make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=vxlan_assymmetric.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: vxlan_asymmetric.sh [ 25.541611][ T234] ip (234) used greatest stack depth: 23536 bytes left [ 35.281821][ T310] br1: port 1(vx10) entered blocking state [ 35.282258][ T310] br1: port 1(vx10) entered disabled state [ 35.282896][ T310] vx10: entered allmulticast mode [ 35.285064][ T310] vx10: entered promiscuous mode [ 35.285996][ T310] br1: port 1(vx10) entered blocking state [ 35.286375][ T310] br1: port 1(vx10) entered forwarding state [ 35.974501][ T315] br1: port 2(vx20) entered blocking state [ 35.974849][ T315] br1: port 2(vx20) entered disabled state [ 35.975314][ T315] vx20: entered allmulticast mode [ 35.978839][ T315] vx20: entered promiscuous mode [ 35.980799][ T315] br1: port 2(vx20) entered blocking state [ 35.981135][ T315] br1: port 2(vx20) entered forwarding state [ 36.337131][ T317] br1: port 3(veth1) entered blocking state [ 36.338216][ T317] br1: port 3(veth1) entered disabled state [ 36.338596][ T317] veth1: entered allmulticast mode [ 36.340747][ T317] veth1: entered promiscuous mode [ 36.519367][ T42] br1: port 3(veth1) entered blocking state [ 36.519800][ T42] br1: port 3(veth1) entered forwarding state [ 36.864586][ T320] br1: port 4(veth2) entered blocking state [ 36.865099][ T320] br1: port 4(veth2) entered disabled state [ 36.865641][ T320] veth2: entered allmulticast mode [ 36.869137][ T320] veth2: entered promiscuous mode [ 37.063221][ T8] br1: port 4(veth2) entered blocking state [ 37.063767][ T8] br1: port 4(veth2) entered forwarding state [ 38.499016][ T330] 8021q: 802.1Q VLAN Support v1.8 [ 39.004552][ T333] br1: entered promiscuous mode [ 39.013317][ T333] br1: left promiscuous mode [ 39.026040][ T333] br1: entered promiscuous mode [ 50.906467][ T408] br1: port 1(vx10) entered blocking state [ 50.906966][ T408] br1: port 1(vx10) entered disabled state [ 50.908829][ T408] vx10: entered allmulticast mode [ 50.912898][ T408] vx10: entered promiscuous mode [ 50.914025][ T408] br1: port 1(vx10) entered blocking state [ 50.914346][ T408] br1: port 1(vx10) entered forwarding state [ 51.647068][ T412] br1: port 2(vx20) entered blocking state [ 51.647594][ T412] br1: port 2(vx20) entered disabled state [ 51.648116][ T412] vx20: entered allmulticast mode [ 51.653104][ T412] vx20: entered promiscuous mode [ 51.654805][ T412] br1: port 2(vx20) entered blocking state [ 51.655269][ T412] br1: port 2(vx20) entered forwarding state [ 52.009225][ T414] br1: port 3(w1) entered blocking state [ 52.009641][ T414] br1: port 3(w1) entered disabled state [ 52.010063][ T414] w1: entered allmulticast mode [ 52.012152][ T414] w1: entered promiscuous mode [ 52.179365][ T8] br1: port 3(w1) entered blocking state [ 52.179745][ T8] br1: port 3(w1) entered forwarding state [ 52.518346][ T417] br1: port 4(w3) entered blocking state [ 52.518718][ T417] br1: port 4(w3) entered disabled state [ 52.519108][ T417] w3: entered allmulticast mode [ 52.522333][ T417] w3: entered promiscuous mode [ 52.723911][ T43] br1: port 4(w3) entered blocking state [ 52.724252][ T43] br1: port 4(w3) entered forwarding state [ 54.341428][ T428] br1: entered promiscuous mode [ 54.344611][ T428] br1: left promiscuous mode [ 54.354111][ T428] br1: entered promiscuous mode [ 55.716153][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 55.718005][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 56.083964][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 56.483555][ C1] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 56.485178][ C1] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 56.530965][ C1] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 59.683068][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 60.834824][ C1] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 68.003254][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) # TEST: ping: local->local vid 10->vid 20 [ OK ] [ 70.050873][ C1] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) # TEST: ping: local->remote vid 10->vid 10 [ OK ] # TEST: ping: local->remote vid 20->vid 20 [ OK ] # TEST: ping: local->remote vid 10->vid 20 [ OK ] # TEST: ping: local->remote vid 20->vid 10 [ OK ] # INFO: deleting neighbours from vlan interfaces # TEST: ping: local->local vid 10->vid 20 [ OK ] # TEST: ping: local->remote vid 10->vid 10 [ OK ] # TEST: ping: local->remote vid 20->vid 20 [ OK ] # TEST: ping: local->remote vid 10->vid 20 [ OK ] # TEST: ping: local->remote vid 20->vid 10 [ OK ] [ 84.386876][ C1] br1: received packet on vx10 with own address as source address (addr:00:00:5e:00:01:01, vlan:10) [ 87.460011][ C1] br1: received packet on vx20 with own address as source address (addr:00:00:5e:00:01:01, vlan:20) [ 88.987955][ T589] GACT probability NOT on # TEST: neigh_suppress: on / neigh exists: yes [ OK ] # TEST: neigh_suppress: on / neigh exists: no [ OK ] # TEST: neigh_suppress: off / neigh exists: no [ OK ] # TEST: neigh_suppress: off / neigh exists: yes [ OK ] [ 97.518833][ T11] w3: left allmulticast mode [ 97.519362][ T11] w3: left promiscuous mode [ 97.520047][ T11] br1: port 4(w3) entered disabled state [ 97.538582][ T11] w1: left allmulticast mode [ 97.539019][ T11] w1: left promiscuous mode [ 97.539511][ T11] br1: port 3(w1) entered disabled state [ 97.553822][ T11] vx20: left allmulticast mode [ 97.554183][ T11] vx20: left promiscuous mode [ 97.554716][ T11] br1: port 2(vx20) entered disabled state [ 97.567688][ T11] vx10: left allmulticast mode [ 97.568158][ T11] vx10: left promiscuous mode [ 97.568813][ T11] br1: port 1(vx10) entered disabled state [ 97.732291][ T11] ================================================================== [ 97.732803][ T11] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 97.733326][ T11] Read of size 8 at addr ffff888005f48bd0 by task kworker/u8:0/11 [ 97.733748][ T11] [ 97.733877][ T11] CPU: 0 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 97.734302][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 97.734993][ T11] Workqueue: netns cleanup_net [ 97.735264][ T11] Call Trace: [ 97.735446][ T11] [ 97.735610][ T11] dump_stack_lvl+0x64/0xb0 [ 97.735865][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 97.736241][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 97.736600][ T11] print_report+0xb5/0x270 [ 97.736844][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 97.737111][ T11] kasan_report+0xbe/0xf0 [ 97.737346][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 97.737707][ T11] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 97.738044][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 97.738407][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 97.738698][ T11] notifier_call_chain+0x9a/0x290 [ 97.738972][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 97.739297][ T11] ? mutex_is_locked+0x17/0x50 [ 97.739545][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 97.739886][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 97.740157][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 97.740478][ T11] default_device_exit_batch+0x228/0x2c0 [ 97.740765][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 97.741081][ T11] ? mutex_is_locked+0x17/0x50 [ 97.741324][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 97.741628][ T11] cleanup_net+0x4f3/0xa20 [ 97.741857][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 97.742143][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 97.742397][ T11] ? lock_acquire+0x1c1/0x220 [ 97.742638][ T11] ? process_one_work+0x714/0x1310 [ 97.742903][ T11] process_one_work+0x78c/0x1310 [ 97.743157][ T11] ? hlock_class+0x4e/0x130 [ 97.743388][ T11] ? __pfx_process_one_work+0x10/0x10 [ 97.743665][ T11] ? assign_work+0x16c/0x240 [ 97.743901][ T11] worker_thread+0x73d/0x1010 [ 97.744144][ T11] ? __pfx_worker_thread+0x10/0x10 [ 97.744405][ T11] kthread+0x28f/0x360 [ 97.744613][ T11] ? __pfx_kthread+0x10/0x10 [ 97.744853][ T11] ret_from_fork+0x31/0x70 [ 97.745083][ T11] ? __pfx_kthread+0x10/0x10 [ 97.745316][ T11] ret_from_fork_asm+0x1b/0x30 [ 97.745570][ T11] [ 97.745729][ T11] [ 97.745850][ T11] Allocated by task 11: [ 97.746092][ T11] kasan_save_stack+0x24/0x50 [ 97.746333][ T11] kasan_save_track+0x14/0x30 [ 97.746571][ T11] __kasan_kmalloc+0x7f/0x90 [ 97.746806][ T11] __kmalloc_node_track_caller+0x1fb/0x440 [ 97.747120][ T11] kmalloc_reserve+0xbc/0x1f0 [ 97.747384][ T11] pskb_expand_head+0x1f4/0xff0 [ 97.747640][ T11] netlink_trim+0x198/0x200 [ 97.747888][ T11] netlink_broadcast_filtered+0xcb/0x340 [ 97.748198][ T11] nlmsg_notify+0x6e/0x1e0 [ 97.748427][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 97.748662][ T11] __dev_notify_flags+0x1ba/0x250 [ 97.748932][ T11] dev_change_flags+0xec/0x160 [ 97.749189][ T11] cycle_netdev+0x94/0xf0 [vrf] [ 97.749462][ T11] vrf_dellink+0xdb/0x150 [vrf] [ 97.749728][ T11] default_device_exit_batch+0x16a/0x2c0 [ 97.750025][ T11] cleanup_net+0x4f3/0xa20 [ 97.750272][ T11] process_one_work+0x78c/0x1310 [ 97.750540][ T11] worker_thread+0x73d/0x1010 [ 97.750791][ T11] kthread+0x28f/0x360 [ 97.751010][ T11] ret_from_fork+0x31/0x70 [ 97.751246][ T11] ret_from_fork_asm+0x1b/0x30 [ 97.751506][ T11] [ 97.751636][ T11] Freed by task 11: [ 97.751841][ T11] kasan_save_stack+0x24/0x50 [ 97.752096][ T11] kasan_save_track+0x14/0x30 [ 97.752348][ T11] kasan_save_free_info+0x3f/0x60 [ 97.752625][ T11] __kasan_slab_free+0xfc/0x1c0 [ 97.752887][ T11] kfree+0xf2/0x2d0 [ 97.753095][ T11] skb_release_data+0x56b/0x770 [ 97.753359][ T11] consume_skb+0xad/0x110 [ 97.753597][ T11] netlink_broadcast_filtered+0x224/0x340 [ 97.753907][ T11] nlmsg_notify+0x6e/0x1e0 [ 97.754147][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 97.754380][ T11] __dev_notify_flags+0x1ba/0x250 [ 97.754652][ T11] dev_change_flags+0xec/0x160 [ 97.754907][ T11] cycle_netdev+0x94/0xf0 [vrf] [ 97.755169][ T11] vrf_dellink+0xdb/0x150 [vrf] [ 97.755436][ T11] default_device_exit_batch+0x16a/0x2c0 [ 97.755739][ T11] cleanup_net+0x4f3/0xa20 [ 97.755979][ T11] process_one_work+0x78c/0x1310 [ 97.756259][ T11] worker_thread+0x73d/0x1010 [ 97.756517][ T11] kthread+0x28f/0x360 [ 97.756737][ T11] ret_from_fork+0x31/0x70 [ 97.756981][ T11] ret_from_fork_asm+0x1b/0x30 [ 97.757244][ T11] [ 97.757372][ T11] The buggy address belongs to the object at ffff888005f48800 [ 97.757372][ T11] which belongs to the cache kmalloc-2k of size 2048 [ 97.758126][ T11] The buggy address is located 976 bytes inside of [ 97.758126][ T11] freed 2048-byte region [ffff888005f48800, ffff888005f49000) [ 97.758863][ T11] [ 97.758994][ T11] The buggy address belongs to the physical page: [ 97.759340][ T11] page:ffffea000017d200 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x5f48 [ 97.759872][ T11] head:ffffea000017d200 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 97.760352][ T11] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 97.760681][ T11] page_type: 0xffffffff() [ 97.760900][ T11] raw: 0080000000000840 ffff888001043540 ffffea0000178a10 ffffea000020f410 [ 97.761331][ T11] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 97.761766][ T11] page dumped because: kasan: bad access detected [ 97.762100][ T11] [ 97.762221][ T11] Memory state around the buggy address: [ 97.762503][ T11] ffff888005f48a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 97.762919][ T11] ffff888005f48b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 97.763351][ T11] >ffff888005f48b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 97.763772][ T11] ^ [ 97.764107][ T11] ffff888005f48c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 97.764540][ T11] ffff888005f48c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 97.764964][ T11] ================================================================== [ 97.765494][ T11] Disabling lock debugging due to kernel taint [ 97.765949][ T11] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 97.766680][ T11] KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] [ 97.767128][ T11] CPU: 0 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 97.767633][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 97.768283][ T11] Workqueue: netns cleanup_net [ 97.768543][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 97.768915][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 97.769941][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010246 [ 97.770265][ T11] RAX: 0000000000000000 RBX: ffffffffffffffd0 RCX: dffffc0000000000 [ 97.770688][ T11] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff888005f48c24 [ 97.771116][ T11] RBP: 1ffff92000017f33 R08: 1ffff11000ead21a R09: ffffc900000bf9b8 [ 97.771546][ T11] R10: ffffffffa393ca07 R11: 205d313154202020 R12: ffffed1000ead21a [ 97.771966][ T11] R13: ffff888005f48ba0 R14: ffff88800a034000 R15: ffff888007569000 [ 97.772383][ T11] FS: 0000000000000000(0000) GS:ffff888035200000(0000) knlGS:0000000000000000 [ 97.772861][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 97.773213][ T11] CR2: 00007f0de6bee270 CR3: 000000001ab1e004 CR4: 0000000000770ef0 [ 97.773636][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 97.774066][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 97.774489][ T11] PKRU: 55555554 [ 97.774683][ T11] Call Trace: [ 97.774864][ T11] [ 97.775019][ T11] ? die_addr+0x41/0xa0 [ 97.775258][ T11] ? exc_general_protection+0x149/0x220 [ 97.775556][ T11] ? asm_exc_general_protection+0x26/0x30 [ 97.775868][ T11] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 97.776229][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 97.776581][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 97.776896][ T11] notifier_call_chain+0x9a/0x290 [ 97.777170][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 97.777514][ T11] ? mutex_is_locked+0x17/0x50 [ 97.777774][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 97.778119][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 97.778398][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 97.778716][ T11] default_device_exit_batch+0x228/0x2c0 [ 97.779000][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 97.779312][ T11] ? mutex_is_locked+0x17/0x50 [ 97.779556][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 97.779856][ T11] cleanup_net+0x4f3/0xa20 [ 97.780082][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 97.780370][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 97.780622][ T11] ? lock_acquire+0x1c1/0x220 [ 97.780858][ T11] ? process_one_work+0x714/0x1310 [ 97.781120][ T11] process_one_work+0x78c/0x1310 [ 97.781371][ T11] ? hlock_class+0x4e/0x130 [ 97.781602][ T11] ? __pfx_process_one_work+0x10/0x10 [ 97.781874][ T11] ? assign_work+0x16c/0x240 [ 97.782110][ T11] worker_thread+0x73d/0x1010 [ 97.782351][ T11] ? __pfx_worker_thread+0x10/0x10 [ 97.782610][ T11] kthread+0x28f/0x360 [ 97.782818][ T11] ? __pfx_kthread+0x10/0x10 [ 97.783053][ T11] ret_from_fork+0x31/0x70 [ 97.783277][ T11] ? __pfx_kthread+0x10/0x10 [ 97.783511][ T11] ret_from_fork_asm+0x1b/0x30 [ 97.783760][ T11] [ 97.783914][ T11] Modules linked in: act_gact cls_flower sch_ingress macvlan 8021q vxlan ip6_udp_tunnel udp_tunnel bridge stp llc vrf veth [ 97.784683][ T11] ---[ end trace 0000000000000000 ]--- [ 97.785146][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 97.785656][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 97.786780][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010246 [ 97.787190][ T11] RAX: 0000000000000000 RBX: ffffffffffffffd0 RCX: dffffc0000000000 [ 97.787687][ T11] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff888005f48c24 [ 97.788166][ T11] RBP: 1ffff92000017f33 R08: 1ffff11000ead21a R09: ffffc900000bf9b8 [ 97.788790][ T11] R10: ffffffffa393ca07 R11: 205d313154202020 R12: ffffed1000ead21a [ 97.789381][ T11] R13: ffff888005f48ba0 R14: ffff88800a034000 R15: ffff888007569000 [ 97.789979][ T11] FS: 0000000000000000(0000) GS:ffff888035200000(0000) knlGS:0000000000000000 [ 97.790640][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 97.791113][ T11] CR2: 00007f0de6bee270 CR3: 000000001ab1e004 CR4: 0000000000770ef0 [ 97.791719][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 97.792225][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 97.792712][ T11] PKRU: 55555554 [ 97.792904][ T11] Kernel panic - not syncing: Fatal exception [ 97.793355][ T11] Kernel Offset: 0x1d200000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 97.793951][ T11] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout