[ 18.614281][ T291] 8021q: 802.1Q VLAN Support v1.8 [ 20.366720][ T306] br0: port 1(veth1) entered blocking state [ 20.367417][ T306] br0: port 1(veth1) entered disabled state [ 20.368146][ T306] veth1: entered allmulticast mode [ 20.372305][ T306] veth1: entered promiscuous mode [ 20.528023][ T308] br0: port 2(veth2) entered blocking state [ 20.528545][ T308] br0: port 2(veth2) entered disabled state [ 20.530010][ T308] veth2: entered allmulticast mode [ 20.533875][ T308] veth2: entered promiscuous mode [ 20.788595][ T36] br0: port 1(veth1) entered blocking state [ 20.789448][ T36] br0: port 1(veth1) entered forwarding state [ 20.926764][ T36] br0: port 2(veth2) entered blocking state [ 20.927380][ T36] br0: port 2(veth2) entered forwarding state [ 51.217400][ T379] GACT probability NOT on [ 86.239048][ T596] ================================================================== [ 86.239425][ T596] BUG: KASAN: null-ptr-deref in try_to_grab_pending+0x81/0x6c0 [ 86.239739][ T596] Write of size 8 at addr 0000000000000000 by task ip/596 [ 86.239991][ T596] [ 86.240100][ T596] CPU: 0 UID: 0 PID: 596 Comm: ip Not tainted 6.18.0-rc5-virtme #1 PREEMPT(full) [ 86.240105][ T596] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 86.240108][ T596] Call Trace: [ 86.240110][ T596] [ 86.240113][ T596] dump_stack_lvl+0x82/0xc0 [ 86.240121][ T596] ? try_to_grab_pending+0x81/0x6c0 [ 86.240124][ T596] kasan_report+0xca/0x100 [ 86.240131][ T596] ? try_to_grab_pending+0x81/0x6c0 [ 86.240137][ T596] kasan_check_range+0x39/0x1b0 [ 86.240140][ T596] try_to_grab_pending+0x81/0x6c0 [ 86.240146][ T596] __cancel_work+0x7c/0x260 [ 86.240151][ T596] ? enable_delayed_work+0x10/0x10 [ 86.240155][ T596] ? queue_delayed_work_on+0xa0/0xa0 [ 86.240158][ T596] ? lockdep_hardirqs_on+0x7c/0x110 [ 86.240165][ T596] __cancel_work_sync+0x18/0xc0 [ 86.240169][ T596] __dev_close_many+0x1ce/0x810 [ 86.240177][ T596] ? netdev_notify_peers+0x20/0x20 [ 86.240185][ T596] ? __local_bh_enable_ip+0xa9/0x120 [ 86.240196][ T596] __dev_change_flags+0x24b/0x6c0 [ 86.240203][ T596] ? netif_set_allmulti+0x360/0x360 [ 86.240213][ T596] netif_change_flags+0x80/0x160 [ 86.240217][ T596] dev_change_flags+0xa8/0x150 [ 86.240222][ T596] cycle_netdev+0x90/0xe0 [vrf] [ 86.240230][ T596] vrf_del_slave+0x40/0x50 [vrf] [ 86.240235][ T596] do_set_master+0x144/0x4f0 [ 86.240240][ T596] do_setlink.constprop.0+0x9ee/0x2460 [ 86.240245][ T596] ? rtnl_newlink_create+0x770/0x770 [ 86.240251][ T596] ? rcu_read_lock_any_held+0x3f/0xa0 [ 86.240258][ T596] ? validate_chain+0x15e/0x4d0 [ 86.240266][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.240274][ T596] ? __mutex_trylock_common+0xf9/0x260 [ 86.240278][ T596] ? __mutex_handoff+0x2b0/0x2b0 [ 86.240281][ T596] ? rcu_is_watching+0x12/0xb0 [ 86.240286][ T596] ? rcu_is_watching+0x12/0xb0 [ 86.240290][ T596] ? trace_contention_end+0xd8/0x140 [ 86.240293][ T596] ? __mutex_lock+0x19f/0x1190 [ 86.240299][ T596] ? __lock_release+0x5d/0x170 [ 86.240303][ T596] ? rtnl_newlink+0x64a/0xa60 [ 86.240306][ T596] ? ww_mutex_lock+0x160/0x160 [ 86.240309][ T596] ? trace_cap_capable+0x10b/0x180 [ 86.240314][ T596] ? __rtnl_newlink+0x40a/0xa30 [ 86.240320][ T596] rtnl_newlink+0x693/0xa60 [ 86.240325][ T596] ? __rtnl_newlink+0xa30/0xa30 [ 86.240327][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.240333][ T596] ? find_held_lock+0x2b/0x80 [ 86.240337][ T596] ? rtnetlink_rcv_msg+0x6e6/0xc00 [ 86.240339][ T596] ? __lock_release+0x5d/0x170 [ 86.240344][ T596] ? __rtnl_newlink+0xa30/0xa30 [ 86.240346][ T596] rtnetlink_rcv_msg+0x709/0xc00 [ 86.240350][ T596] ? rtnl_port_fill+0x850/0x850 [ 86.240353][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.240360][ T596] netlink_rcv_skb+0x121/0x340 [ 86.240364][ T596] ? rtnl_port_fill+0x850/0x850 [ 86.240368][ T596] ? netlink_ack+0xdd0/0xdd0 [ 86.240374][ T596] ? netlink_deliver_tap+0x13e/0x340 [ 86.240377][ T596] ? netlink_deliver_tap+0xc3/0x340 [ 86.240382][ T596] netlink_unicast+0x4aa/0x780 [ 86.240390][ T596] ? netlink_attachskb+0x810/0x810 [ 86.240396][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.240403][ T596] netlink_sendmsg+0x714/0xbd0 [ 86.240409][ T596] ? netlink_unicast+0x780/0x780 [ 86.240416][ T596] ? __import_iovec+0x230/0x3b0 [ 86.240426][ T596] ? netlink_unicast+0x780/0x780 [ 86.240431][ T596] ____sys_sendmsg+0x3dd/0x890 [ 86.240440][ T596] ? get_timestamp.constprop.0+0x380/0x380 [ 86.240445][ T596] ? __copy_msghdr+0x3c0/0x3c0 [ 86.240457][ T596] ___sys_sendmsg+0xed/0x170 [ 86.240461][ T596] ? kasan_record_aux_stack+0x8c/0xa0 [ 86.240467][ T596] ? __call_rcu_common.constprop.0+0xa8/0x630 [ 86.240475][ T596] ? copy_msghdr_from_user+0x110/0x110 [ 86.240484][ T596] ? find_held_lock+0x2b/0x80 [ 86.240489][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.240495][ T596] ? find_held_lock+0x2b/0x80 [ 86.240498][ T596] ? __virt_addr_valid+0x22a/0x450 [ 86.240510][ T596] ? __lock_release+0x5d/0x170 [ 86.240517][ T596] __sys_sendmsg+0x10b/0x1a0 [ 86.240522][ T596] ? __call_rcu_common.constprop.0+0x318/0x630 [ 86.240527][ T596] ? __sys_sendmsg_sock+0x20/0x20 [ 86.240534][ T596] ? rcu_is_watching+0x12/0xb0 [ 86.240539][ T596] do_syscall_64+0xc1/0xfd0 [ 86.240546][ T596] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 86.240551][ T596] RIP: 0033:0x7f284f25a1d7 [ 86.240556][ T596] Code: 0e 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 [ 86.240560][ T596] RSP: 002b:00007ffe3e0964a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 86.240567][ T596] RAX: ffffffffffffffda RBX: 00007ffe3e096bd0 RCX: 00007f284f25a1d7 [ 86.240569][ T596] RDX: 0000000000000000 RSI: 00007ffe3e096510 RDI: 0000000000000005 [ 86.240571][ T596] RBP: 0000000000000004 R08: 0000000000000003 R09: 0000000000000000 [ 86.240573][ T596] R10: 00000000301fe910 R11: 0000000000000246 R12: 0000000000000004 [ 86.240575][ T596] R13: 00000000691cd7ea R14: 0000000000499600 R15: 0000000000000000 [ 86.240581][ T596] [ 86.240583][ T596] ================================================================== [ 86.263718][ T596] Disabling lock debugging due to kernel taint [ 86.264353][ T596] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 86.265007][ T596] #PF: supervisor write access in kernel mode [ 86.265385][ T596] #PF: error_code(0x0002) - not-present page [ 86.266189][ T596] PGD 119d6067 P4D 119d6067 PUD e44b067 PMD 0 [ 86.266596][ T596] Oops: Oops: 0002 [#1] SMP KASAN [ 86.266916][ T596] CPU: 0 UID: 0 PID: 596 Comm: ip Tainted: G B 6.18.0-rc5-virtme #1 PREEMPT(full) [ 86.267762][ T596] Tainted: [B]=BAD_PAGE [ 86.268011][ T596] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 86.268605][ T596] RIP: 0010:try_to_grab_pending+0x81/0x6c0 [ 86.269012][ T596] Code: 00 41 89 c0 b8 01 00 00 00 45 85 c0 74 0f 48 83 c4 10 5b 5d 41 5c 41 5d 41 5e 41 5f c3 be 08 00 00 00 48 