make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=q_in_vnii_ipv6.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: q_in_vni_ipv6.sh [ 26.226776][ T284] 8021q: 802.1Q VLAN Support v1.8 [ 32.294830][ T328] br1: port 1(vx100) entered blocking state [ 32.296170][ T328] br1: port 1(vx100) entered disabled state [ 32.296621][ T328] vx100: entered allmulticast mode [ 32.298821][ T328] vx100: entered promiscuous mode [ 32.299787][ T328] br1: port 1(vx100) entered blocking state [ 32.300192][ T328] br1: port 1(vx100) entered forwarding state [ 32.669265][ T330] br1: port 2(veth1) entered blocking state [ 32.669613][ T330] br1: port 2(veth1) entered disabled state [ 32.670216][ T330] veth1: entered allmulticast mode [ 32.672381][ T330] veth1: entered promiscuous mode [ 32.828904][ T67] br1: port 2(veth1) entered blocking state [ 32.829352][ T67] br1: port 2(veth1) entered forwarding state [ 33.139751][ T333] br1: port 3(veth2) entered blocking state [ 33.140121][ T333] br1: port 3(veth2) entered disabled state [ 33.140483][ T333] veth2: entered allmulticast mode [ 33.142637][ T333] veth2: entered promiscuous mode [ 33.301471][ T50] br1: port 3(veth2) entered blocking state [ 33.301821][ T50] br1: port 3(veth2) entered forwarding state [ 38.772491][ T376] br2: port 1(w1) entered blocking state [ 38.772820][ T376] br2: port 1(w1) entered disabled state [ 38.773288][ T376] w1: entered allmulticast mode [ 38.775424][ T376] w1: entered promiscuous mode [ 39.886487][ T383] br2: port 2(vx100) entered blocking state [ 39.886826][ T383] br2: port 2(vx100) entered disabled state [ 39.887186][ T383] vx100: entered allmulticast mode [ 39.889303][ T383] vx100: entered promiscuous mode [ 39.889902][ T383] br2: port 2(vx100) entered blocking state [ 39.890230][ T383] br2: port 2(vx100) entered forwarding state [ 41.225841][ T23] br2: port 1(w1) entered blocking state [ 41.226311][ T23] br2: port 1(w1) entered forwarding state [ 45.178224][ T418] br2: port 1(w1) entered blocking state [ 45.178567][ T418] br2: port 1(w1) entered disabled state [ 45.178933][ T418] w1: entered allmulticast mode [ 45.181456][ T418] w1: entered promiscuous mode [ 46.310541][ T425] br2: port 2(vx100) entered blocking state [ 46.310885][ T425] br2: port 2(vx100) entered disabled state [ 46.311243][ T425] vx100: entered allmulticast mode [ 46.313280][ T425] vx100: entered promiscuous mode [ 46.313888][ T425] br2: port 2(vx100) entered blocking state [ 46.314209][ T425] br2: port 2(vx100) entered forwarding state [ 47.610027][ T49] br2: port 1(w1) entered blocking state [ 47.610371][ T49] br2: port 1(w1) entered forwarding state # Running tests with UDP port 4789 # TEST: ping6: local->local [ OK ] # TEST: ping6: local->remote 1 [ OK ] # TEST: ping6: local->remote 2 [ OK ] [ 62.707252][ T71] vx100: left allmulticast mode [ 62.707620][ T71] vx100: left promiscuous mode [ 62.708893][ T71] br2: port 2(vx100) entered disabled state [ 62.720175][ T71] w1: left allmulticast mode [ 62.720441][ T71] w1: left promiscuous mode [ 62.720809][ T71] br2: port 1(w1) entered disabled state [ 62.806516][ T71] ================================================================== [ 62.806945][ T71] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.807413][ T71] Read of size 8 at addr ffff888009f20bd0 by task kworker/u8:1/71 [ 62.807815][ T71] [ 62.807961][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Not tainted 6.8.0-rc2-virtme #1 [ 62.808397][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 62.809036][ T71] Workqueue: netns cleanup_net [ 62.809288][ T71] Call Trace: [ 62.809457][ T71] [ 62.809622][ T71] dump_stack_lvl+0x64/0xb0 [ 62.809861][ T71] print_address_description.constprop.0+0x2c/0x3b0 [ 62.810221][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.810593][ T71] print_report+0xb5/0x270 [ 62.810817][ T71] ? kasan_addr_to_slab+0x4e/0x90 [ 62.811103][ T71] kasan_report+0xbe/0xf0 [ 62.811335][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.811674][ T71] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.812019][ T71] ? __pfx_vlan_device_event+0x10/0x10 [8021q] [ 62.812381][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 62.812719][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 62.813042][ T71] notifier_call_chain+0x9a/0x290 [ 62.813322][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 62.813648][ T71] ? mutex_is_locked+0x17/0x50 [ 62.813929][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 62.814294][ T71] ? vrf_dellink+0x101/0x150 [vrf] [ 62.814613][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 62.815046][ T71] default_device_exit_batch+0x228/0x2c0 [ 62.815330][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 62.815674][ T71] ? mutex_is_locked+0x17/0x50 [ 62.815958][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 62.816294][ T71] cleanup_net+0x4f3/0xa20 [ 62.816519][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 62.816802][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 62.817087][ T71] ? lock_acquire+0x1c1/0x220 [ 62.817339][ T71] ? process_one_work+0x714/0x1310 [ 62.817612][ T71] process_one_work+0x78c/0x1310 [ 62.817894][ T71] ? hlock_class+0x4e/0x130 [ 62.818147][ T71] ? __pfx_process_one_work+0x10/0x10 [ 62.818471][ T71] ? assign_work+0x16c/0x240 [ 62.818734][ T71] worker_thread+0x73d/0x1010 [ 62.819015][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 62.819386][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.819698][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.819981][ T71] kthread+0x28f/0x360 [ 62.820189][ T71] ? __pfx_kthread+0x10/0x10 [ 62.820450][ T71] ret_from_fork+0x31/0x70 [ 62.820686][ T71] ? __pfx_kthread+0x10/0x10 [ 62.820916][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.821162][ T71] [ 62.821319][ T71] [ 62.821440][ T71] Allocated by task 71: [ 62.821648][ T71] kasan_save_stack+0x24/0x50 [ 62.821886][ T71] kasan_save_track+0x14/0x30 [ 62.822122][ T71] __kasan_kmalloc+0x7f/0x90 [ 62.822353][ T71] __kmalloc_node_track_caller+0x1fb/0x440 [ 62.822647][ T71] kmalloc_reserve+0xbc/0x1f0 [ 62.822885][ T71] pskb_expand_head+0x1f4/0xff0 [ 62.823130][ T71] netlink_trim+0x198/0x200 [ 62.823360][ T71] netlink_broadcast_filtered+0xcb/0x340 [ 62.823648][ T71] nlmsg_notify+0x6e/0x1e0 [ 62.823872][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 62.824092][ T71] __dev_notify_flags+0x1ba/0x250 [ 62.824344][ T71] dev_change_flags+0xec/0x160 [ 62.824583][ T71] cycle_netdev+0x94/0xf0 [vrf] [ 62.824832][ T71] vrf_dellink+0xdb/0x150 [vrf] [ 62.825080][ T71] default_device_exit_batch+0x16a/0x2c0 [ 62.825365][ T71] cleanup_net+0x4f3/0xa20 [ 62.825617][ T71] process_one_work+0x78c/0x1310 [ 62.825893][ T71] worker_thread+0x73d/0x1010 [ 62.826148][ T71] kthread+0x28f/0x360 [ 62.826364][ T71] ret_from_fork+0x31/0x70 [ 62.826601][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.826851][ T71] [ 62.826991][ T71] Freed by task 71: [ 62.827202][ T71] kasan_save_stack+0x24/0x50 [ 62.827445][ T71] kasan_save_track+0x14/0x30 [ 62.827704][ T71] kasan_save_free_info+0x3f/0x60 [ 62.828001][ T71] __kasan_slab_free+0xfc/0x1c0 [ 62.828256][ T71] kfree+0xf2/0x2d0 [ 62.828520][ T71] skb_release_data+0x56b/0x770 [ 62.828785][ T71] consume_skb+0xad/0x110 [ 62.829032][ T71] netlink_broadcast_filtered+0x224/0x340 [ 62.829381][ T71] nlmsg_notify+0x6e/0x1e0 [ 62.829603][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 62.829830][ T71] __dev_notify_flags+0x1ba/0x250 [ 62.830115][ T71] dev_change_flags+0xec/0x160 [ 62.830365][ T71] cycle_netdev+0x94/0xf0 [vrf] [ 62.830640][ T71] vrf_dellink+0xdb/0x150 [vrf] [ 62.831008][ T71] default_device_exit_batch+0x16a/0x2c0 [ 62.831324][ T71] cleanup_net+0x4f3/0xa20 [ 62.831547][ T71] process_one_work+0x78c/0x1310 [ 62.831820][ T71] worker_thread+0x73d/0x1010 [ 62.832118][ T71] kthread+0x28f/0x360 [ 62.832357][ T71] ret_from_fork+0x31/0x70 [ 62.832599][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.832877][ T71] [ 62.833024][ T71] The buggy address belongs to the object at ffff888009f20800 [ 62.833024][ T71] which belongs to the cache kmalloc-2k of size 2048 [ 62.833805][ T71] The buggy address is located 976 bytes inside of [ 62.833805][ T71] freed 2048-byte region [ffff888009f20800, ffff888009f21000) [ 62.834552][ T71] [ 62.834672][ T71] The buggy address belongs to the physical page: [ 62.835021][ T71] page:ffffea000027c800 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x9f20 [ 62.835599][ T71] head:ffffea000027c800 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 62.836100][ T71] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 62.836462][ T71] page_type: 0xffffffff() [ 62.836720][ T71] raw: 0080000000000840 ffff888001043540 ffffea0000185c10 ffffea00001d8c10 [ 62.837168][ T71] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 62.837621][ T71] page dumped because: kasan: bad access detected [ 62.837980][ T71] [ 62.838122][ T71] Memory state around the buggy address: [ 62.838402][ T71] ffff888009f20a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.838828][ T71] ffff888009f20b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.839253][ T71] >ffff888009f20b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.839693][ T71] ^ [ 62.840025][ T71] ffff888009f20c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.840451][ T71] ffff888009f20c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.840871][ T71] ================================================================== [ 62.841744][ T71] Disabling lock debugging due to kernel taint [ 62.842099][ T71] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 62.842780][ T71] KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] [ 62.843225][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Tainted: G B 6.8.0-rc2-virtme #1 [ 62.843723][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 62.844367][ T71] Workqueue: netns cleanup_net [ 62.844613][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 62.844993][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 62.846013][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010246 [ 62.846336][ T71] RAX: 0000000000000000 RBX: ffffffffffffffd0 RCX: dffffc0000000000 [ 62.846778][ T71] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff888009f20c24 [ 62.847223][ T71] RBP: 1ffff920000a3f33 R08: 1ffff1100131781a R09: ffffc9000051f9b8 [ 62.847643][ T71] R10: ffffffffb013ca07 R11: 205d313754202020 R12: ffffed100131781a [ 62.848063][ T71] R13: ffff888009f20ba0 R14: ffff8880072c1000 R15: ffff8880098bc000 [ 62.848456][ T71] FS: 0000000000000000(0000) GS:ffff888035a00000(0000) knlGS:0000000000000000 [ 62.848897][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 62.849224][ T71] CR2: 000056399ab87dec CR3: 0000000007f2a006 CR4: 0000000000770ef0 [ 62.849621][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 62.850014][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 62.850407][ T71] PKRU: 55555554 [ 62.850587][ T71] Call Trace: [ 62.850755][ T71] [ 62.850903][ T71] ? die_addr+0x41/0xa0 [ 62.851115][ T71] ? exc_general_protection+0x149/0x220 [ 62.851397][ T71] ? asm_exc_general_protection+0x26/0x30 [ 62.851686][ T71] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 62.852006][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 62.852342][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 62.852628][ T71] notifier_call_chain+0x9a/0x290 [ 62.852885][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 62.853240][ T71] ? mutex_is_locked+0x17/0x50 [ 62.853482][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 62.853823][ T71] ? vrf_dellink+0x101/0x150 [vrf] [ 62.854106][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 62.854452][ T71] default_device_exit_batch+0x228/0x2c0 [ 62.854750][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 62.855078][ T71] ? mutex_is_locked+0x17/0x50 [ 62.855342][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 62.855654][ T71] cleanup_net+0x4f3/0xa20 [ 62.855905][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 62.856213][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 62.856496][ T71] ? lock_acquire+0x1c1/0x220 [ 62.856746][ T71] ? process_one_work+0x714/0x1310 [ 62.857015][ T71] process_one_work+0x78c/0x1310 [ 62.857299][ T71] ? hlock_class+0x4e/0x130 [ 62.857529][ T71] ? __pfx_process_one_work+0x10/0x10 [ 62.857798][ T71] ? assign_work+0x16c/0x240 [ 62.858057][ T71] worker_thread+0x73d/0x1010 [ 62.858319][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 62.858678][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.858953][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.859219][ T71] kthread+0x28f/0x360 [ 62.859448][ T71] ? __pfx_kthread+0x10/0x10 [ 62.859716][ T71] ret_from_fork+0x31/0x70 [ 62.859942][ T71] ? __pfx_kthread+0x10/0x10 [ 62.860218][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.860479][ T71] [ 62.860664][ T71] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel bridge stp llc 8021q sch_ingress vrf veth [ 62.861237][ T71] ---[ end trace 0000000000000000 ]--- [ 62.861547][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 62.861896][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 62.863414][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010246 [ 62.863764][ T71] RAX: 0000000000000000 RBX: ffffffffffffffd0 RCX: dffffc0000000000 [ 62.864186][ T71] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff888009f20c24 [ 62.864624][ T71] RBP: 1ffff920000a3f33 R08: 1ffff1100131781a R09: ffffc9000051f9b8 [ 62.865055][ T71] R10: ffffffffb013ca07 R11: 205d313754202020 R12: ffffed100131781a [ 62.865468][ T71] R13: ffff888009f20ba0 R14: ffff8880072c1000 R15: ffff8880098bc000 [ 62.865894][ T71] FS: 0000000000000000(0000) GS:ffff888035a00000(0000) knlGS:0000000000000000 [ 62.866518][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 62.866900][ T71] CR2: 000056399ab87dec CR3: 0000000007f2a006 CR4: 0000000000770ef0 [ 62.867302][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 62.867700][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 62.868133][ T71] PKRU: 55555554 [ 62.868315][ T71] Kernel panic - not syncing: Fatal exception [ 62.868751][ T71] Kernel Offset: 0x29a00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 62.869325][ T71] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout