink: 'syz.2.466': attribute type 1 has an invalid length. [ 209.234488][ T56] Bluetooth: hci0: command tx timeout [ 209.317374][ T7825] netlink: 212424 bytes leftover after parsing attributes in process `syz.3.469'. [ 210.957063][ T5953] team0 (unregistering): Port device team_slave_1 removed [ 211.000699][ T5953] team0 (unregistering): Port device team_slave_0 removed [ 211.307834][ T5839] Bluetooth: hci0: command tx timeout [ 211.439294][ T7838] netlink: 65039 bytes leftover after parsing attributes in process `syz.4.473'. [ 211.468279][ T7841] netlink: 10 bytes leftover after parsing attributes in process `syz.2.474'. [ 211.562245][ T7724] chnl_net:caif_netlink_parms(): no params data found [ 211.851042][ T5850] Bluetooth: hci3: command 0x0406 tx timeout [ 211.857024][ T5839] Bluetooth: hci1: command 0x0406 tx timeout [ 211.857221][ T5843] Bluetooth: hci4: command 0x0406 tx timeout [ 211.929272][ T56] Bluetooth: hci2: command 0x0406 tx timeout [ 212.055981][ T7850] netlink: 212424 bytes leftover after parsing attributes in process `syz.4.477'. [ 212.076141][ T7861] netlink: 'syz.1.479': attribute type 21 has an invalid length. [ 212.118574][ T7861] netlink: 132 bytes leftover after parsing attributes in process `syz.1.479'. [ 212.127719][ T7861] netlink: 'syz.1.479': attribute type 1 has an invalid length. [ 212.337169][ T7869] netlink: 'syz.2.481': attribute type 2 has an invalid length. [ 212.378184][ T7869] netlink: 'syz.2.481': attribute type 1 has an invalid length. [ 213.361065][ T7724] bridge0: port 1(bridge_slave_0) entered blocking state [ 213.411403][ T7724] bridge0: port 1(bridge_slave_0) entered disabled state [ 213.432649][ T7724] bridge_slave_0: entered allmulticast mode [ 213.453956][ T7724] bridge_slave_0: entered promiscuous mode [ 213.916508][ T7900] netlink: 212424 bytes leftover after parsing attributes in process `syz.2.486'. [ 214.241797][ T7724] bridge0: port 2(bridge_slave_1) entered blocking state [ 214.249542][ T7724] bridge0: port 2(bridge_slave_1) entered disabled state [ 214.256867][ T7724] bridge_slave_1: entered allmulticast mode [ 214.266706][ T7724] bridge_slave_1: entered promiscuous mode [ 214.302044][ T7904] netlink: 65039 bytes leftover after parsing attributes in process `syz.4.487'. [ 214.563649][ T7724] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link [ 214.626690][ T7724] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link [ 215.135668][ T7927] netlink: 'syz.4.492': attribute type 21 has an invalid length. [ 215.515763][ T7927] netlink: 132 bytes leftover after parsing attributes in process `syz.4.492'. [ 215.534501][ T7927] netlink: 'syz.4.492': attribute type 1 has an invalid length. [ 215.590582][ T7724] team0: Port device team_slave_0 added [ 215.643597][ T7724] team0: Port device team_slave_1 added [ 215.784425][ T7937] netlink: 'syz.3.495': attribute type 2 has an invalid length. [ 215.830491][ T7937] netlink: 'syz.3.495': attribute type 1 has an invalid length. [ 215.900690][ T7938] netlink: 'syz.2.493': attribute type 29 has an invalid length. [ 215.947574][ T7724] batman_adv: batadv0: Adding interface: batadv_slave_0 [ 215.975400][ T7724] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 216.034841][ T7724] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active [ 216.048069][ T7724] batman_adv: batadv0: Adding interface: batadv_slave_1 [ 216.055078][ T7724] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1560 would solve the problem. [ 216.081576][ T7724] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active [ 216.280656][ T7948] netlink: 127868 bytes leftover after parsing attributes in process `syz.3.498'. [ 216.807647][ T7946] netlink: 65039 bytes leftover after parsing attributes in process `syz.1.497'. [ 216.885981][ T7724] hsr_slave_0: entered promiscuous mode [ 216.896571][ T7724] hsr_slave_1: entered promiscuous mode [ 216.905813][ T7724] debugfs: Directory 'hsr0' with parent 'hsr' already present! [ 216.913715][ T7724] Cannot create hsr debugfs directory [ 217.358652][ T7962] netlink: 65039 bytes leftover after parsing attributes in process `syz.2.502'. [ 217.469782][ T7971] netlink: 'syz.1.504': attribute type 2 has an invalid length. [ 217.477601][ T7971] netlink: 'syz.1.504': attribute type 1 has an invalid length. [ 217.484897][ T7965] netlink: 212424 bytes leftover after parsing attributes in process `syz.3.500'. [ 217.541446][ T7971] netlink: 193500 bytes leftover after parsing attributes in process `syz.1.504'. [ 217.627522][ T7971] nbd: must specify at least one socket [ 218.218958][ T7971] delete_channel: no stack [ 218.224720][ T7971] delete_channel: no stack [ 218.367100][ T7986] netlink: 'syz.2.506': attribute type 21 has an invalid length. [ 218.470969][ T7986] netlink: 132 bytes leftover after parsing attributes in process `syz.2.506'. [ 218.498051][ T7986] netlink: 'syz.2.506': attribute type 1 has an invalid length. [ 218.829010][ T7995] netlink: 'syz.1.508': attribute type 2 has an invalid length. [ 219.031815][ T8000] netlink: 127868 bytes leftover after parsing attributes in process `syz.4.510'. [ 223.711749][ T8010] validate_nla: 1 callbacks suppressed [ 223.711772][ T8010] netlink: 'syz.1.512': attribute type 29 has an invalid length. [ 224.331079][ T8027] netlink: 212424 bytes leftover after parsing attributes in process `syz.1.515'. [ 224.604941][ T8026] netlink: 65039 bytes leftover after parsing attributes in process `syz.3.516'. [ 224.936515][ T7724] netdevsim netdevsim0 netdevsim0: renamed from eth0 [ 224.991355][ T7724] netdevsim netdevsim0 netdevsim1: renamed from eth1 [ 225.087426][ T7724] netdevsim netdevsim0 netdevsim2: renamed from eth2 [ 225.164869][ T7724] netdevsim netdevsim0 netdevsim3: renamed from eth3 [ 225.331183][ T8053] netlink: 'syz.2.522': attribute type 2 has an invalid length. [ 225.358096][ T8053] netlink: 'syz.2.522': attribute type 1 has an invalid length. [ 225.773572][ T7724] 8021q: adding VLAN 0 to HW filter on device bond0 [ 225.846758][ T7724] 8021q: adding VLAN 0 to HW filter on device team0 [ 225.947165][ T36] bridge0: port 1(bridge_slave_0) entered blocking state [ 225.954626][ T36] bridge0: port 1(bridge_slave_0) entered forwarding state [ 226.043063][ T36] bridge0: port 2(bridge_slave_1) entered blocking state [ 226.050404][ T36] bridge0: port 2(bridge_slave_1) entered forwarding state [ 226.205001][ T8073] netlink: 127868 bytes leftover after parsing attributes in process `syz.2.526'. [ 226.205426][ T7724] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network [ 226.275366][ T7724] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network [ 226.544459][ T8086] netlink: 65039 bytes leftover after parsing attributes in process `syz.3.531'. [ 226.845332][ T8084] netlink: 212424 bytes leftover after parsing attributes in process `syz.4.529'. [ 227.109708][ T8101] netlink: 'syz.2.532': attribute type 3 has an invalid length. [ 227.199342][ T8101] netlink: 132 bytes leftover after parsing attributes in process `syz.2.532'. [ 227.423894][ T7724] 8021q: adding VLAN 0 to HW filter on device batadv0 [ 227.574685][ T7724] veth0_vlan: entered promiscuous mode [ 227.667644][ T7724] veth1_vlan: entered promiscuous mode [ 227.792521][ T7724] veth0_macvtap: entered promiscuous mode [ 227.819474][ T7724] veth1_macvtap: entered promiscuous mode [ 227.893380][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 227.904106][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 227.914580][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 227.928862][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 227.939173][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 227.945824][ T8114] netlink: 'syz.1.535': attribute type 2 has an invalid length. [ 227.958039][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 227.997931][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3e) already exists on: batadv_slave_0 [ 228.026505][ T8114] netlink: 'syz.1.535': attribute type 1 has an invalid length. [ 228.038140][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 228.071638][ T7724] batman_adv: batadv0: Interface activated: batadv_slave_0 [ 228.111328][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 228.163738][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 228.205616][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 228.237844][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 228.267630][ T7724] batman_adv: The newly added mac address (aa:aa:aa:aa:aa:3f) already exists on: batadv_slave_1 [ 228.312044][ T7724] batman_adv: It is strongly recommended to keep mac addresses unique to avoid problems! [ 228.344371][ T7724] batman_adv: batadv0: Interface activated: batadv_slave_1 [ 228.407546][ T8124] netlink: 830 bytes leftover after parsing attributes in process `syz.3.537'. [ 228.483049][ T7724] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 [ 228.527847][ T7724] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 [ 228.542939][ T7724] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 [ 228.568046][ T7724] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 [ 229.383399][ T36] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 229.428856][ T36] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 229.566405][ T7325] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50 [ 229.580342][ T7325] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50 [ 229.753720][ T8152] bridge0: port 4(veth1_to_bridge) entered blocking state [ 229.832074][ T8152] bridge0: port 4(veth1_to_bridge) entered disabled state [ 229.884539][ T8152] veth1_to_bridge: entered allmulticast mode [ 230.060021][ T8152] veth1_to_bridge: entered promiscuous mode [ 230.129415][ T8152] bridge0: adding interface veth1_to_bridge with same address as a received packet (addr:aa:aa:aa:aa:aa:1c, vlan:0) [ 230.299890][ T8152] bridge0: port 4(veth1_to_bridge) entered blocking state [ 230.307563][ T8152] bridge0: port 4(veth1_to_bridge) entered forwarding state [ 230.769802][ T8158] netlink: 65039 bytes leftover after parsing attributes in process `syz.4.543'. [ 232.995486][ T194] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 233.339876][ T194] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 233.499747][ T194] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 233.672471][ T194] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0 [ 234.017021][ T8198] FAULT_INJECTION: forcing a failure. [ 234.017021][ T8198] name fail_usercopy, interval 1, probability 0, space 0, times 0 [ 234.088167][ T8198] CPU: 1 UID: 0 PID: 8198 Comm: syz.1.549 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 234.088198][ T8198] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 234.088212][ T8198] Call Trace: [ 234.088220][ T8198] [ 234.088229][ T8198] dump_stack_lvl+0x189/0x250 [ 234.088265][ T8198] ? __lock_acquire+0xaac/0xd20 [ 234.088296][ T8198] ? __pfx_dump_stack_lvl+0x10/0x10 [ 234.088325][ T8198] ? __pfx__printk+0x10/0x10 [ 234.088346][ T8198] ? __might_fault+0xb0/0x130 [ 234.088386][ T8198] should_fail_ex+0x414/0x560 [ 234.088414][ T8198] _copy_from_user+0x2d/0xb0 [ 234.088444][ T8198] ___sys_sendmsg+0x158/0x2a0 [ 234.088476][ T8198] ? __pfx____sys_sendmsg+0x10/0x10 [ 234.088543][ T8198] ? __fget_files+0x2a/0x420 [ 234.088569][ T8198] ? __fget_files+0x3a0/0x420 [ 234.088616][ T8198] __x64_sys_sendmsg+0x19b/0x260 [ 234.088647][ T8198] ? __pfx___x64_sys_sendmsg+0x10/0x10 [ 234.088693][ T8198] ? do_syscall_64+0xba/0x210 [ 234.088724][ T8198] do_syscall_64+0xf6/0x210 [ 234.088750][ T8198] ? clear_bhb_loop+0x45/0xa0 [ 234.088776][ T8198] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 234.088795][ T8198] RIP: 0033:0x7f8832d8e969 [ 234.088813][ T8198] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 234.088829][ T8198] RSP: 002b:00007f8833bcd038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 234.088850][ T8198] RAX: ffffffffffffffda RBX: 00007f8832fb5fa0 RCX: 00007f8832d8e969 [ 234.088864][ T8198] RDX: 0000000000000000 RSI: 0000200000000600 RDI: 0000000000000003 [ 234.088877][ T8198] RBP: 00007f8833bcd090 R08: 0000000000000000 R09: 0000000000000000 [ 234.088889][ T8198] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 [ 234.088901][ T8198] R13: 0000000000000000 R14: 00007f8832fb5fa0 R15: 00007ffc850862d8 [ 234.088932][ T8198] [ 234.533987][ T194] bridge_slave_1: left allmulticast mode [ 234.588331][ T194] bridge_slave_1: left promiscuous mode [ 234.623933][ T194] bridge0: port 2(bridge_slave_1) entered disabled state [ 234.770393][ T5840] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1 [ 234.779875][ T5840] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9 [ 234.790294][ T5840] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9 [ 234.803693][ T5840] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4 [ 234.818285][ T5840] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2 [ 235.054686][ T194] bridge_slave_0: left allmulticast mode [ 235.078024][ T194] bridge_slave_0: left promiscuous mode [ 235.120944][ T194] bridge0: port 1(bridge_slave_0) entered disabled state [ 236.501667][ T194] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface [ 236.516382][ T194] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface [ 236.533085][ T194] bond0 (unregistering): Released all slaves [ 236.847444][ T8251] netlink: 65039 bytes leftover after parsing attributes in process `syz.4.558'. [ 236.888202][ T5141] Bluetooth: hci0: command tx timeout [ 243.715172][ T15] sched: DL replenish lagged too much [ 324.176633][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.189429][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.204199][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.217130][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.231592][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.244685][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.259269][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.273058][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.287837][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.301189][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 324.316812][ T5141] Bluetooth: hci0: command tx timeout [ 324.891080][ T1302] ieee802154 phy0 wpan0: encryption failed: -22 [ 324.912965][ T1302] ieee802154 phy1 wpan1: encryption failed: -22 [ 327.186411][ T1302] ieee802154 phy0 wpan0: encryption failed: -22 [ 327.209306][ T1302] ieee802154 phy1 wpan1: encryption failed: -22 [ 329.435674][ C0] net_ratelimit: 1815 callbacks suppressed [ 329.435699][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 330.561196][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 331.102240][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 332.267218][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 332.608196][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 333.639409][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 334.059590][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 334.987962][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 335.307922][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 338.994347][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 339.007401][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 339.022067][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 339.037861][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 339.051075][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 339.065121][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 339.079189][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 339.092290][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 339.306128][ T5840] Bluetooth: hci0: command tx timeout [ 339.998071][ C0] net_ratelimit: 625 callbacks suppressed [ 339.998095][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 340.017129][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 340.031091][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 340.044995][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 340.058397][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 340.072837][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 340.086782][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 340.099776][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 340.114074][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 340.127844][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 343.252494][ T5840] Bluetooth: hci0: command tx timeout [ 345.007834][ C0] net_ratelimit: 3764 callbacks suppressed [ 345.007859][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 345.026757][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 345.040577][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 345.054286][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 345.067170][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 345.080853][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 345.094440][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 345.107365][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 345.121164][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 345.134762][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.018639][ C0] net_ratelimit: 3760 callbacks suppressed [ 350.018666][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 350.038264][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.051168][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.064970][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 350.078739][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.091742][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.105754][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 350.119620][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.132456][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 350.146533][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 355.543640][ C0] net_ratelimit: 3539 callbacks suppressed [ 355.545611][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 356.442562][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 356.637890][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 357.411682][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 358.095706][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 358.457977][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 359.183254][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 360.138015][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 360.679876][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 361.596135][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 362.405855][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 362.868048][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 363.637895][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 375.360990][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 375.667989][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 375.955910][ C0] bridge0: received packet on veth1_to_bridge with own address as source address (addr:9e:2d:c4:42:3c:98, vlan:0) [ 376.533991][ C1] watchdog: BUG: soft lockup - CPU#1 stuck for 142s! [syz.2.559:8253] [ 376.534028][ C1] Modules linked in: [ 376.534049][ C1] irq event stamp: 21294597 [ 376.534057][ C1] hardirqs last enabled at (21294596): [] irqentry_exit+0x74/0x90 [ 376.534093][ C1] hardirqs last disabled at (21294597): [] sysvec_apic_timer_interrupt+0xe/0xc0 [ 376.534120][ C1] softirqs last enabled at (18982776): [] __irq_exit_rcu+0xca/0x1f0 [ 376.534142][ C1] softirqs last disabled at (18982779): [] __irq_exit_rcu+0xca/0x1f0 [ 376.534182][ C1] CPU: 1 UID: 0 PID: 8253 Comm: syz.2.559 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 376.534208][ C1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 376.534225][ C1] RIP: 0010:unwind_next_frame+0x0/0x2390 [ 376.534250][ C1] Code: cc cc 89 d9 80 e1 07 80 c1 03 38 c1 7c 92 48 89 df e8 94 4e b0 00 eb 88 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1e fa 55 41 57 41 56 41 55 41 54 53 48 81 ec 98 00 00 00 49 [ 376.534266][ C1] RSP: 0018:ffffc90000a085e0 EFLAGS: 00000202 [ 376.534282][ C1] RAX: 0000000000000001 RBX: ffffc90000a086a0 RCX: b2ff9fafdeea9800 [ 376.534296][ C1] RDX: dffffc0000000000 RSI: ffffffff8b55c4b6 RDI: ffffc90000a085e8 [ 376.534311][ C1] RBP: ffffc90000a08670 R08: ffffc90000a086b0 R09: 0000000000000018 [ 376.534324][ C1] R10: dffffc0000000000 R11: ffffffff81acaa70 R12: ffff88801bb7da00 [ 376.534339][ C1] R13: ffff8880490ce3c0 R14: ffffffff81acaa70 R15: ffffc90000a085e8 [ 376.534354][ C1] FS: 00007f002c0566c0(0000) GS:ffff8881261ca000(0000) knlGS:0000000000000000 [ 376.534370][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 376.534383][ C1] CR2: 0000001b30515ff8 CR3: 00000000575c8000 CR4: 00000000003526f0 [ 376.534400][ C1] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 376.534411][ C1] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 376.534423][ C1] Call Trace: [ 376.534436][ C1] [ 376.534444][ C1] arch_stack_walk+0x11c/0x150 [ 376.534482][ C1] ? do_syscall_64+0xf6/0x210 [ 376.534517][ C1] stack_trace_save+0x9c/0xe0 [ 376.534540][ C1] ? __pfx_stack_trace_save+0x10/0x10 [ 376.534570][ C1] ? __irq_exit_rcu+0xd8/0x1f0 [ 376.534588][ C1] ? __pfx___irq_exit_rcu+0x10/0x10 [ 376.534610][ C1] kasan_save_track+0x3e/0x80 [ 376.534633][ C1] ? kasan_save_track+0x3e/0x80 [ 376.534654][ C1] ? __kasan_slab_alloc+0x6c/0x80 [ 376.534677][ C1] ? kmem_cache_alloc_node_noprof+0x1bb/0x3c0 [ 376.534703][ C1] ? __alloc_skb+0x112/0x2d0 [ 376.534726][ C1] ? ndisc_alloc_skb+0x9f/0x480 [ 376.534760][ C1] ? ndisc_send_rs+0x2b5/0x630 [ 376.534787][ C1] ? addrconf_rs_timer+0x369/0x670 [ 376.534811][ C1] ? call_timer_fn+0x17b/0x5f0 [ 376.534835][ C1] ? __run_timer_base+0x61a/0x860 [ 376.534856][ C1] ? run_timer_softirq+0xb7/0x180 [ 376.534878][ C1] ? handle_softirqs+0x283/0x870 [ 376.534906][ C1] ? __irq_exit_rcu+0xca/0x1f0 [ 376.534922][ C1] ? irq_exit_rcu+0x9/0x30 [ 376.534936][ C1] ? sysvec_irq_work+0xa3/0xc0 [ 376.534953][ C1] ? asm_sysvec_irq_work+0x1a/0x20 [ 376.534972][ C1] ? _raw_spin_unlock_irqrestore+0xa8/0x110 [ 376.534993][ C1] ? debug_check_no_obj_freed+0x451/0x470 [ 376.535011][ C1] ? __free_frozen_pages+0x403/0xcd0 [ 376.535039][ C1] ? __folio_put+0x21b/0x2c0 [ 376.535056][ C1] ? free_large_kmalloc+0x145/0x200 [ 376.535081][ C1] ? bpf_check+0x14767/0x19c60 [ 376.535099][ C1] ? bpf_prog_load+0x1318/0x1930 [ 376.535123][ C1] ? __sys_bpf+0x5f1/0x860 [ 376.535144][ C1] ? __x64_sys_bpf+0x7c/0x90 [ 376.535163][ C1] ? do_syscall_64+0xf6/0x210 [ 376.535247][ C1] __kasan_slab_alloc+0x6c/0x80 [ 376.535277][ C1] kmem_cache_alloc_node_noprof+0x1bb/0x3c0 [ 376.535305][ C1] ? __alloc_skb+0x112/0x2d0 [ 376.535337][ C1] __alloc_skb+0x112/0x2d0 [ 376.535370][ C1] ndisc_alloc_skb+0x9f/0x480 [ 376.535405][ C1] ndisc_send_rs+0x2b5/0x630 [ 376.535446][ C1] addrconf_rs_timer+0x369/0x670 [ 376.535483][ C1] ? __pfx_addrconf_rs_timer+0x10/0x10 [ 376.535511][ C1] ? __irq_exit_rcu+0xd8/0x1f0 [ 376.535542][ C1] call_timer_fn+0x17b/0x5f0 [ 376.535568][ C1] ? __pfx_addrconf_rs_timer+0x10/0x10 [ 376.535591][ C1] ? lockdep_hardirqs_on+0x9c/0x150 [ 376.535612][ C1] ? call_timer_fn+0xbe/0x5f0 [ 376.535638][ C1] ? __pfx_call_timer_fn+0x10/0x10 [ 376.535686][ C1] ? __pfx_addrconf_rs_timer+0x10/0x10 [ 376.535716][ C1] __run_timer_base+0x61a/0x860 [ 376.535773][ C1] ? __pfx___run_timer_base+0x10/0x10 [ 376.535827][ C1] run_timer_softirq+0xb7/0x180 [ 376.535854][ C1] handle_softirqs+0x283/0x870 [ 376.535892][ C1] ? __irq_exit_rcu+0xca/0x1f0 [ 376.535921][ C1] ? __pfx_handle_softirqs+0x10/0x10 [ 376.535951][ C1] ? irq_work_single+0x1ac/0x240 [ 376.535984][ C1] ? irqtime_account_irq+0xb6/0x1c0 [ 376.536015][ C1] __irq_exit_rcu+0xca/0x1f0 [ 376.536034][ C1] ? __pfx___irq_exit_rcu+0x10/0x10 [ 376.536060][ C1] ? rcu_is_watching+0x15/0xb0 [ 376.536095][ C1] irq_exit_rcu+0x9/0x30 [ 376.536111][ C1] sysvec_irq_work+0xa3/0xc0 [ 376.536129][ C1] [ 376.536136][ C1] [ 376.536145][ C1] asm_sysvec_irq_work+0x1a/0x20 [ 376.536165][ C1] RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 [ 376.536187][ C1] Code: 74 05 e8 8b a1 6e f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 73 23 38 f6 65 8b 05 5c c5 1c 07 85 c0 74 40 48 c7 04 24 0e 36 [ 376.536202][ C1] RSP: 0018:ffffc9000b267140 EFLAGS: 00000206 [ 376.536219][ C1] RAX: b2ff9fafdeea9800 RBX: 0000000000000a06 RCX: b2ff9fafdeea9800 [ 376.536233][ C1] RDX: 0000000000000000 RSI: ffffffff8d74ad15 RDI: 0000000000000001 [ 376.536245][ C1] RBP: ffffc9000b2671c0 R08: ffffffff8f7ed377 R09: 1ffffffff1efda6e [ 376.536259][ C1] R10: dffffc0000000000 R11: fffffbfff1efda6f R12: dffffc0000000000 [ 376.536273][ C1] R13: ffff888058b28000 R14: ffffffff99ab2950 R15: 1ffff9200164ce28 [ 376.536318][ C1] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10 [ 376.536358][ C1] debug_check_no_obj_freed+0x451/0x470 [ 376.536388][ C1] ? __page_table_check_zero+0xba/0x510 [ 376.536432][ C1] __free_frozen_pages+0x403/0xcd0 [ 376.536478][ C1] __folio_put+0x21b/0x2c0 [ 376.536504][ C1] ? __pfx___folio_put+0x10/0x10 [ 376.536533][ C1] ? free_large_kmalloc+0xeb/0x200 [ 376.536568][ C1] free_large_kmalloc+0x145/0x200 [ 376.536601][ C1] bpf_check+0x14767/0x19c60 [ 376.536628][ C1] ? __pfx_perf_swevent_event+0x10/0x10 [ 376.536669][ C1] ? perf_tp_event+0x664/0x1380 [ 376.536701][ C1] ? __pfx_perf_tp_event+0x10/0x10 [ 376.536724][ C1] ? __pfx_perf_swevent_event+0x10/0x10 [ 376.536769][ C1] ? perf_tp_event+0x664/0x1380 [ 376.536802][ C1] ? __pfx_perf_tp_event+0x10/0x10 [ 376.536869][ C1] ? trace_call_bpf+0xb7/0x850 [ 376.536898][ C1] ? trace_call_bpf+0x5ba/0x850 [ 376.536924][ C1] ? __pfx_bpf_check+0x10/0x10 [ 376.536941][ C1] ? trace_call_bpf+0xb7/0x850 [ 376.536978][ C1] ? __pfx_trace_call_bpf+0x10/0x10 [ 376.537013][ C1] ? trace_call_bpf+0x5ba/0x850 [ 376.537045][ C1] ? perf_trace_run_bpf_submit+0xee/0x170 [ 376.537078][ C1] ? perf_trace_preemptirq_template+0x280/0x340 [ 376.537105][ C1] ? irqentry_enter+0x3d/0x60 [ 376.537132][ C1] ? __pfx_perf_trace_preemptirq_template+0x10/0x10 [ 376.537177][ C1] ? irqentry_exit+0x74/0x90 [ 376.537201][ C1] ? lockdep_hardirqs_on+0x9c/0x150 [ 376.537244][ C1] ? seqcount_lockdep_reader_access+0x175/0x1c0 [ 376.537271][ C1] ? seqcount_lockdep_reader_access+0x17e/0x1c0 [ 376.537298][ C1] ? __pfx_seqcount_lockdep_reader_access+0x10/0x10 [ 376.537344][ C1] ? bpf_obj_name_cpy+0x194/0x1e0 [ 376.537373][ C1] ? bpf_lsm_bpf_prog_load+0x9/0x20 [ 376.537401][ C1] ? security_bpf_prog_load+0x7f/0x310 [ 376.537429][ C1] bpf_prog_load+0x1318/0x1930 [ 376.537477][ C1] ? __pfx_bpf_prog_load+0x10/0x10 [ 376.537503][ C1] ? irqentry_exit+0x74/0x90 [ 376.537557][ C1] ? __pfx_bpf_lsm_bpf+0x10/0x10 [ 376.537587][ C1] ? bpf_lsm_bpf+0x9/0x20 [ 376.537612][ C1] ? security_bpf+0x7e/0x300 [ 376.537637][ C1] __sys_bpf+0x5f1/0x860 [ 376.537667][ C1] ? __pfx___sys_bpf+0x10/0x10 [ 376.537741][ C1] __x64_sys_bpf+0x7c/0x90 [ 376.537770][ C1] do_syscall_64+0xf6/0x210 [ 376.537796][ C1] ? asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 376.537816][ C1] ? clear_bhb_loop+0x45/0xa0 [ 376.537843][ C1] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 376.537862][ C1] RIP: 0033:0x7f002b18e969 [ 376.537882][ C1] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 376.537898][ C1] RSP: 002b:00007f002c056038 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 [ 376.537917][ C1] RAX: ffffffffffffffda RBX: 00007f002b3b5fa0 RCX: 00007f002b18e969 [ 376.537931][ C1] RDX: 0000000000000090 RSI: 0000200000000880 RDI: 0000000000000005 [ 376.537943][ C1] RBP: 00007f002b210ab1 R08: 0000000000000000 R09: 0000000000000000 [ 376.537955][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 376.537966][ C1] R13: 0000000000000000 R14: 00007f002b3b5fa0 R15: 00007fff602e2fc8 [ 376.538007][ C1] [ 376.538025][ C1] Sending NMI from CPU 1 to CPUs 0: [ 377.214521][ C0] bridge0: received packet on bridge_slave_1 with own address as source address (addr:aa:aa:aa:aa:aa:0c, vlan:0) [ 377.217822][ C0] NMI backtrace for cpu 0 [ 377.217836][ C0] CPU: 0 UID: 0 PID: 8267 Comm: syz.1.564 Not tainted 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 377.217856][ C0] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 377.217866][ C0] RIP: 0010:kvm_guest_state+0x20/0x150 [ 377.217892][ C0] Code: 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 55 41 57 41 56 53 e8 21 44 81 00 bf 01 00 00 00 e8 d7 41 52 00 48 c7 c7 a0 a8 61 8b 2b b8 17 0a 65 4c 8b 35 eb 06 37 11 4c 89 f3 bf 01 00 00 00 e8 [ 377.217906][ C0] RSP: 0018:ffffc90000005eb8 EFLAGS: 00000006 [ 377.217920][ C0] RAX: 0000000000010104 RBX: 1ffff92000000be0 RCX: ffffffff99808603 [ 377.217933][ C0] RDX: 0000000000010100 RSI: 0000000000000000 RDI: ffffffff8b61a8a0 [ 377.217943][ C0] RBP: ffffc90000005ff0 R08: 0000000000000000 R09: 0000000000080000 [ 377.217954][ C0] R10: 0000000000000000 R11: ffffffff81eef31f R12: 0000000000000018 [ 377.217964][ C0] R13: ffff88807a363e40 R14: ffff88807a363d40 R15: ffff8880b88326b0 [ 377.217976][ C0] FS: 00007f8833bcd6c0(0000) GS:ffff8881260ca000(0000) knlGS:0000000000000000 [ 377.217990][ C0] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 377.218001][ C0] CR2: 00005619c713fa08 CR3: 0000000011b14000 CR4: 00000000003526f0 [ 377.218015][ C0] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 377.218024][ C0] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 377.218034][ C0] Call Trace: [ 377.218044][ C0] [ 377.218072][ C0] perf_event_output_forward+0x222/0x430 [ 377.218119][ C0] ? perf_event_output_forward+0x8f/0x430 [ 377.218155][ C0] ? __pfx_perf_event_output_forward+0x10/0x10 [ 377.218196][ C0] ? __pfx_perf_trace_lock_acquire+0x10/0x10 [ 377.218265][ C0] ? __lock_acquire+0xaac/0xd20 [ 377.218328][ C0] ? __perf_event_account_interrupt+0x167/0x260 [ 377.218383][ C0] __perf_event_overflow+0x7cc/0xe10 [ 377.218479][ C0] ? __pfx___perf_event_overflow+0x10/0x10 [ 377.218516][ C0] ? perf_output_begin_forward+0x9bc/0xa80 [ 377.218577][ C0] ? perf_get_regs_user+0x5bc/0x6b0 [ 377.218634][ C0] perf_swevent_event+0x2f4/0x5e0 [ 377.218707][ C0] ? __pfx_perf_swevent_event+0x10/0x10 [ 377.218809][ C0] perf_tp_event+0x4f6/0x1380 [ 377.218882][ C0] ? __pfx_perf_tp_event+0x10/0x10 [ 377.218898][ C0] ? perf_get_regs_user+0x5bc/0x6b0 [ 377.218979][ C0] ? lock_acquire+0x311/0x360 [ 377.219156][ C0] ? __pfx___perf_event_overflow+0x10/0x10 [ 377.219172][ C0] ? perf_event_output_forward+0x8f/0x430 [ 377.219256][ C0] ? perf_event_output_forward+0x384/0x430 [ 377.219318][ C0] ? perf_swevent_event+0x2f4/0x5e0 [ 377.219373][ C0] perf_trace_run_bpf_submit+0xee/0x170 [ 377.219446][ C0] perf_trace_lock_acquire+0x335/0x410 [ 377.219537][ C0] ? __pfx_perf_trace_lock_acquire+0x10/0x10 [ 377.219599][ C0] ? __pfx_perf_tp_event+0x10/0x10 [ 377.219687][ C0] ? perf_event_output_forward+0x8f/0x430 [ 377.219711][ C0] lock_acquire+0x311/0x360 [ 377.219741][ C0] ? perf_event_output_forward+0x8f/0x430 [ 377.219865][ C0] perf_event_output_forward+0xb0/0x430 [ 377.219892][ C0] ? perf_event_output_forward+0x8f/0x430 [ 377.219934][ C0] ? perf_event_output_forward+0x8f/0x430 [ 377.219969][ C0] ? __pfx_perf_event_output_forward+0x10/0x10 [ 377.220037][ C0] ? perf_tp_event+0x664/0x1380 [ 377.220117][ C0] ? __perf_event_account_interrupt+0x167/0x260 [ 377.220166][ C0] __perf_event_overflow+0x7cc/0xe10 [ 377.220260][ C0] ? __pfx___perf_event_overflow+0x10/0x10 [ 377.220292][ C0] ? __pfx_cpu_clock_event_update+0x10/0x10 [ 377.220330][ C0] ? __pfx_perf_trace_lock_acquire+0x10/0x10 [ 377.220425][ C0] perf_swevent_hrtimer+0x3c2/0x540 [ 377.220503][ C0] ? __pfx_perf_swevent_hrtimer+0x10/0x10 [ 377.220541][ C0] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 377.220753][ C0] ? _raw_spin_unlock_irqrestore+0xad/0x110 [ 377.220782][ C0] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10 [ 377.220848][ C0] ? __pfx_perf_swevent_hrtimer+0x10/0x10 [ 377.220886][ C0] ? __pfx_perf_swevent_hrtimer+0x10/0x10 [ 377.220919][ C0] __hrtimer_run_queues+0x4dd/0xc60 [ 377.220951][ C0] ? ktime_get_update_offsets_now+0x60/0x3d0 [ 377.221101][ C0] ? __pfx___hrtimer_run_queues+0x10/0x10 [ 377.221135][ C0] ? ktime_get_update_offsets_now+0x3ab/0x3d0 [ 377.221230][ C0] hrtimer_interrupt+0x45b/0xaa0 [ 377.221459][ C0] __sysvec_apic_timer_interrupt+0x108/0x410 [ 377.221505][ C0] sysvec_apic_timer_interrupt+0x52/0xc0 [ 377.221538][ C0] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 377.221558][ C0] RIP: 0010:vprintk_emit+0x58f/0x7a0 [ 377.221574][ C0] Code: 85 32 01 00 00 e8 41 f3 1e 00 41 89 df 4d 85 f6 48 8b 1c 24 75 07 e8 30 f3 1e 00 eb 06 e8 29 f3 1e 00 fb 48 c7 c7 80 fa f2 8d <31> f6 ba 01 00 00 00 31 c9 41 b8 01 00 00 00 45 31 c9 53 e8 f9 3f [ 377.221588][ C0] RSP: 0018:ffffc90000006ec0 EFLAGS: 00000246 [ 377.221602][ C0] RAX: ffffffff81a0cba7 RBX: ffffffff81a0ca64 RCX: ffff88802705da00 [ 377.221615][ C0] RDX: 0000000000000100 RSI: 0000000000000000 RDI: ffffffff8df2fa80 [ 377.221626][ C0] RBP: ffffc90000006fd0 R08: ffffffff8f7ed377 R09: 1ffffffff1efda6e [ 377.221638][ C0] R10: dffffc0000000000 R11: fffffbfff1efda6f R12: dffffc0000000000 [ 377.221650][ C0] R13: 1ffff92000000ddc R14: 0000000000000200 R15: 000000000000006e [ 377.221689][ C0] ? vprintk_emit+0x444/0x7a0 [ 377.221725][ C0] ? vprintk_emit+0x587/0x7a0 [ 377.221790][ C0] ? vprintk_emit+0x444/0x7a0 [ 377.221831][ C0] ? __pfx_vprintk_emit+0x10/0x10 [ 377.221845][ C0] ? _raw_spin_unlock_irqrestore+0x85/0x110 [ 377.221873][ C0] ? lockdep_hardirqs_on+0x9c/0x150 [ 377.221913][ C0] ? _raw_spin_unlock_irqrestore+0xad/0x110 [ 377.221941][ C0] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10 [ 377.222044][ C0] _printk+0xcf/0x120 [ 377.222115][ C0] ? __pfx__printk+0x10/0x10 [ 377.222167][ C0] ? __pfx_perf_trace_preemptirq_template+0x10/0x10 [ 377.222251][ C0] br_fdb_update+0x62d/0x690 [ 377.222330][ C0] ? __pfx_br_fdb_update+0x10/0x10 [ 377.222444][ C0] br_handle_frame_finish+0x573/0x1950 [ 377.222558][ C0] ? __pfx_br_handle_frame_finish+0x10/0x10 [ 377.222660][ C0] ? ip6t_do_table+0x1db/0x1530 [ 377.222727][ C0] ? nf_hook_slow+0x176/0x220 [ 377.222775][ C0] ? __pfx_br_handle_frame_finish+0x10/0x10 [ 377.222802][ C0] br_nf_hook_thresh+0x3bf/0x490 [ 377.222894][ C0] ? __pfx_br_nf_hook_thresh+0x10/0x10 [ 377.222940][ C0] ? __pfx_br_handle_frame_finish+0x10/0x10 [ 377.222962][ C0] ? nf_nat_ipv6_in+0x1fc/0x2b0 [ 377.223072][ C0] br_nf_pre_routing_finish_ipv6+0x948/0xd00 [ 377.223094][ C0] ? __pfx_br_handle_frame_finish+0x10/0x10 [ 377.223180][ C0] ? br_nf_pre_routing_ipv6+0x42f/0x6b0 [ 377.223213][ C0] br_nf_pre_routing_ipv6+0x37e/0x6b0 [ 377.223265][ C0] ? __pfx_br_nf_pre_routing_ipv6+0x10/0x10 [ 377.223314][ C0] ? __pfx_br_nf_pre_routing_finish_ipv6+0x10/0x10 [ 377.223332][ C0] ? br_nf_pre_routing+0x720/0x1470 [ 377.223421][ C0] ? __pfx_br_nf_pre_routing+0x10/0x10 [ 377.223446][ C0] br_handle_frame+0x97f/0x14c0 [ 377.223539][ C0] ? __pfx_br_handle_frame+0x10/0x10 [ 377.223586][ C0] ? __pfx_br_handle_frame_finish+0x10/0x10 [ 377.223615][ C0] ? do_raw_spin_unlock+0x122/0x240 [ 377.223676][ C0] ? __pfx_br_handle_frame+0x10/0x10 [ 377.223719][ C0] __netif_receive_skb_core+0x10de/0x4180 [ 377.223743][ C0] ? lapic_next_event+0x11/0x20 [ 377.223761][ C0] ? clockevents_program_event+0x24d/0x360 [ 377.223817][ C0] ? __pfx_sched_clock_cpu+0x10/0x10 [ 377.223963][ C0] ? __pfx___netif_receive_skb_core+0x10/0x10 [ 377.223979][ C0] ? __irq_exit_rcu+0xd8/0x1f0 [ 377.224003][ C0] ? __pfx___irq_exit_rcu+0x10/0x10 [ 377.224060][ C0] ? irqentry_exit+0x74/0x90 [ 377.224088][ C0] ? lockdep_hardirqs_on+0x9c/0x150 [ 377.224165][ C0] ? process_backlog+0x2d5/0x14f0 [ 377.224182][ C0] ? process_backlog+0x2d5/0x14f0 [ 377.224273][ C0] __netif_receive_skb+0x72/0x380 [ 377.224322][ C0] ? process_backlog+0x2d5/0x14f0 [ 377.224373][ C0] process_backlog+0x60e/0x14f0 [ 377.224511][ C0] ? __pfx_process_backlog+0x10/0x10 [ 377.224609][ C0] __napi_poll+0xc4/0x480 [ 377.224669][ C0] net_rx_action+0x6ea/0xdf0 [ 377.224806][ C0] ? __pfx_net_rx_action+0x10/0x10 [ 377.225078][ C0] handle_softirqs+0x283/0x870 [ 377.225142][ C0] ? __irq_exit_rcu+0xca/0x1f0 [ 377.225209][ C0] ? __pfx_handle_softirqs+0x10/0x10 [ 377.225282][ C0] ? irqtime_account_irq+0xb6/0x1c0 [ 377.225334][ C0] __irq_exit_rcu+0xca/0x1f0 [ 377.225392][ C0] ? __pfx___irq_exit_rcu+0x10/0x10 [ 377.225481][ C0] irq_exit_rcu+0x9/0x30 [ 377.225496][ C0] sysvec_apic_timer_interrupt+0xa6/0xc0 [ 377.225524][ C0] [ 377.225529][ C0] [ 377.225545][ C0] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 377.225565][ C0] RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 [ 377.225584][ C0] Code: 74 05 e8 8b a1 6e f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 73 23 38 f6 65 8b 05 5c c5 1c 07 85 c0 74 40 48 c7 04 24 0e 36 [ 377.225597][ C0] RSP: 0018:ffffc90004d47000 EFLAGS: 00000206 [ 377.225611][ C0] RAX: c34c14aea76a2900 RBX: 0000000000000a06 RCX: c34c14aea76a2900 [ 377.225624][ C0] RDX: 0000000000000007 RSI: ffffffff8d74ad15 RDI: 0000000000000001 [ 377.225635][ C0] RBP: ffffc90004d47098 R08: ffffffff8f7ed377 R09: 1ffffffff1efda6e [ 377.225647][ C0] R10: dffffc0000000000 R11: fffffbfff1efda6f R12: dffffc0000000000 [ 377.225660][ C0] R13: ffff88807e340000 R14: ffffffff99a2aca8 R15: 1ffff920009a8e00 [ 377.225794][ C0] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10 [ 377.225905][ C0] debug_check_no_obj_freed+0x451/0x470 [ 377.225975][ C0] ? __page_table_check_zero+0xba/0x510 [ 377.226069][ C0] __free_frozen_pages+0x403/0xcd0 [ 377.226174][ C0] __put_partials+0x161/0x1c0 [ 377.226251][ C0] put_cpu_partial+0x17c/0x250 [ 377.226275][ C0] ? put_cpu_partial+0x6d/0x250 [ 377.226333][ C0] __slab_free+0x2f7/0x400 [ 377.226635][ C0] ? __phys_addr+0xba/0x170 [ 377.226704][ C0] qlist_free_all+0x9a/0x140 [ 377.226767][ C0] kasan_quarantine_reduce+0x148/0x160 [ 377.226817][ C0] __kasan_slab_alloc+0x22/0x80 [ 377.226863][ C0] __kvmalloc_node_noprof+0x2b7/0x5e0 [ 377.226901][ C0] ? bpf_check+0xee8/0x19c60 [ 377.226966][ C0] bpf_check+0xee8/0x19c60 [ 377.227018][ C0] ? __pfx___perf_event_overflow+0x10/0x10 [ 377.227036][ C0] ? __perf_event_overflow+0x8c1/0xe10 [ 377.227216][ C0] ? __pfx_perf_swevent_event+0x10/0x10 [ 377.227257][ C0] ? perf_swevent_event+0x2f4/0x5e0 [ 377.227334][ C0] ? perf_tp_event+0x664/0x1380 [ 377.227414][ C0] ? __pfx_perf_tp_event+0x10/0x10 [ 377.227431][ C0] ? perf_trace_buf_alloc+0x131/0x2a0 [ 377.227520][ C0] ? lock_acquire+0x311/0x360 [ 377.227674][ C0] ? trace_call_bpf+0xb7/0x850 [ 377.227719][ C0] ? __pfx_bpf_check+0x10/0x10 [ 377.227795][ C0] ? trace_call_bpf+0xb7/0x850 [ 377.227844][ C0] ? trace_call_bpf+0xb7/0x850 [ 377.227876][ C0] ? trace_call_bpf+0x5ba/0x850 [ 377.227929][ C0] ? perf_trace_run_bpf_submit+0xee/0x170 [ 377.228002][ C0] ? perf_trace_lock_acquire+0x335/0x410 [ 377.228093][ C0] ? __pfx_perf_trace_lock_acquire+0x10/0x10 [ 377.228162][ C0] ? __lock_acquire+0xaac/0xd20 [ 377.228259][ C0] ? ktime_get_with_offset+0x8c/0x2a0 [ 377.228342][ C0] ? seqcount_lockdep_reader_access+0x123/0x1c0 [ 377.228371][ C0] ? lockdep_hardirqs_on+0x9c/0x150 [ 377.228407][ C0] ? ktime_get_with_offset+0x8c/0x2a0 [ 377.228430][ C0] ? seqcount_lockdep_reader_access+0x175/0x1c0 [ 377.228458][ C0] ? __pfx_seqcount_lockdep_reader_access+0x10/0x10 [ 377.228578][ C0] ? bpf_obj_name_cpy+0x194/0x1e0 [ 377.228605][ C0] ? bpf_lsm_bpf_prog_load+0x9/0x20 [ 377.228629][ C0] ? security_bpf_prog_load+0x7f/0x310 [ 377.228682][ C0] bpf_prog_load+0x1318/0x1930 [ 377.228808][ C0] ? __pfx_bpf_prog_load+0x10/0x10 [ 377.229006][ C0] ? bpf_lsm_bpf+0x9/0x20 [ 377.229031][ C0] ? security_bpf+0x7e/0x300 [ 377.229079][ C0] __sys_bpf+0x5f1/0x860 [ 377.229134][ C0] ? __pfx___sys_bpf+0x10/0x10 [ 377.229273][ C0] ? rcu_is_watching+0x15/0xb0 [ 377.229387][ C0] __x64_sys_bpf+0x7c/0x90 [ 377.229437][ C0] do_syscall_64+0xf6/0x210 [ 377.229473][ C0] ? asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 377.229492][ C0] ? clear_bhb_loop+0x45/0xa0 [ 377.229540][ C0] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 377.229560][ C0] RIP: 0033:0x7f8832d8e969 [ 377.229588][ C0] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 377.229603][ C0] RSP: 002b:00007f8833bcd038 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 [ 377.229621][ C0] RAX: ffffffffffffffda RBX: 00007f8832fb5fa0 RCX: 00007f8832d8e969 [ 377.229633][ C0] RDX: 0000000000000094 RSI: 0000200000000880 RDI: 0000000000000005 [ 377.229644][ C0] RBP: 00007f8832e10ab1 R08: 0000000000000000 R09: 0000000000000000 [ 377.229654][ C0] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 377.229664][ C0] R13: 0000000000000000 R14: 00007f8832fb5fa0 R15: 00007ffc850862d8 [ 377.229790][ C0] [ 377.229838][ C1] Kernel panic - not syncing: softlockup: hung tasks [ 377.229859][ C1] CPU: 1 UID: 0 PID: 8253 Comm: syz.2.559 Tainted: G L 6.15.0-rc4-syzkaller-g25b6d5def6f8 #0 PREEMPT(full) [ 377.229887][ C1] Tainted: [L]=SOFTLOCKUP [ 377.229894][ C1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 [ 377.229907][ C1] Call Trace: [ 377.229917][ C1] [ 377.229927][ C1] dump_stack_lvl+0x99/0x250 [ 377.229960][ C1] ? __asan_memcpy+0x40/0x70 [ 377.229984][ C1] ? __pfx_dump_stack_lvl+0x10/0x10 [ 377.230015][ C1] ? __pfx__printk+0x10/0x10 [ 377.230060][ C1] panic+0x2db/0x790 [ 377.230100][ C1] ? __pfx_panic+0x10/0x10 [ 377.230132][ C1] ? nmi_backtrace_stall_check+0x433/0x440 [ 377.230188][ C1] watchdog_timer_fn+0x85c/0x860 [ 377.230225][ C1] ? __pfx_watchdog_timer_fn+0x10/0x10 [ 377.230257][ C1] ? _raw_spin_unlock_irqrestore+0xad/0x110 [ 377.230282][ C1] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10 [ 377.230317][ C1] ? __pfx_watchdog_timer_fn+0x10/0x10 [ 377.230348][ C1] ? __pfx_watchdog_timer_fn+0x10/0x10 [ 377.230377][ C1] __hrtimer_run_queues+0x4dd/0xc60 [ 377.230409][ C1] ? ktime_get_update_offsets_now+0x60/0x3d0 [ 377.230466][ C1] ? __pfx___hrtimer_run_queues+0x10/0x10 [ 377.230499][ C1] ? ktime_get_update_offsets_now+0x3ab/0x3d0 [ 377.230544][ C1] hrtimer_interrupt+0x45b/0xaa0 [ 377.230623][ C1] __sysvec_apic_timer_interrupt+0x108/0x410 [ 377.230663][ C1] sysvec_apic_timer_interrupt+0x52/0xc0 [ 377.230691][ C1] asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 377.230714][ C1] RIP: 0010:unwind_next_frame+0x0/0x2390 [ 377.230741][ C1] Code: cc cc 89 d9 80 e1 07 80 c1 03 38 c1 7c 92 48 89 df e8 94 4e b0 00 eb 88 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1e fa 55 41 57 41 56 41 55 41 54 53 48 81 ec 98 00 00 00 49 [ 377.230759][ C1] RSP: 0018:ffffc90000a085e0 EFLAGS: 00000202 [ 377.230778][ C1] RAX: 0000000000000001 RBX: ffffc90000a086a0 RCX: b2ff9fafdeea9800 [ 377.230794][ C1] RDX: dffffc0000000000 RSI: ffffffff8b55c4b6 RDI: ffffc90000a085e8 [ 377.230811][ C1] RBP: ffffc90000a08670 R08: ffffc90000a086b0 R09: 0000000000000018 [ 377.230827][ C1] R10: dffffc0000000000 R11: ffffffff81acaa70 R12: ffff88801bb7da00 [ 377.230844][ C1] R13: ffff8880490ce3c0 R14: ffffffff81acaa70 R15: ffffc90000a085e8 [ 377.230862][ C1] ? __pfx_stack_trace_consume_entry+0x10/0x10 [ 377.230890][ C1] ? __pfx_stack_trace_consume_entry+0x10/0x10 [ 377.230920][ C1] ? do_syscall_64+0xf6/0x210 [ 377.230955][ C1] arch_stack_walk+0x11c/0x150 [ 377.230994][ C1] ? do_syscall_64+0xf6/0x210 [ 377.231029][ C1] stack_trace_save+0x9c/0xe0 [ 377.231053][ C1] ? __pfx_stack_trace_save+0x10/0x10 [ 377.231085][ C1] ? __irq_exit_rcu+0xd8/0x1f0 [ 377.231105][ C1] ? __pfx___irq_exit_rcu+0x10/0x10 [ 377.231128][ C1] kasan_save_track+0x3e/0x80 [ 377.231153][ C1] ? kasan_save_track+0x3e/0x80 [ 377.231176][ C1] ? __kasan_slab_alloc+0x6c/0x80 [ 377.231201][ C1] ? kmem_cache_alloc_node_noprof+0x1bb/0x3c0 [ 377.231227][ C1] ? __alloc_skb+0x112/0x2d0 [ 377.231251][ C1] ? ndisc_alloc_skb+0x9f/0x480 [ 377.231280][ C1] ? ndisc_send_rs+0x2b5/0x630 [ 377.231308][ C1] ? addrconf_rs_timer+0x369/0x670 [ 377.231334][ C1] ? call_timer_fn+0x17b/0x5f0 [ 377.231359][ C1] ? __run_timer_base+0x61a/0x860 [ 377.231383][ C1] ? run_timer_softirq+0xb7/0x180 [ 377.231407][ C1] ? handle_softirqs+0x283/0x870 [ 377.231436][ C1] ? __irq_exit_rcu+0xca/0x1f0 [ 377.231454][ C1] ? irq_exit_rcu+0x9/0x30 [ 377.231470][ C1] ? sysvec_irq_work+0xa3/0xc0 [ 377.231488][ C1] ? asm_sysvec_irq_work+0x1a/0x20 [ 377.231509][ C1] ? _raw_spin_unlock_irqrestore+0xa8/0x110 [ 377.231531][ C1] ? debug_check_no_obj_freed+0x451/0x470 [ 377.231550][ C1] ? __free_frozen_pages+0x403/0xcd0 [ 377.231579][ C1] ? __folio_put+0x21b/0x2c0 [ 377.231598][ C1] ? free_large_kmalloc+0x145/0x200 [ 377.231626][ C1] ? bpf_check+0x14767/0x19c60 [ 377.231651][ C1] ? bpf_prog_load+0x1318/0x1930 [ 377.231676][ C1] ? __sys_bpf+0x5f1/0x860 [ 377.231700][ C1] ? __x64_sys_bpf+0x7c/0x90 [ 377.231721][ C1] ? do_syscall_64+0xf6/0x210 [ 377.231807][ C1] __kasan_slab_alloc+0x6c/0x80 [ 377.231835][ C1] kmem_cache_alloc_node_noprof+0x1bb/0x3c0 [ 377.231861][ C1] ? __alloc_skb+0x112/0x2d0 [ 377.231894][ C1] __alloc_skb+0x112/0x2d0 [ 377.231930][ C1] ndisc_alloc_skb+0x9f/0x480 [ 377.231969][ C1] ndisc_send_rs+0x2b5/0x630 [ 377.232010][ C1] addrconf_rs_timer+0x369/0x670 [ 377.232050][ C1] ? __pfx_addrconf_rs_timer+0x10/0x10 [ 377.232082][ C1] ? __irq_exit_rcu+0xd8/0x1f0 [ 377.232115][ C1] call_timer_fn+0x17b/0x5f0 [ 377.232144][ C1] ? __pfx_addrconf_rs_timer+0x10/0x10 [ 377.232170][ C1] ? lockdep_hardirqs_on+0x9c/0x150 [ 377.232194][ C1] ? call_timer_fn+0xbe/0x5f0 [ 377.232223][ C1] ? __pfx_call_timer_fn+0x10/0x10 [ 377.232274][ C1] ? __pfx_addrconf_rs_timer+0x10/0x10 [ 377.232305][ C1] __run_timer_base+0x61a/0x860 [ 377.232360][ C1] ? __pfx___run_timer_base+0x10/0x10 [ 377.232415][ C1] run_timer_softirq+0xb7/0x180 [ 377.232444][ C1] handle_softirqs+0x283/0x870 [ 377.232485][ C1] ? __irq_exit_rcu+0xca/0x1f0 [ 377.232517][ C1] ? __pfx_handle_softirqs+0x10/0x10 [ 377.232549][ C1] ? irq_work_single+0x1ac/0x240 [ 377.232585][ C1] ? irqtime_account_irq+0xb6/0x1c0 [ 377.232619][ C1] __irq_exit_rcu+0xca/0x1f0 [ 377.232648][ C1] ? __pfx___irq_exit_rcu+0x10/0x10 [ 377.232676][ C1] ? rcu_is_watching+0x15/0xb0 [ 377.232714][ C1] irq_exit_rcu+0x9/0x30 [ 377.232731][ C1] sysvec_irq_work+0xa3/0xc0 [ 377.232753][ C1] [ 377.232761][ C1] [ 377.232771][ C1] asm_sysvec_irq_work+0x1a/0x20 [ 377.232794][ C1] RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 [ 377.232818][ C1] Code: 74 05 e8 8b a1 6e f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 73 23 38 f6 65 8b 05 5c c5 1c 07 85 c0 74 40 48 c7 04 24 0e 36 [ 377.232838][ C1] RSP: 0018:ffffc9000b267140 EFLAGS: 00000206 [ 377.232857][ C1] RAX: b2ff9fafdeea9800 RBX: 0000000000000a06 RCX: b2ff9fafdeea9800 [ 377.232873][ C1] RDX: 0000000000000000 RSI: ffffffff8d74ad15 RDI: 0000000000000001 [ 377.232888][ C1] RBP: ffffc9000b2671c0 R08: ffffffff8f7ed377 R09: 1ffffffff1efda6e [ 377.232905][ C1] R10: dffffc0000000000 R11: fffffbfff1efda6f R12: dffffc0000000000 [ 377.232922][ C1] R13: ffff888058b28000 R14: ffffffff99ab2950 R15: 1ffff9200164ce28 [ 377.232970][ C1] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10 [ 377.233012][ C1] debug_check_no_obj_freed+0x451/0x470 [ 377.233044][ C1] ? __page_table_check_zero+0xba/0x510 [ 377.233091][ C1] __free_frozen_pages+0x403/0xcd0 [ 377.233139][ C1] __folio_put+0x21b/0x2c0 [ 377.233168][ C1] ? __pfx___folio_put+0x10/0x10 [ 377.233200][ C1] ? free_large_kmalloc+0xeb/0x200 [ 377.233260][ C1] free_large_kmalloc+0x145/0x200 [ 377.233297][ C1] bpf_check+0x14767/0x19c60 [ 377.233325][ C1] ? __pfx_perf_swevent_event+0x10/0x10 [ 377.233371][ C1] ? perf_tp_event+0x664/0x1380 [ 377.233406][ C1] ? __pfx_perf_tp_event+0x10/0x10 [ 377.233432][ C1] ? __pfx_perf_swevent_event+0x10/0x10 [ 377.233475][ C1] ? perf_tp_event+0x664/0x1380 [ 377.233510][ C1] ? __pfx_perf_tp_event+0x10/0x10 [ 377.233580][ C1] ? trace_call_bpf+0xb7/0x850 [ 377.233609][ C1] ? trace_call_bpf+0x5ba/0x850 [ 377.233638][ C1] ? __pfx_bpf_check+0x10/0x10 [ 377.233664][ C1] ? trace_call_bpf+0xb7/0x850 [ 377.233704][ C1] ? __pfx_trace_call_bpf+0x10/0x10 [ 377.233741][ C1] ? trace_call_bpf+0x5ba/0x850 [ 377.233776][ C1] ? perf_trace_run_bpf_submit+0xee/0x170 [ 377.233811][ C1] ? perf_trace_preemptirq_template+0x280/0x340 [ 377.233840][ C1] ? irqentry_enter+0x3d/0x60 [ 377.233870][ C1] ? __pfx_perf_trace_preemptirq_template+0x10/0x10 [ 377.233919][ C1] ? irqentry_exit+0x74/0x90 [ 377.233946][ C1] ? lockdep_hardirqs_on+0x9c/0x150 [ 377.233990][ C1] ? seqcount_lockdep_reader_access+0x175/0x1c0 [ 377.234020][ C1] ? seqcount_lockdep_reader_access+0x17e/0x1c0 [ 377.234050][ C1] ? __pfx_seqcount_lockdep_reader_access+0x10/0x10 [ 377.234098][ C1] ? bpf_obj_name_cpy+0x194/0x1e0 [ 377.234129][ C1] ? bpf_lsm_bpf_prog_load+0x9/0x20 [ 377.234165][ C1] ? security_bpf_prog_load+0x7f/0x310 [ 377.234195][ C1] bpf_prog_load+0x1318/0x1930 [ 377.234246][ C1] ? __pfx_bpf_prog_load+0x10/0x10 [ 377.234274][ C1] ? irqentry_exit+0x74/0x90 [ 377.234331][ C1] ? __pfx_bpf_lsm_bpf+0x10/0x10 [ 377.234363][ C1] ? bpf_lsm_bpf+0x9/0x20 [ 377.234392][ C1] ? security_bpf+0x7e/0x300 [ 377.234416][ C1] __sys_bpf+0x5f1/0x860 [ 377.234448][ C1] ? __pfx___sys_bpf+0x10/0x10 [ 377.234525][ C1] __x64_sys_bpf+0x7c/0x90 [ 377.234553][ C1] do_syscall_64+0xf6/0x210 [ 377.234581][ C1] ? asm_sysvec_apic_timer_interrupt+0x1a/0x20 [ 377.234604][ C1] ? clear_bhb_loop+0x45/0xa0 [ 377.234634][ C1] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 377.234663][ C1] RIP: 0033:0x7f002b18e969 [ 377.234685][ C1] Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 [ 377.234703][ C1] RSP: 002b:00007f002c056038 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 [ 377.234725][ C1] RAX: ffffffffffffffda RBX: 00007f002b3b5fa0 RCX: 00007f002b18e969 [ 377.234741][ C1] RDX: 0000000000000090 RSI: 0000200000000880 RDI: 0000000000000005 [ 377.234756][ C1] RBP: 00007f002b210ab1 R08: 0000000000000000 R09: 0000000000000000 [ 377.234770][ C1] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 [ 377.234785][ C1] R13: 0000000000000000 R14: 00007f002b3b5fa0 R15: 00007fff602e2fc8 [ 377.234829][ C1] [ 377.236975][ C1] Kernel Offset: disabled