make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=vxlan_brridge_1q_port_8472.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: vxlan_bridge_1q_port_8472.sh [ 3937.956878][T12919] 8021q: 802.1Q VLAN Support v1.8 [ 3943.315414][T12963] br1: port 1(vx10) entered blocking state [ 3943.315825][T12963] br1: port 1(vx10) entered disabled state [ 3943.316178][T12963] vx10: entered allmulticast mode [ 3943.318284][T12963] vx10: entered promiscuous mode [ 3943.319790][T12963] br1: port 1(vx10) entered blocking state [ 3943.320153][T12963] br1: port 1(vx10) entered forwarding state [ 3943.909838][T12968] br1: port 2(vx20) entered blocking state [ 3943.910177][T12968] br1: port 2(vx20) entered disabled state [ 3943.910539][T12968] vx20: entered allmulticast mode [ 3943.912550][T12968] vx20: entered promiscuous mode [ 3943.913189][T12968] br1: port 2(vx20) entered blocking state [ 3943.913509][T12968] br1: port 2(vx20) entered forwarding state [ 3944.205489][T12970] br1: port 3(veth1) entered blocking state [ 3944.205846][T12970] br1: port 3(veth1) entered disabled state [ 3944.206235][T12970] veth1: entered allmulticast mode [ 3944.208407][T12970] veth1: entered promiscuous mode [ 3944.360480][T12796] br1: port 3(veth1) entered blocking state [ 3944.360883][T12796] br1: port 3(veth1) entered forwarding state [ 3944.789877][T12974] br1: port 4(veth2) entered blocking state [ 3944.790880][T12974] br1: port 4(veth2) entered disabled state [ 3944.791248][T12974] veth2: entered allmulticast mode [ 3944.793284][T12974] veth2: entered promiscuous mode [ 3944.943772][T12796] br1: port 4(veth2) entered blocking state [ 3944.944128][T12796] br1: port 4(veth2) entered forwarding state [ 3950.417150][T13027] br2: port 1(w1) entered blocking state [ 3950.417500][T13027] br2: port 1(w1) entered disabled state [ 3950.417842][T13027] w1: entered allmulticast mode [ 3950.420015][T13027] w1: entered promiscuous mode [ 3951.589954][T13035] br2: port 2(vx10) entered blocking state [ 3951.590312][T13035] br2: port 2(vx10) entered disabled state [ 3951.590666][T13035] vx10: entered allmulticast mode [ 3951.593139][T13035] vx10: entered promiscuous mode [ 3951.593810][T13035] br2: port 2(vx10) entered blocking state [ 3951.594121][T13035] br2: port 2(vx10) entered forwarding state [ 3952.670033][T13042] br2: port 3(vx20) entered blocking state [ 3952.670487][T13042] br2: port 3(vx20) entered disabled state [ 3952.671105][T13042] vx20: entered allmulticast mode [ 3952.673135][T13042] vx20: entered promiscuous mode [ 3952.673738][T13042] br2: port 3(vx20) entered blocking state [ 3952.674046][T13042] br2: port 3(vx20) entered forwarding state [ 3953.862466][T12796] br2: port 1(w1) entered blocking state [ 3953.862954][T12796] br2: port 1(w1) entered forwarding state [ 3957.428316][T13077] br2: port 1(w1) entered blocking state [ 3957.428647][T13077] br2: port 1(w1) entered disabled state [ 3957.428983][T13077] w1: entered allmulticast mode [ 3957.431009][T13077] w1: entered promiscuous mode [ 3958.610591][T13085] br2: port 2(vx10) entered blocking state [ 3958.610929][T13085] br2: port 2(vx10) entered disabled state [ 3958.611753][T13085] vx10: entered allmulticast mode [ 3958.613788][T13085] vx10: entered promiscuous mode [ 3958.614413][T13085] br2: port 2(vx10) entered blocking state [ 3958.614722][T13085] br2: port 2(vx10) entered forwarding state [ 3959.637712][T13092] br2: port 3(vx20) entered blocking state [ 3959.638047][T13092] br2: port 3(vx20) entered disabled state [ 3959.638414][T13092] vx20: entered allmulticast mode [ 3959.640679][T13092] vx20: entered promiscuous mode [ 3959.641279][T13092] br2: port 3(vx20) entered blocking state [ 3959.641587][T13092] br2: port 3(vx20) entered forwarding state [ 3960.833425][ T33] br2: port 1(w1) entered blocking state [ 3960.833791][ T33] br2: port 1(w1) entered forwarding state # INFO: Running tests with UDP port 8472 # TEST: ping: local->local vid 10 [ OK ] # TEST: ping: local->local vid 20 [ OK ] # TEST: ping: local->remote 1 vid 10 [ OK ] # TEST: ping: local->remote 2 vid 10 [ OK ] # TEST: ping: local->remote 1 vid 20 [ OK ] # TEST: ping: local->remote 2 vid 20 [ OK ] [ 3979.311461][ T71] vx20: left allmulticast mode [ 3979.311788][ T71] vx20: left promiscuous mode [ 3979.312254][ T71] br2: port 3(vx20) entered disabled state [ 3979.322415][ T71] vx10: left allmulticast mode [ 3979.322746][ T71] vx10: left promiscuous mode [ 3979.323130][ T71] br2: port 2(vx10) entered disabled state [ 3979.335627][ T71] w1: left allmulticast mode [ 3979.335942][ T71] w1: left promiscuous mode [ 3979.336387][ T71] br2: port 1(w1) entered disabled state [ 3979.424113][ T71] ================================================================== [ 3979.424607][ T71] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3979.425122][ T71] Read of size 8 at addr ffff888006140bd0 by task kworker/u8:1/71 [ 3979.425548][ T71] [ 3979.425711][ T71] CPU: 1 PID: 71 Comm: kworker/u8:1 Not tainted 6.8.0-rc2-virtme #1 [ 3979.426199][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 3979.426892][ T71] Workqueue: netns cleanup_net [ 3979.427200][ T71] Call Trace: [ 3979.427417][ T71] [ 3979.427568][ T71] dump_stack_lvl+0x64/0xb0 [ 3979.427885][ T71] print_address_description.constprop.0+0x2c/0x3b0 [ 3979.428277][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3979.428634][ T71] print_report+0xb5/0x270 [ 3979.428903][ T71] ? kasan_addr_to_slab+0x4e/0x90 [ 3979.429184][ T71] kasan_report+0xbe/0xf0 [ 3979.429406][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3979.429772][ T71] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 3979.430126][ T71] ? __pfx_vlan_device_event+0x10/0x10 [8021q] [ 3979.430508][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 3979.430887][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 3979.431230][ T71] notifier_call_chain+0x9a/0x290 [ 3979.431563][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 3979.431972][ T71] ? mutex_is_locked+0x17/0x50 [ 3979.432273][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 3979.432686][ T71] ? vrf_dellink+0x101/0x150 [vrf] [ 3979.433000][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 3979.433320][ T71] default_device_exit_batch+0x228/0x2c0 [ 3979.433607][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 3979.433963][ T71] ? mutex_is_locked+0x17/0x50 [ 3979.434240][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 3979.434588][ T71] cleanup_net+0x4f3/0xa20 [ 3979.434850][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 3979.435185][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 3979.435526][ T71] ? lock_acquire+0x1c1/0x220 [ 3979.435767][ T71] ? process_one_work+0x714/0x1310 [ 3979.436085][ T71] process_one_work+0x78c/0x1310 [ 3979.436344][ T71] ? hlock_class+0x4e/0x130 [ 3979.436577][ T71] ? __pfx_process_one_work+0x10/0x10 [ 3979.436853][ T71] ? assign_work+0x16c/0x240 [ 3979.437092][ T71] worker_thread+0x73d/0x1010 [ 3979.437332][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 3979.437675][ T71] ? __pfx_worker_thread+0x10/0x10 [ 3979.437939][ T71] ? __pfx_worker_thread+0x10/0x10 [ 3979.438199][ T71] kthread+0x28f/0x360 [ 3979.438407][ T71] ? __pfx_kthread+0x10/0x10 [ 3979.438644][ T71] ret_from_fork+0x31/0x70 [ 3979.438872][ T71] ? __pfx_kthread+0x10/0x10 [ 3979.439108][ T71] ret_from_fork_asm+0x1b/0x30 [ 3979.439357][ T71] [ 3979.439514][ T71] [ 3979.439635][ T71] Allocated by task 71: [ 3979.439847][ T71] kasan_save_stack+0x24/0x50 [ 3979.440089][ T71] kasan_save_track+0x14/0x30 [ 3979.440330][ T71] __kasan_kmalloc+0x7f/0x90 [ 3979.440566][ T71] __kmalloc_node_track_caller+0x1fb/0x440 [ 3979.440863][ T71] kmalloc_reserve+0xbc/0x1f0 [ 3979.441104][ T71] pskb_expand_head+0x1f4/0xff0 [ 3979.441354][ T71] netlink_trim+0x198/0x200 [ 3979.441585][ T71] netlink_broadcast_filtered+0xcb/0x340 [ 3979.441909][ T71] nlmsg_notify+0x6e/0x1e0 [ 3979.442137][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 3979.442385][ T71] __dev_notify_flags+0x1ba/0x250 [ 3979.442685][ T71] dev_change_flags+0xec/0x160 [ 3979.442929][ T71] cycle_netdev+0x94/0xf0 [vrf] [ 3979.443181][ T71] vrf_dellink+0xdb/0x150 [vrf] [ 3979.443453][ T71] default_device_exit_batch+0x16a/0x2c0 [ 3979.443762][ T71] cleanup_net+0x4f3/0xa20 [ 3979.444042][ T71] process_one_work+0x78c/0x1310 [ 3979.444303][ T71] worker_thread+0x73d/0x1010 [ 3979.444544][ T71] kthread+0x28f/0x360 [ 3979.444751][ T71] ret_from_fork+0x31/0x70 [ 3979.445036][ T71] ret_from_fork_asm+0x1b/0x30 [ 3979.445318][ T71] [ 3979.445440][ T71] Freed by task 71: [ 3979.445670][ T71] kasan_save_stack+0x24/0x50 [ 3979.445919][ T71] kasan_save_track+0x14/0x30 [ 3979.446158][ T71] kasan_save_free_info+0x3f/0x60 [ 3979.446455][ T71] __kasan_slab_free+0xfc/0x1c0 [ 3979.446763][ T71] kfree+0xf2/0x2d0 [ 3979.447008][ T71] skb_release_data+0x544/0x740 [ 3979.447279][ T71] consume_skb+0xad/0x110 [ 3979.447504][ T71] netlink_broadcast_filtered+0x224/0x340 [ 3979.447829][ T71] nlmsg_notify+0x6e/0x1e0 [ 3979.448097][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 3979.448323][ T71] __dev_notify_flags+0x1ba/0x250 [ 3979.448579][ T71] dev_change_flags+0xec/0x160 [ 3979.448864][ T71] cycle_netdev+0x94/0xf0 [vrf] [ 3979.449117][ T71] vrf_dellink+0xdb/0x150 [vrf] [ 3979.449411][ T71] default_device_exit_batch+0x16a/0x2c0 [ 3979.449720][ T71] cleanup_net+0x4f3/0xa20 [ 3979.449959][ T71] process_one_work+0x78c/0x1310 [ 3979.450210][ T71] worker_thread+0x73d/0x1010 [ 3979.450478][ T71] kthread+0x28f/0x360 [ 3979.450721][ T71] ret_from_fork+0x31/0x70 [ 3979.451002][ T71] ret_from_fork_asm+0x1b/0x30 [ 3979.451269][ T71] [ 3979.451391][ T71] The buggy address belongs to the object at ffff888006140800 [ 3979.451391][ T71] which belongs to the cache kmalloc-2k of size 2048 [ 3979.452154][ T71] The buggy address is located 976 bytes inside of [ 3979.452154][ T71] freed 2048-byte region [ffff888006140800, ffff888006141000) [ 3979.452847][ T71] [ 3979.452967][ T71] The buggy address belongs to the physical page: [ 3979.453298][ T71] page:ffffea0000185000 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x6140 [ 3979.453811][ T71] head:ffffea0000185000 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 3979.454260][ T71] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 3979.454597][ T71] page_type: 0xffffffff() [ 3979.454818][ T71] raw: 0080000000000840 ffff888001043540 ffffea0000127810 ffffea00001de210 [ 3979.455250][ T71] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 3979.455682][ T71] page dumped because: kasan: bad access detected [ 3979.456006][ T71] [ 3979.456131][ T71] Memory state around the buggy address: [ 3979.456415][ T71] ffff888006140a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3979.456819][ T71] ffff888006140b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3979.457226][ T71] >ffff888006140b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3979.457640][ T71] ^ [ 3979.457973][ T71] ffff888006140c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3979.458377][ T71] ffff888006140c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 3979.458811][ T71] ================================================================== [ 3979.459275][ T71] Disabling lock debugging due to kernel taint [ 3979.459616][ T71] general protection fault, probably for non-canonical address 0xdffffc002000007d: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 3979.460272][ T71] KASAN: probably user-memory-access in range [0x00000001000003e8-0x00000001000003ef] [ 3979.460761][ T71] CPU: 1 PID: 71 Comm: kworker/u8:1 Tainted: G B 6.8.0-rc2-virtme #1 [ 3979.461330][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 3979.461999][ T71] Workqueue: netns cleanup_net [ 3979.462275][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 3979.462719][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 3979.463876][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010206 [ 3979.464215][ T71] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 3979.464683][ T71] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff888006140c24 [ 3979.465125][ T71] RBP: 1ffff920000a3f33 R08: 1ffff11000d5f21a R09: ffffc9000051f9b8 [ 3979.465568][ T71] R10: ffffffffa1b3ca07 R11: 205d313754202020 R12: ffffed1000d5f21a [ 3979.466013][ T71] R13: ffff888006140ba0 R14: ffff888007799000 R15: ffff888006af9000 [ 3979.466444][ T71] FS: 0000000000000000(0000) GS:ffff888035600000(0000) knlGS:0000000000000000 [ 3979.466891][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 3979.467222][ T71] CR2: 00007f6c14a8c270 CR3: 00000000068aa005 CR4: 0000000000770ef0 [ 3979.467655][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 3979.468061][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 3979.468460][ T71] PKRU: 55555554 [ 3979.468648][ T71] Call Trace: [ 3979.468819][ T71] [ 3979.468975][ T71] ? die_addr+0x41/0xa0 [ 3979.469189][ T71] ? exc_general_protection+0x149/0x220 [ 3979.469478][ T71] ? asm_exc_general_protection+0x26/0x30 [ 3979.469837][ T71] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 3979.470187][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 3979.470548][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 3979.470837][ T71] notifier_call_chain+0x9a/0x290 [ 3979.471103][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 3979.471432][ T71] ? mutex_is_locked+0x17/0x50 [ 3979.471676][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 3979.472017][ T71] ? vrf_dellink+0x101/0x150 [vrf] [ 3979.472283][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 3979.472603][ T71] default_device_exit_batch+0x228/0x2c0 [ 3979.472888][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 3979.473207][ T71] ? mutex_is_locked+0x17/0x50 [ 3979.473479][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 3979.473808][ T71] cleanup_net+0x4f3/0xa20 [ 3979.474050][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 3979.474360][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 3979.474651][ T71] ? lock_acquire+0x1c1/0x220 [ 3979.474909][ T71] ? process_one_work+0x714/0x1310 [ 3979.475191][ T71] process_one_work+0x78c/0x1310 [ 3979.475461][ T71] ? hlock_class+0x4e/0x130 [ 3979.475720][ T71] ? __pfx_process_one_work+0x10/0x10 [ 3979.476000][ T71] ? assign_work+0x16c/0x240 [ 3979.476264][ T71] worker_thread+0x73d/0x1010 [ 3979.476546][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 3979.476899][ T71] ? __pfx_worker_thread+0x10/0x10 [ 3979.477174][ T71] ? __pfx_worker_thread+0x10/0x10 [ 3979.477472][ T71] kthread+0x28f/0x360 [ 3979.477686][ T71] ? __pfx_kthread+0x10/0x10 [ 3979.477943][ T71] ret_from_fork+0x31/0x70 [ 3979.478187][ T71] ? __pfx_kthread+0x10/0x10 [ 3979.478429][ T71] ret_from_fork_asm+0x1b/0x30 [ 3979.478698][ T71] [ 3979.478864][ T71] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel bridge stp llc 8021q sch_ingress vrf veth [ 3979.479480][ T71] ---[ end trace 0000000000000000 ]--- [ 3979.479796][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 3979.480164][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 3979.481549][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010206 [ 3979.481884][ T71] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 3979.482317][ T71] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff888006140c24 [ 3979.482744][ T71] RBP: 1ffff920000a3f33 R08: 1ffff11000d5f21a R09: ffffc9000051f9b8 [ 3979.483199][ T71] R10: ffffffffa1b3ca07 R11: 205d313754202020 R12: ffffed1000d5f21a [ 3979.483642][ T71] R13: ffff888006140ba0 R14: ffff888007799000 R15: ffff888006af9000 [ 3979.484076][ T71] FS: 0000000000000000(0000) GS:ffff888035600000(0000) knlGS:0000000000000000 [ 3979.484544][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 3979.484878][ T71] CR2: 00007f6c14a8c270 CR3: 000000001671e003 CR4: 0000000000770ef0 [ 3979.485301][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 3979.485789][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 3979.486213][ T71] PKRU: 55555554 [ 3979.486426][ T71] Kernel panic - not syncing: Fatal exception [ 3979.486854][ T71] Kernel Offset: 0x1b400000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 3979.487442][ T71] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout