make -C tools/testing/selftests TARGETS=net/forwarding TEST_PROGS=dual_vxllan_bridge.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-4/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' make[1]: Entering directory '/home/virtme/testing-4/tools/testing/selftests/net/forwarding' TAP version 13 1..1 # timeout set to 10800 # selftests: net/forwarding: dual_vxlan_bridge.sh [ 3990.982312][T12986] 8021q: 802.1Q VLAN Support v1.8 [ 3995.821316][T13028] br1: port 1(vx100) entered blocking state [ 3995.821728][T13028] br1: port 1(vx100) entered disabled state [ 3995.822079][T13028] vx100: entered allmulticast mode [ 3995.824173][T13028] vx100: entered promiscuous mode [ 3995.825694][T13028] br1: port 1(vx100) entered blocking state [ 3995.826043][T13028] br1: port 1(vx100) entered forwarding state [ 3996.130684][T13030] br1: port 2(veth1) entered blocking state [ 3996.131025][T13030] br1: port 2(veth1) entered disabled state [ 3996.132381][T13030] veth1: entered allmulticast mode [ 3996.134406][T13030] veth1: entered promiscuous mode [ 3996.280897][ T69] br1: port 2(veth1) entered blocking state [ 3996.281303][ T69] br1: port 2(veth1) entered forwarding state [ 3996.841912][T13036] br2: port 1(vx200) entered blocking state [ 3996.842255][T13036] br2: port 1(vx200) entered disabled state [ 3996.842613][T13036] vx200: entered allmulticast mode [ 3996.844639][T13036] vx200: entered promiscuous mode [ 3996.845870][T13036] br2: port 1(vx200) entered blocking state [ 3996.846186][T13036] br2: port 1(vx200) entered forwarding state [ 3997.286183][T13039] br2: port 2(veth2.20) entered blocking state [ 3997.286712][T13039] br2: port 2(veth2.20) entered disabled state [ 3997.293453][T13039] veth2.20: entered allmulticast mode [ 3997.296798][T13039] veth2.20: entered promiscuous mode [ 3997.452112][T13041] veth2: entered allmulticast mode [ 3997.453368][T13041] veth2: entered promiscuous mode [ 3997.454710][T13041] br2: port 2(veth2.20) entered blocking state [ 3997.455043][T13041] br2: port 2(veth2.20) entered forwarding state [ 4002.208162][T13089] br3: port 1(w1) entered blocking state [ 4002.208521][T13089] br3: port 1(w1) entered disabled state [ 4002.208858][T13089] w1: entered allmulticast mode [ 4002.210894][T13089] w1: entered promiscuous mode [ 4003.090327][T13095] br3: port 2(vx100) entered blocking state [ 4003.090680][T13095] br3: port 2(vx100) entered disabled state [ 4003.091046][T13095] vx100: entered allmulticast mode [ 4003.093187][T13095] vx100: entered promiscuous mode [ 4003.094137][T13095] br3: port 2(vx100) entered blocking state [ 4003.094463][T13095] br3: port 2(vx100) entered forwarding state [ 4004.172939][ T69] br3: port 1(w1) entered blocking state [ 4004.173463][ T69] br3: port 1(w1) entered forwarding state [ 4007.993588][T13133] br3: port 1(w1) entered blocking state [ 4007.993915][T13133] br3: port 1(w1) entered disabled state [ 4007.994243][T13133] w1: entered allmulticast mode [ 4007.996954][T13133] w1: entered promiscuous mode [ 4008.862145][T13139] br3: port 2(vx200) entered blocking state [ 4008.862502][T13139] br3: port 2(vx200) entered disabled state [ 4008.862856][T13139] vx200: entered allmulticast mode [ 4008.865297][T13139] vx200: entered promiscuous mode [ 4008.866243][T13139] br3: port 2(vx200) entered blocking state [ 4008.866569][T13139] br3: port 2(vx200) entered forwarding state [ 4009.878416][ T69] br3: port 1(w1) entered blocking state [ 4009.878754][ T69] br3: port 1(w1) entered forwarding state [ 4012.437047][T13168] br3: port 3(w1.20) entered blocking state [ 4012.437991][T13168] br3: port 3(w1.20) entered disabled state [ 4012.438359][T13168] w1.20: entered allmulticast mode [ 4012.440395][T13168] w1.20: entered promiscuous mode [ 4013.307247][T13176] br3: port 3(w1.20) entered blocking state [ 4013.307608][T13176] br3: port 3(w1.20) entered forwarding state # Running tests with UDP port 4789 # TEST: ping: local->remote 1 through VxLAN with an 802.1ad bridge [ OK ] # TEST: ping: local->remote 2 through VxLAN with an 802.1d bridge [ OK ] [ 4024.848841][ T11] w1.20: left allmulticast mode [ 4024.849233][ T11] w1.20: left promiscuous mode [ 4024.849983][ T11] br3: port 3(w1.20) entered disabled state [ 4024.858550][ T11] vx200: left allmulticast mode [ 4024.858874][ T11] vx200: left promiscuous mode [ 4024.859509][ T11] br3: port 2(vx200) entered disabled state [ 4024.872382][ T11] w1: left allmulticast mode [ 4024.872693][ T11] w1: left promiscuous mode [ 4024.873123][ T11] br3: port 1(w1) entered disabled state [ 4024.960974][ T11] ================================================================== [ 4024.961444][ T11] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 4024.961918][ T11] Read of size 8 at addr ffff888007e80bd0 by task kworker/u8:0/11 [ 4024.962316][ T11] [ 4024.962451][ T11] CPU: 0 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 4024.962848][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 4024.963455][ T11] Workqueue: netns cleanup_net [ 4024.963708][ T11] Call Trace: [ 4024.963883][ T11] [ 4024.964032][ T11] dump_stack_lvl+0x64/0xb0 [ 4024.964272][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 4024.964606][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 4024.964928][ T11] print_report+0xb5/0x270 [ 4024.965153][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 4024.965407][ T11] kasan_report+0xbe/0xf0 [ 4024.965629][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 4024.965952][ T11] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 4024.966264][ T11] ? __pfx_vlan_device_event+0x10/0x10 [8021q] [ 4024.966583][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 4024.966920][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 4024.967209][ T11] notifier_call_chain+0x9a/0x290 [ 4024.967468][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 4024.967789][ T11] ? mutex_is_locked+0x17/0x50 [ 4024.968032][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 4024.968376][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 4024.968643][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 4024.968958][ T11] default_device_exit_batch+0x228/0x2c0 [ 4024.969241][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 4024.969550][ T11] ? mutex_is_locked+0x17/0x50 [ 4024.969792][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 4024.970097][ T11] cleanup_net+0x4f3/0xa20 [ 4024.970329][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 4024.970613][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 4024.970863][ T11] ? lock_acquire+0x1c1/0x220 [ 4024.971099][ T11] ? process_one_work+0x714/0x1310 [ 4024.971359][ T11] process_one_work+0x78c/0x1310 [ 4024.971609][ T11] ? hlock_class+0x4e/0x130 [ 4024.971843][ T11] ? __pfx_process_one_work+0x10/0x10 [ 4024.972120][ T11] ? assign_work+0x16c/0x240 [ 4024.972355][ T11] worker_thread+0x73d/0x1010 [ 4024.972597][ T11] ? __pfx_worker_thread+0x10/0x10 [ 4024.972855][ T11] kthread+0x28f/0x360 [ 4024.973066][ T11] ? __pfx_kthread+0x10/0x10 [ 4024.973301][ T11] ret_from_fork+0x31/0x70 [ 4024.973530][ T11] ? __pfx_kthread+0x10/0x10 [ 4024.973762][ T11] ret_from_fork_asm+0x1b/0x30 [ 4024.974009][ T11] [ 4024.974165][ T11] [ 4024.974284][ T11] Allocated by task 11: [ 4024.974507][ T11] kasan_save_stack+0x24/0x50 [ 4024.974749][ T11] kasan_save_track+0x14/0x30 [ 4024.974986][ T11] __kasan_kmalloc+0x7f/0x90 [ 4024.975219][ T11] __kmalloc_node_track_caller+0x1fb/0x440 [ 4024.975512][ T11] kmalloc_reserve+0xbc/0x1f0 [ 4024.975755][ T11] pskb_expand_head+0x1f4/0xff0 [ 4024.976002][ T11] netlink_trim+0x198/0x200 [ 4024.976237][ T11] netlink_broadcast_filtered+0xcb/0x340 [ 4024.976522][ T11] nlmsg_notify+0x6e/0x1e0 [ 4024.976748][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 4024.976973][ T11] dev_close_many+0x2bd/0x650 [ 4024.977212][ T11] unregister_netdevice_many_notify+0x3d5/0x1180 [ 4024.977533][ T11] default_device_exit_batch+0x228/0x2c0 [ 4024.977816][ T11] cleanup_net+0x4f3/0xa20 [ 4024.978042][ T11] process_one_work+0x78c/0x1310 [ 4024.978306][ T11] worker_thread+0x73d/0x1010 [ 4024.978545][ T11] kthread+0x28f/0x360 [ 4024.978758][ T11] ret_from_fork+0x31/0x70 [ 4024.978985][ T11] ret_from_fork_asm+0x1b/0x30 [ 4024.979226][ T11] [ 4024.979346][ T11] Freed by task 11: [ 4024.979537][ T11] kasan_save_stack+0x24/0x50 [ 4024.979774][ T11] kasan_save_track+0x14/0x30 [ 4024.980016][ T11] kasan_save_free_info+0x3f/0x60 [ 4024.980271][ T11] __kasan_slab_free+0xfc/0x1c0 [ 4024.980521][ T11] kfree+0xf2/0x2d0 [ 4024.980715][ T11] skb_release_data+0x544/0x740 [ 4024.980961][ T11] consume_skb+0xad/0x110 [ 4024.981180][ T11] netlink_broadcast_filtered+0x224/0x340 [ 4024.981471][ T11] nlmsg_notify+0x6e/0x1e0 [ 4024.981701][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 4024.981921][ T11] dev_close_many+0x2bd/0x650 [ 4024.982157][ T11] unregister_netdevice_many_notify+0x3d5/0x1180 [ 4024.982492][ T11] default_device_exit_batch+0x228/0x2c0 [ 4024.982782][ T11] cleanup_net+0x4f3/0xa20 [ 4024.983007][ T11] process_one_work+0x78c/0x1310 [ 4024.983258][ T11] worker_thread+0x73d/0x1010 [ 4024.983496][ T11] kthread+0x28f/0x360 [ 4024.983701][ T11] ret_from_fork+0x31/0x70 [ 4024.983927][ T11] ret_from_fork_asm+0x1b/0x30 [ 4024.984170][ T11] [ 4024.984290][ T11] The buggy address belongs to the object at ffff888007e80800 [ 4024.984290][ T11] which belongs to the cache kmalloc-2k of size 2048 [ 4024.984982][ T11] The buggy address is located 976 bytes inside of [ 4024.984982][ T11] freed 2048-byte region [ffff888007e80800, ffff888007e81000) [ 4024.985671][ T11] [ 4024.985792][ T11] The buggy address belongs to the physical page: [ 4024.986116][ T11] page:ffffea00001fa000 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x7e80 [ 4024.986622][ T11] head:ffffea00001fa000 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 4024.987065][ T11] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 4024.987393][ T11] page_type: 0xffffffff() [ 4024.987614][ T11] raw: 0080000000000840 ffff888001043540 ffffea00000a1610 ffff8880010418f0 [ 4024.988043][ T11] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 4024.988474][ T11] page dumped because: kasan: bad access detected [ 4024.988793][ T11] [ 4024.988914][ T11] Memory state around the buggy address: [ 4024.989201][ T11] ffff888007e80a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 4024.989600][ T11] ffff888007e80b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 4024.990002][ T11] >ffff888007e80b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 4024.990408][ T11] ^ [ 4024.990739][ T11] ffff888007e80c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 4024.991137][ T11] ffff888007e80c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 4024.991538][ T11] ================================================================== [ 4024.992338][ T11] Disabling lock debugging due to kernel taint [ 4024.992761][ T11] general protection fault, probably for non-canonical address 0xdffffc002000007d: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 4024.993396][ T11] KASAN: probably user-memory-access in range [0x00000001000003e8-0x00000001000003ef] [ 4024.993873][ T11] CPU: 0 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 4024.994347][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 4024.994955][ T11] Workqueue: netns cleanup_net [ 4024.995199][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 4024.995561][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 4024.996524][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010206 [ 4024.996837][ T11] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 4024.997233][ T11] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff888007e80c24 [ 4024.997652][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100135381a R09: ffffc900000bf9b8 [ 4024.998091][ T11] R10: ffffffffabd3ca07 R11: 205d313154202020 R12: ffffed100135381a [ 4024.998507][ T11] R13: ffff888007e80ba0 R14: ffff888009ab9000 R15: ffff888009a9c000 [ 4024.998904][ T11] FS: 0000000000000000(0000) GS:ffff888035200000(0000) knlGS:0000000000000000 [ 4024.999350][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4024.999681][ T11] CR2: 00007f612c5b1270 CR3: 0000000005ccc002 CR4: 0000000000770ef0 [ 4025.000088][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 4025.000491][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 4025.000887][ T11] PKRU: 55555554 [ 4025.001068][ T11] Call Trace: [ 4025.001238][ T11] [ 4025.001395][ T11] ? die_addr+0x41/0xa0 [ 4025.001613][ T11] ? exc_general_protection+0x149/0x220 [ 4025.001897][ T11] ? asm_exc_general_protection+0x26/0x30 [ 4025.002190][ T11] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 4025.002514][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 4025.002856][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 4025.003143][ T11] notifier_call_chain+0x9a/0x290 [ 4025.003402][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 4025.003722][ T11] ? mutex_is_locked+0x17/0x50 [ 4025.003963][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 4025.004302][ T11] ? vrf_dellink+0x101/0x150 [vrf] [ 4025.004572][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 4025.004893][ T11] default_device_exit_batch+0x228/0x2c0 [ 4025.005177][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 4025.005486][ T11] ? mutex_is_locked+0x17/0x50 [ 4025.005727][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 4025.006031][ T11] cleanup_net+0x4f3/0xa20 [ 4025.006262][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 4025.006551][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 4025.006802][ T11] ? lock_acquire+0x1c1/0x220 [ 4025.007039][ T11] ? process_one_work+0x714/0x1310 [ 4025.007299][ T11] process_one_work+0x78c/0x1310 [ 4025.007551][ T11] ? hlock_class+0x4e/0x130 [ 4025.007782][ T11] ? __pfx_process_one_work+0x10/0x10 [ 4025.008054][ T11] ? assign_work+0x16c/0x240 [ 4025.008300][ T11] worker_thread+0x73d/0x1010 [ 4025.008541][ T11] ? __pfx_worker_thread+0x10/0x10 [ 4025.008802][ T11] kthread+0x28f/0x360 [ 4025.009008][ T11] ? __pfx_kthread+0x10/0x10 [ 4025.009242][ T11] ret_from_fork+0x31/0x70 [ 4025.009466][ T11] ? __pfx_kthread+0x10/0x10 [ 4025.009700][ T11] ret_from_fork_asm+0x1b/0x30 [ 4025.009950][ T11] [ 4025.010104][ T11] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel bridge stp llc 8021q sch_ingress vrf veth [ 4025.010687][ T11] ---[ end trace 0000000000000000 ]--- [ 4025.011056][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 4025.011922][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 4025.012961][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010206 [ 4025.013317][ T11] RAX: 000000002000007d RBX: 00000001000003b8 RCX: dffffc0000000000 [ 4025.013788][ T11] RDX: 00000001000003e8 RSI: 0000000000000004 RDI: ffff888007e80c24 [ 4025.014189][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100135381a R09: ffffc900000bf9b8 [ 4025.014642][ T11] R10: ffffffffabd3ca07 R11: 205d313154202020 R12: ffffed100135381a [ 4025.015091][ T11] R13: ffff888007e80ba0 R14: ffff888009ab9000 R15: ffff888009a9c000 [ 4025.015562][ T11] FS: 0000000000000000(0000) GS:ffff888035200000(0000) knlGS:0000000000000000 [ 4025.016062][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4025.016469][ T11] CR2: 00007f612c5b1270 CR3: 0000000005ccc002 CR4: 0000000000770ef0 [ 4025.016953][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 4025.017426][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 4025.017887][ T11] PKRU: 55555554 [ 4025.018070][ T11] Kernel panic - not syncing: Fatal exception [ 4025.018487][ T11] Kernel Offset: 0x25600000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 4025.019074][ T11] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout