assert failed: (cnp->cn_flags & LOCKPARENT) == NUM || searchdir == NULL || VOP_ISLOCKED(searchdir) == LK_EXCLUSIVE (2)

0 views
Skip to first unread message

syzbot

unread,
Aug 1, 2022, 7:40:26 AM8/1/22
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 5ac4b360b0d1 ms_wscons_ioctl(): Return EPASSTHROUGH instea..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=152223e2080000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=14b74b24f1b909a53c02
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+14b74b...@syzkaller.appspotmail.com

[ 90.9378113] panic: kernel diagnostic assertion "(cnp->cn_flags & LOCKPARENT) == 0 || searchdir == NULL || VOP_ISLOCKED(searchdir) == LK_EXCLUSIVE" failed: file "/syzkaller/managers/ci2-netbsd/kernel/sys/kern/vfs_lookup.c", line 1744
[ 90.9577952] cpu1: Begin traceback...
[ 90.9777963] vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:293
[ 91.0177976] _sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x34c4
[ 91.0577982] namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 namei_oneroot sys/kern/vfs_lookup.c:1747 [inline]
[ 91.0577982] namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 sys/kern/vfs_lookup.c:1919
[ 91.1077960] namei() at netbsd:namei+0x6a sys/kern/vfs_lookup.c:1955
[ 91.1477990] vn_open() at netbsd:vn_open+0x326 sys/kern/vfs_vnops.c:219
[ 91.1877964] do_open() at netbsd:do_open+0x235 sys/kern/vfs_syscalls.c:1752
[ 91.2277966] do_sys_openat() at netbsd:do_sys_openat+0x160 sys/kern/vfs_syscalls.c:1837
[ 91.2777972] sys_open() at netbsd:sys_open+0x9a sys/kern/vfs_syscalls.c:1858
[ 91.3177975] sys___syscall() at netbsd:sys___syscall+0x10e sy_call sys/sys/syscallvar.h:65 [inline]
[ 91.3177975] sys___syscall() at netbsd:sys___syscall+0x10e sys/kern/sys_syscall.c:90
[ 91.3577969] syscall() at netbsd:syscall+0x25a sy_call sys/sys/syscallvar.h:65 [inline]
[ 91.3577969] syscall() at netbsd:syscall+0x25a sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 91.3577969] syscall() at netbsd:syscall+0x25a sys/arch/x86/x86/syscall.c:138
[ 91.3677980] --- syscall (number 5 via SYS_syscall) ---
[ 91.3877982] netbsd:syscall+0x25a:
[ 91.3877982] cpu1: End traceback...
[ 91.3977969] fatal breakpoint trap in supervisor mode
[ 91.3977969] trap type 1 code 0 rip 0xffffffff80220a4d cs 0x8 rflags 0x282 cr2 0x7ac1e81f4c5c ilevel 0 rsp 0xffff9981a6d2c4c0
[ 91.4077959] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2bfe0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2bb00
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2b620
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2b140
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2ac60
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2a780
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d2a2a0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d29dc0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d298e0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d29400
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d28f20
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d28a40
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d28560
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d28080
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff9981a6d27ba0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] fatal double fault in supervisor mode
[ 91.4177949] trap type 13 code 0 rip 0xffffffff81b36bfd cs 0x8 rflags 0x10286 cr2 0xffff9981a6d26f98 ilevel 0x8 rsp 0xffff9981a6d26fa0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: double fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10083 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184debc40
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184deb760
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184deb280
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184deada0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184dea8c0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184dea3e0
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184de9f00
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184de9a20
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184de9540
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184de9060
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
[ 91.4177949] uvm_fault(0xffff998013440618, 0xffff900000000000, 1) -> e
[ 91.4177949] fatal page fault in supervisor mode
[ 91.4177949] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffff998184de8b80
[ 91.4177949] curlwp 0xffff998012974680 pid 3677.4028 lowest kstack 0xffff9981a6d252c0
kernel: page fault trap, code=0
SeaBIOS (version 1.8.2-google)
Total RAM Size = 0x0000000200000000 = 8192 MiB
CPUs found: 2 Max CPUs supported: 2
SeaBIOS (version 1.8.2-google)
Machine UUID d032601e-3e21-4f7d-191d-42e6a16de6a7
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0 removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f2490: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Sending Seabios boot VM event.
Booting from Hard Disk 0...

>> NetBSD/x86 BIOS Boot, Revision 5.11 (Thu Jun 11 19:20:47 UTC 2020) (from NetBSD 9.99.65)
>> Memory: 639/3144640 k

1. Boot normally
2. Boot single user
3. Drop to boot prompt

Choose an option; RETURN for default; SPACE to stop countdown.
Option 1 will be chosen in 5 seconds. 4 seconds. 3 seconds. 2 seconds. 1 seconds. 0 seconds. 0 seconds.
command(s): rndseed /var/db/entropy-file;boot
default boot twice, skipping...
| / - \ | / - \ 53007488| / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | +1518464/ - \ | / - [1518312\ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | +991118/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | ]=0x3665570
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | Loading /var/db/entropy-file
[ 1.0000000] cpu_rng: rdrand/rdseed
[ 1.0000000] entropy: ready
[ 1.0000000] entropy: entering seed from bootloader with 256 bits of entropy


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Aug 1, 2022, 7:59:22 AM8/1/22
to syzkaller-...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 5ac4b360b0d1 ms_wscons_ioctl(): Return EPASSTHROUGH instea..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10413536080000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=14b74b24f1b909a53c02
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1256d846080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+14b74b...@syzkaller.appspotmail.com

[ 42.8959795] panic: kernel diagnostic assertion "(cnp->cn_flags & LOCKPARENT) == 0 || searchdir == NULL || VOP_ISLOCKED(searchdir) == LK_EXCLUSIVE" failed: file "/syzkaller/managers/ci2-netbsd/kernel/sys/kern/vfs_lookup.c", line 1744
[ 42.9159801] cpu1: Begin traceback...
[ 42.9359714] vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:293
[ 42.9659746] _sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x34c4
[ 42.9959708] namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 namei_oneroot sys/kern/vfs_lookup.c:1747 [inline]
[ 42.9959708] namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 sys/kern/vfs_lookup.c:1919
[ 43.0359709] namei() at netbsd:namei+0x6a sys/kern/vfs_lookup.c:1955
[ 43.0659713] vn_open() at netbsd:vn_open+0x326 sys/kern/vfs_vnops.c:219
[ 43.0959721] do_open() at netbsd:do_open+0x235 sys/kern/vfs_syscalls.c:1752
[ 43.1259717] do_sys_openat() at netbsd:do_sys_openat+0x160 sys/kern/vfs_syscalls.c:1837
[ 43.1659731] sys_open() at netbsd:sys_open+0x9a sys/kern/vfs_syscalls.c:1858
[ 43.1959718] sys___syscall() at netbsd:sys___syscall+0x10e sy_call sys/sys/syscallvar.h:65 [inline]
[ 43.1959718] sys___syscall() at netbsd:sys___syscall+0x10e sys/kern/sys_syscall.c:90
[ 43.2259725] syscall() at netbsd:syscall+0x25a sy_call sys/sys/syscallvar.h:65 [inline]
[ 43.2259725] syscall() at netbsd:syscall+0x25a sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 43.2259725] syscall() at netbsd:syscall+0x25a sys/arch/x86/x86/syscall.c:138
[ 43.2359713] --- syscall (number 5 via SYS_syscall) ---
[ 43.2459709] netbsd:syscall+0x25a:
[ 43.2559717] cpu1: End traceback...
[ 43.2559717] fatal breakpoint trap in supervisor mode
[ 43.2659695] trap type 1 code 0 rip 0xffffffff80220a4d cs 0x8 rflags 0x282 cr2 0x63e060 ilevel 0 rsp 0xffffdf019db474c0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db46fe0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db46b00
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db46620
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db46140
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db45c60
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db45780
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db452a0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db44dc0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db448e0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db44400
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db43f20
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db43a40
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db43560
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db43080
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf019db42ba0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] fatal double fault in supervisor mode
[ 43.2759685] trap type 13 code 0 rip 0xffffffff81b36bfd cs 0x8 rflags 0x10286 cr2 0xffffdf019db41f98 ilevel 0x8 rsp 0xffffdf019db41fa0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: double fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10083 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184debc40
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184deb760
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184deb280
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184deada0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184dea8c0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184dea3e0
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184de9f00
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184de9a20
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184de9540
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184de9060
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
[ 43.2759685] uvm_fault(0xffffdf0012cf6a10, 0xffff900000000000, 1) -> e
[ 43.2759685] fatal page fault in supervisor mode
[ 43.2759685] trap type 6 code 0 rip 0xffffffff81b8407b cs 0x8 rflags 0x10283 cr2 0xffff90000000003d ilevel 0x8 rsp 0xffffdf0184de8b80
[ 43.2759685] curlwp 0xffffdf0012ca7580 pid 1352.1075 lowest kstack 0xffffdf019db402c0
kernel: page fault trap, code=0
SeaBIOS (version 1.8.2-google)
Total RAM Size = 0x0000000200000000 = 8192 MiB
CPUs found: 2 Max CPUs supported: 2
SeaBIOS (version 1.8.2-google)
Machine UUID 4c614fef-0d9b-71e9-867c-db19c1491eb8

syzbot

unread,
Aug 2, 2022, 4:49:35 PM8/2/22
to syzkaller-...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 4b97c2317f82 genfb: Handle uninitialized softc in genfb_en..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=106562c1080000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=14b74b24f1b909a53c02
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=163290b6080000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12a80b0e080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+14b74b...@syzkaller.appspotmail.com

[ 73.0012870] panic: kernel diagnostic assertion "(cnp->cn_flags & LOCKPARENT) == 0 || searchdir == NULL || VOP_ISLOCKED(searchdir) == LK_EXCLUSIVE" failed: file "/syzkaller/managers/ci2-netbsd/kernel/sys/kern/vfs_lookup.c", line 1744
[ 73.0012870] cpu0: Begin traceback...
[ 73.0112813] vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:293
[ 73.0412825] _sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x34c4
[ 73.0712812] namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 namei_oneroot sys/kern/vfs_lookup.c:1747 [inline]
[ 73.0712812] namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 sys/kern/vfs_lookup.c:1919
[ 73.1012823] namei() at netbsd:namei+0x6a sys/kern/vfs_lookup.c:1955
[ 73.1312824] vn_open() at netbsd:vn_open+0x326 sys/kern/vfs_vnops.c:219
[ 73.1612787] do_open() at netbsd:do_open+0x235 sys/kern/vfs_syscalls.c:1752
[ 73.1912810] do_sys_openat() at netbsd:do_sys_openat+0x160 sys/kern/vfs_syscalls.c:1837
[ 73.2212810] sys_open() at netbsd:sys_open+0x9a sys/kern/vfs_syscalls.c:1858
[ 73.2412820] sys_syscall() at netbsd:sys_syscall+0x10e sy_call sys/sys/syscallvar.h:65 [inline]
[ 73.2412820] sys_syscall() at netbsd:sys_syscall+0x10e sys/kern/sys_syscall.c:90
[ 73.2712801] syscall() at netbsd:syscall+0x25a sy_call sys/sys/syscallvar.h:65 [inline]
[ 73.2712801] syscall() at netbsd:syscall+0x25a sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 73.2712801] syscall() at netbsd:syscall+0x25a sys/arch/x86/x86/syscall.c:138
[ 73.2825144] --- syscall (number 5 via SYS_syscall) ---
[ 73.3012791] netbsd:syscall+0x25a:
[ 73.3012791] cpu0: End traceback...
[ 73.3012791] fatal breakpoint trap in supervisor mode
[ 73.3117138] trap type 1 code 0 rip 0xffffffff80220a4d cs 0x8 rflags 0x282 cr2 0x760db337cff0 ilevel 0 rsp 0xffffc4819db294c0
[ 73.3247202] curlwp 0xffffc48013cd4600 pid 972.972 lowest kstack 0xffffc4819db222c0
Stopped in pid 972.972 (syz-executor1745) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0x105 sys/ddb/db_panic.c:69
vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:293
_sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x34c4
namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 namei_oneroot sys/kern/vfs_lookup.c:1747 [inline]
namei_tryemulroot() at netbsd:namei_tryemulroot+0x1714 sys/kern/vfs_lookup.c:1919
namei() at netbsd:namei+0x6a sys/kern/vfs_lookup.c:1955
vn_open() at netbsd:vn_open+0x326 sys/kern/vfs_vnops.c:219
do_open() at netbsd:do_open+0x235 sys/kern/vfs_syscalls.c:1752
do_sys_openat() at netbsd:do_sys_openat+0x160 sys/kern/vfs_syscalls.c:1837
sys_open() at netbsd:sys_open+0x9a sys/kern/vfs_syscalls.c:1858
sys_syscall() at netbsd:sys_syscall+0x10e sy_call sys/sys/syscallvar.h:65 [inline]
sys_syscall() at netbsd:sys_syscall+0x10e sys/kern/sys_syscall.c:90
syscall() at netbsd:syscall+0x25a sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x25a sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x25a sys/arch/x86/x86/syscall.c:138
--- syscall (number 5 via SYS_syscall) ---
netbsd:syscall+0x25a:
Panic string: kernel diagnostic assertion "(cnp->cn_flags & LOCKPARENT) == 0 || searchdir == NULL || VOP_ISLOCKED(searchdir) == LK_EXCLUSIVE" failed: file "/syzkaller/managers/ci2-netbsd/kernel/sys/kern/vfs_lookup.c", line 1744
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
1227 1227 2 0 0 ffffc48013cff200 syz-executor1745
1023 1023 2 0 0 ffffc48013cd4a40 syz-executor1745
972 > 972 7 0 0 ffffc48013cd4600 syz-executor1745
1086 1086 3 1 0 ffffc48013cd41c0 syz-executor1745 tstile
1222 1222 3 1 0 ffffc480134729c0 syz-executor1745 tstile
1224 1224 2 0 0 ffffc48013472580 syz-executor1745
1075 >1075 7 1 0 ffffc48013472140 syz-executor1745
1223 1223 2 1 0 ffffc48013c32a00 syz-executor1745
1078 1078 2 0 140 ffffc48013c325c0 syz-executor1745
733 733 2 1 140 ffffc4801344f980 syz-executor1745
1220 1220 2 0 140 ffffc480126c7b80 syz-executor1745
1195 1195 3 0 40180 ffffc48012b420c0 syz-executor1745 nanoslp
1194 1194 3 0 180 ffffc48013375a00 sshd select
1069 1069 3 0 180 ffffc4801338fa40 getty nanoslp
1074 1074 3 1 180 ffffc4801339ca80 getty nanoslp
1070 1070 3 0 180 ffffc4801339c640 getty nanoslp
1259 1259 3 0 1c0 ffffc480126ca040 getty ttyraw
926 926 3 1 180 ffffc4801338f600 sshd select
949 949 3 1 180 ffffc48012cfa280 powerd kqueue
689 689 3 1 180 ffffc480133c7b00 syslogd kqueue
602 602 3 0 180 ffffc48012c17700 dhcpcd poll
547 547 3 0 180 ffffc48012c8c900 dhcpcd poll
546 546 3 0 180 ffffc48012c4db80 dhcpcd poll
589 589 3 1 180 ffffc48012c5d340 dhcpcd poll
289 289 3 0 180 ffffc48012d8e080 dhcpcd poll
288 288 3 0 180 ffffc48012d748c0 dhcpcd poll
351 351 3 0 180 ffffc48012d74480 dhcpcd poll
1 1 3 0 180 ffffc4801285b9c0 init wait
0 965 3 0 200 ffffc48012974ac0 physiod physiod
0 194 3 0 200 ffffc4801298bb00 pooldrain pooldrain
0 193 3 0 200 ffffc4801298b6c0 ioflush syncer
0 192 3 1 200 ffffc4801298b280 pgdaemon pgdaemon
0 169 3 1 200 ffffc48012974240 usb7 usbevt
0 167 3 0 200 ffffc4801292ea80 usb6 usbevt
0 165 3 1 200 ffffc4801292e640 usb5 usbevt
0 164 3 1 200 ffffc4801292e200 usb4 usbevt
0 31 3 1 200 ffffc480128e1a40 usb3 usbevt
0 63 3 1 200 ffffc480128e1600 usb2 usbevt
0 126 3 1 200 ffffc480128e11c0 usb1 usbevt
0 125 3 1 200 ffffc480128bfa00 usb0 usbevt
0 124 3 1 200 ffffc480128bf5c0 usbtask-dr usbtsk
0 123 3 1 200 ffffc480128bf180 usbtask-hc usbtsk
0 122 3 0 200 ffffc480120b66c0 npfgc0 npfgcw
0 121 3 1 200 ffffc4801285b580 rt_free rt_free
0 120 3 1 200 ffffc4801285b140 unpgc unpgc
0 119 3 0 200 ffffc48012854980 key_timehandler key_timehandler
0 118 3 1 200 ffffc48012854540 icmp6_wqinput/1 icmp6_wqinput
0 117 3 0 200 ffffc48012854100 icmp6_wqinput/0 icmp6_wqinput
0 116 3 0 200 ffffc480126f4940 nd6_timer nd6_timer
0 115 3 1 200 ffffc480126f4500 carp6_wqinput/1 carp6_wqinput
0 114 3 0 200 ffffc480126f40c0 carp6_wqinput/0 carp6_wqinput
0 113 3 1 200 ffffc480126e5900 carp_wqinput/1 carp_wqinput
0 112 3 0 200 ffffc480126e54c0 carp_wqinput/0 carp_wqinput
0 111 3 1 200 ffffc480126e5080 icmp_wqinput/1 icmp_wqinput
0 110 3 0 200 ffffc480126ca8c0 icmp_wqinput/0 icmp_wqinput
0 109 3 0 200 ffffc480126ca480 rt_timer rt_timer
0 108 3 0 200 ffffc480126c9bc0 vmem_rehash vmem_rehash
0 99 3 0 200 ffffc480120bbb40 entbutler entropy
0 98 3 1 200 ffffc480120bb700 viomb balloon
0 97 3 1 200 ffffc480120bb2c0 vioif0_txrx/1 vioif0_txrx
0 96 3 0 200 ffffc480120b6b00 vioif0_txrx/0 vioif0_txrx
0 29 3 0 200 ffffc480120b6280 scsibus0 sccomp
0 28 3 0 200 ffffc48010cbaac0 pms0 pmsreset
0 27 3 1 200 ffffc48010cba680 xcall/1 xcall
0 26 1 1 200 ffffc48010cba240 softser/1
0 25 1 1 200 ffffc48010cb9a80 softclk/1
0 24 1 1 200 ffffc48010cb9640 softbio/1
0 23 1 1 200 ffffc48010cb9200 softnet/1
0 22 1 1 201 ffffc4800fb55a40 idle/1
0 21 3 0 200 ffffc4800fb55600 lnxsyswq lnxsyswq
0 20 3 0 200 ffffc4800fb551c0 lnxubdwq lnxubdwq
0 19 3 0 200 ffffc4800fb54a00 lnxpwrwq lnxpwrwq
0 18 3 0 200 ffffc4800fb545c0 lnxlngwq lnxlngwq
0 17 3 0 200 ffffc4800fb54180 lnxhipwq lnxhipwq
0 16 3 0 200 ffffc4800fb4b9c0 lnxrcugc lnxrcugc
0 15 3 0 200 ffffc4800fb4b580 sysmon smtaskq
0 14 3 0 200 ffffc4800fb4b140 pmfsuspend pmfsuspend
0 13 3 0 200 ffffc4800fb48980 pmfevent pmfevent
0 12 3 0 200 ffffc4800fb48540 sopendfree sopendfr
0 11 3 0 200 ffffc4800fb48100 iflnkst iflnkst
0 10 3 0 200 ffffc4800fb3c940 nfssilly nfssilly
0 9 3 0 200 ffffc4800fb3c500 vdrain vdrain
0 8 3 0 200 ffffc4800fb3c0c0 modunload mod_unld
0 7 3 0 200 ffffc4800fb33900 xcall/0 xcall
0 6 1 0 200 ffffc4800fb334c0 softser/0
0 5 1 0 200 ffffc4800fb33080 softclk/0
0 4 1 0 200 ffffc4800fb318c0 softbio/0
0 3 1 0 200 ffffc4800fb31480 softnet/0
0 2 1 0 201 ffffc4800fb31040 idle/0
0 0 3 0 200 ffffffff83341600 swapper uvm
[Locks tracked through LWPs]

****** LWP 1086.1086 (syz-executor1745) @ 0xffffc48013cd41c0, l_stat=3

*** Locks held:

* Lock 0 (initialized at fstrans_init)
lock address : 0xffffffff8348ab80 type : sleep/adaptive
initialized : 0xffffffff81ca0ef1
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013cd41c0 last held: 0xffffc48013cd41c0
last locked* : 0xffffffff81ca3418 unlocked : 0xffffffff81c87197
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at vfs_mountalloc)
lock address : 0xffffc48013cec2c0 type : sleep/adaptive
initialized : 0xffffffff81c832a2
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013cd41c0 last held: 0xffffc48013cd41c0
last locked* : 0xffffffff81c86919 unlocked : 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 2 (initialized at vcache_alloc)
lock address : 0xffffc48013caff40 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013cd41c0 last held: 0xffffc48013cd41c0
last locked* : 0xffffffff81cdbd06 unlocked : 0xffffffff81cdbd68
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1222.1222 (syz-executor1745) @ 0xffffc480134729c0, l_stat=3

*** Locks held:

* Lock 0 (initialized at vcache_alloc)
lock address : 0xffffc48013cc4200 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc480134729c0 last held: 0xffffc480134729c0
last locked* : 0xffffffff81cdbd06 unlocked : 0xffffffff81cdbd68
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at vcache_alloc)
lock address : 0xffffc48013ceb240 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc480134729c0 last held: 0xffffc480134729c0
last locked* : 0xffffffff81cdbcd0 unlocked : 0xffffffff81cdbd68
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1224.1224 (syz-executor1745) @ 0xffffc48013472580, l_stat=2

*** Locks held:

* Lock 0 (initialized at pmap_ctor)
lock address : 0xffffc4801347bd80 type : sleep/adaptive
initialized : 0xffffffff80956139
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc48013472580 last held: 0xffffc48013472580
last locked* : 0xffffffff80957f6c unlocked : 0xffffffff80956001
owner field : 0xffffc48013472580 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1075.1075 (syz-executor1745) @ 0xffffc48013472140, l_stat=7

*** Locks held:

* Lock 0 (initialized at vcache_alloc)
lock address : 0xffffc48013cc4980 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013472140 last held: 0xffffc48013472140
last locked* : 0xffffffff81cdbd06 unlocked : 0xffffffff81cdbd68
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at vcache_alloc)
lock address : 0xffffc48013cc4e80 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013472140 last held: 0xffffc48013472140
last locked* : 0xffffffff81cdbd06 unlocked : 000000000000000000
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1223.1223 (syz-executor1745) @ 0xffffc48013c32a00, l_stat=2

*** Locks held:

* Lock 0 (initialized at vcache_alloc)
lock address : 0xffffc48013cc4c00 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013c32a00 last held: 0xffffc48013c32a00
last locked* : 0xffffffff81cdbd06 unlocked : 0xffffffff81cdbd68
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at vcache_alloc)
lock address : 0xffffc48013ceb9c0 type : sleep/adaptive
initialized : 0xffffffff81ca5730
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc48013c32a00 last held: 0xffffc48013c32a00
last locked* : 0xffffffff81cdbd06 unlocked : 000000000000000000
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 689.689 (syslogd) @ 0xffffc480133c7b00, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at fork1)
lock address : 0xffffc48013b94780 type : sleep/adaptive
initialized : 0xffffffff81af28da
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc480133c7b00 last held: 000000000000000000
last locked : 0xffffffff81c03a90 unlocked*: 0xffffffff81c03aff
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 547.547 (dhcpcd) @ 0xffffc48012c8c900, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc48012c8c900 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 546.546 (dhcpcd) @ 0xffffc48012c4db80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc48012c4db80 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 288.288 (dhcpcd) @ 0xffffc48012d748c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc48012d748c0 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 351.351 (dhcpcd) @ 0xffffc48012d74480, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc48012d74480 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffffc4800fb48100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc4800fb48100 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffffc4800fb33080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc4800fb33080 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff83341600, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83480a80 type : sleep/adaptive
initialized : 0xffffffff81b10cb1
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff83341600 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu0:

* Lock 0 (initialized at kprintf_init)
lock address : 0xffffffff8358bea0 type : spin
initialized : 0xffffffff81bc3115
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc48013cd4600 last held: 0xffffc48013cd4600
last locked* : 0xffffffff81bc3186 unlocked : 0xffffffff81bc31e4
owner field : 0x0000000000000800 wait/spin: 0/1

PAGE FLAG PQ UOBJECT UANON
0xffffc48000017180 0041 00000000 0x0 0x0
0xffffc48000017200 0041 00000000 0x0 0x0
0xffffc48000017280 0041 00000000 0x0 0x0
0xffffc48000017300 0041 00000000 0x0 0x0
0xffffc48000017380 0041 00000000 0x0 0x0
0xffffc48000017400 0041 00000000 0x0 0x0
0xffffc48000017480 0041 00000000 0x0 0x0
0xffffc48000017500 0041 00000000 0x0 0x0
0xffffc48000017580 0041 00000000 0x0 0x0
0xffffc48000017600 0041 00000000 0x0 0x0
0xffffc48000017680 0041 00000000 0x0 0x0
0xffffc48000017700 0041 00000000 0x0 0x0
0xffffc48000017780 0041 00000000 0x0 0x0
0xffffc48000017800 0041 00000000 0x0 0x0
0xffffc48000017880 0041 00000000 0x0 0x0
0xffffc48000017900 0041 00000000 0x0 0x0
0xffffc48000017980 0041 00000000 0x0 0x0
0xffffc48000017a00 0041 00000000 0x0 0x0
0xffffc48000017a80 0041 00000000 0x0 0x0
0xffffc48000017b00 0041 00000000 0x0 0x0
0xffffc48000017b80 0041 00000000 0x0 0x0
0xffffc48000017c00 0041 00000000 0x0 0x0
0xffffc48000017c80 0041 00000000 0x0 0x0
0xffffc48000017d00 0041 00000000 0x0 0x0
0xffffc48000017d80 0041 00000000 0x0 0x0
0xffffc48000017e00 0041 00000000 0x0 0x0
0xffffc48000017e80 0041 00000000 0x0 0x0
0xffffc48000017f00 0041 00000000 0x0 0x0
0xffffc48000017f80 0041 00000000 0x0 0x0
0xffffc48000018000 0041 00000000 0x0 0x0
0xffffc48000018080 0041 00000000 0x0 0x0
0xffffc48000018100 0041 00000000 0x0 0x0
0xffffc48000018180 0041 00000000 0x0 0x0
0xffffc48000018200 0041 00000000 0x0 0x0
0xffffc48000018280 0041 00000000 0x0 0x0
0xffffc48000018300 0041 00000000 0x0 0x0
0xffffc48000018380 0041 00000000 0x0 0x0
0xffffc48000018400 0041 00000000 0x0 0x0
0xffffc48000018480 0041 00000000 0x0 0x0
0xffffc48000018500 0041 00000000 0x0 0x0
0xffffc48000018580 0041 00000000 0x0 0x0
0xffffc48000018600 0041 00000000 0x0 0x0
0xffffc48000018680 0041 00000000 0x0 0x0
0xffffc48000018700 0041 00000000 0x0 0x0
0xffffc48000018780 0041 00000000 0x0 0x0
0xffffc48000018800 0041 00000000 0x0 0x0
0xffffc48000018880 0041 00000000 0x0 0x0
0xffffc48000018900 0041 00000000 0x0 0x0
0xffffc48000018980 0041 00000000 0x0 0x0
0xffffc48000018a00 0041 00000000 0x0 0x0
0xffffc48000018a80 0041 00000000 0x0 0x0
0xffffc48000018b00 0041 00000000 0x0 0x0
0xffffc48000018b80 0041 00000000 0x0 0x0
0xffffc48000018c00 0041 00000000 0x0 0x0
0xffffc48000018c80 0041 00000000 0x0 0x0
0xffffc48000018d00 0041 00000000 0x0 0x0
0xffffc48000018d80 0041 00000000 0x0 0x0
0xffffc48000018e00 0041 00000000 0x0 0x0
0xffffc48000018e80 0041 00000000 0x0 0x0
0xffffc48000018f00 0041 00000000 0x0 0x0
0xffffc48000018f80 0041 00000000 0x0 0x0
0xffffc48000019000 0041 00000000 0x0 0x0
0xffffc48000019080 0041 00000000 0x0 0x0
0xffffc48000019100 0041 00000000 0x0 0x0
0xffffc48000019180 0041 00000000 0x0 0x0
0xffffc48000019200 0041 00000000 0x0 0x0
0xffffc48000019280 0041 00000000 0x0 0x0
0xffffc48000019300 0041 00000000 0x0 0x0
0xffffc48000019380 0041 00000000 0x0 0x0
0xffffc48000019400 0041 00000000 0x0 0x0
0xffffc48000019480 0041 00000000 0x0 0x0
0xffffc48000019500 0041 00000000 0x0 0x0
0xffffc48000019580 0041 00000000 0x0 0x0
0xffffc48000019600 0041 00000000 0x0 0x0
0xffffc48000019680 0041 00000000 0x0 0x0
0xffffc48000019700 0041 00000000 0x0 0x0
0xffffc48000019780 0041 00000000 0x0 0x0
0xffffc48000019800 0041 00000000 0x0 0x0
0xffffc48000019880 0041 00000000 0x0 0x0
0xffffc48000019900 0041 00000000 0x0 0x0
0xffffc48000019980 0041 00000000 0x0 0x0
0xffffc48000019a00 0041 00000000 0x0 0x0
0xffffc48000019a80 0041 00000000 0x0 0x0
0xffffc48000019b00 0041 00000000 0x0 0x0
0xffffc48000019b80 0041 00000000 0x0 0x0
0xffffc48000019c00 0041 00000000 0x0 0x0
0xffffc48000019c80 0041 00000000 0x0 0x0
0xffffc48000019d00 0041 00000000 0x0 0x0
0xffffc48000019d80 0041 00000000 0x0 0x0
0xffffc48000019e00 0041 00000000 0x0 0x0
0xffffc48000019e80 0041 00000000 0x0 0x0
0xffffc48000019f00 0041 00000000 0x0 0x0
0xffffc48000019f80 0041 00000000 0x0 0x0
0xffffc4800001a000 0041 00000000 0x0 0x0
0xffffc4800001a080 0041 00000000 0x0 0x0
0xffffc4800001a100 0041 00000000 0x0 0x0
0xffffc4800001a180 0041 00000000 0x0 0x0
0xffffc4800001a200 0041 00000000 0x0 0x0
0xffffc4800001a280 0041 00000000 0x0 0x0
0xffffc4800001a300 0041 00000000 0x0 0x0
0xffffc4800001a380 0041 00000000 0x0 0x0
0xffffc4800001a400 0041 00000000 0x0 0x0
0xffffc4800001a480 0041 00000000 0x0 0x0
0xffffc4800001a500 0041 00000000 0x0 0x0
0xffffc4800001a580 0041 00000000 0x0 0x0
0xffffc4800001a600 0041 00000000 0x0 0x0
0xffffc4800001a680 0041 00000000 0x0 0x0
0xffffc4800001a700 0041 00000000 0x0 0x0
0xffffc4800001a780 0041 00000000 0x0 0x0
0xffffc4800001a800 0041 00000000 0x0 0x0
0xffffc4800001a880 0041 00000000 0x0 0x0
0xffffc4800001a900 0041 00000000 0x0 0x0
0xffffc4800001a980 0041 00000000 0x0 0x0
0xffffc4800001aa00 0041 00000000 0x0 0x0
0xffffc4800001aa80 0041 00000000 0x0 0x0
0xffffc4800001ab00 0041 00000000 0x0 0x0
0xffffc4800001ab80 0041 00000000 0x0 0x0
0xffffc4800001ac00 0041 00000000 0x0 0x0
0xffffc4800001ac80 0041 00000000 0x0 0x0
0xffffc4800001ad00 0041 00000000 0x0 0x0
0xffffc4800001ad80 0041 00000000 0x0 0x0
0xffffc4800001ae00 0041 00000000 0x0 0x0
0xffffc4800001ae80 0041 00000000 0x0 0x0
0xffffc4800001af00 0041 00000000 0x0 0x0
0xffffc4800001af80 0041 00000000 0x0 0x0
0xffffc4800001b000 0041 00000000 0x0 0x0
0xffffc4800001b080 0041 00000000 0x0 0x0
0xffffc4800001b100 0041 00000000 0x0 0x0
0xffffc4800001b180 0041 00000000 0x0 0x0
0xffffc4800001b200 0041 00000000 0x0 0x0
0xffffc4800001b280 0041 00000000 0x0 0x0
0xffffc4800001b300 0041 00000000 0x0 0x0
0xffffc4800001b380 0041 00000000 0x0 0x0
0xffffc4800001b400 0041 00000000 0x0 0x0
0xffffc4800001b480 0041 00000000 0x0 0x0
0xffffc4800001b500 0041 00000000 0x0 0x0
0xffffc4800001b580 0041 00000000 0x0 0x0
0xffffc4800001b600 0041 00000000 0x0 0x0
0xffffc4800001b680 0041 00000000 0x0 0x0
0xffffc4800001b700 0041 00000000 0x0 0x0
0xffffc4800001b780 0041 00000000 0x0 0x0
0xffffc4800001b800 0041 00000000 0x0 0x0
0xffffc4800001b880 0041 00000000 0x0 0x0
0xffffc4800001b900 0041 00000000 0x0 0x0
0xffffc4800001b980 0041 00000000 0x0 0x0
0xffffc4800001ba00 0041 00000000 0x0 0x0
0xffffc4800001ba80 0001 00000000 0x0 0x0
0xffffc4800001bb00 0001 00000000 0x0 0x0
0xffffc4800001bb80 0001 00000000 0x0 0x0
0xffffc4800001bc00 0001 00000000 0x0 0x0
0xffffc4800001bc80 0001 00000000 0x0 0x0
0xffffc4800001bd00 0001 00000000 0x0 0x0
0xffffc4800001bd80 0001 00000000 0x0 0x0
0xffffc4800001be00 0001 00000000 0x0 0x0
0xffffc4800001be80 0001 00000000 0x0 0x0
0xffffc4800001bf00 0001 00000000 0x0 0x0
0xffffc4800001bf80 0001 00000000 0x0 0x0
0xffffc4800001c000 0001 00000000 0x0 0x0
0xffffc4800001c080 0001 00000000 0x0 0x0
0xffffc4800001c100 0001 00000000 0x0 0x0
0xffffc4800001c180 0001 00000000 0x0 0x0
0xffffc4800001c200 0001 00000000 0x0 0x0
0xffffc4800001c280 0001 00000000 0x0 0x0
0xffffc4800001c300 0001 00000000 0x0 0x0
0xffffc4800001c380 0001 00000000 0x0 0x0
0xffffc4800001c400 0001 00000000 0x0 0x0
0xffffc4800001c480 0001 00000000 0x0 0x0
0xffffc4800001c500 0001 00000000 0x0 0x0
0xffffc4800001c580 0001 00000000 0x0 0x0
0xffffc4800001c600 0001 00000000 0x0 0x0
0xffffc4800001c680 0001 00000000 0x0 0x0
0xffffc4800001c700 0001 00000000 0x0 0x0
0xffffc4800001c780 0001 00000000 0x0 0x0
0xffffc4800001c800 0001 00000000 0x0 0x0
0xffffc4800001c880 0001 00000000 0x0 0x0
0xffffc4800001c900 0001 00000000 0x0 0x0
0xffffc4800001c980 0001 00000000 0x0 0x0
0xffffc4800001ca00 0001 00000000 0x0 0x0
0xffffc4800001ca80 0001 00000000 0x0 0x0
0xffffc4800001cb00 0001 00000000 0x0 0x0
0xffffc4800001cb80 0001 00000000 0x0 0x0
0xffffc4800001cc00 0001 00000000 0x0 0x0
0xffffc4800001cc80 0001 00000000 0x0 0x0
0xffffc4800001cd00 0001 00000000 0x0 0x0
0xffffc4800001cd80 0001 00000000 0x0 0x0
0xffffc4800001ce00 0001 00000000 0x0 0x0
0xffffc4800001ce80 0001 00000000 0x0 0x0
0xffffc4800001cf00 0001 00000000 0x0 0x0
0xffffc4800001cf80 0001 00000000 0x0 0x0
0xffffc4800001d000 0001 00000000 0x0 0x0
0xffffc4800001d080 0001 00000000 0x0 0x0
0xffffc4800001d100 0001 00000000 0x0 0x0
0xffffc4800001d180 0001 00000000 0x0 0x0
0xffffc4800001d200 0001 00000000 0x0 0x0
0xffffc4800001d280 0001 00000000 0x0 0x0
0xffffc4800001d300 0001 00000000 0x0 0x0
0xffffc4800001d380 0001 00000000 0x0 0x0
0xffffc4800001d400 0001 00000000 0x0 0x0
0xffffc4800001d480 0001 00000000 0x0 0x0
0xffffc4800001d500 0001 00000000 0x0 0x0
0xffffc4800001d580 0001 00000000 0x0 0x0
0xffffc4800001d600 0001 00000000 0x0 0x0
0xffffc4800001d680 0001 00000000 0x0 0x0
0xffffc4800001d700 0001 00000000 0x0 0x0
0xffffc4800001d780 0001 00000000 0x0 0x0
0xffffc4800001d800 0001 00000000 0x0 0x0
0xffffc4800001d880 0001 00000000 0x0 0x0
0xffffc4800001d900 0001 00000000 0x0 0x0
0xffffc4800001d980 0001 00000000 0x0 0x0
0xffffc4800001da00 0001 00000000 0x0 0x0
0xffffc4800001da80 0001 00000000 0x0 0x0
0xffffc4800001db00 0001 00000000 0x0 0x0
0xffffc4800001db80 0001 00000000 0x0 0x0
0xffffc4800001dc00 0001 00000000 0x0 0x0
0xffffc4800001dc80 0001 00000000 0x0 0x0
0xffffc4800001dd00 0001 00000000 0x0 0x0
0xffffc4800001dd80 0001 00000000 0x0 0x0
0xffffc4800001de00 0001 00000000 0x0 0x0
0xffffc4800001de80 0001 00000000 0x0 0x0
0xffffc4800001df00 0001 00000000 0x0 0x0
0xffffc4800001df80 0001 00000000 0x0 0x0
0xffffc4800001e000 0001 00000000 0x0 0x0
0xffffc4800001e080 0001 00000000 0x0 0x0
0xffffc4800001e100 0001 00000000 0x0 0x0
0xffffc4800001e180 0001 00000000 0x0 0x0
0xffffc4800001e200 0001 00000000 0x0 0x0
0xffffc4800001e280 0001 00000000 0x0 0x0
0xffffc4800001e300 0001 00000000 0x0 0x0
0xffffc4800001e380 0001 00000000 0x0 0x0
0xffffc4800001e400 0001 00000000 0x0 0x0
0xffffc4800001e480 0001 00000000 0x0 0x0
0xffffc4800001e500 0001 00000000 0x0 0x0
0xffffc4800001e580 0001 00000000 0x0 0x0
0xffffc4800001e600 0001 00000000 0x0 0x0
0xffffc4800001e680 0001 00000000 0x0 0x0
0xffffc4800001e700 0001 00000000 0x0 0x0
0xffffc4800001e780 0001 00000000 0x0 0x0
0xffffc4800001e800 0001 00000000 0x0 0x0
0xffffc4800001e880 0001 00000000 0x0 0x0
0xffffc4800001e900 0001 00000000 0x0 0x0
0xffffc4800001e980 0001 00000000 0x0 0x0
0xffffc4800001ea00 0001 00000000 0x0 0x0
0xffffc4800001ea80 0001 00000000 0x0 0x0
0xffffc4800001eb00 0001 00000000 0x0 0x0
0xffffc4800001eb80 0001 00000000 0x0 0x0
0xffffc4800001ec00 0001 00000000 0x0 0x0
0xffffc4800001ec80 0001 00000000 0x0 0x0
0xffffc4800001ed00 0001 00000000 0x0 0x0
0xffffc4800001ed80 0001 00000000 0x0 0x0
0xffffc4800001ee00 0001 00000000 0x0 0x0
0xffffc4800001ee80 0001 00000000 0x0 0x0
0xffffc4800001ef00 0001 00000000 0x0 0x0
0xffffc4800001ef80 0001 00000000 0x0 0x0
0xffffc4800001f000 0001 00000000 0x0 0x0
0xffffc4800001f080 0001 00000000 0x0 0x0
0xffffc4800001f100 0001 00000000 0x0 0x0
0xffffc4800001f180 0001 00000000 0x0 0x0
0xffffc4800001f200 0001 00000000 0x0 0x0
0xffffc4800001f280 0001 00000000 0x0 0x0
0xffffc4800001f300 0001 00000000 0x0 0x0
0xffffc4800001f380 0001 00000000 0x0 0x0
0xffffc4800001f400 0001 00000000 0x0 0x0
0xffffc4800001f480 0001 00000000 0x0 0x0
0xffffc4800001f500 0001 00000000 0x0 0x0
0xffffc4800001f580 0001 00000000 0x0 0x0
0xffffc4800001f600 0001 00000000 0x0 0x0
0xffffc4800001f680 0001 00000000 0x0 0x0
0xffffc4800001f700 0001 00000000 0x0 0x0
0xffffc4800001f780 0001 00000000 0x0 0x0
0xffffc4800001f800 0001 00000000 0x0 0x0
0xffffc4800001f880 0001 00000000 0x0 0x0
0xffffc4800001f900 0001 00000000 0x0 0x0
0xffffc4800001f980 0001 00000000 0x0 0x0
0xffffc4800001fa00 0001 00000000 0x0 0x0
0xffffc4800001fa80 0001 00000000 0x0 0x0
0xffffc4800001fb00 0001 00000000 0x0 0x0
0xffffc4800001fb80 0001 00000000 0x0 0x0
0xffffc4800001fc00 0001 00000000 0x0 0x0
0xffffc4800001fc80 0001 00000000 0x0 0x0
0xffffc4800001fd00 0001 00000000 0x0 0x0
0xffffc4800001fd80 0001 00000000 0x0 0x0
0xffffc4800001fe00 0001 00000000 0x0 0x0
0xffffc4800001fe80 0001 00000000 0x0 0x0
0xffffc4800001ff00 0001 00000000 0x0 0x0
0xffffc4800001ff80 0001 00000000 0x0 0x0
0xffffc48000020000 0001 00000000 0x0 0x0
0xffffc48000020080 0001 00000000 0x0 0x0
0xffffc48000020100 0001 00000000 0x0 0x0
0xffffc48000020180 0001 00000000 0x0 0x0
0xffffc48000020200 0001 00000000 0x0 0x0
0xffffc48000020280 0001 00000000 0x0 0x0
0xffffc48000020300 0001 00000000 0x0 0x0
0xffffc48000020380 0001 00000000 0x0 0x0
0xffffc48000020400 0001 00000000 0x0 0x0
0xffffc48000020480 0001 00000000 0x0 0x0
0xffffc48000020500 0001 00000000 0x0 0x0
0xffffc48000020580 0001 00000000 0x0 0x0
0xffffc48000020600 0001 00000000 0x0 0x0
0xffffc48000020680 0001 00000000 0x0 0x0
0xffffc48000020700 0001 00000000 0x0 0x0
0xffffc48000020780 0001 00000000 0x0 0x0
0xffffc48000020800 0001 00000000 0x0 0x0
0xffffc48000020880 0001 00000000 0x0 0x0
0xffffc48000020900 0001 00000000 0x0 0x0
0xffffc48000020980 0001 00000000 0x0 0x0
0xffffc48000020a00 0001 00000000 0x0 0x0
0xffffc48000020a80 0001 00000000 0x0 0x0
0xffffc48000020b00 0001 00000000 0x0 0x0
0xffffc48000020b80 0001 00000000 0x0 0x0
0xffffc48000020c00 0001 00000000 0x0 0x0
0xffffc48000020c80 0001 00000000 0x0 0x0
0xffffc48000020d00 0001 00000000 0x0 0x0
0xffffc48000020d80 0001 00000000 0x0 0x0
0xffffc48000020e00 0001 00000000 0x0 0x0
0xffffc48000020e80 0001 00000000 0x0 0x0
0xffffc48000020f00 0001 00000000 0x0 0x0
0xffffc48000020f80 0001 00000000 0x0 0x0
0xffffc48000021000 0001 00000000 0x0 0x0
0xffffc48000021080 0001 00000000 0x0 0x0
0xffffc48000021100 0001 00000000 0x0 0x0
0xffffc48000021180 0001 00000000 0x0 0x0
0xffffc48000021200 0001 00000000 0x0 0x0
0xffffc48000021280 0001 00000000 0x0 0x0
0xffffc48000021300 0001 00000000 0x0 0x0
0xffffc48000021380 0001 00000000 0x0 0x0
0xffffc48000021400 0001 00000000 0x0 0x0
0xffffc48000021480 0001 00000000 0x0 0x0
0xffffc48000021500 0001 00000000 0x0 0x0
0xffffc48000021580 0001 00000000 0x0 0x0
0xffffc48000021600 0001 00000000 0x0 0x0
0xffffc48000021680 0001 00000000 0x0 0x0
0xffffc48000021700 0001 00000000 0x0 0x0
0xffffc48000021780 0001 00000000 0x0 0x0
0xffffc48000021800 0001 00000000 0x0 0x0
0xffffc48000021880 0001 00000000 0x0 0x0
0xffffc48000021900 0001 00000000 0x0 0x0
0xffffc48000021980 0001 00000000 0x0 0x0
0xffffc48000021a00 0001 00000000 0x0 0x0
0xffffc48000021a80 0001 00000000 0x0 0x0
0xffffc48000021b00 0001 00000000 0x0 0x0
0xffffc48000021b80 0001 00000000 0x0 0x0
0xffffc48000021c00 0001 00000000 0x0 0x0
0xffffc48000021c80 0001 00000000 0x0 0x0
0xffffc48000021d00 0001 00000000 0x0 0x0
0xffffc48000021d80 0001 00000000 0x0 0x0
0xffffc48000021e00 0001 00000000 0x0 0x0
0xffffc48000021e80 0001 00000000 0x0 0x0
0xffffc48000021f00 0001 00000000 0x0 0x0
0xffffc48000021f80 0001 00000000 0x0 0x0
0xffffc48000022000 0001 00000000 0x0 0x0
0xffffc48000022080 0001 00000000 0x0 0x0
0xffffc48000022100 0001 00000000 0x0 0x0
0xffffc48000022180 0001 00000000 0x0 0x0
0xffffc48000022200 0001 00000000 0x0 0x0
0xffffc48000022280 0001 00000000 0x0 0x0
0xffffc48000022300 0001 00000000 0x0 0x0
0xffffc48000022380 0001 00000000 0x0 0x0
0xffffc48000022400 0001 00000000 0x0 0x0
0xffffc48000022480 0001 00000000 0x0 0x0
0xffffc48000022500 0001 00000000 0x0 0x0
0xffffc48000022580 0001 00000000 0x0 0x0
0xffffc48000022600 0001 00000000 0x0 0x0
0xffffc48000022680 0001 00000000 0x0 0x0
0xffffc48000022700 0001 00000000 0x0 0x0
0xffffc48000022780 0001 00000000 0x0 0x0
0xffffc48000022800 0001 00000000 0x0 0x0
0xffffc48000022880 0001 00000000 0x0 0x0
0xffffc48000022900 0001 00000000 0x0 0x0
0xffffc48000022980 0001 00000000 0x0 0x0
0xffffc48000022a00 0001 00000000 0x0 0x0
0xffffc48000022a80 0001 00000000 0x0 0x0
0xffffc48000022b00 0001 00000000 0x0 0x0
0xffffc48000022b80 0001 00000000 0x0 0x0
0xffffc48000022c00 0001 00000000 0x0 0x0
0xffffc48000022c80 0001 00000000 0x0 0x0
0xffffc48000022d00 0001 00000000 0x0 0x0
0xffffc48000022d80 0001 00000000 0x0 0x0
0xffffc48000022e00 0001 00000000 0x0 0x0
0xffffc48000022e80 0001 00000000 0x0 0x0
0xffffc48000022f00 0001 00000000 0x0 0x0
0xffffc48000022f80 0001 00000000 0x0 0x0
0xffffc48000023000 0001 00000000 0x0 0x0
0xffffc48000023080 0001 00000000 0x0 0x0
0xffffc48000023100 0001 00000000 0x0 0x0
0xffffc48000023180 0001 00000000 0x0 0x0
0xffffc48000023200 0001 00000000 0x0 0x0
0xffffc48000023280 0001 00000000 0x0 0x0
0xffffc48000023300 0001 00000000 0x0 0x0
0xffffc48000023380 0001 00000000 0x0 0x0
0xffffc48000023400 0001 00000000 0x0 0x0
0xffffc48000023480 0001 00000000 0x0 0x0
0xffffc48000023500 0001 00000000 0x0 0x0
0xffffc48000023580 0001 00000000 0x0 0x0
0xffffc48000023600 0001 00000000 0x0 0x0
0xffffc48000023680 0001 00000000 0x0 0x0
0xffffc48000023700 0001 00000000 0x0 0x0
0xffffc48000023780 0001 00000000 0x0 0x0
0xffffc48000023800 0001 00000000 0x0 0x0
0xffffc48000023880 0001 00000000 0x0 0x0
0xffffc48000023900 0001 00000000 0x0 0x0
0xffffc48000023980 0001 00000000 0x0 0x0
0xffffc48000023a00 0001 00000000 0x0 0x0
0xffffc48000023a80 0001 00000000 0x0 0x0
0xffffc48000023b00 0001 00000000 0x0 0x0
0xffffc48000023b80 0001 00000000 0x0 0x0
0xffffc48000023c00 0001 00000000 0x0 0x0
0xffffc48000023c80 0001 00000000 0x0 0x0
0xffffc48000023d00 0001 00000000 0x0 0x0
0xffffc48000023d80 0001 00000000 0x0 0x0
0xffffc48000023e00 0001 00000000 0x0 0x0
0xffffc48000023e80 0001 00000000 0x0 0x0
0xffffc48000023f00 0001 00000000 0x0 0x0
0xffffc48000023f80 0001 00000000 0x0 0x0
0xffffc48000024000 0001 00000000 0x0 0x0
0xffffc48000024080 0001 00000000 0x0 0x0
0xffffc48000024100 0001 00000000 0x0 0x0
0xffffc48000024180 0001 00000000 0x0 0x0
0xffffc48000024200 0001 00000000 0x0 0x0
0xffffc48000024280 0001 00000000 0x0 0x0
0xffffc48000024300 0001 00000000 0x0 0x0
0xffffc48000024380 0001 00000000 0x0 0x0
0xffffc48000024400 0001 00000000 0x0 0x0
0xffffc48000024480 0001 00000000 0x0 0x0
0xffffc48000024500 0001 00000000 0x0 0x0
0xffffc48000024580 0001 00000000 0x0 0x0
0xffffc48000024600 0001 00000000 0x0 0x0
0xffffc48000024680 0001 00000000 0x0 0x0
0xffffc48000024700 0001 00000000 0x0 0x0
0xffffc48000024780 0001 00000000 0x0 0x0
0xffffc48000024800 0001 00000000 0x0 0x0
0xffffc48000024880 0001 00000000 0x0 0x0
0xffffc48000024900 0001 00000000 0x0 0x0
0xffffc48000024980 0001 00000000 0x0 0x0
0xffffc48000024a00 0001 00000000 0x0 0x0
0xffffc48000024a80 0001 00000000 0x0 0x0
0xffffc48000024b00 0001 00000000 0x0 0x0
0xffffc48000024b80 0001 00000000 0x0 0x0
0xffffc48000024c00 0001 00000000 0x0 0x0
0xffffc48000024c80 0001 00000000 0x0 0x0
0xffffc48000024d00 0001 00000000 0x0 0x0
0xffffc48000024d80 0001 00000000 0x0 0x0
0xffffc48000024e00 0001 00000000 0x0 0x0
0xffffc48000024e80 0001 00000000 0x0 0x0
0xffffc48000024f00 0001 00000000 0x0 0x0
0xffffc48000024f80 0001 00000000 0x0 0x0
0xffffc48000025000 0001 00000000 0x0 0x0
0xffffc48000025080 0001 00000000 0x0 0x0
0xffffc48000025100 0001 00000000 0x0 0x0
0xffffc48000025180 0001 00000000 0x0 0x0
0xffffc48000025200 0001 00000000 0x0 0x0
0xffffc48000025280 0001 00000000 0x0 0x0
0xffffc48000025300 0001 00000000 0x0 0x0
0xffffc48000025380 0001 00000000 0x0 0x0
0xffffc48000025400 0001 00000000 0x0 0x0
0xffffc48000025480 0001 00000000 0x0 0x0
0xffffc48000025500 0001 00000000 0x0 0x0
0xffffc48000025580 0001 00000000 0x0 0x0
0xffffc48000025600 0001 00000000 0x0 0x0
0xffffc48000025680 0001 00000000 0x0 0x0
0xffffc48000025700 0001 00000000 0x0 0x0
0xffffc48000025780 0001 00000000 0x0 0x0
0xffffc48000025800 0001 00000000 0x0 0x0
0xffffc48000025880 0001 00000000 0x0 0x0
0xffffc48000025900 0001 00000000 0x0 0x0
0xffffc48000025980 0001 00000000 0x0 0x0
0xffffc48000025a00 0001 00000000 0x0 0x0
0xffffc48000025a80 0001 00000000 0x0 0x0
0xffffc48000025b00 0001 00000000 0x0 0x0
0xffffc48000025b80 0001 00000000 0x0 0x0
0xffffc48000025c00 0001 00000000 0x0 0x0
0xffffc48000025c80 0001 00000000 0x0 0x0
0xffffc48000025d00 0001 00000000 0x0 0x0
0xffffc48000025d80 0001 00000000 0x0 0x0
0xffffc48000025e00 0001 00000000 0x0 0x0
0xffffc48000025e80 0001 00000000 0x0 0x0
0xffffc48000025f00 0001 00000000 0x0 0x0
0xffffc48000025f80 0001 00000000 0x0 0x0
0xffffc48000026000 0001 00000000 0x0 0x0
0xffffc48000026080 0001 00000000 0x0 0x0
0xffffc48000026100 0001 00000000 0x0 0x0
0xffffc48000026180 0001 00000000 0x0 0x0
0xffffc48000026200 0001 00000000 0x0 0x0
0xffffc48000026280 0001 00000000 0x0 0x0
0xffffc48000026300 0001 00000000 0x0 0x0
0xffffc48000026380 0001 00000000 0x0 0x0
0xffffc48000026400 0001 00000000 0x0 0x0
0xffffc48000026480 0001 00000000 0x0 0x0
0xffffc48000026500 0001 00000000 0x0 0x0
0xffffc48000026580 0001 00000000 0x0 0x0
0xffffc48000026600 0001 00000000 0x0 0x0
0xffffc48000026680 0001 00000000 0x0 0x0
0xffffc48000026700 0001 00000000 0x0 0x0
0xffffc48000026780 0001 00000000 0x0 0x0
0xffffc48000026800 0001 00000000 0x0 0x0
0xffffc48000026880 0001 00000000 0x0 0x0
0xffffc48000026900 0001 00000000 0x0 0x0
0xffffc48000026980 0001 00000000 0x0 0x0
0xffffc48000026a00 0001 00000000 0x0 0x0
0xffffc48000026a80 0001 00000000 0x0 0x0
0xffffc48000026b00 0001 00000000 0x0 0x0
0xffffc48000026b80 0001 00000000 0x0 0x0
0xffffc48000026c00 0001 00000000 0x0 0x0
0xffffc48000026c80 0001 00000000 0x0 0x0
0xffffc48000026d00 0001 00000000 0x0 0x0
0xffffc48000026d80 0001 00000000 0x0 0x0
0xffffc48000026e00 0001 00000000 0x0 0x0
0xffffc48000026e80 0001 00000000 0x0 0x0
0xffffc48000026f00 0001 00000000 0x0 0x0
0xffffc48000026f80 0001 00000000 0x0 0x0
0xffffc48000027000 0001 00000000 0x0 0x0
0xffffc48000027080 0001 00000000 0x0 0x0
0xffffc48000027100 0001 00000000 0x0 0x0
0xffffc48000027180 0001 00000000 0x0 0x0
0xffffc48000027200 0001 00000000 0x0 0x0
0xffffc48000027280 0001 00000000 0x0 0x0
0xffffc48000027300 0001 00000000 0x0 0x0
0xffffc48000027380 0001 00000000 0x0 0x0
0xffffc48000027400 0001 00000000 0x0 0x0
0xffffc48000027480 0001 00000000 0x0 0x0
0xffffc48000027500 0001 00000000 0x0 0x0
0xffffc48000027580 0001 00000000 0x0 0x0
0xffffc48000027600 0001 00000000 0x0 0x0
0xffffc48000027680 0001 00000000 0x0 0x0
0xffffc48000027700 0001 00000000 0x0 0x0
0xffffc48000027780 0001 00000000 0x0 0x0
0xffffc48000027800 0001 00000000 0x0 0x0
0xffffc48000027880 0001 00000000 0x0 0x0
0xffffc48000027900 0001 00000000 0x0 0x0
0xffffc48000027980 0001 00000000 0x0 0x0
0xffffc48000027a00 0001 00000000 0x0 0x0
0xffffc48000027a80 0001 00000000 0x0 0x0
0xffffc48000027b00 0001 00000000 0x0 0x0
0xffffc48000027b80 0001 00000000 0x0 0x0
0xffffc48000027c00 0001 00000000 0x0 0x0
0xffffc48000027c80 0001 00000000 0x0 0x0
0xffffc48000027d00 0001 00000000 0x0 0x0
0xffffc48000027d80 0001 00000000 0x0 0x0
0xffffc48000027e00 0001 00000000 0x0 0x0
0xffffc48000027e80 0001 00000000 0x0 0x0
0xffffc48000027f00 0001 00000000 0x0 0x0
0xffffc48000027f80 0001 00000000 0x0 0x0
0xffffc48000028000 0001 00000000 0x0 0x0
0xffffc48000028080 0001 00000000 0x0 0x0
0xffffc48000028100 0001 00000000 0x0 0x0
0xffffc48000028180 0001 00000000 0x0 0x0
0xffffc48000028200 0001 00000000 0x0 0x0
0xffffc48000028280 0001 00000000 0x0 0x0
0xffffc48000028300 0001 00000000 0x0 0x0
0xffffc48000028380 0001 00000000 0x0 0x0
0xffffc48000028400 0001 00000000 0x0 0x0
0xffffc48000028480 0001 00000000 0x0 0x0
0xffffc48000028500 0001 00000000 0x0 0x0
0xffffc48000028580 0001 00000000 0x0 0x0
0xffffc48000028600 0001 00000000 0x0 0x0
0xffffc48000028680 0001 00000000 0x0 0x0
0xffffc48000028700 0001 00000000 0x0 0x0
0xffffc48000028780 0001 00000000 0x0 0x0
0xffffc48000028800 0001 00000000 0x0 0x0
0xffffc48000028880 0001 00000000 0x0 0x0
0xffffc48000028900 0001 00000000 0x0 0x0
0xffffc48000028980 0001 00000000 0x0 0x0
0xffffc48000028a00 0001 00000000 0x0 0x0
0xffffc48000028a80 0001 00000000 0x0 0x0
0xffffc48000028b00 0001 00000000 0x0 0x0
0xffffc48000028b80 0001 00000000 0x0 0x0
0xffffc48000028c00 0001 00000000 0x0 0x0
0xffffc48000028c80 0001 00000000 0x0 0x0
0xffffc48000028d00 0001 00000000 0x0 0x0
0xffffc48000028d80 0001 00000000 0x0 0x0
0xffffc48000028e00 0001 00000000 0x0 0x0
0xffffc48000028e80 0001 00000000 0x0 0x0
0xffffc48000028f00 0001 00000000 0x0 0x0
0xffffc48000028f80 0001 00000000 0x0 0x0
0xffffc48000029000 0001 00000000 0x0 0x0
0xffffc48000029080 0001 00000000 0x0 0x0
0xffffc48000029100 0001 00000000 0x0 0x0
0xffffc48000029180 0001 00000000 0x0 0x0
0xffffc48000029200 0001 00000000 0x0 0x0
0xffffc48000029280 0001 00000000 0x0 0x0
0xffffc48000029300 0001 00000000 0x0 0x0
0xffffc48000029380 0001 00000000 0x0 0x0
0xffffc48000029400 0001 00000000 0x0 0x0
0xffffc48000029480 0001 00000000 0x0 0x0
0xffffc48000029500 0001 00000000 0x0 0x0
0xffffc48000029580 0001 00000000 0x0 0x0
0xffffc48000029600 0001 00000000 0x0 0x0
0xffffc48000029680 0001 00000000 0x0 0x0
0xffffc48000029700 0001 00000000 0x0 0x0
0xffffc48000029780 0001 00000000 0x0 0x0
0xffffc48000029800 0001 00000000 0x0 0x0
0xffffc48000029880 0001 00000000 0x0 0x0
0xffffc48000029900 0001 00000000 0x0 0x0
0xffffc48000029980 0001 00000000 0x0 0x0
0xffffc48000029a00 0001 00000000 0x0 0x0
0xffffc48000029a80 0001 00000000 0x0 0x0
0xffffc48000029b00 0001 00000000 0x0 0x0
0xffffc48000029b80 0001 00000000 0x0 0x0
0xffffc48000029c00 0001 00000000 0x0 0x0
0xffffc48000029c80 0001 00000000 0x0 0x0
0xffffc48000029d00 0001 00000000 0x0 0x0
0xffffc48000029d80 0001 00000000 0x0 0x0
0xffffc48000029e00 0001 00000000 0x0 0x0
0xffffc48000029e80 0001 00000000 0x0 0x0
0xffffc48000029f00 0001 00000000 0x0 0x0
0xffffc48000029f80 0001 00000000 0x0 0x0
0xffffc4800002a000 0001 00000000 0x0 0x0
0xffffc4800002a080 0001 00000000 0x0 0x0
0xffffc4800002a100 0001 00000000 0x0 0x0
0xffffc4800002a180 0001 00000000 0x0 0x0
0xffffc4800002a200 0001 00000000 0x0 0x0
0xffffc4800002a280 0001 00000000 0x0 0x0
0xffffc4800002a300 0001 00000000
Reply all
Reply to author
Forward
0 new messages