make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=vxlan_brridge_1q_port_8472_ipv6.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: vxlan_bridge_1q_port_8472_ipv6.sh [ 23.983368][ T232] ip (232) used greatest stack depth: 24296 bytes left [ 24.572517][ T244] ip (244) used greatest stack depth: 23632 bytes left [ 29.466147][ T283] 8021q: 802.1Q VLAN Support v1.8 [ 36.695153][ T332] br1: port 1(vx10) entered blocking state [ 36.696385][ T332] br1: port 1(vx10) entered disabled state [ 36.696885][ T332] vx10: entered allmulticast mode [ 36.700227][ T332] vx10: entered promiscuous mode [ 36.701225][ T332] br1: port 1(vx10) entered blocking state [ 36.701630][ T332] br1: port 1(vx10) entered forwarding state [ 37.367409][ T337] br1: port 2(vx20) entered blocking state [ 37.367825][ T337] br1: port 2(vx20) entered disabled state [ 37.368194][ T337] vx20: entered allmulticast mode [ 37.371484][ T337] vx20: entered promiscuous mode [ 37.372215][ T337] br1: port 2(vx20) entered blocking state [ 37.372601][ T337] br1: port 2(vx20) entered forwarding state [ 37.744350][ T339] br1: port 3(veth1) entered blocking state [ 37.744707][ T339] br1: port 3(veth1) entered disabled state [ 37.745079][ T339] veth1: entered allmulticast mode [ 37.747190][ T339] veth1: entered promiscuous mode [ 37.916812][ T49] br1: port 3(veth1) entered blocking state [ 37.917304][ T49] br1: port 3(veth1) entered forwarding state [ 38.596247][ T345] br1: port 4(veth2) entered blocking state [ 38.596616][ T345] br1: port 4(veth2) entered disabled state [ 38.596977][ T345] veth2: entered allmulticast mode [ 38.599119][ T345] veth2: entered promiscuous mode [ 38.772877][ T47] br1: port 4(veth2) entered blocking state [ 38.773236][ T47] br1: port 4(veth2) entered forwarding state [ 45.152614][ T391] br2: port 1(w1) entered blocking state [ 45.152969][ T391] br2: port 1(w1) entered disabled state [ 45.153356][ T391] w1: entered allmulticast mode [ 45.156325][ T391] w1: entered promiscuous mode [ 46.480262][ T399] br2: port 2(vx10) entered blocking state [ 46.480666][ T399] br2: port 2(vx10) entered disabled state [ 46.481037][ T399] vx10: entered allmulticast mode [ 46.483590][ T399] vx10: entered promiscuous mode [ 46.484309][ T399] br2: port 2(vx10) entered blocking state [ 46.484629][ T399] br2: port 2(vx10) entered forwarding state [ 47.769669][ T406] br2: port 3(vx20) entered blocking state [ 47.770070][ T406] br2: port 3(vx20) entered disabled state [ 47.770865][ T406] vx20: entered allmulticast mode [ 47.773175][ T406] vx20: entered promiscuous mode [ 47.773930][ T406] br2: port 3(vx20) entered blocking state [ 47.774258][ T406] br2: port 3(vx20) entered forwarding state [ 49.217622][ T33] br2: port 1(w1) entered blocking state [ 49.218137][ T33] br2: port 1(w1) entered forwarding state [ 53.525722][ T443] br2: port 1(w1) entered blocking state [ 53.526052][ T443] br2: port 1(w1) entered disabled state [ 53.526409][ T443] w1: entered allmulticast mode [ 53.528466][ T443] w1: entered promiscuous mode [ 54.837452][ T452] br2: port 2(vx10) entered blocking state [ 54.837807][ T452] br2: port 2(vx10) entered disabled state [ 54.838167][ T452] vx10: entered allmulticast mode [ 54.840427][ T452] vx10: entered promiscuous mode [ 54.841152][ T452] br2: port 2(vx10) entered blocking state [ 54.841487][ T452] br2: port 2(vx10) entered forwarding state [ 55.996143][ T459] br2: port 3(vx20) entered blocking state [ 55.996507][ T459] br2: port 3(vx20) entered disabled state [ 55.996909][ T459] vx20: entered allmulticast mode [ 55.999323][ T459] vx20: entered promiscuous mode [ 55.999989][ T459] br2: port 3(vx20) entered blocking state [ 56.000363][ T459] br2: port 3(vx20) entered forwarding state [ 57.398847][ T33] br2: port 1(w1) entered blocking state [ 57.399228][ T33] br2: port 1(w1) entered forwarding state # INFO: Running tests with UDP port 8472 # TEST: ping: local->local vid 10 [ OK ] # TEST: ping: local->local vid 20 [ OK ] [ 71.704140][ T532] GACT probability NOT on # TEST: ping: local->remote 1 vid 10 [ OK ] # TEST: ping: local->remote 2 vid 10 [ OK ] # TEST: ping: local->remote 1 vid 20 [ OK ] # TEST: ping: local->remote 2 vid 20 [ OK ] # TEST: ping6: local->local vid 10 [ OK ] # TEST: ping6: local->local vid 20 [ OK ] # TEST: ping6: local->remote 1 vid 10 [ OK ] # TEST: ping6: local->remote 2 vid 10 [ OK ] # TEST: ping6: local->remote 1 vid 20 [ OK ] # TEST: ping6: local->remote 2 vid 20 [ OK ] [ 171.659706][ T11] vx20: left allmulticast mode [ 171.660196][ T11] vx20: left promiscuous mode [ 171.660907][ T11] br2: port 3(vx20) entered disabled state [ 171.673670][ T11] vx10: left allmulticast mode [ 171.674122][ T11] vx10: left promiscuous mode [ 171.674726][ T11] br2: port 2(vx10) entered disabled state [ 171.690439][ T11] w1: left allmulticast mode [ 171.690904][ T11] w1: left promiscuous mode [ 171.691514][ T11] br2: port 1(w1) entered disabled state [ 171.805633][ T11] ================================================================== [ 171.806154][ T11] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 171.806724][ T11] Read of size 8 at addr ffff888002690bd0 by task kworker/u8:0/11 [ 171.807163][ T11] [ 171.807328][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 171.807796][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 171.808450][ T11] Workqueue: netns cleanup_net [ 171.808734][ T11] Call Trace: [ 171.808908][ T11] [ 171.809094][ T11] dump_stack_lvl+0x64/0xb0 [ 171.809335][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 171.809691][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 171.810060][ T11] print_report+0xb5/0x270 [ 171.810315][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 171.810616][ T11] kasan_report+0xbe/0xf0 [ 171.810916][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 171.811292][ T11] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 171.811635][ T11] ? __pfx_vlan_device_event+0x10/0x10 [8021q] [ 171.812003][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 171.812348][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 171.812646][ T11] notifier_call_chain+0x9a/0x290 [ 171.812931][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 171.813269][ T11] ? mutex_is_locked+0x17/0x50 [ 171.813627][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 171.814004][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 171.814290][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 171.814638][ T11] default_device_exit_batch+0x228/0x2c0 [ 171.815028][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 171.815442][ T11] ? mutex_is_locked+0x17/0x50 [ 171.815796][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 171.816130][ T11] cleanup_net+0x4f3/0xa20 [ 171.816417][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 171.816796][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 171.817190][ T11] ? lock_acquire+0x1c1/0x220 [ 171.817568][ T11] ? process_one_work+0x714/0x1310 [ 171.817992][ T11] process_one_work+0x78c/0x1310 [ 171.818372][ T11] ? hlock_class+0x4e/0x130 [ 171.818735][ T11] ? __pfx_process_one_work+0x10/0x10 [ 171.819205][ T11] ? assign_work+0x16c/0x240 [ 171.819594][ T11] worker_thread+0x73d/0x1010 [ 171.819974][ T11] ? __pfx_worker_thread+0x10/0x10 [ 171.820393][ T11] kthread+0x28f/0x360 [ 171.820701][ T11] ? __pfx_kthread+0x10/0x10 [ 171.821035][ T11] ret_from_fork+0x31/0x70 [ 171.821371][ T11] ? __pfx_kthread+0x10/0x10 [ 171.821711][ T11] ret_from_fork_asm+0x1b/0x30 [ 171.822069][ T11] [ 171.822301][ T11] [ 171.822475][ T11] Allocated by task 11: [ 171.822739][ T11] kasan_save_stack+0x24/0x50 [ 171.823085][ T11] kasan_save_track+0x14/0x30 [ 171.823405][ T11] __kasan_kmalloc+0x7f/0x90 [ 171.823727][ T11] __kmalloc_node_track_caller+0x1fb/0x440 [ 171.824155][ T11] kmalloc_reserve+0xbc/0x1f0 [ 171.824489][ T11] pskb_expand_head+0x1f4/0xff0 [ 171.824833][ T11] netlink_trim+0x198/0x200 [ 171.825156][ T11] netlink_broadcast_filtered+0xcb/0x340 [ 171.825559][ T11] nlmsg_notify+0x6e/0x1e0 [ 171.825883][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 171.826111][ T11] __dev_notify_flags+0x1ba/0x250 [ 171.826391][ T11] dev_change_flags+0xec/0x160 [ 171.826653][ T11] cycle_netdev+0xc3/0xf0 [vrf] [ 171.826923][ T11] vrf_dellink+0xdb/0x150 [vrf] [ 171.827275][ T11] default_device_exit_batch+0x16a/0x2c0 [ 171.827614][ T11] cleanup_net+0x4f3/0xa20 [ 171.827843][ T11] process_one_work+0x78c/0x1310 [ 171.828129][ T11] worker_thread+0x73d/0x1010 [ 171.828429][ T11] kthread+0x28f/0x360 [ 171.828700][ T11] ret_from_fork+0x31/0x70 [ 171.829002][ T11] ret_from_fork_asm+0x1b/0x30 [ 171.829335][ T11] [ 171.829501][ T11] Freed by task 11: [ 171.829766][ T11] kasan_save_stack+0x24/0x50 [ 171.830013][ T11] kasan_save_track+0x14/0x30 [ 171.830303][ T11] kasan_save_free_info+0x3f/0x60 [ 171.830657][ T11] __kasan_slab_free+0xfc/0x1c0 [ 171.831031][ T11] kfree+0xf2/0x2d0 [ 171.831264][ T11] skb_release_data+0x544/0x740 [ 171.831566][ T11] consume_skb+0xad/0x110 [ 171.831905][ T11] netlink_broadcast_filtered+0x224/0x340 [ 171.832371][ T11] nlmsg_notify+0x6e/0x1e0 [ 171.832735][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 171.833086][ T11] __dev_notify_flags+0x1ba/0x250 [ 171.833470][ T11] dev_change_flags+0xec/0x160 [ 171.833864][ T11] cycle_netdev+0xc3/0xf0 [vrf] [ 171.834234][ T11] vrf_dellink+0xdb/0x150 [vrf] [ 171.834620][ T11] default_device_exit_batch+0x16a/0x2c0 [ 171.835058][ T11] cleanup_net+0x4f3/0xa20 [ 171.835405][ T11] process_one_work+0x78c/0x1310 [ 171.835770][ T11] worker_thread+0x73d/0x1010 [ 171.836112][ T11] kthread+0x28f/0x360 [ 171.836414][ T11] ret_from_fork+0x31/0x70 [ 171.836782][ T11] ret_from_fork_asm+0x1b/0x30 [ 171.837135][ T11] [ 171.837344][ T11] The buggy address belongs to the object at ffff888002690800 [ 171.837344][ T11] which belongs to the cache kmalloc-2k of size 2048 [ 171.838191][ T11] The buggy address is located 976 bytes inside of [ 171.838191][ T11] freed 2048-byte region [ffff888002690800, ffff888002691000) [ 171.838942][ T11] [ 171.839065][ T11] The buggy address belongs to the physical page: [ 171.839392][ T11] page:ffffea000009a400 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2690 [ 171.839902][ T11] head:ffffea000009a400 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 171.840388][ T11] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 171.840821][ T11] page_type: 0xffffffff() [ 171.841091][ T11] raw: 0080000000000840 ffff888001043540 ffffea0000219a10 ffff8880010418f0 [ 171.841603][ T11] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 171.842183][ T11] page dumped because: kasan: bad access detected [ 171.842653][ T11] [ 171.842832][ T11] Memory state around the buggy address: [ 171.843305][ T11] ffff888002690a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 171.843942][ T11] ffff888002690b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 171.844591][ T11] >ffff888002690b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 171.845153][ T11] ^ [ 171.845663][ T11] ffff888002690c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 171.846295][ T11] ffff888002690c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 171.846963][ T11] ================================================================== [ 171.847627][ T11] Disabling lock debugging due to kernel taint [ 171.848121][ T11] general protection fault, probably for non-canonical address 0xdffffc002000007d: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 171.849084][ T11] KASAN: probably user-memory-access in range [0x00000001000003e8-0x00000001000003ef] [ 171.849842][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 171.850545][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 171.851395][ T11] Workqueue: netns cleanup_net [ 171.851690][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 171.852154][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 171.853292][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010206 [ 171.853603][ T11] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 171.854064][ T11] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff888002690c24 [ 171.854583][ T11] RBP: 1ffff92000017f33 R08: 1ffff11000efb81a R09: ffffc900000bf9b8 [ 171.855087][ T11] R10: ffffffff9a33ca07 R11: 205d313154202020 R12: ffffed1000efb81a [ 171.855549][ T11] R13: ffff888002690ba0 R14: ffff88800a869000 R15: ffff8880077dc000 [ 171.856056][ T11] FS: 0000000000000000(0000) GS:ffff888035e00000(0000) knlGS:0000000000000000 [ 171.856661][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 171.857106][ T11] CR2: 00007f00bc533000 CR3: 000000001b31e004 CR4: 0000000000770ef0 [ 171.857697][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 171.858251][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 171.858872][ T11] PKRU: 55555554 [ 171.859146][ T11] Call Trace: [ 171.859403][ T11] [ 171.859629][ T11] ? die_addr+0x41/0xa0 [ 171.859937][ T11] ? exc_general_protection+0x149/0x220 [ 171.860382][ T11] ? asm_exc_general_protection+0x26/0x30 [ 171.860890][ T11] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 171.861367][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 171.861898][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 171.862374][ T11] notifier_call_chain+0x9a/0x290 [ 171.862774][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 171.863253][ T11] ? mutex_is_locked+0x17/0x50 [ 171.863600][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 171.864195][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 171.864589][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 171.865062][ T11] default_device_exit_batch+0x228/0x2c0 [ 171.865446][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 171.865886][ T11] ? mutex_is_locked+0x17/0x50 [ 171.866209][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 171.866641][ T11] cleanup_net+0x4f3/0xa20 [ 171.866970][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 171.867346][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 171.867633][ T11] ? lock_acquire+0x1c1/0x220 [ 171.867925][ T11] ? process_one_work+0x714/0x1310 [ 171.868233][ T11] process_one_work+0x78c/0x1310 [ 171.868560][ T11] ? hlock_class+0x4e/0x130 [ 171.868901][ T11] ? __pfx_process_one_work+0x10/0x10 [ 171.869215][ T11] ? assign_work+0x16c/0x240 [ 171.869487][ T11] worker_thread+0x73d/0x1010 [ 171.869739][ T11] ? __pfx_worker_thread+0x10/0x10 [ 171.870068][ T11] kthread+0x28f/0x360 [ 171.870387][ T11] ? __pfx_kthread+0x10/0x10 [ 171.870745][ T11] ret_from_fork+0x31/0x70 [ 171.871069][ T11] ? __pfx_kthread+0x10/0x10 [ 171.871317][ T11] ret_from_fork_asm+0x1b/0x30 [ 171.871626][ T11] [ 171.871854][ T11] Modules linked in: act_gact cls_flower vxlan ip6_udp_tunnel udp_tunnel bridge stp llc 8021q sch_ingress vrf veth [ 171.873291][ T11] ---[ end trace 0000000000000000 ]--- [ 171.873693][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 171.874214][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 171.875651][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010206 [ 171.876091][ T11] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 171.876746][ T11] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff888002690c24 [ 171.877360][ T11] RBP: 1ffff92000017f33 R08: 1ffff11000efb81a R09: ffffc900000bf9b8 [ 171.878024][ T11] R10: ffffffff9a33ca07 R11: 205d313154202020 R12: ffffed1000efb81a [ 171.878607][ T11] R13: ffff888002690ba0 R14: ffff88800a869000 R15: ffff8880077dc000 [ 171.879225][ T11] FS: 0000000000000000(0000) GS:ffff888035e00000(0000) knlGS:0000000000000000 [ 171.879901][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 171.880380][ T11] CR2: 00007f00bc533000 CR3: 000000001b31e004 CR4: 0000000000770ef0 [ 171.880969][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 171.881528][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 171.881959][ T11] PKRU: 55555554 [ 171.882167][ T11] Kernel panic - not syncing: Fatal exception [ 171.882687][ T11] Kernel Offset: 0x13c00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 171.883274][ T11] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout