make -C tools/testing/selftests TARGETS=net TEST_PROGS=test_bridge_backup__port.sh TEST_GEN_PROGS="" run_tests make: Entering directory '/home/virtme/testing-3/tools/testing/selftests' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/home/virtme/testing-3/tools/testing/selftests/net' make[1]: Entering directory '/home/virtme/testing-3/tools/testing/selftests/net' TAP version 13 1..1 # timeout set to 6000 # selftests: net: test_bridge_backup_port.sh [ 26.428802][ T259] veth0: renamed from veth1 [ 28.112667][ T275] br0: port 1(swp1) entered blocking state [ 28.113090][ T275] br0: port 1(swp1) entered disabled state [ 28.114061][ T275] swp1: entered allmulticast mode [ 28.115478][ T275] swp1: entered promiscuous mode [ 28.117098][ T275] br0: port 1(swp1) entered blocking state [ 28.117466][ T275] br0: port 1(swp1) entered forwarding state [ 28.712127][ T277] br0: port 2(vx0) entered blocking state [ 28.712539][ T277] br0: port 2(vx0) entered disabled state [ 28.712909][ T277] vx0: entered allmulticast mode [ 28.714416][ T277] vx0: entered promiscuous mode [ 28.715043][ T277] br0: port 2(vx0) entered blocking state [ 28.715382][ T277] br0: port 2(vx0) entered forwarding state [ 30.912377][ T291] br0: port 1(swp1) entered blocking state [ 30.912724][ T291] br0: port 1(swp1) entered disabled state [ 30.913074][ T291] swp1: entered allmulticast mode [ 30.914420][ T291] swp1: entered promiscuous mode [ 30.915798][ T291] br0: port 1(swp1) entered blocking state [ 30.916147][ T291] br0: port 1(swp1) entered forwarding state [ 31.235112][ T293] br0: port 2(vx0) entered blocking state [ 31.235988][ T293] br0: port 2(vx0) entered disabled state [ 31.236321][ T293] vx0: entered allmulticast mode [ 31.237700][ T293] vx0: entered promiscuous mode [ 31.238667][ T293] br0: port 2(vx0) entered blocking state [ 31.238991][ T293] br0: port 2(vx0) entered forwarding state # # Backup port # ----------- [ 37.698447][ T306] GACT probability NOT on # TEST: Forwarding out of swp1 [ OK ] # TEST: No forwarding out of vx0 [ OK ] [ 39.781794][ T253] br0: port 1(swp1) entered disabled state # TEST: swp1 carrier off [ OK ] # TEST: No forwarding out of swp1 [ OK ] # TEST: No forwarding out of vx0 [ OK ] [ 41.073114][ T47] br0: port 1(swp1) entered blocking state [ 41.073488][ T47] br0: port 1(swp1) entered forwarding state # TEST: swp1 carrier on [ OK ] # TEST: vx0 configured as backup port of swp1 [ OK ] # TEST: Forwarding out of swp1 [ OK ] # TEST: No forwarding out of vx0 [ OK ] [ 42.741062][ T8] br0: port 1(swp1) entered disabled state # TEST: swp1 carrier off [ OK ] # TEST: No forwarding out of swp1 [ OK ] # TEST: Forwarding out of vx0 [ OK ] [ 44.073424][ T49] br0: port 1(swp1) entered blocking state [ 44.073779][ T49] br0: port 1(swp1) entered forwarding state # TEST: swp1 carrier on [ OK ] # TEST: Forwarding out of swp1 [ OK ] # TEST: No forwarding out of vx0 [ OK ] # TEST: vx0 not configured as backup port of swp1 [ OK ] # TEST: Forwarding out of swp1 [ OK ] # TEST: No forwarding out of vx0 [ OK ] [ 46.786417][ T253] br0: port 1(swp1) entered disabled state # TEST: swp1 carrier off [ OK ] # TEST: No forwarding out of swp1 [ OK ] # TEST: No forwarding out of vx0 [ OK ] [ 48.096837][ T71] vx0: left allmulticast mode [ 48.097197][ T71] vx0: left promiscuous mode [ 48.097660][ T71] br0: port 2(vx0) entered disabled state [ 48.111835][ T71] swp1: left allmulticast mode [ 48.112297][ T71] swp1: left promiscuous mode [ 48.112880][ T71] br0: port 1(swp1) entered disabled state [ 48.207129][ T71] ================================================================== [ 48.207577][ T71] BUG: KASAN: slab-use-after-free in vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 48.208060][ T71] Read of size 8 at addr ffff888005ea8bf0 by task kworker/u8:1/71 [ 48.208453][ T71] [ 48.208577][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Not tainted 6.8.0-rc2-virtme #1 [ 48.208981][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 48.209601][ T71] Workqueue: netns cleanup_net [ 48.209857][ T71] Call Trace: [ 48.210032][ T71] [ 48.210189][ T71] dump_stack_lvl+0x64/0xb0 [ 48.210429][ T71] print_address_description.constprop.0+0x2c/0x3b0 [ 48.210768][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 48.211096][ T71] print_report+0xb5/0x270 [ 48.211326][ T71] ? kasan_addr_to_slab+0x4e/0x90 [ 48.211586][ T71] kasan_report+0xbe/0xf0 [ 48.211812][ T71] ? vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 48.212170][ T71] vxlan_netdevice_event+0x32f/0x340 [vxlan] [ 48.212507][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 48.212887][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 48.213197][ T71] notifier_call_chain+0x9a/0x290 [ 48.213461][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 48.213788][ T71] ? mutex_is_locked+0x17/0x50 [ 48.214036][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 48.214380][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 48.214751][ T71] default_device_exit_batch+0x228/0x2c0 [ 48.215043][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 48.215380][ T71] ? mutex_is_locked+0x17/0x50 [ 48.215625][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 48.215955][ T71] cleanup_net+0x4f3/0xb50 [ 48.216183][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 48.216496][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 48.216759][ T71] ? lock_acquire+0x1c1/0x220 [ 48.217034][ T71] ? process_one_work+0x714/0x1310 [ 48.217414][ T71] process_one_work+0x78c/0x1310 [ 48.217760][ T71] ? hlock_class+0x4e/0x130 [ 48.218094][ T71] ? __pfx_process_one_work+0x10/0x10 [ 48.218504][ T71] ? assign_work+0x16c/0x240 [ 48.218863][ T71] worker_thread+0x73d/0x1010 [ 48.219227][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 48.219741][ T71] ? __pfx_worker_thread+0x10/0x10 [ 48.220135][ T71] ? __pfx_worker_thread+0x10/0x10 [ 48.220527][ T71] kthread+0x28f/0x360 [ 48.220844][ T71] ? __pfx_kthread+0x10/0x10 [ 48.221204][ T71] ret_from_fork+0x31/0x70 [ 48.221549][ T71] ? __pfx_kthread+0x10/0x10 [ 48.221901][ T71] ret_from_fork_asm+0x1b/0x30 [ 48.222286][ T71] [ 48.222571][ T71] [ 48.222756][ T71] Allocated by task 71: [ 48.223080][ T71] kasan_save_stack+0x24/0x50 [ 48.223452][ T71] kasan_save_track+0x14/0x30 [ 48.223830][ T71] __kasan_kmalloc+0x7f/0x90 [ 48.224202][ T71] __kmalloc_node_track_caller+0x1fb/0x440 [ 48.224662][ T71] kmalloc_reserve+0xbc/0x1f0 [ 48.224990][ T71] pskb_expand_head+0x1f4/0xff0 [ 48.225262][ T71] netlink_trim+0x198/0x200 [ 48.225497][ T71] netlink_broadcast_filtered+0xcb/0x340 [ 48.225808][ T71] nlmsg_notify+0x6e/0x1e0 [ 48.226068][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 48.226290][ T71] dev_close_many+0x2bd/0x650 [ 48.226548][ T71] unregister_netdevice_many_notify+0x3d5/0x1180 [ 48.226891][ T71] default_device_exit_batch+0x228/0x2c0 [ 48.227177][ T71] cleanup_net+0x4f3/0xb50 [ 48.227418][ T71] process_one_work+0x78c/0x1310 [ 48.227691][ T71] worker_thread+0x73d/0x1010 [ 48.227931][ T71] kthread+0x28f/0x360 [ 48.228154][ T71] ret_from_fork+0x31/0x70 [ 48.228382][ T71] ret_from_fork_asm+0x1b/0x30 [ 48.228626][ T71] [ 48.228748][ T71] Freed by task 71: [ 48.228944][ T71] kasan_save_stack+0x24/0x50 [ 48.229186][ T71] kasan_save_track+0x14/0x30 [ 48.229428][ T71] kasan_save_free_info+0x3f/0x60 [ 48.229723][ T71] __kasan_slab_free+0xfc/0x1c0 [ 48.229972][ T71] kfree+0xf2/0x2d0 [ 48.230183][ T71] skb_release_data+0x544/0x740 [ 48.230450][ T71] consume_skb+0xad/0x110 [ 48.230684][ T71] netlink_broadcast_filtered+0x224/0x340 [ 48.230976][ T71] nlmsg_notify+0x6e/0x1e0 [ 48.231202][ T71] rtmsg_ifinfo+0x5b/0xa0 [ 48.231425][ T71] dev_close_many+0x2bd/0x650 [ 48.231663][ T71] unregister_netdevice_many_notify+0x3d5/0x1180 [ 48.231985][ T71] default_device_exit_batch+0x228/0x2c0 [ 48.232272][ T71] cleanup_net+0x4f3/0xb50 [ 48.232498][ T71] process_one_work+0x78c/0x1310 [ 48.232751][ T71] worker_thread+0x73d/0x1010 [ 48.232992][ T71] kthread+0x28f/0x360 [ 48.233199][ T71] ret_from_fork+0x31/0x70 [ 48.233428][ T71] ret_from_fork_asm+0x1b/0x30 [ 48.233674][ T71] [ 48.233797][ T71] The buggy address belongs to the object at ffff888005ea8800 [ 48.233797][ T71] which belongs to the cache kmalloc-2k of size 2048 [ 48.234503][ T71] The buggy address is located 1008 bytes inside of [ 48.234503][ T71] freed 2048-byte region [ffff888005ea8800, ffff888005ea9000) [ 48.235214][ T71] [ 48.235338][ T71] The buggy address belongs to the physical page: [ 48.235663][ T71] page:ffffea000017aa00 refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888005eab800 pfn:0x5ea8 [ 48.236239][ T71] head:ffffea000017aa00 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 48.236689][ T71] flags: 0x80000000000a40(workingset|slab|head|node=0|zone=1) [ 48.237072][ T71] page_type: 0xffffffff() [ 48.237300][ T71] raw: 0080000000000a40 ffff888001043540 ffff8880010418d0 ffff8880010418d0 [ 48.237732][ T71] raw: ffff888005eab800 0000000000050002 00000001ffffffff 0000000000000000 [ 48.238169][ T71] page dumped because: kasan: bad access detected [ 48.238497][ T71] [ 48.238619][ T71] Memory state around the buggy address: [ 48.238904][ T71] ffff888005ea8a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 48.239314][ T71] ffff888005ea8b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 48.239720][ T71] >ffff888005ea8b80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 48.240123][ T71] ^ [ 48.240514][ T71] ffff888005ea8c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 48.240920][ T71] ffff888005ea8c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [ 48.241324][ T71] ================================================================== [ 48.241837][ T71] Disabling lock debugging due to kernel taint [ 48.242169][ T71] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 48.242786][ T71] KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] [ 48.243209][ T71] CPU: 2 PID: 71 Comm: kworker/u8:1 Tainted: G B 6.8.0-rc2-virtme #1 [ 48.243685][ T71] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 48.244308][ T71] Workqueue: netns cleanup_net [ 48.244557][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 48.244927][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 48.246050][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010246 [ 48.246395][ T71] RAX: 0000000000000000 RBX: ffffffffffffffd0 RCX: dffffc0000000000 [ 48.246825][ T71] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff888005ea8c44 [ 48.247308][ T71] RBP: 1ffff920000a3f33 R08: 1ffff11000ec521a R09: ffffc9000051f9b8 [ 48.247740][ T71] R10: ffffffff91434a07 R11: 205d313754202020 R12: ffffed1000ec521a [ 48.248192][ T71] R13: ffff888005ea8bc0 R14: ffff8880020fc000 R15: ffff888007629000 [ 48.248657][ T71] FS: 0000000000000000(0000) GS:ffff888035a00000(0000) knlGS:0000000000000000 [ 48.249163][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 48.249500][ T71] CR2: 00007ffc759a1ff8 CR3: 0000000024934003 CR4: 0000000000770ef0 [ 48.249900][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 48.250302][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 48.250715][ T71] PKRU: 55555554 [ 48.250898][ T71] Call Trace: [ 48.251067][ T71] [ 48.251222][ T71] ? die_addr+0x41/0xa0 [ 48.251439][ T71] ? exc_general_protection+0x149/0x220 [ 48.251771][ T71] ? asm_exc_general_protection+0x26/0x30 [ 48.252129][ T71] ? vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 48.252484][ T71] ? __pfx_vxlan_netdevice_event+0x10/0x10 [vxlan] [ 48.252853][ T71] ? netconsole_netdev_event+0x1b4/0x300 [ 48.253184][ T71] notifier_call_chain+0x9a/0x290 [ 48.253444][ T71] unregister_netdevice_many_notify+0x55a/0x1180 [ 48.253826][ T71] ? mutex_is_locked+0x17/0x50 [ 48.254120][ T71] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 48.254495][ T71] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 48.254864][ T71] default_device_exit_batch+0x228/0x2c0 [ 48.255195][ T71] ? __pfx_default_device_exit_batch+0x10/0x10 [ 48.255538][ T71] ? mutex_is_locked+0x17/0x50 [ 48.255795][ T71] ? nexthop_net_exit_batch_rtnl+0x83/0x210 [ 48.256174][ T71] cleanup_net+0x4f3/0xb50 [ 48.256404][ T71] ? __pfx_lock_acquire.part.0+0x10/0x10 [ 48.256730][ T71] ? __pfx_cleanup_net+0x10/0x10 [ 48.257016][ T71] ? lock_acquire+0x1c1/0x220 [ 48.257271][ T71] ? process_one_work+0x714/0x1310 [ 48.257561][ T71] process_one_work+0x78c/0x1310 [ 48.257848][ T71] ? hlock_class+0x4e/0x130 [ 48.258091][ T71] ? __pfx_process_one_work+0x10/0x10 [ 48.258398][ T71] ? assign_work+0x16c/0x240 [ 48.258674][ T71] worker_thread+0x73d/0x1010 [ 48.258943][ T71] ? lockdep_hardirqs_on_prepare.part.0+0x1b1/0x370 [ 48.259278][ T71] ? __pfx_worker_thread+0x10/0x10 [ 48.259539][ T71] ? __pfx_worker_thread+0x10/0x10 [ 48.259799][ T71] kthread+0x28f/0x360 [ 48.260015][ T71] ? __pfx_kthread+0x10/0x10 [ 48.260250][ T71] ret_from_fork+0x31/0x70 [ 48.260482][ T71] ? __pfx_kthread+0x10/0x10 [ 48.260718][ T71] ret_from_fork_asm+0x1b/0x30 [ 48.260966][ T71] [ 48.261122][ T71] Modules linked in: act_gact cls_flower sch_ingress vxlan ip6_udp_tunnel udp_tunnel [ 48.261675][ T71] ---[ end trace 0000000000000000 ]--- [ 48.261954][ T71] RIP: 0010:vxlan_netdevice_event+0x19e/0x340 [vxlan] [ 48.262310][ T71] Code: 00 00 00 48 b9 00 00 00 00 00 fc ff df 49 89 c0 48 89 44 24 08 49 c1 e8 03 4d 8d 24 08 eb 2c 48 8d 53 30 48 89 d0 48 c1 e8 03 <80> 3c 08 00 0f 85 e0 00 00 00 48 8b 43 30 49 89 dd 48 83 e8 30 49 [ 48.263373][ T71] RSP: 0018:ffffc9000051f980 EFLAGS: 00010246 [ 48.263720][ T71] RAX: 0000000000000000 RBX: ffffffffffffffd0 RCX: dffffc0000000000 [ 48.264160][ T71] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff888005ea8c44 [ 48.264648][ T71] RBP: 1ffff920000a3f33 R08: 1ffff11000ec521a R09: ffffc9000051f9b8 [ 48.265123][ T71] R10: ffffffff91434a07 R11: 205d313754202020 R12: ffffed1000ec521a [ 48.265563][ T71] R13: ffff888005ea8bc0 R14: ffff8880020fc000 R15: ffff888007629000 [ 48.266010][ T71] FS: 0000000000000000(0000) GS:ffff888035a00000(0000) knlGS:0000000000000000 [ 48.266504][ T71] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 48.266873][ T71] CR2: 00007ffc759a1ff8 CR3: 0000000024934003 CR4: 0000000000770ef0 [ 48.267304][ T71] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 48.267760][ T71] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 48.268188][ T71] PKRU: 55555554 [ 48.268486][ T71] Kernel panic - not syncing: Fatal exception [ 48.268896][ T71] Kernel Offset: 0xaa00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 48.269476][ T71] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stdout Ctrl-C stdout Ctrl-C stdout WAIT TIMEOUT stdout