make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=q_in_vnii.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: q_in_vni.sh [ 26.305056][ T285] 8021q: 802.1Q VLAN Support v1.8 [ 32.284657][ T331] br1: port 1(vx100) entered blocking state [ 32.285794][ T331] br1: port 1(vx100) entered disabled state [ 32.286240][ T331] vx100: entered allmulticast mode [ 32.288479][ T331] vx100: entered promiscuous mode [ 32.290214][ T331] br1: port 1(vx100) entered blocking state [ 32.290592][ T331] br1: port 1(vx100) entered forwarding state [ 32.621427][ T333] br1: port 2(veth1) entered blocking state [ 32.622378][ T333] br1: port 2(veth1) entered disabled state [ 32.622750][ T333] veth1: entered allmulticast mode [ 32.624809][ T333] veth1: entered promiscuous mode [ 32.791808][ T28] br1: port 2(veth1) entered blocking state [ 32.792236][ T28] br1: port 2(veth1) entered forwarding state [ 33.102677][ T336] br1: port 3(veth2) entered blocking state [ 33.103277][ T336] br1: port 3(veth2) entered disabled state [ 33.103627][ T336] veth2: entered allmulticast mode [ 33.105702][ T336] veth2: entered promiscuous mode [ 33.258220][ T28] br1: port 3(veth2) entered blocking state [ 33.258562][ T28] br1: port 3(veth2) entered forwarding state [ 38.563693][ T378] br2: port 1(w1) entered blocking state [ 38.564751][ T378] br2: port 1(w1) entered disabled state [ 38.565098][ T378] w1: entered allmulticast mode [ 38.567275][ T378] w1: entered promiscuous mode [ 39.636798][ T385] br2: port 2(vx100) entered blocking state [ 39.637137][ T385] br2: port 2(vx100) entered disabled state [ 39.637489][ T385] vx100: entered allmulticast mode [ 39.639536][ T385] vx100: entered promiscuous mode [ 39.640841][ T385] br2: port 2(vx100) entered blocking state [ 39.641154][ T385] br2: port 2(vx100) entered forwarding state [ 40.958314][ T8] br2: port 1(w1) entered blocking state [ 40.958828][ T8] br2: port 1(w1) entered forwarding state [ 44.930284][ T420] br2: port 1(w1) entered blocking state [ 44.930801][ T420] br2: port 1(w1) entered disabled state [ 44.931315][ T420] w1: entered allmulticast mode [ 44.935705][ T420] w1: entered promiscuous mode [ 46.085281][ T427] br2: port 2(vx100) entered blocking state [ 46.085621][ T427] br2: port 2(vx100) entered disabled state [ 46.086005][ T427] vx100: entered allmulticast mode [ 46.088076][ T427] vx100: entered promiscuous mode [ 46.088681][ T427] br2: port 2(vx100) entered blocking state [ 46.089013][ T427] br2: port 2(vx100) entered forwarding state [ 47.362659][ T8] br2: port 1(w1) entered blocking state [ 47.363022][ T8] br2: port 1(w1) entered forwarding state # Running tests with UDP port 4789 # TEST: ping: local->local [ OK ] # TEST: ping: local->remote 1 [ OK ] # TEST: ping: local->remote 2 [ OK ] [ 62.090156][ T71] vx100: left allmulticast mode [ 62.090494][ T71] vx100: left promiscuous mode [ 62.090976][ T71] br2: port 2(vx100) entered disabled state [ 62.101238][ T71] w1: left allmulticast mode [ 62.101521][ T71] w1: left promiscuous mode [ 62.101945][ T71] br2: port 1(w1) entered disabled state [ 62.191280][ T71] ================================================================== [ 62.191751][ T71] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.192280][ T71] Read of size 8 at addr ffff8880076a8bd0 by task kworker/u8:1/71 [ 62.192703][ T71] [ 62.192843][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Not tainted 6.8.0-rc2-virtme #1 [ 62.193296][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 62.193950][ T71] Workqueue: netns cleanup_net [ 62.194253][ T71] Call Trace: [ 62.194422][ T71] [ 62.194580][ T71] dump_stack_lvl+0x64/0xb0 [ 62.194827][ T71] print_address_description.constprop.0+0x2c/0x3b0 [ 62.195191][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.195602][ T71] print_report+0xb5/0x270 [ 62.195852][ T71] ? kasan_addr_to_slab+0x4e/0x90 [ 62.196124][ T71] kasan_report+0xbe/0xf0 [ 62.196381][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.196724][ T71] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 62.197070][ T71] ? __pfx_vlan_device_event+0x10/0x10 [8021q] [ 62.197426][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 62.197806][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 62.198138][ T71] notifier_call_chain+0x9a/0x290 [ 62.198421][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 62.198785][ T71] ? mutex_is_locked+0x17/0x50 [ 62.199045][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 62.199420][ T71] ? vrf_dellink+0x101/0x150 [vrf] [ 62.199734][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 62.200092][ T71] default_device_exit_batch+0x228/0x2c0 [ 62.200392][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 62.200728][ T71] ? mutex_is_locked+0x17/0x50 [ 62.200968][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 