protection fault in pmap_check_pv (3)

0 views
Skip to first unread message

syzbot

unread,
Sep 13, 2023, 4:44:12 AM9/13/23
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 23ee83f7c0ae c.7: mention that C11 and C17 have been publi..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13d4c6bfa80000
kernel config: https://syzkaller.appspot.com/x/.config?x=739e57438eb9ed9e
dashboard link: https://syzkaller.appspot.com/bug?extid=5f97815493288c01b71d
compiler: Debian clang version 15.0.6

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/a2246aa2875c/disk-23ee83f7.raw.xz
netbsd.gdb: https://storage.googleapis.com/syzbot-assets/f5e0702a2a8a/netbsd-23ee83f7.gdb.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5f9781...@syzkaller.appspotmail.com

[ 345.3052194] fatal protection fault in supervisor mode
[ 345.3052194] trap type 4 code 0 rip 0xffffffff8195d753 cs 0x8 rflags 0x10246 cr2 0x795e2dc02000 ilevel 0x8 rsp 0xffffd800c8b3b040
[ 345.3052194] curlwp 0xffffd80013d1a940 pid 3203.9551 lowest kstack 0xffffd800c8b342c0
kernel: protection fault trap, code=0
Stopped in pid 3203.9551 (syz-executor.4) at netbsd:pmap_check_pv+0x523: movq 0(%r14),%rbx
?
pmap_check_pv() at netbsd:pmap_check_pv+0x523 sys/arch/x86/x86/pmap.c:2187
pmap_enter_ma() at netbsd:pmap_enter_ma+0x3186 pmap_enter_pv sys/arch/x86/x86/pmap.c:2341 [inline]
pmap_enter_ma() at netbsd:pmap_enter_ma+0x3186 sys/arch/x86/x86/pmap.c:5098
pmap_enter_default() at netbsd:pmap_enter_default+0x158 sys/arch/x86/x86/pmap.c:4977
udv_fault() at netbsd:udv_fault+0x6a5 sys/uvm/uvm_device.c:453
uvm_fault_internal() at netbsd:uvm_fault_internal+0x3fbd sys/uvm/uvm_fault.c:921
uvm_fault_wire() at netbsd:uvm_fault_wire+0x211 sys/uvm/uvm_fault.c:2633
uvm_map_pageable() at netbsd:uvm_map_pageable+0x1d72 sys/uvm/uvm_map.c:3583
uvm_mmap() at netbsd:uvm_mmap+0x13e7 sys/uvm/uvm_mmap.c:986
sys_mmap() at netbsd:sys_mmap+0x19e3 sys/uvm/uvm_mmap.c:431
compat_43_sys_mmap() at netbsd:compat_43_sys_mmap+0x331 sys/compat/common/vm_43.c:150
sys___syscall() at netbsd:sys___syscall+0x2ae sy_call sys/sys/syscallvar.h:65 [inline]
sys___syscall() at netbsd:sys___syscall+0x2ae sys/kern/sys_syscall.c:90
syscall() at netbsd:syscall+0x60c sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x60c sys/arch/x86/x86/syscall.c:138
--- syscall (number 71 via SYS_syscall) ---
netbsd:syscall+0x60c:
Panic string: (null)
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
4537 12382 3 0 180 ffffd800140ae600 syz-executor.0 parked
4537 4537 2 0 10000000 ffffd800137ceb40 syz-executor.0
12884 12374 3 0 0 ffffd800140ae1c0 syz-executor.1 fdclose
12884 3579 2 0 100 ffffd80013f845c0 syz-executor.1
12884 12884 2 0 10000000 ffffd80013638200 syz-executor.1
3203 >9551 7 0 100 ffffd80013d1a940 syz-executor.4
3203 3203 2 0 10040000 ffffd800134f55c0 syz-executor.4
3730 4563 3 0 180 ffffd8001397a8c0 syz-executor.5 parked
3730 3945 3 1 0 ffffd800140beac0 syz-executor.5 fdclose
3730 3948 3 0 180 ffffd800140be680 syz-executor.5 parked
3730 >3481 7 1 100 ffffd800140af640 syz-executor.5
3730 3730 3 1 10000180 ffffd80013d1a500 syz-executor.5 nanoslp
3712 4442 2 1 100100 ffffd800140afa80 syz-executor.3
3712 3712 3 1 10000000 ffffd80013f84180 syz-executor.3 lwpwait
8170 3395 2 1 140100 ffffd800140be240 syz-executor.2
8170 8170 3 1 10000000 ffffd8001397a480 syz-executor.2 lwpwait
11624 11624 3 0 180 ffffd800133fb100 syz-executor.4 nanoslp
3309 3309 3 1 180 ffffd80013d0d900 syz-executor.5 nanoslp
5938 5938 3 0 180 ffffd80013e6d540 syz-executor.2 nanoslp
3235 3235 3 0 180 ffffd800136c8ac0 syz-executor.3 nanoslp
2954 2954 3 1 180 ffffd800134cc140 syz-executor.0 nanoslp
9782 9782 3 0 180 ffffd80013759340 syz-executor.1 nanoslp
5946 5946 3 0 180 ffffd80013e6d980 syz-executor.3 parked
509 509 3 1 180 ffffd80013f84a00 syz-executor.3 parked
483 483 3 1 180 ffffd80013759780 syz-executor.0 parked
988 988 3 0 180 ffffd80013e8f580 syz-executor.3 parked
1358 1358 3 1 180 ffffd800134cc9c0 syz-executor.3 parked
6213 6213 3 0 180 ffffd800136c8240 syz-executor.2 parked
577 577 3 0 180 ffffd800136d2b00 syz-executor.1 parked
960 960 3 0 180 ffffd800136d2280 syz-executor.0 parked
9272 9272 3 1 180 ffffd800135e5a40 syz-executor.0 parked
9133 9133 3 0 180 ffffd80013d0d080 syz-executor.0 parked
7598 7598 3 0 180 ffffd80013e8f140 syz-executor.2 parked
296 296 3 1 180 ffffd80013759bc0 syz-executor.0 parked
293 293 3 0 180 ffffd80013e6d100 syz-executor.1 parked
414 414 3 0 180 ffffd80013d0d4c0 syz-executor.2 parked
407 407 3 1 180 ffffd800137eb740 syz-executor.2 parked
399 399 3 0 180 ffffd8001397a040 syz-executor.1 parked
7887 7887 3 0 180 ffffd800133fb540 syz-executor.0 parked
4714 4714 3 0 180 ffffd800137eb300 syz-executor.1 parked
8269 8269 3 0 180 ffffd80013638a80 syz-executor.1 parked
4445 4445 3 1 180 ffffd800137ce2c0 syz-executor.0 parked
2612 2612 3 0 180 ffffd80013638640 syz-executor.1 parked
7329 7329 3 1 180 ffffd800137ce700 syz-executor.0 parked
4274 4274 3 0 180 ffffd800136d26c0 syz-executor.1 parked
1081 2473 3 1 180 ffffd800136c8680 syz-fuzzer kqueue
1081 1205 3 1 180 ffffd800135e51c0 syz-fuzzer wait
1081 1382 3 1 180 ffffd800134f5a00 syz-fuzzer wait
1081 1079 3 1 1c0 ffffd800134f5180 syz-fuzzer wait
1081 991 3 1 180 ffffd800134cc580 syz-fuzzer wait
1081 1109 2 1 0 ffffd800133fb980 syz-fuzzer
1081 1242 3 0 180 ffffd80012c9f940 syz-fuzzer parked
1081 1241 3 1 1c0 ffffd80012c9f500 syz-fuzzer wait
1081 829 3 0 180 ffffd80012c9f0c0 syz-fuzzer parked
1081 1243 3 1 180 ffffd80012bde900 syz-fuzzer parked
1081 449 3 0 180 ffffd80012bde4c0 syz-fuzzer parked
1081 1222 3 0 180 ffffd80012bde080 syz-fuzzer parked
1081 1230 3 1 180 ffffd800123812c0 syz-fuzzer nanoslp
1081 1081 3 1 180 ffffd800122efb00 syz-fuzzer wait
1239 1239 3 0 180 ffffd800122ef6c0 sshd select
1225 1225 3 0 180 ffffd800122ef280 getty nanoslp
1086 1086 3 0 180 ffffd80012bb18c0 getty nanoslp
1226 1226 3 0 180 ffffd800121efac0 getty nanoslp
1056 1056 3 0 1c0 ffffd800121ec200 getty ttyraw
1107 1107 3 0 180 ffffd8001250b300 sshd select
978 978 3 0 180 ffffd800125eb780 powerd kqueue
699 699 3 1 180 ffffd80012bb1480 syslogd kqueue
747 747 3 0 180 ffffd80012bb1040 dhcpcd poll
748 748 3 1 180 ffffd8001250bb80 dhcpcd poll
745 745 3 1 180 ffffd80012381700 dhcpcd poll
604 604 3 0 180 ffffd800125ebbc0 dhcpcd poll
487 487 3 0 180 ffffd800125eb340 dhcpcd poll
292 292 3 1 180 ffffd80012381b40 dhcpcd poll
485 485 3 1 180 ffffd8001250b740 dhcpcd poll
1 1 3 1 180 ffffd80011ee0100 init wait
0 8007 5 0 200 ffffd80013d1a0c0 (zombie)
0 10064 3 1 200 ffffd800135e5600 swapiod swapiod
0 9521 3 1 200 ffffd80013e8f9c0 ktrace ktrwait
0 674 3 0 200 ffffd800121ec640 physiod physiod
0 196 3 1 200 ffffd800121ef680 pooldrain pooldrain
0 195 3 0 200 ffffd800121ef240 ioflush syncer
0 194 3 1 200 ffffd800121eca80 pgdaemon pgdaemon
0 167 3 1 200 ffffd8001215ba40 usb7 usbevt
0 172 3 0 200 ffffd8001215b600 usb6 usbevt
0 170 3 0 200 ffffd8001215b1c0 usb5 usbevt
0 168 3 0 200 ffffd8001212ca00 usb4 usbevt
0 166 3 0 200 ffffd8001212c5c0 usb3 usbevt
0 165 3 0 200 ffffd8001212c180 usb2 usbevt
0 31 3 1 200 ffffd800120859c0 usb1 usbevt
0 63 3 0 200 ffffd80012085580 usb0 usbevt
0 126 3 1 200 ffffd80012085140 usbtask-dr usbtsk
0 125 3 0 200 ffffd80011ee0980 usbtask-hc usbtsk
0 124 3 1 200 ffffd80011ee0540 swwreboot swwreboot
0 123 3 0 200 ffffd800103f4b00 npfgc0 npfgcw
0 122 3 1 200 ffffd80011ed4940 rt_free rt_free
0 121 3 1 200 ffffd80011ed4500 unpgc unpgc
0 120 3 0 200 ffffd80011ed40c0 key_timehandler key_timehandler
0 119 3 1 200 ffffd80011ecf900 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 ffffd80011ecf4c0 icmp6_wqinput/0 icmp6_wqinput
0 117 3 0 200 ffffd80011ecf080 nd6_timer nd6_timer
0 116 3 1 200 ffffd80011eaa8c0 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 ffffd80011eaa480 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 ffffd80011cecb80 carp_wqinput/1 carp_wqinput
0 113 3 0 200 ffffd80011cec740 carp_wqinput/0 carp_wqinput
0 112 3 1 200 ffffd80011ceebc0 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 ffffd80011cee780 icmp_wqinput/0 icmp_wqinput
0 110 3 0 200 ffffd80011eaa040 rt_timer rt_timer
0 109 3 0 200 ffffd80011cee340 vmem_rehash vmem_rehash
0 100 3 0 200 ffffd80011cec300 entbutler entropy
0 99 3 1 200 ffffd800117e0b40 viomb balloon
0 98 3 1 200 ffffd800117e0700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 ffffd800117e02c0 vioif0_txrx/0 vioif0_txrx
0 30 3 0 200 ffffd800103f46c0 scsibus0 sccomp
0 29 3 0 200 ffffd800103f4280 pms0 pmsreset
0 28 3 1 200 ffffd800103d9ac0 xcall/1 xcall
0 27 1 1 200 ffffd800103d9680 softser/1
0 26 1 1 200 ffffd800103d9240 softclk/1
0 25 1 1 200 ffffd800103d7a80 softbio/1
0 24 1 1 200 ffffd800103d7640 softnet/1
0 23 1 1 201 ffffd800103d7200 idle/1
0 22 3 0 200 ffffd8000f1e3a40 lnxsyswq lnxsyswq
0 21 3 0 200 ffffd8000f1e3600 lnxubdwq lnxubdwq
0 20 3 0 200 ffffd8000f1e31c0 lnxpwrwq lnxpwrwq
0 19 3 0 200 ffffd8000f1e1a00 lnxlngwq lnxlngwq
0 18 3 0 200 ffffd8000f1e15c0 lnxhipwq lnxhipwq
0 17 3 0 200 ffffd8000f1e1180 lnxrcugc lnxrcugc
0 16 3 0 200 ffffd8000f1db9c0 sysmon smtaskq
0 15 3 0 200 ffffd8000f1db580 pmfsuspend pmfsuspend
0 14 3 0 200 ffffd8000f1db140 pmfevent pmfevent
0 13 3 0 200 ffffd8000f1d9980 sopendfree sopendfr
0 12 3 0 200 ffffd8000f1d9540 ifwdog ifwdog
0 11 3 0 200 ffffd8000f1d9100 iflnkst iflnkst
0 10 3 0 200 ffffd8000f1cf940 nfssilly nfssilly
0 9 3 0 200 ffffd8000f1cf500 vdrain vdrain
0 8 3 1 200 ffffd8000f1cf0c0 modunload mod_unld
0 7 3 0 200 ffffd8000ebdb900 xcall/0 xcall
0 6 1 0 200 ffffd8000ebdb4c0 softser/0
0 5 1 0 200 ffffd8000ebdb080 softclk/0
0 4 1 0 200 ffffd8000ebd98c0 softbio/0
0 3 1 0 200 ffffd8000ebd9480 softnet/0
0 2 1 0 201 ffffd8000ebd9040 idle/0
0 0 3 0 200 ffffffff8686ea80 swapper uvm
[Locks tracked through LWPs]

****** LWP 3203.9551 (syz-executor.4) @ 0xffffd80013d1a940, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:uvm_obj_init+0x88 sys/uvm/uvm_object.c:70)
lock address : ffffd80014529380
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0x88
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffd80013d1a940 last held: 0xffffd80013d1a940
last locked* : netbsd:uvm_fault_internal+0x3ea0
unlocked : netbsd:udv_fault+0x8e8
owner/count : 0xffffd80013d1a940 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:pmap_ctor+0xc0 sys/arch/x86/x86/pmap.c:2872)
lock address : ffffd80013bb08c0
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0xc0
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 0
relevant lwp : 0xffffd80013d1a940 last held: 0xffffd80013d1a940
last locked* : netbsd:pmap_enter_ma+0x11ce
unlocked : netbsd:pmap_enter_ma+0x6f3f
owner field : 0xffffd80013d1a940 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 3203.3203 (syz-executor.4) @ 0xffffd800134f55c0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:pmap_ctor+0xc0 sys/arch/x86/x86/pmap.c:2872)
lock address : ffffd80013bb08c0
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0xc0
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 0
relevant lwp : 0xffffd800134f55c0 last held: 0xffffd80013d1a940
last locked* : netbsd:pmap_enter_ma+0x11ce
unlocked : netbsd:pmap_enter_ma+0x6f3f
owner field : 0xffffd80013d1a940 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 3730.3481 (syz-executor.5) @ 0xffffd800140af640, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:amap_ctor+0xdf sys/uvm/uvm_amap.c:265)
lock address : ffffd80014529400
type : sleep/adaptive
initialized : netbsd:amap_ctor+0xdf
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffd800140af640 last held: 0xffffd800140af640
last locked* : netbsd:uvm_fault_internal+0x1d08
unlocked : netbsd:uvm_fault_lower_enter+0x1bbc
owner/count : 0xffffd800140af640 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 748.748 (dhcpcd) @ 0xffffd8001250bb80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffd8001250bb80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 745.745 (dhcpcd) @ 0xffffd80012381700, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffd80012381700 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 292.292 (dhcpcd) @ 0xffffd80012381b40, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffd80012381b40 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 485.485 (dhcpcd) @ 0xffffd8001250b740, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffd8001250b740 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.26 (softclk/1) @ 0xffffd800103d9240, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffd800103d9240 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffffd8000f1d9100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffd8000f1d9100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff8686ea80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff8686ea80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffffd80000017180 0001 00000000 0x0 0x0
0xffffd80000017200 0041 00000000 0x0 0x0
0xffffd80000017280 0041 00000000 0x0 0x0
0xffffd80000017300 0041 00000000 0x0 0x0
0xffffd80000017380 0041 00000000 0x0 0x0
0xffffd80000017400 0041 00000000 0x0 0x0
0xffffd80000017480 0041 00000000 0x0 0x0
0xffffd80000017500 0041 00000000 0x0 0x0
0xffffd80000017580 0041 00000000 0x0 0x0
0xffffd80000017600 0041 00000000 0x0 0x0
0xffffd80000017680 0041 00000000 0x0 0x0
0xffffd80000017700 0041 00000000 0x0 0x0
0xffffd80000017780 0041 00000000 0x0 0x0
0xffffd80000017800 0041 00000000 0x0 0x0
0xffffd80000017880 0041 00000000 0x0 0x0
0xffffd80000017900 0041 00000000 0x0 0x0
0xffffd80000017980 0041 00000000 0x0 0x0
0xffffd80000017a00 0041 00000000 0x0 0x0
0xffffd80000017a80 0041 00000000 0x0 0x0
0xffffd80000017b00 0041 00000000 0x0 0x0
0xffffd80000017b80 0041 00000000 0x0 0x0
0xffffd80000017c00 0041 00000000 0x0 0x0
0xffffd80000017c80 0041 00000000 0x0 0x0
0xffffd80000017d00 0041 00000000 0x0 0x0
0xffffd80000017d80 0041 00000000 0x0 0x0
0xffffd80000017e00 0041 00000000 0x0 0x0
0xffffd80000017e80 0041 00000000 0x0 0x0
0xffffd80000017f00 0041 00000000 0x0 0x0
0xffffd80000017f80 0041 00000000 0x0 0x0
0xffffd80000018000 0041 00000000 0x0 0x0
0xffffd80000018080 0041 00000000 0x0 0x0
0xffffd80000018100 0041 00000000 0x0 0x0
0xffffd80000018180 0041 00000000 0x0 0x0
0xffffd80000018200 0041 00000000 0x0 0x0
0xffffd80000018280 0041 00000000 0x0 0x0
0xffffd80000018300 0041 00000000 0x0 0x0
0xffffd80000018380 0041 00000000 0x0 0x0
0xffffd80000018400 0041 00000000 0x0 0x0
0xffffd80000018480 0041 00000000 0x0 0x0
0xffffd80000018500 0041 00000000 0x0 0x0
0xffffd80000018580 0041 00000000 0x0 0x0
0xffffd80000018600 0041 00000000 0x0 0x0
0xffffd80000018680 0041 00000000 0x0 0x0
0xffffd80000018700 0041 00000000 0x0 0x0
0xffffd80000018780 0041 00000000 0x0 0x0
0xffffd80000018800 0041 00000000 0x0 0x0
0xffffd80000018880 0041 00000000 0x0 0x0
0xffffd80000018900 0041 00000000 0x0 0x0
0xffffd80000018980 0041 00000000 0x0 0x0
0xffffd80000018a00 0041 00000000 0x0 0x0
0xffffd80000018a80 0041 00000000 0x0 0x0
0xffffd80000018b00 0041 00000000 0x0 0x0
0xffffd80000018b80 0041 00000000 0x0 0x0
0xffffd80000018c00 0041 00000000 0x0 0x0
0xffffd80000018c80 0041 00000000 0x0 0x0
0xffffd80000018d00 0041 00000000 0x0 0x0
0xffffd80000018d80 0041 00000000 0x0 0x0
0xffffd80000018e00 0041 00000000 0x0 0x0
0xffffd80000018e80 0041 00000000 0x0 0x0
0xffffd80000018f00 0041 00000000 0x0 0x0
0xffffd80000018f80 0041 00000000 0x0 0x0
0xffffd80000019000 0041 00000000 0x0 0x0
0xffffd80000019080 0041 00000000 0x0 0x0
0xffffd80000019100 0041 00000000 0x0 0x0
0xffffd80000019180 0041 00000000 0x0 0x0
0xffffd80000019200 0041 00000000 0x0 0x0
0xffffd80000019280 0041 00000000 0x0 0x0
0xffffd80000019300 0041 00000000 0x0 0x0
0xffffd80000019380 0041 00000000 0x0 0x0
0xffffd80000019400 0041 00000000 0x0 0x0
0xffffd80000019480 0041 00000000 0x0 0x0
0xffffd80000019500 0041 00000000 0x0 0x0
0xffffd80000019580 0041 00000000 0x0 0x0
0xffffd80000019600 0041 00000000 0x0 0x0
0xffffd80000019680 0041 00000000 0x0 0x0
0xffffd80000019700 0041 00000000 0x0 0x0
0xffffd80000019780 0041 00000000 0x0 0x0
0xffffd80000019800 0041 00000000 0x0 0x0
0xffffd80000019880 0041 00000000 0x0 0x0
0xffffd80000019900 0041 00000000 0x0 0x0
0xffffd80000019980 0041 00000000 0x0 0x0
0xffffd80000019a00 0041 00000000 0x0 0x0
0xffffd80000019a80 0041 00000000 0x0 0x0
0xffffd80000019b00 0041 00000000 0x0 0x0
0xffffd80000019b80 0041 00000000 0x0 0x0
0xffffd80000019c00 0041 00000000 0x0 0x0
0xffffd80000019c80 0041 00000000 0x0 0x0
0xffffd80000019d00 0041 00000000 0x0 0x0
0xffffd80000019d80 0041 00000000 0x0 0x0
0xffffd80000019e00 0041 00000000 0x0 0x0
0xffffd80000019e80 0041 00000000 0x0 0x0
0xffffd80000019f00 0041 00000000 0x0 0x0
0xffffd80000019f80 0041 00000000 0x0 0x0
0xffffd8000001a000 0041 00000000 0x0 0x0
0xffffd8000001a080 0041 00000000 0x0 0x0
0xffffd8000001a100 0041 00000000 0x0 0x0
0xffffd8000001a180 0041 00000000 0x0 0x0
0xffffd8000001a200 0041 00000000 0x0 0x0
0xffffd8000001a280 0041 00000000 0x0 0x0
0xffffd8000001a300 0041 00000000 0x0 0x0
0xffffd8000001a380 0041 00000000 0x0 0x0
0xffffd8000001a400 0041 00000000 0x0 0x0
0xffffd8000001a480 0041 00000000 0x0 0x0
0xffffd8000001a500 0041 00000000 0x0 0x0
0xffffd8000001a580 0041 00000000 0x0 0x0
0xffffd8000001a600 0041 00000000 0x0 0x0
0xffffd8000001a680 0041 00000000 0x0 0x0
0xffffd8000001a700 0041 00000000 0x0 0x0
0xffffd8000001a780 0041 00000000 0x0 0x0
0xffffd8000001a800 0041 00000000 0x0 0x0
0xffffd8000001a880 0041 00000000 0x0 0x0
0xffffd8000001a900 0041 00000000 0x0 0x0
0xffffd8000001a980 0041 00000000 0x0 0x0
0xffffd8000001aa00 0041 00000000 0x0 0x0
0xffffd8000001aa80 0041 00000000 0x0 0x0
0xffffd8000001ab00 0041 00000000 0x0 0x0
0xffffd8000001ab80 0041 00000000 0x0 0x0
0xffffd8000001ac00 0041 00000000 0x0 0x0
0xffffd8000001ac80 0041 00000000 0x0 0x0
0xffffd8000001ad00 0041 00000000 0x0 0x0
0xffffd8000001ad80 0041 00000000 0x0 0x0
0xffffd8000001ae00 0041 00000000 0x0 0x0
0xffffd8000001ae80 0041 00000000 0x0 0x0
0xffffd8000001af00 0041 00000000 0x0 0x0
0xffffd8000001af80 0041 00000000 0x0 0x0
0xffffd8000001b000 0041 00000000 0x0 0x0
0xffffd8000001b080 0041 00000000 0x0 0x0
0xffffd8000001b100 0041 00000000 0x0 0x0
0xffffd8000001b180 0041 00000000 0x0 0x0
0xffffd8000001b200 0041 00000000 0x0 0x0
0xffffd8000001b280 0041 00000000 0x0 0x0
0xffffd8000001b300 0041 00000000 0x0 0x0
0xffffd8000001b380 0041 00000000 0x0 0x0
0xffffd8000001b400 0041 00000000 0x0 0x0
0xffffd8000001b480 0041 00000000 0x0 0x0
0xffffd8000001b500 0041 00000000 0x0 0x0
0xffffd8000001b580 0041 00000000 0x0 0x0
0xffffd8000001b600 0041 00000000 0x0 0x0
0xffffd8000001b680 0041 00000000 0x0 0x0
0xffffd8000001b700 0041 00000000 0x0 0x0
0xffffd8000001b780 0041 00000000 0x0 0x0
0xffffd8000001b800 0041 00000000 0x0 0x0
0xffffd8000001b880 0041 00000000 0x0 0x0
0xffffd8000001b900 0041 00000000 0x0 0x0
0xffffd8000001b980 0041 00000000 0x0 0x0
0xffffd8000001ba00 0041 00000000 0x0 0x0
0xffffd8000001ba80 0041 00000000 0x0 0x0
0xffffd8000001bb00 0041 00000000 0x0 0x0
0xffffd8000001bb80 0041 00000000 0x0 0x0
0xffffd8000001bc00 0041 00000000 0x0 0x0
0xffffd8000001bc80 0041 00000000 0x0 0x0
0xffffd8000001bd00 0041 00000000 0x0 0x0
0xffffd8000001bd80 0041 00000000 0x0 0x0
0xffffd8000001be00 0041 00000000 0x0 0x0
0xffffd8000001be80 0041 00000000 0x0 0x0
0xffffd8000001bf00 0041 00000000 0x0 0x0
0xffffd8000001bf80 0041 00000000 0x0 0x0
0xffffd8000001c000 0041 00000000 0x0 0x0
0xffffd8000001c080 0041 00000000 0x0 0x0
0xffffd8000001c100 0041 00000000 0x0 0x0
0xffffd8000001c180 0041 00000000 0x0 0x0
0xffffd8000001c200 0041 00000000 0x0 0x0
0xffffd8000001c280 0041 00000000 0x0 0x0
0xffffd8000001c300 0041 00000000 0x0 0x0
0xffffd8000001c380 0041 00000000 0x0 0x0
0xffffd8000001c400 0041 00000000 0x0 0x0
0xffffd8000001c480 0041 00000000 0x0 0x0
0xffffd8000001c500 0041 00000000 0x0 0x0
0xffffd8000001c580 0041 00000000 0x0 0x0
