[ 22.143239][ T235] netdevsim netdevsim298 eni298np1: renamed from eth0 [ 22.148293][ T237] netdevsim netdevsim740 eni740np1: renamed from eth1 [ 23.864885][ T502] Could not find device with ifindex 2000 in netnsfd 11 [ 23.865946][ T502] Could not find netns with fd: 2000 [ 23.866812][ T502] Cannot link a netdevsim to itself [ 23.867594][ T502] Format for linking two devices is "netnsfd_a:ifidx_a netnsfd_b:ifidx_b" (int uint int uint). [ 24.888010][ T502] ================================================================== [ 24.888381][ T502] BUG: KASAN: use-after-free in page_pool_item_uninit+0x100/0x130 [ 24.888631][ T502] Read of size 8 at addr ffff888004c1c008 by task peer.sh/502 [ 24.888869][ T502] [ 24.888952][ T502] CPU: 2 UID: 0 PID: 502 Comm: peer.sh Not tainted 6.13.0-rc5-virtme #1 [ 24.889196][ T502] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 24.889399][ T502] Call Trace: [ 24.889522][ T502] [ 24.889607][ T502] dump_stack_lvl+0x82/0xd0 [ 24.889775][ T502] print_address_description.constprop.0+0x2c/0x3b0 [ 24.889977][ T502] ? page_pool_item_uninit+0x100/0x130 [ 24.890144][ T502] print_report+0xb4/0x270 [ 24.890306][ T502] ? kasan_addr_to_slab+0x25/0x80 [ 24.890471][ T502] kasan_report+0xbd/0xf0 [ 24.890597][ T502] ? page_pool_item_uninit+0x100/0x130 [ 24.890761][ T502] page_pool_item_uninit+0x100/0x130 [ 24.890922][ T502] page_pool_release+0x44a/0x5b0 [ 24.891082][ T502] ? __pfx_autoremove_wake_function+0x10/0x10 [ 24.891287][ T502] ? __pfx_page_pool_release+0x10/0x10 [ 24.891450][ T502] ? napi_disable+0x383/0x5b0 [ 24.891610][ T502] page_pool_destroy+0x11e/0x560 [ 24.891774][ T502] nsim_stop+0x21a/0x390 [netdevsim] [ 24.891950][ T502] __dev_close_many+0x1a0/0x2d0 [ 24.892110][ T502] ? __pfx___dev_close_many+0x10/0x10 [ 24.892270][ T502] ? __pfx_validate_chain+0x10/0x10 [ 24.892436][ T502] ? hlock_class+0x4e/0x130 [ 24.892599][ T502] ? mark_lock+0x38/0x3e0 [ 24.892722][ T502] ? hlock_class+0x4e/0x130 [ 24.892882][ T502] dev_close_many+0x202/0x650 [ 24.893043][ T502] ? __pfx_dev_close_many+0x10/0x10 [ 24.893205][ T502] unregister_netdevice_many_notify+0x8ed/0x1580 [ 24.893406][ T502] ? __mutex_trylock_common+0xfa/0x260 [ 24.893567][ T502] ? __pfx___mutex_trylock_common+0x10/0x10 [ 24.893771][ T502] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 24.893975][ T502] ? lock_acquire+0x32/0xc0 [ 24.894136][ T502] ? __mutex_lock+0x190/0xbc0 [ 24.894298][ T502] ? nsim_destroy+0x6b/0x620 [netdevsim] [ 24.894469][ T502] ? __pfx___mutex_lock+0x10/0x10 [ 24.894628][ T502] unregister_netdevice_queue+0x2a4/0x410 [ 24.894794][ T502] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 24.894967][ T502] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 24.895176][ T502] nsim_destroy+0xe8/0x620 [netdevsim] [ 24.895349][ T502] __nsim_dev_port_del+0x17e/0x250 [netdevsim] [ 24.895556][ T502] nsim_dev_reload_destroy+0xe0/0x470 [netdevsim] [ 24.895763][ T502] nsim_drv_remove+0x51/0x1d0 [netdevsim] [ 24.895934][ T502] device_release_driver_internal+0x3bf/0x590 [ 24.896132][ T502] ? klist_put+0xb1/0x170 [ 24.896255][ T502] bus_remove_device+0x1f1/0x3f0 [ 24.896420][ T502] device_del+0x33f/0x8c0 [ 24.896546][ T502] ? __pfx_device_del+0x10/0x10 [ 24.896706][ T502] ? lock_acquire.part.0+0xeb/0x330 [ 24.896864][ T502] ? kernfs_fop_write_iter+0x22e/0x460 [ 24.897026][ T502] device_unregister+0x17/0xb0 [ 24.897188][ T502] del_device_store+0x2f3/0x4f0 [netdevsim] [ 24.897397][ T502] ? __pfx_del_device_store+0x10/0x10 [netdevsim] [ 24.897617][ T502] ? __pfx_sysfs_kf_write+0x10/0x10 [ 24.897776][ T502] ? sysfs_file_ops+0x11e/0x170 [ 24.897937][ T502] ? __pfx_sysfs_kf_write+0x10/0x10 [ 24.898096][ T502] kernfs_fop_write_iter+0x2ba/0x460 [ 24.898255][ T502] vfs_write+0xa81/0x11e0 [ 24.898377][ T502] ? __pfx_vfs_write+0x10/0x10 [ 24.898538][ T502] ? find_held_lock+0x2c/0x110 [ 24.898705][ T502] ? __pfx___lock_release+0x10/0x10 [ 24.898865][ T502] ksys_write+0xf8/0x1d0 [ 24.898985][ T502] ? __pfx_ksys_write+0x10/0x10 [ 24.899146][ T502] do_syscall_64+0xc1/0x1d0 [ 24.899306][ T502] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 24.899503][ T502] RIP: 0033:0x7fa4d169bb77 [ 24.899669][ T502] Code: 0b 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24 [ 24.900236][ T502] RSP: 002b:00007ffeed5a3a78 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 24.900479][ T502] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fa4d169bb77 [ 24.900719][ T502] RDX: 0000000000000004 RSI: 000055579c44e7a0 RDI: 0000000000000001 [ 24.900958][ T502] RBP: 000055579c44e7a0 R08: 0000000000000000 R09: 00007fa4d170e4e0 [ 24.901197][ T502] R10: 00007fa4d170e3e0 R11: 0000000000000246 R12: 0000000000000004 [ 24.901433][ T502] R13: 00007fa4d1757760 R14: 0000000000000004 R15: 00007fa4d17529c0 [ 24.901674][ T502] [ 24.901800][ T502] [ 24.901882][ T502] The buggy address belongs to the physical page: [ 24.902082][ T502] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4c1c [ 24.902364][ T502] flags: 0x80000000000000(node=0|zone=1) [ 24.902529][ T502] page_type: f5(slab) [ 24.902652][ T502] raw: 0080000000000000 ffff8880010427c0 ffffea0000227910 ffffea0000260690 [ 24.902932][ T502] raw: 0000000000000000 0000000000190019 00000001f5000000 0000000000000000 [ 24.903215][ T502] page dumped because: kasan: bad access detected [ 24.903412][ T502] [ 24.903493][ T502] Memory state around the buggy address: [ 24.903650][ T502] ffff888004c1bf00: 00 00 00 00 00 00 00 00 00 00 00 00 00 fc fc fc [ 24.903881][ T502] ffff888004c1bf80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 24.904113][ T502] >ffff888004c1c000: fc fc fa fb fc fc fc fc fc fc fc fc fc fc fc fc [ 24.904345][ T502] ^ [ 24.904470][ T502] ffff888004c1c080: fc fc fc fc fc fc fa fb fc fc fc fc fc fc fc fc [ 24.904718][ T502] ffff888004c1c100: fc fc fc fc fc fc fc fc fc fc fa fb fc fc fc fc [ 24.904955][ T502] ================================================================== [ 24.905242][ T502] Disabling lock debugging due to kernel taint [ 24.905475][ T502] Oops: general protection fault, probably for non-canonical address 0xf99995999999999c: 0000 [#1] PREEMPT SMP KASAN NOPTI [ 24.905859][ T502] KASAN: maybe wild-memory-access in range [0xcccccccccccccce0-0xcccccccccccccce7] [ 24.906125][ T502] CPU: 2 UID: 0 PID: 502 Comm: peer.sh Tainted: G B 6.13.0-rc5-virtme #1 [ 24.906403][ T502] Tainted: [B]=BAD_PAGE [ 24.906526][ T502] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 24.906719][ T502] RIP: 0010:page_pool_item_uninit+0x7a/0x130 [ 24.906918][ T502] Code: 8e 48 bb 00 00 00 00 00 fc ff df 48 c1 ed 03 48 01 dd 4d 8d 75 1c be 04 00 00 00 4c 89 f7 e8 dd 9c 69 fe 4c 89 f0 48 c1 e8 03 <0f> b6 14 18 4c 89 f0 83 e0 07 83 c0 03 38 d0 7c 04 84 d2 75 62 41 [ 24.907472][ T502] RSP: 0018:ffffc90000c974f0 EFLAGS: 00010a06 [ 24.907669][ T502] RAX: 199999999999999c RBX: dffffc0000000000 RCX: ffffffff8d429ac3 [ 24.907903][ T502] RDX: 0000000000000000 RSI: 0000000000000004 RDI: cccccccccccccce0 [ 24.908136][ T502] RBP: fffffbfff1d18a78 R08: 0000000000000000 R09: fffffbfff20da088 [ 24.908373][ T502] R10: ffffffff906d0447 R11: 205d323035542020 R12: ffff888004afe620 [ 24.908607][ T502] R13: ccccccccccccccc4 R14: cccccccccccccce0 R15: 0000000000000000 [ 24.908838][ T502] FS: 00007fa4d155a740(0000) GS:ffff888036100000(0000) knlGS:0000000000000000 [ 24.909112][ T502] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 24.909310][ T502] CR2: 000055579c44e7a0 CR3: 0000000008e92002 CR4: 0000000000772ef0 [ 24.909549][ T502] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 24.909780][ T502] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 24.910010][ T502] PKRU: 55555554 [ 24.910128][ T502] Call Trace: [ 24.910248][ T502] [ 24.910331][ T502] ? die_addr+0x41/0xa0 [ 24.910455][ T502] ? exc_general_protection+0x14d/0x230 [ 24.910617][ T502] ? asm_exc_general_protection+0x26/0x30 [ 24.910778][ T502] ? page_pool_item_uninit+0x73/0x130 [ 24.910933][ T502] ? page_pool_item_uninit+0x7a/0x130 [ 24.911090][ T502] page_pool_release+0x44a/0x5b0 [ 24.911248][ T502] ? __pfx_autoremove_wake_function+0x10/0x10 [ 24.911449][ T502] ? __pfx_page_pool_release+0x10/0x10 [ 24.911604][ T502] ? napi_disable+0x383/0x5b0 [ 24.911761][ T502] page_pool_destroy+0x11e/0x560 [ 24.911919][ T502] nsim_stop+0x21a/0x390 [netdevsim] [ 24.912099][ T502] __dev_close_many+0x1a0/0x2d0 [ 24.912254][ T502] ? __pfx___dev_close_many+0x10/0x10 [ 24.912410][ T502] ? __pfx_validate_chain+0x10/0x10 [ 24.912571][ T502] ? hlock_class+0x4e/0x130 [ 24.912731][ T502] ? mark_lock+0x38/0x3e0 [ 24.912849][ T502] ? hlock_class+0x4e/0x130 [ 24.913006][ T502] dev_close_many+0x202/0x650 [ 24.913162][ T502] ? __pfx_dev_close_many+0x10/0x10 [ 24.913417][ T502] unregister_netdevice_many_notify+0x8ed/0x1580 [ 24.913619][ T502] ? __mutex_trylock_common+0xfa/0x260 [ 24.913775][ T502] ? __pfx___mutex_trylock_common+0x10/0x10 [ 24.913972][ T502] ? __pfx_unregister_netdevice_many_notify+0x10/0x10 [ 24.914263][ T502] ? lock_acquire+0x32/0xc0 [ 24.914417][ T502] ? __mutex_lock+0x190/0xbc0 [ 24.914574][ T502] ? nsim_destroy+0x6b/0x620 [netdevsim] [ 24.914832][ T502] ? __pfx___mutex_lock+0x10/0x10 [ 24.914994][ T502] unregister_netdevice_queue+0x2a4/0x410 [ 24.915152][ T502] ? __pfx_do_raw_spin_lock+0x10/0x10 [ 24.915307][ T502] ? __pfx_unregister_netdevice_queue+0x10/0x10 [ 24.915601][ T502] nsim_destroy+0xe8/0x620 [netdevsim] [ 24.915769][ T502] __nsim_dev_port_del+0x17e/0x250 [netdevsim] [ 24.915971][ T502] nsim_dev_reload_destroy+0xe0/0x470 [netdevsim] [ 24.916175][ T502] nsim_drv_remove+0x51/0x1d0 [netdevsim] [ 24.916437][ T502] device_release_driver_internal+0x3bf/0x590 [ 24.916636][ T502] ? klist_put+0xb1/0x170 [ 24.916754][ T502] bus_remove_device+0x1f1/0x3f0 [ 24.916912][ T502] device_del+0x33f/0x8c0 [ 24.917127][ T502] ? __pfx_device_del+0x10/0x10 [ 24.917297][ T502] ? lock_acquire.part.0+0xeb/0x330 [ 24.917450][ T502] ? kernfs_fop_write_iter+0x22e/0x460 [ 24.917607][ T502] device_unregister+0x17/0xb0 [ 24.917863][ T502] del_device_store+0x2f3/0x4f0 [netdevsim] [ 24.918067][ T502] ? __pfx_del_device_store+0x10/0x10 [netdevsim] [ 24.918270][ T502] ? __pfx_sysfs_kf_write+0x10/0x10 [ 24.918520][ T502] ? sysfs_file_ops+0x11e/0x170 [ 24.918675][ T502] ? __pfx_sysfs_kf_write+0x10/0x10 [ 24.918830][ T502] kernfs_fop_write_iter+0x2ba/0x460 [ 24.918985][ T502] vfs_write+0xa81/0x11e0 [ 24.919109][ T502] ? __pfx_vfs_write+0x10/0x10 [ 24.919361][ T502] ? find_held_lock+0x2c/0x110 [ 24.919518][ T502] ? __pfx___lock_release+0x10/0x10 [ 24.919674][ T502] ksys_write+0xf8/0x1d0 [ 24.919792][ T502] ? __pfx_ksys_write+0x10/0x10 [ 24.920047][ T502] do_syscall_64+0xc1/0x1d0 [ 24.920202][ T502] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 24.920399][ T502] RIP: 0033:0x7fa4d169bb77 [ 24.920559][ T502] Code: 0b 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 48 89 54 24 18 48 89 74 24 [ 24.921201][ T502] RSP: 002b:00007ffeed5a3a78 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 24.921530][ T502] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fa4d169bb77 [ 24.921763][ T502] RDX: 0000000000000004 RSI: 000055579c44e7a0 RDI: 0000000000000001 [ 24.921994][ T502] RBP: 000055579c44e7a0 R08: 0000000000000000 R09: 00007fa4d170e4e0 [ 24.922320][ T502] R10: 00007fa4d170e3e0 R11: 0000000000000246 R12: 0000000000000004 [ 24.922549][ T502] R13: 00007fa4d1757760 R14: 0000000000000004 R15: 00007fa4d17529c0 [ 24.922883][ T502] [ 24.923001][ T502] Modules linked in: macsec netdevsim [ 24.923196][ T502] ---[ end trace 0000000000000000 ]--- [ 24.923367][ T502] RIP: 0010:page_pool_item_uninit+0x7a/0x130 [ 24.923585][ T502] Code: 8e 48 bb 00 00 00 00 00 fc ff df 48 c1 ed 03 48 01 dd 4d 8d 75 1c be 04 00 00 00 4c 89 f7 e8 dd 9c 69 fe 4c 89 f0 48 c1 e8 03 <0f> b6 14 18 4c 89 f0 83 e0 07 83 c0 03 38 d0 7c 04 84 d2 75 62 41 [ 24.924141][ T502] RSP: 0018:ffffc90000c974f0 EFLAGS: 00010a06 [ 24.924446][ T502] RAX: 199999999999999c RBX: dffffc0000000000 RCX: ffffffff8d429ac3 [ 24.924697][ T502] RDX: 0000000000000000 RSI: 0000000000000004 RDI: cccccccccccccce0 [ 24.925043][ T502] RBP: fffffbfff1d18a78 R08: 0000000000000000 R09: fffffbfff20da088 [ 24.925291][ T502] R10: ffffffff906d0447 R11: 205d323035542020 R12: ffff888004afe620 [ 24.925547][ T502] R13: ccccccccccccccc4 R14: cccccccccccccce0 R15: 0000000000000000 [ 24.925884][ T502] FS: 00007fa4d155a740(0000) GS:ffff888036100000(0000) knlGS:0000000000000000 [ 24.926165][ T502] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 24.926374][ T502] CR2: 000055579c44e7a0 CR3: 0000000008e92002 CR4: 0000000000772ef0 [ 24.926719][ T502] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 24.926964][ T502] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 24.927300][ T502] PKRU: 55555554 [ 24.927430][ T502] Kernel panic - not syncing: Fatal exception [ 24.927708][ T502] Kernel Offset: 0x9e00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 24.928163][ T502] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr