make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=q_in_vnii.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: q_in_vni.sh [ 3939.824223][T12916] 8021q: 802.1Q VLAN Support v1.8 [ 3945.253623][T12961] br1: port 1(vx100) entered blocking state [ 3945.254066][T12961] br1: port 1(vx100) entered disabled state [ 3945.254439][T12961] vx100: entered allmulticast mode [ 3945.256765][T12961] vx100: entered promiscuous mode [ 3945.257812][T12961] br1: port 1(vx100) entered blocking state [ 3945.258232][T12961] br1: port 1(vx100) entered forwarding state [ 3945.571478][T12963] br1: port 2(veth1) entered blocking state [ 3945.571818][T12963] br1: port 2(veth1) entered disabled state [ 3945.572186][T12963] veth1: entered allmulticast mode [ 3945.574669][T12963] veth1: entered promiscuous mode [ 3945.727816][ T50] br1: port 2(veth1) entered blocking state [ 3945.728269][ T50] br1: port 2(veth1) entered forwarding state [ 3946.015900][T12966] br1: port 3(veth2) entered blocking state [ 3946.016910][T12966] br1: port 3(veth2) entered disabled state [ 3946.017276][T12966] veth2: entered allmulticast mode [ 3946.019340][T12966] veth2: entered promiscuous mode [ 3946.174117][ T8] br1: port 3(veth2) entered blocking state [ 3946.174478][ T8] br1: port 3(veth2) entered forwarding state [ 3951.236082][T13015] br2: port 1(w1) entered blocking state [ 3951.237146][T13015] br2: port 1(w1) entered disabled state [ 3951.237498][T13015] w1: entered allmulticast mode [ 3951.239586][T13015] w1: entered promiscuous mode [ 3952.284135][T13022] br2: port 2(vx100) entered blocking state [ 3952.285238][T13022] br2: port 2(vx100) entered disabled state [ 3952.285602][T13022] vx100: entered allmulticast mode [ 3952.287662][T13022] vx100: entered promiscuous mode [ 3952.288268][T13022] br2: port 2(vx100) entered blocking state [ 3952.288581][T13022] br2: port 2(vx100) entered forwarding state [ 3953.550557][T12792] br2: port 1(w1) entered blocking state [ 3953.551187][T12792] br2: port 1(w1) entered forwarding state [ 3957.176825][T13057] br2: port 1(w1) entered blocking state [ 3957.178110][T13057] br2: port 1(w1) entered disabled state [ 3957.178474][T13057] w1: entered allmulticast mode [ 3957.180518][T13057] w1: entered promiscuous mode [ 3958.224250][T13064] br2: port 2(vx100) entered blocking state [ 3958.224595][T13064] br2: port 2(vx100) entered disabled state [ 3958.224945][T13064] vx100: entered allmulticast mode [ 3958.233274][T13064] vx100: entered promiscuous mode [ 3958.233946][T13064] br2: port 2(vx100) entered blocking state [ 3958.234279][T13064] br2: port 2(vx100) entered forwarding state [ 3959.430357][T12792] br2: port 1(w1) entered blocking state [ 3959.430704][T12792] br2: port 1(w1) entered forwarding state # Running tests with UDP port 4789 # TEST: ping: local->local [ OK ] # TEST: ping: local->remote 1 [ OK ] # TEST: ping: local->remote 2 [ OK ] [ 3973.887310][ T11] vx100: left allmulticast mode [ 3973.887649][ T11] vx100: left promiscuous mode [ 3973.888082][ T11] br2: port 2(vx100) entered disabled state [ 3973.912031][ T11] w1: left allmulticast mode [ 3973.912350][ T11] w1: left promiscuous mode [ 3973.912729][ T11] br2: port 1(w1) entered disabled state [ 3974.021067][ T11] ================================================================== [ 3974.021513][ T11] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3974.022070][ T11] Read of size 8 at addr ffff8880046b0bd0 by task kworker/u8:0/11 [ 3974.022485][ T11] [ 3974.022610][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 3974.023059][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 3974.023702][ T11] Workqueue: netns cleanup_net [ 3974.024012][ T11] Call Trace: [ 3974.024226][ T11] <TASK> [ 3974.024376][ T11] dump_stack_lvl+0x64/0xb0 [ 3974.024682][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 3974.025120][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3974.025450][ T11] print_report+0xb5/0x270 [ 3974.025742][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 3974.026049][ T11] kasan_report+0xbe/0xf0 [ 3974.026331][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3974.026715][ T11] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3974.027042][ T11] ? __pfx_vlan_device_event+0x10/0x10 [8021q] [ 3974.027392][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 3974.027769][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 3974.028125][ T11] notifier_call_chain+0x9a/0x290 [ 3974.028415][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 3974.028763][ T11] ? mutex_is_locked+0x17/0x50 [ 3974.029006][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 3974.029395][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 3974.029664][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 3974.029979][ T11] default_device_exit_batch+0x228/0x2c0 [ 3974.030263][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 3974.030611][ T11] ? mutex_is_locked+0x17/0x50 [ 3974.030899][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 3974.031219][ T11] cleanup_net+0x4f3/0xa20 [ 3974.031446][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 3974.031740][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 3974.032029][ T11] ? lock_acquire+0x1c1/0x220 [ 3974.032287][ T11] ? process_one_work+0x714/0x1310 [ 3974.032629][ T11] process_one_work+0x78c/0x1310 [ 3974.032931][ T11] ? hlock_class+0x4e/0x130 [ 3974.033215][ T11] ? __pfx_process_one_work+0x10/0x10 [ 3974.033574][ T11] ? assign_work+0x16c/0x240 [ 3974.033857][ T11] worker_thread+0x73d/0x1010 [ 3974.034119][ T11] ? __pfx_worker_thread+0x10/0x10 [ 3974.034407][ T11] kthread+0x28f/0x360 [ 3974.034617][ T11] ? __pfx_kthread+0x10/0x10 [ 3974.034885][ T11] ret_from_fork+0x31/0x70 [ 3974.035157][ T11] ? __pfx_kthread+0x10/0x10 [ 3974.035449][ T11] ret_from_fork_asm+0x1b/0x30 [ 3974.035704][ T11] </TASK> [ 3974.035912][ T11] [ 3974.036070][ T11] Allocated by task 11: [ 3974.036280][ T11] kasan_save_stack+0x24/0x50 [ 3974.036571][ T11] kasan_save_track+0x14/0x30 [ 3974.036861][ T11] __kasan_kmalloc+0x7f/0x90 [ 3974.037148][ T11] __kmalloc_node_track_caller+0x1fb/0x440 [ 3974.037475][ T11] kmalloc_reserve+0xbc/0x1f0 [ 3974.037749][ T11] pskb_expand_head+0x1f4/0xff0 [ 3974.038005][ T11] netlink_trim+0x198/0x200 [ 3974.038266][ T11] netlink_broadcast_filtered+0xcb/0x340 [ 3974.038589][ T11] nlmsg_notify+0x6e/0x1e0 [ 3974.038855][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 3974.039076][ T11] __dev_notify_flags+0x1ba/0x250 [ 3974.039371][ T11] dev_change_flags+0xec/0x160 [ 3974.039667][ T11] cycle_netdev+0x94/0xf0 [vrf] [ 3974.040009][ T11] vrf_dellink+0xdb/0x150 [vrf] [ 3974.040307][ T11] default_device_exit_batch+0x16a/0x2c0 [ 3974.040614][ T11] cleanup_net+0x4f3/0xa20 [ 3974.040836][ T11] process_one_work+0x78c/0x1310 [ 3974.041162][ T11] worker_thread+0x73d/0x1010 [ 3974.041436][ T11] kthread+0x28f/0x360 [ 3974.041665][ T11] ret_from_fork+0x31/0x70 [ 3974.041890][ T11] ret_from_fork_asm+0x1b/0x30 [ 3974.042142][ T11] [ 3974.042270][ T11] Freed by task 11: [ 3974.042499][ T11] kasan_save_stack+0x24/0x50 [ 3974.042782][ T11] kasan_save_track+0x14/0x30 [ 3974.043020][ T11] kasan_save_free_info+0x3f/0x60 [ 3974.043294][ T11] __kasan_slab_free+0xfc/0x1c0 [ 3974.043551][ T11] kfree+0xf2/0x2d0 [ 3974.043791][ T11] skb_release_data+0x56b/0x770 [ 3974.044037][ T11] consume_skb+0xad/0x110 [ 3974.044290][ T11] netlink_broadcast_filtered+0x224/0x340 [ 3974.044604][ T11] nlmsg_notify+0x6e/0x1e0 [ 3974.044845][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 3974.045064][ T11] __dev_notify_flags+0x1ba/0x250 [ 3974.045358][ T11] dev_change_flags+0xec/0x160 [ 3974.045646][ T11] cycle_netdev+0x94/0xf0 [vrf] [ 3974.045917][ T11] vrf_dellink+0xdb/0x150 [vrf] [ 3974.046164][ T11] default_device_exit_batch+0x16a/0x2c0 [ 3974.046462][ T11] cleanup_net+0x4f3/0xa20 [ 3974.046726][ T11] process_one_work+0x78c/0x1310 [ 3974.047014][ T11] worker_thread+0x73d/0x1010 [ 3974.047253][ T11] kthread+0x28f/0x360 [ 3974.047487][ T11] ret_from_fork+0x31/0x70 [ 3974.047723][ T11] ret_from_fork_asm+0x1b/0x30 [ 3974.047965][ T11] [ 3974.048086][ T11] The buggy address belongs to the object at ffff8880046b0800 [ 3974.048086][ T11] which belongs to the cache kmalloc-2k of size 2048 [ 3974.048882][ T11] The buggy address is located 976 bytes inside of [ 3974.048882][ T11] freed 2048-byte region [ffff8880046b0800, ffff8880046b1000) [ 3974.049604][ T11] [ 3974.049770][ T11] The buggy address belongs to the physical page: [ 3974.050126][ T11] page:ffffea000011ac00 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x46b0 [ 3974.050659][ T11] head:ffffea000011ac00 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 3974.051119][ T11] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 3974.051485][ T11] page_type: 0xffffffff() [ 3974.051754][ T11] raw: 0080000000000840 ffff888001043540 ffffea000012c410 ffff8880010418f0 [ 3974.052206][ T11] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 3974.052669][ T11] page dumped because: kasan: bad access detected [ 3974.052990][ T11] [ 3974.053152][ T11] Memory state around the buggy address: [ 3974.053433][ T11] ffff8880046b0a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3974.053865][ T11] ffff8880046b0b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3974.054297][ T11] >ffff8880046b0b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3974.054753][ T11] ^ [ 3974.055123][ T11] ffff8880046b0c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3974.055541][ T11] ffff8880046b0c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3974.055976][ T11] ================================================================== [ 3974.056435][ T11] Disabling lock debugging due to kernel taint [ 3974.056786][ T11] general protection fault, probably for non-canonical address 0xdffffc002000007d: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 3974.057433][ T11] KASAN: probably user-memory-access in range [0x00000001000003e8-0x00000001000003ef] [ 3974.057957][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 3974.058545][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 3974.059200][ T11] Workqueue: netns cleanup_net [ 3974.059494][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 3974.059861][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 3974.060933][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010206 [ 3974.061261][ T11] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 3974.061675][ T11] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff8880046b0c24 [ 3974.062119][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100135081a R09: ffffc900000bf9b8 [ 3974.062668][ T11] R10: ffffffffabd3ca07 R11: 205d313154202020 R12: ffffed100135081a [ 3974.063140][ T11] R13: ffff8880046b0ba0 R14: ffff888009b49000 R15: ffff888009a84000 [ 3974.063647][ T11] FS: 0000000000000000(0000) GS:ffff88802f400000(0000) knlGS:0000000000000000 [ 3974.064162][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 3974.064590][ T11] CR2: 00007ff01b1e9270 CR3: 0000000006662005 CR4: 0000000000770ef0 [ 3974.065068][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 3974.065537][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 3974.066009][ T11] PKRU: 55555554 [ 3974.066263][ T11] Call Trace: [ 3974.066511][ T11] <TASK> [ 3974.066676][ T11] ? die_addr+0x41/0xa0 [ 3974.066950][ T11] ? exc_general_protection+0x149/0x220 [ 3974.067290][ T11] ? asm_exc_general_protection+0x26/0x30 [ 3974.067611][ T11] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 3974.068014][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 3974.068489][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 3974.068781][ T11] notifier_call_chain+0x9a/0x290 [ 3974.069039][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 3974.069415][ T11] ? mutex_is_locked+0x17/0x50 [ 3974.069655][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 3974.070062][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 3974.070327][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 3974.070652][ T11] default_device_exit_batch+0x228/0x2c0 [ 3974.070964][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 3974.071304][ T11] ? mutex_is_locked+0x17/0x50 [ 3974.071565][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 3974.071881][ T11] cleanup_net+0x4f3/0xa20 [ 3974.072135][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 3974.072461][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 3974.072734][ T11] ? lock_acquire+0x1c1/0x220 [ 3974.073029][ T11] ? process_one_work+0x714/0x1310 [ 3974.073342][ T11] process_one_work+0x78c/0x1310 [ 3974.073594][ T11] ? hlock_class+0x4e/0x130 [ 3974.073873][ T11] ? __pfx_process_one_work+0x10/0x10 [ 3974.074201][ T11] ? assign_work+0x16c/0x240 [ 3974.074509][ T11] worker_thread+0x73d/0x1010 [ 3974.074840][ T11] ? __pfx_worker_thread+0x10/0x10 [ 3974.075154][ T11] kthread+0x28f/0x360 [ 3974.075396][ T11] ? __pfx_kthread+0x10/0x10 [ 3974.075650][ T11] ret_from_fork+0x31/0x70 [ 3974.075874][ T11] ? __pfx_kthread+0x10/0x10 [ 3974.076137][ T11] ret_from_fork_asm+0x1b/0x30 [ 3974.076422][ T11] </TASK> [ 3974.076577][ T11] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel bridge stp llc 8021q sch_ingress vrf veth [ 3974.077712][ T11] ---[ end trace 0000000000000000 ]--- [ 3974.077992][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 3974.078426][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 3974.079539][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010206 [ 3974.079890][ T11] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 3974.080398][ T11] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff8880046b0c24 [ 3974.080864][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100135081a R09: ffffc900000bf9b8 [ 3974.081304][ T11] R10: ffffffffabd3ca07 R11: 205d313154202020 R12: ffffed100135081a [ 3974.081804][ T11] R13: ffff8880046b0ba0 R14: ffff888009b49000 R15: ffff888009a84000 [ 3974.082345][ T11] FS: 0000000000000000(0000) GS:ffff88802f400000(0000) knlGS:0000000000000000 [ 3974.082887][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 3974.083281][ T11] CR2: 00007ff01b1e9270 CR3: 0000000006662005 CR4: 0000000000770ef0 [ 3974.083791][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 3974.084321][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 3974.084822][ T11] PKRU: 55555554 [ 3974.085015][ T11] Kernel panic - not syncing: Fatal exception [ 3974.085491][ T11] Kernel Offset: 0x25600000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 3974.086067][ T11] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout