assert failed: rv (2)

0 views
Skip to first unread message

syzbot

unread,
Oct 26, 2019, 3:30:10 PM10/26/19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 8a749946 In non-MBR specific files, #ifdef all tests for M..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1466f024e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=6e4d6bd2b8e377a2
dashboard link: https://syzkaller.appspot.com/bug?extid=2a84e8bb0967d5b95a73

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2a84e8...@syzkaller.appspotmail.com

[ 106.0302963] panic: kernel diagnostic assertion "rv" failed:
file "/syzkaller/managers/netbsd/kernel/sys/miscfs/genfs/genfs_io.c", line
1907
[ 106.0414049] cpu1: Begin traceback...
[ 106.0636574] vpanic() at netbsd:[ 106.0747787] vpanic+0x267
[ 106.1081519] _GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
[ 106.1526487] genfs_directio() at netbsd:genfs_directio+0x9eb
genfs_do_directio sys/miscfs/genfs/genfs_io.c:1907 [inline]
[ 106.1526487] genfs_directio() at netbsd:genfs_directio+0x9eb
sys/miscfs/genfs/genfs_io.c:1798
[ 106.1971531] ffs_write() at netbsd:ffs_write+0x6fa
sys/ufs/ufs/ufs_readwrite.c:354
[ 106.2416461] VOP_WRITE() at netbsd:VOP_WRITE+0x13a sys/kern/vnode_if.c:506
[ 106.2972692] vn_write() at netbsd:vn_write+0x1c3 sys/kern/vfs_vnops.c:609
[ 106.3417640] do_filewritev() at netbsd:do_filewritev+0x452
sys/kern/sys_generic.c:472
[ 106.3862616] sys___syscall() at netbsd:sys___syscall+0xf5 sy_call
sys/sys/syscallvar.h:65 [inline]
[ 106.3862616] sys___syscall() at netbsd:sys___syscall+0xf5
sys/kern/sys_syscall.c:77
[ 106.4418803] syscall() at netbsd:syscall+0x3ac sy_call
sys/sys/syscallvar.h:65 [inline]
[ 106.4418803] syscall() at netbsd:syscall+0x3ac sy_invoke
sys/sys/syscallvar.h:94 [inline]
[ 106.4418803] syscall() at netbsd:syscall+0x3ac
sys/arch/x86/x86/syscall.c:138
[ 106.4530097] --- syscall (number 198) ---
[ 106.4752556] 7c09ca443b9a:
[ 106.4752556] cpu1: End traceback...
[ 106.4752556] fatal breakpoint trap in supervisor mode
[ 106.4863761] trap type 1 code 0 rip 0xffffffff8021ccd5 cs 0x8 rflags
0x246 cr2 0x628060 ilevel 0x8 rsp 0xffff9a017b8c0700
[ 106.4975057] curlwp 0xffff9a0013d29300 pid 329.2 lowest kstack
0xffff9a017b8b92c0
Stopped in pid 329.2 (syz-executor.3) at netbsd:breakpoint+0x5:
leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xf9 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x267 sys/kern/subr_prf.c:336
_GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
genfs_directio() at netbsd:genfs_directio+0x9eb genfs_do_directio
sys/miscfs/genfs/genfs_io.c:1907 [inline]
genfs_directio() at netbsd:genfs_directio+0x9eb
sys/miscfs/genfs/genfs_io.c:1798
ffs_write() at netbsd:ffs_write+0x6fa sys/ufs/ufs/ufs_readwrite.c:354
VOP_WRITE() at netbsd:VOP_WRITE+0x13a sys/kern/vnode_if.c:506
vn_write() at netbsd:vn_write+0x1c3 sys/kern/vfs_vnops.c:609
do_filewritev() at netbsd:do_filewritev+0x452 sys/kern/sys_generic.c:472
sys___syscall() at netbsd:sys___syscall+0xf5 sy_call
sys/sys/syscallvar.h:65 [inline]
sys___syscall() at netbsd:sys___syscall+0xf5 sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x3ac sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x3ac sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x3ac sys/arch/x86/x86/syscall.c:138
--- syscall (number 198) ---
7c09ca443b9a:
ds 0
es 1
fs 7b9
gs fd30
rdi ffff9a000d92d458
rsi ffff9a0013d295e8
rbp ffff9a017b8c0700
rbx ffff9a016d892000
rdx 3ffff
rcx ffff9a0172461000
rax ffff9a0013ca2248
r8 4
r9 ffffffff82a9b543 db_onpanic+0x3
r10 1ffffffff05536a8
r11 8000000000
r12 ffff9a016d8a4000
r13 ffffffff821c9ca0 fiforead_filtops+0x120
r14 ffff9a017b8c0790
r15 ffff9a016d892058
rip ffffffff8021ccd5 breakpoint+0x5
cs 8
rflags 246
rsp ffff9a017b8c0700
ss 10
netbsd:breakpoint+0x5: leave
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
193 1 3 0 80 ffff9a0013fb81c0 syz-executor.4 parked
192 1 3 0 80 ffff9a0013fa1a20 syz-executor.4 parked
890 1 4 0 1000000 ffff9a0013fa11a0 syz-executor.4
739 1 3 0 80 ffff9a0013f8fa00 syz-executor.2 parked
618 1 3 0 80 ffff9a0013f875a0 syz-executor.3 parked
883 1 3 0 10000004 ffff9a0013ce16e0 syz-executor.2 xclocv
644 1 3 1 40080 ffff9a0013d5ebc0 syz-executor.1 parked
1012 5 2 1 0 ffff9a0013f87160 syz-executor.5
1012 4 2 1 0 ffff9a0013735200 syz-executor.5
1012 3 3 1 0 ffff9a0012e021a0 syz-executor.5 tstile
1012 2 3 0 0 ffff9a0011ea61a0 syz-executor.5 tstile
1012 1 2 1 10040000 ffff9a0013556a60 syz-executor.5
798 1 3 1 40080 ffff9a0013c88b00 syz-executor.3 parked
329 6 3 0 80 ffff9a0013f8f180 syz-executor.3 parked
329 5 3 1 80 ffff9a0013f879e0 syz-executor.3 parked
329 4 3 1 80 ffff9a0012322ae0 syz-executor.3 parked
329 3 3 0 80 ffff9a0012e0e1c0 syz-executor.3 parked
329 > 2 7 1 0 ffff9a0013d29300 syz-executor.3
329 1 2 1 10040000 ffff9a001216c300 syz-executor.3
655 3 3 1 40080 ffff9a0012db60c0 syz-executor.4 parked
655 2 3 0 80 ffff9a0012dcb980 syz-executor.4 parked
655 1 2 0 10040000 ffff9a00121252c0 syz-executor.4
723 1 3 0 80 ffff9a0013ded940 syz-executor.1 parked
444 1 3 0 80 ffff9a0012330b00 syz-executor.4 parked
818 1 3 0 80 ffff9a0013ded500 syz-executor.4 parked
687 5 3 1 80 ffff9a0013d688c0 syz-executor.0 parked
687 4 2 0 0 ffff9a0012182ba0 syz-executor.0
687 3 2 0 0 ffff9a0012314ac0 syz-executor.0
687 2 3 0 80 ffff9a0013d052c0 syz-executor.0 parked
687 1 2 1 10040000 ffff9a0013e08980 syz-executor.0
301 1 3 1 80 ffff9a0012289120 syz-executor.0 parked
290 1 3 1 80 ffff9a00122004c0 syz-executor.4 parked
620 1 3 1 80 ffff9a00122b65c0 syz-executor.3 parked
823 1 3 0 80 ffff9a00121ca340 syz-executor.3 parked
205 1 3 0 80 ffff9a00122899a0 syz-executor.4 parked
612 1 3 1 80 ffff9a00122250c0 syz-executor.1 parked
136 1 3 1 80 ffff9a0013d68040 syz-executor.3 parked
438 1 3 1 80 ffff9a0012dae0a0 syz-executor.3 parked
718 1 3 0 80 ffff9a0013d05b40 syz-executor.3 parked
597 1 3 0 80 ffff9a0012140b60 syz-executor.3 parked
720 1 3 1 80 ffff9a0012e02a20 syz-executor.3 parked
657 1 3 0 80 ffff9a00122f6200 syz-executor.1 parked
805 1 3 0 80 ffff9a0012d5dbc0 syz-executor.2 parked
688 1 3 1 80 ffff9a0012dd6120 syz-executor.5 parked
686 1 3 1 80 ffff9a0012125b40 syz-executor.3 parked
724 1 3 1 80 ffff9a0013d9c8e0 syz-executor.5 parked
639 1 3 1 80 ffff9a0013d9c4a0 syz-executor.5 parked
569 1 3 0 80 ffff9a0012314680 syz-executor.2 parked
615 1 3 1 80 ffff9a001216c740 syz-executor.2 parked
97 1 3 1 80 ffff9a0013d9c060 syz-executor.2 parked
96 1 3 0 80 ffff9a0012e0e600 syz-executor.2 parked
561 1 2 1 0 ffff9a0013c886c0 syz-executor.4
530 1 2 1 0 ffff9a0013c88280 syz-executor.3
41 1 2 1 0 ffff9a0013c0fae0 syz-executor.5
40 1 4 1 1000000 ffff9a0013c0f6a0 syz-executor.2
543 1 3 0 80 ffff9a0013c0f260 syz-executor.1 pipe_rd
614 1 2 1 0 ffff9a0013af4ac0 syz-executor.0
619 12 3 1 80 ffff9a0013af4680 syz-fuzzer parked
619 11 3 1 80 ffff9a0013af4240 syz-fuzzer parked
619 10 3 0 80 ffff9a0012d42760 syz-fuzzer kqueue
619 9 3 0 80 ffff9a0013ab6aa0 syz-fuzzer parked
619 8 3 0 80 ffff9a0013ab6220 syz-fuzzer parked
619 7 3 0 80 ffff9a0013735a80 syz-fuzzer parked
619 6 3 0 80 ffff9a0013735640 syz-fuzzer parked
619 5 3 1 80 ffff9a0012de19c0 syz-fuzzer parked
619 4 3 1 80 ffff9a0012df2a00 syz-fuzzer parked
619 3 3 0 80 ffff9a0012df2180 syz-fuzzer parked
619 2 3 1 80 ffff9a0011ea45a0 syz-fuzzer parked
619 1 3 1 80 ffff9a0011ea5180 syz-fuzzer parked
599 1 3 0 80 ffff9a0011ea55c0 sshd select
473 1 3 1 80 ffff9a0012df25c0 getty nanoslp
568 1 3 1 80 ffff9a0012de99e0 getty nanoslp
571 1 3 1 80 ffff9a0012de95a0 getty nanoslp
501 1 3 0 80 ffff9a0012e025e0 getty ttyraw
381 1 3 0 80 ffff9a0012dd6560 cron nanoslp
519 1 3 0 80 ffff9a0012d8e900 inetd kqueue
396 1 3 0 80 ffff9a0012346b20 sshd select
474 1 3 1 80 ffff9a00122e71e0 powerd kqueue
323 > 1 7 0 40000 ffff9a0012215920 makemandb
202 1 2 1 0 ffff9a0012d5d780 syslogd
278 1 3 0 80 ffff9a00122e7620 dhcpcd kqueue
220 1 3 1 80 ffff9a00122150a0 dhcpcd kqueue
1 1 3 0 80 ffff9a0012010240 init wait
0 58 3 0 204 ffff9a0012010ac0 physiod physiod
0 57 3 1 204 ffff9a00120596a0 pooldrain pooldrain
0 56 3 0 204 ffff9a001205a280 aiodoned aiodoned
0 55 3 1 200 ffff9a0012059ae0 ioflush syncer
0 54 3 1 200 ffff9a0012059260 pgdaemon pgdaemon
0 51 3 1 200 ffff9a0012010680 npfgc-0 npfgccv
0 50 3 0 204 ffff9a0011ffeaa0 rt_free rt_free
0 49 3 0 204 ffff9a0011ffe660 unpgc unpgc
0 48 3 1 204 ffff9a0011ffe220 key_timehandler
key_timehandler
0 47 3 1 204 ffff9a0011ed4a80 icmp6_wqinput/1
icmp6_wqinput
0 46 3 0 204 ffff9a0011ed4640 icmp6_wqinput/0
icmp6_wqinput
0 45 3 1 204 ffff9a0011ed4200 nd6_timer nd6_timer
0 44 3 1 204 ffff9a0011ecba60 carp6_wqinput/1
carp6_wqinput
0 43 3 0 204 ffff9a0011ecb620 carp6_wqinput/0
carp6_wqinput
0 42 3 1 204 ffff9a0011ecb1e0 carp_wqinput/1
carp_wqinput
0 41 3 0 204 ffff9a0011eb7a40 carp_wqinput/0
carp_wqinput
0 40 3 1 204 ffff9a0011eb7600 icmp_wqinput/1
icmp_wqinput
0 39 3 0 204 ffff9a0011eb71c0 icmp_wqinput/0
icmp_wqinput
0 38 3 1 204 ffff9a0011ea6a20 rt_timer rt_timer
0 37 3 1 204 ffff9a0011ea65e0 vmem_rehash vmem_rehash
0 27 3 0 204 ffff9a000f7ca580 scsibus0 sccomp
0 26 3 0 200 ffff9a000f7ca140 pms0 pmsreset
0 25 2 1 200 ffff9a000f73c9a0 xcall/1
0 24 1 1 200 ffff9a000f73c560 softser/1
0 23 1 1 200 ffff9a000f73c120 softclk/1
0 22 1 1 200 ffff9a000f738980 softbio/1
0 21 1 1 200 ffff9a000f738540 softnet/1
0 20 1 1 201 ffff9a000f738100 idle/1
0 19 3 1 204 ffff9a000f66e960 lnxpwrwq lnxpwrwq
0 18 3 1 204 ffff9a000f66e520 lnxlngwq lnxlngwq
0 17 3 1 204 ffff9a000f66e0e0 lnxsyswq lnxsyswq
0 16 3 0 204 ffff9a000de53940 lnxrcugc lnxrcugc
0 15 3 0 204 ffff9a000de53500 sysmon smtaskq
0 14 3 1 204 ffff9a000de530c0 pmfsuspend pmfsuspend
0 13 3 0 204 ffff9a000de43920 pmfevent pmfevent
0 12 3 0 204 ffff9a000de434e0 sopendfree sopendfr
0 11 3 1 204 ffff9a000de430a0 nfssilly nfssilly
0 10 3 1 200 ffff9a000de39900 cachegc cachegc
0 9 2 1 200 ffff9a000de394c0 vdrain
0 8 3 0 200 ffff9a000de39080 modunload mod_unld
0 7 3 0 204 ffff9a000de2b8e0 xcall/0 xcall
0 6 1 0 200 ffff9a000de2b4a0 softser/0
0 5 1 0 200 ffff9a000de2b060 softclk/0
0 4 1 0 200 ffff9a000de268c0 softbio/0
0 3 1 0 200 ffff9a000de26480 softnet/0
0 2 1 0 201 ffff9a000de26040 idle/0
0 1 2 0 200 ffffffff82b63600 swapper
[Locks tracked through LWPs]
Locks held by an LWP (syz-executor.5):
Lock 0 (initialized at vcache_alloc)
lock address : 0xffff9a0013f39d00 type : sleep/adaptive
initialized : 0xffffffff812a86cb
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
current cpu : 1 last held: 1
current lwp : 0xffff9a0013d29300 last held: 0xffff9a0013735200
last locked* : 0xffffffff812d75e0 unlocked : 0xffffffff812d7613
owner/count : 0xffff9a0013735200 flags : 0x0000000000000007

Turnstile chain at 0xffffffff82d7c640.
=> Turnstile at 0xffff9a0012d751f8 (wrq=0xffff9a0012d75218,
rdq=0xffff9a0012d75228).
=> 0 waiting readers:
=> 1 waiting writers: 0xffff9a0012e021a0

Locks held by an LWP (syz-executor.5):
Lock 0 (initialized at vcache_alloc)
lock address : 0xffff9a0012267768 type : sleep/adaptive
initialized : 0xffffffff812a86cb
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
current cpu : 1 last held: 1
current lwp : 0xffff9a0013d29300 last held: 0xffff9a0012e021a0
last locked* : 0xffffffff812d75e0 unlocked : 0xffffffff812d7613
owner/count : 0xffff9a0012e021a0 flags : 0x0000000000000007

Turnstile chain at 0xffffffff82d7c710.
=> Turnstile at 0xffff9a0012d75330 (wrq=0xffff9a0012d75350,
rdq=0xffff9a0012d75360).
=> 0 waiting readers:
=> 1 waiting writers: 0xffff9a0011ea61a0

Locks held by an LWP (syz-executor.3):
Lock 0 (initialized at vcache_alloc)
lock address : 0xffff9a0012229f68 type : sleep/adaptive
initialized : 0xffffffff812a86cb
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xffff9a0013d29300 last held: 0xffff9a0013d29300
last locked* : 0xffffffff812d75e0 unlocked : 0xffffffff812d7613
owner/count : 0xffff9a0013d29300 flags : 0x0000000000000004

Turnstile chain at 0xffffffff82d7c710.
=> No active turnstile for this lock.

Locks held by an LWP (makemandb):
Lock 0 (initialized at amap_alloc)
lock address : 0xffff9a0013dcf980 type : sleep/adaptive
initialized : 0xffffffff810c25a2
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 0
current lwp : 0xffff9a0013d29300 last held: 0xffff9a0012215920
last locked* : 0xffffffff810d1f21 unlocked : 0xffffffff810d03c7
owner field : 000000000000000000 wait/spin: 0/0

Turnstile chain at 0xffffffff82d7c740.
=> No active turnstile for this lock.


[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffff9a0000014180 0048 0000 0x0 0x0
0xffff9a00000141f8 0048 0000 0x0 0x0
0xffff9a0000014270 0048 0000 0x0 0x0
0xffff9a00000142e8 0048 0000 0x0 0x0
0xffff9a0000014360 0048 0000 0x0 0x0
0xffff9a00000143d8 0040 0000 0x0 0x0
0xffff9a0000014450 0048 0000 0x0 0x0
0xffff9a00000144c8 0048 0000 0x0 0x0
0xffff9a0000014540 0048 0000 0x0 0x0
0xffff9a00000145b8 0048 0000 0x0 0x0
0xffff9a0000014630 0048 0000 0x0 0x0
0xffff9a00000146a8 0048 0000 0x0 0x0
0xffff9a0000014720 0048 0000 0x0 0x0
0xffff9a0000014798 0048 0000 0x0 0x0
0xffff9a0000014810 0040 0000 0x0 0x0
0xffff9a0000014888 0040 0000 0x0 0x0
0xffff9a0000014900 0040 0000 0x0 0x0
0xffff9a0000014978 0040 0000 0x0 0x0
0xffff9a00000149f0 0040 0000 0x0 0x0
0xffff9a0000014a68 0040 0000 0x0 0x0
0xffff9a0000014ae0 0040 0000 0x0 0x0
0xffff9a0000014b58 0040 0000 0x0 0x0
0xffff9a0000014bd0 0048 0000 0x0 0x0
0xffff9a0000014c48 0048 0000 0x0 0x0
0xffff9a0000014cc0 0048 0000 0x0 0x0
0xffff9a0000014d38 0048 0000 0x0 0x0
0xffff9a0000014db0 0048 0000 0x0 0x0
0xffff9a0000014e28 0048 0000 0x0 0x0
0xffff9a0000014ea0 0048 0000 0x0 0x0
0xffff9a0000014f18 0048 0000 0x0 0x0
0xffff9a0000014f90 0048 0000 0x0 0x0
0xffff9a0000015008 0048 0000 0x0 0x0
0xffff9a0000015080 0048 0000 0x0 0x0
0xffff9a00000150f8 0048 0000 0x0 0x0
0xffff9a0000015170 0048 0000 0x0 0x0
0xffff9a00000151e8 0048 0000 0x0 0x0
0xffff9a0000015260 0048 0000 0x0 0x0
0xffff9a00000152d8 0048 0000 0x0 0x0
0xffff9a0000015350 0048 0000 0x0 0x0
0xffff9a00000153c8 0048 0000 0x0 0x0
0xffff9a0000015440 0048 0000 0x0 0x0
0xffff9a00000154b8 0048 0000 0x0 0x0
0xffff9a0000015530 0048 0000 0x0 0x0
0xffff9a00000155a8 0048 0000 0x0 0x0
0xffff9a0000015620 0048 0000 0x0 0x0
0xffff9a0000015698 0048 0000 0x0 0x0
0xffff9a0000015710 0048 0000 0x0 0x0
0xffff9a0000015788 0048 0000 0x0 0x0
0xffff9a0000015800 0048 0000 0x0 0x0
0xffff9a0000015878 0048 0000 0x0 0x0
0xffff9a00000158f0 0048 0000 0x0 0x0
0xffff9a0000015968 0048 0000 0x0 0x0
0xffff9a00000159e0 0048 0000 0x0 0x0
0xffff9a0000015a58 0048 0000 0x0 0x0
0xffff9a0000015ad0 0048 0000 0x0 0x0
0xffff9a0000015b48 0048 0000 0x0 0x0
0xffff9a0000015bc0 0048 0000 0x0 0x0
0xffff9a0000015c38 0048 0000 0x0 0x0
0xffff9a0000015cb0 0048 0000 0x0 0x0
0xffff9a0000015d28 0048 0000 0x0 0x0
0xffff9a0000015da0 0048 0000 0x0 0x0
0xffff9a0000015e18 0048 0000 0x0 0x0
0xffff9a0000015e90 0048 0000 0x0 0x0
0xffff9a0000015f08 0048 0000 0x0 0x0
0xffff9a0000015f80 0048 0000 0x0 0x0
0xffff9a0000015ff8 0048 0000 0x0 0x0
0xffff9a0000016070 0040 0000 0x0 0x0
0xffff9a00000160e8 0041 0000 0x0 0x0
0xffff9a0000016160 0041 0000 0x0 0x0
0xffff9a00000161d8 0048 0000 0x0 0x0
0xffff9a0000016250 0048 0000 0x0 0x0
0xffff9a00000162c8 0048 0000 0x0 0x0
0xffff9a0000016340 0048 0000 0x0 0x0
0xffff9a00000163b8 0040 0000 0x0 0x0
0xffff9a0000016430 0041 0000 0x0 0x0
0xffff9a00000164a8 0041 0000 0x0 0x0
0xffff9a0000016520 0041 0000 0x0 0x0
0xffff9a0000016598 0048 0000 0x0 0x0
0xffff9a0000016610 0040 0000 0x0 0x0
0xffff9a0000016688 0048 0000 0x0 0x0
0xffff9a0000016700 0048 0000 0x0 0x0
0xffff9a0000016778 0041 0000 0x0 0x0
0xffff9a00000167f0 0041 0000 0x0 0x0
0xffff9a0000016868 0048 0000 0x0 0x0
0xffff9a00000168e0 0048 0000 0x0 0x0
0xffff9a0000016958 0041 0000 0x0 0x0
0xffff9a00000169d0 0041 0000 0x0 0x0
0xffff9a0000016a48 0040 0000 0x0 0x0
0xffff9a0000016ac0 0040 0000 0x0 0x0
0xffff9a0000016b38 0041 0000 0x0 0x0
0xffff9a0000016bb0 0048 0000 0x0 0x0
0xffff9a0000016c28 0048 0000 0x0 0x0
0xffff9a0000016ca0 0048 0000 0x0 0x0
0xffff9a0000016d18 0041 0000 0x0 0x0
0xffff9a0000016d90 0041 0000 0x0 0x0
0xffff9a0000016e08 0041 0000 0x0 0x0
0xffff9a0000016e80 0041 0000 0x0 0x0
0xffff9a0000016ef8 0048 0000 0x0 0x0
0xffff9a0000016f70 0048 0000 0x0 0x0
0xffff9a0000016fe8 0048 0000 0x0 0x0
0xffff9a0000017060 0048 0000 0x0 0x0
0xffff9a00000170d8 0048 0000 0x0 0x0
0xffff9a0000017150 0048 0000 0x0 0x0
0xffff9a00000171c8 0041 0000 0x0 0x0
0xffff9a0000017240 0041 0000 0x0 0x0
0xffff9a00000172b8 0048 0000 0x0 0x0
0xffff9a0000017330 0048 0000 0x0 0x0
0xffff9a00000173a8 0048 0000 0x0 0x0
0xffff9a0000017420 0048 0000 0x0 0x0
0xffff9a0000017498 0048 0000 0x0 0x0
0xffff9a0000017510 0048 0000 0x0 0x0
0xffff9a0000017588 0048 0000 0x0 0x0
0xffff9a0000017600 0048 0000 0x0 0x0
0xffff9a0000017678 0048 0000 0x0 0x0
0xffff9a00000176f0 0048 0000 0x0 0x0
0xffff9a0000017768 0048 0000 0x0 0x0
0xffff9a00000177e0 0048 0000 0x0 0x0
0xffff9a0000017858 0048 0000 0x0 0x0
0xffff9a00000178d0 0048 0000 0x0 0x0
0xffff9a0000017948 0048 0000 0x0 0x0
0xffff9a00000179c0 0048 0000 0x0 0x0
0xffff9a0000017a38 0048 0000 0x0 0x0
0xffff9a0000017ab0 0048 0000 0x0 0x0
0xffff9a0000017b28 0048 0000 0x0 0x0
0xffff9a0000017ba0 0048 0000 0x0 0x0
0xffff9a0000017c18 0048 0000 0x0 0x0
0xffff9a0000017c90 0048 0000 0x0 0x0
0xffff9a0000017d08 0048 0000 0x0 0x0
0xffff9a0000017d80 0048 0000 0x0 0x0
0xffff9a0000017df8 0048 0000 0x0 0x0
0xffff9a0000017e70 0048 0000 0x0 0x0
0xffff9a0000017ee8 0048 0000 0x0 0x0
0xffff9a0000017f60 0048 0000 0x0 0x0
0xffff9a0000017fd8 0048 0000 0x0 0x0
0xffff9a0000018050 0048 0000 0x0 0x0
0xffff9a00000180c8 0048 0000 0x0 0x0
0xffff9a0000018140 0048 0000 0x0 0x0
0xffff9a00000181b8 0048 0000 0x0 0x0
0xffff9a0000018230 0048 0000 0x0 0x0
0xffff9a00000182a8 0048 0000 0x0 0x0
0xffff9a0000018320 0048 0000 0x0 0x0
0xffff9a0000018398 0048 0000 0x0 0x0
0xffff9a0000018410 0048 0000 0x0 0x0
0xffff9a0000018488 0048 0000 0x0 0x0
0xffff9a0000018500 0048 0000 0x0 0x0
0xffff9a0000018578 0048 0000 0x0 0x0
0xffff9a00000185f0 0048 0000 0x0 0x0
0xffff9a0000018668 0048 0000 0x0 0x0
0xffff9a00000186e0 0048 0000 0x0 0x0
0xffff9a0000018758 0048 0000 0x0 0x0
0xffff9a00000187d0 0048 0000 0x0 0x0
0xffff9a0000018848 0048 0000 0x0 0x0
0xffff9a00000188c0 0048 0000 0x0 0x0
0xffff9a0000018938 0048 0000 0x0 0x0
0xffff9a00000189b0 0048 0000 0x0 0x0
0xffff9a0000018a28 0048 0000 0x0 0x0
0xffff9a0000018aa0 0048 0000 0x0 0x0
0xffff9a0000018b18 0048 0000 0x0 0x0
0xffff9a0000018b90 0048 0000 0x0 0x0
0xffff9a0000018c08 0048 0000 0x0 0x0
0xffff9a0000018c80 0048 0000 0x0 0x0
0xffff9a0000018cf8 0048 0000 0x0 0x0
0xffff9a0000018d70 0048 0000 0x0 0x0
0xffff9a0000018de8 0048 0000 0x0 0x0
0xffff9a0000018e60 0048 0000 0x0 0x0
0xffff9a0000018ed8 0048 0000 0x0 0x0
0xffff9a0000018f50 0048 0000 0x0 0x0
0xffff9a0000018fc8 0048 0000 0x0 0x0
0xffff9a0000019040 0048 0000 0x0 0x0
0xffff9a00000190b8 0048 0000 0x0 0x0
0xffff9a0000019130 0048 0000 0x0 0x0
0xffff9a00000191a8 0048 0000 0x0 0x0
0xffff9a0000019220 0048 0000 0x0 0x0
0xffff9a0000019298 0048 0000 0x0 0x0
0xffff9a0000019310 0048 0000 0x0 0x0
0xffff9a0000019388 0048 0000 0x0 0x0
0xffff9a0000019400 0048 0000 0x0 0x0
0xffff9a0000019478 0048 0000 0x0 0x0
0xffff9a00000194f0 0048 0000 0x0 0x0
0xffff9a0000019568 0048 0000 0x0 0x0
0xffff9a00000195e0 0048 0000 0x0 0x0
0xffff9a0000019658 0048 0000 0x0 0x0
0xffff9a00000196d0 0048 0000 0x0 0x0
0xffff9a0000019748 0048 0000 0x0 0x0
0xffff9a00000197c0 0048 0000 0x0 0x0
0xffff9a0000019838 0048 0000 0x0 0x0
0xffff9a00000198b0 0048 0000 0x0 0x0
0xffff9a0000019928 0048 0000 0x0 0x0
0xffff9a00000199a0 0048 0000 0x0 0x0
0xffff9a0000019a18 0048 0000 0x0 0x0
0xffff9a0000019a90 0048 0000 0x0 0x0
0xffff9a0000019b08 0048 0000 0x0 0x0
0xffff9a0000019b80 0048 0000 0x0 0x0
0xffff9a0000019bf8 0048 0000 0x0 0x0
0xffff9a0000019c70 0048 0000 0x0 0x0
0xffff9a0000019ce8 0048 0000 0x0 0x0
0xffff9a0000019d60 0048 0000 0x0 0x0
0xffff9a0000019dd8 0048 0000 0x0 0x0
0xffff9a0000019e50 0048 0000 0x0 0x0
0xffff9a0000019ec8 0048 0000 0x0 0x0
0xffff9a0000019f40 0048 0000 0x0 0x0
0xffff9a0000019fb8 0048 0000 0x0 0x0
0xffff9a000001a030 0048 0000 0x0 0x0
0xffff9a000001a0a8 0048 0000 0x0 0x0
0xffff9a000001a120 0048 0000 0x0 0x0
0xffff9a000001a198 0048 0000 0x0 0x0
0xffff9a000001a210 0048 0000 0x0 0x0
0xffff9a000001a288 0048 0000 0x0 0x0
0xffff9a000001a300 0048 0000 0x0 0x0
0xffff9a000001a378 0048 0000 0x0 0x0
0xffff9a000001a3f0 0048 0000 0x0 0x0
0xffff9a000001a468 0048 0000 0x0 0x0
0xffff9a000001a4e0 0048 0000 0x0 0x0
0xffff9a000001a558 0048 0000 0x0 0x0
0xffff9a000001a5d0 0048 0000 0x0 0x0
0xffff9a000001a648 0048 0000 0x0 0x0
0xffff9a000001a6c0 0048 0000 0x0 0x0
0xffff9a000001a738 0008 0000 0x0 0x0
0xffff9a000001a7b0 0008 0000 0x0 0x0
0xffff9a000001a828 0008 0000 0x0 0x0
0xffff9a000001a8a0 0008 0000 0x0 0x0
0xffff9a000001a918 0008 0000 0x0 0x0
0xffff9a000001a990 0008 0000 0x0 0x0
0xffff9a000001aa08 0008 0000 0x0 0x0
0xffff9a000001aa80 0008 0000 0x0 0x0
0xffff9a000001aaf8 0008 0000 0x0 0x0
0xffff9a000001ab70 0008 0000 0x0 0x0
0xffff9a000001abe8 0008 0000 0x0 0x0
0xffff9a000001ac60 0008 0000 0x0 0x0
0xffff9a000001acd8 0008 0000 0x0 0x0
0xffff9a000001ad50 0008 0000 0x0 0x0
0xffff9a000001adc8 0008 0000 0x0 0x0
0xffff9a000001ae40 0008 0000 0x0 0x0
0xffff9a000001aeb8 0008 0000 0x0 0x0
0xffff9a000001af30 0008 0000 0x0 0x0
0xffff9a000001afa8 0008 0000 0x0 0x0
0xffff9a000001b020 0008 0000 0x0 0x0
0xffff9a000001b098 0008 0000 0x0 0x0
0xffff9a000001b110 0008 0000 0x0 0x0
0xffff9a000001b188 0008 0000 0x0 0x0
0xffff9a000001b200 0008 0000 0x0 0x0
0xffff9a000001b278 0008 0000 0x0 0x0
0xffff9a000001b2f0 0008 0000 0x0 0x0
0xffff9a000001b368 0008 0000 0x0 0x0
0xffff9a000001b3e0 0008 0000 0x0 0x0
0xffff9a000001b458 0008 0000 0x0 0x0
0xffff9a000001b4d0 0008 0000 0x0 0x0
0xffff9a000001b548 0008 0000 0x0 0x0
0xffff9a000001b5c0 0008 0000 0x0 0x0
0xffff9a000001b638 0008 0000 0x0 0x0
0xffff9a000001b6b0 0008 0000 0x0 0x0
0xffff9a000001b728 0008 0000 0x0 0x0
0xffff9a000001b7a0 0008 0000 0x0 0x0
0xffff9a000001b818 0008 0000 0x0 0x0
0xffff9a000001b890 0008 0000 0x0 0x0
0xffff9a000001b908 0008 0000 0x0 0x0
0xffff9a000001b980 0008 0000 0x0 0x0
0xffff9a000001b9f8 0008 0000 0x0 0x0
0xffff9a000001ba70 0008 0000 0x0 0x0
0xffff9a000001bae8 0008 0000 0x0 0x0
0xffff9a000001bb60 0008 0000 0x0 0x0
0xffff9a000001bbd8 0008 0000 0x0 0x0
0xffff9a000001bc50 0008 0000 0x0 0x0
0xffff9a000001bcc8 0008 0000 0x0 0x0
0xffff9a000001bd40 0008 0000 0x0 0x0
0xffff9a000001bdb8 0008 0000 0x0 0x0
0xffff9a000001be30 0008 0000 0x0 0x0
0xffff9a000001bea8 0008 0000 0x0 0x0
0xffff9a000001bf20 0008 0000 0x0 0x0
0xffff9a000001bf98 0008 0000 0x0 0x0
0xffff9a000001c010 0008 0000 0x0 0x0
0xffff9a000001c088 0048 0000 0x0 0x0
0xffff9a000001c100 0048 0000 0x0 0x0
0xffff9a000001c178 0048 0000 0x0 0x0
0xffff9a000001c1f0 0048 0000 0x0 0x0
0xffff9a000001c268 0048 0000 0x0 0x0
0xffff9a000001c2e0 0048 0000 0x0 0x0
0xffff9a000001c358 0048 0000 0x0 0x0
0xffff9a000001c3d0 0048 0000 0x0 0x0
0xffff9a000001c448 0048 0000 0x0 0x0
0xffff9a000001c4c0 0048 0000 0x0 0x0
0xffff9a000001c538 0048 0000 0x0 0x0
0xffff9a000001c5b0 0048 0000 0x0 0x0
0xffff9a000001c628 0048 0000 0x0 0x0
0xffff9a000001c6a0 0048 0000 0x0 0x0
0xffff9a000001c718 0048 0000 0x0 0x0
0xffff9a000001c790 0048 0000 0x0 0x0
0xffff9a000001c808 0048 0000 0x0 0x0
0xffff9a000001c880 0048 0000 0x0 0x0
0xffff9a000001c8f8 0048 0000 0x0 0x0
0xffff9a000001c970 0048 0000 0x0 0x0
0xffff9a000001c9e8 0048 0000 0x0 0x0
0xffff9a000001ca60 0048 0000 0x0 0x0
0xffff9a000001cad8 0048 0000 0x0 0x0
0xffff9a000001cb50 0048 0000 0x0 0x0
0xffff9a000001cbc8 0048 0000 0x0 0x0
0xffff9a000001cc40 0048 0000 0x0 0x0
0xffff9a000001ccb8 0048 0000 0x0 0x0
0xffff9a000001cd30 0048 0000 0x0 0x0
0xffff9a000001cda8 0048 0000 0x0 0x0
0xffff9a000001ce20 0048 0000 0x0 0x0
0xffff9a000001ce98 0048 0000 0x0 0x0
0xffff9a000001cf10 0048 0000 0x0 0x0
0xffff9a000001cf88 0048 0000 0x0 0x0
0xffff9a000001d000 0048 0000 0x0 0x0
0xffff9a000001d078 0048 0000 0x0 0x0
0xffff9a000001d0f0 0048 0000 0x0 0x0
0xffff9a000001d168 0048 0000 0x0 0x0
0xffff9a000001d1e0 0048 0000 0x0 0x0
0xffff9a000001d258 0048 0000 0x0 0x0
0xffff9a000001d2d0 0048 0000 0x0 0x0
0xffff9a000001d348 0048 0000 0x0 0x0
0xffff9a000001d3c0 0048 0000 0x0 0x0
0xffff9a000001d438 0008 0000 0x0 0x0
0xffff9a000001d4b0 0008 0000 0x0 0x0
0xffff9a000001d528 0008 0000 0x0 0x0
0xffff9a000001d5a0 0008 0000 0x0 0x0
0xffff9a000001d618 0008 0000 0x0 0x0
0xffff9a000001d690 0008 0000 0x0 0x0
0xffff9a000001d708 0008 0000 0x0 0x0
0xffff9a000001d780 0008 0000 0x0 0x0
0xffff9a000001d7f8 0008 0000 0x0 0x0
0xffff9a000001d870 0008 0000 0x0 0x0
0xffff9a000001d8e8 0008 0000 0x0 0x0
0xffff9a000001d960 0008 0000 0x0 0x0
0xffff9a000001d9d8 0008 0000 0x0 0x0
0xffff9a000001da50 0008 0000 0x0 0x0
0xffff9a000001dac8 0008 0000 0x0 0x0
0xffff9a000001db40 0008 0000 0x0 0x0
0xffff9a000001dbb8 0008 0000 0x0 0x0
0xffff9a000001dc30 0008 0000 0x0 0x0
0xffff9a000001dca8 0008 0000 0x0 0x0
0xffff9a000001dd20 0008 0000 0x0 0x0
0xffff9a000001dd98 0008 0000 0x0 0x0
0xffff9a000001de10 0008 0000 0x0 0x0
0xffff9a000001de88 0008 0000 0x0 0x0
0xffff9a000001df00 0008 0000 0x0 0x0
0xffff9a000001df78 0008 0000 0x0 0x0
0xffff9a000001dff0 0008 0000 0x0 0x0
0xffff9a000001e068 0008 0000 0x0 0x0
0xffff9a000001e0e0 0008 0000 0x0 0x0
0xffff9a000001e158 0008 0000 0x0 0x0
0xffff9a000001e1d0 0008 0000 0x0 0x0
0xffff9a000001e248 0008 0000 0x0 0x0
0xffff9a000001e2c0 0008 0000 0x0 0x0
0xffff9a000001e338 0008 0000 0x0 0x0
0xffff9a000001e3b0 0008 0000 0x0 0x0
0xffff9a000001e428 0008 0000 0x0 0x0
0xffff9a000001e4a0 0008 0000 0x0 0x0
0xffff9a000001e518 0008 0000 0x0 0x0
0xffff9a000001e590 0008 0000 0x0 0x0
0xffff9a000001e608 0008 0000 0x0 0x0
0xffff9a000001e680 0008 0000 0x0 0x0
0xffff9a000001e6f8 0008 0000 0x0 0x0
0xffff9a000001e770 0008 0000 0x0 0x0
0xffff9a000001e7e8 0008 0000 0x0 0x0
0xffff9a000001e860 0008 0000 0x0 0x0
0xffff9a000001e8d8 0008 0000 0x0 0x0
0xffff9a000001e950 0008 0000 0x0 0x0
0xffff9a000001e9c8 0008 0000 0x0 0x0
0xffff9a000001ea40 0008 0000 0x0 0x0
0xffff9a000001eab8 0008 0000 0x0 0x0
0xffff9a000001eb30 0008 0000 0x0 0x0
0xffff9a000001eba8 0008 0000 0x0 0x0
0xffff9a000001ec20 0008 0000 0x0 0x0
0xffff9a000001ec98 0008 0000 0x0 0x0
0xffff9a000001ed10 0008 0000 0x0 0x0
0xffff9a000001ed88 0048 0000 0x0 0x0
0xffff9a000001ee00 0048 0000 0x0 0x0
0xffff9a000001ee78 0048 0000 0x0 0x0
0xffff9a000001eef0 0048 0000 0x0 0x0
0xffff9a000001ef68 0048 0000 0x0 0x0
0xffff9a000001efe0 0048 0000 0x0 0x0
0xffff9a000001f058 0048 0000 0x0 0x0
0xffff9a000001f0d0 0048 0000 0x0 0x0
0xffff9a000001f148 0048 0000 0x0 0x0
0xffff9a000001f1c0 0048 0000 0x0 0x0
0xffff9a000001f238 0048 0000 0x0 0x0
0xffff9a000001f2b0 0048 0000 0x0 0x0
0xffff9a000001f328 0048 0000 0x0 0x0
0xffff9a000001f3a0 0048 0000 0x0 0x0
0xffff9a000001f418 0048 0000 0x0 0x0
0xffff9a000001f490 0048 0000 0x0 0x0
0xffff9a000001f508 0048 0000 0x0 0x0
0xffff9a000001f580 0048 0000 0x0 0x0
0xffff9a000001f5f8 0048 0000 0x0 0x0
0xffff9a000001f670 0048 0000 0x0 0x0
0xffff9a000001f6e8 0048 0000 0x0 0x0
0xffff9a000001f760 0048 0000 0x0 0x0
0xffff9a000001f7d8 0048 0000 0x0 0x0
0xffff9a000001f850 0048 0000 0x0 0x0
0xffff9a000001f8c8 0048 0000 0x0 0x0
0xffff9a000001f940 0048 0000 0x0 0x0
0xffff9a000001f9b8 0048 0000 0x0 0x0
0xffff9a000001fa30 0048 0000 0x0 0x0
0xffff9a000001faa8 0040 0000 0x0 0x0
0xffff9a000001fb20 0040 0000 0x0 0x0
0xffff9a000001fb98 0048 0000 0x0 0x0
0xffff9a000001fc10 0040 0000 0x0 0x0
0xffff9a000001fc88 0048 0000 0x0 0x0
0xffff9a000001fd00 0048 0000 0x0 0x0
0xffff9a000001fd78 0048 0000 0x0 0x0
0xffff9a000001fdf0 0048 0000 0x0 0x0
0xffff9a000001fe68 0040 0000 0x0 0x0
0xffff9a000001fee0 0040 0000 0x0 0x0
0xffff9a000001ff58 0040 0000 0x0 0x0
0xffff9a000001ffd0 0040 0000 0x0 0x0
0xffff9a0000020048 0040 0000 0x0 0x0
0xffff9a00000200c0 0048 0000 0x0 0x0
0xffff9a0000020138 0048 0000 0x0 0x0
0xffff9a00000201b0 0008 0000 0x0 0x0
0xffff9a0000020228 0008 0000 0x0 0x0
0xffff9a00000202a0 0008 0000 0x0 0x0
0xffff9a0000020318 0008 0000 0x0 0x0
0xffff9a0000020390 0008 0000 0x0 0x0
0xffff9a0000020408 0008 0000 0x0 0x0
0xffff9a0000020480 0008 0000 0x0 0x0
0xffff9a00000204f8 0008 0000 0x0 0x0
0xffff9a0000020570 0008 0000 0x0 0x0
0xffff9a00000205e8 0008 0000 0x0 0x0
0xffff9a0000020660 0008 0000 0x0 0x0
0xffff9a00000206d8 0008 0000 0x0 0x0
0xffff9a0000020750 0008 0000 0x0 0x0
0xffff9a00000207c8 0008 0000 0x0 0x0
0xffff9a0000020840 0008 0000 0x0 0x0
0xffff9a00000208b8 0008 0000 0x0 0x0
0xffff9a0000020930 0008 0000 0x0 0x0
0xffff9a00000209a8 0008 0000 0x0 0x0
0xffff9a0000020a20 0008 0000 0x0 0x0
0xffff9a0000020a98 0008 0000 0x0 0x0
0xffff9a0000020b10 0008 0000 0x0 0x0
0xffff9a0000020b88 0008 0000 0x0 0x0
0xffff9a0000020c00 0008 0000 0x0 0x0
0xffff9a0000020c78 0008 0000 0x0 0x0
0xffff9a0000020cf0 0008 0000 0x0 0x0
0xffff9a0000020d68 0008 0000 0x0 0x0
0xffff9a0000020de0 0008 0000 0x0 0x0
0xffff9a0000020e58 0008 0000 0x0 0x0
0xffff9a0000020ed0 0008 0000 0x0 0x0
0xffff9a0000020f48 0008 0000 0x0 0x0
0xffff9a0000020fc0 0008 0000 0x0 0x0
0xffff9a0000021038 0008 0000 0x0 0x0
0xffff9a00000210b0 0008 0000 0x0 0x0
0xffff9a0000021128 0008 0000 0x0 0x0
0xffff9a00000211a0 0008 0000 0x0 0x0
0xffff9a0000021218 0008 0000 0x0 0x0
0xffff9a0000021290 0008 0000 0x0 0x0
0xffff9a0000021308 0008 0000 0x0 0x0
0xffff9a0000021380 0008 0000 0x0 0x0
0xffff9a00000213f8 0008 0000 0x0 0x0
0xffff9a0000021470 0008 0000 0x0 0x0
0xffff9a00000214e8 0008 0000 0x0 0x0
0xffff9a0000021560 0008 0000 0x0 0x0
0xffff9a00000215d8 0008 0000 0x0 0x0
0xffff9a0000021650 0008 0000 0x0 0x0
0xffff9a00000216c8 0008 0000 0x0 0x0
0xffff9a0000021740 0008 0000 0x0 0x0
0xffff9a00000217b8 0008 0000 0x0 0x0
0xffff9a0000021830 0008 0000 0x0 0x0
0xffff9a00000218a8 0008 0000 0x0 0x0
0xffff9a0000021920 0008 0000 0x0 0x0
0xffff9a0000021998 0008 0000 0x0 0x0
0xffff9a0000021a10 0008 0000 0x0 0x0
0xffff9a0000021a88 0008 0000 0x0 0x0
0xffff9a0000021b00 0040 0000 0x0 0x0
0xffff9a0000021b78 0040 0000 0x0 0x0
0xffff9a0000021bf0 0040 0000 0x0 0x0
0xffff9a0000021c68 0040 0000 0x0 0x0
0xffff9a0000021ce0 0040 0000 0x0 0x0
0xffff9a0000021d58 0040 0000 0x0 0x0
0xffff9a0000021dd0 0040 0000 0x0 0x0
0xffff9a0000021e48 0040 0000 0x0 0x0
0xffff9a0000021ec0 0040 0000 0x0 0x0
0xffff9a0000021f38 0040 0000 0x0 0x0
0xffff9a0000021fb0 0040 0000 0x0 0x0
0xffff9a0000022028 0040 0000 0x0 0x0
0xffff9a00000220a0 0040 0000 0x0 0x0
0xffff9a0000022118 0040 0000 0x0 0x0
0xffff9a0000022190 0040 0000 0x0 0x0
0xffff9a0000022208 0040 0000 0x0 0x0
0xffff9a0000022280 0040 0000 0x0 0x0
0xffff9a00000222f8 0040 0000 0x0 0x0
0xffff9a0000022370 0040 0000 0x0 0x0
0xffff9a00000223e8 0040 0000 0x0 0x0
0xffff9a0000022460 0040 0000 0x0 0x0
0xffff9a00000224d8 0040 0000 0x0 0x0
0xffff9a0000022550 0040 0000 0x0 0x0
0xffff9a00000225c8 0040 0000 0x0 0x0
0xffff9a0000022640 0040 0000 0x0 0x0
0xffff9a00000226b8 0040 0000 0x0 0x0
0xffff9a0000022730 0040 0000 0x0 0x0
0xffff9a00000227a8 0040 0000 0x0 0x0
0xffff9a0000022820 0040 0000 0x0 0x0
0xffff9a0000022898 0040 0000 0x0 0x0
0xffff9a0000022910 0040 0000 0x0 0x0
0xffff9a0000022988 0040 0000 0x0 0x0
0xffff9a0000022a00 0040 0000 0x0 0x0
0xffff9a0000022a78 0040 0000 0x0 0x0
0xffff9a0000022af0 0040 0000 0x0 0x0
0xffff9a0000022b68 0040 0000 0x0 0x0
0xffff9a0000022be0 0040 0000 0x0 0x0
0xffff9a0000022c58 0040 0000 0x0 0x0
0xffff9a0000022cd0 0040 0000 0x0 0x0
0xffff9a0000022d48 0040 0000 0x0 0x0
0xffff9a0000022dc0 0040 0000 0x0 0x0
0xffff9a0000022e38 0040 0000 0x0 0x0
0xffff9a0000022eb0 0040 0000 0x0 0x0
0xffff9a0000022f28 0040 0000 0x0 0x0
0xffff9a0000022fa0 0040 0000 0x0 0x0
0xffff9a0000023018 0040 0000 0x0 0x0
0xffff9a0000023090 0040 0000 0x0 0x0
0xffff9a0000023108 0040 0000 0x0 0x0
0xffff9a0000023180 0040 0000 0x0 0x0
0xffff9a00000231f8 0040 0000 0x0 0x0
0xffff9a0000023270 0040 0000 0x0 0x0
0xffff9a00000232e8 0048 0000 0x0 0x0
0xffff9a0000023360 0048 0000 0x0 0x0
0xffff9a00000233d8 0040 0000 0x0 0x0
0xffff9a0000023450 0048 0000 0x0 0x0
0xffff9a00000234c8 0040 0000 0x0 0x0
0xffff9a0000023540 0040 0000 0x0 0x0
0xffff9a00000235b8 0040 0000 0x0 0x0
0xffff9a0000023630 0040 0000 0x0 0x0
0xffff9a00000236a8 0048 0000 0x0 0x0
0xffff9a0000023720 0048 0000 0x0 0x0
0xffff9a0000023798 0040 0000 0x0 0x0
0xffff9a0000023810 0048 0000 0x0 0x0
0xffff9a0000023888 0048 0000 0x0 0x0
0xffff9a0000023900 0048 0000 0x0 0x0
0xffff9a0000023978 0048 0000 0x0 0x0
0xffff9a00000239f0 0048 0000 0x0 0x0
0xffff9a0000023a68 0048 0000 0x0 0x0
0xffff9a0000023ae0 0048 0000 0x0 0x0
0xffff9a0000023b58 0048 0000 0x0 0x0
0xffff9a0000023bd0 0048 0000 0x0 0x0
0xffff9a0000023c48 0048 0000 0x0 0x0
0xffff9a0000023cc0 0048 0000 0x0 0x0
0xffff9a0000023d38 0048 0000 0x0 0x0
0xffff9a0000023db0 0048 0000 0x0 0x0
0xffff9a0000023e28 0048 0000 0x0 0x0
0xffff9a0000023ea0 0048 0000 0x0 0x0
0xffff9a0000023f18 0048 0000 0x0 0x0
0xffff9a0000023f90 0048 0000 0x0 0x0
0xffff9a0000024008 0048 0000 0x0 0x0
0xffff9a0000024080 0048 0000 0x0 0x0
0xffff9a00000240f8 0048 0000 0x0 0x0
0xffff9a0000024170 0048 0000 0x0 0x0
0xffff9a00000241e8 0048 0000 0x0 0x0
0xffff9a0000024260 0048 0000 0x0 0x0
0xffff9a00000242d8 0048 0000 0x0 0x0
0xffff9a0000024350 0048 0000 0x0 0x0
0xffff9a00000243c8 0048 0000 0x0 0x0
0xffff9a0000024440 0048 0000 0x0 0x0
0xffff9a00000244b8 0048 0000 0x0 0x0
0xffff9a0000024530 0048 0000 0x0 0x0
0xffff9a00000245a8 0048 0000 0x0 0x0
0xffff9a0000024620 0048 0000 0x0 0x0
0xffff9a0000024698 0048 0000 0x0 0x0
0xffff9a0000024710 0048 0000 0x0 0x0
0xffff9a0000024788 0048 0000 0x0 0x0
0xffff9a0000024800 0048 0000 0x0 0x0
0xffff9a0000024878 0048 0000 0x0 0x0
0xffff9a00000248f0 0048 0000 0x0 0x0
0xffff9a0000024968 0048 0000 0x0 0x0
0xffff9a00000249e0 0048 0000 0x0 0x0
0xffff9a0000024a58 0048 0000 0x0 0x0
0xffff9a0000024ad0 0048 0000 0x0 0x0
0xffff9a0000024b48 0048 0000 0x0 0x0
0xffff9a0000024bc0 0048 0000 0x0 0x0
0xffff9a0000024c38 0048 0000 0x0 0x0
0xffff9a0000024cb0 0048 0000 0x0 0x0
0xffff9a0000024d28 0048 0000 0x0 0x0
0xffff9a0000024da0 0048 0000 0x0 0x0
0xffff9a0000024e18 0048 0000 0x0 0x0
0xffff9a0000024e90 0048 0000 0x0 0x0
0xffff9a0000024f08 0048 0000 0x0 0x0
0xffff9a0000024f80 0048 0000 0x0 0x0
0xffff9a0000024ff8 0048 0000 0x0 0x0
0xffff9a0000025070 0048 0000 0x0 0x0
0xffff9a00000250e8 0048 0000 0x0 0x0
0xffff9a0000025160 0048 0000 0x0 0x0
0xffff9a00000251d8 0048 0000 0x0 0x0
0xffff9a0000025250 0008 0000 0x0 0x0
0xffff9a00000252c8 0008 0000 0x0 0x0
0xffff9a0000025340 0008 0000 0x0 0x0
0xffff9a00000253b8 0008 0000 0x0 0x0
0xffff9a0000025430 0008 0000 0x0 0x0
0xffff9a00000254a8 0008 0000 0x0 0x0
0xffff9a0000025520 0008 0000 0x0 0x0
0xffff9a0000025598 0008 0000 0x0 0x0
0xffff9a0000025610 0008 0000 0x0 0x0
0xffff9a0000025688 0008 0000 0x0 0x0
0xffff9a0000025700 0008 0000 0x0 0x0
0xffff9a0000025778 0008 0000 0x0 0x0
0xffff9a00000257f0 0008 0000 0x0 0x0
0xffff9a0000025868 0008 0000 0x0 0x0
0xffff9a00000258e0 0008 0000 0x0 0x0
0xffff9a0000025958 0008 0000 0x0 0x0
0xffff9a00000259d0 0008 0000 0x0 0x0
0xffff9a0000025a48 0008 0000 0x0 0x0
0xffff9a0000025ac0 0008 0000 0x0 0x0
0xffff9a0000025b38 0008 0000 0x0 0x0
0xffff9a0000025bb0 0008 0000 0x0 0x0
0xffff9a0000025c28 0008 0000 0x0 0x0
0xffff9a0000025ca0 0008 0000 0x0 0x0
0xffff9a0000025d18 0008 0000 0x0 0x0
0xffff9a0000025d90 0008 0000 0x0 0x0
0xffff9a0000025e08 0008 0000 0x0 0x0
0xffff9a0000025e80 0008 0000 0x0 0x0
0xffff9a0000025ef8 0008 0000 0x0 0x0
0xffff9a0000025f70 0008 0000 0x0 0x0
0xffff9a0000025fe8 0008 0000 0x0 0x0
0xffff9a0000026060 0008 0000 0x0 0x0
0xffff9a00000260d8 0008 0000 0x0 0x0
0xffff9a0000026150 0008 0000 0x0 0x0
0xffff9a00000261c8 0008 0000 0x0 0x0
0xffff9a0000026240 0008 0000 0x0 0x0
0xffff9a00000262b8 0008 0000 0x0 0x0
0xffff9a0000026330 0008 0000 0x0 0x0
0xffff9a00000263a8 0008 0000 0x0 0x0
0xffff9a0000026420 0008 0000 0x0 0x0
0xffff9a0000026498 0008 0000 0x0 0x0
0xffff9a0000026510 0008 0000 0x0 0x0
0xffff9a0000026588 0008 0000 0x0 0x0
0xffff9a0000026600 0008 0000 0x0 0x0
0xffff9a0000026678 0008 0000 0x0 0x0
0xffff9a00000266f0 0008 0000 0x0 0x0
0xffff9a0000026768 0008 0000 0x0 0x0
0xffff9a00000267e0 0008 0000 0x0 0x0
0xffff9a0000026858 0008 0000 0x0 0x0
0xffff9a00000268d0 0008 0000 0x0 0x0
0xffff9a0000026948 0008 0000 0x0 0x0
0xffff9a00000269c0 0008 0000 0x0 0x0
0xffff9a0000026a38 0008 0000 0x0 0x0
0xffff9a0000026ab0 0008 0000 0x0 0x0
0xffff9a0000026b28 0008 0000 0x0 0x0
0xffff9a0000026ba0 0008 0000 0x0 0x0
0xffff9a0000026c18 0008 0000 0x0 0x0
0xffff9a0000026c90 0008 0000 0x0 0x0
0xffff9a0000026d08 0008 0000 0x0 0x0
0xffff9a0000026d80 0008 0000 0x0 0x0
0xffff9a0000026df8 0008 0000 0x0 0x0
0xffff9a0000026e70 0008 0000 0x0 0x0
0xffff9a0000026ee8 0008 0000 0x0 0x0
0xffff9a0000026f60 0008 0000 0x0 0x0
0xffff9a0000026fd8 0008 0000 0x0 0x0
0xffff9a0000027050 0008 0000 0x0 0x0
0xffff9a00000270c8 0008 0000 0x0 0x0
0xffff9a0000027140 0008 0000 0x0 0x0
0xffff9a00000271b8 0008 0000 0x0 0x0
0xffff9a0000027230 0008 0000 0x0 0x0
0xffff9a00000272a8 0008 0000 0x0 0x0
0xffff9a0000027320 0008 0000 0x0 0x0
0xffff9a0000027398 0008 0000 0x0 0x0
0xffff9a0000027410 0008 0000 0x0 0x0
0xffff9a0000027488 0008 0000 0x0 0x0
0xffff9a0000027500 0008 0000 0x0 0x0
0xffff9a0000027578 0008 0000 0x0 0x0
0xffff9a00000275f0 0008 0000 0x0 0x0
0xffff9a0000027668 0008 0000 0x0 0x0
0xffff9a00000276e0 0008 0000 0x0 0x0
0xffff9a0000027758 0008 0000 0x0 0x0
0xffff9a00000277d0 0008 0000 0x0 0x0
0xffff9a0000027848 0008 0000 0x0 0x0
0xffff9a00000278c0 0008 0000 0x0 0x0
0xffff9a0000027938 0008 0000 0x0 0x0
0xffff9a00000279b0 0008 0000 0x0 0x0
0xffff9a0000027a28 0008 0000 0x0 0x0
0xffff9a0000027aa0 0008 0000 0x0 0x0
0xffff9a0000027b18 0008 0000 0x0 0x0
0xffff9a0000027b90 0008 0000 0x0 0x0
0xffff9a0000027c08 0008 0000 0x0 0x0
0xffff9a0000027c80 0008 0000 0x0 0x0
0xffff9a0000027cf8 0008 0000 0x0 0x0
0xffff9a0000027d70 0008 0000 0x0 0x0
0xffff9a0000027de8 0008 0000 0x0 0x0
0xffff9a0000027e60 0008 0000 0x0 0x0
0xffff9a0000027ed8 0008 0000 0x0 0x0
0xffff9a0000027f50 0008 0000 0x0 0x0
0xffff9a0000027fc8 0008 0000 0x0 0x0
0xffff9a0000028040 0008 0000 0x0 0x0
0xffff9a00000280b8 0008 0000 0x0 0x0
0xffff9a0000028130 0008 0000 0x0 0x0
0xffff9a00000281a8 0008 0000 0x0 0x0
0xffff9a0000028220 0008 0000 0x0 0x0
0xffff9a0000028298 0008 0000 0x0 0x0
0xffff9a0000028310 0008 0000 0x0 0x0
0xffff9a0000028388 0008 0000 0x0 0x0
0xffff9a0000028400 0008 0000 0x0 0x0
0xffff9a0000028478 0008 0000 0x0 0x0
0xffff9a00000284f0 0008 0000 0x0 0x0
0xffff9a0000028568 0008 0000 0x0 0x0
0xffff9a00000285e0 0008 0000 0x0 0x0
0xffff9a0000028658 0008 0000 0x0 0x0
0xffff9a00000286d0 0008 0000 0x0 0x0
0xffff9a0000028748 0008 0000 0x0 0x0
0xffff9a00000287c0 0008 0000 0x0 0x0
0xffff9a0000028838 0008 0000 0x0 0x0
0xffff9a00000288b0 0008 0000 0x0 0x0
0xffff9a0000028928 0008 0000 0x0 0x0
0xffff9a00000289a0 0008 0000 0x0 0x0
0xffff9a0000028a18 0008 0000 0x0 0x0
0xffff9a0000028a90 0008 0000 0x0 0x0
0xffff9a0000028b08 0008 0000 0x0 0x0
0xffff9a0000028b80 0008 0000 0x0 0x0
0xffff9a0000028bf8 0008 0000 0x0 0x0
0xffff9a0000028c70 0008 0000 0x0 0x0
0xffff9a0000028ce8 0008 0000 0x0 0x0
0xffff9a0000028d60 0008 0000 0x0 0x0
0xffff9a0000028dd8 0008 0000 0x0 0x0
0xffff9a0000028e50 0008 0000 0x0 0x0
0xffff9a0000028ec8 0008 0000 0x0 0x0
0xffff9a0000028f40 0008 0000 0x0 0x0
0xffff9a0000028fb8 0008 0000 0x0 0x0
0xffff9a0000029030 0008 0000 0x0 0x0
0xffff9a00000290a8 0008 0000 0x0 0x0
0xffff9a0000029120 0008 0000 0x0 0x0
0xffff9a0000029198 0008 0000 0x0 0x0
0xffff9a0000029210 0008 0000 0x0 0x0
0xffff9a0000029288 0008 0000 0x0 0x0
0xffff9a0000029300 0008 0000 0x0 0x0
0xffff9a0000029378 0008 0000 0x0 0x0
0xffff9a00000293f0 0008 0000 0x0 0x0
0xffff9a0000029468 0008 0000 0x0 0x0
0xffff9a00000294e0 0008 0000 0x0 0x0
0xffff9a0000029558 0008 0000 0x0 0x0
0xffff9a00000295d0 0008 0000 0x0 0x0
0xffff9a0000029648 0008 0000 0x0 0x0
0xffff9a00000296c0 0008 0000 0x0 0x0
0xffff9a0000029738 0008 0000 0x0 0x0
0xffff9a00000297b0 0008 0000 0x0 0x0
0xffff9a0000029828 0008 0000 0x0 0x0
0xffff9a00000298a0 0008 0000 0x0 0x0
0xffff9a0000029918 0008 0000 0x0 0x0
0xffff9a0000029990 0008 0000 0x0 0x0
0xffff9a0000029a08 0008 0000 0x0 0x0
0xffff9a0000029a80 0008 0000 0x0 0x0
0xffff9a0000029af8 0008 0000 0x0 0x0
0xffff9a0000029b70 0008 0000 0x0 0x0
0xffff9a0000029be8 0008 0000 0x0 0x0
0xffff9a0000029c60 0008 0000 0x0 0x0
0xffff9a0000029cd8 0008 0000 0x0 0x0
0xffff9a0000029d50 0008 0000

---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 14, 2020, 1:01:12 PM3/14/20
to syzkaller-...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 5651e13d style
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=115f352de00000
kernel config: https://syzkaller.appspot.com/x/.config?x=824b23e1f4b6c76b
dashboard link: https://syzkaller.appspot.com/bug?extid=2a84e8bb0967d5b95a73
compiler: g++ (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=155b8d2de00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1437a1f9e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+2a84e8...@syzkaller.appspotmail.com

[ 77.1433382] panic: kernel diagnostic assertion "rv" failed: file "/syzkaller/managers/netbsd-kubsan/kernel/sys/miscfs/genfs/genfs_io.c", line 1943
[ 77.1570173] cpu0: Begin traceback...
[ 77.1633601] vpanic() at netbsd:vpanic+0x2af sys/kern/subr_prf.c:336
[ 77.2134435] kern_assert() at netbsd:kern_assert+0x63
[ 77.2535142] genfs_directio() at netbsd:genfs_directio+0xb24 genfs_do_directio sys/miscfs/genfs/genfs_io.c:1943 [inline]
[ 77.2535142] genfs_directio() at netbsd:genfs_directio+0xb24 sys/miscfs/genfs/genfs_io.c:1834
[ 77.3035962] ffs_write() at netbsd:ffs_write+0xaf4 sys/ufs/ufs/ufs_readwrite.c:354
[ 77.3436633] VOP_WRITE() at netbsd:VOP_WRITE+0x121 sys/kern/vnode_if.c:506
[ 77.3937505] vn_write() at netbsd:vn_write+0x27a sys/kern/vfs_vnops.c:614
[ 77.4438319] do_filewritev.part.1() at netbsd:do_filewritev.part.1+0x40c
[ 77.4939165] sys_writev() at netbsd:sys_writev+0x54 do_filewritev sys/kern/sys_generic.c:381 [inline]
[ 77.4939165] sys_writev() at netbsd:sys_writev+0x54 sys/kern/sys_generic.c:381
[ 77.5339832] sys_syscall() at netbsd:sys_syscall+0x1c8 sy_call sys/sys/syscallvar.h:65 [inline]
[ 77.5339832] sys_syscall() at netbsd:sys_syscall+0x1c8 sys/kern/sys_syscall.c:77
[ 77.5840678] syscall() at netbsd:syscall+0x29a sy_call sys/sys/syscallvar.h:65 [inline]
[ 77.5840678] syscall() at netbsd:syscall+0x29a sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 77.5840678] syscall() at netbsd:syscall+0x29a sys/arch/x86/x86/syscall.c:138
[ 77.6045859] --- syscall (number 0) ---
[ 77.6045859] Skipping crash dump on recursive panic
[ 77.6045859] panic: UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/arch/amd64/amd64/db_machdep.c:153:24, member access within misaligned address 0xffffffff for type 'struct x86_64_frame' which requires 8 byte alignment

[ 77.6353856] Faulted in mid-traceback; aborting...
[ 77.6353856] fatal breakpoint trap in supervisor mode
[ 77.6451925] trap type 1 code 0 rip 0xffffffff8021f59d cs 0x8 rflags 0x286 cr2 0xffffd500b008a000 ilevel 0 rsp 0xffffd500b73bfc50
[ 77.6567297] curlwp 0xfffffd3b260d3900 pid 4631.1 lowest kstack 0xffffd500b73bd2c0
Stopped in pid 4631.1 (syz-executor5525) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xd1 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x2af sys/kern/subr_prf.c:336
isAlreadyReported() at netbsd:isAlreadyReported
HandleTypeMismatch.part.1() at netbsd:HandleTypeMismatch.part.1+0xcc
HandleTypeMismatch() at netbsd:HandleTypeMismatch+0x7b sys/../common/lib/libc/misc/ubsan.c:417
db_nextframe() at netbsd:db_nextframe+0x6f6 sys/arch/amd64/amd64/db_machdep.c:153
db_stack_trace_print() at netbsd:db_stack_trace_print+0x294 sys/arch/x86/x86/db_trace.c:277
db_panic() at netbsd:db_panic+0x8b x86_curcpu sys/arch/amd64/compile/obj/GENERIC_SYZKALLER/./machine/cpu.h:56 [inline]
db_panic() at netbsd:db_panic+0x8b sys/ddb/db_panic.c:57
vpanic() at netbsd:vpanic+0x2af sys/kern/subr_prf.c:336
kern_assert() at netbsd:kern_assert+0x63
genfs_directio() at netbsd:genfs_directio+0xb24 genfs_do_directio sys/miscfs/genfs/genfs_io.c:1943 [inline]
genfs_directio() at netbsd:genfs_directio+0xb24 sys/miscfs/genfs/genfs_io.c:1834
ffs_write() at netbsd:ffs_write+0xaf4 sys/ufs/ufs/ufs_readwrite.c:354
VOP_WRITE() at netbsd:VOP_WRITE+0x121 sys/kern/vnode_if.c:506
vn_write() at netbsd:vn_write+0x27a sys/kern/vfs_vnops.c:614
do_filewritev.part.1() at netbsd:do_filewritev.part.1+0x40c
sys_writev() at netbsd:sys_writev+0x54 do_filewritev sys/kern/sys_generic.c:381 [inline]
sys_writev() at netbsd:sys_writev+0x54 sys/kern/sys_generic.c:381
sys_syscall() at netbsd:sys_syscall+0x1c8 sy_call sys/sys/syscallvar.h:65 [inline]
sys_syscall() at netbsd:sys_syscall+0x1c8 sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x29a sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x29a sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x29a sys/arch/x86/x86/syscall.c:138
--- syscall (number 0) ---
[ 77.6642036] Skipping crash dump on recursive panic
[ 77.6642036] panic: UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/arch/amd64/amd64/db_machdep.c:154:14, member access within misaligned address 0xffffffff for type 'struct x86_64_frame' which requires 8 byte alignment

[ 77.6642036] Faulted in mid-traceback; aborting...
[ 77.6642036] fatal breakpoint trap in supervisor mode
[ 77.6642036] trap type 1 code 0 rip 0xffffffff8021f59d cs 0x8 rflags 0x282 cr2 0xffffd500b008a000 ilevel 0x8 rsp 0xffffd500b73be8d0
[ 77.6642036] curlwp 0xfffffd3b260d3900 pid 4631.1 lowest kstack 0xffffd500b73bd2c0
Stopped in pid 4631.1 (syz-executor5525) at netbsd:breakpoint+0x5: leave

Reply all
Reply to author
Forward
0 new messages