make -C tools/testing/selftests TARGETS=net TEST_PROGS=pmtu.sh TEST_GEN_PRROGS="" run_tests make: Entering directory '/home/virtme/testing-3/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' TAP version 13 1..1 # timeout set to 6000 # selftests: net: pmtu.sh # TEST: ipv4: PMTU exceptions [ OK ] # TEST: ipv4: PMTU exceptions - nexthop objects [ OK ] # TEST: ipv6: PMTU exceptions [ OK ] # TEST: ipv6: PMTU exceptions - nexthop objects [ OK ] # TEST: ICMPv4 with DSCP and ECN: PMTU exceptions [ OK ] # TEST: ICMPv4 with DSCP and ECN: PMTU exceptions - nexthop objects [ OK ] # TEST: UDPv4 with DSCP and ECN: PMTU exceptions [ OK ] # TEST: UDPv4 with DSCP and ECN: PMTU exceptions - nexthop objects [ OK ] # TEST: IPv4 over vxlan4: PMTU exceptions [ OK ] [ 217.084477][ T11] ================================================================== [ 217.084964][ T11] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 217.085462][ T11] Read of size 8 at addr ffff888007578bf0 by task kworker/u8:0/11 [ 217.085861][ T11] [ 217.085993][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Not tainted 6.8.0-rc2-virtme #1 [ 217.086417][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 217.087072][ T11] Workqueue: netns cleanup_net [ 217.087337][ T11] Call Trace: [ 217.087517][ T11] [ 217.087730][ T11] dump_stack_lvl+0x64/0xb0 [ 217.087976][ T11] print_address_description.constprop.0+0x2c/0x3b0 [ 217.088436][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 217.088835][ T11] print_report+0xb5/0x270 [ 217.089080][ T11] ? kasan_addr_to_slab+0x4e/0x90 [ 217.089369][ T11] kasan_report+0xbe/0xf0 [ 217.089601][ T11] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 217.090007][ T11] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 217.090336][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 217.090698][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 217.091002][ T11] notifier_call_chain+0x9a/0x290 [ 217.091272][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 217.091659][ T11] ? mutex_is_locked+0x17/0x50 [ 217.091914][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 217.092337][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 217.092678][ T11] default_device_exit_batch+0x228/0x2c0 [ 217.092991][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 217.093321][ T11] ? mutex_is_locked+0x17/0x50 [ 217.093567][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 217.093938][ T11] cleanup_net+0x4f3/0xb50 [ 217.094167][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 217.094513][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 217.094774][ T11] ? lock_acquire+0x1c1/0x220 [ 217.095061][ T11] ? process_one_work+0x714/0x1310 [ 217.095332][ T11] process_one_work+0x78c/0x1310 [ 217.095607][ T11] ? hlock_class+0x4e/0x130 [ 217.095841][ T11] ? __pfx_process_one_work+0x10/0x10 [ 217.096190][ T11] ? assign_work+0x16c/0x240 [ 217.096430][ T11] worker_thread+0x73d/0x1010 [ 217.096738][ T11] ? __pfx_worker_thread+0x10/0x10 [ 217.097000][ T11] kthread+0x28f/0x360 [ 217.097211][ T11] ? __pfx_kthread+0x10/0x10 [ 217.097474][ T11] ret_from_fork+0x31/0x70 [ 217.097719][ T11] ? __pfx_kthread+0x10/0x10 [ 217.097971][ T11] ret_from_fork_asm+0x1b/0x30 [ 217.098223][ T11] [ 217.098408][ T11] [ 217.098531][ T11] Allocated by task 11: [ 217.098747][ T11] kasan_save_stack+0x24/0x50 [ 217.099138][ T11] kasan_save_track+0x14/0x30 [ 217.099385][ T11] __kasan_kmalloc+0x7f/0x90 [ 217.099646][ T11] __kmalloc_node_track_caller+0x1fb/0x440 [ 217.099958][ T11] kmalloc_reserve+0xbc/0x1f0 [ 217.100207][ T11] pskb_expand_head+0x1f4/0xff0 [ 217.100475][ T11] netlink_trim+0x198/0x200 [ 217.100749][ T11] netlink_broadcast_filtered+0xcb/0x340 [ 217.101082][ T11] nlmsg_notify+0x6e/0x1e0 [ 217.101310][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 217.101586][ T11] dev_close_many+0x2bd/0x650 [ 217.101827][ T11] unregister_netdevice_many_notify+0x3d5/0x1180 [ 217.102168][ T11] default_device_exit_batch+0x228/0x2c0 [ 217.102452][ T11] cleanup_net+0x4f3/0xb50 [ 217.102715][ T11] process_one_work+0x78c/0x1310 [ 217.102967][ T11] worker_thread+0x73d/0x1010 [ 217.103255][ T11] kthread+0x28f/0x360 [ 217.103482][ T11] ret_from_fork+0x31/0x70 [ 217.103715][ T11] ret_from_fork_asm+0x1b/0x30 [ 217.103970][ T11] [ 217.104093][ T11] Freed by task 11: [ 217.104315][ T11] kasan_save_stack+0x24/0x50 [ 217.104556][ T11] kasan_save_track+0x14/0x30 [ 217.104852][ T11] kasan_save_free_info+0x3f/0x60 [ 217.105146][ T11] __kasan_slab_free+0xfc/0x1c0 [ 217.105393][ T11] kfree+0xf2/0x2d0 [ 217.105591][ T11] skb_release_data+0x56b/0x770 [ 217.105839][ T11] consume_skb+0xad/0x110 [ 217.106063][ T11] netlink_broadcast_filtered+0x224/0x340 [ 217.106372][ T11] nlmsg_notify+0x6e/0x1e0 [ 217.106601][ T11] rtmsg_ifinfo+0x5b/0xa0 [ 217.106824][ T11] dev_close_many+0x2bd/0x650 [ 217.107065][ T11] unregister_netdevice_many_notify+0x3d5/0x1180 [ 217.107386][ T11] default_device_exit_batch+0x228/0x2c0 [ 217.107670][ T11] cleanup_net+0x4f3/0xb50 [ 217.107900][ T11] process_one_work+0x78c/0x1310 [ 217.108157][ T11] worker_thread+0x73d/0x1010 [ 217.108396][ T11] kthread+0x28f/0x360 [ 217.108603][ T11] ret_from_fork+0x31/0x70 [ 217.108886][ T11] ret_from_fork_asm+0x1b/0x30 [ 217.109135][ T11] [ 217.109262][ T11] The buggy address belongs to the object at ffff888007578800 [ 217.109262][ T11] which belongs to the cache kmalloc-2k of size 2048 [ 217.109987][ T11] The buggy address is located 1008 bytes inside of [ 217.109987][ T11] freed 2048-byte region [ffff888007578800, ffff888007579000) [ 217.110743][ T11] [ 217.110880][ T11] The buggy address belongs to the physical page: [ 217.111233][ T11] page:ffffea00001d5e00 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x7578 [ 217.111746][ T11] head:ffffea00001d5e00 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 217.112241][ T11] flags: 0x80000000000840(slab|head|node=0|zone=1) [ 217.112572][ T11] page_type: 0xffffffff() [ 217.112856][ T11] raw: 0080000000000840 ffff888001043540 ffffea0000183c10 ffff8880010418f0 [ 217.113351][ T11] raw: 0000000000000000 0000000000050005 00000001ffffffff 0000000000000000 [ 217.113827][ T11] page dumped because: kasan: bad access detected [ 217.114175][ T11] [ 217.114297][ T11] Memory state around the buggy address: [ 217.114590][ T11] ffff888007578a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 217.115031][ T11] ffff888007578b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 217.115472][ T11] >ffff888007578b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 217.115909][ T11] ^ [ 217.116309][ T11] ffff888007578c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 217.116775][ T11] ffff888007578c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 217.117235][ T11] ================================================================== [ 217.118954][ T11] Disabling lock debugging due to kernel taint [ 217.119421][ T11] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 217.120094][ T11] KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] [ 217.120559][ T11] CPU: 3 PID: 11 Comm: kworker/u8:0 Tainted: G B 6.8.0-rc2-virtme #1 [ 217.121084][ T11] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 217.121768][ T11] Workqueue: netns cleanup_net [ 217.122044][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 217.122454][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 217.123522][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010246 [ 217.123862][ T11] RAX: 0000000000000000 RBX: ffffffffffffffd1 RCX: dffffc0000000000 [ 217.124295][ T11] RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffff888007578c44 [ 217.124762][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100069581a R09: ffffc900000bf9b8 [ 217.125203][ T11] R10: ffffffff9e034a07 R11: 205d313154202020 R12: ffffed100069581a [ 217.125629][ T11] R13: ffff888007578bc0 R14: ffff8880104a1000 R15: ffff8880034ac000 [ 217.126038][ T11] FS: 0000000000000000(0000) GS:ffff888035e00000(0000) knlGS:0000000000000000 [ 217.126506][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 217.126838][ T11] CR2: 00007ffeece85678 CR3: 000000000df3c003 CR4: 0000000000770ef0 [ 217.127242][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 217.127640][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 217.128042][ T11] PKRU: 55555554 [ 217.128224][ T11] Call Trace: [ 217.128396][ T11] [ 217.128547][ T11] ? die_addr+0x41/0xa0 [ 217.128790][ T11] ? exc_general_protection+0x149/0x220 [ 217.129092][ T11] ? asm_exc_general_protection+0x26/0x30 [ 217.129384][ T11] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 217.129713][ T11] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 217.130075][ T11] ? netconsole_netdev_event+0x1b4/0x300 [ 217.130400][ T11] notifier_call_chain+0x9a/0x290 [ 217.130694][ T11] unregister_netdevice_many_notify+0x55a/0x1180 [ 217.131058][ T11] ? mutex_is_locked+0x17/0x50 [ 217.131317][ T11] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 217.131702][ T11] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 217.132071][ T11] default_device_exit_batch+0x228/0x2c0 [ 217.132375][ T11] ? __pfx_default_device_exit_batch+0x10/0x10 [ 217.132740][ T11] ? mutex_is_locked+0x17/0x50 [ 217.133021][ T11] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 217.133360][ T11] cleanup_net+0x4f3/0xb50 [ 217.133617][ T11] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 217.133916][ T11] ? __pfx_cleanup_net+0x10/0x10 [ 217.134210][ T11] ? lock_acquire+0x1c1/0x220 [ 217.134506][ T11] ? process_one_work+0x714/0x1310 [ 217.134774][ T11] process_one_work+0x78c/0x1310 [ 217.135053][ T11] ? hlock_class+0x4e/0x130 [ 217.135309][ T11] ? __pfx_process_one_work+0x10/0x10 [ 217.135620][ T11] ? assign_work+0x16c/0x240 [ 217.135897][ T11] worker_thread+0x73d/0x1010 [ 217.136169][ T11] ? __pfx_worker_thread+0x10/0x10 [ 217.136435][ T11] kthread+0x28f/0x360 [ 217.136685][ T11] ? __pfx_kthread+0x10/0x10 [ 217.136963][ T11] ret_from_fork+0x31/0x70 [ 217.137249][ T11] ? __pfx_kthread+0x10/0x10 [ 217.137524][ T11] ret_from_fork_asm+0x1b/0x30 [ 217.137792][ T11] [ 217.137948][ T11] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel act_csum libcrc32c act_pedit cls_flower sch_prio [ 217.138798][ T11] ---[ end trace 0000000000000000 ]--- [ 217.139276][ T11] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 217.139665][ T11] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 217.140952][ T11] RSP: 0018:ffffc900000bf980 EFLAGS: 00010246 [ 217.141378][ T11] RAX: 0000000000000000 RBX: ffffffffffffffd1 RCX: dffffc0000000000 [ 217.141827][ T11] RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffff888007578c44 [ 217.142371][ T11] RBP: 1ffff92000017f33 R08: 1ffff1100069581a R09: ffffc900000bf9b8 [ 217.142813][ T11] R10: ffffffff9e034a07 R11: 205d313154202020 R12: ffffed100069581a [ 217.143479][ T11] R13: ffff888007578bc0 R14: ffff8880104a1000 R15: ffff8880034ac000 [ 217.143941][ T11] FS: 0000000000000000(0000) GS:ffff888035e00000(0000) knlGS:0000000000000000 [ 217.144477][ T11] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 217.144830][ T11] CR2: 00007ffeece85678 CR3: 000000000df3c003 CR4: 0000000000770ef0 [ 217.145253][ T11] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 217.145664][ T11] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 217.146092][ T11] PKRU: 55555554 [ 217.146282][ T11] Kernel panic - not syncing: Fatal exception [ 217.146690][ T11] Kernel Offset: 0x17600000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 217.147287][ T11] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout