make -C tools/testing/selftests TARGETS=net TEST_PROGS=udpgro_fwd.sh TEST__GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-3/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' TAP version 13 1..1 # timeout set to 6000 # selftests: net: udpgro_fwd.sh # IPv4 # No GRO ok # GRO frag list ok # GRO fwd ok # UDP fwd perf udp rx: 2 MB/s 2201 calls/s # udp tx: 10 MB/s 185 calls/s 185 msg/s # udp rx: 10 MB/s 8592 calls/s # udp tx: 10 MB/s 182 calls/s 182 msg/s # udp rx: 10 MB/s 8784 calls/s # UDP GRO fwd perf udp rx: 5 MB/s 4464 calls/s # udp tx: 10 MB/s 170 calls/s 170 msg/s # udp rx: 9 MB/s 8094 calls/s # udp tx: 10 MB/s 170 calls/s 170 msg/s # udp rx: 9 MB/s 7728 calls/s # GRO frag list over UDP tunnel ok [ 222.836065][ T11] ================================================================== [ 222.836553][ T11] BUG: KASAN: use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 222.837028][ T11] Read of size 8 at addr ffff88800a818bf0 by task kworker/u8:0/11 [ 222.837458][ T11] [ 222.837604][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 222.838021][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 222.838691][ T11] Workqueue: netns cleanup_net [ 222.838978][ T11] Call Trace: [ 222.839165][ T11] [ 222.839319][ T11] dump_stack_lvl+0x64/0xb0 [ 222.839585][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 222.839957][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 222.840305][ T11] print_report+0xb5/0x270 [ 222.840547][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 222.840830][ T11] kasan_report+0xbe/0xf0 [ 222.841084][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 222.841417][ T11] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 222.841740][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 222.842088][ T11] ? nft_offload_netdev_event+0x158/0x3b0 [nf_tables] [ 222.842512][ T11] notifier_call_chain+0x9a/0x290 [ 222.842777][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 222.843104][ T11] ? mutex_is_locked+0x17/0x50 [ 222.843353][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 222.843699][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 222.844022][ T11] default_device_exit_batch+0x228/0x2c0 [ 222.844311][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 222.844626][ T11] ? mutex_is_locked+0x17/0x50 [ 222.844874][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 222.845181][ T11] cleanup_net+0x4f3/0xb50 [ 222.845410][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 222.845704][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 222.845962][ T11] ? lock_acquire+0x1c1/0x220 [ 222.846204][ T11] ? process_one_work+0x714/0x1310 [ 222.846472][ T11] process_one_work+0x78c/0x1310 [ 222.846730][ T11] ? hlock_class+0x4e/0x130 [ 222.846965][ T11] ? __pfx_process_one_work+0x10/0x10 [ 222.847253][ T11] ? assign_work+0x16c/0x240 [ 222.847497][ T11] worker_thread+0x73d/0x1010 [ 222.847765][ T11] ? __pfx_worker_thread+0x10/0x10 [ 222.848065][ T11] kthread+0x28f/0x360 [ 222.848303][ T11] ? __pfx_kthread+0x10/0x10 [ 222.848546][ T11] ret_from_fork+0x31/0x70 [ 222.848784][ T11] ? __pfx_kthread+0x10/0x10 [ 222.849054][ T11] ret_from_fork_asm+0x1b/0x30 [ 222.849331][ T11] [ 222.849490][ T11] [ 222.849641][ T11] The buggy address belongs to the physical page: [ 222.849977][ T11] page:ffffea00002a0600 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xa818 [ 222.850542][ T11] flags: 0x80000000000000(node=0|zone=1) [ 222.850833][ T11] page_type: 0xffffffff() [ 222.851091][ T11] raw: 0080000000000000 ffffea00002a0808 ffff888036001c38 0000000000000000 [ 222.851559][ T11] raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 222.852032][ T11] page dumped because: kasan: bad access detected [ 222.852385][ T11] [ 222.852510][ T11] Memory state around the buggy address: [ 222.852809][ T11] ffff88800a818a80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 222.853270][ T11] ffff88800a818b00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 222.853704][ T11] >ffff88800a818b80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 222.854130][ T11] ^ [ 222.854573][ T11] ffff88800a818c00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 222.855000][ T11] ffff88800a818c80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [ 222.855426][ T11] ================================================================== [ 222.855904][ T11] Disabling lock debugging due to kernel taint # GRO fwd over UDP tunnel ok # UDP tunnel fwd perf udp rx: 6 MB/s 5280 calls/s # udp tx: 12 MB/s 210 calls/s 210 msg/s # udp rx: 13 MB/s 10848 calls/s # udp tx: 12 MB/s 215 calls/s 215 msg/s # udp rx: 12 MB/s 10176 calls/s # udp tx: 12 MB/s 220 calls/s 220 msg/s # UDP tunnel GRO fwd perf udp rx: 3 MB/s 3120 calls/s # udp tx: 12 MB/s 208 calls/s 208 msg/s # udp rx: 12 MB/s 10128 calls/s # udp tx: 11 MB/s 199 calls/s 199 msg/s # udp rx: 11 MB/s 9696 calls/s [ 245.219681][ T11] general protection fault, probably for non-canonical address 0xf999959999999999: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 245.220402][ T11] KASAN: maybe wild-memory-access in range [0xccccccccccccccc8-0xcccccccccccccccf] [ 245.220898][ T11] CPU: 1 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 245.221443][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 245.222114][ T11] Workqueue: netns cleanup_net [ 245.222398][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 245.222778][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 245.223889][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010a07 [ 245.224235][ T11] RAX: 1999999999999999 RBX: cccccccccccccc9c RCX: dffffc0000000000 [ 245.224704][ T11] RDX: cccccccccccccccc RSI: 0000000000000004 RDI: ffff888006b58c44 [ 245.225150][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100141721a R09: ffffc900000bf9b8 [ 245.225581][ T11] R10: ffffffffad750f57 R11: ffff88800a0b9000 R12: ffffed100141721a [ 245.225996][ T11] R13: ffff888006b58bc0 R14: ffff888005a14000 R15: ffff88800a0b9000 [ 245.226399][ T11] FS: 0000000000000000(0000) GS:ffff888035600000(0000) knlGS:0000000000000000 [ 245.226852][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 245.227190][ T11] CR2: 00007f53af858000 CR3: 0000000016134001 CR4: 0000000000770ef0 [ 245.227598][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 245.228003][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 245.228409][ T11] PKRU: 55555554 [ 245.228593][ T11] Call Trace: [ 245.228767][ T11] [ 245.228927][ T11] ? die_addr+0x41/0xa0 [ 245.229148][ T11] ? exc_general_protection+0x149/0x220 [ 245.229437][ T11] ? asm_exc_general_protection+0x26/0x30 [ 245.229734][ T11] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 245.230068][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 245.230415][ T11] ? nft_offload_netdev_event+0x158/0x3b0 [nf_tables] [ 245.230812][ T11] ? addrconf_notify+0xd1/0xd40 [ 245.231109][ T11] notifier_call_chain+0x9a/0x290 [ 245.231381][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 245.231711][ T11] ? mutex_is_locked+0x17/0x50 [ 245.231971][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 245.232329][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 245.232660][ T11] ? __wake_up+0x44/0x60 [ 245.232885][ T11] default_device_exit_batch+0x228/0x2c0 [ 245.233208][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 245.233608][ T11] ? mutex_is_locked+0x17/0x50 [ 245.233893][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 245.234231][ T11] cleanup_net+0x4f3/0xb50 [ 245.234486][ T11] ? lock_acquire+0x1c1/0x220 [ 245.234736][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 245.235017][ T11] ? lock_acquire+0x1c1/0x220 [ 245.235288][ T11] ? process_one_work+0x714/0x1310 [ 245.235581][ T11] process_one_work+0x78c/0x1310 [ 245.235864][ T11] ? hlock_class+0x4e/0x130 [ 245.236131][ T11] ? __pfx_process_one_work+0x10/0x10 [ 245.236421][ T11] ? assign_work+0x16c/0x240 [ 245.236668][ T11] worker_thread+0x73d/0x1010 [ 245.236933][ T11] ? __pfx_worker_thread+0x10/0x10 [ 245.237222][ T11] kthread+0x28f/0x360 [ 245.237455][ T11] ? __pfx_kthread+0x10/0x10 [ 245.237699][ T11] ret_from_fork+0x31/0x70 [ 245.237954][ T11] ? __pfx_kthread+0x10/0x10 [ 245.238218][ T11] ret_from_fork_asm+0x1b/0x30 [ 245.238489][ T11] [ 245.238650][ T11] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel nft_chain_nat xt_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nft_compat nf_tables libcrc32c [ 245.239954][ T11] ---[ end trace 0000000000000000 ]--- [ 245.240290][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 245.240673][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 245.241753][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010a07 [ 245.242088][ T11] RAX: 1999999999999999 RBX: cccccccccccccc9c RCX: dffffc0000000000 [ 245.242552][ T11] RDX: cccccccccccccccc RSI: 0000000000000004 RDI: ffff888006b58c44 [ 245.242990][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100141721a R09: ffffc900000bf9b8 [ 245.243431][ T11] R10: ffffffffad750f57 R11: ffff88800a0b9000 R12: ffffed100141721a [ 245.243867][ T11] R13: ffff888006b58bc0 R14: ffff888005a14000 R15: ffff88800a0b9000 [ 245.244346][ T11] FS: 0000000000000000(0000) GS:ffff888035600000(0000) knlGS:0000000000000000 [ 245.244855][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 245.245206][ T11] CR2: 00007f53af858000 CR3: 0000000016134001 CR4: 0000000000770ef0 [ 245.245632][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 245.246061][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 245.246473][ T11] PKRU: 55555554 [ 245.246659][ T11] Kernel panic - not syncing: Fatal exception [ 245.247112][ T11] Kernel Offset: 0x27e00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 245.247724][ T11] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout