[ 652.745736][ T7815] lag1: Mode changed to "loadbalance" [ 652.776683][ T7816] 8021q: adding VLAN 0 to HW filter on device lag1 [ 652.899274][ T7825] lag1: Port device veth0 added [ 652.922143][ T7827] lag1: Port device veth6 added [ 653.092827][ T7841] 8021q: adding VLAN 0 to HW filter on device lag1 [ 653.589998][ T7864] lag4: Mode changed to "loadbalance" [ 653.628122][ T7866] 8021q: adding VLAN 0 to HW filter on device lag4 [ 653.800550][ T7873] lag4: Port device veth3 added [ 653.824468][ T7874] lag4: Port device veth5 added [ 653.955508][ T7880] 8021q: adding VLAN 0 to HW filter on device lag4 [ 654.457061][ T7903] lag2: Mode changed to "loadbalance" [ 654.484937][ T7905] 8021q: adding VLAN 0 to HW filter on device lag2 [ 654.651797][ T7914] lag2: Port device veth1 added [ 654.682843][ T7915] lag2: Port device veth7 added [ 654.927814][ T7929] br1: port 1(lag2.100) entered blocking state [ 654.928010][ T7929] br1: port 1(lag2.100) entered disabled state [ 654.928192][ T7929] lag2.100: entered allmulticast mode [ 654.928319][ T7929] lag2: entered allmulticast mode [ 654.928462][ T7929] veth1: entered allmulticast mode [ 654.928606][ T7929] veth7: entered allmulticast mode [ 654.930606][ T7929] lag2.100: entered promiscuous mode [ 654.930744][ T7929] lag2: entered promiscuous mode [ 654.930881][ T7929] veth1: entered promiscuous mode [ 654.931157][ T7929] veth7: entered promiscuous mode [ 655.057326][ T7937] br2: port 1(lag2.200) entered blocking state [ 655.057522][ T7937] br2: port 1(lag2.200) entered disabled state [ 655.057706][ T7937] lag2.200: entered allmulticast mode [ 655.059191][ T7937] lag2.200: entered promiscuous mode [ 655.128233][ T7940] br1: port 1(lag2.100) entered blocking state [ 655.128433][ T7940] br1: port 1(lag2.100) entered forwarding state [ 655.154480][ T7941] br2: port 1(lag2.200) entered blocking state [ 655.154692][ T7941] br2: port 1(lag2.200) entered forwarding state [ 655.322511][ T7949] lag3: Mode changed to "loadbalance" [ 655.356722][ T7950] 8021q: adding VLAN 0 to HW filter on device lag3 [ 655.520642][ T7958] lag3: Port device veth2 added [ 655.551159][ T7959] lag3: Port device veth4 added [ 665.453250][ T8049] veth7: left promiscuous mode [ 665.453752][ T8049] veth7: left allmulticast mode [ 665.454696][ T8049] lag2: Port device veth7 removed [ 679.835113][ T8112] veth7: entered promiscuous mode [ 679.836173][ T8112] veth7: entered allmulticast mode [ 679.837229][ T8112] lag2: Port device veth7 added [ 679.951277][ T8123] veth1: left promiscuous mode [ 679.951562][ T8123] veth1: left allmulticast mode [ 679.952644][ T8123] lag2: Port device veth1 removed [ 694.308937][ T36] br1: port 1(lag2.100) entered disabled state [ 694.310176][ T36] br2: port 1(lag2.200) entered disabled state [ 694.323336][ T8186] veth7: left promiscuous mode [ 694.324209][ T8186] veth7: left allmulticast mode [ 694.325071][ T8186] lag2: Port device veth7 removed [ 694.433665][ T8198] veth1: entered promiscuous mode [ 694.434139][ T8198] veth1: entered allmulticast mode [ 694.441731][ T8198] lag2: Port device veth1 added [ 694.455369][ T39] br1: port 1(lag2.100) entered blocking state [ 694.455572][ T39] br1: port 1(lag2.100) entered forwarding state [ 694.456069][ T39] br2: port 1(lag2.200) entered blocking state [ 694.456228][ T39] br2: port 1(lag2.200) entered forwarding state [ 694.562540][ T8209] veth7: entered promiscuous mode [ 694.562877][ T8209] veth7: entered allmulticast mode [ 694.563695][ T8209] lag2: Port device veth7 added [ 708.899742][ T8271] lag2.200: left allmulticast mode [ 708.900031][ T8271] lag2.200: left promiscuous mode [ 708.900586][ T8271] br2: port 1(lag2.200) entered disabled state [ 708.924647][ T8272] lag2.100: left allmulticast mode [ 708.924833][ T8272] lag2: left allmulticast mode [ 708.925023][ T8272] veth1: left allmulticast mode [ 708.925213][ T8272] veth7: left allmulticast mode [ 708.925830][ T8272] lag2.100: left promiscuous mode [ 708.926011][ T8272] lag2: left promiscuous mode [ 708.926199][ T8272] veth1: left promiscuous mode [ 708.927069][ T8272] veth7: left promiscuous mode [ 708.927719][ T8272] br1: port 1(lag2.100) entered disabled state [ 710.965178][ T8274] br1: port 1(lag2.100) entered blocking state [ 710.965370][ T8274] br1: port 1(lag2.100) entered disabled state [ 710.965555][ T8274] lag2.100: entered allmulticast mode [ 710.965678][ T8274] lag2: entered allmulticast mode [ 710.965807][ T8274] veth1: entered allmulticast mode [ 710.965948][ T8274] veth7: entered allmulticast mode [ 710.967445][ T8274] lag2.100: entered promiscuous mode [ 710.967579][ T8274] lag2: entered promiscuous mode [ 710.967708][ T8274] veth1: entered promiscuous mode [ 710.967979][ T8274] veth7: entered promiscuous mode [ 710.969301][ T8274] br1: port 1(lag2.100) entered blocking state [ 710.969476][ T8274] br1: port 1(lag2.100) entered forwarding state [ 710.996509][ T8275] br2: port 1(lag2.200) entered blocking state [ 710.996719][ T8275] br2: port 1(lag2.200) entered disabled state [ 710.996947][ T8275] lag2.200: entered allmulticast mode [ 710.998444][ T8275] lag2.200: entered promiscuous mode [ 710.999095][ T8275] br2: port 1(lag2.200) entered blocking state [ 710.999304][ T8275] br2: port 1(lag2.200) entered forwarding state [ 725.334377][ T8337] lag3: Port device veth2 removed [ 739.703133][ T8400] lag3: Port device veth2 added [ 739.810254][ T8411] lag3: Port device veth4 removed [ 754.197171][ T8474] lag3: Port device veth2 removed [ 754.316161][ T8485] lag3: Port device veth4 added [ 754.427945][ T8496] lag3: Port device veth2 added [ 769.006650][ T8566] lag3: Port device veth4 removed [ 769.028649][ T8569] lag3: Port device veth2 removed [ 769.086365][ T7903] ================================================================== [ 769.086508][ T7903] BUG: KASAN: slab-use-after-free in rtnl_fill_prop_list+0x5ad/0x600 [ 769.086633][ T7903] Read of size 8 at addr ff11000015199750 by task teamd/7903 [ 769.086747][ T7903] [ 769.086787][ T7903] CPU: 2 UID: 0 PID: 7903 Comm: teamd Not tainted 7.1.0-rc3-virtme #1 PREEMPT(full) [ 769.086791][ T7903] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 769.086793][ T7903] Call Trace: [ 769.086794][ T7903] [ 769.086795][ T7903] dump_stack_lvl+0x6f/0xa0 [ 769.086801][ T7903] print_address_description.constprop.0+0x56/0x2d0 [ 769.086806][ T7903] print_report+0xfc/0x1fa [ 769.086808][ T7903] ? __virt_addr_valid+0x102/0x440 [ 769.086812][ T7903] ? __virt_addr_valid+0x1da/0x440 [ 769.086814][ T7903] kasan_report+0x108/0x130 [ 769.086817][ T7903] ? rtnl_fill_prop_list+0x5ad/0x600 [ 769.086819][ T7903] ? rtnl_fill_prop_list+0x5ad/0x600 [ 769.086821][ T7903] rtnl_fill_prop_list+0x5ad/0x600 [ 769.086823][ T7903] ? __asan_memcpy+0x3c/0x60 [ 769.086825][ T7903] rtnl_fill_ifinfo.isra.0+0x3d3/0x2b50 [ 769.086828][ T7903] ? rcu_read_lock_any_held+0x3c/0x90 [ 769.086830][ T7903] ? validate_chain+0x38b/0xc20 [ 769.086833][ T7903] ? rtnl_fill_vf+0x450/0x450 [ 769.086834][ T7903] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 769.086835][ T7903] ? lockdep_hardirqs_on+0x8c/0x130 [ 769.086839][ T7903] ? _raw_spin_unlock_irqrestore+0x40/0x80 [ 769.086841][ T7903] ? __lock_acquire+0x508/0xc10 [ 769.086842][ T7903] ? rtnl_fill_vfinfo+0x844/0xf70 [ 769.086844][ T7903] ? lock_acquire.part.0+0xbc/0x260 [ 769.086846][ T7903] ? find_held_lock+0x2b/0x80 [ 769.086848][ T7903] ? __lock_release.isra.0+0x6b/0x1a0 [ 769.086850][ T7903] ? mark_held_locks+0x40/0x70 [ 769.086852][ T7903] ? lockdep_hardirqs_on_prepare.part.0+0x9a/0x160 [ 769.086853][ T7903] ? lockdep_hardirqs_on+0x8c/0x130 [ 769.086854][ T7903] ? _raw_spin_unlock_irqrestore+0x53/0x80 [ 769.086856][ T7903] rtnl_getlink+0xa48/0xe50 [ 769.086859][ T7903] ? find_held_lock+0x2b/0x80 [ 769.086860][ T7903] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 769.086862][ T7903] ? mark_usage+0x61/0x170 [ 769.086863][ T7903] ? __lock_release.isra.0+0x6b/0x1a0 [ 769.086864][ T7903] ? __lock_acquire+0x508/0xc10 [ 769.086872][ T7903] ? lock_acquire.part.0+0xbc/0x260 [ 769.086873][ T7903] ? find_held_lock+0x2b/0x80 [ 769.086875][ T7903] ? mark_usage+0x61/0x170 [ 769.086876][ T7903] ? __lock_release.isra.0+0x6b/0x1a0 [ 769.086877][ T7903] ? __lock_acquire+0x508/0xc10 [ 769.086879][ T7903] ? bpf_address_lookup+0x282/0x290 [ 769.086882][ T7903] ? lock_acquire.part.0+0xbc/0x260 [ 769.086883][ T7903] ? find_held_lock+0x2b/0x80 [ 769.086885][ T7903] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 769.086886][ T7903] ? __lock_release.isra.0+0x6b/0x1a0 [ 769.086888][ T7903] ? rtnl_dump_ifinfo+0xfb0/0xfb0 [ 769.086890][ T7903] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 769.086891][ T7903] ? validate_chain+0x38b/0xc20 [ 769.086893][ T7903] ? rtnl_link_fill+0x900/0x900 [ 769.086894][ T7903] ? __lock_acquire+0x508/0xc10 [ 769.086896][ T7903] ? lock_acquire.part.0+0xbc/0x260 [ 769.086897][ T7903] ? find_held_lock+0x2b/0x80 [ 769.086899][ T7903] netlink_rcv_skb+0x14e/0x3a0 [ 769.086902][ T7903] ? rtnl_link_fill+0x900/0x900 [ 769.086904][ T7903] ? netlink_ack+0xcd0/0xcd0 [ 769.086907][ T7903] ? netlink_deliver_tap+0xc5/0x330 [ 769.086908][ T7903] ? netlink_deliver_tap+0x13c/0x330 [ 769.086911][ T7903] netlink_unicast+0x47c/0x740 [ 769.086913][ T7903] ? netlink_attachskb+0x800/0x800 [ 769.086914][ T7903] ? trace_irq_enable.constprop.0+0x9b/0x180 [ 769.086917][ T7903] ? __lock_acquire+0x508/0xc10 [ 769.086919][ T7903] netlink_sendmsg+0x735/0xc60 [ 769.086921][ T7903] ? netlink_unicast+0x740/0x740 [ 769.086923][ T7903] ? __might_fault+0x97/0x140 [ 769.086928][ T7903] ____sys_sendmsg+0x419/0x850 [ 769.086931][ T7903] ? copy_msghdr_from_user+0x2a0/0x460 [ 769.086933][ T7903] ? get_timestamp.constprop.0+0x3a0/0x3a0 [ 769.086934][ T7903] ? move_addr_to_kernel+0x40/0x40 [ 769.086938][ T7903] ___sys_sendmsg+0x14e/0x1d0 [ 769.086940][ T7903] ? copy_msghdr_from_user+0x460/0x460 [ 769.086941][ T7903] ? kfree+0x22/0x5a0 [ 769.086948][ T7903] __sys_sendmsg+0x145/0x1f0 [ 769.086950][ T7903] ? __sys_sendmsg_sock+0x20/0x20 [ 769.086954][ T7903] ? rcu_is_watching+0x15/0xd0 [ 769.086956][ T7903] do_syscall_64+0x117/0xfc0 [ 769.086958][ T7903] ? irq_exit_rcu+0x1a/0x30 [ 769.086960][ T7903] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 769.086963][ T7903] RIP: 0033:0x7f922b84808e [ 769.086966][ T7903] Code: 4d 89 d8 e8 94 bd 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 03 ff ff ff 0f 1f 00 f3 0f 1e fa [ 769.086968][ T7903] RSP: 002b:00007ffeabf49c20 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [ 769.086971][ T7903] RAX: ffffffffffffffda RBX: 00005650b87a5330 RCX: 00007f922b84808e [ 769.086973][ T7903] RDX: 0000000000000000 RSI: 00007ffeabf49cc0 RDI: 0000000000000005 [ 769.086974][ T7903] RBP: 00007ffeabf49c30 R08: 0000000000000000 R09: 0000000000000000 [ 769.086974][ T7903] R10: 0000000000000000 R11: 0000000000000202 R12: 00005650b87acb30 [ 769.086975][ T7903] R13: 00007ffeabf49cc0 R14: 00005650b87a5240 R15: 00007ffeabf49e00 [ 769.086978][ T7903] [ 769.086978][ T7903] [ 769.094355][ T7903] Allocated by task 7949: [ 769.094415][ T7903] kasan_save_stack+0x2f/0x50 [ 769.094493][ T7903] kasan_save_track+0x14/0x30 [ 769.094570][ T7903] __kasan_kmalloc+0x7b/0x90 [ 769.094646][ T7903] register_netdevice+0x48b/0x1980 [ 769.094761][ T7903] team_newlink+0xa2/0x1a0 [ 769.094839][ T7903] rtnl_newlink_create+0x2da/0x780 [ 769.094916][ T7903] __rtnl_newlink+0x22b/0xa50 [ 769.095035][ T7903] rtnl_newlink+0x8d1/0xee0 [ 769.095112][ T7903] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 769.095191][ T7903] netlink_rcv_skb+0x14e/0x3a0 [ 769.095272][ T7903] netlink_unicast+0x47c/0x740 [ 769.095354][ T7903] netlink_sendmsg+0x735/0xc60 [ 769.095430][ T7903] ____sys_sendmsg+0x419/0x850 [ 769.095513][ T7903] ___sys_sendmsg+0x14e/0x1d0 [ 769.095595][ T7903] __sys_sendmsg+0x145/0x1f0 [ 769.095678][ T7903] do_syscall_64+0x117/0xfc0 [ 769.095757][ T7903] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 769.095856][ T7903] [ 769.095897][ T7903] Freed by task 7949: [ 769.095957][ T7903] kasan_save_stack+0x2f/0x50 [ 769.096039][ T7903] kasan_save_track+0x14/0x30 [ 769.096117][ T7903] kasan_save_free_info+0x3b/0x60 [ 769.096196][ T7903] __kasan_slab_free+0x43/0x70 [ 769.096275][ T7903] kfree+0x123/0x5a0 [ 769.096342][ T7903] unregister_netdevice_many_notify+0xe38/0x1d80 [ 769.096441][ T7903] rtnl_dellink+0x4a0/0xae0 [ 769.096523][ T7903] rtnetlink_rcv_msg+0x6fd/0xbd0 [ 769.096601][ T7903] netlink_rcv_skb+0x14e/0x3a0 [ 769.096681][ T7903] netlink_unicast+0x47c/0x740 [ 769.096761][ T7903] netlink_sendmsg+0x735/0xc60 [ 769.096840][ T7903] ____sys_sendmsg+0x419/0x850 [ 769.096961][ T7903] ___sys_sendmsg+0x14e/0x1d0 [ 769.097039][ T7903] __sys_sendmsg+0x145/0x1f0 [ 769.097118][ T7903] do_syscall_64+0x117/0xfc0 [ 769.097277][ T7903] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 769.097376][ T7903] [ 769.097414][ T7903] The buggy address belongs to the object at ff11000015199740 [ 769.097414][ T7903] which belongs to the cache kmalloc-64 of size 64 [ 769.097674][ T7903] The buggy address is located 16 bytes inside of [ 769.097674][ T7903] freed 64-byte region [ff11000015199740, ff11000015199780) [ 769.097861][ T7903] [ 769.097900][ T7903] The buggy address belongs to the physical page: [ 769.098032][ T7903] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x15199 [ 769.098168][ T7903] flags: 0x80000000000000(node=0|zone=1) [ 769.098248][ T7903] page_type: f5(slab) [ 769.098355][ T7903] raw: 0080000000000000 ff1100000103cac0 ffd4000000244bd0 ffd4000000343310 [ 769.098495][ T7903] raw: 0000000000000000 0000000000100010 00000000f5000000 0000000000000000 [ 769.098629][ T7903] page dumped because: kasan: bad access detected [ 769.098764][ T7903] [ 769.098803][ T7903] Memory state around the buggy address: [ 769.098879][ T7903] ff11000015199600: fc fc fc fc fc fc fc fc 00 00 00 00 03 fc fc fc [ 769.099032][ T7903] ff11000015199680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 769.099144][ T7903] >ff11000015199700: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 769.099255][ T7903] ^ [ 769.099390][ T7903] ff11000015199780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [ 769.099502][ T7903] ff11000015199800: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb [ 769.099614][ T7903] ================================================================== [ 769.099847][ T7903] Disabling lock debugging due to kernel taint [ 769.236629][ T8583] br2: port 1(lag2.200) entered disabled state [ 769.257613][ T8585] br1: port 1(lag2.100) entered disabled state [ 769.306773][ T8588] lag2.200: left allmulticast mode [ 769.306920][ T8588] lag2.200: left promiscuous mode [ 769.307178][ T8588] br2: port 1(lag2.200) entered disabled state [ 769.350561][ T8590] lag2.100: left allmulticast mode [ 769.350663][ T8590] lag2: left allmulticast mode [ 769.350752][ T8590] veth1: left allmulticast mode [ 769.350839][ T8590] veth7: left allmulticast mode [ 769.350985][ T8590] lag2.100: left promiscuous mode [ 769.351066][ T8590] lag2: left promiscuous mode [ 769.351152][ T8590] veth1: left promiscuous mode [ 769.351329][ T8590] veth7: left promiscuous mode [ 769.351670][ T8590] br1: port 1(lag2.100) entered disabled state [ 769.456174][ T8594] lag2: Port device veth7 removed [ 769.467982][ T8595] lag2: Port device veth1 removed [ 769.829457][ T8610] lag4: Port device veth5 removed [ 769.845955][ T8611] lag4: Port device veth3 removed [ 770.213599][ T8626] lag1: Port device veth6 removed [ 770.231079][ T8627] lag1: Port device veth0 removed