UBSan: Undefined Behavior in compat_20_sys_fstatfs

0 views
Skip to first unread message

syzbot

unread,
Jun 27, 2020, 1:36:14 AM6/27/20
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 5f8d4fbd Adjust prior to enforce minimum socket length inc..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=101495f9100000
kernel config: https://syzkaller.appspot.com/x/.config?x=1420f906d33d9f1f
dashboard link: https://syzkaller.appspot.com/bug?extid=61ec052df7a14953038a
compiler: g++ (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=154edf4d100000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16e305c5100000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+61ec05...@syzkaller.appspotmail.com

login: [ 33.6541798] panic: UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/compat/sys/mount.h:104:14, member access within null pointer of type 'struct statfs12'

[ 33.6739012] cpu0: Begin traceback...
[ 33.6841653] vpanic() at netbsd:vpanic+0x287 sys/kern/subr_prf.c:290
[ 33.7141659] isAlreadyReported() at netbsd:isAlreadyReported
[ 33.7441639] HandleTypeMismatch.part.1() at netbsd:HandleTypeMismatch.part.1+0x14e
[ 33.7741663] HandleTypeMismatch() at netbsd:HandleTypeMismatch+0x63 sys/../common/lib/libc/misc/ubsan.c:434
[ 33.7941649] compat_20_sys_fstatfs() at netbsd:compat_20_sys_fstatfs+0xcbe statvfs_to_statfs12 sys/compat/sys/mount.h:104 [inline]
[ 33.7941649] compat_20_sys_fstatfs() at netbsd:compat_20_sys_fstatfs+0xcbe statvfs_to_statfs12_copy sys/compat/sys/mount.h:143 [inline]
[ 33.7941649] compat_20_sys_fstatfs() at netbsd:compat_20_sys_fstatfs+0xcbe sys/compat/common/vfs_syscalls_20.c:135
[ 33.8241642] sys_syscall() at netbsd:sys_syscall+0x1b5 sy_call sys/sys/syscallvar.h:65 [inline]
[ 33.8241642] sys_syscall() at netbsd:sys_syscall+0x1b5 sys/kern/sys_syscall.c:77
[ 33.8541652] syscall() at netbsd:syscall+0x287 sy_call sys/sys/syscallvar.h:65 [inline]
[ 33.8541652] syscall() at netbsd:syscall+0x287 sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 33.8541652] syscall() at netbsd:syscall+0x287 sys/arch/x86/x86/syscall.c:138
[ 33.8641633] --- syscall (number 0) ---
[ 33.8741627] netbsd:syscall+0x287:
[ 33.8741627] cpu0: End traceback...
[ 33.8871636] fatal breakpoint trap in supervisor mode
[ 33.8871636] trap type 1 code 0 rip 0xffffffff80221aa5 cs 0x8 rflags 0x246 cr2 0x767811182eb7 ilevel 0 rsp 0xffffa100bf303910
[ 33.9032821] curlwp 0xffffe7be593c8600 pid 1250.1250 lowest kstack 0xffffa100bf3002c0
Stopped in pid 1250.1250 (syz-executor4800) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xd1 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x287 sys/kern/subr_prf.c:290
isAlreadyReported() at netbsd:isAlreadyReported
HandleTypeMismatch.part.1() at netbsd:HandleTypeMismatch.part.1+0x14e
HandleTypeMismatch() at netbsd:HandleTypeMismatch+0x63 sys/../common/lib/libc/misc/ubsan.c:434
compat_20_sys_fstatfs() at netbsd:compat_20_sys_fstatfs+0xcbe statvfs_to_statfs12 sys/compat/sys/mount.h:104 [inline]
compat_20_sys_fstatfs() at netbsd:compat_20_sys_fstatfs+0xcbe statvfs_to_statfs12_copy sys/compat/sys/mount.h:143 [inline]
compat_20_sys_fstatfs() at netbsd:compat_20_sys_fstatfs+0xcbe sys/compat/common/vfs_syscalls_20.c:135
sys_syscall() at netbsd:sys_syscall+0x1b5 sy_call sys/sys/syscallvar.h:65 [inline]
sys_syscall() at netbsd:sys_syscall+0x1b5 sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x287 sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x287 sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x287 sys/arch/x86/x86/syscall.c:138
--- syscall (number 0) ---
netbsd:syscall+0x287:
Panic string: UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/compat/sys/mount.h:104:14, member access within null pointer of type 'struct statfs12'

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
419 419 2 0 0 ffffe7be59701640 syz-executor4800
993 993 2 0 0 ffffe7be59701200 syz-executor4800
1076 1076 2 0 0 ffffe7be56663980 syz-executor4800
1081 1081 2 0 0 ffffe7be593c8a40 syz-executor4800
1095 >1095 7 1 0 ffffe7be5641dac0 syz-executor4800
980 980 2 0 0 ffffe7be56663540 syz-executor4800
1250 >1250 7 0 0 ffffe7be593c8600 syz-executor4800
1070 1070 2 1 40 ffffe7be5641d240 syz-executor4800
1065 1065 2 0 40 ffffe7be562c1a80 syz-executor4800
1068 1068 2 1 40 ffffe7be58725180 syz-executor4800
1255 1255 2 1 40 ffffe7be587255c0 syz-executor4800
1067 1067 3 0 80 ffffe7be593c81c0 syz-executor4800 nanoslp
1064 1064 3 1 80 ffffe7be58725a00 sshd select
695 695 3 0 80 ffffe7be5825c580 getty nanoslp
1089 1089 3 1 80 ffffe7be562c1640 getty nanoslp
853 853 3 0 80 ffffe7be560735c0 getty nanoslp
1103 1103 3 0 c0 ffffe7be562c1200 getty ttyraw
946 946 3 1 80 ffffe7be5825c9c0 sshd select
977 977 3 1 80 ffffe7be5825c140 powerd kqueue
732 732 3 0 80 ffffe7be579f98c0 syslogd kqueue
589 589 3 1 80 ffffe7be5641d680 dhcpcd poll
587 587 3 1 80 ffffe7be574c4780 dhcpcd poll
585 585 3 1 80 ffffe7be56802b00 dhcpcd poll
551 551 3 1 80 ffffe7be574c4340 dhcpcd poll
347 347 3 0 80 ffffe7be567522c0 dhcpcd poll
346 346 3 0 80 ffffe7be56752700 dhcpcd poll
345 345 3 1 80 ffffe7be569aeb80 dhcpcd poll
1 1 3 0 80 ffffe7be4def24c0 init wait
0 816 3 0 200 ffffe7be56073a00 physiod physiod
0 166 2 0 240 ffffe7be560fba40 ioflush
0 165 3 0 200 ffffe7be560fb600 pooldrain pooldrain
0 164 3 1 200 ffffe7be560fb1c0 pgdaemon pgdaemon
0 161 3 1 200 ffffe7be56073180 usb7 usbevt
0 31 3 0 200 ffffe7be52ff49c0 usb6 usbevt
0 63 3 1 200 ffffe7be52ff4580 usb5 usbevt
0 126 3 1 200 ffffe7be52ff4140 usb4 usbevt
0 125 3 1 200 ffffe7be4ff5d980 usb3 usbevt
0 124 3 1 200 ffffe7be4ff5d540 usb2 usbevt
0 123 3 1 200 ffffe7be4ff5d100 usb1 usbevt
0 122 3 1 200 ffffe7be4ef56940 usb0 usbevt
0 121 3 1 200 ffffe7be4ef56500 usbtask-dr usbtsk
0 120 3 1 200 ffffe7be4ef560c0 usbtask-hc usbtsk
0 119 3 0 200 ffffe7be4def2900 npfgc0 npfgcw
0 118 3 1 200 ffffe7be4def2080 rt_free rt_free
0 117 3 1 200 ffffe7be4deb68c0 unpgc unpgc
0 116 3 1 200 ffffe7be4deb6480 key_timehandler key_timehandler
0 115 3 1 200 ffffe7be4de212c0 icmp6_wqinput/1 icmp6_wqinput
0 114 3 0 200 ffffe7be4de21b40 icmp6_wqinput/0 icmp6_wqinput
0 113 3 0 200 ffffe7be4b324ac0 nd6_timer nd6_timer
0 112 3 1 200 ffffe7be4deb6040 carp6_wqinput/1 carp6_wqinput
0 111 3 0 200 ffffe7be4de97bc0 carp6_wqinput/0 carp6_wqinput
0 110 3 1 200 ffffe7be4de97780 carp_wqinput/1 carp_wqinput
0 109 3 0 200 ffffe7be4de97340 carp_wqinput/0 carp_wqinput
0 108 3 1 200 ffffe7be4de40b80 icmp_wqinput/1 icmp_wqinput
0 107 3 0 200 ffffe7be4de40300 icmp_wqinput/0 icmp_wqinput
0 106 3 0 200 ffffe7be4de21700 rt_timer rt_timer
0 105 3 1 200 ffffe7be4de40740 vmem_rehash vmem_rehash
0 104 3 0 200 ffffe7be4d7a6b00 entbutler entropy
0 30 3 1 200 ffffe7be4d7a66c0 vioif0_txrx/1 vioif0_txrx
0 29 3 0 200 ffffe7be4d7a6280 vioif0_txrx/0 vioif0_txrx
0 27 3 0 200 ffffe7be4b324680 scsibus0 sccomp
0 26 3 0 200 ffffe7be4b324240 pms0 pmsreset
0 25 3 1 200 ffffe7be4b297a80 xcall/1 xcall
0 24 1 1 200 ffffe7be4b297640 softser/1
0 23 1 1 200 ffffe7be4b297200 softclk/1
0 22 1 1 200 ffffe7be4b267a40 softbio/1
0 21 1 1 200 ffffe7be4b267600 softnet/1
0 20 1 1 201 ffffe7be4b2671c0 idle/1
0 19 3 0 200 ffffe7bf5b180a00 lnxpwrwq lnxpwrwq
0 18 3 0 200 ffffe7bf5b1805c0 lnxlngwq lnxlngwq
0 17 3 0 200 ffffe7bf5b180180 lnxsyswq lnxsyswq
0 16 3 0 200 ffffe7bf5b1a79c0 lnxrcugc lnxrcugc
0 15 3 0 200 ffffe7bf5b1a7580 sysmon smtaskq
0 14 3 0 200 ffffe7bf5b1a7140 pmfsuspend pmfsuspend
0 13 3 0 200 ffffe7bf5b1ac980 pmfevent pmfevent
0 12 3 0 200 ffffe7bf5b1ac540 sopendfree sopendfr
0 11 3 0 200 ffffe7bf5b1ac100 iflnkst iflnkst
0 10 3 0 200 ffffe7bf5c1df940 nfssilly nfssilly
0 9 3 0 200 ffffe7bf5c1df500 vdrain vdrain
0 8 3 0 200 ffffe7bf5c1df0c0 modunload mod_unld
0 7 3 0 200 ffffe7bf5c20a900 xcall/0 xcall
0 6 1 0 200 ffffe7bf5c20a4c0 softser/0
0 5 1 0 200 ffffe7bf5c20a080 softclk/0
0 4 1 0 200 ffffe7bf5c23b8c0 softbio/0
0 3 1 0 200 ffffe7bf5c23b480 softnet/0
0 2 1 0 201 ffffe7bf5c23b040 idle/0
0 0 2 0 240 ffffffff85ae88c0 swapper
[Locks tracked through LWPs]

****** LWP 1081.1081 (syz-executor4800) @ 0xffffe7be593c8a40, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at pmap_ctor)
lock address : 0xffffe7be4dec5980 type : sleep/adaptive
initialized : 0xffffffff80ef3330
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 0
relevant lwp : 0xffffe7be593c8a40 last held: 000000000000000000
last locked : 0xffffffff80ef5713 unlocked*: 0xffffffff80ef5cf0
owner field : 0xffffe7be593c8a40 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 1095.1095 (syz-executor4800) @ 0xffffe7be5641dac0, l_stat=7

*** Locks held:

* Lock 0 (initialized at pmap_ctor)
lock address : 0xffffe7be567d6380 type : sleep/adaptive
initialized : 0xffffffff80ef3330
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffe7be5641dac0 last held: 0xffffe7be5641dac0
last locked* : 0xffffffff80ef5713 unlocked : 0xffffffff80ef3086
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 587.587 (dhcpcd) @ 0xffffe7be574c4780, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffe7be574c4780 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 585.585 (dhcpcd) @ 0xffffe7be56802b00, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffe7be56802b00 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 346.346 (dhcpcd) @ 0xffffe7be56752700, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffe7be56752700 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 345.345 (dhcpcd) @ 0xffffe7be569aeb80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffe7be569aeb80 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.23 (softclk/1) @ 0xffffe7be4b297200, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffe7be4b297200 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffffe7bf5b1ac100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffe7bf5b1ac100 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffffa10000006180 0045 00000000 0x0 0x0
0xffffa10000006200 0045 00000000 0x0 0x0
0xffffa10000006280 0045 00000000 0x0 0x0
0xffffa10000006300 0045 00000000 0x0 0x0
0xffffa10000006380 0045 00000000 0x0 0x0
0xffffa10000006400 0045 00000000 0x0 0x0
0xffffa10000006480 0045 00000000 0x0 0x0
0xffffa10000006500 0045 00000000 0x0 0x0
0xffffa10000006580 0041 00000000 0x0 0x0
0xffffa10000006600 0041 00000000 0x0 0x0
0xffffa10000006680 0041 00000000 0x0 0x0
0xffffa10000006700 0041 00000000 0x0 0x0
0xffffa10000006780 0041 00000000 0x0 0x0
0xffffa10000006800 0041 00000000 0x0 0x0
0xffffa10000006880 0041 00000000 0x0 0x0
0xffffa10000006900 0041 00000000 0x0 0x0
0xffffa10000006980 0041 00000000 0x0 0x0
0xffffa10000006a00 0041 00000000 0x0 0x0
0xffffa10000006a80 0041 00000000 0x0 0x0
0xffffa10000006b00 0041 00000000 0x0 0x0
0xffffa10000006b80 0041 00000000 0x0 0x0
0xffffa10000006c00 0041 00000000 0x0 0x0
0xffffa10000006c80 0041 00000000 0x0 0x0
0xffffa10000006d00 0041 00000000 0x0 0x0
0xffffa10000006d80 0041 00000000 0x0 0x0
0xffffa10000006e00 0041 00000000 0x0 0x0
0xffffa10000006e80 0041 00000000 0x0 0x0
0xffffa10000006f00 0041 00000000 0x0 0x0
0xffffa10000006f80 0041 00000000 0x0 0x0
0xffffa10000007000 0041 00000000 0x0 0x0
0xffffa10000007080 0041 00000000 0x0 0x0
0xffffa10000007100 0041 00000000 0x0 0x0
0xffffa10000007180 0041 00000000 0x0 0x0
0xffffa10000007200 0045 00000000 0x0 0x0
0xffffa10000007280 0041 00000000 0x0 0x0
0xffffa10000007300 0041 00000000 0x0 0x0
0xffffa10000007380 0041 00000000 0x0 0x0
0xffffa10000007400 0041 00000000 0x0 0x0
0xffffa10000007480 0041 00000000 0x0 0x0
0xffffa10000007500 0041 00000000 0x0 0x0
0xffffa10000007580 0041 00000000 0x0 0x0
0xffffa10000007600 0041 00000000 0x0 0x0
0xffffa10000007680 0041 00000000 0x0 0x0
0xffffa10000007700 0045 00000000 0x0 0x0
0xffffa10000007780 0045 00000000 0x0 0x0
0xffffa10000007800 0041 00000000 0x0 0x0
0xffffa10000007880 0041 00000000 0x0 0x0
0xffffa10000007900 0041 00000000 0x0 0x0
0xffffa10000007980 0041 00000000 0x0 0x0
0xffffa10000007a00 0041 00000000 0x0 0x0
0xffffa10000007a80 0041 00000000 0x0 0x0
0xffffa10000007b00 0041 00000000 0x0 0x0
0xffffa10000007b80 0041 00000000 0x0 0x0
0xffffa10000007c00 0041 00000000 0x0 0x0
0xffffa10000007c80 0041 00000000 0x0 0x0
0xffffa10000007d00 0041 00000000 0x0 0x0
0xffffa10000007d80 0041 00000000 0x0 0x0
0xffffa10000007e00 0041 00000000 0x0 0x0
0xffffa10000007e80 0041 00000000 0x0 0x0
0xffffa10000007f00 0041 00000000 0x0 0x0
0xffffa10000007f80 0041 00000000 0x0 0x0
0xffffa10000008000 0041 00000000 0x0 0x0
0xffffa10000008080 0041 00000000 0x0 0x0
0xffffa10000008100 0041 00000000 0x0 0x0
0xffffa10000008180 0041 00000000 0x0 0x0
0xffffa10000008200 0041 00000000 0x0 0x0
0xffffa10000008280 0041 00000000 0x0 0x0
0xffffa10000008300 0041 00000000 0x0 0x0
0xffffa10000008380 0041 00000000 0x0 0x0
0xffffa10000008400 0041 00000000 0x0 0x0
0xffffa10000008480 0041 00000000 0x0 0x0
0xffffa10000008500 0041 00000000 0x0 0x0
0xffffa10000008580 0041 00000000 0x0 0x0
0xffffa10000008600 0041 00000000 0x0 0x0
0xffffa10000008680 0041 00000000 0x0 0x0
0xffffa10000008700 0041 00000000 0x0 0x0
0xffffa10000008780 0041 00000000 0x0 0x0
0xffffa10000008800 0041 00000000 0x0 0x0
0xffffa10000008880 0041 00000000 0x0 0x0
0xffffa10000008900 0041 00000000 0x0 0x0
0xffffa10000008980 0041 00000000 0x0 0x0
0xffffa10000008a00 0041 00000000 0x0 0x0
0xffffa10000008a80 0041 00000000 0x0 0x0
0xffffa10000008b00 0041 00000000 0x0 0x0
0xffffa10000008b80 0041 00000000 0x0 0x0
0xffffa10000008c00 0041 00000000 0x0 0x0
0xffffa10000008c80 0045 00000000 0x0 0x0
0xffffa10000008d00 0041 00000000 0x0 0x0
0xffffa10000008d80 0041 00000000 0x0 0x0
0xffffa10000008e00 0041 00000000 0x0 0x0
0xffffa10000008e80 0041 00000000 0x0 0x0
0xffffa10000008f00 0045 00000000 0x0 0x0
0xffffa10000008f80 0041 00000000 0x0 0x0
0xffffa10000009000 0041 00000000 0x0 0x0
0xffffa10000009080 0041 00000000 0x0 0x0
0xffffa10000009100 0041 00000000 0x0 0x0
0xffffa10000009180 0041 00000000 0x0 0x0
0xffffa10000009200 0041 00000000 0x0 0x0
0xffffa10000009280 0041 00000000 0x0 0x0
0xffffa10000009300 0041 00000000 0x0 0x0
0xffffa10000009380 0041 00000000 0x0 0x0
0xffffa10000009400 0041 00000000 0x0 0x0
0xffffa10000009480 0041 00000000 0x0 0x0
0xffffa10000009500 0041 00000000 0x0 0x0
0xffffa10000009580 0041 00000000 0x0 0x0
0xffffa10000009600 0041 00000000 0x0 0x0
0xffffa10000009680 0041 00000000 0x0 0x0
0xffffa10000009700 0041 00000000 0x0 0x0
0xffffa10000009780 0041 00000000 0x0 0x0
0xffffa10000009800 0041 00000000 0x0 0x0
0xffffa10000009880 0041 00000000 0x0 0x0
0xffffa10000009900 0041 00000000 0x0 0x0
0xffffa10000009980 0041 00000000 0x0 0x0
0xffffa10000009a00 0041 00000000 0x0 0x0
0xffffa10000009a80 0041 00000000 0x0 0x0
0xffffa10000009b00 0041 00000000 0x0 0x0
0xffffa10000009b80 0041 00000000 0x0 0x0
0xffffa10000009c00 0041 00000000 0x0 0x0
0xffffa10000009c80 0041 00000000 0x0 0x0
0xffffa10000009d00 0041 00000000 0x0 0x0
0xffffa10000009d80 0045 00000000 0x0 0x0
0xffffa10000009e00 0045 00000000 0x0 0x0
0xffffa10000009e80 0045 00000000 0x0 0x0
0xffffa10000009f00 0041 00000000 0x0 0x0
0xffffa10000009f80 0041 00000000 0x0 0x0
0xffffa1000000a000 0041 00000000 0x0 0x0
0xffffa1000000a080 0041 00000000 0x0 0x0
0xffffa1000000a100 0045 00000000 0x0 0x0
0xffffa1000000a180 0045 00000000 0x0 0x0
0xffffa1000000a200 0045 00000000 0x0 0x0
0xffffa1000000a280 0045 00000000 0x0 0x0
0xffffa1000000a300 0041 00000000 0x0 0x0
0xffffa1000000a380 0041 00000000 0x0 0x0
0xffffa1000000a400 0045 00000000 0x0 0x0
0xffffa1000000a480 0041 00000000 0x0 0x0
0xffffa1000000a500 0045 00000000 0x0 0x0
0xffffa1000000a580 0045 00000000 0x0 0x0
0xffffa1000000a600 0045 00000000 0x0 0x0
0xffffa1000000a680 0045 00000000 0x0 0x0
0xffffa1000000a700 0045 00000000 0x0 0x0
0xffffa1000000a780 0045 00000000 0x0 0x0
0xffffa1000000a800 0045 00000000 0x0 0x0
0xffffa1000000a880 0041 00000000 0x0 0x0
0xffffa1000000a900 0045 00000000 0x0 0x0
0xffffa1000000a980 0045 00000000 0x0 0x0
0xffffa1000000aa00 0045 00000000 0x0 0x0
0xffffa1000000aa80 0045 00000000 0x0 0x0
0xffffa1000000ab00 0045 00000000 0x0 0x0
0xffffa1000000ab80 0045 00000000 0x0 0x0
0xffffa1000000ac00 0045 00000000 0x0 0x0
0xffffa1000000ac80 0045 00000000 0x0 0x0
0xffffa1000000ad00 0045 00000000 0x0 0x0
0xffffa1000000ad80 0041 00000000 0x0 0x0
0xffffa1000000ae00 0041 00000000 0x0 0x0
0xffffa1000000ae80 0041 00000000 0x0 0x0
0xffffa1000000af00 0045 00000000 0x0 0x0
0xffffa1000000af80 0045 00000000 0x0 0x0
0xffffa1000000b000 0045 00000000 0x0 0x0
0xffffa1000000b080 0045 00000000 0x0 0x0
0xffffa1000000b100 0045 00000000 0x0 0x0
0xffffa1000000b180 0041 00000000 0x0 0x0
0xffffa1000000b200 0041 00000000 0x0 0x0
0xffffa1000000b280 0041 00000000 0x0 0x0
0xffffa1000000b300 0045 00000000 0x0 0x0
0xffffa1000000b380 0045 00000000 0x0 0x0
0xffffa1000000b400 0045 00000000 0x0 0x0
0xffffa1000000b480 0045 00000000 0x0 0x0
0xffffa1000000b500 0041 00000000 0x0 0x0
0xffffa1000000b580 0041 00000000 0x0 0x0
0xffffa1000000b600 0041 00000000 0x0 0x0
0xffffa1000000b680 0041 00000000 0x0 0x0
0xffffa1000000b700 0041 00000000 0x0 0x0
0xffffa1000000b780 0041 00000000 0x0 0x0
0xffffa1000000b800 0041 00000000 0x0 0x0
0xffffa1000000b880 0045 00000000 0x0 0x0
0xffffa1000000b900 0041 00000000 0x0 0x0
0xffffa1000000b980 0041 00000000 0x0 0x0
0xffffa1000000ba00 0041 00000000 0x0 0x0
0xffffa1000000ba80 0045 00000000 0x0 0x0
0xffffa1000000bb00 0041 00000000 0x0 0x0
0xffffa1000000bb80 0041 00000000 0x0 0x0
0xffffa1000000bc00 0041 00000000 0x0 0x0
0xffffa1000000bc80 0045 00000000 0x0 0x0
0xffffa1000000bd00 0041 00000000 0x0 0x0
0xffffa1000000bd80 0041 00000000 0x0 0x0
0xffffa1000000be00 0041 00000000 0x0 0x0
0xffffa1000000be80 0041 00000000 0x0 0x0
0xffffa1000000bf00 0041 00000000 0x0 0x0
0xffffa1000000bf80 0041 00000000 0x0 0x0
0xffffa1000000c000 0041 00000000 0x0 0x0
0xffffa1000000c080 0041 00000000 0x0 0x0
0xffffa1000000c100 0041 00000000 0x0 0x0
0xffffa1000000c180 0045 00000000 0x0 0x0
0xffffa1000000c200 0045 00000000 0x0 0x0
0xffffa1000000c280 0041 00000000 0x0 0x0
0xffffa1000000c300 0045 00000000 0x0 0x0
0xffffa1000000c380 0041 00000000 0x0 0x0
0xffffa1000000c400 0041 00000000 0x0 0x0
0xffffa1000000c480 0041 00000000 0x0 0x0
0xffffa1000000c500 0041 00000000 0x0 0x0
0xffffa1000000c580 0045 00000000 0x0 0x0
0xffffa1000000c600 0041 00000000 0x0 0x0
0xffffa1000000c680 0045 00000000 0x0 0x0
0xffffa1000000c700 0041 00000000 0x0 0x0
0xffffa1000000c780 0041 00000000 0x0 0x0
0xffffa1000000c800 0045 00000000 0x0 0x0
0xffffa1000000c880 0041 00000000 0x0 0x0
0xffffa1000000c900 0045 00000000 0x0 0x0
0xffffa1000000c980 0041 00000000 0x0 0x0
0xffffa1000000ca00 0041 00000000 0x0 0x0
0xffffa1000000ca80 0041 00000000 0x0 0x0
0xffffa1000000cb00 0045 00000000 0x0 0x0
0xffffa1000000cb80 0045 00000000 0x0 0x0
0xffffa1000000cc00 0045 00000000 0x0 0x0
0xffffa1000000cc80 0041 00000000 0x0 0x0
0xffffa1000000cd00 0045 00000000 0x0 0x0
0xffffa1000000cd80 0041 00000000 0x0 0x0
0xffffa1000000ce00 0041 00000000 0x0 0x0
0xffffa1000000ce80 0045 00000000 0x0 0x0
0xffffa1000000cf00 0045 00000000 0x0 0x0
0xffffa1000000cf80 0045 00000000 0x0 0x0
0xffffa1000000d000 0045 00000000 0x0 0x0
0xffffa1000000d080 0045 00000000 0x0 0x0
0xffffa1000000d100 0041 00000000 0x0 0x0
0xffffa1000000d180 0041 00000000 0x0 0x0
0xffffa1000000d200 0041 00000000 0x0 0x0
0xffffa1000000d280 0041 00000000 0x0 0x0
0xffffa1000000d300 0045 00000000 0x0 0x0
0xffffa1000000d380 0045 00000000 0x0 0x0
0xffffa1000000d400 0041 00000000 0x0 0x0
0xffffa1000000d480 0045 00000000 0x0 0x0
0xffffa1000000d500 0041 00000000 0x0 0x0
0xffffa1000000d580 0045 00000000 0x0 0x0
0xffffa1000000d600 0041 00000000 0x0 0x0
0xffffa1000000d680 0041 00000000 0x0 0x0
0xffffa1000000d700 0041 00000000 0x0 0x0
0xffffa1000000d780 0041 00000000 0x0 0x0
0xffffa1000000d800 0045 00000000 0x0 0x0
0xffffa1000000d880 0041 00000000 0x0 0x0
0xffffa1000000d900 0041 00000000 0x0 0x0
0xffffa1000000d980 0041 00000000 0x0 0x0
0xffffa1000000da00 0041 00000000 0x0 0x0
0xffffa1000000da80 0041 00000000 0x0 0x0
0xffffa1000000db00 0041 00000000 0x0 0x0
0xffffa1000000db80 0045 00000000 0x0 0x0
0xffffa1000000dc00 0041 00000000 0x0 0x0
0xffffa1000000dc80 0045 00000000 0x0 0x0
0xffffa1000000dd00 0045 00000000 0x0 0x0
0xffffa1000000dd80 0041 00000000 0x0 0x0
0xffffa1000000de00 0045 00000000 0x0 0x0
0xffffa1000000de80 0041 00000000 0x0 0x0
0xffffa1000000df00 0041 00000000 0x0 0x0
0xffffa1000000df80 0041 00000000 0x0 0x0
0xffffa1000000e000 0041 00000000 0x0 0x0
0xffffa1000000e080 0041 00000000 0x0 0x0
0xffffa1000000e100 0041 00000000 0x0 0x0
0xffffa1000000e180 0041 00000000 0x0 0x0
0xffffa1000000e200 0041 00000000 0x0 0x0
0xffffa1000000e280 0041 00000000 0x0 0x0
0xffffa1000000e300 0041 00000000 0x0 0x0
0xffffa1000000e380 0041 00000000 0x0 0x0
0xffffa1000000e400 0041 00000000 0x0 0x0
0xffffa1000000e480 0041 00000000 0x0 0x0
0xffffa1000000e500 0041 00000000 0x0 0x0
0xffffa1000000e580 0041 00000000 0x0 0x0
0xffffa1000000e600 0041 00000000 0x0 0x0
0xffffa1000000e680 0041 00000000 0x0 0x0
0xffffa1000000e700 0041 00000000 0x0 0x0
0xffffa1000000e780 0041 00000000 0x0 0x0
0xffffa1000000e800 0041 00000000 0x0 0x0
0xffffa1000000e880 0041 00000000 0x0 0x0
0xffffa1000000e900 0041 00000000 0x0 0x0
0xffffa1000000e980 0041 00000000 0x0 0x0
0xffffa1000000ea00 0041 00000000 0x0 0x0
0xffffa1000000ea80 0041 00000000 0x0 0x0
0xffffa1000000eb00 0041 00000000 0x0 0x0
0xffffa1000000eb80 0041 00000000 0x0 0x0
0xffffa1000000ec00 0041 00000000 0x0 0x0
0xffffa1000000ec80 0041 00000000 0x0 0x0
0xffffa1000000ed00 0041 00000000 0x0 0x0
0xffffa1000000ed80 0041 00000000 0x0 0x0
0xffffa1000000ee00 0041 00000000 0x0 0x0
0xffffa1000000ee80 0045 00000000 0x0 0x0
0xffffa1000000ef00 0041 00000000 0x0 0x0
0xffffa1000000ef80 0041 00000000 0x0 0x0
0xffffa1000000f000 0041 00000000 0x0 0x0
0xffffa1000000f080 0041 00000000 0x0 0x0
0xffffa1000000f100 0045 00000000 0x0 0x0
0xffffa1000000f180 0041 00000000 0x0 0x0
0xffffa1000000f200 0041 00000000 0x0 0x0
0xffffa1000000f280 0041 00000000 0x0 0x0
0xffffa1000000f300 0041 00000000 0x0 0x0
0xffffa1000000f380 0041 00000000 0x0 0x0
0xffffa1000000f400 0041 00000000 0x0 0x0
0xffffa1000000f480 0045 00000000 0x0 0x0
0xffffa1000000f500 0041 00000000 0x0 0x0
0xffffa1000000f580 0041 00000000 0x0 0x0
0xffffa1000000f600 0041 00000000 0x0 0x0
0xffffa1000000f680 0041 00000000 0x0 0x0
0xffffa1000000f700 0041 00000000 0x0 0x0
0xffffa1000000f780 0041 00000000 0x0 0x0
0xffffa1000000f800 0045 00000000 0x0 0x0
0xffffa1000000f880 0041 00000000 0x0 0x0
0xffffa1000000f900 0041 00000000 0x0 0x0
0xffffa1000000f980 0041 00000000 0x0 0x0
0xffffa1000000fa00 0041 00000000 0x0 0x0
0xffffa1000000fa80 0041 00000000 0x0 0x0
0xffffa1000000fb00 0045 00000000 0x0 0x0
0xffffa1000000fb80 0041 00000000 0x0 0x0
0xffffa1000000fc00 0041 00000000 0x0 0x0
0xffffa1000000fc80 0041 00000000 0x0 0x0
0xffffa1000000fd00 0041 00000000 0x0 0x0
0xffffa1000000fd80 0041 00000000 0x0 0x0
0xffffa1000000fe00 0041 00000000 0x0 0x0
0xffffa1000000fe80 0041 00000000 0x0 0x0
0xffffa1000000ff00 0041 00000000 0x0 0x0
0xffffa1000000ff80 0045 00000000 0x0 0x0
0xffffa10000010000 0041 00000000 0x0 0x0
0xffffa10000010080 0045 00000000 0x0 0x0
0xffffa10000010100 0001 00000000 0x0 0x0
0xffffa10000010180 0001 00000000 0x0 0x0
0xffffa10000010200 0001 00000000 0x0 0x0
0xffffa10000010280 0001 00000000 0x0 0x0
0xffffa10000010300 0001 00000000 0x0 0x0
0xffffa10000010380 0001 00000000 0x0 0x0
0xffffa10000010400 0001 00000000 0x0 0x0
0xffffa10000010480 0001 00000000 0x0 0x0
0xffffa10000010500 0001 00000000 0x0 0x0
0xffffa10000010580 0001 00000000 0x0 0x0
0xffffa10000010600 0001 00000000 0x0 0x0
0xffffa10000010680 0001 00000000 0x0 0x0
0xffffa10000010700 0001 00000000 0x0 0x0
0xffffa10000010780 0001 00000000 0x0 0x0
0xffffa10000010800 0001 00000000 0x0 0x0
0xffffa10000010880 0001 00000000 0x0 0x0
0xffffa10000010900 0001 00000000 0x0 0x0
0xffffa10000010980 0001 00000000 0x0 0x0
0xffffa10000010a00 0001 00000000 0x0 0x0
0xffffa10000010a80 0001 00000000 0x0 0x0
0xffffa10000010b00 0001 00000000 0x0 0x0
0xffffa10000010b80 0001 00000000 0x0 0x0
0xffffa10000010c00 0001 00000000 0x0 0x0
0xffffa10000010c80 0001 00000000 0x0 0x0
0xffffa10000010d00 0001 00000000 0x0 0x0
0xffffa10000010d80 0001 00000000 0x0 0x0
0xffffa10000010e00 0001 00000000 0x0 0x0
0xffffa10000010e80 0001 00000000 0x0 0x0
0xffffa10000010f00 0001 00000000 0x0 0x0
0xffffa10000010f80 0001 00000000 0x0 0x0
0xffffa10000011000 0001 00000000 0x0 0x0
0xffffa10000011080 0001 00000000 0x0 0x0
0xffffa10000011100 0001 00000000 0x0 0x0
0xffffa10000011180 0001 00000000 0x0 0x0
0xffffa10000011200 0001 00000000 0x0 0x0
0xffffa10000011280 0001 00000000 0x0 0x0
0xffffa10000011300 0001 00000000 0x0 0x0
0xffffa10000011380 0001 00000000 0x0 0x0
0xffffa10000011400 0001 00000000 0x0 0x0
0xffffa10000011480 0001 00000000 0x0 0x0
0xffffa10000011500 0001 00000000 0x0 0x0
0xffffa10000011580 0001 00000000 0x0 0x0
0xffffa10000011600 0001 00000000 0x0 0x0
0xffffa10000011680 0001 00000000 0x0 0x0
0xffffa10000011700 0001 00000000 0x0 0x0
0xffffa10000011780 0001 00000000 0x0 0x0
0xffffa10000011800 0001 00000000 0x0 0x0
0xffffa10000011880 0001 00000000 0x0 0x0
0xffffa10000011900 0001 00000000 0x0 0x0
0xffffa10000011980 0001 00000000 0x0 0x0
0xffffa10000011a00 0001 00000000 0x0 0x0
0xffffa10000011a80 0001 00000000 0x0 0x0
0xffffa10000011b00 0001 00000000 0x0 0x0
0xffffa10000011b80 0001 00000000 0x0 0x0
0xffffa10000011c00 0041 00000000 0x0 0x0
0xffffa10000011c80 0041 00000000 0x0 0x0
0xffffa10000011d00 0041 00000000 0x0 0x0
0xffffa10000011d80 0041 00000000 0x0 0x0
0xffffa10000011e00 0041 00000000 0x0 0x0
0xffffa10000011e80 0041 00000000 0x0 0x0
0xffffa10000011f00 0041 00000000 0x0 0x0
0xffffa10000011f80 0041 00000000 0x0 0x0
0xffffa10000012000 0041 00000000 0x0 0x0
0xffffa10000012080 0041 00000000 0x0 0x0
0xffffa10000012100 0041 00000000 0x0 0x0
0xffffa10000012180 0041 00000000 0x0 0x0
0xffffa10000012200 0041 00000000 0x0 0x0
0xffffa10000012280 0041 00000000 0x0 0x0
0xffffa10000012300 0041 00000000 0x0 0x0
0xffffa10000012380 0041 00000000 0x0 0x0
0xffffa10000012400 0041 00000000 0x0 0x0
0xffffa10000012480 0041 00000000 0x0 0x0
0xffffa10000012500 0041 00000000 0x0 0x0
0xffffa10000012580 0041 00000000 0x0 0x0
0xffffa10000012600 0041 00000000 0x0 0x0
0xffffa10000012680 0041 00000000 0x0 0x0
0xffffa10000012700 0041 00000000 0x0 0x0
0xffffa10000012780 0041 00000000 0x0 0x0
0xffffa10000012800 0041 00000000 0x0 0x0
0xffffa10000012880 0041 00000000 0x0 0x0
0xffffa10000012900 0041 00000000 0x0 0x0
0xffffa10000012980 0041 00000000 0x0 0x0
0xffffa10000012a00 0041 00000000 0x0 0x0
0xffffa10000012a80 0041 00000000 0x0 0x0
0xffffa10000012b00 0041 00000000 0x0 0x0
0xffffa10000012b80 0041 00000000 0x0 0x0
0xffffa10000012c00 0041 00000000 0x0 0x0
0xffffa10000012c80 0041 00000000 0x0 0x0
0xffffa10000012d00 0041 00000000 0x0 0x0
0xffffa10000012d80 0041 00000000 0x0 0x0
0xffffa10000012e00 0041 00000000 0x0 0x0
0xffffa10000012e80 0041 00000000 0x0 0x0
0xffffa10000012f00 0041 00000000 0x0 0x0
0xffffa10000012f80 0041 00000000 0x0 0x0
0xffffa10000013000 0041 00000000 0x0 0x0
0xffffa10000013080 0041 00000000 0x0 0x0
0xffffa10000013100 0041 00000000 0x0 0x0
0xffffa10000013180 0041 00000000 0x0 0x0
0xffffa10000013200 0041 00000000 0x0 0x0
0xffffa10000013280 0041 00000000 0x0 0x0
0xffffa10000013300 0041 00000000 0x0 0x0
0xffffa10000013380 0041 00000000 0x0 0x0
0xffffa10000013400 0001 00000000 0x0 0x0
0xffffa10000013480 0001 00000000 0x0 0x0
0xffffa10000013500 0001 00000000 0x0 0x0
0xffffa10000013580 0001 00000000 0x0 0x0
0xffffa10000013600 0001 00000000 0x0 0x0
0xffffa10000013680 0001 00000000 0x0 0x0
0xffffa10000013700 0001 00000000 0x0 0x0
0xffffa10000013780 0001 00000000 0x0 0x0
0xffffa10000013800 0001 00000000 0x0 0x0
0xffffa10000013880 0001 00000000 0x0 0x0
0xffffa10000013900 0001 00000000 0x0 0x0
0xffffa10000013980 0001 00000000 0x0 0x0
0xffffa10000013a00 0001 00000000 0x0 0x0
0xffffa10000013a80 0001 00000000 0x0 0x0
0xffffa10000013b00 0001 00000000 0x0 0x0
0xffffa10000013b80 0001 00000000 0x0 0x0
0xffffa10000013c00 0001 00000000 0x0 0x0
0xffffa10000013c80 0001 00000000 0x0 0x0
0xffffa10000013d00 0001 00000000 0x0 0x0
0xffffa10000013d80 0001 00000000 0x0 0x0
0xffffa10000013e00 0001 00000000 0x0 0x0
0xffffa10000013e80 0001 00000000 0x0 0x0
0xffffa10000013f00 0001 00000000 0x0 0x0
0xffffa10000013f80 0001 00000000 0x0 0x0
0xffffa10000014000 0001 00000000 0x0 0x0
0xffffa10000014080 0001 00000000 0x0 0x0
0xffffa10000014100 0001 00000000 0x0 0x0
0xffffa10000014180 0001 00000000 0x0 0x0
0xffffa10000014200 0001 00000000 0x0 0x0
0xffffa10000014280 0001 00000000 0x0 0x0
0xffffa10000014300 0001 00000000 0x0 0x0
0xffffa10000014380 0001 00000000 0x0 0x0
0xffffa10000014400 0001 00000000 0x0 0x0
0xffffa10000014480 0001 00000000 0x0 0x0
0xffffa10000014500 0001 00000000 0x0 0x0
0xffffa10000014580 0001 00000000 0x0 0x0
0xffffa10000014600 0001 00000000 0x0 0x0
0xffffa10000014680 0001 00000000 0x0 0x0
0xffffa10000014700 0001 00000000 0x0 0x0
0xffffa10000014780 0001 00000000 0x0 0x0
0xffffa10000014800 0001 00000000 0x0 0x0
0xffffa10000014880 0001 00000000 0x0 0x0
0xffffa10000014900 0001 00000000 0x0 0x0
0xffffa10000014980 0001 00000000 0x0 0x0
0xffffa10000014a00 0001 00000000 0x0 0x0
0xffffa10000014a80 0001 00000000 0x0 0x0
0xffffa10000014b00 0001 00000000 0x0 0x0
0xffffa10000014b80 0001 00000000 0x0 0x0
0xffffa10000014c00 0001 00000000 0x0 0x0
0xffffa10000014c80 0001 00000000 0x0 0x0
0xffffa10000014d00 0001 00000000 0x0 0x0
0xffffa10000014d80 0001 00000000 0x0 0x0
0xffffa10000014e00 0001 00000000 0x0 0x0
0xffffa10000014e80 0001 00000000 0x0 0x0
0xffffa10000014f00 0041 00000000 0x0 0x0
0xffffa10000014f80 0041 00000000 0x0 0x0
0xffffa10000015000 0041 00000000 0x0 0x0
0xffffa10000015080 0041 00000000 0x0 0x0
0xffffa10000015100 0041 00000000 0x0 0x0
0xffffa10000015180 0041 00000000 0x0 0x0
0xffffa10000015200 0041 00000000 0x0 0x0
0xffffa10000015280 0041 00000000 0x0 0x0
0xffffa10000015300 0041 00000000 0x0 0x0
0xffffa10000015380 0041 00000000 0x0 0x0
0xffffa10000015400 0041 00000000 0x0 0x0
0xffffa10000015480 0041 00000000 0x0 0x0
0xffffa10000015500 0041 00000000 0x0 0x0
0xffffa10000015580 0041 00000000 0x0 0x0
0xffffa10000015600 0041 00000000 0x0 0x0
0xffffa10000015680 0041 00000000 0x0 0x0
0xffffa10000015700 0041 00000000 0x0 0x0
0xffffa10000015780 0041 00000000 0x0 0x0
0xffffa10000015800 0041 00000000 0x0 0x0
0xffffa10000015880 0041 00000000 0x0 0x0
0xffffa10000015900 0041 00000000 0x0 0x0
0xffffa10000015980 0041 00000000 0x0 0x0
0xffffa10000015a00 0041 00000000 0x0 0x0
0xffffa10000015a80 0041 00000000 0x0 0x0
0xffffa10000015b00 0041 00000000 0x0 0x0
0xffffa10000015b80 0041 00000000 0x0 0x0
0xffffa10000015c00 0041 00000000 0x0 0x0
0xffffa10000015c80 0041 00000000 0x0 0x0
0xffffa10000015d00 0041 00000000 0x0 0x0
0xffffa10000015d80 0041 00000000 0x0 0x0
0xffffa10000015e00 0041 00000000 0x0 0x0
0xffffa10000015e80 0041 00000000 0x0 0x0
0xffffa10000015f00 0041 00000000 0x0 0x0
0xffffa10000015f80 0041 00000000 0x0 0x0
0xffffa10000016000 0041 00000000 0x0 0x0
0xffffa10000016080 0041 00000000 0x0 0x0
0xffffa10000016100 0041 00000000 0x0 0x0
0xffffa10000016180 0041 00000000 0x0 0x0
0xffffa10000016200 0045 00000000 0x0 0x0
0xffffa10000016280 0041 00000000 0x0 0x0
0xffffa10000016300 0041 00000000 0x0 0x0
0xffffa10000016380 0041 00000000 0x0 0x0
0xffffa10000016400 0041 00000000 0x0 0x0
0xffffa10000016480 0041 00000000 0x0 0x0
0xffffa10000016500 0001 00000000 0x0 0x0
0xffffa10000016580 0001 00000000 0x0 0x0
0xffffa10000016600 0001 00000000 0x0 0x0
0xffffa10000016680 0001 00000000 0x0 0x0
0xffffa10000016700 0001 00000000 0x0 0x0
0xffffa10000016780 0001 00000000 0x0 0x0
0xffffa10000016800 0001 00000000 0x0 0x0
0xffffa10000016880 0001 00000000 0x0 0x0
0xffffa10000016900 0001 00000000 0x0 0x0
0xffffa10000016980 0001 00000000 0x0 0x0
0xffffa10000016a00 0001 00000000 0x0 0x0
0xffffa10000016a80 0001 00000000 0x0 0x0
0xffffa10000016b00 0001 00000000 0x0 0x0
0xffffa10000016b80 0001 00000000 0x0 0x0
0xffffa10000016c00 0001 00000000 0x0 0x0
0xffffa10000016c80 0001 00000000 0x0 0x0
0xffffa10000016d00 0001 00000000 0x0 0x0
0xffffa10000016d80 0001 00000000 0x0 0x0
0xffffa10000016e00 0001 00000000 0x0 0x0
0xffffa10000016e80 0001 00000000 0x0 0x0
0xffffa10000016f00 0001 00000000 0x0 0x0
0xffffa10000016f80 0001 00000000 0x0 0x0
0xffffa10000017000 0001 00000000 0x0 0x0
0xffffa10000017080 0001 00000000 0x0 0x0
0xffffa10000017100 0001 00000000 0x0 0x0
0xffffa10000017180 0001 00000000 0x0 0x0
0xffffa10000017200 0001 00000000 0x0 0x0
0xffffa10000017280 0001 00000000 0x0 0x0
0xffffa10000017300 0001 00000000 0x0 0x0
0xffffa10000017380 0001 00000000 0x0 0x0
0xffffa10000017400 0001 00000000 0x0 0x0
0xffffa10000017480 0001 00000000 0x0 0x0
0xffffa10000017500 0001 00000000 0x0 0x0
0xffffa10000017580 0001 00000000 0x0 0x0
0xffffa10000017600 0001 00000000 0x0 0x0
0xffffa10000017680 0001 00000000 0x0 0x0
0xffffa10000017700 0001 00000000 0x0 0x0
0xffffa10000017780 0001 00000000 0x0 0x0
0xffffa10000017800 0001 00000000 0x0 0x0
0xffffa10000017880 0001 00000000 0x0 0x0
0xffffa10000017900 0001 00000000 0x0 0x0
0xffffa10000017980 0001 00000000 0x0 0x0
0xffffa10000017a00 0001 00000000 0x0 0x0
0xffffa10000017a80 0001 00000000 0x0 0x0
0xffffa10000017b00 0001 00000000 0x0 0x0
0xffffa10000017b80 0001 00000000 0x0 0x0
0xffffa10000017c00 0001 00000000 0x0 0x0
0xffffa10000017c80 0001 00000000 0x0 0x0
0xffffa10000017d00 0001 00000000 0x0 0x0
0xffffa10000017d80 0001 00000000 0x0 0x0
0xffffa10000017e00 0001 00000000 0x0 0x0
0xffffa10000017e80 0001 00000000 0x0 0x0
0xffffa10000017f00 0001 00000000 0x0 0x0
0xffffa10000017f80 0001 00000000 0x0 0x0
0xffffa10000018000 0041 00000000 0x0 0x0
0xffffa10000018080 0041 00000000 0x0 0x0
0xffffa10000018100 0041 00000000 0x0 0x0
0xffffa10000018180 0041 00000000 0x0 0x0
0xffffa10000018200 0045 00000000 0x0 0x0
0xffffa10000018280 0041 00000000 0x0 0x0
0xffffa10000018300 0041 00000000 0x0 0x0
0xffffa10000018380 0041 00000000 0x0 0x0
0xffffa10000018400 0041 00000000 0x0 0x0
0xffffa10000018480 0041 00000000 0x0 0x0
0xffffa10000018500 0041 00000000 0x0 0x0
0xffffa10000018580 0045 00000000 0x0 0x0
0xffffa10000018600 0045 00000000 0x0 0x0
0xffffa10000018680 0041 00000000 0x0 0x0
0xffffa10000018700 0041 00000000 0x0 0x0
0xffffa10000018780 0041 00000000 0x0 0x0
0xffffa10000018800 0041 00000000 0x0 0x0
0xffffa10000018880 0041 00000000 0x0 0x0
0xffffa10000018900 0041 00000000 0x0 0x0
0xffffa10000018980 0045 00000000 0x0 0x0
0xffffa10000018a00 0045 00000000 0x0 0x0
0xffffa10000018a80 0041 00000000 0x0 0x0
0xffffa10000018b00 0041 00000000 0x0 0x0
0xffffa10000018b80 0041 00000000 0x0 0x0
0xffffa10000018c00 0041 00000000 0x0 0x0
0xffffa10000018c80 0041 00000000 0x0 0x0
0xffffa10000018d00 0041 00000000 0x0 0x0
0xffffa10000018d80 0045 00000000 0x0 0x0
0xffffa10000018e00 0045 00000000 0x0 0x0
0xffffa10000018e80 0045 00000000 0x0 0x0
0xffffa10000018f00 0041 00000000 0x0 0x0
0xffffa10000018f80 0041 00000000 0x0 0x0
0xffffa10000019000 0045 00000000 0x0 0x0
0xffffa10000019080 0041 00000000 0x0 0x0
0xffffa10000019100 0045 00000000 0x0 0x0
0xffffa10000019180 0045 00000000 0x0 0x0
0xffffa10000019200 0045 00000000 0x0 0x0
0xffffa10000019280 0045 00000000 0x0 0x0
0xffffa10000019300 0041 00000000 0x0 0x0
0xffffa10000019380 0041 00000000 0x0 0x0
0xffffa10000019400 0045 00000000 0x0 0x0
0xffffa10000019480 0041 00000000 0x0 0x0
0xffffa10000019500 0045 00000000 0x0 0x0
0xffffa10000019580 0045 00000000 0x0 0x0
0xffffa10000019600 0045 00000000 0x0 0x0
0xffffa10000019680 0045 00000000 0x0 0x0
0xffffa10000019700 0045 00000000 0x0 0x0
0xffffa10000019780 0041 00000000 0x0 0x0
0xffffa10000019800 0001 00000000 0x0 0x0
0xffffa10000019880 0001 00000000 0x0 0x0
0xffffa10000019900 0001 00000000 0x0 0x0
0xffffa10000019980 0001 00000000 0x0 0x0
0xffffa10000019a00 0001 00000000 0x0 0x0
0xffffa10000019a80 0001 00000000 0x0 0x0
0xffffa10000019b00 0001 00000000 0x0 0x0
0xffffa10000019b80 0001 00000000 0x0 0x0
0xffffa10000019c00 0001 00000000 0x0 0x0
0xffffa10000019c80 0001 00000000 0x0 0x0
0xffffa10000019d00 0001 00000000 0x0 0x0
0xffffa10000019d80 0001 00000000 0x0 0x0
0xffffa10000019e00 0001 00000000 0x0 0x0
0xffffa10000019e80 0001 00000000 0x0 0x0
0xffffa10000019f00 0001 00000000 0x0 0x0
0xffffa10000019f80 0001 00000000 0x0 0x0
0xffffa1000001a000 0001 00000000 0x0 0x0
0xffffa1000001a080 0001 00000000 0x0 0x0
0xffffa1000001a100 0001 00000000 0x0 0x0
0xffffa1000001a180 0001 00000000 0x0 0x0
0xffffa1000001a200 0001 00000000 0x0 0x0
0xffffa1000001a280 0001 00000000 0x0 0x0
0xffffa1000001a300 0001 00000000 0x0 0x0
0xffffa1000001a380 0001 00000000 0x0 0x0
0xffffa1000001a400 0001 00000000 0x0 0x0
0xffffa1000001a480 0001 00000000 0x0 0x0
0xffffa1000001a500 0001 00000000 0x0 0x0
0xffffa1000001a580 0001 00000000 0x0 0x0
0xffffa1000001a600 0001 00000000 0x0 0x0
0xffffa1000001a680 0001 00000000 0x0 0x0
0xffffa1000001a700 0001 00000000 0x0 0x0
0xffffa1000001a780 0001 00000000 0x0 0x0
0xffffa1000001a800 0001 00000000 0x0 0x0
0xffffa1000001a880 0001 00000000 0x0 0x0
0xffffa1000001a900 0001 00000000 0x0 0x0
0xffffa1000001a980 0001 00000000 0x0 0x0
0xffffa1000001aa00 0001 00000000 0x0 0x0
0xffffa1000001aa80 0001 00000000 0x0 0x0
0xffffa1000001ab00 0001 00000000 0x0 0x0
0xffffa1000001ab80 0001 00000000 0x0 0x0
0xffffa1000001ac00 0001 00000000 0x0 0x0
0xffffa1000001ac80 0001 00000000 0x0 0x0
0xffffa1000001ad00 0001 00000000 0x0 0x0
0xffffa1000001ad80 0001 00000000 0x0 0x0
0xffffa1000001ae00 0001 00000000 0x0 0x0
0xffffa1000001ae80 0001 00000000 0x0 0x0
0xffffa1000001af00 0001 00000000 0x0 0x0
0xffffa1000001af80 0001 00000000 0x0 0x0
0xffffa1000001b000 0001 00000000 0x0 0x0
0xffffa1000001b080 0001 00000000 0x0 0x0
0xffffa1000001b100 0001 00000000 0x0 0x0
0xffffa1000001b180 0001 00000000 0x0 0x0
0xffffa1000001b200 0001 00000000 0x0 0x0
0xffffa1000001b280 0001 00000000 0x0 0x0
0xffffa1000001b300 0001 00000000 0x0 0x0
0xffffa1000001b380 0001 00000000 0x0 0x0
0xffffa1000001b400 0001 00000000 0x0 0x0
0xffffa1000001b480 0001 00000000 0x0 0x0
0xffffa1000001b500 0001 00000000 0x0 0x0
0xffffa1000001b580 0001 00000000 0x0 0x0
0xffffa1000001b600 0001 00000000 0x0 0x0
0xffffa1000001b680 0001 00000000 0x0 0x0
0xffffa1000001b700 0001 00000000 0x0 0x0
0xffffa1000001b780 0001 00000000 0x0 0x0
0xffffa1000001b800 0001 00000000 0x0 0x0
0xffffa1000001b880 0001 00000000 0x0 0x0
0xffffa1000001b900 0001 00000000 0x0 0x0
0xffffa1000001b980 0001 00000000 0x0 0x0
0xffffa1000001ba00 0001 00000000 0x0 0x0
0xffffa1000001ba80 0001 00000000 0x0 0x0
0xffffa1000001bb00 0001 00000000 0x0 0x0
0xffffa1000001bb80 0001 00000000 0x0 0x0
0xffffa1000001bc00 0001 00000000 0x0 0x0
0xffffa1000001bc80 0001 00000000 0x0 0x0
0xffffa1000001bd00 0001 00000000 0x0 0x0
0xffffa1000001bd80 0001 00000000 0x0 0x0
0xffffa1000001be00 0001 00000000 0x0 0x0
0xffffa1000001be80 0001 00000000 0x0 0x0
0xffffa1000001bf00 0001 00000000 0x0 0x0
0xffffa1000001bf80 0001 00000000 0x0 0x0
0xffffa1000001c000 0001 00000000 0x0 0x0
0xffffa1000001c080 0001 00000000 0x0 0x0
0xffffa1000001c100 0001 00000000 0x0 0x0
0xffffa1000001c180 0001 00000000 0x0 0x0
0xffffa1000001c200 0001 00000000 0x0 0x0
0xffffa1000001c280 0001 00000000 0x0 0x0
0xffffa1000001c300 0001 00000000 0x0 0x0
0xffffa1000001c380 0001 00000000 0x0 0x0
0xffffa1000001c400 0001 00000000 0x0 0x0
0xffffa1000001c480 0001 00000000 0x0 0x0
0xffffa1000001c500 0001 00000000 0x0 0x0
0xffffa1000001c580 0001 00000000

---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

Maxime Villard

unread,
Jun 27, 2020, 3:14:38 AM6/27/20
to syzbot+61ec05...@syzkaller.appspotmail.com, syzkaller-netbsd-bugs
#syz dup: page fault in statvfs_to_statfs12_copy
Reply all
Reply to author
Forward
0 new messages