make -C tools/testing/selftests TARGETS=net TEST_PROGS=amt.sh TEST_GEN_PROOGS="" run_tests make: Entering directory '/home/virtme/testing-3/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' TAP version 13 1..1 # timeout set to 6000 # selftests: net: amt.sh [ 99.781154][ T1322] br0: port 1(gw_l) entered blocking state [ 99.781583][ T1322] br0: port 1(gw_l) entered disabled state [ 99.781945][ T1322] gw_l: entered allmulticast mode [ 99.784186][ T1322] gw_l: entered promiscuous mode [ 99.785689][ T1322] br0: port 1(gw_l) entered blocking state [ 99.786071][ T1322] br0: port 1(gw_l) entered forwarding state [ 100.346056][ T1324] br0: port 2(amtg) entered blocking state [ 100.346460][ T1324] br0: port 2(amtg) entered disabled state [ 100.346878][ T1324] amtg: entered allmulticast mode [ 100.348569][ T1324] amtg: entered promiscuous mode [ 102.238548][ T1335] br0: port 2(amtg) entered blocking state [ 102.238911][ T1335] br0: port 2(amtg) entered forwarding state [ 103.425874][ T1342] amtr: entered allmulticast mode [ 103.426361][ T1342] relay_gw: entered allmulticast mode [ 103.426771][ T1342] relay_src: entered allmulticast mode # smcroutectl: Cannot find IPC socket /usr/local/var/run/smcroute.sock # smcroutectl: Daemon may be running with another -i NAME [ 103.641959][ T71] br0: port 1(gw_l) entered disabled state [ 103.657640][ T71] gw_l (unregistering): left allmulticast mode [ 103.659311][ T71] gw_l (unregistering): left promiscuous mode [ 103.659968][ T71] br0: port 1(gw_l) entered disabled state [ 103.743342][ T71] amtg: left allmulticast mode [ 103.743656][ T71] amtg: left promiscuous mode [ 103.744060][ T71] br0: port 2(amtg) entered disabled state [ 103.754179][ T71] ================================================================== [ 103.754642][ T71] BUG: KASAN: slab-use-after-free in kobject_put+0xc7/0xe0 [ 103.755032][ T71] Read of size 1 at addr ffff88800311ccfc by task kworker/u8:1/71 [ 103.755455][ T71] [ 103.755585][ T71] CPU: 3 PID: 71 Comm: kworker/u8:1 Not tainted 6.8.0-rc2-virtme #1 [ 103.756040][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 103.756756][ T71] Workqueue: netns cleanup_net [ 103.757032][ T71] Call Trace: [ 103.757256][ T71] [ 103.757424][ T71] dump_stack_lvl+0x64/0xb0 [ 103.757672][ T71] print_address_description.constprop.0+0x2c/0x3b0 [ 103.758057][ T71] ? kobject_put+0xc7/0xe0 [ 103.758327][ T71] print_report+0xb5/0x270 [ 103.758572][ T71] ? kasan_addr_to_slab+0x4e/0x90 [ 103.758871][ T71] kasan_report+0xbe/0xf0 [ 103.759102][ T71] ? kobject_put+0xc7/0xe0 [ 103.759381][ T71] kobject_put+0xc7/0xe0 [ 103.759636][ T71] br_sysfs_delbr+0x3f/0x70 [ 103.759901][ T71] br_dev_delete+0x10d/0x190 [ 103.760159][ T71] br_net_exit_batch_rtnl+0xd6/0x190 [ 103.760572][ T71] cleanup_net+0x499/0xb50 [ 103.760836][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 103.761143][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 103.761428][ T71] ? lock_acquire+0x1c1/0x220 [ 103.761704][ T71] ? process_one_work+0x714/0x1310 [ 103.762002][ T71] process_one_work+0x78f/0x1310 [ 103.762273][ T71] ? hlock_class+0x4e/0x130 [ 103.762539][ T71] ? __pfx_process_one_work+0x10/0x10 [ 103.762854][ T71] ? assign_work+0x16c/0x240 [ 103.763121][ T71] worker_thread+0x73d/0x1010 [ 103.763375][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 103.763729][ T71] ? __pfx_worker_thread+0x10/0x10 [ 103.764003][ T71] ? __pfx_worker_thread+0x10/0x10 [ 103.764272][ T71] kthread+0x292/0x360 [ 103.764488][ T71] ? __pfx_kthread+0x10/0x10 [ 103.764730][ T71] ret_from_fork+0x34/0x70 [ 103.764971][ T71] ? __pfx_kthread+0x10/0x10 [ 103.765218][ T71] ret_from_fork_asm+0x1b/0x30 [ 103.765502][ T71] [ 103.765678][ T71] [ 103.765811][ T71] Allocated by task 1320: [ 103.766058][ T71] kasan_save_stack+0x24/0x50 [ 103.766315][ T71] kasan_save_track+0x14/0x30 [ 103.766585][ T71] __kasan_kmalloc+0x7f/0x90 [ 103.766854][ T71] kobject_create_and_add+0x44/0xc0 [ 103.767144][ T71] br_sysfs_addbr+0x57/0x160 [ 103.767395][ T71] br_device_event+0x1ff/0x740 [ 103.767675][ T71] notifier_call_chain+0x9d/0x290 [ 103.767965][ T71] register_netdevice+0x116d/0x17a0 [ 103.768257][ T71] br_dev_newlink+0x2b/0x100 [ 103.768514][ T71] rtnl_newlink_create+0x344/0x850 [ 103.768809][ T71] __rtnl_newlink+0xad2/0xd60 [ 103.769081][ T71] rtnl_newlink+0x63/0xa0 [ 103.769336][ T71] rtnetlink_rcv_msg+0x2fe/0xb80 [ 103.769605][ T71] netlink_rcv_skb+0x133/0x360 [ 103.769885][ T71] netlink_unicast+0x44c/0x710 [ 103.770166][ T71] netlink_sendmsg+0x726/0xbe0 [ 103.770446][ T71] ____sys_sendmsg+0x7b5/0xa10 [ 103.770713][ T71] ___sys_sendmsg+0xee/0x170 [ 103.770975][ T71] __sys_sendmsg+0xcd/0x170 [ 103.771230][ T71] do_syscall_64+0xcc/0x1e0 [ 103.771501][ T71] entry_SYSCALL_64_after_hwframe+0x6f/0x77 [ 103.771842][ T71] [ 103.771968][ T71] Freed by task 71: [ 103.772196][ T71] kasan_save_stack+0x24/0x50 [ 103.772463][ T71] kasan_save_track+0x14/0x30 [ 103.772723][ T71] kasan_save_free_info+0x3f/0x60 [ 103.773022][ T71] __kasan_slab_free+0xfc/0x1c0 [ 103.773303][ T71] kfree+0xf2/0x2d0 [ 103.773526][ T71] kobject_cleanup+0xe2/0x280 [ 103.773782][ T71] br_sysfs_delbr+0x3f/0x70 [ 103.774041][ T71] br_dev_delete+0x10d/0x190 [ 103.774315][ T71] default_device_exit_batch_rtnl+0x112/0x210 [ 103.774652][ T71] cleanup_net+0x499/0xb50 [ 103.774896][ T71] process_one_work+0x78f/0x1310 [ 103.775192][ T71] worker_thread+0x73d/0x1010 [ 103.775447][ T71] kthread+0x292/0x360 [ 103.775677][ T71] ret_from_fork+0x34/0x70 [ 103.775921][ T71] ret_from_fork_asm+0x1b/0x30 [ 103.776193][ T71] [ 103.776341][ T71] The buggy address belongs to the object at ffff88800311ccc0 [ 103.776341][ T71] which belongs to the cache kmalloc-64 of size 64 [ 103.777091][ T71] The buggy address is located 60 bytes inside of [ 103.777091][ T71] freed 64-byte region [ffff88800311ccc0, ffff88800311cd00) [ 103.777799][ T71] [ 103.777924][ T71] The buggy address belongs to the physical page: [ 103.778263][ T71] page:ffffea00000c4700 refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800311c900 pfn:0x311c [ 103.778861][ T71] head:ffffea00000c4700 order:1 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 103.779383][ T71] flags: 0x80000000000a40(workingset|slab|head|node=0|zone=1) [ 103.779794][ T71] page_type: 0xffffffff() [ 103.780032][ T71] raw: 0080000000000a40 ffff888001042900 ffffea000017ee90 ffffea00002a2e90 [ 103.780533][ T71] raw: ffff88800311c900 0000000000190013 00000001ffffffff 0000000000000000 [ 103.781009][ T71] page dumped because: kasan: bad access detected [ 103.781381][ T71] [ 103.781507][ T71] Memory state around the buggy address: [ 103.781832][ T71] ffff88800311cb80: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc [ 103.782284][ T71] ffff88800311cc00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 103.782750][ T71] >ffff88800311cc80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 103.783201][ T71] ^ [ 103.783637][ T71] ffff88800311cd00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 103.784093][ T71] ffff88800311cd80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 103.784511][ T71] ================================================================== [ 103.784961][ T71] Disabling lock debugging due to kernel taint [ 103.785333][ T71] ------------[ cut here ]------------ [ 103.785644][ T71] refcount_t: underflow; use-after-free. [ 103.785996][ T71] WARNING: CPU: 3 PID: 71 at lib/refcount.c:28 refcount_warn_saturate+0x173/0x1b0 [ 103.786576][ T71] Modules linked in: xt_HL nft_compat nf_tables libcrc32c amt udp_tunnel xfrm_interface sha1_generic xfrm_user [ 103.787275][ T71] CPU: 3 PID: 71 Comm: kworker/u8:1 Tainted: G B 6.8.0-rc2-virtme #1 [ 103.787771][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 103.788485][ T71] Workqueue: netns cleanup_net [ 103.788751][ T71] RIP: 0010:refcount_warn_saturate+0x173/0x1b0 [ 103.789140][ T71] Code: f9 82 03 80 fb 01 0f 87 ee 02 b1 01 83 e3 01 0f 85 4d ff ff ff c6 05 9a f9 82 03 01 90 48 c7 c7 20 7a 82 8e e8 3e 05 2a ff 90 <0f> 0b 90 90 e9 2f ff ff ff 48 89 df e8 8c 68 a6 ff e9 b6 fe ff ff [ 103.790286][ T71] RSP: 0018:ffffc9000051fb98 EFLAGS: 00010282 [ 103.790635][ T71] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff8bb1056f [ 103.791109][ T71] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 0000000000000001 [ 103.791564][ T71] RBP: 0000000000000003 R08: 0000000000000000 R09: fffff520000a3f18 [ 103.792042][ T71] R10: ffffc9000051f8c7 R11: 205d313754202020 R12: ffff88800a322000 [ 103.792490][ T71] R13: ffff88800a322df8 R14: ffffc9000051fc98 R15: ffff88800a322bc0 [ 103.793054][ T71] FS: 0000000000000000(0000) GS:ffff888035e00000(0000) knlGS:0000000000000000 [ 103.793537][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 103.793921][ T71] CR2: 00005568b6beedec CR3: 000000002eb34006 CR4: 00000000001706f0 [ 103.794348][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 103.794765][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 103.795188][ T71] Call Trace: [ 103.795365][ T71] [ 103.795527][ T71] ? __warn+0xcd/0x2d0 [ 103.795786][ T71] ? refcount_warn_saturate+0x173/0x1b0 [ 103.796124][ T71] ? report_bug+0x291/0x2e0 [ 103.796418][ T71] ? vprintk_emit+0xff/0x1d0 [ 103.796687][ T71] ? handle_bug+0x3d/0x80 [ 103.796955][ T71] ? exc_invalid_op+0x18/0x50 [ 103.797230][ T71] ? asm_exc_invalid_op+0x1a/0x20 [ 103.797543][ T71] ? desc_read+0x2af/0x440 [ 103.797793][ T71] ? refcount_warn_saturate+0x173/0x1b0 [ 103.798151][ T71] ? refcount_warn_saturate+0x172/0x1b0 [ 103.798609][ T71] br_sysfs_delbr+0x3f/0x70 [ 103.799018][ T71] br_dev_delete+0x10d/0x190 [ 103.799421][ T71] br_net_exit_batch_rtnl+0xd6/0x190 [ 103.799867][ T71] cleanup_net+0x499/0xb50 [ 103.800200][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 103.800663][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 103.801069][ T71] ? lock_acquire+0x1c1/0x220 [ 103.801451][ T71] ? process_one_work+0x714/0x1310 [ 103.801880][ T71] process_one_work+0x78f/0x1310 [ 103.802327][ T71] ? hlock_class+0x4e/0x130 [ 103.802732][ T71] ? __pfx_process_one_work+0x10/0x10 [ 103.803210][ T71] ? assign_work+0x16c/0x240 [ 103.803589][ T71] worker_thread+0x73d/0x1010 [ 103.803970][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 103.804478][ T71] ? __pfx_worker_thread+0x10/0x10 [ 103.804913][ T71] ? __pfx_worker_thread+0x10/0x10 [ 103.805327][ T71] kthread+0x292/0x360 [ 103.805643][ T71] ? __pfx_kthread+0x10/0x10 [ 103.806035][ T71] ret_from_fork+0x34/0x70 [ 103.806390][ T71] ? __pfx_kthread+0x10/0x10 [ 103.806756][ T71] ret_from_fork_asm+0x1b/0x30 [ 103.807150][ T71] [ 103.807396][ T71] irq event stamp: 470075 [ 103.807742][ T71] hardirqs last enabled at (470075): [] irqentry_exit+0x3b/0x90 [ 103.808485][ T71] hardirqs last disabled at (470074): [] __do_softirq+0x670/0x7ff [ 103.809220][ T71] softirqs last enabled at (470056): [] br_dev_delete+0xd8/0x190 [ 103.809975][ T71] softirqs last disabled at (470054): [] br_fdb_delete_by_port+0x36/0x260 [ 103.810766][ T71] ---[ end trace 0000000000000000 ]--- [ 103.811244][ T71] ------------[ cut here ]------------ [ 103.811768][ T71] sysfs group 'bridge' not found for kobject 'br0' [ 103.812567][ T71] WARNING: CPU: 2 PID: 71 at fs/sysfs/group.c:282 sysfs_remove_group+0x101/0x160 [ 103.813325][ T71] Modules linked in: xt_HL nft_compat nf_tables libcrc32c amt udp_tunnel xfrm_interface sha1_generic xfrm_user [ 103.814302][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Tainted: G B W 6.8.0-rc2-virtme #1 [ 103.815086][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 103.816091][ T71] Workqueue: netns cleanup_net [ 103.816492][ T71] RIP: 0010:sysfs_remove_group+0x101/0x160 [ 103.816975][ T71] Code: 89 d9 49 8b 14 24 48 b8 00 00 00 00 00 fc ff df 48 c1 e9 03 80 3c 01 00 75 45 48 8b 33 48 c7 c7 a0 a7 7c 8e e8 60 65 5e ff 90 <0f> 0b 90 90 48 83 c4 08 5b 5d 41 5c c3 cc cc cc cc e8 e9 c7 da ff [ 103.818554][ T71] RSP: 0018:ffffc9000051fba0 EFLAGS: 00010282 [ 103.819051][ T71] RAX: 0000000000000000 RBX: ffffffff8ebbe220 RCX: ffffffff8bb1056f [ 103.819705][ T71] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 0000000000000001 [ 103.820353][ T71] RBP: 0000000000000000 R08: 0000000000000000 R09: fffff520000a3f19 [ 103.821078][ T71] R10: ffffc9000051f8cf R11: 205d313754202020 R12: ffff88800a322628 [ 103.821760][ T71] R13: ffff88800a322df8 R14: ffffc9000051fc98 R15: ffff88800a322bc0 [ 103.822445][ T71] FS: 0000000000000000(0000) GS:ffff888035a00000(0000) knlGS:0000000000000000 [ 103.823149][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 103.823674][ T71] CR2: 00007f54ee673000 CR3: 000000002eb34002 CR4: 00000000001706f0 [ 103.824309][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 103.824932][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 103.825558][ T71] Call Trace: [ 103.825846][ T71] [ 103.826094][ T71] ? __warn+0xcd/0x2d0 [ 103.826453][ T71] ? console_trylock+0x61/0xf0 [ 103.826887][ T71] ? sysfs_remove_group+0x101/0x160 [ 103.827321][ T71] ? report_bug+0x291/0x2e0 [ 103.827696][ T71] ? handle_bug+0x3d/0x80 [ 103.828051][ T71] ? exc_invalid_op+0x18/0x50 [ 103.828424][ T71] ? asm_exc_invalid_op+0x1a/0x20 [ 103.828828][ T71] ? desc_read+0x2af/0x440 [ 103.829194][ T71] ? sysfs_remove_group+0x101/0x160 [ 103.829640][ T71] br_dev_delete+0x10d/0x190 [ 103.830066][ T71] br_net_exit_batch_rtnl+0xd6/0x190 [ 103.830507][ T71] cleanup_net+0x499/0xb50 [ 103.830875][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 103.831351][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 103.831771][ T71] ? lock_acquire+0x1c1/0x220 [ 103.832187][ T71] ? process_one_work+0x714/0x1310 [ 103.832613][ T71] process_one_work+0x78f/0x1310 [ 103.833052][ T71] ? hlock_class+0x4e/0x130 [ 103.833455][ T71] ? __pfx_process_one_work+0x10/0x10 [ 103.833908][ T71] ? assign_work+0x16c/0x240 [ 103.834304][ T71] worker_thread+0x73d/0x1010 [ 103.834682][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 103.835215][ T71] ? __pfx_worker_thread+0x10/0x10 [ 103.835625][ T71] ? __pfx_worker_thread+0x10/0x10 [ 103.836043][ T71] kthread+0x292/0x360 [ 103.836368][ T71] ? __pfx_kthread+0x10/0x10 [ 103.836743][ T71] ret_from_fork+0x34/0x70 [ 103.837109][ T71] ? __pfx_kthread+0x10/0x10 [ 103.837474][ T71] ret_from_fork_asm+0x1b/0x30 [ 103.837862][ T71] [ 103.838157][ T71] irq event stamp: 470075 [ 103.838539][ T71] hardirqs last enabled at (470075): [] irqentry_exit+0x3b/0x90 [ 103.839329][ T71] hardirqs last disabled at (470074): [] __do_softirq+0x670/0x7ff [ 103.840105][ T71] softirqs last enabled at (470056): [] br_dev_delete+0xd8/0x190 [ 103.840888][ T71] softirqs last disabled at (470054): [] br_fdb_delete_by_port+0x36/0x260 [ 103.841734][ T71] ---[ end trace 0000000000000000 ]--- [ 103.880053][ T71] relay_gw (unregistering): left allmulticast mode [ 103.894543][ T71] amtr (unregistering): left allmulticast mode ok 1 selftests: net: amt.sh # SKIP make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make: Leaving directory '/home/virtme/testing-3/tools/testing/selftests' xx__-> echo $? 0 xx__-> [ 103.998299][ T71] relay_src (unregistering): left allmulticast mode xx__-> xx__->