UBSan: Undefined Behavior in compat_20_sys_statfs

0 views
Skip to first unread message

syzbot

unread,
Jun 26, 2020, 7:25:13 PM6/26/20
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 5f8d4fbd Adjust prior to enforce minimum socket length inc..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17a0b223100000
kernel config: https://syzkaller.appspot.com/x/.config?x=1420f906d33d9f1f
dashboard link: https://syzkaller.appspot.com/bug?extid=88ddf12200c3b3649f44
compiler: g++ (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=142d3355100000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12b8fc39100000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+88ddf1...@syzkaller.appspotmail.com

[ 39.1264097] panic: uvm_fault(0xffff8236ebcd0310, 0x0, 2) -> e
[ 39.1264097] fatal page fault in supervisor mode
[ 39.1264097] UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/compat/sys/mount.h:104:14, member access within null pointer of type 'struct statfs12'

[ 39.1264097] cpu1: Begin traceback...
[ 39.1264097] trap type 6 code 0x2 rip 0xffffffff821b3403 cs 0x8 rflags 0x10282 cr2 0 ilevel 0 rsp 0xffffc000bf2f8ed0
[ 39.1393737] vpanic() at netbsd:vpanic+0x287 sys/kern/subr_prf.c:290
[ 39.1664043] isAlreadyReported() at netbsd:isAlreadyReported
[ 39.1964052] HandleTypeMismatch.part.1() at netbsd:HandleTypeMismatch.part.1+0x14e
[ 39.2264034] HandleTypeMismatch() at netbsd:HandleTypeMismatch+0x63 sys/../common/lib/libc/misc/ubsan.c:434
[ 39.2564040] compat_20_sys_statfs() at netbsd:compat_20_sys_statfs+0xde0 statvfs_to_statfs12 sys/compat/sys/mount.h:104 [inline]
[ 39.2564040] compat_20_sys_statfs() at netbsd:compat_20_sys_statfs+0xde0 statvfs_to_statfs12_copy sys/compat/sys/mount.h:143 [inline]
[ 39.2564040] compat_20_sys_statfs() at netbsd:compat_20_sys_statfs+0xde0 sys/compat/common/vfs_syscalls_20.c:105
[ 39.2864031] sys_syscall() at netbsd:sys_syscall+0x1b5 sy_call sys/sys/syscallvar.h:65 [inline]
[ 39.2864031] sys_syscall() at netbsd:sys_syscall+0x1b5 sys/kern/sys_syscall.c:77
[ 39.3164047] syscall() at netbsd:syscall+0x287 sy_call sys/sys/syscallvar.h:65 [inline]
[ 39.3164047] syscall() at netbsd:syscall+0x287 sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 39.3164047] syscall() at netbsd:syscall+0x287 sys/arch/x86/x86/syscall.c:138
[ 39.3264031] --- syscall (number 0) ---
[ 39.3364063] netbsd:syscall+0x287:
[ 39.3364063] cpu1: End traceback...
[ 39.3364063] uvm_fault(0xffff8236eb3f35d8, 0x0, 2) -> e
[ 39.3364063] fatal breakpoint trapfatal page fault in supervisor mode
[ 39.3565689] trap type 6 code 0x2 rip 0xffffffff821b3403 cs 0x8 rflags 0x10282 cr2 0 ilevel 0 rsp 0xffffc000bf261ed0
[ 39.3670525] in supervisor mode
[ 39.3670525] trap type 1 code 0 rip 0xffffffff80221aa5 cs 0x8 rflags 0x246 cr2 0x7b28dcc126a4 ilevel 0 rsp 0xffffc000bf0d0920
[ 39.3670525] curlwp 0xffff8236eb62a080 pid 1077.1077 lowest kstack 0xffffc000bf0cd2c0
Stopped in pid 1077.1077 (syz-executor8812) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xd1 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x287 sys/kern/subr_prf.c:290
isAlreadyReported() at netbsd:isAlreadyReported
HandleTypeMismatch.part.1() at netbsd:HandleTypeMismatch.part.1+0x14e
HandleTypeMismatch() at netbsd:HandleTypeMismatch+0x63 sys/../common/lib/libc/misc/ubsan.c:434
compat_20_sys_statfs() at netbsd:compat_20_sys_statfs+0xde0 statvfs_to_statfs12 sys/compat/sys/mount.h:104 [inline]
compat_20_sys_statfs() at netbsd:compat_20_sys_statfs+0xde0 statvfs_to_statfs12_copy sys/compat/sys/mount.h:143 [inline]
compat_20_sys_statfs() at netbsd:compat_20_sys_statfs+0xde0 sys/compat/common/vfs_syscalls_20.c:105
sys_syscall() at netbsd:sys_syscall+0x1b5 sy_call sys/sys/syscallvar.h:65 [inline]
sys_syscall() at netbsd:sys_syscall+0x1b5 sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x287 sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x287 sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x287 sys/arch/x86/x86/syscall.c:138
--- syscall (number 0) ---
netbsd:syscall+0x287:
Panic string: UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/compat/sys/mount.h:104:14, member access within null pointer of type 'struct statfs12'

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
419 419 2 0 0 ffff8236ebf3e140 syz-executor8812
1081 >1081 7 0 0 ffff8236ec1fb180 syz-executor8812
1077 >1077 7 1 0 ffff8236eb62a080 syz-executor8812
851 851 2 0 0 ffff8236ecc56240 syz-executor8812
1096 1096 2 1 0 ffff8236ec1fb5c0 syz-executor8812
1068 1068 2 1 0 ffff8236ec623a80 syz-executor8812
1071 1071 2 0 40 ffff8236ec597a40 syz-executor8812
1066 1066 2 0 0 ffff8236e9e765c0 syz-executor8812
1064 1064 2 0 40 ffff8236ea0e1640 syz-executor8812
1250 1250 2 1 40 ffff8236ea0e1200 syz-executor8812
860 860 2 1 40 ffff8236ea0e1a80 syz-executor8812
1117 1117 3 0 80 ffff8236ec623640 syz-executor8812 nanoslp
1254 1254 2 1 0 ffff8236ec623200 sshd
850 850 3 0 80 ffff8236ec597600 getty nanoslp
695 695 3 1 80 ffff8236ec5971c0 getty nanoslp
1088 1088 3 1 80 ffff8236ebf3e9c0 getty nanoslp
1092 1092 3 1 c0 ffff8236ea3d8240 getty ttyraw
947 947 3 1 80 ffff8236ebf8d500 sshd select
976 976 3 1 80 ffff8236ec1fba00 powerd kqueue
721 721 3 0 80 ffff8236ea5bf6c0 syslogd kqueue
591 591 3 1 80 ffff8236eb62a4c0 dhcpcd poll
589 589 3 1 80 ffff8236ea5bfb00 dhcpcd poll
587 587 3 0 80 ffff8236ea692b40 dhcpcd poll
412 412 3 1 80 ffff8236ea3d8ac0 dhcpcd poll
347 347 3 1 80 ffff8236ea6ee300 dhcpcd poll
346 346 3 1 80 ffff8236ea692700 dhcpcd poll
345 345 3 1 80 ffff8236ea6eeb80 dhcpcd poll
1 1 3 0 80 ffff8236e1cad900 init wait
0 853 3 0 200 ffff8236e9e76a00 physiod physiod
0 160 3 0 200 ffff8236e9edda40 pooldrain pooldrain
0 165 2 1 240 ffff8236e9edd600 ioflush
0 164 3 1 200 ffff8236e9edd1c0 pgdaemon pgdaemon
0 161 3 1 200 ffff8236e9e76180 usb7 usbevt
0 31 3 1 200 ffff8236e6dff9c0 usb6 usbevt
0 63 3 1 200 ffff8236e6dff580 usb5 usbevt
0 126 3 1 200 ffff8236e6dff140 usb4 usbevt
0 125 3 0 200 ffff8236e3da0980 usb3 usbevt
0 124 3 1 200 ffff8236e3da0540 usb2 usbevt
0 123 3 1 200 ffff8236e3da0100 usb1 usbevt
0 122 3 0 200 ffff8236e1d01940 usb0 usbevt
0 121 3 0 200 ffff8236e1d01500 usbtask-dr usbtsk
0 120 3 0 200 ffff8236df124ac0 usbtask-hc usbtsk
0 119 3 0 200 ffff8236e1d010c0 npfgc0 npfgcw
0 118 3 1 200 ffff8236e1cad4c0 rt_free rt_free
0 117 3 1 200 ffff8236e1cad080 unpgc unpgc
0 116 3 0 200 ffff8236e1cb68c0 key_timehandler key_timehandler
0 115 3 1 200 ffff8236e1cb6480 icmp6_wqinput/1 icmp6_wqinput
0 114 3 0 200 ffff8236e1cb6040 icmp6_wqinput/0 icmp6_wqinput
0 113 3 0 200 ffff8236e1c9fbc0 nd6_timer nd6_timer
0 112 3 1 200 ffff8236e1c9f780 carp6_wqinput/1 carp6_wqinput
0 111 3 0 200 ffff8236e1c9f340 carp6_wqinput/0 carp6_wqinput
0 110 3 1 200 ffff8236e1c40b80 carp_wqinput/1 carp_wqinput
0 109 3 0 200 ffff8236e1c212c0 carp_wqinput/0 carp_wqinput
0 108 3 1 200 ffff8236e1c21700 icmp_wqinput/1 icmp_wqinput
0 107 3 0 200 ffff8236e15a6b00 icmp_wqinput/0 icmp_wqinput
0 106 3 0 200 ffff8236e1c21b40 rt_timer rt_timer
0 105 3 1 200 ffff8236e1c40300 vmem_rehash vmem_rehash
0 104 3 0 200 ffff8236e1c40740 entbutler entropy
0 30 3 1 200 ffff8236e15a66c0 vioif0_txrx/1 vioif0_txrx
0 29 3 0 200 ffff8236e15a6280 vioif0_txrx/0 vioif0_txrx
0 27 3 0 200 ffff8236df124680 scsibus0 sccomp
0 26 3 0 200 ffff8236df124240 pms0 pmsreset
0 25 3 1 200 ffff8236df097a80 xcall/1 xcall
0 24 1 1 200 ffff8236df097640 softser/1
0 23 1 1 200 ffff8236df097200 softclk/1
0 22 1 1 200 ffff8236df067a40 softbio/1
0 21 1 1 200 ffff8236df067600 softnet/1
0 20 1 1 201 ffff8236df0671c0 idle/1
0 19 3 0 200 ffff8237eef80a00 lnxpwrwq lnxpwrwq
0 18 3 0 200 ffff8237eef805c0 lnxlngwq lnxlngwq
0 17 3 0 200 ffff8237eef80180 lnxsyswq lnxsyswq
0 16 3 0 200 ffff8237eefa79c0 lnxrcugc lnxrcugc
0 15 3 0 200 ffff8237eefa7580 sysmon smtaskq
0 14 3 0 200 ffff8237eefa7140 pmfsuspend pmfsuspend
0 13 3 0 200 ffff8237eefac980 pmfevent pmfevent
0 12 3 0 200 ffff8237eefac540 sopendfree sopendfr
0 11 3 0 200 ffff8237eefac100 iflnkst iflnkst
0 10 3 0 200 ffff8237effdf940 nfssilly nfssilly
0 9 3 0 200 ffff8237effdf500 vdrain vdrain
0 8 3 0 200 ffff8237effdf0c0 modunload mod_unld
0 7 3 0 200 ffff8237f000a900 xcall/0 xcall
0 6 1 0 200 ffff8237f000a4c0 softser/0
0 5 1 0 200 ffff8237f000a080 softclk/0
0 4 1 0 200 ffff8237f003b8c0 softbio/0
0 3 1 0 200 ffff8237f003b480 softnet/0
0 2 1 0 201 ffff8237f003b040 idle/0
0 0 2 1 240 ffffffff85ae88c0 swapper
[Locks tracked through LWPs]

****** LWP 1081.1081 (syz-executor8812) @ 0xffff8236ec1fb180, l_stat=7

*** Locks held:

* Lock 0 (initialized at pmap_ctor)
lock address : 0xffff8236ea436180 type : sleep/adaptive
initialized : 0xffffffff80ef3330
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff8236ec1fb180 last held: 0xffff8236ec1fb180
last locked* : 0xffffffff80ef5713 unlocked : 0xffffffff80ef3086
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 851.851 (syz-executor8812) @ 0xffff8236ecc56240, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at kprintf_init)
lock address : 0xffffffff85fd56e8 type : spin
initialized : 0xffffffff83133e39
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 1
relevant lwp : 0xffff8236ecc56240 last held: 000000000000000000
last locked : 0xffffffff83133e91 unlocked*: 0xffffffff83133eea
owner field : 0x0000000000000800 wait/spin: 0/1

****** LWP 1096.1096 (syz-executor8812) @ 0xffff8236ec1fb5c0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at uvm_map_setup)
lock address : 0xffffffff85f50808 type : sleep/adaptive
initialized : 0xffffffff82f12485
shared holds : 1 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 0
relevant lwp : 0xffff8236ec1fb5c0 last held: 0xffff8236e9e765c0
last locked : 0xffffffff82ef50dd unlocked*: 0xffffffff82ef44e3
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

****** LWP 1068.1068 (syz-executor8812) @ 0xffff8236ec623a80, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at uvm_map_setup)
lock address : 0xffff8236eb9a01b0 type : sleep/adaptive
initialized : 0xffffffff82f12485
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 65535
relevant lwp : 0xffff8236ec623a80 last held: 000000000000000000
last locked : 0xffffffff82ef1359 unlocked*: 0xffffffff82ef3fee
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

****** LWP 1066.1066 (syz-executor8812) @ 0xffff8236e9e765c0, l_stat=2

*** Locks held:

* Lock 0 (initialized at lwp_ctl_alloc)
lock address : 0xffff8236ec3ae380 type : sleep/adaptive
initialized : 0xffffffff82ff6252
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff8236e9e765c0 last held: 0xffff8236e9e765c0
last locked* : 0xffffffff82ff570d unlocked : 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at uvm_obj_init)
lock address : 0xffff8236ec4bcf40 type : sleep/adaptive
initialized : 0xffffffff82f28d10
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff8236e9e765c0 last held: 0xffff8236e9e765c0
last locked* : 0xffffffff82ef518b unlocked : 0xffffffff82eded61
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at pmap_bootstrap)
lock address : 0xffffffff85ee5080 type : sleep/adaptive
initialized : 0xffffffff80eeb8ea
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 1
relevant lwp : 0xffff8236e9e765c0 last held: 000000000000000000
last locked : 0xffffffff80ef5713 unlocked*: 0xffffffff80ef5cf0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 589.589 (dhcpcd) @ 0xffff8236ea5bfb00, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff8236ea5bfb00 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 587.587 (dhcpcd) @ 0xffff8236ea692b40, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff8236ea692b40 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 346.346 (dhcpcd) @ 0xffff8236ea692700, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff8236ea692700 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 345.345 (dhcpcd) @ 0xffff8236ea6eeb80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff8236ea6eeb80 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.23 (softclk/1) @ 0xffff8236df097200, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff8236df097200 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffff8237eefac100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85ee7480 type : sleep/adaptive
initialized : 0xffffffff8300acaf
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff8237eefac100 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffffc00000006180 0045 00000000 0x0 0x0
0xffffc00000006200 0045 00000000 0x0 0x0
0xffffc00000006280 0045 00000000 0x0 0x0
0xffffc00000006300 0045 00000000 0x0 0x0
0xffffc00000006380 0045 00000000 0x0 0x0
0xffffc00000006400 0045 00000000 0x0 0x0
0xffffc00000006480 0045 00000000 0x0 0x0
0xffffc00000006500 0045 00000000 0x0 0x0
0xffffc00000006580 0041 00000000 0x0 0x0
0xffffc00000006600 0041 00000000 0x0 0x0
0xffffc00000006680 0041 00000000 0x0 0x0
0xffffc00000006700 0041 00000000 0x0 0x0
0xffffc00000006780 0041 00000000 0x0 0x0
0xffffc00000006800 0041 00000000 0x0 0x0
0xffffc00000006880 0041 00000000 0x0 0x0
0xffffc00000006900 0041 00000000 0x0 0x0
0xffffc00000006980 0041 00000000 0x0 0x0
0xffffc00000006a00 0041 00000000 0x0 0x0
0xffffc00000006a80 0041 00000000 0x0 0x0
0xffffc00000006b00 0041 00000000 0x0 0x0
0xffffc00000006b80 0041 00000000 0x0 0x0
0xffffc00000006c00 0041 00000000 0x0 0x0
0xffffc00000006c80 0041 00000000 0x0 0x0
0xffffc00000006d00 0041 00000000 0x0 0x0
0xffffc00000006d80 0041 00000000 0x0 0x0
0xffffc00000006e00 0041 00000000 0x0 0x0
0xffffc00000006e80 0041 00000000 0x0 0x0
0xffffc00000006f00 0041 00000000 0x0 0x0
0xffffc00000006f80 0041 00000000 0x0 0x0
0xffffc00000007000 0041 00000000 0x0 0x0
0xffffc00000007080 0041 00000000 0x0 0x0
0xffffc00000007100 0041 00000000 0x0 0x0
0xffffc00000007180 0041 00000000 0x0 0x0
0xffffc00000007200 0045 00000000 0x0 0x0
0xffffc00000007280 0041 00000000 0x0 0x0
0xffffc00000007300 0041 00000000 0x0 0x0
0xffffc00000007380 0041 00000000 0x0 0x0
0xffffc00000007400 0041 00000000 0x0 0x0
0xffffc00000007480 0041 00000000 0x0 0x0
0xffffc00000007500 0041 00000000 0x0 0x0
0xffffc00000007580 0041 00000000 0x0 0x0
0xffffc00000007600 0041 00000000 0x0 0x0
0xffffc00000007680 0041 00000000 0x0 0x0
0xffffc00000007700 0045 00000000 0x0 0x0
0xffffc00000007780 0045 00000000 0x0 0x0
0xffffc00000007800 0041 00000000 0x0 0x0
0xffffc00000007880 0041 00000000 0x0 0x0
0xffffc00000007900 0041 00000000 0x0 0x0
0xffffc00000007980 0041 00000000 0x0 0x0
0xffffc00000007a00 0041 00000000 0x0 0x0
0xffffc00000007a80 0041 00000000 0x0 0x0
0xffffc00000007b00 0041 00000000 0x0 0x0
0xffffc00000007b80 0041 00000000 0x0 0x0
0xffffc00000007c00 0041 00000000 0x0 0x0
0xffffc00000007c80 0041 00000000 0x0 0x0
0xffffc00000007d00 0041 00000000 0x0 0x0
0xffffc00000007d80 0041 00000000 0x0 0x0
0xffffc00000007e00 0041 00000000 0x0 0x0
0xffffc00000007e80 0041 00000000 0x0 0x0
0xffffc00000007f00 0041 00000000 0x0 0x0
0xffffc00000007f80 0041 00000000 0x0 0x0
0xffffc00000008000 0041 00000000 0x0 0x0
0xffffc00000008080 0041 00000000 0x0 0x0
0xffffc00000008100 0041 00000000 0x0 0x0
0xffffc00000008180 0041 00000000 0x0 0x0
0xffffc00000008200 0041 00000000 0x0 0x0
0xffffc00000008280 0041 00000000 0x0 0x0
0xffffc00000008300 0041 00000000 0x0 0x0
0xffffc00000008380 0041 00000000 0x0 0x0
0xffffc00000008400 0041 00000000 0x0 0x0
0xffffc00000008480 0041 00000000 0x0 0x0
0xffffc00000008500 0041 00000000 0x0 0x0
0xffffc00000008580 0041 00000000 0x0 0x0
0xffffc00000008600 0041 00000000 0x0 0x0
0xffffc00000008680 0041 00000000 0x0 0x0
0xffffc00000008700 0041 00000000 0x0 0x0
0xffffc00000008780 0041 00000000 0x0 0x0
0xffffc00000008800 0041 00000000 0x0 0x0
0xffffc00000008880 0041 00000000 0x0 0x0
0xffffc00000008900 0041 00000000 0x0 0x0
0xffffc00000008980 0041 00000000 0x0 0x0
0xffffc00000008a00 0041 00000000 0x0 0x0
0xffffc00000008a80 0041 00000000 0x0 0x0
0xffffc00000008b00 0041 00000000 0x0 0x0
0xffffc00000008b80 0041 00000000 0x0 0x0
0xffffc00000008c00 0041 00000000 0x0 0x0
0xffffc00000008c80 0045 00000000 0x0 0x0
0xffffc00000008d00 0041 00000000 0x0 0x0
0xffffc00000008d80 0041 00000000 0x0 0x0
0xffffc00000008e00 0041 00000000 0x0 0x0
0xffffc00000008e80 0041 00000000 0x0 0x0
0xffffc00000008f00 0045 00000000 0x0 0x0
0xffffc00000008f80 0041 00000000 0x0 0x0
0xffffc00000009000 0041 00000000 0x0 0x0
0xffffc00000009080 0041 00000000 0x0 0x0
0xffffc00000009100 0041 00000000 0x0 0x0
0xffffc00000009180 0041 00000000 0x0 0x0
0xffffc00000009200 0041 00000000 0x0 0x0
0xffffc00000009280 0041 00000000 0x0 0x0
0xffffc00000009300 0041 00000000 0x0 0x0
0xffffc00000009380 0041 00000000 0x0 0x0
0xffffc00000009400 0041 00000000 0x0 0x0
0xffffc00000009480 0041 00000000 0x0 0x0
0xffffc00000009500 0041 00000000 0x0 0x0
0xffffc00000009580 0041 00000000 0x0 0x0
0xffffc00000009600 0041 00000000 0x0 0x0
0xffffc00000009680 0041 00000000 0x0 0x0
0xffffc00000009700 0041 00000000 0x0 0x0
0xffffc00000009780 0041 00000000 0x0 0x0
0xffffc00000009800 0041 00000000 0x0 0x0
0xffffc00000009880 0041 00000000 0x0 0x0
0xffffc00000009900 0041 00000000 0x0 0x0
0xffffc00000009980 0041 00000000 0x0 0x0
0xffffc00000009a00 0041 00000000 0x0 0x0
0xffffc00000009a80 0041 00000000 0x0 0x0
0xffffc00000009b00 0041 00000000 0x0 0x0
0xffffc00000009b80 0041 00000000 0x0 0x0
0xffffc00000009c00 0041 00000000 0x0 0x0
0xffffc00000009c80 0041 00000000 0x0 0x0
0xffffc00000009d00 0041 00000000 0x0 0x0
0xffffc00000009d80 0045 00000000 0x0 0x0
0xffffc00000009e00 0045 00000000 0x0 0x0
0xffffc00000009e80 0045 00000000 0x0 0x0
0xffffc00000009f00 0041 00000000 0x0 0x0
0xffffc00000009f80 0041 00000000 0x0 0x0
0xffffc0000000a000 0041 00000000 0x0 0x0
0xffffc0000000a080 0041 00000000 0x0 0x0
0xffffc0000000a100 0045 00000000 0x0 0x0
0xffffc0000000a180 0045 00000000 0x0 0x0
0xffffc0000000a200 0045 00000000 0x0 0x0
0xffffc0000000a280 0045 00000000 0x0 0x0
0xffffc0000000a300 0041 00000000 0x0 0x0
0xffffc0000000a380 0041 00000000 0x0 0x0
0xffffc0000000a400 0045 00000000 0x0 0x0
0xffffc0000000a480 0041 00000000 0x0 0x0
0xffffc0000000a500 0045 00000000 0x0 0x0
0xffffc0000000a580 0045 00000000 0x0 0x0
0xffffc0000000a600 0045 00000000 0x0 0x0
0xffffc0000000a680 0045 00000000 0x0 0x0
0xffffc0000000a700 0045 00000000 0x0 0x0
0xffffc0000000a780 0045 00000000 0x0 0x0
0xffffc0000000a800 0045 00000000 0x0 0x0
0xffffc0000000a880 0041 00000000 0x0 0x0
0xffffc0000000a900 0045 00000000 0x0 0x0
0xffffc0000000a980 0045 00000000 0x0 0x0
0xffffc0000000aa00 0045 00000000 0x0 0x0
0xffffc0000000aa80 0045 00000000 0x0 0x0
0xffffc0000000ab00 0045 00000000 0x0 0x0
0xffffc0000000ab80 0045 00000000 0x0 0x0
0xffffc0000000ac00 0045 00000000 0x0 0x0
0xffffc0000000ac80 0045 00000000 0x0 0x0
0xffffc0000000ad00 0045 00000000 0x0 0x0
0xffffc0000000ad80 0041 00000000 0x0 0x0
0xffffc0000000ae00 0041 00000000 0x0 0x0
0xffffc0000000ae80 0041 00000000 0x0 0x0
0xffffc0000000af00 0045 00000000 0x0 0x0
0xffffc0000000af80 0045 00000000 0x0 0x0
0xffffc0000000b000 0045 00000000 0x0 0x0
0xffffc0000000b080 0045 00000000 0x0 0x0
0xffffc0000000b100 0045 00000000 0x0 0x0
0xffffc0000000b180 0041 00000000 0x0 0x0
0xffffc0000000b200 0041 00000000 0x0 0x0
0xffffc0000000b280 0041 00000000 0x0 0x0
0xffffc0000000b300 0045 00000000 0x0 0x0
0xffffc0000000b380 0045 00000000 0x0 0x0
0xffffc0000000b400 0045 00000000 0x0 0x0
0xffffc0000000b480 0045 00000000 0x0 0x0
0xffffc0000000b500 0041 00000000 0x0 0x0
0xffffc0000000b580 0041 00000000 0x0 0x0
0xffffc0000000b600 0041 00000000 0x0 0x0
0xffffc0000000b680 0041 00000000 0x0 0x0
0xffffc0000000b700 0041 00000000 0x0 0x0
0xffffc0000000b780 0041 00000000 0x0 0x0
0xffffc0000000b800 0041 00000000 0x0 0x0
0xffffc0000000b880 0045 00000000 0x0 0x0
0xffffc0000000b900 0041 00000000 0x0 0x0
0xffffc0000000b980 0041 00000000 0x0 0x0
0xffffc0000000ba00 0041 00000000 0x0 0x0
0xffffc0000000ba80 0045 00000000 0x0 0x0
0xffffc0000000bb00 0041 00000000 0x0 0x0
0xffffc0000000bb80 0041 00000000 0x0 0x0
0xffffc0000000bc00 0041 00000000 0x0 0x0
0xffffc0000000bc80 0045 00000000 0x0 0x0
0xffffc0000000bd00 0041 00000000 0x0 0x0
0xffffc0000000bd80 0041 00000000 0x0 0x0
0xffffc0000000be00 0041 00000000 0x0 0x0
0xffffc0000000be80 0041 00000000 0x0 0x0
0xffffc0000000bf00 0041 00000000 0x0 0x0
0xffffc0000000bf80 0041 00000000 0x0 0x0
0xffffc0000000c000 0041 00000000 0x0 0x0
0xffffc0000000c080 0041 00000000 0x0 0x0
0xffffc0000000c100 0041 00000000 0x0 0x0
0xffffc0000000c180 0045 00000000 0x0 0x0
0xffffc0000000c200 0045 00000000 0x0 0x0
0xffffc0000000c280 0041 00000000 0x0 0x0
0xffffc0000000c300 0045 00000000 0x0 0x0
0xffffc0000000c380 0041 00000000 0x0 0x0
0xffffc0000000c400 0041 00000000 0x0 0x0
0xffffc0000000c480 0041 00000000 0x0 0x0
0xffffc0000000c500 0041 00000000 0x0 0x0
0xffffc0000000c580 0045 00000000 0x0 0x0
0xffffc0000000c600 0041 00000000 0x0 0x0
0xffffc0000000c680 0045 00000000 0x0 0x0
0xffffc0000000c700 0041 00000000 0x0 0x0
0xffffc0000000c780 0041 00000000 0x0 0x0
0xffffc0000000c800 0045 00000000 0x0 0x0
0xffffc0000000c880 0041 00000000 0x0 0x0
0xffffc0000000c900 0045 00000000 0x0 0x0
0xffffc0000000c980 0041 00000000 0x0 0x0
0xffffc0000000ca00 0041 00000000 0x0 0x0
0xffffc0000000ca80 0041 00000000 0x0 0x0
0xffffc0000000cb00 0045 00000000 0x0 0x0
0xffffc0000000cb80 0045 00000000 0x0 0x0
0xffffc0000000cc00 0045 00000000 0x0 0x0
0xffffc0000000cc80 0041 00000000 0x0 0x0
0xffffc0000000cd00 0045 00000000 0x0 0x0
0xffffc0000000cd80 0041 00000000 0x0 0x0
0xffffc0000000ce00 0041 00000000 0x0 0x0
0xffffc0000000ce80 0045 00000000 0x0 0x0
0xffffc0000000cf00 0045 00000000 0x0 0x0
0xffffc0000000cf80 0045 00000000 0x0 0x0
0xffffc0000000d000 0045 00000000 0x0 0x0
0xffffc0000000d080 0045 00000000 0x0 0x0
0xffffc0000000d100 0041 00000000 0x0 0x0
0xffffc0000000d180 0041 00000000 0x0 0x0
0xffffc0000000d200 0041 00000000 0x0 0x0
0xffffc0000000d280 0041 00000000 0x0 0x0
0xffffc0000000d300 0045 00000000 0x0 0x0
0xffffc0000000d380 0045 00000000 0x0 0x0
0xffffc0000000d400 0041 00000000 0x0 0x0
0xffffc0000000d480 0045 00000000 0x0 0x0
0xffffc0000000d500 0041 00000000 0x0 0x0
0xffffc0000000d580 0045 00000000 0x0 0x0
0xffffc0000000d600 0041 00000000 0x0 0x0
0xffffc0000000d680 0041 00000000 0x0 0x0
0xffffc0000000d700 0041 00000000 0x0 0x0
0xffffc0000000d780 0041 00000000 0x0 0x0
0xffffc0000000d800 0045 00000000 0x0 0x0
0xffffc0000000d880 0041 00000000 0x0 0x0
0xffffc0000000d900 0041 00000000 0x0 0x0
0xffffc0000000d980 0041 00000000 0x0 0x0
0xffffc0000000da00 0041 00000000 0x0 0x0
0xffffc0000000da80 0041 00000000 0x0 0x0
0xffffc0000000db00 0041 00000000 0x0 0x0
0xffffc0000000db80 0045 00000000 0x0 0x0
0xffffc0000000dc00 0041 00000000 0x0 0x0
0xffffc0000000dc80 0045 00000000 0x0 0x0
0xffffc0000000dd00 0045 00000000 0x0 0x0
0xffffc0000000dd80 0041 00000000 0x0 0x0
0xffffc0000000de00 0045 00000000 0x0 0x0
0xffffc0000000de80 0041 00000000 0x0 0x0
0xffffc0000000df00 0041 00000000 0x0 0x0
0xffffc0000000df80 0041 00000000 0x0 0x0
0xffffc0000000e000 0041 00000000 0x0 0x0
0xffffc0000000e080 0041 00000000 0x0 0x0
0xffffc0000000e100 0041 00000000 0x0 0x0
0xffffc0000000e180 0041 00000000 0x0 0x0
0xffffc0000000e200 0041 00000000 0x0 0x0
0xffffc0000000e280 0041 00000000 0x0 0x0
0xffffc0000000e300 0041 00000000 0x0 0x0
0xffffc0000000e380 0041 00000000 0x0 0x0
0xffffc0000000e400 0041 00000000 0x0 0x0
0xffffc0000000e480 0041 00000000 0x0 0x0
0xffffc0000000e500 0041 00000000 0x0 0x0
0xffffc0000000e580 0041 00000000 0x0 0x0
0xffffc0000000e600 0041 00000000 0x0 0x0
0xffffc0000000e680 0041 00000000 0x0 0x0
0xffffc0000000e700 0041 00000000 0x0 0x0
0xffffc0000000e780 0041 00000000 0x0 0x0
0xffffc0000000e800 0041 00000000 0x0 0x0
0xffffc0000000e880 0041 00000000 0x0 0x0
0xffffc0000000e900 0041 00000000 0x0 0x0
0xffffc0000000e980 0041 00000000 0x0 0x0
0xffffc0000000ea00 0041 00000000 0x0 0x0
0xffffc0000000ea80 0041 00000000 0x0 0x0
0xffffc0000000eb00 0041 00000000 0x0 0x0
0xffffc0000000eb80 0041 00000000 0x0 0x0
0xffffc0000000ec00 0041 00000000 0x0 0x0
0xffffc0000000ec80 0041 00000000 0x0 0x0
0xffffc0000000ed00 0041 00000000 0x0 0x0
0xffffc0000000ed80 0041 00000000 0x0 0x0
0xffffc0000000ee00 0041 00000000 0x0 0x0
0xffffc0000000ee80 0045 00000000 0x0 0x0
0xffffc0000000ef00 0041 00000000 0x0 0x0
0xffffc0000000ef80 0041 00000000 0x0 0x0
0xffffc0000000f000 0041 00000000 0x0 0x0
0xffffc0000000f080 0041 00000000 0x0 0x0
0xffffc0000000f100 0045 00000000 0x0 0x0
0xffffc0000000f180 0041 00000000 0x0 0x0
0xffffc0000000f200 0041 00000000 0x0 0x0
0xffffc0000000f280 0041 00000000 0x0 0x0
0xffffc0000000f300 0041 00000000 0x0 0x0
0xffffc0000000f380 0041 00000000 0x0 0x0
0xffffc0000000f400 0041 00000000 0x0 0x0
0xffffc0000000f480 0045 00000000 0x0 0x0
0xffffc0000000f500 0041 00000000 0x0 0x0
0xffffc0000000f580 0041 00000000 0x0 0x0
0xffffc0000000f600 0041 00000000 0x0 0x0
0xffffc0000000f680 0041 00000000 0x0 0x0
0xffffc0000000f700 0041 00000000 0x0 0x0
0xffffc0000000f780 0041 00000000 0x0 0x0
0xffffc0000000f800 0045 00000000 0x0 0x0
0xffffc0000000f880 0041 00000000 0x0 0x0
0xffffc0000000f900 0041 00000000 0x0 0x0
0xffffc0000000f980 0041 00000000 0x0 0x0
0xffffc0000000fa00 0041 00000000 0x0 0x0
0xffffc0000000fa80 0041 00000000 0x0 0x0
0xffffc0000000fb00 0045 00000000 0x0 0x0
0xffffc0000000fb80 0041 00000000 0x0 0x0
0xffffc0000000fc00 0041 00000000 0x0 0x0
0xffffc0000000fc80 0041 00000000 0x0 0x0
0xffffc0000000fd00 0041 00000000 0x0 0x0
0xffffc0000000fd80 0041 00000000 0x0 0x0
0xffffc0000000fe00 0041 00000000 0x0 0x0
0xffffc0000000fe80 0041 00000000 0x0 0x0
0xffffc0000000ff00 0041 00000000 0x0 0x0
0xffffc0000000ff80 0045 00000000 0x0 0x0
0xffffc00000010000 0041 00000000 0x0 0x0
0xffffc00000010080 0045 00000000 0x0 0x0
0xffffc00000010100 0001 00000000 0x0 0x0
0xffffc00000010180 0001 00000000 0x0 0x0
0xffffc00000010200 0001 00000000 0x0 0x0
0xffffc00000010280 0001 00000000 0x0 0x0
0xffffc00000010300 0001 00000000 0x0 0x0
0xffffc00000010380 0001 00000000 0x0 0x0
0xffffc00000010400 0001 00000000 0x0 0x0
0xffffc00000010480 0001 00000000 0x0 0x0
0xffffc00000010500 0001 00000000 0x0 0x0
0xffffc00000010580 0001 00000000 0x0 0x0
0xffffc00000010600 0001 00000000 0x0 0x0
0xffffc00000010680 0001 00000000 0x0 0x0
0xffffc00000010700 0001 00000000 0x0 0x0
0xffffc00000010780 0001 00000000 0x0 0x0
0xffffc00000010800 0001 00000000 0x0 0x0
0xffffc00000010880 0001 00000000 0x0 0x0
0xffffc00000010900 0001 00000000 0x0 0x0
0xffffc00000010980 0001 00000000 0x0 0x0
0xffffc00000010a00 0001 00000000 0x0 0x0
0xffffc00000010a80 0001 00000000 0x0 0x0
0xffffc00000010b00 0001 00000000 0x0 0x0
0xffffc00000010b80 0001 00000000 0x0 0x0
0xffffc00000010c00 0001 00000000 0x0 0x0
0xffffc00000010c80 0001 00000000 0x0 0x0
0xffffc00000010d00 0001 00000000 0x0 0x0
0xffffc00000010d80 0001 00000000 0x0 0x0
0xffffc00000010e00 0001 00000000 0x0 0x0
0xffffc00000010e80 0001 00000000 0x0 0x0
0xffffc00000010f00 0001 00000000 0x0 0x0
0xffffc00000010f80 0001 00000000 0x0 0x0
0xffffc00000011000 0001 00000000 0x0 0x0
0xffffc00000011080 0001 00000000 0x0 0x0
0xffffc00000011100 0001 00000000 0x0 0x0
0xffffc00000011180 0001 00000000 0x0 0x0
0xffffc00000011200 0001 00000000 0x0 0x0
0xffffc00000011280 0001 00000000 0x0 0x0
0xffffc00000011300 0001 00000000 0x0 0x0
0xffffc00000011380 0001 00000000 0x0 0x0
0xffffc00000011400 0001 00000000 0x0 0x0
0xffffc00000011480 0001 00000000 0x0 0x0
0xffffc00000011500 0001 00000000 0x0 0x0
0xffffc00000011580 0001 00000000 0x0 0x0
0xffffc00000011600 0001 00000000 0x0 0x0
0xffffc00000011680 0001 00000000 0x0 0x0
0xffffc00000011700 0001 00000000 0x0 0x0
0xffffc00000011780 0001 00000000 0x0 0x0
0xffffc00000011800 0001 00000000 0x0 0x0
0xffffc00000011880 0001 00000000 0x0 0x0
0xffffc00000011900 0001 00000000 0x0 0x0
0xffffc00000011980 0001 00000000 0x0 0x0
0xffffc00000011a00 0001 00000000 0x0 0x0
0xffffc00000011a80 0001 00000000 0x0 0x0
0xffffc00000011b00 0001 00000000 0x0 0x0
0xffffc00000011b80 0001 00000000 0x0 0x0
0xffffc00000011c00 0041 00000000 0x0 0x0
0xffffc00000011c80 0041 00000000 0x0 0x0
0xffffc00000011d00 0041 00000000 0x0 0x0
0xffffc00000011d80 0041 00000000 0x0 0x0
0xffffc00000011e00 0041 00000000 0x0 0x0
0xffffc00000011e80 0041 00000000 0x0 0x0
0xffffc00000011f00 0041 00000000 0x0 0x0
0xffffc00000011f80 0041 00000000 0x0 0x0
0xffffc00000012000 0041 00000000 0x0 0x0
0xffffc00000012080 0041 00000000 0x0 0x0
0xffffc00000012100 0041 00000000 0x0 0x0
0xffffc00000012180 0041 00000000 0x0 0x0
0xffffc00000012200 0041 00000000 0x0 0x0
0xffffc00000012280 0041 00000000 0x0 0x0
0xffffc00000012300 0041 00000000 0x0 0x0
0xffffc00000012380 0041 00000000 0x0 0x0
0xffffc00000012400 0041 00000000 0x0 0x0
0xffffc00000012480 0041 00000000 0x0 0x0
0xffffc00000012500 0041 00000000 0x0 0x0
0xffffc00000012580 0041 00000000 0x0 0x0
0xffffc00000012600 0041 00000000 0x0 0x0
0xffffc00000012680 0041 00000000 0x0 0x0
0xffffc00000012700 0041 00000000 0x0 0x0
0xffffc00000012780 0041 00000000 0x0 0x0
0xffffc00000012800 0041 00000000 0x0 0x0
0xffffc00000012880 0041 00000000 0x0 0x0
0xffffc00000012900 0041 00000000 0x0 0x0
0xffffc00000012980 0041 00000000 0x0 0x0
0xffffc00000012a00 0041 00000000 0x0 0x0
0xffffc00000012a80 0041 00000000 0x0 0x0
0xffffc00000012b00 0041 00000000 0x0 0x0
0xffffc00000012b80 0041 00000000 0x0 0x0
0xffffc00000012c00 0041 00000000 0x0 0x0
0xffffc00000012c80 0041 00000000 0x0 0x0
0xffffc00000012d00 0041 00000000 0x0 0x0
0xffffc00000012d80 0041 00000000 0x0 0x0
0xffffc00000012e00 0041 00000000 0x0 0x0
0xffffc00000012e80 0041 00000000 0x0 0x0
0xffffc00000012f00 0041 00000000 0x0 0x0
0xffffc00000012f80 0041 00000000 0x0 0x0
0xffffc00000013000 0041 00000000 0x0 0x0
0xffffc00000013080 0041 00000000 0x0 0x0
0xffffc00000013100 0041 00000000 0x0 0x0
0xffffc00000013180 0041 00000000 0x0 0x0
0xffffc00000013200 0041 00000000 0x0 0x0
0xffffc00000013280 0041 00000000 0x0 0x0
0xffffc00000013300 0041 00000000 0x0 0x0
0xffffc00000013380 0041 00000000 0x0 0x0
0xffffc00000013400 0001 00000000 0x0 0x0
0xffffc00000013480 0001 00000000 0x0 0x0
0xffffc00000013500 0001 00000000 0x0 0x0
0xffffc00000013580 0001 00000000 0x0 0x0
0xffffc00000013600 0001 00000000 0x0 0x0
0xffffc00000013680 0001 00000000 0x0 0x0
0xffffc00000013700 0001 00000000 0x0 0x0
0xffffc00000013780 0001 00000000 0x0 0x0
0xffffc00000013800 0001 00000000 0x0 0x0
0xffffc00000013880 0001 00000000 0x0 0x0
0xffffc00000013900 0001 00000000 0x0 0x0
0xffffc00000013980 0001 00000000 0x0 0x0
0xffffc00000013a00 0001 00000000 0x0 0x0
0xffffc00000013a80 0001 00000000 0x0 0x0
0xffffc00000013b00 0001 00000000 0x0 0x0
0xffffc00000013b80 0001 00000000 0x0 0x0
0xffffc00000013c00 0001 00000000 0x0 0x0
0xffffc00000013c80 0001 00000000 0x0 0x0
0xffffc00000013d00 0001 00000000 0x0 0x0
0xffffc00000013d80 0001 00000000 0x0 0x0
0xffffc00000013e00 0001 00000000 0x0 0x0
0xffffc00000013e80 0001 00000000 0x0 0x0
0xffffc00000013f00 0001 00000000 0x0 0x0
0xffffc00000013f80 0001 00000000 0x0 0x0
0xffffc00000014000 0001 00000000 0x0 0x0
0xffffc00000014080 0001 00000000 0x0 0x0
0xffffc00000014100 0001 00000000 0x0 0x0
0xffffc00000014180 0001 00000000 0x0 0x0
0xffffc00000014200 0001 00000000 0x0 0x0
0xffffc00000014280 0001 00000000 0x0 0x0
0xffffc00000014300 0001 00000000 0x0 0x0
0xffffc00000014380 0001 00000000 0x0 0x0
0xffffc00000014400 0001 00000000 0x0 0x0
0xffffc00000014480 0001 00000000 0x0 0x0
0xffffc00000014500 0001 00000000 0x0 0x0
0xffffc00000014580 0001 00000000 0x0 0x0
0xffffc00000014600 0001 00000000 0x0 0x0
0xffffc00000014680 0001 00000000 0x0 0x0
0xffffc00000014700 0001 00000000 0x0 0x0
0xffffc00000014780 0001 00000000 0x0 0x0
0xffffc00000014800 0001 00000000 0x0 0x0
0xffffc00000014880 0001 00000000 0x0 0x0
0xffffc00000014900 0001 00000000 0x0 0x0
0xffffc00000014980 0001 00000000 0x0 0x0
0xffffc00000014a00 0001 00000000 0x0 0x0
0xffffc00000014a80 0001 00000000 0x0 0x0
0xffffc00000014b00 0001 00000000 0x0 0x0
0xffffc00000014b80 0001 00000000 0x0 0x0
0xffffc00000014c00 0001 00000000 0x0 0x0
0xffffc00000014c80 0001 00000000 0x0 0x0
0xffffc00000014d00 0001 00000000 0x0 0x0
0xffffc00000014d80 0001 00000000 0x0 0x0
0xffffc00000014e00 0001 00000000 0x0 0x0
0xffffc00000014e80 0001 00000000 0x0 0x0
0xffffc00000014f00 0041 00000000 0x0 0x0
0xffffc00000014f80 0041 00000000 0x0 0x0
0xffffc00000015000 0041 00000000 0x0 0x0
0xffffc00000015080 0041 00000000 0x0 0x0
0xffffc00000015100 0041 00000000 0x0 0x0
0xffffc00000015180 0041 00000000 0x0 0x0
0xffffc00000015200 0041 00000000 0x0 0x0
0xffffc00000015280 0041 00000000 0x0 0x0
0xffffc00000015300 0041 00000000 0x0 0x0
0xffffc00000015380 0041 00000000 0x0 0x0
0xffffc00000015400 0041 00000000 0x0 0x0
0xffffc00000015480 0041 00000000 0x0 0x0
0xffffc00000015500 0041 00000000 0x0 0x0
0xffffc00000015580 0041 00000000 0x0 0x0
0xffffc00000015600 0041 00000000 0x0 0x0
0xffffc00000015680 0041 00000000 0x0 0x0
0xffffc00000015700 0041 00000000 0x0 0x0
0xffffc00000015780 0041 00000000 0x0 0x0
0xffffc00000015800 0041 00000000 0x0 0x0
0xffffc00000015880 0041 00000000 0x0 0x0
0xffffc00000015900 0041 00000000 0x0 0x0
0xffffc00000015980 0041 00000000 0x0 0x0
0xffffc00000015a00 0041 00000000 0x0 0x0
0xffffc00000015a80 0041 00000000 0x0 0x0
0xffffc00000015b00 0041 00000000 0x0 0x0
0xffffc00000015b80 0041 00000000 0x0 0x0
0xffffc00000015c00 0041 00000000 0x0 0x0
0xffffc00000015c80 0041 00000000 0x0 0x0
0xffffc00000015d00 0041 00000000 0x0 0x0
0xffffc00000015d80 0041 00000000 0x0 0x0
0xffffc00000015e00 0041 00000000 0x0 0x0
0xffffc00000015e80 0041 00000000 0x0 0x0
0xffffc00000015f00 0041 00000000 0x0 0x0
0xffffc00000015f80 0041 00000000 0x0 0x0
0xffffc00000016000 0041 00000000 0x0 0x0
0xffffc00000016080 0041 00000000 0x0 0x0
0xffffc00000016100 0041 00000000 0x0 0x0
0xffffc00000016180 0041 00000000 0x0 0x0
0xffffc00000016200 0045 00000000 0x0 0x0
0xffffc00000016280 0041 00000000 0x0 0x0
0xffffc00000016300 0041 00000000 0x0 0x0
0xffffc00000016380 0041 00000000 0x0 0x0
0xffffc00000016400 0041 00000000 0x0 0x0
0xffffc00000016480 0041 00000000 0x0 0x0
0xffffc00000016500 0001 00000000 0x0 0x0
0xffffc00000016580 0001 00000000 0x0 0x0
0xffffc00000016600 0001 00000000 0x0 0x0
0xffffc00000016680 0001 00000000 0x0 0x0
0xffffc00000016700 0001 00000000 0x0 0x0
0xffffc00000016780 0001 00000000 0x0 0x0
0xffffc00000016800 0001 00000000 0x0 0x0
0xffffc00000016880 0001 00000000 0x0 0x0
0xffffc00000016900 0001 00000000 0x0 0x0
0xffffc00000016980 0001 00000000 0x0 0x0
0xffffc00000016a00 0001 00000000 0x0 0x0
0xffffc00000016a80 0001 00000000 0x0 0x0
0xffffc00000016b00 0001 00000000 0x0 0x0
0xffffc00000016b80 0001 00000000 0x0 0x0
0xffffc00000016c00 0001 00000000 0x0 0x0
0xffffc00000016c80 0001 00000000 0x0 0x0
0xffffc00000016d00 0001 00000000 0x0 0x0
0xffffc00000016d80 0001 00000000 0x0 0x0
0xffffc00000016e00 0001 00000000 0x0 0x0
0xffffc00000016e80 0001 00000000 0x0 0x0
0xffffc00000016f00 0001 00000000 0x0 0x0
0xffffc00000016f80 0001 00000000 0x0 0x0
0xffffc00000017000 0001 00000000 0x0 0x0
0xffffc00000017080 0001 00000000 0x0 0x0
0xffffc00000017100 0001 00000000 0x0 0x0
0xffffc00000017180 0001 00000000 0x0 0x0
0xffffc00000017200 0001 00000000 0x0 0x0
0xffffc00000017280 0001 00000000 0x0 0x0
0xffffc00000017300 0001 00000000 0x0 0x0
0xffffc00000017380 0001 00000000 0x0 0x0
0xffffc00000017400 0001 00000000 0x0 0x0
0xffffc00000017480 0001 00000000 0x0 0x0
0xffffc00000017500 0001 00000000 0x0 0x0
0xffffc00000017580 0001 00000000 0x0 0x0
0xffffc00000017600 0001 00000000 0x0 0x0
0xffffc00000017680 0001 00000000 0x0 0x0
0xffffc00000017700 0001 00000000 0x0 0x0
0xffffc00000017780 0001 00000000 0x0 0x0
0xffffc00000017800 0001 00000000 0x0 0x0
0xffffc00000017880 0001 00000000 0x0 0x0
0xffffc00000017900 0001 00000000 0x0 0x0
0xffffc00000017980 0001 00000000 0x0 0x0
0xffffc00000017a00 0001 00000000 0x0 0x0
0xffffc00000017a80 0001 00000000 0x0 0x0
0xffffc00000017b00 0001 00000000 0x0 0x0
0xffffc00000017b80 0001 00000000 0x0 0x0
0xffffc00000017c00 0001 00000000 0x0 0x0
0xffffc00000017c80 0001 00000000 0x0 0x0
0xffffc00000017d00 0001 00000000 0x0 0x0
0xffffc00000017d80 0001 00000000 0x0 0x0
0xffffc00000017e00 0001 00000000 0x0 0x0
0xffffc00000017e80 0001 00000000 0x0 0x0
0xffffc00000017f00 0001 00000000 0x0 0x0
0xffffc00000017f80 0001 00000000 0x0 0x0
0xffffc00000018000 0041 00000000 0x0 0x0
0xffffc00000018080 0041 00000000 0x0 0x0
0xffffc00000018100 0041 00000000 0x0 0x0
0xffffc00000018180 0041 00000000 0x0 0x0
0xffffc00000018200 0045 00000000 0x0 0x0
0xffffc00000018280 0041 00000000 0x0 0x0
0xffffc00000018300 0041 00000000 0x0 0x0
0xffffc00000018380 0041 00000000 0x0 0x0
0xffffc00000018400 0041 00000000 0x0 0x0
0xffffc00000018480 0041 00000000 0x0 0x0
0xffffc00000018500 0041 00000000 0x0 0x0
0xffffc00000018580 0045 00000000 0x0 0x0
0xffffc00000018600 0045 00000000 0x0 0x0
0xffffc00000018680 0041 00000000 0x0 0x0
0xffffc00000018700 0041 00000000 0x0 0x0
0xffffc00000018780 0041 00000000 0x0 0x0
0xffffc00000018800 0041 00000000 0x0 0x0
0xffffc00000018880 0041 00000000 0x0 0x0
0xffffc00000018900 0041 00000000 0x0 0x0
0xffffc00000018980 0045 00000000 0x0 0x0
0xffffc00000018a00 0045 00000000 0x0 0x0
0xffffc00000018a80 0041 00000000 0x0 0x0
0xffffc00000018b00 0041 00000000 0x0 0x0
0xffffc00000018b80 0041 00000000 0x0 0x0
0xffffc00000018c00 0041 00000000 0x0 0x0
0xffffc00000018c80 0041 00000000 0x0 0x0
0xffffc00000018d00 0041 00000000 0x0 0x0
0xffffc00000018d80 0045 00000000 0x0 0x0
0xffffc00000018e00 0045 00000000 0x0 0x0
0xffffc00000018e80 0045 00000000 0x0 0x0
0xffffc00000018f00 0041 00000000 0x0 0x0
0xffffc00000018f80 0041 00000000 0x0 0x0
0xffffc00000019000 0045 00000000 0x0 0x0
0xffffc00000019080 0041 00000000 0x0 0x0
0xffffc00000019100 0045 00000000 0x0 0x0
0xffffc00000019180 0045 00000000 0x0 0x0
0xffffc00000019200 0045 00000000 0x0 0x0
0xffffc00000019280 0045 00000000 0x0 0x0
0xffffc00000019300 0041 00000000 0x0 0x0
0xffffc00000019380 0041 00000000 0x0 0x0
0xffffc00000019400 0045 00000000 0x0 0x0
0xffffc00000019480 0041 00000000 0x0 0x0
0xffffc00000019500 0045 00000000 0x0 0x0
0xffffc00000019580 0045 00000000 0x0 0x0
0xffffc00000019600 0045 00000000 0x0 0x0
0xffffc00000019680 0045 00000000 0x0 0x0
0xffffc00000019700 0045 00000000 0x0 0x0
0xffffc00000019780 0041 00000000 0x0 0x0
0xffffc00000019800 0001 00000000 0x0 0x0
0xffffc00000019880 0001 00000000 0x0 0x0
0xffffc00000019900 0001 00000000 0x0 0x0
0xffffc00000019980 0001 00000000 0x0 0x0
0xffffc00000019a00 0001 00000000 0x0 0x0
0xffffc00000019a80 0001 00000000 0x0 0x0
0xffffc00000019b00 0001 00000000 0x0 0x0
0xffffc00000019b80 0001 00000000 0x0 0x0
0xffffc00000019c00 0001 00000000 0x0 0x0
0xffffc00000019c80 0001 00000000 0x0 0x0
0xffffc00000019d00 0001 00000000 0x0 0x0
0xffffc00000019d80 0001 00000000 0x0 0x0
0xffffc00000019e00 0001 00000000 0x0 0x0
0xffffc00000019e80 0001 00000000 0x0 0x0
0xffffc00000019f00 0001 00000000 0x0 0x0
0xffffc00000019f80 0001 00000000 0x0 0x0
0xffffc0000001a000 0001 00000000 0x0 0x0
0xffffc0000001a080 0001 00000000 0x0 0x0
0xffffc0000001a100 0001 00000000 0x0 0x0
0xffffc0000001a180 0001 00000000 0x0 0x0
0xffffc0000001a200 0001 00000000 0x0 0x0
0xffffc0000001a280 0001 00000000 0x0 0x0
0xffffc0000001a300 0001 00000000 0x0 0x0
0xffffc0000001a380 0001 00000000 0x0 0x0
0xffffc0000001a400 0001 00000000 0x0 0x0
0xffffc0000001a480 0001 00000000 0x0 0x0
0xffffc0000001a500 0001 00000000 0x0 0x0
0xffffc0000001a580 0001 00000000 0x0 0x0
0xffffc0000001a600 0001 00000000 0x0 0x0
0xffffc0000001a680 0001 00000000 0x0 0x0
0xffffc0000001a700 0001 00000000 0x0 0x0
0xffffc0000001a780 0001 00000000 0x0 0x0
0xffffc0000001a800 0001 00000000 0x0 0x0
0xffffc0000001a880 0001 00000000 0x0 0x0
0xffffc0000001a900 0001 00000000 0x0 0x0
0xffffc0000001a980 0001 00000000 0x0 0x0
0xffffc0000001aa00 0001 00000000 0x0 0x0
0xffffc0000001aa80 0001 00000000 0x0 0x0
0xffffc0000001ab00 0001 00000000 0x0 0x0
0xffffc0000001ab80 0001 00000000 0x0 0x0
0xffffc0000001ac00 0001 00000000 0x0 0x0
0xffffc0000001ac80 0

---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

Maxime Villard

unread,
Jun 27, 2020, 3:13:55 AM6/27/20
to syzbot+88ddf1...@syzkaller.appspotmail.com, syzkaller-netbsd-bugs
#syz dup: page fault in statvfs_to_statfs12_copy
Reply all
Reply to author
Forward
0 new messages