89 df e8 7f 7f 81 00 48 0f ba 2b 00 72 11 48 83 c4 10 31 c0 5b 5d 41 5c 41 5d 41 5e [ 86.270148][ T596] RSP: 0018:ffffc90000d1ee90 EFLAGS: 00010046 [ 86.270545][ T596] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffffb5e4090a [ 86.271026][ T596] RDX: fffffbfff740f2cd RSI: 0000000000000008 RDI: ffffffffba079660 [ 86.271736][ T596] RBP: ffffc90000d1eef8 R08: 0000000000000001 R09: fffffbfff740f2cc [ 86.272226][ T596] R10: ffffffffba079667 R11: ffffc90000d1e980 R12: 0000000000000000 [ 86.272702][ T596] R13: 0000000000000286 R14: ffff888012031000 R15: dffffc0000000000 [ 86.273457][ T596] FS: 00007f284f08c800(0000) GS:ffff88807c1f2000(0000) knlGS:0000000000000000 [ 86.273991][ T596] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 86.274267][ T596] CR2: 0000000000000000 CR3: 00000000119d7002 CR4: 0000000000772ef0 [ 86.274717][ T596] PKRU: 55555554 [ 86.274885][ T596] Call Trace: [ 86.275046][ T596] [ 86.275146][ T596] __cancel_work+0x7c/0x260 [ 86.275488][ T596] ? enable_delayed_work+0x10/0x10 [ 86.275701][ T596] ? queue_delayed_work_on+0xa0/0xa0 [ 86.275942][ T596] ? lockdep_hardirqs_on+0x7c/0x110 [ 86.276142][ T596] __cancel_work_sync+0x18/0xc0 [ 86.276338][ T596] __dev_close_many+0x1ce/0x810 [ 86.276704][ T596] ? netdev_notify_peers+0x20/0x20 [ 86.276939][ T596] ? __local_bh_enable_ip+0xa9/0x120 [ 86.277262][ T596] __dev_change_flags+0x24b/0x6c0 [ 86.277605][ T596] ? netif_set_allmulti+0x360/0x360 [ 86.277815][ T596] netif_change_flags+0x80/0x160 [ 86.278025][ T596] dev_change_flags+0xa8/0x150 [ 86.278236][ T596] cycle_netdev+0x90/0xe0 [vrf] [ 86.278443][ T596] vrf_del_slave+0x40/0x50 [vrf] [ 86.278640][ T596] do_set_master+0x144/0x4f0 [ 86.278837][ T596] do_setlink.constprop.0+0x9ee/0x2460 [ 86.279047][ T596] ? rtnl_newlink_create+0x770/0x770 [ 86.279374][ T596] ? rcu_read_lock_any_held+0x3f/0xa0 [ 86.279617][ T596] ? validate_chain+0x15e/0x4d0 [ 86.279822][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.280035][ T596] ? __mutex_trylock_common+0xf9/0x260 [ 86.280498][ T596] ? __mutex_handoff+0x2b0/0x2b0 [ 86.280709][ T596] ? rcu_is_watching+0x12/0xb0 [ 86.280944][ T596] ? rcu_is_watching+0x12/0xb0 [ 86.281138][ T596] ? trace_contention_end+0xd8/0x140 [ 86.281344][ T596] ? __mutex_lock+0x19f/0x1190 [ 86.281572][ T596] ? __lock_release+0x5d/0x170 [ 86.281788][ T596] ? rtnl_newlink+0x64a/0xa60 [ 86.281998][ T596] ? ww_mutex_lock+0x160/0x160 [ 86.282307][ T596] ? trace_cap_capable+0x10b/0x180 [ 86.282506][ T596] ? __rtnl_newlink+0x40a/0xa30 [ 86.282725][ T596] rtnl_newlink+0x693/0xa60 [ 86.282949][ T596] ? __rtnl_newlink+0xa30/0xa30 [ 86.283275][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.283484][ T596] ? find_held_lock+0x2b/0x80 [ 86.283831][ T596] ? rtnetlink_rcv_msg+0x6e6/0xc00 [ 86.284048][ T596] ? __lock_release+0x5d/0x170 [ 86.284480][ T596] ? __rtnl_newlink+0xa30/0xa30 [ 86.284683][ T596] rtnetlink_rcv_msg+0x709/0xc00 [ 86.284888][ T596] ? rtnl_port_fill+0x850/0x850 [ 86.285096][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.285420][ T596] netlink_rcv_skb+0x121/0x340 [ 86.285628][ T596] ? rtnl_port_fill+0x850/0x850 [ 86.285828][ T596] ? netlink_ack+0xdd0/0xdd0 [ 86.286049][ T596] ? netlink_deliver_tap+0x13e/0x340 [ 86.286240][ T596] ? netlink_deliver_tap+0xc3/0x340 [ 86.286433][ T596] netlink_unicast+0x4aa/0x780 [ 86.286640][ T596] ? netlink_attachskb+0x810/0x810 [ 86.286832][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.287048][ T596] netlink_sendmsg+0x714/0xbd0 [ 86.287240][ T596] ? netlink_unicast+0x780/0x780 [ 86.287435][ T596] ? __import_iovec+0x230/0x3b0 [ 86.287642][ T596] ? netlink_unicast+0x780/0x780 [ 86.287971][ T596] ____sys_sendmsg+0x3dd/0x890 [ 86.288181][ T596] ? get_timestamp.constprop.0+0x380/0x380 [ 86.288427][ T596] ? __copy_msghdr+0x3c0/0x3c0 [ 86.288635][ T596] ___sys_sendmsg+0xed/0x170 [ 86.289218][ T596] ? kasan_record_aux_stack+0x8c/0xa0 [ 86.289424][ T596] ? __call_rcu_common.constprop.0+0xa8/0x630 [ 86.289676][ T596] ? copy_msghdr_from_user+0x110/0x110 [ 86.289887][ T596] ? find_held_lock+0x2b/0x80 [ 86.290098][ T596] ? __lock_acquire+0x449/0x7e0 [ 86.290294][ T596] ? find_held_lock+0x2b/0x80 [ 86.290524][ T596] ? __virt_addr_valid+0x22a/0x450 [ 86.290730][ T596] ? __lock_release+0x5d/0x170 [ 86.291343][ T596] __sys_sendmsg+0x10b/0x1a0 [ 86.291555][ T596] ? __call_rcu_common.constprop.0+0x318/0x630 [ 86.291835][ T596] ? __sys_sendmsg_sock+0x20/0x20 [ 86.292176][ T596] ? rcu_is_watching+0x12/0xb0 [ 86.292525][ T596] do_syscall_64+0xc1/0xfd0 [ 86.292748][ T596] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 86.293005][ T596] RIP: 0033:0x7f284f25a1d7 [ 86.293220][ T596] Code: 0e 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b9 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10 [ 86.294130][ T596] RSP: 002b:00007ffe3e0964a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e [ 86.294573][ T596] RAX: ffffffffffffffda RBX: 00007ffe3e096bd0 RCX: 00007f284f25a1d7 [ 86.294900][ T596] RDX: 0000000000000000 RSI: 00007ffe3e096510 RDI: 0000000000000005 [ 86.295211][ T596] RBP: 0000000000000004 R08: 0000000000000003 R09: 0000000000000000 [ 86.295641][ T596] R10: 00000000301fe910 R11: 0000000000000246 R12: 0000000000000004 [ 86.295944][ T596] R13: 00000000691cd7ea R14: 0000000000499600 R15: 0000000000000000 [ 86.296246][ T596] [ 86.296408][ T596] Modules linked in: act_gact cls_flower sch_ingress bridge stp llc 8021q vrf veth [ 86.296782][ T596] CR2: 0000000000000000 [ 86.296946][ T596] ---[ end trace 0000000000000000 ]--- [ 86.297151][ T596] RIP: 0010:try_to_grab_pending+0x81/0x6c0 [ 86.297408][ T596] Code: 00 41 89 c0 b8 01 00 00 00 45 85 c0 74 0f 48 83 c4 10 5b 5d 41 5c 41 5d 41 5e 41 5f c3 be 08 00 00 00 48 89 df e8 7f 7f 81 00 48 0f ba 2b 00 72 11 48 83 c4 10 31 c0 5b 5d 41 5c 41 5d 41 5e [ 86.298109][ T596] RSP: 0018:ffffc90000d1ee90 EFLAGS: 00010046 [ 86.298363][ T596] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffffb5e4090a [ 86.298651][ T596] RDX: fffffbfff740f2cd RSI: 0000000000000008 RDI: ffffffffba079660 [ 86.298947][ T596] RBP: ffffc90000d1eef8 R08: 0000000000000001 R09: fffffbfff740f2cc [ 86.299236][ T596] R10: ffffffffba079667 R11: ffffc90000d1e980 R12: 0000000000000000 [ 86.299605][ T596] R13: 0000000000000286 R14: ffff888012031000 R15: dffffc0000000000 [ 86.300258][ T596] FS: 00007f284f08c800(0000) GS:ffff88807c1f2000(0000) knlGS:0000000000000000 [ 86.300738][ T596] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 86.300998][ T596] CR2: 0000000000000000 CR3: 00000000119d7002 CR4: 0000000000772ef0 [ 86.301338][ T596] PKRU: 55555554 [ 86.301510][ T596] Kernel panic - not syncing: Fatal exception [ 86.302059][ T596] Kernel Offset: 0x34800000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 86.302570][ T596] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr