[ 618.829032][ T7863] lag1: Mode changed to "loadbalance" [ 618.858753][ T7864] 8021q: adding VLAN 0 to HW filter on device lag1 [ 618.943574][ T7870] lag1: Port device veth0 added [ 618.967318][ T7872] lag1: Port device veth6 added [ 619.158859][ T7888] 8021q: adding VLAN 0 to HW filter on device lag1 [ 619.406990][ T7899] lag4: Mode changed to "loadbalance" [ 619.434973][ T7900] 8021q: adding VLAN 0 to HW filter on device lag4 [ 619.593727][ T7907] lag4: Port device veth3 added [ 619.617505][ T7908] lag4: Port device veth5 added [ 619.775137][ T7914] 8021q: adding VLAN 0 to HW filter on device lag4 [ 620.032006][ T7925] lag2: Mode changed to "loadbalance" [ 620.061661][ T7928] 8021q: adding VLAN 0 to HW filter on device lag2 [ 620.184230][ T7935] lag2: Port device veth1 added [ 620.235289][ T7936] lag2: Port device veth7 added [ 620.337735][ T7943] br1: port 1(lag2) entered blocking state [ 620.337946][ T7943] br1: port 1(lag2) entered disabled state [ 620.338123][ T7943] lag2: entered allmulticast mode [ 620.338255][ T7943] veth1: entered allmulticast mode [ 620.338393][ T7943] veth7: entered allmulticast mode [ 620.341201][ T7943] veth1: entered promiscuous mode [ 620.341519][ T7943] veth7: entered promiscuous mode [ 620.411242][ T7948] br1: port 1(lag2) entered blocking state [ 620.411461][ T7948] br1: port 1(lag2) entered forwarding state [ 620.548738][ T7954] lag3: Mode changed to "loadbalance" [ 620.589156][ T7957] 8021q: adding VLAN 0 to HW filter on device lag3 [ 620.717191][ T7964] lag3: Port device veth2 added [ 620.747010][ T7965] lag3: Port device veth4 added [ 628.487579][ T8036] veth7: left allmulticast mode [ 628.488679][ T8036] lag2: Port device veth7 removed [ 628.510127][ T8037] veth7: left promiscuous mode [ 640.848696][ T8089] veth7: entered allmulticast mode [ 640.848926][ T8089] veth7: entered promiscuous mode [ 640.849846][ T8089] lag2: Port device veth7 added [ 640.960096][ T8100] veth1: left allmulticast mode [ 640.961169][ T8100] lag2: Port device veth1 removed [ 640.993313][ T8101] veth1: left promiscuous mode [ 653.290051][ T38] br1: port 1(lag2) entered disabled state [ 653.319643][ T8153] veth7: left allmulticast mode [ 653.321074][ T8153] lag2: Port device veth7 removed [ 653.355629][ T8154] veth7: left promiscuous mode [ 653.442860][ T8164] veth1: entered allmulticast mode [ 653.443072][ T8164] veth1: entered promiscuous mode [ 653.444875][ T8164] lag2: Port device veth1 added [ 653.453189][ T920] br1: port 1(lag2) entered blocking state [ 653.453393][ T920] br1: port 1(lag2) entered forwarding state [ 653.564693][ T8175] veth7: entered allmulticast mode [ 653.564866][ T8175] veth7: entered promiscuous mode [ 653.565624][ T8175] lag2: Port device veth7 added [ 665.945251][ T8227] lag2: left allmulticast mode [ 665.945429][ T8227] veth1: left allmulticast mode [ 665.945573][ T8227] veth7: left allmulticast mode [ 665.945862][ T8227] br1: port 1(lag2) entered disabled state [ 665.948105][ T8227] veth1: left promiscuous mode [ 665.948268][ T8227] veth7: left promiscuous mode [ 667.980277][ T8229] br1: port 1(lag2) entered blocking state [ 667.980500][ T8229] br1: port 1(lag2) entered disabled state [ 667.980708][ T8229] lag2: entered allmulticast mode [ 667.980842][ T8229] veth1: entered allmulticast mode [ 667.980977][ T8229] veth7: entered allmulticast mode [ 667.983911][ T8229] br1: port 1(lag2) entered blocking state [ 667.984097][ T8229] br1: port 1(lag2) entered forwarding state [ 667.984790][ T8229] veth1: entered promiscuous mode [ 667.984945][ T8229] veth7: entered promiscuous mode [ 680.306460][ T8281] lag3: Port device veth2 removed [ 692.674665][ T8334] lag3: Port device veth2 added [ 692.793534][ T8345] lag3: Port device veth4 removed [ 705.154089][ T8398] lag3: Port device veth2 removed [ 705.266372][ T8409] lag3: Port device veth4 added [ 705.369198][ T8420] lag3: Port device veth2 added [ 717.711256][ T8472] br1: port 2(lag3) entered blocking state [ 717.712052][ T8472] br1: port 2(lag3) entered disabled state [ 717.712255][ T8472] lag3: entered allmulticast mode [ 717.712392][ T8472] veth4: entered allmulticast mode [ 717.712529][ T8472] veth2: entered allmulticast mode [ 717.714141][ T8472] lag3: entered promiscuous mode [ 717.714307][ T8472] veth4: entered promiscuous mode [ 717.714632][ T8472] veth2: entered promiscuous mode [ 717.715266][ T8472] lag2: entered promiscuous mode [ 717.716758][ T8472] br1: port 2(lag3) entered blocking state [ 717.716945][ T8472] br1: port 2(lag3) entered forwarding state [ 719.755088][ T8475] lag3: left allmulticast mode [ 719.755273][ T8475] veth4: left allmulticast mode [ 719.755797][ T8475] veth2: left allmulticast mode [ 719.755993][ T8475] lag3: left promiscuous mode [ 719.756129][ T8475] veth4: left promiscuous mode [ 719.756484][ T8475] veth2: left promiscuous mode [ 719.756954][ T8475] br1: port 2(lag3) entered disabled state [ 719.757673][ T8475] lag2: left promiscuous mode [ 719.757819][ T8475] veth1: left promiscuous mode [ 719.758141][ T8475] veth7: left promiscuous mode [ 719.758597][ T8475] veth1: entered promiscuous mode [ 719.758771][ T8475] veth7: entered promiscuous mode [ 732.222147][ T8530] lag3: Port device veth4 removed [ 732.249635][ T8531] lag3: Port device veth2 removed [ 732.302431][ T7925] ================================================================== [ 732.302638][ T7925] BUG: KASAN: slab-use-after-free in rtnl_fill_prop_list+0x5ad/0x600 [ 732.302816][ T7925] Read of size 8 at addr ff1100001a591250 by task teamd/7925 [ 732.302988][ T7925] [ 732.303048][ T7925] CPU: 2 UID: 0 PID: 7925 Comm: teamd Not tainted 7.1.0-rc3-virtme #1 PREEMPT(full) [ 732.303051][ T7925] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 732.303053][ T7925] Call Trace: [ 732.303055][ T7925] [ 732.303056][ T7925] dump_stack_lvl+0x6f/0xa0 [ 732.303062][ T7925] print_address_description.constprop.0+0x56/0x2d0 [ 732.303067][ T7925] print_report+0xfc/0x1fa [ 732.303069][ T7925] ? __virt_addr_valid+0x102/0x440 [ 732.303080][ T7925] ? __virt_addr_valid+0x1da/0x440 [ 732.303082][ T7925] kasan_report+0x108/0x130 [ 732.303085][ T7925] ? rtnl_fill_prop_list+0x5ad/0x600 [ 732.303086][ T7925] ? rtnl_fill_prop_list+0x5ad/0x600 [ 732.303089][ T7925] rtnl_fill_prop_list+0x5ad/0x600 [ 732.303090][ T7925] ? __asan_memcpy+0x3c/0x60 [ 732.303093][ T7925] rtnl_fill_ifinfo.isra.0+0x3dc/0x2a80 [ 732.303095][ T7925] ? rcu_read_lock_any_held+0x3c/0x90 [ 732.303098][ T7925] ? validate_chain+0x38b/0xc20 [ 732.303101][ T7925] ? rtnl_fill_vf+0x450/0x450 [ 732.303102][ T7925] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 732.303103][ T7925] ? lockdep_hardirqs_on+0x8c/0x130 [ 732.303107][ T7925] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 732.303109][ T7925] ? __lock_acquire+0x508/0xc10 [ 732.303111][ T7925] ? rtnl_fill_vfinfo+0x606/0xf70 [ 732.303113][ T7925] ? lock_acquire.part.0+0xbc/0x260 [ 732.303114][ T7925] ? find_held_lock+0x2b/0x80 [ 732.303117][ T7925] ? __lock_release.isra.0+0x6b/0x1a0 [ 732.303119][ T7925] ? mark_held_locks+0x40/0x70 [ 732.303121][ T7925] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 732.303122][ T7925] ? lockdep_hardirqs_on+0x8c/0x130 [ 732.303123][ T7925] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 732.303126][ T7925] rtnl_getlink+0xa48/0xe50 [ 732.303128][ T7925] ? find_held_lock+0x2b/0x80 [ 732.303130][ T7925] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 732.303132][ T7925] ? mark_usage+0x61/0x170 [ 732.303133][ T7925] ? __lock_release.isra.0+0x6b/0x1a0 [ 732.303134][ T7925] ? __lock_acquire+0x508/0xc10 [ 732.303142][ T7925] ? lock_acquire.part.0+0xbc/0x260 [ 732.303143][ T7925] ? find_held_lock+0x2b/0x80 [ 732.303145][ T7925] ? mark_usage+0x61/0x170 [ 732.303146][ T7925] ? __lock_release.isra.0+0x6b/0x1a0 [ 732.303147][ T7925] ? __lock_acquire+0x508/0xc10 [ 732.303149][ T7925] ? bpf_address_lookup+0x282/0x290 [ 732.303152][ T7925] ? lock_acquire.part.0+0xbc/0x260 [ 732.303153][ T7925] ? find_held_lock+0x2b/0x80 [ 732.303155][ T7925] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 732.303156][ T7925] ? __lock_release.isra.0+0x6b/0x1a0 [ 732.303158][ T7925] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 732.303160][ T7925] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 732.303162][ T7925] ? validate_chain+0x38b/0xc20 [ 732.303163][ T7925] ? rtnl_link_fill+0x900/0x900 [ 732.303164][ T7925] ? __lock_acquire+0x508/0xc10 [ 732.303167][ T7925] ? lock_acquire.part.0+0xbc/0x260 [ 732.303168][ T7925] ? find_held_lock+0x2b/0x80 [ 732.303170][ T7925] netlink_rcv_skb+0x14e/0x3a0 [ 732.303173][ T7925] ? rtnl_link_fill+0x900/0x900 [ 732.303175][ T7925] ? netlink_ack+0xcd0/0xcd0 [ 732.303178][ T7925] ? netlink_deliver_tap+0xc5/0x330 [ 732.303179][ T7925] ? netlink_deliver_tap+0x13c/0x330 [ 732.303181][ T7925] netlink_unicast+0x4af/0x780 [ 732.303184][ T7925] ? netlink_attachskb+0x800/0x800 [ 732.303185][ T7925] ? trace_irq_enable.constprop.0+0x9b/0x180 [ 732.303188][ T7925] ? __lock_acquire+0x508/0xc10 [ 732.303190][ T7925] netlink_sendmsg+0x735/0xc60 [ 732.303192][ T7925] ? netlink_unicast+0x780/0x780 [ 732.303195][ T7925] ? __might_fault+0x97/0x140 [ 732.303198][ T7925] ____sys_sendmsg+0x419/0x850 [ 732.303201][ T7925] ? copy_msghdr_from_user+0x2a0/0x460 [ 732.303204][ T7925] ? get_timestamp.constprop.0+0x3a0/0x3a0 [ 732.303205][ T7925] ? move_addr_to_kernel+0x40/0x40 [ 732.303209][ T7925] ___sys_sendmsg+0x14e/0x1d0 [ 732.303211][ T7925] ? copy_msghdr_from_user+0x460/0x460 [ 732.303212][ T7925] ? kfree+0x22/0x5a0 [ 732.303219][ T7925] ? rcu_is_watching+0x15/0xd0 [ 732.303221][ T7925] ? rcu_is_watching+0x15/0xd0 [ 732.303223][ T7925] __sys_sendmsg+0x145/0x1f0 [ 732.303225][ T7925] ? __sys_sendmsg_sock+0x20/0x20 [ 732.303229][ T7925] ? rcu_is_watching+0x15/0xd0 [ 732.303231][ T7925] do_syscall_64+0x117/0xfc0 [ 732.303233][ T7925] ? irq_exit_rcu+0x1a/0x30 [ 732.303236][ T7925] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 732.303238][ T7925] RIP: 0033:0x7fb8b281908e [ 732.303241][ T7925] Code: 4d 89 d8 e8 94 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 732.303243][ T7925] RSP: 002b:00007fffb4cf9100 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [ 732.303247][ T7925] RAX: ffffffffffffffda RBX: 000055ed729b3330 RCX: 00007fb8b281908e [ 732.303248][ T7925] RDX: 0000000000000000 RSI: 00007fffb4cf91a0 RDI: 0000000000000005 [ 732.303249][ T7925] RBP: 00007fffb4cf9110 R08: 0000000000000000 R09: 0000000000000000 [ 732.303250][ T7925] R10: 0000000000000000 R11: 0000000000000202 R12: 000055ed729bc210 [ 732.303251][ T7925] R13: 00007fffb4cf91a0 R14: 000055ed729b3240 R15: 00007fffb4cf92e0 [ 732.303253][ T7925] [ 732.303254][ T7925] [ 732.312348][ T7925] Allocated by task 7954: [ 732.312411][ T7925] kasan_save_stack+0x2f/0x50 [ 732.312495][ T7925] kasan_save_track+0x14/0x30 [ 732.312637][ T7925] __kasan_kmalloc+0x7b/0x90 [ 732.312720][ T7925] register_netdevice+0x48b/0x1980 [ 732.312832][ T7925] team_newlink+0xa2/0x1a0 [ 732.312946][ T7925] rtnl_newlink_create+0x2da/0x780 [ 732.313054][ T7925] __rtnl_newlink+0x22b/0xa50 [ 732.313170][ T7925] rtnl_newlink+0x8d1/0xee0 [ 732.313253][ T7925] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 732.313331][ T7925] netlink_rcv_skb+0x14e/0x3a0 [ 732.313443][ T7925] netlink_unicast+0x4af/0x780 [ 732.313552][ T7925] netlink_sendmsg+0x735/0xc60 [ 732.313660][ T7925] ____sys_sendmsg+0x419/0x850 [ 732.313767][ T7925] ___sys_sendmsg+0x14e/0x1d0 [ 732.313854][ T7925] __sys_sendmsg+0x145/0x1f0 [ 732.313962][ T7925] do_syscall_64+0x117/0xfc0 [ 732.314059][ T7925] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 732.314201][ T7925] [ 732.314244][ T7925] Freed by task 7954: [ 732.314331][ T7925] kasan_save_stack+0x2f/0x50 [ 732.314417][ T7925] kasan_save_track+0x14/0x30 [ 732.314500][ T7925] kasan_save_free_info+0x3b/0x60 [ 732.314605][ T7925] __kasan_slab_free+0x43/0x70 [ 732.314768][ T7925] kfree+0x123/0x5a0 [ 732.314866][ T7925] unregister_netdevice_many_notify+0xe38/0x1d80 [ 732.315019][ T7925] rtnl_dellink+0x4a0/0xae0 [ 732.315107][ T7925] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 732.315255][ T7925] netlink_rcv_skb+0x14e/0x3a0 [ 732.315371][ T7925] netlink_unicast+0x4af/0x780 [ 732.315487][ T7925] netlink_sendmsg+0x735/0xc60 [ 732.315599][ T7925] ____sys_sendmsg+0x419/0x850 [ 732.315682][ T7925] ___sys_sendmsg+0x14e/0x1d0 [ 732.315763][ T7925] __sys_sendmsg+0x145/0x1f0 [ 732.315867][ T7925] do_syscall_64+0x117/0xfc0 [ 732.316012][ T7925] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 732.316150][ T7925] [ 732.316200][ T7925] The buggy address belongs to the object at ff1100001a591240 [ 732.316200][ T7925] which belongs to the cache kmalloc-64 of size 64 [ 732.316413][ T7925] The buggy address is located 16 bytes inside of [ 732.316413][ T7925] freed 64-byte region [ff1100001a591240, ff1100001a591280) [ 732.316647][ T7925] [ 732.316688][ T7925] The buggy address belongs to the physical page: [ 732.316793][ T7925] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1a591 [ 732.316945][ T7925] flags: 0x80000000000000(node=0|zone=1) [ 732.317030][ T7925] page_type: f5(slab) [ 732.317101][ T7925] raw: 0080000000000000 ff1100000103cac0 ffd4000000694650 ffd400000070f050 [ 732.317332][ T7925] raw: 0000000000000000 0000000000100010 00000000f5000000 0000000000000000 [ 732.317485][ T7925] page dumped because: kasan: bad access detected [ 732.317618][ T7925] [ 732.317659][ T7925] Memory state around the buggy address: [ 732.317765][ T7925] ff1100001a591100: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 732.317922][ T7925] ff1100001a591180: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 732.318069][ T7925] >ff1100001a591200: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 732.318286][ T7925] ^ [ 732.318469][ T7925] ff1100001a591280: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 732.318619][ T7925] ff1100001a591300: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 732.318790][ T7925] ================================================================== [ 732.319035][ T7925] Disabling lock debugging due to kernel taint [ 732.471190][ T38] br1: port 1(lag2) entered disabled state [ 732.497391][ T8548] lag2: left allmulticast mode [ 732.497507][ T8548] veth1: left allmulticast mode [ 732.497600][ T8548] veth7: left allmulticast mode [ 732.497728][ T8548] br1: port 1(lag2) entered disabled state [ 732.580411][ T8550] lag2: Port device veth7 removed [ 732.597977][ T8551] lag2: Port device veth1 removed [ 732.920700][ T8564] lag4: Port device veth5 removed [ 732.934752][ T8565] lag4: Port device veth3 removed [ 733.269105][ T8578] lag1: Port device veth6 removed [ 733.284287][ T8579] lag1: Port device veth0 removed