0xffffd8000001c600 0041 00000000 0x0 0x0
0xffffd8000001c680 0041 00000000 0x0 0x0
0xffffd8000001c700 0041 00000000 0x0 0x0
0xffffd8000001c780 0041 00000000 0x0 0x0
0xffffd8000001c800 0001 00000000 0x0 0x0
0xffffd8000001c880 0001 00000000 0x0 0x0
0xffffd8000001c900 0001 00000000 0x0 0x0
0xffffd8000001c980 0001 00000000 0x0 0x0
0xffffd8000001ca00 0001 00000000 0x0 0x0
0xffffd8000001ca80 0001 00000000 0x0 0x0
0xffffd8000001cb00 0001 00000000 0x0 0x0
0xffffd8000001cb80 0001 00000000 0x0 0x0
0xffffd8000001cc00 0001 00000000 0x0 0x0
0xffffd8000001cc80 0001 00000000 0x0 0x0
0xffffd8000001cd00 0001 00000000 0x0 0x0
0xffffd8000001cd80 0001 00000000 0x0 0x0
0xffffd8000001ce00 0001 00000000 0x0 0x0
0xffffd8000001ce80 0001 00000000 0x0 0x0
0xffffd8000001cf00 0001 00000000 0x0 0x0
0xffffd8000001cf80 0001 00000000 0x0 0x0
0xffffd8000001d000 0001 00000000 0x0 0x0
0xffffd8000001d080 0001 00000000 0x0 0x0
0xffffd8000001d100 0001 00000000 0x0 0x0
0xffffd8000001d180 0001 00000000 0x0 0x0
0xffffd8000001d200 0001 00000000 0x0 0x0
0xffffd8000001d280 0001 00000000 0x0 0x0
0xffffd8000001d300 0001 00000000 0x0 0x0
0xffffd8000001d380 0001 00000000 0x0 0x0
0xffffd8000001d400 0001 00000000 0x0 0x0
0xffffd8000001d480 0001 00000000 0x0 0x0
0xffffd8000001d500 0001 00000000 0x0 0x0
0xffffd8000001d580 0001 00000000 0x0 0x0
0xffffd8000001d600 0001 00000000 0x0 0x0
0xffffd8000001d680 0001 00000000 0x0 0x0
0xffffd8000001d700 0001 00000000 0x0 0x0
0xffffd8000001d780 0001 00000000 0x0 0x0
0xffffd8000001d800 0001 00000000 0x0 0x0
0xffffd8000001d880 0001 00000000 0x0 0x0
0xffffd8000001d900 0001 00000000 0x0 0x0
0xffffd8000001d980 0001 00000000 0x0 0x0
0xffffd8000001da00 0001 00000000 0x0 0x0
0xffffd8000001da80 0001 00000000 0x0 0x0
0xffffd8000001db00 0001 00000000 0x0 0x0
0xffffd8000001db80 0001 00000000 0x0 0x0
0xffffd8000001dc00 0001 00000000 0x0 0x0
0xffffd8000001dc80 0001 00000000 0x0 0x0
0xffffd8000001dd00 0001 00000000 0x0 0x0
0xffffd8000001dd80 0001 00000000 0x0 0x0
0xffffd8000001de00 0001 00000000 0x0 0x0
0xffffd8000001de80 0001 00000000 0x0 0x0
0xffffd8000001df00 0001 00000000 0x0 0x0
0xffffd8000001df80 0001 00000000 0x0 0x0
0xffffd8000001e000 0001 00000000 0x0 0x0
0xffffd8000001e080 0001 00000000 0x0 0x0
0xffffd8000001e100 0001 00000000 0x0 0x0
0xffffd8000001e180 0001 00000000 0x0 0x0
0xffffd8000001e200 0001 00000000 0x0 0x0
0xffffd8000001e280 0001 00000000 0x0 0x0
0xffffd8000001e300 0001 00000000 0x0 0x0
0xffffd8000001e380 0001 00000000 0x0 0x0
0xffffd8000001e400 0001 00000000 0x0 0x0
0xffffd8000001e480 0001 00000000 0x0 0x0
0xffffd8000001e500 0001 00000000 0x0 0x0
0xffffd8000001e580 0001 00000000 0x0 0x0
0xffffd8000001e600 0001 00000000 0x0 0x0
0xffffd8000001e680 0001 00000000 0x0 0x0
0xffffd8000001e700 0001 00000000 0x0 0x0
0xffffd8000001e780 0001 00000000 0x0 0x0
0xffffd8000001e800 0001 00000000 0x0 0x0
0xffffd8000001e880 0001 00000000 0x0 0x0
0xffffd8000001e900 0001 00000000 0x0 0x0
0xffffd8000001e980 0001 00000000 0x0 0x0
0xffffd8000001ea00 0001 00000000 0x0 0x0
0xffffd8000001ea80 0001 00000000 0x0 0x0
0xffffd8000001eb00 0001 00000000 0x0 0x0
0xffffd8000001eb80 0001 00000000 0x0 0x0
0xffffd8000001ec00 0001 00000000 0x0 0x0
0xffffd8000001ec80 0001 00000000 0x0 0x0
0xffffd8000001ed00 0001 00000000 0x0 0x0
0xffffd8000001ed80 0001 00000000 0x0 0x0
0xffffd8000001ee00 0001 00000000 0x0 0x0
0xffffd8000001ee80 0001 00000000 0x0 0x0
0xffffd8000001ef00 0001 00000000 0x0 0x0
0xffffd8000001ef80 0001 00000000 0x0 0x0
0xffffd8000001f000 0001 00000000 0x0 0x0
0xffffd8000001f080 0001 00000000 0x0 0x0
0xffffd8000001f100 0001 00000000 0x0 0x0
0xffffd8000001f180 0001 00000000 0x0 0x0
0xffffd8000001f200 0001 00000000 0x0 0x0
0xffffd8000001f280 0001 00000000 0x0 0x0
0xffffd8000001f300 0001 00000000 0x0 0x0
0xffffd8000001f380 0001 00000000 0x0 0x0
0xffffd8000001f400 0001 00000000 0x0 0x0
0xffffd8000001f480 0001 00000000 0x0 0x0
0xffffd8000001f500 0001 00000000 0x0 0x0
0xffffd8000001f580 0001 00000000 0x0 0x0
0xffffd8000001f600 0001 00000000 0x0 0x0
0xffffd8000001f680 0001 00000000 0x0 0x0
0xffffd8000001f700 0001 00000000 0x0 0x0
0xffffd8000001f780 0001 00000000 0x0 0x0
0xffffd8000001f800 0001 00000000 0x0 0x0
0xffffd8000001f880 0001 00000000 0x0 0x0
0xffffd8000001f900 0001 00000000 0x0 0x0
0xffffd8000001f980 0001 00000000 0x0 0x0
0xffffd8000001fa00 0001 00000000 0x0 0x0
0xffffd8000001fa80 0001 00000000 0x0 0x0
0xffffd8000001fb00 0001 00000000 0x0 0x0
0xffffd8000001fb80 0001 00000000 0x0 0x0
0xffffd8000001fc00 0001 00000000 0x0 0x0
0xffffd8000001fc80 0001 00000000 0x0 0x0
0xffffd8000001fd00 0001 00000000 0x0 0x0
0xffffd8000001fd80 0001 00000000 0x0 0x0
0xffffd8000001fe00 0001 00000000 0x0 0x0
0xffffd8000001fe80 0001 00000000 0x0 0x0
0xffffd8000001ff00 0001 00000000 0x0 0x0
0xffffd8000001ff80 0001 00000000 0x0 0x0
0xffffd80000020000 0001 00000000 0x0 0x0
0xffffd80000020080 0001 00000000 0x0 0x0
0xffffd80000020100 0001 00000000 0x0 0x0
0xffffd80000020180 0001 00000000 0x0 0x0
0xffffd80000020200 0001 00000000 0x0 0x0
0xffffd80000020280 0001 00000000 0x0 0x0
0xffffd80000020300 0001 00000000 0x0 0x0
0xffffd80000020380 0001 00000000 0x0 0x0
0xffffd80000020400 0001 00000000 0x0 0x0
0xffffd80000020480 0001 00000000 0x0 0x0
0xffffd80000020500 0001 00000000 0x0 0x0
0xffffd80000020580 0001 00000000 0x0 0x0
0xffffd80000020600 0001 00000000 0x0 0x0
0xffffd80000020680 0001 00000000 0x0 0x0
0xffffd80000020700 0001 00000000 0x0 0x0
0xffffd80000020780 0001 00000000 0x0 0x0
0xffffd80000020800 0001 00000000 0x0 0x0
0xffffd80000020880 0001 00000000 0x0 0x0
0xffffd80000020900 0001 00000000 0x0 0x0
0xffffd80000020980 0001 00000000 0x0 0x0
0xffffd80000020a00 0001 00000000 0x0 0x0
0xffffd80000020a80 0001 00000000 0x0 0x0
0xffffd80000020b00 0001 00000000 0x0 0x0
0xffffd80000020b80 0001 00000000 0x0 0x0
0xffffd80000020c00 0001 00000000 0x0 0x0
0xffffd80000020c80 0001 00000000 0x0 0x0
0xffffd80000020d00 0001 00000000 0x0 0x0
0xffffd80000020d80 0001 00000000 0x0 0x0
0xffffd80000020e00 0001 00000000 0x0 0x0
0xffffd80000020e80 0001 00000000 0x0 0x0
0xffffd80000020f00 0001 00000000 0x0 0x0
0xffffd80000020f80 0001 00000000 0x0 0x0
0xffffd80000021000 0001 00000000 0x0 0x0
0xffffd80000021080 0001 00000000 0x0 0x0
0xffffd80000021100 0001 00000000 0x0 0x0
0xffffd80000021180 0001 00000000 0x0 0x0
0xffffd80000021200 0001 00000000 0x0 0x0
0xffffd80000021280 0001 00000000 0x0 0x0
0xffffd80000021300 0001 00000000 0x0 0x0
0xffffd80000021380 0001 00000000 0x0 0x0
0xffffd80000021400 0001 00000000 0x0 0x0
0xffffd80000021480 0001 00000000 0x0 0x0
0xffffd80000021500 0001 00000000 0x0 0x0
0xffffd80000021580 0001 00000000 0x0 0x0
0xffffd80000021600 0001 00000000 0x0 0x0
0xffffd80000021680 0001 00000000 0x0 0x0
0xffffd80000021700 0001 00000000 0x0 0x0
0xffffd80000021780 0001 00000000 0x0 0x0
0xffffd80000021800 0001 00000000 0x0 0x0
0xffffd80000021880 0001 00000000 0x0 0x0
0xffffd80000021900 0001 00000000 0x0 0x0
0xffffd80000021980 0001 00000000 0x0 0x0
0xffffd80000021a00 0001 00000000 0x0 0x0
0xffffd80000021a80 0001 00000000 0x0 0x0
0xffffd80000021b00 0001 00000000 0x0 0x0
0xffffd80000021b80 0001 00000000 0x0 0x0
0xffffd80000021c00 0001 00000000 0x0 0x0
0xffffd80000021c80 0001 00000000 0x0 0x0
0xffffd80000021d00 0001 00000000 0x0 0x0
0xffffd80000021d80 0001 00000000 0x0 0x0
0xffffd80000021e00 0001 00000000 0x0 0x0
0xffffd80000021e80 0001 00000000 0x0 0x0
0xffffd80000021f00 0001 00000000 0x0 0x0
0xffffd80000021f80 0001 00000000 0x0 0x0
0xffffd80000022000 0001 00000000 0x0 0x0
0xffffd80000022080 0001 00000000 0x0 0x0
0xffffd80000022100 0001 00000000 0x0 0x0
0xffffd80000022180 0001 00000000 0x0 0x0
0xffffd80000022200 0001 00000000 0x0 0x0
0xffffd80000022280 0001 00000000 0x0 0x0
0xffffd80000022300 0001 00000000 0x0 0x0
0xffffd80000022380 0001 00000000 0x0 0x0
0xffffd80000022400 0001 00000000 0x0 0x0
0xffffd80000022480 0001 00000000 0x0 0x0
0xffffd80000022500 0001 00000000 0x0 0x0
0xffffd80000022580 0001 00000000 0x0 0x0
0xffffd80000022600 0001 00000000 0x0 0x0
0xffffd80000022680 0001 00000000 0x0 0x0
0xffffd80000022700 0001 00000000 0x0 0x0
0xffffd80000022780 0001 00000000 0x0 0x0
0xffffd80000022800 0001 00000000 0x0 0x0
0xffffd80000022880 0001 00000000 0x0 0x0
0xffffd80000022900 0001 00000000 0x0 0x0
0xffffd80000022980 0001 00000000 0x0 0x0
0xffffd80000022a00 0001 00000000 0x0 0x0
0xffffd80000022a80 0001 00000000 0x0 0x0
0xffffd80000022b00 0001 00000000 0x0 0x0
0xffffd80000022b80 0001 00000000 0x0 0x0
0xffffd80000022c00 0001 00000000 0x0 0x0
0xffffd80000022c80 0001 00000000 0x0 0x0
0xffffd80000022d00 0001 00000000 0x0 0x0
0xffffd80000022d80 0001 00000000 0x0 0x0
0xffffd80000022e00 0001 00000000 0x0 0x0
0xffffd80000022e80 0001 00000000 0x0 0x0
0xffffd80000022f00 0001 00000000 0x0 0x0
0xffffd80000022f80 0001 00000000 0x0 0x0
0xffffd80000023000 0001 00000000 0x0 0x0
0xffffd80000023080 0001 00000000 0x0 0x0
0xffffd80000023100 0001 00000000 0x0 0x0
0xffffd80000023180 0001 00000000 0x0 0x0
0xffffd80000023200 0001 00000000 0x0 0x0
0xffffd80000023280 0001 00000000 0x0 0x0
0xffffd80000023300 0001 00000000 0x0 0x0
0xffffd80000023380 0001 00000000 0x0 0x0
0xffffd80000023400 0001 00000000 0x0 0x0
0xffffd80000023480 0001 00000000 0x0 0x0
0xffffd80000023500 0001 00000000 0x0 0x0
0xffffd80000023580 0001 00000000 0x0 0x0
0xffffd80000023600 0001 00000000 0x0 0x0
0xffffd80000023680 0001 00000000 0x0 0x0
0xffffd80000023700 0001 00000000 0x0 0x0
0xffffd80000023780 0001 00000000 0x0 0x0
0xffffd80000023800 0001 00000000 0x0 0x0
0xffffd80000023880 0001 00000000 0x0 0x0
0xffffd80000023900 0001 00000000 0x0 0x0
0xffffd80000023980 0001 00000000 0x0 0x0
0xffffd80000023a00 0001 00000000 0x0 0x0
0xffffd80000023a80 0001 00000000 0x0 0x0
0xffffd80000023b00 0001 00000000 0x0 0x0
0xffffd80000023b80 0001 00000000 0x0 0x0
0xffffd80000023c00 0001 00000000 0x0 0x0
0xffffd80000023c80 0001 00000000 0x0 0x0
0xffffd80000023d00 0001 00000000 0x0 0x0
0xffffd80000023d80 0001 00000000 0x0 0x0
0xffffd80000023e00 0001 00000000 0x0 0x0
0xffffd80000023e80 0001 00000000 0x0 0x0
0xffffd80000023f00 0001 00000000 0x0 0x0
0xffffd80000023f80 0001 00000000 0x0 0x0
0xffffd80000024000 0001 00000000 0x0 0x0
0xffffd80000024080 0001 00000000 0x0 0x0
0xffffd80000024100 0001 00000000 0x0 0x0
0xffffd80000024180 0001 00000000 0x0 0x0
0xffffd80000024200 0001 00000000 0x0 0x0
0xffffd80000024280 0001 00000000 0x0 0x0
0xffffd80000024300 0001 00000000 0x0 0x0
0xffffd80000024380 0001 00000000 0x0 0x0
0xffffd80000024400 0001 00000000 0x0 0x0
0xffffd80000024480 0001 00000000 0x0 0x0
0xffffd80000024500 0001 00000000 0x0 0x0
0xffffd80000024580 0001 00000000 0x0 0x0
0xffffd80000024600 0001 00000000 0x0 0x0
0xffffd80000024680 0001 00000000 0x0 0x0
0xffffd80000024700 0001 00000000 0x0 0x0
0xffffd80000024780 0001 00000000 0x0 0x0
0xffffd80000024800 0001 00000000 0x0 0x0
0xffffd80000024880 0001 00000000 0x0 0x0
0xffffd80000024900 0001 00000000 0x0 0x0
0xffffd80000024980 0001 00000000 0x0 0x0
0xffffd80000024a00 0001 00000000 0x0 0x0
0xffffd80000024a80 0001 00000000 0x0 0x0
0xffffd80000024b00 0001 00000000 0x0 0x0
0xffffd80000024b80 0001 00000000 0x0 0x0
0xffffd80000024c00 0001 00000000 0x0 0x0
0xffffd80000024c80 0001 00000000 0x0 0x0
0xffffd80000024d00 0001 00000000 0x0 0x0
0xffffd80000024d80 0001 00000000 0x0 0x0
0xffffd80000024e00 0001 00000000 0x0 0x0
0xffffd80000024e80 0001 00000000 0x0 0x0
0xffffd80000024f00 0001 00000000 0x0 0x0
0xffffd80000024f80 0001 00000000 0x0 0x0
0xffffd80000025000 0001 00000000 0x0 0x0
0xffffd80000025080 0001 00000000 0x0 0x0
0xffffd80000025100 0001 00000000 0x0 0x0
0xffffd80000025180 0001 00000000 0x0 0x0
0xffffd80000025200 0001 00000000 0x0 0x0
0xffffd80000025280 0001 00000000 0x0 0x0
0xffffd80000025300 0001 00000000 0x0 0x0
0xffffd80000025380 0001 00000000 0x0 0x0
0xffffd80000025400 0001 00000000 0x0 0x0
0xffffd80000025480 0001 00000000 0x0 0x0
0xffffd80000025500 0001 00000000 0x0 0x0
0xffffd80000025580 0001 00000000 0x0 0x0
0xffffd80000025600 0001 00000000 0x0 0x0
0xffffd80000025680 0001 00000000 0x0 0x0
0xffffd80000025700 0001 00000000 0x0 0x0
0xffffd80000025780 0001 00000000 0x0 0x0
0xffffd80000025800 0001 00000000 0x0 0x0
0xffffd80000025880 0001 00000000 0x0 0x0
0xffffd80000025900 0001 00000000 0x0 0x0
0xffffd80000025980 0001 00000000 0x0 0x0
0xffffd80000025a00 0001 00000000 0x0 0x0
0xffffd80000025a80 0001 00000000 0x0 0x0
0xffffd80000025b00 0001 00000000 0x0 0x0
0xffffd80000025b80 0001 00000000 0x0 0x0
0xffffd80000025c00 0001 00000000 0x0 0x0
0xffffd80000025c80 0001 00000000 0x0 0x0
0xffffd80000025d00 0001 00000000 0x0 0x0
0xffffd80000025d80 0001 00000000 0x0 0x0
0xffffd80000025e00 0001 00000000 0x0 0x0
0xffffd80000025e80 0001 00000000 0x0 0x0
0xffffd80000025f00 0001 00000000 0x0 0x0
0xffffd80000025f80 0001 00000000 0x0 0x0
0xffffd80000026000 0001 00000000 0x0 0x0
0xffffd80000026080 0001 00000000 0x0 0x0
0xffffd80000026100 0001 00000000 0x0 0x0
0xffffd80000026180 0001 00000000 0x0 0x0
0xffffd80000026200 0001 00000000 0x0 0x0
0xffffd80000026280 0001 00000000 0x0 0x0
0xffffd80000026300 0001 00000000 0x0 0x0
0xffffd80000026380 0001 00000000 0x0 0x0
0xffffd80000026400 0001 00000000 0x0 0x0
0xffffd80000026480 0001 00000000 0x0 0x0
0xffffd80000026500 0001 00000000 0x0 0x0
0xffffd80000026580 0001 00000000 0x0 0x0
0xffffd80000026600 0001 00000000 0x0 0x0
0xffffd80000026680 0001 00000000 0x0 0x0
0xffffd80000026700 0001 00000000 0x0 0x0
0xffffd80000026780 0001 00000000 0x0 0x0
0xffffd80000026800 0001 00000000 0x0 0x0
0xffffd80000026880 0001 00000000 0x0 0x0
0xffffd80000026900 0001 00000000 0x0 0x0
0xffffd80000026980 0001 00000000 0x0 0x0
0xffffd80000026a00 0001 00000000 0x0 0x0
0xffffd80000026a80 0001 00000000 0x0 0x0
0xffffd80000026b00 0001 00000000 0x0 0x0
0xffffd80000026b80 0001 00000000 0x0 0x0
0xffffd80000026c00 0001 00000000 0x0 0x0
0xffffd80000026c80 0001 00000000 0x0 0x0
0xffffd80000026d00 0001 00000000 0x0 0x0
0xffffd80000026d80 0001 00000000 0x0 0x0
0xffffd80000026e00 0001 00000000 0x0 0x0
0xffffd80000026e80 0001 00000000 0x0 0x0
0xffffd80000026f00 0001 00000000 0x0 0x0
0xffffd80000026f80 0001 00000000 0x0 0x0
0xffffd80000027000 0001 00000000 0x0 0x0
0xffffd80000027080 0001 00000000 0x0 0x0
0xffffd80000027100 0001 00000000 0x0 0x0
0xffffd80000027180 0001 00000000 0x0 0x0
0xffffd80000027200 0001 00000000 0x0 0x0
0xffffd80000027280 0001 00000000 0x0 0x0
0xffffd80000027300 0001 00000000 0x0 0x0
0xffffd80000027380 0001 00000000 0x0 0x0
0xffffd80000027400 0001 00000000 0x0 0x0
0xffffd80000027480 0001 00000000 0x0 0x0
0xffffd80000027500 0001 00000000 0x0 0x0
0xffffd80000027580 0001 00000000 0x0 0x0
0xffffd80000027600 0001 00000000 0x0 0x0
0xffffd80000027680 0001 00000000 0x0 0x0
0xffffd80000027700 0001 00000000 0x0 0x0
0xffffd80000027780 0001 00000000 0x0 0x0
0xffffd80000027800 0001 00000000 0x0 0x0
0xffffd80000027880 0001 00000000 0x0 0x0
0xffffd80000027900 0001 00000000 0x0 0x0
0xffffd80000027980 0001 00000000 0x0 0x0
0xffffd80000027a00 0001 00000000 0x0 0x0
0xffffd80000027a80 0001 00000000 0x0 0x0
0xffffd80000027b00 0001 00000000 0x0 0x0
0xffffd80000027b80 0001 00000000 0x0 0x0
0xffffd80000027c00 0001 00000000 0x0 0x0
0xffffd80000027c80 0001 00000000 0x0 0x0
0xffffd80000027d00 0001 00000000 0x0 0x0
0xffffd80000027d80 0001 00000000 0x0 0x0
0xffffd80000027e00 0001 00000000 0x0 0x0
0xffffd80000027e80 0001 00000000 0x0 0x0
0xffffd80000027f00 0001 00000000 0x0 0x0
0xffffd80000027f80 0001 00000000 0x0 0x0
0xffffd80000028000 0001 00000000 0x0 0x0
0xffffd80000028080 0001 00000000 0x0 0x0
0xffffd80000028100 0001 00000000 0x0 0x0
0xffffd80000028180 0001 00000000 0x0 0x0
0xffffd80000028200 0001 00000000 0x0 0x0
0xffffd80000028280 0001 00000000 0x0 0x0
0xffffd80000028300 0001 00000000 0x0 0x0
0xffffd80000028380 0001 00000000 0x0 0x0
0xffffd80000028400 0001 00000000 0x0 0x0
0xffffd80000028480 0001 00000000 0x0 0x0
0xffffd80000028500 0001 00000000 0x0 0x0
0xffffd80000028580 0001 00000000 0x0 0x0
0xffffd80000028600 0001 00000000 0x0 0x0
0xffffd80000028680 0001 00000000 0x0 0x0
0xffffd80000028700 0001 00000000 0x0 0x0
0xffffd80000028780 0001 00000000 0x0 0x0
0xffffd80000028800 0001 00000000 0x0 0x0
0xffffd80000028880 0001 00000000 0x0 0x0
0xffffd80000028900 0001 00000000 0x0 0x0
0xffffd80000028980 0001 00000000 0x0 0x0
0xffffd80000028a00 0001 00000000 0x0 0x0
0xffffd80000028a80 0001 00000000 0x0 0x0
0xffffd80000028b00 0001 00000000 0x0 0x0
0xffffd80000028b80 0001 00000000 0x0 0x0
0xffffd80000028c00 0001 00000000 0x0 0x0
0xffffd80000028c80 0001 00000000 0x0 0x0
0xffffd80000028d00 0001 00000000 0x0 0x0
0xffffd80000028d80 0001 00000000 0x0 0x0
0xffffd80000028e00 0001 00000000 0x0 0x0
0xffffd80000028e80 0001 00000000 0x0 0x0
0xffffd80000028f00 0001 00000000 0x0 0x0
0xffffd80000028f80 0001 00000000 0x0 0x0
0xffffd80000029000 0001 00000000 0x0 0x0
0xffffd80000029080 0001 00000000 0x0 0x0
0xffffd80000029100 0001 00000000 0x0 0x0
0xffffd80000029180 0001 00000000 0x0 0x0
0xffffd80000029200 0001 00000000 0x0 0x0
0xffffd80000029280 0001 00000000 0x0 0x0
0xffffd80000029300 0001 00000000 0x0 0x0
0xffffd80000029380 0001 00000000 0x0 0x0
0xffffd80000029400 0001 00000000 0x0 0x0
0xffffd80000029480 0001 00000000 0x0 0x0
0xffffd80000029500 0001 00000000 0x0 0x0
0xffffd80000029580 0001 00000000 0x0 0x0
0xffffd80000029600 0001 00000000 0x0 0x0
0xffffd80000029680 0001 00000000 0x0 0x0
0xffffd80000029700 0001 00000000 0x0 0x0
0xffffd80000029780 0001 00000000 0x0 0x0
0xffffd80000029800 0001 00000000 0x0 0x0
0xffffd80000029880 0001 00000000 0x0 0x0
0xffffd80000029900 0001 00000000 0x0 0x0
0xffffd80000029980 0001 00000000 0x0 0x0
0xffffd80000029a00 0001 00000000 0x0 0x0
0xffffd80000029a80 0001 00000000 0x0 0x0
0xffffd80000029b00 0001 00000000 0x0 0x0
0xffffd80000029b80 0001 00000000 0x0 0x0
0xffffd80000029c00 0001 00000000 0x0 0x0
0xffffd80000029c80 0001 00000000 0x0 0x0
0xffffd80000029d00 0001 00000000 0x0 0x0
0xffffd80000029d80 0001 00000000 0x0 0x0
0xffffd80000029e00 0001 00000000 0x0 0x0
0xffffd80000029e80 0001 00000000 0x0 0x0
0xffffd80000029f00 0001 00000000 0x0 0x0
0xffffd80000029f80 0001 00000000 0x0 0x0
0xffffd8000002a000 0001 00000000 0x0 0x0
0xffffd8000002a080 0001 00000000 0x0 0x0
0xffffd8000002a100 0001 00000000 0x0 0x0
0xffffd8000002a180 0001 00000000 0x0 0x0
0xffffd8000002a200 0001 00000000 0x0 0x0
0xffffd8000002a280 0001 00000000 0x0 0x0
0xffffd8000002a300 0001 00000000 0x0 0x0
0xffffd8000002a380 0001 00000000 0x0 0x0
0xffffd8000002a400 0001 00000000 0x0 0x0
0xffffd8000002a480 0001 00000000 0x0 0x0
0xffffd8000002a500 0001 00000000 0x0 0x0
0xffffd8000002a580 0001 00000000 0x0 0x0
0xffffd8000002a600 0001 00000000 0x0 0x0
0xffffd8000002a680 0001 00000000 0x0 0x0
0xffffd8000002a700 0001 00000000 0x0 0x0
0xffffd8000002a780 0001 00000000 0x0 0x0
0xffffd8000002a800 0001 00000000 0x0 0x0
0xffffd8000002a880 0001 00000000 0x0 0x0
0xffffd8000002a900 0001 00000000 0x0 0x0
0xffffd8000002a980 0001 00000000 0x0 0x0
0xffffd8000002aa00 0001 00000000 0x0 0x0
0xffffd8000002aa80 0001 00000000 0x0 0x0
0xffffd8000002ab00 0001 00000000 0x0 0x0
0xffffd8000002ab80 0001 00000000 0x0 0x0
0xffffd8000002ac00 0001 00000000 0x0 0x0
0xffffd8000002ac80 0001 00000000 0x0 0x0
0xffffd8000002ad00 0001 00000000 0x0 0x0
0xffffd8000002ad80 0001 00000000 0x0 0x0
0xffffd8000002ae00 0001 00000000 0x0 0x0
0xffffd8000002ae80 0001 00000000 0x0 0x0
0xffffd8000002af00 0001 00000000 0x0 0x0
0xffffd8000002af80 0001 00000000 0x0 0x0
0xffffd8000002b000 0001 00000000 0x0 0x0
0xffffd8000002b080 0001 00000000 0x0 0x0
0xffffd8000002b100 0001 00000000 0x0 0x0
0xffffd8000002b180 0001 00000000 0x0 0x0
0xffffd8000002b200 0001 00000000 0x0 0x0
0xffffd8000002b280 0001 00000000 0x0 0x0
0xffffd8000002b300 0001 00000000 0x0 0x0
0xffffd8000002b380 0001 00000000 0x0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Dec 12, 2023, 3:44:12 AM12/12/23
to syzkaller-...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages