[ 11.356120][ T254] ip (254) used greatest stack depth: 24496 bytes left [ 11.503202][ T260] ip (260) used greatest stack depth: 24360 bytes left [ 23.149707][ T755] ip (755) used greatest stack depth: 24224 bytes left [ 34.142569][ T1241] ip (1241) used greatest stack depth: 24032 bytes left [ 137.799261][ T4307] netem: version 1.3 [ 149.841204][ T4467] ip (4467) used greatest stack depth: 24016 bytes left [ 420.229271][ T7469] ip (7469) used greatest stack depth: 23264 bytes left [ 422.361206][ T7515] kmemleak: Found object by alias at 0xff1100001f440840 [ 422.361215][ T7515] CPU: 3 UID: 0 PID: 7515 Comm: pm_nl_ctl Not tainted 6.19.0-rc5-virtme #1 PREEMPT(full) [ 422.361219][ T7515] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 422.361220][ T7515] Call Trace: [ 422.361222][ T7515] [ 422.361224][ T7515] dump_stack_lvl+0x6f/0xa0 [ 422.361233][ T7515] __lookup_object+0x8c/0xb0 [ 422.361238][ T7515] delete_object_full+0x2b/0x70 [ 422.361241][ T7515] kfree+0x2b7/0x580 [ 422.361244][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.361250][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.361252][ T7515] mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.361256][ T7515] ? mptcp_pm_nl_del_addr_doit+0x7b0/0x7b0 [ 422.361258][ T7515] ? genl_family_rcv_msg_attrs_parse.isra.0+0x157/0x2b0 [ 422.361265][ T7515] genl_family_rcv_msg_doit+0x1e4/0x2c0 [ 422.361268][ T7515] ? genl_family_rcv_msg_attrs_parse.isra.0+0x2b0/0x2b0 [ 422.361270][ T7515] ? rcu_is_watching+0x15/0xd0 [ 422.361274][ T7515] ? perf_trace_sched_switch+0x6d0/0x6d0 [ 422.361276][ T7515] ? genl_rcv_msg+0x101/0x130 [ 422.361282][ T7515] ? rcu_is_watching+0x15/0xd0 [ 422.361284][ T7515] ? cap_capable+0x181/0x3f0 [ 422.361289][ T7515] genl_family_rcv_msg+0x35a/0x5b0 [ 422.361293][ T7515] ? genl_family_rcv_msg_dumpit+0x320/0x320 [ 422.361296][ T7515] ? mptcp_pm_nl_del_addr_doit+0x7b0/0x7b0 [ 422.361299][ T7515] ? __lock_acquire+0x577/0xc10 [ 422.361304][ T7515] genl_rcv_msg+0xa3/0x130 [ 422.361307][ T7515] netlink_rcv_skb+0x123/0x380 [ 422.361310][ T7515] ? genl_family_rcv_msg+0x5b0/0x5b0 [ 422.361313][ T7515] ? netlink_ack+0xcc0/0xcc0 [ 422.361315][ T7515] ? perf_trace_sched_switch+0x6d0/0x6d0 [ 422.361321][ T7515] ? netlink_deliver_tap+0xc5/0x330 [ 422.361324][ T7515] ? netlink_deliver_tap+0x13f/0x330 [ 422.361330][ T7515] genl_rcv+0x28/0x40 [ 422.361334][ T7515] netlink_unicast+0x4a3/0x770 [ 422.361339][ T7515] ? netlink_attachskb+0x810/0x810 [ 422.361341][ T7515] ? __alloc_skb+0x4cd/0x600 [ 422.361345][ T7515] ? napi_skb_cache_get+0x7a0/0x7a0 [ 422.361347][ T7515] ? __lock_acquire+0x577/0xc10 [ 422.361351][ T7515] netlink_sendmsg+0x735/0xc60 [ 422.361355][ T7515] ? netlink_unicast+0x770/0x770 [ 422.361359][ T7515] ? __might_fault+0x97/0x140 [ 422.361365][ T7515] __sys_sendto+0x265/0x390 [ 422.361368][ T7515] ? __ia32_sys_getpeername+0xd0/0xd0 [ 422.361374][ T7515] ? __lock_release.isra.0+0x59/0x170 [ 422.361381][ T7515] ? update_socket_protocol+0x10/0x10 [ 422.361385][ T7515] __x64_sys_sendto+0xe4/0x1f0 [ 422.361388][ T7515] ? lockdep_hardirqs_on+0x84/0x130 [ 422.361391][ T7515] ? do_syscall_64+0x88/0xfc0 [ 422.361393][ T7515] do_syscall_64+0xbd/0xfc0 [ 422.361396][ T7515] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 422.361398][ T7515] RIP: 0033:0x7f8e05878c5e [ 422.361402][ T7515] Code: 4d 89 d8 e8 14 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 13 ff ff ff 0f 1f 00 f3 0f 1e fa [ 422.361404][ T7515] RSP: 002b:00007ffc66552f30 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 422.361407][ T7515] RAX: ffffffffffffffda RBX: 00007ffc66552fe0 RCX: 00007f8e05878c5e [ 422.361409][ T7515] RDX: 0000000000000014 RSI: 00007ffc66552fe0 RDI: 0000000000000005 [ 422.361410][ T7515] RBP: 00007ffc66552f40 R08: 00007ffc66552fa4 R09: 000000000000000c [ 422.361411][ T7515] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000014 [ 422.361411][ T7515] R13: 0000000000000005 R14: 00007f8e05a43000 R15: 0000000000406e00 [ 422.361418][ T7515] [ 422.361419][ T7515] kmemleak: Object 0xff1100001f440800 (size 128): [ 422.361420][ T7515] kmemleak: comm "ip", pid 7441, jiffies 4295086318 [ 422.361422][ T7515] kmemleak: min_count = 1 [ 422.361423][ T7515] kmemleak: count = 0 [ 422.361423][ T7515] kmemleak: flags = 0x1 [ 422.361423][ T7515] kmemleak: checksum = 0 [ 422.361424][ T7515] kmemleak: backtrace: [ 422.361425][ T7515] __kmalloc_noprof+0x58e/0x820 [ 422.361427][ T7515] ops_init+0x70/0x560 [ 422.361430][ T7515] setup_net+0x100/0x360 [ 422.361431][ T7515] copy_net_ns+0x2bf/0x3f0 [ 422.361432][ T7515] create_new_namespaces+0x35d/0x9e0 [ 422.361434][ T7515] unshare_nsproxy_namespaces+0x89/0x130 [ 422.361436][ T7515] ksys_unshare+0x3f3/0x740 [ 422.361438][ T7515] __x64_sys_unshare+0x34/0x50 [ 422.361440][ T7515] do_syscall_64+0xbd/0xfc0 [ 422.361442][ T7515] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 422.361443][ T7515] ================================================================== [ 422.372154][ T7515] BUG: KASAN: invalid-free in mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372353][ T7515] Free of addr ff1100001f440840 by task pm_nl_ctl/7515 [ 422.372515][ T7515] [ 422.372589][ T7515] CPU: 3 UID: 0 PID: 7515 Comm: pm_nl_ctl Not tainted 6.19.0-rc5-virtme #1 PREEMPT(full) [ 422.372591][ T7515] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 422.372592][ T7515] Call Trace: [ 422.372593][ T7515] [ 422.372594][ T7515] dump_stack_lvl+0x6f/0xa0 [ 422.372597][ T7515] print_address_description.constprop.0+0x6e/0x300 [ 422.372600][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372603][ T7515] print_report+0xfc/0x1fb [ 422.372604][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372606][ T7515] ? __virt_addr_valid+0x1da/0x430 [ 422.372609][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372611][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372613][ T7515] kasan_report_invalid_free+0xb8/0x170 [ 422.372616][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372618][ T7515] check_slab_allocation+0xd8/0xe0 [ 422.372621][ T7515] kfree+0xe4/0x580 [ 422.372623][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372625][ T7515] ? mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372627][ T7515] mptcp_pm_nl_flush_addrs_doit+0x39e/0x530 [ 422.372629][ T7515] ? mptcp_pm_nl_del_addr_doit+0x7b0/0x7b0 [ 422.372631][ T7515] ? genl_family_rcv_msg_attrs_parse.isra.0+0x157/0x2b0 [ 422.372634][ T7515] genl_family_rcv_msg_doit+0x1e4/0x2c0 [ 422.372636][ T7515] ? genl_family_rcv_msg_attrs_parse.isra.0+0x2b0/0x2b0 [ 422.372638][ T7515] ? rcu_is_watching+0x15/0xd0 [ 422.372641][ T7515] ? perf_trace_sched_switch+0x6d0/0x6d0 [ 422.372642][ T7515] ? genl_rcv_msg+0x101/0x130 [ 422.372645][ T7515] ? rcu_is_watching+0x15/0xd0 [ 422.372647][ T7515] ? cap_capable+0x181/0x3f0 [ 422.372649][ T7515] genl_family_rcv_msg+0x35a/0x5b0 [ 422.372652][ T7515] ? genl_family_rcv_msg_dumpit+0x320/0x320 [ 422.372654][ T7515] ? mptcp_pm_nl_del_addr_doit+0x7b0/0x7b0 [ 422.372656][ T7515] ? __lock_acquire+0x577/0xc10 [ 422.372659][ T7515] genl_rcv_msg+0xa3/0x130 [ 422.372661][ T7515] netlink_rcv_skb+0x123/0x380 [ 422.372663][ T7515] ? genl_family_rcv_msg+0x5b0/0x5b0 [ 422.372666][ T7515] ? netlink_ack+0xcc0/0xcc0 [ 422.372667][ T7515] ? perf_trace_sched_switch+0x6d0/0x6d0 [ 422.372670][ T7515] ? netlink_deliver_tap+0xc5/0x330 [ 422.372672][ T7515] ? netlink_deliver_tap+0x13f/0x330 [ 422.372674][ T7515] genl_rcv+0x28/0x40 [ 422.372676][ T7515] netlink_unicast+0x4a3/0x770 [ 422.372679][ T7515] ? netlink_attachskb+0x810/0x810 [ 422.372680][ T7515] ? __alloc_skb+0x4cd/0x600 [ 422.372683][ T7515] ? napi_skb_cache_get+0x7a0/0x7a0 [ 422.372684][ T7515] ? __lock_acquire+0x577/0xc10 [ 422.372687][ T7515] netlink_sendmsg+0x735/0xc60 [ 422.372689][ T7515] ? netlink_unicast+0x770/0x770 [ 422.372691][ T7515] ? __might_fault+0x97/0x140 [ 422.372695][ T7515] __sys_sendto+0x265/0x390 [ 422.372697][ T7515] ? __ia32_sys_getpeername+0xd0/0xd0 [ 422.372700][ T7515] ? __lock_release.isra.0+0x59/0x170 [ 422.372703][ T7515] ? update_socket_protocol+0x10/0x10 [ 422.372705][ T7515] __x64_sys_sendto+0xe4/0x1f0 [ 422.372707][ T7515] ? lockdep_hardirqs_on+0x84/0x130 [ 422.372709][ T7515] ? do_syscall_64+0x88/0xfc0 [ 422.372710][ T7515] do_syscall_64+0xbd/0xfc0 [ 422.372712][ T7515] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 422.372714][ T7515] RIP: 0033:0x7f8e05878c5e [ 422.372716][ T7515] Code: 4d 89 d8 e8 14 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 13 ff ff ff 0f 1f 00 f3 0f 1e fa [ 422.372717][ T7515] RSP: 002b:00007ffc66552f30 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 422.372719][ T7515] RAX: ffffffffffffffda RBX: 00007ffc66552fe0 RCX: 00007f8e05878c5e [ 422.372720][ T7515] RDX: 0000000000000014 RSI: 00007ffc66552fe0 RDI: 0000000000000005 [ 422.372721][ T7515] RBP: 00007ffc66552f40 R08: 00007ffc66552fa4 R09: 000000000000000c [ 422.372721][ T7515] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000014 [ 422.372722][ T7515] R13: 0000000000000005 R14: 00007f8e05a43000 R15: 0000000000406e00 [ 422.372725][ T7515] [ 422.372725][ T7515] [ 422.382174][ T7515] Allocated by task 7441: [ 422.382265][ T7515] kasan_save_stack+0x30/0x50 [ 422.382368][ T7515] kasan_save_track+0x14/0x30 [ 422.382513][ T7515] __kasan_kmalloc+0x7b/0x90 [ 422.382702][ T7515] __kmalloc_noprof+0x2cd/0x820 [ 422.382847][ T7515] ops_init+0x70/0x560 [ 422.382942][ T7515] setup_net+0x100/0x360 [ 422.383049][ T7515] copy_net_ns+0x2bf/0x3f0 [ 422.383216][ T7515] create_new_namespaces+0x35d/0x9e0 [ 422.383355][ T7515] unshare_nsproxy_namespaces+0x89/0x130 [ 422.383487][ T7515] ksys_unshare+0x3f3/0x740 [ 422.383621][ T7515] __x64_sys_unshare+0x34/0x50 [ 422.383786][ T7515] do_syscall_64+0xbd/0xfc0 [ 422.383922][ T7515] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 422.384090][ T7515] [ 422.384156][ T7515] The buggy address belongs to the object at ff1100001f440800 [ 422.384156][ T7515] which belongs to the cache kmalloc-128 of size 128 [ 422.384515][ T7515] The buggy address is located 64 bytes inside of [ 422.384515][ T7515] 120-byte region [ff1100001f440800, ff1100001f440878) [ 422.384855][ T7515] [ 422.384972][ T7515] The buggy address belongs to the physical page: [ 422.385098][ T7515] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1f440 [ 422.385360][ T7515] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 422.385633][ T7515] flags: 0x80000000000040(head|node=0|zone=1) [ 422.385792][ T7515] page_type: f5(slab) [ 422.385911][ T7515] raw: 0080000000000040 ff1100000103ce40 ffd4000000134510 ffd4000000456e10 [ 422.386214][ T7515] raw: 0000000000000000 0000000000150015 00000000f5000000 0000000000000000 [ 422.386456][ T7515] head: 0080000000000040 ff1100000103ce40 ffd4000000134510 ffd4000000456e10 [ 422.386757][ T7515] head: 0000000000000000 0000000000150015 00000000f5000000 0000000000000000 [ 422.386968][ T7515] head: 0080000000000001 ffd40000007d1001 00000000ffffffff 00000000ffffffff [ 422.387183][ T7515] head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 [ 422.387488][ T7515] page dumped because: kasan: bad access detected [ 422.387656][ T7515] [ 422.387724][ T7515] Memory state around the buggy address: [ 422.387912][ T7515] ff1100001f440700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 422.388114][ T7515] ff1100001f440780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 422.388288][ T7515] >ff1100001f440800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fc [ 422.388519][ T7515] ^ [ 422.388696][ T7515] ff1100001f440880: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 422.388890][ T7515] ff1100001f440900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 422.389133][ T7515] ================================================================== [ 422.389483][ T7515] Disabling lock debugging due to kernel taint [ 427.661626][ T12] BUG: unable to handle page fault for address: ffa00000064d7728 [ 427.661839][ T12] #PF: supervisor read access in kernel mode [ 427.661990][ T12] #PF: error_code(0x0000) - not-present page [ 427.662125][ T12] PGD 1000067 P4D 18e6067 PUD 18eb067 PMD 10fd3067 PTE 0 [ 427.662286][ T12] Oops: Oops: 0000 [#1] SMP KASAN [ 427.662403][ T12] CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Tainted: G B 6.19.0-rc5-virtme #1 PREEMPT(full) [ 427.662702][ T12] Tainted: [B]=BAD_PAGE [ 427.662807][ T12] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 427.662961][ T12] Workqueue: netns cleanup_net [ 427.663080][ T12] RIP: 0010:pm_nl_exit_net+0x16c/0x4b0 [ 427.663218][ T12] Code: 4c 01 fd 80 7d 00 00 0f 85 37 02 00 00 4c 8b 73 40 49 8d 76 08 48 89 f0 48 c1 e8 03 42 80 3c 38 00 0f 85 ed 02 00 00 4c 89 f1 <49> 8b 46 08 48 c1 e9 03 42 80 3c 39 00 0f 85 b6 02 00 00 48 89 c7 [ 427.663647][ T12] RSP: 0018:ffa00000000c7a30 EFLAGS: 00010282 [ 427.663778][ T12] RAX: 0000000000000000 RBX: ff1100001f440800 RCX: ffa00000064d7720 [ 427.663935][ T12] RDX: 0000000000000000 RSI: ffa00000064d7728 RDI: ffa00000000c79f8 [ 427.664092][ T12] RBP: ffe21c0003e88108 R08: 0000000000000008 R09: 0000000000000000 [ 427.664276][ T12] R10: 0000000000000001 R11: ffffffffa2395140 R12: ff1100001f440840 [ 427.664429][ T12] R13: dead000000000122 R14: ffa00000064d7720 R15: dffffc0000000000 [ 427.664590][ T12] FS: 0000000000000000(0000) GS:ff11000091ce4000(0000) knlGS:0000000000000000 [ 427.664814][ T12] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 427.664969][ T12] CR2: ffa00000064d7728 CR3: 0000000015b58003 CR4: 0000000000771ef0 [ 427.665194][ T12] PKRU: 55555554 [ 427.665289][ T12] Call Trace: [ 427.665386][ T12] [ 427.665454][ T12] ops_undo_list+0x2d7/0x8f0 [ 427.665587][ T12] ? rtnl_net_dumpid_one+0x2d0/0x2d0 [ 427.665747][ T12] cleanup_net+0x3bc/0x7d0 [ 427.665880][ T12] ? net_passive_dec+0x190/0x190 [ 427.665994][ T12] ? rcu_is_watching+0x15/0xd0 [ 427.666123][ T12] ? process_one_work+0xd16/0x1390 [ 427.666277][ T12] ? lock_acquire+0x10a/0x150 [ 427.666403][ T12] ? rcu_is_watching+0x15/0xd0 [ 427.666534][ T12] process_one_work+0xd57/0x1390 [ 427.666657][ T12] ? pwq_dec_nr_in_flight+0x700/0x700 [ 427.666825][ T12] ? io_schedule_timeout+0x130/0x130 [ 427.666932][ T12] ? __rwlock_init+0x150/0x150 [ 427.667022][ T12] ? schedule+0x109/0x260 [ 427.667089][ T12] ? assign_work+0x152/0x380 [ 427.667213][ T12] worker_thread+0x4d6/0xd40 [ 427.667333][ T12] ? process_one_work+0x1390/0x1390 [ 427.667442][ T12] kthread+0x355/0x5b0 [ 427.667531][ T12] ? kthread_is_per_cpu+0xe0/0xe0 [ 427.667657][ T12] ? __lock_release.isra.0+0x59/0x170 [ 427.667792][ T12] ? rcu_is_watching+0x15/0xd0 [ 427.667906][ T12] ? kthread_is_per_cpu+0xe0/0xe0 [ 427.668029][ T12] ret_from_fork+0x3fb/0x510 [ 427.668143][ T12] ? arch_exit_to_user_mode_prepare.isra.0+0x140/0x140 [ 427.668291][ T12] ? __switch_to+0x53c/0xd00 [ 427.668404][ T12] ? kthread_is_per_cpu+0xe0/0xe0 [ 427.668529][ T12] ret_from_fork_asm+0x11/0x20 [ 427.668671][ T12] [ 427.668762][ T12] Modules linked in: xt_bpf sch_netem ipt_REJECT nf_reject_ipv4 nft_compat nf_tables [ 427.668976][ T12] CR2: ffa00000064d7728 [ 427.669071][ T12] ---[ end trace 0000000000000000 ]--- [ 427.669242][ T12] RIP: 0010:pm_nl_exit_net+0x16c/0x4b0 [ 427.669370][ T12] Code: 4c 01 fd 80 7d 00 00 0f 85 37 02 00 00 4c 8b 73 40 49 8d 76 08 48 89 f0 48 c1 e8 03 42 80 3c 38 00 0f 85 ed 02 00 00 4c 89 f1 <49> 8b 46 08 48 c1 e9 03 42 80 3c 39 00 0f 85 b6 02 00 00 48 89 c7 [ 427.669824][ T12] RSP: 0018:ffa00000000c7a30 EFLAGS: 00010282 [ 427.669982][ T12] RAX: 0000000000000000 RBX: ff1100001f440800 RCX: ffa00000064d7720 [ 427.670160][ T12] RDX: 0000000000000000 RSI: ffa00000064d7728 RDI: ffa00000000c79f8 [ 427.670357][ T12] RBP: ffe21c0003e88108 R08: 0000000000000008 R09: 0000000000000000 [ 427.670506][ T12] R10: 0000000000000001 R11: ffffffffa2395140 R12: ff1100001f440840 [ 427.670699][ T12] R13: dead000000000122 R14: ffa00000064d7720 R15: dffffc0000000000 [ 427.670877][ T12] FS: 0000000000000000(0000) GS:ff11000091ce4000(0000) knlGS:0000000000000000 [ 427.671089][ T12] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 427.671236][ T12] CR2: ffa00000064d7728 CR3: 0000000015b58003 CR4: 0000000000771ef0 [ 427.671395][ T12] PKRU: 55555554 [ 427.671481][ T12] Kernel panic - not syncing: Fatal exception [ 427.671757][ T12] Kernel Offset: 0x1da00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) [ 427.672064][ T12] ---[ end Kernel panic - not syncing: Fatal exception ]--- WAIT TIMEOUT stderr Ctrl-C stderr Ctrl-C stderr WAIT TIMEOUT stderr