62.201323][ T71] cleanup_net+0x4f3/0xa20 [ 62.201576][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 62.201879][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 62.202138][ T71] ? lock_acquire+0x1c1/0x220 [ 62.202375][ T71] ? process_one_work+0x714/0x1310 [ 62.202678][ T71] process_one_work+0x78c/0x1310 [ 62.202956][ T71] ? hlock_class+0x4e/0x130 [ 62.203214][ T71] ? __pfx_process_one_work+0x10/0x10 [ 62.203506][ T71] ? assign_work+0x16c/0x240 [ 62.203757][ T71] worker_thread+0x73d/0x1010 [ 62.204012][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 62.204386][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.204641][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.204897][ T71] kthread+0x28f/0x360 [ 62.205104][ T71] ? __pfx_kthread+0x10/0x10 [ 62.205334][ T71] ret_from_fork+0x31/0x70 [ 62.205560][ T71] ? __pfx_kthread+0x10/0x10 [ 62.205792][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.206037][ T71] [ 62.206194][ T71] [ 62.206314][ T71] Allocated by task 71: [ 62.206521][ T71] kasan_save_stack+0x24/0x50 [ 62.206759][ T71] kasan_save_track+0x14/0x30 [ 62.206995][ T71] __kasan_kmalloc+0x7f/0x90 [ 62.207224][ T71] __kmalloc_node_track_caller+0x1fb/0x440 [ 62.207580][ T71] kmalloc_reserve+0xbc/0x1f0 [ 62.207819][ T71] pskb_expand_head+0x1f4/0xff0 [ 62.208120][ T71] netlink_trim+0x198/0x200 [ 62.208381][ T71] netlink_broadcast_filtered+0xcb/0x340 [ 62.208683][ T71] nlmsg_notify+0x6e/0x1e0 [ 62.208936][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 62.209228][ T71] __dev_notify_flags+0x1ba/0x250 [ 62.209523][ T71] dev_change_flags+0xec/0x160 [ 62.209781][ T71] cycle_netdev+0x94/0xf0 [vrf] [ 62.210049][ T71] vrf_dellink+0xdb/0x150 [vrf] [ 62.210323][ T71] default_device_exit_batch+0x16a/0x2c0 [ 62.210657][ T71] cleanup_net+0x4f3/0xa20 [ 62.210911][ T71] process_one_work+0x78c/0x1310 [ 62.211159][ T71] worker_thread+0x73d/0x1010 [ 62.211395][ T71] kthread+0x28f/0x360 [ 62.211609][ T71] ret_from_fork+0x31/0x70 [ 62.211851][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.212124][ T71] [ 62.212243][ T71] Freed by task 71: [ 62.212445][ T71] kasan_save_stack+0x24/0x50 [ 62.212688][ T71] kasan_save_track+0x14/0x30 [ 62.212936][ T71] kasan_save_free_info+0x3f/0x60 [ 62.213190][ T71] __kasan_slab_free+0xfc/0x1c0 [ 62.213467][ T71] kfree+0xf2/0x2d0 [ 62.213677][ T71] skb_release_data+0x56b/0x770 [ 62.213922][ T71] consume_skb+0xad/0x110 [ 62.214204][ T71] netlink_broadcast_filtered+0x224/0x340 [ 62.214490][ T71] nlmsg_notify+0x6e/0x1e0 [ 62.214724][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 62.214944][ T71] __dev_notify_flags+0x1ba/0x250 [ 62.215217][ T71] dev_change_flags+0xec/0x160 [ 62.215482][ T71] cycle_netdev+0x94/0xf0 [vrf] [ 62.215730][ T71] vrf_dellink+0xdb/0x150 [vrf] [ 62.215978][ T71] default_device_exit_batch+0x16a/0x2c0 [ 62.216261][ T71] cleanup_net+0x4f3/0xa20 [ 62.216511][ T71] process_one_work+0x78c/0x1310 [ 62.216760][ T71] worker_thread+0x73d/0x1010 [ 62.217034][ T71] kthread+0x28f/0x360 [ 62.217238][ T71] ret_from_fork+0x31/0x70 [ 62.217487][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.217728][ T71] [ 62.217848][ T71] The buggy address belongs to the object at ffff8880076a8800 [ 62.217848][ T71] which belongs to the cache kmalloc-2k of size 2048 [ 62.218585][ T71] The buggy address is located 976 bytes inside of [ 62.218585][ T71] freed 2048-byte region [ffff8880076a8800, ffff8880076a9000) [ 62.219334][ T71] [ 62.219454][ T71] The buggy address belongs to the physical page: [ 62.219808][ T71] page:ffffea00001daa00 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x76a8 [ 62.220337][ T71] head:ffffea00001daa00 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 62.220810][ T71] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 62.221134][ T71] page_type: 0xffffffff() [ 62.221352][ T71] raw: 0080000000000840 ffff888001043540 ffffea000029fc10 ffffea000028be10 [ 62.221775][ T71] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 62.222251][ T71] page dumped because: kasan: bad access detected [ 62.222568][ T71] [ 62.222687][ T71] Memory state around the buggy address: [ 62.222967][ T71] ffff8880076a8a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.223365][ T71] ffff8880076a8b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.223762][ T71] >ffff8880076a8b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.224166][ T71] ^ [ 62.224499][ T71] ffff8880076a8c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.224898][ T71] ffff8880076a8c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 62.225293][ T71] ================================================================== [ 62.225793][ T71] Disabling lock debugging due to kernel taint [ 62.226121][ T71] general protection fault, probably for non-canonical address 0xdffffc002000007d: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 62.226780][ T71] KASAN: probably user-memory-access in range [0x00000001000003e8-0x00000001000003ef] [ 62.227311][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Tainted: G B 6.8.0-rc2-virtme #1 [ 62.227824][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 62.228485][ T71] Workqueue: netns cleanup_net [ 62.228741][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 62.229106][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 62.230185][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010206 [ 62.230559][ T71] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 62.231005][ T71] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff8880076a8c24 [ 62.231454][ T71] RBP: 1ffff920000a3f33 R08: 1ffff11000bdf21a R09: ffffc9000051f9b8 [ 62.231882][ T71] R10: ffffffff8673ca07 R11: 205d313754202020 R12: ffffed1000bdf21a [ 62.232285][ T71] R13: ffff8880076a8ba0 R14: ffff888038714000 R15: ffff888005ef9000 [ 62.232726][ T71] FS: 0000000000000000(0000) GS:ffff88802f000000(0000) knlGS:0000000000000000 [ 62.233206][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 62.233553][ T71] CR2: 00007f06dea65000 CR3: 0000000036f1e004 CR4: 0000000000770ef0 [ 62.233962][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 62.234394][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 62.234811][ T71] PKRU: 55555554 [ 62.235009][ T71] Call Trace: [ 62.235178][ T71] [ 62.235341][ T71] ? die_addr+0x41/0xa0 [ 62.235592][ T71] ? exc_general_protection+0x149/0x220 [ 62.235895][ T71] ? asm_exc_general_protection+0x26/0x30 [ 62.236208][ T71] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 62.236570][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 62.236973][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 62.237275][ T71] notifier_call_chain+0x9a/0x290 [ 62.237586][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 62.237973][ T71] ? mutex_is_locked+0x17/0x50 [ 62.238263][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 62.238671][ T71] ? vrf_dellink+0x101/0x150 [vrf] [ 62.238948][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 62.239263][ T71] default_device_exit_batch+0x228/0x2c0 [ 62.239544][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 62.239851][ T71] ? mutex_is_locked+0x17/0x50 [ 62.240092][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 62.240388][ T71] cleanup_net+0x4f3/0xa20 [ 62.240611][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 62.240894][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 62.241145][ T71] ? lock_acquire+0x1c1/0x220 [ 62.241379][ T71] ? process_one_work+0x714/0x1310 [ 62.241637][ T71] process_one_work+0x78c/0x1310 [ 62.241887][ T71] ? hlock_class+0x4e/0x130 [ 62.242119][ T71] ? __pfx_process_one_work+0x10/0x10 [ 62.242389][ T71] ? assign_work+0x16c/0x240 [ 62.242622][ T71] worker_thread+0x73d/0x1010 [ 62.242859][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 62.243188][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.243445][ T71] ? __pfx_worker_thread+0x10/0x10 [ 62.243703][ T71] kthread+0x28f/0x360 [ 62.243908][ T71] ? __pfx_kthread+0x10/0x10 [ 62.244148][ T71] ret_from_fork+0x31/0x70 [ 62.244371][ T71] ? __pfx_kthread+0x10/0x10 [ 62.244619][ T71] ret_from_fork_asm+0x1b/0x30 [ 62.244884][ T71] [ 62.245061][ T71] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel bridge stp llc 8021q sch_ingress vrf veth [ 62.245831][ T71] ---[ end trace 0000000000000000 ]--- [ 62.246118][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 62.246523][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 62.247670][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010206 [ 62.248073][ T71] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 62.248527][ T71] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff8880076a8c24 [ 62.249011][ T71] RBP: 1ffff920000a3f33 R08: 1ffff11000bdf21a R09: ffffc9000051f9b8 [ 62.249508][ T71] R10: ffffffff8673ca07 R11: 205d313754202020 R12: ffffed1000bdf21a [ 62.250026][ T71] R13: ffff8880076a8ba0 R14: ffff888038714000 R15: ffff888005ef9000 [ 62.250492][ T71] FS: 0000000000000000(0000) GS:ffff88802f000000(0000) knlGS:0000000000000000 [ 62.251083][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 62.251474][ T71] CR2: 00007f06dea65000 CR3: 0000000036f1e004 CR4: 0000000000770ef0 [ 62.252026][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 62.252460][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 62.252999][ T71] PKRU: 55555554 [ 62.253225][ T71] Kernel panic - not syncing: Fatal exception [ 62.253690][ T71] Kernel Offset: 0x0 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 62.254243][ T71] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout