make -C tools/testing/selftests TARGETS=net TEST_PROGS=traceroute.sh TEST__GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-3/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' TAP version 13 1..1 # timeout set to 6000 # selftests: net: traceroute.sh [ 568.676916][ T3192] eth3: renamed from tmp [ 569.935794][ T3199] eth2: renamed from tmp [ 571.828643][ T3209] eth0: renamed from tmp [ 572.377083][ T3212] br0: port 1(eth0) entered blocking state [ 572.377514][ T3212] br0: port 1(eth0) entered disabled state [ 572.377875][ T3212] eth0: entered allmulticast mode [ 572.379931][ T3212] eth0: entered promiscuous mode [ 572.381445][ T3212] br0: port 1(eth0) entered blocking state [ 572.381811][ T3212] br0: port 1(eth0) entered forwarding state [ 573.104420][ T3216] eth1: renamed from tmp [ 573.657694][ T3219] br0: port 2(eth1) entered blocking state [ 573.658063][ T3219] br0: port 2(eth1) entered disabled state [ 573.658420][ T3219] eth1: entered allmulticast mode [ 573.659641][ T3219] eth1: entered promiscuous mode [ 573.660661][ T3219] br0: port 2(eth1) entered blocking state [ 573.661014][ T3219] br0: port 2(eth1) entered forwarding state # TEST: IPV6 traceroute [ OK ] [ 578.257651][ T11] br0: port 1(eth0) entered disabled state [ 578.272429][ T11] eth0 (unregistering): left allmulticast mode [ 578.272889][ T11] eth0 (unregistering): left promiscuous mode [ 578.273258][ T11] br0: port 1(eth0) entered disabled state [ 578.744001][ T11] eth1: left allmulticast mode [ 578.744301][ T11] eth1: left promiscuous mode [ 578.744661][ T11] br0: port 2(eth1) entered disabled state [ 578.758028][ T11] ================================================================== [ 578.758519][ T11] BUG: KASAN: slab-use-after-free in kobject_put+0xc7/0xe0 [ 578.758938][ T11] Read of size 1 at addr ffff888004f1947c by task kworker/u8:0/11 [ 578.759427][ T11] [ 578.759557][ T11] CPU: 2 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 578.759995][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 578.760665][ T11] Workqueue: netns cleanup_net [ 578.760936][ T11] Call Trace: [ 578.761142][ T11] [ 578.761321][ T11] dump_stack_lvl+0x64/0xb0 [ 578.761587][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 578.761951][ T11] ? kobject_put+0xc7/0xe0 [ 578.762208][ T11] print_report+0xb5/0x270 [ 578.762495][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 578.762765][ T11] kasan_report+0xbe/0xf0 [ 578.763000][ T11] ? kobject_put+0xc7/0xe0 [ 578.763241][ T11] kobject_put+0xc7/0xe0 [ 578.763466][ T11] br_sysfs_delbr+0x3f/0x70 [ 578.763709][ T11] br_dev_delete+0x10d/0x190 [ 578.763960][ T11] br_net_exit_batch_rtnl+0xd6/0x190 [ 578.764243][ T11] cleanup_net+0x499/0xb50 [ 578.764481][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 578.764798][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 578.765075][ T11] ? lock_acquire+0x1c1/0x220 [ 578.765325][ T11] ? process_one_work+0x714/0x1310 [ 578.765599][ T11] process_one_work+0x78f/0x1310 [ 578.765867][ T11] ? hlock_class+0x4e/0x130 [ 578.766123][ T11] ? __pfx_process_one_work+0x10/0x10 [ 578.766412][ T11] ? assign_work+0x16c/0x240 [ 578.766661][ T11] worker_thread+0x73d/0x1010 [ 578.766912][ T11] ? __pfx_worker_thread+0x10/0x10 [ 578.767182][ T11] kthread+0x292/0x360 [ 578.767399][ T11] ? __pfx_kthread+0x10/0x10 [ 578.767646][ T11] ret_from_fork+0x34/0x70 [ 578.767887][ T11] ? __pfx_kthread+0x10/0x10 [ 578.768133][ T11] ret_from_fork_asm+0x1b/0x30 [ 578.768395][ T11] [ 578.768558][ T11] [ 578.768699][ T11] Allocated by task 3204: [ 578.768939][ T11] kasan_save_stack+0x24/0x50 [ 578.769225][ T11] kasan_save_track+0x14/0x30 [ 578.769487][ T11] __kasan_kmalloc+0x7f/0x90 [ 578.769751][ T11] kobject_create_and_add+0x44/0xc0 [ 578.770066][ T11] br_sysfs_addbr+0x57/0x160 [ 578.770313][ T11] br_device_event+0x1ff/0x740 [ 578.770564][ T11] notifier_call_chain+0x9d/0x290 [ 578.770857][ T11] register_netdevice+0x116d/0x17a0 [ 578.771168][ T11] br_dev_newlink+0x2b/0x100 [ 578.771421][ T11] rtnl_newlink_create+0x344/0x850 [ 578.771712][ T11] __rtnl_newlink+0xad2/0xd60 [ 578.771985][ T11] rtnl_newlink+0x63/0xa0 [ 578.772236][ T11] rtnetlink_rcv_msg+0x2fe/0xb80 [ 578.772506][ T11] netlink_rcv_skb+0x133/0x360 [ 578.772789][ T11] netlink_unicast+0x44c/0x710 [ 578.773067][ T11] netlink_sendmsg+0x726/0xbe0 [ 578.773341][ T11] ____sys_sendmsg+0x7b5/0xa10 [ 578.773600][ T11] ___sys_sendmsg+0xee/0x170 [ 578.773885][ T11] __sys_sendmsg+0xcd/0x170 [ 578.774137][ T11] do_syscall_64+0xcc/0x1e0 [ 578.774389][ T11] entry_SYSCALL_64_after_hwframe+0x6f/0x77 [ 578.774731][ T11] [ 578.774860][ T11] Freed by task 11: [ 578.775089][ T11] kasan_save_stack+0x24/0x50 [ 578.775361][ T11] kasan_save_track+0x14/0x30 [ 578.775628][ T11] kasan_save_free_info+0x3f/0x60 [ 578.775930][ T11] __kasan_slab_free+0xfc/0x1c0 [ 578.776224][ T11] kfree+0xf2/0x2d0 [ 578.776433][ T11] kobject_cleanup+0xe2/0x280 [ 578.776707][ T11] br_sysfs_delbr+0x3f/0x70 [ 578.776977][ T11] br_dev_delete+0x10d/0x190 [ 578.777242][ T11] default_device_exit_batch_rtnl+0x112/0x210 [ 578.777568][ T11] cleanup_net+0x499/0xb50 [ 578.777822][ T11] process_one_work+0x78f/0x1310 [ 578.778110][ T11] worker_thread+0x73d/0x1010 [ 578.778384][ T11] kthread+0x292/0x360 [ 578.778601][ T11] ret_from_fork+0x34/0x70 [ 578.778872][ T11] ret_from_fork_asm+0x1b/0x30 [ 578.779150][ T11] [ 578.779290][ T11] The buggy address belongs to the object at ffff888004f19440 [ 578.779290][ T11] which belongs to the cache kmalloc-64 of size 64 [ 578.780014][ T11] The buggy address is located 60 bytes inside of [ 578.780014][ T11] freed 64-byte region [ffff888004f19440, ffff888004f19480) [ 578.780722][ T11] [ 578.780848][ T11] The buggy address belongs to the physical page: [ 578.781184][ T11] page:ffffea000013c600 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4f18 [ 578.781716][ T11] head:ffffea000013c600 order:1 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 578.782244][ T11] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 578.782624][ T11] page_type: 0xffffffff() [ 578.782858][ T11] raw: 0080000000000840 ffff888001042900 ffffea0000141710 ffffea0000e03990 [ 578.783326][ T11] raw: 0000000000000000 0000000000190019 00000001ffffffff 0000000000000000 [ 578.783818][ T11] page dumped because: kasan: bad access detected [ 578.784176][ T11] [ 578.784312][ T11] Memory state around the buggy address: [ 578.784624][ T11] ffff888004f19300: 00 00 00 00 00 00 00 00 fc fc fc fc fc fc fc fc [ 578.785085][ T11] ffff888004f19380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 578.785522][ T11] >ffff888004f19400: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 578.785978][ T11] ^ [ 578.786419][ T11] ffff888004f19480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 578.786862][ T11] ffff888004f19500: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 578.787294][ T11] ================================================================== [ 578.787765][ T11] Disabling lock debugging due to kernel taint [ 578.788124][ T11] ------------[ cut here ]------------ [ 578.788461][ T11] refcount_t: underflow; use-after-free. [ 578.788804][ T11] WARNING: CPU: 2 PID: 11 at lib/refcount.c:28 refcount_warn_saturate+0x173/0x1b0 [ 578.789445][ T11] Modules linked in: xt_length nft_compat nf_tables act_ct nf_flow_table nf_nat nf_conntrack libcrc32c nf_defrag_ipv6 nf_defrag_ipv4 cls_flower sch_ingress [ 578.790356][ T11] CPU: 2 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 578.790995][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 578.791702][ T11] Workqueue: netns cleanup_net [ 578.791984][ T11] RIP: 0010:refcount_warn_saturate+0x173/0x1b0 [ 578.792340][ T11] Code: f9 82 03 80 fb 01 0f 87 ee 02 b1 01 83 e3 01 0f 85 4d ff ff ff c6 05 9a f9 82 03 01 90 48 c7 c7 20 7a 02 af e8 3e 05 2a ff 90 <0f> 0b 90 90 e9 2f ff ff ff 48 89 df e8 8c 68 a6 ff e9 b6 fe ff ff [ 578.793475][ T11] RSP: 0018:ffffc900000bfb98 EFLAGS: 00010282 [ 578.793828][ T11] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffffac31056f [ 578.794253][ T11] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 0000000000000001 [ 578.794671][ T11] RBP: 0000000000000003 R08: 0000000000000000 R09: fffff52000017f18 [ 578.795092][ T11] R10: ffffc900000bf8c7 R11: 205d313154202020 R12: ffff888009aa2000 [ 578.795512][ T11] R13: ffff888009aa2df8 R14: ffffc900000bfc98 R15: ffff888009aa2bc0 [ 578.795941][ T11] FS: 0000000000000000(0000) GS:ffff88802ee00000(0000) knlGS:0000000000000000 [ 578.796437][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 578.796786][ T11] CR2: 00007f72b6f76000 CR3: 0000000036734003 CR4: 00000000001706f0 [ 578.797213][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 578.797634][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 578.798131][ T11] Call Trace: [ 578.798312][ T11] [ 578.798473][ T11] ? __warn+0xcd/0x2d0 [ 578.798711][ T11] ? refcount_warn_saturate+0x173/0x1b0 [ 578.799033][ T11] ? report_bug+0x291/0x2e0 [ 578.799298][ T11] ? vprintk_emit+0xff/0x1d0 [ 578.799550][ T11] ? handle_bug+0x3d/0x80 [ 578.799782][ T11] ? exc_invalid_op+0x18/0x50 [ 578.800043][ T11] ? asm_exc_invalid_op+0x1a/0x20 [ 578.800314][ T11] ? desc_read+0x2af/0x440 [ 578.800551][ T11] ? refcount_warn_saturate+0x173/0x1b0 [ 578.800847][ T11] ? refcount_warn_saturate+0x172/0x1b0 [ 578.801146][ T11] br_sysfs_delbr+0x3f/0x70 [ 578.801393][ T11] br_dev_delete+0x10d/0x190 [ 578.801645][ T11] br_net_exit_batch_rtnl+0xd6/0x190 [ 578.801965][ T11] cleanup_net+0x499/0xb50 [ 578.802252][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 578.802561][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 578.802852][ T11] ? lock_acquire+0x1c1/0x220 [ 578.803132][ T11] ? process_one_work+0x714/0x1310 [ 578.803432][ T11] process_one_work+0x78f/0x1310 [ 578.803724][ T11] ? hlock_class+0x4e/0x130 [ 578.804060][ T11] ? __pfx_process_one_work+0x10/0x10 [ 578.804368][ T11] ? assign_work+0x16c/0x240 [ 578.804659][ T11] worker_thread+0x73d/0x1010 [ 578.804935][ T11] ? __pfx_worker_thread+0x10/0x10 [ 578.805226][ T11] kthread+0x292/0x360 [ 578.805444][ T11] ? __pfx_kthread+0x10/0x10 [ 578.805690][ T11] ret_from_fork+0x34/0x70 [ 578.806005][ T11] ? __pfx_kthread+0x10/0x10 [ 578.806264][ T11] ret_from_fork_asm+0x1b/0x30 [ 578.806523][ T11] [ 578.806692][ T11] irq event stamp: 3555133 [ 578.806936][ T11] hardirqs last enabled at (3555133): [] irqentry_exit+0x3b/0x90 [ 578.807432][ T11] hardirqs last disabled at (3555132): [] __do_softirq+0x670/0x7ff [ 578.808010][ T11] softirqs last enabled at (3555120): [] br_dev_delete+0xd8/0x190 [ 578.808555][ T11] softirqs last disabled at (3555118): [] br_fdb_delete_by_port+0x36/0x260 [ 578.809141][ T11] ---[ end trace 0000000000000000 ]--- [ 578.809453][ T11] ------------[ cut here ]------------ [ 578.809763][ T11] sysfs group 'bridge' not found for kobject 'br0' [ 578.810167][ T11] WARNING: CPU: 2 PID: 11 at fs/sysfs/group.c:282 sysfs_remove_group+0x101/0x160 [ 578.810703][ T11] Modules linked in: xt_length nft_compat nf_tables act_ct nf_flow_table nf_nat nf_conntrack libcrc32c nf_defrag_ipv6 nf_defrag_ipv4 cls_flower sch_ingress [ 578.811612][ T11] CPU: 2 PID: 11 Comm: kworker/u8:0 Tainted: G B W 6.8.0-rc2-virtme #1 [ 578.812154][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 578.812863][ T11] Workqueue: netns cleanup_net [ 578.813239][ T11] RIP: 0010:sysfs_remove_group+0x101/0x160 [ 578.813577][ T11] Code: 89 d9 49 8b 14 24 48 b8 00 00 00 00 00 fc ff df 48 c1 e9 03 80 3c 01 00 75 45 48 8b 33 48 c7 c7 a0 a7 fc ae e8 60 65 5e ff 90 <0f> 0b 90 90 48 83 c4 08 5b 5d 41 5c c3 cc cc cc cc e8 e9 c7 da ff [ 578.814601][ T11] RSP: 0018:ffffc900000bfba0 EFLAGS: 00010282 [ 578.814935][ T11] RAX: 0000000000000000 RBX: ffffffffaf3be220 RCX: ffffffffac31056f [ 578.815361][ T11] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 0000000000000001 [ 578.815780][ T11] RBP: 0000000000000000 R08: 0000000000000000 R09: fffff52000017f19 [ 578.816212][ T11] R10: ffffc900000bf8cf R11: 205d313154202020 R12: ffff888009aa2628 [ 578.816632][ T11] R13: ffff888009aa2df8 R14: ffffc900000bfc98 R15: ffff888009aa2bc0 [ 578.817100][ T11] FS: 0000000000000000(0000) GS:ffff88802ee00000(0000) knlGS:0000000000000000 [ 578.817599][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 578.817992][ T11] CR2: 00007f72b6f76000 CR3: 0000000036734003 CR4: 00000000001706f0 [ 578.818442][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 578.818919][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 578.819382][ T11] Call Trace: [ 578.819565][ T11] [ 578.819755][ T11] ? __warn+0xcd/0x2d0 [ 578.819992][ T11] ? console_trylock+0x61/0xf0 [ 578.820266][ T11] ? sysfs_remove_group+0x101/0x160 [ 578.820577][ T11] ? report_bug+0x291/0x2e0 [ 578.820841][ T11] ? handle_bug+0x3d/0x80 [ 578.821102][ T11] ? exc_invalid_op+0x18/0x50 [ 578.821382][ T11] ? asm_exc_invalid_op+0x1a/0x20 [ 578.821678][ T11] ? desc_read+0x2af/0x440 [ 578.822009][ T11] ? sysfs_remove_group+0x101/0x160 [ 578.822316][ T11] br_dev_delete+0x10d/0x190 [ 578.822588][ T11] br_net_exit_batch_rtnl+0xd6/0x190 [ 578.822888][ T11] cleanup_net+0x499/0xb50 [ 578.823161][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 578.823474][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 578.823762][ T11] ? lock_acquire+0x1c1/0x220 [ 578.824051][ T11] ? process_one_work+0x714/0x1310 [ 578.824339][ T11] process_one_work+0x78f/0x1310 [ 578.824624][ T11] ? hlock_class+0x4e/0x130 [ 578.824890][ T11] ? __pfx_process_one_work+0x10/0x10 [ 578.825207][ T11] ? assign_work+0x16c/0x240 [ 578.825476][ T11] worker_thread+0x73d/0x1010 [ 578.825757][ T11] ? __pfx_worker_thread+0x10/0x10 [ 578.826063][ T11] kthread+0x292/0x360 [ 578.826304][ T11] ? __pfx_kthread+0x10/0x10 [ 578.826551][ T11] ret_from_fork+0x34/0x70 [ 578.826789][ T11] ? __pfx_kthread+0x10/0x10 [ 578.827039][ T11] ret_from_fork_asm+0x1b/0x30 [ 578.827300][ T11] [ 578.827463][ T11] irq event stamp: 3555133 [ 578.827701][ T11] hardirqs last enabled at (3555133): [] irqentry_exit+0x3b/0x90 [ 578.828200][ T11] hardirqs last disabled at (3555132): [] __do_softirq+0x670/0x7ff [ 578.828771][ T11] softirqs last enabled at (3555120): [] br_dev_delete+0xd8/0x190 [ 578.829304][ T11] softirqs last disabled at (3555118): [] br_fdb_delete_by_port+0x36/0x260 [ 578.829974][ T11] ---[ end trace 0000000000000000 ]--- [ 583.053239][ T3279] eth1: renamed from tmp [ 584.201155][ T3288] eth2: renamed from tmp # TEST: IPV4 traceroute [ OK ] # # Tests passed: 2 # Tests failed: 0 ok 1 selftests: net: traceroute.sh make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make: Leaving directory '/home/virtme/testing-3/tools/testing/selftests' xx__-> echo $? 0 xx__->